Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Perpetual Group

perpetual.com.au

Group Akira
Discovered 2023-06-23 15:49 UTC
Est. attack date 2023-06-23
Country AU

Description:

Perpetual Group is a diversified financial services company whichhas been serving Australians since 1886 when it was established as a trustee company by a group of businessmen. The information about the Australian this group served will soon be available in our blog for everyone. 700GB of databases with highly detailed business information in total.

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 13

Third Party Employee Credentials: 8


External Attack Surface: 11


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mxb-006f9101.gslb.pphosted.com. Proofpoint
  • mxa-006f9101.gslb.pphosted.com. Proofpoint
TXT Records
  • axQJt+LyVSgV5T/iH+uN7QRDYzq0QXfe7IWoe68PejsSI0pHM3HJPP6eXMhUJRUDHWOTtrQ6KuokqR+nu0Mryw==
  • anthropic-domain-verification-xjdp05=aTB4txswdA3SEPAmJiyLFfXTP
  • _zv99i5b5jcewtimuacj90ykmckz1aiq
  • MS=ms28606676"
  • 0p2wkh4hdlpz0rtv5tgwtt8nn5mmswb5
  • docusign=88c56b67-321d-4336-b7a2-b3bb211b5efc
  • docusign=1be22657-48a5-4358-9a36-0e5580c2ab1d
  • atlassian-domain-verification=byVBqPkFjGYwqWtXwCtYhB2/hsFIERVOWByFsQbX5AYDGnoLQIDGy/zhkqdwxkSK
  • _7ukwbzy2zc8gtu0t8j3rnv1hp4hlgu3
  • _spcfqc85xl6m6ubyz1ik6rcprroip0r
  • spf2.0/pra include:amazonses.com -all
  • docusign=66d2f72f-8d83-4fe0-917d-2b5f137e3822
  • docusign=4199953e-a8f8-40d5-b05c-9401b98d76d9
  • VW9dHVf70n5vVAjqk94z3ACqffEvrOjWvOLDApl0aGIvWyz9fXzEmH2cKcKoZEBr1ZCLDXlibZwcHL71sCNP9w==
  • P0E0R34438
  • wrike-verification=NjQ0ODQzNzphMWVlNjJkZmQ0YWFkZjFjOWJkNjFhNmU3YjNmYjk2NzIwNWNmYjk4NTI3ZDExOGYzYWI2NjJjNTJmOTA4NjA2
  • google-site-verification=W0cfMUvZEuG8ah5PrieZqrswHaij6jWpgxHjJwm3XVs
  • 8tf4ygrt9mm8qnzq2wytq3gnxdhblkf3
  • TGnE3lM/U/1zqk/OYuzTSpZxAIWnPi8EHEn+5li8OOeX7vJkue/+MOY6/kV5ZW1OLmT8KQZBO91IV5TKat35/g==
  • miro-verification=35cf1619643e45cb2364b1dbbc1393e7380dbfcd
  • _vynhjxa8bwti7alxontg1hy770dd03a
  • v=spf1 ip4:52.1.235.217 include:spf-006f9101.pphosted.com include:_spf.salesforce.com include:spf.protection.outlook.com ip4:136.147.139.117 ip4:173.203.6.131 ip4:203.10.25.254 ip4:203.10.25.0/24 ip4:203.10.31.0/24 ip4:52.20.208.248 ip4:5" "2.113.66.207 ip4:23.23.239.161 ip4:54.243.244.199 ip4:52.64.111.139 ip4:192.28.150.224/29 ip4:192.28.152.136/29 ip4:199.15.213.48/29 ip4:199.15.214.32/27 ip4:199.15.214.192/27 ip4:199.15.215.64/27 ip4:199.15.215.224/27 ip4:13.236.96.33 include:spf2.perpet" "ual.com.au include:spf-005e7502.pphosted.com include:amazonses.com include:spf-au.iress.com -all
  • t76gmynhd43t7wnryx7jtmnx1mbmzq8m
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Anthropic Miro DocuSign Proofpoint