Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

medicacorp.com

medicacorp.com

Discovered 2024-12-04 12:53 UTC
Est. attack date 2024-11-13
Country US
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Medica Corporation is a manufacturer specializing in diagnostic blood testing analyzers. The company focuses on creating simple-to-use and highly reliable devices for in vitro diagnostic laboratories, particularly those that are small to medium-sized. Their product range includes clinical chemistry analyzers, blood gas analyzers, and electrolyte analyzers.SITE: www.medicacorp.com Address : 5 Oak Park Drive Bedford, MA 01730 United StatesTEL#: 1 800 777 5983ALL DATA SIZE: ≈1.5tb 1. Departments data: Corporate, Financial, Accounting, Graphics… etc 2. Users data, Personal employees documents 3. Confidential data, NDA’s 4. R&D, Engeneering, Projects & etc…

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 0


External Attack Surface: 2


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registrar-abusecloudflare.com
MX Records
  • medicacorp-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • logmein-verification-code=be4f7d8a-be4c-4719-a985-fb43af442a45
  • v=spf1 include:_spf.salesforce.com include:_netblocks.mimecast.com include:spf.protection.outlook.com ip4:50.200.49.85 ip4:50.200.49.46 ip4:50.200.49.88 -all
  • MS=CBC58BE54EA49128F1467530D40A4CB5F05788A1
  • apple-domain-verification=NjFx2Z3dG56YUTGM
  • atlassian-domain-verification=K9ezuaP6wiwuN7ezKRJbwMgN32xSjHFtjO0F9MtQBT5wPlzhVEzKFhLC21Rshzq5
  • atlassian-sending-domain-verification=210ce0cc-50fa-408a-b27d-82e533a0e12c
  • f2bcfb73244547cc9cb950ce91c2ed0c
  • have-i-been-pwned-verification=dweb_r5dpq8jfrldilfhyhnjlqn44
Cloud / SaaS Services Detected
Apple Atlassian Have I Been Pwned LogMeIn Mimecast Salesforce

Leak Screenshot:

Leak Screenshot