+plugin:ElasticSearchOpenPlugin -ip:"124.220.0.0/14" +events.leak.severity:"medium" +country:"France"
Indices: 2, document count: 2, size: 11.4 kB
Found index read-me with 1 documents (4.3 kB)
Found index .kibana_1 with 1 documents (7.1 kB)
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://141.94.69.190:9210 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 2, size: 9.1 kB
Found index .plugins-ml-config with 1 documents (4.0 kB)
Found index .opensearch-observability with 0...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0,003 BTC. Transfer to this BTC address 19pNR4MGshpXAaWxgPYGYtfn79dppP6FEH . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: mrserg@cock.li and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://54.38.59.200:9200 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :
{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
Analysis helper :
estk --url=http://52.143.134.170:9200 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 123, size: 153.1 kB
Through Kibana endpoint
Found index logstash with 120 documents (138.9 kB)
Found index .kibana wi...
Analysis helper :
estk --url=http://51.178.183.221:81 list
Found by ElasticSearchOpenPlugin
Indices: 6, document count: 391, size: 217.9 MB
Through Kibana endpoint
Found index .geoip_databases with 33 documents (32.1 MB)
Found index .kib...
Analysis helper :
estk --url=https://193.47.141.93 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 2, size: 9.5 kB
Through Kibana endpoint
Found index .kibana with 1 documents (5.2 kB)
Found index read-me with 1 docu...
Analysis helper :
estk --url=http://51.178.140.3:5601 list
Found by ElasticSearchOpenPlugin
Indices: 85, document count: 5963250, size: 2.1 GB
Through Kibana endpoint
Found index fluentd-20240519 with 8820 documents (862.1 kB)
Found inde...
Analysis helper :
estk --url=http://51.159.37.49:5601 list
Found by ElasticSearchOpenPlugin
Indices: 1, document count: 9, size: 115.9 kB
Found index jobdescriptiondtos with 9 documents (115.9 kB)
Analysis helper :
estk --url=http://164.132.54.168 list
Found by ElasticSearchOpenPlugin
Indices: 24, document count: 1387, size: 42.1 MB
Found index internal with 1 documents (9.2 kB)
Found index apisix with 44 documents (62.7 kB)
Fo...
Analysis helper :
estk --url=http://91.121.250.232:8080 list
Found by ElasticSearchOpenPlugin
Indices: 4, document count: 4, size: 21.5 kB
Through Kibana endpoint
Found index .kibana with 1 documents (4.2 kB)
Found index api with 1 documen...
Analysis helper :
estk --url=http://51.68.164.6:5601 list
Found by ElasticSearchOpenPlugin
Indices: 810, document count: 39782900, size: 7.5 GB
Through Kibana endpoint
Found index fluent-bit-2024.06.01 with documents ()
Found index rea...
Analysis helper :
estk --url=http://51.158.131.17:5601 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 43, size: 41.2 MB
Found index .geoip_databases with 42 documents (41.2 MB)
Found index read-me with 1 documents (4.5 ...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `h7pEfd` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://146.59.30.12:9201 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 3, size: 14.9 kB
Through Kibana endpoint
Found index .kibana with 1 documents (4.2 kB)
Found index read-me with 1 doc...
Analysis helper :
estk --url=http://52.47.153.42:5601 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 11, size: 46.0 kB
Found index read_me with 1 documents (5.1 kB)
Found index cgi-bin with 0 documents (283 B)
Found in...
Ransom notes :
{"text":"Your DB has been back up. The only way of recovery is you must send 0.002 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
Analysis helper :
estk --url=http://52.143.134.170 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 2, size: 11.3 kB
Found index read-me with 1 documents (4.3 kB)
Found index .kibana_1 with 1 documents (7.1 kB)
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://51.68.173.7:9200 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 1, size: 4.8 kB
Found index .kibana with 1 documents (3.3 kB)
Found index .kibana_1 with 0 documents (795 B)
Found in...
Analysis helper :
estk --url=http://51.254.78.233:9203 list
Found by ElasticSearchOpenPlugin
Indices: 3, document count: 2, size: 9.1 kB
Found index .plugins-ml-config with 1 documents (4.0 kB)
Found index .opensearch-observability with 0...
Ransom notes :
{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0,003 BTC. Transfer to this BTC address 19pNR4MGshpXAaWxgPYGYtfn79dppP6FEH . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: mrserg@cock.li and you will receive a link to download your database dump.\n"}
Analysis helper :
estk --url=http://54.38.59.193:9200 list
Found by ElasticSearchOpenPlugin
Indices: 8, document count: 16164, size: 3.3 MB
Found index opyo_product_2_v28 with 3013 documents (627.6 kB)
Found index opyo_product_5_v28 with...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://54.38.38.205:9200 list
Found by ElasticSearchOpenPlugin
Indices: 11, document count: 85352, size: 1.3 GB
Found index officeeasy_dev2__product_11_v18 with 6212 documents (175.1 MB)
Found index officeeas...
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `5Xcpm5` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://163.172.51.5:9200 list
Found by ElasticSearchOpenPlugin
Indices: 2, document count: 3, size: 14.2 kB
Found index .kibana with 2 documents (9.9 kB)
Found index read-me with 1 documents (4.3 kB)
Ransom notes :
{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
Analysis helper :
estk --url=http://51.77.132.206:9200 list
Found by ElasticSearchOpenPlugin