{"id":773,"date":"2017-01-09T12:29:27","date_gmt":"2017-01-09T12:29:27","guid":{"rendered":"http:\/\/www.adlice.com\/?p=773\/"},"modified":"2022-12-21T10:35:33","modified_gmt":"2022-12-21T10:35:33","slug":"mongodb-ransomware-spreading","status":"publish","type":"post","link":"https:\/\/www.adlice.com\/es\/mongodb-ransomware-spreading\/","title":{"rendered":"MongoDB Ransomware is spreading"},"content":{"rendered":"\n<h4 class=\"has-accent-color has-text-color wp-block-heading\">Apocalypse now<\/h4>\n\n\n\n<p><strong>Right now, bots are scanning the internet for mongodb database with no password, and open port.<\/strong> When they found some, they use that open access for saving all the data (somewhere), <strong>dropping everything<\/strong>, and leaving a ransom note (just like ransomware, yes) to get your data back after <strong>paying the price<\/strong>.<\/p>\n\n\n\n<p>If that happened to you, it&#8217;s mostly too late, but if not please read the following and <strong>secure your database NOW<\/strong>!<\/p>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\"><br>Ransomware<\/h4>\n\n\n\n<p><strong>Dropping a database and leaving a ransom note is somewhat new<\/strong>. Here&#8217;s some logs from our honeypot where the database was dropped by that bot:<br><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/mongodb_apocalypse.png\"><img decoding=\"async\" width=\"1150\" height=\"512\" class=\"alignnone size-full wp-image-775\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/mongodb_apocalypse.png\" alt=\"\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/mongodb_apocalypse.png 1150w, https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/mongodb_apocalypse-300x134.png 300w, https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/mongodb_apocalypse-1024x456.png 1024w\" sizes=\"(max-width: 1150px) 100vw, 1150px\" \/><\/a><\/p>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\"><br>Dockerized mongodb<\/h4>\n\n\n\n<p>If you use the dockerized version, it comes <strong>pre-configured with open access to the world, and no password<\/strong>. This is B.A.D! To secure a dockerized version of mongodb, <a href=\"https:\/\/fralef.me\/docker-and-iptables.html\"><strong>restrict listening address to localhost<\/strong><\/a> like this (put the 127.0.0.1 address before the port):<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>docker run --name db -p 127.0.0.1:27017:27017 -d mongo:3.0 --smallfiles<\/code><\/pre>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\"><br>Regular Mongodb<\/h4>\n\n\n\n<p>If you don&#8217;t use docker, the best you can do is <strong>preventing the port from being accessible to the world with iptables<\/strong>. However, if you don&#8217;t have a firewall, or not familiar with, you can just use the <a href=\"http:\/\/stackoverflow.com\/questions\/4961177\/how-to-listen-only-to-localhost-on-mongodb\"><strong>bind_ip parameter to launch the mongodb instance<\/strong><\/a>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>bind_ip = 127.0.0.1<\/code><\/pre>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\"><br>Links<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/mongodb-apocalypse-is-here-as-ransom-attacks-hit-10-000-servers\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/mongodb-apocalypse-is-here-as-ransom-attacks-hit-10-000-servers\/<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/fralef.me\/docker-and-iptables.html\">https:\/\/fralef.me\/docker-and-iptables.html<\/a><\/li>\n\n\n\n<li><a href=\"http:\/\/stackoverflow.com\/questions\/4961177\/how-to-listen-only-to-localhost-on-mongodb\">http:\/\/stackoverflow.com\/questions\/4961177\/how-to-listen-only-to-localhost-on-mongodb<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Right now, bots are scanning the internet for mongodb database with no password, and open port. Read the following and secure your database now.<\/p>\n","protected":false},"author":1,"featured_media":774,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498],"tags":[499,127],"class_list":["post-773","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-mongodb","tag-ransomware","category-498","description-off"],"views":1805,"yoast_score":55,"yoast_readable":90,"featured_image_src":"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg","author_info":{"display_name":"tigzy","author_link":"https:\/\/www.adlice.com\/es\/author\/tigzy\/"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>MongoDB Ransomware is Spreading (Fast) | Analysis \u2022 Adlice Software<\/title>\n<meta name=\"description\" content=\"Right now, bots are scanning the internet for mongodb database with no password, and open port. Read the following and secure your database.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"MongoDB Ransomware is Spreading (Fast) | Analysis \u2022 Adlice Software\" \/>\n<meta property=\"og:description\" content=\"Right now, bots are scanning the internet for mongodb database with no password, and open port. Read the following and secure your database.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/\" \/>\n<meta property=\"og:site_name\" content=\"Adlice Software\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/RogueKiller\" \/>\n<meta property=\"article:published_time\" content=\"2017-01-09T12:29:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-21T10:35:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1040\" \/>\n\t<meta property=\"og:image:height\" content=\"560\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"tigzy\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@AdliceSoftware\" \/>\n<meta name=\"twitter:site\" content=\"@AdliceSoftware\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"tigzy\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/\"},\"author\":{\"name\":\"tigzy\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d\"},\"headline\":\"MongoDB Ransomware is spreading\",\"datePublished\":\"2017-01-09T12:29:27+00:00\",\"dateModified\":\"2022-12-21T10:35:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/\"},\"wordCount\":221,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.adlice.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg\",\"keywords\":[\"mongodb\",\"ransomware\"],\"articleSection\":[\"News\"],\"inLanguage\":\"es\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/\",\"url\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/\",\"name\":\"MongoDB Ransomware is Spreading (Fast) | Analysis \u2022 Adlice Software\",\"isPartOf\":{\"@id\":\"https:\/\/www.adlice.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg\",\"datePublished\":\"2017-01-09T12:29:27+00:00\",\"dateModified\":\"2022-12-21T10:35:33+00:00\",\"description\":\"Right now, bots are scanning the internet for mongodb database with no password, and open port. Read the following and secure your database.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#primaryimage\",\"url\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg\",\"contentUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg\",\"width\":1040,\"height\":560},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.adlice.com\/es\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"MongoDB Ransomware is spreading\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.adlice.com\/#website\",\"url\":\"https:\/\/www.adlice.com\/\",\"name\":\"Adlice Software\",\"description\":\"Anti-malware and analysis tools\",\"publisher\":{\"@id\":\"https:\/\/www.adlice.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.adlice.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.adlice.com\/#organization\",\"name\":\"Adlice Software\",\"url\":\"https:\/\/www.adlice.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png\",\"contentUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png\",\"width\":276,\"height\":276,\"caption\":\"Adlice Software\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/RogueKiller\",\"https:\/\/x.com\/AdliceSoftware\",\"https:\/\/fr.linkedin.com\/company\/adlice-software\",\"https:\/\/www.youtube.com\/channel\/UC4CQ-gIZMGWxl-auf0QqYhQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d\",\"name\":\"tigzy\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g\",\"caption\":\"tigzy\"},\"description\":\"Founder and owner of Adlice Software, Tigzy started as lead developer on the popular Anti-malware called RogueKiller. Involved in all the Adlice projects as lead developer, Tigzy is also doing research and reverse engineering as well as writing blog posts.\",\"url\":\"https:\/\/www.adlice.com\/es\/author\/tigzy\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"MongoDB Ransomware is Spreading (Fast) | Analysis \u2022 Adlice Software","description":"Right now, bots are scanning the internet for mongodb database with no password, and open port. Read the following and secure your database.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/","og_locale":"es_ES","og_type":"article","og_title":"MongoDB Ransomware is Spreading (Fast) | Analysis \u2022 Adlice Software","og_description":"Right now, bots are scanning the internet for mongodb database with no password, and open port. Read the following and secure your database.","og_url":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/","og_site_name":"Adlice Software","article_publisher":"https:\/\/www.facebook.com\/RogueKiller","article_published_time":"2017-01-09T12:29:27+00:00","article_modified_time":"2022-12-21T10:35:33+00:00","og_image":[{"width":1040,"height":560,"url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg","type":"image\/jpeg"}],"author":"tigzy","twitter_card":"summary_large_image","twitter_creator":"@AdliceSoftware","twitter_site":"@AdliceSoftware","twitter_misc":{"Escrito por":"tigzy","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#article","isPartOf":{"@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/"},"author":{"name":"tigzy","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d"},"headline":"MongoDB Ransomware is spreading","datePublished":"2017-01-09T12:29:27+00:00","dateModified":"2022-12-21T10:35:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/"},"wordCount":221,"commentCount":0,"publisher":{"@id":"https:\/\/www.adlice.com\/#organization"},"image":{"@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#primaryimage"},"thumbnailUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg","keywords":["mongodb","ransomware"],"articleSection":["News"],"inLanguage":"es"},{"@type":"WebPage","@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/","url":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/","name":"MongoDB Ransomware is Spreading (Fast) | Analysis \u2022 Adlice Software","isPartOf":{"@id":"https:\/\/www.adlice.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#primaryimage"},"image":{"@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#primaryimage"},"thumbnailUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg","datePublished":"2017-01-09T12:29:27+00:00","dateModified":"2022-12-21T10:35:33+00:00","description":"Right now, bots are scanning the internet for mongodb database with no password, and open port. Read the following and secure your database.","breadcrumb":{"@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#primaryimage","url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg","contentUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2017\/01\/0001494_search-engine-powered-by-mongodb.jpeg","width":1040,"height":560},{"@type":"BreadcrumbList","@id":"https:\/\/www.adlice.com\/mongodb-ransomware-spreading\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.adlice.com\/es\/"},{"@type":"ListItem","position":2,"name":"MongoDB Ransomware is spreading"}]},{"@type":"WebSite","@id":"https:\/\/www.adlice.com\/#website","url":"https:\/\/www.adlice.com\/","name":"Adlice Software","description":"Anti-malware and analysis tools","publisher":{"@id":"https:\/\/www.adlice.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.adlice.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/www.adlice.com\/#organization","name":"Adlice Software","url":"https:\/\/www.adlice.com\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png","contentUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png","width":276,"height":276,"caption":"Adlice Software"},"image":{"@id":"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/RogueKiller","https:\/\/x.com\/AdliceSoftware","https:\/\/fr.linkedin.com\/company\/adlice-software","https:\/\/www.youtube.com\/channel\/UC4CQ-gIZMGWxl-auf0QqYhQ"]},{"@type":"Person","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d","name":"tigzy","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g","caption":"tigzy"},"description":"Founder and owner of Adlice Software, Tigzy started as lead developer on the popular Anti-malware called RogueKiller. Involved in all the Adlice projects as lead developer, Tigzy is also doing research and reverse engineering as well as writing blog posts.","url":"https:\/\/www.adlice.com\/es\/author\/tigzy\/"}]}},"_links":{"self":[{"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/posts\/773","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/comments?post=773"}],"version-history":[{"count":0,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/posts\/773\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/media\/774"}],"wp:attachment":[{"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/media?parent=773"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/categories?post=773"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/tags?post=773"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}