Attacking IP uploaded and interacted with PHP and ASP.NET webshells on an IIS/WordPress server. The ...
show moreAttacking IP uploaded and interacted with PHP and ASP.NET webshells on an IIS/WordPress server. The attacker used the webshells to attempt an in-memory malicious DLL execution (T1129 - Execution via Shared Modules) using .NET Reflection, which was blocked by our EDR (CrowdStrike).
IIS Access Logs:
2026-07-27 09:11:11 POST /wp-content/pt-br.php - 443 - 157.254.54.19 HTTP/1.1 - 200
2026-07-27 09:11:18 GET /etc/atest.aspx - 443 - 157.254.54.19 HTTP/1.1 - 200
2026-07-27 09:11:32 POST /etc/atest.aspx - 443 - 157.254.54.19 HTTP/1.1 - 200
show less
Automated vulnerability scanner / bad web bot performing aggressive fuzzing and web application atta ...
show moreAutomated vulnerability scanner / bad web bot performing aggressive fuzzing and web application attacks. Attempted Cross-Site Scripting (XSS) injections via 'awstats.pl' parameters, Local File Inclusion (LFI) directory traversal attempts for '/etc/passwd' and 'win.ini', and brute-forcing common backup files (.tar, .7z) and sensitive endpoints (xmlrpc, openflashchart).
show less
Automated fuzzing and attempt to interact with a Web Shell (Remote Code Execution) on a shared web h ...
show moreAutomated fuzzing and attempt to interact with a Web Shell (Remote Code Execution) on a shared web hosting server. The attacker attempted to bypass filters by requesting multiple obfuscated PHP extensions (.ph$p, .php.PhP, .phar, etc.) looking for vulnerable upload directories.
Log snippet:
[02/Jul/2026:07:24:46 -0300] "GET /d44b8f26d823.php HTTP/1.1" 403 472 "https://verdelight.com.br/tmp/272272.ph$p" "Mozilla/5.0 (Windows NT 5.1; WOW64; rv:48.0)"
show less
We detected a phishing web site hosted at:
mailocaweb.click
This is a fake website pretending ...
show moreWe detected a phishing web site hosted at:
mailocaweb.click
This is a fake website pretending to be Locaweb website with the intent of committing fraud against the organization and/or its users. The organization's legitimate website is:
webmail-seguro.com.br
show less
Exploited CMS log in via API and massively using for phishing:
182.0.250.214 - - [19/Dec/2024:04:24 ...
show moreExploited CMS log in via API and massively using for phishing:
182.0.250.214 - - [19/Dec/2024:04:24:38 -0300] "POST //enterprise/control/agent.php HTTP/1.1" 200 224 "-" "python-requests/2.31.0" "-"'/enterprise/control/agent.php' '' '
182.0.250.214 - - [19/Dec/2024:04:29:04 -0300] "POST //enterprise/control/agent.php HTTP/1.1" 200 224 "-" "python-requests/2.31.0" "-"'/enterprise/control/agent.php' ''
182.0.250.214 - - [19/Dec/2024:04:24:38 -0300] "POST //enterprise/control/agent.php HTTP/1.1" 200 224 "-" "python-requests/2.31.0" "-"'/enterprise/control/agent.php' ''
show less