๐ฎ๐ณ
203.115.91.51
02 Nov 2021
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER 401TRG Generic Webshell Reques ...
show more
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER 401TRG Generic Webshell Request - POST with wget in body"; flow:established,to_server; content:"wget"; nocase; http_client_body; content:"http"; nocase; http_client_body; within:11; threshold:type limit, track by_src, seconds 3600, count 1; classtype:web-application-attack; sid:2024930; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2017_10_26, deployment Datacenter, former_category WEB_SERVER, malware_family webshell, performance_impact Moderate, signature_severity Major, updated_at 2020_08_13;)
show less
Hacking
Web App Attack
๐ฎ๐น
87.4.177.28
29 Oct 2021
alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS [PT OPEN] Drupalgeddon2 <8.3.9 <8 ...
show more
alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS [PT OPEN] Drupalgeddon2 <8.3.9 <8.4.6 <8.5.1 RCE Through Registration Form (CVE-2018-7600)"; flow:established,to_server; content:"/user/register"; http_uri; content:"POST"; http_method; content:"drupal"; http_client_body; pcre:"/(%23|#)(access_callback|pre_render|post_render|lazy_builder)/Pi"; reference:cve,2018-7600; reference:url,research.checkpoint.com/uncovering-drupalgeddon-2; classtype:attempted-admin; sid:2025494; rev:2; metadata:affected_product Drupal_Server, attack_target Web_Server, created_at 2018_04_13, deployment Datacenter, former_category WEB_SPECIFIC_APPS, signature_severity Major, updated_at 2020_08_25;)
show less
Hacking
Web App Attack
๐น๐ผ
114.41.50.105
16 Oct 2021
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER 401TRG Generic Webshell Reques ...
show more
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER 401TRG Generic Webshell Request - POST with wget in body"; flow:established,to_server; content:"wget"; nocase; http_client_body; content:"http"; nocase; http_client_body; within:11; threshold:type limit, track by_src, seconds 3600, count 1; classtype:web-application-attack; sid:2024930; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2017_10_26, deployment Datacenter, former_category WEB_SERVER, malware_family webshell, performance_impact Moderate, signature_severity Major, updated_at 2020_08_13;)
show less
Hacking
Web App Attack
๐บ๐ธ
206.189.190.150
16 Oct 2021
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER PHP tags in HTTP POST"; flow:estab ...
show more
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER PHP tags in HTTP POST"; flow:established,to_server; content:"POST"; nocase; http_method; content:"<?php"; nocase; http_client_body; fast_pattern; reference:url,isc.sans.edu/diary.html?storyid=9478; classtype:web-application-attack; sid:2011768; rev:7; metadata:created_at 2010_09_28, updated_at 2020_09_18;)
show less
Hacking
Web App Attack
๐ต๐ฑ
83.218.127.62
16 Oct 2021
alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER WGET Command Specifying Output in HTTP H ...
show more
alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER WGET Command Specifying Output in HTTP Headers"; flow:established,to_server; content:"wget "; fast_pattern; http_header; pcre:"/(?!^User-Agent\x3a)\bwget\s[^\r\n]+(?:\x3b|&&)/Hm"; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2019309; rev:3; metadata:created_at 2014_09_29, updated_at 2020_09_25;)
show less
Hacking
Web App Attack
๐ซ๐ท
51.91.7.5
16 Oct 2021
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET CURRENT_EVENTS Possible Magento Directory ...
show more
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET CURRENT_EVENTS Possible Magento Directory Traversal Attempt"; flow:established,to_server; content:"GET"; http_method; content:"/magmi-importer/web/"; fast_pattern; http_uri; content:"download_file.php?file="; http_uri; distance:0; content:"|2e 2e 2f|"; http_raw_uri; content:!"Referer|3a|"; http_header; reference:url,threatpost.com/zero-day-in-magento-plugin-magmi-under-attack/115026/; classtype:trojan-activity; sid:2021951; rev:2; metadata:created_at 2015_10_15, former_category CURRENT_EVENTS, updated_at 2020_06_04;)
show less
Hacking
Web App Attack
๐บ๐ธ
209.141.43.27
16 Oct 2021
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-Link Devices Home Network Administration Prot ...
show more
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-Link Devices Home Network Administration Protocol Command Execution"; flow:established,to_server; content:"POST"; http_method; content:"SOAPAction|3a|"; http_header; content:"http|3a|//purenetworks.com/HNAP1/"; fast_pattern; http_header; pcre:"/^SOAPAction\x3a\s+?[^\r\n]*?http\x3a\/\/purenetworks\.com\/HNAP1\/([^\x2f]+?[\x2f])?[^\x2f]/Hmi"; reference:url,devttys0.com/2015/04/hacking-the-d-link-dir-890l/; reference:cve,2016-6563; classtype:attempted-admin; sid:2020899; rev:4; metadata:created_at 2015_04_13, updated_at 2020_08_03;)
show less
Hacking
Web App Attack
๐บ๐ธ
205.185.119.4
16 Oct 2021
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Suspicious Chmod Usage in URI ...
show more
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Suspicious Chmod Usage in URI (Inbound)"; flow:to_server,established; content:"chmod"; fast_pattern; nocase; http_uri; pcre:"/^(?:\+|\x2520|\x24IFS|\x252B|\s)+(?:x|[0-9]{3,4})/URi"; content:!"&launchmode="; http_uri; content:!"/chmod/"; http_uri; content:!"searchmod"; http_uri; reference:url,doc.emergingthreats.net/2009363; classtype:attempted-admin; sid:2009363; rev:9; metadata:affected_product Linux, attack_target Client_Endpoint, created_at 2010_07_30, deployment Perimeter, former_category HUNTING, signature_severity Minor, updated_at 2020_10_27;)
show less
Hacking
Web App Attack
๐ฎ๐ณ
111.92.80.80
05 Oct 2021
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-Link Devices Home Network Administration Prot ...
show more
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-Link Devices Home Network Administration Protocol Command Execution"; flow:established,to_server; content:"POST"; http_method; content:"SOAPAction|3a|"; http_header; content:"http|3a|//purenetworks.com/HNAP1/"; fast_pattern; http_header; pcre:"/^SOAPAction\x3a\s+?[^\r\n]*?http\x3a\/\/purenetworks\.com\/HNAP1\/([^\x2f]+?[\x2f])?[^\x2f]/Hmi"; reference:url,devttys0.com/2015/04/hacking-the-d-link-dir-890l/; reference:cve,2016-6563; classtype:attempted-admin; sid:2020899; rev:4; metadata:created_at 2015_04_13, updated_at 2020_08_03;)
show less
Hacking
๐บ๐ธ
209.141.56.100
05 Oct 2021
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET SCAN ZmEu Scanner User-Agent Inbound"; flow:e ...
show more
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET SCAN ZmEu Scanner User-Agent Inbound"; flow:established,to_server; content:"ZmEu"; http_user_agent; depth:4; classtype:trojan-activity; sid:2012936; rev:3; metadata:created_at 2011_06_06, updated_at 2020_04_22;)
show less
Hacking
Web App Attack
๐ฎ๐ณ
61.3.150.233
05 Oct 2021
alert http $EXTERNAL_NET any -> any any (msg:"ET SCAN JAWS Webserver Unauthenticated Shell Command E ...
show more
alert http $EXTERNAL_NET any -> any any (msg:"ET SCAN JAWS Webserver Unauthenticated Shell Command Execution"; flow:established,to_server; content:"GET"; http_method; content:"/shell?cd+/tmp|3b|rm+-rf+*|3b|wget+"; http_raw_uri; depth:29; fast_pattern; reference:md5,fea9e4132fc9d30bda5eb6b1d9d0b9b9; classtype:web-application-attack; sid:2030093; rev:1; metadata:affected_product Linux, attack_target Web_Server, created_at 2020_05_04, deployment Perimeter, signature_severity Minor, updated_at 2020_05_04;)
show less
Hacking
Web App Attack
๐บ๐ธ
104.33.228.127
05 Oct 2021
alert http $EXTERNAL_NET any -> any any (msg:"ET SCAN JAWS Webserver Unauthenticated Shell Command E ...
show more
alert http $EXTERNAL_NET any -> any any (msg:"ET SCAN JAWS Webserver Unauthenticated Shell Command Execution"; flow:established,to_server; content:"GET"; http_method; content:"/shell?cd+/tmp|3b|rm+-rf+*|3b|wget+"; http_raw_uri; depth:29; fast_pattern; reference:md5,fea9e4132fc9d30bda5eb6b1d9d0b9b9; classtype:web-application-attack; sid:2030093; rev:1; metadata:affected_product Linux, attack_target Web_Server, created_at 2020_05_04, deployment Perimeter, signature_severity Minor, updated_at 2020_05_04;)
show less
Hacking
Web App Attack
๐ฑ๐บ
107.189.30.40
21 Sep 2021
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET SCAN ZmEu Scanner User-Agent Inbound"; flow:e ...
show more
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET SCAN ZmEu Scanner User-Agent Inbound"; flow:established,to_server; content:"ZmEu"; http_user_agent; depth:4; classtype:trojan-activity; sid:2012936; rev:3; metadata:created_at 2011_06_06, updated_at 2020_04_22;)
show less
Hacking
Brute-Force
๐ต๐ฑ
5.185.64.167
02 Sep 2021
ET WEB_SERVER 401TRG Generic Webshell Request - POST with wget in body
alert http $EXTERNAL_NET any ...
show more
ET WEB_SERVER 401TRG Generic Webshell Request - POST with wget in body
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER 401TRG Generic Webshell Request - POST with wget in body"; flow:established,to_server; content:"wget"; nocase; http_client_body; content:"http"; nocase; http_client_body; within:11; threshold:type limit, track by_src, seconds 3600, count 1; classtype:web-application-attack; sid:2024930; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2017_10_26, deployment Datacenter, former_category WEB_SERVER, malware_family webshell, performance_impact Moderate, signature_severity Major, updated_at 2020_08_13;)
ET EXPLOIT HackingTrio UA (Hello, World)
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT HackingTrio UA (Hello, World)"; flow:established,to_server; content:"POST"; http_method; content:"Hello, World"; http_user_agent; fast_pattern; isdataat:!1,relative; reference:cve,2018-10561; reference:cve,2018-10562; reference:url,github.com/f3
show less
Hacking
Web App Attack
๐ง๐ท
45.232.101.47
02 Sep 2021
Destination IP: 199.102.55.94
ET SCAN Mirai Variant User-Agent (Inbound)
alert http $EXTERNAL_NET ...
show more
Destination IP: 199.102.55.94
ET SCAN Mirai Variant User-Agent (Inbound)
alert http $EXTERNAL_NET any -> any any (msg:"ET SCAN Mirai Variant User-Agent (Inbound)"; flow:established,to_server; content:"User-Agent|3a 20|Hello, World"; http_header; nocase; fast_pattern; pcre:"/^Hello, World(?:(?:\/|\s)[0-9]\.0)?$/Vi"; classtype:attempted-admin; sid:2029022; rev:2; metadata:affected_product Linux, attack_target IoT, created_at 2019_11_21, deployment Perimeter, former_category SCAN, signature_severity Minor, updated_at 2020_10_29;)
ET WEB_SERVER Suspicious Chmod Usage in URI (Inbound)
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Suspicious Chmod Usage in URI (Inbound)"; flow:to_server,established; content:"chmod"; fast_pattern; nocase; http_uri; pcre:"/^(?:\+|\x2520|\x24IFS|\x252B|\s)+(?:x|[0-9]{3,4})/URi"; content:!"&launchmode="; http_uri; content:!"/chmod/"; http_uri; content:!"searchmod"; http_uri; reference:url,doc.emergingthreats.net/2009363; classtype:attempted-admin; sid:200936
show less
Port Scan
Hacking
Web App Attack
๐ฎ๐ณ
117.204.152.236
02 Sep 2021
Destination IP address: 199.102.55.94
ET SCAN Mirai Variant User-Agent (Inbound)
alert http $EXTER ...
show more
Destination IP address: 199.102.55.94
ET SCAN Mirai Variant User-Agent (Inbound)
alert http $EXTERNAL_NET any -> any any (msg:"ET SCAN Mirai Variant User-Agent (Inbound)"; flow:established,to_server; content:"User-Agent|3a 20|Hello, World"; http_header; nocase; fast_pattern; pcre:"/^Hello, World(?:(?:\/|\s)[0-9]\.0)?$/Vi"; classtype:attempted-admin; sid:2029022; rev:2; metadata:affected_product Linux, attack_target IoT, created_at 2019_11_21, deployment Perimeter, former_category SCAN, signature_severity Minor, updated_at 2020_10_29;)
ET EXPLOIT MVPower DVR Shell UCE
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT MVPower DVR Shell UCE"; flow:to_server,established; content:"/shell?"; http_uri; depth:7; fast_pattern; http_header_names; content:!"Referer"; reference:url,researchcenter.paloaltonetworks.com/2018/07/unit42-finds-new-mirai-gafgyt-iotlinux-botnet-campaigns/; classtype:attempted-admin; sid:2025883; rev:2; metadata:affected_product Linux, attack_target IoT, created_at 2018_07_23,
show less
Port Scan
Hacking
Web App Attack