vyera.com
blackbastaThis record tracks a ransomware attack claimed by the blackbasta group against vyera.com. It collects the publicly disclosed attack details — sector, location and timeline — as published on the operator's leak site and indexed by Breach House.
Window Zero
EXPOSURE GAPWindow Zero is the time the breach stayed in the open before anyone said so — the gap between when the attack was first discovered on the operator's leak site (t1) and when it was publicly disclosed (t2). The wider this window, the longer victims, staff and customers were exposed with no warning.
Attack Summary
Vyera Pharmaceuticals is committed to developing and commercializing treatments that address serious and neglected diseases with high unmet medical needs.SITE: www.vyera.com Address 600 Third Avenue, 19th Floor New York, NY 10016 UNITED STATES 212.202.5935FULL DATA SIZE: 226gb 1. R&D 2. HR 3. W-9 forms 4. ConfidentialityNETWORK: NYNY ny.vyera.com-------------------------DOMAIN ADMINS------------------------- Administrator a-mkolias gunjan.jain kbezrodnykh pauserid-svc rpatel rws rws.ind rws.support SCCMADMIN varonis-svcny.vyera.com\Administrator P@$$m0rd_2021 ny.vyera.com\SCCMADMIN P@$$m0rd_2021 ny.vyera.com\rws.support M@$$m0rd_2023-------------------------DC------------------------- vny-dc01.ny.vyera.com 172.16.15.2 Windows Server 2016 Datacenter vny-dc02.ny.vyera.com vny-dc03.ny.vyera.com 172.17.9.4 Windows Server 2019 Datacenter VNY-RDC01.ny.vyera.com 172.16.26.2 Windows Server 2016 Datacenter NOT REAL DC: vny-rdc01.ny.vyera.com 172.16.26.2 Windows Server 2016 Datacenter-------------------------SERVERS------------------------- fileserver.ny.vyera.com Windows Server 2016 Datacenter fileserver-cl.ny.vyera.com Windows Server 2016 Datacenter vnj-cl02.ny.vyera.com Windows Server 2016 Datacenter vny-ms05.ny.vyera.com 172.16.15.15 Windows Server 2016 Datacenter vny-ms04.ny.vyera.com 172.16.15.26 Windows Server 2016 Datacenter vye-ny-as02.ny.vyera.com Windows Server 2016 Datacenter vnj-cfs01.ny.vyera.com Windows Server 2016 Datacenter vnj-as01.ny.vyera.com Windows Server 2016 Datacenter vnj-dc01.ny.vyera.com Windows Server 2016 Datacenter vnj-hv01.ny.vyera.com Windows Server 2016 Datacenter vnj-cfs02.ny.vyera.com Windows Server 2016 Datacenter vnj-dc02.ny.vyera.com Windows Server 2016 Datacenter vny-hv03.ny.vyera.com 172.16.16.10 Windows Server 2016 Datacenter nsc01.ny.vyera.com Windows Server 2016 Datacenter vny-bi01.ny.vyera.com 172.16.15.43 Windows Server 2016 Datacenter vny-br01.ny.vyera.com Windows Server 2016 Datacenter vny-fs01.ny.vyera.com 172.16.15.12 Windows Server 2016 Datacenter rws_test.ny.vyera.com Windows Server 2016 Datacenter test.ny.vyera.com Windows Server 2016 Datacenter vny-gw01.ny.vyera.com Windows Server 2016 Datacenter vny-ns02.ny.vyera.com Windows Server 2016 Datacenter vnj-ws01.ny.vyera.com Windows Server 2016 Datacenter vny-cfs03.ny.vyera.com 172.16.15.31 Windows Server 2016 Datacenter vny-sh01.ny.vyera.com Windows Server 2016 Datacenter vny-ws01.ny.vyera.com Windows Server 2016 Datacenter vny-ms06.ny.vyera.com 172.16.15.25 Windows Server 2016 Datacenter vny-db05.ny.vyera.com 172.16.15.24 Windows Server 2016 Datacenter vny-cfs02.ny.vyera.com Windows Server 2016 Datacenter vny-cfs01.ny.vyera.com Windows Server 2016 Datacenter vny-cl01.ny.vyera.com 172.16.15.23 Windows Server 2016 Datacenter vny-cl02.ny.vyera.com 172.16.15.29 Windows Server 2016 Datacenter vny-db04.ny.vyera.com Windows Server 2016 Datacenter vny-db03.ny.vyera.com 172.16.15.18 Windows Server 2016 Datacenter vny-us01.ny.vyera.com Windows Server 2016 Datacenter vny-db01.ny.vyera.com 172.16.15.69 Windows Server 2016 Datacenter vny-pr01.ny.vyera.com Windows Server 2016 Datacenter vny-hv01.ny.vyera.com 172.16.15.70 Windows Server 2016 Datacenter vny-sc01.ny.vyera.com 172.16.15.34 Windows Server 2016 Datacenter vny-bk01.ny.vyera.com 172.16.15.79 Windows Server 2016 Datacenter vny-db02.ny.vyera.com Windows Server 2016 Datacenter vny-as04.ny.vyera.com 172.16.15.17 Windows Server 2016 Datacenter vny-cx05.ny.vyera.com 172.16.15.11 Windows Server 2016 Datacenter vny-cx04.ny.vyera.com Windows Server 2016 Datacenter vny-as06.ny.vyera.com 172.16.15.37 Windows Server 2016 Datacenter vny-vc01.ny.vyera.com Windows Server 2016 Datacenter vny-hv02.ny.vyera.com 172.16.15.21 Windows Server 2016 Datacenter vny-cx02.ny.vyera.com 172.16.15.65 Windows Server 2016 Datacenter vny-as02.ny.vyera.com Windows Server 2016 Datacenter vny-ns01.ny.vyera.com Windows Server 2016 Datacenter vny-cx03.ny.vyera.com 172.16.15.64 Windows Server 2016 Datacenter vny-as01.ny.vyera.com 172.16.15.42 Windows Server 2016 Datacenter vny-as03.ny.vyera.com Windows Server 2016 Datacenter admtpc.ny.vyera.com Windows Server 2016 DatacenterPHXCH phoenixus.com-------------------------DOMAIN ADMINS------------------------- Administrator a-mkolias gunjan.jain kbezrodnykh pauserid-svc rpatel rws rws.ind rws.support SCCMADMIN varonis-svcphxch\Administrator 1@rmyKnife!!-------------------------DC------------------------- phx-dc01.phoenixus.com 172.16.105.2 Windows Server 2016 Datacenter phx-dc02.phoenixus.com 172.16.105.3 Windows Server 2016 Datacenter-------------------------SERVERS------------------------- phx-hv02.phoenixus.com 172.16.105.33 Windows Server 2016 Datacenter phx-hv01.phoenixus.com 172.16.105.16 Windows Server 2016 Datacenter phx-bk01.phoenixus.com Windows Server 2016 Datacenter phx-pbx01.phoenixus.com 172.16.111.20 Windows Server 2016 Datacenter phx-cl01.phoenixus.com 172.16.105.19 Windows Server 2016 Datacenter phx-test-cl.phoenixus.com Windows Server 2016 Datacenter test-cfs03.phoenixus.com Windows Server 2016 Datacenter phx-as01.phoenixus.com 172.16.105.32 Windows Server 2016 Datacenter phx-ps01.phoenixus.com 172.16.105.10 Windows Server 2016 Datacenter phx-fs01.phoenixus.com 172.16.105.35 Windows Server 2016 Datacenter phx-ws01.phoenixus.com 172.16.105.13 Windows Server 2016 Datacenter phx-sc01.phoenixus.com 172.16.105.14 Windows Server 2016 Datacenter phx-ns01.phoenixus.com 172.16.105.15 Windows Server 2016 Datacenter phx-ca02.phoenixus.com 172.16.105.11 Windows Server 2016 Datacenter test-fs01.phoenixus.com Windows Server 2016 StandardVYERA vyera.com-------------------------DOMAIN ADMINS------------------------- Administrator admt-svc AzureADSyncvyera.com\AzureADSync Provost_ver!!!23-------------------------DC------------------------- v-dc01.vyera.com 172.16.14.2 Windows Server 2016 Datacenter v-dc02.vyera.com v-dc03.vyera.com 172.17.8.4 Windows Server 2019 Datacenter-------------------------SERVERS------------------------- v-ca02.vyera.com 172.16.15.55 Windows Server 2016 Datacenter v-ws01.vyera.com Windows Server 2016 Datacenter Sage_Test.vyera.com Windows Server 2016 Datacenter EvaluationOAK oakrumpharma.com-------------------------DOMAIN ADMINS------------------------- Administrator veeam-svc Azure-svc varonis-svcOAK\veeam-svc 4RfIp@YXq,j&j,Px1LypRnsu-------------------------DC------------------------- oak-dc01.oakrumpharma.com 172.16.92.2 Windows Server 2016 Datacenter oak-dc02.oakrumpharma.com 172.16.92.3 Windows Server 2016 Datacenter-------------------------SERVERS------------------------- oak-fs01.oakrumpharma.com 172.16.92.5 Windows Server 2016 DatacenterSSP sevenscorepharma.com-------------------------DOMAIN ADMINS------------------------- Administratorsevenscorepharma.com\Administrator P@$$m0rd_2021-------------------------DC------------------------- ssp-dc01.sevenscorepharma.com ssp-dc02.sevenscorepharma.com 172.21.15.3 Windows Server 2016 Datacenter-------------------------SERVERS------------------------- ssp-as01.sevenscorepharma.com 172.21.15.13 Windows Server 2016 Datacenter ssp-ps01.sevenscorepharma.com Windows Server 2016 Datacenter ssp-fs01.sevenscorepharma.com 172.21.15.11 Windows Server 2016 Datacenter
Leak Screenshots
SAMPLEProof-of-breach screenshots the operator posted from the stolen data. Previews are redacted and locked — the originals are available on HaveIBeenRansom.