Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Bay Area Rapid Transit

Group: Vicesociety

Discovered by ransomware.live: 2023-01-06

Estimated attack date: 2023-01-06

Country: US

Description:

The San Francisco Bay Area Rapid Transit District is a heavy-rail public transit system that connects the San Francisco Peninsula with communities in the East Bay and South Bay. BART operates in five counties with 131 miles of track and 50 stations, carrying approximately 405,000 trips on an average weekday.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mail.bart.gov.
  • smtp.bart.gov.
TXT Records
  • ca3-70a3bc37e03b4855b372165c1a33773c
  • autodesk-domain-verification=vCO635Vr1s3B9OFJDV36
  • _cf-custom-hostname.stg-auth.bart.gov=2e77661c-048c-494f-8e2b-d5bce9a89066
  • ca3-a30e691328c744c8879d695d3171e6e3
  • ccc3f66d-9228-48ff-bdcc-eb6438de169f
  • v=spf1 mx ip4:148.165.3.13 ip4:148.165.3.14 ip4:148.165.120.14 ip4:167.89.17.225 include:spf.protection.outlook.com include:_spf.qualtrics.com include:amazonses.com include:_spf.salesforce.com -all
  • ca3-9ca3e97f2237462294f2aa5b2b762f5c
  • 2e77661c-048c-494f-8e2b-d5bce9a89066
  • _cf-custom-hostname.auth.bart.gov=3d2cea9d-0ade-4221-9093-62de95e8c56d
  • 3d2cea9d-0ade-4221-9093-62de95e8c56d
  • dfa5e132-a854-4202-aeca-32f286692c82
  • bea44988-78a8-494b-880b-9f851d195507
  • ca3-23a0fb682aed4daea02aed4101d35696
  • docusign=0fd317f2-c4bc-431a-af8d-3ad84ed87bbb
  • _cf-custom-hostname.dev-auth.bart.gov=bea44988-78a8-494b-880b-9f851d195507
Cloud / SaaS Services Detected
Amazon SES/WorkMail Salesforce Autodesk DocuSign