Received: from recordingdedicate.co ([195.133.38.41]:43815) by <X> (envelope-from <info@recordingded ...
show moreReceived: from recordingdedicate.co ([195.133.38.41]:43815) by <X> (envelope-from <[email protected]>)
show less
UCE to honeypot email: Received: from magttpame.xyz ([51.158.24.160]:55781 helo=hi-pointfirearms.co ...
show moreUCE to honeypot email: Received: from magttpame.xyz ([51.158.24.160]:55781 helo=hi-pointfirearms.com)
show less
2.56.10.18 provides bullet-proof spam-sending services over extended period of time; no abuse-respon ...
show more2.56.10.18 provides bullet-proof spam-sending services over extended period of time; no abuse-responses from ipconnect.services.
show less
Part of a network of (mainly Digital Ocean operated) IPs used in scanning:
Dec 16, 2021 @ 11:31:5 ...
show morePart of a network of (mainly Digital Ocean operated) IPs used in scanning:
Dec 16, 2021 @ 11:31:59.709 /manager/html, Remote addr: 128.199.129.137
Dec 16, 2021 @ 11:31:56.856 /manager/html, Remote addr: 128.199.129.137
Dec 16, 2021 @ 11:31:56.213 /manager/html, Remote addr: 128.199.129.137
Dec 16, 2021 @ 11:31:46.656 /manager/html, Remote addr: 128.199.129.137
Dec 16, 2021 @ 11:28:47.576 /nagios/side.php, Remote addr: 128.199.129.137
Dec 16, 2021 @ 11:28:11.706 /api/get_device_details, Remote addr: 128.199.129.137
show less
Part of a larger security sweep using multiple IPs; part of log:
Dec 16, 2021 @ 11:31:54.599 /man ...
show morePart of a larger security sweep using multiple IPs; part of log:
Dec 16, 2021 @ 11:31:54.599 /manager/html, Remote addr: 165.22.246.215
Dec 16, 2021 @ 11:31:53.078 /manager/html, Remote addr: 165.22.246.215
Dec 16, 2021 @ 11:31:44.336 /manager/html, Remote addr: 165.22.246.215
Dec 16, 2021 @ 11:28:14.762 /apt/v1/context, Remote addr: 165.22.246.215
Dec 16, 2021 @ 11:28:11.676 /api/get_device_details, Remote addr: 165.22.246.215
show less
Security swipe against known common (TomCat, SolarWindows) and APT specific endpoints and part of a ...
show moreSecurity swipe against known common (TomCat, SolarWindows) and APT specific endpoints and part of a larger (10+) IPs involved in the scan.
Dec 16, 2021 @ 11:32:55.514 uri /system/console, Remote addr: 134.209.101.47
Dec 16, 2021 @ 11:31:51.549 uri /manager/html, Remote addr: 134.209.101.47
Dec 16, 2021 @ 11:31:48.751 uri /manager/html, Remote addr: 134.209.101.47
Dec 16, 2021 @ 11:31:28.032 uri /mgmt/shared/authn/login, Remote addr: 134.209.101.47
Dec 16, 2021 @ 11:31:14.978 uri /cgi-bin/cgiServer.exx, Remote addr: 134.209.101.47
Dec 16, 2021 @ 11:29:42.679 uri /admin/, Remote addr: 134.209.101.47
Dec 16, 2021 @ 11:29:02.225 uri /tools.cgi, Remote addr: 134.209.101.47
Dec 16, 2021 @ 11:28:21.006 uri /api/whoami, Remote addr: 134.209.101.47
Dec 16, 2021 @ 11:28:20.995 uri /api/whoami, Remote addr: 134.209.101.47
show less
Trying log4j related web-attacks:
Dec 13, 2021 @ 11:26:58.817 /classpath.jsp
Dec 13, 2021 @ 11:2 ...
show moreTrying log4j related web-attacks:
Dec 13, 2021 @ 11:26:58.817 /classpath.jsp
Dec 13, 2021 @ 11:26:58.801 /servlet/WebEEServlet
Dec 13, 2021 @ 11:26:58.782 /manage.jsp
Dec 13, 2021 @ 11:26:58.772 /web-console/Invoker
Dec 13, 2021 @ 11:26:58.771 /
Dec 13, 2021 @ 11:26:58.735 /invoker/JMXInvokerServlet
Dec 13, 2021 @ 11:26:58.721 /servlet/WebEEServlet
Dec 13, 2021 @ 11:26:58.685 /
Dec 13, 2021 @ 11:26:58.652 /invoker/JMXInvokerServlet
show less
Scanning for PHP backdoors on November 4th and November 11th:
<hostname>/gate.php with user- ...
show moreScanning for PHP backdoors on November 4th and November 11th:
<hostname>/gate.php with user-agent-string: Dalvik/2.1.0 (Linux; U; Android 6.0.1; SM-J700F Build/MMB29K)
<hostname>/restapi.php with user-agent-string: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
show less
Scanning for Solarwinds, TomCat and VOIP vulnerabilities (among others); below a few log-lines:
N ...
show moreScanning for Solarwinds, TomCat and VOIP vulnerabilities (among others); below a few log-lines:
Nov 6, 2021 @ 17:19:36.477 JWT does not conform to regex on uri /cgi-bin/operator/fileread, IP [ERROR] no forward header. Remote addr: 165.22.103.83
Nov 6, 2021 @ 17:19:36.447 JWT does not conform to regex on uri /cgi-bin/operator/fileread, IP [ERROR] no forward header. Remote addr: 165.22.103.83
Nov 6, 2021 @ 17:19:33.080 JWT does not conform to regex on uri /cgi-bin/cgiServer.exx, IP [ERROR] no forward header. Remote addr: 165.22.103.83
Nov 6, 2021 @ 17:19:33.080 JWT does not conform to regex on uri /cgi-bin/cgiServer.exx, IP [ERROR] no forward header. Remote addr: 165.22.103.83
Nov 6, 2021 @ 17:12:28.279 JWT does not conform to regex on uri /WEB_VMS/LEVEL15/, IP [ERROR] no forward header. Remote addr: 165.22.103.83
Nov 6, 2021 @ 17:12:28.228 JWT does not conform to regex on uri /WEB_VMS/LEVEL15/, IP [ERROR] no forward header. Remote addr: 165.22.103.83
show less
@timestamp:Oct 15, 2021 @ 08:03:xx.xxx "message": "JWT does not conform to regex on uri /admin/, Rem ...
show more@timestamp:Oct 15, 2021 @ 08:03:xx.xxx "message": "JWT does not conform to regex on uri /admin/, Remote addr: 153.92.214.217"
@timestamp:Oct 15, 2021 @ 08:00:xx.xxx "message": "JWT does not conform to regex on uri /admin/, Remote addr: 153.92.214.217"
@timestamp:Oct 15, 2021 @ 06:56:xx.xxx "message": "JWT does not conform to regex on uri /admin/, Remote addr: 153.92.214.217"
@timestamp:Oct 15, 2021 @ 06:54:xx.xxx "message": "JWT does not conform to regex on uri /admin/, Remote addr: 153.92.214.217"
show less
Received: from p-impout004.msg.pkvw.co.charter.net (47.43.26.135) by
AM6EUR05FT037.mail.protection ...
show moreReceived: from p-impout004.msg.pkvw.co.charter.net (47.43.26.135) by
AM6EUR05FT037.mail.protection.outlook.com (10.233.241.184) with Microsoft
SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
X via Frontend Transport; Thu, 7 Oct 2021 09:51:31 +0000
show less
More spearphishing from:
Received: from app-11.app.altice.ord.rs.oxcs.net (162.209.33.249) by X id ...
show moreMore spearphishing from:
Received: from app-11.app.altice.ord.rs.oxcs.net (162.209.33.249) by X id X for X; Tue, 5 Oct 2021 06:33:51 +000
show less
Another spearphishing mailheader:
Received: from app-11.app.altice.ord.rs.oxcs.net (162.209.33.249) ...
show moreAnother spearphishing mailheader:
Received: from app-11.app.altice.ord.rs.oxcs.net (162.209.33.249) by X id X for X; Tue, 5 Oct 2021 06:40:56 +0000
show less
Another spearphishing campaign example mail header:
Received: from app-11.app.altice.ord.rs.oxcs.ne ...
show moreAnother spearphishing campaign example mail header:
Received: from app-11.app.altice.ord.rs.oxcs.net (162.209.33.249) by X id X for X; Tue, 5 Oct 2021 06:42:48 +0000
show less
Another spearphishing mailheader line:
Received: from app-11.app.altice.ord.rs.oxcs.net (162.209.33 ...
show moreAnother spearphishing mailheader line:
Received: from app-11.app.altice.ord.rs.oxcs.net (162.209.33.249) by X id X for X; Tue, 5 Oct 2021 06:35:34 +0000
show less
Source of Spearphishing campaign mails; below 1 example of a related mail header
Received: from a ...
show moreSource of Spearphishing campaign mails; below 1 example of a related mail header
Received: from app-11.app.altice.ord.rs.oxcs.net (162.209.33.249) by <x>
show less
Using a few different vulnerability-scanners to scan for common (Wordpress, TomCat, SQLi, XSS) vulne ...
show moreUsing a few different vulnerability-scanners to scan for common (Wordpress, TomCat, SQLi, XSS) vulnerabilities ; below one logline example:
{"accept-language": "en", "bytes_sent": 1474, "content-type": "-", "duration": 0.004, "http_user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36", "method": "GET", "path": "/wp-content/plugins/hero-maps-pro/views/dashboard/index.php", "request_length": 395, "request_proto": "HTTP/1.1", "request_query": "v=%22%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E", "request_time": 0.004, "status": 404, "time": "2021-09-15T11:47:56+00:00", "vhost": "<censored>", "x-forward-for": "103.88.234.221"}
show less
Observed ~28K scans for SQLi and other known web-attacks; upto 10 requests per second; a (very) smal ...
show moreObserved ~28K scans for SQLi and other known web-attacks; upto 10 requests per second; a (very) small example:
Sep 12, 2021 @ 19:18:34.350 user_agent: lYrVquPD' OR 786=(SELECT 786 FROM PG_SLEEP(15))--
Sep 12, 2021 @ 19:18:35.790 user_agent: fS3jMyzK') OR 373=(SELECT 373 FROM PG_SLEEP(15))--
Sep 12, 2021 @ 19:18:37.053 user_agent: GEKkGmeC') OR 19=(SELECT 19 FROM PG_SLEEP(15))--
Sep 12, 2021 @ 19:18:37.600 user_agent: bOlNLDAA')) OR 399=(SELECT 399 FROM PG_SLEEP(15))--
Sep 12, 2021 @ 19:18:38.873 user_agent: TOEOLK9K')) OR 426=(SELECT 426 FROM PG_SLEEP(15))--
Sep 12, 2021 @ 19:18:39.229 user_agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4298.0 Safari/537.36'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
Sep 12, 2021 @ 19:18:40.305 user_agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4298.0 Safari/537.36'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
show less
SQL InjectionWeb App Attack
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.