+plugin:CassandraOpenPlugin
Indices: 14, document count: 111014538, size: 17.7 GB
Found index read__me with 1 documents (4.8 kB)
Found index .apm-agent-configuration with 0 ...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://104.168.157.10:9200 list
Indices: 3, document count: 5, size: 28.8 kB
Found index .kibana_task_manager_1 with 2 documents (12.7 kB)
Found index .apm-agent-configuration w...
Analysis helper :
estk --url=http://47.93.156.92:9200 list
Indices: 17, document count: 78732, size: 20.3 MB
Found index read_me with 1 documents (4.4 kB)
Found index live with 1 documents (5.1 kB)
Found ...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.017 BTC to 17i4n4qnVR4TXDpXWJTQVohaLH5SwXbPku 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@cock.li and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://107.23.249.79 list
Indices: 2, document count: 3, size: 27.9 kB
Found index cec__identified_person with 2 documents (22.5 kB)
Found index read_me_to_recover_databas...
Analysis helper :
estk --url=http://210.211.110.167:9200 list
Indices: 2, document count: 2, size: 10.5 kB
Found index read__me with 1 documents (4.9 kB)
Found index api with 1 documents (5.6 kB)
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://131.153.50.76:9200 list
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = https://github.com/kuldeep34...
NoAuth
Cluster info:
{"_nodes":{"total":3,"successful":3,"failed":0},"cluster_name":"Cassandra","nodes":{"ab6a4357-83b4-4e6c-b765-3e117ebc4e44":{...
Analysis helper :
estk --url=http://13.49.93.248:9200 list
Indices: 23, document count: 234644, size: 299.9 MB
Found index myindex with 4 documents (20.2 kB)
Found index myblog with 2 documents (12.0 kB)
...
Analysis helper :
estk --url=http://120.24.179.186:9200 list
{
"appData": {
"servers": {
"api": {
"host": "abbeyswift.pickacab.com",
"port": "80"
},
"faye": {
...
Indices: 11, document count: 2676, size: 774.8 kB
Found index goodieekeyspace_dev_shared_catalogue with 43 documents (23.9 kB)
Found index goodie...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://128.199.129.194:9200 list
Found 11 files trough .DS_Store spidering:
/_redirects
/asset-manifest.json
/favicon.ico
/index.html
/locales
/manifest.json
/pdf.worker.min.js
...
Indices: 51, document count: 21150228, size: 4.6 GB
Found index .monitoring-kibana-6-2022.03.18 with 17278 documents (3.9 MB)
Found index tn001-m...
Analysis helper :
estk --url=http://115.77.191.44:9200 list
{
"data": {
"alive": true,
"eventCode": "imexamerica21",
"settings": {
"app_analyticsurl": "https://log1.eventreference.com/a...
Found 4 files trough .DS_Store spidering:
/assets
/assets/frontend
/assets/frontend/hp
/queueit
Indices: 234, document count: 6233, size: 110.9 MB
Through Kibana endpoint
Found index dmarc_aggregate-2022-01-09 with 37 documents (74.8 kB)
Fou...
Analysis helper :
estk --url=http://51.89.135.79:5601 list
Found table system_auth.resource_role_permissons_index (index of db roles with permissions granted on a resource)
Found table system_auth.role_me...
Found by CassandraOpenPlugin
Found Wordpress users (CVE-2017-5487):
User #1 bert
Name: bert
Url: https://h-dinsurance.ca
NoAuth
Cluster info:
{"_nodes":{"total":1,"successful":1,"failed":0},"cluster_name":"docker-cluster","nodes":{"r2FVe4WKSLayu2gggx-a2A":{"name":"r...
Analysis helper :
estk --url=http://103.63.109.73:9200 list
Found Wordpress users (CVE-2017-5487):
User #1 user
Name: user
Url: http://127.0.0.1
Found table system_auth.resource_role_permissons_index (index of db roles with permissions granted on a resource)
Found table system_auth.role_me...
Found by CassandraOpenPlugin