Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo piramal.com

Group: lockbit3

Discovered by ransomware.live: 2023-03-27

Estimated attack date: 2023-03-27

Country: IN

Description:

The Piramal Group is an Indian multinational conglomerate that has presence across various sectors such as healthcare, life sciences, drug discovery, financial services, alternative investment and real estate



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse-contact publicdomainregistry.com
MX Records
  • cluster1.us.messagelabs.com.
  • cluster1a.us.messagelabs.com.
TXT Records
  • 9bgr2l9qcgckzmvks1c4ywq9cs1xlhvwqnkwywzptq4n7xwdg35xkvhflmr4sqpm
  • _hccwclhgt8pqzsgy27012ruzayu5fuc
  • _igvndez95vley5kgjf5hof0b3gu7rjb
  • docusign=957e5152-f188-4cc4-9876-698ab8915563
  • _tp4o7300yivst0ehkn4h5jx49duzlgw
  • _td1v7tmdhga12syzbl4t4qscuuex9fl
  • _pxgjgz58ukpwo03alzae93anpjwcn4e
  • _9kxa273t61c5682lzftq58m3l6i5row
  • MS=ms88740911
  • _0ln8mme0yqrz6x8itvu0x6dg32cys93
  • sga1nmah7j904tbkh583bq5qsv
  • glw1nnk4b0hc6ks03wg6lyq7xmrzp2pk
  • _bho896xzflc07b6gbilqx33r7equwz9
  • _6g6jh8sz5hqr67ex9eb86f2rlxvs1zi
  • _hgnnly1sf5uxfvuvrza529m2ji4ou7e
  • _s3qaq4iou0ha29hskzj8hvd13sel5sy
  • npts6juinsaqqnj6d2us157fel
  • box-domain-verification=da206667aec126d2cb8cbc48e409ab3f18b1763146b0fac29eeff50aec65ce99
  • _hwkm5qgeldqrznbuzdsctmdnd92xafn
  • _fxifsckohcgryvmt96pa1u5ro3b0lmo
  • _fl31jtrwcjvmipunkws0fdg6fhxzfjj
  • _knw92q4l7h09j6gh04g1ill4jn4vj7y
  • 571mpvccxhgbf1r6tykb0whd8wtry1kr
  • v=spf1 ip4:180.179.157.242 ip4:49.248.213.236 ip4:122.187.208.12 ip4:122.187.208.13 ip4:49.248.213.238 include:spf.messagelabs.com include:_spf.salesforce.com -all
  • _efhisfndxo2dexpa4gddk3fc89l2qa3
  • _v9i8wrl24v87v26zv06j7mopnkdg3lz
  • google-site-verification=DRhZMn0eV_RMUkqsjEi1g$S668vK@VStgJDx86uWTAc
  • _1bl11nq51to3rxdqlncimulm8h1mptf
  • _2zzelgeof3ln06iw1q56bogs8xu2ske
  • 7jr8yd81qyfnkc77h734yqygmzv55ps0
  • MS=ms26521648
  • mongodb-site-verification=e3r849tIqpqrfHcQ4s3FwupABOCozhCt
  • _7d4thy7ry2tmk2y51j71donc2wtyyh1
  • 1q8lr7gmvyckyhppc2kcwfzyhjr6pqff
  • _85jnkjtkqf3r7ba89bpakmptxxzk1ga
  • _zhnlbltlt65zd3nlkzsnasm2b9vo61p
  • _b9qlpq417zx3io068304f6t91grg45m
  • _4ubelil44iz3rdxztuk27jn2gdhki0h
  • ngczzdvzpvlgnpz1r385gh9y6mvhdwjs
  • docusign=3099f58d-8dd3-43d3-a4e2-45c0ae5ad287
  • d8MT+DM7UOp1DnMXXHIA3muVted4tj0hujBVl57JIi8=
  • google-gws-recovery-domain-verification=60621655
  • docusign=47e7f898-1143-4df0-86c1-9612bf4a9517
  • _9iinfm6zi2jxq434h5vvaj3dwcgj7sw
  • +CYZ+V/+G18f7+tldkuxMCuCfJso1pNUy6OPjgD0Fmegcc9mMADjnT0nzh2219J5vSH2BGLOWlsopJZK6Q+Sfw==
  • _fs9z4jntzeprvum4sahp3kkqulf1ft8
  • YJgbltn+c1A6YSvaW72CENyUUgtrkHVO7WijXGP4G0w=
  • _vqnbx513ffcqcmtdbdyn0qz0qnx812y
  • mongodb-site-verification=XL2399xzwNnq10noWvMAkPqwxkQgCJTr
  • docusign=448338bd-1868-466d-b43d-33d01ea836b3
  • _fwlvyvcx4njt218zof69r9voi48xlm2
  • _byglksxoof3araoyado6kcvm2m234js
  • _7d4thy7ry2tmk2y51j71donc2wtyyh1
  • hdntlj07cccha8jqb8ugipecj0
  • AA4549E851FAF76266402943D8BD96F2967FB2D7ECBA67C419EAB1D51503381D
  • MxQB2j4f46P0JE1GvoeN4/60qo7lgHqkN3WAr89PQXQ=
  • xlk66xwc2fy1cdyjgvhby7lx6sqpcmpr
  • _lyh6bmn6rki617kcvtyaoneuqd2vvol
  • _3sa45tykjhsgsbe7awdja7lphz0eoro
  • atlassian-domain-verification=aKpzvDlyeXZ0qbBzCG6aaTsyw6jjwMmpViFExa93CREifwWLizff67bilazjDmyD
  • Dynatrace-site-verification=8566a7bb-11f7-461d-860f-dfdef38ac68f__c1j1ij56gm77031g4ab1k4a4nq
  • google-site-verification=XEghAahSCkWv3QXMCBFEmCAVEjvbU--gKJr23YsqNAU
  • _7edav9g624wk17nzkk3o249rguwcet7
  • stagingnewpiramalsite.azurewebsites.net
  • _waww03f3ntrkd645e1x7if81akxd54z
  • _87f9j7amaqfqq5rzksze8a98ikt12e3
  • _10s25em77syodzku1nk9h6p36u2q7jz
  • _efau1cjq4akcx2zqkkxjq6im17ycub8
  • _1y0owveiq1qg8ey3bohriwbal015jzh
  • _7f4r6shhzydut5eec46nq84b0snqap8
  • _ii0onc1157qcgpbrvwxmfu9447s5r1m_j6osp7m97228u6nnundrv74p0yuixw1
  • amazonses:q4UTCg7lOYVnGLhnA3QdMvsfGoQBCDwQd7VsJ1MzVho=
  • _i5c1lr4yjj2nxyusnp7q5mmiq5stlr9
  • _68k1kyh3vvw5yvemv5fmiavbmua3x18
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Box Microsoft 365 Salesforce DocuSign

Leak Screenshot:

Leak Screenshot