By searching for results, you agree with our Terms of service
Found 128598 results for
+plugin:ElasticSearchOpenPlugin -ip:"49.232.0.0/14" -ip:"43.136.0.0/13" +events.leak.severity:"high" -ip:"47.96.0.0/12"

Looking for more results ? Register a free account

Countries

  • China 51102
  • United States 25188
  • Germany 6980
  • India 5908
  • Singapore 4607
  • South Korea 4478
  • France 3949
  • Hong Kong 2636
  • Russia 2407
  • The Netherlands 2234

Sources

  • ElasticSearchOpenPlugin 128598

Network

  • AMAZON-02 21914
  • Hangzhou Alibaba Advertising Co.,Ltd. 18699
  • Shenzhen Tencent Computer Systems Company Limited 14973
  • AMAZON-AES 7145
  • MICROSOFT-CORP-MSN-AS-BLOCK 5132
  • Huawei Cloud Service data center 4867
  • GOOGLE-CLOUD-PLATFORM 4024
  • DIGITALOCEAN-ASN 3756
  • OVH SAS 3421
  • Chinanet 3196

IP Ranges

  • 124.220.0.0/14 2065
  • 39.104.0.0/14 1488
  • 47.92.0.0/14 1381
  • 120.76.0.0/14 1287
  • 101.42.0.0/15 1215
  • 120.24.0.0/14 1129
  • 20.64.0.0/10 1120
  • 47.112.0.0/13 1081
  • 81.68.0.0/14 1032
  • 20.192.0.0/10 967

ASN: 16276
62 events in 492 days
Leak size: 42.4 MB
Open ports: 9210
Indices: 2, document count: 44, size: 42.4 MB
Found index .geoip_databases with 43 documents (42.4 MB)
Found index read-me with 1 documents (4.5 ...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `h7pEfd` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://147.135.195.52:9210 list
            

ASN: 19318
66 events in 478 days
Leak size: 483.3 MB
Open ports: 9200
Indices: 6, document count: 1389439, size: 483.3 MB
Found index elastic-logistaeg_external_amasty_xsearch_fulltext_1 with 13 documents (11.1 kB)
...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y3EVBa` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://104.37.190.6:9200 list
            

ASN: 396982
59 events in 377 days
Leak size: 46.5 MB
Open ports: 9200
Indices: 4, document count: 1031, size: 46.5 MB
Found index .geoip_databases with 43 documents (43.1 MB)
Found index read_me with 1 documents (5....
Ransom notes :

{"message":"All your data is a backed up. You must pay 0.05 BTC to 16wrRb6vMi2py5rggYhdRNT2eUDdqTRS5V 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ After paying write to me in the mail with your DB IP: rambler+38jwi@onionmail.org and/or eladb@mailnesia.com and you will receive a link to download your database dump."}
            
Analysis helper :
                
estk --url=http://35.194.18.249:9200 list
            

ASN: 21808
28 events in 206 days
Leak size: 13.0 kB
Open ports: 9200
Indices: 2, document count: 3, size: 13.0 kB
Found index .kibana with 2 documents (8.9 kB)
Found index read-me with 1 documents (4.1 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `5Xcpm5` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://207.223.73.82:9200 list
            

ASN: 58593
34 events in 257 days
Leak size: 6.4 MB
Open ports: 9200
Indices: 9, document count: 2279, size: 6.4 MB
Found index .kibana_task_manager_1 with 2 documents (22.3 kB)
Found index document_catalog with 25...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://52.131.233.140:9200 list
            

ASN: 16276
30 events in 241 days
Leak size: 9.1 kB
Open ports: 9200
Indices: 3, document count: 2, size: 9.1 kB
Found index .plugins-ml-config with 1 documents (4.0 kB)
Found index .opensearch-observability with 0...
Ransom notes :

{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0,003 BTC. Transfer to this BTC address 19pNR4MGshpXAaWxgPYGYtfn79dppP6FEH . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: mrserg@cock.li and you will receive a link to download your database dump.\n"}
            
Analysis helper :
                
estk --url=http://54.38.59.203:9200 list
            

ASN: 37963
22 events in 172 days
Leak size: 74.0 MB
Open ports: 9200
Indices: 4, document count: 9690, size: 74.0 MB
Found index .geoip_databases with 41 documents (40.9 MB)
Found index shop_info with 2729 document...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://120.55.180.34:9200 list
            

ASN: 14061
75 events in 1079 days
Leak size: 46.5 MB
Open ports: 9200
Indices: 5, document count: 40316, size: 46.5 MB
Found index .geoip_databases with 39 documents (38.8 MB)
Found index read_me with 1 documents (4...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.005 BTC to 16w2xEN9pcjFgECWH1LDVps4xV9m3nUMBN In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data5)After paying send mail to us: rambler+46vh@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 56VH"}
            
Analysis helper :
                
estk --url=http://157.230.231.120:9200 list
            

ASN: 40065
67 events in 489 days
Leak size: 100.6 MB
Open ports: 9212
Indices: 5, document count: 24838, size: 100.6 MB
Found index read_me with 1 documents (4.8 kB)
Found index insuser with 550 documents (197.8 kB)...
Ransom notes :

{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 1rsAp5FzhD6huVBjJEnLZxnQXU6EQmUvb . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
            
Analysis helper :
                
estk --url=http://23.224.91.228:9212 list
            

ASN: 51167
76 events in 675 days
Leak size: 32.2 MB
Open ports: 9200
Indices: 3, document count: 35, size: 32.2 MB
Found index .geoip_databases with 33 documents (32.2 MB)
Found index website with 1 documents (4.0 ...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+420wd@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 520WD"}
            
Analysis helper :
                
estk --url=http://185.194.217.214:9200 list
            

ASN: 9318
65 events in 1083 days
Leak size: 2.3 GB
Open ports: 9200
Indices: 86, document count: 3904550, size: 2.3 GB
Found index actuator_loggingconfig with 1 documents (4.0 kB)
Found index read_me with 1 docume...
Ransom notes :

{"took":0,"timed_out":false,"_shards":{"total":5,"successful":5,"skipped":0,"failed":0},"hits":{"total":1,"max_score":1.0,"hits":[{"_index":"read-me","_type":"_doc","_id":"1MacJooBY9kUd17URRg3","_score":1.0,"_source":{"message": "We deleted all databases, but download a copy to our server. The only way of recovery is you must send 0.015 BTC to 1BAW8LmC6bEg1Sjsq1dWpqezVT7EvAqQS9 You have until 48 hours to pay or data will be inaccesible. Once paid email Backups@onionmail.org with code: 'PT53hm' and we will recover your database. please read https://paste.sh/IOMBsAEl#XzwHcDCsND_DJkEuWMkeqlao for more information"}}]}}
            
Analysis helper :
                
estk --url=http://210.219.173.135:9200 list
            

ASN: 16276
28 events in 207 days
Leak size: 9.1 kB
Open ports: 9200
Indices: 3, document count: 2, size: 9.1 kB
Found index .plugins-ml-config with 1 documents (4.0 kB)
Found index .opensearch-observability with 0...
Ransom notes :

{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0,003 BTC. Transfer to this BTC address 19pNR4MGshpXAaWxgPYGYtfn79dppP6FEH . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: mrserg@cock.li and you will receive a link to download your database dump.\n"}
            
Analysis helper :
                
estk --url=http://54.38.59.195:9200 list
            

ASN: 45820
26 events in 192 days
Leak size: 32.2 MB
Open ports: 9200
Indices: 2, document count: 34, size: 32.2 MB
Found index .geoip_databases with 33 documents (32.2 MB)
Found index read_me with 1 documents (5.4 ...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.0057 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://49.249.180.244:9200 list
            

ASN: 399334
59 events in 383 days
Leak size: 5.1 kB
Open ports: 9200
Indices: 1, document count: 1, size: 5.1 kB
Found index read_me with 1 documents (5.1 kB)
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://64.52.108.93:9200 list
            

ASN: 14061
45 events in 276 days
Leak size: 35.5 MB
Open ports: 9200
Indices: 4, document count: 2706, size: 35.5 MB
Found index .geoip_databases with 33 documents (32.2 MB)
Found index read_me with 1 documents (4....
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4sh47@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5SH47"}
            
Analysis helper :
                
estk --url=http://68.183.46.189:9200 list
            

ASN: 16276
70 events in 445 days
Leak size: 74.6 MB
Open ports: 9200
Indices: 63, document count: 58440, size: 74.6 MB
Found index magento2_default_izotoniade_catalog_product_20240603_200059 with 0 documents (226 B...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+44wj6@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 54WJ6"}
            
Analysis helper :
                
estk --url=http://54.38.61.130:9200 list
            

ASN: 45090
33 events in 418 days
Leak size: 44.6 kB
Open ports: 9200
Indices: 6, document count: 5, size: 44.6 kB
Found index read-me with 1 documents (5.1 kB)
Found index test with 1 documents (4.6 kB)
Found index...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://81.69.0.195:9200 list
            

ASN: 8075
74 events in 489 days
Leak size: 94.3 MB
Open ports: 9200
Indices: 3, document count: 151479, size: 94.3 MB
Found index .geoip_databases with 36 documents (39.0 MB)
Found index mosaic-services-log with 1...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0063 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4f5wy@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5F5WY"}
            
Analysis helper :
                
estk --url=http://20.127.133.89:9200 list
            

ASN: 14061
61 events in 464 days
Leak size: 12.7 MB
Open ports: 9200
Indices: 2, document count: 1085, size: 12.7 MB
Found index product with 1084 documents (12.7 MB)
Found index read-me with 1 documents (5.3 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://163.47.10.254:9200 list
            

ASN: 51167
76 events in 834 days
Leak size: 36.4 MB
Open ports: 9200
Indices: 5, document count: 12669, size: 36.4 MB
Found index .geoip_databases with 33 documents (32.2 MB)
Found index product with 12204 document...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4md21@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5MD21"}
            
Analysis helper :
                
estk --url=http://194.163.154.100:9200 list