+plugin:ElasticSearchOpenPlugin -ip:"124.220.0.0/14" +events.leak.severity:"medium" +asn:"8075"
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :
{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
Analysis helper :
estk --url=http://104.211.190.127:9200 list
Found by ElasticSearchOpenPlugin
Indices: 14, document count: 982, size: 34.8 MB
Found index lsbfx-dev_product_5_v62 with 79 documents (219.9 kB)
Found index read_me with 1 docum...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4nuvx@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5NUVX"}
Analysis helper :
estk --url=http://20.205.235.157:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 38, size: 35.9 MB
Found index .geoip_databases with 37 documents (35.9 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.0063 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4lg8z@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5LG8Z"}
Analysis helper :
estk --url=http://40.117.88.175:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 2, size: 11.2 kB
Found index read-me with 1 documents (4.2 kB)
Found index .kibana_1 with 1 documents (6.9 kB)
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://20.7.121.173:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 2, size: 11.4 kB
Found index read-me with 1 documents (4.3 kB)
Found index .kibana_1 with 1 documents (7.1 kB)
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://52.172.197.226:9200 list
Found by ElasticSearchOpenPlugin
Indices: 18, document count: 1438205, size: 797.3 MB
Found index .kibana_task_manager with 2 documents (23.5 kB)
Found index read_me with 1 docum...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.06 BTC to 16wrRb6vMi2py5rggYhdRNT2eUDdqTRS5V 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ After paying write to me in the mail with your DB IP: rambler+3au5x@onionmail.org and/or eladb@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://20.219.180.254:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 38, size: 35.9 MB
Found index .geoip_databases with 37 documents (35.9 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.0063 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+49a7l@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 59A7L"}
Analysis helper :
estk --url=http://20.232.202.46:9200 list
Found by ElasticSearchOpenPlugin
Indices: 5, document count: 359037, size: 71.9 MB
Found index .geoip_databases with 41 documents (44.4 MB)
Found index read_me with 1 documents (...
Ransom notes :
{"message":"All your data is a backed up. You must pay 0.06 BTC to 16wrRb6vMi2py5rggYhdRNT2eUDdqTRS5V 48 hours for recover it. After 48 hours expiration we will leaked and exposed all your data. In case of refusal to pay, we will contact the General Data Protection Regulation, GDPR and notify them that you store user data in an open form and is not safe. Under the rules of the law, you face a heavy fine or arrest and your base dump will be dropped from our server! You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ After paying write to me in the mail with your DB IP: rambler+3la99@onionmail.org and/or eladb@mailnesia.com and you will receive a link to download your database dump."}
Analysis helper :
estk --url=http://20.86.119.37:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 2, size: 10.6 kB
Found index read-me with 1 documents (4.0 kB)
Found index .kibana_1 with 1 documents (6.6 kB)
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://52.242.37.91:9200 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :
{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
Analysis helper :
estk --url=http://13.77.204.229:9200 list
Found by ElasticSearchOpenPlugin
Indices: 18, document count: 34, size: 32.1 MB
Found index supportservice with 0 documents (208 B)
Found index remoteworking with 0 documents (20...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4x3pk@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5X3PK"}
Analysis helper :
estk --url=http://52.140.80.217:9200 list
Found by ElasticSearchOpenPlugin
Indices: 1, document count: 0, size: 955 B
Found index read_me with 0 documents (955 B)
Analysis helper :
estk --url=http://23.99.201.9:9200 list
Found by ElasticSearchOpenPlugin
Indices: 8, document count: 49020, size: 14.4 MB
Found index read-me with 1 documents (5.1 kB)
Found index idx_job_support with 14 documents (48....
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://20.117.145.126:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 17, size: 1.5 MB
Found index read-me with 0 documents (795 B)
Found index sgd-srvpegasus-es with 17 documents (1.5 MB...
Analysis helper :
estk --url=http://20.225.61.158:9200 list
Found by ElasticSearchOpenPlugin
Indices: 5, document count: 2873, size: 1.9 MB
Found index logstash-bouncer with 15 documents (119.7 kB)
Found index .kibana with 3 documents (17...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y3EVBa` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://20.23.241.205:9200 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :
{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
Analysis helper :
estk --url=http://70.37.77.139:9200 list
Found by ElasticSearchOpenPlugin
Indices: 36, document count: 199721, size: 97.5 MB
Found index auth-2024.01.23 with 3 documents (30.8 kB)
Found index auth-2024.01.22 with 3 docu...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://40.114.168.235:9200 list
Found by ElasticSearchOpenPlugin
Indices: 12, document count: 99, size: 2.9 MB
Found index .apm-custom-link with 0 documents (208 B)
Found index .dashboards_2 with 11 documents (...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `h7pEfd` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://13.84.205.162:9200 list
Found by ElasticSearchOpenPlugin
Indices: 468, document count: 1047194, size: 559.6 MB
Found index live_v1pbg5vjoec5h6zrz6sw_game_played with 1 documents (9.7 kB)
Found index sub...
Ransom notes :
{"took":0,"timed_out":false,"_shards":{"total":5,"successful":5,"skipped":0,"failed":0},"hits":{"total":1,"max_score":1.0,"hits":[{"_index":"read-me","_type":"_doc","_id":"1MacJooBY9kUd17URRg3","_score":1.0,"_source":{"message": "We deleted all databases, but download a copy to our server. The only way of recovery is you must send 0.015 BTC to 1BAW8LmC6bEg1Sjsq1dWpqezVT7EvAqQS9 You have until 48 hours to pay or data will be inaccesible. Once paid email Backups@onionmail.org with code: 'PT53hm' and we will recover your database. please read https://paste.sh/IOMBsAEl#XzwHcDCsND_DJkEuWMkeqlao for more information"}}]}}
Analysis helper :
estk --url=http://172.190.72.165:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 1, size: 5.6 kB
Found index read_me with 1 documents (5.3 kB)
Found index .ds-filebeat-8.11.1-2023.12.04-000001 with ...
Ransom notes :
{"message":"All your data is backed up. You must pay 0.0063 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4vroc@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5VROC"}
Analysis helper :
estk --url=http://20.224.20.99:9200 list
Found by ElasticSearchOpenPlugin