+plugin:ElasticSearchOpenPlugin -ip:"124.220.0.0/14" +events.leak.severity:"medium" +country:"Hong Kong"
Indices: 73, document count: 6261882, size: 4.1 GB
Through Kibana endpoint
Found index admin with 1 documents (4.8 kB)
Found index .monitoring-es...
Analysis helper :
estk --url=http://154.207.98.223:5601 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 34, size: 32.7 MB
Through Kibana endpoint
Found index .geoip_databases with 33 documents (32.7 MB)
Found index read_m...
Analysis helper :
estk --url=http://34.150.115.226:5601 list
Found by ElasticSearchOpenPlugin
Indices: 4, document count: 86647, size: 15.2 MB
Through Kibana endpoint
Found index .kibana_task_manager with 2 documents (22.0 kB)
Found index ...
Analysis helper :
estk --url=http://47.243.4.24:5601 list
Found by ElasticSearchOpenPlugin
Indices: 9, document count: 89, size: 200.0 MB
Through Kibana endpoint
Found index .geoip_databases with 33 documents (32.7 MB)
Found index .apm-...
Analysis helper :
estk --url=http://8.210.104.45:5601 list
Found by ElasticSearchOpenPlugin
Indices: 14, document count: 2430, size: 21.1 MB
Through Kibana endpoint
Found index .kibana_7.12.1_001 with 79 documents (2.2 MB)
Found index .a...
Analysis helper :
estk --url=http://8.218.148.97:5601 list
Found by ElasticSearchOpenPlugin
Indices: 1, document count: 1, size: 5.0 kB
Found index read_me with 1 documents (5.0 kB)
Ransom notes :
{"text":"Your DB has been back up. The only way of recovery is you must send 0.0057 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
Analysis helper :
estk --url=http://168.63.150.216:9200 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 3, size: 13.6 kB
Found index test with 1 documents (4.0 kB)
Found index .kibana with 1 documents (5.3 kB)
Found index...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `5Xcpm5` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://103.156.178.100:9200 list
Found by ElasticSearchOpenPlugin
Indices: 11, document count: 2377, size: 2.3 MB
Through Kibana endpoint
Found index logs1-2022.08.26 with 747 documents (414.7 kB)
Found index lo...
Analysis helper :
estk --url=http://198.252.107.120:5601 list
Found by ElasticSearchOpenPlugin
Indices: 9, document count: 17, size: 101.1 kB
Through Kibana endpoint
Found index casa with 0 documents (283 B)
Found index test with 3 document...
Analysis helper :
estk --url=http://34.150.109.27:5601 list
Found by ElasticSearchOpenPlugin
Indices: 28, document count: 143697, size: 76.8 MB
Found index online_inventory_details_search with 17222 documents (7.0 MB)
Found index online_a...
Ransom notes :
{"Hello":"Your Database has been backuped :). Send 1 BTC to this address 1Ca3p5owVDK4CVEBANE3nrK6ZDzctFsKsb and then email us your elasticsearch IP at elasticsearch@airmail.cc to recover your data :)"}
Analysis helper :
estk --url=http://43.154.131.55:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 9380, size: 48.1 MB
Found index read_me with 1 documents (5.4 kB)
Found index master_database with 9379 documents (48...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.05 BTC to 16wrRb6vMi2py5rggYhdRNT2eUDdqTRS5V 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ After paying write to me in the mail with your DB IP: rambler+3il94@onionmail.org and/or eladb@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://8.218.175.138:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 1, size: 5.0 kB
Found index test with 1 documents (4.2 kB)
Found index read-me with 0 documents (810 B)
Analysis helper :
estk --url=http://43.159.228.178:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 3, size: 13.0 kB
Through Kibana endpoint
Found index .kibana with 2 documents (8.9 kB)
Found index read-me-to-recover...
Analysis helper :
estk --url=http://119.8.51.229:5601 list
Found by ElasticSearchOpenPlugin
Indices: 1, document count: 1, size: 5.0 kB
Through Kibana endpoint
Found index read_me with 1 documents (5.0 kB)
Analysis helper :
estk --url=http://65.52.191.123:5601 list
Found by ElasticSearchOpenPlugin
Indices: 10, document count: 8111, size: 1.2 MB
Through Kibana endpoint
Found index casa with 0 documents (208 B)
Found index search_user_v4 with...
Analysis helper :
estk --url=http://43.135.25.152:5601 list
Found by ElasticSearchOpenPlugin
Indices: 9, document count: 17, size: 101.1 kB
Found index casa with 0 documents (283 B)
Found index test with 3 documents (10.3 kB)
Found index ...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://34.150.109.27:9200 list
Found by ElasticSearchOpenPlugin
Indices: 22, document count: 875539, size: 512.5 MB
Through Kibana endpoint
Found index .monitoring-es-7-2024.05.10 with 190134 documents (113.6 ...
Analysis helper :
estk --url=http://180.178.43.106:5601 list
Found by ElasticSearchOpenPlugin
Indices: 8, document count: 2055054, size: 3.3 GB
Found index pending_vpbank with 389 documents (1.6 MB)
Found index pending_momo with 1586507 do...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 15BdJyWiWRcNQY4xBuhJrmjqz7ZQD6zAcT . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://137.116.162.52:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 41, size: 843.7 kB
Through Kibana endpoint
Found index read_me with 1 documents (6.3 kB)
Found index mrk_gpt_knowledg...
Analysis helper :
estk --url=http://154.204.60.125:5601 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 2592471, size: 7.6 GB
Found index read_me with 1 documents (4.6 kB)
Found index app_request_logs with 2592470 documen...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 14UCEfQG5vs7kZAbFrcZ7K4BCiEa48mdFu . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://47.242.3.115:9200 list
Found by ElasticSearchOpenPlugin