Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo DARTMOUTH.EDU

Group: Clop

Discovered by ransomware.live: 2025-11-13

Estimated attack date: 2025-11-13

Country: US

Description:

[AI generated] N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 7

Compromised Users: 998

Third Party Employee Credentials: 46


External Attack Surface: 99


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • dartmouth.network.services dartmouth.edu
MX Records
  • dartmouth-edu.mail.protection.outlook.com.
TXT Records
  • atlassian-domain-verification=yxVV9fe5fSJIOzrg/2jvRHYUZqs2H7a30Ix6hYxrYddhWzGtHri6KrAo7AbrBPWh
  • wrike-verification=MjM2MTM0Njo4Mjk3MDEzMGRlYzA0NGY5NzExYTIxNmZkODY3NzEzOTg3MTg1ZjEyZjYxMWY3MWE1MjZmMDBjZGRiMTc5MTcz
  • facebook-domain-verification=mw3sr9iiez87clr5be0mvqfrfv5pdq
  • amazonses:qibTWZp9Z8XB7Gtv1R4HLgdDjfPqFTY8Xz2g4CxP3DY=
  • r8kFztnc9M0pNIuK8e6W4oNnwPlJ69yd1zxyw66fnYCgdZnHH39dTwkZhDBPicE7NXXsez+cln83J5cxucOv5g==
  • google-site-verification=hKllXvHgM-6kI7rUysmZs8XkZ8WYMAeZfm6u0A-Xkms
  • rqz9jf4yv02sppyr211kbm1btbhz6v7b
  • openai-domain-verification=dv-RtsKPAcMrS3Flc99KVWLzqvf
  • boIuOYRNm52O4nm+5cmx03iN8/aS/0bhvilx2PXCHm5CPCBhVNRYM7R02oWvwLtM8nNOnKaBETibgGYb3xSTiw==
  • atlassian-sending-domain-verification=5d2b1e4e-53a2-41d8-9614-e1924cdde783
  • duo_sso_verification=1molDJXEuY6lYJxqwmYsRBhbi1YwLKsf3P08ctWCcJcJV7NRzEwF9chzEw9NmgJI
  • atlassian-domain-verification=o62Mi2eR+5iVieiLtkYit+SwOzBX3nCYUa0Dmrho8ssDgmmG27mklW5CxyOfc3/x
  • google-site-verification=bkySuymASSMWSDwJS-imzROnABz01fMYdYkOrsfRQNo
  • airtable-verification=b05674e8a09dd5e6c951dd312e88f950
  • logmein-verification-code=d911c3c1-eeb1-4c38-a55e-da6f189ed059
  • bw=RY8AsLPKQdaN7c8rjN6ls8fK6rrBABwOZGtym6dLLTvb
  • v=spf1 ip4:129.170.137.224/28 ip4:158.247.30.34 ip4:143.244.92.221 ip4:206.107.42.254 ip4:209.143.65.64/26 ip4:72.4.236.9 ip4:198.187.196.100 ip4:64.72.147.23 ip4:23.99.180.69 ip4:64.74.237.230/31 ip4:216.147.212.20/30" " ip4:52.43.50.148/32 ip4:52.86.188.131/32 ip4:209.143.65.64/26 ip4:168.245.25.116 include:spf2.dartmouth.edu include:spf.protection.outlook.com include:_spf.google.com include:_spf.qualtrics.com ~all
  • atlassian-domain-verification=FKEPBB7b61BuK3b/O0/7YFIGZVNRC/HIYeXEbm8gA59wkRo3Rbk/7Punjy73rrLH
  • have-i-been-pwned-verification=3be50d4794d105ef5933f0a21cb9a79e
  • TXT" "dartmouth.edu" "ecostruxure-it-verification=6d15177b-1edc-460a-99ab-093745c902af
  • 137342631-6189184
  • apple-domain-verification=ySlaII1ZaW4H3sDj
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail LogMeIn Cisco Duo Have I Been Pwned

Leak Screenshot:

Leak Screenshot