Automated vulnerability scanner attempting PHP RCE (Remote Code Execution) via HTTP headers. The inj ...
show moreAutomated vulnerability scanner attempting PHP RCE (Remote Code Execution) via HTTP headers. The injected payload was: ;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7')); which decodes to print(md5(31337));. The request was blocked by the web server (HTTP 403).
show less
Attacking IP uploaded and interacted with PHP and ASP.NET webshells on an IIS/WordPress server. The ...
show moreAttacking IP uploaded and interacted with PHP and ASP.NET webshells on an IIS/WordPress server. The attacker used the webshells to attempt an in-memory malicious DLL execution (T1129 - Execution via Shared Modules) using .NET Reflection, which was blocked by our EDR (CrowdStrike).
IIS Access Logs:
2026-07-27 09:11:11 POST /wp-content/pt-br.php - 443 - 157.254.54.19 HTTP/1.1 - 200
2026-07-27 09:11:18 GET /etc/atest.aspx - 443 - 157.254.54.19 HTTP/1.1 - 200
2026-07-27 09:11:32 POST /etc/atest.aspx - 443 - 157.254.54.19 HTTP/1.1 - 200
show less
Automated vulnerability scanner / bad web bot performing aggressive fuzzing and web application atta ...
show moreAutomated vulnerability scanner / bad web bot performing aggressive fuzzing and web application attacks. Attempted Cross-Site Scripting (XSS) injections via 'awstats.pl' parameters, Local File Inclusion (LFI) directory traversal attempts for '/etc/passwd' and 'win.ini', and brute-forcing common backup files (.tar, .7z) and sensitive endpoints (xmlrpc, openflashchart).
show less
Automated fuzzing and attempt to interact with a Web Shell (Remote Code Execution) on a shared web h ...
show moreAutomated fuzzing and attempt to interact with a Web Shell (Remote Code Execution) on a shared web hosting server. The attacker attempted to bypass filters by requesting multiple obfuscated PHP extensions (.ph$p, .php.PhP, .phar, etc.) looking for vulnerable upload directories.
Log snippet:
[02/Jul/2026:07:24:46 -0300] "GET /d44b8f26d823.php HTTP/1.1" 403 472 "https://verdelight.com.br/tmp/272272.ph$p" "Mozilla/5.0 (Windows NT 5.1; WOW64; rv:48.0)"
show less
We detected a phishing web site hosted at:
mailocaweb.click
This is a fake website pretending ...
show moreWe detected a phishing web site hosted at:
mailocaweb.click
This is a fake website pretending to be Locaweb website with the intent of committing fraud against the organization and/or its users. The organization's legitimate website is:
webmail-seguro.com.br
show less
Exploited CMS log in via API and massively using for phishing:
182.0.250.214 - - [19/Dec/2024:04:24 ...
show moreExploited CMS log in via API and massively using for phishing:
182.0.250.214 - - [19/Dec/2024:04:24:38 -0300] "POST //enterprise/control/agent.php HTTP/1.1" 200 224 "-" "python-requests/2.31.0" "-"'/enterprise/control/agent.php' '' '
182.0.250.214 - - [19/Dec/2024:04:29:04 -0300] "POST //enterprise/control/agent.php HTTP/1.1" 200 224 "-" "python-requests/2.31.0" "-"'/enterprise/control/agent.php' ''
182.0.250.214 - - [19/Dec/2024:04:24:38 -0300] "POST //enterprise/control/agent.php HTTP/1.1" 200 224 "-" "python-requests/2.31.0" "-"'/enterprise/control/agent.php' ''
show less