Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- MongoDB & ElasticSearch Ransomware victims
- A typically ransom note below is what victims see in their Mongo Indexes or Elasticsearch clusters when their NoSQL server has been targetted by ransomware.
- “SEND 0.2 BTC TO THIS WALLET: 1DAsGY4Kt1a4LCTPMH5vm5PqX32eZmot4r IF YOU WANT RECOVER YOUR DATABASE! SEND TO THIS EMAIL YOUR SERVER IP AFTER SENDING THE BITCOINS p1l4t0s@sigaint.org”
- Shodan.io search: country:"SG" product:"MongoDB" PLEASE_READ_ME country:"SG"
- https://www.shodan.io/search?query=country%3A%22SG%22+product%3A%22MongoDB%22+PLEASE_READ_ME+country%3A%22SG%22
- Install Mongo using Brew
- $ brew update
- $ brew install mongodb
- $ mongo --host [hostname or IP]
- > show dbs
- > use PLEASE_READ_ME
- > show collections
- > db.PLEASE_READ_ME.find().pretty()
- $ mongo --host 119.81.55.37
- MongoDB shell version v3.4.2
- connecting to: mongodb://119.81.55.37:27017/
- MongoDB server version: 2.2.2
- WARNING: shell and server versions do not match
- Welcome to the MongoDB shell.
- For interactive help, type "help".
- For more comprehensive documentation, see
- http://docs.mongodb.org/
- Questions? Try the support group
- http://groups.google.com/group/mongodb-user
- > show dbs
- AppiyoFS (empty)
- MeOnCloud-Auth (empty)
- PLEASE_READ_ME 0.203GB
- ProcessStore 0.203GB
- WARNING (empty)
- admin (empty)
- > use PLEASE_READ_ME
- switched to db PLEASE_READ_ME
- > show collections
- PLEASE_READ_ME
- system.indexes
- > db.PLEASE_READ_ME.find().pretty()
- {
- "Bitcoin Address" : "1PemEbnMSoiaXsEW5nRUpSMRB6RZw9MG8D",
- "_id" : ObjectId("589d14d5b7dc320876e17e30"),
- "amount" : "0.2 BTC",
- "data_we_have" : {
- "MeOnCloud-Auth" : [ ],
- "DB_H4CK3D" : [
- "system.indexes",
- "URG3NT_W4RN1NG"
- ],
- "ProcessStore" : [
- "system.indexes",
- "registry.notification.retry"
- ]
- },
- "email" : "kraken8888@sigaint.org",
- "info" : "Don't panic. Your DB is in safety and backed up (check logs). To restore send 0.05 BTC and email with your server ip or domain name. Each 48 hours we erase all data."
- }
- > quit()
- =================================================================================================
- Shodan.io search: country:"SG" product:"Elastic" please_read
- $ curl -s 188.166.209.11:9200/_aliases?pretty=1 | awk -F\" '!/aliases/ && $2 != "" {print $2}'
- feedback_responses_production
- please_read
- members_production_20170123065033031
- members_production
- leads_production
- faqs_production_20170123065045536
- faqs_production
- $ curl -s 188.166.209.11:9200/please_read/_search?pretty=1
- {
- "took" : 21,
- "timed_out" : false,
- "_shards" : {
- "total" : 5,
- "successful" : 5,
- "failed" : 0
- },
- "hits" : {
- "total" : 1,
- "max_score" : 1.0,
- "hits" : [ {
- "_index" : "please_read",
- "_type" : "info",
- "_id" : "AVm3WtOf4VozCfIW-RNC",
- "_score" : 1.0,
- "_source":{
- "Info": "Your DB is Backed up at our servers, to restore send 0.5 BTC to the Bitcoin Address then send an email with your server ip",
- "Bitcoin Address": "12JNfaS2Gzic2vqzGMvDEo38MQSX1kDQrx",
- "Email" : "elasticsearch@mail2tor.com"
- }
- } ]
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement