By searching for results, you agree with our Terms of service
Found 68173 results for
+dataset.ransom_notes:btc

Looking for more results ? Register a free account

Countries

  • China 32985
  • United States 10348
  • Germany 3353
  • India 2358
  • France 2132
  • Singapore 2036
  • South Korea 1779
  • Hong Kong 1425
  • Russia 1141
  • United Kingdom 854

Sources

  • ElasticSearchOpenPlugin 42081
  • MysqlOpenPlugin 26092

Network

  • Hangzhou Alibaba Advertising Co.,Ltd. 15155
  • Shenzhen Tencent Computer Systems Company Limited 10449
  • AMAZON-02 5967
  • GOOGLE-CLOUD-PLATFORM 3155
  • DIGITALOCEAN-ASN 2092
  • OVH SAS 2075
  • AMAZON-AES 2053
  • Huawei Cloud Service data center 1968
  • Hetzner Online GmbH 1414
  • MICROSOFT-CORP-MSN-AS-BLOCK 1334

IP Ranges

  • 47.96.0.0/12 3352
  • 124.220.0.0/14 1346
  • 43.136.0.0/13 1193
  • 47.92.0.0/14 913
  • 39.104.0.0/14 908
  • 101.42.0.0/15 724
  • 121.40.0.0/14 704
  • 47.112.0.0/13 699
  • 134.236.0.0/16 682
  • 120.24.0.0/14 654

ASN: 20857
125 events in 620 days
Leak size: 39.5 MB
Open ports: 443
Certificate domains:
www.best4mage-demo.com
best4mage-demo.com
webmail.best4mage-demo.com
Indices: 10, document count: 230, size: 39.5 MB
Found index .geoip_databases with 39 documents (38.8 MB)
Found index actuator with 2 documents (1...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qmheh2ukafmsa8y0hxj64lalddzxwj0sfaas7uu. Once paid please email dar0kmdb@tutanota.com with code: `aLEfI8` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://www.best4mage-demo.com list
            

ASN: 45820
87 events in 378 days
Leak size: 40.7 MB
Open ports: 443
Certificate domains:
elasticsearch.ingold-dev.com
Indices: 5, document count: 246, size: 40.7 MB
Found index .geoip_databases with 36 documents (40.5 MB)
Found index internal with 1 documents (6....
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.0057 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=https://elasticsearch.ingold-dev.com list
            

ASN: 16276
65 events in 403 days
Leak size: 37.0 MB
Open ports: 443
Certificate domains:
openmetadata-es.dev.defisetstrategies.dev
Indices: 2, document count: 38, size: 37.0 MB
Found index .geoip_databases with 37 documents (37.0 MB)
Found index read-me with 1 documents (4.5 ...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y8N85w` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://openmetadata-es.dev.defisetstrategies.dev list
            

ASN: 16276
130 events in 631 days
Leak size: 64.9 MB
Open ports: 443
Certificate domains:
elasticsearch.ingoldsolutions.com
Indices: 59, document count: 22605, size: 64.9 MB
Found index bbb2b.ingold-dev.com_product_3_v3 with 818 documents (1.0 MB)
Found index ceratizit...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4ppeo@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5PPEO"}
            
Analysis helper :
                
estk --url=https://elasticsearch.ingoldsolutions.com list
            

ASN: 14618
103 events in 313 days
Leak size: 2.8 MB
Open ports: 80
Certificate domains:
thehrsite.com
Indices: 12, document count: 3435, size: 2.8 MB
Found index v1.24 with 1 documents (9.2 kB)
Found index ohio_-devohiohealthwpenginecom-post-1 wit...
Analysis helper :
                
estk --url=http://thehrsite.com list
            

ASN: 14061
110 events in 404 days
Leak size: 8.9 MB
Open ports: 80
Certificate domains:
drone2.eventcat.info
Databases: 84, row count: 136438, size: 8.9 MB
Found table README_TO_RECOVER_A.RECOVER_YOUR_DATA with 2 records
Found table laravel.email_updates...
Ransom notes :

All your data is backed up. You must pay 0.022 BTC to 18224LViuRGEhqrUzeRLE9Y9ggogcdkNn5 In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data2)
            

ASN: 16276
131 events in 518 days
Leak size: 1.1 MB
Open ports: 443
Certificate domains:
pm.moonbit.xyz
Indices: 4, document count: 1400, size: 1.1 MB
Found index read-me with 1 documents (5.1 kB)
Found index bitbag_attribute_taxons_prod with 10 doc...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `Y3EVBa` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://pm.moonbit.xyz list
            

ASN: 45820
137 events in 984 days
Leak size: 80.6 MB
Open ports: 443
Certificate domains:
elasticsearch.magento-development.asia
Indices: 19, document count: 23781, size: 80.6 MB
Found index internal with 1 documents (6.7 kB)
Found index suithound_product_1_v5631 with 158 d...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0057 BTC to 1tpwVPxbRNtQuzKonhzdEsJL8n562uwAr In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data05)After paying send mail to us: rambler+4tqf5@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 5TQF5"}
            
Analysis helper :
                
estk --url=https://elasticsearch.magento-development.asia list
            

ASN: 132420
125 events in 460 days
Leak size: 60.6 MB
Open ports: 443
Certificate domains:
elasticdev.kalibre.ai
Indices: 25, document count: 50895, size: 60.6 MB
Found index virtualtable with 153 documents (154.5 kB)
Found index roles with 72 documents (35....
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `riDAZo` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://elasticdev.kalibre.ai list
            

ASN: 9808
127 events in 654 days
Leak size: 36.6 kB
Open ports: 443
Certificate domains:
es.demo2.zdbx.net
Indices: 4, document count: 4, size: 36.6 kB
Found index internal with 1 documents (6.3 kB)
Found index service with 1 documents (19.6 kB)
Found ...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `WCR6wZ` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=https://es.demo2.zdbx.net list
            

ASN: 4766
151 events in 654 days
Leak size: 169.4 MB
Open ports: 9202
Indices: 19, document count: 1332965, size: 169.4 MB
Found index f5_system_inf_2023.09.16 with 131256 documents (10.7 MB)
Found index f5_virtuals...
Ransom notes :

{"message": "We delete all databases, but download a copy to our server. The only way of recovery is you must send 0.01 BTC to bc1qmaacz9fdvnkujqlf8m547mzzh0l5t0ajn699th. You have until 48 hours to pay or data will be inaccessible. Once paid please email incomings99112@onionmail.com with code: `eNO2CN` and we will recover your database. please read https://paste.sh/UY6_vtGL#THGqRdL9oQqUc-28RPDOWSbB for more information"}
            
Analysis helper :
                
estk --url=http://175.196.233.51:9202 list
            

ASN: 12297
164 events in 891 days
Leak size: 518.9 MB
Open ports: 9200
Indices: 11, document count: 910796, size: 518.9 MB
Found index .geoip_databases with 37 documents (40.9 MB)
Found index .monitoring-es-7-2024.11...
Ransom notes :

{"text":"Your DB has been back up. The only way of recovery is you must send 0.0057 BTC to 127ZBzXyLJFc7ShMmzkYFDhSiXXSnR8Jfr. Once paid please email databaserestore32@onionmail.org with code: `omoRmq` and we will recover your database. please read https://cutmyurl.com/3caF8EkT for more information"}
            
Analysis helper :
                
estk --url=http://178.160.249.37:9200 list
            

ASN: 396982
156 events in 1184 days
Leak size: 42.8 MB
Open ports: 9200
Indices: 2, document count: 44, size: 42.8 MB
Found index .geoip_databases with 43 documents (42.8 MB)
Found index read-me with 1 documents (4.8 ...
Ransom notes :

{"message": "We delete all databases, but download a copy to our server. The only way of recovery is you must send 0.01 BTC to bc1qmaacz9fdvnkujqlf8m547mzzh0l5t0ajn699th. You have until 48 hours to pay or data will be inaccessible. Once paid please email incomings99112@onionmail.com with code: `eNO2CN` and we will recover your database. please read https://paste.sh/UY6_vtGL#THGqRdL9oQqUc-28RPDOWSbB for more information"}
            
Analysis helper :
                
estk --url=http://34.105.72.41:9200 list
            

ASN: 20454
158 events in 1270 days
Leak size: 45.4 MB
Open ports: 9200
Indices: 2, document count: 44, size: 45.4 MB
Found index .geoip_databases with 43 documents (45.4 MB)
Found index read_me with 1 documents (4.5 ...
Ransom notes :

{"message":"All your data is backed up. You must pay 0.0125 BTC to 156j7MZZQJvKWZjWLDi8eMoqZtyZXiQgP4 In 48 hours, your data will be publicly disclosed and deleted. (more information: go to http://iplis.ru/data5)After paying send mail to us: rambler+53yc3@onionmail.org and we will provide a link for you to download your data. Your DBCODE is: 53YC3"}
            
Analysis helper :
                
estk --url=http://108.170.8.227:9200 list
            

ASN: 16276
37 events in 460 days
Leak size: 124.7 MB
Open ports: 9200
Indices: 3, document count: 331320, size: 124.7 MB
Found index .geoip_databases with 40 documents (39.6 MB)
Found index recipes with 331279 docum...
Ransom notes :

{"message": "Your DB has been back up. The only way of recovery is you must send 0.01 BTC to bc1qaua9cwrp0g2nqg2txn86e7k376v0xm4m0yfcfq. Once paid please email dar0kmdb@tutanota.com with code: `riDAZo` and we will recover your database. please read https://paste.sh/u6JYxXwk#PwdBc7jVzqo9-h12zU5hyPYP for more information"}
            
Analysis helper :
                
estk --url=http://158.69.253.108:9200 list
            

ASN: 396982
171 events in 1279 days
Leak size: 7.2 MB
Open ports: 9200
Indices: 4, document count: 3281, size: 7.2 MB
Found index magento2_product_1_v4 with 3280 documents (7.2 MB)
Found index read-me with 1 document...
Ransom notes :

{"message": "We delete all databases, but download a copy to our server. The only way of recovery is you must send 0.01 BTC to bc1qmaacz9fdvnkujqlf8m547mzzh0l5t0ajn699th. You have until 48 hours to pay or data will be inaccessible. Once paid please email incomings99112@onionmail.com with code: `vxa0sy` and we will recover your database. please read https://paste.sh/UY6_vtGL#THGqRdL9oQqUc-28RPDOWSbB for more information"}
            
Analysis helper :
                
estk --url=http://35.233.232.119:9200 list
            

ASN: 20454
189 events in 1267 days
Leak size: 91.4 kB
Open ports: 9200
Indices: 3, document count: 15, size: 91.4 kB
Found index casa with 0 documents (208 B)
Found index read_me with 1 documents (4.5 kB)
Found index...
Ransom notes :

{"@timestamp": "2099-11-15T13:12:00", "message": "All indexs has been dropped. But we backup all indexs. The only method of recoveribing database is to pay 0.021 BTC. Transfer to this BTC address 1rsAp5FzhD6huVBjJEnLZxnQXU6EQmUvb . You can buy bitcoin here, does not take much time to buy https://localbitcoins.com or https://buy.moonpay.io/ . After paying write to me in the mail with your DB IP: recmydata@onionmail.org and you will receive a link to download your database dump.\n"}
            
Analysis helper :
                
estk --url=http://108.170.8.229:9200 list
            

ASN: 31898
73 events in 329 days
Leak size: 1.2 GB
Open ports: 9202
Indices: 26, document count: 2086341, size: 1.2 GB
Found index .monitoring-es-7-2024.11.28 with 277355 documents (157.6 MB)
Found index .monitori...
Analysis helper :
                
estk --url=http://141.148.174.218:9202 list
            

ASN: 53055
114 events in 433 days
Leak size: 3.2 MB
Open ports: 9200
Indices: 2, document count: 6979, size: 3.2 MB
Found index 8a97eed77f4dc2d4017f4dc357d50000 with 6978 documents (3.2 MB)
Found index read-me-to-r...
Analysis helper :
                
estk --url=http://186.227.200.252:9200 list
            

ASN: 55990
135 events in 576 days
Leak size: 562.5 GB
Open ports: 9200
Indices: 343, document count: 1132403038, size: 562.5 GB
Found index sw_instance_traffic-20231001 with 4 documents (69.4 kB)
Found index sw_insta...
Ransom notes :

{"message": "We delete all databases, but download a copy to our server. The only way of recovery is you must send 0.01 BTC to bc1qmaacz9fdvnkujqlf8m547mzzh0l5t0ajn699th. You have until 48 hours to pay or data will be inaccessible. Once paid please email incomings99112@onionmail.com with code: `eNO2CN` and we will recover your database. please read https://paste.sh/UY6_vtGL#THGqRdL9oQqUc-28RPDOWSbB for more information"}
            
Analysis helper :
                
estk --url=http://121.37.138.114:9200 list