+plugin:ElasticSearchOpenPlugin -ip:"124.220.0.0/14" +events.leak.severity:"medium" +net:"Contabo GmbH" +l9fp:"831cb76b8e05df46f2602735401fb49d6b6b78326b6b78326b6b78326b6b7832"
Indices: 2, document count: 34, size: 32.2 MB
Found index .geoip_databases with 33 documents (32.2 MB)
Found index read-me with 1 documents (4.5 ...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y3EVBa` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://5.189.186.219:9202 list
Found by ElasticSearchOpenPlugin