MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #12

Jakarta IP flagged for exploiting known CVEs

Original: ๐Ÿ•ต๏ธ ๐—œ๐—ฃ ๐—ฐ๐—ต๐—ฒ๐—น๐—ผ๐˜‚ ๐—ฑ๐˜‚ ๐—ท๐—ผ๐˜‚๐—ฟ ๐Ÿ•ต๏ธ **Fiche : "Le Brocanteur de CVEs de Jakarta"** ๐Ÿ“ 103.63.101.24 | AS150273 ๐Ÿ‡ฎ๐Ÿ‡ฉ ๐Ÿ”ซ 5 frappes : Think

A cybersecurity observer has published a profile of IP address 103.63.101.24, hosted on Indonesian network AS150273 in Jakarta, dubbing it 'the CVE broker of Jakarta'. The address is said to have launched five attacks targeting known flaws in ThinkPHP, PHPUnit's eval-stdin, and Apache path traversal vulnerabilities CVE-2021-41773 and CVE-2021-42013, using the libredtail-http user agent and encoded traversal sequences seeking a shell.

Why now: Security communities regularly share threat intelligence about actively scanning and exploiting IP addresses to help defenders block them.

103.63.101.24AS150273JakartaApacheThinkPHP

Open on mastodon โ†’

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/449136