

One of the people that have first detected the attack has written a detailed description.Ī database exploited by this attack will look like the picture below. It appears that the attacker only deletes the data and there isn’t a way to recover them from the attacker, but this may be different from case to case.

There are serveral variations that may ask for different BTC sums or have a different database name. This attack deletes all the databases it finds and replaces them with a table name WARNING containing “To recover your lost data SEND BTC”. How to Update phpMyAdmin to the latest Version.
