nginx 1.21.3
tcp/80
MySQL is currently open without authentication.
Additionally a ransom note has been found in the dataset which indicates it has been compromised
This results in all the database data made available publicly.
Severity: critical
Fingerprint: cf350410ecceb5fdcad0ffdd0f450660e13c265fb31bfbec17b674986cb7737b
Databases: 32, row count: 138547, size: 7.9 MB Found table Z_README_TO_RECOVER.RECOVER_YOUR_DATA with 2 records Found table mysql.time_zone with 1820 records Found table mysql.help_relation with 36 records Found table mysql.proc with 2 records Found table mysql.roles_mapping with 0 records Found table mysql.column_stats with 0 records Found table mysql.time_zone_transition with 124187 records Found table mysql.columns_priv with 0 records Found table mysql.innodb_index_stats with 7 records Found table mysql.global_priv with 6 records Found table mysql.table_stats with 0 records Found table mysql.tables_priv with 1 records Found table mysql.proxies_priv with 2 records Found table mysql.time_zone_leap_second with 0 records Found table mysql.transaction_registry with 0 records Found table mysql.help_keyword with 16 records Found table mysql.help_category with 44 records Found table mysql.general_log with 2 records Found table mysql.func with 0 records Found table mysql.time_zone_transition_type with 9861 records Found table mysql.index_stats with 0 records Found table mysql.time_zone_name with 1820 records Found table mysql.innodb_table_stats with 2 records Found table mysql.event with 0 records Found table mysql.slow_log with 2 records Found table mysql.plugin with 0 records Found table mysql.servers with 0 records Found table mysql.help_topic with 735 records Found table mysql.procs_priv with 0 records Found table mysql.db with 1 records Found table mysql.user with 1 records Found table mysql.gtid_slave_pos with 0 records
Severity: critical
Fingerprint: cf350410ecceb5fd6997e89cce9bbcf5240d846cb6f7d2d977358a9bbc87eff9
Databases: 32, row count: 138546, size: 7.9 MB Found table Z_README_TO_RECOVER.RECOVER_YOUR_DATA with 2 records Found table mysql.time_zone with 1820 records Found table mysql.help_relation with 36 records Found table mysql.proc with 2 records Found table mysql.roles_mapping with 0 records Found table mysql.column_stats with 0 records Found table mysql.time_zone_transition with 124187 records Found table mysql.columns_priv with 0 records Found table mysql.innodb_index_stats with 7 records Found table mysql.global_priv with 5 records Found table mysql.table_stats with 0 records Found table mysql.tables_priv with 1 records Found table mysql.proxies_priv with 2 records Found table mysql.time_zone_leap_second with 0 records Found table mysql.transaction_registry with 0 records Found table mysql.help_keyword with 16 records Found table mysql.help_category with 44 records Found table mysql.general_log with 2 records Found table mysql.func with 0 records Found table mysql.time_zone_transition_type with 9861 records Found table mysql.index_stats with 0 records Found table mysql.time_zone_name with 1820 records Found table mysql.innodb_table_stats with 2 records Found table mysql.event with 0 records Found table mysql.slow_log with 2 records Found table mysql.plugin with 0 records Found table mysql.servers with 0 records Found table mysql.help_topic with 735 records Found table mysql.procs_priv with 0 records Found table mysql.db with 1 records Found table mysql.user with 1 records Found table mysql.gtid_slave_pos with 0 records
Open service 51.195.223.203:3306
2023-01-02 07:58
Open service 51.195.223.203:80
2023-01-17 12:22
Server: nginx/1.21.3 Date: Tue, 17 Jan 2023 12:22:04 GMT Content-Type: text/html Content-Length: 615 Last-Modified: Tue, 07 Sep 2021 15:21:03 GMT Connection: close ETag: "6137835f-267" Accept-Ranges: bytes Page title: Welcome to nginx! <!DOCTYPE html> <html> <head> <title>Welcome to nginx!</title> <style> html { color-scheme: light dark; } body { width: 35em; margin: 0 auto; font-family: Tahoma, Verdana, Arial, sans-serif; } </style> </head> <body> <h1>Welcome to nginx!</h1> <p>If you see this page, the nginx web server is successfully installed and working. Further configuration is required.</p> <p>For online documentation and support please refer to <a href="http://nginx.org/">nginx.org</a>.<br/> Commercial support is available at <a href="http://nginx.com/">nginx.com</a>.</p> <p><em>Thank you for using nginx.</em></p> </body> </html>
Open service 51.195.223.203:3306
2023-01-12 02:27
Open service 51.195.223.203:3306
2022-12-17 16:52
Open service 51.195.223.203:80
2022-12-14 06:06
Server: nginx/1.21.3 Date: Wed, 14 Dec 2022 06:06:34 GMT Content-Type: text/html Content-Length: 615 Last-Modified: Tue, 07 Sep 2021 15:21:03 GMT Connection: close ETag: "6137835f-267" Accept-Ranges: bytes Page title: Welcome to nginx! <!DOCTYPE html> <html> <head> <title>Welcome to nginx!</title> <style> html { color-scheme: light dark; } body { width: 35em; margin: 0 auto; font-family: Tahoma, Verdana, Arial, sans-serif; } </style> </head> <body> <h1>Welcome to nginx!</h1> <p>If you see this page, the nginx web server is successfully installed and working. Further configuration is required.</p> <p>For online documentation and support please refer to <a href="http://nginx.org/">nginx.org</a>.<br/> Commercial support is available at <a href="http://nginx.com/">nginx.com</a>.</p> <p><em>Thank you for using nginx.</em></p> </body> </html>
Open service 51.195.223.203:80
2023-02-04 14:36
HTTP/1.1 200 OK Server: nginx/1.21.3 Date: Sat, 04 Feb 2023 14:36:23 GMT Content-Type: text/html Content-Length: 615 Last-Modified: Tue, 07 Sep 2021 15:21:03 GMT Connection: close ETag: "6137835f-267" Accept-Ranges: bytes Page title: Welcome to nginx! <!DOCTYPE html> <html> <head> <title>Welcome to nginx!</title> <style> html { color-scheme: light dark; } body { width: 35em; margin: 0 auto; font-family: Tahoma, Verdana, Arial, sans-serif; } </style> </head> <body> <h1>Welcome to nginx!</h1> <p>If you see this page, the nginx web server is successfully installed and working. Further configuration is required.</p> <p>For online documentation and support please refer to <a href="http://nginx.org/">nginx.org</a>.<br/> Commercial support is available at <a href="http://nginx.com/">nginx.com</a>.</p> <p><em>Thank you for using nginx.</em></p> </body> </html>
Open service 51.195.223.203:3306
2023-02-02 14:38
Open service 51.195.223.203:3306
2023-02-01 14:47
Open service 51.195.223.203:3306
2022-12-07 08:00