Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Clínica Dávila

Group: Devman

Discovered by ransomware.live: 2025-12-22

Estimated attack date: 2025-12-18

Country: CL

Description:

Patients' full records, HIV test results, IDs. Throughout a long waiting period, and despite a vast number of phone calls and emails sent by our team to the hospital, we have seen no action from the clinic to resolve the issue - knowing that the HIV tests could potentially change the lives of people whose relatives, friends, and workplaces will...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 478

Third Party Employee Credentials: 20


External Attack Surface: 86


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse nic.cl
MX Records
  • mxa-0077b904.gslb.pphosted.com.
  • mxb-0077b904.gslb.pphosted.com.
TXT Records
  • _globalsign-domain-verification=dGhpabPEBcG42IIdZHowH9a7yMq5Fg4FDzzHyRhF4e
  • _3a3tbfxtrdkd1b4vafzwfjj2ee51acc
  • v=spf1 include:_spfae.corpmailsvcs.com a include:_spf.google.com include:_spf.tisal.cl include:spf.protection.outlook.com ip4:200.6.100.56 include:fidelizador.org ~all
  • s7IiVcqBaIZxV2ZpVvt5IyacSFM57fK5pSn+AKdZyOU=
  • _globalsign-domain-verification=IFH_OoAguyWrf66Lw7G_c8ezqoWhZmCQENEMMwvBBE
  • n7v1mb122wtwzyb4br41kp918dls92n8
  • google-site-verification=ylfqdGR2DtScALLnVLqvmIAeJTQ8X6GO9AQKoDJlPEU
  • 3tsvy15tl71hbxksl6bx77rvd6733m5x
  • _globalsign-domain-verification=YSw0Mr6ZlqRuaQa4OpQWMTiLY4EfmdmQShkLWI-k-z
  • _globalsign-domain-verification=WaN8qF9NOUZ1xkr9-_TrSjyiCRNqEIXlivFZvN9HIL
  • MS=ms88875169
  • google-site-verification=hEATyioV4u1AKmcfMZSke9R4IpgRIJNpGCF4v6K9mzE
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot