+plugin:KafkaOpenPlugin +l9fp:"d606b92f1b5fdf18218cad2d218cad2d218cad2d218cad2d218cad2d1e418044"
Redis is open
Redis is open
Redis is open
Found by KafkaOpenPlugin RedisOpenPlugin
Collections: 3, document count: 2, size: 804 B
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (745 B)
Found collection a...
Analysis helper :
echo 'show dbs' | mongo --host 104.248.138.152 --port 27017
Collections: 1, document count: 2, size: 1.5 kB
Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 2 documents (1.5 kB)
Analysis helper :
echo 'show dbs' | mongo --host 49.232.118.59 --port 27017
Indices: 15, document count: 4672, size: 5.0 MB
Found index artist with 383 documents (104.9 kB)
Found index album with 686 documents (181.6 kB)
...
Analysis helper :
estk --url=http://161.97.73.165:9200 list
Redis is open
Redis is open
Redis is open
Collections: 2, document count: 0, size: 0 B
Found collection READ_ME_TO_RECOVER_YOUR_DATA.RREADME
Found collection READ_ME_TO_RECOVER_YOUR_DATA...
Analysis helper :
echo 'show dbs' | mongo --host 134.175.132.194 --port 27017
Redis is open
Found Wordpress users (CVE-2017-5487):
User #1 shamsher
Name: Shamsher Ahmed
Url: http://52.172.38.99/
Redis is open
Found by KafkaOpenPlugin RedisOpenPlugin
Indices: 6, document count: 3469, size: 593.1 kB
Found index api with 1 documents (5.4 kB)
Found index directdata with 1 documents (7.0 kB)
Found...
Analysis helper :
estk --url=http://8.135.4.217:9200 list
Indices: 6, document count: 2805, size: 541.5 kB
Found index api with 1 documents (5.4 kB)
Found index directdata with 1 documents (7.0 kB)
Found...
Analysis helper :
estk --url=http://8.135.32.45:9200 list
Indices: 42, document count: 414, size: 1.5 MB
Found index 528ef5a9-22cb-4149-9686-954c7f2e97ca-node-systemlog-2021.09.06 with 29 documents (27.0...
Analysis helper :
estk --url=http://148.70.31.101:9200 list
Indices: 58, document count: 11597377, size: 3.9 GB
Found index exc-2021.05.13 with 215473 documents (72.1 MB)
Found index exc-2021.05.12 with 23...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://118.24.122.119:9200 list
Redis is open
Found 9 collections:
Found collection "beart_beat_data"
Found collection "charging_bms"
Found collection "charging_curve"
Found collection "gun_s...
Analysis helper :
echo 'show dbs' | mongo --host 119.23.233.186 --port 27017
Redis is open
Found by KafkaOpenPlugin RedisOpenPlugin