External IP 62.133.47.16 performed automated vulnerability scanning against our DMZ web server (62.2 ...
show moreExternal IP 62.133.47.16 performed automated vulnerability scanning against our DMZ web server (62.28.4.75). The activity triggered firewall IPS signatures identifying OpenVAS Vulnerability Scanner patterns.
Observed behavior:
- High-frequency HTTP requests to multiple paths
- Enumeration of web application endpoints
- Probing for known vulnerable files and services
show less
Repeated web application exploitation attempts from this IP.
Directory traversal / LFI payloads tar ...
show moreRepeated web application exploitation attempts from this IP.
Directory traversal / LFI payloads targeting Linux and Windows files, including /etc/passwd and windows/win.ini.
Example requests:
/file/../../../../windows/win.ini
/iclock/file?url=/../../../../windows/win.ini
Multiple failures (400) followed by a successful request (302), indicating active exploitation.
show less
HackingWeb App Attack
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.