Group:
Akira
Discovered by ransomware.live: 2023-06-23
Estimated attack date:
2023-06-23
Country:
Description:
Perpetual Group is a diversified financial services company whichhas been serving Australians since 1886 when it was established as a trustee company by a group of businessmen. The information about the Australian this group served will soon be available in our blog for everyone. 700GB of databases with highly detailed business information in total.
DNS Records:
The following DNS records were found for the victim's domain.
- mxb-006f9101.gslb.pphosted.com.
- mxa-006f9101.gslb.pphosted.com.
- t76gmynhd43t7wnryx7jtmnx1mbmzq8m
- v=spf1 ip4:52.1.235.217 include:spf-006f9101.pphosted.com include:_spf.salesforce.com include:spf.protection.outlook.com ip4:136.147.139.117 ip4:173.203.6.131 ip4:203.10.25.254 ip4:203.10.25.0/24 ip4:203.10.31.0/24 ip4:52.20.208.248 ip4:5" "2.113.66.207 ip4:23.23.239.161 ip4:54.243.244.199 ip4:52.64.111.139 ip4:192.28.150.224/29 ip4:192.28.152.136/29 ip4:199.15.213.48/29 ip4:199.15.214.32/27 ip4:199.15.214.192/27 ip4:199.15.215.64/27 ip4:199.15.215.224/27 ip4:13.236.96.33 include:spf2.perpet" "ual.com.au include:spf-005e7502.pphosted.com include:amazonses.com include:spf-au.iress.com -all
- MS=ms28606676"
- _vynhjxa8bwti7alxontg1hy770dd03a
- wrike-verification=NjQ0ODQzNzphMWVlNjJkZmQ0YWFkZjFjOWJkNjFhNmU3YjNmYjk2NzIwNWNmYjk4NTI3ZDExOGYzYWI2NjJjNTJmOTA4NjA2
- google-site-verification=W0cfMUvZEuG8ah5PrieZqrswHaij6jWpgxHjJwm3XVs
- miro-verification=35cf1619643e45cb2364b1dbbc1393e7380dbfcd
- 0p2wkh4hdlpz0rtv5tgwtt8nn5mmswb5
- TGnE3lM/U/1zqk/OYuzTSpZxAIWnPi8EHEn+5li8OOeX7vJkue/+MOY6/kV5ZW1OLmT8KQZBO91IV5TKat35/g==
- axQJt+LyVSgV5T/iH+uN7QRDYzq0QXfe7IWoe68PejsSI0pHM3HJPP6eXMhUJRUDHWOTtrQ6KuokqR+nu0Mryw==
- anthropic-domain-verification-xjdp05=aTB4txswdA3SEPAmJiyLFfXTP
- _spcfqc85xl6m6ubyz1ik6rcprroip0r
- docusign=1be22657-48a5-4358-9a36-0e5580c2ab1d
- _7ukwbzy2zc8gtu0t8j3rnv1hp4hlgu3
- _zv99i5b5jcewtimuacj90ykmckz1aiq
- 8tf4ygrt9mm8qnzq2wytq3gnxdhblkf3
- P0E0R34438
- spf2.0/pra include:amazonses.com -all
- docusign=4199953e-a8f8-40d5-b05c-9401b98d76d9
- docusign=66d2f72f-8d83-4fe0-917d-2b5f137e3822
- VW9dHVf70n5vVAjqk94z3ACqffEvrOjWvOLDApl0aGIvWyz9fXzEmH2cKcKoZEBr1ZCLDXlibZwcHL71sCNP9w==
- atlassian-domain-verification=byVBqPkFjGYwqWtXwCtYhB2/hsFIERVOWByFsQbX5AYDGnoLQIDGy/zhkqdwxkSK
- docusign=88c56b67-321d-4336-b7a2-b3bb211b5efc
Cloud / SaaS Services Detected
Atlassian
Amazon SES/WorkMail
Microsoft 365
Salesforce
Miro
DocuSign
Proofpoint
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.