All MYSQL databases missing. Don't know hacker nor attack vector yet. Here is what I found on victim server:
# ls /var/lib/mysql/PLEASE_READ_ME_FXF/
total 120
-rw-r----- 1 mysql mysql 61 2019-01-14,02-34-16 db.opt
-rw-r----- 1 mysql mysql 8676 2019-01-14,02-34-29 WARNING.frm
-rw-r----- 1 mysql mysql 98304 2019-01-14,02-34-33 WARNING.ibd
# strings /var/lib/mysql/PLEASE_READ_ME_FXF/WARNING.ibd
{0XYY
0XYY"X
infimum
supremum
To recover your lost data : Send 0.04 BTC to our BitCoin Address and Contact us by eMail with your server IP Address or Domain Name and a Proof of Payment. Any eMail without your server IP Address or Domain Name and a Proof of Payment together will be ignored. Your File and DataBase is downloaded and backed up on our secured servers. If we dont receive your payment,we will leak your database. 1MUhSTik1iNuK9wVrhaBLQqVTjeLzCkMQs
[email protected]
infimum
supremum
Poland, 2019-01-14 12:51:48