|
๐ง๐ท
ICS Labs
|
|
ICS Labs identified 170.64.223.52 as a malicious indicator from threat intelligence.
|
DDoS Attack
Hacking
Exploited Host
|
|
|
๐ง๐ช
cmbplf
|
|
5 requests with url.path /indoxploit.php
|
Brute-Force
Bad Web Bot
|
|
|
๐ฎ๐ฉ
sockominfo
|
|
TheHive Threat Scoring assessment: 170.64.223.52
CVSS v3.1: 0/10 (None)
CVSS Vector: CVSS:3.1/AV:und ...
show more
TheHive Threat Scoring assessment: 170.64.223.52
CVSS v3.1: 0/10 (None)
CVSS Vector: CVSS:3.1/AV:undefined/AC:undefined/PR:undefined/UI:undefined/S:undefined/C:undefined/I:undefined/A:undefined
Bayesian Probability: 80%
MITRE ATT&CK: Exploit Public-Facing Application, Valid Accounts, Command and Scripting Interpreter, Application Layer Protocol, Brute Force, Account Manipulation
OWASP Risk: High (L:8, I:6)
Combined Score: 4.92/10
Confidence Interval: ยฑ0.01
Status: Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
|
Hacking
Email Spam
|
|
|
๐ฎ๐ฉ
sockominfo
|
|
Reported by TangerangKota-CSIRT. Status: MALICIOUS
|
Hacking
Email Spam
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
170.64.223.52 - - [05/May/2026:10:44:48 +0300] "GET /wp-content/themes/alera/alpha.php HTTP/1.1" 404 ...
show more
170.64.223.52 - - [05/May/2026:10:44:48 +0300] "GET /wp-content/themes/alera/alpha.php HTTP/1.1" 404 3353 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐ซ๐ท
Sklurk
|
|
Web App Attack
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
170.64.223.52 - - [04/May/2026:05:26:42 +0300] "GET /xmlrpc.php?rsd HTTP/1.1" 404 683 "-" "Mozilla/5 ...
show more
170.64.223.52 - - [04/May/2026:05:26:42 +0300] "GET /xmlrpc.php?rsd HTTP/1.1" 404 683 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
170.64.223.52 - - [03/May/2026:11:43:22 +0300] "GET /wp-content/flame.php HTTP/1.1" 404 3352 "www.go ...
show more
170.64.223.52 - - [03/May/2026:11:43:22 +0300] "GET /wp-content/flame.php HTTP/1.1" 404 3352 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
170.64.223.52 - - [03/May/2026:11:43:21 +0300] "GET /wp-content/themes/alera/alpha.php HTTP/1.1" 404 3353 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐ฉ๐ช
LRob
|
|
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
|
Bad Web Bot
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
170.64.223.52 - - [03/May/2026:09:03:28 +0300] "GET /wp-content/themes/alera/alpha.php HTTP/1.1" 404 ...
show more
170.64.223.52 - - [03/May/2026:09:03:28 +0300] "GET /wp-content/themes/alera/alpha.php HTTP/1.1" 404 3349 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
170.64.223.52 - - [03/May/2026:09:03:29 +0300] "GET /wp-includes/class-wp-other.php HTTP/1.1" 404 3351 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐บ๐ธ
jormaster3k
|
|
Attack against Apache (too many 404s)
|
Web App Attack
|
|
|
Anonymous
|
|
[02/May/2026:14:25:14 +0300] 177772111490.759008 170.64.223.52 55748 148.251.76.218 80
[02/May/2026: ...
show more
[02/May/2026:14:25:14 +0300] 177772111490.759008 170.64.223.52 55748 148.251.76.218 80
[02/May/2026:14:25:16 +0300] 177772111672.829243 170.64.223.52 55978 148.251.76.218 443
show less
|
Web App Attack
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
170.64.223.52 - - [02/May/2026:12:33:27 +0300] "GET /wp-content/themes/alera/alpha.php HTTP/1.1" 404 ...
show more
170.64.223.52 - - [02/May/2026:12:33:27 +0300] "GET /wp-content/themes/alera/alpha.php HTTP/1.1" 404 3353 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
170.64.223.52 - - [02/May/2026:12:33:28 +0300] "GET /wp-content/flame.php HTTP/1.1" 404 3353 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐ฎ๐ฉ
sockominfo
|
|
TheHive Threat Scoring assessment: 170.64.223.52
CVSS v3.1: 0/10 (None)
CVSS Vector: CVSS:3.1/AV:und ...
show more
TheHive Threat Scoring assessment: 170.64.223.52
CVSS v3.1: 0/10 (None)
CVSS Vector: CVSS:3.1/AV:undefined/AC:undefined/PR:undefined/UI:undefined/S:undefined/C:undefined/I:undefined/A:undefined
Bayesian Probability: 80%
MITRE ATT&CK: Exploit Public-Facing Application, Valid Accounts, Command and Scripting Interpreter, Application Layer Protocol, Brute Force, Account Manipulation
OWASP Risk: High (L:8, I:6)
Combined Score: 4.92/10
Confidence Interval: ยฑ0.01
Status: Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
|
Hacking
Email Spam
|
|
|
๐บ๐ธ
mawan
|
|
Suspected of having performed illicit activity on LAX server.
|
Web App Attack
|
|