Group:
Akira
Discovered by ransomware.live: 2024-02-07
Estimated attack date:
2024-01-31
Country:
Description:
TeraGo provides businesses across Canada with secure cloud services, date recovery, and business grade internet. 45Gb of data willbe uploaded soon. You will find there lots of client agreements with personal information. Many files with financial information and everything that a provider can get from its customers.
DNS Records:
The following DNS records were found for the victim's domain.
- compliance@tucows.com
- ipnoc@terago.ca
- terago-ca.mail.protection.outlook.com.
- google-site-verification=83g2aihiRdN6gdEz8ARETgh2pIuKc_q6QZbvjs1k2uw
- 7qp76sto3e72li1c3rl9h3lkv1
- hk3prfid7s6hrrs7g2c1inu0k3
- v=spf1 mx a:mail.teraint.net ip4:67.226.181.229 ip4:67.226.180.229 ip4:207.54.126.52 ip4:67.226.151.1 ip4:209.97.193.217 ip4:67.226.151.24 ip4:67.226.151.25 ip4:209.97.193.216 ip4:64.46.32.116 include:aspmx.pardot.com include:spf.protection.outlook.com in" "clude:amazonses.com include:campaigns.structuredweb.com -all
- eig0b8gncdsb1ii5ia7umshvd1
- ou4g5ueehks4kcvl0q5lfrpfnm
- atlassian-sending-domain-verification=2f401ba0-5f3e-4b7a-8839-837eb7b2ae5f
- docusign=a469ef43-0dc9-4c74-bcfa-08780d7cb13d
- atlassian-domain-verification=xRyB0exaC2O22DI96BFtjBIWfjMp0dEKMAuOEhYqqLDC90Vn1M4zG5Uj4L6Lm7Vi
- bw=Jkz+6ZzSVvKl6SvGr+oKRxYT31R6glVZTp3kiXrO+QHh
- a3m5o5v744gpo80t9hnp2rji8v
- MS=008DF7AB550417839E44576F497F140A1FD8C163
- pardot503891=6b04203c20a9e43b6952252554ec46569bd3c05d443f959292465b5dfaf26066
- 8u1/iSXQrjtqy4DRQgIkjhs8+/EGkWzx4PQFDa5IwClCHKmXTmxlfizhzrplxTwtTNrsPUPXEMFg0b2tCJdupg==
- ouh1t1m7jnpgtop7urd7or2787
Cloud / SaaS Services Detected
Atlassian
Amazon SES/WorkMail
Salesforce
DocuSign
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.