By searching for results, you agree with our Terms of service
Found 36533 results for
%2Bplugin%3AHiSiliconDVR %2Bcountry%3A%22Vietnam%22 %2Basn%3A%2218403%22 +country:"Japan" +events.leak.severity:"high" -ip:"52.192.0.0/13"

Looking for more results ? Register a free account

Countries

  • Japan 36491
  • United States 17
  • China 12
  • Luxembourg 3
  • Russia 3
  • Singapore 2
  • Taiwan 2
  • Australia 1
  • France 1
  • The Netherlands 1

Sources

  • SmbPlugin 14164
  • GitConfigHttpPlugin 9109
  • DotDsStoreOpenPlugin 6319
  • HiSiliconDVR 4012
  • ElasticSearchOpenPlugin 1604
  • MysqlOpenPlugin 464
  • GitlabPlugin 385
  • MongoOpenPlugin 238
  • MoodlePlugin 111
  • CheckMkPlugin 93

Network

  • AMAZON-02 7171
  • NTT Communications Corporation 5278
  • KDDI CORPORATION 2339
  • SAKURA Internet Inc. 2271
  • Xserver Inc. 2117
  • GMO Internet,Inc 2102
  • Softbank BB Corp. 1293
  • BIGLOBE Inc. 1238
  • Sony Network Communications Inc. 1206
  • NTT PC Communications, Inc. 1079

IP Ranges

  • 18.176.0.0/13 1359
  • 35.72.0.0/13 1066
  • 106.128.0.0/10 764
  • 153.128.0.0/10 758
  • 180.0.0.0/10 736
  • 3.112.0.0/14 648
  • 13.112.0.0/14 612
  • 36.8.0.0/13 592
  • 183.90.224.0/19 581
  • 153.192.0.0/11 545

ASN: 131965
11 events in 94 days
Open ports: 443
Found 2 files trough .DS_Store spidering:

/_backup
/wpcms

ASN: 2514
60 events in 710 days
Open ports: 445
Found open SMB shares with Guest login
ADMIN$
C$
E$
IPC$
LANDISK
SampoERP
Users
wwwroot
YAccBackup$

ASN: 4713
15 events in 94 days
Open ports: 80
Found HiSiliconDVR firmware:
Hardware: General NBD7904T-PL-XPOE
Vulnerable to multiple issues : LFI, possibly RCE

ASN: 4713
39 events in 475 days
Leak size: 9.5 kB
Open ports: 9210
Indices: 2, document count: 2, size: 9.5 kB
Found index .kibana with 1 documents (5.2 kB)
Found index read-me with 1 documents (4.3 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `h7pEfd` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://153.246.0.43:9210 list
            

ASN: 2497
63 events in 386 days
Open ports: 80
Found 45 files trough .DS_Store spidering:

/668
/668.psd
/668.zip
/bqwbzvvg.html
/css
/css/mdjzltvo.css
/css/qeggehib.css
/feqeyiqd.html
/img
/i...

ASN: 45974
22 events in 228 days
Leak size: 25.4 kB
Open ports: 9200
Indices: 12, document count: 3, size: 25.4 kB
Found index msdwikimsd with 1 documents (8.6 kB)
Found index msswikimss with 0 documents (208 B)
Fo...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.0057 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://133.186.146.116:9200 list
            

ASN: 2907
79 events in 1035 days
Open ports: 80
Found 124 files trough .DS_Store spidering:

/.vscode
/104.単一エコーの入射方向が単語了解度に及ぼす影響.pdf
/110.Parametric HRTF再考 -N1・N2・P1+P2による上方音像制御精度の改善-.pdf
/1...

ASN: 2514
32 events in 580 days
Open ports: 445
Found open SMB shares with Guest login
ADMIN$
C$
D$
I$
IPC$
Users
共有

210.140.84.163
high
ヘルパーメールサービス終了のお知らせ
ASN: 4694
84 events in 728 days
Leak size: 292 B
Open ports: 443
[core]
	repositoryformatversion = 0
	filemode = true
	bare = false
	logallrefupdates = true
[remote "origin"]
	fetch = +refs/heads/*:refs/remotes...

ASN: 7473
82 events in 614 days
Open ports: 445
Found open SMB shares with Guest login
ADMIN$
C$
IPC$
Users

ASN: 45974
32 events in 239 days
Leak size: 2.5 kB
Open ports: 27017
Collections: 7, document count: 7, size: 2.5 kB
HTTP/1.0 200 OK
Connection: close
Content-Type: text/plain
Content-Length: 85


It looks like ...
Analysis helper :
                
echo 'show dbs' | mongo --host 133.186.159.66 --port 27017
            

ASN: 396982
56 events in 1016 days
Leak size: 12.3 kB
Open ports: 9200
Indices: 2, document count: 2, size: 12.3 kB
Found index .kibana_1 with 1 documents (7.4 kB)
Found index read-me with 1 documents (4.9 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://35.187.204.105:9200 list
            

ASN: 2519
75 events in 621 days
Open ports: 445
Found open SMB shares with Guest login
IPC$
scan

ASN: 2514
127 events in 1040 days
Leak size: 481 B
Open ports: 443
Certificate domains:
matchapp.grapps.me
tinomy.com
[core]
	repositoryformatversion = 0
	fileMode = false
	bare = false
	logallrefupdates = true
[remote "origin"]
	#url = https://sereyk@bitbucket.o...

ASN: 58652
13 events in 82 days
Open ports: 443
Found 74 files trough .DS_Store spidering:

/.well-known
/moodle
/moodle/.github
/moodle/.grunt
/moodle/.grunt/jsdoc
/moodle/.grunt/tasks
/moodle...

ASN: 17511
16 events in 117 days
Open ports: 88
Found HiSiliconDVR firmware:
Hardware: General AHB7008T-MHV2
Vulnerable to multiple issues : LFI, possibly RCE

ASN: 9370
111 events in 1031 days
Open ports: 443
Certificate domains:
www7183up.sakura.ne.jp
Found 68 files trough .DS_Store spidering:

/bg.jpg
/bootstrap
/favicon.ico
/from_ito_server
/from_ito_server/ajaxchat
/from_ito_server/hako_php
...

ASN: 2519
70 events in 739 days
Open ports: 80
Found HiSiliconDVR firmware:
Hardware: General AHB7004T-MHV2
Vulnerable to multiple issues : LFI, possibly RCE

ASN: 2527
59 events in 710 days
Open ports: 445
Found open SMB shares with Guest login
IPC$

ASN: 396982
89 events in 946 days
Leak size: 311 B
Open ports: 443
[core]
	repositoryformatversion = 0
	filemode = true
	bare = false
	logallrefupdates = true
[remote "origin"]
	url = ssh://item.mapple@gmail.com@...