Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo First Nations Health Authority (fnha.local)

Group: Incransom

Discovered by ransomware.live: 2024-05-22

Estimated attack date: 2024-05-22

Country: US

Description:

The First Nations Health Authority founded in 2013 and headquartered in West Vancouver, BC, is responsible for planning, management, service delivery and funding of health programs in partnership with First Nations communities in BC.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 21

Third Party Employee Credentials: 0


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • Please ask the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Other contacts of the queried domain name
  • abuse@godaddy.com
MX Records
  • fnha-ca.mail.protection.outlook.com.
TXT Records
  • ygk6zsht6rqjppd7jr047st9wz5yml3h
  • v=spf1 ip4:74.3.141.153 ip4:204.89.57.18 ip4:167.89.72.113 include:spf.protection.outlook.com ~all
  • 8wqO7Ngi+cX7lHruar34yvUpLXL/c8b1iFI1NIjiNQt1WtJkqzxAZU1u/0Abl6cnuuatc0lNus3wcTKY482wUg==
  • v=msv1 t=6B25D1F9-663B-4488-BFAF-205F158AF9AE
  • apple-domain-verification=am4oK7TyzX0dlNxL
  • _5607yl0bm7ipaegx8wd67qqf0ndgrje
  • cisco-ci-domain-verification=aa364ad0582f37cc9841b760432a8162e5b73656fb155ef921dc8de57273998
  • MS=ms89444843
  • miro-verification=e148561c1f3bbf7a8fe33e4d536fbfb9f499f3f3
  • bf83njk14hd8p3d1pu9lcobnbq
  • bcn=3113F46E-8B88-11ED-8D85-63B3AA1036FF
  • qwr24730c4ctwsfh3tx6vjgbsn0p1nzs
  • _4gyqmr1r0zc469t6tnuwxmfn3f3pp7t
Cloud / SaaS Services Detected
Apple Microsoft 365 Miro Cisco

Leak Screenshot:

Leak Screenshot