+plugin:MongoWeakPlugin
AWS_ACCESS_KEY_ID=ASIAXM7G6SIWNC6IBWGS
AWS_SECRET_ACCESS_KEY=SkqQfX4PG2t9suq/2N34zSX407kAGfOYV3lHBpSS
AWS_SESSION_TOKEN=IQoJb3JpZ2luX2VjECQaCWV...
Found Wordpress users (CVE-2017-5487):
User #1 user
Name: user
Url:
Collections: 4, document count: 8, size: 3.0 kB
Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 2 documents (1.5 kB)
Found collection ...
Analysis helper :
echo 'show dbs' | mongo --host 13.58.150.149 --port 27017
Collections: 8, document count: 13436, size: 11.5 MB
Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 1 documents (738 B)
Found collect...
Analysis helper :
echo 'show dbs' | mongo --host 173.224.114.226 --port 27017
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = https://github.com/ucool99/u...
Found 2 collections:
Found collection "system.version"
Found collection "system.users"
Analysis helper :
echo 'show dbs' | mongo --host 18.212.223.210 --port 27017
Collections: 5, document count: 0, size: 0 B
Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 0 documents (0 B)
Found collection READ__...
Analysis helper :
echo 'show dbs' | mongo --host 178.128.127.138 --port 27017
Found 1 collections:
Found collection "system.version"
Analysis helper :
echo 'show dbs' | mongo --host 60.250.240.55 --port 27017
Collections: 9, document count: 5219, size: 8.2 MB
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (744 B)
Found collecti...
Analysis helper :
echo 'show dbs' | mongo --host 92.38.184.158 --port 27017
Collections: 3, document count: 2, size: 803 B
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (744 B)
Found collection a...
Analysis helper :
echo 'show dbs' | mongo --host 82.208.58.237 --port 27017
Found 3 collections:
Found collection "system.version"
Found collection "system.indexes"
Found collection "system.users"
Analysis helper :
echo 'show dbs' | mongo --host 107.170.10.108 --port 27017
Collections: 1, document count: 1, size: 738 B
Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 1 documents (738 B)
Analysis helper :
echo 'show dbs' | mongo --host 188.131.188.62 --port 27017
Collections: 6, document count: 96, size: 9.0 kB
Found collection READ_ME_TO_RECOVER_YOUR_DATA.README with 1 documents (729 B)
Found collection ...
Analysis helper :
echo 'show dbs' | mongo --host 161.35.103.85 --port 27017
Collections: 3, document count: 4, size: 948 B
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (745 B)
Found collection a...
Analysis helper :
echo 'show dbs' | mongo --host 134.209.85.70 --port 27017
Collections: 8, document count: 12, size: 4.6 kB
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (744 B)
Found collection...
Analysis helper :
echo 'show dbs' | mongo --host 52.78.132.238 --port 27017
Collections: 4, document count: 5, size: 1.5 kB
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (745 B)
Found collection ...
Analysis helper :
echo 'show dbs' | mongo --host 165.227.133.248 --port 27017
Indices: 1, document count: 1, size: 5.0 kB
Found index read__me with 1 documents (5.0 kB)
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://121.199.72.15:9200 list
Found 1 collections:
Found collection "system.version"
Analysis helper :
echo 'show dbs' | mongo --host 60.250.234.223 --port 27017
Found PHP info page:
$_SERVER['HTTP_AUTHORIZATION'] = no value
$_SERVER['HTTPS'] = on
$_SERVER['HTTP_HOST'] = 85.25.8.51
$_SERVER['HTTP_USER_AGEN...
Found Wordpress users (CVE-2017-5487):
User #1 admin
Name: admin
Url: https://kaden.pitpa.jp