%2Bplugin%3ARedisOpenPlugin %2Basn%3A%22201094%22 -ip:"52.20.0.0/14" -plugin:"ConfigJsonHttp" +country:"France"
Version: Apache/2.4.29 (Ubuntu) mod_jk/1.2.43 OpenSSL/1.1.1
Server MPM: event
Server Built: 2019-04-03T13:22
Found by ApacheStatusPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.3
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u2
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
Generation: 36
Parent Server MPM Generation: 35
Server uptime: 30 days 22 hours 16 minutes 10 seconds
Found by ApacheStatusPlugin
Found open SMB shares with NT AUTHORITY/ANONYMOUS LOGON
print$
IPC$
Found by SmbPlugin
Found 128 files trough .DS_Store spidering:
/_data_
/acapn
/acapn/actu.php
/acapn/admin
/acapn/bottom.php
/acapn/carousel.css
/acapn/conf_site.p...
Found by DotDsStoreOpenPlugin
Indices: 7, document count: 1943, size: 4.5 MB
Found index .opensearch-observability with 0 documents (208 B)
Found index .plugins-ml-config with...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0,003 BTC. Transfer to this BTC address 19pNR4MGshpXAaWxgPYGYtfn79dppP6FEH . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: mrserg@cock.li and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://54.38.135.104:9200 list
Found by ElasticSearchOpenPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.5
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.2p1 Debian-2+deb12u2
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.2p1
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
Indices: 7, document count: 1943, size: 4.5 MB
Found index .opensearch-observability with 0 documents (208 B)
Found index .plugins-ml-config with...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0,003 BTC. Transfer to this BTC address 19pNR4MGshpXAaWxgPYGYtfn79dppP6FEH . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: mrserg@cock.li and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://146.59.56.46:9200 list
Found by ElasticSearchOpenPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.0p1 Ubuntu-1ubuntu7
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.6p1 r4
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
80OPTIONS * HTTP/1.0
21-7-0/0/1734.
0.0031100.00.0051.02
::1http/1.1www.fied.fr:80OPTIONS * HTTP/1.0
22
Found by ApacheStatusPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.0
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.6
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.5
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin
43-22-0/0/82.
0.00324020215120.00.001.90
::1http/1.1
44-22-0/0/80.
0.0032404142780.00.000.69
::1http
Found by ApacheStatusPlugin
Found 1 files trough .DS_Store spidering:
/favicon
Found by DotDsStoreOpenPlugin
Found potentially vulnerable SSH version:
SSH-2.0-OpenSSH_9.0p1 Ubuntu-1ubuntu8.7
WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Found by SshRegresshionPlugin