Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo State Farm

Group: ransomed

Discovered by ransomware.live: 2023-08-26

Estimated attack date: 2023-08-26



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints markmonitor.com
  • home.auto-eisadmin.399n00 statefarm.com
  • whoisrequest markmonitor.com
MX Records
  • mxb-00104b02.gslb.pphosted.com.
  • mxa-00104b02.gslb.pphosted.com.
TXT Records
  • confluent-verification=b1fc325f-ebd4-4bed-8817-e323930d2701
  • confluent-verification=508ddb67-6339-4d36-bd1b-4c8e7f35dff7
  • yahoo-verification-key=+n1JpZryZZxmOpQjafQZfzBN+IpCelY8XUw9m1enSTM=
  • jamf-site-verification=tk1Xj2RLXXAeLYAmiY4eew
  • vertexinc-cloud-044ecbee-26d4-4245-a073-ae4f7937d0f4
  • cisco-ci-domain-verification=3703a183b39432db5ac302eb2d603e009e5dab42a5fb0e2d0e63794feb7b5fad
  • l4cd3yXILz0DOwXK6dTOZQ
  • infoblox-domain-mastery=37c4f2bb9e2c3c7895ef3a08ab324167ca8012adda6d9365850fd5dbc41edac3c0
  • unity-sso-verification=869f7686-8120-414b-b4cb-81acf21eb143
  • liveramp-site-verification=0S7n5roiw5pwuyFp0nPtaKD1vji7s9njFHb_SeXhgJo
  • Dynatrace-site-verification=2c1d3749-4815-4e2f-9e2d-548f91ad6675__ck4kaq57tgo2i40i4qcnml4tn5
  • v=spf1 include:spf-00104b02.pphosted.com include:spf-00104b03.pphosted.com include:spf-00104b04.pphosted.com ~all
  • google-site-verification=dBkEsjv9URgEpuC2J4Ec9RWLreVDCPw4g3kukgD4nVI
  • _keb28hftnm8r1juahvq669ccy34rxhs
  • google-site-verification=WHICQV05cGSovIYMhfCdVR8sDIt6ien3H73lzHfEzhs
  • hover-site-verification=ZxnVaO8KLt
  • confluent-verification=d5729a69-fe17-4b01-b30c-ec77c4329c83
  • google-site-verification=mfVHn7eESOGj8ClMbOEOZ4OBVocXXU4dknQRD5iem2Q
  • google-site-verification=HIL7kX87WOVaTsTCdULCXDz4abDh9a7dMhfcChvHn-w
  • dell-technologies-domain-verification=statefarm.com_90ab7254-abce-409a-9871-e57765ee06e0_1722089303
  • vmware-cloud-verification-ebcaad8f-d80c-4937-a5eb-beae0ac7647b
Cloud / SaaS Services Detected
JamF Cisco Proofpoint

Leak Screenshot:

Leak Screenshot