K.php - a RestApps malicious script

My guess is that FreePBX distros will fight 'tooth and nails ’ your

iptables -A OUTPUT -d 37.49.230.74 -j DROP
/sbin/service iptables save

But I will guarantee the next vector will not be from 37.49.230.74

 whois -h v4.whois.cymru.com ' -v -f  37.49.230.74'

gives the ASN of the ‘careless provider’. “ABC Consultancy”

If you go through your logs you will see these SQUITTER/ABC SQUATTERS have been probing FreePBX deployments for months, likely yours included (FYI, the real blackhats are not Dutch, nor Icelandic :wink: )

1 Like