SCARD

Suspicious activity by IP address 152.32.226.205

Below is a list of the last 500 suspicious interactions with this IP.

Last observed Sat, 30 May 2026 14:32:23 (Australia/Brisbane)

Back to main list

Summary of suspicious activity by IP address 152.32.226.205

Description Count
ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 94
ET WEB_SERVER PHP.//Input in HTTP POST 28
ET WEB_SERVER PHP tags in HTTP POST 28
ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) 28
ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) 28
ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body 28
ET WEB_SERVER auto_prepend_file PHP config option in uri 28
ET WEB_SERVER allow_url_include PHP config option in uri 28
ET WEB_SERVER Generic PHP Remote File Include 28
SERVER-WEBAPP PHP PHP-CGI command execution attempt 26

Detailed activity by IP address 152.32.226.205

Timestamp Description Protocol Destination Port
2026-05-30 14:32:23 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-30 10:20:40 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-30 10:20:40 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-30 10:20:40 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-30 10:20:40 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-30 10:20:40 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-30 10:20:40 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-30 10:20:40 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-30 10:20:40 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-30 10:20:40 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-30 10:20:38 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-30 10:20:38 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-30 10:20:38 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-30 10:20:38 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-30 10:20:38 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-30 10:20:38 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-30 10:20:38 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-30 10:20:38 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-30 10:20:38 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-30 09:19:37 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-30 09:19:37 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-30 06:01:52 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-30 06:01:51 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-30 01:29:04 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-30 01:29:04 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-30 01:29:04 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-30 01:29:04 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-30 01:29:04 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-30 01:29:04 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-30 01:29:04 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-30 01:29:04 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-30 01:29:04 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-30 01:29:03 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-30 01:29:03 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-30 01:29:03 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-30 01:29:03 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-30 01:29:03 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-30 01:29:03 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-30 01:29:03 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-30 01:29:03 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-30 01:29:03 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-30 00:28:05 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-30 00:28:05 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-30 00:28:05 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-30 00:28:05 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-30 00:28:05 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-30 00:28:05 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-30 00:28:05 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-30 00:28:05 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-30 00:28:05 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-30 00:28:05 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-30 00:28:05 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-30 00:28:05 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-30 00:28:05 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-30 00:28:05 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-30 00:28:05 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-30 00:28:05 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-30 00:28:05 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-30 00:28:05 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-30 00:28:05 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-30 00:28:05 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-28 02:54:37 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-28 02:54:37 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-27 18:55:10 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-27 18:55:10 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-27 16:49:11 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-27 16:49:11 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-27 03:39:16 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-27 03:39:15 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-26 20:22:46 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-26 20:22:44 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-26 11:09:47 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-26 11:09:47 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-26 11:09:47 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-26 11:09:47 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-26 11:09:47 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-26 11:09:47 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-26 11:09:47 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-26 11:09:47 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-26 11:09:47 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-26 11:09:45 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-26 11:09:45 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-26 11:09:45 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-26 11:09:45 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-26 11:09:45 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-26 11:09:45 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-26 11:09:45 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-26 11:09:45 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-26 11:09:45 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-26 10:08:44 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-26 10:08:44 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-25 23:51:48 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-25 23:51:48 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-25 23:51:48 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-25 23:51:48 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-25 23:51:48 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-25 23:51:48 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-25 23:51:48 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-25 23:51:48 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-25 23:51:48 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-25 23:51:46 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-25 23:51:46 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-25 23:51:46 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-25 23:51:46 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-25 23:51:46 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-25 23:51:46 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-25 23:51:46 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-25 23:51:46 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-25 23:51:46 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-25 22:50:48 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-25 22:50:48 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-25 07:48:28 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-25 07:48:28 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-24 03:51:10 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-23 18:50:49 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-23 18:50:49 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-22 23:47:09 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-22 23:47:08 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-22 14:46:20 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-22 14:46:20 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-22 14:46:20 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-22 14:46:20 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-22 14:46:20 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-22 14:46:20 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-22 14:46:20 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-22 14:46:20 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-22 14:46:20 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-22 05:37:34 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-21 21:40:48 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-21 19:34:34 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-21 14:49:00 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-20 10:55:01 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-20 10:55:01 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-20 08:37:47 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-20 08:37:47 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 23:41:15 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-19 23:41:15 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-19 23:41:15 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-19 23:41:15 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-19 23:41:15 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-19 23:41:15 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-19 23:41:15 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-19 23:41:15 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-19 23:41:15 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-19 23:41:15 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 23:41:15 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-19 23:41:15 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-19 23:41:15 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 23:41:15 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-19 23:41:15 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-19 23:41:15 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-19 23:41:15 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-19 23:41:15 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-19 23:41:15 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-19 23:41:15 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-19 14:01:31 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 14:01:29 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 11:07:46 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 11:07:46 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 08:42:57 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 08:42:57 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 01:16:21 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-19 01:16:21 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-18 20:54:41 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-18 09:54:06 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-18 09:54:06 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-18 06:04:34 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-18 06:04:32 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 22:07:07 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 22:07:07 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 13:57:44 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 13:57:44 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 10:42:08 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 10:42:08 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 05:59:16 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-17 05:59:16 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-17 05:59:16 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-17 05:59:16 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-17 05:59:16 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-17 05:59:16 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-17 05:59:16 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-17 05:59:16 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-17 05:59:16 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-17 05:59:15 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-17 05:59:15 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-17 05:59:15 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-17 05:59:15 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-17 05:59:15 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-17 05:59:15 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-17 05:59:15 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-17 05:59:15 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-17 05:59:15 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-17 04:58:13 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 04:58:13 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 03:42:07 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 01:18:37 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 01:18:37 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 01:00:05 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 01:00:05 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 00:10:07 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-17 00:10:07 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-16 14:49:55 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-16 14:49:54 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-16 07:40:35 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-16 07:40:35 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-16 07:40:35 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-16 07:40:35 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-16 07:40:35 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-16 07:40:35 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-16 07:40:35 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-16 07:40:35 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-16 06:39:32 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-16 03:25:31 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-16 03:25:23 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-16 01:22:29 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-16 01:22:29 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-16 01:22:29 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-16 01:22:29 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-16 01:22:29 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-16 01:22:29 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-16 01:22:29 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-16 01:22:29 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-16 01:22:29 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-16 01:22:29 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-16 01:22:29 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-16 01:22:29 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-16 01:22:29 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-16 01:22:29 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-16 01:22:29 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-16 01:22:29 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-16 01:22:29 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-16 01:22:29 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-16 00:21:27 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-16 00:21:27 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 22:16:30 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 22:16:30 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 18:53:31 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 18:53:31 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 14:03:01 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 07:28:03 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-15 07:28:03 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-15 07:28:03 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-15 07:28:03 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-15 07:28:03 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-15 07:28:03 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-15 07:28:03 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-15 07:28:03 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-15 07:28:03 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-15 07:28:03 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-15 07:28:03 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-15 07:28:03 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-15 07:28:03 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-15 07:28:03 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-15 07:28:03 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-15 07:28:03 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-15 07:28:03 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-15 07:28:03 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-15 06:27:02 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 06:27:02 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 03:14:30 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 03:14:30 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 01:43:42 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-15 01:43:42 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-15 01:43:42 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-15 01:43:42 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-15 01:43:42 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-15 01:43:42 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-15 01:43:42 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-15 01:43:42 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-15 01:43:42 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-15 01:43:42 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-15 01:43:42 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-15 01:43:42 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-15 01:43:42 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-15 01:43:42 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-15 01:43:42 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-15 01:43:42 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-15 01:43:42 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-15 01:43:42 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-15 00:42:40 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-15 00:42:40 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-14 21:37:59 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-14 21:37:57 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-14 14:41:59 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-14 11:34:44 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-14 11:34:44 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-14 11:34:44 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-14 11:34:44 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-14 11:34:44 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-14 11:34:44 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-14 11:34:44 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-14 11:34:44 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-14 11:34:44 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-14 11:34:44 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-14 11:34:44 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-14 11:34:44 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-14 11:34:44 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-14 11:34:44 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-14 11:34:44 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-14 11:34:44 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-14 11:34:44 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-14 11:34:44 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-14 10:33:43 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-14 10:33:43 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-13 04:33:37 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-13 04:33:37 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-13 04:33:37 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-13 04:33:37 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-13 04:33:37 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-13 04:33:37 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-13 04:33:37 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-13 04:33:37 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-13 04:33:37 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-13 04:33:36 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-13 04:33:36 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-13 04:33:36 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-13 04:33:36 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-13 04:33:36 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-13 04:33:36 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-13 04:33:36 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-13 04:33:36 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-13 04:33:36 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-13 03:32:35 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-13 03:32:35 ET WEB_SERVER PHP.//Input in HTTP POST TCP 80
2026-05-13 03:32:35 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-13 03:32:35 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-13 03:32:35 ET HUNTING Suspicious PHP Code in HTTP POST (Inbound) TCP 80
2026-05-13 03:32:35 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-13 03:32:35 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-13 03:32:35 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-13 03:32:35 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-13 03:32:35 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-13 03:32:35 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-13 03:32:35 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-13 03:32:35 ET WEB_SERVER Generic PHP Remote File Include TCP 80
2026-05-13 03:32:35 SERVER-WEBAPP PHP PHP-CGI command execution attempt TCP 80
2026-05-13 03:32:35 ET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body TCP 80
2026-05-13 03:32:35 ET WEB_SERVER PHP tags in HTTP POST TCP 80
2026-05-13 03:32:35 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-13 03:32:35 ET WEB_SERVER auto_prepend_file PHP config option in uri TCP 80
2026-05-13 03:32:35 ET WEB_SPECIFIC_APPS PHP-CGI OS Command Injection (soft hyphen) (CVE-2024-4577) TCP 80
2026-05-13 03:32:35 ET WEB_SERVER allow_url_include PHP config option in uri TCP 80
2026-05-12 23:39:45 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80
2026-05-12 23:39:45 ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 TCP 80

 

Back to top