Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Ropertech.com & Vertafore.com

Group: Dunghill

Discovered by ransomware.live: 2023-09-26

Estimated attack date: 2023-09-26

Description:

Vertafore is a Denver-based insurance technology company. It has developed various software for insurance companies, such as content management and workflow software, insurance knowledge base, data and analytics. It's insurance management software solutions allow participants in the insurance distribution channel to adapt to an evolving insurance industry by efficiently scaling their businesses through deeper access to information and insights.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • whoisrequest@markmonitor.com
  • abusecomplaints@markmonitor.com
MX Records
  • vertafore-com.mail.protection.outlook.com.
TXT Records
  • Dynatrace-site-verification=e0dcc48d-84ea-4dce-9eda-2602ab011d3c__h5bte1erp9e7uta0t5tjis8ocv
  • openai-domain-verification=dv-D1zDAmuOofvDtryk6SchLith
  • mgverify=9ea88f6f1ba49249c38bd380b3ee6be7dfe0b8c50b35df49daa9e61f7bacd69f
  • _globalsign-domain-verification=Pn7cqpa_6fS7ER93RwIlAU1sw42VBmYuRFvjg8geYu
  • northpass-domain-verification=8b1604f051ab245678629ab7578599a3
  • docusignguid=8751e97d-290b-422e-b01e-523c867be733
  • miro-verification=53969a8d4c0b8c35417bd4c31708527a9b34fdf3
  • 00d41000001hfqrea2
  • northpass-domain-verification=b097424f71576fe70396b81187c4c9c0
  • MS=ms29002745
  • SvaV1JBvjKAbUdI0+lH72mCyPelU0iD30Cu6n3fHx/wcpWP9vIOuYMmBKKZmEKI2Gmd2qjJ61WCTItMJPxSGFw==
  • northpass-domain-verification=426e6639ce08ff4ff2240e9dd63e43e4
  • apple-domain-verification=jcH2a1vKNmjzgGjr
  • hcp-domain-verification=073195eab8cc03ba9193d9e98986851ad12945701b4774d1799bf6197a67e3e5
  • v=spf1 ip4:63.128.102.0/23 ip4:8.42.62.0/23 ip4:205.216.28.0/23 ip4:192.28.152.166 ip4:199.15.213.62 ip4:199.15.213.63 ip4:206.51.252.60 ip4:3.226.105.254 ip4:3.214.248.80 include:spf.sircon.com include:spf.protection.outlook.com include:s" "pf.mandrillapp.com include:sent-via.netsuite.com include:spf.salesforce.com -all
  • reachdesk-verification=brwkhFHCCqooF9YiucIfIUZf5x6cqgdvBlR83cXCZwp8VdUQpa1oA1H6qzrgJg0E
  • anthropic-domain-verification-9ayanx=T17ICUZVwIVGT0j9QoucXnmrU
  • jamf-site-verification=1ZcQHprz_lzVEaU-NvrySQ
  • northpass-domain-verification=4a854794987ace9b56be2a75bbf52c76
  • cloudhealth=c21ba854-43dd-4edd-9f7f-3fd834bf5d23
  • google-site-verification=hh9a-bogXPaaoQSgOtRKrf6M522wpoNcN2667ktxQcQ
  • google-site-verification=es_uWmbigSBubH5tVq80Gfb5CBG8HABGJuLFt_jmIHI
  • google-site-verification=LR-a83fUI1W00_kPfK95qKqkFx8THvyXOmsBB8sOIwM
  • adobe-idp-site-verification=6eb77170a101ac6b24135dd60298dc83981bf7905365df6a08c7d6d6c2d9133a
Cloud / SaaS Services Detected
Adobe Apple Microsoft 365 Salesforce Miro JamF

Leak Screenshot:

Leak Screenshot