By searching for results, you agree with our Terms of service
Found 68068 results for
+dataset.ransom_notes:btc -country:"Russia" -ip:"101.42.0.0/15"

Looking for more results ? Register a free account

Countries

  • China 32754
  • United States 10631
  • Germany 3530
  • India 2438
  • France 2229
  • Singapore 2098
  • South Korea 1831
  • Hong Kong 1476
  • United Kingdom 883
  • Japan 847

Sources

  • ElasticSearchOpenPlugin 42271
  • MysqlOpenPlugin 25797

Network

  • Hangzhou Alibaba Advertising Co.,Ltd. 15331
  • Shenzhen Tencent Computer Systems Company Limited 9792
  • AMAZON-02 5982
  • GOOGLE-CLOUD-PLATFORM 3249
  • DIGITALOCEAN-ASN 2191
  • OVH SAS 2179
  • Huawei Cloud Service data center 2085
  • AMAZON-AES 2058
  • Hetzner Online GmbH 1515
  • MICROSOFT-CORP-MSN-AS-BLOCK 1411

IP Ranges

  • 47.96.0.0/12 3384
  • 124.220.0.0/14 1354
  • 43.136.0.0/13 1202
  • 47.92.0.0/14 923
  • 39.104.0.0/14 921
  • 121.40.0.0/14 713
  • 47.112.0.0/13 708
  • 134.236.0.0/16 682
  • 120.24.0.0/14 661
  • 120.76.0.0/14 646

ASN: 12876
224 events in 793 days
Leak size: 678.9 kB
Open ports: 443
Certificate domains:
es.jobypepper.com
Indices: 41, document count: 110, size: 678.9 kB
Found index v1.24 with 1 documents (8.8 kB)
Found index casa with 0 documents (208 B)
Found inde...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `5Xcpm5` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://es.jobypepper.com list
            

ASN: 328170
199 events in 795 days
Leak size: 143.3 MB
Open ports: 80
Certificate domains:
elastic.ops.cgrate.com
Indices: 17, document count: 58, size: 143.3 MB
Found index internal with 1 documents (6.7 kB)
Found index read_me with 1 documents (5.1 kB)
Foun...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://elastic.ops.cgrate.com list
            

ASN: 14618
173 events in 465 days
Leak size: 3.6 MB
Open ports: 443
Certificate domains:
thehrsite.com
Indices: 13, document count: 6000, size: 3.6 MB
Found index v1.24 with 1 documents (9.2 kB)
Found index internal with 1 documents (6.6 kB)
Found ...
Analysis helper :
                
estk --url=https://thehrsite.com list
            

ASN: 44133
181 events in 622 days
Leak size: 4.8 MB
Open ports: 443
Certificate domains:
elastic23.saviomedia.gmbh
Indices: 4, document count: 492, size: 4.8 MB
Found index internal with 1 documents (6.7 kB)
Found index ecoaustriaacat-post-1 with 489 documents...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=https://elastic23.saviomedia.gmbh list
            

ASN: 207143
16 events in 47 days
Leak size: 5.3 kB
Open ports: 80
Certificate domains:
elasticsearch.time-shepherd.ch
Indices: 1, document count: 1, size: 5.3 kB
Found index read_me with 1 documents (5.3 kB)
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0045 BTC to bc1qt3zrm0va2g5adut9pem790hsmtnwka76yrzwjp In 48 hours, your data will be publicly disclosed and deleted. (more information: go to https://is.gd/rudata5)After paying send mail to us: rambler+5yyj9@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5YYJ9"}
            
Analysis helper :
                
estk --url=http://elasticsearch.time-shepherd.ch list
            

ASN: 51167
178 events in 801 days
Leak size: 243.4 MB
Open ports: 443
Certificate domains:
search.rafraf.com
Indices: 6, document count: 115859, size: 243.4 MB
Found index .geoip_databases with 40 documents (39.1 MB)
Found index magento2_product_1_v4 wit...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0046 BTC to bc1q35hf9sr8zar2tfaplyrw3llyu3mfcj632pwuwn In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+56yx3@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 56YX3"}
            
Analysis helper :
                
estk --url=https://search.rafraf.com list
            

ASN: 12876
186 events in 797 days
Leak size: 128.0 MB
Open ports: 443
Certificate domains:
elastic.muzai.io
brif-demo.muzai.io
cantaloupe.muzai.io
flower.muzai.io
muzai.io
pgadmin.muzai.io
Indices: 3, document count: 25780, size: 128.0 MB
Found index internal with 1 documents (6.3 kB)
Found index prod_manifests with 25779 documents ...
Analysis helper :
                
estk --url=https://elastic.muzai.io list
            

ASN: 16509
187 events in 806 days
Leak size: 9.3 MB
Open ports: 443
Certificate domains:
search.truts.xyz
Indices: 6, document count: 10028, size: 9.3 MB
Found index listings with 9829 documents (9.0 MB)
Found index how-to-recover-data with 1 document...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4o0x3@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5O0X3"}
            
Analysis helper :
                
estk --url=https://search.truts.xyz list
            

ASN: 396982
199 events in 779 days
Leak size: 232.1 kB
Open ports: 80
Certificate domains:
elasticsearch-system.homehub.center
Indices: 28, document count: 33, size: 232.1 kB
Found index ztp with 1 documents (5.5 kB)
Found index internal with 1 documents (7.3 kB)
Found in...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.0057 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://elasticsearch-system.homehub.center list
            

ASN: 14061
191 events in 796 days
Leak size: 11.4 kB
Open ports: 443
Certificate domains:
elastic.staging.uxapp360.com
Indices: 2, document count: 2, size: 11.4 kB
Found index read-me with 1 documents (4.3 kB)
Found index .kibana_1 with 1 documents (7.1 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://elastic.staging.uxapp360.com list
            

ASN: 51167
50 events in 120 days
Leak size: 695.0 MB
Open ports: 443
Certificate domains:
pulseem.sqlserverutilities.com
Indices: 94, document count: 5312226, size: 695.0 MB
Found index read_me with 1 documents (4.5 kB)
Found index collector_version_store_2025.04.30...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0047 BTC to bc1q35hf9sr8zar2tfaplyrw3llyu3mfcj632pwuwn In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+59lc0@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 59LC0"}
            
Analysis helper :
                
estk --url=https://pulseem.sqlserverutilities.com list
            

ASN: 396982
212 events in 810 days
Leak size: 236.7 kB
Open ports: 443
Certificate domains:
elasticsearch-system.staging.homehub.center
Indices: 27, document count: 31, size: 236.7 kB
Found index admin with 1 documents (5.7 kB)
Found index hybridity with 1 documents (6.4 kB)
Found...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `5Xcpm5` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://elasticsearch-system.staging.homehub.center list
            

ASN: 16276
195 events in 783 days
Leak size: 56.1 MB
Open ports: 443
Certificate domains:
elasticsearch.ingoldsolutions.com
Indices: 34, document count: 14445, size: 56.1 MB
Found index biancob2cupgrade_product_13_v2 with 56 documents (120.7 kB)
Found index biancob2cup...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0046 BTC to bc1q35hf9sr8zar2tfaplyrw3llyu3mfcj632pwuwn In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+5w7j6@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5W7J6"}
            
Analysis helper :
                
estk --url=https://elasticsearch.ingoldsolutions.com list
            

ASN: 51167
21 events in 88 days
Leak size: 50.1 kB
Open ports: 443
Certificate domains:
ropme-wp-elasticsearch.giscon.dev
Indices: 2, document count: 11, size: 50.1 kB
Found index read_me with 1 documents (5.7 kB)
Found index ropmewpgiscondev-post-1 with 10 documents...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0046 BTC to bc1q35hf9sr8zar2tfaplyrw3llyu3mfcj632pwuwn In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+5xght@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5XGHT"}
            
Analysis helper :
                
estk --url=https://ropme-wp-elasticsearch.giscon.dev list
            

ASN: 20473
204 events in 712 days
Leak size: 32.1 MB
Open ports: 443
Certificate domains:
api.gestaon.com.br
beta-server.gestaon.com.br
beta.gestaon.com.br
server.gestaon.com.br
staging-api.gestaon.com.br
staging-server.gestaon.com.br
www.gestaon.com.br
es.gestaon.com.br
gestaon.com.br
staging.gestaon.com.br
beta-api.gestaon.com.br
Indices: 19, document count: 277919, size: 32.1 MB
Found index service with 1 documents (19.6 kB)
Found index suite-auth with 9 documents (29.1 k...
Ransom notes :

{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 1rsAp5FzhD6huVBjJEnLZxnQXU6EQmUvb . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
            
Analysis helper :
                
estk --url=https://es.gestaon.com.br list
            

ASN: 16276
190 events in 649 days
Leak size: 527.3 kB
Open ports: 80
Certificate domains:
end24.moonbit.shop
Indices: 4, document count: 1400, size: 527.3 kB
Found index read-me with 1 documents (5.1 kB)
Found index bitbag_option_taxons_prod with 5 docum...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y3EVBa` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://end24.moonbit.shop list
            

ASN: 8075
111 events in 277 days
Leak size: 5.7 kB
Open ports: 443
Certificate domains:
eventbroker.elasticsearch.ugoerp.com
Indices: 1, document count: 1, size: 5.7 kB
Found index read_me with 1 documents (5.7 kB)
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0038 BTC to bc1qj7j77rvzjm6g34kw7frm6zhs9tzjzgtma03c20 In 48 hours, your data will be publicly disclosed and deleted. (more information: go to https://is.gd/rudata5)After paying send mail to us: dzen+5kpop@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5KPOP"}
            
Analysis helper :
                
estk --url=https://eventbroker.elasticsearch.ugoerp.com list
            

ASN: 51167
167 events in 478 days
Leak size: 3.1 MB
Open ports: 443
Certificate domains:
elasticsearch.recrulink.dev
Indices: 11, document count: 40983, size: 3.1 MB
Found index internal with 1 documents (6.7 kB)
Found index auth with 1 documents (4.6 kB)
Found ...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://elasticsearch.recrulink.dev list
            

ASN: 14618
169 events in 464 days
Leak size: 3.6 MB
Open ports: 80
Certificate domains:
thehrsite.com
Indices: 13, document count: 6000, size: 3.6 MB
Found index v1.24 with 1 documents (9.2 kB)
Found index internal with 1 documents (6.6 kB)
Found ...
Analysis helper :
                
estk --url=http://thehrsite.com list
            

ASN: 16509
70 events in 173 days
Leak size: 57.7 MB
Open ports: 443
Certificate domains:
devnet-index.autoscale.finance
Indices: 12, document count: 51, size: 57.7 MB
Found index .geoip_databases with 40 documents (39.1 MB)
Found index operations with 0 documents (...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0047 BTC to bc1q35hf9sr8zar2tfaplyrw3llyu3mfcj632pwuwn In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+54ysn@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 54YSN"}
            
Analysis helper :
                
estk --url=https://devnet-index.autoscale.finance list