Discovered
2025-02-20
Est. attack date
2025-02-20
Country
Description:
Founded in 1946, EHDD seeks to create built environments that enhance our culture, honor the natural environment, and respect and delight the people who use them. Headquartered in San Francisco, EHDD serves clients around the world in Aquariums, Museums and Science Centers, Education, Corporate Office, Mixed-Use Development, and Government. EHDD is a Top 10 AIA COTE honoree, and featured in " The Habits of High-Performance Firms, Lessons from frequent winners of the AIA COTE Top Ten Award.
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 4
Third Party Employee Credentials: 0
External Attack Surface:
1
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- ehdd.com.1.arsmtp.com.
- ehdd.com.2.arsmtp.com.
- google-site-verification=6ylo45KfYM9bNlieDqofkLun_0GNfwNTlngdNe04rGg
- v=spf1 include:spf.protection.outlook.com include:spf-westus.emailsignatures365.com ~all
- mqearfa16tr0dcm78quhchn84g
- duo_sso_verification=nFwRXhINOmNyRdwYRCmQOZ4GhYbi43bBu4yiB70owj1c67s7u3uS76JU1qCXowOh
- a27qips1j5t0bptkvmb7jf5k50
- e18ha6e6bokr7nn4bp50ipajnt
- MS=ms64158633
- aab539190800c4fdfcf7aaa6da34ee3c
Cloud / SaaS Services Detected
Microsoft 365
Cisco Duo
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.