๐ฉ๐ช
152.233.51.60
24 Aug 2026
ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
138.199.15.165
22 Aug 2026
ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
194.126.179.80
21 Aug 2026
ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt
Hacking
Brute-Force
Web App Attack
๐จ๐ฆ
38.240.225.93
18 Aug 2026
ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt
VPN IP
Hacking
Brute-Force
๐ฎ๐น
178.249.211.68
18 Aug 2026
Event Type: Attempted Administrator Privilege Gain
Signature: ET EXPLOIT Fortigate VPN - Request to ...
show more
Event Type: Attempted Administrator Privilege Gain
Signature: ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt
show less
VPN IP
Hacking
Brute-Force
๐บ๐ธ
23.234.76.159
12 Aug 2026
Attempted Administrator Privilege Gain
ET EXPLOIT Fortigate VPN - Request to /remote/info - Possibl ...
show more
Attempted Administrator Privilege Gain
ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt
show less
Hacking
Brute-Force
๐ฉ๐ช
169.150.201.32
09 Aug 2026
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Fortigate VPN - Request to /remote/in ...
show more
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt"; flow:established,to_server; threshold: type limit, track by_src, count 1, seconds 120; http.method; content:"GET"; http.uri; content:"/remote/info"; fast_pattern; startswith; reference:cve,2023-27997; reference:url,blog.lexfo.fr/xortigate-cve-2023-27997.html; classtype:attempted-admin; sid:2046256; rev:1; metadata:affected_product Fortigate, attack_target Networking_Equipment, created_at 2023_06_13, cve CVE_2023_27997, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2023_06_13; target:dest_ip;)
show less
Hacking
๐ซ๐ท
45.134.79.70
27 Jul 2026
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Fortigate VPN - Request to /remote/in ...
show more
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Fortigate VPN - Request to /remote/info - Possible CVE-2023-27997 Exploit Attempt"; flow:established,to_server; threshold: type limit, track by_src, count 1, seconds 120; http.method; content:"GET"; http.uri; content:"/remote/info"; fast_pattern; startswith; reference:cve,2023-27997; reference:url,blog.lexfo.fr/xortigate-cve-2023-27997.html; classtype:attempted-admin; sid:2046256; rev:1; metadata:affected_product Fortigate, attack_target Networking_Equipment, created_at 2023_06_13, cve CVE_2023_27997, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2023_06_13; target:dest_ip;)
show less
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
34.34.103.195
13 Jul 2026
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL WEB_SERVER .htpasswd access"; flow:to_se ...
show more
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL WEB_SERVER .htpasswd access"; flow:to_server,established; content:".htpasswd"; nocase; classtype:web-application-attack; sid:2101071; rev:8; metadata:created_at 2010_09_23, signature_severity Unknown,;)
show less
Hacking
Web App Attack
๐ณ๐ฑ
91.92.243.238
21 Apr 2026
Exceeded the maximum number of login failures which is: 3. The last username they tried to sign in w ...
show more
Exceeded the maximum number of login failures which is: 3. The last username they tried to sign in with was: '*********'
show less
Brute-Force
๐ฎ๐ช
85.208.38.113
21 Apr 2026
Blocked by login security setting
Brute-Force
Web App Attack
๐ช๐ฌ
105.196.23.213
21 Apr 2026
Blocked by login security setting
Brute-Force
Web App Attack
๐ช๐ธ
85.54.34.193
21 Apr 2026
Used an invalid username 'user' to try to sign in
Brute-Force
Web App Attack
๐จ๐ฑ
190.114.33.122
21 Apr 2026
Used an invalid username 'admingusar' to try to sign in
Brute-Force
Web App Attack
๐ช๐ธ
92.114.59.27
21 Apr 2026
Used an invalid username 'Adminroot' to try to sign in
Brute-Force
Web App Attack
๐จ๐ฑ
181.42.128.242
21 Apr 2026
Web App Attack
๐ฌ๐ท
79.127.218.201
10 Apr 2026
The IP address [79.127.218.201] experienced x failed attempts when attempting to log in to FTP runni ...
show more
The IP address [79.127.218.201] experienced x failed attempts when attempting to log in to FTP running on xxxxxx within x minutes, and was blocked.
show less
FTP Brute-Force
๐ฌ๐ท
89.210.32.93
13 Jan 2026
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Aribitrary File Upload Vulnera ...
show more
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Aribitrary File Upload Vulnerability in WP Mobile Detector"; flow:from_client,established; http.uri; content:"/wp-content/plugins/wp-mobile-detector/"; content:"resize.php?src=http"; fast_pattern; reference:url,pluginvulnerabilities.com/2016/05/31/aribitrary-file-upload-vulnerability-in-wp-mobile-detector/; classtype:attempted-user; sid:2022860; rev:4; metadata:created_at 2016_06_03, updated_at 2020_09_14;)
show less
Hacking
Web App Attack
๐ณ๐ฑ
193.142.147.209
12 Jan 2026
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS React Server Components React2Shell U ...
show more
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182)"; flow:established,to_server; http.header; content:"next-action|3a 20|"; fast_pattern; nocase; http.content_type; content:"multipart/form-data|3b|"; http.request_body; content:"|24 40|"; pcre:"/^[0-9a-fA-F]+\x22?\x0d\x0a/R"; content:"|22|_prefix|22|"; content:"|22|_formData|22|"; content:"|22 24|"; pcre:"/^[0-9a-fA-F]+\x3a(?:__proto__|constructor|Module)\x3a/R"; http.method; content:"POST"; reference:url,react2shell.com/; reference:cve,2025-55182; classtype:web-application-attack; sid:2066027; rev:3; metadata:affected_product Next_js, affected_product React, attack_target Server, tls_state TLSDecrypt, created_at 2025_12_04, cve CVE_2025_55182, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence Medium, signature_severity Major, tag Exploit, updated_at 2025_12_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techni
show less
Web App Attack
๐ฉ๐ช
130.12.180.18
02 Jan 2026
alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible IIS Integer Overflow DoS (CVE-2 ...
show more
alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible IIS Integer Overflow DoS (CVE-2015-1635)"; flow:established,to_server; http.header; content:"Range|3a|"; nocase; content:"18446744073709551615"; fast_pattern; distance:0; pcre:"/^Range\x3a[^\r\n]*?18446744073709551615/mi"; reference:cve,2015-1635; classtype:web-application-attack; sid:2020912; rev:5; metadata:created_at 2015_04_15, cve CVE_2015_1635, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2020_10_13;)
show less
DDoS Attack
๐ฑ๐น
194.165.16.11
08 Dec 2025
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Zimbra <8.8.11 - XML External Entity ...
show more
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Zimbra <8.8.11 - XML External Entity Injection/SSRF Attempt (CVE-2019-9621)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/autodiscover"; nocase; http.request_body; content:"<!DOCTYPE"; depth:50; content:"file:///etc/passwd"; distance:0; fast_pattern; content:"<EMailAddress>"; content:"<AcceptableResponseSchema>"; reference:url,www.exploit-db.com/exploits/46967; reference:url,packetstormsecurity.com/files/152487/Zimbra-Collaboration-Autodiscover-Servlet-XXE-ProxyServlet-SSRF.html; reference:cve,2019-9621; reference:cve,2021-2109; classtype:attempted-user; sid:2031562; rev:1; metadata:affected_product Web_Server_Applications, attack_target Client_Endpoint, created_at 2021_01_27, cve CVE_2021_2109, deployment Perimeter, confidence Medium, signature_severity Major, updated_at 2021_01_27;)
show less
Hacking
Web App Attack
๐ฑ๐น
194.165.16.11
19 Sep 2025
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Exploit Suspected PHP Injectio ...
show more
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Exploit Suspected PHP Injection Attack (cmd=)"; flow:established,to_server; http.method; content:"GET"; nocase; http.uri; content:".php?"; nocase; content:"cmd="; fast_pattern; nocase; pcre:"/[&?]cmd=[^\x26\x28]*(?:cd|\;|echo|cat|perl|curl|wget|id|uname|t?ftp)/i"; reference:cve,2002-0953; classtype:web-application-attack; sid:2010920; rev:10; metadata:created_at 2010_07_30, cve CVE_2002_0953, confidence Medium, signature_severity Major, updated_at 2024_01_03;)
show less
Web App Attack
๐ท๐ด
141.98.82.26
16 Sep 2025
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Possible Ivanti Pulse Secur ...
show more
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Possible Ivanti Pulse Secure Authentication Bypass and Command Injection Attempt (CVE-2023-46805, CVE-2024-21887) M1"; flow:established,to_server; http.request_line; pcre:"/^(GE|POS)T/"; content:"/api/v1/totp/"; distance:0; fast_pattern; content:"./"; distance:0; content:"./"; distance:0; reference:url,attackerkb.com/topics/AdUh6by52K/cve-2023-46805/rapid7-analysis; reference:cve,2023-46805; reference:cve,2024-21887; classtype:trojan-activity; sid:2050131; rev:2; metadata:affected_product Pulse_Secure, created_at 2024_01_17, cve CVE_2023_46805_CVE_2024_21887, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, updated_at 2024_11_26, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
show less
Hacking
Web App Attack
๐ท๐ด
141.98.82.26
16 Sep 2025
drop http [$EXTERNAL_NET,![194.165.16.71]] any -> $HOME_NET any (msg:"ET WEB_SERVER PHP tags in HTT ...
show more
drop http [$EXTERNAL_NET,![194.165.16.71]] any -> $HOME_NET any (msg:"ET WEB_SERVER PHP tags in HTTP POST"; flow:established,to_server; http.method; content:"POST"; nocase; http.request_body; content:"<?php"; nocase; fast_pattern; reference:url,isc.sans.edu/diary.html?storyid=9478; classtype:web-application-attack; sid:4000099; rev:1; metadata:created_at 2010_09_28, signature_severity Informational, updated_at 2020_09_18;)
show less
Hacking
๐ฑ๐น
194.165.16.11
15 Sep 2025
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible INSERT VALUES SQL Inj ...
show more
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible INSERT VALUES SQL Injection Attempt"; flow:established,to_server; http.uri; content:"INSERT"; nocase; content:"VALUES"; nocase; distance:0; reference:url,ferruh.mavituna.com/sql-injection-cheatsheet-oku/; reference:url,en.wikipedia.org/wiki/Insert_(SQL); classtype:web-application-attack; sid:2011039; rev:6; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
show less
Web App Attack