Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

National Institute of Social Services for Retirees and Pensioners

pami.org.ar/

Group Rhysida
Discovered 2023-08-12
Est. attack date 2023-08-12
Country AR
City Buenos Aires

Description:

National Institute of Social Services for Retirees and Pensioners

Infostealer activity detected by HudsonRock

Compromised Employees: 301

Compromised Users: 10428

Third Party Employee Credentials: 51


External Attack Surface: 144


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • correo.pami.org.ar.
TXT Records
  • _ghcej3mcfdsry6ftq1ies2cleybr1ud
  • tmes=117fee843203e7d4ab2bfc3d1e81fc03
  • google-site-verification=PdxZPaZ33fsoSBWaW_65VDLEvBHTTw0ijadE3P0xVaQ
  • v=spf1 mx ip4:179.0.4.12/32 ip4:179.0.4.93/32 ip4:179.0.4.94/32 ip4:179.0.4.95/32 ip4:179.0.4.96/32 ip4:179.0.4.97/32 ip4:179.0.4.28/32 ip4:179.0.4.42/32 ip4:179.0.4.246/32 " "include:spf.fromdoppler.com include:sendgrid.net include:proyectos.pami.org.ar include:spf-us.tmes.trendmicro.com ~all
  • Servidor DNS: PAMI.ORG.AR / INSSJP
  • _knir1p8rtg24wn2a592jo2jhnwmz6w0
  • _2sg4fm3kkejsojcaeta1eot2lf0tcws
  • _qxkzo6vu8cage5n002w4uz3gpkl1klr
  • _j0339bj3mizqi12p246g9ateo4kzryp
Cloud / SaaS Services Detected
SendGrid TrendMicro