Attack #291751 telnet
Source
146.190.31.68Target port23
Authenticatedyes
Commands18
Duration34.5s
Session recording
Transcript
[MikroTik] > sh [MikroTik] > >/tmp/.ptmx && cd /tmp/ [MikroTik] > >/var/tmp/.ptmx && cd /var/tmp/ [MikroTik] > >/var/run/.ptmx && cd /var/run/ [MikroTik] > >/dev/shm/.ptmx && cd /dev/shm/ [MikroTik] > >/run/.ptmx && cd /run/ [MikroTik] > >/jffs/.ptmx && cd /jffs/ [MikroTik] > >/jffs2/.ptmx && cd /jffs2/ [MikroTik] > >/mnt/jffs2/.ptmx && cd /mnt/jffs2/ [MikroTik] > >/overlay/.ptmx && cd /overlay/ [MikroTik] > >/nvram/.ptmx && cd /nvram/ [MikroTik] > >/var/.ptmx && cd /var/ [MikroTik] > >/mnt/.ptmx && cd /mnt/ [MikroTik] > >/mnt/mtd/.ptmx && cd /mnt/mtd/ [MikroTik] > /bin/busybox rm -rf dvrHelper tbot [MikroTik] > /bin/busybox cp /bin/busybox dvrHelper; >dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox HolyFuck HolyFuck: applet not found [MikroTik] > /bin/busybox cat /bin/busybox || while read i; do echo $i; done < /bin/busybox cat: /bin/busybox: No such file or directory bad command name while (line 1 column 1) bad command name do (line 1 column 1) bad command name done (line 1 column 1) [MikroTik] > /bin/busybox HolyFuck HolyFuck: applet not found [MikroTik] >
Credentials
Username: system
Password: shell
Geolocation hub-resolved
🇳🇱The Netherlands · North Holland · Amsterdam
Behavioral classification
🦠
Matched signals:
- chmod/exec chain
- BusyBox probing
Command summary
sh >/tmp/.ptmx && cd /tmp/ >/var/tmp/.ptmx && cd /var/tmp/ >/var/run/.ptmx && cd /var/run/ >/dev/shm/.ptmx && cd /dev/shm/ >/run/.ptmx && cd /run/ >/jffs/.ptmx && cd /jffs/ >/jffs2/.ptmx && cd /jffs2/ >/mnt/jffs2/.ptmx && cd /mnt/jffs2/ >/overlay/.ptmx && cd /overlay/ >/nvram/.ptmx && cd /nvram/ >/var/.ptmx && cd /var/ >/mnt/.ptmx && cd /mnt/ >/mnt/mtd/.ptmx && cd /mnt/mtd/ /bin/busybox rm -rf dvrHelper tbot /bin/busybox cp /bin/busybox dvrHelper; >dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox HolyFuck /bin/busybox cat /bin/busybox || while read i; do echo $i; done < /bin/busybox /bin/busybox HolyFuck
Reported to threat intel
HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire