By searching for results, you agree with our Terms of service
Found 3381 results for
+dataset.ransom_notes:btc +ip:"47.96.0.0/12"

Looking for more results ? Register a free account

Countries

  • China 3381

Sources

  • ElasticSearchOpenPlugin 2021
  • MysqlOpenPlugin 1360

Network

  • Hangzhou Alibaba Advertising Co.,Ltd. 3381

IP Ranges

  • 47.96.0.0/12 3381

ASN: 37963
64 events in 1286 days
Leak size: 14.8 MB
Open ports: 9200
Indices: 4, document count: 12738, size: 14.8 MB
Found index read_me with 1 documents (5.0 kB)
Found index course_item_pro with 11981 documents (...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.0057 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://47.106.108.242:9200 list
            

ASN: 37963
166 events in 789 days
Leak size: 41.4 MB
Open ports: 9200
Indices: 15, document count: 2491, size: 41.4 MB
Found index .ds-datahub_usage_event-2025.03.12-000082 with 0 documents (226 B)
Found index read_...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0052 BTC to bc1q7xgc4zkf00yk4u4vrkfpc7m64h8ly5w4ap0cnx In 48 hours, your data will be publicly disclosed and deleted. (more information: go to https://is.gd/rudata5)After paying send mail to us: rambler+5lsus@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5LSUS"}
            
Analysis helper :
                
estk --url=http://47.107.98.192:9200 list
            

ASN: 37963
163 events in 572 days
Leak size: 919.9 kB
Open ports: 3306
Databases: 30, row count: 3026, size: 919.9 kB
Found table mysql.columns_priv with 0 records
Found table mysql.db with 2 records
Found table mysq...
Ransom notes :

1I have backed up all your databases. To recover them you must pay 0.01 BTC (Bitcoin) to this address: 13eWyQW4YB6ecJjZasXyVNH6eAns5ogjto . Backup List: recover_your_data. After your payment email me at sqlrecover471@onionmail.org with your server IP (47.106.134.45) and transaction ID and you will get a download link to your backup. Emails without transaction ID and server IP will be ignored. 13eWyQW4YB6ecJjZasXyVNH6eAns5ogjto 1I have backed up all your databases. To recover them you must pay 0.01 BTC (Bitcoin) to this address: 13eWyQW4YB6ecJjZasXyVNH6eAns5ogjto . Backup List: recover_your_data. After your payment email me at sqlrecover471@onionmail.org with your server IP (47.106.134.45) and transaction ID and you will get a download link to your backup. Emails without transaction ID and server IP will be ignored. 13eWyQW4YB6ecJjZasXyVNH6eAns5ogjto
            

ASN: 37963
52 events in 145 days
Leak size: 5.3 kB
Open ports: 9200
Indices: 1, document count: 1, size: 5.3 kB
Found index read_me with 1 documents (5.3 kB)
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0038 BTC to bc1qj7j77rvzjm6g34kw7frm6zhs9tzjzgtma03c20 In 48 hours, your data will be publicly disclosed and deleted. (more information: go to https://is.gd/rudata5)After paying send mail to us: dzen+5thgk@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5THGK"}
            
Analysis helper :
                
estk --url=http://47.109.81.239:9200 list
            

ASN: 37963
211 events in 1415 days
Leak size: 7.7 kB
Open ports: 9200
Indices: 2, document count: 2, size: 7.7 kB
Found index test with 1 documents (3.6 kB)
Found index read-me with 1 documents (4.1 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `5Xcpm5` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://47.110.240.26:9200 list
            

ASN: 37963
149 events in 505 days
Leak size: 30.3 GB
Open ports: 9201
Indices: 2, document count: 85680061, size: 30.3 GB
Found index read-me with 1 documents (5.3 kB)
Found index ques_house_for_search_by_text with ...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://47.104.4.15:9201 list
            

ASN: 37963
154 events in 615 days
Leak size: 1.6 MB
Open ports: 9200
Indices: 4, document count: 2748, size: 1.6 MB
Found index test with 1 documents (4.0 kB)
Found index goods with 2668 documents (1.5 MB)
Found in...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://47.106.121.42:9200 list
            

ASN: 37963
71 events in 1221 days
Leak size: 73.8 MB
Open ports: 9200
Indices: 199, document count: 369273, size: 73.8 MB
Found index %{[@metadata][beat]}-%{[@metadata][version]}-2021.10.29 with 1720 documents (391....
Ransom notes :

{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 14b57thKoPjmVVkh6HHLPz8g7fyBJ5SEcr . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
            
Analysis helper :
                
estk --url=http://47.104.234.239:9200 list
            

ASN: 37963
195 events in 794 days
Leak size: 384.7 MB
Open ports: 9200
Indices: 5, document count: 1013506, size: 384.7 MB
Found index myfamily-test with 0 documents (208 B)
Found index order-test with 356203 documen...
Ransom notes :

{"message": "We delete all databases, but download a copy to our server. The only way of recovery is you must send 0.01 BTC to bc1qmaacz9fdvnkujqlf8m547mzzh0l5t0ajn699th. You have until 48 hours to pay or data will be inaccessible. Once paid please email incomings99112@onionmail.com with code: `eNO2CN` and we will recover your database. please read https://paste.sh/UY6_vtGL#THGqRdL9oQqUc-28RPDOWSbB for more information"}
            
Analysis helper :
                
estk --url=http://47.99.157.90:9200 list
            

ASN: 37963
171 events in 696 days
Leak size: 123.9 MB
Open ports: 9200
Indices: 10, document count: 996933, size: 123.9 MB
Found index jetlinks-metrics_2024-1 with 874019 documents (90.2 MB)
Found index device_log_16...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://47.98.159.120:9200 list
            

ASN: 37963
9 events in 39 days
Leak size: 3.5 MB
Open ports: 9200
Indices: 7, document count: 25333, size: 3.5 MB
Found index cloudluck-error-2025.04.12 with 2337 documents (301.9 kB)
Found index cloudluck-error...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0054 BTC to bc1q7stxy9axrwmpu77kme55523a723spvcurnyt9x In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+5ewme@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5EWME"}
            
Analysis helper :
                
estk --url=http://47.102.101.221:9200 list
            

ASN: 37963
169 events in 646 days
Leak size: 32.4 MB
Open ports: 9200
Indices: 3, document count: 56499, size: 32.4 MB
Found index zrch_risk_filedoc with 8549 documents (22.4 MB)
Found index read_me with 1 documents...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0054 BTC to bc1qfnu6j2n54k58uduufzuthhy7qn3sx7zalyuytz In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+51mx4@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 51MX4"}
            
Analysis helper :
                
estk --url=http://47.110.158.206:9200 list
            

ASN: 37963
132 events in 318 days
Leak size: 7.8 MB
Open ports: 3307
Databases: 32, row count: 140071, size: 7.8 MB
Found table mysql.columns_priv with 0 records
Found table mysql.db with 2 records
Found table mysq...
Ransom notes :

All your data is backed up. You must pay 0.0072 BTC to 1JjzBZ8MdxFpecDgp24FrrHwQmzXXM4hTr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to https://is.gd/dayuwi)
            

ASN: 37963
194 events in 1096 days
Leak size: 4.0 kB
Open ports: 9200
Indices: 1, document count: 1, size: 4.0 kB
Found index read-me with 1 documents (4.0 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://47.98.178.114:9200 list
            

ASN: 37963
177 events in 755 days
Leak size: 5.3 kB
Open ports: 9200
Indices: 1, document count: 1, size: 5.3 kB
Found index read-me with 1 documents (5.3 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `riDAZo` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://47.101.37.175:9200 list
            

ASN: 37963
145 events in 505 days
Leak size: 152.2 MB
Open ports: 9200
Indices: 4, document count: 770522, size: 152.2 MB
Found index read-me with 1 documents (5.1 kB)
Found index internal with 1 documents (7.3 kB)
F...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `EaBLis` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://47.100.78.105:9200 list
            

ASN: 37963
187 events in 618 days
Leak size: 769.1 kB
Open ports: 3306
Databases: 31, row count: 2174, size: 769.1 kB
Found table mysql.columns_priv with 0 records
Found table mysql.cppccc with 0 records
Found table ...
Ransom notes :

1I have backed up all your databases. To recover them you must pay 0.01 BTC (Bitcoin) to this address: 13eWyQW4YB6ecJjZasXyVNH6eAns5ogjto . Backup List: recover_your_data. After your payment email me at sqlrecover471@onionmail.org with your server IP (47.100.235.177) and transaction ID and you will get a download link to your backup. Emails without transaction ID and server IP will be ignored. 13eWyQW4YB6ecJjZasXyVNH6eAns5ogjto 1I have backed up all your databases. To recover them you must pay 0.01 BTC (Bitcoin) to this address: 13eWyQW4YB6ecJjZasXyVNH6eAns5ogjto . Backup List: recover_your_data. After your payment email me at sqlrecover471@onionmail.org with your server IP (47.100.235.177) and transaction ID and you will get a download link to your backup. Emails without transaction ID and server IP will be ignored. 13eWyQW4YB6ecJjZasXyVNH6eAns5ogjto
            

ASN: 37963
61 events in 167 days
Leak size: 6.3 kB
Open ports: 9200
Indices: 5, document count: 1, size: 6.3 kB
Found index edu_teacher with 0 documents (249 B)
Found index edu_article with 0 documents (249 B)
Fou...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0054 BTC to bc1q50kkrj2zr2l0nm8u8ygscphtxw02xjmkn3smv4 In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+55gr1@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 55GR1"}
            
Analysis helper :
                
estk --url=http://47.111.67.182:9200 list
            

ASN: 37963
183 events in 1030 days
Leak size: 946.2 kB
Open ports: 3306
Databases: 37, row count: 2571, size: 946.2 kB
Found table RECOVER_YOUR_DATA.RECOVER_YOUR_DATA with 0 records
Found table mysql.agieps with 1 rec...

ASN: 37963
172 events in 765 days
Leak size: 196.4 MB
Open ports: 9200
Indices: 13, document count: 1965044, size: 196.4 MB
Found index properties_huanjingshujucaijiqi2024_2025-4 with 11730 documents (1.2 MB)
Found i...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0054 BTC to bc1q7stxy9axrwmpu77kme55523a723spvcurnyt9x In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+534au@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 534AU"}
            
Analysis helper :
                
estk --url=http://47.104.226.46:9200 list