Malware distribution host referenced in a Linksys 'ttcp_ip' command-injection exploit (CVE-2025-3403 ...
show moreMalware distribution host referenced in a Linksys 'ttcp_ip' command-injection exploit (CVE-2025-34037) against our web server on 2026-07-08. Serves Mirai/Gafgyt loader wget.sh (SHA256 90e72cb3...1ff713) plus 12 'kworkerd-*' ELF payloads dropped to /tmp/.k. Exposes 22/tcp OpenSSH 9.6p1 Ubuntu. AS197170 on Spamhaus ASN-DROP. Also on abuse.ch URLhaus.
show less
Sent Linksys hndUnblock.cgi 'ttcp_ip' OS command injection (CVE-2025-34037, the 'TheMoon' vector) ag ...
show moreSent Linksys hndUnblock.cgi 'ttcp_ip' OS command injection (CVE-2025-34037, the 'TheMoon' vector) against our web server on 2026-07-08 23:07 UTC-4, attempting to download and pipe a Mirai/Gafgyt loader (wget.sh) to a shell. Blocked at edge (HTTP 444). Loader host: 91.92.40.118. GreyNoise: malicious. AS197170 on Spamhaus ASN-DROP; this /24 on Spamhaus DROP (SBL679667).
show less
Port ScanHackingWeb App AttackIoT Targeted
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.