ABCDEFGHIJKLMNOPQRSTUVWXYZAAAB
1
Generic warninggoo.gl/VxKqTT
http://www.zdnet.com/article/first-came-mass-mongodb-ransacking-now-copycat-ransoms-hit-elasticsearch/
2
Group nameSighted on
Email AddressBitcoin AddressRansomBTC trans
Name of replaced indice
Known Attacker IPs
Victims (OSINT)
Last Updated (CET)
Victims (helped)
Links
Found byNote
3
a1.0p1l4t0s@sigaint.org12-01-2017p1l4t0s@sigaint.org
1DAsGY4Kt1a4LCTPMH5vm5PqX32eZmot4r
0.2 BTC2warning77426.01.2017 13:00
http://pastebin.com/Jh0RNu6Z
@nmerriganSEND 0.2 BTC TO THIS WALLET: 1DAsGY4Kt1a4LCTPMH5vm5PqX32eZmot4r IF YOU WANT RECOVER YOUR DATABASE! SEND TO THIS EMAIL YOUR SERVER IP AFTER SENDING THE BITCOINS p1l4t0s@sigaint.org
4
a2.0elasticsearch@mail2tor.com13-01-2017elasticsearch@mail2tor.complease_read232726.01.2017 13:00@nmerriganIncomplete
5
a3.04rc0s@sigaint.org15-01-20174rc0s@sigaint.org
1Eqrzhx6yQafKm6WwKMhNAsGMxZXP7uitr
0.1 BTC0pleasereadthis194826.01.2017 13:00@mbromileyDFIRSEND 0.1 BTC TO THIS WALLET: 1Eqrzhx6yQafKm6WwKMhNAsGMxZXP7uitr IF YOU WANT RECOVER YOUR DATABASE! SEND TO THIS EMAIL YOUR SERVER IP AFTER SENDING THE BITCOINS 4rc0s@sigaint.org HOW TO BUY BITCOIN: https://en.bitcoin.it/wiki/Buying_Bitcoins_(the_newbie_version)
6
5049
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100