Attack #291997 telnet
Source
146.190.31.68Target port23
Authenticatedyes
Commands18
Duration34.0s
Session recording
Transcript
Welcome to HiLinux (NVR Box) hilinux-nvrbox# sh hilinux-nvrbox# >/tmp/.ptmx && cd /tmp/ hilinux-nvrbox# >/var/tmp/.ptmx && cd /var/tmp/ hilinux-nvrbox# >/var/run/.ptmx && cd /var/run/ hilinux-nvrbox# >/dev/shm/.ptmx && cd /dev/shm/ hilinux-nvrbox# >/run/.ptmx && cd /run/ hilinux-nvrbox# >/jffs/.ptmx && cd /jffs/ hilinux-nvrbox# >/jffs2/.ptmx && cd /jffs2/ hilinux-nvrbox# >/mnt/jffs2/.ptmx && cd /mnt/jffs2/ hilinux-nvrbox# >/overlay/.ptmx && cd /overlay/ hilinux-nvrbox# >/nvram/.ptmx && cd /nvram/ hilinux-nvrbox# >/var/.ptmx && cd /var/ hilinux-nvrbox# >/mnt/.ptmx && cd /mnt/ hilinux-nvrbox# >/mnt/mtd/.ptmx && cd /mnt/mtd/ hilinux-nvrbox# /bin/busybox rm -rf dvrHelper tbot hilinux-nvrbox# /bin/busybox cp /bin/busybox dvrHelper; >dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox HolyFuck HolyFuck: applet not found hilinux-nvrbox# /bin/busybox cat /bin/busybox || while read i; do echo $i; done < /bin/busybox cat: /bin/busybox: No such file or directory -sh: while: not found -sh: do: not found -sh: done: not found hilinux-nvrbox# /bin/busybox HolyFuck HolyFuck: applet not found hilinux-nvrbox#
Credentials
Username: system
Password: shell
Geolocation hub-resolved
🇳🇱The Netherlands · North Holland · Amsterdam
Behavioral classification
🦠
Matched signals:
- chmod/exec chain
- BusyBox probing
Command summary
sh >/tmp/.ptmx && cd /tmp/ >/var/tmp/.ptmx && cd /var/tmp/ >/var/run/.ptmx && cd /var/run/ >/dev/shm/.ptmx && cd /dev/shm/ >/run/.ptmx && cd /run/ >/jffs/.ptmx && cd /jffs/ >/jffs2/.ptmx && cd /jffs2/ >/mnt/jffs2/.ptmx && cd /mnt/jffs2/ >/overlay/.ptmx && cd /overlay/ >/nvram/.ptmx && cd /nvram/ >/var/.ptmx && cd /var/ >/mnt/.ptmx && cd /mnt/ >/mnt/mtd/.ptmx && cd /mnt/mtd/ /bin/busybox rm -rf dvrHelper tbot /bin/busybox cp /bin/busybox dvrHelper; >dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox HolyFuck /bin/busybox cat /bin/busybox || while read i; do echo $i; done < /bin/busybox /bin/busybox HolyFuck
Reported to threat intel
HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire