User Mmm Gun
joined AbuseIPDB in March 2023 and has reported 22 IP
addresses.
Standing (weight) is
good.
INACTIVE USER
| IP |
Date |
Comment |
Categories |
|
π©πͺ
172.68.195.144
|
|
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep function with sele ...
show more
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep function with select - likely SQL inj 1958
SERVER-OTHER Ghost CMS static-theme.js CVE-2023-32235 Path Traversal 828
SERVER-OTHER Multiple products UNIX platform backslash dir traversal attempt 519
SERVER-APACHE Apache Tomcat AllowLinking URIencoding CVE-2008-2938 dir Traversal Attempt 378
SQL url ending in comment char - possible sql injection attempt 305
SERVER-WEBAPP SolarWinds Storage Manager dir traversal attempt 259
SERVER-OTHER Zimbra XML External Entity Info Disclosure 164
61071 VID22518 Exe File download over HTTP from dotted-quad Host 155
SERVER-WEBAPP TVT NVMS-1000 CVE-2019-20085 dir Traversal 104
show less
|
Web App Attack
|
|
π©πͺ
172.68.192.203
|
|
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep function with sele ...
show more
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep function with select - likely SQL inj 1958
SERVER-OTHER Ghost CMS static-theme.js CVE-2023-32235 Path Traversal 828
SERVER-OTHER Multiple products UNIX platform backslash dir traversal attempt 519
SERVER-APACHE Apache Tomcat AllowLinking URIencoding CVE-2008-2938 dir Traversal Attempt 378
SQL url ending in comment char - possible sql injection attempt 305
SERVER-WEBAPP SolarWinds Storage Manager dir traversal attempt 259
SERVER-OTHER Zimbra XML External Entity Info Disclosure 164
61071 VID22518 Exe File download over HTTP from dotted-quad Host 155
SERVER-WEBAPP TVT NVMS-1000 CVE-2019-20085 dir Traversal 104
SERVER-ORACLE Oracle MySQL sql_auth Integer Overflow 27
SERVER-OTHER Spring Boot Actuator Access Attempt 16
show less
|
Web App Attack
|
|
π©πͺ
172.68.192.202
|
|
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep function with sele ...
show more
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep function with select - likely SQL inj 1958
SERVER-OTHER Ghost CMS static-theme.js CVE-2023-32235 Path Traversal 828
SERVER-OTHER Multiple products UNIX platform backslash dir traversal attempt 519
SERVER-APACHE Apache Tomcat AllowLinking URIencoding CVE-2008-2938 dir Traversal Attempt 378
SQL url ending in comment char - possible sql injection attempt 305
SERVER-WEBAPP SolarWinds Storage Manager dir traversal attempt 259
SERVER-OTHER Zimbra XML External Entity Info Disclosure 164
61071 VID22518 Exe File download over HTTP from dotted-quad Host 155
SERVER-WEBAPP TVT NVMS-1000 CVE-2019-20085 dir Traversal 104
SERVER-ORACLE Oracle MySQL sql_auth Integer Overflow 27
show less
|
Web App Attack
|
|
π©πͺ
162.158.95.63
|
|
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep function with sele ...
show more
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep function with select - likely SQL inj 1958
SERVER-OTHER Ghost CMS static-theme.js CVE-2023-32235 Path Traversal 828
SERVER-OTHER Multiple products UNIX platform backslash dir traversal attempt 519
SERVER-APACHE Apache Tomcat AllowLinking URIencoding CVE-2008-2938 dir Traversal Attempt 378
SQL url ending in comment char - possible sql injection attempt 305
SERVER-WEBAPP SolarWinds Storage Manager dir traversal attempt 259
SERVER-OTHER Zimbra XML External Entity Info Disclosure 164
61071 VID22518 Exe File download over HTTP from dotted-quad Host 155
show less
|
Web App Attack
|
|
π©πͺ
104.23.239.109
|
|
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep with select - likely SQL 1958
...
show more
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep with select - likely SQL 1958
SERVER-OTHER Ghost CMS static-theme.js CVE-2023-32235 Path Traversal 828
SERVER-OTHER Multiple products UNIX platform backslash directory traversal attempt 519
SERVER-APACHE Apache Tomcat AllowLinking URIencoding CVE-2008-2938 Directory Traversal Attempt 378
SQL url ending in comment characters - possible sql injection attempt 305
SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt 259
SERVER-OTHER Zimbra XML External Entity Information Disclosure 164
61071 VID22518 Executable File download over HTTP from dotted-quad Host 155
SERVER-WEBAPP TVT NVMS-1000 CVE-2019-20085 Directory Traversal 104
SERVER-ORACLE Oracle MySQL sql_authentication Integer Overflow 27
SERVER-OTHER Spring Boot Actuator Access Attempt 16
SERVER-APACHE Apache Tomcat mod_jk CVE-2018-11759 Access Control Bypass Attempt 7
SERVER-WEBAPP Moveable Type unauthenticated remote command execution attempt 7
SERVER-WEBAP
show less
|
Web App Attack
|
|
π©πͺ
104.23.239.108
|
|
Attack Hits
SERVER-WEBAPP /etc/passwd access attempt 3316
SQL use of sleep function with select - ...
show more
Attack Hits
SERVER-WEBAPP /etc/passwd access attempt 3316
SQL use of sleep function with select - likely SQL injection 1958
SERVER-OTHER Ghost CMS static-theme.js CVE-2023-32235 Path 828
SERVER-OTHER Multiple products UNIX platform backslash directory traversal attempt 519
SERVER-APACHE Apache Tomcat AllowLinking URIencoding CVE-2008-2938 Directory Traversal Attempt 378
SQL url ending in comment characters - possible sql injection attempt 305
SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt 259
SERVER-OTHER Zimbra XML External Entity Information Disclosure 164
61071 VID22518 Executable File download over HTTP from dotted-quad Host 155
SERVER-WEBAPP TVT NVMS-1000 CVE-2019-20085 Directory Traversal 104
SERVER-ORACLE Oracle MySQL sql_authentication Integer Overflow 27
SERVER-OTHER Spring Boot Actuator Access Attempt 16
SERVER-APACHE Apache Tomcat mod_jk CVE-2018-11759 Access Control Bypass Attempt 7
SERVER-WEBAPP Moveable Type unauthenticated command execution attempt 7
show less
|
Web App Attack
|
|
π©πͺ
104.22.123.17
|
|
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep - likely SQL injec ...
show more
Attack Hits
SERVER-WEBAPP /etc/passwd file access attempt 3316
SQL use of sleep - likely SQL injection 1958
SERVER-OTHER Ghost CMS static-theme.js CVE-2023-32235 Path Traversal 828
SERVER-OTHER Multiple UNIX backslash dir traversal attempt 519
SERVER-APACHE Apache Tomcat AllowLinking URIencoding CVE-2008-2938 Directory Traversal Attempt 378
SQL url ending in comment characters - possible sql injection attempt 305
SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt 259
SERVER-OTHER Z
show less
|
Web App Attack
|
|
πΉπ·
31.56.64.55
|
|
31.56.64.0/24 ddos attack
|
DDoS Attack
|
|
πΉπ·
217.18.85.189
|
|
217.18.85.0/24 DDOS attack
|
DDoS Attack
|
|
πΉπ·
45.152.243.148
|
|
|
DDoS Attack
|
|
πΉπ·
185.188.128.75
|
|
ip ranges 185.188.128.0-185.188.131.255 inwolved in ddos attack
|
DDoS Attack
|
|
ππ°
152.32.186.240
|
|
brute force from 93.123.109.0/24
|
Brute-Force
|
|
πΉπ·
91.198.66.12
|
|
ddos in range 91.198.66.0/24
|
DDoS Attack
|
|
πΉπ·
45.158.57.115
|
|
ddos in range of ips 45.158.57.0/24
|
DDoS Attack
|
|
πΉπ·
45.10.151.248
|
|
ddos in range 45.10.151.0/24
|
DDoS Attack
|
|
πΉπ·
185.148.240.156
|
|
ddos from range of
185.148.240.0/24
|
DDoS Attack
|
|
πΉπ·
213.238.176.101
|
|
ddos in range 213.238.176.0/24
|
DDoS Attack
|
|
πΉπ·
213.238.178.5
|
|
250 attacker in subnet 213.238.178.0/24
|
DDoS Attack
|
|
πΉπ·
37.230.60.0
|
|
all subnet involved in ddos attack
|
DDoS Attack
|
|
πΉπ·
5.180.104.204
|
|
ddos from subnet 5.180.104.0/24
|
DDoS Attack
|
|
πΉπ·
5.180.104.86
|
|
all subnet of 5.180.104.0/24 involved in ddos
|
DDoS Attack
|