Group:
Ransomhub
Discovered by ransomware.live: 2025-03-26
Estimated attack date:
2025-03-26
Country:
Description:
[AI generated] Conterra.com is the official website of Conterra Inc., a company that specializes in intelligent mapping solutions and geospatial data management. Conterra serves various industries including transport, utilities, and public safety. They provide services such as FME consulting & services, system integration, and geospatial web applications. Their head office is based in Münster, Germany.
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- mx2-us1.ppe-hosted.com.
- mx1-us1.ppe-hosted.com.
- MS=ms75093114
- duo_sso_verification=DsHeu0NwMzk6twZOwilZCblHrc25TqrQy7hKuNG8YJZmxcDC5ZAzo33p0DKwVwrf
- 6nrjlgvb7385h7a52t82bhvce8
- b9nc94o5fp7m92emg4rh8fur7
- autodesk-domain-verification=y4G4IcMshq8cJKb6zrjf
- 736e8dc32a1c01e173602312cabcde4b6951ba6a7d253e5f69
- sending_domain1104072=a975dd7147d37c6ffdcc44fc6a580e524ed2e11f66400e59b29937ac24b3be22
- pardot1104072=33a4e730ebf898990a8a57330b266075ebd52adea3489398b4ce21999db3147b
- 1password-site-verification=4PADMLD5QFDIBEPO2O6GTRWHXM
- google-site-verification=VA6D41ZWQyxfF0Hrp-vy0SmG6F1K3_kDasrSD7GH4ys
- nsidgouudjddh227e5rnk1kfg2
- 7fd4bpgn97jcf8q939rvd3e8et
- apple-domain-verification=qDOqtUXmWYOpfxVP
- v=spf1 mx include:spf.protection.outlook.com a ip4:139.180.60.64/27 ip4:208.77.169.0/24 ip4:69.63.171.0/25 ip4:12.31.127.0/24 ip4:208.85.135.7 ip4:4.78.147.148 ip4:50.31.156.96/27 ip4:104.245.209.192/26 ip4:50.31.205.0/24 a:dispatch-us.ppe-hosted.com incl" "ude:_spf.psm.knowbe4.com include:_spf.salesforce.com include:_spf.act-on.net include:20349875.spf05.hubspotemail.net ~all
- 5kdnpa6hnmm80u5sqnaph4a3u8
- pardot1040893=f3939382272d6e7c723c7150651af4c44da71d0c001ae176fc20becb1a627537
Cloud / SaaS Services Detected
Apple
HubSpot
Microsoft 365
Salesforce
Autodesk
KnowBe4
Cisco Duo
Proofpoint Essentials
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.