+plugin:ElasticSearchOpenPlugin -ip:"124.220.0.0/14" +events.leak.severity:"medium" +country:"Brazil" +l9fp:"831cb76b8e05df46c90d04218efa212d20ae4cc626510206a2e11635f2a09dcd"
Indices: 6, document count: 1561487, size: 289.1 MB
Found index graylog_1 with 576676 documents (106.3 MB)
Found index gl-events_0 with 0 documen...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://186.233.199.142:9200 list
Found by ElasticSearchOpenPlugin