Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Parathon by JDA eHealth Systems

jda.com

Group Akira
Discovered 2023-08-01
Est. attack date 2023-08-01

Description:

Parathon is a full-scale healthcare Revenue Cycle Management dataintegrator. We're almost ready to share the 560GB of data we'vetaken from their network . Contracts, employee personal information, and confidential documents will be posted shortly.

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mxb-001c4601.gslb.pphosted.com.
  • mxa-001c4601.gslb.pphosted.com.
TXT Records
  • ntr2b602mn89614t49qhx2vr0knxzpqf
  • t073ljqhfn8jckvhfr1mh487b11qwb11
  • google-site-verification=lrUd_umK6LFDPtwKJhYfwd0X_RXp_CLgUEG5If37la8
  • 8k4T7dPgNzRIrhx3eiLEab5XtBRGNIgbQK5yZlqjB0+a05JZqmztdQN4NdCMsn5rvkgVZaq/aYTiUbQscFdDFQ==
  • qbz76x07dr88dlr3x9fkptj607b82nrv
  • beWeKetr3
  • yon4x3KjKcx8uy5RVb7eJTx5vyXUychx5Q8wy8gDGk7pOd51mzAHbeqpiWJtsvd0MMfCAs43p1fQaOBO4ALa+g==
  • 1vjxzqv9rsylc0z7xdwtwmh7yt7s2x2g
  • anthropic-domain-verification-x91cn8=Gjp9lCV6WrqPUCT1EyBQUjlTB
  • _2fflh0jur6sztn3v2yah0kezmbui6aj
  • google-site-verification=JYzBFi4xS5gU3f78cwCYZGgsrm_73d4YqxAD6vyUbQU
  • google-site-verification=tl3KpcVtT7so8hihLhxqdOuil4JUOeBgKpztXNJQTh8
  • 5k0vsws9jjh1jqrw3nwzbfsmm7msjx33
  • ciscocidomainverification=26c0706c1ec568368c98006b357acc6ee131169c7b49973db72c4357e79efb11
  • apple-domain-verification=RUbDnOBtI0FujG9r
  • atlassian-domain-verification=mFx8i8okG0NgtKhdXGbi8ew2/CCkep8V2MmKRXudwugokYY7Q8NYyS95UabMrmzg
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • google-site-verification=POoekgajcOsGzO2DKply84fijCX4P06QFAIX5iiMmWc
  • docusign=875de14b-6cc0-4a51-a990-b01b625bbad6
  • rovag_verification_token=24812EA332BA4F2E87069972005358C6
  • x+6ae8BHEh3x/fR7SbJFFB7MqQ41Vyy/TzSLeNY2H18=
  • docker-verification=732d8b89-efd6-40a7-b6e0-8fab8c2ae16c
  • drift-domain-verification=57a27043f29fab2ff72773635620249bb93022a6ddd690ddd3663adc8b3b26a3
  • _dv21xdejip5o78zh5quo43fpw3n9mvn
  • f73rv57cyfmfgzwx5cwfrql7lzn3zbt8
  • google-site-verification=hBOHDFUQ9rma0TH51DpdkNPRQYtHT_ZdSbO-_4Ekxjk
  • pzl7vzdfm13m7wmrtnw555dpn2r8y211
  • smartsheet-site-validation=Ioy1rPb0WkDKGOYHrFhXkYgWj7574OPi
  • ycl8bzqsdbw4qjwt81h0ktt6s9v9phw7
Cloud / SaaS Services Detected
Apple Atlassian DocuSign Proofpoint