Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Parathon by JDA eHealth Systems

jda.com

Group Akira
Discovered 2023-08-01 17:58 UTC
Est. attack date 2023-08-01

Description:

Parathon is a full-scale healthcare Revenue Cycle Management dataintegrator. We're almost ready to share the 560GB of data we'vetaken from their network . Contracts, employee personal information, and confidential documents will be posted shortly.

Infostealer activity detected by HudsonRock

Compromised Employees: 38

Compromised Users: 51

Third Party Employee Credentials: 67


External Attack Surface: 64


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • mxa-001c4601.gslb.pphosted.com. Proofpoint
  • mxb-001c4601.gslb.pphosted.com. Proofpoint
TXT Records
  • ntr2b602mn89614t49qhx2vr0knxzpqf
  • 1vjxzqv9rsylc0z7xdwtwmh7yt7s2x2g
  • apple-domain-verification=RUbDnOBtI0FujG9r
  • beWeKetr3
  • drift-domain-verification=57a27043f29fab2ff72773635620249bb93022a6ddd690ddd3663adc8b3b26a3
  • rovag_verification_token=24812EA332BA4F2E87069972005358C6
  • docusign=875de14b-6cc0-4a51-a990-b01b625bbad6
  • ciscocidomainverification=26c0706c1ec568368c98006b357acc6ee131169c7b49973db72c4357e79efb11
  • 5k0vsws9jjh1jqrw3nwzbfsmm7msjx33
  • f73rv57cyfmfgzwx5cwfrql7lzn3zbt8
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • yon4x3KjKcx8uy5RVb7eJTx5vyXUychx5Q8wy8gDGk7pOd51mzAHbeqpiWJtsvd0MMfCAs43p1fQaOBO4ALa+g==
  • qbz76x07dr88dlr3x9fkptj607b82nrv
  • smartsheet-site-validation=Ioy1rPb0WkDKGOYHrFhXkYgWj7574OPi
  • x+6ae8BHEh3x/fR7SbJFFB7MqQ41Vyy/TzSLeNY2H18=
  • google-site-verification=hBOHDFUQ9rma0TH51DpdkNPRQYtHT_ZdSbO-_4Ekxjk
  • docker-verification=732d8b89-efd6-40a7-b6e0-8fab8c2ae16c
  • _2fflh0jur6sztn3v2yah0kezmbui6aj
  • google-site-verification=JYzBFi4xS5gU3f78cwCYZGgsrm_73d4YqxAD6vyUbQU
  • google-site-verification=tl3KpcVtT7so8hihLhxqdOuil4JUOeBgKpztXNJQTh8
  • atlassian-domain-verification=mFx8i8okG0NgtKhdXGbi8ew2/CCkep8V2MmKRXudwugokYY7Q8NYyS95UabMrmzg
  • pzl7vzdfm13m7wmrtnw555dpn2r8y211
  • anthropic-domain-verification-x91cn8=Gjp9lCV6WrqPUCT1EyBQUjlTB
  • google-site-verification=lrUd_umK6LFDPtwKJhYfwd0X_RXp_CLgUEG5If37la8
  • _dv21xdejip5o78zh5quo43fpw3n9mvn
  • ycl8bzqsdbw4qjwt81h0ktt6s9v9phw7
  • t073ljqhfn8jckvhfr1mh487b11qwb11
  • google-site-verification=POoekgajcOsGzO2DKply84fijCX4P06QFAIX5iiMmWc
  • 8k4T7dPgNzRIrhx3eiLEab5XtBRGNIgbQK5yZlqjB0+a05JZqmztdQN4NdCMsn5rvkgVZaq/aYTiUbQscFdDFQ==
Cloud / SaaS Services Detected
Apple Atlassian Docker Anthropic DocuSign Proofpoint