DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back to IP report

Log Explorer

Fact drill-down for 147.78.47.90
Risk 35 MED Scope All time All-time facts 99 In-scope 99 Filtered 99 Seen 2024-12-052025-01-10
Active (none) Clear
Faceted filters (facts-based) exact core + snapshot + optional start/end
Annotation facets
HTTP facets
Snapshot facets
Custom time window (optional override)
Provide start/end to scope time explicitly (overrides days). Leave blank for all-time.
Tip: keep windows tight when you need speed, but the default is fact-complete.
Top annotators (facts, in-scope)
Click a pill to apply it as a filter.

Annotated access events

Showing page 1 / 2 — total 99 rows
#1 2025-01-10 11:30:21 event 3705794 POST 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/uploads.action
referer
-
UA
Mozilla/5.0
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#2 2025-01-10 11:30:21 event 3705794 POST 301 bytes 169
ann ua 8 label ua
Request Truncated Mozilla User-Agent token
referer
-
UA
Mozilla/5.0
Annotation facts
label
ua
rule
ua:truncated_mozilla
conf
70.00
details
Common placeholder UA used by simplistic clients.
More (full fields + snapshot) expand
url
/uploads.action
referer
-
UA
Mozilla/5.0
summary
Truncated Mozilla User-Agent token
details
Common placeholder UA used by simplistic clients.
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#3 2025-01-10 11:30:19 event 3705792 POST 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/uploads.action
referer
-
UA
Mozilla/5.0
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#4 2025-01-10 11:30:19 event 3705791 POST 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/uploads.action
referer
-
UA
Mozilla/5.0
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#5 2025-01-10 11:30:19 event 3705790 POST 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/uploads.action
referer
-
UA
Mozilla/5.0
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#6 2025-01-10 11:30:19 event 3705792 POST 301 bytes 169
ann ua 8 label ua
Request Truncated Mozilla User-Agent token
referer
-
UA
Mozilla/5.0
Annotation facts
label
ua
rule
ua:truncated_mozilla
conf
70.00
details
Common placeholder UA used by simplistic clients.
More (full fields + snapshot) expand
url
/uploads.action
referer
-
UA
Mozilla/5.0
summary
Truncated Mozilla User-Agent token
details
Common placeholder UA used by simplistic clients.
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#7 2025-01-10 11:30:19 event 3705791 POST 301 bytes 169
ann ua 8 label ua
Request Truncated Mozilla User-Agent token
referer
-
UA
Mozilla/5.0
Annotation facts
label
ua
rule
ua:truncated_mozilla
conf
70.00
details
Common placeholder UA used by simplistic clients.
More (full fields + snapshot) expand
url
/uploads.action
referer
-
UA
Mozilla/5.0
summary
Truncated Mozilla User-Agent token
details
Common placeholder UA used by simplistic clients.
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#8 2025-01-10 11:30:19 event 3705790 POST 301 bytes 169
ann ua 8 label ua
Request Truncated Mozilla User-Agent token
referer
-
UA
Mozilla/5.0
Annotation facts
label
ua
rule
ua:truncated_mozilla
conf
70.00
details
Common placeholder UA used by simplistic clients.
More (full fields + snapshot) expand
url
/uploads.action
referer
-
UA
Mozilla/5.0
summary
Truncated Mozilla User-Agent token
details
Common placeholder UA used by simplistic clients.
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#9 2025-01-09 14:01:56 event 3280122 PUT 404 bytes 8110
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.127 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/ULDASxQp.jsp
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.127 Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#10 2025-01-08 22:03:10 event 3051114 PUT 404 bytes 8112
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.127 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/fygFfejo.jsp
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.127 Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#11 2025-01-08 22:03:09 event 3051112 PUT 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.127 Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/fygFfejo.jsp
referer
-
UA
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.127 Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#12 2024-12-28 11:08:56 event 2623923 GET 404 bytes 8110
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#13 2024-12-28 11:08:56 event 2623923 GET 404 bytes 8110
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#14 2024-12-28 11:08:56 event 2623923 GET 404 bytes 8110
ann cmdi 28 label cmdi
Request Command/file-injection indicator: cmdi:op_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#15 2024-12-28 11:08:56 event 2623923 GET 404 bytes 8110
ann cmdi 30 label cmdi
Request Command/file-injection indicator: cmdi:param_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:param_plus_cmd
conf
90.00
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:param_plus_cmd
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#16 2024-12-28 11:08:54 event 2623922 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#17 2024-12-28 11:08:54 event 2623922 GET 301 bytes 169
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#18 2024-12-28 11:08:54 event 2623922 GET 301 bytes 169
ann cmdi 28 label cmdi
Request Command/file-injection indicator: cmdi:op_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#19 2024-12-28 11:08:54 event 2623922 GET 301 bytes 169
ann cmdi 30 label cmdi
Request Command/file-injection indicator: cmdi:param_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:param_plus_cmd
conf
90.00
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:param_plus_cmd
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#20 2024-12-28 11:08:53 event 2623921 GET 404 bytes 8109
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#21 2024-12-28 11:08:53 event 2623921 GET 404 bytes 8109
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#22 2024-12-28 11:08:51 event 2623920 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#23 2024-12-28 11:08:51 event 2623920 GET 301 bytes 169
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#24 2024-12-28 11:08:50 event 2623919 GET 404 bytes 8110
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#25 2024-12-28 11:08:50 event 2623919 GET 404 bytes 8110
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#26 2024-12-28 11:08:50 event 2623919 GET 404 bytes 8110
ann cmdi 28 label cmdi
Request Command/file-injection indicator: cmdi:op_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname -a;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname -a;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#27 2024-12-28 11:08:50 event 2623919 GET 404 bytes 8110
ann cmdi 30 label cmdi
Request Command/file-injection indicator: cmdi:param_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:param_plus_cmd
conf
90.00
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname -a;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:param_plus_cmd
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname -a;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#28 2024-12-28 11:08:48 event 2623918 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#29 2024-12-28 11:08:48 event 2623918 GET 301 bytes 169
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#30 2024-12-28 11:08:48 event 2623918 GET 301 bytes 169
ann cmdi 28 label cmdi
Request Command/file-injection indicator: cmdi:op_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname -a;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname -a;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#31 2024-12-28 11:08:48 event 2623918 GET 301 bytes 169
ann cmdi 30 label cmdi
Request Command/file-injection indicator: cmdi:param_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:param_plus_cmd
conf
90.00
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname -a;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname%20-a;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:param_plus_cmd
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';uname -a;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#32 2024-12-28 11:08:47 event 2623917 GET 404 bytes 8109
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#33 2024-12-28 11:08:47 event 2623917 GET 404 bytes 8109
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#34 2024-12-28 11:08:47 event 2623917 GET 404 bytes 8109
ann cmdi 28 label cmdi
Request Command/file-injection indicator: cmdi:op_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#35 2024-12-28 11:08:47 event 2623917 GET 404 bytes 8109
ann cmdi 30 label cmdi
Request Command/file-injection indicator: cmdi:param_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:param_plus_cmd
conf
90.00
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:param_plus_cmd
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#36 2024-12-28 11:08:45 event 2623916 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#37 2024-12-28 11:08:45 event 2623916 GET 301 bytes 169
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#38 2024-12-28 11:08:45 event 2623916 GET 301 bytes 169
ann cmdi 28 label cmdi
Request Command/file-injection indicator: cmdi:op_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#39 2024-12-28 11:08:45 event 2623916 GET 301 bytes 169
ann cmdi 30 label cmdi
Request Command/file-injection indicator: cmdi:param_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:param_plus_cmd
conf
90.00
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:param_plus_cmd
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';id;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#40 2024-12-26 22:17:22 event 2499392 GET 404 bytes 8111
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#41 2024-12-26 22:17:22 event 2499392 GET 404 bytes 8111
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#42 2024-12-26 22:17:22 event 2499392 GET 404 bytes 8111
ann cmdi 28 label cmdi
Request Command/file-injection indicator: cmdi:op_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#43 2024-12-26 22:17:22 event 2499392 GET 404 bytes 8111
ann cmdi 30 label cmdi
Request Command/file-injection indicator: cmdi:param_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:param_plus_cmd
conf
90.00
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:param_plus_cmd
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#44 2024-12-26 22:17:19 event 2499391 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#45 2024-12-26 22:17:19 event 2499390 GET 404 bytes 8109
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#46 2024-12-26 22:17:19 event 2499391 GET 301 bytes 169
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#47 2024-12-26 22:17:19 event 2499390 GET 404 bytes 8109
ann sfp 36 label sensitive_file
Request Command-style parameter observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
sensitive_file
rule
sfp:param:cmd
conf
86.00
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;''
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command-style parameter observed
details
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;''
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#48 2024-12-26 22:17:19 event 2499391 GET 301 bytes 169
ann cmdi 28 label cmdi
Request Command/file-injection indicator: cmdi:op_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#49 2024-12-26 22:17:19 event 2499391 GET 301 bytes 169
ann cmdi 30 label cmdi
Request Command/file-injection indicator: cmdi:param_plus_cmd
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
cmdi
rule
cmdi:param_plus_cmd
conf
90.00
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat%20/proc/cpuinfo;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
Command/file-injection indicator: cmdi:param_plus_cmd
details
Suspicious command parameter combined with a recognized command token. Snippet='GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';cat /proc/cpuinfo;' -'
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A
#50 2024-12-26 22:17:16 event 2499389 GET 301 bytes 169
ann base label observed
Request event observed
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
Annotation facts
label
observed
rule
base_observed
conf
details
More (full fields + snapshot) expand
url
/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=';hostname;'
referer
-
UA
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
summary
event observed
details
subnet
147.78.47.0/24
asn
geo
The Netherlands, North Holland, Amsterdam
org
Flyservers S.A