Group:
Dunghill
Discovered by ransomware.live: 2023-09-26
Estimated attack date:
2023-09-26
Description:
Robins and Morton is a company operating as a construction firm. It specializes in planning and design, construction management, multiple delivery methods, self-performed work, and green building. The company serves healthcare, government, and commercial markets. In the past ten years alone, it have completed nearly $10 billion in projects. These projects vary from major new hospitals and complex renovations, to hospitality projects and a variety of other commercial work.
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- robinsmorton-com.mail.protection.outlook.com.
- zoho-verification=zb31984692.zmverify.zoho.com
- 1password-site-verification=APQIEJEFSNA5FDXYXTRFGJXKUU
- b4hkig1c5n3krkmktrv6rhrssv
- jamf-site-verification=xOaW7XwRxFumdYqpflYt0w
- google-site-verification=vVP6o8E87jlnUBumTB2ifZ-PTD1JZcU3YX2-lCITDd0
- rj0eo8dla27p5fbl12765e8785
- v=spf1 include:spf.protection.outlook.com include:spfa.cpmails.com include:spfrerouting.xink.io include:spf.zohomail360.com include:mailgun.org include:relay.kinstamailservice.com ip4:23.251.231.52 ip4:3.209.178.232 ip4:23.251.237.159/32 ip4:23.251.237.16" "0/29 ip4:3.251.237.168/30 ip4:23.21.109.197 ip4:23.21.109.212 ip4:147.160.167.0/26 ~all
- 6n2mkashf3ivs02ruc5oqu8gpd
- jamf-site-verification=JuAZlNIgLsnb4KLaXIH6SA
- anthropic-domain-verification-44wnnt=qXBQKMPXkUK4pTxG7sZIqRDXs
- 2GLNR550MNTDD1s1zdjbPJmiY/a71tv0e/7lLvl1gkC5WA+pzRZQDDnF4q5pG084HFo3LO21BRh4HYb868gdnQ==
- openai-domain-verification=dv-OFZY1vdtzFG1iX2hIy2FR0uK
- sd10rc5dhm34h3rjo05he5uj7j
- docusign=5322d609-2f99-46f6-a695-a48052182ee6
- facebook-domain-verification=1fr0dey3ez3mx7u32aq09ox38kg57u
- apple-domain-verification=g3mlSIeBVPYqcnmx
- 2k28rr1kv9flkan4vee41sjgb2
Cloud / SaaS Services Detected
Apple
JamF
Mailgun
Zoho Campaigns
DocuSign
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.