+plugin:ElasticSearchOpenPlugin -ip:"124.220.0.0/14" +events.leak.severity:"medium" +asn:"16509" +country:"United States"
Indices: 3, document count: 1110, size: 45.8 MB
Through Kibana endpoint
Found index .geoip_databases with 39 documents (38.9 MB)
Found index read...
Analysis helper :
estk --url=http://18.216.101.3:5601 list
Found by ElasticSearchOpenPlugin
Indices: 26, document count: 271, size: 853.8 kB
Found index hybridity with 1 documents (6.4 kB)
Found index service with 5 documents (97.6 kB)
F...
Analysis helper :
estk --url=https://reach.dev.salesonepro.com list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 40, size: 38.9 MB
Found index .geoip_databases with 39 documents (38.8 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.006 BTC to 16w2xEN9pcjFgECWH1LDVps4xV9m3nUMBN In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data5)After paying send mail to us: rambler+4teu6@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5TEU6"}
Analysis helper :
estk --url=http://3.137.36.252:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 40, size: 38.9 MB
Found index .geoip_databases with 39 documents (38.8 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.005 BTC to 16w2xEN9pcjFgECWH1LDVps4xV9m3nUMBN In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data5)After paying send mail to us: rambler+41wxf@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 51WXF"}
Analysis helper :
estk --url=http://34.219.171.196:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 40, size: 38.8 MB
Found index .geoip_databases with 39 documents (38.8 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.005 BTC to 16w2xEN9pcjFgECWH1LDVps4xV9m3nUMBN In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data5)After paying send mail to us: rambler+4emxo@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5EMXO"}
Analysis helper :
estk --url=http://44.233.181.232:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 34, size: 32.1 MB
Through Kibana endpoint
Found index .geoip_databases with 33 documents (32.1 MB)
Found index read-m...
Analysis helper :
estk --url=http://35.85.226.12:5601 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :
{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
Analysis helper :
estk --url=http://54.183.164.103 list
Found by ElasticSearchOpenPlugin
Indices: 464, document count: 40, size: 476.1 kB
Found index ssl-vpn with 0 documents (795 B)
Found index upload with 0 documents (795 B)
Found i...
Analysis helper :
estk --url=https://34.214.137.237 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 40, size: 38.9 MB
Found index .geoip_databases with 39 documents (38.8 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.006 BTC to 16w2xEN9pcjFgECWH1LDVps4xV9m3nUMBN In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data5)After paying send mail to us: rambler+4ulqg@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5ULQG"}
Analysis helper :
estk --url=http://18.246.4.29:9200 list
Found by ElasticSearchOpenPlugin
Indices: 15, document count: 1070885, size: 431.6 MB
Through Kibana endpoint
Found index .monitoring-es-6-2024.03.04 with 164952 documents (67.4 ...
Analysis helper :
estk --url=http://54.244.214.176:5601 list
Found by ElasticSearchOpenPlugin
Indices: 15, document count: 2636766, size: 3.3 GB
Through Kibana endpoint
Found index .kibana_1 with 1 documents (3.8 kB)
Found index goose_sear...
Analysis helper :
estk --url=http://18.219.12.25:5601 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 29989, size: 105.1 MB
Found index items with 29988 documents (105.1 MB)
Found index read-me with 1 documents (5.3 kB)...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://18.221.161.219:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 0, size: 1.6 kB
Found index .kibana_1 with 0 documents (810 B)
Found index read-me with 0 documents (810 B)
Analysis helper :
estk --url=http://18.237.173.120:9200 list
Found by ElasticSearchOpenPlugin
Indices: 5, document count: 1671, size: 2.6 MB
Found index pwa-magento243_product_1_v4 with 419 documents (671.6 kB)
Found index pwa-magento243_p...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `5Xcpm5` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://100.21.7.51:9201 list
Found by ElasticSearchOpenPlugin
Indices: 82, document count: 5445206, size: 5.6 GB
Through Kibana endpoint
Found index smartgridlogs-2024.04.01 with 2739 documents (2.8 MB)
Foun...
Analysis helper :
estk --url=https://logs.sg.entgra.net list
Found by ElasticSearchOpenPlugin
Indices: 44, document count: 1521, size: 47.5 MB
Found index internal with 1 documents (6.7 kB)
Found index transrules-dev-test_sc with 1 documen...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=https://es.demo.exfinsights.com list
Found by ElasticSearchOpenPlugin
Indices: 29, document count: 274, size: 849.0 kB
Found index hybridity with 1 documents (6.4 kB)
Found index service with 5 documents (97.6 kB)
F...
Analysis helper :
estk --url=https://reach-dev.salesonepro.com list
Found by ElasticSearchOpenPlugin
Indices: 31, document count: 1002, size: 44.9 MB
Found index casa with 0 documents (226 B)
Found index read_me with 1 documents (4.5 kB)
Found in...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.006 BTC to 16w2xEN9pcjFgECWH1LDVps4xV9m3nUMBN In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data5)After paying send mail to us: rambler+4xv12@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5XV12"}
Analysis helper :
estk --url=https://es.demo.exfdigital.com list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 10044, size: 9.6 MB
Found index smartsearch-1 with 6000 documents (5.8 MB)
Found index smartsearch-2 with 4043 docume...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 14UCEfQG5vs7kZAbFrcZ7K4BCiEa48mdFu . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://52.52.248.235:9200 list
Found by ElasticSearchOpenPlugin
Indices: 16, document count: 4, size: 29.0 kB
Found index index.cfm with 0 documents (208 B)
Found index internal with 1 documents (6.5 kB)
Found...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://52.33.54.69 list
Found by ElasticSearchOpenPlugin