Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Group Health Cooperative - Rev 500kk

ghcscw.com

Discovered 2024-03-09 14:42 UTC
Est. attack date 2024-03-09
Country US

Description:

Patient and member data (MRN numbers, SSN numbers, patient ID, DOB, telephone, EMAIL, residential addresses, information about visits, medical history, various Patient Forms, CLINIC NOTE, scans of diagnoses and examinations with personal data, results of various laboratory tests and Lots of other patient information. Financial documents (balance sheets, budgets, PL reports, audits, statements, transaction reports, cashflow, presentations and many other important financial documents) Employees (ssn numbers, residential addresses, DOB, mail, license numbers, scans of personal documents and much more) Partner database, contracts, NDA forms, I Working documentation (drug db, presentation, reports, various government letters/reports and much more) SQL databases (patient database, employee database, participant database), mail correspondence.

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • ghcscw-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • docusign=ffe98125-c5a4-414d-b2bc-e653f1d67459
  • SSq87F/MEp66QdB00A6itMI7R7gnf6uDQscp5SyGxjA9/ybYyjvLp5lq6ttVXUP48dm8g4R5xe1pYJoW1+sAdQ==
  • MS=ms53421063
  • grqx76k2t5xj7kc1ym06vyt8kg1v7r64
  • XTmnLbkxHTQ_EGs-9aphw2B6ZUARjifqJAJ1Oc8tlGA
  • hhd2fq080bvhqjsty2rb6221yz77b48l
  • pp359fdyjc96h5s0lnzfy0g2qckkdmrm
  • _xh13ce7n7dpxu4est0u0splwdiq01mw
  • _7c8mgxbnama32306l85u6dv972mm624
  • v=spf1 include:spf.protection.outlook.com include:dayforcehcm.com include:spf.mailjet.com include:milliman.com ip4:75.141.38.45 ip4:75.141.38.242 ip4:147.202.206.1 ip4:147.202.206.104 ~all
  • MS=B0A89A3C0E4E9558E4FC70A571B31D0A74D1472E
  • apple-domain-verification=XTmnLbkxHTQ_EGs-9aphw2B6ZUARjifqJAJ1Oc8tlGA
  • google-site-verification=luCInRK9F9Nfl0mbFtvXNJQb08HSIqTgqLDsSC4ag10
Cloud / SaaS Services Detected
Apple Microsoft 365 Mailjet DocuSign

Leak Screenshot:

Leak Screenshot