ET EXPLOIT MVPower DVR Shell UCE
ET HUNTING Suspicious Chmod Usage in URI (Inbound)
ET SCAN JAWS W ...
show moreET EXPLOIT MVPower DVR Shell UCE
ET HUNTING Suspicious Chmod Usage in URI (Inbound)
ET SCAN JAWS Webserver Unauthenticated Shell Command Execution
ET SCAN Mirai Variant User-Agent (Inbound)
@timestamp
Aug 4, 2021 @ 03:02:51.153
source.ip
183.15.88.95
show less
ET HUNTING Suspicious Chmod Usage in URI (Inbound)
ET SCAN JAWS Webserver Unauthenticated Shell Com ...
show moreET HUNTING Suspicious Chmod Usage in URI (Inbound)
ET SCAN JAWS Webserver Unauthenticated Shell Command Execution
ET SCAN Mirai Variant User-Agent (Inbound)
@timestamp
Aug 4, 2021 @ 01:33:26.025
source.address
114.239.177.203
show less
ET EXPLOIT MVPower DVR Shell UCE
ET HUNTING Suspicious Chmod Usage in URI (Inbound)
ET SCAN JAWS W ...
show moreET EXPLOIT MVPower DVR Shell UCE
ET HUNTING Suspicious Chmod Usage in URI (Inbound)
ET SCAN JAWS Webserver Unauthenticated Shell Command Execution
ET SCAN Mirai Variant User-Agent (Inbound)
show less
ET WEB_SERVER Script tag in URI Possible Cross Site Scripting Attempt
related.ip
178.63.152.212, 1 ...
show moreET WEB_SERVER Script tag in URI Possible Cross Site Scripting Attempt
related.ip
178.63.152.212, 192.168.7.2
rule.category
Web Application Attack
rule.id
2009714
rule.name
show less
{"timestamp":"2021-08-03T16:44:09.495737-0700","flow_id":755638641107061,"in_iface":"enx8cae4cf422e8 ...
show more{"timestamp":"2021-08-03T16:44:09.495737-0700","flow_id":755638641107061,"in_iface":"enx8cae4cf422e8","event_type":"alert","vlan":[7],"src_ip":"95.32.28.242","src_port":31873,"dest_ip":"192.168.7.2","dest_port":80,"proto":"TCP","community_id":"1:YlRCXmb9szWUOaBixu8OWczSHcU=","tx_id":0,"alert":{"action":"allowed","gid":1,"signature_id":2031501,"rev":2,"signature":"ET INFO Netlink GPON Login Attempt (GET)","category":"Attempted Administrator Privilege Gain","severity":1,"metadata":{"created_at":["2021_01_08"],"updated_at":["2021_01_08"]}},"http":{"url":"/boaform/admin/formLogin?username=adminisp&psd=adminisp","http_method":"GET","protocol":"HTTP/1.0","length":0},"app_proto":"http","flow":{"pkts_toserver":4,"pkts_toclient":4,"bytes_toserver":477,"bytes_toclient":948,"start":"2021-08-03T16:44:08.008309-0700"}}
show less
{"timestamp":"2021-07-30T12:18:55.508370-0700","flow_id":165490737533052,"in_iface":"enx8cae4cf422e8 ...
show more{"timestamp":"2021-07-30T12:18:55.508370-0700","flow_id":165490737533052,"in_iface":"enx8cae4cf422e8","event_type":"alert","vlan":[7],"src_ip":"201.97.226.106","src_port":49479,"dest_ip":"192.168.7.2","dest_port":80,"proto":"TCP","metadata":{"flowints":{"http.anomaly.count":1}},"community_id":"1:YaEffpTSYzO4DM/45UrKaQyDeMs=","tx_id":0,"alert":{"action":"allowed","gid":1,"signature_id":2221014,"rev":1,"signature":"SURICATA HTTP missing Host header","category":"Generic Protocol Command Decode","severity":3},"http":{"url":"/","http_method":"GET","protocol":"HTTP/1.1","length":0},"app_proto":"http","flow":{"pkts_toserver":5,"pkts_toclient":5,"bytes_toserver":368,"bytes_toclient":836,"start":"2021-07-30T12:18:55.315516-0700"}}
show less
{"timestamp":"2021-07-30T10:49:26.295066-0700","flow_id":723133906951093,"in_iface":"enx8cae4cf422e8 ...
show more{"timestamp":"2021-07-30T10:49:26.295066-0700","flow_id":723133906951093,"in_iface":"enx8cae4cf422e8","event_type":"alert","vlan":[7],"src_ip":"189.161.45.80","src_port":40108,"dest_ip":"192.168.7.2","dest_port":80,"proto":"TCP","metadata":{"flowints":{"http.anomaly.count":1}},"community_id":"1:vNQmEB4OJnVsxTgT81Vap4EuIrs=","tx_id":0,"alert":{"action":"allowed","gid":1,"signature_id":2221014,"rev":1,"signature":"SURICATA HTTP missing Host header","category":"Generic Protocol Command Decode","severity":3},"http":{"url":"/","http_method":"GET","protocol":"HTTP/1.1","length":0},"app_proto":"http","flow":{"pkts_toserver":5,"pkts_toclient":5,"bytes_toserver":368,"bytes_toclient":836,"start":"2021-07-30T10:49:26.138165-0700"}}
show less
Attempted Unauthorized Access
{"timestamp":"2021-07-29T23:21:04.287677-0700","flow_id":14392547197 ...
show moreAttempted Unauthorized Access
{"timestamp":"2021-07-29T23:21:04.287677-0700","flow_id":1439254719767160,"in_iface":"enx8cae4cf422e8","event_type":"alert","vlan":[7],"src_ip":"63.224.143.218","src_port":38800,"dest_ip":"192.168.7.2","dest_port":80,"proto":"TCP","community_id":"1:Blv38UJnpnTKwmo7D+SRns/gSFc=","tx_id":0,"alert":{"action":"allowed","gid":1,"signature_id":2031502,"rev":1,"signature":"ET INFO Request to Hidden Environment File","category":"Misc Attack","severity":2,"metadata":{"created_at":["2021_01_08"],"updated_at":["2021_01_08"]}},"http":{"hostname":"76.94.115.242","url":"/.env","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","http_content_type":"text/html","http_method":"GET","protocol":"HTTP/1.1","status":301
show less
Attempted Access
{"timestamp":"2021-07-29T22:53:09.958154-0700","flow_id":676661691784906,"in_iface ...
show moreAttempted Access
{"timestamp":"2021-07-29T22:53:09.958154-0700","flow_id":676661691784906,"in_iface":"enx8cae4cf422e8","event_type":"alert","vlan":[7],"src_ip":"62.210.245.181","src_port":44314,"dest_ip":"192.168.7.2","dest_port":443,"proto":"TCP","community_id":"1:cQ4doaieamU05C1HVOuIVhV5CuE=","alert":{"action":"allowed","gid":1,"signature_id":2403377,"rev":67640,"signature":"ET CINS Active Threat Intelligence Poor Reputation IP group 78","category":"Misc Attack","severity":2,"metadata":{"affected_product":["Any"],"attack_target":["Any"],"created_at":["2013_10_08"],"deployment":["Perimeter"],"signature_severity":["Major"],"tag":["CINS"],"updated_at":["2021_07_28"]}},"flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":56,"bytes_toclient":0,"start":"2021-07-29T22:53:09.958154-0700"}}
show less
{"timestamp":"2021-07-30T07:40:39.395046-0700","flow_id":1268070025018252,"in_iface":"enx8cae4cf422e ...
show more{"timestamp":"2021-07-30T07:40:39.395046-0700","flow_id":1268070025018252,"in_iface":"enx8cae4cf422e8","event_type":"alert","vlan":[7],"src_ip":"59.99.42.202","src_port":58094,"dest_ip":"192.168.7.2","dest_port":80,"proto":"TCP","community_id":"1:o26ooY3Iyb/0tpo98bJ9+RjCGZ0=","tx_id":0,"alert":{"action":"allowed","gid":1,"signature_id":2031501,"rev":2,"signature":"ET INFO Netlink GPON Login Attempt (GET)","category":"Attempted Administrator Privilege Gain","severity":1,"metadata":{"created_at":["2021_01_08"],"updated_at":["2021_01_08"]}},"http":{"url":"/boaform/admin/formLogin?username=adminisp&psd=adminisp","http_method":"GET","protocol":"HTTP/1.0","length":0},"app_proto":"http","flow":{"pkts_toserver":4,"pkts_toclient":5,"bytes_toserver":477,"bytes_toclient":1022,"start":"2021-07-30T07:40:36.408460-0700"}}
show less
{"timestamp":"2021-07-29T21:30:18.152485-0700","flow_id":131290713628887,"in_iface":"enx8cae4cf422e8 ...
show more{"timestamp":"2021-07-29T21:30:18.152485-0700","flow_id":131290713628887,"in_iface":"enx8cae4cf422e8","event_type":"alert","vlan":[7],"src_ip":"45.77.237.74","src_port":53976,"dest_ip":"192.168.7.2","dest_port":80,"proto":"TCP","community_id":"1:lL7K09kNPGpDTDGWVbs/E23E/kI=","tx_id":0,"alert":{"action":"allowed","gid":1,"signature_id":2031502,"rev":1,"signature":"ET INFO Request to Hidden Environment File","category":"Misc Attack","severity":2,"metadata":{"created_at":["2021_01_08"],"updated_at":["2021_01_08"]}},"http":{"hostname":"76.94.115.242","url":"/.env","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","http_content_type":"text/html","http_method":"GET","protocol":"HTTP/1.1","status":301,"redirect":"https://cloud.shaneburkhardt.com/.env","length":324},"app_proto":"http","flow":{"pkts_toserver":4,"pkts_toclient":3,"bytes_toserver":467,"bytes_toclient":778,"start":"2021-07-29T21:30:17.467159-0700"}}
show less