+port:"80" +asn:"14061" -ip:"128.199.0.0/16" +plugin:"ElasticSearchOpenPlugin"
Indices: 83, document count: 5651, size: 20.0 MB
Found index series-test-ren with 7 documents (45.2 kB)
Found index payments-test- with 94 docume...
Analysis helper :
estk --url=http://elasticsearch5.apps.mobyinc.com list
Found by ElasticSearchOpenPlugin
Indices: 25, document count: 1979089, size: 2.2 GB
Found index casa with 0 documents (208 B)
Found index discontinued_data with 64302 documents (...
Analysis helper :
estk --url=http://opticomsearch.com list
Found by ElasticSearchOpenPlugin
Indices: 75, document count: 7555, size: 61.2 MB
Found index wn0sdwk0003c1-event-da-dk with 2 documents (32.5 kB)
Found index desktop-21lggaf-con...
Analysis helper :
estk --url=http://stromlin-es.test.headnet.dk list
Found by ElasticSearchOpenPlugin
Indices: 14, document count: 5112, size: 59.9 MB
Found index casa with 0 documents (227 B)
Found index mm_all_system with 2190 documents (9.5 MB)...
Ransom notes :
{"readme":"Sorry, we have taken your files from this server and deleted your copy. If you wish to recover your files you will need to pay our price. You will need to make payment by bitcoin. If you do not know how to purchase bitcoin we suggest you google it, prominent exchanges that are easy to use are Kraken, Moonpay, and Cashapp. You will need to send 250 US dollars worth of bitcoin to the following address: 16fnSdjwpPUNnphTvL4Nsw98uJDcETKr1v .Once you have sent the bitcoin send an email to ghostransom@onionmail.org with the bitcoin transaction id, and we will send you a copy of all of your data from this server. Any attempt to negotiate with us or contact us before payment will simply result in deletion of your data."}
Analysis helper :
estk --url=http://orchestration-platform-staging.solomon-ai.dev list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 49, size: 39.3 MB
Found index .geoip_databases with 40 documents (39.2 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.0051 BTC to bc1qrgjl5utvde5cu6un7sudxrjt8v6yu7p8hz4hdr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://2info.win/ela)After paying send mail to us: rambler+5sy25@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5SY25"}
Analysis helper :
estk --url=http://elasticsearch.onfleekq.com list
Found by ElasticSearchOpenPlugin
Indices: 4, document count: 1253810, size: 475.8 MB
Found index locations with 1246421 documents (407.2 MB)
Found index properties_with_error wit...
Analysis helper :
estk --url=https://elasticsearch.portal-imob.flip.eurekahomolog.xyz:80 list
Found by ElasticSearchOpenPlugin
Indices: 349, document count: 231339893, size: 104.7 GB
Through Kibana endpoint
Found index filebeat-debug-7.4.2-2025.03.15 with 137028 documents...
Analysis helper :
estk --url=http://152.42.156.243 list
Found by ElasticSearchOpenPlugin
Indices: 18, document count: 12387, size: 44.8 MB
Found index v1.24 with 1 documents (9.5 kB)
Found index internal with 1 documents (6.7 kB)
Foun...
Analysis helper :
estk --url=http://146.190.233.111 list
Found by ElasticSearchOpenPlugin
Indices: 14, document count: 5112, size: 60.2 MB
Found index casa with 0 documents (227 B)
Found index mm_all_system with 2190 documents (9.5 MB)...
Ransom notes :
{"readme":"Sorry, we have taken your files from this server and deleted your copy. If you wish to recover your files you will need to pay our price. You will need to make payment by bitcoin. If you do not know how to purchase bitcoin we suggest you google it, prominent exchanges that are easy to use are Kraken, Moonpay, and Cashapp. You will need to send 250 US dollars worth of bitcoin to the following address: 16fnSdjwpPUNnphTvL4Nsw98uJDcETKr1v .Once you have sent the bitcoin send an email to ghostransom@onionmail.org with the bitcoin transaction id, and we will send you a copy of all of your data from this server. Any attempt to negotiate with us or contact us before payment will simply result in deletion of your data."}
Analysis helper :
estk --url=http://159.203.163.244 list
Found by ElasticSearchOpenPlugin
Indices: 23, document count: 7237842, size: 870.6 MB
Found index casa with 0 documents (226 B)
Found index pvt-ex-staging-2025.04.21 with 60 docu...
Ransom notes :
{"readme":"Sorry, we have taken your files from this server and deleted your copy. If you wish to recover your files you will need to pay our price. You will need to make payment by bitcoin. If you do not know how to purchase bitcoin we suggest you google it, prominent exchanges that are easy to use are Kraken, Moonpay, and Cashapp. You will need to send 250 US dollars worth of bitcoin to the following address: 16fnSdjwpPUNnphTvL4Nsw98uJDcETKr1v .Once you have sent the bitcoin send an email to ghostransom@onionmail.org with the bitcoin transaction id, and we will send you a copy of all of your data from this server. Any attempt to negotiate with us or contact us before payment will simply result in deletion of your data."}
Analysis helper :
estk --url=http://206.189.47.19 list
Found by ElasticSearchOpenPlugin
Indices: 25, document count: 1979089, size: 2.2 GB
Found index casa with 0 documents (208 B)
Found index discontinued_data with 64302 documents (...
Analysis helper :
estk --url=http://159.65.213.22 list
Found by ElasticSearchOpenPlugin
Indices: 15, document count: 624005537, size: 109.8 GB
Through Kibana endpoint
Found index .ds-logs-generic-default-2024.07.09-000023 with 505463...
Analysis helper :
estk --url=http://167.99.135.190 list
Found by ElasticSearchOpenPlugin
Indices: 31, document count: 3281, size: 61.9 MB
Found index v1.24 with 1 documents (9.4 kB)
Found index internal with 1 documents (6.5 kB)
Found...
Analysis helper :
estk --url=http://147.182.154.9 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 242902, size: 43.7 MB
Found index gipe_plano_contas with 242900 documents (43.7 MB)
Found index read-me with 2 docume...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `aVonh3` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://209.38.4.189 list
Found by ElasticSearchOpenPlugin
Indices: 15, document count: 1218, size: 1.0 MB
Through Kibana endpoint
Found index .internal.alerts-transform.health.alerts-default-000001 with ...
Analysis helper :
estk --url=http://kibana.kunmhing.me list
Found by ElasticSearchOpenPlugin
Indices: 4, document count: 10, size: 78.3 kB
Through Kibana endpoint
Found index .apm-custom-link with 0 documents (208 B)
Found index .kibana_t...
Analysis helper :
estk --url=https://kibana.stg.azship.com.br:80 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 6215339, size: 3.9 GB
Through Kibana endpoint
Found index yente-entities-default-00920241208065302-gdo with 3851339 d...
Analysis helper :
estk --url=http://159.203.28.123 list
Found by ElasticSearchOpenPlugin
Indices: 302, document count: 1980167, size: 424.8 MB
Found index i-006e9effd55b8676d-stage2-2025-01-06-database with 22250 documents (1.7 MB)
Fo...
Analysis helper :
estk --url=http://es.taanaestore.com list
Found by ElasticSearchOpenPlugin
Indices: 17, document count: 8888, size: 31.2 MB
Found index wsi with 70 documents (866.6 kB)
Found index s3 with 9 documents (188.3 kB)
Found in...
Analysis helper :
estk --url=https://es.hub.eicon.ai:80 list
Found by ElasticSearchOpenPlugin
Indices: 18, document count: 101651, size: 571.7 MB
Through Kibana endpoint
Found index users with 69 documents (131.9 kB)
Found index .internal....
Analysis helper :
estk --url=https://kibana-data.aduhay.dev:80 list
Found by ElasticSearchOpenPlugin