+plugin:KafkaOpenPlugin +net:"Shenzhen Tencent Computer Systems Company Limited"
Indices: 6, document count: 7, size: 43.6 kB
Found index v2 with 1 documents (8.0 kB)
Found index api with 2 documents (11.9 kB)
Found index v1 w...
Analysis helper :
estk --url=http://119.45.187.98:9200 list
Indices: 18, document count: 1196048, size: 847.5 MB
Found index .monitoring-kibana-7-2022.06.25 with 14127 documents (3.1 MB)
Found index .monit...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 14b57thKoPjmVVkh6HHLPz8g7fyBJ5SEcr . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://49.235.160.172:9200 list
Indices: 11, document count: 13142, size: 6.8 MB
Through Kibana endpoint
Found index actuator with 1 documents (4.7 kB)
Found index auth with 1 d...
Analysis helper :
estk --url=http://118.89.39.13:5601 list
Indices: 21, document count: 1080, size: 109.7 MB
Found index apitesting with 0 documents (208 B)
Found index gatewayapilist with 1 documents (6....
Analysis helper :
estk --url=http://62.234.69.182:9200 list
Indices: 1, document count: 0, size: 810 B
Found index read_me with 0 documents (810 B)
Analysis helper :
estk --url=http://49.235.109.229:9200 list
Indices: 22, document count: 26458, size: 64.5 MB
Found index zms with 0 documents (795 B)
Found index website with 0 documents (795 B)
Found ind...
Analysis helper :
estk --url=http://182.254.242.57:9200 list
Found 6 files trough .DS_Store spidering:
/favicon.ico
/img
/static
/static/css
/static/js
/static/media
Indices: 5, document count: 3526, size: 1.3 MB
Found index llnb-2022-06 with 27 documents (372.4 kB)
Found index .watches with 0 documents (191 B...
Analysis helper :
estk --url=http://139.199.125.118:9200 list
Collections: 1, document count: 2, size: 1.5 kB
Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 2 documents (1.5 kB)
Analysis helper :
echo 'show dbs' | mongo --host 49.232.118.59 --port 27017
{"stateCode":-1,"resultInfo":{"desc":"无效Token: 错误或过期"}}
Found by KafkaOpenPlugin ConfigJsonHttp
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = https://gitee.com/jking/Micr...
Indices: 5, document count: 117, size: 446.3 kB
Found index a with 0 documents (208 B)
Found index server with 1 documents (4.4 kB)
Found index a...
Analysis helper :
estk --url=http://152.136.220.130:9200 list
Found 4 collections:
Found collection "system.users"
Found collection "SRM_V4_SYSLOG_INPUT"
Found collection "SRM_V4_SYSLOG_OUTPUT"
Found collect...
Analysis helper :
echo 'show dbs' | mongo --host 106.55.40.190 --port 27017
Found 2 collections:
Found collection "system.users"
Found collection "system.version"
Analysis helper :
echo 'show dbs' | mongo --host 49.235.207.25 --port 27017
Found 1 collections:
Found collection "system.version"
Analysis helper :
echo 'show dbs' | mongo --host 123.207.71.77 --port 27017
Collections: 1, document count: 0, size: 0 B
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README
Analysis helper :
echo 'show dbs' | mongo --host 212.64.77.25 --port 27017
Indices: 6, document count: 6, size: 30.3 kB
Through Kibana endpoint
Found index read-me-hacked-by-nightlionsecurity-m81tg6 with 1 documents (5.2...
Analysis helper :
estk --url=http://115.159.22.62:5601 list
Indices: 39, document count: 130830, size: 21.2 MB
Found index casa with 0 documents (283 B)
Found index voc_chatrecord with 0 documents (283 B)
...
Analysis helper :
estk --url=http://118.25.145.143:9200 list
Collections: 2, document count: 0, size: 0 B
Found collection READ_ME_TO_RECOVER_YOUR_DATA.RREADME
Found collection READ_ME_TO_RECOVER_YOUR_DATA...
Analysis helper :
echo 'show dbs' | mongo --host 134.175.132.194 --port 27017
Found PHP info page:
$_SERVER['USER'] = www-data
$_SERVER['HOME'] = /var/www
$_SERVER['HTTP_CONNECTION'] = close
$_SERVER['HTTP_ACCEPT_ENCODING']...