+plugin:RedisOpenPlugin
AWS_ACCESS_KEY_ID=ASIAXM7G6SIWIYPPI4UO
AWS_SECRET_ACCESS_KEY=KzOM6Guk09iQ3EyWCrPIJ1gs42ncAq6R5MfePtKy
AWS_SESSION_TOKEN=IQoJb3JpZ2luX2VjECQaCWF...
Found by RedisOpenPlugin DotEnvHttpPlugin
AWS_ACCESS_KEY_ID=ASIAXM7G6SIWP6BCETXU
AWS_SECRET_ACCESS_KEY=c/DNKCCI6JWT/2W247t7gyhmRdYIeX09PT8/cOe1
AWS_SESSION_TOKEN=IQoJb3JpZ2luX2VjEOH////...
Found by RedisOpenPlugin DotEnvHttpPlugin
Collections: 3, document count: 3, size: 849 B
Found collection READ__ME_TO_RECOVER_YOUR_DATA.README with 1 documents (745 B)
Found collection a...
Analysis helper :
echo 'show dbs' | mongo --host 13.114.238.183 --port 27017
AWS_ACCESS_KEY_ID=ASIAVGJQ4XTVHJ3UTZEW
AWS_SECRET_ACCESS_KEY=wo1yCWxxWYcIY1JtqWTM9W+yXFwGHK/kJ/mY5+4u
AWS_SESSION_TOKEN=IQoJb3JpZ2luX2VjECMaCmV...
Found by RedisOpenPlugin DotEnvHttpPlugin
Redis is open
Found by RedisOpenPlugin
Found PAN-OS web frontend
Last update: 9/2019
Version: 9.0.4
Affected by CVE-2020-2034
Affected by CVE-2020-2021
Found by RedisOpenPlugin PaloAltoPlugin
Found PHP info page:
$_SERVER['HTTP_HOST'] = 52.67.183.59
$_SERVER['HTTP_USER_AGENT'] = l9explore/1.3.0
$_SERVER['HTTP_ACCEPT_ENCODING'] = gzip
$...
Indices: 14, document count: 111014538, size: 17.7 GB
Found index read__me with 1 documents (4.8 kB)
Found index .apm-agent-configuration with 0 ...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.015 BTC to 1PpLEwVd35mrb7qzZtgNhkcF8JjxrsNEX5 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com with this guide https://localbitcoins.com/guides/how-to-buy-bitcoins After paying write to me in the mail with your DB IP: allmydataback@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://104.168.157.10:9200 list
Redis is open
Found by RedisOpenPlugin
Redis is open
Found by RedisOpenPlugin
Redis is open
Found by RedisOpenPlugin
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = git@gitlab.meetlan.com:donat...
Indices: 7, document count: 75, size: 368.8 kB
Found index v1 with 1 documents (7.6 kB)
Found index admin with 1 documents (5.7 kB)
Found index a...
Analysis helper :
estk --url=http://115.159.36.155:9200 list
Indices: 52, document count: 7514579, size: 5.1 GB
Found index etc_passwd with 2 documents (6.5 kB)
Found index logon with 2 documents (8.8 kB)
F...
Analysis helper :
estk --url=http://210.219.173.135:9200 list
Found PHP info page:
$_SERVER['USER'] = www-data
$_SERVER['HOME'] = /var/www
$_SERVER['HTTP_CONNECTION'] = close
$_SERVER['HTTP_ACCEPT_ENCODING']...
Redis is open
Found by RedisOpenPlugin
AWS_ACCESS_KEY_ID=ASIAVGJQ4XTVNYGZENFO
AWS_SECRET_ACCESS_KEY=0jr0Gun4igJ6P0sIPgwLxhjXPR4lu4DFJuxB4CGr
AWS_SESSION_TOKEN=IQoJb3JpZ2luX2VjEBsaCmF...
Found by RedisOpenPlugin DotEnvHttpPlugin
Databases: 1, row count: 0, size: 0 B
Found table . with 0 records
Analysis helper :
mysql -h45.79.90.143 -uroot -e"SELECT TABLE_SCHEMA, TABLE_NAME, TABLE_ROWS, DATA_LENGTH from information_schema.TABLES where table_schema != 'information_schema' AND table_schema != 'sys' AND table_schema != 'performance_schema';"
Databases: 1, row count: 0, size: 0 B
Found table . with 0 records
Analysis helper :
mysql -h172.105.172.220 -uroot -e"SELECT TABLE_SCHEMA, TABLE_NAME, TABLE_ROWS, DATA_LENGTH from information_schema.TABLES where table_schema != 'information_schema' AND table_schema != 'sys' AND table_schema != 'performance_schema';"
Found PHP info page:
$_SERVER['HTTP_HOST'] = 209.250.230.10
$_SERVER['HTTP_USER_AGENT'] = l9explore/1.3.0
$_SERVER['HTTP_ACCEPT_ENCODING'] = gzip...