+plugin:KafkaOpenPlugin
{
"apiUrl": "https://newdemo.nguvu.com:443",
"debug": false,
"imagesProxyUrl": "https://newdemo.nguvu.com:443/secure_image",
"requestHead...
Found by KafkaOpenPlugin ConfigJsonHttp
Indices: 21, document count: 24672, size: 58.9 MB
Found index zms with 0 documents (795 B)
Found index website with 0 documents (795 B)
Found ind...
Analysis helper :
estk --url=http://182.254.242.57:9200 list
Indices: 10, document count: 26170, size: 62.9 MB
Found index a with 0 documents (208 B)
Found index server with 1 documents (4.7 kB)
Found index...
Analysis helper :
estk --url=http://54.74.231.66:9200 list
Found PHP info page:
$_SERVER['HTTP_HOST'] = 70.35.202.145
$_SERVER['HTTP_USER_AGENT'] = l9explore/1.3.0
$_SERVER['HTTP_ACCEPT_ENCODING'] = gzip
...
Indices: 19, document count: 33498823, size: 6.6 GB
Found index logstash-2021.12.31 with 5671 documents (1.0 MB)
Found index logstash-2021.12.30 ...
Analysis helper :
estk --url=http://95.111.246.186:9200 list
Indices: 8, document count: 4, size: 27.9 kB
Found index .kibana_1 with 2 documents (8.8 kB)
Found index tweets with 0 documents (1.3 kB)
Found i...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://34.224.182.213:9200 list
Indices: 6, document count: 28403, size: 10.8 MB
Found index order_tracing_test with 0 documents (283 B)
Found index mfplatformarea with 3211 doc...
Analysis helper :
estk --url=http://117.78.42.35:9200 list
Found 1 files trough .DS_Store spidering:
/assets
Indices: 1833, document count: 510098822, size: 124.7 GB
Found index stat-sample_20-04-01_denstv with 453 documents (111.2 kB)
Found index stat-s...
Analysis helper :
estk --url=http://202.158.99.98:9200 list
Indices: 56, document count: 3441424, size: 1.4 GB
Through Kibana endpoint
Found index tqh5uxu74u-meow with 0 documents (283 B)
Found index .moni...
Analysis helper :
estk --url=http://39.98.86.87:5601 list
Indices: 7, document count: 5600041, size: 2.7 GB
Found index watchman_fire_alarm with 10 documents (79.3 kB)
Found index read__me with 1 documen...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1CzVYhJnL6MrZVG8qpDQLtMqDWBX8R2mfS 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://47.99.185.5:9200 list
Collections: 1, document count: 0, size: 0 B
Found collection READ_ME_TO_RECOVER_YOUR_DATA.README
Analysis helper :
echo 'show dbs' | mongo --host 114.67.176.148 --port 27017
Indices: 329, document count: 4099260478, size: 1.6 TB
Found index irdc_2022.05.09 with 13914745 documents (2.1 GB)
Found index irdc_2022.05.08 w...
Analysis helper :
estk --url=http://221.228.80.164 list
Indices: 49, document count: 3056, size: 1.9 MB
Found index datajobindex_v2 with 2 documents (24.8 kB)
Found index mlmodelgroupindex_v2 with 0 do...
Analysis helper :
estk --url=http://167.172.172.239:9200 list
{
"errorCode": null,
"errorMessage": "No database specified",
"responseObject": {},
"success": false,
"successMessage": null
}
Indices: 145, document count: 67, size: 394.9 kB
Found index magmi with 0 documents (795 B)
Found index casa with 0 documents (795 B)
Found index...
Analysis helper :
estk --url=http://52.55.123.178:9200 list
Indices: 13, document count: 57609, size: 17.0 MB
Found index fenbu with 0 documents (810 B)
Found index address with 881 documents (367.3 kB)
Fo...
Analysis helper :
estk --url=http://47.107.228.143:9200 list
Found Wordpress users (CVE-2017-5487):
User #1 gonboy
Name: Gonboy
Url:
Found by KafkaOpenPlugin WpUserEnumHttp
Indices: 4, document count: 4651, size: 781.2 kB
Found index read__me with 1 documents (5.2 kB)
Found index chat with 892 documents (133.5 kB)
Fo...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://159.65.124.178:9200 list
Indices: 5, document count: 117, size: 446.3 kB
Found index a with 0 documents (208 B)
Found index server with 1 documents (4.4 kB)
Found index a...
Analysis helper :
estk --url=http://152.136.220.130:9200 list