[Silicon Defense logo]

SnortSnarf signature page

SERVER-WEBAPP PHPUnit PHP remote code execution attempt

SnortSnarf v021111.1

Signature section (773)Top 20 source IPsTop 20 dest IPs

120 alerts with this signature using input module SnortFileInput, with sources:

Earliest such alert at 06:03:59.762814 on 04/11/2020
Latest such alert at 05:15:16.004049 on 02/19/2021

SERVER-WEBAPP PHPUnit PHP remote code execution attempt 16 sources 1 destinations
Priority: 1Classification: Web Application Attack
[sid:45749] [CVE:2017-9841]

Sources triggering this attack signature

Source# Alerts (sig)# Alerts (total)# Dsts (sig)# Dsts (total)
104.131.29.93282811
52.247.113.177272711
118.27.32.69252511
161.35.143.115242411
207.154.208.764411
45.88.12.1682211
13.78.126.1051111
119.29.148.1681311
192.228.100.981111
94.191.75.1451111
47.52.255.2021111
94.191.110.2001311
111.231.203.1291111
194.146.50.1941111
82.146.39.471111
128.199.46.1781111

Destinations receiving this attack signature

Destinations# Alerts (sig)# Alerts (total)# Srcs (sig)# Srcs (total)
192.168.0.3812076916431

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Sun Feb 28 18:01:02 2021