Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Philippine Health Insurance

Group: medusa

Discovered by ransomware.live: 2023-09-23

Estimated attack date: 2023-09-23

Country: PH

Description:

The Philippine Health Insurance Corporation (PhilHealth) was established in 1995 to provide universal health insurance in the Philippines. It is a tax-exempt, state-owned and controlled corporation (GOGC) of the Philippines, subordinate to the Ministry of Health. Company came to the tor chat but didn't answer for the payment yet.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 89

Compromised Users: 29058

Third Party Employee Credentials: 32


External Attack Surface: 117



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • smtp2.philhealth.gov.ph.
  • mxa-009de301.gslb.pphosted.com.
  • mxb-009de301.gslb.pphosted.com.
TXT Records
  • MS=2B51A214B6E2B79CD3BB6B8B28CC88642CC7F589
  • tmes=bbd4cfeb80e77142c774618c1daa543f
  • MS=ms93633016
  • google-site-verification=_cH6D7cg1jTC4zBIWDC9Yww1o326kydX6nxrzDjIH2A
  • PHIC2025._domainkey.philhealth.gov.ph. IN TXT \"v=DKIM1; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvp5Bk5ysD96fcSfkNgp\" " "\010\"b96eDAr/58UDZVG4PU6VrYTnnBMiolG5FX8xIDTS7sjMzf66YMPFfnNalHG3i0ykmhXnWUVtSsARiSaDfQ9pSN7xYKWwU11lA6BYBL9Kh5tx29JuGC9fQg2995hpfLUC\" " "\010\"jQXoT4ZJ5MLTnLA+zslptq4so2+KqBNbWLgYfDhHRWtzJ3u/bb/f3mqjbJe1J/nY4xSp00xg2u1LumZvcze6AVW79hxFXQpo6j6vC+kR1fU8HeIKmJXLc8C5T3rXsJ+0\" " "\010\"1oFBoK632GZcnBCk0A/RPkDJSxy+lt0thGWa6FNj7NIec67y0KuBPMxniK3mzKK4pTwIDAQAB\
  • _globalsign-domain-verification=ETeG8I4BGZirF1cKzd5sAy8P-jdwxZRBePCB7RCNTs
  • v=spf1 include:spf.protection.outlook.com include:spf-009de301.pphosted.com include:_spf.google.com include:_spf.mail.yahoo.com ip4:121.58.248.221 -all
  • _globalsign-domain-verification=FhW5Fvj9ZGbA6qVIq5g16XwuHzorBkSozPr-xW8BKj
  • MS=ms31473208
Cloud / SaaS Services Detected
Microsoft 365 Proofpoint

Leak Screenshot:

Leak Screenshot