Group:
Lockbit3
Discovered by ransomware.live: 2024-03-14
Estimated attack date:
2024-03-06
Country:
Description:
With over 25 years of experience we have expanded into a globally positioned third party logistics company with a multitude of offices and agents across the globe to assist with your transport needs.Journey Freight™’s driving force is personalized...
Infostealer activity detected by HudsonRock
Compromised Employees: 2
Compromised Users: 14
Third Party Employee Credentials: 4
External Attack Surface:
60
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- aspmx.l.google.com.
- smtp.google.com.
- alt4.aspmx.l.google.com.
- alt3.aspmx.l.google.com.
- alt2.aspmx.l.google.com.
- alt1.aspmx.l.google.com.
- MS=ms22060758
- MS=ms68128979
- google-site-verification=t3wTLM3oscQb5rTX29a11fFoE0mxsVHR2bAnFHeXVF8
- apple-domain-verification=nVNxSXpL3iuCopKO
- ppe-ba449097f85ca763bbcb5aaf08a758690b769b2f
- v=spf1 include:_spf.google.com include:_spf.salesforce.com include:spf.zoho.com include:transmail.net ip4:104.209.35.28 ip4:104.210.80.79 ip4:104.40.229.156 ip4:13.64.55.16/28 ip4:13.70.157.244 ip4:18.118.35.214 ip4:18.189.50.166 ip4:18.219.54.208 ip4:191" ".237.4.149 ip4:199.115.76.18/25 ip4:199.66.223.104/27 ip4:23.100.16.236 ip4:23.100.38.75 ip4:3.139.206.90 ip4:3.141.139.175 ip4:3.22.88.143 ip4:51.140.37.132 ip4:51.141.5.228 ip4:52.169.0.179 ip4:52.172.38.8 ip4:52.226.94.192/28 ip4:52.233.37.155 ip4:52.2" "42.32.10 ip4:69.17.149.72/29 ip4:69.70.242.197/30 ip4:72.138.188.144/28 ip4:72.138.188.72/29 ip4:96.245.207.30 -all
- MS=ms69213412
- google-site-verification=NJvajtzPbdBJfk1TxzghvZhKNlYNkMSDzmThqOq93dw
- be587e86046645808dc4bac97776bb45acd317ded7ed6d97d7
- zoho-verification=zb87201492.zmverify.zoho.com
- amazon-business-verification=902cc12c99dcb694b22ced8fca34d663e8cb0ab141a504b36deee44d907b0cc0
- nue3ji92ufk66opl927iqqbejv
Cloud / SaaS Services Detected
Apple
Microsoft 365
Salesforce
Zoho Campaigns
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.