Cryptscam Abuse Explorer

Stay safe, check if wallets are scam!

Support us with a donation

Report number
122
Wallet balance
 BTC → 
Total received
 BTC → 
Transaction number
date
05 January 2020 Sunday. 14:33:18 UTC
type
ransomware
scammer/abuser
country
India
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: PapaFitRevamp . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
05 January 2020 Sunday. 14:21:00 UTC
type
ransomware
scammer/abuser
country
Vietnam
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: [*my list database*] . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
05 January 2020 Sunday. 09:32:30 UTC
type
ransomware
scammer/abuser
country
Russia
description
INSERT INTO `WARNING` VALUES (1,'To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email wit h your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: *** . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise. ','1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD','[email protected]');
source
bitcoinabuse
Site url
date
05 January 2020 Sunday. 06:18:30 UTC
type
ransomware
scammer/abuser
country
United States
description
new db created 'PLEASE_READ_ME_XMG", table "WARNING": To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: [redacted] . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
05 January 2020 Sunday. 06:16:40 UTC
type
ransomware
scammer/abuser
Nikolay Fedotov
country
United States
description
Script kiddie attack on vulnerable PHPMYADMIN version with CVE (4.6.6). All databases have tables replaced with "WARNING" table that has the following entry: To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: [redacted] . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise. Nikolay Fedotov was the name used by an individual who claimed the attack on one of my client's websites.
source
bitcoinabuse
Site url
date
20 December 2019 Friday. 13:04:58 UTC
type
ransomware
scammer/abuser
country
Brazil
description
2 Database Hack
source
bitcoinabuse
Site url
date
19 December 2019 Thursday. 19:22:14 UTC
type
ransomware
scammer/abuser
country
Kenya
description
Database hack
source
bitcoinabuse
Site url
date
14 December 2019 Saturday. 06:19:28 UTC
type
ransomware
scammer/abuser
country
India
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: kalaageblog, space, kalaageschema, author . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
05 December 2019 Thursday. 06:53:07 UTC
type
ransomware
scammer/abuser
country
Australia
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
28 November 2019 Thursday. 11:02:20 UTC
type
ransomware
scammer/abuser
country
United Arab Emirates
description
He deleted my SQL database and create a table named WARNING. In the table following statement is written: To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now. If we don't receive your payment in the next 10 days, we will make your database public or use them otherwise. | 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD | [email protected] |
source
bitcoinabuse
Site url
date
26 November 2019 Tuesday. 18:13:03 UTC
type
ransomware
scammer/abuser
country
Germany
description
To recover your lost Database and avoid leaking it...
source
bitcoinabuse
Site url
date
26 November 2019 Tuesday. 07:20:59 UTC
type
ransomware
scammer/abuser
country
Thailand
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: ***. If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
22 November 2019 Friday. 16:45:59 UTC
type
ransomware
scammer/abuser
country
Senegal
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof.
source
bitcoinabuse
Site url
date
22 November 2019 Friday. 12:38:56 UTC
type
ransomware
scammer/abuser
country
Netherlands
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: essentialmode, please_read_me_vvv . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
21 November 2019 Thursday. 18:07:05 UTC
type
ransomware
scammer/abuser
country
France
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: minecraft, panel . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
19 November 2019 Tuesday. 14:03:53 UTC
type
ransomware
scammer/abuser
country
India
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now. If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
18 November 2019 Monday. 17:28:45 UTC
type
ransomware
scammer/abuser
country
Ukraine
description
To recover your lost Database and avoid leaking it: Send us 0.06 Bitcoin (BTC) to our Bitcoin address 1BLYhUDmnmVPVjcTWgc6gFT6DCYwbVieUD and contact us by Email with your Server IP or Domain name and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your Database is downloaded and backed up on our servers. Backups that we have right now: *, * . If we dont receive your payment in the next 10 Days, we will make your database public or use them otherwise.
source
bitcoinabuse
Site url
date
11 November 2019 Monday. 18:19:16 UTC
type
ransomware
scammer/abuser
country
Latvia
description
They hijacked my mysql db after I started hosting an OpenCart demo web site. I guess it was important to follow the "delete installation folder" warning after all...
source
bitcoinabuse
Site url
date
07 November 2019 Thursday. 16:38:08 UTC
type
ransomware
scammer/abuser
country
United States
description
All my mysql databases are deleted, with an entry in each one saying I need to send 0.06 BTC to them, and they will recover my databases. they used the email [email protected]
source
bitcoinabuse
Site url
date
06 November 2019 Wednesday. 14:59:02 UTC
type
ransomware
scammer/abuser
country
Belgium
description
classical MySQL brute force attack, database deletion, create a WARNINGS table with instructions on how to proceed.
source
bitcoinabuse
Site url