+plugin:ElasticSearchOpenPlugin -ip:"124.220.0.0/14" +events.leak.severity:"medium" +country:"Brazil" +l9fp:"831cb76b8e05df46143a04338c4f3948fdcd7cf1fdcd7cf1fdcd7cf1fdcd7cf1"
Indices: 2, document count: 2, size: 10.7 kB
Found index .kibana_1 with 1 documents (6.6 kB)
Found index read-me with 1 documents (4.1 kB)
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://168.138.227.4:9200 list
Found by ElasticSearchOpenPlugin