Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ahn.org

Group: lockbit3

Discovered by ransomware.live: 2024-11-27

Estimated attack date: 2024-11-13

Country: US

Description:

Greetings! Today we are posting here the new company, "West Penn Allegheny Health System .Inc". Company Description: West Penn Hospital, centrally located in Pittsburgh’s Bloomfield neighborhood since 1848, is regionally and nationally known fo...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 6

Compromised Users: 266

Third Party Employee Credentials: 11


External Attack Surface: 43



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
MX Records
  • mailgate.highmark.com.
TXT Records
  • google-site-verification=gdLTO5Eo8XBbZrpwA5WxBI8BtJ0fUCMiGwMi7Wdja9s
  • cisco-ci-domain-verification=444d9217636837affb0877ed0027d13e13252fb3e92f09b09e8336bb86753af
  • Dynatrace-site-verification=f340b346-3aa3-4e29-937d-7b57c9db5ea5__p8iv8v0jh4rccuij5040doq2ro
  • v=spf1 mx a:igate.highmark.com a:igate2.highmark.com ip4:216.235.196.0/22 ip4:216.235.200.0/21 ip4:205.139.104.0/22 ip4:206.79.6.0/24 ip4:157.154.7.0/24 ip4:167.164.7.0/24 include:email-od.com include:outboundmail.convio.net include:spf.protection.outlook" ".com include:_spf.salesforce.com -all
  • google-site-verification=hxrtWCT6_Zw7J5zKcuXj6ewFwnXvoBwT0Y6WlLXfqME
  • oci-domain-verification=Pp9cdzXTGI4WgEZNJLaHyuWpSWqTu2FPLrrHnLgv
  • wiz-domain-verification=e0d03410d4128f53961823f16299258a503c7bd8a67fd10c03316dc2553f6abd
  • MS=ms86469785
  • ai60lhjdeut1ejnuqjf3lg6u49
  • 6drQlFe7EQok8B77jYY/MpCPFIU2jhNpxfExY7ZsghO/5nYMaIpB87mDJPvi9GuD4FFgp+ur9gXuVw2bN+IESg==
  • apple-domain-verification=szfnv1H8OgtToY5Z
  • SFMC-LNyCEJrM8epcyQlzNEkeQUnqu0PKC0rXzGUfKphB
  • google-site-verification=zzgKEAN3lY6jN53GmPeXQ5lVVv2Bi9_pmWQQgQlDY1E
Cloud / SaaS Services Detected
Apple Microsoft 365 Salesforce Cisco

Leak Screenshot:

Leak Screenshot