internetweather

CVE-2019-19781 scans detected by Bad Packets – last 24 hours

Jan 13th, 2020
1,285
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. {
  2.   "count": 6,
  3.   "next": null,
  4.   "previous": null,
  5.   "results": [
  6.     {
  7.       "source_ip_address": "5.101.0.209",
  8.       "country": "RU",
  9.       "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36",
  10.       "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
  11.       "post_data": "",
  12.       "target_port": 80,
  13.       "protocol": "tcp",
  14.       "tags": [
  15.         {
  16.           "cve": "CVE-2019-19781",
  17.           "category": "Platform",
  18.           "description": "Citrix NetScaler Gateway Exploit"
  19.         }
  20.       ],
  21.       "event_count": 248,
  22.       "first_seen": "2020-01-12T13:20:04Z",
  23.       "last_seen": "2020-01-14T03:25:04Z"
  24.     },
  25.     {
  26.       "source_ip_address": "54.38.157.11",
  27.       "country": "DE",
  28.       "user_agent": "curl/7.67.0",
  29.       "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
  30.       "post_data": "",
  31.       "target_port": 443,
  32.       "protocol": "tcp",
  33.       "tags": [
  34.         {
  35.           "cve": "CVE-2019-19781",
  36.           "category": "Platform",
  37.           "description": "Citrix NetScaler Gateway Exploit"
  38.         }
  39.       ],
  40.       "event_count": 30,
  41.       "first_seen": "2020-01-13T03:13:30Z",
  42.       "last_seen": "2020-01-14T02:00:44Z"
  43.     },
  44.     {
  45.       "source_ip_address": "5.101.0.209",
  46.       "country": "RU",
  47.       "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36",
  48.       "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
  49.       "post_data": "",
  50.       "target_port": 443,
  51.       "protocol": "tcp",
  52.       "tags": [
  53.         {
  54.           "cve": "CVE-2019-19781",
  55.           "category": "Platform",
  56.           "description": "Citrix NetScaler Gateway Exploit"
  57.         }
  58.       ],
  59.       "event_count": 622,
  60.       "first_seen": "2020-01-12T12:16:24Z",
  61.       "last_seen": "2020-01-14T02:00:19Z"
  62.     },
  63.     {
  64.       "source_ip_address": "185.234.216.20",
  65.       "country": "IE",
  66.       "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0",
  67.       "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
  68.       "post_data": "",
  69.       "target_port": 443,
  70.       "protocol": "tcp",
  71.       "tags": [
  72.         {
  73.           "cve": "CVE-2019-19781",
  74.           "category": "Platform",
  75.           "description": "Citrix NetScaler Gateway Exploit"
  76.         }
  77.       ],
  78.       "event_count": 31,
  79.       "first_seen": "2020-01-13T19:01:01Z",
  80.       "last_seen": "2020-01-14T01:27:27Z"
  81.     },
  82.     {
  83.       "source_ip_address": "193.57.40.46",
  84.       "country": "UA",
  85.       "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36",
  86.       "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
  87.       "post_data": "",
  88.       "target_port": 443,
  89.       "protocol": "tcp",
  90.       "tags": [
  91.         {
  92.           "cve": "CVE-2019-19781",
  93.           "category": "Platform",
  94.           "description": "Citrix NetScaler Gateway Exploit"
  95.         }
  96.       ],
  97.       "event_count": 91,
  98.       "first_seen": "2020-01-12T22:25:24Z",
  99.       "last_seen": "2020-01-14T00:12:09Z"
  100.     },
  101.     {
  102.       "source_ip_address": "82.102.16.220",
  103.       "country": "DE",
  104.       "user_agent": "curl/7.58.0",
  105.       "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
  106.       "post_data": "",
  107.       "target_port": 443,
  108.       "protocol": "tcp",
  109.       "tags": [
  110.         {
  111.           "cve": "CVE-2019-19781",
  112.           "category": "Platform",
  113.           "description": "Citrix NetScaler Gateway Exploit"
  114.         }
  115.       ],
  116.       "event_count": 5,
  117.       "first_seen": "2020-01-10T00:07:56Z",
  118.       "last_seen": "2020-01-13T13:16:31Z"
  119.     }
  120.   ]
  121. }
Add Comment
Please, Sign In to add comment