%2Bplugin%3AHiSiliconDVR %2Bnet%3A%22Viettel Group%22 -net:"CLOUDFLARENET" -net:"SERVERCENTRAL" -country:"Germany"
pxg_authz_dbd_module/0.4
Server MPM: event
Server Built: Sep 28 2021 14:16:46
Current Time: Wednesday, 22
Found by ApacheStatusPlugin
0.000659187926120.00.004530.38
185.191.171.37http/1.1skolnieshop.cz:443GET /skolni-vytvarne-potreby-146-op/presco-group-a-s
Found by ApacheStatusPlugin
url=https%3A%2F%2Fbmu-edu.uz%2Fru
14-7-0/0/383.
0.381470274810.00.007.62
10.10.10.116http/1.1
15-7-
Found by ApacheStatusPlugin
0.020068170.00.190.69
207.154.240.169http/1.1www.flysolutionts.com:443GET /.vscode/sftp.json HTTP/1.1
22
Found by ApacheStatusPlugin
-0/0/111.
0.012847316880.00.003.25
::1http/1.1
21-3-0/0/185.
0.022847125600.00.007.91
::1http/1.1
22
Found by ApacheStatusPlugin
kibana-event-log-7.15.1-000006 with 0 documents (208 B)
Found index certificado_afiliacion_salud with 22
Ransom notes :
{"message":"All your data is backed up. You must pay 0.0063 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4rbvk@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5RBVK"}
Analysis helper :
estk --url=http://34.145.49.208:9200 list
Found by ElasticSearchOpenPlugin
2.2.22 (Debian) mod_fcgid/2.3.6 PHP/5.4.45-0+deb7u8 mod_ssl/2.2.22 OpenSSL/1.0.1t
Server Built: Feb 22
Found by ApacheStatusPlugin
accesses: 4054 - Total Traffic: 1.3 MB
CPU Usage: u1.38 s.7 cu0 cs0 - .00349% CPU load
.068 requests/sec - 22
Found by ApacheStatusPlugin
Found 22 files trough .DS_Store spidering:
/index.php
/license.txt
/loader.php
/mojo-package.sh
/readme.html
Found by DotDsStoreOpenPlugin
1.1
2-043450/1/1_
0.17400.00.140.14
143.110.156.182openbluetavirarojas.es:80GET / HTTP/1.1
2-043450/22
Found by ApacheStatusPlugin
0.00673451184232600.00.003701.97
17.121.113.41http/1.1www.filmsenacteurs.nl:443GET /fr/movie/714394/Creating+a+Character%3A
Found by ApacheStatusPlugin
/1.1.1f
Server MPM: prefork
Server Built: 2022-06-14T13:30:55
Current Time: Friday, 06-Jan-2023 18:22
Found by ApacheStatusPlugin
Built: 2023-10-26T13:44:44
Current Time: Sunday, 03-Mar-2024 16:09:50 CST
Restart Time: Thursday, 22
Found by ApacheStatusPlugin
Built: Oct 16 2014 14:45:47
Current Time: Thursday, 26-May-2022 01:49:05 WEST
Restart Time: Sunday, 22
Found by ApacheStatusPlugin
43.00011124500.01.491.49
143.198.72.96http/1.1register.unlimitedaccesspass.coGET /v2/_catalog HTTP/1.1
22
Found by ApacheStatusPlugin
url=https%3a%2f%2f1%2fecp%2f HTTP/1.1
0-7610662170/1/1324_
0.006749461839780.00.0211.39
193.106.191.48http
Found by ApacheStatusPlugin
_
2.441645380.00.17912.75
54.179.21.175www.jhm-jukebox.fr:80POST /wp-login.php HTTP/1.1
0-32456720/22
Found by ApacheStatusPlugin
Generation: 23
Parent Server MPM Generation: 22
Server uptime: 21 days 17 hours 15 minutes 34 seconds
Found by ApacheStatusPlugin
Generation: 60
Parent Server MPM Generation: 59
Server uptime: 79 days 8 hours 1 minute 22 seconds
Server
Found by ApacheStatusPlugin
{
"name": "SakuraUploader",
"host": "163.43.195.81",
"protocol": "sftp",
"port": 22,
Found by VsCodeSFTPPlugin