+plugin:KafkaOpenPlugin +country:"Germany"
Indices: 10, document count: 806, size: 2.0 MB
Found index logs-2022.06.26 with 36 documents (269.6 kB)
Found index logs-2022.06.27 with 27 docum...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 15BdJyWiWRcNQY4xBuhJrmjqz7ZQD6zAcT . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://2.56.98.96:9200 list
Indices: 3, document count: 1, size: 8.1 kB
Found index read_me with 1 documents (5.5 kB)
Found index energy_metrics with 0 documents (1.3 kB)
Fo...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 15BdJyWiWRcNQY4xBuhJrmjqz7ZQD6zAcT . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://173.249.10.240:9200 list
{"users":"http://94.237.86.110/users.json","profiles":"http://94.237.86.110/posts_likes.json","promo_codes":"http://94.237.86.110/posts_likes.jso...
Apache Status
Apache Server Status for 159.69.222.74 (via 159.69.222.74)
Server Version: Apache/2.4.41 (Ubuntu) mod_fcgid/2.3.9 OpenSSL/1.1.1f...
8499
Found by KafkaOpenPlugin ConfigJsonHttp
Found 10 files trough .DS_Store spidering:
/bootstrap
/bootstrap/css
/chartjs
/datepicker
/font-awesome
/img
/jquery
/metisMenu
/momentjs
/morri...
Found Wordpress users (CVE-2017-5487):
User #1 download
Name: download
Url: http://download.hellowp.dev
Found PHP info page:
$_SERVER['USER'] = weebuilder
$_SERVER['HOME'] = /home/weebuilder
$_SERVER['HTTP_CONNECTION'] = close
$_SERVER['HTTP_ACCEPT_...
Indices: 4, document count: 6607, size: 1.1 MB
Found index read__me with 1 documents (5.2 kB)
Found index chat with 1032 documents (164.2 kB)
Fou...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://159.65.126.221:9200 list
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = https://github.com/thrymrsof...
Found public CheckMk agent:
Version: 1.6.0p13
AgentOS: linux
Hostname: tstaiosv001
AgentDirectory: /etc/check_mk
DataDirectory: /var/lib/check_mk...
Found public CheckMk agent:
Version: 1.6.0p13
AgentOS: linux
Hostname: devwebsv001
AgentDirectory: /etc/check_mk
DataDirectory: /var/lib/check_mk...
Found open SMB shares with NT AUTHORITY/ANONYMOUS LOGON
Anonymous
IPC$
Found by KafkaOpenPlugin SmbPlugin
Collections: 3, document count: 2, size: 804 B
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (745 B)
Found collection a...
Analysis helper :
echo 'show dbs' | mongo --host 104.248.138.152 --port 27017
Found Wordpress users (CVE-2017-5487):
User #1 admin
Name: admin
Url: https://www.cikotvau.com
Indices: 61, document count: 2034294, size: 1.9 GB
Through Kibana endpoint
Found index humantic-voyager-normalized-versioning with 414 documents ...
Analysis helper :
estk --url=http://116.202.217.109:5601 list
Found Wordpress users (CVE-2017-5487):
User #1 user
Name: user
Url: http://127.0.0.1
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = https://ghp_lWDulI4jJyM2NfVi...
Found Wordpress users (CVE-2017-5487):
User #1 pantanobermejales
Name: pantanobermejales
Url: https://bermejalescanalcacin.com
Found by KafkaOpenPlugin WpUserEnumHttp
Indices: 17, document count: 34412, size: 288.1 MB
Through Kibana endpoint
Found index .triggered_watches with 20 documents (48.9 MB)
Found index...
Analysis helper :
estk --url=http://167.86.69.219:5601 list