[Silicon Defense logo]

SnortSnarf signature page

SERVER-WEBAPP PHPUnit PHP remote code execution attempt

SnortSnarf v021111.1

Signature section (694)Top 20 source IPsTop 20 dest IPs

94 alerts with this signature using input module SnortFileInput, with sources:

Earliest such alert at 11:31:23.831319 on 02/16/2020
Latest such alert at 23:59:43.633965 on 10/31/2020

SERVER-WEBAPP PHPUnit PHP remote code execution attempt 13 sources 1 destinations
Priority: 1Classification: Web Application Attack
[sid:45749] [CVE:2017-9841]

Sources triggering this attack signature

Source# Alerts (sig)# Alerts (total)# Dsts (sig)# Dsts (total)
104.131.29.93282811
52.247.113.177272711
118.27.32.69252511
207.154.208.764411
45.88.12.1682211
13.78.126.1051111
119.29.148.1681311
94.191.110.2001311
111.231.203.1291111
82.146.39.471111
94.191.75.1451111
128.199.46.1781111
47.52.255.2021111

Destinations receiving this attack signature

Destinations# Alerts (sig)# Alerts (total)# Srcs (sig)# Srcs (total)
192.168.0.389469013380

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Nov 24 21:01:02 2020