[Silicon Defense logo]

SnortSnarf signature page

SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt

SnortSnarf v021111.1

Signature section (694)Top 20 source IPsTop 20 dest IPs

23 alerts with this signature using input module SnortFileInput, with sources:

Earliest such alert at 19:02:32.480786 on 01/16/2020
Latest such alert at 14:19:15.233789 on 05/08/2020

SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt 21 sources 1 destinations
Priority: 1Classification: Attempted Administrator Privilege Gain
[url:www.pentestpartners.com/blog/pwning-cctv-cameras/] [sid:42857]

Sources triggering this attack signature

Source# Alerts (sig)# Alerts (total)# Dsts (sig)# Dsts (total)
123.205.119.1312211
74.80.28.2172211
190.112.244.1701111
70.106.217.871111
197.89.76.281111
61.2.21.2461111
103.92.120.2041111
37.152.207.211111
78.181.85.1971111
191.240.103.1371111
39.63.27.1841111
83.66.123.871111
80.2.140.1891111
78.100.194.801111
186.240.170.601111
178.236.220.2361111
180.151.91.1611111
60.237.99.1331111
190.117.127.21111
188.52.71.721111
60.31.158.591111

Destinations receiving this attack signature

Destinations# Alerts (sig)# Alerts (total)# Srcs (sig)# Srcs (total)
192.168.0.382369021380

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Nov 24 20:01:02 2020