By searching for results, you agree with our Terms of service
Found 2239 results for
+plugin:ElasticSearchOpenPlugin -ip:"124.220.0.0/14" +events.leak.severity:"medium" +asn:"8075"

Looking for more results ? Register a free account

Countries

  • United States 947
  • The Netherlands 410
  • India 177
  • Singapore 103
  • Ireland 94
  • France 67
  • United Kingdom 65
  • Hong Kong 59
  • Australia 47
  • Germany 46

Sources

  • ElasticSearchOpenPlugin 2239

Network

  • MICROSOFT-CORP-MSN-AS-BLOCK 2238
  • T-Systems International GmbH 1

IP Ranges

  • 20.64.0.0/10 517
  • 20.192.0.0/10 473
  • 20.0.0.0/11 147
  • 13.64.0.0/11 117
  • 52.160.0.0/11 103
  • 20.48.0.0/12 73
  • 52.224.0.0/11 72
  • 4.192.0.0/10 58
  • 172.128.0.0/10 34
  • 52.136.0.0/13 32

ASN: 8075
46 events in 769 days
Leak size: 46.0 kB
Open ports: 9200
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://104.211.190.127:9200 list
            

ASN: 8075
65 events in 379 days
Leak size: 34.8 MB
Open ports: 9200
Indices: 14, document count: 982, size: 34.8 MB
Found index lsbfx-dev_product_5_v62 with 79 documents (219.9 kB)
Found index read_me with 1 docum...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4nuvx@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5NUVX"}
            
Analysis helper :
                
estk --url=http://20.205.235.157:9200 list
            

ASN: 8075
72 events in 485 days
Leak size: 35.9 MB
Open ports: 9200
Indices: 2, document count: 38, size: 35.9 MB
Found index .geoip_databases with 37 documents (35.9 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0063 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4lg8z@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5LG8Z"}
            
Analysis helper :
                
estk --url=http://40.117.88.175:9200 list
            

ASN: 8075
32 events in 248 days
Leak size: 11.2 kB
Open ports: 9200
Indices: 2, document count: 2, size: 11.2 kB
Found index read-me with 1 documents (4.2 kB)
Found index .kibana_1 with 1 documents (6.9 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://20.7.121.173:9200 list
            

ASN: 8075
70 events in 481 days
Leak size: 11.4 kB
Open ports: 9200
Indices: 2, document count: 2, size: 11.4 kB
Found index read-me with 1 documents (4.3 kB)
Found index .kibana_1 with 1 documents (7.1 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://52.172.197.226:9200 list
            

ASN: 8075
68 events in 676 days
Leak size: 797.3 MB
Open ports: 9200
Indices: 18, document count: 1438205, size: 797.3 MB
Found index .kibana_task_manager with 2 documents (23.5 kB)
Found index read_me with 1 docum...
Ransom notes :

{"message":"All your data is a backed up. You must pay 0.06 BTC to 16wrRb6vMi2py5rggYhdRNT2eUDdqTRS5V 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ After paying write to me in the mail with your DB IP: rambler+3au5x@onionmail.org and/or eladb@mailnesia.com and you will receive a link to download your database dump."}
            
Analysis helper :
                
estk --url=http://20.219.180.254:9200 list
            

ASN: 8075
26 events in 205 days
Leak size: 35.9 MB
Open ports: 9200
Indices: 2, document count: 38, size: 35.9 MB
Found index .geoip_databases with 37 documents (35.9 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0063 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+49a7l@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 59A7L"}
            
Analysis helper :
                
estk --url=http://20.232.202.46:9200 list
            

ASN: 8075
64 events in 890 days
Leak size: 71.9 MB
Open ports: 9200
Indices: 5, document count: 359037, size: 71.9 MB
Found index .geoip_databases with 41 documents (44.4 MB)
Found index read_me with 1 documents (...
Ransom notes :

{"message":"All your data is a backed up. You must pay 0.06 BTC to 16wrRb6vMi2py5rggYhdRNT2eUDdqTRS5V 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ After paying write to me in the mail with your DB IP: rambler+3la99@onionmail.org and/or eladb@mailnesia.com and you will receive a link to download your database dump."}
            
Analysis helper :
                
estk --url=http://20.86.119.37:9200 list
            

ASN: 8075
66 events in 1074 days
Leak size: 10.6 kB
Open ports: 9200
Indices: 2, document count: 2, size: 10.6 kB
Found index read-me with 1 documents (4.0 kB)
Found index .kibana_1 with 1 documents (6.6 kB)
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://52.242.37.91:9200 list
            

ASN: 8075
59 events in 888 days
Leak size: 46.0 kB
Open ports: 9200
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://13.77.204.229:9200 list
            

ASN: 8075
23 events in 170 days
Leak size: 32.1 MB
Open ports: 9200
Indices: 18, document count: 34, size: 32.1 MB
Found index supportservice with 0 documents (208 B)
Found index remoteworking with 0 documents (20...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4x3pk@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5X3PK"}
            
Analysis helper :
                
estk --url=http://52.140.80.217:9200 list
            

ASN: 8075
62 events in 967 days
Leak size: 955 B
Open ports: 9200
Indices: 1, document count: 0, size: 955 B
Found index read_me with 0 documents (955 B)
Analysis helper :
                
estk --url=http://23.99.201.9:9200 list
            

ASN: 8075
58 events in 329 days
Leak size: 14.4 MB
Open ports: 9200
Indices: 8, document count: 49020, size: 14.4 MB
Found index read-me with 1 documents (5.1 kB)
Found index idx_job_support with 14 documents (48....
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://20.117.145.126:9200 list
            

ASN: 8075
68 events in 469 days
Leak size: 1.5 MB
Open ports: 9200
Indices: 2, document count: 17, size: 1.5 MB
Found index read-me with 0 documents (795 B)
Found index sgd-srvpegasus-es with 17 documents (1.5 MB...
Analysis helper :
                
estk --url=http://20.225.61.158:9200 list
            

ASN: 8075
57 events in 490 days
Leak size: 1.9 MB
Open ports: 9200
Indices: 5, document count: 2873, size: 1.9 MB
Found index logstash-bouncer with 15 documents (119.7 kB)
Found index .kibana with 3 documents (17...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y3EVBa` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://20.23.241.205:9200 list
            

ASN: 8075
55 events in 864 days
Leak size: 46.0 kB
Open ports: 9200
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://70.37.77.139:9200 list
            

ASN: 8075
85 events in 1025 days
Leak size: 97.5 MB
Open ports: 9200
Indices: 36, document count: 199721, size: 97.5 MB
Found index auth-2024.01.23 with 3 documents (30.8 kB)
Found index auth-2024.01.22 with 3 docu...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://40.114.168.235:9200 list
            

ASN: 8075
58 events in 317 days
Leak size: 2.9 MB
Open ports: 9200
Indices: 12, document count: 99, size: 2.9 MB
Found index .apm-custom-link with 0 documents (208 B)
Found index .dashboards_2 with 11 documents (...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `h7pEfd` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://13.84.205.162:9200 list
            

ASN: 8075
48 events in 339 days
Leak size: 559.6 MB
Open ports: 9200
Indices: 468, document count: 1047194, size: 559.6 MB
Found index live_v1pbg5vjoec5h6zrz6sw_game_played with 1 documents (9.7 kB)
Found index sub...
Ransom notes :

{"took":0,"timed_out":false,"_shards":{"total":5,"successful":5,"skipped":0,"failed":0},"hits":{"total":1,"max_score":1.0,"hits":[{"_index":"read-me","_type":"_doc","_id":"1MacJooBY9kUd17URRg3","_score":1.0,"_source":{"message": "We deleted all databases, but download a copy to our server. The only way of recovery is you must send 0.015 BTC to 1BAW8LmC6bEg1Sjsq1dWpqezVT7EvAqQS9 You have until 48 hours to pay or data will be inaccesible. Once paid email Backups@onionmail.org with code: 'PT53hm' and we will recover your database. please read https://paste.sh/IOMBsAEl#XzwHcDCsND_DJkEuWMkeqlao for more information"}}]}}
            
Analysis helper :
                
estk --url=http://172.190.72.165:9200 list
            

ASN: 8075
21 events in 143 days
Leak size: 5.6 kB
Open ports: 9200
Indices: 2, document count: 1, size: 5.6 kB
Found index read_me with 1 documents (5.3 kB)
Found index .ds-filebeat-8.11.1-2023.12.04-000001 with ...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0063 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4vroc@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5VROC"}
            
Analysis helper :
                
estk --url=http://20.224.20.99:9200 list