Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo TeraGo

Group: Akira

Discovered by ransomware.live: 2024-02-07

Estimated attack date: 2024-01-31

Country: CA

Description:

TeraGo provides businesses across Canada with secure cloud services, date recovery, and business grade internet. 45Gb of data willbe uploaded soon. You will find there lots of client agreements with personal information. Many files with financial information and everything that a provider can get from its customers.



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • ipnoc@terago.ca
  • compliance@tucows.com
MX Records
  • terago-ca.mail.protection.outlook.com.
TXT Records
  • hk3prfid7s6hrrs7g2c1inu0k3
  • 8u1/iSXQrjtqy4DRQgIkjhs8+/EGkWzx4PQFDa5IwClCHKmXTmxlfizhzrplxTwtTNrsPUPXEMFg0b2tCJdupg==
  • pardot503891=6b04203c20a9e43b6952252554ec46569bd3c05d443f959292465b5dfaf26066
  • eig0b8gncdsb1ii5ia7umshvd1
  • v=spf1 mx a:mail.teraint.net ip4:67.226.181.229 ip4:67.226.180.229 ip4:207.54.126.52 ip4:67.226.151.1 ip4:209.97.193.217 ip4:67.226.151.24 ip4:67.226.151.25 ip4:209.97.193.216 ip4:64.46.32.116 include:aspmx.pardot.com include:spf.protection.outlook.com in" "clude:amazonses.com include:campaigns.structuredweb.com -all
  • ou4g5ueehks4kcvl0q5lfrpfnm
  • a3m5o5v744gpo80t9hnp2rji8v
  • bw=Jkz+6ZzSVvKl6SvGr+oKRxYT31R6glVZTp3kiXrO+QHh
  • atlassian-sending-domain-verification=2f401ba0-5f3e-4b7a-8839-837eb7b2ae5f
  • atlassian-domain-verification=xRyB0exaC2O22DI96BFtjBIWfjMp0dEKMAuOEhYqqLDC90Vn1M4zG5Uj4L6Lm7Vi
  • 7qp76sto3e72li1c3rl9h3lkv1
  • ouh1t1m7jnpgtop7urd7or2787
  • docusign=a469ef43-0dc9-4c74-bcfa-08780d7cb13d
  • MS=008DF7AB550417839E44576F497F140A1FD8C163
  • google-site-verification=83g2aihiRdN6gdEz8ARETgh2pIuKc_q6QZbvjs1k2uw
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Salesforce DocuSign