Detailed List of IPS rules used in the ASG

Last update: Mon Jul 31 04:13:21 2023



Group Name# of attack rules# of warning rulesgoto
 
OS         
OS / Windows  2319    2909    goto rules ...  
OS / Linux  67    171    goto rules ...  
OS / Other  1033    572    goto rules ...  
 
Server         
Server / HTTP         
Server / HTTP / Common  14    67    goto rules ...  
Server / HTTP / Apache  164    143    goto rules ...  
Server / HTTP / Microsoft IIS  8    179    goto rules ...  
Server / HTTP / Other         
Server / HTTP / Coldfusion         
Server / HTTP / Frontpage  0    3    goto rules ...  
Server / HTTP / PHP  479    596    goto rules ...  
Server / HTTP / CGI  211    279    goto rules ...  
Server / Mail         
Server / Mail / Microsoft Exchange  55    50    goto rules ...  
Server / Mail / Sendmail  1    26    goto rules ...  
Server / Mail / POP3  1    2    goto rules ...  
Server / Mail / IMAP  19    49    goto rules ...  
Server / Mail / SMTP  8    123    goto rules ...  
Server / Database         
Server / Database / Microsoft  11    78    goto rules ...  
Server / Database / Oracle         
Server / Database / MySQL  21    64    goto rules ...  
Server / Database / Common SQL  509    363    goto rules ...  
Server / Database / Common SQL         
Server / Misc         
Server / Misc / DNS  159    218    goto rules ...  
Server / Misc / FTP  36    253    goto rules ...  
Server / Misc / SSH  2    25    goto rules ...  
Server / Misc / Backup  45    75    goto rules ...  
Server / Misc / TFTP         
Server / Misc / SNMP  8    7    goto rules ...  
Server / Misc / Authentication  18    54    goto rules ...  
Server / Misc / CVS  1    17    goto rules ...  
 
Client         
Client / Office  1152    1246    goto rules ...  
Client / Browser  2202    1799    goto rules ...  
Client / Email  8    104    goto rules ...  
Client / Multimedia  3261    1475    goto rules ...  
Client / Peer to Peer         
Client / Instant Messenger  17    26    goto rules ...  
 
Protocol Anomaly         
Protocol Anomaly / Invalid Traffic  8    149    goto rules ...  
Protocol Anomaly / ICMP         
Protocol Anomaly / IGMP         
Protocol Anomaly / RPC         
Protocol Anomaly / Misc         
 
Malware  7727    15232    goto rules ...  
Malware / Trojans         
Malware / DoS         

 goto Top

Group: OS

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: OS / Windows

# of attack rules in this group: 2319

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
591PROTOCOL-RPC portmap ypupdated request TCP (more info ...)rpc-portmap-decode  1999-0208  1749    
1277PROTOCOL-RPC portmap ypupdated request UDP (more info ...)rpc-portmap-decode  1999-0208  28383    
2088PROTOCOL-RPC ypupdated arbitrary command attempt UDP (more info ...)misc-attack  1999-0208  28383    
2089PROTOCOL-RPC ypupdated arbitrary command attempt TCP (more info ...)misc-attack  1999-0208  1749    
2103NETBIOS SMB Trans2 OPEN2 unicode maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
2185PROTOCOL-RPC mountd UDP mount path overflow attempt (more info ...)misc-attack  2010-4227  8179  11800  
2435FILE-IDENTIFY Microsoft emf file download request (more info ...)misc-activity  2007-5746  9707    URL
2927OS-WINDOWS Microsoft Windows XPAT pattern overflow attempt (more info ...)attempted-admin  2004-0574      URL
3078PROTOCOL-NNTP Microsoft Windows SEARCH pattern overflow attempt (more info ...)attempted-admin  2004-0574      URL
3114OS-WINDOWS DCERPC NCACN-IP-TCP llsrpc LlsrConnect overflow attempt (more info ...)attempted-admin  2005-0050  12481    URL
3171OS-WINDOWS DCERPC NCADG-IP-UDP msqueue function 4 overflow attempt (more info ...)attempted-admin  2005-0059      URL
3590OS-WINDOWS DCERPC NCACN-IP-TCP mqqm QMDeleteObject overflow attempt (more info ...)attempted-admin  2005-0059    18027  URL
3591OS-WINDOWS DCERPC NCADG-IP-UDP mqqm QMDeleteObject overflow attempt (more info ...)attempted-admin  2005-0059    18027  URL
3632FILE-IMAGE Microsoft Windows Bitmap width integer overflow attempt (more info ...)attempted-admin  2008-3015  11171    URL
3967OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_QueryResConfList attempt (more info ...)protocol-command-decode  2005-1983  14513    URL
4072OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_DetectResourceConflict attempt (more info ...)protocol-command-decode  2005-1983  14513    URL
5485OS-WINDOWS DCERPC NCACN-IP-TCP llsrpc2 LlsrLicenseRequestW overflow attempt (more info ...)attempted-admin  2009-2523  12481    URL
6702NETBIOS SMB NT Trans Secondary Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6703NETBIOS SMB NT Trans Secondary unicode Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6704NETBIOS SMB-DS NT Trans Secondary Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6705NETBIOS SMB-DS NT Trans Secondary unicode Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6706NETBIOS SMB NT Trans Secondary Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6707NETBIOS SMB NT Trans Secondary unicode Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6708NETBIOS SMB NT Trans Secondary andx Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6709NETBIOS SMB NT Trans Secondary unicode andx Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6710NETBIOS SMB-DS NT Trans Secondary andx Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6711NETBIOS SMB-DS NT Trans Secondary unicode andx Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6712NETBIOS SMB NT Trans Secondary andx Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
6713NETBIOS SMB NT Trans Secondary unicode andx Param Count overflow attempt (more info ...)protocol-command-decode  2003-0085  7106    
7007BROWSER-PLUGINS AxDebugger.Document.1 ActiveX function call access (more info ...)attempted-user        
7209OS-WINDOWS DCERPC NCACN-IP-TCP srvsvc NetrPathCanonicalize overflow attempt (more info ...)attempted-admin  2006-3439  19409    URL
9027OS-WINDOWS DCERPC NCACN-IP-TCP wkssvc NetrJoinDomain2 overflow attempt (more info ...)attempted-admin  2006-4691    11921  URL
9769OS-WINDOWS DCERPC NCACN-IP-TCP msqueue function 4 overflow attempt (more info ...)attempted-admin  2005-0059      URL
10018NETBIOS DCERPC NCACN-IP-TCP brightstor-arc ReserveGroup attempt (more info ...)protocol-command-decode  2006-6917      URL
10030NETBIOS DCERPC NCACN-IP-TCP brightstor QSIGetQueuePath_Function_45 overflow attempt (more info ...)attempted-admin  2006-6076  20365    
10202NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetRealTimeScanConfigInfo attempt (more info ...)protocol-command-decode  2007-1070  22639    URL
10208NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect COMN_NetTestConnection attempt (more info ...)protocol-command-decode  2007-1070  22639    URL
10390BROWSER-PLUGINS Symantec Support Controls SmartIssue ActiveX clsid access (more info ...)attempted-user  2006-6490  22564    URL
10392BROWSER-PLUGINS Symantec Support Controls SmartIssue ActiveX function call access (more info ...)attempted-user  2006-6490  22564    URL
10393BROWSER-PLUGINS Symantec SupportSoft SmartIssue ActiveX clsid access (more info ...)attempted-user  2006-6490  22564    URL
10395BROWSER-PLUGINS Symantec SupportSoft SmartIssue ActiveX function call access (more info ...)attempted-user  2006-6490  22564    URL
10486NETBIOS DCERPC NCACN-IP-TCP brightstor-arc corrupt user-supplied memory address attempt (more info ...)protocol-command-decode  2007-1447  22994    URL
11442NETBIOS DCERPC NCACN-IP-TCP lsarpc LsarAddPrivilegesToAccount overflow attempt (more info ...)attempted-admin  2007-2446      
11443NETBIOS DCERPC NCADG-IP-UDP lsarpc LsarAddPrivilegesToAccount overflow attempt (more info ...)attempted-admin  2007-2446      
11684OS-WINDOWS Microsoft Windows WINS overflow attempt (more info ...)misc-attack  2004-1080  11922    URL
11945NETBIOS SMB Trans2 OPEN2 maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11955NETBIOS SMB-DS Trans2 OPEN2 maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11956NETBIOS SMB-DS Trans2 OPEN2 unicode maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11957NETBIOS SMB Trans2 OPEN2 maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11958NETBIOS SMB Trans2 OPEN2 unicode maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11959NETBIOS SMB Trans2 OPEN2 andx maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11960NETBIOS SMB Trans2 OPEN2 unicode andx maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11961NETBIOS SMB-DS Trans2 OPEN2 andx maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11962NETBIOS SMB-DS Trans2 OPEN2 unicode andx maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11963NETBIOS SMB Trans2 OPEN2 andx maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
11964NETBIOS SMB Trans2 OPEN2 unicode andx maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
12069OS-WINDOWS Microsoft Windows Active Directory Crafted LDAP ModifyRequest (more info ...)attempted-admin  2007-0040      URL
12198OS-WINDOWS Microsoft Windows getbulk request attempt (more info ...)attempted-admin  2006-5583      URL
12307NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetPagerNotifyConfig attempt (more info ...)protocol-command-decode  2007-4218  25395    
12317NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect-earthagent RPCFN_CopyAUSrc attempt (more info ...)protocol-command-decode  2007-4218  25395    
12326NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _AddTaskExportLogItem attempt (more info ...)protocol-command-decode  2007-4218  25395    
12332NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _TakeActionOnAFile attempt (more info ...)protocol-command-decode  2007-4218  25395    
12335NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect Trent_req_num_30010 overflow attempt (more info ...)attempted-admin  2007-4218  25395    
12341NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect Trent_req_num_a0030 attempt (more info ...)protocol-command-decode  2007-4218  25395    
12347NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetSvcImpersonateUser attempt (more info ...)protocol-command-decode  2007-4218  25395    
12458PROTOCOL-RPC Solaris TCP portmap sadmin port query request attempt (more info ...)rpc-portmap-decode  2003-0722  8615    
12612BROWSER-PLUGINS Microsoft Windows MFC Library ActiveX clsid access (more info ...)attempted-user  2007-4916  25697    
12614BROWSER-PLUGINS Microsoft Windows MFC Library ActiveX function call access (more info ...)attempted-user  2007-4916  25697    
12627PROTOCOL-RPC Solaris TCP portmapper sadmin port query attempt (more info ...)rpc-portmap-decode  2003-0722  8615    
12910NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 4 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12916NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 12 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12922NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 16 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12928NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 18 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12934NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 19 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12940NETBIOS DCERPC NCACN-IP-TCP brightstor-arc2 CA call 269 overflow attempt (more info ...)attempted-admin  2007-5327  26015    
12972FILE-IDENTIFY Microsoft Media Player asf/wmv/wma file magic detected (more info ...)misc-activity        
12984NETBIOS DCERPC NCACN-IP-TCP srvsvc NetSetFileSecurity integer overflow attempt (more info ...)protocol-command-decode  2007-2446  24196    
12985NETBIOS DCERPC NCADG-IP-UDP srvsvc NetSetFileSecurity integer overflow attempt (more info ...)protocol-command-decode  2007-2446  24196    
13162NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters overflow attempt (more info ...)attempted-admin  2008-0639  21220    
13459BROWSER-PLUGINS Microsoft Windows Forms 2.0 ActiveX function call access (more info ...)attempted-user  2007-0065      URL
13474OS-WINDOWS Microsoft WebDAV MiniRedir remote code execution attempt (more info ...)attempted-user  2008-0080      URL
13525BROWSER-PLUGINS Novell iPrint ActiveX function call access (more info ...)attempted-user  2011-4185  29736    URL
13619OS-WINDOWS Microsoft Windows getBulkRequest memory corruption attempt (more info ...)attempted-admin  2006-5583      URL
13965BROWSER-PLUGINS Microsoft Windows Message System ActiveX clsid access (more info ...)attempted-user  2008-0082      URL
13967BROWSER-PLUGINS Microsoft Windows Message System ActiveX function call access (more info ...)attempted-user  2008-0082      URL
14033BROWSER-PLUGINS Orbit Downloader ActiveX clsid access (more info ...)attempted-user  2008-1602      
14035BROWSER-PLUGINS Orbit Downloader ActiveX function call access (more info ...)attempted-user  2008-1602      
14037BROWSER-PLUGINS Novell iPrint ActiveX clsid access (more info ...)attempted-user  2011-4185  29736    URL
14038BROWSER-PLUGINS Novell iPrint ActiveX function call access (more info ...)attempted-user  2011-4185  29736    URL
14611BROWSER-PLUGINS VMWare VMCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3892  30934    
14613BROWSER-PLUGINS VMWare VMCtl Class ActiveX function call access (more info ...)attempted-user  2008-3892  30934    
14647OS-WINDOWS Microsoft Windows SMB Search Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14648OS-WINDOWS Microsoft Windows SMB Search unicode Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14649OS-WINDOWS Microsoft Windows SMB Search Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14650OS-WINDOWS Microsoft Windows SMB Search unicode Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14651OS-WINDOWS Microsoft Windows SMB Search andx Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14652OS-WINDOWS Microsoft Windows SMB Search unicode andx Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14653OS-WINDOWS Microsoft Windows SMB Search andx Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14654OS-WINDOWS Microsoft Windows SMB Search unicode andx Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14725OS-WINDOWS DCERPC NCACN-IP-TCP mqqm QMGetRemoteQueueName overflow attempt (more info ...)attempted-admin  2008-3479      URL
14726OS-WINDOWS DCERPC NCADG-IP-UDP mqqm QMGetRemoteQueueName overflow attempt (more info ...)attempted-admin  2008-3479      URL
14782OS-WINDOWS DCERPC NCACN-IP-TCP srvsvc NetrpPathCanonicalize path canonicalization stack overflow attempt (more info ...)attempted-admin  2008-4250      URL
14900NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum overflow attempt (more info ...)attempted-admin  2007-2446  24198    
14988NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum overflow attempt (more info ...)attempted-admin  2007-2446  24198    
15196OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE unicode param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15197OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15198OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE unicode param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15199OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15201OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15202OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE unicode andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15204OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE unicode max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15205OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE unicode max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15206OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15207OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15208OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE unicode andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15211OS-WINDOWS Microsoft Windows SMB NT Trans NT CREATE andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15212OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15214OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15215OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 unicode max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15216OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15219OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 unicode andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15221OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15222OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15223OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 unicode param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15226OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15227OS-WINDOWS Microsoft Windows SMB Trans2 OPEN2 unicode andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15508SERVER-OTHER DCERPC NCADG-IP-UDP lsarpc LsarLookupSids translated_names overflow attempt (more info ...)protocol-command-decode  2007-2446  24196    
15527OS-WINDOWS Microsoft Windows Active Directory LDAP denial of service attempt (more info ...)attempted-admin  2009-1138      URL
15528OS-WINDOWS Microsoft Windows DCERPC NCACN-IP-TCP spoolss RpcSetPrinterDataEx attempt (more info ...)protocol-command-decode  2009-0230      URL
15701OS-WINDOWS Microsoft Windows 2000 domain authentication bypass attempt (more info ...)attempted-user  2004-0540      URL
15881NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters Name Field attempt (more info ...)protocol-command-decode  2008-0639      
15911NETBIOS DCERPC NCACN-IP-TCP spoolss RouteRefreshPrinterChangeNotification attempt (more info ...)protocol-command-decode  2007-2446      
15930OS-WINDOWS Microsoft Windows SMB malformed process ID high field remote code execution attempt (more info ...)attempted-admin  2009-3103      URL
15965OS-WINDOWS Microsoft Explorer long share name buffer overflow attempt (more info ...)attempted-user  2004-0214  10213    URL
16034SERVER-SAMBA Samba spools RPC smb_io_notify_option_type_data request handling buffer overflow attempt (more info ...)attempted-user  2007-2446      
16143FILE-IDENTIFY Microsoft asf file magic detected (more info ...)misc-activity        URL
16238OS-WINDOWS DCERPC NCACN-IP-TCP llsrpc2 LlsrLicenseRequestW overflow attempt (more info ...)attempted-admin  2009-2523      URL
16239OS-WINDOWS DCERPC NCADG-IP-UDP llsrpc2 LlsrLicenseRequestW overflow attempt (more info ...)attempted-admin  2009-2523      URL
16329SERVER-OTHER Microsoft Internet Authentication Service EAP-MSCHAPv2 authentication bypass attempt (more info ...)attempted-user  2009-3677      URL
16395OS-WINDOWS Microsoft Windows SMB COPY command oversized pathname attempt (more info ...)attempted-admin  2010-0020      URL
16417OS-WINDOWS Microsoft Windows SMB Negotiate Protocol Response overflow attempt (more info ...)attempted-admin  2010-0016      URL
16538NETBIOS NT QUERY SECURITY DESC flowbit (more info ...)misc-activity        
16539OS-WINDOWS Microsoft Windows SMBv1 BytesNeeded ring0 buffer overflow attempt (more info ...)attempted-admin  2010-0269      URL
16540OS-WINDOWS Microsoft Windows SMB2 client NetBufferList NULL entry remote code execution attempt (more info ...)attempted-admin  2010-0477      URL
16706PROTOCOL-RPC Oracle Solaris sadmind TCP array size buffer overflow attempt (more info ...)attempted-admin  2008-3869  35083    
16728NETBIOS Samba SMB1 chain_reply function memory corruption attempt (more info ...)attempted-admin  2010-2063  40884    
16774BROWSER-PLUGINS EMC Captiva QuickScan Pro ActiveX function call access (more info ...)attempted-user  2012-2515  36546    
16776BROWSER-PLUGINS KeyWorks KeyHelp ActiveX control JumpURL method access attempt (more info ...)attempted-user  2012-2515  36546    
16797PROTOCOL-RPC Oracle Solaris sadmind TCP data length integer overflow attempt (more info ...)attempted-admin  2008-3870  35083    
17042FILE-OTHER Microsoft LNK shortcut arbitrary dll load attempt (more info ...)attempted-user  2017-8464      URL
17056SERVER-OTHER Novell NetIdentity Agent XTIERRPCPIPE remote code execution attempt (more info ...)attempted-admin  2009-1350  34400    
17125OS-WINDOWS Microsoft Windows SMB Trans2 MaxDataCount overflow attempt (more info ...)attempted-admin  2010-2550      URL
17205PROTOCOL-RPC Multiple vendors librpc.dll stack buffer overflow attempt - udp (more info ...)attempted-admin  2009-2754  38472    
17206PROTOCOL-RPC Multiple vendors librpc.dll stack buffer overflow attempt - tcp (more info ...)attempted-admin  2009-2754  38472    
17249OS-WINDOWS Microsoft Windows LSASS integer overflow attempt (more info ...)attempted-user  2010-0820      URL
17707NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect trend_req_num buffer overflow attempt (more info ...)protocol-command-decode  2007-1070  22639    URL
17714NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect CMON_ActiveUpdate attempt (more info ...)protocol-command-decode  2007-1070  22639    URL
17715NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect CMON_ActiveUpdate attempt (more info ...)protocol-command-decode  2007-1070  22639    URL
18189NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum attempt (more info ...)protocol-command-decode  2007-2446  24198    
18190NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum attempt (more info ...)protocol-command-decode  2007-2446  24198    
18191NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum attempt (more info ...)protocol-command-decode  2007-2446  24198    
18192NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum attempt (more info ...)protocol-command-decode  2007-2446  24198    
18319SERVER-SAMBA Samba DCERPC NCACN-IP-TCP lsarpc LsarLookupSids lsa_io_trans_name heap overflow attempt (more info ...)protocol-command-decode  2007-2446  24196    
18320OS-WINDOWS Microsoft Windows WINS association context validation overflow attempt (more info ...)misc-attack  2004-1080  11763    URL
18462OS-WINDOWS Microsoft Windows 2003 browser election remote heap overflow attempt (more info ...)attempted-admin  2011-0654  46360    URL
18472NETBIOS DCERPC NCACN-IP-TCP lsarpc LsarLookupSids lsa_io_trans_name heap overflow attempt (more info ...)protocol-command-decode  2007-2446  24196    
18557PROTOCOL-RPC IBM Informix Dynamic Server librpc.dll buffer overflow attempt (more info ...)attempted-admin  2009-2753  38471    
18558PROTOCOL-RPC IBM Informix Dynamic Server librpc.dll buffer overflow attempt (more info ...)attempted-admin  2009-2753  38471    
18904BROWSER-PLUGINS KingView ActiveX clsid access (more info ...)attempted-user  2011-3142  46757    URL
18994OS-WINDOWS Microsoft Windows 2003 browser election remote heap overflow attempt (more info ...)attempted-admin  2011-0654  46360    URL
19102BROWSER-PLUGINS Symantec CLIProxy.dll ActiveX clsid access (more info ...)attempted-user  2010-0108  38222    URL
19103BROWSER-PLUGINS Symantec CLIProxy.dll ActiveX function call access (more info ...)attempted-user  2010-0108  38222    URL
19290FILE-OTHER Microsoft LNK shortcut arbitary dll load attempt (more info ...)attempted-user  2010-2568      URL
20671OS-WINDOWS Microsoft Windows Active Directory Crafted LDAP ModifyRequest (more info ...)attempted-admin  2007-0040      URL
20850FILE-IDENTIFY Microsoft Windows EMF metafile file attachment detected (more info ...)misc-activity        
20851FILE-IDENTIFY Microsoft Windows EMF metafile file attachment detected (more info ...)misc-activity        
20878OS-WINDOWS Microsoft Windows Embedded Package Object packager.exe file load exploit attempt (more info ...)attempted-user  2012-0009      URL
21078FILE-MULTIMEDIA Microsoft Windows DirectShow GraphEdt closed captioning memory corruption (more info ...)attempted-user  2012-0004      URL
21299BROWSER-PLUGINS Microsoft Silverlight privilege escalation attempt (more info ...)attempted-admin  2012-0014      URL
21305FILE-EXECUTABLE Microsoft .NET Framework System.Uri.ReCreateParts System.Uri.PathAndQuery overflow attempt (more info ...)attempted-user  2012-0015      URL
21308FILE-OTHER Microsoft Windows C Run-Time Library remote code execution attempt (more info ...)attempted-user  2012-0150      URL
21504OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
21505OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
21506OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
21507OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
21508OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
21529OS-WINDOWS Microsoft Windows SMB Trans2 Find_First2 filename overflow attempt (more info ...)attempted-admin  2008-4038      URL
21570OS-WINDOWS Microsoft Windows RemoteDesktop new session flood attempt (more info ...)attempted-admin  2012-0002      URL
21619OS-WINDOWS Microsoft Windows RemoteDesktop connect-initial pdu remote code execution attempt (more info ...)attempted-admin  2012-0002      URL
21792FILE-EXECUTABLE Microsoft Windows .NET invalid parsing of graphics data attempt (more info ...)attempted-user  2012-0163      URL
21795FILE-EXECUTABLE Microsoft Windows Authenticode signature verification bypass attempt (more info ...)attempted-user  2012-0151      
22042FILE-EXECUTABLE Microsoft Windows .NET invalid parsing of graphics data attempt (more info ...)attempted-user  2012-0163      URL
22079OS-WINDOWS Microsoft .NET framework EvidenceBase class remote code execution attempt (more info ...)attempted-user  2012-0160      URL
22087FILE-OTHER Microsoft Windows True Type Font maxComponentPoints overflow attempt (more info ...)attempted-user  2012-0159      URL
22090OS-WINDOWS Microsoft .NET framework malicious XBAP attempt (more info ...)attempted-user  2012-0162      URL
22942FILE-EXECUTABLE Microsoft Windows Authenticode signature verification bypass attempt (more info ...)attempted-user  2012-0151      
23127FILE-EXECUTABLE Microsoft Windows .NET xbap STGMEDIUM.unionmember arbitrary number overwrite attempt (more info ...)attempted-user  2012-1855      URL
23181FILE-EXECUTABLE Microsoft Windows .NET Framework xbap DataObject object pointer attempt (more info ...)attempted-user  2012-1855      URL
23232OS-WINDOWS Microsoft Windows NT DHCP client identifier length overflow attempt (more info ...)attempted-user  2004-0900  11920    URL
23233OS-WINDOWS Microsoft Windows NT DHCP client identifier length overflow attempt (more info ...)attempted-user  2004-0900  11920    URL
23237OS-WINDOWS Microsoft Windows SMB2 client NetBufferList NULL entry remote code execution attempt (more info ...)attempted-admin  2010-0477      URL
23283BROWSER-PLUGINS Oracle WebCenter Forms Recognition ActiveX clsid access attempt (more info ...)attempted-user  2012-1709      
23352BROWSER-PLUGINS Cisco Linksys PlayerPT ActiveX clsid access attempt (more info ...)attempted-user  2012-0284      URL
23353BROWSER-PLUGINS Cisco Linksys PlayerPT ActiveX function call access attempt (more info ...)attempted-user  2012-0284      URL
23489FILE-OTHER Microsoft Windows Task Scheduler buffer overflow attempt (more info ...)attempted-user  2004-0212  10708    
23703FILE-IDENTIFY Microsoft asf file magic detected (more info ...)misc-activity        URL
23732FILE-IDENTIFY Microsoft Media Player .asf file magic detected (more info ...)misc-activity        
23837OS-WINDOWS Microsoft Windows SMB host announcement format string exploit attempt (more info ...)attempted-admin  2012-1851      URL
23838OS-WINDOWS Microsoft Windows SMB NetServerEnum response host format string exploit attempt (more info ...)attempted-admin  2012-1851      URL
23839OS-WINDOWS Microsoft Windows SMB RAP API NetServerEnum2 long server name buffer overflow attempt (more info ...)attempted-dos  2012-1853  54940    URL
23846OS-WINDOWS Microsoft Windows Terminal server RDP freed memory write attempt (more info ...)attempted-admin  2012-2526      URL
24007OS-WINDOWS Microsoft Windows SMB RAP API NetServerEnum2 long server name buffer overflow attempt (more info ...)attempted-dos  2012-1853  54940    URL
24089OS-WINDOWS Microsoft WebDAV PROPFIND request (more info ...)misc-activity        
24090OS-WINDOWS Microsoft Windows WebDAV invalid character argument injection attempt (more info ...)attempted-user  2012-0175  54307    URL
24196BROWSER-PLUGINS GE Intelligent Platforms Proficy HTML help ActiveX clsid access attempt (more info ...)attempted-user  2012-2516  54215    URL
24197BROWSER-PLUGINS GE Intelligent Platforms Proficy HTML help ActiveX function call attempt (more info ...)attempted-user  2012-2516  54215    URL
24336OS-WINDOWS Microsoft Windows SMB RAP API NetServerEnum2 long comment buffer overflow attempt (more info ...)attempted-admin  2012-1852      URL
24446SERVER-OTHER EMC NetWorker SunRPC format string exploit attempt (more info ...)attempted-admin  2012-2288  55330    
24500FILE-OTHER Microsoft LNK shortcut arbitrary dll load attempt (more info ...)attempted-user  2017-8464      URL
24503PROTOCOL-RPC xdrDecodeString caller_name stack overflow attempt (more info ...)misc-attack  2010-4227  46535    
24649FILE-OTHER Microsoft Windows TTF parsing counter overflow attempt (more info ...)attempted-admin  2012-4786      URL
24650FILE-OTHER Microsoft Windows TTF parsing counter overflow attempt (more info ...)attempted-admin  2012-4786      URL
24664FILE-EXECUTABLE Microsoft .NET blacklisted method reflection sandbox bypass attempt (more info ...)misc-activity  2012-1895      URL
24665FILE-EXECUTABLE Microsoft .NET blacklisted method reflection sandbox bypass attempt (more info ...)misc-activity  2012-1895      URL
24675BROWSER-PLUGINS Novell iPrint ActiveX realm parameter overflow attempt (more info ...)attempted-user  2011-4187      
24696PROTOCOL-RPC EMC Networker nsrindexd.exe procedure 0x01 buffer overflow attempt (more info ...)attempted-user  2012-0395      
24771BROWSER-PLUGINS IBM Lotus iNotes Attachment_Times ActiveX clsid access (more info ...)attempted-user  2012-2175      URL
24772BROWSER-PLUGINS IBM Lotus iNotes Attachment_Times ActiveX clsid access (more info ...)attempted-user  2012-2175  53879    URL
24957BROWSER-PLUGINS Microsoft dpnet.dll DirectPlay ActiveX clsid access (more info ...)attempted-user  2012-1537  56839    URL
24958BROWSER-PLUGINS Microsoft dpnet.dll DirectPlay ActiveX clsid access (more info ...)attempted-user  2012-1537  56839    URL
24959BROWSER-PLUGINS Microsoft dpnet.dll DirectPlay ActiveX clsid access (more info ...)attempted-user  2012-1537  56839    URL
24960BROWSER-PLUGINS Microsoft dpnet.dll DirectPlay ActiveX clsid access (more info ...)attempted-user  2012-1537  56839    URL
24961BROWSER-PLUGINS Microsoft dpnet.dll DirectPlay ActiveX clsid access (more info ...)attempted-user  2012-1537  56839    URL
24962BROWSER-PLUGINS Microsoft dpnet.dll DirectPlay ActiveX clsid access (more info ...)attempted-user  2012-1537  56839    URL
24963BROWSER-PLUGINS Microsoft DirectPlay ActiveX clsid access (more info ...)attempted-user  2012-1537  56839    URL
25032FILE-IDENTIFY Microsoft Silverlight application file download request (more info ...)misc-activity        
25033FILE-IDENTIFY Microsoft Silverlight application file attachment detected (more info ...)misc-activity        
25034FILE-IDENTIFY Microsoft Silverlight application file attachment detected (more info ...)misc-activity        
25253FILE-EXECUTABLE Microsoft Windows .NET Framework System.Uri.ReCreateParts System.Uri.PathAndQuery overflow attempt (more info ...)attempted-user  2012-0015      URL
25254BROWSER-PLUGINS Cisco Linksys PlayerPT ActiveX clsid access attempt (more info ...)attempted-user  2012-0284      URL
25299BROWSER-PLUGINS IBM VsVIEW ActiveX control directory traversal attempt (more info ...)attempted-user  2012-0189  51448    URL
25300BROWSER-PLUGINS IBM VsVIEW ActiveX control directory traversal attempt (more info ...)attempted-user  2012-0189  51448    URL
25312SERVER-OTHER Microsoft Threat Management Gateway heap buffer overflow attempt (more info ...)attempted-user  2011-1889  48181    URL
25357FILE-EXECUTABLE Microsoft Windows Authenticode signature verification bypass attempt (more info ...)attempted-user  2012-0151      
25381SERVER-OTHER Microsoft Threat Management Gateway heap buffer overflow attempt (more info ...)attempted-user  2011-1889  48181    URL
25542PROTOCOL-RPC EMC NetWorker nsrindexd service buffer overflow attempt (more info ...)attempted-admin  2012-4607  57182    
25779FILE-EXECUTABLE Microsoft Windows Authenticode signature verification bypass attempt (more info ...)attempted-user  2012-0151      
25795FILE-MULTIMEDIA Microsoft Windows DirectShow MPEG heap overflow attempt (more info ...)attempted-user  2013-0077      URL
25796FILE-MULTIMEDIA Microsoft Windows DirectShow MPEG heap overflow attempt (more info ...)attempted-user  2013-0077      URL
26066OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
26067OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
26068OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
26069OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user  2012-0013      URL
26182BROWSER-PLUGINS Samsung NET-i viewer BackupToAvi ActiveX function call access attempt (more info ...)attempted-user  2012-4333  53193    
26183BROWSER-PLUGINS TRENDNet SecurView internet camera UltraMJCam ActiveX clsid access attempt (more info ...)attempted-user  2012-4876  52760    
26184BROWSER-PLUGINS TRENDNet SecurView internet camera UltraMJCam ActiveX function call access attempt (more info ...)attempted-user  2012-4876  52760    
26355BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26356BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26357BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26358BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26359BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26360BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26361BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26362BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26363BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26365BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
26643OS-WINDOWS Microsoft Windows SMB malformed process ID high field denial of service attempt (more info ...)attempted-dos  2009-3103      URL
26865FILE-IMAGE Microsoft Multiple Products malformed PNG detected tEXt overflow attempt (more info ...)attempted-user  2013-1331  18385    URL
27136OS-WINDOWS Microsoft Windows .NET CLR mutlidimensional array handling remote code execution attempt (more info ...)attempted-admin  2013-3134      URL
27139OS-WINDOWS Microsoft Windows .NET CLR mutlidimensional array handling remote code execution attempt (more info ...)attempted-admin  2013-3134      URL
27576FILE-OTHER Microsoft Windows True Type Font maxComponentPoints overflow attempt (more info ...)attempted-user  2012-0159      URL
27798BROWSER-PLUGINS GE Intelligent Platforms Proficy HTML help ActiveX clsid access attempt (more info ...)attempted-user  2012-2516  54215    URL
27799BROWSER-PLUGINS GE Intelligent Platforms Proficy HTML help ActiveX function call attempt (more info ...)attempted-user  2012-2516  54215    URL
27822FILE-OTHER Microsoft Windows XP .theme file remote code execution attempt (more info ...)attempted-admin  2013-0810      URL
27869BROWSER-PLUGINS HP LoadRunner WriteFileString ActiveX function call attempt (more info ...)attempted-user  2013-4798  61443    URL
27870BROWSER-PLUGINS HP LoadRunner WriteFileString ActiveX function call attempt (more info ...)attempted-user  2013-4798  61443    URL
27871BROWSER-PLUGINS HP LoadRunner WriteFileString ActiveX function call attempt (more info ...)attempted-user  2013-4798  61443    URL
27872BROWSER-PLUGINS HP LoadRunner WriteFileString ActiveX function call attempt (more info ...)attempted-user  2013-4798  61443    URL
28425OS-WINDOWS Microsoft Windows SMB Microsoft Windows Remote Administration Protocol usage attempt (more info ...)misc-activity        
28436BROWSER-PLUGINS IBM SPSS SamplePower ActiveX clsid access attempt (more info ...)attempted-user  2014-0895  66116    
28487OS-WINDOWS Microsoft GDI library TIFF handling memory corruption attempt (more info ...)attempted-user  2013-3906      
28488OS-WINDOWS Microsoft GDI library TIFF handling memory corruption attempt (more info ...)attempted-user  2013-3906      
28506BROWSER-PLUGINS InformationCardSigninHelper ActiveX function call access (more info ...)attempted-user  2013-3918      URL
28507FILE-IDENTIFY Microsoft Write file download file attachment detected (more info ...)misc-activity        
28508FILE-IDENTIFY Microsoft Write file download file attachment detected (more info ...)misc-activity        
28579BROWSER-PLUGINS Microsoft Silverlight ScriptObject untrusted pointer dereference attempt (more info ...)attempted-user  2013-0074  58327    URL
28580BROWSER-PLUGINS Microsoft Silverlight ScriptObject untrusted pointer dereference attempt (more info ...)attempted-user  2013-0074  58327    URL
28581BROWSER-PLUGINS Microsoft Silverlight ScriptObject untrusted pointer dereference attempt (more info ...)attempted-user  2013-0074  58327    URL
28582BROWSER-PLUGINS Microsoft Silverlight ScriptObject untrusted pointer dereference attempt (more info ...)attempted-user  2013-0074  58327    URL
28583BROWSER-PLUGINS Microsoft Silverlight ScriptObject untrusted pointer dereference attempt (more info ...)attempted-user  2013-0074  58327    URL
28584BROWSER-PLUGINS Microsoft Silverlight ScriptObject untrusted pointer dereference attempt (more info ...)attempted-user  2013-0074  58327    URL
29059BROWSER-PLUGINS CYME Power Engineering ChartFX.ClientServer ActiveX clsid access (more info ...)attempted-user        
29060BROWSER-PLUGINS CYME Power Engineering ChartFX.ClientServer ActiveX function call access (more info ...)attempted-user        
29506BROWSER-PLUGINS ABB Test Signal Viewer CWGraph3D ActiveX clsid access attempt (more info ...)attempted-user  2013-5022  61828    
29507BROWSER-PLUGINS ABB Test Signal Viewer CWGraph3D ActiveX clsid access attempt (more info ...)attempted-user  2013-5022  61828    
29508BROWSER-PLUGINS ABB Test Signal Viewer CWGraph3D ActiveX clsid access attempt (more info ...)attempted-user  2013-5022  61828    
29512BROWSER-PLUGINS KingView ActiveX clsid access (more info ...)attempted-user  2011-3142  46757    URL
29513OS-WINDOWS Microsoft Windows SMB Microsoft Windows RAP API NetServerEnum2 long comment buffer overflow attempt (more info ...)attempted-admin  2012-1852      URL
29514OS-WINDOWS Microsoft Windows SMB Microsoft Windows Remote Administration Protocol usage attempt (more info ...)misc-activity        
29538BROWSER-PLUGINS Microsoft Windows Message System ActiveX function call access (more info ...)attempted-user  2008-0082      URL
29618SERVER-WEBAPP Novell GroupWise Client activex InvokeContact untrusted pointer dereference (more info ...)attempted-user  2013-0804  57657    
29619SERVER-WEBAPP Novell GroupWise Client activex GenerateSummaryPage untrusted pointer dereference (more info ...)attempted-user  2013-0804  57657    
29621NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters overflow attempt (more info ...)attempted-admin  2008-0639  21220    
29943OS-WINDOWS Microsoft Windows SMB2 client NetBufferList NULL entry remote code execution attempt (more info ...)attempted-admin  2010-0477      URL
29944FILE-IMAGE Microsoft Multiple Products potentially malicious PNG detected - large or invalid chunk size (more info ...)attempted-user  2013-1331  18385    URL
29945FILE-IMAGE Microsoft Multiple Products potentially malicious PNG detected - large or invalid chunk size (more info ...)attempted-user  2013-1331  18385    URL
30048BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2013-6040  65038    
30049BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2013-6040  65038    
30050BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2013-6040  65038    
30051BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2013-6040  65038    
30052BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2013-6040  65038    
30053BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2013-6040  65038    
30092BROWSER-PLUGINS Novell GroupWise Client for Windows ActiveX clsid access (more info ...)attempted-user  2013-0804      URL
30093BROWSER-PLUGINS Novell GroupWise Client for Windows ActiveX function call access (more info ...)attempted-user  2013-0804      URL
30972EXPLOIT-KIT CritX exploit kit outbound request for Microsoft Silverlight landing page (more info ...)trojan-activity        
31369EXPLOIT-KIT Rig exploit kit outbound Microsoft Silverlight request (more info ...)trojan-activity        
31427FILE-OTHER Microsoft Windows C Run-Time Library remote code execution attempt (more info ...)attempted-user  2012-0150      URL
31702FILE-IDENTIFY Microsoft Silverlight application file magic detected (more info ...)misc-activity        
31703FILE-IDENTIFY Microsoft Silverlight application file magic detected (more info ...)misc-activity        
31877SERVER-OTHER HP Application Life Cycle Management ActiveX arbitrary code execution attempt (more info ...)attempted-user    55272    
31878SERVER-OTHER HP Application Life Cycle Management ActiveX arbitrary code execution attempt (more info ...)attempted-user    55272    
31879SERVER-OTHER HP Application Life Cycle Management ActiveX arbitrary code execution attempt (more info ...)attempted-user    55272    
31880SERVER-OTHER HP Application Life Cycle Management ActiveX arbitrary code execution attempt (more info ...)attempted-user    55272    
31881SERVER-OTHER HP Application Life Cycle Management ActiveX arbitrary code execution attempt (more info ...)attempted-user    55272    
31882SERVER-OTHER HP Application Life Cycle Management ActiveX arbitrary code execution attempt (more info ...)attempted-user    55272    
32149FILE-OTHER Microsoft System.Uri heap corruption attempt (more info ...)attempted-user  2014-4121  70351    URL
32150FILE-OTHER Microsoft System.Uri heap corruption attempt (more info ...)attempted-user  2014-4121  70351    URL
32151FILE-OTHER Microsoft System.Uri heap corruption attempt (more info ...)attempted-user  2014-4121  70351    URL
32152FILE-OTHER Microsoft System.Uri heap corruption attempt (more info ...)attempted-user  2014-4121  70351    URL
32190OS-WINDOWS Microsoft Windows TrueType Font parsing remote code execution attempt (more info ...)attempted-user  2014-4148      URL
32191OS-WINDOWS Microsoft Windows TrueType Font parsing remote code execution attempt (more info ...)attempted-user  2014-4148      URL
32356PROTOCOL-RPC mountd UDP unmount path overflow attempt (more info ...)misc-attack  2010-4227  8179  11800  
32361FILE-OTHER Microsoft Windows Briefcase integer overflow (more info ...)attempted-user  2012-1528      URL
32404OS-WINDOWS Microsoft Windows ECDSA certificate validation bypass attempt (more info ...)misc-attack  2014-6321      URL
32405OS-WINDOWS Microsoft Windows ECDSA certificate validation bypass attempt (more info ...)misc-attack  2014-6321      URL
32406OS-WINDOWS Microsoft Windows ECDSA certificate validation bypass attempt (more info ...)misc-attack  2014-6321      URL
32407OS-WINDOWS Microsoft Windows ECDSA certificate validation bypass attempt (more info ...)misc-attack  2014-6321      URL
32408OS-WINDOWS Microsoft Windows ECDSA certificate validation bypass attempt (more info ...)misc-attack  2014-6321      URL
32409OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32410OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32411OS-WINDOWS Microsoft Windows ECDSA certificate validation bypass attempt (more info ...)misc-attack  2014-6321      URL
32412OS-WINDOWS Microsoft Windows ECDSA certificate validation bypass attempt (more info ...)misc-attack  2014-6321      URL
32413OS-WINDOWS Microsoft Windows ECDSA certificate validation bypass attempt (more info ...)misc-attack  2014-6321      URL
32414OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32415OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32416OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32417OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32422OS-WINDOWS Microsoft Windows DTLSv1.0 handshake cookie buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32423OS-WINDOWS Microsoft Windows DTLSv1.0 hello verify request out of bounds read attempt (more info ...)attempted-admin  2014-6321      URL
32501FILE-OTHER Microsoft XML invalid priority in xsl template (more info ...)attempted-user  2014-4118      URL
32502FILE-OTHER Microsoft XML invalid priority in xsl template (more info ...)attempted-user  2014-4118      URL
32730FILE-OTHER Microsoft Windows XP .theme file remote code execution attempt (more info ...)attempted-admin  2013-0010      URL
32731OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32732OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
32876EXPLOIT-KIT Nuclear exploit kit outbound Microsoft Silverlight exploit request (more info ...)trojan-activity        
33003BROWSER-PLUGINS SolarWinds Orion Pepco32c ActiveX clsid access attempt (more info ...)attempted-user    62585    
33004BROWSER-PLUGINS SolarWinds Orion Pepco32c ActiveX clsid access attempt (more info ...)attempted-user    62585    
33016OS-WINDOWS Microsoft Windows NT DHCP client identifier length overflow attempt (more info ...)attempted-user  2004-0900  11920    URL
33017OS-WINDOWS Microsoft Windows NT DHCP client identifier length overflow attempt (more info ...)attempted-user  2004-0900  11920    URL
33018BROWSER-IE Oracle WebCenter BlackIceDevMode ActiveX clsid access attempt (more info ...)attempted-user  2013-1516      URL
33019BROWSER-IE Oracle WebCenter BlackIceDevMode ActiveX clsid access attempt (more info ...)attempted-user  2013-1516      URL
33020BROWSER-IE Oracle WebCenter BlackIceDevMode ActiveX clsid access attempt (more info ...)attempted-user  2013-1516      URL
33021BROWSER-IE Oracle WebCenter BlackIceDevMode ActiveX clsid access attempt (more info ...)attempted-user  2013-1516      URL
33050PROTOCOL-TELNET Microsoft Telnet Server buffer overflow attempt (more info ...)attempted-user  2015-0014      URL
33051BROWSER-PLUGINS CTSWebProxy ActiveX privilege escalation attempt (more info ...)attempted-admin  2015-0016      URL
33052BROWSER-PLUGINS CTSWebProxy ActiveX privilege escalation attempt (more info ...)attempted-admin  2015-0016      URL
33451PROTOCOL-TELNET Microsoft Telnet Server buffer overflow attempt (more info ...)attempted-user  2015-0014      URL
34057OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
34058OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin  2014-6321      URL
34178OS-WINDOWS Microsoft Windows CreateWindowEx privilege escalation attempt (more info ...)attempted-admin        
34179OS-WINDOWS Microsoft Windows CreateWindowEx privilege escalation attempt (more info ...)attempted-admin        
34331EXPLOIT-KIT Fiesta exploit kit Microsoft SilverLight exploit download (more info ...)trojan-activity        
34371FILE-OTHER Microsoft Journal memory corruption attempt (more info ...)attempted-user  2015-1698      URL
34372FILE-OTHER Microsoft Journal memory corruption attempt (more info ...)attempted-user  2015-1698      URL
34385FILE-OTHER Microsoft Journal memory corruption attempt (more info ...)attempted-user  2015-1697      URL
34386FILE-OTHER Microsoft Journal memory corruption attempt (more info ...)attempted-user  2015-1697      URL
34387FILE-OTHER Microsoft Journal out of bounds write attempt (more info ...)attempted-user  2015-1695      URL
34388FILE-OTHER Microsoft Journal out of bounds write attempt (more info ...)attempted-user  2015-1695      URL
34389FILE-OTHER Microsoft Journal out of bounds read attempt (more info ...)attempted-user  2015-1696      URL
34390FILE-OTHER Microsoft Journal out of bounds read attempt (more info ...)attempted-user  2015-1696      URL
34399FILE-OTHER Microsoft Journal file exploitation attempt (more info ...)attempted-user  2015-1675      URL
34400FILE-OTHER Microsoft Journal file exploitation attempt (more info ...)attempted-user  2015-1675      URL
34401OS-WINDOWS Microsoft Windows Calendar object heap corruption attempt (more info ...)attempted-user  2015-1673      URL
34402OS-WINDOWS Microsoft Windows Calendar object heap corruption attempt (more info ...)attempted-user  2015-1673      URL
34403FILE-OTHER Microsoft Journal out of bounds read attempt (more info ...)attempted-user  2015-1699      URL
34404FILE-OTHER Microsoft Journal out of bounds read attempt (more info ...)attempted-user  2015-1699      URL
34440OS-WINDOWS Microsoft Windows Win32k TrueType Font parsing out of bounds attempt (more info ...)attempted-user  2015-1671      URL
34441OS-WINDOWS Microsoft Windows Win32k TrueType Font parsing out of bounds attempt (more info ...)attempted-user  2015-1671      URL
34638BROWSER-PLUGINS Schneider Electric ProClima ActiveX clsid access attempt (more info ...)attempted-user  2014-8511      
34639BROWSER-PLUGINS Schneider Electric ProClima ActiveX function call access attempt (more info ...)attempted-user  2014-8511      
34640BROWSER-PLUGINS Schneider Electric ProClima ActiveX function call access attempt (more info ...)attempted-user  2014-8511      
34641BROWSER-PLUGINS McAfee Virtual Technician ActiveX clsid access attempt (more info ...)attempted-user  2012-5879      
35151OS-WINDOWS Microsoft Windows RDP server PDU length heap overflow attempt (more info ...)attempted-admin  2015-2373      URL
35304FILE-OTHER Microsoft Windows ATMFD kernel pool overflow attempt (more info ...)attempted-admin  2015-2426      URL
35305FILE-OTHER Microsoft Windows ATMFD kernel pool overflow attempt (more info ...)attempted-admin  2015-2426      URL
35483FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file remote code execution attempt (more info ...)attempted-admin  2015-2432      URL
35484FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file remote code execution attempt (more info ...)attempted-admin  2015-2432      URL
35485FILE-OTHER Microsoft Windows atmfd.dll font driver malformed OTF file remote code execution attempt (more info ...)attempted-admin  2015-2462      URL
35486FILE-OTHER Microsoft Windows atmfd.dll font driver malformed OTF file remote code execution attempt (more info ...)attempted-admin  2015-2462      URL
35489FILE-OTHER Microsoft Windows OTF file parsing error exploitation attempt (more info ...)attempted-user  2015-2458      URL
35490FILE-OTHER Microsoft Windows OTF file parsing error exploitation attempt (more info ...)attempted-user  2015-2458      URL
35491FILE-OTHER Microsoft Windows GDI DrvQueryFontData function uninitialized glyph data remote code execution attempt (more info ...)attempted-user  2015-2435      URL
35492FILE-OTHER Microsoft Windows GDI DrvQueryFontData function uninitialized glyph data remote code execution attempt (more info ...)attempted-user  2015-2435      URL
35495FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file remote code execution attempt (more info ...)attempted-admin  2015-2459      URL
35496FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file remote code execution attempt (more info ...)attempted-admin  2015-2459      URL
35515OS-WINDOWS Microsoft Windows ATFM.DLL malformed OTF use-after-free attempt (more info ...)attempted-user  2015-2460      URL
35516OS-WINDOWS Microsoft Windows ATFM.DLL malformed OTF use-after-free attempt (more info ...)attempted-user  2015-2460      URL
35517FILE-OTHER Microsoft Windows FontView OpenType Font atmfd.dll invalid memory reference attempt (more info ...)attempted-admin  2015-2461      URL
35518FILE-OTHER Microsoft Windows FontView OpenType Font atmfd.dll invalid memory reference attempt (more info ...)attempted-admin  2015-2461      URL
35519FILE-OTHER Microsoft Windows kernel-mode driver TTF file glyf table out of bounds attempt (more info ...)attempted-admin  2015-2463      URL
35520FILE-OTHER Microsoft Windows kernel-mode driver TTF file glyf table out of bounds attempt (more info ...)attempted-admin  2015-2463      URL
35523OS-WINDOWS Microsoft Windows TTF invalid system memory access attempt (more info ...)attempted-admin  2015-2464      URL
35524OS-WINDOWS Microsoft Windows TTF invalid system memory access attempt (more info ...)attempted-admin  2015-2464      URL
35525OS-WINDOWS Microsoft Windows TrueType font parsing integer underflow attempt (more info ...)attempted-admin  2015-2455      URL
35526OS-WINDOWS Microsoft Windows TrueType font parsing integer underflow attempt (more info ...)attempted-admin  2015-2455      URL
35705BROWSER-IE Microsoft Edge history.state use after free attempt (more info ...)attempted-user        
35706BROWSER-IE Microsoft Edge history.state use after free attempt (more info ...)attempted-user        
35719OS-WINDOWS Microsoft Windows CDD font parsing kernel memory corruption attempt (more info ...)attempted-admin  2015-2506      URL
35720OS-WINDOWS Microsoft Windows CDD font parsing kernel memory corruption attempt (more info ...)attempted-admin  2015-2506      URL
35731OS-WINDOWS Microsoft Windows WebDAV invalid character argument injection attempt (more info ...)attempted-user  2012-0175  54307    URL
35848FILE-IMAGE Microsoft Windows Bitmap width integer overflow attempt (more info ...)attempted-admin  2008-3015  11171    URL
35857FILE-OTHER Microsoft System.Uri heap corruption attempt (more info ...)attempted-user  2014-4121  70351    URL
35872BROWSER-PLUGINS Steema Software SL TeeChart Pro ActiveX clsid access (more info ...)attempted-user        
35873BROWSER-PLUGINS Steema Software SL TeeChart Pro ActiveX clsid access (more info ...)attempted-user        
35874BROWSER-PLUGINS Steema Software SL TeeChart Pro ActiveX clsid access (more info ...)attempted-user        
35875BROWSER-PLUGINS Steema Software SL TeeChart Pro ActiveX clsid access (more info ...)attempted-user        
35955BROWSER-IE Microsoft Edge CStr object use after free attempt (more info ...)attempted-user  2015-2490      URL
35956BROWSER-IE Microsoft Edge CStr object use after free attempt (more info ...)attempted-user  2015-6087      URL
35957BROWSER-IE Microsoft Edge CStr object use after free attempt (more info ...)attempted-user  2015-2490      URL
35958BROWSER-IE Microsoft Edge CStr object use after free attempt (more info ...)attempted-user  2015-6087      URL
35960BROWSER-IE Microsoft Edge DOMNode manipulation use after free attempt (more info ...)attempted-user  2015-2488      URL
35961FILE-OTHER Microsoft Journal file parsing remote code execution attempt (more info ...)attempted-user  2015-2513      URL
35962FILE-OTHER Microsoft Journal file parsing remote code execution attempt (more info ...)attempted-user  2015-2513      URL
35984OS-WINDOWS Microsoft Windows GDI+ denial of service attempt (more info ...)attempted-user  2015-2510      URL
35985OS-WINDOWS Microsoft Windows GDI+ denial of service attempt (more info ...)attempted-user  2015-2510      URL
36014OS-WINDOWS Microsoft Windows System.DirectoryServices.Protocols.Utility class memory overflow attempt (more info ...)attempted-user  2015-2504      URL
36015OS-WINDOWS Microsoft Windows System.DirectoryServices.Protocols.Utility class memory overflow attempt (more info ...)attempted-user  2015-2504      URL
36109BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven InterfaceFilter ActiveX clsid access (more info ...)attempted-user  2014-9208      URL
36111BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven InterfaceFilter ActiveX clsid access (more info ...)attempted-user  2014-9208      URL
36112BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven InterfaceFilter ActiveX clsid access (more info ...)attempted-user  2014-9208      URL
36472BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven ConvToSafeArray ActiveX clsid access (more info ...)attempted-user  2014-9208  76672    
36473BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven ConvToSafeArray ActiveX clsid access (more info ...)attempted-user  2014-9208  76672    
36475BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven ConvToSafeArray ActiveX clsid access (more info ...)attempted-user  2014-9208  76672    
36618BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven GetWideStrCpy ActiveX clsid access (more info ...)attempted-user  2014-9208  76672    
36619BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven GetWideStrCpy ActiveX clsid access (more info ...)attempted-user  2014-9208  76672    
36620BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven GetWideStrCpy ActiveX clsid access (more info ...)attempted-user  2014-9208  76672    
36621BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven GetWideStrCpy ActiveX clsid access (more info ...)attempted-user  2014-9208  76672    
36641BROWSER-PLUGINS Advantech WebAccess SCADA webdact.ocx AccessCode ActiveX clsid access attempt (more info ...)attempted-user  2014-0767  66728    
36642BROWSER-PLUGINS Advantech WebAccess SCADA webdact.ocx AccessCode ActiveX clsid access attempt (more info ...)attempted-user  2014-0767  66728    
36643BROWSER-PLUGINS Advantech WebAccess SCADA webdact.ocx AccessCode ActiveX clsid access attempt (more info ...)attempted-user  2014-0767  66728    
36644BROWSER-PLUGINS IBM Lotus iNotes Attachment_Times ActiveX clsid access (more info ...)attempted-user  2012-2175  53879    
36645BROWSER-PLUGINS IBM Lotus iNotes Attachment_Times ActiveX clsid access (more info ...)attempted-user  2012-2175  53879    
36646BROWSER-PLUGINS IBM Lotus iNotes Attachment_Times ActiveX clsid access (more info ...)attempted-user  2012-2175  53879    
36653BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2013-6040  65038    
36654BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2013-6040  65038    
36697FILE-OTHER Microsoft Windows Journal integer overflow attempt (more info ...)attempted-user  2015-6097      URL
36698FILE-OTHER Microsoft Windows Journal integer overflow attempt (more info ...)attempted-user  2015-6097      URL
36703OS-WINDOWS Microsoft Windows DeferWindowPos privilege escalation attempt (more info ...)attempted-admin  2015-6101      URL
36704OS-WINDOWS Microsoft Windows DeferWindowPos privilege escalation attempt (more info ...)attempted-admin  2015-6101      URL
36705OS-WINDOWS Microsoft Windows afd.sys memory corruption attempt (more info ...)attempted-admin  2015-2478      URL
36706OS-WINDOWS Microsoft Windows afd.sys memory corruption attempt (more info ...)attempted-admin  2015-2478      URL
36709OS-WINDOWS Microsoft Windows use after free kernel privilege escalation attempt (more info ...)attempted-admin  2015-6100      URL
36710OS-WINDOWS Microsoft Windows use after free kernel privilege escalation attempt (more info ...)attempted-admin  2015-6100      URL
36711FILE-IDENTIFY Microsoft Windows .NET Application file attachment detected (more info ...)misc-activity        
36712OS-WINDOWS Microsoft Windows ClickOnce information disclosure attempt (more info ...)attempted-user  2015-6096      URL
36713OS-WINDOWS Microsoft Windows ClickOnce information disclosure attempt (more info ...)attempted-user  2015-6096      URL
36722OS-WINDOWS Microsoft Windows win32k information disclosure attempt (more info ...)attempted-recon  2015-6109      URL
36723OS-WINDOWS Microsoft Windows win32k information disclosure attempt (more info ...)attempted-recon  2015-6109      URL
36736FILE-OTHER Microsoft Windows malformed TrueType file remote code execution attempt (more info ...)attempted-user  2015-6104      URL
36737FILE-OTHER Microsoft Windows malformed TrueType file remote code execution attempt (more info ...)attempted-user  2015-6104      URL
36746BROWSER-IE Microsoft Edge click method use after free attempt (more info ...)attempted-user  2015-6088      URL
36747BROWSER-IE Microsoft Edge click method use after free attempt (more info ...)attempted-user  2015-6088      URL
36749FILE-OTHER Microsoft Windows TrueType font parsing out of bounds write attempt (more info ...)attempted-user  2015-6103      URL
36750FILE-OTHER Microsoft Windows TrueType font parsing out of bounds write attempt (more info ...)attempted-user  2015-6103      URL
36761OS-WINDOWS Microsoft Windows NtSetInformationFile hard link sandbox bypass attempt (more info ...)policy-violation  2015-6113      URL
36762OS-WINDOWS Microsoft Windows NtSetInformationFile hard link sandbox bypass attempt (more info ...)policy-violation  2015-6113      URL
36817FILE-IMAGE Microsoft Windows Paint JPEG with malformed SOFx field integer overflow attempt (more info ...)attempted-user  2010-0028      URL
36818FILE-IMAGE Microsoft Windows Paint JPEG with malformed SOFx field integer overflow attempt (more info ...)attempted-user  2010-0028      URL
36865BROWSER-PLUGINS IDAutomation IDAuto.BarCode ActiveX clsid access attempt (more info ...)attempted-user  2008-2283      
36866BROWSER-PLUGINS IDAutomation IDAuto.Datamatrix ActiveX clsid access attempt (more info ...)attempted-user  2008-2283      
36867BROWSER-PLUGINS IDAutomation IDAuto.Datamatrix ActiveX clsid access attempt (more info ...)attempted-user  2008-2283      
36868BROWSER-PLUGINS IDAutomation IDAuto.BarCode ActiveX clsid access attempt (more info ...)attempted-user  2008-2283      
36869BROWSER-PLUGINS IDAutomation IDAuto.PDF417 ActiveX clsid access attempt (more info ...)attempted-user  2008-2283      
36870BROWSER-PLUGINS IDAutomation IDAuto.PDF417 ActiveX clsid access attempt (more info ...)attempted-user  2008-2283      
36871BROWSER-PLUGINS IDAutomation IDAuto.Aztec ActiveX clsid access attempt (more info ...)attempted-user  2008-2283      
36872BROWSER-PLUGINS IDAutomation IDAuto.Aztec ActiveX clsid access attempt (more info ...)attempted-user  2008-2283      
36884FILE-IMAGE Microsoft Windows Paint jpeg with malformed SOFx field integer overflow attempt (more info ...)attempted-user  2010-0028      URL
36932BROWSER-IE Microsoft Edge iframe climbing cross site scripting attempt (more info ...)attempted-user  2015-6170      URL
36933BROWSER-IE Microsoft Edge iframe climbing cross site scripting attempt (more info ...)attempted-user  2015-6170      URL
36952FILE-OTHER Microsoft Windows Font Viewer cmap offset integer underflow attempt (more info ...)attempted-user  2015-6130      URL
36953FILE-OTHER Microsoft Windows Font Viewer cmap offset integer underflow attempt (more info ...)attempted-user  2015-6130      URL
36970OS-WINDOWS Microsoft Windows win32k.sys palette double free attempt (more info ...)attempted-admin  2015-6173      URL
36971OS-WINDOWS Microsoft Windows win32k.sys palette double free attempt (more info ...)attempted-admin  2015-6173      URL
36976OS-WINDOWS Microsoft Windows thread lock desynchronization null pointer dereference attempt (more info ...)attempted-admin  2015-6174      URL
36977OS-WINDOWS Microsoft Windows thread lock desynchronization null pointer dereference attempt (more info ...)attempted-admin  2015-6174      URL
36984BROWSER-IE Microsoft Edge CAttrArray out of bounds read attempt (more info ...)attempted-user  2015-6168      URL
36985BROWSER-IE Microsoft Edge CAttrArray out of bounds read attempt (more info ...)attempted-user  2015-6168      URL
36989OS-WINDOWS Microsoft Windows gpuenergydrv.sys driver privilege escalation attempt (more info ...)attempted-admin  2015-6175      URL
36990OS-WINDOWS Microsoft Windows gpuenergydrv.sys driver privilege escalation attempt (more info ...)attempted-admin  2015-6175      URL
36997OS-WINDOWS Microsoft .NET Silverlight manifest resource file information disclosure attempt (more info ...)attempted-recon  2015-6114      URL
36998OS-WINDOWS Microsoft .NET Silverlight manifest resource file information disclosure attempt (more info ...)attempted-recon  2015-6114      URL
37005BROWSER-PLUGINS AAA EasyGrid DoSaveFile ActiveX clsid access attempt (more info ...)attempted-user  2009-0134      
37006BROWSER-PLUGINS AAA EasyGrid DoSaveFile ActiveX clsid access attempt (more info ...)attempted-user  2009-0134      
37007BROWSER-PLUGINS AAA EasyGrid DoSaveFile ActiveX clsid access attempt (more info ...)attempted-user  2009-0134      
37008BROWSER-PLUGINS AAA EasyGrid DoSaveFile ActiveX clsid access attempt (more info ...)attempted-user  2009-0134      
37021BROWSER-PLUGINS MW6 Technologies Barcode.dll ActiveX clsid access attempt (more info ...)attempted-user  2009-0298  33451    
37022BROWSER-PLUGINS MW6 Technologies Barcode.dll ActiveX clsid access attempt (more info ...)attempted-user  2009-0298  33451    
37023BROWSER-PLUGINS MW6 Technologies Barcode.dll ActiveX clsid access attempt (more info ...)attempted-user  2009-0298  33451    
37267BROWSER-PLUGINS Microsoft Silverlight GetChar out of bounds read attempt (more info ...)attempted-user  2016-0034      URL
37268BROWSER-PLUGINS Microsoft Silverlight GetChar out of bounds read attempt (more info ...)attempted-user  2016-0034      URL
37269OS-WINDOWS Microsoft Windows 10 low integrity level NTFS mount reparse point bypass attempt (more info ...)attempted-user  2016-0007      URL
37270OS-WINDOWS Microsoft Windows 10 low integrity level NTFS mount reparse point bypass attempt (more info ...)attempted-user  2016-0007      URL
37271OS-WINDOWS Microsoft Windows 10 low integrity level NTFS mount reparse point bypass attempt (more info ...)attempted-user  2016-0006      URL
37272OS-WINDOWS Microsoft Windows 10 low integrity level NTFS mount reparse point bypass attempt (more info ...)attempted-user  2016-0006      URL
37275OS-WINDOWS Microsoft Windows feclient.dll dll-load exploit attempt (more info ...)attempted-user  2016-0014      URL
37276OS-WINDOWS Microsoft Windows request for feclient.dll over SMB attempt (more info ...)attempted-user  2016-0014      URL
37277OS-WINDOWS Microsoft Windows devenum.dll device moniker underflow attempt (more info ...)attempted-admin  2016-0015      URL
37278OS-WINDOWS Microsoft Windows devenum.dll device moniker underflow attempt (more info ...)attempted-admin  2016-0015      URL
37279BROWSER-IE Microsoft Edge mutation event memory corruption attempt (more info ...)attempted-user  2016-0124      URL
37280BROWSER-IE Microsoft Edge mutation event memory corruption attempt (more info ...)attempted-user  2016-0124      URL
37512BROWSER-PLUGINS Schneider Electric ProClima F1BookView ActiveX clsid access attempt (more info ...)attempted-user  2015-8561      
37513BROWSER-PLUGINS Schneider Electric ProClima F1BookView ActiveX clsid access attempt (more info ...)attempted-user  2015-8561      
37515BROWSER-PLUGINS Schneider Electric ProClima F1BookView ActiveX clsid access attempt (more info ...)attempted-user  2015-8561      
37537BROWSER-PLUGINS Siemens Solid Edge SEListCtrlX ActiveX clsid access attempt (more info ...)attempted-user    60161    
37538BROWSER-PLUGINS Siemens Solid Edge SEListCtrlX ActiveX clsid access attempt (more info ...)attempted-user    60161    
37539BROWSER-PLUGINS Siemens Solid Edge WebPartHelper ActiveX clsid access attempt (more info ...)attempted-user    60158    
37540BROWSER-PLUGINS Siemens Solid Edge WebPartHelper ActiveX clsid access attempt (more info ...)attempted-user    60158    
37541BROWSER-PLUGINS Siemens Solid Edge SEListCtrlX ActiveX clsid access attempt (more info ...)attempted-user    60161    
37542BROWSER-PLUGINS Siemens Solid Edge SEListCtrlX ActiveX clsid access attempt (more info ...)attempted-user    60161    
37543BROWSER-PLUGINS Siemens Solid Edge WebPartHelper ActiveX clsid access attempt (more info ...)attempted-user    60158    
37544BROWSER-PLUGINS Siemens Solid Edge WebPartHelper ActiveX clsid access attempt (more info ...)attempted-user    60158    
37565FILE-PDF Microsoft Reader dynamic object stream uninitialized memory corruption attempt (more info ...)attempted-user  2016-0046      URL
37566FILE-PDF Microsoft Reader dynamic object stream uninitialized memory corruption attempt (more info ...)attempted-user  2016-0046      URL
37567OS-WINDOWS Microsoft Windows WmipReceiveNotifications out of bounds write attempt (more info ...)attempted-admin  2016-0040      URL
37568OS-WINDOWS Microsoft Windows WmipReceiveNotifications out of bounds write attempt (more info ...)attempted-admin  2016-0040      URL
37569OS-WINDOWS Microsoft Windows WmipReceiveNotifications out of bounds write attempt (more info ...)attempted-admin  2016-0040      URL
37570OS-WINDOWS Microsoft Windows WmipReceiveNotifications out of bounds write attempt (more info ...)attempted-admin  2016-0040      URL
37575BROWSER-IE Microsoft Edge CTextBlock out of bounds read attempt (more info ...)attempted-user  2016-0083      URL
37576BROWSER-IE Microsoft Edge CTextBlock out of bounds read attempt (more info ...)attempted-user  2016-0083      URL
37577FILE-OTHER Microsoft Windows Journal CWispTiss use after free attempt (more info ...)attempted-user  2016-0038      URL
37578FILE-OTHER Microsoft Windows Journal CWispTiss use after free attempt (more info ...)attempted-user  2016-0038      URL
37581BROWSER-IE Microsoft Edge SysFreeString double free attempt (more info ...)attempted-user  2016-0060      URL
37582BROWSER-IE Microsoft Edge SysFreeString double free attempt (more info ...)attempted-user  2016-0060      URL
37584OS-WINDOWS Microsoft Windows wind32kfull.sys out of bounds write attempt (more info ...)attempted-admin  2016-0048      URL
37585OS-WINDOWS Microsoft Windows wind32kfull.sys out of bounds write attempt (more info ...)attempted-admin  2016-0048      URL
37586OS-WINDOWS Microsoft Windows WebDAV mini redirector driver privilege escalation attempt (more info ...)attempted-admin  2016-0051      URL
37587OS-WINDOWS Microsoft Windows WebDAV mini redirector driver privilege escalation attempt (more info ...)attempted-admin  2016-0051      URL
37594FILE-PDF Microsoft Windows PDF Library invalid JPX image heap corruption attempt (more info ...)attempted-user  2016-0058      URL
37595FILE-PDF Microsoft Windows PDF Library invalid JPX image heap corruption attempt (more info ...)attempted-user  2016-0058      URL
37655OS-WINDOWS Microsoft .NET Framework XSLT parser stack exhaustion attempt (more info ...)attempted-dos  2016-0033      URL
37656OS-WINDOWS Microsoft .NET Framework XSLT parser stack exhaustion attempt (more info ...)attempted-dos  2016-0033      URL
37663FILE-MULTIMEDIA Microsoft Windows Movie Maker project file heap buffer overflow attempt (more info ...)attempted-user  2010-0265      URL
37677BROWSER-PLUGINS IBM SPSS SamplePower ActiveX clsid access attempt (more info ...)attempted-user  2014-0895  66116    
37678BROWSER-PLUGINS IBM SPSS SamplePower ActiveX clsid access attempt (more info ...)attempted-user  2014-0895  66116    
37801BROWSER-PLUGINS Microsoft Silverlight ScriptObject untrusted pointer dereference attempt (more info ...)attempted-user  2013-0074  58327    URL
37823BROWSER-PLUGINS InformationCardSigninHelper ActiveX function call access (more info ...)attempted-user  2013-3918      URL
37995BROWSER-PLUGINS IE MsRdpClient ActiveX attempt (more info ...)attempted-user  2013-1302      
37998BROWSER-PLUGINS IE MsRdpClient ActiveX attempt (more info ...)attempted-user  2013-1302      
37999BROWSER-PLUGINS IE MsRdpClient ActiveX attempt (more info ...)attempted-user  2013-1302      
38000BROWSER-PLUGINS IE MsRdpClient ActiveX attempt (more info ...)attempted-user  2013-1302      
38001BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38002BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38003BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38004BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38005BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38006BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38007BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38008BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38009BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38010BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38011BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user  2013-1302  58874    URL
38061OS-WINDOWS Microsoft Windows rpdesk remote code execution attempt (more info ...)attempted-user  2016-0095      URL
38062OS-WINDOWS Microsoft Windows rpdesk remote code execution attempt (more info ...)attempted-user  2016-0095      URL
38063FILE-OTHER Microsoft Windows atmfd.dll font driver malformed OTF file remote code execution attempt (more info ...)attempted-user  2016-0121      URL
38064FILE-OTHER Microsoft Windows atmfd.dll font driver malformed OTF file remote code execution attempt (more info ...)attempted-user  2016-0121      URL
38071OS-WINDOWS Microsoft Windows ValidateParentDepth out of bounds read attempt (more info ...)attempted-admin  2016-0096      URL
38072OS-WINDOWS Microsoft Windows ValidateParentDepth out of bounds read attempt (more info ...)attempted-admin  2016-0096      URL
38073BROWSER-IE Microsoft Edge CAsyncTpWorker Windows.Data.Pdf.dll object use after free attempt (more info ...)attempted-user  2016-0118      URL
38076BROWSER-IE Microsoft Edge CAsyncTpWorker Windows.Data.Pdf.dll object use after free attempt (more info ...)attempted-user  2016-0118      URL
38077BROWSER-IE Microsoft Edge CPostScriptEvaluator out of bounds read attempt (more info ...)attempted-user  2016-0117      URL
38078BROWSER-IE Microsoft Edge CPostScriptEvaluator out of bounds read attempt (more info ...)attempted-user  2016-0117      URL
38083OS-WINDOWS Microsoft Windows GreCreateDisplayDC surface object use after free attempt (more info ...)attempted-admin  2016-0093      URL
38084OS-WINDOWS Microsoft Windows GreCreateDisplayDC surface object use after free attempt (more info ...)attempted-admin  2016-0093      URL
38092OS-WINDOWS Microsoft Windows ObReferenceObjectByHandle function privilege escalation attempt (more info ...)attempted-user  2016-0087      URL
38093OS-WINDOWS Microsoft Windows ObReferenceObjectByHandle function privilege escalation attempt (more info ...)attempted-user  2016-0087      URL
38106BROWSER-IE Microsoft Edge LineBoxBuilder out-of-bound memory access attempt (more info ...)attempted-user  2016-0123      URL
38107BROWSER-IE Microsoft Edge LineBoxBuilder out-of-bound memory access attempt (more info ...)attempted-user  2016-0123      URL
38114OS-WINDOWS Microsoft Windows WebDAV mini redirector driver privilege escalation attempt (more info ...)attempted-admin  2016-0099      URL
38115OS-WINDOWS Microsoft Windows WebDAV mini redirector driver privilege escalation attempt (more info ...)attempted-admin  2016-0099      URL
38119OS-WINDOWS Microsoft Windows EPOINTQF privilege escalation attempt (more info ...)attempted-admin  2016-0094      URL
38120OS-WINDOWS Microsoft Windows EPOINTQF privilege escalation attempt (more info ...)attempted-admin  2016-0094      URL
38146BROWSER-PLUGINS SolarWinds Server Monitor ActiveX clsid access attempt (more info ...)attempted-user  2015-1500  72600    
38147BROWSER-PLUGINS SolarWinds Server Monitor ActiveX clsid access attempt (more info ...)attempted-user  2015-1500  72600    
38148BROWSER-PLUGINS SolarWinds Server Monitor ActiveX clsid access attempt (more info ...)attempted-user  2015-1500  72600    
38149BROWSER-PLUGINS SolarWinds Server Monitor ActiveX clsid access attempt (more info ...)attempted-user  2015-1500  72600    
38152BROWSER-PLUGINS WebGate WESPDiscovery ActiveX clsid access attempt (more info ...)attempted-user  2015-2100  72843    
38154BROWSER-PLUGINS WebGate WESPDiscovery ActiveX clsid access attempt (more info ...)attempted-user  2015-2100  72843    
38155BROWSER-PLUGINS WebGate WESPDiscovery ActiveX clsid access attempt (more info ...)attempted-user  2015-2100  72843    
38384BROWSER-PLUGINS Advantech WebAccess ActiveX clsid access attempt (more info ...)attempted-user        
38435BROWSER-PLUGINS Schneider F1 Bookview ActiveX clsid access attempt (more info ...)attempted-user  2015-7918      
38436BROWSER-PLUGINS Schneider F1 Bookview ActiveX clsid access attempt (more info ...)attempted-user  2015-7918      
38458OS-WINDOWS Microsoft Windows LSARPC LsapLookupSids denial of service attempt (more info ...)attempted-dos  2016-0135      URL
38459OS-WINDOWS Microsoft Windows DrawMenuBarTemp memory corruption attempt (more info ...)attempted-admin  2016-0143      URL
38460OS-WINDOWS Microsoft Windows DrawMenuBarTemp memory corruption attempt (more info ...)attempted-admin  2016-0143      URL
38461OS-WINDOWS DCERPC Bind auth level packet privacy connection detected (more info ...)protocol-command-decode        URL
38462OS-WINDOWS DCERPC Bind auth level packet privacy downgrade attempt (more info ...)attempted-recon  2016-0128      URL
38463BROWSER-PLUGINS Microsoft XML Core Services ActiveX control use after free attempt (more info ...)attempted-user  2016-0147      URL
38464BROWSER-PLUGINS Microsoft XML Core Services ActiveX control use after free attempt (more info ...)attempted-user  2016-0147      URL
38469OS-WINDOWS Microsoft Windows api-ms-win-appmodel-runtime dll-load exploit attempt (more info ...)attempted-user  2016-0160      URL
38470OS-WINDOWS Microsoft Windows api-ms-win-appmodel-runtime dll-load exploit attempt (more info ...)attempted-user  2016-0160      URL
38473BROWSER-IE Microsoft Edge iframe cross-site scripting attempt (more info ...)attempted-user  2016-0158      URL
38474BROWSER-IE Microsoft Edge iframe cross-site scripting attempt (more info ...)attempted-user  2016-0158      URL
38475OS-WINDOWS Microsoft Windows anonymous user token impersonation attempt (more info ...)attempted-admin  2016-0151      URL
38476OS-WINDOWS Microsoft Windows anonymous user token impersonation attempt (more info ...)attempted-admin  2016-0151      URL
38479BROWSER-IE Microsoft Edge remove range out of bounds read attempt (more info ...)attempted-user  2016-0156      URL
38480BROWSER-IE Microsoft Edge remove range out of bounds read attempt (more info ...)attempted-user  2016-0156      URL
38483BROWSER-IE Microsoft Edge CStyleSheet keyframes out of bounds read attempt (more info ...)attempted-user  2016-0157      URL
38484BROWSER-IE Microsoft Edge CStyleSheet keyframes out of bounds read attempt (more info ...)attempted-user  2016-0157      URL
38485BROWSER-IE Microsoft Edge TextDataSlice type confusion attempt (more info ...)attempted-user  2016-0155      URL
38486BROWSER-IE Microsoft Edge TextDataSlice type confusion attempt (more info ...)attempted-user  2016-0155      URL
38487OS-WINDOWS Microsoft Windows win32k.sys PathToRegion buffer overflow attempt (more info ...)attempted-admin  2016-0165      URL
38488OS-WINDOWS Microsoft Windows win32k.sys PathToRegion buffer overflow attempt (more info ...)attempted-admin  2016-0165      URL
38491OS-WINDOWS Microsoft Windows CreatePopupMenu win32k.sys use after free attempt (more info ...)attempted-user  2016-0167      URL
38492OS-WINDOWS Microsoft Windows CreatePopupMenu win32k.sys use after free attempt (more info ...)attempted-user  2016-0167      URL
38493FILE-OTHER Microsoft Windows win32k.sys glyph bitmap boundary out of bounds memory access attempt (more info ...)attempted-admin  2016-0145      URL
38494FILE-OTHER Microsoft Windows win32k.sys glyph bitmap boundary out of bounds memory access attempt (more info ...)attempted-admin  2016-0145      URL
38759OS-WINDOWS Microsoft Windows Win32k window handle use after free attempt (more info ...)attempted-admin  2016-0196      URL
38760OS-WINDOWS Microsoft Windows Win32k window handle use after free attempt (more info ...)attempted-admin  2016-0196      URL
38761OS-WINDOWS Microsoft Windows win32kfull.sys font object use after free attempt (more info ...)attempted-admin  2016-0174      URL
38762OS-WINDOWS Microsoft Windows win32kfull.sys font object use after free attempt (more info ...)attempted-admin  2016-0174      URL
38765OS-WINDOWS Microsoft Windows Dxgkrnl.sys RtlMemoryCopy buffer overflow attempt (more info ...)attempted-admin  2016-0167      URL
38766OS-WINDOWS Microsoft Windows Dxgkrnl.sys RtlMemoryCopy buffer overflow attempt (more info ...)attempted-admin  2016-0167      URL
38774OS-WINDOWS Microsoft Windows device content surface bitmap use after free attempt (more info ...)attempted-user  2016-0171      URL
38775OS-WINDOWS Microsoft Windows device content surface bitmap use after free attempt (more info ...)attempted-user  2016-0171      URL
38787OS-WINDOWS Microsoft Windows Device Context bitmap use after free attempt (more info ...)attempted-user  2016-0172      URL
38788OS-WINDOWS Microsoft Windows Device Context bitmap use after free attempt (more info ...)attempted-user  2016-0172      URL
38797BROWSER-IE Microsoft Edge graphics subcomponent use after free attempt (more info ...)attempted-user  2016-0184      URL
38798BROWSER-IE Microsoft Edge graphics subcomponent use after free attempt (more info ...)attempted-user  2016-0184      URL
38801OS-WINDOWS Microsoft Windows NtGdiGetEmbUFI kernel information disclosure attempt (more info ...)attempted-user  2016-0175      URL
38802OS-WINDOWS Microsoft Windows NtGdiGetEmbUFI kernel information disclosure attempt (more info ...)attempted-user  2016-0175      URL
38803OS-WINDOWS Microsoft Windows kernel Configuration Manager failure attempt (more info ...)attempted-user  2016-0180      URL
38804OS-WINDOWS Microsoft Windows kernel Configuration Manager failure attempt (more info ...)attempted-user  2016-0180      URL
38805BROWSER-IE Microsoft Edge Array.prototype.fill out of bounds write attempt (more info ...)attempted-user  2016-0193      URL
38806BROWSER-IE Microsoft Edge Array.prototype.fill out of bounds write attempt (more info ...)attempted-user  2016-0193      URL
38808OS-WINDOWS Microsoft Windows win32kfull.sys device context use after free attempt (more info ...)attempted-admin  2016-0173      URL
38809OS-WINDOWS Microsoft Windows win32kfull.sys device context use after free attempt (more info ...)attempted-admin  2016-0173      URL
38817FILE-OTHER Microsoft Windows gdi32 malformed EMF file ExtEscape buffer overflow attempt (more info ...)attempted-user  2016-0170      URL
38839OS-WINDOWS Microsoft Windows RPC NDR64 denial of service attempt (more info ...)attempted-dos  2016-0178      URL
38840OS-WINDOWS Microsoft Windows RPC NDR64 denial of service attempt (more info ...)attempted-dos  2016-0178      URL
39038BROWSER-PLUGINS Emerson ROCLINK800 ActiveX clsid access attempt (more info ...)attempted-user        
39039BROWSER-PLUGINS Emerson ROCLINK800 ActiveX clsid access attempt (more info ...)attempted-user        
39041BROWSER-PLUGINS National Instruments ActiveX clsid access attempt (more info ...)attempted-user  2013-5025      
39042BROWSER-PLUGINS National Instruments ActiveX clsid access attempt (more info ...)attempted-user  2013-5025      
39043BROWSER-PLUGINS Mitsubishi MX ActiveX clsid access attempt (more info ...)attempted-user        
39044BROWSER-PLUGINS Mitsubishi MX ActiveX clsid access attempt (more info ...)attempted-user        
39054BROWSER-PLUGINS Siemens Automation License Manager ActiveX clsid access attempt (more info ...)attempted-user  2011-4529      
39055BROWSER-PLUGINS Siemens Automation License Manager ActiveX clsid access attempt (more info ...)attempted-user  2011-4529      
39193OS-WINDOWS Microsoft Windows Win32k.sys MakeWindowForegroundWithState null pointer dereference attempt (more info ...)attempted-admin  2016-3221      URL
39194OS-WINDOWS Microsoft Windows Win32k.sys MakeWindowForegroundWithState null pointer dereference attempt (more info ...)attempted-admin  2016-3221      URL
39195OS-WINDOWS Microsoft Windows Win32k.sys MakeWindowForegroundWithState null pointer dereference attempt (more info ...)attempted-admin  2016-3221      URL
39196OS-WINDOWS Microsoft Windows Win32k.sys MakeWindowForegroundWithState null pointer dereference attempt (more info ...)attempted-admin  2016-3221      URL
39199BROWSER-IE Microsoft Edge class object confusion attempt (more info ...)attempted-user  2016-3199      URL
39200BROWSER-IE Microsoft Edge class object confusion attempt (more info ...)attempted-user  2016-3199      URL
39205BROWSER-IE Microsoft Edge PDF reader out of bounds memory access attempt (more info ...)attempted-user  2016-3203      URL
39206BROWSER-IE Microsoft Edge PDF reader out of bounds memory access attempt (more info ...)attempted-user  2016-3203      URL
39209OS-WINDOWS Microsoft Windows sandbox ProcessFontDisablePolicy check bypass attempt (more info ...)attempted-user  2016-3219      URL
39210OS-WINDOWS Microsoft Windows sandbox ProcessFontDisablePolicy check bypass attempt (more info ...)attempted-user  2016-3219      URL
39213OS-WINDOWS Microsoft Windows WebDAV NTLM reflection attack attempt (more info ...)attempted-admin  2016-3225      URL
39214OS-WINDOWS Microsoft Windows WebDAV NTLM reflection attack attempt (more info ...)attempted-admin  2016-3225      URL
39215OS-WINDOWS Microsoft Windows WebDAV NTLM reflection attack attempt (more info ...)attempted-admin  2016-3225      URL
39216OS-WINDOWS Microsoft Windows WebDAV NTLM reflection attack attempt (more info ...)attempted-admin  2016-3225      URL
39217OS-WINDOWS Microsoft Windows win32kfull.sys NtGdiExtFloodFill use after free attempt (more info ...)attempted-user  2016-3218      URL
39218OS-WINDOWS Microsoft Windows win32kfull.sys NtGdiExtFloodFill use after free attempt (more info ...)attempted-user  2016-3218      URL
39219BROWSER-IE Microsoft Edge edgehtml.dll uninitialized pointer vulnerability attempt (more info ...)attempted-user  2016-3222      URL
39220BROWSER-IE Microsoft Edge edgehtml.dll uninitialized pointer vulnerability attempt (more info ...)attempted-user  2016-3222      URL
39225OS-WINDOWS Microsoft Windows Diagnostics Hub directory traversal attempt (more info ...)attempted-admin  2016-3231      URL
39226OS-WINDOWS Microsoft Windows Diagnostics Hub directory traversal attempt (more info ...)attempted-admin  2016-3231      URL
39227OS-WINDOWS Microsoft Windows WPAD spoofing attempt (more info ...)attempted-user  2016-3236      URL
39232BROWSER-IE Microsoft Edge Content Security Policy bypass attempt (more info ...)attempted-user  2016-3198      URL
39233BROWSER-IE Microsoft Edge Content Security Policy bypass attempt (more info ...)attempted-user  2016-3198      URL
39238BROWSER-IE Microsoft Edge malformed PDF JPEG2000 object out of bounds memory access attempt (more info ...)attempted-user  2016-3215      URL
39239BROWSER-IE Microsoft Edge malformed PDF JPEG2000 object out of bounds memory access attempt (more info ...)attempted-user  2016-3215      URL
39260FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file out-of-bounds memory access attempt (more info ...)attempted-user  2016-3220      URL
39261FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file out-of-bounds memory access attempt (more info ...)attempted-admin  2016-3220      URL
39267OS-WINDOWS Microsoft Windows GdiPlus malformed EMF file out of bounds read attempt (more info ...)attempted-user  2016-3216      URL
39478OS-WINDOWS Microsoft Windows NtGdiSelectPen privilege escalation attempt (more info ...)attempted-admin  2016-3252      URL
39479OS-WINDOWS Microsoft Windows NtGdiSelectPen privilege escalation attempt (more info ...)attempted-admin  2016-3252      URL
39480OS-WINDOWS Microsoft Windows win32k out of bound read attempt (more info ...)attempted-admin  2016-3251      URL
39481OS-WINDOWS Microsoft Windows win32k out of bound read attempt (more info ...)attempted-admin  2016-3251      URL
39482OS-WINDOWS Microsoft Windows NtUserDraw privilege escalation attempt (more info ...)attempted-admin  2016-3249      URL
39483OS-WINDOWS Microsoft Windows NtUserDraw privilege escalation attempt (more info ...)attempted-admin  2016-3249      URL
39486BROWSER-IE Microsoft Edge chakra.dll invalid pointer access attempt (more info ...)attempted-user  2016-3259      URL
39487BROWSER-IE Microsoft Edge chakra.dll invalid pointer access attempt (more info ...)attempted-user  2016-3259      URL
39493BROWSER-IE Microsoft Edge edgehtml negative length out of bound memory copy attempt (more info ...)attempted-user  2016-3246      URL
39494BROWSER-IE Microsoft Edge edgehtml negative length out of bound memory copy attempt (more info ...)attempted-user  2016-3246      URL
39495OS-WINDOWS Microsoft Windows win32k.sys desktop switch use after free attempt (more info ...)attempted-admin  2016-3250      URL
39496OS-WINDOWS Microsoft Windows win32k.sys desktop switch use after free attempt (more info ...)attempted-admin  2016-3250      URL
39506BROWSER-IE Microsoft Edge ArrayBuffer.transfer information disclosure attempt (more info ...)attempted-recon  2016-3271      URL
39507BROWSER-IE Microsoft Edge ArrayBuffer.transfer information disclosure attempt (more info ...)attempted-recon  2016-3271      URL
39508OS-WINDOWS Microsoft Windows EndDeferWindowPos null page dereference attempt (more info ...)attempted-admin  2016-3254      URL
39509OS-WINDOWS Microsoft Windows EndDeferWindowPos null page dereference attempt (more info ...)attempted-admin  2016-3254      URL
39510BROWSER-IE Microsoft Edge bypassing window.opener protection attempt (more info ...)attempted-user  2016-3274      URL
39511BROWSER-IE Microsoft Edge bypassing window.opener protection attempt (more info ...)attempted-user  2016-3274      URL
39516OS-WINDOWS Microsoft Windows win32kfull.sys out of bounds read attempt (more info ...)attempted-admin  2016-3286      URL
39517OS-WINDOWS Microsoft Windows win32kfull.sys out of bounds read attempt (more info ...)attempted-admin  2016-3286      URL
39530BROWSER-IE Microsoft Edge clientInformation.geolocation.getCurrentPosition use-after-free attempt (more info ...)attempted-user  2016-3264      URL
39531BROWSER-IE Microsoft Edge clientInformation.geolocation.getCurrentPosition use-after-free attempt (more info ...)attempted-user  2016-3264      URL
39743SERVER-WEBAPP Dell SonicWall GMS set_time_config XMLRPC method command injection attempt (more info ...)web-application-attack  2018-9866      URL
39808OS-WINDOWS Microsoft Windows graphics subcomponent local privilege escalation attempt (more info ...)attempted-admin  2016-3310      URL
39809OS-WINDOWS Microsoft Windows graphics subcomponent local privilege escalation attempt (more info ...)attempted-admin  2016-3310      URL
39814OS-WINDOWS Microsoft Windows Win32kfull FloodFillWindow privilege escalation attempt (more info ...)attempted-admin  2016-3311      URL
39815OS-WINDOWS Microsoft Windows Win32kfull FloodFillWindow privilege escalation attempt (more info ...)attempted-admin  2016-3311      URL
39822BROWSER-IE Microsoft Edge edgehtml.dll invalid history state use after free attempt (more info ...)attempted-user  2016-3293      URL
39823BROWSER-IE Microsoft Edge edgehtml.dll invalid history state use after free attempt (more info ...)attempted-user  2016-3293      URL
39824OS-WINDOWS Microsoft Windows GDI emf file integer overflow attempt (more info ...)attempted-user  2016-3303      URL
39825OS-WINDOWS Microsoft Windows GDI emf file integer overflow attempt (more info ...)attempted-user  2016-3303      URL
39841OS-WINDOWS Microsoft Windows win32kbase bOutline out of bounds read attempt (more info ...)attempted-admin  2016-3309      URL
39842OS-WINDOWS Microsoft Windows win32kbase bOutline out of bounds read attempt (more info ...)attempted-admin  2016-3309      URL
39843OS-WINDOWS Microsoft Windows gdiplus EMF EmrText out of bounds write attempt (more info ...)attempted-user  2017-3121      URL
39844OS-WINDOWS Microsoft Windows gdiplus EMF EmrText out of bounds write attempt (more info ...)attempted-user  2017-3121      URL
39873FILE-OTHER Microsoft Windows PDF parsing invalid JPEG2000 SIZ marker attempt (more info ...)attempted-user  2016-3319      URL
39875NETBIOS DCERPC NCACN-IP-TCP lsarpc LsarAddPrivilegesToAccount overflow attempt (more info ...)attempted-admin  2007-2446      
39932BROWSER-PLUGINS Iocomp Software ActiveX clsid access attempt (more info ...)attempted-user        URL
39933BROWSER-PLUGINS Iocomp Software ActiveX clsid access attempt (more info ...)attempted-user        URL
39934BROWSER-PLUGINS Iocomp Software ActiveX clsid access attempt (more info ...)attempted-user        URL
39935BROWSER-PLUGINS Iocomp Software ActiveX clsid access attempt (more info ...)attempted-user        URL
39959BROWSER-PLUGINS AdvantechNVS VideoDAQ ActiveX clsid access attempt (more info ...)attempted-user        URL
39960BROWSER-PLUGINS AdvantechNVS VideoDAQ ActiveX clsid access attempt (more info ...)attempted-user        URL
39961BROWSER-PLUGINS AdvantechNVS VideoDAQ ActiveX clsid access attempt (more info ...)attempted-user        URL
39962BROWSER-PLUGINS AdvantechNVS VideoDAQ ActiveX clsid access attempt (more info ...)attempted-user        URL
39963BROWSER-PLUGINS Moxa VPort SDK PLUS ActiveX clsid access attempt (more info ...)attempted-user  2015-0986      
39964BROWSER-PLUGINS Moxa VPort SDK PLUS ActiveX clsid access attempt (more info ...)attempted-user  2015-0986      
39965BROWSER-PLUGINS Moxa VPort SDK PLUS ActiveX clsid access attempt (more info ...)attempted-user  2015-0986      
39966BROWSER-PLUGINS Moxa VPort SDK PLUS ActiveX clsid access attempt (more info ...)attempted-user  2015-0986      
39970BROWSER-PLUGINS UCanCode Visualization Enterprise Suite ActiveX clsid access attempt (more info ...)attempted-user        URL
39971BROWSER-PLUGINS UCanCode Visualization Enterprise Suite ActiveX clsid access attempt (more info ...)attempted-user        URL
39972BROWSER-PLUGINS UCanCode Visualization Enterprise Suite ActiveX clsid access attempt (more info ...)attempted-user        URL
39973BROWSER-PLUGINS UCanCode Visualization Enterprise Suite ActiveX clsid access attempt (more info ...)attempted-user        URL
40008SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-admin  2016-0856  80745    URL
40064OS-WINDOWS Microsoft Windows NFS Server NULL pointer dereference denial-of-service attempt (more info ...)attempted-dos  2013-1281      URL
40065OS-WINDOWS Microsoft Windows NFS Server NULL pointer dereference denial-of-service attempt (more info ...)attempted-dos  2013-1281      URL
40073BROWSER-IE Microsoft Edge white-space information disclosure attempt (more info ...)attempted-recon  2016-3247      URL
40074BROWSER-IE Microsoft Edge white-space information disclosure attempt (more info ...)attempted-user  2016-3247      URL
40096OS-WINDOWS Microsoft Windows 7 Win32k ValidateZorder privilege escalation attempt (more info ...)attempted-admin  2016-3348      URL
40097OS-WINDOWS Microsoft Windows 7 Win32k ValidateZorder privilege escalation attempt (more info ...)attempted-admin  2016-3348      URL
40098BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user  2016-3377      URL
40099BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user  2016-3377      URL
40100BROWSER-IE Microsoft Edge PDF PostScript calculator out of bounds read attempt (more info ...)attempted-recon  2016-3374      URL
40101BROWSER-IE Microsoft Edge PDF PostScript calculator out of bounds read attempt (more info ...)attempted-recon  2016-3374      URL
40110OS-WINDOWS Microsoft Windows Server Ntoskrnl concurrent login attempt (more info ...)attempted-user  2016-3306      URL
40111OS-WINDOWS Microsoft Windows Server Ntoskrnl concurrent login attempt (more info ...)attempted-user  2016-3306      URL
40112OS-WINDOWS Microsoft Windows 10 GDI privilege escalation attempt (more info ...)attempted-admin  2016-3355      URL
40113OS-WINDOWS Microsoft Windows 10 GDI privilege escalation attempt (more info ...)attempted-admin  2016-3355      URL
40114OS-WINDOWS Microsoft Windows 10 privilege escalation attempt (more info ...)attempted-admin  2016-3373      URL
40115OS-WINDOWS Microsoft Windows 10 privilege escalation attempt (more info ...)attempted-admin  2016-3373      URL
40123BROWSER-IE Microsoft Edge edgehtml.dll normalize missing div child use after free attempt (more info ...)attempted-user  2016-3294      URL
40124BROWSER-IE Microsoft Edge edgehtml.dll normalize missing div child use after free attempt (more info ...)attempted-user  2016-3294      URL
40127OS-WINDOWS Microsoft Windows 10 and 8.1 registry key privilege escalation attempt (more info ...)attempted-user  2016-3371      URL
40128OS-WINDOWS Microsoft Windows 10 and 8.1 registry key privilege escalation attempt (more info ...)attempted-user  2016-3371      URL
40129OS-WINDOWS Microsoft Windows Server lsass.exe memory corruption attempt (more info ...)attempted-admin  2016-3368      URL
40134BROWSER-IE Microsoft Edge HTML normalize caption memory corruption attempt (more info ...)attempted-user  2016-3295      URL
40135BROWSER-IE Microsoft Edge HTML normalize caption memory corruption attempt (more info ...)attempted-user  2016-3295      URL
40136BROWSER-IE Microsoft Edge HTML normalize caption memory corruption attempt (more info ...)attempted-user  2016-3295      URL
40137BROWSER-IE Microsoft Edge HTML normalize caption memory corruption attempt (more info ...)attempted-user  2016-3295      URL
40138BROWSER-IE Microsoft Edge HTML normalize caption memory corruption attempt (more info ...)attempted-user  2016-3295      URL
40139BROWSER-IE Microsoft Edge HTML normalize caption memory corruption attempt (more info ...)attempted-user  2016-3295      URL
40140BROWSER-IE Microsoft Edge HTML normalize caption memory corruption attempt (more info ...)attempted-user  2016-3295      URL
40141BROWSER-IE Microsoft Edge HTML normalize caption memory corruption attempt (more info ...)attempted-user  2016-3295      URL
40372BROWSER-IE Microsoft Windows Edge emodel use after free attempt (more info ...)attempted-user  2016-3331      URL
40373BROWSER-IE Microsoft Windows Edge emodel use after free attempt (more info ...)attempted-user  2016-3331      URL
40374OS-WINDOWS Microsoft Windows insecure BoundaryDescriptor privilege escalation attempt (more info ...)attempted-admin  2016-3387      URL
40375OS-WINDOWS Microsoft Windows insecure BoundaryDescriptor privilege escalation attempt (more info ...)attempted-admin  2016-3387      URL
40380OS-WINDOWS Microsoft Windows win32kfull.sys FBitsTouch use after free attempt (more info ...)attempted-user  2016-7211      URL
40381OS-WINDOWS Microsoft Windows win32kfull.sys FBitsTouch use after free attempt (more info ...)attempted-user  2016-7211      URL
40383BROWSER-IE Microsoft Edge array.join information disclosure attempt (more info ...)attempted-user  2016-7189      URL
40384BROWSER-IE Microsoft Edge array.join information disclosure attempt (more info ...)attempted-user  2016-7189      URL
40392OS-WINDOWS Microsoft Windows Ntoskrnl privilege escalation attempt (more info ...)attempted-admin  2016-3376      URL
40393OS-WINDOWS Microsoft Windows Ntoskrnl privilege escalation attempt (more info ...)attempted-admin  2016-3376      URL
40394OS-WINDOWS Microsoft Windows Ntoskrnl integer overflow privilege escalation attempt (more info ...)attempted-admin  2017-0103      URL
40395OS-WINDOWS Microsoft Windows Ntoskrnl integer overflow privilege escalation attempt (more info ...)attempted-admin  2017-0103      URL
40396OS-WINDOWS Microsoft Windows Edge DACL privilege escalation attempt (more info ...)attempted-admin  2016-3388      URL
40397OS-WINDOWS Microsoft Windows Edge DACL privilege escalation attempt (more info ...)attempted-admin  2016-3388      URL
40398OS-WINDOWS Microsoft Windows Diagnostics Hub dll load from stream attempt (more info ...)attempted-admin  2016-7188      URL
40399OS-WINDOWS Microsoft Windows Diagnostics Hub dll load from stream attempt (more info ...)attempted-admin  2016-7188      URL
40400OS-WINDOWS Microsoft Windows 10 arbitrary registry key access privelege escalation attempt (more info ...)attempted-admin  2016-0075      URL
40401OS-WINDOWS Microsoft Windows 10 arbitrary registry key access privelege escalation attempt (more info ...)attempted-admin  2016-0075      URL
40402OS-WINDOWS Microsoft Windows user hive impersonation privelege escalation attempt (more info ...)attempted-admin  2016-0073      URL
40403OS-WINDOWS Microsoft Windows user hive impersonation privelege escalation attempt (more info ...)attempted-admin  2016-0073      URL
40408FILE-OTHER Microsoft Windows malformed TrueType file RCVT out of bounds read attempt (more info ...)attempted-user  2016-3209      URL
40409FILE-OTHER Microsoft Windows malformed TrueType file RCVT out of bounds read attempt (more info ...)attempted-user  2016-3209      URL
40410OS-WINDOWS Microsoft Windows win32k.sys ExtTextOut memory corruption attempt (more info ...)attempted-admin  2016-3270      URL
40411OS-WINDOWS Microsoft Windows win32k.sys ExtTextOut memory corruption attempt (more info ...)attempted-admin  2016-3270      URL
40412OS-WINDOWS Microsoft Windows registry hive privilege escalation attempt (more info ...)attempted-admin  2016-0079      URL
40413OS-WINDOWS Microsoft Windows registry hive privilege escalation attempt (more info ...)attempted-admin  2016-0079      URL
40418OS-WINDOWS Microsoft Windows DFS client driver privilege escalation attempt (more info ...)attempted-user  2016-7185      URL
40419OS-WINDOWS Microsoft Windows DFS client driver privilege escalation attempt (more info ...)attempted-user  2016-7185      URL
40423BROWSER-IE Microsoft Windows Edge function.apply use afterfree attempt (more info ...)attempted-user  2016-7194      URL
40424BROWSER-IE Microsoft Windows Edge function.apply use afterfree attempt (more info ...)attempted-user  2016-7194      URL
40425OS-WINDOWS Microsoft Windows GDI+ EMF buffer overread attempt (more info ...)attempted-user  2016-3263      URL
40426OS-WINDOWS Microsoft Windows GDI+ EMF buffer overread attempt (more info ...)attempted-user  2016-3263      URL
40427OS-WINDOWS Microsoft Windows Win32k.sys sbit_Embolden use after free attempt (more info ...)attempted-admin  2016-7182      URL
40428OS-WINDOWS Microsoft Windows Win32k.sys sbit_Embolden use after free attempt (more info ...)attempted-admin  2016-7182      URL
40555OS-WINDOWS Microsoft Windows AHCACHE.SYS remote denial of service attempt (more info ...)attempted-dos  2016-3369      URL
40556OS-WINDOWS Microsoft Windows AHCACHE.SYS remote denial of service attempt (more info ...)attempted-dos  2016-3369      URL
40645FILE-IMAGE Microsoft Windows asycfilt.dll malformed jpeg buffer overread attempt (more info ...)attempted-user  2016-7212      URL
40646FILE-IMAGE Microsoft Windows asycfilt.dll malformed jpeg buffer overread attempt (more info ...)attempted-user  2016-7212      URL
40657OS-WINDOWS Microsoft Windows clfs.sys local privilege escalation attempt (more info ...)attempted-admin  2016-3343      URL
40658OS-WINDOWS Microsoft Windows clfs.sys local privilege escalation attempt (more info ...)attempted-admin  2016-3343      URL
40659BROWSER-IE Microsoft Edge Chakra.dll Array.splice heap overflow attempt (more info ...)attempted-user  2016-7203      URL
40660BROWSER-IE Microsoft Edge Chakra.dll Array.splice heap overflow attempt (more info ...)attempted-user  2016-7203      URL
40661BROWSER-IE Microsoft Edge Array.concat type confusion attempt (more info ...)attempted-user  2016-7242      URL
40662BROWSER-IE Microsoft Edge Array.concat type confusion attempt (more info ...)attempted-user  2016-7242      URL
40663OS-WINDOWS Microsoft Windows NtGdiSetBitmapAttributes privilege escalation attempt (more info ...)attempted-admin  2016-7215      URL
40664OS-WINDOWS Microsoft Windows NtGdiSetBitmapAttributes privilege escalation attempt (more info ...)attempted-admin  2016-7215      URL
40665OS-WINDOWS Microsoft Windows keybd_event type confusion code execution attempt (more info ...)attempted-admin  2016-7255      URL
40666OS-WINDOWS Microsoft Windows keybd_event type confusion code execution attempt (more info ...)attempted-admin  2016-7255      URL
40671OS-WINDOWS Microsoft windows InProcServer32 privilege escalation attempt (more info ...)attempted-user  2016-7221      URL
40672OS-WINDOWS Microsoft windows InProcServer32 privilege escalation attempt (more info ...)attempted-user  2016-7221      URL
40675BROWSER-IE Microsoft Edge video html tag buffer overflow attempt (more info ...)attempted-admin  2016-7217      URL
40676BROWSER-IE Microsoft Edge video html tag buffer overflow attempt (more info ...)attempted-admin  2016-7217      URL
40677OS-WINDOWS Microsoft Windows Task Scheduler SystemLocal NTLM remote path authentication challenge attempt (more info ...)attempted-admin  2016-7222      URL
40678OS-WINDOWS Microsoft Windows Task Scheduler SystemLocal NTLM remote path authentication challenge attempt (more info ...)attempted-admin  2016-7222      URL
40683BROWSER-IE Microsoft Edge stack variable memory access attempt (more info ...)attempted-user  2016-7198      URL
40684BROWSER-IE Microsoft Edge stack variable memory access attempt (more info ...)attempted-user  2016-7198      URL
40685OS-WINDOWS Microsoft Windows win32kfull.sys MegSetLensContextInformation use after free attempt (more info ...)attempted-user  2016-7246      URL
40686OS-WINDOWS Microsoft Windows win32kfull.sys MegSetLensContextInformation use after free attempt (more info ...)attempted-user  2016-7246      URL
40687OS-WINDOWS Microsoft Windows win32k.sys GetDIBits out of bounds read attempt (more info ...)attempted-user  2016-7214      URL
40688OS-WINDOWS Microsoft Windows win32k.sys GetDIBits out of bounds read attempt (more info ...)attempted-user  2016-7214      URL
40689FILE-OTHER Microsoft Windows BLF file local privilege escalation attempt (more info ...)attempted-admin  2022-21897      URL
40690FILE-OTHER Microsoft Windows BLF file local privilege escalation attempt (more info ...)attempted-admin  2022-21897      URL
40691FILE-OTHER Microsoft Windows BLF file local privilege escalation attempt (more info ...)attempted-user  2018-0846      URL
40692FILE-OTHER Microsoft Windows BLF file local privilege escalation attempt (more info ...)attempted-user  2018-0846      URL
40693OS-WINDOWS Microsoft Windows VHDMP generic privilege escalation attempt (more info ...)attempted-user  2016-7226      URL
40694OS-WINDOWS Microsoft Windows VHDMP generic privilege escalation attempt (more info ...)attempted-user  2016-7226      URL
40705FILE-OTHER Microsoft Windows OTF cmap table parsing integer overflow attempt (more info ...)attempted-admin  2016-7210      URL
40706FILE-OTHER Microsoft Windows OTF cmap table parsing integer overflow attempt (more info ...)attempted-admin  2016-7210      URL
40729FILE-OTHER Microsoft Windows OTF parsing memory corruption attempt (more info ...)attempted-admin  2016-7256      URL
40730FILE-OTHER Microsoft Windows OTF parsing memory corruption attempt (more info ...)attempted-admin  2016-7256      URL
40759OS-WINDOWS Microsoft Windows LSASS GSS-API DER decoding null pointer dereference attempt (more info ...)attempted-dos  2017-0004      URL
40813BROWSER-PLUGINS Microsoft Silverlight GetChar out of bounds read attempt (more info ...)attempted-user  2016-0034      URL
40814BROWSER-PLUGINS Microsoft Silverlight GetChar out of bounds read attempt (more info ...)attempted-user  2016-0034      URL
40886OS-WINDOWS Microsoft Windows keybd_event type confusion code execution attempt (more info ...)attempted-admin  2016-7255      URL
40887OS-WINDOWS Microsoft Windows keybd_event type confusion code execution attempt (more info ...)attempted-admin  2016-7255      URL
40936FILE-EXECUTABLE Microsoft CLFS.sys information leak attempt (more info ...)attempted-recon  2016-7295      URL
40937FILE-EXECUTABLE Microsoft CLFS.sys information leak attempt (more info ...)attempted-recon  2016-7295      URL
40942FILE-OTHER Microsoft Windows GDI32.dll cmap numUVSMappings overflow attempt (more info ...)attempted-user  2016-7274      URL
40943FILE-OTHER Microsoft Windows GDI32.dll cmap numUVSMappings overflow attempt (more info ...)attempted-user  2016-7274      URL
40947OS-WINDOWS Microsoft Windows StripSolidHorizontal out of bounds memory access attempt (more info ...)attempted-admin  2016-7260      URL
40948OS-WINDOWS Microsoft Windows StripSolidHorizontal out of bounds memory access attempt (more info ...)attempted-admin  2016-7260      URL
40953OS-WINDOWS Microsoft Windows ksecdd.sys kernel information disclosure attempt (more info ...)attempted-user  2016-7219      URL
40954OS-WINDOWS Microsoft Windows ksecdd.sys kernel information disclosure attempt (more info ...)attempted-user  2016-7219      URL
40955OS-WINDOWS Microsoft Windows ksecdd.sys kernel information disclosure attempt (more info ...)attempted-user  2016-7219      URL
40956OS-WINDOWS Microsoft Windows ksecdd.sys kernel information disclosure attempt (more info ...)attempted-user  2016-7219      URL
40975BROWSER-IE Microsoft Edge iframe information disclosure attempt (more info ...)attempted-recon  2016-7282      URL
40976BROWSER-IE Microsoft Edge iframe information disclosure attempt (more info ...)attempted-recon  2016-7282      URL
40984OS-WINDOWS Microsoft Windows MSIEXEC privilege escalation attempt (more info ...)attempted-admin  2016-7292      URL
40985OS-WINDOWS Microsoft Windows MSIEXEC privilege escalation attempt (more info ...)attempted-admin  2016-7292      URL
41385BROWSER-IE Microsoft Edge mutation event memory corruption attempt (more info ...)attempted-user  2016-0124      URL
41386BROWSER-IE Microsoft Edge mutation event memory corruption attempt (more info ...)attempted-user  2016-0124      URL
41499SERVER-SAMBA Microsoft Windows SMBv2/SMBv3 Buffer Overflow attempt (more info ...)attempted-dos  2017-0016      
41501BROWSER-PLUGINS NTR ActiveX clsid access attempt (more info ...)attempted-user  2012-0267  51374    
41553BROWSER-IE Microsoft Edge url forgery attempt (more info ...)attempted-user  2017-0033      URL
41554BROWSER-IE Microsoft Edge url forgery attempt (more info ...)attempted-user  2017-0033      URL
41557BROWSER-IE Microsoft Edge Array out of bounds memory corruption attempt (more info ...)attempted-user  2017-0046      URL
41558BROWSER-IE Microsoft Edge Array out of bounds memory corruption attempt (more info ...)attempted-user  2017-0046      URL
41559BROWSER-IE Microsoft Edge Array out of bounds memory corruption attempt (more info ...)attempted-user  2017-0046      URL
41560BROWSER-IE Microsoft Edge Array out of bounds memory corruption attempt (more info ...)attempted-user  2017-0046      URL
41567OS-WINDOWS Microsoft Windows Device Guard code execution attempt (more info ...)attempted-user  2017-0007      URL
41568OS-WINDOWS Microsoft Windows Device Guard code execution attempt (more info ...)attempted-user  2017-0007      URL
41569OS-WINDOWS Microsoft Windows Device Guard code execution attempt (more info ...)attempted-user  2017-0007      URL
41570OS-WINDOWS Microsoft Windows Device Guard code execution attempt (more info ...)attempted-user  2017-0007      URL
41571OS-WINDOWS Microsoft Windows Device Guard code execution attempt (more info ...)attempted-user  2017-0007      URL
41572OS-WINDOWS Microsoft Windows Device Guard code execution attempt (more info ...)attempted-user  2017-0007      URL
41573BROWSER-IE Microsoft Edge CSS animation style information disclosure attempt (more info ...)attempted-recon  2017-0011      URL
41574BROWSER-IE Microsoft Edge CSS animation style information disclosure attempt (more info ...)attempted-recon  2017-0011      URL
41579OS-WINDOWS Microsoft Windows DirectComposition double free attempt (more info ...)attempted-admin  2017-0026      URL
41580OS-WINDOWS Microsoft Windows DirectComposition double free attempt (more info ...)attempted-admin  2017-0026      URL
41591OS-WINDOWS Microsoft Windows GDI privilege escalation attempt (more info ...)attempted-admin  2017-0047      URL
41592OS-WINDOWS Microsoft Windows GDI privilege escalation attempt (more info ...)attempted-admin  2017-0047      URL
41595OS-WINDOWS Microsoft Windows GDI invalid EMF cbBitsSrc memory disclosure attempt (more info ...)attempted-recon  2017-0038      URL
41596OS-WINDOWS Microsoft Windows GDI invalid EMF cbBitsSrc memory disclosure attempt (more info ...)attempted-recon  2017-0038      URL
41601FILE-PDF Microsoft Edge PDF Builder out of bounds read attempt (more info ...)attempted-user  2017-0023      URL
41602FILE-PDF Microsoft Edge PDF Builder out of bounds read attempt (more info ...)attempted-user  2017-0023      URL
41605BROWSER-IE Microsoft Edge AsmJs memory corruption attempt (more info ...)denial-of-service  2017-0035      URL
41606BROWSER-IE Microsoft Edge AsmJs memory corruption attempt (more info ...)denial-of-service  2017-0035      URL
41607OS-WINDOWS Microsoft Windows Kernel NtCreateProfile privilege escalation attempt (more info ...)attempted-user  2017-0050      URL
41608OS-WINDOWS Microsoft Windows Kernel NtCreateProfile privilege escalation attempt (more info ...)attempted-user  2017-0050      URL
41609OS-WINDOWS Microsoft Windows Kernel NtCreateProfile privilege escalation attempt (more info ...)attempted-user  2017-0050      URL
41610OS-WINDOWS Microsoft Windows Kernel NtCreateProfile privilege escalation attempt (more info ...)attempted-user  2017-0050      URL
41625BROWSER-IE Microsoft Edge HandleColumnBreakOnColumnSpanningElement type confusion attempt (more info ...)attempted-admin  2017-0037      URL
41626BROWSER-IE Microsoft Edge HandleColumnBreakOnColumnSpanningElement type confusion attempt (more info ...)attempted-admin  2017-0037      URL
41666BROWSER-PLUGINS KingScada kxClientDownload ActiveX clsid access attempt (more info ...)attempted-user  2013-2827      
41667BROWSER-PLUGINS KingScada kxClientDownload ActiveX clsid access attempt (more info ...)attempted-user  2013-2827      
41668BROWSER-PLUGINS KingScada kxClientDownload ActiveX clsid access attempt (more info ...)attempted-user  2013-2827      
41669BROWSER-PLUGINS KingScada kxClientDownload ActiveX clsid access attempt (more info ...)attempted-user  2013-2827      
41710INDICATOR-COMPROMISE Binary file download request from internationalized domain name using Microsoft BITS (more info ...)trojan-activity        
41763BROWSER-IE Microsoft Edge HandleColumnBreakOnColumnSpanningElement type confusion attempt (more info ...)attempted-admin  2017-0037      
41764BROWSER-IE Microsoft Edge HandleColumnBreakOnColumnSpanningElement type confusion attempt (more info ...)attempted-admin  2017-0037      
41803BROWSER-PLUGINS Elipse E3 ActiveReports ActiveX clsid access attempt (more info ...)attempted-user  2007-3982      
41804BROWSER-PLUGINS Elipse E3 ActiveReports ActiveX clsid access attempt (more info ...)attempted-user  2007-3982      
41805BROWSER-PLUGINS Elipse E3 ActiveReports ActiveX clsid access attempt (more info ...)attempted-user  2007-3982      
41806BROWSER-PLUGINS Elipse E3 ActiveReports ActiveX clsid access attempt (more info ...)attempted-user  2007-3982      
41839BROWSER-IE Microsoft Edge object mutation memory corruption attempt (more info ...)attempted-user  2016-0003      URL
41840BROWSER-IE Microsoft Edge object mutation memory corruption attempt (more info ...)attempted-user  2016-0003      URL
41846SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-admin  2016-0856  80745    URL
41847SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-admin  2016-0856  80745    URL
41848SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-admin  2016-0856  80745    URL
41849SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-admin  2016-0856  80745    URL
41882SERVER-OTHER Advantech WebAccess DCERPC heap buffer overflow attempt (more info ...)attempted-admin  2016-0857  80745    URL
41926OS-WINDOWS Microsoft Win32u NtUserThunkedMenuItemInfo use after free attempt (more info ...)attempted-admin  2017-0056      URL
41927OS-WINDOWS Microsoft Win32u NtUserThunkedMenuItemInfo use after free attempt (more info ...)attempted-admin  2017-0056      URL
41928OS-WINDOWS Microsoft Win32k DDI use after free attempt (more info ...)attempted-admin  2017-0079      URL
41929OS-WINDOWS Microsoft Win32k DDI use after free attempt (more info ...)attempted-admin  2017-0079      URL
41930OS-WINDOWS Microsoft Win32k DDI use after free attempt (more info ...)attempted-admin  2017-0082      URL
41931OS-WINDOWS Microsoft Win32k DDI use after free attempt (more info ...)attempted-admin  2017-0082      URL
41932FILE-OTHER Microsoft Windows Uniscribe privilege escalation attempt (more info ...)attempted-admin  2017-0108      URL
41933FILE-OTHER Microsoft Windows Uniscribe privilege escalation attempt (more info ...)attempted-admin  2017-0108      URL
41934FILE-OTHER Microsoft Windows Uniscribe privilege escalation attempt (more info ...)attempted-admin  2017-0086      URL
41935FILE-OTHER Microsoft Windows Uniscribe privilege escalation attempt (more info ...)attempted-admin  2017-0086      URL
41936BROWSER-IE Microsoft Edge TypedArray setter arbitrary write attempt (more info ...)attempted-user  2017-0071      URL
41937BROWSER-IE Microsoft Edge TypedArray setter arbitrary write attempt (more info ...)attempted-user  2017-0071      URL
41938BROWSER-IE Microsoft Edge reverse helper heap buffer overflow attempt (more info ...)attempted-user  2017-0141      URL
41939BROWSER-IE Microsoft Edge reverse helper heap buffer overflow attempt (more info ...)attempted-user  2017-0141      URL
41940OS-WINDOWS Microsoft Windows TrueTypeFont post table out of bounds write attempt (more info ...)attempted-user  2017-0088      URL
41941OS-WINDOWS Microsoft Windows TrueTypeFont post table out of bounds write attempt (more info ...)attempted-user  2017-0088      URL
41942BROWSER-IE Microsoft Edge EntrySimpleSlotGetter use after free attempt (more info ...)attempted-user  2017-0070      URL
41943BROWSER-IE Microsoft Edge EntrySimpleSlotGetter use after free attempt (more info ...)attempted-user  2017-0070      URL
41944BROWSER-IE Microsoft Edge scripting engine security bypass css attempt (more info ...)attempted-user  2017-0066      URL
41945BROWSER-IE Microsoft Edge scripting engine security bypass css attempt (more info ...)attempted-user  2017-0066      URL
41950BROWSER-IE Microsoft Edge WebAssembly memory corruption attempt (more info ...)attempted-user  2017-0133      URL
41951BROWSER-IE Microsoft Edge WebAssembly memory corruption attempt (more info ...)attempted-user  2017-0133      URL
41952BROWSER-IE Microsoft Edge local file read information leak attempt (more info ...)attempted-user  2017-0065      URL
41953BROWSER-IE Microsoft Edge local file read information leak attempt (more info ...)attempted-user  2017-0065      URL
41958BROWSER-IE Microsoft Edge malformed UTF-8 decode arbitrary read attempt (more info ...)attempted-user  2017-0131      URL
41959BROWSER-IE Microsoft Edge malformed UTF-8 decode arbitrary read attempt (more info ...)attempted-user  2017-0131      URL
41960OS-WINDOWS Microsoft Windows TrueType Font LookupTable out of bounds write attempt (more info ...)attempted-user  2017-0089      URL
41961OS-WINDOWS Microsoft Windows TrueType Font LookupTable out of bounds write attempt (more info ...)attempted-user  2017-0089      URL
41966OS-WINDOWS Microsoft Windows TrueTypeFont GSUB table out of bounds write attempt (more info ...)attempted-user  2017-0087      URL
41967OS-WINDOWS Microsoft Windows TrueTypeFont GSUB table out of bounds write attempt (more info ...)attempted-user  2017-0087      URL
41972OS-WINDOWS Microsoft Windows TrueType Font out of bounds write attempt (more info ...)attempted-user  2017-0072      URL
41973OS-WINDOWS Microsoft Windows TrueType Font out of bounds write attempt (more info ...)attempted-user  2017-0072      URL
41974OS-WINDOWS Microsoft Windows TrueType Font out of bounds write attempt (more info ...)attempted-user  2017-0090      URL
41975OS-WINDOWS Microsoft Windows TrueType Font out of bounds write attempt (more info ...)attempted-user  2017-0090      URL
41978OS-WINDOWS Microsoft Windows SMB remote code execution attempt (more info ...)attempted-admin  2017-0146      URL
41984OS-WINDOWS Microsoft Windows SMBv1 identical MID and FID type confusion attempt (more info ...)attempted-admin  2017-0143      URL
41985OS-WINDOWS Microsoft Windows TrueTypeFont post table out of bounds write attempt (more info ...)attempted-user  2017-0121      URL
41986OS-WINDOWS Microsoft Windows TrueTypeFont post table out of bounds write attempt (more info ...)attempted-user  2017-0121      URL
41991FILE-OTHER Microsoft Windows TTF file out of bounds access attempt (more info ...)attempted-admin  2017-0083      URL
41992FILE-OTHER Microsoft Windows TTF file out of bounds access attempt (more info ...)attempted-admin  2017-0083      URL
41994OS-WINDOWS Microsoft Windows GDI WMF out of bounds read attempt (more info ...)attempted-user  2017-0073      URL
41995OS-WINDOWS Microsoft Windows DDI privilege escalation attempt (more info ...)attempted-admin  2017-0080      URL
41996OS-WINDOWS Microsoft Windows DDI privilege escalation attempt (more info ...)attempted-admin  2017-0080      URL
41998OS-WINDOWS Microsoft GDI+ privilege escalation attempt (more info ...)attempted-admin  2017-0188      URL
42041BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user  2018-4438      URL
42122BROWSER-PLUGINS Invensys Wonderware Archestra ActiveX clsid access attempt (more info ...)attempted-user  2010-2974      
42123BROWSER-PLUGINS Invensys Wonderware Archestra ActiveX clsid access attempt (more info ...)attempted-user  2010-2974      
42124BROWSER-PLUGINS Invensys Wonderware Archestra ActiveX clsid access attempt (more info ...)attempted-user  2010-2974      
42125BROWSER-PLUGINS Invensys Wonderware Archestra ActiveX clsid access attempt (more info ...)attempted-user  2010-2974      
42148FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file out-of-bounds memory access attempt (more info ...)attempted-user  2017-0192      
42149FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file out-of-bounds memory access attempt (more info ...)attempted-user  2017-0192      
42150FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file out-of-bounds memory access attempt (more info ...)attempted-user  2017-0192      
42151FILE-OTHER Microsoft Windows ATMFD font driver malformed OTF file out-of-bounds memory access attempt (more info ...)attempted-user  2017-0192      
42154OS-WINDOWS Microsoft Windows win32k information disclosure attempt (more info ...)attempted-admin  2017-0167      
42155OS-WINDOWS Microsoft Windows win32k information disclosure attempt (more info ...)attempted-admin  2017-0167      
42158OS-WINDOWS Microsoft Win32k privilege escalation attempt (more info ...)attempted-admin  2017-0189      
42159OS-WINDOWS Microsoft Win32k privilege escalation attempt (more info ...)attempted-admin  2017-0189      
42160SERVER-OTHER Microsoft LDAP MaxBuffSize buffer overflow attempt (more info ...)attempted-user  2017-0166      
42173OS-WINDOWS Microsoft GDI PolyTextOutW out of bounds memory write attempt (more info ...)attempted-user  2017-0155      
42174OS-WINDOWS Microsoft GDI PolyTextOutW out of bounds memory write attempt (more info ...)attempted-user  2017-0155      
42183BROWSER-IE Microsoft Edge format rendering type confusion attempt (more info ...)attempted-user  2017-0205      
42184BROWSER-IE Microsoft Edge format rendering type confusion attempt (more info ...)attempted-user  2017-0205      
42185OS-WINDOWS Microsoft Windows WMI DCOM arbitrary .NET serialization code execution attempt (more info ...)attempted-user  2017-0160      URL
42186OS-WINDOWS Microsoft Windows WMI DCOM arbitrary .NET serialization code execution attempt (more info ...)attempted-user  2017-0160      URL
42187OS-WINDOWS Microsoft Windows IE ETW Collector Service privilege escalation attempt (more info ...)attempted-user  2017-0165      
42188OS-WINDOWS Microsoft Windows IE ETW Collector Service privilege escalation attempt (more info ...)attempted-user  2017-0165      
42199OS-WINDOWS Microsoft Windows GDI null pointer dereference attempt (more info ...)attempted-admin  2017-0156      
42200OS-WINDOWS Microsoft Windows GDI null pointer dereference attempt (more info ...)attempted-admin  2017-0156      
42208OS-WINDOWS Microsoft Windows Clipboard Broker privilege escalation vulnerability attempt (more info ...)attempted-user  2017-0211      
42209OS-WINDOWS Microsoft Windows Clipboard Broker privilege escalation vulnerability attempt (more info ...)attempted-user  2017-0211      
42210BROWSER-IE Microsoft Edge xlink type confusion memory corruption attempt (more info ...)attempted-user  2017-0200      
42211BROWSER-IE Microsoft Edge xlink type confusion memory corruption attempt (more info ...)attempted-user  2017-0200      
42226OS-SOLARIS Solaris RPC XDR overflow code execution attempt (more info ...)attempted-admin  2017-3623      URL
42255OS-WINDOWS Microsoft Windows empty RDP cookie negotiation attempt (more info ...)policy-violation  2017-9073      URL
42294OS-WINDOWS Microsoft Windows SMBv1 WriteAndX and TransSecondaryRequest TotalDataCount out of bounds write attempt (more info ...)attempted-admin  2017-0145      URL
42338OS-WINDOWS Microsoft Windows SMB large NT RENAME transaction request memory leak attempt (more info ...)attempted-recon        URL
42339OS-WINDOWS Microsoft Windows SMB possible leak of kernel heap memory (more info ...)attempted-recon  2017-0147      URL
42443OS-WINDOWS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user  2005-0944  12960    
42749BROWSER-IE Microsoft Edge scripting engine postMessage use after free attempt (more info ...)attempted-user  2021-34448      URL
42750BROWSER-IE Microsoft Edge scripting engine postMessage use after free attempt (more info ...)attempted-user  2021-34448      URL
42751OS-WINDOWS Microsoft Windows AFD.sys double fetch race condition attempt (more info ...)attempted-admin  2017-0220      
42752OS-WINDOWS Microsoft Windows AFD.sys double fetch race condition attempt (more info ...)attempted-admin  2017-0220      
42753BROWSER-IE Microsoft Edge Chakra Core type confusion attempt (more info ...)attempted-user  2017-8605      
42754BROWSER-IE Microsoft Edge Chakra Core type confusion attempt (more info ...)attempted-user  2017-8605      
42757OS-WINDOWS Microsoft Windows dxgkrnl CreateDriverAllocations null pointer dereference attempt (more info ...)attempted-admin  2017-0077      
42758OS-WINDOWS Microsoft Windows dxgkrnl CreateDriverAllocations null pointer dereference attempt (more info ...)attempted-admin  2017-0077      
42759OS-WINDOWS Microsoft Windows COM privilege escalation attempt (more info ...)attempted-admin  2017-0214      
42760OS-WINDOWS Microsoft Windows COM privilege escalation attempt (more info ...)attempted-admin  2017-0214      
42761BROWSER-IE Microsoft Edge Chakra array unshift heap overflow attempt (more info ...)attempted-user  2017-0238      
42762BROWSER-IE Microsoft Edge Chakra array unshift heap overflow attempt (more info ...)attempted-user  2017-0238      
42763OS-WINDOWS Microsoft Windows NtTraceControl information disclosure attempt (more info ...)attempted-recon  2017-0259      
42764OS-WINDOWS Microsoft Windows NtTraceControl information disclosure attempt (more info ...)attempted-recon  2017-0259      
42765OS-WINDOWS Microsoft win32k privilege escalation attempt (more info ...)attempted-admin  2017-0263      
42766OS-WINDOWS Microsoft win32k privilege escalation attempt (more info ...)attempted-admin  2017-0263      
42767OS-WINDOWS Microsoft Windows DeviceIoControl double fetch race condition attempt (more info ...)attempted-admin        URL
42768OS-WINDOWS Microsoft Windows DeviceIoControl double fetch race condition attempt (more info ...)attempted-admin        URL
42769OS-WINDOWS Microsoft Win32k kernel memory leak attempt (more info ...)attempted-user  2017-0245      
42770OS-WINDOWS Microsoft Win32k kernel memory leak attempt (more info ...)attempted-user  2017-0245      
42771OS-WINDOWS Microsoft Windows GdiGradientFill null pointer dereference attempt (more info ...)attempted-admin  2017-0246      
42772OS-WINDOWS Microsoft Windows GdiGradientFill null pointer dereference attempt (more info ...)attempted-admin  2017-0246      
42775BROWSER-IE Microsoft Edge Chakra JIT memory corruption attempt (more info ...)attempted-user  2017-0234      
42776BROWSER-IE Microsoft Edge Chakra JIT memory corruption attempt (more info ...)attempted-user  2017-0234      
42777BROWSER-IE Microsoft Edge scripting engine security bypass css attempt (more info ...)attempted-user  2017-0064      URL
42778BROWSER-IE Microsoft Edge scripting engine security bypass css attempt (more info ...)attempted-user  2017-0064      URL
42779BROWSER-IE Microsoft Edge CSS writing mode type confusion attempt (more info ...)attempted-user  2017-0227      
42780BROWSER-IE Microsoft Edge CSS writing mode type confusion attempt (more info ...)attempted-user  2017-0227      
42781BROWSER-IE Microsoft Windows Edge AudioContext use after free attempt (more info ...)attempted-user  2017-0240      
42782BROWSER-IE Microsoft Windows Edge AudioContext use after free attempt (more info ...)attempted-user  2017-0240      
42783OS-WINDOWS Microsoft Windows ntoskrnl information disclosure attempt (more info ...)attempted-admin  2017-0258      
42784OS-WINDOWS Microsoft Windows ntoskrnl information disclosure attempt (more info ...)attempted-admin  2017-0258      
42798BROWSER-IE Microsoft Edge out of bounds read attempt (more info ...)attempted-admin  2017-0221      
42799BROWSER-IE Microsoft Edge out of bounds read attempt (more info ...)attempted-admin  2017-0221      
42811BROWSER-IE Microsoft Edge Chakra Engine use-after-free attempt (more info ...)attempted-user  2017-0228      
42812BROWSER-IE Microsoft Edge Chakra Engine use-after-free attempt (more info ...)attempted-user  2017-0228      
42820OS-WINDOWS Microsoft Malware Protection Engine type confusion attempt (more info ...)attempted-admin  2017-0290      URL
42821OS-WINDOWS Microsoft Malware Protection Engine type confusion attempt (more info ...)attempted-admin  2017-0290      URL
42855BROWSER-PLUGINS Schneider SoMachine ActiveX clsid access attempt (more info ...)attempted-user  2016-4529      
42856BROWSER-PLUGINS Schneider SoMachine ActiveX clsid access attempt (more info ...)attempted-user  2016-4529      
42906BROWSER-PLUGINS IBM SPSS SamplePower ActiveX clsid access attempt (more info ...)attempted-user        URL
42907BROWSER-PLUGINS IBM SPSS SamplePower ActiveX clsid access attempt (more info ...)attempted-user        URL
42908BROWSER-PLUGINS IBM SPSS SamplePower ActiveX clsid access attempt (more info ...)attempted-user        URL
42909BROWSER-PLUGINS IBM SPSS SamplePower ActiveX clsid access attempt (more info ...)attempted-user        URL
42944OS-WINDOWS Microsoft Windows SMB remote code execution attempt (more info ...)attempted-admin  2017-0146      URL
43002PROTOCOL-OTHER NETBIOS SMB IPC share access attempt (more info ...)misc-activity        URL
43003PROTOCOL-OTHER NETBIOS SMB IPC share access attempt (more info ...)misc-activity        URL
43114FILE-OTHER Microsoft Windows OTF parsing memory corruption attempt (more info ...)attempted-admin  2016-7256      URL
43115FILE-OTHER Microsoft Windows OTF parsing memory corruption attempt (more info ...)attempted-admin  2016-7256      URL
43157OS-WINDOWS Microsoft Windows Device Guard code execution attempt (more info ...)attempted-user  2017-0215      
43158OS-WINDOWS Microsoft Windows Device Guard code execution attempt (more info ...)attempted-user  2017-0215      
43163BROWSER-IE Microsoft Edge object property type confusion attempt (more info ...)attempted-user  2017-8524      
43164BROWSER-IE Microsoft Edge object property type confusion attempt (more info ...)attempted-user  2017-8524      
43165BROWSER-IE Microsoft Edge cssText use after free attempt (more info ...)attempted-user  2017-8496      
43166BROWSER-IE Microsoft Edge cssText use after free attempt (more info ...)attempted-user  2017-8496      
43170BROWSER-IE Microsoft Edge textContent use after free attempt (more info ...)attempted-user  2017-8497      
43173OS-WINDOWS Microsoft Windows 10 RS2 x64 linked cursor double free attempt (more info ...)attempted-user  2017-8468      
43174OS-WINDOWS Microsoft Windows 10 RS2 x64 linked cursor double free attempt (more info ...)attempted-user  2017-8468      
43175OS-WINDOWS Microsoft Windows Search Service out of bounds memory access attempt (more info ...)attempted-admin  2017-8543      
43176OS-WINDOWS Microsoft Windows Search Service out of bounds memory access attempt (more info ...)attempted-admin  2017-8543      
43188PROTOCOL-RPC Linux kernel NFSv2 malformed WRITE arbitrary memory read attempt (more info ...)attempted-user  2017-7895      
43189PROTOCOL-RPC Linux kernel NFSv3 malformed WRITE arbitrary memory read attempt (more info ...)attempted-user  2017-7895      
43312BROWSER-PLUGINS MagnetoSoft NetworkResources ActiveX clsid access attempt (more info ...)attempted-user        URL
43313BROWSER-PLUGINS MagnetoSoft NetworkResources ActiveX clsid access attempt (more info ...)attempted-user        URL
43314BROWSER-PLUGINS MagnetoSoft SNTP ActiveX clsid access attempt (more info ...)attempted-user        URL
43315BROWSER-PLUGINS MagnetoSoft SNTP ActiveX clsid access attempt (more info ...)attempted-user        URL
43320BROWSER-PLUGINS MagnetoSoft NetworkResources ActiveX clsid access attempt (more info ...)attempted-user        URL
43321BROWSER-PLUGINS MagnetoSoft NetworkResources ActiveX clsid access attempt (more info ...)attempted-user        URL
43322BROWSER-PLUGINS MagnetoSoft SNTP ActiveX clsid access attempt (more info ...)attempted-user        URL
43323BROWSER-PLUGINS MagnetoSoft SNTP ActiveX clsid access attempt (more info ...)attempted-user        URL
43380OS-WINDOWS Microsoft Windows MsMpEng custom apicall instruction use detected (more info ...)attempted-admin  2017-8558      
43381OS-WINDOWS Microsoft Windows MsMpEng custom apicall instruction use detected (more info ...)attempted-admin  2017-8558      
43460BROWSER-IE Microsoft Edge use-after-free attempt (more info ...)attempted-user  2017-8617      
43461BROWSER-IE Microsoft Edge use-after-free attempt (more info ...)attempted-user  2017-8617      
43462BROWSER-IE Microsoft Edge use-after-free attempt (more info ...)attempted-user  2017-8617      
43463BROWSER-IE Microsoft Edge use-after-free attempt (more info ...)attempted-user  2017-8617      
43465BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-admin  2017-8601      
43466BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-admin  2017-8601      
43469BROWSER-IE Microsoft Edge uninitialized memory attempt (more info ...)attempted-user  2017-8598      
43470BROWSER-IE Microsoft Edge uninitialized memory attempt (more info ...)attempted-user  2017-8598      
43471BROWSER-IE Microsoft Edge VBScript VarType out of bounds read attempt (more info ...)attempted-user  2017-8618      
43472BROWSER-IE Microsoft Edge VBScript VarType out of bounds read attempt (more info ...)attempted-user  2017-8618      
43473OS-WINDOWS Microsoft win32u PlgBlt out of bounds memory write attempt (more info ...)attempted-admin  2017-8578      
43474OS-WINDOWS Microsoft win32u PlgBlt out of bounds memory write attempt (more info ...)attempted-admin  2017-8578      
43490OS-WINDOWS Microsoft Windows unsafe memory access privilege escalation attempt (more info ...)attempted-admin  2017-8577      
43491OS-WINDOWS Microsoft Windows unsafe memory access privilege escalation attempt (more info ...)attempted-admin  2017-8577      
43492BROWSER-IE Microsoft Windows Edge array out of bounds write (more info ...)attempted-user  2017-8619      
43493BROWSER-IE Microsoft Windows Edge array out of bounds write (more info ...)attempted-user  2017-8619      
43851FILE-OTHER Microsoft Windows Device Guard bypass via compiled help file attempt (more info ...)attempted-user  2017-8625      
43852FILE-OTHER Microsoft Windows Device Guard bypass via compiled help file attempt (more info ...)attempted-user  2017-8625      
44331BROWSER-IE Microsoft Windows Edge memory corruption attempt (more info ...)attempted-user  2018-15991      
44332BROWSER-IE Microsoft Windows Edge memory corruption attempt (more info ...)attempted-user  2018-15991      
44333BROWSER-IE Microsoft Edge Chakra Core type confusion attempt (more info ...)attempted-user  2017-8738      
44334BROWSER-IE Microsoft Edge Chakra Core type confusion attempt (more info ...)attempted-user  2017-8738      
44335OS-WINDOWS Microsoft Windows Win32k.sys TrueType font out of bounds write attempt (more info ...)attempted-admin  2017-8682      
44336OS-WINDOWS Microsoft Windows Win32k.sys TrueType font out of bounds write attempt (more info ...)attempted-admin  2017-8682      
44338BROWSER-IE Microsoft Edge denial of service attempt (more info ...)attempted-dos  2017-8757      URL
44339BROWSER-IE Microsoft Edge denial of service attempt (more info ...)attempted-dos  2017-8757      URL
44340BROWSER-IE Microsoft Edge setSelectionRange memory corruption attempt (more info ...)attempted-user  2017-8734      URL
44341BROWSER-IE Microsoft Edge setSelectionRange memory corruption attempt (more info ...)attempted-user  2017-8734      URL
44514OS-WINDOWS Microsoft Windows Win32kfull.sys privilege escalation attempt (more info ...)attempted-admin  2017-8694      URL
44515OS-WINDOWS Microsoft Windows Win32kfull.sys privilege escalation attempt (more info ...)attempted-admin  2017-8694      URL
44516OS-WINDOWS Microsoft Windows CreateMenu use after free attempt (more info ...)attempted-admin  2017-8689      URL
44517OS-WINDOWS Microsoft Windows CreateMenu use after free attempt (more info ...)attempted-admin  2017-8689      URL
44528FILE-OTHER Microsoft Graphics remote code execution attempt (more info ...)attempted-admin  2017-11763      URL
44529FILE-OTHER Microsoft Graphics remote code execution attempt (more info ...)attempted-admin  2017-11763      URL
44532BROWSER-IE Microsoft Edge getOwnPropertyDescriptor memory corruption attempt (more info ...)attempted-user  2017-11798      URL
44533BROWSER-IE Microsoft Edge getOwnPropertyDescriptor memory corruption attempt (more info ...)attempted-user  2017-11798      URL
44637PROTOCOL-RPC Linux kernel nfsd nfsd4_layout_verify out of bounds read attempt (more info ...)attempted-dos  2017-8797  99298    URL
44638PROTOCOL-RPC Linux kernel nfsd nfsd4_layout_verify out of bounds read attempt (more info ...)attempted-dos  2017-8797  99298    URL
44696SERVER-OTHER Advantech WebAccess MSRPC server integer overflow attempt (more info ...)attempted-user  2016-0859  80745    URL
44809BROWSER-IE Microsoft Edge postMessage use after free attempt (more info ...)attempted-user  2017-11837      URL
44810BROWSER-IE Microsoft Edge postMessage use after free attempt (more info ...)attempted-user  2017-11837      URL
44811BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2017-11840      URL
44812BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2017-11840      URL
44813BROWSER-IE Microsoft Edge Chakra scripting engine memory corruption attempt (more info ...)attempted-user  2019-1023      URL
44814BROWSER-IE Microsoft Edge Chakra scripting engine memory corruption attempt (more info ...)attempted-user  2019-1023      URL
44815BROWSER-IE Microsoft Edge use after free attempt (more info ...)attempted-admin  2017-11843      
44816BROWSER-IE Microsoft Edge use after free attempt (more info ...)attempted-admin  2017-11843      
44817BROWSER-IE Microsoft Edge custom property memory corruption attempt (more info ...)attempted-user  2017-11845      URL
44818BROWSER-IE Microsoft Edge custom property memory corruption attempt (more info ...)attempted-user  2017-11845      URL
44819BROWSER-IE Microsoft Edge array use after free attempt (more info ...)attempted-user  2017-11791      
44820BROWSER-IE Microsoft Edge array use after free attempt (more info ...)attempted-user  2017-11791      
44827BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-admin  2017-11858      
44828BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-admin  2017-11858      
44831BROWSER-IE Microsoft Edge memory corruption exploitation attempt (more info ...)attempted-admin  2017-11855      
44832BROWSER-IE Microsoft Edge memory corruption exploitation attempt (more info ...)attempted-admin  2017-11855      
44833OS-WINDOWS Microsoft Windows win32k.sys use after free attempt (more info ...)attempted-user  2017-11847      URL
44834OS-WINDOWS Microsoft Windows win32k.sys use after free attempt (more info ...)attempted-user  2017-11847      URL
44845BROWSER-IE Microsoft Edge heap overflow attempt (more info ...)attempted-user  2017-11846      URL
44846BROWSER-IE Microsoft Edge heap overflow attempt (more info ...)attempted-user  2017-11846      URL
45128BROWSER-IE Microsoft Edge defineGetter type confusion attempt (more info ...)attempted-user  2017-11914      URL
45129BROWSER-IE Microsoft Edge defineGetter type confusion attempt (more info ...)attempted-user  2017-11914      URL
45130OS-WINDOWS Microsoft Windows RRAS service arbitrary pointer dereference attempt (more info ...)attempted-user  2017-11885      URL
45131OS-WINDOWS Microsoft Windows RRAS service arbitrary pointer dereference attempt (more info ...)attempted-user  2017-11885      URL
45140BROWSER-IE Microsoft Edge Chakra RegExp engine memory corruption attempt (more info ...)attempted-user  2017-11894      URL
45141BROWSER-IE Microsoft Edge Chakra RegExp engine memory corruption attempt (more info ...)attempted-user  2017-11894      URL
45143BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2019-1195      
45150BROWSER-IE Microsoft Edge JsSetCurrentContext out of bounds read attempt (more info ...)attempted-user  2017-11909      URL
45151BROWSER-IE Microsoft Edge JsSetCurrentContext out of bounds read attempt (more info ...)attempted-user  2017-11909      URL
45160BROWSER-IE Microsoft Edge null pointer dereference attempt (more info ...)attempted-user  2017-11918      URL
45161BROWSER-IE Microsoft Edge null pointer dereference attempt (more info ...)attempted-user  2017-11918      URL
45162BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2017-11893      URL
45163BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2017-11893      URL
45167BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-admin  2017-11930      
45168BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-admin  2017-11930      
45169BROWSER-IE Microsoft Edge array type confusion attempt (more info ...)attempted-user  2017-11916      URL
45170BROWSER-IE Microsoft Edge array type confusion attempt (more info ...)attempted-user  2017-11916      URL
45198SERVER-OTHER Advantech WebAccess dcerpc service opcode 80061 stack buffer overflow attempt (more info ...)attempted-admin  2017-14016  101685    URL
45270BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45271BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45272BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45273BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45274BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45275BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45276BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45277BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45278BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45279BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45280BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45281BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45282BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45283BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45284BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45285BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45286BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45287BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45288BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45289BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45290BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45291BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45292BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45293BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45294BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45295BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45296BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45297BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45298BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45299BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45300BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45301BROWSER-PLUGINS UCanCode ActiveX clsid access attempt (more info ...)attempted-user        URL
45374BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-admin  2018-0777      URL
45375BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-admin  2018-0777      URL
45376BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0769      URL
45377BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0769      URL
45378BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2018-0933      URL
45379BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2018-0933      URL
45383BROWSER-IE Microsoft Edge scripting engine integer overflow attempt (more info ...)attempted-user  2018-0758      URL
45384BROWSER-IE Microsoft Edge scripting engine integer overflow attempt (more info ...)attempted-user  2018-0758      URL
45387BROWSER-IE Microsoft Edge anonymous function type confusion attempt (more info ...)attempted-user  2018-0774      URL
45388BROWSER-IE Microsoft Edge anonymous function type confusion attempt (more info ...)attempted-user  2018-0774      URL
45389BROWSER-IE Microsoft IE array type confusion attempt (more info ...)attempted-user  2018-0762      URL
45390BROWSER-IE Microsoft IE array type confusion attempt (more info ...)attempted-user  2018-0762      URL
45391BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2018-0775      URL
45392BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2018-0775      URL
45395BROWSER-IE Microsoft Edge scripting engine toString use after free attempt (more info ...)attempted-user  2018-0773      URL
45396BROWSER-IE Microsoft Edge scripting engine toString use after free attempt (more info ...)attempted-user  2018-0773      URL
45445BROWSER-IE Microsoft Edge scripting engine ArrayBuffer memory corruption attempt (more info ...)attempted-user  2017-11812      URL
45446BROWSER-IE Microsoft Edge scripting engine ArrayBuffer memory corruption attempt (more info ...)attempted-user  2017-11812      URL
45508BROWSER-IE Microsoft Edge Scripting Engine array memory corruption attempt (more info ...)attempted-user  2017-11811      URL
45509BROWSER-IE Microsoft Edge Scripting Engine array memory corruption attempt (more info ...)attempted-user  2017-11811      URL
45516BROWSER-IE Microsoft Edge Scripting Engine array memory corruption attempt (more info ...)attempted-user  2017-11802      URL
45517BROWSER-IE Microsoft Edge Scripting Engine array memory corruption attempt (more info ...)attempted-user  2017-11802      URL
45554FILE-MULTIMEDIA Microsoft Windows Movie Maker project file heap buffer overflow attempt (more info ...)attempted-user  2010-0265      URL
45624OS-WINDOWS Microsoft Windows malformed shortcut file with comment buffer overflow attempt (more info ...)attempted-user  2018-0825      URL
45625OS-WINDOWS Microsoft Windows malformed shortcut file with comment buffer overflow attempt (more info ...)attempted-user  2018-0825      URL
45626BROWSER-IE Microsoft Edge Scripting Engine memory corruption attempt (more info ...)attempted-user  2018-0834      URL
45627BROWSER-IE Microsoft Edge Scripting Engine memory corruption attempt (more info ...)attempted-user  2018-0834      URL
45628BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-8466      
45629BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-8466      
45632OS-WINDOWS Microsoft Windows use after free win32kbase.sys privilege escalation attempt (more info ...)attempted-admin  2019-0814      URL
45633OS-WINDOWS Microsoft Windows use after free win32kbase.sys privilege escalation attempt (more info ...)attempted-admin  2018-0756      URL
45634OS-WINDOWS Microsoft Windows use after free win32kbase.sys privilege escalation attempt (more info ...)attempted-admin  2018-0756      URL
45635OS-WINDOWS Microsoft Windows use after free win32kbase.sys privilege escalation attempt (more info ...)attempted-admin  2019-0814      URL
45636BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2018-0860      URL
45637BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2018-0860      URL
45649OS-WINDOWS Microsoft Windows win32k.sys privilege escalation attempt (more info ...)attempted-user  2018-0742      URL
45650OS-WINDOWS Microsoft Windows win32k.sys privilege escalation attempt (more info ...)attempted-user  2018-0742      URL
45656OS-WINDOWS Microsoft Windows HIDPARSE.sys memory corruption attempt (more info ...)attempted-user  2018-0842      URL
45657OS-WINDOWS Microsoft Windows HIDPARSE.sys memory corruption attempt (more info ...)attempted-user  2018-0842      URL
45659BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-admin  2018-0858      URL
45660BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-admin  2018-0858      URL
45807OS-WINDOWS Microsoft Windows GetThreadContext kernel memory leak attempt (more info ...)attempted-recon  2018-0832      URL
45808OS-WINDOWS Microsoft Windows GetThreadContext kernel memory leak attempt (more info ...)attempted-recon  2018-0832      URL
45854OS-WINDOWS Microsoft Windows SMBv3 null pointer dereference attempt (more info ...)denial-of-service  2018-0833      URL
45873OS-WINDOWS Microsoft Windows SetProcessDeviceMap arbitrary file read attempt (more info ...)attempted-admin  2018-0877      URL
45874OS-WINDOWS Microsoft Windows SetProcessDeviceMap arbitrary file read attempt (more info ...)attempted-admin  2018-0877      URL
45875BROWSER-IE Microsoft Edge uninitialized memory use attempt (more info ...)attempted-user  2018-0874      URL
45876BROWSER-IE Microsoft Edge uninitialized memory use attempt (more info ...)attempted-user  2018-0874      URL
45881OS-WINDOWS Microsoft Windows 10 gdi32 library integer overflow attempt (more info ...)attempted-admin  2018-0817      URL
45882OS-WINDOWS Microsoft Windows 10 gdi32 library integer overflow attempt (more info ...)attempted-admin  2018-0817      URL
45889BROWSER-IE Microsoft Edge Chakra Core type confusion attempt (more info ...)attempted-user  2018-0930      URL
45890BROWSER-IE Microsoft Edge Chakra Core type confusion attempt (more info ...)attempted-user  2018-0930      URL
45898BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0893      
45899BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0893      
45900OS-WINDOWS Microsoft Windows Desktop Bridge privilege escalation attempt (more info ...)attempted-admin  2018-0882      URL
45901OS-WINDOWS Microsoft Windows Desktop Bridge privilege escalation attempt (more info ...)attempted-admin  2018-0882      URL
45902OS-WINDOWS Microsoft Windows Desktop Bridge privilege escalation attempt (more info ...)attempted-admin  2018-0880      URL
45903OS-WINDOWS Microsoft Windows Desktop Bridge privilege escalation attempt (more info ...)attempted-admin  2018-0880      URL
45977OS-WINDOWS Microsoft Windows SMB kernel heap memory leak attempt (more info ...)attempted-recon  2017-0147      URL
45978OS-WINDOWS Microsoft Windows SMB kernel heap memory leak attempt (more info ...)attempted-recon  2017-0147      URL
46055FILE-OTHER Microsoft wimgapi LoadIntegrityInfo heap buffer overflow attempt (more info ...)attempted-user  2018-8210      URL
46056FILE-OTHER Microsoft wimgapi LoadIntegrityInfo heap buffer overflow attempt (more info ...)attempted-user  2018-8210      URL
46058FILE-OTHER Microsoft wimgapi LoadIntegrityInfo heap buffer overflow attempt (more info ...)attempted-user  2018-8210      URL
46059FILE-OTHER Microsoft wimgapi LoadIntegrityInfo heap buffer overflow attempt (more info ...)attempted-user  2018-8210      URL
46061SERVER-OTHER Advantech WebAccess webvrpcs service arbitrary pointer dereference attempt (more info ...)attempted-admin  2017-16728  102424    URL
46076NETBIOS MikroTik RouterOS buffer overflow attempt (more info ...)attempted-user  2018-7445  103427    
46163FILE-OTHER Microsoft Windows Defender malformed RAR memory corruption attempt (more info ...)attempted-user  2018-0986      URL
46164FILE-OTHER Microsoft Windows Defender malformed RAR memory corruption attempt (more info ...)attempted-user  2018-0986      URL
46176BROWSER-IE Microsoft Edge Chakra use after free attempt (more info ...)attempted-admin  2018-0995      URL
46177BROWSER-IE Microsoft Edge Chakra use after free attempt (more info ...)attempted-admin  2018-0995      URL
46188FILE-OTHER Microsoft Windows malformed TTF integer overflow attempt (more info ...)attempted-admin  2018-1013      URL
46189FILE-OTHER Microsoft Windows malformed TTF integer overflow attempt (more info ...)attempted-admin  2018-1013      URL
46194BROWSER-IE Microsoft Edge Chakra use after free attempt (more info ...)attempted-user  2018-0990      URL
46195BROWSER-IE Microsoft Edge Chakra use after free attempt (more info ...)attempted-user  2018-0990      URL
46200OS-WINDOWS Microsoft Windows TrueType font heap overflow attempt (more info ...)attempted-user  2018-1010      URL
46201OS-WINDOWS Microsoft Windows TrueType font heap overflow attempt (more info ...)attempted-user  2018-1010      URL
46206BROWSER-IE Microsoft Windows Edge use-after-free attempt (more info ...)attempted-user  2018-0991      URL
46207BROWSER-IE Microsoft Windows Edge use-after-free attempt (more info ...)attempted-user  2018-0991      URL
46212BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0993      URL
46213BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0993      URL
46214OS-WINDOWS Microsoft Windows TrueType font heap overflow attempt (more info ...)attempted-user  2018-1015      URL
46215OS-WINDOWS Microsoft Windows TrueType font heap overflow attempt (more info ...)attempted-user  2018-1015      URL
46218BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-admin  2018-0996      URL
46219BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-admin  2018-0996      URL
46226FILE-PDF Microsoft Edge pdf parsing information disclosure attempt (more info ...)attempted-recon  2018-0998      URL
46227FILE-PDF Microsoft Edge pdf parsing information disclosure attempt (more info ...)attempted-recon  2018-0998      URL
46230OS-WINDOWS Microsoft Windows malformed TTF integer overflow attempt (more info ...)attempted-admin  2018-1012      URL
46231OS-WINDOWS Microsoft Windows malformed TTF integer overflow attempt (more info ...)attempted-admin  2018-1012      URL
46538OS-WINDOWS Microsoft Windows win32k.sys privilege escalation attempt (more info ...)attempted-admin  2018-8124      URL
46539OS-WINDOWS Microsoft Windows win32k.sys privilege escalation attempt (more info ...)attempted-admin  2018-8124      URL
46544BROWSER-IE Microsoft Edge scripting engine use after free attempt (more info ...)attempted-user  2018-0946      URL
46545BROWSER-IE Microsoft Edge scripting engine use after free attempt (more info ...)attempted-user  2018-0946      URL
46546OS-WINDOWS Microsoft Windows win32k NtUserSetImeInfoEx privilege escalation attempt (more info ...)attempted-admin  2018-8120      URL
46547OS-WINDOWS Microsoft Windows win32k NtUserSetImeInfoEx privilege escalation attempt (more info ...)attempted-admin  2018-8120      URL
46562OS-WINDOWS Microsoft Win32k privilege escalation attempt (more info ...)attempted-admin  2018-8164      URL
46563OS-WINDOWS Microsoft Win32k privilege escalation attempt (more info ...)attempted-admin  2018-8164      URL
46564OS-WINDOWS Microsoft Win32k privilege escalation attempt (more info ...)attempted-admin  2018-8166      URL
46565OS-WINDOWS Microsoft Win32k privilege escalation attempt (more info ...)attempted-admin  2018-8166      URL
46603OS-WINDOWS Microsoft Windows clfs.sys out of bounds local privilege escalation attempt (more info ...)attempted-admin  2018-8167      URL
46604OS-WINDOWS Microsoft Windows clfs.sys out of bounds local privilege escalation attempt (more info ...)attempted-admin  2018-8167      URL
46606BROWSER-IE Microsoft Edge out-of-bounds memory access attempt (more info ...)attempted-user  2018-8137      URL
46607BROWSER-IE Microsoft Edge out-of-bounds memory access attempt (more info ...)attempted-user  2018-8137      URL
46637NETBIOS SMB client NULL deref race condition attempt (more info ...)attempted-admin  2010-0231      URL
46754OS-WINDOWS Microsoft Windows win32k NtUserSetImeInfoEx privilege escalation attempt (more info ...)attempted-admin  2018-8120      URL
46755OS-WINDOWS Microsoft Windows win32k NtUserSetImeInfoEx privilege escalation attempt (more info ...)attempted-admin  2018-8120      URL
46811FILE-OTHER Microsoft Windows Host Compute Service Shim remote code execution attempt (more info ...)attempted-user  2018-8115      URL
46830OS-WINDOWS Microsoft Windows kernel privilege escalation attempt (more info ...)attempted-admin  2018-8897      URL
46831OS-WINDOWS Microsoft Windows kernel privilege escalation attempt (more info ...)attempted-admin  2018-8897      URL
46832OS-WINDOWS Microsoft Windows ROP gadget locate attempt (more info ...)attempted-admin  2018-8897      
46833OS-WINDOWS Microsoft Windows ROP gadget locate attempt (more info ...)attempted-admin  2018-8897      
46834OS-WINDOWS Microsoft Windows kernel privilege escalation attempt (more info ...)attempted-admin  2018-8897      URL
46835OS-WINDOWS Microsoft Windows kernel privilege escalation attempt (more info ...)attempted-admin  2018-8897      URL
46927BROWSER-IE Microsoft Edge ClipPath out of bounds write attempt (more info ...)attempted-user  2018-8110      URL
46928BROWSER-IE Microsoft Edge ClipPath out of bounds write attempt (more info ...)attempted-user  2018-8110      
46929BROWSER-IE Microsoft Edge type confusion memory corruption attempt (more info ...)attempted-user  2018-8111      URL
46930BROWSER-IE Microsoft Edge type confusion memory corruption attempt (more info ...)attempted-user  2018-8111      URL
46933BROWSER-IE Microsoft Edge Chakra scripting engine type confusion attempt (more info ...)attempted-user  2018-8229      URL
46934BROWSER-IE Microsoft Edge Chakra scripting engine type confusion attempt (more info ...)attempted-user  2018-8229      URL
46938OS-WINDOWS Microsoft Win32k privilege escalation attempt (more info ...)attempted-admin  2018-8233      URL
46939OS-WINDOWS Microsoft Win32k privilege escalation attempt (more info ...)attempted-admin  2018-8233      URL
46943FILE-OTHER Microsoft Windows .lnk shortcut file executing system32 executable attempt (more info ...)attempted-user  2018-0978      URL
47057BROWSER-IE Microsoft Edge edgehtml.dll uninitialized pointer vulnerability attempt (more info ...)attempted-user  2016-3222      URL
47058BROWSER-IE Microsoft Edge edgehtml.dll uninitialized pointer vulnerability attempt (more info ...)attempted-user  2016-3222      
47096OS-WINDOWS Microsoft Windows xxxNextWindow NULL pointer dereference attempt (more info ...)attempted-admin  2018-8282      URL
47097OS-WINDOWS Microsoft Windows xxxNextWindow NULL pointer dereference attempt (more info ...)attempted-admin  2018-8282      URL
47098BROWSER-IE Microsoft Edge parseFloat type confusion attempt (more info ...)attempted-user  2018-8279      URL
47099BROWSER-IE Microsoft Edge parseFloat type confusion attempt (more info ...)attempted-user  2018-8279      URL
47100BROWSER-IE Microsoft Edge TryArraySplice memory corruption attempt (more info ...)attempted-user  2018-8275      URL
47101BROWSER-IE Microsoft Edge TryArraySplice memory corruption attempt (more info ...)attempted-user  2018-8275      URL
47103BROWSER-IE Microsoft Edge Intl.js memory corruption attempt (more info ...)attempted-user  2018-8298      URL
47107BROWSER-IE Microsoft Edge event handling use-after-free attempt (more info ...)attempted-user  2018-8274      URL
47108BROWSER-IE Microsoft Edge event handling use-after-free attempt (more info ...)attempted-user  2018-8274      URL
47109BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-admin  2018-8291      URL
47110BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-admin  2018-8291      URL
47111BROWSER-IE Microsoft Edge Form buffer overflow attempt (more info ...)attempted-user  2018-8289      URL
47112BROWSER-IE Microsoft Edge Form buffer overflow attempt (more info ...)attempted-user  2018-8289      URL
47113BROWSER-IE Microsoft Edge heap overflow attempt (more info ...)attempted-user  2018-8262      URL
47114BROWSER-IE Microsoft Edge heap overflow attempt (more info ...)attempted-user  2018-8262      URL
47117BROWSER-IE Microsoft Edge browser memory corruption attempt (more info ...)attempted-user  2018-8125      URL
47118BROWSER-IE Microsoft Edge browser memory corruption attempt (more info ...)attempted-user  2018-8125      URL
47119BROWSER-OTHER Microsoft Edge url spoofing attempt (more info ...)attempted-user  2018-8278      URL
47120BROWSER-OTHER Microsoft Edge url spoofing attempt (more info ...)attempted-user  2018-8278      URL
47121BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-8283      URL
47122BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-8283      URL
47141BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2018-8324      URL
47142BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2018-8324      URL
47161BROWSER-IE Microsoft Edge mutation event memory corruption attempt (more info ...)attempted-user  2016-0124      URL
47219FILE-OTHER Microsoft Windows OTF parsing memory corruption attempt (more info ...)attempted-admin  2016-7256      URL
47220FILE-OTHER Microsoft Windows OTF parsing memory corruption attempt (more info ...)attempted-admin  2016-7256      URL
47461BROWSER-PLUGINS CTSWebProxy ActiveX privilege escalation attempt (more info ...)attempted-admin  2015-0016      URL
47462BROWSER-PLUGINS CTSWebProxy ActiveX privilege escalation attempt (more info ...)attempted-admin  2015-0016      URL
47474BROWSER-IE Microsoft Edge browser redirection vulnerability attempt (more info ...)attempted-user  2018-8383      URL
47475BROWSER-IE Microsoft Edge browser redirection vulnerability attempt (more info ...)attempted-user  2018-8383      URL
47477FILE-OTHER Microsoft LNK remote code execution attempt (more info ...)attempted-admin  2018-8345      URL
47478BROWSER-IE Microsoft Edge Chakra Scripting Engine type confusion attempt (more info ...)attempted-user  2018-8372      URL
47479BROWSER-IE Microsoft Edge Chakra Scripting Engine type confusion attempt (more info ...)attempted-user  2018-8372      URL
47480BROWSER-IE Microsoft Edge type confusion vulnerability attempt (more info ...)attempted-user  2018-8384      URL
47481BROWSER-IE Microsoft Edge type confusion vulnerability attempt (more info ...)attempted-user  2018-8384      URL
47486BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-user  2018-8387      URL
47487BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-user  2018-8387      URL
47488BROWSER-IE Microsoft Edge transform type confusion attempt (more info ...)attempted-user  2018-8403      URL
47489BROWSER-IE Microsoft Edge transform type confusion attempt (more info ...)attempted-user  2018-8403      URL
47490BROWSER-IE Microsoft Edge Chakra Scripting Engine memory corruption attempt (more info ...)attempted-user  2018-8266      URL
47491BROWSER-IE Microsoft Edge Chakra Scripting Engine memory corruption attempt (more info ...)attempted-user  2018-8266      URL
47492BROWSER-IE Microsoft Edge Chakra Scripting Engine localeCompare type confusion attempt (more info ...)attempted-user  2018-8355      URL
47493BROWSER-IE Microsoft Edge Chakra Scripting Engine localeCompare type confusion attempt (more info ...)attempted-user  2018-8355      URL
47503FILE-EXECUTABLE Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-user  2018-8404      URL
47504FILE-EXECUTABLE Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-user  2018-8404      URL
47512OS-WINDOWS Microsoft Windows D3D memory corruption attempt (more info ...)attempted-user  2018-8406      URL
47513OS-WINDOWS Microsoft Windows D3D memory corruption attempt (more info ...)attempted-user  2018-8406      URL
47515OS-WINDOWS Microsoft Windows D3D memory corruption attempt (more info ...)attempted-user  2018-8405      URL
47516OS-WINDOWS Microsoft Windows D3D memory corruption attempt (more info ...)attempted-user  2018-8405      URL
47517OS-WINDOWS Microsoft Windows D3D memory corruption attempt (more info ...)attempted-user  2018-8401      URL
47518OS-WINDOWS Microsoft Windows D3D memory corruption attempt (more info ...)attempted-user  2018-8401      URL
47519FILE-OTHER Microsoft Graphics remote code execution attempt (more info ...)attempted-user  2018-8344      URL
47520FILE-OTHER Microsoft Graphics remote code execution attempt (more info ...)attempted-user  2018-8344      URL
47635BROWSER-IE Microsoft Edge Chakra floating point type confusion attempt (more info ...)attempted-user  2018-0953      URL
47636BROWSER-IE Microsoft Edge Chakra floating point type confusion attempt (more info ...)attempted-user  2018-0953      URL
47637BROWSER-IE Microsoft Edge Chakra floating point type confusion attempt (more info ...)attempted-user  2018-0953      URL
47638BROWSER-IE Microsoft Edge Chakra floating point type confusion attempt (more info ...)attempted-user  2018-0953      URL
47702OS-WINDOWS Microsoft Windows ALPC task scheduler local privilege escalation attempt (more info ...)attempted-admin  2018-8440      URL
47703OS-WINDOWS Microsoft Windows ALPC task scheduler local privilege escalation attempt (more info ...)attempted-admin  2018-8440      URL
47717OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-user  2018-8442      URL
47718OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-user  2018-8442      URL
47732BROWSER-IE Microsoft Edge empty prototype use-after-free attempt (more info ...)attempted-user  2018-8459      URL
47733BROWSER-IE Microsoft Edge empty prototype use-after-free attempt (more info ...)attempted-user  2018-8459      URL
47734BROWSER-IE Microsoft Edge Chakra engine use after free exploit attempt (more info ...)attempted-user  2018-8367      URL
47735BROWSER-IE Microsoft Edge Chakra engine use after free exploit attempt (more info ...)attempted-user  2018-8367      URL
47736BROWSER-IE Microsoft Edge type confusion memory corruption attempt (more info ...)attempted-user  2018-8391      URL
47737BROWSER-IE Microsoft Edge type confusion memory corruption attempt (more info ...)attempted-user  2018-8391      URL
47740OS-WINDOWS Microsoft Windows Device Guard bypass attempt (more info ...)attempted-user  2018-8449      URL
47741OS-WINDOWS Microsoft Windows Device Guard bypass attempt (more info ...)attempted-user  2018-8449      URL
47742BROWSER-IE Microsoft Edge type confusion code execution attempt (more info ...)attempted-user  2018-8467      URL
47743BROWSER-IE Microsoft Edge type confusion code execution attempt (more info ...)attempted-user  2018-8467      URL
47745OS-WINDOWS Microsoft Windows predefined registry keys double free attempt (more info ...)attempted-user  2018-8410      URL
47764FILE-IMAGE Microsoft Windows malformed TIFF remote code execution attempt (more info ...)attempted-user  2018-8475      URL
47765FILE-IMAGE Microsoft Windows malformed TIFF remote code execution attempt (more info ...)attempted-user  2018-8475      URL
47850OS-WINDOWS Microsoft Windows SystemCollector privilege escalation attempt (more info ...)attempted-admin  2018-0952      URL
47851OS-WINDOWS Microsoft Windows SystemCollector privilege escalation attempt (more info ...)attempted-admin  2018-0952      URL
48045BROWSER-IE Microsoft Edge DomAttrModified use after free attempt (more info ...)attempted-user  2018-8460      URL
48046BROWSER-IE Microsoft Edge DomAttrModified use after free attempt (more info ...)attempted-user  2018-8460      URL
48047OS-WINDOWS Microsoft Windows dxgkrnl.sys kernel memory information leak attempt (more info ...)attempted-admin  2018-8486      URL
48048OS-WINDOWS Microsoft Windows dxgkrnl.sys kernel memory information leak attempt (more info ...)attempted-admin  2018-8486      URL
48054BROWSER-IE Microsoft Edge App-v vbs command attempt (more info ...)attempted-user  2018-8495      URL
48056OS-WINDOWS Microsoft Windows Filter Manager Elevation Of Privilege attempt (more info ...)denial-of-service  2018-8333      URL
48057FILE-EXECUTABLE Microsoft Windows NTFS privilege escalation attempt (more info ...)attempted-user  2018-8411      URL
48058FILE-EXECUTABLE Microsoft Windows NTFS privilege escalation attempt (more info ...)attempted-user  2018-8411      URL
48059FILE-OTHER Microsoft Windows malformed .themepack Theme API remote code execution attempt (more info ...)attempted-user  2018-8413      URL
48060FILE-OTHER Microsoft Windows malformed .themepack Theme API remote code execution attempt (more info ...)attempted-user  2018-8413      URL
48062FILE-OTHER Microsoft Powershell XML instantiation constrained language mode bypass attempt (more info ...)attempted-user  2018-8492      URL
48063FILE-OTHER Microsoft Powershell XML instantiation constrained language mode bypass attempt (more info ...)attempted-user  2018-8492      URL
48072OS-WINDOWS Microsoft Windows win32k.sys privilege escalation attempt (more info ...)attempted-user  2018-8453      URL
48073OS-WINDOWS Microsoft Windows win32k.sys privilege escalation attempt (more info ...)attempted-user  2018-8453      URL
48122FILE-OTHER Microsoft .NET Resources file remote code execution attempt (more info ...)attempted-user  2018-8172      URL
48123FILE-OTHER Microsoft .NET Resources file remote code execution attempt (more info ...)attempted-user  2018-8172      URL
48128OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2018-8468      URL
48129OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2018-8468      URL
48130BROWSER-IE Microsoft Edge sandbox escape attempt (more info ...)attempted-user  2018-8469      URL
48131BROWSER-IE Microsoft Edge sandbox escape attempt (more info ...)attempted-user  2018-8469      URL
48132BROWSER-IE Microsoft Edge sandbox escape attempt (more info ...)attempted-user  2018-8469      URL
48133BROWSER-IE Microsoft Edge sandbox escape attempt (more info ...)attempted-user  2018-8469      URL
48162BROWSER-IE Microsoft Edge sandbox escape attempt (more info ...)attempted-user  2018-8469      URL
48163BROWSER-IE Microsoft Edge sandbox escape attempt (more info ...)attempted-user  2018-8469      URL
48237OS-WINDOWS Microsoft Data Sharing dssvc.dll arbitrary file deletion attempt (more info ...)attempted-admin  2018-8584      URL
48238OS-WINDOWS Microsoft Data Sharing dssvc.dll arbitrary file deletion attempt (more info ...)attempted-admin  2018-8584      URL
48241NETBIOS Cisco WebEx WebExService.exe remote code execution attempt (more info ...)attempted-admin  2018-15442      URL
48360BROWSER-IE Microsoft Edge JIT floating point value type confusion attempt (more info ...)attempted-admin  2018-8555      URL
48361BROWSER-IE Microsoft Edge JIT floating point value type confusion attempt (more info ...)attempted-user  2018-8555      URL
48362OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-user  2018-8562      URL
48363OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-user  2018-8562      URL
48364OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-user  2018-8589      URL
48365OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-user  2018-8589      URL
48366OS-WINDOWS Microsoft Windows dxgkrnl.sys elevation of privilege attempt (more info ...)attempted-admin  2018-8554      URL
48367OS-WINDOWS Microsoft Windows dxgkrnl.sys elevation of privilege attempt (more info ...)attempted-admin  2018-8554      URL
48374FILE-IMAGE Microsoft Graphics component WMF code execution attempt (more info ...)attempted-user  2018-8553      URL
48375FILE-IMAGE Microsoft Graphics component WMF code execution attempt (more info ...)attempted-user  2018-8553      URL
48376BROWSER-IE Microsoft Edge bailOnImplicitCall type confusion attempt (more info ...)attempted-user  2018-8556      URL
48377BROWSER-IE Microsoft Edge bailOnImplicitCall type confusion attempt (more info ...)attempted-user  2018-8556      URL
48387BROWSER-IE Microsoft Edge information disclosure attempt (more info ...)attempted-user  2018-8545      URL
48388BROWSER-IE Microsoft Edge information disclosure attempt (more info ...)attempted-user  2018-8545      URL
48393OS-WINDOWS Microsoft Windows Win32k information disclosure attempt (more info ...)attempted-recon  2018-8565      URL
48394OS-WINDOWS Microsoft Windows Win32k information disclosure attempt (more info ...)attempted-recon  2018-8565      URL
48398OS-WINDOWS Microsoft Windows potential Device Guard evasion via Jscript9 scripting engine attempt (more info ...)attempted-user  2018-8417      URL
48399OS-WINDOWS Microsoft Windows potential Device Guard evasion via Jscript9 scripting engine attempt (more info ...)attempted-user  2018-8417      URL
48409OS-WINDOWS Microsoft Windows kernel ioctlsocket information disclosure attempt (more info ...)attempted-admin  2018-8408      URL
48410OS-WINDOWS Microsoft Windows kernel ioctlsocket information disclosure attempt (more info ...)attempted-admin  2018-8408      URL
48441BROWSER-PLUGINS Fourier Systems DaqLab ActiveX clsid access attempt (more info ...)attempted-user        
48442BROWSER-PLUGINS Fourier Systems DaqLab ActiveX clsid access attempt (more info ...)attempted-user        
48509BROWSER-IE Microsoft Edge Browser Chakra script type confusion exploit attempt (more info ...)attempted-user  2018-8618      URL
48510BROWSER-IE Microsoft Edge Browser Chakra script type confusion exploit attempt (more info ...)attempted-user  2018-8618      URL
48513BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-user  2018-8629      URL
48514BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-user  2018-8629      URL
48515BROWSER-IE Microsoft Edge Chakra scripting engine memory corruption attempt (more info ...)attempted-user  2018-8583      URL
48516BROWSER-IE Microsoft Edge Chakra scripting engine memory corruption attempt (more info ...)attempted-user  2018-8583      URL
48519BROWSER-IE Microsoft Edge buffer overflow attempt (more info ...)attempted-user  2018-8634      URL
48520BROWSER-IE Microsoft Edge buffer overflow attempt (more info ...)attempted-user  2018-8634      URL
48535BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48536BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48537BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48538BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48539BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48540BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48541BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48542BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48543BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48544BROWSER-PLUGINS Advantech WebAccess 7.0 ActiveX clsid access attempt (more info ...)attempted-user        
48606OS-WINDOWS Microsoft Windows win32k NtGdiCreateDIBitmapInternal memory corruption attempt (more info ...)attempted-user  2018-8639      URL
48607OS-WINDOWS Microsoft Windows win32k NtGdiCreateDIBitmapInternal memory corruption attempt (more info ...)attempted-user  2018-8639      URL
48612FILE-EXECUTABLE Microsoft Windows kernel use-after-free attempt (more info ...)attempted-user  2018-8611      URL
48613FILE-EXECUTABLE Microsoft Windows kernel use-after-free attempt (more info ...)attempted-user  2018-8611      URL
48733BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user        
48734BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user        
48768FILE-EXECUTABLE Microsoft Windows data sharing service privilege escalation attempt (more info ...)attempted-admin  2019-0574      URL
48769FILE-EXECUTABLE Microsoft Windows data sharing service privilege escalation attempt (more info ...)attempted-admin  2019-0574      URL
48770BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0565      URL
48771BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0565      URL
48772BROWSER-IE Microsoft Edge Chakra scripting engine type confusion attempt (more info ...)attempted-user  2019-0539      URL
48773BROWSER-IE Microsoft Edge Chakra scripting engine type confusion attempt (more info ...)attempted-user  2019-0539      URL
48776OS-WINDOWS Microsoft Windows Data Sharing Service privilege escalation attempt (more info ...)attempted-admin  2019-0572      URL
48777OS-WINDOWS Microsoft Windows Data Sharing Service privilege escalation attempt (more info ...)attempted-admin  2019-0572      URL
48778BROWSER-IE Microsoft Edge prototype JsBuiltInEngineInterfaceExtensionObject use-after-free attempt (more info ...)attempted-user  2019-0568      URL
48779BROWSER-IE Microsoft Edge prototype JsBuiltInEngineInterfaceExtensionObject use-after-free attempt (more info ...)attempted-user  2019-0568      URL
48780BROWSER-IE Microsoft Edge object manipulation use-after-free attempt (more info ...)attempted-user  2019-0567      URL
48781BROWSER-IE Microsoft Edge object manipulation use-after-free attempt (more info ...)attempted-user  2019-0567      URL
48787OS-WINDOWS Microsoft Windows COM Desktop Broker sandbox escape attempt (more info ...)attempted-user  2019-0552      URL
48788OS-WINDOWS Microsoft Windows COM Desktop Broker sandbox escape attempt (more info ...)attempted-user  2019-0552      URL
48789OS-WINDOWS Microsoft Windows kernel out of bounds read attempt (more info ...)attempted-admin  2019-0569      URL
48790OS-WINDOWS Microsoft Windows kernel out of bounds read attempt (more info ...)attempted-admin  2019-0569      URL
48793OS-WINDOWS Microsoft Windows Data Sharing Service privilege escalation attempt (more info ...)attempted-user  2019-0573      URL
48794OS-WINDOWS Microsoft Windows Data Sharing Service privilege escalation attempt (more info ...)attempted-user  2019-0573      URL
48795OS-WINDOWS Microsoft XmlDocument privilege escalation attempt (more info ...)attempted-user  2019-0555      URL
48796OS-WINDOWS Microsoft XmlDocument privilege escalation attempt (more info ...)attempted-user  2019-0555      URL
48797OS-WINDOWS Microsoft XmlDocument privilege escalation attempt (more info ...)attempted-user  2019-0555      URL
48798OS-WINDOWS Microsoft XmlDocument privilege escalation attempt (more info ...)attempted-user  2019-0555      URL
48799OS-WINDOWS Microsoft Windows arbitrary file read attempt (more info ...)attempted-admin  2019-0636      URL
48800OS-WINDOWS Microsoft Windows arbitrary file read attempt (more info ...)attempted-admin  2019-0636      URL
48807OS-WINDOWS Microsoft Windows 10 AcquireCredentialsHandle privilege escalation attempt (more info ...)attempted-admin  2019-0543      URL
48808OS-WINDOWS Microsoft Windows 10 AcquireCredentialsHandle privilege escalation attempt (more info ...)attempted-admin  2019-0543      URL
48809OS-WINDOWS Microsoft Edge session boundary violation attempt (more info ...)attempted-user  2019-0566      URL
48810OS-WINDOWS Microsoft Edge session boundary violation attempt (more info ...)attempted-user  2019-0566      URL
48963OS-WINDOWS Microsoft Windows Task Scheduler privileged file overwrite attempt (more info ...)attempted-user        
48964OS-WINDOWS Microsoft Windows Task Scheduler privileged file overwrite attempt (more info ...)attempted-user        
49038FILE-OTHER Microsoft Windows Contact file email address remote code execution attempt (more info ...)attempted-user        URL
49039FILE-OTHER Microsoft Windows Contact file email address remote code execution attempt (more info ...)attempted-user        URL
49041OS-WINDOWS Microsoft Windows Terminal server RDP over non-standard port attempt (more info ...)attempted-user        URL
49073FILE-OTHER Microsoft Windows device metadata file directory traversal attempt (more info ...)attempted-user        
49074FILE-OTHER Microsoft Windows device metadata file directory traversal attempt (more info ...)attempted-user        
49075FILE-OTHER Microsoft Windows device metadata file directory traversal attempt (more info ...)attempted-user        
49076FILE-OTHER Microsoft Windows device metadata file directory traversal attempt (more info ...)attempted-user        
49077FILE-OTHER Microsoft Windows device metadata file directory traversal attempt (more info ...)attempted-user        
49078FILE-OTHER Microsoft Windows device metadata file directory traversal attempt (more info ...)attempted-user        
49079FILE-OTHER Microsoft Windows device metadata file directory traversal attempt (more info ...)attempted-user        
49080FILE-OTHER Microsoft Windows device metadata file directory traversal attempt (more info ...)attempted-user        
49118BROWSER-IE Microsoft Edge edgehtml.dll uninitialized pointer vulnerability attempt (more info ...)attempted-user  2016-3222      URL
49119BROWSER-IE Microsoft Edge edgehtml.dll uninitialized pointer vulnerability attempt (more info ...)attempted-user  2016-3222      URL
49128BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2019-0590      URL
49129BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2019-0590      URL
49130BROWSER-IE Microsoft Edge type confusion exploit attempt (more info ...)attempted-user  2019-0593      URL
49131BROWSER-IE Microsoft Edge type confusion exploit attempt (more info ...)attempted-user  2019-0593      URL
49134BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2019-0591      URL
49135BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2019-0591      URL
49136BROWSER-IE Microsoft Edge scripting engine remote code execution attempt (more info ...)attempted-user  2019-0652      URL
49137BROWSER-IE Microsoft Edge scripting engine remote code execution attempt (more info ...)attempted-user  2019-0652      URL
49138BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2019-0651      URL
49139BROWSER-IE Microsoft Edge scripting engine type confusion attempt (more info ...)attempted-user  2019-0651      URL
49140BROWSER-IE Microsoft Edge ArrayBuffer out of bounds write attempt (more info ...)attempted-user  2019-0610      URL
49141BROWSER-IE Microsoft Edge ArrayBuffer out of bounds write attempt (more info ...)attempted-user  2019-0610      URL
49142BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0645      URL
49143BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0645      URL
49144BROWSER-IE Microsoft Edge type confusion exploit attempt (more info ...)attempted-user  2019-0606      URL
49145BROWSER-IE Microsoft Edge type confusion exploit attempt (more info ...)attempted-user  2019-0606      URL
49146OS-WINDOWS Microsoft Windows SMB named pipe buffer overflow attempt (more info ...)attempted-admin  2019-0630      URL
49147BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2019-0650      URL
49148BROWSER-IE Microsoft Edge type confusion attempt (more info ...)attempted-user  2019-0650      URL
49149BROWSER-IE Microsoft Edge WebAssembly type confusion exploit attempt (more info ...)attempted-user  2019-0607      URL
49150BROWSER-IE Microsoft Edge WebAssembly type confusion exploit attempt (more info ...)attempted-user  2019-0607      URL
49151BROWSER-IE Microsoft Edge Scripting Engine memory corruption attempt (more info ...)attempted-user  2019-0644      URL
49152BROWSER-IE Microsoft Edge Scripting Engine memory corruption attempt (more info ...)attempted-user  2019-0644      URL
49153BROWSER-IE Microsoft Edge Promise object context switch use-after-free attempt (more info ...)attempted-user  2019-0640      URL
49154BROWSER-IE Microsoft Edge Promise object context switch use-after-free attempt (more info ...)attempted-user  2019-0640      URL
49157BROWSER-IE Microsoft Edge out of bounds read attempt (more info ...)attempted-user  2019-0648      URL
49158BROWSER-IE Microsoft Edge out of bounds read attempt (more info ...)attempted-user  2019-0648      URL
49159OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin  2019-0656      URL
49160OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin  2019-0656      URL
49161OS-WINDOWS Microsoft Windows NtTraceControl information disclosure attempt (more info ...)attempted-admin  2019-0661      URL
49162OS-WINDOWS Microsoft Windows NtTraceControl information disclosure attempt (more info ...)attempted-admin  2019-0661      URL
49165BROWSER-IE Microsoft Edge buffer manipulation out-of-bounds read attempt (more info ...)attempted-user  2019-0658      URL
49166BROWSER-IE Microsoft Edge buffer manipulation out-of-bounds read attempt (more info ...)attempted-user  2019-0658      URL
49167BROWSER-IE Microsoft Edge variable length manipulation type confusion attempt (more info ...)attempted-user  2019-0655      URL
49168BROWSER-IE Microsoft Edge variable length manipulation type confusion attempt (more info ...)attempted-user  2019-0655      URL
49169BROWSER-IE Microsoft Edge isSealed object buffer overrun attempt (more info ...)attempted-user  2019-0642      URL
49170BROWSER-IE Microsoft Edge isSealed object buffer overrun attempt (more info ...)attempted-user  2019-0642      URL
49172OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-admin  2019-0767      URL
49173OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-admin  2019-0767      URL
49174OS-WINDOWS Microsoft Windows SMB remote code execution attempt (more info ...)attempted-user  2019-0633      URL
49175OS-WINDOWS Microsoft Windows SMB remote code execution attempt (more info ...)attempted-user  2019-0633      URL
49176OS-WINDOWS Microsoft Windows SMB remote code execution attempt (more info ...)attempted-user  2019-0633      URL
49177OS-WINDOWS Microsoft Windows SMB remote code execution attempt (more info ...)attempted-user  2019-0633      URL
49180OS-WINDOWS Microsoft Windows Win32k SendMessageTimeout kernel information leak attempt (more info ...)attempted-admin  2019-0628      URL
49181OS-WINDOWS Microsoft Windows Win32k SendMessageTimeout kernel information leak attempt (more info ...)attempted-admin  2019-0628      URL
49199FILE-OTHER Microsoft Windows Contact file arbitrary code execution attempt (more info ...)attempted-user        URL
49200FILE-OTHER Microsoft Windows VCF arbitrary code execution attempt (more info ...)attempted-user        URL
49293NETBIOS Cisco WebEx WebExService.exe remote code execution attempt (more info ...)attempted-admin  2019-1674      URL
49333OS-WINDOWS Microsoft Windows DHCP Server remote code execution attempt (more info ...)attempted-user  2019-0626      URL
49364BROWSER-IE Microsoft Edge reference count memory corruption attempt (more info ...)attempted-user  2019-0665      URL
49365BROWSER-IE Microsoft Edge reference count memory corruption attempt (more info ...)attempted-user  2019-0665      URL
49368BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0592      URL
49369BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0592      URL
49371BROWSER-IE Microsoft Edge security feature bypass attempt (more info ...)attempted-user  2019-0612      URL
49372BROWSER-IE Microsoft Edge security feature bypass attempt (more info ...)attempted-user  2019-0612      URL
49380BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-1092      URL
49381BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-1092      URL
49382BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0639      URL
49383BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0639      URL
49386BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0667      URL
49387BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0667      URL
49388BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2021-31959      URL
49389BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2021-31959      URL
49390OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-admin  2019-0775      URL
49391OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-admin  2019-0775      URL
49392OS-WINDOWS Microsoft Windows mailslot kernel information leak attempt (more info ...)attempted-admin  2019-0755      URL
49393OS-WINDOWS Microsoft Windows mailslot kernel information leak attempt (more info ...)attempted-admin  2019-0755      URL
49394BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0609      URL
49395BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0609      URL
49400OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2019-0797      URL
49401OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2019-0797      URL
49402OS-WINDOWS Microsoft Windows NT kernel null pointer dereference attempt (more info ...)attempted-admin  2019-0808      URL
49403OS-WINDOWS Microsoft Windows NT kernel null pointer dereference attempt (more info ...)attempted-admin  2019-0808      URL
49482FILE-OTHER Microsoft Windows TTF parsing counter overflow attempt (more info ...)attempted-admin  2012-4786      URL
49483FILE-OTHER Microsoft Windows TTF parsing counter overflow attempt (more info ...)attempted-admin  2012-4786      URL
49626BROWSER-IE Microsoft Edge resource entry same-origin-policy bypass attempt (more info ...)attempted-user        
49627BROWSER-IE Microsoft Edge resource entry same-origin-policy bypass attempt (more info ...)attempted-user        
49636BROWSER-PLUGINS Foscam IPCWebComponents ActiveX clsid access attempt (more info ...)attempted-user        
49637BROWSER-PLUGINS Foscam IPCWebComponents ActiveX clsid access attempt (more info ...)attempted-user        
49638BROWSER-PLUGINS Foscam IPCWebComponents ActiveX clsid access attempt (more info ...)attempted-user        
49639BROWSER-PLUGINS Foscam IPCWebComponents ActiveX clsid access attempt (more info ...)attempted-user        
49683BROWSER-PLUGINS Schneider Electric ProClima ActiveX function call access attempt (more info ...)attempted-user  2014-8511      
49688FILE-EXECUTABLE Microsoft Windows kernel user after free attempt (more info ...)attempted-admin  2019-0685      URL
49689FILE-EXECUTABLE Microsoft Windows kernel user after free attempt (more info ...)attempted-admin  2019-0685      URL
49692OS-WINDOWS Microsoft Windows LUAFV driver privilege escalation attempt (more info ...)attempted-admin  2019-0730      URL
49693OS-WINDOWS Microsoft Windows LUAFV driver privilege escalation attempt (more info ...)attempted-admin  2019-0730      URL
49696OS-WINDOWS Microsoft Windows LUAFV privilege escalation attempt (more info ...)attempted-admin  2019-0731      URL
49697OS-WINDOWS Microsoft Windows LUAFV privilege escalation attempt (more info ...)attempted-admin  2019-0731      URL
49698BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0812      URL
49699BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0812      URL
49702BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0752      URL
49703BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0752      URL
49704OS-WINDOWS Microsoft Windows NtSetCachedSigningLevel Device Guard bypass attempt (more info ...)policy-violation  2019-0732      URL
49705OS-WINDOWS Microsoft Windows NtSetCachedSigningLevel Device Guard bypass attempt (more info ...)policy-violation  2019-0732      URL
49706BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0860      URL
49707BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0860      URL
49708BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0753      URL
49709BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0753      URL
49710BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0810      URL
49711BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0810      URL
49712OS-WINDOWS Microsoft Windows GDI component use after free attempt (more info ...)attempted-admin  2019-0803      URL
49713OS-WINDOWS Microsoft Windows GDI component use after free attempt (more info ...)attempted-admin  2019-0803      URL
49716BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0806      URL
49717BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0806      URL
49718OS-WINDOWS Microsoft windows LUAFV privilege escalation attempt (more info ...)attempted-admin  2019-0796      URL
49719OS-WINDOWS Microsoft windows LUAFV privilege escalation attempt (more info ...)attempted-admin  2019-0796      URL
49720OS-WINDOWS Microsoft Windows LuafvPostReadWrite privilege escalation attempt (more info ...)attempted-admin  2019-0836      URL
49721OS-WINDOWS Microsoft Windows LuafvPostReadWrite privilege escalation attempt (more info ...)attempted-admin  2019-0836      URL
49722BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0829      URL
49723BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0829      URL
49725BROWSER-IE Microsoft Edge edgehtml.dll uninitialized pointer vulnerability attempt (more info ...)attempted-user  2016-3222      URL
49726BROWSER-IE Microsoft Edge edgehtml.dll uninitialized pointer vulnerability attempt (more info ...)attempted-user  2016-3222      URL
49746OS-WINDOWS Microsoft Windows win32k privilege escalation attempt (more info ...)attempted-admin  2019-0859      URL
49747OS-WINDOWS Microsoft Windows win32k privilege escalation attempt (more info ...)attempted-admin  2019-0859      URL
49748OS-WINDOWS Microsoft Windows LUAFV privilege escalation attempt (more info ...)attempted-admin  2019-0805      URL
49749OS-WINDOWS Microsoft Windows LUAFV privilege escalation attempt (more info ...)attempted-admin  2019-0805      URL
49750OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-recon  2019-0840      URL
49751OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-recon  2019-0840      URL
49754OS-WINDOWS Microsoft Windows Kernel information disclosure attempt (more info ...)attempted-admin  2019-0844      URL
49755OS-WINDOWS Microsoft Windows Kernel information disclosure attempt (more info ...)attempted-admin  2019-0844      URL
49762OS-WINDOWS Microsoft Windows AppXSVC privilege escalation attempt (more info ...)attempted-admin  2019-0841      URL
49763OS-WINDOWS Microsoft Windows AppXSVC privilege escalation attempt (more info ...)attempted-admin  2019-0841      URL
49764OS-WINDOWS Microsoft Windows AppXSVC privilege escalation attempt (more info ...)attempted-admin  2019-0841      URL
49765OS-WINDOWS Microsoft Windows AppXSVC privilege escalation attempt (more info ...)attempted-admin  2019-0841      URL
49861SERVER-WEBAPP Microsoft SharePoint EntityInstanceIdEncoder remote code execution attempt (more info ...)attempted-user  2019-0604      URL
49964OS-WINDOWS Microsoft Windows DHCP client domain search integer underflow attempt (more info ...)attempted-user  2019-0726      URL
50068OS-WINDOWS Microsoft Windows arbitrary registry access privilege escalation attempt (more info ...)attempted-admin  2019-0931      URL
50069OS-WINDOWS Microsoft Windows arbitrary registry access privilege escalation attempt (more info ...)attempted-admin  2019-0931      URL
50070BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0911      URL
50071BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0911      URL
50072BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0918      URL
50073BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0918      URL
50074BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0884      URL
50075BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0884      URL
50076BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0926      URL
50077BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0926      URL
50078BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0940      URL
50079BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0940      URL
50080BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0938      URL
50081BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0938      URL
50088FILE-IMAGE Microsoft Windows OLE Load Picture remote code execution attempt (more info ...)attempted-user  2019-0885      URL
50089FILE-IMAGE Microsoft Windows OLE Load Picture remote code execution attempt (more info ...)attempted-user  2019-0885      URL
50090OS-WINDOWS Microsoft Windows NDIS elevation of privilege attempt (more info ...)attempted-admin  2019-0707      URL
50091OS-WINDOWS Microsoft Windows NDIS elevation of privilege attempt (more info ...)attempted-admin  2019-0707      URL
50115OS-WINDOWS Microsoft Windows Error Reporting elevation of privilege attempt (more info ...)attempted-admin  2019-0863      URL
50116OS-WINDOWS Microsoft Windows Error Reporting elevation of privilege attempt (more info ...)attempted-admin  2019-0863      URL
50121OS-WINDOWS Microsoft Windows TrueType font parsing integer underflow attempt (more info ...)attempted-admin  2019-0903      URL
50122OS-WINDOWS Microsoft Windows TrueType font parsing integer underflow attempt (more info ...)attempted-admin  2019-0903      URL
50137OS-WINDOWS Microsoft Windows RDP MS_T120 channel bind attempt (more info ...)attempted-admin  2019-0708      URL
50162OS-WINDOWS Microsoft Windows Task Scheduler _SchRpcRegisterTask privilege escalation attempt (more info ...)attempted-admin  2019-1069      URL
50163OS-WINDOWS Microsoft Windows Task Scheduler _SchRpcRegisterTask privilege escalation attempt (more info ...)attempted-admin  2019-1069      URL
50174OS-WINDOWS Microsoft Windows GDI component use after free attempt (more info ...)attempted-admin  2019-0803      URL
50175OS-WINDOWS Microsoft Windows GDI component use after free attempt (more info ...)attempted-admin  2019-0803      URL
50275SERVER-WEBAPP Microsoft SharePoint EntityInstanceIdEncoder remote code execution attempt (more info ...)attempted-user  2019-0604      URL
50357BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0990      URL
50358BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0990      URL
50361BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1024      URL
50362BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1024      URL
50363OS-WINDOWS Microsoft Windows win32k NtGdiExtFloodFill memory corruption attempt (more info ...)attempted-admin  2019-1017      URL
50364OS-WINDOWS Microsoft Windows win32k NtGdiExtFloodFill memory corruption attempt (more info ...)attempted-admin  2019-1017      URL
50365OS-WINDOWS Microsoft Windows DComposition privilege escalation attempt (more info ...)attempted-admin  2019-1041      URL
50366OS-WINDOWS Microsoft Windows DComposition privilege escalation attempt (more info ...)attempted-admin  2019-1041      URL
50369OS-WINDOWS Microsoft Windows user profile service elevation of privilege attempt (more info ...)attempted-user  2019-0986      URL
50370OS-WINDOWS Microsoft Windows user profile service elevation of privilege attempt (more info ...)attempted-user  2019-0986      URL
50371OS-WINDOWS Microsoft Windows Common Log File System Driver privilege escalation attempt (more info ...)attempted-admin  2019-0959      URL
50372OS-WINDOWS Microsoft Windows Common Log File System Driver privilege escalation attempt (more info ...)attempted-admin  2019-0959      URL
50373BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0920      URL
50374BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0920      URL
50393FILE-PDF Microsoft Speech API remote code execution attempt (more info ...)attempted-user  2019-0985      URL
50394FILE-PDF Microsoft Speech API remote code execution attempt (more info ...)attempted-user  2019-0985      URL
50395BROWSER-IE Microsoft Edge Chakra memory corruption attempt (more info ...)attempted-user  2019-1003      URL
50396BROWSER-IE Microsoft Edge Chakra memory corruption attempt (more info ...)attempted-user  2019-1003      URL
50397BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-1005      URL
50398BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-1005      URL
50399BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-1002      URL
50400BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-1002      URL
50401BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-0993      URL
50402BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-0993      URL
50403BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-0991      URL
50404BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-0991      URL
50405BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0988      URL
50406BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-0988      URL
50407BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-0989      URL
50408BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-0989      URL
50413OS-WINDOWS Microsoft Windows ALPC privilege escalation attempt (more info ...)attempted-admin  2019-0943      URL
50414OS-WINDOWS Microsoft Windows ALPC privilege escalation attempt (more info ...)attempted-admin  2019-0943      URL
50450OS-WINDOWS Microsoft Windows SymCrypt modular inverse algorithm denial of service attempt (more info ...)denial-of-service        URL
50625OS-WINDOWS Microsoft Windows SMB Transaction heap groom attempt (more info ...)attempted-admin        
50626OS-WINDOWS Microsoft Windows raw WriteAndX InData pointer adjustment attempt (more info ...)attempted-admin        
50627OS-WINDOWS Microsoft SMB Trans secondary out of bounds write attempt (more info ...)attempted-admin        
50662BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1001      URL
50663BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1001      URL
50664OS-WINDOWS Microsoft Windows COM object privilege escalation attempt (more info ...)attempted-admin  2019-1074      URL
50665OS-WINDOWS Microsoft Windows COM object privilege escalation attempt (more info ...)attempted-admin  2019-1074      URL
50666BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1004      URL
50667BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1004      URL
50668BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-1104      URL
50669BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2019-1104      URL
50670OS-WINDOWS Microsoft Windows Win32k null pointer dereference attempt (more info ...)attempted-admin  2019-1132      URL
50671OS-WINDOWS Microsoft Windows Win32k null pointer dereference attempt (more info ...)attempted-admin  2019-1132      URL
50672OS-WINDOWS Microsoft Windows splwow64 privilege escalation attempt (more info ...)attempted-admin  2019-0880      URL
50673OS-WINDOWS Microsoft Windows splwow64 privilege escalation attempt (more info ...)attempted-admin  2019-0880      URL
50674OS-WINDOWS Microsoft Windows RPCSS privilege escalation attempt (more info ...)attempted-user  2019-1089      URL
50675OS-WINDOWS Microsoft Windows RPCSS privilege escalation attempt (more info ...)attempted-user  2019-1089      URL
50678OS-WINDOWS Microsoft Windows win32k use after free attempt (more info ...)attempted-admin  2019-1071      URL
50679OS-WINDOWS Microsoft Windows win32k use after free attempt (more info ...)attempted-user  2019-1071      URL
50777OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-admin  2019-1014      URL
50778OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-admin  2019-1014      URL
50936OS-WINDOWS Microsoft Windows shell privilege escalation attempt (more info ...)attempted-admin  2019-1170      URL
50937OS-WINDOWS Microsoft Windows shell privilege escalation attempt (more info ...)attempted-admin  2019-1170      URL
50938BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-1140      URL
50939BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-1140      URL
50940BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-1196      URL
50941BROWSER-IE Microsoft Edge scripting engine memory corruption vulnerability attempt (more info ...)attempted-user  2019-1196      URL
50942OS-WINDOWS Microsoft Windows graphics component privilege escalation attempt (more info ...)attempted-admin  2019-1164      URL
50943OS-WINDOWS Microsoft Windows graphics component privilege escalation attempt (more info ...)attempted-admin  2019-1164      URL
50963OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-admin  2019-1159      URL
50964OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-admin  2019-1159      URL
50966OS-WINDOWS Microsoft Windows CoreShellCOMServerRegistrar privilege escalation attempt (more info ...)attempted-user  2019-1184      URL
50967OS-WINDOWS Microsoft Windows CoreShellCOMServerRegistrar privilege escalation attempt (more info ...)attempted-user  2019-1184      URL
50969OS-WINDOWS Microsoft win32k driver buffer over read attempt (more info ...)attempted-user  2019-1078      URL
50970OS-WINDOWS Microsoft win32k driver buffer over read attempt (more info ...)attempted-user  2019-1078      URL
50971OS-WINDOWS Microsoft win32k driver buffer over read attempt (more info ...)attempted-user  2019-1078      URL
50972OS-WINDOWS Microsoft win32k driver buffer over read attempt (more info ...)attempted-user  2019-1078      URL
50973OS-WINDOWS Microsoft win32k driver buffer over read attempt (more info ...)attempted-user  2019-1078      URL
50974OS-WINDOWS Microsoft win32k driver buffer over read attempt (more info ...)attempted-user  2019-1078      URL
51015OS-WINDOWS Microsoft Windows PsmSrvDisconnect privilege escalation attempt (more info ...)attempted-admin  2019-1175      URL
51016OS-WINDOWS Microsoft Windows PsmSrvDisconnect privilege escalation attempt (more info ...)attempted-admin  2019-1175      URL
51369OS-WINDOWS Microsoft Windows RDP DecompressUnchopper integer overflow attempt (more info ...)attempted-admin  2019-1182      URL
51419BROWSER-IE Microsoft Edge Scripting Engine array memory corruption attempt (more info ...)attempted-user  2017-11811      URL
51421BROWSER-IE Microsoft Edge Scripting Engine array memory corruption attempt (more info ...)attempted-user  2017-11811      URL
51425BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0838      
51426BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0838      
51431BROWSER-IE Microsoft Edge Chakra setPrototypeOf use-after-free attempt (more info ...)attempted-user  2017-8751      
51432BROWSER-IE Microsoft Edge Chakra setPrototypeOf use-after-free attempt (more info ...)attempted-user  2017-8751      
51436OS-WINDOWS Microsoft Windows common log file system driver escalation of privilege attempt (more info ...)attempted-admin  2019-1214      URL
51437OS-WINDOWS Microsoft Windows common log file system driver escalation of privilege attempt (more info ...)attempted-admin  2019-1214      URL
51438SERVER-WEBAPP Microsoft SharePoint BdcAdminService remote code execution attempt (more info ...)attempted-user  2019-1295      URL
51445OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2019-1215      URL
51446OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2019-1215      URL
51449OS-WINDOWS Microsoft Windows DirectX kernel memory information leak attempt (more info ...)attempted-admin  2019-1216      URL
51450OS-WINDOWS Microsoft Windows DirectX kernel memory information leak attempt (more info ...)attempted-admin  2019-1216      URL
51451OS-WINDOWS Microsoft Windows Common Log File information disclosure attempt (more info ...)attempted-recon  2019-1219      URL
51452OS-WINDOWS Microsoft Windows Common Log File information disclosure attempt (more info ...)attempted-recon  2019-1219      URL
51454OS-WINDOWS Microsoft Windows win32k kernel information leak attempt (more info ...)attempted-admin  2019-1285      URL
51455OS-WINDOWS Microsoft Windows win32k kernel information leak attempt (more info ...)attempted-admin  2019-1285      URL
51456OS-WINDOWS Microsoft Windows gdi32 graphics adapter handling null pointer dereference attempt (more info ...)attempted-admin  2019-1284      URL
51457OS-WINDOWS Microsoft Windows gdi32 graphics adapter handling null pointer dereference attempt (more info ...)attempted-admin  2019-1284      URL
51458BROWSER-IE Microsoft Edge print function information disclosure attempt (more info ...)attempted-user  2019-1030      URL
51459BROWSER-IE Microsoft Edge print function information disclosure attempt (more info ...)attempted-user  2019-1030      URL
51463OS-WINDOWS Microsoft Windows elevation of privilege attempt (more info ...)attempted-admin  2019-1256      URL
51464OS-WINDOWS Microsoft Windows elevation of privilege attempt (more info ...)attempted-admin  2019-1256      URL
51474FILE-OTHER Microsoft SharePoint deserialization attempt (more info ...)attempted-admin  2019-1257      URL
51475FILE-OTHER Microsoft SharePoint deserialization attempt (more info ...)attempted-admin  2019-1257      URL
51479FILE-OTHER Microsoft SharePoint remote code execution attempt (more info ...)attempted-admin  2019-1296      URL
51480FILE-OTHER Microsoft SharePoint remote code execution attempt (more info ...)attempted-admin  2019-1296      URL
51481OS-WINDOWS Microsoft Windows RDP client buffer overflow attempt (more info ...)attempted-user  2019-0787      URL
51482FILE-EXECUTABLE Windows Microsoft Remote Desktop Services remote code execution attempt (more info ...)attempted-user  2019-0788      URL
51483FILE-EXECUTABLE Windows Microsoft Remote Desktop Services remote code execution attempt (more info ...)attempted-user  2019-0788      URL
51649OS-WINDOWS Microsoft Windows Remote Desktop Services license negotiation denial of service attempt (more info ...)attempted-dos  2019-1453      URL
51733OS-WINDOWS Microsoft Windows Win32k font file privilege escalation attempt (more info ...)attempted-admin  2019-1364      URL
51734OS-WINDOWS Microsoft Windows Win32k font file privilege escalation attempt (more info ...)attempted-admin  2019-1364      URL
51735BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1335      URL
51736BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1335      URL
51739OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2019-1362      URL
51740OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2019-1362      URL
51777FILE-OTHER Microsoft Windows dismHost.exe dll-load exploit attempt (more info ...)attempted-admin  2019-1082      URL
51781OS-WINDOWS Microsoft Windows registry key deletion privilege escalation attempt (more info ...)attempted-admin  2019-1341      URL
51782OS-WINDOWS Microsoft Windows registry key deletion privilege escalation attempt (more info ...)attempted-admin  2019-1341      URL
51783BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1366      URL
51784BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1366      URL
51785BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1308      URL
51786BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1308      URL
51787BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1307      URL
51788BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2019-1307      URL
51791BROWSER-IE Microsoft Edge VBScript engine memory corruption attempt (more info ...)attempted-user  2019-1238      URL
51792BROWSER-IE Microsoft Edge VBScript engine memory corruption attempt (more info ...)attempted-user  2019-1238      URL
51793BROWSER-IE Microsoft Edge MSXML memory corruption attempt (more info ...)attempted-user  2019-1060      URL
51794BROWSER-IE Microsoft Edge MSXML memory corruption attempt (more info ...)attempted-user  2019-1060      URL
51814BROWSER-IE Microsoft Edge defineGetter type confusion attempt (more info ...)attempted-user  2017-11914      URL
51815BROWSER-IE Microsoft Edge defineGetter type confusion attempt (more info ...)attempted-user  2017-11914      URL
51827OS-WINDOWS Microsoft Windows NT MiRelocateImage out of bounds read attempt (more info ...)attempted-admin  2019-1347      URL
51828OS-WINDOWS Microsoft Windows NT MiRelocateImage out of bounds read attempt (more info ...)attempted-admin  2019-1347      URL
51829OS-WINDOWS Microsoft Windows NT MiRelocateImage out of bounds read attempt (more info ...)attempted-admin  2019-1347      URL
51830OS-WINDOWS Microsoft Windows NT MiRelocateImage out of bounds read attempt (more info ...)attempted-admin  2019-1347      URL
51843OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51844OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51845OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51846OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51847OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51848OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51849OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51850OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51851OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51852OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51853OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51854OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51855OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51856OS-WINDOWS Microsoft Windows NT MiOffsetToProtos NULL pointer dereference attempt (more info ...)attempted-admin  2019-1343      URL
51872OS-WINDOWS Microsoft Windows DLL Load Configuration Directory out of bounds read attempt (more info ...)attempted-admin  2019-1345      URL
51873OS-WINDOWS Microsoft Windows DLL Load Configuration Directory out of bounds read attempt (more info ...)attempted-admin  2019-1345      URL
51874OS-WINDOWS Microsoft Windows DLL Load Configuration Directory out of bounds read attempt (more info ...)attempted-admin  2019-1345      URL
51875OS-WINDOWS Microsoft Windows DLL Load Configuration Directory out of bounds read attempt (more info ...)attempted-admin  2019-1345      URL
51876OS-WINDOWS Microsoft Windows DLL Load Configuration Directory out of bounds read attempt (more info ...)attempted-admin  2019-1345      URL
51877OS-WINDOWS Microsoft Windows DLL Load Configuration Directory out of bounds read attempt (more info ...)attempted-admin  2019-1345      URL
51878OS-WINDOWS Microsoft Windows DLL Load Configuration Directory out of bounds read attempt (more info ...)attempted-admin  2019-1345      URL
51879OS-WINDOWS Microsoft Windows DLL Load Configuration Directory out of bounds read attempt (more info ...)attempted-admin  2019-1345      URL
51882OS-WINDOWS Microsoft Windows NT CipFixImageType out of bounds read attempt (more info ...)attempted-admin  2019-1344      URL
51883OS-WINDOWS Microsoft Windows NT CipFixImageType out of bounds read attempt (more info ...)attempted-admin  2019-1344      URL
51884OS-WINDOWS Microsoft Windows NT CipFixImageType out of bounds read attempt (more info ...)attempted-admin  2019-1344      URL
51885OS-WINDOWS Microsoft Windows NT CipFixImageType out of bounds read attempt (more info ...)attempted-admin  2019-1344      URL
51886OS-WINDOWS Microsoft Windows NT CipFixImageType out of bounds read attempt (more info ...)attempted-admin  2019-1344      URL
51887OS-WINDOWS Microsoft Windows NT CipFixImageType out of bounds read attempt (more info ...)attempted-admin  2019-1344      URL
51888OS-WINDOWS Microsoft Windows NT CipFixImageType out of bounds read attempt (more info ...)attempted-admin  2019-1344      URL
51889OS-WINDOWS Microsoft Windows NT CipFixImageType out of bounds read attempt (more info ...)attempted-admin  2019-1344      URL
51981SERVER-WEBAPP Microsoft Sharepoint DestinationFolder cross site scripting attempt (more info ...)attempted-user  2019-1262      URL
52084BROWSER-IE Microsoft Edge scripting engine Map prototype memory corruption attempt (more info ...)attempted-user  2018-8288      URL
52085BROWSER-IE Microsoft Edge scripting engine Map prototype memory corruption attempt (more info ...)attempted-user  2018-8288      URL
52205OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-admin  2019-1393      URL
52206OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-admin  2019-1393      URL
52207OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-admin  2019-1393      URL
52208OS-WINDOWS Microsoft Windows win32k.sys memory corruption attempt (more info ...)attempted-admin  2019-1393      URL
52209OS-WINDOWS Microsoft Windows vMatchAPal privilege escalation attempt (more info ...)attempted-admin  2019-1394      URL
52210OS-WINDOWS Microsoft Windows vMatchAPal privilege escalation attempt (more info ...)attempted-admin  2019-1394      URL
52211OS-WINDOWS Microsoft Windows vMatchAPal privilege escalation attempt (more info ...)attempted-admin  2019-1394      URL
52212OS-WINDOWS Microsoft Windows vMatchAPal privilege escalation attempt (more info ...)attempted-admin  2019-1394      URL
52213OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2020-1207      URL
52214OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2020-1207      URL
52215OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2019-1396      URL
52216OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2019-1396      URL
52217OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2019-1395      URL
52218OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2019-1395      URL
52219OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2019-1395      URL
52220OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2019-1395      URL
52221OS-WINDOWS Microsoft Windows NtGdiPlgBlt out-of-bounds write attempt (more info ...)attempted-admin  2019-1438      URL
52222OS-WINDOWS Microsoft Windows NtGdiPlgBlt out-of-bounds write attempt (more info ...)attempted-admin  2019-1438      URL
52223OS-WINDOWS Microsoft Windows CRedirectVisualMarshaler privilege escalation attempt (more info ...)attempted-admin  2019-1437      URL
52224OS-WINDOWS Microsoft Windows CRedirectVisualMarshaler privilege escalation attempt (more info ...)attempted-admin  2019-1437      URL
52225OS-WINDOWS Microsoft Windows Win32k printer driver pallet privilege escalation attempt (more info ...)attempted-admin  2019-1408      URL
52226OS-WINDOWS Microsoft Windows Win32k printer driver pallet privilege escalation attempt (more info ...)attempted-admin  2019-1408      URL
52227OS-WINDOWS Microsoft Windows Win32k printer driver pallet privilege escalation attempt (more info ...)attempted-admin  2019-1408      URL
52228OS-WINDOWS Microsoft Windows Win32k printer driver pallet privilege escalation attempt (more info ...)attempted-admin  2019-1408      URL
52229OS-WINDOWS Microsoft Windows GDI glyph bitmap elevation of privilege attempt (more info ...)attempted-admin  2019-1435      URL
52230OS-WINDOWS Microsoft Windows GDI glyph bitmap elevation of privilege attempt (more info ...)attempted-admin  2019-1435      URL
52231OS-WINDOWS Microsoft Windows GDI glyph bitmap elevation of privilege attempt (more info ...)attempted-admin  2019-1435      URL
52232OS-WINDOWS Microsoft Windows GDI glyph bitmap elevation of privilege attempt (more info ...)attempted-admin  2019-1435      URL
52233OS-WINDOWS Microsoft Windows Win32k kernel information disclosure attempt (more info ...)attempted-user  2019-1436      URL
52234OS-WINDOWS Microsoft Windows Win32k kernel information disclosure attempt (more info ...)attempted-user  2019-1436      URL
52333OS-SOLARIS Solaris RPC XDR overflow code execution attempt (more info ...)attempted-admin  2017-3623      URL
52334OS-SOLARIS Solaris RPC XDR overflow code execution attempt (more info ...)attempted-admin  2017-3623      URL
52402BROWSER-IE Microsoft Edge VBScript SafeArray memory corruption attempt (more info ...)attempted-user  2019-1485      URL
52403BROWSER-IE Microsoft Edge VBScript SafeArray memory corruption attempt (more info ...)attempted-user  2019-1485      URL
52419OS-WINDOWS Microsoft Windows win32k information disclosure attempt (more info ...)attempted-admin  2019-1469      URL
52420OS-WINDOWS Microsoft Windows win32k information disclosure attempt (more info ...)attempted-admin  2019-1469      URL
52593OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (more info ...)misc-attack  2020-0601      URL
52594OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (more info ...)misc-attack  2020-0601      URL
52595OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (more info ...)misc-attack  2020-0601      URL
52596OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (more info ...)misc-attack  2020-0601      URL
52604OS-WINDOWS Microsoft Windows clfs.sys local privilege escalation attempt (more info ...)attempted-admin  2020-0634      URL
52605OS-WINDOWS Microsoft Windows clfs.sys local privilege escalation attempt (more info ...)attempted-admin  2020-0634      URL
52610BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2017-11870      URL
52611BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2017-11870      URL
52617OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (more info ...)misc-attack  2020-0601      URL
52618OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (more info ...)misc-attack  2020-0601      URL
52619OS-WINDOWS Microsoft Windows CryptoAPI TLS handshake with spoofed certificate attempt (more info ...)misc-attack  2020-0601      URL
52987BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0767      URL
52989BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user  2018-0767      URL
53047OS-WINDOWS Microsoft Win32k SendMinRectMessages use after free attempt (more info ...)attempted-admin  2020-0726      URL
53048OS-WINDOWS Microsoft Win32k SendMinRectMessages use after free attempt (more info ...)attempted-admin  2020-0726      URL
53050OS-WINDOWS Microsoft Windows win32k.sys rectangle region use after free attempt (more info ...)attempted-admin  2020-0745      URL
53051OS-WINDOWS Microsoft Windows win32k.sys rectangle region use after free attempt (more info ...)attempted-admin  2020-0745      URL
53052OS-WINDOWS Microsoft Windows Win32k driver DestroyThreadsTimers use after free attempt (more info ...)attempted-admin  2020-0720      URL
53053OS-WINDOWS Microsoft Windows Win32k driver DestroyThreadsTimers use after free attempt (more info ...)attempted-admin  2020-0720      URL
53054OS-WINDOWS Microsoft Windows Graphics component privilege escalation attempt (more info ...)attempted-admin  2020-0715      URL
53056OS-WINDOWS Microsoft Windows Remote Desktop client DYNVC PDU handling integer overflow attempt (more info ...)attempted-admin  2020-0681      URL
53072OS-WINDOWS Microsoft Windows win32k use after free privilege escalation attempt (more info ...)attempted-admin  2020-0722      URL
53073OS-WINDOWS Microsoft Windows win32k use after free privilege escalation attempt (more info ...)attempted-admin  2020-0722      URL
53079OS-WINDOWS Microsoft Windows Win32k driver tagQ object use after free attempt (more info ...)attempted-admin  2020-0725      URL
53080OS-WINDOWS Microsoft Windows Win32k driver tagQ object use after free attempt (more info ...)attempted-admin  2020-0725      URL
53082OS-WINDOWS Microsoft Windows Remote Desktop client RDPGFX PDU handling integer overflow attempt (more info ...)attempted-admin  2020-0734      URL
53083OS-WINDOWS Microsoft Windows Remote Desktop client RDPGFX PDU handling integer overflow attempt (more info ...)attempted-admin  2020-0734      URL
53084OS-WINDOWS Microsoft Windows Win32k local privilege escalation attempt (more info ...)attempted-admin  2020-0723      URL
53085OS-WINDOWS Microsoft Windows Win32k local privilege escalation attempt (more info ...)attempted-admin  2020-0723      URL
53086OS-WINDOWS Microsoft Windows Common Log File System Driver memory corruption attempt (more info ...)attempted-admin  2020-0658      URL
53087OS-WINDOWS Microsoft Windows Common Log File System Driver memory corruption attempt (more info ...)attempted-admin  2020-0658      URL
53088OS-WINDOWS Microsoft Windows Common Log File System Driver memory corruption attempt (more info ...)attempted-admin  2020-0658      URL
53089OS-WINDOWS Microsoft Windows Common Log File System Driver memory corruption attempt (more info ...)attempted-admin  2020-0658      URL
53104OS-WINDOWS Microsoft Windows Remote Desktop client PDU parsing integer overflow attempt (more info ...)attempted-admin  2020-0817      URL
53402BROWSER-IE Microsoft Edge Scripting Engine memory corruption attempt (more info ...)attempted-user  2020-0832      URL
53403BROWSER-IE Microsoft Edge Scripting Engine memory corruption attempt (more info ...)attempted-user  2020-0832      URL
53406OS-WINDOWS Microsoft Windows DirectComposition elevation of privilege attempt (more info ...)attempted-admin  2020-0898      URL
53407OS-WINDOWS Microsoft Windows DirectComposition elevation of privilege attempt (more info ...)attempted-admin  2020-0898      URL
53414OS-WINDOWS Microsoft Windows DirectX kernel memory leak attempt (more info ...)attempted-admin  2020-0690      URL
53415OS-WINDOWS Microsoft Windows DirectX kernel memory leak attempt (more info ...)attempted-admin  2020-0690      URL
53416BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-0847      URL
53417BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-0847      URL
53419BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-0824      URL
53420BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-0824      URL
53421OS-WINDOWS Microsoft Windows win32k privilege escalation attempt (more info ...)attempted-admin  2020-0877      URL
53422OS-WINDOWS Microsoft Windows win32k privilege escalation attempt (more info ...)attempted-admin  2020-0877      URL
53423OS-WINDOWS Microsoft Windows win32k privilege escalation attempt (more info ...)attempted-admin  2020-0877      URL
53424OS-WINDOWS Microsoft Windows win32k privilege escalation attempt (more info ...)attempted-admin  2020-0877      URL
53425OS-WINDOWS Microsoft Windows SMB srv2.sys remote code execution attempt (more info ...)attempted-admin  2020-0796      URL
53426OS-WINDOWS Microsoft Windows SMB srv2.sys remote code execution attempt (more info ...)attempted-admin  2020-0796      URL
53427OS-WINDOWS Microsoft Windows SMB srv2.sys remote code execution attempt (more info ...)attempted-admin  2020-0796      URL
53428OS-WINDOWS Microsoft Windows SMB srv2.sys remote code execution attempt (more info ...)attempted-admin  2020-0796      URL
53447OS-WINDOWS Microsoft Windows SMB srv2.sys remote code execution attempt (more info ...)attempted-admin  2020-0796      URL
53448OS-WINDOWS Microsoft Windows SMB srv2.sys remote code execution attempt (more info ...)attempted-admin  2020-0796      URL
53469POLICY-OTHER FreeSWITCH mod_xml_rpc default credential login detected (more info ...)policy-violation  2018-19911      URL
53489FILE-OTHER Microsoft Windows fontdrvhost SetBlendDesignPositions out of bounds write attempt (more info ...)attempted-user  2020-0938      URL
53490FILE-OTHER Microsoft Windows fontdrvhost SetBlendDesignPositions out of bounds write attempt (more info ...)attempted-user  2020-0938      URL
53491FILE-OTHER Microsoft Windows Type 1 font stack overflow attempt (more info ...)attempted-user  2020-1020      URL
53492FILE-OTHER Microsoft Windows Type 1 font stack overflow attempt (more info ...)attempted-user  2020-1020      URL
53529MALWARE-OTHER Win.Malware.Winspy-7644935-0 download attempt (more info ...)trojan-activity        URL
53530MALWARE-OTHER Win.Malware.Winspy-7644935-0 download attempt (more info ...)trojan-activity        URL
53621OS-WINDOWS Microsoft Windows DirectX elevation of privilege attempt (more info ...)attempted-admin  2020-0784      URL
53622OS-WINDOWS Microsoft Windows DirectX elevation of privilege attempt (more info ...)attempted-admin  2020-0784      URL
53624BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-0968      URL
53627OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2020-0958      URL
53628OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2020-0958      URL
53629OS-WINDOWS Microsoft Windows Kernel CSRSS privilege escalation attempt (more info ...)attempted-admin  2020-1027      URL
53630OS-WINDOWS Microsoft Windows Kernel CSRSS privilege escalation attempt (more info ...)attempted-admin  2020-1027      URL
53652OS-WINDOWS Microsoft Windows CF_PALETTE privilege escalation attempt (more info ...)attempted-admin  2020-0956      URL
53653OS-WINDOWS Microsoft Windows CF_PALETTE privilege escalation attempt (more info ...)attempted-admin  2020-0956      URL
53654OS-WINDOWS Microsoft Windows 10 Win32k driver elevation of privileges attempt (more info ...)attempted-admin  2020-0957      URL
53655OS-WINDOWS Microsoft Windows 10 Win32k driver elevation of privileges attempt (more info ...)attempted-admin  2020-0957      URL
53866SERVER-WEBAPP Microsoft SharePoint TypeConverter remote code execution attempt (more info ...)attempted-user  2020-0932      URL
53924BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1058      URL
53925BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1058      URL
53926BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1060      URL
53927BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1060      URL
53950OS-WINDOWS Microsoft Windows fontdrvhost remote code execution attempt (more info ...)attempted-admin  2020-1153      URL
53951OS-WINDOWS Microsoft Windows fontdrvhost remote code execution attempt (more info ...)attempted-admin  2020-1153      URL
54191BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1215      URL
54192BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1215      URL
54193BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1214      URL
54194BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1214      URL
54215OS-WINDOWS Microsoft Windows win32k type confusion attempt (more info ...)attempted-admin  2020-1253      URL
54216OS-WINDOWS Microsoft Windows win32k type confusion attempt (more info ...)attempted-admin  2020-1253      URL
54217OS-WINDOWS Microsoft Windows SMB srv2.sys information disclosure attempt (more info ...)attempted-recon  2020-1206      URL
54236BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1219      URL
54237BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1219      URL
54238BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1230      URL
54239BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1230      URL
54240OS-WINDOWS Microsoft Windows SMBv1 remote code execution attempt (more info ...)attempted-admin  2020-1301      URL
54241OS-WINDOWS Microsoft Windows CreateDIBitmap privilege escalation attempt (more info ...)attempted-admin  2020-1247      URL
54242OS-WINDOWS Microsoft Windows CreateDIBitmap privilege escalation attempt (more info ...)attempted-admin  2020-1247      URL
54245BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1260      URL
54246BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1260      URL
54247OS-WINDOWS Microsoft Windows win32k.sys remote code execution attempt (more info ...)attempted-admin  2020-1251      URL
54248OS-WINDOWS Microsoft Windows win32k.sys remote code execution attempt (more info ...)attempted-admin  2020-1251      URL
54249OS-WINDOWS Microsoft Windows kernel security feature bypass attempt (more info ...)attempted-admin  2020-1241      URL
54250OS-WINDOWS Microsoft Windows kernel security feature bypass attempt (more info ...)attempted-admin  2020-1241      URL
54270OS-WINDOWS Microsoft Windows SMB chained compression out of bounds read attempt (more info ...)denial-of-service  2020-1284      URL
54271OS-WINDOWS Microsoft Windows SMB chained compression out of bounds read attempt (more info ...)denial-of-service  2020-1284      URL
54296OS-WINDOWS Microsoft Windows GDI+ printer out of bounds write attempt (more info ...)attempted-user  2020-0986      URL
54297OS-WINDOWS Microsoft Windows GDI+ printer out of bounds write attempt (more info ...)attempted-user  2020-0986      URL
54511SERVER-WEBAPP Microsoft Windows .NET API XML unsafe deserialization attempt (more info ...)attempted-user  2020-1147      URL
54523OS-WINDOWS Microsoft Windows RDP Client remote code execution attempt (more info ...)attempted-user  2020-1374      URL
54528FILE-OTHER Microsoft Windows Address Book Contact file integer overflow attempt (more info ...)attempted-user  2020-1410      URL
54529FILE-OTHER Microsoft Windows Address Book Contact file integer overflow attempt (more info ...)attempted-user  2020-1410      URL
54530FILE-OTHER Microsoft Windows Address Book Contact file integer overflow attempt (more info ...)attempted-user  2020-1410      URL
54531FILE-OTHER Microsoft Windows Address Book Contact file integer overflow attempt (more info ...)attempted-user  2020-1410      URL
54532FILE-OTHER Microsoft Windows Address Book Contact file integer overflow attempt (more info ...)attempted-user  2020-1410      URL
54533FILE-OTHER Microsoft Windows Address Book Contact file integer overflow attempt (more info ...)attempted-user  2020-1410      URL
54534OS-WINDOWS Microsoft Windows null pointer dereference attempt (more info ...)attempted-admin  2020-1399      URL
54535OS-WINDOWS Microsoft Windows null pointer dereference attempt (more info ...)attempted-admin  2020-1399      URL
54629SERVER-WEBAPP Microsoft Windows .NET API XML unsafe deserialization attempt (more info ...)attempted-user  2020-1147      URL
54684SERVER-WEBAPP Microsoft Windows .NET API XML unsafe deserialization attempt (more info ...)attempted-user  2020-1147      URL
54733OS-WINDOWS Microsoft Windows AFD kernel driver privilege escalation attempt (more info ...)attempted-admin  2020-1587      URL
54734OS-WINDOWS Microsoft Windows AFD kernel driver privilege escalation attempt (more info ...)attempted-admin  2020-1587      URL
54737OS-WINDOWS Microsoft Windows GDI privilege escalation attempt (more info ...)attempted-admin  2020-1529      URL
54738OS-WINDOWS Microsoft Windows GDI privilege escalation attempt (more info ...)attempted-admin  2020-1529      URL
54739BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1570      URL
54740BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1570      URL
54743BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1380      URL
54744BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-1380      URL
54745OS-WINDOWS Microsoft Windows GDI elevation of privilege attempt (more info ...)attempted-admin  2020-1480      URL
54746OS-WINDOWS Microsoft Windows GDI elevation of privilege attempt (more info ...)attempted-admin  2020-1480      URL
54753OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-admin  2020-1578      URL
54765OS-WINDOWS Microsoft Windows TCPIP kernel driver use-after-free attempt (more info ...)attempted-admin  2020-1566      URL
54766OS-WINDOWS Microsoft Windows TCPIP kernel driver use-after-free attempt (more info ...)attempted-admin  2020-1566      URL
55143OS-WINDOWS Microsoft Windows win32k kernel driver use after free attempt (more info ...)attempted-admin  2020-1245      URL
55144OS-WINDOWS Microsoft Windows win32k kernel driver use after free attempt (more info ...)attempted-admin  2020-1245      URL
55161OS-WINDOWS Microsoft Windows kernel DirectComposition use after free attempt (more info ...)attempted-user  2020-1152      URL
55162OS-WINDOWS Microsoft Windows kernel DirectComposition use after free attempt (more info ...)attempted-user  2020-1152      URL
55187OS-WINDOWS Microsoft Windows kernel driver escalation of privilege attempt (more info ...)attempted-user  2020-0941      URL
55188OS-WINDOWS Microsoft Windows kernel driver escalation of privilege attempt (more info ...)attempted-user  2020-0941      URL
55703OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerReqChallenge elevation of privilege attempt (more info ...)attempted-admin  2020-1472      URL
55704OS-WINDOWS Microsoft Windows Netlogon crafted NetrServerAuthenticate elevation of privilege attempt (more info ...)attempted-admin  2020-1472      URL
55802OS-WINDOWS Microsoft Windows NetrServerReqChallenge RPC transport sign and seal disabling attempt (more info ...)attempted-admin  2020-1472      URL
55862SERVER-WEBAPP Microsoft SharePoint EntityInstanceIdEncoder remote code execution attempt (more info ...)attempted-user  2019-0604      URL
55922OS-WINDOWS Microsoft Windows Defender privilege escalation attempt (more info ...)attempted-admin  2020-1170      URL
55923OS-WINDOWS Microsoft Windows Defender privilege escalation attempt (more info ...)attempted-admin        URL
55942OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin  2020-16907      URL
55982OS-WINDOWS Microsoft Windows digital signature spoofing attempt (more info ...)attempted-user  2020-16922      URL
55983OS-WINDOWS Microsoft Windows digital signature spoofing attempt (more info ...)attempted-user  2020-16922      URL
55989OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)attempted-admin  2020-16913      URL
55990OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)attempted-admin  2020-16913      URL
55994OS-WINDOWS Microsoft Windows Remote Desktop information disclosure attempt (more info ...)attempted-admin  2020-16896      URL
56134SERVER-WEBAPP Microsoft Sharepoint DataFormWebPart remote code execution attempt (more info ...)attempted-user  2020-16952      URL
56135SERVER-WEBAPP Microsoft Sharepoint DataFormWebPart remote code execution attempt (more info ...)attempted-user  2020-16952      URL
56136SERVER-WEBAPP Microsoft Sharepoint DataFormWebPart remote code execution attempt (more info ...)attempted-user  2020-16952      URL
56230OS-WINDOWS Microsoft Windows Kernel Cryptography Driver privilege escalation attempt (more info ...)attempted-admin  2020-17087      URL
56231OS-WINDOWS Microsoft Windows Kernel Cryptography Driver privilege escalation attempt (more info ...)attempted-admin  2020-17087      URL
56254OS-WINDOWS Microsoft Windows DirectX graphics kernel subsystem privilege escalation attempt (more info ...)attempted-admin  2020-16998      URL
56255OS-WINDOWS Microsoft Windows DirectX graphics kernel subsystem privilege escalation attempt (more info ...)attempted-admin  2020-16998      URL
56259OS-WINDOWS Microsoft Windows Win32k DirectComposition privilege escalation attempt (more info ...)attempted-admin  2020-17057      URL
56260OS-WINDOWS Microsoft Windows Win32k DirectComposition privilege escalation attempt (more info ...)attempted-admin  2020-17057      URL
56261OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2020-17038      URL
56262OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2020-17038      URL
56286BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-17052      URL
56287BROWSER-IE Microsoft Edge memory corruption attempt (more info ...)attempted-user  2020-17052      URL
56290OS-WINDOWS Microsoft Windows malicious Netlogon NetrServerAuthenticate3 request attempt (more info ...)attempted-admin  2020-1472      URL
56295FILE-OTHER Microsoft Windows Common Log Files System driver privilege escalation attempt (more info ...)attempted-admin  2020-17088      URL
56296FILE-OTHER Microsoft Windows Common Log Files System driver privilege escalation attempt (more info ...)attempted-admin  2020-17088      URL
56301OS-WINDOWS Microsoft Windows NFS read procedure remote code execution attempt (more info ...)attempted-admin  2020-17056      URL
56302OS-WINDOWS Microsoft Windows NFS read procedure remote code execution attempt (more info ...)attempted-user  2020-17056      URL
56304SERVER-WEBAPP Microsoft SharePoint remote code execution attempt (more info ...)attempted-user  2020-17061      URL
56305SERVER-WEBAPP Microsoft SharePoint remote code execution attempt (more info ...)attempted-user  2020-17061      URL
56309PROTOCOL-RPC Windows Network File System denial of service attempt (more info ...)attempted-dos  2020-17047      URL
56310PROTOCOL-RPC Windows Network File System RPCSEC_GSS_INIT message attempt (more info ...)misc-activity        
56311OS-WINDOWS Microsoft Windows NFS v3 Server heap overflow denial of service attempt (more info ...)attempted-dos  2020-17051      URL
56312OS-WINDOWS Microsoft Windows NFS v3 Server heap overflow denial of service attempt (more info ...)attempted-dos  2020-17051      URL
56561OS-WINDOWS Microsoft Windows SMB authenticated remote code execution attempt (more info ...)attempted-admin  2020-17096      URL
56562OS-WINDOWS Microsoft Windows SMB authenticated remote code execution attempt (more info ...)attempted-admin  2020-17096      URL
56571OS-WINDOWS Microsoft Windows SMB2 SET_INFO information disclosure attempt (more info ...)attempted-recon  2020-17140      URL
56574BROWSER-OTHER Microsoft Teams mention functionality displayName remote code execution attempt (more info ...)attempted-user  2020-10146      URL
56604SERVER-WEBAPP Microsoft Dynamics NAV remote code execution attempt (more info ...)attempted-admin  2020-17158      URL
56849OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)trojan-activity  2021-1709      URL
56850OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)trojan-activity  2021-1709      URL
56851OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)trojan-activity  2021-1709      URL
56852OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)trojan-activity  2021-1709      URL
56853OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)trojan-activity  2021-1709      URL
56854OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)trojan-activity  2021-1709      URL
56855OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)trojan-activity  2021-1709      URL
56856OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)trojan-activity  2021-1709      URL
56857FILE-EXECUTABLE Microsoft Windows Defender buffer overflow attempt (more info ...)attempted-admin  2021-1647      URL
56858FILE-EXECUTABLE Microsoft Windows Defender buffer overflow attempt (more info ...)attempted-admin  2021-1647      URL
56859FILE-EXECUTABLE Microsoft Windows Defender buffer overflow attempt (more info ...)attempted-admin  2021-1647      URL
56860FILE-EXECUTABLE Microsoft Windows Defender buffer overflow attempt (more info ...)attempted-admin  2021-1647      URL
56865SERVER-OTHER Microsoft Sharepoint Server remote code execution attempt (more info ...)attempted-user  2021-1707      URL
57104OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-user  2021-1732      URL
57106OS-WINDOWS Microsoft Win32k Windows privilege escalation attempt (more info ...)attempted-admin  2021-1698      URL
57107OS-WINDOWS Microsoft Win32k Windows privilege escalation attempt (more info ...)attempted-admin  2021-1698      URL
57108SERVER-WEBAPP Microsoft SharePoint Server XML external entity injection attempt (more info ...)web-application-attack  2021-24072      URL
57136NETBIOS TRUFFLEHUNTER TALOS-2021-1246 attack attempt (more info ...)attempted-admin        URL
57232NETBIOS TRUFFLEHUNTER TALOS-2021-1258 attack attempt (more info ...)attempted-admin        URL
57259OS-WINDOWS Microsoft Windows DirectX kernel driver use after free attempt (more info ...)attempted-admin  2021-24095      URL
57260OS-WINDOWS Microsoft Windows DirectX kernel driver use after free attempt (more info ...)attempted-admin  2021-24095      URL
57261OS-WINDOWS Microsoft Windows Graphics Component privilege escalation attempt (more info ...)attempted-admin  2021-26868      URL
57262OS-WINDOWS Microsoft Windows Graphics Component privilege escalation attempt (more info ...)attempted-admin  2021-26868      URL
57263OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2021-26863      URL
57264OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2021-26863      URL
57265NETBIOS TRUFFLEHUNTER TALOS-2021-1263 attack attempt (more info ...)attempted-dos        URL
57279OS-WINDOWS Microsoft Windows Netlogon DCERPC over SMB NetrServerAuthenticate failed elevation of privilege attempt (more info ...)attempted-admin  2020-1472      URL
57280OS-WINDOWS Microsoft Windows Netlogon NetrServerAuthenticate failed elevation of privilege attempt (more info ...)attempted-admin  2020-1472      URL
57281OS-WINDOWS Microsoft Windows Netlogon NetrServerAuthenticate failed elevation of privilege attempt (more info ...)attempted-admin  2020-1472      URL
57310NETBIOS TRUFFLEHUNTER TALOS-2021-1268 attack attempt (more info ...)attempted-recon        URL
57347OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2021-1732      URL
57348OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2021-1732      URL
57386BROWSER-IE Microsoft Edge Chakra scripting engine memory corruption attempt (more info ...)attempted-user  2018-0770      URL
57387BROWSER-IE Microsoft Edge Chakra scripting engine memory corruption attempt (more info ...)attempted-user  2018-0770      URL
57403OS-WINDOWS Microsoft Windows win32k elevation of privilege attempt (more info ...)attempted-admin  2021-28310      URL
57404OS-WINDOWS Microsoft Windows win32k elevation of privilege attempt (more info ...)attempted-admin  2021-28310      URL
57549OS-WINDOWS Microsoft Windows HTTP protocol stack remote code execution attempt (more info ...)attempted-user  2021-31166      URL
57550OS-WINDOWS Microsoft Windows HTTP protocol stack remote code execution attempt (more info ...)attempted-user  2021-31166      URL
57605OS-WINDOWS Microsoft Windows HTTP protocol stack remote code execution attempt (more info ...)attempted-user  2022-21907      URL
57722OS-WINDOWS Microsoft Windows kernel privilege escalation attempt (more info ...)attempted-admin  2021-31952      URL
57723OS-WINDOWS Microsoft Windows kernel privilege escalation attempt (more info ...)attempted-admin  2021-31952      URL
57724OS-WINDOWS Microsoft Windows cryptographic API integer overflow attempt (more info ...)attempted-admin  2021-31199      URL
57725OS-WINDOWS Microsoft Windows cryptographic API integer overflow attempt (more info ...)attempted-admin  2021-31199      URL
57726OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-admin  2021-31955      URL
57727OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-admin  2021-31955      URL
57730OS-WINDOWS Microsoft Windows dssenh.dll privilege escalation attempt (more info ...)attempted-admin  2021-31201      URL
57731OS-WINDOWS Microsoft Windows dssenh.dll privilege escalation attempt (more info ...)attempted-admin  2021-31201      URL
57734OS-WINDOWS Microsoft Windows common log file system driver elevation of privilege attempt (more info ...)attempted-admin  2021-31954      URL
57735OS-WINDOWS Microsoft Windows common log file system driver elevation of privilege attempt (more info ...)attempted-admin  2021-31954      URL
57736OS-WINDOWS Microsoft Windows Dynamic Window Manager privilege escalation attempt (more info ...)attempted-admin  2021-33739      URL
57737OS-WINDOWS Microsoft Windows Dynamic Window Manager privilege escalation attempt (more info ...)attempted-admin  2021-33739      URL
57876OS-WINDOWS Microsoft Windows Print Spooler remote code execution attempt (more info ...)attempted-admin  2021-34527      URL
57877OS-WINDOWS Microsoft Windows Print Spooler remote code execution attempt (more info ...)attempted-admin  2021-34527      URL
57951OS-WINDOWS Microsoft Windows SAM database improper ACLs elevation of privilege attempt (more info ...)attempted-admin  2021-36934      URL
57965OS-WINDOWS Microsoft Windows EFSRPC bind detected (more info ...)protocol-command-decode  2021-36942      URL
57966OS-WINDOWS Microsoft Windows NTLM relay attack attempt (more info ...)attempted-user  2021-36942      URL
58004OS-WINDOWS Microsoft Windows BITS privilege escalation attempt (more info ...)attempted-admin  2020-0787      URL
58005OS-WINDOWS Microsoft Windows BITS privilege escalation attempt (more info ...)attempted-admin  2020-0787      URL
58011OS-WINDOWS Microsoft Windows Update Medic service elevation of privilege attempt (more info ...)attempted-user  2021-36948      URL
58012OS-WINDOWS Microsoft Windows Update Medic service elevation of privilege attempt (more info ...)attempted-user  2021-36948      URL
58111SERVER-WEBAPP Microsoft SharePoint remote code execution attempt (more info ...)attempted-user  2021-28474      URL
58112SERVER-WEBAPP Microsoft SharePoint remote code execution attempt (more info ...)attempted-user  2021-28474      URL
58114OS-WINDOWS Microsoft Windows EFSRPC bind detected (more info ...)protocol-command-decode  2021-36942      URL
58136OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)attempted-user  2021-36975      URL
58137OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)attempted-user  2021-36975      URL
58140OS-WINDOWS Microsoft Windows CLFS local privilege escalation attempt (more info ...)attempted-admin  2021-38633      URL
58141OS-WINDOWS Microsoft Windows CLFS local privilege escalation attempt (more info ...)attempted-admin  2021-38633      URL
58169SERVER-WEBAPP Microsoft Windows Open Management Infrastructure remote code execution attempt (more info ...)web-application-attack  2021-38647      
58196OS-WINDOWS Microsoft Windows Common Log File System Driver privilege escalation attempt (more info ...)attempted-admin  2021-36955      URL
58197OS-WINDOWS Microsoft Windows Common Log File System Driver privilege escalation attempt (more info ...)attempted-admin  2021-36955      URL
58198OS-WINDOWS Microsoft Windows Common Log File System Driver privilege escalation attempt (more info ...)attempted-admin  2021-36955      URL
58199OS-WINDOWS Microsoft Windows Common Log File System Driver privilege escalation attempt (more info ...)attempted-admin  2021-36955      URL
58286OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2021-41357      URL
58287OS-WINDOWS Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-admin  2021-41357      URL
58288OS-WINDOWS Microsoft Windows Win32k elevation of privilege exploit download attempt (more info ...)attempted-admin  2021-40449      URL
58294OS-WINDOWS Microsoft DirectX graphics kernel privilege escalation attempt (more info ...)attempted-admin  2021-40470      URL
58295OS-WINDOWS Microsoft DirectX graphics kernel privilege escalation attempt (more info ...)attempted-admin  2021-40470      URL
58305OS-WINDOWS Microsoft Windows Common Log File System driver privilege escalation attempt (more info ...)attempted-admin  2021-40467      URL
58306OS-WINDOWS Microsoft Windows Common Log File System driver privilege escalation attempt (more info ...)attempted-admin  2021-40467      URL
58308OS-WINDOWS Microsoft Windows CLFS kernel driver buffer overflow attempt (more info ...)attempted-user  2021-40466      URL
58309OS-WINDOWS Microsoft Windows CLFS kernel driver buffer overflow attempt (more info ...)attempted-user  2021-40466      URL
58310OS-WINDOWS Microsoft Windows 10 Win32k elevation of privilege attempt (more info ...)attempted-admin  2021-40450      URL
58311OS-WINDOWS Microsoft Windows 10 Win32k elevation of privilege attempt (more info ...)attempted-admin  2021-40450      URL
58312OS-WINDOWS Microsoft Windows 10 Win32k elevation of privilege attempt (more info ...)attempted-admin  2021-40450      URL
58313OS-WINDOWS Microsoft Windows 10 Win32k elevation of privilege attempt (more info ...)attempted-admin  2021-40450      URL
58314SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt (more info ...)web-application-attack  2021-40487      URL
58315SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt (more info ...)web-application-attack  2021-40487      URL
58316SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt (more info ...)web-application-attack  2021-40487      URL
58317SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt (more info ...)web-application-attack  2021-40487      URL
58318SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt (more info ...)web-application-attack  2021-40487      URL
58319SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt (more info ...)web-application-attack  2021-40487      URL
58519BROWSER-IE Microsoft Defender memory corruption attempt (more info ...)attempted-user  2021-42298      URL
58520BROWSER-IE Microsoft Defender memory corruption attempt (more info ...)attempted-user  2021-42298      URL
58586OS-WINDOWS Microsoft Windows Installer elevation of privilege attempt (more info ...)attempted-admin  2020-0683      URL
58615OS-WINDOWS Microsoft Windows Content-Disposition CLSID command attempt (more info ...)attempted-user  2004-0420  9510    URL
58616OS-WINDOWS Microsoft Windows Content-Disposition CLSID command attempt (more info ...)attempted-user  2004-0420  9510    URL
58617OS-WINDOWS Microsoft Windows Content-Disposition CLSID command attempt (more info ...)attempted-user  2004-0420  9510    URL
58635OS-WINDOWS Microsoft Windows Installer privilege escalation attempt (more info ...)attempted-admin  2021-43883      URL
58636OS-WINDOWS Microsoft Windows Installer privilege escalation attempt (more info ...)attempted-admin  2021-43883      URL
58753OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2021-41333      URL
58754OS-WINDOWS Microsoft Windows Common Log File System Driver elevation of privilege attempt (more info ...)attempted-admin  2021-43226      URL
58755OS-WINDOWS Microsoft Windows Common Log File System Driver elevation of privilege attempt (more info ...)attempted-admin  2021-43226      URL
58756OS-WINDOWS Microsoft Windows Common Log File System Driver elevation of privilege attempt (more info ...)attempted-admin  2021-43226      URL
58757OS-WINDOWS Microsoft Windows Common Log File System Driver elevation of privilege attempt (more info ...)attempted-admin  2021-43226      URL
58774OS-WINDOWS Microsoft Windows Remote Desktop Protocol remote code execution attempt (more info ...)attempted-user  2021-43233      URL
58775OS-WINDOWS Microsoft Windows Common Log File System driver privilege escalation attempt (more info ...)attempted-admin  2021-43207      URL
58776OS-WINDOWS Microsoft Windows Common Log File System driver privilege escalation attempt (more info ...)attempted-admin  2021-43207      URL
58859OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin  2022-21882      URL
58860OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin  2022-21882      URL
58866OS-WINDOWS Microsoft Windows kernel elevation of privilege attempt (more info ...)attempted-admin  2022-21881      URL
58867OS-WINDOWS Microsoft Windows kernel elevation of privilege attempt (more info ...)attempted-admin  2022-21881      URL
58868OS-WINDOWS Microsoft Windows privilege escalation via path redirection attempt (more info ...)attempted-admin  2022-21919      URL
58869OS-WINDOWS Microsoft Windows privilege escalation via path redirection attempt (more info ...)attempted-admin  2022-21919      URL
58870OS-WINDOWS Microsoft Windows 10 elevation of privilege attempt (more info ...)attempted-user  2022-21908      URL
58871OS-WINDOWS Microsoft Windows 10 elevation of privilege attempt (more info ...)attempted-user  2022-21908      URL
58872OS-WINDOWS Microsoft Windows Common Log File System driver privilege escalation attempt (more info ...)attempted-admin  2022-21916      URL
58873OS-WINDOWS Microsoft Windows Common Log File System driver privilege escalation attempt (more info ...)attempted-admin  2022-21916      URL
58874OS-WINDOWS Microsoft Windows kernel elevation of privilege attempt (more info ...)attempted-admin  2022-21887      URL
58875OS-WINDOWS Microsoft Windows kernel elevation of privilege attempt (more info ...)attempted-admin  2022-21887      URL
58993OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2022-22718      URL
58994OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2022-22718      URL
58999OS-WINDOWS Microsoft Windows Desktop Window Manager type confusion attempt (more info ...)attempted-admin  2022-21994      URL
59000OS-WINDOWS Microsoft Windows Desktop Window Manager type confusion attempt (more info ...)attempted-admin  2022-21994      URL
59001OS-WINDOWS Microsoft Windows Kernel privilege escalation attempt (more info ...)attempted-admin  2022-21989      URL
59002OS-WINDOWS Microsoft Windows Kernel privilege escalation attempt (more info ...)attempted-admin  2022-21989      URL
59004OS-WINDOWS Microsoft Windows NPFS file system privilege escalation attempt (more info ...)attempted-user  2022-22715      URL
59005OS-WINDOWS Microsoft Windows NPFS file system privilege escalation attempt (more info ...)attempted-user  2022-22715      URL
59008OS-WINDOWS Microsoft Windows win32k local privilege escalation attempt (more info ...)attempted-admin  2022-21996      URL
59009OS-WINDOWS Microsoft Windows win32k local privilege escalation attempt (more info ...)attempted-admin  2022-21996      URL
59052OS-WINDOWS Microsoft Windows AD DS potential elevation of privilege attempt (more info ...)attempted-admin  2021-42291      URL
59107OS-WINDOWS Microsoft Windows RDP path redirection remote code execution attempt (more info ...)attempted-admin  2022-21990      URL
59108OS-WINDOWS Microsoft Windows RDP path redirection remote code execution attempt (more info ...)attempted-admin  2022-21990      URL
59212OS-WINDOWS Microsoft Windows PPTP denial-of-service attempt (more info ...)denial-of-service  2022-23253      URL
59213OS-WINDOWS Microsoft Windows Cloud Files Mini Filter driver elevation of privilege attempt (more info ...)attempted-admin  2022-23286      URL
59214OS-WINDOWS Microsoft Windows Cloud Files Mini Filter driver elevation of privilege attempt (more info ...)attempted-admin  2022-23286      URL
59215OS-WINDOWS Microsoft Windows Remote Desktop client remote code execution attempt (more info ...)attempted-user  2022-23285      URL
59220OS-WINDOWS Microsoft Windows Winsock local privilege escalation attempt (more info ...)attempted-admin  2022-24507      URL
59221OS-WINDOWS Microsoft Windows Winsock local privilege escalation attempt (more info ...)attempted-admin  2022-24507      URL
59476SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-user  2019-3975      URL
59477SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-user  2019-3953      URL
59492FILE-OTHER Microsoft Windows GDI memory corruption attempt (more info ...)attempted-user  2018-8472      URL
59493FILE-OTHER Microsoft Windows GDI memory corruption attempt (more info ...)attempted-admin  2018-8472      URL
59497OS-WINDOWS Microsoft Windows Win32k escalation of privileges attempt (more info ...)attempted-admin  2022-24474      URL
59498OS-WINDOWS Microsoft Windows Win32k escalation of privileges attempt (more info ...)attempted-admin  2022-24474      URL
59502OS-WINDOWS Microsoft Windows Server 2003 smart card authentication buffer overflow attempt (more info ...)attempted-admin  2017-9073      URL
59511OS-WINDOWS Microsoft Windows User Profile Service privilege escalation attempt (more info ...)attempted-admin  2022-26904      URL
59512OS-WINDOWS Microsoft Windows User Profile Service privilege escalation attempt (more info ...)attempted-admin  2022-26904      URL
59519OS-WINDOWS Microsoft Windows win32k.sys driver local privilege escalation attempt (more info ...)attempted-admin  2022-26914      URL
59520OS-WINDOWS Microsoft Windows win32k.sys driver local privilege escalation attempt (more info ...)attempted-admin  2022-26914      URL
59521OS-WINDOWS Microsoft Windows CLFS driver local privilege escalation attempt (more info ...)attempted-admin  2022-24481      URL
59522OS-WINDOWS Microsoft Windows CLFS driver local privilege escalation attempt (more info ...)attempted-admin  2022-24481      URL
59523FILE-OTHER Microsoft Windows CLFS driver privilege escalation attempt (more info ...)attempted-admin  2022-24521      URL
59524FILE-OTHER Microsoft Windows CLFS driver privilege escalation attempt (more info ...)attempted-admin  2022-24521      URL
59531OS-WINDOWS Microsoft Windows Digital Media Receiver privilege escalation attempt (more info ...)attempted-admin  2022-24547      URL
59532OS-WINDOWS Microsoft Windows Digital Media Receiver privilege escalation attempt (more info ...)attempted-admin  2022-24547      URL
59533OS-WINDOWS Microsoft Windows Server portmap.sys out of bounds write attempt (more info ...)attempted-admin  2022-24497      URL
59534OS-WINDOWS Microsoft Windows Server portmap.sys out of bounds write attempt (more info ...)attempted-admin  2022-24491      URL
59535OS-WINDOWS Microsoft Windows Server portmap.sys out of bounds write attempt (more info ...)attempted-admin  2022-24491      URL
59614SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-user  2019-3954      URL
59726OS-WINDOWS Microsoft Windows Kernel Point-to-Point Tunneling Protocol remote code execution attempt (more info ...)attempted-admin  2022-23270      URL
59727OS-WINDOWS Microsoft Windows ALPC privilege escalation attempt (more info ...)attempted-admin  2022-23279      URL
59728OS-WINDOWS Microsoft Windows ALPC privilege escalation attempt (more info ...)attempted-admin  2022-23279      URL
59733OS-WINDOWS Microsoft Windows win32k local privilege escalation attempt (more info ...)attempted-admin  2022-29142      URL
59734OS-WINDOWS Microsoft Windows win32k local privilege escalation attempt (more info ...)attempted-admin  2022-29142      URL
59737OS-WINDOWS Microsoft Windows LSA authentication spoofing attempt (more info ...)attempted-user  2022-26925      URL
59739PROTOCOL-RPC Portmapper NLM GETADDR call attempt (more info ...)attempted-admin  2022-26937      URL
59741PROTOCOL-RPC Portmapper NLM GETADDR call attempt (more info ...)attempted-admin  2022-26937      URL
59889OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (more info ...)attempted-user  2022-30190      URL
59890OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (more info ...)attempted-user  2022-30190      URL
59891OS-WINDOWS Microsoft Support Diagnostic Tool remote code execution attempt (more info ...)attempted-user  2022-30190      URL
59892OS-WINDOWS Microsoft Support Diagnostic Tool remote code execution attempt (more info ...)attempted-user  2022-30190      URL
59893OS-WINDOWS Microsoft Support Diagnostic Tool remote code execution attempt (more info ...)attempted-user  2022-30190      URL
59894OS-WINDOWS Microsoft Support Diagnostic Tool remote code execution attempt (more info ...)attempted-user  2022-30190      URL
59919OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (more info ...)attempted-user  2022-30190      URL
59920OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (more info ...)attempted-user  2022-30190      URL
59949OS-WINDOWS Microsoft Support Diagnostic Tool remote code execution attempt (more info ...)attempted-user  2022-30190      URL
59950OS-WINDOWS Microsoft Support Diagnostic Tool remote code execution attempt (more info ...)attempted-user  2022-30190      URL
59967OS-WINDOWS Microsoft Windows Installer privilege escalation attempt (more info ...)attempted-admin  2022-30147      URL
59968OS-WINDOWS Microsoft Windows Installer privilege escalation attempt (more info ...)attempted-admin  2022-30147      URL
59971OS-WINDOWS Microsoft Windows Advanced Local Procedure Call elevation of privilege attempt (more info ...)attempted-admin  2022-30160      URL
59972OS-WINDOWS Microsoft Windows Advanced Local Procedure Call elevation of privilege attempt (more info ...)attempted-admin  2022-30160      URL
60117SERVER-WEBAPP Microsoft SharePoint Workflow XOML injection attempt (more info ...)web-application-attack  2020-0646      URL
60191OS-WINDOWS Microsoft Windows storage elevation of privilege attempt (more info ...)attempted-admin  2022-30220      URL
60192OS-WINDOWS Microsoft Windows storage elevation of privilege attempt (more info ...)attempted-admin  2022-30220      URL
60198OS-WINDOWS Microsoft Windows Advanced Local Procedure Call elevation of privilege attempt (more info ...)attempted-admin  2022-30202      URL
60199OS-WINDOWS Microsoft Windows Advanced Local Procedure Call elevation of privilege attempt (more info ...)attempted-admin  2022-30202      URL
60201OS-WINDOWS Microsoft Windows Server Service tampering attempt (more info ...)attempted-user  2022-30216      URL
60202OS-WINDOWS Microsoft Windows Server Service tampering attempt (more info ...)attempted-user  2022-30216      URL
60203OS-WINDOWS Microsoft Windows SRVSVC bind detected (more info ...)protocol-command-decode        
60206OS-WINDOWS Microsoft Windows Graphics Component elevation of privilege attempt (more info ...)attempted-admin  2022-22034      URL
60207OS-WINDOWS Microsoft Windows Graphics Component elevation of privilege attempt (more info ...)attempted-admin  2022-22034      URL
60213OS-WINDOWS Microsoft Windows CSRS subsytem elevation of privilege attempt (more info ...)attempted-admin  2022-22047      URL
60214OS-WINDOWS Microsoft Windows CSRS subsytem elevation of privilege attempt (more info ...)attempted-admin  2022-22047      URL
60314OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2022-21999      URL
60315OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2022-21999      URL
60316OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2022-21999      URL
60317OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2022-21999      URL
60371OS-WINDOWS Microsoft Windows Print Spooler privilege escalation attempt (more info ...)attempted-admin  2022-35755      URL
60372OS-WINDOWS Microsoft Windows Print Spooler privilege escalation attempt (more info ...)attempted-admin  2022-35755      URL
60373OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (more info ...)attempted-admin  2022-35761      URL
60374OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (more info ...)attempted-admin  2022-35761      URL
60375OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2022-35793      URL
60376OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2022-35793      URL
60382OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-35750      URL
60383OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-35750      URL
60384OS-WINDOWS Microsoft Windows Support Diagnostic Tool directory traversal attempt (more info ...)attempted-user  2022-34713      URL
60386OS-WINDOWS Microsoft Windows Hyper-V elevation of privilege attempt (more info ...)attempted-admin  2022-35751      URL
60387OS-WINDOWS Microsoft Windows Hyper-V elevation of privilege attempt (more info ...)attempted-admin  2022-35751      URL
60429OS-WINDOWS Microsoft Windows Event Tracing privilege escalation attempt (more info ...)attempted-admin  2021-34486      URL
60430OS-WINDOWS Microsoft Windows Event Tracing privilege escalation attempt (more info ...)attempted-admin  2021-34486      URL
60478OS-WINDOWS Microsoft Windows Runtime remote code execution attempt (more info ...)attempted-user  2022-21971      URL
60479OS-WINDOWS Microsoft Windows Runtime remote code execution attempt (more info ...)attempted-user  2022-21971      URL
60546OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2022-37957      URL
60547OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2022-37957      URL
60549OS-WINDOWS Microsoft Windows GDI elevation of privilege attempt (more info ...)attempted-admin  2022-34729      URL
60550OS-WINDOWS Microsoft Windows GDI elevation of privilege attempt (more info ...)attempted-admin  2022-34729      URL
60646OS-WINDOWS Microsoft Windows IKE remote code execution attempt (more info ...)attempted-user  2022-34721      URL
60693OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-38050      URL
60694OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-38050      URL
60695OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-38050      URL
60696OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-38050      URL
60700OS-WINDOWS Microsoft Windows Perception Simulation service remote code execution attempt (more info ...)attempted-user  2022-37974      URL
60701OS-WINDOWS Microsoft Windows Perception Simulation service remote code execution attempt (more info ...)attempted-user  2022-37974      URL
60704OS-WINDOWS Microsoft Windows Client-Server Runtime Subsystem privilege escalation attempt (more info ...)attempted-admin  2022-37989      URL
60705OS-WINDOWS Microsoft Windows Client-Server Runtime Subsystem privilege escalation attempt (more info ...)attempted-admin  2022-37989      URL
60706OS-WINDOWS Microsoft Windows Client-Server Runtime Subsystem privilege escalation attempt (more info ...)attempted-admin  2022-37987      URL
60707OS-WINDOWS Microsoft Windows Client-Server Runtime Subsystem privilege escalation attempt (more info ...)attempted-admin  2022-37987      URL
60815OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-41109      URL
60816OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-41109      URL
60820OS-WINDOWS Microsoft Windows DWM core library elevation of privilege attempt (more info ...)attempted-admin  2022-41096      URL
60821OS-WINDOWS Microsoft Windows DWM core library elevation of privilege attempt (more info ...)attempted-admin  2022-41096      URL
60822OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt (more info ...)attempted-admin  2022-41057      URL
60823OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt (more info ...)attempted-admin  2022-41057      URL
60831OS-WINDOWS Microsoft Windows CNG Key Isolation Service elevation of privilege attempt (more info ...)attempted-admin  2022-41125      URL
60832OS-WINDOWS Microsoft Windows CNG Key Isolation Service elevation of privilege attempt (more info ...)attempted-admin  2022-41125      URL
60833BROWSER-IE Microsoft Windows Scripting Engine use-after-free attempt (more info ...)attempted-user  2022-41118      URL
60834BROWSER-IE Microsoft Windows Scripting Engine use-after-free attempt (more info ...)attempted-user  2022-41118      URL
60972OS-WINDOWS Microsoft Windows Client Server Run-Time Subsystem privilege escalation attempt (more info ...)attempted-admin  2022-44673      URL
60973OS-WINDOWS Microsoft Windows Client Server Run-Time Subsystem privilege escalation attempt (more info ...)attempted-admin  2022-44673      URL
60974OS-WINDOWS Microsoft Windows kernel privilege escalation attempt (more info ...)attempted-admin  2022-44683      URL
60975OS-WINDOWS Microsoft Windows kernel privilege escalation attempt (more info ...)attempted-admin  2022-44683      URL
61060OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin  2023-21552      URL
61061OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin  2023-21552      URL
61062OS-WINDOWS Microsoft Windows ALPC privilege escalation attempt (more info ...)attempted-admin  2023-21674      URL
61063OS-WINDOWS Microsoft Windows ALPC privilege escalation attempt (more info ...)attempted-admin  2023-21674      URL
61064OS-WINDOWS Microsoft Windows AFD.sys privilege escalation attempt (more info ...)attempted-admin  2023-21768      URL
61065OS-WINDOWS Microsoft Windows AFD.sys privilege escalation attempt (more info ...)attempted-admin  2023-21768      URL
61099OS-WINDOWS Microsoft Windows malicious LNK file download attempt (more info ...)attempted-user        
61100OS-WINDOWS Microsoft Windows malicious LNK file download attempt (more info ...)attempted-user        
61101OS-WINDOWS Microsoft Windows malicious LNK file download attempt (more info ...)attempted-user        
61102OS-WINDOWS Microsoft Windows malicious LNK file download attempt (more info ...)attempted-user        
61312OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (more info ...)attempted-admin  2023-21688      URL
61313OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (more info ...)attempted-admin  2023-21688      URL
61314OS-WINDOWS Microsoft Windows Graphics Component elevation of privilege attempt (more info ...)attempted-admin  2023-21823      URL
61315OS-WINDOWS Microsoft Windows Graphics Component elevation of privilege attempt (more info ...)attempted-admin  2023-21823      URL
61320OS-WINDOWS Microsoft Windows Common Log File System Driver elevation of privilege attempt (more info ...)attempted-admin  2023-23376      URL
61321OS-WINDOWS Microsoft Windows Common Log File System Driver elevation of privilege attempt (more info ...)attempted-admin  2023-23376      URL
61464OS-WINDOWS Microsoft Windows http.sys elevation of privilege attempt (more info ...)attempted-admin  2023-23410      URL
61465OS-WINDOWS Microsoft Windows http.sys elevation of privilege attempt (more info ...)attempted-admin  2023-23410      URL
61523FILE-IDENTIFY Microsoft OneNote file magic detected (more info ...)misc-activity        
61524FILE-IDENTIFY Microsoft OneNote file magic detected (more info ...)misc-activity        
61554OS-WINDOWS Microsoft Windows AFD.sys privilege escalation attempt (more info ...)attempted-admin  2023-21768      URL
61555OS-WINDOWS Microsoft Windows AFD.sys privilege escalation attempt (more info ...)attempted-admin  2023-21768      URL
61613OS-WINDOWS Microsoft Windows Server L2TP remote code execution attempt (more info ...)attempted-user  2023-28220      URL
61614OS-WINDOWS Microsoft Windows VPN Server rasl2tp.sys remote code execution attempt (more info ...)attempted-user  2023-28219      URL
61615OS-WINDOWS Microsoft Windows AFD.sys privilege escalation attempt (more info ...)attempted-admin  2023-28218      URL
61616OS-WINDOWS Microsoft Windows AFD.sys privilege escalation attempt (more info ...)attempted-admin  2023-28218      URL
61617OS-WINDOWS Microsoft Windows graphics component elevation of privilege attempt (more info ...)attempted-admin  2023-24912      URL
61618OS-WINDOWS Microsoft Windows graphics component elevation of privilege attempt (more info ...)attempted-admin  2023-24912      URL
61619OS-WINDOWS Microsoft Windows MSMQ remote code execution attempt (more info ...)attempted-user  2023-21554      URL
61621SERVER-WEBAPP Microsoft Azure Fabric Explorer cross site scripting attempt (more info ...)web-application-attack  2022-35829      URL
61622SERVER-WEBAPP Microsoft Azure Fabric Explorer cross site scripting attempt (more info ...)web-application-attack  2022-35829      URL
61623SERVER-WEBAPP Microsoft Azure Fabric Explorer cross site scripting attempt (more info ...)web-application-attack  2022-35829      URL
61666FILE-IDENTIFY Microsoft OneNote with embedded structure detected (more info ...)misc-activity        URL
61667FILE-IDENTIFY Microsoft OneNote with embedded structure detected (more info ...)misc-activity        URL
61705OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2023-24902      URL
61706OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2023-24902      URL
61707OS-WINDOWS Microsoft Windows NFS server memory corruption attempt (more info ...)attempted-admin  2023-24941      URL
61718OS-WINDOWS Microsoft Windows Scripting elevation of privilege attempt (more info ...)attempted-admin  2023-29324      URL
61719OS-WINDOWS Microsoft Windows Scripting elevation of privilege attempt (more info ...)attempted-admin  2023-29324      URL
61720SERVER-WEBAPP Microsoft SharePoint WebControls AdRotator NTLM relay attempt (more info ...)attempted-admin  2023-24950      URL
61722OS-WINDOWS Microsoft Windows local privilege escalation attempt (more info ...)attempted-admin  2023-29336      URL
61723OS-WINDOWS Microsoft Windows local privilege escalation attempt (more info ...)attempted-admin  2023-29336      URL
61802FILE-OTHER Microsoft Visual Studio Code Markdown Preview Enhanced extension command injection attempt (more info ...)attempted-user  2022-45025      
61803FILE-OTHER Microsoft Visual Studio Code Markdown Preview Enhanced extension command injection attempt (more info ...)attempted-user  2022-45025      
61893INDICATOR-COMPROMISE Microsoft Windows ntds.dit file exfiltration attempt (more info ...)misc-activity        URL
61894FILE-IDENTIFY Microsoft Extensible Storage Engine database detected (more info ...)misc-activity        
61907OS-WINDOWS Microsoft Windows Cloud Files Mini Filter driver elevation of privilege attempt (more info ...)attempted-admin  2023-29361      URL
61908OS-WINDOWS Microsoft Windows Cloud Files Mini Filter driver elevation of privilege attempt (more info ...)attempted-admin  2023-29361      URL
61909OS-WINDOWS Microsoft Windows GDI elevation of privilege attempt (more info ...)attempted-admin  2023-29358      URL
61910OS-WINDOWS Microsoft Windows GDI elevation of privilege attempt (more info ...)attempted-admin  2023-29358      URL
61911OS-WINDOWS Microsoft Windows User-mode Printer Driver privilege escalation attempt (more info ...)attempted-admin  2023-29371      URL
61912OS-WINDOWS Microsoft Windows User-mode Printer Driver privilege escalation attempt (more info ...)attempted-admin  2023-29371      URL
61915OS-WINDOWS Microsoft Windows TPM device driver elevation of privilege attempt (more info ...)attempted-admin  2023-29360      URL
61916OS-WINDOWS Microsoft Windows TPM device driver elevation of privilege attempt (more info ...)attempted-admin  2023-29360      URL
61937SERVER-WEBAPP Microsoft SharePoint OAuth authentication bypass attempt (more info ...)attempted-admin  2023-29357      URL
61938SERVER-WEBAPP Microsoft SharePoint OAuth authentication bypass attempt (more info ...)attempted-admin  2023-29357      URL
61939SERVER-WEBAPP Microsoft SharePoint OAuth authentication bypass attempt (more info ...)attempted-admin  2023-29357      URL
62012SERVER-WEBAPP Microsoft SharePoint remote code execution attempt (more info ...)attempted-user  2023-33157      URL
62022OS-WINDOWS Microsoft Windows MSHTML platform elevation of privilege attempt (more info ...)attempted-admin  2023-32046      URL
62023OS-WINDOWS Microsoft Windows MSHTML platform elevation of privilege attempt (more info ...)attempted-admin  2023-32046      URL
62024OS-WINDOWS Microsoft Windows MSHTML platform elevation of privilege attempt (more info ...)attempted-admin  2023-32046      URL
62025OS-WINDOWS Microsoft Windows MSHTML platform elevation of privilege attempt (more info ...)attempted-admin  2023-32046      URL
62026SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt (more info ...)attempted-admin  2023-33134      URL
62027SERVER-WEBAPP Microsoft SharePoint Server remote code execution attempt (more info ...)attempted-admin  2023-33134      URL
62034OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2023-36874      URL
62035OS-WINDOWS Microsoft Windows privilege escalation attempt (more info ...)attempted-admin  2023-36874      URL


# of warning rules in this group: 2909

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
534NETBIOS SMB CD.. (more info ...)attempted-recon    
535NETBIOS SMB CD... (more info ...)attempted-recon    
572PROTOCOL-RPC DOS ttdbserv Solaris (more info ...)attempted-dos 1999-0003 122  
574PROTOCOL-RPC mountd TCP export request (more info ...)attempted-recon    
575PROTOCOL-RPC portmap admind request UDP (more info ...)rpc-portmap-decode    
577PROTOCOL-RPC portmap bootparam request UDP (more info ...)rpc-portmap-decode    
580PROTOCOL-RPC portmap nisd request UDP (more info ...)rpc-portmap-decode 1999-0008   
581PROTOCOL-RPC portmap pcnfsd request UDP (more info ...)rpc-portmap-decode 2002-0910 4816  
582PROTOCOL-RPC portmap rexd request UDP (more info ...)rpc-portmap-decode    
583PROTOCOL-RPC portmap rstatd request UDP (more info ...)rpc-portmap-decode    
584PROTOCOL-RPC portmap rusers request UDP (more info ...)rpc-portmap-decode 1999-0626   
586PROTOCOL-RPC portmap selection_svc request UDP (more info ...)rpc-portmap-decode 1999-0209 8  
587PROTOCOL-RPC portmap status request UDP (more info ...)rpc-portmap-decode    
588PROTOCOL-RPC portmap ttdbserv request UDP (more info ...)rpc-portmap-decode 2001-0717 3382  URL
589PROTOCOL-RPC portmap yppasswd request UDP (more info ...)rpc-portmap-decode    
590PROTOCOL-RPC portmap ypserv request UDP (more info ...)rpc-portmap-decode 2002-1232 6016  
595PROTOCOL-RPC portmap espd request TCP (more info ...)rpc-portmap-decode 2001-0331 2714  
598PROTOCOL-RPC portmap listing TCP 111 (more info ...)rpc-portmap-decode    
599PROTOCOL-RPC portmap listing TCP 32771 (more info ...)rpc-portmap-decode    
612PROTOCOL-RPC rusers query UDP (more info ...)attempted-recon 1999-0626   
1079OS-WINDOWS Microsoft Windows WebDAV propfind access (more info ...)web-application-activity 2003-0718 1656 10505 URL
1262PROTOCOL-RPC portmap admind request TCP (more info ...)rpc-portmap-decode    
1263PROTOCOL-RPC portmap amountd request TCP (more info ...)rpc-portmap-decode 1999-0704 614  
1264PROTOCOL-RPC portmap bootparam request TCP (more info ...)rpc-portmap-decode    
1265PROTOCOL-RPC portmap cmsd request TCP (more info ...)rpc-portmap-decode    
1267PROTOCOL-RPC portmap nisd request TCP (more info ...)rpc-portmap-decode    
1268PROTOCOL-RPC portmap pcnfsd request TCP (more info ...)rpc-portmap-decode 2002-0910 4816  
1269PROTOCOL-RPC portmap rexd request TCP (more info ...)rpc-portmap-decode    
1270PROTOCOL-RPC portmap rstatd request TCP (more info ...)rpc-portmap-decode    
1271PROTOCOL-RPC portmap rusers request TCP (more info ...)rpc-portmap-decode 1999-0626   
1272PROTOCOL-RPC portmap sadmind request TCP (more info ...)rpc-portmap-decode    
1273PROTOCOL-RPC portmap selection_svc request TCP (more info ...)rpc-portmap-decode 1999-0209 205  
1274PROTOCOL-RPC portmap ttdbserv request TCP (more info ...)rpc-portmap-decode 2001-0717 3382  URL
1275PROTOCOL-RPC portmap yppasswd request TCP (more info ...)rpc-portmap-decode    
1276PROTOCOL-RPC portmap ypserv request TCP (more info ...)rpc-portmap-decode 2002-1232 6016  
1280PROTOCOL-RPC portmap listing UDP 111 (more info ...)rpc-portmap-decode    
1281PROTOCOL-RPC portmap listing UDP 32771 (more info ...)rpc-portmap-decode    
1388OS-WINDOWS Microsoft Windows UPnP Location overflow attempt (more info ...)misc-attack 2007-2386 3723 10829 URL
1447POLICY-OTHER Microsoft Windows Terminal server RDP attempt (more info ...)protocol-command-decode 2001-0663 3099 10940 URL
1732PROTOCOL-RPC portmap rwalld request UDP (more info ...)rpc-portmap-decode 1999-0181 205  
1733PROTOCOL-RPC portmap rwalld request TCP (more info ...)rpc-portmap-decode 1999-0181 205  
1746PROTOCOL-RPC portmap cachefsd request UDP (more info ...)rpc-portmap-decode 2002-0084 4674 10951 
1747PROTOCOL-RPC portmap cachefsd request TCP (more info ...)rpc-portmap-decode 2002-0084 4674 10951 
1890PROTOCOL-RPC status GHBN format string attack (more info ...)misc-attack 2000-0666 1480 10544 
1891PROTOCOL-RPC status GHBN format string attack (more info ...)misc-attack 2000-0666 1480 10544 
1905PROTOCOL-RPC AMD UDP amqproc_mount plog overflow attempt (more info ...)misc-attack 1999-0704 614  
1906PROTOCOL-RPC AMD TCP amqproc_mount plog overflow attempt (more info ...)misc-attack 1999-0704 614  
1907PROTOCOL-RPC CMSD UDP CMSD_CREATE buffer overflow attempt (more info ...)attempted-admin 2009-3699 524  
1908PROTOCOL-RPC CMSD TCP CMSD_CREATE buffer overflow attempt (more info ...)attempted-admin 1999-0696 524  
1909PROTOCOL-RPC CMSD TCP CMSD_INSERT buffer overflow attempt (more info ...)misc-attack 1999-0696 524  URL
1910PROTOCOL-RPC CMSD udp CMSD_INSERT buffer overflow attempt (more info ...)misc-attack 1999-0696   URL
1912PROTOCOL-RPC sadmind TCP NETMGT_PROC_SERVICE CLIENT_DOMAIN overflow attempt (more info ...)attempted-admin 1999-0977 866  
1913PROTOCOL-RPC STATD UDP stat mon_name format string exploit attempt (more info ...)attempted-admin 2000-0666 1480 10544 
1914PROTOCOL-RPC STATD TCP stat mon_name format string exploit attempt (more info ...)attempted-admin 2000-0666 1480 10544 
1915PROTOCOL-RPC STATD UDP monitor mon_name format string exploit attempt (more info ...)attempted-admin 2000-0666 1480 10544 
1916PROTOCOL-RPC STATD TCP monitor mon_name format string exploit attempt (more info ...)attempted-admin 2000-0666 1480 10544 
1922PROTOCOL-RPC portmap proxy attempt TCP (more info ...)rpc-portmap-decode    
1924PROTOCOL-RPC mountd UDP export request (more info ...)attempted-recon    
1925PROTOCOL-RPC mountd TCP exportall request (more info ...)attempted-recon    
1926PROTOCOL-RPC mountd UDP exportall request (more info ...)attempted-recon    
1931SERVER-WEBAPP rpc-nlog.pl access (more info ...)web-application-activity 1999-1278   URL
1932SERVER-WEBAPP rpc-smb.pl access (more info ...)web-application-activity 1999-1278   
1949PROTOCOL-RPC portmap SET attempt TCP 111 (more info ...)rpc-portmap-decode    
1950PROTOCOL-RPC portmap SET attempt UDP 111 (more info ...)rpc-portmap-decode    
1951PROTOCOL-RPC mountd TCP mount request (more info ...)attempted-recon 1999-0210   
1952PROTOCOL-RPC mountd UDP mount request (more info ...)attempted-recon    
1953PROTOCOL-RPC AMD TCP pid request (more info ...)rpc-portmap-decode    
1954PROTOCOL-RPC AMD UDP pid request (more info ...)rpc-portmap-decode    
1955PROTOCOL-RPC AMD TCP version request (more info ...)rpc-portmap-decode    
1956PROTOCOL-RPC AMD UDP version request (more info ...)rpc-portmap-decode 2000-0696 1554  
1957PROTOCOL-RPC sadmind UDP PING (more info ...)protocol-command-decode 1999-0977 866 10229 
1958PROTOCOL-RPC sadmind TCP PING (more info ...)protocol-command-decode 1999-0977 866 10229 
1959PROTOCOL-RPC portmap NFS request UDP (more info ...)rpc-portmap-decode    
1960PROTOCOL-RPC portmap NFS request TCP (more info ...)rpc-portmap-decode    
1961PROTOCOL-RPC portmap RQUOTA request UDP (more info ...)rpc-portmap-decode    
1962PROTOCOL-RPC portmap RQUOTA request TCP (more info ...)rpc-portmap-decode    
1963PROTOCOL-RPC RQUOTA getquota overflow attempt UDP (more info ...)misc-attack 1999-0974 864  
1964PROTOCOL-RPC tooltalk UDP overflow attempt (more info ...)attempted-admin 1999-0003 122  
1965PROTOCOL-RPC tooltalk TCP overflow attempt (more info ...)attempted-admin 2001-0717 122  
2005PROTOCOL-RPC portmap kcms_server request UDP (more info ...)rpc-portmap-decode 2003-0027 6665  URL
2006PROTOCOL-RPC portmap kcms_server request TCP (more info ...)rpc-portmap-decode 2003-0027 6665  URL
2007PROTOCOL-RPC kcms_server directory traversal attempt (more info ...)misc-attack 2003-0027 6665  URL
2014PROTOCOL-RPC portmap UNSET attempt TCP 111 (more info ...)rpc-portmap-decode  1892  
2015PROTOCOL-RPC portmap UNSET attempt UDP 111 (more info ...)rpc-portmap-decode 2011-0321 1892  
2016PROTOCOL-RPC portmap status request TCP (more info ...)rpc-portmap-decode    
2017PROTOCOL-RPC portmap espd request UDP (more info ...)rpc-portmap-decode 2001-0331 2714  
2018PROTOCOL-RPC mountd TCP dump request (more info ...)attempted-recon    
2019PROTOCOL-RPC mountd UDP dump request (more info ...)attempted-recon    
2020PROTOCOL-RPC mountd TCP unmount request (more info ...)attempted-recon    
2021PROTOCOL-RPC mountd UDP unmount request (more info ...)attempted-recon    
2022PROTOCOL-RPC mountd TCP unmountall request (more info ...)attempted-recon    
2023PROTOCOL-RPC mountd UDP unmountall request (more info ...)attempted-recon    
2024PROTOCOL-RPC RQUOTA getquota overflow attempt TCP (more info ...)misc-attack 1999-0974 864  
2025PROTOCOL-RPC yppasswd username overflow attempt UDP (more info ...)rpc-portmap-decode 2001-0779 2763 10684 
2026PROTOCOL-RPC yppasswd username overflow attempt TCP (more info ...)rpc-portmap-decode 2001-0779 2763 10684 
2031PROTOCOL-RPC yppasswd user update UDP (more info ...)rpc-portmap-decode 2001-0779 2763  
2032PROTOCOL-RPC yppasswd user update TCP (more info ...)rpc-portmap-decode 2001-0779 2763  
2033PROTOCOL-RPC ypserv maplist request UDP (more info ...)rpc-portmap-decode 2002-1232 6016 13976 
2034PROTOCOL-RPC ypserv maplist request TCP (more info ...)rpc-portmap-decode 2002-1232 6016  
2035PROTOCOL-RPC portmap network-status-monitor request UDP (more info ...)rpc-portmap-decode    
2036PROTOCOL-RPC portmap network-status-monitor request TCP (more info ...)rpc-portmap-decode    
2037PROTOCOL-RPC network-status-monitor mon-callback request UDP (more info ...)rpc-portmap-decode    
2038PROTOCOL-RPC network-status-monitor mon-callback request TCP (more info ...)rpc-portmap-decode    
2079PROTOCOL-RPC portmap nlockmgr request UDP (more info ...)rpc-portmap-decode 2000-0508 1372 10220 
2080PROTOCOL-RPC portmap nlockmgr request TCP (more info ...)rpc-portmap-decode 2000-0508 1372 10220 
2081PROTOCOL-RPC portmap rpc.xfsmd request UDP (more info ...)rpc-portmap-decode 2002-0359 5075  
2082PROTOCOL-RPC portmap rpc.xfsmd request TCP (more info ...)rpc-portmap-decode 2002-0359 5075  
2083PROTOCOL-RPC rpc.xfsmd xfs_export attempt UDP (more info ...)rpc-portmap-decode 2002-0359 5075  
2084PROTOCOL-RPC rpc.xfsmd xfs_export attempt TCP (more info ...)rpc-portmap-decode 2002-0359 5075  
2092PROTOCOL-RPC portmap proxy integer overflow attempt UDP (more info ...)rpc-portmap-decode 2003-0028 7123 11420 
2093PROTOCOL-RPC portmap proxy integer overflow attempt TCP (more info ...)rpc-portmap-decode 2003-0028 7123 11420 
2094PROTOCOL-RPC CMSD UDP CMSD_CREATE array buffer overflow attempt (more info ...)attempted-admin 2009-3699 5356 11418 
2095PROTOCOL-RPC CMSD TCP CMSD_CREATE array buffer overflow attempt (more info ...)attempted-admin 2002-0391 5356 11418 
2101OS-WINDOWS Microsoft Windows SMB Trans Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
2123INDICATOR-COMPROMISE Microsoft cmd.exe banner (more info ...)successful-admin   11633 
2126OS-WINDOWS Microsoft Windows PPTP Start Control Request buffer overflow attempt (more info ...)attempted-admin 2002-1214 5807 11178 URL
2176OS-WINDOWS Microsoft Windows SMB startup folder access (more info ...)attempted-recon    URL
2177OS-WINDOWS Microsoft Windows SMB startup folder unicode access (more info ...)attempted-recon    URL
2184PROTOCOL-RPC mountd TCP mount path overflow attempt (more info ...)misc-attack 2003-0252 8179 11800 
2190NETBIOS DCERPC invalid bind attempt (more info ...)attempted-dos    
2191NETBIOS SMB DCERPC invalid bind attempt (more info ...)attempted-dos    
2252OS-WINDOWS Microsoft Windows SMB-DS DCERPC Remote Activation bind attempt (more info ...)attempted-admin 2003-0715 8458 11835 URL
2255PROTOCOL-RPC sadmind query with root credentials attempt TCP (more info ...)misc-attack    
2256PROTOCOL-RPC sadmind query with root credentials attempt UDP (more info ...)misc-attack    
2257OS-WINDOWS DCERPC Messenger Service buffer overflow attempt (more info ...)attempted-admin 2003-0717 8826 11890 URL
2258OS-WINDOWS Microsoft Windows SMB-DS DCERPC Messenger Service buffer overflow attempt (more info ...)attempted-admin 2003-0717 8826 11890 URL
2382OS-WINDOWS Microsoft Windows SMB Session Setup NTLMSSP asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
2383OS-WINDOWS Microsoft Windows SMB-DS Session Setup NTLMSSP asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
2401NETBIOS SMB Session Setup andx username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
2402NETBIOS SMB-DS Session Setup andx username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
2403NETBIOS SMB Session Setup unicode username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
2404NETBIOS SMB-DS Session Setup unicode andx username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
2436FILE-IDENTIFY Microsoft Windows Audio wmf file download request (more info ...)misc-activity    URL
2474NETBIOS SMB-DS ADMIN$ share access (more info ...)protocol-command-decode    
2485BROWSER-PLUGINS Symantec Norton Internet Security 2004 ActiveX clsid access (more info ...)attempted-user 2004-0363 9916  
2508OS-WINDOWS DCERPC NCACN-IP-TCP lsass DsRolerUpgradeDownlevelServer overflow attempt (more info ...)attempted-admin 2003-0533 10108 12205 URL
2511OS-WINDOWS DCERPC NCADG-IP-UDP lsass DsRolerUpgradeDownlevelServer overflow attempt (more info ...)attempted-admin 2003-0533 10108 12205 URL
2563NETBIOS NS lookup response name overflow attempt (more info ...)attempted-admin 2004-0444 10333  URL
2564NETBIOS NS lookup short response attempt (more info ...)attempted-admin 2004-0444 10335  URL
2705FILE-IMAGE Microsoft Multiple Products JPEG parser heap overflow attempt (more info ...)attempted-user 2004-0200 11173  URL
2936OS-WINDOWS DCERPC NCACN-IP-TCP nddeapi NDdeSetTrustedShareW overflow attempt (more info ...)attempted-admin 2004-0206 11372  URL
2942NETBIOS DCERPC NCACN-IP-TCP winreg InitiateSystemShutdown attempt (more info ...)protocol-command-decode    URL
3001OS-WINDOWS Microsoft Windows SMB Session Setup NTLMSSP andx asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
3002OS-WINDOWS Microsoft Windows SMB Session Setup NTLMSSP unicode andx asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
3004OS-WINDOWS Microsoft Windows SMB-DS Session Setup NTLMSSP andx asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
3005OS-WINDOWS Microsoft Windows SMB-DS Session Setup NTLMSSP unicode andx asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
3017OS-WINDOWS Microsoft Windows WINS overflow attempt (more info ...)misc-attack 2004-1080 11763  URL
3020NETBIOS SMB NT Trans NT CREATE unicode oversized Security Descriptor attempt (more info ...)protocol-command-decode 2004-1154   
3022NETBIOS SMB-DS NT Trans NT CREATE oversized Security Descriptor attempt (more info ...)protocol-command-decode 2004-1154   
3024NETBIOS SMB-DS NT Trans NT CREATE unicode oversized Security Descriptor attempt (more info ...)protocol-command-decode 2004-1154   
3026NETBIOS SMB NT Trans NT CREATE SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3027NETBIOS SMB NT Trans NT CREATE andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3028NETBIOS SMB NT Trans NT CREATE unicode SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3030NETBIOS SMB-DS NT Trans NT CREATE SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3031NETBIOS SMB-DS NT Trans NT CREATE andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3032NETBIOS SMB-DS NT Trans NT CREATE unicode SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3034NETBIOS SMB NT Trans NT CREATE DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3035NETBIOS SMB NT Trans NT CREATE andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3036NETBIOS SMB NT Trans NT CREATE unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3038NETBIOS SMB-DS NT Trans NT CREATE DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3039NETBIOS SMB-DS NT Trans NT CREATE andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3040NETBIOS SMB-DS NT Trans NT CREATE unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3041NETBIOS SMB-DS NT Trans NT CREATE unicode andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3042NETBIOS SMB NT Trans NT CREATE invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3043NETBIOS SMB NT Trans NT CREATE andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3044NETBIOS SMB NT Trans NT CREATE unicode invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3045NETBIOS SMB NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3046NETBIOS SMB-DS NT Trans NT CREATE invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3047NETBIOS SMB-DS NT Trans NT CREATE andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3048NETBIOS SMB-DS NT Trans NT CREATE unicode invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3049NETBIOS SMB-DS NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3050NETBIOS SMB NT Trans NT CREATE invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3051NETBIOS SMB NT Trans NT CREATE andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3052NETBIOS SMB NT Trans NT CREATE unicode invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3053NETBIOS SMB NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3054NETBIOS SMB-DS NT Trans NT CREATE invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3055NETBIOS SMB-DS NT Trans NT CREATE andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3056NETBIOS SMB-DS NT Trans NT CREATE unicode invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3057NETBIOS SMB-DS NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3132FILE-IMAGE Microsoft and libpng multiple products PNG large image width overflow attempt (more info ...)attempted-user 2007-5503 11523  URL
3133FILE-IMAGE Microsoft Multiple Products PNG large image height download attempt (more info ...)attempted-user 2007-5503 11523  URL
3134FILE-IMAGE Microsoft PNG large colour depth download attempt (more info ...)attempted-user 2004-1244 11523  URL
3135NETBIOS SMB Trans2 QUERY_FILE_INFO attempt (more info ...)protocol-command-decode    
3137NETBIOS SMB-DS Trans2 QUERY_FILE_INFO attempt (more info ...)protocol-command-decode    
3139NETBIOS SMB Trans2 FIND_FIRST2 attempt (more info ...)protocol-command-decode    
3141NETBIOS SMB-DS Trans2 FIND_FIRST2 attempt (more info ...)protocol-command-decode    
3143OS-WINDOWS Microsoft Windows SMB Trans2 FIND_FIRST2 command response overflow attempt (more info ...)protocol-command-decode 2005-0045 12484  URL
3144OS-WINDOWS Microsoft Windows SMB Trans2 FIND_FIRST2 response andx overflow attempt (more info ...)protocol-command-decode 2005-0045 12484  URL
3146OS-WINDOWS Microsoft Windows SMB-DS Trans2 FIND_FIRST2 response andx overflow attempt (more info ...)protocol-command-decode 2005-0045 12484  URL
3158OS-WINDOWS DCERPC NCACN-IP-TCP ISystemActivator CoGetInstanceFromFile attempt (more info ...)protocol-command-decode 2003-0715   URL
3159OS-WINDOWS DCERPC NCADG-IP-UDP ISystemActivator CoGetInstanceFromFile attempt (more info ...)protocol-command-decode 2003-0715   URL
3238OS-WINDOWS DCERPC NCACN-IP-TCP irot IrotIsRunning/Revoke overflow attempt (more info ...)attempted-admin 2002-1561 6005  URL
3239OS-WINDOWS DCERPC NCADG-IP-UDP irot IrotIsRunning/Revoke overflow attempt (more info ...)attempted-admin 2002-1561 6005  URL
3397OS-WINDOWS DCERPC NCACN-IP-TCP ISystemActivator RemoteCreateInstance attempt (more info ...)protocol-command-decode 2003-0715 8205  URL
3398OS-WINDOWS DCERPC NCADG-IP-UDP ISystemActivator RemoteCreateInstance attempt (more info ...)protocol-command-decode 2003-0715 8205  URL
3409OS-WINDOWS DCERPC NCACN-IP-TCP IActivation remoteactivation overflow attempt (more info ...)attempted-admin 2003-0715 8205  URL
3552OS-WINDOWS Microsoft Windows OLE32 MSHTA masquerade attempt (more info ...)attempted-user 2005-0063 13132  URL
3639NETBIOS SMB Trans andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3640NETBIOS SMB Trans data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3641NETBIOS SMB Trans unicode data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3642NETBIOS SMB Trans unicode andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3643NETBIOS SMB-DS Trans andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3644NETBIOS SMB-DS Trans data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3645NETBIOS SMB-DS Trans unicode data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3646NETBIOS SMB-DS Trans unicode andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3647NETBIOS SMB Trans andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3648NETBIOS SMB Trans data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3649NETBIOS SMB Trans unicode data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3650NETBIOS SMB Trans unicode andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode 2005-1470 13504  URL
3673OS-WINDOWS Microsoft SMS remote control client DoS overly long length attempt (more info ...)attempted-user 2004-0728 10726  
3820FILE-IDENTIFY Microsoft Windows CHM file magic detected (more info ...)attempted-user 2005-1208 13953 18482 URL
4145BROWSER-PLUGINS Microsoft Windows Trouble Shooter ActiveX object access (more info ...)attempted-user 2003-0662 8833  URL
4146BROWSER-PLUGINS Share Point Portal Services Log Sink ActiveX object access (more info ...)attempted-user  14515  URL
4151BROWSER-PLUGINS System Monitor Source Properties ActiveX object access (more info ...)attempted-user  7384  
4153BROWSER-PLUGINS Microsoft Windows Eyedog ActiveX object access (more info ...)attempted-user 1999-0669 619  URL
4157BROWSER-PLUGINS MSN Setup BBS 4.71.0.10 ActiveX object access (more info ...)attempted-user 1999-1484 668  
4159BROWSER-PLUGINS Multimedia File Property Sheet ActiveX object access (more info ...)attempted-user 2002-1984 5094  
4160BROWSER-PLUGINS Microsoft Windows Reporting Tool ActiveX object access (more info ...)attempted-user 2003-0530 8454  URL
4161BROWSER-PLUGINS DigWebX MSN ActiveX object access (more info ...)attempted-user  13946  URL
4162BROWSER-PLUGINS DigWebX MSN ActiveX object access (more info ...)attempted-user  13946  URL
4163BROWSER-PLUGINS DigWebX MSN ActiveX object access (more info ...)attempted-user  13946  URL
4164BROWSER-PLUGINS DigWebX MSN ActiveX object access (more info ...)attempted-user  13946  URL
4167BROWSER-PLUGINS MSN Heartbeat ActiveX clsid access (more info ...)attempted-user 2004-0978 11367  URL
4168BROWSER-PLUGINS Shell Automation Service ActiveX object access (more info ...)attempted-user 2004-2291 9335  
4172BROWSER-PLUGINS Microsoft Windows Agent v1.5 ActiveX clsid access (more info ...)attempted-user 2007-1205   URL
4173BROWSER-PLUGINS Microsoft Windows MsnPUpld ActiveX object access (more info ...)attempted-user    URL
4174BROWSER-PLUGINS Symantec RuFSI registry Information Class ActiveX object access (more info ...)attempted-user 2003-0470 8008  URL
4179BROWSER-PLUGINS Microsoft Windows DirectX Files Viewer ActiveX object access (more info ...)attempted-user 2002-0975 5489  URL
4180BROWSER-PLUGINS Kodak Image Scan Control ActiveX object access (more info ...)attempted-user    URL
4181BROWSER-PLUGINS Microsoft Windows Smartcard Enrollment ActiveX object access (more info ...)attempted-user 2002-0699   URL
4182BROWSER-PLUGINS Microsoft MSN Chat v4.5, 4.6 ActiveX object access (more info ...)attempted-user 2002-0155 4707  URL
4183BROWSER-PLUGINS Microsoft Windows HTML Help ActiveX object access (more info ...)attempted-user 2005-1208 13953  URL
4184BROWSER-PLUGINS Microsoft Windows Certificate Enrollment ActiveX object access (more info ...)attempted-user 2002-0699 5593  URL
4185BROWSER-PLUGINS Microsoft Windows Terminal Services Advanced Client ActiveX object access (more info ...)attempted-user 2002-0726 5554  URL
4186BROWSER-PLUGINS Kodak Image Editing ActiveX object access (more info ...)attempted-user    URL
4187BROWSER-PLUGINS Microsoft Windows Terminal Services Advanced Client ActiveX object access (more info ...)attempted-user 2002-0726 5554  URL
4190BROWSER-PLUGINS Kodak Thumbnail Image ActiveX object access (more info ...)attempted-user    URL
4191BROWSER-PLUGINS Microsoft Windows MsnPUpld ActiveX object access (more info ...)attempted-user    URL
4193BROWSER-PLUGINS Kodak Image Editing ActiveX object access (more info ...)attempted-user    URL
4197BROWSER-PLUGINS DigWebX MSN ActiveX object access (more info ...)attempted-user  13946  URL
4202BROWSER-PLUGINS Microsoft Windows DirectAnimation ActiveX object access (more info ...)attempted-user 2005-2127   URL
4219BROWSER-PLUGINS Microsoft Windows Network Connections Tray ActiveX object access (more info ...)attempted-user 2005-2127   URL
4220BROWSER-PLUGINS Microsoft Windows Network and Dial-Up Connections ActiveX object access (more info ...)attempted-user 2005-2127   URL
4228BROWSER-PLUGINS Microsoft Windows Start Menu ActiveX object access (more info ...)attempted-user 2005-2127   URL
4245OS-WINDOWS DCERPC NCACN-IP-TCP msdtc BuildContextW overflow attempt (more info ...)attempted-admin 2005-2119 15056  URL
4246OS-WINDOWS DCERPC NCADG-IP-UDP msdtc BuildContextW overflow attempt (more info ...)attempted-admin 2005-2119 15056  URL
4334OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
4358OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
4413OS-WINDOWS DCERPC NCACN-IP-TCP spoolss AddPrinterEx overflow attempt (more info ...)attempted-admin 2005-1984 14514  URL
4608OS-WINDOWS DCERPC NCACN-IP-TCP netware_cs function 43 overflow attempt (more info ...)attempted-admin 2005-1985 15066  URL
4643OS-WINDOWS Microsoft Windows malformed shortcut file buffer overflow attempt (more info ...)attempted-user 2005-2122 15070  URL
4644OS-WINDOWS Microsoft Windows malformed shortcut file with comment buffer overflow attempt (more info ...)attempted-user 2005-2122 15070  URL
4651NETBIOS SMB NT Trans NT SET SECURITY DESC SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4652NETBIOS SMB NT Trans NT SET SECURITY DESC andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4653NETBIOS SMB NT Trans NT SET SECURITY DESC unicode SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4654NETBIOS SMB NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4655NETBIOS SMB-DS NT Trans NT SET SECURITY DESC SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4656NETBIOS SMB-DS NT Trans NT SET SECURITY DESC andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4657NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4658NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4659NETBIOS SMB NT Trans NT SET SECURITY DESC SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4660NETBIOS SMB NT Trans NT SET SECURITY DESC andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4661NETBIOS SMB NT Trans NT SET SECURITY DESC unicode SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4662NETBIOS SMB NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4663NETBIOS SMB NT Trans NT SET SECURITY DESC DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4664NETBIOS SMB NT Trans NT SET SECURITY DESC andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4665NETBIOS SMB NT Trans NT SET SECURITY DESC unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4666NETBIOS SMB NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4667NETBIOS SMB-DS NT Trans NT SET SECURITY DESC DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4668NETBIOS SMB-DS NT Trans NT SET SECURITY DESC andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4669NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4670NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4671NETBIOS SMB NT Trans NT SET SECURITY DESC DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4672NETBIOS SMB NT Trans NT SET SECURITY DESC andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4673NETBIOS SMB NT Trans NT SET SECURITY DESC unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4674NETBIOS SMB NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4754OS-WINDOWS DCERPC NCACN-IP-TCP locator nsi_binding_lookup_begin overflow attempt (more info ...)attempted-admin 2003-0003 6666  URL
4755OS-WINDOWS DCERPC NCADG-IP-UDP locator nsi_binding_lookup_begin overflow attempt (more info ...)attempted-admin 2003-0003 6666  URL
4826OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetRootDeviceInstance attempt (more info ...)protocol-command-decode 2005-3644 15460  URL
5096OS-WINDOWS DCERPC NCADG-IP-UDP lsass DsRolerGetPrimaryDomainInformation attempt (more info ...)protocol-command-decode 2003-0533 10108 12205 URL
5319OS-WINDOWS Microsoft Windows picture and fax viewer wmf arbitrary code execution attempt (more info ...)web-application-attack 2005-4560 16074  URL
5677NETBIOS SMB Session Setup username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
5678NETBIOS SMB-DS Session Setup username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
5679NETBIOS SMB-DS Session Setup unicode username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
5680NETBIOS SMB Session Setup username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
5681NETBIOS SMB Session Setup unicode username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
5682NETBIOS SMB Session Setup unicode andx username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
5683NETBIOS SMB Session Setup andx username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
5684NETBIOS SMB Session Setup unicode andx username overflow attempt (more info ...)protocol-command-decode 2004-0193 9752  URL
5713OS-WINDOWS Microsoft Windows Metafile invalid header size integer overflow attempt (more info ...)attempted-admin 2006-0020 16516  URL
5717OS-WINDOWS Microsoft Windows SMB-DS Trans Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5719OS-WINDOWS Microsoft Windows SMB Trans Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5720OS-WINDOWS Microsoft Windows SMB Trans unicode Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5721OS-WINDOWS Microsoft Windows SMB Trans andx Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5722OS-WINDOWS Microsoft Windows SMB Trans unicode andx Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5723OS-WINDOWS Microsoft Windows SMB-DS Trans andx Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5724OS-WINDOWS Microsoft Windows SMB-DS Trans unicode andx Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5725OS-WINDOWS Microsoft Windows SMB Trans andx Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5726OS-WINDOWS Microsoft Windows SMB Trans unicode andx Max Param/Count OS-WINDOWS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5727OS-WINDOWS Microsoft Windows SMB Trans unicode Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5728OS-WINDOWS Microsoft Windows SMB Trans Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5729OS-WINDOWS Microsoft Windows SMB Trans Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5730OS-WINDOWS Microsoft Windows SMB-DS Trans Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5731OS-WINDOWS Microsoft Windows SMB-DS Trans unicode Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5732OS-WINDOWS Microsoft Windows SMB Trans unicode Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5733OS-WINDOWS Microsoft Windows SMB Trans unicode andx Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5734OS-WINDOWS Microsoft Windows SMB Trans andx Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5735OS-WINDOWS Microsoft Windows SMB Trans andx Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5736OS-WINDOWS Microsoft Windows SMB-DS Trans andx Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5737OS-WINDOWS Microsoft Windows SMB-DS Trans unicode andx Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5738OS-WINDOWS Microsoft Windows SMB Trans unicode andx Max Param OS-WINDOWS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5740FILE-IDENTIFY Microsoft Windows HTML help workshop file download request (more info ...)misc-activity    URL
5741FILE-OTHER Microsoft HTML help workshop buffer overflow attempt (more info ...)attempted-user 2009-0133   URL
6008BROWSER-PLUGINS Microsoft DT DDS OrgChart GDD Route ActiveX object access (more info ...)attempted-user 2006-1186   URL
6009BROWSER-PLUGINS Microsoft Windows RDS.Dataspace ActiveX object access (more info ...)attempted-user 2006-0003 17462  URL
6412SERVER-MAIL Microsoft Windows Address Book attachment detected (more info ...)misc-activity 2006-2386 17459  URL
6413SERVER-MAIL Microsoft Windows Address Book Base64 encoded attachment detected (more info ...)misc-activity 2006-2386 17459  URL
6419OS-WINDOWS DCERPC NCACN-IP-TCP msdtc BuildContextW invalid uuid size attempt (more info ...)attempted-admin 2006-1184 17905  URL
6420OS-WINDOWS DCERPC NCADG-IP-UDP msdtc BuildContextW invalid uuid size attempt (more info ...)attempted-admin 2006-1184 17905  URL
6431OS-WINDOWS DCERPC NCACN-IP-TCP msdtc BuildContextW heap overflow attempt (more info ...)attempted-admin 2006-1184 17905  URL
6432OS-WINDOWS DCERPC NCADG-IP-UDP msdtc BuildContextW invalid second uuid size attempt (more info ...)attempted-admin 2006-1184 17905  URL
6443OS-WINDOWS DCERPC NCACN-IP-TCP msdtc BuildContextW heap overflow attempt (more info ...)attempted-admin 2006-0034 17906  URL
6444OS-WINDOWS DCERPC NCADG-IP-UDP msdtc BuildContextW heap overflow attempt (more info ...)attempted-admin 2006-0034 17906  URL
6455OS-WINDOWS DCERPC NCACN-IP-TCP msdtc BuildContext heap overflow attempt (more info ...)attempted-admin 2006-0034 17906  URL
6456OS-WINDOWS DCERPC NCADG-IP-UDP msdtc BuildContext heap overflow attempt (more info ...)attempted-admin 2006-0034 17906  URL
6584OS-WINDOWS DCERPC NCACN-IP-TCP rras RasRpcSubmitRequest overflow attempt (more info ...)attempted-admin 2006-2370 18325  URL
6714OS-WINDOWS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences phonebook mode overflow attempt (more info ...)attempted-admin 2006-2371 18358  URL
6810OS-WINDOWS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences area/country overflow attempt (more info ...)attempted-admin 2006-2371 18358  URL
6906OS-WINDOWS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences callback number overflow attempt (more info ...)attempted-admin 2006-2371 18358  URL
7003BROWSER-PLUGINS ADODB.Recordset ActiveX function call access (more info ...)attempted-user 2006-5559 20704  
7006BROWSER-PLUGINS ASControls.InstallEngineCtl ActiveX function call access (more info ...)attempted-user    
7008BROWSER-PLUGINS DirectAnimation.DAUserData ActiveX function call access (more info ...)attempted-user    
7009BROWSER-PLUGINS Microsoft Windows DirectAnimation.StructuredGraphicsControl ActiveX function call access (more info ...)attempted-user 2006-4777   URL
7010BROWSER-PLUGINS HtmlDlgSafeHelper.HtmlDlgSafeHelper.1 ActiveX function call access (more info ...)attempted-user    
7011BROWSER-PLUGINS HtmlDlgSafeHelper.HtmlDlgSafeHelper ActiveX function call access (more info ...)attempted-user    
7012BROWSER-PLUGINS Internet.PopupMenu.1 ActiveX function call access (more info ...)attempted-user    
7013BROWSER-PLUGINS Microsoft.ISCatAdm ActiveX function call access (more info ...)attempted-user 2006-4495   URL
7018BROWSER-PLUGINS Sysmon ActiveX function call access (more info ...)attempted-user    
7022OS-WINDOWS Microsoft Windows Explorer invalid url file overflow attempt (more info ...)denial-of-service 2006-3351 18838  
7035OS-WINDOWS Microsoft Windows SMB Trans mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7036OS-WINDOWS Microsoft Windows SMB Trans unicode mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7037OS-WINDOWS Microsoft Windows SMB Trans mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7038OS-WINDOWS Microsoft Windows SMB Trans unicode mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7039OS-WINDOWS Microsoft Windows SMB Trans andx mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7041OS-WINDOWS Microsoft Windows SMB Trans andx mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7042OS-WINDOWS Microsoft Windows SMB Trans unicode andx mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7210OS-WINDOWS DCERPC NCADG-IP-UDP srvsvc NetrPathCanonicalize overflow attempt (more info ...)attempted-admin 2006-3439 19409  URL
7422OS-WINDOWS Microsoft Windows MMC mmcndmgr.dll cross site scripting attempt (more info ...)attempted-user 2006-3643 19417  URL
7423OS-WINDOWS Microsoft Windows MMC mmc.exe cross site scripting attempt (more info ...)attempted-user 2006-3643 19417  URL
7424OS-WINDOWS Microsoft Windows MMC createcab.cmd cross site scripting attempt (more info ...)attempted-user 2006-3643 19417  URL
7502BROWSER-PLUGINS tsuserex.ADsTSUserEx.1 ActiveX clsid access (more info ...)attempted-user 2006-4219 19570  URL
7856MALWARE-OTHER Trackware winsysba-a runtime detection - track surfing activity (more info ...)successful-recon-limited    URL
7862BROWSER-PLUGINS Mcafee Security Center McSubMgr.IsAppExpired ActiveX function call access (more info ...)attempted-user 2006-3961 19265  
7863BROWSER-PLUGINS Mcafee Security Center McSubMgr.IsOldAppInstalled ActiveX function call access (more info ...)attempted-user 2006-3961 19265  
7864BROWSER-PLUGINS McSubMgr ActiveX CLSID access (more info ...)attempted-user 2006-3961 19265  
7866BROWSER-PLUGINS ADODB.Connection ActiveX clsid access (more info ...)attempted-user 2006-5559   URL
7868BROWSER-PLUGINS ADODB.Recordset ActiveX clsid access (more info ...)attempted-user 2006-5559 20704  
7878BROWSER-PLUGINS AxMetaStream.MetaStreamCtl ActiveX clsid access (more info ...)attempted-user    URL
7880BROWSER-PLUGINS AxMetaStream.MetaStreamCtlSecondary ActiveX clsid access (more info ...)attempted-user    
7882BROWSER-PLUGINS AccSync.AccSubNotHandler ActiveX clsid access (more info ...)attempted-user    
7884BROWSER-PLUGINS AolCalSvr.ACCalendarListCtrl ActiveX clsid access (more info ...)attempted-user    
7886BROWSER-PLUGINS AolCalSvr.ACDictionary ActiveX clsid access (more info ...)attempted-user    
7890BROWSER-PLUGINS AOL.MemExpWz ActiveX clsid access (more info ...)attempted-user    
7892BROWSER-PLUGINS AOL Phobos Class ActiveX clsid access (more info ...)attempted-user    
7894BROWSER-PLUGINS AOL.PicDownloadCtrl ActiveX clsid access (more info ...)attempted-user    
7896BROWSER-PLUGINS AOL.PicEditCtrl ActiveX clsid access (more info ...)attempted-user 2007-6699   
7898BROWSER-PLUGINS AOL.PicSsvrCtrl ActiveX clsid access (more info ...)attempted-user    
7900BROWSER-PLUGINS AOL.UPFCtrl ActiveX clsid access (more info ...)attempted-user    
7902BROWSER-PLUGINS CDDBControlAOL.CDDBAOLControl ActiveX clsid access (more info ...)attempted-user 2006-3134 23567  URL
7906BROWSER-PLUGINS CDO.KnowledgeSearchFolder ActiveX clsid access (more info ...)attempted-user    
7908BROWSER-PLUGINS DXImageTransform.Microsoft.Chroma ActiveX clsid access (more info ...)attempted-user  24188  URL
7910BROWSER-PLUGINS DXImageTransform.Microsoft.DropShadow ActiveX clsid access (more info ...)attempted-user    URL
7912BROWSER-PLUGINS DX3DTransform.Microsoft.Shapes ActiveX clsid access (more info ...)attempted-user    URL
7914BROWSER-PLUGINS DXImageTransform.Microsoft.NDFXArtEffects ActiveX clsid access (more info ...)attempted-user 2006-3638 19340  URL
7916BROWSER-PLUGINS CLSID_IMimeInternational ActiveX clsid access (more info ...)attempted-user    
7918BROWSER-PLUGINS CoAxTrackVideo Class ActiveX clsid access (more info ...)attempted-user    
7920BROWSER-PLUGINS DsPropertyPages.OU ActiveX clsid access (more info ...)attempted-user    
7922BROWSER-PLUGINS DXImageTransform.Microsoft.RevealTrans ActiveX clsid access (more info ...)attempted-user    URL
7924BROWSER-PLUGINS DXImageTransform.Microsoft.Shadow ActiveX clsid access (more info ...)attempted-user    URL
7926BROWSER-PLUGINS DXTFilter ActiveX clsid access (more info ...)attempted-user    
7930BROWSER-PLUGINS FolderItem2 ActiveX clsid access (more info ...)attempted-user    URL
7932BROWSER-PLUGINS FolderItems3 ActiveX clsid access (more info ...)attempted-user    
7936BROWSER-PLUGINS DXImageTransform.Microsoft.Glow ActiveX clsid access (more info ...)attempted-user    URL
7940BROWSER-PLUGINS DXImageTransform.Microsoft.Gradient ActiveX clsid access (more info ...)attempted-user    URL
7946BROWSER-PLUGINS DXImageTransform.Microsoft.MaskFilter ActiveX clsid access (more info ...)attempted-user    URL
7948BROWSER-PLUGINS Microsoft Common Browser Architecture ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
7950BROWSER-PLUGINS Microsoft DirectAnimation Control ActiveX clsid access (more info ...)attempted-user    
7952BROWSER-PLUGINS Microsoft DirectAnimation Windowed Control ActiveX clsid access (more info ...)attempted-user    
7954BROWSER-PLUGINS Microsoft Forms 2.0 ComboBox ActiveX clsid access (more info ...)attempted-user 1999-0384   URL
7956BROWSER-PLUGINS Microsoft Forms 2.0 ListBox ActiveX clsid access (more info ...)attempted-user    URL
7974BROWSER-PLUGINS Rendezvous Class ActiveX clsid access (more info ...)attempted-user    
7981BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX clsid access attempt (more info ...)attempted-user 2008-2463 30114  URL
7983BROWSER-PLUGINS SuperBuddy Class ActiveX clsid access (more info ...)attempted-user    
7987BROWSER-PLUGINS WebViewFolderIcon.WebViewFolderIcon.2 ActiveX clsid access (more info ...)attempted-user    
8025BROWSER-PLUGINS Microsoft HTML Window Security Proxy ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8027BROWSER-PLUGINS Microsoft WBEM Event Subsystem ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8055BROWSER-PLUGINS DirectAnimation.PathControl ActiveX function call access (more info ...)attempted-user 2006-4777 19738  
8066BROWSER-PLUGINS Microsoft Windows Scripting Host Shell ActiveX clsid access (more info ...)attempted-user 2003-0532 8456  URL
8068BROWSER-PLUGINS Microsoft Windows Scripting Host Shell ActiveX function call access (more info ...)attempted-user 2017-11774 17462  URL
8069BROWSER-PLUGINS Microsoft Virtual Machine ActiveX clsid access (more info ...)attempted-user 2000-1061 1754  URL
8082OS-WINDOWS Microsoft Windows UPnP malformed advertisement (more info ...)misc-attack 2001-0877 3723 10829 URL
8083OS-WINDOWS Microsoft Windows UPnP Location overflow (more info ...)misc-attack 2001-0876 3723 10829 URL
8157OS-WINDOWS DCERPC NCACN-IP-TCP webdav DavrCreateConnection hostname overflow attempt (more info ...)attempted-admin 2006-0013 16636  URL
8253OS-WINDOWS DCERPC NCACN-IP-TCP webdav DavrCreateConnection username overflow attempt (more info ...)attempted-admin 2006-0013 16636  URL
8363BROWSER-PLUGINS Business Object Factory ActiveX clsid access (more info ...)attempted-user    URL
8365BROWSER-PLUGINS DExplore.AppObj.8.0 ActiveX clsid access (more info ...)attempted-user    URL
8367BROWSER-PLUGINS Microsoft.DbgClr.DTE.8.0 ActiveX clsid access (more info ...)attempted-user    URL
8373BROWSER-PLUGINS VsmIDE.DTE ActiveX clsid access (more info ...)attempted-user    URL
8379BROWSER-PLUGINS Xml2Dex ActiveX clsid access (more info ...)attempted-user    
8391BROWSER-PLUGINS RFXInstMgr Class ActiveX clsid access (more info ...)attempted-user    
8393BROWSER-PLUGINS WebDetectFrm ActiveX clsid access (more info ...)attempted-user    
8395BROWSER-PLUGINS DX3DTransform.Microsoft.CrShatter ActiveX clsid access (more info ...)attempted-user    
8399BROWSER-PLUGINS Microsoft.WebCapture ActiveX clsid access (more info ...)attempted-user    
8403BROWSER-PLUGINS XML Schema Cache 6.0 ActiveX clsid access (more info ...)attempted-user    
8407BROWSER-PLUGINS VisualExec Control ActiveX clsid access (more info ...)attempted-user    
8411BROWSER-PLUGINS DocFind Command ActiveX clsid access (more info ...)attempted-user    
8416OS-WINDOWS Microsoft Windows Vector Markup Language fill method overflow attempt (more info ...)attempted-user 2006-4868 20096  URL
8417BROWSER-PLUGINS TriEditDocument.TriEditDocument ActiveX function call access (more info ...)attempted-user 2006-3591 18946  URL
8418BROWSER-PLUGINS DXImageTransform.Microsoft.RevealTrans ActiveX function call access (more info ...)attempted-user    URL
8419BROWSER-PLUGINS Microsoft Windows Explorer WebViewFolderIcon.WebViewFolderIcon.1 ActiveX function call (more info ...)attempted-user 2006-3730 19030  URL
8420BROWSER-PLUGINS DXImageTransform.Microsoft.Gradient ActiveX function call access (more info ...)attempted-user    URL
8421BROWSER-PLUGINS OWC11.DataSourceControl.11 ActiveX function call access (more info ...)attempted-user    URL
8423BROWSER-PLUGINS CEnroll.CEnroll.2 ActiveX function call access (more info ...)attempted-user    
8424BROWSER-PLUGINS Microsoft Forms 2.0 ListBox ActiveX function call access (more info ...)attempted-user    URL
8425BROWSER-PLUGINS DXImageTransform.Microsoft.NDFXArtEffects ActiveX function call access (more info ...)attempted-user 2006-3638 19340  URL
8449OS-WINDOWS Microsoft Windows SMB Rename invalid buffer type andx attempt (more info ...)attempted-dos 2006-4696   URL
8450OS-WINDOWS Microsoft Windows SMB Rename invalid buffer type attempt (more info ...)attempted-dos 2006-4696   URL
8451OS-WINDOWS Microsoft Windows SMB Rename invalid buffer type unicode andx attempt (more info ...)attempted-dos 2006-4696   URL
8452OS-WINDOWS Microsoft Windows SMB Rename invalid buffer type unicode attempt (more info ...)attempted-dos 2006-4696   URL
8453OS-WINDOWS Microsoft Windows SMB-DS Rename invalid buffer type andx attempt (more info ...)attempted-dos 2006-4696   URL
8454OS-WINDOWS Microsoft Windows SMB-DS Rename invalid buffer type attempt (more info ...)attempted-dos 2006-4696   URL
8455OS-WINDOWS Microsoft Windows SMB-DS Rename invalid buffer type unicode andx attempt (more info ...)attempted-dos 2006-4696   URL
8456OS-WINDOWS Microsoft Windows SMB-DS Rename invalid buffer type unicode attempt (more info ...)attempted-dos 2006-4696   URL
8457OS-WINDOWS Microsoft Windows SMB Rename invalid buffer type andx attempt (more info ...)attempted-dos 2006-4696   URL
8458OS-WINDOWS Microsoft Windows SMB Rename invalid buffer type attempt (more info ...)attempted-dos 2006-4696   URL
8459OS-WINDOWS Microsoft Windows SMB Rename invalid buffer type unicode andx attempt (more info ...)attempted-dos 2006-4696   URL
8460OS-WINDOWS Microsoft Windows SMB Rename invalid buffer type unicode attempt (more info ...)attempted-dos 2006-4696   URL
8709OS-WINDOWS Microsoft Windows NAT helper components tcp denial of service attempt (more info ...)misc-attack 2006-5614   
8710OS-WINDOWS Microsoft Windows NAT helper components udp denial of service attempt (more info ...)misc-attack 2006-5614   
8717BROWSER-PLUGINS VsaIDE.DTE ActiveX clsid access (more info ...)attempted-user    URL
8719BROWSER-PLUGINS VisualStudio.DTE.8.0 ActiveX clsid access (more info ...)attempted-user    URL
8725BROWSER-PLUGINS Microsoft Windows System Monitor ActiveX clsid access (more info ...)attempted-user 2000-1034 1899  URL
8735BROWSER-PLUGINS BOWebAgent.Webagent.1 ActiveX clsid access (more info ...)attempted-user    
8737BROWSER-PLUGINS BOWebAgent.Webagent.1 ActiveX function call access (more info ...)attempted-user    
8846BROWSER-PLUGINS Microsoft Agent Character Custom Proxy Class ActiveX clsid access (more info ...)attempted-user 2007-1205   URL
8848BROWSER-PLUGINS Microsoft Agent Notify Sink Custom Proxy Class ActiveX clsid access (more info ...)attempted-user 2007-1205   URL
8850BROWSER-PLUGINS Microsoft Agent Custom Proxy Class ActiveX clsid access (more info ...)attempted-user 2007-1205   URL
8852BROWSER-PLUGINS Microsoft Agent v2.0 ActiveX clsid access (more info ...)attempted-user 2007-1205   URL
8854BROWSER-PLUGINS Microsoft Agent v2.0 ActiveX function call access (more info ...)attempted-user 2007-1205   URL
8856BROWSER-PLUGINS Microsoft Agent v1.5 ActiveX function call access (more info ...)attempted-user 2007-1205   URL
8925OS-WINDOWS DCERPC NCACN-IP-TCP wkssvc NetrAddAlternateComputerName overflow attempt (more info ...)attempted-admin 2003-0812 9011 11921 URL
9129BROWSER-PLUGINS WinZip FileView 6.1 ActiveX clsid access (more info ...)attempted-user 2006-5198 21108  URL
9131BROWSER-PLUGINS WinZip FileView 6.1 ActiveX function call access (more info ...)attempted-user 2006-5198 21108  URL
9132OS-WINDOWS DCERPC NCACN-IP-TCP netware_cs NwrOpenEnumNdsStubTrees_Any overflow attempt (more info ...)attempted-admin 2006-4689   URL
9228OS-WINDOWS DCERPC NCACN-IP-TCP netware_cs NwGetConnectionInformation overflow attempt (more info ...)attempted-admin 2006-4689   URL
9427BROWSER-PLUGINS Acer LunchApp.APlunch ActiveX clsid access (more info ...)attempted-user    URL
9432OS-WINDOWS Microsoft Agent buffer overflow attempt (more info ...)attempted-user 2006-3445 21034  URL
9433OS-WINDOWS Microsoft Agent buffer overflow attempt (more info ...)attempted-user 2006-3445 21034  URL
9441NETBIOS DCERPC NCACN-IP-TCP brightstor QSIGetQueuePath overflow attempt (more info ...)attempted-admin 2006-5143 20365  URL
9623PROTOCOL-RPC UNIX authentication machinename string overflow attempt TCP (more info ...)attempted-user 2006-5780 20941  
9624PROTOCOL-RPC UNIX authentication machinename string overflow attempt UDP (more info ...)attempted-user 2006-5780 20941  
9626BROWSER-PLUGINS AcroPDF.PDF ActiveX clsid access attempt (more info ...)attempted-user 2006-6236 21338  URL
9629BROWSER-PLUGINS Citrix.ICAClient ActiveX clsid access (more info ...)attempted-user 2006-6334 23246  URL
9631BROWSER-PLUGINS Citrix.ICAClient ActiveX function call access (more info ...)attempted-user 2006-6334 23246  URL
9640BROWSER-PLUGINS Microsoft Windows ADODB.Connection ActiveX function call access (more info ...)attempted-user 2006-5559   URL
9772NETBIOS DCERPC NCACN-IP-TCP msqueue function 1 overflow attempt (more info ...)attempted-admin    
9773NETBIOS DCERPC NCADG-IP-UDP msqueue function 1 overflow attempt (more info ...)attempted-admin    
9793BROWSER-PLUGINS YMMAPI.YMailAttach ActiveX clsid access (more info ...)attempted-user 2006-6603 21607  URL
9795BROWSER-PLUGINS Panda ActiveScan ActiveScan.1 ActiveX clsid access (more info ...)attempted-user 2006-5966 21132  
9797BROWSER-PLUGINS Panda ActiveScan ActiveScan.1 ActiveX function call access (more info ...)attempted-user    
9798BROWSER-PLUGINS Panda ActiveScan PAVPZ.SOS.1 ActiveX clsid access (more info ...)attempted-user 2006-5966 21132  
9800BROWSER-PLUGINS Panda ActiveScan PAVPZ.SOS.1 ActiveX function call access (more info ...)attempted-user    
9812BROWSER-PLUGINS Yahoo Messenger YMMAPI.YMailAttach ActiveX function call access (more info ...)attempted-user 2006-6603 21607  URL
9814BROWSER-PLUGINS ICQPhone.SipxPhoneManager ActiveX clsid access (more info ...)attempted-user 2006-5650 20930  
9816BROWSER-PLUGINS ICQPhone.SipxPhoneManager ActiveX function call access (more info ...)attempted-user 2006-5650 20930  
9817BROWSER-PLUGINS CEnroll.CEnroll.2 ActiveX clsid access (more info ...)attempted-user    
9820BROWSER-PLUGINS OWC11.DataSourceControl.11 ActiveX function call access (more info ...)attempted-user 2006-3729 19069  URL
9821BROWSER-PLUGINS TriEditDocument.TriEditDocument ActiveX clsid access (more info ...)attempted-user 2006-3591 18946  URL
9824BROWSER-PLUGINS Rediff Bol Downloader ActiveX clsid access (more info ...)attempted-user 2006-6838 21831  
9826BROWSER-PLUGINS Rediff Bol Downloader ActiveX function call access (more info ...)attempted-user 2006-6838 21831  
9848OS-WINDOWS Microsoft Windows Vector Markup Language recolorinfo tag numfills parameter buffer overflow attempt (more info ...)attempted-user 2007-0024   URL
9849OS-WINDOWS Microsoft Windows Vector Markup Language recolorinfo tag numcolors parameter buffer overflow attempt (more info ...)attempted-user 2007-0024   URL
9914OS-WINDOWS DCERPC NCACN-IP-TCP tapisrv ClientRequest LSetAppPriority overflow attempt (more info ...)attempted-admin 2005-0058 14518  URL
10013BROWSER-PLUGINS CCRP FolderTreeView ActiveX clsid access (more info ...)attempted-user 2007-0356 22092  URL
10015BROWSER-PLUGINS Oracle ORADC ActiveX clsid access (more info ...)attempted-user  22026  
10017BROWSER-PLUGINS Oracle ORADC ActiveX function call access (more info ...)attempted-user  22026  
10024NETBIOS DCERPC NCACN-IP-TCP brightstor-arc ClientDBMiniAgentClose attempt (more info ...)protocol-command-decode 2007-0168 22010  URL
10036NETBIOS DCERPC NCACN-IP-TCP brightstor ASRemotePFC overflow attempt (more info ...)attempted-admin 2007-0169 22005  URL
10050NETBIOS DCERPC NCACN-IP-TCP brightstor-arc2 ASDBLoginToComputer overflow attempt (more info ...)attempted-admin 2007-0169 22005  URL
10084BROWSER-PLUGINS NCTAudioFile2 ActiveX clsid access (more info ...)attempted-user 2007-0018 33469  URL
10086BROWSER-PLUGINS NCTAudioFile2 ActiveX function call access (more info ...)attempted-user 2007-0018 33469  URL
10115FILE-IMAGE Microsoft Windows WMF denial of service attempt (more info ...)web-application-attack 2006-4071 21992  
10117NETBIOS DCERPC NCACN-IP-TCP brightstor-arc GetGCBHandleFromGroupName overflow attempt (more info ...)attempted-admin 2007-0169 22005  
10128BROWSER-PLUGINS Aliplay ActiveX clsid access (more info ...)attempted-user 2007-0827 22446  
10137BROWSER-PLUGINS Microsoft Input Method Editor ActiveX clsid access (more info ...)attempted-user 2006-4697   URL
10139BROWSER-PLUGINS Microsoft Input Method Editor ActiveX function call access (more info ...)attempted-user 2006-4697   URL
10140BROWSER-PLUGINS Microsoft Input Method Editor 2 ActiveX clsid access attempt (more info ...)attempted-user 2006-4697   URL
10156BROWSER-PLUGINS ActiveX Soft DVD Tools ActiveX clsid access (more info ...)attempted-user 2007-0976 22558  URL
10162BROWSER-PLUGINS BrowseDialog ActiveX clsid access (more info ...)attempted-user 2007-0371 22110  
10170BROWSER-PLUGINS Verisign ConfigCHK ActiveX clsid access (more info ...)attempted-user 2007-1083 22676  
10176BROWSER-PLUGINS Microsoft Windows Shell User Enumeration Object ActiveX clsid access (more info ...)attempted-user    
10178BROWSER-PLUGINS Microsoft Windows Shell User Enumeration Object ActiveX function call access (more info ...)attempted-user    
10189BROWSER-PLUGINS DivXBrowserPlugin ActiveX clsid access (more info ...)attempted-user    
10191BROWSER-PLUGINS DivXBrowserPlugin ActiveX function call access (more info ...)attempted-user    
10214BROWSER-PLUGINS Shockwave ActiveX Control clsid access (more info ...)attempted-user 2007-1403 22842  
10216BROWSER-PLUGINS Shockwave ActiveX Control ActiveX function call access (more info ...)attempted-user 2006-6885 22842  
10285NETBIOS DCERPC NCACN-IP-TCP svcctl ChangeServiceConfig2A attempt (more info ...)protocol-command-decode    
10387BROWSER-PLUGINS McAfee Site Manager ActiveX clsid access attempt (more info ...)attempted-user 2007-1498 22952  
10389BROWSER-PLUGINS McAfee Site Manager ActiveX function call access attempt (more info ...)attempted-user 2007-1498 22952  
10404BROWSER-PLUGINS SignKorea SKCommAX ActiveX clsid access (more info ...)attempted-user    
10406BROWSER-PLUGINS SignKorea SKCommAX ActiveX function call access (more info ...)attempted-user    
10408PROTOCOL-RPC portmap HP-UX Single Logical Screen SLSD tcp request (more info ...)rpc-portmap-decode 2007-0915 22551  
10409PROTOCOL-RPC portmap HP-UX Single Logical Screen SLSD udp request (more info ...)rpc-portmap-decode 2007-0915 22551  
10410PROTOCOL-RPC portmap HP-UX Single Logical Screen SLSD tcp request (more info ...)rpc-portmap-decode 2007-0915 22551  
10411PROTOCOL-RPC portmap HP-UX Single Logical Screen SLSD udp request (more info ...)rpc-portmap-decode 2007-0915 22551  
10412BROWSER-PLUGINS IBM Lotus SameTime STJNILoader ActiveX clsid access attempt (more info ...)attempted-user 2007-1784 23201  URL
10414BROWSER-PLUGINS IBM Lotus SameTime STJNILoader Alt CLSID ActiveX function call access (more info ...)attempted-user 2007-1784 23201  URL
10415BROWSER-PLUGINS IBM Lotus SameTime STJNILoader ActiveX clsid access attempt (more info ...)attempted-user 2007-1784 23201  URL
10417BROWSER-PLUGINS IBM Lotus SameTime STJNILoader ActiveX function call access (more info ...)attempted-user 2007-1784 23201  URL
10419BROWSER-PLUGINS HP Mercury Quality Center SPIDERLib ProgColor ActiveX clsid access (more info ...)attempted-user 2007-1819 23239  URL
10421BROWSER-PLUGINS HP Mercury Quality Center SPIDERLib ActiveX function call access (more info ...)attempted-user 2007-1819 23239  URL
10423BROWSER-PLUGINS Yahoo Audio Conferencing ActiveX clsid access (more info ...)attempted-user 2007-1680 23291  URL
10425BROWSER-PLUGINS Yahoo Audio Conferencing ActiveX function call access (more info ...)attempted-user 2007-1680 23291  URL
10427BROWSER-PLUGINS Kaspersky AntiVirus SysInfo ActiveX clsid access (more info ...)attempted-user 2007-1112 23325  URL
10429BROWSER-PLUGINS Kaspersky AntiVirus SysInfo ActiveX function call access (more info ...)attempted-user 2007-1112 23325  URL
10431BROWSER-PLUGINS Kaspersky AntiVirus KAV60Info ActiveX clsid access (more info ...)attempted-user 2007-1112 23345  URL
10433BROWSER-PLUGINS Kaspersky AntiVirus KAV60Info ActiveX function call access (more info ...)attempted-user 2007-1112 23345  URL
10466BROWSER-PLUGINS iPIX Image Well ActiveX clsid access (more info ...)attempted-user 2007-1687 23379  URL
10468BROWSER-PLUGINS iPIX Image Well ActiveX function call access (more info ...)attempted-user 2007-1687 23379  URL
10470BROWSER-PLUGINS iPIX Media Send Class ActiveX clsid access (more info ...)attempted-user 2007-1687 23379  URL
10472BROWSER-PLUGINS iPIX Media Send Class ActiveX function call access (more info ...)attempted-user 2007-1687 23379  URL
10475OS-WINDOWS Microsoft Windows UPnP notification type overflow attempt (more info ...)attempted-admin 2007-1204 23371  URL
10476BROWSER-PLUGINS MarkAny MaPrintModule_WORK ActiveX clsid access (more info ...)attempted-user  23420  
10478BROWSER-PLUGINS MarkAny MaPrintModule_WORK ActiveX function call access (more info ...)attempted-user  23420  
10978BROWSER-PLUGINS Second Sight Software ActiveGS ActiveX clsid access (more info ...)attempted-user 2007-1690 23554  URL
10980BROWSER-PLUGINS Second Sight Software ActiveGS ActiveX function call access (more info ...)attempted-user 2007-1690 23554  URL
10982BROWSER-PLUGINS Second Sight Software ActiveMod ActiveX clsid access (more info ...)attempted-user 2007-1691 23554  URL
10984BROWSER-PLUGINS Second Sight Software ActiveMod ActiveX function call access (more info ...)attempted-user 2007-1691 23554  URL
10986BROWSER-PLUGINS GraceNote CDDB ActiveX clsid access (more info ...)attempted-user 2007-0443 23567  URL
10988BROWSER-PLUGINS GraceNote CDDB ActiveX function call access (more info ...)attempted-user 2007-0443 23567  URL
10991BROWSER-PLUGINS Microgaming Download Helper ActiveX clsid access (more info ...)attempted-user 2007-2177 23595  URL
10993BROWSER-PLUGINS Microgaming Download Helper ActiveX function call access (more info ...)attempted-user 2007-2177 23595  URL
11073OS-WINDOWS DCERPC NCACN-IP-TCP rpcss _RemoteGetClassObject attempt (more info ...)protocol-command-decode 2003-0605   URL
11074OS-WINDOWS DCERPC NCADG-IP-UDP rpcss _RemoteGetClassObject attempt (more info ...)protocol-command-decode 2003-0605   URL
11197BROWSER-PLUGINS ActiveX Soft DVD Tools ActiveX function call access (more info ...)attempted-user 2007-0976 22558  URL
11206BROWSER-PLUGINS East Wind Software ADVDAUDIO ActiveX clsid access (more info ...)attempted-user 2007-2576 23833  URL
11208BROWSER-PLUGINS East Wind Software ADVDAUDIO ActiveX function call access (more info ...)attempted-user 2007-2576 23833  URL
11210BROWSER-PLUGINS Sienzo Digital Music Mentor ActiveX clsid access (more info ...)attempted-user 2007-2564 23838  URL
11212BROWSER-PLUGINS Sienzo Digital Music Mentor ActiveX function call access (more info ...)attempted-user 2007-2564 23838  URL
11214BROWSER-PLUGINS VeralSoft HTTP File Uploader ActiveX clsid access (more info ...)attempted-user 2007-2563 23853  URL
11216BROWSER-PLUGINS VeralSoft HTTP File Uploader ActiveX function call access (more info ...)attempted-user 2007-2563 23853  URL
11218BROWSER-PLUGINS SmartCode VNC Manager ActiveX clsid access (more info ...)attempted-user 2007-2526 23869  URL
11220BROWSER-PLUGINS SmartCode VNC Manager ActiveX function call access (more info ...)attempted-user 2007-2526 23869  URL
11228BROWSER-PLUGINS Microsoft Input Method Editor 3 ActiveX clsid access (more info ...)attempted-user 2007-0942   URL
11230BROWSER-PLUGINS Microsoft Cryptographic API COM 1 ActiveX clsid access (more info ...)attempted-user 2007-0940   URL
11232BROWSER-PLUGINS Microsoft CAPICOM CAPICOM.Certificates ActiveX clsid access attempt (more info ...)attempted-user 2007-0940   
11234BROWSER-PLUGINS Microsoft Cryptographic API COM 2 ActiveX clsid access (more info ...)attempted-user 2007-0940   URL
11239BROWSER-PLUGINS DXImageTransform.Microsoft.Redirect ActiveX clsid access (more info ...)attempted-user    URL
11241BROWSER-PLUGINS DXImageTransform.Microsoft.Redirect ActiveX function call access (more info ...)attempted-user    URL
11250BROWSER-PLUGINS Sony Rootkit Uninstaller ActiveX clsid access (more info ...)attempted-user    URL
11253BROWSER-PLUGINS Microsoft MciWndx ActiveX clsid access (more info ...)attempted-user    
11255BROWSER-PLUGINS Microsoft MciWndx ActiveX function call access (more info ...)attempted-user    
11259BROWSER-PLUGINS BarcodeWiz ActiveX clsid access (more info ...)attempted-user 2010-2932 23891  URL
11261BROWSER-PLUGINS BarcodeWiz ActiveX function call access (more info ...)attempted-user 2010-2932 23891  URL
11268BROWSER-PLUGINS Symantec Norton AntiVirus ActiveX clsid access (more info ...)attempted-user 2006-3456 23822  URL
11270BROWSER-PLUGINS Symantec Norton AntiVirus ActiveX function call access (more info ...)attempted-user 2006-3456 23822  URL
11274BROWSER-PLUGINS RControl ActiveX clsid access (more info ...)attempted-user 2007-2623 23914  URL
11276BROWSER-PLUGINS GDivX Zenith Player AVI Fixer ActiveX clsid access (more info ...)attempted-user 2007-2601 23907  
11278BROWSER-PLUGINS GDivX Zenith Player AVI Fixer ActiveX function call access (more info ...)attempted-user 2007-2601 23907  
11280BROWSER-PLUGINS FlexLabel ActiveX clsid access (more info ...)attempted-user    URL
11282BROWSER-PLUGINS FlexLabel ActiveX function call access (more info ...)attempted-user    URL
11284BROWSER-PLUGINS AudioCDRipper ActiveX clsid access (more info ...)attempted-user 2007-2603 23900  
11286BROWSER-PLUGINS AudioCDRipper ActiveX function call access (more info ...)attempted-user 2007-2603 23900  
11288PROTOCOL-RPC portmap mountd tcp request (more info ...)rpc-portmap-decode 2006-0900 16838  
11289PROTOCOL-RPC portmap mountd tcp zero-length payload denial of service attempt (more info ...)rpc-portmap-decode 2006-0900 16838  
11291BROWSER-PLUGINS Hewlett Packard HPQVWOCX.DL ActiveX clsid access (more info ...)attempted-user 2007-3649 24793  
11293BROWSER-PLUGINS IDAutomation Linear Bar Code ActiveX clsid access (more info ...)attempted-user 2007-2658 23954  URL
11295BROWSER-PLUGINS IDAutomation Linear Bar Code ActiveX function call access (more info ...)attempted-user 2007-2658 23954  URL
11297BROWSER-PLUGINS Clever Database Comparer ActiveX clsid access (more info ...)attempted-user 2007-2648 23969  URL
11299BROWSER-PLUGINS Clever Database Comparer ActiveX function call access (more info ...)attempted-user 2007-2648 23969  URL
11620BROWSER-PLUGINS DXImageTransform.Microsoft.Chroma ActiveX function call access (more info ...)attempted-user  24188  URL
11624BROWSER-PLUGINS LeadTools ISIS ActiveX clsid access (more info ...)attempted-user 2007-2854 24094  URL
11626BROWSER-PLUGINS LeadTools ISIS ActiveX function call access (more info ...)attempted-user 2007-2854 24094  URL
11628BROWSER-PLUGINS LeadTools JPEG 2000 COM Object ActiveX function call access (more info ...)attempted-user 2007-2771 24040  URL
11630BROWSER-PLUGINS LeadTools Raster Dialog File Object ActiveX clsid access (more info ...)attempted-user 2007-2895 24133  URL
11632BROWSER-PLUGINS LeadTools Raster Dialog File Object ActiveX function call access (more info ...)attempted-user 2007-2895 24133  URL
11634BROWSER-PLUGINS LeadTools Raster Dialog File_D Object ActiveX clsid access (more info ...)attempted-user 2007-2946 24153  URL
11636BROWSER-PLUGINS LeadTools Raster Dialog File_D Object ActiveX function call access (more info ...)attempted-user 2007-2946 24153  URL
11638BROWSER-PLUGINS LeadTools Raster Document Object Library ActiveX clsid access (more info ...)attempted-user 2007-2981 24179  URL
11640BROWSER-PLUGINS LeadTools Raster Document Object Library ActiveX function call access (more info ...)attempted-user 2007-2981 24179  URL
11642BROWSER-PLUGINS LeadTools Raster ISIS Object ActiveX clsid access (more info ...)attempted-user 2007-2980 24193  URL
11644BROWSER-PLUGINS LeadTools Raster ISIS Object ActiveX function call access (more info ...)attempted-user 2007-2980 24193  URL
11646BROWSER-PLUGINS LeadTools Raster Thumbnail Object Library ActiveX clsid access (more info ...)attempted-user 2007-2787 24057  URL
11648BROWSER-PLUGINS LeadTools Raster Thumbnail Object Library ActiveX function call access (more info ...)attempted-user 2007-2787 24057  URL
11650BROWSER-PLUGINS LeadTools Raster Variant Object Library ActiveX clsid access (more info ...)attempted-user 2007-2851 24075  URL
11652BROWSER-PLUGINS LeadTools Raster Variant Object Library ActiveX function call access (more info ...)attempted-user 2007-2851 24075  URL
11654BROWSER-PLUGINS LeadTools Thumbnail Browser Control ActiveX clsid access (more info ...)attempted-user 2007-2787 24053  URL
11656BROWSER-PLUGINS LeadTools Thumbnail Browser Control ActiveX function call access (more info ...)attempted-user 2007-2787 24053  URL
11658BROWSER-PLUGINS Dart ZipLite Compression ActiveX clsid access (more info ...)attempted-user  24099  URL
11673BROWSER-PLUGINS Zenturi ProgramChecker ActiveX clsid access (more info ...)attempted-user 2007-3703 24883  
11675BROWSER-PLUGINS Zenturi ProgramChecker ActiveX function call access (more info ...)attempted-user 2007-3703 24883  
11677BROWSER-PLUGINS Provideo Camimage Class ISSCamControl ActiveX clsid access (more info ...)attempted-user 2007-3111 24279  
11816NETBIOS Session Service NetDDE attack (more info ...)attempted-admin 2004-0206 11372  
11818BROWSER-PLUGINS Yahoo Webcam Viewer Wrapper ActiveX clsid access (more info ...)attempted-user 2007-3148 24341  URL
11820BROWSER-PLUGINS Yahoo Webcam Viewer Wrapper ActiveX function call access (more info ...)attempted-user 2007-3148 24341  URL
11823BROWSER-PLUGINS Yahoo Webcam Upload ActiveX clsid unicode access (more info ...)attempted-user 2007-3147 24341  
11825BROWSER-PLUGINS Yahoo Webcam Upload ActiveX function call unicode access (more info ...)attempted-user 2007-3147 24341  
11826BROWSER-PLUGINS Microsoft Voice Control Recognition ActiveX clsid access attempt (more info ...)attempted-user 2007-2222   URL
11828BROWSER-PLUGINS Microsoft Voice Control ActiveX function call access (more info ...)attempted-user 2007-2222   URL
11830BROWSER-PLUGINS Microsoft Direct Speech Recognition ActiveX clsid access attempt (more info ...)attempted-user 2007-2222   URL
11832BROWSER-PLUGINS Microsoft Direct Speech Recognition ActiveX function call access (more info ...)attempted-user 2007-2222   URL
11838OS-WINDOWS Microsoft Windows API res buffer overflow attempt (more info ...)attempted-user 2007-2219   URL
11839BROWSER-PLUGINS TEC-IT TBarCode ActiveX clsid access (more info ...)attempted-user 2007-3233 24440  
11841BROWSER-PLUGINS TEC-IT TBarCode ActiveX function call access (more info ...)attempted-user 2007-3233 24440  
11843OS-WINDOWS DCERPC NCACN-IP-TCP spoolss AddPrinter overflow attempt (more info ...)attempted-admin 2005-1984 14514  URL
11940BROWSER-PLUGINS Westbyte Internet Download Accelerator ActiveX function call access (more info ...)attempted-user 2007-3162 24400  
11942BROWSER-PLUGINS Westbyte internet download accelerator ActiveX clsid access (more info ...)attempted-user 2007-3162 24400  
11943BROWSER-PLUGINS HP ModemUtil ActiveX clsid access (more info ...)attempted-user    
11946NETBIOS Datagram Service NetDDE attack (more info ...)attempted-admin 2004-0206 11372  
11947OS-WINDOWS Microsoft Windows schannel security package (more info ...)attempted-user 2007-2218   URL
11951MALWARE-BACKDOOR winshadow runtime detection - init connection request (more info ...)trojan-activity    URL
11952MALWARE-BACKDOOR winshadow runtime detection - udp response (more info ...)trojan-activity    URL
12010BROWSER-PLUGINS RKD Software BarCode ActiveX clsid access (more info ...)attempted-user 2007-3435 24596  
12012BROWSER-PLUGINS RKD Software BarCode ActiveX function call access (more info ...)attempted-user 2007-3435 24596  
12015BROWSER-PLUGINS NCTAudioStudio2 NCT WavChunksEditor ActiveX clsid access (more info ...)attempted-user 2007-3493 24656  URL
12017BROWSER-PLUGINS NCTAudioStudio2 NCT WavChunksEditor ActiveX function call access (more info ...)attempted-user 2007-3493 24656  URL
12019BROWSER-PLUGINS NCTsoft NCTAudioFile2 NCTWMAFile ActiveX clsid access (more info ...)attempted-user 2007-3400 24613  URL
12021BROWSER-PLUGINS NCTsoft NCTAudioFile2 NCTWMAFile ActiveX function call access (more info ...)attempted-user 2007-3400 24613  URL
12029BROWSER-PLUGINS HP Digital Imaging hpqxml.dll ActiveX clsid access (more info ...)attempted-user 2007-3487 24678  URL
12058OS-WINDOWS Microsoft Windows SPNEGO ASN.1 library heap corruption overflow attempt (more info ...)attempted-admin 2005-1935 9633  URL
12062BROWSER-PLUGINS HP Instant Support ActiveX clsid access (more info ...)attempted-user 2007-3554 24730  URL
12083BROWSER-PLUGINS Data Dynamics ActiveBar Actbar3 ActiveX clsid access (more info ...)attempted-user 2007-3883 24959  
12085BROWSER-PLUGINS Data Dynamics ActiveBar Actbar3 ActiveX function call access (more info ...)attempted-user 2007-3883 24959  
12087BROWSER-PLUGINS McAfee NeoTrace ActiveX clsid access (more info ...)attempted-user 2006-6707 21697  
12089BROWSER-PLUGINS McAfee NeoTrace ActiveX function call access (more info ...)attempted-user 2006-6707 21697  
12091BROWSER-PLUGINS EldoS SecureBlackbox PGPBBox ActiveX clsid access (more info ...)attempted-user 2007-3785 24882  
12093BROWSER-PLUGINS EldoS SecureBlackbox PGPBBox ActiveX function call access (more info ...)attempted-user 2007-3785 24882  
12116BROWSER-PLUGINS Zenturi ProgramChecker SASATL ActiveX clsid access (more info ...)attempted-user 2007-3984 25025  
12118BROWSER-PLUGINS Zenturi ProgramChecker SASATL ActiveX function call access (more info ...)attempted-user 2007-3984 25025  
12144MALWARE-BACKDOOR access remote pc runtime detection - rpc setup (more info ...)trojan-activity    
12145MALWARE-BACKDOOR access remote pc runtime detection - rpc setup (more info ...)trojan-activity    URL
12168BROWSER-PLUGINS Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX clsid access (more info ...)attempted-user 2007-3302 25050  URL
12185PROTOCOL-RPC portmap 2112 tcp request (more info ...)rpc-portmap-decode 2007-2798 24653  URL
12186PROTOCOL-RPC portmap 2112 udp request (more info ...)rpc-portmap-decode 2007-2798 24653  URL
12189BROWSER-PLUGINS Clever Internet Suite ActiveX clsid access (more info ...)attempted-user 2007-4067 25063  
12191BROWSER-PLUGINS Clever Internet Suite ActiveX function call access (more info ...)attempted-user 2007-4067 25063  
12193BROWSER-PLUGINS Yahoo Widgets Engine ActiveX clsid access (more info ...)attempted-user 2007-4034 25086  URL
12195BROWSER-PLUGINS Yahoo Widgets Engine ActiveX function call access (more info ...)attempted-user 2007-4034 25086  URL
12200BROWSER-PLUGINS VMWare IntraProcessLogging ActiveX clsid access (more info ...)attempted-user 2007-4059 25110  
12203BROWSER-PLUGINS VMWare Vielib.dll ActiveX clsid access (more info ...)attempted-user 2007-4058 25118  
12205BROWSER-PLUGINS VMWare Vielib.dll ActiveX function call access (more info ...)attempted-user 2007-4058 25118  
12207BROWSER-PLUGINS Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX function call access (more info ...)attempted-user 2007-3302 25050  URL
12246BROWSER-PLUGINS Symantec NavComUI AxSysListView32 ActiveX clsid access attempt (more info ...)attempted-user 2007-2955 24983  URL
12248BROWSER-PLUGINS Symantec NavComUI AxSysListView32 ActiveX function call access attempt (more info ...)attempted-user 2007-2955 24983  URL
12250BROWSER-PLUGINS Symantec NavComUI AxSysListView32OAA ActiveX clsid access attempt (more info ...)attempted-user 2007-2955 24983  URL
12252BROWSER-PLUGINS Symantec NavComUI AxSysListView32OAA ActiveX function call access attempt (more info ...)attempted-user 2007-2955 24983  URL
12257BROWSER-PLUGINS Microsoft DirectX Media SDK ActiveX clsid access (more info ...)attempted-user 2007-4336 25279  
12259BROWSER-PLUGINS Microsoft DirectX Media SDK ActiveX function call access (more info ...)attempted-user 2007-4336 25279  
12279OS-WINDOWS Microsoft XML substringData integer overflow attempt (more info ...)attempted-user 2008-1442   URL
12301BROWSER-PLUGINS eCentrex VOIP Client Module ActiveX clsid access (more info ...)attempted-user 2007-4489 25383  URL
12306POLICY-SOCIAL Microsoft Messenger web client connection (more info ...)policy-violation    
12380BROWSER-PLUGINS Oracle JInitiator ActiveX clsid access (more info ...)attempted-user 2007-4467 25473  
12384BROWSER-PLUGINS Yahoo Messenger YVerInfo ActiveX clsid access (more info ...)attempted-user 2007-4515 25494  URL
12386BROWSER-PLUGINS Yahoo Messenger YVerInfo ActiveX function call access (more info ...)attempted-user 2007-4515 25494  URL
12388BROWSER-PLUGINS PPStream PowerPlayer ActiveX clsid access (more info ...)attempted-user 2007-4748 25502  
12393BROWSER-PLUGINS Intuit QuickBooks Online Edition 1 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12395BROWSER-PLUGINS Intuit QuickBooks Online Edition 2 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12397BROWSER-PLUGINS Intuit QuickBooks Online Edition 3 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12399BROWSER-PLUGINS Intuit QuickBooks Online Edition 4 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12401BROWSER-PLUGINS Intuit QuickBooks Online Edition 5 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12403BROWSER-PLUGINS Intuit QuickBooks Online Edition 6 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12405BROWSER-PLUGINS Intuit QuickBooks Online Edition 7 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12407BROWSER-PLUGINS Intuit QuickBooks Online Edition 8 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12409BROWSER-PLUGINS Intuit QuickBooks Online Edition 9 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12411BROWSER-PLUGINS Intuit QuickBooks Online Edition 10 ActiveX clsid access (more info ...)attempted-user 2007-4471 25544  URL
12413BROWSER-PLUGINS Earth Resource Mapper NCSView ActiveX clsid access (more info ...)attempted-user 2007-4470 25584  
12415BROWSER-PLUGINS Earth Resource Mapper NCSView ActiveX function call access (more info ...)attempted-user 2007-4470 25584  
12417BROWSER-PLUGINS Microsoft Visual FoxPro ActiveX clsid access (more info ...)attempted-user 2007-5322 25977  
12419BROWSER-PLUGINS Microsoft Visual FoxPro ActiveX function call access (more info ...)attempted-user 2007-5322 25977  
12428BROWSER-PLUGINS GlobalLink glitemflat.dll ActiveX clsid access (more info ...)attempted-user 2007-4802 25586  
12434BROWSER-PLUGINS BaoFeng Storm MPS.dll ActiveX clsid access (more info ...)attempted-user 2009-1612 25601  
12438BROWSER-PLUGINS Ultra Crypto Component CryptoX.dll ActiveX clsid access (more info ...)attempted-user 2007-4903 25609  URL
12440BROWSER-PLUGINS Ultra Crypto Component CryptoX.dll ActiveX function call access (more info ...)attempted-user 2007-4903 25609  URL
12442BROWSER-PLUGINS Ultra Crypto Component CryptoX.dll 2 ActiveX clsid access (more info ...)attempted-user 2007-4902 25611  URL
12450BROWSER-PLUGINS Microsoft Windows Agent Control ActiveX function call access (more info ...)attempted-user 2007-3040 25566  URL
12452BROWSER-PLUGINS Microsoft Windows Agent File Provider ActiveX clsid access (more info ...)attempted-user 2007-3040 25566  URL
12459BROWSER-PLUGINS Microsoft Windows Visual Studio 6 PDWizard.ocx ActiveX clsid access attempt (more info ...)attempted-user 2007-4891 25638  
12461BROWSER-PLUGINS Microsoft Visual Studio 6 VBTOVSI.dll ActiveX clsid access (more info ...)attempted-user 2007-4890 25635  
12463OS-WINDOWS Microsoft Windows Visual Studio Crystal Reports RPT file handling buffer overflow attempt (more info ...)attempted-user 2006-6133 21261  URL
12466BROWSER-PLUGINS MW6 Technologies QRCode ActiveX clsid access (more info ...)attempted-user 2007-4982 25702  
12468BROWSER-PLUGINS COWON America JetAudio JetFlExt.dll ActiveX clsid access (more info ...)attempted-user 2007-4983 25723  
12470BROWSER-PLUGINS COWON America JetAudio JetFlExt.dll ActiveX function call access (more info ...)attempted-user 2007-4983 25723  
12476BROWSER-PLUGINS Yahoo Messenger CYFT ActiveX clsid access (more info ...)attempted-user 2007-5017 25727  
12478BROWSER-PLUGINS Yahoo Messenger CYFT ActiveX function call access (more info ...)attempted-user 2007-5017 25727  
12489NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrWkstaGetInfo attempt (more info ...)protocol-command-decode 2006-6723   
12598BROWSER-PLUGINS Xunlei Web Thunder ActiveX clsid access (more info ...)attempted-user 2007-5064 25751  
12600BROWSER-PLUGINS ebCrypt IncrementalHash ActiveX clsid access (more info ...)attempted-user 2007-5111 25789  
12602BROWSER-PLUGINS ebCrypt IncrementalHash ActiveX function call access (more info ...)attempted-user 2007-5111 25789  
12604BROWSER-PLUGINS ebCrypt PRNGenerator ActiveX clsid access (more info ...)attempted-user 2007-5110 25787  
12606BROWSER-PLUGINS ebCrypt PRNGenerator ActiveX function call access (more info ...)attempted-user 2007-5110 25787  
12608PROTOCOL-RPC portmap walld udp request (more info ...)rpc-portmap-decode 2002-0573 4639  
12609PROTOCOL-RPC portmap walld udp format string attack attempt (more info ...)rpc-portmap-decode 2002-0573 4639  
12616BROWSER-PLUGINS Microsoft Windows Visual Studio 6 PDWizard.ocx ActiveX function call access attempt (more info ...)attempted-user 2007-4891 25638  
12631OS-WINDOWS Microsoft Windows 2000 Kodak Imaging small offset malformed jpeg tables (more info ...)attempted-user 2007-2217   URL
12632OS-WINDOWS Microsoft Windows 2000 Kodak Imaging large offset malformed jpeg tables (more info ...)attempted-user 2007-2217   URL
12635OS-WINDOWS RPC NTLMSSP malformed credentials attempt (more info ...)denial-of-service 2007-2228   URL
12637BROWSER-PLUGINS Kaspersky Online Scanner KAVWebScan.dll ActiveX clsid access (more info ...)attempted-user 2007-3675 26004  
12639BROWSER-PLUGINS Kaspersky Online Scanner KAVWebScan.dll ActiveX function call access (more info ...)attempted-user 2007-3675 26004  
12642OS-WINDOWS RPC NTLMSSP malformed credentials (more info ...)denial-of-service 2007-2228   URL
12643OS-WINDOWS Microsoft Windows URI External handler arbitrary command attempt (more info ...)attempted-user 2007-3896   URL
12644BROWSER-PLUGINS PBEmail7 ActiveX clsid access (more info ...)attempted-user 2007-5446 26058  
12646BROWSER-PLUGINS PBEmail7 ActiveX function call access (more info ...)attempted-user 2007-5446 26058  
12648BROWSER-PLUGINS DB Software Laboratory VImpX ActiveX clsid access (more info ...)attempted-user 2007-5445 26064  
12650BROWSER-PLUGINS DB Software Laboratory VImpX ActiveX function call access (more info ...)attempted-user 2007-5445 26064  
12687OS-WINDOWS Microsoft Windows ShellExecute and IE7 url handling code execution attempt (more info ...)attempted-user 2007-3896 25945  URL
12688OS-WINDOWS Microsoft Windows ShellExecute and IE7 url handling code execution attempt (more info ...)attempted-user 2007-3896 25945  URL
12689BROWSER-PLUGINS GlobalLink ConnectAndEnterRoom ActiveX clsid access (more info ...)attempted-user 2007-5722 26244  
12714BROWSER-PLUGINS WebEx GPCContainer ActiveX clsid access (more info ...)attempted-user 2007-6005 26430  
12716BROWSER-PLUGINS WebEx GPCContainer ActiveX function call access (more info ...)attempted-user 2007-6005 26430  
12731BROWSER-PLUGINS AOL Radio AmpX ActiveX function call access (more info ...)attempted-user 2007-5755 35028  
12733BROWSER-PLUGINS ComponentOne FlexGrid ActiveX clsid access (more info ...)attempted-user 2007-6028 26467  
12735BROWSER-PLUGINS ComponentOne FlexGrid ActiveX function call access (more info ...)attempted-user 2007-6028 26467  
12737BROWSER-PLUGINS Xunlei Thunder PPLAYER.DLL ActiveX clsid access (more info ...)attempted-user 2007-6144 26536  
12739BROWSER-PLUGINS Xunlei Thunder PPLAYER.DLL ActiveX function call access (more info ...)attempted-user 2007-6144 26536  
12749BROWSER-PLUGINS BitDefender Online Scanner ActiveX function call access (more info ...)attempted-user 2007-5775 26210  
12751BROWSER-PLUGINS RichFX Basic Player ActiveX clsid access (more info ...)attempted-user  26573  
12753BROWSER-PLUGINS RichFX Basic Player ActiveX function call access (more info ...)attempted-user  26573  
12755BROWSER-PLUGINS PPStream PowerList ActiveX clsid access (more info ...)attempted-user  26580  
12762BROWSER-PLUGINS Yahoo Toolbar Helper Class ActiveX clsid access (more info ...)attempted-user 2007-6228 26656  
12764BROWSER-PLUGINS Yahoo Toolbar Helper Class ActiveX function call access (more info ...)attempted-user 2007-6228 26656  
12770BROWSER-PLUGINS Microsoft Windows obfuscated RDS.Dataspace ActiveX exploit attempt (more info ...)attempted-user 2006-0003 17462  URL
12771BROWSER-PLUGINS obfuscated BaoFeng Storm MPS.dll ActiveX exploit attempt (more info ...)attempted-user 2007-4816 25601  URL
12772BROWSER-PLUGINS obfuscated PPStream PowerPlayer ActiveX exploit attempt (more info ...)attempted-user 2007-4748 25502  URL
12773BROWSER-PLUGINS obfuscated Xunlei Thunder PPLAYER.DLL ActiveX exploit attempt (more info ...)attempted-user 2007-6144 26536  URL
12774BROWSER-PLUGINS obfuscated GlobalLink ConnectAndEnterRoom ActiveX exploit attempt (more info ...)attempted-user 2007-5722 26244  URL
12780BROWSER-PLUGINS Aurigma Image Uploader 4 Vulnerable Methods ActiveX clsid access attempt (more info ...)attempted-user 2008-0660 27577  URL
12782BROWSER-PLUGINS Aurigma Image Uploader 4 Vulnerable Methods ActiveX function call access attempt (more info ...)attempted-user 2008-0660 27577  URL
12803BROWSER-PLUGINS VideoLAN VLC ActiveX clsid access (more info ...)attempted-user 2007-6262 26675  URL
12805BROWSER-PLUGINS VideoLAN VLC ActiveX function call access (more info ...)attempted-user 2007-6262 26675  URL
12808NETBIOS DCERPC NCACN-IP-TCP spoolss OpenPrinter overflow attempt (more info ...)attempted-admin 2006-5854 21220  
12946OS-WINDOWS Microsoft Windows SMB-DS SMBv2 protocol negotiation attempt (more info ...)attempted-admin 2007-5351   URL
12947OS-WINDOWS Microsoft Windows SMB SMBv2 protocol negotiation attempt (more info ...)attempted-admin 2007-5351   URL
12948BROWSER-PLUGINS Vantage Linguistics 1 ActiveX clsid access (more info ...)attempted-user    URL
12950BROWSER-PLUGINS Vantage Linguistics 2 ActiveX clsid access (more info ...)attempted-user    URL
12952BROWSER-PLUGINS Vantage Linguistics 3 ActiveX clsid access (more info ...)attempted-user    URL
12961BROWSER-PLUGINS Intuit QuickBooks Online Import 1 ActiveX clsid access (more info ...)attempted-user    URL
12963BROWSER-PLUGINS Intuit QuickBooks Online Import 2 ActiveX clsid access (more info ...)attempted-user    URL
12965BROWSER-PLUGINS Intuit QuickBooks Online Import 3 ActiveX clsid access (more info ...)attempted-user    URL
12967BROWSER-PLUGINS Intuit QuickBooks Online Import 4 ActiveX clsid access (more info ...)attempted-user    URL
12969BROWSER-PLUGINS Intuit QuickBooks Online Import 5 ActiveX clsid access (more info ...)attempted-user    URL
12971FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2007-3895   URL
12977OS-WINDOWS DCERPC NCACN-IP-TCP mqqm QMCreateObjectInternal overflow attempt (more info ...)attempted-admin 2007-3039   URL
12978OS-WINDOWS DCERPC NCADG-IP-UDP mqqm QMCreateObjectInternal overflow attempt (more info ...)attempted-admin 2007-3039   URL
13158FILE-MULTIMEDIA Microsoft Media Player asf streaming format interchange data integer overflow attempt (more info ...)attempted-user 2007-0064   URL
13159FILE-MULTIMEDIA Microsoft Media Player asf streaming format audio error masking integer overflow attempt (more info ...)attempted-user 2007-0064   URL
13160FILE-MULTIMEDIA Microsoft Media Player asf streaming audio spread error correction data length integer overflow attempt (more info ...)attempted-user 2007-0064   URL
13210OS-WINDOWS DCERPC NCACN-IP-TCP mqqm QMObjectPathToObjectFormat overflow attempt (more info ...)attempted-admin 2007-3039   URL
13211OS-WINDOWS DCERPC NCADG-IP-UDP mqqm QMObjectPathToObjectFormat overflow attempt (more info ...)attempted-admin 2007-3039   URL
13219BROWSER-PLUGINS HP Software Update RulesEngine.dll ActiveX clsid access (more info ...)attempted-user 2007-6506 26950  
13226BROWSER-PLUGINS Yahoo Toolbar YShortcut ActiveX function call access (more info ...)attempted-user 2007-6535 26956  
13228BROWSER-PLUGINS HP eSupportDiagnostics 1 ActiveX clsid access (more info ...)attempted-user 2007-6513 26967  URL
13230BROWSER-PLUGINS HP eSupportDiagnostics 2 ActiveX clsid access (more info ...)attempted-user 2007-6513 26967  URL
13232BROWSER-PLUGINS Persits Software XUpload ActiveX clsid access (more info ...)attempted-user 2009-3693 36550  
13234BROWSER-PLUGINS Persits Software XUpload ActiveX function call access (more info ...)attempted-user 2009-3693 36550  
13250PROTOCOL-RPC portmap 390113 tcp request (more info ...)rpc-portmap-decode 2007-3618 25375  
13251PROTOCOL-RPC portmap 390113 udp request (more info ...)rpc-portmap-decode 2007-3618 25375  
13252PROTOCOL-RPC portmap 390113 tcp procedure 4 attempt (more info ...)rpc-portmap-decode 2007-3618 25375  
13253PROTOCOL-RPC portmap 390113 udp procedure 4 attempt (more info ...)rpc-portmap-decode 2007-3618 25375  
13256PROTOCOL-RPC portmap 390113 tcp procedure 5 attempt (more info ...)rpc-portmap-decode 2007-3618 25375  
13257PROTOCOL-RPC portmap 390113 udp procedure 5 attempt (more info ...)rpc-portmap-decode 2007-3618 25375  
13266BROWSER-PLUGINS SkyFex Client ActiveX clsid access (more info ...)attempted-user 2007-6605 27059  
13273BROWSER-PLUGINS DivX Web Player ActiveX clsid access (more info ...)attempted-user 2008-0090 27106  
13275BROWSER-PLUGINS DivX Web Player ActiveX function call access (more info ...)attempted-user 2008-0090 27106  
13289BROWSER-PLUGINS Gatway CWebLaunchCtl ActiveX clsid access (more info ...)attempted-user 2008-0220 27193  URL
13294BROWSER-PLUGINS Microsoft Rich TextBox ActiveX clsid access (more info ...)attempted-user 2008-0237 27201  
13296BROWSER-PLUGINS Microsoft Rich TextBox ActiveX clsid access (more info ...)attempted-user 2008-0237 27201  
13298BROWSER-PLUGINS Microsoft Rich TextBox ActiveX function call access (more info ...)attempted-user 2008-0237 27201  
13303BROWSER-PLUGINS Microsoft Visual FoxPro 2 ActiveX clsid access (more info ...)attempted-user 2008-0236 27205  
13305BROWSER-PLUGINS Microsoft Visual FoxPro 2 ActiveX function call access (more info ...)attempted-user 2008-0236 27205  
13312BROWSER-PLUGINS StreamAudio ProxyManager ActiveX clsid access (more info ...)attempted-user 2008-0248 27247  
13314BROWSER-PLUGINS StreamAudio ProxyManager ActiveX function call access (more info ...)attempted-user 2008-0248 27247  
13321BROWSER-PLUGINS Microsoft Package and Deployment Wizard ActiveX clsid access (more info ...)attempted-user 2007-3041 25295  URL
13323BROWSER-PLUGINS Microsoft Package and Deployment Wizard ActiveX function call access (more info ...)attempted-user 2007-3041 25295  URL
13329BROWSER-PLUGINS Toshiba Surveillance Surveillix DVR ActiveX clsid access (more info ...)attempted-user 2008-0399 27360  
13331BROWSER-PLUGINS Toshiba Surveillance Surveillix DVR ActiveX function call access (more info ...)attempted-user 2008-0399 27360  
13333BROWSER-PLUGINS HP Virtual Rooms ActiveX clsid access (more info ...)attempted-user 2008-0437 27384  
13335BROWSER-PLUGINS Lycos File Upload Component ActiveX clsid access (more info ...)attempted-user 2008-0443 27411  
13337BROWSER-PLUGINS Comodo AntiVirus ActiveX clsid access (more info ...)attempted-user 2008-0470 27424  
13348BROWSER-PLUGINS Move Networks Media Player ActiveX clsid access (more info ...)attempted-user 2008-0477 27438  
13350BROWSER-PLUGINS Move Networks Media Player ActiveX function call access (more info ...)attempted-user 2008-0477 27438  
13352BROWSER-PLUGINS Lycos File Upload Component ActiveX function call access (more info ...)attempted-user 2008-0443 27411  
13354BROWSER-PLUGINS HP Virtual Rooms ActiveX function call access (more info ...)attempted-user 2008-0437 27384  
13367NETBIOS DCERPC NCACN-IP-TCP spoolss GetPrinterData attempt (more info ...)protocol-command-decode 2006-6296 21401  
13421BROWSER-PLUGINS Facebook Photo Uploader ActiveX function call access (more info ...)attempted-user 2008-0660 27576  URL
13423BROWSER-PLUGINS SwiftView ActiveX clsid access (more info ...)attempted-user 2007-5602 27527  URL
13428BROWSER-PLUGINS Yahoo Music JukeBox DataGrid ActiveX function call access (more info ...)attempted-user 2008-0624 27579  
13430BROWSER-PLUGINS Yahoo Music JukeBox MediaGrid ActiveX clsid access (more info ...)attempted-user 2008-0625 27578  
13432BROWSER-PLUGINS Yahoo Music JukeBox MediaGrid ActiveX function call access (more info ...)attempted-user 2008-0625 27578  
13434BROWSER-PLUGINS Aurigma Image Uploader 4 Property Overflows ActiveX clsid access (more info ...)attempted-user 2008-0660 27577  URL
13436BROWSER-PLUGINS Aurigma Image Uploader 4 Property Overflows ActiveX function call access (more info ...)attempted-user 2008-0660 27577  URL
13438BROWSER-PLUGINS Aurigma Image Uploader 5 Vulnerable Methods ActiveX clsid access (more info ...)attempted-user 2008-0660 27577  URL
13440BROWSER-PLUGINS Aurigma Image Uploader 5 Vulnerable Methods ActiveX function call access (more info ...)attempted-user 2008-0660 27577  URL
13442BROWSER-PLUGINS Aurigma Image Uploader 5 Property Overflows ActiveX clsid access (more info ...)attempted-user 2008-0660 27577  URL
13444BROWSER-PLUGINS Aurigma Image Uploader 5 Property Overflows ActiveX function call access (more info ...)attempted-user 2008-0660 27577  URL
13446BROWSER-PLUGINS GlobalLink HanGamePlugin ActiveX clsid access (more info ...)attempted-user 2008-0647 27626  
13448OS-WINDOWS Microsoft Windows vbscript/jscript scripting engine begin buffer overflow attempt (more info ...)attempted-user 2008-0083   URL
13449OS-WINDOWS Microsoft Windows vbscript/jscript scripting engine end buffer overflow attempt (more info ...)attempted-user 2008-0083   URL
13451BROWSER-PLUGINS Microsoft Windows Visual FoxPro foxtlib ActiveX clsid access (more info ...)attempted-user 2007-5322 25977  URL
13465FILE-IDENTIFY Microsoft Works file download request (more info ...)misc-activity    URL
13475OS-WINDOWS Microsoft Active Directory LDAP denial of service attempt (more info ...)attempted-dos 2008-0088   URL
13527BROWSER-PLUGINS D-Link MPEG4 SHM Audio Control ActiveX clsid access (more info ...)attempted-user 2008-4771 28010  
13529BROWSER-PLUGINS D-Link MPEG4 SHM Audio Control ActiveX function call access (more info ...)attempted-user 2008-4771 28010  
13531BROWSER-PLUGINS 4xem VatCtrl ActiveX clsid access (more info ...)attempted-user 2008-4771 28010  
13533BROWSER-PLUGINS 4xem VatCtrl ActiveX function call access (more info ...)attempted-user 2008-4771 28010  
13535BROWSER-PLUGINS Vivotek RTSP MPEG4 SP Control ActiveX clsid access (more info ...)attempted-user 2008-4771 28010  
13537BROWSER-PLUGINS Vivotek RTSP MPEG4 SP Control ActiveX function call access (more info ...)attempted-user 2008-4771 28010  
13541BROWSER-PLUGINS Symantec Backup Exec ActiveX function call access (more info ...)attempted-user 2007-6016 26904  URL
13543BROWSER-PLUGINS Learn2 STRunner ActiveX clsid access (more info ...)attempted-user 2007-6252 28058  
13545BROWSER-PLUGINS Learn2 STRunner ActiveX function call access (more info ...)attempted-user 2007-6252 28058  
13547BROWSER-PLUGINS Sony ImageStation ActiveX clsid access (more info ...)attempted-user 2008-0748 27715  
13549BROWSER-PLUGINS Sony ImageStation ActiveX function call access (more info ...)attempted-user 2008-0748 27715  
13583FILE-IDENTIFY Microsoft SYmbolic LinK file download request (more info ...)misc-activity 2008-0112   URL
13585FILE-IDENTIFY Microsoft SYmbolic LinK file magic detected (more info ...)misc-activity 2008-0112   URL
13594OS-WINDOWS Microsoft Windows print spooler little endian DoS attempt (more info ...)protocol-command-decode 2006-6296 21401  
13595BROWSER-PLUGINS ICQ Toolbar toolbaru.dll ActiveX clsid access (more info ...)attempted-user 2008-7136 28118  
13597BROWSER-PLUGINS ICQ Toolbar toolbaru.dll ActiveX function call access (more info ...)attempted-user 2008-7136 28118  
13599BROWSER-PLUGINS Kingsoft Antivirus Online Update Module ActiveX clsid access (more info ...)attempted-user 2008-1307 28172  
13601BROWSER-PLUGINS Kingsoft Antivirus Online Update Module ActiveX function call access (more info ...)attempted-user 2008-1307 28172  
13623BROWSER-PLUGINS CA BrightStor ListCtrl ActiveX function call access (more info ...)attempted-user 2008-1472 28268  
13657BROWSER-PLUGINS BusinessObjects RptViewerAx ActiveX clsid access (more info ...)attempted-user 2007-6254 28292  
13659BROWSER-PLUGINS BusinessObjects RptViewerAx ActiveX function call access (more info ...)attempted-user 2007-6254 28292  
13661BROWSER-PLUGINS VeralSoft HTTP File Upload ActiveX clsid access (more info ...)attempted-user 2008-6638 28301  
13666OS-WINDOWS Microsoft Windows GDI integer overflow attempt (more info ...)attempted-user 2008-1083   URL
13668BROWSER-PLUGINS Microsoft Windows Help 2.0 Contents Control ActiveX clsid access (more info ...)attempted-user 2008-1086   URL
13670BROWSER-PLUGINS Microsoft Windows Help 2.0 Contents Control ActiveX function call access (more info ...)attempted-user 2008-1086   URL
13672BROWSER-PLUGINS Microsoft Windows Help 2.0 Contents Control 2 ActiveX clsid access (more info ...)attempted-user 2008-1086   URL
13674BROWSER-PLUGINS Microsoft Windows Help 2.0 Contents Control 2 ActiveX function call access (more info ...)attempted-user 2008-1086   URL
13679BROWSER-PLUGINS IBiz EBanking Integrator ActiveX clsid access (more info ...)attempted-user 2008-1725 28700  
13681BROWSER-PLUGINS CDNetworks Nefficient Download ActiveX clsid access (more info ...)attempted-user 2008-1886 28666  
13683BROWSER-PLUGINS CDNetworks Nefficient Download ActiveX function call access (more info ...)attempted-user 2008-1886 28666  
13685BROWSER-PLUGINS Chilkat HTTP 1 ActiveX clsid access (more info ...)attempted-user 2008-1647 28546  
13687BROWSER-PLUGINS Chilkat HTTP 1 ActiveX function call access (more info ...)attempted-user 2008-1647 28546  
13689BROWSER-PLUGINS Chilkat HTTP 2 ActiveX clsid access (more info ...)attempted-user 2008-1647 28546  
13691BROWSER-PLUGINS Chilkat HTTP 2 ActiveX function call access (more info ...)attempted-user 2008-1647 28546  
13720BROWSER-PLUGINS HP eSupportDiagnostics 3 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13722BROWSER-PLUGINS HP eSupportDiagnostics 4 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13724BROWSER-PLUGINS HP eSupportDiagnostics 5 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13726BROWSER-PLUGINS HP eSupportDiagnostics 6 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13728BROWSER-PLUGINS HP eSupportDiagnostics 7 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13730BROWSER-PLUGINS HP eSupportDiagnostics 8 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13732BROWSER-PLUGINS HP eSupportDiagnostics 9 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13734BROWSER-PLUGINS HP eSupportDiagnostics 10 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13736BROWSER-PLUGINS HP eSupportDiagnostics 11 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13738BROWSER-PLUGINS HP eSupportDiagnostics 12 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13740BROWSER-PLUGINS HP eSupportDiagnostics 13 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13742BROWSER-PLUGINS HP eSupportDiagnostics 14 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13744BROWSER-PLUGINS HP eSupportDiagnostics 15 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13746BROWSER-PLUGINS HP eSupportDiagnostics 16 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13748BROWSER-PLUGINS HP eSupportDiagnostics 17 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13750BROWSER-PLUGINS HP eSupportDiagnostics 18 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13752BROWSER-PLUGINS HP eSupportDiagnostics 19 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13754BROWSER-PLUGINS HP eSupportDiagnostics 20 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13756BROWSER-PLUGINS HP eSupportDiagnostics 21 ActiveX clsid access (more info ...)attempted-user 2008-0712 28929  URL
13758BROWSER-PLUGINS Microsoft HeartbeatCtl ActiveX clsid access (more info ...)attempted-user 2007-6255 28882  
13760BROWSER-PLUGINS Microsoft HeartbeatCtl ActiveX function call access (more info ...)attempted-user 2007-6255 28882  
13783BROWSER-PLUGINS Yahoo Assistant ActiveX clsid access (more info ...)attempted-user 2008-2111 29065  
13785BROWSER-PLUGINS Ourgame GLWorld ActiveX clsid access (more info ...)attempted-user 2008-0647 27626  
13787BROWSER-PLUGINS Ourgame GLWorld ActiveX function call access (more info ...)attempted-user 2008-0647 27626  
13798OS-WINDOWS Microsoft malware protection engine denial of service attempt (more info ...)attempted-dos 2008-1437   URL
13807FILE-IMAGE Microsoft Windows metafile SetPaletteEntries heap overflow attempt (more info ...)attempted-user 2005-2124 15356  URL
13824FILE-MULTIMEDIA Microsoft Windows DirectX malformed mjpeg arbitrary code execution attempt (more info ...)attempted-user 2008-0011   URL
13827OS-WINDOWS Microsoft Windows PGM denial of service attempt (more info ...)attempted-dos 2008-1440   URL
13835OS-WINDOWS Microsoft Active Directory LDAP cookie denial of service attempt (more info ...)attempted-dos 2008-1445   URL
13857BROWSER-PLUGINS HP Instant Support DataManager ActiveX clsid access (more info ...)attempted-user 2008-0953 29536  URL
13859BROWSER-PLUGINS HP Instant Support DataManager ActiveX function call access (more info ...)attempted-user 2008-0953 29536  URL
13883BROWSER-PLUGINS UUSee UUUpgrade ActiveX clsid access (more info ...)attempted-user 2008-7168 29963  
13885BROWSER-PLUGINS UUSee UUUpgrade ActiveX function call access (more info ...)attempted-user 2008-7168 29963  
13893FILE-OTHER Microsoft malformed saved search heap corruption attempt (more info ...)attempted-admin 2008-1435   URL
13903BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX clsid access attempt (more info ...)attempted-user 2008-2463 30114  URL
13905BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX function call access attempt (more info ...)attempted-user 2008-2463 30114  URL
13907BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX clsid access attempt (more info ...)attempted-user 2008-2463 30114  URL
13913BROWSER-PLUGINS AcroPDF.PDF ActiveX clsid access attempt (more info ...)attempted-user 2006-6236 21338  URL
13975BROWSER-PLUGINS Microsoft Windows Event System ActiveX clsid access (more info ...)attempted-user 2008-1457   URL
13976BROWSER-PLUGINS Microsoft Windows Event System ActiveX clsid unicode access (more info ...)attempted-user 2008-1457   URL
13977BROWSER-PLUGINS Microsoft Windows Event System ActiveX function call access (more info ...)attempted-user 2008-1457   URL
13978BROWSER-PLUGINS Microsoft Windows Event System ActiveX function call unicode access (more info ...)attempted-user 2008-1457   URL
13979OS-WINDOWS Microsoft Windows Event System Subscription VBScript access (more info ...)attempted-user 2008-1457   URL
14015BROWSER-PLUGINS Cisco WebEx Meeting Manager atucfobj ActiveX function call access (more info ...)attempted-user 2008-3558 30578  URL
14023BROWSER-PLUGINS Microsoft Visual Studio Msmask32 ActiveX function call access (more info ...)attempted-user 2008-3704 30674  URL
14027BROWSER-PLUGINS CA DSM gui_cm_ctrls ActiveX function call access (more info ...)attempted-user 2008-1786 28809  
14029BROWSER-PLUGINS Computer Associates gui_cm_ctrls ActiveX clsid access (more info ...)attempted-user 2008-1786   
14031BROWSER-PLUGINS Computer Associates gui_cm_ctrls ActiveX function call access (more info ...)attempted-user 2008-1786   
14066PUA-ADWARE Adware winsecuredisc runtime detection (more info ...)misc-activity    URL
14078PUA-ADWARE Adware winspywareprotect runtime detection - download malicous code (more info ...)misc-activity    URL
14079PUA-ADWARE Adware winspywareprotect runtime detection - connection to malicious sites (more info ...)misc-activity    URL
14080PUA-ADWARE Adware winspywareprotect runtime detection - connection to malicious server (more info ...)misc-activity    URL
14088BROWSER-PLUGINS Aurigma Image Uploader unspecified 1 ActiveX clsid access (more info ...)attempted-user    URL
14090BROWSER-PLUGINS Aurigma Image Uploader unspecified 2 ActiveX clsid access (more info ...)attempted-user    URL
14092BROWSER-PLUGINS Aurigma Image Uploader unspecified 3 ActiveX clsid access (more info ...)attempted-user    URL
14094BROWSER-PLUGINS Aurigma Image Uploader unspecified 4 ActiveX clsid access (more info ...)attempted-user    URL
14096BROWSER-PLUGINS Aurigma Image Uploader unspecified 5 ActiveX clsid access (more info ...)attempted-user    URL
14098BROWSER-PLUGINS Aurigma Image Uploader unspecified 6 ActiveX clsid access (more info ...)attempted-user    URL
14100BROWSER-PLUGINS Aurigma Image Uploader unspecified 7 ActiveX clsid access (more info ...)attempted-user    URL
14102BROWSER-PLUGINS Aurigma Image Uploader unspecified 8 ActiveX clsid access (more info ...)attempted-user    URL
14104BROWSER-PLUGINS Aurigma Image Uploader unspecified 9 ActiveX clsid access (more info ...)attempted-user    URL
14106BROWSER-PLUGINS Aurigma Image Uploader unspecified 10 ActiveX clsid access (more info ...)attempted-user    URL
14108BROWSER-PLUGINS Aurigma Image Uploader unspecified 11 ActiveX clsid access (more info ...)attempted-user    URL
14110BROWSER-PLUGINS Aurigma Image Uploader unspecified 12 ActiveX clsid access (more info ...)attempted-user    URL
14112BROWSER-PLUGINS Aurigma Image Uploader unspecified 13 ActiveX clsid access (more info ...)attempted-user    URL
14114BROWSER-PLUGINS Aurigma Image Uploader unspecified 14 ActiveX clsid access (more info ...)attempted-user    URL
14116BROWSER-PLUGINS Aurigma Image Uploader unspecified 15 ActiveX clsid access (more info ...)attempted-user    URL
14118BROWSER-PLUGINS Aurigma Image Uploader unspecified 16 ActiveX clsid access (more info ...)attempted-user    URL
14120BROWSER-PLUGINS Aurigma Image Uploader unspecified 17 ActiveX clsid access (more info ...)attempted-user    URL
14122BROWSER-PLUGINS Aurigma Image Uploader unspecified 18 ActiveX clsid access (more info ...)attempted-user    URL
14124BROWSER-PLUGINS Aurigma Image Uploader unspecified 19 ActiveX clsid access (more info ...)attempted-user    URL
14126BROWSER-PLUGINS Aurigma Image Uploader unspecified 20 ActiveX clsid access (more info ...)attempted-user    URL
14128BROWSER-PLUGINS Aurigma Image Uploader unspecified 21 ActiveX clsid access (more info ...)attempted-user    URL
14130BROWSER-PLUGINS Aurigma Image Uploader unspecified 22 ActiveX clsid access (more info ...)attempted-user    URL
14132BROWSER-PLUGINS Aurigma Image Uploader unspecified 23 ActiveX clsid access (more info ...)attempted-user    URL
14134BROWSER-PLUGINS Aurigma Image Uploader unspecified 24 ActiveX clsid access (more info ...)attempted-user    URL
14136BROWSER-PLUGINS Aurigma Image Uploader unspecified 25 ActiveX clsid access (more info ...)attempted-user    URL
14138BROWSER-PLUGINS Aurigma Image Uploader unspecified 26 ActiveX clsid access (more info ...)attempted-user    URL
14140BROWSER-PLUGINS Aurigma Image Uploader unspecified 27 ActiveX clsid access (more info ...)attempted-user    URL
14142BROWSER-PLUGINS Aurigma Image Uploader unspecified 28 ActiveX clsid access (more info ...)attempted-user    URL
14144BROWSER-PLUGINS Aurigma Image Uploader unspecified 29 ActiveX clsid access (more info ...)attempted-user    URL
14146BROWSER-PLUGINS Aurigma Image Uploader unspecified 30 ActiveX clsid access (more info ...)attempted-user    URL
14148BROWSER-PLUGINS Aurigma Image Uploader unspecified 31 ActiveX clsid access (more info ...)attempted-user    URL
14150BROWSER-PLUGINS Aurigma Image Uploader unspecified 32 ActiveX clsid access (more info ...)attempted-user    URL
14152BROWSER-PLUGINS Aurigma Image Uploader unspecified 33 ActiveX clsid access (more info ...)attempted-user    URL
14154BROWSER-PLUGINS Aurigma Image Uploader unspecified 34 ActiveX clsid access (more info ...)attempted-user    URL
14156BROWSER-PLUGINS Aurigma Image Uploader unspecified 35 ActiveX clsid access (more info ...)attempted-user    URL
14158BROWSER-PLUGINS Aurigma Image Uploader unspecified 36 ActiveX clsid access (more info ...)attempted-user    URL
14160BROWSER-PLUGINS Aurigma Image Uploader unspecified 37 ActiveX clsid access (more info ...)attempted-user    URL
14162BROWSER-PLUGINS Aurigma Image Uploader unspecified 38 ActiveX clsid access (more info ...)attempted-user    URL
14164BROWSER-PLUGINS Aurigma Image Uploader unspecified 39 ActiveX clsid access (more info ...)attempted-user    URL
14166BROWSER-PLUGINS Aurigma Image Uploader unspecified 40 ActiveX clsid access (more info ...)attempted-user    URL
14168BROWSER-PLUGINS Aurigma Image Uploader unspecified 41 ActiveX clsid access (more info ...)attempted-user    URL
14170BROWSER-PLUGINS Aurigma Image Uploader unspecified 42 ActiveX clsid access (more info ...)attempted-user    URL
14172BROWSER-PLUGINS Aurigma Image Uploader unspecified 43 ActiveX clsid access (more info ...)attempted-user    URL
14174BROWSER-PLUGINS Aurigma Image Uploader unspecified 44 ActiveX clsid access (more info ...)attempted-user    URL
14176BROWSER-PLUGINS Aurigma Image Uploader unspecified 45 ActiveX clsid access (more info ...)attempted-user    URL
14178BROWSER-PLUGINS Aurigma Image Uploader unspecified 46 ActiveX clsid access (more info ...)attempted-user    URL
14180BROWSER-PLUGINS Aurigma Image Uploader unspecified 47 ActiveX clsid access (more info ...)attempted-user    URL
14182BROWSER-PLUGINS Aurigma Image Uploader unspecified 48 ActiveX clsid access (more info ...)attempted-user    URL
14184BROWSER-PLUGINS Aurigma Image Uploader unspecified 49 ActiveX clsid access (more info ...)attempted-user    URL
14186BROWSER-PLUGINS Aurigma Image Uploader unspecified 50 ActiveX clsid access (more info ...)attempted-user    URL
14188BROWSER-PLUGINS Aurigma Image Uploader unspecified 51 ActiveX clsid access (more info ...)attempted-user    URL
14190BROWSER-PLUGINS Aurigma Image Uploader unspecified 52 ActiveX clsid access (more info ...)attempted-user    URL
14192BROWSER-PLUGINS Aurigma Image Uploader unspecified 53 ActiveX clsid access (more info ...)attempted-user    URL
14194BROWSER-PLUGINS Aurigma Image Uploader unspecified 54 ActiveX clsid access (more info ...)attempted-user    URL
14196BROWSER-PLUGINS Aurigma Image Uploader unspecified 55 ActiveX clsid access (more info ...)attempted-user    URL
14198BROWSER-PLUGINS Aurigma Image Uploader unspecified 56 ActiveX clsid access (more info ...)attempted-user    URL
14200BROWSER-PLUGINS Aurigma Image Uploader unspecified 57 ActiveX clsid access (more info ...)attempted-user    URL
14202BROWSER-PLUGINS Aurigma Image Uploader unspecified 58 ActiveX clsid access (more info ...)attempted-user    URL
14204BROWSER-PLUGINS Aurigma Image Uploader unspecified 59 ActiveX clsid access (more info ...)attempted-user    URL
14206BROWSER-PLUGINS Aurigma Image Uploader unspecified 60 ActiveX clsid access (more info ...)attempted-user    URL
14208BROWSER-PLUGINS Aurigma Image Uploader unspecified 61 ActiveX clsid access (more info ...)attempted-user    URL
14210BROWSER-PLUGINS Aurigma Image Uploader unspecified 62 ActiveX clsid access (more info ...)attempted-user    URL
14212BROWSER-PLUGINS Aurigma Image Uploader unspecified 63 ActiveX clsid access (more info ...)attempted-user    URL
14214BROWSER-PLUGINS Aurigma Image Uploader unspecified 64 ActiveX clsid access (more info ...)attempted-user    URL
14216BROWSER-PLUGINS Aurigma Image Uploader unspecified 65 ActiveX clsid access (more info ...)attempted-user    URL
14218BROWSER-PLUGINS Aurigma Image Uploader unspecified 66 ActiveX clsid access (more info ...)attempted-user    URL
14220BROWSER-PLUGINS Aurigma Image Uploader unspecified 67 ActiveX clsid access (more info ...)attempted-user    URL
14222BROWSER-PLUGINS Aurigma Image Uploader unspecified 68 ActiveX clsid access (more info ...)attempted-user    URL
14224BROWSER-PLUGINS Aurigma Image Uploader unspecified 69 ActiveX clsid access (more info ...)attempted-user    URL
14226BROWSER-PLUGINS Aurigma Image Uploader unspecified 70 ActiveX clsid access (more info ...)attempted-user    URL
14228BROWSER-PLUGINS Aurigma Image Uploader unspecified 71 ActiveX clsid access (more info ...)attempted-user    URL
14231BROWSER-PLUGINS SoftArtisans XFile FileManager ActiveX clsid access (more info ...)attempted-user 2007-1682 30826  URL
14233BROWSER-PLUGINS SoftArtisans XFile FileManager ActiveX function call access (more info ...)attempted-user 2007-1682 30826  URL
14239BROWSER-PLUGINS Friendly Technologies fwRemoteConfig ActiveX clsid access (more info ...)attempted-user 2008-4049 30891  
14241BROWSER-PLUGINS Friendly Technologies fwRemoteConfig ActiveX function call access (more info ...)attempted-user 2008-4049 30891  
14243BROWSER-PLUGINS Najdi.si Toolbar ActiveX clsid access (more info ...)attempted-user 2008-7103 30922  
14245BROWSER-PLUGINS Najdi.si Toolbar ActiveX function call access (more info ...)attempted-user 2008-7103 30922  
14247BROWSER-PLUGINS Eyeball MessengerSDK ActiveX clsid access (more info ...)attempted-user 2008-3430 30424  
14249BROWSER-PLUGINS Eyeball MessengerSDK ActiveX function call access (more info ...)attempted-user 2008-3430 30424  
14251OS-WINDOWS Microsoft GDI malformed metarecord buffer overflow attempt (more info ...)attempted-user 2008-3014   URL
14261OS-WINDOWS Microsoft Windows GDI VML gradient size heap overflow attempt (more info ...)attempted-user 2007-5348   URL
14266BROWSER-PLUGINS Microsoft Windows Image Acquisition Logger ActiveX clsid access (more info ...)attempted-user 2008-3957 31069  
14268BROWSER-PLUGINS Microsoft Windows Image Acquisition Logger ActiveX function call access (more info ...)attempted-user 2008-3957 31069  
14270BROWSER-PLUGINS VieLib2.Vie2Locator ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14272BROWSER-PLUGINS VieLib2.Vie2Locator ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14274BROWSER-PLUGINS Vie2Lib.Vie2LinuxVolume ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14276BROWSER-PLUGINS Vie2Lib.Vie2LinuxVolume ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14278BROWSER-PLUGINS VieLib2.Vie2Process ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14280BROWSER-PLUGINS VieLib2.Vie2Process ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14282BROWSER-PLUGINS IntraProcessLogging.Logger ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14284BROWSER-PLUGINS IntraProcessLogging.Logger ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14286BROWSER-PLUGINS VMClientHosts Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14288BROWSER-PLUGINS VMClientHosts Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14290BROWSER-PLUGINS VhdCvtCom.DiskLibCreateParamObj ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14292BROWSER-PLUGINS VhdCvtCom.DiskLibCreateParamObj ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14294BROWSER-PLUGINS RemoteDirDlg Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14296BROWSER-PLUGINS RemoteDirDlg Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14298BROWSER-PLUGINS TeamListViewWnd Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14300BROWSER-PLUGINS TeamListViewWnd Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14302BROWSER-PLUGINS VMStatusbarCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14304BROWSER-PLUGINS VMStatusbarCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14306BROWSER-PLUGINS Vmc2vmx.CoVPCConfiguration ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14308BROWSER-PLUGINS Vmc2vmx.CoVPCConfiguration ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14310BROWSER-PLUGINS VmdbUpdate Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14312BROWSER-PLUGINS VmdbUpdate Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14314BROWSER-PLUGINS VMWare unspecified 1 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14316BROWSER-PLUGINS VmdbExecuteError Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14318BROWSER-PLUGINS VmdbExecuteError Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14320BROWSER-PLUGINS VMWare unspecified 2 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14322BROWSER-PLUGINS reconfig.SysImageUti ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14324BROWSER-PLUGINS reconfig.SysImageUti ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14326BROWSER-PLUGINS Microsoft Visual Database Tools Query Designer V7.0 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14328BROWSER-PLUGINS Microsoft Visual Database Tools Query Designer V7.0 ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14330BROWSER-PLUGINS VmdbContext Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14332BROWSER-PLUGINS VmdbContext Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14334BROWSER-PLUGINS VMClientVMs Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14336BROWSER-PLUGINS VMClientVMs Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14338BROWSER-PLUGINS vmappPropObj Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14340BROWSER-PLUGINS vmappPropObj Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14342BROWSER-PLUGINS VMWare unspecified 3 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14344BROWSER-PLUGINS VMMsg Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14346BROWSER-PLUGINS VMMsg Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14348BROWSER-PLUGINS VMWare unspecified 4 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14350BROWSER-PLUGINS reconfig.PopulatedDi ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14352BROWSER-PLUGINS reconfig.PopulatedDi ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14354BROWSER-PLUGINS Elevated.ElevMgr ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14356BROWSER-PLUGINS Elevated.ElevMgr ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14358BROWSER-PLUGINS VMWare unspecified 5 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14360BROWSER-PLUGINS HardwareCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14362BROWSER-PLUGINS HardwareCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14364BROWSER-PLUGINS VMWare unspecified 6 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14366BROWSER-PLUGINS VmdbQuery Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14368BROWSER-PLUGINS VmdbQuery Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14370BROWSER-PLUGINS vmappPropObj2 Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14372BROWSER-PLUGINS vmappPropObj2 Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14374BROWSER-PLUGINS VmappPoll Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14376BROWSER-PLUGINS VmappPoll Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14378BROWSER-PLUGINS VMClient Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14380BROWSER-PLUGINS VMClient Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14382BROWSER-PLUGINS Pq2vcom.Pq2v ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14384BROWSER-PLUGINS Pq2vcom.Pq2v ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14386BROWSER-PLUGINS VmdbSchema Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14388BROWSER-PLUGINS VmdbSchema Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14394BROWSER-PLUGINS VixCOM.VixLib ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14396BROWSER-PLUGINS VixCOM.VixLib ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14398BROWSER-PLUGINS vmappsdk.CuiObj ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14400BROWSER-PLUGINS vmappsdk.CuiObj ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14402BROWSER-PLUGINS RemoteBrowseDlg Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14404BROWSER-PLUGINS RemoteBrowseDlg Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14406BROWSER-PLUGINS RegVmsCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14408BROWSER-PLUGINS RegVmsCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14410BROWSER-PLUGINS VmdbEnumTags Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14412BROWSER-PLUGINS VmdbEnumTags Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14414BROWSER-PLUGINS VMWare unspecified 7 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14420BROWSER-PLUGINS VmdbDatabase Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14422BROWSER-PLUGINS VmdbDatabase Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14424BROWSER-PLUGINS VMAppSdkUtil Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14426BROWSER-PLUGINS VMAppSdkUtil Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14428BROWSER-PLUGINS VMWare unspecified 8 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14430BROWSER-PLUGINS VMEnumStrings Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14432BROWSER-PLUGINS VMEnumStrings Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14434BROWSER-PLUGINS VMWare unspecified 9 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14436BROWSER-PLUGINS VMClientHost Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14438BROWSER-PLUGINS VMClientHost Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14440BROWSER-PLUGINS VMWare unspecified 10 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14442BROWSER-PLUGINS VMWare unspecified 11 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14444BROWSER-PLUGINS VMWare unspecified 12 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14446BROWSER-PLUGINS VMWare unspecified 13 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14448BROWSER-PLUGINS reconfig.SystemReconfigur ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14450BROWSER-PLUGINS reconfig.SystemReconfigur ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14452BROWSER-PLUGINS vmhwcfg.NwzCompleted ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14454BROWSER-PLUGINS vmhwcfg.NwzCompleted ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14456BROWSER-PLUGINS MksCompatCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14458BROWSER-PLUGINS MksCompatCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14460BROWSER-PLUGINS VMWare unspecified 14 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14466BROWSER-PLUGINS VMWare unspecified 15 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14468BROWSER-PLUGINS Elevated.HostDeviceInfos ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14470BROWSER-PLUGINS Elevated.HostDeviceInfos ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14472BROWSER-PLUGINS VMWare unspecified 16 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14474BROWSER-PLUGINS VMWare unspecified 17 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14476BROWSER-PLUGINS reconfig.GuestInfo ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14478BROWSER-PLUGINS reconfig.GuestInfo ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14480BROWSER-PLUGINS VmappPropFrame Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14482BROWSER-PLUGINS VmappPropFrame Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14484BROWSER-PLUGINS VhdCvtCom.VhdConverter ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14486BROWSER-PLUGINS VhdCvtCom.VhdConverter ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14488BROWSER-PLUGINS VMSwitchCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14490BROWSER-PLUGINS VMSwitchCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14492BROWSER-PLUGINS VMWare unspecified 18 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14494BROWSER-PLUGINS VmdbUtil Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14496BROWSER-PLUGINS VmdbUtil Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14498BROWSER-PLUGINS VMWare unspecified 19 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14500BROWSER-PLUGINS VMwareVpcCvt.VpcC ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14502BROWSER-PLUGINS VMwareVpcCvt.VpcC ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14504BROWSER-PLUGINS VmdbCnxUtil Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14506BROWSER-PLUGINS VmdbCnxUtil Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14508BROWSER-PLUGINS Vmc2vmx.CoVPCDrive ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14510BROWSER-PLUGINS Vmc2vmx.CoVPCDrive ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14512BROWSER-PLUGINS VMWare unspecified 20 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14514BROWSER-PLUGINS VMClientVM Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14516BROWSER-PLUGINS VMClientVM Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14518BROWSER-PLUGINS VMWare unspecified 21 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14520BROWSER-PLUGINS Elevated.VMXCreator ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14522BROWSER-PLUGINS Elevated.VMXCreator ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14524BROWSER-PLUGINS VMWare unspecified 22 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14526BROWSER-PLUGINS HotfixWz Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14528BROWSER-PLUGINS HotfixWz Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14530BROWSER-PLUGINS VmdbUpdates Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14532BROWSER-PLUGINS VmdbUpdates Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14534BROWSER-PLUGINS VMListCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14536BROWSER-PLUGINS VMListCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14538BROWSER-PLUGINS CheckedListViewWnd Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14540BROWSER-PLUGINS CheckedListViewWnd Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14542BROWSER-PLUGINS VMWare unspecified 23 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14544BROWSER-PLUGINS VmdbTreeCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14546BROWSER-PLUGINS VmdbTreeCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14548BROWSER-PLUGINS Nwz Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14550BROWSER-PLUGINS Nwz Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14552BROWSER-PLUGINS Vmc2vmx.CoVPCDrives ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14554BROWSER-PLUGINS Vmc2vmx.CoVPCDrives ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14556BROWSER-PLUGINS MksCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14558BROWSER-PLUGINS MksCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14560BROWSER-PLUGINS VmappPropPath Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14562BROWSER-PLUGINS VmappPropPath Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14564BROWSER-PLUGINS VMWare unspecified 24 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14566BROWSER-PLUGINS PolicyCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14568BROWSER-PLUGINS PolicyCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14570BROWSER-PLUGINS VmdbParseError Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14572BROWSER-PLUGINS VmdbParseError Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14574BROWSER-PLUGINS NavigationCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14576BROWSER-PLUGINS NavigationCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14578BROWSER-PLUGINS VMList Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14580BROWSER-PLUGINS VMList Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14582BROWSER-PLUGINS VMWare unspecified 25 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14584BROWSER-PLUGINS VMWare unspecified 26 ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14586BROWSER-PLUGINS CurrentVMCtl Class ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14588BROWSER-PLUGINS CurrentVMCtl Class ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14590BROWSER-PLUGINS VhdCvtCom.DiskLibHelper ActiveX clsid access (more info ...)attempted-user 2008-3696 30934  URL
14592BROWSER-PLUGINS VhdCvtCom.DiskLibHelper ActiveX function call access (more info ...)attempted-user 2008-3696 30934  URL
14594BROWSER-PLUGINS Peachtree Accounting 2004 ActiveX clsid access (more info ...)attempted-user 2008-4699 31096  
14596BROWSER-PLUGINS ComponentOne VSFlexGrid ActiveX clsid access (more info ...)attempted-user 2008-4132 31200  
14598BROWSER-PLUGINS ComponentOne VSFlexGrid ActiveX function call access (more info ...)attempted-user 2008-4132 31200  
14603BROWSER-PLUGINS Data Dynamics ActiveReport ARViewer2 ActiveX clsid access (more info ...)attempted-user 2008-5089 31227  
14605BROWSER-PLUGINS Data Dynamics ActiveReport ARViewer2 ActiveX function call access (more info ...)attempted-user 2008-5089 31227  
14607SERVER-OTHER CA Brightstor SUN RPC malformed string buffer overflow attempt (more info ...)attempted-admin 2007-2139 23635  
14631BROWSER-PLUGINS Husdawg System Requirements Lab Control ActiveX clsid access (more info ...)attempted-user 2008-4385 31752  URL
14633BROWSER-PLUGINS PhotoStockPlus ActiveX clsid access (more info ...)attempted-user 2008-0957 29279  URL
14635BROWSER-PLUGINS Microsoft RSClientPrint ActiveX clsid access (more info ...)attempted-user 2008-3015   URL
14637BROWSER-PLUGINS Microsoft PicturePusher ActiveX clsid access (more info ...)attempted-user 2008-4493 31632  
14639BROWSER-PLUGINS Microsoft PicturePusher ActiveX function call access (more info ...)attempted-user 2008-4493 31632  
14744BROWSER-PLUGINS Hummingbird HostExplorer ActiveX clsid access (more info ...)attempted-user 2008-4729 31783  
14746BROWSER-PLUGINS Autodesk DWF Viewer ActiveX clsid access (more info ...)attempted-user 2008-4472 31490  
14748BROWSER-PLUGINS Autodesk LiveUpdate ActiveX clsid access (more info ...)attempted-user 2008-4472 31490  
14750BROWSER-PLUGINS Autodesk LiveUpdate ActiveX function call access (more info ...)attempted-user 2008-4472 31490  
14754BROWSER-PLUGINS Novell ZENworks Desktop Management ActiveX function call access (more info ...)attempted-user 2008-5073 31435  
14762BROWSER-PLUGINS iseemedia LPViewer ActiveX function call access (more info ...)attempted-user 2008-4384 31604  
14783OS-WINDOWS DCERPC NCADG-IP-UDP srvsvc NetrpPathCanonicalize path canonicalization stack overflow attempt (more info ...)attempted-admin 2008-4250   URL
14896OS-WINDOWS Microsoft Windows SMB v4 srvsvc NetrpPathCononicalize unicode path cononicalization stack overflow attempt (more info ...)attempted-admin 2008-4250   URL
14897BROWSER-PLUGINS HP Software Update RulesEngine.dll ActiveX function call access (more info ...)attempted-user 2007-6506 26950  
14993BROWSER-PLUGINS Visagesoft eXPert PDF Viewer ActiveX clsid access (more info ...)attempted-user 2008-4919 31984  
14995BROWSER-PLUGINS Visagesoft eXPert PDF Viewer ActiveX function call access (more info ...)attempted-user 2008-4919 31984  
14999BROWSER-PLUGINS Microsoft Debug Diagnostic Tool ActiveX clsid access (more info ...)attempted-user 2008-4800 31996  
15001BROWSER-PLUGINS Microsoft Debug Diagnostic Tool ActiveX function call access (more info ...)attempted-user 2008-4800 31996  
15003BROWSER-PLUGINS Chilkat Crypt 2 ActiveX clsid access (more info ...)attempted-user 2008-5002 32073  
15005BROWSER-PLUGINS Chilkat Crypt 2 ActiveX function call access (more info ...)attempted-user 2008-5002 32073  
15015OS-WINDOWS DCERPC NCACN-IP-TCP wkssvc NetrUseAdd/NetrUseGetInfo/NetrUseDel overflow attempt (more info ...)attempted-admin 2008-4250   URL
15069BROWSER-PLUGINS SAP AG SAPgui mdrmsap ActiveX clsid access (more info ...)attempted-user 2008-4387 32186  
15084BROWSER-PLUGINS Microsoft Windows Common Controls Animation Object ActiveX clsid access (more info ...)attempted-user 2008-4255   URL
15086BROWSER-PLUGINS Microsoft Windows Common Controls Animation Object ActiveX function call access (more info ...)attempted-user 2008-4255   URL
15116OS-WINDOWS Microsoft Windows search protocol remote command injection attempt (more info ...)attempted-user 2008-4269   URL
15127OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function WriteAndX andx attempt (more info ...)attempted-admin 2008-5416 32710  URL
15128OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function WriteAndX attempt (more info ...)attempted-admin 2008-5416 32710  URL
15129OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function WriteAndX unicode andx attempt (more info ...)attempted-admin 2008-5416 32710  URL
15130OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function WriteAndX unicode attempt (more info ...)attempted-admin 2008-5416 32710  URL
15131OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function andx attempt (more info ...)attempted-admin 2008-5416 32710  URL
15132OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function attempt (more info ...)attempted-admin 2008-5416 32710  URL
15133OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function unicode andx attempt (more info ...)attempted-admin 2008-5416 32710  URL
15134OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function unicode attempt (more info ...)attempted-admin 2008-5416 32710  URL
15135OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function WriteAndX andx attempt (more info ...)attempted-admin 2008-5416 32710  URL
15136OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function WriteAndX attempt (more info ...)attempted-admin 2008-5416 32710  URL
15137OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function WriteAndX unicode andx attempt (more info ...)attempted-admin 2008-5416 32710  URL
15138OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function WriteAndX unicode attempt (more info ...)attempted-admin 2008-5416 32710  URL
15139OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function andx attempt (more info ...)attempted-admin 2008-5416 32710  URL
15140OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function attempt (more info ...)attempted-admin 2008-5416 32710  URL
15141OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function unicode andx attempt (more info ...)attempted-admin 2008-5416 32710  URL
15142OS-WINDOWS Microsoft Windows SMB sp_replwritetovarbin vulnerable function unicode attempt (more info ...)attempted-admin 2008-5416 32710  URL
15173BROWSER-PLUGINS Phoenician Casino ActiveX clsid access (more info ...)attempted-user 2008-5691 32901  
15175BROWSER-PLUGINS Phoenician Casino ActiveX function call access (more info ...)attempted-user 2008-5691 32901  
15177BROWSER-PLUGINS Trend Micro HouseCall ActiveX clsid access (more info ...)attempted-user 2008-2435 32965  
15179BROWSER-PLUGINS Trend Micro HouseCall ActiveX function call access (more info ...)attempted-user 2008-2435 32965  
15181BROWSER-PLUGINS SaschArt SasCam Webcam Server ActiveX clsid access (more info ...)attempted-user 2008-6898 33053  
15192BROWSER-PLUGINS SizerOne ActiveX clsid access attempt (more info ...)attempted-user 2008-4827 33148  
15194BROWSER-PLUGINS SizerOne ActiveX function call access (more info ...)attempted-user 2008-4827 33148  
15228BROWSER-PLUGINS Ciansoft PDFBuilderX ActiveX clsid access (more info ...)attempted-user  33233  
15232BROWSER-PLUGINS Easy Grid ActiveX clsid access (more info ...)attempted-user 2009-0134 33272  
15234BROWSER-PLUGINS Easy Grid ActiveX function call access (more info ...)attempted-user 2009-0134 33272  
15243BROWSER-PLUGINS AXIS Camera ActiveX clsid access (more info ...)attempted-user 2008-5260 33408  
15245BROWSER-PLUGINS AXIS Camera ActiveX function call access (more info ...)attempted-user 2008-5260 33408  
15247BROWSER-PLUGINS JamDTA ActiveX clsid access (more info ...)attempted-user  33345  
15249BROWSER-PLUGINS SmartVMD ActiveX clsid access (more info ...)attempted-user  33349  
15251BROWSER-PLUGINS MetaProducts MetaTreeX ActiveX clsid access (more info ...)attempted-user  33318  
15253BROWSER-PLUGINS MetaProducts MetaTreeX ActiveX function call access (more info ...)attempted-user  33318  
15268BROWSER-PLUGINS MW6 Technologies Barcode ActiveX function call access (more info ...)attempted-user 2009-0298 33451  
15270BROWSER-PLUGINS MW6 Technologies PDF417 ActiveX clsid access (more info ...)attempted-user 2008-4926   
15272BROWSER-PLUGINS MW6 Technologies PDF417 ActiveX function call access (more info ...)attempted-user 2008-4926   
15274BROWSER-PLUGINS MW6 Technologies DataMatrix ActiveX clsid access (more info ...)attempted-user 2008-4925   
15276BROWSER-PLUGINS MW6 Technologies DataMatrix ActiveX function call access (more info ...)attempted-user 2008-4925   
15278BROWSER-PLUGINS MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user 2008-4923   
15280BROWSER-PLUGINS MW6 Technologies Aztec ActiveX function call access (more info ...)attempted-user 2008-4923   
15284BROWSER-PLUGINS NCTAudioGrabber2 ActiveX clsid access (more info ...)attempted-user 2008-0958   URL
15286BROWSER-PLUGINS NCTAudioGrabber2 ActiveX function call access (more info ...)attempted-user 2008-0958   URL
15288BROWSER-PLUGINS NCTAudioInformation2 ActiveX clsid access (more info ...)attempted-user 2008-0959   URL
15290BROWSER-PLUGINS NCTAudioInformation2 ActiveX function call access (more info ...)attempted-user 2008-0959   URL
15307BROWSER-PLUGINS Microsoft Animation Control ActiveX clsid access (more info ...)attempted-user    URL
15309BROWSER-PLUGINS Microsoft Animation Control ActiveX function call access (more info ...)attempted-user    URL
15311BROWSER-PLUGINS Research In Motion AxLoader ActiveX clsid access (more info ...)attempted-user 2009-0305 33663  URL
15313BROWSER-PLUGINS Research In Motion AxLoader ActiveX function call access (more info ...)attempted-user 2009-0305 33663  URL
15315BROWSER-PLUGINS Akamai DownloadManager ActiveX clsid access (more info ...)attempted-user    URL
15317BROWSER-PLUGINS Akamai DownloadManager ActiveX function call access (more info ...)attempted-user    URL
15330BROWSER-PLUGINS Nokia Phoenix Service 1 ActiveX clsid access (more info ...)attempted-user  33726  
15332BROWSER-PLUGINS Nokia Phoenix Service 2 ActiveX clsid access (more info ...)attempted-user  33726  
15346BROWSER-PLUGINS Synactis ALL In-The-Box ActiveX clsid access (more info ...)attempted-user 2009-0465 33535  
15348BROWSER-PLUGINS Synactis ALL In-The-Box ActiveX function call access (more info ...)attempted-user 2009-0465 33535  
15350BROWSER-PLUGINS Web on Windows ActiveX clsid access (more info ...)attempted-user 2009-0389 33515  
15352BROWSER-PLUGINS Web on Windows ActiveX function call access (more info ...)attempted-user 2009-0389 33515  
15372BROWSER-PLUGINS iDefense COMRaider ActiveX clsid access (more info ...)attempted-user  33867  
15374BROWSER-PLUGINS iDefense COMRaider ActiveX function call access (more info ...)attempted-user  33867  
15376BROWSER-PLUGINS Sopcast SopCore ActiveX clsid access (more info ...)attempted-user 2009-0811 33920  
15378BROWSER-PLUGINS Sopcast SopCore ActiveX function call access (more info ...)attempted-user 2009-0811 33920  
15380BROWSER-PLUGINS HP Virtual Rooms v7 ActiveX clsid access (more info ...)attempted-user 2009-0208 33918  
15386OS-WINDOWS Microsoft Windows wpad dynamic update request (more info ...)attempted-admin 2009-0093   URL
15387OS-WINDOWS udp WINS WPAD registration attempt (more info ...)misc-attack 2009-0094   URL
15430FILE-OTHER Microsoft EMF+ GpFont.SetData buffer overflow attempt (more info ...)attempted-user 2009-1217 34250  
15448NETBIOS DCERPC NCADG-IP-UDP srvsvc NetrShareEnum null policy handle attempt (more info ...)protocol-command-decode    
15457OS-WINDOWS Microsoft Windows DirectShow MJPEG arbitrary code execution attempt (more info ...)attempted-user 2009-0084   URL
15475OS-WINDOWS Microsoft Windows ISA Server cross-site scripting attempt (more info ...)attempted-user 2009-0237   URL
15513OS-WINDOWS DCERPC NCADG-IP-UDP rpcss2_RemoteGetClassObject attempt (more info ...)protocol-command-decode 2003-0605   URL
15523OS-WINDOWS Microsoft Windows srvsvc NetrShareEnum netname overflow attempt (more info ...)protocol-command-decode 2009-0228   URL
15543BROWSER-PLUGINS Microsoft Communications Control v6 ActiveX clsid access (more info ...)attempted-user    URL
15545BROWSER-PLUGINS Microsoft Communications Control v6 ActiveX function call access (more info ...)attempted-user    URL
15547BROWSER-PLUGINS eBay Picture Uploads control 1 ActiveX clsid access (more info ...)attempted-user    URL
15549BROWSER-PLUGINS eBay Picture Uploads control 1 ActiveX function call access (more info ...)attempted-user    URL
15551BROWSER-PLUGINS eBay Picture Uploads control 2 ActiveX clsid access (more info ...)attempted-user    URL
15557BROWSER-PLUGINS SAP AG SAPgui EnjoySAP ActiveX clsid access (more info ...)attempted-user  35256  
15588BROWSER-PLUGINS Microsoft Video 1 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15590BROWSER-PLUGINS Microsoft Video 10 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15592BROWSER-PLUGINS Microsoft Video 11 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15594BROWSER-PLUGINS Microsoft Video 12 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15596BROWSER-PLUGINS Microsoft Video 13 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15598BROWSER-PLUGINS Microsoft Video 14 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15600BROWSER-PLUGINS Microsoft Video 15 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15602BROWSER-PLUGINS Microsoft Video 16 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15604BROWSER-PLUGINS Microsoft Video 17 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15606BROWSER-PLUGINS Microsoft Video 18 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15608BROWSER-PLUGINS Microsoft Video 19 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15610BROWSER-PLUGINS Microsoft Video 2 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15612BROWSER-PLUGINS Microsoft Video 20 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15614BROWSER-PLUGINS Microsoft Video 21 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15616BROWSER-PLUGINS Microsoft Video 22 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15618BROWSER-PLUGINS Microsoft Video 23 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15620BROWSER-PLUGINS Microsoft Video 24 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15622BROWSER-PLUGINS Microsoft Video 25 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15624BROWSER-PLUGINS Microsoft Video 26 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15626BROWSER-PLUGINS Microsoft Video 27 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15628BROWSER-PLUGINS Microsoft Video 28 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15630BROWSER-PLUGINS Microsoft Video 29 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15634BROWSER-PLUGINS Microsoft Video 30 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15636BROWSER-PLUGINS Microsoft Video 31 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15640BROWSER-PLUGINS Microsoft Video 33 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15642BROWSER-PLUGINS Microsoft Video 34 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15644BROWSER-PLUGINS Microsoft Video 35 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15646BROWSER-PLUGINS Microsoft Video 36 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15648BROWSER-PLUGINS Microsoft Video 37 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15650BROWSER-PLUGINS Microsoft Video 38 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15652BROWSER-PLUGINS Microsoft Video 39 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15654BROWSER-PLUGINS Microsoft Video 4 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15656BROWSER-PLUGINS Microsoft Video 40 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15658BROWSER-PLUGINS Microsoft Video 41 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15660BROWSER-PLUGINS Microsoft Video 42 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15662BROWSER-PLUGINS Microsoft Video 43 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15664BROWSER-PLUGINS Microsoft Video 44 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15666BROWSER-PLUGINS Microsoft Video 45 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15668BROWSER-PLUGINS Microsoft Video 5 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15670BROWSER-PLUGINS Microsoft Video 6 ActiveX clsid access (more info ...)attempted-user 2009-0901 35558  URL
15671BROWSER-PLUGINS Microsoft Video 6 ActiveX function call (more info ...)attempted-user 2009-0901 35558  URL
15672BROWSER-PLUGINS Microsoft Video 7 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15674BROWSER-PLUGINS Microsoft Video 8 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15676BROWSER-PLUGINS Microsoft Video 9 ActiveX clsid access (more info ...)attempted-user 2008-0015   URL
15693FILE-OTHER Microsoft Windows Embedded Open Type Font malformed name table overflow attempt (more info ...)attempted-user 2009-0231   URL
15694FILE-OTHER Microsoft Windows Embedded Open Type Font malformed name table integer overflow attempt (more info ...)attempted-user 2009-0232   URL
15695FILE-OTHER Microsoft Windows Embedded Open Type Font malformed name table platform type 3 integer overflow attempt (more info ...)attempted-user 2009-0232   URL
15702NETBIOS DCERPC NCACN-IP-TCP brightstor opcode 0x13 overflow attempt (more info ...)attempted-dos 2009-1761 35396  
15710NETBIOS DCERPC NCACN-IP-TCP brightstor opcode 0x3B null strings attempt (more info ...)attempted-dos 2009-1761 35396  
15848OS-WINDOWS WINS replication request memory corruption attempt (more info ...)attempted-admin 2009-1923   URL
15849OS-WINDOWS Microsoft Windows WINS replication inform2 request memory corruption attempt (more info ...)attempted-admin 2009-1924   URL
15854FILE-MULTIMEDIA Microsoft Windows AVIFile media file processing memory corruption attempt (more info ...)attempted-user 2009-1546 35970  URL
15857FILE-MULTIMEDIA Microsoft Windows AVIFile media file invalid header length (more info ...)attempted-user 2009-1546   URL
15860OS-WINDOWS DCERPC NCACN-IP-TCP wkssvc NetrGetJoinInformation attempt (more info ...)protocol-command-decode 2009-1544   URL
15863BROWSER-PLUGINS Microsoft Windows Remote Desktop Client ActiveX function call access (more info ...)attempted-user 2009-1929   URL
15878BROWSER-PLUGINS AcerCtrls.APlunch ActiveX clsid access (more info ...)attempted-user 2009-2627   URL
15894OS-WINDOWS Microsoft Color Management Module remote code execution attempt (more info ...)attempted-admin 2005-1219   URL
15920FILE-MULTIMEDIA Microsoft mp3 malformed APIC header RCE attempt (more info ...)attempted-user 2009-2499   URL
15921FILE-IDENTIFY Microsoft multimedia format file download request (more info ...)misc-activity    URL
15926BROWSER-PLUGINS PPStream PPSMediaList ActiveX clsid access (more info ...)attempted-user  36234  
15928BROWSER-PLUGINS PPStream PPSMediaList ActiveX function call access (more info ...)attempted-user  36234  
15944OS-WINDOWS Microsoft Windows Active Directory crafted LDAP request denial of service attempt (more info ...)attempted-dos 2007-3028 24796  
15946FILE-OTHER Microsoft Windows Vista Feed Headlines Gagdet code execution attempt (more info ...)attempted-user 2007-3033 25287  
15985OS-WINDOWS Microsoft ASP.NET canonicalization exploit attempt (more info ...)attempted-user 2004-0847 11342  
15995FILE-MULTIMEDIA Microsoft Windows DirectX malformed mjpeg arbitrary code execution attempt (more info ...)attempted-user 2008-0011   URL
15996OS-WINDOWS Microsoft Negotiate SSP buffer overflow attempt (more info ...)attempted-admin 2004-0119 10113  
16016OS-WINDOWS Microsoft client for netware overflow attempt (more info ...)attempted-admin 2006-4688   URL
16048SERVER-OTHER Microsoft ASP.NET application folder info disclosure attempt (more info ...)attempted-recon 2006-1300 18920  
16058SERVER-SAMBA Samba WINS Server Name Registration handling stack buffer overflow attempt (more info ...)attempted-user 2007-5398 26455  
16066OS-WINDOWS Microsoft Windows Server driver crafted SMB data denial of service (more info ...)attempted-dos 2006-3942   URL
16068BROWSER-PLUGINS Yahoo Music Jukebox ActiveX exploit (more info ...)attempted-user 2008-0625 27579  
16081PROTOCOL-RPC portmap 395650 tcp XDR SString buffer overflow attempt (more info ...)rpc-portmap-decode 2008-2242 29283  URL
16082PROTOCOL-RPC portmap 395650 udp XDR SString buffer overflow attempt (more info ...)rpc-portmap-decode 2008-2242 29283  URL
16084PROTOCOL-RPC portmap 395650 udp request (more info ...)rpc-portmap-decode 2008-2242   URL
16085PROTOCOL-RPC portmap 395650 tcp xml buffer overflow attempt (more info ...)rpc-portmap-decode 2008-2242   URL
16086PROTOCOL-RPC portmap 395650 udp xml buffer overflow attempt (more info ...)rpc-portmap-decode 2008-2242   URL
16089OS-WINDOWS Microsoft Windows embedded web font handling buffer overflow attempt (more info ...)attempted-user 2006-0010 16194  
16090BROWSER-PLUGINS Microsoft Core XML core services XMLHTTP control open method code execution attempt (more info ...)attempted-user 2006-5745 20915  
16153FILE-IMAGE Microsoft Windows malformed WMF meta escape record memory corruption attempt (more info ...)attempted-user 2009-2500   URL
16157OS-WINDOWS Microsoft Windows malformed ASF voice codec memory corruption attempt (more info ...)attempted-user 2009-0555   URL
16168OS-WINDOWS Microsoft Windows SMBv2 integer overflow denial of service attempt (more info ...)attempted-admin 2009-2526   URL
16181OS-WINDOWS Microsoft Windows CryptoAPI ASN.1 integer overflow attempt (more info ...)attempted-user 2009-2511   URL
16184FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502 36646  URL
16185OS-WINDOWS Microsoft Windows GDI+ compressed TIFF file parsing remote code execution attempt (more info ...)attempted-user 2009-2503   URL
16186FILE-IMAGE Microsoft Windows GDI+ interlaced PNG file parsing heap overflow attempt (more info ...)attempted-user 2009-3126   URL
16187OS-WINDOWS Microsoft Windows DirectShow MJPEG arbitrary code execution attempt (more info ...)attempted-user 2009-0084   URL
16221OS-WINDOWS Microsoft ISA and Forefront Threat Management Web Proxy TCP Listener denial of service attempt (more info ...)attempted-dos 2009-0077 34414  URL
16231FILE-PDF Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt (more info ...)attempted-admin 2010-2862 42203  URL
16237SERVER-OTHER Microsoft Active Directory NTDSA stack space exhaustion attempt (more info ...)attempted-dos 2009-1928   URL
16285PROTOCOL-RPC AIX ttdbserv function 15 buffer overflow attempt (more info ...)attempted-admin 2009-2727 35419  URL
16287OS-WINDOWS Microsoft Windows SMB Negotiate Protocol response DoS attempt (more info ...)attempted-dos 2009-3676   URL
16294OS-WINDOWS Microsoft Windows TCP stack zero window size exploit attempt (more info ...)attempted-dos 2008-4609 31545  URL
16305BROWSER-PLUGINS Symantec Altiris Deployment Solution ActiveX clsid access attempt (more info ...)attempted-user 2009-3033 37092  
16307BROWSER-PLUGINS Symantec Altiris Deployment Solution ActiveX clsid access attempt (more info ...)attempted-user 2009-3033 37092  
16327OS-WINDOWS Microsoft Windows GDI+ TIFF RLE compressed data buffer overflow attempt (more info ...)attempted-user 2009-2503   URL
16342FILE-MULTIMEDIA Microsoft Windows AVIFile truncated media file processing memory corruption attempt (more info ...)attempted-user 2009-1546 35970  URL
16366OS-WINDOWS Microsoft Windows embedded OpenType font engine LZX decompression buffer overflow attempt (more info ...)attempted-admin 2010-0018 37671  URL
16379BROWSER-PLUGINS SAP AG SAPgui sapirrfc ActiveX clsid access (more info ...)attempted-user  35256  URL
16386BROWSER-PLUGINS AcroPDF.PDF ActiveX clsid access (more info ...)attempted-user 2009-2987   
16388BROWSER-PLUGINS AcroPDF.PDF ActiveX function call access (more info ...)attempted-user 2009-2987   
16396NETBIOS SMB server srvnet.sys driver race condition attempt (more info ...)attempted-dos 2010-0021   URL
16397OS-WINDOWS Microsoft Windows SMB andx invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16398OS-WINDOWS Microsoft Windows SMB invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16399OS-WINDOWS Microsoft Windows SMB unicode andx invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16400OS-WINDOWS Microsoft Windows SMB unicode invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16401OS-WINDOWS Microsoft Windows SMB andx invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16402OS-WINDOWS Microsoft Windows SMB invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16403OS-WINDOWS Microsoft Windows SMB unicode andx invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16404OS-WINDOWS Microsoft Windows SMB unicode invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16414OS-WINDOWS Microsoft Windows Shell Handler remote code execution attempt (more info ...)attempted-user 2010-0027   URL
16422FILE-IMAGE Microsoft Windows Paint JPEG with malformed SOFx field integer overflow attempt (more info ...)attempted-user 2010-0028   URL
16424BROWSER-PLUGINS Microsoft Windows Script Host Shell Object ActiveX clsid access (more info ...)attempted-user    URL
16432BROWSER-PLUGINS Trend Micro Web Deployment ActiveX clsid access (more info ...)attempted-user 2008-3364 30407  
16446PROTOCOL-RPC portmap Solaris sadmin tcp request (more info ...)rpc-portmap-decode 2008-4556 31751  
16447PROTOCOL-RPC Solaris UDP portmap sadmin request attempt (more info ...)rpc-portmap-decode 2008-4556 31751  
16448PROTOCOL-RPC portmap Solaris sadmin tcp adm_build_path overflow attempt (more info ...)rpc-portmap-decode 2008-4556 31751  
16449PROTOCOL-RPC portmap Solaris sadmin udp adm_build_path overflow attempt (more info ...)rpc-portmap-decode 2008-4556 31751  
16454OS-WINDOWS Microsoft Windows SMB Negotiate Protocol response DoS attempt - empty SMB 2 (more info ...)attempted-dos 2009-3676   URL
16473FILE-IDENTIFY Microsoft Windows Movie Maker project file download request (more info ...)misc-activity    URL
16532NETBIOS SMB client TRANS response ring0 remote code execution attempt (more info ...)attempted-admin 2010-0476   URL
16533OS-WINDOWS Microsoft Windows ISATAP-addressed IPv6 traffic spoofing attempt (more info ...)misc-attack 2010-0812   URL
16566BROWSER-PLUGINS Tumbleweed SecureTransport ActiveX clsid access (more info ...)attempted-user 2008-1724 28662  
16568BROWSER-PLUGINS Altnet Download Manager ADM4 ActiveX clsid access (more info ...)attempted-user 2007-5217 25903  
16569BROWSER-PLUGINS EnjoySAP kweditcontrol ActiveX clsid access (more info ...)attempted-user 2008-4830 34524  
16571BROWSER-PLUGINS EnjoySAP kweditcontrol ActiveX function call access (more info ...)attempted-user 2008-4830 34524  
16573BROWSER-PLUGINS obfuscated ActiveX object instantiation via unescape (more info ...)attempted-user    URL
16574BROWSER-PLUGINS obfuscated ActiveX object instantiation via fromCharCode (more info ...)attempted-user    URL
16575BROWSER-PLUGINS RKD Software BarCode ActiveX buffer overflow attempt (more info ...)attempted-user 2007-3435 24596  
16577OS-WINDOWS Microsoft Windows SMBv2 compound request DoS attempt (more info ...)attempted-dos 2010-2552   URL
16580BROWSER-PLUGINS NCTAudioFile2 ActiveX clsid access via object tag (more info ...)attempted-user 2007-0018 33469  
16581BROWSER-PLUGINS Persits Software XUpload ActiveX clsid unsafe function access attempt (more info ...)attempted-user 2009-3693 36550  
16587BROWSER-PLUGINS Symantec Altiris Deployment Solution ActiveX clsid access attempt (more info ...)attempted-user 2009-3033 37092  
16588BROWSER-PLUGINS iseemedia LPViewer ActiveX clsid access (more info ...)attempted-user 2008-4384 31604  
16589BROWSER-PLUGINS iseemedia LPViewer ActiveX function call access (more info ...)attempted-user 2008-4384 31604  
16590BROWSER-PLUGINS Oracle EasyMail Objects ActiveX exploit attempt (more info ...)attempted-user 2007-4607 25467  
16595SERVER-MAIL Microsoft Windows Mail remote code execution attempt (more info ...)attempted-user 2010-0816   URL
16599BROWSER-PLUGINS AtHocGov IWSAlerts ActiveX control buffer overflow attempt (more info ...)attempted-user    URL
16608BROWSER-PLUGINS HP Mercury Quality Center SPIDERLib ActiveX control access attempt (more info ...)attempted-user 2007-1819 23239  URL
16610BROWSER-PLUGINS IBM Access Support ActiveX GetXMLValue method buffer overflow attempt (more info ...)attempted-user 2009-0215 34228  
16636OS-WINDOWS Microsoft Windows .NET framework XMLDsig data tampering attempt (more info ...)misc-attack 2009-0217   URL
16661FILE-MULTIMEDIA Microsoft Windows DirectX quartz.dll MJPEG content processing memory corruption attempt (more info ...)attempted-user 2010-1879   URL
16665OS-WINDOWS Microsoft Windows Help Centre escape sequence XSS attempt (more info ...)attempted-user 2010-1885 40725  URL
16672BROWSER-PLUGINS Symantec Backup Exec ActiveX control buffer overflow attempt (more info ...)attempted-user 2007-6016 26904  
16679OS-WINDOWS Microsoft Windows GDIplus integer overflow attempt (more info ...)misc-activity 2009-1217 34250  
16687BROWSER-PLUGINS Juniper Networks SSL-VPN Client JuniperSetup ActiveX control buffer overflow attempt (more info ...)attempted-user 2006-2086 17712  
16699PROTOCOL-RPC Linux Kernel nfsd v2 udp CAP_MKNOD security bypass attempt (more info ...)misc-attack 2009-1072 34205  
16700PROTOCOL-RPC Linux Kernel nfsd v2 tcp CAP_MKNOD security bypass attempt (more info ...)misc-attack 2009-1072 34205  
16701PROTOCOL-RPC Linux Kernel nfsd v3 udp CAP_MKNOD security bypass attempt (more info ...)misc-attack 2009-1072 34205  
16702PROTOCOL-RPC Linux Kernel nfsd v3 tcp CAP_MKNOD security bypass attempt (more info ...)misc-attack 2009-1072 34205  
16704BROWSER-PLUGINS CA eTrust PestPatrol ActiveX Initialize method overflow attempt (more info ...)attempted-user 2009-4225 37133  
16711BROWSER-PLUGINS E-Book Systems FlipViewer FlipViewerX.dll activex clsid access ActiveX clsid access (more info ...)attempted-user 2007-2919 24328  
16714BROWSER-PLUGINS SoftArtisans XFile FileManager ActiveX Control access attempt (more info ...)attempted-user 2007-1682 30826  URL
16715BROWSER-PLUGINS SaschArt SasCam Webcam Server ActiveX control exploit attempt (more info ...)attempted-user 2008-6898 33053  
16729BROWSER-PLUGINS McAfee Remediation client ActiveX control access attempt (more info ...)attempted-user    URL
16740BROWSER-PLUGINS Microsoft Works WkImgSrv.dll ActiveX control code execution attempt (more info ...)attempted-user 2008-1898 28820  
16741BROWSER-PLUGINS Microsoft Works WkImgSrv.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-4607 25467  
16745BROWSER-PLUGINS DjVu ActiveX control access attempt (more info ...)attempted-user 2008-4922 31987  
16748BROWSER-PLUGINS IBM Access Support ActiveX function call access (more info ...)attempted-user 2009-0215 34228  
16754NETBIOS SMB /PlughNTCommand andx create tree attempt (more info ...)protocol-command-decode 2009-1394   
16755NETBIOS SMB /PlughNTCommand create tree attempt (more info ...)protocol-command-decode 2009-1394   
16756NETBIOS SMB /PlughNTCommand unicode andx create tree attempt (more info ...)protocol-command-decode 2009-1394   
16757NETBIOS SMB /PlughNTCommand unicode create tree attempt (more info ...)protocol-command-decode 2009-1394   
16758NETBIOS SMB /PlughNTCommand andx create tree attempt (more info ...)protocol-command-decode 2009-1394   
16759NETBIOS SMB /PlughNTCommand create tree attempt (more info ...)protocol-command-decode 2009-1394   
16760NETBIOS SMB /PlughNTCommand unicode andx create tree attempt (more info ...)protocol-command-decode 2009-1394   
16761NETBIOS SMB /PlughNTCommand unicode create tree attempt (more info ...)protocol-command-decode 2009-1394   
16762NETBIOS SMB Timbuktu Pro overflow WriteAndX andx attempt (more info ...)attempted-admin 2009-1394   
16763NETBIOS SMB Timbuktu Pro overflow WriteAndX attempt (more info ...)attempted-admin 2009-1394   
16764NETBIOS SMB Timbuktu Pro overflow WriteAndX unicode andx attempt (more info ...)attempted-admin 2009-1394   
16765NETBIOS SMB Timbuktu Pro overflow WriteAndX unicode attempt (more info ...)attempted-admin 2009-1394   
16766NETBIOS SMB Timbuktu Pro overflow andx attempt (more info ...)attempted-admin 2009-1394   
16767BROWSER-PLUGINS AwingSoft Web3D Player SceneURL ActiveX clsid access (more info ...)attempted-user 2009-4850   
16769BROWSER-PLUGINS AwingSoft Web3D Player ActiveX function call access (more info ...)attempted-user 2009-4850   
16771BROWSER-PLUGINS AwingSoft Web3D Player WindsPlayerIE.View.1 ActiveX SceneURL method overflow attempt (more info ...)attempted-user 2009-4588   
16772BROWSER-PLUGINS EMC Captiva QuickScan Pro ActiveX clsid access (more info ...)attempted-user 2012-2515 36546  
16783BROWSER-PLUGINS Autodesk iDrop ActiveX clsid access (more info ...)attempted-user    URL
16784BROWSER-PLUGINS Autodesk iDrop ActiveX function call access (more info ...)attempted-user    URL
16789BROWSER-PLUGINS Chilkat Crypt 2 ActiveX object access attempt (more info ...)attempted-user 2008-5002 32073  
16790BROWSER-PLUGINS Chilkat Crypt 2 ActiveX clsid access attempt (more info ...)attempted-user 2008-5002 32073  
16793BROWSER-PLUGINS SAP AG SAPgui EAI WebViewer3D ActiveX function call access (more info ...)attempted-user 2007-4475 34310  
16802BROWSER-PLUGINS WinDVD IASystemInfo.dll ActiveX clsid access (more info ...)attempted-user 2007-0348 23071  
16926MALWARE-CNC URI request for known malicious URI - strMode=setup&strID=pcvaccine&strPC= (more info ...)trojan-activity    URL
17052BROWSER-PLUGINS Symantec AppStream Client LaunchObj ActiveX clsid access attempt (more info ...)attempted-user 2008-4388 33247  
17053BROWSER-PLUGINS Symantec AppStream Client LaunchObj ActiveX clsid access attempt (more info ...)attempted-user 2008-4388 33247  
17054BROWSER-PLUGINS Symantec AppStream Client LaunchObj ActiveX clsid access attempt (more info ...)attempted-user 2008-4388 33247  
17060BROWSER-PLUGINS Roxio CinePlayer SonicDVDDashVRNav.dll ActiveX control buffer overflow attempt (more info ...)attempted-user 2007-1559 23412  
17061BROWSER-PLUGINS Symantec Norton Personal Firewall 2004 ActiveX clsid access (more info ...)attempted-user 2007-1689 23936  
17063BROWSER-PLUGINS Logitech Video Call 1 ActiveX clsid access (more info ...)attempted-user 2007-2918 24254  
17065BROWSER-PLUGINS Logitech Video Call 2 ActiveX clsid access (more info ...)attempted-user 2007-2918 24254  
17067BROWSER-PLUGINS Logitech Video Call 3 ActiveX clsid access (more info ...)attempted-user 2007-2918 24254  
17069BROWSER-PLUGINS Logitech Video Call 4 ActiveX clsid access (more info ...)attempted-user 2007-2918 24254  
17071BROWSER-PLUGINS Logitech Video Call 5 ActiveX clsid access (more info ...)attempted-user 2007-2918 24254  
17073BROWSER-PLUGINS Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX clsid access (more info ...)attempted-user 2007-5107 25785  
17075BROWSER-PLUGINS Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX function call access (more info ...)attempted-user 2007-5107 25785  
17077BROWSER-PLUGINS Ask Toolbar AskJeevesToolBar.SettingsPlugin.1 ActiveX control buffer overflow attempt (more info ...)attempted-user 2007-5107 25785  
17078BROWSER-PLUGINS GOM Player GomWeb ActiveX clsid access (more info ...)attempted-user 2007-5779 26236  
17080BROWSER-PLUGINS GOM Player GomWeb ActiveX function call access (more info ...)attempted-user 2007-5779 26236  
17082BROWSER-PLUGINS SonicWALL SSL-VPN NeLaunchCtrl ActiveX clsid access (more info ...)attempted-user 2007-5603 26288  
17084BROWSER-PLUGINS Creative Software AutoUpdate Engine ActiveX clsid access (more info ...)attempted-user 2008-0955 29391  
17086BROWSER-PLUGINS Creative Software AutoUpdate Engine CTSUEng.ocx ActiveX control access attempt (more info ...)attempted-user 2008-0955 29391  
17087BROWSER-PLUGINS VeryDOC PDF Viewer ActiveX clsid access (more info ...)attempted-user 2008-5492 32313  
17089BROWSER-PLUGINS VeryDOC PDF Viewer ActiveX function call access (more info ...)attempted-user 2008-5492 32313  
17091BROWSER-PLUGINS VeryDOC PDF Viewer ActiveX control OpenPDF buffer overflow attempt (more info ...)attempted-user 2008-5492 32313  
17092BROWSER-PLUGINS Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX clsid access (more info ...)attempted-user 2009-3028 36346  
17094BROWSER-PLUGINS Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX function call access (more info ...)attempted-user 2009-3028 36346  
17112OS-WINDOWS DCERPC rpcss2 _RemoteGetClassObject attempt (more info ...)attempted-user 2003-0715 8205  URL
17117FILE-MULTIMEDIA Microsoft Windows MPEG Layer-3 audio heap corruption attempt (more info ...)attempted-user 2010-1882   URL
17118FILE-EXECUTABLE Microsoft .NET CreateDelegate method arbitrary code execution attempt (more info ...)attempted-user 2010-1898   URL
17126OS-WINDOWS Microsoft Windows SMB large session length with small packet (more info ...)attempted-dos 2010-2551   URL
17128FILE-MULTIMEDIA Microsoft Windows AVI cinepak codec decompression remote code execution attempt (more info ...)attempted-user 2010-2553 42256  URL
17133OS-WINDOWS Microsoft Windows MSXML2 ActiveX malformed HTTP response (more info ...)attempted-dos 2010-2561   URL
17135FILE-MULTIMEDIA Microsoft Windows Movie Maker string size overflow attempt (more info ...)attempted-user 2010-2564   URL
17151NETBIOS SMB negotiate protocol request - ascii strings (more info ...)protocol-command-decode    
17163BROWSER-PLUGINS Liquid XML Studio ActiveX function call access (more info ...)attempted-user    URL
17167BROWSER-PLUGINS Oracle Siebel Option Pack 1 ActiveX clsid access (more info ...)attempted-user 2009-3737   URL
17169BROWSER-PLUGINS Oracle Siebel Option Pack 2 ActiveX clsid access (more info ...)attempted-user 2009-3737   URL
17171BROWSER-PLUGINS Oracle Siebel Option Pack 3 ActiveX clsid access (more info ...)attempted-user 2009-3737   URL
17173BROWSER-PLUGINS Oracle Siebel Option Pack 4 ActiveX clsid access (more info ...)attempted-user 2009-3737   URL
17175BROWSER-PLUGINS Oracle Siebel Option Pack 5 ActiveX clsid access (more info ...)attempted-user 2009-3737   URL
17177BROWSER-PLUGINS Oracle Siebel Option Pack 6 ActiveX clsid access (more info ...)attempted-user 2009-3737   URL
17210FILE-EXECUTABLE Microsoft Windows executable file load from SMB share attempt (more info ...)policy-violation    
17226BROWSER-PLUGINS AXIS Camera ActiveX initialization via script (more info ...)attempted-user 2008-5260 33408  
17231FILE-IMAGE Microsoft Kodak Imaging small offset malformed tiff - little-endian (more info ...)attempted-user 2007-2217   URL
17232FILE-IMAGE Microsoft Kodak Imaging large offset malformed tiff - big-endian (more info ...)attempted-user 2010-3950   URL
17252OS-WINDOWS Microsoft Windows Print Spooler arbitrary file write attempt (more info ...)attempted-user 2010-2729   URL
17256OS-WINDOWS Microsoft Windows uniscribe fonts parsing memory corruption attempt (more info ...)attempted-user 2010-2738 43068  URL
17306OS-WINDOWS Microsoft Malware Protection Engine file processing denial of service attempt (more info ...)denial-of-service 2008-1437   URL
17316OS-WINDOWS Microsoft Windows Folder GUID Code Execution attempt (more info ...)attempted-user 2006-3281 19389  
17321NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters name overflow attempt (more info ...)attempted-admin 2007-6701 25092  URL
17330FILE-IMAGE Microsoft Windows GRE WMF Handling Memory Read Exception attempt (more info ...)attempted-user 2006-0143 16167  
17337INDICATOR-SHELLCODE x86 Microsoft Win32 export table enumeration variant (more info ...)shellcode-detect    
17347OS-WINDOWS Microsoft Windows Color Management Module buffer overflow attempt (more info ...)attempted-user 2005-1219 14214  
17364FILE-IDENTIFY Microsoft Windows Help Workshop CNT Help file download request (more info ...)misc-activity    URL
17365FILE-OTHER Microsoft Windows Help Workshop CNT Help contents buffer overflow attempt (more info ...)web-application-attack 2007-0352 22100  
17366FILE-OTHER Microsoft Help Workshop HPJ OPTIONS section buffer overflow attempt (more info ...)attempted-user 2007-0427 22135  
17374FILE-OTHER Microsoft Windows HLP File Handling heap overflow attempt (more info ...)attempted-user 2007-1912 23382  
17382FILE-OTHER Microsoft Project Invalid Memory Pointer Code Execution attempt (more info ...)attempted-user 2008-1088 28607  
17408OS-WINDOWS Microsoft Windows DirectX Targa image file heap overflow attempt (more info ...)attempted-user 2006-4183 24963  
17413OS-WINDOWS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user 2005-0944 12960  
17435OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
17436OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
17437OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
17438OS-WINDOWS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
17439OS-WINDOWS Microsoft Distributed Transaction Controller TIP DoS attempt (more info ...)attempted-dos 2005-1979 15058  
17442FILE-OTHER Microsoft Windows download of .lnk file that executes cmd.exe detected (more info ...)attempted-user 2005-2122 15069  URL
17443FILE-MULTIMEDIA Microsoft DirectShow AVI decoder buffer overflow attempt (more info ...)attempted-user 2005-2128 15063  
17464BROWSER-PLUGINS AOL Radio AmpX ActiveX clsid access (more info ...)attempted-user 2007-5755 26396  
17467OS-WINDOWS Microsoft Windows ShellExecute and IE7 snews url handling code execution attempt (more info ...)attempted-user 2007-3896 25945  URL
17489FILE-OTHER Microsoft Windows Help File Heap Buffer Overflow attempt (more info ...)attempted-user 2006-1591 17325  
17490FILE-OTHER Microsoft Windows itss.dll CHM File Handling Heap Corruption attempt (more info ...)attempted-admin 2006-2297 17926  
17509FILE-IDENTIFY Microsoft Windows .NET Manifest file download request (more info ...)misc-activity 2006-6696 21688  URL
17510FILE-IDENTIFY Microsoft Windows .NET Deploy file download request (more info ...)misc-activity 2006-6696 21688  URL
17546FILE-IDENTIFY Microsoft Media Player compressed skin download request (more info ...)policy-violation 2007-3037 25305  URL
17571BROWSER-PLUGINS obfuscated instantiation of ActiveX object - likely malicious (more info ...)attempted-user 2008-3558   URL
17572OS-WINDOWS Microsoft XML Core Services cross-site information disclosure attempt (more info ...)attempted-recon 2013-7331 32155  URL
17592BROWSER-PLUGINS Microsoft MyInfo.dll ActiveX clsid access (more info ...)attempted-user 2006-4495 19636  URL
17593BROWSER-PLUGINS Microsoft msdxm.ocx ActiveX clsid access (more info ...)attempted-user 2006-4495 19636  URL
17594BROWSER-PLUGINS Microsoft creator.dll 1 ActiveX clsid access (more info ...)attempted-user 2006-4495 19636  URL
17595BROWSER-PLUGINS Microsoft creator.dll 2 ActiveX clsid access (more info ...)attempted-user 2006-4495 19636  URL
17614BROWSER-PLUGINS SAP GUI SAPBExCommonResources ActiveX clsid access (more info ...)attempted-user    URL
17616BROWSER-PLUGINS SAP GUI SAPBExCommonResources ActiveX function call access (more info ...)attempted-user    URL
17618OS-WINDOWS Microsoft Windows Graphics engine EMF rendering vulnerability (more info ...)attempted-user 2005-2123 15352  
17626OS-WINDOWS Microsoft Windows embedded web font handling buffer overflow attempt (more info ...)attempted-user 2006-0010 16194  
17634NETBIOS DCERPC NCACN-IP-TCP brightstor-arc function 0 little endian object call overflow attempt (more info ...)attempted-admin 2008-4398   URL
17635NETBIOS DCERPC NCACN-IP-TCP brightstor-arc function 0 little endian overflow attempt (more info ...)attempted-admin 2008-4398   URL
17636NETBIOS DCERPC NCACN-IP-TCP brightstor-arc function 0 object call overflow attempt (more info ...)attempted-admin 2008-4398   URL
17637NETBIOS DCERPC NCACN-IP-TCP brightstor-arc function 0 overflow attempt (more info ...)attempted-admin 2008-4398   URL
17640NETBIOS DCERPC NCACN-IP-TCP brightstor opnum 43 overflow attempt (more info ...)attempted-admin 2007-0169 22005  URL
17654BROWSER-PLUGINS Facebook Photo Uploader ActiveX exploit attempt (more info ...)attempted-user 2008-5711 27756  URL
17702OS-WINDOWS DCERPC NCACN-IP-TCP srvsvc NetrDfsCreateExitPoint dos attempt (more info ...)attempted-dos 2005-3644 15460  URL
17711OS-WINDOWS Microsoft Windows ASF parsing memory corruption attempt (more info ...)attempted-user 2007-0064   URL
17721OS-WINDOWS Microsoft Windows WINS replication inform2 request memory corruption attempt (more info ...)attempted-admin 2009-1924   URL
17730OS-WINDOWS Microsoft XML Core Services MIME Viewer memory corruption attempt (more info ...)attempted-user 2007-0099   URL
17731OS-WINDOWS Microsoft Windows wpad dynamic update request (more info ...)attempted-admin 2009-0093   URL
17737SERVER-MAIL Microsoft collaboration data objects buffer overflow attempt (more info ...)attempted-user 2005-1987 15067  
17745NETBIOS SMB TRANS2 Find_First2 request attempt (more info ...)protocol-command-decode    
17746OS-WINDOWS Microsoft Windows SMB client TRANS response Find_First2 filename overflow attempt (more info ...)attempted-admin 2005-0045 12484  URL
17749PROTOCOL-RPC Linux Kernel nfsd v4 CAP_MKNOD security bypass attempt (more info ...)misc-attack 2009-1072 34205  
18072OS-WINDOWS Microsoft Forefront UAG external redirect attempt (more info ...)policy-violation 2010-2732   URL
18073OS-WINDOWS Microsoft Forefront UAG arbitrary embedded scripting attempt (more info ...)attempted-user 2010-2733   URL
18074OS-WINDOWS Microsoft Windows Forefront UAG URL XSS attempt (more info ...)attempted-admin 2010-2734   URL
18076OS-WINDOWS Microsoft Forefront UAG URL XSS alternate attempt (more info ...)attempted-admin 2010-3936   URL
18195OS-WINDOWS Microsoft Windows SMB Negotiate Protocol response DoS attempt (more info ...)attempted-dos 2009-3676   URL
18215OS-WINDOWS NETAPI RPC interface reboot attempt (more info ...)attempted-user 2010-2742   URL
18219FILE-OTHER Microsoft Windows ATMFD font driver remote code execution attempt (more info ...)attempted-user 2010-3957   URL
18220OS-WINDOWS Microsoft Windows ATMFD font driver malformed character glyph remote code execution attempt (more info ...)attempted-user 2010-3959   URL
18242BROWSER-PLUGINS Microsoft Windows WMI Administrator Tools Object Viewer ActiveX function call access (more info ...)attempted-user 2010-4588   URL
18246OS-WINDOWS Microsoft Windows Fax Services Cover Page Editor overflow attempt (more info ...)attempted-user    URL
18266OS-WINDOWS DCERPC NCADG-IP-UDP rpcss2_RemoteGetClassObject attempt (more info ...)protocol-command-decode 2003-0605   URL
18267OS-WINDOWS DCERPC NCACN-IP-TCP rpcss2_RemoteGetClassObject attempt (more info ...)protocol-command-decode 2003-0605   URL
18274FILE-IDENTIFY Microsoft Windows Mail file download request (more info ...)misc-activity   10767 
18276FILE-OTHER Microsoft Data Access Components library attempt (more info ...)attempted-user 2011-0026   URL
18277OS-WINDOWS Microsoft Windows Vista Backup Tool fveapi.dll dll-load exploit attempt (more info ...)attempted-user 2010-3145   URL
18278OS-WINDOWS Microsoft Windows Vista Backup Tool request for fveapi.dll over SMB attempt (more info ...)attempted-user 2010-3145   URL
18297OS-WINDOWS Microsoft Windows Comctl32.dll third-party SVG viewer heap overflow attempt (more info ...)attempted-user 2010-2746   URL
18309OS-WINDOWS Microsoft Vector Markup Language fill method overflow attempt (more info ...)attempted-user 2006-4868 20096  URL
18315OS-WINDOWS DCERPC NCACN-IP-TCP wkssvc NetrValidateName2 overflow attempt (more info ...)attempted-admin 2003-0812 9011 11921 URL
18321BROWSER-PLUGINS SonicWall Aventail EPInterrogator ActiveX clsid access (more info ...)attempted-user    
18322BROWSER-PLUGINS SonicWall Aventail EPInterrogator ActiveX function call access (more info ...)attempted-user    
18323BROWSER-PLUGINS SonicWall Aventail EPInstaller ActiveX clsid access (more info ...)attempted-user 2010-2583 44535  
18324BROWSER-PLUGINS SonicWall Aventail EPInstaller ActiveX function call access (more info ...)attempted-user 2010-2583 44535  
18325BROWSER-PLUGINS Image Viewer CP Gold 6 ActiveX clsid access (more info ...)attempted-user  45155  
18329BROWSER-PLUGINS Microsoft Windows WMI Administrator Tools Object Viewer ActiveX function call access (more info ...)attempted-user 2010-4588   URL
18335OS-WINDOWS Microsoft Windows MHTML XSS attempt (more info ...)attempted-user 2011-0096   URL
18385MALWARE-CNC User-Agent known malicious user-agent string HTTPCSDCENTER (more info ...)trojan-activity    URL
18396OS-WINDOWS Microsoft Windows Hypervisor OS-WINDOWS vfd download attempt (more info ...)attempted-admin 2010-0026   URL
18406FILE-OTHER Microsoft Windows Server 2003 update service principal name spn dos executable attempt (more info ...)attempted-admin 2011-0040   URL
18407FILE-OTHER Microsoft Windows Server 2003 update service principal name spn dos attempt (more info ...)attempted-admin 2011-0040   URL
18408OS-WINDOWS Microsoft Windows WMI tracing api integer truncation attempt (more info ...)attempted-admin 2011-0045   URL
18463FILE-OTHER Microsoft Windows MPEG Layer-3 audio heap corruption attempt (more info ...)attempted-user 2010-1882   URL
18490BROWSER-PLUGINS Whale Client Components ActiveX clsid access (more info ...)attempted-user 2007-2238 34532  
18494OS-WINDOWS Microsoft product .dll dll-load exploit attempt (more info ...)attempted-user 2015-1758   URL
18498FILE-OTHER Microsoft Media Player dvr-ms file parsing remote code execution attempt (more info ...)attempted-user 2011-0042   URL
18499OS-WINDOWS Microsoft Groove mso.dll dll-load exploit attempt (more info ...)attempted-user 2011-0108   URL
18583FILE-IMAGE Microsoft Windows wmf integer overflow attempt (more info ...)web-application-attack 2007-3034 25302  URL
18594BROWSER-PLUGINS Trend Micro Web Deployment ActiveX clsid access (more info ...)attempted-user 2008-3364 30407  
18595BROWSER-PLUGINS Trend Micro Web Deployment ActiveX clsid access (more info ...)attempted-user 2008-3364 30407  
18619OS-WINDOWS Microsoft Visual Studio MFC applications mfc40.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18620OS-WINDOWS Microsoft Visual Studio MFC applications mfc42.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18621OS-WINDOWS Microsoft Visual Studio MFC applications mfc80.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18622OS-WINDOWS Microsoft Visual Studio MFC applications mfc90.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18623OS-WINDOWS Microsoft Visual Studio MFC applications mfc100.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18624OS-WINDOWS Microsoft Windows .NET framework optimizer escalation attempt (more info ...)attempted-user 2010-3958   URL
18625OS-WINDOWS Microsoft Foundation Class applications mfc40.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18626OS-WINDOWS Microsoft Foundation Class applications mfc42.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18627OS-WINDOWS Microsoft Foundation Class applications mfc80.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18628OS-WINDOWS Microsoft Foundation Class applications mfc90.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18629OS-WINDOWS Microsoft Foundation Class applications mfc100.dll dll-load exploit attempt (more info ...)attempted-user 2010-3190   URL
18644FILE-OTHER Microsoft Windows OpenType Fonts CompactFontFormat FontMatrix tranform memory corruption attempt (more info ...)attempted-admin 2011-0034   URL
18645FILE-IMAGE Microsoft Windows GDI+ arbitrary code execution attempt (more info ...)attempted-user 2011-0041   URL
18655OS-WINDOWS Microsoft Windows LLMNR invalid reverse name lookup stack corruption attempt (more info ...)attempted-admin 2011-0657   URL
18660OS-WINDOWS Microsoft Windows SMB2 write packet buffer overflow attempt (more info ...)attempted-admin 2011-0661   URL
18668BROWSER-PLUGINS Microsoft Windows Messenger ActiveX clsid access (more info ...)attempted-user 2011-1243   URL
18673OS-WINDOWS Microsoft Fax Cover Page Editor heap corruption attempt (more info ...)attempted-user 2010-3974   URL
18675FILE-IDENTIFY Microsoft Windows Fax Cover page document file download request (more info ...)misc-activity    
18691OS-WINDOWS Microsoft Windows AFD.SYS null write attempt (more info ...)attempted-admin 2011-1249   URL
18741BROWSER-PLUGINS CrystalReports EnterpriseControls ActiveX clsid access (more info ...)attempted-user 2008-0379 27333  
18756INDICATOR-COMPROMISE Microsoft cmd.exe banner Windows 7/Server 2008R2 (more info ...)successful-admin   11633 
18757INDICATOR-COMPROMISE Microsoft cmd.exe banner Windows Vista (more info ...)successful-admin   11633 
18950OS-WINDOWS Microsoft WINS service oversize payload exploit attempt (more info ...)attempted-admin 2011-1248   URL
18952FILE-OTHER Microsoft Windows uniscribe fonts parsing memory corruption attempt (more info ...)attempted-user 2010-2738 43068  URL
18961OS-WINDOWS Microsoft Windows MSXML2 ActiveX malformed HTTP response (more info ...)attempted-dos 2010-2561   URL
18962OS-WINDOWS Microsoft Windows MSXML2 ActiveX malformed HTTP response (more info ...)attempted-dos 2010-2561   URL
18974BROWSER-PLUGINS SAP Crystal Reports PrintControl.dll ActiveX function call attempt (more info ...)attempted-user 2010-2590 45387  
18975BROWSER-PLUGINS SAP Crystal Reports PrintControl.dll ActiveX function call access (more info ...)attempted-user 2010-2590 45387  
18980MALWARE-CNC WinSpywareProtect variant outbound connection (more info ...)trojan-activity    URL
18981MALWARE-CNC WinSpywareProtect variant outbound connection (more info ...)trojan-activity    URL
18982MALWARE-CNC WinSpywareProtect variant outbound connection (more info ...)trojan-activity    URL
19063FILE-MULTIMEDIA Microsoft Windows Movie Maker string size overflow attempt (more info ...)attempted-user 2010-2564   URL
19064FILE-OTHER Microsoft OpenType font index remote code execution attempt (more info ...)attempted-user 2010-3956 45311  URL
19086BROWSER-PLUGINS LEADTOOLS Raster Twain LtocxTwainu.dll ActiveX function call (more info ...)attempted-user  42823  
19109BROWSER-PLUGINS SonicWall Aventail EPInstaller ActiveX function call access (more info ...)attempted-user    
19119OS-WINDOWS Microsoft Windows ATMFD font driver remote code execution attempt (more info ...)attempted-user 2010-3957   URL
19130FILE-IMAGE Microsoft Windows Paint jpeg with malformed SOFx field integer overflow attempt (more info ...)attempted-user 2010-0028   URL
19144FILE-OTHER Microsoft Windows MPEG Layer-3 audio heap corruption attempt (more info ...)attempted-user 2010-1882 42298  URL
19146FILE-MULTIMEDIA Microsoft Windows DirectX quartz.dll MJPEG content processing memory corruption attempt (more info ...)attempted-user 2010-1879 40432  URL
19151BROWSER-PLUGINS Trend Micro HouseCall ActiveX clsid access (more info ...)attempted-user 2010-3189   
19152BROWSER-PLUGINS Trend Micro HouseCall ActiveX function call access (more info ...)attempted-user 2010-3189   
19170FILE-OTHER Microsoft Windows .NET Framework XAML browser applications stack corruption (more info ...)attempted-user 2010-3958 47223  
19184OS-WINDOWS Microsoft Windows OLEAUT32.DLL malicious WMF file remote code execution attempt (more info ...)attempted-user 2011-0658   URL
19185OS-WINDOWS Microsoft Windows .NET ArraySegment escape exploit attempt (more info ...)attempted-user 2011-0664   URL
19186OS-WINDOWS Microsoft Certification service XSS attempt (more info ...)attempted-user 2011-1264   URL
19188OS-WINDOWS Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
19189OS-WINDOWS Microsoft Windows SMB-DS Trans2 Distributed File System response PathConsumed integer overflow attempt (more info ...)attempted-admin 2011-1869   URL
19190NETBIOS SMB-DS Trans2 Distributed File System GET_DFS_REFERRAL request (more info ...)protocol-command-decode    
19191OS-WINDOWS Microsoft Windows SMB2 zero length write attempt (more info ...)attempted-admin 2011-1267   URL
19193BROWSER-PLUGINS Oracle Document Capture ActiveX clsid access (more info ...)attempted-user 2010-3599 45856  
19194BROWSER-PLUGINS Oracle Document Capture ActiveX function call access (more info ...)attempted-user 2010-3599 45856  
19195BROWSER-PLUGINS Oracle Document Capture ActiveX function call access (more info ...)attempted-user 2010-3599 45856  
19197BROWSER-PLUGINS CA Internet Security Suite XMLSecDB ActiveX clsid access (more info ...)attempted-user 2011-1036 46539  
19198BROWSER-PLUGINS CA Internet Security Suite XMLSecDB ActiveX function call access (more info ...)attempted-user 2011-1036 46539  
19218FILE-IDENTIFY Microsoft Windows Fax Cover page document file download request (more info ...)misc-activity    
19219FILE-OTHER Microsoft Windows Fax Services Cover Page Editor Double Free Memory Corruption (more info ...)attempted-admin 2010-2701 45942  
19220FILE-OTHER Microsoft Windows Fax Services Cover Page Editor Double Free Memory Corruption (more info ...)attempted-admin 2010-2701 45942  
19221OS-WINDOWS Microsoft Windows SMB-DS Trans2 Distributed File System response PathConsumed integer overflow attempt (more info ...)attempted-admin 2011-1869   URL
19233FILE-IDENTIFY Microsoft Windows Visual Studio DISCO file download request (more info ...)misc-activity    URL
19234OS-WINDOWS Microsoft Visual Studio information disclosure attempt (more info ...)misc-attack 2011-1280   URL
19241BROWSER-IE Microsoft Windows Vector Markup Language imagedata page deconstruction attempt (more info ...)attempted-admin 2011-1264 48173  URL
19242BROWSER-IE Microsoft Windows Vector Markup Language imagedata page deconstruction attempt (more info ...)attempted-admin 2011-1264 48173  URL
19304BROWSER-PLUGINS Oracle EasyMail ActiveX clsid access (more info ...)attempted-user 2010-3595 45849  
19305BROWSER-PLUGINS Oracle EasyMail ActiveX function call access (more info ...)attempted-user 2010-3595 45849  
19308FILE-OTHER Microsoft Windows embedded OpenType EOT font integer overflow attempt (more info ...)attempted-user 2010-1883 43775  URL
19315OS-WINDOWS Microsoft Groove GroovePerfmon.dll dll-load exploit attempt (more info ...)attempted-user 2010-3146   URL
19320FILE-MULTIMEDIA Microsoft Windows AVI Header insufficient data corruption attempt (more info ...)attempted-user 2009-1545 35967  URL
19403FILE-MULTIMEDIA Microsoft Windows AVI cinepak codec decompression remote code execution attempt (more info ...)attempted-user 2010-2553 42256  URL
19460OS-WINDOWS Microsoft Windows CSRSS multiple consoles on a single process attempt (more info ...)attempted-user 2011-1281   URL
19461OS-WINDOWS Microsoft CSRSS NULL Fontface pointer attempt (more info ...)attempted-user 2011-1282   URL
19462OS-WINDOWS Microsoft Windows CSRSS negative array index code execution attempt (more info ...)attempted-user 2011-1283   URL
19463OS-WINDOWS Microsoft Windows CSRSS double free attempt (more info ...)attempted-user 2011-1284   URL
19464OS-WINDOWS Microsoft CSRSS integer overflow attempt (more info ...)attempted-user 2011-1870   URL
19467OS-WINDOWS Microsoft CSRSS NULL Fontface pointer attempt (more info ...)attempted-user 2011-1874   URL
19468OS-WINDOWS Microsoft stale data code execution attempt (more info ...)attempted-user 2011-1875   URL
19469OS-WINDOWS Microsoft invalid message kernel-mode memory disclosure attempt (more info ...)attempted-user 2011-1886   URL
19562BROWSER-PLUGINS RealNetworks RealGames InstallerDlg.dll ActiveX clsid access (more info ...)attempted-user    
19563BROWSER-PLUGINS RealNetworks RealGames InstallerDlg.dll ActiveX function call access (more info ...)attempted-user    
19564BROWSER-PLUGINS RealNetworks RealGames InstallerDlg.dll ActiveX clsid access (more info ...)attempted-user    
19565BROWSER-PLUGINS RealNetworks RealGames InstallerDlg.dll ActiveX function call access (more info ...)attempted-user    
19650BROWSER-PLUGINS Cisco AnyConnect ActiveX clsid access (more info ...)attempted-user 2011-2039   URL
19651BROWSER-PLUGINS Cisco AnyConnect ActiveX function call access (more info ...)attempted-user 2011-2039   URL
19665OS-WINDOWS Microsoft Windows Remote Desktop web access cross site scripting attempt - GET request (more info ...)web-application-attack 2011-1263   URL
19673OS-WINDOWS Microsoft Data Access Components bidlab.dll dll-load exploit attempt (more info ...)attempted-user 2011-1975   URL
19674OS-WINDOWS Microsoft Data Access Components bidlab.dll dll-load exploit attempt (more info ...)attempted-user 2011-1975   URL
19681OS-WINDOWS Microsoft Report Viewer reflect XSS attempt (more info ...)attempted-user 2011-1976   URL
19694SERVER-WEBAPP Microsoft Windows .NET Chart Control directory traversal attempt (more info ...)attempted-recon 2011-1977   URL
19816NETBIOS Juniper NeoterisSetupService named pipe access attempt (more info ...)protocol-command-decode 2009-4643   
19817NETBIOS Juniper Odyssey Access Client DSSETUPSERVICE_CMD_UNINSTALL overflow attempt (more info ...)attempted-admin 2009-4643   URL
19818OS-WINDOWS Microsoft XML core services cross-domain information disclosure attempt (more info ...)attempted-recon 2008-4033   URL
19893BROWSER-PLUGINS Microsoft Windows Tabular Control ActiveX overflow by CLSID / param tag (more info ...)attempted-user 2010-0805   URL
19909BROWSER-PLUGINS Cisco AnyConnect ActiveX clsid access (more info ...)attempted-user 2011-2039   URL
19911FILE-OTHER Microsoft SYmbolic LinK stack overflow attempt (more info ...)attempted-user 2011-1276 48161  URL
19925BROWSER-PLUGINS Novell iPrint ActiveX client browser plugin call-back-url buffer overflow attempt (more info ...)attempted-user 2010-1527   URL
19956FILE-MULTIMEDIA Microsoft Windows Movie Maker project file heap buffer overflow attempt (more info ...)attempted-user 2010-0265   URL
20061NETBIOS DCERPC NCACN-IP-TCP ca-alert function 16,23,40, and 41 overflow attempt (more info ...)attempted-admin 2007-4620 28605  URL
20071BROWSER-PLUGINS Microsoft Windows Visual Studio WMIScriptUtils.WMIObjectBroker2.1 ActiveX CLSID access (more info ...)attempted-user 2006-4704   URL
20073OS-WINDOWS Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-user 2011-1873   URL
20114SERVER-WEBAPP Microsoft SharePoint hiddenSpanData cross site scripting attempt (more info ...)web-application-attack 2011-1891   URL
20117SERVER-WEBAPP Microsoft SharePoint XSS (more info ...)web-application-attack 2011-1252   URL
20118OS-WINDOWS Microsoft Windows shell extensions deskpan.dll dll-load exploit attempt (more info ...)attempted-user 2011-1991   URL
20119OS-WINDOWS Microsoft Windows shell extensions deskpan.dll dll-load exploit attempt (more info ...)attempted-user 2011-1991   URL
20120OS-WINDOWS Microsoft Windows WINS internal communications on network exploit attempt (more info ...)attempted-user 2011-1984   URL
20132OS-WINDOWS Microsoft Windows Vista SMB2 zero length write attempt (more info ...)attempted-admin 2011-1267   URL
20168BROWSER-PLUGINS ChemView SaveAsMolFile vulnerability ActiveX clsid access (more info ...)attempted-user 2010-0679 38225  
20175BROWSER-PLUGINS Microsoft Windows Remote Desktop Client ActiveX clsid access (more info ...)attempted-user 2009-1929   URL
20248PROTOCOL-RPC IBM AIX and Oracle Solaris nfsd v4 nfs_portmon security bypass attempt (more info ...)misc-attack 2009-3517 36544  
20253OS-WINDOWS Microsoft products oleacc.dll dll-load exploit attempt (more info ...)attempted-user 2011-1247   URL
20255BROWSER-PLUGINS Microsoft Silverlight inheritance restriction bypass (more info ...)attempted-user 2011-1253   URL
20256OS-WINDOWS Microsoft Forefront UAG http response splitting attempt (more info ...)attempted-user 2011-1895   URL
20259FILE-OTHER Microsoft Agent Helper Malicious JAR download attempt (more info ...)attempted-user 2011-1969   URL
20260FILE-IDENTIFY Microsoft Client Agent Helper JAR file download request (more info ...)misc-activity 2011-1969   URL
20271OS-WINDOWS Microsoft Windows Host Integration Server SNA length dos attempt (more info ...)attempted-dos 2011-2008   URL
20272OS-WINDOWS Microsoft Windows Forefront UAG NLSessionS cookie overflow attempt (more info ...)attempted-dos 2011-2012   URL
20274NETBIOS DCERPC NCACN-IP-TCP NetShareEnumAll request (more info ...)protocol-command-decode    URL
20275NETBIOS DCERPC NCACN-IP-TCP spoolss NetShareEnumAll response overflow attempt (more info ...)attempted-admin 2009-0228 35206  URL
20285BROWSER-PLUGINS Black Ice Barcode SDK ActiveX clsid access (more info ...)attempted-user 2008-2684 29579  
20286BROWSER-PLUGINS Black Ice Barcode SDK ActiveX function call access (more info ...)attempted-user 2008-2684 29579  
20536BROWSER-PLUGINS Moxa MediaDBPlayback.DLL ActiveX clsid access (more info ...)attempted-user    
20537BROWSER-PLUGINS Phobos.Playlist ActiveX clsid access (more info ...)attempted-user    
20538BROWSER-PLUGINS Phobos.Playlist ActiveX function call access (more info ...)attempted-user    
20572FILE-OTHER Microsoft Windows Font Library file buffer overflow attempt (more info ...)attempted-user 2011-2003   URL
20573BROWSER-PLUGINS Oracle AutoVueX Control ExportEdaBom ActiveX clsid access (more info ...)attempted-user    URL
20574BROWSER-PLUGINS Oracle AutoVueX Control ExportEdaBom ActiveX function call access (more info ...)attempted-user    URL
20591BROWSER-PLUGINS Flexera InstallShield ISGrid2.dll DoFindReplace heap buffer overlow ActiveX clsid access (more info ...)attempted-user 2011-3174   
20592BROWSER-PLUGINS Flexera InstallShield ISGrid2.dll DoFindReplace heap buffer overlow ActiveX function call access (more info ...)attempted-user 2011-3174   
20603OS-WINDOWS Microsoft Windows RSH daemon buffer overflow attempt (more info ...)attempted-admin 2007-4006   
20707BROWSER-PLUGINS Dell IT Assistant ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20708BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20710BROWSER-PLUGINS HP Photo Creative ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20711BROWSER-PLUGINS HP Photo Creative ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20712BROWSER-PLUGINS HP Photo Creative ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20713BROWSER-PLUGINS HP Photo Creative ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20714BROWSER-PLUGINS HP Photo Creative ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20715BROWSER-PLUGINS HP Photo Creative ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20716BROWSER-PLUGINS Yahoo! CD Player ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20735FILE-OTHER Microsoft Windows TrueType font parsing engine sfac_GetSbitBitmap elevation of privileges attempt (more info ...)attempted-user 2011-3402   URL
20768FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
20769FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-user 2011-1873   URL
20770FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
20771FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
20772FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
20773FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
20774FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
20775FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
20776FILE-OTHER Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
20834BROWSER-PLUGINS Novell ZENworks LaunchHelp.dll ActiveX clsid access attempt (more info ...)attempted-user 2011-2657   URL
20835BROWSER-PLUGINS Novell ZENworks LaunchHelp.dll ActiveX clsid access attempt (more info ...)attempted-user 2011-2657   URL
20846BROWSER-PLUGINS Oracle Hyperion Strategic Finance Client SetDevNames ActiveX clsid access attempt (more info ...)attempted-user 2011-5167   
20847BROWSER-PLUGINS Oracle Hyperion Strategic Finance Client SetDevNames ActiveX clsid access attempt (more info ...)attempted-user 2011-5167   
20879OS-WINDOWS Microsoft Windows Embedded Package Object packager.exe file load exploit attempt (more info ...)attempted-user 2012-0009   URL
20884OS-WINDOWS Microsoft Anti-Cross Site Scripting library bypass attempt (more info ...)attempted-user 2012-0007   URL
20901BROWSER-PLUGINS Microsoft Works WkImgSrv.dll ActiveX control exploit attempt (more info ...)attempted-user 2008-1898 28820  
20902FILE-OTHER Microsoft Windows OpenType font parsing stack overflow attempt (more info ...)attempted-admin 2011-0034   URL
20903FILE-OTHER Microsoft Windows OpenType font parsing stack overflow attempt (more info ...)attempted-admin 2011-0034   URL
20904FILE-OTHER Microsoft Windows OpenType font parsing stack overflow attempt (more info ...)attempted-admin 2011-0034   URL
20949BROWSER-PLUGINS Autodesk iDrop ActiveX clsid access (more info ...)attempted-user    URL
21000PROTOCOL-SCADA Microsys PROMOTIC ActiveX clsid access (more info ...)attempted-user    URL
21001PROTOCOL-SCADA Microsys PROMOTIC ActiveX function call access (more info ...)attempted-user    URL
21007FILE-IDENTIFY Microsoft Money file magic detected (more info ...)misc-activity    
21008FILE-IDENTIFY Microsoft Money file download request (more info ...)misc-activity    
21009FILE-IDENTIFY Microsoft Money file attachment detected (more info ...)misc-activity    
21010FILE-IDENTIFY Microsoft Money file attachment detected (more info ...)misc-activity    
21022BROWSER-PLUGINS Viscom Software Image Viewer ActiveX clsid access (more info ...)attempted-user 2010-5193   URL
21023BROWSER-PLUGINS Viscom Software Image Viewer ActiveX function call access (more info ...)attempted-user 2010-5193   URL
21024BROWSER-PLUGINS McAfee Security as a Service ActiveX clsid access attempt (more info ...)attempted-user  51397  URL
21025BROWSER-PLUGINS McAfee Security as a Service ActiveX function call attempt (more info ...)attempted-user  51397  URL
21026BROWSER-PLUGINS McAfee Security as a Service ActiveX clsid access attempt (more info ...)attempted-user  51397  URL
21027BROWSER-PLUGINS McAfee Security as a Service ActiveX function call attempt (more info ...)attempted-user  51397  URL
21029BROWSER-PLUGINS Bennet-Tec TList saveData arbitrary file creation ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
21030BROWSER-PLUGINS Bennet-Tec TList saveData arbitrary file creation ActiveX function call access (more info ...)attempted-user 2011-3397   URL
21031BROWSER-PLUGINS Bennet-Tec TList saveData arbitrary file creation ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
21032BROWSER-PLUGINS Bennet-Tec TList saveData arbitrary file creation ActiveX function call access (more info ...)attempted-user 2011-3397   URL
21033BROWSER-PLUGINS Bennet-Tec TList saveData arbitrary file creation ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
21034BROWSER-PLUGINS Bennet-Tec TList saveData arbitrary file creation ActiveX function call access (more info ...)attempted-user 2011-3397   URL
21063BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access attempt (more info ...)attempted-user 2011-4786 51396  
21064BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access attempt (more info ...)attempted-user 2011-4786 51396  
21076BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access (more info ...)attempted-user 2011-4787 51400  
21077BROWSER-PLUGINS HP Easy Printer Care Software ActiveX function call (more info ...)attempted-user 2011-4787 51400  
21080BROWSER-PLUGINS Microsoft Windows Scripting Host Shell ActiveX function call access (more info ...)attempted-user 2006-0003 17462  URL
21088OS-WINDOWS Microsoft Windows remote desktop denial of service attempt (more info ...)attempted-dos 2005-1218 14259  URL
21089OS-WINDOWS Microsoft Windows remote desktop oversized cookie attempt (more info ...)attempted-dos 2005-1218 14259  URL
21094BROWSER-PLUGINS McAfee Remediation Agent ActiveX function call access (more info ...)attempted-user    URL
21100PROTOCOL-RPC Novell Netware xdr decode string length buffer overflow attempt (more info ...)attempted-user 2011-4191   URL
21160FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502 36646  URL
21165FILE-OTHER multiple products GeckoActiveX COM object recon attempt (more info ...)attempted-recon 2009-3987 37360  
21262OS-WINDOWS DCERPC ISystemActivate flood attempt (more info ...)protocol-command-decode 2003-0813 8811 12206 URL
21264BROWSER-PLUGINS Symantec Norton Internet Security 2004 ActiveX function call (more info ...)attempted-user 2004-0363 9916  
21281OS-WINDOWS Microsoft Windows ATMFD font driver malicious font file remote code execution attempt (more info ...)attempted-admin 2011-1873   URL
21289OS-WINDOWS Microsoft Color Control Panel STI.dll dll-load exploit attempt (more info ...)attempted-user 2010-5082   URL
21290OS-WINDOWS Microsoft Color Control Panel STI.dll dll-load exploit attempt (more info ...)attempted-user 2010-5082   URL
21298SERVER-WEBAPP Microsoft SharePoint chart webpart XSS attempt (more info ...)web-application-attack 2012-0145   URL
21309OS-WINDOWS Microsoft product request for fputlsat.dll over SMB attempt (more info ...)attempted-user 2011-1980   URL
21310OS-WINDOWS Microsoft product fputlsat.dll dll-load exploit attempt (more info ...)attempted-user 2011-1980   URL
21352OS-WINDOWS Microsoft Fax Cover Page Editor heap corruption attempt (more info ...)attempted-user 2010-3974   URL
21357OS-WINDOWS Microsoft Windows OLEAUT32.DLL malicious WMF file remote code execution attempt (more info ...)attempted-user 2011-0658   URL
21405OS-WINDOWS Microsoft Anti-Cross Site Scripting library bypass attempt (more info ...)attempted-user 2012-0007   URL
21439FILE-IMAGE Microsoft Windows GDI+ arbitrary code execution attempt (more info ...)attempted-user 2011-0041   URL
21489FILE-OTHER Microsoft Windows chm file malware related exploit (more info ...)trojan-activity    URL
21493BROWSER-PLUGINS Microsoft Windows DRM technology msnetobj.dll ActiveX clsid access (more info ...)attempted-user  43345  URL
21558BROWSER-PLUGINS Symantec Norton Antivirus ActiveX clsid access (more info ...)attempted-user 2005-2127 10392  URL
21559BROWSER-PLUGINS Symantec Norton Antivirus ActiveX clsid access (more info ...)attempted-user 2005-2127 10392  URL
21560BROWSER-PLUGINS Symantec Norton Antivirus ActiveX clsid access (more info ...)attempted-user 2005-2127   
21561BROWSER-PLUGINS Symantec Norton Antivirus ActiveX function call access (more info ...)attempted-user 2005-2127   
21566OS-WINDOWS Microsoft Expression Design request for wintab32.dll over SMB attempt (more info ...)attempted-user 2012-0016   URL
21567OS-WINDOWS Microsoft Expression Design wintab32.dll dll-load exploit attempt (more info ...)attempted-user 2012-0016   URL
21568OS-WINDOWS Microsoft Windows RDP RST denial of service attempt (more info ...)attempted-dos 2012-0152   URL
21573FILE-IDENTIFY Microsoft Visual Studio addin file download request (more info ...)misc-activity    
21574FILE-IDENTIFY Microsoft Visual Studio addin file attachment detected (more info ...)misc-activity    
21575FILE-IDENTIFY Microsoft Visual Studio addin file attachment detected (more info ...)misc-activity    
21576FILE-OTHER Microsoft Windows Visual Studio .addin file access (more info ...)attempted-user 2012-0008   URL
21770FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2007-3895   URL
21771FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2007-3895   URL
21772FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2007-3895   URL
21773FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2007-3895   URL
21774FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2007-3895   URL
21775FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2007-3895   URL
21865FILE-IDENTIFY Microsoft Windows Fax Cover page document file attachment detected (more info ...)misc-activity    
21866FILE-IDENTIFY Microsoft Windows Fax Cover page document file attachment detected (more info ...)misc-activity    
21867FILE-IDENTIFY Microsoft Windows Fax Cover page document file attachment detected (more info ...)misc-activity    
21868FILE-IDENTIFY Microsoft Windows Fax Cover page document file attachment detected (more info ...)misc-activity    
21879FILE-IDENTIFY Microsoft search file attachment detected (more info ...)misc-activity 2008-4268   URL
21880FILE-IDENTIFY Microsoft search file attachment detected (more info ...)misc-activity 2008-4268   URL
21882BROWSER-PLUGINS ICONICS WebHMI ActiveX clsid access attempt (more info ...)attempted-user 2011-2089   URL
21883BROWSER-PLUGINS ICONICS WebHMI ActiveX clsid access attempt (more info ...)attempted-user 2011-2089   URL
21888FILE-IDENTIFY Microsoft Windows Movie Maker file attachment detected (more info ...)misc-activity    
21889FILE-IDENTIFY Microsoft Windows Movie Maker file attachment detected (more info ...)misc-activity    
21950BROWSER-PLUGINS Microsoft Windows MSWebDVD ActiveX clsid access attempt (more info ...)attempted-user  10056  
21951BROWSER-PLUGINS Microsoft Windows MSWebDVD ActiveX function call attempt (more info ...)attempted-user  10056  
21955FILE-IDENTIFY Microsoft Windows hlp file magic detected (more info ...)misc-activity    
21956FILE-IDENTIFY Microsoft Windows hlp file attachment detected (more info ...)misc-activity    
21957FILE-IDENTIFY Microsoft Windows hlp file attachment detected (more info ...)misc-activity    
22013FILE-IDENTIFY Microsoft Visual Studio DBP file download request (more info ...)misc-activity    
22014FILE-IDENTIFY Microsoft Visual Studio DBP file attachment detected (more info ...)misc-activity    
22015FILE-IDENTIFY Microsoft Visual Studio DBP file attachment detected (more info ...)misc-activity    
22016FILE-IDENTIFY Microsoft Visual Studio DBP file magic detected (more info ...)misc-activity    
22017FILE-IDENTIFY Microsoft Visual Studio PKP file download request (more info ...)misc-activity    
22018FILE-IDENTIFY Microsoft Visual Studio PKP file attachment detected (more info ...)misc-activity    
22019FILE-IDENTIFY Microsoft Visual Studio PKP file attachment detected (more info ...)misc-activity    
22020FILE-IDENTIFY Microsoft Visual Studio PKP file magic detected (more info ...)misc-activity    
22021FILE-IDENTIFY Microsoft Visual Studio SLN file download request (more info ...)misc-activity    
22022FILE-IDENTIFY Microsoft Visual Studio SLN file attachment detected (more info ...)misc-activity    
22023FILE-IDENTIFY Microsoft Visual Studio SLN file attachment detected (more info ...)misc-activity    
22024FILE-IDENTIFY Microsoft Visual Studio SLN file magic detected (more info ...)misc-activity    
22025FILE-IDENTIFY Microsoft Visual Studio VAP file download request (more info ...)misc-activity    
22026FILE-IDENTIFY Microsoft Visual Studio VAP file attachment detected (more info ...)misc-activity    
22027FILE-IDENTIFY Microsoft Visual Studio VAP file attachment detected (more info ...)misc-activity    
22028FILE-IDENTIFY Microsoft Visual Studio VAP file magic detected (more info ...)misc-activity    
22049BROWSER-PLUGINS Symantec Norton Internet Security ActiveX clsid access (more info ...)attempted-user 2004-0364   URL
22050BROWSER-PLUGINS Symantec Norton Internet Security ActiveX function call (more info ...)attempted-user 2004-0364   URL
22999FILE-IDENTIFY Microsoft Windows WMF file magic detected (more info ...)misc-activity    URL
23048BROWSER-PLUGINS McAfee Virtual Technician Security Bypass ActiveX clsid access attempt (more info ...)attempted-user 2012-4598 53304  
23049BROWSER-PLUGINS McAfee Virtual Technician Security Bypass ActiveX clsid access attempt (more info ...)attempted-user 2012-4598 53304  
23050BROWSER-PLUGINS McAfee Virtual Technician Security Bypass ActiveX clsid access attempt (more info ...)attempted-user 2012-4598 53304  
23090SERVER-OTHER known malicious SSL certificate derived from Microsoft CA detected (more info ...)misc-attack    URL
23110FILE-IMAGE Microsoft Windows graphics rendering engine buffer overflow attempt (more info ...)attempted-user 2004-0209 11375  
23136BROWSER-IE Microsoft multiple product toStaticHTML XSS attempt (more info ...)attempted-user 2012-2520   URL
23137BROWSER-IE Microsoft multiple product toStaticHTML XSS attempt (more info ...)attempted-user 2012-2520   URL
23162OS-WINDOWS Microsoft Lync Online request for ncrypt.dll over SMB attempt (more info ...)attempted-user 2012-1849   URL
23163OS-WINDOWS Microsoft Lync Online request for wlanapi.dll over SMB attempt (more info ...)attempted-user 2012-1849   URL
23165SERVER-OTHER Microsoft Lync Online wlanapi.dll dll-load exploit attempt (more info ...)attempted-user 2012-1849   URL
23172SERVER-WEBAPP Microsoft ASP.NET improper comment handling XSS attempt (more info ...)web-application-attack 2008-3843 20753  
23174BROWSER-PLUGINS IBM Lotus Quickr ActiveX stack buffer overflow attempt (more info ...)attempted-user 2012-2176 53678  
23175BROWSER-PLUGINS IBM Lotus Quickr ActiveX stack buffer overflow attempt (more info ...)attempted-user 2012-2176 53678  
23186BROWSER-PLUGINS Dell CrazyTalk.DLL ActiveX clsid access (more info ...)attempted-user    
23228BROWSER-PLUGINS Oracle Webcenter ActiveX clsid access (more info ...)attempted-user 2012-1710   
23230OS-WINDOWS Microsoft Windows NT DHCP REQUEST client identifier overflow attempt (more info ...)denial-of-service 2004-0899 11920  URL
23231OS-WINDOWS Microsoft Windows NT DHCP REQUEST hostname overflow attempt (more info ...)denial-of-service 2004-0899 11920  URL
23238NETBIOS Wireshark console.lua file load exploit attempt (more info ...)attempted-user 2011-3360 49528  URL
23253BROWSER-PLUGINS HP Easy Printer Care XMLSimpleAccessor ActiveX function call access attempt (more info ...)attempted-user 2011-2404 49100  
23284BROWSER-PLUGINS Oracle WebCenter Forms Recognition ActiveX clsid access attempt (more info ...)attempted-user 2012-1709   
23372BROWSER-PLUGINS Teechart Professional ActiveX clsid access (more info ...)attempted-user    
23374BROWSER-PLUGINS Teechart Professional ActiveX clsid access (more info ...)attempted-user    
23375BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
23376BROWSER-PLUGINS Teechart Professional ActiveX clsid access (more info ...)attempted-user    
23408OS-WINDOWS Microsoft Windows large image resize denial of service attempt (more info ...)attempted-dos    URL
23436OS-WINDOWS Microsoft Windows DirectX IDirectPlay4 denial of service attempt (more info ...)attempted-dos 2004-0202   
23437OS-WINDOWS Microsoft Windows DirectX IDirectPlay4 denial of service attempt (more info ...)attempted-dos 2004-0202   
23470BROWSER-PLUGINS StoneTrip S3DPlayer ActiveX clsid access attempt (more info ...)attempted-user 2009-1792 35105  
23499FILE-OTHER Microsoft Windows CUR file parsing overflow attempt (more info ...)attempted-user 2004-1049 12095  
23508FILE-PDF Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt (more info ...)attempted-admin 2010-2862   URL
23561FILE-IMAGE Microsoft Kodak Imaging large offset malformed tiff - big-endian (more info ...)attempted-user 2010-3950   URL
23562FILE-OTHER Microsoft MHTML XSS attempt (more info ...)attempted-user 2011-0096   URL
23563FILE-OTHER Microsoft Windows MHTML XSS attempt (more info ...)attempted-user 2011-0096   URL
23566FILE-OTHER Microsoft Windows Embedded Open Type Font malformed name table overflow attempt (more info ...)attempted-user 2009-0231   URL
23567FILE-MULTIMEDIA Microsoft Windows AVI Header insufficient data corruption attempt (more info ...)attempted-user 2009-1545 35967  URL
23568FILE-MULTIMEDIA Microsoft Windows AVIFile media file processing memory corruption attempt (more info ...)attempted-user 2009-1546 35970  URL
23569FILE-MULTIMEDIA Microsoft Windows AVIFile truncated media file processing memory corruption attempt (more info ...)attempted-user 2009-1546 35970  URL
23578FILE-OTHER Microsoft Windows malformed ASF voice codec memory corruption attempt (more info ...)attempted-user 2009-0555   URL
23589FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502 36646  URL
23590FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502 36646  URL
23701FILE-IDENTIFY Microsoft SYmbolic LinK file magic detected (more info ...)misc-activity 2008-0112   URL
23722FILE-IDENTIFY Microsoft Windows Address Book file magic detected (more info ...)misc-activity 2006-2386   URL
23750FILE-IDENTIFY Microsoft Money file magic detected (more info ...)misc-activity    
23757FILE-IDENTIFY Microsoft Windows CHM file magic detected (more info ...)attempted-user 2005-1208 13953 18482 URL
23767FILE-IDENTIFY Microsoft Windows hlp file magic detected (more info ...)misc-activity    
23769FILE-IDENTIFY Microsoft Visual Studio DBP file magic detected (more info ...)misc-activity    
23770FILE-IDENTIFY Microsoft Visual Studio PKP file magic detected (more info ...)misc-activity    
23771FILE-IDENTIFY Microsoft Visual Studio SLN file magic detected (more info ...)misc-activity    
23772FILE-IDENTIFY Microsoft Visual Studio VAP file magic detected (more info ...)misc-activity    
23847NETBIOS MS-RAP NetServerEnum2 read access violation attempt (more info ...)attempted-admin 2012-1850   URL
23878BROWSER-PLUGINS Oracle JRE Deployment Toolkit ActiveX clsid access attempt (more info ...)attempted-user 2010-1423 39346  
24039BROWSER-PLUGINS HP Easy Printer Care Software ActiveX function call access (more info ...)attempted-user 2011-4786 51396  
24040BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access attempt (more info ...)attempted-user 2011-4786 51396  
24041BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access attempt (more info ...)attempted-user 2011-4786 51396  
24042BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access attempt (more info ...)attempted-user 2011-4786 51396  
24043BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access attempt (more info ...)attempted-user 2011-4786 51396  
24044BROWSER-PLUGINS HP Easy Printer Care Software ActiveX clsid access attempt (more info ...)attempted-user 2011-4786 51396  
24080FILE-IDENTIFY Microsoft Works file attachment detected (more info ...)misc-activity    
24081FILE-IDENTIFY Microsoft Works file attachment detected (more info ...)misc-activity    
24128OS-WINDOWS Microsoft SCCM ReportChart xss attempt (more info ...)web-application-attack 2012-2536   URL
24246BROWSER-PLUGINS AdminStudio and InstallShield ActiveX clsid access attempt (more info ...)attempted-user    URL
24247BROWSER-PLUGINS AdminStudio and InstallShield ActiveX clsid access attempt (more info ...)attempted-user    URL
24248BROWSER-PLUGINS AdminStudio and InstallShield ActiveX function call access attempt (more info ...)attempted-user    URL
24249BROWSER-PLUGINS AdminStudio and InstallShield ActiveX function call access attempt (more info ...)attempted-user    URL
24281BROWSER-PLUGINS Cisco Secure Desktop CSDWebInstaller ActiveX clsid access (more info ...)attempted-user 2011-0926 46536  
24282BROWSER-PLUGINS Cisco Secure Desktop CSDWebInstaller ActiveX function call access (more info ...)attempted-user 2011-0926 46536  
24293SERVER-OTHER EMC NetWorker SunRPC buffer overflow attempt (more info ...)attempted-admin 2012-2228   URL
24322BROWSER-PLUGINS EMC ApplicationXtender Desktop ActiveX function call attempt (more info ...)attempted-user 2012-2289   
24323BROWSER-PLUGINS EMC ApplicationXtender Desktop ActiveX function call attempt (more info ...)attempted-user 2012-2289   
24359OS-WINDOWS Microsoft Windows SMB NTLM NULL session attempt (more info ...)attempted-recon 2000-0347 1163  
24465FILE-IDENTIFY Microsoft Windows WMF file magic detected (more info ...)misc-activity    URL
24485FILE-PDF Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt (more info ...)attempted-admin 2010-2862   URL
24486FILE-PDF Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt (more info ...)attempted-admin 2010-2862   URL
24487FILE-PDF Microsoft Windows kernel-mode drivers core font parsing integer overflow attempt (more info ...)attempted-admin 2010-2862 42203  URL
24488OS-WINDOWS Microsoft Windows CryptoAPI common name spoofing attempt (more info ...)misc-attack 2009-2510   URL
24489OS-WINDOWS Microsoft Windows CryptoAPI common name spoofing attempt (more info ...)misc-attack 2009-2510   URL
24490OS-WINDOWS Microsoft Windows CryptoAPI common name spoofing attempt (more info ...)misc-attack 2009-2510   URL
24522SERVER-OTHER VxWorks RPC request to MGCP service attempt (more info ...)denial-of-service    
24535FILE-OTHER Microsoft Windows Embedded Open Type Font malformed name table integer overflow attempt (more info ...)attempted-user 2009-0232   URL
24559BROWSER-PLUGINS CYME Power Engineering ShowPropertiesDialog ActiveX clsid access (more info ...)attempted-user    
24560BROWSER-PLUGINS CYME Power Engineering ShowPropertiesDialog ActiveX function call access (more info ...)attempted-user    
24578BROWSER-PLUGINS Viscom Movie Player Pro DrawText ActiveX clsid access (more info ...)attempted-user 2010-0356 40719  
24579BROWSER-PLUGINS Viscom Movie Player Pro DrawText ActiveX function call access (more info ...)attempted-user 2010-0356 40719  
24643BROWSER-PLUGINS Tom Sawyer GET extension ActiveX function call access attempt (more info ...)attempted-user 2011-2217   
24644BROWSER-PLUGINS Tom Sawyer GET extension ActiveX clsid access attempt (more info ...)attempted-user 2011-2217   
24645BROWSER-PLUGINS Tom Sawyer GET extension ActiveX clsid access attempt (more info ...)attempted-user 2011-2217   
24646BROWSER-PLUGINS Tom Sawyer GET extension ActiveX clsid access attempt (more info ...)attempted-user 2011-2217   
24652FILE-OTHER Microsoft proxy autoconfig script system library import attempt (more info ...)policy-violation 2012-4776 56463  URL
24655OS-WINDOWS Microsoft .NET fully qualified System.Data.dll assembly name exploit attempt (more info ...)attempted-user 2012-2519   URL
24656OS-WINDOWS Microsoft .NET fully qualified System.Data.dll assembly name exploit attempt (more info ...)attempted-user 2012-2519   URL
24689BROWSER-PLUGINS Tom Sawyer GET extension ActiveX function call access attempt (more info ...)attempted-user 2011-2217   
24690BROWSER-PLUGINS Tom Sawyer GET extension ActiveX clsid access attempt (more info ...)attempted-user 2011-2217   
24691BROWSER-PLUGINS Tom Sawyer GET extension ActiveX clsid access attempt (more info ...)attempted-user 2011-2217   
24692BROWSER-PLUGINS Tom Sawyer GET extension ActiveX clsid access attempt (more info ...)attempted-user 2011-2217   
24773BROWSER-PLUGINS IBM Lotus iNotes Attachement_Times ActiveX clsid access (more info ...)attempted-user 2012-2175 53879  URL
24774BROWSER-PLUGINS ASUS Net4Switch ipswcom.dll ActiveX clsid access attempt (more info ...)attempted-user 2012-4924   
24775BROWSER-PLUGINS ASUS Net4Switch ipswcom.dll ActiveX clsid access attempt (more info ...)attempted-user 2012-4924   
24776BROWSER-PLUGINS ASUS Net4Switch ipswcom.dll ActiveX clsid access attempt (more info ...)attempted-user 2012-4924   
24777BROWSER-PLUGINS ASUS Net4Switch ipswcom.dll ActiveX clsid access attempt (more info ...)attempted-user 2012-4924   
25004BROWSER-PLUGINS ClearQuest session ActiveX control access (more info ...)attempted-user 2012-0708   
25005BROWSER-PLUGINS ClearQuest session ActiveX control access (more info ...)attempted-user 2012-0708   
25035BROWSER-PLUGINS Microsoft Silverlight inheritance restriction bypass (more info ...)attempted-user 2011-1253   URL
25060INDICATOR-OBFUSCATION ActiveX multiple adjacent object tags (more info ...)misc-attack    URL
25111BROWSER-PLUGINS Oracle SetMarkupMode buffer overflow ActiveX clsid access attempt (more info ...)attempted-user 2012-0549   
25112BROWSER-PLUGINS Oracle SetMarkupMode buffer overflow ActiveX function call access attempt (more info ...)attempted-user 2012-0549   
25113BROWSER-PLUGINS Oracle SetMarkupMode buffer overflow ActiveX function call access attempt (more info ...)attempted-user 2012-0549   
25114BROWSER-PLUGINS Oracle SetMarkupMode buffer overflow ActiveX function call access attempt (more info ...)attempted-user 2012-0549   
25115BROWSER-PLUGINS Oracle SetMarkupMode buffer overflow ActiveX clsid access attempt (more info ...)attempted-user 2012-0549   
25116BROWSER-PLUGINS Oracle SetMarkupMode buffer overflow ActiveX function call access attempt (more info ...)attempted-user 2012-0549   
25117BROWSER-PLUGINS Oracle SetMarkupMode buffer overflow ActiveX function call access attempt (more info ...)attempted-user 2012-0549   
25118BROWSER-PLUGINS Oracle SetMarkupMode buffer overflow ActiveX function call access attempt (more info ...)attempted-user 2012-0549   
25252FILE-EXECUTABLE Microsoft Windows .NET Framework System.Uri.ReCreateParts System.Uri.PathAndQuery overflow attempt (more info ...)attempted-user 2012-0015   URL
25273SERVER-WEBAPP Microsoft SCOM Web Console cross-site scripting attempt (more info ...)attempted-user 2013-0010   URL
25343BROWSER-PLUGINS Citrix Access Gateway plug-in ActiveX code execution attempt (more info ...)attempted-user 2011-2882 48676  URL
25344BROWSER-PLUGINS Citrix Access Gateway plug-in ActiveX code execution attempt (more info ...)attempted-user 2011-2882 48676  URL
25502FILE-MULTIMEDIA Microsoft GDI EMF malformed file buffer overflow attempt (more info ...)attempted-user 2008-3012   URL
25567OS-WINDOWS Microsoft Windows Remote Desktop web access cross site scripting attempt - POST request (more info ...)web-application-attack 2011-1263   URL
26165SERVER-WEBAPP Microsoft SharePoint Server directory traversal attempt (more info ...)attempted-admin 2013-0084   URL
26166SERVER-WEBAPP Microsoft SharePoint Server directory traversal attempt (more info ...)attempted-admin 2013-0084   URL
26167SERVER-WEBAPP Microsoft SharePoint Server directory traversal attempt (more info ...)attempted-admin 2013-0084   URL
26181BROWSER-PLUGINS Samsung NET-i viewer BackupToAvi ActiveX clsid access attempt (more info ...)attempted-user 2012-4333 53193  
26187BROWSER-PLUGINS McAfee Virtual Technician Security Bypass ActiveX clsid access attempt (more info ...)attempted-user 2012-4598 53304  
26241BROWSER-PLUGINS ActivePDF WebGrabber APWebGrb.ocx ActiveX function call access attempt (more info ...)attempted-user    
26321NETBIOS SMB named pipe bruteforce attempt (more info ...)attempted-recon    URL
26364BROWSER-PLUGINS Microsoft Windows RDP ActiveX component mstscax use after free attempt (more info ...)attempted-user 2013-1302 58874  URL
26378BROWSER-PLUGINS Viscom Software Image Viewer ActiveX function call access (more info ...)attempted-user 2010-5193   URL
26385FILE-EXECUTABLE Microsoft Windows executable file save onto SMB share attempt (more info ...)policy-violation    
26393BROWSER-PLUGINS Microsoft Windows Messenger ActiveX function call access (more info ...)attempted-user 2011-1243   URL
26497BROWSER-PLUGINS Siemens SIMATIC WinCC RegReader ActiveX vulnerable function access attempt (more info ...)attempted-user 2013-0674   
26498BROWSER-PLUGINS Siemens SIMATIC WinCC RegReader ActiveX vulnerable function access attempt (more info ...)attempted-user 2013-0674   
26543BROWSER-PLUGINS SafeNet ActiveX clsid access (more info ...)attempted-user 2007-0348 23071  URL
26544BROWSER-PLUGINS SafeNet ActiveX clsid access (more info ...)attempted-user 2007-0348 23071  URL
26545BROWSER-PLUGINS SafeNet ActiveX clsid access (more info ...)attempted-user 2007-0348 23071  URL
26546BROWSER-PLUGINS SafeNet ActiveX clsid access (more info ...)attempted-user 2007-0348 23071  URL
26573BROWSER-PLUGINS Honeywell HscRemoteDeploy ActiveX control arbitrary HTA execution attempt (more info ...)attempted-user 2013-0108 58134  
26574BROWSER-PLUGINS Honeywell HscRemoteDeploy ActiveX control arbitrary HTA execution attempt (more info ...)attempted-user 2013-0108 58134  
26590FILE-EXECUTABLE Microsoft Windows Authenticode signature verification bypass attempt (more info ...)attempted-user 2010-0151   URL
26601FILE-EXECUTABLE Microsoft Windows Authenticode signature verification bypass attempt (more info ...)attempted-user 2010-0151   URL
26622BROWSER-IE Microsoft Windows Live Writer wlw protocol handler information disclosure attempt (more info ...)attempted-recon 2013-0096   URL
26623BROWSER-IE Microsoft Windows Live Writer wlw protocol handler information disclosure attempt (more info ...)attempted-recon 2013-0096   URL
26632SERVER-WEBAPP Microsoft Windows 2012 Server additional empty Accept-Encoding field denial of service attempt (more info ...)attempted-dos 2013-1305   URL
26648FILE-OTHER Microsoft Windows uniscribe fonts parsing memory corruption attempt (more info ...)attempted-user 2010-2738 43068  URL
26649FILE-OTHER Microsoft Windows uniscribe fonts parsing memory corruption attempt (more info ...)attempted-user 2010-2738 43068  URL
26682BROWSER-PLUGINS Oracle JRE Deployment Toolkit ActiveX clsid access attempt (more info ...)attempted-user 2010-1423 39346  
26877OS-WINDOWS Microsoft Windows TCPRecomputeMss denial of service attempt (more info ...)attempted-dos 2013-3138   URL
26909FILE-IMAGE Microsoft Windows WMF denial of service attempt (more info ...)web-application-attack 2006-4071 21992  
26922OS-WINDOWS Microsoft Windows FlattenPath paged memory consumption privilege escalation attempt (more info ...)attempted-admin 2013-3660   URL
26975BROWSER-PLUGINS Aurigma Image uploader ActiveX function call access attempt (more info ...)attempted-user  26537  URL
27111BROWSER-PLUGINS PcVue SVUIGrd.ocx ActiveX clsid access (more info ...)attempted-user 2008-4915 49795  
27112BROWSER-PLUGINS PcVue SVUIGrd.ocx ActiveX function call access (more info ...)attempted-user 2008-4915 49795  
27166FILE-OTHER Microsoft Windows HLP File Handling heap overflow attempt (more info ...)attempted-user 2007-1912 23382  
27167FILE-OTHER Microsoft Windows HLP File Handling heap overflow attempt (more info ...)attempted-user 2007-1912 23382  
27168FILE-OTHER Microsoft Windows HLP File Handling heap overflow attempt (more info ...)attempted-user 2007-1912 23382  
27174BROWSER-PLUGINS Chilkat Socket ActiveX clsid access (more info ...)misc-attack 2008-6959 32333  
27175BROWSER-PLUGINS Chilkat Socket ActiveX clsid access (more info ...)misc-attack 2008-6959 32333  
27176BROWSER-PLUGINS Chilkat Socket ActiveX clsid access (more info ...)misc-attack 2008-6959 32333  
27177BROWSER-PLUGINS Chilkat Socket ActiveX clsid access (more info ...)misc-attack 2008-6959 32333  
27206BROWSER-PLUGINS SigPlus Pro ActiveX clsid access (more info ...)misc-attack    
27207BROWSER-PLUGINS SigPlus Pro ActiveX clsid access (more info ...)misc-attack    
27208BROWSER-PLUGINS Symantec WinFax Pro ActiveX heap buffer overflow attempt (more info ...)attempted-user 2009-2570 34766  URL
27219BROWSER-PLUGINS DB Software Laboratory VImpX activex control ActiveX clsid access attempt (more info ...)attempted-user 2008-4750 31907  
27223BROWSER-PLUGINS Oracle document capture Actbar2.ocx ActiveX clsid access attempt (more info ...)attempted-user 2010-3591   
27231OS-WINDOWS Microsoft Windows FlattenPath paged memory consumption privilege escalation attempt (more info ...)attempted-admin 2013-3660   URL
27234SERVER-OTHER Microsoft Active Directory LDAP search denial of service attempt (more info ...)denial-of-service 2013-1282   URL
27251FILE-OTHER Microsoft Windows Embedded Open Type Font malformed name table platform type 3 integer overflow attempt (more info ...)attempted-user 2009-0232   URL
27282BROWSER-PLUGINS PPMate PPMPlayer.dll ActiveX clsid access (more info ...)attempted-user 2008-3242 30246  URL
27283BROWSER-PLUGINS PPMate PPMPlayer.dll ActiveX clsid access (more info ...)attempted-user 2008-3242 30246  URL
27570BROWSER-PLUGINS CEnroll.CEnroll.2 ActiveX function stringtoBinary access attempt (more info ...)attempted-user 2006-3899 19102  
27597BROWSER-PLUGINS Morovia Barcode ActiveX Professional arbitrary file overwrite attempt (more info ...)attempted-user 2007-2644 23934  
27609POLICY-OTHER Microsoft ADFS endpoint information disclosure attempt (more info ...)misc-activity 2013-3185   URL
27718OS-WINDOWS Microsoft Windows malformed shortcut file buffer overflow attempt (more info ...)attempted-user 2005-2122 15070  URL
27719OS-WINDOWS Microsoft Windows malformed shortcut file with comment buffer overflow attempt (more info ...)attempted-user 2005-2122 15070  URL
27742BROWSER-PLUGINS EasyMail Objects Activex remote buffer overflow attempt (more info ...)attempted-user 2008-6447 32722  
27743BROWSER-PLUGINS EasyMail Objects Activex remote buffer overflow attempt (more info ...)attempted-user 2008-6447 32722  
27744BROWSER-PLUGINS BaoFeng Storm ActiveX control OnBeforeVideoDownload method buffer overflow attempt (more info ...)web-application-attack 2009-1612 34789  
27745BROWSER-PLUGINS BaoFeng Storm ActiveX control SetAttributeValue method buffer overflow attempt (more info ...)web-application-attack 2009-1807 34869  
27757BROWSER-PLUGINS Microsoft Visual Studio Msmask32 ActiveX clsid access (more info ...)attempted-user 2008-3704 30674  URL
27758BROWSER-PLUGINS Microsoft Visual Studio Msmask32 ActiveX function call access (more info ...)attempted-user 2008-3704 30674  URL
27763BROWSER-PLUGINS Husdawg System Requirements Lab Control ActiveX clsid access (more info ...)attempted-user 2008-4385 31752  URL
27767BROWSER-PLUGINS Icona SpA C6 Messenger Downloader ActiveX clsid access (more info ...)attempted-user 2008-2551 29519  
27768BROWSER-PLUGINS Icona SpA C6 Messenger Downloader ActiveX clsid access (more info ...)attempted-user 2008-2551 29519  
27781BROWSER-PLUGINS Cisco WebEx Meeting Manager atucfobj ActiveX clsid access (more info ...)attempted-user 2008-3558 30578  URL
27782BROWSER-PLUGINS Cisco WebEx Meeting Manager atucfobj ActiveX function call access (more info ...)attempted-user 2008-3558 30578  URL
27788BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX function call access (more info ...)attempted-user 2008-2463 30114  URL
27789BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX clsid access attempt (more info ...)attempted-user 2008-2463 30114  URL
27790BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX clsid access attempt (more info ...)attempted-user 2008-2463 30114  URL
27791BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX clsid access attempt (more info ...)attempted-user 2008-2463 30114  URL
27792BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX function call access attempt (more info ...)attempted-user 2008-2463 30114  URL
27793BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX function call access (more info ...)attempted-user 2008-2463 30114  URL
27794BROWSER-PLUGINS Black Ice Barcode SDK ActiveX clsid access (more info ...)attempted-user 2008-2684 29579  
27795BROWSER-PLUGINS Black Ice Barcode SDK ActiveX function call access (more info ...)attempted-user 2008-2684 29579  
27818SERVER-OTHER Microsoft SharePoint denial of service attempt (more info ...)web-application-attack 2013-0081   URL
27819SERVER-OTHER Microsoft SharePoint denial of service attempt (more info ...)web-application-attack 2013-0081   URL
27826SERVER-WEBAPP Microsoft SharePoint self cross site scripting attempt (more info ...)web-application-attack 2013-3180   URL
27827SERVER-WEBAPP Microsoft SharePoint self cross site scripting attempt (more info ...)web-application-attack 2013-3180   URL
27828SERVER-WEBAPP Microsoft SharePoint self cross site scripting attempt (more info ...)web-application-attack 2013-3180   URL
27860OS-WINDOWS Microsoft Windows Active Directory LDAP denial of service attempt (more info ...)attempted-dos 2013-3868   URL
28126BROWSER-PLUGINS WibuKey Runtime ActiveX clsid access (more info ...)attempted-user    
28127BROWSER-PLUGINS WibuKey Runtime ActiveX function call access (more info ...)attempted-user    
28161FILE-OTHER Microsoft .NET XML digital signature denial of service attempt (more info ...)attempted-user 2013-3860   URL
28162FILE-OTHER Microsoft .NET XML digital signature denial of service attempt (more info ...)attempted-user 2013-3860   URL
28201SERVER-OTHER Microsoft SharePoint XSS attempt (more info ...)attempted-admin 2013-3895   URL
28228SERVER-WEBAPP Microsoft Interactive Training buffer overflow attempt (more info ...)attempted-user 2006-3448 13944 18492 URL
28349BROWSER-PLUGINS Microsoft Windows WMI administrator tools object viewer ActiveX clsid access (more info ...)attempted-user 2010-4588 45546  URL
28350BROWSER-PLUGINS Microsoft Windows WMI administrator tools object viewer ActiveX clsid access (more info ...)attempted-user 2010-4588 45546  URL
28351BROWSER-PLUGINS Microsoft Windows WMI administrator tools object viewer ActiveX clsid access (more info ...)attempted-user 2010-4588 45546  URL
28386OS-WINDOWS Microsoft Windows HTML Help security zone bypass attempt (more info ...)attempted-user 2004-1043 11467  URL
28387OS-WINDOWS Microsoft Windows HTML Help security zone bypass attempt (more info ...)attempted-user 2004-1043 11467  URL
28435BROWSER-PLUGINS IBM SPSS SamplePower ActiveX clsid access attempt (more info ...)attempted-user 2014-0895 66116  
28437BROWSER-PLUGINS IBM SPSS SamplePower ActiveX function call access attempt (more info ...)attempted-user 2012-5947 59556  
28438BROWSER-PLUGINS IBM SPSS SamplePower ActiveX function call access attempt (more info ...)attempted-user 2012-5947 59556  
28749BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28750BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28751BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28752BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28753BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28754BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28755BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28756BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28757BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28758BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28759BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28760BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28761BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28762BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28763BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28764BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28765BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28766BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28767BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28768BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28769BROWSER-PLUGINS Novell GroupWise ActiveX clsid access attempt (more info ...)attempted-user 2012-0439   
28770BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28771BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28772BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28773BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28774BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28775BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28776BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28777BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28778BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28779BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28780BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28781BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28782BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28783BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28784BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28785BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28786BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28787BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28788BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28789BROWSER-PLUGINS Novell GroupWise ActiveX function call access attempt (more info ...)attempted-user 2012-0439   
28867OS-WINDOWS Microsoft Windows NDProxy.sys privilege escalation attempt (more info ...)attempted-admin 2013-5065 63971  URL
28868OS-WINDOWS Microsoft Windows NDProxy.sys privilege escalation attempt (more info ...)attempted-admin 2013-5065 63971  URL
28869OS-WINDOWS Microsoft Windows NDProxy.sys privilege escalation attempt (more info ...)attempted-admin 2013-5065 63971  URL
28870OS-WINDOWS Microsoft Windows NDProxy.sys privilege escalation attempt (more info ...)attempted-admin 2013-5065 63971  URL
28871OS-WINDOWS Microsoft Windows NDProxy.sys privilege escalation attempt (more info ...)attempted-admin 2013-5065 63971  URL
28872OS-WINDOWS Microsoft Windows NDProxy.sys privilege escalation attempt (more info ...)attempted-admin 2013-5065 63971  URL
28920BROWSER-IE Microsoft Windows showHelp CHM malicious file execution attempt (more info ...)attempted-admin 2003-1041 9320  URL
28921BROWSER-IE Microsoft Windows showHelp CHM malicious file execution attempt (more info ...)attempted-admin 2003-1041 9320  URL
28922BROWSER-IE Microsoft Windows showHelp CHM malicious file execution attempt (more info ...)attempted-admin 2003-1041 9320  URL
28923BROWSER-IE Microsoft Windows showHelp CHM malicious file execution attempt (more info ...)attempted-admin 2003-1041 9320  URL
28924BROWSER-IE Microsoft Windows showHelp CHM malicious file execution attempt (more info ...)attempted-admin 2003-1041 9320  URL
28925BROWSER-IE Microsoft Windows showHelp CHM malicious file execution attempt (more info ...)attempted-admin 2003-1041 9320  URL
28946SERVER-WEBAPP Microsoft Sharepoint server callback function cross-site scripting attempt (more info ...)attempted-user 2013-0080 58371  
29014OS-WINDOWS Microsoft Windows embedded OpenType font engine LZX decompression buffer overflow attempt (more info ...)attempted-admin 2010-0018 37671  URL
29092BROWSER-PLUGINS ABB Test Signal Viewer CWGraph3D ActiveX clsid access attempt (more info ...)attempted-user 2013-5022 61828  
29098BROWSER-PLUGINS HP Application Lifecycle Management XGO.XGoCtrl ActiveX access attempt (more info ...)attempted-user  55272  
29100BROWSER-PLUGINS HP Application Lifecycle Management XGO.XGoCtrl ActiveX clsid access attempt (more info ...)attempted-user  55272  
29102BROWSER-PLUGINS HP Application Lifecycle Management XGO.XGoCtrl ActiveX access attempt (more info ...)attempted-user  55272  
29224BROWSER-PLUGINS Microsoft Common Browser Architecture ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29225BROWSER-PLUGINS Microsoft HTML Window Security Proxy ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29258BROWSER-PLUGINS Microsoft WBEM Event Subsystem ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29405FILE-IDENTIFY Microsoft Internet Shortcut file attachment detected (more info ...)misc-activity    
29406FILE-IDENTIFY Microsoft Internet Shortcut file attachment detected (more info ...)misc-activity    
29407FILE-IDENTIFY Microsoft Internet Shortcut file download request (more info ...)misc-activity    
29581SERVER-OTHER CA Brightstor SUN RPC malformed string buffer overflow attempt (more info ...)attempted-admin 2007-2139 23635  
29680BROWSER-PLUGINS Microsoft XML Core Services same origin policy bypass attempt (more info ...)attempted-recon 2014-0266   URL
29681BROWSER-PLUGINS Microsoft XML Core Services same origin policy bypass attempt (more info ...)attempted-recon 2014-0266   URL
29749BROWSER-PLUGINS IBM SizerOne ActiveX clsid access attempt (more info ...)attempted-user 2012-5946 33148  
29823OS-WINDOWS Microsoft Windows secure channel malformed certificate request memory corruption attempt (more info ...)attempted-dos 2010-2566 42246  URL
29914MALWARE-CNC Win.Trojan.Zmcwinsvc outbound system information disclosure (more info ...)trojan-activity    URL
30209SERVER-WEBAPP Microsoft Forefront Unified Access Gateway null session cookie denial of service (more info ...)attempted-user 2011-2012   URL
30232OS-WINDOWS Microsoft Anti-Cross Site Scripting library bypass attempt (more info ...)attempted-user 2012-0007   URL
30233OS-WINDOWS Microsoft Anti-Cross Site Scripting library bypass attempt (more info ...)attempted-user 2012-0007   URL
30898FILE-OTHER Microsoft Windows Briefcase integer underflow (more info ...)attempted-user 2012-1527   URL
30939FILE-EXECUTABLE Microsoft Windows NtUserMessageCall implementation exploitation attempt (more info ...)attempted-user 2013-1300   URL
30940FILE-EXECUTABLE Microsoft Windows NtUserMessageCall implementation exploitation attempt (more info ...)attempted-user 2013-1300   URL
30951SERVER-WEBAPP Microsoft Sharepoint cross site scripting attempt (more info ...)attempted-user 2014-1754   URL
31081MALWARE-CNC Win.Trojan.WinSpy variant outbound connection (more info ...)trojan-activity    URL
31217OS-WINDOWS Microsoft Lync Server meeting URL XSS attempt (more info ...)web-application-attack 2014-1823   URL
31333BROWSER-PLUGINS IBM iNotes version 8.5 ActiveX clsid access (more info ...)attempted-user 2013-3027   
31334BROWSER-PLUGINS IBM iNotes version 8.5 ActiveX clsid access (more info ...)attempted-user 2013-3027   
31335BROWSER-PLUGINS IBM iNotes version 9 ActiveX clsid access (more info ...)attempted-user 2013-3027   
31336BROWSER-PLUGINS IBM iNotes version 9 ActiveX clsid access (more info ...)attempted-user 2013-3027   
31429SERVER-WEBAPP Microsoft Sharepoint server callback function cross-site scripting attempt (more info ...)attempted-user 2013-0080 58371  
31538BROWSER-PLUGINS UltraCrypto ActiveX clsid access attempt (more info ...)attempted-user 2007-4903   
31539BROWSER-PLUGINS UltraCrypto ActiveX clsid access attempt (more info ...)attempted-user 2007-4903   
31650SERVER-MAIL Microsoft Windows Mail file execution attempt (more info ...)attempted-user 2007-1658   URL
31707BROWSER-PLUGINS IBiz EBanking Integrator ActiveX clsid access (more info ...)attempted-user 2008-1725 28700  
31719FILE-IMAGE Microsoft Multiple Products JPEG parser heap overflow attempt (more info ...)attempted-user 2004-0200 11173  URL
31914SERVER-WEBAPP Microsoft ASP.NET null byte injection attempt (more info ...)web-application-attack 2007-0042 24791  URL
32102BROWSER-PLUGINS Oracle WebCenter Content CheckOutAndOpen.dll ActiveX control code execution ActiveX clsid access (more info ...)attempted-user 2013-1559 59122  URL
32103BROWSER-PLUGINS Oracle WebCenter Content CheckOutAndOpen.dll ActiveX control code execution ActiveX clsid access (more info ...)attempted-user 2013-1559 59122  URL
32104BROWSER-PLUGINS Oracle WebCenter Content CheckOutAndOpen.dll ActiveX control code execution ActiveX function call access (more info ...)attempted-user 2013-1559 59122  URL
32105BROWSER-PLUGINS Oracle WebCenter Content CheckOutAndOpen.dll ActiveX control code execution ActiveX function call access (more info ...)attempted-user 2013-1559 59122  URL
32114SERVER-OTHER Cisco ASA SunRPC inspection engine denial of service attempt (more info ...)attempted-dos 2014-3387   
32141OS-WINDOWS Microsoft Windows 7 TrackPopupMenu code execution attempt (more info ...)attempted-admin 2014-4113   URL
32142OS-WINDOWS Microsoft Windows 7 TrackPopupMenu code execution attempt (more info ...)attempted-admin 2014-4113   URL
32143OS-WINDOWS Microsoft Windows 7 TrackPopupMenu code execution attempt (more info ...)attempted-admin 2014-4113   URL
32144OS-WINDOWS Microsoft Windows 7 TrackPopupMenu code execution attempt (more info ...)attempted-admin 2014-4113   URL
32145OS-WINDOWS Microsoft Windows 7 TrackPopupMenu code execution attempt (more info ...)attempted-admin 2014-4113   URL
32146OS-WINDOWS Microsoft Windows 7 TrackPopupMenu code execution attempt (more info ...)attempted-admin 2014-4113   URL
32264BROWSER-IE ActiveX installer broker object sandbox escape attempt (more info ...)attempted-user 2014-4123   URL
32265BROWSER-IE ActiveX installer broker object sandbox escape attempt (more info ...)attempted-user 2014-4123   URL
32489OS-WINDOWS Microsoft Windows tcpip.sys null pointer dereference attempt (more info ...)attempted-admin 2014-4076   URL
32490OS-WINDOWS Microsoft Windows tcpip.sys null pointer dereference attempt (more info ...)attempted-admin 2014-4076   URL
32615OS-WINDOWS Microsoft Windows search protocol remote command injection attempt (more info ...)attempted-user 2008-4269   URL
32616FILE-IDENTIFY Microsoft Windows Registry file attachment detected (more info ...)misc-activity    URL
32617FILE-IDENTIFY Microsoft Windows Registry file attachment detected (more info ...)misc-activity    URL
32618FILE-IDENTIFY Microsoft Windows Registry file download request (more info ...)misc-activity    URL
32631NETBIOS SMB server response heap overflow attempt (more info ...)attempted-user 2008-1105 29404  
32633BROWSER-PLUGINS Oracle Data Quality ActiveX function call access (more info ...)attempted-user 2014-2418   URL
32634BROWSER-PLUGINS Oracle Data Quality ActiveX clsid access (more info ...)attempted-user 2014-2418   URL
32635BROWSER-PLUGINS Oracle Data Quality ActiveX function call access (more info ...)attempted-user 2014-2418   URL
32828FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502   URL
32829FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502   URL
32830FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502   URL
32831FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502   URL
32832FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502   URL
32833FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502   URL
32841BROWSER-PLUGINS Microsoft Windows Messenger ActiveX clsid access (more info ...)attempted-user 2011-1243   URL
32864APP-DETECT I2P NetBIOS name resolution request attempt (more info ...)misc-activity    URL
32869OS-WINDOWS Microsoft Windows ShellExecute and IE7 snews url handling code execution attempt (more info ...)attempted-user 2007-3896 25945  URL
32870OS-WINDOWS Microsoft Windows ShellExecute and IE7 snews url handling code execution attempt (more info ...)attempted-user 2007-3896 25945  URL
32889FILE-IMAGE Microsoft and libpng multiple products PNG large image width overflow attempt (more info ...)attempted-user 2007-5503 11523  URL
32895BROWSER-PLUGINS HP Sprinter Tidestone ActiveX function call access attempt (more info ...)attempted-user 2014-2637   
32896BROWSER-PLUGINS HP Sprinter Tidestone ActiveX clsid access attempt (more info ...)attempted-user 2014-2637   
32897BROWSER-PLUGINS HP Sprinter Tidestone ActiveX function call access attempt (more info ...)attempted-user 2014-2637   
32943FILE-OTHER Microsoft SYmbolic LinK stack overflow attempt (more info ...)attempted-user 2011-1276 48161  URL
32965OS-WINDOWS Microsoft Windows identity token authorization bypass attempt (more info ...)attempted-admin 2015-0002   URL
32966OS-WINDOWS Microsoft Windows identity token authorization bypass attempt (more info ...)attempted-admin 2015-0002   URL
33013BROWSER-PLUGINS HP LoadRunner ActiveX clsid access attempt (more info ...)attempted-user 2013-2370   
33014BROWSER-PLUGINS HP LoadRunner ActiveX clsid access attempt (more info ...)attempted-user 2013-2370   
33044BROWSER-PLUGINS Microsoft Windows Visual Studio 6 PDWizard.ocx ActiveX clsid access attempt (more info ...)attempted-user 2007-4891 25638  
33045BROWSER-PLUGINS Microsoft Windows Visual Studio 6 PDWizard.ocx ActiveX function call access attempt (more info ...)attempted-user 2007-4891 25638  
33048OS-WINDOWS Microsoft Windows WebdavRedirector privilege escalation attempt (more info ...)attempted-user 2015-0011   URL
33049OS-WINDOWS Microsoft Windows WebdavRedirector privilege escalation attempt (more info ...)attempted-user 2015-0011   URL
33100BROWSER-PLUGINS PTC IsoView ActiveX clsid access attempt (more info ...)attempted-user 2014-9267 71491  
33101BROWSER-PLUGINS PTC IsoView ActiveX clsid access attempt (more info ...)attempted-user 2014-9267 71491  
33102BROWSER-PLUGINS PTC IsoView ActiveX clsid access attempt (more info ...)attempted-user 2014-9267 71491  
33103BROWSER-PLUGINS PTC IsoView ActiveX clsid access attempt (more info ...)attempted-user 2014-9267 71491  
33105BROWSER-PLUGINS Honeywell OPOS Suite Scanner.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8269 71642  
33106BROWSER-PLUGINS Honeywell OPOS Suite Scanner.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8269 71642  
33107BROWSER-PLUGINS Honeywell OPOS Suite Scanner.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8269 71642  
33108BROWSER-PLUGINS Honeywell OPOS Suite Scanner.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8269 71642  
33109BROWSER-PLUGINS Honeywell OPOS Suite Scale.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8269 71642  
33110BROWSER-PLUGINS Honeywell OPOS Suite Scale.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8269 71642  
33111BROWSER-PLUGINS Honeywell OPOS Suite Scale.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8269 71642  
33112BROWSER-PLUGINS Honeywell OPOS Suite Scale.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8269 71642  
33343OS-WINDOWS Microsoft Windows 8 x64 linked cursor double free attempt (more info ...)attempted-user 2015-0058   URL
33344OS-WINDOWS Microsoft Windows 8 x64 linked cursor double free attempt (more info ...)attempted-user 2015-0058   URL
33355OS-WINDOWS Microsoft Windows win32k.sys use-after-free attempt (more info ...)attempted-admin 2015-0057   URL
33363OS-WINDOWS Microsoft Windows WM_SYSTIMER null pWnd attempt (more info ...)attempted-admin 2015-0003   URL
33364OS-WINDOWS Microsoft Windows WM_SYSTIMER null pWnd attempt (more info ...)attempted-admin 2015-0003   URL
33429POLICY-OTHER Microsoft Windows SMB potential group policy fallback exploit attempt (more info ...)policy-violation 2015-0009   URL
33436FILE-OTHER Microsoft Windows True Type Font integer overflow attempt (more info ...)attempted-user 2015-0059   URL
33437FILE-OTHER Microsoft Windows True Type Font integer overflow attempt (more info ...)attempted-user 2015-0059   URL
33479OS-WINDOWS Microsoft Windows Comctl32.dll third-party SVG viewer heap overflow attempt (more info ...)attempted-user 2010-2746   URL
33515FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502 36646  URL
33516FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502 36646  URL
33517FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502 36646  URL
33518FILE-IMAGE Microsoft Windows GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user 2009-2502 36646  URL
33582SERVER-SAMBA Samba WINS Server Name Registration handling stack buffer overflow attempt (more info ...)attempted-user 2007-5398 26455  
33603FILE-OTHER Microsoft Windows Fax Services Cover Page Editor Double Free Memory Corruption attempt (more info ...)web-application-attack 2010-4701 45942  
33604FILE-OTHER Microsoft Windows Fax Services Cover Page Editor Double Free Memory Corruption attempt (more info ...)attempted-user 2010-4701 45942  
33636SERVER-OTHER SAP Sybase ESP xmlrpc unsafe pointer dereference attempt (more info ...)web-application-attack 2014-3457   
33713OS-WINDOWS Microsoft Windows atlmfd.dll out-of-bounds memory write attempt (more info ...)attempted-admin 2015-0091   URL
33714OS-WINDOWS Microsoft Windows atlmfd.dll out-of-bounds memory write attempt (more info ...)attempted-admin 2015-0091   URL
33717OS-WINDOWS Microsoft Windows Task Scheduler access control bypass attempt (more info ...)attempted-admin 2015-0084   URL
33732FILE-OTHER Microsoft OpenType font atlmfd.dll uninitialized memory read attempt (more info ...)attempted-admin 2015-0089   URL
33733FILE-OTHER Microsoft OpenType font atlmfd.dll uninitialized memory read attempt (more info ...)attempted-admin 2015-0089   URL
33740FILE-IMAGE Microsoft emf file download request (more info ...)misc-activity 2007-5746 9707  URL
33765OS-WINDOWS Microsoft Windows NtUserGetClipboardAccessToken privilege escalation attempt (more info ...)attempted-admin 2015-2527   URL
33766OS-WINDOWS Microsoft Windows NtUserGetClipboardAccessToken privilege escalation attempt (more info ...)attempted-admin 2015-2527   URL
33767OS-WINDOWS Microsoft Windows NtUserFnINOUTNCCALCSIZE kernel memory leak attempt (more info ...)attempted-user 2015-0094   URL
33768OS-WINDOWS Microsoft Windows NtUserFnINOUTNCCALCSIZE kernel memory leak attempt (more info ...)attempted-user 2015-0094   URL
33769OS-WINDOWS Microsoft Windows NtUserfnINSTRINGNULL memory leak kernel ASLR bypass attempt (more info ...)attempted-recon 2015-0077   URL
33770OS-WINDOWS Microsoft Windows NtUserfnINSTRINGNULL memory leak kernel ASLR bypass attempt (more info ...)attempted-recon 2015-0077   URL
33771FILE-OTHER Microsoft Windows jxr information disclosure attempt (more info ...)attempted-user 2015-0076   URL
33772FILE-OTHER Microsoft Windows jxr information disclosure attempt (more info ...)attempted-user 2015-0076   URL
33773OS-WINDOWS Microsoft Windows CmpGetVirtualizationID race condition user impersonation attempt (more info ...)attempted-user 2015-0073   URL
33774OS-WINDOWS Microsoft Windows CmpGetVirtualizationID race condition user impersonation attempt (more info ...)attempted-user 2015-0073   URL
33808SERVER-OTHER Microsoft Sharepoint Server Newsfeed XSS attempt (more info ...)web-application-attack 2015-1636   URL
33809SERVER-OTHER Microsoft Sharepoint user display name XSS attempt (more info ...)attempted-user 2015-1633   URL
33825OS-WINDOWS Microsoft Windows SMB NTLM NULL session attempt (more info ...)attempted-recon 2000-0347 1163  
33827OS-WINDOWS Microsoft XML Core Services MIME Viewer memory corruption attempt (more info ...)attempted-user 2007-0099   URL
33828OS-WINDOWS Microsoft XML Core Services MIME Viewer memory corruption attempt (more info ...)attempted-user 2007-0099   URL
33829OS-WINDOWS Microsoft XML Core Services MIME Viewer memory corruption attempt (more info ...)attempted-user 2007-0099   URL
34015BROWSER-PLUGINS Advantech WebAccess webeye.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8388 71193  
34016BROWSER-PLUGINS Advantech WebAccess webeye.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8388 71193  
34017BROWSER-PLUGINS Advantech WebAccess webeye.ocx ActiveX clsid access attempt (more info ...)attempted-user 2014-8388 71193  
34078FILE-EXECUTABLE Microsoft Windows DosDevices mapping privilege escalation attempt (more info ...)attempted-user 2015-1644   URL
34079FILE-EXECUTABLE Microsoft Windows DosDevices mapping privilege escalation attempt (more info ...)attempted-user 2015-1644   URL
34080FILE-EXECUTABLE Microsoft Windows DosDevices mapping privilege escalation attempt (more info ...)attempted-user 2015-1644   URL
34081FILE-EXECUTABLE Microsoft Windows DosDevices mapping privilege escalation attempt (more info ...)attempted-user 2015-1644   URL
34083FILE-OTHER Microsoft emf small header overwrite attempt (more info ...)attempted-user 2017-3052   URL
34091OS-WINDOWS Microsoft Windows Defender misconfiguration MpCmdRun.exe system execution attempt (more info ...)attempted-admin 2015-0098   URL
34092OS-WINDOWS Microsoft Windows Defender misconfiguration MpCmdRun.exe system execution attempt (more info ...)attempted-admin 2015-0098   URL
34095OS-WINDOWS Microsoft Windows NtCreateTransactionManager type confusion attempt (more info ...)attempted-admin 2015-1643   URL
34096OS-WINDOWS Microsoft Windows NtCreateTransactionManager type confusion attempt (more info ...)attempted-admin 2015-1643   URL
34099SERVER-OTHER Microsoft SharePoint projectdetails.aspx ret parameter XSS attempt (more info ...)attempted-user 2015-1640   URL
34135FILE-IMAGE Microsoft Kodak Imaging small offset malformed tiff - little-endian (more info ...)attempted-user 2007-2217   URL
34293FILE-IMAGE Microsoft Windows wmf integer overflow attempt (more info ...)web-application-attack 2007-3034 25302  URL
34294FILE-IMAGE Microsoft Windows wmf integer overflow attempt (more info ...)web-application-attack 2007-3034 25302  URL
34298BROWSER-PLUGINS Microsoft Windows Trouble Shooter ActiveX object access (more info ...)attempted-user 2003-0662 8833  URL
34377OS-WINDOWS Microsoft Windows NtUserGetComboBoxInfo information disclosure attempt (more info ...)attempted-recon 2015-1678   URL
34378OS-WINDOWS Microsoft Windows NtUserGetComboBoxInfo information disclosure attempt (more info ...)attempted-recon 2015-1678   URL
34413OS-WINDOWS Microsoft Windows NtUserGetScrollBarInfo information disclosure attempt (more info ...)attempted-admin 2015-1677   URL
34414OS-WINDOWS Microsoft Windows NtUserGetScrollBarInfo information disclosure attempt (more info ...)attempted-admin 2015-1677   URL
34426OS-WINDOWS Microsoft Windows cng.sys memory leak kernel ASLR bypass attempt (more info ...)attempted-recon 2015-1674 74488  URL
34427OS-WINDOWS Microsoft Windows cng.sys memory leak kernel ASLR bypass attempt (more info ...)attempted-recon 2015-1674 74488  URL
34434OS-WINDOWS Microsoft Windows .NET XML recursive call denial of service attempt (more info ...)attempted-dos 2015-1672   URL
34435OS-WINDOWS Microsoft Windows .NET XML recursive call denial of service attempt (more info ...)attempted-dos 2015-1672   URL
34438OS-WINDOWS Microsoft Windows Explorer .msc file stack overflow attempt (more info ...)attempted-user 2015-1681   URL
34439OS-WINDOWS Microsoft Windows Explorer .msc file stack overflow attempt (more info ...)attempted-user 2015-1681   URL
34442OS-WINDOWS Microsoft Windows NTUserGetTitleBarInfo information disclosure attempt (more info ...)attempted-recon 2015-1676   URL
34443OS-WINDOWS Microsoft Windows NTUserGetTitleBarInfo information disclosure attempt (more info ...)attempted-recon 2015-1676   URL
34448BROWSER-PLUGINS WebGate WESPMonitor ActiveX clsid access attempt (more info ...)attempted-user 2015-2097   
34449BROWSER-PLUGINS WebGate WESPMonitor ActiveX clsid access attempt (more info ...)attempted-user 2015-2097   
34450BROWSER-PLUGINS WebGate WESPMonitor ActiveX clsid access attempt (more info ...)attempted-user 2015-2097   
34451BROWSER-PLUGINS WebGate WESPMonitor ActiveX clsid access attempt (more info ...)attempted-user 2015-2097   
34454BROWSER-PLUGINS WebGate WESPPlaybackCtrl ActiveX clsid access attempt (more info ...)attempted-user 2015-2094   
34456BROWSER-PLUGINS WebGate WESPPlaybackCtrl ActiveX clsid access attempt (more info ...)attempted-user 2015-2094   
34457BROWSER-PLUGINS WebGate WESPPlaybackCtrl ActiveX clsid access attempt (more info ...)attempted-user 2015-2094   
34498OS-WINDOWS Microsoft Windows Win32k.sys kernel-mode driver privilege escalation attempt (more info ...)attempted-admin 2015-1701   URL
34499OS-WINDOWS Microsoft Windows Win32k.sys kernel-mode driver privilege escalation attempt (more info ...)attempted-admin 2015-1701   URL
34530FILE-OTHER Microsoft CAB incorrect version multiple antivirus evasion attempt (more info ...)misc-attack 2012-1455   
34531FILE-OTHER Microsoft CAB incorrect version multiple antivirus evasion attempt (more info ...)misc-attack 2012-1455   
34565OS-WINDOWS Microsoft Windows Graphics engine EMF rendering vulnerability (more info ...)attempted-user 2005-2123 15352  
34566FILE-OTHER Microsoft Windows Font Library file buffer overflow attempt (more info ...)attempted-user 2011-2003   URL
34642BROWSER-PLUGINS McAfee Virtual Technician ActiveX clsid access attempt (more info ...)attempted-user 2012-5879   
34643BROWSER-PLUGINS Schneider Electric Pelco Rvctl.RVControl.1 ActiveX clsid access attempt ActiveX clsid access (more info ...)attempted-user 2015-0982   
34714OS-WINDOWS Microsoft Windows atlmfd.dll out-of-bounds memory write attempt (more info ...)attempted-admin 2015-0091   URL
34715OS-WINDOWS Microsoft Windows atlmfd.dll out-of-bounds memory write attempt (more info ...)attempted-admin 2015-0091   URL
34761OS-WINDOWS Microsoft Windows clipboard null pointer dereference privilege escalation attempt (more info ...)attempted-admin 2015-1721   URL
34762OS-WINDOWS Microsoft Windows clipboard null pointer dereference privilege escalation attempt (more info ...)attempted-admin 2015-1721   URL
34770OS-WINDOWS Microsoft Windows bitmap menu item use after free attempt (more info ...)attempted-admin 2015-1722   URL
34771OS-WINDOWS Microsoft Windows bitmap menu item use after free attempt (more info ...)attempted-admin 2015-1722   URL
34774OS-WINDOWS Microsoft Windows multiple linked fonts memory corruption attempt (more info ...)attempted-admin 2015-1768   URL
34775OS-WINDOWS Microsoft Windows multiple linked fonts memory corruption attempt (more info ...)attempted-admin 2015-1768   URL
34776OS-WINDOWS Microsoft Windows NtUserMessageCall information disclosure attempt (more info ...)attempted-recon 2015-1719   URL
34777OS-WINDOWS Microsoft Windows NtUserMessageCall information disclosure attempt (more info ...)attempted-recon 2015-1719   URL
34780FILE-OTHER Microsoft Windows device context visible region memory corruption attempt (more info ...)attempted-admin 2015-1725   URL
34781FILE-OTHER Microsoft Windows device context visible region memory corruption attempt (more info ...)attempted-admin 2015-1725   URL
34782OS-WINDOWS Microsoft Windows BrushAttributes use-after-free attempt (more info ...)attempted-admin 2015-1726   URL
34783OS-WINDOWS Microsoft Windows BrushAttributes use-after-free attempt (more info ...)attempted-admin 2015-1726   URL
34784OS-WINDOWS Microsoft Windows window placement invalid memory write attempt (more info ...)attempted-admin 2015-1727   URL
34785OS-WINDOWS Microsoft Windows window placement invalid memory write attempt (more info ...)attempted-admin 2015-1727   URL
34786FILE-OTHER Microsoft Windows device context memory corruption attempt (more info ...)attempted-admin 2015-1724   URL
34787FILE-OTHER Microsoft Windows device context memory corruption attempt (more info ...)attempted-admin 2015-1724   URL
34788OS-WINDOWS Microsoft Windows 8 CreateWindowEx privilege escalation attempt (more info ...)attempted-admin 2015-2360   URL
34789OS-WINDOWS Microsoft Windows 8 CreateWindowEx privilege escalation attempt (more info ...)attempted-admin 2015-2360   URL
34792OS-WINDOWS Microsoft Windows WM_SYSTIMER null pWnd attempt (more info ...)attempted-user 2015-0003   URL
34793OS-WINDOWS Microsoft Windows WM_SYSTIMER null pWnd attempt (more info ...)attempted-user 2015-0003   URL
34915NETBIOS SMB Corel PaintShop Pro quserex.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34916NETBIOS SMB Corel PaintShop Pro u32zlib.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34918BROWSER-PLUGINS Schneider Electric ProClima ActiveX clsid access (more info ...)attempted-user 2014-9188   
34919BROWSER-PLUGINS Schneider Electric ProClima ActiveX function call access (more info ...)attempted-user 2014-9188   
34920BROWSER-PLUGINS Schneider Electric ProClima ActiveX clsid access (more info ...)attempted-user 2014-9188   
34921BROWSER-PLUGINS Schneider Electric ProClima ActiveX function call access (more info ...)attempted-user 2014-9188   
34922BROWSER-PLUGINS Schneider Electric ProClima ActiveX function call access (more info ...)attempted-user 2014-9188   
34923BROWSER-PLUGINS Schneider Electric ProClima ActiveX function call access (more info ...)attempted-user 2014-9188   
34933OS-WINDOWS Microsoft Windows HSC DVD driver upgrade code execution attempt (more info ...)attempted-user 2004-0199 10321  URL
35094FILE-OTHER Microsoft proxy autoconfig script system library import attempt (more info ...)policy-violation 2012-4776 56463  URL
35105OS-WINDOWS Microsoft Windows ATMFD.dll open font type privilege escalation attempt (more info ...)attempted-admin 2015-2387   URL
35106OS-WINDOWS Microsoft Windows ATMFD.dll open font type privilege escalation attempt (more info ...)attempted-admin 2015-2387   URL
35107OS-WINDOWS Microsoft Windows ATMFD.dll open font type privilege escalation attempt (more info ...)attempted-admin 2015-2387   URL
35108OS-WINDOWS Microsoft Windows ATMFD.dll open font type privilege escalation attempt (more info ...)attempted-admin 2015-2387   URL
35112OS-WINDOWS Microsoft Windows clipboard null pointer dereference attempt (more info ...)attempted-admin 2015-1723 75009  URL
35113OS-WINDOWS Microsoft Windows clipboard null pointer dereference attempt (more info ...)attempted-admin 2015-1723 75009  URL
35131OS-WINDOWS Microsoft Windows NtUserDisableProcessWindowFiltering information disclosure attempt (more info ...)attempted-recon 2015-2367   URL
35132OS-WINDOWS Microsoft Windows NtUserDisableProcessWindowFiltering information disclosure attempt (more info ...)attempted-recon 2015-2367   URL
35135OS-WINDOWS Microsoft Windows DeferWindowPos access after release code injection attempt (more info ...)attempted-user 2015-2365   URL
35136OS-WINDOWS Microsoft Windows DeferWindowPos access after release code injection attempt (more info ...)attempted-user 2015-2365   URL
35149OS-WINDOWS Microsoft Windows desktop reference use after free attempt (more info ...)attempted-admin 2015-6171   URL
35150OS-WINDOWS Microsoft Windows desktop reference use after free attempt (more info ...)attempted-admin 2015-6171   URL
35174OS-WINDOWS DCOM DCE/RPC NTLM reflection elevation of privilege attempt (more info ...)attempted-admin 2015-2370   URL
35175OS-WINDOWS DCOM DCE/RPC NTLM reflection elevation of privilege attempt (more info ...)attempted-admin 2015-2370   URL
35327BROWSER-PLUGINS Agilent Technologies Feature Extraction ActiveX clsid access attempt (more info ...)attempted-user 2015-2092 72840  
35328BROWSER-PLUGINS Agilent Technologies Feature Extraction ActiveX clsid access attempt (more info ...)attempted-user 2015-2092 72840  
35329BROWSER-PLUGINS Agilent Technologies Feature Extraction ActiveX clsid access attempt (more info ...)attempted-user 2015-2092 72840  
35330BROWSER-PLUGINS Agilent Technologies Feature Extraction ActiveX clsid access attempt (more info ...)attempted-user 2015-2092 72840  
35350BROWSER-PLUGINS Oracle DcsXB onloadstatechange ActiveX clsid access attempt (more info ...)attempted-user 2014-2417   
35351BROWSER-PLUGINS Oracle DcsXB onloadstatechange ActiveX clsid access attempt (more info ...)attempted-user 2014-2417   
35352BROWSER-PLUGINS Oracle DcsXB onloadstatechange ActiveX clsid access attempt (more info ...)attempted-user 2014-2417   
35487OS-WINDOWS Microsoft Windows Notepad remote printer file access attempt (more info ...)attempted-recon 2015-2423   URL
35488OS-WINDOWS Microsoft Windows Notepad remote printer file access attempt (more info ...)attempted-recon 2015-2423   URL
35513OS-WINDOWS Microsoft Windows NtGdiGetTextMetricsW TEXTMETRICW kernel mode ASLR bypass attempt (more info ...)policy-violation 2015-2433   URL
35514OS-WINDOWS Microsoft Windows NtGdiGetTextMetricsW TEXTMETRICW kernel mode ASLR bypass attempt (more info ...)policy-violation 2015-2433   URL
35529FILE-OTHER Microsoft Windows malformed TTF table hmtx remote code execution attempt (more info ...)attempted-user 2015-2456   URL
35530FILE-OTHER Microsoft Windows malformed TTF table hmtx remote code execution attempt (more info ...)attempted-user 2015-2456   URL
35556BROWSER-PLUGINS Panasonic Security API SDK MulticastAddr ActiveX clsid access attempt (more info ...)attempted-user 2015-4648 75405  
35558BROWSER-PLUGINS Panasonic Security API SDK MulticastAddr ActiveX clsid access attempt (more info ...)attempted-user 2015-4648 75405  
35559BROWSER-PLUGINS Panasonic Security API SDK MulticastAddr ActiveX clsid access attempt (more info ...)attempted-user 2015-4648 75405  
35614BROWSER-PLUGINS NetIQ SafeShellExecute ActiveX clsid access attempt (more info ...)attempted-user 2015-0795   
35615BROWSER-PLUGINS NetIQ SafeShellExecute ActiveX clsid access attempt (more info ...)attempted-user 2015-0795   
35616BROWSER-PLUGINS NetIQ SafeShellExecute ActiveX clsid access attempt (more info ...)attempted-user 2015-0795   
35617BROWSER-PLUGINS NetIQ SafeShellExecute ActiveX clsid access attempt (more info ...)attempted-user 2015-0795   
35621BROWSER-PLUGINS Panasonic Security API SDK Ipropsapi ActiveX clsid access attempt (more info ...)attempted-user 2015-4647 75409  
35623BROWSER-PLUGINS Panasonic Security API SDK Ipropsapi ActiveX clsid access attempt (more info ...)attempted-user 2015-4647 75409  
35698BROWSER-PLUGINS Oracle Data Quality Trillium TSS12.LoaderWizard.lwctrl ActiveX clsid access attempt (more info ...)attempted-user 2015-4759 75806  
35699BROWSER-PLUGINS Oracle Data Quality Trillium TSS12.LoaderWizard.lwctrl ActiveX clsid access attempt (more info ...)attempted-user 2015-4759 75806  
35700BROWSER-PLUGINS Oracle Data Quality Trillium TSS12.LoaderWizard.lwctrl ActiveX clsid access attempt (more info ...)attempted-user 2015-4759 75806  
35858FILE-OTHER Microsoft System.Uri heap corruption attempt (more info ...)attempted-user 2015-4021 70351  URL
35883NETBIOS DCERPC NCACN-IP-TCP brightstor opcode 0x13 overflow attempt (more info ...)attempted-dos 2009-1761 35396  
35959BROWSER-IE Microsoft Edge DOMNode manipulation use after free attempt (more info ...)attempted-user 2015-2488   URL
35967BROWSER-IE Microsoft Edge sandbox CreateFileW arbitrary file delete attempt (more info ...)attempted-user 2015-2484   URL
35968BROWSER-IE Microsoft Edge sandbox CreateFileW arbitrary file delete attempt (more info ...)attempted-user 2015-2484   URL
35973OS-WINDOWS Microsoft Windows SURFACE objects kernel privilege escalation attempt (more info ...)attempted-admin 2015-2518   URL
35974OS-WINDOWS Microsoft Windows SURFACE objects kernel privilege escalation attempt (more info ...)attempted-admin 2015-2518   URL
35977OS-WINDOWS Microsoft Windows CreateObjectTask privilege escalation attempt (more info ...)policy-violation 2015-2528   URL
35978OS-WINDOWS Microsoft Windows CreateObjectTask privilege escalation attempt (more info ...)policy-violation 2015-2528   URL
35986OS-WINDOWS Microsoft Windows NtUserSetWindowsHook memory disclosure attempt (more info ...)attempted-recon 2015-2529   URL
35987OS-WINDOWS Microsoft Windows NtUserSetWindowsHook memory disclosure attempt (more info ...)attempted-recon 2015-2529   URL
35994OS-WINDOWS Microsoft Windows desktop window privilege escalation attempt (more info ...)attempted-admin 2015-2511   URL
35995OS-WINDOWS Microsoft Windows desktop window privilege escalation attempt (more info ...)attempted-admin 2015-2511   URL
36010OS-WINDOWS Microsoft Windows task scheduler race condition attempt (more info ...)attempted-admin 2015-2525   URL
36011OS-WINDOWS Microsoft Windows task scheduler race condition attempt (more info ...)attempted-admin 2015-2525   URL
36012OS-WINDOWS Microsoft Windows Kernel SettingsSyncDiagnostics privilege escalation attempt (more info ...)attempted-admin 2015-2524   URL
36013OS-WINDOWS Microsoft Windows Kernel SettingsSyncDiagnostics privilege escalation attempt (more info ...)attempted-admin 2015-2524   URL
36016OS-WINDOWS Microsoft Windows use after free kernel privilege escalation attempt (more info ...)attempted-admin 2015-2507   URL
36017OS-WINDOWS Microsoft Windows use after free kernel privilege escalation attempt (more info ...)attempted-admin 2015-2507   URL
36028OS-WINDOWS Microsoft Windows Win32k.sys use after free attempt (more info ...)attempted-admin 2015-2546   URL
36029OS-WINDOWS Microsoft Windows Win32k.sys use after free attempt (more info ...)attempted-admin 2015-2546   URL
36110BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven InterfaceFilter ActiveX clsid access (more info ...)attempted-user 2014-9208   URL
36117BROWSER-PLUGINS HP LoadRunner ActiveX clsid access attempt (more info ...)attempted-user 2013-2368   
36118BROWSER-PLUGINS HP LoadRunner ActiveX clsid access attempt (more info ...)attempted-user 2013-2368   
36119BROWSER-PLUGINS HP LoadRunner ActiveX clsid access attempt (more info ...)attempted-user 2013-2368   
36320BROWSER-PLUGINS Microsoft Input Method Editor 2 ActiveX clsid access attempt (more info ...)attempted-user 2006-4697   URL
36349BROWSER-PLUGINS Touch22 Software Image22 DrawIcon ActiveX clsid access attempt (more info ...)attempted-user  41547  
36350BROWSER-PLUGINS Touch22 Software Image22 DrawIcon ActiveX clsid access attempt (more info ...)attempted-user  41547  
36383OS-WINDOWS Microsoft Windows FlattenPath paged memory consumption privilege escalation attempt (more info ...)attempted-admin 2013-3660 60051  URL
36384OS-WINDOWS Microsoft Windows FlattenPath paged memory consumption privilege escalation attempt (more info ...)attempted-admin 2013-3660 60051  URL
36403OS-WINDOWS Microsoft Windows SepReferenceLowBoxObjects privilege escalation attempt (more info ...)attempted-admin 2015-2554   URL
36404OS-WINDOWS Microsoft Windows SepReferenceLowBoxObjects privilege escalation attempt (more info ...)attempted-admin 2015-2554   URL
36405OS-WINDOWS Microsoft Windows sandbox policy bypass attempt (more info ...)attempted-user 2015-2550   URL
36406OS-WINDOWS Microsoft Windows sandbox policy bypass attempt (more info ...)attempted-user 2015-2550   URL
36415OS-WINDOWS Microsoft Windows kernel ALPC synchronous requests memory corruption attempt (more info ...)attempted-admin 2015-2549   URL
36416OS-WINDOWS Microsoft Windows kernel ALPC synchronous requests memory corruption attempt (more info ...)attempted-admin 2015-2549   URL
36445OS-WINDOWS Microsoft Windows 10 low integrity level NTFS mount reparse point bypass attempt (more info ...)attempted-admin 2015-2553   URL
36446OS-WINDOWS Microsoft Windows 10 low integrity level NTFS mount reparse point bypass attempt (more info ...)attempted-admin 2015-2553   URL
36452BROWSER-IE Microsoft Edge cross site scripting filter bypass attempt (more info ...)attempted-user 2016-7280   URL
36474BROWSER-PLUGINS Advantech WebAccess AspVCObj.AspDataDriven ConvToSafeArray ActiveX clsid access (more info ...)attempted-user 2014-9208 76672  
36481BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36482BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36483BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36484BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36485BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36486BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36487BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36488BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36489BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36490BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36491BROWSER-PLUGINS Schneider Electric TeeChart ActiveX clsid access attempt (more info ...)attempted-user 2011-4034 50837  URL
36514BROWSER-PLUGINS X360 VideoPlayer ConvertFile ActiveX clsid access (more info ...)attempted-user    
36515BROWSER-PLUGINS X360 VideoPlayer SetText ActiveX clsid access (more info ...)attempted-user    
36516BROWSER-PLUGINS X360 VideoPlayer ConvertFile ActiveX clsid access (more info ...)attempted-user    
36517BROWSER-PLUGINS X360 VideoPlayer SetText ActiveX clsid access (more info ...)attempted-user    
36562OS-WINDOWS Microsoft Windows cng.sys memory leak kernel ASLR bypass attempt (more info ...)attempted-recon 2015-1674 74488  URL
36563OS-WINDOWS Microsoft Windows cng.sys memory leak kernel ASLR bypass attempt (more info ...)attempted-recon 2015-1674 74488  URL
36640BROWSER-PLUGINS Advantech WebAccess SCADA webdact.ocx AccessCode ActiveX clsid access attempt (more info ...)attempted-user 2014-0767 66728  
36647BROWSER-PLUGINS Oracle Hyperion Strategic Finance Client SetDevNames ActiveX clsid access attempt (more info ...)attempted-user 2011-5167   
36648BROWSER-PLUGINS Oracle Hyperion Strategic Finance Client SetDevNames ActiveX clsid access attempt (more info ...)attempted-user 2011-5167   
36663BROWSER-PLUGINS Advantech WebAccess SCADA ActiveX clsid access (more info ...)attempted-user 2014-0765 66722  
36664BROWSER-PLUGINS Advantech WebAccess SCADA ActiveX clsid access (more info ...)attempted-user 2014-0765 66722  
36665BROWSER-PLUGINS Advantech WebAccess SCADA ActiveX clsid access (more info ...)attempted-user 2014-0765 66722  
36718OS-WINDOWS Microsoft Windows win32k kernel memory information disclosure attempt (more info ...)attempted-recon 2015-6102   URL
36719OS-WINDOWS Microsoft Windows win32k kernel memory information disclosure attempt (more info ...)attempted-recon 2015-6102   URL
36744OS-WINDOWS Microsoft Windows NDIS.SYS driver buffer overflow attempt (more info ...)attempted-admin 2015-6098   URL
36745OS-WINDOWS Microsoft Windows NDIS.SYS driver buffer overflow attempt (more info ...)attempted-admin 2015-6098   URL
36792BROWSER-PLUGINS Microsoft Visual FoxPro ActiveX clsid access (more info ...)attempted-user 2007-5322 25977  
36804OS-WINDOWS Microsoft Windows wininet peerdistsvc.dll dll-load exploit attempt (more info ...)attempted-user 2010-3966   URL
36805OS-WINDOWS Microsoft Windows wininet request for peerdistsvc.dll over SMB attempt (more info ...)attempted-user 2010-3966   
36856FILE-IMAGE Microsoft Windows malformed WMF meta escape record memory corruption attempt (more info ...)attempted-user 2009-2500   URL
36891BROWSER-PLUGINS ClearQuest session ActiveX control access (more info ...)attempted-user 2012-0708   
36892BROWSER-PLUGINS ClearQuest session ActiveX control access (more info ...)attempted-user 2012-0708   
37040BROWSER-PLUGINS Microsoft CAPICOM CAPICOM.Certificates ActiveX clsid access attempt (more info ...)attempted-user 2007-0940   
37041BROWSER-PLUGINS Microsoft CAPICOM CAPICOM.Certificates ActiveX clsid access attempt (more info ...)attempted-user 2007-0940   
37042BROWSER-PLUGINS Microsoft CAPICOM CAPICOM.Certificates ActiveX clsid access attempt (more info ...)attempted-user 2007-0940   
37043BROWSER-PLUGINS Microsoft CAPICOM CAPICOM.Certificates ActiveX clsid access attempt (more info ...)attempted-user 2007-0940   
37044BROWSER-PLUGINS Microsoft CAPICOM CAPICOM.Certificates ActiveX clsid access attempt (more info ...)attempted-user 2007-0940   
37087OS-WINDOWS Microsoft Windows Metafile invalid header size integer overflow (more info ...)attempted-admin 2006-0020 16516  URL
37151FILE-MULTIMEDIA Microsoft Windows DirectX malformed mjpeg arbitrary code execution attempt (more info ...)attempted-user 2008-0011   URL
37152FILE-MULTIMEDIA Microsoft Windows DirectX malformed mjpeg arbitrary code execution attempt (more info ...)attempted-user 2008-0011   URL
37153FILE-MULTIMEDIA Microsoft Windows DirectX malformed mjpeg arbitrary code execution attempt (more info ...)attempted-user 2008-0011   URL
37364OS-WINDOWS Microsoft Windows NT DHCP REQUEST client identifier overflow attempt (more info ...)attempted-dos 2004-0899 11920  URL
37365OS-WINDOWS Microsoft Windows NT DHCP REQUEST client identifier overflow attempt (more info ...)attempted-dos 2004-0899 11920  URL
37366OS-WINDOWS Microsoft Windows NT DHCP REQUEST hostname overflow attempt (more info ...)attempted-dos 2004-0899 11920  URL
37367OS-WINDOWS Microsoft Windows NT DHCP REQUEST hostname overflow attempt (more info ...)attempted-dos 2004-0899 11920  URL
37445OS-WINDOWS Microsoft Windows Color Management Module buffer overflow attempt (more info ...)attempted-user 2005-1219 14214  
37514BROWSER-PLUGINS Schneider Electric ProClima F1BookView ActiveX clsid access attempt (more info ...)attempted-user 2015-8561   
37625BROWSER-PLUGINS SizerOne ActiveX clsid access attempt (more info ...)attempted-user 2008-4827 33148  
37635OS-WINDOWS Microsoft Windows SPNEGO ASN.1 library heap corruption overflow attempt (more info ...)attempted-admin 2005-1935 9633  URL
37713BROWSER-PLUGINS Unitronics VisiLogic TeeChart Pro ActiveX clsid access attempt (more info ...)attempted-user 2015-6478   URL
37714BROWSER-PLUGINS Unitronics VisiLogic TeeChart Pro ActiveX clsid access attempt (more info ...)attempted-user 2015-6478   URL
37826BROWSER-PLUGINS HP LoadRunner ActiveX function call access attempt (more info ...)attempted-user 2013-2370   
37827BROWSER-PLUGINS HP LoadRunner ActiveX function call access attempt (more info ...)attempted-user 2013-2370   
37874BROWSER-PLUGINS Novell ZENworks LaunchHelp.dll ActiveX clsid access attempt (more info ...)attempted-user 2011-2657   URL
37875BROWSER-PLUGINS Novell ZENworks LaunchHelp.dll ActiveX clsid access attempt (more info ...)attempted-user 2011-2657   URL
37876FILE-IMAGE Microsoft Windows GDI metafile integer overflow attempt (more info ...)attempted-user 2007-3034 25302  URL
37877FILE-IMAGE Microsoft Windows GDI metafile integer overflow attempt (more info ...)attempted-user 2007-3034 25302  URL
37878FILE-IMAGE Microsoft Windows GDI metafile integer overflow attempt (more info ...)attempted-user 2007-3034 25302  URL
37879FILE-IMAGE Microsoft Windows GDI metafile integer overflow attempt (more info ...)attempted-user 2007-3034 25302  URL
37882BROWSER-PLUGINS IBM SizerOne ActiveX clsid access attempt (more info ...)attempted-user 2012-5946 59559  
37883BROWSER-PLUGINS IBM SizerOne ActiveX clsid access attempt (more info ...)attempted-user 2012-5946 59559  
37886OS-WINDOWS DCERPC Plug and Play registry key access buffer overflow attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
37887OS-WINDOWS DCERPC Plug and Play registry key access buffer overflow attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
37899BROWSER-PLUGINS Attachmate Reflection ActiveX buffer overflow clsid attempt (more info ...)attempted-user    URL
37900BROWSER-PLUGINS Attachmate Reflection ActiveX buffer overflow clsid attempt (more info ...)attempted-user    URL
37901BROWSER-PLUGINS Attachmate Reflection ActiveX buffer overflow function call attempt (more info ...)attempted-user    URL
37902BROWSER-PLUGINS Attachmate Reflection ActiveX buffer overflow function call attempt (more info ...)attempted-user    URL
37996BROWSER-PLUGINS IE MsRdpClient ActiveX attempt (more info ...)attempted-user 2013-1302   
37997BROWSER-PLUGINS IE MsRdpClient ActiveX attempt (more info ...)attempted-user 2013-1302   
38046POLICY-OTHER PDF ActiveX CLSID access detected (more info ...)attempted-user 2014-0527   URL
38125FILE-MULTIMEDIA Microsoft Windows Transport Stream Program Map Table Heap overflow attempt (more info ...)attempted-user 2016-0101   URL
38151BROWSER-PLUGINS Symantec Altiris Deployment Solution ActiveX clsid access attempt (more info ...)attempted-user 2009-3033 37092  
38153BROWSER-PLUGINS WebGate WESPDiscovery ActiveX clsid access attempt (more info ...)attempted-user 2015-2100 72843  
38230BROWSER-PLUGINS WebGate Control Center WESPPlayback ActiveX clsid access attempt (more info ...)attempted-user 2015-2099 72834  
38231BROWSER-PLUGINS WebGate Control Center WESPPlayback ActiveX clsid access attempt (more info ...)attempted-user 2015-2099 72834  
38232BROWSER-PLUGINS WebGate Control Center WESPPlayback ActiveX clsid access attempt (more info ...)attempted-user 2015-2099 72834  
38233BROWSER-PLUGINS WebGate Control Center WESPPlayback ActiveX clsid access attempt (more info ...)attempted-user 2015-2099 72834  
38250INDICATOR-OBFUSCATION HTML entity encoded ActiveX object instantiation detected (more info ...)misc-activity    URL
38264OS-WINDOWS DCERPC Direct detection of malicious DCE RPC request in suspicious pcap (more info ...)protocol-command-decode 2009-1544   URL
38319NETBIOS SMB winreg named pipe creation attempt (more info ...)misc-activity    
38320NETBIOS SMB srvsvc named pipe creation attempt (more info ...)misc-activity    
38321NETBIOS SMB svcctl named pipe creation attempt (more info ...)misc-activity    
38322NETBIOS SMB samr named pipe creation attempt (more info ...)misc-activity    
38383BROWSER-PLUGINS Advantech WebAccess ActiveX clsid access attempt (more info ...)attempted-user    
38477BROWSER-IE Microsoft Edge webnote exit event css arbitrary file read attempt (more info ...)attempted-user 2016-0161   URL
38478BROWSER-IE Microsoft Edge webnote exit event css arbitrary file read attempt (more info ...)attempted-user 2016-0161   URL
38537BROWSER-PLUGINS Symantec NavComUI AxSysListView32 ActiveX clsid access attempt (more info ...)attempted-user 2007-2955 24983  URL
38538BROWSER-PLUGINS Symantec NavComUI AxSysListView32 ActiveX function call access attempt (more info ...)attempted-user 2007-2955 24983  URL
38539BROWSER-PLUGINS Symantec NavComUI AxSysListView32OAA ActiveX clsid access attempt (more info ...)attempted-user 2007-2955 24983  URL
38540BROWSER-PLUGINS Symantec NavComUI AxSysListView32OAA ActiveX function call access attempt (more info ...)attempted-user 2007-2955 24983  URL
38816FILE-OTHER Microsoft Windows gdi32 malformed EMF file ExtEscape buffer overflow attempt (more info ...)attempted-user 2016-0170   URL
39228BROWSER-IE Microsoft Edge PDF Color Space out-of-bounds memory access attempt (more info ...)attempted-recon 2016-3201   URL
39229BROWSER-IE Microsoft Edge PDF Color Space out-of-bounds memory access attempt (more info ...)attempted-recon 2016-3201   URL
39266OS-WINDOWS Microsoft Windows GdiPlus malformed EMF file out of bounds read attempt (more info ...)attempted-user 2016-3216   URL
39373BROWSER-PLUGINS Oracle AutoVueXCtrl ActiveX clsid access attempt (more info ...)attempted-user  50332  
39374BROWSER-PLUGINS Oracle AutoVueXCtrl ActiveX clsid access attempt (more info ...)attempted-user  50332  
39375BROWSER-PLUGINS Oracle AutoVueXCtrl ActiveX clsid access attempt (more info ...)attempted-user  50332  
39376BROWSER-PLUGINS IBM SPSS SamplePower ActiveX function call access attempt (more info ...)attempted-user 2012-5947 59556  
39377BROWSER-PLUGINS IBM SPSS SamplePower ActiveX function call access attempt (more info ...)attempted-user 2012-5947 59556  
39382BROWSER-PLUGINS Oracle Hyperion Financial Management TList6 ActiveX clsid access attempt (more info ...)attempted-user  50476  
39383BROWSER-PLUGINS Oracle Hyperion Financial Management TList6 ActiveX clsid access attempt (more info ...)attempted-user  50476  
39384BROWSER-PLUGINS Oracle Hyperion Financial Management TList6 ActiveX clsid access attempt (more info ...)attempted-user  50476  
39485BROWSER-IE Microsoft Edge DWrite.dll out of bounds read attempt (more info ...)attempted-recon 2016-3277   URL
39863OS-WINDOWS Microsoft Windows win32k.sys escalation of privilege attempt (more info ...)attempted-user 2011-1231   URL
39874FILE-OTHER Microsoft Windows PDF parsing invalid JPEG2000 SIZ marker attempt (more info ...)attempted-user 2016-3319   URL
39879BROWSER-PLUGINS Mitsubishi MC-WorkX ActiveX clsid access attempt (more info ...)attempted-user 2013-2817   
39880BROWSER-PLUGINS Mitsubishi MC-WorkX ActiveX clsid access attempt (more info ...)attempted-user 2013-2817   
39891BROWSER-PLUGINS Schneider Electric SCADA Expert ClearSCADA ActiveX clsid access attempt (more info ...)attempted-user 2014-1848   
39892BROWSER-PLUGINS Schneider Electric SCADA Expert ClearSCADA ActiveX clsid access attempt (more info ...)attempted-user 2014-1848   
39895BROWSER-PLUGINS Tom Sawyer GET exetension ActiveX clsid access (more info ...)attempted-user 2011-2217   
39896BROWSER-PLUGINS Tom Sawyer GET Extension ActiveX function call access (more info ...)attempted-user 2011-2217   
40022BROWSER-PLUGINS AcroPDF.PDF ActiveX clsid access attempt (more info ...)attempted-user 2006-6236 21338  URL
40023BROWSER-PLUGINS AcroPDF.PDF ActiveX clsid access attempt (more info ...)attempted-user 2006-6236 21338  URL
40130OS-WINDOWS Microsoft Windows GDI emf filename buffer overflow attempt (more info ...)attempted-user 2008-1087   URL
40144BROWSER-IE Microsoft Edge PDF out-of-bounds Crypt Filter length attempt (more info ...)attempted-user 2016-3370   URL
40145BROWSER-IE Microsoft Edge PDF out-of-bounds Crypt Filter length attempt (more info ...)attempted-user 2016-3370   URL
40146BROWSER-IE Microsoft Edge malformed response information disclosure attempt (more info ...)attempted-recon 2016-3325   URL
40347BROWSER-PLUGINS Samsung SmartViewer ActiveX clsid access attempt (more info ...)attempted-user 2015-8040   
40348BROWSER-PLUGINS Samsung SmartViewer ActiveX clsid access attempt (more info ...)attempted-user 2015-8040   
40376OS-WINDOWS Microsoft GDI local privilege escalation attempt (more info ...)attempted-admin 2016-3266   URL
40377OS-WINDOWS Microsoft GDI local privilege escalation attempt (more info ...)attempted-admin 2016-3266   URL
40651BROWSER-IE Microsoft Edge webkit directory file disclosure attempt (more info ...)attempted-user 2016-7204   URL
40652BROWSER-IE Microsoft Edge webkit directory file disclosure attempt (more info ...)attempted-user 2016-7204   URL
40713BROWSER-IE Microsoft Edge JSON.parse information disclosure attempt (more info ...)attempted-recon 2016-7241 94055  URL
40714BROWSER-IE Microsoft Edge JSON.parse information disclosure attempt (more info ...)attempted-recon 2016-7241 94055  URL
40715BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user 2016-7240   URL
40716BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user 2016-7240   URL
40946BROWSER-IE Microsoft Edge CSS browser history disclosure attempt (more info ...)attempted-recon    URL
40949BROWSER-IE Microsoft Edge SIMD memory corruption attempt (more info ...)attempted-user 2016-7286   URL
40950BROWSER-IE Microsoft Edge SIMD memory corruption attempt (more info ...)attempted-user 2016-7286   URL
40969BROWSER-IE Microsoft Edge Object.defineProperty type confusion attempt (more info ...)attempted-user 2016-7287   URL
40970BROWSER-IE Microsoft Edge Object.defineProperty type confusion attempt (more info ...)attempted-user 2016-7287   URL
41365OS-WINDOWS Microsoft Windows RtlQueryRegistryValues buffer overflow attempt (more info ...)attempted-admin 2010-4398   URL
41462FILE-EXECUTABLE Microsoft Windows Win32 Divide Error Exception Denial of Service attempt (more info ...)attempted-dos 2013-1334   URL
41463FILE-EXECUTABLE Microsoft Windows Win32 Divide Error Exception Denial of Service attempt (more info ...)attempted-dos 2013-1334   URL
41464FILE-EXECUTABLE Microsoft Windows Win32 Divide Error Exception Denial of Service attempt (more info ...)attempted-dos 2013-1334   URL
41465FILE-EXECUTABLE Microsoft Windows Win32 Divide Error Exception Denial of Service attempt (more info ...)attempted-dos 2013-1334   URL
41502BROWSER-PLUGINS NTR ActiveX clsid access attempt (more info ...)attempted-user 2012-0267 51374  
41503BROWSER-PLUGINS NTR ActiveX clsid access attempt (more info ...)attempted-user 2012-0267 51374  
41593BROWSER-IE Microsoft Edge Data URI same origin policy bypass attempt (more info ...)attempted-user 2017-0017   URL
41594BROWSER-IE Microsoft Edge Data URI same origin policy bypass attempt (more info ...)attempted-user 2017-0017   URL
41701POLICY-OTHER Microsoft Active Directory DSGetNCChanges attempt (more info ...)policy-violation    URL
41715BROWSER-IE Microsoft Health and Support Center iframe injection attempt (more info ...)attempted-user    
41946FILE-IMAGE Microsoft GDI+ malformed EMF description out of bounds read attempt (more info ...)attempted-admin 2018-12849   URL
41948BROWSER-IE Microsoft Edge fetch API same origin policy bypass attempt (more info ...)attempted-recon 2017-0140   URL
41949BROWSER-IE Microsoft Edge fetch API same origin policy bypass attempt (more info ...)attempted-recon 2017-0140   URL
41987BROWSER-IE Microsoft Edge web address spoofing attempt (more info ...)attempted-admin 2017-0069   URL
41988BROWSER-IE Microsoft Edge web address spoofing attempt (more info ...)attempted-admin 2017-0069   URL
41989FILE-EXECUTABLE Microsoft Windows Com Session Moniker pivilege escalation attempt (more info ...)attempted-user 2017-0100   URL
41990FILE-EXECUTABLE Microsoft Windows Com Session Moniker pivilege escalation attempt (more info ...)attempted-user 2017-0100   URL
41993OS-WINDOWS Microsoft Windows GDI WMF out of bounds read attempt (more info ...)attempted-user 2017-0073   URL
41997OS-WINDOWS Microsoft GDI+ privilege escalation attempt (more info ...)attempted-admin 2017-0188   URL
42040BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user 2018-4438   URL
42256OS-WINDOWS Microsoft Windows SMB anonymous user session setup request detected (more info ...)policy-violation    URL
42340OS-WINDOWS Microsoft Windows SMB anonymous session IPC share access attempt (more info ...)attempted-recon    URL
42440OS-WINDOWS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user 2005-0944 12960  
42441OS-WINDOWS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user 2005-0944 12960  
42442OS-WINDOWS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user 2005-0944 12960  
42444OS-WINDOWS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user 2005-0944 12960  
42445OS-WINDOWS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user 2005-0944 12960  
42446OS-WINDOWS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user 2005-0944 12960  
42773OS-WINDOWS Microsoft Windows COM privilege escalation attempt (more info ...)attempted-admin 2017-0213   
42774OS-WINDOWS Microsoft Windows COM privilege escalation attempt (more info ...)attempted-admin 2017-0213   
42865OS-WINDOWS Microsoft Windows RRAS MIBEntryGet buffer overflow attempt (more info ...)attempted-user    URL
42921BROWSER-PLUGINS Schneider Electric SoMachine HVAC ActiveX information disclosure clsid access attempt (more info ...)attempted-user    URL
42922BROWSER-PLUGINS Schneider Electric SoMachine HVAC ActiveX information disclosure clsid access attempt (more info ...)attempted-user    URL
43009BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43010BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43011BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43012BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43013BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43014BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43015BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43016BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43017BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43018BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43019BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43020BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43021BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43022BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43023BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43024BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43025BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43026BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43027BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43028BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43029BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43030BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43031BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43032BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43033BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43034BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43035BROWSER-PLUGINS Micro Focus Rumba+ ActiveX clsid access attempt (more info ...)attempted-user 2016-1606   
43046BROWSER-PLUGINS ICONICS SCADA WebHMI ActiveX clsid access attempt (more info ...)attempted-user    URL
43047BROWSER-PLUGINS ICONICS SCADA WebHMI ActiveX clsid access attempt (more info ...)attempted-user    URL
43110BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user 2016-7240   URL
43111BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user 2016-7240   URL
43122PROTOCOL-SCADA Advantech WebAccess webvrpcs denial of service attempt (more info ...)attempted-dos    URL
43161POLICY-OTHER Microsoft Browser iframe local file load attempt (more info ...)attempted-recon 2017-8529   
43162POLICY-OTHER Microsoft Browser iframe local file load attempt (more info ...)attempted-recon 2017-8529   
43185BROWSER-PLUGINS Advantech WebAccess ActiveX clsid access attempt (more info ...)attempted-user 2014-2364   
43186BROWSER-PLUGINS Advantech WebAccess ActiveX clsid access attempt (more info ...)attempted-user 2014-2364   
43225OS-WINDOWS Microsoft .NET framework CLI loader denial of service attempt (more info ...)attempted-dos 2007-0041 24778  URL
43226OS-WINDOWS Microsoft .NET framework CLI loader denial of service attempt (more info ...)attempted-dos 2007-0041 24778  URL
43240BROWSER-PLUGINS Rising Online Virus Scanner ActiveX clsid access attempt (more info ...)attempted-user  38282  
43241BROWSER-PLUGINS Rising Online Virus Scanner ActiveX clsid access attempt (more info ...)attempted-user  38282  
43242BROWSER-PLUGINS Rising Online Virus Scanner ActiveX clsid access attempt (more info ...)attempted-user  38282  
43243BROWSER-PLUGINS Rising Online Virus Scanner ActiveX clsid access attempt (more info ...)attempted-user  38282  
43269FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2009-1546   URL
43270FILE-MULTIMEDIA Microsoft Windows DirectX directshow wav file overflow attempt (more info ...)attempted-user 2009-1546   URL
43275OS-WINDOWS Microsoft Windows MFT denial of service attempt (more info ...)denial-of-service  98729  URL
43276OS-WINDOWS Microsoft Windows MFT denial of service attempt (more info ...)denial-of-service  98729  URL
43277OS-WINDOWS Microsoft Windows MFT denial of service attempt (more info ...)denial-of-service  98729  URL
43278OS-WINDOWS Microsoft Windows MFT denial of service attempt (more info ...)denial-of-service  98729  URL
43342BROWSER-PLUGINS Data Dynamics ActiveBar remote file write attempt ActiveX clsid access attempt (more info ...)attempted-user 2007-3883 24959  
43343BROWSER-PLUGINS Data Dynamics ActiveBar remote file write attempt ActiveX clsid access attempt (more info ...)attempted-user 2007-3883 24959  
43344BROWSER-PLUGINS Data Dynamics ActiveBar remote file write attempt ActiveX clsid access attempt (more info ...)attempted-user 2007-3883 24959  
43345BROWSER-PLUGINS Data Dynamics ActiveBar remote file write attempt ActiveX clsid access attempt (more info ...)attempted-user 2007-3883 24959  
43359FILE-IMAGE Microsoft GDI WMF file parsing integer overflow attempt (more info ...)attempted-admin 2008-2249   URL
43360FILE-IMAGE Microsoft GDI WMF file parsing integer overflow attempt (more info ...)attempted-admin 2008-2249   URL
43361FILE-IMAGE Microsoft GDI WMF file parsing integer overflow attempt (more info ...)attempted-admin 2008-2249   URL
43362FILE-IMAGE Microsoft GDI WMF file parsing integer overflow attempt (more info ...)attempted-admin 2008-2249   URL
43363FILE-IDENTIFY Microsoft Windows Audio wmf file magic detected (more info ...)misc-activity    URL
43364FILE-IDENTIFY Microsoft Windows Audio wmf file magic detected (more info ...)misc-activity    URL
43370NETBIOS DCERPC possible wmi remote process launch (more info ...)policy-violation    URL
43371BROWSER-PLUGINS DivX Player DivXBrowserPlugin ActiveX clsid access attempt (more info ...)attempted-user 2007-0429   
43372BROWSER-PLUGINS DivX Player DivXBrowserPlugin ActiveX clsid access attempt (more info ...)attempted-user 2007-0429   
43373BROWSER-PLUGINS DivX Player DivXBrowserPlugin ActiveX clsid access attempt (more info ...)attempted-user 2007-0429   
43374BROWSER-PLUGINS DivX Player DivXBrowserPlugin ActiveX clsid access attempt (more info ...)attempted-user 2007-0429   
43375BROWSER-PLUGINS EB Design Pty Ltd ActiveX clsid access attempt (more info ...)attempted-user 2007-5110   
43376BROWSER-PLUGINS EB Design Pty Ltd ActiveX clsid access attempt (more info ...)attempted-user 2007-5110   
43377BROWSER-PLUGINS EB Design Pty Ltd ActiveX clsid access attempt (more info ...)attempted-user 2007-5111   
43378BROWSER-PLUGINS EB Design Pty Ltd ActiveX clsid access attempt (more info ...)attempted-user 2007-5111   
43386OS-WINDOWS Microsoft Windows MFT denial of service attempt (more info ...)denial-of-service  98729  URL
43387OS-WINDOWS Microsoft Windows MFT denial of service attempt (more info ...)denial-of-service  98729  URL
43400BROWSER-PLUGINS IBM Lotus Quickr ActiveX stack buffer overflow ActiveX clsid access attempt (more info ...)attempted-user 2012-2176 53678  
43401BROWSER-PLUGINS IBM Lotus Quickr ActiveX stack buffer overflow ActiveX clsid access attempt (more info ...)attempted-user 2012-2176 53678  
43519BROWSER-PLUGINS Pegasus ImagXpress ActiveX clsid access attempt (more info ...)attempted-user 2007-5320   
43520BROWSER-PLUGINS Pegasus ImagXpress ActiveX clsid access attempt (more info ...)attempted-user 2007-5320   
43537BROWSER-PLUGINS IBM SPSS Statistics ActiveX clsid access attempt (more info ...)attempted-user 2015-8530 90524  URL
43538BROWSER-PLUGINS IBM SPSS Statistics ActiveX clsid access attempt (more info ...)attempted-user 2015-8530 90524  URL
43605BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX function call access attempt (more info ...)attempted-user 2008-2463 30114  URL
43606BROWSER-PLUGINS Microsoft Access Snapshot Viewer ActiveX function call access attempt (more info ...)attempted-user 2008-2463 30114  URL
43607BROWSER-PLUGINS HP Photo Creative ActiveX clsid access attempt (more info ...)attempted-user 2011-3397 45631  
43649BROWSER-PLUGINS Ultra Crypto Component ActiveX clsid access attempt (more info ...)attempted-user 2007-4902   
43650BROWSER-PLUGINS Ultra Crypto Component ActiveX clsid access attempt (more info ...)attempted-user 2007-4902   
43701BROWSER-PLUGINS McAfee FreeScan information disclosure ActiveX clsid access attempt (more info ...)attempted-user 2004-1908 10077  
43702BROWSER-PLUGINS McAfee FreeScan information disclosure ActiveX clsid access attempt (more info ...)attempted-user 2004-1908 10077  
43703BROWSER-PLUGINS McAfee FreeScan information disclosure ActiveX clsid access attempt (more info ...)attempted-user 2004-1908 10077  
43704BROWSER-PLUGINS McAfee FreeScan information disclosure ActiveX clsid access attempt (more info ...)attempted-user 2004-1908 10077  
43731OS-WINDOWS Microsoft Windows Vista contacts gadget code execution attempt (more info ...)attempted-user 2007-3032   URL
43732OS-WINDOWS Microsoft Windows Vista contacts gadget code execution attempt (more info ...)attempted-user 2007-3032   URL
43791OS-WINDOWS Microsoft .NET framework mscormmc.dll ASLR bypass attempt (more info ...)attempted-user 2015-6115 77482  URL
43792OS-WINDOWS Microsoft .NET framework mscormmc.dll ASLR bypass attempt (more info ...)attempted-user 2015-6115 77482  URL
43815OS-WINDOWS Microsoft VBScript engine RegExp information disclosure attempt (more info ...)policy-violation 2015-1684 74522  
43816OS-WINDOWS Microsoft VBScript engine RegExp information disclosure attempt (more info ...)policy-violation 2015-1684 74522  
43817OS-WINDOWS Microsoft VBScript engine RegExp information disclosure attempt (more info ...)policy-violation 2015-1684 74522  
43818OS-WINDOWS Microsoft VBScript engine RegExp information disclosure attempt (more info ...)policy-violation 2015-1684 74522  
43928PROTOCOL-OTHER NETBIOS Session Service header length field denial of service attempt (more info ...)attempted-dos    URL
43951BROWSER-PLUGINS Shockwave ActiveX Control clsid access (more info ...)attempted-user 2007-1403 22842  
43965OS-WINDOWS Microsoft Windows Explorer .doc file denial of service attempt (more info ...)attempted-user 2007-1347   
43966OS-WINDOWS Microsoft Windows Explorer .doc file denial of service attempt (more info ...)attempted-user 2007-1347   
44128FILE-IMAGE Microsoft Windows metafile SetPaletteEntries heap overflow attempt (more info ...)attempted-user 2005-2124 15356  URL
44129OS-WINDOWS Microsoft Windows Metafile invalid header size integer overflow attempt (more info ...)attempted-user 2005-2124 15356  URL
44130OS-WINDOWS Microsoft Windows Metafile invalid header size integer overflow attempt (more info ...)attempted-user 2005-2124 15356  URL
44131OS-WINDOWS Microsoft Windows Metafile invalid header size integer overflow attempt (more info ...)attempted-user 2005-2124 15356  URL
44132OS-WINDOWS Microsoft Windows Metafile invalid header size integer overflow attempt (more info ...)attempted-user 2005-2124 15356  URL
44199BROWSER-IE Microsoft Internet print table of links cross site scripting attempt (more info ...)attempted-admin    URL
44200BROWSER-IE Microsoft Internet print table of links cross site scripting attempt (more info ...)attempted-admin    URL
44216OS-WINDOWS Microsoft Windows Shell Handler remote code execution attempt (more info ...)attempted-user 2010-0027   URL
44217OS-WINDOWS Microsoft Windows Shell Handler remote code execution attempt (more info ...)attempted-user 2010-0027   URL
44218OS-WINDOWS Microsoft Windows Shell Handler remote code execution attempt (more info ...)attempted-user 2010-0027   URL
44305OS-WINDOWS Microsoft DirectShow memory corruption attempt (more info ...)attempted-user 2010-0250   URL
44306OS-WINDOWS Microsoft DirectShow memory corruption attempt (more info ...)attempted-user 2010-0250   URL
44548BROWSER-IE Microsoft Edge webnote exit event css arbitrary file read attempt (more info ...)attempted-user 2016-0161   URL
44549BROWSER-IE Microsoft Edge webnote exit event css arbitrary file read attempt (more info ...)attempted-user 2016-0161   URL
44635BROWSER-IE Microsoft Edge sandbox escape attempt (more info ...)attempted-admin    URL
44636BROWSER-IE Microsoft Edge sandbox escape attempt (more info ...)attempted-admin    URL
44651NETBIOS SMB NTLMSSP authentication brute force attempt (more info ...)attempted-user    URL
44664BROWSER-PLUGINS Microsoft Windows shell.application object ShellExecute attempt (more info ...)attempted-user    URL
44732BROWSER-PLUGINS Mitsubishi MC-WorkX ActiveX clsid access attempt (more info ...)attempted-user 2013-2817   
44733BROWSER-PLUGINS Mitsubishi MC-WorkX ActiveX clsid access attempt (more info ...)attempted-user 2013-2817   
44825OS-WINDOWS Microsoft Edge out of bounds write attempt (more info ...)attempted-admin 2017-11861   URL
44826OS-WINDOWS Microsoft Edge out of bounds write attempt (more info ...)attempted-admin 2017-11861   URL
44843BROWSER-IE Microsoft Edge Uint8Array memory corruption attempt (more info ...)attempted-admin 2017-11873   URL
44844BROWSER-IE Microsoft Edge Uint8Array memory corruption attempt (more info ...)attempted-admin 2017-11873   URL
45058FILE-OTHER Microsoft Windows UAC bypass attempt (more info ...)attempted-admin    
45059FILE-OTHER Microsoft Windows UAC bypass attempt (more info ...)attempted-admin    
45101PROTOCOL-SCADA vxworks rpc credential flavor integer overflow device crash attempt (more info ...)denial-of-service 2015-7599   
45108PROTOCOL-RPC XDR string allocation denial of service attempt (more info ...)denial-of-service 2017-8779 98325  
45152INDICATOR-COMPROMISE Microsoft MsMpEng shrink compressed zip code execution attempt (more info ...)attempted-admin 2017-11937   URL
45153INDICATOR-COMPROMISE Microsoft MsMpEng shrink compressed zip code execution attempt (more info ...)attempted-admin 2017-11937   URL
45164POLICY-OTHER RPC Portmapper version 3 dump request attempt (more info ...)denial-of-service    URL
45165POLICY-OTHER RPC Portmapper version 2 dump request attempt (more info ...)denial-of-service    URL
45166POLICY-OTHER RPC Portmapper getstat request attempt (more info ...)denial-of-service    URL
45175OS-WINDOWS Microsoft Windows ShellExecute and IE7 url handling code execution attempt (more info ...)attempted-user 2007-3896 25945  URL
45315FILE-OTHER Microsoft Windows MPEG Layer-3 audio heap corruption attempt (more info ...)attempted-user 2010-1882   URL
45316FILE-OTHER Microsoft Windows MPEG Layer-3 audio heap corruption attempt (more info ...)attempted-user 2010-1882   URL
45462BROWSER-IE Microsoft ChakraCore scripting engine memory corruption attempt (more info ...)attempted-user 2017-11799   URL
45463BROWSER-IE Microsoft ChakraCore scripting engine memory corruption attempt (more info ...)attempted-user 2017-11799   URL
45474BROWSER-IE Microsoft Edge scripting engine uninitialized pointers memory corruption attempt (more info ...)attempted-user 2017-11809   URL
45475BROWSER-IE Microsoft Edge scripting engine uninitialized pointers memory corruption attempt (more info ...)attempted-user 2017-11809   URL
45515NETBIOS SMB SESSION_SETUP subcommand detected (more info ...)protocol-command-decode    URL
45553FILE-MULTIMEDIA Microsoft Windows Movie Maker project file heap buffer overflow attempt (more info ...)attempted-user 2010-0265   URL
45630FILE-OTHER Microsoft Windows CLFS privilege escalation attempt (more info ...)attempted-user 2018-0844   URL
45631FILE-OTHER Microsoft Windows CLFS privilege escalation attempt (more info ...)attempted-user 2018-0844   URL
45971SERVER-OTHER Advantech WebAccess webvrpcs service arbitrary command execution attempt (more info ...)attempted-admin 2017-16720 102424  URL
46074FILE-OTHER Microsoft Windows Remote Assistance external entity remote file download attempt (more info ...)attempted-recon 2018-0878   URL
46075FILE-OTHER Microsoft Windows Remote Assistance external entity remote file download attempt (more info ...)attempted-recon 2018-0878   URL
46351BROWSER-PLUGINS Mitsubishi EZPcAut220 ActiveX clsid access attempt (more info ...)attempted-user 2014-1847   
46352BROWSER-PLUGINS Mitsubishi EZPcAut220 ActiveX clsid access attempt (more info ...)attempted-user 2014-1847   
46403NETBIOS SMB NTLM Authentication with unknown authentication message type attempt (more info ...)misc-activity    
46419OS-WINDOWS Microsoft Windows XXE information disclosure attempt (more info ...)attempted-admin 2017-8710   
46420OS-WINDOWS Microsoft Windows XXE information disclosure attempt (more info ...)attempted-admin 2017-8710   
46441BROWSER-IE Microsoft Edge AsmJsInterpreter method use after free attempt (more info ...)attempted-user 2017-8603   
46442BROWSER-IE Microsoft Edge AsmJsInterpreter method use after free attempt (more info ...)attempted-user 2017-8603   
46503OS-WINDOWS Microsoft Windows TTF cmap integer overflow attempt (more info ...)attempted-admin 2016-3393 93377  URL
46504OS-WINDOWS Microsoft Windows TTF cmap integer overflow attempt (more info ...)attempted-admin 2016-3393 93377  URL
46505BROWSER-IE Microsoft Edge eval heap overflow attempt (more info ...)attempted-user 2017-8641   URL
46506BROWSER-IE Microsoft Edge eval heap overflow attempt (more info ...)attempted-user 2017-8641   URL
46507BROWSER-IE Microsoft Edge eval heap overflow attempt (more info ...)attempted-user 2017-8641   URL
46508BROWSER-IE Microsoft Edge eval heap overflow attempt (more info ...)attempted-user 2017-8641   URL
46592BROWSER-IE Microsoft Edge JSON.parse information disclosure attempt (more info ...)attempted-recon 2016-7241 94055  URL
46593BROWSER-IE Microsoft Edge JSON.parse information disclosure attempt (more info ...)attempted-recon 2016-7241 94055  URL
46713BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-admin 2018-8179   URL
46714BROWSER-IE Microsoft Edge out of bounds write attempt (more info ...)attempted-admin 2018-8179   URL
46763BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user 2016-7240   URL
46764BROWSER-IE Microsoft Edge proxy object type confusion attempt (more info ...)attempted-user 2016-7240   URL
46903INDICATOR-COMPROMISE Microsoft Windows SYSTEM token stealing attempt (more info ...)attempted-user 2018-8897   
46904INDICATOR-COMPROMISE Microsoft Windows SYSTEM token stealing attempt (more info ...)attempted-user 2018-8897   
46905INDICATOR-COMPROMISE Microsoft Windows malicious CONTEXT structure creation attempt (more info ...)attempted-user 2018-8897   
46906INDICATOR-COMPROMISE Microsoft Windows malicious CONTEXT structure creation attempt (more info ...)attempted-user 2018-8897   
46907INDICATOR-COMPROMISE Microsoft Windows processor modification return to user-mode attempt (more info ...)attempted-user 2018-8897   
46908INDICATOR-COMPROMISE Microsoft Windows processor modification return to user-mode attempt (more info ...)attempted-user 2018-8897   
46909INDICATOR-COMPROMISE Microsoft Windows Interrupt Service Routine stack rollback attempt (more info ...)attempted-user 2018-8897   
46910INDICATOR-COMPROMISE Microsoft Windows Interrupt Service Routine stack rollback attempt (more info ...)attempted-user 2018-8897   
46942FILE-OTHER Microsoft Windows .lnk shortcut file executing system32 executable attempt (more info ...)attempted-user 2018-0978   URL
46947BROWSER-IE Microsoft Edge Media Foundation use-after-free attempt (more info ...)attempted-user 2018-8251   URL
46948BROWSER-IE Microsoft Edge Media Foundation use-after-free attempt (more info ...)attempted-user 2018-8251   URL
46957OS-WINDOWS Microsoft Windows hidparse.sys privilege escalation attempt (more info ...)attempted-admin 2018-8169   URL
46958OS-WINDOWS Microsoft Windows hidparse.sys privilege escalation attempt (more info ...)attempted-admin 2018-8169   URL
46983INDICATOR-COMPROMISE Microsoft cmd.exe banner (more info ...)successful-admin   11633 
47066BROWSER-IE Microsoft Edge array.join information disclosure attempt (more info ...)attempted-user 2016-7189   URL
47071BROWSER-IE Microsoft Edge Cross Origin Request Sharing information leak attempt (more info ...)attempted-recon 2018-8235   URL
47072BROWSER-IE Microsoft Edge Cross Origin Request Sharing information leak attempt (more info ...)attempted-recon 2018-8235   URL
47102BROWSER-IE Microsoft Edge Intl.js memory corruption attempt (more info ...)attempted-user 2018-8298   URL
47160BROWSER-IE Microsoft Edge mutation event memory corruption attempt (more info ...)attempted-user 2016-0124   URL
47171BROWSER-PLUGINS Microsoft Silverlight GetChar out of bounds read attempt (more info ...)attempted-user 2016-0034   URL
47172BROWSER-PLUGINS Microsoft Silverlight GetChar out of bounds read attempt (more info ...)attempted-user 2016-0034   URL
47398INDICATOR-COMPROMISE Microsoft cmd.exe outbound shell attempt (more info ...)attempted-user    URL
47399INDICATOR-COMPROMISE Microsoft cmd.exe outbound shell attempt (more info ...)attempted-user    URL
47400INDICATOR-COMPROMISE Microsoft powershell.exe outbound shell attempt (more info ...)attempted-user    URL
48205OS-WINDOWS Microsoft Windows Filter Manager Elevation Of Privilege attempt (more info ...)denial-of-service 2018-8333   URL
48487BROWSER-PLUGINS Accelrys BIOVIA DSVisualizerControlR22.SaveToFile ActiveX access attempt (more info ...)attempted-user    URL
48488BROWSER-PLUGINS Accelrys BIOVIA DSVisualizerControlR22.SaveToFile ActiveX access attempt (more info ...)attempted-user    URL
48489BROWSER-PLUGINS Accelrys BIOVIA DSVisualizerControlR22.SaveToFile ActiveX access attempt (more info ...)attempted-user    URL
48490BROWSER-PLUGINS Accelrys BIOVIA DSVisualizerControlR22.SaveToFile ActiveX access attempt (more info ...)attempted-user    URL
48901BROWSER-PLUGINS CA Internet Security Suite XMLSecDB ActiveX function call access (more info ...)attempted-user 2011-1036 46539  
48902BROWSER-PLUGINS CA Internet Security Suite XMLSecDB ActiveX function call access (more info ...)attempted-user 2011-1036 46539  
48903BROWSER-PLUGINS CA Internet Security Suite XMLSecDB ActiveX function call access (more info ...)attempted-user 2011-1036 46539  
48969FILE-OTHER Microsoft Windows Contact file remote code execution attempt (more info ...)attempted-user    URL
48970FILE-OTHER Microsoft Windows VCF file remote code execution attempt (more info ...)attempted-user    URL
48971FILE-OTHER Microsoft Windows Contact file remote code execution attempt (more info ...)attempted-user    URL
48972FILE-OTHER Microsoft Windows VCF file remote code execution attempt (more info ...)attempted-user    URL
49040INDICATOR-COMPROMISE Microsoft Windows Terminal server RDP over non-standard port attempt (more info ...)attempted-user    URL
49163INDICATOR-COMPROMISE Microsoft Windows NtTraceControl function use (more info ...)misc-activity    
49164INDICATOR-COMPROMISE Microsoft Windows NtTraceControl function use (more info ...)misc-activity    
49325FILE-OTHER Microsoft Windows Avast Anti-Virus local credentials disclosure attempt (more info ...)attempted-user 2018-12572   
49423FILE-OTHER Microsoft Windows TrueType font parsing engine sfac_GetSbitBitmap elevation of privileges attempt (more info ...)attempted-user 2011-3402   URL
49444BROWSER-PLUGINS Phoenix Contact Think & Do ISSymbol ActiveX clsid access attempt (more info ...)attempted-user    
49445BROWSER-PLUGINS Phoenix Contact Think & Do ISSymbol ActiveX clsid access attempt (more info ...)attempted-user    
49446BROWSER-PLUGINS Phoenix Contact Think & Do ISSymbol ActiveX clsid access attempt (more info ...)attempted-user    
49447BROWSER-PLUGINS Phoenix Contact Think & Do ISSymbol ActiveX clsid access attempt (more info ...)attempted-user    
49758BROWSER-PLUGINS GE Intelligent Platforms Proficy HTML help ActiveX function call attempt (more info ...)attempted-user 2012-2516   URL
49759BROWSER-PLUGINS GE Intelligent Platforms Proficy HTML help ActiveX function call attempt (more info ...)attempted-user 2012-2516   URL
49807BROWSER-PLUGINS IBM Lotus Quickr ActiveX stack buffer overflow attempt (more info ...)attempted-user 2012-2176 53678  
49808BROWSER-PLUGINS IBM Lotus Quickr ActiveX stack buffer overflow attempt (more info ...)attempted-user 2012-2176   
49809BROWSER-PLUGINS IBM Lotus Quickr ActiveX stack buffer overflow attempt (more info ...)attempted-user 2012-2176   
49810BROWSER-PLUGINS IBM Lotus Quickr ActiveX stack buffer overflow attempt (more info ...)attempted-user 2012-2176 53678  
49868BROWSER-IE Microsoft Edge SIMD memory corruption attempt (more info ...)attempted-user 2016-7286   URL
49869BROWSER-IE Microsoft Edge SIMD memory corruption attempt (more info ...)attempted-user 2016-7286   URL
49873BROWSER-PLUGINS IBM iNotes version 9 ActiveX clsid access (more info ...)attempted-user 2013-3027   
49874BROWSER-PLUGINS IBM iNotes version 9 ActiveX clsid access (more info ...)attempted-user 2013-3027   
49875BROWSER-PLUGINS IBM iNotes version 9 ActiveX clsid access (more info ...)attempted-user 2013-3027   
49876BROWSER-PLUGINS IBM iNotes version 9 ActiveX clsid access (more info ...)attempted-user 2013-3027   
49877BROWSER-PLUGINS IBM iNotes version 9 ActiveX clsid access (more info ...)attempted-user 2013-3027   
49878BROWSER-PLUGINS IBM iNotes version 9 ActiveX clsid access (more info ...)attempted-user 2013-3027   
49886BROWSER-IE Microsoft Windows IOleCvt interface use attempt (more info ...)policy-violation 2019-0845   URL
49887BROWSER-IE Microsoft Windows IOleCvt interface use attempt (more info ...)policy-violation 2019-0845   URL
49904BROWSER-PLUGINS Tom Sawyer GET extension ActiveX function call access attempt (more info ...)attempted-user 2011-2217   
49905BROWSER-PLUGINS Tom Sawyer GET extension ActiveX function call access attempt (more info ...)attempted-user 2011-2217   
49969OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
49970OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
49971OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
49972OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
49973OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
49974OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
49975OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
49976OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
49977OS-WINDOWS Microsoft Windows SChannel CertificateVerify buffer overflow attempt (more info ...)attempted-admin 2014-6321   URL
50129BROWSER-PLUGINS CA Internet Security Suite XMLSecDB ActiveX function call access (more info ...)attempted-user 2011-1036 46539  
50130BROWSER-PLUGINS CA Internet Security Suite XMLSecDB ActiveX function call access (more info ...)attempted-user 2011-1036 46539  
50633OS-WINDOWS Microsoft Windows SMBv1 NTLM tampering attempt (more info ...)attempted-user 2019-1040   
50721OS-WINDOWS Microsoft Windows malformed NTLMv2 authentication message attempt (more info ...)attempted-user 2019-1019   URL
51028OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user 2012-0013   URL
51029OS-WINDOWS Microsoft Windows Object Packager ClickOnce object remote code execution attempt (more info ...)attempted-user 2012-0013   URL
51039OS-WINDOWS Microsoft Windows OLE32 MSHTA masquerade attempt (more info ...)attempted-user 2005-0063 13132  URL
51070SERVER-OTHER Microsoft WINS Server remote memory corruption attempt (more info ...)attempted-user    
51160FILE-IMAGE Microsoft GDI crafted EMF file information disclosure attempt (more info ...)attempted-admin 2019-0961   URL
51161FILE-IMAGE Microsoft GDI crafted EMF file information disclosure attempt (more info ...)attempted-admin 2019-0961   URL
51335BROWSER-IE Microsoft Edge scripting engine uninitialized pointers memory corruption attempt (more info ...)attempted-user 2017-11809   URL
51867OS-WINDOWS Microsoft Windows malformed PE DLL out of bounds read attempt (more info ...)denial-of-service 2019-1346   URL
51868OS-WINDOWS Microsoft Windows malformed PE DLL out of bounds read attempt (more info ...)denial-of-service 2019-1346   URL
51869OS-WINDOWS Microsoft Windows malformed PE DLL out of bounds read attempt (more info ...)denial-of-service 2019-1346   URL
51870OS-WINDOWS Microsoft Windows malformed PE DLL out of bounds read attempt (more info ...)denial-of-service 2019-1346   URL
51880FILE-OTHER Microsoft Windows WER arbitrary file move escalation of privilege attempt (more info ...)attempted-admin 2019-1315   URL
51881FILE-OTHER Microsoft Windows WER arbitrary file move escalation of privilege attempt (more info ...)attempted-admin 2019-1315   URL
51897BROWSER-IE Microsoft ChakraCore scripting engine memory corruption attempt (more info ...)attempted-user 2017-11799   URL
52030OS-WINDOWS Microsoft Windows GDI+ EMF buffer overwrite attempt (more info ...)attempted-user 2008-2245   URL
52031OS-WINDOWS Microsoft Windows GDI+ EMF buffer overwrite attempt (more info ...)attempted-user 2008-2245   URL
52032OS-WINDOWS Microsoft Windows GDI+ EMF buffer overwrite attempt (more info ...)attempted-user 2008-2245   URL
52033OS-WINDOWS Microsoft Windows GDI+ EMF buffer overwrite attempt (more info ...)attempted-user 2008-2245   URL
52034OS-WINDOWS Microsoft Windows GDI+ EMF buffer overwrite attempt (more info ...)attempted-user 2008-2245   URL
52035OS-WINDOWS Microsoft Windows GDI+ EMF buffer overwrite attempt (more info ...)attempted-user 2008-2245   URL
52322BROWSER-PLUGINS Samsung SmartViewer ActiveX clsid access attempt (more info ...)attempted-user 2015-8040   
52335OS-WINDOWS Microsoft Windows MHTML XSS attempt (more info ...)attempted-user 2011-0096   URL
52347BROWSER-PLUGINS Flexera InstallShield ISGrid2.dll DoFindReplace heap buffer overlow ActiveX clsid access (more info ...)attempted-user 2011-3174   
52369OS-WINDOWS Microsoft Windows and Server malformed header denial of service attempt (more info ...)attempted-dos 2009-3676   URL
52468BROWSER-PLUGINS Oracle EasyMail Objects ActiveX clsid access attempt (more info ...)attempted-user 2007-4607 25467  
52469BROWSER-PLUGINS Oracle EasyMail Objects ActiveX clsid access attempt (more info ...)attempted-user 2007-4607 25467  
52470BROWSER-PLUGINS Oracle EasyMail Objects ActiveX clsid access attempt (more info ...)attempted-user 2007-4607 25467  
52479BROWSER-IE Microsoft Edge Chakra JIT out of bounds information disclosure attempt (more info ...)attempted-dos 2018-8145   URL
52522BROWSER-IE Microsoft Edge Chakra ProcessLinkFailedAsmJsModule type confusion attempt (more info ...)attempted-user 2017-8645   URL
52523BROWSER-IE Microsoft Edge Chakra ProcessLinkFailedAsmJsModule type confusion attempt (more info ...)attempted-user 2017-8645   URL
52663OS-WINDOWS Microsoft Windows Imaging API use after free attempt (more info ...)attempted-user 2019-1311   URL
52664OS-WINDOWS Microsoft Windows Imaging API use after free attempt (more info ...)attempted-user 2019-1311   URL
52864OS-WINDOWS Microsoft Windows CryptoAPI signed binary with explicitly-defined ECC curve parameters attempt (more info ...)misc-attack 2020-0601   URL
52865OS-WINDOWS Microsoft Windows CryptoAPI signed binary with explicitly-defined ECC curve parameters attempt (more info ...)misc-attack 2020-0601   URL
52866OS-WINDOWS Microsoft Windows CryptoAPI TLS server certificate public key with explicitly-defined ECC curve parameters attempt (more info ...)misc-attack 2020-0601   URL
53055OS-WINDOWS Microsoft Windows Graphics component privilege escalation attempt (more info ...)attempted-admin 2020-0715   URL
53091BROWSER-PLUGINS IBM SPSS Statistics ActiveX clsid access attempt (more info ...)attempted-user 2015-8530 90524  URL
53092BROWSER-PLUGINS IBM SPSS Statistics ActiveX clsid access attempt (more info ...)attempted-user 2015-8530 90524  URL
53110BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user 2018-0980   URL
53111BROWSER-IE Microsoft Edge scripting engine memory corruption attempt (more info ...)attempted-user 2018-0980   URL
53116BROWSER-PLUGINS Microsoft Windows Data Analyzer 3.5 ActiveX use-after-free attempt (more info ...)attempted-user 2010-0252   URL
53117BROWSER-PLUGINS Microsoft Windows Data Analyzer 3.5 ActiveX use-after-free attempt (more info ...)attempted-user 2010-0252   URL
53374POLICY-OTHER Microsoft Active Directory DrsAddEntry attempt (more info ...)policy-violation    URL
53375POLICY-OTHER Microsoft Active Directory DRSUAPI_REPLICA_ADD attempt (more info ...)policy-violation    URL
53464SERVER-OTHER FreeSWITCH mod_xml_rpc arbitrary command execution attempt (more info ...)attempted-user 2018-19911   URL
53465SERVER-OTHER FreeSWITCH mod_xml_rpc arbitrary command execution attempt (more info ...)attempted-user 2018-19911   URL
53466SERVER-OTHER FreeSWITCH mod_xml_rpc arbitrary command execution attempt (more info ...)attempted-user 2018-19911   URL
53467SERVER-OTHER FreeSWITCH mod_xml_rpc arbitrary command execution attempt (more info ...)attempted-user 2018-19911   URL
53468SERVER-OTHER FreeSWITCH mod_xml_rpc arbitrary command execution attempt (more info ...)attempted-user 2018-19911   URL
54526FILE-OTHER Microsoft Windows CAB file szName directory traversal attempt (more info ...)attempted-user 2020-1300   URL
54527FILE-OTHER Microsoft Windows CAB file szName directory traversal attempt (more info ...)attempted-user 2020-1300   URL
54754OS-WINDOWS Microsoft Windows kernel information disclosure attempt (more info ...)attempted-admin 2020-1578   URL
55943OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin 2020-16907   URL
56069INDICATOR-COMPROMISE Microsoft Sharepoint DataFormWebPart fingerprinting attempt (more info ...)attempted-user 2020-16952   URL
56070INDICATOR-COMPROMISE Microsoft Sharepoint DataFormWebPart remote code execution attempt (more info ...)attempted-user 2020-16952   URL
56263FILE-EXECUTABLE Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-user 2020-17010   URL
56264FILE-EXECUTABLE Microsoft Windows Win32k privilege escalation attempt (more info ...)attempted-user 2020-17010   URL
56303SERVER-WEBAPP Microsoft Sharepoint machineKey information disclosure attempt (more info ...)attempted-user 2020-17061   URL
56560POLICY-OTHER Microsoft SharePoint external ImportWeb attempt (more info ...)policy-violation 2020-17121   URL
56971MALWARE-OTHER Win.Malware.Winsecsrv-9823442-0 download attempt (more info ...)trojan-activity    URL
56972MALWARE-OTHER Win.Malware.Winsecsrv-9823442-0 download attempt (more info ...)trojan-activity    URL
56973MALWARE-OTHER Win.Malware.Winsecsrv-9823448-0 download attempt (more info ...)trojan-activity    URL
56974MALWARE-OTHER Win.Malware.Winsecsrv-9823448-0 download attempt (more info ...)trojan-activity    URL
56977MALWARE-OTHER Win.Malware.Winsecsrv-9823545-0 download attempt (more info ...)trojan-activity    URL
56978MALWARE-OTHER Win.Malware.Winsecsrv-9823545-0 download attempt (more info ...)trojan-activity    URL
56979MALWARE-OTHER Win.Malware.Winsecsrv-9823554-0 download attempt (more info ...)trojan-activity    URL
56980MALWARE-OTHER Win.Malware.Winsecsrv-9823554-0 download attempt (more info ...)trojan-activity    URL
57103OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-user 2021-1732   URL
57282NETBIOS TRUFFLEHUNTER TALOS-2021-1260 attack attempt (more info ...)attempted-admin    URL
57340NETBIOS TRUFFLEHUNTER TALOS-2021-1269 attack attempt (more info ...)attempted-recon    URL
57539OS-WINDOWS Microsoft Windows Graphics component privilege escalation attempt (more info ...)attempted-admin 2021-31170   URL
57540OS-WINDOWS Microsoft Windows Graphics component privilege escalation attempt (more info ...)attempted-admin 2021-31170   URL
57544OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)attempted-admin 2021-31188   URL
57545OS-WINDOWS Microsoft Windows Win32k kernel driver privilege escalation attempt (more info ...)attempted-admin 2021-31188   URL
57548SERVER-WEBAPP Microsoft SharePoint authenticated remote code execution attempt (more info ...)attempted-user 2021-31181   URL
57718SERVER-OTHER Microsoft Systems Management Server out of bounds write attempt (more info ...)attempted-dos 2004-0728 10726  
57719SERVER-OTHER Microsoft Systems Management Server out of bounds write attempt (more info ...)attempted-dos 2004-0728 10726  
57770OS-WINDOWS Microsoft Windows UPnP notification type overflow attempt (more info ...)attempted-admin 2007-1204 23371  URL
57771OS-WINDOWS Microsoft Windows UPnP notification type overflow attempt (more info ...)attempted-admin 2007-1204 23371  URL
57772OS-WINDOWS Microsoft Windows UPnP notification type overflow attempt (more info ...)attempted-admin 2007-1204 23371  URL
57910SERVER-WEBAPP Microsoft SharePoint Server authenticated remote code execution attempt (more info ...)attempted-user 2021-34467   URL
57952OS-WINDOWS Microsoft Windows SAM database improper ACLs elevation of privilege attempt (more info ...)attempted-admin 2021-36934   URL
57997OS-WINDOWS Microsoft Windows Remote Desktop client integer overflow attempt (more info ...)attempted-user 2021-34535   URL
58003OS-WINDOWS Microsoft Windows NFS remote code execution attempt (more info ...)attempted-user 2021-26432   URL
58289OS-WINDOWS Microsoft Windows Win32k elevation of privilege exploit download attempt (more info ...)attempted-admin 2021-40449   URL
58303OS-WINDOWS Microsoft Windows CLFS privilege escalation attempt (more info ...)attempted-admin 2021-40443   URL
58304OS-WINDOWS Microsoft Windows CLFS privilege escalation attempt (more info ...)attempted-admin 2021-40443   URL
58587OS-WINDOWS Microsoft Windows Installer elevation of privilege attempt (more info ...)attempted-admin 2020-0683   URL
58654OS-WINDOWS Microsoft Windows file signature spoofing attempt (more info ...)attempted-user 2020-1464   URL
58655OS-WINDOWS Microsoft Windows file signature spoofing attempt (more info ...)attempted-user 2020-1464   URL
58752OS-WINDOWS Microsoft Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin 2021-41333   URL
59053POLICY-OTHER Microsoft Windows S4U2self request for administrator account attempt (more info ...)policy-violation 2021-42287   URL
59210OS-WINDOWS Microsoft Windows PDEV escalation of privilege attempt (more info ...)attempted-admin 2022-23299   URL
59211OS-WINDOWS Microsoft Windows PDEV escalation of privilege attempt (more info ...)attempted-admin 2022-23299   URL
59437SERVER-WEBAPP Microsoft Sharepoint cross site scripting attempt (more info ...)attempted-user 2014-1754   
59438SERVER-WEBAPP Microsoft Sharepoint cross site scripting attempt (more info ...)attempted-user 2014-1754   
59439SERVER-WEBAPP Microsoft Sharepoint cross site scripting attempt (more info ...)attempted-user 2014-1754   
59503FILE-IMAGE Microsoft Windows asycfilt.dll malformed jpeg buffer overread attempt (more info ...)attempted-user 2016-7212   URL
59504FILE-IMAGE Microsoft Windows asycfilt.dll malformed jpeg buffer overread attempt (more info ...)attempted-user 2016-7212   URL
59529OS-WINDOWS Microsoft Windows DWM Core privilege escalation attempt (more info ...)attempted-admin 2022-24546   URL
59530OS-WINDOWS Microsoft Windows DWM Core privilege escalation attempt (more info ...)attempted-admin 2022-24546   URL
59563SERVER-OTHER Advantech WebAccess DCERPC stack buffer overflow attempt (more info ...)attempted-user 2019-3951   URL
59655OS-WINDOWS Microsoft Windows SMBv1 out of bounds read attempt (more info ...)attempted-user 2017-0267   
59666OS-WINDOWS Microsoft Windows SMBv1 information disclosure attempt (more info ...)misc-attack 2017-0271   URL
59730OS-WINDOWS Microsoft Windows Print Spooler escalation of privilege attempt (more info ...)attempted-admin 2022-29104   URL
59731OS-WINDOWS Microsoft Windows Print Spooler escalation of privilege attempt (more info ...)attempted-admin 2022-29104   URL
59821OS-WINDOWS Microsoft Windows malicious LNK file download attempt (more info ...)attempted-user 2020-0729   
59822OS-WINDOWS Microsoft Windows malicious LNK file download attempt (more info ...)attempted-user 2020-0729   
59828FILE-IMAGE Microsoft Windows DirectShow JPEG double free attempt (more info ...)attempted-user 2014-0301   
59829FILE-IMAGE Microsoft Windows DirectShow JPEG double free attempt (more info ...)attempted-user 2014-0301   
59830FILE-IMAGE Microsoft Windows DirectShow JPEG double free attempt (more info ...)attempted-user 2014-0301   
59853OS-WINDOWS Microsoft Windows LNK file remote code execution attempt (more info ...)attempted-user 2020-1421   URL
59854OS-WINDOWS Microsoft Windows LNK file remote code execution attempt (more info ...)attempted-user 2020-1421   URL
60416OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin 2022-21882   URL
60417OS-WINDOWS Microsoft Windows Win32k driver privilege escalation attempt (more info ...)attempted-admin 2022-21882   URL
60627PROTOCOL-RPC Microsoft Windows Network File System remote code execution attempt (more info ...)attempted-admin 2022-34715   URL
60698OS-WINDOWS Microsoft Windows DWM Core Library privilege escalation attempt (more info ...)attempted-admin 2022-37970   URL
60699OS-WINDOWS Microsoft Windows DWM Core Library privilege escalation attempt (more info ...)attempted-admin 2022-37970   URL
60977OS-WINDOWS Microsoft Windows Bluetooth Driver privilege escalation attempt (more info ...)attempted-admin 2022-44675   URL
60978OS-WINDOWS Microsoft Windows Bluetooth Driver privilege escalation attempt (more info ...)attempted-admin 2022-44675   URL
61303OS-WINDOWS Microsoft Windows PPTP denial-of-service attempt (more info ...)denial-of-service 2022-23253   URL
61357OS-WINDOWS Microsoft Windows Secure Channel denial of service attempt (more info ...)attempted-dos 2023-21819   URL
61430OS-WINDOWS Microsoft Windows Scripting Language remote code execution attempt (more info ...)attempted-user 2022-41128   URL
61431OS-WINDOWS Microsoft Windows Scripting Language remote code execution attempt (more info ...)attempted-user 2022-41128   URL
61445OS-WINDOWS Microsoft Windows Kernel Point-to-Point Tunneling Protocol remote code execution attempt (more info ...)attempted-admin 2022-23270   URL
61446OS-WINDOWS Microsoft Windows Kernel Point-to-Point Tunneling Protocol remote code execution attempt (more info ...)attempted-admin 2022-23270   URL
61447OS-WINDOWS Microsoft Windows Kernel Point-to-Point Tunneling Protocol remote code execution attempt (more info ...)attempted-admin 2022-23270   URL
61448OS-WINDOWS Microsoft Windows Kernel Point-to-Point Tunneling Protocol remote code execution attempt (more info ...)attempted-admin 2022-23270   URL
61466OS-WINDOWS Microsoft Windows cryptographic services code execution attempt (more info ...)attempted-user 2023-23416   URL
61467OS-WINDOWS Microsoft Windows cryptographic services code execution attempt (more info ...)attempted-user 2023-23416   URL
61606OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin 2023-28274   URL
61607OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (more info ...)attempted-admin 2023-28274   URL
61610OS-WINDOWS Microsoft Windows CD-ROM file system driver remote code execution attempt (more info ...)attempted-user 2022-38044   
61611OS-WINDOWS Microsoft Windows CD-ROM file system driver remote code execution attempt (more info ...)attempted-user 2022-38044   
61620OS-WINDOWS Microsoft Windows DHCP service remove code execution attempt (more info ...)attempted-user 2023-28231   URL
61714OS-WINDOWS Microsoft Windows kernel denial of service attempt (more info ...)attempted-dos 2023-24949   URL
61715OS-WINDOWS Microsoft Windows kernel denial of service attempt (more info ...)attempted-dos 2023-24949   URL
61836OS-WINDOWS Microsoft Windows DHCP service remove code execution attempt (more info ...)attempted-user 2023-28231   URL
61905FILE-OTHER Microsoft Visual Studio Python Interpreter Services remote code execution attempt (more info ...)attempted-user 2021-27068   
61906FILE-OTHER Microsoft Visual Studio Python Interpreter Services remote code execution attempt (more info ...)attempted-user 2021-27068   
62010SERVER-WEBAPP Microsoft SharePoint remote code execution attempt (more info ...)attempted-user 2023-33157   URL
62011SERVER-WEBAPP Microsoft SharePoint remote code execution attempt (more info ...)attempted-user 2023-33157   URL

 goto Top

Group: OS / Linux

# of attack rules in this group: 67

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
15490OS-LINUX Linux SCTP malformed forward-tsn chunk arbitrary code execution attempt (more info ...)attempted-admin  2009-0065  33113    
24642SERVER-WEBAPP RedHat JBoss Enterprise Application Platform JMX code execution attempt (more info ...)attempted-admin  2014-7883  39710    
32080MALWARE-BACKDOOR Linux.Backdoor.Starysu variant inbound connection (more info ...)trojan-activity        URL
32081MALWARE-BACKDOOR Linux.Backdoor.Starysu variant inbound connection (more info ...)trojan-activity        URL
37435OS-LINUX Linux Kernel keyring object exploit download attempt (more info ...)attempted-admin  2016-0728      
37436OS-LINUX Linux Kernel keyring object exploit download attempt (more info ...)attempted-admin  2016-0728      
37437OS-LINUX Linux Kernel keyring object exploit download attempt (more info ...)attempted-admin  2016-0728      
37438OS-LINUX Linux Kernel keyring object exploit download attempt (more info ...)attempted-admin  2016-0728      
39893OS-LINUX Linux Kernel USBIP out of bounds write attempt (more info ...)attempted-dos  2016-3955      URL
39894OS-LINUX Linux Kernel USBIP out of bounds write attempt (more info ...)attempted-dos  2016-3955      URL
40542OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin  2016-5195      URL
40543OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin  2016-5195      URL
40560OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin  2016-5195      URL
40561OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin  2016-5195      URL
40563OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin  2016-5195      URL
40565OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin  2016-5195      URL
40566OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin  2016-5195      URL
41040OS-LINUX Ubuntu Apport CrashDB crash report code injection attempt (more info ...)attempted-admin  2016-9949      URL
41041OS-LINUX Ubuntu Apport CrashDB crash report code injection attempt (more info ...)attempted-admin  2016-9949      URL
41516SERVER-WEBAPP McAfee Virus Scan Linux file existence test attempt (more info ...)web-application-attack  2016-8016      
41521SERVER-WEBAPP McAfee Virus Scan Linux cross site scripting attempt (more info ...)web-application-attack  2016-8019      
41681SERVER-WEBAPP McAfee Virus Scan Linux remote code execution attempt (more info ...)web-application-attack  2016-8020      
41707SERVER-WEBAPP McAfee Virus Scan Linux http response splitting attempt (more info ...)web-application-attack  2016-8024      
43692OS-LINUX Linux kernel SCTP invalid chunk length denial of service attempt (more info ...)attempted-dos  2016-9555      
43809SERVER-WEBAPP Kaspersky Linux File Server WMC cross site request forgery attempt (more info ...)web-application-attack  2017-9810  99330    URL
43810SERVER-WEBAPP Kaspersky Linux File Server WMC directory traversal attempt (more info ...)web-application-attack  2017-9812  99330    URL
43811SERVER-WEBAPP Kaspersky Linux File Server WMC directory traversal attempt (more info ...)web-application-attack  2017-9812  99330    URL
43812SERVER-WEBAPP Kaspersky Linux File Server WMC directory traversal attempt (more info ...)web-application-attack  2017-9812  99330    URL
52661MALWARE-OTHER Linux.Downloader.CoinMiner variant bash script dropper (more info ...)trojan-activity        
54794SERVER-WEBAPP Zeroshell Linux Router command injection attempt (more info ...)web-application-attack  2019-12725      URL
54795SERVER-WEBAPP Zeroshell Linux Router command injection attempt (more info ...)web-application-attack  2019-12725      URL
54796SERVER-WEBAPP Zeroshell Linux Router command injection attempt (more info ...)web-application-attack  2019-12725      URL
54797SERVER-WEBAPP Zeroshell Linux Router command injection attempt (more info ...)web-application-attack  2019-12725      URL
56051OS-LINUX Linux kernel af_packet tpacket_rcv integer overflow attempt (more info ...)attempted-admin  2020-14386      URL
56052OS-LINUX Linux kernel af_packet tpacket_rcv integer overflow attempt (more info ...)attempted-admin  2020-14386      URL
57156OS-LINUX Linux Kernel 4.17 out of bound access attempt (more info ...)attempted-user  2017-18344      URL
57157OS-LINUX Linux Kernel 4.17 out of bound access attempt (more info ...)attempted-user  2017-18344      URL
57985OS-LINUX Linux Kernel seq_file integer underflow privilege escalation attempt (more info ...)attempted-admin  2021-33909      URL
57986OS-LINUX Linux Kernel seq_file integer underflow privilege escalation attempt (more info ...)attempted-admin  2021-33909      URL
58955OS-LINUX Polkit pkexec privilege escalation attempt (more info ...)attempted-admin  2021-4034      URL
58956OS-LINUX Polkit pkexec privilege escalation attempt (more info ...)attempted-admin  2021-4034      URL
58973INDICATOR-SHELLCODE ARM Linux reverse connect shell (more info ...)shellcode-detect  2022-20699      URL
59256OS-LINUX Linux Kernel Dirty Pipe privilege escalation attempt (more info ...)attempted-admin  2022-0847      URL
59257OS-LINUX Linux Kernel Dirty Pipe privilege escalation attempt (more info ...)attempted-admin  2022-0847      URL
60431OS-LINUX Linux kernel PTRACE_TRACEME pkexec escalation of privileges attempt (more info ...)attempted-admin  2019-13272      URL
60432OS-LINUX Linux kernel PTRACE_TRACEME pkexec escalation of privileges attempt (more info ...)attempted-admin  2019-13272      URL
60504OS-LINUX Sudo heap-based buffer overflow attempt (more info ...)attempted-admin  2021-3156      
60505OS-LINUX Sudo heap-based buffer overflow attempt (more info ...)attempted-admin  2021-3156      
60596OS-LINUX Linux Kernel futex user access credential overwrite privilege escalation attempt (more info ...)attempted-admin  2014-3153      URL
60597OS-LINUX Linux Kernel futex user access credential overwrite privilege escalation attempt (more info ...)attempted-admin  2014-3153      URL
60643OS-LINUX Linux kernel route4_change use after free attempt (more info ...)attempted-admin  2022-2588      
60644OS-LINUX Linux kernel route4_change use after free attempt (more info ...)attempted-admin  2022-2588      
60753OS-LINUX Linux Kernel OverlayFS capabilities escalation of privileges attempt (more info ...)attempted-admin  2021-3493      
60754OS-LINUX Linux Kernel OverlayFS capabilities escalation of privileges attempt (more info ...)attempted-admin  2021-3493      
61041OS-LINUX Linux Kernel SMB2_TREE_DISCONNECT compound request use-after-free attempt (more info ...)attempted-user  2022-47939      URL
61153OS-LINUX Linux Kernel ksmbd smb2write out of bounds read attempt (more info ...)attempted-admin  2022-47940      URL
61292OS-LINUX KSMBD unauthenticated remote heap overflow attempt (more info ...)denial-of-service  2023-0210      URL
61642MALWARE-OTHER Linux.Trojan.SysUpdate variant download attempt (more info ...)trojan-activity        URL
61643MALWARE-OTHER Linux.Trojan.SysUpdate variant download attempt (more info ...)trojan-activity        URL
61644MALWARE-OTHER Linux.Trojan.SysUpdate variant download attempt (more info ...)trojan-activity        URL
61645MALWARE-OTHER Linux.Trojan.SysUpdate variant download attempt (more info ...)trojan-activity        URL
61646MALWARE-OTHER Linux.Trojan.SysUpdate variant download attempt (more info ...)trojan-activity        URL
61647MALWARE-OTHER Linux.Trojan.SysUpdate variant download attempt (more info ...)trojan-activity        URL
61648MALWARE-OTHER Linux.Trojan.SysUpdate variant download attempt (more info ...)trojan-activity        URL
61649MALWARE-OTHER Linux.Trojan.SysUpdate variant download attempt (more info ...)trojan-activity        URL
61792OS-LINUX Red Hat polkit privilege escalation attempt (more info ...)attempted-admin  2021-3560      URL
61793OS-LINUX Red Hat polkit privilege escalation attempt (more info ...)attempted-admin  2021-3560      URL


# of warning rules in this group: 171

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
213MALWARE-BACKDOOR MISC Linux rootkit attempt (more info ...)attempted-admin    URL
214MALWARE-BACKDOOR MISC Linux rootkit attempt lrkr0x (more info ...)attempted-admin    URL
215MALWARE-BACKDOOR MISC Linux rootkit attempt (more info ...)attempted-admin    URL
216MALWARE-BACKDOOR MISC Linux rootkit satori attempt (more info ...)attempted-admin    URL
262OS-LINUX x86 Linux overflow attempt (more info ...)attempted-admin    
264OS-LINUX x86 Linux overflow attempt (more info ...)attempted-admin    
265OS-LINUX x86 Linux overflow attempt ADMv2 (more info ...)attempted-admin    
288PROTOCOL-POP EXPLOIT x86 Linux overflow (more info ...)attempted-admin    
292OS-LINUX x86 Linux samba overflow (more info ...)attempted-admin 1999-0811 536  
302OS-LINUX Redhat 7.0 lprd overflow (more info ...)attempted-admin 2000-0917 1712  
517X11 xdmcp query (more info ...)attempted-recon    
652INDICATOR-SHELLCODE Linux shellcode (more info ...)shellcode-detect    
1867X11 xdmcp info query (more info ...)attempted-recon   10891 
7021OS-LINUX kernel SCTP chunkless packet denial of service attempt (more info ...)attempted-dos 2006-2934 18755  
15906OS-LINUX Linux Kernel DCCP Protocol Handler dccp_setsockopt_change integer overflow attempt (more info ...)denial-of-service 2008-3276 30704  
15907OS-LINUX Linux Kernel DCCP Protocol Handler dccp_setsockopt_change integer overflow attempt (more info ...)denial-of-service 2008-3276 30704  
16352OS-LINUX Linux Kernel NFSD Subsystem overflow attempt (more info ...)attempted-dos 2008-3915 31133  
16724OS-LINUX Linux kernel sctp_process_unk_param SCTPChunkInit buffer overflow attempt (more info ...)attempted-admin 2010-1173 39794  
17324INDICATOR-SHELLCODE x86 Linux reverse connect shellcode (more info ...)shellcode-detect    
17738SERVER-OTHER Linux Kernel SNMP Netfilter Memory Corruption attempt (more info ...)attempted-dos 2006-2444 18081  
18997OS-LINUX Linux kernel sctp_rcv_ootb invalid chunk length DoS attempt (more info ...)attempted-dos 2010-0008 38857  
24370OS-LINUX Linux kernel IA32 out-of-bounds system call attempt (more info ...)attempted-admin 2010-3301   
24371OS-LINUX Linux kernel IA32 out-of-bounds system call attempt (more info ...)attempted-admin 2010-3301   
26107SERVER-OTHER HP Linux Imaging and Printing Project hpssd daemon command injection attempt (more info ...)attempted-admin 2007-5208 26054  
26108SERVER-OTHER HP Linux Imaging and Printing Project hpssd daemon command injection attempt (more info ...)attempted-admin 2007-5208 26054  
27756SERVER-WEBAPP RedHat Piranha Virtual Server Package default passwd and arbitrary command execution attempt (more info ...)attempted-admin 2000-0322 1149  URL
28399MALWARE-CNC Linux.Backdoor.Tsunami outbound connection (more info ...)trojan-activity    URL
28852MALWARE-CNC User-Agent known malicious user-agent string - Linux.Trojan.Zollard (more info ...)trojan-activity    URL
28998OS-LINUX Linux kernel ARM put_user write outside process address space privilege escalation attempt (more info ...)attempted-admin 2013-6282 63734  
28999OS-LINUX Linux kernel ARM put_user write outside process address space privilege escalation attempt (more info ...)attempted-admin 2013-6282 63734  
29493MALWARE-CNC Linux.Backdoor.Tsunami outbound connection (more info ...)trojan-activity    
29494MALWARE-CNC Linux.Backdoor.Tsunami outbound connection (more info ...)trojan-activity    
29569MALWARE-CNC Linux.Backdoor.Shellbot outbound connection (more info ...)trojan-activity    URL
30221INDICATOR-SHELLCODE Metasploit linux/x86 reverse_tcp stager transfer attempt (more info ...)shellcode-detect    URL
30222INDICATOR-SHELLCODE Metasploit shellcode linux/x86/meterpreter stage transfer attempt (more info ...)shellcode-detect    URL
30223INDICATOR-SHELLCODE Metasploit shellcode linux/x86/shell stage transfer attempt (more info ...)shellcode-detect    URL
30224INDICATOR-SHELLCODE Metasploit shellcode linux/x86/shell_reverse_tcp single stage transfer attempt (more info ...)shellcode-detect    URL
30326OS-LINUX Linux kernel SCTP duplicate cookie denial of service attempt (more info ...)attempted-dos 2013-2206 60715  
30335MALWARE-CNC Linux.Trojan.Calfbot variant outbound connection (more info ...)trojan-activity    URL
30336MALWARE-CNC Linux.Trojan.Calfbot outbound connection (more info ...)trojan-activity    URL
30398INDICATOR-SHELLCODE Metasploit payload linux_armle_adduser (more info ...)shellcode-detect    
30399INDICATOR-SHELLCODE Metasploit payload linux_armle_exec (more info ...)shellcode-detect    
30400INDICATOR-SHELLCODE Metasploit payload linux_armle_shell_bind_tcp (more info ...)shellcode-detect    
30401INDICATOR-SHELLCODE Metasploit payload linux_armle_shell_reverse_tcp (more info ...)shellcode-detect    
30402INDICATOR-SHELLCODE Metasploit payload linux_mipsbe_shell_bind_tcp (more info ...)shellcode-detect    
30403INDICATOR-SHELLCODE Metasploit payload linux_mipsbe_shell_reverse_tcp (more info ...)shellcode-detect    
30404INDICATOR-SHELLCODE Metasploit payload linux_mipsle_reboot (more info ...)shellcode-detect    
30405INDICATOR-SHELLCODE Metasploit payload linux_mipsle_shell_bind_tcp (more info ...)shellcode-detect    
30406INDICATOR-SHELLCODE Metasploit payload linux_mipsle_shell_reverse_tcp (more info ...)shellcode-detect    
30407INDICATOR-SHELLCODE Metasploit payload linux_ppc64_shell_bind_tcp (more info ...)shellcode-detect    
30408INDICATOR-SHELLCODE Metasploit payload linux_ppc64_shell_find_port (more info ...)shellcode-detect    
30409INDICATOR-SHELLCODE Metasploit payload linux_ppc_shell_bind_tcp (more info ...)shellcode-detect    
30410INDICATOR-SHELLCODE Metasploit payload linux_ppc_shell_find_port (more info ...)shellcode-detect    
30411INDICATOR-SHELLCODE Metasploit payload linux_x64_exec (more info ...)shellcode-detect    
30412INDICATOR-SHELLCODE Metasploit payload linux_x64_shell_bind_tcp (more info ...)shellcode-detect    
30413INDICATOR-SHELLCODE Metasploit payload linux_x64_shell_bind_tcp_random_port (more info ...)shellcode-detect    
30414INDICATOR-SHELLCODE Metasploit payload linux_x64_shell_find_port (more info ...)shellcode-detect    
30415INDICATOR-SHELLCODE Metasploit payload linux_x64_shell_reverse_tcp (more info ...)shellcode-detect    
30416INDICATOR-SHELLCODE Metasploit payload linux_x86_adduser (more info ...)shellcode-detect    
30417INDICATOR-SHELLCODE Metasploit payload linux_x86_chmod (more info ...)shellcode-detect    
30418INDICATOR-SHELLCODE Metasploit payload linux_x86_exec (more info ...)shellcode-detect    
30419INDICATOR-SHELLCODE Metasploit payload linux_x86_meterpreter_bind_ipv6_tcp (more info ...)shellcode-detect    
30420INDICATOR-SHELLCODE Metasploit payload linux_x86_meterpreter_bind_nonx_tcp (more info ...)shellcode-detect    
30421INDICATOR-SHELLCODE Metasploit payload linux_x86_meterpreter_bind_tcp (more info ...)shellcode-detect    
30422INDICATOR-SHELLCODE Metasploit payload linux_x86_meterpreter_find_tag (more info ...)shellcode-detect    
30423INDICATOR-SHELLCODE Metasploit payload linux_x86_meterpreter_reverse_ipv6_tcp (more info ...)shellcode-detect    
30424INDICATOR-SHELLCODE Metasploit payload linux_x86_meterpreter_reverse_nonx_tcp (more info ...)shellcode-detect    
30425INDICATOR-SHELLCODE Metasploit payload linux_x86_meterpreter_reverse_tcp (more info ...)shellcode-detect    
30426INDICATOR-SHELLCODE Metasploit payload linux_x86_shell_bind_ipv6_tcp (more info ...)shellcode-detect    
30427INDICATOR-SHELLCODE Metasploit payload linux_x86_shell_bind_tcp (more info ...)shellcode-detect    
30428INDICATOR-SHELLCODE Metasploit payload linux_x86_shell_bind_tcp_random_port (more info ...)shellcode-detect    
30429INDICATOR-SHELLCODE Metasploit payload linux_x86_shell_find_port (more info ...)shellcode-detect    
30430INDICATOR-SHELLCODE Metasploit payload linux_x86_shell_reverse_tcp (more info ...)shellcode-detect    
30431INDICATOR-SHELLCODE Metasploit payload linux_x86_shell_reverse_tcp2 (more info ...)shellcode-detect    
30566MALWARE-CNC Linux.Trojan.Elknot outbound connection (more info ...)trojan-activity    URL
30938MALWARE-CNC Linux.Trojan.Roopre outbound connection (more info ...)trojan-activity    URL
31589PROTOCOL-SERVICES Linux iscsi_add_notunderstood_response request buffer overflow attempt (more info ...)attempted-user 2013-2850   URL
31590PROTOCOL-SERVICES Linux iscsi_add_notunderstood_response request buffer overflow attempt (more info ...)attempted-user 2013-2850   URL
31808MALWARE-CNC Linux.Trojan.IptabLex outbound connection (more info ...)trojan-activity    URL
31925MALWARE-CNC Linux.Trojan.Jynxkit outbound connection (more info ...)trojan-activity    URL
32009MALWARE-CNC Linux.Backdoor.Flooder inbound connection attempt - command (more info ...)trojan-activity    URL
32010MALWARE-CNC Linux.Backdoor.Flooder outbound telnet connection attempt (more info ...)trojan-activity    URL
32011MALWARE-CNC Linux.Backdoor.Flooder outbound connection (more info ...)trojan-activity    URL
32013MALWARE-CNC Linux.Worm.Darlloz variant outbound connection (more info ...)trojan-activity    URL
32040MALWARE-CNC Linux.Backdoor.Ganiw variant outbound connection (more info ...)trojan-activity    URL
32493MALWARE-CNC Linux.Trojan.SpikeA variant outbound connection (more info ...)trojan-activity    URL
32494MALWARE-CNC Linux.Trojan.SpikeA variant outbound connection (more info ...)trojan-activity    URL
32504MALWARE-CNC Linux.Backdoor.Kiler attempted outbound connection (more info ...)trojan-activity    URL
32505MALWARE-CNC Linux.Backdoor.Kiler attempted outbound connection (more info ...)trojan-activity    URL
32510MALWARE-CNC Linux.Trojan.PiltabeA outbound connection (more info ...)trojan-activity    URL
33481MALWARE-CNC Linux.Backdoor.Xnote outbound connection (more info ...)trojan-activity    URL
33646MALWARE-CNC Linux.Trojan.XORDDoS outbound connection (more info ...)trojan-activity    URL
33647MALWARE-CNC Linux.Trojan.XORDDoS outbound connection (more info ...)trojan-activity    URL
33648MALWARE-CNC Linux.Trojan.XORDDoS outbound connection (more info ...)trojan-activity    URL
33985MALWARE-CNC Linux.Trojan.ChinaZ outbound connection (more info ...)trojan-activity    URL
34261MALWARE-CNC Linux.Trojan.XORDDoS outbound connection (more info ...)trojan-activity    URL
34262MALWARE-CNC Linux.Trojan.XORDDoS outbound connection (more info ...)trojan-activity    URL
34263MALWARE-CNC Linux.Trojan.XORDDoS outbound connection (more info ...)trojan-activity    URL
34461MALWARE-CNC Linux.Trojan.Mumblehard variant outbound connection (more info ...)trojan-activity    URL
34462MALWARE-CNC Linux.Downloader.Mumblehard variant outbound connection (more info ...)trojan-activity    URL
34802OS-LINUX Linux kernel SCTP Unknown Chunk Types denial of service attempt (more info ...)attempted-dos 2014-3673   
34847MALWARE-CNC Linux.Trojan.ChinaZ outbound connection (more info ...)trojan-activity 2014-6271   URL
34993MALWARE-CNC Linux.Trojan.Benloader variant outbound connection (more info ...)trojan-activity    URL
35039MALWARE-CNC Trojan.Linux.Linuxor outbound variant connection (more info ...)trojan-activity    URL
35062MALWARE-CNC Linux.Backdoor.Powbot inbound variant connection (more info ...)trojan-activity    URL
35063MALWARE-CNC Linux.Backdoor.Powbot inbound variant connection (more info ...)trojan-activity    URL
35064MALWARE-CNC Linux.Backdoor.Powbot inbound variant connection (more info ...)trojan-activity    URL
35065MALWARE-CNC Linux.Backdoor.Powbot inbound variant connection (more info ...)trojan-activity    URL
35066MALWARE-CNC Linux.Backdoor.Powbot outbound variant connection (more info ...)trojan-activity    URL
35067MALWARE-CNC Linux.Backdoor.Powbot outbound variant connection (more info ...)trojan-activity    URL
35082MALWARE-CNC Backdoor.Linux.Qenerek outbound connection (more info ...)trojan-activity    URL
35710MALWARE-CNC User-Agent known malicious user-agent string - Linux.Trojan.Zollard (more info ...)trojan-activity    URL
37654OS-LINUX Linux kernel SCTP handshake COOKIE ECHO Chunks denial of service attempt (more info ...)attempted-dos 2014-0101 65943  
37817MALWARE-CNC Linux.Trojan.Torte variant outbound connection (more info ...)trojan-activity    URL
38255MALWARE-CNC Win-Linux.Trojan.Derusbi variant outbound connection (more info ...)trojan-activity    URL
38256MALWARE-CNC Win-Linux.Trojan.Derusbi variant outbound connection (more info ...)trojan-activity    URL
38257MALWARE-CNC Win-Linux.Trojan.Derusbi variant outbound connection (more info ...)trojan-activity    URL
38258MALWARE-CNC Win/Linux.Trojan.Derusbi variant outbound connection (more info ...)trojan-activity    URL
38333MALWARE-CNC Linux.Trojan.Bifrose outbound connection (more info ...)trojan-activity    URL
38346OS-LINUX Linux kernel SCTP INIT null pointer dereference attempt (more info ...)attempted-dos 2014-7841   
40063OS-LINUX Linux Kernel Challenge ACK provocation attempt (more info ...)attempted-admin 2017-7285 91704  
40562OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin 2016-5195   URL
40564OS-LINUX Linux kernel madvise race condition attempt (more info ...)attempted-admin 2016-5195   URL
40991MALWARE-CNC Linux.DDoS.D93 outbound connection (more info ...)trojan-activity    URL
41027OS-LINUX Linux net af_packet.c tpacket version race condition use after free attempt (more info ...)attempted-user 2016-8655   
41028OS-LINUX Linux net af_packet.c tpacket version race condition use after free attempt (more info ...)attempted-user 2016-8655   
41252INDICATOR-SHELLCODE Linux MIPS shell (more info ...)shellcode-detect    
41253INDICATOR-SHELLCODE Linux PPC read execute (more info ...)shellcode-detect    
41254INDICATOR-SHELLCODE Linux PPC reverse connect shell (more info ...)shellcode-detect    
41255INDICATOR-SHELLCODE Linux PPC shell (more info ...)shellcode-detect    
41256INDICATOR-SHELLCODE Linux PPC shell (more info ...)shellcode-detect    
41257INDICATOR-SHELLCODE Linux SPARC bind shell (more info ...)shellcode-detect    
41258INDICATOR-SHELLCODE Linux SPARC bind shell (more info ...)shellcode-detect    
41259INDICATOR-SHELLCODE Linux SPARC FindSock shell (more info ...)shellcode-detect    
41260INDICATOR-SHELLCODE Linux SPARC reverse connect shell (more info ...)shellcode-detect    
41261INDICATOR-SHELLCODE Linux SPARC reverse connect shell (more info ...)shellcode-detect    
41262INDICATOR-SHELLCODE Linux x86 execute (more info ...)shellcode-detect    
41263INDICATOR-SHELLCODE Linux x86 FindSock shell (more info ...)shellcode-detect    
41264INDICATOR-SHELLCODE Linux x86 reverse connect UDP shell (more info ...)shellcode-detect    
41275INDICATOR-SHELLCODE Multi-OS shell - linux x86/ppc (more info ...)shellcode-detect    
41277INDICATOR-SHELLCODE Multi-OS shell - solaris/linux (more info ...)shellcode-detect    
41278INDICATOR-SHELLCODE Multi-OS shell - solaris/linux/irix (more info ...)shellcode-detect    
41517SERVER-WEBAPP McAfee Virus Scan Linux replace tag file poisoning attempt (more info ...)web-application-attack 2016-8017   
41518SERVER-WEBAPP McAfee Virus Scan Linux bracket tag file poisoning attempt (more info ...)web-application-attack 2016-8017   
41519SERVER-WEBAPP McAfee Virus Scan Linux url encoded bracket tag file poisoning attempt (more info ...)web-application-attack 2016-8017   
41692SERVER-WEBAPP McAfee Virus Scan Linux unauthorized authentication token usage attempt (more info ...)web-application-attack 2016-8022   
41853OS-LINUX cURL and libcurl set-cookie remote code execution attempt (more info ...)attempted-user 2015-3145 74303  
41920SERVER-WEBAPP McAfee Virus Scan Linux authentication token brute force attempt (more info ...)web-application-attack 2016-8023   URL
42510FILE-EXECUTABLE XOR 0x11 encrypted portable executable file download attempt (more info ...)policy-violation    
42892MALWARE-CNC Linux.Trojan.SpikeA outbound connection (more info ...)trojan-activity    URL
43813SERVER-WEBAPP Kaspersky Linux File Server WMC cross site scripting attempt (more info ...)attempted-user 2017-9813 99330  URL
44308OS-LINUX Linux kernel sctp_rcv_ootb invalid chunk length DoS attempt (more info ...)attempted-dos 2010-0008 38857  
44309OS-LINUX Linux kernel sctp_rcv_ootb invalid chunk length DoS attempt (more info ...)attempted-dos 2010-0008 38857  
44681MALWARE-CNC Linux.Trojan.IoTReaper_Botnet telnet connection attempt (more info ...)trojan-activity    
46847OS-LINUX Red Hat NetworkManager DHCP client command injection attempt (more info ...)attempted-user 2018-1111   URL
48191MALWARE-CNC Linux.Malware.Torii variant malicious file download (more info ...)trojan-activity    URL
48470MALWARE-CNC Linux.Trojan.Coinminer variant outbound connection (more info ...)trojan-activity    URL
48471MALWARE-CNC Linux.Trojan.Coinminer variant outbound connection (more info ...)trojan-activity    URL
48472MALWARE-CNC Linux.Trojan.Coinminer variant outbound connection (more info ...)trojan-activity    URL
48473MALWARE-CNC Linux.Trojan.Coinminer variant outbound connection (more info ...)trojan-activity    URL
49188MALWARE-CNC User-Agent known malicious user-agent string - Linux.Trojan.SpeakUp (more info ...)trojan-activity    URL
50146MALWARE-CNC Linux.Trojan.ChachaDDoS outbound connection (more info ...)trojan-activity    URL
50147MALWARE-CNC Linux.Trojan.ChachaDDoS outbound connection (more info ...)trojan-activity    URL
50190OS-LINUX Debian apt remote code execution attempt (more info ...)attempted-user 2019-3462 106690  URL
51238SERVER-OTHER Rockwell Automation RSLinux heap buffer overflow attempt (more info ...)attempted-user 2018-14821   URL
52022OS-LINUX Red Hat NetworkManager DHCP client command injection attempt (more info ...)attempted-user 2018-1111   URL
57987OS-LINUX Linux Kernel netfilter xt_compat_target_from_user out of bounds write attempt (more info ...)attempted-admin 2021-22555   
57988OS-LINUX Linux Kernel netfilter xt_compat_target_from_user out of bounds write attempt (more info ...)attempted-admin 2021-22555   
59849OS-LINUX Linux Kernel ipv4_pktinfo_prepare denial of service attempt (more info ...)attempted-dos 2017-5970   URL
61796OS-LINUX Linux kernel n_tty_write privilege escalation attempt (more info ...)attempted-admin 2014-0196   URL
61797OS-LINUX Linux kernel n_tty_write privilege escalation attempt (more info ...)attempted-admin 2014-0196   URL

 goto Top

Group: OS / Other

# of attack rules in this group: 1033

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
604PROTOCOL-SERVICES Unix rlogin froot parameter root access attempt (more info ...)attempted-admin  1999-0113  458    
3527OS-SOLARIS Oracle Solaris LPD overflow attempt (more info ...)attempted-admin  2001-1583  3274    
6507SERVER-WEBAPP novell edirectory imonitor overflow attempt (more info ...)attempted-admin  2006-2496  18026    
10136OS-SOLARIS Oracle Solaris login environment variable authentication bypass attempt (more info ...)attempted-admin  2007-0882  22512    
10998SERVER-OTHER Novell GroupWise WebAccess authentication overflow (more info ...)attempted-admin  2007-2171  23556    
11670SERVER-OTHER Symantec Discovery logging buffer overflow (more info ...)attempted-admin  2007-1173  24002    
13363SERVER-OTHER Cisco Unified Communications Manager heap overflow attempt (more info ...)attempted-admin  2008-0027  27313    
13613OS-SOLARIS Oracle Solaris username overflow authentication bypass attempt (more info ...)attempted-admin  2001-0797      
14989SERVER-WEBAPP Novell eDirectory SOAP Accept Language header overflow attempt (more info ...)attempted-user  2008-4479      
16515SERVER-MAIL Novell Groupwise Internet Agent RCPT command overflow attempt (more info ...)attempted-user  2009-0410  33560    
17057SERVER-OTHER Novell Client NetIdentity Agent remote arbitrary pointer dereference code execution attempt (more info ...)attempted-admin  2009-1350  34400    
18311SERVER-WEBAPP Novell iManager getMultiPartParameters arbitrary file upload attempt (more info ...)attempted-admin    43635    URL
18589SERVER-OTHER Novell Client NetIdentity Agent remote arbitrary pointer dereference code execution attempt (more info ...)attempted-admin  2009-1350  34400    
18768SERVER-MAIL Novell GroupWise Internet Agent RRULE parsing buffer overflow attempt (more info ...)attempted-admin  2011-2663  49781    
18769SERVER-OTHER LDAP Novell eDirectory evtFilteredMonitorEventsRequest function heap overflow attempt (more info ...)attempted-admin  2006-4509      URL
18791SERVER-OTHER Novell ZENworks Configuration Management Preboot service code overflow attempt (more info ...)attempted-admin    39111    
18792SERVER-WEBAPP Novell ZENworks Configuration Management UploadServlet code execution attempt (more info ...)attempted-admin    39914    URL
18793SERVER-WEBAPP Novell ZENworks Configuration Management fileupload code execution attempt (more info ...)attempted-admin  2010-5324  39914    URL
18902SERVER-WEBAPP Novell Teaming ajaxUploadImageFile remote code execution attempt (more info ...)attempted-admin  2010-2773  41795    
19224FILE-IDENTIFY Cisco Webex wrf file download request (more info ...)misc-activity        URL
19323SERVER-OTHER Novell ZENworks Handheld Management ZfHIPCND.exe buffer overflow attempt (more info ...)attempted-admin  2011-0742  46024    
20607SERVER-OTHER Novell Groupwise internet agent http uri buffer overflow attempt (more info ...)attempted-user  2011-0334      
20608SERVER-OTHER Novell Groupwise internet agent http uri buffer overflow attempt (more info ...)attempted-user  2011-0334      
20691POLICY-OTHER Cisco Network Registrar default credentials authentication attempt (more info ...)default-login-attempt  2011-2024      URL
20692POLICY-OTHER Cisco network registrar default credentials authentication attempt (more info ...)default-login-attempt  2011-2024      URL
20725OS-SOLARIS Oracle Solaris in.rwhod hostname denial of service attempt (more info ...)attempted-dos  2004-1351  13401    
21113FILE-IDENTIFY Cisco Webex Player .wrf file magic detected (more info ...)misc-activity        
21752SERVER-OTHER Novell ZENWorks configuration management preboot request buffer overflow attempt (more info ...)attempted-user  2011-3176  52659    
21914SERVER-OTHER Novell ZENWorks configuration management preboot opcode 6C request buffer overflow attempt (more info ...)attempted-user  2011-3176  52659    URL
21917SERVER-OTHER Novell Groupwise HTTP response message parsing overflow (more info ...)attempted-user  2008-2703      
21952SERVER-OTHER ISC dhcpd discover hostname overflow attempt (more info ...)attempted-dos  2004-0460  10590    
23269FILE-OTHER Cisco WebEx recording integer overflow attempt (more info ...)attempted-user  2012-1336  52882    URL
23385SERVER-WEBAPP Novell GroupWise Messenger nmma.exe login memory corruption attempt (more info ...)attempted-admin    52056    URL
23755FILE-IDENTIFY Cisco Webex Player .wrf file magic detected (more info ...)misc-activity        
24239SERVER-WEBAPP Novell GroupWise Internet Agent content-length integer overflow attempt (more info ...)attempted-admin  2012-0271  55551    
24291SERVER-WEBAPP HP SiteScope APISiteScopeImpl information disclosure attempt (more info ...)web-application-activity  2012-3259  55269    
24292SERVER-WEBAPP HP SiteScope APISiteScopeImpl information disclosure attempt (more info ...)web-application-activity  2012-3259  55269    
24667EXPLOIT-KIT KaiXin exploit kit attack vector attempt (more info ...)attempted-user  2012-1889      
24668EXPLOIT-KIT KaiXin exploit kit attack vector attempt (more info ...)attempted-user  2012-1889      
24669EXPLOIT-KIT KaiXin exploit kit attack vector attempt (more info ...)attempted-user  2012-1889      
24670EXPLOIT-KIT KaiXin exploit kit attack vector attempt (more info ...)attempted-user  2012-1889      
24678FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1335      
24679FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1335      
24680FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1335      
24681FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1335      
24682FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1335      
24683FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1335      
24684FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1335      
24685FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1335      
24765SERVER-WEBAPP Novell File Reporter SRS request heap overflow attempt (more info ...)attempted-admin  2012-4956  56579    
24767SERVER-WEBAPP Novell File Reporter FSFUI request directory traversal attempt (more info ...)attempted-admin  2012-4959  56579    
24997FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1337      
24998FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1337      
24999FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1337      
25000FILE-OTHER Cisco WebEx recording format buffer overflow attempt (more info ...)attempted-user  2012-1337      
25303FILE-OTHER Cisco WebEx WRF memory corruption attempt (more info ...)attempted-user  2012-3939      
25304FILE-OTHER Cisco WebEx WRF memory corruption attempt (more info ...)attempted-user  2012-3939      
25334SERVER-OTHER Novell File Reporter record tag parsing buffer overflow attempt (more info ...)attempted-admin  2011-2220      
25335SERVER-OTHER Novell File Reporter record tag parsing buffer overflow attempt (more info ...)attempted-admin  2011-2220      
25336SERVER-OTHER Novell File Reporter record tag parsing buffer overflow attempt (more info ...)attempted-admin  2011-2220      
25337SERVER-OTHER Novell File Reporter record tag parsing buffer overflow attempt (more info ...)attempted-admin  2011-2220      
25338SERVER-OTHER Novell File Reporter record tag parsing buffer overflow attempt (more info ...)attempted-admin  2011-2220      
25339SERVER-OTHER Novell File Reporter record tag parsing buffer overflow attempt (more info ...)attempted-admin  2011-2220      
25340SERVER-OTHER Novell File Reporter record tag parsing buffer overflow attempt (more info ...)attempted-admin  2011-2220      
25535PROTOCOL-SERVICES Cisco Prime Lan Management rsh command execution attempt (more info ...)attempted-admin  2012-6392  57221    URL
25549SERVER-OTHER Novell eDirectory NCP stack buffer overflow attempt (more info ...)attempted-admin  2012-0432      URL
25550SERVER-OTHER Novell eDirectory NCP stack buffer overflow attempt (more info ...)attempted-admin  2012-0432      URL
26489BROWSER-OTHER Novell Messenger Client nim URI handler buffer overflow attempt (more info ...)attempted-user  2013-1085      URL
26490BROWSER-OTHER Novell Messenger Client nim URI handler buffer overflow attempt (more info ...)attempted-user  2013-1085      URL
26531MALWARE-OTHER Unix.Backdoor.Cdorked download attempt (more info ...)trojan-activity        URL
26532MALWARE-OTHER Unix.Backdoor.Cdorked download attempt (more info ...)trojan-activity        URL
27025MALWARE-OTHER UNIX.Trojan.Netweird.A file download attempt (more info ...)trojan-activity        URL
28263FILE-OTHER Cisco WebEx recording integer overflow attempt (more info ...)attempted-user  2012-1336  52882    URL
29041SERVER-WEBAPP Cisco Prime Data Center Network Manager processImageSave.jsp directory traversal attempt (more info ...)attempted-admin  2013-5486  62484    URL
29042SERVER-WEBAPP Cisco Prime Data Center Network Manager processImageSave.jsp directory traversal attempt (more info ...)attempted-admin  2013-5486  62484    URL
29141SERVER-WEBAPP Cisco Prime Data Center Network Manager FileUploadServlet arbitrary file upload attempt (more info ...)attempted-admin  2013-5486  62484    URL
29142SERVER-WEBAPP Cisco Prime Data Center Network Manager FileUploadServlet arbitrary file upload attempt (more info ...)attempted-admin  2013-5486  62484    URL
29441PROTOCOL-VOIP CISCO Telepresence VCS SIP denial of service attempt (more info ...)attempted-dos  2014-0662      
29536SERVER-OTHER Novell Client NetIdentity Agent remote arbitrary pointer dereference code execution attempt (more info ...)attempted-admin  2009-1350  34400    
29537SERVER-WEBAPP HP SiteScope APIMonitorImpl information disclosure attempt (more info ...)web-application-activity  2012-3259  55269    
29596SERVER-WEBAPP HP SiteScope soap request code execution attempt (more info ...)attempted-user  2013-2367  61506    
29597SERVER-WEBAPP HP SiteScope soap request code execution attempt (more info ...)attempted-user  2013-2367  61506    
29598SERVER-WEBAPP HP SiteScope soap call apipreferenceimpl security bypass attempt (more info ...)web-application-attack  2012-3261  55269    
29599SERVER-WEBAPP HP SiteScope soap call apipreferenceimpl security bypass attempt (more info ...)web-application-attack  2012-3261  55269    
29600SERVER-WEBAPP HP SiteScope soap call apipreferenceimpl security bypass attempt (more info ...)web-application-attack  2012-3261  55269    
29601SERVER-WEBAPP HP SiteScope soap call apipreferenceimpl security bypass attempt (more info ...)web-application-attack  2012-3261  55269    
29607SERVER-OTHER Novell ZENworks Handheld Management ZfHIPCND.exe buffer overflow attempt (more info ...)attempted-admin  2011-0742  46024    
29626SERVER-OTHER Novell ZENworks Handheld Management ZfHIPCND.exe buffer overflow attempt (more info ...)attempted-admin  2011-0742  46024    
29627SERVER-OTHER Novell ZENworks Handheld Management ZfHIPCND.exe buffer overflow attempt (more info ...)attempted-admin  2011-0742  46024    
29628SERVER-OTHER Novell ZENworks Handheld Management ZfHIPCND.exe buffer overflow attempt (more info ...)attempted-admin  2011-0742  46024    
29629SERVER-OTHER Novell ZENworks Handheld Management ZfHIPCND.exe buffer overflow attempt (more info ...)attempted-admin  2011-0742  46024    
29753SERVER-WEBAPP Novell Groupwise Messenger parameter memory corruption attempt (more info ...)attempted-admin        URL
30282PROTOCOL-VOIP Cisco IOS SIP header denial of service attempt (more info ...)attempted-dos  2014-2106      
30283PROTOCOL-VOIP Cisco IOS SIP header denial of service attempt (more info ...)attempted-dos  2014-2106      
30887SERVER-OTHER Cisco Tshell command injection attempt (more info ...)attempted-admin  2014-2170      URL
30888SERVER-OTHER Cisco Tshell command injection attempt (more info ...)attempted-admin  2014-2170      URL
30902FILE-OTHER Cisco Webex WRF heap corruption attempt (more info ...)attempted-user  2014-2135      URL
30903FILE-OTHER Cisco Webex WRF heap corruption attempt (more info ...)attempted-user  2014-2135      URL
30912FILE-OTHER Cisco Webex WRF heap corruption attempt (more info ...)attempted-user  2014-2135      URL
30913FILE-OTHER Cisco Webex WRF heap corruption attempt (more info ...)attempted-user  2014-2135      URL
30921FILE-OTHER Cisco WebEx Player atas32.dll memory overread attempt (more info ...)attempted-user  2014-2132      URL
30922FILE-OTHER Cisco WebEx Player atas32.dll memory overread attempt (more info ...)attempted-user  2014-2132      URL
30929SERVER-OTHER Cisco RV180 VPN CSRF attempt (more info ...)attempted-admin        
30931SERVER-OTHER Cisco RV180W remote file inclusion attempt (more info ...)attempted-admin  2014-2179      
30932FILE-OTHER Cisco WebEx WRF heap corruption attempt (more info ...)attempted-user  2014-2134      URL
30933SERVER-OTHER Cisco RV180 VPN remote code execution attempt (more info ...)attempted-admin  2014-2177      
30942FILE-OTHER Cisco Webex ARF Player LZW decompress memory corruption denial of service attempt (more info ...)attempted-dos  2014-2133      URL
30943FILE-OTHER Cisco Webex ARF Player LZW decompress memory corruption denial of service attempt (more info ...)attempted-dos  2014-2133      URL
31398PROTOCOL-VOIP Cisco Unified IP phone BVSMWeb portal attack attempt (more info ...)attempted-admin        
31451PROTOCOL-VOIP Cisco Unified IP phone BVSMWeb portal attack attempt (more info ...)attempted-admin  2014-3300      URL
31615OS-OTHER Cisco IOS EnergyWise malformed packet denial of service attempt (more info ...)denial-of-service  2014-3327      URL
31616OS-OTHER Cisco IOS EnergyWise malformed packet denial of service attempt (more info ...)denial-of-service  2014-3327      URL
31891SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
32101SERVER-WEBAPP Cisco ASA WebVPN login.html memory corruption attempt (more info ...)web-application-attack  2014-3392      URL
32107SERVER-WEBAPP Cisco ASA WebVPN directory traversal attempt (more info ...)web-application-attack  2014-3393      URL
32108SERVER-WEBAPP Cisco ASA WebVPN directory traversal attempt (more info ...)web-application-attack  2014-3393      URL
33074SERVER-WEBAPP ManageEngine Multiple Products WsDiscoveryServlet directory traversal attempt (more info ...)web-application-attack  2014-5302      
33075SERVER-WEBAPP ManageEngine Multiple Products WsDiscoveryServlet directory traversal attempt (more info ...)web-application-attack  2014-5302      
33076SERVER-WEBAPP ManageEngine Multiple Products WsDiscoveryServlet directory traversal attempt (more info ...)web-application-attack  2014-5302      
33229SERVER-WEBAPP Cisco Prime Services Catalog XML external entity injection attempt (more info ...)web-application-attack  2015-0581      URL
33871SERVER-WEBAPP Cisco TelePresence Video Communication Server authentication bypass attempt (more info ...)attempted-admin  2015-0653      URL
34104SERVER-WEBAPP Novell ZENworks Configuration Management directory traversal attempt (more info ...)web-application-attack  2015-0779      
34105SERVER-WEBAPP Novell ZENworks Configuration Management directory traversal attempt (more info ...)web-application-attack  2015-0779      
34106SERVER-WEBAPP Novell ZENworks Configuration Management directory traversal attempt (more info ...)web-application-attack  2015-0779      
34139SERVER-OTHER Novell ZenWorks configuration management file upload directory traversal attempt (more info ...)attempted-admin  2013-1080      URL
34180OS-OTHER Cisco Secure Desktop Applet command execution attempt (more info ...)attempted-user  2015-0691      
34364SERVER-WEBAPP Novell ZENworks Configuration Management rtrlet.class directory traversal attempt (more info ...)web-application-attack  2015-0783  74292    
34369SERVER-WEBAPP Cisco UCS Central command injection attempt (more info ...)attempted-admin  2015-0701  74491    URL
34602SERVER-WEBAPP Novell ZENworks Configuration Management rtrlet.class directory traversal attempt (more info ...)web-application-attack  2015-0783  74292    
34619SERVER-WEBAPP Novell ZENworks Configuration Management rtrlet.class directory traversal attempt (more info ...)web-application-attack  2015-0785  74288    
34620SERVER-WEBAPP Novell ZENworks Configuration Management rtrlet.class directory traversal attempt (more info ...)web-application-attack  2015-0785  74288    
34621SERVER-WEBAPP Novell ZENworks Configuration Management rtrlet.class directory traversal attempt (more info ...)web-application-attack  2015-0785  74288    
34823POLICY-OTHER HP SiteScope unspecified privilege escalation attempt (more info ...)policy-violation  2015-2120      URL
34937SERVER-OTHER Novell ZENworks Configuration Management preboot policy service stack buffer overflow attempt (more info ...)attempted-admin  2015-0786  74290    URL
35941SERVER-WEBAPP Cisco Integrated Management Controller and UCS Director directory traversal attempt (more info ...)web-application-attack  2015-6259      URL
36282POLICY-OTHER Cisco router Security Device Manager default banner (more info ...)policy-violation        URL
36903SERVER-OTHER Cisco ASA IKEv2 invalid fragment length heap buffer overflow attempt (more info ...)attempted-admin  2016-1287      URL
36913SERVER-WEBAPP Cisco WebEx Meetings Server command injection attempt (more info ...)web-application-attack  2015-0589  72493    URL
37414SERVER-OTHER Cisco NX-OS zero length DHCP VPN suboption denial of service attempt (more info ...)attempted-dos  2015-6393      URL
37426SERVER-OTHER Cisco NX-OS DHCP option parsing denial of service attempt (more info ...)attempted-dos  2015-6392      URL
37674SERVER-OTHER Cisco ASA IKEv1 invalid fragment length heap buffer overflow attempt (more info ...)attempted-admin  2016-1287      URL
37675SERVER-OTHER Cisco IOS invalid IKE fragment length memory corruption or exhaustion attempt (more info ...)attempted-admin  2016-6381      URL
37853SERVER-WEBAPP Cisco ACE A5 trace.vm command injection attempt (more info ...)web-application-attack  2016-1297      URL
38137SERVER-OTHER Cisco DPC2203 arbitrary code execution attempt (more info ...)attempted-admin        
38138SERVER-OTHER Cisco DPQ3925 denial of service attempt (more info ...)web-application-attack        URL
38139SERVER-OTHER Cisco DPQ3939 denial of service attempt (more info ...)web-application-attack        URL
38511SERVER-WEBAPP Novell Service Desk directory traversal attempt (more info ...)web-application-attack  2016-1593      URL
38543SERVER-WEBAPP Cisco UCS Central Web Framework remote file include attempt (more info ...)web-application-attack  2015-4286      URL
39118SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39119SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39120SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39121SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39122SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39123SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39124SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39125SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39126SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39127SERVER-WEBAPP Cisco Prime Network Analysis Module command injection attempt (more info ...)web-application-attack  2016-1388      URL
39303SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2016-1395      URL
39370SERVER-WEBAPP Cisco Prime Infrastructure API authentication bypass attempt (more info ...)attempted-user        URL
39678SERVER-WEBAPP Cisco UCS Performance Manager command injection attempt (more info ...)web-application-attack        URL
39679SERVER-WEBAPP Cisco UCS Performance Manager command injection attempt (more info ...)web-application-attack        URL
39706BROWSER-OTHER Novell Messenger Client folder name buffer overflow attempt (more info ...)attempted-user    52062    
39878SERVER-OTHER Cisco IOS truncated NTP packet processing denial of service attempt (more info ...)attempted-dos  2016-1478      URL
39885PROTOCOL-SNMP Cisco ASA SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2016-6366      URL
39936OS-SOLARIS XMDCP double-free attempt (more info ...)attempted-admin  2004-0368      
39994PROTOCOL-SNMP Cisco SG200 Series SNMP request via undocumented community string attempt (more info ...)attempted-admin  2016-1473      URL
40006SERVER-OTHER Cisco Small Business SPA3x/5x series denial of service attempt (more info ...)attempted-admin        URL
40049SERVER-OTHER Cisco IOS PPTP control message response information disclosure detected (more info ...)attempted-recon  2016-6398      URL
40220SERVER-OTHER Cisco IOS Group-Prime memory disclosure exfiltration attempt (more info ...)attempted-recon  2016-6415      URL
40221SERVER-OTHER Cisco IOS Group-Prime MD5 memory disclosure attempt (more info ...)attempted-recon  2016-6415      URL
40222SERVER-OTHER Cisco IOS Group-Prime SHA memory disclosure attempt (more info ...)attempted-recon  2016-6415      URL
40224SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
40225SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
40226SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
40227SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
40228SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
40229SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
40230SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
40231SERVER-WEBAPP Cisco ASA WebVPN auth_handle cross site scripting attempt (more info ...)web-application-attack  2014-2120  66290    URL
40240SERVER-WEBAPP Cisco WebEx Meetings Server config_dmz remote code execution attempt (more info ...)attempted-admin  2016-1482      URL
40275SERVER-WEBAPP Cisco ESA internal testing interface access attempt (more info ...)attempted-admin  2016-6406      URL
40298PROTOCOL-VOIP Cisco IOS malformed H.450 PER data out of bounds read attempt (more info ...)attempted-dos  2016-6384      URL
40303PROTOCOL-SCADA Cisco IOS CIP request parser out of bounds array access attempt (more info ...)attempted-dos  2016-6391      URL
40304PROTOCOL-SCADA Cisco IOS CIP request parser out of bounds array access attempt (more info ...)attempted-dos  2016-6391      URL
40343SERVER-OTHER Cisco NX-OS malformed BGP UPDATE denial of service attempt (more info ...)attempted-dos  2016-1454      URL
40498SERVER-WEBAPP Cisco ASA Crypto CA Server out of bounds read attempt (more info ...)web-application-attack        URL
40499SERVER-OTHER Cisco ASA NBSTAT response stack buffer overflow attempt (more info ...)attempted-admin  2016-6432      URL
40552SERVER-OTHER Cisco ESA lzw attachment parsing denial of service attempt (more info ...)attempted-dos  2016-6356      URL
40553SERVER-OTHER Cisco ESA uuencode attachment processing exception denial of service attempt (more info ...)attempted-dos  2016-1486      URL
40554SERVER-OTHER Cisco ESA uuencode attachment processing exception denial of service attempt (more info ...)attempted-dos  2016-1486      URL
40608SERVER-WEBAPP Joomla UsersController non-standard insecure account registration method access attempt (more info ...)attempted-admin  2016-8870      URL
40609SERVER-WEBAPP Joomla UsersController non-standard insecure account registration method access attempt (more info ...)attempted-admin  2016-8870      URL
40638PROTOCOL-VOIP Cisco Meeting Server SIP SDP media description buffer overflow attempt (more info ...)attempted-admin  2016-6448      URL
40767FILE-OTHER Cisco IOS-XE update directory traversal attempt (more info ...)attempted-admin        URL
40768FILE-OTHER Cisco IOS-XE update directory traversal attempt (more info ...)attempted-admin        URL
40769FILE-OTHER Cisco IOS-XE update directory traversal attempt (more info ...)attempted-admin        URL
40770FILE-OTHER Cisco IOS-XE update directory traversal attempt (more info ...)attempted-admin        URL
40877SERVER-OTHER Cisco Application Control Engine SSL handshake parsing denial of service attempt (more info ...)attempted-dos  2016-6399      URL
41195PROTOCOL-SNMP Cisco IP routing configuration manipulation via SNMP attempt (more info ...)policy-violation        URL
41356SERVER-WEBAPP Cisco Firepower Management Console 6.0 local file include attempt (more info ...)web-application-attack  2016-6435      URL
41407BROWSER-OTHER Cisco WebEx extension command execution attempt (more info ...)attempted-admin  2017-6753      URL
41408BROWSER-OTHER Cisco WebEx extension command execution attempt (more info ...)attempted-admin  2017-6753      URL
41446SERVER-WEBAPP Cisco Meraki default admin credentials attempt (more info ...)attempted-admin  2014-7999      URL
41538SERVER-WEBAPP Cisco ASA WebVPN memory corruption attempt (more info ...)attempted-admin  2017-3807      URL
41722SERVER-OTHER Cisco IOS Smart Install protocol backup config command attempt (more info ...)attempted-admin        URL
41723SERVER-OTHER Cisco IOS Smart Install protocol download config command attempt (more info ...)attempted-admin        URL
41724SERVER-OTHER Cisco IOS Smart Install protocol download image command attempt (more info ...)attempted-admin        URL
41725SERVER-OTHER Cisco IOS Smart Install protocol version command attempt (more info ...)attempted-admin  2018-0156      URL
41786SERVER-OTHER Cisco NetFlow Generation Appliance SCTP denial of service attempt (more info ...)attempted-dos  2017-3826      URL
41909SERVER-OTHER Cisco Software Cluster Management Protocol remote code execution attempt (more info ...)attempted-admin  2017-3881      URL
41910SERVER-OTHER Cisco Software Cluster Management Protocol remote code execution attempt (more info ...)attempted-admin  2017-3881      URL
42001SERVER-WEBAPP Cisco CWA and TES Client Manager Server directory traversal attempt (more info ...)web-application-attack  2017-3846      URL
42002SERVER-WEBAPP Cisco CWA and TES Client Manager Server directory traversal attempt (more info ...)web-application-attack  2017-3846      URL
42051SERVER-OTHER Cisco IOS autonomic networking discovery denial of service attempt (more info ...)attempted-dos  2017-3850      URL
42060SERVER-OTHER Cisco IOS DHCP client dummy XID denial of service attempt (more info ...)attempted-dos  2017-3864      URL
42061SERVER-WEBAPP Cisco IOS XE webui software upgrade command injection attempt (more info ...)web-application-attack  2017-3858      URL
42139SERVER-WEBAPP Cisco Wireless LAN Controller denial of service attempt (more info ...)attempted-dos  2017-3832      URL
42253OS-SOLARIS Solaris dtappgather local privilege escalation attempt (more info ...)attempted-admin        URL
42254OS-SOLARIS Solaris dtappgather local privilege escalation attempt (more info ...)attempted-admin        URL
42403SERVER-WEBAPP Trend Micro Threat Discovery Appliance cache_id command injection attempt (more info ...)web-application-attack  2016-8592  98343    
42404SERVER-WEBAPP Trend Micro Threat Discovery Appliance cache_id command injection attempt (more info ...)web-application-attack  2016-8592  98343    
42405SERVER-WEBAPP Trend Micro Threat Discovery Appliance cache_id command injection attempt (more info ...)web-application-attack  2016-8592  98343    
42489SERVER-OTHER Cisco Aironet Mobility Express PnP agent directory traversal attempt (more info ...)attempted-admin  2017-3873      URL
42493SERVER-OTHER Cisco RV Series Routers SSDP uuid stack buffer overflow attempt (more info ...)attempted-admin  2021-34730      URL
42923SERVER-WEBAPP Cisco Prime Collaboration ScriptMgr authentication bypass attempt (more info ...)attempted-admin  2017-6622      URL
43271SERVER-WEBAPP Cisco Prime Infrastructure XML external entity injection attempt (more info ...)web-application-attack  2017-6662      URL
43424PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6744      URL
43425PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6743      URL
43426PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6742      URL
43427PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6741      URL
43428PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6740      URL
43429PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6739      URL
43430PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6738      URL
43431PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6737      URL
43432PROTOCOL-SNMP Cisco IOS SNMP OID parsing stack buffer overflow attempt (more info ...)attempted-admin  2017-6736      URL
43456SERVER-WEBAPP Cisco Ultra Services Framework command injection attempt (more info ...)attempted-admin  2017-6714      URL
43628SERVER-WEBAPP Cisco Web Security Appliance https_proxy command injection attempt (more info ...)web-application-attack  2017-6746      URL
43629SERVER-WEBAPP Cisco Web Security Appliance https_proxy command injection attempt (more info ...)web-application-attack  2017-6746      URL
43630SERVER-WEBAPP Cisco Web Security Appliance https_proxy command injection attempt (more info ...)web-application-attack  2017-6746      URL
43631SERVER-WEBAPP Cisco Web Security Appliance https_proxy command injection attempt (more info ...)web-application-attack  2017-6746      URL
44005SERVER-WEBAPP Cisco DDR2200 ADSL gateway command injection attempt (more info ...)web-application-attack  2017-11588      URL
44006SERVER-WEBAPP Cisco DDR2200 ADSL gateway command injection attempt (more info ...)web-application-attack  2017-11588      URL
44007SERVER-WEBAPP Cisco DDR2200 ADSL gateway command injection attempt (more info ...)web-application-attack  2017-11588      URL
44008SERVER-WEBAPP Cisco DDR2200 ADSL gateway command injection attempt (more info ...)web-application-attack        URL
44063SERVER-WEBAPP Cisco Ultra Services Framework AutoVNF directory traversal attempt (more info ...)web-application-attack  2017-6708      URL
44125SERVER-WEBAPP Cisco Prime Collaboration logconfigtracer directory traversal attempt (more info ...)web-application-attack  2017-6621  98522    URL
44126SERVER-WEBAPP Cisco Prime Collaboration logconfigtracer directory traversal attempt (more info ...)web-application-attack  2017-6621  98522    URL
44127SERVER-WEBAPP Cisco Prime Collaboration logconfigtracer directory traversal attempt (more info ...)web-application-attack  2017-6621  98522    URL
44417SERVER-WEBAPP Cisco Customer Voice Portal MyAccountEditAction.do privilege escalation attempt (more info ...)attempted-admin  2017-12214      URL
44458PROTOCOL-SCADA Cisco IE2000 CIP get attributes all packet processing memory leak attempt (more info ...)attempted-dos  2017-12233      URL
44459PROTOCOL-SCADA Cisco IOS CIP forward open packet processing denial of service attempt (more info ...)attempted-dos  2022-20919      URL
44460SERVER-WEBAPP Cisco IOS XE Web UI resource path authentication bypass attempt (more info ...)attempted-admin  2017-12229      URL
44461SERVER-WEBAPP Cisco IOS XE Web UI resource path authentication bypass attempt (more info ...)attempted-admin  2017-12229      URL
44462SERVER-WEBAPP Cisco IOS XE Web UI rest path authentication bypass attempt (more info ...)attempted-admin  2017-12229      URL
44463SERVER-WEBAPP Cisco IOS XE Web UI rest path authentication bypass attempt (more info ...)attempted-admin  2017-12229      URL
44464SERVER-OTHER Cisco IOS IKEv2 session initialization denial of service attempt (more info ...)attempted-dos  2017-12237      URL
44498SERVER-WEBAPP Cisco License Manager ReportCSV directory traversal attempt (more info ...)web-application-attack  2017-12263      URL
44499SERVER-WEBAPP Cisco License Manager ReportCSV directory traversal attempt (more info ...)web-application-attack  2017-12263      URL
44500SERVER-WEBAPP Cisco License Manager ReportCSV directory traversal attempt (more info ...)web-application-attack  2017-12263      URL
44503SERVER-WEBAPP Cisco Adaptive Security Appliance direct authentication denial of service attempt (more info ...)attempted-dos  2017-12246      URL
44724SERVER-WEBAPP Cisco Firepower Smart Licensing command injection attempt (more info ...)web-application-attack  2017-12277      URL
44725PROTOCOL-SNMP Cisco Wireless LAN Controller clExtApDot11IfTable OID memory leak attempt (more info ...)attempted-dos  2017-12278      URL
45524FILE-OTHER Cisco WebEx Network Recording Player for ARF files dll-load exploit attempt (more info ...)attempted-user  2018-0104  102382    URL
45525FILE-OTHER Cisco WebEx Network Recording Player for ARF files dll-load exploit attempt (more info ...)attempted-user  2018-0104  102382    URL
45575SERVER-OTHER Cisco ASA VPN aggregateAuthDataHandler double free attempt (more info ...)attempted-admin  2018-0101      URL
45596SERVER-OTHER Cisco ASA VPN aggregateAuthDataHandler double free attempt (more info ...)attempted-admin  2018-0101      URL
45597INDICATOR-SHELLCODE Cisco ASA alloc_ch connection string (more info ...)shellcode-detect  2018-0101      URL
45623SERVER-WEBAPP Cisco RV132W and RV134W routers command injection attempt (more info ...)web-application-attack  2018-0125      URL
45731SERVER-WEBAPP Cisco Elastic Services Controller authentication bypass attempt (more info ...)attempted-user  2018-0121      URL
45975MALWARE-BACKDOOR Unix.Malware.Chaos backdoor trigger attempt (more info ...)trojan-activity        URL
46096SERVER-OTHER Cisco Smart Install init discovery message stack buffer overflow attempt (more info ...)attempted-admin  2018-0171      URL
46104SERVER-OTHER Cisco IOS DHCP relay agent information memory corruption attempt (more info ...)attempted-admin  2018-0172      URL
46105PROTOCOL-SNMP Cisco IOS SNMP natPoolRange OID denial of service attempt (more info ...)attempted-dos  2018-0160      URL
46110SERVER-OTHER Cisco ASR1001 IKEv2 memory leak attempt (more info ...)attempted-user        
46111SERVER-OTHER Cisco IOS Adaptive QoS message parsing stack buffer overflow attempt (more info ...)attempted-admin  2018-0151      URL
46119SERVER-OTHER Cisco IOS DHCP relay reply integer underflow attempt (more info ...)attempted-admin  2018-0173      URL
46120SERVER-OTHER Cisco IOS DHCP relay integer underflow attempt (more info ...)attempted-admin  2018-0174      URL
46125SERVER-OTHER Cisco IOS invalid IKEv1 payload denial of service attempt (more info ...)attempted-dos  2018-0159      URL
46386SERVER-WEBAPP Cisco IOS XE Web UI arbitrary file write attempt (more info ...)web-application-attack  2018-0196      URL
46492SERVER-WEBAPP Cisco Prime Infrastructure directory traversal attempt (more info ...)web-application-attack  2019-1821      URL
46493SERVER-WEBAPP Cisco Prime Infrastructure directory traversal attempt (more info ...)web-application-attack  2019-1821      URL
46494SERVER-WEBAPP Cisco Prime Infrastructure directory traversal attempt (more info ...)web-application-attack  2019-1821      URL
46496FILE-OTHER Cisco WebEx Recording Player memory corruption attempt (more info ...)attempted-user  2018-0264      URL
46497FILE-OTHER Cisco WebEx Recording Player memory corruption attempt (more info ...)attempted-user  2018-0264      URL
46498FILE-OTHER Cisco WebEx Recording Player memory corruption attempt (more info ...)attempted-user  2018-0264      URL
46499FILE-OTHER Cisco WebEx Recording Player memory corruption attempt (more info ...)attempted-user  2018-0264      URL
46738SERVER-WEBAPP Cisco DNA Center API directory traversal attempt (more info ...)web-application-attack  2018-0271      URL
46739SERVER-WEBAPP Cisco DNA Center API default login attempt (more info ...)default-login-attempt  2018-0222      URL
46749SERVER-OTHER Cisco Meeting Server configuration download attempt (more info ...)attempted-recon  2018-0263      
46750SERVER-OTHER Cisco Meeting Server user configuration download attempt (more info ...)attempted-recon  2018-0263      
46887SERVER-WEBAPP Cisco Network Services Orchestrator arbitrary command execution attempt (more info ...)attempted-admin  2018-0274      URL
46888SERVER-WEBAPP Cisco Network Services Orchestrator arbitrary command execution attempt (more info ...)attempted-admin  2018-0274      URL
46897SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt (more info ...)web-application-attack  2018-0296      URL
46992SERVER-WEBAPP Cisco NX-OS NX-API privilege escalation attempt (more info ...)attempted-admin  2018-0330      URL
46993SERVER-OTHER Cisco NX-OS Fabric Services Protocol denial of service attempt (more info ...)attempted-dos  2018-0310      URL
46994SERVER-OTHER Cisco NX-OS Fabric Services Protocol denial of service attempt (more info ...)attempted-dos  2018-0310      URL
46995SERVER-OTHER Cisco NX-OS Fabric Services Protocol heap buffer overflow attempt (more info ...)attempted-admin  2018-0312      URL
46996SERVER-OTHER Cisco NX-OS Fabric Services Protocol heap buffer overflow attempt (more info ...)attempted-admin  2018-0312      URL
47003SERVER-OTHER Cisco NX-OS Fabric Services Protocol stack buffer overflow attempt (more info ...)attempted-admin  2018-0314      URL
47004SERVER-OTHER Cisco NX-OS Fabric Services Protocol stack buffer overflow attempt (more info ...)attempted-admin  2018-0314      URL
47008SERVER-WEBAPP Cisco NX-OS NX-API ins_api command injection attempt (more info ...)web-application-attack  2022-20650      URL
47009SERVER-WEBAPP Cisco NX-OS NX-API cli_ascii command injection attempt (more info ...)web-application-attack  2018-0313      URL
47010SERVER-WEBAPP Cisco FX-OS mod_nuova stack buffer overflow attempt (more info ...)web-application-attack  2018-0298      URL
47011SERVER-OTHER Cisco NX-OS Fabric Services Protocol TLV out of bounds read attempt (more info ...)attempted-admin  2018-0304      URL
47012SERVER-OTHER Cisco NX-OS Fabric Services Protocol TLV out of bounds read attempt (more info ...)attempted-admin  2018-0304      URL
47013SERVER-OTHER Cisco NX-OS Fabric Services Protocol TLV integer overflow attempt (more info ...)attempted-admin  2018-0304      URL
47014SERVER-OTHER Cisco NX-OS Fabric Services Protocol TLV integer overflow attempt (more info ...)attempted-admin  2018-0304      URL
47078SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector command injection attempt (more info ...)web-application-attack        
47079SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector command injection attempt (more info ...)web-application-attack        
47080SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector command injection attempt (more info ...)web-application-attack        
47081SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector command injection attempt (more info ...)web-application-attack        
47166SERVER-WEBAPP Cisco UCS Director launcher.jsp cross site scripting attempt (more info ...)attempted-user  2018-0219      URL
47281SERVER-OTHER Cisco SD-WAN Solution default login attempt (more info ...)attempted-user  2018-0345      URL
47282SERVER-OTHER Cisco SD-WAN Solution default login attempt (more info ...)attempted-user  2018-0345      URL
47285SERVER-OTHER Cisco Policy Suite interface unauthenticated access attempt (more info ...)attempted-user  2018-0377      URL
47286SERVER-OTHER Cisco Policy Suite interface unauthenticated access attempt (more info ...)attempted-user  2018-0377      URL
47363FILE-OTHER Cisco WebEx Network Recording Player out of bounds write attempt (more info ...)attempted-user  2018-0379      URL
47364FILE-OTHER Cisco WebEx Network Recording Player out of bounds write attempt (more info ...)attempted-user  2018-0379      URL
47380MALWARE-OTHER Unix.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
47381MALWARE-OTHER Unix.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
47394FILE-OTHER Cisco WebEx Network Recording Player out of bounds write attempt (more info ...)attempted-user  2018-0379      URL
47395FILE-OTHER Cisco WebEx Network Recording Player out of bounds write attempt (more info ...)attempted-user  2018-0379      URL
47571SERVER-WEBAPP Cisco Web Security Appliance proxy denial of service attempt (more info ...)attempted-dos  2018-0410      URL
47572SERVER-WEBAPP Cisco Web Security Appliance proxy denial of service attempt (more info ...)attempted-dos  2018-0410      URL
47573SERVER-WEBAPP Cisco Web Security Appliance proxy denial of service attempt (more info ...)attempted-dos  2018-0410      URL
47679SERVER-WEBAPP Cisco TelePresence command injection attempt (more info ...)web-application-attack  2015-0713      URL
47680SERVER-WEBAPP Cisco TelePresence command injection attempt (more info ...)web-application-attack  2015-0713      URL
47681SERVER-WEBAPP Cisco TelePresence command injection attempt (more info ...)web-application-attack  2015-0713      URL
47698SERVER-WEBAPP Cisco Integrated Management Controller command injection attempt (more info ...)web-application-attack  2020-3371      URL
47704SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2018-0424      URL
47705SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2018-0424      URL
47706SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2018-0424      URL
47707SERVER-OTHER Cisco RV Series Router information disclosure attempt (more info ...)attempted-recon  2018-0425      URL
47709SERVER-WEBAPP Cisco RV Series Routers arbitrary file read attempt (more info ...)web-application-attack  2018-0426      URL
47710SERVER-WEBAPP Cisco RV Series Router buffer overflow attempt (more info ...)attempted-user  2018-0423      URL
47711SERVER-WEBAPP Cisco RV Series Router buffer overflow attempt (more info ...)attempted-user  2018-0423      URL
47713SERVER-WEBAPP Cisco Data Center Network Manager command injection attempt (more info ...)web-application-attack  2018-0440      URL
47714SERVER-WEBAPP Cisco Data Center Network Manager command injection attempt (more info ...)web-application-attack  2018-0440      URL
47715SERVER-WEBAPP Cisco Data Center Network Manager command injection attempt (more info ...)web-application-attack  2018-0440      URL
47870MALWARE-OTHER Unix.Miner.Xbash variant dropped bash script (more info ...)trojan-activity        URL
47871MALWARE-OTHER Unix.Miner.Xbash variant dropped bash script (more info ...)trojan-activity        URL
47872MALWARE-OTHER Unix.Miner.Xbash variant dropped bash script (more info ...)trojan-activity        URL
47873MALWARE-OTHER Unix.Miner.Xbash variant dropped bash script (more info ...)trojan-activity        URL
47878FILE-OTHER Cisco WebEx Network Recording Player stack buffer overflow attempt (more info ...)attempted-user  2018-15422      URL
47879FILE-OTHER Cisco WebEx Network Recording Player stack buffer overflow attempt (more info ...)attempted-user  2018-15422      URL
47893SERVER-WEBAPP Cisco IOS XE Web UI denial of service attempt (more info ...)attempted-dos  2018-0469      URL
47894SERVER-WEBAPP Cisco IOS XE Web UI denial of service attempt (more info ...)attempted-dos  2018-0469      URL
47916SERVER-WEBAPP Cisco IOS XE denial of service attempt (more info ...)attempted-dos  2018-0191      URL
48015SERVER-WEBAPP Cisco Prime Infrastructure arbitrary JSP file upload attempt (more info ...)attempted-admin  2018-15379      URL
48023SERVER-WEBAPP Cisco DNA Center unauthenticated user creation attempt (more info ...)attempted-admin  2018-0448      URL
48201SERVER-OTHER Cisco Wireless LAN Controller CAPWAP denial of service attempt (more info ...)attempted-dos  2018-0443      URL
48204SERVER-OTHER Cisco Wireless LAN Controller CAPWAP information disclosure attempt (more info ...)attempted-recon  2018-0442      URL
48357SERVER-WEBAPP Cisco Energy Management Suite external executeScript attempt (more info ...)attempted-user  2018-15445      URL
48358SERVER-WEBAPP Cisco Stealthwatch Management Console authentication bypass attempt (more info ...)attempted-user  2018-15394      URL
48572MALWARE-OTHER Unix.Trojan.Fastcash download attempt (more info ...)trojan-activity        URL
48938MALWARE-OTHER Unix.Rocke.Evasion variant dropped bash script (more info ...)trojan-activity        URL
48939MALWARE-OTHER Unix.Rocke.Evasion variant dropped bash script (more info ...)trojan-activity        URL
48946SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2019-1652      URL
48947SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2019-1652      URL
48948SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2019-1652      URL
48949SERVER-WEBAPP Cisco RV Series Routers information disclosure attempt (more info ...)attempted-recon  2019-1653      URL
48950FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1637      URL
48951FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1637      URL
48952FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1638      URL
48953FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1638      URL
48954FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1639      URL
48955FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1639      URL
48956FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1640      URL
48957FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1640      URL
48958FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1927      URL
48959FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1927      URL
48960BROWSER-OTHER Cisco Webex Teams command line injection attempt (more info ...)attempted-user  2019-1939      URL
48961BROWSER-OTHER Cisco Webex Teams command line injection attempt (more info ...)attempted-user  2019-1939      URL
49240SERVER-WEBAPP Cisco Prime Collaboration Assurance unauthorized access attempt (more info ...)attempted-user  2019-1662      URL
49296SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2019-1843      URL
49334SERVER-OTHER Cisco NX-OS Fabric Services Protocol stack buffer overflow attempt (more info ...)attempted-admin  2019-1616      URL
49335SERVER-OTHER Cisco NX-OS Fabric Services Protocol stack buffer overflow attempt (more info ...)attempted-admin  2019-1616      URL
49336SERVER-OTHER Cisco FXOS and NX-OS LDAP denial of service attempt (more info ...)attempted-dos  2019-1598      URL
49339SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15440      URL
49340SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15440      URL
49341SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15463      URL
49342SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15463      URL
49343SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15463      URL
49344SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15463      URL
49345SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15463      URL
49346SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15463      URL
49347SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15463      URL
49348SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)attempted-user  2018-15463      URL
49349SERVER-WEBAPP Cisco WebEx Meeting Server cross site scripting attempt (more info ...)attempted-user  2019-1655      URL
49350SERVER-WEBAPP Cisco NX-OS System Software NX-API command injection attempt (more info ...)attempted-user  2022-20650      URL
49509SERVER-WEBAPP Cisco IP Phone web interface authorization bypass attempt (more info ...)web-application-attack  2019-1764      URL
49510SERVER-WEBAPP Cisco IP Phone web interface directory traversal attempt (more info ...)web-application-attack  2019-1766      URL
49511SERVER-WEBAPP Cisco IP Phone web interface stack buffer overflow attempt (more info ...)attempted-admin  2019-1716      URL
49588SERVER-WEBAPP Cisco IOS XE webui debugBundle command injection attempt (more info ...)web-application-attack  2019-1753      URL
49589SERVER-WEBAPP Cisco IOS XE webui debugBundle command injection attempt (more info ...)web-application-attack  2019-1753      URL
49590SERVER-WEBAPP Cisco IOS XE webui debugBundle command injection attempt (more info ...)web-application-attack  2019-1753      URL
49591SERVER-WEBAPP Cisco IOS XE webui directory traversal attempt (more info ...)web-application-attack  2019-1743      URL
49608SERVER-WEBAPP Cisco IOS XE webui execPython access attempt (more info ...)attempted-admin  2019-1756      URL
49609SERVER-WEBAPP Cisco IOS XE webui cdp resource command injection attempt (more info ...)web-application-attack  2019-1755      URL
49610SERVER-WEBAPP Cisco IOS XE webui dhcp resource command injection attempt (more info ...)web-application-attack  2019-1755      URL
49611SERVER-WEBAPP Cisco IOS XE webui information disclosure attempt (more info ...)attempted-recon  2019-1742      URL
49614SERVER-WEBAPP Cisco IOS XE webui rathrottler command injection attempt (more info ...)web-application-attack  2019-1754      URL
49615SERVER-WEBAPP Cisco IOS XE webui rathrottler command injection attempt (more info ...)web-application-attack  2019-1754      URL
49616SERVER-WEBAPP Cisco IOS XE webui rathrottler command injection attempt (more info ...)web-application-attack  2019-1754      URL
49617FILE-OTHER Unix systemd-journald memory corruption attempt (more info ...)attempted-admin  2018-16865      URL
49618FILE-OTHER Unix systemd-journald memory corruption attempt (more info ...)attempted-admin  2018-16865      URL
49619SERVER-WEBAPP Cisco RV Series Routers information disclosure attempt (more info ...)attempted-recon  2019-1653      URL
49858PROTOCOL-VOIP Cisco VCS exponential XML entity expansion attack attempt (more info ...)attempted-dos  2019-1721      URL
49859SERVER-WEBAPP Cisco Wireless LAN Controller cross site request forgery attempt (more info ...)web-application-attack  2019-1797      URL
49866SERVER-WEBAPP Cisco Wireless LAN Controller denial of service attempt (more info ...)attempted-dos  2018-0248      URL
49867SERVER-WEBAPP Cisco Wireless LAN Controller denial of service attempt (more info ...)attempted-dos  2018-0248      URL
49879SERVER-OTHER Cisco Wireless LAN Controller IAPP message denial of service attempt (more info ...)attempted-dos  2019-1800      URL
49986SERVER-WEBAPP Cisco Prime Infrastructure arbitrary JSP file upload attempt (more info ...)attempted-admin  2019-1823      URL
49990PROTOCOL-VOIP Cisco IP Phone malformed SIP presence information data denial of service attempt (more info ...)attempted-dos  2019-1635      URL
49992SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)web-application-attack  2020-3367      URL
49993SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)web-application-attack  2020-3367      URL
49994SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)web-application-attack  2020-3367      URL
49995SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)web-application-attack  2020-3367      URL
49996SERVER-WEBAPP Cisco ASA secure desktop login denial of service attempt (more info ...)attempted-dos  2018-15388      URL
49997SERVER-WEBAPP Cisco RV Series Routers session hijack attempt (more info ...)attempted-admin  2019-1724      URL
49998SERVER-WEBAPP Cisco Adaptive Security Appliance admin command interface access attempt (more info ...)attempted-admin  2022-20828      URL
49999SERVER-WEBAPP Cisco Adaptive Security Appliance admin command interface access attempt (more info ...)attempted-admin  2022-20828      URL
50037SERVER-WEBAPP Cisco Elastic Services Controller authentication bypass attempt (more info ...)attempted-user  2019-1867      URL
50117SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2019-1862      URL
50118SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2019-1862      URL
50131PROTOCOL-SNMP Cisco Small Business Series Switches SNMP denial of service attempt (more info ...)attempted-dos  2019-1806      URL
50132FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1929      URL
50133FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1929      URL
50134SERVER-WEBAPP Cisco Video Surveillance Manager directory traversal attempt (more info ...)web-application-attack  2019-1717      URL
50135SERVER-WEBAPP Cisco Video Surveillance Manager directory traversal attempt (more info ...)web-application-attack  2019-1717      URL
50136SERVER-WEBAPP Cisco Video Surveillance Manager directory traversal attempt (more info ...)web-application-attack  2019-1717      URL
50285MALWARE-OTHER Unix.Miner.Decred additional payload download attempt (more info ...)trojan-activity        URL
50286MALWARE-OTHER Unix.Miner.Decred additional payload download attempt (more info ...)trojan-activity        URL
50287MALWARE-OTHER Unix.Miner.Decred additional payload download attempt (more info ...)trojan-activity        URL
50288MALWARE-OTHER Unix.Miner.Decred additional payload download attempt (more info ...)trojan-activity        URL
50289MALWARE-OTHER Unix.Miner.Decred additional payload download attempt (more info ...)trojan-activity        URL
50290MALWARE-OTHER Unix.Miner.Decred additional payload download attempt (more info ...)trojan-activity        URL
50291MALWARE-OTHER Unix.Miner.Decred additional payload download attempt (more info ...)trojan-activity        URL
50292MALWARE-OTHER Unix.Miner.Decred additional payload download attempt (more info ...)trojan-activity        URL
50320SERVER-OTHER Cisco Unified Communications Manager denial of service attempt (more info ...)attempted-dos  2019-1845      URL
50335SERVER-WEBAPP Cisco Industrial Network Director remote code execution attempt (more info ...)attempted-admin  2023-20036      URL
50427SERVER-WEBAPP Cisco IOS XE Web UI cross site request forgery attempt (more info ...)web-application-attack  2019-1904      URL
50457MALWARE-TOOLS Unix.Downloader.HiddenWasp initial deployment script download attempt (more info ...)trojan-activity        URL
50458MALWARE-TOOLS Unix.Downloader.HiddenWasp initial deployment script download attempt (more info ...)trojan-activity        URL
50469SERVER-WEBAPP Cisco RV Series Routers denial of service attempt (more info ...)attempted-dos  2019-1843      URL
50470SERVER-WEBAPP Cisco RV Series Routers denial of service attempt (more info ...)attempted-dos  2019-1843      URL
50471SERVER-WEBAPP Cisco RV Series Routers denial of service attempt (more info ...)attempted-dos  2019-1843      URL
50472SERVER-WEBAPP Cisco RV Series Routers denial of service attempt (more info ...)attempted-dos  2019-1843      URL
50485SERVER-WEBAPP Cisco Prime Service Catalog cross site scripting attempt (more info ...)attempted-user  2019-1874      URL
50486SERVER-WEBAPP Cisco Prime Service Catalog cross site scripting attempt (more info ...)attempted-user  2019-1874      URL
50487SERVER-WEBAPP Cisco Prime Service Catalog cross site scripting attempt (more info ...)attempted-user  2019-1874      URL
50488SERVER-WEBAPP Cisco Prime Service Catalog cross site scripting attempt (more info ...)attempted-user  2019-1874      URL
50489SERVER-WEBAPP Cisco Prime Service Catalog cross site request forgery attempt (more info ...)attempted-user  2019-1874      URL
50492SERVER-WEBAPP Cisco SD-WAN Solution command injection attempt (more info ...)web-application-attack  2019-1624      URL
50512SERVER-WEBAPP Cisco Data Center Network Manager authentication bypass attempt (more info ...)attempted-admin  2019-1619      URL
50513SERVER-WEBAPP Cisco Data Center Network Manager arbitrary WAR file upload attempt (more info ...)attempted-admin  2019-1620      URL
50514SERVER-WEBAPP Cisco Data Center Network Manager arbitrary file download attempt (more info ...)attempted-recon  2019-1621      URL
50515SERVER-WEBAPP Cisco Data Center Network Manager information disclosure attempt (more info ...)attempted-recon  2019-1622      URL
50622SERVER-WEBAPP Cisco Web Security Appliance denial of service attempt (more info ...)attempted-dos  2019-1884      URL
50637SERVER-WEBAPP Cisco Small Business Series Switches denial of service attempt (more info ...)attempted-dos  2019-1891      URL
50650SERVER-WEBAPP Cisco Enterprise NFV command injection attempt (more info ...)web-application-attack  2021-1421      URL
50651SERVER-WEBAPP Cisco Enterprise NFV command injection attempt (more info ...)web-application-attack  2021-1421      URL
50652SERVER-WEBAPP Cisco Enterprise NFV command injection attempt (more info ...)web-application-attack  2021-1421      URL
50653SERVER-WEBAPP Cisco Enterprise NFV command injection attempt (more info ...)web-application-attack  2021-1421      URL
50794PUA-OTHER Unix.Trojan.CoinMiner attempted download (more info ...)trojan-activity        URL
50850MALWARE-OTHER Unix.Trojan.EvilGnome variant download attempt (more info ...)trojan-activity        URL
50851MALWARE-OTHER Unix.Trojan.EvilGnome variant download attempt (more info ...)trojan-activity        URL
50903SERVER-WEBAPP Cisco UCS Director command injection attempt (more info ...)web-application-attack  2019-1936      URL
50904FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1925      URL
50905FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1925      URL
50906FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1928      URL
50907FILE-OTHER Cisco WebEx Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-1928      URL
51164SERVER-WEBAPP Cisco Integrated Management Controller Redfish API command injection attempt (more info ...)web-application-attack  2019-1885      URL
51173SERVER-WEBAPP Cisco UCS Director authentication bypass attempt (more info ...)attempted-admin  2019-1974      URL
51180SERVER-OTHER Cisco Integrated Management Controller IPMI command injection attempt (more info ...)attempted-admin  2019-1634      URL
51187SERVER-WEBAPP Cisco Integrated Management Controller buffer overflow attempt (more info ...)attempted-admin  2019-1871      URL
51188SERVER-WEBAPP Cisco Integrated Management Controller command injection attempt (more info ...)web-application-attack  2019-1864      URL
51189SERVER-WEBAPP Cisco Integrated Management Controller command injection attempt (more info ...)web-application-attack  2019-1864      URL
51193SERVER-WEBAPP Cisco Integrated Management Controller command injection attempt (more info ...)web-application-attack  2019-1896      URL
51194SERVER-WEBAPP Cisco Integrated Management Controller command injection attempt (more info ...)web-application-attack  2019-1896      URL
51195SERVER-WEBAPP Cisco Integrated Management Controller command injection attempt (more info ...)web-application-attack  2019-1896      URL
51198SERVER-WEBAPP Cisco Integrated Management Controller denial of service attempt (more info ...)attempted-dos  2019-1900      URL
51199SERVER-WEBAPP Cisco Integrated Management Controller denial of service attempt (more info ...)attempted-dos  2019-1900      URL
51201SERVER-WEBAPP Cisco Integrated Management Controller authentication bypass attempt (more info ...)attempted-admin  2019-1907      URL
51293SERVER-WEBAPP Cisco 220 Series Smart Switches stack buffer overflow attempt (more info ...)attempted-admin  2019-1913      URL
51294SERVER-WEBAPP Cisco 220 Series Smart Switches stack buffer overflow attempt (more info ...)attempted-admin  2019-1913      URL
51295SERVER-WEBAPP Cisco 220 Series Smart Switches stack buffer overflow attempt (more info ...)attempted-admin  2019-1913      URL
51306SERVER-WEBAPP Cisco 220 Series Smart Switches command injection attempt (more info ...)web-application-attack  2021-1541      URL
51307SERVER-WEBAPP Cisco 220 Series Smart Switches command injection attempt (more info ...)web-application-attack  2021-1541      URL
51308SERVER-WEBAPP Cisco 220 Series Smart Switches command injection attempt (more info ...)web-application-attack  2021-1541      URL
51355SERVER-WEBAPP Cisco IOS XE REST API information disclosure attempt (more info ...)attempted-recon  2019-12643      URL
51536MALWARE-OTHER Unix.Trojan.Agent IoT backdoor download (more info ...)trojan-activity        URL
51582SERVER-WEBAPP HP SiteScope APIMonitorImpl information disclosure attempt (more info ...)web-application-activity  2012-3259  55269    
51622SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2020-3229      URL
51623SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2020-3229      URL
51624SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2020-3229      URL
51625SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2020-3229      URL
51705SERVER-WEBAPP Cisco Firepower Management Center directory traversal attempt (more info ...)web-application-attack  2019-12689      URL
51706SERVER-WEBAPP Cisco Firepower Management Center directory traversal attempt (more info ...)web-application-attack  2019-12689      URL
51707SERVER-WEBAPP Cisco Firepower Management Center directory traversal attempt (more info ...)web-application-attack  2019-12689      URL
51708SERVER-WEBAPP Cisco Firepower Management Center command injection attempt (more info ...)web-application-attack  2019-12688      URL
51709SERVER-WEBAPP Cisco Firepower Management Center command injection attempt (more info ...)web-application-attack  2019-12688      URL
51710SERVER-WEBAPP Cisco Firepower Management Center command injection attempt (more info ...)web-application-attack  2019-12688      URL
51711SERVER-WEBAPP Cisco Firepower Management Center command injection attempt (more info ...)web-application-attack  2019-12688      URL
51713SERVER-WEBAPP Cisco WebVPN denial of service attempt (more info ...)attempted-dos  2019-12698      URL
51716SERVER-WEBAPP Cisco Firepower Management Center command injection attempt (more info ...)web-application-attack  2019-12690      URL
51717SERVER-WEBAPP Cisco Firepower Management Center command injection attempt (more info ...)web-application-attack  2019-12690      URL
51718SERVER-WEBAPP Cisco Firepower Management Center command injection attempt (more info ...)web-application-attack  2019-12690      URL
51719SERVER-WEBAPP Cisco Firepower Management Center command injection attempt (more info ...)web-application-attack  2019-12690      URL
51728SERVER-WEBAPP Cisco WebVPN cross site scripting attempt (more info ...)attempted-user  2019-12695      URL
51729SERVER-WEBAPP Cisco WebVPN cross site scripting attempt (more info ...)attempted-user  2019-12695      URL
51890SERVER-WEBAPP Cisco SPA100 Series analog telephone adapters buffer overflow attempt (more info ...)attempted-admin  2019-15252      URL
51891SERVER-WEBAPP Cisco SPA100 Series analog telephone adapters buffer overflow attempt (more info ...)attempted-admin  2019-15252      URL
51892SERVER-WEBAPP Cisco SPA100 Series analog telephone adapters buffer overflow attempt (more info ...)attempted-admin  2019-15252      URL
51893SERVER-WEBAPP Cisco SPA100 Series analog telephone adapters buffer overflow attempt (more info ...)attempted-admin  2019-15252      URL
51894SERVER-WEBAPP Cisco SPA100 Series analog telephone adapters buffer overflow attempt (more info ...)attempted-admin  2019-15252      URL
51895SERVER-WEBAPP Cisco SPA100 Series analog telephone adapters buffer overflow attempt (more info ...)attempted-admin  2019-15252      URL
51900SERVER-WEBAPP Cisco Small Business Switches cross site scripting attempt (more info ...)attempted-user  2019-12636      URL
51901SERVER-WEBAPP Cisco Small Business Switches denial of service attempt (more info ...)attempted-dos  2019-12636      URL
51902SERVER-WEBAPP Cisco Small Business Switches cross site scripting attempt (more info ...)attempted-user  2019-12636      URL
51903SERVER-WEBAPP Cisco Small Business Switches cross site scripting attempt (more info ...)attempted-user  2019-12636      URL
51904SERVER-WEBAPP Cisco Small Business Switches cross site scripting attempt (more info ...)attempted-user  2019-12636      URL
51905SERVER-WEBAPP Cisco Small Business Switches cross site scripting attempt (more info ...)attempted-user  2019-12636      URL
51906SERVER-WEBAPP Cisco Small Business Switches cross site scripting attempt (more info ...)attempted-user  2019-12636      URL
51907SERVER-WEBAPP Cisco Small Business Switches cross site scripting attempt (more info ...)attempted-user  2019-12636      URL
52102FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15283      URL
52103FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15283      URL
52104FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15284      URL
52105FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15284      URL
52106FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15285      URL
52107FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15285      URL
52108FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15286      URL
52109FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15286      URL
52110FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15287      URL
52111FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2019-15287      URL
52119SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2019-15957      URL
52120SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2019-15957      URL
52121SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2019-15957      URL
52122SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2019-15957      URL
52126SERVER-WEBAPP Cisco Wireless LAN Controller denial of service attempt (more info ...)attempted-dos  2019-15276      URL
52129SERVER-WEBAPP Cisco Prime Infrastructure directory traversal attempt (more info ...)attempted-admin  2019-15958      URL
52525SERVER-WEBAPP Cisco Data Center Network Manager XML external entity injection attempt (more info ...)web-application-attack  2019-15983      URL
52526SERVER-WEBAPP Cisco Data Center Network Manager XML external entity injection attempt (more info ...)web-application-attack  2019-15983      URL
52527SERVER-WEBAPP Cisco Data Center Network Manager XML external entity injection attempt (more info ...)web-application-attack  2019-15983      URL
52528SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      URL
52529SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      URL
52530SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      URL
52531SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      URL
52532SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      URL
52533SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      
52534SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      
52535SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      
52536SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      URL
52537SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15980      URL
52538SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15981      URL
52539SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15981      URL
52540SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15981      URL
52541SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15982      URL
52542SERVER-WEBAPP Cisco Data Center Network Manager displayServerInfos information disclosure attempt (more info ...)web-application-attack  2019-15982      URL
52545SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2019-15984      URL
52546SERVER-WEBAPP Cisco Data Center Network Manager LanFabricImpl createLanFabric command injection attempt (more info ...)web-application-attack  2019-15978      URL
52547SERVER-WEBAPP Cisco Data Center Network Manager SanWS importTS arbitrary file upload attempt (more info ...)web-application-attack  2019-15979      URL
52555SERVER-WEBAPP Cisco Webex Video Mesh Node command injection attempt (more info ...)web-application-attack  2019-16005      URL
52627SERVER-WEBAPP Cisco Firepower Management Center LDAP authentication bypass attempt (more info ...)attempted-user  2019-16028      URL
52628SERVER-WEBAPP Cisco Firepower Management Center LDAP authentication bypass attempt (more info ...)attempted-user  2019-16028      URL
52629SERVER-WEBAPP Cisco Firepower Management Center LDAP authentication bypass attempt (more info ...)attempted-user  2019-16028      URL
52630SERVER-WEBAPP Cisco Firepower Management Center LDAP authentication bypass attempt (more info ...)attempted-user  2019-16028      URL
52631SERVER-WEBAPP Cisco Firepower Management Center LDAP authentication bypass attempt (more info ...)attempted-user  2019-16028      URL
52632SERVER-WEBAPP Cisco Firepower Management Center LDAP authentication bypass attempt (more info ...)attempted-user  2019-16028      URL
52633SERVER-OTHER Cisco IOS EVPN NLRI parsing denial of service attempt (more info ...)attempted-dos  2019-16023      URL
52643SERVER-WEBAPP Cisco Smart Software Manager denial of service attempt (more info ...)attempted-dos  2019-16029      URL
52644SERVER-WEBAPP Cisco Smart Software Manager denial of service attempt (more info ...)attempted-dos  2019-16029      URL
52645PROTOCOL-SNMP Cisco IOS IS-IS SNMP denial of service attempt (more info ...)attempted-dos  2019-16027      URL
52646PROTOCOL-SNMP Cisco IOS IS-IS SNMP denial of service attempt (more info ...)attempted-dos  2019-16027      URL
52647PROTOCOL-SNMP Cisco IOS IS-IS SNMP denial of service attempt (more info ...)attempted-dos  2019-16027      URL
52648PROTOCOL-SNMP Cisco IOS IS-IS SNMP denial of service attempt (more info ...)attempted-dos  2019-16027      URL
52649PROTOCOL-SNMP Cisco IOS IS-IS SNMP denial of service attempt (more info ...)attempted-dos  2019-16027      URL
52825MALWARE-OTHER Unix.Trojan.Muhstik variant binary download attempt (more info ...)trojan-activity        URL
52826MALWARE-OTHER Unix.Trojan.Muhstik variant binary download attempt (more info ...)trojan-activity        URL
52996SERVER-WEBAPP Cisco Small Business Series Switches information disclosure attempt (more info ...)attempted-recon  2019-15993      URL
52997SERVER-WEBAPP Cisco Small Business Series Switches cross site scripting attempt (more info ...)attempted-user  2019-15993      URL
52998SERVER-WEBAPP Cisco Small Business Series Switches denial of service attempt (more info ...)attempted-dos  2020-3147      URL
53131MALWARE-OTHER Win.Trojan.Syscon variant payload download attempt (more info ...)trojan-activity        
53132MALWARE-OTHER Win.Trojan.Syscon variant payload download attempt (more info ...)trojan-activity        URL
53139MALWARE-OTHER Win.Trojan.Syscon variant payload download attempt (more info ...)trojan-activity        URL
53168SERVER-WEBAPP Cisco Unified Contact Center Express arbitrary JSP file upload attempt (more info ...)attempted-admin  2019-1888      URL
53175SERVER-WEBAPP Cisco Data Center Network Manager cross site request forgery attempt (more info ...)attempted-user  2020-3114      URL
53176SERVER-WEBAPP Cisco Data Center Network Manager cross site request forgery attempt (more info ...)attempted-user  2020-3114      URL
53384FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2020-3127      URL
53385FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2020-3127      URL
53386FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2020-3128      URL
53387FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2020-3128      URL
53388SERVER-WEBAPP Cisco Prime Network Registrar cross site request forgery attempt (more info ...)attempted-user  2020-3148      URL
53389SERVER-WEBAPP Cisco Prime Network Registrar cross site request forgery attempt (more info ...)attempted-user  2020-3148      URL
53390SERVER-WEBAPP Cisco Prime Network Registrar cross site request forgery attempt (more info ...)attempted-user  2020-3148      URL
53391SERVER-WEBAPP Cisco Prime Network Registrar cross site request forgery attempt (more info ...)attempted-user  2020-3148      URL
53470SERVER-OTHER Cisco IOS EnergyWise heap buffer overflow attempt (more info ...)attempted-admin  2017-3860      URL
53471SERVER-OTHER Cisco IOS EnergyWise integer underflow attempt (more info ...)attempted-admin  2017-3862      URL
53472SERVER-OTHER Cisco IOS EnergyWise out of bounds read attempt (more info ...)attempted-admin  2017-3863      URL
53482SERVER-WEBAPP Cisco SD-WAN vManage cross site scripting attempt (more info ...)attempted-user  2019-16010      URL
53483SERVER-WEBAPP Cisco SD-WAN vManage cross site scripting attempt (more info ...)attempted-user  2019-16010      URL
53497SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2020-3211      URL
53498SERVER-WEBAPP Cisco IOS XE Web UI file upload directory traversal attempt (more info ...)attempted-user  2020-3218      URL
53499SERVER-WEBAPP Cisco IOS XE Web UI file upload remote code execution attempt (more info ...)attempted-user  2020-3218      URL
53500SERVER-WEBAPP Cisco IOS XE Web UI file upload remote code execution attempt (more info ...)attempted-user  2020-3218      URL
53501SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2021-1220      URL
53502SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2021-1220      URL
53503SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2020-3212      URL
53527MALWARE-OTHER Unix.Exploit.Lotoor-7643871-0 download attempt (more info ...)trojan-activity        URL
53528MALWARE-OTHER Unix.Exploit.Lotoor-7643871-0 download attempt (more info ...)trojan-activity        URL
53613MALWARE-OTHER PUA.Unix.Adware.Mobidash-7653096-0 download attempt (more info ...)trojan-activity        URL
53614MALWARE-OTHER PUA.Unix.Adware.Mobidash-7653096-0 download attempt (more info ...)trojan-activity        URL
53660FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2020-3194      URL
53661FILE-OTHER Cisco Webex Network Recording Player memory corruption attempt (more info ...)attempted-user  2020-3194      URL
53666SERVER-OTHER Cisco Wireless Lan Controller CAPWAP out of bounds access attempt (more info ...)attempted-admin  2020-3262      URL
53668SERVER-OTHER Cisco Unified Communications Manager TAPS RMI directory traversal attempt (more info ...)attempted-recon  2020-3177      URL
53669SERVER-WEBAPP Cisco IP Phone libHTTPService.so stack buffer overflow attempt (more info ...)attempted-admin  2016-1421      URL
53670SERVER-WEBAPP Cisco IP Phone libHTTPService.so stack buffer overflow attempt (more info ...)attempted-admin  2020-3161      URL
53671SERVER-WEBAPP Cisco UCS Director authentication bypass attempt (more info ...)web-application-attack  2020-3243      URL
53672SERVER-WEBAPP Cisco UCS Director REST API directory traversal attempt (more info ...)web-application-attack  2020-3250      URL
53673SERVER-WEBAPP Cisco UCS Director REST API directory traversal attempt (more info ...)web-application-attack  2020-3250      URL
53674SERVER-WEBAPP Cisco UCS Director REST API directory traversal attempt (more info ...)web-application-attack  2020-3250      URL
53675SERVER-WEBAPP Cisco UCS Director LargeFileUploadServlet directory traversal attempt (more info ...)web-application-attack  2020-3239      URL
53676SERVER-WEBAPP Cisco UCS Director LargeFileUploadServlet directory traversal attempt (more info ...)web-application-attack  2020-3247      URL
53677SERVER-WEBAPP Cisco UCS Director ClientServlet directory traversal attempt (more info ...)web-application-attack  2020-3252      URL
53678SERVER-WEBAPP Cisco UCS Director ClientServlet directory traversal attempt (more info ...)web-application-attack  2020-3252      URL
53679SERVER-WEBAPP Cisco UCS Director ClientServlet directory traversal attempt (more info ...)web-application-attack  2020-3252      URL
53680SERVER-WEBAPP Cisco UCS Director filename directory traversal attempt (more info ...)web-application-attack  2020-3240      URL
53681SERVER-WEBAPP Cisco UCS Director arbitrary JSP file upload attempt (more info ...)web-application-attack  2020-3251      URL
53682SERVER-WEBAPP Cisco Mobility Express cross site request forgery attempt (more info ...)attempted-user  2020-3261      URL
53683SERVER-WEBAPP Cisco Mobility Express cross site request forgery attempt (more info ...)attempted-user  2020-3261      URL
53707MALWARE-OTHER Unix.Trojan.Coinminer-7668629-0 download attempt (more info ...)trojan-activity        URL
53708MALWARE-OTHER Unix.Trojan.Coinminer-7668629-0 download attempt (more info ...)trojan-activity        URL
53847PROTOCOL-OTHER Cisco ASA and FTD malformed OSPF denial of service attempt (more info ...)attempted-dos  2020-3298      URL
53850SERVER-WEBAPP Cisco ASA and FTD memory disclosure attempt (more info ...)attempted-recon  2020-3259      URL
53851SERVER-WEBAPP Cisco ASA and FTD directory traversal attempt (more info ...)web-application-attack  2020-3187      URL
53868SERVER-OTHER Cisco ASA and FTD MGCP denial of service attempt (more info ...)attempted-dos  2020-3254      URL
53869SERVER-OTHER Cisco ASA and FTD MGCP denial of service attempt (more info ...)attempted-dos  2020-3254      URL
53870SERVER-OTHER Cisco ASA and FTD MGCP denial of service attempt (more info ...)attempted-dos  2020-3254      URL
53871SERVER-OTHER Cisco ASA and FTD MGCP denial of service attempt (more info ...)attempted-dos  2020-3254      URL
54005MALWARE-OTHER Unix.Trojan.Rootnik-7825953-0 download attempt (more info ...)trojan-activity        URL
54006MALWARE-OTHER Unix.Trojan.Rootnik-7825953-0 download attempt (more info ...)trojan-activity        URL
54034SERVER-OTHER Cisco Prime Network Registrar denial of service attempt (more info ...)attempted-dos  2020-3272      URL
54158PROTOCOL-OTHER Cisco IOS XE NetFlow packet parsing denial of service attempt (more info ...)attempted-dos  2020-3221      URL
54159SERVER-OTHER Cisco IOS IKE2 invalid port denial of service attempt (more info ...)attempted-dos  2020-3230      URL
54160SERVER-OTHER Cisco IOS IKE2 invalid port denial of service attempt (more info ...)attempted-dos  2020-3230      URL
54281INDICATOR-SCAN CallStranger UPnP discovery attempt (more info ...)misc-attack  2020-12695      URL
54320SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54321SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54322SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54323SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54324SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54325SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54326SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54327SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54328SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54329SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54330SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54331SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3276      URL
54333SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3286      URL
54334SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3286      URL
54335SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3286      URL
54336SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3286      URL
54337SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3288      URL
54338SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3288      URL
54339SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3287      URL
54340SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3287      URL
54341SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3288      URL
54342SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3288      URL
54343SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3268      URL
54344SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3268      URL
54345SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3268      URL
54346SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3268      URL
54347SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54348SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54349SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54350SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54351SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54352SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54353SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54354SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54355SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54356SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2020-3269      URL
54358BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54359BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54360BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54361BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54362BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54363BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54364BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54365BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54366BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54367BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54368BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54369BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54370BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54371BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54372BROWSER-OTHER Cisco Webex Meetings Desktop App arbitrary program execution attempt (more info ...)attempted-user  2020-3263      URL
54422SERVER-WEBAPP Cisco DNA Center cross site scripting attempt (more info ...)attempted-user  2019-15253      URL
54423SERVER-WEBAPP Cisco DNA Center cross site scripting attempt (more info ...)attempted-user  2019-15253      URL
54538SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3332      URL
54539SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3332      URL
54540SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3332      URL
54541SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2020-3332      URL
54542SERVER-WEBAPP Cisco RV Series Routers heap buffer overflow attempt (more info ...)web-application-attack  2020-3357      URL
54543SERVER-WEBAPP Cisco RV Series Routers heap buffer overflow attempt (more info ...)web-application-attack  2020-3357      URL
54546SERVER-WEBAPP Cisco SD-WAN vManage cypher query language injection attempt (more info ...)web-application-attack  2020-3387      URL
54547SERVER-WEBAPP Cisco SD-WAN vManage cypher query language injection attempt (more info ...)web-application-attack  2020-3387      URL
54548SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3331      URL
54549SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3331      URL
54550SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3331      URL
54551SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3331      URL
54552SERVER-WEBAPP Cisco RV Series Routers null pointer dereference attempt (more info ...)attempted-dos  2020-3358      URL
54557SERVER-WEBAPP Cisco RV Series Routers authentication bypass attempt (more info ...)web-application-attack  2020-3144      URL
54560SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2021-1172      URL
54561SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2021-1172      URL
54562SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3146      URL
54563SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin  2020-3146      URL
54598SERVER-WEBAPP Cisco ASA directory traversal attempt (more info ...)web-application-attack  2020-3452      URL
54599SERVER-WEBAPP Cisco ASA directory traversal attempt (more info ...)web-application-attack  2020-3452      URL
54600SERVER-WEBAPP Cisco ASA directory traversal attempt (more info ...)web-application-attack  2020-3452      URL
54601SERVER-WEBAPP Cisco ASA directory traversal attempt (more info ...)web-application-attack  2020-3452      URL
54655SERVER-WEBAPP Cisco Data Center Network Manager command injection attempt (more info ...)web-application-attack  2020-3384      URL
54668SERVER-WEBAPP Cisco Data Center Network Manager directory traversal attempt (more info ...)web-application-attack  2020-3383      URL
54694FILE-OTHER Cisco AnyConnect Secure Mobility Client dll-load exploit attempt (more info ...)attempted-user  2020-3433      URL
54695FILE-OTHER Cisco AnyConnect Secure Mobility Client dll-load exploit attempt (more info ...)attempted-user  2020-3433      URL
54836MALWARE-OTHER Unix.Trojan.Gafgyt-9403217-0 download attempt (more info ...)trojan-activity        URL
54837MALWARE-OTHER Unix.Trojan.Gafgyt-9403217-0 download attempt (more info ...)trojan-activity        URL
54896SERVER-OTHER Cisco NX-OS malformed BGP UPDATE denial of service attempt (more info ...)attempted-dos  2020-3398      URL
54899PROTOCOL-OTHER Cisco NX-OS protocol independent multicast denial of service attempt (more info ...)attempted-dos  2020-3338      URL
55806SERVER-OTHER Cisco Wireless LAN Controller CAPWAP denial of service attempt (more info ...)attempted-dos  2020-3488      URL
55807SERVER-OTHER Cisco Wireless LAN Controller CAPWAP denial of service attempt (more info ...)attempted-dos  2020-3494      URL
55819SERVER-OTHER Cisco IOS Common Open Policy Service denial of service attempt (more info ...)attempted-dos  2020-3526      URL
55820PROTOCOL-OTHER Cisco IOS XE Flexible NetFlow denial of service attempt (more info ...)attempted-dos  2020-3492      URL
55830SERVER-OTHER Cisco Wireless LAN Controller CAPWAP denial of service attempt (more info ...)attempted-dos  2020-3399      URL
55831SERVER-OTHER Cisco Wireless LAN Controller CAPWAP denial of service attempt (more info ...)attempted-dos  2020-3487      URL
55924SERVER-OTHER Cisco Wireless LAN Controller CAPWAP denial of service attempt (more info ...)attempted-dos  2020-3487      URL
55925SERVER-OTHER Cisco Wireless LAN Controller CAPWAP denial of service attempt (more info ...)attempted-dos  2020-3487      URL
56084SERVER-WEBAPP Cisco FXOS Software Firepower Chassis Manager cross site request forgery attempt (more info ...)attempted-user  2020-3456      URL
56085SERVER-WEBAPP Cisco FXOS Software Firepower Chassis Manager cross site request forgery attempt (more info ...)attempted-user  2020-3456      URL
56089SERVER-WEBAPP Cisco ASA and FTD denial of service attempt (more info ...)attempted-dos  2020-3572      URL
56090SERVER-OTHER Cisco ASA/FTD OSPF LLS denial of service attempt (more info ...)denial-of-service  2020-3528      URL
56091SERVER-OTHER Cisco ASA/FTD OSPF LLS denial of service attempt (more info ...)denial-of-service  2020-3528      URL
56216FILE-OTHER Cisco Webex Network Recording Player out of bounds write attempt (more info ...)attempted-user  2020-3603      URL
56217FILE-OTHER Cisco Webex Network Recording Player out of bounds write attempt (more info ...)attempted-user  2020-3603      URL
56218FILE-OTHER Cisco Webex Network Recording Player buffer overflow attempt (more info ...)attempted-user  2020-3604      URL
56219FILE-OTHER Cisco Webex Network Recording Player buffer overflow attempt (more info ...)attempted-user  2020-3604      URL
56220SERVER-WEBAPP Cisco SD-WAN vManage directory traversal attempt (more info ...)web-application-attack  2020-26073      URL
56221FILE-OTHER Cisco AnyConnect Secure Mobility Client arbitrary code execution attempt (more info ...)attempted-user  2020-3556      URL
56222FILE-OTHER Cisco AnyConnect Secure Mobility Client arbitrary code execution attempt (more info ...)attempted-user  2020-3556      URL
56225SERVER-OTHER Cisco Webex Meetings virtual channel remote code execution attempt (more info ...)attempted-admin  2020-3588      URL
56256MALWARE-OTHER Unix.Worm.Gitpaste12 variant download attempt (more info ...)trojan-activity        URL
56257MALWARE-OTHER Unix.Worm.Gitpaste12 variant download attempt (more info ...)trojan-activity        URL
56258MALWARE-OTHER Unix.Worm.Gitpaste12 variant outbound infection attempt (more info ...)trojan-activity        URL
56306SERVER-WEBAPP Cisco Data Center Network Manager arbitrary file download attempt (more info ...)attempted-recon  2019-1621      URL
56404SERVER-WEBAPP Cisco Security Manager XmpFileUploadServlet arbitrary JSP file upload attempt (more info ...)attempted-admin  2020-27130      URL
56405SERVER-WEBAPP Cisco Security Manager XmpFileUploadServlet directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56414SERVER-WEBAPP Cisco Security Manager XmpFileDownloadServlet directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56415SERVER-WEBAPP Cisco Security Manager XmpFileDownloadServlet directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56416SERVER-WEBAPP Cisco Security Manager XmpFileDownloadServlet directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56417SERVER-WEBAPP Cisco Security Manager SampleFileDownloadServlet directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56418SERVER-WEBAPP Cisco Security Manager SampleFileDownloadServlet directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56419SERVER-WEBAPP Cisco Security Manager SampleFileDownloadServlet directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56420SERVER-WEBAPP Cisco Security Manager resultsFrame directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56421SERVER-WEBAPP Cisco Security Manager resultsFrame directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56422SERVER-WEBAPP Cisco Security Manager resultsFrame directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56423SERVER-WEBAPP Cisco Security Manager xdmProxy directory traversal attempt (more info ...)web-application-attack  2020-27130      URL
56424SERVER-WEBAPP Cisco DNA Spaces Connector command injection attempt (more info ...)web-application-attack  2020-3586      URL
56440SERVER-WEBAPP Cisco Integrated Management Controller stack buffer overflow attempt (more info ...)web-application-attack  2020-3470      URL
56441SERVER-WEBAPP Cisco Integrated Management Controller stack buffer overflow attempt (more info ...)web-application-attack  2020-3470      URL
56442SERVER-WEBAPP Cisco Integrated Management Controller stack buffer overflow attempt (more info ...)web-application-attack  2020-3470      URL
56443SERVER-WEBAPP Cisco Integrated Management Controller stack buffer overflow attempt (more info ...)web-application-attack  2020-3470      URL
56444SERVER-WEBAPP Cisco Integrated Management Controller stack buffer overflow attempt (more info ...)web-application-attack  2020-3470      URL
56543SERVER-OTHER AnyDesk Discovery Feature crafted hostname remote code execution attempt (more info ...)attempted-user  2020-13160      URL
56544SERVER-OTHER AnyDesk Discovery Feature crafted username remote code execution attempt (more info ...)attempted-user  2020-13160      URL
56838SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-1150      URL
56839SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1215      URL
56840SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1217      URL
56841SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1211      URL
56842SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1203      URL
56843SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1195      URL
56844SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1204      URL
56861SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1213      URL
56866SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1183      URL
56867SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1189      URL
56868SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1205      URL
56869SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1186      URL
56870SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1201      URL
56871SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1193      URL
56872SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1193      URL
56873SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1193      URL
56874SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1193      URL
56875SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1193      URL
56876SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1210      URL
56881FILE-OTHER Cisco AnyConnect information disclosure attempt (more info ...)attempted-recon  2021-1258      URL
56882FILE-OTHER Cisco AnyConnect information disclosure attempt (more info ...)attempted-recon  2021-1258      URL
56883FILE-OTHER Cisco AnyConnect information disclosure attempt (more info ...)attempted-recon  2021-1258      URL
56884FILE-OTHER Cisco AnyConnect information disclosure attempt (more info ...)attempted-recon  2021-1258      URL
56885SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1159      URL
56910MALWARE-OTHER Unix.Keylogger.Asacub-9821542-0 download attempt (more info ...)trojan-activity        URL
56911MALWARE-OTHER Unix.Keylogger.Asacub-9821542-0 download attempt (more info ...)trojan-activity        URL
56938SERVER-WEBAPP Cisco Smart Software Manager Satellite Web UI command injection attempt (more info ...)web-application-attack  2021-1140      URL
56939SERVER-WEBAPP Cisco Smart Software Manager Satellite Web UI command injection attempt (more info ...)web-application-attack  2021-1140      URL
56940SERVER-WEBAPP Cisco Smart Software Manager Satellite Web UI command injection attempt (more info ...)web-application-attack  2021-1140      URL
56941SERVER-WEBAPP Cisco Smart Software Manager Satellite Web UI command injection attempt (more info ...)web-application-attack  2021-1140      URL
56942SERVER-WEBAPP Cisco SD-WAN vManage directory traversal attempt (more info ...)web-application-attack  2021-1299      URL
56943SERVER-WEBAPP Cisco SD-WAN vManage directory traversal attempt (more info ...)web-application-attack  2021-1299      URL
56944SERVER-WEBAPP Cisco SD-WAN vManage directory traversal attempt (more info ...)web-application-attack  2021-1299      URL
56945SERVER-WEBAPP Cisco Smart Software Manager Satellite Web UI command injection attempt (more info ...)web-application-attack  2021-1141      URL
56946SERVER-WEBAPP Cisco SD-WAN WebUI command injection attempt (more info ...)web-application-attack  2021-1298      URL
56950SERVER-WEBAPP Cisco DNA Center command injection attempt (more info ...)web-application-attack  2021-1264      URL
56953SERVER-WEBAPP Cisco Smart Software Manager Satellite Web UI command injection attempt (more info ...)web-application-attack  2021-1139      URL
57068SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1324      URL
57069SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1321      URL
57072SERVER-WEBAPP Cisco RV Series Routers directory traversal attempt (more info ...)web-application-attack  2021-1297      URL
57073SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1334      URL
57074SERVER-WEBAPP Cisco RV Series Routers directory traversal attempt (more info ...)web-application-attack  2021-1296      URL
57075SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1338      URL
57076SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-1294      URL
57077SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)attempted-user  2021-1342      URL
57078SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1343      URL
57079SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1343      URL
57080SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1343      URL
57081SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1343      URL
57082SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)attempted-user  2021-1327      URL
57083SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)attempted-user  2021-1346      URL
57084SERVER-WEBAPP Cisco RV series routers command injection attempt (more info ...)web-application-attack  2021-1318      URL
57085SERVER-WEBAPP Cisco RV series routers command injection attempt (more info ...)web-application-attack  2021-1318      URL
57086SERVER-WEBAPP Cisco RV Series routers command injection attempt (more info ...)web-application-attack  2021-1316      URL
57088SERVER-WEBAPP Cisco Small Business RV Series routers command injection attempt (more info ...)web-application-attack  2021-1292      URL
57089SERVER-WEBAPP Cisco Small Business RV Series routers command injection attempt (more info ...)web-application-attack  2021-1292      URL
57095SERVER-WEBAPP Cisco RV Series routers command injection attempt (more info ...)web-application-attack  2021-1317      URL
57096SERVER-WEBAPP Cisco RV Series routers command injection attempt (more info ...)web-application-attack  2021-1317      URL
57098SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-user  2021-1332      URL
57099SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-user  2021-1331      URL
57100SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1347      URL
57101SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1322      URL
57102SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)attempted-user  2021-1340      URL
57105SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)attempted-user  2021-1341      URL
57109SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)attempted-user  2021-1337      URL
57110SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)attempted-user  2021-1336      URL
57113SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1348      URL
57114SERVER-WEBAPP Cisco RV Series routers stack overflow attempt (more info ...)web-application-attack  2021-1345      URL
57222SERVER-OTHER Cisco NX-OS arbitrary file write attempt (more info ...)attempted-admin  2021-1361      URL
57343SERVER-WEBAPP Cisco IOS and IOS-XE Application Environment directory traversal attempt (more info ...)web-application-attack  2021-1385      URL
57344SERVER-WEBAPP Cisco IOS-XE Software Plug-and-Play command execution attempt (more info ...)attempted-admin  2021-1442      URL
57345SERVER-WEBAPP Cisco IOS XE Software cross site request forgery attempt (more info ...)attempted-user  2021-1403      URL
57346SERVER-WEBAPP Cisco IOS XE Software cross site request forgery attempt (more info ...)attempted-user  2021-1403      URL
57349SERVER-OTHER Cisco Virtual Switching System stack buffer overflow attempt (more info ...)attempted-admin  2021-1451      URL
57355SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2021-1356      URL
57356SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2021-1356      URL
57357SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2021-1356      URL
57358SERVER-WEBAPP Cisco IOS XE Web UI command injection attempt (more info ...)web-application-attack  2021-1356      URL
57360SERVER-OTHER Cisco IOS XE Wireless Controller Software CAPWAP denial of service attempt (more info ...)attempted-dos  2021-1373      URL
57392SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-1610      URL
57393FILE-OTHER Cisco AMP for Endpoints dll-load exploit attempt (more info ...)attempted-user  2021-1386      URL
57394FILE-OTHER Cisco AMP for Endpoints dll-load exploit attempt (more info ...)attempted-user  2021-1386      URL
57396SERVER-WEBAPP Cisco Unified Communications Products command injection attempt (more info ...)attempted-admin  2021-1362      URL
57398SERVER-WEBAPP Cisco Unified Communications Products command injection attempt (more info ...)attempted-admin  2021-1362      URL
57399SERVER-WEBAPP Cisco Unified Communications Products cross site scripting attempt (more info ...)attempted-admin  2021-1362      URL
57400SERVER-WEBAPP Cisco Unified Communications Products cross site scripting attempt (more info ...)attempted-admin  2021-1362      URL
57402SERVER-WEBAPP Cisco RV Series Routers authentication bypass attempt (more info ...)attempted-admin  2021-1472      URL
57410SERVER-OTHER Cisco IOS XE Wireless Controller Software CAPWAP denial of service attempt (more info ...)attempted-dos  2021-1373      URL
57486SERVER-WEBAPP Cisco ASA and FTD Web Service buffer overflow attempt (more info ...)attempted-user  2021-1493      URL
57488SERVER-WEBAPP Cisco ASA and FTD WebVPN denial of service attempt (more info ...)attempted-dos  2021-1445      URL
57489SERVER-WEBAPP Cisco ASA and FTD WebVPN denial of service attempt (more info ...)attempted-dos  2021-1504      URL
57520SERVER-WEBAPP Cisco Small Business WAP command injection attempt (more info ...)web-application-attack  2021-1401      URL
57521SERVER-WEBAPP Cisco Small Business WAP command injection attempt (more info ...)web-application-attack  2021-1401      URL
57522SERVER-WEBAPP Cisco Small Business WAP command injection attempt (more info ...)web-application-attack  2021-1401      URL
57526SERVER-WEBAPP Cisco HyperFlex HX Data Platform command injection attempt (more info ...)web-application-attack  2021-1498      URL
57527SERVER-WEBAPP Cisco HyperFlex HX Data Platform command injection attempt (more info ...)web-application-attack  2021-1498      URL
57528SERVER-WEBAPP Cisco HyperFlex HX Data Platform command injection attempt (more info ...)web-application-attack  2021-1498      URL
57576SERVER-WEBAPP Cisco Elastic Services Controller authentication bypass attempt (more info ...)attempted-user  2019-1867      URL
57581SERVER-WEBAPP Cisco Prime Infrastructure EPNM command injection attempt (more info ...)web-application-attack  2021-1487      URL
57582SERVER-WEBAPP Cisco Prime Infrastructure EPNM command injection attempt (more info ...)web-application-attack  2021-1487      URL
57583SERVER-WEBAPP Cisco Prime Infrastructure EPNM command injection attempt (more info ...)web-application-attack  2021-1487      URL
57584SERVER-WEBAPP Cisco Modeling Labs command injection attempt (more info ...)web-application-attack  2021-1531      URL
57706MALWARE-TOOLS Unix.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57707MALWARE-TOOLS Unix.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57708MALWARE-TOOLS Unix.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57809SERVER-WEBAPP Nagios XI autodiscovery_component_update_cron command injection attempt (more info ...)web-application-attack  2020-28648      URL
57810SERVER-WEBAPP Nagios XI autodiscovery_component_update_cron command injection attempt (more info ...)web-application-attack  2020-28648      URL
57811SERVER-WEBAPP Nagios XI autodiscovery_component_update_cron command injection attempt (more info ...)web-application-attack  2020-28648      URL
57812SERVER-WEBAPP Nagios XI autodiscovery_component_update_cron command injection attempt (more info ...)web-application-attack  2020-28648      URL
57856SERVER-WEBAPP Cisco ASA cross site scripting attempt (more info ...)attempted-user  2020-3580      URL
57857SERVER-WEBAPP Cisco ASA cross site scripting attempt (more info ...)attempted-user  2020-3580      URL
57882SERVER-WEBAPP Cisco Business Process Automation privilege escalation attempt (more info ...)attempted-admin  2021-1574      URL
57883SERVER-WEBAPP Cisco Business Process Automation privilege escalation attempt (more info ...)attempted-admin  2021-1574      URL
57884SERVER-WEBAPP Cisco Business Process Automation privilege escalation attempt (more info ...)attempted-admin  2021-1574      URL
57885SERVER-WEBAPP Cisco Business Process Automation privilege escalation attempt (more info ...)attempted-admin  2021-1574      URL
57887SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)attempted-admin  2021-1359      URL
57980SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-1602      URL
57981SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-1602      URL
57982SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2021-1609      URL
58006SERVER-WEBAPP Cisco Firepower Device Manager command injection attempt (more info ...)web-application-attack  2021-1518      URL
58097SERVER-WEBAPP Cisco Enterprise NFVIS authentication bypass attempt (more info ...)attempted-user  2021-34746      URL
58098SERVER-WEBAPP Cisco Enterprise NFVIS authentication bypass attempt (more info ...)attempted-user  2021-34746      URL
58099SERVER-WEBAPP Cisco Enterprise NFVIS authentication bypass attempt (more info ...)attempted-user  2021-34746      URL
58170SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector command injection attempt (more info ...)web-application-attack        URL
58171SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector command injection attempt (more info ...)web-application-attack        URL
58172SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector command injection attempt (more info ...)web-application-attack        URL
58173SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector command injection attempt (more info ...)web-application-attack        URL
58187SERVER-OTHER Cisco IOS XE Wireless Controller Software CAPWAP denial of service attempt (more info ...)attempted-dos  2021-34770      URL
58188SERVER-OTHER Cisco IOS XE Wireless Controller Software CAPWAP denial of service attempt (more info ...)attempted-dos  2021-34770      URL
58191SERVER-OTHER Cisco IOS XE Wireless Controller Software CAPWAP denial of service attempt (more info ...)attempted-dos  2021-1565      URL
58254SERVER-WEBAPP Cisco Identity Services Engine command execution attempt (more info ...)attempted-admin  2021-1594      URL
58255SERVER-WEBAPP Cisco Analog Telephone Adapter command injection attempt (more info ...)web-application-attack  2021-34710      URL
58256SERVER-WEBAPP Cisco Analog Telephone Adapter command injection attempt (more info ...)web-application-attack  2021-34710      URL
58257SERVER-WEBAPP Cisco Analog Telephone Adapter command injection attempt (more info ...)web-application-attack  2021-34710      URL
58258SERVER-WEBAPP Cisco Analog Telephone Adapter command injection attempt (more info ...)web-application-attack  2021-34710      URL
58259SERVER-WEBAPP Cisco Intersight Virtual Appliance command injection attempt (more info ...)web-application-attack  2021-34748      URL
58440SERVER-WEBAPP Cisco ASA and FTD web services stack buffer overflow attempt (more info ...)attempted-admin  2021-34704      URL
58441SERVER-WEBAPP Cisco ASA and FTD web services denial of service attempt (more info ...)attempted-dos  2021-40118      URL
58443SERVER-WEBAPP Cisco ASA and FTD web services denial of service attempt (more info ...)attempted-dos  2021-1573      URL
58444SERVER-WEBAPP Cisco ASA and FTD web services denial of service attempt (more info ...)attempted-dos  2021-1573      URL
58445SERVER-WEBAPP Cisco ASA and FTD web services denial of service attempt (more info ...)attempted-dos  2021-1573      URL
58446SERVER-WEBAPP Cisco Firepower Management Center directory traversal attempt (more info ...)web-application-attack  2021-34762      URL
58478SERVER-WEBAPP Cisco Catalyst PON Series ONT command injection attempt (more info ...)web-application-attack  2021-40113      URL
58479SERVER-WEBAPP Cisco Catalyst PON Series ONT command injection attempt (more info ...)web-application-attack  2021-40113      URL
58480SERVER-WEBAPP Cisco Catalyst PON Series ONT command injection attempt (more info ...)web-application-attack  2021-40113      URL
58481SERVER-WEBAPP Cisco Catalyst PON Series ONT command injection attempt (more info ...)web-application-attack  2021-40113      URL
58482SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-40120      URL
58483SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-40120      URL
58484SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-40120      URL
58485SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2021-40120      URL
58514SERVER-WEBAPP EyesOfNetwork autodiscovery command injection attempt (more info ...)web-application-attack  2020-8655      
58515SERVER-WEBAPP EyesOfNetwork autodiscovery command injection attempt (more info ...)web-application-attack  2020-8655      
58878SERVER-WEBAPP Cisco Unified CCMP and CCDM privilege escalation attempt (more info ...)attempted-admin  2022-20658      URL
58879SERVER-WEBAPP Cisco Unified CCMP and CCDM privilege escalation attempt (more info ...)attempted-admin  2022-20658      URL
58967SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2022-20712      URL
58968SERVER-WEBAPP Cisco RV Series Routers directory traversal attempt (more info ...)web-application-attack  2022-20707      URL
58969SERVER-WEBAPP Cisco RV Series Routers directory traversal attempt (more info ...)web-application-attack  2022-20707      URL
58970SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2022-20749      URL
58972SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)attempted-admin  2022-20841      URL
58984SERVER-WEBAPP Cisco RV Series Routers authentication bypass attempt (more info ...)attempted-admin  2022-20709      URL
58987SERVER-WEBAPP Cisco RV Series Routers arbitrary file overwrite attempt (more info ...)web-application-attack  2022-20711      URL
58988SERVER-WEBAPP Cisco RV Series Routers arbitrary file overwrite attempt (more info ...)web-application-attack  2022-20711      URL
59086SERVER-OTHER Cisco NX-OS Fabric Services Protocol heap buffer overflow attempt (more info ...)attempted-admin  2022-20624      URL
59087SERVER-OTHER Cisco NX-OS Fabric Services Protocol heap buffer overflow attempt (more info ...)attempted-admin  2022-20624      URL
59095MALWARE-OTHER Unix.Trojan.CyclopsBlink download attempt (more info ...)attempted-user        URL
59096MALWARE-OTHER Unix.Trojan.CyclopsBlink download attempt (more info ...)attempted-user        URL
59097MALWARE-OTHER Unix.Trojan.CyclopsBlink upload attempt (more info ...)attempted-user        URL
59098MALWARE-OTHER Unix.Trojan.CyclopsBlink upload attempt (more info ...)attempted-user        URL
59118SERVER-WEBAPP Cisco Expressway and TelePresence Video Communication Server directory traversal attempt (more info ...)web-application-attack  2022-20754      URL
59119SERVER-WEBAPP Cisco Expressway and TelePresence Video Communication Server directory traversal attempt (more info ...)web-application-attack  2022-20754      URL
59120SERVER-WEBAPP Cisco Expressway and TelePresence Video Communication Server directory traversal attempt (more info ...)web-application-attack  2022-20754      URL
59121SERVER-WEBAPP Cisco Expressway and TelePresence Video Communication Server command injection attempt (more info ...)web-application-attack  2022-20755      URL
59122SERVER-WEBAPP Cisco Expressway and TelePresence Video Communication Server command injection attempt (more info ...)web-application-attack  2022-20755      URL
59123SERVER-WEBAPP Cisco Expressway and TelePresence Video Communication Server command injection attempt (more info ...)web-application-attack  2022-20755      URL
59124SERVER-WEBAPP Cisco Expressway and TelePresence Video Communication Server command injection attempt (more info ...)web-application-attack  2022-20755      URL
59134MALWARE-OTHER Unix.Trojan.CyclopsBlink upload attempt (more info ...)trojan-activity        URL
59135MALWARE-OTHER Unix.Trojan.CyclopsBlink upload attempt (more info ...)trojan-activity        URL
59136MALWARE-OTHER Unix.Trojan.CyclopsBlink download attempt (more info ...)trojan-activity        URL
59137MALWARE-OTHER Unix.Trojan.CyclopsBlink download attempt (more info ...)trojan-activity        URL
59138MALWARE-OTHER Unix.Trojan.CyclopsBlink download attempt (more info ...)trojan-activity        URL
59139MALWARE-OTHER Unix.Trojan.CyclopsBlink upload attempt (more info ...)trojan-activity        URL
59140MALWARE-OTHER Unix.Trojan.CyclopsBlink upload attempt (more info ...)trojan-activity        URL
59141MALWARE-OTHER Unix.Trojan.CyclopsBlink upload attempt (more info ...)trojan-activity        URL
59142MALWARE-OTHER Unix.Trojan.CyclopsBlink download attempt (more info ...)trojan-activity        URL
59143MALWARE-OTHER Unix.Trojan.CyclopsBlink download attempt (more info ...)trojan-activity        URL
59430MALWARE-OTHER Unix.Malware.B1txor20 download attempt (more info ...)trojan-activity        URL
59431MALWARE-OTHER Unix.Malware.B1txor20 download attempt (more info ...)trojan-activity        URL
59566SERVER-WEBAPP Cisco IOx application environment command injection attempt (more info ...)web-application-attack  2022-20718      URL
59567SERVER-WEBAPP Cisco IOx application environment command injection attempt (more info ...)web-application-attack  2022-20719      URL
59568PROTOCOL-OTHER Cisco IOS XE RPKI-RTR denial of service attempt (more info ...)attempted-dos  2022-20694      URL
59569PROTOCOL-OTHER Cisco IOS XE RPKI-RTR denial of service attempt (more info ...)attempted-dos  2022-20694      URL
59618PROTOCOL-VOIP Cisco TelePresence and RoomOS H.323 denial of service attempt (more info ...)attempted-dos  2022-20783      URL
59722SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance firewall_setting command injection attempt (more info ...)web-application-attack        URL
59723SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance firewall_setting command injection attempt (more info ...)web-application-attack        URL
59724SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance firewall_setting command injection attempt (more info ...)web-application-attack        URL
59750SERVER-WEBAPP Cisco Enterprise NFV Infrastructure command injection attempt (more info ...)attempted-admin  2022-20779      URL
59751SERVER-WEBAPP Cisco Enterprise NFV Infrastructure command injection attempt (more info ...)attempted-admin  2022-20779      URL
59957MALWARE-OTHER Unix.Trojan.Symbiote variant binary download attempt (more info ...)trojan-activity        URL
59958MALWARE-OTHER Unix.Trojan.Symbiote variant binary download attempt (more info ...)trojan-activity        URL
59979SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2022-20825      URL
59986SERVER-WEBAPP Cisco Email Security Appliance authentication bypass attempt (more info ...)attempted-admin  2022-20798      URL
59987SERVER-WEBAPP Cisco Email Security Appliance information disclosure attempt (more info ...)attempted-recon  2022-20664      URL
60174SERVER-WEBAPP Cisco TelePresence VCS arbitrary file write attempt (more info ...)attempted-admin  2022-20812      URL
60175SERVER-WEBAPP Cisco TelePresence VCS arbitrary file write attempt (more info ...)attempted-admin  2022-20812      URL
60356SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)attempted-admin  2022-20827      URL
60357SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)web-application-attack  2022-20842      URL
60424SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)web-application-attack  2022-20871      URL
60425SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)web-application-attack  2022-20871      URL
60426SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)web-application-attack  2022-20871      URL
60427SERVER-WEBAPP Cisco Web Security Appliance command injection attempt (more info ...)web-application-attack  2022-20871      URL
60472SERVER-OTHER Cisco NX-OS OSPFv3 link-state advertisement denial of service attempt (more info ...)attempted-dos  2022-20823      URL
60629SERVER-OTHER Cisco IOS XE Wireless Controller CAPWAP denial of service attempt (more info ...)attempted-dos  2022-20856      URL
60688SERVER-WEBAPP Cisco Expressway and TelePresence cross site request forgery attempt (more info ...)attempted-dos  2022-20853      URL
60689SERVER-WEBAPP Cisco Expressway and TelePresence cross site request forgery attempt (more info ...)attempted-dos  2022-20853      URL
60751SERVER-WEBAPP Cisco Identity Services Engine directory traversal attempt (more info ...)web-application-attack  2022-20822      URL
60752SERVER-WEBAPP Cisco Identity Services Engine directory traversal attempt (more info ...)web-application-attack  2022-20822      URL
60801SERVER-WEBAPP Cisco BroadWorks CommPilot arbitrary JSP file upload attempt (more info ...)attempted-admin  2022-20958      URL
60802SERVER-WEBAPP Cisco BroadWorks CommPilot server side request forgery attempt (more info ...)web-application-attack  2022-20951      URL
60839PROTOCOL-SNMP Cisco ASA SNMP OID parsing denial of service attempt (more info ...)attempted-dos  2022-20924      URL
60856SERVER-WEBAPP Cisco Identity Services Engine command injection attempt (more info ...)web-application-attack  2022-20965      URL
60857SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)web-application-attack  2022-20966      URL
60886SERVER-WEBAPP Cisco Identity Services Engine cross site scripting attempt (more info ...)web-application-attack  2022-20967      URL
60887SERVER-WEBAPP Cisco ASA DAP HostScan denial of service attempt (more info ...)attempted-dos  2022-20947      URL
61077SERVER-WEBAPP Cisco IP Phone web interface authentication bypass attempt (more info ...)web-application-attack  2023-20018      URL
61078SERVER-WEBAPP Cisco Industrial Network Director cross site scripting attempt (more info ...)attempted-user  2023-20037      URL
61079SERVER-WEBAPP Cisco BroadWorks Application Delivery Platform denial of service attempt (more info ...)attempted-dos  2023-20020      URL
61080SERVER-WEBAPP Cisco BroadWorks Application Delivery Platform denial of service attempt (more info ...)attempted-dos  2023-20020      URL
61086SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20026      URL
61087SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20026      URL
61088SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20026      URL
61089SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20026      URL
61090SERVER-WEBAPP Cisco RV Series Routers authentication bypass attempt (more info ...)web-application-attack  2023-20025      URL
61187MALWARE-OTHER Unix.Malware.Dacls logcollector file download attempt (more info ...)trojan-activity        URL
61188MALWARE-OTHER Unix.Malware.Dacls logcollector file download attempt (more info ...)trojan-activity        URL
61189MALWARE-OTHER Unix.Malware.Dacls malware file download attempt (more info ...)trojan-activity        URL
61190MALWARE-OTHER Unix.Malware.Dacls malware file download attempt (more info ...)trojan-activity        URL
61252SERVER-WEBAPP Cisco IOx application environment command injection attempt (more info ...)web-application-attack  2023-20076      URL
61449SERVER-WEBAPP Cisco IP Phone web interface command injection attempt (more info ...)attempted-admin  2023-20078      URL
61457SERVER-WEBAPP Cisco RV series routers command injection attempt (more info ...)web-application-attack  2021-1318      URL
61458SERVER-WEBAPP Cisco RV series routers command injection attempt (more info ...)web-application-attack  2021-1318      URL
61591SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20117      URL
61592SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20117      URL
61593SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20117      URL
61594SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20117      URL
61595SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20128      URL
61596SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20128      URL
61597SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20128      URL
61598SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack  2023-20128      URL
61704POLICY-OTHER Cisco SPA112 firmware upgrade detected (more info ...)policy-violation  2023-20126      URL
61785SERVER-WEBAPP Cisco Small Business Series Switches stack buffer overflow attempt (more info ...)web-application-attack  2023-20189      URL
61786SERVER-WEBAPP Cisco Small Business Series Switches heap buffer overflow attempt (more info ...)web-application-attack  2023-20156      URL
61787SERVER-WEBAPP Cisco Small Business Series Switches configuration disclosure attempt (more info ...)attempted-recon  2023-20162      URL
61788SERVER-WEBAPP Cisco Small Business Series Switches heap buffer overflow attempt (more info ...)web-application-attack  2023-20024      URL
61789SERVER-WEBAPP Cisco Small Business Series Switches heap buffer overflow attempt (more info ...)web-application-attack  2023-20157      URL
61790SERVER-WEBAPP Cisco Small Business Series Switches buffer overflow attempt (more info ...)web-application-attack  2023-20160      URL
61791SERVER-WEBAPP Cisco Small Business Series Switches buffer overflow attempt (more info ...)web-application-attack  2023-20160      URL
61895SERVER-OTHER Cisco Unified Communications Manager denial of service attempt (more info ...)attempted-dos  2023-20108      URL


# of warning rules in this group: 572

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
218MALWARE-BACKDOOR MISC Solaris 2.5 attempt (more info ...)attempted-user    
267OS-SOLARIS EXPLOIT sparc overflow attempt (more info ...)attempted-admin    
289PROTOCOL-POP EXPLOIT x86 SCO overflow (more info ...)attempted-admin 1999-0006 156  
300OS-SOLARIS Oracle Solaris npls x86 overflow (more info ...)attempted-admin 1999-1588 2319  
304SERVER-OTHER SCO calserver overflow (more info ...)attempted-admin 2000-0306 2353  
640INDICATOR-SHELLCODE AIX NOOP (more info ...)shellcode-detect    
641INDICATOR-SHELLCODE Digital UNIX NOOP (more info ...)shellcode-detect    
1132SERVER-WEBAPP Netscape Unixware overflow (more info ...)attempted-recon 1999-0744 908  
1165SERVER-WEBAPP Novell Groupwise gwweb.exe access (more info ...)attempted-recon 1999-1006 879 10877 
1209SERVER-WEBAPP .nsconfig access (more info ...)attempted-recon    
1544SERVER-WEBAPP Cisco Catalyst command execution attempt (more info ...)web-application-activity 2000-0945 1846 10545 
1545SERVER-OTHER Cisco denial of service attempt (more info ...)web-application-attack    
1614SERVER-WEBAPP Novell Groupwise gwweb.exe attempt (more info ...)attempted-recon 1999-1006 879 10877 
1718SERVER-WEBAPP statsconfig.pl access (more info ...)web-application-activity 2001-0113 2211  
1814SERVER-WEBAPP CISCO VoIP DOS ATTEMPT (more info ...)misc-attack 2002-0882 4794 11013 
1858SERVER-WEBAPP CISCO PIX Firewall Manager directory traversal attempt (more info ...)misc-attack 1999-0158 691 10819 
3467SERVER-WEBAPP CISCO VoIP Portinformation access (more info ...)web-application-activity 2002-0882 4798  
4127SERVER-OTHER Novell eDirectory Server iMonitor overflow attempt (more info ...)attempted-admin 2005-2551 14548  
4129SERVER-OTHER Novell ZenWorks Remote Management Agent large login packet DoS attempt (more info ...)attempted-dos 2005-1543 13678  
4130SERVER-OTHER Novell ZenWorks Remote Management Agent buffer overflow Attempt (more info ...)attempted-dos 2005-1543 13678  
4144OS-SOLARIS Oracle Solaris lpd control file upload attempt (more info ...)misc-attack    
5798PUA-ADWARE Adware mydailyhoroscope runtime detection (more info ...)misc-activity    URL
5799BROWSER-PLUGINS mydailyhoroscope update or installation in progress (more info ...)misc-activity    URL
6017MALWARE-BACKDOOR dsk lite 1.0 runtime detection - disconnect (more info ...)trojan-activity    URL
6384MALWARE-OTHER Keylogger stealthwatcher 2000 runtime detection - agent discover broadcast (more info ...)successful-recon-limited    URL
6414SERVER-WEBAPP Novell GroupWise Messenger Accept-Language header buffer overflow attempt (more info ...)attempted-admin 2006-0992 17503  
7720MALWARE-BACKDOOR desktop scout runtime detection (more info ...)trojan-activity    URL
8081INDICATOR-SCAN UPnP service discover attempt (more info ...)network-scan    URL
8711SERVER-WEBAPP Novell eDirectory HTTP redirection buffer overflow attempt (more info ...)attempted-admin 2006-5478 20655  
9633SERVER-OTHER Computer Associates Product Discovery Service type 9B remote buffer overflow attempt TCP (more info ...)attempted-admin 2006-6379 21502  
9634SERVER-OTHER Computer Associates Product Discovery Service type 9C remote buffer overflow attempt TCP (more info ...)attempted-admin 2006-6379 21502  
9635SERVER-OTHER Computer Associates Product Discovery Service type 9B remote buffer overflow attempt UDP (more info ...)attempted-admin 2006-6379 21502  
9636SERVER-OTHER Computer Associates Product Discovery Service type 9C remote buffer overflow attempt UDP (more info ...)attempted-admin 2006-6379 21502  
10134SERVER-OTHER CA Brightstor discovery service buffer overflow attempt (more info ...)attempted-admin 2005-0260 12491  
10418OS-SOLARIS Oracle Solaris lpd unlink file attempt (more info ...)misc-attack 2005-4797 14510  
12080OS-SOLARIS Oracle Solaris printd arbitrary file deletion vulnerability (more info ...)misc-attack 2005-4797 14510  URL
12223SERVER-OTHER Novell WebAdmin long user name (more info ...)attempted-admin 2007-1350 22857  
12299OS-OTHER Cisco NHRP incorrect packet size (more info ...)attempted-user 2007-4286 25238  
12300OS-OTHER Cisco NHRP incorrect packet size (more info ...)attempted-user 2007-4286 25238  
13510SERVER-OTHER Novell eDirectory EventsRequest heap overflow attempt (more info ...)attempted-admin 2006-4509 20663  URL
13511SERVER-OTHER Novell eDirectory EventsRequest invalid event count exploit attempt (more info ...)attempted-admin 2006-4510 20663  URL
13620SERVER-OTHER CA Brightstor discovery service alternate buffer overflow attempt (more info ...)attempted-admin 2005-0260   
14990SERVER-WEBAPP Novell eDirectory SOAP Accept Charset header overflow attempt (more info ...)attempted-user 2008-4479   
15446SERVER-WEBAPP Novell eDirectory management console Accept-Language buffer overflow attempt (more info ...)attempted-admin 2008-5094 31553  URL
15958SERVER-OTHER Novell ZENworks Remote Management overflow attempt (more info ...)attempted-admin 2005-1543 13678  
15973SERVER-OTHER Novell eDirectory LDAP null search parameter buffer overflow attempt (more info ...)attempted-admin 2008-1809 30175  URL
16019SERVER-OTHER Novell Distributed Print Services integer overflow attempt (more info ...)attempted-user 2006-2327   
16028SERVER-WEBAPP Novell Groupwise Messenger parameters invalid memory access attempt (more info ...)attempted-admin 2006-4511 20316  
16052SERVER-OTHER Novell iManager Tree parameter denial of service attempt (more info ...)attempted-dos 2010-1930 40485  
16194SERVER-WEBAPP Novell eDirectory HTTP request content-length heap buffer overflow attempt (more info ...)attempted-user 2008-4478   
16429SERVER-WEBAPP Novell iManager eDirectory plugin schema buffer overflow attempt - GET request (more info ...)attempted-admin 2009-4486 37672  
16430SERVER-WEBAPP Novell iManager eDirectory plugin schema buffer overflow attempt - POST request (more info ...)attempted-admin 2009-4486 37672  
16522SERVER-OTHER Novell QuickFinder server cross-site-scripting attempt (more info ...)web-application-attack 2009-0611   
16597SERVER-MAIL Novell GroupWise Internet Agent Email address processing buffer overflow attempt (more info ...)attempted-admin 2009-1636 35064  
16787FILE-OTHER Symantec multiple products AeXNSConsoleUtilities RunCMD buffer overflow attempt (more info ...)attempted-user 2009-3033 37092  
16950POLICY-SPAM tabscotti71i.ru known spam email attempt (more info ...)policy-violation    
17027POLICY-SPAM scoreenjoy.ru known spam email attempt (more info ...)policy-violation    
17287SERVER-WEBAPP Cisco IOS HTTP service HTML injection attempt (more info ...)attempted-dos 2005-3921 15602  
17353OS-SOLARIS Oracle Solaris printd Daemon Arbitrary File Deletion attempt (more info ...)misc-attack 2005-4797 14510  URL
17391SERVER-OTHER Multiple products UNIX platform backslash directory traversal attempt (more info ...)web-application-attack 2017-16744 99515  URL
17433OS-SOLARIS Oracle Solaris DHCP Client Arbitrary Code Execution attempt (more info ...)attempted-user 2005-2870 14687  
17504SERVER-OTHER Novell ZENworks Asset Management buffer overflow attempt (more info ...)attempted-admin 2006-6299 21395  
17620SERVER-OTHER Products Discovery Service Buffer Overflow (more info ...)attempted-user 2006-5143 20364  
17621SERVER-OTHER Products Discovery Service Buffer Overflow (more info ...)attempted-user 2006-5143 20364  
17713SERVER-OTHER Novell NetMail NMAP STOR buffer overflow attempt (more info ...)attempted-admin 2006-6424 21725  
18512SERVER-OTHER Novell ZENworks Remote Management overflow attempt (more info ...)attempted-admin 2005-1543 13678  
18790SERVER-OTHER Novell ZENworks Handheld Management ZfHIPCND.exe overflow attempt (more info ...)attempted-admin 2010-4299 44700  
18796SERVER-WEBAPP Novell iManager ClassName handling overflow attempt (more info ...)attempted-admin 2010-1929 40480  
18960SERVER-WEBAPP Novell GroupWise agents HTTP request remote code execution attempt (more info ...)attempted-admin 2010-4714 44732  
19087SERVER-OTHER CA Discovery Service Overflow Attempt (more info ...)attempted-admin 2006-6379   
19088SERVER-OTHER CA Discovery Service Overflow Attempt (more info ...)attempted-admin 2006-6379   
19089SERVER-OTHER CA Discovery Service Overflow Attempt (more info ...)attempted-admin 2006-6379   
19090SERVER-OTHER CA Discovery Serice Overflow Attempt (more info ...)attempted-admin 2006-6379   
19205SERVER-OTHER Novell iManager Tree parameter denial of service attempt (more info ...)attempted-dos 2010-1930 40485  
19609SERVER-OTHER Novell ZENworks Handheld Management upload directory traversal attempt (more info ...)attempted-admin  48467  
19741MALWARE-OTHER PWS.Win32.Scofted keylogger runtime detection (more info ...)trojan-activity    URL
19813SERVER-WEBAPP Novell File Reporter Agent stack buffer overflow attempt (more info ...)attempted-admin 2011-0994   
20576SERVER-OTHER Novell ZENworks Remote Management overflow attempt (more info ...)attempted-admin 2005-1543 13678  
20995POLICY-OTHER HP SiteScope integrationViewer default credentials policy-bypass attempt (more info ...)policy-violation    URL
21116FILE-OTHER Cisco Webex selector and size2 subrecords corruption attempt (more info ...)attempted-user 2011-3319   URL
21378SERVER-OTHER Novell iPrint attributes-natural-language buffer overflow attempt (more info ...)attempted-user 2011-4194 51791  URL
21385SERVER-WEBAPP Cisco Common Services Help servlet XSS attempt (more info ...)web-application-attack 2011-0961   
21389SERVER-WEBAPP Cisco Common Services Device Center XSS attempt (more info ...)web-application-attack 2011-0962   
22947FILE-OTHER Novell Groupwise Addressbook buffer overflow attempt (more info ...)attempted-user 2012-0418 55729  URL
23354SERVER-WEBAPP Novell iManager buffer overflow attempt (more info ...)attempted-admin 2011-4188   URL
23363SERVER-OTHER Novell Netware XNFS.NLM xdrdecodeString heap buffer overflow attempt (more info ...)misc-attack 2011-4191 50804  
23364SERVER-OTHER Novell Netware XNFS.NLM v2 xdrdecodeString heap buffer overflow attempt (more info ...)misc-attack 2011-4191 50804  
23365SERVER-OTHER Novell Netware XNFS.NLM NFS v3 xdrdecodeString heap buffer overflow attempt (more info ...)misc-attack 2011-4191 50804  
23366SERVER-OTHER Novell Netware XNFS.NLM NFS v2 xdrdecodeString heap buffer overflow attempt (more info ...)misc-attack 2011-4191 50804  
23384SERVER-WEBAPP Novell Groupwise Messenger parameter memory corruption attempt (more info ...)attempted-admin    URL
23580FILE-OTHER Novell Groupwise Addressbook buffer overflow attempt (more info ...)attempted-user 2012-0418 55729  URL
23998SERVER-OTHER DHCP discover broadcast flood attempt (more info ...)denial-of-service  53649  URL
24114INDICATOR-SHELLCODE x86 OS agnostic avoid_underscore_tolower encoder (more info ...)shellcode-detect    
24337SERVER-OTHER Novell Remote Manager off-by-one denial of service attempt (more info ...)denial-of-service    
24435SERVER-WEBAPP Novell ZENworks Asset Management default admin credentials function call attempt (more info ...)attempted-admin 2012-4933   URL
24436SERVER-WEBAPP Novell ZENworks Asset Management default admin credentials function call attempt (more info ...)attempted-admin 2012-4933   URL
24447SERVER-WEBAPP HP SiteScope DownloadFilesHandler directory traversal attempt (more info ...)web-application-activity 2012-3264 55273  
24448SERVER-WEBAPP HP SiteScope UploadFilesHandler directory traversal attempt (more info ...)web-application-activity 2012-3264 55273  
24524SERVER-MAIL Novell GroupWise internet agent iCalendar parsing denial of service attempt (more info ...)denial-of-service 2011-3827 55574  URL
24531MALWARE-CNC Win.Trojan.Scondatie.A variant outbound connection (more info ...)trojan-activity    URL
24532MALWARE-CNC Win.Trojan.Scondatie.A inbound connection (more info ...)trojan-activity    URL
24766SERVER-WEBAPP Novell File Reporter SRS request arbitrary file download attempt (more info ...)attempted-admin 2012-4957 56579  
24806SERVER-WEBAPP Novell GroupWise WebAccess directory traversal attempt - POST request (more info ...)attempted-recon 2012-0410 54253  URL
24807SERVER-WEBAPP Novell GroupWise WebAccess directory traversal attempt - GET request (more info ...)attempted-recon 2012-0410 54253  URL
25019OS-OTHER Cisco Nexus OS software command injection attempt (more info ...)attempted-admin 2011-2569   URL
25020OS-OTHER Cisco Nexus OS software command injection attempt (more info ...)attempted-admin 2011-2569   URL
25101SERVER-OTHER Cisco IOS syslog message flood denial of service attempt (more info ...)attempted-dos 2001-1097 3096  
25341FILE-OTHER Cisco WebEx player remote code execution attempt (more info ...)attempted-user 2011-4004   
26180SERVER-OTHER Novell ZENworks Configuration Management Preboot service code overflow attempt (more info ...)attempted-admin  40486  
26432FILE-OTHER Cisco WebEx recording integer overflow attempt (more info ...)attempted-user    URL
26433FILE-OTHER Cisco WebEx recording integer overflow attempt (more info ...)attempted-user    URL
26527EXPLOIT-KIT Unix.Backdoor.Cdorked possible blackhole request attempt (more info ...)trojan-activity    URL
26528INDICATOR-COMPROMISE Unix.Backdoor.Cdorked redirect attempt (more info ...)trojan-activity    URL
26529MALWARE-BACKDOOR Unix.Backdoor.Cdorked backdoor command attempt (more info ...)trojan-activity    URL
26530INDICATOR-COMPROMISE Unix.Backdoor.Cdorked redirected URI attempt (more info ...)trojan-activity    URL
27001SERVER-OTHER Novell ZENWorks Remote Management overflow attempt (more info ...)attempted-admin 2005-1543 13678  
27036SERVER-OTHER Novell NetIQ User Manager modifyAccounts policy bypass attempt (more info ...)attempted-admin  56535  
27075SERVER-OTHER Novell NetIQ User Manager ldapagnt_eval remote code execution attempt (more info ...)attempted-admin  56539  
27599MALWARE-CNC Fort Disco Registration variant outbound connection (more info ...)trojan-activity    URL
27746MALWARE-CNC Unix.Trojan.Hanthie variant outbound connection (more info ...)trojan-activity    URL
28563MALWARE-CNC Win.Trojan.Pkdesco variant outbound connection (more info ...)trojan-activity    URL
28564MALWARE-CNC Win.Trojan.Pkdesco variant outbound connection (more info ...)trojan-activity    URL
28937SERVER-WEBAPP HP SiteScope issuesiebelcmd soap request code execution attempt (more info ...)attempted-user 2013-4835   
28956SERVER-WEBAPP Novell Zenworks configuration management umaninv information disclosure attempt (more info ...)attempted-user 2013-1084   
29000SERVER-WEBAPP Cisco EPC3925 cross site request forgery attempt (more info ...)attempted-user    URL
29118SERVER-WEBAPP Novell Groupwise Messenger Server process memory information disclosure attempt (more info ...)attempted-user 2011-3179   
29266SERVER-OTHER Cisco Prime Data Center Network Manager arbitrary file read attempt (more info ...)web-application-attack 2013-5487 62483  
29362SERVER-OTHER Novell NetWare AFP denial of service attempt (more info ...)attempted-dos 2010-0317 37616  
29792SERVER-OTHER Novell iPrint Server remote code execution attempt (more info ...)attempted-user 2010-4328 46309  
30338SERVER-OTHER Cisco 677-678 telnet buffer overflow attempt (more info ...)attempted-dos    URL
30339SERVER-OTHER Cisco Catalyst telnet memory leak denial of service attempt (more info ...)attempted-dos  2072  URL
30340SERVER-WEBAPP Cisco 675 web administration denial of service attempt (more info ...)attempted-dos  2012  URL
30350INDICATOR-SHELLCODE Metasploit payload aix_ppc_shell_bind_tcp (more info ...)shellcode-detect    
30351INDICATOR-SHELLCODE Metasploit payload aix_ppc_shell_find_port (more info ...)shellcode-detect    
30352INDICATOR-SHELLCODE Metasploit payload aix_ppc_shell_interact (more info ...)shellcode-detect    
30353INDICATOR-SHELLCODE Metasploit payload aix_ppc_shell_reverse_tcp (more info ...)shellcode-detect    
30364INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_awk (more info ...)shellcode-detect    
30365INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_inetd (more info ...)shellcode-detect    
30366INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_lua (more info ...)shellcode-detect    
30367INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_netcat (more info ...)shellcode-detect    
30368INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_netcat_gaping (more info ...)shellcode-detect    
30369INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_netcat_gaping_ipv6 (more info ...)shellcode-detect    
30370INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_nodejs (more info ...)shellcode-detect    
30371INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_perl (more info ...)shellcode-detect    
30372INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_perl_ipv6 (more info ...)shellcode-detect    
30373INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_ruby (more info ...)shellcode-detect    
30374INDICATOR-SHELLCODE Metasploit payload cmd_unix_bind_zsh (more info ...)shellcode-detect    
30375INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse (more info ...)shellcode-detect    
30376INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_awk (more info ...)shellcode-detect    
30377INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_lua (more info ...)shellcode-detect    
30378INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_openssl (more info ...)shellcode-detect    
30379INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_perl (more info ...)shellcode-detect    
30380INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_perl_ssl (more info ...)shellcode-detect    
30382INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_python (more info ...)shellcode-detect    
30383INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_ruby (more info ...)shellcode-detect    
30384INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_ruby_ssl (more info ...)shellcode-detect    
30385INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_zsh (more info ...)shellcode-detect    
30465INDICATOR-SHELLCODE Metasploit payload solaris_sparc_shell_bind_tcp (more info ...)shellcode-detect    
30466INDICATOR-SHELLCODE Metasploit payload solaris_sparc_shell_find_port (more info ...)shellcode-detect    
30467INDICATOR-SHELLCODE Metasploit payload solaris_sparc_shell_reverse_tcp (more info ...)shellcode-detect    
30468INDICATOR-SHELLCODE Metasploit payload solaris_x86_shell_bind_tcp (more info ...)shellcode-detect    
30469INDICATOR-SHELLCODE Metasploit payload solaris_x86_shell_find_port (more info ...)shellcode-detect    
30470INDICATOR-SHELLCODE Metasploit payload solaris_x86_shell_reverse_tcp (more info ...)shellcode-detect    
30884PROTOCOL-VOIP Cisco MXP Telepresence gssapi-data unauthenticated denial of service attempt (more info ...)attempted-dos 2014-2158   URL
30885PROTOCOL-VOIP Cisco SIP malformed date header buffer overflow attempt (more info ...)attempted-dos 2014-2162   URL
30886PROTOCOL-VOIP Cisco SIP malformed date header buffer overflow attempt (more info ...)attempted-dos 2014-2162   URL
31013SERVER-OTHER UNIX platform forwardslash directory traversal (more info ...)web-application-attack 2014-0130 67244  URL
31668SERVER-WEBAPP Cisco Unified Web and E-Mail Interaction Manager cross site scripting attempt (more info ...)web-application-attack 2014-2194 67464  URL
31905SERVER-WEBAPP HP SiteScope DownloadFilesHandler directory traversal attempt (more info ...)web-application-activity 2012-3264 55273  
31906SERVER-WEBAPP HP SiteScope UploadFilesHandler directory traversal attempt (more info ...)web-application-activity 2012-3264 55273  
31942SERVER-WEBAPP Novell GroupWise Admin Service FileUploadServlet directory traversal attempt (more info ...)web-application-attack 2014-0600 69424  URL
31943SERVER-WEBAPP HP SiteScope EmailServlet directory traversal attempt (more info ...)web-application-activity 2014-2614   URL
31979SERVER-OTHER Cisco IOS MediaNet metadata over RSVP IPFIX setlen=4 denial of service attempt (more info ...)attempted-dos 2014-3356   URL
31980SERVER-OTHER Cisco IOS RSVP Path message with no session attribute denial of service attempt (more info ...)attempted-dos 2014-3354   URL
31981SERVER-OTHER Cisco RSVP Protocol invalid Set ID DoS attempt (more info ...)attempted-dos 2014-3355   URL
32007SERVER-WEBAPP HP SiteScope UploadFilesHandler unauthorized file upload attempt (more info ...)web-application-activity 2012-3264 55273  
32106SERVER-OTHER Cisco ASA SCPS command injection attempt (more info ...)attempted-admin 2015-0675   URL
32110SERVER-OTHER Cisco ASA IKEv2 denial of service attempt (more info ...)attempted-dos 2014-3384   URL
32111SERVER-OTHER Cisco ASA IKEv2 denial of service attempt (more info ...)attempted-dos 2014-3384   URL
32112SERVER-OTHER Cisco ASA IKEv2 denial of service attempt (more info ...)attempted-dos 2014-3384   URL
32113SERVER-OTHER Cisco ASA IKEv2 denial of service attempt (more info ...)attempted-dos 2014-3384   URL
32277SERVER-OTHER Novell ZENworks PreBoot directory traversal attempt (more info ...)attempted-admin 2013-3706   URL
32398SERVER-OTHER Cisco RV180W Router cross-site request forgery attempt (more info ...)attempted-user 2014-2178   URL
33024SERVER-WEBAPP Cisco Security Agent Management Center code execution attempt (more info ...)web-application-attack 2011-0364 46420  
33025SERVER-WEBAPP Cisco Security Agent Management Center code execution attempt (more info ...)web-application-attack 2011-0364 46420  
33113SERVER-WEBAPP Novell eDirectory IMONITOR cross site scripting attempt (more info ...)attempted-user 2014-5212 71741  
33217MALWARE-CNC Win.Trojan.Nuovoscor variant outbound connection (more info ...)trojan-activity    URL
33620MALWARE-CNC Unix.Trojan.lubot outbound connection (more info ...)trojan-activity    URL
33621MALWARE-CNC Unix.Trojan.lubot outbound connection (more info ...)trojan-activity    URL
33679SERVER-OTHER Cisco CNS Network Registrar denial of service attempt (more info ...)denial-of-service 2004-1164   
33680SERVER-OTHER Cisco CNS Network Registrar denial of service attempt (more info ...)denial-of-service 2004-1164   
33869PROTOCOL-VOIP Cisco TelePresence Video Communication Server SDP media description denial of service attempt (more info ...)attempted-dos 2015-0652   URL
33870PROTOCOL-VOIP Cisco TelePresence Video Communication Server SDP media description denial of service attempt (more info ...)attempted-dos 2015-0652   URL
34022PROTOCOL-VOIP Cisco Unity Connection malformed contact header denial of service attempt (more info ...)attempted-dos 2015-0614   
34224INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_perl (more info ...)shellcode-detect    
34584POLICY-OTHER Novell ZENworks Configuration Management session id disclosure attempt (more info ...)policy-violation 2015-0784 74289  
34968SERVER-WEBAPP Cisco Sourcefire 3D System integrated BMC arbitrary file upload attempt (more info ...)attempted-admin 2015-0739 74709  URL
35315MALWARE-CNC Unix.Trojan.Downloader.Comsteal outbound connection (more info ...)trojan-activity    URL
35668SERVER-WEBAPP Novell GroupWise WebAccess cross-site scripting attempt (more info ...)attempted-user 2014-0611   
35669SERVER-WEBAPP Novell GroupWise WebAccess cross-site scripting attempt (more info ...)attempted-user 2014-0611   
36037SERVER-WEBAPP Novell Zenworks Mobile Management cross site scripting attempt (more info ...)attempted-user    URL
36038SERVER-WEBAPP Novell Zenworks Mobile Management cross site scripting attempt (more info ...)attempted-user    URL
36039SERVER-WEBAPP Novell Zenworks Mobile Management cross site scripting attempt (more info ...)attempted-user    URL
36040SERVER-WEBAPP Novell Zenworks Mobile Management cross site scripting attempt (more info ...)attempted-user    URL
36246PROTOCOL-VOIP Cisco IOS SIP header parsing memory leak attempt (more info ...)attempted-dos    URL
36461SERVER-OTHER Novell eDirectory DHost sadminpwd buffer overflow attempt (more info ...)attempted-user 2009-4654 37042  
36462SERVER-OTHER Novell eDirectory DHost verifypwd buffer overflow attempt (more info ...)attempted-user 2009-4654 37042  
36557SERVER-OTHER Cisco ASA DHCPv6 relay denial of service attempt (more info ...)attempted-dos 2015-6324   URL
36558SERVER-OTHER Cisco ASA DHCPv6 relay solicit denial of service attempt (more info ...)attempted-dos 2016-1367   URL
36649SERVER-OTHER Cisco Web Security Appliance range request memory leak denial of service attempt (more info ...)denial-of-service 2015-6293   URL
36652SERVER-OTHER Cisco ESA malformed spf TXT record anti-spam bypass attempt (more info ...)misc-attack 2015-4184   URL
36912SERVER-OTHER Novell eDirectory dhost buffer overflow attempt (more info ...)attempted-admin 2009-4653 36815  URL
38087SERVER-WEBAPP Cisco WLAN Controller insecure configuration wizard access attempt (more info ...)policy-violation 2015-6314   URL
38302SERVER-OTHER Cisco IOS DHCPv6 relay denial of service attempt (more info ...)attempted-dos    URL
38351SERVER-WEBAPP Cisco Prime Data Center Network Manager processImageSave.jsp directory traversal attempt (more info ...)attempted-admin 2013-5486 62484  URL
38397SERVER-WEBAPP Cisco Prime Infrastructure API authentication bypass attempt (more info ...)web-application-attack 2016-1289   URL
38399SERVER-WEBAPP Cisco TelePresence Server denial of service attempt (more info ...)attempted-dos 2015-6313   URL
38400SERVER-WEBAPP Cisco Prime Infrastructure API credentials enumeration attempt (more info ...)web-application-attack 2016-1290   URL
38584MALWARE-CNC Win.Backdoor.DFSCook variant JS dropper outbound connection (more info ...)trojan-activity    URL
38585MALWARE-CNC Win.Backdoor.DFSCook variant outbound connection (more info ...)trojan-activity    URL
38586MALWARE-CNC Win.Backdoor.DFSCook variant outbound connection (more info ...)trojan-activity    URL
38587MALWARE-CNC Win.Backdoor.DFSCook variant temporary redirect attempt (more info ...)trojan-activity    URL
38588MALWARE-CNC Win.Backdoor.DFSCook variant outbound connection (more info ...)trojan-activity    URL
38591SERVER-WEBAPP Cisco WLAN Controller management interface denial of service attempt (more info ...)attempted-dos 2016-1362   URL
38735SERVER-WEBAPP Cisco TelePresence XML API authentication bypass attempt (more info ...)attempted-admin 2016-1387   URL
38736SERVER-WEBAPP Cisco TelePresence XML API authentication bypass attempt (more info ...)attempted-admin 2016-1387   URL
38737SERVER-WEBAPP Cisco TelePresence XML API authentication bypass attempt (more info ...)attempted-admin 2016-1387   URL
38738SERVER-WEBAPP Cisco TelePresence XML API authentication bypass attempt (more info ...)attempted-admin 2016-1387   URL
38739SERVER-WEBAPP Cisco TelePresence XML API authentication bypass attempt (more info ...)attempted-admin 2016-1387   URL
38740SERVER-WEBAPP Cisco TelePresence XML API authentication bypass attempt (more info ...)attempted-admin 2016-1387   URL
38741SERVER-WEBAPP Cisco TelePresence XML API authentication bypass attempt (more info ...)attempted-admin 2016-1387   URL
38958SERVER-OTHER Cisco Web Security Appliance socket exhaustion denial of service attempt (more info ...)attempted-dos    URL
39185SERVER-WEBAPP Cisco Unified Interactive Voice Response directory traversal attempt (more info ...)web-application-attack 2011-3315   
39186SERVER-WEBAPP Cisco Unified Interactive Voice Response directory traversal attempt (more info ...)web-application-attack 2011-3315   
39187SERVER-WEBAPP Cisco Unified Interactive Voice Response directory traversal attempt (more info ...)web-application-attack 2011-3315   
39358SERVER-WEBAPP Cisco DPC2420 router configuration file access attempt (more info ...)attempted-recon    URL
39371SERVER-WEBAPP Cisco Prime Infrastructure API default credentials authentication attempt (more info ...)attempted-user    URL
39472SERVER-OTHER Jenkins server auto-discovery attempt (more info ...)policy-violation    URL
39707BROWSER-OTHER Novell Messenger Client folder name buffer overflow attempt (more info ...)attempted-user  52062  
39708BROWSER-OTHER Novell Messenger Client folder name buffer overflow attempt (more info ...)attempted-user  52062  
39709BROWSER-OTHER Novell Messenger Client folder name buffer overflow attempt (more info ...)attempted-user  52062  
39795SERVER-WEBAPP Cisco RV Series Routers insecure guest account login attempt (more info ...)attempted-admin 2015-6397   URL
39796PROTOCOL-VOIP Cisco Unified Communications Manager null pointer dereference attempt (more info ...)attempted-dos 2016-1466   URL
39797PROTOCOL-VOIP Cisco Unified Communications Manager null pointer dereference attempt (more info ...)attempted-dos 2016-1466   URL
39983INDICATOR-COMPROMISE Cisco IOS commandline overflow attempt (more info ...)attempted-admin 2016-6367   
39984INDICATOR-COMPROMISE Cisco IOS commandline overflow attempt. (more info ...)attempted-admin 2016-6367   
39985INDICATOR-COMPROMISE Cisco IOS commandline overflow attempt. (more info ...)attempted-admin 2016-6367   
39986INDICATOR-COMPROMISE Cisco IOS commandline overflow attempt (more info ...)attempted-admin 2016-6367   
39987INDICATOR-COMPROMISE Cisco IOS commandline overflow attempt. (more info ...)attempted-admin 2016-6367   
40013FILE-OTHER Cisco WebEx Meetings Player arbitrary code execution attempt (more info ...)attempted-user    URL
40014FILE-OTHER Cisco WebEx Meetings Player arbitrary code execution attempt (more info ...)attempted-user    URL
40072MALWARE-CNC Cisco ASA backdoor installer inbound connection attempt (more info ...)trojan-activity    
40131POLICY-OTHER Cisco Prime Collaboration Assurance session ID privilege escalation attempt (more info ...)policy-violation 2015-4306   URL
40239SERVER-OTHER Cisco WebEx meetings server denial of service attempt (more info ...)attempted-dos 2016-1483   URL
40504SERVER-OTHER Cisco Snort HTTP chunked transfer encoding processing denial of service attempt (more info ...)attempted-dos 2016-6439   URL
40519MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    URL
40520MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    URL
40521MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    URL
40522MALWARE-CNC Unix.Trojan.Mirai variant post compromise fingerprinting (more info ...)trojan-activity    URL
40523MALWARE-CNC Unix.Trojan.Mirai variant post compromise echo loader attempt (more info ...)trojan-activity    URL
40580POLICY-OTHER Cisco Universal Media Services potentially unauthorized API access detected (more info ...)policy-violation 2016-6397   URL
40599MALWARE-CNC Unix.Trojan.Mirai variant post compromise echo loader attempt (more info ...)trojan-activity    URL
40600MALWARE-CNC Unix.Trojan.Mirai variant post compromise echo loader attempt (more info ...)trojan-activity    URL
40601MALWARE-CNC Unix.Trojan.Mirai variant post compromise activity (more info ...)trojan-activity    URL
40612MALWARE-CNC Unix.Trojan.Mirai variant post compromise download attempt (more info ...)trojan-activity    URL
40636POLICY-OTHER Cisco Prime Home API insecure SSO authentication detected (more info ...)default-login-attempt 2016-6452   URL
41137SERVER-OTHER Cisco IOS XR command line interface privilege escalation attempt (more info ...)attempted-admin 2016-6428   URL
41226INDICATOR-SHELLCODE AIX /bin/sh (more info ...)shellcode-detect    
41285INDICATOR-SHELLCODE SCO OpenServer x86 shell (more info ...)shellcode-detect    
41286INDICATOR-SHELLCODE Solaris x86 bind shell (more info ...)shellcode-detect    
41287INDICATOR-SHELLCODE Solaris x86 FindSock shell (more info ...)shellcode-detect    
41288INDICATOR-SHELLCODE Solaris x86 reverse connect shell (more info ...)shellcode-detect    
41389POLICY-OTHER Cisco Firepower Management Console rule import access detected (more info ...)policy-violation 2016-6433   URL
41409POLICY-OTHER Cisco Webex explicit use of web plugin detected (more info ...)policy-violation 2017-6753   URL
41415PROTOCOL-VOIP Cisco Expressway and TelePresence VCS denial of service attempt (more info ...)attempted-dos 2017-3790   URL
41487POLICY-OTHER Cisco Prime Home portlet API access detected (more info ...)policy-violation 2017-3791   URL
42004POLICY-OTHER Cisco Mobility Express Access Point radio.html access detected (more info ...)policy-violation 2017-3831   URL
42016PROTOCOL-SCADA Moxa discovery packet information disclosure attempt (more info ...)attempted-recon    URL
42069SERVER-OTHER Cisco IOS XE DHCP vendor class identifier format string exploit attempt (more info ...)attempted-admin 2017-3859   URL
42070SERVER-OTHER Cisco IOS L2TP invalid message digest AVP denial of service attempt (more info ...)attempted-dos 2017-3857   URL
42071SERVER-WEBAPP Cisco IOS XE webui denial of service attempt (more info ...)attempted-dos 2017-3856   URL
42113MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    URL
42114MALWARE-CNC Unix.Trojan.Mirai variant new bot registered (more info ...)trojan-activity    URL
42281OS-SOLARIS Solaris catflap telnet remote code execution attempt (more info ...)attempted-admin    
42282OS-SOLARIS Solaris catflap telnet remote code execution attempt (more info ...)attempted-admin    
42283OS-SOLARIS Solaris catflap telnet remote code execution attempt (more info ...)attempted-admin    
42293PROTOCOL-VOIP Cisco Unified Communications Manager SIP NOTIFY denial of service attempt (more info ...)attempted-dos 2017-3808   URL
42924POLICY-OTHER Cisco Prime Collaboration potentially unauthorized log file access detected (more info ...)policy-violation 2017-6621   URL
43265SERVER-WEBAPP Novell NetIQ Sentinel Server ReportViewServlet directory traversal attempt directory traversal attempt (more info ...)web-application-attack 2016-1605   
43266SERVER-WEBAPP Novell NetIQ Sentinel Server ReportViewServlet directory traversal attempt directory traversal attempt (more info ...)web-application-attack 2016-1605   
43267SERVER-WEBAPP Novell NetIQ Sentinel Server ReportViewServlet directory traversal attempt directory traversal attempt (more info ...)web-application-attack 2016-1605   
43297SERVER-OTHER Cisco IOS HTTP percent sign denial of service attempt (more info ...)denial-of-service  1154  
43351MALWARE-CNC Unix.Trojan.Erebus variant outbound connection (more info ...)trojan-activity    URL
43435SERVER-WEBAPP Cisco Secure Access Control Server cross site scripting attempt (more info ...)attempted-user 2006-3101   
43452POLICY-OTHER Cisco Ultra Services Framework unauthenticated ZAB connect request detected (more info ...)policy-violation 2017-6711   URL
43499SERVER-WEBAPP Cisco Prime Infrastructure cross site scripting attempt (more info ...)attempted-user 2017-6699   URL
43500SERVER-WEBAPP Cisco Prime Infrastructure cross site scripting attempt (more info ...)attempted-user 2017-6699   URL
43501SERVER-WEBAPP Cisco Prime Infrastructure cross site scripting attempt (more info ...)attempted-user 2017-6700   URL
43502SERVER-WEBAPP Cisco Prime Infrastructure cross site scripting attempt (more info ...)attempted-user 2017-6700   URL
43514SERVER-OTHER Cisco IOS authentication proxy authentication request attempt (more info ...)attempted-user 2009-2863   
43525SERVER-OTHER Cisco ASA malformed SCCP packet denial of service attempt (more info ...)denial-of-service 2010-0151   
43573SERVER-OTHER Cisco IOS DHCP denial of service attempt (more info ...)attempted-dos 2013-5475   URL
43752SERVER-OTHER Sun Solaris dhcpd malformed bootp denial of service attempt (more info ...)denial-of-service 2007-5365 32213  
43775SERVER-WEBAPP HP Sitescope EmailServlet directory traversal attempt (more info ...)web-application-attack 2014-2614   
43776SERVER-WEBAPP HP Sitescope EmailServlet directory traversal attempt (more info ...)web-application-attack 2014-2614   
43777SERVER-WEBAPP HP Sitescope EmailServlet directory traversal attempt (more info ...)web-application-attack 2014-2614   
44457POLICY-OTHER Cisco IOS XE Web UI user administration page access detected (more info ...)policy-violation 2017-12230   URL
44555SERVER-WEBAPP Cisco FirePower Management Center cross site scripting attempt (more info ...)attempted-user 2017-12220   URL
44556SERVER-WEBAPP Cisco Unity Connection edit-nuance.do cross site scripting attempt (more info ...)attempted-user 2017-12212 100645  URL
44557SERVER-WEBAPP Cisco Unity Connection nick-name.do cross site scripting attempt (more info ...)attempted-user 2017-12212 100645  URL
44558SERVER-WEBAPP Cisco Unity Connection serviceParamEdit.do cross site scripting attempt (more info ...)attempted-user 2017-12212 100645  URL
44604SERVER-OTHER Novell eDirectory LDAP server buffer overflow attempt (more info ...)attempted-user    URL
44739SERVER-OTHER Novell GroupWise HTTP interface arbitrary file retrieval attempt (more info ...)attempted-recon 2012-0419   
44740SERVER-OTHER Novell GroupWise HTTP interface arbitrary file retrieval attempt (more info ...)attempted-recon 2012-0419   
44741SERVER-OTHER Novell GroupWise HTTP interface arbitrary file retrieval attempt (more info ...)attempted-recon 2012-0419   
44742SERVER-OTHER Novell GroupWise HTTP interface arbitrary file retrieval attempt (more info ...)attempted-recon 2012-0419   
44971SERVER-OTHER QNAP transcode server command injection attempt (more info ...)attempted-admin    URL
44974SERVER-OTHER Cisco IOS Smart Install identification attempt (more info ...)attempted-recon    URL
45099MALWARE-CNC Win.Trojan.Syscon variant inbound connection (more info ...)trojan-activity    URL
45100MALWARE-CNC Win.Trojan.Syscon variant outbound connection (more info ...)trojan-activity    URL
45120SERVER-OTHER Cisco Application Control Engine padding oracle attack attempt (more info ...)attempted-recon    URL
45464PROTOCOL-VOIP Cisco Unified Customer Voice Portal denial of service attempt (more info ...)attempted-dos 2018-0086   URL
45513SERVER-OTHER OpenLDAP zero size PagedResultsControl denial of service attempt (more info ...)denial-of-service 2017-9287   
45563MALWARE-CNC Unix.Trojan.Vpnfilter variant outbound connection attempt (more info ...)trojan-activity    URL
45564MALWARE-CNC Unix.Trojan.Vpnfilter variant outbound connection attempt (more info ...)trojan-activity    URL
45729POLICY-OTHER Cisco Unified Communications Manager appuserFindList.do access detected (more info ...)policy-violation 2018-0135   URL
45730SERVER-OTHER Cisco TelePresence TC and TE software authentication bypass attempt (more info ...)attempted-admin 2014-2174   URL
45813SERVER-WEBAPP Cisco Unified Communications Manager information disclosure attempt (more info ...)attempted-recon 2018-0198   URL
45941SERVER-OTHER Memcached UDP version discovery attempt (more info ...)attempted-recon    URL
45956MALWARE-CNC Unix.Trojan.PyCryptoMiner outbound connection (more info ...)trojan-activity    URL
46121PROTOCOL-OTHER use of undocumented ScMM test interface in Cisco small business devices detected (more info ...)misc-activity 2014-0659   
46122PROTOCOL-OTHER use of undocumented ScMM test interface in Cisco small business devices detected (more info ...)misc-activity 2014-0659   
46123PROTOCOL-OTHER use of undocumented ScMM test interface in Cisco small business devices detected (more info ...)misc-activity 2014-0659   
46124PROTOCOL-OTHER use of undocumented ScMM test interface in Cisco small business devices detected (more info ...)misc-activity 2014-0659   
46325SERVER-WEBAPP HPE Intelligent Management Center UrlAccessController authentication bypass attempt (more info ...)web-application-attack 2017-8982   URL
46782MALWARE-CNC Unix.Trojan.Vpnfilter variant SSL connection attempt (more info ...)trojan-activity    URL
46783MALWARE-CNC Unix.Trojan.Vpnfilter variant SSL connection attempt (more info ...)trojan-activity    URL
47084MALWARE-CNC Unix.Trojan.Vpnfilter variant connection attempt (more info ...)trojan-activity    URL
47236MALWARE-CNC Unix.Trojan.Prowli variant outbound connection (more info ...)trojan-activity    URL
47377MALWARE-CNC Unix.Trojan.Vpnfilter plugin variant connection attempt (more info ...)trojan-activity    URL
47426PROTOCOL-VOIP Cisco SPA514G SDP field processing denial of service attempt (more info ...)attempted-dos 2018-0389   URL
47919PROTOCOL-VOIP Cisco IOS XE NAT SIP application layer gateway denial of service attempt (more info ...)attempted-dos 2019-12646   URL
48109SERVER-OTHER Aktakom oscilloscope denial of service attempt (more info ...)attempted-dos    URL
48160POLICY-OTHER Infrasightlabs vScopeServer admin user creation attempt (more info ...)misc-activity    URL
48192MALWARE-CNC Unix.Worm.Hakai outbound connection (more info ...)trojan-activity    URL
48239SERVER-OTHER Cisco NX-OS precision time protocol denial of service attempt (more info ...)attempted-dos 2018-0378   URL
48240SERVER-OTHER Cisco NX-OS precision time protocol denial of service attempt (more info ...)attempted-dos 2018-0378   URL
48275MALWARE-CNC Unix.Trojan.Gafgyt variant new bot registered (more info ...)trojan-activity    URL
48281MALWARE-CNC Unix.Trojan.Chalubo downloader connection (more info ...)trojan-activity    URL
48282MALWARE-CNC Unix.Trojan.Chalubo outbound connection (more info ...)trojan-activity    URL
48283MALWARE-CNC Unix.Trojan.Chalubo outbound connection (more info ...)trojan-activity    URL
48284MALWARE-CNC Unix.Trojan.Chalubo outbound connection (more info ...)trojan-activity    URL
48285MALWARE-CNC Unix.Trojan.Chalubo outbound connection (more info ...)trojan-activity    URL
48286MALWARE-CNC Unix.Trojan.Chalubo outbound connection (more info ...)trojan-activity    URL
48644POLICY-OTHER Cisco Adaptive Security Appliance admin REST API access attempt (more info ...)policy-violation 2018-15465   URL
48962SERVER-OTHER Cisco IoT Field Network Director UDP flood attempt (more info ...)attempted-dos 2019-1644   URL
49512MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49513MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49514MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49515MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49516MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49517MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49518MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49519MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49520MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49606PROTOCOL-VOIP Cisco IOS SIP calling display name denial of service attempt (more info ...)attempted-dos 2019-1752   URL
49607PROTOCOL-VOIP Cisco IOS SIP calling display name denial of service attempt (more info ...)attempted-dos 2019-1752   URL
49612POLICY-OTHER Cisco Virtual Switching System standby interested message detected (more info ...)policy-violation 2019-1750   URL
49613POLICY-OTHER Cisco Virtual Switching System master request message detected (more info ...)policy-violation    URL
49664MALWARE-CNC Win.Trojan.TSCookie variant outbound connection (more info ...)trojan-activity    URL
49791MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49792MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49793MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
49794MALWARE-CNC Unix.Trojan.Mirai variant post compromise download (more info ...)trojan-activity    
50006SERVER-WEBAPP Cisco Web Security Appliance proxy service buffer overflow attempt (more info ...)attempted-dos 2019-1817   URL
50007SERVER-WEBAPP Cisco ASA WebVPN expired session page direct access denial of service attempt (more info ...)attempted-dos 2019-1693   URL
50164MALWARE-CNC Unix.Trojan.Winnti variant outbound connection (more info ...)trojan-activity    URL
50166MALWARE-CNC Unix.Trojan.Winnti malicious executable download attempt (more info ...)trojan-activity    URL
50167MALWARE-CNC Unix.Trojan.Winnti malicious executable download attempt (more info ...)trojan-activity    URL
50281MALWARE-CNC Unix.Miner.Decred variant outbound connection (more info ...)trojan-activity    URL
50282MALWARE-CNC Unix.Miner.Decred variant outbound connection (more info ...)trojan-activity    URL
50283MALWARE-CNC Unix.Miner.Decred variant outbound connection (more info ...)trojan-activity    URL
50284MALWARE-CNC Unix.Miner.Decred variant outbound connection (more info ...)trojan-activity    URL
50808MALWARE-CNC Unix.Backdoor.Godlua variant outbound connection (more info ...)trojan-activity    URL
50809MALWARE-CNC Unix.Backdoor.Godlua variant outbound connection (more info ...)trojan-activity    URL
50810MALWARE-CNC Unix.Backdoor.Godlua variant outbound connection (more info ...)trojan-activity    URL
50811MALWARE-CNC Unix.Backdoor.Godlua variant outbound connection (more info ...)trojan-activity    URL
50902POLICY-OTHER Cisco ASA running configuration download request detected (more info ...)policy-violation 2019-1934   URL
50990MALWARE-CNC Unix.Malware.ech0raix outbound connection attempt (more info ...)trojan-activity    URL
50991MALWARE-CNC Unix.Malware.ech0raix outbound connection attempt (more info ...)trojan-activity    URL
50992MALWARE-CNC Unix.Malware.ech0raix outbound connection attempt (more info ...)trojan-activity    URL
50993MALWARE-CNC Unix.Malware.ech0raix outbound connection attempt (more info ...)trojan-activity    URL
51027SERVER-OTHER Novell iManager ASN.1 client hello parsing denial of service attempt (more info ...)denial-of-service 2003-0543   
51190SERVER-WEBAPP Novell iManager buffer overflow attempt (more info ...)attempted-admin 2011-4188   URL
51298POLICY-OTHER Cisco 220 Series Smart Switches unauthenticated request detected (more info ...)policy-violation 2019-1912   URL
51299POLICY-OTHER Cisco 220 Series Smart Switches unauthenticated request detected (more info ...)policy-violation 2019-1912   URL
51300POLICY-OTHER Cisco 220 Series Smart Switches unauthenticated request detected (more info ...)policy-violation 2019-1912   URL
51365SERVER-WEBAPP Cisco NX-OS Software NX-API denial of service attempt (more info ...)attempted-dos 2019-1968   URL
51366SERVER-WEBAPP Cisco NX-OS Software NX-API denial of service attempt (more info ...)attempted-dos 2019-1968   URL
51367SERVER-WEBAPP Cisco NX-OS Software NX-API denial of service attempt (more info ...)attempted-dos 2019-1968   URL
51414POLICY-OTHER Cisco Industrial Network Director unauthenticated configuration request detected (more info ...)policy-violation 2019-1976   URL
51626PROTOCOL-VOIP Cisco IOS SIP denial of service attempt (more info ...)attempted-dos 2019-12654   URL
51627PROTOCOL-VOIP Cisco IOS SIP denial of service attempt (more info ...)attempted-dos 2019-12654   URL
51628POLICY-OTHER Cisco IOS Layer 2 Traceroute vlan enumeration detected (more info ...)attempted-recon    URL
51645SERVER-OTHER Cisco IOx invalid TLS handshake type denial of service attempt (more info ...)attempted-dos 2019-12656   URL
51724SERVER-OTHER Novell Remote Manager off-by-one denial of service attempt (more info ...)denial-of-service    
51795MALWARE-CNC Unix.Malware.Agent outbound connection attempt (more info ...)trojan-activity    URL
51796MALWARE-CNC Unix.Malware.Agent outbound connection attempt (more info ...)trojan-activity    URL
51797MALWARE-CNC Unix.Malware.Agent outbound connection attempt (more info ...)trojan-activity    URL
51798MALWARE-CNC Unix.Malware.Agent outbound connection attempt (more info ...)trojan-activity    URL
51799MALWARE-CNC Unix.Malware.Agent outbound connection attempt (more info ...)trojan-activity    URL
51800MALWARE-CNC Unix.Malware.Agent outbound connection attempt (more info ...)trojan-activity    URL
51801MALWARE-CNC Unix.Malware.Agent outbound connection attempt (more info ...)trojan-activity    URL
51898OS-OTHER Cisco Nexus OS software command injection attempt (more info ...)attempted-admin 2011-2569   URL
52127POLICY-OTHER Cisco Web Security Appliance system setup wizard access detected (more info ...)policy-violation 2019-15956   URL
52128POLICY-OTHER Cisco Web Security Appliance system setup wizard access detected (more info ...)policy-violation 2019-15956   URL
52554MALWARE-CNC Unix.Trojan.Mirai variant outbound Technicolor TD5130v2 TD5336 routers command injection attempt (more info ...)trojan-activity 2019-18396   
52559SERVER-WEBAPP Cisco IOS Web UI cross site request forgery attempt (more info ...)attempted-user 2019-16009   URL
52560SERVER-WEBAPP Cisco IOS Web UI cross site request forgery attempt (more info ...)attempted-user 2019-16009   URL
52588MALWARE-CNC Unix.Trojan.Mirai Enigma NMS command injection attempt (more info ...)trojan-activity 2019-16072   
52824MALWARE-CNC Unix.Trojan.Muhstik variant IRC outbound connection (more info ...)trojan-activity    URL
52993POLICY-OTHER Cisco Small Business Series Switches admin settings page access detected (more info ...)policy-violation 2019-15993   URL
52994POLICY-OTHER Cisco Small Business Series Switches device configuration page access detected (more info ...)policy-violation 2019-15993   URL
52995POLICY-OTHER Cisco Small Business Series Switches device configuration page access detected (more info ...)policy-violation 2019-15993   URL
53142MALWARE-CNC Win.Trojan.Syscon variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53143MALWARE-CNC Win.Trojan.Syscon variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53144MALWARE-CNC Win.Trojan.Syscon variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53170SERVER-OTHER Cisco Email Security Appliance mail log parsing denial of service attempt (more info ...)attempted-dos 2019-1983   URL
53172POLICY-OTHER Cisco Data Center Network Manager user add detected (more info ...)policy-violation 2019-3114   URL
53173POLICY-OTHER Cisco Data Center Network Manager server properties update detected (more info ...)policy-violation 2020-3112   URL
53174POLICY-OTHER Cisco Data Center Network Manager saveDefaultCredentials detected (more info ...)policy-violation 2020-3112   URL
53392POLICY-OTHER Cisco Prime Network Registrar AddObject request detected (more info ...)policy-violation 2020-3148   URL
53393POLICY-OTHER Cisco Prime Network Registrar EditAdmin request detected (more info ...)policy-violation 2020-3148   URL
53400MALWARE-CNC Unix.Trojan.snoopy TCP connection attempt (more info ...)trojan-activity    URL
53401MALWARE-CNC Unix.Trojan.snoopy TCP connection attempt (more info ...)trojan-activity    URL
53551MALWARE-OTHER Unix.Malware.Lotoor-7645228-0 download attempt (more info ...)trojan-activity    URL
53552MALWARE-OTHER Unix.Malware.Lotoor-7645228-0 download attempt (more info ...)trojan-activity    URL
53595MALWARE-OTHER PUA.Unix.Adware.Mobidash-7648778-0 download attempt (more info ...)trojan-activity    URL
53596MALWARE-OTHER PUA.Unix.Adware.Mobidash-7648778-0 download attempt (more info ...)trojan-activity    URL
53667POLICY-OTHER Cisco Unified Communications Manager TAPS RMI method lookup detected (more info ...)policy-violation 2020-3177   URL
53697MALWARE-OTHER Unix.Exploit.Generic-7664564-0 download attempt (more info ...)trojan-activity    URL
53698MALWARE-OTHER Unix.Exploit.Generic-7664564-0 download attempt (more info ...)trojan-activity    URL
53699MALWARE-OTHER Unix.Trojan.Feejar-7665621-0 download attempt (more info ...)trojan-activity    URL
53700MALWARE-OTHER Unix.Trojan.Feejar-7665621-0 download attempt (more info ...)trojan-activity    URL
53701MALWARE-OTHER Unix.Trojan.Mirai-7666587-0 download attempt (more info ...)trojan-activity    URL
53702MALWARE-OTHER Unix.Trojan.Mirai-7666587-0 download attempt (more info ...)trojan-activity    URL
54083MALWARE-OTHER PUA.Unix.Adware.Mobidash-7914334-0 download attempt (more info ...)trojan-activity    URL
54084MALWARE-OTHER PUA.Unix.Adware.Mobidash-7914334-0 download attempt (more info ...)trojan-activity    URL
54155SERVER-OTHER Cisco IOx Application Environment external VDS control message attempt (more info ...)attempted-user 2020-3258   URL
54161POLICY-OTHER Cisco IOx token service access detected (more info ...)policy-violation 2020-3227   URL
54163PROTOCOL-VOIP Cisco IOS malformed SIP Via header denial of service attempt (more info ...)attempted-dos 2020-3226   URL
54164PROTOCOL-VOIP Cisco IOS malformed SIP Via header denial of service attempt (more info ...)attempted-dos 2020-3226   URL
54306POLICY-OTHER Novell ZENworks Configuration Management session id disclosure attempt (more info ...)policy-violation 2015-0784 74289  
54332POLICY-OTHER Cisco TelePresence API SoftwareUpgrade SystemUnit command detected (more info ...)policy-violation 2020-3336   URL
54417MALWARE-OTHER PUA.Unix.Adware.Macsearch-8347867-0 download attempt (more info ...)trojan-activity    URL
54418MALWARE-OTHER PUA.Unix.Adware.Macsearch-8347867-0 download attempt (more info ...)trojan-activity    URL
54544POLICY-OTHER Cisco RV110W Router default credential login detected (more info ...)policy-violation 2020-3330   URL
54553POLICY-OTHER Cisco SD-WAN vManage file upload detected (more info ...)policy-violation 2020-3381   URL
54564POLICY-OTHER Cisco RV Series Routers configuration download detected (more info ...)policy-violation 2020-3146   URL
54656POLICY-OTHER Cisco Data Center Network Manager device manager access detected (more info ...)policy-violation 2020-3376   URL
54696POLICY-OTHER Cisco Data Center Network Manager privileged API access detected (more info ...)policy-violation 2020-3386   URL
54697POLICY-OTHER Cisco Data Center Network Manager privileged API access detected (more info ...)policy-violation 2020-3386   URL
54698POLICY-OTHER Cisco Data Center Network Manager privileged API access detected (more info ...)policy-violation 2020-3386   URL
54699POLICY-OTHER Cisco Data Center Network Manager privileged API access detected (more info ...)policy-violation 2020-3386   URL
54700POLICY-OTHER Cisco Data Center Network Manager privileged API access detected (more info ...)policy-violation 2020-3386   URL
54703MALWARE-CNC Unix.Malware.QSnatch infected QNAP device outbound communication attempt (more info ...)trojan-activity    URL
54793MALWARE-CNC Unix.Malware.Drovorub cnc inbound connection attempt (more info ...)trojan-activity    URL
54848MALWARE-OTHER Unix.Malware.Mrblack-9428384-0 download attempt (more info ...)trojan-activity    URL
54849MALWARE-OTHER Unix.Malware.Mrblack-9428384-0 download attempt (more info ...)trojan-activity    URL
55795MALWARE-OTHER PUA.Unix.Adware.Cimpli-9764278-0 download attempt (more info ...)trojan-activity    URL
55796MALWARE-OTHER PUA.Unix.Adware.Cimpli-9764278-0 download attempt (more info ...)trojan-activity    URL
55808POLICY-OTHER Cisco IOS Software VLPWA file read detected (more info ...)policy-violation 2020-3426   URL
55815POLICY-OTHER Cisco IOS XE WebUI administrative access detected (more info ...)policy-violation 2020-3141   URL
55816POLICY-OTHER Cisco IOS XE WebUI administrative access detected (more info ...)policy-violation 2020-3141   URL
55817POLICY-OTHER Cisco IOS XE WebUI administrative access detected (more info ...)policy-violation 2020-3141   URL
55818POLICY-OTHER Cisco IOS XE WebUI administrative access detected (more info ...)policy-violation 2020-3425   URL
55833POLICY-OTHER Cisco IOS XE WebUI restricted character in authentication detected (more info ...)policy-violation 2020-3516   URL
56087SERVER-WEBAPP Cisco ASA and FTD web services large file upload denial of service attempt (more info ...)attempted-dos 2020-3436   URL
56088MALWARE-CNC Unix.Spyware.WellMess variant outbound cnc attempt (more info ...)trojan-activity    URL
56408POLICY-OTHER Cisco Security Manager vulnerable CsJaasServiceServlet access detected (more info ...)policy-violation 2020-27131   URL
56409POLICY-OTHER Cisco Security Manager vulnerable SecretService.jsp access detected (more info ...)policy-violation 2020-27131   URL
56410POLICY-OTHER Cisco Security Manager vulnerable AuthTokenServlet access detected (more info ...)policy-violation 2020-27131   URL
56411POLICY-OTHER Cisco Security Manager vulnerable ClientServicesServlet access detected (more info ...)policy-violation 2020-27131   URL
56412POLICY-OTHER Cisco Security Manager vulnerable CTMServlet access detected (more info ...)policy-violation 2020-27131   URL
56413POLICY-OTHER Cisco Security Manager vulnerable SecretServiceServlet access detected (more info ...)policy-violation 2020-27131   URL
56431POLICY-OTHER Cisco IoT Field Network Director access detected (more info ...)policy-violation 2020-3531   URL
56447POLICY-OTHER Cisco IoT Field Network Director access detected (more info ...)policy-violation 2020-3392   URL
56448POLICY-OTHER Cisco IoT Field Network Director access detected (more info ...)policy-violation 2020-26072   URL
56819MALWARE-OTHER Unix.Miner.PGMiner variant exploit attempt (more info ...)trojan-activity    URL
56820MALWARE-OTHER Unix.Miner.PGMiner variant dropped bash script (more info ...)trojan-activity    URL
56821MALWARE-OTHER Unix.Miner.PGMiner variant exploit attempt (more info ...)trojan-activity    URL
56955POLICY-OTHER Cisco Smart Software Manager Satellite Web UI user creation detected (more info ...)policy-violation 2021-1142   URL
56956POLICY-OTHER Cisco Data Center Network Manager session validation request detected (more info ...)policy-violation 2021-1272   URL
56957POLICY-OTHER Cisco SD-WAN vManage terminal request detected (more info ...)policy-violation 2021-1302   URL
56958POLICY-OTHER Cisco SD-WAN vManage terminal request detected (more info ...)policy-violation 2021-1304   URL
56959POLICY-OTHER Cisco SD-WAN vManage enumeration request detected (more info ...)policy-violation 2021-1304   URL
56960POLICY-OTHER Cisco SD-WAN vManage enumeration request detected (more info ...)policy-violation 2021-1304   URL
56961POLICY-OTHER Cisco SD-WAN vManage enumeration request detected (more info ...)policy-violation 2021-1304   URL
56962POLICY-OTHER Cisco SD-WAN vManage configuration request detected (more info ...)policy-violation 2021-1304   URL
56963POLICY-OTHER Cisco SD-WAN vManage request detected (more info ...)policy-violation 2021-1305   URL
57087SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)attempted-admin 2021-1289   URL
57090SERVER-WEBAPP Cisco Small Business RV series routers denial of service attempt (more info ...)attempted-user 2021-1325   URL
57091SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)attempted-admin 2021-1290   URL
57092SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack 2021-1295   URL
57093SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)attempted-admin 2021-1289   URL
57094SERVER-WEBAPP Cisco RV Series Routers command injection attempt (more info ...)web-application-attack 2021-1291   URL
57097SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin 2021-1293   URL
57223POLICY-OTHER Cisco Application Services Engine API access detected (more info ...)policy-violation 2021-1396   URL
57300SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin 2021-1287   URL
57368MALWARE-CNC Unix.Malware.Exaramel outbound connection attempt (more info ...)trojan-activity    URL
57369MALWARE-CNC Unix.Malware.Exaramel outbound connection attempt (more info ...)trojan-activity    URL
57370MALWARE-CNC Unix.Malware.Exaramel outbound connection attempt (more info ...)trojan-activity    URL
57401SERVER-WEBAPP Cisco RV Series Routers stack buffer overflow attempt (more info ...)attempted-admin 2021-1459   URL
57448SERVER-OTHER Cisco FTD SSL inspection denial of service attempt (more info ...)attempted-dos 2020-3562   URL
57451MALWARE-CNC Unix.Trojan.Malcodecov data exfiltration attempt (more info ...)trojan-activity    URL
57529SERVER-WEBAPP Cisco HyperFlex HX Installer command injection attempt (more info ...)web-application-attack 2021-1497   URL
57530SERVER-WEBAPP Cisco HyperFlex HX Installer command injection attempt (more info ...)web-application-attack 2021-1497   URL
57531SERVER-WEBAPP Cisco HyperFlex HX Installer command injection attempt (more info ...)web-application-attack 2021-1497   URL
57535POLICY-OTHER Cisco SD-WAN vManage administrator API access detected (more info ...)policy-violation 2021-1505   URL
57536SERVER-WEBAPP Novell eDirectory iMonitor crafted Accept-Language header buffer overflow attempt (more info ...)attempted-user 2009-0192   
57538POLICY-OTHER Cisco SD-WAN vManage cluster API access detected (more info ...)policy-violation 2021-1508   URL
57886POLICY-OTHER Cisco Business Process Automation permissions modification detected (more info ...)policy-violation 2021-1574   URL
58061POLICY-OTHER Cisco TelePresence Video Communication Server upgrade request detected (more info ...)policy-violation 2021-34716   URL
58062MALWARE-CNC Unix.Backdoor.SNIcat outbound request attempt (more info ...)trojan-activity 2021-34749   URL
58110POLICY-OTHER Cisco BroadWorks administrator account modification detected (more info ...)policy-violation 2021-34786   URL
58182SERVER-OTHER Cisco IOS XE Software for CBR8 COPS denial of service attempt (more info ...)attempted-dos 2021-1622   URL
58189POLICY-OTHER Cisco IOS and IOS XE TrustSec deprecated API access detected (more info ...)policy-violation 2021-34699   URL
58190POLICY-OTHER Cisco IOS and IOS XE TrustSec deprecated API access detected (more info ...)policy-violation 2021-34699   URL
58346SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center UrlAccessController Filter directory traversal attempt (more info ...)web-application-attack 2017-5791   
58442SERVER-OTHER Cisco ASA and FTD denial of service attempt (more info ...)attempted-dos 2021-40117   URL
58486POLICY-OTHER Cisco Catalyst PON Series ONT enable telnet request detected (more info ...)policy-violation 2021-40112   URL
58488POLICY-OTHER Cisco Catalyst PON Series ONT default credential login detected (more info ...)policy-violation 2021-34795   URL
58971POLICY-OTHER Cisco PnP image_install response detected (more info ...)policy-violation 2022-20703   URL
58989SERVER-WEBAPP Cisco RV Series Routers denial of service attempt (more info ...)attempted-dos 2022-20710   URL
59060POLICY-OTHER Cisco RV Series Routers driver upload detected (more info ...)policy-violation 2022-20700   URL
59065SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59066SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59067SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59068SERVER-WEBAPP Trend Micro SafeSync for Enterprise discovery_iscsi_device command injection attempt (more info ...)web-application-attack    
59069SERVER-WEBAPP Trend Micro SafeSync for Enterprise discovery_iscsi_device command injection attempt (more info ...)web-application-attack    
59078SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59079SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59232SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59233SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59234SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59235SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance command injection attempt (more info ...)web-application-attack    
59587POLICY-OTHER Schneider Electric UDP discovery packet detected (more info ...)policy-violation    URL
59654SERVER-WEBAPP Cisco ASA and FTD web services denial of service attempt (more info ...)attempted-dos 2022-20745   URL
59658SERVER-WEBAPP Cisco ASA and FTD SSL VPN heap buffer overflow attempt (more info ...)attempted-dos 2022-20737   URL
59659SERVER-WEBAPP Cisco ASA and FTD SSL VPN heap buffer overflow attempt (more info ...)attempted-dos 2022-20737   URL
59660SERVER-WEBAPP Cisco ASA and FTD SSL VPN heap buffer overflow attempt (more info ...)attempted-dos 2022-20737   URL
59661SERVER-WEBAPP Cisco ASA and FTD SSL VPN heap buffer overflow attempt (more info ...)attempted-dos 2022-20737   URL
59662SERVER-WEBAPP Cisco ASA and FTD SSL VPN heap buffer overflow attempt (more info ...)attempted-dos 2022-20737   URL
59668SERVER-WEBAPP Cisco ASA and FTD privilege escalation attempt (more info ...)attempted-admin 2022-20759   URL
59670SERVER-WEBAPP Cisco Firepower Management Console security bypass file upload attempt (more info ...)attempted-user 2022-20743   URL
60273POLICY-OTHER Cisco Nexus Dashboard Kubernetes API access detected (more info ...)policy-violation 2022-20857   URL
60274POLICY-OTHER Cisco Nexus Dashboard Kubernetes API access detected (more info ...)policy-violation 2022-20857   URL
60514MALWARE-CNC Unix.Backdoor.KeyPlug variant outbound connection (more info ...)trojan-activity    URL
60515MALWARE-CNC Unix.Backdoor.KeyPlug variant outbound connection (more info ...)trojan-activity    URL
60624POLICY-OTHER Cisco IOS XE Wireless Controller PSK SNMP get request detected (more info ...)policy-violation 2022-20810   URL
60628SERVER-OTHER Cisco IOS XE Wireless Controller DHCP processing denial of service attempt (more info ...)attempted-dos 2022-20847   URL
60817MALWARE-CNC Unix.Trojan.RedXOR variant outbound connection (more info ...)trojan-activity    URL
60895MALWARE-CNC Unix.Downloader.Shikitega variant payload download attempt (more info ...)trojan-activity    URL
61367SERVER-WEBAPP Cisco Email Security Appliance arbitrary code execution attempt (more info ...)attempted-admin 2023-20009   URL
61450SERVER-WEBAPP Cisco IP Phone web interface stack buffer overflow attempt (more info ...)attempted-admin 2023-20079   URL
61724POLICY-OTHER Cisco SD-WAN vManage cluster mode access (more info ...)policy-violation 2023-20113   URL
61725POLICY-OTHER Cisco SD-WAN vManage cluster mode access (more info ...)policy-violation 2023-20113   URL
61726POLICY-OTHER Cisco SD-WAN vManage cluster mode access (more info ...)policy-violation 2023-20113   URL
61727POLICY-OTHER Cisco SD-WAN vManage cluster mode acess (more info ...)policy-violation 2023-20113   URL
61728POLICY-OTHER Cisco SD-WAN vManage cluster mode access (more info ...)policy-violation 2023-20113   URL
61729POLICY-OTHER Cisco SD-WAN vManage cluster mode access (more info ...)policy-violation 2023-20113   URL
62048POLICY-OTHER Cisco SD-WAN vManage REST API access detected (more info ...)policy-violation 2023-20214   URL

 goto Top

Group: Server

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / HTTP

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / HTTP / Common

# of attack rules in this group: 14

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
18525SERVER-OTHER Lotus Domino LDAP Heap Buffer Overflow Attempt (more info ...)attempted-user  2010-0358      
26369MALWARE-OTHER Double HTTP Server declared (more info ...)trojan-activity        
35944SERVER-MAIL IBM Domino BMP color palette stack buffer overflow attempt (more info ...)attempted-admin  2015-1903  74598    
36153SERVER-OTHER IBM Domino LDAP server ModifyRequest stack buffer overflow attempt (more info ...)attempted-admin  2015-0117  73911    URL
39654SERVER-MAIL IBM Lotus Domino Server nrouter.exe malformed GIF parsing remote exploit attempt (more info ...)attempted-user  2015-0135  74194    URL
39655SERVER-MAIL IBM Lotus Domino Server nrouter.exe malformed GIF parsing remote exploit attempt (more info ...)attempted-user  2015-0135  74194    URL
42438SERVER-MAIL IBM Domino BMP parsing integer overflow attempt (more info ...)attempted-admin  2015-1902  74597    URL
49094BROWSER-PLUGINS IBM Lotus Domino Quickr ActiveX clsid access attempt (more info ...)attempted-user  2013-3026      
49095BROWSER-PLUGINS IBM Lotus Domino Quickr ActiveX clsid access attempt (more info ...)attempted-user  2013-3026      
49096BROWSER-PLUGINS IBM Lotus Domino Quickr ActiveX clsid access attempt (more info ...)attempted-user  2013-3026      
49097BROWSER-PLUGINS IBM Lotus Domino Quickr ActiveX clsid access attempt (more info ...)attempted-user  2013-3026      
52561POLICY-OTHER Yachtcontrol webserver unauthenticated remote code execution attempt (more info ...)attempted-user  2019-17270      
52562POLICY-OTHER Yachtcontrol webserver unauthenticated remote code execution attempt (more info ...)attempted-user  2019-17270      
59417SERVER-OTHER Git HTTP server submodule potential remote code execution attempt (more info ...)attempted-user  2017-1000117      


# of warning rules in this group: 67

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1072SERVER-WEBAPP Lotus Domino directory traversal (more info ...)web-application-attack 2001-0009 2173 12248 
1115SERVER-WEBAPP ICQ webserver DOS (more info ...)attempted-dos 1999-0474   URL
1150SERVER-WEBAPP Domino catalog.nsf access (more info ...)attempted-recon   10629 
1151SERVER-WEBAPP Domino domcfg.nsf access (more info ...)attempted-recon   10629 
1152SERVER-WEBAPP Domino domlog.nsf access (more info ...)attempted-recon   10629 
1153SERVER-WEBAPP Domino log.nsf access (more info ...)attempted-recon   10629 
1154SERVER-WEBAPP Domino names.nsf access (more info ...)attempted-recon   10629 
1505SERVER-WEBAPP alchemy http server PRN arbitrary command execution attempt (more info ...)web-application-activity 2001-0871 3599 10818 
1506SERVER-WEBAPP alchemy http server NUL arbitrary command execution attempt (more info ...)web-application-activity 2001-0871 3599 10818 
1575SERVER-WEBAPP Domino mab.nsf access (more info ...)attempted-recon 2001-1567 4022 10953 
1576SERVER-WEBAPP Domino cersvr.nsf access (more info ...)attempted-recon   10629 
1577SERVER-WEBAPP Domino setup.nsf access (more info ...)attempted-recon   10629 
1578SERVER-WEBAPP Domino statrep.nsf access (more info ...)attempted-recon   10629 
1579SERVER-WEBAPP Domino webadmin.nsf access (more info ...)attempted-recon 2004-2369 9901 10629 
1580SERVER-WEBAPP Domino events4.nsf access (more info ...)attempted-recon   10629 
1581SERVER-WEBAPP Domino ntsync4.nsf access (more info ...)attempted-recon   10629 
1582SERVER-WEBAPP Domino collect4.nsf access (more info ...)attempted-recon   10629 
1583SERVER-WEBAPP Domino mailw46.nsf access (more info ...)attempted-recon   10629 
1584SERVER-WEBAPP Domino bookmark.nsf access (more info ...)attempted-recon   10629 
1585SERVER-WEBAPP Domino agentrunner.nsf access (more info ...)attempted-recon   10629 
1586SERVER-WEBAPP Domino mail.box access (more info ...)attempted-recon 2000-0023 881 10629 
13258BROWSER-PLUGINS IBM Lotus Domino Web Access 6 ActiveX clsid access (more info ...)attempted-user 2010-0919 26972  
13260BROWSER-PLUGINS IBM Lotus Domino Web Access 6 ActiveX function call access (more info ...)attempted-user 2010-0919 26972  
13262BROWSER-PLUGINS IBM Lotus Domino Web Access 7 ActiveX clsid access (more info ...)attempted-user 2010-0919 26972  
13264BROWSER-PLUGINS IBM Lotus Domino Web Access 7 ActiveX function call access (more info ...)attempted-user 2010-0919 26972  
15956SERVER-ORACLE http Server mod_access restriction bypass attempt (more info ...)attempted-user 2005-1383 13418  
16017SERVER-OTHER IBM Lotus Domino LDAP server invalid DN message buffer overflow attempt (more info ...)attempted-user 2007-1739 23174  
16060SERVER-OTHER IBM Lotus Domino LDAP server memory exception attempt (more info ...)attempted-dos 2006-0580 16523  
16671BROWSER-PLUGINS IBM Lotus Domino Web Access ActiveX exploit attempt (more info ...)attempted-user 2010-0919 26972  
17466BROWSER-PLUGINS IBM Lotus Domino Web Access 7 ActiveX exploit attempt (more info ...)attempted-user 2010-0919 26972  
17545BROWSER-PLUGINS Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user 2010-0919 38457  URL
18461SERVER-MAIL IBM Lotus Domino nrouter.exe iCalendar MAILTO stack buffer overflow attempt (more info ...)attempted-admin 2010-3407 43219  URL
21358SERVER-WEBAPP iPlanet Webserver command injection attempt (more info ...)web-application-attack 2002-1315 6202  
23433SERVER-WEBAPP IBM Lotus Domino cross site scripting attempt (more info ...)web-application-attack 2005-3015 14845  
23434SERVER-WEBAPP IBM Lotus Domino cross site scripting attempt (more info ...)web-application-attack 2005-3015 14845  
23480SERVER-WEBAPP IBM Lotus Domino webadmin.nsf directory traversal attempt (more info ...)web-application-attack 2004-2369 9900  
30011SERVER-WEBAPP GE Proficy CIMPLICITY CimWebServer remote code execution attempt (more info ...)attempted-admin 2014-0750 65124  URL
30031SERVER-WEBAPP IBM Lotus Domino stack buffer overflow attempt (more info ...)web-application-attack 2011-3575 49705  
30341SERVER-WEBAPP Cisco CatOS CiscoView HTTP server buffer overflow attempt (more info ...)attempted-dos    URL
30342SERVER-WEBAPP Cisco IOS HTTP server denial of service attempt (more info ...)attempted-dos  1838  URL
35928SERVER-WEBAPP IBM Domino cross site scripting attempt (more info ...)web-application-attack    
37495FILE-PDF IBM Domino KeyView PDF filter compressed stream length code execution attempt (more info ...)attempted-user 2016-0278   URL
37496FILE-PDF IBM Domino KeyView PDF filter compressed stream length code execution attempt (more info ...)attempted-user 2016-0278   URL
37498FILE-PDF IBM Domino KeyView PDF filter encrypted stream code execution attempt (more info ...)attempted-user 2016-0277   URL
37499FILE-PDF IBM Domino KeyView PDF Filter Basefont string overflow attempt (more info ...)attempted-user 2016-0279   URL
37500FILE-PDF IBM Domino KeyView PDF Filter Basefont string overflow attempt (more info ...)attempted-user 2016-0279   URL
37501FILE-PDF IBM Domino KeyView PDF Filter Trailer ID array heap buffer overflow attempt (more info ...)attempted-user 2016-0301   URL
37502FILE-PDF IBM Domino KeyView PDF Filter Trailer ID array heap buffer overflow attempt (more info ...)attempted-user 2016-0301   URL
41187SERVER-WEBAPP IBM Lotus Domino BOX mailbox information disclosure attempt (more info ...)attempted-recon    URL
41188SERVER-WEBAPP IBM Lotus Domino NSF database information disclosure attempt (more info ...)attempted-recon    URL
41189SERVER-WEBAPP IBM Lotus Domino srvnam.htm information disclosure attempt (more info ...)attempted-recon    URL
41747PROTOCOL-SCADA Moxa SoftCMS webserver DOS attempt (more info ...)attempted-dos    
43349SERVER-OTHER Karjasoft Sami HTTP Server denial of service attempt (more info ...)denial-of-service 2007-0548   
44378SERVER-WEBAPP Easy File Sharing HTTP Server Post buffer overflow attempt (more info ...)web-application-attack    
46540SERVER-WEBAPP UltiDev Cassini Webserver file download attempt (more info ...)web-application-attack    URL
51406BROWSER-PLUGINS Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user 2010-0919 38457  URL
51407BROWSER-PLUGINS Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user 2010-0919 38457  URL
51408BROWSER-PLUGINS Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user 2010-0919 38457  URL
51409BROWSER-PLUGINS Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user 2010-0919 38457  URL
51410BROWSER-PLUGINS Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user 2010-0919 38457  URL
51411BROWSER-PLUGINS Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user 2010-0919 38457  URL
51412BROWSER-PLUGINS Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user 2010-0919 38457  URL
52563MALWARE-CNC Unix.Trojan.Mirai variant outbound Yachtcontrol webserver unauthenticated remote code execution attempt (more info ...)trojan-activity 2019-17270   
52564MALWARE-CNC Unix.Trojan.Mirai variant outbound Yachtcontrol webserver unauthenticated remote code execution attempt (more info ...)trojan-activity 2019-17270   
57875SERVER-WEBAPP IBM Lotus Domino Web Service denial of service attempt (more info ...)attempted-user 2005-0986 13045  
59418SERVER-OTHER Git HTTP server submodule potential remote code execution attempt (more info ...)attempted-user 2017-1000117   
59419SERVER-OTHER Git HTTP server submodule potential remote code execution attempt (more info ...)attempted-user 2017-1000117   

 goto Top

Group: Server / HTTP / Apache

# of attack rules in this group: 164

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
14771SERVER-APACHE BEA WebLogic Apache Oracle connector Transfer-Encoding buffer overflow attempt (more info ...)attempted-admin  2008-4008  31683    URL
15511SERVER-APACHE Oracle WebLogic Apache Connector buffer overflow attempt (more info ...)attempted-admin  2008-3257  30273    URL
16198SERVER-APACHE Apache mod_auth_pgsql module logging facility format string exploit attempt (more info ...)attempted-user  2005-3656  16153    
16479SERVER-APACHE Apache mod_isapi dangling pointer exploit attempt - public shell code (more info ...)attempted-admin  2010-0425  38494    
16480SERVER-APACHE Apache mod_isapi dangling pointer exploit attempt (more info ...)attempted-admin  2010-0425  38494    
17156SERVER-APACHE HP Performance Manager Apache Tomcat policy bypass attempt (more info ...)attempted-admin  2009-3843  37086    
18283SERVER-APACHE Oracle WebLogic Apache Connector buffer overflow attempt (more info ...)attempted-admin  2008-3257  30273    URL
19107SERVER-APACHE Apache mod_isapi dangling pointer code execution attempt (more info ...)attempted-admin  2010-0425  38494    
19124SERVER-APACHE Apache mod_isapi dangling pointer exploit attempt (more info ...)attempted-admin  2010-0425  38494    
21072SERVER-APACHE Apache Struts remote code execution attempt - GET parameter (more info ...)attempted-admin  2016-3081      URL
21073SERVER-APACHE Apache Struts allowStaticMethodAccess invocation attempt (more info ...)attempted-admin  2012-0391      URL
21075SERVER-APACHE Apache Struts remote code execution attempt - DebuggingInterceptor (more info ...)attempted-admin  2012-0394      URL
21656SERVER-APACHE Apache Struts remote code execution attempt - GET parameter (more info ...)attempted-admin  2016-3081      URL
23631SERVER-APACHE Apache Struts remote code execution attempt - POST parameter (more info ...)attempted-admin  2017-9791      URL
26772SERVER-OTHER Apache Struts2 skillName remote code execution attempt (more info ...)attempted-admin  2013-1965  60082    
26824SERVER-OTHER Apache Struts allowStaticMethodAccess invocation attempt (more info ...)attempted-admin  2013-2115  60166    URL
26825SERVER-OTHER Apache Struts allowStaticMethodAccess invocation attempt (more info ...)attempted-admin  2013-2115  60166    URL
27243SERVER-APACHE Apache Struts2 blacklisted method redirectAction (more info ...)web-application-attack  2013-2251      URL
27244SERVER-APACHE Apache Struts2 blacklisted method redirect (more info ...)web-application-attack  2013-2251      URL
27245SERVER-APACHE Apache Struts2 remote code execution attempt (more info ...)web-application-attack  2013-2251      URL
27572SERVER-APACHE Apache Struts wildcard matching OGNL remote code execution attempt (more info ...)attempted-admin  2013-2134  60346    URL
27573SERVER-APACHE Apache Struts wildcard matching OGNL remote code execution attempt (more info ...)attempted-admin  2013-2134  60346    URL
27574SERVER-APACHE Apache Struts OGNL getRuntime.exec static method access attempt (more info ...)attempted-admin  2013-2135  60346    URL
27575SERVER-APACHE Apache Struts arbitrary OGNL remote code execution attempt (more info ...)attempted-admin  2013-2135  60345    URL
29523SERVER-APACHE Oracle WebLogic Apache Connector buffer overflow attempt (more info ...)attempted-admin  2008-3257  30273    URL
29747SERVER-APACHE Apache Struts2 blacklisted method redirect (more info ...)web-application-attack  2013-2251      URL
29748SERVER-APACHE Apache Struts2 blacklisted method redirect (more info ...)web-application-attack  2013-2251      URL
29859SERVER-APACHE Apache Struts allowStaticMethodAccess invocation attempt (more info ...)attempted-admin  2013-2115  60166    URL
38392SERVER-WEBAPP Apache Jetspeed Portal Site Manager directory traversal attempt (more info ...)attempted-admin  2016-0709      URL
38393SERVER-WEBAPP Apache Jetspeed Portal Site Manager directory traversal attempt (more info ...)attempted-admin  2016-0709      URL
39190SERVER-APACHE Apache Struts remote code execution attempt (more info ...)attempted-admin  2018-11776      URL
39191SERVER-APACHE Apache Struts remote code execution attempt (more info ...)attempted-admin  2018-11776      URL
40359SERVER-APACHE Apache Struts xslt.location local file inclusion attempt (more info ...)attempted-admin  2016-3082      URL
40846SERVER-APACHE Apache Subversion svnserve integer overflow attempt (more info ...)attempted-user  2015-5259      URL
40847SERVER-APACHE Apache Subversion svnserve integer overflow attempt (more info ...)attempted-user  2015-5259      URL
40848SERVER-APACHE Apache Subversion svnserve integer overflow attempt (more info ...)attempted-user  2015-5259      URL
40849SERVER-APACHE Apache Subversion svnserve integer overflow attempt (more info ...)attempted-user  2015-5259      URL
41390SERVER-WEBAPP Apache Commons Library FileUpload unauthorized Java object upload attempt (more info ...)attempted-user  2016-1000031      URL
41818SERVER-APACHE Apache Struts remote code execution attempt (more info ...)attempted-admin  2017-9791      URL
41819SERVER-APACHE Apache Struts remote code execution attempt (more info ...)attempted-admin  2017-9791      URL
41922SERVER-APACHE Apache Struts remote code execution attempt (more info ...)attempted-admin  2019-0230      URL
41923SERVER-APACHE Apache Struts remote code execution attempt (more info ...)attempted-admin  2019-0230      URL
43790SERVER-OTHER Apache mod_auth_digest out of bounds read attempt (more info ...)attempted-user  2017-9788      URL
44327SERVER-APACHE Apache Struts freemarker tag OGNL expression injection attempt (more info ...)attempted-admin  2017-12611      URL
44328SERVER-APACHE Apache Struts freemarker tag OGNL expression injection attempt (more info ...)attempted-admin  2020-17530      URL
44329SERVER-APACHE Apache Struts freemarker tag OGNL expression injection attempt (more info ...)attempted-admin  2017-12611      URL
44330SERVER-APACHE Apache Struts freemarker tag OGNL expression injection attempt (more info ...)attempted-admin  2017-12611      URL
44531SERVER-APACHE Apache Tomcat remote JSP file upload attempt (more info ...)attempted-user  2017-12617  100954    URL
44890SERVER-OTHER Apache CouchDB remote privilege escalation attempt (more info ...)attempted-user  2017-12635      
45083SERVER-APACHE Apache Solr RunExecutableListener arbitrary command execution attempt (more info ...)attempted-admin  2017-12629  101261    
45084SERVER-APACHE Apache Solr xmlparser external doctype or entity expansion attempt (more info ...)web-application-attack  2017-12629  101261    
45269SERVER-OTHER Apache CouchDB remote code execution attempt (more info ...)attempted-user  2017-12636      
45353SERVER-APACHE Sling framework information disclosure attempt (more info ...)web-application-attack  2016-0956      URL
46071SERVER-APACHE Apache Tomcat Java JmxRemoteLifecycleListener unauthorized serialized object attempt (more info ...)attempted-user  2016-8735      URL
46440SERVER-OTHER Apache CouchDB remote code execution attempt (more info ...)attempted-user  2017-12636      
47615SERVER-APACHE Apache Tika crafted HTTP header command injection attempt (more info ...)attempted-user  2018-1335      
47634SERVER-APACHE Apache Struts OGNL getRuntime.exec static method access attempt (more info ...)attempted-admin  2018-11776      URL
47649SERVER-WEBAPP Apache Struts remote code execution attempt (more info ...)attempted-user  2018-11776      URL
47689SERVER-APACHE Apache Struts java.net.Socket class access attempt (more info ...)attempted-user  2018-11776      URL
47690SERVER-APACHE Apache Struts java.lang.ProcessBuilder class access attempt (more info ...)attempted-user  2020-17530      URL
47691SERVER-APACHE Apache Struts ognl remote code execution attempt (more info ...)attempted-user  2018-11776      URL
48231SERVER-WEBAPP Apache Syncope XSL transform code injection attempt (more info ...)web-application-attack  2018-1321      URL
48232SERVER-WEBAPP Apache Syncope XSL transform code injection attempt (more info ...)web-application-attack  2018-1321      URL
48381SERVER-APACHE Apache Tomcat mod_jk access control bypass attempt (more info ...)attempted-user  2018-11759      
48382SERVER-APACHE Apache Tomcat mod_jk access control bypass attempt (more info ...)attempted-user  2018-11759      
48383SERVER-APACHE Apache Tomcat mod_jk access control bypass attempt (more info ...)attempted-user  2018-11759      
48384SERVER-APACHE Apache Tomcat mod_jk access control bypass attempt (more info ...)attempted-user  2018-11759      
48474SERVER-APACHE Apache Hadoop YARN ResourceManager arbitrary command execution attempt (more info ...)attempted-user        URL
48549SERVER-WEBAPP Apache Superset python pickle library remote code execution attempt (more info ...)attempted-user  2018-8021      
48550SERVER-WEBAPP Apache Superset python pickle library remote code execution attempt (more info ...)attempted-user  2018-8021      
48551SERVER-WEBAPP Apache Superset python pickle library remote code execution attempt (more info ...)attempted-user  2018-8021      
49376SERVER-APACHE Apache Struts remote code execution attempt (more info ...)attempted-admin  2017-9791      URL
49377SERVER-APACHE Apache Struts remote code execution attempt (more info ...)attempted-admin  2017-9791      URL
49557SERVER-WEBAPP Apache Solr jmx.serviceUrl remote code execution attempt (more info ...)attempted-admin  2019-0192      URL
49885SERVER-APACHE Apache Struts2 remote code execution attempt (more info ...)web-application-attack  2013-2251      URL
52130SERVER-WEBAPP Apache Struts OGNL expression injection attempt (more info ...)attempted-admin  2017-9791      URL
52324SERVER-APACHE Apache Solr Velocity Response Writer remote code execution attempt (more info ...)attempted-user        URL
52325SERVER-APACHE Apache Solr Velocity Response Writer remote code execution attempt (more info ...)attempted-user        URL
52494SERVER-APACHE Apache httpd mod_remoteip heap buffer overflow attempt (more info ...)attempted-user  2019-10097      URL
53341SERVER-APACHE Apache Tomcat AJP connector arbitrary file access attempt (more info ...)attempted-user  2020-1938      
53475SERVER-OTHER Apache Log4j SocketServer insecure deserialization remote code execution attempt (more info ...)attempted-user  2019-17571      URL
54162SERVER-WEBAPP Apache Tomcat FileStore directory traversal attempt (more info ...)web-application-attack  2020-9484      
54650SERVER-WEBAPP Apache Kylin REST API migrate command injection attempt (more info ...)attempted-admin  2020-1956      URL
55978SERVER-OTHER Apache OFBiz XMLRPC deserialization attempt (more info ...)attempted-admin  2022-35405      URL
55999SERVER-APACHE Apache Struts denial of service attempt (more info ...)attempted-admin  2019-0233      URL
56000SERVER-APACHE Apache Struts denial of service attempt (more info ...)attempted-admin  2019-0233      URL
56001SERVER-APACHE Apache Struts denial of service attempt (more info ...)attempted-admin  2019-0233      URL
56990SERVER-WEBAPP Apache Unomi OGNL MVEL2 remote command execution attempt (more info ...)attempted-user  2020-13942      URL
57921SERVER-WEBAPP Apache OFBiz XMLRPC unsafe deserialization attempt (more info ...)attempted-user  2021-29200      
57984SERVER-OTHER Apache Dubbo insecure deserialization remote code execution attempt (more info ...)attempted-user  2021-25641      
58067SERVER-WEBAPP Apache Flink FileUploadHandler directory traversal attempt (more info ...)web-application-attack  2020-17518      
58068SERVER-WEBAPP Apache Flink FileUploadHandler directory traversal attempt (more info ...)web-application-attack  2020-17518      
58069SERVER-WEBAPP Apache Flink FileUploadHandler directory traversal attempt (more info ...)web-application-attack  2020-17518      
58276SERVER-WEBAPP Apache HTTP Server httpd directory traversal attempt (more info ...)web-application-attack  2021-42013      URL
58447SERVER-APACHE Apache Druid remote code execution attempt (more info ...)attempted-admin  2021-25646      URL
58722SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58723SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58724SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58725SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58726SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58727SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58728SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58729SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58730SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58731SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58732SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58733SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58734SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58735SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58736SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58737SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58738SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58739SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58740SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58741SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58742SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2022-20933      URL
58743SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58744SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58751SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58784SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58785SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58786SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58787SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58788SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58789SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58790SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58795SERVER-OTHER Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      
58802SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58803SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58804SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58805SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58806SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58807SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58808SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58809SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58810SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-user  2021-45105      URL
58820SERVER-APACHE Apache HTTP server SSRF attempt (more info ...)attempted-user  2021-40438      
58966SERVER-WEBAPP Apache Airflow command injection attempt (more info ...)web-application-attack  2020-11978      
59088SERVER-APACHE Apache Shiro HTTP Cookie insecure deserialization attempt (more info ...)attempted-user  2016-4437      URL
59115SERVER-APACHE Apache Druid JDBC connection remote code execution attempt (more info ...)attempted-user  2021-26919      
59246SERVER-WEBAPP Apache Log4j logging remote code execution attempt (more info ...)attempted-admin  2021-45105      URL
59274SERVER-APACHE Mod Proxy DOS Attempt (more info ...)denial-of-service  2021-44224      URL
59333SERVER-WEBAPP Apache Kylin REST API DiagnosisService command injection attempt (more info ...)web-application-attack  2020-13925      
59334SERVER-WEBAPP Apache Kylin REST API DiagnosisService command injection attempt (more info ...)web-application-attack  2020-13925      
59480SERVER-WEBAPP Apache APISIX default admin API backdoor usage attempt (more info ...)attempted-admin  2022-24112      URL
59481SERVER-WEBAPP Apache APISIX default admin API backdoor usage attempt (more info ...)attempted-admin  2022-24112      URL
59513SERVER-WEBAPP Apache APISIX Dashboard authentication bypass attempt (more info ...)web-application-attack  2021-45232      URL
59876SERVER-WEBAPP Apache Solr configset Java expression language injection attempt (more info ...)web-application-attack  2020-13957      URL
59906SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (more info ...)attempted-user  2021-31805      
60227SERVER-WEBAPP Apache httpd mod_lua req_parsebody denial of service attempt (more info ...)attempted-dos  2022-22719      
60358SERVER-WEBAPP Apache Spark command injection attempt (more info ...)web-application-attack  2022-33891      
60359SERVER-WEBAPP Apache Spark command injection attempt (more info ...)web-application-attack  2022-33891      
60360SERVER-WEBAPP Apache Spark command injection attempt (more info ...)web-application-attack  2022-33891      
60361SERVER-WEBAPP Apache Spark command injection attempt (more info ...)web-application-attack  2022-33891      
60737SERVER-OTHER Apache Commons Text string interpolation remote code execution attempt (more info ...)web-application-attack  2022-42889      
60738SERVER-OTHER Apache Commons Text string interpolation remote code execution attempt (more info ...)web-application-attack  2022-42889      
60739SERVER-OTHER Apache Commons Text string interpolation remote code execution attempt (more info ...)web-application-attack  2022-42889      
60740SERVER-OTHER Apache Commons Text string interpolation remote code execution attempt (more info ...)web-application-attack  2022-42889      
60741SERVER-OTHER Apache Commons Text string interpolation remote code execution attempt (more info ...)web-application-attack  2022-42889      
60742SERVER-OTHER Apache Commons Text string interpolation remote code execution attempt (more info ...)web-application-attack  2022-42889      
61390SERVER-WEBAPP Apache Kylin runSparkSubmit command injection attempt (more info ...)web-application-attack  2022-24697      
61454SERVER-WEBAPP Apache Kafka Connect remote code execution attempt (more info ...)attempted-user  2023-25194      URL
61472SERVER-WEBAPP Apache OFBiz XMLRPC unsafe deserialization attempt (more info ...)attempted-user  2021-26295      
62047SERVER-OTHER Apache RocketMQ command injection attempt (more info ...)attempted-admin  2023-33246      URL


# of warning rules in this group: 143

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1056SERVER-APACHE Apache Tomcat view source attempt (more info ...)web-application-attack 2001-0590 2527  
1108SERVER-APACHE Apache Tomcat server snoop access (more info ...)attempted-recon 2000-0760 1532 10478 
1110SERVER-WEBAPP apache source.asp file access (more info ...)attempted-recon 2000-0628 1457 10480 
1111SERVER-APACHE Apache Tomcat server exploit access (more info ...)attempted-recon 2000-0672 1548 10477 
1519SERVER-WEBAPP apache ?M=D directory list attempt (more info ...)web-application-activity 2001-0731 3009 10704 
1808SERVER-WEBAPP Apache chunked-encoding memory corruption exploit attempt (more info ...)web-application-activity 2002-0392 5033  
1809SERVER-APACHE Apache chunked-encoding worm attempt (more info ...)web-application-attack 2002-0392 5033 10932 
1827SERVER-APACHE Apache Tomcat servlet mapping cross site scripting attempt (more info ...)web-application-attack 2002-0682 5193 11041 
1829SERVER-APACHE Apache Tomcat TroubleShooter servlet access (more info ...)web-application-activity 2002-2006 4575 11046 
1830SERVER-APACHE Apache Tomcat SnoopServlet servlet access (more info ...)web-application-activity 2002-2006 4575 11046 
2061SERVER-APACHE Apache Tomcat null byte directory listing attempt (more info ...)web-application-attack 2003-0042 6721 11438 
5715SERVER-APACHE Apache malformed ipv6 uri overflow attempt (more info ...)web-application-attack 2004-0786 11187  
11272SERVER-APACHE Apache newline exploit attempt (more info ...)web-application-attack 2003-0132 7254  
11273SERVER-APACHE Apache header parsing space saturation denial of service attempt (more info ...)attempted-dos 2004-0942   
11679SERVER-APACHE Apache mod_rewrite buffer overflow attempt (more info ...)attempted-admin 2006-3747   
12465SERVER-APACHE Apache APR memory corruption attempt (more info ...)attempted-admin 2003-0245 7723  
12591SERVER-APACHE Apache mod_cache denial of service attempt (more info ...)denial-of-service 2007-1863 24649  
12711SERVER-APACHE Apache Tomcat WebDAV system tag remote file disclosure attempt (more info ...)successful-recon-limited 2007-5461 26070  URL
13302SERVER-APACHE Apache mod_imagemap cross site scripting attempt (more info ...)web-application-attack 2007-5000 26838  
15578MALWARE-TOOLS Slowloris http DoS tool (more info ...)attempted-dos 2007-0086   
15980SERVER-APACHE Apache mod_ssl hook functions format string attempt (more info ...)attempted-user 2004-0700 10736  
16021SERVER-APACHE Apache http Server mod_tcl format string attempt (more info ...)attempted-user 2006-4154 20527  
16611SERVER-APACHE Apache 413 error HTTP request method cross-site scripting attack (more info ...)web-application-attack 2007-6203 26663  
17107SERVER-APACHE Apache Tomcat JK Web Server Connector long URL stack overflow attempt - 1 (more info ...)attempted-admin 2007-0774 22791  
17354SERVER-APACHE Apache Byte-Range Filter denial of service attempt (more info ...)attempted-dos 2005-2728 14660  
17387SERVER-APACHE Apache Tomcat allowLinking URIencoding directory traversal attempt (more info ...)suspicious-filename-detect 2008-2938 30633  
17498SERVER-APACHE Apache Tomcat UNIX platform directory traversal (more info ...)web-application-attack 2007-0450 22960  URL
17499SERVER-APACHE Apache Tomcat UNIX platform directory traversal (more info ...)web-application-attack 2007-0450 22960  URL
17500SERVER-APACHE Apache Tomcat UNIX platform directory traversal (more info ...)web-application-attack 2007-0450 22960  URL
17501SERVER-APACHE Apache Tomcat UNIX platform directory traversal (more info ...)web-application-attack 2007-0450 22960  URL
17502SERVER-APACHE Apache Tomcat UNIX platform directory traversal (more info ...)web-application-attack 2007-0450 22960  URL
17533SERVER-APACHE Apache Struts Information Disclosure Attempt (more info ...)attempted-recon 2008-6505 32104  
17656SERVER-APACHE Apache HTTP server mod_rewrite module LDAP scheme handling buffer overflow attempt (more info ...)attempted-user 2006-3747   
18096SERVER-APACHE Apache Tomcat username enumeration attempt (more info ...)attempted-recon 2009-0580 35196  
18931SERVER-APACHE Apache Struts OGNL parameter interception bypass command execution attempt (more info ...)attempted-admin 2010-1870 41592  
19709SERVER-APACHE Apache APR apr_fn match infinite loop denial of service attempt (more info ...)attempted-dos 2011-0419   URL
19825SERVER-APACHE Apache Killer denial of service tool exploit attempt (more info ...)attempted-dos 2011-3192 49303  URL
20528SERVER-APACHE Apache mod_proxy reverse proxy information disclosure attempt (more info ...)attempted-recon 2011-4317   
20612SERVER-APACHE Apache Tomcat Java AJP connector invalid header timeout DOS attempt (more info ...)attempted-dos 2009-0033 35193  
20821SERVER-APACHE Apache APR header memory corruption attempt (more info ...)attempted-admin 2003-0245 7723  
21074SERVER-APACHE Apache Struts remote code execution attempt - CookieInterceptor (more info ...)attempted-admin 2012-0392 51257  URL
21214SERVER-APACHE Apache server mod_proxy reverse proxy bypass attempt (more info ...)attempted-recon 2011-4317   
21260SERVER-APACHE Apache Byte-Range Filter denial of service attempt (more info ...)attempted-dos 2005-2728 14660  
21337SERVER-APACHE Apache XML HMAC truncation authentication bypass attempt (more info ...)attempted-user 2009-0217 35671  
21356SERVER-APACHE Apache URI directory traversal attempt (more info ...)attempted-recon 2002-0661 5434  
21515SERVER-APACHE Apache Tomcat Web Application Manager access (more info ...)attempted-recon    URL
21522SERVER-APACHE Apache Struts parameters interceptor remote code execution attempt (more info ...)attempted-user 2011-3923   URL
21923SERVER-APACHE Apache Tomcat PUT request remote file deployment attempt (more info ...)attempted-user    URL
23779SERVER-APACHE Apache WebDAV mod_dav nested entity reference DoS attempt (more info ...)attempted-dos 2009-1955 35253  
24306SERVER-APACHE HP Operations Dashboard Apache Tomcat default admin account access attempt (more info ...)attempted-admin 2009-4188 36258  URL
24348SERVER-APACHE Apache mod_rpaf X-Forwarded-For header denial of service attempt (more info ...)web-application-attack 2012-3526   
24697SERVER-APACHE Apache mod_log_config cookie handling denial of service attempt (more info ...)denial-of-service 2012-0021 51705  
24698SERVER-APACHE Apache mod_log_config cookie handling denial of service attempt (more info ...)denial-of-service 2012-0021 51705  
26431SERVER-WEBAPP Apache mod_proxy_balancer cross site scripting attempt (more info ...)web-application-attack 2012-4558 58165  
27203INDICATOR-COMPROMISE Apache auto_prepend_file a.control.bin C2 traffic (more info ...)trojan-activity    URL
29639SERVER-APACHE Apache Struts wildcard matching OGNL remote code execution attempt (more info ...)attempted-admin 2018-11776 60346  URL
29647SERVER-APACHE Apache Roller OGNL injection remote code execution attempt (more info ...)attempted-user 2013-4212 63928  
29648SERVER-APACHE Apache Roller OGNL injection remote code execution attempt (more info ...)attempted-user 2013-4212 63928  
29649SERVER-APACHE Apache Roller allowStaticMethodAccess invocation attempt (more info ...)attempted-user 2013-4212 63928  
29896SERVER-APACHE Apache Tomcat infinite loop denial of service attempt (more info ...)denial-of-service 2014-0050   
29936SERVER-APACHE Apache Struts remote code execution attempt - CookieInterceptor (more info ...)attempted-admin 2012-0392 51257  URL
30010SERVER-APACHE Apache Solr SolrResourceLoader directory traversal attempt (more info ...)attempted-admin 2013-6397 63935  URL
30194SERVER-WEBAPP Apache Camel XSLT unauthorized code execution (more info ...)attempted-user 2014-0003   URL
30944SERVER-APACHE Apache Struts CookieInterceptor classloader access attempt (more info ...)attempted-admin 2014-0113 67081  URL
31405SERVER-APACHE Apache Chunked-Encoding worm attempt (more info ...)web-application-attack 2002-0392 5033 10932 
34048SERVER-APACHE Apache mod_log_config cookie handling denial of service attempt (more info ...)denial-of-service 2012-0021 51705  
34973SERVER-OTHER Apache mod_include buffer overflow attempt (more info ...)attempted-user 2004-0940 11471  
35314SERVER-APACHE Apache HTTP Server mod_proxy denial of service attempt (more info ...)attempted-admin 2014-0117   URL
35406SERVER-APACHE Apache HTTP Server mod_status heap buffer overflow attempt (more info ...)web-application-activity 2014-0226   URL
35531SERVER-WEBAPP Apache HTTP server mod_cache denial of service attempt (more info ...)attempted-dos 2013-4352 69248  URL
35532SERVER-WEBAPP Apache HTTP server mod_cache denial of service attempt (more info ...)attempted-dos 2013-4352 69248  URL
36057SERVER-WEBAPP Apache ActiveMQ directory traversal attempt (more info ...)web-application-attack 2015-1830   
37503SERVER-OTHER Apache ActiveMQ shutdown command denial of service attempt (more info ...)denial-of-service 2014-3576 76272  
37968SERVER-WEBAPP Apache HTTP server potential cookie disclosure attempt (more info ...)web-application-attack 2012-0053 51706  
38268SERVER-APACHE 404 OK response (more info ...)misc-attack    URL
38990SERVER-WEBAPP Apache Struts I18NInterceptor locale object cross site scripting attempt (more info ...)attempted-user 2016-2162   
40302SERVER-APACHE Apache Jetspeed Portal cross-site scripting attempt (more info ...)attempted-user 2016-0712   URL
40316SERVER-APACHE Apache Tomcat default credential login attempt (more info ...)default-login-attempt    URL
40317SERVER-APACHE Apache Tomcat default credential login attempt (more info ...)default-login-attempt    URL
40318SERVER-APACHE Apache Tomcat default credential login attempt (more info ...)default-login-attempt    URL
40319SERVER-APACHE Apache Tomcat default credential login attempt (more info ...)default-login-attempt    URL
40320SERVER-APACHE Apache Tomcat default credential login attempt (more info ...)default-login-attempt    URL
40321SERVER-APACHE Apache Tomcat credential disclosure attempt (more info ...)attempted-admin    URL
41688SERVER-APACHE Apache HTTP Server mod_http2 denial of service attempt (more info ...)denial-of-service 2016-8740   
41811SERVER-OTHER Apache ActiveMQ fileserver broker service file delete attempt (more info ...)attempted-user 2016-3088   
41850SERVER-WEBAPP Apache Struts URL validator denial of service attempt (more info ...)web-application-attack 2016-4465   URL
42133SERVER-APACHE Apache mod_session_crypto padding oracle brute force attempt (more info ...)web-application-attack 2016-0736   URL
42878SERVER-WEBAPP Apache TomEE java deserialization attempt (more info ...)attempted-user 2017-3248   URL
42879SERVER-WEBAPP Apache TomEE java deserialization attempt (more info ...)attempted-user 2016-0779   URL
43247SERVER-APACHE Apache Rave information disclosure attempt (more info ...)attempted-recon 2013-1814   
43547SERVER-APACHE httpd mod_mime content-type buffer overflow attempt (more info ...)attempted-user 2017-7679   
43587SERVER-WEBAPP Apache httpd ap_find_token buffer overread attempt (more info ...)attempted-user 2017-7668 99137  
44155SERVER-APACHE Apache Qpid AMQP denial of service attempt (more info ...)denial-of-service 2015-0203   
44156SERVER-APACHE Apache Qpid AMQP denial of service attempt (more info ...)denial-of-service 2015-0203   
44703POLICY-OTHER Apache OpenOffice malicious macro exploitation attempt (more info ...)policy-violation    
44704POLICY-OTHER Apache OpenOffice malicious macro exploitation attempt (more info ...)policy-violation    
44705POLICY-OTHER Apache OpenOffice malicious macro exploitation attempt (more info ...)policy-violation    
44706POLICY-OTHER Apache OpenOffice malicious macro exploitation attempt (more info ...)policy-violation    
44808INDICATOR-COMPROMISE Apache HTTP Server possible mod_dav.c remote denial of service vulnerability attempt (more info ...)attempted-dos 2013-1896 100872  
45093SERVER-WEBAPP Apache Archiva XML server side request forgery attempt (more info ...)web-application-attack 2016-5002   
45307SERVER-APACHE Apache SSI error page cross-site scripting attempt (more info ...)web-application-attack 2002-0840 5847  
46115SERVER-APACHE FrontPage privilege escalation attempt (more info ...)attempted-admin    
46116SERVER-APACHE FrontPage privilege escalation attempt (more info ...)attempted-admin    
46304SERVER-OTHER Apache ActiveMQ JMS ObjectMessage deserialization attempt (more info ...)misc-activity 2015-5254   
46326SERVER-APACHE Apache Jetspeed PageManagementService persistent XSS attempt (more info ...)attempted-user 2016-0711   
46327SERVER-APACHE Apache Jetspeed PageManagementService persistent XSS attempt (more info ...)attempted-user 2016-0711   
46328SERVER-WEBAPP Apache Jetspeed PageManagementService persistent XSS attempt (more info ...)attempted-user 2016-0711   
46336SERVER-APACHE Apache Jetspeed User Manager service unauthorized API access attempt (more info ...)policy-violation 2016-2171   
47061SERVER-WEBAPP Apache Struts URL validator denial of service attempt (more info ...)web-application-attack 2016-4465   URL
48233SERVER-WEBAPP Apache Syncope information disclosure by orderBy (more info ...)attempted-recon 2018-1322   URL
48234SERVER-WEBAPP Apache Syncope information disclosure by fiql (more info ...)attempted-recon 2018-1322   URL
51287SERVER-WEBAPP Apache CouchDB _config command injection attempt (more info ...)web-application-attack 2018-8007   URL
51662SERVER-APACHE Apache Qpid AMQP denial of service attempt (more info ...)denial-of-service 2015-0203   
52471SERVER-APACHE Apache Tomcat chunked transfer encoding denial of service attempt (more info ...)attempted-dos 2014-0227   
55800SERVER-WEBAPP Apache Tomcat HTTP/2 denial of service attempt (more info ...)denial-of-service 2020-13934   
55801SERVER-WEBAPP Apache Tomcat HTTP/2 denial of service attempt (more info ...)denial-of-service 2020-13934   
56086SERVER-WEBAPP Apache Tomcat WebSocket length denial of service attempt (more info ...)attempted-dos 2020-13935   
56989SERVER-WEBAPP Apache OpenMeetings NetTest denial of service attempt (more info ...)attempted-dos 2020-13951   
57299SERVER-WEBAPP Apache HTTP server mod_rewrite external URL redirection attempt (more info ...)misc-attack 2020-1927   URL
57537POLICY-OTHER Cisco SD-WAN vManage user creation via Apache Kafka detected (more info ...)policy-violation 2021-1468   URL
57580SERVER-APACHE Apache HTTP Server auth_ldap format string exploit attempt (more info ...)attempted-user 2006-0150 16177  
58939SERVER-WEBAPP Apache Superset Markdown component cross site scripting attempt (more info ...)attempted-user 2021-27907   URL
58940SERVER-WEBAPP Apache Superset Markdown component cross site scripting attempt (more info ...)attempted-user 2021-27907   URL
59032SERVER-WEBAPP Apache ActiveMQ Web Console cross site scripting attempt (more info ...)attempted-user 2020-13947   
59033SERVER-WEBAPP Apache ActiveMQ Web Console cross site scripting attempt (more info ...)attempted-user 2020-13947   
59114SERVER-APACHE Apache Druid JDBC connection remote code execution attempt (more info ...)attempted-user 2021-26919   
59258POLICY-OTHER Apache ShenYu plugins API access attempt (more info ...)policy-violation 2022-23944   URL
59302SERVER-APACHE Apache httpd mod_lua integer underflow attempt (more info ...)attempted-admin 2021-44790   URL
59363SERVER-WEBAPP Apache Airflow trigger origin cross site scripting attempt (more info ...)attempted-user 2020-13944   
59364SERVER-WEBAPP Apache Airflow trigger origin cross site scripting attempt (more info ...)attempted-user 2020-13944   
59440SERVER-APACHE Apache mod_http2 NULL pointer dereference attempt (more info ...)denial-of-service 2017-7659   
59656SERVER-WEBAPP Apache Groovy Elastic Search unauthorized serialized object attempt (more info ...)attempted-user 2015-5377   URL
59667SERVER-APACHE SVN URL command injection attempt (more info ...)attempted-user 2017-9800   
59669SERVER-WEBAPP Apache Subversion denial-of-service attempt (more info ...)attempted-dos 2018-11803   URL
59742SERVER-APACHE Apache SVN mod_authz_svn MOVE denial of service attempt (more info ...)attempted-dos 2016-2168   
59743SERVER-APACHE Apache SVN mod_authz_svn COPY denial of service attempt (more info ...)attempted-dos 2016-2168   
59874POLICY-OTHER Apache Solr configset upload attempt (more info ...)policy-violation    URL
59875POLICY-OTHER Apache Solr configset upload attempt (more info ...)policy-violation    URL
60078SERVER-APACHE Apache Tomcat open redirect attempt (more info ...)misc-attack 2018-11784   URL
60685SERVER-APACHE Apache Struts multipart request handler DOS attempt (more info ...)attempted-dos 2006-1547   URL
60888SERVER-OTHER Apache CouchDB node remote command execution attempt (more info ...)attempted-admin 2022-24706   URL
61650SERVER-OTHER Apache Commons Text string interpolation remote code execution attempt (more info ...)web-application-attack 2022-42889   
61651SERVER-OTHER Apache Commons Text string interpolation remote code execution attempt (more info ...)web-application-attack 2022-42889   

 goto Top

Group: Server / HTTP / Microsoft IIS

# of attack rules in this group: 8

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3087SERVER-IIS w3who.dll buffer overflow attempt (more info ...)attempted-admin  2004-1134  11820    
13922SERVER-IIS Microsoft IIS HTMLEncode Unicode string buffer overflow attempt (more info ...)web-application-attack  2008-0075      URL
15959SERVER-IIS Microsoft ASP.NET viewstate DoS attempt (more info ...)attempted-dos  2005-1665      URL
18243SERVER-IIS Microsoft Windows 7 IIS7.5 FTPSVC buffer overflow attempt (more info ...)attempted-admin  2010-3972  45542    URL
21161SERVER-IIS Microsoft Windows IIS5 NTLM and basic authentication bypass attempt (more info ...)attempted-user  2007-2815  24105    URL
34061SERVER-IIS Microsoft IIS Range header integer overflow attempt (more info ...)attempted-dos  2015-1635  74013    URL
39905OS-WINDOWS Microsoft Windows IIS denial of service attempt (more info ...)denial-of-service  2022-35748      URL
42110SERVER-WEBAPP Microsoft IIS ScStoragePathFromUrl function buffer overflow attempt (more info ...)attempted-admin  2017-7269  97127    


# of warning rules in this group: 179

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
971SERVER-IIS ISAPI .printer access (more info ...)web-application-activity 2001-0241 2674 10661 URL
973SERVER-IIS *.idc attempt (more info ...)web-application-attack 2000-0661 1448  
974SERVER-IIS Microsoft Windows IIS directory traversal attempt (more info ...)web-application-attack 1999-0229 2218  
978SERVER-IIS ASP contents view (more info ...)web-application-attack 2000-0302 1084 10356 URL
979SERVER-IIS ASP contents view (more info ...)web-application-attack 2000-0942 1861  URL
980SERVER-IIS CGImail.exe access (more info ...)web-application-activity 2000-0726 1623 11721 
984SERVER-IIS JET VBA access (more info ...)web-application-activity 1999-0874 307 10116 
985SERVER-IIS JET VBA access (more info ...)web-application-activity 1999-0874 286  
986SERVER-IIS MSProxy access (more info ...)web-application-activity    URL
991SERVER-IIS achg.htr access (more info ...)web-application-activity 1999-0407 2110  
992SERVER-IIS adctest.asp access (more info ...)web-application-activity    
993SERVER-IIS iisadmin access (more info ...)web-application-attack 1999-1538 189 11032 
994SERVER-IIS /scripts/iisadmin/default.htm access (more info ...)web-application-attack    
995SERVER-IIS ism.dll access (more info ...)web-application-attack 2000-0630 189  
996SERVER-IIS anot.htr access (more info ...)web-application-activity 1999-0407 2110  
997SERVER-IIS asp-dot attempt (more info ...)web-application-attack  1814 10363 
998SERVER-IIS asp-srch attempt (more info ...)web-application-attack    
999SERVER-IIS bdir access (more info ...)web-application-activity  2280  
1000SERVER-IIS bdir.htr access (more info ...)web-application-activity  2280 10577 
1003SERVER-IIS cmd? access (more info ...)web-application-attack    
1004SERVER-IIS codebrowser Exair access (more info ...)web-application-activity 1999-0815   
1005SERVER-IIS codebrowser SDK access (more info ...)web-application-activity 1999-0736 167  
1007SERVER-IIS Form_JScript.asp access (more info ...)web-application-attack 2000-1104 1595 10572 URL
1008SERVER-IIS del attempt (more info ...)web-application-attack    
1011SERVER-IIS exec-src access (more info ...)web-application-activity    
1012SERVER-IIS fpcount attempt (more info ...)web-application-attack 1999-1376 2252  
1013SERVER-IIS fpcount access (more info ...)web-application-activity 1999-1376 2252  
1015SERVER-IIS getdrvs.exe access (more info ...)web-application-activity    
1017SERVER-IIS idc-srch attempt (more info ...)web-application-attack 1999-0874   
1018SERVER-IIS iisadmpwd attempt (more info ...)web-application-attack 1999-0407 2110 10371 
1019SERVER-IIS Malformed Hit-Highlighting Argument File Access Attempt (more info ...)web-application-attack 2000-0097 950  URL
1020SERVER-IIS isc$data attempt (more info ...)web-application-attack 1999-0874 307 10116 
1021SERVER-IIS ism.dll attempt (more info ...)web-application-attack 2000-0457 1193 10680 URL
1022SERVER-IIS jet vba access (more info ...)web-application-activity 1999-0874 286  URL
1023SERVER-IIS msadcs.dll access (more info ...)web-application-activity 1999-1011 529 10357 URL
1024SERVER-IIS newdsn.exe access (more info ...)web-application-activity 1999-0191 1818 10360 
1025SERVER-IIS perl access (more info ...)web-application-activity    
1026SERVER-IIS perl-browse newline attempt (more info ...)web-application-attack 2003-1365 6833  
1027SERVER-IIS perl-browse space attempt (more info ...)web-application-attack 2003-1365 6833  
1028SERVER-IIS query.asp access (more info ...)web-application-activity 1999-0449 193  
1029SERVER-IIS scripts-browse access (more info ...)web-application-attack   11032 
1030SERVER-IIS search97.vts access (more info ...)web-application-activity  162  
1031SERVER-IIS /SiteServer/Publishing/viewcode.asp access (more info ...)web-application-activity   10576 
1032SERVER-IIS showcode access (more info ...)web-application-activity 1999-0737  10576 URL
1033SERVER-IIS viewcode access (more info ...)web-application-activity 1999-0737  10576 URL
1034SERVER-IIS viewcode access (more info ...)web-application-activity 1999-0737  10576 URL
1035SERVER-IIS viewcode access (more info ...)web-application-activity 1999-0737  10576 URL
1036SERVER-IIS viewcode access (more info ...)web-application-activity 1999-0737  10576 URL
1037SERVER-IIS showcode.asp access (more info ...)web-application-activity 1999-0736 167 10007 URL
1038SERVER-IIS site server config access (more info ...)web-application-activity 1999-1520 256  
1039SERVER-IIS srch.htm access (more info ...)web-application-activity    
1040SERVER-IIS srchadm access (more info ...)web-application-activity   11032 
1041SERVER-IIS uploadn.asp access (more info ...)web-application-activity 1999-0360 1811  
1043SERVER-IIS viewcode.asp access (more info ...)web-application-activity 1999-0737  10576 
1044SERVER-IIS webhits access (more info ...)web-application-activity 2000-0097 950  
1045SERVER-IIS Unauthorized IP Access Attempt (more info ...)web-application-attack    
1046SERVER-IIS site/iisamples access (more info ...)web-application-activity   10370 
1075SERVER-IIS postinfo.asp access (more info ...)web-application-activity 1999-0360 1811  
1076SERVER-IIS repost.asp access (more info ...)web-application-activity   10372 
1244SERVER-IIS ISAPI .idq attempt (more info ...)web-application-attack 2001-0500 968 10115 
1256SERVER-IIS CodeRed v2 root.exe access (more info ...)web-application-attack    URL
1283SERVER-IIS Microsoft Office Outlook web dos (more info ...)web-application-attack  3223  
1285SERVER-IIS msdac access (more info ...)web-application-activity   11032 
1286SERVER-IIS _mem_bin access (more info ...)web-application-activity   11032 
1380SERVER-IIS Form_VBScript.asp access (more info ...)web-application-attack 2000-1104 1595 10572 URL
1400SERVER-IIS /scripts/samples/ access (more info ...)web-application-attack   10370 
1401SERVER-IIS /msadc/samples/ access (more info ...)web-application-attack 1999-0736 167 1007 
1485SERVER-IIS mkilog.exe access (more info ...)web-application-activity   10359 
1486SERVER-IIS ctss.idc access (more info ...)web-application-activity   10359 
1487SERVER-IIS /iisadmpwd/aexp2.htr access (more info ...)web-application-activity 2002-0421 4236 10371 
1567SERVER-IIS /exchange/root.asp attempt (more info ...)web-application-attack 2001-0660 3301 10781 URL
1568SERVER-IIS /exchange/root.asp access (more info ...)web-application-activity 2001-0660 3301 10781 
1595SERVER-IIS htimage.exe access (more info ...)web-application-activity 2000-0256 964 10376 
1618SERVER-IIS .asp chunked Transfer-Encoding (more info ...)web-application-attack 2002-0079 4485 10932 
1626SERVER-IIS /StoreCSVS/InstantOrder.asmx request (more info ...)web-application-activity    
1661SERVER-IIS cmd32.exe access (more info ...)web-application-attack    
1726SERVER-IIS doctodep.btr access (more info ...)web-application-activity    
1753SERVER-IIS as_web.exe access (more info ...)web-application-activity 2002-1728 4670  
1754SERVER-IIS as_web4.exe access (more info ...)web-application-activity 2002-1728 4670  
1756SERVER-IIS NewsPro administration authentication attempt (more info ...)web-application-activity 2002-1734 4672  
1772SERVER-IIS pbserver access (more info ...)web-application-activity 2000-1089   URL
1802SERVER-IIS .asa HTTP header buffer overflow attempt (more info ...)web-application-attack 2002-0150 4476 10936 URL
1803SERVER-IIS .cer HTTP header buffer overflow attempt (more info ...)web-application-attack 2002-0150 4476 10936 URL
1804SERVER-IIS .cdx HTTP header buffer overflow attempt (more info ...)web-application-attack 2002-0150 4476 10936 URL
1806SERVER-IIS .htr chunked Transfer-Encoding (more info ...)web-application-attack 2002-0364 5003 11028 
1817SERVER-IIS MS Site Server default login attempt (more info ...)web-application-attack   11018 URL
1818SERVER-IIS MS Site Server admin attempt (more info ...)web-application-attack   11018 
1970SERVER-IIS MDAC Content-Type overflow attempt (more info ...)web-application-attack 2002-1142 6214 11161 URL
2090SERVER-IIS WEBDAV exploit attempt (more info ...)attempted-admin 2003-0109 7716 11413 URL
2091SERVER-IIS WEBDAV nessus safe scan attempt (more info ...)attempted-admin 2003-0109 7116 11413 URL
2117SERVER-IIS Battleaxe Forum login.asp access (more info ...)web-application-activity 2003-0215 7416 11548 
2130SERVER-IIS IISProtect siteadmin.asp access (more info ...)web-application-activity 2003-0377 7675 11662 
2131SERVER-IIS IISProtect access (more info ...)web-application-activity   11661 
2132SERVER-IIS Synchrologic Email Accelerator userid list access attempt (more info ...)web-application-activity   11657 
2133SERVER-IIS MS BizTalk server access (more info ...)web-application-activity 2003-0118 7470 11638 URL
2157SERVER-IIS IISProtect globaladmin.asp access (more info ...)web-application-activity   11661 
2247SERVER-IIS UploadScript11.asp access (more info ...)web-application-activity 2001-0938 3608 11746 
2248SERVER-IIS DirectoryListing.asp access (more info ...)web-application-activity 2001-0938   
2249SERVER-IIS /pcadmin/login.asp access (more info ...)web-application-activity  8103 11785 
2321SERVER-IIS foxweb.exe access (more info ...)web-application-activity   11939 
2322SERVER-IIS foxweb.dll access (more info ...)web-application-activity   11939 
2324SERVER-IIS VP-ASP shopsearch.asp access (more info ...)web-application-activity  9134 11942 
2325SERVER-IIS VP-ASP ShopDisplayProducts.asp access (more info ...)web-application-activity  9134 11942 
2326SERVER-IIS sgdynamo.exe access (more info ...)web-application-activity 2002-0375 4720 11955 
2386SERVER-IIS NTLM ASN1 vulnerability scan attempt (more info ...)attempted-dos 2003-0818 9635 12065 URL
2571SERVER-IIS SmarterTools SmarterMail frmGetAttachment.aspx access (more info ...)web-application-activity 2004-2585 9805  
2572SERVER-IIS SmarterTools SmarterMail login.aspx buffer overflow attempt (more info ...)web-application-attack 2004-2585 9805  
2573SERVER-IIS SmarterTools SmarterMail frmCompose.asp access (more info ...)web-application-activity 2004-2585 9805  
2667SERVER-IIS ping.asp access (more info ...)web-application-activity   10968 
3150SERVER-IIS SQLXML content type overflow (more info ...)attempted-admin 2002-0186 5004 11304 URL
3193SERVER-IIS .cmd executable file parsing attack (more info ...)web-application-attack 2000-0886 1912  
3194SERVER-IIS .bat executable file parsing attack (more info ...)web-application-attack 2000-0886 1912  
3201SERVER-IIS httpodbc.dll access - nimda (more info ...)web-application-activity 2001-0333 2708  
7027SERVER-IIS Microsoft Office FrontPage server extensions 2002 cross site scripting attempt (more info ...)attempted-user 2006-0015 17452  URL
7028SERVER-IIS Microsoft Office FrontPage server extensions 2002 cross site scripting attempt (more info ...)attempted-user 2006-0015 17452  URL
7029SERVER-IIS Microsoft Office FrontPage server extensions 2002 cross site scripting attempt (more info ...)attempted-user 2006-0015 17452  URL
8349SERVER-IIS Indexing Service ciRestriction cross-site scripting attempt (more info ...)misc-attack 2006-0032 19927  URL
8700SERVER-IIS ASP.NET 2.0 cross-site scripting attempt (more info ...)attempted-user 2006-3436 20337  URL
11191SERVER-IIS Microsoft Content Management Server memory corruption (more info ...)attempted-user 2007-0938 22861  URL
12043SERVER-IIS Microsoft XML parser IIS WebDAV attack attempt (more info ...)denial-of-service 2003-0718 11384  
12064SERVER-IIS w3svc _vti_bin null pointer dereference attempt (more info ...)attempted-dos 2005-4360 15921  URL
12595SERVER-IIS malicious ASP file upload attempt (more info ...)attempted-user 2006-0026 18858  URL
15470FILE-EXECUTABLE IIS ASP/ASP.NET potentially malicious file upload attempt (more info ...)attempted-user 2009-0080   URL
15851SERVER-IIS Microsoft ASP.NET bad request denial of service attempt (more info ...)attempted-dos 2009-1536   URL
15974SERVER-IIS Microsoft IIS ASP handling buffer overflow attempt (more info ...)web-application-attack 2008-0075 27676  URL
16147SERVER-IIS Microsoft Windows IIS malformed URL .dll denial of service attempt (more info ...)attempted-dos 2005-4360 15921  URL
16312SERVER-IIS ADFS custom header arbitrary code execution attempt (more info ...)attempted-admin 2009-2509   URL
16356SERVER-IIS multiple extension code execution attempt (more info ...)web-application-attack 2009-4444   
17103SERVER-IIS IIS 5.1 alternate data stream authentication bypass attempt (more info ...)web-application-attack 2011-4963   URL
17254SERVER-IIS Microsoft Windows IIS stack exhaustion DoS attempt (more info ...)attempted-dos 2010-1899   URL
17431SERVER-IIS Microsoft Windows IIS SChannel improper certificate verification (more info ...)misc-activity 2009-0085   URL
17440SERVER-IIS RSA Authentication Agent chunked HTTP request buffer overflow attempt (more info ...)web-application-attack 2005-4734 26424  URL
17525SERVER-IIS Microsoft Windows IIS 5.0 WebDav Request Directory Security Bypass (more info ...)attempted-admin 2009-1122 35232  
17564SERVER-IIS WebDAV Request Directory Security Bypass attempt (more info ...)attempted-admin 2009-1535 34993  
17648SERVER-IIS source code disclosure attempt (more info ...)attempted-recon  14764  
17652SERVER-IIS Microsoft Windows IIS source code disclosure attempt (more info ...)misc-attack 2005-2678   URL
17653SERVER-IIS Microsoft Windows IIS source code disclosure attempt (more info ...)misc-attack 2005-2678   URL
17705SERVER-IIS RSA Authentication Agent chunked HTTP request buffer overflow attempt (more info ...)web-application-attack 2005-1471 13524  URL
17724OS-WINDOWS Microsoft IIS malicious ASP file upload attempt (more info ...)attempted-user 2006-0026 18858  URL
19183SERVER-IIS Microsoft Windows IIS FastCGI request header buffer overflow attempt (more info ...)attempted-admin 2010-2730 43138  URL
19192SERVER-IIS Microsoft Windows IIS stack exhaustion DoS attempt (more info ...)attempted-dos 2010-1899 43140  URL
20664SERVER-IIS Microsoft Windows IIS UNC mapped virtual host file source code access attempt (more info ...)attempted-recon 2000-0246 1081  URL
20665SERVER-IIS Microsoft Windows IIS UNC mapped virtual host file source code access attempt (more info ...)attempted-recon 2000-0246 1081  URL
20675SERVER-IIS Microsoft Active Directory Federation Services code execution attempt (more info ...)web-application-attack 2009-2509   URL
20828SERVER-IIS Microsoft Windows IIS aspx login ReturnURL arbitrary redirect attempt (more info ...)web-application-attack 2011-3415   URL
20829SERVER-IIS Microsoft Windows IIS .NET null character username truncation attempt (more info ...)suspicious-login 2011-3416   URL
21599SERVER-IIS Microsoft Windows IIS 6 multiple executable extension access attempt (more info ...)web-application-attack 2009-4444 37460  URL
21600SERVER-IIS Microsoft Windows IIS 6 multiple executable extension access attempt (more info ...)web-application-attack 2009-4444 37460  URL
21601SERVER-IIS Microsoft Windows IIS 6 multiple executable extension access attempt (more info ...)web-application-attack 2009-4444 37460  URL
21602SERVER-IIS Microsoft Windows IIS 6 multiple executable extension access attempt (more info ...)web-application-attack 2009-4444 37460  URL
21603SERVER-IIS Microsoft Windows IIS 6 multiple executable extension access attempt (more info ...)web-application-attack 2009-4444 37460  URL
21604SERVER-IIS Microsoft Windows IIS 6 multiple executable extension access attempt (more info ...)web-application-attack 2009-4444 37460  URL
21605SERVER-IIS Microsoft Windows IIS 6 multiple executable extension access attempt (more info ...)web-application-attack 2009-4444 37460  URL
21606SERVER-IIS Microsoft Windows IIS 6 multiple executable extension access attempt (more info ...)web-application-attack 2009-4444 37460  URL
23360SERVER-IIS tilde character file name discovery attempt (more info ...)attempted-recon    URL
23361SERVER-IIS tilde character file name discovery attempt (more info ...)attempted-recon    URL
23362SERVER-IIS tilde character file name discovery attempt (more info ...)attempted-recon    URL
23626SERVER-IIS cmd.exe access (more info ...)web-application-attack    
24274SERVER-IIS Microsoft Windows IIS stack exhaustion DoS attempt (more info ...)attempted-dos 2010-1899 43140  URL
24275SERVER-IIS Microsoft Windows IIS stack exhaustion DoS attempt (more info ...)attempted-dos 2010-1899 43140  URL
24276SERVER-IIS Microsoft Windows IIS stack exhaustion DoS attempt (more info ...)attempted-dos 2010-1899 43140  URL
24379SERVER-IIS Microsoft Windows IIS FastCGI request header buffer overflow attempt (more info ...)attempted-admin 2010-2730 43138  URL
24380SERVER-IIS Microsoft Windows IIS FastCGI request header buffer overflow attempt (more info ...)attempted-admin 2010-2730 43138  URL
24866SERVER-IIS Microsoft Windows IIS UNC mapped virtual host file source code access attempt (more info ...)attempted-recon 2000-0246 1081  URL
24867SERVER-IIS Microsoft Windows IIS UNC mapped virtual host file source code access attempt (more info ...)attempted-recon 2000-0246 1081  URL
25250SERVER-IIS Microsoft Windows IIS .NET null character username truncation attempt (more info ...)suspicious-login 2011-3416   URL
25251SERVER-IIS Microsoft Windows IIS .NET null character username truncation attempt (more info ...)suspicious-login 2011-3416   URL
25274SERVER-IIS Microsoft Windows Server 2012 IIS OData protocol nested replace filter dos attempt (more info ...)attempted-dos 2013-0005   URL
29715SERVER-IIS Microsoft Windows ASP .NET denial of service attempt (more info ...)denial-of-service 2014-0253   URL
29866SERVER-IIS Microsoft Windows Server 2012 IIS OData protocol nested replace filter dos attempt (more info ...)attempted-dos 2013-0005   URL
31443SERVER-WEBAPP ActiveState ActivePerl perlIIS.dll server URI buffer overflow attempt (more info ...)attempted-admin 2001-0815 3526  URL
34088SERVER-IIS Web.config information disclosure attempt (more info ...)web-application-attack 2015-1648   URL
34769SERVER-IIS Microsoft Active Directory Federation Services wct parameter cross site scripting attempt (more info ...)attempted-user 2015-1757   URL
43054OS-WINDOWS Microsoft Windows IIS buffer overflow attempt (more info ...)attempted-user    URL
43807SERVER-IIS Microsoft ASP.NET bad request denial of service attempt (more info ...)denial-of-service 2009-1536   URL
43808SERVER-IIS Microsoft ASP.NET bad request denial of service attempt (more info ...)denial-of-service 2009-1536   URL
51780SERVER-IIS Microsoft IIS IDC ISAPI cross-site scripting attempt (more info ...)web-application-attack    URL
56804SERVER-IIS Microsoft ASP.NET bad request denial of service attempt (more info ...)denial-of-service 2009-1536   URL
59729SERVER-IIS Microsoft Windows HTTP.sys denial of service attempt (more info ...)attempted-dos 2016-0150   URL

 goto Top

Group: Server / HTTP / Other

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / HTTP / Coldfusion

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / HTTP / Frontpage

# of attack rules in this group: 0

# of warning rules in this group: 3

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
6409SERVER-OTHER Microsoft Frontpage server extension long host string overflow attempt (more info ...)attempted-admin 2003-0824 9008  URL
6410SERVER-OTHER Microsoft Frontpage server extension long host string overflow attempt (more info ...)attempted-admin 2003-0824 9008  URL
6411SERVER-OTHER Microsoft Frontpage server extension long host string overflow attempt (more info ...)attempted-admin 2003-0824 9008  URL

 goto Top

Group: Server / HTTP / PHP

# of attack rules in this group: 479

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
15257SERVER-ORACLE Secure Backup common.php variable based command injection attempt (more info ...)attempted-admin  2008-4006      
15258SERVER-ORACLE Secure Backup login.php variable based command injection attempt (more info ...)attempted-admin  2008-5449      
17638SERVER-ORACLE Secure Backup administration server login.php cookies command injection attempt (more info ...)attempted-admin  2008-4006  33177    
18293SERVER-WEBAPP Secure Backup login.php uname variable based command injection attempt (more info ...)attempted-admin  2008-5449      
20558EXPLOIT-KIT URI request for known malicious URI /stat2.php (more info ...)trojan-activity        URL
21041EXPLOIT-KIT Blackhole exploit kit URL - main.php?page= (more info ...)attempted-user  2012-4681      URL
21042EXPLOIT-KIT Blackhole exploit kit post-compromise download attempt - .php?f= (more info ...)attempted-user  2012-4681      URL
21043EXPLOIT-KIT Blackhole exploit kit post-compromise download attempt - .php?e= (more info ...)attempted-user  2012-4681      URL
21347EXPLOIT-KIT Blackhole exploit kit URL - .php?page= (more info ...)attempted-user  2012-4681      URL
21348EXPLOIT-KIT Blackhole exploit kit URL - search.php?page= (more info ...)attempted-user  2012-4681      URL
21550MALWARE-BACKDOOR ToolsPack PHP Backdoor access (more info ...)web-application-attack        URL
21659EXPLOIT-KIT Blackhole exploit kit landing page Requested - /Home/index.php (more info ...)trojan-activity  2012-4681      URL
21660EXPLOIT-KIT Blackhole exploit kit landing page Requested - /Index/index.php (more info ...)trojan-activity  2012-4681      URL
23111POLICY-OTHER PHP uri tag injection attempt (more info ...)web-application-attack  2019-11043      
23783SERVER-WEBAPP Symantec Web Gateway pbcontrol.php filename parameter command injection attempt (more info ...)attempted-admin  2012-2953  54426    
24017MALWARE-OTHER Possible malicious redirect - rebots.php (more info ...)misc-activity        URL
24256MALWARE-BACKDOOR phpMyAdmin server_sync.php backdoor access attempt (more info ...)trojan-activity  2012-5159  55672    URL
24518SERVER-WEBAPP Symantec Web Gateway PHP remote code injection attempt (more info ...)attempted-admin  2012-0299  53443    URL
24519SERVER-WEBAPP Symantec Web Gateway PHP remote code execution attempt (more info ...)attempted-admin  2012-0299  53443    URL
25096MALWARE-OTHER PHP.Exploit.C99 suspicious file download (more info ...)trojan-activity        URL
25097MALWARE-OTHER PHP.Exploit.C99 suspicious file download (more info ...)trojan-activity        URL
26339EXPLOIT-KIT Blackhole exploit kit landing page retrieval - ff.php (more info ...)trojan-activity  2012-4681      URL
26834EXPLOIT-KIT Sweet Orange exploit kit landing page in.php base64 uri (more info ...)trojan-activity  2013-2423      
28251SERVER-WEBAPP Zabbix httpmon.php SQL injection attempt (more info ...)web-application-attack  2013-5743  62794    URL
28288SERVER-WEBAPP WebTester install2.php arbitrary command execution attempt (more info ...)attempted-admin        URL
28796EXPLOIT-KIT iFRAMEr successful cnt.php redirection (more info ...)trojan-activity        URL
29157SERVER-WEBAPP NagiosQL hostdependencies.php cross site scripting attempt (more info ...)web-application-attack        URL
29158SERVER-WEBAPP NagiosQL hostdependencies.php cross site scripting attempt (more info ...)web-application-attack        URL
29815SERVER-WEBAPP Kloxo webcommand.php SQL injection attempt (more info ...)attempted-admin        URL
29949SERVER-WEBAPP WebCalendar index.php form_single_user_login parameter command injection (more info ...)web-application-attack  2012-1495  53207    
30042SERVER-WEBAPP WebCalendar index.php form_readonly login parameter command injection (more info ...)web-application-attack  2012-1495  53207    
30100FILE-OTHER ftpchk3.php malicious script upload attempt (more info ...)trojan-activity        URL
30101FILE-OTHER ftpchk3.php malicious script upload attempt (more info ...)trojan-activity        URL
30249SERVER-WEBAPP Embedded php in Exif data upload attempt (more info ...)attempted-admin        URL
31356SERVER-WEBAPP Wordpress timthumb.php webshot source attack attempt (more info ...)web-application-attack        URL
31499INDICATOR-COMPROMISE Liz0ziM php shell download attempt (more info ...)attempted-user        URL
31500INDICATOR-COMPROMISE Liz0ziM php shell upload attempt (more info ...)attempted-user        URL
31501INDICATOR-COMPROMISE Liz0ziM php shell command and control attempt (more info ...)attempted-user        URL
31502INDICATOR-COMPROMISE Liz0ziM php shell command and control attempt (more info ...)attempted-user        URL
31503INDICATOR-COMPROMISE Liz0ziM php shell download attempt (more info ...)attempted-user        URL
31892SERVER-WEBAPP HybridAuth install.php code injection attempt (more info ...)web-application-attack    69043    
32128SERVER-WEBAPP PineApp Mail-SeCure confpremenu.php command injection attempt (more info ...)attempted-admin    61476    
32203SERVER-WEBAPP PineApp Mail-SeCure ldapsyncnow.php command injection attempt (more info ...)attempted-admin    61474    URL
32247MALWARE-BACKDOOR PHP IRCBot command execution attempt (more info ...)trojan-activity        URL
32248MALWARE-BACKDOOR PHP IRCBot file edit attempt (more info ...)trojan-activity        URL
32249MALWARE-BACKDOOR PHP IRCBot port bind attempt (more info ...)trojan-activity        URL
32269SERVER-WEBAPP PineApp Mail-SeCure confpremenu.php install license command injection attempt (more info ...)attempted-admin    61475    
32352SERVER-WEBAPP Centreon displayServiceStatus.php command injection attempt (more info ...)attempted-admin  2014-3829  70649    
32611SERVER-WEBAPP phpMemcachedAdmin path traversal attempt (more info ...)web-application-attack  2014-8731      URL
32742SERVER-WEBAPP Arris VAP2500 tools_command.php command execution attempt (more info ...)attempted-admin  2014-8423  71299    
32887SERVER-WEBAPP ActualScripts ActualAnalyzer aa.php command injection attempt (more info ...)attempted-admin        
33276SERVER-WEBAPP AlienVault OSSIM a_deployment.php command injection attempt (more info ...)attempted-admin        URL
33277SERVER-WEBAPP AlienVault OSSIM a_deployment.php command injection attempt (more info ...)attempted-admin        URL
33278SERVER-WEBAPP AlienVault OSSIM a_deployment.php command injection attempt (more info ...)attempted-admin        URL
33832SERVER-WEBAPP Seagate BlackArmor NAS getAlias.php command injection attempt (more info ...)web-application-attack  2013-6924  64655    
34000SERVER-WEBAPP Berta Content Management System PHP code execution attempt (more info ...)attempted-admin  2015-2780      
34569SERVER-WEBAPP Wordpress Creative Contact Form arbitrary PHP file upload attempt (more info ...)attempted-admin  2014-8739  70723    
35014SERVER-WEBAPP Centreon GetXMLTrapsForVendor.php SQL injection attempt (more info ...)web-application-attack  2014-3828  70648    
35015SERVER-WEBAPP Centreon GetXmlTree.php SQL injection attempt (more info ...)web-application-attack  2015-1560  75602    
35016SERVER-WEBAPP Centreon cmdGetExample.php SQL injection attempt (more info ...)web-application-attack  2014-3828  70648    
35017SERVER-WEBAPP Centreon makeXML_ListMetrics.php SQL injection attempt (more info ...)web-application-attack  2014-3828  70648    
35678SERVER-WEBAPP Dell KACE Appliance downloadpxy.php directory traversal attempt (more info ...)web-application-attack        
35679SERVER-WEBAPP Dell KACE Appliance downloadpxy.php directory traversal attempt (more info ...)web-application-attack        
35680SERVER-WEBAPP Dell KACE Appliance downloadpxy.php directory traversal attempt (more info ...)web-application-attack        
35681SERVER-WEBAPP Dell KACE Appliance kbot_upload.php authentication bypass attempt (more info ...)web-application-attack        
35682SERVER-WEBAPP Dell KACE Appliance kbot_upload.php directory traversal attempt (more info ...)web-application-attack        
35683SERVER-WEBAPP Dell KACE Appliance kbot_upload.php directory traversal attempt (more info ...)web-application-attack        
35684SERVER-WEBAPP Dell KACE Appliance kbot_upload.php directory traversal attempt (more info ...)web-application-attack        
36022SERVER-WEBAPP FireEye ModuleDispatch.php name parameter directory traversal directory traversal attempt (more info ...)web-application-attack        URL
36023SERVER-WEBAPP FireEye ModuleDispatch.php name parameter directory traversal directory traversal attempt (more info ...)web-application-attack        URL
36024SERVER-WEBAPP FireEye ModuleDispatch.php name parameter directory traversal directory traversal attempt (more info ...)web-application-attack        URL
36104SERVER-WEBAPP Silver Peak VXOA configdb_file.php arbitrary PHP file upload attempt (more info ...)attempted-admin        URL
36270SERVER-WEBAPP Centreon main.php command injection attempt (more info ...)web-application-attack        URL
36763SERVER-WEBAPP vBulletin decodeArguments PHP object injection attempt (more info ...)attempted-admin  2015-7808      
37321SERVER-WEBAPP Cacti graphs_new.php SQL injection attempt (more info ...)web-application-attack  2015-8604      URL
37412SERVER-WEBAPP SevOne NMS kill.php command injection attempt (more info ...)attempted-admin        URL
37413SERVER-WEBAPP SevOne NMS kill.php command injection attempt (more info ...)attempted-admin        URL
38140SERVER-WEBAPP ATutor connections.php SQL injection attempt (more info ...)web-application-attack  2016-2555      
38229SERVER-WEBAPP Wordpress Simple Ads Manager sam-ajax-admin.php directory traversal attempt (more info ...)web-application-attack  2015-2825  73924    
38347FILE-EXECUTABLE PHP libmagic PE out of bounds memory access attempt (more info ...)attempted-admin  2014-2270  66002    URL
39177SERVER-WEBAPP Nagios XI graphApi.php command injection attempt (more info ...)web-application-attack        URL
39178SERVER-WEBAPP Nagios XI graphApi.php command injection attempt (more info ...)web-application-attack        URL
39179SERVER-WEBAPP Nagios XI nagiosim.php command injection attempt (more info ...)web-application-attack        URL
39180SERVER-WEBAPP Nagios XI nagiosim.php command injection attempt (more info ...)web-application-attack        URL
39181SERVER-WEBAPP Nagios XI ajaxproxy.php server side request forgery attempt (more info ...)web-application-attack        URL
39328SERVER-WEBAPP TikiWiki tiki-calendar.php template command injection attempt (more info ...)web-application-attack        URL
39329SERVER-WEBAPP TikiWiki tiki-calendar.php template command injection attempt (more info ...)web-application-attack        URL
39330SERVER-WEBAPP TikiWiki tiki-calendar.php template command injection attempt (more info ...)web-application-attack        URL
39359SERVER-WEBAPP WordPress Ninja Forms nf_async_upload arbitrary PHP file upload attempt (more info ...)attempted-admin  2016-1209      
39399SERVER-WEBAPP Symantec open redirect in external URL .php script attempt (more info ...)web-application-attack  2016-5304      URL
39562SERVER-WEBAPP Invision Power Board index.php content_class PHP code injection attempt (more info ...)web-application-attack  2016-6174      URL
39849SERVER-WEBAPP Trend Micro Smart Protection Server ccca_ajaxhandler.php command injection attempt (more info ...)web-application-attack  2016-6266      
39850SERVER-WEBAPP Trend Micro Smart Protection Server ccca_ajaxhandler.php command injection attempt (more info ...)web-application-attack  2016-6266      
39912SERVER-WEBAPP Trend Micro Smart Protection Server admin_notification.php command injection attempt (more info ...)web-application-attack  2016-6267      
39913SERVER-WEBAPP Trend Micro Smart Protection Server admin_notification.php command injection attempt (more info ...)web-application-attack  2016-6267      
39942SERVER-WEBAPP FreePBX Recordings Module ajax.php command injection attempt (more info ...)web-application-attack        URL
39943SERVER-WEBAPP FreePBX Recordings Module ajax.php command injection attempt (more info ...)web-application-attack        URL
39944SERVER-WEBAPP FreePBX Recordings Module ajax.php command injection attempt (more info ...)web-application-attack        URL
39945SERVER-WEBAPP FreePBX Recordings Module ajax.php command injection attempt (more info ...)web-application-attack        URL
40030SERVER-WEBAPP FreePBX Module Administration config.php remotemod command injection attempt (more info ...)web-application-attack        URL
40031SERVER-WEBAPP FreePBX Module Administration config.php remotemod command injection attempt (more info ...)web-application-attack        URL
40032SERVER-WEBAPP FreePBX Module Administration config.php remotemod command injection attempt (more info ...)web-application-attack        URL
40033SERVER-WEBAPP FreePBX Module Administration config.php remotemod command injection attempt (more info ...)web-application-attack        URL
40039SERVER-WEBAPP FreePBX config.php unauthenticated SQL injection attempt (more info ...)web-application-attack        URL
40040SERVER-WEBAPP FreePBX config.php unauthenticated SQL injection attempt (more info ...)web-application-attack        URL
40068SERVER-WEBAPP Zabbix Network Monitoring System jsrpc.php SQL injection attempt (more info ...)web-application-attack        URL
40069SERVER-WEBAPP Zabbix Network Monitoring System jsrpc.php SQL injection attempt (more info ...)web-application-attack        URL
40070SERVER-WEBAPP Zabbix Network Monitoring System latest.php SQL injection attempt (more info ...)web-application-attack        URL
40071SERVER-WEBAPP Zabbix Network Monitoring System latest.php SQL injection attempt (more info ...)web-application-attack        URL
40184EXPLOIT-KIT Phoenix Exploit Kit inbound geoip.php bdr exploit attempt (more info ...)web-application-activity        URL
40255SERVER-WEBAPP FreePBX Music Module ajax.php command injection attempt (more info ...)web-application-attack        URL
40276SERVER-WEBAPP SugarCRM SugarRestSerialize.php PHP object injection attempt (more info ...)web-application-attack        URL
40277SERVER-WEBAPP SugarCRM SugarRestSerialize.php PHP object injection attempt (more info ...)web-application-attack        URL
40283SERVER-WEBAPP Kaltura redirectWidgetCmd PHP object injection attempt (more info ...)attempted-admin        URL
40341SERVER-WEBAPP FreePBX Hotelwakeup Module ajax.php PHP code injection attempt (more info ...)web-application-attack        URL
40342SERVER-WEBAPP FreePBX Hotelwakeup Module ajax.php directory traversal attempt (more info ...)web-application-attack        URL
40494SERVER-WEBAPP Wordpress Symposium arbitrary PHP file upload attempt (more info ...)attempted-admin  2014-10021  71686    URL
40589SERVER-WEBAPP DaloRADIUS config-maint-disconnect-user.php command injection attempt (more info ...)web-application-attack        URL
40590SERVER-WEBAPP DaloRADIUS config-maint-disconnect-user.php command injection attempt (more info ...)web-application-attack        URL
40591SERVER-WEBAPP DaloRADIUS config-maint-disconnect-user.php command injection attempt (more info ...)web-application-attack        URL
40592SERVER-WEBAPP DaloRADIUS notificationsBatchDetails.php SQL injection attempt (more info ...)web-application-attack        URL
40754SERVER-WEBAPP Alienvault OSSIM gauge.php value SQL injection attempt (more info ...)web-application-attack  2016-8582  93866    URL
40817SERVER-WEBAPP Symantec Web Gateway new_whitelist.php command injection attempt (more info ...)web-application-attack  2016-5313  93284    URL
40881SERVER-WEBAPP Wordpress Symposium get_album_item.php SQL injection attempt (more info ...)web-application-attack  2015-6522  76499    
40882SERVER-WEBAPP Wordpress Symposium get_album_item.php SQL injection attempt (more info ...)web-application-attack  2015-6522  76499    
40933SERVER-WEBAPP Reference Design Kit ajax_network_diagnostic_tools.php command injection attempt (more info ...)web-application-attack        URL
41106SERVER-WEBAPP PHPMailer command injection remote code execution attempt (more info ...)attempted-admin  2016-10074      URL
41420SERVER-WEBAPP WordPress wp-config.php access via directory traversal attempt (more info ...)web-application-attack    69497    
41421SERVER-WEBAPP WordPress wp-config.php access via directory traversal attempt (more info ...)web-application-attack    69497    
41536SERVER-WEBAPP ZoneMinder file.php directory traversal attempt (more info ...)web-application-attack  2017-5595      URL
41813SERVER-WEBAPP PHPMailer command injection remote code execution attempt (more info ...)attempted-admin  2016-10074      URL
41841SERVER-WEBAPP phpFileManager cmd parameter command injection attempt (more info ...)web-application-attack  2015-5958      URL
41842SERVER-WEBAPP phpFileManager cmd parameter command injection attempt (more info ...)web-application-attack  2015-5958      URL
41843SERVER-WEBAPP phpFileManager cmd parameter command injection attempt (more info ...)web-application-attack  2015-5958      URL
41844SERVER-WEBAPP phpFileManager cmd parameter command injection attempt (more info ...)web-application-attack  2015-5958      URL
42105SERVER-WEBAPP EyesOfNetwork ged_actions.php command injection attempt (more info ...)web-application-attack  2017-6087      URL
42106SERVER-WEBAPP EyesOfNetwork ged_actions.php command injection attempt (more info ...)web-application-attack  2017-6087      URL
42119SERVER-WEBAPP pfSense openvpn_wizard PHP code injection attempt (more info ...)web-application-attack        URL
42250SERVER-WEBAPP ProcessMaker Enterprise translationsAjax.php SQL injection attempt (more info ...)web-application-attack  2016-9048      URL
42252SERVER-WEBAPP ProcessMaker Enterprise PHP object injection attempt (more info ...)web-application-attack  2016-9045      URL
42426SERVER-WEBAPP Phpcms attachment upload SQL injection attempt (more info ...)web-application-attack        
42427SERVER-WEBAPP Phpcms attachment upload SQL injection attempt (more info ...)web-application-attack        
42428SERVER-WEBAPP Phpcms attachment upload SQL injection attempt (more info ...)web-application-attack        
42429SERVER-WEBAPP Phpcms user registration remote file include attempt (more info ...)web-application-attack        
42430SERVER-WEBAPP Phpcms user registration remote file include attempt (more info ...)web-application-attack        
42455SERVER-WEBAPP Unitrends Enterprise Backup Appliance password.php command injection attempt (more info ...)web-application-attack  2017-7280      URL
42456SERVER-WEBAPP Unitrends Enterprise Backup Appliance password.php command injection attempt (more info ...)web-application-attack  2017-7280      URL
42457SERVER-WEBAPP Unitrends Enterprise Backup Appliance password.php command injection attempt (more info ...)web-application-attack  2017-7280      URL
42461SERVER-WEBAPP Unitrends Enterprise Backup Appliance reports.php PHP file injection attempt (more info ...)web-application-attack  2017-7281      URL
42462SERVER-WEBAPP Unitrends Enterprise Backup Appliance reports.php directory traversal attempt (more info ...)web-application-attack  2017-7281      URL
42839SERVER-WEBAPP Crypttech CryptoLog login.php SQL injection attempt (more info ...)web-application-attack        URL
42840SERVER-WEBAPP Crypttech CryptoLog logshares_ajax.php command injection attempt (more info ...)web-application-attack        URL
43147SERVER-WEBAPP IBM OpenAdmin Tool SOAP welcomeService.php PHP code injection attempt (more info ...)web-application-attack  2017-1092  98615    URL
43451SERVER-WEBAPP TerraMaster NAS arbitrary PHP file upload attempt (more info ...)attempted-admin        URL
43534SERVER-WEBAPP AlienVault OSSIM nfsen.php command injection attempt (more info ...)web-application-attack  2017-6971      URL
43535SERVER-WEBAPP AlienVault OSSIM nfsen.php command injection attempt (more info ...)web-application-attack  2017-6971      URL
43536SERVER-WEBAPP AlienVault OSSIM nfsen.php command injection attempt (more info ...)web-application-attack  2017-6971      URL
43934SERVER-WEBAPP Synology Photo Station PixlrEditorHandler.php arbitrary PHP file upload attempt (more info ...)attempted-admin  2017-11154      URL
43935SERVER-WEBAPP Synology Photo Station PixlrEditorHandler.php directory traversal attempt (more info ...)web-application-attack  2017-11152      URL
43936SERVER-WEBAPP Synology Photo Station file_upload.php directory traversal attempt (more info ...)web-application-attack        URL
43937SERVER-WEBAPP Synology Photo Station file_upload.php directory traversal attempt (more info ...)web-application-attack        URL
43938SERVER-WEBAPP Synology Photo Station file_upload.php directory traversal attempt (more info ...)web-application-attack        URL
43939SERVER-WEBAPP Synology Photo Station synotheme_upload.php session forgery attempt (more info ...)attempted-admin  2017-11151      URL
44079SERVER-WEBAPP Schneider Electric Umotion Builder localize.php SQL injection attempt (more info ...)web-application-attack  2017-7973  99344    URL
44080SERVER-WEBAPP Schneider Electric Umotion Builder localize.php SQL injection attempt (more info ...)web-application-attack  2017-7973  99344    URL
44175SERVER-WEBAPP Schneider Electric Umotion Builder runscript.php arbitrary file include attempt (more info ...)web-application-attack  2017-7974  99344    URL
44176SERVER-WEBAPP Schneider Electric Umotion Builder runscript.php arbitrary file include attempt (more info ...)web-application-attack  2017-7974  99344    URL
44232SERVER-WEBAPP Western Digital Dropbox App dropbox.php command injection attempt (more info ...)web-application-attack        URL
44233SERVER-WEBAPP Western Digital Dropbox App dropbox.php command injection attempt (more info ...)web-application-attack        URL
44234SERVER-WEBAPP Western Digital Dropbox App dropbox.php command injection attempt (more info ...)web-application-attack        URL
44235INDICATOR-OBFUSCATION FOPO obfuscated PHP file upload attempt (more info ...)misc-attack        URL
44236SERVER-WEBAPP Wordpress Symposium arbitrary PHP file upload attempt (more info ...)attempted-admin  2014-10021  71686    URL
44359SERVER-WEBAPP Trend Micro proxy_controller.php command injection attempt (more info ...)web-application-attack  2017-11394  100130    URL
44360SERVER-WEBAPP Trend Micro proxy_controller.php command injection attempt (more info ...)web-application-attack  2017-11394  100130    URL
44361SERVER-WEBAPP Trend Micro proxy_controller.php command injection attempt (more info ...)web-application-attack  2017-11394  100130    URL
44388SERVER-WEBAPP Multiple routers getcfg.php credential disclosure attempt (more info ...)attempted-recon  2018-7034      URL
44436SERVER-WEBAPP DenyAll WAF tail.php command injection attempt (more info ...)web-application-attack        URL
44437SERVER-WEBAPP DenyAll WAF tail.php command injection attempt (more info ...)web-application-attack        URL
44465SERVER-WEBAPP Fibaro Home Center liliSetDeviceCommand.php command injection attempt (more info ...)web-application-attack        URL
44466SERVER-WEBAPP Fibaro Home Center liliSetDeviceCommand.php command injection attempt (more info ...)web-application-attack        URL
44467SERVER-WEBAPP Fibaro Home Center liliSetDeviceCommand.php command injection attempt (more info ...)web-application-attack        URL
44471SERVER-WEBAPP Netgear ReadyNAS Surveillance upgrade_handle.php command injection attempt (more info ...)web-application-attack        URL
44472SERVER-WEBAPP Netgear ReadyNAS Surveillance upgrade_handle.php command injection attempt (more info ...)web-application-attack        URL
44578SERVER-WEBAPP QNAP NAS HelpDesk App supportutils.php SQL injection attempt (more info ...)attempted-user  2017-13068      URL
44684SERVER-WEBAPP Kaltura userzone cookie PHP object injection attempt (more info ...)web-application-attack  2017-14143  100976    
44731SERVER-WEBAPP Tuleap getRecentElements PHP object injection attempt (more info ...)web-application-attack  2017-7411      URL
44764SERVER-WEBAPP CMS Made Simple editusertag.php arbitrary PHP code execution attempt (more info ...)web-application-attack  2017-8912      URL
44767SERVER-WEBAPP Trend Micro Smart Protection Server cm_agent.php command injection attempt (more info ...)web-application-attack  2017-11395  100461    URL
45060SERVER-WEBAPP pfSense system_groupmanager.php command injection attempt (more info ...)web-application-attack        URL
45235SERVER-WEBAPP Palo Alto Networks Firewall router.php XML attribute injection attempt (more info ...)attempted-admin  2017-15944  102079    URL
45240SERVER-WEBAPP OpenEMR fax_dispatch.php command injection attempt (more info ...)web-application-attack        URL
45421SERVER-WEBAPP PhpCollab editclient.php arbitrary PHP file upload attempt (more info ...)attempted-admin  2017-6090      URL
45479SERVER-WEBAPP Western Digital MyCloud multi_uploadify.php arbitrary PHP file upload attempt (more info ...)attempted-admin  2017-17560      URL
45523SERVER-OTHER Magneto CE and EE PHP objection injection attempt (more info ...)attempted-admin  2016-4010      
45749SERVER-WEBAPP PHPUnit PHP remote code execution attempt (more info ...)web-application-attack  2017-9841      
45917SERVER-WEBAPP PHPMailer command injection remote code execution attempt (more info ...)web-application-attack  2016-10074      URL
45984SERVER-WEBAPP Joomla component Jimtawl 2.2.5 arbitrary PHP file upload attempt (more info ...)attempted-admin  2018-6580      URL
46026SERVER-WEBAPP EventManager page.php sql injection attempt SQL injection attempt (more info ...)web-application-attack  2018-6576      URL
46027SERVER-WEBAPP EventManager page.php sql injection attempt SQL injection attempt (more info ...)web-application-attack  2018-6576      URL
46343SERVER-WEBAPP Cisco Prime Network Analysis graph.php directory traversal attempt (more info ...)web-application-attack  2017-12285  101527    URL
46753SERVER-WEBAPP LG NAS login_check.php command injection attempt (more info ...)web-application-attack  2018-10818      URL
46822SERVER-WEBAPP Western Digital MyCloud raid_cgi.php arbitrary command execution attempt (more info ...)web-application-attack        URL
46860SERVER-WEBAPP Western Digital MyCloud jqueryFileTree.php command injection attempt (more info ...)web-application-attack        URL
46861SERVER-WEBAPP Western Digital MyCloud jqueryFileTree.php command injection attempt (more info ...)web-application-attack        URL
46862SERVER-WEBAPP Western Digital MyCloud jqueryFileTree.php command injection attempt (more info ...)web-application-attack        URL
46886SERVER-WEBAPP Quest KACE Systems Management Appliance ajax_email_connection_test.php command injection attempt (more info ...)web-application-attack  2018-11139      URL
47041SERVER-WEBAPP Quest KACE Systems Management Appliance download_agent_installer.php command injection attempt (more info ...)web-application-attack  2018-11138      URL
47042SERVER-WEBAPP Quest KACE Systems Management Appliance download_agent_installer.php command injection attempt (more info ...)web-application-attack  2018-11138      URL
47499SERVER-WEBAPP TestLink Open Source Test Management PHP code injection attempt (more info ...)web-application-attack  2018-7466      
47500SERVER-WEBAPP TestLink Open Source Test Management PHP code injection attempt (more info ...)web-application-attack  2018-7466      
47543SERVER-WEBAPP MicroFocus Secure Messaging Gateway enginelist.php SQL injection attempt (more info ...)web-application-attack  2018-12464      URL
47544SERVER-WEBAPP MicroFocus Secure Messaging Gateway enginelist.php SQL injection attempt (more info ...)web-application-attack  2018-12464      URL
47657SERVER-WEBAPP Horde Groupware Webmail encryptMessage prefs.php command injection attempt (more info ...)web-application-attack  2017-7413      URL
47658SERVER-WEBAPP Horde Groupware Webmail encryptMessage prefs.php command injection attempt (more info ...)web-application-attack  2017-7413      URL
47659SERVER-WEBAPP Horde Groupware Webmail encryptMessage prefs.php command injection attempt (more info ...)web-application-attack  2017-7413      URL
47660SERVER-WEBAPP Horde Groupware Webmail encryptMessage edit.php command injection attempt (more info ...)web-application-attack  2017-7413      URL
47661SERVER-WEBAPP Horde Groupware Webmail encryptMessage prefs.php command injection attempt (more info ...)web-application-attack  2017-7413      URL
47672SERVER-WEBAPP TerraMaster NAS logtable.php command injection attempt (more info ...)web-application-attack  2018-13354      URL
47817SERVER-WEBAPP SoftNAS StorageCenter snserv.php command injection attempt (more info ...)web-application-attack  2018-14417  104914    URL
47818SERVER-WEBAPP SoftNAS StorageCenter snserv.php command injection attempt (more info ...)web-application-attack  2018-14417  104914    URL
47819SERVER-WEBAPP SoftNAS StorageCenter snserv.php command injection attempt (more info ...)web-application-attack  2018-14417  104914    URL
47831SERVER-WEBAPP phpmyadmin post-authentication local file inclusion attempt (more info ...)web-application-attack  2018-12613      URL
47832SERVER-WEBAPP WordPress Responsive Thumbnail Slider arbitrary PHP file upload attempt (more info ...)attempted-admin        URL
48004SERVER-WEBAPP Navigate CMS login.php SQL injection attempt (more info ...)web-application-attack  2018-17552      URL
48005SERVER-WEBAPP Navigate CMS navigate_upload.php arbitrary PHP file upload attempt (more info ...)attempted-admin  2018-17553      URL
48006SERVER-WEBAPP Navigate CMS navigate_upload.php directory traversal attempt (more info ...)web-application-attack  2018-17553      URL
48007SERVER-WEBAPP Navigate CMS navigate_upload.php directory traversal attempt (more info ...)web-application-attack  2018-17553      URL
48008SERVER-WEBAPP Navigate CMS navigate_upload.php directory traversal attempt (more info ...)web-application-attack  2018-17553      URL
48061SERVER-WEBAPP pfSense status_interfaces.php command injection attempt (more info ...)web-application-attack  2018-16055      URL
48104SERVER-WEBAPP CMS Made Simple arbitrary PHP file upload attempt (more info ...)attempted-admin  2018-1000094      
48252SERVER-WEBAPP Idreamsoft iCMS admincp.php SQL injection attempt (more info ...)web-application-attack  2018-12888      URL
48263SERVER-WEBAPP Blueimp jQuery File Upload arbitrary PHP file upload attempt (more info ...)web-application-attack  2018-9206      URL
48443SERVER-WEBAPP Nagios XI magpie_debug.php command argument injection attempt (more info ...)web-application-attack  2018-15708      URL
48484SERVER-WEBAPP Nagios XI cmdsubsys.php command injection attempt (more info ...)web-application-attack  2018-15709      URL
48838SERVER-WEBAPP Wifi-Soft Unibox diagnostic_tools_controller.php command injection attempt (more info ...)web-application-attack  2019-3496      URL
48839SERVER-WEBAPP Wifi-Soft Unibox diagnostic_tools_controller.php command injection attempt (more info ...)web-application-attack  2019-3496      URL
48840SERVER-WEBAPP Wifi-Soft Unibox diagnostic_tools_controller.php command injection attempt (more info ...)web-application-attack  2019-3496      URL
48841SERVER-WEBAPP Wifi-Soft Unibox ping.php command injection attempt (more info ...)web-application-attack  2019-3497      URL
48842SERVER-WEBAPP Wifi-Soft Unibox ping.php command injection attempt (more info ...)web-application-attack  2019-3497      URL
48843SERVER-WEBAPP Wifi-Soft Unibox ping.php command injection attempt (more info ...)web-application-attack  2019-3497      URL
49257SERVER-WEBAPP Drupal Core 8 PHP object injection RCE attempt (more info ...)web-application-attack  2019-6340      
49298SERVER-WEBAPP NoneCms V1.3 PHP code execution attempt (more info ...)web-application-attack  2018-20062      URL
49456SERVER-OTHER PHP webshell upload attempt (more info ...)attempted-user        URL
49457SERVER-OTHER PHP webshell upload attempt (more info ...)attempted-user        URL
49458SERVER-OTHER PHP webshell upload attempt (more info ...)attempted-user        URL
49537SERVER-WEBAPP elFinder PHP connector arbitrary PHP file upload attempt (more info ...)attempted-admin  2019-9194      URL
49538SERVER-WEBAPP elFinder PHP connector command injection attempt (more info ...)web-application-attack  2019-9194      URL
49635SERVER-WEBAPP CMS Made Simple Showtime2 Module arbitrary PHP file upload attempt (more info ...)attempted-admin  2019-9692      URL
49657INDICATOR-COMPROMISE php web shell upload attempt (more info ...)web-application-attack        
49672SERVER-OTHER PHP gdImageColorMatch heap buffer overflow file upload attempt (more info ...)web-application-attack  2019-6977      URL
49673SERVER-OTHER PHP gdImageColorMatch heap buffer overflow file download attempt (more info ...)web-application-attack  2019-6977      URL
49674FILE-OTHER PHP use after free attempt (more info ...)attempted-user        
49675FILE-OTHER PHP use after free attempt (more info ...)attempted-user        
49714SERVER-WEBAPP Horde Groupware Webmail Contact Management add.php arbitrary PHP file upload attempt (more info ...)attempted-admin  2019-9858      URL
49715SERVER-WEBAPP Horde Groupware Webmail Contact Management add.php directory traversal attempt (more info ...)web-application-attack        URL
49768SERVER-WEBAPP D-Link DNS-320L ShareCenter PHP code injection attempt (more info ...)web-application-attack        URL
49769SERVER-WEBAPP D-Link DNS-320L ShareCenter PHP code injection attempt (more info ...)web-application-attack        URL
49991SERVER-WEBAPP WordPress WooCommerce Checkout Manager Plugin arbitrary PHP file upload attempt (more info ...)attempted-admin        URL
50182INDICATOR-SCAN PHP backdoor scan attempt (more info ...)misc-activity        URL
50507MALWARE-BACKDOOR WebShellOrb PHP shell outbound connection attempt (more info ...)trojan-activity        
50508MALWARE-BACKDOOR WebShellOrb PHP shell upload attempt (more info ...)trojan-activity        
50646SERVER-WEBAPP NUUO NVRmini upgrade_handle.php command injection attempt (more info ...)web-application-attack  2018-14933      URL
50647SERVER-WEBAPP NUUO NVRmini upgrade_handle.php command injection attempt (more info ...)web-application-attack  2018-14933      URL
50648SERVER-WEBAPP NUUO NVRmini upgrade_handle.php command injection attempt (more info ...)web-application-attack  2018-14933      URL
50649SERVER-WEBAPP NUUO NVRmini upgrade_handle.php command injection attempt (more info ...)web-application-attack  2018-14933      URL
50995SERVER-WEBAPP PHP ProjectPier remote file include attempt (more info ...)web-application-attack  2018-10759      
50996SERVER-WEBAPP PHP ProjectPier remote file include attempt (more info ...)web-application-attack  2018-10759      
51142SERVER-WEBAPP Moodle 3.x PHP code injection attempt (more info ...)web-application-attack  2018-1133      
51143SERVER-WEBAPP Moodle 3.x PHP code injection attempt (more info ...)web-application-attack  2018-1133      
51396SERVER-WEBAPP ThinkPHP 5.0.23/5.1.31 command injection attempt (more info ...)web-application-attack        URL
51397SERVER-WEBAPP ThinkPHP SQL injection attempt (more info ...)web-application-attack        URL
51398SERVER-WEBAPP ThinkPHP command injection attempt (more info ...)web-application-attack        URL
51399SERVER-WEBAPP ThinkPHP SQL injection attempt (more info ...)web-application-attack        URL
51570SERVER-WEBAPP osCommerce PHP code injection attempt (more info ...)web-application-attack        URL
51667SERVER-WEBAPP Trend Micro Control Manager download.php directory traversal attempt (more info ...)web-application-attack        URL
51668SERVER-WEBAPP Trend Micro Control Manager download.php directory traversal attempt (more info ...)web-application-attack        URL
51669SERVER-WEBAPP Trend Micro Control Manager download.php directory traversal attempt (more info ...)web-application-attack        URL
51816SERVER-WEBAPP vBulletin updateAvatar PHP remote code execution attempt (more info ...)web-application-attack  2019-17132      
51817SERVER-WEBAPP vBulletin updateAvatar PHP remote code execution attempt (more info ...)web-application-attack  2019-17132      
51818SERVER-WEBAPP vBulletin updateAvatar PHP remote code execution attempt (more info ...)web-application-attack  2019-17132      
51924SERVER-WEBAPP YouPHPTube getImage.php command injection attempt (more info ...)web-application-attack  2019-5127      URL
51925SERVER-WEBAPP YouPHPTube getImageMP4.php command injection attempt (more info ...)web-application-attack  2019-5128      URL
51926SERVER-WEBAPP YouPHPTube getSpiritsFromVideo.php command injection attempt (more info ...)web-application-attack  2019-5129      URL
51927SERVER-WEBAPP YouPHPTube getSpiritsFromVideo.php command injection attempt (more info ...)web-application-attack        URL
51928SERVER-WEBAPP YouPHPTube getSpiritsFromVideo.php command injection attempt (more info ...)web-application-attack        URL
51977SERVER-WEBAPP FusionPBX service_edit.php command injection attempt (more info ...)web-application-attack  2019-15029      
51978SERVER-WEBAPP FusionPBX service_edit.php command injection attempt (more info ...)web-application-attack  2019-15029      
51979SERVER-WEBAPP FusionPBX service_edit.php command injection attempt (more info ...)web-application-attack  2019-15029      
51980SERVER-WEBAPP FusionPBX service_edit.php command injection attempt (more info ...)web-application-attack  2019-15029      
52123SERVER-WEBAPP PHP FPM env_path_info buffer underflow attempt (more info ...)web-application-attack  2019-11043      URL
52350SERVER-WEBAPP Wordpress Plainview Activity Monitor activities_overview.php command injection attempt (more info ...)web-application-attack  2018-15877      
52351SERVER-WEBAPP Wordpress Plainview Activity Monitor activities_overview.php command injection attempt (more info ...)web-application-attack  2018-15877      
52352SERVER-WEBAPP Wordpress Plainview Activity Monitor activities_overview.php command injection attempt (more info ...)web-application-attack  2018-15877      
52353SERVER-WEBAPP rConfig ajaxServerSettingsChk.php command injection attempt (more info ...)web-application-attack  2019-16662      URL
52354SERVER-WEBAPP rConfig ajaxServerSettingsChk.php command injection attempt (more info ...)web-application-attack  2019-16662      URL
52355SERVER-WEBAPP rConfig ajaxServerSettingsChk.php command injection attempt (more info ...)web-application-attack  2019-16662      URL
53505SERVER-WEBAPP Horde Groupware Webmail data import PHP code injection attempt (more info ...)web-application-attack  2020-8518      
53506SERVER-WEBAPP Horde Groupware Webmail data import PHP code injection attempt (more info ...)web-application-attack  2020-8518      
53566SERVER-WEBAPP WordPress Plugin ThemeREX PHP code injection attempt (more info ...)web-application-attack  2020-10257      URL
53567SERVER-WEBAPP WordPress Plugin ThemeREX PHP code injection attempt (more info ...)web-application-attack  2020-10257      URL
53568SERVER-WEBAPP WordPress Plugin ThemeREX PHP code injection attempt (more info ...)web-application-attack  2020-10257      URL
54767SERVER-WEBAPP vBulletin template rendering arbitrary PHP code execution attempt (more info ...)attempted-user  2020-17496      URL
56519SERVER-WEBAPP WordPress plugin Autoptimize arbitrary PHP file upload attempt (more info ...)attempted-user  2020-24948      URL
56545SERVER-WEBAPP rConfig commands.inc.php SQL injection attempt (more info ...)web-application-attack  2020-10220      URL
56823SERVER-WEBAPP Citrix CakePHP command injection attempt (more info ...)web-application-attack  2020-8271      URL
56824SERVER-WEBAPP Citrix CakePHP command injection attempt (more info ...)web-application-attack  2020-8271      URL
56830SERVER-WEBAPP WordPress Adning Advertising plugin arbitrary PHP file upload attempt (more info ...)attempted-admin        URL
56831SERVER-WEBAPP WordPress Adning Advertising plugin arbitrary PHP file upload attempt (more info ...)attempted-admin        URL
56877SERVER-WEBAPP Nagios XI mibs.php remote command injection attempt (more info ...)web-application-attack  2020-5791      
56879SERVER-WEBAPP Nagios XI mibs.php remote command injection attempt (more info ...)web-application-attack  2020-5791      
56880SERVER-WEBAPP Nagios XI mibs.php remote command injection attempt (more info ...)web-application-attack  2020-5791      
57425MALWARE-BACKDOOR Php.Malware.Matamu inbound connection attempt (more info ...)trojan-activity        URL
57426SERVER-WEBAPP Zend and laminas-http frameworks streamName PHP object injection attempt (more info ...)web-application-attack  2021-3007      URL
57490SERVER-WEBAPP Klog Server authenticate.php user command injection attempt (more info ...)web-application-attack  2020-35729      
57491SERVER-WEBAPP Klog Server authenticate.php user command injection attempt (more info ...)web-application-attack  2020-35729      
57492SERVER-WEBAPP Klog Server authenticate.php user command injection attempt (more info ...)web-application-attack  2020-35729      
57493SERVER-WEBAPP Klog Server authenticate.php user command injection attempt (more info ...)web-application-attack  2020-35729      
57517SERVER-WEBAPP Serendipity index.php SQL injection attempt (more info ...)web-application-attack  2007-1326      
57518SERVER-WEBAPP Serendipity index.php SQL injection attempt (more info ...)web-application-attack  2007-1326      
57519SERVER-WEBAPP Serendipity index.php SQL injection attempt (more info ...)web-application-attack  2007-1326      
57911SERVER-WEBAPP Nagios XI monitoringplugins.php command injection attempt (more info ...)web-application-attack  2020-35578      URL
58048MALWARE-OTHER Php.Webshell.CNHonker download attempt (more info ...)trojan-activity        URL
58049MALWARE-OTHER Php.Webshell.CNHonker download attempt (more info ...)trojan-activity        URL
58050MALWARE-OTHER Php.Webshell.CNHonker upload attempt (more info ...)trojan-activity        URL
58051MALWARE-OTHER Php.Webshell.CNHonker upload attempt (more info ...)trojan-activity        URL
58089MALWARE-OTHER Php.Webshell.Phpshell3 upload attempt (more info ...)trojan-activity        URL
58090MALWARE-OTHER Php.Webshell.Phpshell3 upload attempt (more info ...)trojan-activity        URL
58091MALWARE-OTHER Php.Webshell.Phpshell3 download attempt (more info ...)trojan-activity        URL
58092MALWARE-OTHER Php.Webshell.Phpshell3 download attempt (more info ...)trojan-activity        URL
58138MALWARE-OTHER Php.Webshell.R57 download attempt (more info ...)trojan-activity        URL
58139MALWARE-OTHER Php.Webshell.R57 upload attempt (more info ...)trojan-activity        URL
58142MALWARE-OTHER Php.Webshell.WorseLinux upload attempt (more info ...)trojan-activity        URL
58143MALWARE-OTHER Php.Webshell.WorseLinux download attempt (more info ...)trojan-activity        URL
58144MALWARE-OTHER Php.Webshell.WorseLinux download attempt (more info ...)trojan-activity        URL
58145MALWARE-OTHER Php.Webshell.WorseLinux upload attempt (more info ...)trojan-activity        URL
58149MALWARE-OTHER Php.Webshell.Ayyildiz upload attempt (more info ...)trojan-activity        URL
58150MALWARE-OTHER Php.Webshell.Ayyildiz download attempt (more info ...)trojan-activity        URL
58151MALWARE-OTHER Php.Webshell.Ayyildiz upload attempt (more info ...)trojan-activity        URL
58152MALWARE-OTHER Php.Webshell.Ayyildiz download attempt (more info ...)trojan-activity        URL
58161MALWARE-OTHER Php.Webshell.C99Madnet download attempt (more info ...)trojan-activity        URL
58162MALWARE-OTHER Php.Webshell.C99Madnet upload attempt (more info ...)trojan-activity        URL
58165MALWARE-OTHER Php.Webshell.Icesword upload attempt (more info ...)trojan-activity        URL
58166MALWARE-OTHER Php.Webshell.Icesword download attempt (more info ...)trojan-activity        URL
58167MALWARE-OTHER Php.Webshell.Icesword download attempt (more info ...)trojan-activity        URL
58168MALWARE-OTHER Php.Webshell.Icesword upload attempt (more info ...)trojan-activity        URL
58228MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58229MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58243MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58244MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58341SERVER-WEBAPP PHPMyAdmin SearchController SQL injection attempt (more info ...)web-application-attack  2020-26935      
58342SERVER-WEBAPP PHPMyAdmin SearchController SQL injection attempt (more info ...)web-application-attack  2020-26935      
58343SERVER-WEBAPP PHPMyAdmin SearchController SQL injection attempt (more info ...)web-application-attack  2020-26935      
58347MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58348MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58349MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58350MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58351MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58369MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58370MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58371MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58372MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58373MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58396SERVER-WEBAPP Nagios XI PHP file injection attempt (more info ...)web-application-attack  2021-37343      
58397SERVER-WEBAPP Nagios XI PHP file injection attempt (more info ...)web-application-attack  2021-37343      
58398SERVER-WEBAPP Nagios XI PHP file injection attempt (more info ...)web-application-attack  2021-37343      
58428SERVER-WEBAPP Trend Micro Control Manager Widget modDLPViolationCntdrildown.php directory traversal attempt (more info ...)web-application-attack        
58434MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58435MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58436MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58437MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58438MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58439MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58470SERVER-WEBAPP Trend Micro Deep Discovery Email Inspector Virtual Appliance policy_setting arbitrary PHP file upload attempt (more info ...)attempted-admin        
58522SERVER-WEBAPP rConfig ajaxAddTemplate.php command injection attempt (more info ...)web-application-attack  2020-10221      
58523SERVER-WEBAPP rConfig ajaxAddTemplate.php command injection attempt (more info ...)web-application-attack  2020-10221      
58549SERVER-WEBAPP Unraid Operating System PHP code injection attempt (more info ...)web-application-attack  2020-5849      
58550SERVER-WEBAPP Unraid Operating System PHP code injection attempt (more info ...)web-application-attack  2020-5849      
58595SERVER-WEBAPP OpenEMR backup.php command injection attempt (more info ...)web-application-attack  2020-36243      
58596SERVER-WEBAPP OpenEMR backup.php command injection attempt (more info ...)web-application-attack  2020-36243      
58700MALWARE-OTHER Php.Webshell.PhpJackal upload attempt (more info ...)trojan-activity        URL
58701MALWARE-OTHER Php.Webshell.PhpJackal download attempt (more info ...)trojan-activity        URL
58912MALWARE-OTHER Php.Webshell.AcceptLanguage upload attempt (more info ...)trojan-activity        URL
58913MALWARE-OTHER Php.Webshell.AcceptLanguage download attempt (more info ...)trojan-activity        URL
58914MALWARE-OTHER Php.Webshell.529 outbound connection attempt (more info ...)trojan-activity        URL
58915MALWARE-OTHER Php.Webshell.529 download attempt (more info ...)trojan-activity        URL
58916MALWARE-OTHER Php.Webshell.529 inbound connection attempt (more info ...)trojan-activity        URL
58917MALWARE-OTHER Php.Webshell.529 upload attempt (more info ...)trojan-activity        URL
58918MALWARE-OTHER Php.Webshell.529 inbound connection attempt (more info ...)trojan-activity        URL
58920MALWARE-OTHER Php.Webshell.AjaxPHPCommandShell outbound connection attempt (more info ...)trojan-activity        URL
58921MALWARE-OTHER Php.Webshell.AjaxPHPCommandShell inbound connection attempt (more info ...)trojan-activity        URL
58922MALWARE-OTHER Php.Webshell.AjaxPHPCommandShell inbound connection attempt (more info ...)trojan-activity        URL
58923MALWARE-OTHER Php.Webshell.AjaxPHPCommandShell inbound connection attempt (more info ...)trojan-activity        URL
58924MALWARE-OTHER Php.Webshell.AjaxPHPCommandShell upload attempt (more info ...)trojan-activity        URL
58925MALWARE-OTHER Php.Webshell.AjaxPHPCommandShell download attempt (more info ...)trojan-activity        URL
59021MALWARE-OTHER Php.Webshell.Antichat download attempt (more info ...)trojan-activity        URL
59022MALWARE-OTHER Php.Webshell.Antichat upload attempt (more info ...)trojan-activity        URL
59044MALWARE-OTHER Php.Webshell.AK74 download attempt (more info ...)trojan-activity        URL
59045MALWARE-OTHER Php.Webshell.AK74 upload attempt (more info ...)trojan-activity        URL
59048MALWARE-OTHER Php.Webshell.Generic outbound connection attempt (more info ...)trojan-activity        URL
59050MALWARE-OTHER Php.Webshell.Andela download attempt (more info ...)trojan-activity        URL
59051MALWARE-OTHER Php.Webshell.Andela upload attempt (more info ...)trojan-activity        URL
59056MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
59057MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
59092MALWARE-OTHER Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
59094MALWARE-OTHER Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
59260MALWARE-OTHER Php.Webshell.Generic outbound connection attempt (more info ...)trojan-activity        URL
59261MALWARE-OTHER Php.Webshell.C0ders download attempt (more info ...)trojan-activity        URL
59262MALWARE-OTHER Php.Webshell.C0ders outbound connection attempt (more info ...)trojan-activity        URL
59263MALWARE-OTHER Php.Webshell.C0ders inbound connection attempt (more info ...)trojan-activity        URL
59264MALWARE-OTHER Php.Webshell.C0ders inbound connection attempt (more info ...)trojan-activity        URL
59265MALWARE-OTHER Php.Webshell.C0ders upload attempt (more info ...)trojan-activity        URL
59347MALWARE-OTHER Php.Webshell.CWShell inbound connection attempt (more info ...)trojan-activity        URL
59348MALWARE-OTHER Php.Webshell.CWShell outbound connection attempt (more info ...)trojan-activity        URL
59349MALWARE-OTHER Php.Webshell.CWShell inbound connection attempt (more info ...)trojan-activity        URL
59350MALWARE-OTHER Php.Webshell.CWShell inbound connection attempt (more info ...)trojan-activity        URL
59351MALWARE-OTHER Php.Webshell.SmallShell upload attempt (more info ...)trojan-activity        URL
59352MALWARE-OTHER Php.Webshell.SmallShell download attempt (more info ...)trojan-activity        URL
59353MALWARE-OTHER Php.Webshell.SmallShell download attempt (more info ...)trojan-activity        URL
59354MALWARE-OTHER Php.Webshell.SmallShell upload attempt (more info ...)trojan-activity        URL
59361SERVER-WEBAPP YouPHPTube checkConfiguration php PHP code injection attempt (more info ...)web-application-attack  2019-16124      
59362SERVER-WEBAPP YouPHPTube checkConfiguration php PHP code injection attempt (more info ...)web-application-attack  2019-16124      
59483SERVER-WEBAPP GilaCMS arbitrary php file upload attempt (more info ...)web-application-attack  2020-5514      URL
59515SERVER-WEBAPP CentOS Web Panel PHP file injection attempt (more info ...)web-application-attack  2021-45466      URL
59516SERVER-WEBAPP CentOS Web Panel PHP file injection attempt (more info ...)web-application-attack  2021-45466      URL
59517SERVER-WEBAPP CentOS Web Panel PHP file injection attempt (more info ...)web-application-attack  2021-45466      URL
59577SERVER-WEBAPP rConfig ajaxAddTemplate.php directory traversal attempt (more info ...)web-application-attack  2020-10221      
59578SERVER-WEBAPP rConfig ajaxAddTemplate.php directory traversal attempt (more info ...)web-application-attack  2020-10221      
59904SERVER-WEBAPP ImpressCMS findusers.php groups SQL injection attempt (more info ...)web-application-attack  2021-26599      URL
59905SERVER-WEBAPP ImpressCMS findusers.php groups SQL injection attempt (more info ...)web-application-attack  2021-26599      URL
60085SERVER-WEBAPP OctoberCMS PHP file injection attempt (more info ...)web-application-attack  2022-21705      
60086SERVER-WEBAPP OctoberCMS PHP file injection attempt (more info ...)web-application-attack  2022-21705      
60087SERVER-WEBAPP OctoberCMS PHP file injection attempt (more info ...)web-application-attack  2022-21705      
60284MALWARE-OTHER Php.Webshell.CrewShell inbound connection attempt (more info ...)trojan-activity        URL
60285MALWARE-OTHER Php.Webshell.CrewShell inbound connection attempt (more info ...)trojan-activity        URL
60286MALWARE-OTHER Php.Webshell.CrewShell outbound connection attempt (more info ...)trojan-activity        URL
60296MALWARE-OTHER Php.Webshell.Cybershell download attempt (more info ...)trojan-activity        URL
60297MALWARE-OTHER Php.Webshell.Cybershell inbound connection attempt (more info ...)trojan-activity        URL
60299MALWARE-OTHER Php.Webshell.Cybershell upload attempt (more info ...)trojan-activity        URL
60300MALWARE-OTHER Php.Webshell.Cybershell inbound connection attempt (more info ...)trojan-activity        URL
60301MALWARE-OTHER Php.Webshell.Cybershell outbound connection attempt (more info ...)trojan-activity        URL
60302MALWARE-OTHER Php.Webshell.Cybershell outbound connection attempt (more info ...)trojan-activity        URL
60339MALWARE-OTHER Php.Webshell.DiveShell upload attempt (more info ...)trojan-activity        URL
60340MALWARE-OTHER Php.Webshell.DiveShell download attempt (more info ...)trojan-activity        URL
60399MALWARE-OTHER Php.Webshell.DToolPro download attempt (more info ...)trojan-activity        URL
60400MALWARE-OTHER Php.Webshell.DToolPro upload attempt (more info ...)trojan-activity        URL
60422SERVER-WEBAPP PAN-OS Simple Certificate Enrollment Protocol arbitrary PHP file upload attempt (more info ...)attempted-admin  2021-3060      
60423SERVER-WEBAPP PAN-OS Simple Certificate Enrollment Protocol arbitrary PHP file upload attempt (more info ...)attempted-admin  2021-3060      
60451MALWARE-OTHER Php.Webshell.Erne inbound connection attempt (more info ...)trojan-activity        URL
60452MALWARE-OTHER Php.Webshell.Erne inbound connection attempt (more info ...)trojan-activity        URL
60469MALWARE-OTHER Php.Webshell.CmdShell upload attempt (more info ...)trojan-activity        URL
60470MALWARE-OTHER Php.Webshell.CmdShell download attempt (more info ...)trojan-activity        URL
60471MALWARE-OTHER Php.Webshell.CmdShell outbound connection attempt (more info ...)trojan-activity        URL
60494MALWARE-OTHER Php.Webshell.Exoshell upload attempt (more info ...)trojan-activity        URL
60495MALWARE-OTHER Php.Webshell.Exoshell download attempt (more info ...)trojan-activity        URL
60506MALWARE-OTHER Php.Webshell.FTPSearch outbound connection attempt (more info ...)trojan-activity        URL
60569SERVER-WEBAPP QNAP Photo Station combine.php remote code execution attempt (more info ...)web-application-attack  2022-27593      
60589MALWARE-OTHER Php.Webshell.GoShell download attempt (more info ...)trojan-activity        URL
60697SERVER-WEBAPP VICIdial user_stats.php SQL injection attempt (more info ...)web-application-attack  2022-34878      URL
60791SERVER-WEBAPP GLPI htmlawed php remote code execution attempt (more info ...)web-application-attack  2022-35914      URL
60792SERVER-WEBAPP GLPI htmlawed php remote code execution attempt (more info ...)web-application-attack  2022-35914      URL
61046MALWARE-OTHER Php.Webshell.HiddenShell download attempt (more info ...)trojan-activity        URL
61047MALWARE-OTHER Php.Webshell.HiddenShell upload attempt (more info ...)trojan-activity        URL
61132SERVER-WEBAPP Fscan scanner PHP object injection attempt (more info ...)web-application-attack        URL
61177SERVER-WEBAPP SugarCRM EmailTemplates PHP webshell access attempt (more info ...)attempted-user  2023-22952      URL
61178SERVER-WEBAPP SugarCRM EmailTemplates PHP webshell access attempt (more info ...)attempted-user  2023-22952      URL
61179SERVER-WEBAPP SugarCRM EmailTemplates PHP file injection attempt (more info ...)web-application-attack  2023-22952      URL
61534SERVER-WEBAPP Avaya Aura Device Services PhoneBackup arbitrary PHP file upload attempt (more info ...)attempted-admin        URL
61834SERVER-WEBAPP Bitrix CMS Vote Module PHP file injection attempt (more info ...)web-application-attack  2022-27228      URL
61835SERVER-WEBAPP Bitrix CMS HTML Editor Module PHP file injection attempt (more info ...)web-application-attack  2022-27228      URL
62055MALWARE-BACKDOOR Php.Webshell.AntSword transfer attempt (more info ...)trojan-activity        URL
62056MALWARE-BACKDOOR Php.Webshell.AntSword transfer attempt (more info ...)trojan-activity        URL
62096SERVER-WEBAPP WordPress Core l10n.php directory traversal attempt (more info ...)web-application-attack  2023-2745      
62097SERVER-WEBAPP WordPress Core l10n.php directory traversal attempt (more info ...)web-application-attack  2023-2745      
62115SERVER-WEBAPP GetSimple CMS PHP code injection attempt (more info ...)web-application-attack  2022-41544      URL
62116SERVER-WEBAPP GetSimple CMS PHP code injection attempt (more info ...)web-application-attack  2022-41544      URL
62117MALWARE-BACKDOOR Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
62118MALWARE-BACKDOOR Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL
62119MALWARE-BACKDOOR Php.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
62120MALWARE-BACKDOOR Php.Webshell.Generic download attempt (more info ...)trojan-activity        URL


# of warning rules in this group: 596

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
824SERVER-WEBAPP php.cgi access (more info ...)attempted-recon 1999-0238 712 10178 
1161SERVER-WEBAPP piranha passwd.php3 access (more info ...)attempted-recon 2000-0322 1149  
1254SERVER-WEBAPP PHPLIB remote command attempt (more info ...)attempted-user 2001-1370 3079 14910 
1255SERVER-WEBAPP PHPLIB remote command attempt (more info ...)attempted-user 2001-1370 3079  
1300SERVER-WEBAPP admin.php file upload attempt (more info ...)attempted-admin 2001-1032 3361  
1301SERVER-WEBAPP admin.php access (more info ...)attempted-recon 2001-1032 9270  
1399SERVER-WEBAPP PHP-Nuke remote file include attempt (more info ...)web-application-attack 2002-0206 3889  
1407SERVER-WEBAPP smssend.php access (more info ...)web-application-activity 2002-0220 3982  
1490SERVER-WEBAPP Phorum /support/common.php attempt (more info ...)web-application-attack  1997  
1491SERVER-WEBAPP Phorum /support/common.php access (more info ...)web-application-attack 2004-0034 9361  
1742SERVER-WEBAPP Blahz-DNS dostuff.php modify user attempt (more info ...)web-application-attack 2002-0599 4618  
1743SERVER-WEBAPP Blahz-DNS dostuff.php access (more info ...)web-application-activity 2002-0599 4618  
1745SERVER-WEBAPP Messagerie supp_membre.php access (more info ...)web-application-activity  4635  
1773SERVER-WEBAPP php.exe access (more info ...)web-application-activity    URL
1774SERVER-WEBAPP bb_smilies.php access (more info ...)web-application-activity    URL
1815SERVER-WEBAPP directory.php arbitrary command attempt (more info ...)misc-attack 2002-0434 4278 11017 
1816SERVER-WEBAPP directory.php access (more info ...)misc-attack 2002-0434 4278  
1834SERVER-WEBAPP PHP-Wiki cross site scripting attempt (more info ...)web-application-attack 2002-1070 5254  
1967SERVER-WEBAPP phpbb quick-reply.php arbitrary command attempt (more info ...)web-application-attack 2002-2287 6173  
1968SERVER-WEBAPP phpbb quick-reply.php access (more info ...)web-application-activity 2002-2287 6173  
1999SERVER-WEBAPP edit_image.php access (more info ...)web-application-activity 2001-1020 3288 11104 
2000SERVER-WEBAPP readmsg.php access (more info ...)web-application-activity 2001-1408  11073 
2074SERVER-WEBAPP Mambo uploadimage.php upload php file attempt (more info ...)web-application-attack 2003-1204 6572 16315 
2075SERVER-WEBAPP Mambo upload.php upload php file attempt (more info ...)web-application-attack 2003-1204 6572 16315 
2076SERVER-WEBAPP Mambo uploadimage.php access (more info ...)web-application-activity 2003-1204 6572 16315 
2078SERVER-WEBAPP phpBB privmsg.php access (more info ...)web-application-activity 2003-1530 6634  
2140SERVER-WEBAPP p-news.php access (more info ...)web-application-activity   11669 
2141SERVER-WEBAPP shoutbox.php directory traversal attempt (more info ...)web-application-attack   11668 
2142SERVER-WEBAPP shoutbox.php access (more info ...)web-application-activity   11668 
2143SERVER-WEBAPP b2 cafelog gm-2-b2.php remote file include attempt (more info ...)web-application-attack   11667 
2144SERVER-WEBAPP b2 cafelog gm-2-b2.php access (more info ...)web-application-activity   11667 
2145SERVER-WEBAPP TextPortal admin.php default password admin attempt (more info ...)web-application-activity  7673 11660 URL
2146SERVER-WEBAPP TextPortal admin.php default password 12345 attempt (more info ...)web-application-activity  7673 11660 URL
2147SERVER-WEBAPP BLNews objects.inc.php4 remote file include attempt (more info ...)web-application-attack 2003-0394 7677 11647 
2148SERVER-WEBAPP BLNews objects.inc.php4 access (more info ...)web-application-activity 2003-0394 7677 11647 
2149SERVER-WEBAPP Turba status.php access (more info ...)web-application-activity   11646 
2150SERVER-WEBAPP ttCMS header.php remote file include attempt (more info ...)web-application-attack 2003-1459 7625 11636 
2151SERVER-WEBAPP ttCMS header.php access (more info ...)web-application-activity 2003-1459 7625 11636 
2152SERVER-WEBAPP test.php access (more info ...)web-application-activity   11617 
2153SERVER-WEBAPP autohtml.php directory traversal attempt (more info ...)web-application-attack   11630 
2154SERVER-WEBAPP autohtml.php access (more info ...)web-application-activity   11630 
2227SERVER-WEBAPP forum_details.php access (more info ...)web-application-attack  7933 11760 
2228SERVER-WEBAPP phpMyAdmin db_details_importdocsql.php access (more info ...)web-application-attack  7965 11761 
2229SERVER-WEBAPP viewtopic.php access (more info ...)web-application-attack 2003-0486 7979 11767 
2279SERVER-WEBAPP UpdateClasses.php access (more info ...)web-application-activity  9057  
2282SERVER-WEBAPP GlobalFunctions.php access (more info ...)web-application-activity  9057  
2283SERVER-WEBAPP DatabaseFunctions.php access (more info ...)web-application-activity  9057  
2287SERVER-WEBAPP Advanced Poll admin_comment.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2288SERVER-WEBAPP Advanced Poll admin_edit.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2289SERVER-WEBAPP Advanced Poll admin_embed.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2290SERVER-WEBAPP Advanced Poll admin_help.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2291SERVER-WEBAPP Advanced Poll admin_license.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2292SERVER-WEBAPP Advanced Poll admin_logout.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2293SERVER-WEBAPP Advanced Poll admin_password.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2294SERVER-WEBAPP Advanced Poll admin_preview.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2295SERVER-WEBAPP Advanced Poll admin_settings.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2296SERVER-WEBAPP Advanced Poll admin_stats.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2297SERVER-WEBAPP Advanced Poll admin_templates_misc.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2298SERVER-WEBAPP Advanced Poll admin_templates.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2299SERVER-WEBAPP Advanced Poll admin_tpl_misc_new.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2300SERVER-WEBAPP Advanced Poll admin_tpl_new.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2301SERVER-WEBAPP Advanced Poll booth.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2302SERVER-WEBAPP Advanced Poll poll_ssi.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2303SERVER-WEBAPP Advanced Poll popup.php access (more info ...)web-application-activity 2003-1181 8890 11487 
2304SERVER-WEBAPP files.inc.php access (more info ...)web-application-activity 2003-1153 8910  
2305SERVER-WEBAPP chatbox.php access (more info ...)web-application-activity 2003-1191 8930  
2328SERVER-WEBAPP authentication_index.php access (more info ...)web-application-activity 2004-0032  11982 
2345SERVER-WEBAPP PhpGedView search.php access (more info ...)web-application-activity 2004-0032 9369  
2346SERVER-WEBAPP myPHPNuke chatheader.php access (more info ...)web-application-activity  6544  
2353SERVER-WEBAPP IdeaBox cord.php file include (more info ...)web-application-activity  7488  
2354SERVER-WEBAPP IdeaBox notification.php file include (more info ...)web-application-activity  7488  
2355SERVER-WEBAPP Invision Board emailer.php file include (more info ...)web-application-activity  7204  
2356SERVER-WEBAPP WebChat db_mysql.php file include (more info ...)web-application-attack 2007-0485 7000  
2357SERVER-WEBAPP WebChat english.php file include (more info ...)web-application-attack 2007-0485 7000  
2358SERVER-WEBAPP Typo3 translations.php file include (more info ...)web-application-attack  6984  
2359SERVER-WEBAPP Invision Board ipchat.php file include (more info ...)web-application-attack 2003-1385 6976  
2360SERVER-WEBAPP myphpPagetool pt_config.inc file include (more info ...)web-application-attack  6744  
2361SERVER-WEBAPP news.php file include (more info ...)web-application-attack  6674  
2362SERVER-WEBAPP YaBB SE packages.php file include (more info ...)web-application-attack  6663  
2363SERVER-WEBAPP Cyboards default_header.php access (more info ...)web-application-activity  6597  
2364SERVER-WEBAPP Cyboards options_form.php access (more info ...)web-application-activity  6597  
2365SERVER-WEBAPP newsPHP Language file include attempt (more info ...)web-application-activity  8488  
2366SERVER-WEBAPP PhpGedView PGV authentication_index.php base directory manipulation attempt (more info ...)web-application-attack 2004-0030 9368  
2367SERVER-WEBAPP PhpGedView PGV functions.php base directory manipulation attempt (more info ...)web-application-attack 2004-0030 9368  
2368SERVER-WEBAPP PhpGedView PGV config_gedcom.php base directory manipulation attempt (more info ...)web-application-attack 2004-0030 9368  
2372SERVER-WEBAPP Photopost PHP Pro showphoto.php access (more info ...)web-application-activity 2004-0250 9557  
2398SERVER-WEBAPP WAnewsletter newsletter.php file include attempt (more info ...)web-application-attack  6965  
2399SERVER-WEBAPP WAnewsletter db_type.php access (more info ...)web-application-activity  6964  
2405SERVER-WEBAPP phptest.php access (more info ...)web-application-activity 2004-2374 9737  
2410SERVER-WEBAPP IGeneric Free Shopping Cart page.php access (more info ...)web-application-activity  9773  
2566SERVER-WEBAPP PHPBB viewforum.php access (more info ...)web-application-activity 2004-1809 9866 12093 
2575SERVER-WEBAPP Opt-X header.php remote file include attempt (more info ...)web-application-attack 2004-2368 9732  
2654SERVER-WEBAPP PHPNuke Forum viewtopic SQL insertion attempt (more info ...)web-application-attack  7193  
2926SERVER-WEBAPP PhpGedView PGV base directory manipulation (more info ...)web-application-attack 2004-0030 9368  
3544SERVER-WEBAPP TrackerCam ComGetLogFile.php3 directory traversal attempt (more info ...)web-application-attack 2005-0481 12592 17160 
3545SERVER-WEBAPP TrackerCam ComGetLogFile.php3 log information disclosure (more info ...)web-application-activity 2005-0481 12592 17160 
3547SERVER-WEBAPP TrackerCam overly long php parameter overflow attempt (more info ...)web-application-attack 2005-0481 12592  
3690SERVER-WEBAPP Nucleus CMS action.php itemid SQL injection (more info ...)web-application-activity 2004-2056 10798 14194 
4650SERVER-WEBAPP cacti graph_image.php access (more info ...)web-application-activity  14042  
5744PUA-ADWARE Hijacker actualnames outbound connection - online.php request (more info ...)misc-activity    URL
5848PUA-ADWARE Adware warez_p2p runtime detection - ip.php request (more info ...)misc-activity    URL
6020MALWARE-CNC dsk lite 1.0 variant outbound connection php notification (more info ...)trojan-activity    URL
6042MALWARE-CNC fear 0.2 variant outbound connection php notification (more info ...)trojan-activity    URL
7149MALWARE-CNC Hacker-Tool sars notifier variant outbound connection php notification (more info ...)misc-activity    URL
7639MALWARE-CNC air variant outbound connection php notification (more info ...)trojan-activity    URL
9653MALWARE-CNC apofis 1.0 variant outbound connection php notification (more info ...)trojan-activity    URL
10196MALWARE-BACKDOOR Wordpress backdoor feed.php code execution (more info ...)trojan-activity 2007-1277 22797  URL
10197MALWARE-BACKDOOR Wordpress backdoor theme.php code execution (more info ...)trojan-activity 2007-1277 22797  URL
11664SERVER-WEBAPP sphpblog password.txt access attempt (more info ...)attempted-user 2005-2733 14667  
11665SERVER-WEBAPP sphpblog install03_cgi access attempt (more info ...)attempted-user 2005-2733 14667  
11666SERVER-WEBAPP sphpblog upload_img_cgi access attempt (more info ...)attempted-user 2005-2733 14667  
11667SERVER-WEBAPP sphpblog arbitrary file delete attempt (more info ...)attempted-user 2005-2733 14667  
11668SERVER-WEBAPP vbulletin php code injection (more info ...)attempted-user 2005-0511   URL
12610SERVER-WEBAPP phpBB viewtopic double URL encoding attempt (more info ...)web-application-attack 2004-1315   
13816SERVER-WEBAPP PHP xmlrpc.php command injection attempt (more info ...)attempted-admin 2005-1921 14088  
13817SERVER-WEBAPP PHP xmlrpc.php command injection attempt (more info ...)attempted-admin 2005-1921 14088  
13818SERVER-WEBAPP PHP alternate xmlrpc.php command injection attempt (more info ...)attempted-admin 2005-1921 14088  
15424SERVER-WEBAPP phpBB mod shoutbox sql injection attempt (more info ...)web-application-attack 2008-6301 32123  URL
15425SERVER-WEBAPP phpBB mod tag board sql injection attempt (more info ...)web-application-attack 2008-6314 32701  URL
15977SERVER-WEBAPP PHP strip_tags bypass vulnerability exploit attempt (more info ...)attempted-user 2004-0595 10724  
16078SERVER-WEBAPP PHP memory_limit vulnerability exploit attempt (more info ...)attempted-user 2004-0594 10725  
16190SERVER-ORACLE Oracle Secure Backup Administration server property_box.php command injection attempt (more info ...)attempted-admin 2009-1978 35678  
16243MALWARE-CNC downloader-ash.gen.b variant outbound connection 3264.php (more info ...)trojan-activity    URL
16613INDICATOR-COMPROMISE c99shell.php command request - cmd (more info ...)policy-violation    URL
16614INDICATOR-COMPROMISE c99shell.php command request - search (more info ...)policy-violation    URL
16615INDICATOR-COMPROMISE c99shell.php command request - upload (more info ...)policy-violation    URL
16616INDICATOR-COMPROMISE c99shell.php command request - about (more info ...)policy-violation    URL
16617INDICATOR-COMPROMISE c99shell.php command request - encoder (more info ...)policy-violation    URL
16618INDICATOR-COMPROMISE c99shell.php command request - bind (more info ...)policy-violation    URL
16619INDICATOR-COMPROMISE c99shell.php command request - ps_aux (more info ...)policy-violation    URL
16620INDICATOR-COMPROMISE c99shell.php command request - ftpquickbrute (more info ...)policy-violation    URL
16621INDICATOR-COMPROMISE c99shell.php command request - security (more info ...)policy-violation    URL
16622INDICATOR-COMPROMISE c99shell.php command request - sql (more info ...)policy-violation    URL
16623INDICATOR-COMPROMISE c99shell.php command request - eval (more info ...)policy-violation    URL
16624INDICATOR-COMPROMISE c99shell.php command request - feedback (more info ...)policy-violation    URL
16625INDICATOR-COMPROMISE c99shell.php command request - selfremove (more info ...)policy-violation    URL
16626INDICATOR-COMPROMISE c99shell.php command request - fsbuff (more info ...)policy-violation    URL
16627INDICATOR-COMPROMISE c99shell.php command request - ls (more info ...)policy-violation    URL
16628INDICATOR-COMPROMISE c99shell.php command request - phpinfo (more info ...)policy-violation    URL
16913MALWARE-CNC URI request for known malicious URI - count_log/log/boot.php?p= (more info ...)trojan-activity    URL
16923MALWARE-CNC URI request for known malicious URI - /search.php?username=coolweb07&keywords= (more info ...)trojan-activity    URL
16924MALWARE-CNC URI request for known malicious URI - /inst.php?fff= (more info ...)trojan-activity    URL
16925MALWARE-CNC URI request for known malicious URI - /message.php?subid= (more info ...)trojan-activity    URL
16927MALWARE-CNC URI request for known malicious URI - MGWEB.php?c=TestUrl (more info ...)trojan-activity    URL
16929MALWARE-CNC URI request for known malicious URI - gate.php?guid= (more info ...)trojan-activity    URL
16931MALWARE-CNC URI request for known malicious URI - feedbigfoot.php?m= (more info ...)trojan-activity    URL
17597SERVER-WEBAPP TikiWiki jhot.php script file upload attempt (more info ...)attempted-user 2006-4602 19819  URL
17898MALWARE-CNC URI request for known malicious URI - /get2.php?c=VTOXUGUI&d= (more info ...)trojan-activity    URL
17905MALWARE-CNC URI request for known malicious URI - 1de49069b6044785e9dfcd4c035cfd0c.php (more info ...)trojan-activity    URL
17906MALWARE-CNC URI request for known malicious URI - 2x/.*php (more info ...)trojan-activity    URL
18333SERVER-WEBAPP phpBook date command execution attempt (more info ...)attempted-admin 2006-0206 16229  
18334SERVER-WEBAPP phpBook mail command execution attempt (more info ...)attempted-admin 2006-0075 16106  
18478SERVER-WEBAPP miniBB rss.php premodDir remote file include attempt (more info ...)web-application-attack    
18493INDICATOR-OBFUSCATION generic PHP code obfuscation attempt (more info ...)trojan-activity    URL
18586SERVER-WEBAPP Visuplay CMS news_article.php unspecified SQL injection attempt (more info ...)web-application-activity  33209  
18678SERVER-WEBAPP osCommerce categories.php Arbitrary File Upload And Code Execution (more info ...)web-application-attack  44995  
18797SERVER-WEBAPP Oracle Secure Backup Administration property_box.php other variable command execution attempt (more info ...)attempted-admin 2010-0899 41616  
19553SERVER-WEBAPP phpMyAdmin session_to_unset session variable injection attempt (more info ...)attempted-user 2011-2506   URL
19625MALWARE-CNC URI request for known malicious URI - .sys.php?getexe= (more info ...)trojan-activity    URL
19628MALWARE-CNC URI request for known malicious URI - /1cup/script.php (more info ...)trojan-activity    URL
19632MALWARE-CNC URI request for known malicious URI - /VertexNet/adduser.php?uid= (more info ...)trojan-activity    URL
19633MALWARE-CNC URI request for known malicious URI - /VertexNet/tasks.php?uid= (more info ...)trojan-activity    URL
19653SERVER-WEBAPP Wordpress timthumb.php theme remote file include attack attempt (more info ...)web-application-attack  47374  URL
19661SERVER-OTHER Alucar php shell download attempt (more info ...)attempted-user  47374  URL
19778MALWARE-CNC URI request for known malicious URI - /games/java_trust.php?f= (more info ...)trojan-activity    URL
19869MALWARE-TOOLS Anonymous PHP RefRef DoS tool (more info ...)attempted-dos    URL
19913MALWARE-CNC URI request for known malicious URI - optima/index.php (more info ...)trojan-activity    URL
20045SQL PHPSESSID SQL injection attempt (more info ...)web-application-attack    
20046SQL PHPSESSID SQL injection attempt (more info ...)web-application-attack    
20184INDICATOR-SHELLCODE Metasploit php meterpreter stub .php file upload (more info ...)shellcode-detect    URL
20533SERVER-WEBAPP php tiny shell upload attempt (more info ...)misc-activity    URL
20629SERVER-WEBAPP geoBlog SQL injection in viewcat.php cat parameter attempt (more info ...)web-application-activity 2006-0249 16249  
20631SERVER-WEBAPP Akarru remote file include in main_content.php bm_content (more info ...)web-application-activity 2006-4645 19870  
20632SERVER-WEBAPP AnnoncesV annonce.php remote file include attempt (more info ...)web-application-attack 2006-4622 19854  
20633SERVER-WEBAPP Boite de News remote file include in inc.php url_index (more info ...)web-application-activity 2006-4123 19440  
20640SERVER-WEBAPP VEGO Web Forum SQL injection in login.php username attempt (more info ...)web-application-attack 2006-0067 16108  
20641SERVER-WEBAPP TheWebForum SQL injection in login.php username attempt (more info ...)web-application-attack 2006-0135 16161  
20642SERVER-WEBAPP TankLogger SQL injection in showInfo.php livestock_id attempt (more info ...)web-application-attack 2006-0209 16228  
20643SERVER-WEBAPP ScozBook SQL injection in auth.php adminname attempt (more info ...)web-application-attack 2006-0079 16115  
20644SERVER-WEBAPP Lizard Cart CMS SQL injection in detail.php id attempt (more info ...)web-application-attack 2006-0087 16140  
20645SERVER-WEBAPP Lizard Cart CMS SQL injection in pages.php id attempt (more info ...)web-application-attack 2006-0087 16140  
20646SERVER-WEBAPP Benders Calendar SQL injection in index.php this_day attempt (more info ...)web-application-attack 2006-0252 16242  
20647SERVER-WEBAPP inTouch SQL injection in index.php user attempt (more info ...)web-application-attack 2006-0088 16110  
20648SERVER-WEBAPP Bit 5 Blog SQL injection in processlogin.php username via (more info ...)web-application-attack 2006-0320 16244  
20649SERVER-WEBAPP ADNForum SQL injection in index.php fid attempt (more info ...)web-application-attack 2006-0123 16157  
20650SERVER-WEBAPP MyNewsGroups remote file include in layersmenu.inc.php myng_root (more info ...)web-application-attack 2006-3966 19258  
20651SERVER-WEBAPP Modernbill remote file include in config.php DIR (more info ...)web-application-attack 2006-4034 19335  
20652SERVER-WEBAPP ME Download System remote file include in header.php Vb8878b936c2bd8ae0cab (more info ...)web-application-attack 2006-4053 19336  
20654SERVER-WEBAPP GrapAgenda remote file include in index.php page (more info ...)web-application-attack 2006-4610 19857  
20656SERVER-WEBAPP GestArtremote file include in aide.php3 aide (more info ...)web-application-attack 2006-5612 22825  
20657SERVER-WEBAPP Free File Hosting remote file include in forgot_pass.php ad_body_temp (more info ...)web-application-attack 2006-5762 20781  
20660SERVER-OTHER sl.php script injection (more info ...)misc-activity    URL
20663SERVER-WEBAPP Comet WebFileManager remote file include in CheckUpload.php Language (more info ...)web-application-attack 2006-4077 19433  
20669EXPLOIT-KIT URI request for known malicious URI - w.php?f= (more info ...)trojan-activity    URL
20680SERVER-WEBAPP Flashchat aedating4CMS.php remote file include attempt (more info ...)web-application-activity 2006-4583 19826  
20728SERVER-WEBAPP WoW Roster remote file include with hslist.php and conf.php attempt (more info ...)web-application-attack 2006-3998 19269  
20731SERVER-WEBAPP TSEP tsep_config absPath parameter PHP remote file include attempt (more info ...)web-application-attack 2006-4055 19326  
20732SERVER-WEBAPP Sabdrimer PHP pluginpath remote file include attempt (more info ...)web-application-attack 2006-3520 18907  
20815SERVER-WEBAPP Vmist Downstat remote file include in chart.php art (more info ...)web-application-activity 2006-4827 20007  
20816SERVER-WEBAPP Vmist Downstat remote file include in admin.php art (more info ...)web-application-activity 2006-4827 20007  
20817SERVER-WEBAPP Vmist Downstat remote file include in modes.php art (more info ...)web-application-activity 2006-4827 20007  
20818SERVER-WEBAPP Vmist Downstat remote file include in stats.php art (more info ...)web-application-activity 2006-4827 20007  
20827SERVER-WEBAPP phpThumb fltr[] parameter remote command execution attempt (more info ...)attempted-user 2010-1598 39605  URL
21555MALWARE-OTHER Horde javascript.php href backdoor (more info ...)trojan-activity 2012-0209   URL
21670SERVER-WEBAPP PHP phpinfo cross site scripting attempt (more info ...)attempted-user 2007-1287   URL
21926SERVER-WEBAPP Joomla JCE multiple plugin arbitrary PHP file execution attempt (more info ...)attempted-user    URL
21941INDICATOR-COMPROMISE Wordpress Request for php file in fgallery directory (more info ...)web-application-attack    
22063SERVER-WEBAPP PHP-CGI remote file include attempt (more info ...)attempted-admin 2012-2336   
22064SERVER-WEBAPP PHP-CGI command injection attempt (more info ...)attempted-admin 2012-2336   
22097SERVER-WEBAPP PHP-CGI command injection attempt (more info ...)attempted-admin 2012-2336   
22917INDICATOR-COMPROMISE c99shell.php command request - cmd (more info ...)policy-violation    URL
22918INDICATOR-COMPROMISE c99shell.php command request - search (more info ...)policy-violation    URL
22919INDICATOR-COMPROMISE c99shell.php command request - upload (more info ...)policy-violation    URL
22920INDICATOR-COMPROMISE c99shell.php command request - about (more info ...)policy-violation    URL
22921INDICATOR-COMPROMISE c99shell.php command request - encoder (more info ...)policy-violation    URL
22922INDICATOR-COMPROMISE c99shell.php command request - bind (more info ...)policy-violation    URL
22923INDICATOR-COMPROMISE c99shell.php command request - ps_aux (more info ...)policy-violation    URL
22924INDICATOR-COMPROMISE c99shell.php command request - ftpquickbrute (more info ...)policy-violation    URL
22925INDICATOR-COMPROMISE c99shell.php command request - security (more info ...)policy-violation    URL
22926INDICATOR-COMPROMISE c99shell.php command request - sql (more info ...)policy-violation    URL
22927INDICATOR-COMPROMISE c99shell.php command request - eval (more info ...)policy-violation    URL
22928INDICATOR-COMPROMISE c99shell.php command request - feedback (more info ...)policy-violation    URL
22929INDICATOR-COMPROMISE c99shell.php command request - selfremove (more info ...)policy-violation    URL
22930INDICATOR-COMPROMISE c99shell.php command request - fsbuff (more info ...)policy-violation    URL
22931INDICATOR-COMPROMISE c99shell.php command request - ls (more info ...)policy-violation    URL
22932INDICATOR-COMPROMISE c99shell.php command request - phpinfo (more info ...)policy-violation    URL
22933INDICATOR-COMPROMISE c99shell.php command request - tools (more info ...)policy-violation    URL
23057MALWARE-CNC Flame malware connection - /view.php (more info ...)trojan-activity    URL
23114INDICATOR-OBFUSCATION GIF header with PHP tags - likely malicious (more info ...)misc-activity    URL
23177SERVER-WEBAPP Symantec Web Gateway timer.php cross site scripting attempt (more info ...)web-application-attack 2012-0296 53396  
23405SERVER-WEBAPP PHP-Nuke index.php SQL injection attempt (more info ...)web-application-attack 2007-1061 22638  
23406SERVER-WEBAPP PHP-Nuke index.php SQL injection attempt (more info ...)web-application-attack 2007-1061 22638  
23438INDICATOR-COMPROMISE php-shell remote command shell initialization attempt (more info ...)attempted-admin    
23439INDICATOR-COMPROMISE php-shell remote command shell upload attempt (more info ...)attempted-admin    
23440INDICATOR-COMPROMISE php-shell remote command shell upload attempt (more info ...)attempted-admin    
23441INDICATOR-COMPROMISE php-shell remote command shell upload attempt (more info ...)attempted-admin    
23442INDICATOR-COMPROMISE php-shell remote command injection attempt (more info ...)attempted-admin    
23443INDICATOR-COMPROMISE php-shell failed remote command injection attempt (more info ...)attempted-admin    
23485SERVER-WEBAPP Wordpress Invit0r plugin php upload attempt (more info ...)web-application-attack  53995  URL
23791SERVER-WEBAPP PHP use-after-free in substr_replace attempt (more info ...)misc-activity 2011-1148   
23792SERVER-WEBAPP PHP use-after-free in substr_replace attempt (more info ...)misc-activity 2011-1148   
23895SERVER-WEBAPP PHP truncated crypt function attempt (more info ...)attempted-admin 2012-2143   
23896SERVER-WEBAPP PHP truncated crypt function attempt (more info ...)attempted-admin 2012-2143   
23934SERVER-WEBAPP Symantec Web Gateway blocked.php blind sql injection attempt (more info ...)attempted-user 2012-2574 54424  URL
24060SERVER-WEBAPP PHP 5.3.3 mt_rand integer overflow attempt (more info ...)misc-activity 2011-0755   
24061SERVER-WEBAPP PHP 5.3.3 mt_rand integer overflow attempt (more info ...)misc-activity 2011-0755   
24112SERVER-WEBAPP inTouch SQL injection in index.php user attempt (more info ...)web-application-attack 2006-0088 16110  
24391INDICATOR-COMPROMISE itsoknoproblembro start php (more info ...)policy-violation    URL
24434INDICATOR-COMPROMISE fx29shell.php connection attempt (more info ...)policy-violation    
24502SERVER-WEBAPP TikiWiki tiki-graph_formula.php remote php code execution attempt (more info ...)attempted-admin 2007-5423 26006  
24517SERVER-WEBAPP F5 Networks FirePass my.activation.php3 state parameter sql injection attempt (more info ...)attempted-admin 2012-1777   URL
24561SERVER-WEBAPP WordPress XSS fs-admin.php injection attempt (more info ...)web-application-attack    
24804SERVER-WEBAPP Invision IP Board PHP unserialize code execution attempt (more info ...)attempted-admin 2012-5692 56288  URL
25063SERVER-WEBAPP PHP htmlspecialchars htmlentities function buffer overflow attempt (more info ...)attempted-admin  51860  URL
25064SERVER-WEBAPP PHP htmlspecialchars htmlentities function buffer overflow attempt (more info ...)attempted-admin  51860  URL
25236SERVER-WEBAPP WikkaWikki php code injection attempt (more info ...)web-application-attack 2011-4451 50866  
25238SERVER-WEBAPP OpenX server file upload PHP code execution attempt (more info ...)attempted-admin 2009-4098 37110  
25370SERVER-OTHER CakePHP unserialize method vulnerability exploitation attempt (more info ...)attempted-admin 2010-4335   
25907SERVER-WEBAPP PHPmyadmin brute force login attempt - User-Agent User-Agent (more info ...)trojan-activity    URL
26023MALWARE-CNC Win.Trojan.Zbot variant in.php outbound connection (more info ...)trojan-activity    URL
26191SERVER-WEBAPP MobileCartly arbitrary PHP file upload attempt (more info ...)attempted-admin  54970  
26314SERVER-OTHER Coppermine Photo Gallery picEditor.php command execution attempt (more info ...)attempted-admin 2008-0506   
26315SERVER-OTHER Coppermine Photo Gallery picEditor.php command execution attempt (more info ...)attempted-admin 2008-0506   
26316SERVER-OTHER Coppermine Photo Gallery picEditor.php command execution attempt (more info ...)attempted-admin 2008-0506   
26547SERVER-WEBAPP phpMyAdmin preg_replace remote code execution attempt (more info ...)attempted-admin 2013-3238   URL
26585INDICATOR-COMPROMISE config.inc.php in iframe (more info ...)trojan-activity    URL
26593SERVER-WEBAPP PHP htmlspecialchars htmlentities function buffer overflow attempt (more info ...)attempted-admin  51860  URL
27018SERVER-WEBAPP Novell ZENworks Mobile Management dusap.php directory traversal attempt (more info ...)attempted-admin 2013-1082 60179  URL
27019SERVER-WEBAPP Novell ZENworks Mobile Management dusap.php directory traversal attempt (more info ...)attempted-admin 2013-1082 60179  URL
27020SERVER-WEBAPP Novell ZENworks Mobile Management dusap.php directory traversal attempt (more info ...)attempted-admin 2013-1082 60179  URL
27027POLICY-OTHER PHP tag injection in http header attempt (more info ...)web-application-attack 2013-1081   
27028SERVER-WEBAPP Novell ZENworks Mobile Management mdm.php directory traversal attempt (more info ...)attempted-admin 2013-1081 58402  URL
27029SERVER-WEBAPP Novell ZENworks Mobile Management mdm.php directory traversal attempt (more info ...)attempted-admin 2013-1081 58402  URL
27030SERVER-WEBAPP Novell ZENworks Mobile Management mdm.php directory traversal attempt (more info ...)attempted-admin 2013-1081 58402  URL
27192SERVER-WEBAPP DM Albums album.php remote file include attempt (more info ...)web-application-attack 2009-2399 35521  
27196SERVER-WEBAPP OpenEngine filepool.php remote file include attempt (more info ...)web-application-attack 2008-4791 31423  URL
27218SERVER-WEBAPP Themescript remote file include in CheckUpload.php Language (more info ...)web-application-attack 2008-5066 31959  
27226SERVER-WEBAPP DokuWiki PHP file inclusion attempt (more info ...)web-application-attack 2009-1960 35095  
27227SERVER-WEBAPP txtSQL startup.php remote file include attempt (more info ...)attempted-user 2008-3595 30625  
27230SERVER-WEBAPP Pragyan CMS form.lib.php remove file include attempt (more info ...)attempted-user 2008-3207 30235  
27284SERVER-WEBAPP SezHoo remote file include in SezHooTabsAndActions.php (more info ...)web-application-attack  31756  
27623SERVER-OTHER Joomla media.php arbitrary file upload attempt (more info ...)attempted-admin 2013-5576 61582  URL
27667SERVER-WEBAPP Joomla media.php file.upload direct administrator access attempt (more info ...)attempted-admin 2013-5576 61582  URL
27752SERVER-WEBAPP Neocrome Land Down Under profile.inc.php SQL injection attempt (more info ...)attempted-user 2006-6268 21227  URL
27980MALWARE-CNC URI request for known malicious URI - /botnet/adduser.php?uid= (more info ...)trojan-activity    
27981MALWARE-CNC URI request for known malicious URI - /botnet/tasks.php?uid= (more info ...)trojan-activity    
28048SERVER-WEBAPP GLPI install.php arbitrary code injection attempt (more info ...)attempted-admin 2013-5696   URL
28049SERVER-WEBAPP GLPI install.php arbitrary code injection attempt (more info ...)attempted-admin 2013-5696   URL
28050SERVER-WEBAPP GLPI install.php arbitrary code injection attempt (more info ...)attempted-admin 2013-5696   URL
28051SERVER-WEBAPP GLPI install.php arbitrary code injection attempt (more info ...)attempted-admin 2013-5696   URL
28215SERVER-WEBAPP vBulletin upgrade.php exploit attempt (more info ...)attempted-admin    URL
28348MALWARE-OTHER SimpleTDS - request to go.php (more info ...)misc-activity    URL
28909SERVER-WEBAPP OTManager ADM_Pagina.php remote file include attempt (more info ...)web-application-attack 2008-5063 32235  
28910SERVER-WEBAPP mcRefer install.php arbitrary PHP code injection attempt (more info ...)web-application-attack 2007-1073   
28912SERVER-WEBAPP Joomla simple RSS reader admin.rssreader.php remote file include attempt (more info ...)web-application-attack 2008-5053 32265  
28957SERVER-WEBAPP RSS-aggregator display.php remote file include attempt (more info ...)attempted-user 2008-2884 29873  
29549SERVER-WEBAPP PineApp Mail-SeCure test_li_connection.php command injection (more info ...)attempted-admin    URL
29746SERVER-WEBAPP Symantec Web Gateway languagetest.php language parameter directory traversal attempt (more info ...)attempted-admin 2012-2957 54429  
29757SERVER-WEBAPP Datalife Engine preview.php Remote Code Execution attempt (more info ...)attempted-user 2013-1412   URL
30199SERVER-WEBAPP PHP DateInterval heap buffer overread denial of service attempt (more info ...)attempted-dos 2013-6712 64018  URL
30200SERVER-WEBAPP PHP DateInterval heap buffer overread denial of service attempt (more info ...)attempted-dos 2013-6712 64018  URL
30280SERVER-WEBAPP FreePBX config.php remote code execution attempt (more info ...)attempted-admin 2014-1903 65509  URL
30294SERVER-WEBAPP SePortal poll.php SQL injection attempt (more info ...)web-application-attack 2008-5191   
30295SERVER-WEBAPP SePortal print.php SQL injection attempt (more info ...)web-application-attack 2008-5191   
30296SERVER-WEBAPP SePortal staticpages.php SQL injection attempt (more info ...)web-application-attack 2008-5191   
30305SERVER-WEBAPP Horde Framework variables.php unserialize PHP code execution attempt (more info ...)attempted-admin 2014-1691 65200  
30381INDICATOR-SHELLCODE Metasploit payload cmd_unix_reverse_php_ssl (more info ...)shellcode-detect    
30452INDICATOR-SHELLCODE Metasploit payload php_bind_perl (more info ...)shellcode-detect    
30453INDICATOR-SHELLCODE Metasploit payload php_download_exec (more info ...)shellcode-detect    
30454INDICATOR-SHELLCODE Metasploit payload php_exec (more info ...)shellcode-detect    
30455INDICATOR-SHELLCODE Metasploit payload php_meterpreter_bind_tcp (more info ...)shellcode-detect    
30456INDICATOR-SHELLCODE Metasploit payload php_meterpreter_reverse_tcp (more info ...)shellcode-detect    
30457INDICATOR-SHELLCODE Metasploit payload php_reverse_perl (more info ...)shellcode-detect    
30458INDICATOR-SHELLCODE Metasploit payload php_reverse_php (more info ...)shellcode-detect    
30459INDICATOR-SHELLCODE Metasploit payload php_shell_findsock (more info ...)shellcode-detect    
31360SERVER-WEBAPP PHP include parameter remote file include attempt (more info ...)attempted-user 2001-1237 3397  
31362SERVER-WEBAPP MiniBB PHP arbitrary remote code execution attempt (more info ...)attempted-user 2006-3690 18998  
31363SERVER-WEBAPP MF Piadas admin.php page parameter PHP remote file include attempt (more info ...)web-application-attack 2006-3323 18679  
31364SERVER-WEBAPP FlashGameScript index.php func parameter PHP remote file include attempt (more info ...)web-application-attack 2007-1078 22646  
31377SERVER-WEBAPP PHP includedir parameter remote file include attempt (more info ...)web-application-attack 2007-5014 3397  
31419SERVER-WEBAPP PHPMyAdmin file inclusion arbitrary command execution attempt (more info ...)web-application-attack 2001-0478 2642  
31425SERVER-WEBAPP PHP Simple Shop abs_path parameter PHP remote file include attempt (more info ...)web-application-attack 2006-4052   URL
31426SERVER-WEBAPP Jevontech PHPenpals PersonalID SQL injection attempt (more info ...)attempted-admin 2006-0074 16109  
31460SERVER-WEBAPP PHP DNS parsing heap overflow attempt (more info ...)web-application-attack 2014-4049   URL
31546SERVER-WEBAPP Ultimate PHP Board admin_iplog remote code execution attempt (more info ...)attempted-user 2003-0395 7678  
31565SERVER-WEBAPP Flashchat aedatingCMS2.php remote file include attempt (more info ...)web-application-activity 2006-4583 19826  
31566SERVER-WEBAPP Flashchat aedatingCMS.php remote file include attempt (more info ...)web-application-activity 2006-4583 19826  
31569SERVER-WEBAPP Tiki Wiki 8.3 unserialize PHP remote code execution attempt (more info ...)web-application-attack 2012-0911 54298  
31638SERVER-WEBAPP Voodoo Chat index.php remote include path attempt (more info ...)web-application-attack 2006-3991 19277  
31672MALWARE-CNC Inbound command to php based DoS bot (more info ...)trojan-activity    
31730SERVER-WEBAPP Symantec Web Gateway dbutils.php SQL injection attempt (more info ...)web-application-attack 2014-1651 67754  
31731SERVER-WEBAPP Symantec Web Gateway dbutils.php SQL injection attempt (more info ...)web-application-attack 2014-1651 67754  
31886SERVER-WEBAPP WebEdition captchaMemory.class PHP code injection attempt (more info ...)web-application-attack    URL
31945SERVER-WEBAPP PhpWiki Ploticus plugin command injection attempt (more info ...)web-application-attack 2014-5519 69444  
32014SERVER-WEBAPP GetSimpleCMS arbitrary PHP code execution attempt (more info ...)attempted-admin    
32268SERVER-WEBAPP PineApp Mail-SeCure confpremenu.php install license command injection attempt (more info ...)attempted-admin  61475  
32581SERVER-WEBAPP Mantis Bug Tracker XmlImportExport plugin PHP code injection attempt (more info ...)attempted-admin 2014-7146 70993  
32582SERVER-WEBAPP Mantis Bug Tracker XmlImportExport plugin PHP code injection attempt (more info ...)attempted-admin 2014-7146 70993  
32735MALWARE-CNC Win.Trojan.CryptoPHP variant outbound connection (more info ...)trojan-activity    URL
32736MALWARE-CNC Win.Trojan.CryptoPHP variant outbound connection (more info ...)trojan-activity    URL
32885SERVER-WEBAPP Enalean Tuleap PHP unserialize code execution attempt (more info ...)attempted-admin 2014-8791 71335  
32886SERVER-WEBAPP Enalean Tuleap PHP unserialize code execution attempt (more info ...)attempted-admin 2014-8791 71335  
32891MALWARE-CNC Php.Malware.SoakSoakRedirect Malware traffic containing WordPress Administrator credentials (more info ...)attempted-user    URL
33294SERVER-WEBAPP phpBB viewtopic double URL encoding attempt (more info ...)web-application-attack 2004-1315   
33440SERVER-WEBAPP WordPress EasyCart PHP code execution attempt (more info ...)web-application-attack 2014-9308 71983  
33514SERVER-WEBAPP WordPress Photo Gallery PHP code execution attempt (more info ...)attempted-admin 2014-9312   
33632SERVER-WEBAPP PHP xmlrpc.php command injection attempt (more info ...)attempted-admin 2005-1921 14088  
33676SERVER-WEBAPP Symantec Web Gateway restore.php command injection attempt (more info ...)web-application-attack 2014-7285 71620  
33682SERVER-OTHER PHP unserialize use after free attempt (more info ...)attempted-user 2014-8142   
33683SERVER-OTHER PHP unserialize use after free attempt (more info ...)attempted-user 2014-8142   
33685SERVER-OTHER PHPMoAdmin remote code execution attempt (more info ...)attempted-admin 2015-2208   URL
33960SERVER-OTHER PHP unserialize code execution attempt (more info ...)attempted-admin 2015-0231   
33961SERVER-OTHER PHP unserialize code execution attempt (more info ...)attempted-admin 2015-0231   
34027SERVER-OTHER PHP 4 unserialize ZVAL Reference Counter Overflow attempt (more info ...)attempted-admin 2007-1286   
34053SERVER-OTHER PHP unserialize and __wakeup use after free attempt (more info ...)attempted-user 2015-2787   
34054SERVER-OTHER PHP unserialize and __wakeup use after free attempt (more info ...)attempted-user 2015-2787   
34123SERVER-WEBAPP PHP php_date.c DateTimeZone data user after free attempt (more info ...)web-application-attack 2015-0273 72701  URL
34124SERVER-WEBAPP PHP php_date.c DateTimeZone data user after free attempt (more info ...)web-application-attack 2015-0273 72701  URL
34213SERVER-WEBAPP WordPress overly large password class-phpass.php denial of service attempt (more info ...)attempted-dos 2014-9034   
34238SERVER-OTHER PHP zip_cdir_new function integer overflow file upload attempt (more info ...)attempted-user 2015-2331   
34239SERVER-OTHER PHP zip_cdir_new function integer overflow file upload attempt (more info ...)attempted-user 2015-2331   
34373SERVER-OTHER PHP zip_cdir_new function integer overflow file download attempt (more info ...)attempted-user 2015-2331   
34374SERVER-OTHER PHP zip_cdir_new function integer overflow file download attempt (more info ...)attempted-user 2015-2331   
34375SERVER-OTHER PHP zip_cdir_new function integer overflow file download attempt (more info ...)attempted-user 2015-2331   
34376SERVER-OTHER PHP zip_cdir_new function integer overflow file download attempt (more info ...)attempted-user 2015-2331   
34623SERVER-WEBAPP PHP unserialize function integer overflow attempt (more info ...)attempted-admin 2014-3669   URL
34710SERVER-OTHER PHP unserialize datetimezone object code execution attempt (more info ...)attempted-admin 2015-0273   
34951SERVER-OTHER PHP DateTime object timezone type confusion attempt (more info ...)attempted-admin 2015-0273   URL
34983SERVER-WEBAPP PHP SoapClient __call method type confusion attempt (more info ...)attempted-user 2015-4147   URL
35006SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
35007SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
35008SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
35009SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
35010SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
35011SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
35040SERVER-WEBAPP PHP php_parse_metadata heap corruption attempt (more info ...)attempted-dos 2015-3307   
35041SERVER-WEBAPP PHP php_parse_metadata heap corruption attempt (more info ...)attempted-dos 2015-3307   
35092SERVER-OTHER PHP core compressed file temp_len buffer overflow attempt (more info ...)attempted-admin 2015-3329   
35093SERVER-OTHER PHP core compressed file temp_len buffer overflow attempt (more info ...)attempted-admin 2015-3329   
35310SERVER-WEBAPP Centreon getStats.php command injection attempt (more info ...)web-application-attack 2015-1561 75605  
35311SERVER-WEBAPP Centreon getStats.php command injection attempt (more info ...)web-application-attack 2015-1561 75605  
35372SERVER-WEBAPP WebUI mainfile.php command injection attempt (more info ...)web-application-attack    
35373SERVER-WEBAPP WebUI mainfile.php command injection attempt (more info ...)web-application-attack    
35374SERVER-WEBAPP WebUI mainfile.php command injection attempt (more info ...)web-application-attack    
35375SERVER-WEBAPP WebUI mainfile.php command injection attempt (more info ...)web-application-attack    
35399SERVER-WEBAPP WordPress MailChimp Subscribe Forms PHP Code Execution command injection attempt (more info ...)web-application-attack    
35704SERVER-WEBAPP Maarch LetterBox arbitrary PHP file upload attempt (more info ...)attempted-admin 2015-1587 72621  
35846SERVER-WEBAPP Navis DocumentCloud WordPress plugin window.php cross site scripting attempt (more info ...)attempted-user 2015-2807   
35853SERVER-WEBAPP PHP exif_ifd_make_value thumbnail heap buffer overflow attempt (more info ...)attempted-dos 2014-3670   
35854SERVER-WEBAPP PHP exif_ifd_make_value thumbnail heap buffer overflow attempt (more info ...)attempted-dos 2014-3670   
35855SERVER-WEBAPP PHP exif_ifd_make_value thumbnail heap buffer overflow attempt (more info ...)attempted-dos 2014-3670   
35856SERVER-WEBAPP PHP exif_ifd_make_value thumbnail heap buffer overflow attempt (more info ...)attempted-dos 2014-3670   
35940SERVER-WEBAPP PHP phar_parse_tarfile method integer overflow attempt (more info ...)attempted-user 2015-4021 74700  URL
36059SERVER-WEBAPP PHP CDF file handling infinite loop dos attempt (more info ...)attempted-dos 2014-0238 67765  URL
36261SERVER-WEBAPP PHP fileinfo cdf_read_property_info denial of service attempt (more info ...)attempted-dos 2014-3587 69325  URL
36262SERVER-WEBAPP PHP fileinfo cdf_read_property_info denial of service attempt (more info ...)attempted-dos 2014-3587 69325  URL
36449SERVER-WEBAPP Wordpress xmlrpc.php multiple failed authentication response (more info ...)web-application-attack    
36594SERVER-WEBAPP OpenEMR globals.php authentication bypass attempt (more info ...)attempted-user 2015-4453 75299  URL
36595SERVER-WEBAPP OpenEMR globals.php authentication bypass attempt (more info ...)attempted-user 2015-4453 75299  URL
36638SERVER-WEBAPP WordPress Font Plugin AjaxProxy.php absolute path traversal attempt (more info ...)attempted-recon 2015-7683   
37038SERVER-WEBAPP HumHub index.php from parameter SQL injection attempt (more info ...)web-application-attack    URL
37444SERVER-WEBAPP Roundcube Webmail index.php _skin directory traversal attempt (more info ...)web-application-attack 2015-8770   URL
37941SERVER-WEBAPP AlienVault OSSIM a_deployment.php command injection attempt (more info ...)attempted-admin    URL
37942SERVER-WEBAPP AlienVault OSSIM a_deployment.php command injection attempt (more info ...)attempted-admin    URL
37943SERVER-WEBAPP AlienVault OSSIM a_deployment.php command injection attempt (more info ...)attempted-admin    URL
38012SERVER-WEBAPP Alienvault OSSIM graph_geoloc.php SQL injection attempt (more info ...)web-application-attack    
38049SERVER-WEBAPP Centreon Web Interface index.php command injection attempt (more info ...)web-application-attack    URL
38236SERVER-WEBAPP Wordpress MM Forms community plugin arbitrary PHP file upload attempt (more info ...)attempted-admin 2012-3574 53852  
38371SERVER-WEBAPP Bharat Mediratta Gallery PHP file inclusion attempt (more info ...)attempted-admin 2002-1412 5375  
38512SERVER-WEBAPP ATutor question_import.php directory traversal attempt (more info ...)web-application-attack    URL
38513SERVER-WEBAPP ATutor question_import.php directory traversal attempt (more info ...)web-application-attack    URL
38609SERVER-WEBAPP pfSense status_rrd_graph_img.php command injection attempt (more info ...)web-application-attack    URL
38675SERVER-WEBAPP Sefrengo CMS main.php SQL injection attempt (more info ...)web-application-attack 2015-0919 71885  
38753MALWARE-CNC 1.php outbound connection attempt (more info ...)trojan-activity    
38807SERVER-WEBAPP PHP-Address remote file include attempt (more info ...)web-application-attack 2002-0953 5039  
39324SERVER-WEBAPP Bomgar Remote Support session_complete PHP object injection attempt (more info ...)web-application-attack 2015-0935 74460  
39325SERVER-WEBAPP Bomgar Remote Support session_complete PHP object injection attempt (more info ...)web-application-attack 2015-0935 74460  
39353SERVER-WEBAPP WolfCMS file_manager arbitrary PHP file upload attempt (more info ...)attempted-admin 2015-6568   URL
39363SERVER-WEBAPP Riverbed SteelCentral NetProfiler index.php command injection attempt (more info ...)web-application-attack    URL
39364SERVER-WEBAPP Riverbed SteelCentral NetProfiler index.php command injection attempt (more info ...)web-application-attack    URL
39365SERVER-WEBAPP Riverbed SteelCentral NetProfiler popup.php command injection attempt (more info ...)web-application-attack    URL
39366SERVER-WEBAPP Riverbed SteelCentral NetProfiler popup.php command injection attempt (more info ...)web-application-attack    URL
39456SERVER-WEBAPP NAS4Free txtPHPCommand remote code execution attempt (more info ...)attempted-admin 2013-3631 63448  URL
39590SERVER-WEBAPP TikiWiki elFinder component arbitrary PHP file upload attempt (more info ...)attempted-admin    URL
39662SERVER-WEBAPP PHP phar extension remote code execution attempt (more info ...)attempted-user 2016-4072   URL
39714SERVER-WEBAPP phpFileManager command injection attempt (more info ...)web-application-attack    URL
39715SERVER-WEBAPP phpFileManager command injection attempt (more info ...)web-application-attack    URL
39716SERVER-WEBAPP phpFileManager command injection attempt (more info ...)web-application-attack    URL
39717SERVER-WEBAPP phpFileManager command injection attempt (more info ...)web-application-attack    URL
39733SERVER-WEBAPP InBoundio Marketing for Wordpress plugin PHP file upload attempt (more info ...)attempted-admin    URL
40038SERVER-WEBAPP PHP unserialize var_hash use-after-free attempt (more info ...)attempted-user 2016-6290   URL
40046SERVER-OTHER PHP locale_accept_from_http out of bounds read attempt (more info ...)web-application-attack 2016-6294   URL
40243FILE-IMAGE PHP exif_process_user_comment null pointer dereference attempt (more info ...)attempted-user 2016-6292   URL
40244FILE-IMAGE PHP exif_process_user_comment null pointer dereference attempt (more info ...)attempted-user 2016-6292   URL
40245FILE-IMAGE PHP exif_process_user_comment null pointer dereference attempt (more info ...)attempted-user 2016-6292   URL
40246FILE-IMAGE PHP exif_process_user_comment null pointer dereference attempt (more info ...)attempted-user 2016-6292   URL
40247FILE-IMAGE PHP exif_process_user_comment null pointer dereference attempt (more info ...)attempted-user 2016-6292   URL
40248FILE-IMAGE PHP exif_process_user_comment null pointer dereference attempt (more info ...)attempted-user 2016-6292   URL
40256SERVER-WEBAPP Idera Up.Time Monitoring Station post2file.php arbitrary PHP file upload attempt (more info ...)attempted-admin  64031  
40294FILE-IMAGE PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt (more info ...)attempted-user 2016-6291   URL
40295FILE-IMAGE PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt (more info ...)attempted-user 2016-6291   URL
40296FILE-IMAGE PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt (more info ...)attempted-user 2016-6291   URL
40297FILE-IMAGE PHP exif_process_IFD_in_MAKERNOTE out of bounds read attempt (more info ...)attempted-user 2016-6291   URL
41355SERVER-WEBAPP WordPress Admin API ajax-actions.php directory traversal attempt (more info ...)web-application-attack 2016-6897 92573  
41383SERVER-WEBAPP PHP ZipArchive getFromIndex and getFromName integer overflow attempt (more info ...)attempted-admin 2016-3078   URL
41384SERVER-WEBAPP PHP ZipArchive getFromIndex and getFromName integer overflow attempt (more info ...)attempted-admin 2016-3078   URL
41404SERVER-WEBAPP Joomla JCE multiple plugin arbitrary PHP file upload attempt (more info ...)attempted-user    URL
41430SERVER-WEBAPP PHP unserialize function use after free memory corruption vulnerability attempt (more info ...)attempted-admin 2016-7479   URL
41431SERVER-WEBAPP PHP unserialize function use after free memory corruption vulnerability attempt (more info ...)attempted-admin 2016-7479   URL
41432SERVER-WEBAPP PHP unserialize function use after free memory corruption vulnerability attempt (more info ...)attempted-admin 2016-7479   URL
41433SERVER-WEBAPP PHP unserialize function use after free memory corruption vulnerability attempt (more info ...)attempted-admin 2016-7479   URL
41643SERVER-WEBAPP Wordpress xmlrpc.php multiple failed authentication response (more info ...)web-application-attack    
41647POLICY-OTHER Piwik Analytics Platform PHP plugin installation detected (more info ...)policy-violation    URL
41689SERVER-OTHER PHP Exception Handling remote denial of service attempt (more info ...)attempted-admin 2016-7478   
41690SERVER-OTHER PHP Exception Handling remote denial of service attempt (more info ...)attempted-admin 2016-7478   
41845SERVER-WEBAPP pfSense status_rrd_graph_img.php command injection via CSRF attempt (more info ...)web-application-attack    URL
42289INDICATOR-SCAN PHP info leak attempt (more info ...)attempted-recon    URL
42451SERVER-WEBAPP MCA Sistemas ScadaBR index.php brute force login attempt (more info ...)web-application-attack    URL
43066SERVER-WEBAPP Trend Micro Control Manager importFile.php directory traversal attempt (more info ...)web-application-attack    URL
43244SERVER-WEBAPP Active Calendar showcode.php directory traversal attempt (more info ...)web-application-attack 2007-1110   
43245SERVER-WEBAPP Active Calendar showcode.php directory traversal attempt (more info ...)web-application-attack 2007-1110   
43246SERVER-WEBAPP Active Calendar showcode.php directory traversal attempt (more info ...)web-application-attack 2007-1110   
43329SERVER-WEBAPP AssetMan download_pdf.php directory traversal attempt (more info ...)web-application-attack 2007-1427   
43330SERVER-WEBAPP AssetMan download_pdf.php directory traversal attempt (more info ...)web-application-attack 2007-1427   
43331SERVER-WEBAPP AssetMan download_pdf.php directory traversal attempt (more info ...)web-application-attack 2007-1427   
43365SERVER-WEBAPP Wordpress Complete Gallery Manager arbitrary PHP file upload attempt (more info ...)attempted-admin 2013-5962   
43653SERVER-WEBAPP Pheap edit.php directory traversal attempt (more info ...)web-application-attack 2007-1140   
43654SERVER-WEBAPP Pheap edit.php directory traversal attempt (more info ...)web-application-attack 2007-1140   
43655SERVER-WEBAPP Pheap edit.php directory traversal attempt (more info ...)web-application-attack 2007-1140   
43668SERVER-WEBAPP PHP core unserialize use after free attempt (more info ...)attempted-user 2014-8142   
43680SERVER-WEBAPP phpSecurePages secure.php remote file include attempt (more info ...)web-application-attack 2001-1468   
43681SERVER-WEBAPP phpSecurePages secure.php remote file include attempt (more info ...)web-application-attack 2001-1468   
43691SERVER-WEBAPP Ultimate Fun Book function.php remote file include attempt (more info ...)web-application-attack 2007-1059   
43718SERVER-WEBAPP Site-Assistant menu.php remote file include attempt (more info ...)web-application-attack 2007-0867 22467  
43719SERVER-WEBAPP Site-Assistant menu.php remote file include attempt (more info ...)web-application-attack 2007-0867 22467  
43756SERVER-WEBAPP Coppermine Photo Gallery thumbnails.php SQL injection attempt (more info ...)web-application-attack 2007-1107 22709  
44001SERVER-WEBAPP PHP malformed quoted printable denial of service attempt (more info ...)denial-of-service 2013-2110   
44390SERVER-WEBAPP PHP form-based file upload DoS attempt (more info ...)denial-of-service 2015-4024   
44644SERVER-WEBAPP pSys index.php shownews parameter SQL injection attempt (more info ...)web-application-attack 2008-5269   
44645SERVER-WEBAPP pSys index.php shownews parameter SQL injection attempt (more info ...)web-application-attack 2008-5269   
44744SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
44745SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
44746SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
44747SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
44748SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
44749SERVER-WEBAPP PHP unserialize call SPL ArrayObject and SPLObjectStorage memory corruption attempt (more info ...)attempted-user 2014-3515   
44765SERVER-WEBAPP CMS Made Simple addgroup.php cross site scripting attempt (more info ...)attempted-user    URL
44766SERVER-WEBAPP CMS Made Simple addgroup.php cross site scripting attempt (more info ...)attempted-user    URL
44975MALWARE-CNC Php.Dropper.Mayhem variant outbound connection (more info ...)trojan-activity    URL
45372SERVER-WEBAPP Trend Micro Smart Protection Server admin_update_program.php command injection attempt (more info ...)web-application-attack 2017-14094 102275  URL
45406SERVER-WEBAPP Possible Phpmyadmin CSRF exploitation attempt (more info ...)policy-violation 2017-1000499   
45456SERVER-WEBAPP Samsung SRN-1670D network_ssl_upload.php arbitrary PHP file upload attempt (more info ...)attempted-admin 2017-16524   URL
45457SERVER-WEBAPP Samsung SRN-1670D cslog_export.php arbitrary file read attempt (more info ...)attempted-recon 2015-8279   URL
45676SERVER-WEBAPP PHP php_mime_split multipart file upload buffer overflow attempt (more info ...)attempted-user 2002-0081   
45768SERVER-WEBAPP PHP unserialize integer overflow attempt (more info ...)attempted-admin 2017-5340 95371  
45769SERVER-WEBAPP PHP unserialize integer overflow attempt (more info ...)attempted-admin 2017-5340 95371  
45914INDICATOR-COMPROMISE PHP phpinfo command execution attempt (more info ...)web-application-attack    
45915INDICATOR-COMPROMISE PHP obfuscated eval command execution attempt (more info ...)web-application-attack    URL
45916INDICATOR-COMPROMISE PHP shell_exec command execution attempt (more info ...)web-application-attack    
46315SERVER-WEBAPP Joomla restore.php PHP object injection attempt (more info ...)web-application-attack 2014-7228   
46340SERVER-WEBAPP Akeeba Kickstart restoration.php reconnaissance attempt (more info ...)web-application-attack 2014-7229   
46347SERVER-WEBAPP MediaWiki index.php rs cross site scripting attempt (more info ...)attempted-user 2007-0177   
46469SERVER-WEBAPP PHP unserialize integer overflow attempt (more info ...)attempted-admin 2017-5340 95371  
46470SERVER-WEBAPP PHP unserialize integer overflow attempt (more info ...)attempted-admin 2017-5340 95371  
46808SERVER-WEBAPP PHP .phar cross site scripting attempt (more info ...)attempted-user 2018-5712 104020  
47045SERVER-WEBAPP phpMyAdmin preg_replace null byte injection attempt (more info ...)web-application-attack 2016-5734   URL
47046SERVER-WEBAPP phpMyAdmin preg_replace null byte injection attempt (more info ...)web-application-attack 2016-5734   URL
47155SERVER-WEBAPP PHP unserialize integer overflow attempt (more info ...)attempted-admin 2017-5340 95371  
47156SERVER-WEBAPP PHP unserialize integer overflow attempt (more info ...)attempted-admin 2017-5340 95371  
47207SERVER-WEBAPP PHP phar extension remote code execution attempt (more info ...)attempted-user 2016-4072   URL
47537SERVER-WEBAPP Bacula-Web client-report.php SQL injection attempt (more info ...)web-application-attack 2017-15367   
47538SERVER-WEBAPP Bacula-Web jobs.php SQL injection attempt (more info ...)web-application-attack 2017-15367   
47539SERVER-WEBAPP Bacula-Web jobs.php SQL injection attempt (more info ...)web-application-attack 2017-15367   
47540SERVER-WEBAPP Bacula-Web client-report.php SQL injection attempt (more info ...)web-application-attack 2017-15367   
47768SERVER-WEBAPP ClipBucket beats_uploader arbitrary PHP file upload attempt (more info ...)attempted-admin 2018-7665   
47769SERVER-WEBAPP ClipBucket photo_uploader arbitrary PHP file upload attempt (more info ...)attempted-admin 2018-7665   
47770SERVER-WEBAPP ClipBucket edit_account arbitrary PHP file upload attempt (more info ...)attempted-admin 2018-7665   
48029SERVER-MAIL PHPMailer information disclosure attempt (more info ...)attempted-recon 2017-5223   URL
48486SERVER-WEBAPP Wordpress Portable phpMyAdmin plugin authentication bypass attempt (more info ...)web-application-attack 2012-5469   URL
49184INDICATOR-COMPROMISE PEAR Archive_Tar PHP object injection attempt (more info ...)web-application-attack 2018-1000888   URL
49185INDICATOR-COMPROMISE PEAR Archive_Tar PHP object injection attempt (more info ...)web-application-attack 2018-1000888   URL
49207MALWARE-CNC PHP.PEAR.Backdoor malicious script download attempt (more info ...)trojan-activity    URL
49208MALWARE-CNC PHP.PEAR.Backdoor malicious script download attempt (more info ...)trojan-activity    URL
50171MALWARE-CNC Php.Webshell.Backdoor inbound connection attempt (more info ...)trojan-activity    URL
51138SERVER-WEBAPP PHP phpinfo function cross site scripting attempt (more info ...)web-application-attack    
51139SERVER-WEBAPP PHP phpinfo function cross site scripting attempt (more info ...)web-application-attack    
51239SERVER-OTHER PHP-Proxy local file include attempt (more info ...)web-application-attack 2018-19246   
51262SERVER-WEBAPP TinyPHPForum action.php cross site scripting attempt (more info ...)attempted-user 2006-0102   
51263SERVER-WEBAPP TinyPHPForum action.php cross site scripting attempt (more info ...)attempted-user 2006-0102   
51273SERVER-WEBAPP Modx Revolution PHP code injection attempt (more info ...)web-application-attack 2018-1000207   URL
51274SERVER-WEBAPP Modx Revolution PHP code injection attempt (more info ...)web-application-attack 2018-1000207   URL
51278SERVER-WEBAPP SolusLabs SolusVM centralbackup.php SQL injection attempt (more info ...)web-application-attack    URL
51279SERVER-WEBAPP SolusLabs SolusVM centralbackup.php SQL injection attempt (more info ...)web-application-attack    URL
51280SERVER-WEBAPP SolusLabs SolusVM centralbackup.php SQL injection attempt (more info ...)web-application-attack    URL
51923INDICATOR-OBFUSCATION Possible PHP eval backdoor upload attempt (more info ...)web-application-attack    URL
52265SERVER-WEBAPP phpMyAdmin delete server cross-site request forgery attempt (more info ...)web-application-attack 2019-12922   
52266SERVER-WEBAPP phpMyAdmin direct access server deletion attempt (more info ...)web-application-attack 2019-12922   
52267SERVER-WEBAPP phpMyAdmin delete server cross-site request forgery attempt (more info ...)web-application-attack 2019-12922   
52454SERVER-WEBAPP PHP malformed quoted printable denial of service attempt (more info ...)denial-of-service 2013-2110   
53120SERVER-WEBAPP Wordpress DreamworkGallery plugin arbitrary PHP file upload attempt (more info ...)web-application-attack    URL
53649INDICATOR-COMPROMISE PHP eval command execution attempt (more info ...)web-application-attack    
55648INDICATOR-SCAN Drupal PHP remote debug attempt (more info ...)web-application-activity    
57415SERVER-WEBAPP Adobe Magento DownloadCss.php cross site scripting attempt (more info ...)attempted-user 2021-21029   
57578SERVER-OTHER PHP DateTime object timezone type confusion attempt (more info ...)attempted-admin 2015-0273   URL
57942MALWARE-CNC Php.Webshell.C99 inbound connection attempt (more info ...)trojan-activity    URL
57943MALWARE-CNC Php.Webshell.C99 inbound connection attempt (more info ...)trojan-activity    URL
57944MALWARE-CNC Php.Webshell.C99 inbound connection attempt (more info ...)trojan-activity    URL
57945MALWARE-CNC Php.Webshell.C99 inbound connection attempt (more info ...)trojan-activity    URL
57946MALWARE-CNC Php.Webshell.C99 inbound connection attempt (more info ...)trojan-activity    URL
57947MALWARE-CNC Php.Webshell.C99 inbound connection attempt (more info ...)trojan-activity    URL
58334SERVER-WEBAPP Schneider Electric Umotion Builder Virtual Appliance arbitrary PHP file upload attempt (more info ...)attempted-admin    
58652SERVER-WEBAPP Schneider Electric Umotion Builder Virtual Appliance Editscript PHP code injection attempt (more info ...)web-application-attack    
58653SERVER-WEBAPP Schneider Electric Umotion Builder Virtual Appliance Editscript PHP code injection attempt (more info ...)web-application-attack    
58702MALWARE-CNC Php.Webshell.PhpJackal outbound connection attempt (more info ...)trojan-activity    URL
58963SERVER-WEBAPP Aviatrix Controller PHP file injection attempt (more info ...)web-application-attack 2021-40870   
58964SERVER-WEBAPP Aviatrix Controller PHP file injection attempt (more info ...)web-application-attack 2021-40870   
58965SERVER-WEBAPP Aviatrix Controller PHP file injection attempt (more info ...)web-application-attack 2021-40870   
59024MALWARE-CNC Php.Webshell.Antichat outbound connection attempt (more info ...)trojan-activity    URL
59035MALWARE-OTHER Php.Webshell.AK74 inbound connection attempt (more info ...)trojan-activity    URL
59037MALWARE-OTHER Php.Webshell.AK74 inbound connection attempt (more info ...)trojan-activity    URL
59038MALWARE-OTHER Php.Webshell.AK74 inbound connection attempt (more info ...)trojan-activity    URL
59039MALWARE-OTHER Php.Webshell.AK74 inbound connection attempt (more info ...)trojan-activity    URL
59040MALWARE-OTHER Php.Webshell.AK74 inbound connection attempt (more info ...)trojan-activity    URL
59041MALWARE-OTHER Php.Webshell.AK74 inbound connection attempt (more info ...)trojan-activity    URL
59042MALWARE-OTHER Php.Webshell.AK74 inbound connection attempt (more info ...)trojan-activity    URL
59043MALWARE-OTHER Php.Webshell.AK74 inbound connection attempt (more info ...)trojan-activity    URL
59091MALWARE-OTHER Php.Webshell.Azrail inbound connection attempt (more info ...)trojan-activity    URL
59219MALWARE-OTHER Php.Webshell.C99Madnet inbound connection attempt (more info ...)trojan-activity    URL
59259MALWARE-OTHER Php.Webshell.Bypass inbound connection attempt (more info ...)trojan-activity    URL
59266MALWARE-OTHER Php.Webshell.C0ders inbound connection attempt (more info ...)trojan-activity    URL
59536SERVER-WEBAPP YouPHPTube getSpiritsFromVideo.php command injection attempt (more info ...)web-application-attack 2019-5129   URL
59617PROTOCOL-DNS PHP dns_get_record out of bounds read attempt (more info ...)attempted-user 2019-9022   
59699SERVER-WEBAPP Magento PHP object injection attempt (more info ...)web-application-attack 2016-4010   
59859PROTOCOL-DNS PHP dns_get_record out of bounds read attempt (more info ...)attempted-user 2019-9022   
60337MALWARE-CNC Php.Webshell.DiveShell inbound connection attempt (more info ...)trojan-activity    URL
60338MALWARE-CNC Php.Webshell.DiveShell outbound connection attempt (more info ...)trojan-activity    URL
60401MALWARE-CNC Php.Webshell.DToolPro inbound connection attempt (more info ...)trojan-activity    URL
60402MALWARE-CNC Php.Webshell.DToolPro outbound connection attempt (more info ...)trojan-activity    URL
60496MALWARE-CNC Php.Webshell.Exoshell inbound connection attempt (more info ...)trojan-activity    URL
60497MALWARE-CNC Php.Webshell.Exoshell inbound connection attempt (more info ...)trojan-activity    URL
60498MALWARE-CNC Php.Webshell.Exoshell outbound connection attempt (more info ...)trojan-activity    URL
60632SERVER-WEBAPP WordPress Property Plugin arbitrary PHP file upload attempt (more info ...)attempted-admin    URL
60825MALWARE-CNC Php.Webshell.GReatPost inbound connection attempt (more info ...)trojan-activity    URL
61043MALWARE-CNC Php.Webshell.H4ntu outbound connection attempt (more info ...)trojan-activity    URL
61083MALWARE-CNC Php.Webshell.IronShell outbound connection (more info ...)trojan-activity    URL
61435MALWARE-OTHER Php.Webshell.Generic file delivery attempt (more info ...)attempted-user    
61436MALWARE-OTHER Php.Webshell.Generic file delivery attempt (more info ...)attempted-user    
61437MALWARE-OTHER Php.Webshell.Generic file delivery attempt (more info ...)attempted-user    
61438MALWARE-OTHER Php.Webshell.Generic file delivery attempt (more info ...)attempted-user    
61439MALWARE-OTHER Php.Webshell.Generic file delivery attempt (more info ...)attempted-user    
61440MALWARE-OTHER Php.Webshell.Generic file delivery attempt (more info ...)attempted-user    
61441MALWARE-OTHER Php.Webshell.Generic file delivery attempt (more info ...)attempted-user    
61442MALWARE-OTHER Php.Webshell.Generic file delivery attempt (more info ...)attempted-user    
61493MALWARE-CNC Php.Webshell.Agent outbound connection (more info ...)trojan-activity    URL
61494MALWARE-CNC Php.Webshell.Agent outbound connection (more info ...)trojan-activity    URL
62057MALWARE-CNC Php.Webshell.AntSword inbound connection (more info ...)trojan-activity    URL

 goto Top

Group: Server / HTTP / CGI

# of attack rules in this group: 211

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1547SERVER-WEBAPP csSearch.cgi arbitrary command execution attempt (more info ...)web-application-attack  2002-0495  4368  10924  
1548SERVER-WEBAPP csSearch.cgi access (more info ...)web-application-activity  2002-0495  4368  10924  
13161SERVER-OTHER HP OpenView CGI parameter buffer overflow attempt (more info ...)attempted-user  2008-0067  26741    
13656SERVER-WEBAPP Cisco Secure Access Control Server UCP Application CSuserCGI.exe buffer overflow attempt (more info ...)attempted-admin  2008-0532  28222    URL
15510SERVER-OTHER Trend Micro OfficeScan Server cgiRecvFile overflow attempt (more info ...)attempted-admin  2008-2437  31139    
15908SERVER-WEBAPP Trend Micro OfficeScan multiple CGI modules HTTP form processing buffer overflow attempt (more info ...)attempted-admin  2008-3862      
16674SERVER-WEBAPP HP OpenView CGI parameter buffer overflow attempt (more info ...)attempted-user  2011-3167      
18579SERVER-WEBAPP HP OpenView Network Node Manager OpenView5 CGI buffer overflow attempt (more info ...)attempted-user  2008-0067  33147    
19137SERVER-WEBAPP HP OpenView NNM getnnmdata.exe CGI ICount parameter buffer overflow attempt (more info ...)attempted-user  2010-1554      
19138SERVER-WEBAPP HP OpenView NNM getnnmdata.exe CGI hostname parameter buffer overflow attempt (more info ...)attempted-admin  2010-1555  40072    URL
19139SERVER-WEBAPP HP OpenView NNM getnnmdata.exe CGI MaxAge parameter buffer overflow attempt (more info ...)attempted-user  2010-1553      
19140SERVER-WEBAPP HP OpenView NNM snmpviewer.exe CGI parameter buffer overflow attempt (more info ...)attempted-user  2010-1552      
20177SERVER-WEBAPP HP OpenView NNM ovlogin.exe CGI Host parameter buffer overflow attempt (more info ...)attempted-user  2009-4180      URL
20240SERVER-WEBAPP HP OpenView NNM nnmRptConfig.exe CGI Host parameter buffer overflow attempt (more info ...)attempted-user  2009-3848      URL
20241SERVER-WEBAPP HP OpenView NNM snmp.exe CGI Host parameter buffer overflow attempt (more info ...)attempted-user  2009-3849      URL
21850MALWARE-OTHER TDS Sutra - request hi.cgi (more info ...)trojan-activity        URL
24693SERVER-WEBAPP HP OpenView CGI parameter buffer overflow attempt (more info ...)attempted-user  2011-3167      
26275SERVER-WEBAPP DD-WRT httpd cgi-bin remote command execution attempt (more info ...)attempted-admin  2016-6277  94819    
28052SERVER-WEBAPP Linksys WRT110 ping.cgi remote command execution attempt (more info ...)attempted-admin  2013-3568  61151    
29401SERVER-WEBAPP Netgear DGN1000B setup.cgi parameter code execution attempt (more info ...)attempted-user    57836    
29402SERVER-WEBAPP Netgear DGN1000B setup.cgi parameter code execution attempt (more info ...)attempted-user    57836    
29403SERVER-WEBAPP Netgear DGN1000B setup.cgi cross site scripting attempt (more info ...)web-application-attack    57836    
29502SERVER-WEBAPP HP OpenView CGI parameter buffer overflow attempt (more info ...)attempted-user  2011-3167      
29511SERVER-WEBAPP HP OpenView NNM jovgraph.exe CGI hostname parameter bugger overflow attempt (more info ...)attempted-user  2010-1555      
29992SERVER-WEBAPP Linksys WRT120N tmUnblock.cgi TM_Block_URL parameter fprintf stack buffer overflow attempt (more info ...)attempted-admin        URL
31148SERVER-WEBAPP Supermicro Intelligent Management Controller login.cgi buffer overflow attempt (more info ...)attempted-admin  2013-3621      
31149SERVER-WEBAPP Supermicro Intelligent Management Controller login.cgi buffer overflow attempt (more info ...)attempted-admin  2013-3621      
31210SERVER-WEBAPP Supermicro Intelligent Management Controller close_window.cgi buffer overflow attempt (more info ...)attempted-admin  2013-3623  63775    
31211SERVER-WEBAPP Supermicro Intelligent Management Controller close_window.cgi buffer overflow attempt (more info ...)attempted-admin  2013-3623  63775    
31375SERVER-WEBAPP Hp OpenView CGI parameter buffer overflow attempt (more info ...)attempted-user  2011-3166      URL
31975OS-OTHER Bash CGI environment variable injection attempt (more info ...)attempted-admin  2014-7169      
31977OS-OTHER Bash CGI environment variable injection attempt (more info ...)attempted-admin  2014-7169      
31978OS-OTHER Bash CGI environment variable injection attempt (more info ...)attempted-admin  2014-7169      
32047OS-OTHER Bash CGI nested loops word_lineno denial of service attempt (more info ...)attempted-dos  2014-7187      URL
32049OS-OTHER Bash CGI nested loops word_lineno denial of service attempt (more info ...)attempted-dos  2014-7187      URL
33984SERVER-WEBAPP D-Link DNS-345 Network Storage System system_mgr.cgi command injection attempt (more info ...)web-application-attack  2014-2691      
34220SERVER-WEBAPP Barracuda Networks Web Filter index.cgi command injection attempt (more info ...)web-application-attack        
34221SERVER-WEBAPP Barracuda Networks Web Filter index.cgi command injection attempt (more info ...)web-application-attack        
34222SERVER-WEBAPP Barracuda Networks Web Filter index.cgi command injection attempt (more info ...)web-application-attack        
35356SERVER-WEBAPP AirLink101 SkyIPCam snwrite.cgi command injection attempt (more info ...)web-application-attack  2015-2280  75597    
35357SERVER-WEBAPP AirLink101 SkyIPCam snwrite.cgi command injection attempt (more info ...)web-application-attack  2015-2280  75597    
36030SERVER-WEBAPP Synology Video Station subtitle.cgi command injection attempt (more info ...)web-application-attack        URL
36031SERVER-WEBAPP Synology Video Station subtitle.cgi command injection attempt (more info ...)web-application-attack        URL
36032SERVER-WEBAPP Synology Video Station subtitle.cgi command injection attempt (more info ...)web-application-attack        URL
36033SERVER-WEBAPP Synology Video Station subtitle.cgi command injection attempt (more info ...)web-application-attack        URL
36041SERVER-WEBAPP Synology Video Station watchstatus.cgi SQL injection attempt (more info ...)web-application-attack        URL
36042SERVER-WEBAPP Synology Video Station watchstatus.cgi SQL injection attempt (more info ...)web-application-attack        URL
36043SERVER-WEBAPP Synology Video Station watchstatus.cgi SQL injection attempt (more info ...)web-application-attack        URL
36049SERVER-WEBAPP Synology Video Station audiotrack.cgi SQL injection attempt (more info ...)web-application-attack        URL
36050SERVER-WEBAPP Synology Video Station audiotrack.cgi SQL injection attempt (more info ...)web-application-attack        URL
36051SERVER-WEBAPP Synology Video Station audiotrack.cgi SQL injection attempt (more info ...)web-application-attack        URL
36178SERVER-WEBAPP Endian Firewall Proxy chpasswd.cgi command injection attempt (more info ...)web-application-attack  2015-5082      
36181SERVER-WEBAPP Endian Firewall Proxy chpasswd.cgi command injection attempt (more info ...)web-application-attack  2015-5082      
37427SERVER-WEBAPP IP Camera /cgi-bin/admin/servetest command injection attempt (more info ...)web-application-attack  2013-2578      
37428SERVER-WEBAPP IP Camera /cgi-bin/admin/servetest command injection attempt (more info ...)web-application-attack  2013-2578      
37429SERVER-WEBAPP IP Camera /cgi-bin/admin/servetest command injection attempt (more info ...)web-application-attack  2013-2578      
37430SERVER-WEBAPP IP Camera /cgi-bin/admin/servetest command injection attempt (more info ...)web-application-attack  2013-2578      
37439SERVER-WEBAPP Cisco UCS Manager getkvmurl.cgi command injection attempt (more info ...)web-application-attack  2015-6435      URL
37440SERVER-WEBAPP Cisco UCS Manager getkvmurl.cgi command injection attempt (more info ...)web-application-attack  2015-6435      URL
37492SERVER-WEBAPP Cisco RV220 platform.cgi SQL injection attempt (more info ...)web-application-attack  2015-6319      URL
38269SERVER-WEBAPP Netgear ReadyNAS Surveillance cgi_system command injection attempt (more info ...)attempted-admin        URL
39790SERVER-WEBAPP Cisco RV180 VPN Router platform.cgi command injection attempt (more info ...)web-application-attack  2016-1430      URL
39791SERVER-WEBAPP Cisco RV180 VPN Router platform.cgi command injection attempt (more info ...)web-application-attack  2016-1430      URL
39792SERVER-WEBAPP Cisco RV180 VPN Router platform.cgi command injection attempt (more info ...)web-application-attack  2016-1430      URL
39793SERVER-WEBAPP Cisco RV180 VPN Router platform.cgi directory traversal attempt (more info ...)web-application-attack  2016-1429      URL
39794SERVER-WEBAPP Cisco RV180 VPN Router platform.cgi directory traversal attempt (more info ...)web-application-attack  2016-1429      URL
39897SERVER-WEBAPP Cisco FirePOWER Management Center sajaxintf.cgi command injection attempt (more info ...)attempted-admin  2016-1457      URL
39898SERVER-WEBAPP Cisco FirePOWER Management Center pjb.cgi privilege escalation attempt (more info ...)attempted-admin  2016-1458      URL
39978SERVER-WEBAPP Netgear ReadyNAS Surveillance cgi_main command injection attempt (more info ...)attempted-admin  2016-5679      URL
39979SERVER-WEBAPP Netgear ReadyNAS Surveillance cgi_main command injection attempt (more info ...)attempted-admin  2016-5679      URL
39980SERVER-WEBAPP Netgear ReadyNAS Surveillance cgi_main command injection attempt (more info ...)attempted-admin  2016-5679      URL
39981SERVER-WEBAPP Netgear ReadyNAS Surveillance cgi_main stack buffer overflow attempt (more info ...)attempted-admin  2016-5680      URL
39982SERVER-WEBAPP Netgear ReadyNAS Surveillance cgi_main stack buffer overflow attempt (more info ...)attempted-admin  2016-5680      URL
40447SERVER-WEBAPP Avtech IP Camera search.cgi command injection attempt (more info ...)attempted-admin        URL
40448SERVER-WEBAPP Avtech IP Camera search.cgi command injection attempt (more info ...)attempted-admin        URL
40994SERVER-WEBAPP Sony IPELA IP Cameras prima-factory.cgi telnet backdoor access attempt (more info ...)attempted-admin        URL
41032SERVER-WEBAPP Trend Micro hotfix_upload.cgi command injection attempt (more info ...)web-application-attack  2016-8588  91229    URL
41504SERVER-WEBAPP Netgear passwordrecovered.cgi insecure admin password disclosure attempt (more info ...)attempted-recon  2017-5521  95457    URL
41652SERVER-WEBAPP Geutebruck IP Camera testaction.cgi command injection attempt (more info ...)web-application-attack  2017-5174      URL
41653SERVER-WEBAPP Geutebruck IP Camera testaction.cgi command injection attempt (more info ...)web-application-attack  2017-5174      URL
41654SERVER-WEBAPP Geutebruck IP Camera testaction.cgi command injection attempt (more info ...)web-application-attack  2017-5174      URL
41693SERVER-WEBAPP Avtech IP Camera adcommand.cgi command execution attempt (more info ...)attempted-admin        URL
41694SERVER-WEBAPP Avtech IP Camera pwdgrp.cgi command injection attempt (more info ...)attempted-admin        URL
41695SERVER-WEBAPP Avtech IP Camera pwdgrp.cgi command injection attempt (more info ...)attempted-admin        URL
41696SERVER-WEBAPP Avtech IP Camera cloudsetup.cgi command execution attempt (more info ...)attempted-admin        URL
41697SERVER-WEBAPP Avtech IP Camera machine.cgi information disclosure attempt (more info ...)attempted-recon        URL
41698SERVER-WEBAPP Netgear DGN2200 ping.cgi command injection attempt (more info ...)web-application-attack  2017-6077      URL
41699SERVER-WEBAPP Netgear DGN2200 ping.cgi command injection attempt (more info ...)web-application-attack  2017-6077      URL
41700SERVER-WEBAPP Netgear DGN2200 ping.cgi command injection attempt (more info ...)web-application-attack  2017-6077      URL
41748SERVER-WEBAPP Netgear DGN2200 dnslookup.cgi command injection attempt (more info ...)web-application-attack  2017-6334      
41749SERVER-WEBAPP Netgear DGN2200 dnslookup.cgi command injection attempt (more info ...)web-application-attack  2017-6334      
41750SERVER-WEBAPP Netgear DGN2200 dnslookup.cgi command injection attempt (more info ...)web-application-attack  2017-6334      
41751SERVER-WEBAPP Netgear DGN2200 dnslookup.cgi command injection attempt (more info ...)web-application-attack  2017-6334      
42048SERVER-WEBAPP dnaLIMS sysAdmin.cgi arbitrary command execution attempt (more info ...)attempted-admin  2017-6526  96823    URL
42078SERVER-WEBAPP Foscam cgiproxy.fcgi stack buffer overflow attempt (more info ...)attempted-admin  2017-2805      URL
42234SERVER-WEBAPP QNAP NAS authLogin.cgi command injection attempt (more info ...)attempted-admin  2017-6361  97059    URL
42236SERVER-WEBAPP QNAP NAS userConfig.cgi command injection attempt (more info ...)web-application-attack  2017-6360  97059    URL
42237SERVER-WEBAPP QNAP NAS userConfig.cgi command injection attempt (more info ...)web-application-attack  2017-6360  97059    URL
42238SERVER-WEBAPP QNAP NAS userConfig.cgi command injection attempt (more info ...)web-application-attack  2017-6360  97059    URL
42239SERVER-WEBAPP QNAP NAS utilRequest.cgi command injection attempt (more info ...)web-application-attack  2017-6359  97059    URL
42240SERVER-WEBAPP QNAP NAS utilRequest.cgi command injection attempt (more info ...)web-application-attack  2017-6359  97059    URL
42241SERVER-WEBAPP QNAP NAS utilRequest.cgi command injection attempt (more info ...)web-application-attack  2017-6359  97059    URL
42327SERVER-WEBAPP Cpanel cgiemail format string code execution attempt (more info ...)attempted-user  2017-5613  95870    URL
42328SERVER-WEBAPP Cpanel cgiemail format string code execution attempt (more info ...)attempted-user  2017-5613  95870    URL
42333SERVER-WEBAPP Trend Micro Threat Discovery Appliance admin_sys_time.cgi command injection attempt (more info ...)web-application-attack  2016-7547  97610    
42334SERVER-WEBAPP Trend Micro Threat Discovery Appliance admin_sys_time.cgi command injection attempt (more info ...)web-application-attack  2016-7547  97610    
42335SERVER-WEBAPP Trend Micro Threat Discovery Appliance admin_sys_time.cgi command injection attempt (more info ...)web-application-attack  2016-7547  97610    
42336SERVER-WEBAPP Trend Micro Threat Discovery Appliance logoff.cgi directory traversal attempt (more info ...)web-application-attack  2016-7552  97599    
42382SERVER-WEBAPP Trend Micro Threat Discovery Appliance detected_potential_files.cgi command injection attempt (more info ...)web-application-attack  2016-8586      
42383SERVER-WEBAPP Trend Micro Threat Discovery Appliance detected_potential_files.cgi command injection attempt (more info ...)web-application-attack  2016-8586      
42384SERVER-WEBAPP Trend Micro Threat Discovery Appliance detected_potential_files.cgi command injection attempt (more info ...)web-application-attack  2016-8586      
42407SERVER-WEBAPP WePresent WiPG rdfs.cgi command injection attempt (more info ...)web-application-attack        URL
42408SERVER-WEBAPP WePresent WiPG rdfs.cgi command injection attempt (more info ...)web-application-attack        URL
42409SERVER-WEBAPP WePresent WiPG rdfs.cgi command injection attempt (more info ...)web-application-attack        URL
42431SERVER-WEBAPP Foscam IP Video Camera CGIProxy.fcgi query append buffer overflow attempt (more info ...)web-application-attack  2017-2831      URL
42955SERVER-WEBAPP Trend Micro Threat Discovery Appliance upload.cgi directory traversal attempt (more info ...)web-application-attack  2016-8593      
44453SERVER-WEBAPP D-Link hedwig.cgi NTP service configuration command injection attempt (more info ...)attempted-recon        URL
44454SERVER-WEBAPP D-Link hedwig.cgi directory traversal attempt (more info ...)attempted-recon        URL
44490SERVER-WEBAPP ZyXEL Router Firmware qos_queue_add.cgi command injection attempt (more info ...)web-application-attack        URL
44491SERVER-WEBAPP ZyXEL Router Firmware qos_queue_add.cgi command injection attempt (more info ...)web-application-attack        URL
44492SERVER-WEBAPP ZyXEL Router Firmware qos_queue_add.cgi command injection attempt (more info ...)web-application-attack        URL
44494SERVER-WEBAPP Faleemi IP Cameras ftp.cgi command injection attempt (more info ...)web-application-attack        URL
44495SERVER-WEBAPP Faleemi IP Cameras ftp.cgi command injection attempt (more info ...)web-application-attack        URL
44496SERVER-WEBAPP Faleemi IP Cameras ftp.cgi command injection attempt (more info ...)web-application-attack        URL
44614SERVER-WEBAPP D-Link soap.cgi service command injection attempt (more info ...)web-application-attack  2018-6530      
44671SERVER-WEBAPP HP OpenView NNM snmpviewer.exe CGI parameter buffer overflow attempt (more info ...)attempted-user  2010-1552      
44672SERVER-WEBAPP HP OpenView NNM snmpviewer.exe CGI parameter buffer overflow attempt (more info ...)attempted-user  2010-1552      
44673SERVER-WEBAPP HP OpenView NNM snmpviewer.exe CGI parameter buffer overflow attempt (more info ...)attempted-user  2010-1552      
45218SERVER-WEBAPP Embedthis GoAhead CGI information disclosure attempt (more info ...)attempted-recon  2017-17562      
45407SERVER-WEBAPP Western Digital MyCloud nas_sharing.cgi backdoor account access attempt (more info ...)web-application-attack        URL
45408SERVER-WEBAPP Western Digital MyCloud nas_sharing.cgi command injection attempt (more info ...)web-application-attack        URL
45409SERVER-WEBAPP Western Digital MyCloud nas_sharing.cgi command injection attempt (more info ...)web-application-attack        URL
45410SERVER-WEBAPP Western Digital MyCloud nas_sharing.cgi command injection attempt (more info ...)web-application-attack        URL
45526SERVER-WEBAPP AsusWRT vpnupload.cgi unauthenticated NVRAM configuration modification attempt (more info ...)attempted-admin  2018-6000      
45621SERVER-WEBAPP Cisco UCS Central recvbackup.cgi command injection attempt (more info ...)web-application-attack  2018-0113      URL
45622SERVER-WEBAPP Cisco UCS Central recvbackup.cgi command injection attempt (more info ...)web-application-attack  2018-0113      URL
46160SERVER-WEBAPP Western Digital MyCloud home_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46161SERVER-WEBAPP Western Digital MyCloud home_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46162SERVER-WEBAPP Western Digital MyCloud home_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46735SERVER-WEBAPP D-Link DSL-2750B routers login.cgi command injection attempt (more info ...)web-application-attack        URL
46736SERVER-WEBAPP D-Link DSL-2750B routers login.cgi command injection attempt (more info ...)web-application-attack        URL
46737SERVER-WEBAPP D-Link DSL-2750B routers login.cgi command injection attempt (more info ...)web-application-attack        URL
46758SERVER-WEBAPP D-Link DNS-325 ShareCenter photocenter_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46759SERVER-WEBAPP D-Link DNS-325 ShareCenter photocenter_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46760SERVER-WEBAPP D-Link DNS-325 ShareCenter photocenter_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46799SERVER-WEBAPP Western Digital MyCloud snmp_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46800SERVER-WEBAPP Western Digital MyCloud snmp_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46801SERVER-WEBAPP Western Digital MyCloud snmp_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46814SERVER-WEBAPP Western Digital MyCloud login_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46815SERVER-WEBAPP Western Digital MyCloud login_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46816SERVER-WEBAPP Western Digital MyCloud login_mgr.cgi command injection attempt (more info ...)web-application-attack        URL
46828SERVER-WEBAPP D-Link DIR-620 index.cgi command injection attempt (more info ...)web-application-attack  2018-6211      URL
46829SERVER-WEBAPP D-Link DIR-620 index.cgi command injection attempt (more info ...)web-application-attack  2018-6211      URL
47464SERVER-WEBAPP CGit cgit_clone_objects function directory traversal attempt (more info ...)web-application-attack  2018-14912      
47465SERVER-WEBAPP CGit cgit_clone_objects function directory traversal attempt (more info ...)web-application-attack  2018-14912      
47466SERVER-WEBAPP CGit cgit_clone_objects function directory traversal attempt (more info ...)web-application-attack  2018-14912      
48172SERVER-WEBAPP D-Link DIR-816 form2systime.cgi command injection attempt (more info ...)web-application-attack  2018-17066      URL
48173SERVER-WEBAPP D-Link DIR-816 form2systime.cgi command injection attempt (more info ...)web-application-attack  2018-17066      URL
48174SERVER-WEBAPP D-Link DIR-816 form2systime.cgi command injection attempt (more info ...)web-application-attack  2018-17066      URL
48228SERVER-WEBAPP Supervene RazDC create_user.cgi command injection attempt (more info ...)web-application-attack  2018-15551      
48229SERVER-WEBAPP Supervene RazDC create_user.cgi command injection attempt (more info ...)web-application-attack  2018-15551      
48230SERVER-WEBAPP Supervene RazDC create_user.cgi command injection attempt (more info ...)web-application-attack  2018-15551      
48244SERVER-WEBAPP Supervene RazDC save_passwd.cgi command injection attempt (more info ...)web-application-attack  2018-15549      
48245SERVER-WEBAPP Supervene RazDC save_passwd.cgi command injection attempt (more info ...)web-application-attack  2018-15549      
48246SERVER-WEBAPP Supervene RazDC save_passwd.cgi command injection attempt (more info ...)web-application-attack  2018-15549      
48266SERVER-WEBAPP Teltonika RUT9XX autologin.cgi command injection attempt (more info ...)web-application-attack  2018-17532      URL
48267SERVER-WEBAPP Teltonika RUT9XX autologin.cgi command injection attempt (more info ...)web-application-attack  2018-17532      URL
48268SERVER-WEBAPP Teltonika RUT9XX hotspotlogin.cgi command injection attempt (more info ...)web-application-attack  2018-17532      URL
48269SERVER-WEBAPP Teltonika RUT9XX hotspotlogin.cgi command injection attempt (more info ...)web-application-attack  2018-17532      URL
48270SERVER-WEBAPP Teltonika RUT9XX autologin.cgi command injection attempt (more info ...)web-application-attack  2018-17532      URL
48271SERVER-WEBAPP Teltonika RUT9XX hotspotlogin.cgi command injection attempt (more info ...)web-application-attack  2018-17532      URL
48744SERVER-WEBAPP TRENDnet TEW-673GRU apply.cgi start_arpping command injection attempt (more info ...)web-application-attack  2018-19239      URL
50336SERVER-WEBAPP GoAhead IP Camera set_ftp.cgi command injection attempt (more info ...)web-application-attack        URL
50337SERVER-WEBAPP GoAhead IP Camera set_ftp.cgi command injection attempt (more info ...)web-application-attack        URL
50338SERVER-WEBAPP GoAhead IP Camera set_ftp.cgi command injection attempt (more info ...)web-application-attack        URL
50339SERVER-WEBAPP GoAhead IP Camera set_ftp.cgi command injection attempt (more info ...)web-application-attack        URL
50748SERVER-WEBAPP Seowonintech diagnostic.cgi command injection attempt (more info ...)web-application-attack  2016-10760      URL
50750SERVER-WEBAPP Seowonintech diagnostic.cgi command injection attempt (more info ...)web-application-attack  2016-10760      URL
50751SERVER-WEBAPP Seowonintech diagnostic.cgi command injection attempt (more info ...)web-application-attack  2016-10760      URL
51453SERVER-WEBAPP Pulse Secure Connect VPN post-auth hc.cgi buffer overflow attempt (more info ...)web-application-attack  2019-11542      URL
54012SERVER-WEBAPP ASUS ASUSWRT appGet.cgi command injection attempt (more info ...)web-application-attack        
55823SERVER-WEBAPP Trend Micro Control Manager CCGIServlet SQL injection attempt (more info ...)web-application-attack        
55824SERVER-WEBAPP Trend Micro Control Manager CCGIServlet SQL injection attempt (more info ...)web-application-attack        
55825SERVER-WEBAPP Trend Micro Control Manager CCGIServlet SQL injection attempt (more info ...)web-application-attack        
55827SERVER-WEBAPP Trend Micro Control Manager CCGIServlet multiple functions SQL injection attempt (more info ...)web-application-attack  2018-3603      
55828SERVER-WEBAPP Trend Micro Control Manager CCGIServlet multiple functions SQL injection attempt (more info ...)web-application-attack  2018-3603      
55829SERVER-WEBAPP Trend Micro Control Manager CCGIServlet multiple functions SQL injection attempt (more info ...)web-application-attack  2018-3603      
58337SERVER-WEBAPP Webmin Package Updates update.cgi command injection attempt (more info ...)web-application-attack  2020-35606      
58338SERVER-WEBAPP Webmin Package Updates update.cgi command injection attempt (more info ...)web-application-attack  2020-35606      
58339SERVER-WEBAPP Webmin Package Updates update.cgi command injection attempt (more info ...)web-application-attack  2020-35606      
58340SERVER-WEBAPP Webmin Package Updates update.cgi command injection attempt (more info ...)web-application-attack  2020-35606      
58471SERVER-WEBAPP Trend Micro Control Manager CCGIServlet SQL injection attempt (more info ...)web-application-attack        
58472SERVER-WEBAPP Trend Micro Control Manager CCGIServlet SQL injection attempt (more info ...)web-application-attack        
58473SERVER-WEBAPP Trend Micro Control Manager CCGIServlet SQL injection attempt (more info ...)web-application-attack        
58542SERVER-WEBAPP Trend Micro Control Manager CCGIServlet EmailMessageDetected SQL injection attempt (more info ...)web-application-attack        
58543SERVER-WEBAPP Trend Micro Control Manager CCGIServlet EmailMessageDetected SQL injection attempt (more info ...)web-application-attack        
58544SERVER-WEBAPP Trend Micro Control Manager CCGIServlet EmailMessageDetected SQL injection attempt (more info ...)web-application-attack        
58670SERVER-WEBAPP Trend Micro Control Manager CCGIServlet DLPIncidentStatusChangeResult SQL injection attempt (more info ...)web-application-attack        
58671SERVER-WEBAPP Trend Micro Control Manager CCGIServlet DLPIncidentStatusChangeResult SQL injection attempt (more info ...)web-application-attack        
58672SERVER-WEBAPP Trend Micro Control Manager CCGIServlet DLPIncidentStatusChangeResult SQL injection attempt (more info ...)web-application-attack        
58974SERVER-WEBAPP Webmin Usermin secret.cgi command injection attempt (more info ...)web-application-attack        URL
58975SERVER-WEBAPP Webmin Usermin secret.cgi command injection attempt (more info ...)web-application-attack        URL
58976SERVER-WEBAPP Webmin Usermin secret.cgi command injection attempt (more info ...)web-application-attack        URL
58977SERVER-WEBAPP Webmin Usermin secret.cgi command injection attempt (more info ...)web-application-attack        URL
59375SERVER-WEBAPP IPFire Firewall Web Interface backup cgi directory traversal attempt (more info ...)web-application-attack  2018-16232      
59376SERVER-WEBAPP IPFire Firewall Web Interface backup cgi directory traversal attempt (more info ...)web-application-attack  2018-16232      
59377SERVER-WEBAPP IPFire Firewall Web Interface backup cgi directory traversal attempt (more info ...)web-application-attack  2018-16232      
59378SERVER-WEBAPP IPFire Firewall Web Interface backup cgi command injection attempt (more info ...)web-application-attack  2018-16232      
59379SERVER-WEBAPP IPFire Firewall Web Interface backup cgi command injection attempt (more info ...)web-application-attack  2018-16232      
59380SERVER-WEBAPP IPFire Firewall Web Interface backup cgi command injection attempt (more info ...)web-application-attack  2018-16232      
59381SERVER-WEBAPP IPFire Firewall Web Interface backup cgi command injection attempt (more info ...)web-application-attack  2018-16232      


# of warning rules in this group: 279

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
803SERVER-WEBAPP HyperSeek hsx.cgi directory traversal attempt (more info ...)web-application-attack 2001-0253 2314 10602 
809SERVER-WEBAPP whois_raw.cgi arbitrary command execution attempt (more info ...)web-application-attack 1999-1063 304 10306 URL
810SERVER-WEBAPP whois_raw.cgi access (more info ...)attempted-recon 1999-1063 304 10306 
817SERVER-WEBAPP dcboard.cgi invalid user addition attempt (more info ...)web-application-attack 2001-0527 2728 10583 
818SERVER-WEBAPP dcforum.cgi access (more info ...)attempted-recon 2001-0527 2728 10583 
819SERVER-WEBAPP mmstdod.cgi access (more info ...)attempted-recon 2001-0021 2063 10566 
823SERVER-WEBAPP cvsweb.cgi access (more info ...)attempted-recon 2000-0670 1469 10465 
829SERVER-WEBAPP nph-test-cgi access (more info ...)attempted-recon 1999-0045 686 10165 
835SERVER-WEBAPP test-cgi access (more info ...)attempted-recon 1999-0070 2003 10282 
840SERVER-WEBAPP perlshop.cgi access (more info ...)attempted-recon 1999-1374   
845SERVER-WEBAPP AT-admin.cgi access (more info ...)attempted-recon 1999-1072   
846SERVER-WEBAPP bnbform.cgi access (more info ...)attempted-recon 1999-0937 2147  
854SERVER-WEBAPP classifieds.cgi access (more info ...)attempted-recon 1999-0934 2020  
856SERVER-WEBAPP environ.cgi access (more info ...)attempted-recon    
863SERVER-WEBAPP day5datacopier.cgi access (more info ...)attempted-recon 1999-1232   
864SERVER-WEBAPP day5datanotifier.cgi access (more info ...)attempted-recon 1999-1232   
871SERVER-WEBAPP survey.cgi access (more info ...)attempted-recon 1999-0936 1817  
889SERVER-WEBAPP ppdscgi.exe access (more info ...)attempted-recon  491 10187 URL
890SERVER-WEBAPP sendform.cgi access (more info ...)attempted-recon 2002-0710 5286  URL
897SERVER-WEBAPP pals-cgi access (more info ...)attempted-recon 2001-0217 2372 10611 
898SERVER-WEBAPP commerce.cgi access (more info ...)attempted-recon 2001-0210 2361 10612 
900SERVER-WEBAPP webspirs.cgi directory traversal attempt (more info ...)web-application-attack 2001-0211 2362 10616 
901SERVER-WEBAPP webspirs.cgi access (more info ...)attempted-recon 2001-0211 2362 10616 
1051FILE-OTHER technote main.cgi file directory traversal attempt (more info ...)web-application-attack 2001-0075 2156 10584 
1052SERVER-WEBAPP technote print.cgi directory traversal attempt (more info ...)web-application-attack 2001-0075 2156 10584 
1053SERVER-WEBAPP ads.cgi command execution attempt (more info ...)web-application-attack 2001-0025 2103 11464 
1093SERVER-WEBAPP cached_feed.cgi moreover shopping cart directory traversal (more info ...)web-application-attack 2000-0906 1762  
1149SERVER-WEBAPP count.cgi access (more info ...)web-application-activity 1999-0021 128 10049 
1163SERVER-WEBAPP webdist.cgi access (more info ...)web-application-activity 1999-0039 374 10299 
1172SERVER-WEBAPP bigconf.cgi access (more info ...)web-application-activity 1999-1550 778 10027 
1174SERVER-WEBAPP /cgi-bin/jj access (more info ...)web-application-activity 1999-0260 2002 10131 
1194SERVER-WEBAPP sojourn.cgi File attempt (more info ...)web-application-attack 2000-0180 1052 10349 
1195SERVER-WEBAPP sojourn.cgi access (more info ...)web-application-activity 2000-0180 1052 10349 
1204SERVER-WEBAPP ax-admin.cgi access (more info ...)web-application-activity    
1205SERVER-WEBAPP axs.cgi access (more info ...)web-application-activity    
1206SERVER-WEBAPP cachemgr.cgi access (more info ...)web-application-activity 1999-0710 2059 10034 
1208SERVER-WEBAPP responder.cgi access (more info ...)web-application-activity  3155  
1211SERVER-WEBAPP web-map.cgi access (more info ...)web-application-activity    
1219SERVER-WEBAPP dfire.cgi access (more info ...)web-application-activity 1999-0913 564  
1221SERVER-WEBAPP Muscat Empower cgi access (more info ...)web-application-activity 2001-0224 2374 10609 
1222SERVER-WEBAPP pals-cgi arbitrary file access attempt (more info ...)web-application-attack 2001-0217 2372 10611 
1304SERVER-WEBAPP txt2html.cgi access (more info ...)web-application-activity    
1305SERVER-WEBAPP txt2html.cgi directory traversal attempt (more info ...)web-application-attack    
1307SERVER-WEBAPP store.cgi access (more info ...)web-application-activity 2001-0305 2385 10639 
1308SERVER-WEBAPP sendmessage.cgi access (more info ...)attempted-recon 2001-1100 3673  
1392SERVER-WEBAPP lastlines.cgi access (more info ...)attempted-recon 2001-1206 3755  
1395SERVER-WEBAPP zml.cgi attempt (more info ...)web-application-activity 2001-1209 3759 10830 
1396SERVER-WEBAPP zml.cgi access (more info ...)web-application-activity 2001-1209 3759 10830 
1405SERVER-WEBAPP AHG search.cgi access (more info ...)web-application-activity 2002-2113 3985  
1406SERVER-WEBAPP agora.cgi access (more info ...)web-application-activity 2002-0215 3976 10836 
1410SERVER-WEBAPP dcboard.cgi access (more info ...)attempted-recon 2001-0527 2728 10583 
1453SERVER-WEBAPP AT-generated.cgi access (more info ...)attempted-recon 1999-1072   
1465SERVER-WEBAPP auktion.cgi access (more info ...)web-application-activity 2001-0212 2367 10638 
1466SERVER-WEBAPP cgiforum.pl access (more info ...)web-application-activity 2000-1171 1963 10552 
1467SERVER-WEBAPP directorypro.cgi access (more info ...)web-application-activity 2001-0780 2793 10679 
1468SERVER-WEBAPP Web Shopper shopper.cgi attempt (more info ...)web-application-attack 2000-0922 1776 10533 
1469SERVER-WEBAPP Web Shopper shopper.cgi access (more info ...)attempted-recon 2000-0922 1776  
1471SERVER-WEBAPP mailnews.cgi access (more info ...)attempted-recon 2001-0271 2391 10641 
1472SERVER-WEBAPP book.cgi access (more info ...)web-application-activity 2001-1114 3178 10721 
1473SERVER-WEBAPP newsdesk.cgi access (more info ...)attempted-recon 2001-0232 2172 10586 
1476SERVER-WEBAPP sdbsearch.cgi access (more info ...)attempted-recon 2001-1130 1658 10720 
1479SERVER-WEBAPP ttawebtop.cgi arbitrary file attempt (more info ...)web-application-attack 2001-0805 2890 10696 
1480SERVER-WEBAPP ttawebtop.cgi access (more info ...)attempted-recon 2001-0805 2890 10696 
1481SERVER-WEBAPP upload.cgi access (more info ...)attempted-recon   10290 
1488SERVER-WEBAPP store.cgi directory traversal attempt (more info ...)web-application-attack 2001-0305 2385 10639 
1494SERVER-WEBAPP SIX webboard generate.cgi attempt (more info ...)web-application-attack 2001-1115 3175 10725 
1495SERVER-WEBAPP SIX webboard generate.cgi access (more info ...)web-application-activity 2001-1115 3175 10725 
1496SERVER-WEBAPP spin_client.cgi access (more info ...)web-application-activity   10393 
1501SERVER-WEBAPP a1stats a1disp3.cgi directory traversal attempt (more info ...)web-application-attack 2001-0561 2705 10669 
1502SERVER-WEBAPP a1stats a1disp3.cgi access (more info ...)web-application-activity 2001-0561 2705 10669 
1534SERVER-WEBAPP agora.cgi attempt (more info ...)web-application-attack 2002-0215 3976 10836 
1539SERVER-WEBAPP /cgi-bin/ls access (more info ...)web-application-activity 2000-0079 936 10037 
1542SERVER-WEBAPP cgimail access (more info ...)web-application-activity 2000-0726 1623 11721 
1543SERVER-WEBAPP cgiwrap access (more info ...)web-application-activity 2001-0987 777 10041 
1554SERVER-WEBAPP dbman db.cgi access (more info ...)web-application-activity 2000-0381 1178 10403 
1569SERVER-WEBAPP loadpage.cgi directory traversal attempt (more info ...)web-application-attack 2000-1092 2109 10065 
1570SERVER-WEBAPP loadpage.cgi access (more info ...)web-application-activity 2000-1092 2109 10065 
1571SERVER-WEBAPP dcforum.cgi directory traversal attempt (more info ...)web-application-attack 2001-0437 2611 10583 
1572SERVER-WEBAPP commerce.cgi arbitrary file access attempt (more info ...)attempted-recon 2001-0210 2361 10612 
1573SERVER-WEBAPP cgiforum.pl attempt (more info ...)web-application-attack 2000-1171 1963 10552 
1574SERVER-WEBAPP directorypro.cgi attempt (more info ...)web-application-attack 2001-0780 2793 10679 
1587SERVER-WEBAPP cgitest.exe access (more info ...)web-application-activity 2002-0128 3885 11131 
1590SERVER-WEBAPP faqmanager.cgi arbitrary file access attempt (more info ...)web-application-attack 2002-2033 3810 10837 
1591SERVER-WEBAPP faqmanager.cgi access (more info ...)web-application-activity 2002-2033 3810 10837 
1592SERVER-WEBAPP /fcgi-bin/echo.exe access (more info ...)web-application-activity   10838 
1593SERVER-WEBAPP FormHandler.cgi external site redirection attempt (more info ...)web-application-attack 1999-1050 799 10075 
1594SERVER-WEBAPP FormHandler.cgi access (more info ...)web-application-activity 1999-1050 799 10075 
1597SERVER-WEBAPP guestbook.cgi access (more info ...)web-application-activity 1999-0237  10098 
1598SERVER-WEBAPP Home Free search.cgi directory traversal attempt (more info ...)web-application-attack 2000-0054 921 10101 
1599SERVER-WEBAPP search.cgi access (more info ...)web-application-activity 2000-0054 921  
1607SERVER-WEBAPP HyperSeek hsx.cgi access (more info ...)web-application-activity 2001-0253 2314 10602 
1617SERVER-WEBAPP Bugzilla doeditvotes.cgi access (more info ...)web-application-activity 2002-0011 3800  
1628SERVER-WEBAPP FormHandler.cgi directory traversal attempt (more info ...)web-application-attack 1999-1050 799 10075 
1644SERVER-WEBAPP test-cgi attempt (more info ...)web-application-attack 1999-0070 2003 10282 
1645SERVER-WEBAPP testcgi access (more info ...)web-application-activity 2003-1531 7214 11610 
1646SERVER-WEBAPP test.cgi access (more info ...)web-application-activity    
1655SERVER-WEBAPP pfdispaly.cgi arbitrary command execution attempt (more info ...)web-application-attack 1999-0270  10174 
1656SERVER-WEBAPP pfdispaly.cgi access (more info ...)web-application-activity 1999-0270 64 10174 
1657SERVER-WEBAPP pagelog.cgi directory traversal attempt (more info ...)web-application-activity 2000-0940 1864 10591 
1658SERVER-WEBAPP pagelog.cgi access (more info ...)web-application-activity 2000-0940 1864 10591 
1666INDICATOR-COMPROMISE index of /cgi-bin/ response (more info ...)bad-unknown   10039 
1668SERVER-WEBAPP /cgi-bin/ access (more info ...)web-application-attack    
1669SERVER-WEBAPP /cgi-dos/ access (more info ...)web-application-attack    
1703SERVER-WEBAPP auktion.cgi directory traversal attempt (more info ...)web-application-attack 2001-0212 2367 10638 
1709SERVER-WEBAPP ad.cgi access (more info ...)web-application-activity 2001-0025 2103 11464 
1710SERVER-WEBAPP bbs_forum.cgi access (more info ...)web-application-activity 2001-0123 2177  URL
1711SERVER-WEBAPP bsguest.cgi access (more info ...)web-application-activity 2001-0099 2159  
1712SERVER-WEBAPP bslist.cgi access (more info ...)web-application-activity 2001-0100 2160  
1713SERVER-WEBAPP cgforum.cgi access (more info ...)web-application-activity 2000-1132 1951  
1715SERVER-WEBAPP register.cgi access (more info ...)web-application-activity 2001-0076 2157  
1716SERVER-WEBAPP gbook.cgi access (more info ...)web-application-activity 2000-1131 1940  
1717SERVER-WEBAPP simplestguest.cgi access (more info ...)web-application-activity 2001-0022 2106  
1719SERVER-WEBAPP talkback.cgi directory traversal attempt (more info ...)web-application-attack 2001-0420 2547  
1720SERVER-WEBAPP talkback.cgi access (more info ...)web-application-activity 2001-0420 2547  
1723SERVER-WEBAPP emumail.cgi NULL attempt (more info ...)web-application-activity 2002-1526 5824  
1724SERVER-WEBAPP emumail.cgi access (more info ...)web-application-activity 2002-1526 5824  
1763SERVER-WEBAPP Nortel Contivity cgiproc DOS attempt (more info ...)web-application-attack 2000-0064 938 10160 
1764SERVER-WEBAPP Nortel Contivity cgiproc DOS attempt (more info ...)web-application-attack 2000-0064 938 10160 
1765SERVER-WEBAPP Nortel Contivity cgiproc access (more info ...)web-application-activity 2000-0064 938 10160 
1787SERVER-WEBAPP csPassword.cgi access (more info ...)web-application-activity 2002-0918 4889  
1788SERVER-WEBAPP csPassword password.cgi.tmp access (more info ...)web-application-activity 2002-0920 4889  
1805SERVER-WEBAPP Oracle Reports CGI access (more info ...)web-application-activity 2002-0947 4848  
1822SERVER-WEBAPP AlienForm alienform.cgi directory traversal attempt (more info ...)web-application-attack 2002-0934 4983 11027 
1823SERVER-WEBAPP AlienForm af.cgi directory traversal attempt (more info ...)web-application-attack 2002-0934 4983 11027 
1824SERVER-WEBAPP AlienForm alienform.cgi access (more info ...)web-application-activity 2002-0934 4983 11027 
1825SERVER-WEBAPP AlienForm af.cgi access (more info ...)web-application-activity 2002-0934 4983 11027 
1850SERVER-WEBAPP way-board.cgi access (more info ...)web-application-activity   10610 
1862SERVER-WEBAPP mrtg.cgi directory traversal attempt (more info ...)web-application-attack 2002-0232 4017 11001 
1865SERVER-WEBAPP webdist.cgi arbitrary command attempt (more info ...)web-application-attack 1999-0039 374 10299 
1870SERVER-WEBAPP siteUserMod.cgi access (more info ...)web-application-activity 2000-0117 951 10253 
1875SERVER-WEBAPP cgicso access (more info ...)web-application-activity 2002-1652 6141 10780 
1876SERVER-WEBAPP nph-publish.cgi access (more info ...)web-application-activity 1999-1177  10164 
1878SERVER-WEBAPP sdbsearch.cgi access (more info ...)web-application-activity 2000-0868 1658 10503 
1879SERVER-WEBAPP book.cgi arbitrary command execution attempt (more info ...)web-application-attack 2001-1114 3178 10721 
1933SERVER-WEBAPP cart.cgi access (more info ...)web-application-activity 2000-0252 1115 10368 
1994SERVER-WEBAPP vpasswd.cgi access (more info ...)web-application-activity  6038 11165 
1995SERVER-WEBAPP alya.cgi access (more info ...)web-application-activity   11118 
1996SERVER-WEBAPP viralator.cgi access (more info ...)web-application-activity 2001-0849 3495 11107 
2001SERVER-WEBAPP smartsearch.cgi access (more info ...)web-application-activity  7133  
2051SERVER-WEBAPP cached_feed.cgi moreover shopping cart access (more info ...)web-application-activity 2000-0906 1762  
2052SERVER-WEBAPP overflow.cgi access (more info ...)web-application-activity 2002-1361 6326 11190 URL
2053SERVER-WEBAPP Bugtraq process_bug.cgi access (more info ...)web-application-activity 2002-0008 3272  
2054SERVER-WEBAPP Bugtraq enter_bug.cgi arbitrary command attempt (more info ...)web-application-attack 2002-0008 3272  
2055SERVER-WEBAPP Bugtraq enter_bug.cgi access (more info ...)web-application-activity 2002-0008 3272  
2085SERVER-WEBAPP parse_xml.cgi access (more info ...)web-application-activity 2003-0423 6958  
2086SERVER-WEBAPP streaming server parse_xml.cgi access (more info ...)web-application-activity 2003-0423 6958  
2116SERVER-WEBAPP chipcfg.cgi access (more info ...)web-application-activity 2001-1341 2767  URL
2127SERVER-WEBAPP ikonboard.cgi access (more info ...)web-application-activity  7361 11605 
2128SERVER-WEBAPP swsrv.cgi access (more info ...)web-application-activity 2003-0217 7510 11608 
2194SERVER-WEBAPP CSMailto.cgi access (more info ...)web-application-activity 2002-0749 6265 11748 
2195SERVER-WEBAPP alert.cgi access (more info ...)web-application-activity 2002-0346 4579 11748 
2196SERVER-WEBAPP catgy.cgi access (more info ...)web-application-activity 2001-1212 4579 11748 
2197SERVER-WEBAPP cvsview2.cgi access (more info ...)web-application-activity 2003-0153 5517 11748 
2198SERVER-WEBAPP cvslog.cgi access (more info ...)web-application-activity 2003-0153 5517 11748 
2199SERVER-WEBAPP multidiff.cgi access (more info ...)web-application-activity 2003-0153 5517 11748 
2200SERVER-WEBAPP dnewsweb.cgi access (more info ...)web-application-activity 2000-0423 4579 11748 
2202SERVER-WEBAPP Webmin Directory edit_action.cgi access (more info ...)web-application-activity 2001-1196 4579 11748 
2203SERVER-WEBAPP Leif M. Wright everythingform.cgi access (more info ...)web-application-activity 2001-0023 4579 11748 
2204SERVER-WEBAPP EasyBoard 2000 ezadmin.cgi access (more info ...)web-application-activity 2002-0263 4579 11748 
2205SERVER-WEBAPP EasyBoard 2000 ezboard.cgi access (more info ...)web-application-activity 2002-0263 4579 11748 
2206SERVER-WEBAPP EasyBoard 2000 ezman.cgi access (more info ...)web-application-activity 2002-0263 4579 11748 
2207SERVER-WEBAPP FileSeek fileseek.cgi access (more info ...)web-application-activity 2002-0611 6784 11748 
2208SERVER-WEBAPP Faq-O-Matic fom.cgi access (more info ...)web-application-activity 2002-0230 4579 11748 
2209SERVER-WEBAPP Infonautics getdoc.cgi access (more info ...)web-application-activity 2000-0288 4579 11748 
2210SERVER-WEBAPP Multiple Vendors global.cgi access (more info ...)web-application-activity 2000-0952 4579 11748 
2211SERVER-WEBAPP Lars Ellingsen guestserver.cgi access (more info ...)web-application-activity 2001-0180 4579 11748 
2212SERVER-WEBAPP cgiCentral WebStore imageFolio.cgi access (more info ...)web-application-activity 2002-1334 6265 11748 
2213SERVER-WEBAPP Oatmeal Studios Mail File mailfile.cgi access (more info ...)web-application-activity 2000-0977 4579 11748 
2214SERVER-WEBAPP 3R Soft MailStudio 2000 mailview.cgi access (more info ...)web-application-activity 2000-0526 4579 11748 
2215SERVER-WEBAPP Alabanza Control Panel nsManager.cgi access (more info ...)web-application-activity 2000-1023 4579 11748 
2216SERVER-WEBAPP Ipswitch IMail readmail.cgi access (more info ...)web-application-activity 2001-1283 4579 11748 
2217SERVER-WEBAPP Ipswitch IMail printmail.cgi access (more info ...)web-application-activity 2001-1283 4579 11748 
2218SERVER-WEBAPP Oracle Cobalt RaQ service.cgi access (more info ...)web-application-activity 2002-0346 4579 11748 
2219SERVER-WEBAPP Trend Micro Interscan VirusWall setpasswd.cgi access (more info ...)web-application-activity 2001-0133 4579 11748 
2220SERVER-WEBAPP Leif M. Wright simplestmail.cgi access (more info ...)web-application-activity 2001-0022 4579 11748 
2221SERVER-WEBAPP cgiCentral WebStore ws_mail.cgi access (more info ...)web-application-activity 2001-1343 4579 11748 
2222SERVER-WEBAPP Infinity CGI exploit scanner nph-exploitscanget.cgi access (more info ...)web-application-activity 2003-0434 7913 11740 
2224SERVER-WEBAPP Psunami Bulletin Board psunami.cgi access (more info ...)web-application-activity  6607 11750 
2225SERVER-WEBAPP Linksys BEFSR41 gozila.cgi access (more info ...)web-application-activity 2002-1236 6086 11773 
2237SERVER-WEBAPP cgiWebupdate.exe access (more info ...)web-application-activity 2001-1150 3216 11722 
2242SERVER-WEBAPP ddicgi.exe access (more info ...)web-application-activity 2000-0826 1657 11728 
2243SERVER-WEBAPP ndcgi.exe access (more info ...)web-application-activity 2001-0922 3583 11730 
2277SERVER-WEBAPP PeopleSoft PeopleBooks psdoccgi access (more info ...)web-application-activity 2003-0627 9038  
2323SERVER-WEBAPP iSoft-Solutions QuickStore shopping cart quickstore.cgi access (more info ...)web-application-activity  9282 11975 
2388SERVER-WEBAPP Apple QuickTime streaming server view_broadcast.cgi access (more info ...)web-application-activity 2003-0422 8257  
2396SERVER-WEBAPP CCBill whereami.cgi arbitrary command execution attempt (more info ...)web-application-attack  8095  URL
2397SERVER-WEBAPP CCBill whereami.cgi access (more info ...)web-application-activity  8095  URL
2433SERVER-WEBAPP MDaemon form2raw.cgi overflow attempt (more info ...)web-application-attack 2003-1200 9317  URL
2568SERVER-WEBAPP Emumail emumail.fcgi access (more info ...)web-application-activity 2004-2385 9861 12095 
3062SERVER-WEBAPP NetScreen SA 5000 delhomepage.cgi access (more info ...)web-application-activity 2004-0347 9791  
3468SERVER-WEBAPP math_sum.mscgi access (more info ...)web-application-activity  10831 14182 
3638SERVER-WEBAPP SoftCart.exe CGI buffer overflow attempt (more info ...)web-application-attack 2004-2221 10926  
4128SERVER-WEBAPP 4DWebstar ShellExample.cgi information disclosure (more info ...)attempted-recon 2004-0696 10721  URL
5706POLICY-SOCIAL Namazu incoming namazu.cgi access (more info ...)web-application-activity    URL
5764PUA-ADWARE Hijacker begin2search outbound connection - fcgi query (more info ...)misc-activity    URL
5945PUA-ADWARE Adware weirdontheweb runtime detection - track.cgi request (more info ...)misc-activity    URL
6019MALWARE-CNC dsk lite 1.0 variant outbound connection cgi notification (more info ...)trojan-activity    URL
6043MALWARE-CNC fear 0.2 variant outbound connection cgi notification (more info ...)trojan-activity    URL
6059MALWARE-CNC neurotickat1.3 variant outbound connection cgi notification (more info ...)trojan-activity    URL
7076MALWARE-CNC minimo v0.6 variant outbound connection cgi notification (more info ...)trojan-activity    
7148MALWARE-TOOLS Hacker-Tool sars notifier runtime detection - cgi notification (more info ...)misc-activity    URL
7524PUA-ADWARE Hijacker moneybar outbound connection - cgispy counter (more info ...)misc-activity    URL
7722MALWARE-CNC prorat 1.9 cgi notification detection (more info ...)trojan-activity    URL
7742MALWARE-CNC nova 1.0 variant outbound connection cgi notification client-to-server (more info ...)trojan-activity    URL
7743MALWARE-BACKDOOR nova 1.0 runtime detection - cgi notification server-to-client (more info ...)trojan-activity    URL
13591SERVER-WEBAPP Trend Micro OfficeScan CGI password decryption buffer overflow attempt (more info ...)web-application-attack 2008-1365 28020  URL
15264SERVER-WEBAPP Oracle TimesTen In-Memory Database evtdump CGI module format string exploit attempt (more info ...)attempted-admin 2008-5440 33177  
16922MALWARE-CNC URI request for known malicious URI - /cgi-bin/rd.cgi?f=/vercfg.dat?AgentID= (more info ...)trojan-activity    URL
17386SERVER-WEBAPP Lighttpd mod_fastcgi Extension CGI Variable Overwriting Vulnerability attempt (more info ...)attempted-user 2007-4727 25622  URL
17605SERVER-WEBAPP Trend Micro OfficeScan CGI password decryption buffer overflow attempt (more info ...)web-application-attack 2008-1365 28020  URL
21846MALWARE-CNC TDS Sutra - request in.cgi (more info ...)trojan-activity    URL
25394MALWARE-CNC URI request for /cgi-bin/nt/th (more info ...)trojan-activity    URL
25395MALWARE-CNC URI request for /cgi-bin/nt/sk (more info ...)trojan-activity    URL
25396MALWARE-CNC URI request for /cgi-bin/dllhost/ac (more info ...)trojan-activity    URL
25397MALWARE-CNC URI request for /cgi-bin/ms/check (more info ...)trojan-activity    URL
25398MALWARE-CNC URI request for /cgi-bin/ms/flush (more info ...)trojan-activity    URL
25399MALWARE-CNC URI request for /cgi-bin/win/wcx (more info ...)trojan-activity    URL
25400MALWARE-CNC URI request for /cgi-bin/win/cab (more info ...)trojan-activity    URL
25503MALWARE-CNC Necurs Rootkit sba.cgi (more info ...)trojan-activity    URL
25504MALWARE-CNC Necurs Rootkit op.cgi (more info ...)trojan-activity    URL
26274SERVER-WEBAPP Nagios3 statuswml.cgi remote command execution attempt (more info ...)attempted-admin 2009-2288   
26276SERVER-WEBAPP Linksys E1500/E2500 apply.cgi submit_button page redirection attempt (more info ...)attempted-admin    
26277SERVER-WEBAPP Linksys E1500/E2500 apply.cgi submit_button page redirection attempt (more info ...)attempted-admin    
26278SERVER-WEBAPP Linksys E1500/E2500 apply.cgi unauthenticated password reset attempt (more info ...)attempted-admin  57760  URL
26279SERVER-WEBAPP Linksys E1500/E2500 apply.cgi unauthenticated password reset attempt (more info ...)attempted-admin  57760  URL
26559OS-OTHER DLink IP camera remote command execution vulnerability - access to vulnerable rtpd.cgi (more info ...)attempted-admin 2013-1599   URL
28083SERVER-WEBAPP Netgear DGN1000B setup.cgi cross site scripting attempt (more info ...)web-application-attack  57836  
29267SERVER-WEBAPP Nagios3 statuswml.cgi remote command execution attempt (more info ...)attempted-admin 2009-2288   
29374SERVER-WEBAPP Nagios process_cgivars off-by-one memory access denial of service attempt (more info ...)attempted-dos 2013-7108 64363  URL
29375SERVER-WEBAPP Nagios process_cgivars off-by-one memory access denial of service attempt (more info ...)attempted-dos 2013-7108 64363  URL
31259SERVER-WEBAPP Supermicro Intelligent Management Controller url_redirect.cgi directory traversal attempt (more info ...)attempted-recon    
31542SERVER-WEBAPP D-Link Multiple Products info.cgi request buffer overflow attempt (more info ...)attempted-admin    URL
31588SERVER-WEBAPP D-Link Multiple Products hedwig.cgi cookie buffer overflow attempt (more info ...)attempted-admin    
31651SERVER-WEBAPP VMTurbo Operations Manager vmtadmin.cgi command injection attempt (more info ...)attempted-admin 2014-5073 69225  
31652SERVER-WEBAPP VMTurbo Operations Manager vmtadmin.cgi command injection attempt (more info ...)attempted-admin 2014-5073 69225  
31976OS-OTHER Bash CGI environment variable injection attempt (more info ...)attempted-admin 2014-7169   
32335OS-OTHER Bash CGI environment variable injection attempt (more info ...)attempted-admin 2014-7169   
32336OS-OTHER Bash CGI environment variable injection attempt (more info ...)attempted-admin 2014-7169   
38252SERVER-WEBAPP AWStats awstats.cgi remote file include attempt (more info ...)web-application-attack 2010-4367   
38253SERVER-WEBAPP AWStats awstats.cgi remote file include attempt (more info ...)web-application-attack 2010-4367   
38625SERVER-WEBAPP Gemtek CPE7000 sysconf.cgi command injection attempt (more info ...)web-application-attack    URL
38626SERVER-WEBAPP Gemtek CPE7000 sysconf.cgi command injection attempt (more info ...)web-application-attack    URL
39073SERVER-WEBAPP Aruba Networks IAP swarm.cgi command injection attempt (more info ...)web-application-attack 2016-2031   URL
39074SERVER-WEBAPP Aruba Networks IAP swarm.cgi command injection attempt (more info ...)web-application-attack 2016-2031   URL
39075SERVER-WEBAPP Aruba Networks IAP swarm.cgi raddb config injection attempt (more info ...)web-application-attack 2016-2031   URL
39133SERVER-WEBAPP Ubiquiti Networks XM Firmware scr.cgi command injection attempt (more info ...)web-application-attack    URL
39134SERVER-WEBAPP Ubiquiti Networks XM Firmware scr.cgi command injection attempt (more info ...)web-application-attack    URL
39135SERVER-WEBAPP Ubiquiti Networks XM Firmware scr.cgi directory traversal attempt (more info ...)web-application-attack    URL
39737SERVER-WEBAPP HttpOxy CGI application vulnerability potential man-in-the-middle attempt (more info ...)web-application-attack 2016-5388   URL
40349SERVER-WEBAPP IPFire proxy.cgi command injection attempt (more info ...)web-application-attack    URL
40350SERVER-WEBAPP IPFire proxy.cgi command injection attempt (more info ...)web-application-attack    URL
40351SERVER-WEBAPP IPFire proxy.cgi command injection attempt (more info ...)web-application-attack    URL
40352SERVER-WEBAPP IPFire proxy.cgi command injection attempt (more info ...)web-application-attack    URL
40815SERVER-WEBAPP Netgear ReadyNAS Surveillance cgi_system administrator password reset attempt (more info ...)attempted-admin 2016-5676 92318  URL
42003POLICY-OTHER Cisco Mobility Express Access Point radio.cgi access detected (more info ...)policy-violation 2017-3831   URL
42049SERVER-WEBAPP dnaLIMS viewAppletFsa.cgi directory traversal attempt (more info ...)web-application-attack 2017-6528 96823  URL
42050SERVER-WEBAPP dnaLIMS viewAppletFsa.cgi directory traversal attempt (more info ...)web-application-attack 2017-6528 96823  URL
43286SERVER-WEBAPP /cgi-bin/sh file access attempt (more info ...)attempted-recon    
44750SERVER-WEBAPP ASUS RP-AC52 login.cgi stack buffer overflow attempt (more info ...)attempted-admin    
45308SERVER-WEBAPP Axis Communications CGI Parser information disclosure attempt (more info ...)attempted-recon    URL
45570SERVER-WEBAPP HP Moonshot Provisioning Manager Appliance khuploadfile.cgi directory traversal attempt (more info ...)attempted-admin 2017-8977   URL
46080SERVER-WEBAPP Linksys E-Series apply.cgi cross site scripting attempt (more info ...)attempted-user    URL
46081SERVER-WEBAPP Linksys E-Series apply.cgi cross site scripting attempt (more info ...)attempted-user    URL
46082SERVER-WEBAPP Linksys E-Series apply.cgi ping function command injection attempt (more info ...)web-application-attack 2013-3307   
46083SERVER-WEBAPP Linksys E-Series apply.cgi directory traversal attempt (more info ...)web-application-attack    URL
46084SERVER-WEBAPP Linksys E-Series apply.cgi directory traversal attempt (more info ...)web-application-attack    URL
46085SERVER-WEBAPP Linksys E-Series apply.cgi ping function command injection attempt (more info ...)web-application-attack 2013-3307   
46086SERVER-WEBAPP Linksys E-Series apply.cgi ping function command injection attempt (more info ...)web-application-attack 2013-3307   
52067SERVER-WEBAPP Squid HTTP Proxy cachemgr.cgi denial of service attempt (more info ...)attempted-user 2012-5643   URL
57432SERVER-WEBAPP Webmin shell index.cgi module cross site scripting attempt (more info ...)web-application-attack 2020-8821   URL
58559SERVER-WEBAPP Trend Micro Control Manager CCGIServlet ID_HIDDEN_RED_ALERT_TASK_ID SQL injection attempt (more info ...)web-application-attack    
58560SERVER-WEBAPP Trend Micro Control Manager CCGIServlet ID_HIDDEN_RED_ALERT_TASK_ID SQL injection attempt (more info ...)web-application-attack    
58561SERVER-WEBAPP Trend Micro Control Manager CCGIServlet ID_HIDDEN_RED_ALERT_TASK_ID SQL injection attempt (more info ...)web-application-attack    
59237SERVER-WEBAPP Multiple products cgi-bin command injection attempt (more info ...)web-application-attack 2016-6277   URL
59238SERVER-WEBAPP Multiple products cgi-bin command injection attempt (more info ...)web-application-attack 2016-6277   URL
59315SERVER-WEBAPP IPFire ids cgi OINKCODE command injection attempt (more info ...)web-application-attack 2017-9757   
59316SERVER-WEBAPP IPFire ids cgi OINKCODE command injection attempt (more info ...)web-application-attack 2017-9757   
59317SERVER-WEBAPP IPFire ids cgi OINKCODE command injection attempt (more info ...)web-application-attack 2017-9757   
59318SERVER-WEBAPP IPFire ids cgi OINKCODE command injection attempt (more info ...)web-application-attack 2017-9757   

 goto Top

Group: Server / Mail

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Mail / Microsoft Exchange

# of attack rules in this group: 55

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
10010SERVER-OTHER Putty Server key exchange buffer overflow attempt (more info ...)attempted-user  2002-1359      
15329SERVER-MAIL Microsoft Exchange MODPROPS memory corruption attempt (more info ...)attempted-admin  2006-0027  17908    URL
32419OS-WINDOWS Microsoft Windows SChannel ECDH key exchange heap overflow attempt (more info ...)attempted-admin  2014-6321      URL
32420OS-WINDOWS Microsoft Windows SChannel ECDH key exchange heap overflow attempt (more info ...)attempted-admin  2014-6321      URL
32421OS-WINDOWS Microsoft Windows SChannel ECDH key exchange heap overflow attempt (more info ...)attempted-admin  2014-6321      URL
37371SERVER-OTHER OpenSSH insecure roaming key exchange attempt (more info ...)attempted-user  2016-0778      URL
49100SERVER-OTHER Microsoft Exchange Server NTLM relay attack attempt (more info ...)attempted-user  2019-0724      URL
50714MALWARE-OTHER Win.Trojan.Trickbot self-signed certificate exchange attempt (more info ...)trojan-activity        URL
53380SERVER-WEBAPP Microsoft Exchange Control Panel remote code execution attempt (more info ...)attempted-admin  2020-0688      URL
53381SERVER-WEBAPP Microsoft Exchange Control Panel remote code execution attempt (more info ...)attempted-admin  2020-0688      URL
53382SERVER-WEBAPP Microsoft Exchange Control Panel static viewstate key use attempt (more info ...)attempted-admin  2020-0688      URL
53383SERVER-WEBAPP Microsoft Exchange Control Panel remote code execution attempt (more info ...)attempted-admin  2020-0688      URL
57233SERVER-OTHER Microsoft Exchange Server Unified Messaging arbitrary code execution attempt (more info ...)attempted-admin  2021-26857      URL
57234SERVER-OTHER Microsoft Exchange Server Unified Messaging arbitrary code execution attempt (more info ...)attempted-admin  2021-26857      URL
57241SERVER-WEBAPP Microsoft Exchange Server server side request forgery attempt (more info ...)attempted-admin  2021-26855      URL
57242SERVER-WEBAPP Microsoft Exchange Server server side request forgery attempt (more info ...)attempted-admin  2021-26855      URL
57243SERVER-WEBAPP Microsoft Exchange Server server side request forgery attempt (more info ...)attempted-admin  2021-26855      URL
57244SERVER-WEBAPP Microsoft Exchange Server server side request forgery attempt (more info ...)attempted-admin  2021-26855      URL
57245SERVER-WEBAPP Microsoft Exchange Server arbitrary file write attempt (more info ...)attempted-admin  2021-27065      URL
57246SERVER-WEBAPP Microsoft Exchange Server arbitrary file write attempt (more info ...)attempted-admin  2021-27065      URL
57251SERVER-MAIL Microsoft Exchange Server certificate leak attempt (more info ...)attempted-admin  2021-24085      URL
57252SERVER-MAIL Microsoft Exchange Server arbitrary file write attempt (more info ...)attempted-admin  2021-27065      URL
57253SERVER-MAIL Microsoft Exchange Server arbitrary file write attempt (more info ...)attempted-admin  2021-27065      URL
57277FILE-OTHER Metasploit Gather Exchange post-exploitation tool download attempt (more info ...)attempted-recon        URL
57278FILE-OTHER Metasploit Gather Exchange post-exploitation tool download attempt (more info ...)attempted-recon        URL
57382SERVER-OTHER Microsoft Exchange Server DLPUtils remote code execution attempt (more info ...)attempted-admin  2020-17132      URL
57487SERVER-WEBAPP Microsoft Exchange MeetingHandler remote code execution attempt (more info ...)attempted-admin  2021-28482      URL
57906SERVER-WEBAPP Microsoft Exchange autodiscover server side request forgery attempt (more info ...)attempted-admin  2022-41082      URL
57907SERVER-WEBAPP Microsoft Exchange autodiscover server side request forgery attempt (more info ...)attempted-admin  2023-21529      URL
57908SERVER-WEBAPP Microsoft Exchange autodiscover server side request forgery attempt (more info ...)attempted-admin  2022-41082      URL
57909SERVER-WEBAPP Microsoft Exchange autodiscover server side request forgery attempt (more info ...)attempted-admin  2021-34523      URL
57983SERVER-WEBAPP Microsoft Exchange autodiscover server side request forgery attempt (more info ...)attempted-admin  2022-41082      URL
58249SERVER-WEBAPP Microsoft Exchange server security feature bypass attempt (more info ...)attempted-admin  2021-34523      URL
58637SERVER-OTHER Microsoft Exchange Server remote code execution attempt (more info ...)attempted-user  2021-42321      URL
58638SERVER-OTHER Microsoft Exchange Server remote code execution attempt (more info ...)attempted-user  2021-42321      URL
60241SERVER-WEBAPP Microsoft Exchange MAPI arbitrary file write attempt (more info ...)web-application-attack  2021-26858      URL
60242SERVER-WEBAPP Microsoft Exchange MAPI arbitrary file write attempt (more info ...)web-application-attack  2021-26858      URL
60244SERVER-WEBAPP Microsoft Exchange ProxyToken information disclosure attempt (more info ...)attempted-user  2021-33766      URL
60486SERVER-WEBAPP Microsoft Exchange Server MailboxExport arbitrary file write attempt (more info ...)attempted-admin  2021-31207      URL
60642SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-user  2022-41082      URL
60670SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
60671SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
60672SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
60673SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
60674SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
60675SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
60676SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
60677SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
60678SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
61042SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-admin  2022-41082      URL
61359SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-user  2023-21706      URL
61360SERVER-WEBAPP Microsoft Exchange Server remote code execution attempt (more info ...)attempted-user  2023-21529      URL
61361MALWARE-BACKDOOR FoggyWeb Exchange backdoor access attempt (more info ...)trojan-activity        URL
61362MALWARE-BACKDOOR FoggyWeb Exchange backdoor access attempt (more info ...)trojan-activity        URL
61933SERVER-MAIL Microsoft Exchange Server remote PowerShell session type confusion attempt (more info ...)attempted-admin  2023-28310      URL


# of warning rules in this group: 50

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
658SERVER-MAIL Microsoft Windows Exchange Server 5.5 mime DOS (more info ...)attempted-dos 2000-1006 1869 10558 URL
3815SERVER-MAIL Kinesphere eXchange POP3 mail server overflow attempt (more info ...)misc-attack 2004-1945 10180  
7165MALWARE-OTHER Keylogger ab system spy runtime detection - information exchange - flowbit set 1 (more info ...)successful-recon-limited    URL
7166MALWARE-OTHER Keylogger ab system spy runtime detection - information exchange - flowbit set 2 (more info ...)successful-recon-limited    URL
7167MALWARE-OTHER Keylogger ab system spy runtime detection - information exchange - flowbit set 3 (more info ...)successful-recon-limited    URL
7168MALWARE-OTHER Keylogger ab system spy runtime detection - information exchange - flowbit set 4 (more info ...)successful-recon-limited    URL
7169MALWARE-OTHER Keylogger ab system spy runtime detection - information exchange (more info ...)successful-recon-limited    URL
12423SERVER-MAIL Microsoft Windows Exchange CDO long header name (more info ...)attempted-admin 2005-1987 15067  URL
12619SERVER-MAIL Microsoft Windows Exchange ical/vcal malformed property (more info ...)attempted-admin 2006-0027 17908  URL
15301SERVER-MAIL Exchange compressed RTF remote code execution attempt (more info ...)attempted-admin 2009-0098   URL
15964SERVER-MAIL Microsoft Windows Exchange OWA XSS and spoofing attempt (more info ...)misc-attack 2004-0203 10902  
16108MALWARE-CNC Win.Trojan.exchanger.gen2 variant outbound connection (more info ...)trojan-activity    URL
19091SERVER-OTHER OpenSSL ssl3_get_key_exchange use-after-free attempt (more info ...)attempted-admin 2010-2939 42306  
19092SERVER-OTHER OpenSSL ssl3_get_key_exchange use-after-free attempt (more info ...)attempted-admin 2010-2939 42306  
21776SERVER-MAIL Microsoft Windows Exchange MODPROPS denial of service attempt (more info ...)attempted-dos 2007-0039 23808  URL
32705SERVER-MAIL Microsoft Exchange OWA meeting invite XSS attempt (more info ...)misc-attack 2014-6326   URL
33807SERVER-MAIL Microsoft Exchange OWA X-OWA-CANARY command injection attempt (more info ...)misc-attack 2015-1628   URL
33810SERVER-OTHER Microsoft Exchange Server custom DLP policy name cross-site scripting attempt (more info ...)attempted-user 2015-1629   URL
33811SERVER-MAIL Microsoft Exchange UM Management user stored XSS attempt (more info ...)web-application-attack 2015-1630   URL
34649SERVER-OTHER OpenSSL zero-length ClientKeyExchange message denial of service attempt (more info ...)attempted-dos 2015-1787 73238  URL
34917MALWARE-CNC Win.Trojan.Critroni certificate exchange (more info ...)trojan-activity    URL
38378MALWARE-CNC Win.Trojan.Dridex certificate exchange (more info ...)trojan-activity    URL
38620MALWARE-CNC Win.Trojan.Dridex certificate exchange (more info ...)trojan-activity    URL
38621MALWARE-CNC Win.Trojan.Dridex certificate exchange (more info ...)trojan-activity    URL
39163MALWARE-CNC Win.Trojan.Dridex self-signed certificate exchange (more info ...)trojan-activity    URL
39164MALWARE-CNC Win.Trojan.Dridex self-signed certificate exchange (more info ...)trojan-activity    URL
41675MALWARE-CNC Win.Trojan.Dridex self-signed certificate exchange (more info ...)trojan-activity    URL
41676MALWARE-CNC Win.Trojan.Dridex self-signed certificate exchange (more info ...)trojan-activity    URL
44399MALWARE-CNC Win.Trojan.Trickbot self-signed certificate exchange (more info ...)trojan-activity    URL
44400MALWARE-CNC Win.Trojan.Trickbot self-signed certificate exchange (more info ...)trojan-activity    URL
44401MALWARE-CNC Win.Trojan.Trickbot self-signed certificate exchange (more info ...)trojan-activity    URL
44402MALWARE-CNC Win.Trojan.Trickbot self-signed certificate exchange (more info ...)trojan-activity    URL
44591MALWARE-CNC Win.Trojan.PandaZeus malicious certificate exchange (more info ...)trojan-activity    URL
44592MALWARE-CNC Win.Trojan.PandaZeus self-signed certificate exchange (more info ...)trojan-activity    URL
46965MALWARE-CNC Win.Trojan.Backswap self-signed certificate exchange (more info ...)trojan-activity    URL
49545MALWARE-CNC Win.Trojan.IcedID variant certificate exchange attempt (more info ...)trojan-activity    URL
49546MALWARE-CNC Win.Trojan.IcedID variant certificate exchange attempt (more info ...)trojan-activity    URL
49547MALWARE-CNC Win.Trojan.IcedID variant certificate exchange attempt (more info ...)trojan-activity    URL
49549MALWARE-CNC Win.Trojan.IcedID variant certificate exchange attempt (more info ...)trojan-activity    URL
49550MALWARE-CNC Win.Trojan.IcedID variant certificate exchange attempt (more info ...)trojan-activity    URL
49551MALWARE-CNC Win.Trojan.IcedID variant certificate exchange attempt (more info ...)trojan-activity    URL
49552MALWARE-CNC Win.Trojan.IcedID variant certificate exchange attempt (more info ...)trojan-activity    URL
54061MALWARE-CNC Win.Trojan.TrickBot variant certificate exchange attempt (more info ...)trojan-activity    URL
56554SERVER-OTHER Microsoft Exchange Server 2010 deserialization attempt (more info ...)attempted-user 2020-17144   URL
56587MALWARE-CNC Win.Backdoor.SSLBeacon variant certificate exchange attempt (more info ...)trojan-activity    URL
59843POLICY-OTHER Microsoft Exchange Export-ExchangeCertificate SOAP API call detected (more info ...)policy-violation 2020-17083   URL
59844POLICY-OTHER Microsoft Exchange New-ExchangeCertificate SOAP API call detected (more info ...)policy-violation 2020-17085   URL
59845POLICY-OTHER Microsoft Exchange Import-TransportRuleCollection SOAP request detected (more info ...)policy-violation 2020-17117   URL
60050MALWARE-CNC Win.Rootkit.Daxin HTTP host information exchange attempt (more info ...)trojan-activity    
61736POLICY-OTHER Microsoft Exchange Web Services brute force login attempt (more info ...)policy-violation    

 goto Top

Group: Server / Mail / Sendmail

# of attack rules in this group: 1

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
42354SERVER-WEBAPP Squirrelmail sendmail delivery parameter injection attempt (more info ...)web-application-attack  2017-7692      


# of warning rules in this group: 26

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
655SERVER-MAIL Sendmail 8.6.9 exploit (more info ...)attempted-admin 1999-0204 2311  
659SERVER-MAIL Sendmail expn decode (more info ...)attempted-recon 1999-0096  10248 
662SERVER-MAIL Sendmail 5.5.5 exploit (more info ...)attempted-admin 1999-0203  10258 
663SERVER-MAIL Sendmail rcpt to command attempt (more info ...)attempted-admin 1999-0095 1  
664SERVER-MAIL Sendmail RCPT TO decode attempt (more info ...)attempted-admin 1999-0203 2308  
665SERVER-MAIL Sendmail 5.6.5 exploit (more info ...)attempted-user 1999-0203 2308  
667SERVER-MAIL Sendmail 8.6.10 exploit (more info ...)attempted-user 1999-0204 2311  
668SERVER-MAIL Sendmail 8.6.10 exploit (more info ...)attempted-user 1999-0204 2311  
669SERVER-MAIL Sendmail 8.6.9 exploit (more info ...)attempted-user 1999-0204 2311  
670SERVER-MAIL Sendmail 8.6.9 exploit (more info ...)attempted-user 1999-0204 2311  
671SERVER-MAIL Sendmail 8.6.9c exploit (more info ...)attempted-user 1999-0204 2311  
815SERVER-WEBAPP websendmail access (more info ...)attempted-recon 1999-0196 2077 10301 
1526SERVER-WEBAPP basilix sendmail.inc access (more info ...)web-application-activity 2001-1044 2198 10601 
1659SERVER-OTHER Adobe Coldfusion sendmail.cfm access (more info ...)attempted-recon 2001-0535   
2261SERVER-MAIL Sendmail SEND FROM prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991 11316 
2262SERVER-MAIL Sendmail SEND FROM prescan too long addresses overflow (more info ...)misc-attack 2003-0161 7230 11499 
2263SERVER-MAIL Sendmail SAML FROM prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991  
2264SERVER-MAIL Sendmail SAML FROM prescan too long addresses overflow (more info ...)misc-attack 2003-0161 7230 11499 
2265SERVER-MAIL Sendmail SOML FROM prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991  
2266SERVER-MAIL Sendmail SOML FROM prescan too long addresses overflow (more info ...)misc-attack 2003-0161 7230 11499 
2267SERVER-MAIL Sendmail MAIL FROM prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991  
2268SERVER-MAIL Sendmail MAIL FROM prescan too long addresses overflow (more info ...)attempted-admin 2003-0161 7230 11499 
2269SERVER-MAIL Sendmail RCPT TO prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991  
2270SERVER-MAIL Sendmail RCPT TO prescan too long addresses overflow (more info ...)attempted-admin 2003-0694 7230 11499 
15936SERVER-MAIL Sendmail identd command parsing vulnerability (more info ...)attempted-admin 1999-0204 2311  
16057SERVER-MAIL Sendmail smtp timeout buffer overflow attempt (more info ...)attempted-admin 2006-0058 17192  

 goto Top

Group: Server / Mail / POP3

# of attack rules in this group: 1

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
20614SERVER-MAIL Axigen POP3 server remote format string exploit (more info ...)attempted-admin    22603    


# of warning rules in this group: 2

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
27179BROWSER-PLUGINS Oracle document capture EMPOP3Lib ActiveX clsid access attempt (more info ...)attempted-user 2010-3591 45851  
37683POLICY-OTHER junk rule to autoenable pop3.stat flowbit (more info ...)misc-activity    

 goto Top

Group: Server / Mail / IMAP

# of attack rules in this group: 19

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1842PROTOCOL-IMAP login buffer overflow attempt (more info ...)attempted-user  2007-3925  502  10125  
3007PROTOCOL-IMAP command overflow attempt (more info ...)misc-attack  2005-3155  15753  15771  
3066PROTOCOL-IMAP APPEND overflow attempt (more info ...)misc-attack  2006-6425  21729  15867  
3067PROTOCOL-IMAP examine literal overflow attempt (more info ...)misc-attack  2004-1211  11775  15867  
3069PROTOCOL-IMAP fetch literal overflow attempt (more info ...)misc-attack  2004-1211  11775  15867  
3070PROTOCOL-IMAP fetch overflow attempt (more info ...)misc-attack  2004-1211  11775  15867  
3071PROTOCOL-IMAP status literal overflow attempt (more info ...)misc-attack  2004-1211  15491  15867  
3072PROTOCOL-IMAP STATUS overflow attempt (more info ...)misc-attack  2017-1274  15491  15867  
3073PROTOCOL-IMAP SUBSCRIBE literal overflow attempt (more info ...)attempted-admin  2007-3510  26219  15867  
3074PROTOCOL-IMAP SUBSCRIBE overflow attempt (more info ...)attempted-admin  2007-3510  26219  15867  
3075PROTOCOL-IMAP unsubscribe literal overflow attempt (more info ...)misc-attack  2004-1211  11775  15867  
3076PROTOCOL-IMAP UNSUBSCRIBE overflow attempt (more info ...)attempted-admin  2005-3189  15488  15867  
5702PROTOCOL-IMAP subscribe directory traversal attempt (more info ...)attempted-admin  2007-3510  26219  15867  
5704PROTOCOL-IMAP SELECT overflow attempt (more info ...)misc-attack  2006-1255  15006    
11004PROTOCOL-IMAP CRAM-MD5 authentication request detected (more info ...)protocol-command-decode        URL
13359APP-DETECT failed IMAP login attempt - invalid username/password (more info ...)misc-activity        URL
15484PROTOCOL-IMAP CRAM-MD5 authentication method buffer overflow attempt (more info ...)attempted-admin  2007-1675  23172    
43067PROTOCOL-IMAP IMAP CRAM-MD5 authentication attempt (more info ...)protocol-command-decode  2007-1675      
48417SERVER-WEBAPP PrestaShop PS_SAV_IMAP_URL command injection attempt (more info ...)attempted-user        URL


# of warning rules in this group: 49

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1755PROTOCOL-IMAP partial body buffer overflow attempt (more info ...)misc-attack 2002-0379 4713 10966 
1844PROTOCOL-IMAP authenticate overflow attempt (more info ...)misc-attack 1999-0042 130 10292 
1845PROTOCOL-IMAP list literal overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
1902PROTOCOL-IMAP lsub literal overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
1903PROTOCOL-IMAP rename overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
1904PROTOCOL-IMAP find overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
1930PROTOCOL-IMAP auth literal overflow attempt (more info ...)misc-attack 2006-6424 21724  
1993PROTOCOL-IMAP login literal buffer overflow attempt (more info ...)misc-attack 2007-0221 6298 12532 
2046PROTOCOL-IMAP partial body.peek buffer overflow attempt (more info ...)misc-attack 2002-0379 4713 10966 
2105PROTOCOL-IMAP authenticate literal overflow attempt (more info ...)misc-attack 2006-6424 21724 10292 
2106PROTOCOL-IMAP lsub overflow attempt (more info ...)misc-attack 2005-3155 15006 10374 
2107PROTOCOL-IMAP create buffer overflow attempt (more info ...)misc-attack 2003-1470 7446  
2118PROTOCOL-IMAP list overflow attempt (more info ...)misc-attack 2005-3155 15006 10374 
2119PROTOCOL-IMAP rename literal overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
2120PROTOCOL-IMAP create literal buffer overflow attempt (more info ...)misc-attack 2003-1470 7446  
2273PROTOCOL-IMAP login brute force attempt (more info ...)suspicious-login    URL
2330PROTOCOL-IMAP auth overflow attempt (more info ...)misc-attack 2003-1177 8861 11910 
2664PROTOCOL-IMAP login format string attempt (more info ...)attempted-admin 2004-0777 10976  
2665PROTOCOL-IMAP login literal format string attempt (more info ...)attempted-admin 2007-0221 10976  URL
3008PROTOCOL-IMAP delete literal overflow attempt (more info ...)misc-attack 2005-1520 11675 15771 
3058PROTOCOL-IMAP copy literal overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
4645PROTOCOL-IMAP search format string attempt (more info ...)attempted-admin 2005-2878 10976  
4646PROTOCOL-IMAP search literal format string attempt (more info ...)attempted-admin 2004-0777 10976  
5696PROTOCOL-IMAP delete directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5697PROTOCOL-IMAP examine directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5698PROTOCOL-IMAP list directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5699PROTOCOL-IMAP lsub directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5700PROTOCOL-IMAP rename directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5701PROTOCOL-IMAP status directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5703PROTOCOL-IMAP unsubscribe directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5705PROTOCOL-IMAP CAPABILITY overflow attempt (more info ...)misc-attack 2005-3155 15006  
10011SERVER-MAIL Multiple IMAP servers APPEND command buffer overflow attempt (more info ...)misc-attack 2017-1274 21723  
13663SERVER-MAIL Alt-N MDaemon IMAP Server FETCH command buffer overflow attempt (more info ...)attempted-admin 2008-1358 28245  URL
13921SERVER-MAIL Altrium Software MERCUR IMAPD NTLMSSP command handling memory corruption attempt (more info ...)attempted-admin 2007-1578 23058  URL
16781BROWSER-PLUGINS EasyMail IMAP4 ActiveX function call access (more info ...)attempted-user 2007-4607 25467  
17239SERVER-MAIL Multiple IMAP servers CREATE command buffer overflow attempt (more info ...)attempted-admin 2017-1274 41704  
17240SERVER-MAIL Multiple IMAP server literal CREATE command buffer overflow attempt (more info ...)attempted-admin 2010-2777 41704  
17503SERVER-MAIL MailEnable IMAP Service Invalid Command Buffer Overlow LOGIN (more info ...)attempted-admin  21252  
24599FILE-IDENTIFY Alt-N MDaemon IMAP Server (more info ...)attempted-admin 2008-1358 28245  URL
35933SERVER-WEBAPP Qualcomm WorldMail IMAP select directory traversal attempt (more info ...)web-application-attack 2005-3189 15488  
35934SERVER-WEBAPP Qualcomm WorldMail IMAP append directory traversal attempt (more info ...)web-application-attack 2005-3189 15488  
37375SERVER-MAIL Multiple IMAP servers EXAMINE command buffer overflow attempt (more info ...)attempted-admin 2017-1274   
37845POLICY-OTHER junk rule to autoenable imap.cram_md5 flowbit (more info ...)misc-activity    
46484SERVER-MAIL Multiple IMAP servers DELETE command buffer overflow attempt (more info ...)attempted-admin 2017-1274   
47509SERVER-WEBAPP RoundCube WebMail IMAP command injection attempt (more info ...)attempted-user 2018-9846   
47510SERVER-WEBAPP RoundCube WebMail IMAP command injection attempt (more info ...)attempted-user 2018-9846   
52019SERVER-MAIL MailEnable Mail Server IMAP client command buffer overflow attempt (more info ...)attempted-user 2004-2501   
59573PROTOCOL-IMAP Dovecot Pigeonhole string parsing remote code execution attempt (more info ...)attempted-admin 2019-11500   
59782PROTOCOL-IMAP Dovecot Pigeonhole string parsing remote code execution attempt (more info ...)attempted-admin 2019-11500   

 goto Top

Group: Server / Mail / SMTP

# of attack rules in this group: 8

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
17224SERVER-MAIL McAfee WebShield SMTP bounce message format string attempt (more info ...)attempted-admin  2006-0559  16742    
26802MALWARE-OTHER WIN.Worm.Beagle.AZ SMTP propagation detection (more info ...)trojan-activity        URL
39903FILE-OFFICE Microsoft Windows RTF file with embedded object package SMTP upload attempt (more info ...)misc-activity        URL
39907MALWARE-OTHER Rtf.Dropper.Agent-1404614 SMTP upload attempt (more info ...)trojan-activity        URL
50100INDICATOR-COMPROMISE Responder poisoner SMTP attack attempt (more info ...)misc-attack        URL
53431SERVER-MAIL OpenSMTPD smtp_mailaddr command injection attempt (more info ...)attempted-admin  2020-7247      
54122SERVER-OTHER OpenSMTPD mta_io remote command injection attempt (more info ...)attempted-admin  2020-8794      URL
54388SERVER-OTHER OpenSMTPD mta_io remote command injection attempt (more info ...)attempted-admin  2020-8794      URL


# of warning rules in this group: 123

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
567SERVER-MAIL SMTP relaying denied (more info ...)misc-activity    URL
657SERVER-MAIL Netmanager chameleon SMTPd buffer overflow attempt (more info ...)attempted-admin 1999-0261 2387  
5790MALWARE-OTHER Keylogger pc actmon pro runtime detection - smtp (more info ...)successful-recon-limited    URL
5880MALWARE-OTHER Keylogger spyagent runtime detect - smtp delivery (more info ...)successful-recon-limited    URL
6125MALWARE-BACKDOOR dkangel runtime detection - smtp (more info ...)trojan-activity    URL
6126MALWARE-BACKDOOR dkangel runtime detection - smtp (more info ...)trojan-activity    URL
6207MALWARE-OTHER Keylogger winsession runtime detection - smtp (more info ...)successful-recon-limited    URL
6301MALWARE-BACKDOOR cia 1.3 runtime detection - smtp notification (more info ...)trojan-activity    URL
6397MALWARE-BACKDOOR http rat runtime detection - smtp (more info ...)trojan-activity    URL
6477MALWARE-TOOLS Hacker-Tool beee runtime detection - smtp (more info ...)misc-activity    URL
7184MALWARE-OTHER Keylogger 007 spy software runtime detection - smtp (more info ...)successful-recon-limited    URL
7551MALWARE-OTHER Keylogger ardamax keylogger runtime detection - smtp (more info ...)successful-recon-limited    URL
8544MALWARE-OTHER Keylogger nicespy runtime detection - smtp (more info ...)successful-recon-limited    URL
9326MALWARE-OTHER netsky.p smtp propagation detection (more info ...)trojan-activity    URL
9327MALWARE-OTHER netsky.af smtp propagation detection (more info ...)trojan-activity    URL
9328MALWARE-OTHER zhangpo smtp propagation detection (more info ...)trojan-activity    URL
9329MALWARE-CNC yarner.b smtp propagation detection (more info ...)trojan-activity    URL
9330MALWARE-OTHER mydoom.e smtp propagation detection (more info ...)trojan-activity    URL
9331MALWARE-OTHER mydoom.m smtp propagation detection (more info ...)trojan-activity    URL
9332MALWARE-OTHER mimail.a smtp propagation detection (more info ...)trojan-activity    URL
9333MALWARE-OTHER mimail.e smtp propagation detection (more info ...)trojan-activity    URL
9334MALWARE-OTHER lovgate.c smtp propagation detection (more info ...)trojan-activity    URL
9335MALWARE-OTHER netsky.b smtp propagation detection (more info ...)trojan-activity    URL
9336MALWARE-OTHER netsky.t smtp propagation detection (more info ...)trojan-activity    URL
9337MALWARE-OTHER netsky.x smtp propagation detection (more info ...)trojan-activity    URL
9338MALWARE-OTHER mydoom.i smtp propagation detection (more info ...)trojan-activity    URL
9342MALWARE-OTHER paroc.a smtp propagation detection (more info ...)trojan-activity    URL
9343MALWARE-OTHER kadra smtp propagation detection (more info ...)trojan-activity    URL
9344MALWARE-OTHER kindal smtp propagation detection (more info ...)trojan-activity    URL
9345MALWARE-OTHER kipis.a smtp propagation detection (more info ...)trojan-activity    URL
9348MALWARE-OTHER morbex smtp propagation detection (more info ...)trojan-activity    URL
9349MALWARE-OTHER plemood smtp propagation detection (more info ...)trojan-activity    URL
9350MALWARE-OTHER mimail.k smtp propagation detection (more info ...)trojan-activity    URL
9352MALWARE-OTHER lovgate.a smtp propagation detection (more info ...)trojan-activity    URL
9358MALWARE-OTHER fizzer smtp propagation detection (more info ...)trojan-activity    URL
9359MALWARE-OTHER zafi.b smtp propagation detection (more info ...)trojan-activity    URL
9360MALWARE-OTHER cult.b smtp propagation detection (more info ...)trojan-activity    URL
9361MALWARE-OTHER mimail.l smtp propagation detection (more info ...)trojan-activity    URL
9362MALWARE-OTHER mimail.m smtp propagation detection (more info ...)trojan-activity    URL
9365MALWARE-OTHER cult.c smtp propagation detection (more info ...)trojan-activity    URL
9366MALWARE-OTHER mimail.s smtp propagation detection (more info ...)trojan-activity    URL
9367MALWARE-OTHER anset.b smtp propagation detection (more info ...)trojan-activity    URL
9368MALWARE-OTHER agist.a smtp propagation detection (more info ...)trojan-activity    URL
9369MALWARE-OTHER atak.a smtp propagation detection (more info ...)trojan-activity    URL
9370MALWARE-OTHER bagle.b smtp propagation detection (more info ...)trojan-activity    URL
9371MALWARE-OTHER bagle.e smtp propagation detection (more info ...)trojan-activity    URL
9372MALWARE-OTHER blebla.a smtp propagation detection (more info ...)trojan-activity    URL
9373MALWARE-OTHER clepa smtp propagation detection (more info ...)trojan-activity    URL
9374MALWARE-OTHER creepy.b smtp propagation detection (more info ...)trojan-activity    URL
9375MALWARE-OTHER duksten.c smtp propagation detection (more info ...)trojan-activity    URL
9376MALWARE-OTHER fishlet.a smtp propagation detection (more info ...)trojan-activity    URL
9377MALWARE-OTHER mydoom.g smtp propagation detection (more info ...)trojan-activity    URL
9378MALWARE-OTHER netsky.q smtp propagation detection (more info ...)trojan-activity    URL
9379MALWARE-OTHER netsky.s smtp propagation detection (more info ...)trojan-activity    URL
9381MALWARE-OTHER lara smtp propagation detection (more info ...)trojan-activity    URL
9382MALWARE-OTHER fearso.c smtp propagation detection (more info ...)trojan-activity    URL
9383MALWARE-OTHER netsky.y smtp propagation detection (more info ...)trojan-activity    URL
9384MALWARE-OTHER beglur.a smtp propagation detection (more info ...)trojan-activity    URL
9385MALWARE-OTHER collo.a smtp propagation detection (more info ...)trojan-activity    URL
9386MALWARE-OTHER bagle.f smtp propagation detection (more info ...)trojan-activity    URL
9388MALWARE-OTHER mimail.g smtp propagation detection (more info ...)trojan-activity    URL
9389MALWARE-OTHER bagle.i smtp propagation detection (more info ...)trojan-activity    URL
9391MALWARE-OTHER mimail.i smtp propagation detection (more info ...)trojan-activity    URL
9392MALWARE-OTHER bagle.j smtp propagation detection (more info ...)trojan-activity    URL
9393MALWARE-OTHER bagle.k smtp propagation detection (more info ...)trojan-activity    URL
9394MALWARE-OTHER bagle.n smtp propagation detection (more info ...)trojan-activity    URL
9397MALWARE-OTHER neysid smtp propagation detection (more info ...)trojan-activity    URL
9398MALWARE-OTHER totilix.a smtp propagation detection (more info ...)trojan-activity    URL
9399MALWARE-OTHER hanged smtp propagation detection (more info ...)trojan-activity    URL
9400MALWARE-OTHER abotus smtp propagation detection (more info ...)trojan-activity    URL
9403MALWARE-OTHER netsky.aa smtp propagation detection (more info ...)trojan-activity    URL
9404MALWARE-OTHER netsky.ac smtp propagation detection (more info ...)trojan-activity    URL
9406MALWARE-OTHER lovgate.e smtp propagation detection (more info ...)trojan-activity    URL
9408MALWARE-OTHER lacrow smtp propagation detection (more info ...)trojan-activity    URL
9409MALWARE-OTHER atak.b smtp propagation detection (more info ...)trojan-activity    URL
9410MALWARE-OTHER netsky.z smtp propagation detection (more info ...)trojan-activity    URL
9411MALWARE-OTHER mimail.f smtp propagation detection (more info ...)trojan-activity    URL
9413MALWARE-OTHER ganda smtp propagation detection (more info ...)trojan-activity    URL
9414MALWARE-OTHER lovelorn.a smtp propagation detection (more info ...)trojan-activity    URL
9415MALWARE-OTHER plexus.a smtp propagation detection (more info ...)trojan-activity    URL
9416MALWARE-OTHER bagle.at smtp propagation detection (more info ...)trojan-activity    URL
9417MALWARE-OTHER bagle.a smtp propagation detection (more info ...)trojan-activity    URL
9827MALWARE-OTHER Keylogger paq keylog runtime detection - smtp (more info ...)successful-recon-limited    URL
10065MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10066MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10067MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10068MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10069MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10070MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10071MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10072MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10073MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10074MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10075MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10076MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10077MALWARE-CNC Win.Trojan.Peacomm smtp propagation detection (more info ...)trojan-activity    
10078MALWARE-OTHER W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity    
10079MALWARE-OTHER W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity    
10080MALWARE-OTHER W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity    
10081MALWARE-OTHER W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity    
10082MALWARE-OTHER W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity    
10083MALWARE-OTHER W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity    
10088MALWARE-OTHER Keylogger beyond Keylogger runtime detection - log sent by smtp (more info ...)successful-recon-limited    URL
10453MALWARE-BACKDOOR zalivator 1.4.2 pro runtime detection - smtp notification (more info ...)trojan-activity    URL
11305PUA-ADWARE Snoopware childwebguardian outbound connection - send log through smtp (more info ...)successful-recon-limited    URL
13651MALWARE-OTHER Keylogger family cyber alert runtime detection - smtp traffic for recorded activities (more info ...)successful-recon-limited    URL
13923SERVER-MAIL MailEnable SMTP HELO command denial of service attempt (more info ...)attempted-dos 2006-3277 18630  
16025SERVER-MAIL MailEnable SMTP service SPF lookup buffer overflow attempt (more info ...)attempted-admin 2006-4616 20091  
16193SERVER-MAIL Novell GroupWise Internet Agent SMTP AUTH LOGIN command buffer overflow attempt (more info ...)attempted-admin 2009-1636 35065  
16201SERVER-MAIL Ipswitch Collaboration Suite SMTP format string exploit attempt (more info ...)attempted-admin 2005-2931 15752  
16534SERVER-OTHER Windows Server2000/2003/2008 SMTP service DNS MX lookup denial of service attempt (more info ...)attempted-dos 2010-0024 39308  URL
17099BROWSER-PLUGINS CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX clsid access (more info ...)attempted-user    
17101BROWSER-PLUGINS CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX function call access (more info ...)attempted-user    
18765SERVER-MAIL Majordomo2 smtp directory traversal attempt (more info ...)web-application-attack 2011-0049 46127  
27725OS-MOBILE Android SMSAgent.C outbound SMTP communication (more info ...)trojan-activity    URL
32959PROTOCOL-DNS Microsoft SMTP excessive answer records buffer overflow attempt (more info ...)attempted-user 2004-0840   
33147MALWARE-CNC Win.Trojan.Agent variant SMTP reporting attempt (more info ...)trojan-activity    
33148MALWARE-CNC Win.Trojan.Agent variant SMTP reporting attempt (more info ...)trojan-activity    
43136SERVER-MAIL SysGauge SMTP response buffer overflow (more info ...)attempted-user    
49541POLICY-OTHER WordPress Easy WP SMTP plugin log file access attempt (more info ...)policy-violation    URL
49542POLICY-OTHER WordPress Easy WP SMTP plugin config settings import attempt (more info ...)policy-violation    URL
49543POLICY-OTHER WordPress Easy WP SMTP plugin config settings export attempt (more info ...)policy-violation    URL
56905POLICY-OTHER WordPress Easy WP SMTP plugin debug log file access attempt (more info ...)policy-violation 2020-35234   URL

 goto Top

Group: Server / Database

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Database / Microsoft

# of attack rules in this group: 11

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
35198SERVER-MSSQL Microsoft SQL Server transcational replication and showxmlplan enabled remote code execution attempt (more info ...)attempted-user  2015-1762      URL
35359SERVER-WEBAPP Cacti selected_items SQL injection attempt (more info ...)web-application-attack        URL
42424POLICY-OTHER MSSQL CLR permission set to unsafe attempt (more info ...)attempted-admin        URL
48170SERVER-WEBAPP Joomla Component eXtroForms SQL injection attempt (more info ...)web-application-attack        URL
48171SERVER-WEBAPP Joomla Component eXtroForms SQL injection attempt (more info ...)web-application-attack        URL
50101INDICATOR-COMPROMISE Responder poisoner MSSQL attack attempt (more info ...)misc-attack        URL
59744SERVER-WEBAPP TuziCMS SQL injection attempt (more info ...)web-application-attack  2022-23882      URL
59745SERVER-WEBAPP TuziCMS SQL injection attempt (more info ...)web-application-attack  2022-23882      URL
60171SERVER-WEBAPP Moodle LMS SQL injection attempt (more info ...)web-application-attack  2022-0332      
60172SERVER-WEBAPP Moodle LMS SQL injection attempt (more info ...)web-application-attack  2022-0332      
60173SERVER-WEBAPP Moodle LMS SQL injection attempt (more info ...)web-application-attack  2022-0332      


# of warning rules in this group: 78

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
686SERVER-MSSQL xp_reg* - registry access (more info ...)attempted-user 2002-0642 5205 10642 URL
689SERVER-MSSQL xp_reg* registry access (more info ...)attempted-user 2002-0642 5205 10642 URL
695SERVER-MSSQL xp_sprintf possible buffer overflow (more info ...)attempted-user  1204  URL
704SERVER-MSSQL xp_sprintf possible buffer overflow (more info ...)attempted-user 2001-0542 3733  URL
1386SERVER-MSSQL raiserror possible buffer overflow (more info ...)attempted-user 2001-0542 3733  URL
8496SERVER-MSSQL sp_oacreate unicode vulnerable function attempt (more info ...)attempted-admin    URL
8497SERVER-MSSQL sp_oacreate vulnerable function attempt (more info ...)attempted-admin    URL
8498SERVER-MSSQL sp_oacreate unicode vulnerable function attempt (more info ...)attempted-admin    URL
8499SERVER-MSSQL xp_displayparamstmt unicode vulnerable function attempt (more info ...)attempted-admin 2000-1081 2030  URL
8500SERVER-MSSQL xp_displayparamstmt unicode vulnerable function attempt (more info ...)attempted-admin 2000-1081 2030  URL
8501SERVER-MSSQL xp_displayparamstmt vulnerable function attempt (more info ...)attempted-admin 2000-1081 2030  URL
8502SERVER-MSSQL xp_enumresultset unicode vulnerable function attempt (more info ...)attempted-admin 2000-1082 2031  URL
8503SERVER-MSSQL xp_enumresultset unicode vulnerable function attempt (more info ...)attempted-admin 2000-1082 2031  URL
8504SERVER-MSSQL xp_enumresultset vulnerable function attempt (more info ...)attempted-admin 2000-1082 2031  URL
8505SERVER-MSSQL xp_oadestroy unicode vulnerable function attempt (more info ...)attempted-admin    URL
8506SERVER-MSSQL xp_oadestroy unicode vulnerable function attempt (more info ...)attempted-admin    URL
8507SERVER-MSSQL xp_oadestroy vulnerable function attempt (more info ...)attempted-admin    URL
8508SERVER-MSSQL xp_oagetproperty unicode vulnerable function attempt (more info ...)attempted-admin    URL
8509SERVER-MSSQL xp_oagetproperty unicode vulnerable function attempt (more info ...)attempted-admin    URL
8510SERVER-MSSQL xp_oagetproperty vulnerable function attempt (more info ...)attempted-admin    URL
8511SERVER-MSSQL xp_oamethod unicode vulnerable function attempt (more info ...)attempted-admin    URL
8512SERVER-MSSQL xp_oamethod vulnerable function attempt (more info ...)attempted-admin    URL
8513SERVER-MSSQL xp_oamethod unicode vulnerable function attempt (more info ...)attempted-admin    URL
8514SERVER-MSSQL xp_oasetproperty unicode vulnerable function attempt (more info ...)attempted-admin    URL
8515SERVER-MSSQL xp_oasetproperty unicode vulnerable function attempt (more info ...)attempted-admin    URL
8516SERVER-MSSQL xp_oasetproperty vulnerable function attempt (more info ...)attempted-admin    URL
8517SERVER-MSSQL xp_peekqueue unicode vulnerable function attempt (more info ...)attempted-admin 2000-1085 2041  URL
8518SERVER-MSSQL xp_peekqueue unicode vulnerable function attempt (more info ...)attempted-admin 2000-1085 2041  URL
8519SERVER-MSSQL xp_peekqueue vulnerable function attempt (more info ...)attempted-admin 2000-1085 2041  URL
8520SERVER-MSSQL xp_printstatements unicode vulnerable function attempt (more info ...)attempted-admin 2000-1086 2041  URL
8521SERVER-MSSQL xp_printstatements unicode vulnerable function attempt (more info ...)attempted-admin 2000-1086 2041  URL
8522SERVER-MSSQL xp_printstatements vulnerable function attempt (more info ...)attempted-admin 2000-1086 2041  URL
8523SERVER-MSSQL xp_proxiedmetadata unicode vulnerable function attempt (more info ...)attempted-admin 2000-1087 2024  URL
8524SERVER-MSSQL xp_proxiedmetadata unicode vulnerable function attempt (more info ...)attempted-admin 2000-1087 2024  URL
8525SERVER-MSSQL xp_proxiedmetadata vulnerable function attempt (more info ...)attempted-admin 2000-1087 2024  URL
8526SERVER-MSSQL xp_SetSQLSecurity unicode vulnerable function attempt (more info ...)attempted-admin 2000-1086 2043  URL
8527SERVER-MSSQL xp_SetSQLSecurity unicode vulnerable function attempt (more info ...)attempted-admin 2000-1086 2043  URL
8528SERVER-MSSQL xp_SetSQLSecurity vulnerable function attempt (more info ...)attempted-admin 2000-1086 2043  URL
8529SERVER-MSSQL xp_showcolv unicode vulnerable function attempt (more info ...)attempted-admin 2000-1083 2038  URL
8530SERVER-MSSQL xp_showcolv unicode vulnerable function attempt (more info ...)attempted-admin 2000-1083 2038  URL
8531SERVER-MSSQL xp_showcolv vulnerable function attempt (more info ...)attempted-admin 2000-1083 2038  URL
8532SERVER-MSSQL xp_sqlagent_monitor unicode vulnerable function attempt (more info ...)attempted-admin    URL
8533SERVER-MSSQL xp_sqlagent_monitor vulnerable function attempt (more info ...)attempted-admin    URL
8534SERVER-MSSQL xp_sqlagent_monitor unicode vulnerable function attempt (more info ...)attempted-admin    URL
8535SERVER-MSSQL xp_sqlinventory unicode vulnerable function attempt (more info ...)attempted-admin    URL
8536SERVER-MSSQL xp_sqlinventory vulnerable function attempt (more info ...)attempted-admin    URL
8537SERVER-MSSQL xp_sqlinventory unicode vulnerable function attempt (more info ...)attempted-admin    URL
8538SERVER-MSSQL xp_updatecolvbm unicode vulnerable function attempt (more info ...)attempted-admin 2000-1084 2039  URL
8539SERVER-MSSQL xp_updatecolvbm unicode vulnerable function attempt (more info ...)attempted-admin 2000-1084 2039  URL
8540SERVER-MSSQL xp_updatecolvbm vulnerable function attempt (more info ...)attempted-admin 2000-1084 2039  URL
11264SERVER-MSSQL Microsoft SQL Server 2000 Server hello buffer overflow attempt (more info ...)attempted-admin 2002-1123 5411  URL
12444BROWSER-PLUGINS Microsoft SQL Server Distributed Management Objects ActiveX clsid access (more info ...)attempted-user 2007-4814 25594  
12446BROWSER-PLUGINS Microsoft SQL Server Distributed Management Objects ActiveX function call access (more info ...)attempted-user 2007-4814 25594  
13888FILE-OTHER Microsoft SQL Server Backup Database File integer overflow attempt (more info ...)attempted-admin 2008-0107   URL
13889FILE-OTHER Microsoft SQL Server Backup Database File integer overflow attempt (more info ...)attempted-admin 2008-0107   URL
13890FILE-OTHER Microsoft SQL Server Backup Database File integer overflow attempt (more info ...)attempted-admin 2008-0107   URL
13891SERVER-MSSQL Memory page overwrite attempt (more info ...)attempted-admin 2008-0106   URL
13892SERVER-MSSQL Convert function style overwrite (more info ...)attempted-admin 2008-0086   URL
14756BROWSER-PLUGINS Microsoft SQL Server 2000 Client Components ActiveX clsid access (more info ...)attempted-user 2008-4110 31129  
14758BROWSER-PLUGINS Microsoft SQL Server 2000 Client Components ActiveX function call access (more info ...)attempted-user 2008-4110 31129  
15143SERVER-MSSQL sp_replwritetovarbin unicode vulnerable function attempt (more info ...)attempted-admin 2008-5416 32710  URL
15144SERVER-MSSQL sp_replwritetovarbin vulnerable function attempt (more info ...)attempted-admin 2008-5416 32710  URL
16073OS-WINDOWS MS-SQL convert function unicode overflow (more info ...)attempted-admin 2008-0086   URL
16208SERVER-MSSQL Microsoft SQL Server Distributed Management Objects overflow attempt (more info ...)attempted-user 2007-4814 25594  
17307SERVER-MSSQL Microsoft SQL Server INSERT Statement Buffer Overflow attempt (more info ...)policy-violation 2008-0106   
21084SERVER-MSSQL MSSQL CONVERT function buffer overflow attempt (more info ...)attempted-admin 2008-0086   URL
21085SERVER-MSSQL MSSQL CONVERT function unicode buffer overflow attempt (more info ...)attempted-admin 2008-0086   URL
21663SERVER-OTHER CA BrightStor Agent for Microsoft SQL overflow attempt (more info ...)attempted-admin 2005-1272 14453  
24355SERVER-MSSQL Microsoft SQL Server Reporting Services cross site scripting attempt (more info ...)web-application-attack 2012-2552   URL
24356SERVER-MSSQL Microsoft SQL Server Reporting Services cross site scripting attempt (more info ...)attempted-user 2012-2552   URL
29028SERVER-MSSQL Microsoft SQL Server TDS packet fragment handling remote denial of service attempt (more info ...)attempted-dos 2004-1560 11265  
29029SERVER-MSSQL Microsoft SQL Server TDS packet fragment handling remote denial of service attempt (more info ...)attempted-dos 2004-1560 11265  
32754BROWSER-PLUGINS Microsoft SQL Server 2000 Client Components ActiveX clsid access (more info ...)attempted-user 2008-4110 31129  
32768SQL PK-CMS SQL injection attempt (more info ...)web-application-attack    URL
34136MALWARE-CNC Win.Trojan.Banload variant MSSQL response (more info ...)trojan-activity    URL
39449SERVER-MSSQL Microsoft SQL Server sp_addsrvrolemember privilege escalation attempt (more info ...)attempted-admin    URL
43074INDICATOR-COMPROMISE SysAid mssql potentially malicious new user creation attempt (more info ...)attempted-admin 2015-3001   
43075INDICATOR-COMPROMISE SysAid mssql potentially malicious user permissions creation (more info ...)attempted-admin 2015-3001   

 goto Top

Group: Server / Database / Oracle

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Database / MySQL

# of attack rules in this group: 21

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3665SERVER-MYSQL server greeting (more info ...)attempted-user  2004-0627  10655  12639  URL
3666SERVER-MYSQL server greeting finished (more info ...)attempted-user  2004-0627  10655  12639  URL
3667SERVER-MYSQL protocol 41 client authentication bypass attempt (more info ...)misc-attack  2004-0627  10655  12639  URL
3668SERVER-MYSQL client authentication bypass attempt (more info ...)misc-attack  2004-0627  10655  12639  URL
3669SERVER-MYSQL protocol 41 secure client overflow attempt (more info ...)misc-attack  2004-0627  10655  12639  URL
3670SERVER-MYSQL secure client overflow attempt (more info ...)misc-attack  2004-0627  10655  12639  URL
3671SERVER-MYSQL protocol 41 client overflow attempt (more info ...)misc-attack  2004-0627  10655  12639  URL
3672SERVER-MYSQL client overflow attempt (more info ...)misc-attack  2004-0627  10655  12639  URL
15951SERVER-MYSQL MaxDB Webtool GET command overflow attempt (more info ...)attempted-user  2005-0684  13368    
32533SERVER-MYSQL Oracle MySQL Server XPath memory Corruption attempt (more info ...)denial-of-service  2014-0384      
35890SERVER-MYSQL Oracle MySQL XPath number function uninitialized pointer arbitrary code execution attempt (more info ...)attempted-admin        
35891SERVER-MYSQL Oracle MySQL XPath number function uninitialized pointer arbitrary code execution attempt (more info ...)attempted-admin        
37077SERVER-WEBAPP Joomla JDatabaseDriverMysqli unserialize code execution attempt (more info ...)attempted-user  2015-8562      URL
37078SERVER-WEBAPP Joomla JDatabaseDriverMysqli unserialize code execution attempt (more info ...)attempted-user  2015-8562      URL
40253SERVER-MYSQL Multiple SQL products privilege escalation attempt (more info ...)attempted-admin  2016-6662      
40254SERVER-MYSQL Multiple SQL products privilege escalation attempt (more info ...)attempted-admin  2016-6662      
45844SERVER-MYSQL into dumpfile function attempt (more info ...)misc-activity        URL
45845SERVER-MYSQL UDF system access attempt (more info ...)attempted-user        URL
45846SERVER-MYSQL UDF function check attempt (more info ...)misc-activity        URL
45847SERVER-MYSQL UDF function create attempt (more info ...)misc-activity        URL
45848SERVER-MYSQL UDF function drop attempt (more info ...)misc-activity        URL


# of warning rules in this group: 64

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
509SERVER-WEBAPP PCCS mysql database admin tool access (more info ...)web-application-attack 2000-0707 1557 10783 
1527SERVER-WEBAPP basilix mysql.class access (more info ...)web-application-activity 2001-1044 2198 10601 
1775SERVER-MYSQL root login attempt (more info ...)protocol-command-decode    
1776SERVER-MYSQL show databases attempt (more info ...)protocol-command-decode    
3518SERVER-MYSQL MaxDB WebSQL wppassword buffer overflow (more info ...)web-application-attack 2005-0111 12265  
3519SERVER-MYSQL MaxDB WebSQL wppassword buffer overflow default port (more info ...)web-application-attack 2005-0111 12265  URL
4649SERVER-MYSQL create function buffer overflow attempt (more info ...)misc-activity 2005-2558 14509  
8057SERVER-MYSQL Date_Format denial of service attempt (more info ...)attempted-dos 2006-3469 19032  URL
11619SERVER-MYSQL MySQL COM_TABLE_DUMP Function Stack Overflow attempt (more info ...)attempted-admin 2006-1517 17780  URL
13357SERVER-MYSQL failed Oracle Mysql login attempt (more info ...)misc-activity    URL
13358SERVER-MYSQL Oracle Mysql login attempt from unauthorized location (more info ...)misc-activity    URL
13714SERVER-MYSQL yaSSL SSLv3 Client Hello Message Cipher Specs Buffer Overflow attempt (more info ...)attempted-user 2008-0226 27140  URL
15442SERVER-MYSQL XML Functions ExtractValue Scalar XPath denial of service attempt (more info ...)attempted-dos 2009-0819 33972  URL
15443SERVER-MYSQL XML Functions UpdateXML Scalar XPath denial of service attempt (more info ...)attempted-dos 2009-0819 33972  URL
15952SERVER-MYSQL create function libc arbitrary code execution attempt (more info ...)attempted-user 2005-0709 12781  
16020SERVER-MYSQL login handshake information disclosure attempt (more info ...)misc-activity 2006-1516 17780  
16348SERVER-MYSQL database PROCEDURE ANALYSE denial of service attempt - 1 (more info ...)attempted-dos 2009-4019   URL
16349SERVER-MYSQL database Procedure Analyse denial of service attempt - 2 (more info ...)attempted-dos 2009-4019   URL
16385SERVER-MYSQL yaSSL library cert parsing stack overflow attempt (more info ...)attempted-user 2009-4484 37640  
17412SERVER-MYSQL create function mysql.func arbitrary library injection attempt (more info ...)attempted-user 2005-0710 12781  
18513SERVER-MYSQL yaSSL SSL Hello Message Buffer Overflow attempt (more info ...)attempted-admin 2008-0226   URL
19000SERVER-MYSQL Database CASE NULL argument denial of service attempt (more info ...)attempted-dos 2010-3678 42596  
19001SERVER-MYSQL IN NULL argument denial of service attempt (more info ...)attempted-dos 2010-3678 42596  
19093SERVER-MYSQL Database unique set column denial of service attempt (more info ...)attempted-dos 2010-3677 42646  
19094SERVER-MYSQL Database unique set column denial of service attempt (more info ...)attempted-dos 2010-3677 42646  
20053SERVER-MYSQL Database SELECT subquery denial of service attempt (more info ...)attempted-dos 2009-4019   URL
24897SERVER-MYSQL Oracle MySQL grant file long database name stack overflow attempt (more info ...)attempted-user 2012-5611 56769  
24908SERVER-MYSQL Oracle MySQL user enumeration attempt (more info ...)attempted-recon 2012-5615 56766  
24909SERVER-MYSQL Oracle MySQL select UpdateXML nested xml elements denial of service attempt (more info ...)attempted-dos 2012-5614   
24910SERVER-MYSQL Oracle MySQL MDL free corrupted pointer heap overflow attempt (more info ...)attempted-user 2012-5612 56768  
26299SERVER-MYSQL MySQL/MariaDB Server geometry query polygon object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26300SERVER-MYSQL MySQL/MariaDB Server geometry query multistring object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26301SERVER-MYSQL MySQL/MariaDB Server geometry query multipolygon object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26302SERVER-MYSQL MySQL/MariaDB Server geometry query linestring object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26303SERVER-MYSQL MySQL/MariaDB Server geometry query polygon object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26304SERVER-MYSQL MySQL/MariaDB Server geometry query multistring object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26305SERVER-MYSQL MySQL/MariaDB Server geometry query multipolygon object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26306SERVER-MYSQL MySQL/MariaDB Server geometry query linestring object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26307SERVER-MYSQL MySQL/MariaDB Server geometry query polygon object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26308SERVER-MYSQL MySQL/MariaDB Server geometry query multistring object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26309SERVER-MYSQL MySQL/MariaDB Server geometry query multipolygon object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26310SERVER-MYSQL MySQL/MariaDB Server geometry query linestring object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26311SERVER-MYSQL MySQL/MariaDB Server geometry query polygon object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26312SERVER-MYSQL MySQL/MariaDB Server geometry query multistring object integer overflow attempt (more info ...)attempted-admin 2013-1861   
26313SERVER-MYSQL MySQL/MariaDB Server geometry query multipolygon object integer overflow attempt (more info ...)attempted-admin 2013-1861   
31570SERVER-MYSQL MySQL/MariaDB mysql.cc buffer overflow attempt (more info ...)attempted-user 2014-0001 65298  
32647SERVER-MYSQL Oracle MySQL Server InnoDB Memcached plugin resource exhaustion attempt (more info ...)denial-of-service 2013-1570   
32648SERVER-MYSQL Oracle MySQL Server InnoDB Memcached plugin resource exhaustion attempt (more info ...)denial-of-service 2013-1570   
32649SERVER-MYSQL Oracle MySQL Server InnoDB Memcached plugin resource exhaustion attempt (more info ...)denial-of-service 2013-1570   
32650SERVER-MYSQL Oracle MySQL Server InnoDB Memcached plugin resource exhaustion attempt (more info ...)denial-of-service 2013-1570   
32651SERVER-MYSQL Oracle MySQL Server InnoDB Memcached plugin resource exhaustion attempt (more info ...)denial-of-service 2013-1570   
33637SERVER-MYSQL MySQL/MariaDB Server geometry query object integer overflow attempt (more info ...)attempted-admin 2013-1861   
43391SERVER-WEBAPP MySQL Commander remote file include attempt (more info ...)web-application-attack 2007-1439 22941  
43392SERVER-WEBAPP MySQL Commander remote file include attempt (more info ...)web-application-attack 2007-1439 22941  
43671SQL Oracle MySQL Pluggable Auth denial of service attempt (more info ...)denial-of-service 2017-3599   
44674SERVER-MYSQL MySQL/MariaDB Server geometry query integer overflow attempt (more info ...)attempted-admin 2013-1861   
48221SERVER-OTHER Oracle MySQL uninitialized variable remote code execution attempt (more info ...)attempted-user    
52366SERVER-MYSQL yaSSL SSL Hello Message buffer overflow attempt (more info ...)attempted-admin 2008-0226   URL
53864POLICY-OTHER Cisco Firepower User Agent Service default MySQL credentials detected (more info ...)policy-violation 2020-3318   URL
59692SERVER-MYSQL Dell OpenManage Network Manager remote code execution attempt (more info ...)attempted-admin 2018-15768   
59693SERVER-MYSQL Dell OpenManage Network Manager remote code execution attempt (more info ...)attempted-admin 2018-15768   
59694SERVER-MYSQL Dell OpenManage Network Manager remote code execution attempt (more info ...)attempted-admin 2018-15768   
59695SERVER-MYSQL Dell OpenManage Network Manager remote code execution attempt (more info ...)attempted-admin 2018-15768   
60710SERVER-MYSQL MySQL client insecure deserialization attempt (more info ...)attempted-user 2022-40955   

 goto Top

Group: Server / Database / Common SQL

# of attack rules in this group: 509

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
12027SQL Ingres Database uuid_from_char buffer overflow attempt (more info ...)attempted-admin  2007-3338  24585    URL
13356SQL SAP MaxDB shell command injection attempt (more info ...)attempted-admin  2008-0244  27206    
13512SQL generic sql exec injection attempt - GET parameter (more info ...)web-application-attack        URL
13513SQL generic sql insert injection attempt - GET parameter (more info ...)web-application-attack  2012-2998      URL
13990SQL union select - possible sql injection attempt - GET parameter (more info ...)misc-attack  2020-17506  24067    URL
14991SQL IBM DB2 Universal Database xmlquery buffer overflow attempt (more info ...)attempted-user  2008-3854  29601    
15584SQL char and sysobjects - possible sql injection recon attempt (more info ...)web-application-attack        URL
15868SQL Borland InterBase username buffer overflow (more info ...)attempted-user  2008-2559  29302    
15874SQL union select - possible sql injection attempt - POST parameter (more info ...)misc-attack        URL
15875SQL generic sql insert injection attempt - POST parameter (more info ...)web-application-attack        URL
15877SQL generic sql exec injection attempt - POST parameter (more info ...)web-application-attack        URL
16049SERVER-OTHER GNU Radius SQL accounting format string exploit attempt (more info ...)attempted-admin  2006-4181  21303    
16074SQL Suspicious SQL ansi_padding option (more info ...)policy-violation  2008-0106      URL
16431SQL generic sql with comments injection attempt - GET parameter (more info ...)web-application-attack        URL
16513SQL Jive Software Openfire Jabber Server SQL injection attempt (more info ...)attempted-user  2008-6510  32189    
17044SQL WinCC DB default password security bypass attempt (more info ...)attempted-user  2010-2772      URL
17209SQL IBM DB2 DATABASE SERVER SQL REPEAT Buffer Overflow (more info ...)attempted-admin  2010-0462  37976    
19437INDICATOR-OBFUSCATION select concat statement - possible sql injection (more info ...)web-application-attack        URL
19438SQL url ending in comment characters - possible sql injection attempt (more info ...)web-application-attack  2012-2998      URL
19439SQL 1 = 1 - possible sql injection attempt (more info ...)web-application-attack        URL
19440SQL 1 = 0 - possible sql injection attempt (more info ...)web-application-attack        URL
20628SERVER-WEBAPP HP Data Protector FinishedCopy SQL Injection attempt (more info ...)attempted-user  2011-3162      URL
20635SERVER-WEBAPP HP Data Protector GetPolicies SQL Injection attempt (more info ...)attempted-user  2011-3157      URL
21459MALWARE-TOOLS Havij advanced SQL injection tool user-agent string (more info ...)attempted-user        URL
21778SQL parameter ending in comment characters - possible sql injection attempt - POST (more info ...)web-application-attack        URL
23241SERVER-OTHER HP DPNECentral RequestCopy type SQL injection attempt (more info ...)web-application-attack  2011-3158      URL
23947SQL IBM System Storage DS storage manager profiler sql injection attempt (more info ...)web-application-attack  2012-2171  54112    URL
24172SQL use of concat function with select - likely SQL injection (more info ...)web-application-attack        URL
24704SERVER-WEBAPP CA Total Defense management.asmx sql injection attempt (more info ...)attempted-admin  2011-1653  47355    URL
24705SERVER-WEBAPP CA Total Defense management.asmx sql injection attempt (more info ...)attempted-admin  2011-1653  47355    URL
26829SQL generic sql update injection attempt - POST parameter (more info ...)web-application-attack        URL
26898BROWSER-PLUGINS Java Applet sql.DriverManager fakedriver exploit attempt (more info ...)attempted-user  2013-1488  58504    
26899BROWSER-PLUGINS Java Applet sql.DriverManager fakedriver exploit attempt (more info ...)attempted-user  2013-1488  58504    
26900BROWSER-PLUGINS Java Applet sql.DriverManager exploit attempt (more info ...)attempted-user  2013-1488  58504    
26901BROWSER-PLUGINS Java Applet sql.DriverManager exploit attempt (more info ...)attempted-user  2013-1488  58504    
27287SQL 1 = 1 - possible sql injection attempt (more info ...)web-application-attack        URL
27288SQL 1 = 1 - possible sql injection attempt (more info ...)web-application-attack        URL
27724SQL McAfee ePolicy Orchestrator timing based SQL injection attempt (more info ...)attempted-admin  2013-0140  59500    URL
27796SERVER-WEBAPP CA Total Defense Suite UNCWS UnassignFunctionalRoles stored procedure POST SQL injection attempt (more info ...)attempted-admin  2011-1653      
27797SERVER-WEBAPP CA Total Defense Suite UNCWS UnassignFunctionalRoles stored procedure SQL injection attempt (more info ...)attempted-admin  2011-1653      
29584SERVER-WEBAPP HP Data Protector LogClientInstallation SQL Injection attempt (more info ...)attempted-user  2011-3156      
29608SERVER-WEBAPP McAfee ePO showRegisteredTypeDetails.do sql injection attempt (more info ...)attempted-admin        URL
29609SERVER-WEBAPP McAfee ePO DisplayMSAPropsDetail.do sql injection attempt (more info ...)attempted-admin        URL
30040SQL 1 = 1 - possible sql injection attempt (more info ...)web-application-attack        URL
30041SQL 1 = 1 - possible sql injection attempt (more info ...)web-application-attack        URL
31300SERVER-OTHER Xerox DocuShare SQL injection attempt (more info ...)attempted-admin    66922    
31664SERVER-OTHER Cisco ASA SQLNet inspection engine denial of service attempt (more info ...)attempted-dos  2013-5508  62912    URL
31665SERVER-OTHER Cisco ASA SQLNet inspection engine denial of service attempt (more info ...)attempted-dos  2013-5508  62912    URL
31666SERVER-OTHER Cisco ASA SQLNet inspection engine denial of service attempt (more info ...)attempted-dos  2013-5508  62912    URL
31667SERVER-OTHER Cisco ASA SQLNet inspection engine denial of service attempt (more info ...)attempted-dos  2013-5508  62912    URL
32353SQL Drupal 7 pre auth SQL injection attempt (more info ...)web-application-attack  2014-3704      URL
32761SERVER-WEBAPP dBlog CMS m parameter SQL injection attempt (more info ...)web-application-attack    62146    
34295SQL Lblog possible sql injection attempt - GET parameter (more info ...)misc-attack  2006-4284      URL
34363SERVER-WEBAPP Novell ZENworks Configuration Management GetStoredResult.class SQL injection attempt (more info ...)web-application-attack  2015-0780  74284    
34646SERVER-WEBAPP ZOHO ManageEngine OpManager SQL injection attempt (more info ...)web-application-attack        URL
34647SERVER-WEBAPP ZOHO ManageEngine OpManager SQL injection attempt (more info ...)web-application-attack        URL
34648SERVER-WEBAPP ZOHO ManageEngine OpManager SQL injection attempt (more info ...)web-application-attack        URL
34999SERVER-WEBAPP Novell ZENworks Configuration Management queryid SQL injection attempt (more info ...)web-application-attack  2015-0782  72808    
35000SERVER-WEBAPP Novell ZENworks Configuration Management queryid SQL injection attempt (more info ...)web-application-attack  2015-0782  72808    
35077SERVER-WEBAPP ManageEngine Applications Manager getMGList groupId SQL injection attempt (more info ...)web-application-attack        
35078SERVER-WEBAPP ManageEngine Applications Manager getMGList groupId SQL injection attempt (more info ...)web-application-attack        
35079SERVER-WEBAPP ManageEngine Applications Manager getMGList groupId SQL injection attempt (more info ...)web-application-attack        
35279SERVER-WEBAPP ManageEngine Applications Manager haid SQL injection attempt (more info ...)web-application-attack        
35280SERVER-WEBAPP ManageEngine Applications Manager haid SQL injection attempt (more info ...)web-application-attack        
35281SERVER-WEBAPP ManageEngine Applications Manager haid SQL injection attempt (more info ...)web-application-attack        
35427SERVER-WEBAPP ManageEngine Applications Manager customerName SQL injection attempt (more info ...)web-application-attack        
35428SERVER-WEBAPP ManageEngine Applications Manager customerName SQL injection attempt (more info ...)web-application-attack        
35429SERVER-WEBAPP ManageEngine Applications Manager customerName SQL injection attempt (more info ...)web-application-attack        
35533SERVER-WEBAPP ManageEngine IT360 BSIntegInfoHandler resIds SQL injection attempt (more info ...)web-application-attack        
35534SERVER-WEBAPP ManageEngine IT360 BSIntegInfoHandler resIds SQL injection attempt (more info ...)web-application-attack        
35535SERVER-WEBAPP ManageEngine IT360 BSIntegInfoHandler resIds SQL injection attempt (more info ...)web-application-attack        
35540SERVER-OTHER EMC AutoStart ftagent SQL injection attempt (more info ...)attempted-admin  2015-0538  74426    
35541SERVER-OTHER EMC AutoStart ftagent SQL injection attempt (more info ...)attempted-admin  2015-0538  74426    
35703SERVER-WEBAPP ManageEngine OpManager agentKey SQL injection attempt (more info ...)web-application-attack        
35819SQL union select - possible percent-delimited SQL injection attempt - GET parameter (more info ...)misc-attack  2011-1667  21227    URL
35929SERVER-WEBAPP Nagios XI Incident Manager SQL injection attempt (more info ...)web-application-attack        
35930SERVER-WEBAPP Nagios XI Incident Manager SQL injection attempt (more info ...)web-application-attack        
35931SERVER-WEBAPP Nagios XI Incident Manager SQL injection attempt (more info ...)web-application-attack        
35932SERVER-WEBAPP Nagios XI Incident Manager SQL injection attempt (more info ...)web-application-attack        
36097SERVER-WEBAPP ManageEngine OpManager SubmitQuery SQL injection attempt (more info ...)web-application-attack  2015-7766      URL
36098SERVER-WEBAPP ManageEngine OpManager SubmitQuery SQL injection attempt (more info ...)web-application-attack  2015-7766      URL
36099SERVER-WEBAPP ManageEngine OpManager SubmitQuery SQL injection attempt (more info ...)web-application-attack  2015-7766      URL
36283SERVER-WEBAPP ManageEngine OpManager APMAlertOperations servlet SQL injection attempt (more info ...)web-application-attack        URL
36284SERVER-WEBAPP ManageEngine OpManager APMAlertOperations servlet SQL injection attempt (more info ...)web-application-attack        URL
36285SERVER-WEBAPP ManageEngine OpManager APMAlertOperations servlet SQL injection attempt (more info ...)web-application-attack        URL
37369SERVER-WEBAPP Ipswitch WhatsUp iDroneComAPI SQL injection attempt (more info ...)attempted-admin  2015-8261      
37443SQL use of sleep function with select - likely SQL injection (more info ...)web-application-attack        URL
37547SERVER-WEBAPP eClinicalWorks portalUserService.jsp SQL injection attempt (more info ...)web-application-attack  2015-4592  82296    
37687SERVER-WEBAPP Oracle e-Business Suite HR_UTIL_DISP_WEB SQL injection attempt (more info ...)web-application-attack  2016-0517      
38531SERVER-WEBAPP WSN Live SQL injection attempt SQL injection attempt (more info ...)web-application-attack  2010-4006  44593    
38993SQL use of sleep function in HTTP header - likely SQL injection attempt (more info ...)web-application-attack        URL
39268SERVER-WEBAPP Joomla PayPlans Extension com_payplans group_id SQL injection attempt (more info ...)web-application-attack        URL
39331SERVER-WEBAPP SolarWinds SRM Profiler BackupExceptionsServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39332SERVER-WEBAPP SolarWinds SRM Profiler BackupExceptionsServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39333SERVER-WEBAPP SolarWinds SRM Profiler DuplicateFilesServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39334SERVER-WEBAPP SolarWinds SRM Profiler DuplicateFilesServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39335SERVER-WEBAPP SolarWinds SRM Profiler ScriptServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39336SERVER-WEBAPP SolarWinds SRM Profiler BexDriveUsageSummaryServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39337SERVER-WEBAPP SolarWinds SRM Profiler BexDriveUsageSummaryServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39338SERVER-WEBAPP SolarWinds SRM Profiler ScriptServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39339SERVER-WEBAPP SolarWinds SRM Profiler WindowsEventLogsServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39340SERVER-WEBAPP SolarWinds SRM Profiler WindowsEventLogsServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
39474SERVER-WEBAPP Riverbed SteelCentral NetProfiler REST API login SQL injection attempt (more info ...)web-application-attack        URL
39475SERVER-WEBAPP Riverbed SteelCentral NetProfiler algorithm_settings SQL injection attempt (more info ...)web-application-attack        URL
39476SERVER-WEBAPP Riverbed SteelCentral NetProfiler export_report SQL injection attempt (more info ...)web-application-attack        URL
39477SERVER-WEBAPP Riverbed SteelCentral NetProfiler port_config SQL injection attempt (more info ...)web-application-attack        URL
41029SERVER-WEBAPP Nagios Core Configuration Manager SQL injection attempt (more info ...)web-application-attack  2013-6875      
41112SERVER-WEBAPP Dell SonicWall GMS Logs.class SQL injection attempt (more info ...)web-application-attack        URL
41113SERVER-WEBAPP Dell SonicWall GMS Logs.class SQL injection attempt (more info ...)web-application-attack        URL
41114SERVER-WEBAPP Dell SonicWall GMS TaskViewServlet.class SQL injection attempt (more info ...)web-application-attack        URL
41115SERVER-WEBAPP Dell SonicWall GMS TaskViewServlet.class SQL injection attempt (more info ...)web-application-attack        URL
41116SERVER-WEBAPP Dell SonicWall GMS WorkFlowServlet.class SQL injection attempt (more info ...)web-application-attack        URL
41117SERVER-WEBAPP Dell SonicWall GMS WorkFlowServlet.class SQL injection attempt (more info ...)web-application-attack        URL
41410SERVER-WEBAPP McAfee ePolicy Orchestrator data channel SQL injection attempt (more info ...)attempted-user  2016-8027      URL
41449SQL use of sleep function with and - likely SQL injection (more info ...)web-application-attack        URL
41454SERVER-WEBAPP Advantech WebAccess updateTemplate SQL injection attempt (more info ...)web-application-attack  2017-5154  95410    URL
41455SERVER-WEBAPP Advantech WebAccess updateTemplate SQL injection attempt (more info ...)web-application-attack  2017-5154  95410    URL
41488SERVER-WEBAPP GitHub Enterprise pre-receive-hooks SQL injection attempt (more info ...)web-application-attack        URL
41767SERVER-WEBAPP WP_Query plugin SQL injection attempt (more info ...)web-application-attack  2017-5611  95816    URL
41768SERVER-WEBAPP WP_Query plugin SQL injection attempt (more info ...)web-application-attack  2017-5611  95816    URL
41769SERVER-WEBAPP WP_Query plugin SQL injection attempt (more info ...)web-application-attack  2017-5611  95816    URL
41770SERVER-WEBAPP Wordpress NextGEN Gallery SQL injection attempt (more info ...)web-application-attack        URL
41817SERVER-WEBAPP generic SQL select statement possible sql injection (more info ...)web-application-attack        URL
42248SERVER-WEBAPP ProcessMaker Enterprise eventsAjax SQL injection attempt (more info ...)web-application-attack  2016-9048      URL
42249SERVER-WEBAPP ProcessMaker Enterprise proxy SQL injection attempt (more info ...)web-application-attack  2016-9048      URL
42251SERVER-WEBAPP ProcessMaker Enterprise genericAjax SQL injection attempt (more info ...)web-application-attack  2016-9048      URL
42848SERVER-WEBAPP Symantec Endpoint Protection Manager SQL injection attempt (more info ...)web-application-attack  2015-1491      
42849SERVER-WEBAPP Symantec Endpoint Protection Manager SQL injection attempt (more info ...)web-application-attack  2015-1491      
42850SERVER-WEBAPP Dell SonicWALL Global Management System SQL injection attempt (more info ...)web-application-attack        URL
42851SERVER-WEBAPP Dell SonicWALL Global Management System SQL injection attempt (more info ...)web-application-attack        URL
42852SERVER-WEBAPP Dell SonicWALL Global Management System SQL injection attempt (more info ...)web-application-attack        URL
42958SERVER-WEBAPP Joomla 3.7.0 com_fields view SQL injection attempt (more info ...)web-application-attack  2017-8917      URL
42959SERVER-WEBAPP Joomla 3.7.0 com_fields view SQL injection attempt (more info ...)web-application-attack  2017-8917      URL
43036SERVER-WEBAPP ZOHO ManageEngine OpManager OPM_BVNAME SQL injection attempt (more info ...)web-application-attack  2014-7868      URL
43037SERVER-WEBAPP ZOHO ManageEngine OpManager OPM_BVNAME SQL injection attempt (more info ...)web-application-attack  2014-7868      URL
43038SERVER-WEBAPP ZOHO ManageEngine OpManager Search query SQL injection attempt (more info ...)web-application-attack  2014-7868      URL
43039SERVER-WEBAPP ZOHO ManageEngine OpManager Search query SQL injection attempt (more info ...)web-application-attack  2014-7868      URL
43040SERVER-WEBAPP ZOHO ManageEngine OpManager probeName SQL injection attempt (more info ...)web-application-attack  2014-7868      URL
43041SERVER-WEBAPP ZOHO ManageEngine OpManager probeName SQL injection attempt (more info ...)web-application-attack  2014-7868      URL
43195SERVER-WEBAPP SolarWinds SRM Profiler BackupAssociationServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43196SERVER-WEBAPP SolarWinds SRM Profiler BackupAssociationServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43197SERVER-WEBAPP SolarWinds SRM Profiler FileActionAssignmentServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43198SERVER-WEBAPP SolarWinds SRM Profiler FileActionAssignmentServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43199SERVER-WEBAPP SolarWinds SRM Profiler HostStorageServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43200SERVER-WEBAPP SolarWinds SRM Profiler HostStorageServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43201SERVER-WEBAPP SolarWinds SRM Profiler NbuErrorMessageServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43202SERVER-WEBAPP SolarWinds SRM Profiler NbuErrorMessageServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43203SERVER-WEBAPP SolarWinds SRM Profiler ProcessesServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43204SERVER-WEBAPP SolarWinds SRM Profiler ProcessesServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43205SERVER-WEBAPP SolarWinds SRM Profiler QuantumMonitorServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43206SERVER-WEBAPP SolarWinds SRM Profiler QuantumMonitorServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43207SERVER-WEBAPP SolarWinds SRM Profiler UserDefinedFieldConfigServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43208SERVER-WEBAPP SolarWinds SRM Profiler UserDefinedFieldConfigServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43209SERVER-WEBAPP SolarWinds SRM Profiler XiotechMonitorServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43210SERVER-WEBAPP SolarWinds SRM Profiler XiotechMonitorServlet SQL injection attempt (more info ...)web-application-attack  2016-4350  89557    URL
43284SERVER-WEBAPP HP Network Automation RedirectServlet SQL injection attempt (more info ...)web-application-attack  2017-5810  98331    URL
43439SERVER-WEBAPP GoAutoDial go_get_user_info SQL injection attempt (more info ...)web-application-attack  2015-2843  74281    
43440SERVER-WEBAPP GoAutoDial validate_credentials SQL injection attempt (more info ...)web-application-attack  2015-2843  74281    
43441SERVER-WEBAPP GoAutoDial validate_credentials SQL injection attempt (more info ...)web-application-attack  2015-2843  74281    
44493SERVER-WEBAPP Faleemi IP Cameras ONVIF device_service SQL injection attempt (more info ...)attempted-admin  2017-14743      URL
44571SERVER-WEBAPP Trend Micro Mobile Security Enterprise web_service.dll SQL injection attempt (more info ...)web-application-attack  2017-14078  100966    URL
44572SERVER-WEBAPP Trend Micro Mobile Security Enterprise web_service.dll SQL injection attempt (more info ...)web-application-attack  2017-14078  100966    URL
44573SERVER-WEBAPP Trend Micro Mobile Security Enterprise web_service.dll SQL injection attempt (more info ...)web-application-attack  2017-14078  100966    URL
44605SERVER-WEBAPP Nagios XI Incident Manager SQL injection attempt (more info ...)web-application-attack        
44606SERVER-WEBAPP Nagios XI Incident Manager SQL injection attempt (more info ...)web-application-attack        
44657SERVER-WEBAPP Unitrends Enterprise Backup API SQL injection attempt (more info ...)web-application-attack  2017-12478      URL
44722SERVER-WEBAPP Cisco Prime Collaboration Provisioning pmclasschooser.xml SQL injection attempt (more info ...)web-application-attack  2017-12276      URL
44723SERVER-WEBAPP Cisco Prime Collaboration Provisioning pmclasschooser.xml SQL injection attempt (more info ...)web-application-attack  2017-12276      URL
44916SERVER-WEBAPP ManageEngine Applications Manager GraphicalView.do SQL injection attempt (more info ...)web-application-attack  2017-16543      URL
44917SERVER-WEBAPP ManageEngine Applications Manager GraphicalView.do SQL injection attempt (more info ...)web-application-attack  2017-16543      URL
44918SERVER-WEBAPP ManageEngine Applications Manager GraphicalView.do SQL injection attempt (more info ...)web-application-attack  2017-16543      URL
44921SERVER-WEBAPP ManageEngine Applications Manager manageApplications.do SQL injection attempt (more info ...)web-application-attack  2017-16846      URL
44922SERVER-WEBAPP ManageEngine Applications Manager manageApplications.do SQL injection attempt (more info ...)web-application-attack  2017-16846      URL
45052SERVER-WEBAPP Wordpress wpdb prepare sprintf placeholder SQL injection attempt (more info ...)web-application-attack  2017-14723  100912    URL
45075SERVER-WEBAPP WordPress Ultimate Form Builder plugin SQL injection attempt (more info ...)web-application-attack  2017-15919  101604    URL
45076SERVER-WEBAPP WordPress Ultimate Form Builder plugin SQL injection attempt (more info ...)web-application-attack  2017-15919  101604    URL
45077SERVER-WEBAPP WordPress Ultimate Form Builder plugin SQL injection attempt (more info ...)web-application-attack  2017-15919  101604    URL
45112SERVER-WEBAPP ManageEngine Applications Manager showresource.do SQL injection attempt (more info ...)web-application-attack  2017-16847      URL
45113SERVER-WEBAPP ManageEngine Applications Manager showresource.do SQL injection attempt (more info ...)web-application-attack  2017-16847      URL
45189SERVER-WEBAPP ManageEngine Applications Manager mypage.do SQL injection attempt (more info ...)web-application-attack  2017-16849      URL
45190SERVER-WEBAPP ManageEngine Applications Manager mypage.do SQL injection attempt (more info ...)web-application-attack  2017-16849      URL
45192SERVER-WEBAPP ManageEngine Applications Manager showActionProfiles.do SQL injection attempt (more info ...)web-application-attack  2017-16850      URL
45193SERVER-WEBAPP ManageEngine Applications Manager showActionProfiles.do SQL injection attempt (more info ...)web-application-attack  2017-16850      URL
45688SERVER-WEBAPP Advantech WebAccess SQL injection attempt (more info ...)web-application-attack  2017-16716      
46024SERVER-WEBAPP multiple vendor calendar application id parameter SQL injection attempt (more info ...)web-application-attack  2018-6576  437437    
46025SERVER-WEBAPP multiple vendor calendar application id parameter SQL injection attempt (more info ...)web-application-attack  2018-6576  437437    
46028SERVER-WEBAPP Joomla JE PayperVideo extension SQL injection attempt (more info ...)web-application-attack  2018-6578      
46029SERVER-WEBAPP Joomla jextn-classifieds SQL injection attempt (more info ...)web-application-attack  2018-6575      
46030SERVER-WEBAPP Joomla jextn-classifieds SQL injection attempt (more info ...)web-application-attack  2018-6575      
46041SERVER-WEBAPP Joomla Component JMS Music 1.1.1 SQL injection attempt (more info ...)web-application-attack  2018-6581      URL
46042SERVER-WEBAPP Joomla Component JMS Music 1.1.1 SQL injection attempt (more info ...)web-application-attack  2018-6581      URL
46043SERVER-WEBAPP Joomla Component JMS Music 1.1.1 SQL injection attempt (more info ...)web-application-attack  2018-6581      URL
46044SERVER-WEBAPP Joomla Component JMS Music 1.1.1 SQL injection attempt (more info ...)web-application-attack  2018-6581      URL
46045SERVER-WEBAPP Joomla Component JMS Music 1.1.1 SQL injection attempt (more info ...)web-application-attack  2018-6581      URL
46046SERVER-WEBAPP Joomla Component JMS Music 1.1.1 SQL injection attempt (more info ...)web-application-attack  2018-6581      URL
46062SERVER-WEBAPP Joomla JEXTN Membership extension SQL injection attempt (more info ...)web-application-attack  2018-6578      
46063SERVER-WEBAPP Joomla JEXTN Membership extension SQL injection attempt (more info ...)web-application-attack  2018-6578      
46064SERVER-WEBAPP Joomla JEXTN Membership extension SQL injection attempt (more info ...)web-application-attack  2018-6578      
46087SERVER-WEBAPP Joomla JEXTN Reverse Auction extension SQL injection attempt (more info ...)web-application-attack  2018-6579      URL
46088SERVER-WEBAPP Joomla JEXTN Reverse Auction extension SQL injection attempt (more info ...)web-application-attack  2018-6579      URL
46089SERVER-WEBAPP Joomla JEXTN Reverse Auction extension SQL injection attempt (more info ...)web-application-attack  2018-6579      URL
46132SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack        URL
46133SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack        URL
46283SERVER-WEBAPP Quest NetVault Backup Server NVBUJobCountHistory SQL injection attempt (more info ...)web-application-attack  2017-17420  102252    
46302SERVER-WEBAPP Quest NetVault Backup Server NVBUEventHistory SQL injection attempt (more info ...)web-application-attack  2017-17412  102252    
46311SERVER-WEBAPP Quest NetVault Backup Server NVBUTransferHistory SQL injection attempt (more info ...)web-application-attack  2017-17419      
46333SERVER-WEBAPP Joomla DT Register SQL injection attempt (more info ...)web-application-attack  2018-6584      
46334SERVER-WEBAPP Joomla DT Register SQL injection attempt (more info ...)web-application-attack  2018-6584      
46337SERVER-WEBAPP Joomla Saxum Picker SQL injection attempt (more info ...)web-application-attack  2018-7178      
46338SERVER-WEBAPP Joomla Saxum Picker SQL injection attempt (more info ...)web-application-attack  2018-7178      
46379SERVER-WEBAPP Afian FileRun SQL injection attempt (more info ...)web-application-attack  2018-7735      URL
46380SERVER-WEBAPP Afian FileRun SQL injection attempt (more info ...)web-application-attack  2018-7735      URL
46449SERVER-OTHER PostgreSQL Empty Password authentication bypass attempt (more info ...)attempted-user  2017-7546      
46489SERVER-WEBAPP Quest NetVault Backup Server NVBUBackup SQL injection attempt (more info ...)web-application-attack  2017-17657      
46773SERVER-WEBAPP Nagios XI SQL injection attempt (more info ...)web-application-attack  2018-8734      
46774SERVER-WEBAPP NagiosXI SQL injection attempt (more info ...)web-application-attack  2018-8734      
46863SERVER-WEBAPP Quest NetVault Backup Server NVBUBackupOptionSet SQL injection attempt (more info ...)web-application-attack  2017-17653      
46889SERVER-WEBAPP Cisco Prime Collaboration Provisioning SQL injection attempt (more info ...)web-application-attack  2018-0320      URL
46890SERVER-WEBAPP Cisco Prime Collaboration Provisioning SQL injection attempt (more info ...)web-application-attack  2018-0320      URL
46891SERVER-WEBAPP Cisco Prime Collaboration Provisioning SQL injection attempt (more info ...)web-application-attack  2018-0320      URL
46892SERVER-WEBAPP Cisco Prime Collaboration Provisioning SQL injection attempt (more info ...)web-application-attack  2018-0320      URL
47497SERVER-WEBAPP Joomla CheckList extension SQL injection attempt (more info ...)web-application-attack  2018-7318      
47498SERVER-WEBAPP Joomla CheckList extension SQL injection attempt (more info ...)web-application-attack  2018-7318      
47501SERVER-WEBAPP Joomla ProjectLog search SQL injection attempt (more info ...)web-application-attack  2018-6024      
47502SERVER-WEBAPP Joomla ProjectLog search SQL injection attempt (more info ...)web-application-attack  2018-6024      
47550SERVER-WEBAPP Advantech WebAccess SCADA SQL injection attempt (more info ...)web-application-attack  2018-5443  102781    URL
47551SERVER-WEBAPP Advantech WebAccess SCADA SQL injection attempt (more info ...)web-application-attack  2018-5443  102781    URL
47552SERVER-WEBAPP Epic MyChart SQL injection attempt (more info ...)web-application-attack  2016-6272      
47553SERVER-WEBAPP Epic MyChart SQL injection attempt (more info ...)web-application-attack  2016-6272      
47554SERVER-WEBAPP Epic MyChart SQL injection attempt (more info ...)web-application-attack  2016-6272      
47555SERVER-WEBAPP Epic MyChart SQL injection attempt (more info ...)web-application-attack  2016-6272      
47576SERVER-WEBAPP Cobub Razor channel name SQL injection attempt (more info ...)web-application-attack  2018-8057      
47577SERVER-WEBAPP Cobub Razor channel name SQL injection attempt (more info ...)web-application-attack  2018-8057      
47579SERVER-WEBAPP Joomla Aist id SQL injection attempt (more info ...)web-application-attack  2018-5993      
47580SERVER-WEBAPP Joomla Aist id SQL injection attempt (more info ...)web-application-attack  2018-5993      
47655SERVER-WEBAPP Joomla PostInstall Message SQL injection attempt (more info ...)web-application-attack  2018-6376      
47788SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6226      
47789SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6226      
47794SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6229      
47795SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6229      
47796SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6228      
47797SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6228      
47799SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6230      
47800SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6230      
48126SERVER-WEBAPP Joomba component Timetable Schedule 3.6.8 SQL injection attempt (more info ...)web-application-attack  2018-17394      URL
48161SERVER-WEBAPP Joomba component Article Factory Manager SQL injection attempt (more info ...)web-application-attack  2018-17380      URL
48177SERVER-WEBAPP Advantech WebAccess SQL injection attempt (more info ...)web-application-attack  2017-16716      
48193SERVER-WEBAPP Joomba component AlphaIndex Dictionaries SQL injection attempt (more info ...)web-application-attack  2018-17397      URL
48194SERVER-WEBAPP Joomba component AlphaIndex Dictionaries SQL injection attempt (more info ...)web-application-attack  2018-17397      URL
48195SERVER-WEBAPP Joomla Component Collection Factory SQL injection attempt (more info ...)web-application-attack  2018-17383      URL
48196SERVER-WEBAPP Joomla component Reverse Auction Factory SQL injection attempt (more info ...)web-application-attack  2018-17376      URL
48215SERVER-WEBAPP Webport SQL injection attempt (more info ...)web-application-attack        URL
48216SERVER-WEBAPP Webport SQL injection attempt (more info ...)web-application-attack        URL
48236SERVER-WEBAPP Joomla Component Responsive Portfolio SQL injection attempt (more info ...)web-application-attack        URL
48412SERVER-WEBAPP ManageEngine Firewall Analyzer setManaged SQL injection attempt (more info ...)web-application-attack  2018-17283      URL
48413SERVER-WEBAPP ManageEngine Applications Manager editDisplaynames.do SQL injection attempt (more info ...)web-application-attack  2018-15168      URL
48414SERVER-WEBAPP ManageEngine Applications Manager editDisplaynames.do SQL injection attempt (more info ...)web-application-attack  2018-15168      URL
48415SERVER-WEBAPP ManageEngine Applications Manager editDisplaynames.do SQL injection attempt (more info ...)web-application-attack  2018-15168      URL
48454SERVER-WEBAPP Cisco Prime License Manager SQL injection attempt (more info ...)web-application-attack  2018-15441      URL
48455SERVER-WEBAPP Cisco Prime License Manager SQL injection attempt (more info ...)web-application-attack  2018-15441      URL
48785SERVER-OTHER SQLite FTS integer overflow attempt (more info ...)attempted-user  2018-20346      
48786SERVER-OTHER SQLite FTS integer overflow attempt (more info ...)attempted-user  2018-20346      
48900SERVER-WEBAPP Trend Micro Control Manager reporting.aspx SQL injection attempt (more info ...)web-application-attack  2018-3607      URL
49301SERVER-WEBAPP Trend Micro Smart Protection Server SQL injection attempt (more info ...)web-application-attack  2018-10350      
49302SERVER-WEBAPP Trend Micro Smart Protection Server SQL injection attempt (more info ...)web-application-attack  2018-10350      
49303SERVER-WEBAPP Trend Micro Smart Protection Server SQL injection attempt (more info ...)web-application-attack  2018-10350      
49463SERVER-WEBAPP Joomla CW Articles Attachments SQL injection attempt (more info ...)web-application-attack  2018-14592      URL
49464SERVER-WEBAPP Joomla CW Articles Attachments SQL injection attempt (more info ...)web-application-attack  2018-14592      URL
49465SERVER-WEBAPP Joomla CW Articles Attachments SQL injection attempt (more info ...)web-application-attack  2018-14592      URL
49587SERVER-WEBAPP CMSsite 1.0 SQL injection attempt (more info ...)web-application-attack        URL
49603SERVER-WEBAPP Trend Micro Control Manager SQL injection attempt (more info ...)web-application-attack  2018-3606      
49604SERVER-WEBAPP Trend Micro Control Manager SQL injection attempt (more info ...)web-application-attack  2018-3606      URL
49605SERVER-WEBAPP Trend Micro Control Manager SQL injection attempt (more info ...)web-application-attack  2018-3606      URL
49662SERVER-WEBAPP CMSsite 1.0 SQL injection attempt (more info ...)web-application-attack        URL
49663SERVER-WEBAPP CMSsite 1.0 SQL injection attempt (more info ...)web-application-attack        URL
49666SQL HTTP URI blind injection attempt (more info ...)web-application-attack        
49847SERVER-WEBAPP All in One Video Downloader SQL injection attempt (more info ...)web-application-attack        URL
49848SERVER-WEBAPP All in One Video Downloader SQL injection attempt (more info ...)web-application-attack        URL
49849SERVER-WEBAPP All in One Video Downloader SQL injection attempt (more info ...)web-application-attack        URL
49984SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack  2019-1825      URL
49985SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack  2019-1825      URL
51125SERVER-WEBAPP Joomla 3.7.0 com_fields view SQL injection attempt (more info ...)web-application-attack  2017-8917      URL
51275SERVER-WEBAPP Joomla Saxum Astro Component SQL injection attempt (more info ...)web-application-attack  2018-7180      URL
51276SERVER-WEBAPP Joomla Saxum Astro Component SQL injection attempt (more info ...)web-application-attack  2018-7180      URL
51277SERVER-WEBAPP Joomla Saxum Astro Component SQL injection attempt (more info ...)web-application-attack  2018-7180      URL
51572SERVER-WEBAPP Joomla component Alexandria Book Library SQL injection attempt (more info ...)web-application-attack  2018-7312      
51573SERVER-WEBAPP Joomla component Alexandria Book Library SQL injection attempt (more info ...)web-application-attack  2018-7312      
51574SERVER-WEBAPP Joomla component Alexandria Book Library SQL injection attempt (more info ...)web-application-attack  2018-7312      
51629SERVER-WEBAPP Trend Micro Control Manager reporting.aspx SQL injection attempt (more info ...)web-application-attack  2018-3607      URL
51630SERVER-WEBAPP Trend Micro Control Manager reporting.aspx SQL injection attempt (more info ...)web-application-attack  2018-3606      URL
51687SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12683      URL
51688SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12683      URL
51689SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12684      URL
51690SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12684      URL
51691SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12679      URL
51692SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12679      URL
51693SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12682      URL
51694SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12682      URL
51695SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12681      URL
51696SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12681      URL
51697SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12681      URL
51698SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12681      URL
51699SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12680      URL
51700SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12680      URL
51701SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12680      URL
51702SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12680      URL
51703SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12680      URL
51704SERVER-WEBAPP Cisco Firepower Management Center SQL injection attempt (more info ...)attempted-user  2019-12680      URL
51808SERVER-WEBAPP vBulletin SQL injection attempt (more info ...)web-application-attack  2019-17271      
51809SERVER-WEBAPP vBulletin SQL injection attempt (more info ...)web-application-attack  2019-17271      
51810SERVER-WEBAPP vBulletin SQL injection attempt (more info ...)web-application-attack  2019-17271      
51811SERVER-WEBAPP vBulletin SQL injection attempt (more info ...)web-application-attack  2019-17271      
51812SERVER-WEBAPP vBulletin SQL injection attempt (more info ...)web-application-attack  2019-17271      
51813SERVER-WEBAPP vBulletin SQL injection attempt (more info ...)web-application-attack  2019-17271      
52043SERVER-WEBAPP VEGO Web Forum SQL injection attempt (more info ...)web-application-attack  2006-0065      
52044SERVER-WEBAPP VEGO Web Forum SQL injection attempt (more info ...)web-application-attack  2006-0065      
52045SERVER-WEBAPP VEGO Web Forum SQL injection attempt (more info ...)web-application-attack  2006-0065      
52271SERVER-WEBAPP Joomla Jimtawl id parameter SQL injection attempt (more info ...)web-application-attack  2018-17399      URL
52272SERVER-WEBAPP Joomla Jimtawl id parameter SQL injection attempt (more info ...)web-application-attack  2018-17399      URL
52273SERVER-WEBAPP Joomla Jimtawl id parameter SQL injection attempt (more info ...)web-application-attack  2018-17399      URL
52543SERVER-WEBAPP Cisco Data Center Network Manager SQL injection attempt (more info ...)web-application-attack  2019-15984      URL
52544SERVER-WEBAPP Cisco Data Center Network Manager SQL injection attempt (more info ...)web-application-attack  2019-15984      URL
53169POLICY-OTHER PostgreSQL default credential login detected (more info ...)policy-violation  2020-3158      URL
53256SERVER-WEBAPP SQL Server Reporting Services web application remote code execution attempt (more info ...)attempted-user  2020-0618      URL
53480SERVER-WEBAPP Cisco SD-WAN vManage SQL injection attempt (more info ...)web-application-attack  2019-16012      URL
53481SERVER-WEBAPP Cisco SD-WAN vManage SQL injection attempt (more info ...)web-application-attack  2019-16012      URL
53857SERVER-WEBAPP Grandstream UCM6202 series SQL injection attempt (more info ...)web-application-attack  2020-5722      
53858SERVER-WEBAPP Grandstream UCM6202 series SQL injection attempt (more info ...)web-application-attack  2020-5722      
53859SERVER-WEBAPP Grandstream UCM6202 series SQL injection attempt (more info ...)web-application-attack  2020-5722      
53885SERVER-WEBAPP Grandstream UCM6200 series SQL injection attempt (more info ...)web-application-attack  2020-5722      URL
54558SERVER-WEBAPP Park Ticketing Management System SQL injection attempt (more info ...)web-application-attack        URL
54559SERVER-WEBAPP Park Ticketing Management System SQL injection attempt (more info ...)web-application-attack        URL
54565SERVER-WEBAPP Park Ticketing Management System SQL injection attempt (more info ...)web-application-attack        URL
54566SERVER-WEBAPP Park Ticketing Management System SQL injection attempt (more info ...)web-application-attack        URL
54567SERVER-WEBAPP Park Ticketing Management System SQL injection attempt (more info ...)web-application-attack        URL
54569SERVER-WEBAPP Barangay Management System SQL injection attempt (more info ...)web-application-attack        URL
54570SERVER-WEBAPP Barangay Management System SQL injection attempt (more info ...)web-application-attack        URL
54894SERVER-WEBAPP Cisco Data Center Network Manager SQL injection attempt (more info ...)web-application-attack  2019-15984      URL
54895SERVER-WEBAPP Cisco Data Center Network Manager SQL injection attempt (more info ...)web-application-attack  2019-15984      URL
55836SERVER-WEBAPP Wordpress Nexos theme SQL injection attempt (more info ...)web-application-attack  2020-15363      
55837SERVER-WEBAPP Wordpress Nexos theme SQL injection attempt (more info ...)web-application-attack  2020-15363      
55838SERVER-WEBAPP Wordpress Nexos theme SQL injection attempt (more info ...)web-application-attack  2020-15363      
56005SERVER-WEBAPP D-Link Central WiFi Manager CWM 100 SQL injection attempt (more info ...)web-application-attack  2019-13375      URL
56006SERVER-WEBAPP D-Link Central WiFi Manager CWM 100 SQL injection attempt (more info ...)web-application-attack  2019-13375      URL
56007SERVER-WEBAPP D-Link Central WiFi Manager CWM 100 SQL injection attempt (more info ...)web-application-attack  2019-13375      URL
56523SERVER-WEBAPP Joomla Core Featured Article SQL injection attempt (more info ...)web-application-attack  2020-10243      URL
56524SERVER-WEBAPP Joomla Core Featured Article SQL injection attempt (more info ...)web-application-attack  2020-10243      URL
56525SERVER-WEBAPP Joomla Core Featured Article SQL injection attempt (more info ...)web-application-attack  2020-10243      URL
56947SERVER-WEBAPP Cisco Data Center Network Manager SQL injection attempt (more info ...)web-application-attack  2021-1247      URL
56954SERVER-WEBAPP Cisco Data Center Network Manager SQL injection attempt (more info ...)web-application-attack  2021-1248      URL
57412SERVER-WEBAPP Nagios XI do_update_user SQL injection attempt (more info ...)web-application-attack  2020-27988      URL
57413SERVER-WEBAPP Nagios XI do_update_user SQL injection attempt (more info ...)web-application-attack  2020-27988      URL
57511SERVER-WEBAPP Sinapsi eSolar Light Photovoltaic System Monitor SQL injection attempt (more info ...)web-application-attack  2012-5861      
57512SERVER-WEBAPP Sinapsi eSolar Light Photovoltaic System Monitor SQL injection attempt (more info ...)web-application-attack  2012-5861      
57513SERVER-WEBAPP Sinapsi eSolar Light Photovoltaic System Monitor SQL injection attempt (more info ...)web-application-attack  2012-5861      
57514SERVER-WEBAPP Sinapsi eSolar Light Photovoltaic System Monitor SQL injection attempt (more info ...)web-application-attack  2012-5861      
57515SERVER-WEBAPP Sinapsi eSolar Light Photovoltaic System Monitor SQL injection attempt (more info ...)web-application-attack  2012-5861      
57516SERVER-WEBAPP Sinapsi eSolar Light Photovoltaic System Monitor SQL injection attempt (more info ...)web-application-attack  2012-5861      
57523SERVER-WEBAPP Cisco Unified Communications Manager SQL injection attempt (more info ...)web-application-attack  2021-1365      URL
57524SERVER-WEBAPP Cisco Unified Communications Manager SQL injection attempt (more info ...)web-application-attack  2021-1365      URL
57525SERVER-WEBAPP Cisco Unified Communications Manager SQL injection attempt (more info ...)web-application-attack  2021-1365      URL
57954SERVER-WEBAPP Velocloud VMware SD-WAN Orchestrator SQL injection attempt (more info ...)web-application-attack  2020-3973      URL
58026SERVER-WEBAPP Zoho ManageEngine OpManager OPMDeviceDetailsServlet SQL injection attempt (more info ...)web-application-attack  2019-17602      URL
58027SERVER-WEBAPP Zoho ManageEngine OpManager OPMDeviceDetailsServlet SQL injection attempt (more info ...)web-application-attack  2019-17602      URL
58028SERVER-WEBAPP Zoho ManageEngine OpManager OPMDeviceDetailsServlet SQL injection attempt (more info ...)web-application-attack  2019-17602      URL
58072SERVER-WEBAPP Trend Micro SafeSync for Enterprise displayName_get SQL injection attempt (more info ...)web-application-attack        
58224SERVER-WEBAPP SonicWall SMA100 SQL injection attempt (more info ...)web-application-attack  2019-7481      
58225SERVER-WEBAPP SonicWall SMA100 SQL injection attempt (more info ...)web-application-attack  2019-7481      
58226SERVER-WEBAPP SonicWall SMA100 SQL injection attempt (more info ...)web-application-attack  2019-7481      
58242SERVER-WEBAPP Sophos XG Firewall SQL injection attempt (more info ...)web-application-attack  2020-12271      URL
58260SERVER-WEBAPP AlienVault Unified Security Management SQL injection attempt (more info ...)web-application-attack        
58261SERVER-WEBAPP AlienVault Unified Security Management SQL injection attempt (more info ...)web-application-attack        
58262SERVER-WEBAPP AlienVault Unified Security Management SQL injection attempt (more info ...)web-application-attack        
58320SERVER-WEBAPP Trend Micro Encryption Email Gateway formChangePass username SQL injection attempt (more info ...)web-application-attack  2018-10353      
58321SERVER-WEBAPP Trend Micro Encryption Email Gateway formChangePass username SQL injection attempt (more info ...)web-application-attack  2018-10353      
58322SERVER-WEBAPP Trend Micro Encryption Email Gateway formChangePass username SQL injection attempt (more info ...)web-application-attack  2018-10353      
58323SERVER-WEBAPP Advantech WebAccess Node Quality ItemGroupIdAry SQL injection attempt (more info ...)web-application-attack  2018-7501      
58324SERVER-WEBAPP Advantech WebAccess Node Quality ItemGroupIdAry SQL injection attempt (more info ...)web-application-attack  2018-7501      
58325SERVER-WEBAPP Advantech WebAccess Node Quality ItemGroupIdAry SQL injection attempt (more info ...)web-application-attack  2018-7501      
58330SERVER-WEBAPP Advantech WebAccess Node controlNode bnid SQL injection attempt (more info ...)web-application-attack  2018-7501      
58331SERVER-WEBAPP Advantech WebAccess Node controlNode bnid SQL injection attempt (more info ...)web-application-attack  2018-7501      
58332SERVER-WEBAPP Advantech WebAccess Node controlNode bnid SQL injection attempt (more info ...)web-application-attack  2018-7501      
58353SERVER-WEBAPP Advantech WebAccess Node Quality_Reg ItemIdAry SQL injection attempt (more info ...)web-application-attack  2018-7501      
58362SERVER-WEBAPP Advantech WebAccess Node BWSCADASoap ProjectName SQL injection attempt (more info ...)web-application-attack  2018-7501      
58381SERVER-WEBAPP Trend Micro Encryption Email Gateway formConfiguration saveValue SQL injection attempt (more info ...)web-application-attack  2018-10352      
58382SERVER-WEBAPP Trend Micro Encryption Email Gateway formConfiguration saveValue SQL injection attempt (more info ...)web-application-attack  2018-10352      
58383SERVER-WEBAPP Trend Micro Encryption Email Gateway formConfiguration saveValue SQL injection attempt (more info ...)web-application-attack  2018-10352      
58407SERVER-WEBAPP Nagios XI bulk modification tool SQL injection attempt (more info ...)web-application-attack  2021-37350      
58408SERVER-WEBAPP Nagios XI bulk modification tool SQL injection attempt (more info ...)web-application-attack  2021-37350      
58409SERVER-WEBAPP Nagios XI bulk modification tool SQL injection attempt (more info ...)web-application-attack  2021-37350      
58421SERVER-WEBAPP BillQuick Web Suite SQL injection attempt (more info ...)web-application-attack  2021-42258      
58422SERVER-WEBAPP BillQuick Web Suite SQL injection attempt (more info ...)web-application-attack  2021-42258      
58423SERVER-WEBAPP BillQuick Web Suite SQL injection attempt (more info ...)web-application-attack  2021-42258      
58509SERVER-WEBAPP Accellion File Transfer Appliance SQL injection attempt (more info ...)web-application-attack  2021-27101      URL
58510SERVER-WEBAPP EyesOfNetwork SQL injection attempt (more info ...)web-application-attack  2020-8656      
58511SERVER-WEBAPP EyesOfNetwork SQL injection attempt (more info ...)web-application-attack  2020-8656      
58512SERVER-WEBAPP EyesOfNetwork SQL injection attempt (more info ...)web-application-attack  2020-8656      
58513SERVER-WEBAPP Advantech WebAccess updateTemplate SQL injection attempt (more info ...)web-application-attack  2017-5154      URL
58709SERVER-WEBAPP Trend Micro Email Encryption Gateway SQL injection attempt (more info ...)web-application-attack  2018-6229      
58843SERVER-WEBAPP FUEL CMS col SQL injection attempt (more info ...)web-application-attack  2021-38727      
58844SERVER-WEBAPP FUEL CMS col SQL injection attempt (more info ...)web-application-attack  2021-38727      
58845SERVER-WEBAPP FUEL CMS col SQL injection attempt (more info ...)web-application-attack  2021-38727      
58847SERVER-WEBAPP Trend Micro Encryption Email Gateway requestDomains hidDomains SQL injection attempt (more info ...)web-application-attack  2018-10356      
58848SERVER-WEBAPP Trend Micro Encryption Email Gateway requestDomains hidDomains SQL injection attempt (more info ...)web-application-attack  2018-10356      
58849SERVER-WEBAPP Trend Micro Encryption Email Gateway requestDomains hidDomains SQL injection attempt (more info ...)web-application-attack  2018-10356      
58855SERVER-WEBAPP Trend Micro Encryption Email Gateway register2 Client SQL injection attempt (more info ...)web-application-attack  2018-10351      
58959SERVER-WEBAPP WordPress Core SQL injection attempt (more info ...)web-application-attack  2022-21661      URL
59003SERVER-WEBAPP Trend Micro SafeSync for Enterprise SQL injection attempt (more info ...)web-application-attack        URL
59080SERVER-WEBAPP Zoho ManageEngine OpManager GetGraphData Alarms section SQL injection attempt (more info ...)web-application-attack  2018-20338      
59081SERVER-WEBAPP Zoho ManageEngine OpManager GetGraphData Alarms section SQL injection attempt (more info ...)web-application-attack  2018-20338      
59082SERVER-WEBAPP Zoho ManageEngine OpManager GetGraphData Alarms section SQL injection attempt (more info ...)web-application-attack  2018-20338      
59090SERVER-WEBAPP Zoho ManageEngine OpManager GetGraphData API SQL injection attempt (more info ...)web-application-attack  2018-20173      
59126SERVER-WEBAPP Advantech iView UserServlet SQL injection attempt (more info ...)web-application-attack  2021-22658      
59127SERVER-WEBAPP Advantech iView UserServlet SQL injection attempt (more info ...)web-application-attack  2021-22658      
59128SERVER-WEBAPP Advantech iView UserServlet SQL injection attempt (more info ...)web-application-attack  2021-22658      
59326SERVER-WEBAPP rConfig compliance policies SQL injection attempt (more info ...)web-application-attack  2020-10547      
59327SERVER-WEBAPP rConfig compliance policies SQL injection attempt (more info ...)web-application-attack  2020-10547      
59328SERVER-WEBAPP rConfig compliance policies SQL injection attempt (more info ...)web-application-attack  2020-10547      
59329SERVER-WEBAPP rConfig snippets SQL injection attempt (more info ...)web-application-attack  2020-10549      
59330SERVER-WEBAPP rConfig snippets SQL injection attempt (more info ...)web-application-attack  2020-10549      
59331SERVER-WEBAPP rConfig snippets SQL injection attempt (more info ...)web-application-attack  2020-10549      
59339SERVER-WEBAPP Trend Micro Control Manager AdHocQuery_Processor GetProductCategory SQL injection attempt (more info ...)web-application-attack  2018-3602      
59340SERVER-WEBAPP Trend Micro Control Manager AdHocQuery_Processor GetProductCategory SQL injection attempt (more info ...)web-application-attack  2018-3602      
59341SERVER-WEBAPP Trend Micro Control Manager AdHocQuery_Processor GetProductCategory SQL injection attempt (more info ...)web-application-attack  2018-3602      
59358SERVER-WEBAPP Zoho ManageEngine Applications Manager AlertRes_Mtrgrp jsp sid SQL injection attempt (more info ...)web-application-attack  2020-15533      
59359SERVER-WEBAPP Zoho ManageEngine Applications Manager AlertRes_Mtrgrp jsp sid SQL injection attempt (more info ...)web-application-attack  2020-15533      
59360SERVER-WEBAPP Zoho ManageEngine Applications Manager AlertRes_Mtrgrp jsp sid SQL injection attempt (more info ...)web-application-attack  2020-15533      
59382SERVER-WEBAPP Zoho ManageEngine Applications Manager Popup_SLA SQL injection attempt (more info ...)web-application-attack  2019-11448      
59383SERVER-WEBAPP Zoho ManageEngine Applications Manager Popup_SLA SQL injection attempt (more info ...)web-application-attack  2019-11448      
59384SERVER-WEBAPP Zoho ManageEngine Applications Manager Popup_SLA SQL injection attempt (more info ...)web-application-attack  2019-11448      
59389SERVER-WEBAPP Trend Micro Control Manager GetRuleList SQL injection attempt (more info ...)web-application-attack  2018-3604      
59390SERVER-WEBAPP Trend Micro Control Manager GetRuleList SQL injection attempt (more info ...)web-application-attack  2018-3604      
59391SERVER-WEBAPP Trend Micro Control Manager GetRuleList SQL injection attempt (more info ...)web-application-attack  2018-3604      
59392SERVER-WEBAPP Trend Micro Control Manager GetRuleList SQL injection attempt (more info ...)web-application-attack  2018-3604      
59402SERVER-WEBAPP TimeClock Software 1.01 authenticated time based SQL injection attempt (more info ...)web-application-attack        
59403SERVER-WEBAPP TimeClock Software 1.01 authenticated time based SQL injection attempt (more info ...)web-application-attack        
59404SERVER-WEBAPP TimeClock Software 1.01 authenticated time based SQL injection attempt (more info ...)web-application-attack        
59436SERVER-WEBAPP Advantech WISE-PaaS RMM SQLMgmt qryData SQL injection attempt (more info ...)web-application-attack  2019-18229      
59609SERVER-WEBAPP Exponent CMS eaasController SQL injection attempt (more info ...)web-application-attack  2017-7991      URL
59812SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (more info ...)web-application-attack  2019-12989      URL
59910SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (more info ...)web-application-attack  2021-20028      URL
59911SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (more info ...)web-application-attack  2021-20028      URL
59912SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (more info ...)web-application-attack  2021-20028      URL
59913SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (more info ...)web-application-attack  2021-20028      URL
59914SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (more info ...)web-application-attack  2021-20028      URL
59915SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (more info ...)web-application-attack  2021-20028      URL
59976SERVER-WEBAPP Sonic Wall SRA and SMA appliances SQL injection attempt (more info ...)web-application-attack  2019-7484      
59977SERVER-WEBAPP Sonic Wall SRA and SMA appliances SQL injection attempt (more info ...)web-application-attack  2019-7484      
59978SERVER-WEBAPP Sonic Wall SRA and SMA appliances SQL injection attempt (more info ...)web-application-attack  2019-7484      
60073SERVER-WEBAPP NETGEAR ProSafe SSL VPN SQL injection attempt (more info ...)web-application-attack  2022-29383      
60074SERVER-WEBAPP NETGEAR ProSafe SSL VPN SQL injection attempt (more info ...)web-application-attack  2022-29383      
60075SERVER-WEBAPP NETGEAR ProSafe SSL VPN SQL injection attempt (more info ...)web-application-attack  2022-29383      
60093SERVER-WEBAPP Kaseya VSA SQL injection attempt (more info ...)web-application-attack  2021-30117      
60094SERVER-WEBAPP Kaseya VSA SQL injection attempt (more info ...)web-application-attack  2021-30117      
60095SERVER-WEBAPP Kaseya VSA SQL injection attempt (more info ...)web-application-attack  2021-30117      
60119SERVER-WEBAPP Kaseya VSA ManagedITSync arbitrary SQL command execution attempt (more info ...)web-application-attack  2017-18362      
60120SERVER-WEBAPP Kaseya VSA ManagedITSync arbitrary SQL command execution attempt (more info ...)web-application-attack  2017-18362      
60165SERVER-WEBAPP Zoho ManageEngine NetFlow Analyzer ReportApiHandler compareReport SQL injection attempt (more info ...)web-application-attack  2019-12196      
60166SERVER-WEBAPP Zoho ManageEngine NetFlow Analyzer ReportApiHandler compareReport SQL injection attempt (more info ...)web-application-attack  2019-12196      
60782SERVER-WEBAPP GLPI Project external token SQL injection attempt (more info ...)web-application-attack  2022-35947      
60783SERVER-WEBAPP GLPI Project external token SQL injection attempt (more info ...)web-application-attack  2022-35947      
60784SERVER-WEBAPP GLPI Project external token SQL injection attempt (more info ...)web-application-attack  2022-35947      
60786SERVER-WEBAPP GLPI Project external token SQL injection attempt (more info ...)web-application-attack  2022-35947      
60789SERVER-WEBAPP GLPI Project external token SQL injection attempt (more info ...)web-application-attack  2022-35947      
60800SERVER-WEBAPP Cisco Email Security Appliance SQL injection attempt (more info ...)web-application-attack  2022-20867      URL
60840SERVER-WEBAPP Joomla J2Store plugin SQL injection attempt (more info ...)web-application-attack  2019-9184      URL
60841SERVER-WEBAPP Joomla J2Store plugin SQL injection attempt (more info ...)web-application-attack  2019-9184      URL
60842SERVER-WEBAPP Joomla J2Store plugin SQL injection attempt (more info ...)web-application-attack  2019-9184      URL
60896SERVER-WEBAPP WordPress Zephyr Project Manager plugin zpm_view_task SQL injection attempt (more info ...)web-application-attack  2022-2840      URL
60897SERVER-WEBAPP WordPress Zephyr Project Manager plugin zpm_view_task SQL injection attempt (more info ...)web-application-attack  2022-2840      URL
60898SERVER-WEBAPP WordPress Zephyr Project Manager plugin zpm_view_project SQL injection attempt (more info ...)web-application-attack  2022-2840      URL
60899SERVER-WEBAPP WordPress Zephyr Project Manager plugin zpm_view_project SQL injection attempt (more info ...)web-application-attack  2022-2840      URL
60900SERVER-WEBAPP WordPress Zephyr Project Manager plugin zpm_new_task SQL injection attempt (more info ...)web-application-attack  2022-2840      URL
60901SERVER-WEBAPP WordPress Zephyr Project Manager plugin zpm_new_task SQL injection attempt (more info ...)web-application-attack  2022-2840      URL
60907SERVER-WEBAPP Sophos XG Firewall SQL injection attempt (more info ...)web-application-attack  2020-15504      URL
60908SERVER-WEBAPP Sophos XG Firewall SQL injection attempt (more info ...)web-application-attack  2020-15504      URL
60909SERVER-WEBAPP Sophos XG Firewall SQL injection attempt (more info ...)web-application-attack  2020-15504      URL
61106SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61112SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61117SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61118SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61120SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61128SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61130SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61131SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61140SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61142SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61144SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61149SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61151SERVER-WEBAPP Fscan scanner SQL injection attempt (more info ...)web-application-attack        URL
61169SERVER-WEBAPP Cisco Unified Communications Manager SQL injection attempt (more info ...)web-application-attack  2023-20010      URL
61170SERVER-WEBAPP Cisco Unified Communications Manager SQL injection attempt (more info ...)web-application-attack  2023-20010      URL
61241SERVER-WEBAPP Paid Memberships Pro WordPress Plugin SQL injection attempt (more info ...)web-application-attack  2023-23488      
61242SERVER-WEBAPP Paid Memberships Pro WordPress Plugin SQL injection attempt (more info ...)web-application-attack  2023-23488      
61243SERVER-WEBAPP Paid Memberships Pro WordPress Plugin SQL injection attempt (more info ...)web-application-attack  2023-23488      
61326INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit PowerUpSQL download attempt (more info ...)trojan-activity        URL
61327INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit PowerUpSQL download attempt (more info ...)trojan-activity        URL
61537SERVER-WEBAPP Zoho ManageEngine Password Manager Pro SQL injection attempt (more info ...)web-application-attack  2022-43672      URL
61538SERVER-WEBAPP Zoho ManageEngine Password Manager Pro SQL injection attempt (more info ...)web-application-attack  2022-43672      URL
61540SERVER-WEBAPP Rebuild files/list-file SQL injection attempt (more info ...)web-application-attack  2023-1610      URL
61541SERVER-WEBAPP Rebuild project/tasks/list SQL injection attempt (more info ...)web-application-attack  2023-1610      URL
61542SERVER-WEBAPP Rebuild files/list-file SQL injection attempt (more info ...)web-application-attack  2023-1610      URL
61543SERVER-WEBAPP Rebuild files/list-file SQL injection attempt (more info ...)web-application-attack  2023-1610      URL
61544SERVER-WEBAPP Rebuild project/tasks/list SQL injection attempt (more info ...)web-application-attack  2023-1610      URL
61545SERVER-WEBAPP Rebuild project/tasks/list SQL injection attempt (more info ...)web-application-attack  2023-1610      URL
61868FILE-IDENTIFY sqlite3 magic detected (more info ...)misc-activity        
61869FILE-IDENTIFY sqlite3 magic detected (more info ...)misc-activity        
62013SERVER-WEBAPP MOVEit username sql injection attempt (more info ...)web-application-attack  2023-36934      URL
62104SERVER-WEBAPP Progress MOVEit Transfer SILCertToUser SQL injection attempt (more info ...)web-application-attack  2023-35036      


# of warning rules in this group: 363

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
673SQL sp_start_job - program execution (more info ...)attempted-user    
676SQL sp_start_job - program execution (more info ...)attempted-user    
677SQL sp_password password change (more info ...)attempted-user    
678SQL sp_delete_alert log file deletion (more info ...)attempted-user    
679SQL sp_adduser database user creation (more info ...)attempted-user    
681SQL xp_cmdshell program execution (more info ...)attempted-user  5309  
683SQL sp_password - password change (more info ...)attempted-user    
684SQL sp_delete_alert log file deletion (more info ...)attempted-user    
685SQL sp_adduser - database user creation (more info ...)attempted-user    
687SQL xp_cmdshell - program execution (more info ...)attempted-user  5309  
688SQL sa login failed (more info ...)unsuccessful-user 2000-1209 4797 10673 
861SERVER-WEBAPP w3-msql access (more info ...)attempted-recon 2000-0012 898 10296 
887SERVER-WEBAPP www-sql access (more info ...)attempted-recon    URL
1057SQL ftp attempt (more info ...)web-application-activity    
1058SQL xp_enumdsn attempt (more info ...)web-application-attack    
1059SQL xp_filelist attempt (more info ...)web-application-attack    
1060SQL xp_availablemedia attempt (more info ...)web-application-attack    
1061SQL xp_cmdshell attempt (more info ...)web-application-attack  5309  
1069SQL xp_regread attempt (more info ...)web-application-activity    
1077SQL queryhit.htm access (more info ...)web-application-activity   10370 
1078SQL counter.exe access (more info ...)web-application-activity 1999-1030 267  
1385SERVER-WEBAPP mod-plsql administration access (more info ...)web-application-activity 2001-1217 3727 10849 
1387SQL raiserror possible buffer overflow (more info ...)attempted-user 2001-0542 3733 11217 
1759SQL xp_cmdshell program execution 445 (more info ...)attempted-user  5309  
2063SERVER-WEBAPP Demarc SQL injection attempt (more info ...)web-application-activity 2002-0539 4520  
2701SERVER-WEBAPP Oracle iSQLPlus sid overflow attempt (more info ...)web-application-attack 2004-1371 10871  URL
2702SERVER-WEBAPP Oracle iSQLPlus username overflow attempt (more info ...)web-application-attack 2004-1371 10871  URL
2703SERVER-WEBAPP Oracle iSQLPlus login.uix username overflow attempt (more info ...)web-application-attack 2004-1371 10871  URL
2704SERVER-WEBAPP Oracle 10g iSQLPlus login.unix connectID overflow attempt (more info ...)web-application-attack 2004-1371 10871  URL
3152SQL sa brute force failed login attempt (more info ...)unsuccessful-user 2000-1209 4797 10673 URL
3273SQL sa brute force failed login unicode attempt (more info ...)unsuccessful-user 2000-1209 4797 10673 URL
3542SQL SA brute force login attempt (more info ...)suspicious-login 2000-1209 4797 10673 URL
4984SQL sa brute force failed login unicode attempt (more info ...)unsuccessful-user 2000-1209 4797 10673 URL
7207SERVER-ORACLE DBMS_EXPORT_EXTENSION SQL injection attempt (more info ...)attempted-user 2006-3702 19054  
8059SERVER-ORACLE SYS.KUPW-WORKER sql injection attempt (more info ...)attempted-admin 2006-3698 19054  URL
8494SQL formatmessage possible buffer overflow (more info ...)attempted-admin 2001-0542 3733  
8495SQL formatmessage possible buffer overflow (more info ...)attempted-admin 2001-0542 3733  
8713SERVER-WEBAPP cacti graph_image SQL injection attempt (more info ...)web-application-attack 2005-2148 14129  
8714SERVER-WEBAPP cacti graph_image SQL injection attempt (more info ...)web-application-attack 2005-2148 14129  
8715SERVER-WEBAPP cacti graph_image SQL injection attempt (more info ...)web-application-attack 2005-2148 14129  
8716SERVER-WEBAPP cacti graph_image SQL injection attempt (more info ...)web-application-attack 2005-2148 14129  
11193SERVER-WEBAPP Oracle iSQL Plus cross site scripting attempt (more info ...)web-application-attack 2004-2115 9484  
11194SERVER-WEBAPP Oracle iSQL Plus cross site scripting attempt (more info ...)web-application-attack 2004-2115 9484  
11204SERVER-ORACLE Oracle Database DBMS_AQADM_SYS package GRANT_TYPE_ACCESS procedure SQL injection attempt (more info ...)attempted-admin 2009-0977 34461  URL
11616SERVER-WEBAPP Symantec Sygate Policy Manager SQL injection (more info ...)attempted-admin 2006-0522 16452  
11685SERVER-WEBAPP Oracle iSQL Plus cross site scripting attempt (more info ...)web-application-attack 2004-2115 9484  
12009SQL Firebird SQL Fbserver buffer overflow attempt (more info ...)attempted-user 2007-3181   
13366SERVER-ORACLE Oracle database SYS.LT.FINDRICSET SQL injection attempt (more info ...)attempted-admin 2007-5511 26098  URL
13551SERVER-ORACLE Oracle XDB.XDB_PITRIG_PKG sql injection attempt (more info ...)attempted-admin 2008-0339 27229  URL
13553SERVER-OTHER Sybase SQL Anywhere Mobilink username string buffer overflow (more info ...)attempted-admin 2008-0912 27914  URL
13554SERVER-OTHER Sybase SQL Anywhere Mobilink version string buffer overflow (more info ...)attempted-admin 2008-0912 27914  URL
13555SERVER-OTHER Sybase SQL Anywhere Mobilink remoteID string buffer overflow (more info ...)attempted-admin 2008-0912 27914  URL
13791INDICATOR-OBFUSCATION oversized cast statement - possible sql injection obfuscation (more info ...)web-application-attack    URL
13928SERVER-WEBAPP Adobe RoboHelp rx SQL injection attempt (more info ...)web-application-attack 2008-2991 30137  URL
13929SERVER-WEBAPP Adobe RoboHelp rx SQL injection attempt (more info ...)web-application-attack 2008-2991 30137  URL
13987INDICATOR-OBFUSCATION oversized convert statement - possible sql injection obfuscation (more info ...)web-application-attack    URL
13988INDICATOR-OBFUSCATION large number of calls to ascii function - possible sql injection obfuscation (more info ...)web-application-attack    URL
13991SQL xp_regaddmultistring attempt (more info ...)web-application-activity    
13992SQL xp_regdeletevalue attempt (more info ...)web-application-activity    
13993SQL xp_regenumkeys attempt (more info ...)web-application-activity    
13994SQL xp_regenumvalues attempt (more info ...)web-application-activity    
13995SQL xp_regremovemultistring attempt (more info ...)web-application-activity    
13996SQL xp_servicecontrol attempt (more info ...)web-application-activity    
13997SQL xp_loginconfig attempt (more info ...)web-application-activity    
13998SQL xp_terminate_process attempt (more info ...)web-application-activity    
15319NETBIOS SMB /sql/query create tree attempt (more info ...)protocol-command-decode    
15321NETBIOS SMB /sql/query create tree attempt (more info ...)protocol-command-decode    
15322NETBIOS SMB /sql/query unicode create tree attempt (more info ...)protocol-command-decode    
15323NETBIOS SMB /sql/query andx create tree attempt (more info ...)protocol-command-decode    
15324NETBIOS SMB /sql/query unicode andx create tree attempt (more info ...)protocol-command-decode    
15325NETBIOS SMB /sql/query andx create tree attempt (more info ...)protocol-command-decode    
15326NETBIOS SMB /sql/query unicode andx create tree attempt (more info ...)protocol-command-decode    
15515SERVER-ORACLE Oracle Database Server RollbackWorkspace SQL injection attempt (more info ...)attempted-admin 2009-0978 34461  URL
15722SERVER-ORACLE Oracle database server Workspace Manager multiple SQL injection attempt (more info ...)attempted-admin 2008-3982 31683  URL
15723SERVER-ORACLE Oracle database server CompressWorkspaceTree SQL injection attempt (more info ...)attempted-admin 2008-3982 31683  URL
15724SERVER-ORACLE Oracle database server MergeWorkspace SQL injection attempt (more info ...)attempted-admin 2008-3982 31683  URL
15725SERVER-ORACLE Oracle database server RemoveWorkspace SQL injection attempt (more info ...)attempted-admin 2008-3982 31683  URL
15876SQL generic sql update injection attempt - POST parameter (more info ...)web-application-attack    URL
15896SERVER-OTHER Firebird SQL op_connect_request denial of service attempt (more info ...)attempted-dos 2009-2620 35842  
16159BROWSER-PLUGINS Microsoft Office Excel Add-in for SQL Analysis Services 1 ActiveX clsid access (more info ...)attempted-user 2009-2493   URL
16161BROWSER-PLUGINS Microsoft Office Excel Add-in for SQL Analysis Services 2 ActiveX clsid access (more info ...)attempted-user 2009-2493   URL
16163BROWSER-PLUGINS Microsoft Office Excel Add-in for SQL Analysis Services 3 ActiveX clsid access (more info ...)attempted-user 2009-2493   URL
16165BROWSER-PLUGINS Microsoft Office Excel Add-in for SQL Analysis Services 4 ActiveX clsid access (more info ...)attempted-user 2009-2493   URL
16189SERVER-ORACLE Database REPCAT_RPC.VALIDATE_REMOTE_RC SQL injection attempt (more info ...)attempted-admin 2009-1021 35685  URL
16290SERVER-ORACLE Oracle database server CREATE_TABLES SQL injection attempt (more info ...)attempted-admin 2009-1991 36748  URL
16364SERVER-OTHER IBM DB2 database server SQLSTT denial of service attempt (more info ...)denial-of-service 2009-0173   
16393SERVER-OTHER PostgreSQL bit substring buffer overflow attempt (more info ...)attempted-admin 2010-0442 37973  
16524PROTOCOL-FTP ProFTPD username sql injection attempt (more info ...)attempted-admin 2009-0542 33722  URL
16722SERVER-ORACLE Oracle Database Server DBMS_CDC_PUBLISH.DROP_CHANGE_SOURCE procedure SQL injection attempt (more info ...)attempted-user 2010-0870 39422  
16723SERVER-ORACLE Oracle Database Server DBMS_CDC_PUBLISH.ALTER_CHANGE_SOURCE procedure SQL injection attempt (more info ...)attempted-user 2010-0870 39422  
17270SERVER-ORACLE DBMS_METADATA Package SQL Injection attempt (more info ...)attempted-user 2005-1197   
17449SERVER-WEBAPP Novell ZENworks patch management SQL injection attempt (more info ...)web-application-attack 2005-3315 15220  
17590SERVER-ORACLE DBMS_ASSERT.simple_sql_name double quote SQL injection attempt (more info ...)misc-attack  19203  
18426FILE-OTHER Adobe Acrobat Reader plugin sqlite.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18431FILE-PDF Adobe Acrobat Reader plugin sqlite.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18556SERVER-WEBAPP Symantec IM manager IMAdminReportTrendFormRun.asp sql injection attempt (more info ...)attempted-user 2010-0112 44299  URL
18955SERVER-WEBAPP Symantec IM Manager LoggedInUsers.lgx definition file multiple SQL injections attempt (more info ...)web-application-attack 2010-0112 44299  
18956SERVER-WEBAPP Symantec IM Manager LoggedInUsers.lgx definition file multiple SQL injections attempt (more info ...)web-application-attack 2010-0112 44299  
19142SERVER-WEBAPP Symantec IM Manager IMAdminScheduleReport.asp SQL injection attempt (more info ...)web-application-attack 2010-0112 44299  
19201SQL waitfor delay function - possible SQL injection attempt (more info ...)web-application-attack 2012-2998   URL
19202SQL declare varchar - possible SQL injection attempt (more info ...)web-application-attack    URL
19476MALWARE-CNC Exploit.Win32.SqlShell.r variant outbound connection (more info ...)trojan-activity    URL
19599SERVER-ORACLE Warehouse builder WE_OLAP_AW_REMOVE_SOLVE_ID SQL Injection attempt (more info ...)attempted-admin 2011-0799 44260  
19600SERVER-ORACLE Warehouse builder WE_OLAP_AW_SET_SOLVE_ID SQL Injection attempt (more info ...)attempted-admin 2011-0799 44260  
19779INDICATOR-SCAN sqlmap SQL injection scan attempt (more info ...)web-application-activity    URL
19810SERVER-OTHER CA Total Defense Suite UNCWS deleteReportTemplate SQL injection attempt (more info ...)attempted-admin 2011-1655   
20047SQL 1 = 1 - possible sql injection attempt (more info ...)web-application-attack    URL
20615SERVER-WEBAPP Wordcircle SQL injection attempt (more info ...)web-application-activity 2006-0205 16227  
20623SERVER-WEBAPP Venom Board SQL injection attempt (more info ...)web-application-activity 2006-0160 16176  
20624SERVER-WEBAPP Venom Board SQL injection attempt (more info ...)web-application-activity 2006-0160 16176  
20625SERVER-WEBAPP Venom Board SQL injection attempt (more info ...)web-application-activity 2006-0160 16176  
20832SERVER-WEBAPP Symantec IM Manager administrator interface SQL injection attempt (more info ...)web-application-attack 2011-0553 49738  URL
21121INDICATOR-COMPROMISE WSO web shell interactive SQL display (more info ...)trojan-activity    URL
21132INDICATOR-COMPROMISE Mulcishell web shell sql interaction page (more info ...)trojan-activity    URL
21271SERVER-WEBAPP Devellion CubeCart searchStr parameter SQL injection (more info ...)web-application-attack    URL
21377SERVER-WEBAPP Cisco Unified Communications Manager sql injection attempt (more info ...)web-application-attack 2011-1610   URL
21395SERVER-ORACLE 10g iSQLPlus service heap overflow attempt (more info ...)attempted-user 2004-1371 10871  
21396SERVER-ORACLE 10g iSQLPlus service heap overflow attempt (more info ...)attempted-user 2004-1371 10871  
21777SQL waitfor delay function in POST - possible SQL injection attempt (more info ...)web-application-attack    URL
21779SQL parameter ending in encoded comment characters - possible sql injection attempt - POST (more info ...)web-application-attack    URL
21780INDICATOR-OBFUSCATION encoded waitfor delay function in POST - possible sql injection attempt (more info ...)misc-attack    URL
21781INDICATOR-OBFUSCATION encoded union select function in POST - possible sql injection attempt (more info ...)misc-attack    URL
21788SQL or kic = kic - known SQL injection routine (more info ...)web-application-attack    
21789SQL or kic = kic - known SQL injection routine (more info ...)web-application-attack    
23213SQL Ruby on rails SQL injection attempt (more info ...)web-application-attack 2012-2695   
23216SERVER-WEBAPP Ruby on Rails SQL injection attempt (more info ...)web-application-attack 2012-2661   
23393SQL IBM SolidDB initial banner (more info ...)misc-activity    
24421PROTOCOL-SCADA Sinapsi SQL injection attempt (more info ...)web-application-attack    URL
24422PROTOCOL-SCADA Sinapsi SQL injection attempt (more info ...)web-application-attack    URL
24423PROTOCOL-SCADA Sinapsi SQL hard coded user login attempt (more info ...)web-application-attack    URL
24424PROTOCOL-SCADA Sinapsi SQL hard coded user login attempt (more info ...)web-application-attack    URL
24629SERVER-WEBAPP Oracle Fusion Middleware WebCenter selectedLocale parameter sql injection attempt (more info ...)web-application-attack 2012-3186 55984  URL
24801SERVER-WEBAPP IBM Tivoli Provisioning Manager Express asset.getmimetype sql injection attempt (more info ...)attempted-user 2012-0199   URL
25285SERVER-OTHER Ruby on Rails authlogic session cookie SQL injection attempt (more info ...)web-application-attack 2012-6496   URL
25783INDICATOR-OBFUSCATION large number of calls to char function - possible sql injection obfuscation (more info ...)web-application-attack    URL
26075MALWARE-CNC Bancos variant outbound connection SQL query POST data (more info ...)trojan-activity    URL
26586SERVER-OTHER PostgreSQL database name command line injection attempt (more info ...)attempted-user 2013-1899   URL
26925SQL generic convert injection attempt - GET parameter (more info ...)web-application-attack    URL
27285SERVER-WEBAPP Gazi Download Portal down_indir.asp SQL injection attempt (more info ...)web-application-attack 2007-2810 23714  
27286SERVER-WEBAPP DuWare DuClassmate default.asp iCity sql injection attempt (more info ...)web-application-attack 2006-6355   URL
27681SERVER-WEBAPP ASPMForum SQL injection attempt (more info ...)web-application-attack 2006-6270 21113  
27682SERVER-WEBAPP ASPMForum SQL injection attempt (more info ...)web-application-attack 2006-6270 21113  
27683SERVER-WEBAPP ASPMForum SQL injection attempt (more info ...)web-application-attack 2006-6270 21113  
27684SERVER-WEBAPP ASPMForum SQL injection attempt (more info ...)web-application-attack 2006-6270 21113  
27685SERVER-WEBAPP ASPMForum SQL injection attempt (more info ...)web-application-attack 2006-6270 21113  
27686SERVER-WEBAPP ASPMForum SQL injection attempt (more info ...)web-application-attack 2006-6270 21113  
27687SERVER-WEBAPP ASPMForum SQL injection attempt (more info ...)web-application-attack 2006-6270 21113  
27723SQL McAfee ePolicy Orchestrator timing based SQL injection attempt (more info ...)attempted-admin 2013-0140 59500  URL
27748SERVER-WEBAPP Outfront Spooky Login register.asp SQL injection attempt (more info ...)web-application-attack 2006-6861 21822  URL
27749SERVER-WEBAPP Outfront Spooky Login a_register.asp SQL injection attempt (more info ...)web-application-attack 2006-6861 21822  URL
27753SERVER-WEBAPP Click N Print Coupons coupon_detail.asp SQL injection attempt (more info ...)web-application-attack 2006-6859 21824  URL
28098SERVER-OTHER CA Total Defense Suite UNCWS reGenerateReports/DeleteReports SQL injection attempt (more info ...)attempted-admin 2011-1655   
28099SERVER-OTHER CA Total Defense Suite UNCWS reGenerateReports/DeleteReports SQL injection attempt (more info ...)attempted-admin 2011-1655   
28100SERVER-OTHER CA Total Defense Suite UNCWS deleteReportFilter SQL injection attempt (more info ...)attempted-admin 2011-1655   
28101SERVER-OTHER CA Total Defense Suite UNCWS reGenerateReports/DeleteReports SQL injection attempt (more info ...)attempted-admin 2011-1655   
28102SERVER-OTHER CA Total Defense Suite UNCWS ReportFilterID/reportTemplateID SQL injection attempt (more info ...)attempted-admin 2011-1655   
28278SERVER-WEBAPP IBM Tivoli Provisioning Manager express user.updateUserValue sql injection attempt (more info ...)attempted-admin 2012-0199   URL
28299SERVER-WEBAPP WHMCS SQL injection attempt (more info ...)web-application-attack    URL
28344INDICATOR-OBFUSCATION large number of calls to chr function - possible sql injection obfuscation (more info ...)web-application-attack    URL
28446MALWARE-CNC Win.Trojan.Symmi variant SQL check-in (more info ...)trojan-activity    URL
28555MALWARE-OTHER SQL Slammer worm propagation attempt inbound (more info ...)trojan-activity 2002-0649 5311  
28908SERVER-OTHER Nagios core config manager tfpassword sql injection attempt (more info ...)web-application-attack 2013-6875   URL
29018SERVER-WEBAPP HP LoadRunner Virtual User Generator EmulationAdmin getReport SQL injection attempt (more info ...)attempted-admin 2013-4839 63477  URL
29756SERVER-WEBAPP IBM Tivoli Provisioning Manager express user.updateUserValue sql injection attempt (more info ...)attempted-admin 2012-0199   URL
29878MALWARE-CNC Win.Trojan.Dexter CasinoLoader SQL injection (more info ...)trojan-activity    URL
29879MALWARE-CNC Win.Trojan.Dexter CasinoLoader SQL injection (more info ...)trojan-activity    URL
29880MALWARE-CNC Win.Trojan.Dexter CasinoLoader SQL injection (more info ...)trojan-activity    URL
29881MALWARE-CNC Win.Trojan.Dexter CasinoLoader SQL injection (more info ...)trojan-activity    URL
30343SERVER-WEBAPP Joomla weblinks-categories SQL injection attempt (more info ...)web-application-attack  65410  URL
31067SERVER-WEBAPP Advantech WebAccess ChartThemeConfig SQL injection attempt (more info ...)attempted-admin 2014-0763 66740  URL
31636SERVER-WEBAPP Parallels Plesk Panel HTTP_AUTH_LOGIN SQL injection attempt (more info ...)web-application-attack 2012-1557 52267  URL
31728SERVER-WEBAPP ManageEngine Desktop Central LinkViewFetchServlet SQL injection attempt (more info ...)web-application-attack 2014-3996 69305  
31729SERVER-WEBAPP ManageEngine Password Manager MetadataServlet SQL injection attempt (more info ...)web-application-attack 2014-3997 69303  
32115SERVER-OTHER Cisco ASA SQLNet inspection engine denial of service attempt (more info ...)attempted-dos 2014-3382   URL
32116SERVER-OTHER Cisco ASA SQLNet inspection engine denial of service attempt (more info ...)attempted-dos 2014-3382   URL
32323SERVER-WEBAPP WordPress Custom Contact Forms plugin SQL export attempt (more info ...)attempted-recon    
32324SERVER-WEBAPP WordPress Custom Contact Forms plugin arbitrary SQL execution attempt (more info ...)attempted-admin    
32737SERVER-OTHER Lianja SQL Server db_netserver Buffer Overflow attempt (more info ...)attempted-user 2013-3563   
33651SERVER-WEBAPP Solarwinds Orion AccountManagement SQL injection attempt (more info ...)web-application-attack 2014-9566   
33652SERVER-WEBAPP Solarwinds Orion AccountManagement SQL injection attempt (more info ...)web-application-attack 2014-9566   
33653SERVER-WEBAPP Solarwinds Orion AccountManagement SQL injection attempt (more info ...)web-application-attack 2014-9566   
33657SERVER-WEBAPP Dell ScriptLogic Asset Manager SQL injection attempt (more info ...)web-application-attack 2015-1605 72697  
33658SERVER-WEBAPP Dell ScriptLogic Asset Manager SQL injection attempt (more info ...)web-application-attack 2015-1605 72697  
33659SERVER-WEBAPP Dell ScriptLogic Asset Manager SQL injection attempt (more info ...)web-application-attack 2015-1605 72697  
34472SERVER-WEBAPP Symantec Critical System Protection SQL injection attempt (more info ...)attempted-admin 2014-7289 72092  
34800SERVER-ORACLE 10g iSQLPlus service heap overflow attempt (more info ...)attempted-user 2004-1371 10871  
34801SERVER-ORACLE 10g iSQLPlus service heap overflow attempt (more info ...)attempted-user 2004-1371 10871  
35354SERVER-WEBAPP Cacti graphs local_graph_id SQL injection attempt (more info ...)web-application-attack 2015-4634 75984  
35385MALWARE-CNC Win.Trojan.MSIL-Pwsfcbk SQL connection (more info ...)trojan-activity    URL
35701SERVER-WEBAPP ManageEngine OpManager agentKey SQL injection attempt (more info ...)web-application-attack    
35702SERVER-WEBAPP ManageEngine OpManager agentKey SQL injection attempt (more info ...)web-application-attack    
35887POLICY-OTHER SCADA Engine BACnet OPC Server untrusted SQL query execution attempt (more info ...)policy-violation    
36061SERVER-OTHER SAP SQL Anywhere .NET malformed integer buffer overflow attempt (more info ...)attempted-user 2014-9264   URL
36615SERVER-WEBAPP Joomla com_contenthistory module SQL injection attempt (more info ...)web-application-attack 2015-7858 77295  
36616SERVER-WEBAPP Joomla com_contenthistory module SQL injection attempt (more info ...)web-application-attack 2015-7858 77295  
36617SERVER-WEBAPP Joomla com_contenthistory module SQL injection attempt (more info ...)web-application-attack 2015-7858 77295  
36655SERVER-WEBAPP Joomla com_realestatemanager module SQL injection attempt (more info ...)web-application-attack    URL
36656SERVER-WEBAPP Joomla com_realestatemanager module SQL injection attempt (more info ...)web-application-attack    URL
36657SERVER-WEBAPP Joomla com_realestatemanager module SQL injection attempt (more info ...)web-application-attack    URL
36915POLICY-OTHER ManageEngine EventLog Analyzer runQuery.do insecure SQL query attempt (more info ...)policy-violation 2015-7387 76866  
37096SERVER-WEBAPP Joomla Component com_gmaps SQL injection attempt (more info ...)web-application-attack 2007-4128 25146  
37097SERVER-WEBAPP Joomla Component com_gmaps SQL injection attempt (more info ...)web-application-attack 2007-4128 25146  
37098SERVER-WEBAPP Joomla Component com_gmaps SQL injection attempt (more info ...)web-application-attack 2007-4128 25146  
37099SERVER-WEBAPP Joomla Component com_gmaps SQL injection attempt (more info ...)web-application-attack 2007-4128 25146  
37133SERVER-WEBAPP Joomla com_youtubegallery module SQL injection attempt (more info ...)web-application-attack 2014-4960 68676  
37134SERVER-WEBAPP Joomla com_youtubegallery module SQL injection attempt (more info ...)web-application-attack 2014-4960 68676  
37148SERVER-WEBAPP WordPress Gallery Objects Plugin viewid SQL injection attempt (more info ...)web-application-attack 2014-5201 68791  
37643SQL Oracle e-Business Suite ORACLESSWA SQL injection attempt (more info ...)web-application-attack 2016-0589   
37648SQL Oracle e-Business Suite JTF_BISUTILITY_PUB SQL injection attempt (more info ...)web-application-attack 2016-0515   
38398SERVER-WEBAPP DotCMS UserAjax.getUsersList.dwr SQL injection attempt (more info ...)web-application-attack 2016-3688   
38499MALWARE-OTHER samsam sqlsrvtmg1.exe file load attempt (more info ...)trojan-activity    
38502MALWARE-OTHER samsam sqlsrvtmg1.exe file load attempt (more info ...)trojan-activity    
38720SERVER-WEBAPP Wordpress Simple Ads Manager SQL injection attempt (more info ...)web-application-attack 2015-2824 73698  
38721SERVER-WEBAPP Wordpress Simple Ads Manager SQL injection attempt (more info ...)web-application-attack 2015-2824 73698  
38722SERVER-WEBAPP Wordpress Simple Ads Manager SQL injection attempt (more info ...)web-application-attack 2015-2824 73698  
38723SERVER-WEBAPP Wordpress Simple Ads Manager SQL injection attempt (more info ...)web-application-attack 2015-2824 73698  
38925SERVER-WEBAPP Dell SonicWall Scrutinizer deleteTab SQL injection attempt (more info ...)web-application-attack    URL
38926SERVER-WEBAPP Dell SonicWall Scrutinizer deleteTab SQL injection attempt (more info ...)web-application-attack    URL
38927SERVER-WEBAPP Dell SonicWall Scrutinizer setSkin SQL injection attempt (more info ...)web-application-attack    URL
38928SERVER-WEBAPP Dell SonicWall Scrutinizer setSkin SQL injection attempt (more info ...)web-application-attack    URL
38929SERVER-WEBAPP Dell SonicWall Scrutinizer user_id SQL injection attempt (more info ...)web-application-attack    URL
38930SERVER-WEBAPP Dell SonicWall Scrutinizer user_id SQL injection attempt (more info ...)web-application-attack    URL
38979SERVER-WEBAPP Dell SonicWall Scrutinizer methodDetail SQL injection attempt (more info ...)web-application-attack 2014-4977 68495  
39027SERVER-WEBAPP ManageEngine Applications Manager downTimeScheduler.do SQL injection attempt (more info ...)web-application-attack    URL
39060SERVER-WEBAPP SAP NetWeaver UDDISecurityImplBean SQL injection attempt (more info ...)web-application-attack 2016-2386   URL
39388SERVER-WEBAPP ICSCADA SQL injection attempt (more info ...)web-application-attack    
39389SERVER-WEBAPP Wintr SQL injection attempt (more info ...)web-application-attack    URL
39390SERVER-WEBAPP IntegraXOR SQL injection attempt (more info ...)web-application-attack 2016-2301   
39435SERVER-WEBAPP Advantech SQL injection attempt (more info ...)web-application-attack    URL
39436SERVER-WEBAPP Soitec Smart Energy SQL injection attempt (more info ...)web-application-attack    URL
39437SERVER-WEBAPP Advantech SQL injection attempt (more info ...)web-application-attack    URL
39460SERVER-WEBAPP Oracle E-Business Suite SQL injection attempt (more info ...)web-application-attack 2007-2126 23532  
39461SERVER-WEBAPP Oracle E-Business Suite SQL injection attempt (more info ...)web-application-attack 2007-2126 23532  
39462SERVER-WEBAPP Oracle E-Business Suite SQL injection attempt (more info ...)web-application-attack 2007-2126 23532  
40313SQL PostgreSQL potential remote code execution attempt (more info ...)misc-activity    URL
40462SERVER-WEBAPP Magento Cms_Wysiwyg SQL injection attempt (more info ...)web-application-attack 2015-1397   
40463SERVER-WEBAPP Magento Cms_Wysiwyg SQL injection attempt (more info ...)web-application-attack 2015-1397   
40464SERVER-WEBAPP Magento Cms_Wysiwyg SQL injection attempt (more info ...)web-application-attack 2015-1397   
41637INDICATOR-COMPROMISE Writable SQL directories discovery attempt (more info ...)attempted-recon    URL
41915POLICY-OTHER Carel PlantVisorPRO insecure SQL query transmission (more info ...)web-application-attack    URL
41916SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - DBCommander (more info ...)web-application-attack    URL
41918SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - RCmdComm (more info ...)web-application-attack    URL
41919SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - RCmdComm2 (more info ...)web-application-attack    URL
42976SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42977SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42978SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42979SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42980SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42981SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42982SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42983SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42984SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42985SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42986SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42987SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42988SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42989SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42990SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42991SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
42992SERVER-ORACLE Oracle Database Server SYS.KUPV SQL injection attempt (more info ...)attempted-admin 2006-0586 16287  
43073SQL SysAid potential default credential login attempt (more info ...)default-login-attempt 2015-3001   URL
43503SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43504SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43505SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43506SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43507SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43508SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43509SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43510SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43511SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43512SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43513SERVER-WEBAPP Cisco Prime Infrastructure SQL injection attempt (more info ...)web-application-attack 2017-6698   
43581SERVER-OTHER Oracle DBMS AUTH_ALTER_SESSION SQL injection attempt (more info ...)attempted-admin 2006-0547 84088  URL
43733SERVER-WEBAPP Sophos XG Firewall Controller filter SQL injection attempt (more info ...)web-application-attack    URL
43734SERVER-WEBAPP Sophos XG Firewall Controller filter SQL injection attempt (more info ...)web-application-attack    URL
45832SERVER-WEBAPP Cisco Unified Communications Manager appuserFindList.do SQL injection attempt (more info ...)web-application-attack 2018-0120 102958  URL
45833SERVER-WEBAPP Cisco Unified Communications Manager appuserFindList.do SQL injection attempt (more info ...)web-application-attack 2018-0120 102958  URL
46462SERVER-WEBAPP Adobe RoboHelp rx SQL injection attempt (more info ...)web-application-attack 2008-2991 30137  URL
46463SERVER-WEBAPP Adobe RoboHelp rx SQL injection attempt (more info ...)web-application-attack 2008-2991 30137  URL
46866SERVER-WEBAPP TYPO3 news module SQL injection attempt (more info ...)web-application-attack 2017-7581   URL
46998MALWARE-CNC Win.Trojan.MnuBot variant outbound SQL connection (more info ...)trojan-activity    URL
47467SERVER-WEBAPP Redaxo CMS addon SQL injection attempt (more info ...)web-application-attack    
47468SERVER-WEBAPP Redaxo CMS addon SQL injection attempt (more info ...)web-application-attack    
47469SERVER-WEBAPP Redaxo CMS addon SQL injection attempt (more info ...)web-application-attack    
47675SERVER-WEBAPP Cogent DataHub SQL injection attempt (more info ...)web-application-attack    
47676SERVER-WEBAPP Cogent DataHub SQL injection attempt (more info ...)web-application-attack    
47771SERVER-WEBAPP ClipBucket vote_channel SQL injection attempt (more info ...)web-application-attack 2018-7666   
47772SERVER-WEBAPP ClipBucket commonAjax SQL injection attempt (more info ...)web-application-attack 2018-7666   
47858SERVER-WEBAPP Joomla CW Tags Searchtext SQL injection attempt (more info ...)web-application-attack 2018-7313   URL
47859SERVER-WEBAPP Joomla CW Tags Searchtext SQL injection attempt (more info ...)web-application-attack 2018-7313   URL
48165SERVER-WEBAPP Joomla Component Swap Factory SQL injection attempt (more info ...)web-application-attack 2018-17384   URL
48166SERVER-WEBAPP Joomla Component Swap Factory SQL injection attempt (more info ...)web-application-attack 2018-17384   URL
49405SERVER-WEBAPP Advantech WebAccess 8.3.2 Dashboard SQL injection attempt (more info ...)web-application-attack 2017-16716   
49406SERVER-WEBAPP Advantech WebAccess 8.3.2 Dashboard SQL injection attempt (more info ...)web-application-attack 2017-16716   
49407SERVER-WEBAPP Advantech WebAccess 8.3.2 Dashboard SQL injection attempt (more info ...)web-application-attack 2017-16716   
49413SERVER-WEBAPP Samsung Integrated Management System Data Management Server SQL injection attempt (more info ...)web-application-attack 2010-4284   
49414SERVER-WEBAPP Samsung Integrated Management System Data Management Server SQL injection attempt (more info ...)web-application-attack 2010-4284   
49415SERVER-WEBAPP Samsung Integrated Management System Data Management Server SQL injection attempt (more info ...)web-application-attack 2010-4284   
49524SERVER-WEBAPP TPLink TD W8151N SQL injection attempt (more info ...)web-application-attack    
49525SERVER-WEBAPP TPLink TD W8151N SQL injection attempt (more info ...)web-application-attack    
49526SERVER-WEBAPP TPLink TD W8151N SQL injection attempt (more info ...)web-application-attack    
49819SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49820SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49821SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49822SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49823SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49824SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49825SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49826SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49827SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49828SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49829SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49830SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49831SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49832SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49833SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49834SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49835SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
49836SERVER-WEBAPP DoD IT Solutions Homey BnB script SQL injection attempt (more info ...)web-application-attack    URL
50709SERVER-WEBAPP WordPress Rencontre plugin SQL injection attempt (more info ...)web-application-attack 2019-13413   
50710SERVER-WEBAPP WordPress Rencontre plugin SQL injection attempt (more info ...)web-application-attack 2019-13413   
50711SERVER-WEBAPP WordPress Rencontre plugin SQL injection attempt (more info ...)web-application-attack 2019-13413   
51046SERVER-OTHER PostgreSQL interval stack buffer overflow attempt (more info ...)attempted-user 2014-0063   URL
51071SERVER-WEBAPP revolutionProducts FlexBB flexbb_lang_id cookie parameter SQL injection attempt (more info ...)web-application-attack 2007-1729 23161  
51246SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51247SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51248SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51249SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51250SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51251SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51252SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51253SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51254SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51255SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51256SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
51257SERVER-WEBAPP OpenEMR SQL injection attempt (more info ...)web-application-attack 2018-9250   URL
52038SERVER-OTHER PostgreSQL SCRAM authentication stack buffer overflow attempt (more info ...)attempted-user 2019-10164   URL
56002SERVER-WEBAPP D-Link Central WiFi Manager CMW 100 SQL injection attempt (more info ...)web-application-attack 2019-13373   URL
59070SERVER-WEBAPP Trend Micro SafeSync for Enterprise SQL injection attempt (more info ...)web-application-attack    
59280SERVER-WEBAPP Medical Center Portal Management System SQL injection attempt (more info ...)web-application-attack    
59311SERVER-WEBAPP NagiosQL txtSearch cross site scripting attempt (more info ...)attempted-user 2013-6039   
59312SERVER-WEBAPP NagiosQL txtSearch cross site scripting attempt (more info ...)attempted-user 2013-6039   
59342SERVER-WEBAPP Multi Restaurant Table Reservation System 1.0 table_id unauthenticated SQL injection attempt (more info ...)web-application-attack 2020-29284   URL
59343SERVER-WEBAPP Multi Restaurant Table Reservation System 1.0 table_id unauthenticated SQL injection attempt (more info ...)web-application-attack 2020-29284   URL
59344SERVER-WEBAPP Multi Restaurant Table Reservation System 1.0 table_id unauthenticated SQL injection attempt (more info ...)web-application-attack 2020-29284   URL
59570SERVER-OTHER Trend Micro Control Manager TVCSCommander SQL injection attempt (more info ...)attempted-user 2017-11383   
59571SERVER-OTHER Trend Micro Control Manager mdHandlerLicenseManager SQL injection attempt (more info ...)attempted-user 2017-11384   
59572SERVER-OTHER Trend Micro Control Manager cmdHandlerStatusMonitor SQL injection attempt (more info ...)attempted-user 2017-11385   
59574SERVER-ORACLE Oracle Warehouse Builder WB_RT_AUDIT_SHADOW_TABLE SQL injection attempt (more info ...)attempted-user 2011-0799   
59608SERVER-WEBAPP Exponent CMS eaasController SQL injection attempt (more info ...)web-application-attack 2017-7991   URL
59626SERVER-OTHER PostgreSQL database SET ROLE security bypass attempt (more info ...)attempted-user 2014-0060   
59627SERVER-OTHER PostgreSQL database SET ROLE security bypass attempt (more info ...)attempted-user 2014-0060   
59636SERVER-OTHER PostgreSQL database geo_ops path_in integer overflow attempt (more info ...)attempted-user 2014-0064   
59680SERVER-WEBAPP Online Learning Management System SQL injection attempt (more info ...)web-application-attack    URL
59681SERVER-WEBAPP Online Learning Management System SQL injection attempt (more info ...)web-application-attack    URL
60484SERVER-WEBAPP Django trunc SQL injection attempt (more info ...)web-application-attack 2022-34265   
60485SERVER-WEBAPP Django extract SQL injection attempt (more info ...)web-application-attack 2022-34265   
60785SERVER-WEBAPP GLPI Project external token SQL injection attempt (more info ...)web-application-attack 2022-35947   
60787SERVER-WEBAPP GLPI Project external token SQL injection attempt (more info ...)web-application-attack 2022-35947   
60788SERVER-WEBAPP GLPI Project external token SQL injection attempt (more info ...)web-application-attack 2022-35947   
60848SERVER-WEBAPP Chimera Web Portal SQL injection attempt (more info ...)web-application-attack 2006-0137   
60849SERVER-WEBAPP Chimera Web Portal SQL injection attempt (more info ...)web-application-attack 2006-0137   
60850SERVER-WEBAPP Chimera Web Portal SQL injection attempt (more info ...)web-application-attack 2006-0137   

 goto Top

Group: Server / Database / Common SQL

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Misc

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Misc / DNS

# of attack rules in this group: 159

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
10603OS-WINDOWS DCERPC NCACN-IP-TCP dns R_DnssrvUpdateRecord2 overflow attempt (more info ...)attempted-admin  2007-1748  23470    URL
16029OS-WINDOWS Microsoft Windows DNS client ATMA buffer overrun attempt (more info ...)attempted-admin  2006-3441  19404    
16030OS-WINDOWS Microsoft Windows DNS client TXT buffer overrun attempt (more info ...)attempted-admin  2006-3441  19404    
19677OS-WINDOWS Microsoft Windows DNS NAPTR remote unauthenticated code execution vulnerability attempt (more info ...)attempted-admin  2011-1966      URL
23040PROTOCOL-DNS Multiple vendor DNS message decompression denial of service attempt (more info ...)attempted-dos  2007-1030  22606    URL
23950OS-WINDOWS Microsoft Windows DNS NAPTR remote unauthenticated code execution vulnerability attempt (more info ...)attempted-admin  2011-1966      URL
23951OS-WINDOWS Microsoft Windows DNS NAPTR remote unauthenticated code execution vulnerability attempt (more info ...)attempted-admin  2011-1966      URL
26286APP-DETECT Absolute Software Computrace outbound connection - search.dnssearch.org (more info ...)misc-activity        URL
26803MALWARE-OTHER DNS data exfiltration attempt (more info ...)policy-violation        URL
27984APP-DETECT DNS request for Dynamic Internet Technology domain dfgvx.com (more info ...)misc-activity        URL
27985APP-DETECT DNS request for Dynamic Internet Technology domain hjuyv.com (more info ...)misc-activity        URL
27986APP-DETECT DNS request for Dynamic Internet Technology domain rfvcd.com (more info ...)misc-activity        URL
27987APP-DETECT DNS request for Dynamic Internet Technology domain vfrtg.com (more info ...)misc-activity        URL
27988APP-DETECT DNS request for Dynamic Internet Technology domain dongtaiwang.com (more info ...)misc-activity        URL
27989APP-DETECT DNS request for Dynamic Internet Technology domain mjuyh.com (more info ...)misc-activity        URL
27990APP-DETECT DNS request for Dynamic Internet Technology domain umikl.com (more info ...)misc-activity        URL
27991APP-DETECT DNS request for Dynamic Internet Technology domain ziyouforever.com (more info ...)misc-activity        URL
27992APP-DETECT DNS response for Dynamic Internet Technology domain ziyouforever.com (more info ...)misc-activity        URL
27993APP-DETECT DNS request for Dynamic Internet Technology domain xcder.com (more info ...)misc-activity        URL
27994APP-DETECT DNS request for Dynamic Internet Technology domain dit-inc.us (more info ...)misc-activity        URL
27995APP-DETECT DNS request for Dynamic Internet Technology domain ewsxz.com (more info ...)misc-activity        URL
27996APP-DETECT DNS request for Dynamic Internet Technology domain nbgtr.com (more info ...)misc-activity        URL
27997APP-DETECT DNS request for Dynamic Internet Technology domain dongtaiwang.net (more info ...)misc-activity        URL
27998APP-DETECT DNS request for Dynamic Internet Technology domain washingtonchinareview.org (more info ...)misc-activity        URL
28039INDICATOR-COMPROMISE Suspicious .pw dns query (more info ...)misc-activity        
28284INDICATOR-COMPROMISE Suspicious .nl.ai dns query (more info ...)trojan-activity        
28556PROTOCOL-DNS DNS query amplification attempt (more info ...)attempted-dos        URL
28557PROTOCOL-DNS Malformed DNS query with HTTP content (more info ...)misc-activity        URL
30272MALWARE-OTHER Unix.Trojan.Onimiki redirected client DNS request (more info ...)trojan-activity        URL
30273MALWARE-OTHER Unix.Trojan.Onimiki DNS compromised server response (more info ...)trojan-activity        URL
31984OS-OTHER Cisco IOS mDNS malformed rrlength denial of service attempt (more info ...)attempted-dos  2014-3357      URL
35942PROTOCOL-DNS ISC BIND TKEY query processing denial of service attempt (more info ...)attempted-dos  2015-5477      URL
35943PROTOCOL-DNS ISC BIND TKEY query processing denial of service attempt (more info ...)attempted-dos  2015-5477      URL
37015PROTOCOL-DNS DNS DNAME query detected - possible attack attempt (more info ...)attempted-admin  2015-6125      URL
37730PROTOCOL-DNS glibc getaddrinfo A record stack buffer overflow attempt (more info ...)attempted-user  2015-7547      URL
37731PROTOCOL-DNS glibc getaddrinfo AAAA record stack buffer overflow attempt (more info ...)attempted-user  2015-7547      URL
39192SERVER-WEBAPP D-Link router unauthorised DNS change attempt (more info ...)attempted-admin        URL
39742SERVER-WEBAPP Dell SonicWall GMS set_dns XMLRPC method command injection attempt (more info ...)web-application-attack        URL
39926MALWARE-OTHER pisloader DNS drive command response attempt (more info ...)trojan-activity        URL
39927MALWARE-OTHER pisloader DNS list command response attempt (more info ...)trojan-activity        URL
39928MALWARE-OTHER pisloader DNS open command response attempt (more info ...)trojan-activity        URL
39929MALWARE-OTHER pisloader DNS sinfo command response attempt (more info ...)trojan-activity        URL
39946PROTOCOL-DNS PowerDNS TKEY query denial of service attempt (more info ...)attempted-dos  2015-5311  77522    URL
39947PROTOCOL-DNS PowerDNS TKEY query denial of service attempt (more info ...)attempted-dos  2015-5311  77522    URL
39948PROTOCOL-DNS PowerDNS TCP TKEY query denial of service attempt (more info ...)attempted-dos  2015-5311  77522    URL
39949PROTOCOL-DNS PowerDNS TCP TKEY query denial of service attempt (more info ...)attempted-dos  2015-5311  77522    URL
39950PROTOCOL-DNS PowerDNS TCP TSIG query denial of service attempt (more info ...)attempted-dos  2015-5311  77522    URL
39951PROTOCOL-DNS PowerDNS TCP TSIG query denial of service attempt (more info ...)attempted-dos  2015-5311  77522    URL
39952PROTOCOL-DNS PowerDNS TSIG query denial of service attempt (more info ...)attempted-dos  2015-5311  77522    URL
39953PROTOCOL-DNS PowerDNS TSIG query denial of service attempt (more info ...)attempted-dos  2015-5311  77522    URL
40257SERVER-WEBAPP Cisco Cloud Services Platform dnslookup command injection attempt (more info ...)attempted-admin  2016-6374      URL
40344PROTOCOL-DNS ISC BIND isc__buffer_add assertion failure denial of service attempt (more info ...)attempted-dos  2016-2776      URL
40579SERVER-OTHER ISC BIND 9 DNS query overly long name denial of service attempt (more info ...)attempted-dos  2016-2848      
42785INDICATOR-SCAN DNS version.bind string information disclosure attempt (more info ...)attempted-recon  2017-0171      URL
43308BROWSER-PLUGINS MagnetoSoft DNS ActiveX clsid access attempt (more info ...)attempted-user        URL
43309BROWSER-PLUGINS MagnetoSoft DNS ActiveX clsid access attempt (more info ...)attempted-user        URL
43316BROWSER-PLUGINS MagnetoSoft DNS ActiveX clsid access attempt (more info ...)attempted-user        URL
43317BROWSER-PLUGINS MagnetoSoft DNS ActiveX clsid access attempt (more info ...)attempted-user        URL
43687INDICATOR-COMPROMISE Suspicious .top dns query (more info ...)misc-activity        URL
44037INDICATOR-COMPROMISE DNS request for known malware sinkhole domain iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com - WannaCry (more info ...)trojan-activity        URL
44076INDICATOR-COMPROMISE Suspicious .trade dns query (more info ...)misc-activity        
44477SERVER-OTHER dnsmasq dhcp6_maybe_relay stack buffer overflow attempt (more info ...)attempted-admin  2017-14493      URL
44478PROTOCOL-DNS dnsmasq add_pseudoheader memory leak attempt (more info ...)attempted-dos  2017-14495      URL
44480SERVER-OTHER dnsmasq Relay-forw information leak attempt (more info ...)attempted-recon  2017-14494      
46400SERVER-WEBAPP D-Link DNS-343 Mail_Test command injection attempt (more info ...)web-application-attack        URL
46401SERVER-WEBAPP D-Link DNS-343 Mail_Test command injection attempt (more info ...)web-application-attack        URL
46402SERVER-WEBAPP D-Link DNS-343 Mail_Test command injection attempt (more info ...)web-application-attack        URL
47809PROTOCOL-DNS TRUFFLEHUNTER TALOS-2018-0672 attack attempt (more info ...)attempted-user  2018-4003      URL
47811PROTOCOL-DNS TRUFFLEHUNTER TALOS-2018-0671 attack attempt (more info ...)attempted-dos  2020-6072      URL
47842PROTOCOL-DNS TRUFFLEHUNTER TALOS-2018-0681 attack attempt (more info ...)attempted-admin  2018-4011      URL
47881PROTOCOL-DNS dnsmasq add_pseudoheader memory leak attempt (more info ...)attempted-dos  2017-14495      URL
48353SERVER-WEBAPP Quest DR Series Disk Backup DnsService.pm command injection attempt (more info ...)web-application-attack  2018-11183      URL
48647INDICATOR-COMPROMISE suspicious .bbs tcp dns query (more info ...)misc-activity        
48648INDICATOR-COMPROMISE suspicious .bbs dns query (more info ...)misc-activity        
48649INDICATOR-COMPROMISE suspicious .chan tcp dns query (more info ...)misc-activity        
48650INDICATOR-COMPROMISE suspicious .chan dns query (more info ...)misc-activity        
48651INDICATOR-COMPROMISE suspicious .cyb tcp dns query (more info ...)misc-activity        
48652INDICATOR-COMPROMISE suspicious .cyb dns query (more info ...)misc-activity        
48653INDICATOR-COMPROMISE suspicious .dyn tcp dns query (more info ...)misc-activity        
48654INDICATOR-COMPROMISE suspicious .dyn dns query (more info ...)misc-activity        
48655INDICATOR-COMPROMISE suspicious .geek tcp dns query (more info ...)misc-activity        
48656INDICATOR-COMPROMISE suspicious .geek dns query (more info ...)misc-activity        
48657INDICATOR-COMPROMISE suspicious .gopher tcp dns query (more info ...)misc-activity        
48658INDICATOR-COMPROMISE suspicious .gopher dns query (more info ...)misc-activity        
48659INDICATOR-COMPROMISE suspicious .indy tcp dns query (more info ...)misc-activity        
48660INDICATOR-COMPROMISE suspicious .indy dns query (more info ...)misc-activity        
48661INDICATOR-COMPROMISE suspicious .libre tcp dns query (more info ...)misc-activity        
48662INDICATOR-COMPROMISE suspicious .libre dns query (more info ...)misc-activity        
48663INDICATOR-COMPROMISE suspicious .neo tcp dns query (more info ...)misc-activity        
48664INDICATOR-COMPROMISE suspicious .neo dns query (more info ...)misc-activity        
48665INDICATOR-COMPROMISE suspicious .null tcp dns query (more info ...)misc-activity        
48667INDICATOR-COMPROMISE suspicious .o tcp dns A query (more info ...)misc-activity        
48668INDICATOR-COMPROMISE suspicious .o dns A query (more info ...)misc-activity        
48669INDICATOR-COMPROMISE suspicious .oss tcp dns query (more info ...)misc-activity        
48670INDICATOR-COMPROMISE suspicious .oss dns query (more info ...)misc-activity        
48671INDICATOR-COMPROMISE suspicious .oz tcp dns A query (more info ...)misc-activity        
48672INDICATOR-COMPROMISE suspicious .oz dns A query (more info ...)misc-activity        
48673INDICATOR-COMPROMISE suspicious .parody tcp dns query (more info ...)misc-activity        
48674INDICATOR-COMPROMISE suspicious .parody dns query (more info ...)misc-activity        
48675INDICATOR-COMPROMISE suspicious .pirate tcp dns query (more info ...)misc-activity        
48676INDICATOR-COMPROMISE suspicious .pirate dns query (more info ...)misc-activity        
48677INDICATOR-COMPROMISE suspicious .free tcp dns query (more info ...)misc-activity        
48678INDICATOR-COMPROMISE suspicious .free dns query (more info ...)misc-activity        
48679INDICATOR-COMPROMISE suspicious .bazar tcp dns query (more info ...)misc-activity        
48680INDICATOR-COMPROMISE suspicious .bazar dns query (more info ...)misc-activity        
48681INDICATOR-COMPROMISE suspicious .coin tcp dns query (more info ...)misc-activity        
48682INDICATOR-COMPROMISE suspicious .coin dns query (more info ...)misc-activity        
48683INDICATOR-COMPROMISE suspicious .emc tcp dns query (more info ...)misc-activity        
48684INDICATOR-COMPROMISE suspicious .emc dns query (more info ...)misc-activity        
48685INDICATOR-COMPROMISE suspicious .lib tcp dns query (more info ...)misc-activity        
48686INDICATOR-COMPROMISE suspicious .lib dns query (more info ...)misc-activity        
48687INDICATOR-COMPROMISE suspicious .fur tcp dns query (more info ...)misc-activity        
48688INDICATOR-COMPROMISE suspicious .fur dns query (more info ...)misc-activity        
48713INDICATOR-COMPROMISE suspicious .glue dns query (more info ...)misc-activity        
48714INDICATOR-COMPROMISE suspicious .glue tcp dns query (more info ...)misc-activity        
48829INDICATOR-COMPROMISE suspicious .o tcp dns AAAA query (more info ...)misc-activity        
48830INDICATOR-COMPROMISE suspicious .o tcp dns TXT query (more info ...)misc-activity        
48831INDICATOR-COMPROMISE suspicious .o dns AAAA query (more info ...)misc-activity        
48832INDICATOR-COMPROMISE suspicious .o dns TXT query (more info ...)misc-activity        
48833INDICATOR-COMPROMISE suspicious .oz tcp dns AAAA query (more info ...)misc-activity        
48834INDICATOR-COMPROMISE suspicious .oz tcp dns TXT query (more info ...)misc-activity        
48835INDICATOR-COMPROMISE suspicious .oz dns AAAA query (more info ...)misc-activity        
48836INDICATOR-COMPROMISE suspicious .oz dns TXT query (more info ...)misc-activity        
50348MALWARE-OTHER Win.Trojan.DNSpionage variant download attempt (more info ...)attempted-user        URL
50349MALWARE-OTHER Win.Trojan.DNSpionage variant download attempt (more info ...)attempted-user        URL
50350MALWARE-OTHER Win.Trojan.DNSpionage variant download attempt (more info ...)attempted-user        URL
50353MALWARE-OTHER Win.Trojan.DNSpionage variant download attempt (more info ...)attempted-user        URL
50616MALWARE-OTHER Html.Phishing.Necurs DNS compromise attempt (more info ...)trojan-activity        URL
50617MALWARE-OTHER Html.Phishing.Necurs DNS compromise attempt (more info ...)trojan-activity        URL
50618MALWARE-OTHER Html.Phishing.Necurs DNS compromise attempt (more info ...)trojan-activity        URL
51534MALWARE-BACKDOOR DNS request for open LocalXpose reverse proxy backdoor domain ANY.loclx.io (more info ...)trojan-activity        URL
51712INDICATOR-COMPROMISE Win.Trojan.NanoCore DNS request for known malware domain bsbs.duckdns.org (more info ...)trojan-activity        URL
52242SERVER-WEBAPP D-Link DNS-320 ShareCenter command injection attempt (more info ...)web-application-attack  2019-16057      URL
52243SERVER-WEBAPP D-Link DNS-320 ShareCenter command injection attempt (more info ...)web-application-attack  2019-16057      URL
53867PROTOCOL-DNS Cisco ASA and FTD IPv6 DNS request stack buffer overflow attempt (more info ...)attempted-admin  2020-3191      URL
53972MALWARE-OTHER Cobalt Strike beacon.dll DNS download attempt (more info ...)trojan-activity        URL
53975INDICATOR-COMPROMISE Cobalt Strike multiple large DNS TXT query responses (more info ...)trojan-activity        URL
53985INDICATOR-COMPROMISE msiexec.exe command execution over DNS attempt (more info ...)trojan-activity        URL
54518SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt (more info ...)attempted-user  2021-26897      URL
54575SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt (more info ...)attempted-user  2020-1350      URL
54576SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt (more info ...)attempted-user  2020-1350      URL
54577SERVER-OTHER Microsoft Windows DNS server remote integer overflow attempt (more info ...)attempted-user  2020-1350      URL
54735OS-WINDOWS Microsoft Windows DNS Resolver local privilege escalation attempt (more info ...)attempted-admin  2020-1584      URL
54736OS-WINDOWS Microsoft Windows DNS Resolver local privilege escalation attempt (more info ...)attempted-admin  2020-1584      URL
54827MALWARE-TOOLS dnscat dns tunneling detected (more info ...)trojan-activity        URL
55206SERVER-OTHER Active Directory LDAP addRequest crafted dnsRecord information leak attempt (more info ...)attempted-user  2020-0856      URL
55822PROTOCOL-DNS Cisco IOS XE Umbrella Connector denial of service attempt (more info ...)attempted-dos  2020-3510      URL
55993PROTOCOL-ICMP Microsoft Windows IPv6 DNSSL option record denial of service attempt (more info ...)attempted-dos  2020-16899      URL
56569MALWARE-TOOLS Win.Trojan.MemscraperDNS variant download attempt (more info ...)trojan-activity        URL
57123SERVER-OTHER Microsoft Windows DNS server remote code execution attempt (more info ...)attempted-user  2021-24078      URL
57274OS-WINDOWS Microsoft Windows DNS Server out of bounds read attempt (more info ...)attempted-user  2021-26877      URL
57329SERVER-WEBAPP D-Link DNS-320 Firewall command injection attempt (more info ...)web-application-attack  2020-25506      URL
57330SERVER-WEBAPP D-Link DNS-320 Firewall command injection attempt (more info ...)web-application-attack  2020-25506      URL
57331SERVER-WEBAPP D-Link DNS-320 Firewall command injection attempt (more info ...)web-application-attack  2020-25506      URL
57350SERVER-OTHER invalid multicast DNS name length response attempt (more info ...)attempted-user  2021-1439      URL
59564PROTOCOL-DNS Cisco IOS XE mDNS denial of service attempt (more info ...)attempted-dos  2022-20682      URL
59565PROTOCOL-DNS Cisco IOS XE mDNS denial of service attempt (more info ...)attempted-dos  2022-20682      URL
59955MALWARE-OTHER Unix.Backdoor.Dnscat2 variant binary download attempt (more info ...)trojan-activity        URL
59956MALWARE-OTHER Unix.Backdoor.Dnscat2 variant binary download attempt (more info ...)trojan-activity        URL


# of warning rules in this group: 218

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1261SERVER-OTHER AIX pdnsd overflow (more info ...)attempted-user 1999-0745 590  
1739SERVER-WEBAPP DNSTools administrator authentication bypass attempt (more info ...)web-application-attack 2002-0613 4617  
1740SERVER-WEBAPP DNSTools authentication bypass attempt (more info ...)web-application-attack 2002-0613 4617  
1741SERVER-WEBAPP DNSTools access (more info ...)web-application-activity 2002-0613 4617  
3154PROTOCOL-DNS UDP inverse query overflow (more info ...)attempted-admin 1999-0009 134  
12357SERVER-OTHER Apple mDNSresponder excessive HTTP headers (more info ...)attempted-admin 2007-3744 25159  
13900APP-DETECT Apple iTunes server multicast DNS response (more info ...)misc-activity    URL
15327PROTOCOL-DNS libspf2 DNS TXT record parsing buffer overflow attempt (more info ...)attempted-user 2008-2469 31881  
15734PROTOCOL-DNS BIND named 9 dynamic update message remote dos attempt (more info ...)attempted-dos 2009-0696   URL
15963OS-LINUX Red Hat Enterprise Linux DNS resolver buffer overflow attempt (more info ...)attempted-admin 2002-0029 6186  
15988OS-WINDOWS Microsoft ISA Server DNS spoofing attempt (more info ...)misc-attack 2004-0892 11605  
16206OS-WINDOWS Microsoft Windows DNS server spoofing attempt (more info ...)misc-attack 2008-1447 25919  URL
16443POLICY-SOCIAL deny Gmail chat DNS request (more info ...)policy-violation    
16612BROWSER-FIREFOX Mozilla Firefox oversized SOCKS5 DNS reply memory corruption attempt (more info ...)attempted-user 2009-2470 35925  
16693MALWARE-CNC Torpig bot sinkhole server DNS lookup (more info ...)trojan-activity    URL
17294OS-WINDOWS Microsoft Windows NAT Helper DNS query denial of service attempt (more info ...)attempted-dos 2006-5614 20804  
17483PROTOCOL-DNS squid proxy dns A record response denial of service attempt (more info ...)attempted-dos 2005-0446 12551  
17484PROTOCOL-DNS squid proxy dns PTR record response denial of service attempt (more info ...)attempted-dos 2005-0446 12551  
17485PROTOCOL-DNS Symantec Gateway products DNS cache poisoning attempt (more info ...)misc-attack 2005-0817   
17495SERVER-OTHER Squid proxy DNS response spoofing attempt (more info ...)attempted-dos 2005-1519 13592  
17680SERVER-OTHER ISC BIND DNSSEC Validation Multiple RRsets DoS (more info ...)attempted-dos 2007-0494 22231  
17696PROTOCOL-DNS Microsoft Windows DNS Server ANY query cache weakness (more info ...)misc-activity 2009-0234   URL
19125PROTOCOL-DNS ISC BIND DNSSEC authority response record overflow attempt (more info ...)denial-of-service 2011-1910   
19187PROTOCOL-DNS TMG Firewall Client long host entry exploit attempt (more info ...)attempted-user 2011-1889   URL
19471POLICY-OTHER dnstunnel v0.5 outbound traffic detected (more info ...)policy-violation    URL
20095INDICATOR-COMPROMISE IRC dns request on non-standard port (more info ...)trojan-activity    
21354PROTOCOL-DNS dns query - storing query and txid (more info ...)misc-activity 2010-1690   URL
21421PROTOCOL-DNS ISC BIND DNSSEC authority response record overflow attempt (more info ...)denial-of-service 2011-1910   
21544MALWARE-CNC Possible host infection - excessive DNS queries for .eu (more info ...)trojan-activity    
21545MALWARE-CNC Possible host infection - excessive DNS queries for .ru (more info ...)trojan-activity    
21546MALWARE-CNC Possible host infection - excessive DNS queries for .cn (more info ...)trojan-activity    
21817PROTOCOL-DNS excessive queries of type ANY - potential DoS (more info ...)attempted-dos    URL
23368PROTOCOL-DNS Tftpd32 DNS server denial of service attempt (more info ...)denial-of-service    
23608PROTOCOL-DNS dns zone transfer with zero-length rdata attempt (more info ...)attempted-dos 2012-1667   URL
24304PROTOCOL-DNS dead alive6 DNS attempt (more info ...)misc-activity    URL
25080APP-DETECT Apple Messages push.apple.com DNS TXT request attempt (more info ...)policy-violation    URL
25081APP-DETECT Apple Messages courier.push.apple.com DNS TXT request attempt (more info ...)policy-violation    URL
25333PROTOCOL-DNS Exim DKIM decoding buffer overflow attempt (more info ...)attempted-admin 2012-5671   
25983INDICATOR-OBFUSCATION DNS tunneling attempt (more info ...)policy-violation    URL
26266MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected (more info ...)trojan-activity    
26267MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected (more info ...)trojan-activity    
26268MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected (more info ...)trojan-activity    
26269MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected (more info ...)trojan-activity    
26270MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected (more info ...)trojan-activity    
26271MALWARE-CNC Win.Trojan.Zeus v3 DGA DNS query detected (more info ...)trojan-activity    
26324PROTOCOL-DNS ISC BIND NAPTR record regular expression handling denial of service attempt (more info ...)attempted-dos 2013-2266   URL
26353INDICATOR-COMPROMISE IP address check to dyndns.org detected (more info ...)misc-activity    
26397INDICATOR-COMPROMISE IP address check to myip.dnsomatic.com detected (more info ...)misc-activity    
26427PROTOCOL-DNS ISC libdns client NAPTR record regular expression handling denial of service attempt (more info ...)attempted-dos 2013-2266   URL
26740MALWARE-CNC Win.Trojan.BlackRev cnc dns command (more info ...)trojan-activity    URL
27046APP-DETECT iodine dns tunneling handshake server ACK (more info ...)policy-violation    URL
27536APP-DETECT TCP over DNS response attempt (more info ...)policy-violation    URL
27540APP-DETECT OzymanDNS dns tunneling up attempt (more info ...)policy-violation    URL
27541APP-DETECT OzymanDNS dns tunneling down attempt (more info ...)policy-violation    URL
27666SERVER-OTHER ISC BIND 9 DNS rdata length handling remote denial of service attempt (more info ...)denial-of-service 2013-4854 61479  URL
27700APP-DETECT NSTX DNS tunnel outbound connection attempt (more info ...)policy-violation    
27721INDICATOR-COMPROMISE Suspicious .su dns query (more info ...)trojan-activity    
27737MALWARE-CNC DNS suspicious .c0m.li dns query (more info ...)trojan-activity    
27930APP-DETECT DNS request for Splashtop domain splashtop.com (more info ...)misc-activity    URL
27931APP-DETECT DNS request for Splashtop domain splashtop.net (more info ...)misc-activity    URL
27932APP-DETECT DNS request for Splashtop domain devicevm.com (more info ...)misc-activity    URL
27938PROTOCOL-DNS IPv6 host name enumeration (more info ...)attempted-recon    URL
28070APP-DETECT DNS request for potential malware SafeGuard to domain 360safe.com (more info ...)trojan-activity    URL
28190INDICATOR-COMPROMISE Suspicious .cc dns query (more info ...)trojan-activity    
29381APP-DETECT VPN Over DNS outbound traffic attempt (more info ...)policy-violation    URL
29382APP-DETECT VPN Over DNS application download attempt (more info ...)policy-violation    URL
29383APP-DETECT VPN Over DNS application download attempt (more info ...)policy-violation    URL
29935PROTOCOL-DNS ISC libdns client NAPTR record regular expression handling denial of service attempt (more info ...)attempted-dos 2013-2266   URL
30853APP-DETECT DNS request for known bitcoin domain bitseed.xf2.org (more info ...)policy-violation    
30854APP-DETECT DNS request for known bitcoin domain dnsseed.btcltcftc.com (more info ...)policy-violation    
30855APP-DETECT DNS request for known bitcoin domain dnsseed.fc.altcointech.net (more info ...)policy-violation    
30856APP-DETECT DNS request for known bitcoin domain dnsseed.feathercoin.com (more info ...)policy-violation    
30857APP-DETECT DNS request for known bitcoin domain dnsseed.koin-project.com (more info ...)policy-violation    
30858APP-DETECT DNS request for known bitcoin domain dnsseed.litecoinpool.org (more info ...)policy-violation    
30859APP-DETECT DNS request for known bitcoin domain dnsseed.litecointools.com (more info ...)policy-violation    
30860APP-DETECT DNS request for known bitcoin domain dnsseed.ltc.xurious.com (more info ...)policy-violation    
30861APP-DETECT DNS request for known bitcoin domain dnsseed.ppc.altcointech.net (more info ...)policy-violation    
30862APP-DETECT DNS request for known bitcoin domain dnsseed.xpm.altcointech.net (more info ...)policy-violation    
30863APP-DETECT DNS request for known bitcoin domain dvcstable01.dvcnode.org (more info ...)policy-violation    
30864APP-DETECT DNS request for known bitcoin domain dvcstable02.dvcnode.org (more info ...)policy-violation    
30865APP-DETECT DNS request for known bitcoin domain seed.bitcoinstats.com (more info ...)policy-violation    
30866APP-DETECT DNS request for known bitcoin domain seed.dglibrary.org (more info ...)policy-violation    
30867APP-DETECT DNS request for known bitcoin domain seed.dogechain.info (more info ...)policy-violation    
30868APP-DETECT DNS request for known bitcoin domain seed.dogecoin.com (more info ...)policy-violation    
30869APP-DETECT DNS request for known bitcoin domain seed.mophides.com (more info ...)policy-violation    
30870APP-DETECT DNS request for known bitcoin domain seed.ppcoin.net (more info ...)policy-violation    
30871APP-DETECT DNS request for known bitcoin domain seed1.metiscoininvest.info (more info ...)policy-violation    
30872APP-DETECT DNS request for known bitcoin domain seed1.net.terracoin.org (more info ...)policy-violation    
30873APP-DETECT DNS request for known bitcoin domain seed1.qrkcoin.org (more info ...)policy-violation    
30874APP-DETECT DNS request for known bitcoin domain seed2.net.terracoin.org (more info ...)policy-violation    
30875APP-DETECT DNS request for known bitcoin domain tnseed.ppcoin.net (more info ...)policy-violation    
31982SERVER-OTHER Cisco IOS mdns memory leak (more info ...)attempted-dos 2014-3358   URL
32312MALWARE-CNC FrameworkPOS data exfiltration through DNS - beacon message (more info ...)trojan-activity    URL
32865APP-DETECT I2P DNS request attempt (more info ...)trojan-activity    URL
33522MALWARE-CNC User-Agent known malicious user-agent - DNS Changer (more info ...)trojan-activity    URL
33523MALWARE-CNC Win.Trojan.DNSChanger variant outbound connection (more info ...)trojan-activity    URL
33524MALWARE-CNC Win.Trojan.DNSChanger variant outbound connection (more info ...)trojan-activity    URL
33928SERVER-OTHER Cisco IOS mDNS denial of service attempt (more info ...)attempted-dos 2014-3357 70132  URL
33929SERVER-OTHER Cisco IOS mDNS denial of service attempt (more info ...)attempted-dos 2014-3357 70132  URL
34051PROTOCOL-DNS Cisco ASA memory exhaustion denial of service attempt (more info ...)attempted-dos 2015-0676   URL
34496APP-DETECT Your-Freedom DNS tunneling query attempt (more info ...)misc-activity    URL
34497APP-DETECT Your-Freedom DNS tunneling query response attempt (more info ...)misc-activity    URL
36055PROTOCOL-DNS ISC BIND DNSSEC response unsupported DNSKEY cryptographic algorithm attempt (more info ...)attempted-dos 2015-5722   URL
36130PROTOCOL-DNS ISC BIND zero length OPENPGPKEY rdata response attempt (more info ...)attempted-dos 2015-5986   URL
36379POLICY-OTHER dnstunnel v0.5 outbound traffic detected (more info ...)policy-violation    URL
37062APP-DETECT 12P DNS request attempt (more info ...)misc-activity    URL
37343SERVER-WEBAPP D-Link DNS-326 check_login command injection attempt (more info ...)web-application-attack    URL
37891INDICATOR-OBFUSCATION DNS tunneling attempt (more info ...)policy-violation    URL
37892INDICATOR-OBFUSCATION DNS tunneling attempt (more info ...)policy-violation    URL
38281PROTOCOL-DNS ISC BIND totext_in_apl denial of service attempt (more info ...)attempted-dos 2015-8704 81329  URL
38282PROTOCOL-DNS ISC BIND totext_in_apl denial of service attempt (more info ...)attempted-dos 2015-8704 81329  URL
38283PROTOCOL-DNS ISC BIND totext_in_apl denial of service attempt (more info ...)attempted-dos 2015-8704 81329  URL
38284PROTOCOL-DNS ISC BIND totext_in_apl denial of service attempt (more info ...)attempted-dos 2015-8704 81329  URL
38457POLICY-OTHER Suspicious typo squatting DNS query to .om TLD attempt (more info ...)policy-violation    URL
38590SERVER-OTHER Cisco Wireless LAN Controller mDNS denial of service attempt (more info ...)attempted-dos    URL
39866INDICATOR-COMPROMISE Suspicious .ml dns query (more info ...)misc-activity    URL
39867INDICATOR-COMPROMISE Suspicious .tk dns query (more info ...)misc-activity    URL
40362PROTOCOL-DNS ISC BIND DNS duplicate cookie denial of service attempt (more info ...)attempted-dos 2016-2088   URL
40610INDICATOR-COMPROMISE DNS response points to sinkholed domain (more info ...)trojan-activity    URL
41083MALWARE-CNC DNS suspicious .bit dns query (more info ...)trojan-activity    
41755INDICATOR-COMPROMISE d-link sharecenter dns-320 denial of service attempt (more info ...)web-application-attack    URL
41756INDICATOR-COMPROMISE d-link sharecenter dns-320 denial of service attempt (more info ...)web-application-attack    URL
41757INDICATOR-COMPROMISE d-link sharecenter dns-320 denial of service attempt (more info ...)web-application-attack    URL
41758INDICATOR-COMPROMISE d-link sharecenter dns-320 denial of service attempt (more info ...)web-application-attack    URL
41787MALWARE-CNC Win.Trojan.PowerMacro TCP DNS query response (more info ...)trojan-activity    URL
41788MALWARE-CNC Win.Trojan.PowerMacro DNS query response (more info ...)trojan-activity    URL
41789MALWARE-CNC Win.Trojan.PowerMacro DNS query response (more info ...)trojan-activity    URL
41852PROTOCOL-DNS PowerDNS name compression pointer loop denial of service attempt (more info ...)attempted-dos 2015-1868 74306  URL
41903PROTOCOL-DNS PowerDNS name compression pointer loop denial of service attempt (more info ...)attempted-dos 2015-1868 74306  URL
41904PROTOCOL-DNS PowerDNS name compression pointer loop denial of service attempt (more info ...)attempted-dos 2015-1868 74306  URL
41905PROTOCOL-DNS PowerDNS name compression pointer loop denial of service attempt (more info ...)attempted-dos 2015-1868 74306  URL
42458PROTOCOL-DNS ISC BIND unexpected DNAME CNAME ordering denial of service attempt (more info ...)attempted-dos 2017-3137   URL
42841MALWARE-CNC DNS suspicious .bit tcp dns query (more info ...)trojan-activity    
42966SERVER-WEBAPP Java URLDNS Library unauthorized serialized object attempt (more info ...)attempted-admin    URL
43053SERVER-SAMBA Samba LDAP modify dnsRecord buffer overflow attempt (more info ...)attempted-user 2016-2123   
44077INDICATOR-COMPROMISE Suspicious .win dns query (more info ...)misc-activity    
44320SERVER-OTHER Symantec Firewalls DNS response denial of service attempt (more info ...)denial-of-service 2004-0445   
44379PROTOCOL-DNS Cisco IOS ipnat_dns_shift_data integer underflow attempt (more info ...)attempted-dos 2014-2111 66470  URL
44418SERVER-OTHER Tipping Point IPS reverse DNS lookup format string exploit attempt (more info ...)denial-of-service    URL
44479PROTOCOL-DNS dnsmasq overly large DNS query denial of service attempt (more info ...)attempted-dos 2017-13704   URL
44481SERVER-OTHER dnsmasq IPv6 heap overflow attempt (more info ...)attempted-admin 2017-14492   
44595MALWARE-CNC Win.Trojan.DNSMessenger outbound connection (more info ...)trojan-activity    URL
44628OS-WINDOWS Attempted DNSSEC NSEC3 buffer overflow attempt (more info ...)attempted-user 2017-11779   URL
44629OS-WINDOWS Attempted DNSSEC NSEC3 buffer overflow attempt (more info ...)attempted-user 2017-11779   URL
44630OS-WINDOWS Attempted DNSSEC NSEC3 buffer overflow attempt (more info ...)attempted-user 2017-11779   URL
44797MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44798MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44799MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44800MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44801MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44802MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44803MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44804MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44805MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44806MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44807MALWARE-CNC Win.Trojan.Shadowpad DNS TXT encrypted outbound connection (more info ...)trojan-activity    URL
44879SERVER-OTHER ISC BIND 9 DNS rdata length handling remote denial of service attempt (more info ...)denial-of-service 2013-4854 61479  URL
45325SERVER-WEBAPP Dahua DVR DDNS configuration download attempt (more info ...)attempted-recon 2013-6117 63742  
45906MALWARE-CNC CobaltStrike DNS Beacon outbound A record (more info ...)trojan-activity    URL
45907MALWARE-CNC Cobalt Strike DNS beacon outbound TXT record (more info ...)trojan-activity    URL
45908MALWARE-CNC Cobalt Strike DNS beacon inbound TXT record (more info ...)trojan-activity    URL
46409OS-WINDOWS Attempted DNS overflow (more info ...)denial-of-service 2017-11779   URL
46613OS-LINUX Linux systemd DNS resolver denial of service attempt (more info ...)denial-of-service 2017-15908   
46614OS-LINUX Linux systemd DNS resolver denial of service attempt (more info ...)denial-of-service 2017-15908   
46615OS-LINUX Linux systemd DNS resolver denial of service attempt (more info ...)denial-of-service 2017-15908   
46616OS-LINUX Linux systemd DNS resolver denial of service attempt (more info ...)denial-of-service 2017-15908   
46617OS-LINUX Linux systemd DNS resolver denial of service attempt (more info ...)denial-of-service 2017-15908   
46618OS-LINUX Linux systemd DNS resolver denial of service attempt (more info ...)denial-of-service 2017-15908   
46619OS-LINUX Linux systemd DNS resolver denial of service attempt (more info ...)denial-of-service 2017-15908   
46848INDICATOR-COMPROMISE Possible Samba internal DNS forged response (more info ...)denial-of-service 2014-0239   
46935OS-WINDOWS Microsoft Windows DNSAPI remote code execution attempt (more info ...)attempted-admin 2018-8225   URL
47639INDICATOR-OBFUSCATION DNS TXT response record tunneling (more info ...)misc-activity    URL
47640SERVER-WEBAPP SSL certificate with null issuer rdnSequence fields detected (more info ...)misc-activity    
48444MALWARE-CNC Win.Malware.DNSpionage variant outbound connection (more info ...)trojan-activity    URL
48445MALWARE-CNC Win.Malware.DNSpionage variant outbound connection (more info ...)trojan-activity    URL
48666INDICATOR-COMPROMISE suspicious .null dns query (more info ...)misc-activity    
49411MALWARE-CNC Win.Trojan.FrameworkPoS anti-debugging long dns query attempt (more info ...)trojan-activity    
50761MALWARE-CNC Win.Trojan.Helminth outbound DNS tunnel (more info ...)trojan-activity    URL
50762MALWARE-CNC Win.Trojan.Helminth outbound DNS tunnel (more info ...)trojan-activity    URL
50763MALWARE-CNC Win.Trojan.Helminth outbound DNS tunnel (more info ...)trojan-activity    URL
50764MALWARE-CNC Win.Trojan.Helminth outbound DNS tunnel (more info ...)trojan-activity    URL
50765MALWARE-CNC Win.Trojan.ISMAgent outbound DNS tunnel (more info ...)trojan-activity    URL
50766MALWARE-CNC Win.Trojan.ALMA_Dash outbound DNS tunnel (more info ...)trojan-activity    URL
50767MALWARE-CNC Win.Trojan.ALMA_Dot outbound DNS tunnel (more info ...)trojan-activity    URL
50768MALWARE-CNC Win.Trojan.BONDUPDATER outbound DNS tunnel (more info ...)trojan-activity    URL
50769MALWARE-CNC Win.Trojan.QUADAGENT outbound DNS tunnel (more info ...)trojan-activity    URL
51000PROTOCOL-DNS PowerDNS Recursor query denial of service attempt (more info ...)attempted-dos 2018-16855   URL
51126SERVER-OTHER ISC Bind libdns EDNS option handling denial of service attempt (more info ...)denial-of-service 2014-3859   
51485SERVER-OTHER Squid proxy DNS CNAME record response denial of service attempt (more info ...)denial-of-service 2011-4096   URL
52338SERVER-OTHER ISC BIND DNS root DNAME query response denial of service attempt (more info ...)denial-of-service    URL
52524PROTOCOL-DNS dnsmasq crafted OPT record denial of service attempt (more info ...)attempted-dos 2017-13704   URL
53046PROTOCOL-DNS TRUFFLEHUNTER TALOS-2020-1001 attack attempt (more info ...)attempted-dos 2020-6078   URL
53593MALWARE-OTHER Unix.Tool.Dnsamp-7647492-0 download attempt (more info ...)trojan-activity    URL
53594MALWARE-OTHER Unix.Tool.Dnsamp-7647492-0 download attempt (more info ...)trojan-activity    URL
55832SERVER-OTHER Cisco IOS XE mDNS denial of service attempt (more info ...)attempted-dos 2020-3359   URL
56592MALWARE-CNC Cobalt Strike DNS beacon inbound TXT record (more info ...)trojan-activity    URL
56593MALWARE-CNC Cobalt Strike DNS beacon inbound TXT record (more info ...)trojan-activity    URL
57381PROTOCOL-DNS Dnsmasq extract_name buffer overflow attempt (more info ...)attempted-user 2020-25687   URL
57383PROTOCOL-DNS dnsmasq sort_rrset buffer overflow attempt (more info ...)attempted-user 2020-25681   URL
57460SERVER-OTHER dnsmasq PX record response heap overflow attempt (more info ...)attempted-user 2020-25683   URL
57579PROTOCOL-DNS ISC BIND OPT record text format handling denial of service attempt (more info ...)attempted-dos 2015-8705   URL
57744SERVER-OTHER TippingPoint web interface reverse DNS lookup cross site scripting attempt (more info ...)attempted-user    
57878PROTOCOL-DNS Microsoft Threat Management Gateway heap buffer overflow attempt (more info ...)attempted-user 2011-1889 48181  URL
57953PROTOCOL-DNS ISC BIND RRSIG response processing denial of service attempt (more info ...)attempted-dos 2016-1286   URL
59104PROTOCOL-DNS Dnsmasq PX extract_name buffer overflow attempt (more info ...)attempted-user 2020-25682   URL
59579PROTOCOL-DNS Microsoft DNS server denial of service attempt (more info ...)attempted-dos 2012-0006   URL
59600PROTOCOL-DNS Systemd resolved dns_packet_new buffer overflow attempt (more info ...)attempted-user 2017-9445   URL
59639SERVER-OTHER Samba AD DC dns denial of service attempt (more info ...)attempted-dos 2018-1140   
59707PROTOCOL-DNS GNU C library glibc getanswer_r DNS buffer overflow attempt (more info ...)attempted-dos 2015-1781   
59708PROTOCOL-DNS ISC BIND query response missing RRSIG denial of service attempt (more info ...)attempted-dos 2016-9444   
59709PROTOCOL-DNS ISC BIND RRSIG response without relevant RR denial of service attempt (more info ...)attempted-dos 2016-9147   
59725PROTOCOL-DNS BIND DNS64 and RPZ query processing denial of service attempt (more info ...)attempted-dos 2017-3135   
59746PROTOCOL-DNS ISC BIND TKEY response denial of service attempt (more info ...)attempted-dos 2016-9131   
59800SERVER-OTHER Bind9 server response self-signed certificate denial of service attempt (more info ...)attempted-dos 2015-4620   URL
59974MALWARE-CNC Unix.Backdoor.Dnscat2 variant DNS tunneling outbound communication (more info ...)trojan-activity    URL
60601SERVER-OTHER Nginx resolver DNS Response out of bounds write (more info ...)attempted-user 2021-23017   
60881SERVER-WEBAPP D-Link DSL-2760U Web-UI Dynamic DNS cross site scripting attempt (more info ...)attempted-user 2013-5223   URL
60882SERVER-WEBAPP D-Link DSL-2760U Web-UI Dynamic DNS cross site scripting attempt (more info ...)attempted-user 2013-5223   URL

 goto Top

Group: Server / Misc / FTP

# of attack rules in this group: 36

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3818PROTOCOL-TFTP PUT transfer mode overflow attempt (more info ...)attempted-admin  2006-6183  21301    
9621PROTOCOL-TFTP 3COM server transport mode buffer overflow attempt (more info ...)attempted-admin  2006-6183  21301    
13927PROTOCOL-TFTP Open TFTP Server log generation buffer overflow attempt (more info ...)attempted-admin  2008-2161  29111    
19014PROTOCOL-TFTP HP Intelligent Management Center TFTP server MODE remote code execution attempt - RRQ (more info ...)attempted-admin  2011-1851  47789    
21255MALWARE-OTHER known malicious FTP login banner - 0wns j0 (more info ...)trojan-activity        URL
21256MALWARE-OTHER known malicious FTP quit banner - Goodbye happy r00ting (more info ...)trojan-activity        URL
29096MALWARE-TOOLS Browser Password Decryptor - Password List sent via FTP (more info ...)trojan-activity        URL
31711INDICATOR-COMPROMISE Keylog string over FTP detected (more info ...)string-detect        URL
31830POLICY-OTHER QLogic Switch 5600/5800 default ftp login attempt (more info ...)default-login-attempt        URL
31831POLICY-OTHER QLogic Switch 5600/5800 default ftp login attempt (more info ...)default-login-attempt        URL
33062FILE-OTHER BulletProof FTP Client BPS file buffer overflow attempt (more info ...)attempted-user  2008-5753      URL
33063FILE-OTHER BulletProof FTP Client BPS file buffer overflow attempt (more info ...)attempted-user  2008-5753      URL
33070BROWSER-PLUGINS Attachmate Reflection FTP Client ActiveX clsid access attempt (more info ...)attempted-user  2014-0603  69151    
33071BROWSER-PLUGINS Attachmate Reflection FTP Client ActiveX clsid access attempt (more info ...)attempted-user  2014-0603  69151    
33072BROWSER-PLUGINS Attachmate Reflection FTP Client ActiveX clsid access attempt (more info ...)attempted-user  2014-0603  69151    
33073BROWSER-PLUGINS Attachmate Reflection FTP Client ActiveX clsid access attempt (more info ...)attempted-user  2014-0603  69151    
33212PUA-ADWARE SoftPulse variant HTTP response attempt (more info ...)trojan-activity        URL
34225PROTOCOL-FTP ProFTPD mod_copy remote code execution attempt (more info ...)attempted-admin  2015-3306  74238    
40908SERVER-OTHER Foscam C1 backdoor account ftp login attempt (more info ...)attempted-user  2016-8731      URL
40909SERVER-OTHER Foscam C1 backdoor account ftp login attempt (more info ...)attempted-user  2016-8731      URL
41793INDICATOR-SCAN Cisco Smart Install Protocol scan TFTP response (more info ...)attempted-recon        URL
42787POLICY-OTHER Schneider Electric hardcoded FTP login attempt (more info ...)attempted-admin        
42862PROTOCOL-FTP FTP server directory traversal attempt (more info ...)attempted-admin  2022-41328  96944    
45460PROTOCOL-FTP Multiple products FTP Client buffer overflow attempt (more info ...)attempted-user  2017-15222      URL
45461PROTOCOL-FTP Multiple products FTP Client buffer overflow attempt (more info ...)attempted-user  2017-15222  101602    URL
47564PROTOCOL-TFTP NetGain Systems Enterprise Manager TFTP directory traversal attempt (more info ...)attempted-admin  2017-16597      
49241PROTOCOL-TFTP Read Request directory traversal attempt (more info ...)attempted-recon  2019-1681      URL
49987SERVER-WEBAPP Cisco Prime Infrastructure arbitrary file upload to tftpRoot attempt (more info ...)attempted-admin  2019-1823      URL
50747PROTOCOL-TFTP TRUFFLEHUNTER TALOS-2019-0851 attack attempt (more info ...)attempted-recon        URL
53565PROTOCOL-TFTP TRUFFLEHUNTER TALOS-2020-1029 attack attempt (more info ...)attempted-dos  2020-6097      URL
57395SERVER-WEBAPP Cisco Unified Communications Products FTP command injection attempt (more info ...)attempted-admin  2021-1362      URL
57397SERVER-WEBAPP Cisco Unified Communications Products FTP command injection attempt (more info ...)attempted-admin  2021-1362      URL
57914SERVER-OTHER Serv-U Secure FTP unauthorized user creation attempt (more info ...)attempted-user  2021-35211      URL
57915SERVER-OTHER Serv-U Secure FTP unauthorized user creation attempt (more info ...)attempted-user  2021-35211      URL
58042SERVER-WEBAPP Serv-U FTP Server stored cross site scripting attempt (more info ...)attempted-user  2019-13182      
58043SERVER-WEBAPP Serv-U FTP Server stored cross site scripting attempt (more info ...)attempted-user  2019-13182      


# of warning rules in this group: 253

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
144PROTOCOL-FTP ADMw0rm ftp login attempt (more info ...)suspicious-login    
157MALWARE-BACKDOOR BackConstruction 2.1 Client FTP Open Request (more info ...)misc-activity    
158MALWARE-BACKDOOR BackConstruction 2.1 Server FTP Open Reply (more info ...)misc-activity    
308SERVER-OTHER NextFTP client overflow (more info ...)attempted-user 1999-0671 572  
334PROTOCOL-FTP .forward (more info ...)suspicious-filename-detect    
335PROTOCOL-FTP .rhosts (more info ...)suspicious-filename-detect    
336PROTOCOL-FTP CWD ~root attempt (more info ...)bad-unknown 1999-0082   
337PROTOCOL-FTP CEL overflow attempt (more info ...)attempted-admin 1999-0789 679 10009 
353PROTOCOL-FTP adm scan (more info ...)suspicious-login    
354PROTOCOL-FTP iss scan (more info ...)suspicious-login    
355PROTOCOL-FTP pass wh00t (more info ...)suspicious-login    
356PROTOCOL-FTP passwd retrieval attempt (more info ...)suspicious-filename-detect    
357PROTOCOL-FTP piss scan (more info ...)suspicious-login    URL
358PROTOCOL-FTP saint scan (more info ...)suspicious-login    
359PROTOCOL-FTP satan scan (more info ...)suspicious-login    
360PROTOCOL-FTP serv-u directory traversal (more info ...)bad-unknown 2001-0054 2052 10565 
361PROTOCOL-FTP SITE EXEC attempt (more info ...)bad-unknown 1999-0955 2241  
362PROTOCOL-FTP tar parameters (more info ...)bad-unknown 1999-0997 2240  
489PROTOCOL-FTP no password (more info ...)unknown    
491PROTOCOL-FTP Bad login (more info ...)bad-unknown    
543INDICATOR-COMPROMISE FTP 'STOR 1MB' possible warez site (more info ...)misc-activity    
544INDICATOR-COMPROMISE FTP 'RETR 1MB' possible warez site (more info ...)misc-activity    
545INDICATOR-COMPROMISE FTP 'CWD / ' possible warez site (more info ...)misc-activity    
546INDICATOR-COMPROMISE FTP 'CWD ' possible warez site (more info ...)misc-activity    
547INDICATOR-COMPROMISE FTP 'MKD ' possible warez site (more info ...)misc-activity    
548INDICATOR-COMPROMISE FTP 'MKD .' possible warez site (more info ...)misc-activity    
554INDICATOR-COMPROMISE FTP 'MKD / ' possible warez site (more info ...)misc-activity    
1068SERVER-WEBAPP tftp attempt (more info ...)web-application-activity    
1107SERVER-WEBAPP ftp.pl access (more info ...)web-application-activity 2000-0674 1471 10467 
1229PROTOCOL-FTP CWD ... (more info ...)bad-unknown  9237  
1230SERVER-WEBAPP VirusWall FtpSave access (more info ...)attempted-recon 2001-0432 2808 10733 
1234SERVER-WEBAPP VirusWall FtpSaveCSP access (more info ...)attempted-recon 2001-0432 2808 10733 
1235SERVER-WEBAPP VirusWall FtpSaveCVP access (more info ...)attempted-recon 2001-0432 2808 10733 
1289PROTOCOL-TFTP GET Admin.dll (more info ...)successful-admin    URL
1379PROTOCOL-FTP STAT overflow attempt (more info ...)attempted-admin 2011-0762 8542  URL
1441PROTOCOL-TFTP GET nc.exe (more info ...)successful-admin    
1442PROTOCOL-TFTP GET shadow (more info ...)successful-admin    
1443PROTOCOL-TFTP GET passwd (more info ...)successful-admin 2021-1437   URL
1445INDICATOR-COMPROMISE FTP file_id.diz access possible warez site (more info ...)suspicious-filename-detect    
1529PROTOCOL-FTP SITE overflow attempt (more info ...)attempted-admin 2001-0770   
1562PROTOCOL-FTP SITE CHOWN overflow attempt (more info ...)attempted-admin 2001-0065 2120 10579 
1612SERVER-WEBAPP ftp.pl attempt (more info ...)web-application-attack 2000-0674 1471 10467 
1621PROTOCOL-FTP CMD overflow attempt (more info ...)attempted-admin    
1622PROTOCOL-FTP RNFR ././ attempt (more info ...)misc-attack 1999-0081   
1623PROTOCOL-FTP invalid MODE (more info ...)protocol-command-decode    URL
1624PROTOCOL-FTP PWD overflow attempt (more info ...)protocol-command-decode    
1625PROTOCOL-FTP SYST overflow attempt (more info ...)protocol-command-decode    URL
1662SERVER-WEBAPP /~ftp access (more info ...)attempted-recon    
1670SERVER-WEBAPP /home/ftp access (more info ...)web-application-activity   11032 
1672PROTOCOL-FTP CWD ~ attempt (more info ...)denial-of-service 2001-0421 9215  
1734PROTOCOL-FTP USER overflow attempt (more info ...)attempted-admin 2005-3683 8376  
1777PROTOCOL-FTP EXPLOIT STAT asterisk dos attempt (more info ...)attempted-dos 2002-0073 4482 10934 URL
1778PROTOCOL-FTP EXPLOIT STAT ? dos attempt (more info ...)attempted-dos 2002-0073 4482 10934 URL
1864PROTOCOL-FTP SITE NEWER attempt (more info ...)attempted-dos 1999-0880  10319 
1888PROTOCOL-FTP SITE CPWD overflow attempt (more info ...)misc-attack 2002-0826 5427  
1919PROTOCOL-FTP CWD overflow attempt (more info ...)attempted-admin 2002-0405 7950  
1920PROTOCOL-FTP SITE NEWER overflow attempt (more info ...)attempted-admin 1999-0800 229  
1921PROTOCOL-FTP SITE ZIPCHK overflow attempt (more info ...)attempted-admin 2000-0040   
1927PROTOCOL-FTP authorized_keys (more info ...)suspicious-filename-detect    
1928PROTOCOL-FTP shadow retrieval attempt (more info ...)suspicious-filename-detect    
1941PROTOCOL-TFTP GET filename overflow attempt (more info ...)attempted-admin 2009-2958 5328 18264 
1942PROTOCOL-FTP RMDIR overflow attempt (more info ...)attempted-admin  819  
1971PROTOCOL-FTP SITE EXEC format string attempt (more info ...)bad-unknown 2000-0573 1505  
1972PROTOCOL-FTP PASS overflow attempt (more info ...)attempted-admin 2006-6576 9285  
1973PROTOCOL-FTP MKD overflow attempt (more info ...)attempted-admin 2010-0625 9872 12108 URL
1974PROTOCOL-FTP REST overflow attempt (more info ...)attempted-admin 2001-0826 2972 11755 
1976PROTOCOL-FTP RMD overflow attempt (more info ...)attempted-admin 2010-0625 39041  
1992PROTOCOL-FTP LIST directory traversal attempt (more info ...)protocol-command-decode 2002-1054 2618 11112 
2125PROTOCOL-FTP CWD Root directory traversal attempt (more info ...)protocol-command-decode 2003-0392 7674 11677 
2178PROTOCOL-FTP USER format string attempt (more info ...)misc-attack 2004-0277 9800 11687 
2179PROTOCOL-FTP PASS format string attempt (more info ...)misc-attack 2007-1195 9800 10490 
2272PROTOCOL-FTP LIST integer overflow attempt (more info ...)misc-attack 2003-0854 8875 11912 
2332PROTOCOL-FTP MKD format string attempt (more info ...)misc-attack  9262  
2333PROTOCOL-FTP RENAME format string attempt (more info ...)misc-attack  9262  
2334PROTOCOL-FTP Yak! FTP server default account login attempt (more info ...)suspicious-login  9072  URL
2335PROTOCOL-FTP RMD / attempt (more info ...)attempted-dos  9159  
2337PROTOCOL-TFTP PUT filename overflow attempt (more info ...)attempted-admin 2009-2958 8505 18264 
2338PROTOCOL-FTP LIST buffer overflow attempt (more info ...)misc-attack 2009-0351 9675  URL
2340PROTOCOL-FTP SITE CHMOD overflow attempt (more info ...)attempted-admin 1999-0838 9675 12037 
2343PROTOCOL-FTP STOR overflow attempt (more info ...)attempted-admin 2000-0133 8668  URL
2344PROTOCOL-FTP XCWD overflow attempt (more info ...)attempted-admin 2004-2728 8704  
2373PROTOCOL-FTP XMKD overflow attempt (more info ...)attempted-admin 2001-1021 7909  
2374PROTOCOL-FTP NLST overflow attempt (more info ...)attempted-admin 2009-3023 7909  URL
2389PROTOCOL-FTP RNTO overflow attempt (more info ...)attempted-admin 2005-3683 8315  
2390PROTOCOL-FTP STOU overflow attempt (more info ...)attempted-admin 2003-0466 8315  
2391PROTOCOL-FTP APPE overflow attempt (more info ...)attempted-admin 2003-0772 8542  
2392PROTOCOL-FTP RETR overflow attempt (more info ...)attempted-admin 2005-3683 8315  
2416PROTOCOL-FTP invalid MDTM command attempt (more info ...)attempted-admin 2004-0330 9751  
2417PROTOCOL-FTP format string attempt (more info ...)string-detect 2009-4769 9800  
2449PROTOCOL-FTP ALLO overflow attempt (more info ...)attempted-admin 2004-1883 9953 14598 
2546PROTOCOL-FTP MDTM overflow attempt (more info ...)attempted-admin 2004-0330 9751 12080 
2574PROTOCOL-FTP RETR format string attempt (more info ...)attempted-admin 2004-1883 9800  
3077PROTOCOL-FTP RNFR overflow attempt (more info ...)attempted-admin  14339  
3441PROTOCOL-FTP PORT bounce attempt (more info ...)misc-attack 1999-0017 126 10081 
3460PROTOCOL-FTP REST with numeric argument (more info ...)attempted-recon  7825  
3523PROTOCOL-FTP SITE INDEX format string attempt (more info ...)bad-unknown 2000-0573 1387  
3526SERVER-ORACLE XDB FTP UNLOCK overflow attempt (more info ...)attempted-admin 2003-0727 8375  
3532SERVER-ORACLE ftp password buffer overflow attempt (more info ...)attempted-user 2003-0727 8375  
3630SERVER-ORACLE ftp TEST command buffer overflow attempt (more info ...)misc-attack 2003-0727 8375  
3631SERVER-ORACLE ftp user name buffer overflow attempt (more info ...)attempted-user 2003-0727 8375  
3817PROTOCOL-TFTP GET transfer mode overflow attempt (more info ...)attempted-admin 2005-1812 13821  
5881MALWARE-OTHER Keylogger spyagent runtime detect - ftp delivery (more info ...)successful-recon-limited    URL
6142MALWARE-BACKDOOR hellzaddiction v1.0e runtime detection - ftp open (more info ...)trojan-activity    URL
6208MALWARE-OTHER Keylogger winsession runtime detection - ftp (more info ...)successful-recon-limited    URL
6288MALWARE-BACKDOOR fictional daemon 4.4 runtime detection - ftp (more info ...)trojan-activity    URL
6319MALWARE-BACKDOOR evilftp runtime detection - init connection (more info ...)trojan-activity    URL
7185MALWARE-OTHER Keylogger 007 spy software runtime detection - ftp (more info ...)successful-recon-limited    URL
7504MALWARE-OTHER Keylogger actualspy runtime detection - ftp-data (more info ...)successful-recon-limited    URL
7762MALWARE-CNC analftp 0.1 variant outbound connection icq notification (more info ...)trojan-activity    URL
7934BROWSER-PLUGINS Microsoft Internet Explorer ftp Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user 2007-0218   URL
8415PROTOCOL-FTP SIZE overflow attempt (more info ...)attempted-admin 2006-4318 19617  
8479PROTOCOL-FTP HELP overflow attempt (more info ...)attempted-admin 2001-0826 2972  
8480PROTOCOL-FTP PORT overflow attempt (more info ...)attempted-admin 2006-2226 18711  
8481PROTOCOL-FTP Microsoft NLST * dos attempt (more info ...)attempted-dos 2001-0334 2717  URL
8707PROTOCOL-FTP WZD-FTPD SITE arbitrary command execution attempt (more info ...)attempted-admin 2005-3081 14935  
9341MALWARE-OTHER sasser open ftp command shell (more info ...)trojan-activity    URL
9402MALWARE-OTHER welchia tftp propagation detection (more info ...)trojan-activity    URL
9638PROTOCOL-TFTP PUT Microsoft RIS filename overwrite attempt (more info ...)policy-violation 2006-5584   URL
9792PROTOCOL-FTP PASV overflow attempt (more info ...)attempted-admin    URL
9828MALWARE-OTHER Keylogger paq keylog runtime detection - ftp (more info ...)successful-recon-limited    URL
10089MALWARE-OTHER Keylogger beyond Keylogger runtime detection - log sent by ftp (more info ...)successful-recon-limited    URL
10135SERVER-OTHER Squid proxy FTP denial of service attempt (more info ...)denial-of-service 2007-0247 22079  
10188PROTOCOL-FTP Ipswitch Ws_ftp XMD5 overflow attempt (more info ...)attempted-admin 2006-5000 20076  
10444MALWARE-BACKDOOR acidbattery 1.0 runtime detection - open ftp serice (more info ...)trojan-activity    URL
12076SERVER-OTHER Ipswitch WS_FTP log server long unicode string (more info ...)denial-of-service 2007-3823   URL
12237MALWARE-BACKDOOR theef 2.10 runtime detection - ftp (more info ...)trojan-activity    
12238MALWARE-BACKDOOR theef 2.10 runtime detection - ftp (more info ...)trojan-activity    URL
12379MALWARE-OTHER Keylogger PaqKeylogger 5.1 runtime detection - ftp (more info ...)successful-recon-limited    URL
13360APP-DETECT FTP 530 Login failed response (more info ...)misc-activity    URL
13925PROTOCOL-FTP Computer Associates eTrust Secure Content Manager PASV stack overflow attempt (more info ...)attempted-user 2008-2541 29528  
14743PROTOCOL-FTP RNTO directory traversal attempt (more info ...)suspicious-filename-detect 2008-4501 31563  
14778BROWSER-PLUGINS Dart Communications PowerTCP FTP ActiveX clsid access (more info ...)attempted-user 2008-4652 31814  
14780BROWSER-PLUGINS Dart Communications PowerTCP FTP ActiveX function call access (more info ...)attempted-user 2008-4652 31814  
15159BROWSER-PLUGINS Evans FTP ActiveX clsid access (more info ...)attempted-user  32814  
15161BROWSER-PLUGINS Evans FTP ActiveX function call access (more info ...)attempted-user  32814  
15368BROWSER-PLUGINS FathFTP ActiveX clsid access (more info ...)attempted-user  33842  
15370BROWSER-PLUGINS FathFTP ActiveX function call access (more info ...)attempted-user  33842  
15932PROTOCOL-FTP LIST globbing denial of service attack (more info ...)attempted-dos 2009-2521   URL
16077SERVER-OTHER Tripwire format string vulnerability ftp exploit attempt (more info ...)attempted-admin 2004-0536 10454  
16357PROTOCOL-FTP multiple extension code execution attempt (more info ...)web-application-attack 2009-4444   
16363FILE-EXECUTABLE potentially executable file upload via FTP (more info ...)policy-violation    URL
16697PROTOCOL-FTP httpdx USER null byte denial of service (more info ...)attempted-dos    URL
16698PROTOCOL-FTP httpdx PASS null byte denial of service (more info ...)attempted-dos    URL
16795BROWSER-CHROME Google Chrome FTP handling out-of-bounds array index denial of service attempt (more info ...)attempted-dos  39183  
16806MALWARE-CNC Win.Trojan.Qakbot.E - FTP upload seclog (more info ...)trojan-activity    URL
16807MALWARE-CNC Win.Trojan.Qakbot.E - FTP Upload ps_dump (more info ...)trojan-activity    URL
17059PROTOCOL-FTP Vermillion 1.31 vftpd port command memory corruption (more info ...)misc-attack    URL
17329PROTOCOL-FTP EPRT overflow attempt (more info ...)attempted-admin 2005-4459 15998  
17367BROWSER-IE Microsoft Internet Explorer FTP response parsing memory corruption attempt (more info ...)web-application-attack 2007-0217 22489  
17446BROWSER-IE Microsoft Internet Explorer FTP client directory traversal attempt (more info ...)misc-activity 2004-1376   
17518PROTOCOL-FTP FlashGet PWD command stack buffer overflow attempt (more info ...)attempted-user 2008-4321 30685  
17521SERVER-OTHER GoodTech SSH Server SFTP processing buffer overflow attempt (more info ...)attempted-user 2008-4726 31879  
17712OS-WINDOWS TFTP PUT Microsoft RIS filename overwrite attempt (more info ...)policy-violation 2006-5584   URL
18181PROTOCOL-FTP ProFTPd 1.3.3c backdoor activity (more info ...)trojan-activity    URL
18182PROTOCOL-FTP ProFTPd 1.3.3c backdoor help access attempt (more info ...)trojan-activity    URL
18300BROWSER-IE Microsoft Internet Explorer FTP command injection attempt (more info ...)attempted-user 2004-1166 11826  URL
18326PROTOCOL-FTP ProFTPD mod_site_misc module directory traversal attempt (more info ...)attempted-user 2010-3867 44562  
18575PROTOCOL-FTP Computer Associates eTrust Secure Content Manager LIST stack overflow attempt (more info ...)attempted-user 2008-2541 29528  
18580PROTOCOL-FTP ACCT overflow attempt (more info ...)attempted-admin    URL
18588PROTOCOL-FTP Ipswitch Ws_ftp XCRC overflow attempt (more info ...)attempted-admin 2006-4847 20076  
18598SERVER-OTHER GoodTech SSH Server SFTP Processing Buffer Overflow (more info ...)attempted-user 2008-4726 31879  
18933SERVER-OTHER SolarWinds TFTP Server Read request denial of service attempt (more info ...)attempted-dos 2010-2115 40333  
19415MALWARE-CNC vsFTPd 2.3.4 backdoor connection (more info ...)trojan-activity  48539  
19761MALWARE-CNC Win.Trojan.Ftpharvxqq variant outbound connection (more info ...)trojan-activity    URL
21445SERVER-OTHER vsFTPd denial of service attempt (more info ...)attempted-dos 2004-2259   
23055PROTOCOL-FTP Multiple Products FTP MKD buffer overflow attempt (more info ...)attempted-admin 2010-0625 9872 12108 URL
26179SERVER-WEBAPP TP-Link http/tftp backdoor initiation attempt (more info ...)policy-violation    URL
26471PROTOCOL-FTP VanDyke AbsoluteFTP LIST command stack buffer overflow attempt (more info ...)attempted-user 2011-5164 50614  
26745MALWARE-CNC Win.Trojan.BlackRev cnc ftp command (more info ...)trojan-activity    URL
27269SERVER-OTHER GuildFTPd CWD command heap overflow attempt (more info ...)attempted-admin 2008-4572 31729  
27270SERVER-OTHER GuildFTPd LIST command heap overflow attempt (more info ...)attempted-admin 2008-4572 31729  
28216MALWARE-CNC known malware FTP login (more info ...)trojan-activity    URL
28551MALWARE-CNC Win.Trojan.NXI ftp username connection (more info ...)trojan-activity    URL
28560MALWARE-CNC Win.Trojan.Plugx FTP keepalive outbound connection (more info ...)trojan-activity    URL
28991MALWARE-CNC Win.Trojan.Qakbot FTP data exfiltration (more info ...)trojan-activity    URL
29095MALWARE-CNC Win.Trojan.Fotip FTP file upload variant outbound connection (more info ...)trojan-activity    URL
29420MALWARE-CNC Win.Trojan.Reedum BlackPoS outbound FTP connection (more info ...)trojan-activity    URL
29421MALWARE-CNC Win.Trojan.Reedum BlackPoS outbound FTP connection (more info ...)trojan-activity    URL
30055MALWARE-CNC Win.Trojan.Deventiz CWD system information disclosure via FTP (more info ...)trojan-activity    URL
30058MALWARE-CNC Win.Trojan.Bogoclak outbound FTP connection information disclosure (more info ...)trojan-activity    URL
30098MALWARE-CNC Win.Trojan.Reedum BlackPoS outbound FTP file timestamp (more info ...)trojan-activity    URL
30945MALWARE-CNC Win.Worm.Winiga FTP login attempt (more info ...)trojan-activity    URL
31063MALWARE-CNC Win.Trojan.Expone FTP login attempt (more info ...)trojan-activity    URL
31128PROTOCOL-FTP CoreFTP FTP Server TYPE command denial of service attempt (more info ...)attempted-dos  67613  
31564MALWARE-CNC Win.Trojan.CosmicDuke FTP data exfiltration (more info ...)trojan-activity    URL
31717MALWARE-CNC Win.Trojan.SoftPulse variant outbound connection (more info ...)trojan-activity    URL
31742SERVER-WEBAPP Wing FTP Server admin interface remote code execution attempt (more info ...)attempted-admin    URL
32523BROWSER-OTHER FreeBSD tnftp fetch_url client side command injection attempt (more info ...)attempted-user 2014-8517 70792  
32524BROWSER-OTHER FreeBSD tnftp fetch_url client side command injection attempt (more info ...)attempted-user 2014-8517 70792  
32525BROWSER-OTHER FreeBSD tnftp client detected (more info ...)protocol-command-decode    
32637PROTOCOL-TFTP UDP large packet use after free attempt (more info ...)attempted-user 2018-8476   URL
32672SERVER-OTHER Cisco ios ftp proxy overflow attempt (more info ...)attempted-user 2005-2841   
33170BROWSER-PLUGINS Attachmate Reflection FTP Client Memory Corruption ActiveX function call access attempt (more info ...)attempted-user 2014-0603   URL
33171BROWSER-PLUGINS Attachmate Reflection FTP Client Memory Corruption ActiveX clsid access attempt (more info ...)attempted-user 2014-0603   URL
33172BROWSER-PLUGINS Attachmate Reflection FTP Client Memory Corruption ActiveX function call access attempt (more info ...)attempted-user 2014-0603   URL
33173BROWSER-PLUGINS Attachmate Reflection FTP Client Memory Corruption ActiveX clsid access attempt (more info ...)attempted-user 2014-0603   URL
33174BROWSER-PLUGINS Attachmate Reflection FTP Client Memory Corruption ActiveX function call access attempt (more info ...)attempted-user 2014-0603   URL
33175BROWSER-PLUGINS Attachmate Reflection FTP Client Memory Corruption ActiveX function call access attempt (more info ...)attempted-user 2014-0603   URL
35336PROTOCOL-TFTP Cisco IOS TFTP server denial of service attempt (more info ...)attempted-dos 2015-0681   URL
35337PROTOCOL-TFTP Cisco IOS TFTP server denial of service attempt (more info ...)attempted-dos 2015-0681   URL
35338PROTOCOL-TFTP Cisco IOS TFTP server denial of service attempt (more info ...)attempted-dos 2015-0681   URL
35339PROTOCOL-TFTP Cisco IOS TFTP server denial of service attempt (more info ...)attempted-dos 2015-0681   URL
35340PROTOCOL-TFTP Cisco IOS TFTP server denial of service attempt (more info ...)attempted-dos 2015-0681   URL
35341PROTOCOL-TFTP Cisco IOS TFTP server denial of service attempt (more info ...)attempted-dos 2015-0681   URL
35342PROTOCOL-TFTP Cisco IOS TFTP server denial of service attempt (more info ...)attempted-dos 2015-0681   URL
35343PROTOCOL-TFTP Cisco IOS TFTP server denial of service attempt (more info ...)attempted-dos 2015-0681   URL
37934PROTOCOL-FTP Computer Associates eTrust Secure Content Manager LIST stack overflow attempt (more info ...)attempted-user 2008-2541 29528  
37951BROWSER-IE Microsoft Internet Explorer FTP client directory traversal attempt (more info ...)misc-activity 2004-1376   
37952BROWSER-IE Microsoft Internet Explorer FTP client directory traversal attempt (more info ...)misc-activity 2004-1376   
38385MALWARE-CNC Win.Trojan.FTPKeyLogger outbound connection (more info ...)trojan-activity    URL
38386MALWARE-CNC Win.Trojan.FTPKeyLogger outbound connection (more info ...)trojan-activity    URL
38387MALWARE-CNC Win.Trojan.FTPKeyLogger outbound connection (more info ...)trojan-activity    URL
38388MALWARE-CNC Win.Trojan.FTPKeyLogger geolocation check (more info ...)trojan-activity    URL
39378PROTOCOL-FTP PUT overflow attempt (more info ...)attempted-admin    URL
39450PROTOCOL-TFTP Firmware upgrade request (more info ...)bad-unknown    
39451PROTOCOL-TFTP Comtrol RocketLinx switch reboot request (more info ...)bad-unknown    
39452PROTOCOL-TFTP Comtrol RocketLinx factory reset request (more info ...)bad-unknown    
40355PROTOCOL-FTP z/OS FTP Job Entry Subsystem JCL execution attempt (more info ...)policy-violation    URL
41854BROWSER-WEBKIT Apple Safari FTP URL cross-domain restriction bypass attempt (more info ...)misc-activity 2015-1126 73977  
41855BROWSER-WEBKIT Apple Safari FTP URL cross-domain restriction bypass attempt (more info ...)misc-activity 2015-1126 73977  
41906POLICY-OTHER HTTP redirect to FTP server attempt (more info ...)attempted-user 2016-4971 91530  URL
43106PROTOCOL-SCADA Optima PLC APIFTP denial of service attempt (more info ...)attempted-dos 2012-5049   
43123INDICATOR-COMPROMISE OptoMMP FTP Password read or write attempt (more info ...)attempted-admin    URL
43124INDICATOR-COMPROMISE OptoMMP FTP Username read or write attempt (more info ...)attempted-admin    URL
43125INDICATOR-COMPROMISE OptoMMP FTP Password read or write attempt (more info ...)attempted-admin    URL
43126INDICATOR-COMPROMISE OptoMMP FTP Username read or write attempt (more info ...)attempted-admin    URL
43239PROTOCOL-FTP WS-FTP REST command overly large file creation attempt (more info ...)attempted-dos 2004-1848 9953  
43290SERVER-WEBAPP /ws_ftp.log file access attempt (more info ...)attempted-recon    
43384INDICATOR-COMPROMISE Wing FTP Server potentially malicious admin user creation attempt (more info ...)attempted-admin    URL
43385INDICATOR-COMPROMISE Wing FTP Server potentially malicious admin user creation attempt (more info ...)attempted-admin    URL
43574SERVER-WEBAPP Wing FTP Server command injection attempt (more info ...)web-application-attack 2015-4107 75043  URL
43663SERVER-OTHER WSFTP IpSwitch custom SITE command execution attempt (more info ...)attempted-admin 2004-1885   
43753SERVER-OTHER Sami FTP RETR denial of service attempt (more info ...)denial-of-service 2008-5105   
43987SERVER-OTHER Konqueror KDE ftp iframe denial of service attempt (more info ...)attempted-admin 2007-1308   
43988SERVER-OTHER Konqueror KDE ftp iframe denial of service attempt (more info ...)attempted-admin 2007-1308   
44633SERVER-OTHER Colorado FTP Server directory traversal attempt (more info ...)attempted-user    URL
45188SERVER-OTHER ElectraSoft 32bit FTP PASV reply stack buffer overflow attempt (more info ...)attempted-user 2009-1675 34838  
45591PROTOCOL-FTP LabF nfsAxe FTP Client buffer overflow attempt (more info ...)attempted-user    URL
45612PROTOCOL-TFTP WRITE long filename attempt (more info ...)misc-activity    
45828PROTOCOL-FTP Computer Associates eTrust Secure Content Manager LIST stack overflow attempt (more info ...)attempted-user 2008-2541   
46271MALWARE-CNC Win.Trojan.Sanny malware variant FTP login (more info ...)trojan-activity    URL
46272MALWARE-CNC Win.Trojan.Sanny malware variant FTP login (more info ...)trojan-activity    URL
46791SERVER-WEBAPP Ruby Net FTP library command injection attempt (more info ...)web-application-attack 2017-17405 102204  URL
47402INDICATOR-OBFUSCATION FTP file upload over non-standard port attempt (more info ...)misc-activity    URL
49426PROTOCOL-FTP GP-Pro EX HMI WinGP Runtime Arbitrary File Disclosure attempt (more info ...)attempted-user    URL
51646SERVER-OTHER Cisco IOS XE FTP Application Layer Gateway denial of service attempt (more info ...)attempted-dos 2019-12655   URL
53689MALWARE-CNC Win.Malware.PoetRat malware variant FTP login (more info ...)trojan-activity    URL
54644MALWARE-CNC Win.Trojan.Hackbit outbound ftp connection attempt (more info ...)trojan-activity    URL
57207FILE-OTHER SolarWinds Serv-U FTP Server admin profile download attempt (more info ...)attempted-admin 2021-25276   URL
57208FILE-OTHER SolarWinds Serv-U FTP Server admin profile download attempt (more info ...)attempted-admin 2021-25276   URL
59527PROTOCOL-FTP uftpd handle_PORT buffer overflow attempt (more info ...)attempted-user 2020-5204   URL
59690PROTOCOL-FTP Attachmate Reflection FTP client buffer overflow attempt (more info ...)attempted-user 2014-5211   
61798SERVER-WEBAPP NETGEAR Nighthawk RAX30 router TFTP command injection attempt (more info ...)attempted-user 2023-27367   URL

 goto Top

Group: Server / Misc / SSH

# of attack rules in this group: 2

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
57048SERVER-WEBAPP SaltStack Salt API SSH Client command injection attempt (more info ...)web-application-attack  2020-16846      
57049SERVER-WEBAPP SaltStack Salt API SSH Client command injection attempt (more info ...)web-application-attack  2020-16846      


# of warning rules in this group: 25

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1326INDICATOR-SHELLCODE ssh CRC32 overflow NOOP (more info ...)shellcode-detect 2001-0572 2347  
1638INDICATOR-SCAN SSH Version map attempt (more info ...)network-scan    URL
1810SERVER-OTHER successful gobbles ssh exploit GOBBLE (more info ...)successful-admin 2002-0640 5093  
1811SERVER-OTHER successful gobbles ssh exploit uname (more info ...)misc-attack 2002-0640 5093 11031 
1812SERVER-OTHER gobbles SSH exploit attempt (more info ...)misc-attack 2002-0639 5093 11031 
1838SERVER-OTHER SSH server banner overflow (more info ...)misc-attack 2002-1059 5287 15822 
13586APP-DETECT SSH server detected on non-standard port (more info ...)protocol-command-decode    URL
13814MALWARE-CNC passhax variant outbound connection (more info ...)trojan-activity    URL
16680APP-DETECT Tandberg VCS SSH default key (more info ...)misc-activity 2009-4510   URL
19559INDICATOR-SCAN SSH brute force login attempt (more info ...)misc-activity 2022-20854   URL
30337SERVER-OTHER Cisco Catalyst SSH protocol mismatch denial of service attempt (more info ...)attempted-dos  2117  URL
31708SERVER-OTHER Cougar-LG SSH key path access attempt (more info ...)attempted-recon 2014-3929   URL
31747SERVER-WEBAPP Gitlab ssh key upload command injection attempt (more info ...)attempted-admin 2013-4490 63513  
37017SERVER-OTHER Redis SSH authorized keys file overwrite attempt (more info ...)misc-activity    URL
37356MALWARE-CNC Win.Trojan.BlackEnergy DropBear SSH public key (more info ...)trojan-activity    URL
37357MALWARE-CNC Win.Trojan.BlackEnergy DropBear SSH server password authentication (more info ...)trojan-activity    URL
40189POLICY-OTHER SSH weak 3DES cipher suite use attempt (more info ...)policy-violation 2016-2183 92630  
40190POLICY-OTHER SSH weak blowfish cipher suite use attempt (more info ...)policy-violation 2016-2183 92630  
45974MALWARE-CNC Suspected Unix.Malware.GoScanSSH outbound beacon attempt (more info ...)trojan-activity    URL
58070SERVER-WEBAPP Nagios XI Web SSH Terminal sshterm cross site scripting attempt (more info ...)attempted-user 2021-25299   
58071SERVER-WEBAPP Nagios XI Web SSH Terminal sshterm cross site scripting attempt (more info ...)attempted-user 2021-25299   
61546SERVER-OTHER OpenSSH deprecated client version string expiration (more info ...)not-suspicious 2023-25136   URL
61547SERVER-OTHER OpenSSH deprecated client string remote code execution attempt (more info ...)attempted-user 2023-25136   URL
61548SERVER-OTHER OpenSSH deprecated WinSCP version detected (more info ...)not-suspicious 2023-25136   URL
61549SERVER-OTHER OpenSSH deprecated PuTTY version detected (more info ...)not-suspicious 2023-25136   URL

 goto Top

Group: Server / Misc / Backup

# of attack rules in this group: 45

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3084SERVER-OTHER Veritas backup overflow attempt (more info ...)attempted-admin  2004-1172  11974    
3453SERVER-OTHER Arkeia client backup system info probe (more info ...)attempted-recon  2005-0491  12594    
3454SERVER-OTHER Arkeia client backup generic info probe (more info ...)attempted-recon  2005-0491  12594    
3457SERVER-OTHER Arkeia backup client type 77 overflow attempt (more info ...)attempted-user  2005-0491  12594  17158  
3458SERVER-OTHER Arkeia backup client type 84 overflow attempt (more info ...)attempted-user  2005-0491  12594    
4126SERVER-OTHER Veritas Backup Exec root connection attempt using default password hash (more info ...)suspicious-login  2005-2611  14551    URL
10130POLICY-OTHER VERITAS NetBackup system - execution function call access (more info ...)misc-activity  2006-6822  21565    
12078SERVER-OTHER CA BrightStor ARCserve LGServer heap buffer overflow (more info ...)attempted-admin  2007-0449  22340    
12079SERVER-OTHER CA BrightStor ARCserve LGServer stack buffer overflow attempt (more info ...)attempted-admin  2007-0449  22342    
12667SERVER-OTHER CA BrightStor ARCServer malicious fileupload attempt (more info ...)attempted-admin  2007-5005  24348    
12784SERVER-OTHER CA ARCserve LGServer stack buffer overflow attempt (more info ...)attempted-admin  2007-3216  24348    
12785SERVER-OTHER CA ARCserve LGServer stack buffer overflow attempt (more info ...)attempted-admin  2007-3216  24348    
12786SERVER-OTHER CA ARCserve LGServer stack buffer overflow attempt (more info ...)attempted-admin  2007-3216  24348    
14768SERVER-OTHER Symantec Veritas Storage Scheduler Service NULL Session auth bypass attempt (more info ...)attempted-user  2008-3703  30596    
14773SERVER-OTHER CA ARCserve LGServer handshake buffer overflow attempt (more info ...)attempted-admin  2008-3175  30472    
17045SERVER-OTHER CA ARCserve Backup for Laptops and Desktops LGServer handshake buffer overflow attempt (more info ...)attempted-admin  2008-3175  30472    
17046SERVER-OTHER CA ARCserve Backup for Laptops and Desktops LGServer handshake buffer overflow attempt (more info ...)attempted-admin  2008-3175  30472    
17706SERVER-OTHER Veritas NetBackup java user interface service format string attack attempt (more info ...)attempted-admin  2005-2715  15079    
18285SERVER-OTHER BrightStor ARCserve backup tape engine buffer overflow attempt (more info ...)attempted-admin  2006-6076  21221    
18291SERVER-OTHER Arkeia Network Backup Client Buffer Overflow Type 77 Attempt (more info ...)attempted-user  2005-0491  12594    
18292SERVER-OTHER Arkeia Network Backup Client Buffer Overflow Type 84 Attempt (more info ...)attempted-user  2005-0491  12594    
18555SERVER-OTHER VERITAS NetBackup java authentication service format string exploit attempt (more info ...)attempted-user  2005-2715  15079    URL
23096SERVER-OTHER VERITAS NetBackup java authentication service format string exploit attempt (more info ...)attempted-user  2005-2715  15079    URL
29585SERVER-OTHER Symantec Veritas Enterprise Administrator service vxsvc type 3 buffer overflow attempt (more info ...)attempted-admin  2011-0547  49014    
29586SERVER-OTHER Symantec Veritas Enterprise Administrator service vxsvc type 6 buffer overflow attempt (more info ...)attempted-admin  2011-0547  49014    
29587SERVER-OTHER Symantec Veritas Enterprise Administrator service vxsvc type 6 buffer overflow attempt (more info ...)attempted-admin  2011-0547  49014    
29588SERVER-OTHER Symantec Veritas Enterprise Administrator service vxsvc type 7 buffer overflow attempt (more info ...)attempted-admin  2011-0547  49014    
29589SERVER-OTHER Symantec Veritas Enterprise Administrator service vxsvc type 7 buffer overflow attempt (more info ...)attempted-admin  2011-0547  49014    
29590SERVER-OTHER Symantec Veritas Enterprise Administrator service vxsvc type A buffer overflow attempt (more info ...)attempted-admin  2011-0547  49014    
29591SERVER-OTHER Symantec Veritas Enterprise Administrator service vxsvc type A buffer overflow attempt (more info ...)attempted-admin  2011-0547  49014    
34878SERVER-WEBAPP Arcserve Unified Data Protection export servlet directory traversal attempt (more info ...)web-application-attack  2015-4068  74845    
34879SERVER-WEBAPP Arcserve Unified Data Protection export servlet directory traversal attempt (more info ...)web-application-attack  2015-4068  74845    
34880SERVER-WEBAPP Arcserve Unified Data Protection export servlet directory traversal attempt (more info ...)web-application-attack  2015-4068  74845    
34881SERVER-WEBAPP Arcserve Unified Data Protection reportFileServlet directory traversal attempt (more info ...)web-application-attack  2015-4068  74845    
34882SERVER-WEBAPP Arcserve Unified Data Protection reportFileServlet directory traversal attempt (more info ...)web-application-attack  2015-4068  74845    
34883SERVER-WEBAPP Arcserve Unified Data Protection reportFileServlet directory traversal attempt (more info ...)web-application-attack  2015-4068  74845    
36877NETBIOS DCERPC BrightStor ARCserve corrupt user-supplied memory location attempt (more info ...)protocol-command-decode  2006-6917      URL
40837SERVER-WEBAPP Veritas NetBackup Appliance getLicense command injection attempt (more info ...)web-application-attack  2016-7399  94384    URL
40838SERVER-WEBAPP Veritas NetBackup Appliance getLicense command injection attempt (more info ...)web-application-attack  2016-7399  94384    URL
43055SERVER-OTHER Veritas Netbackup bprd remote code execution attempt (more info ...)attempted-user  2017-8856      URL
44700SERVER-OTHER Veritas Backup Exec Agent use after free attempt (more info ...)attempted-admin  2017-8895  98386    URL
44701SERVER-OTHER Veritas Backup Exec Agent use after free attempt (more info ...)attempted-admin  2017-8895  98386    URL
61629SERVER-WEBAPP Veritas Backup Exec Agent command execution attempt (more info ...)attempted-admin  2021-27878      URL
61630SERVER-WEBAPP Veritas Backup Exec Agent command execution attempt (more info ...)attempted-admin  2021-27878      URL
61631SERVER-WEBAPP Veritas Backup Exec Agent directory traversal attempt (more info ...)attempted-user  2021-27876      URL


# of warning rules in this group: 75

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3474SERVER-OTHER ARCserve backup TCP slot info msg client name overflow (more info ...)attempted-admin 2005-2535 12536  
3475SERVER-OTHER ARCserve backup TCP slot info msg client domain overflow (more info ...)attempted-admin 2005-2535 12536  
3476SERVER-OTHER ARCserve backup TCP product info msg 0x9b client domain overflow (more info ...)attempted-admin 2005-2535 12536  
3477SERVER-OTHER ARCserve backup TCP product info msg 0x9b client name overflow (more info ...)attempted-admin 2005-2535 12536  
3479SERVER-OTHER ARCserve backup TCP product info msg 0x9c client name overflow (more info ...)attempted-admin 2005-2535 12536  
3480SERVER-OTHER ARCserve backup UDP slot info msg client name overflow (more info ...)attempted-admin 2005-2535 12536  
3481SERVER-OTHER ARCserve backup UDP slot info msg client domain overflow (more info ...)attempted-admin 2005-2535 12536  
3482SERVER-OTHER ARCserve backup UDP product info msg 0x9b client name overflow (more info ...)attempted-admin 2005-2535 12536  
3483SERVER-OTHER ARCserve backup UDP product info msg 0x9b client domain overflow (more info ...)attempted-admin 2005-2535 12536  
3484SERVER-OTHER ARCserve backup UDP product info msg 0x9c client name overflow (more info ...)attempted-admin 2005-2535 12536  
3485SERVER-OTHER ARCserve backup UDP product info msg 0x9c client domain overflow (more info ...)attempted-admin 2005-2535 12536  
3530SERVER-OTHER ARCserve backup UDP msg 0x99 client name overflow (more info ...)attempted-admin 2005-2535 12536  
3531SERVER-OTHER ARCserve backup UDP msg 0x99 client domain overflow (more info ...)attempted-admin 2005-2535 12536  
3658SERVER-OTHER ARCserve universal backup agent option 1000 little endian buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3659SERVER-OTHER ARCserve universal backup agent option 1000 buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3660SERVER-OTHER ARCserve universal backup agent option 00 little endian buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3661SERVER-OTHER ARCserve universal backup agent option 00 buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3662SERVER-OTHER ARCserve universal backup agent option 03 little endian buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3663SERVER-OTHER ARCserve universal backup agent option 03 buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3695SERVER-OTHER Veritas Backup Agent password overflow attempt (more info ...)attempted-admin 2005-0773 14022  
3696SERVER-OTHER Veritas Backup Agent DoS attempt (more info ...)attempted-dos 2005-0772 14201  
6010SERVER-OTHER VERITAS NetBackup vnetd connection attempt (more info ...)protocol-command-decode    
6011SERVER-OTHER VERITAS NetBackup vnetd buffer overflow attempt (more info ...)attempted-admin 2006-0991 17264  
6404SERVER-OTHER Veritas NetBackup Volume Manager connection attempt (more info ...)protocol-command-decode    
6405SERVER-OTHER Veritas NetBackup Volume Manager overflow attempt (more info ...)attempted-admin 2006-0989 17264  
10132PROTOCOL-RPC portmap BrightStor ARCserve denial of service attempt (more info ...)attempted-dos 2007-0816 22365  
10133PROTOCOL-RPC portmap BrightStor ARCserve denial of service attempt (more info ...)attempted-dos 2007-0816 22365  
10483PROTOCOL-RPC portmap CA BrightStor ARCserve udp request (more info ...)rpc-portmap-decode 2007-1785 23209  
10484PROTOCOL-RPC portmap CA BrightStor ARCserve tcp procedure 191 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
10485PROTOCOL-RPC portmap CA BrightStor ARCserve udp procedure 191 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
12904SERVER-OTHER Veritas NetBackup vmd shared library buffer overflow attempt (more info ...)attempted-admin 2005-3116 15353  
13552SERVER-OTHER Symantec VERITAS Storage Foundation Suite buffer overflow attempt (more info ...)attempted-admin 2008-0638 25778  URL
13716PROTOCOL-RPC portmap CA BrightStor ARCserve tcp procedure 232 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
13717PROTOCOL-RPC portmap CA BrightStor ARCserve udp procedure 232 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
13800SERVER-OTHER ARCServe LGServer service data overflow attempt (more info ...)attempted-admin 2008-1328 28616  
13805PROTOCOL-RPC portmap CA BrightStor ARCserve tcp procedure 234 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
13806PROTOCOL-RPC portmap CA BrightStor ARCserve udp procedure 234 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
13846SERVER-OTHER Veritas Backup Agent password overflow attempt (more info ...)attempted-admin 2005-0773   
14741SERVER-OTHER Symantec Veritas Foundation Service NULL service authentication attempt (more info ...)attempted-admin 2007-2279   
16071SERVER-OTHER CA ARCServe Backup Discovery Service denial of service attempt (more info ...)attempted-dos 2008-1979 28927  URL
17520SERVER-OTHER CA ARCserve Backup DB Engine Denial of Service (more info ...)protocol-command-decode 2008-4399 31684  
17643SERVER-OTHER CA BrightStor ARCServe logger servie null-pointer dereference attempt (more info ...)attempted-admin 2007-2772   
19890NETBIOS DCERPC NCACN-IP-TCP CA Arcserve Backup directory traversal attempt (more info ...)attempted-admin 2008-4397 31684  
23409BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23410BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23411BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23412BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23413BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23414BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23415BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23416BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23417BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23418BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23419BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23420BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23421BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23422BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23423BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23424BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23425BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23426BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23427BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23428BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23429BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23430BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23431BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
23432BROWSER-PLUGINS Veritas Storage Exec ActiveX clsid access attempt (more info ...)attempted-user 2005-2996 14801  
24639PROTOCOL-RPC portmap CA BrightStor ARCserve tcp procedure 122 invalid function call attempt (more info ...)attempted-admin 2012-2971   URL
28093SERVER-WEBAPP Western Digital Arkeia Appliance directory traversal attempt (more info ...)attempted-admin  62444  
34944POLICY-OTHER Arcserve Unified Data Protection Management credential disclosure attempt (more info ...)policy-violation 2015-4069 74838  URL
37546SERVER-OTHER Veritas NetBackup Volume Manager connection attempt (more info ...)protocol-command-decode    
38350SERVER-OTHER Veritas NetBackup Volume Manager overflow attempt (more info ...)attempted-admin 2006-0989 17264  
43544SERVER-WEBAPP CA ArcServe information disclosure attempt (more info ...)attempted-user 2011-3011   
57532POLICY-OTHER Arcserve Unified Data Protection Management credential disclosure attempt (more info ...)policy-violation 2015-4069 74838  URL
59518SERVER-OTHER ArcServe D2D getNews XXE attempt (more info ...)attempted-user 2020-27868   URL

 goto Top

Group: Server / Misc / TFTP

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Misc / SNMP

# of attack rules in this group: 8

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
16712SERVER-WEBAPP HP OpenView Network Node Manager ovwebsnmpsrv.exe OVwSelection buffer overflow attempt - GET (more info ...)attempted-user  2009-4181  37343    
16713SERVER-WEBAPP HP OpenView Network Node Manager ovwebsnmpsrv.exe OVwSelection buffer overflow attempt - POST (more info ...)attempted-user  2009-4181  37343    
18759SERVER-WEBAPP HP OpenView Network Node Manager ovwebsnmpsrv.exe displayWidth buffer overflow attempt - POST (more info ...)attempted-user  2011-0262  45762    
18760SERVER-WEBAPP HP OpenView Network Node Manager ovwebsnmpsrv.exe displayWidth buffer overflow attempt - GET (more info ...)attempted-user  2011-0262  45762    
18998SERVER-WEBAPP HP OpenView NNM ovwebsnmpsrv.exe command line argument buffer overflow attempt (more info ...)attempted-admin  2011-0261  45762    
26336SERVER-OTHER HP LeftHand Virtual SAN hydra snmp request buffer overflow attempt (more info ...)attempted-admin  2012-3284      URL
31373SERVER-WEBAPP HP OpenView NNM ovwebsnmpsrv.exe command line argument buffer overflow attempt (more info ...)attempted-admin  2011-0261  45762    
36053SERVER-WEBAPP Silver Peak VXOA snmp JSON interface command injection attempt (more info ...)attempted-admin        URL


# of warning rules in this group: 7

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
569PROTOCOL-RPC snmpXdmi overflow attempt TCP (more info ...)attempted-admin 2001-0236 2417 10659 URL
593PROTOCOL-RPC portmap snmpXdmi request TCP (more info ...)rpc-portmap-decode 2001-0236 2417 10659 URL
1279PROTOCOL-RPC portmap snmpXdmi request UDP (more info ...)rpc-portmap-decode 2001-0236 2417 10659 URL
2045PROTOCOL-RPC snmpXdmi overflow attempt UDP (more info ...)attempted-admin 2001-0236 2417 10659 URL
13773OS-LINUX linux kernel snmp nat netfilter memory corruption attempt (more info ...)attempted-dos 2008-1673 18081  URL
26980SERVER-OTHER RealNetworks Helix snmp master agent denial of service attempt (more info ...)attempted-dos 2012-1923 52929  
36493SERVER-OTHER Squid snmphandleUDP off-by-one buffer overflow attempt (more info ...)attempted-dos 2014-6270 69686  URL

 goto Top

Group: Server / Misc / Authentication

# of attack rules in this group: 18

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
12424PROTOCOL-RPC MIT Kerberos kadmind rpc RPCSEC_GSS buffer overflow attempt (more info ...)attempted-admin  2007-3999  25534    URL
17741SERVER-OTHER MIT Kerberos ASN.1 asn1_decode_generaltime uninitialized pointer reference attempt (more info ...)attempted-admin  2009-0846  34409    
27906SERVER-OTHER MIT Kerberos KDC prep_reprocess_req null pointer dereference attempt (more info ...)attempted-admin  2013-1416      URL
31874OS-WINDOWS Microsoft Windows Active Directory kerberos encryption type downgrade attempt (more info ...)attempted-user        URL
33053OS-WINDOWS Microsoft RADIUS Server invalid access-request username denial of service attempt (more info ...)attempted-dos  2016-0050      URL
34971SERVER-OTHER MIT Kerberos KDC as-req sname null pointer dereference attempt (more info ...)attempted-dos  2013-1418  63555    URL
34972SERVER-OTHER MIT Kerberos KDC as-req sname null pointer dereference attempt (more info ...)attempted-dos  2013-1418  63555    URL
35118OS-WINDOWS Microsoft Windows Kerberos privilege escalation attempt (more info ...)attempted-admin  2014-6324  70958    URL
36596OS-WINDOWS Microsoft Windows Kerberos privilege escalation attempt (more info ...)attempted-admin  2014-6324  70958    URL
44085SERVER-OTHER FreeRADIUS invalid WiMAX VSA length out of bounds write attempt (more info ...)attempted-admin  2017-10979  99901    
44293SERVER-OTHER FreeRADIUS data2vp_wimax out of bounds write attempt (more info ...)attempted-admin  2017-10984  99876    URL
56581MALWARE-TOOLS GhostPack Rubeus kerberos request attempt (more info ...)trojan-activity        URL
56582MALWARE-TOOLS GhostPack Rubeus kerberos request attempt (more info ...)trojan-activity        URL
56583MALWARE-TOOLS GhostPack Rubeus kerberos request attempt (more info ...)trojan-activity        URL
56584MALWARE-TOOLS GhostPack Rubeus kerberos request attempt (more info ...)trojan-activity        URL
59144SERVER-OTHER Cisco Identity Services Engine RADIUS denial of service attempt (more info ...)attempted-dos  2022-20756      URL
60377OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt (more info ...)attempted-admin  2022-35756      URL
60378OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt (more info ...)attempted-admin  2022-35756      URL


# of warning rules in this group: 54

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
2578SERVER-OTHER kerberos principal name overflow UDP (more info ...)attempted-admin 2003-0072  11512 URL
2579SERVER-OTHER kerberos principal name overflow TCP (more info ...)attempted-admin 2003-0072  11512 URL
3538SERVER-OTHER RADIUS registration MSID overflow attempt (more info ...)attempted-admin 2005-0699 12759 19120 
3539SERVER-OTHER RADIUS MSID overflow attempt (more info ...)attempted-admin 2005-0699 12759 19120 
3540SERVER-OTHER RADIUS registration vendor ATTR_TYPE_STR overflow attempt (more info ...)attempted-admin 2005-0699 12759 19120 
3541SERVER-OTHER RADIUS ATTR_TYPE_STR overflow attempt (more info ...)attempted-admin 2005-0699 12759 19120 
10464PROTOCOL-TELNET kerberos login environment variable authentication bypass attempt (more info ...)attempted-admin 2007-0956   URL
12046PROTOCOL-RPC MIT Kerberos kadmind RPC Library unix authentication buffer overflow attempt (more info ...)attempted-admin 2007-2443 24657  URL
12075PROTOCOL-RPC MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt (more info ...)attempted-admin 2007-2442 24655  URL
12708PROTOCOL-RPC MIT Kerberos kadmind auth buffer overflow attempt (more info ...)rpc-portmap-decode 2007-2443 24657  URL
13223PROTOCOL-RPC MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt (more info ...)attempted-admin 2007-2442 24655  URL
15169POLICY-SOCIAL XBOX Live Kerberos authentication request (more info ...)policy-violation    URL
16207SERVER-WEBAPP MIT Kerberos V% KAdminD klog_vsyslog server overflow attempt (more info ...)attempted-user 2007-0957 23285  URL
16209SERVER-OTHER FreeRADIUS RADIUS server rad_decode remote denial of service attempt (more info ...)attempted-dos 2009-3111 36263  
16394OS-WINDOWS Active Directory Kerberos referral TGT renewal DoS attempt (more info ...)attempted-dos 2010-0035   URL
17243SERVER-OTHER MIT Kerberos V5 krb5_recvauth double free attempt (more info ...)attempted-admin 2005-1689 14239  URL
17273SERVER-OTHER MIT Kerberos V5 KDC krb5_unparse_name overflow attempt (more info ...)attempted-admin 2005-1174   URL
17274SERVER-OTHER MIT Kerberos V5 KDC krb5_unparse_name overflow attempt (more info ...)attempted-admin 2005-1175   URL
18414OS-WINDOWS Microsoft Windows Kerberos auth downgrade to DES MITM attempt (more info ...)attempted-user 2011-0091   URL
18533SERVER-OTHER MIT Kerberos KDC authentication denial of service attempt (more info ...)attempted-dos 2010-0283 38260  URL
18534SERVER-OTHER MIT Kerberos KDC authentication denial of service attempt (more info ...)attempted-dos 2010-0283 38260  URL
18901SERVER-OTHER MIT Kerberos KDC Ticket validation double free memory corruption attempt (more info ...)attempted-admin 2010-1320 39599  URL
24360OS-WINDOWS Microsoft Windows SMB Kerberos NULL session denial of service attempt (more info ...)attempted-dos 2012-2551   URL
26759SERVER-OTHER MIT Kerberos libkdb_ldap principal name handling denial of service attempt (more info ...)attempted-dos 2011-0282 46271  URL
26769SERVER-OTHER MIT Kerberos kpasswd process_chpw_request denial of service attempt (more info ...)attempted-dos 2011-0285 47310  URL
27193SERVER-OTHER Kerberos KDC null pointer dereference denial of service attempt (more info ...)denial-of-service 2011-0283   URL
27194SERVER-OTHER Kerberos KDC null pointer dereference denial of service attempt (more info ...)denial-of-service 2011-0283   URL
27195SERVER-OTHER Kerberos KDC null pointer dereference denial of service attempt (more info ...)denial-of-service 2011-0283   URL
31764SERVER-OTHER MIT Kerberos KDC TGS request cross-realm referral null pointer dereference denial of service attempt (more info ...)attempted-dos 2009-3295 37486  URL
31765SERVER-OTHER MIT Kerberos KDC TGS request cross-realm referral null pointer dereference denial of service attempt (more info ...)attempted-dos 2009-3295 37486  URL
34709SERVER-OTHER MIT Kerberos 5 krb5_read_message denial of service attempt (more info ...)attempted-dos 2014-5355   URL
36815SERVER-OTHER MIT Kerberos 5 SPNEGO incoming token detected (more info ...)protocol-command-decode 2014-4344   URL
36816SERVER-OTHER MIT Kerberos 5 IAKERB outbound token detected (more info ...)protocol-command-decode 2014-4344   URL
42466SERVER-OTHER WinRadius long password denial of service attempt (more info ...)misc-activity 2012-3816   
45187SERVER-OTHER WinRadius long password denial of service attempt (more info ...)misc-activity 2012-3816   
51085SERVER-OTHER FreeRadius malformed service type field denial of service attempt (more info ...)denial-of-service 2004-0938   
51228SERVER-OTHER FreeRADIUS DHCP string options integer underflow attempt (more info ...)denial-of-service 2017-10986   
51231SERVER-OTHER FreeRADIUS DHCP string options integer underflow attempt (more info ...)denial-of-service 2017-10986   
51232SERVER-OTHER FreeRADIUS DHCP string options integer underflow attempt (more info ...)denial-of-service 2017-10986   
51233SERVER-OTHER FreeRADIUS DHCP string options integer underflow attempt (more info ...)denial-of-service 2017-10986   
52384SERVER-OTHER MIT Kerberos 5 krb5_read_message klogin ksh kprop protocols bad sendauth version string denial of service attempt (more info ...)attempted-dos 2014-5355   
52385SERVER-OTHER MIT Kerberos 5 krb5_read_message klogin protocol bad sendauth or app version length denial of service attempt (more info ...)attempted-dos 2014-5355   
52386SERVER-OTHER MIT Kerberos 5 krb5_read_message klogin ksh kprop protocols bad app version length denial of service attempt (more info ...)attempted-dos 2014-5355   
52387SERVER-OTHER MIT Kerberos 5 krb5_read_message kprop protocol bad sendauth version length denial of service attempt (more info ...)attempted-dos 2014-5355   
52388SERVER-OTHER MIT Kerberos 5 krb5_read_message klogin ksh kprop protocols bad sendauth version string denial of service attempt (more info ...)attempted-dos 2014-5355   
52389SERVER-OTHER MIT Kerberos 5 krb5_read_message klogin ksh kprop protocols bad app version string denial of service attempt (more info ...)attempted-dos 2014-5355   
52391SERVER-OTHER MIT Kerberos 5 krb5_read_message ksh protocol bad sendauth version length denial of service attempt (more info ...)attempted-dos 2014-5355   
52392SERVER-OTHER MIT Kerberos 5 krb5_read_message ksh protocol bad sendauth version length denial of service attempt (more info ...)attempted-dos 2014-5355   
59485SERVER-OTHER MIT Kerberos null pointer dereference attempt (more info ...)attempted-dos 2016-3119   
59615SERVER-OTHER Kerberos cross-realm referrals KDC NULL pointer dereference attempt (more info ...)attempted-dos 2013-1417   
59616SERVER-OTHER Kerberos cross-realm referrals KDC NULL pointer dereference attempt (more info ...)attempted-dos 2013-1417   
59640SERVER-OTHER Kerberos 5 build_principal_va denial of service attempt (more info ...)attempted-dos 2015-2697   
59641SERVER-OTHER Kerberos 5 build_principal_va denial of service attempt (more info ...)attempted-dos 2015-2697   
59747SERVER-OTHER MIT Kerberos Modify Principal null principal denial of service attempt (more info ...)attempted-dos 2015-8630   

 goto Top

Group: Server / Misc / CVS

# of attack rules in this group: 1

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
15971SERVER-OTHER CVS Argumentx command double free attempt (more info ...)attempted-admin  2004-0416  10499    


# of warning rules in this group: 17

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1552SERVER-WEBAPP cvsweb version access (more info ...)web-application-activity 2000-0670  10465 
2008INDICATOR-COMPROMISE CVS invalid user authentication response (more info ...)misc-attack    
2009INDICATOR-COMPROMISE CVS invalid repository response (more info ...)misc-attack    
2010INDICATOR-COMPROMISE CVS double free exploit attempt response (more info ...)misc-attack 2003-0015 6650 11385 
2011INDICATOR-COMPROMISE CVS invalid directory response (more info ...)misc-attack 2003-0015 6650 11385 
2012INDICATOR-COMPROMISE CVS missing cvsroot response (more info ...)misc-attack    
2013INDICATOR-COMPROMISE CVS invalid module response (more info ...)misc-attack    
2317INDICATOR-COMPROMISE CVS non-relative path error response (more info ...)misc-attack 2003-0977 9178 11947 
2318SERVER-OTHER CVS non-relative path access attempt (more info ...)misc-attack 2003-0977 9178 11947 
2583SERVER-OTHER CVS Max-dotdot integer overflow attempt (more info ...)misc-attack 2004-0417 10499  
3651SERVER-OTHER CVS rsh annotate revision overflow attempt (more info ...)attempted-dos 2005-0753 13217 18097 URL
3652SERVER-OTHER CVS pserver annotate revision overflow attempt (more info ...)attempted-dos 2005-0753 13217 18097 URL
13614SERVER-OTHER CVS Argument overflow attempt (more info ...)attempted-admin 2004-0396   
13615SERVER-OTHER CVS Argument overflow attempt (more info ...)attempted-admin 2004-0396   
13616SERVER-OTHER CVS Argument overflow (more info ...)attempted-admin 2004-0396   
20060SERVER-OTHER CVS annotate command buffer overflow attempt (more info ...)attempted-dos 2005-0573 13217  
23402SERVER-WEBAPP CVS remote file information disclosure attempt (more info ...)attempted-recon 2004-0788 10955  

 goto Top

Group: Client

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Client / Office

# of attack rules in this group: 1152

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
7098MALWARE-BACKDOOR remote hack 1.5 runtime detection - get password (more info ...)trojan-activity        URL
8445FILE-OFFICE Microsoft Windows RTF file with embedded object package download attempt (more info ...)misc-activity  2006-4692      URL
10407SERVER-OTHER Helix Server LoadTestPassword buffer overflow attempt (more info ...)attempted-admin  2006-6026  23068    
11835FILE-IDENTIFY Visio file magic detected (more info ...)policy-violation        URL
12283FILE-IDENTIFY Microsoft Office Excel xlw file magic detected (more info ...)misc-activity        URL
13473FILE-IDENTIFY Microsoft Office Publisher file download request (more info ...)misc-activity        URL
15118BROWSER-PLUGINS Microsoft Visual Basic Winsock ActiveX clsid access (more info ...)attempted-user  2008-4251      URL
15120BROWSER-PLUGINS Microsoft Visual Basic Winsock ActiveX function call access (more info ...)attempted-user  2008-4251      URL
15294FILE-IDENTIFY Microsoft Office Visio file download request (more info ...)misc-activity        
15463FILE-IDENTIFY Microsoft Office Excel file download request (more info ...)misc-activity        URL
15586FILE-IDENTIFY Microsoft Office PowerPoint file download request (more info ...)misc-activity        URL
15587FILE-IDENTIFY Microsoft Office Word file download request (more info ...)misc-activity        URL
15975FILE-IMAGE OpenOffice TIFF file in little endian format parsing integer overflow attempt (more info ...)attempted-user  2007-2834  25690    
15976FILE-IMAGE OpenOffice TIFF file in big endian format parsing integer overflow attempt (more info ...)attempted-user  2007-2834  25690    
16216SERVER-OTHER IBM Tivoli Provisioning Manager long URI request buffer overflow attempt (more info ...)attempted-user  2008-0401  27387    
16654FILE-OFFICE Microsoft Office Excel Publisher record heap buffer overflow attempt (more info ...)attempted-user  2012-1886      URL
17295SERVER-WEBAPP Trend Micro OfficeScan Console authentication buffer overflow attempt (more info ...)attempted-admin  2007-3455  24935    
17665FILE-OFFICE OpenOffice Word document table parsing multiple heap based buffer overflow attempt (more info ...)attempted-user  2009-0201  36200    
18066FILE-OFFICE Microsoft Office PowerPoint integer underflow heap corruption attempt (more info ...)attempted-user  2010-2573      URL
18067FILE-OFFICE Microsoft Office RTF parsing remote code execution attempt (more info ...)attempted-user  2010-3333      URL
18200FILE-OFFICE Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user  2012-2524      URL
18310FILE-OFFICE Microsoft Office RTF parsing remote code execution attempt (more info ...)attempted-user  2010-3333      URL
18481SERVER-WEBAPP HP openview network node manager ovlogin.exe buffer overflow - password parameter (more info ...)attempted-admin  2009-4176  37330    URL
18516FILE-IDENTIFY Microsoft Office Word file download request (more info ...)misc-activity        
18546FILE-OFFICE Microsoft Office Word with embedded Flash file transfer (more info ...)attempted-user  2011-0611      URL
18581SERVER-OTHER IBM Tivoli Provisioning Manager long URI request buffer overflow attempt (more info ...)attempted-user  2008-0401  27387    
18582SERVER-OTHER IBM Tivoli Provisioning Manager long URI request buffer overflow attempt (more info ...)attempted-user  2008-0401  27387    
18680FILE-OFFICE Microsoft Office RTF malformed pfragments field (more info ...)attempted-user  2010-3333  44652    URL
18702FILE-OFFICE Microsoft Office RTF malformed pfragments field (more info ...)attempted-user  2010-3333  44652    URL
18703FILE-OFFICE Microsoft Office RTF malformed pfragments field (more info ...)attempted-user  2010-3333  44652    URL
18704FILE-OFFICE Microsoft Office RTF malformed second pfragments field (more info ...)attempted-user  2010-3333  44652    URL
18705FILE-OFFICE Microsoft Office RTF malformed second pfragments field (more info ...)attempted-user  2010-3333  44652    URL
18706FILE-OFFICE Microsoft Office RTF malformed second pfragments field (more info ...)attempted-user  2010-3333  44652    URL
19156FILE-OFFICE Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user  2012-2524      URL
19166FILE-IDENTIFY Microsoft Office Excel file magic detected (more info ...)misc-activity        
19208SERVER-OTHER Citrix Provisioning Services streamprocess.exe buffer overflow attempt (more info ...)attempted-user    45914    URL
20723FILE-IDENTIFY Microsoft Office Word docx file download request (more info ...)misc-activity        URL
20792FILE-IDENTIFY Microsoft Office Excel file attachment detected (more info ...)misc-activity        
20793FILE-IDENTIFY Microsoft Office Excel file attachment detected (more info ...)misc-activity        
20795FILE-IDENTIFY Microsoft Office Word file attachment detected (more info ...)misc-activity        
20796FILE-IDENTIFY Microsoft Office Word file attachment detected (more info ...)misc-activity        
20854FILE-IDENTIFY Microsoft Office Visio file attachment detected (more info ...)misc-activity        
20855FILE-IDENTIFY Microsoft Office Visio file attachment detected (more info ...)misc-activity        
20880FILE-OFFICE Microsoft DirectShow Line 21 decoder exploit attempt (more info ...)attempted-user  2012-0004      URL
20982FILE-IDENTIFY Microsoft Office PowerPoint file attachment detected (more info ...)misc-activity        
20983FILE-IDENTIFY Microsoft Office PowerPoint file attachment detected (more info ...)misc-activity        
20986FILE-IDENTIFY Microsoft Office Word docx file attachment detected (more info ...)misc-activity        
20987FILE-IDENTIFY Microsoft Office Word docx file attachment detected (more info ...)misc-activity        
21011FILE-IDENTIFY Microsoft Office PowerPoint file magic detected (more info ...)misc-activity        
21291FILE-OFFICE Microsoft Office Visio invalid row option attempt (more info ...)attempted-user  2012-0138      URL
21293FILE-OFFICE Microsoft Office Visio corrupted compressed data memory corruption attempt (more info ...)attempted-user  2012-0137      URL
21301FILE-OFFICE Microsoft Office Visio TAG_xxxSect code execution attempt (more info ...)attempted-user  2012-0019      URL
21302FILE-OFFICE Microsoft Office Visio TAG_OLEChunk code execution attempt (more info ...)attempted-user  2012-0020      URL
21307FILE-OFFICE Microsoft Office Visio TAG_xxxSheet code execution attempt (more info ...)attempted-user  2012-0136      URL
21699FILE-IDENTIFY Microsoft Office Excel xlw file attachment detected (more info ...)misc-activity        
21700FILE-IDENTIFY Microsoft Office Excel xlw file attachment detected (more info ...)misc-activity        
21764FILE-OFFICE Microsoft Office Word unicode parsing buffer overflow attempt (more info ...)attempted-user  2004-0963      URL
21794FILE-OFFICE Microsoft Works 9 and Word 12 converter heap overflow attempt (more info ...)attempted-user  2012-0177      URL
21797FILE-OFFICE MSCOMCTL ActiveX control deserialization arbitrary code execution attempt (more info ...)attempted-user  2012-0158      URL
21798FILE-OFFICE MSCOMCTL ActiveX control deserialization arbitrary code execution attempt (more info ...)attempted-user  2012-0158      URL
21799FILE-OFFICE MSCOMCTL ActiveX control deserialization arbitrary code execution attempt (more info ...)attempted-user  2012-0158      URL
21800FILE-OFFICE MSCOMCTL ActiveX control deserialization arbitrary code execution attempt (more info ...)attempted-user  2012-0158      URL
21801FILE-OFFICE MSCOMCTL ActiveX control deserialization arbitrary code execution attempt (more info ...)attempted-user  2012-0158      URL
21884FILE-IDENTIFY Microsoft Office Publisher file attachment detected (more info ...)misc-activity        
21885FILE-IDENTIFY Microsoft Office Publisher file attachment detected (more info ...)misc-activity        
21896FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21897FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21898FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21899FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21900FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21901FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21902FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21903FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21904FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21905FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21906FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
21935FILE-OFFICE Microsoft Works 9 and Word 12 converter heap overflow attempt (more info ...)attempted-user  2012-0177      URL
21937FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
22076FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user  2012-0141      URL
22077FILE-OFFICE Microsoft Office Excel ObjectLink invalid wLinkVar2 value attempt (more info ...)attempted-user  2012-0142  53373    URL
22082FILE-IDENTIFY Microsoft Office PowerPoint pptx file download request (more info ...)misc-activity        URL
22083FILE-IDENTIFY Microsoft Office PowerPoint pptx file attachment detected (more info ...)misc-activity        
22084FILE-IDENTIFY Microsoft Office PowerPoint pptx file attachment detected (more info ...)misc-activity        
22085FILE-OFFICE Microsoft Office GDI+ incorrect index validation of malformed EMF image attempt (more info ...)attempted-user  2012-0165      URL
22086FILE-OFFICE Microsoft Office GDI+ incorrect index validation of malformed EMF image attempt (more info ...)attempted-user  2012-0165      URL
22089FILE-OFFICE Microsoft RTF improper listoverride nesting attempt (more info ...)attempted-user  2012-0183      URL
22091FILE-OFFICE Microsoft Office Excel SXLI record integer overrun attempt (more info ...)attempted-user  2012-0184      URL
22092FILE-OFFICE Microsoft Office Excel SERIES record sdtY memory corruption attempt (more info ...)attempted-user  2012-1847      URL
22093FILE-OFFICE Microsoft Office Excel SERIES record SerAuxTrend sdtX memory corruption attempt (more info ...)attempted-user  2012-1847      URL
22094FILE-OFFICE Microsoft Office Excel SERIES record SerAuxErrBar sdtX memory corruption attempt (more info ...)attempted-user  2012-1847      URL
22101FILE-OFFICE Microsoft Office RTF malformed pfragments field (more info ...)attempted-user  2010-3333  44652    URL
22102FILE-OFFICE Microsoft Office RTF malformed pfragments field (more info ...)attempted-user  2010-3333  44652    URL
23009FILE-OFFICE Microsoft Office Excel SXLI record integer overrun attempt (more info ...)attempted-user  2012-0184      URL
23059FILE-OFFICE Microsoft Office Visio TAG_xxxSect code execution attempt (more info ...)attempted-user  2012-0019      URL
23102POLICY-OTHER Seagate BlackArmor administrator password reset attempt (more info ...)attempted-admin  2012-2568      URL
23305FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
23330PROTOCOL-SCADA ScadaTec Procyon Core server password overflow attempt (more info ...)attempted-user  2011-3322  49480    
23697FILE-IDENTIFY Microsoft Office Excel xlw file magic detected (more info ...)misc-activity        URL
23712FILE-IDENTIFY Microsoft Office Excel file magic detected (more info ...)misc-activity        
23714FILE-IDENTIFY Microsoft Office Publisher file magic detected (more info ...)misc-activity  2006-0001      URL
23751FILE-IDENTIFY Microsoft Office PowerPoint file magic detected (more info ...)misc-activity        
23753FILE-IDENTIFY Visio file magic detected (more info ...)policy-violation        URL
23842FILE-OFFICE Microsoft Office Visio DXF file text overflow attempt (more info ...)attempted-user  2012-1888      URL
23843FILE-OFFICE Microsoft Office Visio DXF file text overflow attempt (more info ...)attempted-user  2012-1888      URL
23956FILE-OFFICE Microsoft Office Visio DXF file text overflow attempt (more info ...)attempted-user  2012-1888      URL
23957FILE-OFFICE Microsoft Office Visio DXF file text overflow attempt (more info ...)attempted-user  2012-1888      URL
23989FILE-OFFICE Microsoft Office EMF image EMFPlusPointF record memory corruption attempt (more info ...)attempted-user  2012-0167      
23992FILE-OFFICE Microsoft Office EMF image EMFPlusPointF record memory corruption attempt (more info ...)attempted-user  2012-0167      
24004FILE-OFFICE Microsoft Office MSCOMCTL ActiveX control tabstrip method access (more info ...)misc-activity        
24005FILE-OFFICE Microsoft Office MSCOMCTL ActiveX control tabstrip method access (more info ...)misc-activity        
24006FILE-OFFICE Microsoft Office MSCOMCTL ActiveX control tabstrip method attempt (more info ...)attempted-user  2013-1313      URL
24351FILE-OFFICE Microsoft Works 9 use-after-free attempt (more info ...)attempted-user  2012-2550      URL
24352FILE-OFFICE Microsoft Works 9 use-after-free attempt (more info ...)attempted-user  2012-2550      URL
24353FILE-OFFICE Microsoft Office Word RTF malformed listid attempt (more info ...)attempted-user  2012-2528      URL
24354FILE-OFFICE Microsoft Office Word RTF malformed listid attempt (more info ...)attempted-user  2012-2528      URL
24357FILE-OFFICE Microsoft Office Word rgfc value overflow attempt (more info ...)attempted-user  2012-0182      URL
24358FILE-OFFICE Microsoft Office Word rgfc value overflow attempt (more info ...)attempted-user  2012-0182      URL
24512SERVER-OTHER Citrix Provisioning Services opcode buffer overflow attempt (more info ...)attempted-user    49803    
24513SERVER-OTHER Citrix Provisioning Services opcode buffer overflow attempt (more info ...)attempted-user    49803    
24520SERVER-WEBAPP Avaya IP Office Customer Call Reporter invalid file upload attempt (more info ...)attempted-admin  2012-3811  54225    URL
24587FILE-OFFICE Microsoft Works Word document use after free attempt (more info ...)attempted-user  2012-2550      
24588FILE-OFFICE Microsoft Works Word document use after free attempt (more info ...)attempted-user  2012-2550      
24657FILE-OFFICE Microsoft Office Excel Publisher record heap buffer overflow attempt (more info ...)attempted-user  2012-1886      URL
24658FILE-OFFICE Microsoft Office Excel SERIES record code execution attempt (more info ...)attempted-user  2012-1885      URL
24659FILE-OFFICE Microsoft Office Excel SERIES record code execution attempt (more info ...)attempted-user  2012-1885      URL
24673FILE-OFFICE Microsoft Office Excel SST record invalid length memory corruption attempt (more info ...)attempted-user  2012-1887  56430    URL
24741SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24742SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24743SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24744SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24745SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24746SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24747SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24748SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24749SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24750SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24751SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24752SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24753SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24754SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24755SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24756SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24757SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24758SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24759SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24760SERVER-OTHER Citrix Provisioning Services multiple opcode integer overflow attempt (more info ...)attempted-user    49803    
24823FILE-OFFICE Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user  2012-2524      URL
24964FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
24965FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
24966FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
24967FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
24968FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
24969FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
24970FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
25293FILE-OFFICE Microsoft Office Excel IPMT record buffer overflow attempt (more info ...)attempted-user  2011-0101      URL
25294FILE-OFFICE Microsoft Office Excel IPMT record buffer overflow attempt (more info ...)attempted-user  2011-0101      URL
25295FILE-OFFICE Microsoft Office Excel IPMT record buffer overflow attempt (more info ...)attempted-user  2011-0101      URL
25296FILE-OFFICE Microsoft Office Excel IPMT record buffer overflow attempt (more info ...)attempted-user  2011-0101      URL
25366FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user  2012-0143  53374    URL
25367FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user  2012-0143  53374    URL
25393FILE-OFFICE Microsoft Office RTF malformed pfragments field (more info ...)attempted-user  2010-3333  44652    URL
26059FILE-IDENTIFY Microsoft Office PowerPoint file magic detected (more info ...)misc-activity        
26060FILE-IDENTIFY Microsoft Office PowerPoint file download request (more info ...)misc-activity        
26061FILE-IDENTIFY Microsoft Office PowerPoint file attachment detected (more info ...)misc-activity        
26062FILE-IDENTIFY Microsoft Office PowerPoint file attachment detected (more info ...)misc-activity        
26063FILE-IDENTIFY Microsoft Office Word docm file download request (more info ...)misc-activity        URL
26064FILE-IDENTIFY Microsoft Office Word docm file attachment detected (more info ...)misc-activity        
26065FILE-IDENTIFY Microsoft Office Word docm file attachment detected (more info ...)misc-activity        
26083FILE-IDENTIFY Microsoft Office Excel file download request (more info ...)misc-activity        
26084FILE-IDENTIFY Microsoft Office Excel file attachment detected (more info ...)misc-activity        
26085FILE-IDENTIFY Microsoft Office Excel file attachment detected (more info ...)misc-activity        
26163FILE-OFFICE Microsoft Office Visio TAG_xxxSheet code execution attempt (more info ...)attempted-user  2013-0079      URL
26164FILE-OFFICE Microsoft Office Visio TAG_xxxSheet code execution attempt (more info ...)attempted-user  2013-0079      URL
26973FILE-OFFICE Microsoft Office Visio TAG_xxxSect code execution attempt (more info ...)attempted-user  2012-0019      URL
27249FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user  2012-0141      URL
27820FILE-OFFICE Microsoft Office Excel PtgMemFunc zero-value cce-field read access violation attempt (more info ...)attempted-user  2013-1315      URL
27821FILE-OFFICE Microsoft Office Excel PtgMemFunc zero-value cce-field read access violation attempt (more info ...)attempted-user  2013-1315      URL
27823SERVER-WEBAPP Microsoft Office SharePoint malicious serialized viewstate evaluation attempt (more info ...)attempted-admin  2013-1330      URL
27824FILE-OFFICE Microsoft Office Excel invalid external defined names read AV attempt (more info ...)attempted-user  2013-3158      URL
27825FILE-OFFICE Microsoft Office Excel invalid external defined names read AV attempt (more info ...)attempted-user  2013-3158      URL
27850FILE-OFFICE Microsoft Office SDTI signed integer underflow attempt (more info ...)attempted-user  2013-3848      URL
27851FILE-OFFICE Microsoft Office SDTI signed integer underflow attempt (more info ...)attempted-user  2013-3848      URL
27852FILE-OFFICE Microsoft Office Word invalid number of cells memory corruption attempt (more info ...)attempted-user  2013-3852      URL
27853FILE-OFFICE Microsoft Office Word invalid number of cells memory corruption attempt (more info ...)attempted-user  2013-3852      URL
27854FILE-OFFICE Microsoft Office Word document invalid cell count memory corruption attempt (more info ...)attempted-user  2013-3856      URL
27855FILE-OFFICE Microsoft Office Word document invalid cell count memory corruption attempt (more info ...)attempted-user  2013-3856      URL
27856FILE-OFFICE Microsoft Office Word document invalid cell count memory corruption attempt (more info ...)attempted-user  2013-3854      URL
27857FILE-OFFICE Microsoft Office Word document invalid cell count memory corruption attempt (more info ...)attempted-user  2013-3854      URL
27858FILE-OFFICE Microsoft Office Word malformed OCXINFO element EoP attempt (more info ...)attempted-user  2013-3850      URL
27859FILE-OFFICE Microsoft Office Word malformed OCXINFO element EoP attempt (more info ...)attempted-user  2013-3850      URL
27862SERVER-WEBAPP Avaya IP Office Customer Call Reporter invalid file upload attempt (more info ...)attempted-admin  2012-3811  54225    URL
27945FILE-OFFICE Microsoft Office Excel ObjectLink invalid wLinkVar2 value attempt (more info ...)attempted-user  2012-0142  53373    URL
28205FILE-OFFICE Microsoft Office Word 2003 macro byte opcode large data structure arbitrary code execution attempt (more info ...)attempted-user  2013-3891      URL
28206FILE-OFFICE Microsoft Office Word 2003 macro byte opcode large data structure arbitrary code execution attempt (more info ...)attempted-user  2013-3891      URL
28331FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28332FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28333FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28334FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28335FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28336FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28337FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28338FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28339FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28340FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28341FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28342FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28343FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
28464FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28465FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28466FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28467FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28468FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28469FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28470FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28471FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28472FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28473FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28497FILE-IDENTIFY WordPerfect file magic detected (more info ...)misc-activity        URL
28498FILE-OTHER Microsoft Word WordPerfect CSTYL border element stack overflow attempt (more info ...)attempted-user  2013-1325      URL
28499FILE-OTHER Microsoft Word WordPerfect CSTYL border element stack overflow attempt (more info ...)attempted-user  2013-1325      URL
28502FILE-OTHER Microsoft Word WordPerfect CSTYL border element stack overflow attempt (more info ...)attempted-user  2013-1324      URL
28503FILE-OTHER Microsoft Word WordPerfect CSTYL border element stack overflow attempt (more info ...)attempted-user  2013-1324      URL
28521FILE-OTHER Microsoft Wordpad embedded BMP overflow attempt (more info ...)attempted-user  2013-3940      URL
28525FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28526FILE-OFFICE Microsoft Office GDI library TIFF handling integer overflow attempt (more info ...)attempted-user  2013-3906  63530    URL
28544FILE-OFFICE Microsoft Office Excel RealTimeData record memory corruption attempt (more info ...)attempted-user  2011-0101      URL
28545FILE-OFFICE Microsoft Office Excel RealTimeData record memory corruption attempt (more info ...)attempted-user  2011-0101      URL
28546FILE-OFFICE Microsoft Office Excel RealTimeData record memory corruption attempt (more info ...)attempted-user  2011-0101      URL
29326FILE-OFFICE Microsoft Office Excel SERIES record sdtY memory corruption attempt (more info ...)attempted-user  2012-1847      URL
29327FILE-OFFICE Microsoft Office Excel SERIES record SerAuxTrend sdtX memory corruption attempt (more info ...)attempted-user  2012-1847      URL
29328FILE-OFFICE Microsoft Office Excel SERIES record SerAuxErrBar sdtX memory corruption attempt (more info ...)attempted-user  2012-1847      URL
29346SERVER-WEBAPP Avaya IP Office Customer Call Reporter cross site scripting attempt (more info ...)web-application-attack        URL
29515PROTOCOL-SCADA ScadaTec Procyon Core server password overflow attempt (more info ...)attempted-user  2011-3322  49480    
29522SERVER-WEBAPP Alcatel-Lucent OmniPCX Office remote code execution attempt (more info ...)attempted-user  2008-1331  25758    
29723FILE-OFFICE Microsoft Office Word invalid sprmPNumRM record (more info ...)attempted-admin  2014-0258      URL
29724FILE-OFFICE Microsoft Office Word invalid sprmPNumRM record (more info ...)attempted-admin  2014-0258      URL
29725FILE-OFFICE Microsoft Office Word invalid sprmPNumRM record (more info ...)attempted-admin  2014-0258      URL
29726FILE-OFFICE Microsoft Office Word invalid sprmPNumRM record (more info ...)attempted-admin  2014-0258      URL
30153FILE-OFFICE Microsoft Windows common controls stack buffer overflow via MIME HTML document attempt (more info ...)attempted-user  2012-0158      URL
30154FILE-OFFICE Microsoft Windows common controls stack buffer overflow via MIME HTML document attempt (more info ...)attempted-user  2012-0158      URL
30155FILE-OFFICE Microsoft Windows common controls stack buffer overflow via MIME HTML document attempt (more info ...)attempted-user  2012-0158      URL
30156FILE-OFFICE Microsoft Windows common controls stack buffer overflow via MIME HTML document attempt (more info ...)attempted-user  2012-0158      URL
30157FILE-OFFICE Microsoft Windows common controls stack buffer overflow via MIME HTML document attempt (more info ...)attempted-user  2012-0158      URL
30158FILE-OFFICE Microsoft Windows common controls stack buffer overflow via MIME HTML document attempt (more info ...)attempted-user  2012-0158      URL
30159FILE-OFFICE Microsoft Windows common controls stack buffer overflow via MIME HTML document attempt (more info ...)attempted-user  2012-0158      URL
30160FILE-OFFICE Microsoft Windows common controls stack buffer overflow via MIME HTML document attempt (more info ...)attempted-user  2012-0158      URL
30161FILE-OFFICE Microsoft Windows common controls stack buffer overflow via malicious MSComctlLib object attempt (more info ...)attempted-user  2012-0158      URL
30163FILE-OFFICE Microsoft Windows common controls stack buffer overflow via malicious MSComctlLib object attempt (more info ...)attempted-user  2012-0158      URL
30164FILE-OFFICE Microsoft Windows common controls stack buffer overflow via malicious MSComctlLib xls object attempt (more info ...)attempted-user  2012-0158      URL
30165FILE-OFFICE Microsoft Windows common controls stack buffer overflow via malicious toolbar and author attempt (more info ...)attempted-user  2012-0158      URL
30166FILE-OFFICE Microsoft Windows common controls stack buffer overflow via malicious toolbar and author attempt (more info ...)attempted-user  2012-0158      URL
30769SERVER-OTHER Wordpress linenity theme LFI attempt (more info ...)attempted-admin    66921    
31341SERVER-WEBAPP Supermicro Intelligent Management Controller password file disclosure attempt (more info ...)attempted-recon        URL
31342SERVER-WEBAPP Supermicro Intelligent Management Controller password file disclosure attempt (more info ...)attempted-recon        URL
31534FILE-OFFICE Microsoft Access memory corruption attempt (more info ...)attempted-user  2013-3155      URL
31535FILE-OFFICE Microsoft Access memory corruption attempt (more info ...)attempted-user  2013-3155      URL
31536FILE-OFFICE Microsoft Access memory corruption attempt (more info ...)attempted-user  2013-3155      URL
31537FILE-OFFICE Microsoft Access memory corruption attempt (more info ...)attempted-user  2013-3155      URL
31926FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
31927FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
32063FILE-OFFICE Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user  2012-2524      URL
32147FILE-OFFICE Microsoft Office Word styleWithEffects use-after-free attempt (more info ...)attempted-user  2014-4117      URL
32148FILE-OFFICE Microsoft Office Word styleWithEffects use-after-free attempt (more info ...)attempted-user  2014-4117      URL
32186FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
32187FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
32313FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
32314FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
32315FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
32316FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
32432FILE-OFFICE Microsoft Office Word lcbPlcffndTxt out-of-bounds attempt (more info ...)attempted-user  2014-6334      URL
32433FILE-OFFICE Microsoft Office Word fcPlfguidUim out-of-bounds attempt (more info ...)attempted-user  2014-6334      URL
32434FILE-OFFICE Microsoft Office Word lcbPlcffndTxt out-of-bounds attempt (more info ...)attempted-user  2014-6334      URL
32435FILE-OFFICE Microsoft Office Word fcPlfguidUim out-of-bounds attempt (more info ...)attempted-user  2014-6334      URL
32477FILE-OFFICE Microsoft Office Word bOffset value overflow attempt (more info ...)attempted-user  2014-6335      URL
32643FILE-OFFICE Microsoft Works 9 and Word 12 converter heap overflow attempt (more info ...)attempted-user  2012-0177      URL
32644FILE-OFFICE Microsoft Works 9 and Word 12 converter heap overflow attempt (more info ...)attempted-user  2012-0177      URL
32683FILE-OFFICE Microsoft Office Excel blip image use after free attempt (more info ...)attempted-user  2014-6360      URL
32684FILE-OFFICE Microsoft Office Excel blip image use after free attempt (more info ...)attempted-user  2014-6360      URL
32687FILE-OFFICE Microsoft Office use after free (more info ...)attempted-user  2014-6364      URL
32688FILE-OFFICE Microsoft Office use after free (more info ...)attempted-user  2014-6364      URL
32707FILE-OFFICE Microsoft Office RTF object use after free attempt (more info ...)attempted-user  2014-6357      URL
32708FILE-OFFICE Microsoft Office RTF object use after free attempt (more info ...)attempted-user  2014-6357      URL
32711FILE-OFFICE Microsoft Office Word array index out-of-bounds attempt (more info ...)attempted-user  2014-6356      URL
32712FILE-OFFICE Microsoft Office Word array index out-of-bounds attempt (more info ...)attempted-user  2014-6356      URL
32718FILE-OFFICE Microsoft Office Excel remote code execution attempt (more info ...)attempted-user  2014-6361      URL
32719FILE-OFFICE Microsoft Office Excel remote code execution attempt (more info ...)attempted-user  2014-6361      URL
32857FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
32858FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
32859FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
32860FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
32861FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
32862FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
32863FILE-OFFICE Microsoft Windows common controls MSCOMCTL.OCX buffer overflow attempt (more info ...)attempted-user  2012-0158      URL
32888INDICATOR-COMPROMISE Potential Redirect from Compromised WordPress site to Fedex - Spammed Malware Download attempt (more info ...)trojan-activity        URL
32962SERVER-WEBAPP Lexmark MarkVision Enterprise GfdFileUploadServlet directory traversal attempt (more info ...)attempted-admin  2014-8741  71623    URL
32963SERVER-WEBAPP Lexmark MarkVision Enterprise GfdFileUploadServlet directory traversal attempt (more info ...)attempted-admin  2014-8741  71623    URL
32964SERVER-WEBAPP Lexmark MarkVision Enterprise GfdFileUploadServlet directory traversal attempt (more info ...)attempted-admin  2014-8741  71623    URL
33275SERVER-WEBAPP WordPress pingback gethostbyname heap buffer overflow attempt (more info ...)web-application-attack  2015-0235  72325    URL
33350FILE-OFFICE Microsoft Office Word wwlib use after free attempt (more info ...)attempted-user  2015-0064      URL
33351FILE-OFFICE Microsoft Office Word wwlib use after free attempt (more info ...)attempted-user  2015-0064      URL
33362FILE-OFFICE Microsoft Office Excel remote exploit attempt (more info ...)attempted-user  2015-0063      URL
33587FILE-OFFICE Microsoft RTF improper listoverride nesting attempt (more info ...)attempted-user  2012-0183      URL
33705FILE-OTHER Microsoft Office RTF out-of-bounds memory access attempt (more info ...)attempted-user  2015-0086      URL
33706FILE-OTHER Microsoft Office RTF out-of-bounds memory access attempt (more info ...)attempted-user  2015-0086      URL
33715FILE-OFFICE Microsoft Office Word incorrect schema property remote code execution attempt (more info ...)attempted-user  2015-0085      URL
33716FILE-OFFICE Microsoft Office Word incorrect schema property remote code execution attempt (more info ...)attempted-user  2015-0085      URL
33826SERVER-SAMBA Samba smbd _netr_ServerPasswordSet deprecated vulnerable function access attempt (more info ...)policy-violation  2015-0240  72711    URL
33934SERVER-WEBAPP Wordpress WP Marketplace plugin directory traversal attempt (more info ...)attempted-recon  2014-9014      
33935SERVER-WEBAPP Wordpress WP Marketplace plugin privilege escalation attempt (more info ...)attempted-admin  2014-9013      
33986POLICY-OTHER ManageEngine Desktop Central insecure admin password reset attempt (more info ...)policy-violation  2015-2560      
34024POLICY-OTHER ManageEngine Desktop Central insecure admin password reset attempt (more info ...)policy-violation  2015-2560      
34055SERVER-WEBAPP Lexmark Markvision Enterprise LibraryFileUploadServlet directory traversal attempt (more info ...)web-application-attack  2014-9375  72726    
34056SERVER-WEBAPP Lexmark Markvision Enterprise LibraryFileUploadServlet directory traversal attempt (more info ...)web-application-attack  2014-9375  72726    
34062FILE-OFFICE Microsoft Office Word document memory corruption attempt (more info ...)attempted-user  2015-1641      URL
34063FILE-OFFICE Microsoft Office Word document memory corruption attempt (more info ...)attempted-user  2015-1641      URL
34066FILE-OFFICE Microsoft Office XML nested num tag double-free attempt (more info ...)attempted-user  2015-1650  74011    URL
34067FILE-OFFICE Microsoft Office XML nested num tag double-free attempt (more info ...)attempted-user  2015-1650  74011    URL
34086FILE-OFFICE Microsoft Office RTF double-free remote code execution attempt (more info ...)attempted-user  2015-1651      URL
34087FILE-OFFICE Microsoft Office RTF double-free remote code execution attempt (more info ...)attempted-user  2015-1651      URL
34093FILE-OFFICE Microsoft Office RTF out-of-bounds array access remote code execution attempt (more info ...)attempted-user  2015-1649      URL
34094FILE-OFFICE Microsoft Office RTF out-of-bounds array access remote code execution attempt (more info ...)attempted-user  2015-1649      URL
34428FILE-OFFICE Microsoft Office Word incorrect ptCount element denial of service attempt (more info ...)denial-of-service  2015-1682      URL
34429FILE-OFFICE Microsoft Office Word incorrect ptCount element denial of service attempt (more info ...)denial-of-service  2015-1682      URL
34737FILE-OFFICE Microsoft Office Word WordPerfect converter ForeignToRtf32 use after free attempt (more info ...)attempted-user  2015-1759      URL
34738FILE-OFFICE Microsoft Office Word WordPerfect converter ForeignToRtf32 use after free attempt (more info ...)attempted-user  2015-1759      URL
34739FILE-OFFICE Microsoft Office Word WordPerfect converter EnumFontFamProc use after free attempt (more info ...)attempted-user  2015-1760      URL
34740FILE-OFFICE Microsoft Office Word WordPerfect converter EnumFontFamProc use after free attempt (more info ...)attempted-user  2015-1760      URL
34743FILE-OFFICE Microsoft Office Word ActiveX object uninitialized memory access attempt (more info ...)attempted-user  2015-1770      URL
34744FILE-OFFICE Microsoft Office Word ActiveX object uninitialized memory access attempt (more info ...)attempted-user  2015-1770      URL
35018FILE-OFFICE Microsoft Office Word nested tblStylePr element use after free attempt (more info ...)attempted-user  2014-4117      URL
35019FILE-OFFICE Microsoft Office Word nested tblStylePr element use after free attempt (more info ...)attempted-user  2014-4117      URL
35020FILE-OFFICE Microsoft Office Word nested tblStylePr element use after free attempt (more info ...)attempted-user  2014-4117      URL
35021FILE-OFFICE Microsoft Office Word nested tblStylePr element use after free attempt (more info ...)attempted-user  2014-4117      URL
35137FILE-OFFICE Microsoft Office Excel out of bounds memory access attempt (more info ...)attempted-user  2015-2376      URL
35138FILE-OFFICE Microsoft Office Excel out of bounds memory access attempt (more info ...)attempted-user  2015-2376      URL
35141FILE-OFFICE Microsoft Office Excel malformed workbook record remote code execution attempt (more info ...)attempted-user  2015-2415      URL
35142FILE-OFFICE Microsoft Office Excel malformed workbook record remote code execution attempt (more info ...)attempted-user  2015-2415      URL
35176FILE-OFFICE Microsoft Office Excel c legend remote code execution attempt (more info ...)attempted-user  2015-2377      URL
35177FILE-OFFICE Microsoft Office Excel c legend remote code execution attempt (more info ...)attempted-user  2015-2377      URL
35190FILE-OFFICE Microsoft Office Word sprmPItap heap corruption attempt (more info ...)attempted-user  2019-1201      URL
35191FILE-OFFICE Microsoft Office Word sprmPItap heap corruption attempt (more info ...)attempted-user  2019-1201      URL
35201FILE-OFFICE Microsoft Office Word OCX use after free attempt (more info ...)attempted-user  2015-2380      URL
35202FILE-OFFICE Microsoft Office Word OCX use after free attempt (more info ...)attempted-user  2015-2380      URL
35325FILE-OFFICE Microsoft Office Word RTF Control.TaskSymbol.1 heap corruption attempt - Win.Trojan.Sofacy (more info ...)trojan-activity  2015-2424      URL
35326FILE-OFFICE Microsoft Office Word RTF Control.TaskSymbol.1 heap corruption attempt - Win.Trojan.Sofacy (more info ...)trojan-activity  2015-2424      URL
35347SERVER-WEBAPP Cisco Unified MeetingPlace password change policy bypass attempt (more info ...)policy-violation  2015-4262      URL
35497FILE-OFFICE Microsoft Office Word Document invalid directory entry use after free attempt (more info ...)attempted-user  2015-2431      URL
35498FILE-OFFICE Microsoft Office Word Document invalid directory entry use after free attempt (more info ...)attempted-user  2015-2431      URL
35501FILE-OFFICE Microsoft Office Word wwlib.dll corrupt fcPlcfFldMom out of bounds read attempt (more info ...)attempted-user  2015-2477  76192    URL
35502FILE-OFFICE Microsoft Office Word wwlib.dll corrupt fcPlcfFldMom out of bounds read attempt (more info ...)attempted-user  2015-2477  76192    URL
35503FILE-OFFICE Microsoft Office Word incomplete ActiveX control use-after-free attempt (more info ...)attempted-user  2015-1642      URL
35504FILE-OFFICE Microsoft Office Word incomplete ActiveX control use-after-free attempt (more info ...)attempted-user  2015-1642      URL
35505FILE-OFFICE Microsoft Office Word mso.dll use-after-free attempt (more info ...)attempted-user  2015-2468      URL
35506FILE-OFFICE Microsoft Office Word mso.dll use-after-free attempt (more info ...)attempted-user  2015-2468      URL
35509FILE-OFFICE Microsoft Office Word wwlib.dll out of bounds read attempt (more info ...)attempted-user  2015-2469      URL
35510FILE-OFFICE Microsoft Office Word wwlib.dll out of bounds read attempt (more info ...)attempted-user  2015-2469      URL
35511FILE-OFFICE Microsoft Office Word msptls.dll integer underflow attempt (more info ...)attempted-user  2015-2470      URL
35512FILE-OFFICE Microsoft Office Word msptls.dll integer underflow attempt (more info ...)attempted-user  2015-2470      URL
35521FILE-OFFICE Microsoft Office Word malformed document file use after free attempt (more info ...)attempted-admin  2015-2467      URL
35522FILE-OFFICE Microsoft Office Word malformed document file use after free attempt (more info ...)attempted-admin  2015-2467      URL
35832FILE-OTHER Hangul Word Processor malicious tab count memory corruption attempt (more info ...)attempted-user  2017-2819      URL
35833FILE-OTHER Hangul Word Processor malicious tab count memory corruption attempt (more info ...)attempted-user  2017-2819      URL
35996FILE-OFFICE Microsoft Office Excel OLESS directory entry type confusion remote code execution attempt (more info ...)attempted-user  2015-2521      URL
35997FILE-OFFICE Microsoft Office Excel OLESS directory entry type confusion remote code execution attempt (more info ...)attempted-user  2015-2521      URL
36000FILE-OFFICE Microsoft Office Excel malformed XF record use after free attempt (more info ...)attempted-user  2015-2523      URL
36001FILE-OFFICE Microsoft Office Excel malformed XF record use after free attempt (more info ...)attempted-user  2015-2523      URL
36002FILE-OFFICE Microsoft Office Excel bad file pointer memory corruption attempt (more info ...)attempted-user  2015-2520      URL
36003FILE-OFFICE Microsoft Office Excel bad file pointer memory corruption attempt (more info ...)attempted-user  2015-2520      URL
36026FILE-OFFICE Microsoft Office Word EPS filter PostScript object use after free attempt (more info ...)attempted-user  2015-2545      URL
36027FILE-OFFICE Microsoft Office Word EPS filter PostScript object use after free attempt (more info ...)attempted-user  2015-2545      URL
36147FILE-OFFICE Microsoft Windows OLE Packer Remote Code Execution attempt (more info ...)attempted-user  2014-6352      URL
36148FILE-OFFICE Microsoft Windows OLE Packer Remote Code Execution attempt (more info ...)attempted-user  2014-6352      URL
36203FILE-OFFICE Microsoft Office Word wwlib.dll corrupt fcPlcfFldMom uninitialized memory access attempt (more info ...)attempted-user  2015-2477  76192    URL
36204FILE-OFFICE Microsoft Office Word wwlib.dll corrupt fcPlcfFldMom uninitialized memory access attempt (more info ...)attempted-user  2015-2477  76192    URL
36244FILE-OFFICE Microsoft Office XML nested num tag double-free attempt (more info ...)attempted-user  2015-1650  74011    URL
36245FILE-OFFICE Microsoft Office XML nested num tag double-free attempt (more info ...)attempted-user  2015-1650  74011    URL
36427FILE-OFFICE Microsoft Visio lmetaclasscount buffer overflow attempt (more info ...)attempted-user  2015-2557      URL
36428FILE-OFFICE Microsoft Visio lmetaclasscount buffer overflow attempt (more info ...)attempted-user  2015-2557      URL
36429FILE-OFFICE Microsoft Office Excel malformed binary format use after free attempt (more info ...)attempted-user  2015-2555      URL
36430FILE-OFFICE Microsoft Office Excel malformed binary format use after free attempt (more info ...)attempted-user  2015-2555      URL
36441FILE-OTHER Visual Basic scripting engine Filter argument mishandling attempt (more info ...)attempted-user  2015-6055      URL
36442FILE-OTHER Visual Basic scripting engine Filter argument mishandling attempt (more info ...)attempted-user  2015-6055      URL
36498FILE-OTHER Microsoft Word WordPerfect CSTYL border element stack overflow attempt (more info ...)attempted-user  2013-1324      URL
36499FILE-OTHER Microsoft Word WordPerfect CSTYL border element stack overflow attempt (more info ...)attempted-user  2013-1324      URL
36500FILE-OTHER Microsoft Word WordPerfect CSTYL border element stack overflow attempt (more info ...)attempted-user  2013-1324      URL
36501FILE-OTHER Microsoft Word WordPerfect CSTYL border element stack overflow attempt (more info ...)attempted-user  2013-1324      URL
36707FILE-OFFICE Microsoft Office malformed odttf integer overflow attempt (more info ...)attempted-user  2015-6093      URL
36708FILE-OFFICE Microsoft Office malformed odttf integer overflow attempt (more info ...)attempted-user  2015-6093      URL
36714FILE-OFFICE Microsoft Office Excel slicer style use-after-free attempt (more info ...)attempted-user  2015-6094      URL
36715FILE-OFFICE Microsoft Office Excel slicer style use-after-free attempt (more info ...)attempted-user  2015-6094      URL
36716FILE-OFFICE Microsoft Office Word PmwdFromDoc use after free attempt (more info ...)attempted-user  2015-6092      URL
36717FILE-OFFICE Microsoft Office Word PmwdFromDoc use after free attempt (more info ...)attempted-user  2015-6092      URL
36720FILE-OFFICE Microsoft Office Word CoCreateInstance elevation of privilege attempt (more info ...)attempted-user  2015-2503      URL
36721FILE-OFFICE Microsoft Office Word CoCreateInstance elevation of privilege attempt (more info ...)attempted-user  2015-2503      URL
36740FILE-OFFICE Microsoft Office Word FGetCpFlowDr memory corruption attempt (more info ...)attempted-user  2015-6091      URL
36741FILE-OFFICE Microsoft Office Word FGetCpFlowDr memory corruption attempt (more info ...)attempted-user  2015-6091      URL
36751FILE-OFFICE Microsoft Office Excel MdCallBack out of bounds read attempt (more info ...)attempted-user  2016-0136      URL
36752FILE-OFFICE Microsoft Office Excel MdCallBack out of bounds read attempt (more info ...)attempted-user  2016-0136      URL
36888FILE-OFFICE Microsoft Office PowerPoint out of bounds value remote code execution attempt (more info ...)attempted-user  2010-0031      URL
36924FILE-OFFICE Microsoft Office Excel MSO reference count use after free attempt (more info ...)attempted-user  2015-6040      URL
36925FILE-OFFICE Microsoft Office Excel MSO reference count use after free attempt (more info ...)attempted-user  2015-6040      URL
36930FILE-OFFICE Microsoft Office request for wuaext.dll over SMB attempt (more info ...)attempted-user  2015-6133      URL
36931FILE-OFFICE Microsoft Office wuaext.dll dll-load exploit attempt (more info ...)attempted-user  2015-6133      URL
36934FILE-OFFICE Microsoft Office Word pointer release validation use after free attempt (more info ...)attempted-user  2015-6118      URL
36935FILE-OFFICE Microsoft Office Word pointer release validation use after free attempt (more info ...)attempted-user  2015-6118      URL
36958FILE-OFFICE Microsoft Office Excel StyleXF invalid icvXF out of bounds read attempt (more info ...)attempted-user  2015-6122      URL
36959FILE-OFFICE Microsoft Office Excel StyleXF invalid icvXF out of bounds read attempt (more info ...)attempted-user  2015-6122      URL
36960FILE-OFFICE Microsoft Office Word XML parsing use after free attempt (more info ...)attempted-user  2015-6124      URL
36961FILE-OFFICE Microsoft Office Word XML parsing use after free attempt (more info ...)attempted-user  2015-6124      URL
36964FILE-OFFICE Microsoft Office Word gdiplus integer overflow attempt (more info ...)attempted-user  2015-6107      URL
36965FILE-OFFICE Microsoft Office Word gdiplus integer overflow attempt (more info ...)attempted-user  2015-6107      URL
36966FILE-OFFICE Microsoft Office Word OGL module out of bounds read attempt (more info ...)attempted-user  2015-6106      URL
36967FILE-OFFICE Microsoft Office Word OGL module out of bounds read attempt (more info ...)attempted-user  2015-6106      URL
36974FILE-OFFICE Microsoft Office Excel out of bounds read attempt (more info ...)attempted-user  2015-6177      URL
36975FILE-OFFICE Microsoft Office Excel out of bounds read attempt (more info ...)attempted-user  2015-6177      URL
36993FILE-OFFICE Microsoft Office request for mqrt.dll over SMB attempt (more info ...)attempted-user  2015-6132      URL
36994FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user  2015-6132      URL
36995FILE-OFFICE Microsoft Office request for spframe.dll over SMB attempt (more info ...)attempted-user  2015-6132      URL
36996FILE-OFFICE Microsoft Office spframe.dll dll-load exploit attempt (more info ...)attempted-user  2015-6132      URL
36999FILE-OFFICE Microsoft Office elsext.dll dll-load exploit attempt (more info ...)attempted-user  2015-6128      URL
37000FILE-OFFICE Microsoft Office nwdblib.dll dll-load exploit attempt (more info ...)attempted-user  2015-6128      URL
37001FILE-OFFICE Microsoft Office request for elsext.dll over SMB attempt (more info ...)attempted-user  2015-6128      URL
37002FILE-OFFICE Microsoft Office request for nwdblib.dll over SMB attempt (more info ...)attempted-user  2015-6128      URL
37011FILE-OFFICE Microsoft Office Outlook embedded OLE object sandbox bypass attempt (more info ...)attempted-user  2015-6172      URL
37013FILE-OFFICE Microsoft Office Outlook embedded OLE object sandbox bypass attempt (more info ...)attempted-user  2015-6172      URL
37018SERVER-WEBAPP wordpress kses bypass cross site scripting attempt (more info ...)attempted-user  2015-5714      
37019SERVER-WEBAPP wordpress kses bypass cross site scripting attempt (more info ...)attempted-user  2015-5714      
37120FILE-OFFICE Microsoft Office Outlook embedded OLE object sandbox bypass attempt (more info ...)attempted-user  2015-6172      URL
37243INDICATOR-COMPROMISE download of a Office document with embedded PowerShell (more info ...)trojan-activity        URL
37244INDICATOR-COMPROMISE download of a Office document with embedded PowerShell (more info ...)trojan-activity        URL
37259FILE-OFFICE Microsoft Office Excel mso20win32client use after free attempt (more info ...)attempted-user  2016-0035      URL
37260FILE-OFFICE Microsoft Office Excel mso20win32client use after free attempt (more info ...)attempted-user  2016-0035      URL
37261FILE-OFFICE Microsoft Office request for mfplat.dll over SMB attempt (more info ...)attempted-user  2016-0016      URL
37262FILE-OFFICE Microsoft Office mfplat.dll dll-load exploit attempt (more info ...)attempted-user  2016-0016      URL
37263FILE-OFFICE Microsoft Office request for api-ms-win-core-winrt-l1-1-0.dll over SMB attempt (more info ...)attempted-user  2016-0018      URL
37264FILE-OFFICE Microsoft Office api-ms-win-core-winrt-l1-1-0.dll dll-load exploit attempt (more info ...)attempted-user  2016-0018      URL
37265FILE-OFFICE Microsoft Office metafile conversion out of bounds read attempt (more info ...)attempted-user  2016-0008      URL
37266FILE-OFFICE Microsoft Office metafile conversion out of bounds read attempt (more info ...)attempted-user  2016-0008      URL
37274FILE-OFFICE Microsoft Office RTF parser heap overflow attempt (more info ...)attempted-user  2016-0010      URL
37358SERVER-WEBAPP Cisco Identity Services Engine default password authentication attempt (more info ...)attempted-admin  2015-6323      URL
37409FILE-OFFICE Microsoft Office Word ActiveX object uninitialized memory access attempt (more info ...)attempted-user  2015-1770      URL
37410FILE-OFFICE Microsoft Office Word ActiveX object uninitialized memory access attempt (more info ...)attempted-user  2015-1770      URL
37555FILE-OFFICE Microsoft Office msdaora.dll dll-load exploit attempt (more info ...)attempted-user  2016-0041      URL
37557FILE-OFFICE Microsoft Office request for msdaora.dll over SMB attempt (more info ...)attempted-user  2016-0041      URL
37558FILE-OFFICE Microsoft Office request for phoneinfo.dll over SMB attempt (more info ...)attempted-user  2016-0041      URL
37559FILE-OFFICE Microsoft Office Word rtf file ffdefres integer underflow attempt (more info ...)attempted-user  2016-0053      URL
37560FILE-OFFICE Microsoft Office Word rtf file ffdefres integer underflow attempt (more info ...)attempted-user  2016-0053      URL
37561FILE-OFFICE Microsoft Office Word missing dpinfo structure integer overflow attempt (more info ...)attempted-user  2016-0022      URL
37563FILE-OFFICE Microsoft Office Word missing dpinfo structure integer overflow attempt (more info ...)attempted-user  2016-0022      URL
37564FILE-OFFICE Microsoft Office Word missing dpinfo structure integer overflow attempt (more info ...)attempted-user  2016-0022      URL
37579FILE-OFFICE Microsoft Powerpoint shape object null pointer dereference attempt (more info ...)attempted-user  2016-0055      URL
37580FILE-OFFICE Microsoft Powerpoint shape object null pointer dereference attempt (more info ...)attempted-user  2016-0055      URL
37588FILE-OFFICE Microsoft Office Word BCSRuntime.dll dll-load exploit attempt (more info ...)attempted-user  2016-0042      URL
37589FILE-OFFICE Microsoft Office Word OLMAPI32.dll dll-load exploit attempt (more info ...)attempted-user  2016-0042      URL
37590FILE-OFFICE Microsoft Office Word request for BCSRuntime.dll over SMB attempt (more info ...)attempted-user  2016-0042      URL
37591FILE-OFFICE Microsoft Office Word request for OLMAPI32.dll over SMB attempt (more info ...)attempted-user  2016-0042      URL
37592FILE-OFFICE Microsoft Office Excel formula length heap corruption attempt (more info ...)attempted-user  2016-0054      URL
37593FILE-OFFICE Microsoft Office Excel formula length heap corruption attempt (more info ...)attempted-user  2016-0054      URL
37598FILE-OFFICE Microsoft Office Word external document access use-after-free attempt (more info ...)attempted-user  2016-0056      URL
37599FILE-OFFICE Microsoft Office Word external document access use-after-free attempt (more info ...)attempted-user  2016-0056      URL
37600FILE-OFFICE Microsoft Powerpoint shape objects null pointer dereference memory corruption attempt (more info ...)attempted-user  2016-0056      URL
37601FILE-OFFICE Microsoft Powerpoint shape objects null pointer dereference memory corruption attempt (more info ...)attempted-user  2016-0056      URL
37606FILE-OFFICE Microsoft Office Word rtf file bitmap width integer overflow attempt (more info ...)attempted-user  2016-0052      URL
37607FILE-OFFICE Microsoft Office Word rtf file bitmap width integer overflow attempt (more info ...)attempted-user  2016-0052      URL
37700FILE-OFFICE Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37701FILE-OFFICE Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37702FILE-OFFICE Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37703FILE-OFFICE Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37704FILE-OFFICE Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37705FILE-OFFICE Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37706FILE-OFFICE Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37707FILE-OFFICE Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37726FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37727FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37824FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37825FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
37975FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37976FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37977FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37978FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37979FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37980FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
37981FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37982FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
37983FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37984FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
37985FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37986FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37987FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
37988FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37989FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37990FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37991FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
37992FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37993FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537  56839    URL
37994FILE-OFFICE Microsoft Office dpnet.dll DirectPlay CFixedPool-Get clsid access (more info ...)attempted-dos  2012-1537      URL
38100FILE-OFFICE Microsoft Office Word wwlib.dll invalid pointer read attempt (more info ...)attempted-user  2016-0134      URL
38101FILE-OFFICE Microsoft Office Word wwlib.dll invalid pointer read attempt (more info ...)attempted-user  2016-0134      URL
38111FILE-OFFICE Microsoft Office Word bitmap stream parsing remote code execution attempt (more info ...)attempted-user  2016-0092      URL
38126FILE-OFFICE Microsoft Office Word ipdesign.dll ActiveX object access attempt (more info ...)attempted-user  2016-0021      URL
38127FILE-OFFICE Microsoft Office Word ipdesign.dll ActiveX object access attempt (more info ...)attempted-user  2016-0021      URL
38128FILE-OFFICE Microsoft Office Word ipdesign.dll ActiveX object access attempt (more info ...)attempted-user  2016-0021      URL
38129FILE-OFFICE Microsoft Office Word ipdesign.dll ActiveX object access attempt (more info ...)attempted-user  2016-0021      URL
38471FILE-OFFICE Microsoft Office Excel sheet object use after free attempt (more info ...)attempted-user  2016-0139      URL
38472FILE-OFFICE Microsoft Office Excel sheet object use after free attempt (more info ...)attempted-user  2016-0139      URL
38481FILE-OFFICE Microsoft Office Excel msxml6 ParseElementN use after free attempt (more info ...)attempted-user  2016-0122      URL
38482FILE-OFFICE Microsoft Office Excel msxml6 ParseElementN use after free attempt (more info ...)attempted-user  2016-0122      URL
38489FILE-OFFICE Microsoft Office Word OleRegEnumVerbs object icon memory corruption attempt (more info ...)attempted-user  2016-0153      URL
38490FILE-OFFICE Microsoft Office Word OleRegEnumVerbs object icon memory corruption attempt (more info ...)attempted-user  2016-0153      URL
38495FILE-OFFICE Microsoft Office Word out of bound read exception attempt (more info ...)attempted-user  2016-0127      URL
38496FILE-OFFICE Microsoft Office Word out of bound read exception attempt (more info ...)attempted-user  2016-0127      URL
38580FILE-OFFICE RFT document malformed header (more info ...)attempted-user  2015-1641      URL
38581FILE-OFFICE RFT document malformed header (more info ...)attempted-user  2015-1641      URL
38639FILE-OFFICE Microsoft Office document with auto-start VBA macro detected (more info ...)attempted-user        
38640FILE-OFFICE Microsoft Office document with auto-start VBA macro detected (more info ...)attempted-user        
38742FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin  2014-6352      URL
38782FILE-OFFICE Microsoft Office Word TTF out-of-bounds memory access attempt (more info ...)attempted-user  2016-0126      URL
38783FILE-OFFICE Microsoft Office Word TTF out-of-bounds memory access attempt (more info ...)attempted-user  2016-0126      URL
38811FILE-OFFICE Microsoft Office wwlib out of bounds memory access attempt (more info ...)attempted-recon  2016-0183      URL
38812FILE-OFFICE Microsoft Office wwlib out of bounds memory access attempt (more info ...)attempted-recon  2016-0183      URL
38813FILE-OFFICE Microsoft Office wwlib out of bounds memory access attempt (more info ...)attempted-recon  2016-0183      URL
38814FILE-OFFICE Microsoft Office wwlib out of bounds memory access attempt (more info ...)attempted-recon  2016-0183      URL
38815FILE-OFFICE Microsoft Office wwlib out of bounds memory access attempt (more info ...)attempted-recon  2016-0183      URL
38862FILE-IDENTIFY Hancom Hangul Office Document file download request (more info ...)misc-activity        
38863FILE-IDENTIFY Hancom Hangul Office Document file attachment detected (more info ...)misc-activity        
38864FILE-IDENTIFY Hancom Hangul Office Document file attachment detected (more info ...)misc-activity        
38865FILE-IDENTIFY Hancom Hangul Office Document file magic detected (more info ...)misc-activity        
38866FILE-IDENTIFY Hancom Hangul Office Document file magic detected (more info ...)misc-activity        
38868FILE-OTHER Hancom Hangul Office HShow integer-based heap buffer overflow attempt (more info ...)attempted-user  2016-4298      URL
38869FILE-OTHER Hancom Hangul Office HShow integer-based heap buffer overflow attempt (more info ...)attempted-user  2016-4298      URL
39036FILE-OFFICE RTF file with embedded OLE object itself embedding a Flash file (more info ...)policy-violation        URL
39037FILE-OFFICE RTF file with embedded OLE object itself embedding a Flash file (more info ...)policy-violation        URL
39148FILE-OFFICE Document Foundation LibreOffice RTF stylesheet use after free attempt (more info ...)attempted-user  2016-4324      URL
39149FILE-OFFICE Document Foundation LibreOffice RTF stylesheet use after free attempt (more info ...)attempted-user  2016-4324      URL
39203FILE-OFFICE Microsoft Office Word wwlib.dll out of bounds read attempt (more info ...)attempted-user  2016-3234      URL
39204FILE-OFFICE Microsoft Office Word wwlib.dll out of bounds read attempt (more info ...)attempted-user  2016-3234      URL
39221FILE-OFFICE Microsoft Office Word mso.dll subcomponent use after free attempt (more info ...)attempted-user  2016-0025      URL
39222FILE-OFFICE Microsoft Office Word mso.dll subcomponent use after free attempt (more info ...)attempted-user  2016-0025      URL
39223FILE-OFFICE Microsoft Office Excel malformed XLS out of bounds memory read attempt (more info ...)attempted-user  2016-3233      URL
39224FILE-OFFICE Microsoft Office Excel malformed XLS out of bounds memory read attempt (more info ...)attempted-user  2016-3233      URL
39349SERVER-WEBAPP Wordpress Mobile Detector Plugin remote file upload attempt (more info ...)web-application-attack        URL
39350SERVER-WEBAPP Wordpress Mobile Detector Plugin remote file upload attempt (more info ...)web-application-attack        URL
39417FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39418FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39419FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39420FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39421FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39422FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39423FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39424FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39425FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39426FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39427FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39428FILE-OFFICE Symantec multiple product Dec2SS PowerPoint file buffer overflow attempt (more info ...)attempted-user  2016-2209      URL
39503FILE-OFFICE Microsoft Office Word wwlib out-of-bounds memory access attempt (more info ...)attempted-user  2016-3281      URL
39504FILE-OFFICE Microsoft Office Word wwlib out-of-bounds memory access attempt (more info ...)attempted-user  2016-3281      URL
39518FILE-OFFICE Microsoft Office Word wwlib out of bounds memory access attempt (more info ...)attempted-user  2016-3280      URL
39519FILE-OFFICE Microsoft Office Word wwlib out of bounds memory access attempt (more info ...)attempted-user  2016-3280      URL
39520FILE-OFFICE Microsoft Office Word unsupported XML schema out of bounds read attempt (more info ...)attempted-user  2016-3282      URL
39521FILE-OFFICE Microsoft Office Word unsupported XML schema out of bounds read attempt (more info ...)attempted-user  2016-3282      URL
39522FILE-OFFICE Microsoft Office Word unsupported XML schema out of bounds read attempt (more info ...)attempted-user  2016-3282      URL
39523FILE-OFFICE Microsoft Office Word unsupported XML schema out of bounds read attempt (more info ...)attempted-user  2016-3282      URL
39524FILE-OFFICE Microsoft Office Excel empty bookViews element denial of service attempt (more info ...)attempted-dos  2016-3284      URL
39525FILE-OFFICE Microsoft Office Excel empty bookViews element denial of service attempt (more info ...)attempted-dos  2016-3284      URL
39526FILE-OFFICE RTF document incorrect file magic attempt (more info ...)attempted-user  2015-1641      URL
39527FILE-OFFICE RTF document incorrect file magic attempt (more info ...)attempted-user  2015-1641      URL
39528FILE-OFFICE Microsoft Office RTF WRAssembly ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
39529FILE-OFFICE Microsoft Office RTF WRAssembly ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
39817FILE-OFFICE Microsoft Office Word sprmSDyaTop memory leak attempt (more info ...)attempted-user  2016-3316      URL
39831FILE-OFFICE Microsoft Office Word wwlib out of bounds read attempt (more info ...)attempted-recon  2016-3317      URL
39832FILE-OFFICE Microsoft Office Word wwlib out of bounds read attempt (more info ...)attempted-recon  2016-3317      URL
39835FILE-OFFICE Microsoft Office Word malformed jpeg memory corruption attempt (more info ...)attempted-admin  2016-3318      URL
39836FILE-OFFICE Microsoft Office Word malformed jpeg memory corruption attempt (more info ...)attempted-admin  2016-3318      URL
39837FILE-OFFICE Microsoft Office mso.dll out of bounds memory access attempt (more info ...)attempted-user  2016-3313      URL
39838FILE-OFFICE Microsoft Office mso.dll out of bounds memory access attempt (more info ...)attempted-user  2016-3313      URL
39868FILE-OFFICE LexMark Perceptive Document Filters msofbtCLSID stack buffer overflow attempt (more info ...)attempted-user        URL
39869FILE-OFFICE LexMark Perceptive Document Filters msofbtCLSID stack buffer overflow attempt (more info ...)attempted-user        URL
39871FILE-OFFICE LexMark Perceptive Document Filters wSectorShift heap buffer overflow attempt (more info ...)attempted-user        URL
39872FILE-OFFICE LexMark Perceptive Document Filters wSectorShift heap buffer overflow attempt (more info ...)attempted-user        URL
39881INDICATOR-COMPROMISE Meteocontrol WEBlog config containing passwords download attempt (more info ...)web-application-attack  2016-2296      
39925SERVER-WEBAPP WordPress pingback gethostbyname heap buffer overflow attempt (more info ...)web-application-attack  2015-0235  72325    URL
40075FILE-OFFICE Microsoft Office Excel LPenHelper out of bounds write attempt (more info ...)attempted-user  2016-3365      URL
40076FILE-OFFICE Microsoft Office Excel LPenHelper out of bounds write attempt (more info ...)attempted-user  2016-3365      URL
40079FILE-OFFICE Microsoft Office Visio visdlgu.dll dll-load exploit attempt (more info ...)attempted-user  2016-3364      URL
40080FILE-OFFICE Microsoft Office Visio request for visdlgu.dll over SMB attempt (more info ...)attempted-user  2016-3364      URL
40082FILE-OFFICE Microsoft Office Excel Ordinal43 out of bounds read attempt (more info ...)attempted-user  2016-3363      URL
40083FILE-OFFICE Microsoft Office Excel Ordinal43 out of bounds read attempt (more info ...)attempted-user  2016-3363      URL
40102FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3358      URL
40103FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3358      URL
40104FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3358      URL
40105FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3358      URL
40106FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3359      URL
40107FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3359      URL
40116FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3362      URL
40117FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3362      URL
40118FILE-IDENTIFY Microsoft Excel XLSB file download request (more info ...)misc-activity        
40119FILE-IDENTIFY Microsoft Excel XLSB file attachment detected (more info ...)misc-activity        
40120FILE-IDENTIFY Microsoft Excel XLSB file attachment detected (more info ...)misc-activity        
40121FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3381      URL
40122FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-admin  2016-3381      URL
40143FILE-OFFICE Microsoft PowerPoint bogus JPEG marker length heap buffer overflow (more info ...)attempted-user  2016-3357      URL
40147FILE-OFFICE Microsoft Office PowerPoint ppcore invalid pointer reference attempt (more info ...)attempted-user  2016-3360      URL
40148FILE-OFFICE Microsoft Office PowerPoint ppcore invalid pointer reference attempt (more info ...)attempted-user  2016-3360      URL
40281FILE-OFFICE Microsoft Office Wordpad font conversion buffer overflow attempt (more info ...)attempted-admin  2004-0901      
40282FILE-OFFICE Microsoft Office Wordpad font conversion buffer overflow attempt (more info ...)attempted-admin  2004-0901      
40287SERVER-OTHER Cisco prime collaboration provisioning web framework access control bypass attempt (more info ...)attempted-admin  2015-4307      URL
40368FILE-OFFICE Microsoft Office Word RTF file parsing buffer overflow attempt (more info ...)attempted-user  2016-7193      URL
40369FILE-OFFICE Microsoft Office Word RTF file parsing buffer overflow attempt (more info ...)attempted-user  2016-7193      URL
40459FILE-OFFICE Microsoft Office Excel malicious cce value following a PtgMemFunc token (more info ...)attempted-user  2013-1315      URL
40460FILE-OFFICE Microsoft Office Excel malicious cce value following a PtgMemFunc token (more info ...)attempted-user  2013-1315      URL
40490FILE-OFFICE JustSystems Ichitaro Word Processor malformed PersistDirectory memory corruption attempt (more info ...)attempted-user  2017-2791      URL
40491FILE-OFFICE JustSystems Ichitaro Word Processor malformed PersistDirectory memory corruption attempt (more info ...)attempted-user  2017-2791      URL
40575FILE-PDF Adobe Acrobat Reader XFA excelGroup memory corruption attempt (more info ...)attempted-user  2016-6950      URL
40576FILE-PDF Adobe Acrobat Reader XFA excelGroup memory corruption attempt (more info ...)attempted-user  2016-6950      URL
40620FILE-OFFICE Microsoft Office RTF WRAssembly CLSID ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40621FILE-OFFICE Microsoft Office RTF WRLoader ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40622FILE-OFFICE Microsoft Office RTF WRLoader CLSID ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40623FILE-OFFICE Microsoft Office RTF hex encoded WRLoader ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40624FILE-OFFICE Microsoft Office RTF hex encoded wrLoader ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40625FILE-OFFICE Microsoft Office RTF WRAssembly CLSID ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40626FILE-OFFICE Microsoft Office RTF WRLoader ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40627FILE-OFFICE Microsoft Office RTF WRLoader CLSID ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40628FILE-OFFICE Microsoft Office RTF hex encoded WRAsembly ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40629FILE-OFFICE Microsoft Office RTF hex encoded WRAssembly ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40630FILE-OFFICE Microsoft Office RTF hex encoded WRLoader ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40631FILE-OFFICE Microsoft Office RTF hex encoded wrLoader ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40632FILE-OFFICE Microsoft Office RTF hex encoded WRAssembly CLSID ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40633FILE-OFFICE Microsoft Office RTF hex encoded WRLoader CLSID ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40634FILE-OFFICE Microsoft Office RTF hex encoded WRAssembly CLSID ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40635FILE-OFFICE Microsoft Office RTF hex encoded WRLoader CLSID ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
40667FILE-OFFICE Microsoft Office Word PrcData out of bounds read attempt (more info ...)attempted-user  2016-7232      URL
40668FILE-OFFICE Microsoft Office Word PrcData out of bounds read attempt (more info ...)attempted-user  2016-7232      URL
40673FILE-OFFICE Microsoft Office Word wwlib out of bounds read attempt (more info ...)attempted-user  2016-7235      URL
40674FILE-OFFICE Microsoft Office Word wwlib out of bounds read attempt (more info ...)attempted-user  2016-7235      URL
40679FILE-OFFICE Microsoft Office Word wwlib out of bounds read attempt (more info ...)attempted-user  2016-7233      URL
40680FILE-OFFICE Microsoft Office Word wwlib out of bounds read attempt (more info ...)attempted-user  2016-7233      URL
40681FILE-OFFICE Microsoft PowerPoint ntdll out of bounds read attempt (more info ...)attempted-user  2016-7230      URL
40682FILE-OFFICE Microsoft PowerPoint ntdll out of bounds read attempt (more info ...)attempted-user  2016-7230      URL
40701FILE-OFFICE Microsoft Office Word out of bounds memory read attempt (more info ...)attempted-admin  2016-7234      URL
40702FILE-OFFICE Microsoft Office Word out of bounds memory read attempt (more info ...)attempted-admin  2016-7234      URL
40711FILE-OFFICE Microsoft Office 2016 arbitrary pointer dereference vulnerability attempt (more info ...)attempted-user  2016-7228      URL
40712FILE-OFFICE Microsoft Office 2016 arbitrary pointer dereference vulnerability attempt (more info ...)attempted-user  2016-7228      URL
40717FILE-OFFICE Microsoft Office Excel LPenHelper use after free attempt (more info ...)attempted-user  2016-7236      URL
40718FILE-OFFICE Microsoft Office Excel LPenHelper use after free attempt (more info ...)attempted-user  2016-7236      URL
40719FILE-OFFICE Microsoft Office Excel SST record use after free attempt (more info ...)attempted-user  2016-7213      URL
40720FILE-OFFICE Microsoft Office Excel SST record use after free attempt (more info ...)attempted-user  2016-7213      URL
40723FILE-OFFICE Microsoft Office Excel Viewer remote code execution attempt (more info ...)attempted-user  2016-7231      URL
40724FILE-OFFICE Microsoft Office Excel Viewer remote code execution attempt (more info ...)attempted-user  2016-7231      URL
40725FILE-OFFICE Microsoft Office Excel invalid signed integer attempt (more info ...)attempted-user  2016-7229      URL
40726FILE-OFFICE Microsoft Office Excel invalid signed integer attempt (more info ...)attempted-user  2016-7229      URL
40727FILE-OTHER Microsoft Office RTF out-of-bounds memory access attempt (more info ...)attempted-user  2015-0086      URL
40728FILE-OTHER Microsoft Office RTF out-of-bounds memory access attempt (more info ...)attempted-user  2015-0086      URL
40883SERVER-WEBAPP WordPress XMLRPC pingback ddos attempt (more info ...)web-application-attack  2013-0235      URL
40917FILE-PDF Iceni Argus PDF uninitialized WordStyle color length code overflow attempt (more info ...)attempted-user  2016-8385      URL
40918FILE-PDF Iceni Argus PDF uninitialized WordStyle color length code overflow attempt (more info ...)attempted-user  2016-8385      URL
40927FILE-OFFICE AntennaHouse HTMLFilter Doc_SetSummary remote code execution attempt (more info ...)attempted-user  2016-8382      URL
40928FILE-OFFICE AntennaHouse HTMLFilter Doc_SetSummary remote code execution attempt (more info ...)attempted-user  2016-8382      URL
40929FILE-OFFICE AntennaHouse HTMLFilter GetFontTable remote code execution attempt (more info ...)attempted-user  2016-8383      URL
40930FILE-OFFICE AntennaHouse HTMLFilter GetFontTable remote code execution attempt (more info ...)attempted-user  2016-8383      URL
40931FILE-OFFICE AntennaHouse HTMLFilter DHFSummary remote code execution attempt (more info ...)attempted-user  2016-8384      URL
40932FILE-OFFICE AntennaHouse HTMLFilter DHFSummary remote code execution attempt (more info ...)attempted-user  2016-8384      URL
40938FILE-OFFICE Microsoft Office PowerPoint OpenType font overly large instructionLength out of bounds read attempt (more info ...)attempted-user  2016-7276      URL
40939FILE-OFFICE Microsoft Office PowerPoint OpenType font overly large instructionLength out of bounds read attempt (more info ...)attempted-user  2016-7276      URL
40945FILE-OFFICE Microsoft Office Excel CrtMlFrt record out of bounds read attempt (more info ...)attempted-user  2016-7264      URL
40951FILE-OFFICE Microsoft Office Word XST structure out of bounds read attempt (more info ...)attempted-user  2016-7268      URL
40952FILE-OFFICE Microsoft Office Word XST structure out of bounds read attempt (more info ...)attempted-user  2016-7268      URL
40957FILE-OFFICE Microsoft Office Excel security descriptor out of bounds read attempt (more info ...)attempted-user  2016-7265      URL
40958FILE-OFFICE Microsoft Office Excel security descriptor out of bounds read attempt (more info ...)attempted-user  2016-7265      URL
40959FILE-OFFICE Microsoft Office Excel ddeService command execution attempt (more info ...)attempted-user  2016-7262      URL
40960FILE-OFFICE Microsoft Office Excel ddeService command execution attempt (more info ...)attempted-user  2016-7262      URL
40962FILE-OTHER Microsoft Office OLE DLL side load attempt (more info ...)attempted-user  2016-7275      URL
40963FILE-OFFICE Microsoft Office Excel type confusion attempt (more info ...)attempted-user  2016-7277      URL
40964FILE-OFFICE Microsoft Office Excel type confusion attempt (more info ...)attempted-user  2016-7277      URL
40965FILE-OFFICE Microsoft Office Publisher out of bounds read attempt (more info ...)attempted-user  2016-7289      URL
40966FILE-OFFICE Microsoft Office Publisher out of bounds read attempt (more info ...)attempted-user  2016-7289      URL
40967FILE-OFFICE Microsoft Office PowerPoint WMF conversion information disclosure attempt (more info ...)attempted-user  2016-7257      URL
40968FILE-OFFICE Microsoft Office PowerPoint WMF conversion information disclosure attempt (more info ...)attempted-user  2016-7257      URL
40977FILE-OFFICE Microsoft Office Excel insecure workbook load via reference to named share attempt (more info ...)policy-violation  2016-7267      URL
40978FILE-OFFICE Microsoft Office Excel insecure workbook load via reference to named share attempt (more info ...)policy-violation  2016-7267      URL
41108FILE-OFFICE Oracle Outside In Technology image export use after free attempt (more info ...)attempted-user  2017-3293      URL
41109FILE-OFFICE Oracle Outside In Technology image export use after free attempt (more info ...)attempted-user  2017-3293      URL
41110FILE-OFFICE Ichitaro Office JTD Figure handling code execution attempt (more info ...)attempted-user  2017-2789      URL
41111FILE-OFFICE Ichitaro Office JTD Figure handling code execution attempt (more info ...)attempted-user  2017-2789      URL
41140FILE-OFFICE Microsoft Office Word Out-of-Bounds Write attempt (more info ...)attempted-user  2017-0003      URL
41141FILE-OFFICE Microsoft Office Word Out-of-Bounds Write attempt (more info ...)attempted-user  2017-0003      URL
41468FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0272 attack attempt (more info ...)attempted-user  2017-2778      URL
41469FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0272 attack attempt (more info ...)attempted-user  2017-2778      URL
41495SERVER-WEBAPP WordPress get_post authentication bypass attempt (more info ...)web-application-attack        URL
41496SERVER-WEBAPP WordPress get_post authentication bypass attempt (more info ...)web-application-attack        URL
41497SERVER-WEBAPP WordPress get_post authentication bypass attempt (more info ...)web-application-attack        URL
41511FILE-OFFICE AntennaHouse HTMLFilter FillRowFormat remote code execution attempt (more info ...)attempted-user  2017-2783      URL
41512FILE-OFFICE AntennaHouse HTMLFilter FillRowFormat remote code execution attempt (more info ...)attempted-user  2017-2783      URL
41543FILE-OFFICE AntennaHouse DMC HTMLFilter UnCompressUnicode out of bounds write attempt (more info ...)attempted-user  2017-2793      URL
41544FILE-OFFICE AntennaHouse DMC HTMLFilter UnCompressUnicode out of bounds write attempt (more info ...)attempted-user  2017-2793      URL
41545FILE-OFFICE AntennaHouse DMC HTMLFilter iBldDirInfo heap buffer overflow attempt (more info ...)attempted-user  2017-2792      URL
41546FILE-OFFICE AntennaHouse DMC HTMLFilter iBldDirInfo heap buffer overflow attempt (more info ...)attempted-user  2017-2792      URL
41565FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-user  2017-0020      URL
41566FILE-OFFICE Microsoft Office Excel xlsb use-after-free attempt (more info ...)attempted-user  2017-0020      URL
41577FILE-OFFICE Microsoft Office RTF footnote format use after free attempt (more info ...)attempted-user  2017-0019      URL
41578FILE-OFFICE Microsoft Office RTF footnote format use after free attempt (more info ...)attempted-user  2017-0019      URL
41581FILE-OFFICE Microsoft Office Excel malformed CellXF memory corruption attempt (more info ...)attempted-user  2017-0027      URL
41582FILE-OFFICE Microsoft Office Excel malformed CellXF memory corruption attempt (more info ...)attempted-user  2017-0027      URL
41703FILE-OFFICE Ichitaro Office Excel TxO record heap buffer overflow attempt (more info ...)attempted-user  2017-2795      URL
41704FILE-OFFICE Ichitaro Office Excel TxO record heap buffer overflow attempt (more info ...)attempted-user  2017-2795      URL
41726FILE-OFFICE AntennaHouse DMC HTMLFilter AddSst heap overflow attempt (more info ...)attempted-user  2017-2799      URL
41727FILE-OFFICE AntennaHouse DMC HTMLFilter AddSst heap overflow attempt (more info ...)attempted-user  2017-2799      URL
41728FILE-OFFICE Microsoft Office Excel SXLI record integer overrun attempt (more info ...)attempted-user  2012-0184      URL
41729FILE-OFFICE Microsoft Office Excel SXLI record integer overrun attempt (more info ...)attempted-user  2012-0184      URL
41730FILE-OFFICE Microsoft Office Excel SXLI record integer overrun attempt (more info ...)attempted-user  2012-0184      URL
41731FILE-OFFICE Microsoft Office Excel SXLI record integer overrun attempt (more info ...)attempted-user  2012-0184      URL
41753FILE-OFFICE AntennaHouse DMC GetIndexArray out of bounds write attempt (more info ...)attempted-user  2017-2798      URL
41754FILE-OFFICE AntennaHouse DMC GetIndexArray out of bounds write attempt (more info ...)attempted-user  2017-2798      URL
41760FILE-OFFICE AntennaHouse DMC ParseEnvironment heap buffer overflow attempt (more info ...)attempted-user  2017-2797      URL
41765FILE-OFFICE AntennaHouse DMC DHFSummary stack buffer overflow attempt (more info ...)attempted-user  2017-2794      URL
41766FILE-OFFICE AntennaHouse DMC DHFSummary stack buffer overflow attempt (more info ...)attempted-user  2017-2794      URL
41791FILE-OTHER Microsoft Office RTF out-of-bounds memory access attempt (more info ...)attempted-user  2015-0086      URL
41792FILE-OTHER Microsoft Office RTF out-of-bounds memory access attempt (more info ...)attempted-user  2015-0086      URL
41962FILE-OFFICE Microsoft Office Word template remote code execution attempt (more info ...)attempted-user  2017-0106      URL
41963FILE-OFFICE Microsoft Office Word template remote code execution attempt (more info ...)attempted-user  2017-0106      URL
41964FILE-OFFICE Microsoft Office Word 2010 use-after-free memory corruption vulnerability attempt (more info ...)attempted-user  2017-0030      URL
41965FILE-OFFICE Microsoft Office Word 2010 use-after-free memory corruption vulnerability attempt (more info ...)attempted-user  2017-0030      URL
41976FILE-OFFICE Microsoft Office Excel shared strings memory corruption attempt (more info ...)attempted-user  2017-0006      URL
41977FILE-OFFICE Microsoft Office Excel shared strings memory corruption attempt (more info ...)attempted-user  2017-0006      URL
41979FILE-OFFICE Microsoft Office Excel shared strings memory corruption attempt (more info ...)attempted-user  2017-0052      URL
41980FILE-OFFICE Microsoft Office Excel shared strings memory corruption attempt (more info ...)attempted-user  2017-0052      URL
41981FILE-OFFICE Microsoft Office Word out of bounds read attempt (more info ...)attempted-user  2017-0105      URL
41982FILE-OFFICE Microsoft Office Word out of bounds read attempt (more info ...)attempted-user  2017-0105      URL
42008FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0295 attack attempt (more info ...)attempted-user        URL
42009FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0295 attack attempt (more info ...)attempted-user        URL
42076FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0300 attack attempt (more info ...)attempted-user  2019-5030      URL
42077FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0300 attack attempt (more info ...)attempted-user  2019-5030      URL
42120SERVER-WEBAPP Dahua IP Camera username and password disclosure attempt (more info ...)attempted-recon  2017-6343  96456    URL
42121SERVER-WEBAPP Dahua IP Camera username and password disclosure attempt (more info ...)attempted-recon  2017-6343  96456    URL
42138FILE-OFFICE Lexmark Perceptive Document Filters malformed XLS information disclosure attempt (more info ...)attempted-recon  2017-2806      URL
42144FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0301 attack attempt (more info ...)attempted-user        URL
42145FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0301 attack attempt (more info ...)attempted-user        URL
42161FILE-OFFICE Microsoft Office Excel out of bounds memory attempt (more info ...)attempted-user  2017-0194      
42162FILE-OFFICE Microsoft Office Excel out of bounds memory attempt (more info ...)attempted-user  2017-0194      
42167FILE-OFFICE Microsoft Office custom message class security bypass attempt (more info ...)attempted-user  2017-0204      
42168FILE-OFFICE Microsoft Office custom message class security bypass attempt (more info ...)attempted-user  2017-0204      
42189FILE-OFFICE RTF objautlink url moniker file download attempt (more info ...)misc-activity  2017-0199      
42190FILE-OFFICE RTF objautlink url moniker file download attempt (more info ...)misc-activity  2017-0199      
42198FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user  2015-6132      URL
42755FILE-OFFICE Microsoft Office Word 2010 Sepx memory corruption attempt (more info ...)attempted-user  2017-0243      
42756FILE-OFFICE Microsoft Office Word 2010 Sepx memory corruption attempt (more info ...)attempted-user  2017-0243      
42863FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user  2015-6132      URL
42864FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user  2015-6132      URL
42900FILE-OFFICE Microsoft Office EPS restore command use after free attempt (more info ...)attempted-user  2017-0261      URL
42901FILE-OFFICE Microsoft Office EPS file containing embedded PE (more info ...)policy-violation        
42902FILE-OFFICE Microsoft Office EPS restore command use after free attempt (more info ...)attempted-user  2017-0261      URL
42903FILE-OFFICE Microsoft Office EPS restore command use after free attempt (more info ...)attempted-user  2017-0261      URL
42904FILE-OFFICE Microsoft Office EPS restore command use after free attempt (more info ...)attempted-user  2017-0261      URL
42905FILE-OFFICE Microsoft Office EPS file containing embedded PE (more info ...)policy-violation        
43159FILE-OFFICE Microsoft Office Word 2016 use after free attempt (more info ...)attempted-user  2017-8509      
43160FILE-OFFICE Microsoft Office Word 2016 use after free attempt (more info ...)attempted-user  2017-8509      
43171FILE-OFFICE Microsoft Office Word malformed jpeg remote code execution attempt (more info ...)attempted-user  2017-8510      
43172FILE-OFFICE Microsoft Office Word malformed jpeg remote code execution attempt (more info ...)attempted-user  2017-8510      
43179FILE-OFFICE Powerpoint mouseover powershell malware download attempt (more info ...)trojan-activity        URL
43180FILE-OFFICE Powerpoint mouseover powershell malware download attempt (more info ...)trojan-activity        URL
43802FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user  2015-6132      URL
43803FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user  2015-6132      URL
43847FILE-OFFICE Microsoft Office Access Jet Database Engine integer overflow attempt (more info ...)attempted-user  2017-0250      
43848FILE-OFFICE Microsoft Office Access Jet Database Engine integer overflow attempt (more info ...)attempted-user  2017-0250      
44030FILE-IDENTIFY Microsoft Office PowerPoint ppt file attachment detected file attachment detected (more info ...)misc-activity        
44052FILE-OFFICE Microsoft Office Word EPS filter PostScript object use after free attempt (more info ...)attempted-user  2015-2545      URL
44092FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0404 attack attempt (more info ...)attempted-user  2017-2897      URL
44093FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0404 attack attempt (more info ...)attempted-user  2017-2897      URL
44101FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0403 attack attempt (more info ...)attempted-user  2017-2896      URL
44102FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0403 attack attempt (more info ...)attempted-user  2017-2896      URL
44106FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0417 attack attempt (more info ...)attempted-user  2017-2910      URL
44107FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0417 attack attempt (more info ...)attempted-user  2017-2910      URL
44163FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0426 attack attempt (more info ...)attempted-user  2017-2919      URL
44164FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0426 attack attempt (more info ...)attempted-user  2017-2919      URL
44231FILE-IDENTIFY Microsoft Office Word doc file attachment detected (more info ...)misc-activity        
44271FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0430 attack attempt (more info ...)attempted-user  2017-2923      URL
44272FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0430 attack attempt (more info ...)attempted-user  2017-2923      URL
44273FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0431 attack attempt (more info ...)attempted-user  2017-2924      URL
44274FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0431 attack attempt (more info ...)attempted-user  2017-2924      URL
44275FILE-IDENTIFY Microsoft Office Excel file attachment detected (more info ...)misc-activity        
44363FILE-OFFICE Microsoft Office RTF hex encoded WRAsembly ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
44364FILE-OFFICE Microsoft Office RTF hex encoded WRAssembly ASLR bypass download attempt (more info ...)attempted-user  2015-1641      URL
44371FILE-OFFICE RTF WSDL file download attempt (more info ...)attempted-user  2017-8759      URL
44372FILE-OFFICE RTF WSDL file download attempt (more info ...)attempted-user  2017-8759      URL
44430FILE-OFFICE Fin7 Maldoc campaign exploitation attempt (more info ...)misc-activity        
44431FILE-OFFICE Fin7 Maldoc campaign exploitation attempt (more info ...)misc-activity        
44432FILE-OFFICE Fin7 Maldoc campaign exploitation attempt (more info ...)misc-activity        
44433FILE-OFFICE Fin7 Maldoc campaign exploitation attempt (more info ...)misc-activity        
44518FILE-OFFICE Microsoft Graphics remote code execution attempt (more info ...)attempted-admin  2017-11762      URL
44519FILE-OFFICE Microsoft Graphics remote code execution attempt (more info ...)attempted-admin  2017-11762      URL
44520FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0461 attack attempt (more info ...)attempted-user  2017-12109      URL
44521FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0461 attack attempt (more info ...)attempted-user  2017-12109      URL
44522FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0460 attack attempt (more info ...)attempted-user  2017-12108      URL
44523FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0460 attack attempt (more info ...)attempted-user  2017-12108      URL
44579FILE-OFFICE Microsoft Office dde field code execution attempt (more info ...)attempted-admin        URL
44580FILE-OFFICE Microsoft Office dde field code execution attempt (more info ...)attempted-admin        URL
44587SERVER-WEBAPP Trend Micro OfficeScan server side request forgery attempt (more info ...)web-application-attack        URL
44588SERVER-WEBAPP Trend Micro OfficeScan server side request forgery attempt (more info ...)web-application-attack        URL
44589FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0463 attack attempt (more info ...)attempted-user  2017-12111      URL
44590FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0463 attack attempt (more info ...)attempted-user  2017-12111      URL
44593FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0462 attack attempt (more info ...)attempted-user  2017-12110      URL
44594FILE-OFFICE TRUFFLEHUNTER TALOS-2017-0462 attack attempt (more info ...)attempted-user  2017-12110      URL
44669FILE-OFFICE Microsoft Office Outlook SMB attach by reference code execution attempt (more info ...)attempted-user  2010-0266  41446    URL
44670FILE-OFFICE Microsoft Office Outlook SMB attach by reference code execution attempt (more info ...)attempted-user  2010-0266  41446    URL
44682SERVER-OTHER Novell GroupWise Post Office Agent heap overflow attempt (more info ...)attempted-admin        URL
44683SERVER-OTHER Novell GroupWise Post Office Agent heap overflow attempt (more info ...)attempted-admin        URL
44821FILE-OFFICE Microsoft Office Excel use after free vulnerability exploit attempt (more info ...)attempted-user  2017-11878      
44822FILE-OFFICE Microsoft Office Excel use after free vulnerability exploit attempt (more info ...)attempted-user  2017-11878      
44908FILE-OTHER KeyView SDK WordPerfect parsing stack buffer overflow attempt (more info ...)attempted-admin        
44909FILE-OTHER KeyView SDK WordPerfect parsing stack buffer overflow attempt (more info ...)attempted-admin        
44989FILE-OFFICE Microsoft Office Equation Editor object with automatic execution embedded in RTF attempt (more info ...)attempted-user  2018-0802      URL
44990FILE-OFFICE Microsoft Office Equation Editor object with automatic execution embedded in RTF attempt (more info ...)attempted-user  2018-0802      URL
45066SERVER-WEBAPP WordPress Duplicator cross site scripting attempt (more info ...)attempted-user  2017-16815      URL
45067SERVER-WEBAPP WordPress Duplicator cross site scripting attempt (more info ...)attempted-user  2017-16815      URL
45123FILE-OFFICE Microsoft Office Excel malformed spreadsheet use-after-free attempt (more info ...)attempted-admin  2017-11935      URL
45124FILE-OFFICE Microsoft Office Excel malformed spreadsheet use-after-free attempt (more info ...)attempted-admin  2017-11935      URL
45133FILE-OFFICE Microsoft Office Equation Editor object stack buffer overflow attempt (more info ...)attempted-user  2017-11882      URL
45134FILE-OFFICE Microsoft Office Equation Editor object stack buffer overflow attempt (more info ...)attempted-user  2017-11882      URL
45135FILE-OFFICE Microsoft Office Equation Editor object stack buffer overflow attempt (more info ...)attempted-user  2017-11882      URL
45214FILE-OTHER Microsoft Word DDEauto code execution attempt (more info ...)attempted-admin        URL
45215FILE-OTHER Microsoft Word DDEauto code execution attempt (more info ...)attempted-admin        URL
45243POLICY-OTHER ZyXEL PK5001Z modem hardcoded admin password telnet login attempt (more info ...)attempted-admin  2016-10401      URL
45244POLICY-OTHER ZyXEL PK5001Z modem hardcoded root password telnet login attempt (more info ...)attempted-admin  2016-10401      URL
45245POLICY-OTHER ZyXEL PK5001Z modem hardcoded admin password telnet login attempt (more info ...)attempted-admin  2016-10401      URL
45314SERVER-WEBAPP Beijing Hanbang Hanbanggaoke IP camera admin password change attempt (more info ...)attempted-user  2017-14335      URL
45370FILE-OFFICE Microsoft Office Word docx subDocument file include attempt (more info ...)attempted-user        URL
45371FILE-OFFICE Microsoft Office Word docx subDocument file include attempt (more info ...)attempted-user        URL
45413SERVER-WEBAPP Hikvision IP camera admin authentication attempt (more info ...)web-application-attack  2017-7921      URL
45415FILE-OFFICE RTF Composite Moniker object creation attempt (more info ...)attempted-user  2017-8570      URL
45416FILE-OFFICE RTF Composite Moniker object creation attempt (more info ...)attempted-user  2017-8570      URL
45466FILE-OFFICE Microsoft Office None type objclass RTF evasion attempt (more info ...)attempted-user  2018-0802      
45467FILE-OFFICE Microsoft Office None type objclass RTF evasion attempt (more info ...)attempted-user  2018-0802      
45511FILE-OFFICE Microsoft Office Equation Editor Package objclass RTF evasion attempt (more info ...)attempted-admin  2018-0802      
45512FILE-OFFICE Microsoft Office Equation Editor Package objclass RTF evasion attempt (more info ...)attempted-admin  2018-0802      
45519INDICATOR-COMPROMISE Microsoft Word internal object auto update attempt (more info ...)attempted-user  2017-0199      URL
45520INDICATOR-COMPROMISE Microsoft Word internal object auto update attempt (more info ...)attempted-user  2017-0199      URL
45598SERVER-OTHER Wordpress CMS platform denial of service attempt (more info ...)denial-of-service  2018-6389      
45654FILE-OFFICE Microsoft Office remote code execution attempt (more info ...)attempted-admin  2018-0841      URL
45655FILE-OFFICE Microsoft Office remote code execution attempt (more info ...)attempted-admin  2018-0841      URL
45689FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0527 attack attempt (more info ...)attempted-user  2018-3844      URL
45690FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0527 attack attempt (more info ...)attempted-user  2018-3844      URL
45717FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0528 attack attempt (more info ...)attempted-user  2018-3845      URL
45718FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0528 attack attempt (more info ...)attempted-user  2018-3845      URL
45750FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0534 attack attempt (more info ...)attempted-user  2018-3851      URL
45751FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0534 attack attempt (more info ...)attempted-user  2018-3851      URL
45883FILE-OFFICE Microsoft Access remote code execution attempt (more info ...)attempted-user  2018-0903      URL
45884FILE-OFFICE Microsoft Access remote code execution attempt (more info ...)attempted-user  2018-0903      URL
45896FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0538 attack attempt (more info ...)attempted-user  2018-3855      URL
45897FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0538 attack attempt (more info ...)attempted-user  2018-3855      URL
46095POLICY-OTHER Cisco IOS XE default one-time password login detected (more info ...)policy-violation  2018-0150      URL
46106FILE-OFFICE Microsoft Office Equation Editor RTF evasion attempt (more info ...)attempted-user  2018-0802      
46107FILE-OFFICE Microsoft Office Equation Editor RTF evasion attempt (more info ...)attempted-user  2018-0802      
46178FILE-OFFICE Microsoft Office Excel out of bounds read attempt (more info ...)attempted-user  2018-1030      URL
46179FILE-OFFICE Microsoft Office Excel out of bounds read attempt (more info ...)attempted-user  2018-1030      URL
46180FILE-OFFICE Microsoft Office Excel use after free remote code execution attempt (more info ...)attempted-user  2018-1029      URL
46181FILE-OFFICE Microsoft Office Excel use after free remote code execution attempt (more info ...)attempted-user  2018-1029      URL
46182FILE-OFFICE Microsoft Office Excel graphics remote code execution attempt (more info ...)attempted-user  2018-1028      URL
46183FILE-OFFICE Microsoft Office Excel graphics remote code execution attempt (more info ...)attempted-user  2018-1028      URL
46184FILE-OFFICE Microsoft Office Excel remote code execution attempt (more info ...)attempted-user  2018-1026      URL
46185FILE-OFFICE Microsoft Office Excel remote code execution attempt (more info ...)attempted-user  2018-1026      URL
46192FILE-OFFICE Microsoft Office Excel drawing cell reuse use-after-free attempt (more info ...)attempted-user  2018-1011      URL
46193FILE-OFFICE Microsoft Office Excel drawing cell reuse use-after-free attempt (more info ...)attempted-user  2018-1011      URL
46196FILE-OFFICE Microsoft Office Excel named range cell content use-after-free attempt (more info ...)attempted-user  2018-0920      URL
46197FILE-OFFICE Microsoft Office Excel named range cell content use-after-free attempt (more info ...)attempted-user  2018-0920      URL
46208FILE-OFFICE Microsoft Office Excel use after free remote code execution attempt (more info ...)attempted-user  2018-1027      URL
46209FILE-OFFICE Microsoft Office Excel use after free remote code execution attempt (more info ...)attempted-user  2018-1027      URL
46266FILE-OTHER Microsoft Office Outlook 2003 OLE information disclosure attempt detected (more info ...)policy-violation  2018-0950      URL
46267FILE-OTHER Microsoft Office Outlook 2003 OLE information disclosure attempt detected (more info ...)policy-violation  2018-0950      URL
46552FILE-OFFICE Microsoft Office Excel remote code execution attempt (more info ...)attempted-user  2018-8147      URL
46553FILE-OFFICE Microsoft Office Excel remote code execution attempt (more info ...)attempted-user  2018-8147      URL
46556FILE-OFFICE Microsoft Office Excel remote code execution attempt (more info ...)attempted-user  2018-8148      URL
46557FILE-OFFICE Microsoft Office Excel remote code execution attempt (more info ...)attempted-user  2018-8148      URL
46558FILE-OFFICE Microsoft Office docx heap out of bounds read attempt (more info ...)attempted-user  2018-8157      URL
46559FILE-OFFICE Microsoft Office docx heap out of bounds read attempt (more info ...)attempted-user  2018-8157      URL
46560FILE-OFFICE Microsoft Office RTF embedded ole file out of bounds write attempt (more info ...)attempted-user  2018-8158      URL
46561FILE-OFFICE Microsoft Office RTF embedded ole file out of bounds write attempt (more info ...)attempted-user  2018-8158      URL
46632SERVER-MAIL Office 365 ATP Safe Links bypass attempt (more info ...)attempted-user        
46633SERVER-MAIL Office 365 ATP Safe Links bypass attempt (more info ...)attempted-user        
46756FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0596 attack attempt (more info ...)attempted-user  2018-3929      URL
46757FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0596 attack attempt (more info ...)attempted-user  2018-3929      URL
46761FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0597 attack attempt (more info ...)attempted-user  2018-3930      URL
46762FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0597 attack attempt (more info ...)attempted-user  2018-3930      URL
46768FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0598 attack attempt (more info ...)attempted-user  2018-3931      URL
46769FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0598 attack attempt (more info ...)attempted-user  2018-3931      URL
46843FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0599 attack attempt (more info ...)attempted-user  2018-3932      URL
46844FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0599 attack attempt (more info ...)attempted-user  2018-3932      URL
46845FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0600 attack attempt (more info ...)attempted-user  2018-3933      URL
46846FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0600 attack attempt (more info ...)attempted-user  2018-3933      URL
46882FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0603 attack attempt (more info ...)attempted-user  2018-3936      URL
46883FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0603 attack attempt (more info ...)attempted-user  2018-3936      URL
46893SERVER-OTHER Cisco Prime Collaboration Provisioning Java remote method invocation attempt (more info ...)attempted-admin  2018-0321      URL
46911SERVER-WEBAPP Cisco Prime Collaboration Provisioning potentially unauthenticated administrator password change attempt (more info ...)attempted-admin  2018-0318      URL
46914SERVER-WEBAPP Cisco Prime Collaboration Provisioning password recovery field reuse attempt (more info ...)web-application-attack  2018-0319      URL
46940FILE-OFFICE Microsoft Office Word malformed RTF memory corruption attempt (more info ...)attempted-admin  2018-8248      URL
46941FILE-OFFICE Microsoft Office Word malformed RTF memory corruption attempt (more info ...)attempted-admin  2018-8248      URL
46953OS-WINDOWS Microsoft OfficeHub object manager namespace privilege escalation attempt (more info ...)attempted-admin  2018-8208      URL
46954OS-WINDOWS Microsoft OfficeHub object manager namespace privilege escalation attempt (more info ...)attempted-admin  2018-8208      URL
47015SERVER-WEBAPP Quest DR Series Disk Backup PasswordService.pm command injection attempt (more info ...)web-application-attack  2018-11151      URL
47055FILE-OFFICE Microsoft Office Excel empty bookViews element denial of service attempt (more info ...)attempted-dos  2016-3284      URL
47056FILE-OFFICE Microsoft Office Excel empty bookViews element denial of service attempt (more info ...)attempted-dos  2016-3284      URL
47063FILE-OFFICE Microsoft Office Word malformed emf remote code execution attempt (more info ...)attempted-user  2017-8510      
47175FILE-OFFICE Microsoft Office Excel ddeService command execution attempt (more info ...)attempted-user  2016-7262      URL
47176FILE-OFFICE Microsoft Office Excel ddeService command execution attempt (more info ...)attempted-user  2016-7262      URL
47206FILE-OFFICE Microsoft Office Word sprmSDyaTop memory leak attempt (more info ...)attempted-user  2016-3316      URL
47254FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47255FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47256FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47257FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47258FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47259FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47260FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47261FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47262FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47263FILE-OTHER Microsoft Excel malicious CSV code execution attempt (more info ...)attempted-user        
47456FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0646 attack attempt (more info ...)attempted-user  2018-3978      URL
47457FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0646 attack attempt (more info ...)attempted-user  2018-3978      URL
47482FILE-OFFICE Microsoft PowerPoint slide show type confusion attempt (more info ...)attempted-user  2018-8376      URL
47483FILE-OFFICE Microsoft PowerPoint slide show type confusion attempt (more info ...)attempted-user  2018-8376      URL
47495FILE-OFFICE Microsoft Office Excel use after free attempt (more info ...)attempted-user  2018-8379      URL
47496FILE-OFFICE Microsoft Office Excel use after free attempt (more info ...)attempted-user  2018-8379      URL
47521FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0652 attack attempt (more info ...)attempted-user  2018-3894      URL
47522FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0652 attack attempt (more info ...)attempted-user  2018-3894      URL
47523FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0651 attack attempt (more info ...)attempted-user  2018-3983      URL
47524FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0651 attack attempt (more info ...)attempted-user  2018-3983      URL
47527FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0650 attack attempt (more info ...)attempted-user  2018-3982      URL
47528FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0650 attack attempt (more info ...)attempted-user  2018-3982      URL
47568FILE-OFFICE Adobe Flash Player ActiveX security bypass attempt (more info ...)attempted-user  2018-12825      URL
47569FILE-OFFICE Adobe Flash Player ActiveX security bypass attempt (more info ...)attempted-user  2018-12825      URL
47603SERVER-WEBAPP WordPress phar deserialization attempt (more info ...)attempted-user        
47753FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0669 attack attempt (more info ...)attempted-user  2018-4001      URL
47754FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0669 attack attempt (more info ...)attempted-user  2018-4001      URL
47755FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0667 attack attempt (more info ...)attempted-user  2018-3999      URL
47756FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0667 attack attempt (more info ...)attempted-user  2018-3999      URL
47757FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0666 attack attempt (more info ...)attempted-user  2018-3998      URL
47758FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0666 attack attempt (more info ...)attempted-user  2018-3998      URL
47759FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0666 attack attempt (more info ...)attempted-user  2018-3998      URL
47760FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0666 attack attempt (more info ...)attempted-user  2018-3998      URL
47762FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0668 attack attempt (more info ...)attempted-user  2018-4000      URL
47763FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0668 attack attempt (more info ...)attempted-user  2018-4000      URL
47946FILE-PDF Adobe Acrobat Distiller invalid Keywords tag double free attempt (more info ...)attempted-user  2018-12841      URL
48037SERVER-OTHER Cisco Prime Collaboration Provisioning hardcoded LDAP password authentication attempt (more info ...)attempted-admin  2018-15389      URL
48378FILE-OFFICE Microsoft Office directory entry remote code execution attempt (more info ...)attempted-user  2018-8539      URL
48379FILE-OFFICE Microsoft Office directory entry remote code execution attempt (more info ...)attempted-user  2018-8539      URL
48389FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0711 attack attempt (more info ...)attempted-user  2018-4038      URL
48390FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0711 attack attempt (more info ...)attempted-user  2018-4038      URL
48391FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0712 attack attempt (more info ...)attempted-user  2018-4039      URL
48392FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0712 attack attempt (more info ...)attempted-user  2018-4039      URL
48403FILE-OFFICE Microsoft Outlook email rules file memory corruption attempt (more info ...)attempted-user  2018-8582      URL
48404FILE-OFFICE Microsoft Outlook email rules file memory corruption attempt (more info ...)attempted-user  2018-8582      URL
48405FILE-OFFICE Microsoft Office Outlook rwz file memory corruption attempt (more info ...)attempted-user  2018-8587      URL
48406FILE-OFFICE Microsoft Office Outlook rwz file memory corruption attempt (more info ...)attempted-user  2018-8587      URL
48407FILE-OFFICE Microsoft Office Outlook rwz file memory corruption attempt (more info ...)attempted-user  2018-8522      URL
48408FILE-OFFICE Microsoft Office Outlook rwz file memory corruption attempt (more info ...)attempted-user  2018-8522      URL
48416SERVER-WEBAPP WordPress wp_delete_attachment directory traversal attempt (more info ...)web-application-attack  2018-12895  104569    URL
48423FILE-OFFICE Microsoft Office Word document malicious iframe code injection attempt (more info ...)attempted-user        
48424FILE-OFFICE Microsoft Office Word document malicious iframe code injection attempt (more info ...)attempted-user        
48573SERVER-WEBAPP WordPress arbitrary file deletion attempt (more info ...)web-application-attack        URL
48601FILE-OFFICE Microsoft Office Powerpoint use after free attempt (more info ...)attempted-user  2018-8628      URL
48602FILE-OFFICE Microsoft Office Powerpoint use after free attempt (more info ...)attempted-user  2018-8628      URL
49048FILE-OFFICE Microsoft Office XML nested num tag double-free attempt (more info ...)attempted-user  2015-1650      URL
49049FILE-OFFICE Microsoft Office XML nested num tag double-free attempt (more info ...)attempted-user  2015-1650      URL
49132FILE-OFFICE Microsoft Excel information disclosure attempt (more info ...)attempted-user  2019-0669      URL
49133FILE-OFFICE Microsoft Excel information disclosure attempt (more info ...)attempted-user  2019-0669      URL
49209FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0780 attack attempt (more info ...)attempted-user  2019-5019      URL
49210FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0780 attack attempt (more info ...)attempted-user  2019-5019      URL
49448SERVER-WEBAPP WordPress comment cross site request forgery attempt (more info ...)attempted-user        URL
49495FILE-OFFICE Microsoft Office MSCOMCTL ActiveX control tabstrip method access (more info ...)misc-activity        
49497FILE-OFFICE Microsoft Office MSCOMCTL ActiveX control tabstrip method access (more info ...)misc-activity        
49527SERVER-WEBAPP WordPress SocialWarfare deprecated function access attempt (more info ...)web-application-attack  2019-9978      URL
49528SERVER-WEBAPP WordPress SocialWarfare plugin stored cross site scripting attempt (more info ...)web-application-attack  2019-9978      URL
49539SERVER-OTHER WordPress wp_user_roles configuration change attempt (more info ...)web-application-attack        URL
49540SERVER-OTHER WordPress wp_user_roles configuration change attempt (more info ...)web-application-attack        URL
49645SERVER-WEBAPP Wordpress image edit directory traversal attempt (more info ...)web-application-attack  2019-8942      
49646SERVER-WEBAPP Wordpress image edit directory traversal attempt (more info ...)web-application-attack  2019-8942      
49647SERVER-WEBAPP Wordpress image edit directory traversal attempt (more info ...)web-application-attack  2019-8942      
49700FILE-OFFICE Microsoft Powerpoint graphics component remote code execution attempt (more info ...)attempted-admin  2019-0822      URL
49701FILE-OFFICE Microsoft Powerpoint graphics component remote code execution attempt (more info ...)attempted-admin  2019-0822      URL
49727FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49728FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49729FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49730FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49731FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49732FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49733FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49734FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49735FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49736FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49737FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49738FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49739FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49740FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49741FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49742FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49743FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49744FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49745FILE-OFFICE Microsoft Office directory traversal attempt (more info ...)attempted-user  2019-0801      URL
49776FILE-OFFICE Microsoft Office Equation Editor object stack buffer overflow attempt (more info ...)attempted-user  2017-11882      URL
49795SERVER-WEBAPP WordPress Yuzo Related Posts plugin cross site scripting attempt (more info ...)web-application-attack        URL
49796SERVER-WEBAPP WordPress Yuzo Related Posts plugin cross site scripting attempt (more info ...)web-application-attack        URL
50086FILE-OFFICE Microsoft Windows GDI EMR_POLYTEXTOUTW out-of-bounds read attempt (more info ...)attempted-user  2019-0882      URL
50087FILE-OFFICE Microsoft Windows GDI EMR_POLYTEXTOUTW out-of-bounds read attempt (more info ...)attempted-user  2019-0882      URL
50299SERVER-WEBAPP WordPress plugin Convert Plus unauthenticated administrator account creation attempt (more info ...)web-application-attack        URL
50680FILE-OFFICE Microsoft Excel information disclosure attempt (more info ...)attempted-recon  2019-1112      URL
50681FILE-OFFICE Microsoft Excel information disclosure attempt (more info ...)attempted-recon  2019-1112      URL
50690FILE-OFFICE Microsoft Office Equation Editor RTF evasion attempt (more info ...)attempted-user  2018-0802      URL
50691FILE-OFFICE Microsoft Office Equation Editor RTF evasion attempt (more info ...)attempted-user  2018-0802      URL
50692FILE-OFFICE Microsoft Office Equation Editor RTF evasion attempt (more info ...)attempted-user  2018-0802      URL
50693FILE-OFFICE Microsoft Office Equation Editor RTF evasion attempt (more info ...)attempted-user  2018-0802      URL
50694MALWARE-OTHER Microsoft Office Equation Editor remote code execution attempt (more info ...)attempted-user  2018-0798      URL
50695MALWARE-OTHER Microsoft Office Equation Editor remote code execution attempt (more info ...)attempted-user  2018-0798      URL
50732SERVER-WEBAPP CyberArk Enterprise Password Vault XML external entity injection attempt (more info ...)web-application-attack  2019-7442      
50733SERVER-WEBAPP CyberArk Enterprise Password Vault XML external entity injection attempt (more info ...)web-application-attack  2019-7442      
50745SERVER-WEBAPP Cisco Vision Dynamic Signage Director authentication bypass attempt (more info ...)attempted-admin  2019-1917      URL
50772SERVER-WEBAPP Schneider Electric quantum modicon ethernet module unauthenticated password change attempt (more info ...)attempted-admin  2018-7811      
50779SERVER-WEBAPP Schneider Electric Quantum modicon ethernet module unauthenticated password reset attempt (more info ...)attempted-user  2019-7809      
50998FILE-OFFICE Microsoft Office Outlook memory corruption attempt (more info ...)attempted-user  2019-1199      URL
50999FILE-OFFICE Microsoft Office Outlook memory corruption attempt (more info ...)attempted-user  2019-1199      URL
51098FILE-OTHER LibreOffice macro remote code execution attempt (more info ...)attempted-user  2018-16858      URL
51099FILE-OTHER LibreOffice macro remote code execution attempt (more info ...)attempted-user  2018-16858      URL
51100FILE-OTHER LibreOffice macro remote code execution attempt (more info ...)attempted-user  2018-16858      URL
51101FILE-OTHER LibreOffice macro remote code execution attempt (more info ...)attempted-user  2018-16858      URL
51123FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0886 attack attempt (more info ...)attempted-user        URL
51124FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0886 attack attempt (more info ...)attempted-user        URL
51267FILE-OFFICE Microsoft Outlook rwz file memory corruption attempt (more info ...)attempted-user  2018-8587      URL
51486SERVER-WEBAPP Webmin password_change command injection attempt (more info ...)web-application-attack  2019-15107      URL
51487SERVER-WEBAPP Webmin password_change command injection attempt (more info ...)web-application-attack  2019-15107      URL
51488SERVER-WEBAPP Webmin password_change command injection attempt (more info ...)web-application-attack  2019-15107      URL
51489SERVER-WEBAPP Webmin password_change command injection attempt (more info ...)web-application-attack  2019-15107      URL
51537SERVER-WEBAPP WordPress Print-My-Blog plugin server side request forgery attempt (more info ...)web-application-attack  2019-11565      URL
52417FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0968 attack attempt (more info ...)attempted-user  2021-40474      URL
52418FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0968 attack attempt (more info ...)attempted-user  2021-40474      URL
52481INDICATOR-COMPROMISE Microsoft Word internal OLE object update attempt (more info ...)attempted-user  2017-0199      URL
52482INDICATOR-COMPROMISE Microsoft Word internal OLE object update attempt (more info ...)attempted-user  2017-0199      URL
52641SERVER-WEBAPP Cisco Smart Software Manager unauthorized password change attempt (more info ...)attempted-admin  2019-16029      URL
52642SERVER-WEBAPP Cisco Smart Software Manager unauthorized password change attempt (more info ...)attempted-admin  2019-16029      URL
53260MALWARE-OTHER Win.Trojan.DarkVision RAT download attempt (more info ...)attempted-user        URL
53261MALWARE-OTHER Win.Trojan.DarkVision RAT download attempt (more info ...)attempted-user        URL
53268FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1015 attack attempt (more info ...)attempted-user        URL
53269FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1015 attack attempt (more info ...)attempted-user        URL
53487FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1027 attack attempt (more info ...)attempted-user        URL
53488FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1027 attack attempt (more info ...)attempted-user        URL
53650FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1045 attack attempt (more info ...)attempted-user        URL
53651FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1045 attack attempt (more info ...)attempted-user        URL
54596SERVER-WEBAPP WordPress bbPress plugin unauthenticated privilege escalation attempt (more info ...)attempted-admin  2020-13693      URL
54597SERVER-WEBAPP WordPress bbPress plugin unauthenticated privilege escalation attempt (more info ...)attempted-admin  2020-13693      URL
54617SERVER-WEBAPP GeoVision Door Access Control hidden url access attempt (more info ...)attempted-admin  2020-3928      
55748FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1153 attack attempt (more info ...)attempted-user        URL
55749FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1153 attack attempt (more info ...)attempted-user        URL
55778SERVER-WEBAPP Wordpress File Manager plugin elFinder remote code execution attempt (more info ...)attempted-user  2020-25213      
55797SERVER-WEBAPP Wordpress plugin WP Database Reset database reset attempt (more info ...)web-application-attack  2020-7048      
55834SERVER-WEBAPP Wordpress Nexos theme cross site scripting attempt (more info ...)attempted-user  2020-15364      
55835SERVER-WEBAPP Wordpress Nexos theme cross site scripting attempt (more info ...)attempted-user  2020-15364      
56082SERVER-WEBAPP Wordpress WP Database Backup plug-in command injection attempt (more info ...)web-application-attack        URL
56083SERVER-WEBAPP Wordpress WP Database Backup plug-in command injection attempt (more info ...)web-application-attack        URL
56156FILE-OFFICE Microsoft Office Outlook email parsing remote code execution attempt (more info ...)attempted-user  2020-16947      URL
56157FILE-OFFICE Microsoft Office Outlook email parsing remote code execution attempt (more info ...)attempted-user  2020-16947      URL
56209FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1192 attack attempt (more info ...)attempted-user  2020-13581      URL
56210FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1192 attack attempt (more info ...)attempted-user  2020-13581      URL
56212FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1191 attack attempt (more info ...)attempted-user  2020-13580      URL
56213FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1191 attack attempt (more info ...)attempted-user  2020-13580      URL
56226FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1190 attack attempt (more info ...)attempted-user  2020-13579      URL
56227FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1190 attack attempt (more info ...)attempted-user  2020-13579      URL
56228FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1190 attack attempt (more info ...)attempted-user  2020-13579      URL
56229FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1190 attack attempt (more info ...)attempted-user  2020-13579      URL
56389FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1197 attack attempt (more info ...)attempted-user  2020-13586      URL
56390FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1197 attack attempt (more info ...)attempted-user  2020-13586      URL
56526FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1210 attack attempt (more info ...)attempted-user  2020-28587      URL
56527FILE-OFFICE TRUFFLEHUNTER TALOS-2020-1210 attack attempt (more info ...)attempted-user  2020-28587      URL
57063INDICATOR-COMPROMISE Microsoft Word internal OLE object update attempt (more info ...)attempted-admin  2017-0199      URL
57066INDICATOR-COMPROMISE Microsoft Word internal OLE object update attempt (more info ...)attempted-user  2017-0199      URL
57570SERVER-WEBAPP WordPRess DZS Video Gallery directory traversal attempt (more info ...)web-application-attack        URL
57571SERVER-WEBAPP WordPRess DZS Video Gallery directory traversal attempt (more info ...)web-application-attack        URL
57572SERVER-WEBAPP WordPRess DZS Video Gallery directory traversal attempt (more info ...)web-application-attack        URL
57573SERVER-WEBAPP WordPress DZS Video Gallery remote file include attempt (more info ...)web-application-attack        URL
57574SERVER-WEBAPP WordPress DZS Video Gallery remote file include attempt (more info ...)web-application-attack        URL
58120FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58121FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58122FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58123FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58124FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58125FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58126FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58127FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58130FILE-OFFICE Microsoft MSHTML code execution attempt (more info ...)attempted-user  2021-40444      URL
58131FILE-OFFICE Microsoft MSHTML code execution attempt (more info ...)attempted-user  2021-40444      URL
58132FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58133FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58134FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58135FILE-OFFICE Microsoft MSHTML ActiveX control bypass attempt (more info ...)attempted-user  2021-40444      URL
58366FILE-OFFICE TRUFFLEHUNTER TALOS-2021-1386 attack attempt (more info ...)attempted-user  2021-21958      URL
58410SERVER-WEBAPP IBM Spectrum Protect Plus changeAdministratorPassword command injection attempt (more info ...)web-application-attack  2020-4210      
58411SERVER-WEBAPP IBM Spectrum Protect Plus changeAdministratorPassword command injection attempt (more info ...)web-application-attack  2020-4210      
58412SERVER-WEBAPP IBM Spectrum Protect Plus changeAdministratorPassword command injection attempt (more info ...)web-application-attack  2020-4210      
58413SERVER-WEBAPP IBM Spectrum Protect Plus changeAdministratorPassword command injection attempt (more info ...)web-application-attack  2020-4210      
58487SERVER-WEBAPP WordPress Snap Creek Duplicator and Duplicator Pro plugins directory traversal attempt (more info ...)web-application-attack  2020-11738      
58555SERVER-WEBAPP Hikvision webLanguage command injection vulnerability (more info ...)attempted-user  2021-36260      
58574FILE-OFFICE TRUFFLEHUNTER TALOS-2021-1412 attack attempt (more info ...)attempted-user  2021-40399      URL
58575FILE-OFFICE TRUFFLEHUNTER TALOS-2021-1412 attack attempt (more info ...)attempted-user  2021-40399      URL
59323SERVER-WEBAPP Trend Micro Apex One and OfficeScan directory traversal attempt (more info ...)web-application-attack  2020-8470      
59324SERVER-WEBAPP Trend Micro Apex One and OfficeScan directory traversal attempt (more info ...)web-application-attack  2020-8470      
59325SERVER-WEBAPP Trend Micro Apex One and OfficeScan directory traversal attempt (more info ...)web-application-attack  2020-8470      
59393SERVER-WEBAPP HPE Moonshot Provisioning Manager Appliance directory traversal attempt (more info ...)web-application-attack  2017-8977      
59394SERVER-WEBAPP HPE Moonshot Provisioning Manager Appliance directory traversal attempt (more info ...)web-application-attack  2017-8977      
59395SERVER-WEBAPP HPE Moonshot Provisioning Manager Appliance directory traversal attempt (more info ...)web-application-attack  2017-8977      
59396FILE-OFFICE Microsoft Word tblStylePr use after free attempt (more info ...)attempted-user  2014-4117      URL
59397FILE-OFFICE Microsoft Word tblStylePr use after free attempt (more info ...)attempted-user  2014-4117      URL
59398FILE-OFFICE Microsoft Word tblStylePr use after free attempt (more info ...)attempted-user  2014-4117      URL
59399FILE-OFFICE Microsoft Word tblStylePr use after free attempt (more info ...)attempted-user  2014-4117      URL
59400FILE-OFFICE Microsoft Word tblStylePr use after free attempt (more info ...)attempted-user  2014-4117      URL
59401FILE-OFFICE Microsoft Word tblStylePr use after free attempt (more info ...)attempted-user  2014-4117      URL
59432SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance Password command injection attempt (more info ...)web-application-attack  2020-8466      
59433SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance Password command injection attempt (more info ...)web-application-attack  2020-8466      
59434SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance Password command injection attempt (more info ...)web-application-attack  2020-8466      
59435SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance Password command injection attempt (more info ...)web-application-attack  2020-8466      
59585FILE-OFFICE Microsoft Office XML nested num tag double-free attempt (more info ...)attempted-user  2015-1650      
59946POLICY-OTHER Sumavision Enhanced Multimedia Router privileged account creation detected (more info ...)policy-violation  2020-10181      URL
60035FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1527 attack attempt (more info ...)attempted-user  2022-32543      URL
60036FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1527 attack attempt (more info ...)attempted-user  2022-32543      URL
60037FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1527 attack attempt (more info ...)attempted-user  2022-32543      URL
60038FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1527 attack attempt (more info ...)attempted-user  2022-32543      URL
60039FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1533 attack attempt (more info ...)attempted-user  2022-29886      URL
60040FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1533 attack attempt (more info ...)attempted-user  2022-29886      URL
60041FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1533 attack attempt (more info ...)attempted-user  2022-29886      URL
60042FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1533 attack attempt (more info ...)attempted-user  2022-29886      URL
60500FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1591 attack attempt (more info ...)attempted-user        URL
60501FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1591 attack attempt (more info ...)attempted-user        URL
60637MALWARE-OTHER MultiOS.Backdoor.antSword inbound connection attempt (more info ...)trojan-activity        URL
61091FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1684 attack attempt (more info ...)attempted-user  2022-45115      URL
61092FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1684 attack attempt (more info ...)attempted-user  2022-45115      URL
61163FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1687 attack attempt (more info ...)attempted-dos  2023-22291      URL
61164FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1687 attack attempt (more info ...)attempted-dos  2023-22291      URL
61393FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1722 attack attempt (more info ...)attempted-user  2023-22660      URL
61394FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1722 attack attempt (more info ...)attempted-user  2023-22660      URL
61459FILE-OFFICE Microsoft Office RTF font table memory corruption attempt (more info ...)attempted-user  2023-21716      URL
61460FILE-OFFICE Microsoft Office RTF font table memory corruption attempt (more info ...)attempted-user  2023-21716      URL
61478FILE-OFFICE Microsoft Office Outlook appointment privilege escalation attempt (more info ...)attempted-user  2023-23397      URL
61479FILE-OFFICE Microsoft Office Outlook appointment privilege escalation attempt (more info ...)attempted-user  2023-23397      URL
61503FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1730 attack attempt (more info ...)attempted-user        URL
61504FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1730 attack attempt (more info ...)attempted-user        URL
61505FILE-OFFICE Microsoft Office Outlook appointment privilege escalation attempt (more info ...)attempted-user  2023-23397      URL
61506FILE-OFFICE Microsoft Office Outlook appointment privilege escalation attempt (more info ...)attempted-user  2023-23397      URL
61574FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1734 attack attempt (more info ...)attempted-user        URL
61575FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1734 attack attempt (more info ...)attempted-user        URL
61716FILE-OFFICE Microsoft Office Outlook remote code execution attempt (more info ...)attempted-user  2023-29325      URL
61717FILE-OFFICE Microsoft Office Outlook remote code execution attempt (more info ...)attempted-user  2023-29325      URL
61781FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1748 attack attempt (more info ...)attempted-user  2023-31275      URL
61782FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1748 attack attempt (more info ...)attempted-user  2023-31275      URL
61957FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1758 attack attempt (more info ...)attempted-user  2023-34366      URL
61958FILE-OFFICE TRUFFLEHUNTER TALOS-2023-1758 attack attempt (more info ...)attempted-user  2023-34366      URL
62053FILE-OFFICE Microsoft Office RTF object remote code execution attempt (more info ...)attempted-user  2023-36884      
62054FILE-OFFICE Microsoft Office RTF object remote code execution attempt (more info ...)attempted-user  2023-36884      
62121SERVER-WEBAPP WooCommerce WordPress elevation of privilege attempt (more info ...)web-application-attack  2023-28121      URL
62122SERVER-WEBAPP WooCommerce WordPress elevation of privilege attempt (more info ...)web-application-attack  2023-28121      URL


# of warning rules in this group: 1246

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
233MALWARE-OTHER Trin00 Attacker to Master default startup password (more info ...)attempted-dos 2000-0138   URL
234MALWARE-OTHER Trin00 Attacker to Master default password (more info ...)attempted-dos 2000-0138   URL
235MALWARE-OTHER Trin00 Attacker to Master default mdie password (more info ...)attempted-dos 2000-0138   URL
237MALWARE-OTHER Trin00 Master to Daemon default password attempt (more info ...)attempted-dos 2000-0138   URL
505SERVER-OTHER Insecure TIMBUKTU Password (more info ...)bad-unknown    
1098SERVER-WEBAPP SmartWin CyberOffice Shopping Cart access (more info ...)web-application-attack 2000-0925 1734  
1192SERVER-WEBAPP Trend Micro OfficeScan access (more info ...)attempted-recon  1057  
1381SERVER-WEBAPP Trend Micro OfficeScan attempt (more info ...)attempted-recon  1057  
1860SERVER-WEBAPP Linksys router default password login attempt (more info ...)default-login-attempt   10999 URL
2027PROTOCOL-RPC yppasswd old password overflow attempt UDP (more info ...)rpc-portmap-decode 2001-0779 2763  
2028PROTOCOL-RPC yppasswd old password overflow attempt TCP (more info ...)rpc-portmap-decode 2001-0779 2763  
2029PROTOCOL-RPC yppasswd new password overflow attempt UDP (more info ...)rpc-portmap-decode 2001-0779 2763  
2030PROTOCOL-RPC yppasswd new password overflow attempt TCP (more info ...)rpc-portmap-decode 2001-0779 2763  
2114PROTOCOL-SERVICES rexec password overflow attempt (more info ...)attempted-admin    
2230SERVER-WEBAPP NetGear router default password login attempt admin/password (more info ...)default-login-attempt   11737 URL
2408SERVER-WEBAPP Invision Power Board search.pl access (more info ...)web-application-activity 2004-0338 9766  
4150BROWSER-PLUGINS Microsoft Office Outlook View OVCtl ActiveX function call access (more info ...)attempted-user 2001-0538 3026  URL
4175BROWSER-PLUGINS Microsoft Office 2000/2002 Web Components PivotTable ActiveX object access (more info ...)attempted-user 2002-0727 4449  URL
4177BROWSER-PLUGINS Microsoft Office Web Components OWC.Spreadsheet.9 ActiveX clsid access attempt (more info ...)attempted-user 2006-4695 4453  URL
4178BROWSER-PLUGINS Microsoft Office 2000 and 2002 Web Components Record Navigation Control ActiveX object access (more info ...)attempted-user 2002-0727 4449  URL
4217BROWSER-PLUGINS Microsoft Office Services on the Web Free/Busy ActiveX object access (more info ...)attempted-user 2005-2127   URL
4218BROWSER-PLUGINS Microsoft Microsoft Windows Visual Basic WebClass ActiveX object access (more info ...)attempted-user 2005-2127   URL
4229BROWSER-PLUGINS Microsoft Internet Explorer MSAPP Export Support for Office Access ActiveX object access (more info ...)attempted-user 2005-2127   URL
5780MALWARE-OTHER Keylogger runtime detection - hwpe word filtered echelon log (more info ...)successful-recon-limited    URL
5782MALWARE-OTHER Keylogger runtime detection - hwae word filtered echelon log (more info ...)successful-recon-limited    URL
5892PUA-TOOLBARS Trackware wordiq toolbar runtime detection - get link info (more info ...)successful-recon-limited    URL
5893PUA-TOOLBARS Trackware wordiq toolbar runtime detection - search keyword (more info ...)successful-recon-limited    URL
5958MALWARE-TOOLS Hacker-Tool ghostvoice 1.02 runtime detection - init connection with password requirement (more info ...)misc-activity    URL
5959PUA-ADWARE Hijacker raxsearch detection - send search keywords to raxsearch (more info ...)misc-activity    URL
5962PUA-ADWARE Hijacker searchfast detection - catch search keyword (more info ...)misc-activity    URL
5992MALWARE-CNC User-Agent known malicious user agent - Mirar_KeywordContentHijacker (more info ...)misc-activity    URL
6185PUA-ADWARE Adware 180Search assistant runtime detection - reporting keyword (more info ...)misc-activity    URL
6192PUA-ADWARE Adware seekmo runtime detection - reporting keyword (more info ...)misc-activity    URL
6278PUA-TOOLBARS Trickler navexcel search toolbar runtime detection - activate/update (more info ...)misc-activity    URL
6309MALWARE-BACKDOOR net demon runtime detection - initial connection - password request (more info ...)trojan-activity    URL
6310MALWARE-BACKDOOR net demon runtime detection - initial connection - password send (more info ...)trojan-activity    URL
6311MALWARE-BACKDOOR net demon runtime detection - initial connection - password accepted (more info ...)trojan-activity    
6471SERVER-OTHER RealVNC password authentication bypass attempt (more info ...)attempted-admin 2006-2369 17978  
7002FILE-OFFICE Microsoft Office Excel url unicode overflow attempt (more info ...)attempted-user 2011-0104 18500  URL
7025FILE-OFFICE Microsoft Office Excel url unicode overflow attempt (more info ...)attempted-user 2006-3014 18583  URL
7048FILE-OFFICE Microsoft Office Excel object record overflow attempt (more info ...)attempted-user 2006-1306 18886  URL
7087MALWARE-BACKDOOR sinique 1.0 runtime detection - initial connection with correct password client-to-server (more info ...)trojan-activity    URL
7088MALWARE-BACKDOOR sinique 1.0 runtime detection - initial connection with correct password server-to-client (more info ...)trojan-activity    URL
7089MALWARE-BACKDOOR sinique 1.0 runtime detection - initial connection with wrong password -client-to-server (more info ...)trojan-activity    URL
7090MALWARE-BACKDOOR sinique 1.0 runtime detection - initial connection with wrong password server-to-client (more info ...)trojan-activity    URL
7197FILE-OFFICE Microsoft Office Excel MSO.DLL malformed string parsing single byte buffer over attempt (more info ...)attempted-user 2006-1540 17252  URL
7202FILE-OFFICE Microsoft Office Word document summary information string overflow attempt (more info ...)attempted-user 2006-1540   URL
7205FILE-OFFICE Microsoft Office Excel FngGroupCount record overflow attempt (more info ...)attempted-user 2006-1308 18890  
7517PUA-ADWARE Hijacker chinese keywords outbound connection (more info ...)misc-activity    URL
7616MALWARE-BACKDOOR theef 2.0 runtime detection - connection without password (more info ...)trojan-activity    URL
7617MALWARE-BACKDOOR theef 2.0 runtime detection - connection request with password - flowbit 1 (more info ...)trojan-activity    
7618MALWARE-BACKDOOR theef 2.0 runtime detection - connection request with password - flowbit 2 (more info ...)trojan-activity    
7619MALWARE-BACKDOOR theef 2.0 runtime detection - connection request with password (more info ...)trojan-activity    URL
7785MALWARE-BACKDOOR forced control uploader runtime detection - connection with password (more info ...)trojan-activity    
7833PUA-ADWARE Hijacker navexcel helper outbound connection - search (more info ...)misc-activity    URL
7870BROWSER-PLUGINS Microsoft Office Data Source Control 9.0 ActiveX clsid access (more info ...)attempted-user 2007-1201 28136  URL
7874BROWSER-PLUGINS Microsoft Office PivotTable 10.0 ActiveX clsid access (more info ...)attempted-user 2002-0861   URL
8358PUA-ADWARE Hijacker yok supersearch outbound connection - addressbar keyword search hijack (more info ...)misc-activity    URL
8397BROWSER-PLUGINS Microsoft Office List 11.0 ActiveX clsid access (more info ...)attempted-user    
8422BROWSER-PLUGINS Microsoft Office Outlook View OVCtl ActiveX clsid access (more info ...)attempted-user 2017-11774 3026  URL
8448FILE-OFFICE Microsoft Office Excel colinfo XF record overflow attempt (more info ...)attempted-user 2006-3875   URL
8708SERVER-WEBAPP Wordpress cache_lastpostdate code injection attempt (more info ...)attempted-admin 2005-2612 14533  
8723BROWSER-PLUGINS Microsoft Office Data Source Control 11.0 ActiveX clsid access (more info ...)attempted-user 2006-3729 24462  URL
8738BROWSER-PLUGINS Macrovision InstallShield Update Service ActiveX clsid access (more info ...)attempted-user 2007-5660 31235  URL
8740BROWSER-PLUGINS Macrovision InstallShield Update Service ActiveX function call access (more info ...)attempted-user 2007-5660 31235  URL
9431FILE-OFFICE Microsoft Office Outlook Express NNTP response overflow attempt (more info ...)attempted-user 2005-1213 13951  URL
9645PUA-ADWARE Hijacker sogou outbound connection - keyword hijack (more info ...)misc-activity    URL
9841SERVER-MAIL Microsoft Office Outlook VEVENT overflow attempt (more info ...)attempted-user 2007-0033 21931  URL
9847FILE-OFFICE Microsoft Office Outlook Saved Search download attempt (more info ...)attempted-user 2007-0034   URL
10087SERVER-OTHER VNC password request buffer overflow attempt (more info ...)web-application-attack 2006-1652 2305  
10123PROTOCOL-VOIP PA168 chipset based IP phone default password attempt (more info ...)attempted-admin 2007-0528 22191  URL
10175BROWSER-PLUGINS Trend Micro OfficeScan Client ActiveX function call access (more info ...)attempted-user 2007-0325 22585  
10445MALWARE-BACKDOOR acidbattery 1.0 runtime detection - get password (more info ...)trojan-activity    URL
11176BROWSER-PLUGINS Microsoft Office PowerPoint Viewer ActiveX clsid access (more info ...)attempted-user 2007-2494 33243  URL
11178BROWSER-PLUGINS Microsoft Office PowerPoint Viewer ActiveX function call access (more info ...)attempted-user 2007-2494 33243  URL
11181BROWSER-PLUGINS Microsoft Office Excel Viewer ActiveX clsid access (more info ...)attempted-user 2007-2495 33243  URL
11183BROWSER-PLUGINS Microsoft Office Excel Viewer ActiveX function call access (more info ...)attempted-user 2007-2495 33243  URL
11186SERVER-OTHER CA eTrust key handling dos -- password (more info ...)denial-of-service 2007-1005 22743  
11187BROWSER-PLUGINS Microsoft Office Word Viewer ActiveX clsid access (more info ...)attempted-user 2007-2496 33243  URL
11189BROWSER-PLUGINS Microsoft Office Word Viewer ActiveX function call access (more info ...)attempted-user 2007-2496 33243  URL
11199BROWSER-PLUGINS Microsoft Office Viewer ActiveX clsid access (more info ...)attempted-user 2009-0382 33283  URL
11201BROWSER-PLUGINS Microsoft Office Viewer ActiveX function call access (more info ...)attempted-user 2009-0382 33283  URL
11622BROWSER-PLUGINS Microsoft Office 2000 OUACTR ActiveX clsid access (more info ...)attempted-user 2007-2903 24118  URL
11660BROWSER-PLUGINS EDraw Office Viewer ActiveX clsid access (more info ...)attempted-user 2007-3169 24230  URL
11662BROWSER-PLUGINS EDraw Office Viewer ActiveX function call access (more info ...)attempted-user 2007-3169 24230  URL
12070FILE-OFFICE Microsoft Office Excel malformed version field (more info ...)attempted-user 2007-1756 24801  URL
12099FILE-OFFICE Microsoft Office Excel rtWindow1 record handling arbitrary code execution attempt (more info ...)attempted-user 2007-3029 22555  URL
12184FILE-OFFICE Microsoft Office Excel workbook workspace designation handling arbitrary code execution attempt (more info ...)attempted-user 2007-3030 24803  URL
12233MALWARE-BACKDOOR theef 2.10 runtime detection - connect with no password (more info ...)trojan-activity    
12234MALWARE-BACKDOOR theef 2.10 runtime detection - connect with no password (more info ...)trojan-activity    URL
12235MALWARE-BACKDOOR theef 2.10 runtime detection - connect with password (more info ...)trojan-activity    
12236MALWARE-BACKDOOR theef 2.10 runtime detection - connect with password (more info ...)trojan-activity    URL
12261BROWSER-PLUGINS Microsoft Visual Basic 6 PDWizard.File ActiveX clsid access (more info ...)attempted-user 2007-3041   URL
12263BROWSER-PLUGINS Microsoft Visual Basic 6 PDWizard.File ActiveX function call access (more info ...)attempted-user 2007-3041   URL
12265BROWSER-PLUGINS Microsoft Visual Basic 6 SearchHelper ActiveX clsid access (more info ...)attempted-user 2007-2216   URL
12267BROWSER-PLUGINS Microsoft Visual Basic 6 SearchHelper ActiveX function call access (more info ...)attempted-user 2007-2216   URL
12269BROWSER-PLUGINS Microsoft Visual Basic 6 TLIApplication ActiveX clsid access (more info ...)attempted-user 2007-2216   URL
12270BROWSER-PLUGINS Microsoft Visual Basic 6 TLIApplication ActiveX function call (more info ...)attempted-user 2007-2216   URL
12273BROWSER-PLUGINS Microsoft Visual Basic 6 TypeLibInfo ActiveX clsid access (more info ...)attempted-user 2007-2216   URL
12275BROWSER-PLUGINS Microsoft Visual Basic 6 TypeLibInfo ActiveX function call access (more info ...)attempted-user 2007-2216   URL
12284FILE-OFFICE Microsoft Office Excel rtWnDesk record memory corruption exploit attempt (more info ...)attempted-user 2007-3890   URL
12430BROWSER-PLUGINS EDraw Office Viewer Component ActiveX clsid access (more info ...)attempted-user 2007-4821 25892  
12432BROWSER-PLUGINS EDraw Office Viewer Component ActiveX function call access (more info ...)attempted-user 2007-4821 25892  
12618FILE-OTHER Microsoft Visual Basic VBP file reference overflow attempt (more info ...)attempted-user 2007-4776 25629  
12629SERVER-WEBAPP Microsoft Office SharePoint cross site scripting attempt (more info ...)web-application-attack 2007-2581 23832  URL
12641FILE-IDENTIFY Microsoft Word for Mac 5 file magic detected (more info ...)misc-activity 2007-3899 25906  URL
13277PUA-ADWARE Adware netword agent runtime detection (more info ...)misc-activity    URL
13325BROWSER-PLUGINS Macrovision FLEXnet Connect ActiveX clsid access (more info ...)attempted-user 2008-4587 27279  
13327BROWSER-PLUGINS Macrovision FLEXnet Connect ActiveX function call access (more info ...)attempted-user 2008-4587 27279  
13466FILE-OFFICE Microsoft Works file converter file section length headers memory corruption attempt (more info ...)attempted-user 2007-0216 27657  URL
13469FILE-OFFICE Microsoft Word ole stream memory corruption attempt (more info ...)attempted-user 2008-0109   URL
13471FILE-OFFICE Microsoft Office Publisher invalid pathname overwrite attempt (more info ...)attempted-user 2008-0104   URL
13472FILE-OFFICE Microsoft Works file converter field length invalid chunk size buffer overflow attempt (more info ...)attempted-user 2008-0108 27659  URL
13556PUA-ADWARE Hijacker kword interkey outbound connection - search traffic 1 (more info ...)misc-activity    URL
13557PUA-ADWARE Hijacker kword interkey outbound connection - search traffic 2 (more info ...)misc-activity    URL
13558PUA-ADWARE Hijacker kword interkey outbound connection - log user info (more info ...)misc-activity    URL
13569FILE-OFFICE Microsoft Office Excel macro validation arbitrary code execution attempt (more info ...)attempted-user 2008-0081   URL
13572FILE-OFFICE Microsoft Office PowerPoint malformed shapeid arbitrary code execution attempt (more info ...)attempted-user 2008-0118 28146  URL
13573FILE-OFFICE Microsoft Office Outlook arbitrary command line attempt (more info ...)misc-attack 2008-0110   URL
13580BROWSER-PLUGINS Microsoft Office Web Components remote code execution attempt ActiveX clsid access (more info ...)attempted-user 2006-4695   URL
13629FILE-IDENTIFY Microsoft Office Access JSDB file magic detected (more info ...)misc-activity 2008-1092 26468  URL
13630FILE-IDENTIFY Microsoft Office Access TJDB file magic detected (more info ...)misc-activity 2008-1092 26468  URL
13633FILE-IDENTIFY Microsoft Office Access MSISAM file magic detected (more info ...)misc-activity 2008-1092 26468  URL
13665FILE-OFFICE Microsoft Office Visio DXF file invalid memory allocation exploit attempt (more info ...)attempted-user 2008-1090   URL
13790FILE-OFFICE Microsoft Word malformed css remote code execution attempt (more info ...)attempted-user 2008-1434   URL
13803FILE-OFFICE RTF control word overflow attempt (more info ...)attempted-user 2008-1091   URL
13895SERVER-MAIL Microsoft Office Outlook Web Access invalid CSS escape sequence script execution attempt (more info ...)misc-attack 2008-2248   URL
13958FILE-OFFICE WordPerfect Graphics file invalid RLE buffer overflow attempt (more info ...)attempted-user 2008-3460   URL
14262FILE-OFFICE Microsoft Office OneNote iframe caller exploit attempt (more info ...)web-application-attack 2008-3007   URL
14610SERVER-WEBAPP Joomla invalid token administrative password reset attempt (more info ...)attempted-admin 2008-3681 30667  URL
14642FILE-OFFICE Microsoft Office Excel file with embedded ActiveX control (more info ...)attempted-user 2008-3477   URL
14765BROWSER-PLUGINS Macrovision InstallShield Update Service Agent ActiveX function call (more info ...)attempted-user 2008-2470 31235  
14997BROWSER-PLUGINS DjVu MSOffice Converter ActiveX clsid access (more info ...)attempted-user 2008-4922 31987  
15082FILE-OFFICE Microsoft Office Word rtf malformed dpcallout buffer overflow attempt (more info ...)attempted-user 2008-4028 32585  URL
15083FILE-OFFICE Microsoft Office Word .rtf file double free attempt (more info ...)attempted-user 2008-4027   URL
15088BROWSER-PLUGINS Microsoft Windows Visual Basic Charts ActiveX clsid access (more info ...)attempted-user 2008-4256   URL
15090BROWSER-PLUGINS Microsoft Windows Visual Basic Charts ActiveX function call access (more info ...)attempted-user 2008-4256   URL
15092BROWSER-PLUGINS Microsoft Windows Visual Basic DataGrid ActiveX clsid access (more info ...)attempted-user 2008-4252   URL
15094BROWSER-PLUGINS Microsoft Windows Visual Basic DataGrid ActiveX function call access (more info ...)attempted-user 2008-4252   URL
15096BROWSER-PLUGINS Microsoft Windows Visual Basic FlexGrid ActiveX clsid access (more info ...)attempted-user 2008-4253   URL
15098BROWSER-PLUGINS Microsoft Windows Visual Basic FlexGrid ActiveX function call access (more info ...)attempted-user 2008-4253   URL
15100BROWSER-PLUGINS Microsoft Windows Visual Basic Hierarchical FlexGrid ActiveX clsid access (more info ...)attempted-user 2008-4254   URL
15102BROWSER-PLUGINS Microsoft Windows Visual Basic Hierarchical FlexGrid ActiveX function call access (more info ...)attempted-user 2008-4254   URL
15104FILE-MULTIMEDIA Microsoft Windows Visual Basic 6.0 malformed AVI buffer overflow attempt (more info ...)attempted-user 2008-4255   URL
15106FILE-OFFICE Microsoft Office Word .rtf file integer overflow attempt (more info ...)misc-attack 2008-4025   URL
15107FILE-OFFICE Microsoft Office Word .rtf file stylesheet buffer overflow attempt (more info ...)attempted-user 2008-4031   URL
15108SERVER-WEBAPP Microsoft Office SharePoint Server elevation of privilege exploit attempt (more info ...)attempted-admin 2008-4032   URL
15119BROWSER-PLUGINS Microsoft Visual Basic Winsock ActiveX clsid unicode access (more info ...)attempted-user 2008-4251   URL
15121BROWSER-PLUGINS Microsoft Visual Basic Winsock ActiveX function call unicode access (more info ...)attempted-user 2008-4251   URL
15163FILE-OFFICE Microsoft Office Visio Object Header Buffer Overflow attempt (more info ...)attempted-user 2008-1089   
15230BROWSER-PLUGINS Microsoft Office Viewer 2 ActiveX clsid access (more info ...)attempted-user 2007-2588 33245  URL
15282BROWSER-PLUGINS FlexCell Grid ActiveX clsid access (more info ...)attempted-user 2009-0301 33453  
15298FILE-OFFICE Microsoft Visio could allow remote code execution (more info ...)attempted-user 2009-0097   URL
15299FILE-OFFICE Microsoft Office Visio invalid ho tag attempt (more info ...)attempted-user 2009-0096 33660  URL
15303FILE-OFFICE Microsoft Office Visio Malformed IconBitsComponent arbitrary code execution attempt (more info ...)attempted-user 2009-0095   URL
15334BROWSER-PLUGINS GeoVision LiveX 7000 ActiveX clsid access (more info ...)attempted-user 2009-0865 33782  
15336BROWSER-PLUGINS GeoVision LiveX 7000 ActiveX function call access (more info ...)attempted-user 2009-0865 33782  
15338BROWSER-PLUGINS GeoVision LiveX 8120 ActiveX clsid access (more info ...)attempted-user 2009-0865 33782  
15340BROWSER-PLUGINS GeoVision LiveX 8120 ActiveX function call access (more info ...)attempted-user 2009-0865 33782  
15342BROWSER-PLUGINS GeoVision LiveX 8200 ActiveX clsid access (more info ...)attempted-user 2009-0865 33782  
15344BROWSER-PLUGINS GeoVision LiveX 8200 ActiveX function call access (more info ...)attempted-user 2009-0865 33782  
15367FILE-OFFICE Microsoft Office Outlook web access script injection attempt (more info ...)attempted-user 2006-1193 18381  
15454FILE-OFFICE Microsoft Office PowerPoint malformed msofbtTextbox exploit attempt (more info ...)attempted-user 2009-0556   URL
15455FILE-OFFICE Microsoft Office WordPad and Office Text Converters XST parsing buffer overflow attempt (more info ...)attempted-user 2008-4841   URL
15465FILE-OFFICE Microsoft Excel malformed object record remote code execution attempt (more info ...)attempted-user 2009-0100   URL
15466FILE-OFFICE Microsoft Office WordPad WordPerfect 6.x converter buffer overflow attempt (more info ...)attempted-user 2009-0088   URL
15467FILE-OFFICE Microsoft Office WordPad and Office Text Converters PlcPcd aCP buffer overflow attempt (more info ...)attempted-user 2009-0235   URL
15488SERVER-ORACLE Oracle Database Application Express Component APEX password hash disclosure attempt (more info ...)misc-attack 2009-0981 34461  URL
15499FILE-OFFICE Microsoft Office PowerPoint PP7 Component buffer overflow attempt (more info ...)attempted-user 2009-1129   URL
15500FILE-OFFICE Microsoft Office PowerPoint LinkedSlide memory corruption (more info ...)attempted-user 2009-0221   URL
15501FILE-OFFICE Microsoft Office PowerPoint ParaBuildAtom memory corruption attempt (more info ...)attempted-user 2009-0224   URL
15502FILE-OFFICE Microsoft Office PowerPoint DiagramBuildContainer memory corruption attempt (more info ...)attempted-user 2009-0224   URL
15503FILE-OFFICE Download of PowerPoint 95 file (more info ...)attempted-user    URL
15505FILE-OFFICE Microsoft Office PowerPoint HashCode10Atom memory corruption attempt (more info ...)attempted-user 2009-1130   URL
15506FILE-OFFICE Microsoft Office PowerPoint CurrentUserAtom remote code execution attempt (more info ...)attempted-user 2009-1131   URL
15524FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0563   URL
15525FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0565   URL
15526FILE-OFFICE Microsoft Works 4.x converter font name buffer overflow attempt (more info ...)attempted-user 2009-1533   URL
15539FILE-OFFICE Microsoft Office Excel Formula record remote code execution attempt (more info ...)attempted-user 2009-0560 35244  URL
15541FILE-OFFICE Microsoft Office Excel SST record remote code execution attempt (more info ...)attempted-user 2009-3037 36042  URL
15542FILE-OFFICE Microsoft Office Excel Qsir and Qsif record remote code execution attempt (more info ...)attempted-user 2009-1134   URL
15681FILE-OFFICE Microsoft Office Publisher 2007 file format arbitrary code execution attempt (more info ...)attempted-user 2009-0566   URL
15687BROWSER-PLUGINS Microsoft Office Web Components 10 Spreadsheet ActiveX function call access (more info ...)attempted-user 2009-2496   URL
15691BROWSER-PLUGINS Microsoft Office Web Components 11 Spreadsheet ActiveX function call access (more info ...)attempted-user 2009-1136   URL
15852BROWSER-PLUGINS Microsoft Office Web Components Datasource ActiveX clsid access (more info ...)attempted-user 2009-0562   URL
15855BROWSER-PLUGINS Microsoft Office Spreadsheet 10.0 ActiveX function call access (more info ...)attempted-user 2009-2496   URL
15858BROWSER-PLUGINS Microsoft Office Web Components Spreadsheet ActiveX clsid access (more info ...)attempted-user 2009-1534   URL
15913OS-WINDOWS Microsoft Windows javascript arguments keyword override rce attempt (more info ...)attempted-user 2009-1920   URL
15947FILE-OFFICE Microsoft Office Outlook Web Access Cross-Site Scripting attempt (more info ...)attempted-user 2005-0563 13952  
16051FILE-OFFICE Microsoft Office Publisher 2007 conversion library code execution attempt (more info ...)attempted-user 2007-1754 22702  URL
16059FILE-OFFICE Microsoft Office Excel malformed file format parsing code execution attempt (more info ...)attempted-user 2006-0028   URL
16177FILE-OFFICE Microsoft Office Word GDI+ Office Art Property Table remote code execution attempt (more info ...)attempted-user 2009-2528   URL
16178FILE-OFFICE Microsoft Office Excel GDI+ Office Art Property Table remote code execution attempt (more info ...)attempted-user 2009-2528   URL
16188FILE-OFFICE Microsoft Office PowerPoint bad text header txttype attempt (more info ...)attempted-user 2011-1269   URL
16226FILE-OFFICE Microsoft Office Excel integer field in row record improper validation remote code execution attempt (more info ...)attempted-user 2009-3130   URL
16228FILE-OFFICE Microsoft Office Excel malformed StartObject record arbitrary code execution attempt (more info ...)attempted-admin 2009-3134   URL
16229FILE-OFFICE Microsoft Office Excel oversized ib memory corruption attempt (more info ...)attempted-user 2009-3131   URL
16230FILE-OFFICE Microsoft Excel oversized ib memory corruption attempt (more info ...)attempted-user 2009-3131   URL
16233FILE-OFFICE Microsoft Office Excel oversized ptgFuncVar cparams value buffer overflow attempt (more info ...)attempted-user 2009-3132   URL
16234FILE-OFFICE Microsoft Office Word Document remote code execution attempt (more info ...)attempted-user 2016-3283   URL
16235FILE-OFFICE Microsoft Office Excel file SXDB record exploit attempt (more info ...)attempted-user 2009-3127   URL
16236FILE-OFFICE Microsoft Office Excel file SxView record exploit attempt (more info ...)attempted-user 2009-3128   URL
16240FILE-OFFICE Microsoft Office Excel file Window/Pane record exploit attempt (more info ...)attempted-user 2009-3133   URL
16241FILE-OFFICE Microsoft Office Excel FeatHdr BIFF record remote code execution attempt (more info ...)attempted-user 2009-3129   URL
16314FILE-OFFICE Microsoft Windows WordPad and Office text converter integer overflow attempt (more info ...)attempted-user 2009-2506   URL
16318FILE-OFFICE Microsoft Office Visio invalid ho tag attempt (more info ...)attempted-user 2009-0096 33660  URL
16328FILE-OFFICE Microsoft Office Project file parsing arbitrary memory access attempt (more info ...)attempted-user 2009-0102   URL
16361FILE-OFFICE Microsoft Office BMP header biClrUsed integer overflow attempt (more info ...)attempted-admin 2009-2518 36651  
16409FILE-OFFICE Microsoft Office PowerPoint improper filename remote code execution attempt (more info ...)attempted-user 2010-0029   URL
16410FILE-OFFICE Microsoft Office PowerPoint file LinkedSlide10Atom record parsing heap corruption attempt (more info ...)attempted-user 2010-0030   URL
16412FILE-OFFICE Microsoft Office PowerPoint invalid TextByteAtom remote code execution attempt (more info ...)attempted-user 2010-0033   URL
16416FILE-OFFICE Microsoft Office Excel Malformed MSODrawing Record attempt (more info ...)attempted-user 2010-0243   URL
16421FILE-OFFICE Microsoft Office PowerPoint out of bounds value remote code execution attempt (more info ...)attempted-user 2010-0032   URL
16428FILE-OFFICE Microsoft Office Outlook Express and Windows Mail NNTP handling buffer overflow attempt (more info ...)attempted-user 2007-3897   URL
16462FILE-OFFICE Microsoft Office Excel BIFF8 formulas from records parsing code execution attempt (more info ...)attempted-user 2010-0258   URL
16463FILE-OFFICE Microsoft Office Excel BIFF5 formulas from records parsing code execution attempt (more info ...)attempted-user 2010-0258   URL
16464FILE-OFFICE Microsoft Office Excel ContinueFRT12 heap overflow attempt (more info ...)attempted-user 2010-0260   URL
16465FILE-OFFICE Microsoft Office Excel ContinueFRT12 and MDXSet heap overflow attempt (more info ...)attempted-user 2010-0261   URL
16466FILE-OFFICE Microsoft Office Excel uninitialized stack variable code execution attempt (more info ...)attempted-user 2010-0262   URL
16467FILE-OFFICE Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt (more info ...)attempted-user 2010-0263   URL
16468FILE-OFFICE Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt (more info ...)attempted-user 2010-0263   URL
16469FILE-OFFICE Microsoft Office Excel DbOrParamQry.fOdbcConn parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
16470FILE-OFFICE Microsoft Office Excel DbOrParamQry.fWeb parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
16471FILE-OFFICE Microsoft Office Excel DbOrParamQry.fWeb parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
16535FILE-OFFICE Microsoft Office Visio improper attribute code execution attempt (more info ...)attempted-user 2010-0254   URL
16536FILE-OFFICE Microsoft Office Visio off-by-one in array index code execution attempt (more info ...)attempted-user 2010-0256   URL
16542FILE-OFFICE Microsoft Office Publisher 2007 and earlier stack buffer overflow attempt (more info ...)attempted-user 2010-0479 39347  URL
16553FILE-OFFICE Microsoft Office Excel ptg index parsing code execution attempt (more info ...)attempted-user 2009-3132   URL
16560SERVER-WEBAPP Microsoft Office SharePoint XSS attempt (more info ...)attempted-user 2010-0817   URL
16565BROWSER-PLUGINS Ultra Shareware Office Control ActiveX clsid access (more info ...)attempted-user 2008-3878 30861  
16586FILE-OFFICE Microsoft Office Word Document remote code execution attempt (more info ...)attempted-user 2009-3135   URL
16593FILE-OFFICE Microsoft VBE6.dll stack corruption attempt (more info ...)attempted-user 2010-0815 39931  URL
16639FILE-OFFICE Microsoft Office Excel OBJ record stack buffer overflow attempt - with macro (more info ...)attempted-user 2010-0822   URL
16640FILE-OFFICE Microsoft Office Excel OBJ record stack buffer overflow attempt - with linkFmla (more info ...)attempted-user 2010-0822   URL
16641FILE-OFFICE Microsoft Office Excel OBJ record stack buffer overflow attempt - with macro and linkFmla (more info ...)attempted-user 2010-0822   URL
16643FILE-OFFICE Microsoft Office Excel Chart Sheet Substream memory corruption attempt (more info ...)attempted-user 2010-0823   URL
16644FILE-OFFICE Microsoft Office Excel WOpt record memory corruption attempt (more info ...)attempted-user 2010-0824   URL
16645FILE-OFFICE Microsoft Office Excel SxView record memory pointer corruption attempt (more info ...)attempted-user 2010-1245   URL
16646FILE-OFFICE Microsoft Office Excel RTD buffer overflow attempt (more info ...)attempted-user 2010-1246   URL
16647FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt - 2 (more info ...)attempted-user 2010-1247   URL
16648FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt - 1 (more info ...)attempted-user 2010-1247   URL
16649FILE-OFFICE Microsoft Excel HFPicture record stack buffer overflow attempt (more info ...)attempted-user 2010-1248   URL
16650FILE-OFFICE Microsoft Office Excel ExternName record stack buffer overflow attempt - 1 (more info ...)attempted-user 2010-1249   URL
16651FILE-OFFICE Microsoft Office Excel ExternName record stack buffer overflow attempt - 2 (more info ...)attempted-user 2010-1249   URL
16652FILE-OFFICE Microsoft Office Excel ExternName record stack buffer overflow attempt - 3 (more info ...)attempted-user 2010-1249   URL
16653FILE-OFFICE Microsoft Office Excel ExternName record stack buffer overflow attempt - 4 (more info ...)attempted-user 2010-1249   URL
16656FILE-OFFICE Microsoft Office Excel BIFF5 ExternSheet record stack overflow attempt (more info ...)attempted-user 2010-1252   URL
16657FILE-OFFICE Microsoft Office Excel DBQueryExt record memory corruption attempt (more info ...)attempted-user 2010-1253   URL
16660SERVER-WEBAPP Microsoft Office SharePoint Server 2007 help.aspx denial of service attempt (more info ...)attempted-dos 2010-1264   URL
16786FILE-OFFICE Microsoft Office Web Components Spreadsheet ActiveX buffer overflow attempt (more info ...)attempted-user 2009-1534 35992  
16800FILE-OFFICE Microsoft Office Excel FRTWrapper record buffer overflow attempt (more info ...)attempted-user 2008-3471   URL
17037BROWSER-PLUGINS Microsoft Office Access multiple control instantiation memory corruption attempt (more info ...)attempted-user 2010-0814   URL
17038FILE-OFFICE Microsoft Office Access ACCWIZ library release after free attempt - 1 (more info ...)attempted-user 2010-1881   URL
17039FILE-OFFICE Microsoft Office Access ACCWIZ library release after free attempt - 2 (more info ...)attempted-user 2010-1881   URL
17119FILE-OFFICE Microsoft Office Word sprmCMajority SPRM overflow attempt (more info ...)attempted-user 2010-1900   URL
17120FILE-OFFICE Microsoft Office Word rich text format unexpected field type memory corruption attempt 1 (more info ...)attempted-user 2010-1901   URL
17121FILE-OFFICE Microsoft Office Word rich text format unexpected field type memory corruption attempt 2 (more info ...)attempted-user 2010-1901   URL
17122FILE-OFFICE Microsoft Office Word rich text format unexpected field type memory corruption attempt 3 (more info ...)attempted-user 2010-1901   URL
17123FILE-OFFICE Microsoft Office Word rich text format invalid field size memory corruption attempt (more info ...)attempted-user 2010-1902   URL
17124FILE-OFFICE Microsoft Office Word HTML linked objects memory corruption attempt (more info ...)attempted-user 2010-1903 42130  URL
17134FILE-OFFICE Microsoft Office Excel pivot item index boundary corruption attempt (more info ...)attempted-user 2010-2562 42199  URL
17227FILE-OFFICE Microsoft Office Excel sheet name memory corruption attempt (more info ...)attempted-user 2007-3490 24691  
17250FILE-OFFICE Microsoft Windows WordPad sprmTSetBrc SPRM overflow attempt (more info ...)attempted-user 2010-2563 43122  URL
17251FILE-OFFICE Outlook RTF remote code execution attempt (more info ...)attempted-admin 2010-2728   URL
17271FILE-OFFICE Microsoft Windows Web View script injection attempt (more info ...)attempted-user 2005-1191 13248  
17284FILE-OFFICE Microsoft Office malformed routing slip code execution attempt (more info ...)attempted-user 2006-0009 17000  
17286FILE-OTHER Microsoft Visual Basic for Applications document properties overflow attempt (more info ...)attempted-user 2006-3649 19414  
17292FILE-OFFICE Microsoft Office PowerPoint malformed data record code execution attempt (more info ...)attempted-user 2006-3876 20322  
17296SERVER-WEBAPP Microsoft Office Outlook Web Access XSRF attempt (more info ...)attempted-user 2010-3213 41462  URL
17301FILE-OFFICE Microsoft Office Word TextBox sub-document memory corruption attempt (more info ...)attempted-user 2007-1910 23380  
17304FILE-OFFICE Microsoft Works file converter file section header index table stack overflow attempt (more info ...)attempted-user 2008-0105 27658  
17308FILE-OFFICE Microsoft Office Word SmartTag record code execution attempt (more info ...)attempted-user 2008-2244 30124  
17310FILE-OFFICE Microsoft Office PowerPoint Viewer memory allocation code execution attempt (more info ...)attempted-user 2008-0120 30552  
17315FILE-OFFICE OpenOffice OLE file stream buffer overflow attempt (more info ...)attempted-user 2008-0320 28819  
17318FILE-OFFICE Microsoft Office PowerPoint MCAtom remote code execution attempt (more info ...)attempted-user 2006-5296 20495  
17319FILE-OFFICE Microsoft Office PowerPoint MCAtom remote code execution attempt (more info ...)attempted-user 2006-5296 20495  
17320FILE-OFFICE Microsoft Office PowerPoint MCAtom remote code execution attempt (more info ...)attempted-user 2006-5296 20495  
17344INDICATOR-SHELLCODE x86 OS agnostic xor dword decoder (more info ...)shellcode-detect    
17345INDICATOR-SHELLCODE x86 OS agnostic dword additive feedback decoder (more info ...)shellcode-detect    
17362FILE-OFFICE Microsoft Office Excel IMDATA buffer overflow attempt (more info ...)attempted-user 2007-0027 21856  
17368FILE-OFFICE Microsoft Office Word document stream handling code execution attempt (more info ...)attempted-user 2007-0870 25567  
17377FILE-OFFICE Microsoft Office Excel Malformed Filter Records Handling Code Execution attempt (more info ...)attempted-user 2007-1214 23780  
17383FILE-OFFICE Microsoft Office Publisher Object Handler Validation Code Execution attempted (more info ...)attempted-user 2008-0119 29158  
17403FILE-OFFICE OpenOffice RTF File parsing heap buffer overflow attempt (more info ...)attempted-user 2007-0245 24450  
17404FILE-OFFICE Microsoft Office Word Converter XST structure buffer overflow attempt (more info ...)attempted-user 2008-4841   URL
17405FILE-OFFICE Microsoft Office Word Converter XST structure buffer overflow attempt (more info ...)attempted-user 2008-4841   URL
17406FILE-OFFICE Microsoft Office Word Converter XST structure buffer overflow attempt (more info ...)attempted-user 2008-4841   URL
17421FILE-OFFICE Microsoft OLE automation string manipulation overflow attempt (more info ...)attempted-user 2007-2224 25282  
17488FILE-OFFICE Microsoft Office Excel Malformed Range Code Execution attempt (more info ...)attempted-user 2005-4131 15780  
17491FILE-OFFICE Microsoft Office Word mso.dll LsCreateLine memory corruption attempt (more info ...)attempted-user 2006-3493 18905  
17492FILE-OFFICE Microsoft Office Excel Malformed SELECTION Record Code Execution attempt (more info ...)attempted-user 2006-1301 18853  
17496FILE-OFFICE Microsoft Office PowerPoint malformed NamedShows record code execution attempt (more info ...)attempted-user 2006-4694 20226  
17497FILE-OFFICE Microsoft Office PowerPoint malformed NamedShows record code execution attempt (more info ...)attempted-user 2006-4694 20226  
17505FILE-OFFICE Microsoft Office Word formatted disk pages table memory corruption attempt (more info ...)attempted-user 2006-6561 21589  
17506FILE-OFFICE Microsoft Office Word formatted disk pages table memory corruption attempt (more info ...)attempted-user 2006-6561 21589  
17507FILE-OFFICE Microsoft Office Word formatted disk pages table memory corruption attempt (more info ...)attempted-user 2006-6561 21589  
17511FILE-OFFICE Microsoft Office Excel malformed Graphic Code Execution (more info ...)attempted-user 2006-0030 16181  
17537FILE-OFFICE Microsoft Office Excel unspecified memory corruption attempt (more info ...)attempted-user  15926  
17538FILE-OFFICE Microsoft Office Excel unspecified memory corruption attempt (more info ...)attempted-user  15926  
17539FILE-OFFICE Microsoft Office Excel unspecified memory corruption attempt (more info ...)attempted-user  15926  
17542FILE-OFFICE Microsoft Office Excel MalformedPalete Record Memory Corruption attempt (more info ...)attempted-user 2007-0031 21922  
17543FILE-OFFICE Microsoft Office Excel Column record handling memory corruption attempt (more info ...)attempted-user 2007-0030 21925  
17550FILE-OFFICE Microsoft Office Word Font Parsing Buffer Overflow attempt (more info ...)attempted-user 2005-0564 14216  
17555BROWSER-PLUGINS Macrovision InstallShield Update Service ActiveX exploit attempt (more info ...)attempted-user 2007-5660 31235  URL
17560FILE-OFFICE Microsoft Office Word global array index heap overflow attempt (more info ...)attempted-user 2008-4026 32583  
17565FILE-OFFICE Microsoft Office PowerPoint PP7 File Handling Memory Corruption attempt (more info ...)attempted-user 2009-0225 34880  
17568FILE-OFFICE Microsoft Office XP URL Handling Buffer Overflow attempt (more info ...)attempted-admin 2004-0848 12480  
17574FILE-OFFICE Sophos Anti-Virus Visio File Parsing Buffer Overflow attempt (more info ...)attempted-user 2005-2768 14362  
17578FILE-OFFICE Microsoft Office Word Section Table Array Buffer Overflow attempt (more info ...)attempted-user 2007-0515 22225  
17591FILE-OFFICE Microsoft Office Word invalid sprmTDefTable length stack buffer overflow attempt (more info ...)attempted-user 2008-4837 32584  URL
17646FILE-OFFICE Microsoft Office PowerPoint Legacy file format picture object code execution attempt (more info ...)attempted-user 2009-0223 34834  
17649FILE-OFFICE Microsoft Office Word array data handling buffer overflow attempt (more info ...)attempted-user 2007-0035 23804  
17655FILE-OFFICE Microsoft Office Excel malformed formula parsing code execution attempt (more info ...)attempted-user 2008-0115 28167  URL
17664FILE-OFFICE Microsoft Office GIF image descriptor memory corruption attempt (more info ...)attempted-user 2007-1071 22630  URL
17670BROWSER-PLUGINS BigAnt Office Manager ActiveX clsid access (more info ...)attempted-user  39721  
17672BROWSER-PLUGINS BigAnt Office Manager ActiveX function call access (more info ...)attempted-user  39721  
17690FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0565   URL
17691FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0565   URL
17695FILE-OFFICE Microsoft Office PowerPoint paragraph format array inner header overflow attempt (more info ...)attempted-user 2009-0220 34833  
17701BROWSER-PLUGINS Office Viewer ActiveX arbitrary command execution attempt (more info ...)attempted-user 2007-2588 33245  URL
17708SERVER-OTHER VNC password request URL buffer overflow attempt (more info ...)web-application-attack 2006-1652 17378  
17742FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0563   URL
17743FILE-OFFICE Microsoft Office Word RTF parsing memory corruption attempt (more info ...)attempted-user 2008-1091 29104  URL
17754FILE-OFFICE Microsoft Office Word bookmark bound check remote code execution attempt (more info ...)attempted-user 2010-3216   URL
17755FILE-OFFICE Microsoft Office Word unchecked index value remote code execution attempt (more info ...)attempted-user 2010-3219   URL
17756FILE-OFFICE Microsoft Office Word XP PLFLSInTableStream heap overflow attempt (more info ...)attempted-user 2010-3220   URL
17757FILE-OFFICE Microsoft Office Excel CrErr record integer overflow attempt (more info ...)attempted-user 2010-3230   URL
17758FILE-OFFICE Microsoft Office Excel PtgExtraArray data parsing vulnerability exploit attempt (more info ...)attempted-user 2010-3231 43647  URL
17759FILE-OFFICE Microsoft Office Excel invalid SerAr object exploit attempt (more info ...)attempted-user 2010-3239   URL
17760FILE-OFFICE Microsoft Office Excel RealTimeData record exploit attempt (more info ...)attempted-user 2010-3240 43655  URL
17763FILE-OFFICE Microsoft Office Excel GhostRw record exploit attempt (more info ...)attempted-user 2010-3242   URL
17764FILE-OFFICE Microsoft Office Excel PtgName invalid index exploit attempt (more info ...)attempted-user 2010-3235 43650  URL
17770FILE-OFFICE Microsoft HtmlDlgHelper ActiveX clsid access (more info ...)attempted-user 2010-3329   URL
18049POLICY-SPAM word.onlinephilbert42f.ru known spam email attempt (more info ...)policy-violation    
18063FILE-OFFICE Microsoft Office embedded Office Art drawings execution attempt (more info ...)attempted-user 2010-3334   URL
18065FILE-OFFICE Microsoft Office PowerPoint converter bad indirection remote code execution attempt (more info ...)attempted-user 2010-2572   URL
18068FILE-OFFICE Microsoft Office Excel malformed MsoDrawingObject record attempt (more info ...)attempted-user 2010-3335   URL
18069FILE-OFFICE Microsoft Office Art drawing invalid shape identifier attempt (more info ...)attempted-user 2010-3336   URL
18070FILE-OFFICE Microsoft Office pptimpconv.dll dll-load exploit attempt (more info ...)attempted-user 2010-3337   URL
18071FILE-OFFICE Microsoft Office pptimpconv.dll dll-load exploit attempt (more info ...)attempted-user 2010-3337   URL
18212FILE-OFFICE Microsoft Office Publisher tyo.oty field heap overflow attempt (more info ...)attempted-user 2010-2569   URL
18213FILE-OFFICE Microsoft Office Publisher column and row remote code execution attempt (more info ...)attempted-user 2010-2570   URL
18214FILE-OFFICE Microsoft Office Publisher 97 conversion remote code execution attempt (more info ...)attempted-user 2010-2571   URL
18230FILE-OFFICE Microsoft Office Publisher memory corruption attempt (more info ...)attempted-user 2010-3954   URL
18231FILE-OFFICE Microsoft Office Publisher oversized oti length attempt (more info ...)attempted-user 2010-3955   URL
18233FILE-OFFICE Microsoft Office Publisher Adobe Font Driver code execution attempt (more info ...)attempted-user 2010-3956   URL
18236FILE-OFFICE Microsoft Office TIFFIM32.FLT filter memory corruption attempt (more info ...)attempted-user 2010-3949   URL
18238SERVER-WEBAPP Microsoft Office SharePoint document conversion remote code excution attempt (more info ...)attempted-admin 2010-3964   URL
18265FILE-OFFICE Microsoft Office thumbnail bitmap invalid biClrUsed attempt (more info ...)attempted-user 2010-3970   URL
18284FILE-OFFICE Microsoft Office XP URL Handling Buffer Overflow attempt (more info ...)attempted-admin 2004-0848 12480  
18331FILE-OFFICE Microsoft Office Visio DXF variable name overflow attempt (more info ...)attempted-user 2010-1681 39836  
18345MALWARE-CNC User-Agent known malicious user-agent string Macrovision_DM_2.4.15 (more info ...)trojan-activity    URL
18398FILE-OFFICE Microsoft Office thumbnail bitmap invalid biClrUsed attempt (more info ...)attempted-user 2010-3970   URL
18399FILE-OFFICE Microsoft Office Excel BRAI record remote code execution attempt (more info ...)attempted-user 2009-0549   URL
18415FILE-OFFICE Microsoft Office Visio deserialization double free attempt (more info ...)attempted-user 2011-0092   URL
18416FILE-OFFICE Microsoft Office Visio ORMinfo classes length overflow attempt (more info ...)attempted-user 2011-0093   URL
18417FILE-OFFICE Microsoft Office Visio ORMinfo classes length overflow attempt (more info ...)attempted-user 2011-0093   URL
18514FILE-OFFICE Microsoft Office PowerPoint malformed shapeid arbitrary code execution attempt (more info ...)attempted-user 2008-0118 28146  URL
18515FILE-OFFICE Microsoft Office Visio VSD file icon memory corruption attempt (more info ...)attempted-user 2009-0095   URL
18535FILE-OFFICE Microsoft Office Word file sprmTSetBrc processing buffer overflow attempt (more info ...)attempted-user 2010-2563 38218  URL
18536FILE-OFFICE OpenOffice.org Microsoft Office Word file processing integer underflow attempt (more info ...)attempted-user 2009-3301 38218  
18537FILE-OTHER OpenOffice.org XPM file processing integer overflow attempt (more info ...)attempted-user 2009-2949 38218  
18538FILE-OFFICE Microsoft Office Excel PtgName invalid index exploit attempt (more info ...)attempted-user 2010-3235 43650  URL
18541FILE-OFFICE Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt (more info ...)attempted-user 2010-0263   URL
18547FILE-OFFICE Microsoft Office PowerPoint with embedded Flash file transfer (more info ...)attempted-user    
18548FILE-OFFICE Microsoft Office Excel with embedded Flash file attachment (more info ...)attempted-user 2016-3279   URL
18549FILE-OFFICE Microsoft Office Word with embedded Flash file attachment (more info ...)attempted-user    
18550FILE-OFFICE Microsoft Office PowerPoint with embedded Flash file attachment (more info ...)attempted-user    
18615FILE-OFFICE Microsoft Works 4.x converter font name buffer overflow attempt (more info ...)attempted-user 2009-1533   URL
18616FILE-OFFICE Microsoft Works 4.x converter font name buffer overflow attempt (more info ...)attempted-user 2009-1533   URL
18630FILE-OFFICE Microsoft Office Excel rtToolbarDef record integer overflow attempt (more info ...)attempted-user 2011-0097   URL
18631FILE-OFFICE Microsoft Office Excel rtToolbarDef record integer overflow attempt (more info ...)attempted-user 2011-0097   URL
18633FILE-OFFICE Microsoft Office Excel RealTimeData record memory corruption attempt (more info ...)attempted-user 2011-0101   URL
18634FILE-OFFICE Microsoft Office Excel Workspace file FontCount record memory corruption attempt (more info ...)attempted-user 2011-0103   URL
18635FILE-OFFICE Microsoft Office PowerPoint malformed record call to freed object attempt (more info ...)attempted-admin 2011-0655   URL
18636FILE-OFFICE Microsoft Office PowerPoint SlideAtom record exploit attempt (more info ...)attempted-user 2011-0656   URL
18638FILE-OFFICE Microsoft Office Excel drawing layer use after free attempt (more info ...)attempted-user 2011-0977 46227  URL
18640FILE-OFFICE Microsoft Office Excel malformed SupBook record attempt (more info ...)attempted-user 2011-0979   URL
18641FILE-OFFICE Microsoft Office Excel OBJ record invalid cmo.ot exploit attempt (more info ...)attempted-admin 2011-0980   URL
18642FILE-OFFICE Microsoft Office Word Converter sprmTSplit overflow attempt (more info ...)attempted-user 2011-0028 47236  URL
18643FILE-OFFICE Microsoft Office Word Converter sprmTTextFflow overflow attempt (more info ...)attempted-user 2011-0028 47236  URL
18676FILE-OFFICE Microsoft Office Excel DV record buffer overflow attempt (more info ...)attempted-user 2011-0105   URL
18740FILE-OFFICE Microsoft Office Excel sheet object type confusion exploit attempt (more info ...)attempted-user 2010-0258   URL
18755FILE-OFFICE Microsoft Office Visio Data Type Memory Corruption (more info ...)attempted-user 2011-0093 46138  
18758FILE-IDENTIFY Microsoft Windows Visual Basic script file download request (more info ...)misc-activity    URL
18771FILE-OFFICE Microsoft Office Excel ADO Object Parsing Code Execution (more info ...)attempted-user 2010-1253 40531  
18772FILE-OFFICE Microsoft Office Excel ADO Object Parsing Code Execution (more info ...)attempted-user 2010-1253 40531  
18948FILE-OFFICE Microsoft Office PowerPoint converter bad indirection remote code execution attempt (more info ...)attempted-user 2010-2572   URL
18949FILE-OFFICE Microsoft Office PowerPoint malformed RecolorInfoAtom out of bounds read attempt (more info ...)attempted-user 2011-1270   URL
19015POLICY-SPAM visiopharm-3d.eu known spam email attempt (more info ...)policy-violation    
19132FILE-OFFICE Microsoft Office Excel RTD buffer overflow attempt (more info ...)attempted-user 2010-1246 40524  
19133FILE-OFFICE Microsoft Office Excel EntExU2 write access violation attempt (more info ...)attempted-user 2010-0257 38547  URL
19134FILE-OFFICE Microsoft Office Excel PtgExtraArray data parsing vulnerability exploit attempt (more info ...)attempted-user 2010-3231 43647  URL
19141FILE-OFFICE Microsoft Access Wizard control memory corruption ActiveX clsid access (more info ...)attempted-user 2010-1881 41442  
19153FILE-OFFICE Microsoft Office Word malformed index code execution attempt (more info ...)attempted-user 2010-2750 43766  
19154FILE-OFFICE Microsoft Office Excel PtgExtraArray parsing attempt (more info ...)attempted-user 2010-3239 43654  
19200FILE-OFFICE Microsoft Office Excel ObjBiff exploit attempt (more info ...)attempted-user 2011-1272   URL
19222FILE-OFFICE Microsoft Office Excel ObjBiff validation exploit attempt (more info ...)attempted-user 2011-1273   URL
19225FILE-OFFICE Microsoft Office Excel SerAuxTrend biff record corruption attempt (more info ...)attempted-user 2011-1274 48159  URL
19227FILE-OFFICE Microsoft Office Excel Scenario heap memory overflow (more info ...)attempted-user 2011-1275   URL
19229FILE-OFFICE Microsoft Office Excel SLK file excessive Picture records exploit attempt (more info ...)attempted-user 2011-1276   URL
19230FILE-OFFICE Microsoft Office Excel Selection exploit attempt (more info ...)attempted-user 2011-1277   URL
19231FILE-OFFICE Microsoft Office Excel Series record exploit attempt (more info ...)attempted-user 2011-1278   URL
19232FILE-OFFICE Microsoft Office Excel XF record exploit attempt (more info ...)attempted-user 2011-1279   URL
19258FILE-OFFICE Microsoft Office Excel SxView record memory pointer corruption attempt (more info ...)attempted-user 2010-1245 40523  URL
19259FILE-OFFICE Microsoft Office Excel WOpt record memory corruption attempt (more info ...)attempted-user 2010-0824 40522  URL
19260FILE-OFFICE Microsoft Office Excel malformed MsoDrawingObject record attempt (more info ...)attempted-user 2010-3335   URL
19261FILE-OFFICE Microsoft Office Excel BIFF8 invalid Selection.cref exploit attempt (more info ...)attempted-user 2011-1277   URL
19294FILE-OFFICE Microsoft Office Excel Chart Sheet Substream memory corruption attempt (more info ...)attempted-user 2010-0823 40521  URL
19295FILE-OFFICE Microsoft Office Word HTML linked objects memory corruption attempt (more info ...)attempted-user 2010-1903 42130  URL
19296FILE-OFFICE Microsoft Office PowerPoint improper filename remote code execution attempt (more info ...)attempted-user 2010-0029   URL
19303FILE-OFFICE Microsoft Office PowerPoint out of bounds value remote code execution attempt (more info ...)attempted-user 2010-0032 38104  URL
19306FILE-OFFICE Microsoft Office Publisher pubconv.dll corruption attempt (more info ...)attempted-user 2010-2569 45277  
19317FILE-OFFICE Microsoft Office Word sprmTDiagLine80 record parsing stack buffer overflow attempt (more info ...)attempted-admin 2010-3214 43760  
19405FILE-OFFICE Microsoft Office Outlook SMB attach by reference code execution attempt (more info ...)attempted-user 2010-0266 41446  URL
19412FILE-OFFICE Microsoft Office Excel RealTimeData record parsing memory corruption (more info ...)attempted-user 2010-1247 40525  
19413FILE-OFFICE Microsoft Office Publisher 2007 and earlier stack buffer overflow attempt (more info ...)attempted-user 2010-0479 39347  URL
19414FILE-OFFICE Microsoft Office Publisher 2007 and earlier stack buffer overflow attempt (more info ...)attempted-user 2010-0479 39347  URL
19442FILE-OFFICE Microsoft Office embedded Office Art drawings execution attempt (more info ...)attempted-user 2010-0243 38073  URL
19458FILE-OFFICE Microsoft Office Word sprmCMajority record buffer overflow attempt (more info ...)attempted-user 2010-1900 42136  URL
19459FILE-OFFICE Microsoft Office Word sprmCMajority record buffer overflow attempt (more info ...)attempted-user 2010-1900 42136  URL
19465OS-WINDOWS Visio mfc71 dll-load attempt (more info ...)attempted-user 2010-3148   URL
19606FILE-OFFICE Microsoft Office Word STSH record parsing memory corruption (more info ...)attempted-user  48261  
19607FILE-OFFICE Microsoft Office Word STSH record parsing memory corruption (more info ...)attempted-user  48261  
19675FILE-OFFICE Microsoft Office Visio invalid UMLString data length exploit attempt (more info ...)attempted-user 2011-1979   URL
19676FILE-OFFICE Microsoft Office Visio invalid UMLDTOptions object exploit attempt (more info ...)attempted-user 2011-1972   URL
19707FILE-OFFICE Microsoft Office Word Converter sprmTSplit overflow attempt (more info ...)attempted-user 2011-0028   URL
19811FILE-OFFICE Microsoft Office PowerPoint malformed record call to freed object attempt (more info ...)attempted-admin 2011-0655   URL
19841PUA-ADWARE 0desa MSN password stealer (more info ...)misc-activity    URL
19894FILE-OFFICE Microsoft Office PowerPoint TextCharsAtom record buffer overflow attempt (more info ...)attempted-user 2010-0034 38108  URL
19932FILE-OFFICE Microsoft Office Publisher 2007 pointer dereference attempt (more info ...)attempted-user 2009-0566 35599  URL
19943FILE-OFFICE Microsoft Office Excel MsoDrawingGroup record remote code execution attempt (more info ...)attempted-user 2009-0559 35243  URL
20029FILE-OFFICE Microsoft Office Excel FNGROUPNAME record memory corruption attempt (more info ...)attempted-user 2010-0262 38553  URL
20049FILE-OFFICE Microsoft Office Excel SLK file excessive Picture records exploit attempt (more info ...)attempted-user 2011-1276   URL
20062FILE-OFFICE Microsoft Office Excel File Importing Code Execution (more info ...)attempted-user 2008-0112 28095  URL
20111SERVER-WEBAPP Microsoft Office SharePoint XSS vulnerability attempt (more info ...)attempted-user 2011-0653   URL
20112SERVER-WEBAPP Microsoft Office SharePoint XSS vulnerability attempt (more info ...)attempted-user 2011-1890   URL
20113SERVER-WEBAPP Microsoft Office SharePoint XSS vulnerability attempt (more info ...)attempted-user 2011-1890   URL
20115SERVER-WEBAPP Microsoft Office SharePoint XML external entity exploit attempt (more info ...)web-application-attack 2011-1892   URL
20116SERVER-WEBAPP Microsoft Office SharePoint Javascript XSS attempt (more info ...)web-application-attack 2011-1893   URL
20123FILE-OFFICE Microsoft Office Excel ShrFmla record use after free attempt (more info ...)attempted-user 2011-1986 49476  URL
20124FILE-OFFICE Microsoft Office Excel invalid Lbl record attempt (more info ...)attempted-user 2011-1988 49478  URL
20125FILE-OFFICE Microsoft Office Excel invalid Lbl record (more info ...)attempted-user 2011-1988   URL
20126FILE-OFFICE Microsoft Office Excel invalid Lbl record (more info ...)attempted-user 2011-1988   URL
20127FILE-OFFICE Microsoft Office Excel Conditional Formatting record vulnerability (more info ...)attempted-user 2011-1989   URL
20128FILE-OFFICE Microsoft Office invalid MS-OGRAPH DataFormat buffer overflow attempt (more info ...)attempted-user 2011-1990 49517  URL
20129FILE-OFFICE Microsoft Office BpscBulletProof uninitialized pointer dereference attempt (more info ...)attempted-user 2011-1982   URL
20139FILE-OFFICE Microsoft Office Word document summary information string overflow attempt (more info ...)attempted-user 2006-1540   URL
20140FILE-OFFICE Microsoft Office Word document summary information string overflow attempt (more info ...)attempted-user 2006-1540   URL
20141FILE-OFFICE Microsoft Office Word document summary information string overflow attempt (more info ...)attempted-user 2006-1540   URL
20257OS-WINDOWS Microsoft ForeFront UAG ExcelTable.asp XSS attempt (more info ...)attempted-user 2011-1896   URL
20534FILE-OFFICE Microsoft Office Excel rtToolbarDef record integer overflow attempt (more info ...)attempted-user 2011-0097   URL
20590FILE-OFFICE Microsoft Office PowerPoint out of bounds value remote code execution attempt (more info ...)attempted-user 2010-0032 38104  URL
20700FILE-OFFICE Microsoft Office PowerPoint pp7x32.dll dll-load exploit attempt (more info ...)attempted-user 2011-3396   URL
20701FILE-OFFICE Microsoft Office PowerPoint pp4x322.dll dll-load exploit attempt (more info ...)attempted-user 2011-3396   URL
20702FILE-OFFICE Microsoft Office PowerPoint pp7x32.dll dll-load exploit attempt (more info ...)attempted-user 2011-3396   URL
20703FILE-OFFICE Microsoft Office PowerPoint pp4x322.dll dll-load exploit attempt (more info ...)attempted-user 2011-3396   URL
20717FILE-OFFICE Microsoft Windows OLE versioned stream missing data stream (more info ...)attempted-user 2011-3400 50977  URL
20718FILE-OFFICE Microsoft Office Excel Lel record memory corruption attempt (more info ...)attempted-user 2011-3403   URL
20719FILE-OFFICE Microsoft Office Publisher Opltc memory corruption attempt (more info ...)attempted-user 2011-3410   URL
20720FILE-OFFICE Microsoft Office Publisher 2003 EscherStm memory corruption attempt (more info ...)attempted-user 2011-3411 50949  URL
20721FILE-OFFICE Microsoft Office Publisher PLC object memory corruption attempt (more info ...)attempted-user 2011-3412   URL
20722FILE-OFFICE Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord type confusion attempt (more info ...)attempted-user 2011-3413 50964  URL
20724FILE-OFFICE Microsoft Office Word border use-after-free attempt (more info ...)attempted-user 2011-1983   URL
20882FILE-OFFICE Microsoft Windows embedded packager object identifier (more info ...)attempted-user 2012-0013   URL
20885FILE-OFFICE Microsoft Office Excel use after free attempt (more info ...)attempted-user    URL
20886FILE-OFFICE Microsoft Office Excel use after free attempt (more info ...)attempted-user    URL
20887FILE-OFFICE Microsoft Office Excel use after free attempt (more info ...)attempted-user    URL
21002FILE-OFFICE Microsoft Office Word border use-after-free attempt (more info ...)attempted-user 2011-1983   URL
21082FILE-OFFICE Microsoft Office Excel window2 record use after free attempt (more info ...)attempted-user    URL
21083FILE-OFFICE Microsoft Office Excel window2 record use after free attempt (more info ...)attempted-user    URL
21135INDICATOR-COMPROMISE Mulcishell web shell password cracking page (more info ...)trojan-activity    URL
21156FILE-OFFICE Microsoft Office Excel macro validation arbitrary code execution attempt (more info ...)attempted-user 2008-0081   URL
21157FILE-OFFICE Microsoft Office Excel macro validation arbitrary code execution attempt (more info ...)attempted-user 2008-0081   URL
21158FILE-OFFICE Microsoft Office Excel macro validation arbitrary code execution attempt (more info ...)attempted-user 2008-0081   URL
21163FILE-OFFICE Microsoft Office Outlook VEVENT overflow attempt (more info ...)attempted-user 2007-0033 21931  URL
21170FILE-OFFICE Microsoft Office OLESS stream object name corruption attempt (more info ...)attempted-user 2011-3400 50977  URL
21243FILE-OFFICE Microsoft Office Publisher 2003 EscherStm memory corruption attempt (more info ...)attempted-user 2011-3411 50949  URL
21297SERVER-WEBAPP Microsoft Office SharePoint themeweb.aspx XSS attempt (more info ...)web-application-attack 2012-0144   URL
21414FILE-OFFICE Microsoft Office Excel MergeCells record parsing code execution attempt (more info ...)attempted-user 2010-3237 43652  URL
21415FILE-OFFICE Microsoft Office Excel MergeCells record parsing code execution attempt (more info ...)attempted-user 2010-3237 43652  URL
21422FILE-OFFICE Microsoft Office Excel Lel record memory corruption attempt (more info ...)attempted-user 2011-3403   URL
21423FILE-OFFICE Microsoft Office Publisher Opltc memory corruption attempt (more info ...)attempted-user 2011-3410   URL
21437FILE-OTHER WordPerfect WP3TablesGroup heap overflow attempt (more info ...)attempted-user 2007-0002   
21503FILE-OFFICE Microsoft Office Excel SXDB memory corruption (more info ...)attempted-user 2009-3127 36943  
21524FILE-OFFICE Microsoft Windows object packager dialogue code execution attempt (more info ...)attempted-admin 2006-4692 20318  
21674FILE-OFFICE Microsoft Office Word Smart Tags code execution attempt (more info ...)attempted-user 2006-2492 18037  URL
21675FILE-OFFICE Microsoft Office Word Smart Tags code execution attempt (more info ...)attempted-user 2006-2492 18037  URL
21677FILE-OFFICE Microsoft Office Word Smart Tags code execution attempt (more info ...)attempted-user 2006-2492 18037  URL
21759FILE-OTHER Ultra Shareware Office HttpUpload buffer overflow attempt (more info ...)attempted-user 2008-3878 30861  
21907FILE-OFFICE Microsoft Office rtf document generic exploit indicator (more info ...)attempted-user    
21919BROWSER-PLUGINS IBM Tivoli Provisioning Manager Express ActiveX clsid access attempt (more info ...)attempted-user 2012-0198   
21928FILE-OFFICE Microsoft Office Excel malformed FBI record buffer overflow attempt (more info ...)attempted-user 2007-1747 23826  URL
21929FILE-OFFICE Microsoft Office Excel DbOrParamQry.fodbcConn parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
21930FILE-OFFICE Microsoft Office Excel DbOrParamQry.fodbcConn parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
21931FILE-OFFICE Microsoft Office Excel TXO and OBJ records parsing stack memory corruption attempt (more info ...)misc-activity 2008-4265 32618  URL
21932FILE-OFFICE Microsoft Office Excel TXO and OBJ records parsing stack memory corruption attempt (more info ...)attempted-user 2008-4265 32618  URL
21933FILE-OFFICE Microsoft Office Excel MalformedPalette Record Memory Corruption attempt (more info ...)attempted-user 2007-0031 21922  
21942FILE-OFFICE Microsoft Office Excel sheet object type confusion exploit attempt (more info ...)attempted-user 2010-0258   URL
21943FILE-OFFICE Microsoft Office Excel sheet object type confusion exploit attempt (more info ...)attempted-user 2010-0258   URL
22002FILE-IDENTIFY Microsoft Visual Basic v6.0 - additional file magic detected (more info ...)misc-activity    
22066FILE-OFFICE Microsoft Office Word ScriptBridge OCX controller attempt (more info ...)attempted-user    URL
22071INDICATOR-OBFUSCATION Microsoft Office Word JavaScript obfuscation - eval (more info ...)attempted-user    URL
22072INDICATOR-OBFUSCATION Microsoft Office Word JavaScript obfuscation - fromCharCode (more info ...)attempted-user    URL
22073INDICATOR-OBFUSCATION Microsoft Office Word JavaScript obfuscation - unescape (more info ...)attempted-user    URL
22074INDICATOR-OBFUSCATION Microsoft Office Word JavaScript obfuscation - charCode (more info ...)attempted-user    URL
22075FILE-OFFICE Microsoft Office Visio IndexDirectorySize greater than ChildrenSize memory access attempt (more info ...)attempted-user 2012-0018   URL
23010FILE-OFFICE Microsoft Office Excel FNGROUPNAME record memory corruption attempt (more info ...)attempted-user 2010-0262 38553  URL
23151FILE-OFFICE Microsoft Office Excel zero-width worksheet code execution attempt (more info ...)attempted-user  15926  
23171INDICATOR-COMPROMISE Wordpress Request for html file in fgallery directory (more info ...)web-application-attack    
23211FILE-OFFICE Microsoft Office Outlook arbitrary command line attempt (more info ...)misc-attack 2008-0110   URL
23266FILE-OFFICE Microsoft Office Word invalid sprmTDefTable length stack buffer overflow attempt (more info ...)attempted-user 2008-4837 32584  URL
23267FILE-OFFICE Microsoft Office Word invalid sprmTDefTable length stack buffer overflow attempt (more info ...)attempted-user 2008-4837 32584  URL
23268FILE-OFFICE Microsoft Office Word invalid sprmTDefTable length stack buffer overflow attempt (more info ...)attempted-user 2008-4837 32584  URL
23270FILE-OFFICE Microsoft Office Malformed MSODrawing Record attempt (more info ...)attempted-user 2010-0243   URL
23279SERVER-WEBAPP Microsoft Office SharePoint name field cross site scripting attempt (more info ...)web-application-attack 2012-1861   URL
23281SERVER-WEBAPP Microsoft Office SharePoint scriptresx.ashx XSS attempt (more info ...)web-application-attack 2012-1859   URL
23282SERVER-WEBAPP Microsoft Office SharePoint query.iqy XSS attempt (more info ...)attempted-user 2012-1863   URL
23315FILE-OFFICE Microsoft Office Word request for imeshare.dll over SMB attempt (more info ...)attempted-user 2012-1854   URL
23316FILE-OFFICE Microsoft Office Word imeshare.dll dll-load exploit attempt (more info ...)attempted-user 2012-1854   URL
23356FILE-OFFICE Microsoft Office WordPad and Office text converters integer underflow attempt (more info ...)attempted-user 2009-0087   URL
23397SERVER-OTHER Citrix Provisioning Services stack buffer overflow attempt (more info ...)attempted-admin    
23398SERVER-OTHER Citrix Provisioning Services stack buffer overflow attempt (more info ...)attempted-admin    
23484INDICATOR-COMPROMISE Wordpress Invit0r plugin non-image file upload attempt (more info ...)web-application-attack  53995  URL
23525FILE-OFFICE Microsoft Office BMP header biClrUsed integer overflow attempt (more info ...)attempted-admin 2009-2518 36651  
23526FILE-OFFICE Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user 2010-3945   URL
23527FILE-OFFICE Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user 2010-3945   URL
23528FILE-OFFICE Microsoft Office PICT graphics converter memory corruption attempt (more info ...)attempted-user 2010-3946   URL
23530FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2010-3947 45274  URL
23531FILE-OFFICE Microsoft Office Excel invalid Lbl record (more info ...)attempted-user 2011-1988   URL
23532FILE-OFFICE Microsoft Office Excel invalid Lbl record (more info ...)attempted-user 2011-1988   URL
23533FILE-OFFICE Microsoft Office Excel invalid Lbl record (more info ...)attempted-user 2011-1988   URL
23534FILE-OFFICE Microsoft Office PowerPoint paragraph format array inner header overflow attempt (more info ...)attempted-user 2009-0220 34833  
23535FILE-OFFICE Microsoft Office PowerPoint Download of version 4.0 file (more info ...)attempted-user 2009-1137   URL
23536FILE-OFFICE Microsoft Office PowerPoint CurrentUserAtom remote code execution attempt (more info ...)attempted-user 2009-1131   URL
23537FILE-OFFICE Microsoft Office PowerPoint HashCode10Atom memory corruption attempt (more info ...)attempted-user 2009-1130   URL
23538FILE-OFFICE Microsoft Office PowerPoint PP7 Component buffer overflow attempt (more info ...)attempted-user 2009-1129   URL
23539FILE-OFFICE Microsoft Office PowerPoint Legacy file format picture object code execution attempt (more info ...)attempted-user 2009-0223 34834  
23540FILE-OFFICE Microsoft Office Word GDI+ Office Art Property Table remote code execution attempt (more info ...)attempted-user 2009-2528   URL
23541FILE-OFFICE Microsoft Office Excel GDI+ Office Art Property Table remote code execution attempt (more info ...)attempted-user 2009-2528   URL
23542FILE-OFFICE Microsoft Office Excel integer field in row record improper validation remote code execution attempt (more info ...)attempted-user 2009-3130   URL
23543FILE-OFFICE Microsoft Office Excel file SxView record exploit attempt (more info ...)attempted-user 2009-3128   URL
23544FILE-OFFICE Microsoft Office Excel OBJ record stack buffer overflow attempt (more info ...)attempted-user 2010-0822 40520  URL
23545FILE-OFFICE Microsoft Office Excel OBJ record stack buffer overflow attempt - with macro (more info ...)attempted-user 2010-0822   URL
23546FILE-OFFICE Microsoft Office Excel OBJ record stack buffer overflow attempt - with linkFmla (more info ...)attempted-user 2010-0822   URL
23547FILE-OFFICE Microsoft Office Excel OBJ record stack buffer overflow attempt - with macro and linkFmla (more info ...)attempted-user 2010-0822   URL
23548FILE-OFFICE Microsoft Office Excel RTD buffer overflow attempt (more info ...)attempted-user 2010-1246 40524  
23549FILE-OFFICE Microsoft Office Excel RTD buffer overflow attempt (more info ...)attempted-user 2010-1246 40524  
23550FILE-OFFICE Microsoft Office Excel RealTimeData record stack buffer overflow attempt (more info ...)attempted-user 2010-1246   URL
23551FILE-OFFICE Microsoft Office Excel SxView record memory pointer corruption attempt (more info ...)attempted-user 2010-1245 40523  URL
23552FILE-OFFICE Microsoft Office Excel SxView record memory pointer corruption attempt (more info ...)attempted-user 2010-1245   URL
23553FILE-OFFICE Microsoft Office Excel WOpt record memory corruption attempt (more info ...)attempted-user 2010-0824 40522  URL
23554FILE-OFFICE Microsoft Office Excel WOpt record memory corruption attempt (more info ...)attempted-user 2010-0824   URL
23555FILE-OFFICE Microsoft HtmlDlgHelper ActiveX clsid access (more info ...)attempted-user 2010-3329   URL
23556FILE-OFFICE Microsoft Office WordPad and Office text converters integer underflow attempt (more info ...)attempted-user 2009-0087   URL
23557FILE-OFFICE Microsoft Office WordPad and Office text converters integer underflow attempt (more info ...)attempted-user 2009-0087   URL
23558FILE-OFFICE Microsoft Office Excel pivot item index boundary corruption attempt (more info ...)attempted-user 2010-2562 42199  
23559FILE-OFFICE Microsoft Office Excel pivot item index boundary corruption attempt (more info ...)attempted-user 2010-2562 42199  URL
23700FILE-IDENTIFY Microsoft Word for Mac 5 file magic detected (more info ...)misc-activity 2007-3899 25906  URL
23715FILE-IDENTIFY Microsoft Office Access file magic detected (more info ...)misc-activity 2008-1092 26468  URL
23716FILE-IDENTIFY Microsoft Office Access JSDB file magic detected (more info ...)misc-activity 2008-1092 26468  URL
23717FILE-IDENTIFY Microsoft Office Access TJDB file magic detected (more info ...)misc-activity 2008-1092 26468  URL
23718FILE-IDENTIFY Microsoft Office Access MSISAM file magic detected (more info ...)misc-activity 2008-1092 26468  URL
23768FILE-IDENTIFY Microsoft Visual Basic v6.0 - additional file magic detected (more info ...)misc-activity    
23844FILE-OFFICE Microsoft Office MSCOMCTL ActiveX control tabstrip method attempt (more info ...)attempted-user 2013-1313   URL
23943FILE-MULTIMEDIA Microsoft Windows Visual Basic 6.0 malformed AVI buffer overflow attempt (more info ...)attempted-user 2008-4255   URL
24129FILE-OFFICE Microsoft Office Excel catLabel pointer manipulation attempt (more info ...)attempted-user 2011-0978 46225  URL
24130FILE-OFFICE Microsoft Office Excel catLabel pointer manipulation attempt (more info ...)attempted-user 2011-0978 46225  URL
24186FILE-OFFICE Microsoft Office Visio DXF variable name overflow attempt (more info ...)attempted-user 2010-1681 39836  
24198SERVER-WEBAPP Microsoft Office SharePoint name field cross site scripting attempt (more info ...)attempted-user 2012-1861   URL
24240FILE-OFFICE Microsoft Office Excel drawing layer use after free attempt (more info ...)attempted-user 2011-0977 46227  URL
24241FILE-OFFICE Microsoft Office Excel drawing layer use after free attempt (more info ...)attempted-user 2011-0977 46227  URL
24242FILE-OFFICE Microsoft Office Excel drawing layer use after free attempt (more info ...)attempted-user 2011-0977 46227  URL
24267FILE-OFFICE Microsoft Office Excel Malformed Range Code Execution attempt (more info ...)attempted-user 2005-4131 15780  
24268FILE-OFFICE Microsoft Office Excel Malformed Range Code Execution attempt (more info ...)attempted-user 2005-4131 15780  
24269FILE-OFFICE Microsoft Office Excel Malformed Range Code Execution attempt (more info ...)attempted-user 2005-4131 15780  
24284FILE-OFFICE Microsoft Office Drawing object code execution attempt (more info ...)attempted-user 2007-1747 23826  URL
24556FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2010-3947 45274  URL
24557FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2010-3947 45274  URL
24558FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2010-3947 45274  URL
24815FILE-OFFICE Microsoft Office Visio VSD file icon memory corruption attempt (more info ...)attempted-user 2009-0095   URL
24868FILE-OFFICE Microsoft Office PowerPoint bad text header txttype attempt (more info ...)attempted-user 2011-1269   URL
24911SERVER-ORACLE Oracle Outside In Excel file parsing integer overflow attempt (more info ...)attempted-admin    URL
24912SERVER-ORACLE Oracle Outside In Excel file parsing integer overflow attempt (more info ...)attempted-admin    URL
24974FILE-OFFICE Microsoft Office Word rtf invalid listoverridecount value attempt (more info ...)attempted-user 2014-1761   URL
24975FILE-OFFICE Microsoft Office Word rtf invalid listoverridecount value attempt (more info ...)attempted-user 2014-1761   URL
25120SERVER-WEBAPP W3 Total Cache for Wordpress access - likely information disclosure (more info ...)successful-recon-limited    URL
25311FILE-OFFICE Microsoft Office PowerPoint integer underflow heap corruption attempt (more info ...)attempted-user 2010-2573   URL
25330FILE-OFFICE Microsoft Office Excel conditional code execution attempt (more info ...)attempted-user 2011-1989   
25331FILE-OFFICE Microsoft Office Excel conditional code execution attempt (more info ...)attempted-user 2011-1989   
25353FILE-OFFICE Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord type confusion attempt (more info ...)attempted-user 2011-3413 50964  URL
25354FILE-OFFICE Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord type confusion attempt (more info ...)attempted-user 2011-3413 50964  URL
25355FILE-OFFICE Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord type confusion attempt (more info ...)attempted-user 2011-3413 50964  URL
25527FILE-OFFICE Microsoft Office PowerPoint TextCharsAtom record buffer overflow attempt (more info ...)attempted-user 2010-0034 38108  URL
25587FILE-OFFICE Microsoft Office PowerPoint malformed shapeid arbitrary code execution attempt (more info ...)attempted-user 2008-0118 28146  URL
25630FILE-OFFICE Microsoft Office Word Document remote code execution attempt (more info ...)attempted-user 2009-3135   URL
25631FILE-OFFICE Microsoft Office Word Document remote code execution attempt (more info ...)attempted-user 2016-3283   URL
25768FILE-OFFICE Microsoft Office Word unchecked index value remote code execution attempt (more info ...)attempted-user 2010-3219   URL
25969FILE-OFFICE Microsoft Office Excel MsoDrawingGroup record remote code execution attempt (more info ...)attempted-user 2009-0559 35243  URL
26089FILE-OFFICE Microsoft Office Visio version number anomaly (more info ...)misc-activity 2007-0934 24349  URL
26124SERVER-WEBAPP Microsoft Office SharePoint cross site scripting attempt (more info ...)web-application-attack 2013-0083   URL
26131SERVER-WEBAPP Microsoft Office SharePoint cross site scripting attempt (more info ...)web-application-attack 2013-0080   URL
26170FILE-OFFICE Microsoft Office OneNote 2010 buffer overread info disclosure attempt (more info ...)attempted-recon 2013-0086   URL
26171FILE-OFFICE Microsoft Office OneNote 2010 buffer overread info disclosure attempt (more info ...)attempted-recon 2013-0086   URL
26174FILE-OFFICE Microsoft Office Excel FRTWrapper record buffer overflow attempt (more info ...)attempted-user 2008-3471   URL
26175FILE-OFFICE Microsoft Office Excel invalid FRTWrapper record buffer overflow attempt (more info ...)attempted-user 2008-3471   URL
26176FILE-OFFICE Microsoft Office Excel SXDB memory corruption attempt (more info ...)attempted-user 2009-3127 36943  
26177FILE-OFFICE Microsoft Office Excel SXDB memory corruption attempt (more info ...)attempted-user 2009-3127 36943  
26205OS-MOBILE Android Fakenetflix email password upload (more info ...)trojan-activity    URL
26263SERVER-WEBAPP Wordpress wp-banners-lite plugin cross site scripting attempt (more info ...)web-application-attack    URL
26329FILE-OFFICE Microsoft Office Excel format record code execution attempt (more info ...)attempted-user 2008-3005   URL
26330FILE-OFFICE Microsoft Office PowerPoint TxMasterStyle10Atom atom numLevels buffer overflow attempt (more info ...)attempted-user 2008-1455   URL
26340FILE-OTHER Corel WordPerfect document parsing buffer overflow attempt (more info ...)misc-activity 2012-4900   
26453FILE-OFFICE OpenOffice OLE File Stream Buffer Overflow attempt (more info ...)attempted-user 2008-0320 28819  
26557SERVER-WEBAPP Wordpress brute-force login attempt (more info ...)suspicious-login    URL
26576MALWARE-CNC Potential hostile executable served from compromised or malicious WordPress site attempt (more info ...)trojan-activity    URL
26602FILE-OFFICE Microsoft Office Excel sheet name memory corruption attempt (more info ...)attempted-user 2007-3490 24691  
26626FILE-OFFICE XML parameter entity reference local file disclosure attempt (more info ...)attempted-recon 2018-0878 59765  URL
26627FILE-OFFICE Microsoft Office Visio SVG external entity local file disclosure attempt (more info ...)attempted-recon 2013-1301   URL
26628FILE-OFFICE Microsoft Office Visio SVG external entity local file disclosure attempt (more info ...)attempted-recon 2013-1301   URL
26663FILE-OFFICE Microsoft Office PowerPoint malformed shapeid arbitrary code execution attempt (more info ...)attempted-user 2008-0118 28146  URL
26672FILE-OFFICE Microsoft Office Word TextBox sub-document memory corruption attempt (more info ...)attempted-user 2007-1910 23380  
26673FILE-OFFICE Microsoft Office Word TextBox sub-document memory corruption attempt (more info ...)attempted-user 2007-1910 23380  
26674FILE-OFFICE Microsoft Office Word TextBox sub-document memory corruption attempt (more info ...)attempted-user 2007-1910 23380  
26676FILE-OFFICE Microsoft Windows WordPad sprmTSetBrc SPRM overflow attempt (more info ...)attempted-user 2010-2563 43122  URL
26706FILE-OFFICE Microsoft Office PowerPoint Viewer memory allocation code execution attempt (more info ...)attempted-user 2008-0120 30552  
26707FILE-OFFICE Microsoft Office PowerPoint Viewer memory allocation code execution attempt (more info ...)attempted-user 2008-0120 30552  
26708FILE-OFFICE Microsoft Office PowerPoint Viewer memory allocation code execution attempt (more info ...)attempted-user 2008-0120 30552  
26709FILE-OFFICE Microsoft Office PowerPoint Viewer memory allocation code execution attempt (more info ...)attempted-user 2008-0120 30552  
26710FILE-OFFICE Microsoft Office PowerPoint Viewer memory allocation code execution attempt (more info ...)attempted-user 2008-0120 30552  
26711FILE-OFFICE Microsoft Office Excel malformed ftCMO record remote code execution attempt (more info ...)attempted-user 2009-0100   URL
26799FILE-OFFICE Microsoft Office Excel style handling overflow attempt (more info ...)attempted-user 2006-3431 18872  URL
26800FILE-OFFICE Microsoft Office Excel style handling overflow attempt (more info ...)attempted-user 2006-3431 18872  URL
26801FILE-OFFICE Microsoft Office Excel style handling overflow attempt (more info ...)attempted-user 2006-3431 18872  URL
26830FILE-OFFICE Microsoft Office MSComctlLib.Toolbar ActiveX control access (more info ...)misc-activity    
26831FILE-OFFICE Microsoft Office MSComctlLib.Toolbar ActiveX control access (more info ...)misc-activity    
26832FILE-OFFICE Microsoft Office MSComctlLib.Toolbar ActiveX control exploit attempt (more info ...)attempted-user 2012-1856   URL
26833FILE-OFFICE Microsoft Office MSComctlLib.Toolbar ActiveX control exploit attempt (more info ...)attempted-user    URL
26981SERVER-WEBAPP WordPress login denial of service attempt (more info ...)denial-of-service    URL
26990SERVER-WEBAPP WordPress Super Cache & W3 Total Cache remote code execution attempt (more info ...)attempted-admin 2013-2010 59316  
26991SERVER-WEBAPP WordPress Super Cache & W3 Total Cache remote code execution attempt (more info ...)attempted-admin 2013-2010 59316  
26992SERVER-WEBAPP WordPress Super Cache & W3 Total Cache remote code execution attempt (more info ...)attempted-admin 2013-2010 59316  
27209BROWSER-PLUGINS GeoVision LiveAudio ActiveX remote code execution attempt (more info ...)attempted-user 2009-1092 34115  
27211FILE-OFFICE Microsoft Office Excel style handling overflow attempt (more info ...)attempted-user 2006-3431 18872  URL
27212FILE-OFFICE Microsoft Office Excel style handling overflow attempt (more info ...)attempted-user 2006-3431 18872  URL
27213FILE-OFFICE Microsoft Office Excel style handling overflow attempt (more info ...)attempted-user 2006-3431 18872  URL
27214FILE-OFFICE Microsoft Office Excel style handling overflow attempt (more info ...)attempted-user 2006-3431 18872  URL
27215FILE-OFFICE Microsoft Office PowerPoint schemes record buffer overflow (more info ...)attempted-user 2009-0226   
27216FILE-OFFICE Microsoft Office PowerPoint printer record buffer overflow (more info ...)attempted-user 2009-0227   
27236SERVER-OTHER Citrix XenApp password buffer overflow attempt (more info ...)attempted-admin  48898  URL
27634FILE-OFFICE Microsoft Office Excel FngGroupCount record overflow attempt (more info ...)attempted-user 2008-0320 18890  
27635FILE-OFFICE Microsoft Office Excel Malformed Record Code Execution attempt (more info ...)attempted-user 2006-0031 17101  
27760BROWSER-PLUGINS Ultra Shareware Office Control ActiveX function call access (more info ...)attempted-user 2008-3878 30861  
27761BROWSER-PLUGINS Ultra Shareware Office Control ActiveX function call access (more info ...)attempted-user 2008-3878 30861  
27762BROWSER-PLUGINS Ultra Shareware Office Control ActiveX clsid access (more info ...)attempted-user 2008-3878 30861  
27940SERVER-WEBAPP Django web framework oversized password denial of service attempt (more info ...)attempted-dos 2013-1443   URL
27947FILE-OFFICE Microsoft Office Excel rtMergeCells heap overflow attempt (more info ...)attempted-user 2012-0185   URL
27948FILE-OFFICE Microsoft Office Excel rtMergeCells heap overflow attempt (more info ...)attempted-user 2012-0185   URL
28103FILE-OFFICE Microsoft Office Excel Workspace file FontCount record memory corruption attempt (more info ...)attempted-user 2011-0103   URL
28113FILE-OFFICE Microsoft Office Excel FngGroupCount record overflow attempt (more info ...)attempted-user 2006-1308 18890  
28129FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0563   URL
28130FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0563   URL
28131FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0563   URL
28132FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0563   URL
28133FILE-OFFICE Microsoft Office Word remote code execution attempt (more info ...)attempted-user 2009-0563   URL
28135FILE-OFFICE Microsoft Office Excel FtCbls remote code execution attempt (more info ...)attempted-admin 2009-0557   URL
28136FILE-OFFICE Microsoft Office Excel FtCbls remote code execution attempt (more info ...)attempted-admin 2009-0557   URL
28137FILE-OFFICE Microsoft Office Excel ShrFmla record use after free attempt (more info ...)attempted-user 2011-1986 49476  URL
28311FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28312FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28313FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28314FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28315FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28316FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28317FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28318FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28319FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28320FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28321FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28322FILE-OTHER Microsoft Office Image filter BMP overflow attempt (more info ...)attempted-user 2008-3020   
28390FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2006-2025 17732  URL
28391FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2006-2025 17732  URL
28440FILE-OFFICE Microsoft Office Visio DXF file invalid memory allocation exploit attempt (more info ...)attempted-user 2008-1090   URL
28501FILE-OTHER WordPerfect file magic with .doc extension (more info ...)misc-activity 2013-1325   URL
28509FILE-OTHER Microsoft Wordpad embedded BMP overflow attempt (more info ...)attempted-user 2013-3940   URL
28511FILE-OTHER Microsoft Wordpad embedded BMP overflow attempt (more info ...)attempted-user 2013-3940   URL
28515FILE-OTHER Microsoft Wordpad embedded BMP overflow attempt (more info ...)attempted-user 2013-3940   URL
28516FILE-OTHER Microsoft Wordpad embedded BMP overflow attempt (more info ...)attempted-user 2013-3940   URL
28517FILE-OTHER Microsoft Wordpad embedded BMP overflow attempt (more info ...)attempted-user 2013-3940   URL
28549FILE-OFFICE Microsoft Office Excel rtToolbarDef record integer overflow attempt (more info ...)attempted-user 2011-0097   URL
28794FILE-OFFICE Microsoft Office Excel SerAuxTrend biff record corruption attempt (more info ...)attempted-user 2011-1274 48159  URL
28849SERVER-WEBAPP WordPress XMLRPC potential port-scan attempt (more info ...)web-application-attack 2013-0235 57554  URL
29032FILE-OFFICE Microsoft Office PowerPoint MasterPagePackedText structure CharacterFormatArrayOuterHeaderSize buffer overflow (more info ...)attempted-user 2009-1137   URL
29033FILE-OFFICE Microsoft Office PowerPoint MasterPagePackedText structure CharacterFormatArrayOuterHeaderSize buffer overflow (more info ...)attempted-user 2009-1137   URL
29264FILE-OFFICE Microsoft Office Excel SERIES record sdtX memory corruption attempt (more info ...)attempted-user 2012-1847   URL
29329FILE-OFFICE Microsoft Office Excel SERIES record sdtX memory corruption attempt (more info ...)attempted-user 2012-1847   URL
29404FILE-OFFICE Microsoft Office Excel country record arbitrary code execution attempt (more info ...)attempted-user 2008-4266   URL
29955SERVER-WEBAPP WordPress Quick-Post Widget GET request using Body cross-site scripting (more info ...)attempted-user 2012-4226   
29956SERVER-WEBAPP WordPress Quick-Post Widget POST request cross-site scripting (more info ...)attempted-user 2012-4226   
30162FILE-OFFICE Microsoft Windows common controls stack buffer overflow via malicious MSComctlLib xls object attempt (more info ...)attempted-user 2012-0158   URL
30243FILE-OFFICE Microsoft Office Excel malicious cce value following a PtgMemFunc token (more info ...)attempted-user 2013-1315   URL
30244FILE-OFFICE Microsoft Office Excel DbOrParamQry.fOdbcConn parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
30245FILE-OFFICE Microsoft Office Excel DbOrParamQry.fWeb parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
30246FILE-OFFICE Microsoft Office Excel DbOrParamQry.fWeb parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
30247FILE-OFFICE Microsoft Office Excel DbOrParamQry.fodbcConn parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
30248FILE-OFFICE Microsoft Office Excel DbOrParamQry.fodbcConn parsing remote code execution attempt (more info ...)attempted-user 2010-0264   URL
30941FILE-OFFICE Microsoft Office PowerPoint out of bounds value remote code execution attempt (more info ...)attempted-user 2010-0032 38104  URL
31031FILE-OFFICE Microsoft Office Word WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2009-0088 34469  URL
31032FILE-OFFICE Microsoft Office Word WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2009-0088 34469  URL
31059PROTOCOL-SNMP Brocade snAgentUserAccntPassword enumeration attempt (more info ...)attempted-recon    URL
31097PROTOCOL-SNMP CableHome Devices cabhPsDevUIPassword enumeration attempt (more info ...)attempted-recon 2014-4863 69631  URL
31100PROTOCOL-SNMP Ubee U10C019 series password enumeration attempt (more info ...)attempted-recon    
31112MALWARE-CNC Win.Trojan.Bancos password stealing attempt (more info ...)trojan-activity    URL
31125FILE-OFFICE Microsoft Office Excel rtToolbarDef record integer overflow attempt (more info ...)attempted-user 2011-0097   URL
31126FILE-OFFICE Microsoft Office Excel rtToolbarDef record integer overflow attempt (more info ...)attempted-user 2011-0097   URL
31127FILE-OFFICE Microsoft Office Excel rtToolbarDef record integer overflow attempt (more info ...)attempted-user 2011-0097   URL
31150MALWARE-CNC User-Agent known malicious User-Agent DefaultBotPassword - Win.Trojan.Tirabot (more info ...)trojan-activity    URL
31310FILE-OFFICE Microsoft Office Word SmartTag record code execution attempt (more info ...)attempted-user 2008-2244 30124  
31311FILE-OFFICE Microsoft Office Word SmartTag record code execution attempt (more info ...)attempted-user 2008-2244 30124  
31312FILE-OFFICE Microsoft Office Word SmartTag record code execution attempt (more info ...)attempted-user 2008-2244 30124  
31374FILE-OFFICE Microsoft Office Excel Qsir and Qsif record remote code execution attempt (more info ...)attempted-user 2009-1134   URL
31378FILE-OFFICE Microsoft Office Word Converter sprmTSplit overflow attempt (more info ...)attempted-user 2011-0028 47236  URL
31379FILE-OFFICE Microsoft Office Word Converter sprmTTextFflow overflow attempt (more info ...)attempted-user 2011-0028 47236  URL
31420FILE-OFFICE Microsoft Office thumbnail bitmap invalid biClrUsed attempt (more info ...)attempted-user 2010-3970   URL
31421FILE-OFFICE Microsoft Office thumbnail bitmap invalid biClrUsed attempt (more info ...)attempted-user 2010-3970   URL
31434FILE-OFFICE Microsoft Office Word Section Table Array Buffer Overflow attempt (more info ...)attempted-user 2007-0515 22225  
31435FILE-OFFICE Microsoft Office Excel SXDB record memory corruption attempt (more info ...)attempted-user 2009-3127   URL
31436FILE-OFFICE Microsoft Office Excel SXDB record memory corruption attempt (more info ...)attempted-user 2009-3127   URL
31437FILE-OFFICE Microsoft Office PowerPoint improper filename remote code execution attempt (more info ...)attempted-user 2010-0029   URL
31441FILE-OFFICE Microsoft Office Excel malformed chart arbitrary code execution attempt (more info ...)attempted-user 2011-1987   URL
31461FILE-OFFICE Microsoft Office Excel Malformed MSODrawing Record attempt (more info ...)attempted-user 2010-0243   URL
31462FILE-OFFICE Microsoft Office Malformed MSODrawing Record attempt (more info ...)attempted-user 2010-0243   URL
31473FILE-OFFICE Microsoft Office Excel PtgName invalid index exploit attempt (more info ...)attempted-user 2010-3235 43650  URL
31474FILE-OFFICE Microsoft Office Excel PtgName invalid index exploit attempt (more info ...)attempted-user 2010-3235 43650  URL
31475FILE-OFFICE Microsoft Office Excel PtgName invalid index exploit attempt (more info ...)attempted-user 2010-3235 43650  URL
31476FILE-OFFICE Microsoft Office Excel PtgName invalid index exploit attempt (more info ...)attempted-user 2010-3235 43650  URL
31560SERVER-WEBAPP Wordpress MailPoet plugin theme file upload attempt (more info ...)attempted-user 2014-4725   URL
31561SERVER-WEBAPP Wordpress MailPoet plugin successful theme file upload detected (more info ...)successful-user 2014-4725   URL
31562FILE-OFFICE Microsoft Office Word global array index heap overflow attempt (more info ...)attempted-user 2008-4026 32583  
31577PROTOCOL-SNMP HP Huawei password disclosure attempt (more info ...)attempted-recon 2012-3268 56183  
31578PROTOCOL-SNMP HP Huawei password disclosure attempt (more info ...)attempted-recon 2012-3268 56183  
31579FILE-OFFICE Microsoft Office Excel invalid Lbl record attempt (more info ...)attempted-user 2011-1988 49478  URL
31591FILE-OFFICE Microsoft Office Excel TXO and OBJ records parsing stack memory corruption attempt (more info ...)misc-activity 2008-4265 32618  URL
31592FILE-OFFICE Microsoft Office Excel TXO and OBJ records parsing stack memory corruption attempt (more info ...)attempted-user 2008-4265 32618  URL
31743SERVER-WEBAPP Wordpress WPTouch file upload remote code execution attempt (more info ...)attempted-admin  68654  
31751FILE-OFFICE Microsoft Office Outlook mailto injection attempt (more info ...)attempted-user 2004-0121   
31752FILE-OFFICE Microsoft Office Outlook mailto injection attempt (more info ...)attempted-user 2004-0121   
31756BROWSER-PLUGINS Microsoft Office Web Components 11 Spreadsheet ActiveX clsid access (more info ...)attempted-user 2009-1136   URL
31757BROWSER-PLUGINS Microsoft Office Web Components 11 Spreadsheet ActiveX function call access (more info ...)attempted-user 2009-1136   URL
31758BROWSER-PLUGINS Microsoft Office Spreadsheet 10.0 ActiveX function call access (more info ...)attempted-user 2009-2496   URL
31759BROWSER-PLUGINS Microsoft Office Spreadsheet 10.0 ActiveX clsid access (more info ...)attempted-user 2009-1136   URL
31843FILE-OFFICE Microsoft Office Word rich text format unexpected field type memory corruption attempt 1 (more info ...)attempted-user 2010-1901   URL
31844FILE-OFFICE Microsoft Office Word rich text format unexpected field type memory corruption attempt 2 (more info ...)attempted-user 2010-1901   URL
31845FILE-OFFICE Microsoft Office Word rich text format unexpected field type memory corruption attempt 3 (more info ...)attempted-user 2010-1901   URL
31875FILE-OFFICE Microsoft Office Excel FtCbls remote code execution attempt (more info ...)attempted-admin 2009-0557   URL
31876FILE-OFFICE Microsoft Office Excel FtCbls remote code execution attempt (more info ...)attempted-admin 2009-0557   URL
31939SERVER-WEBAPP password sent via POST parameter (more info ...)policy-violation    
31940SERVER-WEBAPP password sent via URL parameter (more info ...)policy-violation    
32062FILE-OFFICE Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user 2012-2524   URL
32064FILE-OFFICE Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user 2012-2524   URL
32082FILE-OFFICE Microsoft Office Excel Malformed Filter Records Handling Code Execution attempt (more info ...)attempted-user 2007-1214 23780  
32083FILE-OFFICE Microsoft Office Excel malformed file format parsing code execution attempt (more info ...)attempted-user 2006-0028   URL
32094FILE-OFFICE Microsoft Office Excel MalformedPalete Record Memory Corruption attempt (more info ...)attempted-user 2007-0031 21922  
32095FILE-OFFICE Microsoft Office Excel MalformedPalette Record Memory Corruption attempt (more info ...)attempted-user 2007-0031 21922  
32122FILE-OFFICE Microsoft Office Excel rtWnDesk record memory corruption exploit attempt (more info ...)attempted-user 2007-3890   URL
32131FILE-OFFICE Microsoft Office Excel malformed FBI record buffer overflow attempt (more info ...)attempted-user 2007-1203 23826  URL
32132FILE-OFFICE Microsoft Office Excel malformed FBI record buffer overflow attempt (more info ...)attempted-user 2007-1747 23826  URL
32206FILE-OFFICE Microsoft Office Excel style record overflow attempt (more info ...)attempted-user 2008-0114   URL
32276SERVER-WEBAPP WordPress Infusionsoft Gravity Forms Plugin arbitrary code execution attempt (more info ...)attempted-admin 2014-6446 70317  
32377FILE-OFFICE Microsoft Office invalid MS-OGRAPH DataFormat buffer overflow attempt (more info ...)attempted-user 2011-1990 49517  URL
32428FILE-OFFICE Microsoft Office Word document malicious lcbSttbfBkmkArto value attempt (more info ...)attempted-user 2014-6333   URL
32429FILE-OFFICE Microsoft Office Word document malicious lcbSttbfBkmkArto value attempt (more info ...)attempted-user 2014-6333   URL
32514FILE-OFFICE Microsoft Office Excel ObjBiff validation exploit attempt (more info ...)attempted-user 2011-1273   URL
32515FILE-OFFICE Microsoft Office Excel ObjBiff validation exploit attempt (more info ...)attempted-user 2011-1273   URL
32516FILE-OFFICE Microsoft Office Excel ObjBiff validation exploit attempt (more info ...)attempted-user 2011-1273   URL
32517FILE-OFFICE Microsoft Office Excel ObjBiff validation exploit attempt (more info ...)attempted-user 2011-1273   URL
32587FILE-OFFICE Microsoft Office Excel Series record exploit attempt (more info ...)attempted-user 2011-1278   URL
32588FILE-OFFICE Microsoft Office Excel Selection exploit attempt (more info ...)attempted-user 2011-1277   URL
32589FILE-OFFICE Microsoft Office Excel Selection exploit attempt (more info ...)attempted-user 2011-1277   URL
32601SERVER-OTHER Hikvision DVR RTSP request buffer overflow attempt (more info ...)attempted-admin 2014-4880   
32625FILE-OFFICE Microsoft Office Excel DV record buffer overflow attempt (more info ...)attempted-user 2011-0105   URL
32642BROWSER-PLUGINS Microsoft Office Web Components OWC.Spreadsheet.9 ActiveX clsid access attempt (more info ...)attempted-user 2006-4695 4453  URL
32746SERVER-WEBAPP Wordpress OptimizePress plugin theme upload attempt (more info ...)attempted-user 2013-7102   URL
32872FILE-OFFICE Microsoft Office Excel ObjBiff exploit attempt (more info ...)attempted-user 2011-1272   URL
32939SERVER-WEBAPP Wordpress XSS Clean and Simple Contact Form plugin cross-site scripting attempt (more info ...)attempted-user 2014-8955   
32940FILE-OFFICE Microsoft Office Excel malformed Label record exploit attempt (more info ...)attempted-user 2011-0098   URL
32941FILE-OFFICE Microsoft Office Excel SLK file excessive Picture records exploit attempt (more info ...)attempted-user 2011-1276   URL
32942FILE-OFFICE Microsoft Office Excel SLK file excessive Picture records exploit attempt (more info ...)attempted-user 2011-1276   URL
32960FILE-OFFICE Microsoft Office Publisher 2003 EscherStm memory corruption attempt (more info ...)attempted-user 2011-3411 50949  URL
32961FILE-OFFICE Microsoft Office Publisher 2003 EscherStm memory corruption attempt (more info ...)attempted-user 2011-3411 50949  URL
33307FILE-OTHER Microsoft Visio packed object parsing memory corruption attempt (more info ...)attempted-user 2007-0936   URL
33308FILE-OTHER Microsoft Visio packed object parsing memory corruption attempt (more info ...)attempted-user 2007-0936   URL
33441FILE-OFFICE Microsoft Office OLESS stream object name corruption attempt (more info ...)attempted-user 2011-3400 50977  URL
33442FILE-OFFICE Microsoft Office OLESS stream object name corruption attempt (more info ...)attempted-user 2011-3400 50977  URL
33548BROWSER-PLUGINS Microsoft Office Access multiple control instantiation memory corruption attempt (more info ...)attempted-user 2010-0814   URL
33562FILE-OFFICE Microsoft Office Word document with embedded networking script (more info ...)policy-violation    URL
33563FILE-OFFICE Microsoft Office Word document with embedded networking script (more info ...)policy-violation    URL
33567FILE-OFFICE Microsoft Office Word border use-after-free attempt (more info ...)attempted-user 2011-1983   URL
33568FILE-OFFICE Microsoft Office Word border use-after-free attempt (more info ...)attempted-user 2011-1983   URL
33734FILE-OFFICE Microsoft Office ADODB.RecordSet code execution attempt (more info ...)attempted-user 2015-0097   URL
33735FILE-OFFICE Microsoft Office ADODB.RecordSet code execution attempt (more info ...)attempted-user 2015-0097   URL
33855SERVER-WEBAPP Wordpress Ultimate CSV Importer auth bypass export attempt (more info ...)attempted-admin    URL
33856SERVER-WEBAPP Wordpress Holding Pattern theme file upload attempt (more info ...)attempted-admin 2015-1172 72546  
33922SERVER-WEBAPP WordPress arbitrary web script injection attempt (more info ...)attempted-user 2014-9031   
33944FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33945FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33946FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33947FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33948FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33949FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33950FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33951FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33952FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33953FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33954FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33955FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33956FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33957FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33958FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
33959FILE-OTHER WordPerfect converter buffer overflow attempt (more info ...)attempted-user 2004-0573   
34047MALWARE-CNC Win.Trojan.VBPasswordStealer variant outbound connection (more info ...)trojan-activity    URL
34131FILE-OFFICE RTF file with embedded OLE object (more info ...)policy-violation    URL
34328SERVER-WEBAPP Wordpress comment field stored XSS attempt (more info ...)attempted-user 2015-3440   URL
34475SERVER-WEBAPP Wordpress username enumeration attempt (more info ...)attempted-recon    URL
34568SERVER-WEBAPP Wordpress Gravity Forms gf_page arbitrary file upload attempt (more info ...)attempted-user    URL
34974FILE-OFFICE Microsoft Office Visio UML string object heap buffer overflow attempt (more info ...)attempted-user 2011-1979   URL
34975FILE-OFFICE Microsoft Office Visio UML string object heap buffer overflow attempt (more info ...)attempted-user 2011-1979   URL
35102MALWARE-CNC Win.Trojan.Dridex Microsoft Word document dropper download attempt (more info ...)trojan-activity    URL
35103MALWARE-CNC Win.Trojan.Dridex Microsoft Word document dropper download attempt (more info ...)trojan-activity    URL
35129FILE-OFFICE Microsoft Office Excel invalid table information disclosure attempt (more info ...)attempted-recon 2015-2375   URL
35130FILE-OFFICE Microsoft Office Excel invalid table information disclosure attempt (more info ...)attempted-recon 2015-2375   URL
35143FILE-OFFICE Microsoft Office Excel Viewer msostyle.dll dll-load exploit attempt (more info ...)attempted-user 2015-2378   URL
35144FILE-OFFICE Microsoft Office Excel Viewer request for msostyle.dll over SMB attempt (more info ...)attempted-user 2015-2378   URL
35166FILE-OFFICE Microsoft Office RTF object remote code execution attempt (more info ...)attempted-user 2015-2369   URL
35167FILE-OFFICE Microsoft Office RTF object remote code execution attempt (more info ...)attempted-user 2015-2369   URL
35168FILE-OFFICE Microsoft Office rapi.dll dll-load exploit attempt (more info ...)attempted-user 2015-2369   URL
35169FILE-OFFICE Microsoft Office request for rapi.dll over SMB attempt (more info ...)attempted-user 2015-2369   URL
35253SERVER-OTHER LibreOffice Impress socket manager Use After Free attempt (more info ...)attempted-user 2014-3963 71351  URL
35358SERVER-WEBAPP Wordpress RightNow theme file upload attempt (more info ...)web-application-attack    
35423BROWSER-PLUGINS Microsoft Windows Visual Basic Charts ActiveX function call access (more info ...)attempted-user 2008-4256   URL
35440FILE-OFFICE Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord type confusion attempt (more info ...)attempted-user 2011-3413 50964  URL
35441FILE-OFFICE Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord type confusion attempt (more info ...)attempted-user 2011-3413 50964  URL
35442FILE-OFFICE Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord type confusion attempt (more info ...)attempted-user 2011-3413 50964  URL
35443FILE-OFFICE Microsoft Office PowerPoint invalid OfficeArtSpContainer subrecord type confusion attempt (more info ...)attempted-user 2011-3413 50964  URL
35670POLICY-OTHER Symantec Endpoint Protection insecure password reset attempt (more info ...)policy-violation 2015-1486   
35829FILE-OTHER OpenOffice Starview metafile arbitrary read write attempt (more info ...)attempted-user 2016-1513   URL
35876FILE-OTHER InduSoft Web Studio insecure visual basic code execution attempt (more info ...)policy-violation    
35886POLICY-OTHER Kaskad SCADA default username and password attempt (more info ...)default-login-attempt    URL
36277FILE-FLASH Adobe Flash Player diplayAsPassword information disclosure attempt (more info ...)attempted-user 2015-5572   URL
36278FILE-FLASH Adobe Flash Player diplayAsPassword information disclosure attempt (more info ...)attempted-user 2015-5572   URL
36279FILE-FLASH Adobe Flash Player diplayAsPassword information disclosure attempt (more info ...)attempted-user 2015-5572   URL
36280FILE-FLASH Adobe Flash Player diplayAsPassword information disclosure attempt (more info ...)attempted-user 2015-5572   URL
36334SERVER-WEBAPP Ignite Realtime Openfire user-password cross site request forgery attempt (more info ...)attempted-user 2015-6973   
36375SERVER-OTHER IBM Tivoli Management Framework Endpoint default HTTP password authentication attempt (more info ...)attempted-user 2011-2330   URL
36419POLICY-OTHER Remote non-VBScript file found in Visual Basic script tag src attribute (more info ...)policy-violation 2015-6059   URL
36420POLICY-OTHER Remote non-VBScript file found in Visual Basic script tag src attribute (more info ...)policy-violation 2015-6059   URL
36421POLICY-OTHER Remote non-VBScript file found in Visual Basic script tag src attribute (more info ...)policy-violation 2015-6059   URL
36422POLICY-OTHER Remote non-VBScript file found in Visual Basic script tag src attribute (more info ...)policy-violation 2015-6059   URL
36425FILE-OFFICE Microsoft Office Excel fileVersion use-after-free attempt (more info ...)attempted-user 2015-2558   URL
36426FILE-OFFICE Microsoft Office Excel fileVersion use-after-free attempt (more info ...)attempted-user 2015-2558   URL
36435SERVER-OTHER Xerox Administrator Console password extraction attempt (more info ...)attempted-recon    URL
36631FILE-OFFICE Microsoft Office Word .rtf file stylesheet buffer overflow attempt (more info ...)attempted-user 2008-4031   URL
36784POLICY-OTHER Symantec LiveUpdate forcepasswd.do insecure password change attempt (more info ...)policy-violation 2014-1644 66399  
36857FILE-OFFICE Microsoft Office Excel WOpt record memory corruption attempt (more info ...)attempted-user 2010-0824 40522  URL
36914MALWARE-CNC Potential hostile executable served from compromised or malicious WordPress site (more info ...)trojan-activity    
37012FILE-OFFICE Microsoft Office Outlook embedded OLE object sandbox bypass attempt (more info ...)attempted-user 2015-6172   URL
37029FILE-OFFICE Microsoft Office PowerPoint malformed record call to freed object attempt (more info ...)attempted-admin 2011-0655   URL
37030FILE-OFFICE Microsoft Office PowerPoint malformed record call to freed object attempt (more info ...)attempted-admin 2011-0655   URL
37031FILE-OFFICE Microsoft Office PowerPoint malformed record call to freed object attempt (more info ...)attempted-admin 2011-0655   URL
37032FILE-OFFICE Microsoft Office PowerPoint malformed record call to freed object attempt (more info ...)attempted-admin 2011-0655   URL
37033FILE-OFFICE Microsoft Office PowerPoint malformed record call to freed object attempt (more info ...)attempted-admin 2011-0655   URL
37035FILE-OFFICE Microsoft Office PowerPoint malformed record call to freed object attempt (more info ...)attempted-admin 2011-0655   URL
37246FILE-OFFICE Microsoft Office Excel CrErr record integer overflow attempt (more info ...)attempted-user 2010-3230 43643  URL
37273FILE-OFFICE Microsoft Office RTF parser heap overflow attempt (more info ...)attempted-user 2016-0010   URL
37281FILE-OTHER Microsoft Office MScomctl.ocx memory leak attempt (more info ...)attempted-user 2016-0012   URL
37282FILE-OTHER Microsoft Office MScomctl.ocx memory leak attempt (more info ...)attempted-user 2016-0012   URL
37293FILE-OFFICE Microsoft Office Excel RTD buffer overflow attempt (more info ...)attempted-user 2010-1246   URL
37294FILE-OFFICE Microsoft Office Excel RTD buffer overflow attempt (more info ...)attempted-user 2010-1246   URL
37318FILE-OFFICE Microsoft Office Word rpawinet.dll dll-load exploit attempt (more info ...)attempted-user 2011-0107 47246  URL
37319FILE-OFFICE Microsoft Office Word request for rpawinet.dll over SMB attempt (more info ...)attempted-user 2011-0107 47246  URL
37362FILE-OFFICE Microsoft Office Publisher 2007 conversion library code execution attempt (more info ...)attempted-user 2007-1754 22702  URL
37378SERVER-WEBAPP ABB default password login attempt (more info ...)default-login-attempt    URL
37379SERVER-WEBAPP BinTec Elmeg default password login attempt (more info ...)default-login-attempt    URL
37380SERVER-WEBAPP BinTec Elmeg default password login attempt (more info ...)default-login-attempt    URL
37381SERVER-WEBAPP Digi default password login attempt (more info ...)default-login-attempt    URL
37382SERVER-WEBAPP Digi default password login attempt (more info ...)default-login-attempt    URL
37383SERVER-WEBAPP Digi default password login attempt (more info ...)default-login-attempt    URL
37384SERVER-WEBAPP Emerson default password login attempt (more info ...)default-login-attempt    URL
37385SERVER-WEBAPP Hirschmann default password login attempt (more info ...)default-login-attempt    URL
37386SERVER-WEBAPP Hirschmann default password login attempt (more info ...)default-login-attempt    URL
37387SERVER-WEBAPP Moxa default password login attempt (more info ...)default-login-attempt    URL
37388SERVER-WEBAPP NOVUS AUTOMATION default password login attempt (more info ...)default-login-attempt    URL
37389SERVER-WEBAPP Rockwell Automation default password login attempt (more info ...)default-login-attempt    URL
37390SERVER-WEBAPP Rockwell Automation default password login attempt (more info ...)default-login-attempt    URL
37391SERVER-WEBAPP Samsung default password login attempt (more info ...)default-login-attempt    URL
37392SERVER-WEBAPP Schneider default password login attempt (more info ...)default-login-attempt    URL
37393SERVER-WEBAPP Schneider default password login attempt (more info ...)default-login-attempt    URL
37394SERVER-WEBAPP Wago default password login attempt (more info ...)default-login-attempt    URL
37395SERVER-WEBAPP Westermo default password login attempt (more info ...)default-login-attempt    URL
37396SERVER-WEBAPP eWON default password login attempt (more info ...)default-login-attempt    URL
37403SERVER-OTHER Easy Chat server authentication request password parameter overflow attempt (more info ...)misc-attack    URL
37462SERVER-WEBAPP WordPress Job Manager plugin cross site scripting attempt (more info ...)attempted-user 2015-2321 76503  
37463SERVER-WEBAPP WordPress Job Manager plugin cross site scripting attempt (more info ...)attempted-user 2015-2321 76503  
37556FILE-OFFICE Microsoft Office phoneinfo.dll dll-load exploit attempt (more info ...)attempted-user 2016-0041   URL
37562FILE-OFFICE Microsoft Office Word missing dpinfo structure integer overflow attempt (more info ...)attempted-user 2016-0022   URL
37846FILE-OFFICE Microsoft Office Excel file with embedded ActiveX control (more info ...)attempted-user 2008-3477   URL
37884BROWSER-PLUGINS IBM Tivoli Provisioning Manager Express ActiveX clsid access attempt (more info ...)attempted-user 2012-0198   
37885BROWSER-PLUGINS IBM Tivoli Provisioning Manager Express ActiveX clsid access attempt (more info ...)attempted-user 2012-0198   
37920FILE-OFFICE Microsoft Office Publisher pubconv.dll corruption attempt (more info ...)attempted-user 2010-2569 45277  
37921FILE-OFFICE Microsoft Office Publisher tyo.oty field heap overflow attempt (more info ...)attempted-user 2010-2569   URL
38110FILE-OFFICE Microsoft Office Word bitmap stream parsing remote code execution attempt (more info ...)attempted-user 2016-0092   URL
38237FILE-OFFICE Microsoft Office Word RTF parsing memory corruption attempt (more info ...)attempted-user 2008-1091 29104  URL
38249SERVER-WEBAPP Samsung Data Manager default password login attempt (more info ...)default-login-attempt    URL
38262FILE-OFFICE Microsoft Office Word rtf malformed dpcallout buffer overflow attempt (more info ...)attempted-user 2008-4028 32585  URL
38265FILE-OFFICE Microsoft Office Excel Formula record remote code execution attempt (more info ...)attempted-user 2009-0560 35244  URL
38266FILE-OFFICE Microsoft Office Word HTML linked objects memory corruption attempt (more info ...)attempted-user 2010-1903 42130  URL
38267FILE-OFFICE Microsoft Office Word HTML linked objects memory corruption attempt (more info ...)attempted-user 2010-1903 42130  URL
38272FILE-OFFICE Microsoft Office Word formatted disk pages table memory corruption attempt (more info ...)attempted-user 2006-6561 21589  
38273FILE-OFFICE Microsoft Office Word formatted disk pages table memory corruption attempt (more info ...)attempted-user 2006-6561 21589  
38274FILE-OFFICE Microsoft Office Word formatted disk pages table memory corruption attempt (more info ...)attempted-user 2006-6561 21589  
38536SERVER-WEBAPP Wordpress Scoreme cross site scripting attempt (more info ...)attempted-user    URL
38785FILE-OFFICE Microsoft Office Excel BOF memory disclosure attempt (more info ...)attempted-recon 2018-8162   URL
38786FILE-OFFICE Microsoft Office Excel BOF memory disclosure attempt (more info ...)attempted-recon 2018-8162   URL
38810FILE-OFFICE Microsoft Office wwlib out of bounds memory access attempt (more info ...)attempted-recon 2016-0183   URL
38856FILE-OTHER Hancom Hangul HCell pConnectionSites OfficeArt record heap buffer overflow attempt (more info ...)attempted-user 2016-4294   URL
38858FILE-OTHER Hancom Hangul HCell pConnectionSites OfficeArt record heap buffer overflow attempt (more info ...)attempted-user 2016-4294   URL
38859FILE-OTHER Hancom Hangul HCell pVertices OfficeArt record heap buffer overflow attempt (more info ...)attempted-user 2016-4294   URL
38950MALWARE-CNC Win.Trojan.PassStealer passwords exfiltration attempt (more info ...)trojan-activity    URL
39049FILE-OFFICE Hancom Hangul Office NXDeleteLineObj memory corruption attempt (more info ...)attempted-user 2016-4290   URL
39050FILE-OFFICE Hancom Hangul Office NXDeleteLineObj memory corruption attempt (more info ...)attempted-user 2016-4290   URL
39082FILE-OFFICE TRUFFLEHUNTER TALOS-CAN-0160 attack attempt (more info ...)attempted-user    URL
39083FILE-OFFICE TRUFFLEHUNTER TALOS-CAN-0160 attack attempt (more info ...)attempted-user    URL
39110FILE-OFFICE Hancom Hangul Office HCell HncChart out of bounds write attempt (more info ...)attempted-user 2016-4295   URL
39111FILE-OFFICE Hancom Hangul Office HCell HncChart out of bounds write attempt (more info ...)attempted-user 2016-4295   URL
39152SERVER-WEBAPP Huawei HG866 GPON root password change attempt (more info ...)web-application-attack    
39157FILE-OFFICE Microsoft Office Excel RealTimeData record exploit attempt (more info ...)attempted-user 2010-3240 43655  URL
39158FILE-OFFICE Microsoft Office Excel RealTimeData record exploit attempt (more info ...)attempted-user 2010-3240 43655  URL
39166SERVER-WEBAPP Asus RT-N56U router password disclosure attempt (more info ...)web-application-attack    URL
39169SERVER-WEBAPP Alpha Networks ADSL2/2+ Wireless Router password disclosure attempt (more info ...)web-application-attack    URL
39346FILE-OFFICE Microsoft Office Excel RealTimeData record exploit attempt (more info ...)attempted-user 2013-1315 43655  URL
39347FILE-OFFICE Microsoft Office Excel RealTimeData record exploit attempt (more info ...)attempted-user 2013-1315 43655  URL
39444INDICATOR-COMPROMISE Netgear D6000 or D3600 password recovery page access attempt (more info ...)misc-activity 2015-8289   URL
39665FILE-OTHER Oracle OIT libvs_word ContentAccess out of bounds write attempt (more info ...)attempted-user 2016-3592   URL
39666FILE-OTHER Oracle OIT libvs_word ContentAccess out of bounds write attempt (more info ...)attempted-user 2016-3592   URL
39667FILE-OTHER Oracle OIT libvs_word ContentAccess out of bounds write attempt (more info ...)attempted-user 2016-3592   URL
39668FILE-OTHER Oracle OIT libvs_word ContentAccess out of bounds write attempt (more info ...)attempted-user 2016-3592   URL
39671FILE-OTHER Oracle OIT libvs_word ContentAccess out of bounds write attempt (more info ...)attempted-user 2016-3590   URL
39672FILE-OTHER Oracle OIT libvs_word ContentAccess out of bounds write attempt (more info ...)attempted-user 2016-3590   URL
39757FILE-OFFICE Hancom Hangul HCell TableStyle record heap buffer overflow attempt (more info ...)attempted-user 2016-4293   URL
39758FILE-OFFICE Hancom Hangul HCell TableStyle record heap buffer overflow attempt (more info ...)attempted-user 2016-4293   URL
39759FILE-OFFICE Hancom Hangul HCell TableStyle record heap buffer overflow attempt (more info ...)attempted-user 2016-4293   URL
39760FILE-OFFICE Hancom Hangul HCell TableStyle record heap buffer overflow attempt (more info ...)attempted-user 2016-4293   URL
39761FILE-OFFICE Hancom Hangul Hcell cssValFormat checkUnderbar out of bounds write attempt (more info ...)attempted-user 2016-4296   URL
39762FILE-OFFICE Hancom Hangul Hcell cssValFormat checkUnderbar out of bounds write attempt (more info ...)attempted-user 2016-4296   URL
39816FILE-OFFICE Microsoft Office Word sprmSDyaTop memory leak attempt (more info ...)attempted-user 2016-3316   URL
39988FILE-OFFICE Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt (more info ...)attempted-user 2010-0263   URL
39989FILE-OFFICE Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt (more info ...)attempted-user 2010-0263   URL
39990FILE-OFFICE Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt (more info ...)attempted-user 2010-0263   URL
39991FILE-OFFICE Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt (more info ...)attempted-user 2010-0263   URL
39992FILE-OFFICE Microsoft Office Excel 2007 invalid comments.xml uninitialized pointer access attempt (more info ...)attempted-user 2010-0263   URL
40058SERVER-WEBAPP WordPress Quick-Post Widget GET request using Body cross-site scripting (more info ...)attempted-user 2012-4226   
40125FILE-OTHER Ichitaro Office Excel TxO record heap overflow attempt (more info ...)attempted-user 2017-2790   URL
40126FILE-OTHER Ichitaro Office Excel TxO record heap overflow attempt (more info ...)attempted-user 2017-2790   URL
40142FILE-OFFICE Microsoft PowerPoint bogus JPEG marker length heap buffer overflow (more info ...)attempted-user 2016-3357   URL
40278INDICATOR-SHELLCODE x86 OS agnostic dword additive feedback decoder (more info ...)shellcode-detect    
40279INDICATOR-SHELLCODE x86 OS agnostic dword additive feedback decoder (more info ...)shellcode-detect    
40307FILE-OFFICE Microsoft Office Word document containing VBA project entry detected (more info ...)policy-violation    
40497SERVER-WEBAPP WordPress Plugin RevSlider file upload attempt (more info ...)web-application-attack 2014-9735   
40884FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin 2014-4114   URL
40885FILE-OTHER Microsoft Office ole object external file loading attempt (more info ...)attempted-admin 2014-4114   URL
40940FILE-OFFICE Microsoft Office hyperlink object out of bounds read attempt (more info ...)attempted-user 2016-7278 94716  URL
40941FILE-OFFICE Microsoft Office hyperlink object out of bounds read attempt (more info ...)attempted-user 2016-7278 94716  URL
40944FILE-OFFICE Microsoft Office Excel CrtMlFrt record out of bounds read attempt (more info ...)attempted-user 2016-7264   URL
40961FILE-OTHER Microsoft Office OLE DLL side load attempt (more info ...)attempted-user 2016-7275   URL
41094FILE-OFFICE Microsoft Office PowerPoint improper filename remote code execution attempt (more info ...)attempted-user 2010-0029   URL
41132FILE-OFFICE RTF file with embedded OLE object (more info ...)policy-violation    
41223SERVER-WEBAPP Moxa AWK-3131A plaintext password leak attempt (more info ...)policy-violation 2016-8716   URL
41413FILE-OFFICE Microsoft Office PowerPoint malformed msofbtTextbox exploit attempt (more info ...)attempted-admin 2009-0556   
41414FILE-OFFICE Microsoft Office PowerPoint malformed msofbtTextbox exploit attempt (more info ...)attempted-admin 2009-0556   
41452MALWARE-CNC Swf.Tool.Agent flash file in a word document uploading system capabilities (more info ...)trojan-activity    URL
41453FILE-OFFICE Microsoft Works file converter field length invalid chunk size buffer overflow attempt (more info ...)attempted-user 2008-0108 27659  URL
41563FILE-OFFICE Microsoft Office request for imjp12k.dll over SMB attempt (more info ...)attempted-user 2017-0039   URL
41564FILE-OFFICE Microsoft Office imjp12k.dll dll-load exploit attempt (more info ...)attempted-user 2017-0039   URL
41638SERVER-WEBAPP Wordpress NextGEN gallery directory traversal attempt (more info ...)attempted-recon    URL
41639SERVER-WEBAPP Wordpress NextGEN gallery directory traversal attempt (more info ...)attempted-recon    URL
41650SERVER-WEBAPP Wordpress Excerpt cross site scripting attempt (more info ...)attempted-user 2017-5612   
41761POLICY-OTHER Microsoft Word document with large docProps/core.xml file (more info ...)policy-violation    URL
41762POLICY-OTHER Microsoft Word document with large docProps/core.xml file (more info ...)policy-violation    URL
41825SERVER-WEBAPP WordPress Plugins Simple Ads Manager information disclosure attempt (more info ...)web-application-attack 2015-2826   
41826SERVER-WEBAPP WordPress Plugins Simple Ads Manager information disclosure attempt (more info ...)web-application-attack 2015-2826   
41914SERVER-WEBAPP WordPress Plugin RevSlider file upload attempt (more info ...)web-application-attack 2014-9735   
42042SERVER-WEBAPP Wordpress Press-This cross site request forgery attempt (more info ...)denial-of-service 2017-6819   URL
42043SERVER-WEBAPP WordPress embedded URL video cross site scripting attempt (more info ...)attempted-user    
42055PROTOCOL-SCADA Moxa password retrieval attempt (more info ...)attempted-admin    URL
42056PROTOCOL-SCADA Moxa password retrieval attempt (more info ...)attempted-admin    URL
42066SERVER-WEBAPP Wordpress plugin arbitrary file deletion attempt (more info ...)web-application-attack    URL
42137FILE-OFFICE Lexmark Perceptive Document Filters malformed XLS information disclosure attempt (more info ...)attempted-recon 2017-2806   URL
42163FILE-OTHER Microsoft Office OneNote 2007 dll-load exploit attempt (more info ...)attempted-user 2017-0197   URL
42164FILE-OTHER Microsoft Office OneNote 2007 dll-load exploit attempt (more info ...)attempted-user 2017-0197   URL
42197FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user 2015-6132   URL
42231FILE-OFFICE RTF url moniker COM file download attempt (more info ...)attempted-admin 2017-0199   
42819SERVER-WEBAPP WordPress admin password reset attempt (more info ...)web-application-attack 2017-8295   
42928INDICATOR-COMPROMISE Microsoft Office with embedded EPS download attempt (more info ...)attempted-admin 2017-0262   
43259FILE-OTHER Hangul Word Processor type confusion attempt (more info ...)attempted-admin 2015-6585   
43260FILE-OTHER Hangul Word Processor type confusion attempt (more info ...)attempted-admin 2015-6585   
43261FILE-OTHER Hangul Word Processor type confusion attempt (more info ...)attempted-admin 2015-6585   
43262FILE-OTHER Hangul Word Processor type confusion attempt (more info ...)attempted-admin 2015-6585   
43263FILE-OTHER Hangul Word Processor type confusion attempt (more info ...)attempted-admin 2015-6585   
43264FILE-OTHER Hangul Word Processor type confusion attempt (more info ...)attempted-admin 2015-6585   
43294SERVER-WEBAPP Cybozu Office directory traversal attempt (more info ...)web-application-attack 2006-4490   
43295SERVER-WEBAPP Cybozu Office directory traversal attempt (more info ...)web-application-attack 2006-4490   
43328FILE-OFFICE Microsoft Office Word .rtf file integer overflow attempt (more info ...)misc-attack 2008-4025   URL
43450FILE-OFFICE Microsoft Office Word .rtf file double free attempt (more info ...)attempted-user 2008-4027   URL
43458SERVER-WEBAPP WordPress wp_title function cross site scripting attempt (more info ...)attempted-user 2007-1894   
43638FILE-OFFICE Microsoft Office Excel null pointer dereference attempt (more info ...)attempted-user 2007-1239   
43639FILE-OFFICE Microsoft Office Excel null pointer dereference attempt (more info ...)attempted-user 2007-1239   
43640FILE-OFFICE Microsoft Office Excel null pointer dereference attempt (more info ...)attempted-user 2007-1239   
43641FILE-OFFICE Microsoft Office Excel null pointer dereference attempt (more info ...)attempted-user 2007-1239   
43674FILE-OFFICE Microsoft Office Word SmartTag record code execution attempt (more info ...)attempted-user 2008-2244 30124  
43675FILE-OFFICE Microsoft Office Word SmartTag record code execution attempt (more info ...)attempted-user 2008-2244 30124  
43678FILE-OFFICE Microsoft Office RTF parsing remote code execution attempt (more info ...)attempted-user 2010-3333   URL
43679FILE-OFFICE Microsoft Office RTF parsing remote code execution attempt (more info ...)attempted-user 2010-3333   URL
43699FILE-OFFICE Microsoft Office Excel invalid FRTWrapper record buffer overflow attempt (more info ...)attempted-user 2008-3471   URL
43804FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user 2015-6132   URL
43805FILE-OFFICE Microsoft Office mqrt.dll dll-load exploit attempt (more info ...)attempted-user 2015-6132   URL
43853FILE-OFFICE Microsoft Office Word unpaired RTF dpendgroup buffer overflow attempt (more info ...)attempted-user 2008-4030 32642  URL
43854FILE-OFFICE Microsoft Office Word unpaired RTF dpendgroup buffer overflow attempt (more info ...)attempted-user 2008-4030 32642  URL
44031FILE-OFFICE Powerpoint Viewer malformed msoDrawing property table buffer overflow attempt (more info ...)attempted-user 2008-0121   URL
44032FILE-OFFICE Powerpoint Viewer malformed msoDrawing property table buffer overflow attempt (more info ...)attempted-user 2008-0121   URL
44068FILE-OFFICE Microsoft Office PowerPoint Viewer memory allocation code execution attempt (more info ...)attempted-user 2008-0120 30552  
44069FILE-OFFICE Microsoft Office PowerPoint Viewer memory allocation code execution attempt (more info ...)attempted-user 2008-0120 30552  
44157FILE-OFFICE Microsoft Office Word rich text format invalid field size memory corruption attempt (more info ...)attempted-user 2010-1902   URL
44182FILE-OFFICE Microsoft Office Word .rtf file integer overflow attempt (more info ...)misc-attack 2008-4025   URL
44183FILE-OFFICE Microsoft Office Word .rtf file integer overflow attempt (more info ...)misc-attack 2008-4025   URL
44280FILE-OFFICE Microsoft Office PowerPoint invalid TextByteAtom remote code execution attempt (more info ...)attempted-user 2010-0033   URL
44289FILE-OFFICE Microsoft Office Excel sheet object type confusion exploit attempt (more info ...)attempted-user 2010-0258   URL
44290FILE-OFFICE Microsoft Office Excel sheet object type confusion exploit attempt (more info ...)attempted-user 2010-0258   URL
44291FILE-OFFICE Microsoft Office Excel BIFF5 formulas from records parsing code execution attempt (more info ...)attempted-user 2010-0258   URL
44292FILE-OFFICE Microsoft Office Excel BIFF8 formulas from records parsing code execution attempt (more info ...)attempted-user 2010-0258   URL
44296FILE-OFFICE Microsoft Office Excel sheet object type confusion exploit attempt (more info ...)attempted-user 2010-0258   URL
44303FILE-OFFICE Microsoft PowerPoint CString atom overflow attempt (more info ...)attempted-user 2009-1128   URL
44304FILE-OFFICE Microsoft PowerPoint CString atom overflow attempt (more info ...)attempted-user 2009-1128   URL
44469MALWARE-CNC Potential hostile executable served from compromised or malicious WordPress site attempt (more info ...)trojan-activity    URL
44470MALWARE-CNC Potential hostile executable served from compromised or malicious WordPress site attempt (more info ...)trojan-activity    URL
44559MALWARE-CNC Word.Trojan.Emotet obfuscated powershell (more info ...)trojan-activity    URL
44560MALWARE-CNC Word.Trojan.Emotet obfuscated powershell (more info ...)trojan-activity    URL
44566SERVER-WEBAPP Wordpress Customizer directory traversal attempt (more info ...)web-application-attack 2017-14722   
44567SERVER-WEBAPP Wordpress Customizer directory traversal attempt (more info ...)web-application-attack 2017-14722   
44568SERVER-WEBAPP Wordpress Customizer directory traversal attempt (more info ...)web-application-attack 2017-14722   
44581SERVER-OTHER TrendMicro OfficeScan LogonUser buffer overflow attempt (more info ...)attempted-user 2017-14089   
44585FILE-OFFICE Microsoft Office Word docx object type confusion attempt (more info ...)attempted-admin 2017-11826   URL
44586FILE-OFFICE Microsoft Office Word docx object type confusion attempt (more info ...)attempted-admin 2017-11826   URL
44596FILE-OFFICE Microsoft Office request for oci.dll over SMB attempt (more info ...)attempted-user 2016-0041 82505  URL
44597FILE-OFFICE Microsoft Office request for iasdatastore2.dll over SMB attempt (more info ...)attempted-user 2016-0041 82505  URL
44598FILE-OFFICE Microsoft Office request for ociw32.dll over SMB attempt (more info ...)attempted-user 2016-0041 82505  URL
44599FILE-OFFICE Microsoft Office oci.dll dll-load exploit attempt (more info ...)attempted-user 2016-0041 82505  URL
44600FILE-OFFICE Microsoft Office iasdatastore2.dll dll-load exploit attempt (more info ...)attempted-user 2016-0041 82505  URL
44601FILE-OFFICE Microsoft Office ociw32.dll dll-load exploit attempt (more info ...)attempted-user 2016-0041 82505  URL
44631SERVER-WEBAPP Wordpress plugin bbPress comment cross site scripting attempt (more info ...)attempted-user    URL
44632SERVER-WEBAPP Wordpress content cross site scripting attempt (more info ...)attempted-user    URL
44694FILE-OFFICE Microsoft Office dde field code execution attempt (more info ...)attempted-admin    URL
44695FILE-OFFICE Microsoft Office dde field code execution attempt (more info ...)attempted-admin    URL
44795FILE-OFFICE Hewlett-Packard Autonomy KeyView library stack-based buffer overflow attempt (more info ...)attempted-user 2012-6277   
44796FILE-OFFICE Hewlett-Packard Autonomy KeyView library stack-based buffer overflow attempt (more info ...)attempted-user 2012-6277   
44838FILE-OFFICE Microsoft Office Word RTF memory corruption attempt (more info ...)attempted-user 2017-11854   
44839FILE-OFFICE Microsoft Office Word RTF memory corruption attempt (more info ...)attempted-user 2017-11854   
45061SERVER-WEBAPP Wordpress User History plugin cross site scripting attempt (more info ...)attempted-user 2017-15867   
45324SERVER-WEBAPP Dahua DVR user password hash query attempt (more info ...)attempted-recon 2013-6117 63742  
45328SERVER-WEBAPP Dahua DVR admin password reset attempt (more info ...)attempted-admin 2013-6117 63742  
45402FILE-OFFICE Microsoft Office Word memory corruption exploit attempt (more info ...)attempted-user 2018-0797   URL
45403FILE-OFFICE Microsoft Office Word memory corruption exploit attempt (more info ...)attempted-user 2018-0797   URL
45491FILE-OFFICE Microsoft Office Word PlfLfo use after free attempt (more info ...)attempted-user 2008-4024   
45492FILE-OFFICE Microsoft Office Word PlfLfo use after free attempt (more info ...)attempted-user 2008-4024   
45556FILE-OFFICE Microsoft Office embedded Office Art drawings execution attempt (more info ...)attempted-user 2010-3334   URL
45557FILE-OFFICE Microsoft Office embedded Office Art drawings execution attempt (more info ...)attempted-user 2010-3334   URL
45601SERVER-WEBAPP Cambium ePMP 1000 admin account password reset attempt (more info ...)web-application-attack 2017-5254   URL
45619FILE-OFFICE Microsoft Office Excel SxView record memory pointer corruption attempt (more info ...)attempted-user 2010-1245 40523  URL
45620FILE-OFFICE Microsoft Office Excel SxView record memory pointer corruption attempt (more info ...)attempted-user 2010-1245   URL
45879FILE-OFFICE Microsoft Office RTF listoverride memory corruption attempt (more info ...)attempted-user 2018-0922   URL
45880FILE-OFFICE Microsoft Office RTF listoverride memory corruption attempt (more info ...)attempted-user 2018-0922   URL
46108SERVER-WEBAPP Cisco Prime Collaboration Provisioning writable file privilege escalation attempt (more info ...)attempted-admin 2018-0144   
46109SERVER-WEBAPP Cisco Prime Collaboration Provisioning writable file privilege escalation attempt (more info ...)attempted-admin 2018-0144   
46233FILE-OFFICE Microsoft JET Database remote code execution attempt (more info ...)attempted-user 2018-1003   URL
46234FILE-OFFICE Microsoft JET Database remote code execution attempt (more info ...)attempted-user 2018-1003   URL
46483SERVER-WEBAPP Wordpress VideoWhisper Live Streaming Integration plugin double extension file upload attempt (more info ...)web-application-attack 2014-1905   
46899POLICY-OTHER Cisco Prime Collaboration Provisioning access control group modification request detected (more info ...)policy-violation 2018-0317   URL
46931INDICATOR-COMPROMISE dynamic Excel web query file download attempt (more info ...)attempted-admin    URL
46932INDICATOR-COMPROMISE dynamic Excel web query file download attempt (more info ...)attempted-admin    URL
46979INDICATOR-COMPROMISE Microsoft Office Discovery User-Agent to a potential URL shortener service (more info ...)misc-activity    URL
46980INDICATOR-COMPROMISE Microsoft Office Discovery User-Agent to a potential URL shortener service (more info ...)misc-activity    URL
47064FILE-OFFICE Microsoft Office Word malformed emf remote code execution attempt (more info ...)attempted-user 2017-8510   
47159SERVER-WEBAPP Cognex VisionView directory traversal attempt (more info ...)web-application-attack    URL
47199FILE-OFFICE Microsoft Office Excel fileVersion use-after-free attempt (more info ...)attempted-user 2015-2558   URL
47200FILE-OFFICE Microsoft Office Excel fileVersion use-after-free attempt (more info ...)attempted-user 2015-2558   URL
47201FILE-OFFICE Microsoft Office Excel fileVersion use-after-free attempt (more info ...)attempted-user 2015-2558   URL
47202FILE-OFFICE Microsoft Office Excel fileVersion use-after-free attempt (more info ...)attempted-user 2015-2558   URL
47203FILE-OFFICE Microsoft Office Excel fileVersion use-after-free attempt (more info ...)attempted-user 2015-2558   URL
47204FILE-OFFICE Microsoft Office Excel fileVersion use-after-free attempt (more info ...)attempted-user 2015-2558   URL
47205FILE-OFFICE Microsoft Office Word sprmSDyaTop memory leak attempt (more info ...)attempted-user 2016-3316   URL
47403FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47404FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47406FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47407FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47408FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47409FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47410FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47411FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47412FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0641 attack attempt (more info ...)attempted-user 2018-3975   URL
47424SERVER-WEBAPP Site Editor WordPress plugin local file access attempt (more info ...)web-application-attack 2018-7422   
47565FILE-OFFICE LibreOffice WEBSERVICE arbitrary file disclosure attempt (more info ...)attempted-user 2018-6871   
47566FILE-OFFICE LibreOffice WEBSERVICE arbitrary file disclosure attempt (more info ...)attempted-user 2018-6871   
47668SERVER-WEBAPP WordPress plugin WP with Spritz remote file include attempt (more info ...)web-application-attack    URL
47669SERVER-WEBAPP Wordpress plugin WP with Spritz directory traversal attempt (more info ...)web-application-attack    URL
47880POLICY-OTHER Cisco Video Surveillance Operations Manager default password use attempt (more info ...)policy-violation 2018-15427   URL
47889FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user 2012-0143 53374  URL
47890FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user 2012-0143 53374  URL
48136FILE-OFFICE Microsoft Office Excel SYLK file arbitrary code execution attempt (more info ...)policy-violation    
48137FILE-OFFICE Microsoft Office Excel SYLK file arbitrary code execution attempt (more info ...)policy-violation    
48138FILE-OFFICE Microsoft Office Excel SYLK file arbitrary code execution attempt (more info ...)policy-violation    
48139FILE-OFFICE Microsoft Office Excel SYLK file arbitrary code execution attempt (more info ...)policy-violation    
48272SERVER-WEBAPP Netgear Router admin password access attempt (more info ...)policy-violation    
48385FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0713 attack attempt (more info ...)attempted-user 2018-4040   URL
48386FILE-OFFICE TRUFFLEHUNTER TALOS-2018-0713 attack attempt (more info ...)attempted-user 2018-4040   URL
49182FILE-OFFICE Microsoft Office Publisher Opltc memory corruption attempt (more info ...)attempted-user 2011-3410   URL
49183FILE-OFFICE Microsoft Office Publisher Opltc memory corruption attempt (more info ...)attempted-user 2011-3410   URL
49248SERVER-WEBAPP WordPress login reconnaissance attempt (more info ...)suspicious-login    URL
49249SERVER-WEBAPP WordPress login reconnaissance attempt (more info ...)suspicious-login    URL
49253FILE-OFFICE Microsoft Office Word styleWithEffects use-after-free attempt (more info ...)attempted-user 2014-4117   URL
49254FILE-OFFICE Microsoft Office Word styleWithEffects use-after-free attempt (more info ...)attempted-user 2014-4117   URL
49285FILE-OFFICE Microsoft Access arbitrary code execution attempt (more info ...)attempted-user 2013-3157   URL
49286FILE-OFFICE Microsoft Access arbitrary code execution attempt (more info ...)attempted-user 2013-3157   URL
49299FILE-OFFICE Microsoft Access arbitrary code execution attempt (more info ...)attempted-user 2013-3156   URL
49300FILE-OFFICE Microsoft Access arbitrary code execution attempt (more info ...)attempted-user 2013-3156   URL
49323FILE-OFFICE Microsoft Office Excel Lel record memory corruption attempt (more info ...)attempted-user 2011-3403   URL
49324FILE-OFFICE Microsoft Office Excel Lel record memory corruption attempt (more info ...)attempted-user 2011-3403   URL
49427FILE-OTHER Microsoft Wordpad embedded BMP overflow attempt (more info ...)attempted-user 2013-3940   URL
49428FILE-OTHER Microsoft Wordpad embedded BMP overflow attempt (more info ...)attempted-user 2013-3940   URL
49431FILE-OFFICE Microsoft Office Publisher 2003 EscherStm memory corruption attempt (more info ...)attempted-user 2011-3411 50949  URL
49432FILE-OFFICE Microsoft Office Publisher 2003 EscherStm memory corruption attempt (more info ...)attempted-user 2011-3411 50949  URL
49461POLICY-OTHER D-Link DIR-615 remote unauthenticated password modification attempt (more info ...)policy-violation    URL
49462POLICY-OTHER D-Link DIR-615 remote unauthenticated password modification attempt (more info ...)policy-violation    URL
49494FILE-OFFICE Microsoft Office MSCOMCTL ActiveX control tabstrip method attempt (more info ...)attempted-user 2013-1313   URL
49500FILE-OFFICE Microsoft Office Excel conditional code execution attempt (more info ...)attempted-user 2011-1989   URL
49501FILE-OFFICE Microsoft Office Excel conditional code execution attempt (more info ...)attempted-user 2011-1989   URL
49756FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0794 attack attempt (more info ...)attempted-user 2019-5032   URL
49757FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0794 attack attempt (more info ...)attempted-user 2019-5032   URL
49761FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0795 attack attempt (more info ...)attempted-user 2019-5033   URL
49775FILE-OFFICE Microsoft Office Equation Editor object stack buffer overflow attempt (more info ...)attempted-user 2017-11882   URL
49852FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0805 attack attempt (more info ...)attempted-user 2019-5041   URL
49853FILE-OFFICE TRUFFLEHUNTER TALOS-2019-0805 attack attempt (more info ...)attempted-user 2019-5041   URL
49939FILE-OFFICE Microsoft Office PowerPoint malformed RecolorInfoAtom out of bounds read attempt (more info ...)attempted-user 2011-1270   URL
50708SERVER-WEBAPP WordPress Rencontre plugin cross site scripting attempt (more info ...)attempted-user 2019-13413   
50818FILE-OFFICE Microsoft Office Project file parsing arbitrary memory access attempt (more info ...)attempted-user 2009-0102   URL
50819FILE-OFFICE Microsoft Office Project file parsing arbitrary memory access attempt (more info ...)attempted-user 2009-0102   URL
50820FILE-OFFICE Microsoft Office Project file parsing arbitrary memory access attempt (more info ...)attempted-user 2009-0102   URL
50821FILE-OFFICE Microsoft Office Project file parsing arbitrary memory access attempt (more info ...)attempted-user 2009-0102   URL
50822FILE-OFFICE Microsoft Office Project file parsing arbitrary memory access attempt (more info ...)attempted-user 2009-0102   URL
50823FILE-OFFICE Microsoft Office Project file parsing arbitrary memory access attempt (more info ...)attempted-user 2009-0102   URL
50870APP-DETECT Quagga password challenge detected (more info ...)misc-activity    URL
50956FILE-OFFICE Microsoft Office Excel MsoDrawingGroup record remote code execution attempt (more info ...)attempted-user 2009-0559 35243  URL
50957FILE-OFFICE Microsoft Office Excel MsoDrawingGroup record remote code execution attempt (more info ...)attempted-user 2009-0559 35243  URL
50959FILE-OFFICE Microsoft VBE6.dll stack corruption attempt (more info ...)attempted-user 2010-0815 39931  URL
50962FILE-OFFICE Microsoft Office PowerPoint OfficeArt atom memory corruption attempt (more info ...)attempted-admin 2011-0976   URL
50968SERVER-WEBAPP WordPress Crop Image arbitrary file write attempt (more info ...)web-application-attack 2019-8943   
51059FILE-OFFICE Microsoft Office Excel Chart Sheet Substream memory corruption attempt (more info ...)attempted-user 2010-0823   URL
51061FILE-OFFICE Microsoft Office Excel Chart Sheet Substream memory corruption attempt (more info ...)attempted-user 2010-0823   URL
51062FILE-OFFICE Microsoft Office Excel Chart Sheet Substream memory corruption attempt (more info ...)attempted-user 2010-0823   URL
51076FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (more info ...)attempted-user 2010-1247   URL
51077FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (more info ...)attempted-user 2010-1247   URL
51078FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (more info ...)attempted-user 2010-1247   URL
51079FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (more info ...)attempted-user 2010-1247   URL
51088FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2010-3947 45274  URL
51089FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2010-3947 45274  URL
51090FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2010-3947 45274  URL
51091FILE-OFFICE Microsoft Office TIFF filter buffer overflow attempt (more info ...)attempted-user 2010-3947 45274  URL
51165FILE-OFFICE Microsoft Office Excel SxView heap overflow attempt (more info ...)attempted-user 2010-0821   URL
51166FILE-OFFICE Microsoft Office Excel SxView heap overflow attempt (more info ...)attempted-user 2010-0821   URL
51167FILE-OFFICE Microsoft Office Excel SxView heap overflow attempt (more info ...)attempted-user 2010-0821   URL
51168FILE-OFFICE Microsoft Office Excel SxView heap overflow attempt (more info ...)attempted-user 2010-0821   URL
51169FILE-OFFICE Microsoft Office Excel SxView heap overflow attempt (more info ...)attempted-user 2010-0821   URL
51170FILE-OFFICE Microsoft Office Excel SxView heap overflow attempt (more info ...)attempted-user 2010-0821   URL
51171FILE-OFFICE Microsoft Office Excel SxView heap overflow attempt (more info ...)attempted-user 2010-0821   URL
51172FILE-OFFICE Microsoft Office Excel SxView heap overflow attempt (more info ...)attempted-user 2010-0821   URL
51182FILE-OFFICE Microsoft Excel Jet Database Engine code execution attempt (more info ...)attempted-user 2017-8718   URL
51183FILE-OFFICE Microsoft Excel Jet Database Engine code execution attempt (more info ...)attempted-user 2017-8718   URL
51207SERVER-WEBAPP WordPress default admin theme cross site scripting attempt (more info ...)attempted-user    URL
51208SERVER-WEBAPP WordPress default admin theme cross site scripting attempt (more info ...)attempted-user    URL
51310FILE-OFFICE Microsoft Excel ExternSheet record remote code execution attempt (more info ...)attempted-user 2009-0558   URL
51311FILE-OFFICE Microsoft Excel ExternSheet record remote code execution attempt (more info ...)attempted-user 2009-0558   URL
51313FILE-OFFICE Microsoft Office Excel invalid FRTWrapper record integer underflow attempt (more info ...)attempted-user 2008-3471   URL
51314FILE-OFFICE Microsoft Office Excel invalid FRTWrapper record integer underflow attempt (more info ...)attempted-user 2008-3471   URL
51326FILE-OFFICE Microsoft Office Excel DBQueryExt record memory corruption attempt (more info ...)attempted-user 2010-1253   URL
51473FILE-OFFICE Microsoft Windows WordPad and Office text converter integer overflow attempt (more info ...)attempted-user 2009-2506   URL
51565FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user 2012-0141   URL
51566FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user 2012-0141   URL
51567FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user 2012-0141   URL
51568FILE-OFFICE Microsoft Office Excel invalid Window2 BIFF record value attempt (more info ...)attempted-user 2012-0141   URL
51663SERVER-WEBAPP WordPress plugin Grace Media Player local file inclusion attempt (more info ...)web-application-attack 2019-9618   URL
51804SERVER-WEBAPP Wordpress Admin panel delete action cross site scripting attempt (more info ...)attempted-user 2017-1244   URL
51805SERVER-WEBAPP Wordpress Admin panel delete action cross site scripting attempt (more info ...)attempted-user 2017-1244   URL
51806SERVER-WEBAPP Wordpress Admin panel delete action cross site scripting attempt (more info ...)attempted-user 2017-1244   URL
51807SERVER-WEBAPP Wordpress Admin panel delete action cross site scripting attempt (more info ...)attempted-user 2017-1244   URL
51946FILE-OFFICE Microsoft Office PowerPoint out of bounds value remote code execution attempt (more info ...)attempted-user 2010-0032   URL
51958FILE-OFFICE Microsoft Word RTF stack exhaustion denial of service attempt (more info ...)attempted-dos    
51959FILE-OFFICE Microsoft Word RTF stack exhaustion denial of service attempt (more info ...)attempted-dos    
51960FILE-OFFICE Microsoft Word RTF stack exhaustion denial of service attempt (more info ...)attempted-dos    
51999FILE-OTHER LibreOffice office document arbitrary script execution attempt (more info ...)attempted-user 2019-9848   
52000FILE-OTHER LibreOffice office document arbitrary script execution attempt (more info ...)attempted-user 2019-9848   
52001SERVER-WEBAPP WordPress meta_input path traversal attempt (more info ...)web-application-attack 2019-8942   
52055POLICY-OTHER WordPress XML-RPC pingback request attempt (more info ...)policy-violation    URL
52065FILE-OFFICE Microsoft Office Excel row record buffer overflow attempt (more info ...)attempted-user 2009-3130   URL
52066FILE-OFFICE Microsoft Office Excel row record buffer overflow attempt (more info ...)attempted-user 2009-3130   URL
52356FILE-OFFICE Microsoft Office Word invalid sprmTDefTable length stack buffer overflow attempt (more info ...)attempted-user 2008-4837 32584  URL
52357FILE-OFFICE Microsoft Office Word invalid sprmTDefTable length stack buffer overflow attempt (more info ...)attempted-user 2008-4837 32584  URL
52358FILE-OFFICE Microsoft Office Word invalid sprmTDefTable length stack buffer overflow attempt (more info ...)attempted-user 2008-4837 32584  URL
52359FILE-OFFICE Microsoft Office Word invalid sprmTDefTable length stack buffer overflow attempt (more info ...)attempted-user 2008-4837 32584  URL
53171POLICY-OTHER Cisco Data Center Network Manager password change detected (more info ...)policy-violation 2019-3114   URL
54568POLICY-OTHER Cisco Prime License Manager password reset detected (more info ...)policy-violation 2020-3140   URL
54814SERVER-WEBAPP WordPress TinyMCE Thumbnail Gallery plugin directory traversal attempt (more info ...)web-application-attack    URL
54815SERVER-WEBAPP WordPress TinyMCE Thumbnail Gallery plugin directory traversal attempt (more info ...)web-application-attack    URL
54816SERVER-WEBAPP WordPress TinyMCE Thumbnail Gallery plugin directory traversal attempt (more info ...)web-application-attack    URL
56324SERVER-WEBAPP KingComposer plugin for WordPress cross site scripting attempt (more info ...)attempted-user 2020-15299   URL
56325SERVER-WEBAPP KingComposer plugin for WordPress cross site scripting attempt (more info ...)attempted-user 2020-15299   URL
56833SERVER-WEBAPP WordPress plugin Total Upkeep database backup download attempt (more info ...)web-application-attack    URL
57064INDICATOR-COMPROMISE Microsoft Word internal OLE object update attempt (more info ...)attempted-user 2017-0199   URL
57065INDICATOR-COMPROMISE Microsoft Word internal OLE object update attempt (more info ...)attempted-user 2017-0199   URL
57384SERVER-WEBAPP WordPress Plugin WP-Paginate 2.1.3 cross site scripting attempt (more info ...)web-application-attack    URL
59472FILE-OFFICE Microsoft JET Database remote code execution attempt (more info ...)attempted-user 2018-1003   URL
59473FILE-OFFICE Microsoft JET Database remote code execution attempt (more info ...)attempted-user 2018-1003   URL
59560FILE-OTHER LibreOffice and OpenOffice ODF document PrinterSetup integer underflow attempt (more info ...)attempted-user 2015-5212   
59561FILE-OTHER LibreOffice and OpenOffice ODF document PrinterSetup integer underflow attempt (more info ...)attempted-user 2015-5212   
59584FILE-OFFICE Microsoft Office XML nested num tag double-free attempt (more info ...)attempted-user 2015-1650   
59664FILE-OFFICE Microsoft Word internal object auto update attempt (more info ...)attempted-user 2017-0199   URL
59665FILE-OFFICE Microsoft Word internal object auto update attempt (more info ...)attempted-user 2017-0199   URL
59838POLICY-OTHER WordPress Plugin WPGraphQL potential denial of service attempt (more info ...)policy-violation    URL
59839POLICY-OTHER WordPress Plugin WPGraphQL potential denial of service attempt (more info ...)policy-violation    URL
59970FILE-OFFICE Microsoft Word malformed jpeg remote code execution attempt (more info ...)attempted-user 2016-3318   URL
60254FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1574 attack attempt (more info ...)attempted-user 2022-33896   URL
60255FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1574 attack attempt (more info ...)attempted-user 2022-33896   URL
60480SERVER-WEBAPP Invision Community cross site scripting attempt (more info ...)web-application-attack 2020-29477   
60481SERVER-WEBAPP Invision Community cross site scripting attempt (more info ...)web-application-attack 2020-29477   
61011FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1673 attack attempt (more info ...)attempted-user 2022-43664   URL
61012FILE-OFFICE TRUFFLEHUNTER TALOS-2022-1673 attack attempt (more info ...)attempted-user 2022-43664   URL
61713SERVER-WEBAPP WordPress Comment Content Filter cross-site request forgery attempt (more info ...)attempted-admin 2019-9787   
61896POLICY-OTHER Cisco TelePresence Video Communication Server password reset request detected (more info ...)policy-violation 2023-20105   URL
61946POLICY-OTHER WordPress WooCommerce Stripe Gateway information disclosure attempt (more info ...)policy-violation 2023-34000   URL

 goto Top

Group: Client / Browser

# of attack rules in this group: 2202

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3689BROWSER-IE Microsoft Internet Explorer tRNS overflow attempt (more info ...)attempted-user  2012-4170  13941  18490  URL
10142BROWSER-PLUGINS Microsoft Internet Explorer LexRefBilingualTextContext ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10144BROWSER-PLUGINS Microsoft Internet Explorer LexRefBilingualTextContext ActiveX function call access (more info ...)attempted-user  2007-0219      URL
10145BROWSER-PLUGINS Microsoft Internet Explorer HTML Inline Sound Control ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10147BROWSER-PLUGINS Microsoft Internet Explorer HTML Inline Sound Control ActiveX function call access (more info ...)attempted-user  2007-0219      URL
10148BROWSER-PLUGINS Microsoft Internet Explorer HTML Inline Movie Control ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10150BROWSER-PLUGINS Microsoft Internet Explorer HTML Inline Movie Control ActiveX function call access (more info ...)attempted-user  2007-0219      URL
10151BROWSER-PLUGINS Microsoft Internet Explorer BlnSetUser Proxy ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10153BROWSER-PLUGINS Microsoft Internet Explorer BlnSetUser Proxy ActiveX function call access (more info ...)attempted-user  2007-0219      URL
10154BROWSER-PLUGINS Microsoft Internet Explorer BlnSetUser Proxy 2 ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
11680SERVER-WEBAPP Oracle Java web proxy sockd buffer overflow attempt (more info ...)attempted-admin  2007-2881  24165    
12474BROWSER-PLUGINS Oracle Java Web Start ActiveX function call access (more info ...)attempted-user  2007-5019  25734    
15191BROWSER-FIREFOX Mozilla Firefox animated PNG processing integer overflow (more info ...)attempted-user  2008-4064      
15237FILE-IDENTIFY Java .class file download request (more info ...)misc-activity        URL
15428BROWSER-FIREFOX Mozilla Firefox SVG data processing memory corruption attempt (more info ...)attempted-user  2009-0771  33990    URL
15482SERVER-OTHER Oracle Java System sockd authentication buffer overflow attempt (more info ...)attempted-admin  2007-2881      
15733BROWSER-IE Microsoft Internet Explorer empty table tag memory corruption attempt (more info ...)attempted-user  2009-1918      URL
15872BROWSER-FIREFOX Mozilla Firefox defineSetter function pointer memory corruption attempt (more info ...)attempted-user  2009-2469  35758    
16032BROWSER-IE Microsoft Internet Explorer HTML Decoding memory corruption attempt (more info ...)attempted-user  2006-2382  18309    
16344BROWSER-FIREFOX Mozilla Firefox top-level script object offset calculation memory corruption attempt (more info ...)attempted-user  2009-3073  36343    
16347BROWSER-FIREFOX Mozilla Firefox browser engine memory corruption attempt (more info ...)attempted-user  2009-3382  36866    
16482BROWSER-IE Microsoft Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806  38615    URL
16667BROWSER-CHROME Google Chrome GURL cross origin bypass attempt (more info ...)attempted-user  2010-1663  39813    
16668BROWSER-CHROME Google Chrome GURL cross origin bypass attempt (more info ...)attempted-user  2010-1663  39813    
17153BROWSER-FIREFOX Mozilla Firefox plugin parameter array dangling pointer exploit attempt - 1 (more info ...)attempted-user  2010-2755  41933    URL
17154BROWSER-FIREFOX Mozilla Firefox plugin parameter array dangling pointer exploit attempt - 2 (more info ...)attempted-user  2010-2755  41933    URL
17236BROWSER-FIREFOX Mozilla Firefox nsPropertyTable PropertyList memory corruption attempt (more info ...)attempted-user  2009-3070      URL
17378BROWSER-FIREFOX Mozilla Firefox Animated PNG Processing integer overflow attempt (more info ...)attempted-user  2008-4064      
17379BROWSER-FIREFOX Mozilla Firefox Animated PNG Processing integer overflow attempt (more info ...)attempted-user  2008-4064      
17398BROWSER-FIREFOX Mozilla Firefox Javascript array.splice memory corruption attempt (more info ...)attempted-user  2009-0773  33990    
17399BROWSER-FIREFOX Mozilla Firefox Javascript array.splice memory corruption attempt (more info ...)attempted-user  2009-0773  33990    
17422BROWSER-FIREFOX Mozilla Firefox defineSetter function pointer memory corruption attempt (more info ...)attempted-user  2009-2469  35758    
17519BROWSER-FIREFOX Mozilla Firefox UTF-8 URL Handling Stack Buffer Overflow (more info ...)attempted-user  2008-0016  31346    
17557BROWSER-PLUGINS Novell iPrint ActiveX operation parameter overflow (more info ...)attempted-user  2008-2908  30986    URL
17631FILE-JAVA Oracle Java Web Start JNLP j2se key value buffer overflow attempt (more info ...)attempted-user  2008-3111  30148    
17642BROWSER-FIREFOX Mozilla Firefox ConstructFrame with floating first-letter memory corruption attempt (more info ...)attempted-user  2009-2462  35765    
17685BROWSER-IE Microsoft Internet Explorer invalid pointer memory corruption attempt (more info ...)attempted-user  2010-0806      URL
17686BROWSER-IE Microsoft Internet Explorer invalid pointer memory corruption attempt (more info ...)attempted-user  2010-0806      URL
17687BROWSER-IE Microsoft Internet Explorer invalid pointer memory corruption attempt (more info ...)attempted-user  2010-0806      URL
17688BROWSER-IE Microsoft Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806  38615    URL
17689BROWSER-IE Microsoft Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806      URL
18187BROWSER-FIREFOX Mozilla Firefox InstallTrigger.install memory corruption attempt (more info ...)attempted-user  2006-1790  17516    URL
18244FILE-JAVA Oracle Java browser plugin docbase overflow attempt (more info ...)attempted-user  2010-3552  44023    
18245BROWSER-PLUGINS Oracle Java browser plugin docbase overflow attempt (more info ...)attempted-user  2010-3552  44023    URL
18612SERVER-WEBAPP Oracle Java Web Server WebDAV Stack Buffer Overflow attempt (more info ...)attempted-admin  2010-0361  37874    
18613SERVER-WEBAPP Oracle Java Web Server WebDAV Stack Buffer Overflow attempt (more info ...)attempted-admin  2010-0361  37874    
18649PROTOCOL-SCADA IGSS IGSSDataServer.exe file operation overflow attempt (more info ...)attempted-admin  2011-4050  46936    
18679SERVER-OTHER Oracle Java Applet2ClassLoader Remote Code Execution (more info ...)attempted-user  2010-4452      URL
18958BROWSER-WEBKIT Apple Safari Webkit attribute child removal code execution attempt (more info ...)attempted-user  2010-1119  40642    
19713BROWSER-FIREFOX Mozilla Array.reduceRight integer overflow (more info ...)attempted-user  2011-2371  48372    
19714BROWSER-FIREFOX Mozilla Array.reduceRight integer overflow (more info ...)attempted-user  2011-2371  48372    
19809BROWSER-IE Microsoft Internet Explorer covered object memory corruption attempt (more info ...)attempted-user  2012-1260      URL
19814BROWSER-IE Microsoft Internet Explorer empty table tag memory corruption attempt (more info ...)attempted-user  2009-1918      URL
20030PROTOCOL-SCADA IGSS IGSSDataServer.exe file operation directory traversal attempt (more info ...)attempted-admin  2011-1567  46936    
20072BROWSER-FIREFOX Mozilla Firefox nsTreeRange Use After Free attempt (more info ...)attempted-user  2011-0073      URL
20215PROTOCOL-SCADA Measuresoft ScadaPro directory traversal file operation attempt (more info ...)attempted-admin  2011-3497      
20444FILE-JAVA Oracle Java browser plugin docbase overflow attempt (more info ...)attempted-user  2010-3552  44023    
20492FILE-IDENTIFY Universal Binary/Java Bytecode file magic detected (more info ...)misc-activity        
20600BROWSER-FIREFOX Mozilla Products SVG text content element getCharNumAtPosition use after free attempt (more info ...)attempted-user  2011-0084  49213    
20622FILE-JAVA Oracle Java Applet remote code execution attempt (more info ...)attempted-user  2012-5076      
20820FILE-JAVA Oracle Java JNLP parameter argument injection attempt (more info ...)attempted-user  2005-0418      
20831FILE-JAVA Oracle Java Applet Rhino script engine remote code execution attempt (more info ...)attempted-user  2011-3544      
21057FILE-OTHER Java Applet Rhino script engine remote code execution attempt (more info ...)attempted-user  2011-3544      
21092MALWARE-TOOLS JavaScript LOIC attack (more info ...)attempted-dos        URL
21292BROWSER-IE Microsoft Internet Explorer style.position use-after-free memory corruption attempt (more info ...)attempted-dos  2012-0155      URL
21438EXPLOIT-KIT Blackhole exploit kit JavaScript carat string splitting with hostile applet (more info ...)trojan-activity  2012-4681      URL
21481FILE-JAVA Oracle Java Web Start arbitrary command execution attempt (more info ...)attempted-user  2012-0500      
21664FILE-JAVA Oracle Java JRE sandbox Atomic breach attempt (more info ...)attempted-user  2012-0507  52161    
21665FILE-JAVA Oracle Java JRE sandbox Atomic breach attempt (more info ...)attempted-user  2012-0507  52161    
21666FILE-JAVA Oracle Java JRE sandbox Atomic breach attempt (more info ...)attempted-user  2015-2590  52161    
21667FILE-JAVA Oracle Java JRE sandbox Atomic breach attempt (more info ...)attempted-user  2012-0507  52161    
21668EXPLOIT-KIT Java exploit kit iframe drive by attempt (more info ...)attempted-user  2011-3544      URL
21790BROWSER-IE Microsoft Internet Explorer SelectAll dangling pointer use after free attempt (more info ...)attempted-user  2012-0171      URL
21791BROWSER-IE Microsoft Internet Explorer SelectAll dangling pointer use after free attempt (more info ...)attempted-user  2012-0171      URL
21793BROWSER-IE Microsoft Internet Explorer vector graphics reference counting use-after-free attempt (more info ...)attempted-user  2012-0172  52906    URL
21796BROWSER-IE Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt (more info ...)attempted-user  2012-0170  52904    URL
21869FILE-OTHER Java JRE sandbox breach attempt (more info ...)attempted-user  2012-0507  52161    
21881FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2012-0775  52949    URL
21953BROWSER-FIREFOX Mozilla Multiple Products HTML href shell attempt (more info ...)policy-violation  2004-0648      
22038BROWSER-IE Microsoft Internet Explorer SelectAll dangling pointer use after free attempt (more info ...)attempted-user  2012-0171      URL
22080BROWSER-IE Microsoft Internet Explorer xbap custom ISeralizable object exception attempt (more info ...)attempted-user  2012-0161      URL
23008FILE-JAVA Oracle Java Rhino script engine remote code execution attempt (more info ...)attempted-user  2011-3544      
23060BROWSER-IE Microsoft Internet Explorer style.position use-after-free memory corruption attempt (more info ...)attempted-dos  2012-0155      URL
23106EXPLOIT-KIT SET java applet load attempt (more info ...)attempted-user        
23116BROWSER-IE Microsoft Internet Explorer 9 CTreeNode use after free attempt (more info ...)attempted-user  2012-1878      URL
23117BROWSER-IE Microsoft Internet Explorer 9 DOM element use after free attempt (more info ...)attempted-user  2012-1877      URL
23118BROWSER-IE Microsoft Internet Explorer console object use after free attempt (more info ...)attempted-user  2012-1874      URL
23121BROWSER-IE Microsoft Internet Explorer center element dynamic manipulation attempt (more info ...)attempted-user  2012-1523      URL
23122BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)misc-attack  2012-1881      URL
23123BROWSER-IE Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt (more info ...)attempted-user  2012-1880      URL
23124BROWSER-IE Microsoft Internet Explorer html table column span width increase memory corruption attempt (more info ...)attempted-user  2012-1876      URL
23125BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
23126BROWSER-IE Microsoft Internet Explorer insertAdjacentText memory corruption attempt (more info ...)attempted-user  2012-1879      URL
23142BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23143BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23144BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23145BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23146BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23212BROWSER-FIREFOX Mozilla Firefox IDB use-after-free attempt (more info ...)attempted-user  2012-0469      URL
23219EXPLOIT-KIT Redkit exploit kit Java Exploit request to .class file (more info ...)trojan-activity  2013-2423      URL
23220EXPLOIT-KIT Redkit exploit kit Java Exploit Requested - 5 digit jar (more info ...)trojan-activity  2013-2423      URL
23273FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723      URL
23274FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723      URL
23275FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723      URL
23276FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723      URL
23277FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723      URL
23278BROWSER-IE Microsoft Internet Explorer nested list memory corruption attempt (more info ...)attempted-user  2012-1522      URL
23285BROWSER-IE Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt (more info ...)attempted-user  2012-0170  52904    URL
23286BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23287BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23288BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23289BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23290BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23292BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23294BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23295BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23296BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23297BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23299BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23300BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23302BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23303BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user  2012-1889      URL
23609BROWSER-IE Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt (more info ...)attempted-user  2012-1880      URL
23611FILE-PDF JavaScript contained in an xml template embedded in a pdf attempt (more info ...)trojan-activity  2019-7115      URL
23612FILE-PDF JavaScript contained in an xml template embedded in a pdf attempt (more info ...)trojan-activity  2019-7115      URL
23614FILE-JAVA Oracle JavaScript heap exploitation library usage attempt (more info ...)attempted-user  2012-4969      URL
23637FILE-IDENTIFY Java .class file attachment detected (more info ...)misc-activity        
23638FILE-IDENTIFY Java .class file attachment detected (more info ...)misc-activity        
23676FILE-IDENTIFY Universal Binary/Java Bytecode file magic detected (more info ...)misc-activity        
23789BROWSER-FIREFOX Mozilla Multiple Products table frames memory corruption attempt (more info ...)attempted-user  2012-1952      
23790BROWSER-FIREFOX Mozilla Multiple Products table frames memory corruption attempt (more info ...)attempted-user  2012-1952      
23834BROWSER-IE Microsoft Internet Explorer asynchronous code execution attempt (more info ...)attempted-user  2012-2521      URL
23835BROWSER-IE Microsoft Internet Explorer asynchronous code execution attempt (more info ...)attempted-user  2012-2521      URL
23836BROWSER-IE Microsoft Internet Explorer negative margin use after free attempt (more info ...)attempted-user  2012-1526  54950    URL
23840BROWSER-IE Microsoft Internet Explorer sign extension vulnerability exploitation attempt (more info ...)attempted-user  2012-2523      URL
23841BROWSER-IE Microsoft Internet Explorer sign extension vulnerability exploitation attempt (more info ...)attempted-user  2012-2523      URL
23958SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020      
23959SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020      
23960SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
23961SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24020FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24021FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24022FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24023FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24024FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24025FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24026FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-5076      
24027FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24028FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24036FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24037FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24038FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24055FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24056FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24057FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24058FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24063FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24064FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24065FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24066FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24084FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24085FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24125FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24126FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24187BROWSER-FIREFOX Mozilla Array.reduceRight integer overflow (more info ...)attempted-user  2011-2371  48372    
24188BROWSER-FIREFOX Mozilla Array.reduceRight integer overflow (more info ...)attempted-user  2011-2371  48372    
24201FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723      URL
24202FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723      URL
24203BROWSER-IE Microsoft Internet Explorer html table column span width increase memory corruption attempt (more info ...)attempted-user  2012-1876      URL
24204BROWSER-IE Microsoft Internet Explorer html table column span width increase memory corruption attempt (more info ...)attempted-user  2012-1876      URL
24205BROWSER-IE Microsoft Internet Explorer html table column span width increase memory corruption attempt (more info ...)attempted-user  2012-1876      URL
24212BROWSER-IE Microsoft Internet Explorer execCommand use-after-free attempt (more info ...)attempted-user  2012-4969      URL
24252BROWSER-IE Microsoft Internet Explorer execCommand use embedded within javascript tags (more info ...)attempted-user  2012-4969      
24313SERVER-WEBAPP HP OpenView Operations Agent request attempt (more info ...)misc-activity  2012-2020      
24314SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24315SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24316SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24317SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24318SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24319SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24320SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24570BROWSER-FIREFOX Mozilla Firefox IDB use-after-free attempt (more info ...)attempted-user  2012-0469      URL
24571BROWSER-FIREFOX Mozilla Firefox IDB use-after-free attempt (more info ...)attempted-user  2012-0469      URL
24572BROWSER-FIREFOX Mozilla Firefox IDB use-after-free attempt (more info ...)attempted-user  2012-0469      URL
24573BROWSER-FIREFOX Mozilla Firefox IDB use-after-free attempt (more info ...)attempted-user  2012-0469      URL
24574BROWSER-FIREFOX Mozilla Firefox IDB use-after-free attempt (more info ...)attempted-user  2012-0469      URL
24653BROWSER-IE Microsoft Internet Explorer 9 table th element use after free attempt (more info ...)attempted-user  2012-4775      URL
24654BROWSER-IE Microsoft Internet Explorer 9 table th element use after free attempt (more info ...)attempted-user  2012-4775      URL
24660BROWSER-IE Microsoft Internet Explorer 9 style properties use after free attempt (more info ...)attempted-user  2012-1539      URL
24661BROWSER-IE Microsoft Internet Explorer 9 style properties use after free attempt (more info ...)attempted-user  2012-1539      URL
24662BROWSER-IE Microsoft Internet Explorer button object use after free memory corruption attempt (more info ...)attempted-user  2012-1538      URL
24663BROWSER-IE Microsoft Internet Explorer button object use after free memory corruption attempt (more info ...)attempted-user  2012-1538      URL
24701FILE-JAVA Oracle Java Runtime true type font idef opcode heap buffer overflow attempt (more info ...)attempted-user  2012-0499      
24769FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24770FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
24786EXPLOIT-KIT CritX exploit kit Java Exploit request structure (more info ...)trojan-activity        URL
24787EXPLOIT-KIT CritX exploit kit Java Exploit download (more info ...)trojan-activity        URL
24793EXPLOIT-KIT KaiXin exploit kit Java Class download (more info ...)trojan-activity  2012-1889      URL
24808FILE-FLASH Microsoft Internet Explorer premature unload of Flash plugin use after free attempt (more info ...)attempted-user  2012-5272      URL
24809FILE-FLASH Microsoft Internet Explorer premature unload of Flash plugin use after free attempt (more info ...)attempted-user  2012-5272      URL
24827SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24828SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24829SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24830SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24831SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24832SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24833SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24834SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24835SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24836SERVER-WEBAPP HP OpenView Operations Agent buffer overflow attempt (more info ...)attempted-admin  2012-2020  54362    URL
24904FILE-JAVA Oracle Java Web Start JNLP j2se key value buffer overflow attempt (more info ...)attempted-user  2008-3111  30148    
24915FILE-JAVA Oracle Java Runtime true type font idef opcode heap buffer overflow attempt (more info ...)attempted-user  2012-0499      
24956BROWSER-IE Microsoft Internet Explorer invalid object property use after free memory corruption attempt (more info ...)attempted-dos  2012-4787      URL
24993FILE-JAVA Oracle Java Applet remote code execution attempt (more info ...)attempted-user  2012-5076      
24994BROWSER-FIREFOX Mozilla Firefox onChannelRedirect method attempt (more info ...)attempted-user  2011-0065      
25006FILE-JAVA Oracle JavaScript heap exploitation library usage attempt (more info ...)attempted-user  2012-4969      URL
25041EXPLOIT-KIT Java User-Agent flowbit set (more info ...)misc-activity        
25046EXPLOIT-KIT CritX exploit kit Java V6 exploit download (more info ...)trojan-activity        URL
25047EXPLOIT-KIT CritX exploit kit Java V7 exploit download (more info ...)trojan-activity        URL
25052EXPLOIT-KIT Redkit exploit kit Java Exploit requested - 3 digit (more info ...)trojan-activity  2012-4681      
25078BROWSER-IE Microsoft Internet Explorer sign extension vulnerability exploitation attempt (more info ...)attempted-user  2012-2523      URL
25079BROWSER-IE Microsoft Internet Explorer sign extension vulnerability exploitation attempt (more info ...)attempted-user  2012-2523      URL
25121FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723  53960    URL
25122FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723  53960    URL
25123FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-4681  53960    URL
25125BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25126BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25127BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25128BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25129BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25130BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25131BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25132BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25133BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25134BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25234BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25235BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user  2012-4792      URL
25297FILE-MULTIMEDIA Mozilla products Ogg Vorbis decoding memory corruption attempt (more info ...)attempted-user  2012-0444  51753    
25301EXPLOIT-KIT redirect to malicious java archive attempt (more info ...)attempted-user  2013-0422  57246    URL
25320BROWSER-IE Microsoft Internet Explorer nonexistent attribute removal memory corruption attempt (more info ...)attempted-dos  2012-1524      URL
25392FILE-JAVA Oracle Java Rhino script engine remote code execution attempt (more info ...)attempted-user  2011-3544      
25449FILE-PDF Javascript openDoc UNC network request attempt (more info ...)policy-violation  2013-0622  57295    URL
25450FILE-PDF Javascript openDoc UNC network request attempt (more info ...)policy-violation  2013-0622  57295    URL
25472FILE-JAVA Oracle Java JMX class arbitrary code execution attempt (more info ...)attempted-user  2013-0431  57246    URL
25473FILE-JAVA Oracle Java JMX class arbitrary code execution attempt (more info ...)attempted-user  2013-0422  57246    URL
25475FILE-PDF JavaScript contained in an xml template embedded in a pdf attempt (more info ...)trojan-activity  2019-7115      URL
25539EXPLOIT-KIT Red Dot java retrieval attempt (more info ...)trojan-activity  2013-0422      URL
25650BROWSER-IE Microsoft Internet Explorer malformed iframe buffer overflow attempt (more info ...)attempted-user  2004-1050  11515    
25764EXPLOIT-KIT Zuponcic exploit kit Oracle Java file download (more info ...)trojan-activity        URL
25769BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
25771BROWSER-IE Microsoft Internet Explorer custom cursor file use after free attempt (more info ...)attempted-user  2013-0028      URL
25772BROWSER-IE Microsoft Internet Explorer onbeforeeditfocus element attribute use after free attempt (more info ...)attempted-user  2013-0029      URL
25773BROWSER-IE Microsoft Internet Explorer VML shape object malformed path attempt (more info ...)attempted-user  2013-0030      
25775BROWSER-IE Microsoft Internet Explorer pre-line use after free attempt (more info ...)attempted-user  2015-6050      URL
25776BROWSER-IE Microsoft Internet Explorer CTreePos use after free memory corruption attempt (more info ...)attempted-user  2013-0024      URL
25777BROWSER-IE Microsoft Internet Explorer CTreePos use after free memory corruption attempt (more info ...)attempted-user  2013-0024      URL
25784BROWSER-IE Microsoft Internet Explorer text layout calculation use after free attempt (more info ...)attempted-user  2013-0022      URL
25785BROWSER-IE Microsoft Internet Explorer text layout calculation use after free attempt (more info ...)attempted-user  2013-0022      URL
25786BROWSER-IE Microsoft Internet Explorer 9 deleted object access memory corruption attempt (more info ...)attempted-user  2013-0026  57832    URL
25787BROWSER-IE Microsoft Internet Explorer 9 deleted object access memory corruption attempt (more info ...)attempted-user  2013-0026  57832    URL
25788BROWSER-IE Microsoft Internet Explorer iframe use after free attempt (more info ...)attempted-user  2013-0019      URL
25789BROWSER-IE Microsoft Internet Explorer iframe use after free attempt (more info ...)attempted-user  2013-0019      URL
25790BROWSER-IE Microsoft Internet Explorer compatibility mode invalid memory access attempt (more info ...)attempted-user  2013-0021      URL
25791BROWSER-IE Microsoft Internet Explorer compatibility mode invalid memory access attempt (more info ...)attempted-user  2013-0021      URL
25792BROWSER-IE Microsoft Internet Explorer SVG object use after free attempt (more info ...)attempted-admin  2013-0023      URL
25805EXPLOIT-KIT Whitehole exploit kit Java exploit retrieval (more info ...)trojan-activity  2013-2423      URL
25823EXPLOIT-KIT CritX exploit kit Java V5 exploit download (more info ...)trojan-activity        URL
25830FILE-JAVA Oracle Java malicious class download attempt (more info ...)attempted-user  2013-2471  60659    
25831FILE-JAVA Oracle Java JMX class arbitrary code execution attempt (more info ...)attempted-user  2013-0422  57246    URL
25832FILE-JAVA Oracle Java JMX class arbitrary code execution attempt (more info ...)attempted-user  2013-0431  57246    URL
25833FILE-JAVA Oracle Java malicious class download attempt (more info ...)attempted-user  2013-0422  57246    
25834FILE-JAVA Oracle Java JMX class arbitrary code execution attempt (more info ...)attempted-user  2013-0422  57246    URL
25984BROWSER-IE Microsoft Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806  38615    URL
25985BROWSER-IE Microsoft Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806  38615    URL
25986BROWSER-IE Microsoft Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806  38615    URL
26000FILE-FLASH Adobe Flash Player HTML & Javascript SWF use-after-free execution attempt (more info ...)attempted-user  2013-0648  58186    URL
26001FILE-FLASH Adobe Flash Player HTML & Javascript SWF use-after-free execution attempt (more info ...)attempted-user  2013-0648  58186    URL
26003FILE-FLASH Adobe Flash Player HTML & Javascript SWF use-after-free execution attempt (more info ...)attempted-user  2013-0648  58186    URL
26005FILE-FLASH Adobe Flash Player HTML & Javascript SWF use-after-free execution attempt (more info ...)attempted-user  2013-0648  58186    URL
26007FILE-FLASH Adobe Flash Player HTML & Javascript SWF use-after-free execution attempt (more info ...)attempted-user  2013-0648  58186    URL
26025INDICATOR-COMPROMISE Java user-agent request to svchost.jpg (more info ...)trojan-activity  2013-1493      
26035EXPLOIT-KIT Crimeboss exploit kit - java on (more info ...)trojan-activity        URL
26036EXPLOIT-KIT Crimeboss exploit kit - Java Exploit (more info ...)trojan-activity  2012-4681      URL
26038EXPLOIT-KIT Crimeboss exploit kit - Java exploit download (more info ...)trojan-activity  2013-0422      URL
26039EXPLOIT-KIT Crimeboss exploit kit - Java exploit download (more info ...)trojan-activity  2013-0422      URL
26125BROWSER-IE Microsoft Internet Explorer text transform use after free attempt (more info ...)attempted-user  2013-0087  58341    URL
26129BROWSER-IE Microsoft Internet Explorer htc file use after free attempt (more info ...)attempted-user  2013-0094      URL
26130BROWSER-IE Microsoft Internet Explorer htc file use after free attempt (more info ...)attempted-user  2013-0094      URL
26132BROWSER-IE Microsoft Internet Explorer saveHistory use after free attempt (more info ...)attempted-dos  2013-0088      URL
26133BROWSER-IE Microsoft Internet Explorer saveHistory use after free attempt (more info ...)attempted-dos  2013-0088      URL
26134BROWSER-IE Microsoft Internet Explorer 8 deleted object access memory corruption attempt (more info ...)attempted-user  2013-0091      URL
26135BROWSER-IE Microsoft Internet Explorer saveHistory use after free attempt (more info ...)attempted-user  2013-0089      URL
26136BROWSER-IE Microsoft Internet Explorer saveHistory use after free attempt (more info ...)attempted-user  2013-0089      URL
26137BROWSER-IE Microsoft Internet Explorer 9 onBeforeCopy use after free attempt (more info ...)attempted-user  2013-0093      URL
26138BROWSER-IE Microsoft Internet Explorer 9 onBeforeCopy use after free attempt (more info ...)attempted-user  2013-0093      URL
26157BROWSER-IE Microsoft Internet Explorer 9 onbeforeprint use after free attempt (more info ...)attempted-user  2013-0092      URL
26158BROWSER-IE Microsoft Internet Explorer 9 onbeforeprint use after free attempt (more info ...)attempted-user  2013-0092      URL
26159BROWSER-IE Microsoft Internet Explorer 9 onbeforeprint use after free attempt (more info ...)attempted-user  2013-0092      URL
26160BROWSER-IE Microsoft Internet Explorer 9 onbeforeprint use after free attempt (more info ...)attempted-user  2013-0092      URL
26161BROWSER-IE Microsoft Internet Explorer 9 onbeforeprint use after free attempt (more info ...)attempted-user  2013-0092      URL
26162BROWSER-IE Microsoft Internet Explorer 9 onbeforeprint use after free attempt (more info ...)attempted-user  2013-0092      URL
26185FILE-JAVA Oracle Java Gmbal package sandbox breach attempt (more info ...)attempted-user  2012-5076      
26186FILE-JAVA Oracle Java Gmbal package sandbox breach attempt (more info ...)attempted-user  2012-5076      
26195FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp integer overflow attempt (more info ...)attempted-user  2013-0809  58296    
26196FILE-JAVA Oracle Java 2D ImagingLib LookupOp integer overflow attempt (more info ...)attempted-user  2013-0809  58296    
26197FILE-JAVA Oracle Java 2D ImagingLib ConvolveOp integer overflow attempt (more info ...)attempted-user  2013-0809  58296    
26198FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp integer overflow attempt (more info ...)attempted-user  2013-0809  58296    
26199FILE-JAVA Oracle Java 2D ImagingLib LookupOp integer overflow attempt (more info ...)attempted-user  2013-0809  58296    
26200FILE-JAVA Oracle Java 2D ImagingLib ConvolveOp integer overflow attempt (more info ...)attempted-user  2013-0809  58296    
26216BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26217BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26218BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26219BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26220BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26221BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26222BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26223BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26224BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26225BROWSER-IE Microsoft Internet Explorer CHTMLEditor object use after free attempt (more info ...)attempted-user  2013-0027      URL
26292EXPLOIT-KIT Oracle Java Jar file downloaded when zip is defined (more info ...)trojan-activity        
26348EXPLOIT-KIT Redkit exploit kit java exploit delivery (more info ...)trojan-activity  2013-2423      URL
26377EXPLOIT-KIT Redkit exploit kit java exploit request (more info ...)trojan-activity  2013-2423      URL
26419BROWSER-IE Microsoft Internet Explorer 9 onbeforeprint use after free attempt (more info ...)attempted-user  2013-0092      URL
26420BROWSER-IE Microsoft Internet Explorer 9 onbeforeprint use after free attempt (more info ...)attempted-user  2013-0092      URL
26441INDICATOR-OBFUSCATION Obfuscated javascript/html generated by myobfuscate.com detected (more info ...)bad-unknown        URL
26509EXPLOIT-KIT Multiple exploit kit java payload detection (more info ...)trojan-activity  2013-2423      
26569BROWSER-IE Microsoft Internet Explorer null object access attempt (more info ...)attempted-user  2013-1347      URL
26571BROWSER-IE Microsoft Internet Explorer null object access attempt (more info ...)attempted-user  2013-1347      URL
26572BROWSER-IE Microsoft Internet Explorer null object access attempt (more info ...)attempted-user  2013-1347      URL
26584BROWSER-IE Microsoft Internet Explorer vector graphics reference counting use-after-free attempt (more info ...)attempted-user  2012-0172  52906    URL
26629BROWSER-IE Microsoft Internet Explorer setInterval focus use after free attempt (more info ...)attempted-admin  2013-1308      URL
26630BROWSER-IE Microsoft Internet Explorer CDispNode float css element use after free attempt (more info ...)attempted-user  2013-1309      URL
26631BROWSER-IE Microsoft Internet Explorer CDispNode float css element use after free attempt (more info ...)attempted-user  2013-1309      URL
26633BROWSER-IE Microsoft Internet Explorer html reload loop attempt (more info ...)misc-activity  2013-1306  59745    URL
26634BROWSER-IE Microsoft Internet Explorer 8 deleted object access via timer memory corruption attempt (more info ...)attempted-user  2013-1311      URL
26635BROWSER-IE Microsoft Internet Explorer 8 deleted object access via timer memory corruption attempt (more info ...)attempted-user  2013-1311      URL
26636BROWSER-IE Microsoft Internet Explorer DCOMTextNode object use after free attempt (more info ...)attempted-user  2013-1312      URL
26637BROWSER-IE Microsoft Internet Explorer DCOMTextNode object use after free attempt (more info ...)attempted-user  2013-1312      URL
26641BROWSER-IE Microsoft Internet Explorer runtimeStyle memory corruption attempt (more info ...)attempted-user  2013-1307      URL
26642BROWSER-IE Microsoft Internet Explorer runtimeStyle memory corruption attempt (more info ...)attempted-user  2013-1307      URL
26666BROWSER-IE Microsoft Internet Explorer ANIMATECOLOR SMIL access attempt (more info ...)attempted-user  2013-1347      
26668BROWSER-IE Microsoft Internet Explorer null object access attempt (more info ...)attempted-user  2013-1347      URL
26716FILE-JAVA Oracle Java font rendering remote code execution attempt (more info ...)attempted-user  2013-1491      URL
26717FILE-JAVA Oracle Java font rendering remote code execution attempt (more info ...)attempted-user  2013-1491      URL
26753BROWSER-IE Microsoft Internet Explorer CDispNode float css element use after free attempt (more info ...)attempted-user  2013-1309      URL
26754BROWSER-IE Microsoft Internet Explorer CDispNode float css element use after free attempt (more info ...)attempted-user  2013-1309      URL
26843BROWSER-IE Microsoft Internet Explorer 9 array element property use after free attempt (more info ...)attempted-user  2013-3112      URL
26844BROWSER-IE Microsoft Internet Explorer 9 layout engine memory corruption attempt (more info ...)attempted-user  2013-3122      URL
26845BROWSER-IE Microsoft Internet Explorer 10 insertImage with designMode on deleted object access attempt (more info ...)attempted-user  2013-3120      URL
26846BROWSER-IE Microsoft Internet Explorer 10 insertImage with designMode on deleted object access attempt (more info ...)attempted-user  2013-3120      URL
26847BROWSER-IE Microsoft Internet Explorer 10 use after free attempt (more info ...)attempted-user  2013-3125      URL
26849BROWSER-IE Microsoft Internet Explorer superscript use after free attempt (more info ...)attempted-user  2013-3111      URL
26851BROWSER-IE Microsoft Internet Explorer 5 compatibility mode use after free attempt (more info ...)attempted-user  2013-3121      URL
26867BROWSER-IE Microsoft Internet Explorer 8 select element deleted object access attempt (more info ...)attempted-user  2013-3139      URL
26868BROWSER-IE Microsoft Internet Explorer 8 select element deleted object access attempt (more info ...)attempted-user  2013-3139      URL
26869BROWSER-IE Microsoft Internet Explorer double-free memory corruption attempt (more info ...)attempted-user  2013-3118      URL
26870BROWSER-IE Microsoft Internet Explorer double-free memory corruption attempt (more info ...)attempted-user  2013-3118      URL
26871BROWSER-IE Microsoft Internet Explorer double-free memory corruption attempt (more info ...)attempted-user  2013-3118      URL
26872BROWSER-IE Microsoft Internet Explorer double-free memory corruption attempt (more info ...)attempted-user  2013-3118      URL
26873BROWSER-IE Microsoft Internet Explorer 9 CSS rules cache use-after-free attempt (more info ...)attempted-user  2013-3117      URL
26874BROWSER-IE Microsoft Internet Explorer 9 CSS rules cache use-after-free attempt (more info ...)attempted-user  2013-3117      URL
26875BROWSER-IE Microsoft Internet Explorer 9 CTreeNodeobject use-after-free attempt (more info ...)attempted-user  2013-3119      URL
26876BROWSER-IE Microsoft Internet Explorer 9 cached display node use-after-free attempt (more info ...)attempted-user  2013-3116      URL
26878BROWSER-IE Microsoft Internet Explorer 8 tree element use after free attempt (more info ...)attempted-user  2013-3110      URL
26882BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
26883BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
26884BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
26885BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
26886BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
26887BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
26888BROWSER-IE Microsoft Internet Explorer CTreeNode use after free memory corruption attempt (more info ...)attempted-user  2013-3142      URL
26889BROWSER-IE Microsoft Internet Explorer CTreeNode use after free memory corruption attempt (more info ...)attempted-user  2013-3142      URL
26894EXPLOIT-KIT Flashpack/Safe/CritX exploit kit Java V6 exploit download (more info ...)trojan-activity        URL
26895EXPLOIT-KIT Flashpack/Safe/CritX exploit kit Java V7 exploit download (more info ...)trojan-activity        URL
26985EXPLOIT-KIT Rawin exploit kit outbound java retrieval (more info ...)trojan-activity        
26988BROWSER-IE Microsoft Internet Explorer 9 CTreeNodeobject use-after-free attempt (more info ...)attempted-user  2013-3119      URL
27052MALWARE-OTHER Trojan.Java.JVDrop.A jar file download attempt (more info ...)trojan-activity        URL
27053MALWARE-OTHER Trojan.Java.JVDrop.A jar file download attempt (more info ...)trojan-activity        URL
27061BROWSER-IE Microsoft Internet Explorer 8 deleted object access via timer memory corruption attempt (more info ...)attempted-user  2013-1311      URL
27062BROWSER-IE Microsoft Internet Explorer 8 deleted object access via timer memory corruption attempt (more info ...)attempted-user  2013-1311      URL
27076FILE-JAVA Oracle Java Applet disable security manager attempt (more info ...)attempted-user  2013-2460  60635    URL
27077FILE-JAVA Oracle Java Applet disable security manager attempt (more info ...)attempted-user  2013-2460  60635    URL
27081EXPLOIT-KIT Nailed exploit kit Internet Explorer exploit download - autopwn (more info ...)trojan-activity  2012-4969      URL
27100BROWSER-IE Microsoft Internet Explorer double-free memory corruption attempt (more info ...)attempted-user  2013-3118      URL
27101BROWSER-IE Microsoft Internet Explorer double-free memory corruption attempt (more info ...)attempted-user  2013-3118      URL
27126BROWSER-IE Microsoft Internet Explorer setCapture use after free attempt (more info ...)attempted-user  2013-3150      URL
27127BROWSER-IE Microsoft Internet Explorer 10 CTreePos use-after-free attempt (more info ...)attempted-user  2013-3143      URL
27128BROWSER-IE Microsoft Internet Explorer 10 CTreePos use-after-free attempt (more info ...)attempted-user  2013-3143      URL
27129BROWSER-IE Microsoft Internet Explorer 9 use after free attempt (more info ...)attempted-user  2013-3148      URL
27130BROWSER-IE Microsoft Internet Explorer 9 use after free attempt (more info ...)attempted-user  2013-3148      URL
27131BROWSER-IE Microsoft Internet Explorer 8 CTreePos use after free attempt (more info ...)attempted-user  2013-3151      URL
27132BROWSER-IE Microsoft Internet Explorer PreviousTreePos use after free attempt (more info ...)attempted-user  2013-3153      URL
27133BROWSER-IE Microsoft Internet Explorer display node use after free attempt (more info ...)attempted-user  2013-3115      URL
27134BROWSER-IE Microsoft Internet Explorer display node use after free attempt (more info ...)attempted-user  2013-3115      URL
27135BROWSER-IE Microsoft Internet Explorer 10 CTreePos use after free attempt (more info ...)attempted-user  2013-3152      URL
27137BROWSER-IE Microsoft Internet Explorer CTreeNode use after free memory corruption attempt (more info ...)attempted-user  2013-3164      URL
27138BROWSER-IE Microsoft Internet Explorer CTreeNode use after free memory corruption attempt (more info ...)attempted-user  2013-3164      URL
27147BROWSER-IE Microsoft Internet Explorer 9 IE5 compatibility mode use after free attempt (more info ...)attempted-admin  2013-3144      URL
27148BROWSER-IE Microsoft Internet Explorer beforeeditfocus use after free exploit attempt (more info ...)attempted-user  2013-3147      URL
27149BROWSER-IE Microsoft Internet Explorer beforeeditfocus use after free exploit attempt (more info ...)attempted-user  2013-3147      URL
27150BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
27151BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
27152BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
27153BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
27154BROWSER-IE Microsoft Internet Explorer pElement member use after free attempt (more info ...)attempted-user  2013-3145      URL
27156BROWSER-IE Microsoft Internet Explorer table column-count integer overflow attempt (more info ...)attempted-user  2013-3146      URL
27157BROWSER-IE Microsoft Internet Explorer table column-count integer overflow attempt (more info ...)attempted-user  2013-3146      URL
27171BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
27172BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
27188FILE-JAVA Oracle Java Applet ProviderSkeleton sandbox bypass attempt (more info ...)attempted-user  2013-2460  60635    URL
27189FILE-JAVA Oracle Java Applet ProviderSkeleton sandbox bypass attempt (more info ...)attempted-user  2013-2460  60635    URL
27190FILE-JAVA Oracle Java Applet ProviderSkeleton sandbox bypass attempt (more info ...)attempted-user  2013-2460  60635    URL
27191FILE-JAVA Oracle Java Applet ProviderSkeleton sandbox bypass attempt (more info ...)attempted-user  2013-2460  60635    URL
27220BROWSER-IE Microsoft Internet Explorer virtual function table corruption attempt (more info ...)attempted-user  2012-2522  54951    URL
27221BROWSER-IE Microsoft Internet Explorer virtual function table corruption attempt (more info ...)attempted-user  2012-2522  54951    URL
27272INDICATOR-OBFUSCATION Javascript obfuscation - fromCharCode (more info ...)attempted-user        URL
27274EXPLOIT-KIT CritX exploit kit Java Exploit request structure (more info ...)trojan-activity        
27568BROWSER-FIREFOX Mozilla Firefox 17 onreadystatechange memory corruption attempt (more info ...)attempted-user  2013-1690      URL
27592INDICATOR-OBFUSCATION Javascript obfuscation - split - seen in IFRAMEr Tool attack (more info ...)misc-activity        URL
27605BROWSER-IE Microsoft Internet Explorer TreeNode use after free attempt (more info ...)attempted-user  2013-3188      URL
27606BROWSER-IE Microsoft Internet Explorer CSelectionManager use after free attempt (more info ...)attempted-admin  2013-3199      URL
27607BROWSER-IE Microsoft Internet Explorer content generation use after free attempt (more info ...)attempted-user  2013-3187      URL
27608BROWSER-IE Microsoft Internet Explorer CTreeNode object CSS text overflow attempt (more info ...)attempted-dos  2013-3189      URL
27612BROWSER-IE Microsoft Internet Explorer CMarkupPointer with SVG use-after-free attempt (more info ...)attempted-user  2013-3194      URL
27613BROWSER-IE Microsoft Internet Explorer CElement use-after-free attempt (more info ...)attempted-user  2013-3193      URL
27614BROWSER-IE Microsoft Internet Explorer CElement use-after-free attempt (more info ...)attempted-user  2013-3193      URL
27615BROWSER-IE Microsoft Internet Explorer MoveToMarkupPointer call with CControlTracker OnExitTree use-after-free attempt (more info ...)attempted-user  2013-3184      URL
27616BROWSER-IE Microsoft Internet Explorer MoveToMarkupPointer call with CControlTracker OnExitTree use-after-free attempt (more info ...)attempted-user  2013-3184      URL
27618BROWSER-IE Microsoft Internet Explorer 6 usp10.dll Bengali font stack overrun attempt (more info ...)attempted-dos  2013-3181      URL
27619BROWSER-IE Microsoft Internet Explorer 6 usp10.dll Bengali font stack overrun attempt (more info ...)attempted-dos  2013-3181      URL
27620BROWSER-IE Microsoft Internet Explorer merged stylesheet array use after free attempt (more info ...)attempted-user  2013-3191      URL
27621FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
27622FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
27672FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
27673FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
27674FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
27675FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
27676FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
27677FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
27691FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2013-2471  60659    URL
27692FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2013-2471  60659    URL
27697EXPLOIT-KIT Kore exploit kit successful Java exploit (more info ...)trojan-activity  2013-2471      URL
27704EXPLOIT-KIT Gong Da exploit kit Java exploit requested (more info ...)trojan-activity  2013-1493      
27705EXPLOIT-KIT Gong Da exploit kit Java exploit requested (more info ...)trojan-activity  2013-1493      
27716BROWSER-IE Microsoft Internet Explorer 9 deleted object access memory corruption attempt (more info ...)attempted-user  2013-0026  57832    URL
27717BROWSER-IE Microsoft Internet Explorer 9 deleted object access memory corruption attempt (more info ...)attempted-user  2013-0026  57832    URL
27733EXPLOIT-KIT IFRAMEr Tool embedded javascript attack method - generic structure (more info ...)misc-activity        URL
27734EXPLOIT-KIT IFRAMEr Tool embedded javascript attack method - specific structure (more info ...)misc-activity        URL
27735INDICATOR-OBFUSCATION Javascript obfuscation - document - seen in IFRAMEr Tool usage (more info ...)misc-activity        URL
27736INDICATOR-OBFUSCATION Javascript obfuscation - split - seen in IFRAMEr Tool attack (more info ...)misc-activity        URL
27741EXPLOIT-KIT Zip file downloaded by Java (more info ...)misc-activity        
27750FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2013-2473  60659    URL
27751FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2013-2471  60659    URL
27764FILE-JAVA Oracle Java ImagingLib buffer overflow attempt (more info ...)attempted-user  2013-2463      
27765FILE-JAVA Oracle Java ImagingLib buffer overflow attempt (more info ...)attempted-user  2013-2463      
27766BROWSER-PLUGINS Oracle Java Security Slider feature bypass attempt (more info ...)attempted-user  2013-1489      URL
27786FILE-JAVA Oracle Java ImagingLib buffer overflow attempt (more info ...)attempted-user  2013-2463      
27787FILE-JAVA Oracle Java ImagingLib buffer overflow attempt (more info ...)attempted-user  2013-2463      
27829BROWSER-IE Microsoft Internet Explorer hgroup element DOM reset use after free attempt (more info ...)attempted-user  2013-3202      URL
27830BROWSER-IE Microsoft Internet Explorer hgroup element DOM reset use after free attempt (more info ...)attempted-user  2013-3202      URL
27831BROWSER-IE Microsoft Internet Explorer javascript call method type confusion attempt (more info ...)attempted-user  2013-3203      URL
27832BROWSER-IE Microsoft Internet Explorer javascript apply method type confusion attempt (more info ...)attempted-user  2013-3203      URL
27833BROWSER-IE Microsoft Internet Explorer javascript call method type confusion attempt (more info ...)attempted-user  2013-3203      URL
27834BROWSER-IE Microsoft Internet Explorer javascript apply method type confusion attempt (more info ...)attempted-user  2013-3203      URL
27835BROWSER-IE Microsoft Internet Explorer AddOption use after free attempt (more info ...)attempted-user  2013-3204      URL
27836BROWSER-IE Microsoft Internet Explorer AddOption use after free attempt (more info ...)attempted-user  2013-3204      URL
27837BROWSER-IE Microsoft Internet Explorer CDisplayPointer use after free attempt (more info ...)attempted-user  2013-3205      URL
27838BROWSER-IE Microsoft Internet Explorer CDisplayPointer use after free attempt (more info ...)attempted-user  2013-3205      URL
27839BROWSER-IE Microsoft Internet Explorer range markup switch use after free attempt (more info ...)attempted-user  2013-3206      URL
27840BROWSER-IE Microsoft Internet Explorer range markup switch use after free attempt (more info ...)attempted-user  2013-3206      URL
27841BROWSER-IE Microsoft Internet Explorer 9 MutationEvent use after free attempt (more info ...)attempted-admin  2013-3207      URL
27842BROWSER-IE Microsoft Internet Explorer CSegment object use after free attempt (more info ...)attempted-user  2013-3209      URL
27843BROWSER-IE Microsoft Internet Explorer CTreePos object use-after-free attempt (more info ...)attempted-user  2013-3845      URL
27844BROWSER-IE Microsoft Internet Explorer CTreePos object use-after-free attempt (more info ...)attempted-user  2013-3845      URL
27845BROWSER-IE Microsoft Internet Explorer iframe execCommand use after free attempt (more info ...)attempted-user  2013-3208      URL
27846BROWSER-IE Microsoft Internet Explorer iframe execCommand use after free attempt (more info ...)attempted-user  2013-3208      URL
27883EXPLOIT-KIT Teletubbies exploit kit exploit attempt for Oracle Java (more info ...)trojan-activity  2013-2465      URL
27908BROWSER-IE Microsoft Internet Explorer CPhraseElement use after free attempt (more info ...)attempted-user  2013-3163  60975    URL
27909BROWSER-IE Microsoft Internet Explorer CPhraseElement use after free attempt (more info ...)attempted-user  2013-3163  60975    URL
27920INDICATOR-OBFUSCATION Javascript obfuscation - split - seen in IFRAMEr Tool attack (more info ...)misc-activity        URL
28023INDICATOR-OBFUSCATION Javascript obfuscation - document - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28024INDICATOR-OBFUSCATION Javascript obfuscation - seen in IFRAMEr Tool attack (more info ...)misc-activity        URL
28025INDICATOR-OBFUSCATION Javascript obfuscation - split - seen in IFRAMEr Tool attack (more info ...)misc-activity        URL
28109EXPLOIT-KIT Nuclear/Magnitude exploit kit Oracle Java exploit download attempt (more info ...)trojan-activity  2013-0431      
28111EXPLOIT-KIT Nuclear/Magnitude exploit kit post Java compromise download attempt (more info ...)trojan-activity  2013-0431      
28151BROWSER-IE Microsoft Internet Explorer STextBlockPosition use after free attempt (more info ...)attempted-user  2013-3885      URL
28158BROWSER-IE Microsoft Internet Explorer CLayoutBlock use after free attempt (more info ...)attempted-user  2013-3875      URL
28159BROWSER-IE Microsoft Internet Explorer CLayoutBlock use after free attempt (more info ...)attempted-user  2013-3875      URL
28160BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2013-3874      URL
28195EXPLOIT-KIT X2O exploit kit post java exploit download attempt (more info ...)trojan-activity        
28204BROWSER-IE Microsoft Internet Explorer deleted object memory corruption attempt (more info ...)attempted-user  2013-3886      URL
28231BROWSER-IE Microsoft Internet Explorer javascript call method type confusion attempt (more info ...)attempted-user  2013-3203      URL
28232BROWSER-IE Microsoft Internet Explorer javascript call method type confusion attempt (more info ...)attempted-user  2013-3203      URL
28264EXPLOIT-KIT Sweet Orange exploit kit java compromise successful (more info ...)trojan-activity        
28276FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
28277FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp storeImageArray memory corruption attempt (more info ...)attempted-user  2013-2465  60657    URL
28309EXPLOIT-KIT Himan exploit kit payload - Oracle Java compromise (more info ...)trojan-activity  2013-2465      URL
28310EXPLOIT-KIT Himan exploit kit payload - Oracle Java compromise (more info ...)trojan-activity  2011-3544      URL
28345INDICATOR-OBFUSCATION Javascript obfuscation - split - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28346INDICATOR-OBFUSCATION Javascript obfuscation - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28354BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
28355BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
28356BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
28357BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
28358BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
28359BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
28360BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
28363BROWSER-IE Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt (more info ...)attempted-user  2012-0170  52904    URL
28364BROWSER-IE Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt (more info ...)attempted-user  2012-0170  52904    URL
28414EXPLOIT-KIT Nuclear/Magnitude exploit kit Oracle Java exploit download attempt (more info ...)trojan-activity  2013-0431      
28420INDICATOR-OBFUSCATION Javascript obfuscation - createElement - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28421INDICATOR-OBFUSCATION Javascript obfuscation - fromCharCode - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28422INDICATOR-OBFUSCATION Javascript obfuscation - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28424EXPLOIT-KIT Nuclear exploit kit Microsoft Internet Explorer vulnerability request (more info ...)trojan-activity  2013-2551      
28476EXPLOIT-KIT Neutrino exploit kit outbound request by Java - generic detection (more info ...)trojan-activity  2013-2465      
28489BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user  2013-3871      URL
28490BROWSER-IE Microsoft Internet Explorer deleted object memory corruption attempt (more info ...)attempted-user  2013-3917      URL
28491BROWSER-IE Microsoft Internet Explorer CEditAdorner use after free attempt (more info ...)attempted-user  2013-3911      URL
28492BROWSER-IE Microsoft Internet Explorer freed CTreePos object use-after-free attempt (more info ...)attempted-user  2013-3912      URL
28494BROWSER-IE Microsoft Internet Explorer execCommand CTreePos memory corruption attempt (more info ...)attempted-user  2013-3914      URL
28495BROWSER-IE Microsoft Internet Explorer execCommand CTreePos memory corruption attempt (more info ...)attempted-user  2013-3914      URL
28496BROWSER-IE Microsoft Internet Explorer createRange user after free attempt (more info ...)attempted-user  2013-3910      URL
28504BROWSER-IE Microsoft Internet Explorer undo use after free attempt (more info ...)attempted-user  2013-3915      URL
28523BROWSER-IE Microsoft Internet Explorer generic use after free attempt (more info ...)attempted-user  2013-3916      URL
28524BROWSER-IE Microsoft Internet Explorer generic use after free attempt (more info ...)attempted-recon  2013-3916      URL
28594EXPLOIT-KIT Nuclear exploit kit Microsoft Internet Explorer vulnerability request (more info ...)trojan-activity        
28595EXPLOIT-KIT Nuclear exploit kit Oracle Java jar file retrieval (more info ...)trojan-activity        
28658FILE-PDF Adobe Acrobat Reader XML Java used in app.setTimeOut (more info ...)attempted-admin  2013-0641  57931    URL
28811INDICATOR-OBFUSCATION Javascript obfuscation - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28812INDICATOR-OBFUSCATION Javascript obfuscation - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28843FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2013-3346  62149    URL
28844FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2013-3346  62149    URL
28845FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2013-3346  62149    URL
28846FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2013-3346  62149    URL
28854BROWSER-IE Microsoft Internet Explorer beforeeditfocus use after free exploit attempt (more info ...)attempted-user  2013-3147  60966    URL
28855BROWSER-IE Microsoft Internet Explorer beforeeditfocus use after free exploit attempt (more info ...)attempted-user  2013-3147  60966    URL
28862BROWSER-IE Microsoft Internet Explorer CViewportChangeInvalidation use after free attempt (more info ...)attempted-user  2013-5051      URL
28863BROWSER-IE Microsoft Internet Explorer CViewportChangeInvalidation use after free attempt (more info ...)attempted-user  2013-5051      URL
28865BROWSER-IE Microsoft Internet Explorer table sub structure use after free attempt (more info ...)attempted-user  2013-5048      URL
28866BROWSER-IE Microsoft Internet Explorer table sub structure use after free attempt (more info ...)attempted-user  2013-5048      URL
28873BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-5047      URL
28874BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-5047      URL
28875BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
28876BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
28877BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
28878BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
28880BROWSER-IE Microsoft Internet Explorer 8 CElement Use After Free exploit attempt (more info ...)attempted-user  2013-5052      URL
28881BROWSER-IE Microsoft Internet Explorer Dictionary Object use after free attempt (more info ...)attempted-user  2013-5056  64082    URL
28882BROWSER-IE Microsoft Internet Explorer Dictionary Object use after free attempt (more info ...)attempted-user  2013-5056  64082    URL
28915FILE-JAVA Oracle Java IntegerInterleavedRaster.verify method integer overflow attempt (more info ...)attempted-user  2013-2471  60659    URL
28916FILE-JAVA Oracle Java IntegerInterleavedRaster.verify method integer overflow attempt (more info ...)attempted-user  2013-2471  60659    URL
28926FILE-JAVA Oracle Java ImagingLib buffer overflow attempt (more info ...)attempted-user  2013-2463      
28927FILE-JAVA Oracle Java ImagingLib buffer overflow attempt (more info ...)attempted-user  2013-2463      
28941INDICATOR-OBFUSCATION Javascript obfuscation - seen in IFRAMEr Tool attack (more info ...)trojan-activity        URL
28972BROWSER-IE Microsoft Internet Explorer malformed GIF double-free remote code execution attempt (more info ...)attempted-user  2003-1048  8530    URL
28973BROWSER-IE Microsoft Internet Explorer malformed GIF double-free remote code execution attempt (more info ...)attempted-user  2003-1048  8530    URL
28974BROWSER-IE Microsoft Internet Explorer malformed GIF double-free remote code execution attempt (more info ...)attempted-user  2003-1048  8530    URL
28975BROWSER-IE Microsoft Internet Explorer malformed GIF double-free remote code execution attempt (more info ...)attempted-user  2003-1048  8530    URL
29034BROWSER-IE Microsoft Internet Explorer CDisplayPointer use after free attempt (more info ...)attempted-user  2013-3205      URL
29035BROWSER-IE Microsoft Internet Explorer CDisplayPointer use after free attempt (more info ...)attempted-user  2013-3205      URL
29036BROWSER-IE Microsoft Internet Explorer 8 CElement Use After Free exploit attempt (more info ...)attempted-user  2013-5052  64124    URL
29189EXPLOIT-KIT Magnitude exploit kit Microsoft Internet Explorer Payload request (more info ...)trojan-activity        
29190INDICATOR-OBFUSCATION Javascript obfuscation - seen in Nuclear exploit kit (more info ...)trojan-activity        URL
29218FILE-JAVA Oracle Java and JavaFX JPEGImageReader memory corruption attempt (more info ...)attempted-user  2013-2420      
29219FILE-JAVA Oracle Java and JavaFX JPEGImageReader memory corruption attempt (more info ...)attempted-user  2013-2420      
29265BROWSER-IE Microsoft Internet Explorer invalid object property use after free memory corruption attempt (more info ...)attempted-dos  2012-4787      URL
29268FILE-JAVA Oracle Java sun.awt.image.ImageRepresentation.setPixels integer overflow attempt (more info ...)attempted-user  2013-2420      
29269FILE-JAVA Oracle Java sun.awt.image.ImageRepresentation.setPixels integer overflow attempt (more info ...)attempted-user  2013-2420      
29270FILE-JAVA Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt (more info ...)attempted-user  2013-2470  60651    URL
29271FILE-JAVA Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt (more info ...)attempted-user  2013-2470  60651    URL
29272FILE-JAVA Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt (more info ...)attempted-user  2013-2470  60651    URL
29273FILE-JAVA Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt (more info ...)attempted-user  2013-2470  60651    URL
29409FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2016-1079  64804    URL
29410FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2016-1079  64804    URL
29412EXPLOIT-KIT Angler exploit kit Java download attempt (more info ...)trojan-activity        
29490FILE-JAVA Oracle Java ShortComponentRaster integer overflow attempt (more info ...)attempted-user  2013-2472  60656    URL
29491FILE-JAVA Oracle Java ShortComponentRaster integer overflow attempt (more info ...)attempted-user  2013-2472  60656    URL
29503BROWSER-FIREFOX Mozilla Products SVG text content element getCharNumAtPosition use after free attempt (more info ...)attempted-user  2011-0084  49213    
29535FILE-JAVA Oracle Java Rhino script engine remote code execution attempt (more info ...)attempted-user  2011-3544      
29579BROWSER-FIREFOX Mozilla Firefox browser engine memory corruption attempt (more info ...)attempted-user  2009-3382  36866    
29580BROWSER-FIREFOX Mozilla Firefox SVG data processing obfuscated memory corruption attempt (more info ...)attempted-user  2009-0771  33990    URL
29602BROWSER-IE Microsoft Internet Explorer VML array with negative length memory corruption attempt (more info ...)attempted-user  2013-2551  58570    URL
29605FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp integer overflow attempt (more info ...)attempted-user  2013-0809  58296    
29606FILE-JAVA Oracle Java 2D ImagingLib AffineTransformOp integer overflow attempt (more info ...)attempted-user  2013-0809  58296    
29617BROWSER-FIREFOX Mozilla Firefox nsTreeRange Use After Free attempt (more info ...)attempted-user  2011-0073      URL
29623BROWSER-WEBKIT Apple Safari Webkit attribute child removal code execution attempt (more info ...)attempted-user  2010-1119  40642    
29624BROWSER-FIREFOX Mozilla Array.reduceRight integer overflow attempt (more info ...)attempted-user  2011-2371  48372    
29625BROWSER-FIREFOX Mozilla Array.reduceRight integer overflow attempt (more info ...)attempted-user  2011-2371  48372    
29640MALWARE-OTHER Java FileDialog heap buffer overflow attempt (more info ...)attempted-user  2011-0802  48129    
29641MALWARE-OTHER Java FileDialog heap buffer overflow attempt (more info ...)attempted-user  2011-0802  48129    
29642MALWARE-OTHER Java FileDialog heap buffer overflow attempt (more info ...)attempted-user  2011-0802  48129    
29643MALWARE-OTHER Java FileDialog heap buffer overflow attempt (more info ...)attempted-user  2011-0802  48129    
29655BROWSER-IE Microsoft Internet Explorer 8 use after free attempt (more info ...)attempted-user  2014-0272      URL
29667BROWSER-IE Microsoft Internet Explorer CTreePos deleted object access attempt (more info ...)attempted-user  2014-0277      URL
29668BROWSER-IE Microsoft Internet Explorer CTreePos deleted object access attempt (more info ...)attempted-user  2014-0277      URL
29671BROWSER-IE Microsoft Internet Explorer SVG handling use after free attempt (more info ...)attempted-user  2014-0283  65382    URL
29672BROWSER-IE Microsoft Internet Explorer SVG handling use after free attempt (more info ...)attempted-user  2014-0283  65382    URL
29673BROWSER-IE Microsoft Internet Explorer SVG handling use after free attempt (more info ...)attempted-user  2014-0283  65382    URL
29674BROWSER-IE Microsoft Internet Explorer SVG handling use after free attempt (more info ...)attempted-user  2014-0283  65382    URL
29676BROWSER-IE Microsoft Internet Explorer CRootElement Object use after free attempt (more info ...)attempted-user  2014-0273      URL
29677BROWSER-IE Microsoft Internet Explorer CRootElement Object use after free attempt (more info ...)attempted-user  2014-0273      URL
29678BROWSER-IE Microsoft Internet Explorer swap node user after free (more info ...)attempted-user  2014-0290      URL
29679BROWSER-IE Microsoft Internet Explorer swap node user after free (more info ...)attempted-user  2014-0290      URL
29706BROWSER-IE Microsoft Internet Explorer deleted object access attempt detected (more info ...)attempted-user  2014-0285      URL
29707BROWSER-IE Microsoft Internet Explorer deleted object access attempt detected (more info ...)attempted-user  2014-0285      URL
29708BROWSER-IE Microsoft Internet Explorer CSS uninitialized object access attempt detected (more info ...)attempted-user  2014-0278      URL
29709BROWSER-IE Microsoft Internet Explorer fontFamily attribute deleted object access memory corruption attempt (more info ...)attempted-user  2014-0284      URL
29710BROWSER-IE Microsoft Internet Explorer fontFamily attribute deleted object access memory corruption attempt (more info ...)attempted-user  2014-0284      URL
29711BROWSER-IE Microsoft Internet Explorer CTree Node use after free attempt (more info ...)attempted-user  2014-0281      URL
29712BROWSER-IE Microsoft Internet Explorer CTree Node use after free attempt (more info ...)attempted-user  2014-0281      URL
29716BROWSER-IE Microsoft Internet Explorer deleted object memory corruption attempt (more info ...)attempted-user  2014-0267      URL
29717BROWSER-IE Microsoft Internet Explorer text node use after free attempt (more info ...)attempted-user  2014-0298      URL
29718BROWSER-IE Microsoft Internet Explorer text node use after free attempt (more info ...)attempted-user  2014-0298      URL
29721BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-0279      URL
29722BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-0279      URL
29727BROWSER-IE Microsoft Internet Explorer CElement event handler use after free attempt (more info ...)attempted-user  2014-0275      URL
29728BROWSER-IE Microsoft Internet Explorer CElement event handler use after free attempt (more info ...)attempted-user  2014-0275      URL
29729BROWSER-IE Microsoft Internet Explorer CElement event handler use after free attempt (more info ...)attempted-user  2014-0275      URL
29730BROWSER-IE Microsoft Internet Explorer CElement event handler use after free attempt (more info ...)attempted-user  2014-0275      URL
29731BROWSER-IE Microsoft Internet Explorer list element use after free attempt (more info ...)attempted-user  2014-0270      URL
29732BROWSER-IE Microsoft Internet Explorer list element use after free attempt (more info ...)attempted-user  2014-0270      URL
29733BROWSER-IE Microsoft Internet Explorer overlapping object boundaries memory corruption attempt (more info ...)attempted-user  2014-0274      URL
29734BROWSER-IE Microsoft Internet Explorer overlapping object boundaries memory corruption attempt (more info ...)attempted-user  2014-0274      URL
29735BROWSER-IE Microsoft Internet Explorer selectall use after free attempt (more info ...)attempted-user  2014-0287      URL
29736BROWSER-IE Microsoft Internet Explorer selectall use after free attempt (more info ...)attempted-user  2014-0287      URL
29737BROWSER-IE Microsoft Internet Explorer cmarkup methods use after free attempt (more info ...)attempted-user  2014-0269      URL
29738BROWSER-IE Microsoft Internet Explorer cmarkup methods use after free attempt (more info ...)attempted-user  2014-0269      URL
29741BROWSER-IE Microsoft Internet Explorer deleted object access memory corruption attempt (more info ...)attempted-user  2014-0288      URL
29742BROWSER-IE Microsoft Internet Explorer deleted object access memory corruption attempt (more info ...)attempted-user  2014-0288      URL
29743BROWSER-IE Microsoft Internet Explorer CInput element user after free attempt (more info ...)attempted-user  2014-0286      URL
29744BROWSER-IE Microsoft Internet Explorer CInput element user after free attempt (more info ...)attempted-user  2014-0286      URL
29796BROWSER-IE Microsoft Internet Explorer SelectAll dangling pointer use after free attempt (more info ...)attempted-user  2012-0171      URL
29797BROWSER-IE Microsoft Internet Explorer SelectAll dangling pointer use after free attempt (more info ...)attempted-user  2012-0171      URL
29819BROWSER-IE Microsoft Internet Explorer 10 use after free attempt (more info ...)attempted-user  2014-0322      URL
29820BROWSER-IE Microsoft Internet Explorer 10 use after free attempt (more info ...)attempted-user  2014-0322      URL
29821INDICATOR-COMPROMISE Windows Internet Explorer EMET check and garbage collection (more info ...)misc-attack  2013-7331      URL
29822INDICATOR-COMPROMISE Windows Internet Explorer EMET check and garbage collection (more info ...)misc-attack  2013-7331      URL
29988BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
29989BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
30002EXPLOIT-KIT Hello/LightsOut exploit kit Java download attempt (more info ...)trojan-activity  2013-1489      URL
30004EXPLOIT-KIT Hello/LightsOut exploit kit - exploit targeting Java before v1.7.17 (more info ...)trojan-activity  2013-1489      URL
30005EXPLOIT-KIT Hello/LightsOut exploit kit - exploit targeting Google Chrome with Java before v1.7.17 (more info ...)trojan-activity  2013-1489      URL
30006EXPLOIT-KIT Hello/LightsOut exploit kit - exploit targeting Microsoft Internet Explorer 6 on Windows XP (more info ...)trojan-activity  2013-1489      URL
30007EXPLOIT-KIT Hello/LightsOut exploit kit - exploit targeting Microsoft Internet Explorer 7 on Windows XP with Java before v1.7.17 (more info ...)trojan-activity  2013-1489      URL
30008EXPLOIT-KIT Hello/LightsOut exploit kit - exploit targeting Microsoft Internet Explorer 8 on Windows XP (more info ...)trojan-activity  2013-1489      URL
30009EXPLOIT-KIT Hello/LightsOut exploit kit - exploit targeting Java v1.6.32 and older (more info ...)trojan-activity  2013-1489      URL
30079BROWSER-IE Microsoft Internet Explorer SVG handling use after free attempt (more info ...)attempted-user  2014-0283  65382    URL
30080BROWSER-IE Microsoft Internet Explorer SVG handling use after free attempt (more info ...)attempted-user  2014-0283  65382    URL
30081BROWSER-IE Microsoft Internet Explorer SVG handling use after free attempt (more info ...)attempted-user  2014-0283  65382    URL
30082BROWSER-IE Microsoft Internet Explorer SVG handling use after free attempt (more info ...)attempted-user  2014-0283  65382    URL
30106BROWSER-IE Microsoft Internet Explorer 10 use after free attempt (more info ...)attempted-user  2014-0322      URL
30107BROWSER-IE Microsoft Internet Explorer 10 use after free attempt (more info ...)attempted-user  2014-0322      URL
30108BROWSER-IE Microsoft Internet Explorer Remove Format use after free attempt (more info ...)attempted-user  2014-0306      URL
30109BROWSER-IE Microsoft Internet Explorer Remove Format use after free attempt (more info ...)attempted-user  2014-0306      URL
30110BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2014-2799  66028    URL
30111BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2014-2799  66028    URL
30112BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2014-2799  66028    URL
30113BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2014-2799  66028    URL
30116BROWSER-IE Microsoft Internet Explorer button element onreadystatechange use after free attempt (more info ...)attempted-user  2014-0302      URL
30117BROWSER-IE Microsoft Internet Explorer button element onreadystatechange use after free attempt (more info ...)attempted-user  2014-0302      URL
30118BROWSER-IE Microsoft Internet Explorer setEndPoint use after free attempt (more info ...)attempted-user  2014-0314      URL
30119BROWSER-IE Microsoft Internet Explorer setEndPoint use after free attempt (more info ...)attempted-user  2014-0314      URL
30120BROWSER-IE Microsoft Internet Explorer pastHTML use after free (more info ...)attempted-user  2014-0305      URL
30121BROWSER-IE Microsoft Internet Explorer pastHTML use after free (more info ...)attempted-user  2014-0305      URL
30122BROWSER-IE Microsoft Internet Explorer CSelectElement SetCurSel remote code execution attempt (more info ...)attempted-user  2014-0312      URL
30123BROWSER-IE Microsoft Internet Explorer CTreePos use after free attempt (more info ...)attempted-user  2014-0297      URL
30124BROWSER-IE Microsoft Internet Explorer CTreePos use after free attempt (more info ...)attempted-user  2014-0297      URL
30125BROWSER-IE Microsoft Internet Explorer CTreeDataPos object use after free attempt (more info ...)attempted-user  2014-0311      URL
30126BROWSER-IE Microsoft Internet Explorer CTreeDataPos object use after free attempt (more info ...)attempted-user  2014-0311      URL
30127BROWSER-IE Microsoft Internet Explorer use after free memory corruption attempt (more info ...)attempted-user  2014-0304      URL
30128BROWSER-IE Microsoft Internet Explorer use after free memory corruption attempt (more info ...)attempted-user  2014-0304      URL
30129BROWSER-IE Microsoft Internet Explorer Nested Tables use after free attempt (more info ...)attempted-user  2014-0299      URL
30130BROWSER-IE Microsoft Internet Explorer Nested Tables use after free attempt (more info ...)attempted-user  2014-0299      URL
30131BROWSER-IE Microsoft Internet Explorer ruby element in media element use after free attempt (more info ...)attempted-user  2014-0309      URL
30132BROWSER-IE Microsoft Internet Explorer ruby element in media element use after free attempt (more info ...)attempted-user  2014-0309      URL
30140BROWSER-IE Microsoft Internet Explorer OnMove use after free attempt (more info ...)attempted-user  2014-0324      URL
30141BROWSER-IE Microsoft Internet Explorer OnMove use after free attempt (more info ...)attempted-user  2014-0324      URL
30142BROWSER-IE Microsoft Internet Explorer OnMove use after free attempt (more info ...)attempted-user  2014-0324      URL
30143BROWSER-IE Microsoft Internet Explorer OnMove use after free attempt (more info ...)attempted-user  2014-0324      URL
30144BROWSER-IE Microsoft Internet Explorer ruby text tag heap-based buffer overflow attempt (more info ...)attempted-dos  2014-0313      URL
30145BROWSER-IE Microsoft Internet Explorer ruby text tag heap-based buffer overflow attempt (more info ...)attempted-dos  2014-0313      URL
30169BROWSER-IE Microsoft Internet Explorer CSS uninitialized object access attempt detected (more info ...)attempted-user  2014-0278      URL
30201BROWSER-IE Microsoft Internet Explorer merged stylesheet array use after free attempt (more info ...)attempted-user  2013-3191      URL
30217FILE-JAVA Oracle Java font rendering remote code execution attempt (more info ...)attempted-user  2013-1491      URL
30345BROWSER-IE Microsoft Internet Explorer onbeforeeditfocus element attribute use after free attempt (more info ...)attempted-user  2013-0029      URL
30497BROWSER-IE Microsoft Internet Explorer failed large copy clonenode attempt (more info ...)attempted-user  2014-1753      URL
30498BROWSER-IE Microsoft Internet Explorer failed large copy clonenode attempt (more info ...)attempted-user  2014-1753      URL
30499BROWSER-IE Microsoft Internet Explorer remote code execution attempt (more info ...)attempted-user  2014-1751      URL
30500BROWSER-IE Microsoft Internet Explorer remote code execution attempt (more info ...)attempted-user  2014-1751      URL
30501BROWSER-IE Microsoft Internet Explorer nth-child use after free attempt (more info ...)attempted-user  2014-1755      URL
30502BROWSER-IE Microsoft Internet Explorer nth-child use after free attempt (more info ...)attempted-user  2014-1755      URL
30503BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
30504BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
30505BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
30506BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
30528FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2013-3346  62149    URL
30529FILE-PDF Adobe Acrobat Reader javascript toolbar button use after free attempt (more info ...)attempted-user  2013-3346  62149    URL
30767EXPLOIT-KIT Magnitude exploit kit Oracle Java payload request (more info ...)trojan-activity        
30768EXPLOIT-KIT Magnitude exploit kit Oracle Java payload request (more info ...)trojan-activity        
30790SERVER-WEBAPP Java ClassLoader access attempt (more info ...)attempted-admin  2022-22965  65999    URL
30791SERVER-WEBAPP Java ClassLoader access attempt (more info ...)attempted-admin  2022-22965      URL
30792SERVER-WEBAPP Java ClassLoader access attempt (more info ...)attempted-admin  2022-22965  65999    URL
30793SERVER-WEBAPP Java ClassLoader access attempt (more info ...)attempted-admin  2022-22965      URL
30794BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user  2014-1776  67075    URL
30803BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user  2014-1776  67075    URL
30847BROWSER-IE Microsoft Internet Explorer CElement event handler use after free attempt (more info ...)attempted-user  2014-0275      URL
30848BROWSER-IE Microsoft Internet Explorer CElement event handler use after free attempt (more info ...)attempted-user  2014-0275      URL
30892BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user  2014-1776      URL
30893BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user  2014-1776      URL
30894BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user  2014-1776      URL
30895BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user  2014-1776      URL
30956BROWSER-IE Microsoft Internet Explorer deleted object memory corruption attempt (more info ...)attempted-user  2014-0310      URL
30957BROWSER-IE Microsoft Internet Explorer deleted object memory corruption attempt (more info ...)attempted-user  2014-0310      URL
30961BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2014-1815      URL
30962BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2014-1815      URL
30963BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2014-1815      URL
30964BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2014-1815      URL
30965EXPLOIT-KIT CritX exploit kit landing page - redirection to Oracle Java exploit (more info ...)trojan-activity        
30966EXPLOIT-KIT CritX exploit kit landing page - redirection to Microsoft Internet Explorer exploit (more info ...)trojan-activity        
30969EXPLOIT-KIT CritX exploit kit outbound request for Microsoft Internet Explorer landing page (more info ...)trojan-activity        
30971EXPLOIT-KIT CritX exploit kit outbound request for Oracle Java landing page (more info ...)trojan-activity        
30975EXPLOIT-KIT CritX exploit kit landing page - redirection to Oracle Java exploit (more info ...)trojan-activity        
31017BROWSER-PLUGINS Microsoft Internet Explorer Adobe Reader Extension race condition attempt (more info ...)attempted-user  2014-0527      URL
31018BROWSER-PLUGINS Microsoft Internet Explorer Adobe Reader Extension race condition attempt (more info ...)attempted-user  2014-0527      URL
31188BROWSER-IE Microsoft Internet Explorer isIndex attribute overflow attempt (more info ...)attempted-user  2014-1797      URL
31189BROWSER-IE Microsoft Internet Explorer isIndex attribute overflow attempt (more info ...)attempted-user  2014-1797      URL
31190BROWSER-IE Microsoft Internet Explorer RemoveSplice use-after-free attempt (more info ...)attempted-user  2014-1785      URL
31191BROWSER-IE Microsoft Internet Explorer RemoveSplice use-after-free attempt (more info ...)attempted-user  2014-1785      URL
31196BROWSER-IE Microsoft Internet Explorer CTreeNode onmousemove use-after-free attempt (more info ...)attempted-user  2014-1791      URL
31197BROWSER-IE Microsoft Internet Explorer CTreeNode onmousemove use-after-free attempt (more info ...)attempted-user  2014-1791      URL
31198BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-1804      URL
31199BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-1804      URL
31202BROWSER-IE Microsoft Internet Explorer CRangeSaver use after free attempt (more info ...)attempted-user  2014-1772      URL
31203BROWSER-IE Microsoft Internet Explorer CRangeSaver use after free attempt (more info ...)attempted-user  2014-1772      URL
31204BROWSER-IE Microsoft Internet Explorer celement use after free attempt (more info ...)attempted-user  2014-0282      URL
31205BROWSER-IE Microsoft Internet Explorer celement use after free attempt (more info ...)attempted-user  2014-0282      URL
31206BROWSER-IE Microsoft Internet Explorer 11 CTreePos child element use-after-free attempt (more info ...)attempted-user  2014-1800      URL
31207BROWSER-IE Microsoft Internet Explorer 11 CTreePos child element use-after-free attempt (more info ...)attempted-user  2014-1800      URL
31215BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-1802      URL
31216BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-1802      URL
31219BROWSER-IE Microsoft Internet Explorer WindowedMarkupContext use after free attempt (more info ...)attempted-user  2014-1805      URL
31220BROWSER-IE Microsoft Internet Explorer WindowedMarkupContext use after free attempt (more info ...)attempted-user  2014-1805      URL
31277EXPLOIT-KIT CottonCastle exploit kit Oracle Java outbound connection (more info ...)trojan-activity  2013-2465      URL
31278EXPLOIT-KIT CottonCastle exploit kit Oracle java outbound connection (more info ...)trojan-activity  2013-2465      URL
31284FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin  2015-3083      URL
31286FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin  2015-3081      URL
31296BROWSER-IE Microsoft Internet Explorer negative margin use after free attempt (more info ...)attempted-user  2012-1526  54950    URL
31302APP-DETECT Oracle Java debug wire protocol remote debugging attempt (more info ...)protocol-command-decode  2017-6639      URL
31366FILE-JAVA Oracle Java sun.tracing.ProviderSkeleton sandbox bypass attempt (more info ...)attempted-user  2013-2460  60635    URL
31367FILE-JAVA Oracle Java sun.tracing.ProviderSkeleton sandbox bypass attempt (more info ...)attempted-user  2013-2460  60635    URL
31380BROWSER-IE Microsoft Internet Explorer 11 onpropertychange remote code execution attempt (more info ...)attempted-user  2014-1765  66244    URL
31381BROWSER-IE Microsoft Internet Explorer 11 onpropertychange remote code execution attempt (more info ...)attempted-user  2014-1765  66244    URL
31382BROWSER-IE Microsoft Internet Explorer uninitialized object use after free attempt (more info ...)attempted-user  2014-2797      URL
31383BROWSER-IE Microsoft Internet Explorer uninitialized object use after free attempt (more info ...)attempted-user  2014-2797      URL
31384BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-2795      URL
31385BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-2795      URL
31388BROWSER-IE Microsoft Internet Explorer improper object cast memory corruption attempt (more info ...)attempted-user  2014-2787      URL
31389BROWSER-IE Microsoft Internet Explorer improper object cast memory corruption attempt (more info ...)attempted-user  2014-2787      URL
31403BROWSER-IE Microsoft Internet Explorer celement use after free (more info ...)attempted-user  2014-0282      URL
31404BROWSER-IE Microsoft Internet Explorer celement use after free (more info ...)attempted-user  2014-0282      URL
31470BROWSER-IE Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt (more info ...)attempted-user  2012-1880      URL
31485BROWSER-IE Microsoft Internet Explorer onbeforeeditfocus element attribute use after free attempt (more info ...)attempted-user  2013-0029      URL
31486BROWSER-IE Microsoft Internet Explorer onbeforeeditfocus element attribute use after free attempt (more info ...)attempted-user  2013-0029      URL
31511FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723  53960    URL
31512FILE-JAVA Oracle Java field bytecode verifier cache code execution attempt (more info ...)attempted-user  2012-1723  53960    URL
31540FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2013-2473  60659    URL
31541FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2013-2473  60659    URL
31580BROWSER-IE Microsoft Internet Explorer OnMove Use After Free exploit attempt (more info ...)attempted-user  2012-1529  55641    URL
31581BROWSER-IE Microsoft Internet Explorer OnMove Use After Free exploit attempt (more info ...)attempted-user  2012-1529  55641    URL
31582BROWSER-IE Microsoft Internet Explorer OnMove Use After Free exploit attempt (more info ...)attempted-user  2012-1529  55641    URL
31583BROWSER-IE Microsoft Internet Explorer OnMove Use After Free exploit attempt (more info ...)attempted-user  2012-1529  55641    URL
31584BROWSER-IE Microsoft Internet Explorer CSS .ipsum layout use-after-free attempt (more info ...)attempted-user  2013-1310  59751    URL
31585BROWSER-IE Microsoft Internet Explorer CSS .ipsum layout use-after-free attempt (more info ...)attempted-user  2013-1310  59751    URL
31608BROWSER-IE Microsoft Internet Explorer cloneNode for loop remote code execution attempt (more info ...)attempted-user  2012-2557  55647    URL
31609BROWSER-IE Microsoft Internet Explorer cloneNode for loop remote code execution attempt (more info ...)attempted-user  2012-2557  55647    URL
31610BROWSER-IE Microsoft Internet Explorer cloneNode for loop remote code execution attempt (more info ...)attempted-user  2012-2557  55647    URL
31611BROWSER-IE Microsoft Internet Explorer cloneNode for loop remote code execution attempt (more info ...)attempted-user  2012-2557  55647    URL
31619BROWSER-IE Microsoft Internet Explorer kbd element use-after-free attempt (more info ...)attempted-user  2014-4050      URL
31620BROWSER-IE Microsoft Internet Explorer kbd element use-after-free attempt (more info ...)attempted-user  2014-4050      URL
31621BROWSER-IE Microsoft Internet Explorer onreadystatechange use after free attempt (more info ...)attempted-user  2014-4063      URL
31622BROWSER-IE Microsoft Internet Explorer onreadystatechange use after free attempt (more info ...)attempted-user  2014-4063      URL
31623BROWSER-IE Microsoft Internet Explorer EventListener use after free attempt (more info ...)attempted-user  2012-2546  55645    URL
31624BROWSER-IE Microsoft Internet Explorer EventListener use after free attempt (more info ...)attempted-user  2012-2546  55645    URL
31625BROWSER-IE Microsoft Internet Explorer Use after free attempt (more info ...)attempted-user  2014-2823      URL
31626BROWSER-IE Microsoft Internet Explorer Use after free attempt (more info ...)attempted-user  2014-2823      URL
31627BROWSER-IE Microsoft Internet Explorer cdomuievent use after free attempt (more info ...)attempted-user  2014-2820  69116    URL
31628BROWSER-IE Microsoft Internet Explorer cdomuievent use after free attempt (more info ...)attempted-user  2014-2820  69116    URL
31629BROWSER-IE Microsoft Internet Explorer CMarkup insertMarquee use after free attempt (more info ...)attempted-user  2014-4057      URL
31630BROWSER-IE Microsoft Internet Explorer CMarkup insertMarquee use after free attempt (more info ...)attempted-user  2014-4057      URL
31634BROWSER-IE Microsoft Internet Explorer margin overflow use after free attempt (more info ...)attempted-user  2014-2824      URL
31635BROWSER-IE Microsoft Internet Explorer margin overflow use after free attempt (more info ...)attempted-user  2014-2824      URL
31760BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
31761BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
31762BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
31763BROWSER-IE Microsoft Internet Explorer GetClassObject use after free attempt (more info ...)attempted-user  2013-5049      URL
31782BROWSER-IE Microsoft Internet Explorer CHTMLEditor instance use after free attempt (more info ...)attempted-user  2014-4095      URL
31783BROWSER-IE Microsoft Internet Explorer CHTMLEditor instance use after free attempt (more info ...)attempted-user  2014-4095      URL
31784BROWSER-IE Microsoft Internet Explorer 11 C1DLayout ruby element use-after-free attempt (more info ...)attempted-user  2014-4094      URL
31785BROWSER-IE Microsoft Internet Explorer 11 C1DLayout ruby element use-after-free attempt (more info ...)attempted-user  2014-4094      URL
31786BROWSER-IE Microsoft Internet Explorer style-image-url use after free attempt (more info ...)attempted-user  2014-4087      URL
31787BROWSER-IE Microsoft Internet Explorer style-image-url use after free attempt (more info ...)attempted-user  2014-4087      URL
31788BROWSER-IE Microsoft Internet Explorer justifying text with an incorrect type use after free attempt (more info ...)attempted-user  2014-4080      URL
31789BROWSER-IE Microsoft Internet Explorer justifying text with an incorrect type use after free attempt (more info ...)attempted-user  2014-4080      URL
31790BROWSER-IE Microsoft Internet Explorer CAttrArray use after free attempt (more info ...)attempted-user  2014-4065      URL
31791BROWSER-IE Microsoft Internet Explorer CAttrArray use after free attempt (more info ...)attempted-user  2014-4065      URL
31792BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode use-after-free attempt (more info ...)attempted-user  2014-4084      URL
31793BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode use-after-free attempt (more info ...)attempted-user  2014-4084      URL
31794BROWSER-IE Microsoft Internet Explorer access violation attempt (more info ...)attempted-user  2014-4081      URL
31795BROWSER-IE Microsoft Internet Explorer access violation attempt (more info ...)attempted-user  2014-4081      URL
31799BROWSER-IE Microsoft Internet Explorer CTableCell Use After Free exploit attempt (more info ...)attempted-user  2014-4092      URL
31800BROWSER-IE Microsoft Internet Explorer CTableCell Use After Free exploit attempt (more info ...)attempted-user  2014-4092      URL
31801BROWSER-IE Microsoft Internet Explorer 11 InsertInputSubmit use after free attempt (more info ...)attempted-user  2014-4088      URL
31802BROWSER-IE Microsoft Internet Explorer 11 InsertInputSubmit use after free attempt (more info ...)attempted-user  2014-4088      URL
31809BROWSER-IE Microsoft Internet Explorer integer overflow exploit attempt (more info ...)attempted-user  2014-4082      URL
31810BROWSER-IE Microsoft Internet Explorer integer overflow exploit attempt (more info ...)attempted-user  2014-4082      URL
31900EXPLOIT-KIT Angler exploit kit Internet Explorer encoded shellcode detected (more info ...)trojan-activity        
31901EXPLOIT-KIT Angler exploit kit Oracle Java encoded shellcode detected (more info ...)trojan-activity        
31946FILE-JAVA Oracle Java Web Start arbitrary command execution attempt (more info ...)attempted-user  2012-0500      
32137BROWSER-IE Microsoft Internet Explorer element attribute use after free attempt (more info ...)attempted-user  2014-4134      URL
32138BROWSER-IE Microsoft Internet Explorer element attribute use after free attempt (more info ...)attempted-user  2014-4134      URL
32139BROWSER-IE Microsoft Internet Explorer DCOM sandbox escape attempt (more info ...)attempted-user  2014-4073      URL
32140BROWSER-IE Microsoft Internet Explorer DCOM sandbox escape attempt (more info ...)attempted-user  2014-4073      URL
32153BROWSER-IE Microsoft Internet Explorer innerHTML use after free attempt (more info ...)attempted-user  2014-4127      URL
32154BROWSER-IE Microsoft Internet Explorer innerHTML use after free attempt (more info ...)attempted-user  2014-4127      URL
32155BROWSER-IE Microsoft Internet Explorer FormatContext Use after free attempt (more info ...)attempted-user  2014-4129      URL
32156BROWSER-IE Microsoft Internet Explorer FormatContext Use after free attempt (more info ...)attempted-user  2014-4129      URL
32159BROWSER-IE Microsoft Internet Explorer CMarkup Object use after free attempt (more info ...)attempted-user  2014-4132      URL
32160BROWSER-IE Microsoft Internet Explorer CMarkup Object use after free attempt (more info ...)attempted-user  2014-4132      URL
32161BROWSER-IE Microsoft Internet Explorer superscript invalid parameter denial of service attempt (more info ...)attempted-dos  2014-4133      URL
32162BROWSER-IE Microsoft Internet Explorer superscript invalid parameter denial of service attempt (more info ...)attempted-dos  2014-4133      URL
32166FILE-OTHER Microsoft Internet Explorer SVG heap corruption attempt (more info ...)attempted-user  2014-4138      URL
32167FILE-OTHER Microsoft Internet Explorer SVG heap corruption attempt (more info ...)attempted-user  2014-4138      URL
32168BROWSER-IE Microsoft Internet Explorer CTransientLookaside object use after free attempt (more info ...)attempted-user  2014-4126      URL
32169BROWSER-IE Microsoft Internet Explorer CTransientLookaside object use after free attempt (more info ...)attempted-user  2014-4126      URL
32182BROWSER-IE Microsoft Internet Explorer CTableLayout AddRow out of bounds array access heap corruption attempt (more info ...)attempted-user  2014-4137      URL
32183BROWSER-IE Microsoft Internet Explorer CTableLayout AddRow out of bounds array access heap corruption attempt (more info ...)attempted-user  2014-4137      URL
32184BROWSER-IE Microsoft Internet Explorer CFunctionPointer use after free exploit attempt (more info ...)attempted-user  2014-4141      URL
32185BROWSER-IE Microsoft Internet Explorer CFunctionPointer use after free exploit attempt (more info ...)attempted-user  2014-4141      URL
32232FILE-JAVA Oracle Java ServiceLoader exception handling exploit attempt (more info ...)attempted-user  2014-0457  66866    
32233FILE-JAVA Oracle Java ServiceLoader exception handling exploit attempt (more info ...)attempted-user  2014-0457  66866    
32234FILE-JAVA Oracle Java ServiceLoader exception handling exploit attempt (more info ...)attempted-user  2014-0457  66866    
32235FILE-JAVA Oracle Java ServiceLoader exception handling exploit attempt (more info ...)attempted-user  2014-0457  66866    
32317BROWSER-IE Microsoft Internet Explorer onreadystatechange use after free attempt (more info ...)attempted-user  2014-4063      URL
32318BROWSER-IE Microsoft Internet Explorer onreadystatechange use after free attempt (more info ...)attempted-user  2014-4063      URL
32362BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user  2014-1776  67075    URL
32363BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user  2014-1776  67075    URL
32364BROWSER-IE Microsoft Internet Explorer overlapping object boundaries memory corruption attempt (more info ...)attempted-user  2014-0274      URL
32365BROWSER-IE Microsoft Internet Explorer overlapping object boundaries memory corruption attempt (more info ...)attempted-user  2014-0274      URL
32389EXPLOIT-KIT Nuclear exploit kit outbound Oracle Java request (more info ...)trojan-activity        
32399EXPLOIT-KIT Angler exploit kit outbound Oracle Java request (more info ...)trojan-activity        URL
32424BROWSER-IE Microsoft Internet Explorer object type confusion remote code execution attempt (more info ...)attempted-user  2014-6347      URL
32425BROWSER-IE Microsoft Internet Explorer object type confusion remote code execution attempt (more info ...)attempted-user  2014-6347      URL
32426BROWSER-IE Microsoft Internet Explorer contentEditable use after free attempt (more info ...)attempted-user  2014-6337      URL
32427BROWSER-IE Microsoft Internet Explorer contentEditable use after free attempt (more info ...)attempted-user  2014-6337      URL
32430BROWSER-IE Microsoft Internet Explorer CHeaderElement object use-after-free remote code execution attempt (more info ...)attempted-admin  2014-6348      URL
32431BROWSER-IE Microsoft Internet Explorer CHeaderElement object use-after-free remote code execution attempt (more info ...)attempted-admin  2014-6348      URL
32438BROWSER-IE Microsoft Internet Explorer 9 CHTMLEditorProxy use after free attempt (more info ...)attempted-user  2014-6353      URL
32439BROWSER-IE Microsoft Internet Explorer 9 CHTMLEditorProxy use after free attempt (more info ...)attempted-user  2014-6353      URL
32440BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-6344      URL
32441BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2014-6344      URL
32442BROWSER-IE Microsoft Internet Explorer CElementIDContextList use after free attempt (more info ...)attempted-user  2015-1662      URL
32443BROWSER-IE Microsoft Internet Explorer CElementIDContextList use after free attempt (more info ...)attempted-user  2015-1662      URL
32460BROWSER-IE Microsoft Internet Explorer CPtsTextParaclient out of bounds error remote code execution attempt (more info ...)attempted-admin  2014-6342      URL
32461BROWSER-IE Microsoft Internet Explorer CPtsTextParaclient out of bounds error remote code execution attempt (more info ...)attempted-admin  2014-6342      URL
32470BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
32471BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
32472BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
32473BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
32478BROWSER-IE Microsoft Internet Explorer CSecurityContext use after free attempt (more info ...)attempted-user  2014-4143      URL
32479BROWSER-IE Microsoft Internet Explorer CSecurityContext use after free attempt (more info ...)attempted-user  2014-4143      URL
32495BROWSER-IE Microsoft Internet Explorer 11 CStyleSheet object use after free attempt (more info ...)attempted-user  2014-6341      URL
32496BROWSER-IE Microsoft Internet Explorer 11 CStyleSheet object use after free attempt (more info ...)attempted-user  2014-6341      URL
32497BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user  2014-6351      URL
32498BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user  2014-6351      URL
32508FILE-OTHER Oracle Java SE GSUB FeatureCount Buffer Overflow attempt (more info ...)attempted-user        URL
32509FILE-OTHER Oracle Java SE GSUB FeatureCount Buffer Overflow attempt (more info ...)attempted-user        URL
32555EXPLOIT-KIT Hellspawn exploit kit outbound Oracle Java jar request (more info ...)trojan-activity        
32562FILE-OTHER Oracle Java awt_setPixels out-of-bounds read attempt (more info ...)attempted-user        URL
32564BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
32565BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
32629BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
32630BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
32679BROWSER-IE Microsoft Internet Explorer lineboxbuilder out of bound array access attempt (more info ...)attempted-user  2014-6376      URL
32680BROWSER-IE Microsoft Internet Explorer lineboxbuilder out of bound array access attempt (more info ...)attempted-user  2014-6376      URL
32685BROWSER-IE Microsoft Internet Explorer setTimeout use after free attempt (more info ...)attempted-user  2014-6327      URL
32686BROWSER-IE Microsoft Internet Explorer setTimeout use after free attempt (more info ...)attempted-user  2014-6327      URL
32689BROWSER-IE Microsoft Internet Explorer style object type confusion attempt (more info ...)attempted-user  2014-6373      URL
32690BROWSER-IE Microsoft Internet Explorer style object type confusion attempt (more info ...)attempted-user  2014-6373      URL
32691BROWSER-IE Microsoft Internet Explorer NodeFilter use after free attempt (more info ...)attempted-user  2014-6330      URL
32692BROWSER-IE Microsoft Internet Explorer NodeFilter use after free attempt (more info ...)attempted-user  2014-6330      URL
32703BROWSER-IE Microsoft Internet Explorer use of rtf file in clipboard attempt (more info ...)attempted-user  2014-6374      URL
32704BROWSER-IE Microsoft Internet Explorer use of rtf file in clipboard attempt (more info ...)attempted-user  2014-6374      URL
32714BROWSER-IE Microsoft Internet Explorer 10 CTableSection remote code execution attempt (more info ...)attempted-user  2014-6369      URL
32715BROWSER-IE Microsoft Internet Explorer 10 CTableSection remote code execution attempt (more info ...)attempted-user  2014-6369      URL
32716BROWSER-IE Microsoft Internet Explorer 7 CTreeNode object remote code execution attempt (more info ...)attempted-user  2014-6366      URL
32717BROWSER-IE Microsoft Internet Explorer 7 CTreeNode object remote code execution attempt (more info ...)attempted-user  2014-6366      URL
32720BROWSER-IE Microsoft Internet Explorer element type confusion use after free attempt (more info ...)attempted-user  2014-8966      URL
32721BROWSER-IE Microsoft Internet Explorer element type confusion use after free attempt (more info ...)attempted-user  2014-8966      URL
32722BROWSER-IE Microsoft Internet Explorer CButton object use after free attempt (more info ...)attempted-user  2014-6375      URL
32723BROWSER-IE Microsoft Internet Explorer CButton object use after free attempt (more info ...)attempted-user  2014-6375      URL
32724BROWSER-IE Microsoft Internet Explorer CTreePos insertAdjacentText use after free attempt (more info ...)attempted-user  2014-6329      URL
32725BROWSER-IE Microsoft Internet Explorer CTreePos insertAdjacentText use after free attempt (more info ...)attempted-user  2014-6329      URL
32804EXPLOIT-KIT known malicious javascript packer detected (more info ...)misc-activity        URL
33085BROWSER-IE Microsoft Internet Explorer 10 use after free attempt (more info ...)attempted-user  2014-0322      URL
33086BROWSER-IE Microsoft Internet Explorer 10 use after free attempt (more info ...)attempted-user  2014-0322      URL
33088BROWSER-FIREFOX Mozilla Firefox 17 onreadystatechange memory corruption attempt (more info ...)attempted-user  2013-1690      URL
33089BROWSER-FIREFOX Mozilla Firefox 17 onreadystatechange memory corruption attempt (more info ...)attempted-user  2013-1690      URL
33090BROWSER-FIREFOX Mozilla Firefox 17 onreadystatechange memory corruption attempt (more info ...)attempted-user  2013-1690      URL
33093BROWSER-IE Microsoft Internet Explorer CInput element user after free attempt (more info ...)attempted-user  2014-0286      URL
33094BROWSER-IE Microsoft Internet Explorer CInput element user after free attempt (more info ...)attempted-user  2014-0286      URL
33095BROWSER-IE Microsoft Internet Explorer CTreePos Use After Free attempt (more info ...)attempted-user  2013-3845      
33096BROWSER-IE Microsoft Internet Explorer CTreePos Use After Free attempt (more info ...)attempted-user  2013-3845      
33097BROWSER-IE Microsoft Internet Explorer CTreePos Use After Free attempt (more info ...)attempted-user  2013-3845      
33098BROWSER-IE Microsoft Internet Explorer CTreePos Use After Free attempt (more info ...)attempted-user  2013-3845      
33115BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
33116BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
33157BROWSER-IE Microsoft Internet Explorer CClipStack array index exploitation attempt (more info ...)attempted-user  2014-1773      URL
33158BROWSER-IE Microsoft Internet Explorer CClipStack array index exploitation attempt (more info ...)attempted-user  2014-1773      URL
33191BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user  2014-6351      URL
33192BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user  2014-6351      URL
33193BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user  2014-6351      URL
33194BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user  2014-6351      URL
33195BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user  2014-6351      URL
33196BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user  2014-6351      URL
33312BROWSER-IE Microsoft Internet Explorer InsertElementInternal out of bounds indexed array remote code execution attempt (more info ...)attempted-user  2015-0044      URL
33313BROWSER-IE Microsoft Internet Explorer InsertElementInternal out of bounds indexed array remote code execution attempt (more info ...)attempted-user  2015-0044      URL
33314BROWSER-IE Microsoft Internet Explorer CGeneratedSvgTreeNode use-after-free attempt (more info ...)attempted-user  2015-0043      URL
33315BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2015-0035      URL
33316BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2015-0035      URL
33317BROWSER-IE Microsoft Internet Explorer CTreeNode use after free attempt (more info ...)attempted-user  2015-0020      URL
33318BROWSER-IE Microsoft Internet Explorer CTreeNode use after free attempt (more info ...)attempted-user  2015-0020      URL
33323BROWSER-IE Microsoft Internet Explorer uninitialized pointer use exploit attempt (more info ...)attempted-admin  2015-0067      URL
33324BROWSER-IE Microsoft Internet Explorer CFormElement use after free attempt (more info ...)attempted-user  2015-0026      URL
33325BROWSER-IE Microsoft Internet Explorer CFormElement use after free attempt (more info ...)attempted-user  2015-0026      URL
33331BROWSER-IE Microsoft Internet Explorer CHTMLEditorProxy use after free attempt (more info ...)attempted-user  2015-0049      URL
33332BROWSER-IE Microsoft Internet Explorer CHTMLEditorProxy use after free attempt (more info ...)attempted-user  2015-0049      URL
33333BROWSER-IE Microsoft Internet Explorer Hyphenator object use after free attempt (more info ...)attempted-user  2015-0039      URL
33334BROWSER-IE Microsoft Internet Explorer Hyphenator object use after free attempt (more info ...)attempted-user  2015-0039      URL
33335BROWSER-IE Microsoft Internet Explorer ActiveX type confusion attempt (more info ...)attempted-user  2015-0046      URL
33336BROWSER-IE Microsoft Internet Explorer ActiveX type confusion attempt (more info ...)attempted-user  2015-0046      URL
33340BROWSER-IE Microsoft Internet Explorer CParaElement use after free attempt (more info ...)attempted-user  2015-0019      URL
33341BROWSER-IE Microsoft Internet Explorer CParaElement use after free attempt (more info ...)attempted-user  2015-0019      URL
33345BROWSER-IE Microsoft Internet Explorer CBatchParentUndoUnit object use after free attempt (more info ...)attempted-user  2015-0030      URL
33346BROWSER-IE Microsoft Internet Explorer CBatchParentUndoUnit object use after free attempt (more info ...)attempted-user  2015-0030      URL
33347BROWSER-IE Microsoft Internet Explorer CTreePos use-after-free attempt (more info ...)attempted-user  2015-0021      URL
33348BROWSER-IE Microsoft Internet Explorer dximagetransform.microsoft.shadow out of bounds array access attempt (more info ...)attempted-user  2015-0036      URL
33349BROWSER-IE Microsoft Internet Explorer dximagetransform.microsoft.shadow out of bounds array access attempt (more info ...)attempted-user  2015-0036      URL
33353BROWSER-IE Microsoft Internet Explorer CAttrArray object used after free attempt (more info ...)attempted-user  2015-0038      URL
33354BROWSER-IE Microsoft Internet Explorer CAttrArray object used after free attempt (more info ...)attempted-user  2015-0038      URL
33356BROWSER-IE Microsoft Internet Explorer CTreeNode object used after free attempt (more info ...)attempted-user  2015-0023      URL
33357BROWSER-IE Microsoft Internet Explorer CTreeNode object used after free attempt (more info ...)attempted-user  2015-0023      URL
33358BROWSER-IE Microsoft Internet Explorer SLayoutRun use-after-free attempt (more info ...)attempted-user  2015-0050      URL
33359BROWSER-IE Microsoft Internet Explorer svg use after free attempt (more info ...)attempted-user  2015-0042      URL
33360BROWSER-IE Microsoft Internet Explorer svg use after free attempt (more info ...)attempted-user  2015-0042      URL
33361BROWSER-IE Microsoft Internet Explorer CCharFormat use-after-free attempt (more info ...)attempted-admin  2015-0029      URL
33365BROWSER-IE Microsoft Internet Explorer CMapElement use-after-free attempt (more info ...)attempted-user  2015-0040      URL
33366BROWSER-IE Microsoft Internet Explorer CMapElement use-after-free attempt (more info ...)attempted-user  2015-0040      URL
33412BROWSER-IE Microsoft Internet Explorer style type confusion remote code execution attempt (more info ...)attempted-user  2015-0052      URL
33415BROWSER-IE Microsoft Internet Explorer CLineCore use after free attempt (more info ...)attempted-user  2015-0045      URL
33416BROWSER-IE Microsoft Internet Explorer CLineCore use after free attempt (more info ...)attempted-user  2015-0045      URL
33417BROWSER-IE Microsoft Internet Explorer CGenericElement use after free attempt (more info ...)attempted-user  2015-0017      URL
33418BROWSER-IE Microsoft Internet Explorer CGenericElement use after free attempt (more info ...)attempted-user  2015-0017      URL
33419BROWSER-IE Microsoft Internet Explorer CTreePos use after free attempt (more info ...)attempted-user  2015-0068      URL
33420BROWSER-IE Microsoft Internet Explorer CTreePos use after free attempt (more info ...)attempted-user  2015-0068      URL
33421BROWSER-IE Microsoft Internet Explorer CTreeDataPos use-after-free remote code execution attempt (more info ...)attempted-user  2015-0041      URL
33422BROWSER-IE Microsoft Internet Explorer memory leak exploit attempt (more info ...)attempted-user  2015-0037      URL
33425BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2015-0018      URL
33426BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2015-0018      URL
33427BROWSER-IE Microsoft Internet Explorer CMarkupTransNavContext object use after free attempt (more info ...)attempted-user  2015-0031      URL
33428BROWSER-IE Microsoft Internet Explorer CMarkupTransNavContext object use after free attempt (more info ...)attempted-user  2015-0031      URL
33707BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2015-0056      URL
33708BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2015-0056      URL
33709BROWSER-IE Microsoft Internet Explorer 11 VBScript array element use after free attempt (more info ...)attempted-user  2015-0032      URL
33710BROWSER-IE Microsoft Internet Explorer 11 VBScript array element use after free attempt (more info ...)attempted-user  2015-0032      URL
33718BROWSER-IE Microsoft Internet Explorer CTreeNode interpreted as CGeneratedTreeNode remote code execution attempt (more info ...)attempted-user  2015-1622      URL
33719BROWSER-IE Microsoft Internet Explorer CTreeNode interpreted as CGeneratedTreeNode remote code execution attempt (more info ...)attempted-user  2015-1622      URL
33724FILE-OTHER Microsoft Windows Type 1 font blend operator negative operand code execution attempt (more info ...)attempted-user  2015-0093      URL
33725FILE-OTHER Microsoft Windows Type 1 font blend operator negative operand code execution attempt (more info ...)attempted-user  2015-0093      URL
33726BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2015-1623      URL
33727BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2015-1623      URL
33730BROWSER-IE Microsoft Internet Explorer out of bounds array access attempt (more info ...)attempted-user  2015-0099      URL
33731BROWSER-IE Microsoft Internet Explorer out of bounds array access attempt (more info ...)attempted-user  2015-0099      URL
33736BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode use after free attempt (more info ...)attempted-user  2015-1624      URL
33737BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode use after free attempt (more info ...)attempted-user  2015-1624      URL
33738BROWSER-IE Microsoft Internet Explorer 11 CInputContext object use after free attempt (more info ...)attempted-user  2015-1626      URL
33739BROWSER-IE Microsoft Internet Explorer 11 CInputContext object use after free attempt (more info ...)attempted-user  2015-1626      URL
33741BROWSER-IE Microsoft Internet Explorer CTreeNode use-after-free attempt (more info ...)attempted-user  2015-0100      URL
33742BROWSER-IE Microsoft Internet Explorer CTreeNode use-after-free attempt (more info ...)attempted-user  2015-0100      URL
33743BROWSER-IE Microsoft Internet Explorer table cell out-of-bounds access attempt (more info ...)attempted-user  2015-1625      URL
33744BROWSER-IE Microsoft Internet Explorer table cell out-of-bounds access attempt (more info ...)attempted-user  2015-1625      URL
33763BROWSER-IE Microsoft Internet Explorer 11 CInputContext object use after free attempt (more info ...)attempted-user  2015-1634      URL
33764BROWSER-IE Microsoft Internet Explorer 11 CInputContext object use after free attempt (more info ...)attempted-user  2015-1634      URL
33775BROWSER-IE Microsoft Internet Explorer out of bounds array access attempt (more info ...)attempted-user  2015-0081      URL
33776BROWSER-IE Microsoft Internet Explorer out of bounds array access attempt (more info ...)attempted-user  2015-0081      URL
33979BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
33980BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-dos  2014-6332      URL
34059BROWSER-IE Microsoft Internet Explorer CBodyElement use after free attempt (more info ...)attempted-user  2015-1660      URL
34060BROWSER-IE Microsoft Internet Explorer CBodyElement use after free attempt (more info ...)attempted-user  2015-1660      URL
34070BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34071BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34072BROWSER-IE Microsoft Internet Explorer CMetaElement use after free attempt (more info ...)attempted-user  2015-1666      URL
34073BROWSER-IE Microsoft Internet Explorer CMetaElement use after free attempt (more info ...)attempted-user  2015-1666      URL
34074BROWSER-IE Microsoft Internet Explorer TextData object use after free attempt (more info ...)attempted-user  2015-1665      URL
34075BROWSER-IE Microsoft Internet Explorer TextData object use after free attempt (more info ...)attempted-user  2015-1665      URL
34076BROWSER-IE Microsoft Internet Explorer append and swap use after free attempt (more info ...)attempted-user  2015-1659      URL
34077BROWSER-IE Microsoft Internet Explorer append and swap use after free attempt (more info ...)attempted-user  2015-1659      URL
34084BROWSER-IE Microsoft Internet Explorer CDocument use after free attempt (more info ...)attempted-user  2015-1652      URL
34085BROWSER-IE Microsoft Internet Explorer CDocument use after free attempt (more info ...)attempted-user  2015-1652      URL
34089BROWSER-IE Microsoft Internet Explorer incorrect array element read information disclosure attempt (more info ...)attempted-user  2015-1657      URL
34090BROWSER-IE Microsoft Internet Explorer incorrect array element read information disclosure attempt (more info ...)attempted-user  2015-1657      URL
34195BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34196BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34197BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34198BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34199BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34200BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34201BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34202BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34203BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34204BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34205BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34206BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34207BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34208BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34209BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34210BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34211BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34212BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user  2015-1668      URL
34332EXPLOIT-KIT Fiesta exploit kit Oracle Java exploit download (more info ...)trojan-activity        
34381BROWSER-IE Microsoft Internet Explorer range use after free attempt (more info ...)attempted-user  2015-1708      URL
34382BROWSER-IE Microsoft Internet Explorer range use after free attempt (more info ...)attempted-user  2015-1708      URL
34383BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2015-1712      URL
34384BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2015-1712      URL
34409BROWSER-IE Microsoft Internet Explorer DOMNodeInserted use-after-free attempt (more info ...)attempted-admin  2015-1689      URL
34410BROWSER-IE Microsoft Internet Explorer DOMNodeInserted use-after-free attempt (more info ...)attempted-admin  2015-1689      URL
34411BROWSER-IE Microsoft Internet Explorer CSecurityContext type confusion use after free attempt (more info ...)attempted-user  2015-1706      URL
34412BROWSER-IE Microsoft Internet Explorer CSecurityContext type confusion use after free attempt (more info ...)attempted-user  2015-1706      URL
34415BROWSER-IE Microsoft Internet Explorer dd element use after free attempt (more info ...)attempted-user  2015-1691      URL
34417BROWSER-IE Microsoft Internet Explorer dd element use after free attempt (more info ...)attempted-user  2015-1691      URL
34418BROWSER-IE Microsoft Internet Explorer Element object use-after-free attempt (more info ...)attempted-admin  2015-1705      URL
34419BROWSER-IE Microsoft Internet Explorer Element object use-after-free attempt (more info ...)attempted-admin  2015-1705      URL
34420BROWSER-IE Microsoft Internet Explorer CDispScroller object use-after-free attempt (more info ...)attempted-admin  2015-1718      URL
34421BROWSER-IE Microsoft Internet Explorer CDispScroller object use-after-free attempt (more info ...)attempted-admin  2015-1718      URL
34422BROWSER-IE Microsoft Internet Explorer CTitleElement object use-after-free attempt (more info ...)attempted-admin  2015-1717      URL
34423BROWSER-IE Microsoft Internet Explorer CTitleElement object use-after-free attempt (more info ...)attempted-admin  2015-1717      URL
34424BROWSER-IE Microsoft Internet Explorer compatibility mode use after free attempt (more info ...)attempted-user  2015-1710      URL
34425BROWSER-IE Microsoft Internet Explorer compatibility mode use after free attempt (more info ...)attempted-user  2015-1710      URL
34430BROWSER-IE Microsoft Internet Explorer CTreePos object use after free attempt (more info ...)attempted-user  2015-1711      URL
34431BROWSER-IE Microsoft Internet Explorer CTreePos object use after free attempt (more info ...)attempted-user  2015-1711      URL
34432BROWSER-IE Microsoft Internet Explorer TableGridBlock use after free attempt (more info ...)attempted-user  2015-1658      URL
34433BROWSER-IE Microsoft Internet Explorer TableGridBlock use after free attempt (more info ...)attempted-user  2015-1658      URL
34436BROWSER-IE Microsoft Internet Explorer CTitleElement use after free attempt (more info ...)attempted-user  2015-1714      URL
34437BROWSER-IE Microsoft Internet Explorer CTitleElement use after free attempt (more info ...)attempted-user  2015-1714      URL
34444BROWSER-IE Microsoft Internet Explorer TableGridBlock object use after free attempt (more info ...)attempted-admin  2015-1709      URL
34445BROWSER-IE Microsoft Internet Explorer TableGridBlock object use after free attempt (more info ...)attempted-admin  2015-1709      URL
34550FILE-PDF Adobe Acrobat Reader JavaScript API trustPropagatorFunction execution bypass attempt (more info ...)attempted-admin  2015-3074      URL
34551FILE-PDF Adobe Acrobat Reader JavaScript API trustPropagatorFunction execution bypass attempt (more info ...)attempted-admin  2015-3074      URL
34557FILE-PDF Adobe Acrobat Reader embedded JavaScript remote code execution attempt (more info ...)attempted-user  2015-3072      
34558FILE-PDF Adobe Acrobat Reader embedded JavaScript remote code execution attempt (more info ...)attempted-user  2015-3072      
34612FILE-PDF Adobe Reader bypass JavaScript API restrictions attempt (more info ...)attempted-user  2015-3062      URL
34613FILE-PDF Adobe Reader bypass JavaScript API restrictions attempt (more info ...)attempted-user  2015-3062      URL
34625FILE-PDF Adobe Reader bypass JavaScript API restrictions attempt (more info ...)attempted-user  2015-3069      URL
34626FILE-PDF Adobe Reader bypass JavaScript API restrictions attempt (more info ...)attempted-user  2015-3069      URL
34627FILE-PDF Adobe Reader bypass JavaScript API restrictions attempt (more info ...)attempted-user  2015-3064      URL
34628FILE-PDF Adobe Reader bypass JavaScript API restrictions attempt (more info ...)attempted-user  2015-3064      URL
34721BROWSER-IE Microsoft Internet Explorer callback function use-after-free attempt (more info ...)attempted-user  2015-1741      URL
34722BROWSER-IE Microsoft Internet Explorer callback function use-after-free attempt (more info ...)attempted-user  2015-1741      URL
34723BROWSER-IE Microsoft Internet Explorer out of bounds array access attempt (more info ...)attempted-user  2015-1742      URL
34724BROWSER-IE Microsoft Internet Explorer out of bounds array access attempt (more info ...)attempted-user  2015-1742      URL
34725BROWSER-IE Microsoft Internet Explorer CTreeNode undefined beforeElement use-after-free attempt (more info ...)attempted-user  2015-1766      URL
34726BROWSER-IE Microsoft Internet Explorer CTreeNode undefined beforeElement use-after-free attempt (more info ...)attempted-user  2015-1766      URL
34729BROWSER-IE Microsoft Internet Explorer stack exhaustion handler remote code execution attempt (more info ...)attempted-admin  2015-1730      URL
34730BROWSER-IE Microsoft Internet Explorer stack exhaustion handler remote code execution attempt (more info ...)attempted-admin  2015-1730      URL
34733BROWSER-IE Microsoft Internet Explorer CAttrValue uninitialized object access attempt (more info ...)attempted-admin  2015-1745      URL
34734BROWSER-IE Microsoft Internet Explorer CAttrValue uninitialized object access attempt (more info ...)attempted-admin  2015-1745      URL
34735BROWSER-IE Microsoft Internet Explorer COptionElement object use after free attempt (more info ...)attempted-user  2015-1755      URL
34736BROWSER-IE Microsoft Internet Explorer COptionElement object use after free attempt (more info ...)attempted-user  2015-1755      URL
34745BROWSER-IE Microsoft Internet Explorer TextNode object use after free attempt (more info ...)attempted-user  2015-1737      URL
34746BROWSER-IE Microsoft Internet Explorer TextNode object use after free attempt (more info ...)attempted-user  2015-1737      URL
34747BROWSER-IE Microsoft Internet Explorer CoInternetParseUrl use-after-free attempt (more info ...)attempted-user  2015-1740      URL
34748BROWSER-IE Microsoft Internet Explorer CoInternetParseUrl use-after-free attempt (more info ...)attempted-user  2015-1740      URL
34749BROWSER-IE Microsoft Internet Explorer TableGridBlock object use after free attempt (more info ...)attempted-user  2015-1751      URL
34750BROWSER-IE Microsoft Internet Explorer TableGridBlock object use after free attempt (more info ...)attempted-user  2015-1751      URL
34753BROWSER-IE Microsoft Internet Explorer CLegendElement object use after free attempt (more info ...)attempted-user  2015-1753      URL
34754BROWSER-IE Microsoft Internet Explorer CLegendElement object use after free attempt (more info ...)attempted-user  2015-1753      URL
34755BROWSER-IE Microsoft Internet Explorer uninitialized VARIANT object remote code execution attempt (more info ...)attempted-admin  2015-1735      URL
34756BROWSER-IE Microsoft Internet Explorer uninitialized VARIANT object remote code execution attempt (more info ...)attempted-admin  2015-1735      URL
34757BROWSER-IE Microsoft Internet Explorer CDXTFilterNode object remote code execution attempt (more info ...)attempted-admin  2015-1744      URL
34758BROWSER-IE Microsoft Internet Explorer CDXTFilterNode object remote code execution attempt (more info ...)attempted-admin  2015-1744      URL
34759BROWSER-IE Microsoft Internet Explorer 9 CTableSection object use-after-free attempt (more info ...)attempted-user  2015-1687      URL
34760BROWSER-IE Microsoft Internet Explorer 9 CTableSection object use-after-free attempt (more info ...)attempted-user  2015-1687      URL
34763BROWSER-IE Microsoft Internet Explorer 8 mode menu tag out-of-bounds access attempt (more info ...)attempted-user  2015-1752      URL
34764BROWSER-IE Microsoft Internet Explorer 8 mode menu tag out-of-bounds access attempt (more info ...)attempted-user  2015-1752      URL
34765BROWSER-IE Microsoft Internet Explorer CStyleAttrArray use after free attempt (more info ...)policy-violation  2015-1736      URL
34766BROWSER-IE Microsoft Internet Explorer CStyleAttrArray use after free attempt (more info ...)policy-violation  2015-1736      URL
34767BROWSER-IE Microsoft Internet Explorer textarea parent use-after-free attempt (more info ...)attempted-user  2015-1750      URL
34768BROWSER-IE Microsoft Internet Explorer textarea parent use-after-free attempt (more info ...)attempted-user  2015-1750      URL
34778BROWSER-IE Microsoft Internet Explorer LayoutLineBoxFullShort use after free attempt (more info ...)attempted-user  2015-1731      URL
34779BROWSER-IE Microsoft Internet Explorer LayoutLineBoxFullShort use after free attempt (more info ...)attempted-user  2015-1731      URL
34790BROWSER-IE Microsoft Internet Explorer out of bounds memory access attempt (more info ...)attempted-admin  2015-1732      URL
34791BROWSER-IE Microsoft Internet Explorer out of bounds memory access attempt (more info ...)attempted-admin  2015-1732      URL
34824BROWSER-IE Microsoft Internet Explorer moveEnd information disclosure attempt (more info ...)attempted-recon        URL
34825BROWSER-IE Microsoft Internet Explorer moveEnd information disclosure attempt (more info ...)attempted-recon        URL
34873BROWSER-IE Microsoft Internet Explorer CTextElement use after free attempt (more info ...)attempted-user  2014-2782      URL
34874BROWSER-IE Microsoft Internet Explorer CTextElement use after free attempt (more info ...)attempted-user  2014-2782      URL
35012BROWSER-IE Microsoft Internet Explorer CTreeNode use-after-free attempt (more info ...)attempted-user  2015-0100      URL
35013BROWSER-IE Microsoft Internet Explorer CTreeNode use-after-free attempt (more info ...)attempted-user  2015-0100      URL
35051BROWSER-FIREFOX Mozilla Firefox IDL fragment privilege escalation attempt (more info ...)attempted-user  2014-1510      URL
35052BROWSER-FIREFOX Mozilla Firefox IDL fragment privilege escalation attempt (more info ...)attempted-user  2014-1510      URL
35070BROWSER-FIREFOX Mozilla Firefox DOMSVGLength insertItemBefore use after free attempt (more info ...)attempted-user  2014-1563      URL
35071BROWSER-FIREFOX Mozilla Firefox DOMSVGLength replaceItem use after free attempt (more info ...)attempted-user  2014-1563      URL
35072BROWSER-FIREFOX Mozilla Firefox DOMSVGLength initialize use after free attempt (more info ...)attempted-user  2014-1563      URL
35073BROWSER-FIREFOX Mozilla Firefox DOMSVGLength insertItemBefore use after free attempt (more info ...)attempted-user  2014-1563      URL
35074BROWSER-FIREFOX Mozilla Firefox DOMSVGLength replaceItem use after free attempt (more info ...)attempted-user  2014-1563      URL
35075BROWSER-FIREFOX Mozilla Firefox DOMSVGLength initialize use after free attempt (more info ...)attempted-user  2014-1563      URL
35114BROWSER-IE Microsoft Internet Explorer replaceChild function memory corruption attempt (more info ...)attempted-user  2014-0280      URL
35115BROWSER-IE Microsoft Internet Explorer replaceChild function memory corruption attempt (more info ...)attempted-user  2014-0280      URL
35119BROWSER-IE Microsoft Internet Explorer CTreeNode type confusion attempt (more info ...)attempted-user  2015-2384      URL
35120BROWSER-IE Microsoft Internet Explorer CTreeNode type confusion attempt (more info ...)attempted-user  2015-2384      URL
35121BROWSER-IE Microsoft Internet Explorer CTextArea use after free attempt (more info ...)attempted-user  2015-2397      URL
35122BROWSER-IE Microsoft Internet Explorer CTextArea use after free attempt (more info ...)attempted-user  2015-2397      URL
35123BROWSER-IE Microsoft Internet Explorer CTableRow use after free attempt (more info ...)attempted-user  2015-2406      URL
35124BROWSER-IE Microsoft Internet Explorer CTableRow use after free attempt (more info ...)attempted-user  2015-2406      URL
35125BROWSER-IE Microsoft Internet Explorer CInput use after free attempt (more info ...)attempted-user  2015-2401      URL
35126BROWSER-IE Microsoft Internet Explorer CInput use after free attempt (more info ...)attempted-user  2015-2401      URL
35139BROWSER-IE Microsoft Internet Explorer sandbox permission bypass registry read attempt (more info ...)attempted-user  2015-2429      URL
35140BROWSER-IE Microsoft Internet Explorer sandbox permission bypass registry read attempt (more info ...)attempted-user  2015-2429      URL
35145BROWSER-IE Microsoft Internet Explorer CTableSection use after free attempt (more info ...)attempted-user  2015-1733      URL
35146BROWSER-IE Microsoft Internet Explorer CTableSection use after free attempt (more info ...)attempted-user  2015-1733      URL
35152BROWSER-IE Microsoft Internet Explorer memory access through an uninitialized pointer attempt (more info ...)attempted-admin  2015-2406      URL
35153BROWSER-IE Microsoft Internet Explorer memory access through an uninitialized pointer attempt (more info ...)attempted-admin  2015-2406      URL
35154BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode use after free attempt (more info ...)attempted-user  2015-1767      URL
35155BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode use after free attempt (more info ...)attempted-user  2015-1767      URL
35156BROWSER-IE Microsoft Internet Explorer CTableSection object out of bounds memory access attempt (more info ...)attempted-user  2015-2403      URL
35157BROWSER-IE Microsoft Internet Explorer CTableSection object out of bounds memory access attempt (more info ...)attempted-user  2015-2403      URL
35158BROWSER-IE Microsoft Internet Explorer CFancyFormat object use-after-free attempt (more info ...)attempted-user  2015-2422      URL
35159BROWSER-IE Microsoft Internet Explorer CFancyFormat object use-after-free attempt (more info ...)attempted-user  2015-2422      URL
35164BROWSER-IE Microsoft Internet Explorer CTreeNode object use after free attempt (more info ...)attempted-admin  2015-2390      URL
35165BROWSER-IE Microsoft Internet Explorer CTreeNode object use after free attempt (more info ...)attempted-admin  2015-2390      URL
35170BROWSER-IE Microsoft Internet Explorer MutationObserver use after free attempt (more info ...)attempted-user  2015-2425  75745    URL
35172BROWSER-IE Microsoft Internet Explorer CTitleElement object use after free attempt (more info ...)attempted-user  2015-2408      URL
35173BROWSER-IE Microsoft Internet Explorer CTitleElement object use after free attempt (more info ...)attempted-user  2015-2408      URL
35178BROWSER-IE Microsoft Internet Explorer CAttribute object use after free attempt (more info ...)attempted-admin  2015-2389      URL
35179BROWSER-IE Microsoft Internet Explorer CAttribute object use after free attempt (more info ...)attempted-admin  2015-2389      URL
35182BROWSER-IE Microsoft Internet Explorer table column resize use-after-free attempt (more info ...)attempted-user  2015-2388      URL
35183BROWSER-IE Microsoft Internet Explorer table column resize use-after-free attempt (more info ...)attempted-user  2015-2388      URL
35185BROWSER-IE Microsoft Internet Explorer meta tag double free attempt (more info ...)attempted-user  2015-2391      URL
35196BROWSER-IE Microsoft Internet Explorer CFieldSetElement object use after free attempt (more info ...)attempted-user  2015-1738      URL
35197BROWSER-IE Microsoft Internet Explorer CFieldSetElement object use after free attempt (more info ...)attempted-user  2015-1738      URL
35199BROWSER-IE Microsoft Internet Explorer TreeComputedContent object use after free attempt (more info ...)attempted-user  2015-6073      URL
35200BROWSER-IE Microsoft Internet Explorer TreeComputedContent object use after free attempt (more info ...)attempted-user  2015-6073      URL
35203BROWSER-IE Microsoft Internet Explorer CImgElement object use after free attempt (more info ...)attempted-user  2015-2383      URL
35204BROWSER-IE Microsoft Internet Explorer CImgElement object use after free attempt (more info ...)attempted-user  2015-2383      URL
35205BROWSER-IE Microsoft Internet Explorer CImgElement object use after free attempt (more info ...)attempted-user  2015-2383      URL
35206BROWSER-IE Microsoft Internet Explorer CImgElement object use after free attempt (more info ...)attempted-user  2015-2383      URL
35209BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2015-2404      URL
35210BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2015-2404      URL
35211BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2015-2404      URL
35212BROWSER-IE Microsoft Internet Explorer CMarkup object use after free attempt (more info ...)attempted-user  2015-2404      URL
35213BROWSER-IE Microsoft Internet Explorer 10 VBScript array element use after free attempt (more info ...)attempted-user  2015-2372      URL
35214BROWSER-IE Microsoft Internet Explorer 10 VBScript array element use after free attempt (more info ...)attempted-user  2015-2372      URL
35331FILE-PDF Adobe Reader PDF document closed prior to javascript termination use after free attempt (more info ...)attempted-user  2016-0937      URL
35332FILE-PDF Adobe Reader PDF document closed prior to javascript termination use after free attempt (more info ...)attempted-user  2016-0937      URL
35380FILE-PDF Adobe Reader javascript setExportValues field object use after free attempt (more info ...)attempted-user  2015-4448      URL
35381FILE-PDF Adobe Reader javascript setExportValues field object use after free attempt (more info ...)attempted-user  2015-4448      URL
35382FILE-PDF Adobe Reader javascript setExportValues field object use after free attempt (more info ...)attempted-user  2015-4448      URL
35383FILE-PDF Adobe Reader javascript setExportValues field object use after free attempt (more info ...)attempted-user  2015-4448      URL
35467FILE-JAVA Oracle Java VersionHelper loadClass sandbox bypass attempt (more info ...)policy-violation  2014-0422      
35468FILE-JAVA Oracle Java VersionHelper loadClass sandbox bypass attempt (more info ...)policy-violation  2014-0422      
35469FILE-JAVA Oracle Java VersionHelper loadClass sandbox bypass attempt (more info ...)policy-violation  2014-0422      
35473BROWSER-IE Microsoft Internet Explorer COrphanedStylesheetArray use-after-free attempt (more info ...)attempted-user  2015-2450      URL
35474BROWSER-IE Microsoft Internet Explorer COrphanedStylesheetArray use-after-free attempt (more info ...)attempted-user  2015-2450      URL
35475BROWSER-IE Microsoft Internet Explorer COrphanedStylesheetArray use after free attempt (more info ...)attempted-user  2015-2451      URL
35476BROWSER-IE Microsoft Internet Explorer COrphanedStylesheetArray use after free attempt (more info ...)attempted-user  2015-2451      URL
35477BROWSER-IE Microsoft Internet Explorer CLabelElement object use after free attempt (more info ...)attempted-user  2015-2444  69325    URL
35478BROWSER-IE Microsoft Internet Explorer CLabelElement object use after free attempt (more info ...)attempted-user  2015-2444  69325    URL
35481BROWSER-IE Microsoft Internet Explorer CParaElement use-after-free attempt (more info ...)attempted-user  2015-2442      URL
35482BROWSER-IE Microsoft Internet Explorer CParaElement use-after-free attempt (more info ...)attempted-user  2015-2442      URL
35493BROWSER-IE Microsoft Internet Explorer CAttrArray use after free attempt (more info ...)attempted-admin  2015-2452      URL
35494BROWSER-IE Microsoft Internet Explorer CAttrArray use after free attempt (more info ...)attempted-admin  2015-2452      URL
35499BROWSER-IE Microsoft Internet Explorer window scroll integer overflow attempt (more info ...)attempted-user  2015-2446  76193    URL
35500BROWSER-IE Microsoft Internet Explorer window scroll integer overflow attempt (more info ...)attempted-user  2015-2446  76193    URL
35536BROWSER-IE Microsoft Internet Explorer table layout cache arbitrary code execution attempt (more info ...)attempted-user  2015-2502      URL
35537BROWSER-IE Microsoft Internet Explorer table layout cache arbitrary code execution attempt (more info ...)attempted-user  2015-2502      URL
35588FILE-FLASH Google Chrome pepflashplayer SurfaceFilterList use-after-free attempt (more info ...)attempted-user  2015-5563      URL
35589FILE-FLASH Google Chrome pepflashplayer SurfaceFilterList use-after-free attempt (more info ...)attempted-user  2015-5563      URL
35590FILE-FLASH Google Chrome pepflashplayer SurfaceFilterList use-after-free attempt (more info ...)attempted-user  2015-5563      URL
35591FILE-FLASH Google Chrome pepflashplayer SurfaceFilterList use-after-free attempt (more info ...)attempted-user  2015-5563      URL
35685BROWSER-PLUGINS Mozilla Firefox generatecrmfrequest policy function call access attempt (more info ...)attempted-user  2013-1710  61900    URL
35686BROWSER-PLUGINS Mozilla Firefox generatecrmfrequest policy function call access attempt (more info ...)attempted-user  2013-1710  61900    URL
35737INDICATOR-OBFUSCATION Javascript stealth executable download attempt (more info ...)trojan-activity        URL
35738INDICATOR-OBFUSCATION Javascript stealth executable download attempt (more info ...)trojan-activity        URL
35747BROWSER-IE Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt (more info ...)attempted-user  2012-0170  52904    URL
35748BROWSER-IE Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt (more info ...)attempted-user  2012-0170  52904    URL
35771BROWSER-IE Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt (more info ...)attempted-user  2012-0170  52904    URL
35772BROWSER-IE Microsoft Internet Explorer iframe onreadystatechange handler use after free attempt (more info ...)attempted-user  2012-0170  52904    URL
35809FILE-PDF Adobe Reader Javascript API ANSendForReview - possible privilege escalation attempt (more info ...)attempted-user  2015-4438      URL
35810FILE-PDF Adobe Reader Javascript API ANSendForReview - possible privilege escalation attempt (more info ...)attempted-user  2015-4438      URL
35811FILE-PDF Adobe Reader Javascript API ANStartApproval - possible privilege escalation attempt (more info ...)attempted-user  2015-4435      URL
35812FILE-PDF Adobe Reader Javascript API ANStartApproval - possible privilege escalation attempt (more info ...)attempted-user  2015-4435      URL
35836BROWSER-IE Microsoft Internet Explorer CLabelElement object use after free attempt (more info ...)attempted-user  2015-2444  69325    URL
35837BROWSER-IE Microsoft Internet Explorer CLabelElement object use after free attempt (more info ...)attempted-user  2015-2444  69325    URL
35865BROWSER-IE Internet Explorer DataSource recordset remote code execution attempt (more info ...)attempted-user        
35866BROWSER-IE Microsoft Internet Explorer XMLDOM double free corruption attempt (more info ...)attempted-user        
35867BROWSER-IE Microsoft Internet Explorer XMLDOM double free corruption attempt (more info ...)attempted-user        
35868BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user        
35869BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user        
35870BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user        
35871BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user        
35877FILE-PDF Adobe Acrobat Reader javascript AcroForm object use after free attempt (more info ...)attempted-user        
35878FILE-PDF Adobe Acrobat Reader javascript AcroForm object use after free attempt (more info ...)attempted-user        
35879FILE-PDF Adobe Acrobat Reader javascript AcroForm object use after free attempt (more info ...)attempted-user        
35880FILE-PDF Adobe Acrobat Reader javascript AcroForm object use after free attempt (more info ...)attempted-user        
35963BROWSER-IE Microsoft Internet Explorer element attribute use after free attempt (more info ...)attempted-user  2015-2485      URL
35964BROWSER-IE Microsoft Internet Explorer element attribute use after free attempt (more info ...)attempted-user  2015-2485      URL
35965BROWSER-IE Microsoft Internet Explorer CElement input type memory corruption attempt (more info ...)attempted-user  2015-2486      URL
35966BROWSER-IE Microsoft Internet Explorer CElement input type memory corruption attempt (more info ...)attempted-user  2015-2486      URL
35969BROWSER-IE Microsoft Internet Explorer Embedded Windows Media Player CMarkup object use after free attempt (more info ...)attempted-user  2015-2487      URL
35970BROWSER-IE Microsoft Internet Explorer Embedded Windows Media Player CMarkup object use after free attempt (more info ...)attempted-user  2015-2487      URL
35971BROWSER-IE Microsoft Internet Explorer Embedded Windows Media Player CMarkup object use after free attempt (more info ...)attempted-user  2015-2487      URL
35972BROWSER-IE Microsoft Internet Explorer Embedded Windows Media Player CMarkup object use after free attempt (more info ...)attempted-user  2015-2487      URL
35975BROWSER-IE Microsoft Internet Explorer CElement object use-after-free attempt (more info ...)attempted-user  2015-2491      URL
35976BROWSER-IE Microsoft Internet Explorer CElement object use-after-free attempt (more info ...)attempted-user  2015-2491      URL
35990BROWSER-IE Microsoft Internet Explorer JScript.Compact insertBefore memory corruption attempt (more info ...)attempted-user  2015-2493      URL
35991BROWSER-IE Microsoft Internet Explorer JScript.Compact insertBefore memory corruption attempt (more info ...)attempted-user  2015-2493      URL
35992BROWSER-IE Microsoft Internet Explorer CImgTaskSvgDoc object double free attempt (more info ...)attempted-user  2015-2501      URL
35993BROWSER-IE Microsoft Internet Explorer CImgTaskSvgDoc object double free attempt (more info ...)attempted-user  2015-2501      URL
36004BROWSER-IE Microsoft Internet Explorer CImgElement object double free attempt (more info ...)attempted-user  2015-2500      URL
36005BROWSER-IE Microsoft Internet Explorer CImgElement object double free attempt (more info ...)attempted-user  2015-2500      URL
36006BROWSER-IE Microsoft Internet Explorer CTableColCalc out of bounds memory write attempt (more info ...)attempted-user  2015-2499      URL
36007BROWSER-IE Microsoft Internet Explorer CTableColCalc out of bounds memory write attempt (more info ...)attempted-user  2015-2499      URL
36008BROWSER-IE Microsoft Internet Explorer out of bounds array memory access attempt (more info ...)attempted-user  2015-2498      URL
36009BROWSER-IE Microsoft Internet Explorer out of bounds array memory access attempt (more info ...)attempted-user  2015-2498      URL
36018BROWSER-IE Microsoft Internet Explorer invalid memory access attempt (more info ...)attempted-user  2015-2492      URL
36019BROWSER-IE Microsoft Internet Explorer invalid memory access attempt (more info ...)attempted-user  2015-2492      URL
36068BROWSER-IE Microsoft Internet Explorer window scroll integer overflow attempt (more info ...)attempted-user  2015-2446  76193    URL
36069BROWSER-IE Microsoft Internet Explorer window scroll integer overflow attempt (more info ...)attempted-user  2015-2446  76193    URL
36224BROWSER-IE Microsoft Internet Explorer superscript use after free attempt (more info ...)attempted-user  2013-3111      URL
36235BROWSER-IE Microsoft Internet Explorer CGenericElement use after free attempt (more info ...)attempted-user  2015-0017      URL
36236BROWSER-IE Microsoft Internet Explorer CGenericElement use after free attempt (more info ...)attempted-user  2015-0017      URL
36237BROWSER-IE Microsoft Internet Explorer CGenericElement use after free attempt (more info ...)attempted-user  2015-0017      URL
36238BROWSER-IE Microsoft Internet Explorer CGenericElement use after free attempt (more info ...)attempted-user  2015-0017      URL
36239FILE-JAVA Oracle Java System.arraycopy race condition attempt (more info ...)attempted-user  2014-0456      
36240FILE-JAVA Oracle Java System.arraycopy race condition attempt (more info ...)attempted-user  2014-0456      
36249BROWSER-IE Microsoft Internet Explorer CSelectElement SetCurSel remote code execution attempt (more info ...)attempted-user  2014-0312      URL
36401BROWSER-IE Microsoft Internet Explorer CQuickLinks object use-after-free attempt (more info ...)attempted-user  2015-2515      URL
36402BROWSER-IE Microsoft Internet Explorer CQuickLinks object use-after-free attempt (more info ...)attempted-user  2015-2515      URL
36418BROWSER-IE Microsoft Internet Explorer CWindow object use after free attempt (more info ...)attempted-user  2015-6042      URL
36423BROWSER-IE Microsoft Internet Explorer CDeskBand use-after-free attempt (more info ...)attempted-user  2015-2548      URL
36424BROWSER-IE Microsoft Internet Explorer CDeskBand use-after-free attempt (more info ...)attempted-user  2015-2548      URL
36436BROWSER-IE Microsoft Internet Explorer pre-line use after free attempt (more info ...)attempted-user  2015-6050      URL
36437BROWSER-IE Microsoft Internet Explorer ieframe.dll ActiveX clsid access (more info ...)attempted-user  2015-6049      URL
36438BROWSER-IE Microsoft Internet Explorer ieframe.dll ActiveX clsid access (more info ...)attempted-user  2015-6049      URL
36439BROWSER-IE Microsoft Internet Explorer CTableSelection use-after-free attempt (more info ...)attempted-user  2015-6048      URL
36440BROWSER-IE Microsoft Internet Explorer CTableSelection use-after-free attempt (more info ...)attempted-user  2015-6048      URL
36443BROWSER-IE Microsoft Internet Explorer EventListener use after free attempt (more info ...)attempted-user  2015-6045      URL
36444BROWSER-IE Microsoft Internet Explorer EventListener use after free attempt (more info ...)attempted-user  2015-6045      URL
36450BROWSER-IE Microsoft Internet Explorer RegExp object use after free attempt (more info ...)attempted-user  2015-2482      URL
36451BROWSER-IE Microsoft Internet Explorer RegExp object use after free attempt (more info ...)attempted-user  2015-2482      URL
36532SERVER-OTHER Oracle Java RMI remote code execution attempt (more info ...)attempted-user  2020-11998      URL
36604BROWSER-IE Microsoft Internet Explorer meta tag double free attempt (more info ...)attempted-user  2015-2391      URL
36605BROWSER-IE Microsoft Internet Explorer meta tag double free attempt (more info ...)attempted-user  2015-2391      URL
36671BROWSER-IE Microsoft Internet Explorer fragmented CtxtBlk heap overflow attempt (more info ...)attempted-user  2015-6068      URL
36672BROWSER-IE Microsoft Internet Explorer fragmented CtxtBlk heap overflow attempt (more info ...)attempted-user  2015-6068      URL
36673BROWSER-IE Microsoft Internet Explorer GetPlainText negative start index out of bounds write attempt (more info ...)attempted-user  2015-6158      URL
36674BROWSER-IE Microsoft Internet Explorer GetPlainText negative start index out of bounds write attempt (more info ...)attempted-user  2015-6158      URL
36675BROWSER-IE Microsoft Internet Explorer CMarkup use-after-free attempt (more info ...)attempted-user  2015-6078      URL
36676BROWSER-IE Microsoft Internet Explorer CMarkup use-after-free attempt (more info ...)attempted-user  2015-6078      URL
36677BROWSER-IE Microsoft Internet Explorer SVG textbox out of bound memory access attempt (more info ...)attempted-user  2015-6085      URL
36678BROWSER-IE Microsoft Internet Explorer SVG textbox out of bound memory access attempt (more info ...)attempted-user  2015-6085      URL
36679BROWSER-IE Microsoft Internet Explorer cache management code overflow attempt (more info ...)attempted-user  2015-6064      URL
36680BROWSER-IE Microsoft Internet Explorer cache management code overflow attempt (more info ...)attempted-user  2015-6064      URL
36681BROWSER-IE Microsoft Internet Explorer access violation attempt (more info ...)attempted-user  2015-6081      URL
36682BROWSER-IE Microsoft Internet Explorer access violation attempt (more info ...)attempted-user  2015-6081      URL
36683BROWSER-IE Microsoft Internet Explorer CTableCell object use after free attempt (more info ...)attempted-user  2015-6079      URL
36684BROWSER-IE Microsoft Internet Explorer CTableCell object use after free attempt (more info ...)attempted-user  2015-6079      URL
36685BROWSER-IE Microsoft Internet Explorer col onpropertychange memory corruption attempt (more info ...)attempted-user  2015-6070      URL
36686BROWSER-IE Microsoft Internet Explorer col onpropertychange memory corruption attempt (more info ...)attempted-user  2015-6070      URL
36687BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2015-6076      URL
36688BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2015-6076      URL
36689BROWSER-IE Microsoft Internet Explorer managed CDispNode objects use-after-free attempt (more info ...)attempted-user  2015-6082      URL
36690BROWSER-IE Microsoft Internet Explorer managed CDispNode objects use-after-free attempt (more info ...)attempted-user  2015-6082      URL
36691BROWSER-IE Microsoft Internet Explorer CUListElement use-after-free attempt (more info ...)attempted-user  2015-6080      URL
36692BROWSER-IE Microsoft Internet Explorer CUListElement use-after-free attempt (more info ...)attempted-user  2015-6080      URL
36693BROWSER-IE Microsoft Internet Explorer style object stylesheet use after free attempt (more info ...)attempted-user  2015-6065      URL
36694BROWSER-IE Microsoft Internet Explorer style object stylesheet use after free attempt (more info ...)attempted-user  2015-6065      URL
36695BROWSER-IE Microsoft Internet Explorer table element modification use after free attempt (more info ...)attempted-user  2015-6066      URL
36696BROWSER-IE Microsoft Internet Explorer table element modification use after free attempt (more info ...)attempted-user  2015-6066      URL
36699BROWSER-IE Microsoft Internet Explorer CTreeNode row element removal remote code execution attempt (more info ...)attempted-user  2015-6072      URL
36700BROWSER-IE Microsoft Internet Explorer CTreeNode row element removal remote code execution attempt (more info ...)attempted-user  2015-6072      URL
36701BROWSER-IE Microsoft Internet Explorer CEditEventSink navigate use after free attempt (more info ...)attempted-user  2015-6071  77445    URL
36702BROWSER-IE Microsoft Internet Explorer CEditEventSink navigate use after free attempt (more info ...)attempted-user  2015-6071  77445    URL
36738BROWSER-IE Microsoft Internet Explorer CTsfTextStore use-after-free attempt (more info ...)attempted-user  2015-6077      URL
36739BROWSER-IE Microsoft Internet Explorer CTsfTextStore use-after-free attempt (more info ...)attempted-user  2015-6077      URL
36742BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2015-6075      URL
36743BROWSER-IE Microsoft Internet Explorer CElement use after free attempt (more info ...)attempted-user  2015-6075      URL
36759INDICATOR-COMPROMISE Microsoft Internet Explorer setAttributeNS ASLR bypass attempt (more info ...)misc-activity  2015-6086      URL
36760INDICATOR-COMPROMISE Microsoft Internet Explorer setAttributeNS ASLR bypass attempt (more info ...)misc-activity  2015-6086      URL
36811BROWSER-IE Microsoft Internet Explorer nonexistent attribute removal memory corruption attempt (more info ...)attempted-dos  2012-1524      URL
36813BROWSER-IE Microsoft Internet Explorer nonexistent attribute removal memory corruption attempt (more info ...)attempted-dos  2012-1524      URL
36826SERVER-OTHER Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user  2018-15381      URL
36896BROWSER-IE Microsoft Internet Explorer 11 VBScript redim preserve denial-of-service attempt (more info ...)attempted-user  2014-6332      URL
36917BROWSER-IE Microsoft Internet Explorer iCalendar cross site scripting attempt (more info ...)attempted-user  2015-6139      URL
36918BROWSER-IE Microsoft Internet Explorer CElement object use after free attempt (more info ...)attempted-user  2015-6151      URL
36919BROWSER-IE Microsoft Internet Explorer CElement object use after free attempt (more info ...)attempted-user  2015-6151      URL
36920BROWSER-IE Microsoft Internet Explorer invalid TableRow use after free attempt (more info ...)attempted-user  2015-6147      URL
36921BROWSER-IE Microsoft Internet Explorer invalid TableRow use after free attempt (more info ...)attempted-user  2015-6147      URL
36922BROWSER-IE Microsoft Internet Explorer VBScript engine use after free attempt (more info ...)attempted-user  2015-6136      URL
36923BROWSER-IE Microsoft Internet Explorer VBScript engine use after free attempt (more info ...)attempted-user  2015-6136      URL
36926BROWSER-IE Microsoft Internet Explorer CObjectElement type confusion attempt (more info ...)attempted-user  2015-6156      URL
36927BROWSER-IE Microsoft Internet Explorer CObjectElement type confusion attempt (more info ...)attempted-user  2015-6156      URL
36928BROWSER-IE Microsoft Internet Explorer CTableLayout use after free attempt (more info ...)attempted-user  2015-6150      URL
36929BROWSER-IE Microsoft Internet Explorer CTableLayout use after free attempt (more info ...)attempted-user  2015-6150      URL
36936BROWSER-IE Microsoft Internet Explorer TextBlock out of bounds read attempt (more info ...)attempted-user  2015-6159      URL
36937BROWSER-IE Microsoft Internet Explorer TextBlock out of bounds read attempt (more info ...)attempted-user  2015-6159      URL
36938BROWSER-IE Microsoft Internet Explorer invalid table grid memory corruption attempt (more info ...)attempted-user  2015-6153      URL
36939BROWSER-IE Microsoft Internet Explorer invalid table grid memory corruption attempt (more info ...)attempted-user  2015-6153      URL
36940BROWSER-IE Microsoft Internet Explorer CSpliceTreeEngine RemoveSplice null pointer dereference attempt (more info ...)attempted-user  2015-6148      URL
36941BROWSER-IE Microsoft Internet Explorer CSpliceTreeEngine RemoveSplice null pointer dereference attempt (more info ...)attempted-user  2015-6148      URL
36942BROWSER-IE Microsoft Internet Explorer flexbox use after free attempt (more info ...)attempted-user  2015-6155      URL
36943BROWSER-IE Microsoft Internet Explorer flexbox use after free attempt (more info ...)attempted-user  2015-6155      URL
36944BROWSER-IE Microsoft Internet Explorer CTreePos use after free attempt (more info ...)attempted-user  2015-6160      URL
36945BROWSER-IE Microsoft Internet Explorer CTreePos use after free attempt (more info ...)attempted-user  2015-6160      URL
36946BROWSER-IE Microsoft Internet Explorer CSharedStyleSheet RemoveRule out of bounds read attempt (more info ...)attempted-user  2015-6141      URL
36947BROWSER-IE Microsoft Internet Explorer CSharedStyleSheet RemoveRule out of bounds read attempt (more info ...)attempted-user  2015-6141      URL
36948BROWSER-IE Microsoft Internet Explorer CTableCell invalid index memory corruption attempt (more info ...)attempted-user  2015-6149      URL
36949BROWSER-IE Microsoft Internet Explorer CTableCell invalid index memory corruption attempt (more info ...)attempted-user  2015-6149      URL
36950BROWSER-IE Microsoft Internet Explorer SComputedStyle destructor out of bounds read attempt (more info ...)attempted-user  2015-6140      URL
36951BROWSER-IE Microsoft Internet Explorer SComputedStyle destructor out of bounds read attempt (more info ...)attempted-user  2015-6140      URL
36956BROWSER-IE Microsoft Internet Explorer TableGridBoxBuilder UpdateColumnSize out of bounds read attempt (more info ...)attempted-user  2015-6157      URL
36957BROWSER-IE Microsoft Internet Explorer TableGridBoxBuilder UpdateColumnSize out of bounds read attempt (more info ...)attempted-user  2015-6157      URL
36962BROWSER-IE Microsoft Internet Explorer CAttribute to CStyleAttrArray type confusion attempt (more info ...)attempted-user  2015-6142      URL
36963BROWSER-IE Microsoft Internet Explorer CAttribute to CStyleAttrArray type confusion attempt (more info ...)attempted-user  2015-6142      URL
36980BROWSER-IE Microsoft Internet Explorer javascript argument type confusion attempt (more info ...)attempted-user  2015-6134      URL
36981BROWSER-IE Microsoft Internet Explorer javascript argument type confusion attempt (more info ...)attempted-user  2015-6134      URL
36983BROWSER-IE Microsoft Internet Explorer select use after free attempt (more info ...)attempted-user  2015-6145      URL
36986BROWSER-IE Microsoft Internet Explorer CAttrArray use after free attempt (more info ...)attempted-user  2016-0082      URL
36987BROWSER-IE Microsoft Internet Explorer CAttrArray use after free attempt (more info ...)attempted-user  2016-0082      URL
36988BROWSER-IE Microsoft Internet Explorer cross origin policy bypass via redirect attempt (more info ...)attempted-user  2015-6164      URL
36991BROWSER-IE Microsoft Internet Explorer CDispContainer out of bounds read attempt (more info ...)attempted-user  2015-6152      URL
36992BROWSER-IE Microsoft Internet Explorer CDispContainer out of bounds read attempt (more info ...)attempted-user  2015-6152      URL
37003BROWSER-IE Microsoft Internet Explorer CMarkupPointer UnEmbed out of bounds read attempt (more info ...)attempted-user  2015-6154      URL
37004BROWSER-IE Microsoft Internet Explorer CMarkupPointer UnEmbed out of bounds read attempt (more info ...)attempted-user  2015-6154      URL
37009BROWSER-IE Microsoft Internet Explorer TextBlock object use after free attempt (more info ...)attempted-user  2015-6162      URL
37010BROWSER-IE Microsoft Internet Explorer TextBlock object use after free attempt (more info ...)attempted-user  2015-6162      URL
37135SERVER-WEBAPP Fireeye Java decompiler reflection remote code execution attempt (more info ...)attempted-user        URL
37136SERVER-WEBAPP Fireeye Java decompiler reflection remote code execution attempt (more info ...)attempted-user        URL
37137SERVER-WEBAPP Fireeye Java decompiler reflection remote code execution attempt (more info ...)attempted-user        URL
37257BROWSER-IE Microsoft Internet Explorer mapi32x.dll dll-load exploit attempt (more info ...)attempted-user  2016-0020      URL
37258BROWSER-IE Microsoft Internet Explorer request for mapi32x.dll over SMB attempt (more info ...)attempted-user  2016-0020      URL
37283BROWSER-IE Microsoft Internet Explorer VBScript engine use after free attempt (more info ...)attempted-user  2018-1023      URL
37284BROWSER-IE Microsoft Internet Explorer VBScript engine use after free attempt (more info ...)attempted-user  2018-1023      URL
37326BROWSER-CHROME Google Chrome PDF Viewer information disclosure attempt (more info ...)misc-attack  2015-1302      URL
37327BROWSER-CHROME Google Chrome PDF Viewer information disclosure attempt (more info ...)misc-attack  2015-1302      URL
37405FILE-PDF Adobe Reader addAnnot JavaScript based memory corruption attempt (more info ...)attempted-user  2016-0931      URL
37406FILE-PDF Adobe Reader addAnnot JavaScript based memory corruption attempt (more info ...)attempted-user  2016-0931      URL
37441FILE-OTHER Adobe Flash Player javascript parsing cross site scripting attempt (more info ...)attempted-user  2014-0533      URL
37442FILE-OTHER Adobe Flash Player javascript parsing cross site scripting attempt (more info ...)attempted-user  2014-0533      URL
37464FILE-PDF Adobe Acrobat Reader JavaScript model privileged API bypass attempt (more info ...)policy-violation  2016-0943      URL
37465FILE-PDF Adobe Acrobat Reader JavaScript model privileged API bypass attempt (more info ...)policy-violation  2016-0943      URL
37527SERVER-OTHER IBM WebSphere InvokerTransformer serialized Java object remote code execution attempt (more info ...)attempted-user  2015-7450  77653    URL
37553BROWSER-IE Microsoft Internet Explorer CDATA use-after-free attempt (more info ...)attempted-user  2016-0072      URL
37554BROWSER-IE Microsoft Internet Explorer CDATA use-after-free attempt (more info ...)attempted-user  2016-0072      URL
37571BROWSER-IE Microsoft Internet Explorer CDomPrototype type confusion attempt (more info ...)attempted-user  2016-0063      URL
37572BROWSER-IE Microsoft Internet Explorer CDomPrototype type confusion attempt (more info ...)attempted-user  2016-0063      URL
37573BROWSER-IE Microsoft Internet Explorer CDomPrototype type confusion attempt (more info ...)attempted-user  2016-0063      URL
37574BROWSER-IE Microsoft Internet Explorer CDomPrototype type confusion attempt (more info ...)attempted-user  2016-0063      URL
37596BROWSER-IE Microsoft Internet Explorer CTextBlock use-after-free attempt (more info ...)attempted-user  2016-0071      URL
37597BROWSER-IE Microsoft Internet Explorer CTextBlock use-after-free attempt (more info ...)attempted-user  2016-0071      URL
37602BROWSER-IE Microsoft Internet Explorer IFRAME object constructor cross site scripting attempt (more info ...)web-application-attack  2016-0068      URL
37603BROWSER-IE Microsoft Internet Explorer IFRAME object constructor cross site scripting attempt (more info ...)web-application-attack  2016-0068      URL
37604BROWSER-IE Microsoft Internet Explorer StrCmpNICW string object use after free attempt (more info ...)attempted-user  2016-0067      URL
37605BROWSER-IE Microsoft Internet Explorer StrCmpNICW string object use after free attempt (more info ...)attempted-user  2016-0067      URL
37608BROWSER-IE Microsoft Internet Explorer CallInvoke type confusion attempt (more info ...)attempted-user  2016-0061      URL
37609BROWSER-IE Microsoft Internet Explorer CallInvoke type confusion attempt (more info ...)attempted-user  2016-0061      URL
37610BROWSER-IE Microsoft Internet Explorer CallInvoke type confusion attempt (more info ...)attempted-user  2016-0061      URL
37611BROWSER-IE Microsoft Internet Explorer CallInvoke type confusion attempt (more info ...)attempted-user  2016-0061      URL
37612BROWSER-IE Microsoft Internet Explorer CACPWrap object use-after-free attempt (more info ...)attempted-user  2016-0062      URL
37613BROWSER-IE Microsoft Internet Explorer CACPWrap object use-after-free attempt (more info ...)attempted-user  2016-0062      URL
37614BROWSER-IE Microsoft Internet Explorer CFGBitmap heap code execution attempt (more info ...)attempted-user  2016-0080      URL
37615BROWSER-IE Microsoft Internet Explorer CFGBitmap heap code execution attempt (more info ...)attempted-user  2016-0080      URL
37626BROWSER-FIREFOX Mozilla Firefox IDL fragment privilege escalation attempt (more info ...)attempted-user  2014-1510      URL
37633BROWSER-IE Microsoft Internet Explorer CTextElement use after free attempt (more info ...)attempted-user  2014-2782      URL
37634BROWSER-IE Microsoft Internet Explorer CTextElement use after free attempt (more info ...)attempted-user  2014-2782      URL
37664FILE-JAVA Oracle Java ServiceLoader exception handling exploit attempt (more info ...)attempted-user  2014-0457  66866    
37665FILE-JAVA Oracle Java ServiceLoader exception handling exploit attempt (more info ...)attempted-user  2014-0457  66866    
37802FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2013-2471  60659    URL
37804FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2014-4262  60659    URL
37805FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user  2014-4262  60659    URL
37810BROWSER-IE Microsoft Internet Explorer CDisplayPointer use after free attempt (more info ...)attempted-user  2013-3205      URL
37811BROWSER-IE Microsoft Internet Explorer CDisplayPointer use after free attempt (more info ...)attempted-user  2013-3205      URL
37818FILE-JAVA Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt (more info ...)attempted-user  2013-2470  60651    URL
37819FILE-JAVA Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt (more info ...)attempted-user  2013-2470  60651    URL
37820FILE-JAVA Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt (more info ...)attempted-user  2013-2470  60651    URL
37821FILE-JAVA Oracle Java sun.awt.image.ImagingLib.lookupByteBI memory corruption attempt (more info ...)attempted-user  2013-2470  60651    URL
37859SERVER-WEBAPP Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user  2020-14625      URL
37860SERVER-WEBAPP Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user  2017-15708      URL
37870BROWSER-IE Microsoft Internet Explorer tRNS overflow attempt (more info ...)attempted-user  2005-1211  13941  18490  URL
37918EXPLOIT-KIT Magnitude exploit kit Internet Explorer exploit attempt (more info ...)attempted-admin        
38015BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
38016BROWSER-IE Microsoft Internet Explorer DOM manipulation memory corruption attempt (more info ...)attempted-user  2012-1875  53847    URL
38065BROWSER-IE Microsoft Internet Explorer GETDISPID invalid pointer access attempt (more info ...)attempted-user  2016-0112      URL
38066BROWSER-IE Microsoft Internet Explorer GETDISPID invalid pointer access attempt (more info ...)attempted-user  2016-0112      URL
38067BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
38068BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
38069BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
38070BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
38079BROWSER-IE Microsoft Internet Explorer embedded media player use after free attempt (more info ...)attempted-user  2016-0098      URL
38080BROWSER-IE Microsoft Internet Explorer embedded media player use after free attempt (more info ...)attempted-user  2016-0098      URL
38081BROWSER-IE Microsoft Internet Explorer SetItem use after free attempt (more info ...)attempted-user  2016-0106      URL
38082BROWSER-IE Microsoft Internet Explorer SetItem use after free attempt (more info ...)attempted-user  2016-0106      URL
38085BROWSER-IE Microsoft Internet Explorer CTravelEntry use after free attempt (more info ...)attempted-user  2016-0113      URL
38086BROWSER-IE Microsoft Internet Explorer CTravelEntry use after free attempt (more info ...)attempted-user  2016-0113      URL
38088BROWSER-IE Microsoft Internet Explorer string type confusion remote code execution attempt (more info ...)attempted-user  2016-0105      URL
38089BROWSER-IE Microsoft Internet Explorer string type confusion remote code execution attempt (more info ...)attempted-user  2016-0105      URL
38090BROWSER-IE Microsoft Internet Explorer CSVGHelpers use-after-free attempt (more info ...)attempted-user  2016-0111      URL
38091BROWSER-IE Microsoft Internet Explorer CSVGHelpers use-after-free attempt (more info ...)attempted-user  2016-0111      URL
38094BROWSER-IE Microsoft Internet Explorer CTreePos remote code execution attempt (more info ...)attempted-user  2016-0102      URL
38095BROWSER-IE Microsoft Internet Explorer CTreePos remote code execution attempt (more info ...)attempted-user  2016-0102      URL
38096BROWSER-IE Microsoft Internet Explorer out of bound write access attempt (more info ...)attempted-admin  2016-0110      URL
38097BROWSER-IE Microsoft Internet Explorer out of bound write access attempt (more info ...)attempted-admin  2016-0110      URL
38098BROWSER-IE Microsoft Internet Explorer TableCellLayoutArray use-after-free attempt (more info ...)attempted-user  2016-0109      URL
38099BROWSER-IE Microsoft Internet Explorer TableCellLayoutArray use-after-free attempt (more info ...)attempted-user  2016-0109      URL
38102BROWSER-IE Microsoft Internet Explorer CEditEventSink navigate use after free attempt (more info ...)attempted-user  2015-6071  77445    URL
38103BROWSER-IE Microsoft Internet Explorer CEditEventSink navigate use after free attempt (more info ...)attempted-user  2015-6071  77445    URL
38108BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode use-after-free (more info ...)attempted-user  2016-0104      URL
38109BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode use-after-free (more info ...)attempted-user  2016-0104      URL
38112BROWSER-IE Microsoft Internet Explorer addRow out-of-bounds read attempt (more info ...)attempted-user  2016-3242      URL
38113BROWSER-IE Microsoft Internet Explorer addRow out-of-bounds read attempt (more info ...)attempted-user  2016-3242      URL
38117BROWSER-IE Microsoft Internet Explorer mshtml InsertRange out of bounds write access (more info ...)attempted-user  2016-0103      URL
38118BROWSER-IE Microsoft Internet Explorer mshtml InsertRange out of bounds write access (more info ...)attempted-user  2016-0103      URL
38122BROWSER-IE Microsoft Internet Explorer CInput sliderdata object use after free attempt (more info ...)attempted-user  2016-0114      URL
38123BROWSER-IE Microsoft Internet Explorer CInput sliderdata object use after free attempt (more info ...)attempted-user  2016-0114      URL
38276BROWSER-IE Microsoft Internet Explorer text transform use after free attempt (more info ...)attempted-user  2013-0087  58341    URL
38277BROWSER-IE Microsoft Internet Explorer text transform use after free attempt (more info ...)attempted-user  2013-0087  58341    URL
38278BROWSER-IE Microsoft Internet Explorer text transform use after free attempt (more info ...)attempted-user  2013-0087  58341    URL
38308BROWSER-IE Microsoft Internet Explorer VBScript engine use after free attempt (more info ...)attempted-user  2016-0002      URL
38309BROWSER-IE Microsoft Internet Explorer VBScript engine use after free attempt (more info ...)attempted-user  2016-0002      URL
38317FILE-OTHER Microsoft Edge Chakra JavaScript engine out of bounds read attempt (more info ...)attempted-user  2016-0024      URL
38318FILE-OTHER Microsoft Edge Chakra JavaScript engine out of bounds read attempt (more info ...)attempted-user  2016-0024      URL
38338FILE-JAVA Oracle Java Class Loader namespace sandbox bypass attempt (more info ...)attempted-user  2013-5838  63131    URL
38339FILE-JAVA Oracle Java Class Loader namespace sandbox bypass attempt (more info ...)attempted-user  2013-5838  63131    URL
38465BROWSER-IE Microsoft Internet Explorer InsertSanitizedTextEx use after free attempt (more info ...)attempted-admin  2016-0164      URL
38466BROWSER-IE Microsoft Internet Explorer InsertSanitizedTextEx use after free attempt (more info ...)attempted-admin  2016-0164      URL
38467BROWSER-IE Microsoft Internet Explorer 9 frameset use after free attempt (more info ...)attempted-user  2016-0159      URL
38468BROWSER-IE Microsoft Internet Explorer 9 frameset use after free attempt (more info ...)attempted-user  2016-0159      URL
38503BROWSER-IE Microsoft Internet Explorer CChildIterator media object use-after-free attempt (more info ...)attempted-user  2016-0166      URL
38504BROWSER-IE Microsoft Internet Explorer CChildIterator media object use-after-free attempt (more info ...)attempted-user  2016-0166      URL
38505BROWSER-IE Microsoft Internet Explorer CChildIterator media object use-after-free attempt (more info ...)attempted-user  2016-0166      URL
38506BROWSER-IE Microsoft Internet Explorer CChildIterator media object use-after-free attempt (more info ...)attempted-user  2016-0166      URL
38507BROWSER-IE Microsoft Internet Explorer ConvertStringFromUnicodeEx out of bounds write attempt (more info ...)attempted-user  2016-0154      URL
38508BROWSER-IE Microsoft Internet Explorer ConvertStringFromUnicodeEx out of bounds write attempt (more info ...)attempted-user  2016-0154      URL
38669BROWSER-IE Microsoft Internet Explorer onpropertychange use-after-free attempt (more info ...)attempted-user  2014-0322      
38670BROWSER-IE Microsoft Internet Explorer onpropertychange use-after-free attempt (more info ...)attempted-user  2014-0322      
38763BROWSER-IE Microsoft Internet Explorer mshtml.dll null pointer dereference attempt (more info ...)attempted-user  2016-0192      URL
38764BROWSER-IE Microsoft Internet Explorer mshtml.dll null pointer dereference attempt (more info ...)attempted-user  2016-0192      URL
38768BROWSER-IE Microsoft Internet Explorer CreateColorSpace vulnerability attempt (more info ...)attempted-user  2016-0168      URL
38769BROWSER-IE Microsoft Internet Explorer CreateColorSpace vulnerability attempt (more info ...)attempted-user  2016-0168      URL
38770BROWSER-IE Microsoft Internet Explorer CreateColorSpace vulnerability attempt (more info ...)attempted-user  2016-0168      URL
38771BROWSER-IE Microsoft Internet Explorer CreateColorSpace vulnerability attempt (more info ...)attempted-user  2016-0168      URL
38772BROWSER-IE Microsoft Internet Explorer EMF file integer overflow attempt (more info ...)attempted-user  2016-0169      URL
38773BROWSER-IE Microsoft Internet Explorer EMF file integer overflow attempt (more info ...)attempted-user  2016-0169      URL
38776BROWSER-IE Microsoft Internet Explorer uninitialized pointer attempt (more info ...)attempted-user  2016-0191      URL
38777BROWSER-IE Microsoft Internet Explorer uninitialized pointer attempt (more info ...)attempted-user  2016-0191      URL
38780OS-WINDOWS Microsoft Internet Explorer VerifyFile information disclosure attempt (more info ...)attempted-user  2016-0194      URL
38781OS-WINDOWS Microsoft Internet Explorer VerifyFile information disclosure attempt (more info ...)attempted-user  2016-0194      URL
38794FILE-PDF Adobe Reader XFA javascript use after free attempt (more info ...)attempted-user  2016-1073      URL
38795FILE-PDF Adobe Reader XFA javascript use after free attempt (more info ...)attempted-user  2016-1073      URL
38828BROWSER-IE Microsoft Internet Explorer BooleanProtoObj objects JSONStringifyArray use-after-free attempt (more info ...)attempted-user  2016-0187      URL
38829BROWSER-IE Microsoft Internet Explorer BooleanProtoObj objects JSONStringifyArray use-after-free attempt (more info ...)attempted-user  2016-0187      URL
38841BROWSER-IE Microsoft Internet Explorer VBScript toString redim array use after free attempt (more info ...)attempted-user  2016-0189      URL
38842BROWSER-IE Microsoft Internet Explorer VBScript toString redim array use after free attempt (more info ...)attempted-user  2016-0189      URL
38843FILE-PDF Adobe Reader javascript replace integer overflow attempt (more info ...)attempted-user  2016-1043      URL
38844FILE-PDF Adobe Reader javascript replace integer overflow attempt (more info ...)attempted-user  2016-1043      URL
38874FILE-FLASH Adobe Flash Player DeleteRangeTimelineOperation type confusion attempt (more info ...)attempted-user  2016-4224      URL
38875FILE-FLASH Adobe Flash Player DeleteRangeTimelineOperation type confusion attempt (more info ...)attempted-user  2016-4224      URL
38877FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1044      URL
38878FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1044      URL
38909FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1039      URL
38910FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1039      URL
38911FILE-PDF Adobe Reader DisablePermEnforcement JavaScript function use-after-free attempt (more info ...)attempted-user  2016-1084      URL
38912FILE-PDF Adobe Reader DisablePermEnforcement JavaScript function use-after-free attempt (more info ...)attempted-user  2016-1084      URL
38914FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1038      URL
38915FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1038      URL
38918FILE-PDF Adobe Reader createAVView JavaScript use-after-free attempt (more info ...)attempted-user  2016-1082      URL
38919FILE-PDF Adobe Reader createAVView JavaScript use-after-free attempt (more info ...)attempted-user  2016-1082      URL
38920FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1042      URL
38921FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1042      URL
38923FILE-PDF Adobe Reader compareDocuments JavaScript function use-after-free attempt (more info ...)attempted-user  2016-1085      URL
38924FILE-PDF Adobe Reader compareDocuments JavaScript function use-after-free attempt (more info ...)attempted-user  2016-1085      URL
38935FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1041      URL
38936FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin  2016-1041      URL
38943FILE-PDF Adobe Reader XFA javascript out of bound memory corruption attempt (more info ...)attempted-user  2016-1072      URL
38944FILE-PDF Adobe Reader XFA javascript out of bound memory corruption attempt (more info ...)attempted-user  2016-1072      URL
38991FILE-PDF Adobe Reader execAVDialog JavaScript function use-after-free attempt (more info ...)attempted-user  2016-1083      URL
38992FILE-PDF Adobe Reader execAVDialog JavaScript function use-after-free attempt (more info ...)attempted-user  2016-1083      URL
39161FILE-PDF Google Chrome PDFium jpeg2000 SIZ segment check failure heap buffer overflow attempt (more info ...)attempted-user  2016-1681      URL
39162FILE-PDF Google Chrome PDFium jpeg2000 SIZ segment check failure heap buffer overflow attempt (more info ...)attempted-user  2016-1681      URL
39170SERVER-WEBAPP Cisco Video Surveillance Operations Manager directory traversal attempt (more info ...)web-application-attack  2013-3429      URL
39171SERVER-WEBAPP Cisco Video Surveillance Operations Manager directory traversal attempt (more info ...)web-application-attack  2013-3429      URL
39172SERVER-WEBAPP Cisco Video Surveillance Operations Manager directory traversal attempt (more info ...)web-application-attack  2013-3429      URL
39201BROWSER-IE Microsoft Internet Explorer vbscript csession close use after free attempt (more info ...)attempted-user  2016-3205      
39202BROWSER-IE Microsoft Internet Explorer vbscript csession close use after free attempt (more info ...)attempted-user  2016-3205      
39207BROWSER-IE Microsoft Internet Explorer drag and drop API remote code execution attempt (more info ...)attempted-user  2016-3211      URL
39208BROWSER-IE Microsoft Internet Explorer drag and drop API remote code execution attempt (more info ...)attempted-user  2016-3211      URL
39211BROWSER-IE Microsoft Internet Explorer VBScript out of bounds memory access remote code execution attempt (more info ...)attempted-user  2016-3206      URL
39212BROWSER-IE Microsoft Internet Explorer VBScript out of bounds memory access remote code execution attempt (more info ...)attempted-user  2016-3206      URL
39230BROWSER-IE Microsoft Internet Explorer CSS link element use-after-free attempt (more info ...)attempted-user  2016-0200      URL
39231BROWSER-IE Microsoft Internet Explorer CSS link element use-after-free attempt (more info ...)attempted-user  2016-0200      URL
39234BROWSER-IE Microsoft Internet Explorer tagged integer type confusion attempt (more info ...)attempted-user  2016-0199      URL
39235BROWSER-IE Microsoft Internet Explorer tagged integer type confusion attempt (more info ...)attempted-user  2016-0199      URL
39236BROWSER-IE Microsoft Internet Explorer scripting engine buffer overflow attempt (more info ...)attempted-user  2016-3207      URL
39237BROWSER-IE Microsoft Internet Explorer scripting engine buffer overflow attempt (more info ...)attempted-user  2016-3207      URL
39242BROWSER-IE Microsoft Internet Explorer Typed Array use after free attempt (more info ...)attempted-user  2016-3210      URL
39243BROWSER-IE Microsoft Internet Explorer Typed Array use after free attempt (more info ...)attempted-user  2016-3210      URL
39491BROWSER-IE Microsoft Internet Explorer Dxtrans table element use after free attempt (more info ...)attempted-user  2016-3240      URL
39492BROWSER-IE Microsoft Internet Explorer Dxtrans table element use after free attempt (more info ...)attempted-user  2016-3240      URL
39499BROWSER-IE Microsoft Internet Explorer mshtml.dll invalid resize use after free attempt (more info ...)attempted-user  2016-3243      URL
39500BROWSER-IE Microsoft Internet Explorer mshtml.dll invalid resize use after free attempt (more info ...)attempted-user  2016-3243      URL
39505BROWSER-IE Microsoft Internet Explorer Edge text node table-cell use after free attempt (more info ...)attempted-user  2016-3244      URL
39514BROWSER-IE Microsoft Internet Explorer textTransform out-of-bounds memory access attempt (more info ...)attempted-user  2016-3261      URL
39515BROWSER-IE Microsoft Internet Explorer textTransform out-of-bounds memory access attempt (more info ...)attempted-user  2016-3261      URL
39680BROWSER-IE Microsoft Internet Explorer VBScript toString redim array use after free attempt (more info ...)attempted-user  2016-0189      URL
39681BROWSER-IE Microsoft Internet Explorer VBScript toString redim array use after free attempt (more info ...)attempted-user  2016-0189      URL
39763BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
39764BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
39810BROWSER-IE Microsoft Internet Explorer iertutil.dll long UNC redirect out of bounds read attempt (more info ...)attempted-user  2016-3327      URL
39811BROWSER-IE Microsoft Internet Explorer iertutil.dll long UNC redirect out of bounds read attempt (more info ...)attempted-user  2016-3327      URL
39812BROWSER-IE Microsoft Internet Explorer page layout use after free attempt (more info ...)attempted-user  2016-3288      URL
39813BROWSER-IE Microsoft Internet Explorer page layout use after free attempt (more info ...)attempted-user  2016-3288      URL
39818OS-WINDOWS Microsoft Windows operating system win32kfull heap corruption attempt (more info ...)attempted-admin  2016-3308      URL
39819OS-WINDOWS Microsoft Windows operating system win32kfull heap corruption attempt (more info ...)attempted-admin  2016-3308      URL
39827BROWSER-IE Microsoft Internet Explorer CStr internal string use-after-free attempt (more info ...)attempted-user  2016-3326      URL
39828BROWSER-IE Microsoft Internet Explorer mshtml.dll cached object use after free attempt (more info ...)attempted-user  2016-3322      URL
39829BROWSER-IE Microsoft Internet Explorer mshtml.dll cached object use after free attempt (more info ...)attempted-user  2016-3322      URL
39833BROWSER-IE Microsoft Internet Explorer InsertSelectDropdown use after free attempt (more info ...)attempted-user  2016-3289      URL
39834BROWSER-IE Microsoft Internet Explorer InsertSelectDropdown use after free attempt (more info ...)attempted-user  2016-3289      URL
39839BROWSER-IE Microsoft Windows Internet Explorer MSHTML.dll type confusion attempt (more info ...)attempted-user  2016-3290      URL
39840BROWSER-IE Microsoft Windows Internet Explorer MSHTML.dll type confusion attempt (more info ...)attempted-user  2016-3290      URL
40077BROWSER-IE Microsoft Internet Explorer protected mode sandbox escape attempt (more info ...)attempted-admin  2016-3292      URL
40078BROWSER-IE Microsoft Internet Explorer protected mode sandbox escape attempt (more info ...)attempted-admin  2016-3292      URL
40108BROWSER-IE Microsoft Internet Explorer font element out of bounds read attempt (more info ...)attempted-recon  2016-3297      URL
40109BROWSER-IE Microsoft Internet Explorer font element out of bounds read attempt (more info ...)attempted-recon  2016-3297      URL
40149BROWSER-IE Microsoft Internet Explorer MSXML IDispatch use after free attempt (more info ...)attempted-user        
40150BROWSER-IE Microsoft Internet Explorer MSXML IDispatch use after free attempt (more info ...)attempted-user        
40312BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
40363BROWSER-FIREFOX Mozilla Firefox CSP report-uri arbitrary file write attempt (more info ...)attempted-user  2016-1954      URL
40364BROWSER-IE Microsoft Internet Explorer loadXML parseError.errorCode information disclosure attempt (more info ...)attempted-user  2017-0022      URL
40365BROWSER-IE Microsoft Internet Explorer loadXML parseError.errorCode information disclosure attempt (more info ...)attempted-user  2017-0022      URL
40370BROWSER-IE Microsoft Edge spread operator memory corruption attempt (more info ...)attempted-user  2016-3386      URL
40371BROWSER-IE Microsoft Edge spread operator memory corruption attempt (more info ...)attempted-user  2016-3386      URL
40378BROWSER-IE Microsoft Internet Explorer iframe type confusion attempt (more info ...)attempted-user  2016-3383      URL
40379BROWSER-IE Microsoft Internet Explorer iframe type confusion attempt (more info ...)attempted-user  2016-3383      URL
40385BROWSER-IE Microsoft Internet Explorer vbscript variable type confusion attempt (more info ...)attempted-user  2016-3385      URL
40386BROWSER-IE Microsoft Internet Explorer vbscript variable type confusion attempt (more info ...)attempted-user  2016-3385      URL
40420BROWSER-IE Microsoft Internet Explorer readyState property information disclosure attempt (more info ...)attempted-user  2016-3267      URL
40421BROWSER-IE Microsoft Internet Explorer readyState property information disclosure attempt (more info ...)attempted-user  2016-3267      URL
40546FILE-PDF Adobe Reader JavaScript API privileged function bypass attempt (more info ...)attempted-user  2016-6958      URL
40547FILE-PDF Adobe Reader JavaScript API privileged function bypass attempt (more info ...)attempted-user  2016-6958      URL
40577FILE-PDF Adobe Reader XFA remerge JavaScript use after free attempt (more info ...)attempted-user  2016-6988      URL
40578FILE-PDF Adobe Reader XFA remerge JavaScript use after free attempt (more info ...)attempted-user  2016-6988      URL
40602FILE-PDF Adobe Reader XFA exclGroup JavaScript out of bounds memory access attempt (more info ...)attempted-user  2016-6942      URL
40603FILE-PDF Adobe Reader XFA exclGroup JavaScript out of bounds memory access attempt (more info ...)attempted-user  2016-6942      URL
40641FILE-PDF Adobe Reader XFA relayoutPageArea JavaScript out of bounds memory access attempt (more info ...)attempted-user  2016-6947      URL
40642FILE-PDF Adobe Reader XFA relayoutPageArea JavaScript out of bounds memory access attempt (more info ...)attempted-user  2016-6947      URL
40653BROWSER-IE Microsoft Internet Explorer msSaveBlob use after free attempt (more info ...)attempted-admin  2016-7196      URL
40654BROWSER-IE Microsoft Internet Explorer msSaveBlob use after free attempt (more info ...)attempted-admin  2016-7196      URL
40655BROWSER-IE Microsoft Internet Explorer Chakra.dll Array.filter type confusion attempt (more info ...)attempted-user  2016-7200      URL
40656BROWSER-IE Microsoft Internet Explorer Chakra.dll Array.filter type confusion attempt (more info ...)attempted-user  2016-7200      URL
40703BROWSER-IE Microsoft Internet Explorer UIAnimaation.dll use after free attempt (more info ...)attempted-user  2016-7205      URL
40704BROWSER-IE Microsoft Internet Explorer UIAnimaation.dll use after free attempt (more info ...)attempted-user  2016-7205      URL
40707FILE-PDF Adobe Reader JavaScript use after free attempt (more info ...)attempted-user  2016-6944      URL
40708FILE-PDF Adobe Reader JavaScript use after free attempt (more info ...)attempted-user  2016-6944      URL
40721BROWSER-IE Microsoft Internet Explorer print preview information disclosure attempt (more info ...)attempted-recon  2016-7227      URL
40722BROWSER-IE Microsoft Internet Explorer print preview information disclosure attempt (more info ...)attempted-recon  2016-7227      URL
40731BROWSER-IE Microsoft Internet Explorer CDeskBand use-after-free attempt (more info ...)attempted-user  2015-2548      URL
40732BROWSER-IE Microsoft Internet Explorer CDeskBand use-after-free attempt (more info ...)attempted-user  2015-2548      URL
40787BROWSER-IE Microsoft Internet Explorer iertutil.dll long UNC redirect out of bounds read attempt (more info ...)attempted-user  2016-3327      URL
40788BROWSER-IE Microsoft Internet Explorer iertutil.dll long UNC redirect out of bounds read attempt (more info ...)attempted-user  2016-3327      URL
40825FILE-PDF Adobe Reader JavaScript recursive calls memory corruption attempt (more info ...)attempted-user  2016-6970      URL
40826FILE-PDF Adobe Reader JavaScript recursive calls memory corruption attempt (more info ...)attempted-user  2016-6970      URL
40888BROWSER-FIREFOX Mozilla Firefox ESR NotifyTimeChange use after free attempt (more info ...)attempted-user  2016-9079      URL
40896BROWSER-FIREFOX Mozilla Firefox ESR NotifyTimeChange use after free attempt (more info ...)attempted-user  2016-9079      URL
40971BROWSER-IE Microsoft Edge spread operator memory corruption attempt (more info ...)attempted-user  2016-7297      URL
40972BROWSER-IE Microsoft Edge spread operator memory corruption attempt (more info ...)attempted-user  2016-7297      URL
40973BROWSER-IE Microsoft Edge spread operator memory corruption attempt (more info ...)attempted-user  2016-7296      URL
40974BROWSER-IE Microsoft Edge spread operator memory corruption attempt (more info ...)attempted-user  2016-7296      URL
40982FILE-OTHER Microsoft Internet Explorer malformed ico integer overflow attempt (more info ...)attempted-admin  2016-7272      URL
40983FILE-OTHER Microsoft Internet Explorer malformed ico integer overflow attempt (more info ...)attempted-admin  2016-7272      URL
40986BROWSER-IE Microsoft Internet Explorer title integer overflow attempt (more info ...)attempted-user  2016-7279      URL
40987BROWSER-IE Microsoft Internet Explorer title integer overflow attempt (more info ...)attempted-user  2016-7279      URL
40988BROWSER-IE Microsoft Internet Explorer out of bounds read attempt (more info ...)attempted-user  2016-7283      URL
40989BROWSER-IE Microsoft Internet Explorer out of bounds read attempt (more info ...)attempted-user  2016-7283      URL
40992BROWSER-IE Microsoft Internet Explorer information disclosure attempt (more info ...)attempted-recon  2016-7284      URL
40993BROWSER-IE Microsoft Internet Explorer information disclosure attempt (more info ...)attempted-recon  2016-7284      URL
41086SERVER-WEBAPP Oracle Opera Property Management System ProcessInfo command injection attempt (more info ...)web-application-attack  2016-5563  93768    URL
41087SERVER-WEBAPP Oracle Opera Property Management System ProcessInfo command injection attempt (more info ...)web-application-attack  2016-5563  93768    URL
41150FILE-PDF Adobe Acrobat Reader JavaScript navigation pane use after free attempt (more info ...)attempted-user  2017-2957      URL
41151FILE-PDF Adobe Acrobat Reader JavaScript navigation pane use after free attempt (more info ...)attempted-user  2017-2957      URL
41152FILE-PDF Adobe Acrobat Reader Forms Data Format embedded javascript attempt (more info ...)attempted-user  2017-2947      URL
41153FILE-PDF Adobe Acrobat Reader Forms Data Format embedded javascript attempt (more info ...)attempted-user  2017-2947      URL
41405BROWSER-IE Microsoft Internet Explorer object property change use after free attempt (more info ...)attempted-user  2015-0048      URL
41406BROWSER-IE Microsoft Internet Explorer object property change use after free attempt (more info ...)attempted-user  2015-0048      URL
41422BROWSER-PLUGINS Mozilla Firefox generatecrmfrequest policy function call access attempt (more info ...)attempted-user  2013-1710  61900    URL
41423BROWSER-PLUGINS Mozilla Firefox generatecrmfrequest policy function call access attempt (more info ...)attempted-user  2013-1710  61900    URL
41450BROWSER-IE Microsoft Internet Explorer CElement object use after free attempt (more info ...)attempted-user  2013-3846      URL
41451BROWSER-IE Microsoft Internet Explorer CElement object use after free attempt (more info ...)attempted-user  2013-3846      URL
41474BROWSER-IE Microsoft Internet Explorer 7 CTreeNode object remote code execution attempt (more info ...)attempted-user  2014-6366      URL
41475BROWSER-IE Microsoft Internet Explorer 7 CTreeNode object remote code execution attempt (more info ...)attempted-user  2014-6366      URL
41555BROWSER-IE Microsoft Internet Explorer use asm memory corruption attempt (more info ...)attempted-user  2016-0010      URL
41556BROWSER-IE Microsoft Internet Explorer use asm memory corruption attempt (more info ...)attempted-user  2016-0010      URL
41561BROWSER-IE Microsoft Internet Explorer array proto chain manipulation memory corruption attempt (more info ...)attempted-user  2017-0032      URL
41562BROWSER-IE Microsoft Internet Explorer array proto chain manipulation memory corruption attempt (more info ...)attempted-user  2017-0032      URL
41583BROWSER-IE Microsoft Internet Explorer DOMAttrModified event use after free attempt (more info ...)attempted-user  2017-0009      URL
41584BROWSER-IE Microsoft Internet Explorer DOMAttrModified event use after free attempt (more info ...)attempted-user  2017-0009      URL
41585BROWSER-IE Microsoft Internet Explorer mutated scope with generator memory corruption attempt (more info ...)attempted-user  2017-0049      URL
41586BROWSER-IE Microsoft Internet Explorer mutated scope with generator memory corruption attempt (more info ...)attempted-user  2017-0049      URL
41587BROWSER-IE Microsoft Internet Explorer Array out of bounds memory corruption (more info ...)attempted-user  2017-0040      URL
41588BROWSER-IE Microsoft Internet Explorer Array out of bounds memory corruption (more info ...)attempted-user  2017-0040      URL
41589BROWSER-IE Microsoft Internet Explorer CHtmlTab use after free attempt (more info ...)attempted-user  2017-0018      URL
41590BROWSER-IE Microsoft Internet Explorer CHtmlTab use after free attempt (more info ...)attempted-user  2017-0018      URL
41599BROWSER-IE Microsoft Internet Explorer CPeerHolder use after free attempt (more info ...)attempted-user  2015-0022      URL
41600BROWSER-IE Microsoft Internet Explorer CPeerHolder use after free attempt (more info ...)attempted-user  2015-0022      URL
41718BROWSER-IE Microsoft Internet Explorer malformed iframe buffer overflow attempt (more info ...)attempted-user  2004-1050  11515    
41719BROWSER-IE Microsoft Internet Explorer malformed iframe buffer overflow attempt (more info ...)attempted-user  2004-1050  11515    
41720BROWSER-IE Microsoft Internet Explorer malformed iframe buffer overflow attempt (more info ...)attempted-user  2004-1050  11515    
41745FILE-MULTIMEDIA Chrome Pepper Flash Player SampleCount heap overflow attempt (more info ...)attempted-user  2017-2992      URL
41746FILE-MULTIMEDIA Chrome Pepper Flash Player SampleCount heap overflow attempt (more info ...)attempted-user  2017-2992      URL
41797BROWSER-IE Microsoft Internet Explorer loadXML parseError.errorCode information disclosure attempt (more info ...)attempted-user  2017-0022      URL
41798BROWSER-IE Microsoft Internet Explorer loadXML parseError.errorCode information disclosure attempt (more info ...)attempted-user  2017-0022      URL
41911BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (more info ...)attempted-user  2015-1747      URL
41912BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (more info ...)attempted-user  2015-1747      URL
41954BROWSER-IE Microsoft Internet Explorer textarea type confusion attempt (more info ...)attempted-user  2017-8652      URL
41955BROWSER-IE Microsoft Internet Explorer textarea type confusion attempt (more info ...)attempted-user  2017-8652      URL
41956BROWSER-IE Microsoft Internet Explorer arguments type confusion attempt (more info ...)attempted-user  2017-0130      URL
41957BROWSER-IE Microsoft Internet Explorer arguments type confusion attempt (more info ...)attempted-user  2017-0130      URL
42152BROWSER-IE Microsoft Edge JavaScript string object type confusion attempt (more info ...)attempted-user  2017-0201      
42153BROWSER-IE Microsoft Edge JavaScript string object type confusion attempt (more info ...)attempted-user  2017-0201      
42156BROWSER-IE Microsoft Internet Explorer recordset use after free attempt (more info ...)attempted-user  2017-0158      
42157BROWSER-IE Microsoft Internet Explorer recordset use after free attempt (more info ...)attempted-user  2017-0158      
42165BROWSER-IE Microsoft Internet Explorer type confusion vulnerability attempt (more info ...)attempted-user  2017-0202      
42166BROWSER-IE Microsoft Internet Explorer type confusion vulnerability attempt (more info ...)attempted-user  2017-0202      
42175FILE-PDF Adobe Reader JavaScript API documentToStream use after free attempt (more info ...)attempted-user  2017-3057      URL
42176FILE-PDF Adobe Reader JavaScript API documentToStream use after free attempt (more info ...)attempted-user  2017-3057      URL
42201BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
42202FILE-PDF Adobe Reader JavaScript string from stream memory corruption attempt (more info ...)attempted-user  2017-3056      URL
42203FILE-PDF Adobe Reader JavaScript string from stream memory corruption attempt (more info ...)attempted-user  2017-3056      URL
42204BROWSER-IE Microsoft Internet Explorer htmlFile ActiveX control universal XSS attempt (more info ...)attempted-user  2017-0210      
42205BROWSER-IE Microsoft Internet Explorer htmlFile ActiveX control universal XSS attempt (more info ...)attempted-user  2017-0210      
42414FILE-PDF Adobe PDF JavaScript engine use after free memory corruption attempt (more info ...)attempted-user  2017-3047      URL
42415FILE-PDF Adobe PDF JavaScript engine use after free memory corruption attempt (more info ...)attempted-user  2017-3047      URL
42416BROWSER-IE Microsoft Internet Explorer IE11 memory corruption attempt (more info ...)attempted-user  2015-1752      URL
42417BROWSER-IE Microsoft Internet Explorer IE8 mode menu tag out-of-bounds access attempt (more info ...)attempted-user  2015-1752      URL
42932FILE-FLASH Adobe Flash Player javascript decompressor use after free attempt (more info ...)attempted-user  2017-3037      URL
42933FILE-FLASH Adobe Flash Player javascript decompressor use after free attempt (more info ...)attempted-user  2017-3037      URL
43007SERVER-OTHER HP Operations Orchestration unauthorized serialized object attempt (more info ...)attempted-user  2016-8519      URL
43056OS-WINDOWS Microsoft Windows MsMpEng JavaScript garbage collection use after free attempt (more info ...)attempted-admin  2017-8541      URL
43057OS-WINDOWS Microsoft Windows MsMpEng JavaScript garbage collection use after free attempt (more info ...)attempted-admin  2017-8541      URL
43117BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin  2016-5182      
43118BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin  2016-5182      
43155BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2017-8547      
43156BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2017-8547      
43337BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
43338BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2013-3163      URL
43346BROWSER-FIREFOX Mozilla Firefox domFuzzLite3 table use after free attempt (more info ...)attempted-admin  2017-5404      
43347BROWSER-FIREFOX Mozilla Firefox domFuzzLite3 table use after free attempt (more info ...)attempted-admin  2017-5404      
43497BROWSER-IE Microsoft Internet Explorer EPM brokercreatefile file access bypass attempt (more info ...)policy-violation  2017-3080      URL
43498BROWSER-IE Microsoft Internet Explorer EPM brokercreatefile file access bypass attempt (more info ...)policy-violation  2017-3080      URL
43521BROWSER-IE Microsoft Internet Explorer 11 type confusion vulnerability attempt (more info ...)attempted-user  2017-8594      
43522BROWSER-IE Microsoft Internet Explorer 11 type confusion vulnerability attempt (more info ...)attempted-user  2017-8594      
43758BROWSER-IE Microsoft Internet Explorer CTravelEntry use after free attempt (more info ...)attempted-user  2016-0113      URL
43759BROWSER-IE Microsoft Internet Explorer CTravelEntry use after free attempt (more info ...)attempted-user  2016-0113      URL
43779BROWSER-FIREFOX Mozilla multiple products SharedWorker MessagePort memory corruption attempt (more info ...)attempted-user  2014-1548  68818    URL
43961FILE-PDF Adobe Acrobat Reader Forms Data Format embedded javascript attempt (more info ...)attempted-user  2017-11229      URL
43962FILE-PDF Adobe Acrobat Reader Forms Data Format embedded javascript attempt (more info ...)attempted-user  2017-11229      URL
44098FILE-PDF Multiple products PDF JavaScript launchURL command injection and remote code execution attempt (more info ...)attempted-user  2017-7442      
44315SERVER-WEBAPP Java XML deserialization remote code execution attempt (more info ...)attempted-admin  2017-9805      URL
44342BROWSER-IE Internet Explorer WeakMap Freeze memory corruption attempt (more info ...)attempted-user  2017-8750      URL
44343BROWSER-IE Internet Explorer WeakMap Freeze memory corruption attempt (more info ...)attempted-user  2017-8750      URL
44350BROWSER-IE Microsoft Internet Explorer object use after free attempt (more info ...)attempted-user  2017-8749      URL
44356BROWSER-IE Microsoft Internet Explorer CSS padding property memory corruption attempt (more info ...)attempted-user  2017-8747      URL
44357BROWSER-IE Microsoft Internet Explorer CSS padding property memory corruption attempt (more info ...)attempted-user  2017-8747      URL
44510BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)attempted-user  2017-11810      URL
44511BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)attempted-user  2017-11810      URL
44512BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2017-11822      URL
44513BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2017-11822      URL
44526BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2017-8727      URL
44527BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2017-8727      URL
44530SERVER-WEBAPP HP Intelligent Management Center DeviceService Java expression language injection attempt (more info ...)attempted-admin  2017-12491  100367    URL
44534SERVER-WEBAPP HP IMC wmiConfigContent Java expression language injection attempt (more info ...)attempted-admin  2017-12526  100367    URL
44535SERVER-WEBAPP HP IMC wmiConfigContent Java expression language injection attempt (more info ...)attempted-admin  2017-12526  100367    URL
44536SERVER-WEBAPP HP IMC wmiConfigContent Java expression language injection attempt (more info ...)attempted-admin  2017-12526  100367    URL
44607SERVER-WEBAPP HP IMC userSelectPagingContent Java expression language injection attempt (more info ...)attempted-admin  2017-12521  100367    URL
44608SERVER-WEBAPP HP IMC userSelectPagingContent Java expression language injection attempt (more info ...)attempted-admin  2017-12521  100367    URL
44609SERVER-WEBAPP HP IMC userSelectPagingContent Java expression language injection attempt (more info ...)attempted-admin  2017-12521  100367    URL
44642SERVER-WEBAPP HP Intelligent Management Center getSelInsBean Java expression language injection attempt (more info ...)attempted-admin  2017-12490  100367    URL
44829BROWSER-IE Microsoft Internet Explorer array memory corruption attempt (more info ...)attempted-user  2017-11856      URL
44830BROWSER-IE Microsoft Internet Explorer array memory corruption attempt (more info ...)attempted-user  2017-11856      URL
44856FILE-PDF Adobe Acrobat Reader XI JavaScript annotation use after free attempt (more info ...)attempted-user  2017-16393      URL
44857FILE-PDF Adobe Acrobat Reader XI JavaScript annotation use after free attempt (more info ...)attempted-user  2017-16393      URL
44900FILE-PDF Adobe Reader PDF embedded javascript events use after free attempt (more info ...)attempted-user  2017-16389      URL
44901FILE-PDF Adobe Reader PDF embedded javascript events use after free attempt (more info ...)attempted-user  2017-16389      URL
44955FILE-PDF Adobe Acrobat Reader JavaScript infinite recursion heap overflow attempt (more info ...)attempted-user  2017-16419      URL
44956FILE-PDF Adobe Acrobat Reader JavaScript infinite recursion heap overflow attempt (more info ...)attempted-user  2017-16419      URL
44978BROWSER-FIREFOX Mozilla Firefox browser engine memory corruption attempt (more info ...)attempted-user  2009-3382  36866    URL
45121BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2018-8297      URL
45122BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-user  2018-8297      URL
45138BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)attempted-user  2017-11890      URL
45139BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)attempted-user  2017-11890      URL
45144BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)attempted-user  2017-11901      URL
45145BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)attempted-user  2017-11901      URL
45146BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)misc-activity  2017-11903      URL
45147BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)misc-activity  2017-11903      URL
45148BROWSER-IE Microsoft Internet Explorer Array out of bounds write attempt (more info ...)attempted-user  2017-11907      URL
45149BROWSER-IE Microsoft Internet Explorer Array out of bounds write attempt (more info ...)attempted-user  2017-11907      URL
45155BROWSER-IE Microsoft Internet Explorer out of bounds read attempt (more info ...)attempted-user  2017-11911      URL
45156BROWSER-IE Microsoft Internet Explorer out of bounds read attempt (more info ...)attempted-user  2017-11911      URL
45171BROWSER-FIREFOX Mozilla Firefox buffer overflow attempt (more info ...)attempted-user  2004-0902      URL
45172BROWSER-FIREFOX Mozilla Firefox buffer overflow attempt (more info ...)attempted-user  2004-0902      URL
45177BROWSER-FIREFOX Mozilla Firefox SOAPParameter integer overflow attempt (more info ...)attempted-user  2004-0722      URL
45178BROWSER-FIREFOX Mozilla Firefox SOAPParameter integer overflow attempt (more info ...)attempted-user  2004-0722      URL
45179BROWSER-FIREFOX Mozilla Firefox SOAPParameter integer overflow attempt (more info ...)attempted-user  2004-0722      URL
45180BROWSER-FIREFOX Mozilla Firefox SOAPParameter integer overflow attempt (more info ...)attempted-user  2004-0722      URL
45181BROWSER-FIREFOX Mozilla Firefox SOAPParameter integer overflow attempt (more info ...)attempted-user  2004-0722      URL
45182BROWSER-FIREFOX Mozilla Firefox SOAPParameter integer overflow attempt (more info ...)attempted-user  2004-0722      URL
45183BROWSER-FIREFOX Mozilla Firefox SOAPParameter integer overflow attempt (more info ...)attempted-user  2004-0722      URL
45184BROWSER-FIREFOX Mozilla Firefox SOAPParameter integer overflow attempt (more info ...)attempted-user  2004-0722      URL
45212BROWSER-IE Microsoft Internet Explorer out of bounds read attempt (more info ...)attempted-user  2016-7283      URL
45213BROWSER-IE Microsoft Internet Explorer out of bounds read attempt (more info ...)attempted-user  2016-7283      URL
45267POLICY-OTHER CoinHive Miner Javascript library download detected (more info ...)policy-violation        URL
45673BROWSER-IE Microsoft Internet Explorer localeCompare use after free attempt (more info ...)attempted-user  2018-0866      URL
45674BROWSER-IE Microsoft Internet Explorer localeCompare use after free attempt (more info ...)attempted-user  2018-0866      URL
45677SERVER-WEBAPP HP IMC mibBrowser arbitrary Java object deserialization attempt (more info ...)attempted-admin  2017-12556  101152    URL
45695FILE-PDF Adobe Acrobat Reader JavaScript XFA engine use after free attempt (more info ...)attempted-user  2018-4913      URL
45696FILE-PDF Adobe Acrobat Reader JavaScript XFA engine use after free attempt (more info ...)attempted-user  2018-4913      URL
45774SERVER-WEBAPP HP IMC operatorGroupSelectContent Java expression language injection attempt (more info ...)attempted-admin  2017-12524  100367    URL
45775SERVER-WEBAPP HP IMC operatorGroupSelectContent Java expression language injection attempt (more info ...)attempted-admin  2017-12524  100367    URL
45790SERVER-WEBAPP Jenkins Java SignedObject deserialization command execution attempt (more info ...)attempted-admin  2017-1000353      URL
45805SERVER-WEBAPP HP IMC guiDataDetail Java expression language injection attempt (more info ...)attempted-admin  2017-12523  100367    URL
45806SERVER-WEBAPP HP IMC guiDataDetail Java expression language injection attempt (more info ...)attempted-admin  2017-12523  100367    URL
45870SERVER-WEBAPP Cisco ACS unsafe Java object deserialization attempt (more info ...)attempted-admin  2018-0147      URL
45877BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)attempted-user  2018-8353      URL
45878BROWSER-IE Microsoft Internet Explorer scripting engine memory corruption attempt (more info ...)attempted-user  2018-8353      URL
45887BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)misc-activity  2018-0889      URL
45888BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)misc-activity  2018-0889      URL
45953SERVER-WEBAPP HP IMC mediaForAction Java expression language injection attempt (more info ...)attempted-admin  2017-12494  100367    URL
45954SERVER-WEBAPP HP IMC mediaForAction Java expression language injection attempt (more info ...)attempted-admin  2017-12494  100367    URL
45957SERVER-WEBAPP HP IMC iccSelectDeviceSeries Java expression language injection attempt (more info ...)attempted-admin  2017-12510  100367    URL
45958SERVER-WEBAPP HP IMC iccSelectDeviceSeries Java expression language injection attempt (more info ...)attempted-admin  2017-12510  100367    URL
46198BROWSER-IE Microsoft Internet Explorer Vbscript String out of bounds write (more info ...)attempted-user  2018-0988      URL
46199BROWSER-IE Microsoft Internet Explorer Vbscript String out of bounds write (more info ...)attempted-user  2018-0988      URL
46204BROWSER-IE Microsoft Internet Explorer array use after free attempt (more info ...)attempted-user  2018-1018      URL
46205BROWSER-IE Microsoft Internet Explorer array use after free attempt (more info ...)attempted-user  2018-1018      URL
46220BROWSER-IE Microsoft Internet Explorer object use after free attempt (more info ...)attempted-user  2018-0997      URL
46221BROWSER-IE Microsoft Internet Explorer object use after free attempt (more info ...)attempted-user  2018-0997      URL
46228BROWSER-IE Microsoft Internet Explorer javascript memory corruption attempt (more info ...)attempted-user  2018-1001      URL
46229BROWSER-IE Microsoft Internet Explorer JavaScript memory corruption attempt (more info ...)attempted-user  2018-1001      URL
46243BROWSER-IE Microsoft Internet Explorer embedSWF use after free exploit attempt (more info ...)attempted-user  2018-0870      URL
46244BROWSER-IE Microsoft Internet Explorer embedSWF use after free exploit attempt (more info ...)attempted-user  2018-0870      URL
46245BROWSER-IE Microsoft Internet Explorer embedSWF use after free exploit attempt (more info ...)attempted-user  2018-0870      URL
46246BROWSER-IE Microsoft Internet Explorer embedSWF use after free exploit attempt (more info ...)attempted-user  2018-0870      URL
46384BROWSER-IE Internet Explorer URL file remote code execution attempt detected (more info ...)attempted-user  2016-3353      URL
46385BROWSER-IE Internet Explorer URL file remote code execution attempt detected (more info ...)attempted-user  2016-3353      URL
46414PUA-OTHER Mineralt JavaScript cryptocurrency mining attempt (more info ...)misc-attack        URL
46415PUA-OTHER obfuscated cryptomining javascript download attempt (more info ...)misc-attack        URL
46549BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-admin  2019-1390      
46554BROWSER-IE Microsoft Internet Explorer Regexp use after free attempt (more info ...)attempted-user  2019-0666      URL
46555BROWSER-IE Microsoft Internet Explorer Regexp use after free attempt (more info ...)attempted-user  2019-0666      URL
46594BROWSER-IE Microsoft Internet Explorer prototype type confusion attempt (more info ...)attempted-admin  2018-8122      URL
46595BROWSER-IE Microsoft Internet Explorer prototype type confusion attempt (more info ...)attempted-admin  2018-8122      URL
46653FILE-PDF Adobe Acrobat Reader JavaScript data structure use after free attempt (more info ...)attempted-user  2018-4983      URL
46654FILE-PDF Adobe Acrobat Reader JavaScript data structure use after free attempt (more info ...)attempted-user  2018-4983      URL
46657FILE-PDF Adobe Acrobat Reader JavaScript Engine annotations use after free attempt (more info ...)attempted-user  2018-4958      URL
46658FILE-PDF Adobe Acrobat Reader JavaScript Engine annotations use after free attempt (more info ...)attempted-user  2018-4958      URL
46721FILE-PDF Adobe Acrobat Reader JavaScript annotation use after free attempt (more info ...)attempted-user  2018-4961      URL
46722FILE-PDF Adobe Acrobat Reader JavaScript annotation use after free attempt (more info ...)attempted-user  2018-4961      URL
46745BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-admin        
46746BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-admin        
46912BROWSER-FIREFOX Mozilla multiple products JavaScript string replace buffer overflow attempt (more info ...)attempted-user  2009-3075  36343    
46913BROWSER-FIREFOX Mozilla multiple products JavaScript string replace buffer overflow attempt (more info ...)attempted-user  2009-3075  36343    
46937INDICATOR-SHELLCODE ysoserial Java object deserialization exploit attempt (more info ...)shellcode-detect  2020-36239      
46944BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2018-8249      URL
46945BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2018-8249      URL
46951BROWSER-IE Microsoft Internet Explorer 11 JScript use-after-free attempt (more info ...)attempted-user  2018-8267      URL
46952BROWSER-IE Microsoft Internet Explorer 11 JScript use-after-free attempt (more info ...)attempted-user  2018-8267      URL
47091BROWSER-IE Microsoft Internet Explorer crafted UNC path sandbox escape attempt (more info ...)attempted-user  2018-0949      URL
47092BROWSER-IE Microsoft Internet Explorer crafted UNC path sandbox escape attempt (more info ...)attempted-user  2018-0949      URL
47151BROWSER-IE Microsoft Internet Explorer CTravelEntry use after free attempt (more info ...)attempted-user  2016-0113      URL
47152BROWSER-IE Microsoft Internet Explorer CTravelEntry use after free attempt (more info ...)attempted-user  2016-0113      URL
47189FILE-PDF Adobe Reader JavaScript field manipulation out-of-bounds read attempt (more info ...)attempted-user  2018-5022      URL
47190FILE-PDF Adobe Reader JavaScript field manipulation out-of-bounds read attempt (more info ...)attempted-user  2018-5022      URL
47212FILE-PDF Adobe Reader JavaScript form field manipulation out-of-bounds read attempt (more info ...)attempted-user  2018-5023      URL
47213FILE-PDF Adobe Reader JavaScript form field manipulation out-of-bounds read attempt (more info ...)attempted-user  2018-5023      URL
47214FILE-PDF Adobe Reader JavaScript annotation objects out-of-bounds read attempt (more info ...)attempted-user  2018-5024      URL
47215FILE-PDF Adobe Reader JavaScript annotation objects out-of-bounds read attempt (more info ...)attempted-user  2018-5024      URL
47221FILE-PDF Adobe Reader JavaScript object prototype defineSetter out-of-bounds read attempt (more info ...)attempted-user  2018-5025      URL
47222FILE-PDF Adobe Reader JavaScript object prototype defineSetter out-of-bounds read attempt (more info ...)attempted-user  2018-5025      URL
47227FILE-PDF Adobe Acrobat Reader JavaScript annotation out of bound read attempt (more info ...)attempted-user  2018-5066      URL
47228FILE-PDF Adobe Acrobat Reader JavaScript annotation out of bound read attempt (more info ...)attempted-user  2018-5066      URL
47270FILE-PDF Adobe Reader JavaScript XSL value-of select transformation out-of-bounds write attempt (more info ...)attempted-user  2018-5064      URL
47271FILE-PDF Adobe Reader JavaScript XSL value-of select transformation out-of-bounds write attempt (more info ...)attempted-user  2018-5064      URL
47287FILE-PDF Adobe Reader JavaScript XSLT parsing out-of-bounds read attempt (more info ...)attempted-user  2018-5063      URL
47288FILE-PDF Adobe Reader JavaScript XSLT parsing out-of-bounds read attempt (more info ...)attempted-user  2018-5063      URL
47289FILE-PDF Adobe Reader JavaScript exportAsFDFStr out-of-bounds write attempt (more info ...)attempted-user  2018-5021      URL
47290FILE-PDF Adobe Reader JavaScript exportAsFDFStr out-of-bounds write attempt (more info ...)attempted-user  2018-5021      URL
47291BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
47292BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
47293BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
47294BROWSER-IE Microsoft Internet Explorer CTreePos type confusion attempt (more info ...)attempted-user  2016-0108      URL
47310BROWSER-IE Microsoft Internet Explorer page layout use after free attempt (more info ...)attempted-user  2016-3288      URL
47311BROWSER-IE Microsoft Internet Explorer page layout use after free attempt (more info ...)attempted-user  2016-3288      URL
47484BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2018-8389      URL
47485BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2018-8389      URL
47591BROWSER-IE Microsoft Internet Explorer VBScript engine memory corruption attempt (more info ...)attempted-user  2018-8373      URL
47592BROWSER-IE Microsoft Internet Explorer VBScript engine memory corruption attempt (more info ...)attempted-user  2018-8373      URL
47730BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2018-8447      URL
47731BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2018-8447      URL
47738BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2018-8461      URL
47739BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2018-8461      URL
47747BROWSER-IE Microsoft Internet Explorer MSXML use after free attempt (more info ...)attempted-user  2018-8420      URL
47748BROWSER-IE Microsoft Internet Explorer MSXML use after free attempt (more info ...)attempted-user  2018-8420      URL
47924FILE-PDF Adobe Reader JavaScript annotation object rotation use-after-free attempt (more info ...)attempted-user  2018-12769      URL
47925FILE-PDF Adobe Reader JavaScript annotation object rotation use-after-free attempt (more info ...)attempted-user  2018-12769      URL
47928FILE-PDF Adobe Reader JavaScript endInitiatorMailOperation heap overflow attempt (more info ...)attempted-user  2018-12832      URL
47929FILE-PDF Adobe Reader JavaScript endInitiatorMailOperation heap overflow attempt (more info ...)attempted-user  2018-12832      URL
47930FILE-PDF Adobe Acrobat Reader JavaScript engine heap overflow attempt (more info ...)attempted-user  2018-12846      URL
47931FILE-PDF Adobe Acrobat Reader JavaScript engine heap overflow attempt (more info ...)attempted-user  2018-12846      URL
47947FILE-PDF Adobe Acrobat Reader JavaScript Engine use after free attempt (more info ...)attempted-user  2018-15920      URL
47948FILE-PDF Adobe Acrobat Reader JavaScript Engine use after free attempt (more info ...)attempted-user  2018-15920      URL
47963FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (more info ...)attempted-user  2019-7078      URL
47964FILE-OTHER Adobe Acrobat Pro WebCapture JavaScript manipulation type confusion attempt (more info ...)attempted-user  2019-7078      URL
47965FILE-PDF Adobe Reader getProps Javascript heap overflow attempt (more info ...)attempted-user  2018-12836      URL
47966FILE-PDF Adobe Reader getProps Javascript heap overflow attempt (more info ...)attempted-user  2018-12836      URL
47973FILE-PDF Adobe Acrobat Reader JavaScript engine use after free attempt (more info ...)attempted-user  2018-15924      URL
47974FILE-PDF Adobe Acrobat Reader JavaScript engine use after free attempt (more info ...)attempted-user  2018-15924      URL
48000FILE-PDF Adobe Reader JavaScript pointer offset out-of-bounds read attempt (more info ...)attempted-user  2018-15921      URL
48001FILE-PDF Adobe Reader JavaScript pointer offset out-of-bounds read attempt (more info ...)attempted-user  2018-15921      URL
48016FILE-IMAGE Adobe Acrobat Reader malformed JavaScript input out of bounds read attempt (more info ...)attempted-user  2018-15922      URL
48017FILE-IMAGE Adobe Acrobat Reader malformed JavaScript input out of bounds read attempt (more info ...)attempted-user  2018-15922      URL
48018FILE-PDF Adobe Reader malformed JavaScript input out of bounds read attempt (more info ...)attempted-user  2018-15923      URL
48019FILE-PDF Adobe Reader malformed JavaScript input out of bounds read attempt (more info ...)attempted-user  2018-15923      URL
48020FILE-PDF Adobe Acrobat Reader malformed JavaScript input out of bounds read attempt (more info ...)attempted-user  2018-15925      URL
48021FILE-PDF Adobe Acrobat Reader malformed JavaScript input out of bounds read attempt (more info ...)attempted-user  2018-15925      URL
48049BROWSER-IE Microsoft Internet Explorer import key use-after-free attempt (more info ...)attempted-user  2018-8491      URL
48050BROWSER-IE Microsoft Internet Explorer import key use-after-free attempt (more info ...)attempted-user  2018-8491      URL
48368BROWSER-IE Microsoft Internet Explorer VBScript Engine remote code execution attempt (more info ...)attempted-user  2018-8552      URL
48369BROWSER-IE Microsoft Internet Explorer VBScript Engine remote code execution attempt (more info ...)attempted-admin  2018-8552      URL
48370BROWSER-IE Microsoft Internet Explorer DirectX information disclosure attempt (more info ...)attempted-user  2018-8563      URL
48371BROWSER-IE Microsoft Internet Explorer DirectX information disclosure attempt (more info ...)attempted-user  2018-8563      URL
48372BROWSER-IE Microsoft Internet Explorer VBScript Engine remote code execution attempt (more info ...)attempted-admin  2018-8544      URL
48373BROWSER-IE Microsoft Internet Explorer VBScript Engine remote code execution attempt (more info ...)attempted-user  2018-8544      URL
48517BROWSER-IE Microsoft Internet Explorer Chakra engine memory corruption attempt (more info ...)attempted-user  2018-8624      URL
48518BROWSER-IE Microsoft Internet Explorer Chakra engine memory corruption attempt (more info ...)attempted-admin  2018-8624      URL
48531BROWSER-IE Microsoft Internet Explorer 11 VBScript execution policy bypass attempt (more info ...)attempted-user  2018-8619      URL
48532BROWSER-IE Microsoft Internet Explorer 11 VBScript execution policy bypass attempt (more info ...)attempted-user  2018-8619      URL
48533BROWSER-IE Microsoft Internet Explorer Jscript.Encode out-of-bounds read attempt (more info ...)attempted-user  2018-8631      URL
48534BROWSER-IE Microsoft Internet Explorer Jscript.Encode out-of-bounds read attempt (more info ...)attempted-admin  2018-8631      URL
48564BROWSER-FIREFOX Mozilla Firefox javascript type confusion code execution attempt (more info ...)attempted-user  2018-12386      URL
48565BROWSER-FIREFOX Mozilla Firefox javascript type confusion code execution attempt (more info ...)attempted-user  2018-12386      URL
48596BROWSER-IE Microsoft Internet Explorer out-of-bounds read attempt (more info ...)attempted-user  2018-8643      URL
48597BROWSER-IE Microsoft Internet Explorer out-of-bounds read attempt (more info ...)attempted-user  2018-8643      URL
48625BROWSER-FIREFOX Mozilla Firefox method array.prototype.push remote code execution attempt (more info ...)attempted-user  2018-12387      URL
48626BROWSER-FIREFOX Mozilla Firefox method array.prototype.push remote code execution attempt (more info ...)attempted-user  2018-12387      URL
48693BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-user  2018-8373      URL
48694BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-user  2018-8373      URL
48695BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-user  2018-8373      URL
48696BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-user  2018-8373      URL
48697BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-user        
48698BROWSER-IE Microsoft Internet Explorer VBScript remote code execution attempt (more info ...)attempted-user        
48699BROWSER-IE Microsoft Internet Explorer JavaScript engine downgrade detected (more info ...)policy-violation        
48700BROWSER-IE Microsoft Internet Explorer JavaScript engine downgrade detected (more info ...)policy-violation        
48701BROWSER-IE Microsoft Internet Explorer JavaScript engine memory corruption attempt (more info ...)attempted-user  2020-0674      URL
48702BROWSER-IE Microsoft Internet Explorer JavaScript engine memory corruption attempt (more info ...)attempted-user  2020-0674      URL
48750FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (more info ...)attempted-user  2018-19707      URL
48751FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (more info ...)attempted-user  2018-19707      URL
48756FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (more info ...)attempted-user  2018-15992      URL
48757FILE-PDF Adobe Acrobat Reader JavaScript extractContents use after free attempt (more info ...)attempted-user  2018-15992      URL
48782BROWSER-IE Microsoft Internet Explorer ProgID arbitrary code execution attempt (more info ...)attempted-user  2019-0541      URL
48783BROWSER-IE Microsoft Internet Explorer ProgID arbitrary code execution attempt (more info ...)attempted-user  2019-0541      URL
48816FILE-PDF Adobe Acrobat javascript based security bypass attempt (more info ...)attempted-user  2018-16044      URL
48817FILE-PDF Adobe Acrobat javascript based security bypass attempt (more info ...)attempted-user  2018-16044      URL
48848FILE-PDF Adobe Reader Javascript ANAuthenticateResource use-after-free attempt (more info ...)attempted-user  2018-16040      URL
48849FILE-PDF Adobe Reader Javascript ANAuthenticateResource use-after-free attempt (more info ...)attempted-user  2018-16040      URL
48898BROWSER-IE Microsoft Internet Explorer page layout use after free attempt (more info ...)attempted-user  2016-3288      URL
48899BROWSER-IE Microsoft Internet Explorer page layout use after free attempt (more info ...)attempted-user  2016-3288      URL
48942FILE-PDF Adobe Reader Javascript out-of-bounds read (more info ...)attempted-user  2018-16031      URL
48943FILE-PDF Adobe Reader Javascript out-of-bounds read (more info ...)attempted-user  2018-16031      URL
48944FILE-PDF Adobe Reader Javascript out-of-bounds read (more info ...)attempted-user  2018-16047      URL
48945FILE-PDF Adobe Reader Javascript out-of-bounds read (more info ...)attempted-user  2018-19701      URL
49081FILE-PDF Adobe Acrobat Reader JavaScript out-of-bounds read (more info ...)attempted-user  2018-16047      URL
49082FILE-PDF Adobe Acrobat Reader JavaScript out-of-bounds read (more info ...)attempted-user  2018-16047      URL
49120SERVER-WEBAPP HP IMC faultEventSelectBean Java expression language injection attempt (more info ...)attempted-admin  2017-12519      URL
49121SERVER-WEBAPP HP IMC faultEventSelectBean Java expression language injection attempt (more info ...)attempted-admin  2017-12519      URL
49126SERVER-WEBAPP HP IMC perfAddorModDeviceMonitorBean Java expression language injection attempt (more info ...)attempted-admin  2017-12520      URL
49127SERVER-WEBAPP HP IMC perfAddorModDeviceMonitorBean Java expression language injection attempt (more info ...)attempted-admin  2017-12520      URL
49155BROWSER-IE Microsoft Internet Explorer information disclosure attempt (more info ...)attempted-user  2019-0676      URL
49156BROWSER-IE Microsoft Internet Explorer information disclosure attempt (more info ...)attempted-user  2019-0676      URL
49196FILE-PDF Adobe Acrobat JavaScript defineProperty memory corruption attempt (more info ...)attempted-user  2018-19725      URL
49197FILE-PDF Adobe Acrobat JavaScript defineProperty memory corruption attempt (more info ...)attempted-user  2018-19725      URL
49201FILE-PDF Adobe Acrobat Reader JavaScript memory corruption attempt (more info ...)attempted-user  2019-7018      URL
49202FILE-PDF Adobe Acrobat Reader JavaScript memory corruption attempt (more info ...)attempted-user  2019-7018      URL
49203FILE-PDF Adobe Reader Javascript out-of-bounds read attempt (more info ...)attempted-user  2019-7022      URL
49204FILE-PDF Adobe Reader Javascript out-of-bounds read attempt (more info ...)attempted-user  2019-7022      URL
49211FILE-PDF Adobe Acrobat JavaScript engine use after free attempt (more info ...)attempted-user  2019-7029      URL
49212FILE-PDF Adobe Acrobat JavaScript engine use after free attempt (more info ...)attempted-user  2019-7029      URL
49213FILE-PDF Adobe Acrobat JavaScript engine out-of-bounds read attempt (more info ...)attempted-user  2019-7053      URL
49214FILE-PDF Adobe Acrobat JavaScript engine out-of-bounds read attempt (more info ...)attempted-user  2019-7053      URL
49227FILE-PDF Adobe Acrobat JavaScript engine use after free attempt (more info ...)attempted-user  2019-7082      URL
49228FILE-PDF Adobe Acrobat JavaScript engine use after free attempt (more info ...)attempted-user  2019-7082      URL
49229FILE-PDF Adobe Reader Javascript out-of-bounds write attempt (more info ...)attempted-user  2019-7060      URL
49230FILE-PDF Adobe Reader Javascript out-of-bounds write attempt (more info ...)attempted-user  2019-7060      URL
49233FILE-PDF Adobe Reader Javascript untrusted pointer dereference attempt detected (more info ...)attempted-user  2019-7054      URL
49234FILE-PDF Adobe Reader Javascript untrusted pointer dereference attempt detected (more info ...)attempted-user  2019-7054      URL
49235FILE-PDF JavaScript XFA engine use after free attempt (more info ...)attempted-user  2019-7022      URL
49236FILE-PDF JavaScript XFA engine use after free attempt (more info ...)attempted-user  2019-7022      URL
49239SERVER-WEBAPP Exhibitor for ZooKeeper javaEnvironment command injection attempt (more info ...)web-application-attack  2018-15380      URL
49246FILE-OTHER Adobe Acrobat JavaScript engine security bypass attempt (more info ...)attempted-user  2019-7041      URL
49247FILE-OTHER Adobe Acrobat JavaScript engine security bypass attempt (more info ...)attempted-user  2019-7041      URL
49255FILE-JAVA Oracle Java ImagingLib buffer overflow attempt (more info ...)attempted-user  2013-2463      
49256FILE-JAVA Oracle Java ImagingLib buffer overflow attempt (more info ...)attempted-user  2013-2463      
49313FILE-PDF Adobe Acrobat XFA JavaScript manipulation out of bounds read attempt (more info ...)attempted-user  2019-7065      URL
49314FILE-PDF Adobe Acrobat XFA JavaScript manipulation out of bounds read attempt (more info ...)attempted-user  2019-7065      URL
49360BROWSER-CHROME Google Chrome FileReader use after free attempt (more info ...)attempted-user  2019-5786  107213    URL
49361BROWSER-CHROME Google Chrome FileReader use after free attempt (more info ...)attempted-user  2019-5786  107213    URL
49378BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2019-0768      URL
49379BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2019-0768      URL
49384BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2019-0763      URL
49385BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2019-0763      URL
49442BROWSER-CHROME TRUFFLEHUNTER TALOS-2019-0791 attack attempt (more info ...)attempted-user        URL
49443BROWSER-CHROME TRUFFLEHUNTER TALOS-2019-0791 attack attempt (more info ...)attempted-user        URL
49752BROWSER-IE Microsoft Internet Explorer use-after-free attempt (more info ...)attempted-user  2019-0862      URL
49753BROWSER-IE Microsoft Internet Explorer use-after-free attempt (more info ...)attempted-user  2019-0862      URL
49799BROWSER-IE Microsoft Internet Explorer MHTML XXE external entity attempt (more info ...)attempted-user        URL
49800BROWSER-IE Microsoft Internet Explorer MHTML XXE external entity attempt (more info ...)attempted-user        URL
49805BROWSER-IE Microsoft Internet Explorer Element object use-after-free attempt (more info ...)attempted-admin  2015-1705      URL
49806BROWSER-IE Microsoft Internet Explorer Element object use-after-free attempt (more info ...)attempted-admin  2015-1705      URL
49846FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin  2012-4681      
49917BROWSER-FIREFOX Mozilla Firefox DOMSVGLength appendItem use after free attempt (more info ...)attempted-user  2014-1563      URL
49918BROWSER-FIREFOX Mozilla Firefox DOMSVGLength appendItem use after free attempt (more info ...)attempted-user  2014-1563      URL
49950BROWSER-IE Microsoft Internet Explorer TextData object use after free attempt (more info ...)attempted-user  2015-1665      URL
49951BROWSER-IE Microsoft Internet Explorer TextData object use after free attempt (more info ...)attempted-user  2015-1665      URL
50082BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2019-0930      URL
50083BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2019-0930      URL
50183BROWSER-IE Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin  2019-1053      URL
50184BROWSER-IE Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin  2019-1053      URL
50359BROWSER-IE Microsoft Internet Explorer Chakra scripting engine memory corruption attempt (more info ...)attempted-user  2019-1051      URL
50360BROWSER-IE Microsoft Internet Explorer Chakra scripting engine memory corruption attempt (more info ...)attempted-user  2019-1051      URL
50367BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2019-1055      URL
50368BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2019-1055      URL
50518BROWSER-FIREFOX Mozilla Firefox Array.prototype.pop type confusion attempt (more info ...)attempted-user  2019-11707      URL
50519BROWSER-FIREFOX Mozilla Firefox Array.prototype.pop type confusion attempt (more info ...)attempted-user  2019-11707      URL
51375SERVER-OTHER Fortigate SSL VPN javascript parsing heap buffer overflow attempt (more info ...)attempted-user  2018-13383      
51376SERVER-OTHER Fortigate SSL VPN javascript parsing heap buffer overflow attempt (more info ...)attempted-user  2018-13383      
51388BROWSER-WEBKIT Apple Safari JSValues type confusion attempt (more info ...)attempted-user  2017-7064      URL
51389BROWSER-WEBKIT Apple Safari JSValues type confusion attempt (more info ...)attempted-user  2017-7064      URL
51391BROWSER-WEBKIT Apple Safari WebKit out-of-bounds write attempt (more info ...)attempted-user  2017-2505      URL
51392BROWSER-WEBKIT Apple Safari WebKit out-of-bounds write attempt (more info ...)attempted-user  2017-2505      URL
51433BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user  2015-1747      
51434BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user  2015-1747      
51640SERVER-WEBAPP JavaScript library OpenPGP.js improper signature verification attempt (more info ...)web-application-attack  2019-9153      URL
51641SERVER-WEBAPP JavaScript library OpenPGP.js improper signature verification attempt (more info ...)web-application-attack  2019-9153      URL
51789BROWSER-IE Microsoft Edge JavaScript engine memory corruption attempt (more info ...)attempted-user  2019-1239      URL
51790BROWSER-IE Microsoft Edge JavaScript engine memory corruption attempt (more info ...)attempted-user  2019-1239      URL
51821BROWSER-WEBKIT WebKit JavaScriptCore AIR optimization memory corruption attempt (more info ...)attempted-user  2019-8611      
51822BROWSER-WEBKIT WebKit JavaScriptCore AIR optimization memory corruption attempt (more info ...)attempted-user  2019-8611      
51823BROWSER-WEBKIT WebKit JavaScriptCore JSValue use after free attempt (more info ...)attempted-user  2019-8672      
51824BROWSER-WEBKIT WebKit JavaScriptCore JSValue use after free attempt (more info ...)attempted-user  2019-8672      
51831BROWSER-WEBKIT WebKit JavaScriptCore emitEqualityOpImpl memory corruption attempt (more info ...)attempted-user  2019-8684      
51832BROWSER-WEBKIT WebKit JavaScriptCore emitEqualityOpImpl memory corruption attempt (more info ...)attempted-user  2019-8684      
51943BROWSER-IE Microsoft Internet Explorer ActiveX type confusion attempt (more info ...)attempted-user  2015-0046      URL
51944BROWSER-IE Microsoft Internet Explorer ActiveX type confusion attempt (more info ...)attempted-user  2015-0046      URL
51961SERVER-WEBAPP Jenkins CLI arbitrary Java object deserialization attempt (more info ...)attempted-admin  2017-1000353      URL
52068BROWSER-CHROME Google Chrome blink webaudio module use after free attempt (more info ...)attempted-user  2019-13720      URL
52069BROWSER-CHROME Google Chrome blink webaudio module use after free attempt (more info ...)attempted-user  2019-13720      URL
52348BROWSER-CHROME Google Chrome V8 engine memory corruption attempt (more info ...)attempted-user        URL
52349BROWSER-CHROME Google Chrome V8 engine memory corruption attempt (more info ...)attempted-user        URL
52400BROWSER-CHROME V8 JavaScript engine Out-of-Memory denial of service attempt (more info ...)attempted-dos        URL
52401BROWSER-CHROME V8 JavaScript engine Out-of-Memory denial of service attempt (more info ...)attempted-dos        URL
52424BROWSER-FIREFOX Mozilla Firefox RemotePrompt sandbox escape attempt (more info ...)attempted-user  2019-11708      URL
52425BROWSER-FIREFOX Mozilla Firefox RemotePrompt sandbox escape attempt (more info ...)attempted-user  2019-11708      URL
52503BROWSER-CHROME Google Chrome V8 AwaitedPromise memory corruption attempt (more info ...)attempted-user  2018-6106      URL
52504BROWSER-CHROME Google Chrome V8 AwaitedPromise memory corruption attempt (more info ...)attempted-user  2018-6106      URL
52601BROWSER-CHROME Google V8 engine type confusion attempt (more info ...)attempted-user  2018-6064      
52602BROWSER-CHROME Google V8 engine type confusion attempt (more info ...)attempted-user  2018-6064      
53100BROWSER-WEBKIT Apple Safari Webkit WebCore memory corruption attempt (more info ...)attempted-user  2018-4200      URL
53101BROWSER-WEBKIT Apple Safari Webkit WebCore memory corruption attempt (more info ...)attempted-user  2018-4200      URL
53121BROWSER-WEBKIT Apple Safari WebKit cached page memory corruption attempt (more info ...)attempted-user  2019-8822      URL
53122BROWSER-WEBKIT Apple Safari WebKit cached page memory corruption attempt (more info ...)attempted-user  2019-8822      URL
53123BROWSER-WEBKIT Apple Safari WebKit cached page universal cross-site scripting attempt (more info ...)attempted-user        URL
53124BROWSER-WEBKIT Apple Safari WebKit cached page universal cross-site scripting attempt (more info ...)attempted-user        URL
53145BROWSER-CHROME Google Chrome V8 FindSharedFunctionInfo out-of-bounds read attempt (more info ...)attempted-user  2017-5071      
53146BROWSER-CHROME Google Chrome V8 FindSharedFunctionInfo out-of-bounds read attempt (more info ...)attempted-user  2017-5071      
53150BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
53151BROWSER-IE Microsoft Internet Explorer onscroll use after free attempt (more info ...)attempted-user  2013-3123      URL
53342BROWSER-CHROME Google Chrome V8 Turbofan Array pop type confusion attempt (more info ...)attempted-user  2020-6418      URL
53343BROWSER-CHROME Google Chrome V8 Turbofan Array pop type confusion attempt (more info ...)attempted-user  2020-6418      URL
53404BROWSER-IE Internet Explorer Scripting Engine memory corruption attempt (more info ...)attempted-user  2020-0833      URL
53405BROWSER-IE Internet Explorer Scripting Engine memory corruption attempt (more info ...)attempted-user  2020-0833      URL
53459BROWSER-IE Microsoft Internet Explorer center element dynamic manipulation attempt (more info ...)attempted-user  2012-1523      URL
53460BROWSER-IE Microsoft Internet Explorer center element dynamic manipulation attempt (more info ...)attempted-user  2012-1523      URL
53461BROWSER-IE Microsoft Internet Explorer center element dynamic manipulation attempt (more info ...)attempted-user  2012-1523      
53462BROWSER-IE Microsoft Internet Explorer center element dynamic manipulation attempt (more info ...)attempted-user  2012-1523      URL
53463BROWSER-IE Microsoft Internet Explorer center element dynamic manipulation attempt (more info ...)attempted-user  2012-1523      URL
53477BROWSER-WEBKIT Apple Safari WebKit type confusion attempt (more info ...)attempted-dos  2019-8765      
53478BROWSER-WEBKIT Apple Safari WebKit type confusion attempt (more info ...)attempted-dos  2019-8765      
53533BROWSER-CHROME Google Chrome desktopMediaPickerController use after free attempt (more info ...)attempted-user  2019-13767      URL
53534BROWSER-CHROME Google Chrome desktopMediaPickerController use after free attempt (more info ...)attempted-user  2019-13767      URL
53751BROWSER-CHROME Google Chrome ObjectCreate type confusion attempt (more info ...)attempted-user  2018-17463      
53752BROWSER-CHROME Google Chrome ObjectCreate type confusion attempt (more info ...)attempted-user  2018-17463      
53753BROWSER-CHROME Google Chrome ObjectCreate type confusion attempt (more info ...)attempted-user  2018-17463      
53754BROWSER-CHROME Google Chrome ObjectCreate type confusion attempt (more info ...)attempted-user  2018-17463      
53844BROWSER-CHROME Google Chromium ImageCapture use after free attempt (more info ...)attempted-user  2019-13687      
53845BROWSER-CHROME Google Chromium ImageCapture use after free attempt (more info ...)attempted-user  2019-13687      
53918BROWSER-IE Internet Explorer VBScript engine memory corruption attempt (more info ...)attempted-user  2020-1035      URL
53919BROWSER-IE Internet Explorer VBScript engine memory corruption attempt (more info ...)attempted-user  2020-1035      URL
53928BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2020-1062      URL
53929BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2020-1062      URL
53930BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2020-1062      URL
53931BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2020-1062      URL
53942BROWSER-CHROME Google Chromium for Android AddInterface use after free attempt (more info ...)attempted-user  2019-13686      
53943BROWSER-CHROME Google Chromium for Android AddInterface use after free attempt (more info ...)attempted-user  2019-13686      
54028INDICATOR-SHELLCODE Java RMI deserialization exploit attempt (more info ...)shellcode-detect  2020-3280      URL
54051BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1085 attack attempt (more info ...)attempted-user        URL
54052BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1085 attack attempt (more info ...)attempted-user        URL
54169MALWARE-OTHER Cobalt Strike signed java applet execution attempt (more info ...)trojan-activity        URL
54170MALWARE-OTHER Cobalt Strike signed java applet execution attempt (more info ...)trojan-activity        URL
54171MALWARE-OTHER Cobalt Strike signed java applet download attempt (more info ...)trojan-activity        URL
54172MALWARE-OTHER Cobalt Strike signed java applet download attempt (more info ...)trojan-activity        URL
54173MALWARE-OTHER Cobalt Strike signed java applet download attempt (more info ...)trojan-activity        URL
54174MALWARE-OTHER Cobalt Strike signed java applet download attempt (more info ...)trojan-activity        URL
54189FILE-PDF Adobe Reader custom JavaScript field use-after-free attempt (more info ...)attempted-user  2020-3805      URL
54190FILE-PDF Adobe Reader custom JavaScript field use-after-free attempt (more info ...)attempted-user  2020-3805      URL
54230BROWSER-IE Microsoft Internet Explorer VBScript engine memory corruption attempt (more info ...)attempted-user  2020-1213      URL
54231BROWSER-IE Microsoft Internet Explorer VBScript engine memory corruption attempt (more info ...)attempted-user  2020-1213      URL
54232BROWSER-IE Microsoft Internet Explorer VBScript memory corruption attempt (more info ...)attempted-user  2020-1216      URL
54233BROWSER-IE Microsoft Internet Explorer VBScript memory corruption attempt (more info ...)attempted-user  2020-1216      URL
54319SERVER-WEBAPP VMWare Cloud Director Java expression language injection attempt (more info ...)attempted-admin  2020-3956      
54379BROWSER-FIREFOX Mozilla Firefox ReadableStreamCloseInternal out-of-bounds access attempt (more info ...)attempted-user  2020-6806      URL
54380BROWSER-FIREFOX Mozilla Firefox ReadableStreamCloseInternal out-of-bounds access attempt (more info ...)attempted-user  2020-6806      URL
54399BROWSER-IE Microsoft Internet Explorer JavaScript engine memory corruption attempt (more info ...)attempted-user  2020-0674      URL
54400BROWSER-IE Microsoft Internet Explorer JavaScript engine memory corruption attempt (more info ...)attempted-user  2020-0674      URL
54497BROWSER-CHROME Google Chrome Blink use-after-free attempt (more info ...)attempted-user  2019-13688      URL
54498BROWSER-CHROME Google Chrome Blink use-after-free attempt (more info ...)attempted-user  2019-13688      URL
54509BROWSER-IE Microsoft Internet Explorer VBScript engine memory corruption attempt (more info ...)attempted-user  2020-1403      URL
54510BROWSER-IE Microsoft Internet Explorer VBScript engine memory corruption attempt (more info ...)attempted-user  2020-1403      URL
54545SERVER-WEBAPP Cisco SD-WAN vManage arbitrary Java object deserialization attempt (more info ...)attempted-admin  2020-3387      URL
54584BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1123 attack attempt (more info ...)attempted-recon        URL
54585BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1123 attack attempt (more info ...)attempted-recon        URL
54622BROWSER-CHROME Google Chrome ReadableStream out of bounds read attempt (more info ...)attempted-user  2020-6390      
54623BROWSER-CHROME Google Chrome ReadableStream out of bounds read attempt (more info ...)attempted-user  2020-6390      
54638BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1127 attack attempt (more info ...)attempted-user        URL
54639BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1127 attack attempt (more info ...)attempted-user        URL
54741BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2020-1567      URL
54742BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2020-1567      URL
55036BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (more info ...)attempted-user        URL
55037BROWSER-CHROME TRUFFLEHUNTER TALOS-2020-1152 attack attempt (more info ...)attempted-user        URL
56130BROWSER-CHROME Google Chrome PNG in TTF parsing heap overflow attempt (more info ...)attempted-user  2020-15999      URL
56131BROWSER-CHROME Google Chrome PNG in TTF parsing heap overflow attempt (more info ...)attempted-user  2020-15999      URL
56132BROWSER-CHROME Google Chrome PNG in TTF parsing heap overflow attempt (more info ...)attempted-user  2020-15999      URL
56133BROWSER-CHROME Google Chrome PNG in TTF parsing heap overflow attempt (more info ...)attempted-user  2020-15999      URL
56150SERVER-OTHER Adobe ColdFusion DataServicesCFProxy insecure Java deserialization attempt (more info ...)attempted-user  2018-4939      
56288BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2020-17053      URL
56289BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2020-17053      URL
56406INDICATOR-SHELLCODE ysoserial Java object deserialization exploit attempt (more info ...)shellcode-detect  2020-27131      
56407INDICATOR-SHELLCODE ysoserial Java object deserialization exploit attempt (more info ...)shellcode-detect  2020-27131      
56437BROWSER-CHROME Google Chrome Blink Renderer MediaElementEventListener memory corruption attempt (more info ...)attempted-user  2020-6549      URL
56438BROWSER-CHROME Google Chrome Blink Renderer MediaElementEventListener memory corruption attempt (more info ...)attempted-user  2020-6549      URL
56445SERVER-WEBAPP Java Library UniversalExtractor unauthorized deserialization attempt (more info ...)attempted-user  2020-14625      URL
56497SERVER-WEBAPP Multiple Products Java Faces ViewState deserialization remote code execution attempt (more info ...)attempted-user  2019-2904      URL
56557SERVER-WEBAPP Microsoft Dynamics365 Finance and Operations remote code execution attempt (more info ...)attempted-admin  2020-17152      URL
56558SERVER-WEBAPP Microsoft Dynamics365 Finance and Operations remote code execution attempt (more info ...)attempted-admin  2020-17152      URL
56799SERVER-WEBAPP Liferay arbitrary Java object deserialization attempt (more info ...)attempted-admin  2020-7961      URL
56800SERVER-WEBAPP Liferay arbitrary Java object deserialization attempt (more info ...)attempted-admin  2020-7961      URL
57057BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1235 attack attempt (more info ...)attempted-user        URL
57058BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1235 attack attempt (more info ...)attempted-user        URL
57268BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2021-26411      URL
57269BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2021-26411      URL
57283SERVER-WEBAPP Liferay arbitrary Java object deserialization attempt (more info ...)attempted-admin  2020-7961      URL
57420BROWSER-CHROME Google Chrome V8 engine integer overflow attempt (more info ...)attempted-user  2021-21220      URL
57421BROWSER-CHROME Google Chrome V8 engine integer overflow attempt (more info ...)attempted-user  2021-21220      URL
57429BROWSER-CHROME Google Chrome Math.max memory corruption attempt (more info ...)attempted-user  2021-21224      URL
57430BROWSER-CHROME Google Chrome Math.max memory corruption attempt (more info ...)attempted-user  2021-21224      URL
57434SERVER-WEBAPP VMware vRealize Operations Manager directory traversal attempt (more info ...)web-application-attack  2021-21983      URL
57435SERVER-WEBAPP VMware vRealize Operations Manager SSRF attempt (more info ...)web-application-attack  2021-21975      URL
57440BROWSER-CHROME Google Chrome V8 OnServiceConnectionError memory corruption attempt (more info ...)attempted-user  2020-6541      URL
57441BROWSER-CHROME Google Chrome V8 OnServiceConnectionError memory corruption attempt (more info ...)attempted-user  2020-6541      URL
57494SERVER-WEBAPP Micro Focus Operations Bridge Manager remote code execution attempt (more info ...)attempted-admin  2020-11854      
57495POLICY-OTHER Micro Focus Operations Bridge default credentials login attempt (more info ...)policy-violation        
57496POLICY-OTHER Micro Focus Operations Bridge default credentials login attempt (more info ...)policy-violation        
57500SERVER-WEBAPP HPE Intelligent Management Center IccSelectDevTypeBean Expression Language Injection Java expression language injection attempt (more info ...)web-application-attack  2019-11941      URL
57542BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2021-26419      URL
57543BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2021-26419      URL
57837BROWSER-CHROME Google Chrome NewFixedDoubleArray memory corruption attempt (more info ...)attempted-user        
57838BROWSER-CHROME Google Chrome NewFixedDoubleArray memory corruption attempt (more info ...)attempted-user        
57839BROWSER-CHROME Google Chrome NewFixedDoubleArray memory corruption attempt (more info ...)attempted-user        
57840BROWSER-CHROME Google Chrome NewFixedDoubleArray memory corruption attempt (more info ...)attempted-user        
57938BROWSER-CHROME Google Chrome WebRTC addIceCandidate use after free attempt (more info ...)attempted-user  2021-30602      URL
57939BROWSER-CHROME Google Chrome WebRTC addIceCandidate use after free attempt (more info ...)attempted-user  2021-30602      URL
58001BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1352 attack attempt (more info ...)attempted-user        URL
58002BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1352 attack attempt (more info ...)attempted-user        URL
58081BROWSER-CHROME Chromium V8 type confusion attempt (more info ...)attempted-user  2021-30563      URL
58082BROWSER-CHROME Chromium V8 type confusion attempt (more info ...)attempted-user  2021-30563      URL
58108BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1372 attack attempt (more info ...)attempted-user        URL
58109BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1372 attack attempt (more info ...)attempted-user        URL
58183BROWSER-IE Microsoft Internet Explorer MSHTML CTreePos remote code execution attempt (more info ...)attempted-user  2021-33742      URL
58184BROWSER-IE Microsoft Internet Explorer MSHTML CTreePos remote code execution attempt (more info ...)attempted-user  2021-33742      URL
58282SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center perfAddFormServer Java expression language injection attempt (more info ...)web-application-attack  2017-12487      
58283SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center perfSelItemServer Java expression language injection attempt (more info ...)web-application-attack        
58344BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1385 attack attempt (more info ...)attempted-user        URL
58345BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1385 attack attempt (more info ...)attempted-user        URL
58355SERVER-WEBAPP GE MDS PulseNET HealthCheck arbitrary Java object deserialization attempt (more info ...)attempted-admin  2018-10611      
58379SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center devSoftSel Java expression language injection attempt (more info ...)attempted-admin  2017-12514      
58380SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center devSoftSel Java expression language injection attempt (more info ...)attempted-admin  2017-12514      
58384SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center operationSelect Java expression language injection attempt (more info ...)attempted-admin  2017-12518      
58385SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center operationSelect Java expression language injection attempt (more info ...)attempted-admin  2017-12518      
58489BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1398 attack attempt (more info ...)attempted-user        URL
58490BROWSER-CHROME TRUFFLEHUNTER TALOS-2021-1398 attack attempt (more info ...)attempted-user        URL
58521SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center perfInsListServer Java expression language injection attempt (more info ...)web-application-attack        
58524FILE-OTHER Apple Safari Type 1 fonts RCE attempt (more info ...)attempted-user  2020-27930      
58546SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center TopoBroadcastServlet arbitrary Java object deserialization attempt (more info ...)attempted-admin  2017-8964      
58547BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2021-26411      URL
58548BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user  2021-26411      URL
58563SERVER-WEBAPP GE MDS PulseNET foglight service arbitrary Java object deserialization attempt (more info ...)attempted-admin  2018-10611      
58599BROWSER-CHROME Google Chrome V8 kConstantType type confusion attempt (more info ...)attempted-user  2021-30632      URL
58600BROWSER-CHROME Google Chrome V8 kConstantType type confusion attempt (more info ...)attempted-user  2021-30632      URL
58606SERVER-WEBAPP SAP NetWeaver AS JAVA CRM log injection attempt (more info ...)attempted-user  2018-2380      
58607SERVER-WEBAPP SAP NetWeaver AS JAVA CRM log injection attempt (more info ...)attempted-user  2018-2380      
58608SERVER-WEBAPP SAP NetWeaver AS JAVA CRM log injection attempt (more info ...)attempted-user  2018-2380      
58611BROWSER-FIREFOX Mozilla Firefox IonMonkey type confusion attempt (more info ...)attempted-user  2019-17026      
58612BROWSER-FIREFOX Mozilla Firefox IonMonkey type confusion attempt (more info ...)attempted-user  2019-17026      
58613BROWSER-CHROME Google Chrome V8 JavaScript Engine type confusion attempt (more info ...)attempted-user  2021-30551      
58614BROWSER-CHROME Google Chrome V8 JavaScript Engine type confusion attempt (more info ...)attempted-user  2021-30551      
58683BROWSER-CHROME Google Chrome ScriptProcessorNode race condition exploit attempt (more info ...)attempted-user  2021-21166      URL
58684BROWSER-CHROME Google Chrome ScriptProcessorNode race condition exploit attempt (more info ...)attempted-user  2021-21166      URL
58791MALWARE-OTHER Win.Ransomware.Blackbyte malicious javascript file download attempt (more info ...)trojan-activity        URL
58793MALWARE-OTHER Win.Ransomware.Blackbyte malicious javascript file download attempt (more info ...)trojan-activity        URL
58841SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance Java expression language injection attempt (more info ...)attempted-admin        
58842SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance Java expression language injection attempt (more info ...)attempted-admin        
58905SERVER-WEBAPP OneDev AttachmentUploadServet arbitrary Java deserialization attempt (more info ...)attempted-user  2021-21242      URL
58985SERVER-WEBAPP OneDev Platform AttachmentUploadServet arbitrary Java object deserialization attempt (more info ...)attempted-admin  2021-21243      
58986SERVER-WEBAPP OneDev Platform AttachmentUploadServet arbitrary Java object deserialization attempt (more info ...)attempted-admin  2021-21243      
59016SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center Java expression language injection attempt (more info ...)attempted-admin  2020-7161      URL
59017SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center Java expression language injection attempt (more info ...)attempted-admin  2020-7161      URL
59216BROWSER-IE Microsoft Internet Explorer security zone bypass attempt (more info ...)attempted-user  2022-24502      URL
59217BROWSER-IE Microsoft Internet Explorer security zone bypass attempt (more info ...)attempted-user  2022-24502      URL
59405EXPLOIT-KIT Operation Dream Job profile attempt (more info ...)attempted-user        URL
59416SERVER-WEBAPP Java getRuntime remote code execution attempt (more info ...)attempted-user  2022-22965      URL
59448BROWSER-CHROME TRUFFLEHUNTER TALOS-2022-1508 attack attempt (more info ...)attempted-user        URL
59449BROWSER-CHROME TRUFFLEHUNTER TALOS-2022-1508 attack attempt (more info ...)attempted-user        URL
59836SERVER-WEBAPP Jenkins Pipeline Groovy plugin Java expression language injection attempt (more info ...)web-application-attack  2019-1003030      URL
59837SERVER-WEBAPP Jenkins Pipeline Groovy plugin Java expression language injection attempt (more info ...)web-application-attack  2019-1003030      URL
60076BROWSER-CHROME TRUFFLEHUNTER TALOS-2022-1543 attack attempt (more info ...)attempted-user        URL
60077BROWSER-CHROME TRUFFLEHUNTER TALOS-2022-1543 attack attempt (more info ...)attempted-user        URL
60154BROWSER-WEBKIT Apple Safari WebKit loadInSameDocument use-after-free attempt (more info ...)attempted-user  2022-22620      
60155BROWSER-WEBKIT Apple Safari WebKit loadInSameDocument use-after-free attempt (more info ...)attempted-user  2022-22620      
60177SERVER-WEBAPP Zoho ManageEngine ADAudit Plus Java deserialize payload execution attempt (more info ...)web-application-attack  2022-28219      
60178SERVER-WEBAPP Zoho ManageEngine ADAudit Plus Java deserialize payload execution attempt (more info ...)web-application-attack  2022-28219      
60179SERVER-WEBAPP Zoho ManageEngine ADAudit Plus Java deserialize payload execution attempt (more info ...)web-application-attack  2022-28219      
60256SERVER-WEBAPP Nexus Repository Manager Java EL Injection RCE attempt (more info ...)attempted-user  2020-10199      URL
60291MALWARE-OTHER Win.Downloader.ChromeLoader payload download attempt (more info ...)trojan-activity        URL
60292MALWARE-OTHER Win.Downloader.ChromeLoader payload download attempt (more info ...)trojan-activity        URL
60293MALWARE-OTHER Win.Downloader.ChromeLoader payload download attempt (more info ...)trojan-activity        URL
60294MALWARE-OTHER Win.Downloader.ChromeLoader payload download attempt (more info ...)trojan-activity        URL
60344BROWSER-CHROME WebRTC heap buffer overflow attempt (more info ...)attempted-user  2022-2294      
60345BROWSER-CHROME WebRTC heap buffer overflow attempt (more info ...)attempted-user  2022-2294      
60362BROWSER-CHROME Google Chrome Animation timeline use after free attempt (more info ...)attempted-user  2022-0609      URL
60363BROWSER-CHROME Google Chrome Animation timeline use after free attempt (more info ...)attempted-user  2022-0609      URL
60366BROWSER-CHROME V8 Array concat remote code execution attempt (more info ...)attempted-user  2017-5030      URL
60367BROWSER-CHROME V8 Array concat remote code execution attempt (more info ...)attempted-user  2017-5030      URL
60369BROWSER-CHROME V8 ReadDenseJSArray out of bounds write attempt (more info ...)attempted-user  2018-17480      URL
60370BROWSER-CHROME V8 ReadDenseJSArray out of bounds write attempt (more info ...)attempted-user  2018-17480      URL
60395BROWSER-CHROME Google Chrome V8 CSS prop type interceptor confusion attempt (more info ...)attempted-user  2022-1232      URL
60396BROWSER-CHROME Google Chrome V8 CSS prop type interceptor confusion attempt (more info ...)attempted-user  2022-1232      URL
60413BROWSER-WEBKIT JavaScriptCore watchpoint type confusion attempt (more info ...)attempted-user  2019-8506      URL
60414BROWSER-WEBKIT JavaScriptCore watchpoint type confusion attempt (more info ...)attempted-user  2019-8506      URL
60482BROWSER-CHROME Google Chrome V8 JSON.stringify remote code execution attempt (more info ...)attempted-user  2021-38003      URL
60483BROWSER-CHROME Google Chrome V8 JSON.stringify remote code execution attempt (more info ...)attempted-user  2021-38003      URL
60502SERVER-WEBAPP Dojo Toolkit JavaScript prototype pollution attempt (more info ...)attempted-user  2021-23450      
60503SERVER-WEBAPP Dojo Toolkit JavaScript prototype pollution attempt (more info ...)attempted-user  2021-23450      
60578BROWSER-CHROME Google Chromium security bypass attempt (more info ...)attempted-user  2021-30533      URL
60579BROWSER-CHROME Google Chromium security bypass attempt (more info ...)attempted-user  2021-30533      URL
60647BROWSER-CHROME Chrome IPC memory dump attempt (more info ...)attempted-user  2021-37976      URL
60648BROWSER-CHROME Chrome IPC memory dump attempt (more info ...)attempted-user  2021-37976      URL
60917BROWSER-IE Google Chrome LinkToTextMenuObserver heap use-after-free attempt (more info ...)attempted-user  2022-2998      URL
60918BROWSER-IE Google Chrome LinkToTextMenuObserver heap use-after-free attempt (more info ...)attempted-user  2022-2998      URL
60950BROWSER-CHROME Google Chrome PDFiumEngine RequestThumbnail use-after-free attempt (more info ...)attempted-user  2022-0306      URL
60951BROWSER-CHROME Google Chrome PDFiumEngine RequestThumbnail use-after-free attempt (more info ...)attempted-user  2022-0306      URL
61346INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Get-ChromeDump download attempt (more info ...)trojan-activity        URL
61347INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Get-ChromeDump download attempt (more info ...)trojan-activity        URL
61412BROWSER-CHROME TRUFFLEHUNTER TALOS-2023-1724 attack attempt (more info ...)attempted-user        URL
61413BROWSER-CHROME TRUFFLEHUNTER TALOS-2023-1724 attack attempt (more info ...)attempted-user        URL
61599SERVER-WEBAPP Cisco Secure Network Analytics arbitrary Java object deserialization attempt (more info ...)attempted-admin  2023-20102      URL
61608BROWSER-CHROME Google Chrome URLLoader NotifyCompleted use-after-free attempt (more info ...)attempted-user  2022-3038      URL
61609BROWSER-CHROME Google Chrome URLLoader NotifyCompleted use-after-free attempt (more info ...)attempted-user  2022-3038      URL
61640MALWARE-TOOLS Chrome infostealer download attempt (more info ...)trojan-activity        URL
61641MALWARE-TOOLS Chrome infostealer download attempt (more info ...)trojan-activity        URL
61687BROWSER-CHROME Google Chrome synchronous Mojo message handler use-after-free attempt (more info ...)attempted-user  2022-4178      URL
61688BROWSER-CHROME Google Chrome synchronous Mojo message handler use-after-free attempt (more info ...)attempted-user  2022-4178      URL
61804BROWSER-CHROME Google Chrome PerformLayout use after free attempt (more info ...)attempted-user  2022-3654      
61805BROWSER-CHROME Google Chrome PerformLayout use after free attempt (more info ...)attempted-user  2022-3654      
61885BROWSER-CHROME TRUFFLEHUNTER TALOS-2023-1751 attack attempt (more info ...)attempted-user        URL
61886BROWSER-CHROME TRUFFLEHUNTER TALOS-2023-1751 attack attempt (more info ...)attempted-user        URL


# of warning rules in this group: 1799

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1667SERVER-WEBAPP cross site scripting HTML Image tag set to javascript attempt (more info ...)web-application-attack 2002-0902 4858  
1735BROWSER-OTHER Mozilla Netscape XMLHttpRequest local file read attempt (more info ...)web-application-attack 2002-0354 4628  
1840FILE-JAVA Oracle Javascript document.domain attempt (more info ...)attempted-user 2002-0815 5346  
1841BROWSER-FIREFOX Mozilla 1.0 Javascript arbitrary cookie access attempt (more info ...)attempted-user 2002-2314 5293  
1846POLICY-MULTIMEDIA vncviewer Java applet download attempt (more info ...)misc-activity   10758 
2437FILE-MULTIMEDIA RealNetworks RealPlayer arbitrary javascript command attempt (more info ...)attempted-user 2003-0726 9378  
2671BROWSER-IE Microsoft Internet Explorer bitmap BitmapOffset integer overflow attempt (more info ...)attempted-user 2004-0566 9663  URL
3079BROWSER-IE Microsoft Internet Explorer ANI file parsing buffer overflow attempt (more info ...)attempted-user 2007-1765   URL
3149BROWSER-IE Microsoft Internet Explorer malformed object type overflow attempt (more info ...)attempted-user 2003-0344   URL
3462BROWSER-IE Microsoft Internet Explorer Content-Encoding overflow attempt (more info ...)attempted-admin 2003-0113 7419  URL
3534FILE-IMAGE Mozilla GIF single packet heap overflow - NETSCAPE2.0 (more info ...)attempted-user 2005-0399 12881 17605 
3553BROWSER-IE Microsoft Internet Explorer HTML DOM null DHTML element insertion attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
3814BROWSER-IE Microsoft Internet Explorer javaprxy.dll COM access (more info ...)attempted-user 2005-2087 14087  URL
4132BROWSER-IE Microsoft Internet Explorer msdds clsid access attempt (more info ...)attempted-user 2005-2127 14594  URL
4133BROWSER-IE Microsoft Internet Explorer devenum clsid access attempt (more info ...)attempted-user 2005-1990 14511  URL
4134BROWSER-IE Microsoft Internet Explorer blnmgr clsid access attempt (more info ...)attempted-user 2005-1990 14511  URL
4147BROWSER-PLUGINS Microsoft Internet Explorer ActiveLabel ActiveX object access (more info ...)attempted-user 2002-0647 5558  URL
4155BROWSER-PLUGINS Microsoft Internet Explorer htmlfile ActiveX object access attempt (more info ...)attempted-user 2011-1995 49960  URL
4165BROWSER-PLUGINS Microsoft Internet Explorer Image Control 1.0 ActiveX object access (more info ...)attempted-user  12477  URL
4169BROWSER-PLUGINS Microsoft Internet Explorer Active Setup ActiveX object access (more info ...)attempted-user  667  URL
4171BROWSER-PLUGINS Microsoft Internet Explorer Registration Wizard ActiveX object access (more info ...)attempted-user 1999-1578 671  URL
4188BROWSER-PLUGINS Microsoft Internet Explorer RAV Online Scanner ActiveX object access (more info ...)attempted-user 2004-0936 11448  URL
4189BROWSER-PLUGINS Microsoft Internet Explorer Third-Party Plugin ActiveX object access (more info ...)attempted-user 2003-0233   URL
4192BROWSER-PLUGINS Microsoft Internet Explorer HHOpen ActiveX object access (more info ...)attempted-user 1999-1577 669  URL
4198BROWSER-PLUGINS Microsoft Internet Explorer Blnmgrps.dll ActiveX object access (more info ...)attempted-user 2005-2127   URL
4199BROWSER-PLUGINS Microsoft Internet Explorer Blnmgrps.dll ActiveX object access (more info ...)attempted-user 2005-2127   URL
4200BROWSER-PLUGINS Microsoft Internet Explorer Index Server Scope Administration ActiveX object access (more info ...)attempted-user 2005-2127   URL
4201BROWSER-PLUGINS Microsoft Internet Explorer Queued Components Recorder ActiveX object access (more info ...)attempted-user 2005-2127   URL
4203BROWSER-PLUGINS Microsoft Internet Explorer Marquee Control ActiveX object access (more info ...)attempted-user 2005-2127   URL
4204BROWSER-PLUGINS Microsoft Internet Explorer DT PolyLine Control 2 ActiveX object access (more info ...)attempted-user 2005-2127   URL
4205BROWSER-PLUGINS Microsoft Internet Explorer Visual Database Tools Database Designer v7.0 ActiveX object access (more info ...)attempted-user 2005-2127   URL
4206BROWSER-PLUGINS Microsoft Internet Explorer MPEG-4 Video Decompressor Property Page ActiveX object access (more info ...)attempted-user 2005-2127   URL
4207BROWSER-PLUGINS Microsoft Internet Explorer Audio Decompressor Control Property Page ActiveX object access (more info ...)attempted-user 2005-2127   URL
4208BROWSER-PLUGINS Microsoft Internet Explorer LexRefStEsObject Class ActiveX object access (more info ...)attempted-user 2005-2127   URL
4209BROWSER-PLUGINS Microsoft Internet Explorer LexRefStFrObject Class ActiveX object access (more info ...)attempted-user 2005-2127   URL
4210BROWSER-PLUGINS Microsoft Internet Explorer Msb1geen.dll ActiveX object access (more info ...)attempted-user 2005-2127   URL
4211BROWSER-PLUGINS Microsoft Internet Explorer DDS Library Shape Control ActiveX object access (more info ...)attempted-user 2005-2127   URL
4212BROWSER-PLUGINS Microsoft Internet Explorer DDS Generic Class ActiveX object access (more info ...)attempted-user 2005-2127   URL
4213BROWSER-PLUGINS Microsoft Internet Explorer DDS Picture Shape Control ActiveX object access (more info ...)attempted-user 2005-2127   URL
4214BROWSER-PLUGINS Microsoft Internet Explorer TipGW Init ActiveX object access (more info ...)attempted-user 2005-2127   URL
4215BROWSER-PLUGINS Microsoft Internet Explorer HTML Popup Window ActiveX object access (more info ...)attempted-user 2005-2127   URL
4216BROWSER-PLUGINS Microsoft Internet Explorer CLSID_CComAcctImport ActiveX object access (more info ...)attempted-user 2005-2127   URL
4221BROWSER-PLUGINS Microsoft Internet Explorer ProxyStub Dispatch ActiveX object access (more info ...)attempted-user 2005-2127   URL
4222BROWSER-PLUGINS Microsoft Internet Explorer Outllib.dll ActiveX object access (more info ...)attempted-user 2005-2127   URL
4223BROWSER-PLUGINS Microsoft Internet Explorer OpenCable Class ActiveX object access (more info ...)attempted-user 2005-2127   URL
4224BROWSER-PLUGINS Microsoft Internet Explorer VideoPort ActiveX object access (more info ...)attempted-user 2005-2127   URL
4225BROWSER-PLUGINS Microsoft Internet Explorer Repository ActiveX object access (more info ...)attempted-user 2005-2127   URL
4226BROWSER-PLUGINS Microsoft Internet Explorer DocHost User Interface Handler ActiveX object access (more info ...)attempted-user 2005-2127   URL
4227BROWSER-PLUGINS Microsoft Internet Explorer Network Connections ActiveX object access (more info ...)attempted-user 2005-2127   URL
4230BROWSER-PLUGINS Microsoft Internet Explorer Search Assistant UI ActiveX object access (more info ...)attempted-user 2005-2127   URL
4231BROWSER-PLUGINS Microsoft Internet Explorer SysTray ActiveX object access (more info ...)attempted-user 2005-2127   URL
4232BROWSER-PLUGINS Microsoft Internet Explorer SysTray Invoker ActiveX object access (more info ...)attempted-user 2005-2127   URL
4233BROWSER-PLUGINS Microsoft Internet Explorer Visual Database Tools Query Designer v7.0 ActiveX object access (more info ...)attempted-user 2005-2127   URL
4234BROWSER-PLUGINS Microsoft Internet Explorer MSVTDGridCtrl7 ActiveX object access (more info ...)attempted-user 2005-2127   URL
4235BROWSER-PLUGINS Microsoft Internet Explorer Helper Object for Java ActiveX object access (more info ...)attempted-user 2005-2127   URL
4236BROWSER-PLUGINS Microsoft Internet Explorer WMI ASDI Extension ActiveX object access (more info ...)attempted-user 2005-2127   URL
4647BROWSER-IE Microsoft Internet Explorer javascript onload overflow attempt (more info ...)attempted-user 2005-1790 13799  URL
4648BROWSER-PLUGINS Microsoft Internet Explorer wang image admin activex object access (more info ...)attempted-user    URL
4890BROWSER-PLUGINS Microsoft Internet Explorer IAVIStream & IAVIFile Proxy ActiveX object access (more info ...)attempted-user 2005-2831   URL
4891BROWSER-PLUGINS Microsoft Internet Explorer cfw Class ActiveX object access (more info ...)attempted-user 2005-2831   URL
4892BROWSER-PLUGINS Microsoft Internet Explorer MTSEvents Class ActiveX object access (more info ...)attempted-user 2005-2831   URL
4893BROWSER-PLUGINS Microsoft Internet Explorer Trident HTMLEditor ActiveX object access (more info ...)attempted-user 2005-2831   URL
4894BROWSER-PLUGINS Microsoft Internet Explorer PSEnumVariant ActiveX object access (more info ...)attempted-user 2005-2831   URL
4895BROWSER-PLUGINS Microsoft Internet Explorer PSTypeInfo ActiveX object access (more info ...)attempted-user 2005-2831   URL
4896BROWSER-PLUGINS Microsoft Internet Explorer PSTypeLib ActiveX object access (more info ...)attempted-user 2005-2831   URL
4897BROWSER-PLUGINS Microsoft Internet Explorer PSOAInterface ActiveX object access (more info ...)attempted-user 2005-2831   URL
4898BROWSER-PLUGINS Microsoft Internet Explorer PSTypeComp ActiveX object access (more info ...)attempted-user 2005-2831   URL
4899BROWSER-PLUGINS Microsoft Internet Explorer ISupportErrorInfo Interface ActiveX object access (more info ...)attempted-user 2005-2831   URL
4900BROWSER-PLUGINS Microsoft Internet Explorer Outlook Progress Ctl ActiveX object access (more info ...)attempted-user 2005-2831   URL
4901BROWSER-PLUGINS Microsoft Internet Explorer VMR Allocator Presenter 9 ActiveX object access (more info ...)attempted-user 2005-2831   URL
4902BROWSER-PLUGINS Microsoft Internet Explorer Video Mixing Renderer 9 ActiveX object access (more info ...)attempted-user 2005-2831   URL
4903BROWSER-PLUGINS Microsoft Internet Explorer VMR ImageSync 9 ActiveX object access (more info ...)attempted-user 2005-2831   URL
4904BROWSER-PLUGINS Microsoft Internet Explorer Repository Alias ActiveX object access (more info ...)attempted-user 2005-2831   URL
4905BROWSER-PLUGINS Microsoft Internet Explorer Repository Object ActiveX object access (more info ...)attempted-user 2005-2831   URL
4906BROWSER-PLUGINS Microsoft Internet Explorer Repository Interface Definition ActiveX object access (more info ...)attempted-user 2005-2831   URL
4907BROWSER-PLUGINS Microsoft Internet Explorer Repository Collection Definition ActiveX object access (more info ...)attempted-user 2005-2831   URL
4908BROWSER-PLUGINS Microsoft Internet Explorer Repository Method Definition ActiveX object access (more info ...)attempted-user 2005-2831   URL
4909BROWSER-PLUGINS Microsoft Internet Explorer Repository Property Definition ActiveX object access (more info ...)attempted-user 2005-2831   URL
4910BROWSER-PLUGINS Microsoft Internet Explorer Repository Relationship Definition ActiveX object access (more info ...)attempted-user 2005-2831   URL
4911BROWSER-PLUGINS Microsoft Internet Explorer Repository Type Library ActiveX object access (more info ...)attempted-user 2005-2831   URL
4912BROWSER-PLUGINS Microsoft Internet Explorer Repository Root ActiveX object access (more info ...)attempted-user 2005-2831   URL
4913BROWSER-PLUGINS Microsoft Internet Explorer Repository Workspace ActiveX object access (more info ...)attempted-user 2005-2831   URL
4914BROWSER-PLUGINS Microsoft Internet Explorer Repository Script Definition ActiveX object access (more info ...)attempted-user 2005-2831   URL
4915BROWSER-PLUGINS Microsoft Internet Explorer Shortcut Handler ActiveX object access (more info ...)attempted-user 2005-2831   URL
4916BROWSER-IE Microsoft Internet Explorer javascript onload document.write obfuscation overflow attempt (more info ...)attempted-user 2005-1790 13799  URL
4917BROWSER-IE Microsoft Internet Explorer javascript onload prompt obfuscation overflow attempt (more info ...)attempted-user 2005-1790 13799  URL
4982BROWSER-PLUGINS Microsoft Internet Explorer Adodb.Stream ActiveX object access (more info ...)attempted-user 2004-0549 10514  URL
6002BROWSER-PLUGINS Microsoft Internet Explorer DT DDS Rectilinear GDD Layout ActiveX object access (more info ...)attempted-user 2006-1186   URL
6003BROWSER-PLUGINS Microsoft Internet Explorer DT DDS Rectilinear GDD Route ActiveX object access (more info ...)attempted-user 2006-1186   URL
6004BROWSER-PLUGINS Microsoft Internet Explorer DT DDS Circular Auto Layout Logic 2 ActiveX object access (more info ...)attempted-user 2006-1186   URL
6005BROWSER-PLUGINS Microsoft Internet Explorer DT DDS Straight Line Routing Logic 2 ActiveX object access (more info ...)attempted-user 2006-1186   URL
6006BROWSER-PLUGINS Microsoft Internet Explorer DT Icon Control ActiveX object access (more info ...)attempted-user 2006-1186   URL
6007BROWSER-PLUGINS Microsoft Internet Explorer DT DDS OrgChart GDD Layout ActiveX object access (more info ...)attempted-user 2006-1186   URL
6502FILE-IMAGE Mozilla GIF single packet heap overflow - ANIMEXTS1.0 (more info ...)attempted-user 2005-0399 12881 17605 
6509BROWSER-IE Microsoft Internet Explorer mhtml uri href buffer overflow attempt (more info ...)attempted-user 2006-2766 18198  URL
6510BROWSER-IE Microsoft Internet Explorer mhtml uri shortcut buffer overflow attempt (more info ...)attempted-user 2006-2766 18198  URL
6516BROWSER-PLUGINS Microsoft Internet Explorer DXImageTransform.Microsoft.Light ActiveX function call access (more info ...)attempted-user 2006-2383   URL
6517BROWSER-PLUGINS Microsoft Internet Explorer DXImageTransform.Microsoft.Light ActiveX clsid access (more info ...)attempted-user 2006-2383   URL
6681BROWSER-PLUGINS Microsoft Internet Explorer DXImageTransform.Microsoft.MMSpecialEffect1Input ActiveX clsid access (more info ...)attempted-user 2006-1303 18328  URL
6682BROWSER-PLUGINS Microsoft Internet Explorer DXImageTransform.Microsoft.MMSpecialEffect2Inputs ActiveX function call access (more info ...)attempted-user 2006-1303 18328  URL
6684BROWSER-PLUGINS Microsoft Internet Explorer DXImageTransform.Microsoft.MMSpecialEffectInplace1Input ActiveX clsid access (more info ...)attempted-user 2006-1303 18328  URL
6686BROWSER-PLUGINS Microsoft Internet Explorer DXImageTransform.Microsoft.MMSpecialEffect2Inputs ActiveX clsid access (more info ...)attempted-user 2006-1303 18328  URL
6687BROWSER-PLUGINS Microsoft Internet Explorer DXImageTransform.Microsoft.MMSpecialEffect1Input ActiveX function call access (more info ...)attempted-user 2006-1303 18328  URL
7014BROWSER-PLUGINS Microsoft Internet Explorer NMSA.ASFSourceMediaDescription.1 ActiveX function call access (more info ...)attempted-dos 2006-3897 19114  
7016BROWSER-PLUGINS Microsoft Internet Explorer Object.Microsoft.DXTFilter ActiveX function call access (more info ...)attempted-dos 2006-3512 18903  
7017BROWSER-PLUGINS Microsoft Internet Explorer RDS.DataControl ActiveX function call access (more info ...)attempted-user 2006-3510 18900  
7020BROWSER-IE Microsoft Internet Explorer isComponentInstalled function buffer overflow (more info ...)attempted-user 2006-1016 16870  
7071SERVER-WEBAPP encoded cross site scripting HTML Image tag set to javascript attempt (more info ...)web-application-attack 2002-0902 4858  
7196OS-OTHER Multiple Operating Systems invalid DHCP option attempt (more info ...)attempted-admin 2019-12264 35668  URL
7425BROWSER-PLUGINS Microsoft Internet Explorer 9x8Resize ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7427BROWSER-PLUGINS Microsoft Internet Explorer Allocator Fix ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7429BROWSER-PLUGINS Microsoft Internet Explorer Bitmap ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7431BROWSER-PLUGINS Microsoft Internet Explorer DirectFrame.DirectControl.1 ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7433BROWSER-PLUGINS Microsoft Internet Explorer DirectX Transform Wrapper Property Page ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7435BROWSER-PLUGINS Microsoft Internet Explorer Dynamic Casts ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7436BROWSER-PLUGINS Microsoft Internet Explorer Dynamic Casts ActiveX function call (more info ...)attempted-user 2006-3638   URL
7437BROWSER-PLUGINS Microsoft Internet Explorer Frame Eater ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7442BROWSER-PLUGINS Microsoft Internet Explorer mmAEPlugIn.AEPlugIn.1 ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7444BROWSER-PLUGINS Microsoft Internet Explorer Mmedia.AsyncMHandler.1 ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7446BROWSER-PLUGINS Microsoft Internet Explorer Record Queue ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7448BROWSER-PLUGINS Microsoft Internet Explorer ShotDetect ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7450BROWSER-PLUGINS Microsoft Internet Explorer Stetch ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7452BROWSER-PLUGINS Microsoft Internet Explorer WM Color Converter Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7454BROWSER-PLUGINS Microsoft Internet Explorer Wmm2ae.dll ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7456BROWSER-PLUGINS Microsoft Internet Explorer Wmm2fxa.dll ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7458BROWSER-PLUGINS Microsoft Internet Explorer Wmm2fxb.dll ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7460BROWSER-PLUGINS Microsoft Internet Explorer WMT Audio Analyzer ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7462BROWSER-PLUGINS Microsoft Internet Explorer WMT Black Frame Generator ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7464BROWSER-PLUGINS Microsoft Internet Explorer WMT DeInterlace Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7466BROWSER-PLUGINS Microsoft Internet Explorer WMT DeInterlace Prop Page ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7468BROWSER-PLUGINS Microsoft Internet Explorer WMT DirectX Transform Wrapper ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7470BROWSER-PLUGINS Microsoft Internet Explorer WMT DV Extract Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7472BROWSER-PLUGINS Microsoft Internet Explorer WMT FormatConversion Prop Page ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7474BROWSER-PLUGINS Microsoft Internet Explorer WMT FormatConversion ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7476BROWSER-PLUGINS Microsoft Internet Explorer WMT Import Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7478BROWSER-PLUGINS Microsoft Internet Explorer WMT Interlacer ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7480BROWSER-PLUGINS Microsoft Internet Explorer WMT Log Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7482BROWSER-PLUGINS Microsoft Internet Explorer WMT MuxDeMux Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7484BROWSER-PLUGINS Microsoft Internet Explorer WMT Sample Info Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7486BROWSER-PLUGINS Microsoft Internet Explorer WMT Screen Capture Filter Task Page ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7488BROWSER-PLUGINS Microsoft Internet Explorer WMT Screen capture Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7490BROWSER-PLUGINS Microsoft Internet Explorer WMT Switch Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7492BROWSER-PLUGINS Microsoft Internet Explorer WMT Virtual Renderer ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7494BROWSER-PLUGINS Microsoft Internet Explorer WMT Virtual Source ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7496BROWSER-PLUGINS Microsoft Internet Explorer WMT Volume ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7498BROWSER-PLUGINS Microsoft Internet Explorer WM TV Out Smooth Picture Filter ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7500BROWSER-PLUGINS Microsoft Internet Explorer WM VIH2 Fix ActiveX clsid access (more info ...)attempted-user 2006-3638   URL
7904BROWSER-PLUGINS Microsoft Internet Explorer CDL Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user 2007-0218   URL
7928BROWSER-PLUGINS Microsoft Internet Explorer file or local Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user 2007-0218   URL
7938BROWSER-PLUGINS Microsoft Internet Explorer gopher Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user 2007-0218   URL
7942BROWSER-PLUGINS Microsoft Internet Explorer http Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user 2007-0218   URL
7944BROWSER-PLUGINS Microsoft Internet Explorer https Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user 2007-0218   URL
7958BROWSER-PLUGINS Microsoft Internet Explorer mk Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user 2007-0218   URL
7970BROWSER-PLUGINS Microsoft Internet Explorer PostBootReminder object ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
7976BROWSER-PLUGINS Microsoft Internet Explorer ShellFolder for CD Burning ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
7989BROWSER-PLUGINS Microsoft Internet Explorer WIA FileSystem USD ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
7991BROWSER-PLUGINS Microsoft Internet Explorer ACM Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
7993BROWSER-PLUGINS Microsoft Internet Explorer clbcatex.dll ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
7995BROWSER-PLUGINS Microsoft Internet Explorer clbcatq.dll ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
7997BROWSER-PLUGINS Microsoft Internet Explorer CLSID_ApprenticeICW ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
7999BROWSER-PLUGINS Microsoft Internet Explorer CLSID_CDIDeviceActionConfigPage ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8001BROWSER-PLUGINS Microsoft Internet Explorer CommunicationManager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8003BROWSER-PLUGINS Microsoft Internet Explorer Content.mbcontent.1 ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8005BROWSER-PLUGINS Microsoft Internet Explorer DiskManagement.Connection ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8007BROWSER-PLUGINS Microsoft Internet Explorer Dutch_Dutch Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8009BROWSER-PLUGINS Microsoft Internet Explorer English_UK Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8011BROWSER-PLUGINS Microsoft Internet Explorer English_US Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8013BROWSER-PLUGINS Microsoft Internet Explorer French_French Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8015BROWSER-PLUGINS Microsoft Internet Explorer German_German Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8017BROWSER-PLUGINS Microsoft Internet Explorer ICM Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8019BROWSER-PLUGINS Microsoft Internet Explorer Address Bar ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8021BROWSER-PLUGINS Microsoft Internet Explorer ISSimpleCommandCreator.1 ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8023BROWSER-PLUGINS Microsoft Internet Explorer Italian_Italian Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8029BROWSER-PLUGINS Microsoft Internet Explorer MidiOut Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8031BROWSER-PLUGINS Microsoft Internet Explorer Mslablti.MarshalableTI.1 ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8033BROWSER-PLUGINS Microsoft Internet Explorer QC.MessageMover.1 ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8035BROWSER-PLUGINS Microsoft Internet Explorer Spanish_Modern Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8037BROWSER-PLUGINS Microsoft Internet Explorer Swedish_Default Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8039BROWSER-PLUGINS Microsoft Internet Explorer syncui.dll ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8041BROWSER-PLUGINS Microsoft Internet Explorer VFW Capture Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8043BROWSER-PLUGINS Microsoft Internet Explorer Video Effect Class Manager 1 Input ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8045BROWSER-PLUGINS Microsoft Internet Explorer Video Effect Class Manager 2 Input ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8047BROWSER-PLUGINS Microsoft Internet Explorer WaveIn Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8049BROWSER-PLUGINS Microsoft Internet Explorer WaveOut and DSound Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8051BROWSER-PLUGINS Microsoft Internet Explorer WDM Instance Provider ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
8058BROWSER-FIREFOX Mozilla javascript navigator object access (more info ...)attempted-user 2006-3677 19181  URL
8064BROWSER-PLUGINS Microsoft Internet Explorer Scriptlet.Typelib ActiveX clsid access (more info ...)attempted-user 2000-1061 598  URL
8369BROWSER-PLUGINS Microsoft Internet Explorer WMIScriptUtils.WMIObjectBroker2.1 ActiveX clsid access attempt (more info ...)attempted-user 2006-4704   URL
8405BROWSER-PLUGINS Microsoft Internet Explorer ActiveX clsid access (more info ...)attempted-user 2006-5745 20915  URL
8443BROWSER-FIREFOX Mozilla regular expression heap corruption attempt (more info ...)attempted-user 2006-4566 20042  
8741BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAFontStyle.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8743BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAFontStyle.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8744BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAEvent.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8746BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAEvent.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8747BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAEndStyle.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8749BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAEndStyle.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8750BROWSER-PLUGINS Microsoft Internet Explorer LM.LMBehaviorFactory.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8752BROWSER-PLUGINS Microsoft Internet Explorer LM.LMBehaviorFactory.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8753BROWSER-PLUGINS Microsoft Internet Explorer LM.AutoEffectBvr.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8755BROWSER-PLUGINS Microsoft Internet Explorer LM.AutoEffectBvr.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8756BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.SpriteControl ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8758BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.SpriteControl ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8759BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.SequencerControl ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8761BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.SequencerControl ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8762BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.Sequence ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8764BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.Sequence ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8765BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAView.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8767BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAView.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8768BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAVector3.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8770BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAVector3.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8771BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAVector2.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8773BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAVector2.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8774BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAUserData.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8776BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAUserData.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8777BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DATransform3.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8779BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DATransform3.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8780BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DATransform2.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8782BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DATransform2.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8783BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAString.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8785BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAString.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8786BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DASound.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8788BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DASound.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8789BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAPoint3.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8791BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAPoint3.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8792BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAPoint2.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8794BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAPoint2.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8795BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAPath2.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8797BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAPath2.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8798BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAPair.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8800BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAPair.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8801BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DANumber.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8803BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DANumber.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8804BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAMontage.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8806BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAMontage.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8807BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAMicrophone.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8809BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAMicrophone.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8810BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAMatte.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8812BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAMatte.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8813BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DALineStyle.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8815BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DALineStyle.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8816BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAJoinStyle.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8818BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAJoinStyle.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8819BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAImage.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8821BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAImage.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8822BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAGeometry.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8824BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAGeometry.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8825BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DADashStyle.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8827BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DADashStyle.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8828BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAColor.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8830BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAColor.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8831BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DACamera.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8833BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DACamera.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8834BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DABoolean.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8836BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DABoolean.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8837BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DABbox3.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8839BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DABbox3.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8840BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DABbox2.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8842BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DABbox2.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
8843BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAArray.1 ActiveX clsid access (more info ...)attempted-user 2006-4777   URL
8845BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAArray.1 ActiveX function call access (more info ...)attempted-user 2006-4777   URL
9843FILE-PDF Adobe Acrobat Plugin JavaScript parameter double free attempt (more info ...)attempted-user 2007-0046   URL
10062FILE-IMAGE Oracle Java Virtual Machine malformed GIF buffer overflow attempt (more info ...)attempted-user 2007-0243 22085  
10063BROWSER-FIREFOX Mozilla Firefox query interface suspicious function call access attempt (more info ...)attempted-user 2006-0295 16476  URL
10131BROWSER-FIREFOX Mozilla compareTo arbitrary code execution attempt (more info ...)attempted-user 2005-2265 14242  URL
11000SERVER-ORACLE dbms_snap_internal.delete_refresh_operations buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  URL
11001SERVER-ORACLE dbms_snap_internal.delete_refresh_operations buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  URL
11002SERVER-ORACLE dbms_snap_internal.generate_refresh_operations buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  URL
11003SERVER-ORACLE dbms_snap_internal.generate_refresh_operations buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  URL
11224BROWSER-PLUGINS Microsoft Internet Explorer MSAuth ActiveX clsid access (more info ...)attempted-user 2007-2221   URL
11226BROWSER-PLUGINS Microsoft Internet Explorer MSAuth ActiveX function call access (more info ...)attempted-user 2007-2221   URL
11243BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAstatics ActiveX clsid access (more info ...)attempted-user    URL
11245BROWSER-PLUGINS Microsoft Internet Explorer DirectAnimation.DAstatics ActiveX function call access (more info ...)attempted-user    URL
11247BROWSER-PLUGINS Microsoft Internet Explorer Research In Motion TeamOn Import ActiveX clsid access (more info ...)attempted-user 2007-0323 23331  URL
11252BROWSER-PLUGINS Microsoft Internet Explorer Address ActiveX clsid access (more info ...)attempted-user    URL
11301BROWSER-PLUGINS Microsoft Internet Explorer DB Software Laboratory DeWizardX ActiveX clsid access (more info ...)attempted-user 2007-2725 23986  URL
11303BROWSER-PLUGINS Microsoft Internet Explorer DB Software Laboratory DeWizardX ActiveX function call access (more info ...)attempted-user 2007-2725 23986  URL
11834BROWSER-IE Microsoft Internet Explorer navcancl.htm url spoofing attempt (more info ...)misc-attack 2007-1499 22966  URL
11966BROWSER-IE Microsoft Internet Explorer CSS tag memory corruption attempt (more info ...)attempted-user 2007-1750 24423  URL
12014BROWSER-IE Microsoft Internet Explorer navcancl.htm url spoofing attempt (more info ...)misc-attack 2007-1499 22966  URL
12277BROWSER-IE Microsoft Internet Explorer CSS memory corruption exploit (more info ...)attempted-user 2007-0943   URL
12281BROWSER-IE Microsoft Internet Explorer VML source file memory corruption attempt (more info ...)attempted-user 2007-1749 25310  URL
12282BROWSER-IE Microsoft Internet Explorer VML source file memory corruption attempt (more info ...)attempted-user 2007-1749 25310  URL
12593BROWSER-FIREFOX Mozilla Firefox Apple Quicktime chrome exploit (more info ...)attempted-user 2007-5045   
12664BROWSER-IE Microsoft Windows ShellExecute and Internet Explorer 7 url handling code execution attempt (more info ...)attempted-user 2007-3896 25945  URL
12954BROWSER-PLUGINS Microsoft Internet Explorer DXLTPI.DLL ActiveX clsid access (more info ...)attempted-user    URL
12957BROWSER-PLUGINS Microsoft Internet Explorer MSN Heartbeat 2 ActiveX clsid access (more info ...)attempted-user    URL
12959BROWSER-PLUGINS Microsoft Internet Explorer MSN Heartbeat 3 ActiveX clsid access (more info ...)attempted-user    URL
13453BROWSER-IE Microsoft Internet Explorer DXLUTBuilder ActiveX clsid access (more info ...)attempted-user 2008-0078   URL
13454BROWSER-IE Microsoft Internet Explorer DXLUTBuilder ActiveX clsid unicode access (more info ...)attempted-user 2008-0078   URL
13456BROWSER-IE Microsoft Internet Explorer DXLUTBuilder ActiveX function call unicode access (more info ...)attempted-user 2008-0078   URL
13828BROWSER-PLUGINS Microsoft Internet Explorer sapi.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-0675   URL
13830BROWSER-PLUGINS Microsoft Internet Explorer sapi.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-0675   URL
13832BROWSER-PLUGINS Microsoft Internet Explorer backweb ActiveX clsid access (more info ...)attempted-user 2007-0675   URL
13834BROWSER-IE Microsoft Internet Explorer request header overwrite (more info ...)misc-activity 2008-1544 28379  URL
13838BROWSER-FIREFOX Mozilla Firefox IFRAME style change handling code execution (more info ...)attempted-user 2008-1236 28448  URL
13840SERVER-OTHER Borland Interbase service attach operation buffer overflow (more info ...)attempted-admin 2007-5243   
13841SERVER-OTHER Borland Interbase create operation buffer overflow (more info ...)attempted-admin 2007-5243   
13842SERVER-OTHER Borland Interbase operation buffer overflow (more info ...)attempted-admin 2007-5243   
13912BROWSER-IE Microsoft Internet Explorer isComponentInstalled attack attempt (more info ...)attempted-user 2006-1016 16870  
13932MALWARE-CNC User-Agent known malicious user agent - opera (more info ...)successful-recon-limited    URL
13960BROWSER-IE Microsoft Internet Explorer static text range overflow attempt (more info ...)attempted-user 2008-2255   URL
13961BROWSER-IE Microsoft Internet Explorer table layout access violation vulnerability (more info ...)misc-attack 2008-2258   URL
13963BROWSER-IE Microsoft Internet Explorer argument validation in print preview handling exploitation attempt (more info ...)attempted-user 2008-2259 30612  URL
14615SERVER-OTHER Oracle Java web console format string attempt (more info ...)attempted-user 2007-1681   
15081FILE-JAVA Oracle Java Web Start xml encoding buffer overflow attempt (more info ...)attempted-admin 2008-1188 28083  URL
15109BROWSER-PLUGINS Microsoft Internet Explorer Shell.Explorer 1 ActiveX clsid access (more info ...)attempted-user 2008-4258   URL
15112BROWSER-PLUGINS Microsoft Internet Explorer Shell.Explorer 2 ActiveX function call access (more info ...)attempted-user 2008-4258 11466  URL
15114BROWSER-IE Microsoft Internet Explorer embed src buffer overflow attempt (more info ...)attempted-user 2008-4261   URL
15122BROWSER-PLUGINS Microsoft Internet Explorer Shell.Explorer 2 ActiveX clsid access (more info ...)attempted-user 2008-4258 11466  URL
15126BROWSER-IE Microsoft Internet Explorer nested tag memory corruption attempt (more info ...)attempted-user 2008-4844 32721  URL
15164BROWSER-FIREFOX Mozilla Firefox SVG pathSegList memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
15238FILE-MULTIMEDIA Apple QuickTime for Java toQTPointer function memory corruption attempt (more info ...)attempted-user 2007-2175 23608  
15300BROWSER-IE Microsoft Internet Explorer EMF polyline overflow attempt (more info ...)attempted-user 2009-0081   URL
15304BROWSER-IE Microsoft Internet Explorer object clone deletion memory corruption attempt (more info ...)attempted-user 2009-0075   URL
15305BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
15328FILE-JAVA Sun JDK image parsing library ICC buffer overflow attempt (more info ...)attempted-user 2007-2788 24004  URL
15363INDICATOR-OBFUSCATION Potential obfuscated javascript eval unescape attack attempt (more info ...)misc-activity    URL
15383BROWSER-FIREFOX Mozilla Firefox XBL Event Handler Tags Removal memory corruption attempt (more info ...)attempted-user 2007-5339 26132  
15431BROWSER-FIREFOX Mozilla Firefox 3 xsl parsing heap overflow attempt (more info ...)attempted-user 2009-1169 34235  URL
15458BROWSER-IE Microsoft Internet Explorer navigating between pages race condition attempt (more info ...)attempted-user 2009-0551   URL
15459BROWSER-IE Microsoft Internet Explorer deleted/unitialized object memory corruption attempt (more info ...)attempted-user 2009-0552   URL
15460BROWSER-IE Microsoft Internet Explorer ActiveX load/unload race condition attempt (more info ...)attempted-user 2009-0553   URL
15529BROWSER-IE Microsoft Internet Explorer cross-domain navigation cookie stealing attempt (more info ...)misc-attack 2007-3091   URL
15531BROWSER-IE Microsoft Internet Explorer Unexpected method call remote code execution attempt (more info ...)attempted-user 2009-1141   URL
15534BROWSER-IE Microsoft Internet Explorer XML HttpRequest race condition exploit attempt (more info ...)attempted-user 2009-1528   URL
15535BROWSER-IE Microsoft Internet Explorer setCapture heap corruption exploit attempt (more info ...)attempted-user 2009-1529   URL
15538BROWSER-IE Microsoft Internet Explorer onreadystatechange memory corruption attempt (more info ...)misc-attack 2009-1531   URL
15540BROWSER-IE Microsoft Internet Explorer layout object use after free attempt (more info ...)attempted-admin 2009-1532   URL
15678BROWSER-PLUGINS Microsoft DirectShow ActiveX exploit via JavaScript (more info ...)attempted-user 2008-0015   URL
15679BROWSER-PLUGINS Microsoft DirectShow ActiveX exploit via JavaScript - unicode encoding (more info ...)attempted-user 2008-0015   URL
15697INDICATOR-OBFUSCATION rename of javascript unescape function detected (more info ...)misc-activity    URL
15698INDICATOR-SHELLCODE Possible generic javascript heap spray attempt (more info ...)attempted-user 2009-2477 35660  
15699BROWSER-FIREFOX Mozilla Firefox 3.5 unicode stack overflow attempt (more info ...)attempted-user 2009-2479 35707  
15731BROWSER-IE Microsoft Internet Explorer javascript deleted reference arbitrary code execution attempt (more info ...)attempted-user 2009-1917   URL
15732BROWSER-IE Microsoft Internet Explorer CSS handling memory corruption attempt (more info ...)attempted-user 2009-1919   URL
15880BROWSER-IE Microsoft Internet Explorer popup window object tag code execution attempt (more info ...)attempted-user 2003-0838   
15910BROWSER-IE Microsoft Internet Explorer getElementById object corruption attempt (more info ...)attempted-user 2008-2254 30614  URL
15924BROWSER-PLUGINS Microsoft Internet Explorer DHTML Editing ActiveX clsid access (more info ...)attempted-user 2009-2519 36280  URL
15933BROWSER-IE Microsoft Internet Explorer URL canonicalization address bar spoofing attempt (more info ...)misc-activity 2003-1025   URL
15997BROWSER-FIREFOX Mozilla Firefox JIT escape function memory corruption attempt (more info ...)attempted-user 2009-2477 35660  URL
15999BROWSER-FIREFOX Mozilla products frame comment objects manipulation memory corruption attempt (more info ...)attempted-user 2006-6504 21668  
16000FILE-IMAGE Sun Microsystems Java gif handling memory corruption attempt (more info ...)attempted-user 2007-0243 22085  
16005BROWSER-FIREFOX Mozilla browsers JavaScript argument passing code execution attempt (more info ...)attempted-user 2007-0777 22694  
16007BROWSER-IE Microsoft Internet Explorer colgroup tag uninitialized memory exploit attempt (more info ...)attempted-user 2007-0944 23771  URL
16009BROWSER-FIREFOX Mozilla products overflow event handling memory corruption attempt (more info ...)attempted-user 2007-2876 24376  
16010BROWSER-IE Microsoft Internet Explorer Javascript Page update race condition attempt (more info ...)misc-activity 2007-3091 24283  
16011BROWSER-IE Microsoft Internet Explorer CSS property method handling memory corruption attempt (more info ...)attempted-user 2007-0945 23769  
16024BROWSER-FIREFOX Mozilla Firefox Javascript Function focus overflow attempt (more info ...)attempted-user 2006-1993 17671  
16031BROWSER-IE Microsoft Internet Explorer nested object tag memory corruption attempt (more info ...)attempted-user 2006-1992 17658  
16033BROWSER-IE Microsoft Internet Explorer compressed content attempt (more info ...)attempted-user 2006-3873 19987  
16035BROWSER-IE Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user 2006-1359 17196  URL
16036BROWSER-FIREFOX Mozilla Products QueryInterface method memory corruption attempt (more info ...)attempted-user 2006-0295 16476  
16037BROWSER-FIREFOX Mozilla products graphics and XML features integer overflows attempt (more info ...)attempted-user 2006-0297 16476  
16038BROWSER-FIREFOX Mozilla Thunderbird WYSIWYG engine filtering IFRAME JavaScript execution attempt (more info ...)attempted-user 2006-0884 16770  
16042BROWSER-FIREFOX Mozilla browsers CSS moz-binding cross domain scripting attempt (more info ...)attempted-user 2006-0496 16427  
16043BROWSER-IE Microsoft Internet Explorer html tag memory corruption attempt (more info ...)attempted-dos 2006-1188 17468  
16044BROWSER-FIREFOX Mozilla Firefox CSS Letter-Spacing overflow attempt (more info ...)attempted-user 2006-1730 17516  
16045BROWSER-IE Microsoft Internet Explorer cross domain information disclosure attempt (more info ...)attempted-user 2006-3280 18682  
16047BROWSER-FIREFOX Mozilla Firefox layout frame constructor memory corruption attempt (more info ...)attempted-user 2007-5959   
16050BROWSER-FIREFOX Mozilla Firefox tag order memory corruption attempt (more info ...)attempted-user 2006-0749 17516  
16063BROWSER-IE Microsoft Internet Explorer isindex buffer overflow attempt (more info ...)attempted-user 2008-0076 27668  URL
16064BROWSER-IE Microsoft Internet Explorer onBeforeUnload address bar spoofing attempt (more info ...)misc-activity 2007-3826 24911  URL
16065BROWSER-IE Microsoft Internet Explorer location.replace memory corruption attempt (more info ...)attempted-user 2007-5347 26427  URL
16067BROWSER-IE Microsoft Internet Explorer DOM object cache management memory corruption attempt (more info ...)attempted-user 2007-5344   
16142BROWSER-FIREFOX Mozilla Firefox PKCS11 module installation code execution attempt (more info ...)attempted-user 2009-3076 36343  
16145BROWSER-WEBKIT Apple Safari Webkit floating point buffer overflow attempt (more info ...)attempted-user 2009-2195 36023  
16149BROWSER-IE Microsoft Internet Explorer data stream header remote code execution attempt (more info ...)attempted-user 2009-1547   URL
16150BROWSER-IE Microsoft Internet Explorer variant argument validation remote code execution attempt (more info ...)misc-activity 2009-2529   URL
16151BROWSER-IE Microsoft Internet Explorer uninitialized or deleted object access attempt (more info ...)misc-activity 2009-2530   URL
16152BROWSER-IE Microsoft Internet Explorer table layout unitialized or deleted object access attempt (more info ...)misc-activity 2009-2531   URL
16155BROWSER-IE Microsoft Internet Explorer indexing service malformed parameters (more info ...)attempted-user 2009-2507   URL
16169BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
16200BROWSER-FIREFOX Mozilla Firefox command line URL shell command injection attempt (more info ...)attempted-user 2005-2968 14888  
16284BROWSER-FIREFOX Mozilla Firefox ClearTextRun exploit attempt (more info ...)attempted-user 2009-1313 34743  
16288FILE-JAVA Oracle Java Runtime AWT setDiffICM stack buffer overflow attempt (more info ...)attempted-user 2009-3869 36881  
16291BROWSER-FIREFOX Mozilla Network Security Services regexp heap overflow attempt (more info ...)attempted-user 2009-2404 35891  
16292BROWSER-FIREFOX Mozilla CSS value counter overflow attempt (more info ...)attempted-user 2008-2785 29802  URL
16310BROWSER-IE Microsoft Internet Explorer 6/7 single line outerHTML invalid reference arbitrary code execution attempt (more info ...)attempted-user 2009-3672 37085  URL
16311BROWSER-IE Microsoft Internet Explorer 6/7 single line outerHTML invalid reference arbitrary code execution attempt (more info ...)attempted-user 2009-3672 37085  URL
16317BROWSER-IE Microsoft Internet Explorer mouse move during refresh memory corruption attempt (more info ...)attempted-user 2009-3673   URL
16326BROWSER-IE Microsoft Internet Explorer 8 DOM memory corruption attempt (more info ...)attempted-user 2010-0246   URL
16330BROWSER-IE Microsoft Internet Explorer orphan DOM objects memory corruption attempt (more info ...)attempted-user 2009-3674   URL
16339BROWSER-IE Microsoft Internet Explorer object clone deletion memory corruption attempt - obfuscated (more info ...)attempted-user 2009-0075   URL
16367BROWSER-IE Microsoft Internet Explorer invalid object access memory corruption attempt (more info ...)attempted-user 2010-0249   URL
16369BROWSER-IE Microsoft Internet Explorer deleted object access memory corruption attempt (more info ...)attempted-user 2010-0249   URL
16376BROWSER-IE Microsoft Internet Explorer CTableLayout memory corruption attempt (more info ...)attempted-user 2010-0244 37891  URL
16377BROWSER-IE Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt (more info ...)misc-activity 2011-0094 37893  URL
16378BROWSER-IE Microsoft Internet Explorer deleted object cells reference memory corruption vulnerability (more info ...)attempted-user 2010-0248   
16382BROWSER-IE Microsoft Internet Explorer HTML+TIME animatemotion property memory corruption attempt (more info ...)attempted-user 2008-0077 27666  URL
16392SERVER-WEBAPP Oracle Java System Web Server 7.0u7 authorization digest heap overflow (more info ...)attempted-user 2010-0387 37896  
16423BROWSER-IE Microsoft Internet Explorer 7/8 execute local file in Internet zone redirect attempt (more info ...)attempted-user 2010-0555   URL
16426SERVER-WEBAPP Oracle Java System Web Server 7.0 WebDAV format string exploit attempt - PROPFIND method (more info ...)attempted-user 2010-0388 37910  
16427SERVER-WEBAPP Oracle Java System Web Server 7.0 WebDAV format string exploit attempt - LOCK method (more info ...)attempted-user 2010-0388 37910  
16452BROWSER-IE Microsoft Internet Explorer .hlp samba share download attempt (more info ...)attempted-user 2010-0483   
16481BROWSER-OTHER Opera Content-Length header integer overflow attempt (more info ...)attempted-user 2010-1349 38519  URL
16492BROWSER-WEBKIT Apple Safari inline text box use after free attempt (more info ...)attempted-user 2010-0049   
16501BROWSER-FIREFOX Mozilla Firefox WOFF font processing integer overflow attempt (more info ...)attempted-user 2010-1028 38298  URL
16502BROWSER-FIREFOX Mozilla Firefox WOFF font processing integer overflow attempt - CFF-based (more info ...)attempted-user 2010-1028 38298  URL
16503BROWSER-IE Microsoft Internet Explorer event handling remote code execution attempt (more info ...)attempted-user 2010-0267   URL
16504BROWSER-IE Microsoft Internet Explorer 7 encoded content handling exploit attempt (more info ...)misc-attack 2010-0488   URL
16505BROWSER-IE Microsoft Internet Explorer HTML parsing memory corruption attempt (more info ...)attempted-user 2010-0489   URL
16506BROWSER-IE Microsoft Internet Explorer innerHTML against incomplete element heap corruption attempt (more info ...)attempted-user 2010-0490 39031  URL
16507BROWSER-IE Microsoft Internet Explorer onreadystatechange memory corruption attempt (more info ...)attempted-user 2010-0491   URL
16508BROWSER-IE Microsoft Internet Explorer 8 non-IE8 compatibility mode htmltime remote code execution attempt (more info ...)attempted-user 2010-0492   URL
16509BROWSER-IE Microsoft Internet Explorer designMode-enabled information disclosure attempt (more info ...)misc-attack 2010-0494   URL
16511BROWSER-PLUGINS Microsoft Internet Explorer Tabular Control ActiveX overflow by ProgID (more info ...)attempted-user 2010-0805   URL
16512BROWSER-IE Microsoft Internet Explorer malformed span/div html document heap corruption attempt (more info ...)attempted-user 2010-0807   URL
16549FILE-OTHER Oracle JRE Java Platform SE and Java Deployment Toolkit plugins code execution attempt - npruntime-scriptable-plugin (more info ...)attempted-user 2010-1423 39346  
16550FILE-OTHER Oracle JRE Java Platform SE and Java Deployment Toolkit plugins code execution attempt - java-deployment-toolkit (more info ...)attempted-user 2010-1423 39346  
16554FILE-PDF Adobe Acrobat Reader javascript getIcon method buffer overflow attempt (more info ...)attempted-user 2009-0927 34169  
16584BROWSER-IE Oracle Java Web Start arbitrary command execution attempt - Internet Explorer (more info ...)attempted-user 2010-1423 39346  
16592BROWSER-OTHER Opera asynchronous document modifications attempted memory corruption (more info ...)attempted-user    URL
16596BROWSER-WEBKIT Apple Safari information disclosure and remote code execution attempt (more info ...)attempted-user 2010-1939   URL
16602BROWSER-PLUGINS Microsoft DirectShow 3 ActiveX exploit via JavaScript (more info ...)attempted-user 2008-0015   URL
16605BROWSER-IE Microsoft Internet Explorer nested SPAN tag memory corruption attempt (more info ...)attempted-user 2008-4844 32721  
16635BROWSER-PLUGINS Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access (more info ...)attempted-user 2010-0811   URL
16637BROWSER-IE Microsoft Internet Explorer security zone restriction bypass attempt (more info ...)attempted-user 2010-0255   URL
16658BROWSER-IE Microsoft Internet Explorer 8 cross-site scripting attempt (more info ...)attempted-user 2010-1257   URL
16659BROWSER-IE Microsoft Internet Explorer style sheet array memory corruption attempt (more info ...)attempted-user 2011-0027 40410  URL
16666BROWSER-WEBKIT Apple Safari window.parent.close unspecified remote code execution vulnerability (more info ...)attempted-user 2010-1939 39990  URL
16690BROWSER-IE Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user 2006-1359 17196  URL
17058MALWARE-CNC Trojan-Downloader.JS.Agent.ewh Javascript download (more info ...)trojan-activity    URL
17109SERVER-ORACLE Oracle Java Web Console logging functionality format string exploit attempt (more info ...)attempted-admin 2007-1681 23539  
17111INDICATOR-OBFUSCATION known JavaScript obfuscation routine (more info ...)attempted-user    URL
17115BROWSER-IE Microsoft Internet Explorer cross domain information disclosure attempt (more info ...)attempted-user 2010-1258   URL
17130BROWSER-IE Microsoft Internet Explorer boundElements arbitrary code execution attempt (more info ...)attempted-user 2010-2557 42288  URL
17131BROWSER-IE Microsoft Internet Explorer 8 parent style rendering arbitrary code execution (more info ...)attempted-user 2010-2559   URL
17132BROWSER-IE Microsoft Internet Explorer invalid object access attempt (more info ...)attempted-user 2010-2560   URL
17136BROWSER-IE Microsoft Internet Explorer 6 race condition exploit attempt (more info ...)attempted-user 2010-2558   URL
17165BROWSER-OTHER Opera browser document writing uninitialized memory access attempt (more info ...)attempted-user 2010-1728 39855  
17212BROWSER-FIREFOX Mozilla Firefox JavaScript eval arbitrary code execution attempt (more info ...)attempted-user 2005-1532 13645  URL
17213BROWSER-FIREFOX Mozilla Firefox Chrome Page Loading Restriction Bypass attempt (more info ...)attempted-user 2005-2706   URL
17216BROWSER-WEBKIT Apple Safari TABLE tag with large CELLSPACING attribute exploit attempt (more info ...)attempted-user 2006-1986 17634  
17217BROWSER-WEBKIT Apple Safari invalid FRAME tag remote code execution attempt (more info ...)attempted-user 2006-1987 17634  
17218BROWSER-WEBKIT Apple Safari LI tag with large VALUE attribute exploit attempt (more info ...)attempted-user 2006-1988 17634  
17219BROWSER-FIREFOX Mozilla Firefox domain name handling buffer overflow attempt (more info ...)attempted-user 2005-2871 14784  
17220BROWSER-FIREFOX Mozilla Firefox domain name handling buffer overflow attempt (more info ...)attempted-user 2005-2871 14784  
17221BROWSER-FIREFOX Mozilla Firefox domain name handling buffer overflow attempt (more info ...)attempted-user 2005-2871 14784  
17222BROWSER-FIREFOX Mozilla Firefox domain name handling buffer overflow attempt (more info ...)attempted-user 2005-2871 14784  
17258BROWSER-FIREFOX Mozilla Firefox XUL tree element code execution attempt (more info ...)attempted-user 2009-1044 34181  
17260BROWSER-FIREFOX Mozilla Firefox Javascript contentWindow in an iframe exploit attempt (more info ...)attempted-user 2006-1993 17671  
17261BROWSER-IE Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user 2006-1359 17196  URL
17262BROWSER-IE Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user 2006-1359 17196  URL
17263BROWSER-IE Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user 2006-1359 17196  URL
17265BROWSER-FIREFOX Mozilla Firefox plugin access control bypass attempt (more info ...)attempted-user 2005-0527 12655  URL
17268BROWSER-FIREFOX Mozilla Firefox sidebar panel arbitrary code execution attempt (more info ...)attempted-user 2005-0402 12884  
17303BROWSER-IE Microsoft Internet Explorer clone object memory corruption attempt (more info ...)attempted-user 2007-3903 26816  
17311BROWSER-IE Microsoft Internet Explorer CSS import cross-domain restriction bypass attempt (more info ...)attempted-user 2005-4089 15660  
17312BROWSER-IE Microsoft Internet Explorer CSS import cross-domain restriction bypass attempt (more info ...)attempted-user 2005-4089 15660  
17360BROWSER-FIREFOX Mozilla Firefox XBM image processing buffer overflow attempt (more info ...)attempted-user 2005-2701 14916  
17384BROWSER-IE Microsoft Internet Explorer setRequestHeader overflow attempt (more info ...)attempted-user 2008-1544 28379  
17385BROWSER-IE Microsoft Internet Explorer setRequestHeader overflow attempt (more info ...)attempted-user 2008-1544 28379  
17389BROWSER-FIREFOX Mozilla Firefox DOMNodeRemoved attack attempt (more info ...)attempted-user 2006-2779 18228  
17392INDICATOR-SHELLCODE JavaScript var shellcode (more info ...)shellcode-detect    
17393INDICATOR-SHELLCODE JavaScript var heapspray (more info ...)shellcode-detect    
17395FILE-IMAGE Oracle Java Web Start Splashscreen GIF decoding buffer overflow attempt (more info ...)attempted-user 2008-2086   
17400INDICATOR-OBFUSCATION rename of javascript unescape function detected (more info ...)misc-activity    URL
17401BROWSER-IE Microsoft Internet Explorer nested tag memory corruption attempt - unescaped (more info ...)attempted-user 2008-4844 32721  URL
17402BROWSER-IE Microsoft Internet Explorer nested tag memory corruption attempt (more info ...)attempted-user 2008-4844 32721  URL
17411BROWSER-IE Microsoft Internet Explorer CDF cross-domain scripting attempt (more info ...)attempted-user 2005-0056 12427  URL
17414BROWSER-FIREFOX Mozilla Firefox Javascript Engine Information Disclosure attempt (more info ...)attempted-user 2005-0989 12998  
17415BROWSER-FIREFOX Mozilla Firefox Javascript Engine Information Disclosure attempt (more info ...)attempted-user 2005-0989 12998  
17424BROWSER-FIREFOX Mozilla Firefox IconURL Arbitrary Javascript Execution attempt (more info ...)attempted-user 2005-1477 13544  
17434BROWSER-FIREFOX Mozilla Firefox Unicode sequence handling stack corruption attempt (more info ...)attempted-user 2005-2702 14918  
17444BROWSER-FIREFOX Mozilla Firefox 3 xsl parsing heap overflow attempt (more info ...)attempted-user 2009-1169 34235  URL
17448BROWSER-IE Microsoft Internet Explorer HTTPS proxy information disclosure vulnerability (more info ...)misc-attack 2005-2830   URL
17462BROWSER-IE Microsoft Internet Explorer marquee object handling memory corruption attempt (more info ...)attempted-user 2009-0554   URL
17463BROWSER-IE Microsoft Internet Explorer File Download Dialog Box Manipulation (more info ...)attempted-user 2005-2829 15823  URL
17471FILE-PDF Adobe Acrobat JavaScript getIcon method buffer overflow attempt (more info ...)attempted-user 2009-0927 34169  
17472FILE-PDF Adobe Acrobat JavaScript getIcon method buffer overflow attempt (more info ...)attempted-user 2009-0927 34169  
17482BROWSER-FIREFOX Mozilla NNTP URL Handling Buffer Overflow attempt (more info ...)attempted-user 2004-1316 12131  
17487BROWSER-IE Microsoft Internet Explorer Script Engine Stack Exhaustion Denial of Service attempt (more info ...)attempted-dos 2006-0753 16687  
17494BROWSER-IE Microsoft Internet Explorer long URL buffer overflow attempt (more info ...)attempted-user 2006-3869 19667  
17512BROWSER-IE Microsoft Internet Explorer Script Action Handler buffer overflow attempt (more info ...)attempted-user 2006-1245 17131  
17522FILE-JAVA Oracle Java Runtime Environment Pack200 Decompression Integer Overflow (more info ...)attempted-user 2009-1095 34240  
17549BROWSER-IE Microsoft Internet Explorer Error Handling Code Execution (more info ...)attempted-admin 2007-3893 25916  URL
17554BROWSER-IE Microsoft Internet Explorer DOM object cache management memory corruption attempt (more info ...)attempted-user 2007-5344 26817  
17562FILE-JAVA Oracle Java Runtime Environment Pack200 Decompression Integer Overflow attempt (more info ...)misc-attack 2008-5352 32608  
17563FILE-JAVA Oracle Java Runtime Environment JAR File Processing Stack Buffer Overflow (more info ...)attempted-user 2008-5354 32608  
17566BROWSER-IE Microsoft Internet Explorer event handler memory corruption attempt (more info ...)attempted-user 2009-1530 35224  URL
17570BROWSER-FIREFOX Mozilla Firefox IFRAME style change handling code execution (more info ...)attempted-user 2008-1236 28448  URL
17580BROWSER-IE Microsoft Internet Explorer span tag memory corruption attempt (more info ...)attempted-user 2006-1188 17468  
17581BROWSER-FIREFOX Mozilla Firefox tag order memory corruption attempt (more info ...)attempted-user 2006-0749 17516  
17585BROWSER-IE Microsoft Internet Explorer possible javascript onunload event memory corruption (more info ...)attempted-user 2007-1094 22678  
17586FILE-JAVA Oracle Java Web Start malicious parameter value (more info ...)attempted-user 2004-1029 11726  
17601BROWSER-FIREFOX Mozilla Firefox file type memory corruption attempt (more info ...)attempted-user 2008-5016 32281  URL
17603BROWSER-FIREFOX Mozilla Firefox file type memory corruption attempt (more info ...)attempted-user 2008-5021 32281  URL
17604SERVER-OTHER Oracle Java AWT ConvolveOp memory corruption attempt (more info ...)attempted-user 2006-6731 21675  URL
17613BROWSER-FIREFOX Mozilla Firefox browser engine memory corruption attempt (more info ...)attempted-user 2009-1392 35326  
17622BROWSER-IE Microsoft Internet Explorer object reference memory corruption attempt (more info ...)attempted-user 2007-3902   URL
17623FILE-JAVA Oracle Java Runtime Environment Type1 Font parsing integer overflow attempt (more info ...)attempted-user 2009-1099 34240  
17624FILE-JAVA Oracle Java Runtime Environment Type1 Font parsing integer overflow attempt (more info ...)attempted-user 2009-1099 34240  
17628FILE-IMAGE Sun Microsystems Java gif handling memory corruption attempt (more info ...)attempted-user 2007-0243 22085  
17629BROWSER-FIREFOX Mozilla Firefox Chrome Page Loading Restriction Bypass attempt (more info ...)attempted-user 2005-2706 14920  
17630BROWSER-FIREFOX Mozilla multiple products CSSValue array memory corruption attempt (more info ...)attempted-user 2008-2785 29802  
17644BROWSER-IE Microsoft Internet Explorer object clone deletion memory corruption attempt (more info ...)attempted-user 2009-0075   URL
17645BROWSER-IE Microsoft Internet Explorer CSS strings parsing memory corruption attempt (more info ...)attempted-user 2007-0943   URL
17660SERVER-OTHER Oracle Java Web Start arbitrary command execution attempt (more info ...)attempted-user 2010-1423 39346  
17668FILE-PDF download of a PDF with embedded JavaScript - JS string attempt (more info ...)policy-violation    URL
17692BROWSER-IE Microsoft Internet Explorer ExecWB security zone bypass attempt (more info ...)attempted-user 2008-2259 30612  URL
17703BROWSER-IE Microsoft Internet Explorer popup title bar spoofing attempt (more info ...)misc-activity 2005-0500 12602  
17709BROWSER-IE Microsoft Internet Explorer EMBED element memory corruption attempt (more info ...)attempted-user 2009-0553 34424  URL
17719BROWSER-FIREFOX Mozilla Firefox ClearTextRun exploit attempt (more info ...)attempted-user 2009-1313 34743  
17720BROWSER-IE Microsoft Internet Explorer static text range overflow attempt (more info ...)attempted-user 2008-2255   URL
17725BROWSER-OTHER Opera file URI handling buffer overflow (more info ...)attempted-user 2008-5178 32323  
17726BROWSER-IE Microsoft Internet Explorer address bar spoofing attempt (more info ...)misc-activity 2006-1626 17404  
17729BROWSER-IE Microsoft Internet Explorer EMBED element memory corruption attempt (more info ...)attempted-user 2009-0553 34424  URL
17747BROWSER-IE Microsoft Internet Explorer compressed HDMX font processing integer overflow attempt (more info ...)attempted-admin 2010-1883   URL
17766BROWSER-IE Microsoft Internet Explorer 8 XSS in toStaticHTML API attempt (more info ...)attempted-user 2010-3243   URL
17767BROWSER-IE Microsoft Internet Explorer 8 tostaticHTML CSS import vulnerability (more info ...)attempted-user 2010-3324   URL
17768BROWSER-IE Microsoft Internet Explorer 8 object event handler use after free exploit attempt (more info ...)attempted-user 2010-3326   URL
17769BROWSER-IE Microsoft Internet Explorer 8 CSS invalid mapping exploit attempt (more info ...)attempted-user 2010-3328   URL
17771BROWSER-IE Microsoft Internet Explorer cross-domain information disclosure attempt (more info ...)attempted-user 2010-3330   URL
17774BROWSER-IE Microsoft Internet Explorer 8 CSS XSRF exploit attempt (more info ...)attempted-user 2010-3325   URL
17776FILE-JAVA Oracle Java HsbParser.getSoundBank stack buffer overflow attempt (more info ...)attempted-user 2009-3867 36881  
17804BROWSER-FIREFOX Mozilla Firefox html tag attributes memory corruption (more info ...)attempted-user 2010-3765   
18077BROWSER-FIREFOX Mozilla products CSS rendering out-of-bounds array write attempt (more info ...)attempted-user 2006-1739   
18078BROWSER-FIREFOX Mozilla products CSS rendering out-of-bounds array write attempt (more info ...)attempted-user 2006-1739   
18102FILE-PDF Adobe Acrobat Reader invalid PDF JavaScript printSeps extension call attempt (more info ...)attempted-admin 2010-4091 44638  URL
18132INDICATOR-OBFUSCATION malware-associated JavaScript obfuscation function (more info ...)trojan-activity    URL
18167INDICATOR-SHELLCODE Possible generic javascript heap spray attempt (more info ...)attempted-user 2009-2477 35660  
18168INDICATOR-SHELLCODE Possible generic javascript heap spray attempt (more info ...)attempted-user 2009-2477 35660  
18170BROWSER-FIREFOX Mozilla Firefox and SeaMonkey onUnload event handler memory corruption attempt (more info ...)attempted-user 2007-1092 22679  
18174BROWSER-IE Microsoft Internet Explorer CSS memory corruption attempt (more info ...)attempted-user 2004-0842 10816  
18175BROWSER-IE Microsoft Internet Explorer CSS memory corruption attempt (more info ...)attempted-user 2004-0842 10816  
18176BROWSER-FIREFOX Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt (more info ...)attempted-user 2006-3113 19197  
18177BROWSER-FIREFOX Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt (more info ...)attempted-user 2006-3113 19197  
18178BROWSER-FIREFOX Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt (more info ...)attempted-user 2006-3113 19197  
18186BROWSER-FIREFOX Mozilla products -moz-grid and -moz-grid-group display styles code execution attempt (more info ...)attempted-user 2006-1738 17516  
18193BROWSER-IE Microsoft Internet Explorer cross domain information disclosure attempt (more info ...)attempted-user 2006-3280 18682  
18194BROWSER-IE Microsoft Internet Explorer cross domain information disclosure attempt (more info ...)attempted-user 2006-3280 18682  
18196BROWSER-IE Microsoft Internet Explorer CSS importer use-after-free attempt (more info ...)attempted-user 2010-3971 45246  URL
18197BROWSER-PLUGINS Microsoft Internet Explorer COleSite ActiveX memory corruption attempt (more info ...)attempted-user 2010-3340   URL
18198BROWSER-PLUGINS Microsoft Internet Explorer COleSite ActiveX memory corruption attempt (more info ...)attempted-user 2010-3340   URL
18199BROWSER-PLUGINS Microsoft Internet Explorer COleSite ActiveX memory corruption attempt (more info ...)attempted-user 2010-3340   URL
18216BROWSER-IE Microsoft Internet Explorer 6 #default#anim attempt (more info ...)attempted-user 2010-3343   URL
18217BROWSER-IE Microsoft Internet Explorer select element memory corruption attempt (more info ...)attempted-user 2010-3345 45260  
18218BROWSER-IE Microsoft Internet Explorer time element memory corruption attempt (more info ...)attempted-user 2010-3346 45261  URL
18221BROWSER-IE Microsoft Internet Explorer malformed table remote code execution attempt (more info ...)attempted-user 2010-3962   URL
18239INDICATOR-OBFUSCATION known malicious JavaScript decryption routine (more info ...)attempted-user    URL
18240BROWSER-IE Microsoft Internet Explorer CSS importer use-after-free attempt (more info ...)attempted-user 2010-3971 45246  URL
18250BROWSER-FIREFOX Mozilla products EscapeAttributeValue integer overflow attempt (more info ...)attempted-user 2006-0297 16476  
18261BROWSER-FIREFOX Mozilla Firefox Javascript engine String.toSource memory corruption attempt (more info ...)attempted-user 2006-3806 19181  
18262BROWSER-FIREFOX Mozilla Firefox Javascript engine function arguments memory corruption attempt (more info ...)attempted-user 2006-3806 19181  
18263BROWSER-FIREFOX Mozilla Firefox Javascript deleted frame or window reference attempt (more info ...)attempted-user 2006-3801   
18264BROWSER-FIREFOX Mozilla Firefox Javascript deleted frame or window reference attempt (more info ...)attempted-user 2006-3801   
18280BROWSER-IE Microsoft Internet Explorer oversize recordset object cache size exploit attempt (more info ...)attempted-user 2011-0027   URL
18282BROWSER-IE Microsoft Internet Explorer drag-and-drop vulnerability (more info ...)attempted-user 2005-0053 11466  URL
18286BROWSER-FIREFOX Mozilla products element style change memory corruption code execution attempt (more info ...)attempted-user 2006-0294 16476  
18294BROWSER-WEBKIT Apple Safari Webkit floating point buffer overflow attempt (more info ...)attempted-user 2009-2195 36023  
18295BROWSER-WEBKIT Apple Safari Webkit floating point buffer overflow attempt (more info ...)attempted-user 2009-2195 36023  
18296BROWSER-FIREFOX Mozilla products frame comment objects manipulation memory corruption attempt (more info ...)attempted-user 2006-6504 21668  
18298BROWSER-FIREFOX Mozilla Firefox Javascript large regex memory corruption attempt (more info ...)attempted-user 2006-1737 17516  
18299BROWSER-IE Microsoft Internet Explorer implicit drag and drop file installation attempt (more info ...)attempted-user 2004-0839 10973  
18301BROWSER-FIREFOX Mozilla Firefox GeckoActiveXObject memory corruption attempt (more info ...)attempted-user 2006-3803 19181  
18302BROWSER-FIREFOX Mozilla Firefox new function garbage collection remote code execution attempt (more info ...)attempted-user 2006-3803 19181  
18303BROWSER-IE Microsoft Internet Explorer script action handler overflow attempt (more info ...)attempted-user 2006-1245 17131  
18304BROWSER-IE Microsoft Internet Explorer span tag memory corruption attempt (more info ...)attempted-user 2006-1188   
18305BROWSER-IE Microsoft Internet Explorer span tag memory corruption attempt (more info ...)attempted-user 2006-1188   
18306BROWSER-IE Microsoft Internet Explorer span tag memory corruption attempt (more info ...)attempted-user 2006-1188   
18307BROWSER-IE Microsoft Internet Explorer frameset memory corruption attempt (more info ...)attempted-user 2006-3637 18277  
18313BROWSER-IE Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user 2006-1359 17196  URL
18332BROWSER-FIREFOX Mozilla Firefox JS Web Worker arbitrary code execution attempt (more info ...)attempted-user 2009-3371   URL
18348MALWARE-CNC User-Agent known malicious user-agent string Opera/9.80 Pesto/2.2.15 (more info ...)trojan-activity    URL
18354MALWARE-CNC User-Agent known malicious user-agent string opera/8.11 (more info ...)trojan-activity    URL
18370MALWARE-CNC User-Agent known malicious user-agent string Mozilla Windows MSIE (more info ...)trojan-activity    URL
18401BROWSER-IE Microsoft Internet Explorer Base64 encoded script overflow attempt (more info ...)attempted-admin 2011-0031   URL
18403BROWSER-IE Microsoft Internet Explorer Data Source Object memory corruption attempt (more info ...)attempted-user 2011-0035 46157  URL
18470SERVER-WEBAPP Java floating point number denial of service - via URI (more info ...)attempted-dos 2010-4476   URL
18471SERVER-WEBAPP Java floating point number denial of service - via POST (more info ...)attempted-dos 2010-4476   URL
18482BROWSER-IE Microsoft Internet Explorer History.go method double free corruption attempt (more info ...)attempted-user 2009-0552 34423  
18485BROWSER-FIREFOX Mozilla Firefox JavaScript handler race condition memory corruption attempt (more info ...)attempted-user 2006-4253 19488  
18486BROWSER-FIREFOX Mozilla Firefox JavaScript handler race condition memory corruption attempt (more info ...)attempted-user 2006-4253 19488  
18508BROWSER-WEBKIT Apple Safari WebKit ParentStyleSheet exploit attempt (more info ...)attempted-user    URL
18517BROWSER-IE Microsoft Internet Explorer long URL buffer overflow attempt (more info ...)attempted-user 2006-3869 19667  
18518BROWSER-IE Microsoft Internet Explorer HTML DOM invalid DHTML comment creation attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
18519BROWSER-IE Microsoft Internet Explorer HTML DOM invalid DHTML element creation attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
18520BROWSER-IE Microsoft Internet Explorer HTML DOM invalid DHTML exploit attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
18521BROWSER-IE Microsoft Internet Explorer HTML DOM invalid DHTML element creation attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
18522BROWSER-IE Microsoft Internet Explorer HTML DOM invalid DHTML element creation attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
18523BROWSER-IE Microsoft Internet Explorer HTML DOM invalid DHTML exploit attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
18539BROWSER-IE Microsoft Internet Explorer event handling remote code execution attempt (more info ...)attempted-user 2010-0267   URL
18571INDICATOR-COMPROMISE fraudulent digital certificate for addons.mozilla.org detected (more info ...)misc-attack    URL
18597BROWSER-OTHER Opera file URI handling buffer overflow (more info ...)attempted-user 2008-5178 32323  
18652PROTOCOL-SCADA IGSS IGSSDataServer.exe report template operation overflow attempt (more info ...)attempted-admin    
18669BROWSER-IE Microsoft Internet Explorer cross-domain object manipulation attempt (more info ...)web-application-activity 2011-1245   URL
18670BROWSER-IE Microsoft Internet Explorer object management memory corruption attempt (more info ...)attempted-user 2011-1345 46821  URL
18671BROWSER-IE Microsoft Internet Explorer object management memory corruption attempt (more info ...)attempted-user 2011-1345 46821  URL
18672BROWSER-IE Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access (more info ...)attempted-user 2011-0811   URL
18681FILE-PDF transfer of a PDF with embedded JavaScript - JavaScript object detected (more info ...)policy-violation    URL
18770BROWSER-WEBKIT Apple Safari WebKit range object remote code execution attempt (more info ...)attempted-user 2011-0115 46746  
18798SERVER-OTHER HP Data Protector Media Operations denial of service attempt (more info ...)attempted-dos    URL
18799SERVER-OTHER HP Data Protector Media Operations denial of service attempt (more info ...)attempted-dos    URL
18803SERVER-WEBAPP Oracle Java Runtime CMM readMabCurveData buffer overflow attempt (more info ...)attempted-user 2010-0838 39069  
18809BROWSER-FIREFOX Mozilla EnsureCachedAttrParamArrays integer overflow attempt (more info ...)attempted-user 2010-1214 41842  
18903BROWSER-WEBKIT Apple Safari WebKit Rendering Counter Code Execution (more info ...)attempted-user 2010-1784 42036  
18951BROWSER-IE Microsoft Internet Explorer CTableLayout memory corruption attempt (more info ...)attempted-user 2010-0244 37891  URL
18973BROWSER-WEBKIT Apple Safari Webkit button first-letter style rendering code execution attempt (more info ...)attempted-user 2010-1392 40644  
18995BROWSER-WEBKIT Apple Safari Webkit removeAllRanges use-after-free attempt (more info ...)attempted-user 2010-1812 43079  
18996SERVER-ORACLE DBMS_JAVA.SET_OUTPUT_TO_JAVA privilege escalation attempt (more info ...)attempted-admin 2010-0867 38115  
19003BROWSER-WEBKIT Apple Safari Webkit run-in use-after-free attempt (more info ...)attempted-user 2010-1806 43049  
19004BROWSER-WEBKIT Apple Safari Webkit run-in use-after-free attempt (more info ...)attempted-user 2010-1806 43049  
19005BROWSER-CHROME Apple Safari/Google Chrome Webkit memory corruption attempt (more info ...)attempted-user 2010-1813 43078  
19008BROWSER-WEBKIT Apple Safari Webkit floating point conversion memory corruption attempt (more info ...)attempted-user 2010-1807 43047  
19009BROWSER-WEBKIT Apple Safari WebKit menu onchange memory corruption attempt (more info ...)attempted-user 2010-1814 43083  
19010BROWSER-WEBKIT Apple Safari WebKit menu onchange memory corruption attempt (more info ...)attempted-user 2010-1814 43083  
19074INDICATOR-OBFUSCATION javascript uuencoded noop sled attempt (more info ...)misc-activity    URL
19075INDICATOR-OBFUSCATION javascript uuencoded eval statement (more info ...)misc-activity    URL
19076BROWSER-FIREFOX Mozilla Firefox appendChild use-after-free attempt (more info ...)attempted-user 2010-3765   
19077BROWSER-FIREFOX Mozilla Firefox appendChild use-after-free attempt (more info ...)attempted-user 2010-3765   
19078BROWSER-FIREFOX Mozilla Firefox html tag attributes memory corruption (more info ...)attempted-user 2010-3765   
19079BROWSER-IE Microsoft Internet Explorer getElementById object corruption (more info ...)attempted-user 2008-2254 30614  URL
19084BROWSER-IE Microsoft Internet Explorer CSS style memory corruption attempt (more info ...)attempted-user 2010-3962   URL
19095BROWSER-WEBKIT Apple Safari Webkit CSS Charset Text transformation code execution attempt (more info ...)attempted-user 2010-1770 40653  
19096BROWSER-WEBKIT Apple Safari Webkit CSS Charset Text transformation code execution attempt (more info ...)attempted-user 2010-1770 40653  
19097BROWSER-WEBKIT Apple Safari Webkit ContentEditable code execution attempt (more info ...)attempted-user 2010-1396 40647  
19098BROWSER-WEBKIT Apple Safari Webkit ContentEditable code exeuction attempt (more info ...)attempted-user 2010-1396 40647  
19099BROWSER-WEBKIT Apple Safari CSS font format corruption attempt (more info ...)attempted-user 2010-0046 38684  URL
19100FILE-JAVA Oracle Java Soundbank resource name overflow attempt (more info ...)attempted-user 2010-0839 39070  
19101SERVER-ORACLE Oracle Java Web Server Admin Server denial of service attempt (more info ...)attempted-dos 2010-0389 37909  
19147BROWSER-IE Microsoft Internet Explorer outerHTML against incomplete element heap corruption attempt (more info ...)attempted-user 2010-0490   URL
19149BROWSER-IE Microsoft Internet Explorer malformed table tag memory corruption attempt (more info ...)attempted-user 2010-2560   
19150BROWSER-IE Microsoft Internet Explorer malformed table tag memory corruption attempt (more info ...)attempted-user 2010-2560   
19155SERVER-WEBAPP HP Data Protector Media Operations SignInName Parameter overflow attempt (more info ...)attempted-admin  44381  
19165MALWARE-CNC User-Agent known malicious user-agent string Microsoft Internet Explorer (more info ...)trojan-activity    
19171BROWSER-IE Microsoft Internet Explorer 8 ieshims.dll dll-load exploit attempt (more info ...)attempted-user 2011-0038 46159  URL
19172BROWSER-IE Microsoft Internet Explorer 8 ieshims.dll dll-load exploit attempt (more info ...)attempted-user 2011-0038 46159  URL
19181BROWSER-IE Microsoft Internet Explorer iframe uninitialized memory corruption attempt (more info ...)attempted-user 2010-2556 42257  URL
19203BROWSER-IE Microsoft Internet Explorer MsgBox arbitrary code execution attempt (more info ...)attempted-user 2010-0483   URL
19204BROWSER-IE Microsoft Internet Explorer MsgBox arbitrary code execution attempt (more info ...)attempted-user 2010-0483   URL
19235BROWSER-IE Microsoft Internet Explorer copy/paste memory corruption attempt (more info ...)attempted-user 2011-1256   URL
19236BROWSER-IE Microsoft Internet Explorer drag event memory corruption attempt (more info ...)attempted-admin 2011-1254 48204  URL
19237BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
19238BROWSER-IE Microsoft Internet Explorer 8 self remove from markup vulnerability (more info ...)attempted-user 2011-1251   URL
19239BROWSER-IE Microsoft Internet Explorer 8 toStaticHTML XSS attempt (more info ...)attempted-user 2011-1252   URL
19240BROWSER-IE Microsoft Internet Explorer 6/7/8 reload stylesheet attempt (more info ...)attempted-user 2011-1250   URL
19243BROWSER-IE Microsoft Internet Explorer layout-grid-char value exploit attempt (more info ...)attempted-admin 2011-1260   URL
19245BROWSER-IE Microsoft Internet Explorer redirect to cdl protocol attempt (more info ...)attempted-admin 2011-1262   URL
19246BROWSER-IE Microsoft Internet Explorer CSS expression defined to empty selection attempt (more info ...)attempted-user 2011-1261 48210  URL
19254FILE-PDF Adobe Acrobat Reader javascript in PDF go-to actions exploit attempt (more info ...)attempted-user 2011-2101   URL
19265BROWSER-IE Microsoft Internet Explorer layout-grid-char value exploit attempt (more info ...)attempted-user 2011-1260   URL
19266BROWSER-IE Microsoft Internet Explorer layout-grid-char value exploit attempt (more info ...)attempted-user 2011-1260   URL
19292BROWSER-FIREFOX Mozilla Firefox appendChild use-after-free attempt (more info ...)attempted-user 2010-3765   
19321BROWSER-FIREFOX Mozilla Products nsCSSValue Array Index Integer Overflow (more info ...)attempted-user 2010-2752 41852  
19322BROWSER-IE Microsoft Internet Explorer and SharePoint toStaticHTML information disclosure attempt (more info ...)attempted-recon 2010-3243   
19372MALWARE-CNC User-Agent known malicious user-agent string javasw - Trojan.Banload (more info ...)trojan-activity    URL
19411BROWSER-IE Microsoft Internet Explorer Cross-Domain information disclosure attempt (more info ...)attempted-user 2010-3330 43709  URL
19436BROWSER-IE Microsoft Internet Explorer CStyleSheetRule array memory corruption attempt (more info ...)attempted-user 2010-3328 43705  URL
19666BROWSER-IE Microsoft Internet Explorer multi-window access memory corruption attempt (more info ...)attempted-user 2011-1257   URL
19667BROWSER-IE Microsoft Internet Explorer cross-domain scripting attack (more info ...)attempted-user 2011-1960   URL
19668BROWSER-IE Microsoft Internet Explorer telnet.exe file load exploit attempt (more info ...)attempted-user 2011-1961   URL
19670BROWSER-IE Microsoft Internet Explorer telnet.exe file load exploit attempt (more info ...)attempted-user 2011-1961   URL
19671BROWSER-IE Microsoft Internet Explorer XSLT memory corruption attempt (more info ...)attempted-user 2011-1963 49037  URL
19672BROWSER-IE Microsoft Internet Explorer stylesheet dynamic access memory corruption attempt (more info ...)attempted-user 2011-1964   URL
19710BROWSER-CHROME Google Chrome float rendering corruption attempt (more info ...)attempted-user 2011-1804   
19756MALWARE-CNC User-Agent known malicious user-agent string Opera/8.89 - P2P-Worm.Win32.Palevo.ddm (more info ...)trojan-activity    URL
19786MALWARE-CNC User-Agent known malicious user agent - Mozilla (more info ...)trojan-activity    URL
19806BROWSER-WEBKIT Apple Safari Webkit SVG memory corruption attempt (more info ...)attempted-user 2011-0222 48844  URL
19807BROWSER-WEBKIT Apple Safari Webkit SVG memory corruption attempt (more info ...)attempted-user 2011-0222 48844  URL
19808BROWSER-IE Microsoft Internet Explorer covered object memory corruption attempt (more info ...)attempted-user 2011-1260   URL
19815SERVER-OTHER HP Operations Manager Server Default Credientials in use attempt (more info ...)default-login-attempt 2009-4189   
19867INDICATOR-OBFUSCATION randomized javascript encodings detected (more info ...)policy-violation    URL
19871BROWSER-IE Microsoft Internet Explorer VML buffer overflow attempt (more info ...)attempted-user 2006-4868   URL
19872BROWSER-IE Microsoft Internet Explorer MDAC remote code execution attempt (more info ...)attempted-user 2006-0003   URL
19873BROWSER-IE Microsoft Internet Explorer CSS style memory corruption attempt (more info ...)attempted-user 2010-3962   URL
19885BROWSER-IE Microsoft Internet Explorer daxctle.ocx spline method buffer overflow attempt (more info ...)attempted-user 2006-4446   URL
19887INDICATOR-OBFUSCATION potential javascript unescape obfuscation attempt detected (more info ...)policy-violation    URL
19888INDICATOR-OBFUSCATION potential javascript unescape obfuscation attempt detected (more info ...)policy-violation    URL
19910BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user 2011-1266 48173  URL
19926FILE-JAVA Oracle Java Runtime AWT setDiffICM stack buffer overflow attempt (more info ...)attempted-user 2009-3869 36881  
20137INDICATOR-OBFUSCATION Possible generic javascript heap spray attempt (more info ...)attempted-user 2009-2477 35660  URL
20231MALWARE-CNC User-Agent known malicious user-agent string Mozilla//4.0 (more info ...)trojan-activity    URL
20238SERVER-OTHER Oracle Java calendar deserialize vulnerability (more info ...)attempted-user 2008-5353   
20249SERVER-OTHER Oracle Java Web Start BasicService arbitrary command execution attempt (more info ...)attempted-user 2008-4910   
20258OS-WINDOWS Microsoft generic javascript handler in URI XSS attempt (more info ...)attempted-user 2016-3212   URL
20262BROWSER-IE Microsoft Internet Explorer onscroll DOS attempt (more info ...)attempted-user 2011-1993 49947  URL
20263BROWSER-IE Microsoft Internet Explorer htmlfile null attribute access attempt (more info ...)attempted-user 2011-1995 49960  URL
20264BROWSER-IE Microsoft Internet Explorer form selection reset attempt (more info ...)attempted-user 2011-1996 49961  URL
20265BROWSER-IE Microsoft Internet Explorer null attribute DoS attempt (more info ...)attempted-user 2011-1997 49962  URL
20266BROWSER-IE Microsoft Internet Explorer 8 Javascript negative option index attack attempt (more info ...)attempted-user 2011-1999 49964  URL
20267BROWSER-IE Microsoft Internet Explorer circular reference exploit attempt (more info ...)attempted-user 2011-2000 49965  URL
20268BROWSER-IE Microsoft Internet Explorer Marquee stylesheet object removal (more info ...)attempted-user 2011-2001 49966  URL
20273BROWSER-IE Microsoft Internet Explorer jscript9 parsing corruption attempt (more info ...)attempted-user 2011-1998   URL
20277BROWSER-IE Microsoft Internet Explorer HTML DOM invalid DHTML comment creation attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
20279BROWSER-IE Microsoft Internet Explorer HTML DOM invalid DHTML textnode creation attempt (more info ...)attempted-user 2005-0553 13120 10861 URL
20430FILE-JAVA Oracle Java Web Start BasicServiceImpl security policy bypass attempt (more info ...)attempted-user 2010-3563 43999  
20529FILE-JAVA Oracle Java trusted method chaining attempt (more info ...)attempted-user 2010-0840   
20535BROWSER-OTHER Opera Config File script access attempt (more info ...)attempted-user    
20560FILE-FLASH Adobe Flash Player salign null javascript access attempt (more info ...)attempted-user 2011-2459   URL
20579BROWSER-CHROME Google Chrome and Apple Safari Ruby before and after memory corruption (more info ...)attempted-user 2011-1440   
20593BROWSER-WEBKIT Apple Safari Webkit libxslt arbitrary file creation attempt (more info ...)attempted-user 2011-1774   URL
20666BROWSER-FIREFOX Mozilla Thunderbird / SeaMonkey Content-Type header buffer overflow attempt (more info ...)attempted-user 2006-6505   
20667BROWSER-FIREFOX Mozilla Thunderbird / SeaMonkey Content-Type header buffer overflow attempt (more info ...)attempted-user 2006-6505   
20699BROWSER-IE Microsoft Internet Explorer XSRF timing attack against XSS filter (more info ...)attempted-recon 2011-1992   URL
20704BROWSER-PLUGINS Microsoft Internet Explorer defaulttime behavior attack attempt (more info ...)attempted-user 2011-3397   URL
20705BROWSER-PLUGINS Microsoft Internet Explorer Time DATIME.DLL ActiveX clsid access (more info ...)attempted-user 2011-3397   URL
20727BROWSER-FIREFOX Mozilla Firefox user interface event dispatcher dos attempt (more info ...)attempted-dos 2008-4324 31476  
20729BROWSER-FIREFOX Mozilla XBL object init code execution attempt (more info ...)attempted-user 2006-1733 17516  
20730BROWSER-FIREFOX Mozilla XBL.method memory corruption attempt (more info ...)attempted-admin 2006-1735 17516  
20736BROWSER-WEBKIT Apple Safari x-man-page URI terminal escape attempt (more info ...)attempted-user 2005-1342 13502  
20739BROWSER-FIREFOX Mozilla Object.watch parent access attempt (more info ...)attempted-admin 2006-1734 17516  
20742BROWSER-FIREFOX Mozilla PLUGINSPAGE javascript execution attempt (more info ...)attempted-user 2005-0752 13228  
20766BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20786BROWSER-IE Microsoft Internet Explorer layout-grid-char value exploit attempt (more info ...)attempted-admin 2011-1260   URL
20787BROWSER-IE Microsoft Internet Explorer layout-grid-char value exploit attempt (more info ...)attempted-user 2011-1260   URL
20788BROWSER-IE Microsoft Internet Explorer layout-grid-char value exploit attempt (more info ...)attempted-user 2011-1260   URL
20789BROWSER-IE Microsoft Internet Explorer layout-grid-char value exploit attempt (more info ...)attempted-user 2011-1260   URL
20790BROWSER-IE Microsoft Internet Explorer layout-grid-char value exploit attempt (more info ...)attempted-user 2011-1260   URL
20804BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20805BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20806BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20807BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20808BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20809BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20810BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20811BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt (more info ...)attempted-user 2011-1255   URL
20814BROWSER-FIREFOX Mozilla favicon href javascript execution attempt (more info ...)attempted-user 2005-1531   
20822BROWSER-IE Microsoft Internet Explorer contenteditable corruption attempt malicious string (more info ...)attempted-user 2011-1255   
20858FILE-JAVA Oracle Java getSoundBank overflow Attempt malicious jar file (more info ...)attempted-user 2009-3867 36881  
20998FILE-PDF Adobe Acrobat Reader javascript submitform memory corruption attempt (more info ...)attempted-user 2011-4371   URL
20999BROWSER-WEBKIT Microsoft Windows 7 x64 Apple Safari abnormally long iframe exploit attempt (more info ...)attempted-dos 2011-5046 51122  URL
21037INDICATOR-OBFUSCATION randomized javascript encodings detected (more info ...)policy-violation    URL
21039INDICATOR-OBFUSCATION potential javascript unescape obfuscation attempt detected (more info ...)policy-violation    URL
21040INDICATOR-OBFUSCATION potential javascript unescape obfuscation attempt detected (more info ...)policy-violation    URL
21056FILE-JAVA Oracle Java attempt to write in system32 (more info ...)policy-violation    
21086BROWSER-IE Microsoft Internet Explorer object clone deletion memory corruption (more info ...)attempted-user 2009-0075   URL
21154BROWSER-FIREFOX Mozilla products floating point buffer overflow attempt (more info ...)attempted-user 2009-0689 37078  
21155BROWSER-FIREFOX Mozilla products floating point buffer overflow attempt (more info ...)attempted-user 2009-0689 37078  
21166BROWSER-CHROME Google Chrome https spoofing attempt (more info ...)attempted-recon    URL
21189BROWSER-WEBKIT Apple Safari innerHTML use after free exploit attempt (more info ...)attempted-user 2011-0221 48844  
21190BROWSER-FIREFOX Mozilla Multiple Products MozOrientation loading attempt (more info ...)attempted-user 2011-2980 49217  
21191BROWSER-FIREFOX Mozilla Multiple Products MozOrientation loading attempt (more info ...)attempted-user 2011-2980 49217  
21268SERVER-OTHER Oracle Java RMI services remote object execution attempt (more info ...)misc-attack 2015-2342   URL
21272BROWSER-IE Microsoft Internet Explorer orphan DOM objects memory corruption attempt (more info ...)attempted-user 2009-3674   URL
21300BROWSER-IE Microsoft Internet Explorer 9 null character in string information disclosure attempt (more info ...)attempted-recon 2012-0012   URL
21353BROWSER-IE Microsoft Internet Explorer mouse drag hijack (more info ...)attempted-user 2004-0841   URL
21363BROWSER-FIREFOX Mozilla Firefox appendChild use-after-free attempt (more info ...)attempted-user 2010-3765   
21387FILE-JAVA Oracle Java runtime RMIConnectionImpl deserialization execution attempt (more info ...)attempted-user 2010-0094   
21392BROWSER-IE Microsoft Internet Explorer writing-mode property memory corruption attempt (more info ...)attempted-user 2009-2531 36616  
21394BROWSER-FIREFOX Mozilla Firefox null byte file remote code execution attempt (more info ...)attempted-user 2007-3285 24447  
21399BROWSER-OTHER Opera Web Browser History Search Input validation vulnerability (more info ...)attempted-user 2008-4696 31869  
21446BROWSER-CHROME Google Chrome FileSystemObject clsid access (more info ...)attempted-user 2009-3934 36947  
21447BROWSER-CHROME Google Chrome FileSystemObject function call (more info ...)attempted-user 2009-3931 36947  
21462FILE-JAVA Oracle Java Plugin security bypass (more info ...)attempted-user 2004-1029 11726  
21501FILE-JAVA Oracle JavaScript file upload keystroke hijack attempt (more info ...)misc-activity 2006-2900 18308  
21519INDICATOR-OBFUSCATION Dadongs obfuscated javascript (more info ...)misc-activity    URL
21569BROWSER-IE Microsoft Internet Explorer toStaticHTML XSS attempt (more info ...)web-application-activity 2011-1252   URL
21577INDICATOR-OBFUSCATION JavaScript obfuscation - charcode (more info ...)attempted-user    URL
21578INDICATOR-OBFUSCATION JavaScript obfuscation - eval (more info ...)attempted-user    URL
21579INDICATOR-OBFUSCATION JavaScript obfuscation - fromCharCode (more info ...)attempted-user    URL
21580INDICATOR-OBFUSCATION JavaScript obfuscation - fromCharCode (more info ...)attempted-user    URL
21631MALWARE-CNC Win.Trojan.Sinowal javascript delivery method (more info ...)trojan-activity    URL
21786INDICATOR-OBFUSCATION encoded javascript escape function in POST parameters - likely javascript injection (more info ...)web-application-attack    URL
21787INDICATOR-OBFUSCATION encoded javascript escape function in POST parameters - likely javascript injection (more info ...)web-application-attack    URL
21991BROWSER-IE Microsoft Internet Explorer data stream header remote code execution attempt (more info ...)attempted-user 2009-1547   URL
21992BROWSER-IE Microsoft Internet Explorer data stream header remote code execution attempt (more info ...)attempted-user 2009-1547   URL
21993BROWSER-IE Microsoft Internet Explorer data stream header remote code execution attempt (more info ...)attempted-user 2009-1547   URL
21994BROWSER-IE Microsoft Internet Explorer 8 DOM memory corruption attempt (more info ...)attempted-user 2009-3671 37188  URL
22003BROWSER-PLUGINS Microsoft Internet Explorer WMIScriptUtils.WMIObjectBroker2.1 ActiveX clsid access attempt (more info ...)attempted-user 2006-4704   URL
23015BROWSER-CHROME Google Chrome and Apple Safari runin handling use after free attempt (more info ...)attempted-user 2011-3068   
23054BROWSER-FIREFOX Mozilla Firefox nSSVGValue memory corruption attempt (more info ...)attempted-user 2011-3658 51138  
23085INDICATOR-OBFUSCATION Obfuscated javascript string - join (more info ...)bad-unknown    URL
23086INDICATOR-OBFUSCATION Obfuscated javascript string - push (more info ...)bad-unknown    URL
23087INDICATOR-OBFUSCATION Obfuscated javascript string - xval (more info ...)bad-unknown    URL
23088INDICATOR-OBFUSCATION Obfuscated javascript string - qweqwe (more info ...)bad-unknown    URL
23089INDICATOR-OBFUSCATION Obfuscated javascript strings - obfuscation pattern (more info ...)bad-unknown    URL
23107INDICATOR-COMPROMISE BeEF javascript hook.js download attempt (more info ...)attempted-user    
23128BROWSER-IE Microsoft Internet Explorer 9 memory disclosure attempt (more info ...)attempted-recon 2012-1873 53844  URL
23160INDICATOR-OBFUSCATION Javascript obfuscation - fromCharCode (more info ...)attempted-user    URL
23161INDICATOR-OBFUSCATION Javascript obfuscation - eval (more info ...)attempted-user    URL
23217INDICATOR-SHELLCODE x86 OS agnostic avoid_utf8_tolower javascript encoder (more info ...)shellcode-detect    
23226INDICATOR-OBFUSCATION JavaScript error suppression routine (more info ...)misc-activity    URL
23236INDICATOR-SHELLCODE x86 OS agnostic alpha numeric upper case javascript decoder (more info ...)shellcode-detect    
23243FILE-JAVA Oracle Java Zip file directory record overflow attempt (more info ...)attempted-user 2012-0501 52013  
23291BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user 2012-1889   URL
23389MALWARE-CNC Win.Trojan.Java.Arratomref variant outbound connection (more info ...)trojan-activity    URL
23390MALWARE-CNC Win.Trojan.Java.Arratomref variant outbound connection (more info ...)trojan-activity    URL
23445BROWSER-FIREFOX Mozilla Firefox use-after free remote code execution attempt (more info ...)attempted-user 2011-3659   
23471BROWSER-CHROME Google Chrome net-internals uri fragment identifier XSS attempt (more info ...)attempted-user 2010-1503 39667  URL
23490FILE-MULTIMEDIA Oracle Java MixerSequencer RMF MIDI structure handling exploit attempt (more info ...)attempted-user 2011-3545 39077  
23501FILE-PDF Adobe Acrobat Reader javascript getIcon method buffer overflow attempt (more info ...)attempted-user 2009-0927 34169  
23502FILE-PDF Adobe Acrobat JavaScript getIcon method buffer overflow attempt (more info ...)attempted-user 2009-0927 34169  
23503FILE-PDF Adobe Acrobat JavaScript getIcon method buffer overflow attempt (more info ...)attempted-user 2009-0927 34169  
23560FILE-JAVA Oracle Java Zip file directory record overflow attempt (more info ...)attempted-user 2012-0501 52013  
23617APP-DETECT Amazon Kindle chrome-scriptable-plugin attempt (more info ...)policy-violation    URL
23625BROWSER-FIREFOX Mozilla Firefox resource URL handling directory traversal attempt (more info ...)attempted-recon 2007-3073   
23636INDICATOR-OBFUSCATION JavaScript built-in function parseInt appears obfuscated - likely packer or encoder (more info ...)trojan-activity    URL
23831INDICATOR-OBFUSCATION non-alphanumeric javascript detected (more info ...)attempted-user    URL
23832INDICATOR-OBFUSCATION non-alphanumeric javascript detected (more info ...)attempted-user    URL
23897FILE-PDF Sending of a PDF with embedded JavaScript - JS string attempt (more info ...)policy-violation    URL
23899FILE-PDF Adobe Acrobat Reader Javascript buffer overflow attempt (more info ...)attempted-user 2007-5659   
23900FILE-PDF Adobe Acrobat Reader Javascript buffer overflow attempt (more info ...)attempted-user 2007-5659   
23901FILE-PDF Adobe Acrobat Reader Javascript buffer overflow attempt (more info ...)attempted-user 2007-5659   
23902FILE-PDF Adobe Acrobat Reader Javascript buffer overflow attempt (more info ...)attempted-user 2007-5659   
24113BROWSER-PLUGINS Microsoft Internet Explorer 8 ieframe.dll ActiveX clsid access (more info ...)attempted-user    URL
24210BROWSER-IE Microsoft Internet Explorer execCommand use-after-free attempt (more info ...)attempted-user    URL
24386BROWSER-FIREFOX Mozilla Multiple Products xdomain object information disclosure attempt (more info ...)attempted-recon 2012-4192   URL
24387BROWSER-FIREFOX Mozilla Multiple Products xdomain object information disclosure attempt (more info ...)attempted-recon 2012-4192   URL
24426MALWARE-OTHER Java.Trojan.Jacksbot class download (more info ...)trojan-activity    URL
24427MALWARE-OTHER Java.Trojan.Jacksbot jar download (more info ...)trojan-activity    URL
24449MALWARE-CNC Java.Exploit.Agent variant outbound connection (more info ...)trojan-activity    URL
24452BROWSER-IE Microsoft Internet Explorer JPEG rendering buffer overflow attempt (more info ...)attempted-user 2005-2308 14284  URL
24498FILE-JAVA Oracle Java JNLP parameter argument injection attempt (more info ...)attempted-user 2005-0418   
24499FILE-JAVA Oracle Java JNLP parameter argument injection attempt (more info ...)attempted-user 2005-0418   
24510FILE-JAVA Oracle Java XGetSamplePtrFromSnd memory corruption attempt (more info ...)attempted-user 2010-4462 46394  
24511FILE-JAVA Oracle Java XGetSamplePtrFromSnd memory corruption attempt (more info ...)attempted-user 2010-4462 46394  
24568MALWARE-CNC User-Agent known malicious user agent - Mozilla/00 (more info ...)trojan-activity    URL
24575MALWARE-CNC User-Agent known malicious user agent - Opera/9.61 (more info ...)trojan-activity    URL
24869BROWSER-IE Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt (more info ...)misc-activity 2011-0094 37893  URL
24870BROWSER-IE Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt (more info ...)misc-activity 2011-0094 37893  URL
24871BROWSER-IE Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt (more info ...)misc-activity 2011-0094 37893  URL
24872BROWSER-IE Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt (more info ...)misc-activity 2011-0094 37893  URL
24905FILE-JAVA Oracle Java Web Start JNLP j2se key value buffer overflow attempt (more info ...)attempted-user 2008-3111 30148  
24906FILE-JAVA Oracle Java Web Start JNLP j2se key value buffer overflow attempt (more info ...)attempted-user 2008-3111 30148  
25036BROWSER-WEBKIT Apple Safari WebKit form elements virtual function DoS attempt (more info ...)attempted-dos 2011-2813   URL
25037BROWSER-WEBKIT Apple Safari Webkit css title memory corruption attempt (more info ...)attempted-user 2012-3684   URL
25039BROWSER-WEBKIT Apple Safari Webkit css title memory corruption attempt (more info ...)attempted-user 2012-3684   URL
25042EXPLOIT-KIT Java User-Agent downloading Portable Executable - Possible exploit kit (more info ...)trojan-activity 2012-5076   URL
25225BROWSER-IE Microsoft Internet Explorer Marquee stylesheet object removal (more info ...)attempted-user 2011-2001 49966  URL
25226BROWSER-IE Microsoft Internet Explorer Marquee stylesheet object removal (more info ...)attempted-user 2011-2001 49966  URL
25227BROWSER-FIREFOX Mozilla Firefox iframe and xul element reload crash attempt (more info ...)attempted-user 2011-2982   
25228BROWSER-FIREFOX Mozilla Firefox iframe and xul element reload crash attempt (more info ...)attempted-user 2011-2982   
25246BROWSER-IE Microsoft Internet Explorer html table column span width increase memory corruption attempt (more info ...)attempted-user 2012-1876   URL
25272SERVER-WEBAPP Microsoft System Center Operations Manager cross site scripting attempt (more info ...)attempted-user 2013-0009   URL
25289BROWSER-FIREFOX Mozilla Firefox Javascript arbitrary memory reading attempt (more info ...)attempted-recon 2011-2983   
25290BROWSER-FIREFOX Mozilla Firefox Javascript arbitrary memory reading attempt (more info ...)attempted-recon 2011-2983   
25291BROWSER-FIREFOX Mozilla Firefox Javascript arbitrary memory reading attempt (more info ...)attempted-recon 2011-2983   
25292BROWSER-FIREFOX Mozilla Firefox Javascript arbitrary memory reading attempt (more info ...)attempted-recon 2011-2983   
25329BROWSER-IE Microsoft Internet Explorer CSS style memory corruption attempt (more info ...)attempted-user 2010-3962   URL
25562FILE-JAVA Oracle Java obfuscated jar file download attempt (more info ...)trojan-activity    URL
25621BROWSER-OTHER Opera use after free attempt (more info ...)attempted-user    URL
25622BROWSER-OTHER Opera use after free attempt (more info ...)attempted-user    URL
25653BROWSER-OTHER Opera browser window null pointer dereference attempt (more info ...)attempted-user  46872  
25657SERVER-OTHER HP Data Protector Media Operations directory traversal attempt (more info ...)attempted-user  50531  
25658SERVER-OTHER HP Data Protector Media Operations directory traversal attempt (more info ...)attempted-user  50531  
25770BROWSER-IE Microsoft Internet Explorer deleted object access memory corruption attempt (more info ...)attempted-user 2013-0020   URL
25778BROWSER-IE Microsoft Internet Explorer SVG use after free attempt (more info ...)attempted-user 2013-0018   URL
25793BROWSER-IE Microsoft Internet Explorer invalid Shift_JIS character xss attempt (more info ...)attempted-user 2013-0015   URL
25794BROWSER-IE Microsoft Internet Explorer invalid Shift_JIS character xss attempt (more info ...)attempted-user 2013-0015   URL
25800EXPLOIT-KIT Stamp exploit kit Javascript request (more info ...)trojan-activity 2013-0431   URL
25853BROWSER-IE Microsoft Internet Explorer bitmap BitmapOffset integer overflow attempt (more info ...)attempted-user 2004-0566 9663  URL
26076FILE-PDF download of a PDF with embedded JavaScript - JS string attempt (more info ...)policy-violation    URL
26077FILE-PDF transfer of a PDF with embedded JavaScript - JavaScript object detected (more info ...)policy-violation    URL
26168BROWSER-IE Microsoft Internet Explorer CCaret use after free attempt (more info ...)attempted-user 2013-0090   URL
26169BROWSER-IE Microsoft Internet Explorer CCaret use after free attempt (more info ...)attempted-user 2013-0090   URL
26188BROWSER-FIREFOX Mozilla Firefox 3.5 unicode stack overflow attempt (more info ...)attempted-user 2009-2479 35707  
26258BROWSER-WEBKIT Apple Safari SVG Markers Memory Use-After-Free attempt (more info ...)attempted-user 2011-1453 46677  URL
26259BROWSER-WEBKIT Apple Safari SVG Markers Memory Use-After-Free attempt (more info ...)attempted-user 2011-1453 46677  URL
26354BROWSER-IE Microsoft Internet Explorer expression clause in style tag cross site scripting attempt (more info ...)web-application-attack 2013-1289   URL
26439FILE-JAVA Oracle Java known malicious jar file download - specific structure (more info ...)trojan-activity    
26440INDICATOR-OBFUSCATION Obfuscated javascript/html generated by myobfuscate.com detected (more info ...)bad-unknown    URL
26451INDICATOR-OBFUSCATION g01pack Javascript substr function wrapper attempt (more info ...)trojan-activity    URL
26483SERVER-WEBAPP JavaScript tag in User-Agent field possible XSS attempt (more info ...)web-application-attack    URL
26484FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26485FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26486FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26487FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26499FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26500FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26513FILE-PDF PDF with large embedded JavaScript - JS string attempt (more info ...)policy-violation    URL
26524BROWSER-PLUGINS Java security warning bypass through JWS attempt (more info ...)attempted-user    URL
26525BROWSER-PLUGINS Java security warning bypass through JWS attempt (more info ...)attempted-user    URL
26549FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26550FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26551FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26552FILE-JAVA Oracle Java JRE reflection types public final field overwrite attempt (more info ...)attempted-user 2013-2423 59162  URL
26577MALWARE-CNC User-Agent known malicious user agent Opera 10 (more info ...)trojan-activity    URL
26587FILE-JAVA Oracle Java runtime JMX findclass sandbox breach attempt (more info ...)attempted-admin 2013-0431 57563  
26588FILE-JAVA Oracle Java runtime JMX findclass sandbox breach attempt (more info ...)attempted-admin 2013-0431 57563  
26592BROWSER-WEBKIT Apple Safari Webkit libxslt arbitrary file creation attempt (more info ...)attempted-user 2011-1774 48840  URL
26595INDICATOR-OBFUSCATION javascript hex character extraction routine detected (more info ...)policy-violation    URL
26596INDICATOR-OBFUSCATION javascript fromCharCode xor decryption routine detected (more info ...)policy-violation    URL
26615INDICATOR-OBFUSCATION Javascript substr rename attempt (more info ...)misc-activity    URL
26616INDICATOR-OBFUSCATION Javascript indexOf rename attempt (more info ...)misc-activity    URL
26624BROWSER-IE Microsoft Internet Explorer 7-9 VBScript JSON reference information disclosure attempt (more info ...)attempted-recon 2013-1297   URL
26625BROWSER-IE Microsoft Internet Explorer 7-9 VBScript JSON reference information disclosure attempt (more info ...)attempted-recon 2013-1297   URL
26639BROWSER-IE Microsoft Internet Explorer XML digital signature transformation of digest value (more info ...)misc-activity 2013-1336   URL
26640BROWSER-IE Microsoft Internet Explorer XML digital signature transformation of digest value (more info ...)misc-activity 2013-1336   URL
26646BROWSER-PLUGINS Java security warning bypass through JWS attempt (more info ...)attempted-user    URL
26647BROWSER-PLUGINS Java security warning bypass through JWS attempt (more info ...)attempted-user    URL
26650FILE-PDF Adobe Acrobat Reader javascript regex embedded sandbox escape attempt (more info ...)attempted-user 2013-2550   URL
26658BROWSER-WEBKIT Possible Google Chrome Plugin install from non-trusted source (more info ...)bad-unknown    URL
26659BROWSER-FIREFOX Possible Mozilla Firefox Plugin install from non-Mozilla source (more info ...)bad-unknown    URL
26765BROWSER-PLUGINS Oracle Java Web Start control launchapp ActiveX function call access (more info ...)attempted-user 2013-2416   URL
26766BROWSER-PLUGINS Oracle Java Web Start control launchapp ActiveX clsid access (more info ...)attempted-user 2013-2416   URL
26767BROWSER-PLUGINS Oracle Java Web Start control launchapp embed access (more info ...)attempted-user 2013-2416   URL
26817FILE-PDF Adobe Acrobat Reader javascript regex embedded sandbox escape attempt (more info ...)attempted-user 2013-2550   URL
26848BROWSER-IE Microsoft Internet Explorer 7 emulation via meta tag (more info ...)attempted-user    
26850INDICATOR-COMPROMISE Microsoft Internet Explorer IE5 compatibility mode enable attempt (more info ...)policy-violation    URL
26852BROWSER-IE Microsoft Internet Explorer create-add range on DOM objects memory corruption attempt (more info ...)attempted-user 2013-3124   URL
26853BROWSER-IE Microsoft Internet Explorer create-add range on DOM objects memory corruption attempt (more info ...)attempted-user 2013-3124   URL
26890BROWSER-IE Microsoft Internet Explorer CDocument use after free attempt (more info ...)attempted-user 2013-3114   URL
26935BROWSER-IE Microsoft Internet Explorer image download spoofing attempt (more info ...)bad-unknown  11768  
26936BROWSER-IE Microsoft Internet Explorer image download spoofing attempt (more info ...)bad-unknown  11768  
26937BROWSER-IE Microsoft Internet Explorer image download spoofing attempt (more info ...)bad-unknown  11768  
26947EXPLOIT-KIT DotkaChef/Rmayana/DotCache exploit kit inbound java exploit download (more info ...)trojan-activity 2013-2423   URL
26948EXPLOIT-KIT DotkaChef/Rmayana/DotCache exploit kit inbound java exploit download (more info ...)trojan-activity 2013-1493   URL
26994BROWSER-PLUGINS Oracle Javadoc generated frame replacement attempt (more info ...)attempted-user 2013-1571   
27063BROWSER-IE Microsoft Internet Explorer file type spoofing attempt (more info ...)bad-unknown 2004-1331 11686  
27222BROWSER-IE Microsoft Internet Explorer innerHTML against incomplete element heap corruption attempt (more info ...)attempted-user 2010-0490 39031  URL
27260MALWARE-CNC Win.Trojan.Java.Agent.NFK variant connection (more info ...)trojan-activity    URL
27531BROWSER-IE Microsoft Internet Explorer 9 and 10 information disclosure attempt (more info ...)attempted-user    URL
27593INDICATOR-OBFUSCATION Javascript obfuscation - split (more info ...)attempted-user    URL
27663BROWSER-IE Microsoft Internet Explorer 9 memory disclosure attempt (more info ...)attempted-recon 2012-1873 53844  URL
27693FILE-JAVA Oracle Java 2D ImagingLib BytePackedRaster signed integer overflow attempt (more info ...)attempted-user 2013-2549   URL
27694FILE-JAVA Oracle Java 2D ImagingLib BytePackedRaster signed integer overflow attempt (more info ...)attempted-user 2013-2549   URL
27875INDICATOR-OBFUSCATION Javascript obfuscation technique - has been observed in Rmayana/DotkaChef/DotCache exploit kit (more info ...)trojan-activity    
27943BROWSER-IE Microsoft Internet Explorer onlosecapture memory corruption attempt (more info ...)attempted-user 2013-3893 62453  URL
27944BROWSER-IE Microsoft Internet Explorer onlosecapture memory corruption attempt (more info ...)attempted-user 2013-3893 62453  URL
28043OS-MOBILE Android WebKit Java reflection command execution attempt (more info ...)attempted-user 2014-0514   URL
28157BROWSER-PLUGINS Oracle Java XML digital signature spoofing attempt (more info ...)attempted-user 2013-2461   URL
28163BROWSER-IE Microsoft Internet Explorer HtmlLayout SmartObject use after free attempt (more info ...)attempted-user 2013-3873   URL
28207BROWSER-IE Microsoft Internet Explorer swapNode memory corruption attempt (more info ...)attempted-user 2013-3897 62811  URL
28208BROWSER-IE Microsoft Internet Explorer swapNode memory corruption attempt (more info ...)attempted-user 2013-3897 62811  URL
28258BROWSER-IE Microsoft Internet Explorer object management memory corruption attempt (more info ...)attempted-user 2011-1345 46821  URL
28259BROWSER-IE Microsoft Internet Explorer object management memory corruption attempt (more info ...)attempted-user 2011-1345 46821  URL
28267BROWSER-IE Microsoft Internet Explorer option element use after free attempt (more info ...)attempted-user 2011-1995   URL
28268BROWSER-IE Microsoft Internet Explorer option element use after free attempt (more info ...)attempted-user 2011-1995   URL
28269BROWSER-IE Microsoft Internet Explorer option element use after free attempt (more info ...)attempted-user 2011-1995   URL
28270BROWSER-IE Microsoft Internet Explorer option element use after free attempt (more info ...)attempted-user 2011-1995   URL
28271BROWSER-IE Microsoft Internet Explorer htmlfile null attribute access attempt (more info ...)attempted-user 2011-1995 49960  URL
28272BROWSER-PLUGINS Microsoft Internet Explorer htmlfile ActiveX object access attempt (more info ...)attempted-user 2011-1995 49960  URL
28287BROWSER-IE Microsoft Internet Explorer deleted object cells reference memory corruption vulnerability (more info ...)attempted-user 2010-0248   
28306BROWSER-IE Microsoft Internet Explorer CSS expression defined to empty selection attempt (more info ...)attempted-user 2011-1261 48210  URL
28352BROWSER-IE Microsoft Internet Explorer CTableLayout memory corruption attempt (more info ...)attempted-user 2010-0244 37891  URL
28353BROWSER-IE Microsoft Internet Explorer CTableLayout memory corruption attempt (more info ...)attempted-user 2010-0244 37891  URL
28447BROWSER-IE Microsoft Internet Explorer style.position use-after-free memory corruption attempt (more info ...)attempted-dos 2012-0155   URL
28522BROWSER-IE Microsoft Internet Explorer print preview information disclosure attempt (more info ...)attempted-recon 2013-3908   URL
28662BROWSER-IE Microsoft Internet Explorer address bar spoofing attempt (more info ...)attempted-user 2006-1626 17404  
28663BROWSER-IE Microsoft Internet Explorer address bar spoofing attempt (more info ...)attempted-user 2006-1626 17404  
28722FILE-PDF Adobe Acrobat Reader invalid PDF JavaScript printSeps extension call attempt (more info ...)attempted-user 2010-4091   
28723FILE-PDF Adobe Acrobat Reader invalid PDF JavaScript printSeps extension call attempt (more info ...)attempted-user 2010-4091   
28932BROWSER-IE Microsoft Internet Explorer CHM file load attempt (more info ...)misc-activity    URL
28997BROWSER-IE Microsoft Internet Explorer print preview information disclosure attempt (more info ...)attempted-recon 2013-3908   URL
29037BROWSER-PLUGINS Microsoft Internet Explorer DXImageTransform.Microsoft.MMSpecialEffectInplace1Input ActiveX function call access (more info ...)attempted-user 2006-1303 18328  URL
29168BROWSER-IE Microsoft Internet Explorer EUC-JP encoding cross site scripting attempt (more info ...)attempted-user 2013-3192   URL
29214FILE-JAVA Oracle Java JPEGImageWriter memory corruption attempt (more info ...)attempted-user 2013-2429   
29215FILE-JAVA Oracle Java sun.awt.image.ImageRepresentation.setPixels integer overflow attempt (more info ...)attempted-user 2013-2420   
29221BROWSER-IE Microsoft Internet Explorer blnmgr clsid access attempt (more info ...)attempted-user 2005-1990 14511  URL
29222BROWSER-IE Microsoft Internet Explorer devenum clsid access attempt (more info ...)attempted-user 2005-1990 14511  URL
29223BROWSER-IE Microsoft Internet Explorer msdds clsid access attempt (more info ...)attempted-user 2005-2127 14594  URL
29226BROWSER-PLUGINS Microsoft Internet Explorer ACM Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29227BROWSER-PLUGINS Microsoft Internet Explorer Address Bar ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29228BROWSER-PLUGINS Microsoft Internet Explorer CLSID_ApprenticeICW ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29229BROWSER-PLUGINS Microsoft Internet Explorer CLSID_CDIDeviceActionConfigPage ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29230BROWSER-PLUGINS Microsoft Internet Explorer CommunicationManager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29231BROWSER-PLUGINS Microsoft Internet Explorer Content.mbcontent.1 ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29232BROWSER-PLUGINS Microsoft Internet Explorer DiskManagement.Connection ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29233BROWSER-PLUGINS Microsoft Internet Explorer Dutch_Dutch Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29234BROWSER-PLUGINS Microsoft Internet Explorer English_UK Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29235BROWSER-PLUGINS Microsoft Internet Explorer English_US Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29236BROWSER-PLUGINS Microsoft Internet Explorer French_French Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29237BROWSER-PLUGINS Microsoft Internet Explorer German_German Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29238BROWSER-PLUGINS Microsoft Internet Explorer ICM Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29239BROWSER-PLUGINS Microsoft Internet Explorer ISSimpleCommandCreator.1 ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29240BROWSER-PLUGINS Microsoft Internet Explorer Italian_Italian Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29241BROWSER-PLUGINS Microsoft Internet Explorer MidiOut Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29242BROWSER-PLUGINS Microsoft Internet Explorer Mslablti.MarshalableTI.1 ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29243BROWSER-PLUGINS Microsoft Internet Explorer PostBootReminder object ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29244BROWSER-PLUGINS Microsoft Internet Explorer QC.MessageMover.1 ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29245BROWSER-PLUGINS Microsoft Internet Explorer ShellFolder for CD Burning ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29246BROWSER-PLUGINS Microsoft Internet Explorer Spanish_Modern Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29247BROWSER-PLUGINS Microsoft Internet Explorer Swedish_Default Stemmer ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29248BROWSER-PLUGINS Microsoft Internet Explorer VFW Capture Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29249BROWSER-PLUGINS Microsoft Internet Explorer Video Effect Class Manager 1 Input ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29250BROWSER-PLUGINS Microsoft Internet Explorer Video Effect Class Manager 2 Input ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29251BROWSER-PLUGINS Microsoft Internet Explorer WDM Instance Provider ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29252BROWSER-PLUGINS Microsoft Internet Explorer WIA FileSystem USD ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29253BROWSER-PLUGINS Microsoft Internet Explorer WaveIn Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29254BROWSER-PLUGINS Microsoft Internet Explorer WaveOut and DSound Class Manager ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29255BROWSER-PLUGINS Microsoft Internet Explorer clbcatex.dll ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29256BROWSER-PLUGINS Microsoft Internet Explorer clbcatq.dll ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29257BROWSER-PLUGINS Microsoft Internet Explorer syncui.dll ActiveX clsid access (more info ...)attempted-user 2005-1990 14511  URL
29408MALWARE-CNC JAVAFOG Java malware backdoor connection to cnc server (more info ...)trojan-activity    URL
29519INDICATOR-OBFUSCATION Javascript obfuscation using split reverse join (more info ...)attempted-user    URL
29650BROWSER-IE Microsoft Internet Explorer MoveToMarkupPointer call with CControlTracker OnExitTree use-after-free attempt (more info ...)attempted-user 2013-3184 61668  URL
29651BROWSER-IE Microsoft Internet Explorer MoveToMarkupPointer call with CControlTracker OnExitTree use-after-free attempt (more info ...)attempted-user 2013-3184 61668  URL
29675BROWSER-IE Microsoft Internet Explorer type confusion attempt (more info ...)attempted-user 2014-0271   URL
29713BROWSER-IE Microsoft Internet Explorer overlapping object boundaries memory corruption attempt (more info ...)attempted-user 2014-0263 65393  URL
29714BROWSER-IE Microsoft Internet Explorer overlapping object boundaries memory corruption attempt (more info ...)attempted-user 2014-0263 65393  URL
29719BROWSER-IE Microsoft Internet Explorer SLayoutRun use after free attempt (more info ...)attempted-user 2014-0276   URL
29720BROWSER-IE Microsoft Internet Explorer SLayoutRun use after free attempt (more info ...)attempted-user 2014-0276   URL
29754BROWSER-IE Microsoft Internet Explorer style.position use-after-free memory corruption attempt (more info ...)attempted-dos 2012-0155   URL
29755BROWSER-CHROME Google Chrome and Apple Safari Ruby before and after memory corruption (more info ...)attempted-user 2011-1440   
29758BROWSER-IE Microsoft Internet Explorer 8 Javascript negative option index attack attempt (more info ...)attempted-user 2011-1999 49964  URL
29802BROWSER-IE Microsoft Internet Explorer 8 deleted object access via timer memory corruption attempt (more info ...)attempted-user 2013-1311   URL
29803BROWSER-IE Microsoft Internet Explorer 8 deleted object access via timer memory corruption attempt (more info ...)attempted-user 2013-1311   URL
29804BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
29805BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
29806BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
29809BROWSER-WEBKIT Google Chrome and Apple Safari CSS float use-after-free attempt (more info ...)attempted-user 2011-2790 48960  
29810BROWSER-WEBKIT Google Chrome and Apple Safari CSS float use-after-free attempt (more info ...)attempted-user 2011-2790 48960  
29811BROWSER-WEBKIT Google Chrome and Apple Safari CSS float use-after-free attempt (more info ...)attempted-user 2011-2790 48960  
29812BROWSER-WEBKIT Google Chrome and Apple Safari CSS float use-after-free attempt (more info ...)attempted-user 2011-2790 48960  
29814BROWSER-IE Microsoft Internet Explorer null attribute DoS attempt (more info ...)attempted-user 2011-1997 49962  URL
29969FILE-JAVA Oracle Java java.util.concurrent.ConcurrentHashMap memory corruption attempt (more info ...)attempted-user 2013-2426 59206  URL
29970FILE-JAVA Oracle Java java.util.concurrent.ConcurrentHashMap memory corruption attempt (more info ...)attempted-user 2013-2426 59206  URL
29971FILE-JAVA Oracle Java java.util.concurrent.ConcurrentHashMap memory corruption attempt (more info ...)attempted-user 2013-2426 59206  URL
29972FILE-JAVA Oracle Java java.util.concurrent.ConcurrentHashMap memory corruption attempt (more info ...)attempted-user 2013-2426 59206  URL
30102BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3882   URL
30103BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3882   URL
30104BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3882   URL
30105BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3882   URL
30218FILE-JAVA Oracle Java font rendering remote code execution attempt (more info ...)attempted-user 2013-1491   URL
30252BROWSER-CHROME Google Chrome XSSAuditor filter security policy bypass attempt (more info ...)attempted-user  65066  URL
30289BROWSER-IE Microsoft Internet Explorer HtmlLayout SmartObject use after free attempt (more info ...)attempted-user 2013-3873   URL
30396INDICATOR-SHELLCODE Metasploit payload java_jsp_shell_bind_tcp (more info ...)shellcode-detect    
30397INDICATOR-SHELLCODE Metasploit payload java_shell_reverse_tcp (more info ...)shellcode-detect    
30485BROWSER-FIREFOX Mozilla Firefox nsTreeRange Use After Free attempt (more info ...)attempted-user 2010-2753   URL
30486BROWSER-FIREFOX Mozilla Firefox nsTreeRange Use After Free attempt (more info ...)attempted-user 2010-2753   URL
30490BROWSER-IE Microsoft Internet Explorer address bar spoofing with scripting (more info ...)attempted-user 2004-2219 10943  
30491BROWSER-IE Microsoft Internet Explorer address bar spoofing with scripting (more info ...)attempted-user 2004-2219 10943  
30508BROWSER-IE Microsoft Internet Explorer 7 swapNode use after free attempt (more info ...)attempted-user 2014-1752   URL
30509BROWSER-IE Microsoft Internet Explorer 7 swapNode use after free attempt (more info ...)attempted-user 2014-1752   URL
30849BROWSER-IE Microsoft Internet Explorer type confusion attempt (more info ...)attempted-user 2014-0271   URL
30850BROWSER-IE Microsoft Internet Explorer type confusion attempt (more info ...)attempted-user 2014-0271   URL
30851BROWSER-IE Microsoft Internet Explorer type confusion attempt (more info ...)attempted-user 2014-0271   URL
30878EXPLOIT-KIT Goon/Infinity exploit kit mp3 requested by Java (more info ...)trojan-activity    
30918MALWARE-CNC User-Agent known malicious user agent - User-Agent User-Agent Mozilla (more info ...)trojan-activity    URL
31192BROWSER-IE Microsoft Internet Explorer 11 use after free attempt (more info ...)attempted-user 2014-1762   URL
31193BROWSER-IE Microsoft Internet Explorer 11 use after free attempt (more info ...)attempted-user 2014-1762   URL
31194BROWSER-IE Microsoft Internet Explorer onpagehide use after free attempt (more info ...)attempted-user 2014-1795   URL
31195SERVER-WEBAPP VMTurbo Operations Manager directory traversal attempt (more info ...)attempted-admin 2014-3806 67292  
31200BROWSER-IE Microsoft Internet Explorer summary node swap use after free attempt (more info ...)attempted-user 2014-1789   URL
31201BROWSER-IE Microsoft Internet Explorer summary node swap use after free attempt (more info ...)attempted-user 2014-1789   URL
31208BROWSER-IE Microsoft Internet Explorer CDispNode use after free attempt (more info ...)attempted-user 2014-1766   URL
31209BROWSER-IE Microsoft Internet Explorer CDispNode use after free attempt (more info ...)attempted-user 2014-1766   URL
31283FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin 2014-0517   URL
31285FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin 2014-0517   URL
31301BROWSER-IE Microsoft Internet Explorer XSLT memory corruption attempt (more info ...)attempted-user 2011-1963 49037  URL
31386BROWSER-IE Microsoft Internet Explorer CLayout object user after free attempt (more info ...)attempted-user 2014-2801   URL
31387BROWSER-IE Microsoft Internet Explorer CLayout object user after free attempt (more info ...)attempted-user 2014-2801   URL
31390BROWSER-IE Microsoft Internet Explorer BSTR use after free attempt (more info ...)attempted-user 2014-2804   URL
31391BROWSER-IE Microsoft Internet Explorer BSTR use after free attempt (more info ...)attempted-user 2014-2804   URL
31402BROWSER-IE Microsoft Internet Explorer Unexpected method call remote code execution attempt (more info ...)attempted-user 2009-1141   URL
31428BROWSER-IE Microsoft Internet Explorer html table column span width increase memory corruption attempt (more info ...)attempted-user 2012-1876   URL
31469BROWSER-IE Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt (more info ...)attempted-user 2012-1880   URL
31471BROWSER-IE Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt (more info ...)attempted-user 2012-1880   URL
31495FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin 2014-0519   URL
31496FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin 2014-0519   URL
31504BROWSER-IE Microsoft Internet Explorer outerHTML against incomplete element heap corruption attempt (more info ...)attempted-user 2010-0490   URL
31557MALWARE-CNC User-Agent known malicious user-agent string - Mozilla/5.0 - Win.Trojan.Upatre (more info ...)trojan-activity    URL
31594BROWSER-CHROME Google Chrome NotifyInstanceWasDeleted object use after free attempt (more info ...)attempted-user 2013-2912 62752  
31595BROWSER-CHROME Google Chrome NotifyInstanceWasDeleted object use after free attempt (more info ...)attempted-user 2013-2912 62752  
31596BROWSER-CHROME Google Chrome NotifyInstanceWasDeleted embed use after free attempt (more info ...)attempted-user 2013-2912 62752  
31597BROWSER-CHROME Google Chrome NotifyInstanceWasDeleted embed use after free attempt (more info ...)attempted-user 2013-2912 62752  
31598BROWSER-CHROME Google Chrome NotifyInstanceWasDeleted object use after free attempt (more info ...)attempted-user 2013-2912 62752  
31599BROWSER-CHROME Google Chrome NotifyInstanceWasDeleted embed use after free attempt (more info ...)attempted-user 2013-2912 62752  
31617BROWSER-IE Microsoft Internet Explorer meter element use-after-free attempt (more info ...)attempted-user 2012-2548   URL
31618BROWSER-IE Microsoft Internet Explorer meter element use-after-free attempt (more info ...)attempted-user 2012-2548   URL
31645BROWSER-IE Microsoft Internet Explorer 5 XML page object type validation (more info ...)attempted-user 2003-0809 8565  
31646BROWSER-IE Microsoft Internet Explorer 5 XML page object type validation (more info ...)attempted-user 2003-0809 8565  
31749FILE-FLASH Adobe Flash Player marshallException through JavaScript XSS attempt (more info ...)attempted-user 2014-0531 67962  URL
31750FILE-FLASH Adobe Flash Player marshallException through JavaScript XSS attempt (more info ...)attempted-user 2014-0531 67962  URL
31796BROWSER-IE Microsoft Internet Explorer 11 CTreeNode use after free (more info ...)attempted-user 2014-4089   URL
31797BROWSER-IE Microsoft Internet Explorer 11 CTreeNode use after free (more info ...)attempted-user 2014-4089   URL
31811BROWSER-IE Microsoft Internet Explorer CHtmlLayout use after free attempt (more info ...)attempted-user 2014-4086   URL
31812BROWSER-IE Microsoft Internet Explorer CHtmlLayout use after free attempt (more info ...)attempted-user 2014-4086   URL
31821FILE-OTHER Mozilla products clipPath element stroke-width buffer overflow attempt (more info ...)attempted-user 2007-0776   
31822FILE-OTHER Mozilla products clipPath element stroke-width buffer overflow attempt (more info ...)attempted-user 2007-0776   
31887BROWSER-IE Microsoft Internet Explorer URL domain spoof attempt (more info ...)attempted-user 2003-1025   URL
31888BROWSER-IE Microsoft Internet Explorer URL domain spoof attempt (more info ...)attempted-user 2003-1025   URL
32133BROWSER-FIREFOX Mozilla Firefox XBM image processing buffer overflow attempt (more info ...)attempted-user 2005-2701 14916  
32157BROWSER-IE Microsoft Internet Explorer 11 CMarkup GetMarkupTitle use-after-free attempt (more info ...)attempted-user 2014-4130   URL
32158BROWSER-IE Microsoft Internet Explorer 11 CMarkup GetMarkupTitle use-after-free attempt (more info ...)attempted-user 2014-4130   URL
32163BROWSER-IE Microsoft Internet Explorer GetUpdatedLayout partial table declaration use-after-free attempt (more info ...)attempted-user 2014-4128   URL
32164BROWSER-IE Microsoft Internet Explorer GetUpdatedLayout partial table declaration use-after-free attempt (more info ...)attempted-user 2014-4128   URL
32230BROWSER-IE Microsoft Internet Explorer address bar spoofing without scripting (more info ...)attempted-user 2004-2219 10943  
32231BROWSER-IE Microsoft Internet Explorer address bar spoofing without scripting (more info ...)attempted-user 2004-2219 10943  
32244BROWSER-FIREFOX Mozilla 1.0 Javascript arbitrary cookie access attempt (more info ...)attempted-user 2002-2314 5293  
32262BROWSER-IE Microsoft Internet Explorer Active X installer broker privilege elevation attempt (more info ...)attempted-user 2015-1743   URL
32263BROWSER-IE Microsoft Internet Explorer Active X installer broker privilege elevation attempt (more info ...)attempted-user 2015-1743   URL
32266BROWSER-IE Microsoft Internet Explorer 11 out of bounds array access attempt (more info ...)attempted-user 2014-4140   URL
32267BROWSER-IE Microsoft Internet Explorer 11 out of bounds array access attempt (more info ...)attempted-user 2014-4140   URL
32319BROWSER-CHROME Google Chrome Blink locationAttributeSetter use after free attempt (more info ...)attempted-user 2014-1713 66243  URL
32320BROWSER-CHROME Google Chrome Blink locationAttributeSetter use after free attempt (more info ...)attempted-user 2014-1713 66243  URL
32355INDICATOR-OBFUSCATION Javascript variable obfuscation (more info ...)bad-unknown    URL
32394MALWARE-CNC Win.Trojan.Orcarat variant outbound connection (more info ...)trojan-activity    URL
32395MALWARE-CNC Win.Trojan.Orcarat variant outbound connection (more info ...)trojan-activity    URL
32396MALWARE-CNC Win.Trojan.Orcarat variant outbound connection (more info ...)trojan-activity    URL
32397MALWARE-CNC Win.Trojan.Orcarat variant outbound connection (more info ...)trojan-activity    URL
32436BROWSER-IE Microsoft Internet Explorer document.URL override information disclosure attempt (more info ...)attempted-recon 2014-6340   URL
32437BROWSER-IE Microsoft Internet Explorer document.URL override information disclosure attempt (more info ...)attempted-recon 2014-6340   URL
32458BROWSER-IE Microsoft Internet Explorer clipboardData unauthorized JavaScript read and write attempt (more info ...)attempted-admin 2014-6323   URL
32459BROWSER-IE Microsoft Internet Explorer clipboardData unauthorized JavaScript read and write attempt (more info ...)attempted-admin 2014-6323   URL
32482BROWSER-IE Microsoft Internet Explorer pasteHTML use after free attempt (more info ...)attempted-user 2014-6339   URL
32483BROWSER-IE Microsoft Internet Explorer pasteHTML use after free attempt (more info ...)attempted-user 2014-6339   URL
32484BROWSER-IE Microsoft Internet Explorer immutable application settings sandbox escape attempt (more info ...)attempted-user 2014-6349   URL
32485BROWSER-IE Microsoft Internet Explorer immutable application settings sandbox escape attempt (more info ...)attempted-user 2014-6349   URL
32491BROWSER-IE Microsoft Internet Explorer information disclosure attempt (more info ...)misc-activity 2014-6346   URL
32492BROWSER-IE Microsoft Internet Explorer information disclosure attempt (more info ...)misc-activity 2014-6346   URL
32499FILE-OTHER Microsoft Internet Explorer EPM sandbox escape attempt (more info ...)attempted-user 2014-6350   URL
32500FILE-OTHER Microsoft Internet Explorer EPM sandbox escape attempt (more info ...)attempted-user 2014-6350   URL
32518FILE-OTHER Microsoft Internet Explorer registry symbolic link attack attempt (more info ...)attempted-user 2014-6322   URL
32519FILE-OTHER Microsoft Internet Explorer registry symbolic link attack attempt (more info ...)attempted-user 2014-6322   URL
32532BROWSER-IE Microsoft Internet Explorer style sheet array memory corruption attempt (more info ...)attempted-user 2011-0027 40410  URL
32641EXPLOIT-KIT Sweet Orange exploit kit Oracle Java jnlp file requested on defined port (more info ...)trojan-activity    
32693BROWSER-IE Microsoft Internet Explorer CSS out-of-bounds buffer access attempt (more info ...)attempted-user 2014-6368   URL
32694BROWSER-IE Microsoft Internet Explorer CSS out-of-bounds buffer access attempt (more info ...)attempted-user 2014-6368   URL
32695BROWSER-IE Microsoft Internet Explorer JPEG stack information disclosure attempt (more info ...)attempted-user 2014-6355   URL
32696BROWSER-IE Microsoft Internet Explorer JPEG stack information disclosure attempt (more info ...)attempted-user 2014-6355   URL
32697BROWSER-IE Microsoft Internet Explorer JPEG stack information disclosure attempt (more info ...)attempted-user 2014-6355   URL
32698BROWSER-IE Microsoft Internet Explorer JPEG stack information disclosure attempt (more info ...)attempted-user 2014-6355   URL
32699BROWSER-IE Microsoft Internet Explorer JPEG stack information disclosure attempt (more info ...)attempted-user 2014-6355   URL
32700BROWSER-IE Microsoft Internet Explorer JPEG stack information disclosure attempt (more info ...)attempted-user 2014-6355   URL
32701BROWSER-IE Microsoft Internet Explorer JPEG stack information disclosure attempt (more info ...)attempted-user 2014-6355   URL
32702BROWSER-IE Microsoft Internet Explorer JPEG stack information disclosure attempt (more info ...)attempted-user 2014-6355   URL
32710BROWSER-IE Microsoft Internet Explorer XSS filter bypass attempt (more info ...)web-application-attack 2014-6365   URL
32713BROWSER-OTHER Microsoft Internet Explorer cross site scripting filter bypass attempt (more info ...)attempted-user 2014-6328   URL
32762BROWSER-IE Microsoft Internet Explorer TextRange after free attempt (more info ...)attempted-user 2014-0307   URL
32763BROWSER-IE Microsoft Internet Explorer TextRange after free attempt (more info ...)attempted-user 2014-0307   URL
32777BROWSER-IE Microsoft Internet Explorer CheaderElement use after free attempt (more info ...)attempted-user 2014-8967   
32778BROWSER-IE Microsoft Internet Explorer CheaderElement use after free attempt (more info ...)attempted-user 2014-8967   
32787FILE-PDF Adobe Acrobat Reader privileged JavaScript execution attempt (more info ...)misc-activity 2014-8448   URL
32788FILE-PDF Adobe Acrobat Reader privileged JavaScript execution attempt (more info ...)misc-activity 2014-8448   URL
32789FILE-PDF Adobe Acrobat Reader privileged JavaScript execution attempt (more info ...)misc-activity 2014-8448   URL
32790FILE-PDF Adobe Acrobat Reader privileged JavaScript execution attempt (more info ...)misc-activity 2014-8448   URL
32840BROWSER-PLUGINS Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access (more info ...)attempted-user 2010-0811   URL
32842BROWSER-PLUGINS Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access (more info ...)attempted-user 2010-0811   URL
32843BROWSER-PLUGINS Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access (more info ...)attempted-user 2010-0811   URL
32844BROWSER-PLUGINS Microsoft Internet Explorer COleSite ActiveX memory corruption attempt (more info ...)attempted-user 2010-3340   URL
32993BROWSER-FIREFOX Mozilla Firefox XMLSerializer serializeToStream use-after-free attempt (more info ...)attempted-user 2013-0753 57209  URL
32994BROWSER-FIREFOX Mozilla Firefox XMLSerializer serializeToStream use-after-free attempt (more info ...)attempted-user 2013-0753 57209  URL
33099BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3871   URL
33162FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin 2014-0583   URL
33163FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-admin 2014-0583   URL
33243MALWARE-CNC User-Agent known malicious user-agent string - Mozilla - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33244MALWARE-CNC User-Agent known malicious user-agent string - Opera - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33245MALWARE-CNC User-Agent known malicious user-agent string - Opera10 - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33246MALWARE-CNC User-Agent known malicious user-agent string - OperaMini - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33287BROWSER-IE Microsoft Internet Explorer same origin policy bypass attempt (more info ...)attempted-user 2016-0005   URL
33288BROWSER-IE Microsoft Internet Explorer same origin policy bypass attempt (more info ...)attempted-user 2016-0005   URL
33319BROWSER-IE Microsoft Internet Explorer EPM MOTWCreateFileW file access bypass attempt (more info ...)policy-violation 2015-0055 64120  URL
33320BROWSER-IE Microsoft Internet Explorer EPM MOTWCreateFileW file access bypass attempt (more info ...)policy-violation 2015-0055   URL
33321BROWSER-IE Microsoft Internet Explorer EPM MOTWCreateFileW file access bypass attempt (more info ...)policy-violation 2015-0055 64120  URL
33322BROWSER-IE Microsoft Internet Explorer EPM MOTWCreateFileW file access bypass attempt (more info ...)policy-violation 2015-0055   URL
33337BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
33338BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
33352BROWSER-IE Microsoft Internet Explorer 9 error handler XSS exploit attempt (more info ...)attempted-user 2015-0070   URL
33413BROWSER-IE Microsoft Internet Explorer unitialized memory access attempt (more info ...)attempted-user 2015-0051   URL
33414BROWSER-IE Microsoft Internet Explorer unitialized memory access attempt (more info ...)attempted-user 2015-0051   URL
33423BROWSER-IE Microsoft Internet Explorer CHeaderElement object use after free attempt (more info ...)attempted-user 2014-8967   URL
33424BROWSER-IE Microsoft Internet Explorer CHeaderElement object use after free attempt (more info ...)attempted-user 2014-8967   URL
33492BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
33493BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
33494BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
33495BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
33513MALWARE-CNC User-Agent known malicious user-agent string - XAgent - Operation Pawn Storm (more info ...)trojan-activity    URL
33525FILE-OTHER Apple OSX Safari format string validation corruption attempt (more info ...)attempted-user 2007-0644   
33526FILE-OTHER Apple OSX Safari format string validation corruption attempt (more info ...)attempted-user 2007-0644   
33566BROWSER-FIREFOX Mozilla Firefox 3 xsl parsing heap overflow attempt (more info ...)attempted-user 2009-1169 34235  URL
33569BROWSER-IE Microsoft Internet Explorer CTableLayout memory corruption attempt (more info ...)attempted-user 2010-0244 37891  URL
33570BROWSER-IE Microsoft Internet Explorer CTableLayout memory corruption attempt (more info ...)attempted-user 2010-0244 37891  URL
33588FILE-OTHER Oracle Java WebStart JNLP stack buffer overflow attempt (more info ...)attempted-user 2007-3655   
33605BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3882   URL
33606BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3882   URL
33622BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33623BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33624BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33625BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33626BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33627BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33628BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33629BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33630BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33631BROWSER-WEBKIT Apple Safari feeds URI null pointer dereference denial of service attempt (more info ...)denial-of-service 2009-0744   
33638BROWSER-IE Microsoft Internet Explorer Java applet denial of service attempt (more info ...)attempted-dos  15208  
33639BROWSER-IE Microsoft Internet Explorer Java applet denial of service attempt (more info ...)attempted-dos  15208  
33661BROWSER-CHROME Google Chrome NotifyInstanceWasDeleted embed use after free attempt (more info ...)attempted-user 2013-2912 62752  
33662BROWSER-CHROME Google Chrome NotifyInstanceWasDeleted object use after free attempt (more info ...)attempted-user 2013-2912 62752  
33720BROWSER-IE Microsoft Internet Explorer 11 sandbox bypass attempt (more info ...)attempted-user 2015-1627   URL
33721BROWSER-IE Microsoft Internet Explorer 11 sandbox bypass attempt (more info ...)attempted-user 2015-1627   URL
33760FILE-IMAGE Microsoft Internet Explorer PNG tRNS chuck size 1 information disclosure attempt (more info ...)misc-attack 2015-0080   URL
33761FILE-IMAGE Microsoft Internet Explorer PNG tRNS chuck size 1 information disclosure attempt (more info ...)misc-attack 2015-0080   URL
33897BROWSER-IE Microsoft Internet Explorer javascript iframe injection attempt (more info ...)attempted-user 2016-0005   URL
33898BROWSER-IE Microsoft Internet Explorer javascript iframe injection attempt (more info ...)attempted-user 2016-0005   URL
33903BROWSER-FIREFOX Mozilla Firefox proxy prototype privileged javascript execution attempt (more info ...)attempted-user 2014-8636 72041  
33904BROWSER-FIREFOX Mozilla Firefox proxy prototype privileged javascript execution attempt (more info ...)attempted-user 2014-8636 72041  
33962BROWSER-CHROME Google Chrome Pepper Flash same-origin-policy bypass attempt (more info ...)misc-attack 2015-0337   
34064BROWSER-IE Microsoft Internet Explorer CMapStringToPtr use after free attempt (more info ...)attempted-user 2015-1667   URL
34065BROWSER-IE Microsoft Internet Explorer CMapStringToPtr use after free attempt (more info ...)attempted-user 2015-1667   URL
34068BROWSER-IE Microsoft Internet Explorer 11 invalid array element read attempt (more info ...)attempted-user 2015-1661   URL
34069BROWSER-IE Microsoft Internet Explorer 11 invalid array element read attempt (more info ...)attempted-user 2015-1661   URL
34109BROWSER-FIREFOX Mozilla Firefox proxy prototype privileged javascript execution attempt (more info ...)attempted-user 2014-8636 72041  
34110BROWSER-FIREFOX Mozilla Firefox proxy prototype privileged javascript execution attempt (more info ...)attempted-user 2014-8636 72041  
34118INDICATOR-OBFUSCATION known malicious javascript packer detected (more info ...)misc-activity    URL
34170BROWSER-OTHER Opera SVG use after free memory corruption attempt (more info ...)attempted-dos 2013-1638 57633  
34171BROWSER-OTHER Opera SVG use after free memory corruption attempt (more info ...)attempted-dos 2013-1638 57633  
34299BROWSER-IE Microsoft Internet Explorer onpagehide use after free attempt (more info ...)attempted-user 2014-1795   URL
34320BROWSER-IE Microsoft Internet Explorer BSTR use after free attempt (more info ...)attempted-user 2014-2804   URL
34321BROWSER-IE Microsoft Internet Explorer BSTR use after free attempt (more info ...)attempted-user 2014-2804   URL
34379BROWSER-IE Microsoft Internet Explorer protected mode sandbox privilege escalation attempt (more info ...)attempted-user 2015-1713   URL
34380BROWSER-IE Microsoft Internet Explorer protected mode sandbox privilege escalation attempt (more info ...)attempted-user 2015-1713   URL
34391BROWSER-IE Microsoft Internet Explorer TextData out of bounds read attempt (more info ...)attempted-user 2015-1685   URL
34392BROWSER-IE Microsoft Internet Explorer TextData out of bounds read attempt (more info ...)attempted-user 2015-1685   URL
34393BROWSER-IE Microsoft Internet Explorer vbscript regular expression information disclosure attempt (more info ...)attempted-recon 2015-6052   URL
34394BROWSER-IE Microsoft Internet Explorer vbscript regular expression information disclosure attempt (more info ...)attempted-recon 2015-6052   URL
34405BROWSER-IE Microsoft Internet Explorer improper copy buffer access information disclosure attempt (more info ...)policy-violation 2015-1692   URL
34406BROWSER-IE Microsoft Internet Explorer improper copy buffer access information disclosure attempt (more info ...)policy-violation 2015-1692   URL
34407BROWSER-IE Microsoft Internet Explorer protected mode sandbox bypass attempt (more info ...)attempted-admin 2015-1688   URL
34408BROWSER-IE Microsoft Internet Explorer protected mode sandbox bypass attempt (more info ...)attempted-admin 2015-1688   URL
34416INDICATOR-COMPROMISE Microsoft Internet Explorer 8 compatibility mode enable attempt (more info ...)policy-violation    URL
34479FILE-EXECUTABLE Adobe Flash Player Internet Explorer broker process directory traversal attempt (more info ...)attempted-user 2015-3085   URL
34480FILE-EXECUTABLE Adobe Flash Player Internet Explorer broker process directory traversal attempt (more info ...)attempted-user 2015-3085   URL
34727BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
34728BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
34751BROWSER-IE Microsoft Internet Explorer ieframe.dll privilege escalation attempt (more info ...)attempted-user 2015-1748   URL
34752BROWSER-IE Microsoft Internet Explorer ieframe.dll privilege escalation attempt (more info ...)attempted-user 2015-1748   URL
34772BROWSER-IE Microsoft Internet Explorer MOTW.dll sandbox escape attempt (more info ...)attempted-admin 2015-1739   URL
34773BROWSER-IE Microsoft Internet Explorer MOTW.dll sandbox escape attempt (more info ...)attempted-admin 2015-1739   URL
34946BROWSER-FIREFOX Mozilla Firefox automatic user click event attempt (more info ...)attempted-user 2005-0145   URL
34947BROWSER-FIREFOX Mozilla Firefox automatic user click event attempt (more info ...)attempted-user 2005-0145   URL
35044BROWSER-WEBKIT Apple Safari URI spoofing attempt (more info ...)policy-violation 2015-1084   
35045BROWSER-WEBKIT Apple Safari URI spoofing attempt (more info ...)policy-violation 2015-1084   
35053BROWSER-IE Microsoft Internet Explorer CSVGMarkerElement use after free attempt (more info ...)attempted-user 2015-1668   
35116BROWSER-IE Microsoft Internet Explorer svg elements use after free attempt (more info ...)attempted-user 2015-2421   URL
35117BROWSER-IE Microsoft Internet Explorer svg elements use after free attempt (more info ...)attempted-user 2015-2421   URL
35127BROWSER-IE Microsoft Internet Explorer local file information disclosure attempt (more info ...)attempted-user 2015-2413   URL
35128BROWSER-IE Microsoft Internet Explorer local file information disclosure attempt (more info ...)attempted-user 2015-2413   URL
35133BROWSER-IE Microsoft Internet Explorer sandbox read permission bypass attempt (more info ...)attempted-user 2015-2412   URL
35134BROWSER-IE Microsoft Internet Explorer sandbox read permission bypass attempt (more info ...)attempted-user 2015-2412   URL
35160FILE-FLASH Microsoft Internet Explorer IDataObject bitmap data conversion integer overflow attempt (more info ...)attempted-user 2015-2364   URL
35161FILE-FLASH Microsoft Internet Explorer IDataObject bitmap data conversion integer overflow attempt (more info ...)attempted-user 2015-2364   URL
35162FILE-FLASH Microsoft Internet Explorer IDataObject bitmap data conversion integer overflow attempt (more info ...)attempted-user 2015-2364   URL
35163FILE-FLASH Microsoft Internet Explorer IDataObject bitmap data conversion integer overflow attempt (more info ...)attempted-user 2015-2364   URL
35171BROWSER-IE Microsoft Internet Explorer MutationObserver use after free attempt (more info ...)attempted-user 2015-2425 75745  URL
35184BROWSER-IE Microsoft Internet Explorer meta tag double free attempt (more info ...)attempted-user 2015-2391   URL
35186FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-user 2015-2417   URL
35187FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-user 2015-2417   URL
35188FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-user 2015-2417   URL
35189FILE-FLASH Adobe Flash Player Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-user 2015-2417   URL
35194POLICY-OTHER Microsoft Internet Explorer InPrivate mode image information leak attempt (more info ...)attempted-recon 2015-2414   URL
35195POLICY-OTHER Microsoft Internet Explorer InPrivate mode image information leak attempt (more info ...)attempted-recon 2015-2414   URL
35207BROWSER-IE Microsoft Internet Explorer JSON stringify double free attempt (more info ...)attempted-user 2015-2419   URL
35208BROWSER-IE Microsoft Internet Explorer JSON stringify double free attempt (more info ...)attempted-user 2015-2419   URL
35215BROWSER-IE Microsoft Internet Explorer protected mode atlthunk.dll dll-load exploit attempt (more info ...)attempted-user 2015-2368   URL
35216BROWSER-IE Microsoft Internet Explorer protected mode request for atlthunk.dll over SMB attempt (more info ...)attempted-user 2015-2368   URL
35411BROWSER-CHROME Google Chrome XSSAuditor Policy ByPass command injection attempt (more info ...)attempted-user    URL
35412BROWSER-CHROME Google Chrome xssauditor policy bypass command injection attempt (more info ...)attempted-user    URL
35438BROWSER-FIREFOX Mozilla Firefox JavaScript engine integer overflow attempt (more info ...)attempted-user 2005-2705 14917  
35439BROWSER-FIREFOX Mozilla Firefox JavaScript engine integer overflow attempt (more info ...)attempted-user 2005-2705 14917  
35460BROWSER-FIREFOX Mozilla Firefox InstallWrapper error handling code execution attempt (more info ...)attempted-user 2012-3993 56119  
35461BROWSER-FIREFOX Mozilla Firefox InstallWrapper error handling code execution attempt (more info ...)attempted-user 2012-3993 56119  
35479BROWSER-IE Microsoft Internet Explorer RecyclableObject type-confusion remote code execution attempt (more info ...)attempted-user 2015-2443   URL
35480BROWSER-IE Microsoft Internet Explorer RecyclableObject type-confusion remote code execution attempt (more info ...)attempted-user 2015-2443   URL
35507BROWSER-IE Microsoft Internet Explorer array prototype type confusion memory corruption attempt (more info ...)attempted-user 2015-2448   URL
35508BROWSER-IE Microsoft Internet Explorer array prototype type confusion memory corruption attempt (more info ...)attempted-user 2015-2448   URL
35675BROWSER-FIREFOX Mozilla Firefox PDF.js same origin policy violation attempt (more info ...)policy-violation 2015-4495   URL
35676BROWSER-FIREFOX Mozilla Firefox PDF.js same origin policy violation attempt (more info ...)policy-violation 2015-4495   URL
35739FILE-PDF Adobe Reader GoToE javascript execution attempt (more info ...)web-application-attack 2015-4449   URL
35740FILE-PDF Adobe Reader GoToE javascript execution attempt (more info ...)web-application-attack 2015-4449   URL
35881FILE-PDF download of a PDF with embedded JavaScript and U3D objects (more info ...)policy-violation    URL
35882FILE-PDF transfer of a PDF with embedded JavaScript and U3D objects (more info ...)policy-violation    URL
35998BROWSER-IE Microsoft Internet Explorer msGetRegionContent memory corruption attempt (more info ...)attempted-user 2015-2483   URL
35999BROWSER-IE Microsoft Internet Explorer msGetRegionContent memory corruption attempt (more info ...)attempted-user 2015-2483   URL
36020BROWSER-IE Microsoft Internet Explorer EPM SetValue sandbox bypass attempt (more info ...)policy-violation 2015-2489   URL
36021BROWSER-IE Microsoft Internet Explorer EPM SetValue sandbox bypass attempt (more info ...)policy-violation 2015-2489   URL
36070INDICATOR-OBFUSCATION Javascript obfuscation using split reverse join attempt (more info ...)attempted-user    URL
36360OS-MOBILE Android WebKit Java reflection command execution attempt (more info ...)attempted-user 2014-0514   URL
36361OS-MOBILE Android WebKit Java reflection command execution attempt (more info ...)attempted-user 2014-0514   URL
36362OS-MOBILE Android WebKit Java reflection command execution attempt (more info ...)attempted-user 2014-0514   URL
36377BROWSER-OTHER Google Chrome invalid URI denial of service attempt (more info ...)denial-of-service    URL
36378BROWSER-OTHER Google Chrome invalid URI denial of service attempt (more info ...)denial-of-service    URL
36411BROWSER-IE Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-user 2015-6047   URL
36412BROWSER-IE Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-user 2015-6047   URL
36413BROWSER-IE Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-user 2015-6047   URL
36414BROWSER-IE Microsoft Internet Explorer sandbox escape attempt (more info ...)attempted-user 2015-6047   URL
36417BROWSER-IE Microsoft Internet Explorer CWindow object use after free attempt (more info ...)attempted-user 2015-6042   URL
36431BROWSER-IE Microsoft Internet Explorer arraybuffer entryslice memory corruption attempt (more info ...)attempted-user 2015-6053   URL
36432BROWSER-IE Microsoft Internet Explorer arraybuffer entryslice memory corruption attempt (more info ...)attempted-user 2015-6053   URL
36433BROWSER-PLUGINS Microsoft Internet Explorer sapi.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-0675   URL
36434BROWSER-PLUGINS Microsoft Internet Explorer sapi.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-0675   URL
36447BROWSER-IE Microsoft Internet Explorer CSharedStyle object out-of-bounds read attempt (more info ...)attempted-admin 2015-6046   URL
36448BROWSER-IE Microsoft Internet Explorer CSharedStyle object out-of-bounds read attempt (more info ...)attempted-admin 2015-6046   URL
36453BROWSER-IE Microsoft Internet Explorer argument validation in print preview handling exploitation attempt (more info ...)attempted-user 2008-2259 30612  URL
36458BROWSER-IE Microsoft Internet Explorer vbscript regular expression information disclosure attempt (more info ...)attempted-recon 2015-6052   URL
36459BROWSER-IE Microsoft Internet Explorer vbscript regular expression information disclosure attempt (more info ...)attempted-recon 2015-6052   URL
36494BROWSER-IE Microsoft Internet Explorer Script Engine Stack Exhaustion Denial of Service attempt (more info ...)attempted-dos 2006-0753 16687  
36524FILE-JAVA Oracle Java TrueType font parsing mort table ligature subtable buffer overflow attempt (more info ...)attempted-dos    URL
36525FILE-JAVA Oracle Java TrueType font parsing mort table ligature subtable buffer overflow attempt (more info ...)attempted-dos    URL
36559BROWSER-IE Microsoft Internet Explorer arraybuffer entryslice memory corruption attempt (more info ...)attempted-user 2015-6053   URL
36560BROWSER-IE Microsoft Internet Explorer arraybuffer entryslice memory corruption attempt (more info ...)attempted-user 2015-6053   URL
36585BROWSER-WEBKIT Apple Safari user assisted applescript code execution attempt (more info ...)attempted-user 2015-7007   URL
36753BROWSER-IE Microsoft Internet Explorer CElement JSON write-what-where attempt (more info ...)attempted-user 2015-6089   URL
36754BROWSER-IE Microsoft Internet Explorer CElement JSON write-what-where attempt (more info ...)attempted-user 2015-6089   URL
36772BROWSER-PLUGINS Microsoft Internet Explorer Scriptlet Component ActiveX clsid access (more info ...)attempted-user 2010-3331   URL
36782BROWSER-PLUGINS Microsoft Internet Explorer DHTML Editing ActiveX clsid access (more info ...)attempted-user 2009-2519 36280  URL
36783BROWSER-PLUGINS Microsoft Internet Explorer DHTML Editing ActiveX clsid access (more info ...)attempted-user 2009-2519 36280  URL
36789BROWSER-FIREFOX Mozilla Firefox Javascript large regex memory corruption attempt (more info ...)attempted-user 2006-1737 17516  
36791BROWSER-IE Microsoft Internet Explorer data stream header remote code execution attempt (more info ...)attempted-user 2009-1547 36622  URL
36968BROWSER-IE Microsoft Internet Explorer CTableRow memory corruption attempt (more info ...)attempted-user 2015-6083   URL
36969BROWSER-IE Microsoft Internet Explorer CTableRow memory corruption attempt (more info ...)attempted-user 2015-6083   URL
37310BROWSER-CHROME Google Chrome MOTW pageSerializer HTML injection attempt (more info ...)attempted-dos 2015-6784   
37311BROWSER-CHROME Google Chrome MOTW pageSerializer HTML injection attempt (more info ...)attempted-dos 2015-6784   
37316BROWSER-IE Microsoft Internet Explorer corrupted HROW instance write access violation attempt (more info ...)attempted-user 2012-1891   URL
37325BROWSER-CHROME Google Chrome same origin policy bypass attempt (more info ...)policy-violation 2015-6768   
37363SERVER-OTHER Java Library SpringFramework unauthorized serialized object attempt (more info ...)attempted-user 2011-2894 49536  
37453BROWSER-FIREFOX Mozilla Firefox location.hostname DOM modification bypass attempt (more info ...)attempted-user 2007-0981   
37507BROWSER-PLUGINS Microsoft Internet Explorer Media Service Component mdsauth.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-2221   
37508BROWSER-PLUGINS Microsoft Internet Explorer Media Service Component mdsauth.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-2221   
37509BROWSER-PLUGINS Microsoft Internet Explorer Media Service Component mdsauth.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-2221   
37510BROWSER-PLUGINS Microsoft Internet Explorer Media Service Component mdsauth.dll ActiveX clsid access attempt (more info ...)attempted-user 2007-2221   
37583INDICATOR-SHELLCODE Javascript 0xCCCC unicode unescape (more info ...)shellcode-detect    
37715BROWSER-IE Microsoft Internet Explorer onscroll DOS attempt (more info ...)attempted-user 2011-1993 49947  URL
37716BROWSER-IE Microsoft Internet Explorer onscroll DOS attempt (more info ...)attempted-user 2011-1993 49947  URL
37724BROWSER-IE Microsoft Internet Explorer form selection reset attempt (more info ...)attempted-user 2011-1996 49961  URL
37803FILE-JAVA Oracle Java IntegerInterleavedRaster integer overflow attempt (more info ...)attempted-user 2013-2471 60659  URL
37836BROWSER-IE Microsoft Internet Explorer swapNode memory corruption attempt (more info ...)attempted-user 2013-3897 62811  URL
37837BROWSER-IE Microsoft Internet Explorer swapNode memory corruption attempt (more info ...)attempted-user 2013-3897 62811  URL
37847BROWSER-IE Microsoft Internet Explorer vector graphics reference counting use-after-free attempt (more info ...)attempted-user 2012-0172 52906  URL
37848BROWSER-IE Microsoft Internet Explorer vector graphics reference counting use-after-free attempt (more info ...)attempted-user 2012-0172 52906  URL
37881BROWSER-IE Microsoft Internet Explorer DOM mergeAttributes memory corruption attempt (more info ...)misc-activity 2011-0094 37893  URL
37888BROWSER-IE Microsoft Internet Explorer dynamic page reloading memory corruption attempt (more info ...)attempted-user 2007-0946 23770  URL
37889BROWSER-IE Microsoft Internet Explorer dynamic page reloading memory corruption attempt (more info ...)attempted-user 2007-0946 23770  URL
37905INDICATOR-OBFUSCATION javascript charset concatentation attempt (more info ...)misc-activity    URL
37906INDICATOR-OBFUSCATION javascript known obfuscation method attempt (more info ...)misc-activity    URL
37907INDICATOR-OBFUSCATION javascript unicode escape variable name attempt (more info ...)misc-activity    URL
37908INDICATOR-OBFUSCATION javascript with hex variable names (more info ...)misc-activity    URL
37909INDICATOR-OBFUSCATION known javascript packer detected (more info ...)misc-activity    URL
37935BROWSER-IE Microsoft Internet Explorer malformed table tag memory corruption attempt (more info ...)attempted-user 2010-2560   
37936BROWSER-IE Microsoft Internet Explorer malformed table tag memory corruption attempt (more info ...)attempted-user 2010-2560   
37944BROWSER-IE Microsoft Internet Explorer invalid object access memory corruption attempt (more info ...)attempted-user 2010-0249   URL
37945BROWSER-IE Microsoft Internet Explorer deleted object access memory corruption attempt (more info ...)attempted-user 2010-0249   URL
37946BROWSER-IE Microsoft Internet Explorer invalid object access memory corruption attempt (more info ...)attempted-user 2010-0249   URL
37947BROWSER-IE Microsoft Internet Explorer invalid object access memory corruption attempt (more info ...)attempted-user 2010-0249   URL
37948INDICATOR-OBFUSCATION known malicious JavaScript decryption routine (more info ...)attempted-user    URL
37954BROWSER-IE Microsoft Internet Explorer boundElements arbitrary code execution attempt (more info ...)attempted-user 2010-2557 42288  URL
37955BROWSER-IE Microsoft Internet Explorer boundElements arbitrary code execution attempt (more info ...)attempted-user 2010-2557 42288  URL
37956BROWSER-IE Microsoft Internet Explorer boundElements arbitrary code execution attempt (more info ...)attempted-user 2010-2557 42288  URL
37961BROWSER-IE Microsoft Internet Explorer long URL buffer overflow attempt (more info ...)attempted-user 2006-3869 19667  
37966BROWSER-IE Microsoft Internet Explorer covered object memory corruption attempt (more info ...)attempted-user 2011-1260   URL
37967BROWSER-IE Microsoft Internet Explorer covered object memory corruption attempt (more info ...)attempted-user 2011-1260   URL
37969BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
37970BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
37973BROWSER-IE Microsoft Internet Explorer onscroll DOS attempt (more info ...)attempted-user 2011-1993 49947  URL
37974BROWSER-IE Microsoft Internet Explorer onscroll DOS attempt (more info ...)attempted-user 2011-1993 49947  URL
38013BROWSER-IE Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt (more info ...)attempted-user 2012-1880   URL
38014BROWSER-IE Microsoft Internet Explorer getBoundingClientRect incorrect rebalancing attempt (more info ...)attempted-user 2012-1880   URL
38104INDICATOR-OBFUSCATION Javascript obfuscation double unescape (more info ...)attempted-user    URL
38105INDICATOR-OBFUSCATION Javascript obfuscation double unescape (more info ...)attempted-user    URL
38344SERVER-OTHER Pidgin MXIT is operation null pointer dereference attempt (more info ...)attempted-user 2016-2365   URL
38345SERVER-OTHER Pidgin MXIT is operation null pointer dereference attempt (more info ...)attempted-user 2016-2365   URL
38363BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user 2012-4792   URL
38364BROWSER-IE Microsoft Internet Explorer deleted button use after free attempt (more info ...)attempted-user 2012-4792   URL
38530MALWARE-CNC Obfuscated Javascript Attack runtime detection (more info ...)trojan-activity    URL
38937FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin 2016-1040   URL
38938FILE-PDF Adobe Reader trusted JavaScript function security bypass attempt (more info ...)attempted-admin 2016-1040   URL
39067SERVER-WEBAPP SAP Netweaver Java Proxy Runtime ProxyServer register cross site scripting attempt (more info ...)attempted-user 2016-2387   
39068SERVER-WEBAPP SAP Netweaver Java Proxy Runtime ProxyServer unregister cross site scripting attempt (more info ...)attempted-user 2016-2387   
39069SERVER-WEBAPP SAP Netweaver Java Proxy Runtime ProxyServer list cross site scripting attempt (more info ...)attempted-user 2016-2387   
39155BROWSER-IE Microsoft Internet Explorer DOM object cache management memory corruption attempt (more info ...)attempted-user 2007-5344 26817  
39156BROWSER-IE Microsoft Internet Explorer DOM object cache management memory corruption attempt (more info ...)attempted-user 2007-5344   
39174BROWSER-IE Microsoft Internet Explorer iframe uninitialized memory corruption attempt (more info ...)attempted-user 2010-2556 42257  URL
39175BROWSER-IE Microsoft Internet Explorer use-after-free memory corruption attempt (more info ...)attempted-dos 2010-2556 42257  URL
39354FILE-JAVA Oracle Java RangeStatisticImpl sandbox breach attempt (more info ...)attempted-user 2012-5076 56054  
39355FILE-JAVA Oracle Java RangeStatisticImpl sandbox breach attempt (more info ...)attempted-user 2012-5076 56054  
39488INDICATOR-OBFUSCATION obfuscated javascript excessive fromCharCode - potential attack (more info ...)misc-activity    URL
39489INDICATOR-OBFUSCATION obfuscated javascript fromCharCode with mixed number bases - potential attack (more info ...)misc-activity    URL
39490INDICATOR-OBFUSCATION obfuscated javascript fromCharCode with mixed number bases - potential attack (more info ...)misc-activity    URL
39497BROWSER-IE Microsoft Internet Explorer header tag HTML injection remote code execution attempt (more info ...)attempted-user 2016-3276   URL
39498BROWSER-IE Microsoft Internet Explorer header tag HTML injection remote code execution attempt (more info ...)attempted-user 2016-3276   URL
39512BROWSER-IE Microsoft Internet Explorer IE7 compatibility mode attempt (more info ...)attempted-user 2016-3241   URL
39513BROWSER-IE Microsoft Internet Explorer IE7 compatibility mode attempt (more info ...)attempted-user 2016-3241   URL
39585SERVER-WEBAPP Google Chromecast factory reset attempt (more info ...)attempted-dos    URL
39710MALWARE-CNC User-Agent known malicious user-agent string mozilla/2.0 (more info ...)trojan-activity    
39748BROWSER-IE Microsoft Internet Explorer 9 CTreeNode use after free attempt (more info ...)attempted-user 2012-1878   URL
39749BROWSER-IE Microsoft Internet Explorer 9 CTreeNode use after free attempt (more info ...)attempted-user 2012-1878   URL
39750BROWSER-IE Microsoft Internet Explorer 9 CTreeNode use after free attempt (more info ...)attempted-user 2012-1878   URL
39751BROWSER-IE Microsoft Internet Explorer 9 CTreeNode use after free attempt (more info ...)attempted-user 2012-1878   URL
39820BROWSER-IE Microsoft Internet Explorer iframe sandbox file name information disclosure attempt (more info ...)attempted-recon 2016-3321   URL
39821BROWSER-IE Microsoft Internet Explorer iframe sandbox file name information disclosure attempt (more info ...)attempted-recon 2016-3321   URL
39826BROWSER-IE Microsoft Internet Explorer CStr internal string use-after-free attempt (more info ...)attempted-user 2016-3326   URL
40015BROWSER-FIREFOX Mozilla Firefox about field spoofing attempt (more info ...)attempted-user 2016-5268   URL
40037PUA-ADWARE Google Chrome Google Contacts extension adware (more info ...)trojan-activity    URL
40094INDICATOR-SCAN Microsoft Internet Explorer AnchorElement information disclosure attempt (more info ...)attempted-recon 2016-3351   URL
40095INDICATOR-SCAN Microsoft Internet Explorer AnchorElement information disclosure attempt (more info ...)attempted-recon 2016-3351   URL
40280BROWSER-FIREFOX Mozilla Firefox file type memory corruption attempt (more info ...)attempted-user 2008-5021 32281  URL
40366BROWSER-IE Microsoft Internet Explorer ArraySpeciesCreate type confusion attempt (more info ...)attempted-user 2016-7190   URL
40367BROWSER-IE Microsoft Internet Explorer ArraySpeciesCreate type confusion attempt (more info ...)attempted-user 2016-7190   URL
40404BROWSER-IE Microsoft Internet Explorer eval type confusion attempt (more info ...)attempted-user 2016-3382   URL
40405BROWSER-IE Microsoft Internet Explorer eval type confusion attempt (more info ...)attempted-user 2016-3382   URL
40648BROWSER-IE Microsoft Edge JavaScript ReverseHelper buffer overrun attempt (more info ...)attempted-user 2016-7202   URL
40649BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (more info ...)attempted-user 2016-7201   URL
40650BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (more info ...)attempted-user 2016-7201   URL
40669BROWSER-IE Microsoft Internet Explorer classid remote code execution attempt (more info ...)attempted-admin 2016-7195   URL
40670BROWSER-IE Microsoft Internet Explorer classid remote code execution attempt (more info ...)attempted-admin 2016-7195   URL
41107BROWSER-IE Microsoft Internet Explorer layout object use after free attempt (more info ...)attempted-admin 2009-1532   URL
41210BROWSER-IE Microsoft Internet Explorer classid remote code execution attempt (more info ...)attempted-admin 2016-7195   URL
41211BROWSER-IE Microsoft Internet Explorer classid remote code execution attempt (more info ...)attempted-admin 2016-7195   URL
41377BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
41378BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
41493BROWSER-IE Microsoft Internet Explorer nested SPAN tag memory corruption attempt (more info ...)attempted-user 2008-4844 32721  
41494BROWSER-IE Microsoft Internet Explorer nested tag memory corruption attempt (more info ...)attempted-user 2008-4844 32721  URL
41522BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode object use after free attempt (more info ...)attempted-user 2015-0025   URL
41523BROWSER-IE Microsoft Internet Explorer CGeneratedTreeNode object use after free attempt (more info ...)attempted-user 2015-0025   URL
41575BROWSER-IE Microsoft Internet Explorer mhtml and res protocol information disclosure attempt (more info ...)attempted-user 2017-0008   URL
41576BROWSER-IE Microsoft Internet Explorer mhtml and res protocol information disclosure attempt (more info ...)attempted-user 2017-0008   URL
41633BROWSER-IE Microsoft Internet Explorer 11 Windows Media Player information disclosure attempt (more info ...)attempted-recon 2017-0042   URL
41634BROWSER-IE Microsoft Internet Explorer 11 Windows Media Player information disclosure attempt (more info ...)attempted-recon 2017-0042   URL
41716BROWSER-IE Microsoft Internet Explorer malformed iframe buffer overflow attempt (more info ...)attempted-user    
41772BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
41773BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
41775BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
41776BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
41777BROWSER-IE Microsoft Internet Explorer runtimeStyle use-after-free attempt (more info ...)attempted-user 2015-0053   URL
41895BROWSER-IE Microsoft Internet Explorer frameset null pointer dereference attempt (more info ...)attempted-user    URL
41896BROWSER-IE Microsoft Internet Explorer frameset null pointer dereference attempt (more info ...)attempted-user    URL
41968BROWSER-IE Microsoft Edge JavascriptProxy SetPropertyTrap type confusion attempt (more info ...)attempted-admin 2017-0094   URL
41969BROWSER-IE Microsoft Edge JavascriptProxy SetPropertyTrap type confusion attempt (more info ...)attempted-admin 2017-0094   URL
42032BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
42033BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
42034BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
42035BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
42036BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
42037BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
42038BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
42039BROWSER-IE Microsoft Internet Explorer DataView use-after-free attempt (more info ...)attempted-user 2015-1747   URL
42117BROWSER-IE Microsoft Internet Explorer Typed Array use after free attempt (more info ...)attempted-user 2016-7288   URL
42118BROWSER-IE Microsoft Internet Explorer Typed Array use after free attempt (more info ...)attempted-user 2016-7288   URL
42169BROWSER-IE Microsoft Internet Explorer classid remote code execution attempt (more info ...)attempted-admin 2016-7195   URL
42170BROWSER-IE Microsoft Internet Explorer classid remote code execution attempt (more info ...)attempted-admin 2016-7195   URL
42292INDICATOR-COMPROMISE malicious javascript obfuscation detected (more info ...)attempted-user    URL
42389BROWSER-IE Microsoft Internet Explorer uninitialized or deleted object access attempt (more info ...)misc-activity 2009-2530   URL
42420SERVER-OTHER HP Operations Agent for NonStop server HEALTH packet parsing stack buffer overflow attempt (more info ...)attempted-admin    URL
42448BROWSER-IE Microsoft Internet Explorer deleted object access memory corruption attempt (more info ...)attempted-user 2013-0020   
42449BROWSER-IE Microsoft Internet Explorer deleted object access memory corruption attempt (more info ...)attempted-user 2013-0020   
42450BROWSER-IE Microsoft Internet Explorer deleted object access memory corruption attempt (more info ...)attempted-user 2013-0020   URL
42960SERVER-WEBAPP Java BeanShell Library unauthorized serialized object attempt (more info ...)attempted-admin    URL
42961SERVER-WEBAPP Java Groovy Library unauthorized serialized object attempt (more info ...)attempted-admin 2015-5377   URL
42962SERVER-WEBAPP Java Hibernate Library unauthorized serialized object attempt (more info ...)attempted-admin    URL
42963SERVER-WEBAPP Java Mozilla Library unauthorized serialized object attempt (more info ...)attempted-admin    URL
42964SERVER-WEBAPP Java MyFaces Library unauthorized serialized object attempt (more info ...)attempted-admin    URL
42965SERVER-WEBAPP Java RMI Library unauthorized serialized object attempt (more info ...)attempted-admin    URL
42969FILE-PDF Adobe Acrobat Reader javascript engine stack overflow attempt (more info ...)attempted-user 2017-3037   URL
42970FILE-PDF Adobe Acrobat Reader javascript engine stack overflow attempt (more info ...)attempted-user 2017-3037   URL
42971FILE-PDF Adobe Acrobat Reader javascript engine stack overflow attempt (more info ...)attempted-user 2017-3037   URL
42972FILE-PDF Adobe Acrobat Reader javascript engine stack overflow attempt (more info ...)attempted-user 2017-3037   URL
43042BROWSER-IE Microsoft Internet Explorer JSON strigify double free attempt (more info ...)attempted-user 2015-2419   URL
43043BROWSER-IE Microsoft Internet Explorer JSON strigify double free attempt (more info ...)attempted-user 2015-2419   URL
43069BROWSER-IE Microsoft Internet Explorer vbscript regular expression information disclosure attempt (more info ...)attempted-recon 2015-6052   URL
43070BROWSER-IE Microsoft Internet Explorer vbscript regular expression information disclosure attempt (more info ...)attempted-recon 2015-6052   URL
43071BROWSER-IE Microsoft Internet Explorer vbscript regular expression information disclosure attempt (more info ...)attempted-recon 2015-6052   URL
43072BROWSER-IE Microsoft Internet Explorer vbscript regular expression information disclosure attempt (more info ...)attempted-recon 2015-6052   URL
43134BROWSER-IE Microsoft Internet Explorer CStyleSheetRule array memory corruption attempt (more info ...)attempted-user 2010-3328 43705  URL
43293MALWARE-CNC Andr.Adware.Judy malicious java file download attempt (more info ...)trojan-activity    URL
43298BROWSER-WEBKIT Apple Safari Webkit WebCore CSSSelector denial of service attempt (more info ...)denial-of-service 2010-1029   
43358BROWSER-IE Microsoft Internet Explorer CSS property method handling memory corruption attempt (more info ...)attempted-user 2007-0945 23769  
43367BROWSER-FIREFOX Mozilla Firefox XUL tree element code execution attempt (more info ...)attempted-user 2009-1044 34181  
43398BROWSER-IE Microsoft Internet Explorer clone object memory corruption attempt (more info ...)attempted-user 2007-3903 26816  
43515BROWSER-IE Microsoft Internet Explorer cross-domain violation via cached object attempt (more info ...)attempted-user 2002-1254   
43516BROWSER-OTHER Apple Safari nested xml tag denial of service attempt (more info ...)denial-of-service 2009-1233   
43517BROWSER-OTHER Apple Safari nested xml tag denial of service attempt (more info ...)denial-of-service 2009-1233   
43550BROWSER-IE Microsoft Internet Explorer span tag memory corruption attempt (more info ...)attempted-user 2006-1188   
43551BROWSER-IE Microsoft Internet Explorer span tag memory corruption attempt (more info ...)attempted-user 2006-1188   
43579BROWSER-IE Microsoft Internet Explorer type confusion attempt (more info ...)attempted-user 2014-0271   URL
43580BROWSER-IE Microsoft Internet Explorer type confusion attempt (more info ...)attempted-user 2014-0271   URL
43598BROWSER-IE Microsoft Internet Explorer object type confusion remote code execution attempt (more info ...)attempted-user 2014-6347   URL
43599BROWSER-IE Microsoft Internet Explorer object type confusion remote code execution attempt (more info ...)attempted-user 2014-6347   URL
43622BROWSER-IE Microsoft Internet Explorer GDI VML gradient size heap overflow attempt (more info ...)attempted-user 2007-5348   URL
43635BROWSER-IE Microsoft Internet Explorer EUC-JP encoding cross site scripting attempt (more info ...)attempted-user 2013-3192   URL
43636BROWSER-IE Microsoft Internet Explorer EUC-JP encoding cross site scripting attempt (more info ...)attempted-user 2013-3192   URL
43642BROWSER-FIREFOX Mozilla Firefox multiple vulnerabilities memory corruption attempt (more info ...)attempted-user 2007-3734   
43643BROWSER-FIREFOX Mozilla Firefox design mode deleted style memory corruption attempt (more info ...)attempted-user 2007-3734   
43644BROWSER-FIREFOX Mozilla Firefox display moz-deck style memory corruption attempt (more info ...)attempted-user 2007-3734   
43648BROWSER-IE Microsoft Internet Explorer CDocument use after free attempt (more info ...)attempted-user 2013-3114   URL
43651BROWSER-FIREFOX Mozilla Firefox large window null pointer dereference attempt (more info ...)attempted-admin    URL
43652BROWSER-FIREFOX Mozilla Firefox large window null pointer dereference attempt (more info ...)attempted-admin    URL
43656BROWSER-IE Microsoft Edge JavaScript ReverseHelper buffer overrun attempt (more info ...)attempted-user 2016-7202   URL
43657BROWSER-IE Microsoft Edge JavaScript ReverseHelper buffer overrun attempt (more info ...)attempted-user 2016-7202   URL
43658BROWSER-IE Microsoft Edge JavaScript ReverseHelper buffer overrun attempt (more info ...)attempted-user 2016-7202   URL
43659BROWSER-IE Microsoft Edge JavaScript ReverseHelper buffer overrun attempt (more info ...)attempted-user 2016-7202   URL
43664BROWSER-IE Microsoft Internet Explorer 11 CMarkup GetMarkupTitle use-after-free attempt (more info ...)attempted-user 2014-4130   URL
43665BROWSER-IE Microsoft Internet Explorer 11 CMarkup GetMarkupTitle use-after-free attempt (more info ...)attempted-user 2014-4130   URL
43672BROWSER-FIREFOX Mozilla products obfuscated cross site scripting attempt (more info ...)attempted-admin 2008-4066 31346  URL
43673BROWSER-FIREFOX Mozilla products obfuscated cross site scripting attempt (more info ...)attempted-admin 2008-4066 31346  URL
43706BROWSER-FIREFOX Mozilla Firefox Javascript contentWindow in an iframe exploit attempt (more info ...)attempted-user 2006-1993 17671  
43735BROWSER-FIREFOX Mozilla Firefox SVG pathSegList memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43736BROWSER-FIREFOX Mozilla Firefox XUL commandDispatcher memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43737BROWSER-FIREFOX Mozilla Firefox XUL commandDispatcher memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43738BROWSER-FIREFOX Mozilla Firefox SVGZoom memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43739BROWSER-FIREFOX Mozilla Firefox SVGZoom memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43740BROWSER-FIREFOX Mozilla Firefox frameset memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43741BROWSER-FIREFOX Mozilla Firefox frameset memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43742BROWSER-FIREFOX Mozilla Firefox lookup property memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43743BROWSER-FIREFOX Mozilla Firefox lookup property memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43744BROWSER-FIREFOX Mozilla Firefox style display inherit memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43745BROWSER-FIREFOX Mozilla Firefox style display inherit memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43746BROWSER-FIREFOX Mozilla Firefox frame element memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43747BROWSER-FIREFOX Mozilla Firefox frame element memory corruption attempt (more info ...)attempted-user 2007-2867 24242  
43749BROWSER-FIREFOX Mozilla Firefox BOM character cross site scripting attempt (more info ...)attempted-admin 2008-4065   
43761BROWSER-FIREFOX Mozilla Firefox wyciwgy domain forgery attempt (more info ...)attempted-admin 2007-3656   
43763BROWSER-FIREFOX Mozilla Firefox XUL tree node removal memory corruption attempt (more info ...)attempted-admin 2007-0755   
43764BROWSER-FIREFOX Mozilla Firefox XUL tree node removal memory corruption attempt (more info ...)attempted-admin 2007-0755   
43765BROWSER-FIREFOX Mozilla Firefox XUL null menu memory corruption attempt (more info ...)attempted-admin 2007-0755   
43766BROWSER-FIREFOX Mozilla Firefox XUL null menu memory corruption attempt (more info ...)attempted-admin 2007-0755   
43767BROWSER-FIREFOX Mozilla Firefox floating layer denial of service attempt (more info ...)attempted-admin 2007-0755   
43768BROWSER-FIREFOX Mozilla Firefox floating layer denial of service attempt (more info ...)attempted-admin 2007-0755   
43778BROWSER-FIREFOX Mozilla Firefox nsTreeContentView double-free memory corruption attempt (more info ...)attempted-user 2010-0176 39128  URL
43789SERVER-OTHER Solarwinds Virtualization Manager Java malicious object deserialization attempt (more info ...)attempted-user 2016-3642   
43826BROWSER-OTHER Opera animation element denial of service attempt (more info ...)denial-of-service    URL
43827BROWSER-OTHER Opera animation element denial of service attempt (more info ...)denial-of-service    URL
43830BROWSER-IE Microsoft Internet Explorer CTableLayout memory corruption attempt (more info ...)attempted-user 2010-0244 37891  URL
43831BROWSER-IE Microsoft Internet Explorer CTableLayout memory corruption attempt (more info ...)attempted-user 2010-0244 37891  URL
43832BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-admin 2014-6351   
43833BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-admin 2014-6351   
43837INDICATOR-OBFUSCATION obfuscated javascript regex (more info ...)misc-activity    URL
43926FILE-PDF Adobe Acrobat Reader XFA javascript use after free exploitation attempt (more info ...)attempted-user    URL
43927FILE-PDF Adobe Acrobat Reader XFA javascript use after free exploitation attempt (more info ...)attempted-user    URL
43954BROWSER-FIREFOX Mozilla PLUGINSPAGE javascript execution attempt (more info ...)attempted-user 2005-0752 13228  
43955BROWSER-CHROME Google Chrome V8 engine integer overflow attempt (more info ...)attempted-admin    URL
43956BROWSER-CHROME Google Chrome V8 engine integer overflow attempt (more info ...)attempted-admin    URL
43960BROWSER-FIREFOX Mozilla products element style change memory corruption code execution attempt (more info ...)attempted-user 2006-0294 16476  
44009BROWSER-FIREFOX Mozilla Firefox empty lookupGetter dangling pointer attempt (more info ...)attempted-admin 2010-3183   
44010BROWSER-FIREFOX Mozilla Firefox empty lookupGetter dangling pointer attempt (more info ...)attempted-admin 2010-3183   
44035BROWSER-PLUGINS Microsoft Internet Explorer WMIScriptUtils.WMIObjectBroker2.1 ActiveX clsid access attempt (more info ...)attempted-user 2006-4704   URL
44036BROWSER-PLUGINS Microsoft Internet Explorer WMIScriptUtils.WMIObjectBroker2.1 ActiveX clsid access attempt (more info ...)attempted-user 2006-4704   URL
44043BROWSER-FIREFOX Mozilla browsers JavaScript argument passing code execution attempt (more info ...)attempted-user 2007-0777 22694  
44044BROWSER-FIREFOX Mozilla Firefox invalid watchpoint memory corruption attempt (more info ...)attempted-admin 2007-0777   
44045BROWSER-FIREFOX Mozilla Firefox invalid watchpoint memory corruption attempt (more info ...)attempted-admin 2007-0777   
44046BROWSER-FIREFOX Mozilla Firefox memory corruption attempt (more info ...)attempted-admin 2007-0777   
44047BROWSER-FIREFOX Mozilla Firefox memory corruption attempt (more info ...)attempted-admin 2007-0777   
44048BROWSER-FIREFOX Mozilla Firefox memory corruption attempt (more info ...)attempted-admin 2007-0777   
44049BROWSER-FIREFOX Mozilla Firefox memory corruption attempt (more info ...)attempted-admin 2007-0777   
44050BROWSER-OTHER Apple Safari document.write buffer overflow attempt (more info ...)attempted-admin 2008-2000   
44051BROWSER-OTHER Apple Safari document.write buffer overflow attempt (more info ...)attempted-admin 2008-2000   
44081BROWSER-IE Microsoft Internet Explorer onBeforeUnload address bar spoofing attempt (more info ...)misc-activity 2007-3826 24911  URL
44088BROWSER-PLUGINS Microsoft Internet Explorer CapiCom.Utilities ActiveX control getRandom method access attempt (more info ...)attempted-user    URL
44089BROWSER-PLUGINS Microsoft Internet Explorer CapiCom.Utilities ActiveX control getRandom method access attempt (more info ...)attempted-user    URL
44090BROWSER-PLUGINS Microsoft Internet Explorer CapiCom.Utilities ActiveX control getRandom method access attempt (more info ...)attempted-user    URL
44091BROWSER-PLUGINS Microsoft Internet Explorer CapiCom.Utilities ActiveX control getRandom method access attempt (more info ...)attempted-user    URL
44103FILE-PDF Multiple products PDF JavaScript saveAs arbitrary file write attempt (more info ...)attempted-user 2017-7442   URL
44104FILE-PDF Multiple products PDF JavaScript saveAs arbitrary file write attempt (more info ...)attempted-user 2017-7442   URL
44148BROWSER-IE Microsoft Internet Explorer malformed loop denial of service attempt (more info ...)denial-of-service 2007-0811 22408  
44149BROWSER-IE Microsoft Internet Explorer malformed loop denial of service attempt (more info ...)denial-of-service 2007-0811 22408  
44153BROWSER-IE Microsoft Internet Explorer frameBorder denial of service attempt (more info ...)attempted-admin  41990  
44154BROWSER-IE Microsoft Internet Explorer frameBorder denial of service attempt (more info ...)attempted-admin  41990  
44184BROWSER-IE Microsoft Internet Explorer information disclosure attempt (more info ...)attempted-recon 2002-1186   
44185BROWSER-IE Microsoft Internet Explorer information disclosure attempt (more info ...)attempted-recon 2002-1186   
44188BROWSER-IE Microsoft Internet Explorer span frontier parsing memory corruption attempt (more info ...)attempted-user 2008-2254   URL
44192BROWSER-IE Microsoft Internet Explorer frameBorder denial of service attempt (more info ...)attempted-admin  41990  
44193BROWSER-IE Microsoft Internet Explorer frameBorder denial of service attempt (more info ...)attempted-admin  41990  
44195BROWSER-IE Internet Explorer CCaret memory corruption attempt (more info ...)attempted-user 2013-0090   
44196BROWSER-IE Internet Explorer CCaret memory corruption attempt (more info ...)attempted-user 2013-0090   
44197BROWSER-IE Internet Explorer CCaret memory corruption attempt (more info ...)attempted-user 2013-0090   
44198BROWSER-IE Internet Explorer CCaret memory corruption attempt (more info ...)attempted-user 2013-0090   
44281BROWSER-IE Microsoft Internet Explorer MDAC ActiveX clsid access attempt (more info ...)attempted-user 2006-0003   URL
44282BROWSER-IE Microsoft Internet Explorer MDAC ActiveX clsid access attempt (more info ...)attempted-user 2006-0003   URL
44283BROWSER-IE Microsoft Internet Explorer MDAC ActiveX clsid access attempt (more info ...)attempted-user 2006-0003   URL
44284BROWSER-IE Microsoft Internet Explorer MDAC ActiveX clsid access attempt (more info ...)attempted-user 2006-0003   URL
44602BROWSER-IE Microsoft Internet Explorer SetItem use after free attempt (more info ...)attempted-user 2016-0106   URL
44603BROWSER-IE Microsoft Internet Explorer SetItem use after free attempt (more info ...)attempted-user 2016-0106   URL
44615INDICATOR-OBFUSCATION suspicious javascript deobfuscation calls attempt (more info ...)policy-violation    URL
44729BROWSER-IE Microsoft Internet Explorer script action handler buffer overflow attempt (more info ...)attempted-admin 2006-1245   
44730BROWSER-IE Microsoft Internet Explorer script action handler buffer overflow attempt (more info ...)attempted-admin 2006-1245   
44736BROWSER-IE Microsoft Internet Explorer saveHistory use after free attempt (more info ...)attempted-dos 2013-0088   URL
44737BROWSER-IE Microsoft Internet Explorer saveHistory use after free attempt (more info ...)attempted-dos 2013-0088   URL
44751BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-admin 2014-1772   
44752BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-admin 2014-1772   
44754BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-admin 2014-1775   
44755BROWSER-IE Microsoft Internet Explorer use after free attempt (more info ...)attempted-admin 2014-1775   
44823BROWSER-IE Microsoft Internet Explorer VBScript Join out of bounds memory access attempt (more info ...)attempted-user 2017-11869   
44824BROWSER-IE Microsoft Internet Explorer VBScript Join out of bounds memory access attempt (more info ...)attempted-user 2017-11869   
44864INDICATOR-COMPROMISE Microsoft Internet Explorer OLE auto-open attempt (more info ...)misc-activity    
44865INDICATOR-COMPROMISE Microsoft Internet Explorer OLE auto-open attempt (more info ...)misc-activity    
44991BROWSER-FIREFOX Mozilla products CSS rendering out-of-bounds array write attempt (more info ...)attempted-user 2006-1739   
45114MALWARE-CNC Catch-All malicious Chrome extension dropper outbound connection (more info ...)trojan-activity    URL
45127BROWSER-FIREFOX Mozilla SSL certificate spoofing attempt (more info ...)misc-attack 2004-0763   URL
45154BROWSER-IE Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user 2009-0076   URL
45173BROWSER-FIREFOX Mozilla download directory file deletion attempt (more info ...)attempted-user 2004-2225   URL
45174BROWSER-FIREFOX Mozilla download directory file deletion attempt (more info ...)attempted-user 2004-2225   URL
45176BROWSER-FIREFOX Mozilla Firefox nsTreeContentView double-free memory corruption attempt (more info ...)attempted-user 2010-0176 39128  URL
45210BROWSER-IE Microsoft Internet Explorer out of bounds read attempt (more info ...)attempted-user 2016-7283   URL
45211BROWSER-IE Microsoft Internet Explorer out of bounds read attempt (more info ...)attempted-user 2016-7283   URL
45246BROWSER-FIREFOX Mozilla Firefox DOM event handler privilege escalation attempt (more info ...)attempted-admin 2007-3737   
45247BROWSER-FIREFOX Mozilla Firefox DOM event handler privilege escalation attempt (more info ...)attempted-admin 2007-3737   
45258FILE-JAVA Oracle Java strlen denial of service attempt (more info ...)denial-of-service    URL
45259FILE-JAVA Oracle Java strlen denial of service attempt (more info ...)denial-of-service    URL
45346FILE-JAVA Oracle Java strlen denial of service attempt (more info ...)denial-of-service    URL
45347FILE-JAVA Oracle Java strlen denial of service attempt (more info ...)denial-of-service    URL
45348FILE-JAVA IBM Java invokeWithClassLoaders method call attempt (more info ...)attempted-user 2012-4820   
45349FILE-JAVA IBM Java invokeWithPrivilege method call attempt (more info ...)attempted-user 2012-4820   
45350FILE-JAVA IBM Java invokeWithClassLoaders method call attempt (more info ...)attempted-user 2012-4820   
45351FILE-JAVA IBM Java invokeWithPrivilege method call attempt (more info ...)attempted-user 2012-4820   
45354BROWSER-OTHER Apple Safari javascript mutlibyte character escaping denial of service attempt (more info ...)denial-of-service    URL
45355BROWSER-OTHER Apple Safari javascript mutlibyte character escaping denial of service attempt (more info ...)denial-of-service    URL
45537SERVER-OTHER Mozilla Network Security Services heap underflow exploit attempt (more info ...)attempted-user 2007-0008   
45538SERVER-OTHER Mozilla Network Security Services heap underflow exploit attempt (more info ...)attempted-user 2007-0008   
45539SERVER-OTHER Mozilla Network Security Services heap underflow exploit attempt (more info ...)attempted-user 2007-0008   
45576BROWSER-FIREFOX Mozilla Firefox Javascript Function focus overflow attempt (more info ...)attempted-user 2006-1993 17671  
45617SERVER-WEBAPP HP IMC WebDM arbitrary Java object deserialization attempt (more info ...)attempted-admin 2017-12558 101152  URL
45732BROWSER-WEBKIT Apple Safari Webkit button first-letter style rendering code execution attempt (more info ...)attempted-user 2010-1392   
45733BROWSER-WEBKIT Apple Safari Webkit button first-letter style rendering code execution attempt (more info ...)attempted-user 2010-1392   
45734BROWSER-WEBKIT Apple Safari Webkit button first-letter style rendering code execution attempt (more info ...)attempted-user 2010-1392   
45735BROWSER-WEBKIT Apple Safari Webkit button first-letter style rendering code execution attempt (more info ...)attempted-user 2010-1392   
45748SERVER-WEBAPP HP IMC TopoMsgServlet arbitrary Java object deserialization attempt (more info ...)attempted-admin 2017-8966   URL
45760BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin 2016-5182   
45761BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin 2016-5182   
45762BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin 2016-5182   
45763BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin 2016-5182   
45764BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin 2016-5182   
45765BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin 2016-5182   
45766BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin 2016-5182   
45767BROWSER-CHROME Google Chrome Blink ImageBitmap integer overflow attempt (more info ...)attempted-admin 2016-5182   
45795SERVER-OTHER Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user    
45796SERVER-OTHER Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user    
45797SERVER-OTHER Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user    
45798SERVER-OTHER Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user    
45799SERVER-OTHER Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user    
45800SERVER-OTHER Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user    
45801SERVER-OTHER Java Library CommonsCollection unauthorized serialized object attempt (more info ...)attempted-user    
45885SERVER-WEBAPP HP IMC perfAccessMgrServlet arbitrary Java object deserialization attempt (more info ...)attempted-admin 2017-8962   URL
46382SERVER-OTHER Micro Focus Operations Orchestration denial of service attempt (more info ...)denial-of-service 2018-6490   URL
46383SERVER-OTHER Micro Focus Operations Orchestration information disclosure attempt (more info ...)attempted-user 2018-6490   URL
46398BROWSER-OTHER Mozilla Firefox table object integer underflow (more info ...)attempted-admin 2018-5093   
46399BROWSER-OTHER Mozilla Firefox table object integer underflow (more info ...)attempted-admin 2018-5093   
46412PUA-OTHER Javascript obfuscated by obfuscator.io download attempt (more info ...)attempted-user    
46413PUA-OTHER Mineralt JavaScript cryptocurrency mining attempt (more info ...)misc-attack    URL
46424BROWSER-IE Microsoft Edge Javascript ParseCatch type confusion attempt (more info ...)attempted-admin 2017-11764   
46425BROWSER-IE Microsoft Edge Javascript ParseCatch type confusion attempt (more info ...)attempted-admin 2017-11764   
46426BROWSER-IE Microsoft Edge Javascript ParseCatch type confusion attempt (more info ...)attempted-admin 2017-11764   
46427BROWSER-IE Microsoft Edge Javascript ParseCatch type confusion attempt (more info ...)attempted-admin 2017-11764   
46765BROWSER-FIREFOX Mozilla Firefox nsHTMLDocument SetBody use-after-free attempt (more info ...)attempted-admin 2016-1961   URL
46766BROWSER-FIREFOX Mozilla Firefox nsHTMLDocument SetBody use-after-free attempt (more info ...)attempted-admin 2016-1961   URL
46767BROWSER-FIREFOX Mozilla Firefox nsHTMLDocument SetBody use-after-free attempt (more info ...)attempted-admin 2016-1961   URL
46781BROWSER-FIREFOX Mozilla Firefox nsHTMLDocument SetBody use-after-free attempt (more info ...)attempted-admin 2016-1961   URL
46975BROWSER-CHROME Google Chrome Crankshaft type confusion attempt (more info ...)attempted-user 2017-5070   
46976BROWSER-CHROME Google Chrome Crankshaft type confusion attempt (more info ...)attempted-user 2017-5070   
46977BROWSER-CHROME Google Chrome Crankshaft type confusion attempt (more info ...)attempted-user 2017-5070   
46978BROWSER-CHROME Google Chrome Crankshaft type confusion attempt (more info ...)attempted-user 2017-5070   
47018BROWSER-CHROME Google Chrome V8 __defineGetter__ memory corruption attempt (more info ...)attempted-user 2014-1705   
47019BROWSER-CHROME Google Chrome V8 __defineGetter__ memory corruption attempt (more info ...)attempted-user 2014-1705   
47054BROWSER-IE Microsoft Internet Explorer uninitialized pointer attempt (more info ...)attempted-user 2016-0191   URL
47463BROWSER-IE Microsoft Internet Explorer pre-line use after free attempt (more info ...)attempted-user 2015-6050   URL
47761BROWSER-IE Microsoft Internet Explorer iframe open redirect attempt (more info ...)attempted-recon 2018-8470   URL
47843MALWARE-CNC Java.Trojan.Adwind variant outbound connection (more info ...)trojan-activity    URL
48224BROWSER-FIREFOX Mozilla Firefox sandbox escape attempt (more info ...)attempted-user    
48225BROWSER-FIREFOX Mozilla Firefox sandbox escape attempt (more info ...)attempted-user    
48226FILE-PDF Foxit PDF Reader JavaScript annotations use after free attempt (more info ...)attempted-user 2018-9958   URL
48227FILE-PDF Foxit PDF Reader JavaScript annotations use after free attempt (more info ...)attempted-user 2018-9958   URL
48576PROTOCOL-SCADA PNIO-CM Connect Operation (more info ...)protocol-command-decode    URL
48577PROTOCOL-SCADA PNIO-CM Connect Operation (more info ...)protocol-command-decode    URL
48584FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (more info ...)attempted-user 2018-19710   URL
48585FILE-PDF Adobe Reader JavaScript resolveNode use-after-free attempt (more info ...)attempted-user 2018-19710   URL
49008PROTOCOL-SCADA PCOM Read Operands binary request (more info ...)attempted-recon    URL
49030PROTOCOL-SCADA PCOM Read Operands binary reply (more info ...)attempted-recon    URL
49065SERVER-OTHER Robot Operating System aztarna scanner getSystemState attempt (more info ...)attempted-user    URL
49066SERVER-OTHER Robot Operating System aztarna scanner fingerprinting attempt (more info ...)attempted-recon    URL
49067SERVER-OTHER Robot Operating System aztarna scanner fingerprinting attempt (more info ...)attempted-user    URL
49083BROWSER-IE Microsoft Internet Explorer CTextElement use after free attempt (more info ...)attempted-user 2014-2782   URL
49084BROWSER-IE Microsoft Internet Explorer CTextElement use after free attempt (more info ...)attempted-user 2014-2782   
49112BROWSER-OTHER Opera GIF parsing buffer underflow attempt (more info ...)attempted-user 2012-6470   
49113BROWSER-OTHER Opera GIF parsing buffer overflow attempt (more info ...)attempted-user 2012-6470   
49114BROWSER-OTHER Opera GIF parsing buffer underflow attempt (more info ...)attempted-user 2012-6470   
49115BROWSER-OTHER Opera GIF parsing buffer overflow attempt (more info ...)attempted-user 2012-6470   
49116FILE-JAVA Oracle Java JPEGImageWriter memory corruption attempt (more info ...)attempted-user 2013-2429   
49117FILE-JAVA Oracle Java JPEGImageWriter memory corruption attempt (more info ...)attempted-user 2013-2429   
49186BROWSER-IE Microsoft Internet Explorer HtmlLayout styling use after free attempt (more info ...)attempted-user 2014-4050   URL
49187BROWSER-IE Microsoft Internet Explorer HtmlLayout styling use after free attempt (more info ...)attempted-user 2014-4050   URL
49374BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3882   URL
49375BROWSER-IE Microsoft Internet Explorer CAnchorElement use after free attempt (more info ...)attempted-user 2013-3882   URL
49686BROWSER-IE Microsoft Internet Explorer Typed Array use after free attempt (more info ...)attempted-user 2016-7288   URL
49687BROWSER-IE Microsoft Internet Explorer Typed Array use after free attempt (more info ...)attempted-user 2016-7288   URL
49811BROWSER-IE Microsoft Internet Explorer invalid object property memory corruption attempt (more info ...)attempted-user 2012-4787   URL
49812BROWSER-IE Microsoft Internet Explorer invalid object property memory corruption attempt (more info ...)attempted-user 2012-4787   URL
49845FILE-JAVA Oracle Java privileged protection domain exploitation attempt (more info ...)attempted-admin 2012-4681   
49862BROWSER-IE Microsoft Internet Explorer eval type confusion attempt (more info ...)attempted-user 2016-3382   URL
49863BROWSER-IE Microsoft Internet Explorer eval type confusion attempt (more info ...)attempted-user 2016-3382   URL
49870BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user 2014-6351   URL
49871BROWSER-IE Microsoft Internet Explorer CQuotes use-after-free attempt (more info ...)attempted-user 2014-6351   URL
49929BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user 2012-1889   URL
49930BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user 2012-1889   URL
49931BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user 2012-1889   URL
49932BROWSER-PLUGINS Microsoft Internet Explorer MSXML .definition ActiveX clsid access attempt (more info ...)attempted-user 2012-1889   URL
49940BROWSER-IE Microsoft Internet Explorer VML use after free attempt (more info ...)attempted-user 2014-1776   URL
49988BROWSER-IE Microsoft Internet Explorer cdomuievent use after free attempt (more info ...)attempted-user 2014-2820 69116  URL
49989BROWSER-IE Microsoft Internet Explorer cdomuievent use after free attempt (more info ...)attempted-user 2014-2820 69116  URL
50004BROWSER-IE Javascript CollectGarbage use-after-free attempt (more info ...)attempted-user 2014-1791   URL
50005BROWSER-IE Javascript CollectGarbage use-after-free attempt (more info ...)attempted-user 2014-1791   URL
50026BROWSER-IE Microsoft Internet Explorer window scroll integer overflow attempt (more info ...)attempted-user 2015-2446 76193  URL
50027BROWSER-IE Microsoft Internet Explorer window scroll integer overflow attempt (more info ...)attempted-user 2015-2446 76193  URL
50123BROWSER-IE Microsoft Internet Explorer CTextElement use after free attempt (more info ...)attempted-user 2014-2782   URL
50124BROWSER-IE Microsoft Internet Explorer CTextElement use after free attempt (more info ...)attempted-user 2014-2782   URL
50127INDICATOR-OBFUSCATION ActiveXObject javascript obfuscation attempt (more info ...)attempted-user    
50128INDICATOR-OBFUSCATION ActiveXObject javascript obfuscation attempt (more info ...)attempted-user    
51427BROWSER-CHROME Google Chrome V8 engine object instantiation heap corruption attempt (more info ...)attempted-user 2018-6065   
51428BROWSER-CHROME Google Chrome V8 engine object instantiation heap corruption attempt (more info ...)attempted-user 2018-6065   
51439BROWSER-FIREFOX Mozilla Firefox Custom Elements write-after-free attempt (more info ...)attempted-user 2018-18500   
51440BROWSER-FIREFOX Mozilla Firefox Custom Elements write-after-free attempt (more info ...)attempted-user 2018-18500   
51826BROWSER-PLUGINS Microsoft Internet Explorer NMSA.MediaDescription ActiveX function call access attempt (more info ...)denial-of-service 2006-3897   
52028SERVER-WEBAPP JavaServer Faces Library unauthorized serialized object attempt (more info ...)web-application-attack    
52244BROWSER-WEBKIT Apple Safari WebKit handleIntrinsicCall type confusion attempt (more info ...)attempted-user 2018-4382   URL
52245BROWSER-WEBKIT Apple Safari WebKit handleIntrinsicCall type confusion attempt (more info ...)attempted-user 2018-4382   URL
52248BROWSER-CHROME Google Chrome Javascript V8 Array.indexOf information leak attempt (more info ...)attempted-user 2017-5040   URL
52249BROWSER-CHROME Google Chrome Javascript V8 Array.indexOf information leak attempt (more info ...)attempted-user 2017-5040   URL
52250BROWSER-CHROME Google Chrome Javascript V8 Array.includes information leak attempt (more info ...)attempted-user 2017-5040   URL
52251BROWSER-CHROME Google Chrome Javascript V8 Array.includes information leak attempt (more info ...)attempted-user 2017-5040   URL
52313BROWSER-WEBKIT Apple Safari WebKit memory corruption attempt (more info ...)attempted-user 2018-4368   URL
52314BROWSER-WEBKIT Apple Safari WebKit memory corruption attempt (more info ...)attempted-user 2018-4368   URL
52315BROWSER-WEBKIT Apple Safari WebKit memory corruption attempt (more info ...)attempted-user 2018-4368   URL
52316BROWSER-WEBKIT Apple Safari WebKit memory corruption attempt (more info ...)attempted-user 2018-4368   URL
52317BROWSER-CHROME Google Chrome V8 JavaScript Engine memory corruption attempt (more info ...)attempted-user 2017-5115   
52318BROWSER-CHROME Google Chrome V8 JavaScript Engine memory corruption attempt (more info ...)attempted-user 2017-5115   
52341BROWSER-WEBKIT Apple Safari WebKit out-of-bounds read attempt (more info ...)attempted-user 2019-8689   URL
52342BROWSER-WEBKIT Apple Safari WebKit out-of-bounds read attempt (more info ...)attempted-user 2019-8689   URL
53473BROWSER-WEBKIT Apple Safari WebKit JavaScript engine type confusion attempt (more info ...)attempted-user 2019-8820   URL
53474BROWSER-WEBKIT Apple Safari WebKit JavaScript engine type confusion attempt (more info ...)attempted-user 2019-8820   URL
53476BROWSER-WEBKIT Apple Safari browser putToPrimitive cross-site scripting attempt (more info ...)web-application-attack 2019-8764   URL
53479BROWSER-WEBKIT Apple Safari browser putToPrimitive cross-site scripting attempt (more info ...)web-application-attack 2019-8764   URL
53580BROWSER-FIREFOX Mozilla Firefox potential use after free attempt (more info ...)attempted-user 2020-6820   URL
53581BROWSER-FIREFOX Mozilla Firefox potential use after free attempt (more info ...)attempted-user 2020-6820   URL
54024POLICY-OTHER Cisco Unified Contact Center Express vulnerable Java RMI class access detected (more info ...)policy-violation 2020-3280   URL
54025POLICY-OTHER Cisco Unified Contact Center Express vulnerable Java RMI class access detected (more info ...)policy-violation 2020-3280   URL
54026POLICY-OTHER Cisco Unified Contact Center Express vulnerable Java RMI class access detected (more info ...)policy-violation 2020-3280   URL
54027POLICY-OTHER Cisco Unified Contact Center Express vulnerable Java RMI class access detected (more info ...)policy-violation 2020-3280   URL
56008BROWSER-WEBKIT Apple Safari WebKit JSPropertyNameEnumeration type confusion attempt (more info ...)attempted-user 2018-4416   URL
56009BROWSER-WEBKIT Apple Safari WebKit JSPropertyNameEnumeration type confusion attempt (more info ...)attempted-user 2018-4416   URL
56042BROWSER-WEBKIT Apple Safari Webkit attribute child removal code execution attempt (more info ...)attempted-user 2010-1119 40642  
56043BROWSER-WEBKIT Apple Safari WebKit Webcore SVGAnimateElementBase use after free attempt (more info ...)attempted-user 2018-4314   
56044BROWSER-WEBKIT Apple Safari WebKit Webcore SVGAnimateElementBase use after free attempt (more info ...)attempted-user 2018-4314   
56541BROWSER-FIREFOX Mozilla Firefox default content process DACL sandbox escape attempt (more info ...)attempted-user 2020-12388   URL
56542BROWSER-FIREFOX Mozilla Firefox default content process DACL sandbox escape attempt (more info ...)attempted-user 2020-12388   URL
57375BROWSER-CHROME Google Chrome WebAssembly memory corruption attempt (more info ...)attempted-user 2020-15994   URL
57376BROWSER-CHROME Google Chrome WebAssembly memory corruption attempt (more info ...)attempted-user 2020-15994   URL
57385INDICATOR-OBFUSCATION Javascript obfuscation using meaningless bitshift (more info ...)attempted-user    URL
57423BROWSER-CHROME Google Chrome V8 JavaScript Engine memory corruption attempt (more info ...)attempted-user 2020-16009   URL
57424BROWSER-CHROME Google Chrome V8 JavaScript Engine memory corruption attempt (more info ...)attempted-user 2020-16009   URL
57433POLICY-OTHER VMware vRealize Operations Manager potential maintenceAdmin credentials leak attempt (more info ...)policy-violation 2021-21975   URL
57446BROWSER-CHROME Google Chrome JavaScript engine use after free attempt (more info ...)attempted-user 2020-6550   
57447BROWSER-CHROME Google Chrome JavaScript engine use after free attempt (more info ...)attempted-user 2020-6550   
57484BROWSER-IE Microsoft Internet Explorer CSS .ipsum layout use-after-free attempt (more info ...)attempted-user 2013-1310 59751  URL
57485BROWSER-IE Microsoft Internet Explorer CSS .ipsum layout use-after-free attempt (more info ...)attempted-user 2013-1310 59751  URL
57533FILE-JAVA Oracle Java Runtime Environment JAR file processing buffer overflow attempt (more info ...)attempted-user 2008-5354 32608  
57534FILE-JAVA Oracle Java Runtime Environment JAR file processing buffer overflow attempt (more info ...)attempted-user 2008-5354 32608  
57568SERVER-OTHER Oracle Java PhantomReference object handling memory corruption attempt (more info ...)attempted-user 2015-0395   URL
57569SERVER-OTHER Oracle Java PhantomReference object handling memory corruption attempt (more info ...)attempted-user 2015-0395   URL
57743MALWARE-CNC Java.Backdoor.StrRAT outbound connection attempt (more info ...)trojan-activity    URL
57797INDICATOR-OBFUSCATION Javascript obfuscation using parseInt (more info ...)attempted-user    URL
57808SERVER-OTHER Mozilla Network Security Services stack buffer overflow attempt (more info ...)attempted-user 2007-0009 22694  URL
57998BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user 2021-34480   URL
57999BROWSER-IE Microsoft Internet Explorer memory corruption attempt (more info ...)attempted-user 2021-34480   URL
58335SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center Java expression language injection attempt (more info ...)attempted-admin 2017-12513   
58336SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center Java expression language injection attempt (more info ...)attempted-admin 2017-12513   
58389SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center deploySelectBootrom Java expression language injection attempt (more info ...)web-application-attack    
58390SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center deploySelectBootrom Java expression language injection attempt (more info ...)web-application-attack    
58391SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center reportTaskSelect Java expression language injection attempt (more info ...)web-application-attack    
58392SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center reportTaskSelect Java expression language injection attempt (more info ...)web-application-attack    
58393SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center ictExpertCSVDownload Java expression language injection attempt (more info ...)web-application-attack    
58394SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center ictExpertCSVDownload Java expression language injection attempt (more info ...)web-application-attack    
58516SERVER-WEBAPP SAP NetWeaver AS JAVA XML external entity injection attempt (more info ...)web-application-attack 2016-9563   
58838SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center Index Java expression language injection attempt (more info ...)attempted-admin 2017-12525   
58839SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center Index Java expression language injection attempt (more info ...)attempted-admin 2017-12525   
58856SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center TopoReqServlet arbitrary Java object deserialization attempt (more info ...)attempted-admin 2017-8963   
58978SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center Java expression language injection attempt (more info ...)attempted-admin 2017-12517   
58979SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center Java expression language injection attempt (more info ...)attempted-admin 2017-12517   
59313SERVER-WEBAPP HPE Intelligent Management Center PlatNavigationToBean URL Java expression language injection attempt (more info ...)attempted-admin 2019-5387   
59314SERVER-WEBAPP HPE Intelligent Management Center PlatNavigationToBean URL Java expression language injection attempt (more info ...)attempted-admin 2019-5387   
59445MALWARE-CNC Java.Trojan.Verblecon variant outbound connection (more info ...)trojan-activity    URL
59446MALWARE-CNC Java.Trojan.Verblecon variant outbound connection (more info ...)trojan-activity    URL
59463INDICATOR-SHELLCODE Java object deserialization exploit attempt (more info ...)attempted-user 2020-3280   URL
59552FILE-JAVA IBM Java SDK privilege escalation attempt (more info ...)attempted-user 2012-4822   
59553FILE-JAVA IBM Java SDK privilege escalation attempt (more info ...)attempted-user 2012-4822   
59554FILE-JAVA IBM Java SDK privilege escalation attempt (more info ...)attempted-user 2012-4822   
59555FILE-JAVA IBM Java SDK privilege escalation attempt (more info ...)attempted-user 2012-4822   
59712FILE-JAVA Oracle Java Applet ProviderSkeleton sandbox bypass attempt (more info ...)attempted-user 2013-2460   
59713FILE-JAVA Oracle Java Applet ProviderSkeleton sandbox bypass attempt (more info ...)attempted-user 2013-2460   
60051BROWSER-CHROME Google Chrome V8 JavaScript Engine type confusion attempt (more info ...)attempted-user 2020-6383   
60052BROWSER-CHROME Google Chrome V8 JavaScript Engine type confusion attempt (more info ...)attempted-user 2020-6383   
60220BROWSER-CHROME Chrome IPC domDistiller sandbox escape attempt (more info ...)attempted-user 2020-6465   URL
60221BROWSER-CHROME Chrome IPC domDistiller sandbox escape attempt (more info ...)attempted-user 2020-6465   URL
60222BROWSER-CHROME V8 WebAssembly remote code execution attempt (more info ...)attempted-user 2020-15994   URL
60223BROWSER-CHROME V8 WebAssembly remote code execution attempt (more info ...)attempted-user 2020-15994   URL
60282BROWSER-CHROME Intent handling downgrade attempt (more info ...)attempted-user 2022-2856   URL
60290BROWSER-CHROME Google Chrome v8 garbage collector use after free attempt (more info ...)attempted-user 2021-37975   
60295MALWARE-CNC Win.Downloader.ChromeLoader outbound connection attempt (more info ...)trojan-activity    URL
60354BROWSER-CHROME V8 getThis type confusion attempt (more info ...)attempted-user 2022-1364   URL
60355BROWSER-CHROME V8 getThis type confusion attempt (more info ...)attempted-user 2022-1364   URL
60368BROWSER-CHROME Chromium V8 Engine remote code execution attempt (more info ...)attempted-user 2016-5198   URL
60467BROWSER-CHROME Google Chrome V8 engine IterateElements out-of-bounds read attempt (more info ...)attempted-user 2016-1646   
60468BROWSER-CHROME Google Chrome V8 engine IterateElements out-of-bounds read attempt (more info ...)attempted-user 2016-1646   
60683BROWSER-WEBKIT Apple Safari WebCore command cross site scripting attempt (more info ...)attempted-user 2019-8720   URL
60684BROWSER-WEBKIT Apple Safari WebCore command cross site scripting attempt (more info ...)attempted-user 2019-8720   URL
60702BROWSER-IE Microsoft Internet Explorer EPM MOTWCreateFileW file access bypass attempt (more info ...)policy-violation 2014-2817   URL
60703BROWSER-IE Microsoft Internet Explorer EPM MOTWCreateFileW file access bypass attempt (more info ...)policy-violation 2014-2817   URL
60711FILE-JAVA Oracle Java JNLP progress-class remote code execution attempt (more info ...)attempted-user 2015-4902   URL
60712FILE-JAVA Oracle Java JNLP progress-class remote code execution attempt (more info ...)attempted-user 2015-4902   URL
60915BROWSER-CHROME V8 CSS prop type defineProperty interceptor confusion attempt (more info ...)attempted-user 2022-1232   URL
60916BROWSER-CHROME V8 CSS prop type defineProperty interceptor confusion attempt (more info ...)attempted-user 2022-1232   URL
60944BROWSER-CHROME Chrome JavaScript Array.map Out-of-Bounds Write attempt (more info ...)web-application-attack 2019-5825   URL
60945BROWSER-CHROME Chrome JavaScript Array.map Out-of-Bounds Write attempt (more info ...)web-application-attack 2019-5825   URL
60952BROWSER-CHROME Google Chrome PDFiumEngine RequestThumbnail use-after-free attempt (more info ...)attempted-user 2022-0306   URL
60953BROWSER-CHROME Google Chrome PDFiumEngine RequestThumbnail use-after-free attempt (more info ...)attempted-user 2022-0306   URL
60986FILE-PDF Foxit PhantomPDF JavaScript annotation use-after-free attempt (more info ...)attempted-user    
60987FILE-PDF Foxit PhantomPDF JavaScript annotation use-after-free attempt (more info ...)attempted-user    
61029BROWSER-CHROME Google Chrome safe_browsing malicious use-after-free attempt (more info ...)attempted-user 2022-0289   URL
61030BROWSER-CHROME Google Chrome safe_browsing malicious use-after-free attempt (more info ...)attempted-user 2022-0289   URL
61031BROWSER-CHROME Google Chrome safe_browsing malicious use-after-free attempt (more info ...)attempted-user 2022-0289   URL
61032BROWSER-CHROME Google Chrome safe_browsing malicious use-after-free attempt (more info ...)attempted-user 2022-0289   URL
61165BROWSER-CHROME TRUFFLEHUNTER TALOS-2023-1693 attack attempt (more info ...)attempted-user    URL
61166BROWSER-CHROME TRUFFLEHUNTER TALOS-2023-1693 attack attempt (more info ...)attempted-user    URL

 goto Top

Group: Client / Email

# of attack rules in this group: 8

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
37131FILE-IDENTIFY .wsf attachment file type blocked by Outlook detected (more info ...)policy-violation        
44734SERVER-MAIL Microsoft Outlook Express mhtml code execution attempt (more info ...)attempted-admin  2004-0380      
44735SERVER-MAIL Microsoft Outlook Express mhtml code execution attempt (more info ...)attempted-admin  2004-0380      
62038SERVER-WEBAPP Roundcube Webmail Client command injection attempt (more info ...)web-application-attack  2020-12641      URL
62039SERVER-WEBAPP Roundcube Webmail Client command injection attempt (more info ...)web-application-attack  2020-12641      URL
62040SERVER-WEBAPP Roundcube Webmail Client command injection attempt (more info ...)web-application-attack  2020-12641      URL
62041SERVER-WEBAPP Roundcube Webmail Client remote file include attempt (more info ...)web-application-attack  2020-12641      URL
62042SERVER-WEBAPP Roundcube Webmail Client remote file include attempt (more info ...)web-application-attack  2020-12641      URL


# of warning rules in this group: 104

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
7005BROWSER-PLUGINS OutlookExpress.AddressBook ActiveX function call access (more info ...)attempted-user    
8371BROWSER-PLUGINS Outlook.Application ActiveX clsid access (more info ...)attempted-user    URL
8721BROWSER-PLUGINS Outlook Data Object ActiveX clsid access (more info ...)attempted-user    URL
9668BROWSER-PLUGINS Outlook Recipient Control ActiveX clsid access (more info ...)attempted-user 2006-6659 21649  
9670BROWSER-PLUGINS Outlook Recipient Control ActiveX function call access (more info ...)attempted-user 2006-6659 21649  
11236BROWSER-PLUGINS OutlookExpress.AddressBook ActiveX clsid access (more info ...)attempted-user    
12390POLICY-SOCIAL Yahoo Webmail client chat applet (more info ...)policy-violation    
12391POLICY-SOCIAL Google Webmail client chat applet (more info ...)policy-violation    
18590OS-WINDOWS Outlook Express WAB file parsing buffer overflow attempt (more info ...)attempted-user 2006-2386 17459  URL
18811FILE-IDENTIFY .ade attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18812FILE-IDENTIFY .adp attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18813FILE-IDENTIFY .app attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18814FILE-IDENTIFY .asp attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18815FILE-IDENTIFY .bas attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18817FILE-IDENTIFY .cer attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18818FILE-IDENTIFY .chm attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18819FILE-IDENTIFY .cmd attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18820FILE-IDENTIFY .cnt attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18821FILE-IDENTIFY .com attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18822FILE-IDENTIFY .cpl attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18823FILE-IDENTIFY .crt attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18824FILE-IDENTIFY .csh attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18825FILE-IDENTIFY .der attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18826FILE-IDENTIFY .exe attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18827FILE-IDENTIFY .fxp attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18828FILE-IDENTIFY .gadget attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18829FILE-IDENTIFY .hlp attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18830FILE-IDENTIFY .hpj attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18831FILE-IDENTIFY .hta attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18832FILE-IDENTIFY .inf attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18833FILE-IDENTIFY .ins attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18834FILE-IDENTIFY .isp attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18835FILE-IDENTIFY .its attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18836FILE-IDENTIFY .js attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18837FILE-IDENTIFY .jse attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18838FILE-IDENTIFY .ksh attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18839FILE-IDENTIFY .lnk attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18840FILE-IDENTIFY .mad attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18841FILE-IDENTIFY .maf attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18842FILE-IDENTIFY .mag attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18843FILE-IDENTIFY .mam attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18844FILE-IDENTIFY .maq attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18845FILE-IDENTIFY .mar attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18846FILE-IDENTIFY .mas attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18847FILE-IDENTIFY .mat attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18848FILE-IDENTIFY .mau attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18849FILE-IDENTIFY .mav attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18850FILE-IDENTIFY .maw attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18851FILE-IDENTIFY .mda attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18852FILE-IDENTIFY .mdb attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18853FILE-IDENTIFY .mde attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18854FILE-IDENTIFY .mdt attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18855FILE-IDENTIFY .mdw attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18856FILE-IDENTIFY .mdz attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18857FILE-IDENTIFY .msc attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18858FILE-IDENTIFY .msh attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18859FILE-IDENTIFY .msh1 attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18860FILE-IDENTIFY .msh2 attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18861FILE-IDENTIFY .mshxml attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18862FILE-IDENTIFY .msh1xml attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18863FILE-IDENTIFY .msh2xml attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18864FILE-IDENTIFY .msi attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18865FILE-IDENTIFY .msp attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18866FILE-IDENTIFY .mst attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18867FILE-IDENTIFY .ops attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18868FILE-IDENTIFY .osd attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18869FILE-IDENTIFY .pcd attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18870FILE-IDENTIFY .pif attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18871FILE-IDENTIFY .plg attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18872FILE-IDENTIFY .prf attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18873FILE-IDENTIFY .prg attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18874FILE-IDENTIFY .pst attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18875FILE-IDENTIFY .reg attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18876FILE-IDENTIFY .scf attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18877FILE-IDENTIFY .scr attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18878FILE-IDENTIFY .sct attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18879FILE-IDENTIFY .shb attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18880FILE-IDENTIFY .shs attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18881FILE-IDENTIFY .ps1 attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18882FILE-IDENTIFY .ps1xml attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18883FILE-IDENTIFY .ps2 attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18884FILE-IDENTIFY .ps2xml attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18885FILE-IDENTIFY .psc1 attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18886FILE-IDENTIFY .psc2 attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18887FILE-IDENTIFY .tmp attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18888FILE-IDENTIFY .url attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18889FILE-IDENTIFY .vb attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18890FILE-IDENTIFY .vbe attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18891FILE-IDENTIFY .vbp attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18892FILE-IDENTIFY .vbs attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18893FILE-IDENTIFY .vsmacros attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18894FILE-IDENTIFY .vsw attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18895FILE-IDENTIFY .ws attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18896FILE-IDENTIFY .wsc attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18897FILE-IDENTIFY .wsf attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18898FILE-IDENTIFY .wsh attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
18899FILE-IDENTIFY .xnk attachment file type blocked by Outlook detected (more info ...)policy-violation    URL
26993SERVER-WEBAPP Microsoft Outlook Web Access Login URL Redirection attempt (more info ...)web-application-activity 2005-0420   
32681SERVER-WEBAPP Microsoft Outlook Web Access parameter cross site scripting attempt (more info ...)attempted-user 2014-6325   URL
32682SERVER-WEBAPP Microsoft Outlook Web Access parameter cross site scripting attempt (more info ...)attempted-user 2014-6325   URL
33198OS-WINDOWS Outlook Express WAB file parsing buffer overflow attempt (more info ...)attempted-user 2006-2386 17459  URL
33762SERVER-WEBAPP Microsoft Outlook WebAccess msgParam cross site scripting attempt (more info ...)attempted-user 2015-1632   URL
36766FILE-OTHER Microsoft Outlook for Mac EML file http-equiv refresh url attempt (more info ...)misc-attack 2015-6123   URL
36767FILE-OTHER Microsoft Outlook for Mac EML file http-equiv refresh url attempt (more info ...)misc-attack 2015-6123   URL

 goto Top

Group: Client / Multimedia

# of attack rules in this group: 3261

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
2420FILE-IDENTIFY RealNetworks Realplayer .rmp playlist file download request (more info ...)misc-activity        URL
3088FILE-MULTIMEDIA Nullsoft Winamp cda file name overflow attempt (more info ...)attempted-user  2004-1119  11730  15817  
12454FILE-IDENTIFY Microsoft Windows Media ASF file magic detected (more info ...)misc-activity        URL
13520SERVER-OTHER Nullsoft Winamp Ultravox buffer overflow attempt (more info ...)attempted-user  2008-0065      
13521SERVER-OTHER Nullsoft Winamp Ultravox buffer overflow attempt (more info ...)attempted-user  2008-0065      
13897FILE-MULTIMEDIA Apple Quicktime crgn atom parsing stack buffer overflow attempt (more info ...)attempted-user  2008-1017  28583    
15483FILE-IDENTIFY Adobe Shockwave Flash file download request (more info ...)misc-activity        URL
15901FILE-MULTIMEDIA Nullsoft Winamp AIFF parsing heap buffer overflow attempt (more info ...)attempted-user  2009-0263  33226    
16219FILE-IDENTIFY Adobe Director Movie file download request (more info ...)misc-activity        URL
16371BROWSER-PLUGINS NOS Microsystems Adobe atl_getcom ActiveX clsid access (more info ...)attempted-user  2009-3958  37759    URL
16490FILE-PDF Adobe Acrobat Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188      URL
17116FILE-IDENTIFY Microsoft Windows Media ASX file download request (more info ...)misc-activity        URL
17214FILE-PDF Adobe Acrobat Reader libtiff TIFFFetchShortPair stack buffer overflow attempt (more info ...)attempted-user  2010-0188      
17215FILE-PDF Adobe Acrobat Reader libtiff TIFFFetchShortPair stack buffer overflow attempt (more info ...)attempted-user  2010-0188      
17233FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883      URL
17241FILE-IDENTIFY Microsoft Windows Media wmv file download request (more info ...)misc-activity        
17700FILE-MULTIMEDIA RealNetworks RealPlayer wav chunk string overflow attempt (more info ...)attempted-user  2005-0611  12697    
17801FILE-IDENTIFY Adobe Director Movie file magic detected (more info ...)misc-activity        URL
17802FILE-IDENTIFY Adobe Director Movie file download request (more info ...)misc-activity        URL
17809FILE-IDENTIFY Apple Quicktime qt file download request (more info ...)misc-activity        URL
18527FILE-PDF Adobe Acrobat Reader shell metacharacter code execution attempt (more info ...)attempted-user  2004-0630  10931    
18585FILE-PDF Adobe Acrobat Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188      URL
18987FILE-PDF Adobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
18988FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
18989FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
18990FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
18991FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
19257FILE-FLASH Adobe ActionScript float index memory corruption attempt (more info ...)attempted-user  2011-2110      URL
19262FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption (more info ...)attempted-user  2011-2110      URL
19263FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption (more info ...)attempted-user  2011-2110      URL
19264FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption (more info ...)attempted-user  2011-2110      URL
19682FILE-FLASH Adobe Flash Player ActionScript 3 integer overflow attempt (more info ...)attempted-user  2011-2416  49081    URL
20031FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption (more info ...)attempted-user  2011-2110      URL
20110SERVER-OTHER Nullsoft Winamp Ultravox streaming malicious metadata (more info ...)attempted-user  2008-0065      
20131FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt (more info ...)attempted-user  2011-0611  47314    URL
20495FILE-IDENTIFY compressed Adobe Shockwave Flash file magic detected (more info ...)misc-activity        
20496FILE-IDENTIFY Adobe Shockwave Flash file magic detected (more info ...)misc-activity        
20497FILE-IDENTIFY Adobe Shockwave Flash file magic detected (more info ...)misc-activity        
20507FILE-IDENTIFY Adobe Shockwave Flash file magic detected (more info ...)misc-activity        
20544FILE-IDENTIFY Adobe Flash Player FLV file download request (more info ...)misc-activity        URL
20577FILE-PDF Adobe Acrobat Reader malicious TIFF remote code execution attempt (more info ...)attempted-user  2010-0188      URL
20659FILE-PDF Adobe Acrobat Reader malformed shading modifier heap corruption attempt (more info ...)attempted-user  2011-2462      URL
20767FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption (more info ...)attempted-user  2011-2110      URL
20777FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption attempt (more info ...)attempted-user  2011-2110      URL
20778FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt - economy.rar (more info ...)attempted-user  2011-0611  47314    URL
20779FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt - dear chu.rar (more info ...)attempted-user  2011-0611  47314    URL
20780FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt - namelist.xls (more info ...)attempted-user  2011-0611  47314    URL
20781FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt (more info ...)attempted-user  2011-0611  47314    URL
20782FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt - economy.rar (more info ...)attempted-user  2011-0611  47314    URL
20783FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt - dear chu.rar (more info ...)attempted-user  2011-0611  47314    URL
20784FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt - namelist.xls (more info ...)attempted-user  2011-0611  47314    URL
20785FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt (more info ...)attempted-user  2011-0611  47314    URL
20798FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20799FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20803FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt (more info ...)attempted-user  2011-0611  47314    URL
20900FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003  51292    URL
20909FILE-IDENTIFY Microsoft Windows Media ASF file attachment detected (more info ...)misc-activity        
20910FILE-IDENTIFY Microsoft Windows Media ASF file attachment detected (more info ...)misc-activity        
20937FILE-IDENTIFY Adobe Shockwave Flash file download request (more info ...)misc-activity        URL
20938FILE-IDENTIFY Adobe Shockwave Flash file download request (more info ...)misc-activity        URL
20939FILE-IDENTIFY Adobe Shockwave Flash file download request (more info ...)misc-activity        URL
20940FILE-IDENTIFY Adobe Shockwave Flash file download request (more info ...)misc-activity        URL
20941FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20942FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20943FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20944FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20945FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20946FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20947FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
20948FILE-IDENTIFY Adobe Shockwave Flash file attachment detected (more info ...)misc-activity        
21159FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003  51292    URL
21167FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003  51292    URL
21253FILE-PDF Adobe Acrobat Reader malformed shading modifier heap corruption attempt (more info ...)attempted-user  2011-2462      URL
21335FILE-FLASH Adobe Flash Player ActionScript bytecode type confusion null dereference attempt (more info ...)attempted-user  2012-0752      URL
21336FILE-FLASH Adobe Flash ASConstructor insecure calling attempt (more info ...)attempted-user  2012-0753      URL
21338FILE-FLASH Adobe Flash Player MP4 zero length atom attempt (more info ...)attempted-user  2012-0754      URL
21339FILE-MULTIMEDIA Adobe Flash Player MP4 zero length atom auth field attempt (more info ...)attempted-user  2012-0754      URL
21340FILE-MULTIMEDIA Adobe Flash Player MP4 zero length atom titl field attempt (more info ...)attempted-user  2015-0360      URL
21341FILE-MULTIMEDIA Adobe Flash Player MP4 zero length atom 'dscp' field attempt (more info ...)attempted-user  2012-0754      URL
21342FILE-MULTIMEDIA Adobe Flash Player MP4 zero length atom cprt field attempt (more info ...)attempted-user  2012-0754      URL
21457FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption (more info ...)attempted-user  2011-2110      URL
21458FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption (more info ...)attempted-user  2011-2110      URL
21533FILE-FLASH Adobe Flash Player ActionScript Stage3D null dereference attempt (more info ...)attempted-user  2012-0768      URL
21534FILE-FLASH Adobe Flash Player ActionScript Matrix3D.copyRawDataFrom buffer overflow attempt (more info ...)attempted-user  2012-0768      URL
21535FILE-FLASH Adobe Flash Player ActionScript Matrix3D.copyRawDataFrom buffer overflow attempt (more info ...)attempted-user  2012-0768      URL
21536FILE-FLASH Adobe Flash Player ActionScript Stage3D null dereference attempt (more info ...)attempted-user  2012-0768      URL
21653FILE-FLASH Adobe Flash Player ActionScript getURL target null reference attempt (more info ...)denial-of-service  2012-0772      URL
21654FILE-FLASH Adobe Flash Video invalid tag type attempt (more info ...)attempted-user  2012-0773      
21655FILE-FLASH Adobe Flash Video invalid tag type attempt (more info ...)attempted-user  2012-0773      
21740FILE-IDENTIFY Microsoft Windows Media asx file attachment detected (more info ...)misc-activity        URL
21741FILE-IDENTIFY Microsoft Windows Media asx file attachment detected (more info ...)misc-activity        URL
21858FILE-PDF Adobe Acrobat Reader msiexec.exe file load exploit attempt (more info ...)attempted-user  2012-0776  52952    URL
21859FILE-PDF Adobe Acrobat Reader msiexec.exe file load exploit attempt (more info ...)attempted-user  2012-0776  52952    URL
21878FILE-PDF Adobe Acrobat Reader embedded TTF integer overflow attempt (more info ...)attempted-user  2012-0774      URL
21890FILE-IDENTIFY Adobe Director Movie file attachment detected (more info ...)misc-activity        
21891FILE-IDENTIFY Adobe Director Movie file attachment detected (more info ...)misc-activity        
21892FILE-IDENTIFY Adobe Director Movie file attachment detected (more info ...)misc-activity        
21893FILE-IDENTIFY Adobe Director Movie file attachment detected (more info ...)misc-activity        
22069FILE-FLASH Adobe Flash Player object confusion attempt (more info ...)attempted-user  2012-0779      URL
22070FILE-FLASH Adobe Flash Player object confusion attempt (more info ...)attempted-user  2012-0779      URL
22915FILE-FLASH Adobe Flash Player object confusion attempt (more info ...)attempted-user  2012-0779      URL
22916FILE-FLASH Adobe Flash Player object confusion attempt (more info ...)attempted-user  2012-0779      URL
22938FILE-PDF Adobe Acrobat Reader embedded TTF integer overflow attempt (more info ...)attempted-user  2012-0774      URL
23129FILE-FLASH Adobe Flash Player SecureSocket use without Connect attempt (more info ...)attempted-user  2012-2039      URL
23130FILE-FLASH Adobe Flash Player X509 direct instantiation property access attempt (more info ...)attempted-user  2012-2039      URL
23131FILE-FLASH Adobe Flash Player X500 DistinguishedName property access attempt (more info ...)attempted-user  2012-2039      URL
23132FILE-FLASH Adobe Flash Player DefineSound tag long recordheader length field attempt (more info ...)attempted-user  2012-2037      URL
23133FILE-FLASH Adobe Flash Player flash.display.BitmapData constuctor overflow attempt (more info ...)misc-attack  2012-2036      URL
23134FILE-FLASH Adobe Flash Player broker destructor DoS attempt (more info ...)attempted-dos  2012-2035      URL
23135FILE-FLASH Adobe Flash Player flash.DisplayObject memory corruption attempt (more info ...)misc-attack  2012-2034      URL
23190FILE-IDENTIFY Windows Media Metafile file download request (more info ...)misc-activity        
23191FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23192FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23193FILE-IDENTIFY Windows Media Metafile file download request (more info ...)misc-activity        
23194FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23195FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23196FILE-IDENTIFY Windows Media Metafile file download request (more info ...)misc-activity        
23197FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23198FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23199FILE-IDENTIFY Windows Media Metafile file download request (more info ...)misc-activity        
23200FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23201FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23202FILE-IDENTIFY Windows Media Metafile file download request (more info ...)misc-activity        
23205FILE-IDENTIFY Windows Media Metafile file download request (more info ...)misc-activity        
23206FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23207FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
23271FILE-MULTIMEDIA Apple iTunes Extended M3U playlist record overflow attempt (more info ...)attempted-user  2012-0677  53933    
23272FILE-MULTIMEDIA Apple iTunes Extended M3U playlist record overflow attempt (more info ...)attempted-user  2012-0677  53933    
23461FILE-OTHER Apple Quicktime TeXML Transform attribute overflow attempt (more info ...)attempted-user  2012-0663      
23462FILE-OTHER Apple Quicktime TeXML Style attribute overflow attempt (more info ...)attempted-user  2012-0663      
23463FILE-OTHER Apple Quicktime TeXML sampleData attribute overflow attempt (more info ...)attempted-user  2012-0663      
23464FILE-OTHER Apple Quicktime TeXML description attribute overflow attempt (more info ...)attempted-user  2012-0663      
23465FILE-OTHER Apple Quicktime TeXML Style attribute overflow attempt (more info ...)attempted-user  2012-0663      
23517FILE-PDF Adobe Acrobat Reader libtiff TIFFFetchShortPair stack buffer overflow attempt (more info ...)attempted-user  2010-0188      
23518FILE-PDF Adobe Acrobat Reader libtiff TIFFFetchShortPair stack buffer overflow attempt (more info ...)attempted-user  2010-0188      
23522FILE-PDF Adobe Acrobat Reader malicious TIFF remote code execution attempt (more info ...)attempted-user  2010-0188      URL
23523FILE-PDF Adobe Acrobat Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188      URL
23524FILE-PDF Adobe Acrobat Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188      URL
23582FILE-OTHER Apple Quicktime TeXML Transform attribute overflow attempt (more info ...)attempted-user  2012-0663      
23583FILE-OTHER Apple Quicktime TeXML Style attribute overflow attempt (more info ...)attempted-user  2012-0663      
23584FILE-OTHER Apple Quicktime TeXML sampleData attribute overflow attempt (more info ...)attempted-user  2012-0663      
23585FILE-OTHER Apple Quicktime TeXML description attribute overflow attempt (more info ...)attempted-user  2012-0663      
23586FILE-OTHER Apple Quicktime TeXML Style attribute overflow attempt (more info ...)attempted-user  2012-0663      
23587FILE-MULTIMEDIA Apple iTunes Extended M3U playlist record overflow attempt (more info ...)attempted-user  2012-0677  53933    
23588FILE-MULTIMEDIA Apple iTunes Extended M3U playlist record overflow attempt (more info ...)attempted-user  2012-0677  53933    
23679FILE-IDENTIFY compressed Adobe Shockwave Flash file magic detected (more info ...)misc-activity        
23680FILE-IDENTIFY Adobe Shockwave Flash file magic detected (more info ...)misc-activity        
23681FILE-IDENTIFY Adobe Shockwave Flash file magic detected (more info ...)misc-activity        
23687FILE-IDENTIFY Adobe Shockwave Flash file magic detected (more info ...)misc-activity        
23698FILE-IDENTIFY Microsoft Windows Media ASF file magic detected (more info ...)misc-activity        URL
23724FILE-IDENTIFY Adobe Director Movie file magic detected (more info ...)misc-activity        URL
23727FILE-IDENTIFY Adobe Flash Video file magic detected (more info ...)misc-activity        URL
23853FILE-FLASH Adobe Flash OpenType font memory corruption attempt (more info ...)attempted-user  2012-1535  55009    URL
23854FILE-FLASH Adobe Flash OpenType font memory corruption attempt (more info ...)attempted-user  2012-1535  55009    URL
23864FILE-PDF Adobe Acrobat Reader invalid font WeightVector attempt (more info ...)denial-of-service  2012-4152      URL
23865FILE-PDF Adobe Acrobat Reader invalid font WeightVector attempt (more info ...)denial-of-service  2012-4152      URL
23866FILE-PDF Adobe Acrobat Reader invalid inline image attempt (more info ...)denial-of-service  2012-4151      URL
23867FILE-PDF Adobe Acrobat Reader invalid inline image attempt (more info ...)denial-of-service  2012-4151      URL
23868FILE-PDF Adobe Acrobat Reader invalid inline image attempt (more info ...)denial-of-service  2012-4151      URL
23869FILE-PDF Adobe Acrobat Reader invalid inline image attempt (more info ...)denial-of-service  2012-4151      URL
23870FILE-PDF Adobe Acrobat Reader invalid inline image attempt (more info ...)denial-of-service  2012-4151      URL
23871FILE-PDF Adobe Acrobat Reader invalid inline image attempt (more info ...)denial-of-service  2012-4151      URL
23874FILE-PDF Adobe Acrobat Reader postscript font execution malformed subroutine entries attempt (more info ...)denial-of-service  2012-4153      URL
23875FILE-PDF Adobe Acrobat Reader postscript font execution malformed subroutine entries attempt (more info ...)denial-of-service  2012-4153      URL
23879FILE-PDF Adobe Acrobat Reader Texture Declaration buffer overflow attempt (more info ...)attempted-user  2012-2049  55024    URL
23880FILE-PDF Adobe Acrobat Reader Texture Declaration buffer overflow attempt (more info ...)attempted-user  2012-2049  55024    URL
23881FILE-PDF Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt (more info ...)attempted-dos  2012-4147      
23882FILE-PDF Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt (more info ...)attempted-dos  2012-4147      
23883FILE-PDF Adobe Acrobat Reader JBIG2 encoding invalid symbol in dictionary segment (more info ...)attempted-admin  2012-4150      URL
23884FILE-PDF Adobe Acrobat Reader JBIG2 encoding invalid symbol in dictionary segment (more info ...)attempted-admin  2012-4150      URL
23889FILE-PDF Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt (more info ...)attempted-dos  2012-2050      URL
23890FILE-PDF Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt (more info ...)attempted-dos  2012-2050      URL
23891FILE-PDF Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt (more info ...)attempted-dos  2012-2050      URL
23892FILE-PDF Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt (more info ...)attempted-dos  2012-2050      URL
23939SERVER-ORACLE Oracle Business Transaction Management FlashTunnelService directory traversal attempt (more info ...)web-application-attack    54839    
23940SERVER-ORACLE Oracle Business Transaction Management FlashTunnelService directory traversal attempt (more info ...)web-application-attack    54839    
23967FILE-FLASH Adobe Flash OpenType font memory corruption attempt - compressed (more info ...)attempted-user  2012-1535  55009    URL
23985BROWSER-PLUGINS Apple Quicktime plugin SetLanguage buffer overflow attempt (more info ...)attempted-user  2012-0666  53577    URL
23986BROWSER-PLUGINS Apple Quicktime plugin SetLanguage buffer overflow attempt (more info ...)attempted-user  2012-0666  53577    URL
23996FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption attempt (more info ...)attempted-user  2011-2110      URL
23997FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption attempt (more info ...)attempted-user  2011-2110      URL
23999FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003  51292    URL
24000FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003  51292    URL
24001FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003  51292    URL
24002FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003  51292    URL
24003FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003      URL
24138FILE-FLASH Adobe Flash malformed RTMP response attempt (more info ...)protocol-command-decode  2012-0779      URL
24139FILE-FLASH Adobe Flash malformed RTMP response attempt (more info ...)protocol-command-decode  2012-0779      URL
24140FILE-FLASH Adobe Flash malformed RTMP response attempt (more info ...)protocol-command-decode  2012-0779      URL
24142FILE-FLASH Adobe Flash Player object confusion attempt (more info ...)attempted-user  2012-0779      URL
24148FILE-PDF Adobe Acrobat Reader malicious charstring stream attempt (more info ...)attempted-user  2012-4159      URL
24149FILE-PDF Adobe Acrobat Reader malicious charstring stream attempt (more info ...)attempted-user  2012-4159      URL
24150FILE-PDF Adobe Acrobat Reader TrueType font corrupt header attempt (more info ...)attempted-user  2012-4157      URL
24151FILE-PDF Adobe Acrobat Reader TrueType font corrupt header attempt (more info ...)attempted-user  2012-4157      URL
24152FILE-PDF Adobe Acrobat Reader embedded TTF bytecode memory corruption attempt (more info ...)attempted-user  2012-4154  55015    URL
24153FILE-PDF Adobe Acrobat Reader embedded TTF bytecode memory corruption attempt (more info ...)attempted-user  2012-4154  55015    URL
24154FILE-PDF Adobe Acrobat Reader free text annotation invalid IT value denial of service attempt (more info ...)trojan-activity  2012-4149      URL
24155FILE-PDF Adobe Acrobat Reader free text annotation invalid IT value denial of service attempt (more info ...)trojan-activity  2012-4149      URL
24244FILE-FLASH Adobe Flash Player Matrix3D copyRawDataTo integer overflow attempt (more info ...)attempted-user  2012-5054  55691    URL
24245FILE-FLASH Adobe Flash Player Matrix3D copyRawDataTo integer overflow attempt (more info ...)attempted-user  2012-5054  55691    URL
24338FILE-OTHER Apple Quicktime TeXML Style attribute overflow attempt (more info ...)attempted-user  2012-0663      
24362FILE-FLASH Adobe Flash null reference JIT compilation attempt (more info ...)denial-of-service  2012-4165      URL
24363FILE-FLASH Adobe Flash null reference JIT compilation attempt (more info ...)denial-of-service  2012-4165      URL
24364FILE-FLASH Adobe Flash null reference JIT compilation attempt (more info ...)denial-of-service  2012-4165      URL
24365FILE-FLASH Adobe Flash null reference JIT compilation attempt (more info ...)denial-of-service  2012-4165      URL
24366FILE-FLASH Adobe Flash malformed record stack exhaustion attempt (more info ...)denial-of-service  2012-4163      URL
24367FILE-FLASH Adobe Flash malformed record stack exhaustion attempt (more info ...)denial-of-service  2012-4163      URL
24412FILE-FLASH Adobe Flash Player DRM encrypted file detected (more info ...)misc-activity        
24413FILE-FLASH Adobe Flash Player DRM encrypted file detected (more info ...)misc-activity        
24414FILE-FLASH Adobe Flash Player stsz box heap overflow attempt (more info ...)attempted-user  2012-4167      URL
24415FILE-FLASH Adobe Flash Player stsz box heap overflow attempt (more info ...)attempted-user  2012-4167      URL
24428FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
24429FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
24430FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
24431FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
24506FILE-PDF Adobe Acrobat Reader null pointer dereference attempt (more info ...)denial-of-service  2012-4148      URL
24549FILE-MULTIMEDIA Apple QuickTime MOV Atom length buffer overflow attempt (more info ...)attempted-user  2012-0667      URL
24550FILE-MULTIMEDIA Apple QuickTime MOV Atom length buffer overflow attempt (more info ...)attempted-user  2012-0667      URL
24694FILE-IMAGE Apple QuickTime PICT file opcode corruption attempt (more info ...)attempted-user  2012-0671  53584    URL
24695FILE-IMAGE Apple QuickTime PICT file opcode corruption attempt (more info ...)attempted-user  2012-0671  53584    URL
24699FILE-MULTIMEDIA Apple QuickTime text track descriptors heap buffer overflow attempt (more info ...)attempted-user  2012-0664      
24700FILE-MULTIMEDIA Apple QuickTime text track descriptors heap buffer overflow attempt (more info ...)attempted-user  2012-0664      
24702FILE-OTHER Adobe Director rcsL chunk parsing denial of service attempt (more info ...)denial-of-service  2012-2030      
24703FILE-OTHER Adobe Director rcsL chunk parsing denial of service attempt (more info ...)denial-of-service  2012-2030      
24740SERVER-WEBAPP Oracle Business Transaction Management flashtunnelservice directory traversal attempt (more info ...)attempted-user    54870    URL
24761FILE-OTHER Adobe Director rcsL chunk parsing denial of service attempt (more info ...)denial-of-service  2012-2031      
24762FILE-OTHER Adobe Director rcsL chunk parsing denial of service attempt (more info ...)denial-of-service  2012-2031      
24810FILE-FLASH Adobe Flash Player AS2 privilege escalation attempt (more info ...)attempted-user  2012-5278      URL
24811FILE-FLASH Adobe Flash Player AS2 privilege escalation attempt (more info ...)attempted-user  2012-5278      URL
24812FILE-FLASH Adobe Flash Player AS2 privilege escalation attempt (more info ...)attempted-user  2012-5278      URL
24813FILE-FLASH Adobe Flash Player AS2 privilege escalation attempt (more info ...)attempted-user  2012-5278      URL
24874FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
24875FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
24876FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
24877FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
24879FILE-FLASH Adobe Flash Player invalid JPEG index attempt (more info ...)attempted-user  2012-5267      URL
24882FILE-FLASH Adobe Flash Player invalid JPEG index attempt (more info ...)attempted-user  2012-5267      URL
24890FILE-FLASH Adobe Flash Player Action InitArray stack overflow attempt (more info ...)attempted-user  2012-5269      URL
24892FILE-FLASH Action InitArray stack overflow attempt (more info ...)attempted-user  2012-5269      URL
24893FILE-FLASH Action InitArray stack overflow attempt (more info ...)attempted-user  2012-5269      URL
24895FILE-FLASH Adobe Flash Player ActionScript bytecode symbolclass tag type confusion attempt (more info ...)attempted-user  2012-5270      URL
24896FILE-FLASH Adobe Flash Player ActionScript bytecode symbolclass tag type confusion attempt (more info ...)attempted-user  2012-5270      URL
24980FILE-FLASH Adobe Flash Player actionscript bytecode trait type null pointer dereference attempt (more info ...)attempted-user  2012-5266      URL
24981FILE-FLASH Adobe Flash Player actionscript bytecode trait type null pointer dereference attempt (more info ...)attempted-user  2012-5266      URL
24982FILE-FLASH Adobe Flash Player actionscript bytecode trait type null pointer dereference attempt (more info ...)attempted-user  2012-5266      URL
24983FILE-FLASH Adobe Flash Player actionscript bytecode trait type null pointer dereference attempt (more info ...)attempted-user  2012-5266      URL
24984FILE-FLASH Adobe Flash Player loadPCMFromByteArray bad sample count attempt (more info ...)attempted-user  2012-5677      
24985FILE-FLASH Adobe Flash Player index overflow attempt (more info ...)attempted-user  2012-5676      URL
24986FILE-FLASH Adobe Flash Player index overflow attempt (more info ...)attempted-user  2012-5676      URL
24989FILE-FLASH Adobe Flash Player specially invalid traits structure attempt (more info ...)attempted-user  2012-5678      
24990FILE-FLASH Adobe Flash Player specially invalid traits structure attempt (more info ...)attempted-user  2012-5678      
24991FILE-FLASH Adobe Flash Player DoInitAction invalid action overflow attempt (more info ...)attempted-user  2012-5268      URL
24992FILE-FLASH Adobe Flash Player DoInitAction invalid action overflow attempt (more info ...)attempted-user  2012-5268      URL
25373FILE-IDENTIFY Apple Quicktime Targa Image file download request (more info ...)misc-activity        
25374FILE-IDENTIFY Apple Quicktime Targa Image file attachment detected (more info ...)misc-activity        
25375FILE-IDENTIFY Apple Quicktime Targa Image file attachment detected (more info ...)misc-activity        
25376FILE-IMAGE Apple QuickTime Targa image file buffer overflow attempt (more info ...)attempted-user  2012-3755  56438    URL
25378FILE-IMAGE Apple QuickTime Targa image file buffer overflow attempt (more info ...)attempted-user  2012-3755  56438    URL
25466FILE-PDF Adobe Acrobat Reader structtreeroot children recursive call denial of service attempt (more info ...)denial-of-service  2013-0626      URL
25467FILE-PDF Adobe Acrobat Reader structtreeroot children recursive call denial of service attempt (more info ...)denial-of-service  2013-0626      URL
25468FILE-PDF Adobe Acrobat Reader structtreeroot children recursive call denial of service attempt (more info ...)denial-of-service  2013-0626      URL
25469FILE-PDF Adobe Acrobat Reader structtreeroot children recursive call denial of service attempt (more info ...)denial-of-service  2013-0626      URL
25536FILE-PDF Adobe Acrobat Reader TTF parsing bad cmap format attempt (more info ...)attempted-user  2013-0623      URL
25537FILE-PDF Adobe Acrobat Reader TTF parsing bad cmap format attempt (more info ...)attempted-user  2013-0623      URL
25563FILE-PDF Adobe Acrobat Reader heap-based buffer overflow attempt (more info ...)attempted-user  2013-0603  57282    URL
25564FILE-PDF Adobe Acrobat Reader heap-based buffer overflow attempt (more info ...)attempted-user  2013-0603  57282    URL
25644FILE-OTHER Apple QuickTime TeXML style sub-element buffer overflow attempt (more info ...)attempted-user  2012-3758  56557    URL
25645FILE-OTHER Apple QuickTime TeXML style sub-element buffer overflow attempt (more info ...)attempted-user  2012-3752  56557    URL
25646FILE-OTHER Apple QuickTime TeXML style sub-element buffer overflow attempt (more info ...)attempted-user  2012-3752  56557    URL
25647FILE-OTHER Apple QuickTime TeXML style sub-element buffer overflow attempt (more info ...)attempted-user  2012-3752  56557    URL
25648FILE-OTHER Apple QuickTime TeXML style sub-element buffer overflow attempt (more info ...)attempted-user  2012-3758  56557    URL
25649FILE-OTHER Apple QuickTime TeXML style sub-element buffer overflow attempt (more info ...)attempted-user  2012-3752  56557    URL
25676FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
25677FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
25678FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
25679FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
25680FILE-IDENTIFY Adobe Flash Player embedded compact font detected (more info ...)misc-activity        URL
25681FILE-FLASH Adobe Flash Player CFF FeatureCount integer overflow attempt (more info ...)attempted-user  2013-0633      URL
25682FILE-IDENTIFY Adobe Flash Player embedded compact font detected (more info ...)misc-activity        URL
25683FILE-FLASH Adobe Flash Player CFF FeatureCount integer overflow attempt (more info ...)attempted-user  2013-0633      URL
25815FILE-FLASH Adobe Flash Player FLV crafted ADPCM stream heap overflow attempt (more info ...)attempted-user  2013-0638  57907    URL
25816FILE-FLASH Adobe Flash Player FLV crafted ADPCM stream heap overflow attempt (more info ...)attempted-user  2013-0638  57907    URL
25818FILE-PDF Adobe Acrobat Reader known malicious variable exploit attempt (more info ...)attempted-admin  2013-0641      URL
25819FILE-PDF Adobe Acrobat Reader known malicious variable exploit attempt (more info ...)attempted-admin  2013-0641      URL
25835FILE-FLASH Adobe Flash Player ActionScript 3 integer overflow attempt (more info ...)attempted-user  2011-2416  49081    URL
25976POLICY-OTHER Adobe ColdFusion admin API access attempt (more info ...)policy-violation  2013-0632  57330    URL
25977POLICY-OTHER Adobe ColdFusion component browser access attempt (more info ...)policy-violation  2013-0632  57330    URL
26008FILE-FLASH Adobe Flash Player SWF-based shellcode download attempt (more info ...)attempted-user  2013-0648  58186    URL
26009FILE-FLASH Adobe Flash Player SWF-based shellcode download attempt (more info ...)attempted-user  2013-0648  58186    URL
26173FILE-FLASH Adobe Flash Player sortOn heap overflow attempt (more info ...)attempted-user  2013-0646      URL
26429FILE-FLASH Adobe Flash Player RTMP malformed onStatus message type confusion attempt (more info ...)attempted-user  2013-2555      URL
26430FILE-FLASH Adobe Flash Player RTMP malformed onStatus message type confusion attempt (more info ...)attempted-user  2013-2555      URL
26651FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
26652FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
26687FILE-FLASH Adobe Flash Player malformed HTML text null dereference attempt (more info ...)attempted-user  2013-3329      URL
26688FILE-FLASH Adobe Flash Player malformed HTML text null dereference attempt (more info ...)attempted-user  2013-3329      URL
26892EXPLOIT-KIT Flashpack/Safe/CritX exploit kit jar file download (more info ...)trojan-activity        URL
26893EXPLOIT-KIT Flashpack/Safe/CritX exploit kit landing page (more info ...)trojan-activity        URL
26896EXPLOIT-KIT Flashpack/Safe/CritX exploit kit Plugin detection response (more info ...)trojan-activity        URL
26897EXPLOIT-KIT Flashpack/Safe/CritX exploit kit malware download (more info ...)trojan-activity        URL
26927FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
26928FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
26982FILE-FLASH Adobe Flash Player remote memory corruption attempt (more info ...)attempted-user  2013-3343  60478    URL
26983FILE-FLASH Adobe Flash Player remote memory corruption attempt (more info ...)attempted-user  2013-3343  60478    URL
27082EXPLOIT-KIT Nailed exploit kit flash remote code execution exploit download - autopwn (more info ...)trojan-activity  2012-1535      URL
27102FILE-MULTIMEDIA Apple QuickTime enof atom parsing heap buffer overflow attempt (more info ...)attempted-user  2013-0986  60099    URL
27103FILE-MULTIMEDIA Apple QuickTime enof atom parsing heap buffer overflow attempt (more info ...)attempted-user  2013-0986  60099    URL
27224SERVER-OTHER Adobe ColdFusion websocket invoke method access (more info ...)policy-violation  2013-3350  61042    URL
27265FILE-FLASH Adobe Flash Player heap buffer overflow attempt (more info ...)attempted-user  2013-3345  61045    URL
27266FILE-FLASH Adobe Flash Player heap buffer overflow attempt (more info ...)attempted-user  2013-3345  61045    URL
27267FILE-FLASH Adobe Flash Player ActionScript user-supplied PCM resampling integer overflow attempt (more info ...)attempted-user  2013-3347  61048    URL
27268FILE-FLASH Adobe Flash Player ActionScript user-supplied PCM resampling integer overflow attempt (more info ...)attempted-user  2013-3347  61048    URL
27594MALWARE-OTHER Fake Adobe Flash Player update warning enticing clicks to malware payload (more info ...)trojan-activity        
27595MALWARE-OTHER Fake Adobe Flash Player malware binary requested (more info ...)trojan-activity        
27754FILE-FLASH Adobe Flash Player Action InitArray stack overflow attempt (more info ...)attempted-user  2012-5269      URL
27755FILE-FLASH Adobe Flash Player Action InitArray stack overflow attempt (more info ...)attempted-user  2012-5269      URL
27879EXPLOIT-KIT Teletubbies exploit kit exploit attempt for Adobe Acrobat Reader 8 (more info ...)trojan-activity  2010-0188      URL
27880EXPLOIT-KIT Teletubbies exploit kit exploit attempt for Adobe Acrobat Reader 9 (more info ...)trojan-activity  2010-0188      URL
27881EXPLOIT-KIT Teletubbies exploit kit exploit attempt for Adobe Flash Player (more info ...)trojan-activity  2010-1297      URL
27882EXPLOIT-KIT Teletubbies exploit kit exploit attempt for Adobe Flash Player (more info ...)trojan-activity  2010-2884      URL
27892EXPLOIT-KIT Teletubbies exploit kit exploit attempt for Adobe Acrobat Reader (more info ...)trojan-activity  2008-2992      URL
28108EXPLOIT-KIT Nuclear/Magnitude exploit kit Adobe Flash exploit download attempt (more info ...)trojan-activity  2013-0431      
28202FILE-OTHER ATMFD Adobe font driver reserved command denial of service attempt (more info ...)denial-of-service  2013-3128      URL
28203FILE-OTHER ATMFD Adobe font driver reserved command denial of service attempt (more info ...)denial-of-service  2013-3128      URL
28252FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
28308EXPLOIT-KIT Himan exploit kit payload - Adobe Reader compromise (more info ...)trojan-activity  2010-0188      URL
28361FILE-PDF Adobe Acrobat Reader malformed shading modifier heap corruption attempt (more info ...)attempted-user  2015-3070      URL
28374FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28375FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28376FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28377FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28378FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28379FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28380FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883      URL
28534FILE-OTHER Apple Quicktime TeXML description attribute overflow attempt (more info ...)attempted-user  2013-1015  60110    URL
28535FILE-OTHER Apple Quicktime TeXML description attribute overflow attempt (more info ...)attempted-user  2013-1015  60110    URL
28536FILE-OTHER Apple Quicktime TeXML description attribute overflow attempt (more info ...)attempted-user  2013-1015  60110    URL
28537FILE-OTHER Apple Quicktime TeXML description attribute overflow attempt (more info ...)attempted-user  2013-1015  60110    URL
28567FILE-FLASH Adobe Flash Player use after free race condition (more info ...)attempted-user  2013-3361      URL
28568FILE-FLASH Adobe Flash Player remote memory corruption attempt (more info ...)attempted-user  2013-3362  62294    URL
28569FILE-FLASH Adobe Flash Player remote memory corruption attempt (more info ...)attempted-user  2013-3362  62294    URL
28575FILE-OTHER Adobe Acrobat Reader FDF submitForm cross-site scripting attempt (more info ...)misc-attack  2013-5325  62888    URL
28576FILE-OTHER Adobe Acrobat Reader FDF submitForm cross-site scripting attempt (more info ...)misc-attack  2013-5325  62888    URL
28577FILE-PDF Adobe Acrobat Reader memory disclosure attempt (more info ...)attempted-user  2013-3356  62436    URL
28578FILE-PDF Adobe Acrobat Reader memory disclosure attempt (more info ...)attempted-user  2013-3356  62436    URL
28585FILE-PDF Adobe Acrobat Reader OTF font head table size overflow attempt (more info ...)attempted-user  2013-3353      URL
28586FILE-PDF Adobe Acrobat Reader OTF font head table size overflow attempt (more info ...)attempted-user  2013-3353      URL
28587FILE-FLASH Adobe Flash Player GlyphOffset memory disclosure attempt (more info ...)attempted-user  2013-5324      URL
28588FILE-FLASH Adobe Flash Player GlyphOffset memory disclosure attempt (more info ...)attempted-user  2013-5324      URL
28589FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2013-3363      URL
28590FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2013-3363      URL
28591FILE-PDF Adobe Acrobat Reader TTF remote code execution attempt (more info ...)attempted-user  2013-3354      URL
28592FILE-PDF Adobe Acrobat Reader TTF remote code execution attempt (more info ...)attempted-user  2013-3354      URL
28597FILE-PDF Adobe Acrobat and Adobe Acrobat Reader field dictionary null pointer dereference attempt (more info ...)attempted-user  2013-3355      URL
28598FILE-PDF Adobe Acrobat and Adobe Acrobat Reader field dictionary null pointer dereference attempt (more info ...)attempted-user  2013-3355      URL
28600FILE-PDF Adobe Acrobat Reader badly formatted type 0 font attempt (more info ...)attempted-user  2013-3357      URL
28601FILE-PDF Adobe Acrobat Reader badly formatted type 0 font attempt (more info ...)attempted-user  2013-3357      URL
28602FILE-PDF Adobe Acrobat Reader badly formatted type 0 font attempt (more info ...)attempted-user  2013-3357      URL
28603FILE-PDF Adobe Acrobat Reader badly formatted type 0 font attempt (more info ...)attempted-user  2013-3357      URL
28619FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
28620FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
28621FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
28644FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28645FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28646FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28647FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28648FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28649FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28650FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28651FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28652FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28653FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28654FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28655FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28656FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28657FILE-PDF Adobe Acrobat Reader TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
28659FILE-PDF Adobe Acrobat Reader known malicious variable exploit attempt (more info ...)attempted-admin  2013-0641      URL
28687FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
28688FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
28689FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
28690FILE-FLASH Adobe Flash Player ActionScript virtual machine opcode verifying code execution attempt (more info ...)attempted-user  2012-5271      URL
28695FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt (more info ...)attempted-user  2011-0611  47314    URL
28696FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt (more info ...)attempted-user  2011-0611  47314    URL
28697FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt (more info ...)attempted-user  2011-0611  47314    URL
28698FILE-FLASH Adobe Flash Player ActionScript callMethod type confusion attempt (more info ...)attempted-user  2011-0611  47314    URL
28699FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
28701FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
28702FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
28703FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption attempt (more info ...)attempted-user  2011-2110      URL
28704FILE-FLASH Adobe Flash Player ActionScript float index array memory corruption attempt (more info ...)attempted-user  2011-2110      URL
28705FILE-FLASH Adobe Flash OpenType font memory corruption attempt (more info ...)attempted-user  2012-1535  55009    URL
28706FILE-FLASH Adobe Flash OpenType font memory corruption attempt (more info ...)attempted-user  2012-1535  55009    URL
28707FILE-FLASH Adobe Flash OpenType font memory corruption attempt (more info ...)attempted-user  2012-1535  55009    URL
28708FILE-FLASH Adobe Flash OpenType font memory corruption attempt (more info ...)attempted-user  2012-1535  55009    URL
28710FILE-PDF Adobe Acrobat Reader embedded TTF integer overflow attempt (more info ...)attempted-user  2012-0774      URL
28711FILE-PDF Adobe Acrobat Reader embedded TTF integer overflow attempt (more info ...)attempted-user  2012-0774      URL
28712FILE-PDF Adobe Acrobat Reader embedded TTF integer overflow attempt (more info ...)attempted-user  2012-0774      URL
28713FILE-PDF Adobe Acrobat Reader embedded TTF integer overflow attempt (more info ...)attempted-user  2012-0774      URL
28714FILE-PDF Adobe Acrobat Reader embedded TTF integer overflow attempt (more info ...)attempted-user  2012-0774      URL
28715FILE-PDF Adobe Acrobat Reader embedded TTF integer overflow attempt (more info ...)attempted-user  2012-0774      URL
28744FILE-FLASH Adobe Flash Player Matrix3D copyRawDataTo integer overflow attempt (more info ...)attempted-user  2012-5054  55691    URL
28745FILE-FLASH Adobe Flash Player Matrix3D copyRawDataTo integer overflow attempt (more info ...)attempted-user  2012-5054  55691    URL
28791FILE-FLASH Adobe Flash Player loadPCMFromByteArray bad sample count attempt (more info ...)attempted-user  2012-5677      
28792FILE-FLASH Adobe Flash Player loadPCMFromByteArray bad sample count attempt (more info ...)attempted-user  2012-5677      
28793FILE-FLASH Adobe Flash Player loadPCMFromByteArray bad sample count attempt (more info ...)attempted-user  2012-5677      
28887FILE-PDF Adobe Acrobat Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188  38195    
28888FILE-PDF Adobe Acrobat Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188  38195    
28889FILE-PDF Adobe Acrobat Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188  38195    
28890FILE-PDF Adobe Acrobat Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188  38195    
28963EXPLOIT-KIT HiMan exploit kit Flash Exploit landing page (more info ...)trojan-activity        
28968EXPLOIT-KIT HiMan exploit kit outbound flash exploit retrieval attempt (more info ...)trojan-activity        
29047FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
29048FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
29049FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
29050FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
29051FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
29052FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
29053FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
29054FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
29061FILE-MULTIMEDIA Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2013-5332  64201    URL
29062FILE-PDF Adobe Acrobat Reader malformed JBIG2 decode segment null pointer crash attempt (more info ...)attempted-user  2013-3352  62431    URL
29063FILE-PDF Adobe Acrobat Reader malformed JBIG2 decode segment null pointer crash attempt (more info ...)attempted-user  2013-3352  62431    URL
29164EXPLOIT-KIT CritX exploit kit outbound flash request (more info ...)trojan-activity        
29182FILE-OTHER RealNetworks RealPlayer RMP stack buffer overflow attempt (more info ...)attempted-admin  2013-6877  64398    
29183FILE-OTHER RealNetworks RealPlayer RMP stack buffer overflow attempt (more info ...)attempted-admin  2013-6877  64398    
29184FILE-OTHER RealNetworks RealPlayer RMP stack buffer overflow attempt (more info ...)attempted-admin  2013-6877  64398    
29185FILE-OTHER RealNetworks RealPlayer RMP stack buffer overflow attempt (more info ...)attempted-admin  2013-6877  64398    
29210FILE-OTHER RealNetworks RealPlayer RMP file heap buffer overflow attempt (more info ...)attempted-admin  2013-6877  64398    
29211FILE-OTHER RealNetworks RealPlayer RMP file heap buffer overflow attempt (more info ...)attempted-admin  2013-6877  64398    
29281FILE-FLASH Adobe Flash Player sharable ByteArray code execution attempt (more info ...)attempted-user  2013-5329      
29282FILE-FLASH Adobe Flash Player sharable ByteArray code execution attempt (more info ...)attempted-user  2013-5329      
29283FILE-FLASH Adobe Flash Player sharable ByteArray code execution attempt (more info ...)attempted-user  2013-5329      
29284FILE-FLASH Adobe Flash Player sharable ByteArray code execution attempt (more info ...)attempted-user  2013-5329      
29285FILE-FLASH Adobe Flash Player sharable ByteArray code execution attempt (more info ...)attempted-user  2013-5329      
29286FILE-FLASH Adobe Flash Player sharable ByteArray code execution attempt (more info ...)attempted-user  2013-5329      
29287FILE-FLASH Adobe Flash Player sharable ByteArray code execution attempt (more info ...)attempted-user  2013-5329      
29288FILE-FLASH Adobe Flash Player sharable ByteArray code execution attempt (more info ...)attempted-user  2013-5329      
29384FILE-IDENTIFY Adobe AIR file download request (more info ...)misc-activity        
29385FILE-IDENTIFY Adobe AIR file attachment detected (more info ...)misc-activity        
29386FILE-IDENTIFY Adobe AIR file attachment detected (more info ...)misc-activity        
29520FILE-MULTIMEDIA Flip4Mac Windows media components WMV parsing memory corruption attempt (more info ...)attempted-user  2007-0466  22286    URL
29521FILE-MULTIMEDIA Flip4Mac Windows media components WMV parsing memory corruption attempt (more info ...)attempted-user  2007-0466  22286    URL
29524FILE-FLASH Adobe Flash Player loadPCMFromByteArray bad sample count attempt (more info ...)attempted-user  2012-5677      
29525FILE-FLASH Adobe Flash Player loadPCMFromByteArray bad sample count attempt (more info ...)attempted-user  2012-5677      
29551FILE-FLASH Adobe Flash Player invalid instruction memory corruption attempt (more info ...)attempted-user  2013-5330      URL
29552FILE-FLASH Adobe Flash Player invalid instruction memory corruption attempt (more info ...)attempted-user  2013-5330      URL
29553FILE-FLASH Adobe Flash Player invalid instruction memory corruption attempt (more info ...)attempted-user  2013-5330      URL
29554FILE-FLASH Adobe Flash Player invalid instruction memory corruption attempt (more info ...)attempted-user  2013-5330      URL
29631FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
29632FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
29633FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
29634FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
29835FILE-FLASH Adobe Flash Player ActionScript bytecode object type confusion information disclosure attempt (more info ...)attempted-recon  2014-0492      URL
29836FILE-FLASH Adobe Flash Player ActionScript bytecode object type confusion information disclosure attempt (more info ...)attempted-recon  2014-0492      URL
29902FILE-PDF Adobe Acrobat Reader invalid JPEG stream double free attempt (more info ...)attempted-user  2014-0493  64802    URL
29903FILE-PDF Adobe Acrobat Reader invalid JPEG stream double free attempt (more info ...)attempted-user  2014-0493  64802    URL
29904FILE-PDF Adobe Acrobat Reader invalid JPEG stream double free attempt (more info ...)attempted-user  2014-0493  64802    URL
29905FILE-PDF Adobe Acrobat Reader invalid JPEG stream double free attempt (more info ...)attempted-user  2014-0493  64802    URL
29926FILE-FLASH Adobe Flash Player buffer overflow attempt (more info ...)attempted-user  2014-0498      URL
29927FILE-FLASH Adobe Flash Player buffer overflow attempt (more info ...)attempted-user  2014-0498      URL
29928FILE-FLASH Adobe Flash Player worker shared object use-after-free attempt (more info ...)attempted-user  2014-0502      URL
29929FILE-FLASH Adobe Flash Player worker shared object use-after-free attempt (more info ...)attempted-user  2014-0502      URL
29930FILE-FLASH Adobe Flash Player worker shared object use-after-free attempt (more info ...)attempted-user  2014-0502      URL
29931FILE-FLASH Adobe Flash Player worker shared object use-after-free attempt (more info ...)attempted-user  2014-0502      URL
30150FILE-MULTIMEDIA Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2013-5332  64201    URL
30151FILE-MULTIMEDIA Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2013-5332  64201    URL
30152FILE-MULTIMEDIA Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2013-5332  64201    URL
30240FILE-OTHER ATMFD Adobe font driver reserved command denial of service attempt (more info ...)denial-of-service  2013-3128      URL
30241FILE-OTHER ATMFD Adobe font driver reserved command denial of service attempt (more info ...)denial-of-service  2013-3128      URL
30535FILE-FLASH Adobe Flash Player malformed HTML text null dereference attempt (more info ...)attempted-user  2014-0506  66208    URL
30536FILE-FLASH Adobe Flash Player malformed HTML text null dereference attempt (more info ...)attempted-user  2014-0506  66208    URL
30537FILE-FLASH Adobe Flash Player malformed HTML text null dereference attempt (more info ...)attempted-user  2014-0506  66208    URL
30538FILE-FLASH Adobe Flash Player malformed HTML text null dereference attempt (more info ...)attempted-user  2014-0506  66208    URL
30564FILE-MULTIMEDIA Apple QuickTime long rnet atom size buffer overflow attempt (more info ...)attempted-user  2012-3756  56438    
30565FILE-MULTIMEDIA Apple QuickTime long rnet atom size buffer overflow attempt (more info ...)attempted-user  2012-3756  56438    
30754FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
30755FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user  2013-0634  57787    URL
30845FILE-FLASH Adobe Flash Player SWF ActionScript exploit attempt (more info ...)attempted-user  2014-0507      URL
30846FILE-FLASH Adobe Flash Player SWF ActionScript exploit attempt (more info ...)attempted-user  2014-0507      URL
30876FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
30877FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
30901FILE-FLASH known malicious flash actionscript decryption routine (more info ...)attempted-user  2014-1776      URL
30967EXPLOIT-KIT CritX exploit kit landing page - redirection to Adobe Flash exploit (more info ...)trojan-activity        
30970EXPLOIT-KIT CritX exploit kit outbound request for Adobe Flash landing page (more info ...)trojan-activity        
30976EXPLOIT-KIT CritX exploit kit landing page - redirection to Adobe Flash exploit (more info ...)trojan-activity        
31008FILE-PDF Adobe Acrobat Reader length-compute UTF-16 string buffer overflow attempt (more info ...)attempted-user  2014-0524  67369    URL
31009FILE-PDF Adobe Acrobat Reader length-compute UTF-16 string buffer overflow attempt (more info ...)attempted-user  2014-0524  67369    URL
31011FILE-PDF Adobe Acrobat Reader DCT encoded stream null pointer dereference attempt (more info ...)attempted-user  2014-0526      URL
31012FILE-PDF Adobe Acrobat Reader DCT encoded stream null pointer dereference attempt (more info ...)attempted-user  2014-0526      URL
31015FILE-PDF Adobe Acrobat Reader integer overflow attempt (more info ...)attempted-user  2014-0512  66512    URL
31016FILE-PDF Adobe Acrobat Reader integer overflow attempt (more info ...)attempted-user  2014-0512  66512    URL
31021FILE-PDF Adobe Acrobat Reader api call handling arbitrary execution attempt (more info ...)attempted-user  2014-0525  67365    URL
31022FILE-PDF Adobe Acrobat Reader api call handling arbitrary execution attempt (more info ...)attempted-user  2014-0525  67365    URL
31023FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2014-0510      URL
31024FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2014-0510      URL
31025FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2014-0510      URL
31026FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2014-0510      URL
31029FILE-OTHER Adobe Acrobat EMF conversion heap buffer overflow attempt (more info ...)attempted-user  2018-16021  67632    URL
31030FILE-OTHER Adobe Acrobat EMF conversion heap buffer overflow attempt (more info ...)attempted-user  2018-16021  67632    URL
31103FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
31104FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
31105FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
31106FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
31229EXPLOIT-KIT Bleeding Life exploit kit outbound Adobe Flash exploit request (more info ...)trojan-activity        
31276EXPLOIT-KIT CottonCastle exploit kit Adobe flash outbound connection (more info ...)trojan-activity  2014-0515      URL
31347FILE-FLASH Adobe AS3 pcre assertion out of bounds corruption attempt (more info ...)attempted-user  2014-0536      URL
31348FILE-FLASH Adobe AS3 pcre assertion out of bounds corruption attempt (more info ...)attempted-user  2014-0536      URL
31349FILE-FLASH Adobe AS3 simplified pcre assertion out of bounds corruption attempt (more info ...)attempted-user  2014-0536      URL
31350FILE-FLASH Adobe AS3 simplified pcre assertion out of bounds corruption attempt (more info ...)attempted-user  2014-0536      URL
31351FILE-FLASH Adobe AS3 decompressed pcre assertion out of bounds corruption attempt (more info ...)attempted-user  2014-0536      URL
31352FILE-FLASH Adobe AS3 decompressed pcre assertion out of bounds corruption attempt (more info ...)attempted-user  2014-0536      URL
31353FILE-FLASH Adobe AS3 decompressed pcre assertion out of bounds corruption attempt (more info ...)attempted-user  2014-0536      URL
31354FILE-FLASH Adobe AS3 decompressed pcre assertion out of bounds corruption attempt (more info ...)attempted-user  2014-0536      URL
31408BROWSER-PLUGINS Adobe Reader 11 messageHandler ActiveX access attempt (more info ...)attempted-user  2014-0527      URL
31410BROWSER-PLUGINS Adobe Reader 11 messageHandler ActiveX access attempt (more info ...)attempted-user  2014-0527      URL
31519FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
31520FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
31521FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
31522FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
31523FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
31524FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
31555FILE-PDF Adobe Acrobat Reader U3D CLODMeshDeceleration code execution attempt (more info ...)attempted-user  2014-0523  67368    URL
31612FILE-PDF Adobe Acrobat Reader embedded PRC stream NULL dereference denial of service attempt (more info ...)attempted-dos  2014-0522  67360    URL
31613FILE-PDF Adobe Acrobat Reader embedded PRC stream NULL dereference denial of service attempt (more info ...)attempted-dos  2014-0522  67360    URL
31678FILE-FLASH Adobe Flash valueOf memory leak attempt (more info ...)attempted-recon  2014-0540      URL
31679FILE-FLASH Adobe Flash valueOf memory leak attempt (more info ...)attempted-recon  2014-0540      URL
31686FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
31687FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
31723FILE-FLASH Adobe Flash Player memory leak ASLR bypass attempt (more info ...)policy-violation  2014-0544      URL
31724FILE-FLASH Adobe Flash Player memory leak ASLR bypass attempt (more info ...)policy-violation  2014-0544      URL
31725FILE-FLASH Adobe Flash Player memory leak ASLR bypass attempt (more info ...)policy-violation  2014-0544      URL
31726FILE-FLASH Adobe Flash Player memory leak ASLR bypass attempt (more info ...)policy-violation  2014-0544      URL
31732FILE-FLASH Adobe Flash Player MMgc use-after-free attempt (more info ...)attempted-user  2014-0538      URL
31733FILE-FLASH Adobe Flash Player MMgc use-after-free attempt (more info ...)attempted-user  2014-0538      URL
31740FILE-FLASH Adobe Flash Player corrupt image memory leak (more info ...)attempted-user  2014-0545  69197    URL
31839FILE-FLASH Adobe Flash Player local-with-file-access security bypass attempt (more info ...)attempted-user  2014-0554      URL
31840FILE-FLASH Adobe Flash Player local-with-file-access security bypass attempt (more info ...)attempted-user  2014-0554      URL
31841FILE-FLASH Adobe Flash Player local-with-file-access security bypass attempt (more info ...)attempted-user  2014-0554      URL
31842FILE-FLASH Adobe Flash Player local-with-file-access security bypass attempt (more info ...)attempted-user  2014-0554      URL
31847FILE-FLASH Adobe Flash Player RegExp compilation heap overflow attempt (more info ...)attempted-user  2014-0559      URL
31848FILE-FLASH Adobe Flash Player RegExp compilation heap overflow attempt (more info ...)attempted-user  2014-0559      URL
31849FILE-FLASH Adobe Flash Player RegExp compilation heap overflow attempt (more info ...)attempted-user  2014-0559      URL
31850FILE-FLASH Adobe Flash Player RegExp compilation heap overflow attempt (more info ...)attempted-user  2014-0559      URL
31899EXPLOIT-KIT Angler exploit kit Adobe Flash encoded shellcode detected (more info ...)trojan-activity        
31902EXPLOIT-KIT Multiple exploit kit flash file download (more info ...)trojan-activity        
31903EXPLOIT-KIT Multiple exploit kit flash file download (more info ...)trojan-activity        
32021FILE-PDF Adobe Acrobat Reader U3D format Line Set Continuation out-of-bounds memory access attempt (more info ...)attempted-user  2014-0565      URL
32022FILE-PDF Adobe Acrobat Reader U3D format Line Set Continuation out-of-bounds memory access attempt (more info ...)attempted-user  2014-0565      URL
32024FILE-FLASH Adobe Flash Player unsupported bitmapFormat value memory disclosure attempt (more info ...)attempted-user  2014-0543  69195    URL
32025FILE-FLASH Adobe Flash Player unsupported bitmapFormat value memory disclosure attempt (more info ...)attempted-user  2014-0543  69195    URL
32077FILE-FLASH Adobe Flash Player RTMP ping abort message double free attempt (more info ...)attempted-user  2014-0551      URL
32097FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
32098FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
32170FILE-PDF Adobe Acrobat Reader string replacement heap overflow attempt (more info ...)attempted-user  2014-0567  69827    URL
32171FILE-PDF Adobe Acrobat Reader string replacement heap overflow attempt (more info ...)attempted-user  2014-0567  69827    URL
32226FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
32227FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
32228FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
32229FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
32236FILE-FLASH Adobe Flash Player string concatenation memory corruption attempt (more info ...)attempted-user  2014-0558      URL
32237FILE-FLASH Adobe Flash Player string concatenation memory corruption attempt (more info ...)attempted-user  2014-0558      URL
32238FILE-FLASH Adobe Flash Player string concatenation memory corruption attempt (more info ...)attempted-user  2014-0558      URL
32239FILE-FLASH Adobe Flash Player string concatenation memory corruption attempt (more info ...)attempted-user  2014-0558      URL
32301FILE-FLASH Adobe Flash Player regex denial of service attempt (more info ...)attempted-dos  2014-0564      URL
32302FILE-FLASH Adobe Flash Player regex denial of service attempt (more info ...)attempted-dos  2014-0564      URL
32303FILE-FLASH Adobe Flash Player regex denial of service attempt (more info ...)attempted-dos  2014-0564      URL
32304FILE-FLASH Adobe Flash Player regex denial of service attempt (more info ...)attempted-dos  2014-0564      URL
32305FILE-FLASH Adobe Flash Player regex denial of service attempt (more info ...)attempted-dos  2014-0564      URL
32306FILE-FLASH Adobe Flash Player regex denial of service attempt (more info ...)attempted-dos  2014-0564      URL
32307FILE-FLASH Adobe Flash Player regex denial of service attempt (more info ...)attempted-dos  2014-0564      URL
32308FILE-FLASH Adobe Flash Player regex denial of service attempt (more info ...)attempted-dos  2014-0564      URL
32337FILE-PDF Adobe Acrobat Reader pattern object memory corruption attempt (more info ...)attempted-user  2014-0495  64803    URL
32359FILE-FLASH Adobe Flash Player worker shared object use-after-free attempt (more info ...)attempted-user  2014-0502      URL
32360FILE-FLASH Adobe Flash Player worker shared object use-after-free attempt (more info ...)attempted-user  2014-0502      URL
32534FILE-FLASH Adobe Flash Player AS3 regular expression grouping depth denial of service attempt (more info ...)attempted-dos  2014-0581      URL
32535FILE-FLASH Adobe Flash Player AS3 regular expression grouping depth denial of service attempt (more info ...)attempted-dos  2014-0581      URL
32536FILE-FLASH Adobe Flash Player AS3 regular expression grouping depth denial of service attempt (more info ...)attempted-dos  2014-0581      URL
32537FILE-FLASH Adobe Flash Player AS3 regular expression grouping depth denial of service attempt (more info ...)attempted-dos  2014-0581      URL
32538FILE-FLASH Adobe Flash Player AS3 regular expression grouping depth denial of service attempt (more info ...)attempted-dos  2014-0581      URL
32539FILE-FLASH Adobe Flash Player AS3 regular expression grouping depth denial of service attempt (more info ...)attempted-dos  2014-0581      URL
32540FILE-FLASH Adobe Flash Player decompressed microphone object codec denial of service attempt (more info ...)attempted-dos  2014-0577  71038    
32541FILE-FLASH Adobe Flash Player decompressed microphone object codec denial of service attempt (more info ...)attempted-dos  2014-0577  71038    
32542FILE-FLASH Adobe Flash Player compressed microphone object codec denial of service attempt (more info ...)attempted-dos  2014-0577  71038    
32543FILE-FLASH Adobe Flash Player compressed microphone object codec denial of service attempt (more info ...)attempted-dos  2014-0577  71038    
32544FILE-FLASH Adobe Flash Player HTML focus with no data denial of service attempt (more info ...)attempted-dos  2014-8441      URL
32545FILE-FLASH Adobe Flash Player HTML focus with no data denial of service attempt (more info ...)attempted-dos  2014-8441      URL
32552FILE-FLASH Adobe Flash Player incorrect codec denial of service attempt (more info ...)denial-of-service  2014-0576      URL
32553FILE-FLASH Adobe Flash Player incorrect codec denial of service attempt (more info ...)denial-of-service  2014-0576      URL
32558FILE-FLASH Adobe Flash Player setglobalslot malformed bytecode remote code execution attempt (more info ...)attempted-user  2014-0584      URL
32559FILE-FLASH Adobe Flash Player setglobalslot malformed bytecode remote code execution attempt (more info ...)attempted-user  2014-0584      URL
32560FILE-FLASH Adobe Flash Player setglobalslot malformed bytecode remote code execution attempt (more info ...)attempted-user  2014-0584      URL
32561FILE-FLASH Adobe Flash Player setglobalslot malformed bytecode remote code execution attempt (more info ...)attempted-user  2014-0584      URL
32567FILE-FLASH Adobe Flash Player malformed ATF header integer overflow attempt (more info ...)attempted-user  2014-0555      URL
32568FILE-FLASH Adobe Flash Player malformed ATF header integer overflow attempt (more info ...)attempted-user  2014-0555      URL
32569FILE-FLASH Adobe Flash Player malformed ATF header integer overflow attempt (more info ...)attempted-user  2014-0555      URL
32570FILE-FLASH Adobe Flash Player malformed ATF header integer overflow attempt (more info ...)attempted-user  2014-0555      URL
32571FILE-FLASH Adobe Flash Player string concatenation integer overflow attempt (more info ...)attempted-user  2014-0550  69700    URL
32572FILE-FLASH Adobe Flash Player string concatenation integer overflow attempt (more info ...)attempted-user  2014-0550  69700    URL
32573FILE-FLASH Adobe Flash Player string concatenation integer overflow attempt (more info ...)attempted-user  2014-0550  69700    URL
32574FILE-FLASH Adobe Flash Player string concatenation integer overflow attempt (more info ...)attempted-user  2014-0550  69700    URL
32575FILE-FLASH Adobe Flash Player string concatenation integer overflow attempt (more info ...)attempted-user  2014-0550  69700    URL
32576FILE-FLASH Adobe Flash Player string concatenation integer overflow attempt (more info ...)attempted-user  2014-0550  69700    URL
32592FILE-FLASH Adobe Flash Player malformed JPEG information leak attempt (more info ...)attempted-user  2014-0557  69701    
32593FILE-FLASH Adobe Flash Player malformed JPEG information leak attempt (more info ...)attempted-user  2014-0557  69701    
32668FILE-FLASH Adobe Flash Player byteArray.uncompress use after free attempt (more info ...)attempted-user  2014-0588  71048    URL
32669FILE-FLASH Adobe Flash Player byteArray.uncompress use after free attempt (more info ...)attempted-user  2014-0588  71048    URL
32749FILE-FLASH Adobe Flash Player malformed pushcode type confusion remote code execution attempt (more info ...)attempted-user  2014-0585  71044    URL
32750FILE-FLASH Adobe Flash Player malformed pushcode type confusion remote code execution attempt (more info ...)attempted-user  2014-0585  71044    URL
32751FILE-FLASH Adobe Flash Player malformed pushcode type confusion remote code execution attempt (more info ...)attempted-user  2014-0585  71044    URL
32752FILE-FLASH Adobe Flash Player malformed pushcode type confusion remote code execution attempt (more info ...)attempted-user  2014-0585  71044    URL
32764FILE-FLASH Adobe ActionScript malformed pushwith opcode attempt (more info ...)attempted-user  2014-0586      URL
32765FILE-FLASH Adobe ActionScript malformed pushwith opcode attempt (more info ...)attempted-user  2014-0586      URL
32766FILE-FLASH Adobe ActionScript malformed pushwith opcode attempt (more info ...)attempted-user  2014-0586      URL
32767FILE-FLASH Adobe ActionScript malformed pushwith opcode attempt (more info ...)attempted-user  2014-0586      URL
32782FILE-FLASH Adobe Flash Player parseFloat stack overflow remote code execution attempt (more info ...)attempted-user  2014-9163      URL
32783FILE-FLASH Adobe Flash Player parseFloat stack overflow remote code execution attempt (more info ...)attempted-user  2014-9163      URL
32784FILE-FLASH Adobe Flash Player parseFloat stack overflow remote code execution attempt (more info ...)attempted-user  2014-9163      URL
32785FILE-FLASH Adobe Flash Player parseFloat stack overflow remote code execution attempt (more info ...)attempted-user  2014-9163      URL
32786FILE-PDF Adobe Acrobat Reader PDF JBIG2 remote code execution attempt (more info ...)attempted-user  2009-0658  33751    
32793FILE-PDF Adobe Acrobat Reader XRef object integer overflow attempt (more info ...)attempted-user  2014-8449  71568    URL
32794FILE-PDF Adobe Acrobat Reader XRef object integer overflow attempt (more info ...)attempted-user  2014-8449  71568    URL
32795FILE-PDF Adobe Acrobat Reader U3D light resource orphaned array use after free attempt (more info ...)attempted-user  2014-8445      URL
32796FILE-PDF Adobe Acrobat Reader U3D light resource orphaned array use after free attempt (more info ...)attempted-user  2014-8445      URL
32801FILE-FLASH Adobe Flash Player orphaning MP3 crash attempt (more info ...)attempted-user  2014-8443      URL
32802FILE-FLASH Adobe Flash Player orphaning MP3 crash attempt (more info ...)attempted-user  2014-8443      URL
32813FILE-PDF Adobe Acrobat Reader malformed U3D object use after free attempt (more info ...)attempted-user  2014-9165      URL
32814FILE-PDF Adobe Acrobat Reader malformed U3D object use after free attempt (more info ...)attempted-user  2014-9165      URL
32815FILE-PDF Adobe Acrobat Reader raster image memory corruption attempt (more info ...)attempted-user  2014-9158      URL
32816FILE-PDF Adobe Acrobat Reader raster image memory corruption attempt (more info ...)attempted-user  2014-9158      URL
32819FILE-PDF Adobe Acrobat Reader JBIG2 row out of bounds memory corruption attempt (more info ...)attempted-user  2014-8446      URL
32820FILE-PDF Adobe Acrobat Reader JBIG2 row out of bounds memory corruption attempt (more info ...)attempted-user  2014-8446      URL
32834FILE-PDF Adobe Acrobat Reader embedded font type max subroutine buffer overflow attempt (more info ...)attempted-user  2014-8460      URL
32835FILE-PDF Adobe Acrobat Reader embedded font type max subroutine buffer overflow attempt (more info ...)attempted-user  2014-8460      URL
32836FILE-PDF Adobe Acrobat Reader embedded font type max subroutine buffer overflow attempt (more info ...)attempted-user  2014-8460      URL
32837FILE-PDF Adobe Acrobat Reader embedded font type max subroutine buffer overflow attempt (more info ...)attempted-user  2014-8460      URL
32856FILE-PDF Adobe Acrobat Reader graphics module crash attempt (more info ...)attempted-user  2014-8457  71566    URL
32873FILE-FLASH Adobe Flash Player ByteArray crash attempt (more info ...)attempted-user  2014-0574  71041    URL
32874FILE-FLASH Adobe Flash Player ByteArray crash attempt (more info ...)attempted-user  2014-0574  71041    URL
32877EXPLOIT-KIT Nuclear exploit kit outbound Adobe Flash exploit request (more info ...)trojan-activity        
32878EXPLOIT-KIT Nuclear exploit kit outbound Adobe Flash exploit request (more info ...)trojan-activity        
32995EXPLOIT-KIT Nuclear exploit kit Adobe Flash download (more info ...)trojan-activity        
33041FILE-MULTIMEDIA Apple iTunes Extended M3U playlist record overflow attempt (more info ...)attempted-user  2012-0677  53933    
33077FILE-FLASH Adobe Flash Player pre-compile regex length denial of service attempt (more info ...)attempted-dos  2015-0309      URL
33078FILE-FLASH Adobe Flash Player pre-compile regex length denial of service attempt (more info ...)attempted-dos  2015-0309      URL
33079FILE-FLASH Adobe Flash Player pre-compile regex length denial of service attempt (more info ...)attempted-dos  2015-0309      URL
33080FILE-FLASH Adobe Flash Player pre-compile regex length denial of service attempt (more info ...)attempted-dos  2015-0309      URL
33091FILE-FLASH Adobe Flash Player FlashUtil memory corruption attempt (more info ...)attempted-user  2015-0306      URL
33092FILE-FLASH Adobe Flash Player FlashUtil memory corruption attempt (more info ...)attempted-user  2015-0306      URL
33176FILE-FLASH Adobe Flash AWM2 out of bounds corruption attempt (more info ...)attempted-user  2014-0589      URL
33177FILE-FLASH Adobe Flash AWM2 out of bounds corruption attempt (more info ...)attempted-user  2014-0589      URL
33178FILE-FLASH Adobe Flash Player ActionScript out-of-bounds read attempt (more info ...)attempted-user  2015-0307      URL
33179FILE-FLASH Adobe Flash Player ActionScript out-of-bounds read attempt (more info ...)attempted-user  2015-0307      URL
33180FILE-FLASH Adobe Flash Player ActionScript out-of-bounds read attempt (more info ...)attempted-user  2015-0307      URL
33181FILE-FLASH Adobe Flash Player ActionScript out-of-bounds read attempt (more info ...)attempted-user  2015-0307      URL
33182EXPLOIT-KIT Angler exploit kit outbound Adobe Flash request (more info ...)trojan-activity        
33184EXPLOIT-KIT Angler exploit kit Adobe Flash download (more info ...)trojan-activity        
33186EXPLOIT-KIT Angler exploit kit Adobe Flash SWF exploit download (more info ...)trojan-activity        URL
33187EXPLOIT-KIT Angler exploit kit Adobe Flash SWF exploit download (more info ...)trojan-activity        URL
33201FILE-FLASH Adobe Flash Player class confusion memory corruption compressed file attempt (more info ...)attempted-user  2015-0305      URL
33202FILE-FLASH Adobe Flash Player class confusion memory corruption compressed file attempt (more info ...)attempted-user  2015-0305      URL
33203FILE-FLASH Adobe Flash Player class confusion memory corruption compressed file attempt (more info ...)attempted-user  2015-0305      URL
33204FILE-FLASH Adobe Flash Player class confusion memory corruption compressed file attempt (more info ...)attempted-user  2015-0305      URL
33261FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33262FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33263FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33264FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33265FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33266FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33267FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33268FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33269FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33270FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
33271EXPLOIT-KIT Angler exploit kit Adobe Flash SWF exploit download (more info ...)trojan-activity  2015-0311      
33272EXPLOIT-KIT Angler exploit kit Adobe Flash SWF exploit download (more info ...)trojan-activity  2015-0311      
33273EXPLOIT-KIT Angler exploit kit Adobe Flash SWF exploit download (more info ...)trojan-activity  2015-0311      
33274EXPLOIT-KIT Angler exploit kit Adobe Flash SWF exploit download (more info ...)trojan-activity  2015-0311      
33286EXPLOIT-KIT Angler exploit kit Adobe Flash SWF exploit download (more info ...)trojan-activity        URL
33290FILE-FLASH Adobe Flash Player stage object use-after-free attempt (more info ...)attempted-user  2015-0308      URL
33291FILE-FLASH Adobe Flash Player stage object use-after-free attempt (more info ...)attempted-user  2015-0308      URL
33300FILE-FLASH Adobe Flash Player AS3 regex sign-extension denial of service attempt (more info ...)denial-of-service  2015-0310      URL
33301FILE-FLASH Adobe Flash Player AS3 regex sign-extension denial of service attempt (more info ...)denial-of-service  2015-0310      URL
33302FILE-FLASH Adobe Flash Player AS3 regex sign-extension denial of service attempt (more info ...)denial-of-service  2015-0310      URL
33303FILE-FLASH Adobe Flash Player AS3 regex sign-extension denial of service attempt (more info ...)denial-of-service  2015-0310      URL
33367FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33368FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33369FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33370FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33371FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33372FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33373FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33374FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33375FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33376FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33377FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33378FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33379FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33380FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33381FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33382FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33383FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33384FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33385FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33386FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33387FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33388FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33389FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33390FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33391FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33392FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33393FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33394FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33395FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33396FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33397FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33398FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33399FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33400FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33401FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33402FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33403FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33404FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33405FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33406FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33407FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33408FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33409FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33410FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
33454FILE-OTHER Adobe Reader CoolType.DLL out-of-bounds memory access attempt (more info ...)attempted-user  2014-9161      URL
33455FILE-OTHER Adobe Reader CoolType.DLL out-of-bounds memory access attempt (more info ...)attempted-user  2014-9161      URL
33458FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
33459FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
33460FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
33461FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
33462FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
33463FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
33465FILE-FLASH Adobe Flash Player heap overflow using special characters with regex options attempt (more info ...)attempted-user  2015-0323      URL
33466FILE-FLASH Adobe Flash Player heap overflow using special characters with regex options attempt (more info ...)attempted-user  2015-0323      URL
33467FILE-FLASH Adobe Flash Player heap overflow using special characters with regex options attempt (more info ...)attempted-user  2015-0323      URL
33468FILE-FLASH Adobe Flash Player heap overflow using special characters with regex options attempt (more info ...)attempted-user  2015-0323      URL
33469FILE-FLASH Adobe Flash Player PCRE regex compilation memory corruption attempt (more info ...)attempted-user  2015-0329  72514    URL
33470FILE-FLASH Adobe Flash Player PCRE regex compilation memory corruption attempt (more info ...)attempted-user  2015-0329  72514    URL
33471FILE-FLASH Adobe Flash Player arbitrary code execution attempt (more info ...)attempted-user  2015-0329  72514    URL
33472FILE-FLASH Adobe Flash Player arbitrary code execution attempt (more info ...)attempted-user  2015-0329  72514    URL
33473FILE-MULTIMEDIA Adobe Flash Player MP4 malformed avc atom memory corruption attempt (more info ...)attempted-user  2015-0321      URL
33474FILE-MULTIMEDIA Adobe Flash Player MP4 malformed avc atom memory corruption attempt (more info ...)attempted-user  2015-0321      URL
33484FILE-FLASH Adobe Flash Player URLRequestHeaders null pointer dereference denial of service attempt (more info ...)attempted-dos  2015-0326  72514    URL
33485FILE-FLASH Adobe Flash Player URLRequestHeaders null pointer dereference denial of service attempt (more info ...)attempted-dos  2015-0326  72514    URL
33486FILE-FLASH Adobe Flash Player URLRequestHeaders null pointer dereference denial of service attempt (more info ...)attempted-dos  2015-0326  72514    URL
33487FILE-FLASH Adobe Flash Player URLRequestHeaders null pointer dereference denial of service attempt (more info ...)attempted-dos  2015-0326  72514    URL
33490FILE-FLASH Adobe Flash Player Ovector out of bounds stack corruption attempt (more info ...)attempted-user  2015-0330      URL
33491FILE-FLASH Adobe Flash Player Ovector out of bounds stack corruption attempt (more info ...)attempted-user  2015-0330      URL
33497FILE-FLASH Adobe Flash Player extended BitmapFilter class denial of service attempt (more info ...)attempted-dos  2015-0314  72514    URL
33498FILE-FLASH Adobe Flash Player extended BitmapFilter class denial of service attempt (more info ...)attempted-dos  2015-0314  72514    URL
33499FILE-FLASH Adobe Flash Player extended BitmapFilter class denial of service attempt (more info ...)attempted-dos  2015-0314  72514    URL
33500FILE-FLASH Adobe Flash Player extended BitmapFilter class denial of service attempt (more info ...)attempted-dos  2015-0314  72514    URL
33501FILE-FLASH Adobe Flash Player MessageChannel use after free attempt (more info ...)attempted-user  2015-0320  72514    URL
33502FILE-FLASH Adobe Flash Player MessageChannel use after free attempt (more info ...)attempted-user  2015-0320  72514    URL
33503FILE-FLASH Adobe Flash Player MessageChannel use after free attempt (more info ...)attempted-user  2015-0320  72514    URL
33504FILE-FLASH Adobe Flash Player MessageChannel use after free attempt (more info ...)attempted-user  2015-0320  72514    URL
33505FILE-FLASH Adobe Flash Player out of scope newclass memory corruption attempt (more info ...)attempted-user  2015-0322      URL
33506FILE-FLASH Adobe Flash Player out of scope newclass memory corruption attempt (more info ...)attempted-user  2015-0322      URL
33507FILE-FLASH Adobe Flash Player out of scope newclass memory corruption attempt (more info ...)attempted-user  2015-0322      URL
33508FILE-FLASH Adobe Flash Player out of scope newclass memory corruption attempt (more info ...)attempted-user  2015-0322      URL
33509FILE-FLASH Adobe Flash Player SWF buffer overflow attempt (more info ...)attempted-user  2015-0327      URL
33510FILE-FLASH Adobe Flash Player SWF buffer overflow attempt (more info ...)attempted-user  2015-0327      URL
33511FILE-FLASH Adobe Flash Player SWF buffer overflow attempt (more info ...)attempted-user  2015-0327      URL
33512FILE-FLASH Adobe Flash Player SWF buffer overflow attempt (more info ...)attempted-user  2015-0327      URL
33533FILE-FLASH Adobe Flash Player PCRE control character denial of service attempt (more info ...)denial-of-service  2015-0318      URL
33534FILE-FLASH Adobe Flash Player PCRE control character denial of service attempt (more info ...)denial-of-service  2015-0318      URL
33535FILE-FLASH Adobe Flash Player PCRE control character - possible denial of service attempt (more info ...)denial-of-service  2015-0318      URL
33536FILE-FLASH Adobe Flash Player PCRE control character denial of service attempt (more info ...)denial-of-service  2015-0318      URL
33537FILE-FLASH Adobe Flash Player PCRE control character - possible denial of service attempt (more info ...)denial-of-service  2015-0318      URL
33538FILE-FLASH Adobe Flash Player PCRE control character denial of service attempt (more info ...)denial-of-service  2015-0318      URL
33539FILE-FLASH Adobe Flash Player object type confusion attempt (more info ...)attempted-user  2015-3086      URL
33540FILE-FLASH Adobe Flash Player object type confusion attempt (more info ...)attempted-user  2015-3086      URL
33541FILE-FLASH Adobe Flash Player Compressed File object type confusion attempt (more info ...)attempted-user  2015-0319      URL
33542FILE-FLASH Adobe Flash Player Compressed File object type confusion attempt (more info ...)attempted-user  2015-0319      URL
33554FILE-FLASH Adobe Flash Player SWF use-after-free attempt (more info ...)attempted-user  2015-0315      URL
33555FILE-FLASH Adobe Flash Player SWF use-after-free attempt (more info ...)attempted-user  2015-0315      URL
33556FILE-FLASH Adobe Flash Player XMLsocket connect arbitrary code execution attempt (more info ...)attempted-user  2015-0317  72514    URL
33557FILE-FLASH Adobe Flash Player XMLsocket connect arbitrary code execution attempt (more info ...)attempted-user  2015-0317  72514    URL
33558FILE-FLASH Adobe Flash Player XMLsocket connect arbitrary code execution attempt (more info ...)attempted-user  2015-0317  72514    URL
33559FILE-FLASH Adobe Flash Player XMLsocket connect arbitrary code execution attempt (more info ...)attempted-user  2015-0317  72514    URL
33571FILE-OTHER Adobe Reader ETB baseurl memory corruption attempt (more info ...)attempted-user  2004-1153      
33572FILE-OTHER Adobe Reader ETB baseurl memory corruption attempt (more info ...)attempted-user  2004-1153      
33601FILE-PDF Adobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
33602FILE-PDF Adobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883  43057    URL
33684FILE-OTHER Microsoft Windows Media MIDI file memory corruption attempt (more info ...)attempted-user  2012-0003      URL
33899FILE-FLASH Adobe Flash Player ActionScript memory corruption attempt (more info ...)attempted-user  2015-0339  73088    URL
33900FILE-FLASH Adobe Flash Player ActionScript memory corruption attempt (more info ...)attempted-user  2015-0339  73088    URL
33901FILE-FLASH Adobe Flash Player ActionScript memory corruption attempt (more info ...)attempted-user  2015-0339  73088    URL
33902FILE-FLASH Adobe Flash Player ActionScript memory corruption attempt (more info ...)attempted-user  2015-0339  73088    URL
33918FILE-FLASH Adobe Flash Player AVSegmentedSource caption unlink use-after-free attempt (more info ...)attempted-user  2015-0341      URL
33919FILE-FLASH Adobe Flash Player AVSegmentedSource caption unlink use-after-free attempt (more info ...)attempted-user  2015-0341      URL
33920FILE-FLASH Adobe Flash Player AVSegmentedSource caption unlink use-after-free attempt (more info ...)attempted-user  2015-0341      URL
33921FILE-FLASH Adobe Flash Player AVSegmentedSource caption unlink use-after-free attempt (more info ...)attempted-user  2015-0341      URL
33923FILE-FLASH Adobe Flash Player paletteMap integer overflow attempt (more info ...)attempted-user  2015-0338      URL
33924FILE-FLASH Adobe Flash Player paletteMap integer overflow attempt (more info ...)attempted-user  2015-0338      URL
33925FILE-FLASH Adobe Flash Player paletteMap integer overflow attempt (more info ...)attempted-user  2015-0338      URL
33926FILE-FLASH Adobe Flash Player paletteMap integer overflow attempt (more info ...)attempted-user  2015-0338      URL
33967FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
33968FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
33969FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
33970FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
33975FILE-FLASH Adobe Flash Player SWF object type mismatch attempt (more info ...)attempted-user  2015-0334      URL
33976FILE-FLASH Adobe Flash Player SWF object type mismatch attempt (more info ...)attempted-user  2015-0334      URL
33978FILE-FLASH Adobe Flash Player BrokerExtTextOutW invalid string and length parameter sandbox escape attempt (more info ...)attempted-user  2015-0333      URL
33981EXPLOIT-KIT Nuclear exploit kit flash file download (more info ...)trojan-activity  2015-0336      
33998FILE-FLASH Adobe Flash Player malformed mp4 tag memory corruption attempt (more info ...)attempted-user  2015-0332      URL
33999FILE-FLASH Adobe Flash Player malformed mp4 tag memory corruption attempt (more info ...)attempted-user  2015-0332      URL
34020FILE-FLASH Adobe Flash Player mp4 trex tag heap corruption attempt (more info ...)attempted-user  2015-0335      
34021FILE-FLASH Adobe Flash Player mp4 trex tag heap corruption attempt (more info ...)attempted-user  2015-0335      
34133FILE-IMAGE Adobe Flash Player element array stack overflow attempt (more info ...)attempted-user  2015-0350      
34134FILE-IMAGE Adobe Flash Player element array stack overflow attempt (more info ...)attempted-user  2015-0350      
34151FILE-FLASH Adobe Flash Player sound class type confusion attempt (more info ...)attempted-user  2015-0356      
34152FILE-FLASH Adobe Flash Player sound class type confusion attempt (more info ...)attempted-user  2015-0356      
34153FILE-FLASH Adobe Flash Player sound class type confusion attempt (more info ...)attempted-user  2015-0356      
34154FILE-FLASH Adobe Flash Player sound class type confusion attempt (more info ...)attempted-user  2015-0356      
34156FILE-FLASH Adobe Flash Player EAC3 memory corruption attempt (more info ...)attempted-user  2015-0353      URL
34157FILE-FLASH Adobe Flash Player EAC3 memory corruption attempt (more info ...)attempted-user  2015-0353      URL
34158FILE-FLASH Adobe Flash Player EAC3 memory corruption attempt (more info ...)attempted-user  2015-0353      URL
34159FILE-FLASH Adobe Flash Player EAC3 memory corruption attempt (more info ...)attempted-user  2015-0353      URL
34162FILE-FLASH Adobe Flash Player RegExp zero length assertion heap overflow attempt (more info ...)attempted-user  2015-3042      URL
34163FILE-FLASH Adobe Flash Player RegExp zero length assertion heap overflow attempt (more info ...)attempted-user  2015-3042      URL
34164FILE-FLASH Adobe Flash Player RegExp zero length assertion heap overflow attempt (more info ...)attempted-user  2015-3042      URL
34165FILE-FLASH Adobe Flash Player RegExp zero length assertion heap overflow attempt (more info ...)attempted-user  2015-3042      URL
34166FILE-FLASH Adobe Flash Player byte array double free attempt (more info ...)attempted-user  2015-0359  74067    URL
34167FILE-FLASH Adobe Flash Player byte array double free attempt (more info ...)attempted-user  2015-0359  74067    URL
34168FILE-FLASH Adobe Flash Player byte array double free attempt (more info ...)attempted-user  2015-0359  74067    URL
34169FILE-FLASH Adobe Flash Player byte array double free attempt (more info ...)attempted-user  2015-0359  74067    URL
34172FILE-FLASH Adobe Flash Player TextField filter use-after-free attempt (more info ...)attempted-user  2015-0358      URL
34173FILE-FLASH Adobe Flash Player TextField filter use-after-free attempt (more info ...)attempted-user  2015-0358      URL
34174FILE-FLASH Adobe Flash Player TextField filter use-after-free attempt (more info ...)attempted-user  2015-0358      URL
34175FILE-FLASH Adobe Flash Player TextField filter use-after-free attempt (more info ...)attempted-user  2015-0358      URL
34186FILE-FLASH Adobe Flash Player AuthorizedFeaturesLoader object memory corruption attempt (more info ...)attempted-user  2015-0347      URL
34187FILE-FLASH Adobe Flash Player AuthorizedFeaturesLoader object memory corruption attempt (more info ...)attempted-user  2015-0347      URL
34188FILE-FLASH Adobe Flash Player AuthorizedFeaturesLoader object memory corruption attempt (more info ...)attempted-user  2015-0347      URL
34189FILE-FLASH Adobe Flash Player AuthorizedFeaturesLoader object memory corruption attempt (more info ...)attempted-user  2015-0347      URL
34190FILE-FLASH Adobe Flash Player convolution filter use-after-free attempt (more info ...)attempted-user  2015-0349      URL
34191FILE-FLASH Adobe Flash Player convolution filter use-after-free attempt (more info ...)attempted-user  2015-0349      URL
34192FILE-FLASH Adobe Flash Player convolution filter use-after-free attempt (more info ...)attempted-user  2015-0349      URL
34193FILE-FLASH Adobe Flash Player convolution filter use-after-free attempt (more info ...)attempted-user  2015-0349      URL
34228FILE-FLASH Adobe Flash Player malformed CEA-708 packet arbitrary code execution attempt (more info ...)attempted-user  2015-0355      URL
34229FILE-FLASH Adobe Flash Player malformed CEA-708 packet arbitrary code execution attempt (more info ...)attempted-user  2015-0355      URL
34230FILE-FLASH Adobe Flash Player malformed CEA-708 packet arbitrary code execution attempt (more info ...)attempted-user  2015-0355      URL
34231FILE-FLASH Adobe Flash Player malformed CEA-708 packet arbitrary code execution attempt (more info ...)attempted-user  2015-0355      URL
34240FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34241FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34242FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34243FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34244FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34245FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34247FILE-FLASH Adobe Flash Player text field mask use after free attempt (more info ...)attempted-user  2015-0351      URL
34248FILE-FLASH Adobe Flash Player text field mask use after free attempt (more info ...)attempted-user  2015-0351      URL
34249FILE-FLASH Adobe Flash Player text field mask use after free attempt (more info ...)attempted-user  2015-0351      URL
34250FILE-FLASH Adobe Flash Player text field mask use after free attempt (more info ...)attempted-user  2015-0351      URL
34251FILE-FLASH Adobe Flash Player malformed CEA-708 packet denial of service attempt (more info ...)attempted-dos  2015-0354      URL
34252FILE-FLASH Adobe Flash Player malformed CEA-708 packet denial of service attempt (more info ...)attempted-dos  2015-0354      URL
34255FILE-FLASH Adobe Flash Player flash settings manager double free attempt (more info ...)attempted-user  2015-0346      URL
34256FILE-FLASH Adobe Flash Player flash settings manager double free attempt (more info ...)attempted-user  2015-0346      URL
34257FILE-FLASH Adobe Flash Player flash settings manager double free attempt (more info ...)attempted-user  2015-0346      URL
34258FILE-FLASH Adobe Flash Player flash settings manager double free attempt (more info ...)attempted-user  2015-0346      URL
34259FILE-FLASH Adobe Flash Player flash settings manager double free attempt (more info ...)attempted-user  2015-0346      URL
34260FILE-FLASH Adobe Flash Player flash settings manager double free attempt (more info ...)attempted-user  2015-0346      URL
34264FILE-FLASH Adobe Flash Player AVC parser integer overflow attempt (more info ...)attempted-user  2015-0352      URL
34265FILE-FLASH Adobe Flash Player AVC parser integer overflow attempt (more info ...)attempted-user  2015-0352      URL
34266FILE-FLASH Adobe Flash Player AVC parser integer overflow attempt (more info ...)attempted-user  2015-0352      URL
34267FILE-FLASH Adobe Flash Player AVC parser integer overflow attempt (more info ...)attempted-user  2015-0352      URL
34268FILE-MULTIMEDIA Adobe Flash Player AVC parser integer overflow attempt (more info ...)attempted-user  2015-0352      URL
34269FILE-MULTIMEDIA Adobe Flash Player AVC parser integer overflow attempt (more info ...)attempted-user  2015-0352      URL
34270FILE-FLASH Adobe Flash Player FLV tag datasize buffer overflow attempt (more info ...)attempted-user  2015-3043      URL
34271FILE-FLASH Adobe Flash Player FLV tag datasize buffer overflow attempt (more info ...)attempted-user  2015-3043      URL
34272FILE-FLASH Adobe Flash malformed pixel bytecode attempt (more info ...)attempted-user  2015-3041      URL
34273FILE-FLASH Adobe Flash malformed pixel bytecode attempt (more info ...)attempted-user  2015-3041      URL
34274FILE-FLASH Adobe Flash malformed pixel bytecode attempt (more info ...)attempted-user  2015-3041      URL
34275FILE-FLASH Adobe Flash malformed pixel bytecode attempt (more info ...)attempted-user  2015-3041      URL
34276FILE-FLASH Adobe Flash Player Sound.extract integer overflow attempt (more info ...)attempted-user  2015-0348      URL
34277FILE-FLASH Adobe Flash Player Sound.extract integer overflow attempt (more info ...)attempted-user  2015-0348      URL
34278FILE-FLASH Adobe Flash Player Sound.extract integer overflow attempt (more info ...)attempted-user  2015-0348      URL
34279FILE-FLASH Adobe Flash Player Sound.extract integer overflow attempt (more info ...)attempted-user  2015-0348      URL
34302FILE-FLASH Adobe Flash Player shared byte array memory corruption attempt (more info ...)attempted-user  2015-3038      URL
34303FILE-FLASH Adobe Flash Player shared byte array memory corruption attempt (more info ...)attempted-user  2015-3038      URL
34304FILE-FLASH Adobe Flash Player shared byte array memory corruption attempt (more info ...)attempted-user  2015-3038      URL
34305FILE-FLASH Adobe Flash Player shared byte array memory corruption attempt (more info ...)attempted-user  2015-3038      URL
34330EXPLOIT-KIT Fiesta exploit kit Adobe Flash exploit download (more info ...)trojan-activity        
34354FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
34355FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
34356FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
34357FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
34466FILE-EXECUTABLE Adobe Reader AcroBroker registry value out of bounds attempt (more info ...)attempted-user  2015-3048      URL
34467FILE-EXECUTABLE Adobe Reader AcroBroker registry value out of bounds attempt (more info ...)attempted-user  2015-3048      URL
34473FILE-PDF Adobe Acrobat Reader WillSave action use after free attempt (more info ...)attempted-user  2015-3054      URL
34474FILE-PDF Adobe Acrobat Reader WillSave action use after free attempt (more info ...)attempted-user  2015-3054      URL
34477FILE-FLASH Adobe Flash Player object type confusion attempt (more info ...)attempted-user  2015-3086      URL
34478FILE-FLASH Adobe Flash Player object type confusion attempt (more info ...)attempted-user  2015-3086      URL
34492FILE-FLASH Adobe Flash Player same origin policy security bypass attempt (more info ...)attempted-user  2014-0548  69705    URL
34493FILE-FLASH Adobe Flash Player same origin policy security bypass attempt (more info ...)attempted-user  2014-0548  69705    URL
34494FILE-FLASH Adobe Flash Player same origin policy security bypass attempt (more info ...)attempted-user  2014-0548  69705    URL
34495FILE-FLASH Adobe Flash Player same origin policy security bypass attempt (more info ...)attempted-user  2014-0548  69705    URL
34502FILE-FLASH Adobe Flash Player ActionScript AVSS memory corruption attempt (more info ...)attempted-user  2015-3088      URL
34503FILE-FLASH Adobe Flash Player ActionScript AVSS memory corruption attempt (more info ...)attempted-user  2015-3088      URL
34504FILE-FLASH Adobe Flash Player setSubscribedTags memory corruption attempt (more info ...)attempted-user  2015-3088      URL
34505FILE-FLASH Adobe Flash Player setSubscribedTags memory corruption attempt (more info ...)attempted-user  2015-3088      URL
34506FILE-FLASH Adobe Flash Player setCuePointTags memory corruption attempt (more info ...)attempted-user  2015-3088      URL
34507FILE-FLASH Adobe Flash Player setCuePointTags memory corruption attempt (more info ...)attempted-user  2015-3088      URL
34508FILE-FLASH Adobe Flash Player setSubscribedTagsForBackgroundManifest memory corruption attempt (more info ...)attempted-user  2015-3088      URL
34509FILE-FLASH Adobe Flash Player setSubscribedTagsForBackgroundManifest memory corruption attempt (more info ...)attempted-user  2015-3088      URL
34510FILE-OTHER Adobe Flash Player mp4 avcC atom memory corruption attempt (more info ...)attempted-user  2015-3078      URL
34511FILE-OTHER Adobe Flash Player mp4 avcC atom memory corruption attempt (more info ...)attempted-user  2015-3078      URL
34512FILE-OTHER Adobe Flash Player mp4 avcC atom memory corruption attempt (more info ...)attempted-user  2015-3078      URL
34513FILE-OTHER Adobe Flash Player mp4 avcC atom memory corruption attempt (more info ...)attempted-user  2015-3078      URL
34514FILE-PDF Adobe Acrobat Reader addAnnot invalid type conversion attempt (more info ...)attempted-user  2015-3056      URL
34515FILE-PDF Adobe Acrobat Reader addAnnot invalid type conversion attempt (more info ...)attempted-user  2015-3056      URL
34516FILE-PDF Adobe Acrobat Reader addAnnot invalid type conversion attempt (more info ...)attempted-user  2015-3056      URL
34517FILE-PDF Adobe Acrobat Reader addAnnot invalid type conversion attempt (more info ...)attempted-user  2015-3056      URL
34518FILE-OTHER Adobe Flash Player invalid mpd memory corruption attempt (more info ...)attempted-admin  2015-3089      URL
34519FILE-OTHER Adobe Flash Player invalid mpd memory corruption attempt (more info ...)attempted-admin  2015-3089      URL
34520FILE-FLASH Adobe Flash Player Button.filters type confusion remote code execution attempt (more info ...)attempted-user  2015-3077      URL
34521FILE-FLASH Adobe Flash Player Button.filters type confusion remote code execution attempt (more info ...)attempted-user  2015-3077      URL
34522FILE-FLASH Adobe Flash Player Button.filters type confusion remote code execution attempt (more info ...)attempted-user  2015-3077      URL
34523FILE-FLASH Adobe Flash Player Button.filters type confusion remote code execution attempt (more info ...)attempted-user  2015-3077      URL
34524FILE-PDF Adobe Acrobat Reader CoolType blend memory corruption attempt (more info ...)attempted-user  2015-3052  74600    URL
34525FILE-PDF Adobe Acrobat Reader CoolType blend memory corruption attempt (more info ...)attempted-user  2015-3052  74600    URL
34526FILE-PDF Adobe Acrobat Reader Cooltype callother memory corruption attempt (more info ...)attempted-user  2015-3051  74600    URL
34527FILE-PDF Adobe Acrobat Reader Cooltype callother memory corruption attempt (more info ...)attempted-user  2015-3051  74600    URL
34538FILE-FLASH Adobe Flash Player ByteArray shading memory leak attempt (more info ...)attempted-recon  2015-3105  75086    URL
34539FILE-FLASH Adobe Flash Player ByteArray shading memory leak attempt (more info ...)attempted-recon  2015-3105  75086    URL
34542FILE-FLASH Adobe Flash Player GIF sprite kernel memory leak attempt (more info ...)attempted-admin  2015-3093      URL
34543FILE-FLASH Adobe Flash Player GIF sprite kernel memory leak attempt (more info ...)attempted-admin  2015-3093      URL
34544FILE-FLASH Adobe Flash Player GIF sprite kernel memory leak attempt (more info ...)attempted-admin  2015-3093      URL
34545FILE-FLASH Adobe Flash Player GIF sprite kernel memory leak attempt (more info ...)attempted-admin  2015-3093      URL
34546FILE-PDF Adobe Acrobat Reader PCR null pointer dereference attempt (more info ...)attempted-user  2015-3046      URL
34547FILE-PDF Adobe Acrobat Reader PCR null pointer dereference attempt (more info ...)attempted-user  2015-3046      URL
34548FILE-PDF Adobe Acrobat Reader 11.0.09 keystroke combobox use after free attempt (more info ...)attempted-user  2015-3075      URL
34549FILE-PDF Adobe Acrobat Reader 11.0.09 keystroke combobox use after free attempt (more info ...)attempted-user  2015-3075      URL
34552FILE-PDF Adobe Acrobat Reader malformed shading modifier heap corruption attempt (more info ...)attempted-user  2015-3070      URL
34553FILE-FLASH Adobe Flash Player integer overflow attempt (more info ...)attempted-user  2015-3087      URL
34554FILE-FLASH Adobe Flash Player integer overflow attempt (more info ...)attempted-user  2015-3087      URL
34555FILE-FLASH Adobe Flash Player integer overflow attempt (more info ...)attempted-user  2015-3087      URL
34556FILE-FLASH Adobe Flash Player integer overflow attempt (more info ...)attempted-user  2015-3087      URL
34559FILE-PDF Adobe Acrobat Reader openDoc dangling pointer attempt (more info ...)attempted-user  2015-3057      URL
34560FILE-PDF Adobe Acrobat Reader openDoc dangling pointer attempt (more info ...)attempted-user  2015-3057      URL
34561FILE-FLASH Adobe Flash Player asynchronous shader changes memory corruption attempt (more info ...)attempted-user  2015-3090      URL
34562FILE-FLASH Adobe Flash Player asynchronous shader changes memory corruption attempt (more info ...)attempted-user  2015-3090      URL
34563FILE-FLASH Adobe Flash Player asynchronous shader changes memory corruption attempt (more info ...)attempted-user  2015-3090      URL
34564FILE-FLASH Adobe Flash Player asynchronous shader changes memory corruption attempt (more info ...)attempted-user  2015-3090      URL
34582FILE-FLASH Adobe Flash Player invalid BitmapData use after free attempt (more info ...)attempted-user  2015-5127      URL
34583FILE-FLASH Adobe Flash Player invalid BitmapData use after free attempt (more info ...)attempted-user  2015-5127      URL
34589FILE-PDF Adobe Acrobat Reader stateModel use-after-free attempt (more info ...)attempted-user  2015-3059      URL
34590FILE-PDF Adobe Acrobat Reader stateModel use-after-free attempt (more info ...)attempted-user  2015-3059      URL
34591FILE-PDF Adobe Acrobat Reader stateModel use-after-free attempt (more info ...)attempted-user  2015-3059      URL
34592FILE-PDF Adobe Acrobat Reader stateModel use-after-free attempt (more info ...)attempted-user  2015-3059      URL
34593FILE-PDF Adobe Acrobat Reader stateModel use-after-free attempt (more info ...)attempted-user  2015-3059      URL
34594FILE-PDF Adobe Acrobat Reader stateModel use-after-free attempt (more info ...)attempted-user  2015-3059      URL
34650FILE-PDF Adobe Acrobat Reader heap buffer overflow attempt (more info ...)attempted-user  2015-3050      URL
34651FILE-PDF Adobe Acrobat Reader heap buffer overflow attempt (more info ...)attempted-user  2015-3050      URL
34652FILE-PDF Adobe Acrobat Reader JS notification object double free attempt (more info ...)attempted-user  2015-3076      URL
34653FILE-PDF Adobe Acrobat Reader JS notification object double free attempt (more info ...)attempted-user  2015-3076      URL
34731OS-WINDOWS Microsoft Windows Media Player DataObject buffer overflow attempt (more info ...)attempted-user  2015-1728      URL
34732OS-WINDOWS Microsoft Windows Media Player DataObject buffer overflow attempt (more info ...)attempted-user  2015-1728      URL
34794FILE-FLASH Adobe Flash Player JSON stringify memory corruption attempt (more info ...)attempted-user  2015-0324  72514    URL
34795FILE-FLASH Adobe Flash Player JSON stringify memory corruption attempt (more info ...)attempted-user  2015-0324  72514    URL
34796FILE-FLASH Adobe Flash Player JSON stringify memory corruption attempt (more info ...)attempted-user  2015-0324  72514    URL
34797FILE-FLASH Adobe Flash Player JSON stringify memory corruption attempt (more info ...)attempted-user  2015-0324  72514    URL
34803FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34804FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34805FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34806FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359  74067    URL
34807FILE-FLASH Adobe Flash Player NetConnection and NetStream type confusion exploit attempt (more info ...)attempted-user  2015-3084      URL
34808FILE-FLASH Adobe Flash Player NetConnection and NetStream type confusion exploit attempt (more info ...)attempted-user  2015-3084      URL
34809FILE-FLASH Adobe Flash Player NetConnection and NetStream type confusion exploit attempt (more info ...)attempted-user  2015-3084      URL
34810FILE-FLASH Adobe Flash Player NetConnection and NetStream type confusion exploit attempt (more info ...)attempted-user  2015-3084      URL
34816FILE-FLASH Adobe Flash FPU stack corruption attempt (more info ...)attempted-user  2015-3100      URL
34817FILE-FLASH Adobe Flash FPU stack corruption attempt (more info ...)attempted-user  2015-3100      URL
34819FILE-FLASH Adobe Flash Player concurrent worker thread terminate use-after-free attempt (more info ...)attempted-user  2015-3103      URL
34820FILE-FLASH Adobe Flash Player concurrent worker thread terminate use-after-free attempt (more info ...)attempted-user  2015-3103      URL
34821FILE-FLASH Adobe Flash Player concurrent worker thread terminate use-after-free attempt (more info ...)attempted-user  2015-3103      URL
34822FILE-FLASH Adobe Flash Player concurrent worker thread terminate use-after-free attempt (more info ...)attempted-user  2015-3103      URL
34845FILE-PDF Adobe Acrobat Reader setPageAction use after free attempt (more info ...)attempted-user  2015-3053  74602    URL
34846FILE-PDF Adobe Acrobat Reader setPageAction use after free attempt (more info ...)attempted-user  2015-3053  74602    URL
34848FILE-FLASH Adobe Flash Player Shader Channel integer overflow attempt (more info ...)attempted-user  2015-3104      URL
34849FILE-FLASH Adobe Flash Player Shader Channel integer overflow attempt (more info ...)attempted-user  2015-3104      URL
34850FILE-FLASH Adobe Flash Player Shader Channel integer overflow attempt (more info ...)attempted-user  2015-3104      URL
34851FILE-FLASH Adobe Flash Player Shader Channel integer overflow attempt (more info ...)attempted-user  2015-3104      URL
34853FILE-FLASH Adobe Flash custom TextField filter use after free attempt (more info ...)attempted-user  2015-3106      URL
34854FILE-FLASH Adobe Flash custom TextField filter use after free attempt (more info ...)attempted-user  2015-3106      URL
34855FILE-FLASH Adobe Flash Player ShaderParameter out of bounds write attempt (more info ...)attempted-user  2015-3105  75086    URL
34856FILE-FLASH Adobe Flash Player ShaderParameter out of bounds write attempt (more info ...)attempted-user  2015-3105  75086    URL
34988FILE-FLASH Adobe Flash Player malformed FLV file buffer overflow attempt (more info ...)attempted-user  2015-3113      URL
34989FILE-FLASH Adobe Flash Player malformed FLV file buffer overflow attempt (more info ...)attempted-user  2015-3113      URL
34990MALWARE-OTHER Adobe Flash exploit download attempt - Group 6 (more info ...)trojan-activity        URL
34991MALWARE-OTHER Group 6 Adobe Flash exploit download attempt (more info ...)trojan-activity        URL
35048FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
35049FILE-FLASH Adobe Flash Player ByteArray uncompress domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
35086FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
35087FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
35088FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
35089FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
35095FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
35096FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
35109EXPLOIT-KIT Angler exploit kit obfuscated Flash actionscript classname detected (more info ...)misc-attack        URL
35110EXPLOIT-KIT Angler exploit kit obfuscated Flash actionscript classname detected (more info ...)trojan-activity        URL
35217FILE-FLASH Adobe Flash Player BitmapData use-after-free attempt (more info ...)attempted-user  2015-5123      URL
35218FILE-FLASH Adobe Flash Player BitmapData use-after-free attempt (more info ...)attempted-user  2015-5123      URL
35219FILE-FLASH Adobe Flash Player BitmapData use-after-free attempt (more info ...)attempted-user  2015-5123      URL
35220FILE-FLASH Adobe Flash Player BitmapData use-after-free attempt (more info ...)attempted-user  2015-5123      URL
35223FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35224FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35225FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35226FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35227FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35228FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35229FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35230FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35231FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35232FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35233FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35234FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35235FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35236FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35237FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35238FILE-FLASH Adobe Flash Player valueOf and toString use after free attempt (more info ...)attempted-user  2015-3128      URL
35240FILE-PDF Adobe Acrobat Reader mishandling of invalid triangle edge access attempt (more info ...)attempted-user  2014-8459      URL
35241FILE-PDF Adobe Acrobat Reader mishandling of invalid triangle edge access attempt (more info ...)attempted-user  2014-8459      URL
35242FILE-PDF Adobe Acrobat Reader mishandling of invalid triangle edge access attempt (more info ...)attempted-user  2014-8459      URL
35263FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5122      URL
35266FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5122      URL
35267FILE-FLASH Adobe Flash Player textfield filter use-after-free attempt (more info ...)attempted-user  2015-3118      URL
35268FILE-FLASH Adobe Flash Player textfield filter use-after-free attempt (more info ...)attempted-user  2015-3118      URL
35269FILE-FLASH Adobe Flash Player textfield filter use-after-free attempt (more info ...)attempted-user  2015-3118      URL
35270FILE-FLASH Adobe Flash Player textfield filter use-after-free attempt (more info ...)attempted-user  2015-3118      URL
35271FILE-FLASH Adobe Flash Player buildTraitsBindings null pointer dereference attempt (more info ...)attempted-dos  2015-3117      URL
35272FILE-FLASH Adobe Flash Player buildTraitsBindings null pointer dereference attempt (more info ...)attempted-dos  2015-3117      URL
35273FILE-FLASH Adobe Flash Player buildTraitsBindings null pointer dereference attempt (more info ...)attempted-dos  2015-3117      URL
35274FILE-FLASH Adobe Flash Player buildTraitsBindings null pointer dereference attempt (more info ...)attempted-dos  2015-3117      URL
35275FILE-FLASH Adobe Flash Player NetConnection type confusion attempt (more info ...)attempted-user  2015-3119      URL
35276FILE-FLASH Adobe Flash Player NetConnection type confusion attempt (more info ...)attempted-user  2015-3119      URL
35277FILE-FLASH Adobe Flash Player NetConnection type confusion attempt (more info ...)attempted-user  2015-3119      URL
35278FILE-FLASH Adobe Flash Player NetConnection type confusion attempt (more info ...)attempted-user  2015-3119      URL
35290FILE-FLASH Adobe Flash Player SharedObject array.prototype.push use after free attempt (more info ...)attempted-user  2015-3127      URL
35291FILE-FLASH Adobe Flash Player SharedObject array.prototype.push use after free attempt (more info ...)attempted-user  2015-3127      URL
35292FILE-FLASH Adobe Flash Player SharedObject array.prototype.push use after free attempt (more info ...)attempted-user  2015-3127      URL
35293FILE-FLASH Adobe Flash Player SharedObject array.prototype.push use after free attempt (more info ...)attempted-user  2015-3127      URL
35294FILE-FLASH Adobe Flash Player SharedObject array.prototype.push use after free attempt (more info ...)attempted-user  2015-3127      URL
35295FILE-FLASH Adobe Flash Player SharedObject array.prototype.push use after free attempt (more info ...)attempted-user  2015-3127      URL
35296FILE-FLASH Adobe Flash Player SharedObject type confusion attempt (more info ...)attempted-user  2015-3121      URL
35297FILE-FLASH Adobe Flash Player SharedObject type confusion attempt (more info ...)attempted-user  2015-3121      URL
35298FILE-FLASH Adobe Flash Player SharedObject type confusion attempt (more info ...)attempted-user  2015-3121      URL
35299FILE-FLASH Adobe Flash Player SharedObject type confusion attempt (more info ...)attempted-user  2015-3121      URL
35308FILE-PDF Adobe Reader MakeMeasurement buffer overflow attempt (more info ...)attempted-user  2015-5093      URL
35309FILE-PDF Adobe Reader MakeMeasurement buffer overflow attempt (more info ...)attempted-user  2015-5093      URL
35319FILE-PDF Adobe Reader ToolEventHandler use-after-free attempt (more info ...)attempted-user  2015-5094      URL
35320FILE-PDF Adobe Reader ToolEventHandler use-after-free attempt (more info ...)attempted-user  2015-5094      URL
35321FILE-PDF Adobe Reader setTimeOut app.launchURL privilege escalation attempt (more info ...)attempted-user  2015-4447      URL
35322FILE-PDF Adobe Reader setTimeOut app.launchURL privilege escalation attempt (more info ...)attempted-user  2015-4447      URL
35323FILE-PDF Adobe Acrobat Reader ComboBox field Format action use-after-free attempt (more info ...)attempted-user  2015-5113  75739    URL
35324FILE-PDF Adobe Acrobat Reader ComboBox field Format action use-after-free attempt (more info ...)attempted-user  2015-5113  75739    URL
35345FILE-PDF Adobe Acrobat Reader Unicode value memory corruption attempt (more info ...)attempted-user  2015-5087  75740    URL
35346FILE-PDF Adobe Acrobat Reader Unicode value memory corruption attempt (more info ...)attempted-user  2015-5087  75740    URL
35360FILE-IMAGE Adobe Acrobat Reader DC TIFF orientation heap buffer overflow attempt (more info ...)attempted-user  2015-5097      URL
35361FILE-IMAGE Adobe Acrobat Reader DC TIFF orientation heap buffer overflow attempt (more info ...)attempted-user  2015-5097      URL
35362FILE-IMAGE Adobe Acrobat Reader DC TIFF orientation heap buffer overflow attempt (more info ...)attempted-user  2015-5097      URL
35363FILE-IMAGE Adobe Acrobat Reader DC TIFF orientation heap buffer overflow attempt (more info ...)attempted-user  2015-5097      URL
35364FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359      URL
35365FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359      URL
35366FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359      URL
35367FILE-FLASH Adobe Flash Player thread write double-free attempt (more info ...)attempted-user  2015-0359      URL
35407FILE-PDF Adobe Reader setItems use-after-free attempt (more info ...)attempted-admin  2015-5099      URL
35408FILE-PDF Adobe Reader setItems use-after-free attempt (more info ...)attempted-admin  2015-5099      URL
35409FILE-PDF Adobe Reader setItems use-after-free attempt (more info ...)attempted-admin  2015-5099      URL
35410FILE-PDF Adobe Reader setItems use-after-free attempt (more info ...)attempted-admin  2015-5099      URL
35430FILE-PDF Adobe Reader nested events use-after-free attempt (more info ...)attempted-user  2015-5095      URL
35431FILE-PDF Adobe Reader nested events use-after-free attempt (more info ...)attempted-user  2015-5095      URL
35449FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122      URL
35450FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122      URL
35451FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122      URL
35452FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122      URL
35453FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
35454FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
35455FILE-IDENTIFY Adobe LZMA compressed Flash file magic detected (more info ...)misc-activity        
35456FILE-IDENTIFY Adobe LZMA compressed Flash file attachment detected (more info ...)misc-activity        
35457FILE-IDENTIFY Adobe LZMA compressed Flash file attachment detected (more info ...)misc-activity        
35458FILE-IDENTIFY Adobe LZMA compressed Flash file magic detected (more info ...)misc-activity        
35459FILE-IDENTIFY Adobe LZMA compressed Flash file download request (more info ...)misc-activity        
35463FILE-FLASH Adobe flash player BitmapData.paletteMap use after free attempt (more info ...)attempted-user  2015-5123      URL
35464FILE-FLASH Adobe flash player BitmapData.paletteMap use after free attempt (more info ...)attempted-user  2015-5123      URL
35465FILE-FLASH Adobe flash player BitmapData.paletteMap use after free attempt (more info ...)attempted-user  2015-5123      URL
35466FILE-FLASH Adobe flash player BitmapData.paletteMap use after free attempt (more info ...)attempted-user  2015-5123      URL
35571FILE-FLASH Adobe Flash Player SWF dereference attempt (more info ...)attempted-user  2015-5546      URL
35572FILE-FLASH Adobe Flash Player SWF dereference attempt (more info ...)attempted-user  2015-5546      URL
35574FILE-FLASH Adobe Flash Player secret cookie location disclosure attempt (more info ...)attempted-recon  2015-5125      URL
35575FILE-FLASH Adobe Flash Player secret cookie location disclosure attempt (more info ...)attempted-recon  2015-5125      URL
35576FILE-FLASH Adobe Flash Player secret cookie location disclosure attempt (more info ...)attempted-recon  2015-5125      URL
35577FILE-FLASH Adobe Flash Player secret cookie location disclosure attempt (more info ...)attempted-recon  2015-5125      URL
35578FILE-FLASH Adobe Flash Player BitmapData applyFilter heap overflow attempt (more info ...)attempted-user  2015-5541      URL
35579FILE-FLASH Adobe Flash Player BitmapData applyFilter heap overflow attempt (more info ...)attempted-user  2015-5541      URL
35580FILE-FLASH Adobe Flash Player BitmapData applyFilter heap overflow attempt (more info ...)attempted-user  2015-5541      URL
35581FILE-FLASH Adobe Flash Player BitmapData applyFilter heap overflow attempt (more info ...)attempted-user  2015-5541      URL
35582FILE-FLASH Adobe Flash Player button pointer exploit attempt (more info ...)attempted-user  2015-5547      URL
35583FILE-FLASH Adobe Flash Player button pointer exploit attempt (more info ...)attempted-user  2015-5547      URL
35584FILE-FLASH Adobe Flash Player BitmapData object use after free attempt (more info ...)attempted-user  2015-5559  76288    URL
35585FILE-FLASH Adobe Flash Player BitmapData object use after free attempt (more info ...)attempted-user  2015-5559  76288    URL
35586FILE-FLASH Adobe Flash Player BitmapData object use after free attempt (more info ...)attempted-user  2015-5559  76288    URL
35587FILE-FLASH Adobe Flash Player BitmapData object use after free attempt (more info ...)attempted-user  2015-5559  76288    URL
35592FILE-FLASH Adobe Flash Player tag length buffer overflow attempt (more info ...)attempted-user  2015-5131      
35593FILE-FLASH Adobe Flash Player tag length buffer overflow attempt (more info ...)attempted-user  2015-5131      
35599FILE-FLASH Adobe Flash Player NetConnection use-after-free attempt (more info ...)attempted-user  2015-5565      URL
35600FILE-FLASH Adobe Flash Player NetConnection use-after-free attempt (more info ...)attempted-user  2015-5565      URL
35601FILE-FLASH Adobe Flash Player NetConnection use-after-free attempt (more info ...)attempted-user  2015-5565      URL
35602FILE-FLASH Adobe Flash Player NetConnection use-after-free attempt (more info ...)attempted-user  2015-5565      URL
35603FILE-FLASH Adobe Flash Player setAdvancedAntialiasingTable type confusion attempt (more info ...)attempted-user  2015-5555      URL
35604FILE-FLASH Adobe Flash Player setAdvancedAntialiasingTable type confusion attempt (more info ...)attempted-user  2015-5555      URL
35605FILE-FLASH Adobe Flash Player setAdvancedAntialiasingTable type confusion attempt (more info ...)attempted-user  2015-5555      URL
35606FILE-FLASH Adobe Flash Player setAdvancedAntialiasingTable type confusion attempt (more info ...)attempted-user  2015-5555      URL
35607FILE-FLASH Adobe Flash Player CreateTextField use-after-free attempt (more info ...)attempted-user  2015-5556      URL
35608FILE-FLASH Adobe Flash Player CreateTextField use-after-free attempt (more info ...)attempted-user  2015-5556      URL
35609FILE-FLASH Adobe Flash Player CreateTextField use-after-free attempt (more info ...)attempted-user  2015-5556      URL
35610FILE-FLASH Adobe Flash Player CreateTextField use-after-free attempt (more info ...)attempted-user  2015-5556      URL
35618FILE-FLASH Adobe Flash Player slow script invalid pointer dereference attempt (more info ...)attempted-user  2015-5545  76283    URL
35619FILE-FLASH Adobe Flash Player slow script invalid pointer dereference attempt (more info ...)attempted-user  2015-5545  76283    URL
35624FILE-MULTIMEDIA Apple Quicktime invalid samr atom out of bounds read attempt (more info ...)attempted-user  2015-7087      URL
35625FILE-MULTIMEDIA Apple Quicktime invalid samr atom out of bounds read attempt (more info ...)attempted-user  2015-7087      URL
35626FILE-MULTIMEDIA Apple Quicktime invalid samr atom out of bounds read attempt (more info ...)attempted-user  2015-7087      URL
35627FILE-MULTIMEDIA Apple Quicktime invalid samr atom out of bounds read attempt (more info ...)attempted-user  2015-7087      URL
35632FILE-FLASH Adobe Flash Player NetMonitor use-after-free attempt (more info ...)attempted-user  2015-5566      URL
35633FILE-FLASH Adobe Flash Player NetMonitor use-after-free attempt (more info ...)attempted-user  2015-5566      URL
35634FILE-FLASH Adobe Flash Player NetMonitor use-after-free attempt (more info ...)attempted-user  2015-5566      URL
35635FILE-FLASH Adobe Flash Player NetMonitor use-after-free attempt (more info ...)attempted-user  2015-5566      URL
35642FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5134      
35643FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5134      
35644FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5134      
35645FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5134      
35646FILE-FLASH Adobe Flash Player XML pointer wrong parent reference (more info ...)attempted-user  2015-5548      URL
35647FILE-FLASH Adobe Flash Player XML pointer wrong parent reference (more info ...)attempted-user  2015-5548      URL
35649FILE-FLASH Adobe Flash Player XML pointer wrong parent reference (more info ...)attempted-user  2015-8443      URL
35650FILE-FLASH Adobe Flash Player TextField filters use-after-free attempt (more info ...)attempted-user  2015-5561      URL
35651FILE-FLASH Adobe Flash Player TextField filters use-after-free attempt (more info ...)attempted-user  2015-8450      URL
35652FILE-FLASH Adobe Flash Player TextField filters use-after-free attempt (more info ...)attempted-user  2015-5561      URL
35653FILE-FLASH Adobe Flash Player TextField filters use-after-free attempt (more info ...)attempted-user  2015-8450      URL
35654FILE-FLASH Adobe Flash Player XML property delete out of bounds memory write attempt (more info ...)attempted-user  2015-5549      URL
35655FILE-FLASH Adobe Flash Player XML property delete out of bounds memory write attempt (more info ...)attempted-user  2015-5549      URL
35656FILE-FLASH Adobe Flash Player XML property delete out of bounds memory write attempt (more info ...)attempted-user  2015-5549      URL
35657FILE-FLASH Adobe Flash Player XML property delete out of bounds memory write attempt (more info ...)attempted-user  2015-5549      URL
35658FILE-FLASH Adobe Flash Player FileReference constructor type confusion attempt (more info ...)attempted-user  2015-5558      URL
35659FILE-FLASH Adobe Flash Player FileReference constructor type confusion attempt (more info ...)attempted-user  2015-5558      URL
35660FILE-FLASH Adobe Flash Player FileReference constructor type confusion attempt (more info ...)attempted-user  2015-5558      URL
35661FILE-FLASH Adobe Flash Player FileReference constructor type confusion attempt (more info ...)attempted-user  2015-5558      URL
35662FILE-FLASH Adobe Flash Player corrupt glyph array out of bounds attempt (more info ...)attempted-user  2015-5133      
35663FILE-FLASH Adobe Flash Player corrupt glyph array out of bounds attempt (more info ...)attempted-user  2015-5133      
35666FILE-FLASH Adobe Flash Player bitmap handling memory corruption attempt (more info ...)attempted-user  2015-5544      URL
35667FILE-FLASH Adobe Flash Player bitmap handling memory corruption attempt (more info ...)attempted-user  2015-5544      URL
35671FILE-FLASH Adobe Flash Player incorrect reference to IExternalizable object attempt (more info ...)attempted-user  2015-5553      URL
35672FILE-FLASH Adobe Flash Player incorrect reference to IExternalizable object attempt (more info ...)attempted-user  2015-5553      URL
35673FILE-FLASH Adobe Flash Player incorrect reference to IExternalizable object attempt (more info ...)attempted-user  2015-5553      URL
35674FILE-FLASH Adobe Flash Player incorrect reference to IExternalizable object attempt (more info ...)attempted-user  2015-5553      URL
35691FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5557      URL
35692FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5557      URL
35693FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5557      URL
35694FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5557      URL
35695FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5557      URL
35696FILE-FLASH Adobe Flash Player ASnative previously set SharedObject variable set attempt (more info ...)attempted-user  2015-5557      URL
35711FILE-MULTIMEDIA Apple Quicktime invalid alis atom out of bounds read attempt (more info ...)attempted-user  2015-7117      URL
35712FILE-MULTIMEDIA Apple Quicktime invalid alis atom out of bounds read attempt (more info ...)attempted-user  2015-7117      URL
35713FILE-MULTIMEDIA Apple Quicktime invalid dref atom out of bounds read attempt (more info ...)attempted-user  2015-7090      URL
35714FILE-MULTIMEDIA Apple Quicktime invalid dref atom out of bounds read attempt (more info ...)attempted-user  2015-7090      URL
35715FILE-MULTIMEDIA Apple QuickTime mdat atom corruption out of bounds read attempt (more info ...)attempted-user  2015-7088      URL
35716FILE-MULTIMEDIA Apple QuickTime mdat atom corruption out of bounds read attempt (more info ...)attempted-user  2015-7088      URL
35717FILE-MULTIMEDIA Apple QuickTime mdat atom corruption out of bounds read attempt (more info ...)attempted-user  2015-7089      URL
35718FILE-MULTIMEDIA Apple QuickTime mdat atom corruption out of bounds read attempt (more info ...)attempted-user  2015-7089      URL
35741FILE-FLASH Adobe Flash Player raster pointer null pointer dereference attempt (more info ...)attempted-user  2015-5126      URL
35742FILE-FLASH Adobe Flash Player raster pointer null pointer dereference attempt (more info ...)attempted-user  2015-5126      URL
35743FILE-FLASH Adobe Flash Player raster pointer null pointer dereference attempt (more info ...)attempted-user  2015-5126      URL
35744FILE-FLASH Adobe Flash Player raster pointer null pointer dereference attempt (more info ...)attempted-user  2015-5126      URL
35751FILE-IMAGE Adobe Acrobat GIF to PDF conversion heap overflow attempt (more info ...)attempted-user  2015-5096      URL
35752FILE-IMAGE Adobe Acrobat GIF to PDF conversion heap overflow attempt (more info ...)attempted-user  2015-5096      URL
35753FILE-FLASH Adobe Flash Player SharedObject use after free attempt (more info ...)attempted-user  2015-5539      
35754FILE-FLASH Adobe Flash Player SharedObject use after free attempt (more info ...)attempted-user  2015-5539      
35755FILE-FLASH Adobe Flash Player SharedObject use after free attempt (more info ...)attempted-user  2015-5539      
35756FILE-FLASH Adobe Flash Player SharedObject use after free attempt (more info ...)attempted-user  2015-5539      
35759FILE-FLASH Adobe Flash Player XMLSocket destroy function type confusion attempt (more info ...)attempted-user  2015-5554      
35760FILE-FLASH Adobe Flash Player XMLSocket destroy function type confusion attempt (more info ...)attempted-user  2015-5554      
35761FILE-FLASH Adobe Flash Player XMLSocket destroy function type confusion attempt (more info ...)attempted-user  2015-5554      
35762FILE-FLASH Adobe Flash Player XMLSocket destroy function type confusion attempt (more info ...)attempted-user  2015-5554      
35767FILE-PDF Adobe Reader CBBBRInvite privilege escalation attempt (more info ...)attempted-user  2015-4441      URL
35768FILE-PDF Adobe Reader CBBBRInvite privilege escalation attempt (more info ...)attempted-user  2015-4441      URL
35779FILE-PDF Adobe Reader XML XSL transform exploitation attempt (more info ...)attempted-recon  2017-11243      URL
35780FILE-PDF Adobe Reader XML XSL transform exploitation attempt (more info ...)attempted-recon  2017-11243      URL
35798FILE-IMAGE Adobe Acrobat malformed PCX one-byte heap overwrite attempt (more info ...)attempted-user  2015-5105      URL
35799FILE-IMAGE Adobe Acrobat malformed PCX one-byte heap overwrite attempt (more info ...)attempted-user  2015-5105      URL
35813FILE-FLASH Adobe Flash Player loadSound type confusion attempt (more info ...)attempted-user  2015-5562      URL
35814FILE-FLASH Adobe Flash Player loadSound type confusion attempt (more info ...)attempted-user  2015-5562      URL
35815FILE-FLASH Adobe Flash Player loadSound type confusion attempt (more info ...)attempted-user  2015-5562      URL
35816FILE-FLASH Adobe Flash Player loadSound type confusion attempt (more info ...)attempted-user  2015-5562      URL
35821FILE-FLASH Adobe Flash Player scale9Grid use after free attempt (more info ...)attempted-user  2015-5564      
35823FILE-FLASH Adobe Flash Player scale9Grid use after free attempt (more info ...)attempted-user  2015-5564      
35824FILE-FLASH Adobe Flash Player scale9Grid use after free attempt (more info ...)attempted-user  2015-5564      
35825FILE-FLASH Adobe Flash Player scale9Grid use after free attempt (more info ...)attempted-user  2015-5564      
35861FILE-FLASH Adobe Flash Player swapDepths use after free attempt (more info ...)attempted-admin  2015-5550      URL
35862FILE-FLASH Adobe Flash Player swapDepths use after free attempt (more info ...)attempted-admin  2015-5550      URL
35863FILE-FLASH Adobe Flash Player swapDepths use after free attempt (more info ...)attempted-admin  2015-5550      URL
35864FILE-FLASH Adobe Flash Player swapDepths use after free attempt (more info ...)attempted-admin  2015-5550      URL
35935FILE-FLASH Adobe Flash Player attachMovie use after free attempt (more info ...)attempted-admin  2015-5551      URL
35936FILE-FLASH Adobe Flash Player attachMovie use after free attempt (more info ...)attempted-admin  2015-5551      URL
35937FILE-FLASH Adobe Flash Player attachMovie use after free attempt (more info ...)attempted-admin  2015-5551      URL
35938FILE-FLASH Adobe Flash Player attachMovie use after free attempt (more info ...)attempted-admin  2015-5551      URL
35945FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35946FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35947FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35948FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35949FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35950FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35951FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35952FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35953FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35954FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
35983FILE-OTHER Microsoft Windows Media Center link file code execution attempt (more info ...)attempted-user  2016-0185  90023    URL
36113FILE-MULTIMEDIA Adobe Flash Player ID3 tag integer overflow attempt (more info ...)attempted-user  2015-5560  76289    URL
36114FILE-MULTIMEDIA Adobe Flash Player ID3 tag integer overflow attempt (more info ...)attempted-user  2015-5560  76289    URL
36120FILE-FLASH Adobe Flash Player regexp heap buffer overflow attempt (more info ...)attempted-admin  2015-5129      URL
36121FILE-FLASH Adobe Flash Player regexp heap buffer overflow attempt (more info ...)attempted-admin  2015-5129      URL
36122FILE-FLASH Adobe Flash Player regexp heap buffer overflow attempt (more info ...)attempted-admin  2015-5129      URL
36123FILE-FLASH Adobe Flash Player regexp heap buffer overflow attempt (more info ...)attempted-admin  2015-5129      URL
36124FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36125FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36126FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36127FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36128FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36129FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36135FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36136FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36137FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36138FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36139FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36140FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36141FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36142FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36143FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-7659  73084    URL
36144FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
36145FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-7659  73084    URL
36146FILE-FLASH Adobe Flash Player NetConnection AS2 arbitrary code execution attempt (more info ...)attempted-user  2015-0336  73084    URL
36149FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36150FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36151FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36152FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
36154FILE-FLASH Adobe Flash Player ByteArray domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
36155FILE-FLASH Adobe Flash Player ByteArray domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
36156FILE-FLASH Adobe Flash Player ByteArray domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
36157FILE-FLASH Adobe Flash Player ByteArray domainMemory use after free attempt (more info ...)attempted-user  2015-0311  72283    URL
36160FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36161FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36162FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36163FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36164FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36165FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36166FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36167FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36168FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36169FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36170FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36171FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36172FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36173FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36174FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36175FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36176FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36177FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
36187FILE-FLASH Adobe Flash Player display list use after free attempt (more info ...)attempted-user  2015-5543      URL
36188FILE-FLASH Adobe Flash Player display list use after free attempt (more info ...)attempted-user  2015-5543      URL
36189FILE-FLASH Adobe Flash Player display list use after free attempt (more info ...)attempted-user  2015-5543      URL
36190FILE-FLASH Adobe Flash Player display list use after free attempt (more info ...)attempted-user  2015-5543      URL
36193FILE-FLASH Adobe Flash Player Exploit Kit decryption key detected (more info ...)attempted-user  2015-5119      URL
36208FILE-MULTIMEDIA Apple Quicktime invalid url atom out of bounds read attempt (more info ...)attempted-user  2015-3788      URL
36209FILE-MULTIMEDIA Apple Quicktime invalid url atom out of bounds read attempt (more info ...)attempted-user  2015-3788      URL
36229FILE-FLASH Adobe Flash Player On2 VP6 video codec fragment read access violation attempt (more info ...)denial-of-service  2015-3788      URL
36230FILE-FLASH Adobe Flash Player On2 VP6 video codec fragment read access violation attempt (more info ...)denial-of-service  2015-3788      URL
36257FILE-FLASH Adobe Flash Player ByteArray writeByte buffer overflow attempt (more info ...)attempted-user  2015-6676      URL
36258FILE-FLASH Adobe Flash Player ByteArray writeByte buffer overflow attempt (more info ...)attempted-user  2015-6676      URL
36259FILE-FLASH Adobe Flash Player ByteArray writeByte buffer overflow attempt (more info ...)attempted-user  2015-6676      URL
36260FILE-FLASH Adobe Flash Player ByteArray writeByte buffer overflow attempt (more info ...)attempted-user  2015-6676      URL
36263FILE-FLASH Adobe Flash Player URLStreamObject out of bounds read attempt (more info ...)attempted-user  2015-5573      URL
36264FILE-FLASH Adobe Flash Player URLStreamObject out of bounds read attempt (more info ...)attempted-user  2015-5573      URL
36265FILE-FLASH Adobe Flash Player URLStreamObject out of bounds read attempt (more info ...)attempted-user  2015-5573      URL
36266FILE-FLASH Adobe Flash Player URLStreamObject out of bounds read attempt (more info ...)attempted-user  2015-5573      URL
36287FILE-FLASH Adobe Flash Player avc_core out of bounds memory access attempt (more info ...)attempted-user  2015-5579      URL
36288FILE-FLASH Adobe Flash Player avc_core out of bounds memory access attempt (more info ...)attempted-user  2015-5579      URL
36289FILE-FLASH Adobe Flash Player NetStream.appendBytes use after free attempt (more info ...)attempted-user  2015-6682      URL
36290FILE-FLASH Adobe Flash Player NetStream.appendBytes use after free attempt (more info ...)attempted-user  2015-6682      URL
36291FILE-FLASH Adobe Flash Player NetStream.appendBytes use after free attempt (more info ...)attempted-user  2015-6682      URL
36292FILE-FLASH Adobe Flash Player NetStream.appendBytes use after free attempt (more info ...)attempted-user  2015-6682      URL
36295FILE-FLASH Adobe Flash Player movie signed integer memory corruption attempt (more info ...)attempted-user  2015-5582      URL
36296FILE-FLASH Adobe Flash Player movie signed integer memory corruption attempt (more info ...)attempted-user  2015-5582      URL
36297FILE-FLASH Adobe Flash Player video decode use after free attempt (more info ...)attempted-user  2015-5584      URL
36298FILE-FLASH Adobe Flash Player video decode use after free attempt (more info ...)attempted-user  2015-5584      URL
36299FILE-FLASH Adobe Flash Player ShaderParameter out of bounds write attempt (more info ...)attempted-user  2015-3105  75086    URL
36300FILE-FLASH Adobe Flash Player ShaderParameter out of bounds write attempt (more info ...)attempted-user  2015-3105  75086    URL
36301FILE-FLASH Adobe Flash Player ShaderParameter out of bounds write attempt (more info ...)attempted-user  2015-3105  75086    URL
36302FILE-FLASH Adobe Flash Player ShaderParameter out of bounds write attempt (more info ...)attempted-user  2015-3105  75086    URL
36311FILE-FLASH Adobe Flash Player class scope bypass attempt (more info ...)attempted-user  2015-5588      URL
36312FILE-FLASH Adobe Flash Player class scope bypass attempt (more info ...)attempted-user  2015-5588      URL
36313FILE-FLASH Adobe Flash Player class scope bypass attempt (more info ...)attempted-user  2015-5588      URL
36314FILE-FLASH Adobe Flash Player class scope bypass attempt (more info ...)attempted-user  2015-5588      URL
36318FILE-FLASH Adobe Flash Player Netstream Video null pointer dereference attempt (more info ...)attempted-user  2015-5575      URL
36319FILE-FLASH Adobe Flash Player Netstream Video null pointer dereference attempt (more info ...)attempted-user  2015-5575      URL
36321FILE-FLASH Adobe Flash Player removeChildren use-after-free attempt (more info ...)attempted-user  2015-5581      URL
36322FILE-FLASH Adobe Flash Player removeChildren use-after-free attempt (more info ...)attempted-user  2015-5581      URL
36323FILE-FLASH Adobe Flash Player removeChildren use-after-free attempt (more info ...)attempted-user  2015-5581      URL
36324FILE-FLASH Adobe Flash Player removeChildren use-after-free attempt (more info ...)attempted-user  2015-5581      URL
36338MALWARE-OTHER Apple iTunes Connect HTTP response phishing attempt (more info ...)trojan-activity        URL
36339FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36340FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36341FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36342FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36343FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36344FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36345FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36346FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36347FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36348FILE-FLASH Adobe Flash Player DisplayList memory corruption attempt (more info ...)attempted-user  2015-5587      URL
36351FILE-FLASH Adobe Flash Player AVSS null pointer attempt (more info ...)attempted-user  2015-5570      URL
36352FILE-FLASH Adobe Flash Player AVSS null pointer attempt (more info ...)attempted-user  2015-5567      URL
36353FILE-FLASH Adobe Flash Player AVSS null pointer attempt (more info ...)attempted-user  2015-5567      URL
36354FILE-FLASH Adobe Flash Player AVSS null pointer attempt (more info ...)attempted-user  2015-5570      URL
36355FILE-FLASH Adobe Flash Player AVSS null pointer attempt (more info ...)attempted-user  2015-5567      URL
36356FILE-FLASH Adobe Flash Player AVSS null pointer attempt (more info ...)attempted-user  2015-5567      URL
36357FILE-FLASH Adobe Flash Player AVSegmentedSource null pointer attempt (more info ...)attempted-user  2015-5567      URL
36358FILE-FLASH Adobe Flash Player AVSegmentedSource null pointer attempt (more info ...)attempted-user  2015-5567      URL
36367FILE-FLASH Adobe Flash Player DefineText buffer overflow attempt (more info ...)attempted-user  2015-6678      URL
36368FILE-FLASH Adobe Flash Player DefineText buffer overflow attempt (more info ...)attempted-user  2015-6678      URL
36369FILE-FLASH Adobe Flash Player DefineText buffer overflow attempt (more info ...)attempted-user  2015-6678      URL
36370FILE-FLASH Adobe Flash Player DefineText buffer overflow attempt (more info ...)attempted-user  2015-6678      URL
36371FILE-FLASH Adobe Flash Player invalid vector length memory corruption attempt (more info ...)attempted-user  2015-5568      URL
36372FILE-FLASH Adobe Flash Player invalid vector length memory corruption attempt (more info ...)attempted-user  2015-5568      URL
36373FILE-FLASH Adobe Flash Player invalid vector length memory corruption attempt (more info ...)attempted-user  2015-5568      URL
36374FILE-FLASH Adobe Flash Player invalid vector length memory corruption attempt (more info ...)attempted-user  2015-5568      URL
36398FILE-FLASH Adobe Flash Player Ovector out of bounds stack corruption attempt (more info ...)attempted-user  2015-0330      URL
36399FILE-FLASH Adobe Flash Player Ovector out of bounds stack corruption attempt (more info ...)attempted-user  2015-0330      URL
36502FILE-FLASH Adobe Flash Player scrollRect property use after free attempt (more info ...)attempted-admin  2015-5130      URL
36503FILE-FLASH Adobe Flash Player scrollRect property use after free attempt (more info ...)attempted-admin  2015-5130      URL
36504FILE-FLASH Adobe Flash Player scrollRect property use after free attempt (more info ...)attempted-admin  2015-5130      URL
36505FILE-FLASH Adobe Flash Player scrollRect property use after free attempt (more info ...)attempted-admin  2015-5130      URL
36507FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
36508FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
36509FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
36510FILE-FLASH Adobe Flash Player ActionScript worker use after free attempt (more info ...)attempted-user  2015-0313  72429    URL
36512FILE-MULTIMEDIA Adobe Flash Player malformed mp4 CABAC encoding out of bounds read attempt (more info ...)attempted-user  2015-5580      URL
36513FILE-MULTIMEDIA Adobe Flash Player malformed mp4 CABAC encoding out of bounds read attempt (more info ...)attempted-user  2015-5580      URL
36527FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
36528FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
36529FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
36530FILE-FLASH Adobe Flash Player and AIR type confusion remote code execution attempt (more info ...)attempted-user  2013-5331  64199    URL
36549FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36550FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7647      URL
36551FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7647      URL
36552FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36553FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36554FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36555FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36556FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36573FILE-FLASH Adobe Flash Player recursion check stack overflow attempt (more info ...)attempted-user  2015-7625      URL
36574FILE-FLASH Adobe Flash Player recursion check stack overflow attempt (more info ...)attempted-user  2015-7625      URL
36575FILE-FLASH Adobe Flash Player recursion check stack overflow attempt (more info ...)attempted-user  2015-7625      URL
36576FILE-FLASH Adobe Flash Player recursion check stack overflow attempt (more info ...)attempted-user  2015-7625      URL
36581FILE-FLASH Adobe Flash Player PCRE engine find_recurse out-of-bounds read attempt (more info ...)attempted-user  2015-7633      URL
36582FILE-FLASH Adobe Flash Player PCRE engine find_recurse out-of-bounds read attempt (more info ...)attempted-user  2015-7633      URL
36583FILE-FLASH Adobe Flash Player PCRE engine find_recurse out-of-bounds read attempt (more info ...)attempted-user  2015-7633      URL
36584FILE-FLASH Adobe Flash Player PCRE engine find_recurse out-of-bounds read attempt (more info ...)attempted-user  2015-7633      URL
36586FILE-FLASH Adobe Flash Player message handler array length overflow attempt (more info ...)attempted-user  2015-7629      URL
36587FILE-FLASH Adobe Flash Player message handler array length overflow attempt (more info ...)attempted-user  2015-7629      URL
36588FILE-FLASH Adobe Flash Player message handler array length overflow attempt (more info ...)attempted-user  2015-7629      URL
36589FILE-FLASH Adobe Flash Player message handler array length overflow attempt (more info ...)attempted-user  2015-7629      URL
36590FILE-FLASH Adobe Flash Player textLine use-after-free attempt (more info ...)attempted-user  2015-7631      URL
36591FILE-FLASH Adobe Flash Player textLine use-after-free attempt (more info ...)attempted-user  2015-7631      URL
36592FILE-FLASH Adobe Flash Player textLine use-after-free attempt (more info ...)attempted-user  2015-7631      URL
36593FILE-FLASH Adobe Flash Player textLine use-after-free attempt (more info ...)attempted-user  2015-7631      URL
36597FILE-FLASH Adobe Flash Player assertion out of bounds corruption attempt (more info ...)attempted-user  2015-7627      URL
36598FILE-FLASH Adobe Flash Player assertion out of bounds corruption attempt (more info ...)attempted-user  2015-7627      URL
36599FILE-FLASH Adobe Flash Player assertion out of bounds corruption attempt (more info ...)attempted-user  2015-7627      URL
36600FILE-FLASH Adobe Flash Player assertion out of bounds corruption attempt (more info ...)attempted-user  2015-7627      URL
36755FILE-FLASH Adobe Flash Player loadBytes buffer overflow remote code execution attempt (more info ...)attempted-admin  2015-7632      URL
36756FILE-FLASH Adobe Flash Player loadBytes buffer overflow remote code execution attempt (more info ...)attempted-admin  2015-7632      URL
36757FILE-FLASH Adobe Flash Player loadBytes buffer overflow remote code execution attempt (more info ...)attempted-admin  2015-7632      URL
36758FILE-FLASH Adobe Flash Player loadBytes buffer overflow remote code execution attempt (more info ...)attempted-admin  2015-7632      URL
36819FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36820FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36821FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36822FILE-FLASH Adobe Flash Player AS3 opaqueBackground use-after-free attempt (more info ...)attempted-user  2015-5122  75712    URL
36827FILE-FLASH Adobe Flash Player AS2 actionExtends use-after-free attempt (more info ...)attempted-user  2015-7655      URL
36828FILE-FLASH Adobe Flash Player AS2 actionExtends use-after-free attempt (more info ...)attempted-user  2015-7655      URL
36829FILE-FLASH Adobe Flash Player AS2 actionExtends use-after-free attempt (more info ...)attempted-user  2015-7655      URL
36830FILE-FLASH Adobe Flash Player AS2 actionExtends use-after-free attempt (more info ...)attempted-user  2015-7655      URL
36831FILE-FLASH Adobe Flash Player AS2 actionExtends use-after-free attempt (more info ...)attempted-user  2015-7655      URL
36832FILE-FLASH Adobe Flash Player AS2 actionExtends use-after-free attempt (more info ...)attempted-user  2015-7655      URL
36836FILE-FLASH Adobe Flash Player toString with script objects use after free attempt (more info ...)attempted-user  2015-8042      URL
36837FILE-FLASH Adobe Flash Player toString with script objects use after free attempt (more info ...)attempted-user  2015-8042      URL
36838FILE-FLASH Adobe Flash Player file API validation bypass attempt (more info ...)attempted-user  2015-7662      URL
36839FILE-FLASH Adobe Flash Player file API validation bypass attempt (more info ...)attempted-user  2015-7662      URL
36842FILE-FLASH Adobe Flash Player MovieClip object corruption use after free attempt (more info ...)attempted-user  2015-7660      URL
36843FILE-FLASH Adobe Flash Player MovieClip object corruption use after free attempt (more info ...)attempted-user  2015-7660      URL
36844FILE-FLASH Adobe Flash Player AS2 TextField gridFitType use after free attempt (more info ...)attempted-user  2015-7652      URL
36845FILE-FLASH Adobe Flash Player AS2 TextField gridFitType use after free attempt (more info ...)attempted-user  2015-7652      URL
36846FILE-FLASH Adobe Flash Player AS2 TextField gridFitType use after free attempt (more info ...)attempted-user  2015-7652      URL
36847FILE-FLASH Adobe Flash Player AS2 TextField gridFitType use after free attempt (more info ...)attempted-user  2015-7652      URL
36848FILE-FLASH Adobe Flash Player GetConsoleMode input action variable corruption attempt (more info ...)attempted-user  2015-7651      URL
36849FILE-FLASH Adobe Flash Player GetConsoleMode input action variable corruption attempt (more info ...)attempted-user  2015-7651      URL
36850FILE-FLASH Adobe Flash Player globalToLocal use-after-free attempt (more info ...)attempted-user  2015-7653      URL
36851FILE-FLASH Adobe Flash Player globalToLocal use-after-free attempt (more info ...)attempted-user  2015-7653      URL
36852FILE-FLASH Adobe Flash Player globalToLocal use-after-free attempt (more info ...)attempted-user  2015-7653      URL
36853FILE-FLASH Adobe Flash Player globalToLocal use-after-free attempt (more info ...)attempted-user  2015-7653      URL
36858FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36859FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36860FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
36861FILE-FLASH Adobe Flash Player attachsound use-after-free attempt (more info ...)attempted-user  2015-7654      
36862FILE-FLASH Adobe Flash Player attachsound use-after-free attempt (more info ...)attempted-user  2015-7654      
36863FILE-FLASH Adobe Flash Player attachsound use-after-free attempt (more info ...)attempted-user  2015-7654      
36864FILE-FLASH Adobe Flash Player attachsound use-after-free attempt (more info ...)attempted-user  2015-7654      
36873FILE-FLASH Adobe Flash Player AS2 valueOf function assignment with removeTextField use after free attempt (more info ...)attempted-user  2015-8447      URL
36874FILE-FLASH Adobe Flash Player AS2 valueOf function assignment with removeTextField use after free attempt (more info ...)attempted-user  2015-8447      URL
36875FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
36876FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
36878FILE-FLASH Adobe Flash Player SWF buffer overflow attempt (more info ...)attempted-user  2015-0327      URL
36879FILE-FLASH Adobe Flash Player SWF buffer overflow attempt (more info ...)attempted-user  2015-0327      URL
36880FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
36881FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
36882FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
36883FILE-FLASH Adobe Flash Player byte array uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
36885FILE-PDF Adobe Acrobat font parsing integer overflow attempt (more info ...)attempted-admin  2010-2862  42203    URL
36886FILE-PDF Adobe Acrobat font parsing integer overflow attempt (more info ...)attempted-admin  2010-2862  42203    URL
36897FILE-FLASH Adobe Flash Player ActionScript ProgressBar use after free attempt (more info ...)attempted-user  2015-7663      URL
36898FILE-FLASH Adobe Flash Player ActionScript ProgressBar use after free attempt (more info ...)attempted-user  2015-7663      URL
37069FILE-FLASH Adobe Flash Player object Filters type confusion use after free attempt (more info ...)attempted-user  2015-8442      URL
37070FILE-FLASH Adobe Flash Player object Filters type confusion use after free attempt (more info ...)attempted-user  2015-8442      URL
37071FILE-FLASH Adobe Flash Player ShaderParameter integer overflow attempt (more info ...)attempted-user  2015-8445      URL
37072FILE-FLASH Adobe Flash Player ShaderParameter integer overflow attempt (more info ...)attempted-user  2015-8445      URL
37073FILE-FLASH Adobe Flash Player ShaderParameter integer overflow attempt (more info ...)attempted-user  2015-8445      URL
37074FILE-FLASH Adobe Flash Player ShaderParameter integer overflow attempt (more info ...)attempted-user  2015-8445      URL
37075FILE-FLASH Adobe Flash Player ShaderParameter integer overflow attempt (more info ...)attempted-user  2015-8445      URL
37076FILE-FLASH Adobe Flash Player ShaderParameter integer overflow attempt (more info ...)attempted-user  2015-8445      URL
37079FILE-FLASH Adobe Flash Player String length heap buffer overflow attempt (more info ...)attempted-user  2015-8438      URL
37080FILE-FLASH Adobe Flash Player String length heap buffer overflow attempt (more info ...)attempted-user  2015-8438      URL
37081FILE-FLASH Adobe Flash Player String length heap buffer overflow attempt (more info ...)attempted-user  2015-8438      URL
37082FILE-FLASH Adobe Flash Player String length heap buffer overflow attempt (more info ...)attempted-user  2015-8438      URL
37083FILE-FLASH Adobe Flash Player byte array memory corruption attempt (more info ...)attempted-user  2015-8060      URL
37084FILE-FLASH Adobe Flash Player byte array memory corruption attempt (more info ...)attempted-user  2015-8060      URL
37085FILE-FLASH Adobe Flash Player byte array memory corruption attempt (more info ...)attempted-user  2015-8060      URL
37086FILE-FLASH Adobe Flash Player byte array memory corruption attempt (more info ...)attempted-user  2015-8060      URL
37088FILE-FLASH Adobe Flash Player PrintJob object use-after-free attempt (more info ...)attempted-user  2015-8436      URL
37089FILE-FLASH Adobe Flash Player PrintJob object use-after-free attempt (more info ...)attempted-user  2015-8436      URL
37090FILE-FLASH Adobe Flash Player PrintJob object use-after-free attempt (more info ...)attempted-user  2015-8436      URL
37091FILE-FLASH Adobe Flash Player PrintJob object use-after-free attempt (more info ...)attempted-user  2015-8436      URL
37092FILE-FLASH Adobe Flash Player SoundURLStream memory corruption attempt (more info ...)attempted-user  2015-8408  78710    URL
37093FILE-FLASH Adobe Flash Player SoundURLStream memory corruption attempt (more info ...)attempted-user  2015-8408  78710    URL
37094FILE-FLASH Adobe Flash Player SoundURLStream memory corruption attempt (more info ...)attempted-user  2015-8408  78710    URL
37095FILE-FLASH Adobe Flash Player SoundURLStream memory corruption attempt (more info ...)attempted-user  2015-8408  78710    URL
37103FILE-FLASH Adobe Flash Player MovieClip object use-after-free attempt (more info ...)attempted-user  2015-8449      URL
37104FILE-FLASH Adobe Flash Player MovieClip object use-after-free attempt (more info ...)attempted-user  2015-8449      URL
37105FILE-FLASH Adobe Flash Player MovieClip object use-after-free attempt (more info ...)attempted-user  2015-8449      URL
37106FILE-FLASH Adobe Flash Player MovieClip object use-after-free attempt (more info ...)attempted-user  2015-8449      URL
37107FILE-FLASH Adobe Flash Player selection.setFocus use after free attempt (more info ...)attempted-user  2015-8437      URL
37108FILE-FLASH Adobe Flash Player selection.setFocus use after free attempt (more info ...)attempted-user  2015-8437      URL
37109FILE-FLASH Adobe Flash Player selection.setFocus use after free attempt (more info ...)attempted-user  2015-8437      URL
37110FILE-FLASH Adobe Flash Player selection.setFocus use after free attempt (more info ...)attempted-user  2015-8437      URL
37111FILE-FLASH Adobe Flash Player PCRE parsing out of bounds read attempt (more info ...)attempted-user  2015-8418  78710    URL
37112FILE-FLASH Adobe Flash Player PCRE parsing out of bounds read attempt (more info ...)attempted-user  2015-8418  78710    URL
37113FILE-FLASH Adobe Flash Player PCRE parsing out of bounds read attempt (more info ...)attempted-user  2015-8418  78710    URL
37114FILE-FLASH Adobe Flash Player PCRE parsing out of bounds read attempt (more info ...)attempted-user  2015-8418  78710    URL
37115FILE-FLASH Adobe Flash Player DisplacementMapFilter mapBitmap use after free attempt (more info ...)attempted-user  2015-8448      
37116FILE-FLASH Adobe Flash Player DisplacementMapFilter mapBitmap use after free attempt (more info ...)attempted-user  2015-8448      
37118FILE-FLASH Adobe Flash Player TextField filters use-after-free attempt (more info ...)attempted-user  2015-8450      URL
37119FILE-FLASH Adobe Flash Player TextField filters use-after-free attempt (more info ...)attempted-user  2015-8450      URL
37121FILE-FLASH Adobe Flash Player MP3 ID3 data parsing heap buffer overflow attempt (more info ...)attempted-user  2015-8446  78712    URL
37122FILE-FLASH Adobe Flash Player MP3 ID3 data parsing heap buffer overflow attempt (more info ...)attempted-user  2015-8446  78712    URL
37123FILE-FLASH Adobe Flash Player MP3 ID3 data parsing heap buffer overflow attempt (more info ...)attempted-user  2015-8446  78712    URL
37124FILE-FLASH Adobe Flash Player MP3 ID3 data parsing heap buffer overflow attempt (more info ...)attempted-user  2015-8446  78712    URL
37125FILE-FLASH Adobe Flash Player MP3 ID3 data parsing heap buffer overflow attempt (more info ...)attempted-user  2015-8446  78712    URL
37126FILE-FLASH Adobe Flash Player MP3 ID3 data parsing heap buffer overflow attempt (more info ...)attempted-user  2015-8446  78712    URL
37128FILE-FLASH Adobe Flash Player AS2 setTransform use-after-free attempt (more info ...)attempted-user  2015-8447      URL
37129FILE-FLASH Adobe Flash Player AS2 setTransform use-after-free attempt (more info ...)attempted-user  2015-8447      URL
37142FILE-FLASH Adobe Flash Player SetSlot type confusion attempt (more info ...)attempted-user  2015-8439      URL
37143FILE-FLASH Adobe Flash Player SetSlot type confusion attempt (more info ...)attempted-user  2015-8439      URL
37144FILE-FLASH Adobe Flash Player SetSlot type confusion attempt (more info ...)attempted-user  2015-8439      URL
37145FILE-FLASH Adobe Flash Player SetSlot type confusion attempt (more info ...)attempted-user  2015-8439      URL
37149FILE-FLASH Adobe Flash Player MP3 ID3 data parsing heap buffer overflow attempt (more info ...)attempted-user  2015-8446  78712    URL
37150FILE-FLASH Adobe Flash Player MP3 ID3 data parsing heap buffer overflow attempt (more info ...)attempted-user  2015-8446  78712    URL
37156FILE-FLASH Adobe Flash Player SharedObject send stack buffer overflow attempt (more info ...)attempted-user  2015-8407      URL
37157FILE-FLASH Adobe Flash Player SharedObject send stack buffer overflow attempt (more info ...)attempted-user  2015-8407      URL
37158FILE-FLASH Adobe Flash Player SharedObject send stack buffer overflow attempt (more info ...)attempted-user  2015-8407      URL
37159FILE-FLASH Adobe Flash Player SharedObject send stack buffer overflow attempt (more info ...)attempted-user  2015-8407      URL
37160FILE-FLASH Adobe Flash Player oversize source bitmap memory corruption attempt (more info ...)attempted-user  2015-8419      URL
37161FILE-FLASH Adobe Flash Player oversize source bitmap memory corruption attempt (more info ...)attempted-user  2015-8419      URL
37162FILE-FLASH Adobe Flash Player oversize source bitmap memory corruption attempt (more info ...)attempted-user  2015-8419      URL
37163FILE-FLASH Adobe Flash Player oversize source bitmap memory corruption attempt (more info ...)attempted-user  2015-8419      URL
37165FILE-FLASH Adobe Flash Player URLStream use after free attempt (more info ...)attempted-user  2015-8048      URL
37166FILE-FLASH Adobe Flash Player URLStream use after free attempt (more info ...)attempted-user  2015-8048      URL
37167FILE-FLASH Adobe Flash Player URLStream use after free attempt (more info ...)attempted-user  2015-8048      URL
37168FILE-FLASH Adobe Flash Player URLStream use after free attempt (more info ...)attempted-user  2015-8048      URL
37169FILE-FLASH Adobe Flash Player heap memory disclosure via custom valueOf handler attempt (more info ...)attempted-recon  2015-8414      URL
37170FILE-FLASH Adobe Flash Player heap memory disclosure via custom valueOf handler attempt (more info ...)attempted-recon  2015-8414      URL
37171FILE-FLASH Adobe Flash Player heap memory disclosure via custom valueOf handler attempt (more info ...)attempted-recon  2015-8414      URL
37172FILE-FLASH Adobe Flash Player heap memory disclosure via custom valueOf handler attempt (more info ...)attempted-recon  2015-8414      URL
37173FILE-FLASH Adobe Flash Player heap memory disclosure via custom valueOf handler attempt (more info ...)attempted-recon  2015-8414      URL
37174FILE-FLASH Adobe Flash Player heap memory disclosure via custom valueOf handler attempt (more info ...)attempted-recon  2015-8414      URL
37175FILE-FLASH Adobe Flash Player heap memory disclosure via custom valueOf handler attempt (more info ...)attempted-recon  2015-8414      URL
37176FILE-FLASH Adobe Flash Player heap memory disclosure via custom valueOf handler attempt (more info ...)attempted-recon  2015-8414      URL
37177FILE-FLASH Adobe Flash Player M3U8 parser logic memory corruption attempt (more info ...)attempted-user  2015-8457      URL
37178FILE-FLASH Adobe Flash Player M3U8 parser logic memory corruption attempt (more info ...)attempted-user  2015-8457      URL
37179FILE-FLASH Adobe Flash Player M3U8 parser logic memory corruption attempt (more info ...)attempted-user  2015-8457      URL
37180FILE-FLASH Adobe Flash Player M3U8 parser logic memory corruption attempt (more info ...)attempted-user  2015-8457      URL
37182FILE-FLASH Adobe Flash Player String null check memory corruption attempt (more info ...)attempted-user  2015-8444      URL
37183FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37184FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37185FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37186FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37187FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37188FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37189FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37190FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37191FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37192FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37193FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37194FILE-FLASH Adobe Flash Player TextFormat.tabStops use after free attempt (more info ...)attempted-user  2015-8435      URL
37199FILE-FLASH Adobe Flash Player multiple script render display use after free attempt (more info ...)attempted-user  2015-8635      URL
37200FILE-FLASH Adobe Flash Player multiple script render display use after free attempt (more info ...)attempted-user  2015-8635      URL
37201FILE-FLASH Adobe Flash Standalone Player ASSetPropFlags use after free attempt (more info ...)attempted-user  2015-8646      URL
37202FILE-FLASH Adobe Flash Standalone Player ASSetPropFlags use after free attempt (more info ...)attempted-user  2015-8646      URL
37203FILE-FLASH Adobe Flash Player object.addProperty method use after free attempt (more info ...)attempted-user  2015-8640      URL
37204FILE-FLASH Adobe Flash Player object.addProperty method use after free attempt (more info ...)attempted-user  2015-8640      URL
37205FILE-FLASH Adobe Flash Player object.addProperty method use after free attempt (more info ...)attempted-user  2015-8640      URL
37206FILE-FLASH Adobe Flash Player object.addProperty method use after free attempt (more info ...)attempted-user  2015-8640      URL
37208FILE-FLASH Adobe Flash Player LoadVars decode use after free attempt (more info ...)attempted-user  2015-8650      URL
37209FILE-FLASH Adobe Flash Player LoadVars decode use after free attempt (more info ...)attempted-user  2015-8650      URL
37210FILE-FLASH Adobe Flash Player LoadVars decode use after free attempt (more info ...)attempted-user  2015-8650      URL
37211FILE-FLASH Adobe Flash Player LoadVars decode use after free attempt (more info ...)attempted-user  2015-8650      URL
37216FILE-FLASH Adobe Flash Player MovieClip setMask use after free attempt (more info ...)attempted-user  2015-8648      URL
37217FILE-FLASH Adobe Flash Player MovieClip setMask use after free attempt (more info ...)attempted-user  2015-8648      URL
37218FILE-FLASH Adobe Flash Player MovieClip setMask use after free attempt (more info ...)attempted-user  2015-8648      URL
37219FILE-FLASH Adobe Flash Player MovieClip setMask use after free attempt (more info ...)attempted-user  2015-8648      URL
37220FILE-FLASH Adobe Flash Player Date with invalid parameter toTimeString attempt (more info ...)attempted-user  2015-8645      URL
37221FILE-FLASH Adobe Flash Player Date with invalid parameter toTimeString attempt (more info ...)attempted-user  2015-8645      URL
37223FILE-FLASH Adobe Flash Player overly large bitmap integer overflow attempt (more info ...)attempted-user  2015-8460      URL
37224FILE-FLASH Adobe Flash Player overly large bitmap integer overflow attempt (more info ...)attempted-user  2015-8460      URL
37229FILE-FLASH Adobe Flash Player MovieClip method use after free attempt (more info ...)attempted-user  2016-7862      URL
37230FILE-FLASH Adobe Flash Player MovieClip method use after free attempt (more info ...)attempted-user  2016-7862      URL
37231FILE-FLASH Adobe Flash Player getBounds method use after free attempt (more info ...)attempted-user  2015-8638      URL
37232FILE-FLASH Adobe Flash Player getBounds method use after free attempt (more info ...)attempted-user  2015-8638      URL
37234FILE-FLASH Adobe Flash Player removeMovieClip use after free attempt (more info ...)attempted-user  2016-1017      URL
37235FILE-FLASH Adobe Flash Player removeMovieClip use after free attempt (more info ...)attempted-user  2016-1017      URL
37236FILE-FLASH Adobe Flash Player object hasOwnProperty use after free attempt (more info ...)attempted-user  2015-8649      URL
37237FILE-FLASH Adobe Flash Player object hasOwnProperty use after free attempt (more info ...)attempted-user  2015-8649      URL
37238FILE-FLASH Adobe Flash Player object hasOwnProperty use after free attempt (more info ...)attempted-user  2015-8649      URL
37239FILE-FLASH Adobe Flash Player object hasOwnProperty use after free attempt (more info ...)attempted-user  2015-8649      URL
37240FILE-FLASH Adobe Flash Player canvas out of bounds read attempt (more info ...)attempted-user  2015-8636      URL
37241FILE-FLASH Adobe Flash Player canvas out of bounds read attempt (more info ...)attempted-user  2015-8636      URL
37247FILE-FLASH Adobe Flash Player removeMovieClip use after free attempt (more info ...)attempted-user  2015-8642      URL
37248FILE-FLASH Adobe Flash Player removeMovieClip use after free attempt (more info ...)attempted-user  2015-8641      URL
37249FILE-FLASH Adobe Flash Player removeMovieClip use after free attempt (more info ...)attempted-user  2015-8643      URL
37250FILE-FLASH Adobe Flash Player removeMovieClip use after free attempt (more info ...)attempted-user  2015-8642      URL
37251FILE-FLASH Adobe Flash Player removeMovieClip use after free attempt (more info ...)attempted-user  2015-8641      URL
37252FILE-FLASH Adobe Flash Player removeMovieClip use after free attempt (more info ...)attempted-user  2015-8643      URL
37254FILE-FLASH Adobe Flash Player improper display list handling memory corruption attempt (more info ...)attempted-user  2015-8459      URL
37256FILE-FLASH Adobe Flash Player improper display list handling memory corruption attempt (more info ...)attempted-user  2015-8459      URL
37344FILE-FLASH Adobe Flash Player improper display list handling memory corruption attempt (more info ...)attempted-user  2015-8459      URL
37345FILE-FLASH Adobe Flash Player improper display list handling memory corruption attempt (more info ...)attempted-user  2015-8459      URL
37346FILE-FLASH Adobe Flash Player improper display list handling memory corruption attempt (more info ...)attempted-user  2015-8459      URL
37347FILE-FLASH Adobe Flash Player improper display list handling memory corruption attempt (more info ...)attempted-user  2015-8459      URL
37350FILE-FLASH Adobe Flash Player invalid parent pointer use after free attempt (more info ...)attempted-user  2015-8634      URL
37351FILE-FLASH Adobe Flash Player invalid parent pointer use after free attempt (more info ...)attempted-user  2015-8634      URL
37352FILE-FLASH Adobe Flash Player SimpleButton constructor type confusion attempt (more info ...)attempted-user  2015-8644      URL
37353FILE-FLASH Adobe Flash Player SimpleButton constructor type confusion attempt (more info ...)attempted-user  2015-8644      URL
37397FILE-PDF Adobe Acrobat Reader malformed UTF-16 string memory corruption attempt (more info ...)attempted-user  2016-0939      URL
37398FILE-PDF Adobe Acrobat Reader malformed UTF-16 string memory corruption attempt (more info ...)attempted-user  2016-0939      URL
37399FILE-PDF Adobe Acrobat Reader custom string length function memory corruption attempt (more info ...)attempted-user  2016-0938      URL
37400FILE-PDF Adobe Acrobat Reader custom string length function memory corruption attempt (more info ...)attempted-user  2016-0938      URL
37424FILE-PDF Adobe Acrobat Reader ExtGState double free attempt (more info ...)attempted-user  2016-0935      URL
37425FILE-PDF Adobe Acrobat Reader ExtGState double free attempt (more info ...)attempted-user  2016-0935      URL
37433FILE-PDF Adobe Reader setPersistent use after free attempt (more info ...)attempted-user  2016-0941  80358    URL
37434FILE-PDF Adobe Reader setPersistent use after free attempt (more info ...)attempted-user  2016-0941  80358    URL
37448FILE-PDF Adobe Acrobat U3D Bone Weight Modifier memory corruption attempt (more info ...)attempted-user  2016-0933      URL
37449FILE-PDF Adobe Acrobat U3D Bone Weight Modifier memory corruption attempt (more info ...)attempted-user  2016-0933      URL
37450FILE-PDF Adobe Reader JPEG2000 chroma sub-pattern memory corruption attempt (more info ...)attempted-user  2016-0936      URL
37451FILE-PDF Adobe Reader JPEG2000 chroma sub-pattern memory corruption attempt (more info ...)attempted-user  2016-0936      URL
37454FILE-PDF Adobe Acrobat CoolType malformed font memory corruption attempt (more info ...)attempted-dos  2016-0945      URL
37455FILE-PDF Adobe Acrobat CoolType malformed font memory corruption attempt (more info ...)attempted-dos  2016-0945      URL
37458FILE-PDF Adobe Acrobat CoolType font representation decoding memory corruption attempt (more info ...)attempted-dos  2016-0944      URL
37459FILE-PDF Adobe Acrobat CoolType font representation decoding memory corruption attempt (more info ...)attempted-dos  2016-0944      URL
37460FILE-PDF Adobe Reader Graphic State Parameter Dictionaries use after free attempt (more info ...)attempted-user  2016-0940  80358    URL
37461FILE-PDF Adobe Reader Graphic State Parameter Dictionaries use after free attempt (more info ...)attempted-user  2016-0940  80358    URL
37469FILE-PDF Adobe Acrobat Reader null pointer dereference attempt (more info ...)denial-of-service  2016-0946      URL
37470FILE-PDF Adobe Acrobat Reader null pointer dereference attempt (more info ...)attempted-dos  2016-0946      URL
37530FILE-PDF Adobe Acrobat Reader pdfshell preview mode - possible denial of service attempt (more info ...)attempted-dos  2016-0942      URL
37531FILE-PDF Adobe Acrobat Reader pdfshell preview mode - possible denial of service attempt (more info ...)attempted-dos  2016-0942      URL
37532FILE-PDF Adobe Acrobat Reader pdfshell preview mode - possible denial of service attempt (more info ...)attempted-dos  2016-0942      URL
37533FILE-PDF Adobe Acrobat Reader pdfshell preview mode - possible denial of service attempt (more info ...)attempted-dos  2016-0942      URL
37629FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      
37630FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      
37631FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      
37632FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      
37638FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user  2015-5122      URL
37639FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user  2015-5122      URL
37640FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user  2015-5122      URL
37641FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user  2015-5122      URL
37644FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
37645FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
37652FILE-FLASH Adobe Flash Player loadPCMFromByteArray exception null pointer access attempt (more info ...)attempted-user  2016-0984      URL
37653FILE-FLASH Adobe Flash Player loadPCMFromByteArray exception null pointer access attempt (more info ...)attempted-user  2016-0984      URL
37668FILE-FLASH Adobe Flash Player convolution filter use-after-free attempt (more info ...)attempted-user  2015-0349      URL
37669FILE-FLASH Adobe Flash Player convolution filter use-after-free attempt (more info ...)attempted-user  2015-0349      URL
37670FILE-FLASH Adobe Flash Player convolution filter use-after-free attempt (more info ...)attempted-user  2015-0349      URL
37671FILE-FLASH Adobe Flash Player convolution filter use-after-free attempt (more info ...)attempted-user  2015-0349      URL
37679FILE-FLASH Adobe Flash player ASNative textField use after free attempt (more info ...)attempted-user  2016-0982      URL
37680FILE-FLASH Adobe Flash player ASNative textField use after free attempt (more info ...)attempted-user  2016-0982      URL
37684FILE-FLASH Adobe Flash Player worker shared object user-after-free attempt (more info ...)attempted-user  2014-0502      URL
37685FILE-FLASH Adobe Flash Player worker shared object user-after-free attempt (more info ...)attempted-user  2014-0502      URL
37688FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
37689FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-admin  2015-5119      URL
37708FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
37709FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
37710FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
37711FILE-FLASH Adobe Flash copyPixelsToByteArray integer overflow attempt (more info ...)attempted-user  2014-0556      URL
37720FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37721FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37722FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37723FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37734FILE-FLASH Adobe Flash Player Point object integer overflow attempt (more info ...)attempted-user  2016-0976      URL
37735FILE-FLASH Adobe Flash Player Point object integer overflow attempt (more info ...)attempted-user  2016-0976      URL
37736FILE-FLASH Adobe Flash Player Point object integer overflow attempt (more info ...)attempted-user  2016-0976      URL
37737FILE-FLASH Adobe Flash Player Point object integer overflow attempt (more info ...)attempted-user  2016-0976      URL
37738FILE-FLASH Adobe Flash Player BlurFilter memory corruption attempt (more info ...)attempted-user  2016-0964      URL
37739FILE-FLASH Adobe Flash Player BlurFilter memory corruption attempt (more info ...)attempted-user  2016-0964      URL
37740FILE-FLASH Adobe Flash Player BlurFilter memory corruption attempt (more info ...)attempted-user  2016-0964      URL
37741FILE-FLASH Adobe Flash Player BlurFilter memory corruption attempt (more info ...)attempted-user  2016-0964      URL
37742FILE-FLASH Adobe Flash Player TextLine memory corruption attempt (more info ...)attempted-user  2016-0966      URL
37743FILE-FLASH Adobe Flash Player TextLine memory corruption attempt (more info ...)attempted-user  2016-0966      URL
37744FILE-FLASH Adobe Flash Player TextLine memory corruption attempt (more info ...)attempted-user  2016-0966      URL
37745FILE-FLASH Adobe Flash Player TextLine memory corruption attempt (more info ...)attempted-user  2016-0966      URL
37746FILE-FLASH Adobe Flash Player list filter memory corruption attempt (more info ...)attempted-user  2016-0965      URL
37747FILE-FLASH Adobe Flash Player list filter memory corruption attempt (more info ...)attempted-user  2016-0965      URL
37748FILE-FLASH Adobe Flash Player TextField object Type Confusion Attempt (more info ...)attempted-user  2016-0985      URL
37749FILE-FLASH Adobe Flash Player TextField object Type Confusion Attempt (more info ...)attempted-user  2016-0985      URL
37750FILE-FLASH Adobe Flash Player FLV invalid reference frame count memory corruption attempt (more info ...)attempted-user  2016-0972      URL
37751FILE-FLASH Adobe Flash Player FLV invalid reference frame count memory corruption attempt (more info ...)attempted-user  2016-0972      URL
37752FILE-FLASH Adobe Flash Player Point object integer overflow attempt (more info ...)attempted-user  2016-0979      URL
37753FILE-FLASH Adobe Flash Player Point object integer overflow attempt (more info ...)attempted-user  2016-0979      URL
37754FILE-FLASH Adobe Flash Player Point object integer overflow attempt (more info ...)attempted-user  2016-0979      URL
37755FILE-FLASH Adobe Flash Player Point object integer overflow attempt (more info ...)attempted-user  2016-0979      URL
37756FILE-FLASH Adobe Flash Player invalid sourceRect copyPixels heap corruption attempt (more info ...)attempted-user  2018-16030      URL
37757FILE-FLASH Adobe Flash Player invalid sourceRect copyPixels heap corruption attempt (more info ...)attempted-user  2016-0968      URL
37758FILE-FLASH Adobe Flash Player invalid sourceRect copyPixels heap corruption attempt (more info ...)attempted-user  2016-0968      URL
37759FILE-FLASH Adobe Flash Player invalid sourceRect copyPixels heap corruption attempt (more info ...)attempted-user  2018-16030      URL
37760FILE-FLASH Adobe Flash Player rectangle auxiliary method integer overflow attempt (more info ...)attempted-user  2016-0977      URL
37761FILE-FLASH Adobe Flash Player rectangle auxiliary method integer overflow attempt (more info ...)attempted-user  2016-0977      URL
37762FILE-FLASH Adobe Flash Player rectangle auxiliary method integer overflow attempt (more info ...)attempted-user  2016-0977      URL
37763FILE-FLASH Adobe Flash Player rectangle auxiliary method integer overflow attempt (more info ...)attempted-user  2016-0977      URL
37764FILE-FLASH Adobe Flash Player BitmapData method memory corruption attempt (more info ...)attempted-user  2016-0969      URL
37765FILE-FLASH Adobe Flash Player BitmapData method memory corruption attempt (more info ...)attempted-user  2016-0969      URL
37766FILE-FLASH Adobe Flash Player BitmapData method memory corruption attempt (more info ...)attempted-user  2016-0969      URL
37767FILE-FLASH Adobe Flash Player BitmapData method memory corruption attempt (more info ...)attempted-user  2016-0969      URL
37768FILE-FLASH Adobe Flash Player ASnative custom getter use after free attempt (more info ...)attempted-user  2016-0983      URL
37769FILE-FLASH Adobe Flash Player ASnative custom getter use after free attempt (more info ...)attempted-user  2016-0983      URL
37770FILE-FLASH Adobe Flash Player ASnative custom getter use after free attempt (more info ...)attempted-user  2016-0983      URL
37771FILE-FLASH Adobe Flash Player ASnative custom getter use after free attempt (more info ...)attempted-user  2016-0983      URL
37772FILE-FLASH Adobe Flash Player ActionScript constructor use after free attempt (more info ...)attempted-user  2016-0975      URL
37773FILE-FLASH Adobe Flash Player ActionScript constructor use after free attempt (more info ...)attempted-user  2016-0975      URL
37774FILE-FLASH Adobe Flash Player ActionScript constructor use after free attempt (more info ...)attempted-user  2016-0975      URL
37775FILE-FLASH Adobe Flash Player ActionScript constructor use after free attempt (more info ...)attempted-user  2016-0975      URL
37776FILE-FLASH Adobe Flash Player LoadVars use-after-free attempt (more info ...)attempted-user  2016-0974      URL
37777FILE-FLASH Adobe Flash Player LoadVars use-after-free attempt (more info ...)attempted-user  2016-0974      URL
37778FILE-OTHER Adobe Flash Player unsupported video encoding remote code execution attempt (more info ...)attempted-user  2016-0967      
37779FILE-OTHER Adobe Flash Player unsupported video encoding remote code execution attempt (more info ...)attempted-user  2016-0967      
37780FILE-FLASH Adobe Flash Player ASnative memory corruption attempt (more info ...)attempted-user  2016-0981      URL
37781FILE-FLASH Adobe Flash Player ASnative memory corruption attempt (more info ...)attempted-user  2016-0981      URL
37782FILE-FLASH Adobe Flash Player malformed Adobe Texture Format heap overflow attempt (more info ...)attempted-user  2016-0971      URL
37783FILE-FLASH Adobe Flash Player malformed Adobe Texture Format heap overflow attempt (more info ...)attempted-user  2016-0971      URL
37784FILE-IDENTIFY Adobe Texture Format file magic detected (more info ...)misc-activity        
37785FILE-IDENTIFY Adobe Texture Format file attachment detected (more info ...)misc-activity        
37786FILE-IDENTIFY Adobe Texture Format file attachment detected (more info ...)misc-activity        
37787FILE-IDENTIFY Adobe Texture Format file magic detected (more info ...)misc-activity        
37788FILE-IDENTIFY Adobe Texture Format file download request (more info ...)misc-activity        
37789FILE-FLASH Adobe Flash Player ASnative use after free attempt (more info ...)attempted-user  2016-0959      
37790FILE-FLASH Adobe Flash Player ASnative use after free attempt (more info ...)attempted-user  2016-0959      
37791FILE-FLASH Adobe Flash Player ASnative use after free attempt (more info ...)attempted-user  2016-0959      
37792FILE-FLASH Adobe Flash Player ASnative use after free attempt (more info ...)attempted-user  2016-0959      
37793FILE-FLASH Adobe Flash Player ActionScript 3 URLRequest class use after free attempt (more info ...)misc-attack  2016-0973      URL
37794FILE-FLASH Adobe Flash Player ActionScript 3 URLRequest class use after free attempt (more info ...)misc-attack  2016-0973      URL
37795FILE-FLASH Adobe Flash Player rectangle memory access violation attempt (more info ...)attempted-user  2016-0978      URL
37796FILE-FLASH Adobe Flash Player rectangle memory access violation attempt (more info ...)attempted-user  2016-0978      URL
37797FILE-FLASH Adobe Flash Player rectangle memory access violation attempt (more info ...)attempted-user  2016-0978      URL
37798FILE-FLASH Adobe Flash Player rectangle memory access violation attempt (more info ...)attempted-user  2016-0978      URL
37806FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
37807FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
37808FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
37809FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
37828FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
37829FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user  2013-2729  59918    URL
37839FILE-FLASH Adobe Flash Player AAC audio memory corruption attempt (more info ...)attempted-user  2016-0970      URL
37840FILE-FLASH Adobe Flash Player AAC audio memory corruption attempt (more info ...)attempted-user  2016-0970      URL
37925FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37926FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37927FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37930FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37931FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37932FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37933FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
37937FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
37938FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
37939FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
37940FILE-MULTIMEDIA Adobe Flash pixel bender buffer overflow attempt (more info ...)attempted-user  2014-0515  67092    
38165FILE-FLASH Adobe Flash Player hitTest BitmapData object integer overflow attempt (more info ...)attempted-user  2016-0963      URL
38166FILE-FLASH Adobe Flash Player hitTest BitmapData object integer overflow attempt (more info ...)attempted-user  2016-0963      URL
38167FILE-FLASH Adobe Flash Player hitTest BitmapData object integer overflow attempt (more info ...)attempted-user  2016-0963      URL
38168FILE-FLASH Adobe Flash Player hitTest BitmapData object integer overflow attempt (more info ...)attempted-user  2016-0963      URL
38169FILE-FLASH Adobe Flash Player hitTest BitmapData object integer overflow attempt (more info ...)attempted-user  2016-0963      URL
38170FILE-FLASH Adobe Flash Player hitTest BitmapData object integer overflow attempt (more info ...)attempted-user  2016-0963      URL
38171FILE-OTHER Adobe Acrobat request for updaternotifications.dll over SMB attempt (more info ...)attempted-user  2016-1008      URL
38173FILE-FLASH Adobe Standalone Flash Player texfield getter use after free attempt (more info ...)attempted-user  2016-0990      
38174FILE-FLASH Adobe Standalone Flash Player texfield getter use after free attempt (more info ...)attempted-user  2016-0990      
38175FILE-FLASH Adobe Standalone Flash Player texfield getter use after free attempt (more info ...)attempted-user  2016-0990      
38176FILE-FLASH Adobe Standalone Flash Player texfield getter use after free attempt (more info ...)attempted-user  2016-0990      
38177FILE-FLASH Adobe Standalone Flash Player ASnative object use after free attempt (more info ...)attempted-user  2016-0991      
38178FILE-FLASH Microsoft Standalone Flash Player asNative object use after free attempt (more info ...)attempted-user  2016-0991      
38179FILE-FLASH Adobe Standalone Flash Player ASnative object use after free attempt (more info ...)attempted-user  2016-0991      
38180FILE-FLASH Microsoft Standalone Flash Player asNative object use after free attempt (more info ...)attempted-user  2016-0991      
38181FILE-FLASH Adobe Flash Player AS3 multiple axis attributes integer overflow attempt (more info ...)attempted-user  2016-0989      URL
38182FILE-FLASH Adobe Flash Player AS3 multiple axis attributes integer overflow attempt (more info ...)attempted-user  2016-0989      URL
38183FILE-FLASH Adobe Flash Player AS3 multiple axis attributes integer overflow attempt (more info ...)attempted-user  2016-0989      URL
38184FILE-FLASH Adobe Flash Player AS3 multiple axis attributes integer overflow attempt (more info ...)attempted-user  2016-0989      URL
38185FILE-FLASH Adobe Flash Player AS2 setInterval use after free attempt (more info ...)attempted-user  2016-0988      URL
38186FILE-FLASH Adobe Flash Player AS2 setInterval use after free attempt (more info ...)attempted-user  2016-0988      URL
38187FILE-FLASH Adobe Flash Player AS2 setInterval use after free attempt (more info ...)attempted-user  2016-0988      URL
38188FILE-FLASH Adobe Flash Player AS2 setInterval use after free attempt (more info ...)attempted-user  2016-0988      URL
38189FILE-FLASH Adobe Flash Player si32 integer overflow attempt (more info ...)attempted-user  2016-0993  72283    URL
38190FILE-FLASH Adobe Flash Player si32 integer overflow attempt (more info ...)attempted-user  2016-0993      URL
38191FILE-FLASH Adobe Flash Player si32 integer overflow attempt (more info ...)attempted-user  2016-0993  72283    URL
38192FILE-FLASH Adobe Flash Player si32 integer overflow attempt (more info ...)attempted-user  2016-0993  72283    URL
38193FILE-FLASH Adobe Flash Player setInterval use-after-free memory corruption attempt (more info ...)attempted-user  2016-0996      
38194FILE-FLASH Adobe Flash Player setInterval use-after-free memory corruption attempt (more info ...)attempted-user  2016-0996      
38195FILE-FLASH Adobe Flash Player htmlText method use-after-free memory corruption attempt (more info ...)attempted-user  2016-0995      
38196FILE-FLASH Adobe Flash Player htmlText method use-after-free memory corruption attempt (more info ...)attempted-user  2016-0995      
38197FILE-FLASH Adobe Flash Player recursion calls stack overflow attempt (more info ...)attempted-user  2016-0986      URL
38198FILE-FLASH Adobe Flash Player recursion calls stack overflow attempt (more info ...)attempted-user  2016-0986      URL
38199FILE-FLASH Adobe Flash Player BitmapData.copyChannel access violation attempt (more info ...)attempted-user  2016-0960      URL
38200FILE-FLASH Adobe Flash Player BitmapData.copyChannel access violation attempt (more info ...)attempted-user  2016-0960      URL
38201FILE-MULTIMEDIA Adobe Flash Player MP4 length tag out of bounds read attempt (more info ...)attempted-user  2015-8652      URL
38202FILE-MULTIMEDIA Adobe Flash Player MP4 length tag out of bounds read attempt (more info ...)attempted-user  2015-8652      URL
38203FILE-FLASH Adobe Flash Player BitmapData.applyFilter access violation attempt (more info ...)attempted-user  2016-0961      URL
38204FILE-FLASH Adobe Flash Player BitmapData.applyFilter access violation attempt (more info ...)attempted-user  2016-0961      URL
38205FILE-FLASH Adobe Flash Player MPD use-after-free attempt (more info ...)attempted-user  2016-1006      URL
38206FILE-FLASH Adobe Flash Player MPD use-after-free attempt (more info ...)attempted-user  2016-1006      URL
38207FILE-FLASH Adobe Flash Player MPD use-after-free attempt (more info ...)attempted-user  2016-1006      URL
38208FILE-FLASH Adobe Flash Player MPD use-after-free attempt (more info ...)attempted-user  2016-1006      URL
38209FILE-MULTIMEDIA Adobe Flash Player malformed mp4 out of bounds write attempt (more info ...)attempted-user  2015-8658      URL
38210FILE-MULTIMEDIA Adobe Flash Player malformed mp4 out of bounds write attempt (more info ...)attempted-user  2015-8658      URL
38211FILE-PDF Adobe Reader JPEG 2000 chrominance subsampling memory corruption attempt (more info ...)attempted-user  2016-1009      URL
38212FILE-PDF Adobe Reader JPEG 2000 chrominance subsampling memory corruption attempt (more info ...)attempted-user  2016-1009      URL
38213FILE-FLASH Adobe Flash Player BitmapData.paletteMap size mismatch integer overflow attempt (more info ...)attempted-user  2016-0962      URL
38214FILE-FLASH Adobe Flash Player BitmapData.paletteMap size mismatch integer overflow attempt (more info ...)attempted-user  2016-0962      URL
38215FILE-FLASH Adobe Flash Player BitmapData.paletteMap size mismatch integer overflow attempt (more info ...)attempted-user  2016-0962      URL
38216FILE-FLASH Adobe Flash Player BitmapData.paletteMap size mismatch integer overflow attempt (more info ...)attempted-user  2016-0962      URL
38217FILE-MULTIMEDIA Adobe Flash Player malformed mp4 atom use-after-free attempt (more info ...)attempted-user  2015-8655      URL
38218FILE-MULTIMEDIA Adobe Flash Player malformed MP4 atom use-after-free attempt (more info ...)attempted-user  2015-8655      URL
38219FILE-FLASH Adobe Flash Player use after free attempt (more info ...)attempted-user  2016-0987      URL
38220FILE-FLASH Adobe Flash Player use after free (more info ...)attempted-user  2016-0987      URL
38221FILE-FLASH Adobe Flash Player use after free attempt (more info ...)attempted-user  2016-0987      URL
38222FILE-FLASH Adobe Flash Player use after free attempt (more info ...)attempted-user  2016-0987      URL
38223FILE-PDF Adobe Acrobat Reader annotation oversized array memory corruption attempt (more info ...)attempted-user  2016-1007      URL
38224FILE-PDF Adobe Acrobat Reader annotation oversized array memory corruption attempt (more info ...)attempted-user  2016-1007      URL
38225FILE-FLASH Adobe Flash Player invalid FLV header out of bounds write attempt (more info ...)attempted-user  2017-2935      URL
38226FILE-FLASH Adobe Flash Player invalid FLV header out of bounds write attempt (more info ...)attempted-user  2017-2935      URL
38227FILE-FLASH Adobe Flash Player mp4 size memory corruption attempt (more info ...)attempted-user  2016-1005      URL
38238FILE-FLASH Adobe Flash Player rectangle width integer overflow attempt (more info ...)attempted-user  2016-1010      URL
38239FILE-FLASH Adobe Flash Player rectangle width integer overflow attempt (more info ...)attempted-user  2016-1010      URL
38240FILE-FLASH Adobe Flash Player rectangle width integer overflow attempt (more info ...)attempted-user  2016-1010      URL
38241FILE-FLASH Adobe Flash Player rectangle width integer overflow attempt (more info ...)attempted-user  2016-1010      URL
38244EXPLOIT-KIT Angler exploit kit Flash exploit file download (more info ...)trojan-activity        
38245EXPLOIT-KIT Angler exploit kit Flash exploit file download (more info ...)trojan-activity        
38285EXPLOIT-KIT Angler exploit kit Flash exploit file download attempt (more info ...)attempted-user        
38310FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
38311FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
38334FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
38335FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
38401FILE-FLASH Adobe Flash Player multiple scripts display rendering use-after-free attempt (more info ...)attempted-user  2016-1011      URL
38402FILE-FLASH Adobe Flash Player multiple scripts display rendering use-after-free attempt (more info ...)attempted-user  2016-1011      URL
38403FILE-FLASH Adobe Flash Player Transform Class Matrix AS2 use after free attempt (more info ...)attempted-user  2016-1016      URL
38404FILE-FLASH Adobe Flash Player Transform Class Matrix AS2 use after free attempt (more info ...)attempted-user  2016-1016      URL
38405FILE-FLASH Adobe Flash Player Transform Class Matrix AS2 use after free attempt (more info ...)attempted-user  2016-1016      URL
38406FILE-FLASH Adobe Flash Player Transform Class Matrix AS2 use after free attempt (more info ...)attempted-user  2016-1016      URL
38407FILE-FLASH Adobe Flash Player JPEG-XR decode buffer overflow attempt (more info ...)attempted-user  2016-1018      URL
38408FILE-FLASH Adobe Flash Player JPEG-XR decode buffer overflow attempt (more info ...)attempted-user  2016-1018      URL
38409FILE-FLASH Adobe Flash Player JPEG-XR decode buffer overflow attempt (more info ...)attempted-user  2016-1018      URL
38410FILE-FLASH Adobe Flash Player JPEG-XR decode buffer overflow attempt (more info ...)attempted-user  2016-1018      URL
38411FILE-FLASH Adobe Flash Player duplicateMovieClip use after free attempt (more info ...)attempted-user  2016-1013      URL
38412FILE-FLASH Adobe Flash Player duplicateMovieClip use after free attempt (more info ...)attempted-user  2016-1013      URL
38413FILE-FLASH Adobe Flash Player NetConnection to ColorMatrixFilter object type confusion attempt (more info ...)attempted-user  2016-1015      URL
38414FILE-FLASH Adobe Flash Player NetConnection to ColorMatrixFilter object type confusion attempt (more info ...)attempted-user  2016-1015      URL
38415FILE-FLASH Adobe Flash Player NetConnection to ColorMatrixFilter object type confusion attempt (more info ...)attempted-user  2016-1015      URL
38416FILE-FLASH Adobe Flash Player NetConnection to ColorMatrixFilter object type confusion attempt (more info ...)attempted-user  2016-1015      URL
38417FILE-FLASH Adobe Flash Player ClbCatQ.dll dll-load exploit attempt (more info ...)attempted-user  2016-1014      URL
38418FILE-FLASH Adobe Flash Player HNetCfg.dll dll-load exploit attempt (more info ...)attempted-user  2016-1014      URL
38419FILE-FLASH Adobe Flash Player RASMan.dll dll-load exploit attempt (more info ...)attempted-user  2016-1014      URL
38420FILE-FLASH Adobe Flash Player setupapi.dll dll-load exploit attempt (more info ...)attempted-user  2016-1014      URL
38421FILE-FLASH Adobe Flash Player request for ClbCatQ.dll over SMB attempt (more info ...)attempted-user  2016-1014      URL
38422FILE-FLASH Adobe Flash Player request for HNetCfg.dll over SMB attempt (more info ...)attempted-user  2016-1014      URL
38423FILE-FLASH Adobe Flash Player request for RASMan.dll over SMB attempt (more info ...)attempted-user  2016-1014      URL
38424FILE-FLASH Adobe Flash Player request for setupapi.dll over SMB attempt (more info ...)attempted-user  2016-1014      URL
38425FILE-FLASH Adobe Flash Player ExportAssets count memory corruption attempt (more info ...)attempted-user  2016-1012      URL
38426FILE-FLASH Adobe Flash Player ExportAssets count memory corruption attempt (more info ...)attempted-user  2016-1012      URL
38427FILE-FLASH Adobe Flash Player ExportAssets count memory corruption attempt (more info ...)attempted-user  2016-1012      URL
38428FILE-FLASH Adobe Flash Player ExportAssets count memory corruption attempt (more info ...)attempted-user  2016-1012      URL
38429FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
38430FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
38431FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
38432FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
38433FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
38434FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
38455FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
38456FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
38532FILE-FLASH Rig Exploit Kit exploitation attempt (more info ...)attempted-user        
38533FILE-FLASH Rig Exploit Kit exploitation attempt (more info ...)attempted-user        
38534FILE-FLASH Rig Exploit Kit exploitation attempt (more info ...)attempted-user        
38535FILE-FLASH Rig Exploit Kit exploitation attempt (more info ...)attempted-user        
38576FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
38577FILE-FLASH Adobe Flash Player dangling bytearray pointer code execution attempt (more info ...)attempted-user  2014-8439      URL
38629FILE-FLASH Angler exploit kit Adobe Flash SWF exploit download (more info ...)attempted-user        URL
38630FILE-FLASH Angler exploit kit Adobe Flash SWF exploit download (more info ...)attempted-user        URL
38631FILE-FLASH Angler exploit kit Adobe Flash SWF exploit download (more info ...)attempted-user        URL
38632FILE-FLASH Angler exploit kit Adobe Flash SWF exploit download (more info ...)attempted-user        URL
38633FILE-FLASH Nuclear exploit kit Adobe Flash SWF exploit download (more info ...)attempted-user        URL
38634FILE-FLASH Nuclear exploit kit Adobe Flash SWF exploit download (more info ...)attempted-user        URL
38635FILE-FLASH Nuclear exploit kit Adobe Flash SWF exploit download (more info ...)attempted-user        URL
38636FILE-FLASH Nuclear exploit kit Adobe Flash SWF exploit download (more info ...)attempted-user        URL
38730EXPLOIT-KIT Neutrino Exploit Kit Flash exploit download attempt (more info ...)trojan-activity        
38758FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user        
38778FILE-OTHER Microsoft Windows Media Center link file code execution attempt (more info ...)attempted-user  2016-0185  90023    URL
38779FILE-OTHER Microsoft Windows Media Center link file code execution attempt (more info ...)attempted-user  2016-0185  90023    URL
38792FILE-FLASH Adobe Flash Player ASSetNativeAccessor use after free attempt (more info ...)attempted-user  2016-1110      URL
38793FILE-FLASH Adobe Flash Player ASSetNativeAccessor use after free attempt (more info ...)attempted-user  2016-1110      URL
38799FILE-PDF Adobe Acrobat FileAttachment use-after-free attempt (more info ...)attempted-user  2016-1065      URL
38800FILE-PDF Adobe Acrobat FileAttachment use-after-free attempt (more info ...)attempted-user  2016-1065      URL
38818FILE-PDF Adobe Acrobat Reader XFA engine memory leak - possible code instrumentation detected (more info ...)policy-violation  2016-1092      URL
38819FILE-PDF Adobe Acrobat Reader XFA engine memory leak ASLR bypass attempt (more info ...)policy-violation  2016-1092      URL
38820FILE-PDF Adobe Acrobat Reader XFA engine memory leak - possible code instrumentation detected (more info ...)policy-violation  2016-1092      URL
38821FILE-PDF Adobe Acrobat Reader XFA engine memory leak ASLR bypass attempt (more info ...)policy-violation  2016-1092      URL
38824FILE-FLASH Adobe Flash Player removeMovieClip callback use after free attempt (more info ...)attempted-user  2016-1107      URL
38825FILE-FLASH Adobe Flash Player removeMovieClip callback use after free attempt (more info ...)attempted-user  2016-1107      URL
38826FILE-FLASH Adobe Flash Player removeMovieClip callback use after free attempt (more info ...)attempted-user  2016-1107      URL
38827FILE-FLASH Adobe Flash Player removeMovieClip callback use after free attempt (more info ...)attempted-user  2016-1107      URL
38830FILE-FLASH Adobe Flash Player ContentFactory memory corruption attempt (more info ...)attempted-user  2016-1098      URL
38831FILE-FLASH Adobe Flash Player ContentFactory memory corruption attempt (more info ...)attempted-user  2016-1098      URL
38832FILE-FLASH Adobe Flash Player ContentFactory memory corruption attempt (more info ...)attempted-user  2016-1098      URL
38833FILE-FLASH Adobe Flash Player ContentFactory memory corruption attempt (more info ...)attempted-user  2016-1098      URL
38835FILE-FLASH Adobe Flash Player bitmap heap overflow attempt (more info ...)attempted-user  2017-3078      URL
38836FILE-FLASH Adobe Flash Player bitmap heap overflow attempt (more info ...)attempted-user  2017-3078      URL
38837FILE-FLASH Adobe Flash Player faulty x64 support out of bounds read attempt (more info ...)attempted-user  2016-1096      URL
38838FILE-FLASH Adobe Flash Player faulty x64 support out of bounds read attempt (more info ...)attempted-user  2016-1096      URL
38845FILE-PDF Adobe Reader out of bounds memory access violation attempt (more info ...)attempted-user  2016-6941      URL
38846FILE-PDF Adobe Reader out of bounds memory access violation attempt (more info ...)attempted-user  2016-6941      URL
38847FILE-FLASH Adobe Flash Player loadSound method use-after-free memory corruption attempt (more info ...)attempted-user  2016-1108      URL
38848FILE-FLASH Adobe Flash Player loadSound method use-after-free memory corruption attempt (more info ...)attempted-user  2016-1108      URL
38872FILE-FLASH Adobe Flash Player request for MSIMG32.dll over SMB attempt (more info ...)attempted-user  2016-4116      URL
38873FILE-FLASH Adobe Flash Player MSIMG32.dll dll-load exploit attempt (more info ...)attempted-user  2016-4116      URL
38881FILE-FLASH Adobe Flash Player FileReference type confusion attempt (more info ...)attempted-user  2016-1105      URL
38882FILE-FLASH Adobe Flash Player FileReference type confusion attempt (more info ...)attempted-user  2016-1105      URL
38883FILE-FLASH Adobe Flash Player FileReference type confusion attempt (more info ...)attempted-user  2016-1105      URL
38884FILE-FLASH Adobe Flash Player FileReference type confusion attempt (more info ...)attempted-user  2016-1105      URL
38895FILE-PDF Adobe Reader XFA prePrint use after free attempt (more info ...)attempted-user  2016-1048      URL
38896FILE-PDF Adobe Reader XFA prePrint use after free attempt (more info ...)attempted-user  2016-1048      URL
38899FILE-PDF Adobe Reader PDF defineGetter execMenuItem use after free attempt (more info ...)attempted-user  2016-1062      URL
38900FILE-PDF Adobe Reader PDF onEvent execMenuItem use after free attempt (more info ...)attempted-user  2016-1060      URL
38901FILE-PDF Adobe Reader PDF setAction execMenuItem use after free attempt (more info ...)attempted-user  2016-1069      URL
38902FILE-PDF Adobe Reader PDF setPageAction execMenuItem use after free attempt (more info ...)attempted-user  2016-1050      URL
38903FILE-PDF Adobe Reader PDF defineGetter execMenuItem use after free attempt (more info ...)attempted-user  2016-1062      URL
38904FILE-PDF Adobe Reader PDF onEvent execMenuItem use after free attempt (more info ...)attempted-user  2016-1060      URL
38905FILE-PDF Adobe Reader PDF setAction execMenuItem use after free attempt (more info ...)attempted-user  2016-1069      URL
38906FILE-PDF Adobe Reader PDF setPageAction execMenuItem use after free attempt (more info ...)attempted-user  2016-1050      URL
38907FILE-PDF Adobe Reader PDF execMenuItem use after free attempt (more info ...)attempted-user  2016-1047      URL
38908FILE-PDF Adobe Reader PDF execMenuItem use after free attempt (more info ...)attempted-user  2016-1047      URL
38931FILE-PDF Adobe Reader submitForm read out of bounds attempt (more info ...)attempted-user  2016-1064      URL
38932FILE-PDF Adobe Reader submitForm read out of bounds attempt (more info ...)attempted-user  2016-1064      URL
38954FILE-OTHER Adobe Acrobat DC invalid TIFF tagtype out of bounds read attempt (more info ...)attempted-user  2016-1080      URL
38955FILE-OTHER Adobe Acrobat DC invalid TIFF tagtype out of bounds read attempt (more info ...)attempted-user  2016-1080      URL
38956FILE-OTHER Adobe Acrobat DC invalid TIFF tagtype out of bounds read attempt (more info ...)attempted-user  2016-1080      URL
38957FILE-OTHER Adobe Acrobat DC invalid TIFF tagtype out of bounds read attempt (more info ...)attempted-user  2016-1080      URL
38959FILE-PDF Adobe Reader malformed Universal 3D stream memory corruption attempt (more info ...)attempted-user  2016-1037      URL
38960FILE-PDF Adobe Reader malformed Universal 3D stream memory corruption attempt (more info ...)attempted-user  2016-1037      URL
38966FILE-PDF Adobe Reader malformed JPEG2000 image invalid NumberComponents out of bounds read attempt (more info ...)attempted-user  2016-1078      URL
38967FILE-PDF Adobe Reader malformed JPEG2000 image invalid NumberComponents out of bounds read attempt (more info ...)attempted-user  2016-1078      URL
38971FILE-FLASH Adobe Flash Player OpportunityGenerator.update memory corruption attempt (more info ...)attempted-user  2016-1100      URL
38972FILE-FLASH Adobe Flash Player OpportunityGenerator.update memory corruption attempt (more info ...)attempted-user  2016-1100      URL
38973FILE-FLASH Adobe Flash Player OpportunityGenerator.update memory corruption attempt (more info ...)attempted-user  2016-1100      URL
38974FILE-FLASH Adobe Flash Player OpportunityGenerator.update memory corruption attempt (more info ...)attempted-user  2016-1100      URL
38975FILE-PDF Adobe Reader clearGlobalSecurityStore information leak attempt (more info ...)attempted-recon  2016-1086      URL
38976FILE-PDF Adobe Reader clearGlobalSecurityStore information leak attempt (more info ...)attempted-recon  2016-1086      URL
38977FILE-PDF Adobe Acrobat memory corruption vulnerability attempt (more info ...)attempted-user  2016-1081      URL
38978FILE-PDF Adobe Acrobat memory corruption vulnerability attempt (more info ...)attempted-user  2016-1081      URL
38980FILE-PDF Adobe Acrobat Reader malformed FlateDecode stream use after free attempt (more info ...)attempted-user  2016-1094      URL
38981FILE-PDF Adobe Acrobat Reader malformed FlateDecode stream use after free attempt (more info ...)attempted-user  2016-1094      URL
38982FILE-FLASH Adobe Flash Player corrupt PNG image load out of bounds memory access attempt (more info ...)attempted-user  2016-1104      URL
38983FILE-FLASH Adobe Flash Player corrupt PNG image load out of bounds memory access attempt (more info ...)attempted-user  2016-1104      URL
38996FILE-FLASH Adobe Flash Player addProperty use after free attempt (more info ...)attempted-user  2016-4108      URL
38997FILE-FLASH Adobe Flash Player addProperty use after free attempt (more info ...)attempted-user  2016-4108      URL
38998FILE-FLASH Adobe Flash Player addProperty use after free attempt (more info ...)attempted-user  2016-4108      URL
38999FILE-FLASH Adobe Flash Player addProperty use after free attempt (more info ...)attempted-user  2016-4108      URL
39007FILE-PDF Adobe Reader XFA form use-after-free attempt (more info ...)attempted-user  2016-1046      URL
39008FILE-PDF Adobe Reader XFA form use-after-free attempt (more info ...)attempted-user  2016-1046      URL
39009FILE-FLASH Adobe Flash Player setMetadata memory corruption attempt (more info ...)attempted-user  2016-1099      URL
39010FILE-FLASH Adobe Flash Player setMetadata memory corruption attempt (more info ...)attempted-user  2016-1099      URL
39011FILE-FLASH Adobe Flash Player setMetadata memory corruption attempt (more info ...)attempted-user  2016-1099      URL
39012FILE-FLASH Adobe Flash Player setMetadata memory corruption attempt (more info ...)attempted-user  2016-1099      URL
39013FILE-PDF Adobe Reader CTJPEGDecoderReadNextTile out of bounds read attempt (more info ...)attempted-user  2016-1077      URL
39014FILE-PDF Adobe Reader CTJPEGDecoderReadNextTile out of bounds read attempt (more info ...)attempted-user  2016-1077      URL
39015FILE-PDF Adobe Reader AcroForm dictionary object use after free attempt (more info ...)attempted-user  2016-1066      URL
39016FILE-PDF Adobe Reader AcroForm dictionary object use after free attempt (more info ...)attempted-user  2016-1066      URL
39017FILE-PDF Adobe Reader XFA FormInstanceManager use after free attempt (more info ...)attempted-user  2016-1045      URL
39018FILE-PDF Adobe Reader XFA FormInstanceManager use after free attempt (more info ...)attempted-user  2016-1045      URL
39019FILE-FLASH Adobe Flash Player PSDK use-after-free attempt (more info ...)attempted-user  2016-1097      URL
39020FILE-FLASH Adobe Flash Player PSDK use-after-free attempt (more info ...)attempted-user  2016-1097      URL
39021FILE-FLASH Adobe Flash Player PSDK use-after-free attempt (more info ...)attempted-user  2016-1097      URL
39022FILE-FLASH Adobe Flash Player PSDK use-after-free attempt (more info ...)attempted-user  2016-1097      URL
39023FILE-FLASH Adobe Flash Player selection.setFocus use after free attempt (more info ...)attempted-user  2016-1109      URL
39024FILE-FLASH Adobe Flash Player selection.setFocus use after free attempt (more info ...)attempted-user  2016-1109      URL
39025FILE-FLASH Adobe Flash Player selection.setFocus use after free attempt (more info ...)attempted-user  2016-1109      URL
39026FILE-FLASH Adobe Flash Player selection.setFocus use after free attempt (more info ...)attempted-user  2016-1109      URL
39028FILE-PDF Adobe Reader JPEG 2000 memory corruption attempt (more info ...)attempted-user  2016-1095      URL
39029FILE-PDF Adobe Reader JPEG 2000 memory corruption attempt (more info ...)attempted-user  2016-1095      URL
39030FILE-FLASH Adobe Flash Player ASSetNative use-after-free attempt (more info ...)attempted-user  2016-1106      URL
39031FILE-FLASH Adobe Flash Player ASSetNative use-after-free attempt (more info ...)attempted-user  2016-1106      URL
39032FILE-FLASH Adobe Flash Player ASSetNative use-after-free attempt (more info ...)attempted-user  2016-1106      URL
39033FILE-FLASH Adobe Flash Player ASSetNative use-after-free attempt (more info ...)attempted-user  2016-1106      URL
39061FILE-PDF Adobe Reader XFA API preOpen use after free attempt (more info ...)attempted-user  2016-1049      URL
39062FILE-PDF Adobe Reader XFA API preOpen use after free attempt (more info ...)attempted-user  2016-1049      URL
39076FILE-PDF Adobe Reader XFA API preOpen use after free attempt (more info ...)attempted-user  2016-1049      URL
39077FILE-PDF Adobe Reader XFA API preOpen use after free attempt (more info ...)attempted-user  2016-1049      URL
39098FILE-PDF Adobe Reader double memory free call remote code execution attempt (more info ...)attempted-user  2016-1111      URL
39099FILE-PDF Adobe Reader double memory free call remote code execution attempt (more info ...)attempted-user  2016-1111      URL
39101FILE-PDF Adobe Reader Universal 3D engine out of bounds memory access violation attempt (more info ...)attempted-user  2016-1071      URL
39102FILE-PDF Adobe Reader PDF embedded JPEG memory corruption attempt (more info ...)attempted-user  2016-1088      URL
39103FILE-PDF Adobe Reader PDF embedded JPEG memory corruption attempt (more info ...)attempted-user  2016-1088      URL
39104FILE-PDF Adobe Reader Universal 3D engine out of bounds memory access violation attempt (more info ...)attempted-user  2016-1074      URL
39105FILE-PDF Adobe Reader Universal 3D engine out of bounds memory access violation attempt (more info ...)attempted-user  2016-1074      URL
39112FILE-IMAGE Adobe Pro DC Exif ModifyDate metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39113FILE-IMAGE Adobe Pro DC Exif ModifyDate metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39114FILE-IMAGE Adobe Pro DC Exif Software metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39115FILE-IMAGE Adobe Pro DC Exif Software metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39131FILE-PDF Adobe Acrobat Reader Acroform engine memory corruption attempt (more info ...)attempted-user  2016-1093      URL
39132FILE-PDF Adobe Acrobat Reader Acroform engine memory corruption attempt (more info ...)attempted-user  2016-1093      URL
39136FILE-IMAGE Adobe Pro DC Exif ModifyDate metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39137FILE-IMAGE Adobe Pro DC Exif ModifyDate metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39138FILE-IMAGE Adobe Pro DC Exif Software metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39139FILE-IMAGE Adobe Pro DC Exif Software metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39140FILE-IMAGE Adobe Pro DC Exif ModifyDate metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39141FILE-IMAGE Adobe Pro DC Exif ModifyDate metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39142FILE-IMAGE Adobe Pro DC Exif ModifyDate metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39143FILE-IMAGE Adobe Pro DC Exif ModifyDate metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39144FILE-IMAGE Adobe Pro DC Exif Software metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39145FILE-IMAGE Adobe Pro DC Exif Software metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39146FILE-IMAGE Adobe Pro DC Exif Software metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39147FILE-IMAGE Adobe Pro DC Exif Software metadata memory corruption attempt (more info ...)attempted-user  2016-1076      URL
39153FILE-PDF Adobe Acrobat Reader XObject image object use after free attempt (more info ...)attempted-user  2016-1075      URL
39154FILE-PDF Adobe Acrobat Reader XObject image object use after free attempt (more info ...)attempted-user  2016-1075      URL
39269FILE-FLASH Adobe Flash TextFormat.setTabStops use-after-free attempt (more info ...)attempted-user  2016-4142      URL
39270FILE-FLASH Adobe Flash TextFormat.setTabStops use-after-free attempt (more info ...)attempted-user  2016-4142      URL
39271FILE-FLASH Adobe Flash Player ShimContentFactory uninitialized pointer use attempt (more info ...)attempted-user  2016-4150      URL
39272FILE-FLASH Adobe Flash Player ShimContentFactory uninitialized pointer use attempt (more info ...)attempted-user  2016-4150      URL
39273FILE-FLASH Adobe Flash Player malformed ATF heap overflow attempt (more info ...)attempted-user  2017-2927      URL
39274FILE-FLASH Adobe Flash Player malformed ATF heap overflow attempt (more info ...)attempted-user  2017-2927      URL
39275FILE-FLASH Adobe Flash Player loadSound use after free attempt (more info ...)attempted-user  2016-4143      URL
39276FILE-FLASH Adobe Flash Player loadSound use after free attempt (more info ...)attempted-user  2016-4143      URL
39277FILE-OTHER Adobe Flash Player malformed JPEG XR heap overflow attempt (more info ...)attempted-user  2016-4136      URL
39278FILE-OTHER Adobe Flash Player malformed JPEG XR heap overflow attempt (more info ...)attempted-user  2016-4136      URL
39279FILE-FLASH Adobe Primetime SDK object type confusion overflow attempt (more info ...)attempted-user  2016-4149      URL
39280FILE-FLASH Adobe Primetime SDK object type confusion overflow attempt (more info ...)attempted-user  2016-4149      URL
39281FILE-FLASH Adobe Flash Player malformed JPEG-XR out of bounds memory access attempt (more info ...)attempted-user  2016-4141      URL
39282FILE-FLASH Adobe Flash Player malformed JPEG-XR out of bounds memory access attempt (more info ...)attempted-user  2016-4141      URL
39283FILE-FLASH Adobe Flash Player loadSound use after free attempt (more info ...)attempted-user  2016-4147      URL
39284FILE-FLASH Adobe Flash Player loadSound use after free attempt (more info ...)attempted-user  2016-4147      URL
39285FILE-FLASH Adobe Flash Player loadSound use after free attempt (more info ...)attempted-user  2016-4147      URL
39286FILE-FLASH Adobe Flash Player loadSound use after free attempt (more info ...)attempted-user  2016-4147      URL
39287FILE-FLASH Adobe Flash Player ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2016-4155      URL
39288FILE-FLASH Adobe Flash Player ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2016-4155      URL
39289FILE-FLASH Adobe Flash Player Primetime SDK ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2016-4156      URL
39290FILE-FLASH Adobe Flash Player Primetime SDK ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2016-4156      URL
39291FILE-FLASH Adobe Flash Player NetConnection object type confusion overflow attempt (more info ...)attempted-user  2016-4144      URL
39292FILE-FLASH Adobe Flash Player NetConnection object type confusion overflow attempt (more info ...)attempted-user  2016-4144      URL
39293FILE-FLASH Adobe Flash Player apphelp.dll dll-load exploit attempt (more info ...)attempted-user  2016-4140      URL
39294FILE-FLASH Adobe Flash Player dbghelp.dll dll-load exploit attempt (more info ...)attempted-user  2016-4140      URL
39295FILE-FLASH Adobe Flash Player request for apphelp.dll over SMB attempt (more info ...)attempted-user  2016-4140      URL
39296FILE-FLASH Adobe Flash Player request for dbghelp.dll over SMB attempt (more info ...)attempted-user  2016-4140      URL
39297FILE-FLASH Adobe Flash player retrieveResolvers memory corruption attempt (more info ...)attempted-user  2016-4151      URL
39298FILE-FLASH Adobe Flash player retrieveResolvers memory corruption attempt (more info ...)attempted-user  2016-4151      URL
39299FILE-FLASH Adobe Flash Player malformed regular expression use after free attempt (more info ...)attempted-user  2016-4121      URL
39300FILE-FLASH Adobe Flash Player malformed regular expression use after free attempt (more info ...)attempted-user  2016-4121      URL
39301FILE-FLASH Adobe Flash Player ExecPolicy invalid string table lookup attempt (more info ...)attempted-user  2016-4171      URL
39302FILE-FLASH Adobe Flash Player ExecPolicy invalid string table lookup attempt (more info ...)attempted-user  2016-4171      URL
39304FILE-FLASH Adobe Flash Player Primetime SDK ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2016-4154      URL
39305FILE-FLASH Adobe Flash Player Primetime SDK ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2016-4154      URL
39306FILE-FLASH Adobe Flash Player sound object use-after-free attempt (more info ...)attempted-user  2016-4148      URL
39307FILE-FLASH Adobe Flash Player sound object use-after-free attempt (more info ...)attempted-user  2016-4148      URL
39308FILE-FLASH Adobe Flash Player malformed ATF file length load buffer overflow attempt (more info ...)attempted-user  2017-2933      URL
39309FILE-FLASH Adobe Flash Player malformed ATF file length load buffer overflow attempt (more info ...)attempted-user  2017-2933      URL
39310FILE-FLASH Adobe Flash Player same origin policy security bypass attempt (more info ...)attempted-user  2016-4139      URL
39311FILE-FLASH Adobe Flash Player same origin policy security bypass attempt (more info ...)attempted-user  2016-4139      URL
39312FILE-FLASH Adobe Flash Player malformed Adobe Texture Format image load memory corruption attempt (more info ...)attempted-user  2016-4137      URL
39313FILE-FLASH Adobe Flash Player malformed Adobe Texture Format image load memory corruption attempt (more info ...)attempted-user  2016-4137      URL
39314FILE-FLASH Adobe Flash Player RegExp numbered backreference out of bounds read attempt (more info ...)attempted-user  2016-4133      URL
39315FILE-FLASH Adobe Flash Player RegExp numbered backreference out of bounds read attempt (more info ...)attempted-user  2016-4133      URL
39317FILE-FLASH Adobe Flash Player MovieClip object use-after-free attempt (more info ...)attempted-user  2016-4146      URL
39318FILE-FLASH Adobe Flash Player ShimOpportunityGenerator out of bounds memory access attempt (more info ...)attempted-user  2016-4153      URL
39319FILE-FLASH Adobe Flash Player ShimOpportunityGenerator out of bounds memory access attempt (more info ...)attempted-user  2016-4153      URL
39438FILE-FLASH Adobe Flash Player integer overflow attempt (more info ...)attempted-user  2015-3087      URL
39439FILE-FLASH Adobe Flash Player integer overflow attempt (more info ...)attempted-user  2015-3087      URL
39440FILE-FLASH Adobe Flash Player integer overflow attempt (more info ...)attempted-user  2015-3087      URL
39441FILE-FLASH Adobe Flash Player integer overflow attempt (more info ...)attempted-user  2015-3087      URL
39454FILE-PDF Adobe Acrobat Reader U3D e3_bone object out of bounds memory access attempt (more info ...)attempted-user  2016-1116      URL
39455FILE-PDF Adobe Acrobat Reader U3D e3_bone object out of bounds memory access attempt (more info ...)attempted-user  2016-1116      URL
39457FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
39458FILE-FLASH Adobe Flash Player integer underflow attempt (more info ...)attempted-user  2014-0497      
39532FILE-PDF Adobe Acrobat Reader XSL multi-dimensional array memory corruption attempt (more info ...)attempted-user  2016-4202      URL
39533FILE-PDF Adobe Acrobat Reader XSL multi-dimensional array memory corruption attempt (more info ...)attempted-user  2016-4202      URL
39534FILE-PDF Adobe Acrobat Reader embedded TTF name record out of bounds read attempt (more info ...)attempted-user  2016-4203      URL
39535FILE-PDF Adobe Acrobat Reader embedded TTF name record out of bounds read attempt (more info ...)attempted-user  2016-4203      URL
39536FILE-PDF Adobe Acrobat Reader JPEG handling memory corruption attempt (more info ...)attempted-user  2016-4252      URL
39537FILE-PDF Adobe Acrobat Reader JPEG handling memory corruption attempt (more info ...)attempted-user  2016-4252      URL
39538FILE-FLASH Adobe Flash Player malformed tag out of bounds read attempt (more info ...)attempted-user  2016-4176      URL
39539FILE-FLASH Adobe Flash Player malformed tag out of bounds read attempt (more info ...)attempted-user  2016-4176      URL
39540FILE-FLASH Adobe Flash Player local-with-filesystem security bypass attempt (more info ...)attempted-user  2016-4178      URL
39541FILE-FLASH Adobe Flash Player local-with-filesystem security bypass attempt (more info ...)attempted-user  2016-4178      URL
39542FILE-FLASH Adobe Flash Player local-with-filesystem security bypass attempt (more info ...)attempted-user  2016-4178      URL
39543FILE-FLASH Adobe Flash Player local-with-filesystem security bypass attempt (more info ...)attempted-user  2016-4178      URL
39544FILE-FLASH Adobe Flash Player local-with-filesystem security bypass attempt (more info ...)attempted-user  2016-4178      URL
39545FILE-FLASH Adobe Flash Player local-with-filesystem security bypass attempt (more info ...)attempted-user  2016-4178      URL
39546FILE-PDF Adobe Reader embedded TTF heap overflow attempt (more info ...)attempted-user  2016-4204      URL
39547FILE-PDF Adobe Reader embedded TTF heap overflow attempt (more info ...)attempted-user  2016-4204      URL
39548FILE-FLASH Adobe Flash Player AdTimelineItem object memory corruption attempt (more info ...)attempted-user  2016-4223      URL
39549FILE-FLASH Adobe Flash Player AdTimelineItem object memory corruption attempt (more info ...)attempted-user  2016-4223      URL
39550FILE-FLASH Adobe Flash Player MovieClip method loop use-after-free attempt (more info ...)attempted-user  2016-4231      URL
39551FILE-FLASH Adobe Flash Player MovieClip method loop use-after-free attempt (more info ...)attempted-user  2016-4231      URL
39552FILE-FLASH Adobe Flash Player ByteArray type confusion memory corruption attempt (more info ...)attempted-user  2016-4249      URL
39553FILE-FLASH Adobe Flash Player ByteArray type confusion memory corruption attempt (more info ...)attempted-user  2016-4249      URL
39554FILE-FLASH Adobe Flash Player AdBreakPlacement object memory corruption attempt (more info ...)attempted-user  2016-4225      URL
39555FILE-FLASH Adobe Flash Player AdBreakPlacement object memory corruption attempt (more info ...)attempted-user  2016-4225      URL
39557FILE-PDF Adobe Acrobat Reader PostScript font parsing memory corruption attempt (more info ...)attempted-user  2016-4251      URL
39558FILE-FLASH Adobe Flash Player Stage align use aftre free attempt (more info ...)attempted-user  2016-4226      URL
39559FILE-FLASH Adobe Flash Player Stage align use aftre free attempt (more info ...)attempted-user  2016-4226      URL
39560FILE-FLASH Adobe Flash Player AS3 regex sign-extension denial of service attempt (more info ...)denial-of-service  2015-0310      URL
39561FILE-FLASH Adobe Flash Player AS3 regex sign-extension denial of service attempt (more info ...)denial-of-service  2015-0310      URL
39563FILE-FLASH Adobe Flash Player TimedEvent memory corruption attempt (more info ...)attempted-user  2016-4188      URL
39564FILE-FLASH Adobe Flash Player TimedEvent memory corruption attempt (more info ...)attempted-user  2016-4188      URL
39565FILE-FLASH Adobe Flash Player malformed tag parsing memory corruption attempt (more info ...)attempted-user  2016-4177      URL
39566FILE-FLASH Adobe Flash Player malformed tag parsing memory corruption attempt (more info ...)attempted-user  2016-4177      URL
39567FILE-FLASH Adobe Flash Player loadPCMFromByteArray exception null pointer access attempt (more info ...)attempted-user  2016-0984      URL
39568FILE-FLASH Adobe Flash Player loadPCMFromByteArray exception null pointer access attempt (more info ...)attempted-user  2016-0984      URL
39569FILE-PDF Adobe Acrobat Reader JPEG parsing out of bounds read attempt (more info ...)attempted-user  2016-4192      URL
39570FILE-PDF Adobe Acrobat Reader JPEG parsing out of bounds read attempt (more info ...)attempted-user  2016-4192      URL
39571FILE-FLASH Adobe Flash Player Transform object use after free attempt (more info ...)attempted-user  2016-4173      URL
39572FILE-FLASH Adobe Flash Player Transform object use after free attempt (more info ...)attempted-user  2016-4173      URL
39591FILE-FLASH Adobe Flash Player malformed TagTypeAndLength field attempt (more info ...)attempted-user  2016-4175      URL
39592FILE-FLASH Adobe Flash Player malformed TagTypeAndLength field attempt (more info ...)attempted-user  2016-4175      URL
39643FILE-PDF Adobe Reader malformed CID identity-H font file out of bounds read attempt (more info ...)attempted-user  2016-4206      URL
39644FILE-PDF Adobe Reader malformed CID identity-H font file out of bounds read attempt (more info ...)attempted-user  2016-4206      URL
39651FILE-FLASH Adobe Flash Player swapDepths use after free attempt (more info ...)attempted-user  2016-0999      URL
39652FILE-FLASH Adobe Flash Player swapDepths use after free attempt (more info ...)attempted-user  2016-0999      URL
39656FILE-FLASH Adobe Flash Player JPEG handling memory corruption attempt (more info ...)attempted-user  2016-4229      URL
39657FILE-FLASH Adobe Flash Player JPEG handling memory corruption attempt (more info ...)attempted-user  2016-4229      URL
39658FILE-FLASH Adobe Flash Player Transform getter use after free attempt (more info ...)attempted-user  2016-4230      URL
39659FILE-FLASH Adobe Flash Player Transform getter use after free attempt (more info ...)attempted-user  2016-4230      URL
39687FILE-PDF Adobe Acrobat Reader malformed embeded TTF file memory corruption attempt (more info ...)attempted-user  2016-4205      URL
39688FILE-PDF Adobe Acrobat Reader malformed embeded TTF file memory corruption attempt (more info ...)attempted-user  2016-4205      URL
39689FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39690FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39691FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39692FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39693FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39694FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39695FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39696FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39697FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39698FILE-FLASH Adobe Flash Player ABRControlParameters access memory corruption attempt (more info ...)attempted-user  2016-4185      URL
39699FILE-PDF Adobe Acrobat Reader malformed embeded TTF file memory corruption attempt (more info ...)attempted-user  2016-4201      URL
39700FILE-PDF Adobe Acrobat Reader malformed embeded TTF file memory corruption attempt (more info ...)attempted-user  2016-4201      URL
39701FILE-FLASH Adobe Flash Player MediaPlayerItemLoader out of bounds memory access attempt (more info ...)attempted-user  2016-4182      URL
39702FILE-FLASH Adobe Flash Player MediaPlayerItemLoader out of bounds memory access attempt (more info ...)attempted-user  2016-4182      URL
39703FILE-PDF Adobe Flash Player ActionScript setFocus use after free attempt (more info ...)attempted-user  2016-4227      URL
39704FILE-PDF Adobe Flash Player ActionScript setFocus use after free attempt (more info ...)attempted-user  2016-4227      URL
39711FILE-FLASH Adobe Flash Player PrintJobOptions use-after-free attempt (more info ...)attempted-user  2016-4222      URL
39712FILE-FLASH Adobe Flash Player PrintJobOptions use-after-free attempt (more info ...)attempted-user  2016-4222      URL
39727FILE-FLASH Adobe Flash Player Rectangle constructor use after free attempt (more info ...)attempted-user  2016-4228      URL
39728FILE-FLASH Adobe Flash Player Rectangle constructor use after free attempt (more info ...)attempted-user  2016-4228      URL
39731FILE-PDF Adobe Reader malformed CID identity-H font file out of bounds read attempt (more info ...)attempted-user  2016-4206      URL
39732FILE-PDF Adobe Reader malformed CID identity-H font file out of bounds read attempt (more info ...)attempted-user  2016-4206      URL
39752FILE-PDF Adobe Reader malformed ICC profile memory corruption attempt (more info ...)attempted-user  2016-4191      URL
39753FILE-PDF Adobe Reader malformed ICC profile memory corruption attempt (more info ...)attempted-user  2016-4191      URL
39788FILE-FLASH Adobe Flash Player AS2 TextField gridFitType use after free attempt (more info ...)attempted-user  2015-7652      URL
39789FILE-FLASH Adobe Flash Player AS2 TextField gridFitType use after free attempt (more info ...)attempted-user  2015-7652      URL
39798FILE-PDF Adobe Acrobat Reader raster image memory corruption attempt (more info ...)attempted-user  2014-9158      URL
39799FILE-PDF Adobe Acrobat Reader raster image memory corruption attempt (more info ...)attempted-user  2014-9158      URL
39802EXPLOIT-KIT Neutrino Exploit Kit Flash exploit download attempt (more info ...)trojan-activity        
39864FILE-PDF Adobe Reader CoolType engine FlateDecode use-after-free attempt (more info ...)attempted-user  2016-4255      URL
39865FILE-PDF Adobe Reader CoolType engine FlateDecode use-after-free attempt (more info ...)attempted-user  2016-4255      URL
39889FILE-PDF Adobe Acrobat invalid embedded font memory corruption attempt (more info ...)attempted-recon  2016-4208      URL
39890FILE-PDF Adobe Acrobat invalid embedded font memory corruption attempt (more info ...)attempted-user  2016-4208      URL
39922FILE-PDF Adobe Acrobat Reader raster image memory corruption attempt (more info ...)attempted-user  2014-9158      URL
39923FILE-PDF Adobe Acrobat Reader raster image memory corruption attempt (more info ...)attempted-user  2014-9158      URL
39954FILE-FLASH Adobe Flash Player attachMovie use after free attempt (more info ...)attempted-admin  2015-5551      URL
39955FILE-FLASH Adobe Flash Player attachMovie use after free attempt (more info ...)attempted-admin  2015-5551      URL
39956FILE-FLASH Adobe Flash Player FileReference type confusion attempt (more info ...)attempted-user  2016-1105      URL
39957FILE-FLASH Adobe Flash Player FileReference type confusion attempt (more info ...)attempted-user  2016-1105      URL
40009FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
40010FILE-FLASH Adobe Flash Player atomicCompareAndSwapLength integer overflow attempt (more info ...)attempted-user  2014-0569      URL
40151FILE-FLASH Adobe Flash Player DRMManager memory corruption attempt (more info ...)attempted-admin  2016-4285      URL
40153FILE-FLASH Adobe Flash Player malformed VideoFrame memory corruption attempt (more info ...)attempted-user  2016-4274      URL
40154FILE-FLASH Adobe Flash Player malformed VideoFrame memory corruption attempt (more info ...)attempted-user  2016-4274      URL
40155FILE-FLASH Adobe Flash AVC Decoder Memory Corruption attempt (more info ...)attempted-user  2016-4275      URL
40156FILE-FLASH Adobe Flash AVC Decoder Memory Corruption attempt (more info ...)attempted-user  2016-4275      URL
40157FILE-FLASH Adobe Flash Player malformed placeObject2 memory corruption attempt (more info ...)attempted-user  2016-4276      URL
40158FILE-FLASH Adobe Flash Player malformed placeObject2 memory corruption attempt (more info ...)attempted-user  2016-4276      URL
40159FILE-FLASH Adobe Flash Player NetStream type confusion attempt (more info ...)attempted-user  2016-4280      URL
40160FILE-FLASH Adobe Flash Player NetStream type confusion attempt (more info ...)attempted-user  2016-4280      URL
40166FILE-FLASH Adobe Flash Player ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2016-4283      URL
40167FILE-FLASH Adobe Flash Player ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2016-4283      URL
40168FILE-FLASH Adobe Flash Player DisplacementMapFilter use-after-free attempt (more info ...)attempted-user  2016-4272      URL
40169FILE-FLASH Adobe Flash Player DisplacementMapFilter use-after-free attempt (more info ...)attempted-user  2016-4272      URL
40176FILE-FLASH Adobe Flash ContextMenu Clone memory corruption vulnerability attempt (more info ...)attempted-user  2016-4284      URL
40177FILE-FLASH Adobe Flash ContextMenu Clone memory corruption vulnerability attempt (more info ...)attempted-user  2016-4284      URL
40178FILE-FLASH Adobe Flash Player local-with-filesystem sandbox escape attempt (more info ...)attempted-user  2016-4271      URL
40179FILE-FLASH Adobe Flash Player local-with-filesystem sandbox escape attempt (more info ...)attempted-user  2016-4271      URL
40180FILE-FLASH Adobe Flash Player local-with-filesystem sandbox escape attempt (more info ...)attempted-user  2016-4271      URL
40181FILE-FLASH Adobe Flash Player local-with-filesystem sandbox escape attempt (more info ...)attempted-user  2016-4271      URL
40218FILE-FLASH Adobe Flash Player AS2 custom getter addProperty use after free attempt (more info ...)attempted-user  2016-4232      URL
40219FILE-FLASH Adobe Flash Player AS2 custom getter addProperty use after free attempt (more info ...)attempted-user  2016-4232      URL
40236FILE-PDF Adobe Reader embedded font out of bounds memory access attempt (more info ...)attempted-user  2016-4207      URL
40237FILE-PDF Adobe Reader embedded font out of bounds memory access attempt (more info ...)attempted-user  2016-4207      URL
40323SERVER-OTHER Adobe ColdFusion RDS admin bypass attempt (more info ...)attempted-admin  2013-0632  57330    URL
40431FILE-PDF Adobe Acrobat Reader XFA app.setTimeOut memory corruption attempt (more info ...)attempted-admin  2017-2961  57931    URL
40435FILE-FLASH Adobe Flash Player malformed ActionConstantPool memory corruption attempt (more info ...)attempted-user  2016-4273      URL
40436FILE-PDF Adobe Acrobat Reader XSLT substring memory corruption attempt (more info ...)attempted-user  2016-6978      URL
40437FILE-PDF Adobe Acrobat Reader XSLT substring memory corruption attempt (more info ...)attempted-user  2016-6978      URL
40438FILE-FLASH Adobe Standalone Flash Player AS3 NetStream object use after free attempt (more info ...)attempted-user  2016-6981      
40439FILE-FLASH Adobe Standalone Flash Player AS3 NetStream object use after free attempt (more info ...)attempted-user  2016-6981      
40440FILE-PDF Adobe Reader TrueType font file numberofmetrics out of bounds read attempt (more info ...)attempted-user  2016-6954      URL
40441FILE-PDF Adobe Reader TrueType font file numberofmetrics out of bounds read attempt (more info ...)attempted-user  2016-6954      URL
40442FILE-FLASH Adobe Flash Player FrameLabel memory corruption attempt (more info ...)attempted-user  2016-6986      URL
40443FILE-FLASH Adobe Flash Player FrameLabel memory corruption attempt (more info ...)attempted-user  2016-6986      URL
40452FILE-FLASH Adobe Standalone Flash Player AS3 Primetime timeline ShimContentResolver out of bounds read attempt (more info ...)attempted-user  2016-6983      
40453FILE-FLASH Adobe Standalone Flash Player AS3 Primetime timeline ShimContentResolver out of bounds read attempt (more info ...)attempted-user  2016-6983      
40455FILE-PDF Adobe Acrobat Reader JPEG engine spurious object reference use after free attempt (more info ...)attempted-user  2016-1089      URL
40456FILE-PDF Adobe Acrobat Reader JPEG engine spurious object reference use after free attempt (more info ...)attempted-user  2016-1089      URL
40495FILE-FLASH Adobe Standalone Flash Player PSDK FlashRuntime mediaplayer pause attempt (more info ...)attempted-user  2016-6982      URL
40496FILE-FLASH Adobe Standalone Flash Player PSDK FlashRuntime mediaplayer pause attempt (more info ...)attempted-user  2016-6982      URL
40502FILE-FLASH Adobe Flash Player QOSProvider use-after-free attempt (more info ...)attempted-user  2016-6984      URL
40503FILE-FLASH Adobe Flash Player QOSProvider use-after-free attempt (more info ...)attempted-user  2016-6984      URL
40505FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6961      URL
40506FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6961      URL
40507FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6962      URL
40508FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6962      URL
40509FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6963      URL
40510FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6963      URL
40511FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6964      URL
40512FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6964      URL
40513FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6965      URL
40514FILE-PDF Adobe Reader XSLT Transform use after free attempt (more info ...)attempted-user  2016-6965      URL
40515FILE-PDF Adobe Acrobat Reader malformed unicode font name code execution attempt (more info ...)attempted-user  2016-6956      URL
40516FILE-PDF Adobe Acrobat Reader malformed unicode font name code execution attempt (more info ...)attempted-user  2016-6956      URL
40544FILE-FLASH Adobe Standalone Flash Player IExternalizable deserialization use after free attempt (more info ...)attempted-user  2016-7855      URL
40545FILE-FLASH Adobe Standalone Flash Player IExternalizable deserialization use after free attempt (more info ...)attempted-user  2016-7855      URL
40557FILE-PDF Adobe Acrobat Reader malformed object stream memory corruption attempt (more info ...)attempted-user  2016-6948      URL
40558FILE-PDF Adobe Acrobat Reader malformed object stream memory corruption attempt (more info ...)attempted-user  2016-6948      URL
40569FILE-PDF Adobe Acrobat Reader XFA relayoutPageArea memory corruption attempt (more info ...)attempted-user  2016-6952      URL
40570FILE-PDF Adobe Acrobat Reader XFA relayoutPageArea memory corruption attempt (more info ...)attempted-user  2016-6952      URL
40571FILE-PDF Adobe Reader corrupt bookmark use after free attempt (more info ...)attempted-user  2016-1091      URL
40572FILE-PDF Adobe Reader corrupt bookmark use after free attempt (more info ...)attempted-user  2016-1091      URL
40573FILE-PDF Adobe Acrobat Reader XFA resolveNode memory corruption attempt (more info ...)attempted-user  2017-2967      URL
40574FILE-PDF Adobe Acrobat Reader XFA resolveNode memory corruption attempt (more info ...)attempted-user  2017-2967      URL
40581FILE-FLASH Adobe Flash Player sentEvent use after free attempt (more info ...)attempted-user  2016-6987      URL
40582FILE-FLASH Adobe Flash Player sentEvent use after free attempt (more info ...)attempted-user  2016-6987      URL
40583FILE-FLASH Adobe Flash Player event handler out of bounds memory access attempt (more info ...)attempted-user  2016-6985      URL
40584FILE-FLASH Adobe Flash Player event handler out of bounds memory access attempt (more info ...)attempted-user  2016-6985      URL
40585FILE-PDF Adobe Acrobat Reader SaveAs use-after-free attempt (more info ...)attempted-user  2016-6945      URL
40586FILE-PDF Adobe Acrobat Reader SaveAs use-after-free attempt (more info ...)attempted-user  2016-6945      URL
40587FILE-PDF Adobe Reader XLST parsing engine use after free attempt (more info ...)attempted-user  2016-6979      URL
40588FILE-PDF Adobe Reader XLST parsing engine use after free attempt (more info ...)attempted-user  2016-6979      URL
40618FILE-PDF Adobe Reader XML Metadata memory corruption attempt (more info ...)attempted-user  2016-6943      URL
40619FILE-PDF Adobe Reader XML Metadata memory corruption attempt (more info ...)attempted-user  2016-6943      URL
40639FILE-PDF Adobe Acrobat Reader XFA addInstance use after free attempt (more info ...)attempted-user  2016-6953      URL
40640FILE-PDF Adobe Acrobat Reader XFA addInstance use after free attempt (more info ...)attempted-user  2016-6953      URL
40695FILE-PDF Adobe Reader parser object use-after-free attempt (more info ...)attempted-admin  2016-6949      URL
40696FILE-PDF Adobe Reader parser object use-after-free attempt (more info ...)attempted-admin  2016-6949      URL
40697FILE-PDF Adobe Reader MakeAccessible plugin heap overflow attempt (more info ...)attempted-admin  2016-6939      URL
40698FILE-PDF Adobe Reader MakeAccessible plugin heap overflow attempt (more info ...)attempted-admin  2016-6939      URL
40699FILE-PDF Adobe Reader MakeAccessible plugin heap overflow attempt (more info ...)attempted-admin  2016-6939      URL
40700FILE-PDF Adobe Reader MakeAccessible plugin heap overflow attempt (more info ...)attempted-admin  2016-6939      URL
40734FILE-FLASH Adobe Flash MovieClip proto chain manipulation targeting constructor use after free attempt (more info ...)attempted-user  2016-7865      URL
40735FILE-FLASH Adobe Flash MovieClip proto chain manipulation targeting constructor use after free attempt (more info ...)attempted-user  2016-7865      URL
40736FILE-FLASH Adobe Flash Player Primetime SDK AdvertisingMetadata type confustion attempt (more info ...)attempted-admin  2016-7860      URL
40737FILE-FLASH Adobe Flash Player Primetime SDK AdvertisingMetadata type confustion attempt (more info ...)attempted-admin  2016-7860      URL
40738FILE-FLASH Adobe Adobe Flash Player ActionExtends use after free attempt (more info ...)attempted-admin  2016-7859      URL
40739FILE-FLASH Adobe Flash Player ActionExtends use after free attempt (more info ...)attempted-admin  2016-7859      URL
40740FILE-FLASH Adobe Flash Player addCallback use after free attempt (more info ...)attempted-user  2016-7858      URL
40741FILE-FLASH Adobe Flash Player addCallback use after free attempt (more info ...)attempted-user  2016-7858      URL
40742FILE-FLASH Adobe Flash Player AVSegmentedSource use after free attempt (more info ...)attempted-user  2016-7857      URL
40743FILE-FLASH Adobe Flash Player AVSegmentedSource use after free attempt (more info ...)attempted-user  2016-7857      URL
40744FILE-FLASH Adobe Primetime SDK setObject type confusion attempt (more info ...)attempted-recon  2016-7861      URL
40745FILE-FLASH Adobe Primetime SDK setObject type confusion attempt (more info ...)attempted-recon  2016-7861      URL
40746FILE-FLASH Adobe Flash Player TextField use after free attempt (more info ...)attempted-user  2016-7863      URL
40747FILE-FLASH Adobe Flash Player TextField use after free attempt (more info ...)attempted-user  2016-7863      URL
40748FILE-FLASH Adobe Flash Player ASnative setFocus use after free attempt (more info ...)attempted-user  2016-7864      URL
40749FILE-FLASH Adobe Flash Player ASnative setFocus use after free attempt (more info ...)attempted-user  2016-7864      URL
40755FILE-FLASH Adobe Flash EnableDebugger2 obfuscation attempt (more info ...)attempted-user        URL
40780FILE-FLASH Adobe Flash Player LoadVars use-after-free attempt (more info ...)attempted-user  2016-0974      URL
40781FILE-FLASH Adobe Flash Player LoadVars use-after-free attempt (more info ...)attempted-user  2016-0974      URL
40798FILE-FLASH Adobe Standalone Flash Player IExternalizable deserialization use after free attempt (more info ...)attempted-user  2016-7855      URL
40799FILE-FLASH Adobe Standalone Flash Player IExternalizable deserialization use after free attempt (more info ...)attempted-user  2016-7855      URL
40818FILE-FLASH Adobe Flash Player TextField text use after free attempt (more info ...)attempted-admin  2015-8430      URL
40819FILE-FLASH Adobe Flash Player TextField text use after free attempt (more info ...)attempted-admin  2015-8430      URL
40996INDICATOR-COMPROMISE Adobe Flash Player ActionScript vulnerable RegExp verb usage detected (more info ...)attempted-user  2016-7867      URL
40997INDICATOR-COMPROMISE Adobe Flash Player ActionScript vulnerable RegExp verb usage detected (more info ...)attempted-user  2016-7867      URL
40998FILE-FLASH Adobe Flash Player NetConnection proxyType invalid value out of bounds read attempt (more info ...)attempted-user  2016-7874      URL
40999FILE-FLASH Adobe Flash Player NetConnection proxyType invalid value out of bounds read attempt (more info ...)attempted-user  2016-7874      URL
41000INDICATOR-COMPROMISE Adobe Flash Player ActionScript vulnerable RegExp verb usage detected (more info ...)attempted-user  2016-7869      URL
41001INDICATOR-COMPROMISE Adobe Flash Player ActionScript vulnerable RegExp verb usage detected (more info ...)attempted-user  2016-7869      URL
41002FILE-FLASH Adobe Flash Player Primetime SDK out of bounds read attempt (more info ...)attempted-user  2016-7873      URL
41003FILE-FLASH Adobe Flash Player Primetime SDK out of bounds read attempt (more info ...)attempted-user  2016-7873      URL
41004FILE-FLASH Adobe Flash Player Primetime MediaPlayerItemLoader QOSProvider object use after free attempt (more info ...)attempted-user  2018-4877      URL
41005FILE-FLASH Adobe Flash Player Primetime MediaPlayerItemLoader QOSProvider object use after free attempt (more info ...)attempted-user  2018-4877      URL
41006INDICATOR-COMPROMISE Adobe Flash Player ActionScript vulnerable RegExp verb usage detected (more info ...)attempted-user  2016-7870      URL
41007INDICATOR-COMPROMISE Adobe Flash Player ActionScript vulnerable RegExp verb usage detected (more info ...)attempted-user  2016-7870      URL
41008INDICATOR-COMPROMISE Adobe Flash Player ActionScript vulnerable RegExp verb usage detected (more info ...)attempted-user  2016-7868      URL
41009INDICATOR-COMPROMISE Adobe Flash Player ActionScript vulnerable RegExp verb usage detected (more info ...)attempted-user  2016-7868      URL
41010FILE-FLASH Adobe Flash Player BitmapData applyFilter integer overflow attempt (more info ...)attempted-user  2016-7875      URL
41011FILE-FLASH Adobe Flash Player BitmapData applyFilter integer overflow attempt (more info ...)attempted-user  2016-7875      URL
41012FILE-FLASH Adobe Flash Player NetConnection use after free attempt (more info ...)attempted-user  2016-7879      URL
41013FILE-FLASH Adobe Flash Player NetConnection use after free attempt (more info ...)attempted-user  2016-7879      URL
41014FILE-FLASH Acrobat Flash WorkerDomain memory corruption attempt (more info ...)attempted-user  2016-7871      URL
41015FILE-FLASH Acrobat Flash WorkerDomain memory corruption attempt (more info ...)attempted-user  2016-7871      URL
41016FILE-FLASH Adobe Flash Player writeDynamicProperties use-after-free attempt (more info ...)attempted-user  2016-7877      URL
41017FILE-FLASH Adobe Flash Player writeDynamicProperties use-after-free attempt (more info ...)attempted-user  2016-7877      URL
41020FILE-FLASH Adobe Flash Player onSetFocus movie clip use after free attempt (more info ...)attempted-user  2016-7892      URL
41021FILE-FLASH Adobe Flash Player onSetFocus movie clip use after free attempt (more info ...)attempted-user  2016-7892      URL
41022FILE-FLASH Adobe Flash Player addProperty use after free attempt (more info ...)attempted-admin  2016-7872      URL
41023FILE-FLASH Adobe Flash Player addProperty use after free attempt (more info ...)attempted-admin  2016-7872      URL
41024FILE-FLASH Adobe Flash Player addProperty use after free attempt (more info ...)attempted-admin  2016-7872      URL
41025FILE-FLASH Adobe Flash Player addProperty use after free attempt (more info ...)attempted-admin  2016-7872      URL
41045FILE-FLASH Adobe Flash Player TextField setter use after free attempt (more info ...)attempted-admin  2015-8434      URL
41046FILE-FLASH Adobe Flash Player TextField setter use after free attempt (more info ...)attempted-admin  2015-8434      URL
41138FILE-FLASH Adobe Flash Player display list structure memory corruption attempt (more info ...)attempted-user  2017-2930      URL
41139FILE-FLASH Adobe Flash Player display list structure memory corruption attempt (more info ...)attempted-user  2017-2930      URL
41142FILE-PDF Adobe Acrobat animateSyncButton use after free attempt (more info ...)attempted-user  2017-2958      URL
41143FILE-PDF Adobe Acrobat animateSyncButton use after free attempt (more info ...)attempted-user  2017-2958      URL
41144FILE-IMAGE Adobe Reader malformed app13 marker memory corruption attempt (more info ...)attempted-user  2017-2964      URL
41145FILE-IMAGE Adobe Reader malformed app13 marker memory corruption attempt (more info ...)attempted-user  2017-2964      URL
41146FILE-IMAGE Adobe Reader malformed app13 marker memory corruption attempt (more info ...)attempted-user  2017-2964      URL
41147FILE-IMAGE Adobe Reader malformed app13 marker memory corruption attempt (more info ...)attempted-user  2017-2964      URL
41148FILE-IMAGE Adobe Reader malformed app13 marker memory corruption attempt (more info ...)attempted-user  2017-2964      URL
41149FILE-IMAGE Adobe Reader malformed app13 marker memory corruption attempt (more info ...)attempted-user  2017-2964      URL
41154FILE-PDF Adobe Acrobat Reader malformed CFF global subroutine memory corruption attempt (more info ...)attempted-admin  2017-2941      URL
41155FILE-PDF Adobe Acrobat Reader malformed CFF global subroutine memory corruption attempt (more info ...)attempted-admin  2017-2941      URL
41156FILE-FLASH Adobe Flash Player malformed ATF file length heap overflow attempt (more info ...)attempted-user  2017-2934      URL
41157FILE-FLASH Adobe Flash Player malformed ATF file length heap overflow attempt (more info ...)attempted-user  2017-2934      URL
41158FILE-FLASH Adobe Flash Player visual blend out of bounds read attempt (more info ...)attempted-user  2017-2928      URL
41159FILE-FLASH Adobe Flash Player visual blend out of bounds read attempt (more info ...)attempted-user  2017-2928      URL
41160FILE-FLASH Acrobat Flash FileReference class use-after-free memory corruption attempt (more info ...)attempted-user  2017-2937      URL
41161FILE-FLASH Acrobat Flash FileReference class use-after-free memory corruption attempt (more info ...)attempted-user  2017-2937      URL
41163FILE-PDF Adobe Acrobat Reader XSL stylesheet heap overflow attempt (more info ...)attempted-user  2017-2949      URL
41164FILE-PDF Adobe Acrobat Reader XSL stylesheet heap overflow attempt (more info ...)attempted-user  2017-2949      URL
41165FILE-FLASH Acrobat Flash FileReference class use-after-free memory corruption attempt (more info ...)attempted-user  2017-2936      URL
41166FILE-FLASH Acrobat Flash FileReference class use-after-free memory corruption attempt (more info ...)attempted-user  2017-2936      URL
41181FILE-IMAGE Adobe Acrobat TIFF PhotometricInterpretation heap buffer overflow attempt (more info ...)attempted-user  2017-2966      URL
41182FILE-IMAGE Adobe Acrobat TIFF PhotometricInterpretation heap buffer overflow attempt (more info ...)attempted-user  2017-2966      URL
41183FILE-IMAGE Adobe Acrobat TIFF PhotometricInterpretation heap buffer overflow attempt (more info ...)attempted-user  2017-2966      URL
41184FILE-IMAGE Adobe Acrobat TIFF PhotometricInterpretation heap buffer overflow attempt (more info ...)attempted-user  2017-2966      URL
41193FILE-PDF Adobe Acrobat XFA engine stack buffer overflow attempt (more info ...)attempted-user  2017-2948      URL
41194FILE-PDF Adobe Acrobat XFA engine stack buffer overflow attempt (more info ...)attempted-user  2017-2948      URL
41198FILE-IMAGE Adobe Acrobat TIFF Software tag heap buffer overflow attempt (more info ...)attempted-user  2017-2965      URL
41199FILE-IMAGE Adobe Acrobat TIFF Software tag heap buffer overflow attempt (more info ...)attempted-user  2017-2965      URL
41200FILE-IMAGE Adobe Acrobat TIFF Software tag heap buffer overflow attempt (more info ...)attempted-user  2017-2965      URL
41201FILE-IMAGE Adobe Acrobat TIFF Software tag heap buffer overflow attempt (more info ...)attempted-user  2017-2965      URL
41202FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP2 segment out of bounds memory access attempt (more info ...)attempted-admin  2017-2959      URL
41203FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP2 segment out of bounds memory access attempt (more info ...)attempted-admin  2017-2959      URL
41214FILE-FLASH Adobe Flash Player onSetFocus movieclip use after free attempt (more info ...)attempted-user  2017-2932      URL
41215FILE-FLASH Adobe Flash Player onSetFocus movie clip use after free attempt (more info ...)attempted-user  2017-2932      URL
41319FILE-PDF Adobe Acrobat Reader cross reference table memory corruption attempt (more info ...)attempted-user  2016-2939      URL
41320FILE-PDF Adobe Acrobat Reader cross reference table memory corruption attempt (more info ...)attempted-user  2016-2939      URL
41325FILE-PDF Adobe Acrobat XFA Engine use after free attempt (more info ...)attempted-user  2017-2950      URL
41326FILE-PDF Adobe Acrobat XFA Engine use after free attempt (more info ...)attempted-user  2017-2950      URL
41329FILE-PDF Adobe Acrobat Reader APP13 heap overflow attempt (more info ...)attempted-user  2016-2946      URL
41330FILE-PDF Adobe Acrobat Reader APP13 heap overflow attempt (more info ...)attempted-user  2016-2946      URL
41332FILE-FLASH Adobe Flash Player FileReferenceList.browse type confusion attempt (more info ...)attempted-admin  2015-3120      URL
41333FILE-FLASH Adobe Flash Player FileReferenceList.browse type confusion attempt (more info ...)attempted-admin  2015-3120      URL
41338FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP1 segment out of bounds memory access attempt (more info ...)attempted-admin  2017-2960      URL
41339FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP1 segment out of bounds memory access attempt (more info ...)attempted-admin  2017-2960      URL
41340FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP1 segment out of bounds memory access attempt (more info ...)attempted-admin  2017-2960      URL
41341FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP1 segment out of bounds memory access attempt (more info ...)attempted-admin  2017-2960      URL
41342FILE-MULTIMEDIA Adobe Flash Player MP4 stsz atom memory corruption attempt (more info ...)attempted-user  2017-2926      URL
41343FILE-MULTIMEDIA Adobe Flash Player MP4 stsz atom memory corruption attempt (more info ...)attempted-user  2017-2926      URL
41353FILE-FLASH Adobe Flash Player StyleSheets use after free attempt (more info ...)attempted-user  2016-4174      URL
41354FILE-FLASH Adobe Flash Player StyleSheets use after free attempt (more info ...)attempted-user  2016-4174      URL
41357FILE-FLASH Adobe Flash Player Primetime SDK ShimContentResolver memory corruption attempt (more info ...)attempted-user  2016-4152      URL
41358FILE-FLASH Adobe Flash Player Primetime SDK ShimContentResolver memory corruption attempt (more info ...)attempted-user  2016-4152      URL
41391FILE-IMAGE Adobe Acrobat TIFF ICC tag heap buffer overflow attempt (more info ...)attempted-user  2017-2963      URL
41392FILE-IMAGE Adobe Acrobat TIFF ICC tag heap buffer overflow attempt (more info ...)attempted-user  2017-2963      URL
41393FILE-IMAGE Adobe Acrobat TIFF ICC tag heap buffer overflow attempt (more info ...)attempted-user  2017-2963      URL
41394FILE-IMAGE Adobe Acrobat TIFF ICC tag heap buffer overflow attempt (more info ...)attempted-user  2017-2963      URL
41395FILE-IMAGE Adobe Acrobat TIFF ICC tag heap buffer overflow attempt (more info ...)attempted-user  2017-2963      URL
41396FILE-IMAGE Adobe Acrobat TIFF ICC tag heap buffer overflow attempt (more info ...)attempted-user  2017-2963      URL
41397FILE-IMAGE Adobe Acrobat TIFF ICC tag heap buffer overflow attempt (more info ...)attempted-user  2017-2963      URL
41398FILE-IMAGE Adobe Acrobat TIFF ICC tag heap buffer overflow attempt (more info ...)attempted-user  2017-2963      URL
41399FILE-PDF Adobe Acrobat Reader xfa subform use after free attempt (more info ...)attempted-user  2019-8225      URL
41400FILE-PDF Adobe Acrobat Reader xfa subform use after free attempt (more info ...)attempted-user  2019-8225      URL
41412FILE-FLASH Adobe Flash Player custom toString function attempt (more info ...)attempted-user  2017-2951      URL
41418FILE-FLASH Adobe Flash Player NetConnection type confusion attempt (more info ...)attempted-user  2015-4433      
41419FILE-FLASH Adobe Flash Player NetConnection type confusion attempt (more info ...)attempted-user  2015-4433      
41472FILE-FLASH Adobe Flash Player broker arbitrary file write attempt (more info ...)attempted-user  2015-0301      URL
41473FILE-FLASH Adobe Flash Player broker arbitrary file write attempt (more info ...)attempted-user  2015-0301      URL
41479FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user  2015-5122      URL
41480FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user  2015-5122      URL
41481FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user  2015-5122      URL
41482FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user  2015-5122      URL
41486FILE-FLASH Adobe Flash Player AS2 TextField antiAliasType use after free attempt (more info ...)attempted-user  2015-8046      URL
41513FILE-PDF Adobe Reader setPersistent use after free attempt (more info ...)attempted-user  2016-1061  80358    URL
41514FILE-PDF Adobe Reader setPersistent use after free attempt (more info ...)attempted-user  2016-1061  80358    URL
41611FILE-OTHER Adobe Flash Player h264 decoder luminance adjustment out of bounds memory access attempt (more info ...)attempted-user  2017-2991      URL
41612FILE-OTHER Adobe Flash Player h264 decoder luminance adjustment out of bounds memory access attempt (more info ...)attempted-user  2017-2991      URL
41613FILE-OTHER Adobe Flash Player h264 decoder heap overflow attempt (more info ...)attempted-user  2017-2984      URL
41614FILE-OTHER Adobe Flash Player h264 decoder heap overflow attempt (more info ...)attempted-user  2017-2984      URL
41615FILE-OTHER Adobe Flash Player h264 decoder heap overflow attempt (more info ...)attempted-user  2017-2984      URL
41616FILE-OTHER Adobe Flash Player h264 decoder heap overflow attempt (more info ...)attempted-user  2017-2984      URL
41617FILE-OTHER Adobe Flash Player h264 decoder heap overflow attempt (more info ...)attempted-user  2017-2984      URL
41618FILE-OTHER Adobe Flash Player h264 decoder heap overflow attempt (more info ...)attempted-user  2017-2984      URL
41619FILE-FLASH Adobe Flash Player addEventListener use after free attempt (more info ...)attempted-user  2017-2982      URL
41620FILE-FLASH Adobe Flash Player addEventListener use after free attempt (more info ...)attempted-user  2017-2982      URL
41621FILE-FLASH Adobe Flash malformed FLV heap overflow attempt (more info ...)attempted-recon  2017-2986      URL
41622FILE-FLASH Adobe Flash malformed FLV heap overflow attempt (more info ...)attempted-recon  2017-2986      URL
41623FILE-FLASH Adobe Flash Player MessageChannel type confusion attempt (more info ...)attempted-admin  2017-2995      URL
41624FILE-FLASH Adobe Flash Player MessageChannel type confusion attempt (more info ...)attempted-admin  2017-2995      URL
41627FILE-FLASH Adobe Flash Player garbage collection use after free attempt (more info ...)attempted-user  2017-2988      URL
41628FILE-FLASH Adobe Flash Player garbage collection use after free attempt (more info ...)attempted-user  2017-2988      URL
41629FILE-FLASH Adobe Flash Player PSDK EventDispatch removeEventListener use after free attempt (more info ...)attempted-user  2017-2994      URL
41630FILE-FLASH Adobe Flash Player PSDK EventDispatch removeEventListener use after free attempt (more info ...)attempted-user  2017-2994      URL
41631FILE-OTHER Adobe Flash Player mp4 h264 decompression routine out of bounds read attempt (more info ...)attempted-user  2017-2990      URL
41632FILE-OTHER Adobe Flash Player mp4 h264 decompression routine out of bounds read attempt (more info ...)attempted-user  2017-2990      URL
41635FILE-OTHER Adobe AcrobatDC EMF buffer underflow attempt (more info ...)attempted-user  2015-5098      URL
41636FILE-OTHER Adobe AcrobatDC EMF buffer underflow attempt (more info ...)attempted-user  2015-5098      URL
41644FILE-FLASH Adobe Flash Player malformed DefineSprite tag memory corruption attempt (more info ...)attempted-admin  2015-3123      URL
41645FILE-FLASH Adobe Flash Player malformed DefineSprite tag memory corruption attempt (more info ...)attempted-admin  2015-3123      URL
41673FILE-FLASH Adobe Flash Player TextField object event handler use after free attempt (more info ...)attempted-user  2017-2993      URL
41674FILE-FLASH Adobe Flash Player TextField object event handler use after free attempt (more info ...)attempted-user  2017-2993      URL
41679FILE-FLASH Adobe Flash Player ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2017-2996      URL
41680FILE-FLASH Adobe Flash Player ShimContentResolver out of bounds memory access attempt (more info ...)attempted-user  2017-2996      URL
41705FILE-FLASH Adobe Flash Player invalid package script information use after free attempt (more info ...)attempted-user  2015-4430      URL
41706FILE-FLASH Adobe Flash Player invalid package script information use after free attempt (more info ...)attempted-user  2015-4430      URL
41708FILE-FLASH Adobe Flash Player custom valueOf function attempt (more info ...)attempted-user  2015-3130      URL
41709FILE-FLASH Adobe Flash Player custom valueOf function attempt (more info ...)attempted-user  2015-3130      URL
41740FILE-FLASH Adobe Flash Player custom toString and valueOf function attempt (more info ...)attempted-user  2015-3129      URL
41741FILE-FLASH Adobe Flash Player custom toString and valueOf function attempt (more info ...)attempted-user  2015-3129      URL
42006FILE-FLASH Adobe Flash Player Camera use after free attempt (more info ...)attempted-user  2017-3003      URL
42007FILE-FLASH Adobe Flash Player Camera use after free attempt (more info ...)attempted-user  2017-3003      URL
42010FILE-FLASH Adobe Flash Player TextField use after free attempt (more info ...)attempted-user  2017-3002      URL
42011FILE-FLASH Adobe Flash Player TextField use after free attempt (more info ...)attempted-user  2017-3002      URL
42012FILE-FLASH Adobe Flash Player AuditudeSettings stack overflow attempt (more info ...)attempted-user  2017-2997      URL
42013FILE-FLASH Adobe Flash Player AuditudeSettings stack overflow attempt (more info ...)attempted-user  2017-2997      URL
42044FILE-FLASH Adobe Flash Player custom object garbage collection use after free attempt (more info ...)attempted-user  2017-3059      URL
42045FILE-FLASH Adobe Flash Player custom object garbage collection use after free attempt (more info ...)attempted-user  2017-3059      URL
42046FILE-FLASH Adobe Flash Player custom object garbage collection use after free (more info ...)attempted-user  2017-3001      URL
42047FILE-FLASH Adobe Flash Player custom object garbage collection use after free (more info ...)attempted-user  2017-3001      URL
42052FILE-FLASH Adobe Flash Player Primetime TVSDK memory corruption attempt (more info ...)attempted-user  2017-2999  96866    URL
42053FILE-FLASH Adobe Flash Player Primetime TVSDK memory corruption attempt (more info ...)attempted-user  2017-2999  96866    URL
42096FILE-FLASH Adobe Flash Player Resolution Opportunity parameter memory corruption attempt (more info ...)attempted-user  2017-2998      URL
42097FILE-FLASH Adobe Flash Player Resolution Opportunity parameter memory corruption attempt (more info ...)attempted-user  2017-2998      URL
42206FILE-FLASH Adobe Flash Player allocator use-after-free attempt (more info ...)attempted-user  2017-3062      URL
42207FILE-FLASH Adobe Flash Player allocator use-after-free attempt (more info ...)attempted-user  2017-3062      URL
42212FILE-PDF Adobe Acrobat Reader embedded JPEG 2000 flst heap overflow attempt (more info ...)attempted-admin  2017-3055      URL
42213FILE-PDF Adobe Acrobat Reader embedded JPEG 2000 flst heap overflow attempt (more info ...)attempted-admin  2017-3055      URL
42214FILE-FLASH Adobe Flash Player NetStream use after free attempt (more info ...)attempted-user  2017-3036      URL
42215FILE-FLASH Adobe Flash Player NetStream use after free attempt (more info ...)attempted-user  2017-3063      URL
42216FILE-OTHER Adobe Acrobat Reader pcx planes memory corruption attempt (more info ...)attempted-user  2017-3036      URL
42217FILE-OTHER Adobe Acrobat Reader pcx planes memory corruption attempt (more info ...)attempted-user  2017-3036      URL
42218FILE-IMAGE Adobe Acrobat Pro malformed GIF memory corruption attempt (more info ...)attempted-user  2017-3050      URL
42219FILE-IMAGE Adobe Acrobat Pro malformed TIF memory corruption attempt (more info ...)attempted-user  2017-3050      URL
42275FILE-PDF Adobe Reader JPEG2000 pclr tag out of bounds read attempt (more info ...)attempted-user  2017-3045      URL
42276FILE-PDF Adobe Reader JPEG2000 pclr tag out of bounds read attempt (more info ...)attempted-user  2017-3045      URL
42296FILE-PDF Adobe Acrobat Reader malformed PRC file out of bounds read attempt (more info ...)attempted-user  2017-3019      URL
42297FILE-PDF Adobe Acrobat Reader malformed PRC file out of bounds read attempt (more info ...)attempted-user  2017-3019      URL
42299FILE-PDF Adobe PDF PPKLite security handler memory corruption vulnerability attempt (more info ...)attempted-user  2017-3039      URL
42309FILE-PDF Adobe Acrobat embedded JPEG2000 invalid header out of bounds memory access attempt (more info ...)attempted-user  2017-3022      URL
42310FILE-PDF Adobe Acrobat embedded JPEG2000 invalid header out of bounds memory access attempt (more info ...)attempted-user  2017-3022      URL
42324FILE-IMAGE Adobe Acrobat Reader overly large segment size out of bounds read attempt (more info ...)attempted-user  2017-3051      URL
42325FILE-IMAGE Adobe Acrobat Reader overly large segment size out of bounds read attempt (more info ...)attempted-user  2017-3051      URL
42412FILE-OTHER Adobe Director rcsL chunk parsing denial of service attempt (more info ...)denial-of-service  2012-2031      
42413FILE-OTHER Adobe Director rcsL chunk parsing denial of service attempt (more info ...)denial-of-service  2012-2031      
42422FILE-OTHER Adobe Director rcsL chunk parsing denial of service attempt (more info ...)denial-of-service  2012-2030      
42423FILE-OTHER Adobe Director rcsL chunk parsing denial of service attempt (more info ...)denial-of-service  2012-2030      
42788FILE-PDF Adobe Reader malformed app13 tag information disclosure attempt (more info ...)attempted-user  2017-3053      URL
42789FILE-PDF Adobe Reader malformed app13 tag information disclosure attempt (more info ...)attempted-user  2017-3053      URL
42790FILE-PDF Adobe Reader invalid object reference use after free attempt (more info ...)attempted-user  2017-3026      URL
42791FILE-PDF Adobe Reader invalid object reference use after free attempt (more info ...)attempted-user  2017-3026      URL
42792FILE-FLASH Adobe Flash Player FLV invalid tag buffer overflow attempt (more info ...)attempted-user  2017-3068      URL
42793FILE-FLASH Adobe Flash Player FLV invalid tag buffer overflow attempt (more info ...)attempted-user  2017-3068      URL
42794FILE-FLASH Adobe Flash Player beginGradientFill color array out of bounds read attempt (more info ...)attempted-user  2017-3074      URL
42795FILE-FLASH Adobe Flash Player beginGradientFill color array out of bounds read attempt (more info ...)attempted-user  2017-3074      URL
42796FILE-FLASH Adobe Flash Player ConvolutionFilter memory corruption attempt (more info ...)attempted-user  2017-3070      URL
42797FILE-FLASH Adobe Flash Player ConvolutionFilter memory corruption attempt (more info ...)attempted-user  2017-3070      URL
42800FILE-FLASH Adobe Flash Player ActionPush out of bounds read attempt (more info ...)attempted-user  2017-3060      URL
42801FILE-FLASH Adobe Flash Player ActionPush out of bounds read attempt (more info ...)attempted-user  2017-3060      URL
42802FILE-PDF Adobe Acrobat Reader malformed AES key memory corruption attempt (more info ...)attempted-user  2017-3030      URL
42803FILE-PDF Adobe Acrobat Reader malformed AES key memory corruption attempt (more info ...)attempted-user  2017-3030      URL
42807FILE-FLASH Adobe Standalone Flash Player BlendMode memory corruption attempt (more info ...)attempted-user  2017-3069      URL
42808FILE-FLASH Adobe Standalone Flash Player BlendMode memory corruption attempt (more info ...)attempted-user  2017-3069      URL
42809FILE-FLASH Adobe Flash Player BitmapData out of bounds memory access attempt (more info ...)attempted-user  2017-3072      URL
42810FILE-FLASH Adobe Flash Player BitmapData out of bounds memory access attempt (more info ...)attempted-user  2017-3072      URL
42813FILE-PDF Adobe Acrobat Reader malformed URI information disclosure attempt (more info ...)attempted-user  2017-3020  97554    URL
42814FILE-PDF Adobe Acrobat Reader malformed URI information disclosure attempt (more info ...)attempted-user  2017-3020  97554    URL
42815FILE-FLASH Adobe Flash Player display object mask use after free attempt (more info ...)attempted-user  2017-3073      URL
42816FILE-FLASH Adobe Flash Player display object mask use after free attempt (more info ...)attempted-user  2017-3073      URL
42817FILE-FLASH Adobe Flash Player DisplayObject use after free attempt (more info ...)attempted-user  2017-3071      URL
42818FILE-FLASH Adobe Flash Player DisplayObject use after free attempt (more info ...)attempted-user  2017-3071      URL
42844FILE-IMAGE Adobe Acrobat Pro malformed TIF heap overflow attempt (more info ...)attempted-user  2017-3049      URL
42845FILE-IMAGE Adobe Acrobat Pro malformed TIF heap overflow attempt (more info ...)attempted-user  2017-3049      URL
42859FILE-PDF Adobe Reader PDF memory corruption attempt (more info ...)attempted-user  2017-3017      URL
42860FILE-PDF Adobe Reader PDF memory corruption attempt (more info ...)attempted-user  2017-3017      URL
42868FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (more info ...)attempted-user  2018-16011      URL
42869FILE-PDF Adobe Acrobat Reader XFA forms engine use after free attempt (more info ...)attempted-user  2018-16011      URL
42888FILE-PDF Adobe Acrobat JP2 parser information disclosure attempt (more info ...)attempted-user  2017-3021      URL
42889FILE-PDF Adobe Acrobat JP2 parser information disclosure attempt (more info ...)attempted-user  2017-3021      URL
42896FILE-PDF Adobe Acrobat Reader CTJPEGWriter null pointer dereference attempt (more info ...)attempted-user  2017-3025      URL
42897FILE-PDF Adobe Acrobat Reader CTJPEGWriter null pointer dereference attempt (more info ...)attempted-user  2017-3025      URL
42930FILE-FLASH Adobe Flash Player DefineBitsJPEG2 invalid length memory corruption attempt (more info ...)attempted-user  2016-4179      URL
42931FILE-FLASH Adobe Flash Player DefineBitsJPEG2 invalid length memory corruption attempt (more info ...)attempted-user  2016-4179      URL
42942FILE-PDF Adobe Reader XFA large array use after free attempt (more info ...)attempted-user  2017-3014      URL
42943FILE-PDF Adobe Reader XFA large array use after free attempt (more info ...)attempted-user  2017-3014      URL
43048FILE-FLASH Adobe Flash Player JSON stringify memory corruption attempt (more info ...)attempted-user  2015-0324  72514    URL
43058FILE-FLASH Adobe Flash Player invalid DefinedEditText tag memory corruption attempt (more info ...)attempted-user  2017-3061      URL
43059FILE-FLASH Adobe Flash Player invalid DefinedEditText tag memory corruption attempt (more info ...)attempted-user  2017-3061      URL
43382FILE-FLASH Adobe Flash Player AdvertisingMetadata use after free attempt (more info ...)attempted-user  2017-3084      URL
43383FILE-FLASH Adobe Flash Player AdvertisingMetadata use after free attempt (more info ...)attempted-user  2017-3084      URL
43393FILE-FLASH Adobe Flash Player MPEG-4 AVC decoding out of bounds read attempt (more info ...)attempted-user  2017-3076      URL
43394FILE-FLASH Adobe Flash Player MPEG-4 AVC decoding out of bounds read attempt (more info ...)attempted-user  2017-3076      URL
43395FILE-FLASH Adobe Acrobat Reader profile use after free attempt (more info ...)attempted-user  2017-3083      URL
43396FILE-FLASH Adobe Acrobat Reader profile use after free attempt (more info ...)attempted-user  2017-3083      URL
43405FILE-FLASH Adobe Flash Player determinePreferredLocales out of bounds memory read attempt (more info ...)attempted-user  2017-3082      URL
43406FILE-FLASH Adobe Flash Player determinePreferredLocales out of bounds memory read attempt (more info ...)attempted-user  2017-3082      URL
43410FILE-FLASH Adobe Flash Player DisplayObject use after free attempt (more info ...)attempted-user  2017-3081      URL
43411FILE-FLASH Adobe Flash Player DisplayObject use after free attempt (more info ...)attempted-user  2017-3081      URL
43412FILE-FLASH Adobe Flash Player DisplayObject use after free attempt (more info ...)attempted-user  2017-3081      URL
43413FILE-FLASH Adobe Flash Player DisplayObject use after free attempt (more info ...)attempted-user  2017-3081      URL
43414FILE-FLASH Adobe Flash Player DisplayObject use after free attempt (more info ...)attempted-user  2017-3081      URL
43415FILE-FLASH Adobe Flash Player DisplayObject use after free attempt (more info ...)attempted-user  2017-3081      URL
43416FILE-FLASH Adobe Flash Player BitmapData object out of bounds access attempt (more info ...)attempted-user  2017-3079  99025    URL
43417FILE-FLASH Adobe Flash Player BitmapData object out of bounds access attempt (more info ...)attempted-user  2017-3079  99025    URL
43418FILE-FLASH Adobe Flash Player BitmapData object out of bounds access attempt (more info ...)attempted-user  2017-3079  99025    URL
43419FILE-FLASH Adobe Flash Player BitmapData object out of bounds access attempt (more info ...)attempted-user  2017-3079  99025    URL
43420FILE-FLASH Adobe Flash Player custom toString function attempt (more info ...)attempted-user  2017-3075      URL
43421FILE-FLASH Adobe Flash Player custom toString function attempt (more info ...)attempted-user  2017-3075      URL
43433FILE-PDF Adobe Acrobat Reader Annotations memory corruption attempt (more info ...)attempted-user  2017-3024      URL
43434FILE-PDF Adobe Acrobat Reader Annotations memory corruption attempt (more info ...)attempted-user  2017-3024      URL
43453FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
43454FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
43455FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7645      URL
43479FILE-FLASH Adobe Flash Player applyFilter memory corruption attempt (more info ...)attempted-user  2017-3100      
43480FILE-FLASH Adobe Flash Player applyFilter memory corruption attempt (more info ...)attempted-user  2017-3100      
43528FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2017-3099      URL
43529FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2017-3099      URL
43530FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2017-3099      URL
43531FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2017-3099      URL
43532FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2017-3099      URL
43533FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user  2017-3099      URL
43865FILE-IMAGE Adobe Reader EMF EMR_MOVETOEX memory corruption attempt (more info ...)attempted-user  2017-3123      URL
43866FILE-IMAGE Adobe Reader EMF EMR_MOVETOEX memory corruption attempt (more info ...)attempted-user  2017-3123      URL
43867FILE-PDF Adobe Acrobat Reader malformed TTF memory corruption attempt (more info ...)attempted-user  2017-3116      URL
43868FILE-PDF Adobe Acrobat Reader malformed TTF memory corruption attempt (more info ...)attempted-user  2017-3116      URL
43869FILE-PDF Adobe Acrobat Reader malformed TTF memory corruption attempt (more info ...)attempted-user  2017-3116      URL
43870FILE-PDF Adobe Acrobat Reader malformed TTF memory corruption attempt (more info ...)attempted-user  2017-3116      URL
43875FILE-OTHER Adobe Acrobat EMF with malformed embedded JPEG memory corruption attempt (more info ...)attempted-user  2017-11259      
43876FILE-OTHER Adobe Acrobat EMF with malformed embedded JPEG memory corruption attempt (more info ...)attempted-user  2017-11259      
43881FILE-PDF Adobe PDF file annotation plugin use after free memory corruption attempt (more info ...)attempted-user  2017-11231      URL
43882FILE-PDF Adobe PDF file annotation plugin use after free memory corruption attempt (more info ...)attempted-user  2017-11231      URL
43886FILE-PDF Adobe Acrobat Reader malformed UTF-16 string memory corruption attempt (more info ...)attempted-user  2017-11236      URL
43887FILE-PDF Adobe Acrobat Reader malformed UTF-16 string memory corruption attempt (more info ...)attempted-user  2017-11236      URL
43888FILE-MULTIMEDIA Adobe Professional EMF malformed EMR_BITBLT record out of bounds access attempt (more info ...)attempted-user  2018-15942      URL
43889FILE-MULTIMEDIA Adobe Professional EMF malformed EMR_BITBLT record out of bounds access attempt (more info ...)attempted-user  2018-15942      URL
43893FILE-OTHER Adobe Acrobat EMF file GIF LZW coding table memory corruption attempt (more info ...)attempted-user  2017-11258      
43894FILE-OTHER Adobe Acrobat EMF file GIF LZW coding table memory corruption attempt (more info ...)attempted-user  2017-11258      
43900FILE-OTHER Adobe Acrobat Professional XPS2PDF memory corruption attempt (more info ...)attempted-user  2017-11210      URL
43901FILE-OTHER Adobe Acrobat Professional XPS2PDF memory corruption attempt (more info ...)attempted-user  2017-11210      URL
43902FILE-IMAGE Adobe Reader EMF EMR_STROKEPATH memory corruption attempt (more info ...)attempted-user  2018-15986      URL
43903FILE-IMAGE Adobe Reader EMF EMR_STROKEPATH memory corruption attempt (more info ...)attempted-user  2018-15986      URL
43904FILE-PDF Adobe Reader execMenuItem buffer overflow attempt (more info ...)attempted-user  2017-11220      URL
43905FILE-PDF Adobe Reader execMenuItem buffer overflow attempt (more info ...)attempted-user  2017-11220      URL
43906FILE-PDF Adobe Reader XFA loadXML use after free attempt (more info ...)attempted-user  2017-11224      URL
43907FILE-PDF Adobe Reader XFA loadXML use after free attempt (more info ...)attempted-user  2017-11224      URL
43908FILE-IMAGE Adobe Acrobat Reader JPEG 2000 tile memory corruption attempt (more info ...)attempted-user  2017-11226      URL
43909FILE-IMAGE Adobe Acrobat Reader JPEG 2000 tile memory corruption attempt (more info ...)attempted-user  2017-11226      URL
43910FILE-IMAGE Adobe Acrobat Reader JPEG 2000 tile memory corruption attempt (more info ...)attempted-user  2017-11226      URL
43911FILE-IMAGE Adobe Acrobat Reader JPEG 2000 tile memory corruption attempt (more info ...)attempted-user  2017-11226      URL
43912FILE-OTHER Adobe Acrobat Professional XPS2PDF memory corruption attempt (more info ...)attempted-user  2017-11209      URL
43913FILE-OTHER Adobe Acrobat Professional XPS2PDF memory corruption attempt (more info ...)attempted-user  2017-11209      URL
43916FILE-OTHER Adobe Acrobat EMF file GIF sub-block memory corruption attempt (more info ...)attempted-user  2017-11260      URL
43917FILE-OTHER Adobe Acrobat EMF file GIF sub-block memory corruption attempt (more info ...)attempted-user  2017-11260      URL
43924FILE-PDF Adobe Acrobat Reader duplicate U3D header memory corruption attempt (more info ...)attempted-user  2017-11222      URL
43925FILE-PDF Adobe Acrobat Reader duplicate U3D header memory corruption attempt (more info ...)attempted-user  2017-11222      URL
43932EXPLOIT-KIT TERROR exploit kit FlashVars parameter shellcode (more info ...)attempted-user        
43940FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed EMR_COMMENT record out of bounds access attempt (more info ...)attempted-user  2017-11227      URL
43941FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed EMR_COMMENT record out of bounds access attempt (more info ...)attempted-user  2017-11227      URL
43948FILE-PDF Adobe Acrobat XFA engine heap memory corruption attempt (more info ...)attempted-user  2018-4888      URL
43949FILE-PDF Adobe Acrobat XFA engine heap memory corruption attempt (more info ...)attempted-user  2018-4888      URL
43963FILE-OTHER Adobe Acrobat EMF file kerning data memory corruption attempt (more info ...)attempted-user  2017-11239      URL
43964FILE-OTHER Adobe Acrobat EMF file kerning data memory corruption attempt (more info ...)attempted-user  2017-11239      URL
43968FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed EMR_POLYBEZIERTO16 out of bounds access attempt (more info ...)attempted-user  2017-11238      URL
43973FILE-OTHER Adobe Acrobat Pro malformed EMF comment memory corruption attempt (more info ...)attempted-user  2018-12857      URL
43974FILE-OTHER Adobe Acrobat Pro malformed EMF comment memory corruption attempt (more info ...)attempted-user  2018-12857      URL
43977FILE-PDF Adobe Acrobat Reader graphics engine memory corruption attempt (more info ...)attempted-user  2017-11265      URL
43978FILE-PDF Adobe Acrobat Reader graphics engine memory corruption attempt (more info ...)attempted-user  2017-11265      URL
43979FILE-PDF Adobe Acrobat Reader graphics engine memory corruption attempt (more info ...)attempted-user  2017-11265      URL
43980FILE-PDF Adobe Acrobat Reader graphics engine memory corruption attempt (more info ...)attempted-user  2017-11265      URL
43983FILE-OTHER Adobe Professional JPEG APP1 memory corruption attempt (more info ...)attempted-user  2017-11246      URL
43984FILE-OTHER Adobe Professional JPEG APP1 memory corruption attempt (more info ...)attempted-user  2017-11246      URL
43991FILE-PDF Adobe Acrobat Reader graphics engine memory corruption attempt (more info ...)attempted-user  2017-11252      URL
43992FILE-PDF Adobe Acrobat Reader graphics engine memory corruption attempt (more info ...)attempted-user  2017-11252      URL
43993FILE-PDF Adobe Acrobat Reader graphics engine memory corruption attempt (more info ...)attempted-user  2017-11252      URL
43994FILE-PDF Adobe Acrobat Reader graphics engine memory corruption attempt (more info ...)attempted-user  2017-11252      URL
43995FILE-FLASH Adobe Flash Player overly large cpool index out of bounds read attempt (more info ...)attempted-user  2017-3106      URL
43996FILE-FLASH Adobe Flash Player overly large cpool index out of bounds read attempt (more info ...)attempted-user  2017-3106      URL
43997FILE-PDF Adobe Acrobat Reader malformed TrueType font memory corruption attempt (more info ...)attempted-user  2017-11237      URL
43998FILE-PDF Adobe Acrobat Reader malformed TrueType font memory corruption attempt (more info ...)attempted-user  2017-11237      URL
43999FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed brush object attempt (more info ...)attempted-user  2017-11232      URL
44000FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed brush object attempt (more info ...)attempted-user  2017-11232      URL
44002FILE-FLASH Adobe Flash Player SMB sandbox bypass attempt (more info ...)attempted-user  2017-3085      URL
44003FILE-FLASH Adobe Flash Player SMB sandbox bypass attempt (more info ...)attempted-user  2017-3085      URL
44013FILE-PDF Adobe Acrobat Reader exportAsXFAStr use after free attempt (more info ...)attempted-user  2017-3113  100182    URL
44014FILE-PDF Adobe Acrobat Reader exportAsXFAStr use after free attempt (more info ...)attempted-user  2017-3113  100182    URL
44016FILE-FLASH Adobe Flash Player Rectangle constructor use after free attempt (more info ...)attempted-user  2016-4228      URL
44017FILE-FLASH Adobe Flash Player Rectangle constructor use after free attempt (more info ...)attempted-user  2016-4228      URL
44023FILE-IMAGE Adobe Acrobat Pro malformed TIFF memory corruption attempt (more info ...)attempted-user  2018-15927      URL
44025FILE-IMAGE Adobe Acrobat Pro malformed TIFF memory corruption attempt (more info ...)attempted-user  2017-16396      URL
44033FILE-OTHER Adobe Acrobat Professional EMF file JPEG Huffman table memory corrupt attempt (more info ...)attempted-user  2017-11268      URL
44034FILE-OTHER Adobe Acrobat Professional EMF file JPEG Huffman table memory corrupt attempt (more info ...)attempted-user  2017-11268      URL
44053FILE-PDF Adobe Professional JPEG file invalid quantization table use-after-free attempt (more info ...)attempted-user  2017-11235      URL
44054FILE-PDF Adobe Professional JPEG file invalid quantization table use-after-free attempt (more info ...)attempted-user  2017-11235      URL
44059FILE-IMAGE Adobe Acrobat Pro malformed TIFF memory corruption attempt (more info ...)attempted-user  2018-15955      URL
44060FILE-IMAGE Adobe Acrobat Pro malformed TIFF memory corruption attempt (more info ...)attempted-user  2018-15955      URL
44061FILE-IMAGE Adobe Acrobat Pro malformed TIFF memory corruption attempt (more info ...)attempted-user  2019-7037      URL
44062FILE-IMAGE Adobe Acrobat Pro malformed TIFF memory corruption attempt (more info ...)attempted-user  2019-7037      URL
44072FILE-PDF Adobe Acrobat Reader SubmitForm URL spoofing attempt (more info ...)attempted-recon  2017-3115      URL
44073FILE-PDF Adobe Acrobat Reader SubmitForm URL spoofing attempt (more info ...)attempted-recon  2017-3115      URL
44074FILE-PDF Adobe Acrobat Reader SubmitForm URL spoofing attempt (more info ...)attempted-recon  2017-3115      URL
44075FILE-PDF Adobe Acrobat Reader SubmitForm URL spoofing attempt (more info ...)attempted-recon  2017-3115      URL
44083FILE-PDF Adobe Acrobat XFA field initialization memory corruption attempt (more info ...)attempted-user  2017-11218      URL
44084FILE-PDF Adobe Acrobat XFA field initialization memory corruption attempt (more info ...)attempted-user  2017-11218      URL
44086FILE-OTHER Adobe Acrobat EMF line segments memory corruption attempt (more info ...)attempted-user  2017-11242      URL
44087FILE-OTHER Adobe Acrobat EMF line segments memory corruption attempt (more info ...)attempted-user  2017-11242      URL
44094FILE-MULTIMEDIA Adobe Professional EMF malformed EMR_STRETCHDIBITS record memory corruption attempt (more info ...)attempted-user  2017-11271      URL
44095FILE-MULTIMEDIA Adobe Professional EMF malformed EMR_STRETCHDIBITS record memory corruption attempt (more info ...)attempted-user  2017-11271      URL
44099FILE-MULTIMEDIA Adobe Professional EMF malformed EMR_STRETCHDIBITS record out of bounds access attempt (more info ...)attempted-user  2017-11270      URL
44100FILE-MULTIMEDIA Adobe Professional EMF malformed EMR_STRETCHDIBITS record out of bounds access attempt (more info ...)attempted-user  2017-11270      URL
44144FILE-PDF Adobe Reader XFA event use after free attempt (more info ...)attempted-user  2017-11223      URL
44145FILE-PDF Adobe Reader XFA event use after free attempt (more info ...)attempted-user  2017-11223      URL
44173FILE-FLASH Adobe Flash Player SharedObject use after free attempt (more info ...)attempted-user  2015-3132      
44174FILE-FLASH Adobe Flash Player SharedObject use after free attempt (more info ...)attempted-user  2015-3132      
44345FILE-FLASH Adobe Flash Player MP4 atom parser memory corruption attempt (more info ...)attempted-user  2017-11281      
44346FILE-FLASH Adobe Flash Player MP4 atom parser memory corruption attempt (more info ...)attempted-user  2017-11281      
44347FILE-FLASH Adobe Flash Player MP4 atom parser memory corruption attempt (more info ...)attempted-user  2017-11281      
44348FILE-FLASH Adobe Flash Player MP4 atom parser memory corruption attempt (more info ...)attempted-user  2017-11281      
44351FILE-FLASH Adobe Flash Player text handling memory corruption attempt (more info ...)attempted-user  2017-11282      URL
44352FILE-FLASH Adobe Flash Player text handling memory corruption attempt (more info ...)attempted-user  2017-11282      URL
44550FILE-IMAGE Adobe Acrobat Pro malformed EMF memory corruption attempt (more info ...)attempted-user  2017-11248      URL
44551FILE-IMAGE Adobe Acrobat Pro malformed EMF memory corruption attempt (more info ...)attempted-user  2017-11248      URL
44552FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
44553FILE-FLASH Adobe Flash Player toString type confusion memory corruption attempt (more info ...)attempted-user  2016-1019      URL
44583FILE-FLASH Adobe Flash Player array type confusion attempt (more info ...)attempted-user  2017-11292      URL
44584FILE-FLASH Adobe Flash Player array type confusion attempt (more info ...)attempted-user  2017-11292      URL
44793FILE-PDF Adobe Acrobat Reader JPEG2000 codestream memory corruption attempt (more info ...)attempted-user  2017-11227      URL
44794FILE-PDF Adobe Acrobat Reader JPEG2000 codestream memory corruption attempt (more info ...)attempted-user  2017-11227      URL
44853FILE-PDF Adobe Acrobat Reader malformed TTF buffer over-read attempt (more info ...)attempted-user  2017-16365      URL
44854FILE-PDF Adobe Acrobat Reader malformed TTF buffer over-read attempt (more info ...)attempted-user  2017-16365      URL
44859FILE-OTHER Adobe Acrobat Pro PNG file buffer over-read vulnerability attempt (more info ...)attempted-user  2017-16384      URL
44860FILE-OTHER Adobe Acrobat Pro PNG file buffer over-read vulnerability attempt (more info ...)attempted-user  2017-16384      URL
44861FILE-IMAGE Adobe Acrobat Pro malformed CommentExtension attempt (more info ...)attempted-user  2017-16410      URL
44862FILE-IMAGE Adobe Acrobat Pro malformed CommentExtension attempt (more info ...)attempted-user  2017-16410      URL
44871FILE-PDF Adobe Acrobat Reader out of bounds read attempt (more info ...)attempted-user  2017-16365      URL
44872FILE-PDF Adobe Acrobat Reader out of bounds read attempt (more info ...)attempted-user  2017-16365      URL
44873FILE-PDF Adobe Acrobat addAnnot object untrusted pointer dereference attempt (more info ...)denial-of-service  2017-16371      URL
44874FILE-PDF Adobe Acrobat addAnnot object untrusted pointer dereference attempt (more info ...)denial-of-service  2017-16371      URL
44880FILE-IMAGE Adobe Acrobat Pro EMF EMR_STRETCHDIBITS memory corruption attempt (more info ...)attempted-user  2017-16406      URL
44881FILE-IMAGE Adobe Acrobat Pro EMF EMR_STRETCHDIBITS memory corruption attempt (more info ...)attempted-user  2017-16406      URL
44882FILE-PDF Adobe Acrobat acrobat URI handler security bypass (more info ...)attempted-user  2017-16366      URL
44883FILE-PDF Adobe Acrobat acrobat URI handler security bypass (more info ...)attempted-user  2017-16366      URL
44884FILE-IMAGE Adobe Acrobat XPS unicode glyph pointer out of bounds (more info ...)attempted-user  2017-16399      URL
44885FILE-IMAGE Adobe Acrobat XPS unicode glyph pointer out of bounds (more info ...)attempted-user  2017-16399      URL
44887FILE-FLASH Adobe Flash Player bitmap hitTest integer overflow attempt (more info ...)attempted-admin  2017-11213      URL
44888FILE-FLASH Adobe Flash Player bitmap hitTest integer overflow attempt (more info ...)attempted-admin  2017-11213      URL
44891FILE-FLASH Adobe Flash Player determinePreferredLocales memory corruption attempt (more info ...)attempted-user  2017-3114      URL
44892FILE-FLASH Adobe Flash Player determinePreferredLocales memory corruption attempt (more info ...)attempted-user  2017-3114      URL
44893FILE-OTHER Adobe Professional EMF out of bounds read attempt (more info ...)attempted-user  2017-16409      URL
44894FILE-OTHER Adobe Professional EMF out of bounds read attempt (more info ...)attempted-user  2017-16409      URL
44902FILE-FLASH Adobe Flash Player PSDK Metadata memory corruption attempt (more info ...)attempted-user  2017-3112      URL
44903FILE-FLASH Adobe Flash Player PSDK Metadata memory corruption attempt (more info ...)attempted-user  2017-3112      URL
44912FILE-IMAGE Adobe Acrobat Pro invalid APP13 marker size attempt (more info ...)attempted-user  2017-16386      URL
44913FILE-IMAGE Adobe Acrobat Pro invalid APP13 marker size attempt (more info ...)attempted-user  2017-16386      URL
44923FILE-OTHER Adobe Acrobat EMF Bezier curve out of bounds read attempt (more info ...)attempted-user  2017-16403      URL
44924FILE-OTHER Adobe Acrobat EMF Bezier curve out of bounds read attempt (more info ...)attempted-user  2017-16403      URL
44925FILE-PDF Adobe Acrobat thermometer object untrusted pointer dereference attempt (more info ...)denial-of-service  2017-16372      URL
44926FILE-PDF Adobe Acrobat thermometer object untrusted pointer dereference attempt (more info ...)denial-of-service  2017-16372      URL
44927FILE-OTHER Adobe Acrobat Pro WebCapture out of bounds read attempt (more info ...)misc-activity  2017-16411      URL
44928FILE-OTHER Adobe Acrobat Pro WebCapture out of bounds read attempt (more info ...)misc-activity  2017-16411      URL
44929FILE-IMAGE Adobe Acrobat Pro EMF out of bounds write attempt (more info ...)attempted-user  2017-16406      URL
44930FILE-IMAGE Adobe Acrobat Pro EMF out of bounds write attempt (more info ...)attempted-user  2017-16406      URL
44933FILE-PDF Adobe Acrobat Reader untrusted pointer dereference attempt (more info ...)attempted-user  2017-16364      URL
44934FILE-PDF Adobe Acrobat Reader untrusted pointer dereference attempt (more info ...)attempted-user  2017-16364      URL
44937FILE-OTHER Adobe Acrobat EMFPlus out of bounds buffer overflow attempt (more info ...)attempted-user  2017-16404      URL
44938FILE-OTHER Adobe Acrobat EMFPlus out of bounds buffer overflow attempt (more info ...)attempted-user  2017-16404      URL
44939FILE-PDF Adobe Acrobat field dictionary value Unicode buffer overflow attempt (more info ...)attempted-user  2017-16368      URL
44940FILE-PDF Adobe Acrobat field dictionary value Unicode buffer overflow attempt (more info ...)attempted-user  2017-16368      URL
44951FILE-FLASH Adobe Flash Player Primetime SDK use after free attempt (more info ...)attempted-user  2017-11215      URL
44952FILE-FLASH Adobe Flash Player Primetime SDK use after free attempt (more info ...)attempted-user  2017-11215      URL
44953FILE-OTHER Adobe Acrobat EMF out of bounds buffer overflow attempt (more info ...)attempted-user  2017-16397      URL
44954FILE-OTHER Adobe Acrobat EMF out of bounds buffer overflow attempt (more info ...)attempted-user  2017-16397      URL
44959FILE-IMAGE Adobe Acrobat TIFF malformed YCbCrCoefficients values memory corruption attempt (more info ...)attempted-user  2017-16382      URL
44960FILE-IMAGE Adobe Acrobat TIFF malformed YCbCrCoefficients values memory corruption attempt (more info ...)attempted-user  2017-16382      URL
44961FILE-PDF Adobe Acrobat Reader untrusted pointer dereference attempt (more info ...)attempted-user  2017-16375      URL
44962FILE-PDF Adobe Acrobat Reader untrusted pointer dereference attempt (more info ...)attempted-user  2017-16375      URL
44963FILE-FLASH Adobe Flash Player tvsdk object use after free attempt (more info ...)attempted-user  2017-11225      URL
44964FILE-FLASH Adobe Flash Player tvsdk object use after free attempt (more info ...)attempted-user  2017-11225      URL
44965FILE-OTHER Adobe Acrobat Pro security bypass attempt (more info ...)attempted-user  2017-16369      URL
44966FILE-OTHER Adobe Acrobat Pro security bypass attempt (more info ...)attempted-user  2017-16369      URL
44969FILE-IMAGE Adobe Acrobat Pro EMF EmfPlusFont memory corruption attempt (more info ...)attempted-user  2017-16416      URL
44970FILE-IMAGE Adobe Acrobat Pro EMF EmfPlusFont memory corruption attempt (more info ...)attempted-user  2017-16416      URL
44976FILE-PDF Adobe Reader ActualText attribute type confusion attempt (more info ...)attempted-admin  2017-16367      URL
44977FILE-PDF Adobe Reader ActualText attribute type confusion attempt (more info ...)attempted-admin  2017-16367      URL
44983FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2017-16385      URL
44984FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2017-16385      URL
44988FILE-PDF Adobe Acrobat PDF font character encoding out of bounds write attempt (more info ...)attempted-user  2017-16415      URL
45031FILE-OTHER Adobe Acrobat JPEG2000 out of bounds buffer overflow attempt (more info ...)attempted-user  2017-16400      URL
45032FILE-OTHER Adobe Acrobat JPEG2000 out of bounds buffer overflow attempt (more info ...)attempted-user  2017-16400      URL
45035FILE-PDF Adobe Acrobat Reader Annotation use after free attempt (more info ...)attempted-user  2017-16388      URL
45036FILE-PDF Adobe Acrobat Reader Annotation use after free attempt (more info ...)attempted-user  2017-16388      URL
45040FILE-PDF Adobe Acrobat Reader Annotation use after free attempt (more info ...)attempted-user  2018-4959      URL
45041FILE-PDF Adobe Acrobat Reader Annotation use after free attempt (more info ...)attempted-user  2018-4959      URL
45044FILE-PDF Adobe Reader out of bounds memory access violation attempt (more info ...)attempted-user  2017-16405      URL
45045FILE-PDF Adobe Reader out of bounds memory access violation attempt (more info ...)attempted-user  2017-16405      URL
45309FILE-FLASH Adobe Flash Player ConvolutionFilter Matrix use after free attempt (more info ...)attempted-user  2015-3039      
45310FILE-FLASH Adobe Flash Player ConvolutionFilter Matrix use after free attempt (more info ...)attempted-user  2015-3039      
45404FILE-FLASH Adobe Flash Player malformed ATF buffer overflow attempt (more info ...)attempted-user  2018-4871      URL
45405FILE-FLASH Adobe Flash Player malformed ATF buffer overflow attempt (more info ...)attempted-user  2018-4871      URL
45459FILE-FLASH Adobe Flash Player movieclip attachbitmap use-after-free attempt (more info ...)attempted-user  2015-8410      URL
45500FILE-FLASH Adobe Flash Player movieclip startdrag use-after-free attempt (more info ...)attempted-user  2015-8411      URL
45501FILE-FLASH Adobe Flash Player movieclip startdrag use-after-free attempt (more info ...)attempted-user  2015-8411      URL
45546FILE-FLASH Adobe Flash Player DefineFont3 tag overly large NumGlyphs out of bounds read attempt (more info ...)attempted-user  2017-3064      
45547FILE-FLASH Adobe Flash Player DefineFont3 tag overly large NumGlyphs out of bounds read attempt (more info ...)attempted-user  2017-3064      
45593FILE-FLASH Adobe PSDK DRM Manager memory corruption attempt (more info ...)attempted-user  2018-4878      URL
45594FILE-FLASH Adobe PSDK DRM Manager memory corruption attempt (more info ...)attempted-user  2018-4878      URL
45595FILE-FLASH Adobe PSDK DRM Manager memory corruption attempt (more info ...)attempted-user  2018-4878      URL
45613FILE-FLASH Adobe Flash Player Selection.SetSelection use-after-free attempt (more info ...)attempted-user  2015-8413      URL
45614FILE-FLASH Adobe Flash Player Selection.SetSelection use-after-free attempt (more info ...)attempted-user  2015-8413      URL
45615FILE-FLASH Adobe Flash Player movieclip duplicateMovieClip use-after-free attempt (more info ...)attempted-user  2015-8412      URL
45616FILE-FLASH Adobe Flash Player movieclip duplicateMovieClip use-after-free attempt (more info ...)attempted-user  2015-8412      URL
45661FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-recon  2018-4912      URL
45662FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-recon  2018-4912      URL
45663FILE-OTHER Adobe Acrobat Pro malformed EMF EmfPlustDrawImagePoints out of bounds read attempt (more info ...)attempted-user  2018-4906      URL
45664FILE-OTHER Adobe Acrobat Pro malformed EMF EmfPlustDrawImagePoints out of bounds read attempt (more info ...)attempted-user  2018-4906      URL
45665FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-4903      URL
45666FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-4903      URL
45667FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-4903      URL
45668FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-4903      URL
45678FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawString out of bounds read attempt (more info ...)attempted-user  2018-4879      URL
45679FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawString out of bounds read attempt (more info ...)attempted-user  2018-4879      URL
45680FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawString out of bounds read attempt (more info ...)attempted-user  2018-4879      URL
45681FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawString out of bounds read attempt (more info ...)attempted-user  2018-4879      URL
45683FILE-FLASH Adobe PSDK DRM Manager memory corruption attempt (more info ...)attempted-user  2018-4878      URL
45691FILE-OTHER Adobe Acrobat Pro tiff parser out of bounds read attempt (more info ...)attempted-recon  2018-4891      URL
45692FILE-OTHER Adobe Acrobat Pro tiff parser out of bounds read attempt (more info ...)attempted-recon  2018-4891      URL
45723FILE-PDF Adobe Acrobat Reader byte order mark out of bounds read attempt (more info ...)attempted-user  2018-4882      URL
45724FILE-PDF Adobe Acrobat Reader byte order mark out of bounds read attempt (more info ...)attempted-user  2018-4882      URL
45725FILE-PDF Adobe Acrobat Reader byte order mark out of bounds read attempt (more info ...)attempted-user  2018-4882      URL
45726FILE-PDF Adobe Acrobat Reader byte order mark out of bounds read attempt (more info ...)attempted-user  2018-4882      URL
45727FILE-PDF Adobe Acrobat Reader byte order mark out of bounds read attempt (more info ...)attempted-user  2018-4882      URL
45728FILE-PDF Adobe Acrobat Reader byte order mark out of bounds read attempt (more info ...)attempted-user  2018-4882      URL
45736FILE-PDF Adobe Acrobat Reader JBIG2 decoder use after free attempt (more info ...)attempted-user  2018-4892      URL
45737FILE-PDF Adobe Acrobat Reader JBIG2 decoder use after free attempt (more info ...)attempted-user  2018-4892      URL
45744FILE-FLASH Adobe Flash Player ByteArray shading memory leak attempt (more info ...)attempted-recon  2015-3105  75086    URL
45786FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-4903      URL
45787FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-4903      URL
45788FILE-IMAGE Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-4903      URL
45789FILE-IMAGE Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-4903      URL
45791FILE-IMAGE Adobe Acrobat TIFF malformed YCbCrCoefficients values attempt (more info ...)attempted-user  2018-4905      URL
45792FILE-IMAGE Adobe Acrobat TIFF malformed YCbCrCoefficients values attempt (more info ...)attempted-user  2018-4905      URL
45793FILE-OTHER Adobe Acrobat Pro nested IFD out of bounds read attempt (more info ...)attempted-user  2018-4897      URL
45794FILE-OTHER Adobe Acrobat Pro nested IFD out of bounds read attempt (more info ...)attempted-user  2018-4897      URL
45814FILE-IMAGE Adobe Acrobat Pro malformed JPEG tag data buffer overflow attempt (more info ...)attempted-user  2018-4909      URL
45815FILE-IMAGE Adobe Acrobat Pro malformed JPEG tag data buffer overflow attempt (more info ...)attempted-user  2018-4909      URL
45849FILE-OTHER Adobe Acrobat Pro EMF malformed bitmap rectangle destination out of bounds read attempt (more info ...)attempted-user  2018-4886      URL
45850FILE-OTHER Adobe Acrobat Pro EMF malformed bitmap rectangle destination out of bounds read attempt (more info ...)attempted-user  2018-4886      URL
45852FILE-OTHER Adobe Acrobat Pro EMF malformed bitmap rectangle destination out of bounds read attempt (more info ...)attempted-user  2018-4886      URL
45855FILE-OTHER Adobe Acrobat Pro EMF out of bounds write attempt (more info ...)attempted-user  2018-4895      URL
45856FILE-OTHER Adobe Acrobat Pro EMF out of bounds write attempt (more info ...)attempted-user  2018-4895      URL
45860FILE-OTHER Adobe Acrobat Pro XPS malformed TIFF data out of bounds access attempt (more info ...)attempted-user  2018-4907      URL
45861FILE-OTHER Adobe Acrobat Pro XPS malformed TIFF data out of bounds access attempt (more info ...)attempted-user  2018-4907      URL
45862FILE-PDF Adobe Acrobat Reader bookmarkRoot memory corruption attempt (more info ...)attempted-user  2018-4911      URL
45863FILE-PDF Adobe Acrobat Reader bookmarkRoot memory corruption attempt (more info ...)attempted-user  2018-4911      URL
45864FILE-PDF Adobe Acrobat Reader bookmarkRoot memory corruption attempt (more info ...)attempted-user  2018-4911      URL
45865FILE-PDF Adobe Acrobat Reader bookmarkRoot memory corruption attempt (more info ...)attempted-user  2018-4911      URL
45866FILE-PDF Adobe Acrobat Reader invalid trailer memory corruption attempt (more info ...)attempted-user  2018-4901      URL
45867FILE-PDF Adobe Acrobat Reader invalid trailer memory corruption attempt (more info ...)attempted-user  2018-4901      URL
45868FILE-PDF Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt (more info ...)attempted-dos  2018-4902      URL
45869FILE-PDF Adobe Acrobat Reader getAnnotsRichMedia return type confusion attempt (more info ...)attempted-dos  2018-4902      URL
45989FILE-OTHER Adobe Acrobat Pro path element out of bounds memory access attempt (more info ...)attempted-admin  2018-4898      URL
45990FILE-OTHER Adobe Acrobat Pro path element out of bounds memory access attempt (more info ...)attempted-user  2018-4898      URL
46101PROTOCOL-SNMP Cisco IOS SNMP ciscoFlashFileEntry OID denial of service attempt (more info ...)attempted-dos  2018-0161      URL
46247FILE-FLASH Adobe Flash Player Primetime MediaPlayerItemLoader BlurFilter object out of bounds write attempt (more info ...)attempted-user  2018-4937      URL
46248FILE-FLASH Adobe Flash Player Primetime MediaPlayerItemLoader BlurFilter object out of bounds write attempt (more info ...)attempted-user  2018-4937      URL
46254FILE-FLASH Adobe Flash Player corrupt PNG image load out of bounds memory access attempt (more info ...)attempted-user  2018-4934      URL
46255FILE-FLASH Adobe Flash Player corrupt PNG image load out of bounds memory access attempt (more info ...)attempted-user  2018-4934      URL
46260FILE-FLASH Adobe Flash Player malformed DefineSound tag heap overflow attempt (more info ...)attempted-user  2018-4936      URL
46261FILE-FLASH Adobe Flash Player malformed DefineSound tag heap overflow attempt (more info ...)attempted-user  2018-4936      URL
46262FILE-FLASH Adobe Flash Player use after free attempt (more info ...)attempted-admin  2018-4932      URL
46263FILE-FLASH Adobe Flash Player use after free attempt (more info ...)attempted-admin  2018-4932      URL
46264FILE-OTHER Adobe Flash Player ATF image file out of bounds read attempt (more info ...)attempted-user  2018-4933      URL
46265FILE-OTHER Adobe Flash Player ATF image file out of bounds read attempt (more info ...)attempted-user  2018-4933      URL
46324FILE-FLASH Adobe PSDK DRM Manager memory corruption attempt (more info ...)attempted-user  2018-4878      URL
46404BROWSER-PLUGINS RealPlayer rmoc3260.dll ActiveX clsid access attempt (more info ...)attempted-user  2008-1309      
46405BROWSER-PLUGINS RealPlayer rmoc3260.dll ActiveX clsid access attempt (more info ...)attempted-user  2008-1309      
46490FILE-PDF Adobe Flash Player ActionScript setFocus use after free attempt (more info ...)attempted-user  2016-4227      URL
46491FILE-PDF Adobe Flash Player ActionScript setFocus use after free attempt (more info ...)attempted-user  2016-4227      URL
46598FILE-FLASH Adobe Flash Player ASnative MovieClip type confusion attempt (more info ...)attempted-user  2018-4945      URL
46599FILE-FLASH Adobe Flash Player ASnative MovieClip type confusion attempt (more info ...)attempted-user  2018-4945      URL
46638FILE-PDF Adobe Acrobat Reader DC OCG setIntent memory corruption attempt (more info ...)attempted-user  2018-4962      URL
46639FILE-PDF Adobe Acrobat Reader DC OCG setIntent memory corruption attempt (more info ...)attempted-user  2018-4962      URL
46645FILE-PDF Adobe Reader XFA node manipulation use-after-free attempt (more info ...)attempted-user  2018-4977      URL
46646FILE-PDF Adobe Reader XFA node manipulation use-after-free attempt (more info ...)attempted-user  2018-4977      URL
46647FILE-OTHER Adobe Acrobat EMF EmfPlusDrawBeziers buffer over-read attempt (more info ...)attempted-recon  2018-4949      URL
46648FILE-OTHER Adobe Acrobat EMF EmfPlusDrawBeziers buffer over-read attempt (more info ...)attempted-recon  2018-4949      URL
46649FILE-PDF Adobe Acrobat Reader XFA form use after free attempt (more info ...)attempted-user  2018-4974      URL
46650FILE-PDF Adobe Acrobat Reader XFA form use after free attempt (more info ...)attempted-user  2018-4974      URL
46651FILE-OTHER Adobe Acrobat Pro PDX malformed index out of bounds memory read attempt (more info ...)attempted-user  2018-4984      URL
46652FILE-OTHER Adobe Acrobat Pro PDX malformed index out of bounds memory read attempt (more info ...)attempted-user  2018-4984      URL
46655FILE-OTHER Adobe Acrobat XPS2PDF conversion buffer over-read attempt (more info ...)attempted-recon  2018-4960      URL
46656FILE-OTHER Adobe Acrobat XPS2PDF conversion buffer over-read attempt (more info ...)attempted-recon  2018-4960      URL
46660FILE-OTHER Adobe Acrobat Reader jp2 double free attempt (more info ...)attempted-user  2018-4990      URL
46662EXPLOIT-KIT FakeFlash update attempt (more info ...)attempted-user        
46675FILE-PDF Adobe Acrobat Reader go-to action NTLM credential disclosure attempt (more info ...)attempted-recon  2018-4993      URL
46676FILE-PDF Adobe Acrobat Reader go-to action NTLM credential disclosure attempt (more info ...)attempted-recon  2018-4993      URL
46677FILE-PDF Adobe Acrobat Reader go-to action NTLM credential disclosure attempt (more info ...)attempted-recon  2018-4993      URL
46678FILE-PDF Adobe Acrobat Reader go-to action NTLM credential disclosure attempt (more info ...)attempted-recon  2018-4993      URL
46680FILE-PDF Adobe Acrobat Reader security bypass attempt (more info ...)attempted-admin  2018-4979      URL
46681FILE-PDF Adobe Acrobat Reader security bypass attempt (more info ...)attempted-admin  2018-4979      URL
46686FILE-PDF Adobe Acrobat XFA field type confusion overflow attempt (more info ...)attempted-user  2018-4953      URL
46687FILE-PDF Adobe Acrobat XFA field type confusion overflow attempt (more info ...)attempted-user  2018-4953      URL
46688FILE-IMAGE Adobe Acrobat XPS out-of-bounds read attempt (more info ...)attempted-user  2018-4955      URL
46689FILE-IMAGE Adobe Acrobat XPS out-of-bounds read attempt (more info ...)attempted-user  2018-4955      URL
46690FILE-OTHER Adobe Acrobat Pro path rendertransform out of bound write attempt (more info ...)attempted-user  2018-4967      URL
46691FILE-OTHER Adobe Acrobat Pro path rendertransform out of bound write attempt (more info ...)attempted-user  2018-4967      URL
46692FILE-IMAGE Adobe Acrobat EmfPlusDrawCurve out of bounds read attempt (more info ...)attempted-user  2018-4976      URL
46693FILE-IMAGE Adobe Acrobat EmfPlusDrawCurve out of bounds read attempt (more info ...)attempted-user  2018-4976      URL
46694FILE-OTHER Adobe Acrobat Pro EMF embedded GIF memory corruption attempt (more info ...)attempted-user  2018-4966      URL
46695FILE-OTHER Adobe Acrobat Pro EMF embedded GIF memory corruption attempt (more info ...)attempted-user  2018-4966      URL
46696FILE-PDF Adobe Acrobat Reader XFA use after free attempt (more info ...)attempted-user  2018-4952      URL
46697FILE-PDF Adobe Acrobat Reader XFA use after free attempt (more info ...)attempted-user  2018-4952      URL
46698FILE-OTHER Adobe Acrobat EMF embedded DIB out of bound read attempt (more info ...)attempted-user  2018-4968      URL
46699FILE-OTHER Adobe Acrobat EMF embedded DIB out of bound read attempt (more info ...)attempted-user  2018-4968      URL
46701FILE-IMAGE Adobe Acrboat EMF invalid EMR_STRETCHDIBITS record out-of-bounds read attempt (more info ...)attempted-recon  2018-4963      URL
46702FILE-IMAGE Adobe Acrboat EMF invalid EMR_STRETCHDIBITS record out-of-bounds read attempt (more info ...)attempted-recon  2018-4963      URL
46703FILE-OTHER Adobe Acrobat Pro EMF EMR_STRETCHDIBITS size out of bounds read attempt (more info ...)attempted-user  2018-4964      URL
46704FILE-OTHER Adobe Acrobat Pro EMF EMR_STRETCHDIBITS size out of bounds read attempt (more info ...)attempted-user  2018-4964      URL
46705FILE-PDF Adobe Acrobat ADBCAnnotEnumerator use after free attempt (more info ...)attempted-user  2018-4980      URL
46706FILE-PDF Adobe Acrobat ADBCAnnotEnumerator use after free attempt (more info ...)attempted-user  2018-4980      URL
46707FILE-OTHER Adobe Acrobat EMF malformed EmfPlusPointF object buffer overflow attempt (more info ...)attempted-user  2018-4965      URL
46708FILE-OTHER Adobe Acrobat EMF malformed EmfPlusPointF object buffer overflow attempt (more info ...)attempted-user  2018-4965      URL
46709FILE-OTHER Adobe Professional EMF embedded image heap overflow attempt (more info ...)attempted-user  2018-4982      URL
46710FILE-OTHER Adobe Professional EMF embedded image heap overflow attempt (more info ...)attempted-user  2018-4982      URL
46717FILE-IMAGE Adobe Acrobat Pro EMF file EMFPlusPath object heap overflow attempt (more info ...)attempted-user  2018-4978      URL
46719FILE-IMAGE Adobe Acrobat Pro EMF file EMFPlusPath object heap overflow attempt (more info ...)attempted-user  2018-4978      URL
46720FILE-IMAGE Adobe Acrobat Pro EMF file EMFPlusPath object heap overflow attempt (more info ...)attempted-user  2018-4978      URL
46723FILE-PDF Adobe Acrobat Reader pointer dereference attempt (more info ...)attempted-user  2018-4987      URL
46724FILE-PDF Adobe Acrobat Reader pointer dereference attempt (more info ...)attempted-user  2018-4987      URL
46727FILE-OTHER Adobe Acrobat EMF embedded GIF LZW compression out of bound read attempt (more info ...)attempted-user  2018-4969      URL
46728FILE-OTHER Adobe Acrobat EMF embedded GIF LZW compression out of bound read attempt (more info ...)attempted-user  2018-4969      URL
46731FILE-PDF Adobe Reader malformed JPEG2000 image invalid colr size out of bounds read attempt (more info ...)attempted-user  2018-4985      URL
46732FILE-PDF Adobe Reader malformed JPEG2000 image invalid colr size out of bounds read attempt (more info ...)attempted-user  2018-4985      URL
46733FILE-OTHER Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-4986      URL
46734FILE-OTHER Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-4986      URL
46809FILE-PDF Adobe Acrobat Reader font enumeration use after free attempt (more info ...)attempted-user  2018-4971      URL
46810FILE-PDF Adobe Acrobat Reader font enumeration use after free attempt (more info ...)attempted-user  2018-4971      URL
46812FILE-OTHER Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-4972      URL
46813FILE-OTHER Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-4972      URL
46856FILE-PDF ADOBE ActiveX Browser Plugin client side request injection attempt (more info ...)attempted-user  2018-4995      URL
46857FILE-PDF ADOBE ActiveX Browser Plugin client side request injection attempt (more info ...)attempted-user  2018-4995      URL
46875FILE-IMAGE Adobe Acrobat Pro EMF file EMFPlusPath object out of bounds read attempt (more info ...)attempted-user  2018-4970      URL
46876FILE-IMAGE Adobe Acrobat Pro EMF file EMFPlusPath object out of bounds read attempt (more info ...)attempted-user  2018-4970      URL
46917FILE-FLASH Adobe Flash Player out of bounds write attempt (more info ...)attempted-user  2018-5002      
46918FILE-FLASH Adobe Flash Player out of bounds write attempt (more info ...)attempted-user  2018-5002      
46919FILE-FLASH Adobe Flash Player out of bounds write attempt (more info ...)attempted-user  2018-5002      
46920FILE-FLASH Adobe Flash Player out of bounds write attempt (more info ...)attempted-user  2018-5002      
46949FILE-FLASH Adobe Flash Player out of bounds memory access attempt (more info ...)attempted-user  2018-5001      URL
46950FILE-FLASH Adobe Flash Player out of bounds memory access attempt (more info ...)attempted-user  2018-5001      URL
47123FILE-OTHER Adobe Acrobat Pro XPS embedded JPEG with malformed copyright tag heap overflow attempt (more info ...)attempted-user  2018-5028      URL
47124FILE-OTHER Adobe Acrobat Pro XPS embedded JPEG with malformed copyright tag heap overflow attempt (more info ...)attempted-user  2018-5028      URL
47125FILE-OTHER Adobe Acrobat Pro XPS embedded JPEG with malformed copyright tag heap overflow attempt (more info ...)attempted-user  2018-5028      URL
47126FILE-OTHER Adobe Acrobat Pro XPS embedded JPEG with malformed copyright tag heap overflow attempt (more info ...)attempted-user  2018-5028      URL
47127FILE-FLASH Adobe Flash Player malformed ActionSetTarget record information disclosure attempt (more info ...)attempted-user  2018-5008      URL
47128FILE-FLASH Adobe Flash Player malformed ActionSetTarget record information disclosure attempt (more info ...)attempted-user  2018-5008      URL
47132FILE-OTHER Adobe Acrobat Pro EMF Alphablend memory corruption attempt (more info ...)attempted-user  2018-5062      URL
47149FILE-PDF Adobe Acrobat Reader removeLinks use after free attempt (more info ...)attempted-user  2018-12797      URL
47150FILE-PDF Adobe Acrobat Reader removeLinks use after free attempt (more info ...)attempted-user  2018-12797      URL
47162FILE-PDF Adobe Reader XFA nested subforms out-of-bounds read attempt (more info ...)attempted-user  2018-12757      URL
47163FILE-PDF Adobe Reader XFA nested subforms out-of-bounds read attempt (more info ...)attempted-user  2018-12757      URL
47164FILE-PDF Adobe Acrobat Pro HTML image input element use-after-free attempt (more info ...)attempted-user  2018-12770      URL
47165FILE-PDF Adobe Acrobat Pro HTML image input element use-after-free attempt (more info ...)attempted-user  2018-12770      URL
47167FILE-PDF Adobe Acrobat Reader PageLabels heap buffer overflow attempt (more info ...)attempted-user  2018-12798      URL
47168FILE-PDF Adobe Acrobat Reader PageLabels heap buffer overflow attempt (more info ...)attempted-user  2018-12798      URL
47169FILE-PDF Adobe Acrobat Reader PageLabels heap buffer overflow attempt (more info ...)attempted-user  2018-12798      URL
47170FILE-PDF Adobe Acrobat Reader PageLabels heap buffer overflow attempt (more info ...)attempted-user  2018-12798      URL
47179FILE-OTHER Adobe Acrobat Pro EMF invalid EmfPlusFillRects out-of-bounds read attempt (more info ...)attempted-user  2018-5010      URL
47180FILE-OTHER Adobe Acrobat Pro EMF invalid EmfPlusFillRects out-of-bounds read attempt (more info ...)attempted-user  2018-5010      URL
47181FILE-OTHER Adobe Acrobat Pro EMF file uninitialized pointer dereference attempt (more info ...)attempted-user  2018-5012      URL
47182FILE-OTHER Adobe Acrobat Pro EMF file uninitialized pointer dereference attempt (more info ...)attempted-user  2018-5012      URL
47183FILE-OTHER Adobe Acrobat Pro EMF EmfPlusFillRects type confusion attempt (more info ...)attempted-user  2018-5057      URL
47184FILE-OTHER Adobe Acrobat Pro EMF EmfPlusFillRects type confusion attempt (more info ...)attempted-user  2018-5057      URL
47185FILE-PDF Adobe Acrobat Pro EMF EmfPlusDrawLines heap overflow attempt (more info ...)attempted-user  2018-5067      URL
47186FILE-PDF Adobe Acrobat Pro EMF EmfPlusDrawLines heap overflow attempt (more info ...)attempted-user  2018-5067      URL
47191FILE-FLASH Adobe Flash Player ActionScript NetConnection type confusion attempt (more info ...)attempted-user  2018-5007      URL
47192FILE-FLASH Adobe Flash Player ActionScript NetConnection type confusion attempt (more info ...)attempted-user  2018-5007      URL
47193FILE-OTHER Adobe Acrobat Pro EMF use-after-free attempt (more info ...)attempted-user  2018-12796      URL
47194FILE-OTHER Adobe Acrobat Pro EMF use-after-free attempt (more info ...)attempted-user  2018-12796      URL
47197FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-12781      URL
47198FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-12781      URL
47208FILE-OTHER Adobe Acrobat Pro XPS out-of-bounds read attempt (more info ...)attempted-recon  2018-5016      URL
47209FILE-OTHER Adobe Acrobat Pro XPS out-of-bounds read attempt (more info ...)attempted-recon  2018-5016      URL
47210FILE-IMAGE Adobe Acrobat Pro EMF file EmfPlusDrawImagePoints heap overflow attempt (more info ...)attempted-user  2018-5032      URL
47211FILE-IMAGE Adobe Acrobat Pro EMF file EmfPlusDrawImagePoints heap overflow attempt (more info ...)attempted-user  2018-5032      URL
47217FILE-OTHER Adobe Acrobat Pro XPS heap overflow attempt (more info ...)attempted-user  2018-5015      URL
47218FILE-OTHER Adobe Acrobat Pro XPS heap overflow attempt (more info ...)attempted-user  2018-5015      URL
47223FILE-PDF Adobe Flash Player ActionScript setFocus use after free attempt (more info ...)attempted-user  2016-4227      URL
47224FILE-PDF Adobe Flash Player ActionScript setFocus use after free attempt (more info ...)attempted-user  2016-4227      URL
47225FILE-PDF Adobe Reader annotated page object out-of-bounds read attempt (more info ...)attempted-user  2018-5026      URL
47226FILE-PDF Adobe Reader annotated page object out-of-bounds read attempt (more info ...)attempted-user  2018-5026      URL
47237FILE-OTHER Adobe Acrobat Pro XPS out-of-bounds read attempt (more info ...)attempted-user  2018-5017      URL
47238FILE-OTHER Adobe Acrobat Pro XPS out-of-bounds read attempt (more info ...)attempted-user  2018-5017      URL
47239FILE-PDF Adobe Acrobat Reader U3D data stream heap overflow attempt (more info ...)attempted-user  2018-5049      URL
47240FILE-PDF Adobe Acrobat Reader U3D data stream heap overflow attempt (more info ...)attempted-user  2018-5049      URL
47247FILE-IMAGE Adobe Acrobat Pro crafted GIF file out-of-bounds read attempt (more info ...)attempted-user  2018-5050      URL
47248FILE-IMAGE Adobe Acrobat Pro crafted GIF file out-of-bounds read attempt (more info ...)attempted-user  2018-5050      URL
47283FILE-OTHER Adobe Reader HTML to PDF conversion getMatchedCSSRules use-after-free attempt (more info ...)attempted-user  2018-12877      URL
47284FILE-OTHER Adobe Reader HTML to PDF conversion getMatchedCSSRules use-after-free attempt (more info ...)attempted-user  2018-12877      URL
47297FILE-PDF Adobe Acrobat Reader use-after-free attempt (more info ...)attempted-user  2018-5009      URL
47298FILE-PDF Adobe Acrobat Reader use-after-free attempt (more info ...)attempted-user  2018-5009      URL
47306FILE-OTHER Adobe Acrobat Distiller PostScript pdfmark out-of-bounds write attempt (more info ...)attempted-user  2018-12758      URL
47307FILE-OTHER Adobe Acrobat Distiller PostScript pdfmark out-of-bounds write attempt (more info ...)attempted-user  2018-12758      URL
47308FILE-OTHER Adobe Acrobat Pro EMF RegionNodeCount out-of-bounds write attempt (more info ...)attempted-user  2018-5020      URL
47309FILE-OTHER Adobe Acrobat Pro EMF RegionNodeCount out-of-bounds write attempt (more info ...)attempted-user  2018-5020      URL
47316FILE-OTHER Adobe Acrobat Pro EmfPlusDrawPie out-of-bounds write attempt (more info ...)attempted-user  2018-12760      
47317FILE-OTHER Adobe Acrobat Pro EmfPlusDrawPie out-of-bounds write attempt (more info ...)attempted-user  2018-12760      
47345FILE-OTHER Adobe Acrobat Pro EMF EMR_CREATEDIBPATTERNBRUSHPT record buffer overflow attempt (more info ...)attempted-user  2018-5034      URL
47346FILE-OTHER Adobe Acrobat Pro EMF EMR_CREATEDIBPATTERNBRUSHPT record buffer overflow attempt (more info ...)attempted-user  2018-5034      URL
47355FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawPath out of bounds read attempt (more info ...)attempted-recon        
47371FILE-PDF Adobe Acrobat Reader XSLT engine use after free attempt (more info ...)attempted-user  2018-5065      URL
47372FILE-PDF Adobe Acrobat Reader XSLT engine use after free attempt (more info ...)attempted-user  2018-5065      URL
47396FILE-IMAGE Adobe Acrobat Reader malformed JPEG quantization table out-of-bounds write attempt (more info ...)attempted-user  2018-5069      URL
47397FILE-IMAGE Adobe Acrobat Reader malformed JPEG quantization table out-of-bounds write attempt (more info ...)attempted-user  2018-5069      URL
47438FILE-PDF Adobe Acrobat Reader JBIG parsing out of bounds read attempt (more info ...)misc-activity  2018-15929      URL
47439FILE-PDF Adobe Acrobat Reader JBIG parsing out of bounds read attempt (more info ...)misc-activity  2018-15929      URL
47529FILE-MULTIMEDIA Adobe Flash Player malformed COMM ID3 frame out-of-bounds read attempt (more info ...)attempted-user  2018-12824      URL
47530FILE-MULTIMEDIA Adobe Flash Player malformed COMM ID3 frame out-of-bounds read attempt (more info ...)attempted-user  2018-12824      URL
47531FILE-FLASH Adobe Flash Player Vector.String class out-of-bounds read attempt (more info ...)attempted-user  2018-12826      URL
47532FILE-FLASH Adobe Flash Player Vector.String class out-of-bounds read attempt (more info ...)attempted-user  2018-12826      URL
47533FILE-MULTIMEDIA Adobe Flash Player malformed MP4-AVC out-of-bounds read attempt (more info ...)attempted-user  2018-12827      URL
47534FILE-MULTIMEDIA Adobe Flash Player malformed MP4-AVC out-of-bounds read attempt (more info ...)attempted-user  2018-12827      URL
47574FILE-PDF Adobe Acrobat Reader PDF out of bound write attempt (more info ...)attempted-user  2018-12808      URL
47575FILE-PDF Adobe Acrobat Reader PDF out of bound write attempt (more info ...)attempted-user  2018-12808      URL
47623FILE-PDF Adobe Acrobat Reader JBIG engine crafted symbol dictionary out-of-bounds read attempt (more info ...)attempted-user  2018-12765      URL
47624FILE-PDF Adobe Acrobat Reader JBIG engine crafted symbol dictionary out-of-bounds read attempt (more info ...)attempted-user  2018-12765      URL
47628FILE-OTHER Adobe Professional EMF embedded image heap overflow attempt (more info ...)attempted-user  2018-4982      URL
47629FILE-OTHER Adobe Professional EMF embedded image heap overflow attempt (more info ...)attempted-user  2018-4982      URL
47630FILE-OTHER Adobe Acrobat Pro untrusted pointer dereference attempt (more info ...)attempted-user  2018-12799      URL
47631FILE-OTHER Adobe Acrobat Pro untrusted pointer dereference attempt (more info ...)attempted-user  2018-12799      URL
47647FILE-PDF Adobe Acrobat Reader JBIG2 symbol header out of bounds read attempt (more info ...)attempted-user  2018-12768      URL
47648FILE-PDF Adobe Acrobat Reader JBIG2 symbol header out of bounds read attempt (more info ...)attempted-user  2018-12768      URL
47666FILE-PDF Adobe Acrobat Reader JBIG malformed adaptive template pixel out-of-bounds read attempt (more info ...)attempted-user  2018-12764      URL
47667FILE-PDF Adobe Acrobat Reader JBIG malformed adaptive template pixel out-of-bounds read attempt (more info ...)attempted-user  2018-12764      URL
47682FILE-OTHER Adobe Acrobat Pro EMF EmfPlusRegionNodePath out of bounds read attempt (more info ...)attempted-user  2018-12762      URL
47683FILE-OTHER Adobe Acrobat Pro EMF EmfPlusRegionNodePath out of bounds read attempt (more info ...)attempted-user  2018-12762      URL
47699FILE-PDF Adobe Acrobat Reader JBIG malformed data out-of-bounds read attempt (more info ...)attempted-user  2018-12767      URL
47700FILE-PDF Adobe Acrobat Reader JBIG malformed data out-of-bounds read attempt (more info ...)attempted-user  2018-12767      URL
47774FILE-PDF Adobe Acrobat Pro malformed embedded TTF file memory corruption attempt (more info ...)attempted-user  2018-5031      URL
47775FILE-PDF Adobe Acrobat Pro malformed embedded TTF file memory corruption attempt (more info ...)attempted-user  2018-5031      URL
47776FILE-PDF Adobe Acrobat Pro malformed embedded TTF file memory corruption attempt (more info ...)attempted-user  2018-5031      URL
47777FILE-PDF Adobe Acrobat Pro malformed embedded TTF file memory corruption attempt (more info ...)attempted-user  2018-5031      URL
47786FILE-FLASH Adobe Flash Player out of bounds write attempt (more info ...)attempted-user  2018-5002      URL
47787FILE-FLASH Adobe Flash Player out of bounds write attempt (more info ...)attempted-user  2018-5002      
47827FILE-IMAGE Adobe Acrobat EmfPlusDrawImagePoints out of bounds read attempt (more info ...)attempted-user  2018-5035      URL
47828FILE-IMAGE Adobe Acrobat EmfPlusDrawImagePoints out of bounds read attempt (more info ...)attempted-user  2018-5035      URL
47833FILE-FLASH Adobe Flash Player COM server BrokerCreateFile sandbox escape attempt (more info ...)attempted-user  2018-15967      URL
47834FILE-FLASH Adobe Flash Player COM server BrokerCreateFile sandbox escape attempt (more info ...)attempted-user  2018-15967      URL
47852FILE-OTHER Adobe Acrobat Pro HTML invalid pointer offset out-of-bounds read attempt (more info ...)attempted-user  2018-12775      URL
47853FILE-OTHER Adobe Acrobat Pro HTML invalid pointer offset out-of-bounds read attempt (more info ...)attempted-user        URL
47854FILE-OTHER Adobe Acrobat HTML invalid pointer out-of-bounds read attempt (more info ...)attempted-user  2018-12778      URL
47855FILE-OTHER Adobe Acrobat HTML invalid pointer out-of-bounds read attempt (more info ...)attempted-user  2018-12778      URL
47856FILE-IMAGE Adobe Acrobat Pro EMF file object out of bounds write attempt (more info ...)attempted-user  2018-12848      URL
47857FILE-IMAGE Adobe Acrobat Pro EMF file object out of bounds write attempt (more info ...)attempted-user  2018-12848      URL
47891FILE-IMAGE Adobe Acrobat Pro EMF file EMFPlusPath object out of bounds read attempt (more info ...)attempted-user  2018-16014      URL
47911FILE-IMAGE Adobe Acrobat Reader EMF file JPEG Huffman table heap overflow attempt (more info ...)attempted-user  2018-12785      URL
47912FILE-IMAGE Adobe Acrobat Reader EMF file JPEG Huffman table heap overflow attempt (more info ...)attempted-user  2018-12785      URL
47920FILE-PDF Adobe Acrobat Reader PDF out of bounds read attempt (more info ...)attempted-user  2018-12829      URL
47921FILE-PDF Adobe Acrobat Reader PDF out of bounds read attempt (more info ...)attempted-user  2018-12829      URL
47922FILE-PDF Adobe Acrobat Reader PDF out of bounds read attempt (more info ...)attempted-user  2018-12829      URL
47923FILE-PDF Adobe Acrobat Reader PDF out of bounds read attempt (more info ...)attempted-user  2018-12829      URL
47926FILE-OTHER Adobe Acrobat Pro EMF ImageConversion out-of-bounds write attempt (more info ...)attempted-user  2018-12860      URL
47927FILE-OTHER Adobe Acrobat Pro EMF ImageConversion out-of-bounds write attempt (more info ...)attempted-user  2018-12860      URL
47932FILE-IMAGE Adobe Acrobat Pro Universal 3D Engine untrusted pointer dereference attempt (more info ...)attempted-user  2018-15931      URL
47933FILE-IMAGE Adobe Acrobat Pro Universal 3D Engine untrusted pointer dereference attempt (more info ...)attempted-user  2018-15931      URL
47937FILE-PDF Adobe Acrobat Reader rendering engine use-after-free attempt (more info ...)attempted-user  2018-12831      URL
47938FILE-PDF Adobe Acrobat Reader rendering engine use-after-free attempt (more info ...)attempted-user  2018-12831      URL
47941FILE-IMAGE Adobe Acrobat XPS heap overflow attempt (more info ...)attempted-user  2018-12837      URL
47942FILE-IMAGE Adobe Acrobat XPS heap overflow attempt (more info ...)attempted-user  2018-12837      URL
47949FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-15926      URL
47950FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-15926      URL
47951FILE-OTHER Adobe Distiller PostScript conversion heap overflow attempt (more info ...)attempted-admin  2018-12833      URL
47952FILE-OTHER Adobe Distiller PostScript conversion heap overflow attempt (more info ...)attempted-admin  2018-12833      URL
47953FILE-IMAGE Adobe Acrobat Pro malformed TIF tag entry out of bounds read attempt (more info ...)attempted-user  2018-12867      URL
47954FILE-IMAGE Adobe Acrobat Pro malformed TIF tag entry out of bounds read attempt (more info ...)attempted-user  2018-12867      URL
47955FILE-IMAGE Adobe Acrobat Pro malformed TIF tag entry out of bounds read attempt (more info ...)attempted-user  2018-12867      URL
47956FILE-IMAGE Adobe Acrobat Pro malformed TIF tag entry out of bounds read attempt (more info ...)attempted-user  2018-12867      URL
47957FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawDriverString malformed GlyphCount value integer overflow attempt (more info ...)attempted-user  2018-12842      URL
47958FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawDriverString malformed GlyphCount value integer overflow attempt (more info ...)attempted-user  2018-12842      URL
47959FILE-OTHER Adobe Acrobat Pro EMF file out-of-bounds write attempt (more info ...)attempted-user  2018-12865      URL
47960FILE-OTHER Adobe Acrobat Pro EMF file out-of-bounds write attempt (more info ...)attempted-user  2018-12865      URL
47967FILE-PDF Adobe Acrobat Reader JPEG2000 out of bounds read attempt (more info ...)attempted-user  2018-12839      URL
47968FILE-PDF Adobe Acrobat Reader JPEG2000 out of bounds read attempt (more info ...)attempted-user  2018-12839      URL
47969FILE-PDF Adobe Acrobat Reader JPEG2000 out of bounds read attempt (more info ...)attempted-user  2018-12839      URL
47970FILE-PDF Adobe Acrobat Reader JPEG2000 out of bounds read attempt (more info ...)attempted-user  2018-12839      URL
47971FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-12845      URL
47972FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-12845      URL
47975FILE-OTHER Adobe Acrobat Pro EMF memory corruption attempt (more info ...)attempted-user  2018-15951      URL
47976FILE-OTHER Adobe Acrobat Pro EMF memory corruption attempt (more info ...)attempted-user  2018-15951      URL
47977FILE-PDF Adobe Acrobat Pro heap overflow attempt (more info ...)attempted-user  2018-12847      URL
47978FILE-PDF Adobe Acrobat Pro heap overflow attempt (more info ...)attempted-user  2018-12847      URL
47979FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-12843      URL
47980FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-12843      URL
47981FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-12844      URL
47982FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-12844      URL
47983FILE-OTHER Adobe Acrobat Pro EMF out-of-bounds read attempt (more info ...)attempted-user  2018-12880      URL
47984FILE-OTHER Adobe Acrobat Pro EMF out-of-bounds read attempt (more info ...)attempted-user  2018-12880      URL
47986FILE-OTHER Adobe Acrobat Pro XPS out-of-bounds write attempt (more info ...)attempted-user  2018-15945      URL
47987FILE-OTHER Adobe Acrobat Pro XPS file out-of-bounds read attempt (more info ...)attempted-user  2018-15948      URL
47988FILE-OTHER Adobe Acrobat Pro XPS file out-of-bounds read attempt (more info ...)attempted-user  2018-15948      URL
47991FILE-IMAGE Adobe Acrobat Pro EMF engine type confusion attempt (more info ...)attempted-user  2018-12876      URL
47992FILE-IMAGE Adobe Acrobat Pro EMF engine type confusion attempt (more info ...)attempted-user  2018-12876      URL
47993FILE-OTHER Acrobat Adobe Pro XPS out-of-bounds read attempt (more info ...)attempted-user  2018-12878      URL
47994FILE-OTHER Acrobat Adobe Pro XPS out-of-bounds read attempt (more info ...)attempted-user  2018-12878      URL
47995FILE-IMAGE Adobe Acrobat Pro EMF pointer out of bounds write attempt (more info ...)attempted-user  2018-15944      URL
47996FILE-IMAGE Adobe Acrobat Pro EMF pointer out of bounds write attempt (more info ...)attempted-user  2018-15944      URL
47997FILE-IMAGE Adobe Acrobat Pro EMF pointer out of bounds read attempt (more info ...)attempted-user  2018-15943      URL
47998FILE-IMAGE Adobe Acrobat Pro EMF pointer out of bounds read attempt (more info ...)attempted-user  2018-15943      URL
48002FILE-IMAGE Adobe Acrobat Pro Universal 3D engine untrusted pointer dereference attempt (more info ...)attempted-user  2018-15937      URL
48003FILE-IMAGE Adobe Acrobat Pro Universal 3D engine untrusted pointer dereference attempt (more info ...)attempted-user  2018-15937      URL
48009FILE-IMAGE Adobe Acrobat Pro integer overflow attempt (more info ...)attempted-user  2018-12881      URL
48010FILE-IMAGE Adobe Acrobat Pro integer overflow attempt (more info ...)attempted-user  2018-12881      URL
48031FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-12879      URL
48032FILE-IMAGE Adobe Acrobat Pro EMF out of bounds read attempt (more info ...)attempted-user  2018-12879      URL
48033FILE-OTHER Adobe Acrobat Pro EMF file use-after-free attempt (more info ...)attempted-user  2018-12863      URL
48034FILE-OTHER Adobe Acrobat Pro EMF file use-after-free attempt (more info ...)attempted-user  2018-12863      URL
48041FILE-PDF Adobe Acrobat Reader XLST parsing engine use after free attempt (more info ...)attempted-user  2018-12853      URL
48042FILE-PDF Adobe Acrobat Reader XLST parsing engine use after free attempt (more info ...)attempted-user  2018-12853      URL
48043FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP2 marker memory corruption attempt (more info ...)attempted-user  2018-19703      URL
48044FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP2 marker memory corruption attempt (more info ...)attempted-user  2018-19703      URL
48074FILE-OTHER Adobe Acrobat Pro EMF file out-of-bounds read attempt (more info ...)attempted-user  2018-12866      URL
48075FILE-OTHER Adobe Acrobat Pro EMF file out-of-bounds read attempt (more info ...)attempted-user  2018-12866      URL
48100FILE-PDF Adobe Acrobat Reader JPEG Huffman table memory corruption attempt (more info ...)attempted-user  2018-12754      URL
48101FILE-PDF Adobe Acrobat Reader JPEG Huffman table memory corruption attempt (more info ...)attempted-user  2018-12754      URL
48102FILE-PDF Adobe Acrobat Reader JPEG Huffman table memory corruption attempt (more info ...)attempted-user  2018-12754      URL
48103FILE-PDF Adobe Acrobat Reader JPEG Huffman table memory corruption attempt (more info ...)attempted-user  2018-12754      URL
48107FILE-OTHER Adobe Acrobat Pro EMF file out-of-bounds write attempt (more info ...)attempted-user  2018-12862      URL
48108FILE-OTHER Adobe Acrobat Pro EMF file out-of-bounds write attempt (more info ...)attempted-user  2018-12862      URL
48124FILE-OTHER Adobe Acrobat Pro EMF ImageConversion out-of-bounds write attempt (more info ...)attempted-user  2018-12861      URL
48125FILE-OTHER Adobe Acrobat Pro EMF ImageConversion out-of-bounds write attempt (more info ...)attempted-user  2018-12861      URL
48217FILE-OTHER Adobe Acrobat Reader U3D engine memory corruption attempt (more info ...)attempted-user  2018-5038      URL
48218FILE-OTHER Adobe Acrobat Reader U3D engine memory corruption attempt (more info ...)attempted-user  2018-5038      URL
48219FILE-IMAGE Adobe Acrobat Pro JPEG Huffman table memory corruption attempt (more info ...)attempted-user  2018-5060      URL
48220FILE-IMAGE Adobe Acrobat Pro JPEG Huffman table memory corruption attempt (more info ...)attempted-user  2018-5060      URL
48242FILE-OTHER Adobe Acrobat Pro malformed EMF out of bounds read attempt (more info ...)attempted-user  2018-12857      URL
48243FILE-OTHER Adobe Acrobat Pro malformed EMF out of bounds read attempt (more info ...)attempted-user  2018-12857      URL
48289FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawString out of bounds read attempt (more info ...)attempted-user  2018-12761      URL
48290FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawString out of bounds read attempt (more info ...)attempted-user  2018-12761      URL
48291FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawString out of bounds read attempt (more info ...)attempted-user  2018-12761      URL
48292FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawString out of bounds read attempt (more info ...)attempted-user  2018-12761      URL
48293FILE-PDF Adobe Acrobat Reader RegExp out of bounds read attempt (more info ...)attempted-user  2019-8183      URL
48294FILE-PDF Adobe Acrobat Reader RegExp out of bounds read attempt (more info ...)attempted-user  2019-8183      URL
48359SERVER-OTHER Adobe ColdFusion unauthenticated file upload attempt (more info ...)attempted-admin  2018-15961      URL
48425FILE-FLASH Adobe Flash Player AVM type confusion attempt (more info ...)attempted-user  2018-15981      URL
48426FILE-FLASH Adobe Flash Player AVM type confusion attempt (more info ...)attempted-user  2018-15981      URL
48491FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
48492FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
48493FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
48494FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
48495FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
48496FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
48511FILE-PDF Adobe Acrobat Pro PDF file use-after-free attempt (more info ...)attempted-user  2018-5011      URL
48512FILE-PDF Adobe Acrobat Pro PDF file use-after-free attempt (more info ...)attempted-user  2018-5011      URL
48566FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
48567FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
48578FILE-PDF Adobe Acrobat Reader xfa use after free attempt (more info ...)attempted-user  2018-16036      URL
48579FILE-PDF Adobe Acrobat Reader xfa use after free attempt (more info ...)attempted-user  2018-16036      URL
48580FILE-OTHER Adobe Acrobat Pro XPS ODTTF out-of-bounds read attempt (more info ...)attempted-user  2018-19712      URL
48581FILE-OTHER Adobe Acrobat Pro XPS ODTTF out-of-bounds read attempt (more info ...)attempted-user  2018-19712      URL
48582FILE-PDF Adobe Acrobat Reader removeLinks use after free attempt (more info ...)attempted-user  2018-16029      URL
48583FILE-PDF Adobe Acrobat Reader removeLinks use after free attempt (more info ...)attempted-user  2018-16029      URL
48586FILE-OTHER Adobe Acrobat EMF out of bounds write attempt (more info ...)attempted-user  2018-15988      URL
48587FILE-OTHER Adobe Acrobat EMF out of bounds write attempt (more info ...)attempted-user  2018-15988      URL
48594FILE-PDF Adobe Acrobat Pro XSLT out-of-bounds read attempt (more info ...)attempted-user  2018-16024      URL
48595FILE-PDF Adobe Acrobat Pro XSLT out-of-bounds read attempt (more info ...)attempted-user  2018-16024      URL
48598FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (more info ...)attempted-user  2018-19720      URL
48599FILE-PDF Adobe Acrobat index file parsing memory corruption attempt (more info ...)attempted-user  2018-19720      URL
48604FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-16035      URL
48605FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-16035      URL
48608FILE-OTHER Adobe Acrobat Pro XPS ODTTF out-of-bounds read attempt (more info ...)attempted-user  2018-16028      URL
48609FILE-OTHER Adobe Acrobat Pro XPS ODTTF out-of-bounds read attempt (more info ...)attempted-user  2018-16028      URL
48610FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-recon  2018-16033      URL
48611FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-recon  2018-16033      
48622FILE-OTHER Adobe Acrobat Pro malformed XPS JPEG out of bounds read attempt (more info ...)attempted-user  2018-19703      URL
48623FILE-OTHER Adobe Acrobat Pro integer overflow vulnerability attempt (more info ...)attempted-user  2018-15995      URL
48624FILE-OTHER Adobe Acrobat Pro integer overflow vulnerability attempt (more info ...)attempted-user  2018-15995      URL
48627FILE-PDF Adobe Acrobat integer overflow attempt (more info ...)attempted-user  2018-16009      URL
48628FILE-PDF Adobe Acrobat integer overflow attempt (more info ...)attempted-user  2018-16009      URL
48629FILE-OTHER Adobe Acrobat Pro XPS file out-of-bounds read attempt (more info ...)attempted-user  2018-19714      URL
48630FILE-OTHER Adobe Acrobat Pro XPS file out-of-bounds read attempt (more info ...)attempted-user  2018-19714      URL
48631FILE-PDF Adobe Acrobat PDF XFA node use-after-free attempt (more info ...)attempted-user  2018-19699      URL
48632FILE-PDF Adobe Acrobat PDF XFA node use-after-free attempt (more info ...)attempted-user  2018-19699      URL
48633FILE-OTHER Adobe Acrobat EMF EMR_CREATEMONOBRUSH out-of-bounds write attempt (more info ...)attempted-user  2018-16016      URL
48634FILE-OTHER Adobe Acrobat EMF EMR_CREATEMONOBRUSH out-of-bounds write attempt (more info ...)attempted-user  2018-16016      URL
48636FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2018-16034      URL
48637FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2018-16034      URL
48640FILE-OTHER Adobe Acrobat EMF out-of-bounds read attempt (more info ...)attempted-user  2018-16022      URL
48641FILE-OTHER Adobe Acrobat EMF out-of-bounds read attempt (more info ...)attempted-user  2018-16022      URL
48643FILE-OTHER Adobe Acrobat EMF out of bounds read attempt (more info ...)attempted-user  2018-16017      URL
48645FILE-OTHER Adobe Acrobat Pro XPS file font-load out-of-bounds read attempt (more info ...)attempted-user  2018-19711      URL
48646FILE-OTHER Adobe Acrobat Pro XPS file font-load out-of-bounds read attempt (more info ...)attempted-user  2018-19711      URL
48703FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-15985      URL
48704FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-15985      URL
48705FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-15989      URL
48706FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-15989      URL
48707FILE-PDF Adobe Acrobat Reader heap overflow attempt (more info ...)attempted-user  2018-12830      URL
48708FILE-PDF Adobe Acrobat Reader heap overflow attempt (more info ...)attempted-user  2018-12830      URL
48709FILE-OTHER Adobe Acrobat Pro XPS file image-load out-of-bounds read attempt (more info ...)attempted-user  2018-19704      URL
48710FILE-OTHER Adobe Acrobat Pro XPS file image-load out-of-bounds read attempt (more info ...)attempted-user  2018-19704      URL
48711FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-16013      URL
48712FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-16013      URL
48738FILE-PDF Adobe Acrobat Pro memory corruption attempt (more info ...)attempted-user  2018-16027      URL
48739FILE-PDF Adobe Acrobat Pro memory corruption attempt (more info ...)attempted-user  2018-16027      URL
48745FILE-OTHER Adobe Acrobat Pro XPS TTF out-of-bounds read attempt (more info ...)attempted-user  2018-16001      URL
48746FILE-OTHER Adobe Acrobat Pro XPS TTF out-of-bounds read attempt (more info ...)attempted-user  2018-16001      URL
48748FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-15997      URL
48749FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user  2018-15997      URL
48752FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (more info ...)attempted-user  2018-19700      URL
48753FILE-PDF Adobe Acrobat Reader XFA resolveNode use after free attempt (more info ...)attempted-user  2018-19700      URL
48754FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-16012      URL
48755FILE-OTHER Adobe Acrobat Pro TIFF embedded XPS file out of bounds read attempt (more info ...)attempted-user  2018-16012      URL
48758FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (more info ...)attempted-user  2018-16015      URL
48759FILE-OTHER Adobe Acrobat Pro XPS memory corruption attempt (more info ...)attempted-user  2018-16015      URL
48760FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (more info ...)attempted-user  2018-12763      URL
48761FILE-OTHER Adobe Acrobat Pro EmfPlusFillPath out of bounds read attempt (more info ...)attempted-user  2018-12763      URL
48774FILE-OTHER Adobe Acrobat Pro XPS file out of bounds read attempt (more info ...)attempted-user  2018-16002      URL
48775FILE-OTHER Adobe Acrobat Pro XPS file out of bounds read attempt (more info ...)attempted-user  2018-16002      URL
48801FILE-PDF Adobe Acrobat Reader out of bounds read attempt (more info ...)attempted-user  2018-15984      URL
48802FILE-PDF Adobe Acrobat Reader out of bounds read attempt (more info ...)attempted-user  2018-15984      URL
48824FILE-OTHER Adobe Acrobat Pro WebCapture use after free attempt (more info ...)attempted-user  2018-15993      URL
48825FILE-OTHER Adobe Acrobat Pro WebCapture use after free attempt (more info ...)attempted-user  2018-15993      URL
48827FILE-PDF Adobe Acrobat Pro use after free attempt (more info ...)attempted-user  2018-19698      URL
48828FILE-PDF Adobe Acrobat Pro use after free attempt (more info ...)attempted-user  2018-19698      URL
48888FILE-PDF Adobe Acrobat PDF out-of-bounds read attempt (more info ...)attempted-user  2018-19717      URL
48889FILE-PDF Adobe Acrobat PDF out-of-bounds read attempt (more info ...)attempted-user  2018-19717      URL
48890FILE-PDF Adobe Reader XPS embedded font out-of-bounds vulnerability attempt (more info ...)attempted-user  2018-15996      URL
48891FILE-PDF Adobe Reader XPS embedded font out-of-bounds vulnerability attempt (more info ...)attempted-user  2018-15996      URL
48892FILE-PDF Adobe Reader XPS embedded font out-of-bounds vulnerability attempt (more info ...)attempted-user  2018-15996      URL
48893FILE-PDF Adobe Reader XPS embedded font out-of-bounds vulnerability attempt (more info ...)attempted-user  2018-15996      URL
48896FILE-PDF Adobe Acrobat PDF getLegalWarnings use-after-free attempt (more info ...)attempted-user  2018-19715      URL
48897FILE-PDF Adobe Acrobat PDF getLegalWarnings use-after-free attempt (more info ...)attempted-user  2018-19715      URL
48973FILE-PDF Adobe Acrobat PDF calculate tag use-after-free attempt (more info ...)attempted-user  2018-19713      URL
48974FILE-PDF Adobe Acrobat PDF calculate tag use-after-free attempt (more info ...)attempted-user  2018-19713      URL
49036FILE-PDF Adobe Acrobat Reader XFA engine memory corruption attempt (more info ...)attempted-user  2018-16041      URL
49037FILE-PDF Adobe Acrobat Reader XFA engine memory corruption attempt (more info ...)attempted-user  2018-16041      URL
49192FILE-PDF Adobe Acrobat Reader XFA engine memory corruption attempt (more info ...)attempted-user  2019-7021      URL
49193FILE-PDF Adobe Acrobat Reader XFA engine memory corruption attempt (more info ...)attempted-user  2019-7021      URL
49225FILE-PDF Adobe Acrobat Reader TIF orientation out of bounds read attempt (more info ...)attempted-user  2019-7036      URL
49226FILE-PDF Adobe Acrobat Reader TIF orientation out of bounds read attempt (more info ...)attempted-user  2019-7036      URL
49231FILE-FLASH Adobe Flash Player drawTriangles out-of-bounds read attempt (more info ...)attempted-user  2019-7090      URL
49232FILE-FLASH Adobe Flash Player drawTriangles out-of-bounds read attempt (more info ...)attempted-user  2019-7090      URL
49242FILE-OTHER Adobe Acrobat PostScript parsing type confusion attempt (more info ...)attempted-user  2019-7087      URL
49243FILE-OTHER Adobe Acrobat PostScript parsing type confusion attempt (more info ...)attempted-user  2019-7087      URL
49244FILE-OTHER Adobe Acrobat PostScript parsing arbitrary code execution attempt (more info ...)attempted-user  2019-7085      URL
49245FILE-OTHER Adobe Acrobat PostScript parsing arbitrary code execution attempt (more info ...)attempted-user  2019-7085      URL
49250FILE-PDF Adobe Acrobat Pro out of bounds write attempt (more info ...)attempted-user  2019-7039      URL
49251FILE-PDF Adobe Acrobat Pro out of bounds write attempt (more info ...)attempted-user  2019-7039      URL
49258FILE-OTHER Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7049      URL
49259FILE-OTHER Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7049      URL
49260FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7024      URL
49261FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7024      URL
49262FILE-PDF Adobe Acrobat malformed embedded idx file out of bounds read attempt (more info ...)attempted-user  2019-7045      URL
49263FILE-PDF Adobe Acrobat malformed embedded idx file out of bounds read attempt (more info ...)attempted-user  2019-7045      URL
49264FILE-PDF Adobe Acrobat malformed PDF file stack overflow attempt (more info ...)attempted-user  2019-7020      URL
49265FILE-PDF Adobe Acrobat malformed PDF file stack overflow attempt (more info ...)attempted-user  2019-7020      URL
49266FILE-PDF Adobe Acrobat Reader use after free attempt (more info ...)attempted-user  2019-7068      URL
49267FILE-PDF Adobe Acrobat Reader use after free attempt (more info ...)attempted-user  2019-7068      URL
49268FILE-OTHER Adobe Acrobat Pro use-after-free attempt (more info ...)attempted-user  2019-7070      URL
49269FILE-OTHER Adobe Acrobat Pro use-after-free attempt (more info ...)attempted-user  2019-7070      URL
49270FILE-OTHER Adobe Acrobat out of bounds write attempt (more info ...)attempted-user  2019-7079      URL
49271FILE-OTHER Adobe Acrobat out of bounds write attempt (more info ...)attempted-user  2019-7079      URL
49272FILE-PDF Adobe Reader XFA engine untrusted pointer dereference attempt (more info ...)attempted-user  2019-7066      URL
49273FILE-PDF Adobe Reader XFA engine untrusted pointer dereference attempt (more info ...)attempted-user  2019-7066      URL
49274FILE-PDF Adobe Acrobat untrusted pointer dereference attempt (more info ...)attempted-user  2019-7051      URL
49275FILE-PDF Adobe Acrobat untrusted pointer dereference attempt (more info ...)attempted-user  2019-7051      URL
49276FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7067      URL
49277FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7067      URL
49278FILE-PDF Adobe Acrobat Reader out of bounds read attempt (more info ...)attempted-user  2019-7063      URL
49279FILE-PDF Adobe Acrobat Reader out of bounds read attempt (more info ...)attempted-user  2019-7063      URL
49280FILE-OTHER Adobe Acrobat Pro HTML use-after-free attempt (more info ...)attempted-user  2019-7077      URL
49283FILE-PDF Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7026      URL
49284FILE-PDF Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7026      URL
49294FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7038      URL
49295FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7038      URL
49305FILE-PDF Adobe Acrobat Reader PostScript file out of bounds read attempt (more info ...)attempted-user  2019-7074      URL
49306FILE-PDF Adobe Acrobat Reader PostScript file out of bounds read attempt (more info ...)attempted-user  2019-7074      URL
49307FILE-PDF Adobe Acrobat malformed PDF out of bounds read attempt (more info ...)attempted-user  2019-7064      URL
49308FILE-PDF Adobe Acrobat malformed PDF out of bounds read attempt (more info ...)attempted-user  2019-7064      URL
49309FILE-PDF Adobe Acrobat malformed PDF objects use after free attempt (more info ...)attempted-user  2019-7044      URL
49310FILE-PDF Adobe Acrobat malformed PDF objects use after free attempt (more info ...)attempted-user  2019-7044      URL
49311FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7647      URL
49312FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user  2015-7647      URL
49315FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7058      URL
49316FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7058      URL
49317FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7056      URL
49318FILE-PDF Adobe Acrobat out of bounds read attempt (more info ...)attempted-user  2019-7056      URL
49337SERVER-OTHER Adobe ColdFusion arbitrary file upload attempt (more info ...)web-application-attack  2019-7816      URL
49338SERVER-OTHER Adobe ColdFusion arbitrary file upload attempt (more info ...)web-application-attack  2019-7816      URL
49399SERVER-WEBAPP Adobe ColdFusion unauthorized serialized object attempt (more info ...)attempted-user  2019-7091      URL
49504FILE-PDF Adobe Acrobat Pro saveFilteredXML out-of-bounds read attempt (more info ...)attempted-user  2019-7057      URL
49505FILE-PDF Adobe Acrobat Pro saveFilteredXML out-of-bounds read attempt (more info ...)attempted-user  2019-7057      URL
49583FILE-FLASH Adobe Flash Player byteArray inflate information disclosure attempt (more info ...)attempted-user  2014-8440      URL
49584FILE-FLASH Adobe Flash Player byteArray inflate information disclosure attempt (more info ...)attempted-user  2014-8440      URL
49585FILE-FLASH Adobe Flash Player byteArray uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
49586FILE-FLASH Adobe Flash Player byteArray uncompress information disclosure attempt (more info ...)attempted-user  2014-8440      URL
49599FILE-PDF Adobe Acrobat Reader untrusted pointer dereference attempt detected (more info ...)attempted-user  2019-7076      URL
49600FILE-PDF Adobe Acrobat Reader untrusted pointer dereference attempt detected (more info ...)attempted-user  2019-7076      URL
49640FILE-PDF Adobe Acrobat PDF use-after-free attempt (more info ...)attempted-user  2019-7050      URL
49641FILE-PDF Adobe Acrobat PDF use-after-free attempt (more info ...)attempted-user  2019-7050      URL
49650FILE-PDF Adobe Acrobat PDF printWithParams use-after-free attempt (more info ...)attempted-user  2019-7062      URL
49651FILE-PDF Adobe Acrobat PDF printWithParams use-after-free attempt (more info ...)attempted-user  2019-7062      URL
49654FILE-FLASH Adobe Flash Player PCRE control character denial of service attempt (more info ...)denial-of-service  2015-0318      URL
49655FILE-FLASH Adobe Flash Player PCRE control character denial of service attempt (more info ...)denial-of-service  2015-0318      URL
49656FILE-FLASH Adobe Flash Player PCRE control character denial of service attempt (more info ...)denial-of-service  2015-0318      URL
49658FILE-PDF Adobe Acrobat Reader XFA font size out-of-bounds read attempt (more info ...)attempted-user  2019-7023      URL
49659FILE-PDF Adobe Acrobat Reader XFA font size out-of-bounds read attempt (more info ...)attempted-user  2019-7023      URL
49660FILE-PDF Adobe Acrobat Reader XFA font size out-of-bounds read attempt (more info ...)attempted-user  2019-7023      URL
49661FILE-PDF Adobe Acrobat Reader XFA font size out-of-bounds read attempt (more info ...)attempted-user  2019-7023      URL
50139FILE-FLASH Adobe Flash Player out-of-bounds read attempt (more info ...)attempted-user  2019-7108      URL
50140FILE-FLASH Adobe Flash Player out-of-bounds read attempt (more info ...)attempted-user  2019-7108      URL
50141FILE-OTHER Adobe Acrobat type confusion attempt (more info ...)attempted-user  2019-7128      URL
50142FILE-OTHER Adobe Acrobat type confusion attempt (more info ...)attempted-user  2019-7128      URL
50143FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7019      URL
50144FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7019      URL
50150FILE-PDF Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7025      URL
50151FILE-PDF Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7025      URL
50152FILE-PDF Adobe Acrobat integer overflow attempt (more info ...)attempted-user  2019-7030      URL
50153FILE-PDF Adobe Acrobat integer overflow attempt (more info ...)attempted-user  2019-7030      URL
50205FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7033      URL
50206FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7033      URL
50209FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7032      URL
50210FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7032      URL
50211FILE-PDF Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7048      URL
50212FILE-PDF Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7048      URL
50213FILE-OTHER Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7040      URL
50214FILE-OTHER Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7040      URL
50220FILE-PDF Adobe Acrobat untrusted pointer dereference attempt (more info ...)attempted-user  2019-7046      URL
50221FILE-PDF Adobe Acrobat untrusted pointer dereference attempt (more info ...)attempted-user  2019-7046      URL
50222FILE-OTHER Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7043      URL
50223FILE-OTHER Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7043      URL
50224FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7052      URL
50225FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7052      URL
50226FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7055      URL
50227FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7055      URL
50228FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7059      URL
50229FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7059      URL
50230FILE-OTHER Adobe Acrobat malformed font file use after free attempt (more info ...)attempted-user  2019-7072      URL
50231FILE-OTHER Adobe Acrobat malformed font file use after free attempt (more info ...)attempted-user  2019-7072      URL
50232FILE-OTHER Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7071      URL
50233FILE-OTHER Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7071      URL
50234FILE-OTHER Adobe Acrobat type confusion attempt (more info ...)attempted-user  2019-7069      URL
50235FILE-OTHER Adobe Acrobat type confusion attempt (more info ...)attempted-user  2019-7069      URL
50236FILE-OTHER Adobe Acrobat PostScript file parsing TBuildCharDict use after free attempt (more info ...)attempted-user  2019-7084      URL
50237FILE-OTHER Adobe Acrobat PostScript file parsing TBuildCharDict use after free attempt (more info ...)attempted-user  2019-7084      URL
50238FILE-PDF Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7112      URL
50239FILE-PDF Adobe Acrobat use after free attempt (more info ...)attempted-user  2019-7112      URL
50240FILE-OTHER Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7122      URL
50241FILE-OTHER Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7122      URL
50242FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7122      URL
50243FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7122      URL
50244FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7120      URL
50245FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7120      URL
50246FILE-IMAGE Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7120      URL
50247FILE-IMAGE Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7120      URL
50248FILE-OTHER Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7127      URL
50249FILE-OTHER Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7127      URL
50250FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7118      URL
50251FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7118      URL
50252FILE-IMAGE Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7118      URL
50253FILE-IMAGE Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7118      URL
50254FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7124      URL
50255FILE-PDF Adobe Acrobat out-of-bounds write attempt (more info ...)attempted-user  2019-7124      URL
50256FILE-OTHER Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7143      URL
50257FILE-OTHER Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7143      URL
50267FILE-FLASH Adobe Flash Player use after free attempt (more info ...)attempted-user  2019-7837      URL
50268FILE-FLASH Adobe Flash Player use after free attempt (more info ...)attempted-user  2019-7837      URL
50271FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7061      URL
50272FILE-PDF Adobe Acrobat out-of-bounds read attempt (more info ...)attempted-user  2019-7061      URL
50297FILE-PDF Adobe Acrobat execCalculate use after free attempt (more info ...)attempted-user  2019-7782      URL
50298FILE-PDF Adobe Acrobat execCalculate use after free attempt (more info ...)attempted-user  2019-7782      URL
50448FILE-PDF Adobe Acrobat double free attempt (more info ...)attempted-user  2019-7080      URL
50449FILE-PDF Adobe Acrobat double free attempt (more info ...)attempted-user  2019-7080      URL
50534FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
50535FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
50536FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
50537FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user  2018-15982      URL
51026FILE-PDF Adobe Reader SFNT out of bounds memory read attempt (more info ...)attempted-user  2014-8458      URL
51081FILE-FLASH Adobe Flash player memory corruption attempt (more info ...)attempted-user  2015-5577      URL
51082FILE-FLASH Adobe Flash player memory corruption attempt (more info ...)attempted-user  2015-5577      URL
51162FILE-PDF Adobe Acrobat Reader RGB color table out of bounds read attempt (more info ...)misc-activity  2014-8456      URL
51163FILE-PDF Adobe Acrobat Reader RGB color table out of bounds read attempt (more info ...)misc-activity  2014-8456      URL
51225FILE-FLASH Adobe Flash Player malformed ATF heap overflow attempt (more info ...)attempted-user  2016-1002      URL
51226FILE-FLASH Adobe Flash Player malformed ATF heap overflow attempt (more info ...)attempted-user  2016-1002      URL
51648FILE-FLASH Adobe Flash Player ActiveX same origin method execution attempt (more info ...)attempted-user  2019-8069      
51992FILE-IDENTIFY Windows Media Metafile file download request (more info ...)misc-activity        
51993FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
51994FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity        
52036SERVER-OTHER Adobe ColdFusion JNBridge remote code execution attempt (more info ...)attempted-admin  2019-7839      URL
53148FILE-PDF Adobe Acrobat CTextWidget memory corruption attempt (more info ...)attempted-user  2019-8038      URL
53149FILE-PDF Adobe Acrobat CTextWidget memory corruption attempt (more info ...)attempted-user  2019-8038      URL
53687SERVER-WEBAPP Adobe Experience Manager server side request forgery attempt (more info ...)web-application-attack  2018-12809      
53688SERVER-WEBAPP Adobe Experience Manager server side request forgery attempt (more info ...)web-application-attack  2018-12809      
55979FILE-MULTIMEDIA Microsoft Windows Media Foundation memory corruption attempt (more info ...)attempted-user  2020-16915      URL
55980FILE-MULTIMEDIA Microsoft Windows Media Foundation memory corruption attempt (more info ...)attempted-user  2020-16915      URL
57137FILE-PDF Adobe Acrobat heap buffer overflow attempt (more info ...)attempted-user  2021-21017      URL
57138FILE-PDF Adobe Acrobat heap buffer overflow attempt (more info ...)attempted-user  2021-21017      URL
57499FILE-FLASH Adobe Flash Player worker shared object use-after-free attempt (more info ...)attempted-user  2014-0502      URL
57566FILE-PDF Adobe Acrobat Reader DC Annots.api setProps use-after-free attempt (more info ...)attempted-user  2021-28550      URL
57567FILE-PDF Adobe Acrobat Reader DC Annots.api setProps use-after-free attempt (more info ...)attempted-user  2021-28550      URL
58640FILE-PDF Adobe Acrobat Reader DC memory corruption attempt (more info ...)attempted-user  2021-28639      
58641FILE-PDF Adobe Acrobat Reader DC memory corruption attempt (more info ...)attempted-user  2021-28639      
58643FILE-PDF Adobe Acrobat Reader DC memory corruption attempt (more info ...)attempted-user  2021-28639      
58645FILE-PDF Adobe Acrobat Reader DC memory corruption attempt (more info ...)attempted-user  2021-28639      
59084FILE-PDF Adobe Acrobat PDF buttonGetIcon use-after-free attempt (more info ...)attempted-user  2021-39836      URL
59085FILE-PDF Adobe Acrobat PDF buttonGetIcon use-after-free attempt (more info ...)attempted-user  2021-39836      URL
59101FILE-PDF Adobe Acrobat PDF AcroForm addField use-after-free attempt (more info ...)attempted-user  2021-28635      URL
59102FILE-PDF Adobe Acrobat PDF AcroForm addField use-after-free attempt (more info ...)attempted-user  2021-28635      URL
59105FILE-PDF Adobe Acrobat PDF thermometer use-after-free attempt (more info ...)attempted-user  2021-28640      URL
59106FILE-PDF Adobe Acrobat PDF thermometer use-after-free attempt (more info ...)attempted-user  2021-28640      URL
59248FILE-PDF Adobe Acrobat PDF SMask height out of bounds write attempt (more info ...)attempted-user  2021-39843      URL
59249FILE-PDF Adobe Acrobat PDF SMask height out of bounds write attempt (more info ...)attempted-user  2021-39843      URL
60803SERVER-WEBAPP Adobe BlazeDS XML external entity injection attempt (more info ...)web-application-attack  2009-3960      URL
60804SERVER-WEBAPP Adobe BlazeDS XML external entity injection attempt (more info ...)web-application-attack  2009-3960      URL
61033FILE-OTHER Adobe ColdFusion XmlTransform arbitrary file read attempt (more info ...)web-application-attack  2022-42340      
61034FILE-OTHER Adobe ColdFusion XmlTransform arbitrary file read attempt (more info ...)web-application-attack  2022-42340      
61690SERVER-WEBAPP Adobe RoboHelp Server fileName directory traversal attempt (more info ...)web-application-attack  2021-42727      
61691SERVER-WEBAPP Adobe RoboHelp Server fileName directory traversal attempt (more info ...)web-application-attack  2021-42727      
62111SERVER-WEBAPP Adobe ColdFusion Secure Profile access bypass attempt (more info ...)web-application-attack  2023-29298      URL
62112SERVER-WEBAPP Adobe ColdFusion Secure Profile access bypass attempt (more info ...)web-application-attack  2023-29298      URL
62113SERVER-WEBAPP Adobe ColdFusion WDDX Deserialization code execution attempt (more info ...)attempted-user  2023-38204      URL
62114SERVER-WEBAPP Adobe ColdFusion WDDX Deserialization code execution attempt (more info ...)attempted-user  2023-38204      URL


# of warning rules in this group: 1475

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1428POLICY-MULTIMEDIA audio galaxy keepalive (more info ...)misc-activity    
1540SERVER-OTHER Adobe Coldfusion ?Mode=debug attempt (more info ...)web-application-activity 1999-0760  10797 
2419FILE-IDENTIFY RealNetworks Realplayer .ram playlist file download request (more info ...)misc-activity    URL
2422FILE-IDENTIFY RealNetworks Realplayer .rt playlist file download request (more info ...)misc-activity    URL
2423FILE-IDENTIFY RealNetworks Realplayer .rp playlist file download request (more info ...)misc-activity    URL
2438FILE-MULTIMEDIA RealNetworks RealPlayer playlist file URL overflow attempt (more info ...)attempted-user 2005-0755 9579  
2439FILE-MULTIMEDIA RealNetworks RealPlayer playlist http URL overflow attempt (more info ...)attempted-user 2005-0755 9579  
2440FILE-MULTIMEDIA RealNetworks RealPlayer playlist rtsp URL overflow attempt (more info ...)attempted-user 2005-0755 9579  
2550FILE-OTHER Nullsoft Winamp XM file buffer overflow attempt (more info ...)attempted-user 2004-1896   URL
3470FILE-MULTIMEDIA RealNetworks RealPlayer VIDORV30 header length buffer overflow (more info ...)attempted-admin 2004-1481 11309  URL
3473FILE-MULTIMEDIA RealNetworks RealPlayer SMIL file overflow attempt (more info ...)attempted-user 2005-0455 12698  
3822SERVER-WEBAPP RealNetworks RealPlayer realtext long URI request attempt (more info ...)protocol-command-decode 2005-1766 14048 18558 
3823FILE-MULTIMEDIA RealNetworks RealPlayer realtext file bad version buffer overflow attempt (more info ...)attempted-user 2005-1766 14048 18558 
4131SERVER-OTHER SHOUTcast URI format string attempt (more info ...)web-application-attack 2004-1373 12096  
4158BROWSER-PLUGINS Microsoft Windows Media Player Active Movie ActiveX object access (more info ...)attempted-user 2000-0400 1221  
4675FILE-FLASH Adobe Flash DOACTION tag overflow attempt (more info ...)attempted-user    URL
4679FILE-MULTIMEDIA Apple QuickTime movie file component name integer overflow multipacket attempt (more info ...)attempted-user 2005-2754 15308  URL
4680FILE-MULTIMEDIA Apple QuickTime movie file component name integer overflow attempt (more info ...)attempted-user 2005-2754 15308  URL
5710OS-WINDOWS Microsoft Windows Media Player Plugin for Non-IE browsers buffer overflow attempt (more info ...)attempted-user 2006-0005 16644  URL
5711FILE-IMAGE Microsoft Windows Media Player zero length bitmap heap overflow attempt (more info ...)attempted-admin 2006-0006 16633  URL
5712FILE-IMAGE Microsoft Windows Media Player invalid data offset bitmap heap overflow attempt (more info ...)attempted-admin 2006-0006 16633  URL
6368PUA-ADWARE Adware flashtrack media/spoton runtime detection - update request (more info ...)misc-activity    URL
6371PUA-ADWARE Adware flashtrack media/spoton runtime detection - pop up ads (more info ...)misc-activity    URL
6506FILE-MULTIMEDIA Apple QuickTime udta atom overflow attempt (more info ...)attempted-user 2006-1460 17953  
6691FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected sBIT overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
6693FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected bKGD overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
6694FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected hIST overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
6695FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected tRNS overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
6696FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected pHYs overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
6698FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected tIME overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
7142PUA-ADWARE Adware ares flash downloader 2.04 runtime detection (more info ...)misc-activity    URL
7581PUA-TOOLBARS Hijacker flashbar runtime detection - user-agent (more info ...)misc-activity    URL
7888BROWSER-PLUGINS AOLFlash.AOLFlash ActiveX clsid access (more info ...)attempted-user    
7978BROWSER-PLUGINS ShockwaveFlash.ShockwaveFlash ActiveX clsid access (more info ...)attempted-user 2007-6244   URL
8091FILE-MULTIMEDIA RealNetworks RealPlayer error message format string vulnerability attempt (more info ...)attempted-user 2005-2710 14945  
8377BROWSER-PLUGINS RealNetworks RealPlayer Download Handler ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  URL
8381BROWSER-PLUGINS RealNetworks RealPlayer SMIL Download Handler ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  URL
8383BROWSER-PLUGINS RealNetworks RealPlayer RAM Download Handler ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  URL
8385BROWSER-PLUGINS RealNetworks RealPlayer Playback Handler ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  URL
8387BROWSER-PLUGINS RealNetworks RealPlayer RNX Download Handler ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  URL
8389BROWSER-PLUGINS RealNetworks RealPlayer RMP Download Handler ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  URL
8401BROWSER-PLUGINS Microsoft Windows Media Services DRM Storage ActiveX clsid access (more info ...)attempted-user    
8409BROWSER-PLUGINS RealNetworks RealPlayer Stream Handler ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  URL
8701SERVER-WEBAPP IceCast header buffer overflow attempt (more info ...)attempted-admin 2004-1561 11271  URL
8702SERVER-OTHER IceCast header buffer overflow attempt (more info ...)attempted-admin 2004-1561 11271  URL
8703SERVER-OTHER IceCast header buffer overflow attempt (more info ...)attempted-admin 2004-1561 11271  URL
9429FILE-MULTIMEDIA Apple QuickTime Movie link scripting security bypass attempt (more info ...)attempted-user 2006-4965 20138  
9430FILE-MULTIMEDIA Apple QuickTime Movie link file URI security bypass attempt (more info ...)attempted-user 2006-4965 20138  
9625OS-WINDOWS Microsoft Windows Media Player ASX file ref href buffer overflow attempt (more info ...)attempted-user 2006-6134 21247  URL
9637FILE-OTHER Adobe Download Manager dm.ini stack overflow attempt (more info ...)attempted-user 2006-5856 21453  
9641OS-WINDOWS Microsoft Windows Media Player ASF simple index object parsing buffer overflow attempt (more info ...)attempted-user 2009-2527   URL
9642OS-WINDOWS Microsoft Windows Media Player ASF codec list object parsing buffer overflow attempt (more info ...)attempted-user 2009-2527   URL
9643OS-WINDOWS Microsoft Windows Media Player ASF marker object parsing buffer overflow attempt (more info ...)attempted-user 2009-2527   URL
9671BROWSER-PLUGINS RealNetworks RealPlayer AutoStream.AutoStream.1 ActiveX clsid access (more info ...)attempted-user 2006-6847 21802  
9673BROWSER-PLUGINS RealNetworks RealPlayer AutoStream.AutoStream.1 ActiveX function call access (more info ...)attempted-user 2006-6847 21802  
9823FILE-MULTIMEDIA Apple QuickTime RTSP URI overflow attempt (more info ...)attempted-user 2007-0015 21829  URL
9842FILE-PDF Adobe Acrobat Plugin Universal cross-site scripting attempt (more info ...)misc-attack 2007-0045   URL
10193BROWSER-PLUGINS RealNetworks RealPlayer Ierpplug.dll ActiveX function call access (more info ...)attempted-user 2010-3749 44443  
10194BROWSER-PLUGINS RealNetworks RealPlayer Ierpplug.dll ActiveX function call access (more info ...)attempted-user 2010-3749 22811  
11180FILE-MULTIMEDIA Apple QuickTime movie ftyp buffer underflow (more info ...)attempted-user 2007-2296 23652  
11267FILE-IMAGE Adobe Photoshop PNG file handling stack buffer overflow attempt (more info ...)attempted-user 2007-2365 23698  
12219FILE-MULTIMEDIA RealNetworks RealPlayer SMIL wallclock parsing buffer overflow (more info ...)attempted-user 2007-3410 24658  URL
12707FILE-MULTIMEDIA RealNetworks RealPlayer lyrics heap overflow attempt (more info ...)attempted-user 2007-5080 26214  
12741SERVER-OTHER Apple Quicktime TCP RTSP sdp type buffer overflow attempt (more info ...)attempted-user 2007-6166 26549  
12742SERVER-OTHER Apple Quicktime UDP RTSP sdp type buffer overflow attempt (more info ...)attempted-user 2007-6166 26549  
12746FILE-MULTIMEDIA Apple QuickTime invalid stsd atom out of bounds read attempt (more info ...)attempted-user 2015-3789 26341  URL
12757FILE-IMAGE Apple QuickTime uncompressed PICT stack overflow attempt (more info ...)attempted-user 2007-4672 26344  
12767BROWSER-PLUGINS RealNetworks RealPlayer RMOC3260.DLL ActiveX function call access (more info ...)attempted-user 2010-3747 44144  URL
12768BROWSER-PLUGINS RealNetworks RealPlayer RMOC3260.DLL ActiveX function call access (more info ...)attempted-user 2008-1309 28157  URL
12775BROWSER-PLUGINS RealNetworks RealPlayer obfuscated Ierpplug.dll ActiveX exploit attempt (more info ...)attempted-user 2007-5601 26586  URL
13300FILE-FLASH Adobe Flash Player embedded JPG image height overflow attempt (more info ...)attempted-admin 2007-6242 26951  
13477FILE-PDF Adobe Acrobat Reader collab.collectEmailInfo exploit attempt - compressed (more info ...)attempted-user 2008-0655 27641  
13478FILE-PDF Adobe Acrobat Reader collab.collectEmailInfo exploit attempt (more info ...)attempted-user 2008-0655 27641  
13515FILE-MULTIMEDIA Apple QuickTime user agent (more info ...)misc-activity    
13516FILE-MULTIMEDIA Apple QuickTime HTTP error response buffer overflow (more info ...)attempted-user 2008-0234 27225  
13517FILE-MULTIMEDIA Apple Quicktime malformed idsc atom (more info ...)attempted-user 2008-0033   
13603BROWSER-PLUGINS RealNetworks RealPlayer Download Handler ActiveX function call access (more info ...)attempted-user 2008-1309 28157  URL
13605BROWSER-PLUGINS RealNetworks RealPlayer RAM Download Handler ActiveX function call access (more info ...)attempted-user 2008-1309 28157  URL
13607BROWSER-PLUGINS RealNetworks RealPlayer RMOC3260.DLL Vulnerble Property ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  
13609BROWSER-PLUGINS RealNetworks RealPlayer RMOC3260.DLL Vulnerble Property ActiveX function call access (more info ...)attempted-user 2008-1309 28157  
13820FILE-FLASH Adobe Flash Player SWF scene and label data memory corruption attempt (more info ...)attempted-user 2007-0071 29386  URL
13821FILE-FLASH Adobe Flash Player SWF scene and label data memory corruption attempt (more info ...)attempted-user 2007-0071 29386  URL
13822FILE-FLASH Adobe Flash Player SWF scene and label data memory corruption attempt (more info ...)attempted-user 2007-0071 29386  URL
13917FILE-MULTIMEDIA Apple QuickTime MOV file string handling integer overflow attempt (more info ...)attempted-user 2005-2753 15306  
13918FILE-MULTIMEDIA Apple QuickTime MOV file string handling integer overflow attempt (more info ...)attempted-user 2005-2753 15306  
13920FILE-MULTIMEDIA Apple QuickTime Obji Atom parsing stack buffer overflow attempt (more info ...)attempted-user 2008-1022 28583  
14042BROWSER-PLUGINS RealNetworks RealPlayer General Property Page ActiveX clsid access (more info ...)attempted-user 2008-1309 28157  URL
14044BROWSER-PLUGINS RealNetworks RealPlayer Playback Handler ActiveX function call access (more info ...)attempted-user 2008-1309 28157  URL
14046BROWSER-PLUGINS RealNetworks RealPlayer RMP Download Handler ActiveX function call access (more info ...)attempted-user 2008-1309 28157  URL
14048BROWSER-PLUGINS RealNetworks RealPlayer RNX Download Handler ActiveX function call access (more info ...)attempted-user 2008-1309 28157  URL
14050BROWSER-PLUGINS RealNetworks RealPlayer SMIL Download Handler ActiveX function call access (more info ...)attempted-user 2008-1309 28157  URL
14052BROWSER-PLUGINS RealNetworks RealPlayer Stream Handler ActiveX function call access (more info ...)attempted-user 2008-1309 28157  URL
14235BROWSER-PLUGINS Microsoft Windows Media Services CallHTMLHelp ActiveX buffer overflow attempt (more info ...)attempted-user 2008-5232 30814  URL
14237BROWSER-PLUGINS Microsoft Windows Media Services ActiveX function call access (more info ...)attempted-user 2008-5232 30814  
14255BROWSER-PLUGINS Microsoft Windows Media Encoder 9 ActiveX clsid access (more info ...)attempted-user 2008-3008 31065  URL
14257BROWSER-PLUGINS Microsoft Windows Media Encoder 9 ActiveX function call access (more info ...)attempted-user 2008-3008 31065  URL
15007BROWSER-PLUGINS NOS Microsystems / Adobe getPlus Download Manager ActiveX clsid access (more info ...)attempted-user 2008-4817 32105  
15014FILE-PDF Adobe Acrobat Reader util.printf buffer overflow attempt (more info ...)attempted-user 2008-2992   
15358FILE-PDF Adobe Acrobat Reader JBIG2 remote code execution attempt (more info ...)attempted-user 2009-0658 33751  
15433FILE-OTHER Winamp MAKI parsing integer overflow attempt (more info ...)attempted-user 2009-1831 35052  
15478FILE-FLASH Adobe Flash Player invalid object reference code execution attempt (more info ...)attempted-user 2009-0520 33880  URL
15480FILE-MULTIMEDIA Apple QuickTime movie record invalid version number exploit attempt (more info ...)attempted-user 2009-0956   URL
15487FILE-MULTIMEDIA Apple QuickTime SMIL qtnext redirect file execution attempt (more info ...)attempted-user 2008-1585 29650  
15492FILE-PDF Adobe Acrobat Reader spell.customDictionaryOpen exploit attempt (more info ...)attempted-user 2009-1493 34740  
15493FILE-PDF Adobe Acrobat Reader getAnnots exploit attempt (more info ...)attempted-user 2009-1492 34736  
15517FILE-MULTIMEDIA Microsoft Windows AVI DirectShow QuickTime parsing overflow attempt (more info ...)attempted-user 2009-1537 35139  URL
15559FILE-MULTIMEDIA Apple QuickTime movie file clipping region handling heap buffer overflow attempt (more info ...)attempted-user 2009-0954 35167  URL
15562FILE-PDF Adobe Acrobat Reader JPX malformed code-block width memory corruption attempt (more info ...)attempted-user 2009-1861 35295  URL
15680OS-WINDOWS Microsoft DirectShow QuickTime file atom size parsing heap corruption attempt (more info ...)attempted-user 2009-1539   URL
15682FILE-MULTIMEDIA Microsoft Windows DirectShow QuickTime file stsc atom parsing heap corruption attempt (more info ...)attempted-user 2009-1538   URL
15703FILE-MULTIMEDIA Apple iTunes ITMS protocol handler stack buffer overflow attempt (more info ...)attempted-user 2009-0950 35157  
15704FILE-MULTIMEDIA Apple iTunes ITMSS protocol handler stack buffer overflow attempt (more info ...)attempted-user 2009-0950 35157  
15705FILE-MULTIMEDIA Apple iTunes PCAST protocol handler stack buffer overflow attempt (more info ...)attempted-user 2009-0950 35157  
15706FILE-MULTIMEDIA Apple iTunes DAAP protocol handler stack buffer overflow attempt (more info ...)attempted-user 2009-0950 35157  
15707FILE-MULTIMEDIA Apple iTunes ITPC protocol handler stack buffer overflow attempt (more info ...)attempted-user 2009-0950 35157  
15709FILE-PDF Adobe Acrobat Reader FlateDecode integer overflow attempt (more info ...)attempted-user 2009-3459 36600  
15728FILE-PDF Possible Adobe Acrobat Reader ActionScript byte_array heap spray attempt (more info ...)attempted-user 2009-1862 35759  URL
15729FILE-FLASH Possible Adobe Flash Player ActionScript byte_array heap spray attempt (more info ...)attempted-user 2009-1862 35759  URL
15867FILE-PDF Adobe Acrobat Reader PDF font processing memory corruption attempt (more info ...)attempted-user 2008-4813 32100  URL
15869FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
15940FILE-MULTIMEDIA RealNetworks RealPlayer Multiple Products RA file processing overflow attempt (more info ...)attempted-user 2007-2264 26214  
15993FILE-FLASH Adobe Flash Player ActionScript intrf_count integer overflow attempt (more info ...)attempted-user 2009-1869 35907  
16027FILE-MULTIMEDIA Nullsoft Winamp midi file header overflow attempt (more info ...)attempted-user 2006-3228 18507  
16041FILE-MULTIMEDIA Apple QuickTime FLIC animation file buffer overflow attempt (more info ...)attempted-user 2006-4384 19976  
16046FILE-MULTIMEDIA RealNetworks RealPlayer RealMedia file format processing heap corruption attempt (more info ...)attempted-user 2007-5081 26214  
16054FILE-IMAGE Apple QuickTime bitmap multiple header overflow (more info ...)attempted-user 2006-2238 17953  
16055FILE-MULTIMEDIA Apple iTunes AAC file handling integer overflow attempt (more info ...)attempted-user 2006-1467 18730  
16091SERVER-OTHER Macromedia Flash Media Server administration service denial of service attempt (more info ...)attempted-dos 2005-4216 15822  
16148FILE-MULTIMEDIA Apple QuickTime and iTunes heap memory corruption attempt (more info ...)attempted-user 2005-4092 15732  
16156FILE-MULTIMEDIA Windows Media Player ASF marker object memory corruption attempt (more info ...)attempted-user 2009-2527   URL
16158OS-WINDOWS Microsoft Windows Media Runtime malformed ASF codec memory corruption attempt (more info ...)attempted-user 2009-2525   URL
16172FILE-PDF Adobe Acrobat Reader U3D line set heap corruption attempt (more info ...)attempted-user 2009-2997   
16173FILE-PDF Adobe Acrobat Reader U3D progressive mesh continuation pointer overwrite attempt (more info ...)attempted-user 2009-2998   
16174FILE-PDF Adobe Acrobat Reader U3D progressive mesh continuation off by one index attempt (more info ...)attempted-user 2009-3458   
16175FILE-PDF Adobe Acrobat Reader collab.removeStateModel denial of service attempt (more info ...)attempted-user 2009-2988   
16176FILE-PDF Adobe Acrobat Reader collab.addStateModel remote corruption attempt (more info ...)attempted-user 2009-2996   
16220FILE-OTHER Adobe Shockwave director file malformed lcsr block memory corruption attempt (more info ...)attempted-user 2009-3466   URL
16223FILE-OTHER Adobe Shockwave tSAC pointer overwrite attempt (more info ...)attempted-user 2009-3464   URL
16224FILE-MULTIMEDIA Apple iTunes invalid tref box exploit attempt (more info ...)attempted-dos 2010-0531   URL
16225FILE-OTHER Adobe Shockwave Flash arbitrary memory access attempt (more info ...)attempted-user 2009-3465   URL
16293FILE-OTHER Adobe Shockwave Flash memory corruption attempt (more info ...)attempted-user 2009-3463   
16315FILE-FLASH Adobe Flash PlugIn check if file exists attempt (more info ...)misc-activity 2009-3951   
16316FILE-FLASH Adobe Flash Player malformed getPropertyLate actioncode attempt (more info ...)attempted-user 2009-3797   
16320FILE-IMAGE Adobe PNG empty sPLT exploit attempt (more info ...)attempted-user 2009-2984   
16321FILE-IMAGE Adobe tiff oversized image length attempt (more info ...)attempted-user 2009-2995   
16322FILE-PDF Adobe Acrobat Reader oversized object width attempt (more info ...)attempted-user 2009-2980   
16323FILE-PDF Adobe Acrobat Reader JPEG2k uninitialized QCC memory corruption attempt (more info ...)attempted-user 2009-2995   
16324FILE-PDF Adobe Acrobat Reader doc.export arbitrary file write attempt (more info ...)attempted-user 2009-2993   
16325FILE-PDF Adobe JPEG2k uninitialized QCC memory corruption attempt (more info ...)attempted-user 2009-2994   
16331FILE-FLASH Adobe Flash Player JPEG parsing heap overflow attempt (more info ...)attempted-user 2009-3794   
16333FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
16334FILE-PDF Adobe Acrobat Reader compressed media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324   
16337FILE-FLASH Adobe Flash Player directory traversal attempt (more info ...)attempted-admin 2009-3792 37420  URL
16340BROWSER-PLUGINS Microsoft Windows Media Player DHTML Editing ActiveX clsid access (more info ...)attempted-user 2003-0228 7517 11595 URL
16359FILE-OTHER Adobe Illustrator DSC comment overflow attempt (more info ...)attempted-user 2009-4195 37192  
16360FILE-MULTIMEDIA Apple QuickTime Image Description Atom sign extension memory corruption attempt (more info ...)attempted-user 2009-0955 35166  URL
16370FILE-PDF Adobe Reader JP2C Region Atom CompNum memory corruption attempt (more info ...)attempted-user 2009-3955   
16373FILE-PDF Adobe Acrobat Reader U3D CLODMeshContinuation code execution attempt (more info ...)attempted-user 2009-2990 36665  URL
16390FILE-PDF Adobe Acrobat Reader alternate file magic obfuscation (more info ...)misc-activity    URL
16537BROWSER-PLUGINS Microsoft Windows Media Player ActiveX unknown compression algorithm use after free attempt (more info ...)attempted-user 2010-0268   URL
16541OS-WINDOWS Microsoft Windows Media Service stack overflow attempt (more info ...)attempted-admin 2010-0478   URL
16543FILE-MULTIMEDIA Microsoft Windows Media Player codec code execution attempt (more info ...)attempted-user 2010-0480   URL
16546FILE-PDF Adobe Acrobat Reader/Acrobat Pro CFF font parsing heap overflow attempt (more info ...)attempted-user 2010-1241   
16561FILE-IMAGE Adobe Photoshop CS4 TIFF file exploit attempt - 1 (more info ...)attempted-user 2017-3028   URL
16562FILE-IMAGE Adobe Photoshop CS4 TIFF file exploit attempt - 2 (more info ...)attempted-user 2010-1279   URL
16563FILE-IMAGE Adobe Photoshop CS4 TIFF file exploit attempt - 3 (more info ...)attempted-user 2010-1279   URL
16564FILE-IMAGE Adobe Photoshop CS4 TIFF file exploit attempt - 4 (more info ...)attempted-user 2010-1279   URL
16578OS-WINDOWS Microsoft Windows Media Encoder 9 ActiveX buffer overflow attempt (more info ...)attempted-user 2008-3008   URL
16603FILE-PDF Adobe Acrobat Reader Linux malformed U3D mesh deceleration block exploit attempt (more info ...)attempted-user 2010-0196   
16607BROWSER-PLUGINS RealNetworks RealPlayer RAM Download Handler ActiveX control access attempt (more info ...)attempted-user 2008-1309 28157  URL
16609BROWSER-PLUGINS RealNetworks RealPlayer Import ActiveX clsid access attempt (more info ...)attempted-user 2008-3066 30379  
16633FILE-PDF Adobe Acrobat Reader File containing Flash use-after-free attack attempt (more info ...)attempted-user 2010-1297   
16634FILE-FLASH Adobe Flash use-after-free attack attempt (more info ...)attempted-user 2010-1297   
16664FILE-PDF Adobe Acrobat Reader authplay.dll vulnerability exploit attempt (more info ...)attempted-user 2010-1297 40586  
16673FILE-OTHER Adobe Shockwave DIR file PAMI chunk code execution attempt (more info ...)attempted-user 2010-1292   URL
16676FILE-PDF Adobe Acrobat Reader malformed FlateDecode colors declaration (more info ...)attempted-user 2009-3459 36600  
16677FILE-PDF Adobe Acrobat Reader malformed FlateDecode colors declaration (more info ...)attempted-user 2009-3459 36600  
16801FILE-PDF Adobe Acrobat Reader CoolType.dll remote memory corruption denial of service attempt (more info ...)attempted-dos 2010-2204 41130  
17096BROWSER-PLUGINS AOL WinAmpX ActiveX clsid access (more info ...)attempted-user  35028  
17098BROWSER-PLUGINS AOL IWinAmpActiveX class ConvertFile buffer overflow attempt (more info ...)attempted-user  35028  
17141FILE-FLASH Adobe Flash invalid data precision arbitrary code execution exploit attempt (more info ...)attempted-user 2010-2216   URL
17142FILE-FLASH Adobe Flash Player SWF ActionScript exploit attempt (more info ...)attempted-user 2010-0209   URL
17143FILE-IMAGE Adobe Photoshop CS4 ABR file processing buffer overflow attempt - 1 (more info ...)attempted-user 2010-1296 40389  
17144FILE-IMAGE Adobe Photoshop CS4 ABR file processing buffer overflow attempt - 2 (more info ...)attempted-user 2010-1296 40389  
17145FILE-IMAGE Adobe Photoshop CS4 ASL file processing buffer overflow attempt (more info ...)attempted-user 2010-1296 40389  
17146FILE-IMAGE Adobe Photoshop CS4 GRD file processing buffer overflow attempt (more info ...)attempted-user 2010-1296 40389  
17147FILE-IMAGE Adobe Photoshop CS4 ABR file processing buffer overflow attempt (more info ...)attempted-user 2010-1296 40389  
17179FILE-OTHER Adobe Director file pamm record exploit attempt (more info ...)attempted-user 2010-2880   
17180FILE-OTHER Adobe Director file LsCM record exploit attempt (more info ...)attempted-user 2010-2881   
17181FILE-OTHER Adobe Director file LsCM record exploit attempt (more info ...)attempted-user 2010-2864   
17182FILE-OTHER Adobe Director file tSAC record exploit attempt (more info ...)attempted-user 2010-2869   
17183FILE-OTHER Adobe Director file tSAC record exploit attempt (more info ...)attempted-user 2010-2869   
17184FILE-OTHER Adobe Director file tSAC record exploit attempt (more info ...)attempted-user 2010-2869   
17185FILE-OTHER Adobe Director file rcsL record exploit attempt (more info ...)attempted-user 2010-2869   
17186FILE-OTHER Adobe Director file rcsL record exploit attempt (more info ...)attempted-user 2010-2869   
17187FILE-OTHER Adobe Director file rcsL record exploit attempt (more info ...)attempted-user 2010-2869   
17188FILE-OTHER Adobe Director file rcsL record exploit attempt (more info ...)attempted-user 2010-2869   
17189FILE-OTHER Adobe Director file rcsL record exploit attempt (more info ...)attempted-user 2010-2882   
17190FILE-OTHER Adobe Director remote code execution attempt (more info ...)attempted-user 2010-2871   
17191FILE-OTHER Adobe Director remote code execution attempt (more info ...)attempted-user 2010-2872   
17192FILE-OTHER Adobe Director remote code execution attempt (more info ...)attempted-user 2010-2873   
17193FILE-OTHER Adobe Director remote code execution attempt (more info ...)attempted-user 2010-2874   
17194FILE-OTHER Adobe Director file tSAC tag exploit attempt (more info ...)attempted-user 2010-2875 42668  URL
17196FILE-OTHER Adobe Director file exploit attempt (more info ...)attempted-user 2010-2877   
17197FILE-OTHER Adobe Director file exploit attempt (more info ...)attempted-user 2010-2879   
17198FILE-OTHER Adobe Director file exploit attempt (more info ...)attempted-user 2010-2878   
17199FILE-OTHER Adobe Shockwave Director file lRTX overflow attempt (more info ...)attempted-user 2010-2863   
17200FILE-OTHER Adobe Director file LsCM overflow attempt (more info ...)attempted-user 2010-2864   
17201FILE-OTHER Adobe Shockwave Director file LsCM overflow attempt (more info ...)attempted-user 2010-2865   
17202FILE-OTHER Adobe Director file file Shockwave 3D overflow attempt (more info ...)attempted-user 2010-2866   URL
17203FILE-OTHER Adobe Director file file rcsL overflow attempt (more info ...)attempted-user 2010-2867   
17211FILE-MULTIMEDIA Apple QuickTime marshaled punk remote code execution (more info ...)attempted-user 2010-1818   
17223FILE-FLASH Adobe Flash Player navigateToURL cross-site scripting attempt (more info ...)misc-activity 2007-6244 26960  
17228OS-WINDOWS Microsoft Windows Media Player skin decompression code execution attempt (more info ...)attempted-user 2007-3035 25307  
17242FILE-MULTIMEDIA Windows Media Player ASF file arbitrary code execution attempt (more info ...)attempted-user 2010-0818   URL
17257FILE-FLASH Adobe Flash Player and Reader remote code execution attempt (more info ...)attempted-user 2010-2884   URL
17272FILE-MULTIMEDIA RealNetworks RealPlayer AVI parsing buffer overflow attempt (more info ...)attempted-user 2005-2052 13530  
17334FILE-FLASH RealNetworks RealPlayer SWF flash file buffer overflow attempt (more info ...)attempted-user 2006-0323 17202  
17351FILE-OTHER Nullsoft Winamp ID3v2 Tag Handling Buffer Overflow attempt (more info ...)attempted-user 2005-2310 14276  
17361FILE-PDF Adobe Acrobat Reader PDF Catalog Handling denial of service attempt (more info ...)attempted-user 2007-0104 21910  URL
17372FILE-MULTIMEDIA Apple QuickTime udta atom parsing heap overflow vulnerability (more info ...)attempted-user 2007-0714 22844  
17373FILE-MULTIMEDIA Apple QuickTime panorama atoms buffer overflow attempt (more info ...)attempted-user 2007-4675 26342  
17381FILE-MULTIMEDIA Apple QuickTime PDAT Atom parsing buffer overflow attempt (more info ...)attempted-user 2008-3625   URL
17461FILE-OTHER RealNetworks RealPlayer zipped skin file buffer overflow attempt (more info ...)attempted-user 2005-2630 15382  
17470FILE-MULTIMEDIA Apple QuickTime STSD JPEG atom heap corruption attempt (more info ...)attempted-user 2009-0007 33390  
17523FILE-MULTIMEDIA Apple QuickTime H.264 Movie File Buffer Overflow (more info ...)attempted-user 2009-2799 36328  
17526FILE-PDF Adobe Acrobat and Adobe Acrobat Reader U3D RHAdobeMeta buffer overflow attempt (more info ...)attempted-user 2009-1855 35282  URL
17529SERVER-WEBAPP Adobe RoboHelp Server Arbitrary File Upload and Execute (more info ...)attempted-user 2009-1855 35282  
17531FILE-MULTIMEDIA Apple QuickTime MOV file JVTCompEncodeFrame heap overflow attempt (more info ...)attempted-user 2007-2295 23650  
17548FILE-MULTIMEDIA Apple QuickTime SMIL File Handling Integer Overflow attempt (more info ...)attempted-user 2007-2394 24873  
17552FILE-IDENTIFY Adobe Pagemaker file download request (more info ...)misc-activity    URL
17553FILE-OTHER Adobe Pagemaker Font Name Buffer Overflow attempt (more info ...)attempted-user 2007-5169 25989  
17561FILE-MULTIMEDIA RealNetworks RealPlayer IVR Overly Long Filename Code Execution attempt (more info ...)attempted-user 2009-0375 33652  
17587BROWSER-PLUGINS Adobe Multiple Product AcroPDF.PDF ActiveX exploit attempt (more info ...)attempted-user 2006-6027 21155  URL
17606FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
17608FILE-MULTIMEDIA Apple QuickTime color table atom movie file handling heap corruption attempt (more info ...)attempted-user 2007-4677 26338  
17610FILE-MULTIMEDIA GStreamer QuickTime file parsing multiple heap overflow attempt (more info ...)attempted-user 2009-0398 33405  
17611FILE-MULTIMEDIA GStreamer QuickTime file parsing multiple heap overflow attempt (more info ...)attempted-user 2009-0398 33405  
17612FILE-MULTIMEDIA GStreamer QuickTime file parsing multiple heap overflow attempt (more info ...)attempted-user 2009-0398 33405  
17633FILE-OTHER RealNetworks RealPlayer SWF frame handling buffer overflow attempt (more info ...)attempted-user 2007-5400 30370  
17650FILE-OTHER Adobe Pagemaker Key Strings Stack Buffer Overflow attempt (more info ...)attempted-admin 2007-6432 31999  
17658FILE-FLASH Adobe Flash frame type identifier memory corruption attempt (more info ...)attempted-user 2005-2628 15332  
17666FILE-MULTIMEDIA RealNetworks RealPlayer invalid chunk size heap overflow attempt (more info ...)attempted-user 2005-2922 17202  
17678FILE-IMAGE Adobe BMP image handler buffer overflow attempt (more info ...)attempted-user 2008-1765 28874  
17698SERVER-MAIL RealNetworks RealPlayer wav chunk string overflow attempt in email (more info ...)attempted-user 2005-0611 12697  
17735FILE-OTHER Adobe Pagemaker Font Name Buffer Overflow attempt (more info ...)attempted-user 2007-5169 25989  
17739FILE-IDENTIFY FlashPix file download request (more info ...)misc-activity    URL
17753FILE-MULTIMEDIA Microsoft Windows Media Player network sharing service RTSP code execution attempt (more info ...)attempted-user 2010-3225 43776  URL
17803FILE-OTHER Adobe Shockwave Director rcsL chunk memory corruption attempt (more info ...)attempted-user 2010-2873 42682  URL
17806FILE-OTHER Adobe Shockwave Director rcsL chunk remote code execution attempt (more info ...)attempted-user 2010-3653 44291  URL
17807FILE-OTHER Adobe Shockwave Director rcsL chunk remote code execution attempt (more info ...)attempted-user 2010-3653 44291  URL
17808FILE-FLASH Adobe Flash authplay.dll memory corruption attempt (more info ...)attempted-user 2010-3654   URL
18180FILE-FLASH Adobe Flash Player ActionScript remote code execution attempt (more info ...)attempted-user 2010-3648 44684  URL
18229FILE-IMAGE Microsoft FlashPix tile length overflow attempt (more info ...)attempted-user 2010-3952   URL
18237FILE-IMAGE Microsoft Windows Flashpix graphics filter fpx32.flt remote code execution attempt (more info ...)attempted-user 2010-3951   URL
18308FILE-PDF Adobe Acrobat Reader ICC mluc integer overflow attempt (more info ...)attempted-user 2010-3622 43729  URL
18402FILE-OTHER Microsoft Windows ATMFD Adobe font driver remote code execution attempt (more info ...)attempted-user 2011-0033   URL
18418FILE-FLASH Adobe Flash Player ActionScript apply function memory corruption attempt (more info ...)attempted-user 2011-0558   URL
18419FILE-PDF Adobe Acrobat Reader field flags exploit attempt (more info ...)attempted-user 2011-0589   URL
18420FILE-FLASH Adobe Flash Player ActionScript ASnative function remote code execution attempt (more info ...)attempted-user 2011-0559   URL
18421FILE-FLASH Adobe Flash Player ActionScript beginGradientFill memory corruption attempt (more info ...)attempted-user 2011-0561   URL
18432FILE-PDF Adobe Acrobat Reader d3dref9.dll dll-load exploit attempt (more info ...)attempted-user 2011-0588   URL
18433FILE-OTHER Adobe Acrobat Reader d3dref9.dll dll-load exploit attempt (more info ...)attempted-user 2011-0588   URL
18434FILE-OTHER Adobe Acrobat Reader plugin ace.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18435FILE-OTHER Adobe Acrobat Reader plugin agm.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18436FILE-OTHER Adobe Acrobat Reader plugin bibutils.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18437FILE-OTHER Adobe Acrobat Reader plugin cooltype.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18438FILE-OTHER Adobe Acrobat Reader plugin cryptocme2.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18439FILE-PDF Adobe Acrobat Reader plugin ace.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18440FILE-PDF Adobe Acrobat Reader plugin agm.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18441FILE-PDF Adobe Acrobat Reader plugin bibutils.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18442FILE-PDF Adobe Acrobat Reader plugin cooltype.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18443FILE-PDF Adobe Acrobat Reader plugin cryptocme2.dll dll-load exploit attempt (more info ...)attempted-user 2011-0570   URL
18444FILE-FLASH Adobe Flash Player forged atom type attempt (more info ...)attempted-user 2011-0574   URL
18445FILE-FLASH Adobe Acrobat Flash Player nvapi.dll dll-load exploit attempt (more info ...)attempted-user 2011-0575   URL
18446FILE-FLASH Adobe Acrobat Flash Player nvapi.dll dll-load exploit attempt (more info ...)attempted-user 2011-0575   URL
18447FILE-FLASH Adobe OpenAction crafted URI action thru Firefox attempt (more info ...)attempted-user 2011-0587   URL
18448FILE-PDF Adobe Acrobat Universal 3D stream memory corruption attempt (more info ...)attempted-user 2011-0592 46210  URL
18449FILE-OTHER Adobe Acrobat font definition memory corruption attempt (more info ...)attempted-user 2011-0594   URL
18450FILE-PDF Adobe Acrobat Reader malformed BMP RGBQUAD attempt (more info ...)attempted-user 2011-0596   URL
18451FILE-PDF Adobe Acrobat ICC color integer overflow attempt (more info ...)attempted-user 2011-0598 46219  URL
18452FILE-OTHER Adobe malicious IFF memory corruption attempt (more info ...)attempted-admin 2011-0590   URL
18453FILE-PDF Adobe Acrobat universal 3D format memory corruption attempt (more info ...)attempted-user 2011-0593 46211  URL
18454FILE-PDF Adobe Acrobat universal 3D format memory corruption attempt (more info ...)attempted-user 2011-0599   URL
18455FILE-PDF Adobe Acrobat Reader malformed jpeg2000 superbox attempt (more info ...)attempted-user 2011-0602   URL
18456FILE-PDF Adobe Acrobat XML entity escape attempt (more info ...)attempted-user 2011-0604   URL
18457FILE-PDF Adobe Acrobat Reader U3D rgba parsing overflow attempt (more info ...)attempted-user 2011-0591 46209  URL
18464SERVER-WEBAPP Adobe ColdFusion locale directory traversal attempt (more info ...)attempted-admin 2010-2861 42342  
18484FILE-MULTIMEDIA Apple iTunes Playlist Overflow Attempt (more info ...)attempted-user 2005-0043   
18489FILE-OTHER Adobe Photoshop request for wintab32.dll over SMB attempt (more info ...)attempted-user 2010-3127   
18497OS-WINDOWS Microsoft Windows Media Player and shell extension request for ehtrace.dll over SMB attempt (more info ...)attempted-user 2011-2009   URL
18502FILE-FLASH Adobe Flash Player ActionScript Actionlf out of range negative offset attempt (more info ...)attempted-user 2011-0560   URL
18503FILE-FLASH Adobe Flash Player ActionScript flash.geom.Point constructor memory corruption attempt (more info ...)attempted-user 2011-0578   URL
18504FILE-FLASH Adobe Flash Player ActionConstantPool overflow attempt (more info ...)attempted-user 2011-0607   URL
18505FILE-FLASH Adobe Flash Player ActionPush overflow attempt (more info ...)attempted-user 2011-0608   URL
18506FILE-PDF Adobe Acrobat Reader CCITT stream compression filter invalid image size heap overflow attempt (more info ...)attempted-user 2011-0567 46199  URL
18507FILE-PDF Adobe Acrobat Reader CCITT stream compression filter invalid image size heap overflow attempt (more info ...)attempted-user 2011-0567 46199  URL
18510FILE-IMAGE Apple QuickTime FlashPix Movie file integer overflow attempt (more info ...)attempted-user 2010-0519 39020  
18529FILE-OTHER Adobe Premiere Pro ibfs32.dll dll-load exploit attempt (more info ...)attempted-user 2010-3150   URL
18530FILE-OTHER Adobe Premier Pro ibfs32.dll dll-load exploit attempt (more info ...)attempted-user 2010-3150   URL
18542BROWSER-PLUGINS Microsoft Windows Media Player ActiveX unknown compression algorithm use after free attempt (more info ...)attempted-user 2010-0268   URL
18543FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
18544FILE-FLASH embedded Shockwave dropper in email attachment (more info ...)attempted-user 2011-0609   URL
18578BROWSER-PLUGINS RealNetworks RealPlayer RMOC3260.DLL cdda URI overflow attempt (more info ...)attempted-user 2010-3747 44144  
18596FILE-PDF Adobe Acrobat Reader util.printf buffer overflow attempt (more info ...)attempted-user 2008-2992   
18599FILE-IMAGE Apple QuickTime PictureViewer buffer overflow attempt (more info ...)attempted-user 2005-2340 16202  
18600FILE-IMAGE Apple QuickTime PictureViewer buffer overflow attempt (more info ...)attempted-user 2005-2340 16202  
18776FILE-OTHER Adobe Shockwave Director pamm chunk memory corruption attempt (more info ...)attempted-user 2010-4084   URL
18801FILE-PDF Adobe Acrobat Reader JpxDecode invalid crgn memory corruption attempt (more info ...)attempted-user 2009-3955 37757  
18805FILE-FLASH Adobe Flash Player undefined tag exploit attempt (more info ...)attempted-user 2010-2214   
18928FILE-MULTIMEDIA Apple QuickTime streaming debug error logging buffer overflow attempt (more info ...)attempted-user 2010-1799 41962  
18963FILE-FLASH Adobe ActionScript 3 addEventListener exploit attempt (more info ...)attempted-user 2011-0622   URL
18964FILE-FLASH Adobe Flash file DefineFont4 remote code execution attempt (more info ...)attempted-user 2011-0619   URL
18965FILE-FLASH Adobe Flash file ActionScript 2 ActionJump remote code execution attempt (more info ...)attempted-user 2011-0624   URL
18966FILE-FLASH Adobe Flash file DefineFont4 remote code execution attempt (more info ...)attempted-user 2011-0627   URL
18967FILE-FLASH Adobe ActionScript argumentCount download attempt (more info ...)attempted-user 2011-0621   URL
18968FILE-FLASH Adobe Flash Player ActionScript3 stack integer overflow attempt (more info ...)attempted-user 2011-0618   URL
18969FILE-FLASH Adobe Flash Player ActionScript ActionIf integer overflow attempt (more info ...)attempted-user 2011-0625   URL
18970FILE-FLASH Adobe Flash Player null pointer dereference attempt (more info ...)attempted-user 2011-0626   URL
18971FILE-FLASH Adobe Flash beginGradientfill improper color validation attempt (more info ...)attempted-user 2011-0620   URL
18992FILE-FLASH Adobe Flash Player content parsing execution attempt (more info ...)attempted-user 2010-3654 44503  
19002FILE-FLASH RealNetworks RealPlayer FLV integer overflow attempt (more info ...)attempted-user 2010-3000 42775  
19011FILE-OTHER Adobe Shockwave Player Lnam chunk processing buffer overflow attempt (more info ...)attempted-user 2010-3655 44516  URL
19012FILE-OTHER Adobe Shockwave Player Lnam chunk processing buffer overflow attempt (more info ...)attempted-user 2010-3655 44516  URL
19071FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
19080FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
19082FILE-PDF Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
19083FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
19111FILE-FLASH Adobe Flash Media Server memory exhaustion (more info ...)misc-activity 2009-3791   
19112FILE-OTHER Adobe Shockwave 3D stucture heap overflow (more info ...)attempted-user 2009-4002   URL
19113FILE-OTHER Adobe Shockwave 3D structure opcode 81 overflow attempt (more info ...)attempted-user 2009-4003   URL
19114FILE-OTHER Adobe Shockwave 3D structure opcode 45 overflow attempt (more info ...)attempted-user 2009-4003   URL
19115FILE-OTHER Adobe Shockwave 3D structure opcode 89 overflow attempt (more info ...)attempted-user 2009-4003   URL
19117FILE-PDF Adobe Acrobat Reader malformed U3D integer overflow (more info ...)attempted-user 2009-3959   URL
19118FILE-PDF Adobe Acrobat Reader script injection vulnerability (more info ...)attempted-user 2009-3956   URL
19128FILE-IDENTIFY RealNetworks Realplayer REC file magic detected (more info ...)misc-activity    URL
19129FILE-IDENTIFY RealNetworks Realplayer .r1m file magic detected (more info ...)misc-activity    URL
19143FILE-MULTIMEDIA Microsoft Windows Media Player JPG header record mismatch memory corruption attempt (more info ...)attempted-user 2010-1880 40464  URL
19145FILE-FLASH Adobe Flash Player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297 40586  
19148FILE-MULTIMEDIA Adobe Flash Player SWF file MP4 data parsing memory corruption attempt (more info ...)attempted-user 2010-2162 40801  URL
19169FILE-MULTIMEDIA RealNetworks RealPlayer vidplin.dll avi header parsing execution attempt (more info ...)attempted-user 2010-4393 46047  
19178FILE-FLASH Adobe Flash Player cross-site request forgery attempt (more info ...)attempted-user 2011-2107   URL
19179FILE-FLASH Adobe Flash Player cross-site request forgery attempt (more info ...)attempted-user 2011-2107   URL
19196OS-WINDOWS Microsoft Windows ATMFD Adobe font driver remote code execution attempt (more info ...)attempted-user 2011-0033 46106  URL
19247FILE-IMAGE Adobe jpeg 2000 image exploit attempt (more info ...)attempted-user 2011-2098   URL
19248FILE-PDF Adobe Acrobat Reader malformed U3D texture continuation integer overflow attempt (more info ...)attempted-user 2011-2096   URL
19249FILE-FLASH Adobe Universal3D meshes.removeItem exploit attempt (more info ...)attempted-admin 2011-2099   URL
19250FILE-PDF Adobe Acrobat and Adobe Acrobat Reader U3D file include overflow attempt (more info ...)attempted-user 2011-2094   URL
19251FILE-PDF Adobe Acrobat Reader CIDFont dictionary glyph width corruption attempt (more info ...)attempted-user 2011-2105   URL
19253FILE-PDF Adobe Acrobat Reader malicious language.engtesselate.ln file download attempt (more info ...)attempted-user 2011-2095   URL
19255FILE-PDF Adobe Acrobat Reader ICC ProfileDescriptionTag overflow attempt (more info ...)attempted-user 2011-2097   URL
19268FILE-PDF attempted download of a PDF with embedded Flash (more info ...)policy-violation 2010-3654 44503  URL
19269FILE-PDF attempted download of a PDF with embedded Flash (more info ...)policy-violation 2010-3654 44503  URL
19293FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
19350FILE-MULTIMEDIA Adobe Shockwave Player Director file FFFFFF88 record integer overflow attempt (more info ...)attempted-user 2010-2876   URL
19408FILE-FLASH Adobe Flash Player newfunction memory corruption exploit attempt (more info ...)attempted-admin 2010-1297   
19431FILE-MULTIMEDIA Nullsoft Winamp MIDI Timestamp buffer overflow attempt (more info ...)attempted-user  45221  
19432FILE-MULTIMEDIA Nullsoft Winamp MIDI Timestamp buffer overflow attempt (more info ...)attempted-user  45221  
19444FILE-MULTIMEDIA Microsoft Windows Media sample duration header RCE attempt (more info ...)attempted-user 2009-2498   URL
19445FILE-MULTIMEDIA Microsoft Windows Media Timecode header RCE attempt (more info ...)attempted-user 2009-2498   URL
19446FILE-MULTIMEDIA Microsoft Windows Media file name header RCE attempt (more info ...)attempted-user 2009-2498   URL
19447FILE-MULTIMEDIA Microsoft Windows Media content type header RCE attempt (more info ...)attempted-user 2009-2498   URL
19448FILE-MULTIMEDIA Microsoft Windows Media pixel aspect ratio header RCE attempt (more info ...)attempted-user 2009-2498   URL
19449FILE-MULTIMEDIA Microsoft Windows Media encryption sample ID header RCE attempt (more info ...)attempted-user 2009-2498   URL
19450FILE-MULTIMEDIA Microsoft Windows Media encryption sample ID header RCE attempt (more info ...)attempted-user 2009-2498   URL
19560FILE-MULTIMEDIA Apple iTunes PLS file parsing buffer overflow attempt (more info ...)attempted-user 2009-2817 36478  
19561BROWSER-PLUGINS RealNetworks RealPlayer ieframe.dll ActiveX clsid access (more info ...)attempted-user  47565  
19617FILE-OTHER Adobe Audition assist.dll dll-load exploit attempt (more info ...)attempted-user    URL
19619FILE-OTHER Adobe Audition assist.dll dll-load exploit attempt (more info ...)attempted-user    URL
19683FILE-FLASH Adobe Flash Player ActionScript 3 buffer overflow attempt (more info ...)attempted-user 2011-2415   URL
19684FILE-OTHER Adobe CFF font storage memory corruption attempt (more info ...)attempted-user 2011-2417   URL
19685FILE-FLASH Adobe Flash regular expression grouping depth buffer overflow attempt (more info ...)attempted-user 2014-0499 65703  URL
19686FILE-FLASH Adobe Flash uninitialized bitmap structure memory corruption attempt (more info ...)attempted-user 2011-2425   URL
19687FILE-FLASH Adobe Flash ActionStoreRegister instruction length invalidation attempt (more info ...)attempted-admin 2011-2414   URL
19688FILE-FLASH Adobe Flash Player ActionScript BitmapData buffer overflow attempt (more info ...)attempted-user 2011-2138   URL
19689FILE-FLASH Adobe Flash Player ActionScript dynamic calculation double-free attempt (more info ...)attempted-dos 2011-2135   URL
19690FILE-FLASH Adobe Flash Player ActionScript duplicateDoorInputArguments stack overwrite (more info ...)attempted-user 2011-2136   URL
19691FILE-FLASH Adobe Flash Player ActionScript File reference buffer overflow attempt (more info ...)attempted-user 2011-2137   URL
19692FILE-FLASH Adobe Flash cross-site request forgery attempt (more info ...)attempted-user 2011-2139   URL
19693FILE-FLASH Adobe Flash MP4 ref_frame allocated buffer overflow attempt (more info ...)attempted-admin 2011-2140   URL
20050FILE-FLASH Adobe Flash Player memory consumption vulnerability (more info ...)denial-of-service 2009-3793   
20059FILE-IMAGE Apple Quicktime PictureViewer GIF rendering vulnerability (more info ...)attempted-user 2005-1106   
20144FILE-PDF Adobe Acrobat embedded TIFF DotRange structure memory corruption attempt (more info ...)attempted-user 2011-2432   URL
20145FILE-PDF Adobe Acrobat Reader embedded PICT parsing corruption attempt (more info ...)attempted-user 2011-2433   URL
20147FILE-PDF Adobe Acrobat Reader embedded PICT parsing corruption attempt (more info ...)attempted-user 2011-2434   URL
20148FILE-PDF Adobe Acrobat Reader embedded PICT parsing corruption attempt (more info ...)attempted-user 2011-2435   URL
20149FILE-PDF Adobe Acrobat Reader embedded IFF file RGBA chunk memory corruption attempt (more info ...)attempted-user 2011-2436   URL
20150FILE-PDF Adobe Acrobat Reader embedded PCX parsing corruption attempt (more info ...)attempted-user 2011-2437   URL
20152FILE-PDF Adobe Acrobat GDI object leak memory corruption attempt (more info ...)attempted-user 2011-2439   URL
20153FILE-PDF Adobe Acrobat embedded JPEG file APP0 chunk memory corruption attempt (more info ...)attempted-user 2011-2440   URL
20154FILE-PDF Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt (more info ...)attempted-user 2011-2441 49581  URL
20155FILE-PDF Adobe Acrobat Reader CoolType.dll composite glyf buffer overflow attempt (more info ...)attempted-user 2011-2441 49581  URL
20156FILE-PDF Adobe Acrobat Reader getCosObj file overwrite attempt (more info ...)attempted-user 2011-2442   URL
20162FILE-PDF Adobe Acrobat Reader sandbox disable attempt (more info ...)attempted-user 2011-1353   URL
20169FILE-PDF Adobe Acrobat Reader embedded BMP parsing corruption attempt (more info ...)attempted-user 2011-2438   URL
20170FILE-PDF Adobe Acrobat Reader embedded BMP parsing corruption attempt (more info ...)attempted-user 2011-2438   URL
20171FILE-PDF Adobe Acrobat Reader embedded BMP parsing corruption attempt (more info ...)attempted-user 2011-2438   URL
20181FILE-FLASH Adobe Flash Speex-encoded audio buffer underflow attempt (more info ...)attempted-user 2011-2130   URL
20182FILE-FLASH Adobe Flash Player viewSource blacklist exclusion attempt (more info ...)attempted-user 2011-2429   URL
20183FILE-FLASH Adobe Flash Player setInterval use attempt (more info ...)attempted-user 2011-2444   URL
20206FILE-FLASH Adobe Flash Player pcre ActionScript under allocation (more info ...)attempted-user 2011-2427   URL
20211FILE-FLASH Adobe Flash Player recursive stack overflow attempt (more info ...)attempted-user 2011-2426   URL
20235MALWARE-CNC Win.Trojan.AdobeReader.Uz runtime traffic detected (more info ...)trojan-activity    URL
20288FILE-MULTIMEDIA RealNetworks RealPlayer QCP parsing buffer overflow attempt (more info ...)attempted-user 2011-2950   
20294FILE-IMAGE Adobe Reader and Acrobat Libtiff TIFFFetchShortPair stack buffer overflow attempt (more info ...)attempted-user 2006-3459   
20429FILE-PDF Adobe Acrobat Reader U3D CLODMeshDeceleration code execution attempt (more info ...)attempted-user 2014-0523 67368  URL
20545FILE-FLASH Adobe Flash Player SWF embedded font null pointer attempt (more info ...)attempted-user 2011-2452   URL
20547FILE-FLASH Adobe Flash Player overlapping record overflow attempt (more info ...)attempted-user 2011-2453   URL
20548FILE-FLASH Adobe Flash Player recursive doaction stack exhaustion (more info ...)attempted-user 2011-2457   URL
20549FILE-FLASH Adobe Flash Player ActionScript bytecode type confusion attempt (more info ...)attempted-user 2011-2451   URL
20550FILE-FLASH Adobe Flash Player Mover3D clipping exploit (more info ...)attempted-user 2011-2460   URL
20551FILE-FLASH Adobe Flash Player Stage 3D texture format overflow attempt (more info ...)attempted-user 2011-2456   URL
20555FILE-FLASH Adobe Flash MP4 ref_frame allocated buffer overflow attempt (more info ...)attempted-admin 2011-2140   URL
20556FILE-FLASH Adobe Flash Player PlaceObjectX null pointer dereference attempt (more info ...)attempted-user 2011-2450   URL
20557FILE-FLASH Adobe Flash Player ActionDefineFunction2 length overflow attempt (more info ...)attempted-user 2011-2454   URL
20559FILE-MULTIMEDIA Nullsoft Winamp MIDI file buffer overflow attempt (more info ...)attempted-user    URL
20565FILE-OTHER Nullsoft Winamp AMF file buffer overflow attempt (more info ...)attempted-user    URL
20566FILE-OTHER Nullsoft Winamp AMF file buffer overflow attempt (more info ...)attempted-user    URL
20567FILE-FLASH Adobe Flash SWF AVM2 namespace lookup deref exploit (more info ...)attempted-user 2011-2455   
20568FILE-FLASH Adobe Flash SWF ActionScript 3 ByteArray class vulnerability (more info ...)attempted-user 2011-2445   
20575FILE-PDF Adobe Acrobat Reader PDF JBIG2 remote code execution attempt (more info ...)attempted-user 2009-0658 33751  
20610FILE-FLASH Adobe Shockwave Flash Flex authoring tool XSS exploit attempt (more info ...)attempted-admin 2011-2461   URL
20636FILE-IMAGE Adobe Photoshop CS5 gif file heap corruption attempt (more info ...)attempted-user 2011-2131 49106  
20637FILE-IMAGE Adobe Photoshop CS5 gif file heap corruption attempt (more info ...)attempted-user 2011-2131 49106  
20653FILE-MULTIMEDIA Microsoft Windows Media Player ASX file ref href buffer overflow attempt (more info ...)attempted-user 2006-6134 21247  URL
20733FILE-IDENTIFY Microsoft Windows Media Player DVR file download request (more info ...)misc-activity    
20734FILE-MULTIMEDIA Microsoft Windows Media Player digital video recording buffer overflow attempt (more info ...)attempted-user 2011-3401   URL
20744OS-WINDOWS Microsoft Windows Media Player DirectShow MPEG-2 memory corruption attempt (more info ...)attempted-user 2008-0015   URL
20762MALWARE-CNC MacOS.Flashback.A variant outbound connection (more info ...)trojan-activity    URL
20802FILE-PDF Adobe Acrobat Reader PRC file MarkupLinkedItem arbitrary code execution attempt (more info ...)attempted-user 2011-4369   URL
20875BROWSER-PLUGINS ShockwaveFlash.ShockwaveFlash ActiveX clsid access (more info ...)attempted-user 2010-2185   URL
20919FILE-PDF Adobe Acrobat Reader BMP color unused corruption (more info ...)attempted-user 2011-4372   URL
20920FILE-PDF Adobe Acrobat Reader DCT dequantizer memory corruption attempt (more info ...)attempted-user 2011-4370   URL
20921FILE-PDF Adobe Acrobat Reader embedded BMP colors used integer overflow attempt (more info ...)attempted-user 2011-4373   URL
20922FILE-PDF Adobe Acrobat Reader embedded BMP bit count integer overflow attempt (more info ...)attempted-user 2011-4373   URL
20923FILE-PDF Adobe Acrobat Reader embedded BMP bit count integer overflow attempt (more info ...)attempted-user 2011-4373   URL
20925FILE-IDENTIFY Adobe Pagemaker file attachment detected (more info ...)misc-activity    
20926FILE-IDENTIFY Adobe Pagemaker file attachment detected (more info ...)misc-activity    
21090FILE-MULTIMEDIA Nullsoft Winamp player mp4 memory corruption attempt (more info ...)attempted-user 2007-2498 23723  
21091FILE-MULTIMEDIA Nullsoft Winamp player mp4 memory corruption attempt (more info ...)attempted-user 2007-2498 23723  
21112FILE-MULTIMEDIA RealNetworks RealPlayer mpeg width integer memory underflow attempt (more info ...)attempted-user 2011-4259 50741  
21162FILE-PDF Adobe Acrobat file extension overflow attempt (more info ...)attempted-user 2004-0632 10696  
21174FILE-IDENTIFY RealNetworks RealPlayer realtext file download request (more info ...)misc-activity    
21316FILE-OTHER Adobe shockwave director tSAC string termination memory corruption attempt (more info ...)attempted-user 2011-2118   
21320FILE-FLASH Adobe Acrobat Flash Player request for atl.dll over SMB attempt (more info ...)attempted-user 2012-0756   URL
21321FILE-FLASH Adobe Acrobat Flash Player request for uxtheme.dll over SMB attempt (more info ...)attempted-user 2012-0756   URL
21323FILE-FLASH Adobe Acrobat Flash Player atl.dll dll-load exploit attempt (more info ...)attempted-user 2012-0756   URL
21324FILE-FLASH Adobe Acrobat Flash Player uxtheme.dll dll-load exploit attempt (more info ...)attempted-user 2012-0756   URL
21325FILE-FLASH Adobe Flash Player cross site request forgery attempt (more info ...)attempted-user 2012-0767   URL
21326FILE-FLASH Adobe Flash Player ActiveX URL import attempt (more info ...)attempted-user 2012-0751   URL
21371FILE-OTHER Adobe Shockwave Director KEY chunk buffer overflow attempt (more info ...)attempted-user 2011-2111 48300  
21420FILE-OTHER RealNetworks RealPlayer compressed skin overflow attempt (more info ...)attempted-user 2004-1094 11555  
21530FILE-FLASH Adobe Flash Player action script 3 bitmap malicious rectangle attempt (more info ...)attempted-user 2012-0769 52299  URL
21531FILE-FLASH Adobe Flash Player action script 3 bitmap malicious rectangle attempt (more info ...)attempted-user 2012-0769 52299  URL
21532FILE-FLASH Adobe Flash Player action script 3 bitmap malicious rectangle attempt (more info ...)attempted-user 2012-0769 52299  URL
21701FILE-IDENTIFY FlashPix file attachment detected (more info ...)misc-activity    
21702FILE-IDENTIFY FlashPix file attachment detected (more info ...)misc-activity    
21755MALWARE-CNC Apple OSX.Flashback variant outbound connection (more info ...)trojan-activity    URL
21756MALWARE-CNC Apple OSX.Flashback variant outbound connection (more info ...)trojan-activity    URL
21757MALWARE-CNC Apple OSX.Flashback variant outbound connection (more info ...)trojan-activity    URL
21758MALWARE-CNC Apple OSX.Flashback variant outbound connection (more info ...)trojan-activity    URL
21765FILE-PDF Adobe Acrobat Reader PDF subroutine pointer attempt (more info ...)attempted-user 2006-5857   
21807FILE-IDENTIFY Adobe Download Manager aom file download request (more info ...)misc-activity    
21808FILE-IDENTIFY Adobe Download Manager aom file attachment detected (more info ...)misc-activity    
21809FILE-IDENTIFY Adobe Download Manager aom file attachment detected (more info ...)misc-activity    
21810FILE-IDENTIFY Adobe Download Manager aom file magic detected (more info ...)misc-activity    
21811FILE-IDENTIFY Apple Quicktime FLIC animation file file download request (more info ...)misc-activity    
21812FILE-IDENTIFY Apple Quicktime FLIC animation file file attachment detected (more info ...)misc-activity    
21813FILE-IDENTIFY Apple Quicktime FLIC animation file file attachment detected (more info ...)misc-activity    
21814FILE-IDENTIFY Apple Quicktime FLIC file magic detected (more info ...)misc-activity    
21910MALWARE-CNC Apple OSX Flashback malware user-agent (more info ...)trojan-activity    URL
21948FILE-IMAGE Adobe Photoshop CS4 TIFF parsing heap overflow attempt (more info ...)attempted-user 2012-2027   URL
22033MALWARE-CNC Apple OSX Flashback malware variant outbound connection (more info ...)trojan-activity    URL
22034MALWARE-CNC Apple OSX Flashback malware variant outbound connection (more info ...)trojan-activity    URL
22965FILE-IDENTIFY RealNetworks RealPlayer RT file attachment detected (more info ...)misc-activity    
22966FILE-IDENTIFY RealNetworks RealPlayer RT file attachment detected (more info ...)misc-activity    
23000FILE-IDENTIFY Microsoft Windows Media Player DVR file attachment detected (more info ...)misc-activity    
23001FILE-IDENTIFY Microsoft Windows Media Player DVR file attachment detected (more info ...)misc-activity    
23014FILE-OTHER Adobe Photoshop asset elements stack based buffer overflow attempt (more info ...)attempted-user  53464  
23098FILE-MULTIMEDIA Adobe Flash Player MP4 sequence parameter set parsing overflow attempt (more info ...)attempted-user 2011-2140   URL
23166FILE-PDF Adobe Acrobat Reader XDP encoded download attempt (more info ...)misc-activity    URL
23170FILE-MULTIMEDIA Apple QuickTime MPEG stream padding buffer overflow attempt (more info ...)attempted-user 2012-0659   URL
23188FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity    
23189FILE-IDENTIFY Windows Media Metafile file attachment detected (more info ...)misc-activity    
23263FILE-PDF Adobe flash player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297   
23264FILE-FLASH Adobe Flash Player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297 40586  
23265FILE-FLASH Adobe Flash Player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297 40586  
23371FILE-OTHER Adobe Director file file Shockwave 3D overflow attempt (more info ...)attempted-user 2010-2866   URL
23403SERVER-WEBAPP Adobe JRun directory traversal attempt (more info ...)attempted-recon 2009-1874   URL
23500FILE-PDF Adobe Acrobat Reader spell.customDictionaryOpen exploit attempt (more info ...)attempted-user 2009-1493 34740  
23504FILE-PDF Adobe Acrobat Reader getAnnots exploit attempt (more info ...)attempted-user 2009-1492 34736  
23506FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
23509FILE-PDF Adobe Acrobat Reader malformed Richmedia annotation exploit attempt (more info ...)attempted-admin 2010-1297   
23510FILE-PDF Adobe Acrobat Reader File containing Flash use-after-free attack attempt (more info ...)attempted-user 2010-1297   
23511FILE-PDF Adobe Acrobat Reader authplay.dll vulnerability exploit attempt (more info ...)attempted-user 2010-1297 40586  
23512FILE-PDF Adobe flash player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297   
23564FILE-OTHER Adobe Illustrator DSC comment overflow attempt (more info ...)attempted-user 2009-4195 37192  
23565FILE-MULTIMEDIA Microsoft Windows AVI DirectShow QuickTime parsing overflow attempt (more info ...)attempted-user 2009-1537 35139  URL
23570FILE-MULTIMEDIA Microsoft Windows Media sample duration header RCE attempt (more info ...)attempted-user 2009-2498   URL
23571FILE-MULTIMEDIA Microsoft Windows Media Timecode header RCE attempt (more info ...)attempted-user 2009-2498   URL
23572FILE-MULTIMEDIA Microsoft Windows Media file name header RCE attempt (more info ...)attempted-user 2009-2498   URL
23573FILE-MULTIMEDIA Microsoft Windows Media content type header RCE attempt (more info ...)attempted-user 2009-2498   URL
23574FILE-MULTIMEDIA Microsoft Windows Media pixel aspect ratio header RCE attempt (more info ...)attempted-user 2009-2498   URL
23575FILE-MULTIMEDIA Microsoft Windows Media encryption sample ID header RCE attempt (more info ...)attempted-user 2009-2498   URL
23576FILE-MULTIMEDIA Microsoft Windows Media encryption sample ID header RCE attempt (more info ...)attempted-user 2009-2498   URL
23579FILE-FLASH Adobe Flash use-after-free attack attempt (more info ...)attempted-user 2010-1297   
23581FILE-MULTIMEDIA Apple QuickTime MPEG stream padding buffer overflow attempt (more info ...)attempted-user 2012-0659   URL
23591FILE-FLASH Adobe Flash Player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297 40586  
23592FILE-FLASH Adobe Flash Player newfunction memory corruption exploit attempt (more info ...)attempted-admin 2010-1297   
23623FILE-MULTIMEDIA Apple QuickTime VR Track Header Atom heap corruption attempt (more info ...)attempted-user 2009-0002 33384  URL
23720FILE-IDENTIFY RealNetworks Realplayer REC file magic detected (more info ...)misc-activity    URL
23721FILE-IDENTIFY RealNetworks Realplayer .r1m file magic detected (more info ...)misc-activity    URL
23764FILE-IDENTIFY Adobe Download Manager aom file magic detected (more info ...)misc-activity    
23765FILE-IDENTIFY Apple Quicktime FLIC file magic detected (more info ...)misc-activity    
23855FILE-FLASH string heapspray flash file - likely attack (more info ...)attempted-user    
23856FILE-FLASH string heapspray flash file - likely attack (more info ...)attempted-user    
23898FILE-PDF Adobe Acrobat Reader collab.collectEmailInfo exploit attempt (more info ...)attempted-user 2008-0655 27641  
24045FILE-IDENTIFY Winamp skin file wsz file download request (more info ...)misc-activity    
24046FILE-IDENTIFY Winamp skin file wsz file attachment detected (more info ...)misc-activity    
24047FILE-IDENTIFY Winamp skin file wsz file attachment detected (more info ...)misc-activity    
24048FILE-IDENTIFY Winamp skin file wal file download request (more info ...)misc-activity    
24049FILE-IDENTIFY Winamp skin file wal file attachment detected (more info ...)misc-activity    
24050FILE-IDENTIFY Winamp skin file wal file attachment detected (more info ...)misc-activity    
24051FILE-OTHER Winamp skin file arbitrary code execution attempt (more info ...)attempted-user 2004-0820 11053  
24052FILE-OTHER Winamp skin file arbitrary code execution attempt (more info ...)attempted-user 2004-0820 11053  
24124FILE-PDF Adobe Acrobat Reader PDF JBIG2 remote code execution attempt (more info ...)attempted-user 2009-0658 33751  
24220FILE-MULTIMEDIA Apple QuickTime streaming debug error logging buffer overflow attempt (more info ...)attempted-user 2010-1799 41962  
24272FILE-OTHER Adobe Director file file Shockwave 3D overflow attempt (more info ...)attempted-user 2010-2866   URL
24273FILE-OTHER Adobe Director file file Shockwave 3D overflow attempt (more info ...)attempted-user 2010-2866   URL
24277FILE-OTHER Adobe Shockwave Director rcsL chunk memory corruption attempt (more info ...)attempted-user 2010-3653 44291  URL
24278FILE-OTHER Adobe Shockwave Director rcsL chunk memory corruption attempt (more info ...)attempted-user 2010-3653 44291  URL
24279FILE-OTHER Adobe Shockwave Director rcsL chunk remote code execution attempt (more info ...)attempted-user 2010-3653 44291  URL
24280FILE-OTHER Adobe Shockwave Director rcsL chunk remote code execution attempt (more info ...)attempted-user 2010-3653 44291  URL
24508FILE-PDF Adobe Acrobat font parsing integer overflow attempt (more info ...)attempted-user 2010-2862 42203  URL
24551FILE-IMAGE Apple QuickTime PICT Image PnSize Opcode Stack Buffer Overflow attempt (more info ...)attempted-user 2011-0257 49144  
24552FILE-IMAGE Apple QuickTime PICT Image PnSize Opcode Stack Buffer Overflow attempt (more info ...)attempted-user 2011-0257 49144  
24553FILE-IMAGE Apple QuickTime PICT Image PnSize Opcode Stack Buffer Overflow attempt (more info ...)attempted-user 2011-0257 49144  
24554FILE-IDENTIFY Apple QuickTime PICT v2.0 Image header (more info ...)attempted-user 2011-0257 49144  
24555FILE-IDENTIFY Apple QuickTime PICT v2.0 Image header (more info ...)attempted-user 2011-0257 49144  
24640FILE-MULTIMEDIA Apple QuickTime movie buffer overflow attempt (more info ...)attempted-user 2006-4381   URL
24641FILE-MULTIMEDIA Apple QuickTime movie buffer overflow attempt (more info ...)attempted-user 2006-4381   URL
24672FILE-MULTIMEDIA Adobe Flash Player MP4 sequence parameter set parsing overflow attempt (more info ...)attempted-user 2011-2140   URL
24687FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
24688FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
24721FILE-PDF Adobe Acrobat Reader empty object page tree node reference attempt (more info ...)attempted-user    URL
24722FILE-PDF Adobe Acrobat Reader empty object page tree node reference attempt (more info ...)attempted-user    URL
24723BROWSER-PLUGINS IBM Rational Rhapsody BBFlashback ActiveX clsid access attempt (more info ...)attempted-user 2011-1391   
24724BROWSER-PLUGINS IBM Rational Rhapsody BBFlashback ActiveX function call access attempt (more info ...)attempted-user 2011-1391   
24725BROWSER-PLUGINS IBM Rational Rhapsody BBFlashback ActiveX clsid access attempt (more info ...)attempted-user 2011-1391   
24726BROWSER-PLUGINS IBM Rational Rhapsody BBFlashback ActiveX function call access attempt (more info ...)attempted-user 2011-1391   
24768SERVER-OTHER RealPlayer Helix rn5auth credential overflow attempt (more info ...)attempted-admin 2012-0942   URL
24824FILE-IDENTIFY RealPlayer skin file download request (more info ...)misc-activity    
24825FILE-IDENTIFY RealPlayer skin file attachment detected (more info ...)misc-activity    
24826FILE-IDENTIFY RealPlayer skin file attachment detected (more info ...)misc-activity    
24891FILE-FLASH Adobe Flash Player action InitArray stack overflow attempt (more info ...)attempted-user 2012-5269   URL
24894FILE-FLASH Adobe Flash Player Action InitArray stack overflow attempt (more info ...)attempted-user 2012-5269   URL
25266SERVER-OTHER Adobe ColdFusion Admin API arbitrary command execution attempt (more info ...)attempted-user 2013-0631   URL
25305FILE-IDENTIFY Adobe Audition Session file magic detected (more info ...)misc-activity    
25306FILE-IDENTIFY Adobe Audition Session file download request (more info ...)misc-activity    
25307FILE-IDENTIFY Adobe Audition Session file attachment detected (more info ...)misc-activity    
25308FILE-IDENTIFY Adobe Audition Session file attachment detected (more info ...)misc-activity    
25309FILE-OTHER Adobe Audition Session file stack buffer overflow attempt (more info ...)attempted-user 2011-0614 47841  URL
25310FILE-OTHER Adobe Audition Session file stack buffer overflow attempt (more info ...)attempted-user 2011-0614 47841  URL
25332FILE-OTHER Adobe Audition Session file tkrm stack buffer overflow attempt (more info ...)attempted-user 2011-0614 47841  URL
25588FILE-PDF Adobe Acrobat Reader FlateDecode integer overflow attempt (more info ...)attempted-user 2009-3459 36600  
25767FILE-PDF Adobe Acrobat Reader JPX malformed code-block width memory corruption attempt (more info ...)attempted-user 2009-1861 35295  URL
25814FILE-FLASH Adobe Flash Player nested SWF cross domain clickjacking attempt (more info ...)attempted-recon 2013-0637   URL
25975POLICY-OTHER Adobe ColdFusion admin interface access attempt (more info ...)policy-violation 2013-0632 57330  URL
26027FILE-OTHER Adobe Director file file rcsL overflow attempt (more info ...)attempted-user 2010-2867   
26028FILE-OTHER Adobe Shockwave Director rcsL chunk memory corruption attempt (more info ...)attempted-user 2010-2873 42682  URL
26029FILE-OTHER Adobe Director remote code execution attempt (more info ...)attempted-user 2010-2873   
26109FILE-MULTIMEDIA Apple QuickTime Obji Atom parsing stack buffer overflow attempt (more info ...)attempted-user 2008-1022 28583  
26110FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
26111FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
26112FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
26113FILE-PDF Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
26327MALWARE-CNC OSX.Trojan.Flashfake variant outbound connection (more info ...)trojan-activity    
26472FILE-MULTIMEDIA Apple QuickTime pict image poly structure memory corruption attempt (more info ...)attempted-user 2009-0010 34938  
26564FILE-MULTIMEDIA Apple QuickTime movie file clipping region handling heap buffer overflow attempt (more info ...)attempted-user 2009-0954 35167  URL
26621SERVER-OTHER Adobe ColdFusion adminapi information disclosure attempt (more info ...)attempted-recon 2013-3336 59773  URL
26667FILE-MULTIMEDIA Apple iTunes playlist overflow attempt (more info ...)attempted-user 2005-0043   
26694FILE-PDF Adobe Acrobat Reader dll injection sandbox escape (more info ...)attempted-user 2013-2730   URL
26699FILE-IMAGE Apple QuickTime PICT Image PnSize Opcode Stack Buffer Overflow attempt (more info ...)attempted-user 2011-0257 49144  
26700FILE-IMAGE Apple QuickTime PICT Image PnSize Opcode Stack Buffer Overflow attempt (more info ...)attempted-user 2011-0257 49144  
26701FILE-IMAGE Apple QuickTime PICT Image PnSize Opcode Stack Buffer Overflow attempt (more info ...)attempted-user 2011-0257 49144  
26724FILE-MULTIMEDIA Apple iTunes Playlist Overflow Attempt (more info ...)attempted-user 2005-0043   
26854FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected cHRM overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26855FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected iCCP overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26856FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected sBIT overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26857FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected sRGB overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26858FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected bKGD overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26859FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected hIST overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26860FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected tRNS overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26861FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected pHYs overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26862FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected sPLT overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26863FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected tIME overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26864FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected iTXt overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26866FILE-IMAGE Microsoft Windows Media Player Malformed PNG detected zTXt overflow attempt (more info ...)attempted-user 2006-0025 18385  URL
26976FILE-IMAGE Oracle Outside In FlashPix image processing overflow attempt (more info ...)attempted-user 2012-1744   
26977FILE-IMAGE Oracle Outside In FlashPix image processing overflow attempt (more info ...)attempted-user 2012-1744   
26978FILE-IMAGE Oracle Outside In FlashPix image processing overflow attempt (more info ...)attempted-user 2012-1744   
26979FILE-IMAGE Oracle Outside In FlashPix image processing overflow attempt (more info ...)attempted-user 2012-1744   
27182FILE-FLASH Adobe Flash Player malicious swf file download attempt (more info ...)attempted-user    URL
27183FILE-FLASH Adobe Flash Player malicious swf file download attempt (more info ...)attempted-user    URL
27184FILE-FLASH Adobe Flash Player malicious swf file download attempt (more info ...)attempted-user    URL
27185FILE-FLASH Adobe Flash Player malicious swf file download attempt (more info ...)attempted-user    URL
27186FILE-FLASH Adobe Flash Player malicious swf file download attempt (more info ...)attempted-user    URL
27187FILE-FLASH Adobe Flash Player malicious swf file download attempt (more info ...)attempted-user    URL
27205BROWSER-PLUGINS Microsoft Windows Media Services CallHTMLHelp ActiveX buffer overflow attempt (more info ...)attempted-user 2008-5232 30814  URL
27225SERVER-OTHER Adobe ColdFusion JRun error page getWriter denial of service attempt (more info ...)attempted-dos 2013-3349 61039  URL
27232FILE-PDF Adobe Acrobat Reader util.printf buffer overflow attempt (more info ...)attempted-user 2008-2992 30035  
27233FILE-PDF Adobe Acrobat Reader util.printf buffer overflow attempt (more info ...)attempted-user 2008-2992 30035  
27250BROWSER-PLUGINS ShockwaveFlash.ShockwaveFlash.9 ActiveX function overflow attempt (more info ...)attempted-user    
27671FILE-FLASH Adobe Flash Player embedded JPG image height overflow attempt (more info ...)attempted-admin 2007-6242 26951  
27800BROWSER-PLUGINS Microsoft Windows Media Encoder 9 ActiveX function call access (more info ...)attempted-user 2008-3008 31065  URL
28256FILE-PDF Adobe Acrobat Reader ICC mluc integer overflow attempt (more info ...)attempted-user 2010-3622 43729  URL
28257FILE-PDF Adobe Acrobat Reader ICC remote memory corruption attempt (more info ...)attempted-user 2010-3621 43726  URL
28260FILE-PDF Adobe Acrobat Reader ICC remote memory corruption attempt (more info ...)attempted-user 2010-3621 43726  URL
28261FILE-PDF Adobe Acrobat Reader ICC mluc integer overflow attempt (more info ...)attempted-user 2010-3622 43729  URL
28262FILE-PDF Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt (more info ...)attempted-user 2011-2441 49581  URL
28266FILE-PDF Adobe Acrobat Reader CoolType.dll composite glyf buffer overflow attempt (more info ...)attempted-user 2011-2441 49581  URL
28303FILE-PDF Adobe Acrobat and Adobe Acrobat Reader U3D RHAdobeMeta buffer overflow attempt (more info ...)attempted-user 2009-1855 35282  URL
28388FILE-PDF Adobe Acrobat TrueType font handling remote code execution attempt (more info ...)attempted-admin 2010-0195 39417  
28389FILE-PDF Adobe Acrobat TrueType font handling remote code execution attempt (more info ...)attempted-admin 2010-0195 39417  
28426FILE-PDF Adobe Acrobat universal 3D format memory corruption attempt (more info ...)attempted-user 2011-0599   URL
28427FILE-PDF Adobe Acrobat universal 3D format memory corruption attempt (more info ...)attempted-user 2011-0593 46211  URL
28441FILE-MULTIMEDIA Apple QuickTime MOV file string handling integer overflow attempt (more info ...)attempted-user 2005-2753 15306  
28442FILE-MULTIMEDIA Apple QuickTime MOV file string handling integer overflow attempt (more info ...)attempted-user 2005-2753 15306  
28443FILE-MULTIMEDIA Apple QuickTime MOV file string handling integer overflow attempt (more info ...)attempted-user 2005-2753 15306  
28451FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
28452FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
28453FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
28454FILE-PDF Adobe Acrobat Reader compressed media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324   
28461FILE-PDF Adobe Acrobat font parsing integer overflow attempt (more info ...)attempted-user 2010-2862 42203  URL
28462FILE-PDF Adobe Acrobat font parsing integer overflow attempt (more info ...)attempted-user 2010-2862 42203  URL
28617FILE-PDF Adobe Acrobat Reader PDSElementGetPageRangeList recursive call denial of service attempt (more info ...)attempted-dos 2013-3351 62429  URL
28618FILE-PDF Adobe Acrobat Reader PDSElementGetPageRangeList recursive call denial of service attempt (more info ...)attempted-dos 2013-3351 62429  URL
28622FILE-PDF Adobe Acrobat Reader malformed shading modifier heap corruption attempt (more info ...)attempted-user 2011-2462   URL
28623FILE-PDF Adobe Acrobat font parsing integer overflow attempt (more info ...)attempted-admin 2010-2862 42203  URL
28624FILE-PDF Adobe Acrobat font parsing integer overflow attempt (more info ...)attempted-admin 2010-2862 42203  URL
28625FILE-PDF Adobe Acrobat Reader U3D rgba parsing overflow attempt (more info ...)attempted-user 2011-0591 46209  URL
28626FILE-PDF Adobe Acrobat and Adobe Acrobat Reader U3D RHAdobeMeta buffer overflow attempt (more info ...)attempted-user 2009-1855 35282  URL
28627FILE-PDF Adobe Acrobat universal 3D format memory corruption attempt (more info ...)attempted-user 2011-0599   URL
28628FILE-PDF Adobe Acrobat universal 3D format memory corruption attempt (more info ...)attempted-user 2011-0599   URL
28631FILE-FLASH Adobe Flash Player embedded JPG image height overflow attempt (more info ...)attempted-user 2007-6242 26951  
28632FILE-FLASH Adobe Flash Player embedded JPG image height overflow attempt (more info ...)attempted-user 2007-6242 26951  
28633FILE-PDF Adobe Acrobat Universal 3D stream memory corruption attempt (more info ...)attempted-user 2011-0592 46210  URL
28634FILE-PDF Adobe Acrobat Reader CoolType.dll composite glyf buffer overflow attempt (more info ...)attempted-user 2011-2441 49581  URL
28635FILE-PDF Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt (more info ...)attempted-user 2011-2441 49581  URL
28636FILE-FLASH Adobe Flash Player multimedia file DefineSceneAndFrameLabelData code execution attempt (more info ...)attempted-user 2007-0071 28695  URL
28637FILE-FLASH Adobe Flash Player multimedia file DefineSceneAndFrameLabelData code execution attempt (more info ...)attempted-user 2007-0071 28695  URL
28638FILE-PDF Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt (more info ...)attempted-user 2011-2441 49581  URL
28639FILE-PDF Adobe Acrobat Reader CoolType.dll glyf directory table buffer overflow attempt (more info ...)attempted-user 2011-2441 49581  URL
28640FILE-FLASH RealNetworks RealPlayer SWF frame handling buffer overflow attempt (more info ...)attempted-user 2007-5400 30370  
28641FILE-FLASH RealNetworks RealPlayer SWF frame handling buffer overflow attempt (more info ...)attempted-user 2007-5400 30370  
28642FILE-PDF Adobe Acrobat TrueType font handling remote code execution attempt (more info ...)attempted-admin 2010-0195 39417  
28643FILE-PDF Adobe Acrobat TrueType font handling remote code execution attempt (more info ...)attempted-admin 2010-0195 39417  
28660FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user 2009-1862   
28661FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user 2009-1862   
28664FILE-FLASH RealNetworks RealPlayer SWF flash file buffer overflow attempt (more info ...)attempted-user 2006-0323 17202  
28665FILE-FLASH RealNetworks RealPlayer SWF flash file buffer overflow attempt (more info ...)attempted-user 2006-0323 17202  
28666FILE-FLASH RealNetworks RealPlayer SWF flash file buffer overflow attempt (more info ...)attempted-user 2006-0323 17202  
28667FILE-FLASH Adobe Flash ActionDefineFunction memory access exploit attempt (more info ...)attempted-user 2005-2628 15334  
28668FILE-FLASH Adobe Flash ActionDefineFunction memory access exploit attempt (more info ...)attempted-user 2005-2628 15334  
28669FILE-FLASH Adobe Flash ActionDefineFunction memory access exploit attempt (more info ...)attempted-user 2005-2628 15334  
28670FILE-FLASH Adobe Flash frame type identifier memory corruption attempt (more info ...)attempted-user 2005-2628 15332  
28671FILE-FLASH Adobe Flash frame type identifier memory corruption attempt (more info ...)attempted-user 2005-2628 15332  
28672FILE-FLASH Adobe Flash frame type identifier memory corruption attempt (more info ...)attempted-user 2005-2628 15332  
28673FILE-FLASH Adobe Flash Player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297 40586  
28674FILE-FLASH Adobe Flash Player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297 40586  
28675FILE-FLASH Adobe Flash Player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297 40586  
28676FILE-FLASH Adobe Flash Player newfunction memory corruption attempt (more info ...)attempted-user 2010-1297 40586  
28677FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28678FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28679FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28680FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28681FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28682FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28683FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28684FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28685FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28686FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
28691FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609 46860  
28692FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609 46860  
28693FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609 46860  
28694FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609 46860  
28700FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user 2013-0634 57787  URL
28709FILE-PDF Adobe Acrobat Universal 3D stream memory corruption attempt (more info ...)attempted-user 2011-0592 46210  URL
28716FILE-PDF Adobe Acrobat Reader compact font format memory corruption attempt (more info ...)attempted-user 2009-2985   
28717FILE-PDF Adobe Acrobat Reader compact font format memory corruption attempt (more info ...)attempted-user 2009-2985   
28718FILE-PDF Adobe Acrobat Reader memory corruption attempt (more info ...)attempted-user 2010-2202 41234  
28719FILE-PDF Adobe Acrobat Reader memory corruption attempt (more info ...)attempted-user 2010-2202 41234  
28720FILE-PDF Adobe Acrobat Reader memory corruption attempt (more info ...)attempted-user 2010-2202 41234  
28721FILE-PDF Adobe Acrobat Reader memory corruption attempt (more info ...)attempted-user 2010-2202 41234  
28725FILE-PDF Adobe Acrobat Reader ICC mluc integer overflow attempt (more info ...)attempted-user 2010-3622 43729  URL
28726FILE-PDF Adobe Acrobat Reader ICC mluc integer overflow attempt (more info ...)attempted-user 2010-3622 43729  URL
28727FILE-PDF Adobe Acrobat Reader ICC mluc integer overflow attempt (more info ...)attempted-user 2010-3622 43729  URL
28728FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28729FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28730FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28731FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28732FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28733FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28734FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28735FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28736FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28737FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28738FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28739FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28740FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28741FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28742FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28743FILE-PDF Adobe Acrobat Reader media.newPlayer memory corruption attempt (more info ...)attempted-user 2009-4324 37331  
28747FILE-PDF Adobe Acrobat Reader universal 3D format memory corruption attempt (more info ...)attempted-user 2011-0593 46211  URL
28748FILE-PDF Adobe Acrobat Reader universal 3D format memory corruption attempt (more info ...)attempted-user 2011-0593 46211  URL
28790FILE-PDF Adobe Acrobat Reader universal 3D stream memory corruption attempt (more info ...)attempted-user 2011-0592 46210  URL
29207FILE-OTHER RealNetworks RealPlayer RMP file heap buffer overflow attempt (more info ...)attempted-admin 2013-6877 64398  
29208FILE-OTHER RealNetworks RealPlayer RMP file heap buffer overflow attempt (more info ...)attempted-admin 2013-6877 64398  
29209FILE-OTHER RealNetworks RealPlayer RMP file heap buffer overflow attempt (more info ...)attempted-admin 2013-6877 64398  
29212FILE-OTHER RealNetworks RealPlayer RMP file heap buffer overflow attempt (more info ...)attempted-admin 2013-6877 64398  
29394BROWSER-WEBKIT Apple WebKit QuickTime plugin content-type http header buffer overflow attempt (more info ...)attempted-user 2012-3753   URL
29433FILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attempt (more info ...)attempted-user 2012-5679   URL
29434FILE-IMAGE Apple QuickTime PICT file overread buffer overflow attempt (more info ...)attempted-user 2008-1019 28583  
29435FILE-MULTIMEDIA Apple QuickTime pict image poly structure memory corruption attempt (more info ...)attempted-user 2009-0010 34938  
29436FILE-MULTIMEDIA Apple QuickTime pict image poly structure memory corruption attempt (more info ...)attempted-user 2009-0010 34938  
29444EXPLOIT-KIT Fiesta exploit kit flashplayer11 payload download (more info ...)trojan-activity    
29620FILE-IMAGE Adobe Photoshop malformed PNG detected tRNS overflow attempt (more info ...)attempted-user 2012-4170 18385  URL
29622FILE-PDF Adobe Acrobat Reader malformed shading modifier heap corruption attempt (more info ...)attempted-user 2011-2462   URL
29669FILE-PDF Adobe Acrobat Reader pattern object memory corruption attempt (more info ...)attempted-user 2014-0495 64803  URL
29932FILE-FLASH Adobe Flash Player PCRE regexp out of bounds memory leak ASLR bypass attempt (more info ...)attempted-user 2014-0499 65703  URL
29933FILE-FLASH Adobe Flash Player PCRE regexp out of bounds memory leak ASLR bypass attempt (more info ...)attempted-user 2014-0499 65703  URL
29934FILE-FLASH Adobe Flash regular expression grouping depth buffer overflow attempt (more info ...)attempted-user 2014-0499 65703  URL
30146FILE-FLASH Adobe Flash incorrect null uri character normalization attempt (more info ...)attempted-user 2014-0503   URL
30147FILE-FLASH Adobe Flash incorrect null uri character normalization attempt (more info ...)attempted-user 2014-0503   URL
30148FILE-FLASH Adobe Flash incorrect null uri character normalization attempt (more info ...)attempted-user 2014-0503   URL
30149FILE-FLASH Adobe Flash incorrect null uri character normalization attempt (more info ...)attempted-user 2014-0503   URL
30236FILE-PDF Adobe Acrobat Reader field flags exploit attempt (more info ...)attempted-user 2011-0589   URL
30347FILE-FLASH Adobe Flash Player JPEG parsing heap overflow attempt (more info ...)attempted-user 2009-3794   
30348FILE-FLASH Adobe Flash Player JPEG parsing heap overflow attempt (more info ...)attempted-user 2009-3794   
30349FILE-FLASH Adobe Flash Player JPEG parsing heap overflow attempt (more info ...)attempted-user 2009-3794   
30539FILE-FLASH Adobe Flash Player navigateToUrl hidden channel to file creation (more info ...)attempted-user 2014-0508   
30540FILE-FLASH Adobe Flash Player navigateToUrl hidden channel to file creation (more info ...)attempted-user 2014-0508   
30843FILE-FLASH Adobe Acrobat Reader cross-site scripting attempt (more info ...)attempted-user 2014-0509 66703  URL
30844FILE-FLASH Adobe Acrobat Reader cross-site scripting attempt (more info ...)attempted-user 2014-0509 66703  URL
31027FILE-OTHER Adobe Acrobat EMF conversion heap buffer overflow attempt (more info ...)attempted-user 2018-16021 67632  URL
31028FILE-OTHER Adobe Acrobat EMF conversion heap buffer overflow attempt (more info ...)attempted-user 2018-16021 67632  URL
31043BROWSER-PLUGINS Apple Quicktime ActiveX Control use after free (more info ...)attempted-user 2012-3754 56438  
31044BROWSER-PLUGINS Apple Quicktime ActiveX Control use after free (more info ...)attempted-user 2012-3754 56438  
31245FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user 2014-0520   URL
31246FILE-FLASH Adobe Flash malformed regular expression exploit attempt (more info ...)attempted-user 2014-0520   URL
31281FILE-FLASH Adobe Flash Player redirect attempt (more info ...)attempted-user 2014-0535 67970  URL
31282FILE-FLASH Adobe Flash Player redirect attempt (more info ...)attempted-user 2014-0535 67970  URL
31291FILE-PDF Adobe Acrobat Reader DynamicAnnotStore exploit attempt (more info ...)attempted-user 2014-0521   URL
31292FILE-PDF Adobe Acrobat Reader DynamicAnnotStore exploit attempt (more info ...)attempted-user 2014-0521   URL
31308FILE-MULTIMEDIA Apple QuickTime pict image poly structure memory corruption attempt (more info ...)attempted-user 2009-0010 34938  
31309FILE-MULTIMEDIA Apple QuickTime pict image poly structure memory corruption attempt (more info ...)attempted-user 2009-0010 34938  
31320BROWSER-PLUGINS Adobe Multiple Product AcroPDF.PDF ActiveX exploit attempt (more info ...)attempted-user 2005-0035 12989  URL
31321BROWSER-PLUGINS Adobe Multiple Product AcroPDF.PDF ActiveX exploit attempt (more info ...)attempted-user 2006-6027 21155  URL
31322BROWSER-PLUGINS Adobe Multiple Product AcroPDF.PDF ActiveX exploit attempt (more info ...)attempted-user 2005-0035 12989  URL
31376FILE-MULTIMEDIA RealNetworks RealPlayer mpeg width integer memory underflow attempt (more info ...)attempted-user 2011-4259 50741  
31392FILE-FLASH Adobe JSONP callback API vulnerability exploitation attempt (more info ...)attempted-user 2014-4671   URL
31393FILE-FLASH Adobe JSONP callback API vulnerability exploitation attempt (more info ...)attempted-user 2014-4671   URL
31394FILE-FLASH Adobe JSONP callback API vulnerability exploitation attempt (more info ...)attempted-user 2014-4671   URL
31395FILE-FLASH Adobe JSONP callback API vulnerability exploitation attempt (more info ...)attempted-user 2014-4671   URL
31396FILE-FLASH Adobe JSONP callback API vulnerability exploitation attempt (more info ...)attempted-user 2014-4671   URL
31397FILE-FLASH Adobe JSONP callback API vulnerability exploitation attempt (more info ...)attempted-user 2014-4671   URL
31399POLICY-OTHER Rosetta Flash tool use attempt (more info ...)policy-violation 2015-3096   URL
31400POLICY-OTHER Rosetta Flash tool use attempt (more info ...)policy-violation 2015-3096   URL
31401POLICY-OTHER Rosetta Flash tool use attempt (more info ...)policy-violation 2015-3096   URL
31407BROWSER-PLUGINS Adobe Reader 11 messageHandler ActiveX access attempt (more info ...)attempted-user 2014-0527   URL
31409BROWSER-PLUGINS Adobe Reader 11 messageHandler ActiveX access attempt (more info ...)attempted-user 2014-0527   URL
31411OS-WINDOWS Microsoft Windows Media Encoder wmerrorDAN.dll dll-load exploit attempt (more info ...)attempted-user 2010-3965 42855  URL
31412OS-WINDOWS Microsoft Windows Media Encoder winietDAN.dll dll-load exploit attempt (more info ...)attempted-user 2010-3965 42855  URL
31413OS-WINDOWS Microsoft Windows Media Encoder asferrorDAN.dll dll-load exploit attempt (more info ...)attempted-user 2010-3965 42855  URL
31414OS-WINDOWS Microsoft Windows Media Encoder wmerrorDAN.dll dll-load exploit attempt (more info ...)attempted-user 2010-3965 42855  URL
31415OS-WINDOWS Microsoft Windows Media Encoder winietDAN.dll dll-load exploit attempt (more info ...)attempted-user 2010-3965 42855  URL
31416OS-WINDOWS Microsoft Windows Media Encoder asferrorDAN.dll dll-load exploit attempt (more info ...)attempted-user 2010-3965 42855  URL
31439FILE-PDF Adobe Acrobat Reader Texture Declaration buffer overflow attempt (more info ...)attempted-user 2012-2049 55024  URL
31440FILE-PDF Adobe Acrobat Reader Texture Declaration buffer overflow attempt (more info ...)attempted-user 2012-2049 55024  URL
31489FILE-FLASH Adobe Flash Player security sandbox bypass attempt (more info ...)policy-violation 2014-0534 67963  URL
31490FILE-FLASH Adobe Flash Player security sandbox bypass attempt (more info ...)policy-violation 2014-0534 67963  URL
31491FILE-FLASH Adobe Flash Player security sandbox bypass attempt (more info ...)policy-violation 2014-0534 67963  URL
31492FILE-FLASH Adobe Flash Player security sandbox bypass attempt (more info ...)policy-violation 2014-0534 67963  URL
31493FILE-FLASH Adobe Flash Player security sandbox bypass attempt (more info ...)policy-violation 2014-0534 67963  URL
31494FILE-FLASH Adobe Flash Player security sandbox bypass attempt (more info ...)policy-violation 2014-0534 67963  URL
31549FILE-FLASH Adobe Flash Player feed scheme security sandbox bypass attempt (more info ...)policy-violation 2014-0539 68454  URL
31550FILE-FLASH Adobe Flash Player feed scheme security sandbox bypass attempt (more info ...)policy-violation 2014-0539 68454  URL
31551FILE-FLASH Adobe Flash Player pcast scheme security sandbox bypass attempt (more info ...)policy-violation 2014-0539 68454  URL
31552FILE-FLASH Adobe Flash Player feed scheme security sandbox bypass attempt (more info ...)policy-violation 2014-0539 68454  URL
31553FILE-FLASH Adobe Flash Player feed scheme security sandbox bypass attempt (more info ...)policy-violation 2014-0539 68454  URL
31554FILE-FLASH Adobe Flash Player pcast scheme security sandbox bypass attempt (more info ...)policy-violation 2014-0539 68454  URL
31587FILE-PDF Adobe Acrobat Reader XDP encoded download attempt (more info ...)misc-activity    URL
31614POLICY-OTHER Adobe Flash Player possible cross-domain bypass attempt (more info ...)policy-violation 2014-0537 68455  URL
31673FILE-FLASH Adobe Flash Player URL handling remote code execution attempt (more info ...)attempted-admin 2014-0541 69191  URL
31674FILE-FLASH Adobe Flash Broker write to junction exploit attempt (more info ...)attempted-user 2014-0520   URL
31675FILE-FLASH Adobe Flash Broker write to junction exploit attempt (more info ...)attempted-user 2014-0520   URL
31676FILE-FLASH Adobe Flash Broker write to junction exploit attempt (more info ...)attempted-user 2014-0520   URL
31677FILE-FLASH Adobe Flash Broker write to junction exploit attempt (more info ...)attempted-user 2014-0520   URL
31684FILE-FLASH Adobe Flash Player cross-origin security policy bypass attempt (more info ...)policy-violation 2014-0516 67361  URL
31685FILE-FLASH Adobe Flash Player cross-origin security policy bypass attempt (more info ...)policy-violation 2014-0516 67361  URL
31739FILE-FLASH Adobe Flash Player corrupt image memory leak (more info ...)attempted-user 2014-0545 69197  URL
31861FILE-FLASH Adobe Flash Player corrupt image memory leak (more info ...)attempted-user 2014-0542 69194  
31862FILE-FLASH Adobe Flash Player corrupt image memory leak (more info ...)attempted-user 2014-0542 69194  
32026FILE-FLASH Adobe Flash Player invalid TRCK frame attempt (more info ...)attempted-user 2014-0552 69703  URL
32027FILE-FLASH Adobe Flash Player invalid TRCK frame attempt (more info ...)attempted-user 2014-0552 69703  URL
32099FILE-OTHER Adobe Flash Player integer overflow out-of-bounds read attempt (more info ...)attempted-user 2014-0547 69695  
32100FILE-OTHER Adobe Flash Player integer overflow out-of-bounds read attempt (more info ...)attempted-user 2014-0547 69695  
32358FILE-PDF Adobe Acrobat Reader JpxDecode invalid crgn memory corruption attempt (more info ...)attempted-user 2009-3955 37757  
32626BROWSER-PLUGINS Adobe Flash broker privilege escalation file creation attempt (more info ...)attempted-user 2014-8442 71040  URL
32627BROWSER-PLUGINS Adobe Flash broker privilege escalation file creation attempt (more info ...)attempted-user 2014-8442 71040  URL
32638EXPLOIT-KIT Sweet Orange exploit kit Adobe Flash exploit on defined port (more info ...)trojan-activity    
32738FILE-MULTIMEDIA Apple QuickTime text track descriptors heap buffer overflow attempt (more info ...)attempted-user 2012-0664   
32739FILE-MULTIMEDIA Apple QuickTime text track descriptors heap buffer overflow attempt (more info ...)attempted-user 2012-0664   
32771MALWARE-OTHER Adobe Invoice email scam phishing attempt (more info ...)trojan-activity    URL
32772MALWARE-OTHER Adobe License Key email scam phishing attempt (more info ...)trojan-activity    URL
32797FILE-PDF Adobe Acrobat Reader XFA loadXML escape attempt (more info ...)policy-violation 2014-8452   URL
32798FILE-PDF Adobe Acrobat Reader XFA loadXML escape attempt (more info ...)policy-violation 2014-8452   URL
32799FILE-PDF Adobe Acrobat Reader XFA loadXML escape attempt (more info ...)policy-violation 2014-8452   URL
32800FILE-PDF Adobe Acrobat Reader XFA loadXML escape attempt (more info ...)policy-violation 2014-8452   URL
32806FILE-FLASH Adobe Flash Player regex buffer overflow attempt (more info ...)attempted-user 2014-9162   URL
32807FILE-FLASH Adobe Flash Player regex buffer overflow attempt (more info ...)attempted-user 2014-9162   URL
32808FILE-FLASH Adobe Flash Player regex buffer overflow attempt (more info ...)attempted-user 2014-9162   URL
32809FILE-FLASH Adobe Flash Player regex buffer overflow attempt (more info ...)attempted-user 2014-9162   URL
32810FILE-FLASH Adobe Flash Player regex buffer overflow attempt (more info ...)attempted-user 2014-9162   URL
32811FILE-FLASH Adobe Flash Player regex buffer overflow attempt (more info ...)attempted-user 2014-9162   URL
32812FILE-FLASH Adobe Flash Player regex buffer overflow attempt (more info ...)attempted-user 2014-9162   URL
32817FILE-FLASH Adobe Flash Player corrupt MP4 video denial of service attempt (more info ...)attempted-dos 2015-5578 69707  URL
32818FILE-FLASH Adobe Flash Player corrupt MP4 video denial of service attempt (more info ...)attempted-dos 2015-5578 69707  URL
32838FILE-PDF Adobe Acrobat Reader ANTrustPropgateAll privilege propagation attempt (more info ...)attempted-user 2014-8451   URL
32839FILE-PDF Adobe Acrobat Reader ANTrustPropgateAll privilege propagation attempt (more info ...)attempted-user 2014-8451   URL
32867FILE-PDF Adobe Acrobat Reader resampling invalid graphic matrix value attempt (more info ...)attempted-user 2014-9159   URL
32868FILE-PDF Adobe Acrobat Reader resampling invalid graphic matrix value attempt (more info ...)attempted-user 2014-9159   URL
32883FILE-OTHER Adobe Reader MoveFileEx arbitrary file write attempt (more info ...)misc-attack 2014-9150   URL
32884FILE-OTHER Adobe Reader MoveFileEx arbitrary file write attempt (more info ...)misc-attack 2014-9150   URL
32898FILE-MULTIMEDIA Quicktime MJPEG Frame stsd Atom Heap Overflow attempt (more info ...)attempted-user 2013-1020   
32899FILE-MULTIMEDIA Quicktime MJPEG Frame stsd Atom Heap Overflow attempt (more info ...)attempted-user 2013-1020   
32900FILE-FLASH Adobe Flash pepper player 307 redirect custom header cross domain policy evasion attempt (more info ...)attempted-user 2014-0580   
33023FILE-OTHER Apple Quicktime invalid rdrf atom length buffer overflow attempt (more info ...)attempted-admin 2013-1017 60097  URL
33159FILE-FLASH Adobe Flash Player AVM2 opcode type confusion denial of service attempt (more info ...)attempted-dos 2014-0590   URL
33160FILE-FLASH Adobe Flash Player AVM2 opcode type confusion denial of service attempt (more info ...)attempted-dos 2014-0590   URL
33164FILE-FLASH Adobe Flash Player RTMP out-of-bounds read attempt (more info ...)attempted-user 2014-0549 69699  URL
33213FILE-PDF Adobe Acrobat Reader newfunction memory corruption attempt (more info ...)attempted-user 2010-2168   URL
33214FILE-PDF Adobe Acrobat Reader newfunction memory corruption attempt (more info ...)attempted-user 2010-2168   URL
33295FILE-FLASH Adobe Flash Player sound object heap buffer overflow attempt (more info ...)attempted-user 2015-0304   URL
33296FILE-FLASH Adobe Flash Player sound object heap buffer overflow attempt (more info ...)attempted-user 2015-0304   URL
33297FILE-FLASH Adobe Flash Player sound object heap buffer overflow attempt (more info ...)attempted-user 2015-0304   URL
33298FILE-FLASH Adobe Flash Player sound object heap buffer overflow attempt (more info ...)attempted-user 2015-0304   URL
33475FILE-FLASH Adobe Flash Player byte array use after free attempt (more info ...)attempted-user 2015-0312   URL
33476FILE-FLASH Adobe Flash Player byte array use after free attempt (more info ...)attempted-user 2015-0312   URL
33477FILE-FLASH Adobe Flash Player byte array use after free attempt (more info ...)attempted-user 2015-0312   URL
33478FILE-FLASH Adobe Flash Player byte array use after free attempt (more info ...)attempted-user 2015-0312   URL
33527FILE-FLASH Adobe Flash Player PCRE library out of bounds memory access attempt (more info ...)denial-of-service 2015-0316   URL
33528FILE-FLASH Adobe Flash Player PCRE library out of bounds memory access attempt (more info ...)denial-of-service 2015-0316   URL
33529FILE-FLASH Adobe Flash Player PCRE library out of bounds memory access attempt (more info ...)denial-of-service 2015-0316   URL
33530FILE-FLASH Adobe Flash Player PCRE library out of bounds memory access attempt (more info ...)denial-of-service 2015-0316   URL
33549FILE-FLASH Adobe Flash Player addHeader null pointer dereference attempt (more info ...)denial-of-service 2015-0328   URL
33550FILE-FLASH Adobe Flash Player addHeader null pointer dereference attempt (more info ...)denial-of-service 2015-0328   URL
33551FILE-FLASH Adobe Flash Player addHeader null pointer dereference attempt (more info ...)denial-of-service 2015-0328   URL
33552FILE-FLASH Adobe Flash Player addHeader null pointer dereference attempt (more info ...)denial-of-service 2015-0328   URL
33575FILE-MULTIMEDIA Apple QuickTime STSD JPEG atom heap corruption attempt (more info ...)attempted-user 2009-0007 33390  
33577FILE-MULTIMEDIA Apple QuickTime STSD JPEG atom heap corruption attempt (more info ...)attempted-user 2009-0007 33390  
33578FILE-MULTIMEDIA Apple QuickTime STSD JPEG atom heap corruption attempt (more info ...)attempted-user 2009-0007 33390  
33584FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
33585FILE-FLASH Adobe Flash Player ASnative command execution attempt (more info ...)attempted-user 2008-5499 32896  URL
33586FILE-MULTIMEDIA Apple QuickTime Image Description Atom sign extension memory corruption attempt (more info ...)attempted-user 2009-0955 35166  URL
33589FILE-IMAGE Adobe Photoshop CS4 TIFF parsing heap overflow attempt (more info ...)attempted-user 2017-3028   URL
33590FILE-IMAGE Adobe Photoshop CS4 TIFF parsing heap overflow attempt (more info ...)attempted-user 2017-3028   URL
33591FILE-IMAGE Adobe Photoshop CS4 TIFF parsing heap overflow attempt (more info ...)attempted-user 2012-2027   URL
33592FILE-OTHER Adobe Shockwave Player SwDir.dll PlayerVersion Buffer Overflow attempt (more info ...)attempted-user 2009-3244 36905  URL
33593FILE-OTHER Adobe Shockwave Player SwDir.dll PlayerVersion Buffer Overflow attempt (more info ...)attempted-user 2009-3244 36905  URL
33615FILE-IMAGE Adobe Photoshop CS5 gif file heap corruption attempt (more info ...)attempted-user 2011-2131 49106  
33634FILE-FLASH Adobe Flash Player decompressing denial of service attempt (more info ...)attempted-dos 2010-0187   
33635FILE-FLASH Adobe Flash Player decompressing denial of service attempt (more info ...)attempted-dos 2010-0187   
33824FILE-FLASH Adobe Flash Player memory corruption attempt (more info ...)attempted-user 2011-0609   URL
33908FILE-PDF Adobe Acrobat Reader CoolType.dll out-of-bounds memory write access attempt (more info ...)attempted-user 2014-9160   
33909FILE-PDF Adobe Acrobat Reader CoolType.dll out-of-bounds memory write access attempt (more info ...)attempted-user 2014-9160   
33971FILE-FLASH Adobe Flash Player cross domain policy bypass attempt (more info ...)attempted-user 2015-0340   
33972FILE-FLASH Adobe Flash Player cross domain policy bypass attempt (more info ...)attempted-user 2015-0340   
33973FILE-FLASH Adobe Flash Player compressed file cross domain policy bypass attempt (more info ...)attempted-user 2015-0340   
33974FILE-FLASH Adobe Flash Player compressed file cross domain policy bypass attempt (more info ...)attempted-user 2015-0340   
34147FILE-FLASH Adobe Flash Player ConvolutionFilter heap information disclosure attempt (more info ...)attempted-user 2015-0357   URL
34148FILE-FLASH Adobe Flash Player ConvolutionFilter heap information disclosure attempt (more info ...)attempted-user 2015-0357   URL
34149FILE-FLASH Adobe Flash Player ConvolutionFilter heap information disclosure attempt (more info ...)attempted-user 2015-0357   URL
34150FILE-FLASH Adobe Flash Player ConvolutionFilter heap information disclosure attempt (more info ...)attempted-user 2015-0357   URL
34176FILE-FLASH Adobe Flash Player domain security bypass attempt (more info ...)attempted-user 2015-3044   URL
34177FILE-FLASH Adobe Flash Player domain security bypass attempt (more info ...)attempted-user 2015-3044   URL
34232FILE-FLASH Adobe Flash Player potential information disclosure attempt (more info ...)attempted-user 2015-3040   URL
34233FILE-FLASH Adobe Flash Player potential information disclosure attempt (more info ...)attempted-user 2015-3040   URL
34234FILE-FLASH Adobe Flash Player potential information disclosure attempt (more info ...)attempted-user 2015-3040   URL
34235FILE-FLASH Adobe Flash Player potential information disclosure attempt (more info ...)attempted-user 2015-3040   URL
34253FILE-FLASH Adobe Flash Player malformed CEA-708 packet denial of service attempt (more info ...)attempted-dos 2015-0354   URL
34254FILE-FLASH Adobe Flash Player malformed CEA-708 packet denial of service attempt (more info ...)attempted-dos 2015-0354   URL
34334EXPLOIT-KIT Fiesta exploit kit Adobe Reader exploit download (more info ...)trojan-activity    
34528FILE-PDF Adobe Acrobat Reader AVDoc use-after-free attempt (more info ...)attempted-admin 2015-3055   URL
34529FILE-PDF Adobe Acrobat Reader AVDoc use-after-free attempt (more info ...)attempted-admin 2015-3055   URL
34532FILE-PDF Adobe Acrobat Reader customDictionaryExport information disclosure attempt (more info ...)attempted-recon 2015-3058   URL
34533FILE-PDF Adobe Acrobat Reader customDictionaryExport information disclosure attempt (more info ...)attempted-recon 2015-3058   URL
34534FILE-PDF Adobe Acrobat Reader PRC invalid index attempt (more info ...)attempted-user 2015-3047   URL
34535FILE-PDF Adobe Acrobat Reader PRC invalid index attempt (more info ...)attempted-user 2015-3047   URL
34536FILE-FLASH Adobe Flash Player ByteArray shading memory leak attempt (more info ...)attempted-recon 2015-3091   
34537FILE-FLASH Adobe Flash Player ByteArray shading memory leak attempt (more info ...)attempted-recon 2015-3091   
34573FILE-FLASH Adobe Flash Player BrokerMoveFileEx sandbox escape attempt (more info ...)attempted-admin 2015-3081   URL
34574FILE-FLASH Adobe Flash Player BrokerMoveFileEx sandbox escape attempt (more info ...)attempted-admin 2015-3081   URL
34575FILE-FLASH Adobe Flash Player BrokerMoveFileEx sandbox escape attempt (more info ...)attempted-admin 2015-3081   URL
34576FILE-FLASH Adobe Flash Player BrokerMoveFileEx sandbox escape attempt (more info ...)attempted-admin 2015-3081   URL
34577FILE-FLASH Adobe Flash Player uninitialized register memory leak attempt (more info ...)attempted-recon 2015-3092 74617  URL
34578FILE-FLASH Adobe Flash Player uninitialized register memory leak attempt (more info ...)attempted-recon 2015-3092 74617  URL
34579FILE-FLASH Adobe Flash Player uninitialized register memory leak attempt (more info ...)attempted-recon 2015-3092 74617  URL
34580FILE-FLASH Adobe Flash Player uninitialized register memory leak attempt (more info ...)attempted-recon 2015-3092 74617  URL
34585FILE-FLASH Adobe Flash Player BrokerMoveFileEx sandbox escape attempt (more info ...)attempted-admin 2015-3081   URL
34586FILE-FLASH Adobe Flash Player BrokerMoveFileEx sandbox escape attempt (more info ...)attempted-admin 2015-3083   URL
34587FILE-FLASH Adobe Flash Player BrokerMoveFileEx sandbox escape attempt (more info ...)attempted-admin 2015-3081   URL
34588FILE-FLASH Adobe Flash Player BrokerMoveFileEx sandbox escape attempt (more info ...)attempted-admin 2015-3081   URL
34811FILE-FLASH Adobe Flash Player assumed trust URI reference to child file attempt (more info ...)attempted-user 2015-3098   URL
34812FILE-FLASH Adobe Flash Player Security.allowDomain cross domain policy bypass attempt (more info ...)policy-violation 2015-3099   URL
34813FILE-FLASH Adobe Flash Player Security.allowDomain cross domain policy bypass attempt (more info ...)policy-violation 2015-3099   URL
34814FILE-FLASH Adobe Flash Player Security.allowDomain cross domain policy bypass attempt (more info ...)policy-violation 2015-3099   URL
34815FILE-FLASH Adobe Flash Player Security.allowDomain cross domain policy bypass attempt (more info ...)policy-violation 2015-3099   URL
34836FILE-FLASH Adobe Flash Player invalid URL encoding exploit attempt (more info ...)attempted-user 2015-3102   URL
34837FILE-FLASH Adobe Flash Player invalid URL encoding exploit attempt (more info ...)attempted-user 2015-3102   URL
34838FILE-FLASH Adobe Flash Player invalid URL encoding exploit attempt (more info ...)attempted-user 2015-3102   URL
34839FILE-FLASH Adobe Flash Player invalid URL encoding exploit attempt (more info ...)attempted-user 2015-3102   URL
34858FILE-FLASH Adobe Flash Player BitmapData shader bit information disclosure attempt (more info ...)misc-attack 2015-3108   URL
34859FILE-FLASH Adobe Flash Player BitmapData shader bit information disclosure attempt (more info ...)misc-attack 2015-3108   URL
34860FILE-FLASH Adobe Flash Player BitmapData shader bit information disclosure attempt (more info ...)misc-attack 2015-3108   URL
34861FILE-FLASH Adobe Flash Player BitmapData shader bit information disclosure attempt (more info ...)misc-attack 2015-3108   URL
34992MALWARE-OTHER Adobe Flash exploit download attempt - Group 6 (more info ...)trojan-activity    URL
35022FILE-MULTIMEDIA Apple Quicktime corrupt stbl atom out of bounds read attempt (more info ...)attempted-user 2015-3667   URL
35023FILE-MULTIMEDIA Apple Quicktime corrupt stbl atom out of bounds read attempt (more info ...)attempted-user 2015-3667   URL
35282FILE-FLASH Adobe Flash Player cross-site information disclosure attempt (more info ...)attempted-user 2014-0578   URL
35283FILE-FLASH Adobe Flash Player cross-site information disclosure attempt (more info ...)attempted-user 2014-0578   URL
35284FILE-FLASH Adobe Flash Player cross-site information disclosure attempt (more info ...)attempted-user 2014-0578   URL
35285FILE-FLASH Adobe Flash Player cross-site information disclosure attempt (more info ...)attempted-user 2014-0578   URL
35286FILE-FLASH Adobe Flash Player universal allowDomain command proxying attempt (more info ...)policy-violation 2015-3116   URL
35287FILE-FLASH Adobe Flash Player universal allowDomain command proxying attempt (more info ...)policy-violation 2015-3116   URL
35288FILE-FLASH Adobe Flash Player universal allowDomain command proxying attempt (more info ...)policy-violation 2015-3116   URL
35289FILE-FLASH Adobe Flash Player universal allowDomain command proxying attempt (more info ...)policy-violation 2015-3116   URL
35333EXPLOIT-KIT Angler exploit kit Flash download attempt (more info ...)attempted-user    
35334EXPLOIT-KIT Angler exploit kit Flash download attempt (more info ...)attempted-user    
35335EXPLOIT-KIT Angler exploit kit Flash download attempt (more info ...)attempted-user    
35376FILE-FLASH Adobe Flash Player cross-site file download attempt (more info ...)attempted-user 2015-3114   URL
35377FILE-FLASH Adobe Flash Player cross-site file download attempt (more info ...)attempted-user 2015-3114   URL
35378FILE-FLASH Adobe Flash Player cross-site file download attempt (more info ...)attempted-user 2015-3114   URL
35379FILE-FLASH Adobe Flash Player cross-site file download attempt (more info ...)attempted-user 2015-3114   URL
35542EXPLOIT-KIT Nuclear exploit kit flash exploit download attempt (more info ...)attempted-user    
35543FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user    
35544FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user    
35545FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user    
35546FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user    
35547FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user    
35548FILE-FLASH Adobe Flash Player remote code execution attempt (more info ...)attempted-user    
35560FILE-MULTIMEDIA Apple QuickTime invalid stsd atom out of bounds read attempt (more info ...)attempted-user 2015-3789 26341  URL
35561FILE-MULTIMEDIA Apple QuickTime mdat atom corruption out of bounds read attempt (more info ...)attempted-user 2015-3792   URL
35562FILE-MULTIMEDIA Apple QuickTime mdat atom corruption out of bounds read attempt (more info ...)attempted-user 2015-3792   URL
35563FILE-MULTIMEDIA Apple QuickTime esds atom buffer overread attempt (more info ...)attempted-user 2015-3791   URL
35564FILE-MULTIMEDIA Apple QuickTime esds atom buffer overread attempt (more info ...)attempted-user 2015-3791   URL
35567FILE-MULTIMEDIA Apple QuickTime invalid mvhd atom size out of bounds read attempt (more info ...)attempted-user 2015-3790   URL
35568FILE-MULTIMEDIA Apple QuickTime invalid mvhd atom size out of bounds read attempt (more info ...)attempted-user 2015-3790   URL
35628FILE-MULTIMEDIA Apple QuickTime tkhd atom matrix integer overflow attempt (more info ...)attempted-user 2015-5786   URL
35629FILE-MULTIMEDIA Apple QuickTime tkhd atom matrix integer overflow attempt (more info ...)attempted-user 2015-5786   URL
35636FILE-FLASH Adobe Flash invalid swf tag parsing buffer overflow attempt (more info ...)attempted-dos 2015-5132   
35637FILE-FLASH Adobe Flash invalid swf tag parsing buffer overflow attempt (more info ...)attempted-dos 2015-5132   
35638FILE-FLASH Adobe Flash Player childNodes XML object use after free attempt (more info ...)attempted-user 2015-5540   
35639FILE-FLASH Adobe Flash Player childNodes XML object use after free attempt (more info ...)attempted-user 2015-5540   
35640FILE-FLASH Adobe Flash Player childNodes XML object after free attempt (more info ...)attempted-user 2015-5540   
35641FILE-FLASH Adobe Flash Player childNodes XML object use after free attempt (more info ...)attempted-user 2015-5540   
35664FILE-FLASH Adobe Flash Player DefineVideoStream out of bounds memory access attempt (more info ...)attempted-user 2015-5552   URL
35665FILE-FLASH Adobe Flash Player DefineVideoStream out of bounds memory access attempt (more info ...)attempted-user 2015-5552   URL
35757FILE-PDF Adobe Reader exclGroup element null pointer dereference attempt (more info ...)attempted-user 2015-4443   URL
35758FILE-PDF Adobe Reader exclGroup element null pointer dereference attempt (more info ...)attempted-user 2015-4443   URL
35781FILE-PDF Adobe Acrobat Reader privileged method protection bypass attempt (more info ...)attempted-user 2015-4452   URL
35782FILE-PDF Adobe Acrobat Reader privileged method protection bypass attempt (more info ...)attempted-user 2015-4452   URL
35784FILE-PDF Adobe Reader AcroForm null pointer dereference attempt (more info ...)attempted-user 2015-4444   
35785FILE-PDF Adobe Reader AcroForm null pointer dereference attempt (more info ...)attempted-user 2015-4444   
35786FILE-PDF Adobe Acrobat Reader trusted function privilege escalation attempt (more info ...)attempted-user 2015-4451   URL
35787FILE-PDF Adobe Acrobat Reader trusted function privilege escalation attempt (more info ...)attempted-user 2015-4451   URL
35805FILE-EXECUTABLE Adobe Reader NtSetInformationFile privilege escalation attempt (more info ...)attempted-user 2015-4446   URL
35806FILE-EXECUTABLE Adobe Reader NtSetInformationFile privilege escalation attempt (more info ...)attempted-user 2015-4446   URL
35807FILE-PDF Adobe Reader validation bypass privilege escalation attempt (more info ...)attempted-admin 2015-5090   URL
35808FILE-PDF Adobe Reader validation bypass privilege escalation attempt (more info ...)attempted-admin 2015-5090   URL
35820FILE-FLASH Adobe Flash Player scale9Grid use after free attempt (more info ...)attempted-user 2015-5564   
35859FILE-MULTIMEDIA Apple QuickTime traf atom out of bounds read attempt (more info ...)attempted-user 2015-3668   URL
35860FILE-MULTIMEDIA Apple QuickTime traf atom out of bounds read attempt (more info ...)attempted-user 2015-3668   URL
35979FILE-IDENTIFY Windows Media Center link file download request (more info ...)misc-activity    
35980FILE-IDENTIFY Windows Media Center link file attachment detected (more info ...)misc-activity    
35981FILE-IDENTIFY Windows Media Center link file attachment detected (more info ...)misc-activity    
36034FILE-FLASH Infinity popup toolkit detected (more info ...)policy-violation    URL
36035FILE-FLASH Infinity popup toolkit detected (more info ...)policy-violation    URL
36036INDICATOR-OBFUSCATION Adobe Flash file with SecureSwfLoader packer detected (more info ...)policy-violation    URL
36062FILE-PDF Adobe Reader makeMeasurement information disclosure attempt (more info ...)attempted-recon 2015-5107   URL
36063FILE-PDF Adobe Reader makeMeasurement information disclosure attempt (more info ...)attempted-recon 2015-5107   URL
36191FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user 2013-2729 59918  URL
36192FILE-PDF Adobe Acrobat Reader X XML forms specially crafted RLE8 format BMP integer overflow attempt (more info ...)attempted-user 2013-2729 59918  URL
36316FILE-FLASH Adobe Flash Player URI loaded MP4 potential information leak attempt (more info ...)policy-violation 2016-1096   URL
36317FILE-FLASH Adobe Flash Player URI loaded FLV potential information leak attempt (more info ...)policy-violation 2015-5575   URL
36476FILE-FLASH Adobe Flash Player same orgin policy bypass attempt (more info ...)attempted-user 2015-6679   URL
36477FILE-FLASH Adobe Flash Player same orgin policy bypass attempt (more info ...)attempted-user 2015-6679   URL
36478FILE-FLASH Adobe Flash Player same orgin policy bypass attempt (more info ...)attempted-user 2015-6679   URL
36479FILE-FLASH Adobe Flash Player same orgin policy bypass attempt (more info ...)attempted-user 2015-6679   URL
36495BROWSER-PLUGINS RealNetworks RealPlayer Import ActiveX clsid access attempt (more info ...)attempted-user 2008-3066 30379  
36496BROWSER-PLUGINS RealNetworks RealPlayer Import ActiveX clsid access attempt (more info ...)attempted-user 2008-3066 30379  
36606FILE-FLASH Adobe Flash Player NavigatetoURL new tab open attempt (more info ...)policy-violation 2015-7628   URL
36607FILE-FLASH Adobe Flash Player NavigatetoURL new tab open attempt (more info ...)policy-violation 2015-7628   URL
36608FILE-FLASH Adobe Flash Player NavigatetoURL new tab open attempt (more info ...)policy-violation 2015-7628   URL
36609FILE-FLASH Adobe Flash Player NavigatetoURL new tab open attempt (more info ...)policy-violation 2015-7628   URL
36972FILE-OTHER Windows Media Player MCL to HTML information disclosure attempt (more info ...)attempted-recon 2015-6127   URL
36973FILE-OTHER Windows Media Player MCL to HTML information disclosure attempt (more info ...)attempted-recon 2015-6127   URL
37314FILE-PDF Adobe Acrobat Reader privileged method protection bypass attempt (more info ...)policy-violation 2015-5085   URL
37315FILE-PDF Adobe Acrobat Reader privileged method protection bypass attempt (more info ...)policy-violation 2015-5085   URL
37329FILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attempt (more info ...)attempted-user 2012-5679   URL
37331FILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attempt (more info ...)attempted-user 2012-5679   URL
37332FILE-IMAGE Adobe Camera Raw Plug-in TIFF image processing buffer underflow attempt (more info ...)attempted-user 2012-5679   URL
37431FILE-PDF Adobe Acrobat Reader ExtGState use after free attempt (more info ...)attempted-user 2016-0934   URL
37432FILE-PDF Adobe Acrobat Reader ExtGState use after free attempt (more info ...)attempted-user 2016-0934   URL
37672FILE-FLASH Adobe Flash Player heap object address enumeration technique (more info ...)attempted-user 2015-3113   URL
37673FILE-FLASH Adobe Flash Player heap object address enumeration technique (more info ...)attempted-user 2015-3113   URL
37690FILE-FLASH Adobe Flash Player invalid object reference code execution attempt (more info ...)attempted-user 2009-0520 33880  URL
37712FILE-PDF Adobe Acrobat and Adobe Acrobat Reader U3D RHAdobeMeta buffer overflow attempt (more info ...)attempted-user 2009-1855 35282  URL
37729INDICATOR-OBFUSCATION Adobe Flash file with SecureSwfLoader packer detected (more info ...)policy-violation    URL
37849FILE-FLASH Adobe Flash file with embedded PE detected (more info ...)misc-activity    
37850FILE-FLASH Adobe Flash file with embedded PE detected (more info ...)misc-activity    
37910FILE-PDF Adobe Acrobat and Reader U3D Buffer Overflow buffer overflow attempt (more info ...)attempted-user 2009-2997   URL
37911FILE-PDF Adobe Acrobat and Reader U3D Buffer Overflow buffer overflow attempt (more info ...)attempted-user 2009-2997   URL
37953SERVER-WEBAPP Adobe RoboHelp rx cross site scripting attempt (more info ...)attempted-user 2008-2991 30137  URL
37959FILE-MULTIMEDIA Apple iTunes PLS file parsing buffer overflow attempt (more info ...)attempted-user 2009-2817 36478  
38020FILE-FLASH Adobe Flash file with CreateFileA shellcode (more info ...)attempted-user 2015-3113   URL
38021FILE-FLASH Adobe Flash file with large DefineBinaryData tag (more info ...)policy-violation 2015-3113   URL
38023FILE-FLASH Adobe Flash file CreateFileA shellcode found (more info ...)attempted-user 2015-3113   URL
38024FILE-FLASH Adobe Flash file with large DefineBinaryData tag (more info ...)policy-violation 2015-3113   URL
38025FILE-FLASH Adobe Flash file with large DefineBinaryData tag (more info ...)policy-violation 2015-3113   URL
38026FILE-FLASH Adobe Flash file with RC4 decryption routine detected (more info ...)policy-violation    
38141BROWSER-PLUGINS Microsoft Windows Media Player ActiveX unknown compression algorithm use after free attempt (more info ...)attempted-user 2010-0268   URL
38142BROWSER-PLUGINS Microsoft Windows Media Player ActiveX unknown compression algorithm use after free attempt (more info ...)attempted-user 2010-0268   URL
38143BROWSER-PLUGINS Microsoft Windows Media Player ActiveX unknown compression algorithm use after free attempt (more info ...)attempted-user 2010-0268   URL
38144BROWSER-PLUGINS Microsoft Windows Media Player ActiveX unknown compression algorithm use after free attempt (more info ...)attempted-user 2010-0268   URL
38172FILE-OTHER Adobe Acrobat updaternotifications.dll dll-load exploit attempt (more info ...)attempted-user 2016-1008   URL
38897FILE-OTHER Adobe Illustrator CS4 request for aires.dll over SMB attempt (more info ...)attempted-user 2010-3152   
38898FILE-OTHER Adobe Illustrator CS4 aires.dll dll-load exploit attempt (more info ...)attempted-user 2010-3152   URL
39081EXPLOIT-KIT Neutrino Exploit Kit Flash exploit download attempt (more info ...)trojan-activity    URL
39100FILE-PDF Adobe Reader Universal 3D engine out of bounds memory access violation attempt (more info ...)attempted-user 2016-1071   URL
39108FILE-PDF Adobe Acrobat Reader getAnnots exploit attempt (more info ...)attempted-user 2009-1492 34736  
39109FILE-PDF Adobe Acrobat Reader getAnnots exploit attempt (more info ...)attempted-user 2009-1492 34736  
39262FILE-FLASH Adobe Flash Player unhandled recursion limit out of bounds read attempt (more info ...)attempted-user 2016-4132   URL
39263FILE-FLASH Adobe Flash Player unhandled recursion limit out of bounds read attempt (more info ...)attempted-user 2016-4132   URL
39264FILE-FLASH Adobe Flash Player unhandled recursion limit out of bounds read attempt (more info ...)attempted-user 2016-4132   URL
39265FILE-FLASH Adobe Flash Player unhandled recursion limit out of bounds read attempt (more info ...)attempted-user 2016-4132   URL
39316FILE-FLASH Adobe Flash Player MovieClip object use-after-free attempt (more info ...)attempted-user 2016-4146   URL
39556FILE-PDF Adobe Acrobat Reader PostScript font parsing memory corruption attempt (more info ...)attempted-user 2016-4251   URL
39669FILE-PDF Adobe Reader submitForm SOP bypass attempt (more info ...)policy-violation 2016-4215   URL
39670FILE-PDF Adobe Reader submitForm SOP bypass attempt (more info ...)policy-violation 2016-4215   URL
40161FILE-FLASH Adobe Flash Player navigatetoURL sandbox escape attempt (more info ...)attempted-admin 2016-4277   URL
40162FILE-FLASH Adobe Flash Player navigatetoURL sandbox escape attempt (more info ...)attempted-admin 2016-4277   URL
40163FILE-FLASH Adobe Flash Player navigatetoURL sandbox escape attempt (more info ...)attempted-admin 2016-4277   URL
40164FILE-FLASH Adobe Flash Player navigatetoURL sandbox escape attempt (more info ...)attempted-admin 2016-4277   URL
40165FILE-FLASH Adobe Flash Player navigatetoURL sandbox escape attempt (more info ...)attempted-admin 2016-4277   URL
40170FILE-FLASH Adobe Standalone Flash Player use after free attempt (more info ...)attempted-admin 2016-4279   URL
40171FILE-FLASH Adobe Standalone Flash Player use after free attempt (more info ...)attempted-admin 2016-4279   URL
40172FILE-FLASH Adobe Standalone Flash Player out of bounds memory access attempt (more info ...)attempted-admin 2016-4282   
40173FILE-FLASH Adobe Standalone Flash Player out of bounds memory access attempt (more info ...)attempted-admin 2016-4282   
40174FILE-FLASH Adobe Flash Player out of bounds memory access attempt (more info ...)attempted-admin 2016-4281   
40175FILE-FLASH Adobe Flash Player out of bounds memory access attempt (more info ...)attempted-admin 2016-4281   
40324SERVER-OTHER Adobe ColdFusion default credential login attempt (more info ...)default-login-attempt    URL
40325SERVER-OTHER Adobe ColdFusion default credential login attempt (more info ...)default-login-attempt    URL
40327SERVER-OTHER Adobe ColdFusion fckeditor arbitrary file upload (more info ...)attempted-admin    
40354OS-WINDOWS Microsoft Windows Media Runtime malformed ASF codec memory corruption attempt (more info ...)attempted-user 2009-2525   URL
40434FILE-FLASH Adobe Flash Player malformed ActionConstantPool memory corruption attempt (more info ...)attempted-user 2016-4273   URL
41204FILE-PDF Adobe Reader XSL type confusion attempt (more info ...)attempted-user 2017-2962   URL
41205FILE-PDF Adobe Reader XSL type confusion attempt (more info ...)attempted-user 2017-2962   URL
41207FILE-FLASH Adobe Flash Player malformed PlaceObject3 memory corruption attempt (more info ...)attempted-user 2017-2931   URL
41208FILE-FLASH Adobe Flash Player malformed PlaceObject3 memory corruption attempt (more info ...)attempted-user 2017-2931   URL
41298FILE-IMAGE Adobe Acrobat Reader jpeg decoding heap buffer overflow attempt (more info ...)attempted-user 2017-2971   URL
41299FILE-IMAGE Adobe Acrobat Reader jpeg decoding heap buffer overflow attempt (more info ...)attempted-user 2017-2971   URL
41300FILE-IMAGE Adobe Acrobat Reader jpeg decoding heap buffer overflow attempt (more info ...)attempted-user 2017-2971   URL
41301FILE-IMAGE Adobe Acrobat Reader jpeg decoding heap buffer overflow attempt (more info ...)attempted-user 2017-2971   URL
41302FILE-IMAGE Adobe Acrobat Reader jpeg decoding heap buffer overflow attempt (more info ...)attempted-user 2017-2971   URL
41303FILE-IMAGE Adobe Acrobat Reader jpeg decoding heap buffer overflow attempt (more info ...)attempted-user 2017-2971   URL
41304FILE-IMAGE Adobe Acrobat Reader jpeg decoding heap buffer overflow attempt (more info ...)attempted-user 2017-2971   URL
41305FILE-IMAGE Adobe Acrobat Reader jpeg decoding heap buffer overflow attempt (more info ...)attempted-user 2017-2971   URL
41321FILE-PDF Adobe Acrobat Pro zoom caching use after free attempt (more info ...)attempted-admin 2016-6971   URL
41322FILE-PDF Adobe Acrobat Pro zoom caching use after free attempt (more info ...)attempted-admin 2016-6971   URL
41323FILE-PDF Adobe Reader JPEG 2000 COD marker use after free attempt (more info ...)attempted-admin 2016-6955   URL
41324FILE-PDF Adobe Reader JPEG 2000 COD marker use after free attempt (more info ...)attempted-admin 2016-6955   URL
41411FILE-FLASH Adobe Flash Player custom toString function attempt (more info ...)attempted-user 2017-2951   URL
41416FILE-PDF Adobe Acrobat Reader image cache use after free attempt (more info ...)attempted-user 2014-0528   URL
41417FILE-PDF Adobe Acrobat Reader image cache use after free attempt (more info ...)attempted-user 2014-0528   URL
41603FILE-FLASH Adobe Flash player BitmapData class use after free attempt (more info ...)attempted-user 2017-2985   URL
41604FILE-FLASH Adobe Flash player BitmapData class use after free attempt (more info ...)attempted-user 2017-2985   URL
42279FILE-OTHER Adobe Acrobat request for RARfsClientNP.dll over SMB attempt (more info ...)attempted-user 2017-3013   
42280FILE-OTHER Adobe Acrobat RARfsClientNP.dll dll-load exploit attempt (more info ...)attempted-user 2017-3013   URL
42298FILE-PDF Adobe PDF PPKLite security handler memory corruption vulnerability attempt (more info ...)attempted-user 2017-3039   URL
42307FILE-PDF Adobe Acrobat Reader malformed TTF out of bounds memory access attempt (more info ...)attempted-user 2017-3038   URL
42308FILE-PDF Adobe Acrobat Reader malformed TTF out of bounds memory access attempt (more info ...)attempted-user 2017-3038   URL
42315FILE-PDF Adobe Acrobat malformed JPEG 2000 codestream tile height out of bounds read attempt (more info ...)attempted-user 2017-3033   URL
42316FILE-PDF Adobe Acrobat malformed JPEG 2000 codestream tile height out of bounds read attempt (more info ...)attempted-user 2017-3033   URL
42317FILE-PDF Adobe Acrobat malformed JPEG 2000 codestream width out of bounds read attempt (more info ...)attempted-user 2017-3033   URL
42318FILE-PDF Adobe Acrobat malformed JPEG 2000 codestream width out of bounds read attempt (more info ...)attempted-user 2017-3033   URL
42341FILE-PDF Adobe PDF CFF font parsing memory corruption vulnerability attempt (more info ...)attempted-user 2017-3041   URL
42342FILE-PDF Adobe PDF CFF font parsing memory corruption vulnerability attempt (more info ...)attempted-user 2017-3041   URL
42343FILE-PDF Adobe PDF CFF font parsing memory corruption vulnerability attempt (more info ...)attempted-user 2017-3041   URL
42344FILE-PDF Adobe PDF CFF font parsing memory corruption vulnerability attempt (more info ...)attempted-user 2017-3041   URL
42377FILE-PDF Adobe Acrobat Reader dll injection sandbox escape (more info ...)attempted-user 2013-2730   URL
42460INDICATOR-COMPROMISE Adobe Reader PDF embedded null JPEG image (more info ...)misc-activity 2016-1088   URL
42846FILE-IMAGE Adobe Acrobat Pro malformed TIF heap overflow attempt (more info ...)attempted-user 2017-3049   URL
42847FILE-IMAGE Adobe Acrobat Pro malformed TIF heap overflow attempt (more info ...)attempted-user 2017-3049   URL
42870FILE-PDF Adobe Reader PDF document XSLT engine information disclosure exploitation attempt (more info ...)misc-activity 2017-3031   URL
42871FILE-PDF Adobe Reader PDF document XSLT engine information disclosure exploitation attempt (more info ...)misc-activity 2017-3031   URL
42872FILE-PDF Adobe Reader PDF document XSLT engine information disclosure exploitation attempt (more info ...)misc-activity 2017-3031   URL
42873FILE-PDF Adobe Reader PDF document XSLT engine information disclosure exploitation attempt (more info ...)misc-activity 2017-3031   URL
42874FILE-PDF Adobe Reader PDF document XSLT engine information disclosure exploitation attempt (more info ...)misc-activity 2017-3031   URL
42875FILE-PDF Adobe Reader PDF document XSLT engine information disclosure exploitation attempt (more info ...)misc-activity 2017-3031   URL
42876FILE-PDF Adobe Reader PDF document XSLT engine information disclosure exploitation attempt (more info ...)misc-activity 2017-3031   URL
42877FILE-PDF Adobe Reader PDF document XSLT engine information disclosure exploitation attempt (more info ...)misc-activity 2017-3031   URL
42937FILE-IMAGE Adobe Acrobat Pro SampleFormat heap overflow attempt (more info ...)attempted-user 2017-3048   URL
42938FILE-IMAGE Adobe Acrobat Pro SampleFormat heap overflow attempt (more info ...)attempted-user 2017-3048   URL
42939FILE-IMAGE Adobe Acrobat Pro SampleFormat heap overflow attempt (more info ...)attempted-user 2017-3048   URL
42940FILE-IMAGE Adobe Acrobat Pro SampleFormat heap overflow attempt (more info ...)attempted-user 2017-3048   URL
43051FILE-IMAGE Apple Quicktime malformed FPX file memory corruption attempt (more info ...)attempted-admin 2016-1768   
43052FILE-IMAGE Apple Quicktime malformed FPX file memory corruption attempt (more info ...)attempted-admin 2016-1768   
43130FILE-OTHER Adobe malicious IFF memory corruption attempt (more info ...)attempted-user 2011-0590   URL
43131FILE-OTHER Adobe malicious IFF memory corruption attempt (more info ...)attempted-user 2011-0590   URL
43132FILE-OTHER Adobe malicious IFF memory corruption attempt (more info ...)attempted-user 2011-0590   URL
43133FILE-OTHER Adobe malicious IFF memory corruption attempt (more info ...)attempted-user 2011-0590   URL
43229FILE-OTHER Adobe Shockwave Director Shockwave 3D buffer overflow attempt (more info ...)attempted-user 2013-1383   
43230FILE-OTHER Adobe Shockwave Director Shockwave 3D buffer overflow attempt (more info ...)attempted-user 2013-1383   
43231FILE-OTHER Adobe Shockwave Director Shockwave 3D buffer overflow attempt (more info ...)attempted-user 2013-1383   
43232FILE-OTHER Adobe Shockwave Director Shockwave 3D buffer overflow attempt (more info ...)attempted-user 2013-1383   
43233FILE-OTHER Adobe Shockwave Director Shockwave 3D buffer overflow attempt (more info ...)attempted-user 2013-1383   
43234FILE-OTHER Adobe Shockwave Director Shockwave 3D buffer overflow attempt (more info ...)attempted-user 2013-1383   
43235FILE-OTHER Adobe Shockwave Director Shockwave 3D buffer overflow attempt (more info ...)attempted-user 2013-1383   
43236FILE-OTHER Adobe Shockwave Director Shockwave 3D buffer overflow attempt (more info ...)attempted-user 2013-1383   
43303FILE-FLASH Adobe Flash Player ASnative null pointer dereference attempt (more info ...)attempted-user    
43335FILE-MULTIMEDIA Microsoft Windows Media Player JPG header record mismatch memory corruption attempt (more info ...)attempted-user 2010-1880 40464  URL
43336FILE-MULTIMEDIA Microsoft Windows Media Player JPG header record mismatch memory corruption attempt (more info ...)attempted-user 2010-1880 40464  URL
43727FILE-FLASH RealNetworks RealPlayer FLV integer overflow attempt (more info ...)attempted-user 2010-3000 42775  
43835EXPLOIT-KIT RIG exploit kit Adobe Flash exploit download (more info ...)misc-activity    
43836INDICATOR-OBFUSCATION Adobe Flash file packed with SecureSwf obfuscator (more info ...)misc-activity    URL
43838INDICATOR-COMPROMISE Adobe Flash file contains reference to kernel32.dll (more info ...)attempted-user    
43871FILE-IMAGE Adobe Acrobat Professional malformed PCX memory corruption attempt (more info ...)attempted-user 2017-3124   URL
43872FILE-IMAGE Adobe Acrobat Professional malformed PCX memory corruption attempt (more info ...)attempted-user 2017-3124   URL
43873FILE-IMAGE Adobe Acrobat Professional malformed PCX memory corruption attempt (more info ...)attempted-user 2017-3116   URL
43874FILE-IMAGE Adobe Acrobat Professional malformed PCX memory corruption attempt (more info ...)attempted-user 2017-3116   URL
43879FILE-OTHER Adobe Professional EMF polygon heap buffer overflow attempt (more info ...)attempted-user 2017-11241   URL
43880FILE-OTHER Adobe Professional EMF polygon heap buffer overflow attempt (more info ...)attempted-user 2017-11241   URL
43914FILE-PDF Adobe Acrobat Reader XFA resolveNode type confusion exploitation attempt (more info ...)attempted-user    URL
43915FILE-PDF Adobe Acrobat Reader XFA resolveNode type confusion exploitation attempt (more info ...)attempted-user    URL
43918FILE-PDF Adobe Acrobat Reader exportDataObject security bypass attempt (more info ...)attempted-user 2017-3118 100189  URL
43919FILE-PDF Adobe Acrobat Reader exportDataObject security bypass attempt (more info ...)attempted-user 2017-3118 100189  URL
43920FILE-PDF Adobe Acrobat Reader exportDataObject security bypass attempt (more info ...)attempted-user 2017-3118 100189  URL
43921FILE-PDF Adobe Acrobat Reader exportDataObject security bypass attempt (more info ...)attempted-user 2017-3118 100189  URL
43922FILE-PDF Adobe Acrobat Reader exportDataObject security bypass attempt (more info ...)attempted-user 2017-3118 100189  URL
43923FILE-PDF Adobe Acrobat Reader exportDataObject security bypass attempt (more info ...)attempted-user 2017-3118 100189  URL
43967FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed EMR_POLYBEZIERTO16 out of bounds access attempt (more info ...)attempted-user 2017-11238   URL
43970FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed EMR_POLYBEZIER16 out of bounds access attempt (more info ...)attempted-user 2017-3122   URL
43971FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed EMR_POLYBEZIER16 out of bounds access attempt (more info ...)attempted-user 2017-3122   URL
44024FILE-IMAGE Adobe Acrobat Pro malformed TIFF memory corruption attempt (more info ...)attempted-user 2018-15927   URL
44026FILE-IMAGE Adobe Acrobat Pro malformed TIFF memory corruption attempt (more info ...)attempted-user 2017-16396   URL
44056FILE-MULTIMEDIA Adobe Acrobat Professional EMF malformed EMR_COMMENT record out of bounds access attempt (more info ...)attempted-user 2018-15946   URL
44057FILE-OTHER Adobe Acrobat Pro EMF file EMR_ALPHABLEND record memory corruption attempt (more info ...)misc-activity    URL
44058FILE-OTHER Adobe Acrobat Pro EMF file EMR_ALPHABLEND record memory corruption attempt (more info ...)misc-activity    URL
44066FILE-OTHER Adobe Acrobat EMF conversion heap buffer overflow attempt (more info ...)attempted-user 2017-11241   URL
44067FILE-OTHER Adobe Acrobat EMF conversion heap buffer overflow attempt (more info ...)attempted-user 2017-11241   URL
44108FILE-OTHER Adobe Professional EMF file TIFF image size memory corruption attempt (more info ...)attempted-user 2017-11261   URL
44109FILE-OTHER Adobe Professional EMF file TIFF image size memory corruption attempt (more info ...)attempted-user 2017-11261   URL
44110FILE-OTHER Adobe Professional EMF file TIFF image size memory corruption attempt (more info ...)attempted-user 2017-11261   URL
44111FILE-OTHER Adobe Professional EMF file TIFF image size memory corruption attempt (more info ...)attempted-user 2017-11261   URL
44112FILE-OTHER Adobe Professional EMF file TIFF image size memory corruption attempt (more info ...)attempted-user 2017-11261   URL
44113FILE-OTHER Adobe Professional EMF file TIFF image size memory corruption attempt (more info ...)attempted-user 2017-11261   URL
44114FILE-OTHER Adobe Professional EMF file TIFF image size memory corruption attempt (more info ...)attempted-user 2017-11261   URL
44115FILE-OTHER Adobe Professional EMF file TIFF image size memory corruption attempt (more info ...)attempted-user 2017-11261   URL
44120FILE-OTHER Adobe Acrobat Professional EMF JPEG APP13 malformed record crash attempt (more info ...)misc-activity 2017-11267   URL
44121FILE-OTHER Adobe Acrobat Professional EMF JPEG APP13 malformed record memory corruption attempt (more info ...)misc-activity 2018-4981   URL
44122FILE-OTHER Adobe Acrobat Professional EMF JPEG APP13 malformed record memory corruption attempt (more info ...)misc-activity 2018-4981   URL
44158FILE-OTHER Microsoft Windows Media Player malformed au denial of service attempt (more info ...)denial-of-service 2007-4288 25236  
44159FILE-OTHER Microsoft Windows Media Player malformed au denial of service attempt (more info ...)denial-of-service 2007-4288 25236  
44169FILE-PDF Adobe Professional JPEG ICC profile heap overflow attempt (more info ...)attempted-user 2017-11211   URL
44170FILE-PDF Adobe Professional JPEG ICC profile heap overflow attempt (more info ...)attempted-user 2017-11211   URL
44206FILE-PDF Adobe Acrobat Reader embedded JS array memory corruption attempt (more info ...)attempted-user 2017-3119   URL
44207FILE-PDF Adobe Acrobat Reader embedded JS array memory corruption attempt (more info ...)attempted-user 2017-3119   URL
44208FILE-PDF Adobe Acrobat Reader embedded JS array memory corruption attempt (more info ...)attempted-user 2017-3119   URL
44209FILE-PDF Adobe Acrobat Reader embedded JS array memory corruption attempt (more info ...)attempted-user 2017-3119   URL
44904FILE-PDF Adobe Acrobat untrusted pointer dereference attempt (more info ...)attempted-user 2017-16373   URL
44905FILE-PDF Adobe Acrobat untrusted pointer dereference attempt (more info ...)attempted-user 2017-16373   URL
44906FILE-PDF Adobe Acrobat Reader javscript use after free attempt (more info ...)attempted-user 2017-16390   URL
44907FILE-PDF Adobe Acrobat Reader javscript use after free attempt (more info ...)attempted-user 2017-16390   URL
44914FILE-PDF Adobe Acrobat Reader PrintParams out of bounds array index attempt (more info ...)attempted-user 2017-16391   URL
44915FILE-PDF Adobe Acrobat Reader PrintParams out of bounds array index attempt (more info ...)attempted-user 2017-16391   URL
44919FILE-OTHER Adobe Acrobat Pro EmfPlusRectF out of bounds read attempt (more info ...)attempted-user 2017-16401   URL
44920FILE-OTHER Adobe Acrobat Pro EmfPlusRectF out of bounds read attempt (more info ...)attempted-user 2017-16401   URL
44931FILE-OTHER Adobe Acrobat Pro XPS file embedded JPEG invalid SOS data memory corruption attempt (more info ...)attempted-user 2017-16412   URL
44932FILE-OTHER Adobe Acrobat Pro XPS file embedded JPEG invalid SOS data memory corruption attempt (more info ...)attempted-user 2017-16412   URL
44935FILE-OTHER Adobe Acrobat Pro XPS out of bounds read attempt (more info ...)attempted-user 2017-16418   URL
44936FILE-OTHER Adobe Acrobat Pro XPS out of bounds read attempt (more info ...)attempted-user 2017-16418   URL
44941FILE-OTHER Adobe Acrobat Reader FDF file security bypass attempt (more info ...)misc-activity 2017-16361   URL
44942FILE-OTHER Adobe Acrobat Reader FDF file security bypass attempt (more info ...)misc-activity 2017-16361   URL
44947FILE-PDF Adobe Acrobat Reader double free attempt (more info ...)attempted-user 2017-16420   URL
44948FILE-PDF Adobe Acrobat Reader double free attempt (more info ...)attempted-user 2017-16420   URL
44957FILE-PDF Adobe Acrobat malformed XObject use after free attempt (more info ...)attempted-admin 2017-16360   URL
44958FILE-PDF Adobe Acrobat malformed XObject use after free attempt (more info ...)attempted-admin 2017-16360   URL
44987FILE-PDF Adobe Acrobat PDF font character encoding out of bounds write attempt (more info ...)attempted-user 2017-16415   URL
45023FILE-PDF Adobe Acrobat out of bound read exploitation attempt (more info ...)attempted-user 2017-16414   URL
45024FILE-PDF Adobe Acrobat out of bound read exploitation attempt (more info ...)attempted-user 2017-16414   URL
45027FILE-PDF Adobe Acrobat out of bound read exploitation attempt (more info ...)attempted-user 2017-16414   URL
45028FILE-PDF Adobe Acrobat out of bound read exploitation attempt (more info ...)attempted-user 2017-16414   URL
45042BROWSER-OTHER Adobe Acrobat Pro WebCapture information disclosure attempt (more info ...)attempted-user 2017-16408   URL
45043BROWSER-OTHER Adobe Acrobat Pro WebCapture information disclosure attempt (more info ...)attempted-user 2017-16408   URL
45080EXPLOIT-KIT Sundown/Terror malicious flash file load attempt (more info ...)attempted-user    
45085FILE-FLASH Adobe Flash Player use after free attempt (more info ...)attempted-admin 2015-8434   URL
45125FILE-OTHER Adobe Shockwave newModel memory disclosure attempt (more info ...)attempted-recon 2013-1385   
45126FILE-OTHER Adobe Shockwave newModel memory disclosure attempt (more info ...)attempted-recon 2013-1385   
45185FILE-IMAGE Apple Quicktime malformed FPX file memory corruption attempt (more info ...)attempted-admin 2016-1767   
45186FILE-IMAGE Apple Quicktime malformed FPX file memory corruption attempt (more info ...)attempted-admin 2016-1767   
45202FILE-OTHER Adobe Audition Session file stack buffer overflow attempt (more info ...)attempted-user 2011-0614 47841  URL
45203FILE-OTHER Adobe Audition Session file stack buffer overflow attempt (more info ...)attempted-user 2011-0614 47841  URL
45224FILE-FLASH Adobe Flash memory corruption exploit attempt (more info ...)attempted-user 2009-3798 37275  
45225FILE-FLASH Adobe Flash memory corruption exploit attempt (more info ...)attempted-user 2009-3798 37275  
45356FILE-FLASH Adobe Flash Player null pointer dereference attempt (more info ...)attempted-user 2011-0626   URL
45369FILE-PDF Adobe Acrobat Reader getAnnots exploit attempt (more info ...)attempted-user 2009-1492 34736  
45399FILE-OTHER Adobe Photoshop asset elements stack based buffer overflow attempt (more info ...)attempted-user  53464  
45458FILE-FLASH Adobe Flash Player movieclip attachbitmap use-after-free attempt (more info ...)attempted-user 2015-8410   URL
45586FILE-MULTIMEDIA Microsoft Windows Media Player or Explorer Malformed MIDI File DOS attempt (more info ...)denial-of-service 2007-0562 21612  
45669FILE-OTHER Adobe Acrobat Pro embedded TIFF heap overflow attempt (more info ...)attempted-admin 2018-4904   URL
45670FILE-OTHER Adobe Acrobat Pro embedded TIFF heap overflow attempt (more info ...)attempted-admin 2018-4904   URL
45671FILE-OTHER Adobe Acrobat Pro embedded TIFF heap overflow attempt (more info ...)attempted-admin 2018-4904   URL
45672FILE-OTHER Adobe Acrobat Pro embedded TIFF heap overflow attempt (more info ...)attempted-admin 2018-4904   URL
45684FILE-IMAGE Adobe Acrobat Pro BMP out of bounds read attempt (more info ...)attempted-admin 2018-4881   URL
45685FILE-IMAGE Adobe Acrobat Pro BMP out of bounds read attempt (more info ...)attempted-admin 2018-4881   URL
45686FILE-OTHER Adobe Acrobat Pro embedded JPEG out of bounds read attempt (more info ...)attempted-admin 2018-4889   URL
45687FILE-OTHER Adobe Acrobat Pro embedded JPEG out of bounds read attempt (more info ...)attempted-admin 2018-4889   URL
45719FILE-PDF Adobe Acrobat Reader OCG heap overflow attempt (more info ...)attempted-admin 2018-4910   URL
45739INDICATOR-COMPROMISE Adobe Flash potential exploit download attempt (more info ...)attempted-user    
45740INDICATOR-COMPROMISE Adobe Flash potential exploit download attempt (more info ...)attempted-user    
45742INDICATOR-COMPROMISE Adobe Flash potential exploit download attempt (more info ...)attempted-user    
45743FILE-FLASH Adobe Flash Player ByteArray shading memory leak attempt (more info ...)attempted-recon 2015-3105 75086  URL
45776FILE-OTHER Adobe Acrobat Pro XPS file malformed Source attribute buffer overflow attempt (more info ...)attempted-user 2018-4899   URL
45777FILE-OTHER Adobe Acrobat Pro XPS file malformed Source attribute buffer overflow attempt (more info ...)attempted-user 2018-4899   URL
45780FILE-OTHER Adobe Acrobat Pro XPS out of bounds read attempt (more info ...)attempted-recon 2018-4893   
45781FILE-OTHER Adobe Acrobat Pro XPS out of bounds read attempt (more info ...)attempted-recon 2018-4893   
45784FILE-PDF Adobe Reader annotation object out of bounds read attempt (more info ...)attempted-admin 2018-4900   URL
45785FILE-PDF Adobe Reader annotation object out of bounds read attempt (more info ...)attempted-user 2018-4900   URL
45802FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-recon 2018-4894   
45803FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-recon 2018-4894   
45851FILE-OTHER Adobe Acrobat Pro EMF malformed bitmap rectangle destination out of bounds read attempt (more info ...)attempted-user 2018-4886   URL
46053FILE-OTHER Adobe Acrobat EMF malformed Object record out-of-bounds access attempt (more info ...)attempted-user 2018-4885   URL
46054FILE-OTHER Adobe Acrobat EMF malformed Object record out-of-bounds access attempt (more info ...)attempted-user 2018-4885   URL
46103POLICY-OTHER Flash file external url request attempt (more info ...)attempted-user 2018-0112   
46117FILE-OTHER Adobe Acrobat Pro JPEG embedded XPS file heap overflow attempt (more info ...)attempted-user 2018-4890   URL
46118FILE-OTHER Adobe Acrobat Pro JPEG embedded XPS file heap overflow attempt (more info ...)attempted-user 2018-4890   URL
46256FILE-FLASH Adobe Flash Player corrupt PNG image load out of bounds memory access attempt (more info ...)attempted-user 2018-4934   
46257FILE-FLASH Adobe Flash Player corrupt PNG image load out of bounds memory access attempt (more info ...)attempted-user 2018-4934   URL
46258FILE-FLASH Adobe Flash Player MovieClip out of bounds write attempt (more info ...)attempted-user 2018-4935   URL
46259FILE-FLASH Adobe Flash Player MovieClip out of bounds write attempt (more info ...)attempted-user 2018-4935   URL
46461SERVER-WEBAPP Adobe RoboHelp rx cross site scripting attempt (more info ...)attempted-user 2008-2991 30137  URL
46464SERVER-WEBAPP Adobe RoboHelp rx cross site scripting attempt (more info ...)attempted-user 2008-2991 30137  URL
46465SERVER-WEBAPP Adobe RoboHelp rx cross site scripting attempt (more info ...)attempted-user 2008-2991 30137  URL
46480FILE-MULTIMEDIA Apple QuickTime movie file keys atom integer overflow attempt (more info ...)attempted-user 2016-5199 94196  URL
46481FILE-MULTIMEDIA Apple QuickTime movie file keys atom integer overflow attempt (more info ...)attempted-user 2016-5199 94196  URL
46643FILE-OTHER Adobe Professional EMF compression out of bounds write attempt (more info ...)attempted-user 2018-4950   URL
46644FILE-OTHER Adobe Professional EMF compression out of bounds write attempt (more info ...)attempted-user 2018-4950   URL
46659FILE-OTHER Adobe Acrobat Reader jp2 double free attempt (more info ...)attempted-user 2018-4990   URL
46671FILE-IMAGE Adobe Acrobat Pro EMF file EMR_STRETCHDIBITS heap overflow attempt (more info ...)attempted-user 2018-4948   URL
46672FILE-IMAGE Adobe Acrobat Pro EMF file EMR_STRETCHDIBITS heap overflow attempt (more info ...)attempted-user 2018-4948   URL
46673FILE-IMAGE Adobe Acrobat Pro EMF file EMR_STRETCHDIBITS heap overflow attempt (more info ...)attempted-user 2018-4948   URL
46674FILE-IMAGE Adobe Acrobat Pro EMF file EMR_STRETCHDIBITS heap overflow attempt (more info ...)attempted-user 2018-4948   URL
46711FILE-OTHER Adobe Professional BMP embedded image heap overflow attempt (more info ...)attempted-user 2018-4982   URL
46712FILE-OTHER Adobe Professional BMP embedded image heap overflow attempt (more info ...)attempted-user 2018-4982   URL
46716FILE-PDF Adobe Acrobat Reader use after free attempt (more info ...)attempted-admin 2018-4988   URL
46725FILE-IMAGE Adobe Acrobat Pro malformed JPEG out of bounds read attempt (more info ...)attempted-admin 2018-4973   URL
46726FILE-IMAGE Adobe Acrobat Pro malformed JPEG out of bounds read attempt (more info ...)attempted-admin 2018-4973   URL
46729FILE-OTHER Adobe Acrobat Professional XPS out of bounds read attempt (more info ...)attempted-recon 2018-4975   
46730FILE-OTHER Adobe Acrobat Professional XPS out of bounds read attempt (more info ...)attempted-recon 2018-4975   
46797FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-admin 2018-4957   URL
46798FILE-OTHER Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-admin 2018-4957   URL
46960FILE-OTHER Adobe Flash Player AMF0 Shared Object integer overflow attempt (more info ...)attempted-user 2018-5000   URL
47032FILE-MULTIMEDIA Apple QuickTime MPEG stream padding buffer overflow attempt (more info ...)attempted-user 2012-0659   URL
47033FILE-MULTIMEDIA Apple QuickTime MPEG stream padding buffer overflow attempt (more info ...)attempted-user 2012-0659   URL
47059FILE-IMAGE Adobe Acrobat Pro malformed EMF out of bounds read attempt (more info ...)attempted-admin 2018-4951   URL
47060FILE-IMAGE Adobe Acrobat Pro malformed EMF out of bounds read attempt (more info ...)attempted-admin 2018-4951   URL
47129FILE-IMAGE Adobe Acrobat Pro malformed CEL heap overflow attempt (more info ...)attempted-user 2018-5052   URL
47130FILE-IMAGE Adobe Acrobat Pro malformed CEL heap overflow attempt (more info ...)attempted-user 2018-5052   URL
47131FILE-OTHER Adobe Acrobat Pro EMF Alphablend memory corruption attempt (more info ...)attempted-user 2018-5062   URL
47140FILE-OTHER Adobe Acrobat Pro EmfPlusDrawBeziers out-of-bounds read attempt (more info ...)attempted-user 2018-5061   URL
47153FILE-OTHER Adobe Acrobat Pro use after free attempt (more info ...)attempted-user 2018-12783   URL
47154FILE-OTHER Adobe Acrobat Pro use after free attempt (more info ...)attempted-user 2018-12783   URL
47157FILE-IMAGE Adobe Acrobat Reader jp2 out-of-bounds read attempt (more info ...)attempted-user 2018-12790   URL
47158FILE-IMAGE Adobe Acrobat Reader jp2 out-of-bounds read attempt (more info ...)attempted-user 2018-12790   URL
47174FILE-IMAGE Apple Quicktime malformed FPX file memory corruption attempt (more info ...)attempted-admin 2016-1767   
47187FILE-PDF Adobe Acrobat Reader type confusion attempt (more info ...)attempted-user 2018-12794   URL
47188FILE-PDF Adobe Acrobat Reader type confusion attempt (more info ...)attempted-user 2018-12794   URL
47195FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-5014   URL
47196FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-5014   URL
47230FILE-OTHER Adobe Acrobat Pro out-of-bounds write attempt (more info ...)attempted-user 2018-12771   
47231FILE-OTHER Adobe Acrobat Pro out-of-bounds write attempt (more info ...)attempted-user 2018-12771   
47232FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12780   URL
47233FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12780   URL
47245FILE-OTHER Adobe Acrobat Pro XPS TTF out-of-bounds read attempt (more info ...)attempted-user 2018-5019   URL
47246FILE-OTHER Adobe Acrobat Pro XPS TTF out-of-bounds read attempt (more info ...)attempted-user 2018-5019   URL
47249FILE-OTHER Adobe Acrobat Pro XPS out-of-bounds read attempt (more info ...)attempted-recon 2018-5018   URL
47250FILE-OTHER Adobe Acrobat Pro XPS out-of-bounds read attempt (more info ...)attempted-recon 2018-5018   URL
47251FILE-OTHER Adobe Acrobat Pro use after free attempt (more info ...)attempted-user 2018-12773   URL
47252FILE-OTHER Adobe Acrobat Pro use after free attempt (more info ...)attempted-user 2018-12773   URL
47266FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12776   URL
47267FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12776   URL
47268FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12774   URL
47269FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12774   URL
47274FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12777   URL
47275FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12777   URL
47276FILE-OTHER Adobe Acrobat Pro XPS file PPDoc out-of-bounds read attempt (more info ...)attempted-user 2018-5056   URL
47277FILE-OTHER Adobe Acrobat Pro XPS file PPDoc out-of-bounds read attempt (more info ...)attempted-user 2018-5056   URL
47279FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12779   URL
47280FILE-OTHER Adobe Acrobat Pro out-of-bounds read attempt (more info ...)attempted-user 2018-12779   URL
47312FILE-IMAGE Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user 2018-5029   URL
47313FILE-IMAGE Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user 2018-5029   URL
47314FILE-IMAGE Adobe Acrobat Pro malformed CEL out of bounds read attempt (more info ...)attempted-user 2018-5046   URL
47315FILE-IMAGE Adobe Acrobat Pro malformed CEL out of bounds read attempt (more info ...)attempted-user 2018-5046   URL
47318FILE-PDF Adobe Acrobat Reader out of bounds write attempt (more info ...)attempted-user 2018-12755   URL
47328FILE-IMAGE Adobe Acrobat Pro malformed TIFF out of bounds read attempt (more info ...)attempted-user 2018-5044   URL
47329FILE-IMAGE Adobe Acrobat Pro malformed TIFF out of bounds read attempt (more info ...)attempted-user 2018-5044   URL
47330FILE-IMAGE Adobe Acrobat Pro malformed TIFF out of bounds read attempt (more info ...)attempted-user 2018-5044   URL
47331FILE-IMAGE Adobe Acrobat Pro malformed TIFF out of bounds read attempt (more info ...)attempted-user 2018-5044   URL
47332FILE-OTHER Adobe Acrobat Pro out of bounds write attempt (more info ...)attempted-user 2018-5059   URL
47333FILE-OTHER Adobe Acrobat Pro out of bounds write attempt (more info ...)attempted-user 2018-5059   URL
47334FILE-PDF Adobe Acrobat Pro out of bounds write attempt (more info ...)attempted-user 2018-5059   URL
47335FILE-PDF Adobe Acrobat Pro out of bounds write attempt (more info ...)attempted-user 2018-5059   URL
47343FILE-IMAGE Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user 2018-5033   URL
47344FILE-IMAGE Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user 2018-5033   URL
47350FILE-IMAGE Adobe Acrobat Pro malformed JPEG heap overflow attempt (more info ...)attempted-user 2018-5058   URL
47351FILE-IMAGE Adobe Acrobat Pro malformed JPEG heap overflow attempt (more info ...)attempted-user 2018-5058   URL
47352FILE-IMAGE Adobe Acrobat Pro malformed JPEG heap overflow attempt (more info ...)attempted-user 2018-5058   URL
47353FILE-IMAGE Adobe Acrobat Pro malformed JPEG heap overflow attempt (more info ...)attempted-user 2018-5058   URL
47354FILE-OTHER Adobe Acrobat Pro EMF EmfPlusDrawPath out of bounds read attempt (more info ...)attempted-recon    
47356FILE-IMAGE Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user 2018-5039   URL
47357FILE-IMAGE Adobe Acrobat Pro out of bounds read attempt (more info ...)attempted-user 2018-5039   URL
47359FILE-IMAGE Adobe Acrobat Reader malformed TIFF out of bounds read attempt (more info ...)attempted-user 2018-5053   URL
47360FILE-IMAGE Adobe Acrobat Reader malformed TIFF out of bounds read attempt (more info ...)attempted-user 2018-5053   URL
47361FILE-IMAGE Adobe Acrobat Reader malformed TIFF out of bounds read attempt (more info ...)attempted-user 2018-5053   URL
47362FILE-IMAGE Adobe Acrobat Reader malformed TIFF out of bounds read attempt (more info ...)attempted-user 2018-5053   URL
47365FILE-PDF Adobe Acrobat Reader double free attempt (more info ...)attempted-user 2018-12782   URL
47366FILE-PDF Adobe Acrobat Reader double free attempt (more info ...)attempted-user 2018-12782   URL
47367FILE-IMAGE Adobe Acrobat Pro PSD malformed image data out-of-bounds write attempt (more info ...)attempted-user 2018-5042   URL
47368FILE-IMAGE Adobe Acrobat Pro PSD malformed image data out-of-bounds write attempt (more info ...)attempted-user 2018-5042   URL
47369FILE-OTHER Adobe Acrobat Pro out of bounds memory access attempt (more info ...)attempted-user 2018-5037   URL
47370FILE-OTHER Adobe Acrobat Pro out of bounds memory access attempt (more info ...)attempted-user 2018-5037   URL
47378FILE-PDF Adobe Acrobat Reader out of bounds read attempt (more info ...)attempted-user 2018-5068   URL
47379FILE-PDF Adobe Acrobat Reader out of bounds read attempt (more info ...)attempted-user 2018-5068   URL
47382FILE-IMAGE Adobe Acrobat Pro use after free attempt (more info ...)attempted-user 2018-12791   URL
47383FILE-IMAGE Adobe Acrobat Pro use after free attempt (more info ...)attempted-user 2018-12791   URL
47384FILE-OTHER Adobe Acrobat Pro use after free attempt (more info ...)attempted-user 2018-12772   URL
47385FILE-OTHER Adobe Acrobat Pro use after free attempt (more info ...)attempted-user 2018-12772   URL
47625FILE-OTHER Adobe Acrobat Reader EMF path record out-of-bounds read attempt (more info ...)attempted-user 2018-12786   URL
47626FILE-OTHER Adobe Acrobat Reader EMF path record out-of-bounds read attempt (more info ...)attempted-user 2018-12786   URL
47685FILE-PDF Adobe Acrobat Pro U3D IFF out of bounds read attempt (more info ...)attempted-recon 2019-7034   URL
47686FILE-PDF Adobe Acrobat Pro U3D IFF out of bounds read attempt (more info ...)attempted-recon 2019-7034   URL
47687FILE-PDF Adobe Acrobat Pro U3D SGI RGB information leak attempt (more info ...)attempted-recon 2018-5047   URL
47688FILE-PDF Adobe Acrobat Pro U3D SGI RGB information leak attempt (more info ...)attempted-recon 2018-5047   URL
47838FILE-IMAGE Adobe Acrobat Pro SGI RGB run-length encoding out of bounds read attempt (more info ...)attempted-user 2018-5054   URL
47839FILE-IMAGE Adobe Acrobat Pro SGI RGB run-length encoding out of bounds read attempt (more info ...)attempted-user 2018-5054   URL
47874FILE-IMAGE Adobe Acrobat Pro EMF ALPHABLEND heap overflow attempt (more info ...)attempted-user 2018-12788   URL
47875FILE-IMAGE Adobe Acrobat Pro EMF ALPHABLEND heap overflow attempt (more info ...)attempted-user 2018-12788   URL
47883FILE-OTHER Adobe Acrobat Pro EMF image conversion memory corruption attempt (more info ...)attempted-user 2018-5030   URL
47884FILE-OTHER Adobe Acrobat Pro EMF image conversion memory corruption attempt (more info ...)attempted-user 2018-5030   URL
47908FILE-IMAGE Adobe Acrobat Pro EMR_STRETCHDIBITS out-of-bounds write attempt (more info ...)attempted-user 2018-12787   URL
47910FILE-IMAGE Adobe Acrobat Pro EMR_STRETCHDIBITS out-of-bounds write attempt (more info ...)attempted-user 2018-12787   URL
47939FILE-IMAGE Adobe Acrobat Pro EMF+ GIF parsing out of bounds read attempt (more info ...)attempted-recon 2018-12834   URL
47940FILE-IMAGE Adobe Acrobat Pro EMF+ GIF parsing out of bounds read attempt (more info ...)attempted-recon 2018-12834   URL
47943FILE-IMAGE Adobe Acrobat Distiller PostScript stack overflow attempt (more info ...)attempted-user 2018-12838   URL
47944FILE-IMAGE Adobe Acrobat Distiller PostScript stack overflow attempt (more info ...)attempted-user 2018-12838   URL
47961FILE-OTHER Adobe Acrobat Pro EmfPlusDrawBeziers out of bounds write attempt (more info ...)attempted-user 2018-12759   URL
47962FILE-OTHER Adobe Acrobat Pro EmfPlusDrawBeziers out of bounds write attempt (more info ...)attempted-user 2018-12759   URL
47985FILE-OTHER Adobe Acrobat Pro XPS out-of-bounds write attempt (more info ...)attempted-user 2018-15945   URL
47989FILE-OTHER Adobe Acrobat Pro EMF out of bounds write attempt (more info ...)attempted-user 2018-12868   URL
47990FILE-OTHER Adobe Acrobat Pro EMF out of bounds write attempt (more info ...)attempted-user 2018-12868   URL
48011FILE-IMAGE Adobe Acrobat Pro U3D TIFF XResolution out of bounds read attempt (more info ...)attempted-user 2018-15956   URL
48012FILE-IMAGE Adobe Acrobat Pro U3D TIFF XResolution out of bounds read attempt (more info ...)attempted-user 2018-15956   URL
48013FILE-IMAGE Adobe Acrobat Pro U3D TIFF XResolution out of bounds read attempt (more info ...)attempted-user 2018-15956   URL
48014FILE-IMAGE Adobe Acrobat Pro U3D TIFF XResolution out of bounds read attempt (more info ...)attempted-user 2018-15956   URL
48039FILE-IMAGE Adobe Acrobat Pro malformed BMP out of bounds read attempt (more info ...)attempted-user 2018-5051   URL
48040FILE-IMAGE Adobe Acrobat Pro malformed BMP out of bounds read attempt (more info ...)attempted-user 2018-5051   URL
48134FILE-IMAGE Adobe Acrobat SGI parsing out of bounds read attempt (more info ...)attempted-recon 2018-15953   URL
48135FILE-IMAGE Adobe Acrobat SGI parsing out of bounds read attempt (more info ...)attempted-recon 2018-15953   URL
48211FILE-PDF Adobe Acrobat Pro out-of-bounds write attempt (more info ...)attempted-user 2018-5070   URL
48212FILE-PDF Adobe Acrobat Pro out-of-bounds write attempt (more info ...)attempted-user 2018-5070   URL
48400FILE-FLASH Adobe Flash Player out of bounds read attempt (more info ...)attempted-recon 2018-15978   
48401FILE-FLASH Adobe Flash Player out of bounds read attempt (more info ...)attempted-recon 2018-15978   
48642FILE-OTHER Adobe Acrobat EMF out of bounds read attempt (more info ...)attempted-user 2018-16017   URL
48905FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user 2018-15982   URL
48906FILE-FLASH Adobe Flash Player TVSDK metadata use after free attempt (more info ...)attempted-user 2018-15982   URL
48909FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48910FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48911FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48912FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48913FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48914FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48915FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48916FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48917FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48918FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48919FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48920FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48921FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48922FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48923FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48924FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48925FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48926FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48927FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48928FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48929FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48930FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48931FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48932FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48933FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48934FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48935FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48936FILE-IMAGE Adobe Acrobat Pro tga file heap overflow attempt (more info ...)attempted-user 2018-5045   URL
48965FILE-PDF Adobe Reader PPKLite security handler memory corruption vulnerability attempt (more info ...)attempted-user 2018-16042   URL
48966FILE-PDF Adobe Reader PPKLite security handler memory corruption vulnerability attempt (more info ...)attempted-user 2018-16042   URL
48967FILE-PDF Adobe Reader PPKLite security handler memory corruption vulnerability attempt (more info ...)attempted-user 2018-16042   URL
48968FILE-PDF Adobe Reader PPKLite security handler memory corruption vulnerability attempt (more info ...)attempted-user 2018-16042   URL
49122FILE-IMAGE Adobe Acrobat TIFF heap buffer overflow attempt (more info ...)attempted-user 2017-2966   URL
49123FILE-IMAGE Adobe Acrobat TIFF heap buffer overflow attempt (more info ...)attempted-user 2017-2966   URL
49124FILE-IMAGE Adobe Acrobat TIFF heap buffer overflow attempt (more info ...)attempted-user 2017-2966   URL
49125FILE-IMAGE Adobe Acrobat TIFF heap buffer overflow attempt (more info ...)attempted-user 2017-2966   URL
49178FILE-PDF Adobe Acrobat Reader XSLT information disclosure attempt (more info ...)attempted-user 2019-7815   URL
49179FILE-PDF Adobe Acrobat Reader XSLT information disclosure attempt (more info ...)attempted-user 2019-7815   URL
49281FILE-OTHER Adobe Acrobat Pro HTML use-after-free attempt (more info ...)attempted-user 2019-7077   URL
49404FILE-MULTIMEDIA RealNetworks RealPlayer vidplin.dll avi header parsing execution attempt (more info ...)attempted-user 2010-4393 46047  
49573FILE-MULTIMEDIA RealNetworks RealPlayer mpeg width integer memory underflow attempt (more info ...)attempted-user 2011-4259 50741  
50185FILE-FLASH Adobe Flash Player writeExternal type confusion attempt (more info ...)attempted-user 2015-7645   URL
50441FILE-IMAGE Adobe Acrobat TIFF heap buffer overflow attempt (more info ...)attempted-user 2017-2966   URL
50442FILE-IMAGE Adobe Acrobat TIFF heap buffer overflow attempt (more info ...)attempted-user 2017-2966   URL
50443FILE-IMAGE Adobe Acrobat TIFF heap buffer overflow attempt (more info ...)attempted-user 2017-2966   URL
50444FILE-IMAGE Adobe Acrobat TIFF heap buffer overflow attempt (more info ...)attempted-user 2017-2966   URL
51379FILE-OTHER Adobe Acrobat XPS TTF cmap out-of-bounds read attempt (more info ...)attempted-user 2018-5019   URL
51380FILE-OTHER Adobe Acrobat XPS TTF cmap out-of-bounds read attempt (more info ...)attempted-user 2018-5019   URL
51555OS-WINDOWS Microsoft DirectShow QuickTime file atom size parsing heap corruption attempt (more info ...)attempted-user 2009-1539   URL
51556OS-WINDOWS Microsoft DirectShow QuickTime file atom size parsing heap corruption attempt (more info ...)attempted-user 2009-1539   URL
51557OS-WINDOWS Microsoft DirectShow QuickTime file atom size parsing heap corruption attempt (more info ...)attempted-user 2009-1539   URL
51819FILE-MULTIMEDIA RealNetworks RealPlayer 3GP file parsing memory corruption attempt (more info ...)attempted-user 2014-3444   
51820FILE-MULTIMEDIA RealNetworks RealPlayer 3GP file parsing memory corruption attempt (more info ...)attempted-user 2014-3444   
52125FILE-PDF Adobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attempt (more info ...)attempted-user 2010-2883   URL
52383FILE-OTHER Adobe Acrobat and Reader crafted .joboptions file download attempt (more info ...)attempted-user 2019-7110   
52444FILE-OTHER Winamp MAKI parsing integer overflow attempt (more info ...)attempted-user 2009-1831 35052  
52465FILE-PDF Adobe Acrobat Reader embedded font type max subroutine buffer overflow attempt (more info ...)attempted-user 2014-8460   URL
52466FILE-PDF Adobe Acrobat Reader embedded font type max subroutine buffer overflow attempt (more info ...)attempted-user 2014-8460   URL
52483FILE-PDF Adobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attempt (more info ...)attempted-user 2010-2883   URL
52484FILE-PDF Adobe Acrobat Reader and Acrobat TTF SING table parsing remote code execution attempt (more info ...)attempted-user 2010-2883   URL
52499FILE-IMAGE Adobe Photoshop Camera Raw plug-in TIFF image processing buffer underflow attempt (more info ...)attempted-user 2012-5679   URL
52500FILE-IMAGE Adobe Photoshop Camera Raw plug-in TIFF image processing buffer underflow attempt (more info ...)attempted-user 2012-5679   URL
57256FILE-PDF Adobe Acrobat Reader DC TTF parsing heap overflow attempt (more info ...)attempted-user 2019-8042   
57257FILE-PDF Adobe Acrobat Reader DC TTF parsing heap overflow attempt (more info ...)attempted-user 2019-8042   
58102FILE-PDF Adobe Reader ESObject use after free attempt (more info ...)attempted-user 2020-9715   URL
58103FILE-PDF Adobe Reader ESObject use after free attempt (more info ...)attempted-user 2020-9715   URL
58642FILE-PDF Adobe Acrobat Reader DC memory corruption attempt (more info ...)attempted-user 2021-28639   
58644FILE-PDF Adobe Acrobat Reader DC memory corruption attempt (more info ...)attempted-user 2021-28639   
58782FILE-PDF Adobe Reader Uninitialized object RCE attempt (more info ...)attempted-user    
58783FILE-PDF Adobe Reader Uninitialized object RCE attempt (more info ...)attempted-user    
59478FILE-OTHER Adobe Acrobat Pro embedded TIFF heap overflow attempt (more info ...)attempted-user 2018-4904   URL
59479FILE-OTHER Adobe Acrobat Pro embedded TIFF heap overflow attempt (more info ...)attempted-user 2018-4904   URL
59632FILE-FLASH Adobe Flash Player parseFloat stack overflow remote code execution attempt (more info ...)attempted-user 2014-9163   URL
59633FILE-FLASH Adobe Flash Player parseFloat stack overflow remote code execution attempt (more info ...)attempted-user 2014-9163   URL
59678FILE-IMAGE Adobe Acrobat Pro malformed JPEG APP1 segment out of bounds memory access attempt (more info ...)attempted-admin 2017-2960   URL
59748SERVER-WEBAPP Adobe ColdFusion cross-site scripting attempt (more info ...)web-application-attack 2022-28818   URL
59749SERVER-WEBAPP Adobe ColdFusion cross-site scripting attempt (more info ...)web-application-attack 2022-28818   URL
59783FILE-PDF Adobe Acrobat DC memory corruption attempt (more info ...)attempted-user 2019-7125   URL
59784FILE-PDF Adobe Acrobat DC memory corruption attempt (more info ...)attempted-user 2019-7125   URL
59785FILE-MULTIMEDIA Apple QuickTime ftab atom buffer overflow attempt (more info ...)attempted-user 2014-1246   
59786FILE-MULTIMEDIA Apple QuickTime ftab atom buffer overflow attempt (more info ...)attempted-user 2014-1246   
59826FILE-OTHER Adobe Acrobat malicious joboptions file download attempt (more info ...)attempted-user 2019-7111   URL
59827FILE-OTHER Adobe Acrobat malicious joboptions file download attempt (more info ...)attempted-user 2019-7111   URL
59841FILE-OTHER Adobe Acrobat Pro XPS file PPDoc out-of-bounds read attempt (more info ...)attempted-user 2018-5056   URL
59863FILE-OTHER Adobe Acrobat Pro XPS file malformed Source attribute buffer overflow attempt (more info ...)attempted-user 2018-4899   URL
59944FILE-PDF Adobe Acrobat Reader DC out-of-bounds read attempt (more info ...)attempted-user 2021-28554   URL
59945FILE-PDF Adobe Acrobat Reader DC out-of-bounds read attempt (more info ...)attempted-user 2021-28554   URL
60047FILE-PDF Adobe Acrobat Reader DC heap-based buffer overflow attempt (more info ...)attempted-user 2021-28560   URL
60048FILE-PDF Adobe Acrobat Reader DC heap-based buffer overflow attempt (more info ...)attempted-user 2021-28560   URL

 goto Top

Group: Client / Peer to Peer

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Client / Instant Messenger

# of attack rules in this group: 17

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
55016SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (more info ...)attempted-user  2020-3430      URL
55017SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (more info ...)attempted-user  2020-3430      URL
55018SERVER-OTHER Cisco Jabber for Windows protocol handler command injection attempt (more info ...)attempted-user  2020-3430      URL
55035SERVER-OTHER Cisco Jabber client remote code execution attempt (more info ...)attempted-user  2020-3495      URL
56572BROWSER-OTHER Cisco Jabber protocol handler command line argument injection attempt (more info ...)attempted-user  2020-27127      URL
56573BROWSER-OTHER Cisco Jabber protocol handler command line argument injection attempt (more info ...)attempted-user  2020-27127      URL
56575BROWSER-OTHER Cisco Jabber protocol handler command line argument injection attempt (more info ...)attempted-user  2020-27133      URL
56576BROWSER-OTHER Cisco Jabber protocol handler command line argument injection attempt (more info ...)attempted-user  2020-27133      URL
56588BROWSER-OTHER Cisco Jabber XMPP cross site scripting attempt (more info ...)attempted-user  2020-27132      URL
56589BROWSER-OTHER Cisco Jabber XMPP cross site scripting attempt (more info ...)attempted-user  2020-27132      URL
56590BROWSER-OTHER Cisco Jabber XMPP cross site scripting attempt (more info ...)attempted-user  2020-27132      URL
56845BROWSER-OTHER Cisco Jabber protocol cross-site scripting attempt (more info ...)attempted-user  2020-26085      URL
56846BROWSER-OTHER Cisco Jabber protocol cross-site scripting attempt (more info ...)attempted-user  2020-26085      URL
57352BROWSER-OTHER Cisco Jabber XMPP cross site scripting attempt (more info ...)attempted-user  2021-1411      URL
57353BROWSER-OTHER Cisco Jabber XMPP cross site scripting attempt (more info ...)attempted-user  2021-1411      URL
57354BROWSER-OTHER Cisco Jabber XMPP cross site scripting attempt (more info ...)attempted-user  2021-1469      URL
57359BROWSER-OTHER Cisco Jabber XMPP information disclosure attempt (more info ...)attempted-recon  2021-1417      URL


# of warning rules in this group: 26

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3130PUA-OTHER Microsoft MSN Messenger png overflow (more info ...)attempted-user 2004-0957 10872  URL
5692PUA-P2P Skype client successful install (more info ...)policy-violation    URL
5694PUA-P2P Skype client setup get newest version attempt (more info ...)policy-violation    URL
5998PUA-P2P Skype client login startup (more info ...)policy-violation    
5999PUA-P2P Skype client login (more info ...)policy-violation    
9380MALWARE-OTHER jitux msn messenger propagation detection (more info ...)trojan-activity    URL
13292PUA-OTHER Skype skype4com URI handler memory corruption attempt (more info ...)attempted-user 2007-5989 26748  
15150PUA-OTHER Jive Software Openfire Jabber Server login Authentication bypass attempt (more info ...)attempted-admin 2008-6510 32189  
15151PUA-OTHER Jive Software Openfire Jabber Server logout Authentication bypass attempt (more info ...)attempted-admin 2008-6510 32189  
15152PUA-OTHER Jive Software Openfire Jabber Server setup-index Authentication bypass attempt (more info ...)attempted-admin 2008-6510 32189  
15153PUA-OTHER Jive Software Openfire Jabber Server setup Authentication bypass attempt (more info ...)attempted-admin 2008-6509 32189  
15154PUA-OTHER Jive Software Openfire Jabber Server gif Authentication bypass attempt (more info ...)attempted-admin 2008-6510 32189  
15155PUA-OTHER Jive Software Openfire Jabber Server png Authentication bypass attempt (more info ...)attempted-admin 2008-6510 32189  
15156PUA-OTHER Jive Software Openfire Jabber Server serverdown Authentication bypass attempt (more info ...)attempted-admin 2008-6510 32189  
15939SERVER-OTHER MSN Messenger IRC bot calling home attempt (more info ...)trojan-activity    
16525POLICY-SOCIAL Microsoft MSN Messenger web login attempt (more info ...)policy-violation    URL
16718PUA-OTHER Skype URI handler input validation exploit attempt (more info ...)misc-attack  38699  URL
17551PUA-OTHER Microsoft MSN Messenger and Windows Live Messenger Code Execution attempt (more info ...)attempted-user 2007-2931 25461  
17674BROWSER-PLUGINS Skype Extras Manager ActiveX clsid access (more info ...)attempted-user 2009-4741 36459  
17676BROWSER-PLUGINS Skype Extras Manager ActiveX function call access (more info ...)attempted-user 2009-4741 36459  
18570INDICATOR-COMPROMISE fraudulent digital certificate for login.skype.com detected (more info ...)misc-attack    URL
20554PUA-OTHER Microsoft MSN Messenger and Windows Live Messenger Code Execution attempt (more info ...)attempted-user 2007-2931 25461  
31828MALWARE-CNC Win.Trojan.Jabberbot variant outbound connection (more info ...)trojan-activity    URL
31949MALWARE-CNC User-Agent known malicious user-agent string - Skypee - Win.Trojan.Rukypee (more info ...)trojan-activity    URL
56591BROWSER-OTHER Cisco Jabber XMPP cross site scripting attempt (more info ...)attempted-user 2020-27134   URL
57351BROWSER-OTHER Cisco Jabber XMPP mention message denial of service attempt (more info ...)attempted-dos 2021-1418   URL

 goto Top

Group: Protocol Anomaly

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Protocol Anomaly / Invalid Traffic

# of attack rules in this group: 8

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
16405PROTOCOL-ICMP Microsoft Windows Ipv6pHandleRouterAdvertisement Prefix Information stack buffer overflow attempt (more info ...)attempted-admin  2010-0239      URL
32369PROTOCOL-ICMP FreeBSD rtsold dname_labeldec stack buffer overflow attempt (more info ...)attempted-admin  2014-3954  70694    
43310BROWSER-PLUGINS MagnetoSoft ICMP ActiveX clsid access attempt (more info ...)attempted-user        URL
43311BROWSER-PLUGINS MagnetoSoft ICMP ActiveX clsid access attempt (more info ...)attempted-user        URL
43318BROWSER-PLUGINS MagnetoSoft ICMP ActiveX clsid access attempt (more info ...)attempted-user        URL
43319BROWSER-PLUGINS MagnetoSoft ICMP ActiveX clsid access attempt (more info ...)attempted-user        URL
54902PROTOCOL-OTHER IGMP DVMRP scan attempt (more info ...)network-scan        URL
55984PROTOCOL-ICMP Microsoft Windows IPv6 stack remote execution attempt (more info ...)attempted-user  2020-16898      URL


# of warning rules in this group: 149

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
221PROTOCOL-ICMP TFN Probe (more info ...)attempted-dos 2000-0138   
222PROTOCOL-ICMP tfn2k icmp possible communication (more info ...)attempted-dos 2000-0138   
224PROTOCOL-ICMP Stacheldraht server spoof (more info ...)attempted-dos 2000-0138   
225PROTOCOL-ICMP Stacheldraht gag server response (more info ...)attempted-dos 2000-0138   
226PROTOCOL-ICMP Stacheldraht server response (more info ...)attempted-dos 2000-0138   
227PROTOCOL-ICMP Stacheldraht client spoofworks (more info ...)attempted-dos 2000-0138   
228PROTOCOL-ICMP TFN client command BE (more info ...)attempted-dos 2000-0138   
229PROTOCOL-ICMP Stacheldraht client check skillz (more info ...)attempted-dos 2000-0138   
236PROTOCOL-ICMP Stacheldraht client check gag (more info ...)attempted-dos 2000-0138   
238PROTOCOL-ICMP TFN server response (more info ...)attempted-dos 2000-0138   
251PROTOCOL-ICMP - TFN client command LE (more info ...)attempted-dos 2000-0138   
272OS-WINDOWS Microsoft WIndows IGMP dos attack (more info ...)attempted-dos 1999-0918 514  URL
274PROTOCOL-ICMP ath (more info ...)attempted-dos 1999-1228   
363PROTOCOL-ICMP IRDP router advertisement (more info ...)misc-activity 1999-0875 578  
364PROTOCOL-ICMP IRDP router selection (more info ...)misc-activity 1999-0875 578  
365PROTOCOL-ICMP PING undefined code (more info ...)misc-activity    
368PROTOCOL-ICMP PING BSDtype (more info ...)misc-activity    
369PROTOCOL-ICMP PING BayRS Router (more info ...)misc-activity    
370PROTOCOL-ICMP PING BeOS4.x (more info ...)misc-activity    
371PROTOCOL-ICMP PING Cisco Type.x (more info ...)misc-activity    
372PROTOCOL-ICMP PING Delphi-Piette Windows (more info ...)misc-activity    
373PROTOCOL-ICMP PING Flowpoint2200 or Network Management Software (more info ...)misc-activity    
374PROTOCOL-ICMP PING IP NetMonitor Macintosh (more info ...)misc-activity    
375PROTOCOL-ICMP PING LINUX/*BSD (more info ...)misc-activity    
376PROTOCOL-ICMP PING Microsoft Windows (more info ...)misc-activity    
377PROTOCOL-ICMP PING Network Toolbox 3 Windows (more info ...)misc-activity    
378PROTOCOL-ICMP PING Ping-O-MeterWindows (more info ...)misc-activity    
379PROTOCOL-ICMP PING Pinger Windows (more info ...)misc-activity    
380PROTOCOL-ICMP PING Seer Windows (more info ...)misc-activity    
381PROTOCOL-ICMP PING Oracle Solaris (more info ...)misc-activity    
382PROTOCOL-ICMP PING Windows (more info ...)misc-activity    
385PROTOCOL-ICMP traceroute (more info ...)attempted-recon    
386PROTOCOL-ICMP Address Mask Reply (more info ...)misc-activity    
387PROTOCOL-ICMP Address Mask Reply undefined code (more info ...)misc-activity    
388PROTOCOL-ICMP Address Mask Request (more info ...)misc-activity    
389PROTOCOL-ICMP Address Mask Request undefined code (more info ...)misc-activity    
390PROTOCOL-ICMP Alternate Host Address (more info ...)misc-activity    
391PROTOCOL-ICMP Alternate Host Address undefined code (more info ...)misc-activity    
392PROTOCOL-ICMP Datagram Conversion Error (more info ...)misc-activity    
393PROTOCOL-ICMP Datagram Conversion Error undefined code (more info ...)misc-activity    
394PROTOCOL-ICMP Destination Unreachable Destination Host Unknown (more info ...)misc-activity    
395PROTOCOL-ICMP Destination Unreachable Destination Network Unknown (more info ...)misc-activity    
397PROTOCOL-ICMP Destination Unreachable Host Precedence Violation (more info ...)misc-activity    
398PROTOCOL-ICMP Destination Unreachable Host Unreachable for Type of Service (more info ...)misc-activity    
400PROTOCOL-ICMP Destination Unreachable Network Unreachable for Type of Service (more info ...)misc-activity    
401PROTOCOL-ICMP Destination Unreachable Network Unreachable (more info ...)misc-activity    
403PROTOCOL-ICMP Destination Unreachable Precedence Cutoff in effect (more info ...)misc-activity    
404PROTOCOL-ICMP Destination Unreachable Protocol Unreachable (more info ...)misc-activity 2005-0068   
405PROTOCOL-ICMP Destination Unreachable Source Host Isolated (more info ...)misc-activity    
406PROTOCOL-ICMP Destination Unreachable Source Route Failed (more info ...)misc-activity    
407PROTOCOL-ICMP Destination Unreachable cndefined code (more info ...)misc-activity    
411PROTOCOL-ICMP IPV6 I-Am-Here (more info ...)misc-activity    
412PROTOCOL-ICMP IPV6 I-Am-Here undefined code (more info ...)misc-activity    
413PROTOCOL-ICMP IPV6 Where-Are-You (more info ...)misc-activity    
414PROTOCOL-ICMP IPV6 Where-Are-You undefined code (more info ...)misc-activity    
415PROTOCOL-ICMP Information Reply (more info ...)misc-activity    
416PROTOCOL-ICMP Information Reply undefined code (more info ...)misc-activity    
417PROTOCOL-ICMP Information Request (more info ...)misc-activity    
418PROTOCOL-ICMP Information Request undefined code (more info ...)misc-activity    
419PROTOCOL-ICMP Mobile Host Redirect (more info ...)misc-activity    
420PROTOCOL-ICMP Mobile Host Redirect undefined code (more info ...)misc-activity    
421PROTOCOL-ICMP Mobile Registration Reply (more info ...)misc-activity    
422PROTOCOL-ICMP Mobile Registration Reply undefined code (more info ...)misc-activity    
423PROTOCOL-ICMP Mobile Registration Request (more info ...)misc-activity    
424PROTOCOL-ICMP Mobile Registration Request undefined code (more info ...)misc-activity    
425PROTOCOL-ICMP Parameter Problem Bad Length (more info ...)misc-activity    
426PROTOCOL-ICMP Parameter Problem Missing a Required Option (more info ...)misc-activity    
427PROTOCOL-ICMP Parameter Problem Unspecified Error (more info ...)misc-activity    
428PROTOCOL-ICMP Parameter Problem undefined Code (more info ...)misc-activity    
429PROTOCOL-ICMP Photuris Reserved (more info ...)misc-activity    
430PROTOCOL-ICMP Photuris Unknown Security Parameters Index (more info ...)misc-activity    
431PROTOCOL-ICMP Photuris Valid Security Parameters, But Authentication Failed (more info ...)misc-activity    
432PROTOCOL-ICMP Photuris Valid Security Parameters, But Decryption Failed (more info ...)misc-activity    
433PROTOCOL-ICMP Photuris undefined code! (more info ...)misc-activity    
436PROTOCOL-ICMP Redirect for TOS and Host (more info ...)misc-activity 1999-0265   
437PROTOCOL-ICMP Redirect for TOS and Network (more info ...)misc-activity 1999-0265   
438PROTOCOL-ICMP Redirect undefined code (more info ...)misc-activity 1999-0265   
439PROTOCOL-ICMP Reserved for Security Type 19 (more info ...)misc-activity    
440PROTOCOL-ICMP Reserved for Security Type 19 undefined code (more info ...)misc-activity    
441PROTOCOL-ICMP Router Advertisement (more info ...)misc-activity    
443PROTOCOL-ICMP Router Selection (more info ...)misc-activity    
445PROTOCOL-ICMP SKIP (more info ...)misc-activity    
446PROTOCOL-ICMP SKIP undefined code (more info ...)misc-activity    
448PROTOCOL-ICMP Source Quench undefined code (more info ...)misc-activity    
450PROTOCOL-ICMP Time-To-Live Exceeded in Transit undefined code (more info ...)misc-activity    
451PROTOCOL-ICMP Timestamp Reply (more info ...)misc-activity    
452PROTOCOL-ICMP Timestamp Reply undefined code (more info ...)misc-activity    
453PROTOCOL-ICMP Timestamp Request (more info ...)misc-activity    
454PROTOCOL-ICMP Timestamp Request undefined code (more info ...)misc-activity    
456PROTOCOL-ICMP Traceroute (more info ...)misc-activity    
457PROTOCOL-ICMP Traceroute undefined code (more info ...)misc-activity    
458PROTOCOL-ICMP unassigned type 1 (more info ...)misc-activity    
462PROTOCOL-ICMP unassigned type 7 (more info ...)misc-activity    
463PROTOCOL-ICMP unassigned type 7 undefined code (more info ...)misc-activity 1999-0454   
465PROTOCOL-ICMP ISS Pinger (more info ...)attempted-recon    
467PROTOCOL-ICMP Nemesis v1.1 Echo (more info ...)attempted-recon    
476PROTOCOL-ICMP webtrends scanner (more info ...)attempted-recon    
480PROTOCOL-ICMP PING speedera (more info ...)misc-activity    
481PROTOCOL-ICMP TJPingPro1.1Build 2 Windows (more info ...)misc-activity    
482PROTOCOL-ICMP PING WhatsupGold Windows (more info ...)misc-activity    
484PROTOCOL-ICMP PING Sniffer Pro/NetXRay network scan (more info ...)misc-activity    
1813PROTOCOL-ICMP digital island bandwidth query (more info ...)misc-activity    
1854PROTOCOL-ICMP Stacheldraht handler->agent niggahbitch (more info ...)attempted-dos 2000-0138   URL
1855PROTOCOL-ICMP Stacheldraht agent->handler skillz (more info ...)attempted-dos 2000-0138   URL
1856PROTOCOL-ICMP Stacheldraht handler->agent ficken (more info ...)attempted-dos 2000-0138   URL
1918PROTOCOL-ICMP SolarWinds IP scan attempt (more info ...)network-scan    
2462SERVER-OTHER Ethereal IGMP IGAP account overflow attempt (more info ...)attempted-admin 2004-0367 9952  
2463SERVER-OTHER Ethereal IGMP IGAP message overflow attempt (more info ...)attempted-admin 2004-0367 9952  
3626PROTOCOL-ICMP PATH MTU denial of service attempt (more info ...)attempted-dos 2004-1060 13124  
6128MALWARE-BACKDOOR dkangel runtime detection - icmp echo reply client-to-server (more info ...)trojan-activity    URL
8730PROTOCOL-ICMP record route rr denial of service attempt (more info ...)attempted-dos 2001-0752 870  
10107MALWARE-BACKDOOR icmp cmd 1.0 runtime detection - pslist (more info ...)trojan-activity    URL
10108MALWARE-BACKDOOR icmp cmd 1.0 runtime detection - pskill (more info ...)trojan-activity    URL
13288OS-WINDOWS Microsoft Windows remote kernel tcp/ip icmp vulnerability exploit attempt (more info ...)attempted-admin 2007-0066   URL
18249PROTOCOL-ICMP Microsoft Windows Ipv6pHandleRouterAdvertisement Route Information stack buffer overflow attempt (more info ...)attempted-admin 2010-0241   URL
18474PROTOCOL-ICMP ICMPv6 Echo Request (more info ...)misc-activity    
21853APP-DETECT ptunnel icmp proxy (more info ...)policy-violation    URL
23178PROTOCOL-ICMP IPv6 router advertisement flood attempt (more info ...)attempted-dos 2014-2309 65409  URL
24088MALWARE-CNC Win.Trojan.Bledoor TCP tunnel in ICMP (more info ...)trojan-activity    URL
24294PROTOCOL-ICMP IPv6 neighbor advertisement flood attempt (more info ...)misc-activity    URL
24295PROTOCOL-ICMP suspicious IPv6 router advertisement attempt (more info ...)attempted-admin    URL
24296PROTOCOL-ICMP IPv6 router advertisement invalid prefix option attempt (more info ...)misc-activity 2014-0254 65409  URL
24297PROTOCOL-ICMP IPv6 oversized ICMP ping attempt (more info ...)misc-activity    URL
24298PROTOCOL-ICMP IPv6 0xdeadbeef ICMP ping attempt (more info ...)misc-activity    URL
24299PROTOCOL-ICMP IPv6 invalid router advertisement attempt (more info ...)misc-activity    URL
24301PROTOCOL-ICMP IPv6 MLD multicast listener query attempt (more info ...)misc-activity    URL
24302PROTOCOL-ICMP IPv6 multicast neighbor delete attempt (more info ...)misc-activity    URL
24303PROTOCOL-ICMP IPv6 multicast neighbor add attempt (more info ...)misc-activity    URL
24305PROTOCOL-ICMP invalid ICMPv6 header attempt (more info ...)misc-activity    URL
25314OS-LINUX Linux kernel IGMP queries denial of service attempt (more info ...)denial-of-service 2012-0207   
26736MALWARE-CNC Win.Trojan.BlackRev cnc icmp command (more info ...)trojan-activity    URL
27610PROTOCOL-ICMP Truncated ICMPv6 denial of service attempt (more info ...)denial-of-service 2013-3182   URL
27611PROTOCOL-ICMP Truncated ICMPv6 denial of service attempt (more info ...)denial-of-service 2013-3182   URL
27624OS-WINDOWS Microsoft ICMPv6 mismatched prefix length and length field denial of service attempt (more info ...)denial-of-service 2013-3183   URL
28292PROTOCOL-ICMP IPv6 0xfacebabe ICMP ping attempt (more info ...)misc-activity    URL
28463MALWARE-CNC Win.Trojan.AllAple Variant ICMP flood (more info ...)trojan-activity    URL
29454PROTOCOL-ICMP Unusual L3retriever Ping detected (more info ...)successful-recon-limited    URL
29455PROTOCOL-ICMP Unusual Microsoft Windows Ping detected (more info ...)successful-recon-limited    URL
29457PROTOCOL-ICMP Unusual Microsoft Windows 7 Ping detected (more info ...)successful-recon-limited    URL
33927SERVER-OTHER Cisco IOS virtual routing and forwarding ICMP redirect denial of service attempt (more info ...)attempted-dos 2015-0638   URL
36650PROTOCOL-ICMP Squid Pinger IPv6 denial of service attempt (more info ...)attempted-dos 2014-7142   URL
36651PROTOCOL-ICMP Squid Pinger IPv6 denial of service attempt (more info ...)attempted-dos 2014-7142   URL
39065SERVER-OTHER Cisco IOS NX invalid ICMPv6 neighbor discovery hop limit denial of service attempt (more info ...)attempted-dos 2016-1409   URL
46126SERVER-OTHER Cisco IOS XE IGMP denial of service attempt (more info ...)attempted-dos 2018-0165   URL
46127SERVER-OTHER Cisco IOS XE IGMP denial of service attempt (more info ...)attempted-dos 2018-0165   URL
46128SERVER-OTHER Cisco IOS XE IGMP denial of service attempt (more info ...)attempted-dos 2018-0165   URL
47401INDICATOR-OBFUSCATION ICMP HTTP tunneling attempt (more info ...)misc-activity    URL
50165MALWARE-CNC Unix.Trojan.Winnti variant outbound ICMP connection (more info ...)trojan-activity    URL
90033OS-WINDOWS Microsoft Windows IppRateLimitIcmp integer overflow exploit attempt (more info ...)attempted-dos 2011-1871   URL

 goto Top

Group: Protocol Anomaly / ICMP

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Protocol Anomaly / IGMP

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Protocol Anomaly / RPC

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Protocol Anomaly / Misc

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Malware

# of attack rules in this group: 7727

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
610PROTOCOL-SERVICES rsh root (more info ...)attempted-admin  2012-6392  57221    URL
654SERVER-MAIL RCPT TO overflow (more info ...)attempted-admin  2010-2580  9696    
1409PROTOCOL-SNMP community string buffer overflow attempt (more info ...)misc-attack  2002-0013  4089    URL
1422PROTOCOL-SNMP community string buffer overflow attempt with evasion (more info ...)misc-attack  2002-0013  4089    URL
1634PROTOCOL-POP PASS overflow attempt (more info ...)attempted-admin  2006-6605  791  10325  
2551SERVER-OTHER Oracle Web Cache GET overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2552SERVER-OTHER Oracle Web Cache HEAD overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2553SERVER-OTHER Oracle Web Cache PUT overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2554SERVER-OTHER Oracle Web Cache POST overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2555SERVER-OTHER Oracle Web Cache TRACE overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2556SERVER-OTHER Oracle Web Cache DELETE overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2557SERVER-OTHER Oracle Web Cache LOCK overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2558SERVER-OTHER Oracle Web Cache MKCOL overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2559SERVER-OTHER Oracle Web Cache COPY overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2560SERVER-OTHER Oracle Web Cache MOVE overflow attempt (more info ...)attempted-admin  2004-0385  9868  12126  
2580SERVER-WEBAPP server negative Content-Length attempt (more info ...)attempted-admin  2004-0492  10508    URL
2597SERVER-WEBAPP Samba SWAT Authorization overflow attempt (more info ...)web-application-attack  2004-0600  10780    
2598SERVER-WEBAPP Samba SWAT Authorization port 901 overflow attempt (more info ...)web-application-attack  2004-0600  10780    
2673FILE-IMAGE libpng tRNS overflow attempt (more info ...)attempted-user  2004-0597  10872    
3085SERVER-OTHER AOL Instant Messenger goaway message buffer overflow attempt (more info ...)misc-attack  2004-0636  10889    
3517SERVER-OTHER Computer Associates license PUTOLF overflow attempt (more info ...)attempted-user  2005-0582  12705    
3824SERVER-MAIL AUTH user overflow attempt (more info ...)attempted-admin  2018-6789  13772    
4642SERVER-ORACLE sys.pbsde.init buffer overflow attempt (more info ...)attempted-user  2005-3438  15134    URL
4681SERVER-WEBAPP Symantec Antivirus admin scan interface negative Content-Length attempt (more info ...)attempted-admin  2005-2758  15001    
5316SERVER-OTHER CA CAM log_security overflow attempt (more info ...)misc-attack  2005-2668  14622    
6512SERVER-OTHER symantec antivirus realtime virusscan overflow attempt (more info ...)attempted-admin  2006-2630  18107    
7091MALWARE-BACKDOOR serveme runtime detection (more info ...)trojan-activity        URL
7096MALWARE-BACKDOOR remote hack 1.5 runtime detection - logon (more info ...)trojan-activity        URL
7097MALWARE-BACKDOOR remote hack 1.5 runtime detection - execute file (more info ...)trojan-activity        URL
7099MALWARE-BACKDOOR remote hack 1.5 runtime detection - start keylogger (more info ...)trojan-activity        URL
7105MALWARE-BACKDOOR aol admin runtime detection (more info ...)trojan-activity        URL
7108MALWARE-BACKDOOR undetected runtime detection (more info ...)trojan-activity        URL
7111MALWARE-BACKDOOR fearless lite 1.01 runtime detection (more info ...)trojan-activity        URL
7112MALWARE-BACKDOOR fearless lite 1.01 runtime detection (more info ...)trojan-activity        URL
7115MALWARE-BACKDOOR ghost 2.3 runtime detection (more info ...)trojan-activity        URL
8441SERVER-WEBAPP McAfee header buffer overflow attempt (more info ...)attempted-admin  2006-5156  20288    
9421MALWARE-OTHER zotob attempt (more info ...)trojan-activity  2005-1983  14513    URL
9422MALWARE-OTHER msblast attempt (more info ...)trojan-activity  2003-0352  8205    URL
9423MALWARE-OTHER lovegate attempt (more info ...)trojan-activity  2003-0352  8205    URL
9632SERVER-OTHER Tivoli Storage Manager command request buffer overflow attempt (more info ...)attempted-admin  2006-5855  21440    
9845FILE-IDENTIFY M3U file magic detected (more info ...)misc-activity        URL
10187SERVER-OTHER HP Mercury Loadrunner command line buffer overflow (more info ...)attempted-admin  2007-0446  22487    
11265SERVER-OTHER Sentinel license manager buffer overflow attempt (more info ...)attempted-admin  2020-10291  12742    
12362SERVER-WEBAPP Squid HTTP Proxy-Authorization overflow attempt (more info ...)attempted-user  2004-0541  10500    
12480MALWARE-OTHER Keylogger inside website logger 2.4 runtime detection (more info ...)successful-recon-limited        URL
12596SERVER-OTHER CA BrightStor LGServer username buffer overflow attempt (more info ...)attempted-admin  2007-5003  24348    
13221SERVER-OTHER Motorola Timbuktu crafted login request buffer overflow attempt (more info ...)attempted-admin  2007-4221  25454    URL
13222SERVER-OTHER Motorola Timbuktu crafted login request buffer overflow attempt (more info ...)attempted-admin  2007-4221  25454    URL
13365SERVER-OTHER Trend Micro ServerProtect TMregChange buffer overflow attempt (more info ...)attempted-admin  2007-4731      URL
13519SERVER-OTHER Citrix MetaFrame IMA buffer overflow attempt (more info ...)attempted-admin  2008-0356  27329    
13522SERVER-OTHER Firebird Database Server username handling buffer overflow (more info ...)attempted-admin  2008-0467  27467    
13584FILE-IDENTIFY CSV file download request (more info ...)misc-activity  2008-0112      URL
13715SERVER-WEBAPP HP OpenView Network Node Manager HTTP handling buffer overflow attempt (more info ...)attempted-admin  2008-1697  28569    
13718SERVER-MAIL BDAT buffer overflow attempt (more info ...)attempted-admin  2002-0055  4204    URL
13801FILE-IDENTIFY RTF file download request (more info ...)misc-activity        URL
13804SERVER-OTHER Borland Software InterBase ibserver.exe Service Attach Request buffer overflow attempt (more info ...)attempted-admin  2008-1910  28730    
13843SERVER-OTHER MaxDB WebDBM get buffer overflow (more info ...)attempted-admin  2006-4305  13843    
14017FILE-IDENTIFY MPEG Layer 3 playlist file download request (more info ...)misc-activity        URL
14769SERVER-OTHER DATAC RealWin SCADA System buffer overflow attempt (more info ...)attempted-user  2011-1563  46937    
15013FILE-IDENTIFY PDF file download request (more info ...)misc-activity        URL
15079FILE-IDENTIFY WAV file download request (more info ...)misc-activity        URL
15186SERVER-OTHER Multiple vendors CUPS HPGL filter remote code execution attempt (more info ...)attempted-user  2008-3641  31688    
15255SERVER-ORACLE Secure Backup msgid 0x901 username field overflow attempt (more info ...)attempted-admin  2008-5444  33177    
15261SERVER-ORACLE Secure Backup exec_qr command injection attempt (more info ...)attempted-user  2008-5448  33177    
15262SERVER-ORACLE Secure Backup POST exec_qr command injection attempt (more info ...)attempted-user  2008-5448  33177    
15422SERVER-OTHER Sun One web proxy server overflow attempt (more info ...)attempted-admin  2007-2881  24165    URL
15427FILE-IDENTIFY SVG file download request (more info ...)misc-activity        URL
15434SERVER-WEBAPP HP OpenView Network Node Manager OvOSLocale parameter buffer overflow attempt (more info ...)attempted-user  2009-0920  34134    
15436SERVER-OTHER IBM Tivoli Storage Manager Express Backup counter heap corruption attempt (more info ...)attempted-admin  2008-4563  34077    URL
15437SERVER-OTHER IBM Tivoli Storage Manager Express Backup message length heap corruption attempt (more info ...)attempted-admin  2008-4563  34077    URL
15477SERVER-WEBAPP Oracle BEA WebLogic overlong JESSIONID buffer overflow attempt (more info ...)misc-attack  2008-5457      
15479SERVER-OTHER RealNetworks Helix Server RTSP Request Proxy-Require header heap buffer overflow attempt (more info ...)attempted-admin  2008-5911  33059    
15489PUA-OTHER Cerulean Studios Trillian image filename handling XML tag overflow attempt (more info ...)attempted-user  2008-5401      
15516FILE-IDENTIFY AVI multimedia file download request (more info ...)misc-activity        URL
15554SERVER-ORACLE Application Server 10g OPMN service format string vulnerability exploit attempt (more info ...)attempted-admin  2009-0993  34461    
15571SERVER-OTHER RealNetworks Helix Server RTSP SETUP stack buffer overflow attempt (more info ...)attempted-admin  2008-5911  33059    
15573SERVER-OTHER RealNetworks Helix Server RTSP SET_PARAMETER heap buffer overflow attempt (more info ...)attempted-admin  2008-5911  33059    
15708SERVER-OTHER Unisys Business Information Server stack buffer overflow attempt (more info ...)attempted-admin  2009-1628  35494    
15726SERVER-WEBAPP HP OpenView Network Node Manager URI rping stack buffer overflow attempt (more info ...)attempted-user  2009-1420  35267    
15865FILE-IDENTIFY MP4 file download request (more info ...)misc-activity        URL
15900FILE-IDENTIFY Audio Interchange file download request (more info ...)misc-activity        
15943SERVER-OTHER CA Multiple Products Console Server login credentials handling overflow attempt (more info ...)attempted-user  2007-2522  23906    
15966FILE-OTHER F-Secure Anti-Virus LHA processing buffer overflow attempt (more info ...)attempted-user  2004-0234  10243    
15968SERVER-OTHER LANDesk Management Suite QIP service heal packet buffer overflow attempt (more info ...)attempted-admin  2008-2468  31193    URL
15970SERVER-OTHER Subversion svn pProtocol string parsing heap overflow attempt (more info ...)attempted-admin  2004-0413  10519    
15972SERVER-OTHER single byte encoded name response (more info ...)misc-attack  2004-0444      
15978SERVER-WEBAPP Macromedia JRun 4 mod_jrun buffer overflow attempt (more info ...)attempted-user  2004-0646  11245    
15986SERVER-SAMBA Samba unicode filename buffer overflow attempt (more info ...)misc-attack  2004-0882  11678    
15987FILE-IDENTIFY DXF file download request (more info ...)misc-activity        URL
16001FILE-IMAGE Apple QuickDraw PICT images ARGB records handling memory corruption attempt (more info ...)attempted-user  2007-0462  22207    
16015SERVER-OTHER Norton Internet Security NBNS response processing stack overflow attempt (more info ...)attempted-admin  2004-0444  10333    
16080SERVER-OTHER KAME racoon X509 certificate verification bypass attempt (more info ...)attempted-user  2004-0607  10546    
16191SERVER-ORACLE Oracle Secure Backup Administration server authentication bypass attempt - via GET (more info ...)attempted-admin  2009-1977  35672    URL
16192SERVER-ORACLE Secure Backup Administration server authentication bypass attempt (more info ...)attempted-admin  2010-0904  41596    URL
16196SERVER-OTHER Symantec Backup Exec System Recovery Manager unauthorized file upload attempt (more info ...)misc-activity  2008-0457      
16204SERVER-OTHER HP OpenView Network Node Manager ovlaunch host field overflow attempt (more info ...)attempted-user  2008-4562  33668    
16205FILE-IDENTIFY BMP file download request (more info ...)misc-activity        URL
16217SERVER-OTHER OpenView Network Node Manager ovalarmsrv opcode 45 integer overflow attempt (more info ...)attempted-admin  2008-2438  34738    
16286FILE-IDENTIFY TrueType font file download request (more info ...)misc-activity        URL
16296FILE-OTHER Kaspersky antivirus library heap buffer overflow - with optional fields (more info ...)attempted-user  2005-3142  14998    
16332SERVER-OTHER Symantec System Center Alert Management System untrusted command execution attempt (more info ...)policy-violation  2009-1431  34675    
16438SERVER-ORACLE WebLogic Server Node Manager arbitrary command execution attempt (more info ...)attempted-admin  2010-0073  37926    URL
16444SERVER-OTHER HP StorageWorks storage mirroring double take service code execution attempt (more info ...)attempted-admin  2008-1661      URL
16486MALWARE-BACKDOOR Arucer backdoor traffic - command execution attempt (more info ...)trojan-activity  2010-0103      URL
16487MALWARE-BACKDOOR Arucer backdoor traffic - yes command attempt (more info ...)trojan-activity  2010-0103      URL
16488MALWARE-BACKDOOR Arucer backdoor traffic - write file attempt (more info ...)trojan-activity  2010-0103      URL
16514SERVER-OTHER Trillian AIM XML tag handling heap buffer overflow attempt (more info ...)attempted-user  2008-5403  32645    URL
16529FILE-IDENTIFY JPEG file download request (more info ...)misc-activity        URL
16555SERVER-WEBAPP HP Openview Network Node Manager OvAcceptLang overflow attempt (more info ...)attempted-user  2009-0921  34134    
16601FILE-OTHER Amaya web editor XML and HTML Parser Buffer overflow attempt (more info ...)attempted-user  2009-0323  33047    
16604SERVER-WEBAPP HP OpenView Network Node Manager ovalarm.exe Accept-Language buffer overflow attempt (more info ...)attempted-user  2009-4179  37261    
16685SERVER-OTHER IBM Tivoli Storage Manager Client dsmagent.exe NodeName length buffer overflow attempt (more info ...)attempted-admin  2008-4828  34803    URL
16798FILE-OTHER Orbit Downloader long URL buffer overflow attempt (more info ...)attempted-user  2009-0187      
17229FILE-IDENTIFY Tiff little endian file magic detected (more info ...)misc-activity        URL
17230FILE-IDENTIFY Tiff big endian file magic detected (more info ...)misc-activity        URL
17259FILE-IDENTIFY MOV file download request (more info ...)misc-activity        URL
17305FILE-OTHER ClamAV libclamav PE file handling integer overflow attempt (more info ...)attempted-user  2008-0318      
17314FILE-IDENTIFY OLE document file magic detected (more info ...)misc-activity        
17380FILE-IDENTIFY PNG file download request (more info ...)misc-activity        
17394FILE-IDENTIFY GIF file download request (more info ...)misc-activity        
17396SERVER-OTHER VNC client authentication response (more info ...)protocol-command-decode        
17397SERVER-OTHER VNCViewer Authenticate buffer overflow attempt (more info ...)attempted-user  2009-0388  33568    
17441FILE-IDENTIFY LNK file download request (more info ...)misc-activity        
17445SERVER-OTHER Symantec Backup Exec System Recovery Manager unauthorized file upload attempt (more info ...)misc-activity  2008-0457      URL
17530SERVER-OTHER HP OpenView Storage Data Protector Stack Buffer Overflow (more info ...)attempted-admin  2007-2881      
17536SERVER-WEBAPP generic server HTTP Auth Header buffer overflow attempt (more info ...)attempted-user  2009-0183  33554    
17540FILE-IDENTIFY LZH file download request (more info ...)misc-activity        
17625SERVER-ORACLE Database Core RDBMS component denial of service attempt (more info ...)attempted-dos  2007-5530  26108    
17632PROTOCOL-SNMP Castle Rock Computing SNMPc Network Manager community string attempted stack overflow (more info ...)attempted-admin  2008-2214  28990    
17693SERVER-MAIL MailEnable NTLM Authentication buffer overflow attempt (more info ...)attempted-admin  2006-5176  20290    URL
17697POLICY-SOCIAL GnuPG Message Packet Length overflow attempt (more info ...)attempted-user  2006-3746      URL
17723OS-WINDOWS possible SMB replay attempt - overlapping encryption keys detected (more info ...)attempted-user  2010-0231      URL
17732FILE-IDENTIFY TIFF file download request (more info ...)misc-activity        URL
17733FILE-IDENTIFY XML file download request (more info ...)misc-activity        
17751FILE-IDENTIFY OpenType Font file download request (more info ...)misc-activity        
18097BROWSER-PLUGINS VMWare Remote Console format string code execution attempt (more info ...)attempted-user  2009-3732      
18234FILE-IDENTIFY QuickDraw/PICT file download request (more info ...)misc-activity        
18248SERVER-OTHER Unisys Business Information Server stack buffer overflow attempt (more info ...)attempted-admin  2009-1628  35494    
18327PROTOCOL-SCADA Kingview HMI heap overflow attempt (more info ...)attempted-admin  2011-0406  45727    
18475SERVER-WEBAPP HP Openview OvWebHelp.exe buffer overflow (more info ...)attempted-admin  2009-4178  37340    URL
18480SERVER-WEBAPP HP openview network node manager ovlogin.exe buffer overflow - userid parameter (more info ...)attempted-admin  2009-4176  37330    URL
18587SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 267 buffer overflow attempt (more info ...)attempted-admin  2007-2280  37396    URL
18648PROTOCOL-SCADA IGSS IGSSDataServer.exe file upload/download attempt (more info ...)attempted-user  2011-1567  46936    
18651PROTOCOL-SCADA IGSS IGSSDataServer.exe report template overflow attempt (more info ...)attempted-admin  2011-1567  46936    
18654PROTOCOL-SCADA IGSS IGSSDataServer.exe format string attempt (more info ...)attempted-admin  2011-1568  46936    
18656PROTOCOL-SCADA IGSS IGSSDataServer.exe strep overflow attempt (more info ...)attempted-admin  2011-1567  46936    
18659PROTOCOL-SCADA RealWin 2.1 SCPC_INITIALIZE overflow attempt (more info ...)attempted-admin  2010-4142  44150    
18745SERVER-WEBAPP HP Power Manager formExportDataLogs buffer overflow attempt (more info ...)attempted-user  2009-3999  37866    
18751SERVER-WEBAPP Samba SWAT HTTP Authentication overflow attempt (more info ...)attempted-user  2004-0600  10780    
18754SERVER-OTHER HP Data Protector Backup Client Service code execution attempt (more info ...)suspicious-filename-detect  2011-0922      
18795SERVER-WEBAPP HP OpenView Network Node Manager ovet_demandpoll.exe format string execution attempt (more info ...)attempted-admin  2010-1550  40065    
18802SERVER-WEBAPP HP Power Manager formExportDataLogs directory traversal attempt (more info ...)web-application-attack  2009-4000  37866    
18926PROTOCOL-SNMP Multiple vendors AgentX receive_agentx integer overflow attempt (more info ...)attempted-admin  2010-1319  39561    
18930SERVER-WEBAPP HP OpenView Network Node Manager nnmRptConfig.exe Template format string code execution attempt (more info ...)attempted-user  2011-0270  45762    
18999SERVER-WEBAPP HP OpenView NNM webappmon.exe buffer overflow attempt (more info ...)attempted-admin  2010-2703  41829    
19104SERVER-OTHER HP OpenView Storage Data Protector Cell Manager heap overflow attempt (more info ...)attempted-admin  2007-2281  37386    
19105SERVER-OTHER HP Data Protector Manager MMD service buffer overflow attempt (more info ...)attempted-admin    45128    
19136SERVER-WEBAPP CA XOsoft Multiple Products entry_point.aspx buffer overflow attempt (more info ...)attempted-user  2010-1223  39238    URL
19211FILE-IDENTIFY ZIP archive file download request (more info ...)misc-activity        
19289FILE-IDENTIFY MHTML file download request (more info ...)misc-activity        URL
19430FILE-IDENTIFY MIDI file download request (more info ...)misc-activity        
19649SERVER-OTHER HP Intelligent Management Center dbman buffer overflow attempt (more info ...)attempted-admin  2011-1850  47789    
19747MALWARE-BACKDOOR Win.Trojan.GGDoor.22 variant outbound connection (more info ...)trojan-activity        URL
19812SERVER-OTHER CA Total Defense Suite UNCWS getDBConfigSettings credential information disclosure attempt (more info ...)attempted-admin  2011-0406  47356    
19907FILE-IDENTIFY PICT file magic detected (more info ...)misc-activity        
19938SERVER-OTHER IBM Tivoli Directory Server ibmslapd.exe stack buffer overflow attempt (more info ...)attempted-admin  2011-1206      URL
19998PUA-ADWARE IP address disclosure to advertisement sites attempt (more info ...)policy-violation        URL
20052PROTOCOL-SCADA IntelliCom NetBiter config utility hostname overflow attempt (more info ...)attempted-admin  2009-4462  37325    URL
20134SERVER-OTHER HP OpenView Storage Data Protector buffer overflow attempt (more info ...)attempted-admin  2011-1865  48486    
20135SERVER-OTHER HP OpenView Storage Data Protector buffer overflow attempt (more info ...)attempted-admin  2011-1865  48486    
20176PROTOCOL-SCADA DAQFactory NETB protcol stack overflow attempt (more info ...)attempted-admin  2011-3492      URL
20179SERVER-WEBAPP HP OpenView NNM ovlogin.exe userid parameter buffer overflow attempt (more info ...)attempted-user  2009-3846  37295    URL
20180SERVER-WEBAPP HP OpenView NNM ovlogin.exe passwd parameter buffer overflow attempt (more info ...)attempted-user  2009-3846  37295    URL
20214PROTOCOL-SCADA Measuresoft ScadaPro msvcrt.dll local command execution attempt (more info ...)attempted-admin  2011-3497      
20450FILE-IDENTIFY MPEG video stream file magic detected (more info ...)misc-activity        
20451FILE-IDENTIFY MPEG sys stream file magic detected (more info ...)misc-activity        
20459FILE-IDENTIFY GIF file magic detected (more info ...)misc-activity        
20463FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
20464FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
20465FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
20466FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
20467FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
20468FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
20469FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
20471FILE-IDENTIFY RIFX file magic detected (more info ...)misc-activity        
20477FILE-IDENTIFY ELF file magic detected (more info ...)misc-activity        
20478FILE-IDENTIFY PNG file magic detected (more info ...)misc-activity        
20480FILE-IDENTIFY JPEG file magic detection (more info ...)misc-activity        
20483FILE-IDENTIFY JPEG file magic detected (more info ...)misc-activity        
20486FILE-IDENTIFY RTF file magic detected (more info ...)misc-activity        
20493FILE-IDENTIFY jarpack file magic detected (more info ...)misc-activity        
20494FILE-IDENTIFY PDF file magic detected (more info ...)misc-activity        
20500FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20501FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20502FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20503FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20532SERVER-WEBAPP HP OpenView Storage Data Protector get file buffer overflow attempt (more info ...)attempted-user  2011-1729      
20611SERVER-OTHER BOOTP overflow (more info ...)attempted-admin  1999-0799      
20621FILE-IDENTIFY JAR file download request (more info ...)misc-activity        
20761SERVER-OTHER HP OpenView Storage Data Protector buffer overflow attempt (more info ...)attempted-admin  2011-1865  48486    
20812PROTOCOL-TELNET FreeBSD telnetd enc_keyid overflow attempt (more info ...)attempted-admin  2011-4862  51182    URL
20813PROTOCOL-TELNET FreeBSD telnetd dec_keyid overflow attempt (more info ...)attempted-admin  2011-4862  51182    URL
20839FILE-IDENTIFY eSignal .quo file download request (more info ...)misc-activity        URL
20840FILE-IDENTIFY eSignal .por file download request (more info ...)misc-activity        URL
20841FILE-IDENTIFY eSignal .sum file download request (more info ...)misc-activity        URL
20842FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
20843FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
20874SERVER-OTHER IBM Tivoli Storage Manager Express Backup initialization packet (more info ...)protocol-command-decode        
20897FILE-IDENTIFY MIDI file magic detected (more info ...)misc-activity        
20898FILE-IDENTIFY MIDI file attachment detected (more info ...)misc-activity        
20899FILE-IDENTIFY MIDI file attachment detected (more info ...)misc-activity        
20907FILE-IDENTIFY DXF file attachment detected (more info ...)misc-activity        
20908FILE-IDENTIFY DXF file attachment detected (more info ...)misc-activity        
20950FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20951FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20952FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20953FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20954FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20955FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20956FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20957FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20958FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20959FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
20961FILE-IDENTIFY TTE file download request (more info ...)misc-activity        URL
20962FILE-IDENTIFY OTF file download request (more info ...)misc-activity        URL
20963FILE-IDENTIFY DIB file download request (more info ...)misc-activity        URL
20965FILE-IDENTIFY JPEG file download request (more info ...)misc-activity        URL
20966FILE-IDENTIFY JPEG file download request (more info ...)misc-activity        URL
20967FILE-IDENTIFY JPEG file download request (more info ...)misc-activity        URL
20969FILE-IDENTIFY M4A file download request (more info ...)misc-activity        URL
20970FILE-IDENTIFY M4P file download request (more info ...)misc-activity        URL
20971FILE-IDENTIFY M4R file download request (more info ...)misc-activity        URL
20972FILE-IDENTIFY M4V file magic request (more info ...)misc-activity        URL
20973FILE-IDENTIFY M4B file download request (more info ...)misc-activity        URL
20974FILE-IDENTIFY 3GP file download request (more info ...)misc-activity        URL
20975FILE-IDENTIFY 3G2 file download request (more info ...)misc-activity        URL
20976FILE-IDENTIFY K3G file download request (more info ...)misc-activity        URL
20977FILE-IDENTIFY SKM file download request (more info ...)misc-activity        URL
20978FILE-IDENTIFY TTE file attachment detected (more info ...)misc-activity        
20979FILE-IDENTIFY TTE file attachment detected (more info ...)misc-activity        
20980FILE-IDENTIFY OTF file attachment detected (more info ...)misc-activity        
20981FILE-IDENTIFY OTF file attachment detected (more info ...)misc-activity        
20991FILE-IDENTIFY TTF file magic detected (more info ...)misc-activity        
21035FILE-IDENTIFY PDF file attachment detected (more info ...)misc-activity        
21036FILE-IDENTIFY PDF file attachment detected (more info ...)misc-activity        
21044EXPLOIT-KIT Blackhole exploit kit landing page (more info ...)attempted-user  2012-4681      URL
21045EXPLOIT-KIT Blackhole exploit kit landing page (more info ...)attempted-user  2012-4681      URL
21059FILE-IDENTIFY AVI Video file magic detected (more info ...)misc-activity        
21068EXPLOIT-KIT Eleanore exploit kit landing page (more info ...)trojan-activity  2011-3544      URL
21069EXPLOIT-KIT Eleanore exploit kit exploit fetch request (more info ...)trojan-activity  2011-3544      URL
21070EXPLOIT-KIT Eleanore exploit kit pdf exploit page request (more info ...)trojan-activity  2011-3544      URL
21071EXPLOIT-KIT Eleanore exploit kit post-exploit page request (more info ...)trojan-activity  2011-3544      URL
21096EXPLOIT-KIT Crimepack exploit kit control panel access (more info ...)policy-violation  2010-0806      
21097EXPLOIT-KIT Crimepack exploit kit post-exploit download request (more info ...)successful-user  2010-0806      
21098EXPLOIT-KIT Crimepack exploit kit landing page (more info ...)attempted-user  2010-0806      
21099EXPLOIT-KIT Crimepack exploit kit malicious pdf request (more info ...)attempted-user  2010-0806      
21104MALWARE-TOOLS slowhttptest DoS tool (more info ...)attempted-dos        URL
21108EXPLOIT-KIT unknown exploit kit obfuscated landing page (more info ...)attempted-user        URL
21109FILE-IDENTIFY MPEG video stream file download request (more info ...)misc-activity        
21110FILE-IDENTIFY MPEG video stream file attachment detected (more info ...)misc-activity        
21111FILE-IDENTIFY MPEG video stream file attachment detected (more info ...)misc-activity        
21141EXPLOIT-KIT Blackhole exploit kit control panel access (more info ...)policy-violation  2012-4681      URL
21234SERVER-WEBAPP MKCOL Webdav Stack Buffer Overflow attempt (more info ...)attempted-admin  2010-0361  37874    
21236SERVER-WEBAPP UNLOCK Webdav Stack Buffer Overflow attempt (more info ...)attempted-admin  2010-0361  37874    
21247SERVER-OTHER IBM Lotusnotes s_viewname buffer overflow attempt (more info ...)web-application-attack  2003-0178  6871    
21259EXPLOIT-KIT Blackhole exploit kit response (more info ...)attempted-user  2012-4681      URL
21282FILE-IDENTIFY XSL file download request (more info ...)misc-activity        URL
21283FILE-IDENTIFY XSL file attachment detected (more info ...)misc-activity        URL
21284FILE-IDENTIFY XSL file attachment detected (more info ...)misc-activity        URL
21285FILE-IDENTIFY XSLT file download request (more info ...)misc-activity        URL
21286FILE-IDENTIFY XSLT file attachment detected (more info ...)misc-activity        URL
21287FILE-IDENTIFY XSLT file attachment detected (more info ...)misc-activity        URL
21288FILE-IDENTIFY XML download detected (more info ...)misc-activity        
21343EXPLOIT-KIT Blackhole exploit kit pdf request (more info ...)suspicious-filename-detect  2012-4681      URL
21344EXPLOIT-KIT Blackhole exploit kit pdf download (more info ...)attempted-user  2012-4681      URL
21345EXPLOIT-KIT Blackhole exploit kit malicious jar request (more info ...)suspicious-filename-detect  2012-4681      URL
21346EXPLOIT-KIT Blackhole exploit kit malicious jar download (more info ...)attempted-user  2012-4681      URL
21349SERVER-OTHER HP OpenView Storage Data Protector stack overflow attempt (more info ...)attempted-admin  2009-3844  37250    
21350SERVER-OTHER HP OpenView Storage Data Protector stack overflow attempt (more info ...)attempted-admin  2009-3844  37250    
21407SERVER-OTHER Symantic multiple products VRTSweb code execution (more info ...)attempted-admin  2009-3027  37012    URL
21410FILE-IDENTIFY paq8o file download request (more info ...)misc-activity        
21411FILE-IDENTIFY paq8o file attachment detected (more info ...)misc-activity        
21412FILE-IDENTIFY paq8o file attachment detected (more info ...)misc-activity        
21429FILE-PDF Possible unknown malicious PDF (more info ...)attempted-user  2010-0188      
21453FILE-PDF Possible unknown malicious PDF (more info ...)attempted-user  2010-0188      
21480FILE-IDENTIFY XML file magic detected (more info ...)misc-activity        
21488APP-DETECT User-Agent known user agent - GetRight (more info ...)trojan-activity        URL
21492EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - prototype catch (more info ...)attempted-user  2012-4681      URL
21498FILE-IDENTIFY XML file magic detected (more info ...)misc-activity        
21499FILE-IDENTIFY XML file attachment detected (more info ...)misc-activity        
21500FILE-IDENTIFY XML file attachment detected (more info ...)misc-activity        
21509EXPLOIT-KIT Sakura exploit kit rhino jar request (more info ...)attempted-user  2011-3544      URL
21510EXPLOIT-KIT Sakura exploit kit logo transfer (more info ...)string-detect        URL
21517SERVER-WEBAPP JBoss admin-console access (more info ...)attempted-recon  2013-2185      URL
21539EXPLOIT-KIT Blackhole exploit kit landing page with specific header (more info ...)attempted-user  2012-4681      URL
21549EXPLOIT-KIT Blackhole exploit kit landing page with specific header (more info ...)attempted-user  2012-4681      URL
21581EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - BBB (more info ...)attempted-user  2012-4681      URL
21613FILE-IDENTIFY PNG file attachment detected (more info ...)misc-activity        
21614FILE-IDENTIFY PNG file attachment detected (more info ...)misc-activity        
21620FILE-IDENTIFY WAV file magic detected (more info ...)misc-activity        
21623FILE-IDENTIFY QUO file attachment detected (more info ...)misc-activity        
21624FILE-IDENTIFY QUO file attachment detected (more info ...)misc-activity        
21625FILE-IDENTIFY POR file attachment detected (more info ...)misc-activity        
21626FILE-IDENTIFY POR file attachment detected (more info ...)misc-activity        
21627FILE-IDENTIFY SUM file attachment detected (more info ...)misc-activity        
21628FILE-IDENTIFY SUM file attachment detected (more info ...)misc-activity        
21640EXPLOIT-KIT Phoenix exploit kit landing page (more info ...)attempted-user  2012-0779      
21646EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - prototype catch (more info ...)attempted-user  2012-4681      URL
21648FILE-IDENTIFY QuickDraw/PICT file attachment detected (more info ...)misc-activity        
21649FILE-IDENTIFY QuickDraw/PICT file attachment detected (more info ...)misc-activity        
21650FILE-IDENTIFY QuickDraw/PICT file download request (more info ...)misc-activity        
21651FILE-IDENTIFY QuickDraw/PICT file attachment detected (more info ...)misc-activity        
21652FILE-IDENTIFY QuickDraw/PICT file attachment detected (more info ...)misc-activity        
21657EXPLOIT-KIT Blackhole exploit kit landing page - specific structure (more info ...)trojan-activity  2012-4681      URL
21658EXPLOIT-KIT Blackhole exploit kit landing page (more info ...)trojan-activity  2012-4681      URL
21661EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - catch (more info ...)attempted-user  2012-4681      URL
21678EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
21679EXPLOIT-KIT Bleeding Life exploit kit module call attempt (more info ...)attempted-user        URL
21680EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
21681EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
21682EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
21683EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
21684EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
21685EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
21686EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
21709FILE-IDENTIFY AIFF file attachment detected (more info ...)misc-activity        
21710FILE-IDENTIFY AIFF file attachment detected (more info ...)misc-activity        
21711FILE-IDENTIFY PFA file download request (more info ...)misc-activity        
21712FILE-IDENTIFY PFA file magic detected (more info ...)misc-activity        
21713FILE-IDENTIFY PFA file attachment detected (more info ...)misc-activity        
21714FILE-IDENTIFY PFA file attachment detected (more info ...)misc-activity        
21715FILE-IDENTIFY PFB file download request (more info ...)misc-activity        
21716FILE-IDENTIFY PFB file attachment detected (more info ...)misc-activity        
21717FILE-IDENTIFY PFB file attachment detected (more info ...)misc-activity        
21718FILE-IDENTIFY PFM file download request (more info ...)misc-activity        
21719FILE-IDENTIFY PFM file attachment detected (more info ...)misc-activity        
21720FILE-IDENTIFY PFM file attachment detected (more info ...)misc-activity        
21721FILE-IDENTIFY AFM file download request (more info ...)misc-activity        
21722FILE-IDENTIFY AFM file attachment detected (more info ...)misc-activity        
21723FILE-IDENTIFY AFM file attachment detected (more info ...)misc-activity        
21728FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21729FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21730FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21731FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21732FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21733FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21734FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21735FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21736FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21737FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21738FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21739FILE-IDENTIFY JPG file attachment detected (more info ...)misc-activity        
21744FILE-IDENTIFY AVI file attachment detected (more info ...)misc-activity        
21745FILE-IDENTIFY AVI file attachment detected (more info ...)misc-activity        
21746FILE-IDENTIFY RTF file attachment detected (more info ...)misc-activity        
21747FILE-IDENTIFY RTF file attachment detected (more info ...)misc-activity        
21766FILE-IMAGE Apple QuickDraw PICT images ARGB records handling memory corruption attempt (more info ...)attempted-user  2007-0462  22207    
21806SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      
21815FILE-IDENTIFY LZH file attachment detected (more info ...)misc-activity        
21816FILE-IDENTIFY LZH file attachment detected (more info ...)misc-activity        
21845MALWARE-OTHER TDS Sutra - redirect received (more info ...)trojan-activity        URL
21851MALWARE-OTHER TDS Sutra - redirect received (more info ...)trojan-activity        URL
21854FILE-IDENTIFY LNK file attachment detected (more info ...)misc-activity        
21855FILE-IDENTIFY LNK file attachment detected (more info ...)misc-activity        
21856FILE-IDENTIFY ZIP file attachment detected (more info ...)misc-activity        
21857FILE-IDENTIFY ZIP file attachment detected (more info ...)misc-activity        
21861FILE-IDENTIFY WRF file attachment detected (more info ...)misc-activity        
21862FILE-IDENTIFY WRF file attachment detected (more info ...)misc-activity        
21872FILE-IDENTIFY GIF file attachment detected (more info ...)misc-activity        
21873FILE-IDENTIFY GIF file attachment detected (more info ...)misc-activity        
21874EXPLOIT-KIT Possible exploit kit post compromise activity - StrReverse (more info ...)successful-user  2012-4681      
21875EXPLOIT-KIT Possible exploit kit post compromise activity - taskkill (more info ...)successful-user  2012-4681      
21876EXPLOIT-KIT Blackhole exploit landing page with specific structure - Loading (more info ...)trojan-activity  2012-4681      URL
21886FILE-IDENTIFY OpenType Font file attachment detected (more info ...)misc-activity        
21887FILE-IDENTIFY OpenType Font file attachment detected (more info ...)misc-activity        
21894FILE-IDENTIFY SVG file attachment detected (more info ...)misc-activity        
21895FILE-IDENTIFY SVG file attachment detected (more info ...)misc-activity        
21908FILE-IDENTIFY Portable Executable file attachment detected (more info ...)misc-activity        
21909FILE-IDENTIFY Portable Executable file attachment detected (more info ...)misc-activity        
21938PROTOCOL-TELNET RuggedCom default backdoor login attempt (more info ...)attempted-admin  2012-1803      URL
21939PROTOCOL-TELNET RuggedCom telnet initial banner (more info ...)misc-activity        
21940FILE-IDENTIFY EMF file magic detected (more info ...)misc-activity        
21949MALWARE-OTHER nikjju script injection (more info ...)misc-activity        URL
21999FILE-IDENTIFY OpenType Font file magic detection (more info ...)misc-activity        
22004SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22005SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22006SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22007SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22008SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22009SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22010SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22011SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22012SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
22039EXPLOIT-KIT Blackhole suspected landing page (more info ...)attempted-user  2012-4681      URL
22040EXPLOIT-KIT Blackhole suspected landing page (more info ...)attempted-user  2012-4681      URL
22041EXPLOIT-KIT Blackhole landing redirection page (more info ...)attempted-user  2012-4681      URL
22061MALWARE-OTHER Alureon - Malicious IFRAME load attempt (more info ...)trojan-activity        URL
22095MALWARE-BACKDOOR Win.Backdoor.Agent variant outbound connection (more info ...)trojan-activity        URL
22949EXPLOIT-KIT Blackhole redirection attempt (more info ...)attempted-user  2012-4681      URL
22952SERVER-OTHER Iron Mountain connected backup opcode 13 processing command injection attempt (more info ...)misc-attack  2011-2397  50884    
22971FILE-IDENTIFY MPEG Layer 3 playlist file attachment detected (more info ...)misc-activity        
22972FILE-IDENTIFY m3u playlist file file attachment detected (more info ...)misc-activity        
22993FILE-IDENTIFY MP4 file attachment detected (more info ...)misc-activity        
22994FILE-IDENTIFY MP4 file attachment detected (more info ...)misc-activity        
22997FILE-IDENTIFY MHTML file attachment detected (more info ...)misc-activity        
22998FILE-IDENTIFY MHTML file attachment detected (more info ...)misc-activity        
23002FILE-IDENTIFY CSV file attachment detected (more info ...)misc-activity        
23003FILE-IDENTIFY CSV file attachment detected (more info ...)misc-activity        
23056SERVER-OTHER SAP NetWeaver Dispatcher DiagTraceR3Info buffer overflow attempt (more info ...)attempted-admin  2012-2611  53424    
23058MALWARE-OTHER NeoSploit Malvertising - URI Requested (more info ...)trojan-activity        
23141EXPLOIT-KIT Fake transaction redirect page to exploit kit (more info ...)attempted-user        URL
23147EXPLOIT-KIT Suspicious taskkill script - StrReverse (more info ...)attempted-user        URL
23148EXPLOIT-KIT Suspicious StrReverse - Shell (more info ...)attempted-user        URL
23149EXPLOIT-KIT Suspicious StrReverse - Scripting.FileSystemObject (more info ...)attempted-user        URL
23156EXPLOIT-KIT Nuclear Pack exploit kit landing page (more info ...)bad-unknown  2012-4681      URL
23157EXPLOIT-KIT Nuclear Pack exploit kit binary download (more info ...)trojan-activity  2012-4681      URL
23158EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - prototype catch (more info ...)attempted-user  2012-4681      URL
23159EXPLOIT-KIT Blackhole exploit kit landing page download attempt (more info ...)attempted-user  2012-4681      URL
23167FILE-IDENTIFY MPG video stream file download request (more info ...)misc-activity        
23168FILE-IDENTIFY MPG video stream file attachment detected (more info ...)misc-activity        
23169FILE-IDENTIFY MPG video stream file attachment detected (more info ...)misc-activity        
23180FILE-PDF obfuscated header in PDF attachment (more info ...)misc-activity        URL
23182SERVER-OTHER Joomla com_maqmahelpdesk task parameter local file inclusion attempt (more info ...)attempted-user        
23218EXPLOIT-KIT Redkit Repeated Exploit Request Pattern (more info ...)trojan-activity  2012-4681      URL
23221EXPLOIT-KIT Redkit Jar File Naming Algorithm (more info ...)trojan-activity  2013-2423      URL
23222EXPLOIT-KIT Redkit exploit kit landing page Received - applet and 5 digit jar attempt (more info ...)trojan-activity  2013-2423      URL
23223EXPLOIT-KIT Redkit exploit kit landing page Received - applet and code (more info ...)trojan-activity  2013-2423      URL
23224EXPLOIT-KIT Redkit exploit kit landing page Requested - 8Digit.html (more info ...)trojan-activity  2013-2423      URL
23225EXPLOIT-KIT Redkit exploit kit landing page Received - applet and flowbit (more info ...)trojan-activity  2013-2423      URL
23240SERVER-SAMBA Samba malicious user defined array size and buffer attempt (more info ...)attempted-admin  2012-1182      URL
23322FILE-IDENTIFY TAR file download request (more info ...)misc-activity        
23341MALWARE-BACKDOOR Win.Backdoor.Tinrot.A runtime detection (more info ...)trojan-activity        URL
23355SERVER-OTHER Trend Micro Control Manager AddTask stack buffer overflow attempt (more info ...)attempted-user  2011-5001      
23486FILE-IDENTIFY JOB file download request (more info ...)misc-activity        
23487FILE-IDENTIFY JOB file attachment detected (more info ...)misc-activity        
23488FILE-IDENTIFY JOB file attachment detected (more info ...)misc-activity        
23520FILE-PDF Possible unknown malicious PDF (more info ...)attempted-user  2010-0188      
23521FILE-PDF Possible unknown malicious PDF (more info ...)attempted-user  2010-0188      
23577FILE-OTHER VLC mms hostname buffer overflow attempt (more info ...)attempted-user  2012-1775      URL
23618MALWARE-OTHER Malvertising redirection attempt (more info ...)trojan-activity        URL
23619EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - prototype catch broken (more info ...)attempted-user  2012-4681      URL
23620MALWARE-OTHER Malvertising network attempted redirect (more info ...)trojan-activity        URL
23622EXPLOIT-KIT Blackhole exploit kit landing page request - tkr (more info ...)trojan-activity  2012-4681      URL
23624SERVER-OTHER Ubisoft Uplay browser plugin backdoor attempt (more info ...)attempted-user  2012-4177      URL
23632SERVER-OTHER HP Data Protector Express stack buffer overflow attempt (more info ...)attempted-admin  2012-0124  52431    
23639FILE-IDENTIFY MPEG video stream file magic detected (more info ...)misc-activity        
23640FILE-IDENTIFY MPEG sys stream file magic detected (more info ...)misc-activity        
23647FILE-IDENTIFY GIF file magic detected (more info ...)misc-activity        
23651FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
23652FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
23653FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
23654FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
23655FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
23656FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
23657FILE-IDENTIFY JAR/ZIP file magic detected (more info ...)misc-activity        
23658FILE-IDENTIFY RIFX file magic detected (more info ...)misc-activity        
23663FILE-IDENTIFY ELF file magic detected (more info ...)misc-activity        
23664FILE-IDENTIFY PNG file magic detected (more info ...)misc-activity        
23667FILE-IDENTIFY JPEG file magic detected (more info ...)misc-activity        
23670FILE-IDENTIFY RTF file magic detected (more info ...)misc-activity        
23677FILE-IDENTIFY jarpack file magic detected (more info ...)misc-activity        
23678FILE-IDENTIFY PDF file magic detected (more info ...)misc-activity        
23682FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23683FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23684FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23685FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23709FILE-IDENTIFY Tiff little endian file magic detected (more info ...)misc-activity        URL
23710FILE-IDENTIFY Tiff big endian file magic detected (more info ...)misc-activity        URL
23711FILE-IDENTIFY OLE Document file magic detected (more info ...)misc-activity        
23723FILE-IDENTIFY M3U file magic detected (more info ...)misc-activity        URL
23725FILE-IDENTIFY Portable Executable binary file magic detected (more info ...)misc-activity        
23729FILE-IDENTIFY PICT file magic detected (more info ...)misc-activity        
23735FILE-IDENTIFY MIDI file magic detected (more info ...)misc-activity        
23738FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23739FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23740FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23741FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23742FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23743FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23744FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23745FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23746FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23747FILE-IDENTIFY MOV file magic detected (more info ...)misc-activity        
23748FILE-IDENTIFY TTF file magic detected (more info ...)misc-activity        
23754FILE-IDENTIFY AVI Video file magic detected (more info ...)misc-activity        
23758FILE-IDENTIFY XML file magic detected (more info ...)misc-activity        
23759FILE-IDENTIFY XML file magic detected (more info ...)misc-activity        
23760FILE-IDENTIFY WAV file magic detected (more info ...)misc-activity        
23762FILE-IDENTIFY PFA file magic detected (more info ...)misc-activity        
23766FILE-IDENTIFY EMF file magic detected (more info ...)misc-activity        
23781EXPLOIT-KIT Blackhole exploit kit landing page (more info ...)trojan-activity  2012-4681      
23785EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - Math.floor catch (more info ...)attempted-user  2012-4681      
23786EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - Math.round catch (more info ...)attempted-user  2012-4681      
23797EXPLOIT-KIT Blackhole redirection page (more info ...)trojan-activity  2012-4681      URL
23798MALWARE-OTHER Malvertising redirection page (more info ...)trojan-activity        URL
23805BROWSER-WEBKIT WebKit button column memory corruption attempt (more info ...)attempted-user  2012-1520  54680    
23807FILE-IDENTIFY JPEG2000 file download request (more info ...)misc-activity        
23808FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23809FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23810FILE-IDENTIFY JPEG2000 file download request (more info ...)misc-activity        
23811FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23812FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23813FILE-IDENTIFY JPEG2000 file download request (more info ...)misc-activity        
23814FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23815FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23816FILE-IDENTIFY JPEG2000 file download request (more info ...)misc-activity        
23817FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23818FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23819FILE-IDENTIFY JPEG2000 file download request (more info ...)misc-activity        
23820FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23821FILE-IDENTIFY JPEG2000 file attachment detected (more info ...)misc-activity        
23822FILE-IDENTIFY JPEG2000 file magic detected (more info ...)misc-activity        
23823FILE-IDENTIFY JPEG2000 file magic detected (more info ...)misc-activity        
23833MALWARE-OTHER Malvertising redirection campaign - blackmuscat (more info ...)trojan-activity        URL
23848EXPLOIT-KIT Blackhole redirection attempt (more info ...)attempted-user  2012-4681      URL
23849EXPLOIT-KIT Blackhole redirection attempt (more info ...)attempted-user  2012-4681      URL
23850EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - hwehes (more info ...)trojan-activity  2012-4681      URL
23962EXPLOIT-KIT Blackhole exploit kit landing page with specific structure - fewbgazr catch (more info ...)attempted-user  2012-4681      
23964PROTOCOL-SCADA BroadWin WebAccess Client format string exploit attempt (more info ...)attempted-user  2012-0242      URL
23965PROTOCOL-SCADA BroadWin WebAccess Client arbitrary memory corruption attempt (more info ...)attempted-user  2012-0242      URL
23979SERVER-OTHER HP Data Protector Express stack buffer overflow attempt (more info ...)attempted-admin  2012-0124  52431    
23980SERVER-OTHER HP Data Protector Express stack buffer overflow attempt (more info ...)attempted-admin  2012-0124  52431    
23981SERVER-OTHER HP Data Protector Express stack buffer overflow attempt (more info ...)attempted-admin  2012-0124  52431    
23982SERVER-OTHER HP Data Protector Express stack buffer overflow attempt (more info ...)attempted-admin  2012-0124  52431    
23983SERVER-OTHER HP Data Protector Express stack buffer overflow attempt (more info ...)attempted-admin  2012-0124  52431    
24053EXPLOIT-KIT Blackhole exploit kit landing page with specific structure (more info ...)attempted-user  2012-4681      
24054EXPLOIT-KIT Blackhole exploit kit landing page with specific structure (more info ...)attempted-user  2012-4681      
24099MALWARE-OTHER Malvertising redirection attempt (more info ...)trojan-activity        URL
24115MALWARE-BACKDOOR Win.Backdoor.Demtranc variant outbound connection (more info ...)trojan-activity        URL
24116MALWARE-BACKDOOR Win.Backdoor.Demtranc variant outbound connection (more info ...)trojan-activity        URL
24117MALWARE-BACKDOOR Win.Backdoor.Demtranc variant outbound connection (more info ...)trojan-activity        URL
24118MALWARE-BACKDOOR Win.Backdoor.Demtranc variant outbound connection (more info ...)trojan-activity        URL
24119MALWARE-BACKDOOR Win.Backdoor.Demtranc variant outbound connection (more info ...)trojan-activity        URL
24120MALWARE-BACKDOOR Win.Backdoor.Demtranc variant outbound connection (more info ...)trojan-activity        URL
24121MALWARE-BACKDOOR Win.Backdoor.Demtranc variant outbound connection (more info ...)trojan-activity        URL
24122MALWARE-BACKDOOR Win.Backdoor.Demtranc variant outbound connection (more info ...)trojan-activity        URL
24143MALWARE-OTHER Dorifel/Quervar/XDocCrypt query for machine name KASPERSKY (more info ...)trojan-activity        URL
24144MALWARE-OTHER Dorifel/Quervar/XDocCrypt download (more info ...)trojan-activity        URL
24145MALWARE-OTHER Dorifel/Quervar/XDocCrypt sent over email (more info ...)trojan-activity        URL
24147SERVER-WEBAPP HP OpenView Network Node Manager nnmRptConfig.exe multiple parameters buffer overflow attempt (more info ...)attempted-user  2011-0269  45762    
24199SERVER-MAIL IBM Lotus Notes URI handler command execution attempt (more info ...)attempted-user  2012-2174  54070    
24200SERVER-MAIL IBM Lotus Notes URI handler command execution attempt (more info ...)attempted-user  2012-2174  54070    
24206FILE-IDENTIFY LZH archive file magic detected (more info ...)misc-activity  2011-1213  48018    
24213FILE-IDENTIFY MP4 file magic detected (more info ...)misc-activity        
24221SERVER-OTHER HP Data Protector client EXEC_CMD command execution attempt (more info ...)attempted-user  2011-0923  46234    
24222SERVER-OTHER HP Data Protector client EXEC_CMD command execution attempt (more info ...)attempted-user  2011-0923  46234    
24223SERVER-OTHER HP Data Protector client EXEC_CMD command execution attempt (more info ...)attempted-user  2011-0923  46234    
24225MALWARE-OTHER malicious redirection attempt (more info ...)bad-unknown        URL
24226EXPLOIT-KIT Blackholev2 exploit kit landing page received (more info ...)trojan-activity  2012-4681      
24228EXPLOIT-KIT Blackholev2 exploit kit landing page Received (more info ...)misc-activity  2012-4681      
24231EXPLOIT-KIT Crimeboss exploit kit redirection attempt (more info ...)trojan-activity  2012-4681      
24232EXPLOIT-KIT Crimeboss exploit kit outbound connection (more info ...)trojan-activity  2012-4681      
24233EXPLOIT-KIT Crimeboss exploit kit outbound connection (more info ...)trojan-activity  2012-4681      
24234EXPLOIT-KIT Crimeboss exploit kit outbound connection (more info ...)trojan-activity  2012-4681      
24257MALWARE-OTHER mygeeksmail.dll download (more info ...)trojan-activity        URL
24258MALWARE-OTHER mygeeksmail.dll download (more info ...)trojan-activity        URL
24261MALWARE-OTHER Lanman2.dll download (more info ...)trojan-activity        URL
24262MALWARE-OTHER Lanman2.dll download (more info ...)trojan-activity        URL
24265MALWARE-OTHER Malicious UA detected on non-standard port (more info ...)trojan-activity        URL
24311MALWARE-OTHER Win.Trojan.Downloader download (more info ...)trojan-activity        URL
24312MALWARE-OTHER Win.Trojan.Downloader inbound email (more info ...)trojan-activity        URL
24342SERVER-WEBAPP JBoss web console access attempt (more info ...)attempted-recon  2013-2185      URL
24343SERVER-WEBAPP JBoss JMXInvokerServlet access attempt (more info ...)attempted-admin  2013-2185      URL
24344EXPLOIT-KIT Unknown exploit kit redirection page (more info ...)trojan-activity        URL
24408MALWARE-OTHER Win.Trojan.Miniflame download attempt (more info ...)trojan-activity        URL
24409MALWARE-OTHER Win.Trojan.Miniflame download attempt (more info ...)trojan-activity        URL
24410MALWARE-OTHER Win.Trojan.Gauss download attempt (more info ...)trojan-activity        URL
24411MALWARE-OTHER Win.Trojan.Gauss download attempt (more info ...)trojan-activity        URL
24425PROTOCOL-SCADA Sinapsi command injection attempt (more info ...)web-application-attack        URL
24455FILE-IDENTIFY JPEG file magic detected (more info ...)misc-activity        
24456FILE-IDENTIFY JPEG file magic detected (more info ...)misc-activity        
24457FILE-IDENTIFY JPEG file magic detected (more info ...)misc-activity        
24458FILE-IDENTIFY JPEG file magic detected (more info ...)misc-activity        
24463FILE-IDENTIFY TIFF file attachment detected (more info ...)misc-activity        
24464FILE-IDENTIFY TIFF file attachment detected (more info ...)misc-activity        
24472FILE-IDENTIFY FLV file attachment detected (more info ...)misc-activity        
24473FILE-IDENTIFY FLV file attachment detected (more info ...)misc-activity        
24480PROTOCOL-SCADA WellinTech Kingview HMI history server buffer overflow attempt (more info ...)attempted-admin  2011-4536      
24501EXPLOIT-KIT Blackholev2 exploit kit fallback executable download (more info ...)trojan-activity  2012-4681      URL
24515MALWARE-OTHER Win.Trojan.Lucuis malware file download (more info ...)trojan-activity        URL
24516MALWARE-OTHER Win.Trojan.Lucuis malware file download (more info ...)trojan-activity        URL
24530MALWARE-BACKDOOR Win.Trojan.Ransomlock runtime detection (more info ...)trojan-activity        URL
24536SERVER-OTHER HP Intelligent Management Center uam.exe stack buffer overflow attempt (more info ...)attempted-admin  2012-3274  55271    
24537SERVER-OTHER HP Intelligent Management Center uam.exe stack buffer overflow attempt (more info ...)attempted-admin  2012-3274  55271    
24538SERVER-OTHER HP Intelligent Management Center uam.exe stack buffer overflow attempt (more info ...)attempted-admin  2012-3274  55271    
24543EXPLOIT-KIT Blackhole admin page inbound access attempt (more info ...)misc-activity  2012-4681      
24544EXPLOIT-KIT Blackhole admin page outbound access attempt (more info ...)misc-activity  2012-4681      
24546EXPLOIT-KIT Blackholev2 exploit kit landing page download attempt (more info ...)trojan-activity  2012-4681      URL
24547EXPLOIT-KIT Blackhole exploit kit landing page download attempt (more info ...)trojan-activity  2012-4681      
24548EXPLOIT-KIT Blackhole exploit kit landing page download attempt (more info ...)trojan-activity  2012-4681      
24589MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24590MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24591MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24592MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24593EXPLOIT-KIT Blackholev2 exploit kit landing page received - specific structure (more info ...)trojan-activity  2012-4681      
24594MALWARE-OTHER Win.Trojan.MiniFlame C&C command response attempt (more info ...)trojan-activity        URL
24600MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24601MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24602MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24603MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24604MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24605MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24606MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24607MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24608EXPLOIT-KIT Blackholev2 exploit kit landing page download attempt (more info ...)trojan-activity  2012-4681      URL
24609MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24610MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24611MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24612MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24613MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24614MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24615MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24616MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24617MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24618MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24619MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24620MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24621MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24622MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
24636EXPLOIT-KIT Blackholev2 exploit kit redirection page - specific structure (more info ...)trojan-activity  2012-4681      
24637EXPLOIT-KIT Blackholev2 exploit kit redirection page - specific structure (more info ...)trojan-activity  2012-4681      
24638EXPLOIT-KIT Blackholev2 exploit kit redirection successful (more info ...)trojan-activity  2012-4681      
24647SERVER-WEBAPP D-Link Wireless Router CAPTCHA data processing buffer overflow attempt (more info ...)attempted-admin    56330    
24727MALWARE-OTHER HTML.Exploit.C99 suspicious file download (more info ...)trojan-activity        URL
24785EXPLOIT-KIT CritX exploit kit possible redirection attempt (more info ...)trojan-activity        URL
24788EXPLOIT-KIT CritX exploit kit PDF Exploit request structure (more info ...)trojan-activity        URL
24789EXPLOIT-KIT CritX exploit kit PDF Exploit download attempt (more info ...)trojan-activity        URL
24790EXPLOIT-KIT CritX exploit kit Portable Executable request (more info ...)trojan-activity        URL
24791EXPLOIT-KIT CritX exploit kit Portable Executable download (more info ...)trojan-activity        URL
24794EXPLOIT-KIT Multiple exploit kit Class download attempt (more info ...)trojan-activity        
24795EXPLOIT-KIT Multiple exploit kit Class download attempt (more info ...)trojan-activity        
24796EXPLOIT-KIT Multiple exploit kit Class download attempt (more info ...)trojan-activity        
24797EXPLOIT-KIT Multiple exploit kit Class download attempt (more info ...)trojan-activity        
24799MALWARE-OTHER OSX.Trojan.Imuler suspicious download (more info ...)trojan-activity        URL
24800MALWARE-OTHER OSX.Trojan.Imuler suspicious download (more info ...)trojan-activity        URL
24802SERVER-OTHER HP Database Archiving Software GIOP parsing buffer overflow attempt (more info ...)attempted-user  2011-4164      
24816FILE-IDENTIFY MP4 file magic detected (more info ...)misc-activity        
24817FILE-IDENTIFY MP4 file magic detected (more info ...)misc-activity        
24820FILE-IDENTIFY Computer Graphics Metafile file download request (more info ...)misc-activity        
24821FILE-IDENTIFY Computer Graphics Metafile file attachment detected (more info ...)misc-activity        
24822FILE-IDENTIFY Computer Graphics Metafile file attachment detected (more info ...)misc-activity        
24839EXPLOIT-KIT Sweet Orange exploit kit landing page - specific structure (more info ...)trojan-activity  2012-4681      URL
24840EXPLOIT-KIT Sweet Orange exploit kit landing page - JAR redirection (more info ...)trojan-activity  2012-4681      URL
24841EXPLOIT-KIT Sibhost exploit kit outbound JAR download attempt (more info ...)trojan-activity  2013-1493      
24860EXPLOIT-KIT Blackholev2 exploit kit landing page - specific-structure (more info ...)trojan-activity  2013-0431      
24861EXPLOIT-KIT Blackholev2 exploit kit landing page in an email (more info ...)trojan-activity  2013-0431      
24862EXPLOIT-KIT Blackholev2 exploit kit landing page - specific-structure (more info ...)trojan-activity  2013-0431      
24863EXPLOIT-KIT Blackholev2 exploit kit landing page in an email (more info ...)trojan-activity  2013-0431      
24864EXPLOIT-KIT Blackholev2 exploit kit landing page - specific-structure (more info ...)trojan-activity  2013-0431      
24865EXPLOIT-KIT Blackholev2 exploit kit landing page in an email (more info ...)trojan-activity  2013-0431      
24883MALWARE-OTHER Compromised website response - leads to Exploit Kit (more info ...)misc-activity        URL
24884MALWARE-OTHER Compromised website response - leads to Exploit Kit (more info ...)misc-activity        URL
24888EXPLOIT-KIT Nuclear exploit kit landing page detected (more info ...)trojan-activity  2012-4681      
24898SERVER-OTHER ABB Multiple Product RobNetScanHost.exe buffer overflow attempt (more info ...)attempted-admin  2012-0245      URL
24899MALWARE-OTHER Compromised Website response - leads to Exploit Kit (more info ...)misc-activity        URL
24900MALWARE-OTHER HTML.Exploit.C99 suspicious file download (more info ...)trojan-activity        URL
24901FILE-IDENTIFY JNLP file download request (more info ...)misc-activity        
24902FILE-IDENTIFY JNLP file attachment detected (more info ...)misc-activity        
24903FILE-IDENTIFY JNLP file attachment detected (more info ...)misc-activity        
24907SERVER-ORACLE Oracle Secure Backup exec_qr command injection attempt (more info ...)attempted-user  2008-5448      
24913SERVER-WEBAPP HP OpenView NNM ovutil.dll getProxiedStorageAddress buffer overflow attempt (more info ...)attempted-user  2010-1961  40638    
24914SERVER-WEBAPP HP OpenView NNM ovutil.dll getProxiedStorageAddress buffer overflow attempt (more info ...)attempted-user  2010-1961  40638    
24977EXPLOIT-KIT ProPack exploit kit outbound connection attempt (more info ...)trojan-activity        URL
24978EXPLOIT-KIT ProPack exploit kit outbound payload request (more info ...)trojan-activity        URL
24979EXPLOIT-KIT ProPack exploit kit outbound connection (more info ...)trojan-activity        URL
25001MALWARE-OTHER Win.Trojan.Narilam variant outbound connection (more info ...)trojan-activity        URL
25002MALWARE-OTHER Win.Trojan.Narilam variant inbound attachemtn (more info ...)trojan-activity        URL
25003SERVER-OTHER HP Archive Query Server stack overflow attempt (more info ...)attempted-admin  2011-4163      
25015MALWARE-BACKDOOR Arucer backdoor traffic - NOP command attempt (more info ...)trojan-activity  2010-0103      URL
25018MALWARE-OTHER connection to malware sinkhole (more info ...)trojan-activity        URL
25031MALWARE-OTHER Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity        URL
25043EXPLOIT-KIT Blackholev2 exploit kit url structure detected (more info ...)trojan-activity  2012-4681      
25044EXPLOIT-KIT Sweet Orange exploit kit landing page - specific structure (more info ...)trojan-activity  2012-4681      URL
25048EXPLOIT-KIT CritX exploit kit PDF Library exploit download (more info ...)trojan-activity        URL
25051EXPLOIT-KIT Redkit exploit kit landing page redirection (more info ...)trojan-activity  2012-4681      
25053EXPLOIT-KIT Redkit outbound class retrieval (more info ...)trojan-activity  2012-4681      
25059SERVER-OTHER SAP Business One License Manager buffer overflow attempt (more info ...)attempted-admin  2009-4988  35933    
25084MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
25085MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
25086MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
25087MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
25088MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
25089MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
25090MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
25091MALWARE-OTHER Win.Exploit.Hacktool suspicious file download (more info ...)trojan-activity        URL
25092MALWARE-OTHER Win.Exploit.Hacktool variant outbound connection (more info ...)trojan-activity        URL
25094MALWARE-OTHER PERL.Exploit.C99 suspicious file download (more info ...)trojan-activity        URL
25095MALWARE-OTHER HTML.Exploit.C99 suspicious file download (more info ...)trojan-activity        URL
25136EXPLOIT-KIT Styx exploit kit plugin detection connection (more info ...)trojan-activity  2013-2423      URL
25137EXPLOIT-KIT Styx exploit kit jar outbound connection (more info ...)trojan-activity  2013-2423      URL
25138EXPLOIT-KIT Styx exploit kit pdf outbound connection (more info ...)trojan-activity  2013-2423      URL
25139EXPLOIT-KIT Styx exploit kit eot outbound connection (more info ...)trojan-activity  2013-2423      URL
25140EXPLOIT-KIT Styx exploit kit portable executable download request (more info ...)trojan-activity  2013-2423      URL
25255EXPLOIT-KIT Redkit exploit kit redirection attempt (more info ...)trojan-activity  2013-2423      
25270FILE-OTHER overly large XML file MSXML heap overflow attempt (more info ...)attempted-user  2013-0006      URL
25275FILE-OTHER MSXML dynamic pointer casting arbitrary code execution attempt (more info ...)attempted-user  2013-0007      URL
25277MALWARE-OTHER Request for a non-legit postal receipt (more info ...)misc-activity        URL
25278MALWARE-BACKDOOR possible Htran setup command - listen (more info ...)trojan-activity        URL
25279MALWARE-BACKDOOR possible Htran setup command - slave (more info ...)trojan-activity        URL
25280MALWARE-BACKDOOR possible Htran setup command - tran (more info ...)trojan-activity        URL
25281MALWARE-BACKDOOR Htran banner (more info ...)trojan-activity        URL
25282MALWARE-BACKDOOR possible Htran setup command - listen (more info ...)trojan-activity        URL
25283MALWARE-BACKDOOR possible Htran setup command - slave (more info ...)trojan-activity        URL
25284MALWARE-BACKDOOR possible Htran setup command - tran (more info ...)trojan-activity        URL
25302EXPLOIT-KIT Multiple exploit kit malicious jar archive download (more info ...)attempted-user  2013-0422  57246    URL
25318SERVER-WEBAPP InduSoft Web Studio arbitrary file upload attempt (more info ...)attempted-admin  2011-4051  50675    
25319SERVER-WEBAPP InduSoft Web Studio arbitrary file upload attempt (more info ...)attempted-admin  2011-4051  50675    
25347FILE-IMAGE ImageMagick EXIF resolutionunit handling memory corruption attempt (more info ...)attempted-user  2012-0247      
25348FILE-IMAGE ImageMagick EXIF resolutionunit handling memory corruption attempt (more info ...)attempted-user  2012-0247      
25383EXPLOIT-KIT Multiple exploit kit Payload detection - info.exe (more info ...)trojan-activity  2012-4681      URL
25384EXPLOIT-KIT Multiple exploit kit Payload detection - contacts.exe (more info ...)trojan-activity  2012-4681      URL
25385EXPLOIT-KIT Multiple exploit kit Payload detection - calc.exe (more info ...)trojan-activity  2012-4681      URL
25386EXPLOIT-KIT Multiple exploit kit Payload detection - about.exe (more info ...)trojan-activity  2012-4681      URL
25387EXPLOIT-KIT Multiple exploit kit Payload detection - readme.exe (more info ...)trojan-activity  2012-4681      URL
25388EXPLOIT-KIT Blackholev2 exploit kit redirection successful (more info ...)trojan-activity  2012-4681      
25389EXPLOIT-KIT Sweet Orange exploit kit landing page - specific structure (more info ...)trojan-activity  2012-4681      
25390EXPLOIT-KIT Sweet Orange exploit kit landing page - specific structure (more info ...)trojan-activity  2012-4681      
25391EXPLOIT-KIT Sweet Orange exploit kit obfuscated payload download (more info ...)trojan-activity  2012-4681      URL
25451INDICATOR-OBFUSCATION GIF header followed by PDF header (more info ...)misc-activity  2013-0624      URL
25452INDICATOR-OBFUSCATION PNG header followed by PDF header (more info ...)misc-activity  2013-0624      URL
25453INDICATOR-OBFUSCATION JPEG header followed by PDF header (more info ...)misc-activity  2013-0624      URL
25454INDICATOR-OBFUSCATION DOC header followed by PDF header (more info ...)misc-activity  2013-0624      URL
25455INDICATOR-OBFUSCATION GIF header followed by PDF header (more info ...)misc-activity  2013-0624      URL
25456INDICATOR-OBFUSCATION PNG header followed by PDF header (more info ...)misc-activity  2013-0624      URL
25457INDICATOR-OBFUSCATION JPEG header followed by PDF header (more info ...)misc-activity  2013-0624      URL
25458INDICATOR-OBFUSCATION DOC header followed by PDF header (more info ...)misc-activity  2013-0624      URL
25460FILE-PDF Multiple products incomplete JP2K image geometry potentially malicious PDF detected (more info ...)misc-activity  2016-3319      URL
25461FILE-PDF OpenType parsing buffer overflow attempt (more info ...)attempted-user  2013-0604      
25462FILE-PDF OpenType parsing buffer overflow attempt (more info ...)attempted-user  2013-0604      
25463FILE-PDF OpenType parsing buffer overflow attempt (more info ...)attempted-user  2013-0604      
25464FILE-PDF OpenType parsing buffer overflow attempt (more info ...)attempted-user  2013-0604      
25513FILE-IDENTIFY Portable Executable download detected (more info ...)misc-activity        
25514FILE-IDENTIFY Portable Executable download detected (more info ...)misc-activity        
25515FILE-IDENTIFY Portable Executable binary file magic detected (more info ...)misc-activity        
25534SERVER-WEBAPP Sonicwall Global Management System authentication bypass attempt (more info ...)attempted-admin  2013-1359  57445    
25538EXPLOIT-KIT Red Dot landing page (more info ...)trojan-activity  2013-0422      URL
25540EXPLOIT-KIT Red Dot executable retrieval attempt (more info ...)trojan-activity  2013-0422      URL
25558EXPLOIT-KIT embedded iframe redirection - possible exploit kit redirection (more info ...)trojan-activity        
25559EXPLOIT-KIT JDB exploit kit landing page retrieval (more info ...)trojan-activity        URL
25560EXPLOIT-KIT JDB exploit kit landing page (more info ...)trojan-activity        URL
25561EXPLOIT-KIT JDB exploit kit landing page (more info ...)trojan-activity        URL
25568EXPLOIT-KIT Blackhole exploit kit landing page retrieval (more info ...)trojan-activity  2012-4681      
25569EXPLOIT-KIT Blackholev2 exploit kit landing page (more info ...)trojan-activity  2012-4681      
25578MALWARE-OTHER Fake postal receipt HTTP Response phishing attack (more info ...)trojan-activity        URL
25579MALWARE-OTHER Fake bookinginfo HTTP Response phishing attack (more info ...)trojan-activity        URL
25580MALWARE-OTHER Fake bookingdetails HTTP Response phishing attack (more info ...)trojan-activity        URL
25581SERVER-OTHER EMC AlphaStor Device Manager command injection attempt (more info ...)attempted-admin  2013-0928  57472    
25582SERVER-OTHER EMC AlphaStor Device Manager command injection attempt (more info ...)attempted-admin  2013-0928  57472    
25583SERVER-OTHER EMC AlphaStor Device Manager command injection attempt (more info ...)attempted-admin  2013-0928  57472    
25584SERVER-OTHER EMC AlphaStor Device Manager command injection attempt (more info ...)attempted-admin  2013-0928  57472    
25585SERVER-OTHER EMC AlphaStor Device Manager command injection attempt (more info ...)attempted-admin  2013-0928  57472    
25589SERVER-OTHER libupnp command buffer overflow attempt (more info ...)attempted-admin  2012-5962      
25590EXPLOIT-KIT Blackholev2 exploit kit landing page - specific structure (more info ...)trojan-activity  2013-0431      
25591EXPLOIT-KIT Blackhole exploit kit landing page - specific structure (more info ...)trojan-activity  2013-0431      
25592INDICATOR-OBFUSCATION obfuscated document command - used in IFRAMEr tool injection (more info ...)trojan-activity        URL
25601SERVER-OTHER libupnp command buffer overflow attempt (more info ...)attempted-admin  2012-5961      
25611EXPLOIT-KIT Blackholev2 exploit kit redirection successful (more info ...)trojan-activity  2012-4681      
25612SERVER-OTHER libupnp command buffer overflow attempt (more info ...)attempted-admin  2012-5960      
25617SERVER-OTHER libupnp command buffer overflow attempt (more info ...)attempted-admin  2012-5965      
25618SERVER-OTHER libupnp command buffer overflow attempt (more info ...)attempted-admin  2012-5964      
25619SERVER-OTHER libupnp command buffer overflow attempt (more info ...)attempted-admin  2012-5963      
25620SERVER-OTHER libupnp command buffer overflow attempt (more info ...)attempted-admin  2012-5959      
25654SERVER-OTHER HP OpenView Storage Data Protector exec_cmd buffer overflow attempt (more info ...)attempted-admin  2011-1866  48488    
25655SERVER-OTHER HP OpenView Storage Data Protector exec_cmd buffer overflow attempt (more info ...)attempted-admin  2011-1866  48488    
25656SERVER-OTHER HP OpenView Storage Data Protector exec_cmd buffer overflow attempt (more info ...)attempted-admin  2011-1866  48488    
25780SERVER-OTHER MiniUPnPd ExecuteSoapAction buffer overflow attempt (more info ...)attempted-admin  2013-1462      
25798EXPLOIT-KIT Multiple exploit kit 32-alpha jar request (more info ...)trojan-activity  2012-4681      
25801EXPLOIT-KIT Stamp exploit kit jar file request (more info ...)trojan-activity  2013-0431      URL
25803EXPLOIT-KIT Multiple exploit kit jar file dropped (more info ...)trojan-activity        URL
25804EXPLOIT-KIT Whitehole exploit kit malicious jar download attempt (more info ...)trojan-activity  2013-2423      URL
25806EXPLOIT-KIT Whitehole exploit kit landing page (more info ...)trojan-activity  2013-2423      URL
25808EXPLOIT-KIT Fiesta exploit kit landing page detection - specific-structure (more info ...)trojan-activity  2012-4681      
25821EXPLOIT-KIT CritX exploit kit possible plugin detection attempt (more info ...)trojan-activity        URL
25822EXPLOIT-KIT CritX exploit kit malicious PDF retrieval (more info ...)trojan-activity        URL
25824EXPLOIT-KIT CritX exploit kit malicious payload retrieval (more info ...)trojan-activity        URL
25849PROTOCOL-SCADA Schneider Electric IGSS integer underflow attempt (more info ...)attempted-user  2013-0657      
25851PROTOCOL-SCADA Schneider Electric IGSS integer underflow attempt (more info ...)attempted-user  2013-0657      
25852PROTOCOL-SCADA Schneider Electric IGSS integer underflow attempt (more info ...)attempted-user  2013-0657      
25869MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25870MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25871MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25872MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25873MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25874MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25875MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25876MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25877MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25878MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25879MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25880MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25881MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25882MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25883MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25884MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25885MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25886MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25887MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25888MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25889MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25890MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25891MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25892MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25893MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25894MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25895MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25896MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25897MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25898MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25899MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25900MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25901MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25902MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25903MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25904MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25905MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25906MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25908MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25909MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25910MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25911MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25912MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25913MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25914MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25915MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25916MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25917MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25918MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25919MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25920MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25921MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25922MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25923MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25924MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25925MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25926MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25927MALWARE-TOOLS Dirt Jumper toolkit variant http flood attempt (more info ...)attempted-dos        URL
25948EXPLOIT-KIT redirection to driveby download (more info ...)trojan-activity        
25972EXPLOIT-KIT Redkit exploit kit three number PDF Request (more info ...)trojan-activity  2012-4681      
25981APP-DETECT Chocoplayer successful installation (more info ...)misc-activity        URL
25988EXPLOIT-KIT Redkit exploit kit landing page (more info ...)trojan-activity  2013-2423      
25989EXPLOIT-KIT Redkit exploit kit landing page (more info ...)trojan-activity  2013-2423      
26013EXPLOIT-KIT Gong Da exploit kit redirection page received (more info ...)trojan-activity  2013-1493      
26020EXPLOIT-KIT Sibhost exploit kit (more info ...)trojan-activity        URL
26030FILE-OTHER Known malicious jar archive download attempt (more info ...)attempted-admin  2013-1493  58238    
26031EXPLOIT-KIT Blackholev2 exploit kit landing page (more info ...)trojan-activity  2013-0431      
26033EXPLOIT-KIT Blackholev2 exploit kit iframe redirection attempt (more info ...)trojan-activity  2013-0431      
26034EXPLOIT-KIT Crimeboss exploit kit - stats access (more info ...)trojan-activity        URL
26040EXPLOIT-KIT Crimeboss exploit kit - Portable Executable download attempt (more info ...)trojan-activity        URL
26041EXPLOIT-KIT Crimeboss exploit kit - Portable Executable download attempt (more info ...)trojan-activity        URL
26042EXPLOIT-KIT Crimeboss exploit kit - stats loaded (more info ...)trojan-activity        URL
26043EXPLOIT-KIT Crimeboss exploit kit - Portable Executable download attempt (more info ...)trojan-activity        URL
26044EXPLOIT-KIT Crimeboss exploit kit - redirection attempt (more info ...)trojan-activity        URL
26045EXPLOIT-KIT Crimeboss exploit kit - setup (more info ...)trojan-activity        URL
26057FILE-IDENTIFY ZIP file download detected (more info ...)misc-activity        
26058FILE-IDENTIFY ZIP file attachment detected (more info ...)misc-activity        
26070FILE-EXECUTABLE Ichitaro JSMISC32.dll dll-load exploit attempt (more info ...)attempted-user  2013-0707      URL
26071FILE-EXECUTABLE Ichitaro JSMISC32.dll dll-load exploit attempt (more info ...)attempted-user  2013-0707      URL
26090EXPLOIT-KIT Styx exploit kit landing page (more info ...)trojan-activity  2013-2423      URL
26092INDICATOR-OBFUSCATION fromCharCode seen in exploit kit landing pages (more info ...)trojan-activity        URL
26093MALWARE-OTHER Compromised website response - leads to Exploit Kit (more info ...)misc-activity        
26094EXPLOIT-KIT Sweet Orange exploit kit landing page (more info ...)trojan-activity  2013-2423      
26095EXPLOIT-KIT Neutrino exploit kit landing page (more info ...)trojan-activity  2013-2465      URL
26096EXPLOIT-KIT Neutrino exploit kit landing page (more info ...)trojan-activity  2013-2465      URL
26099EXPLOIT-KIT Neutrino exploit kit redirection page (more info ...)trojan-activity  2013-2465      URL
26100EXPLOIT-KIT Neutrino exploit kit redirection page (more info ...)trojan-activity  2013-2465      URL
26101INDICATOR-OBFUSCATION String.fromCharCode concatenation (more info ...)trojan-activity        URL
26103SERVER-OTHER HP LeftHand Virtual SAN hydra ping request buffer overflow attempt (more info ...)attempted-admin  2012-3285      URL
26105SERVER-OTHER BigAnt IM Server buffer overflow attempt (more info ...)attempted-admin  2012-6275  57214    
26226EXPLOIT-KIT Crimeboss exploit kit redirection attempt (more info ...)trojan-activity  2012-4681      
26227EXPLOIT-KIT Blackhole exploit kit landing page retrieval (more info ...)trojan-activity  2012-4681      URL
26230SERVER-WEBAPP Alcatel-Lucent OmniPCX arbitrary command execution attempt (more info ...)attempted-admin  2007-3010  25694    
26232EXPLOIT-KIT Sweet Orange exploit kit landing page (more info ...)trojan-activity  2013-2423      
26233EXPLOIT-KIT Sweet Orange exploit kit landing page (more info ...)trojan-activity  2013-2423      
26251FILE-IDENTIFY JPEG file magic detected (more info ...)misc-activity        
26252EXPLOIT-KIT Impact exploit kit landing page (more info ...)trojan-activity  2013-0422      
26253EXPLOIT-KIT Blackhole exploit kit landing page (more info ...)trojan-activity  2012-4681      
26261MALWARE-OTHER Fake postal receipt HTTP Response phishing attack (more info ...)trojan-activity        URL
26287APP-DETECT Absolute Software Computrace outbound connection - search.namequery.com (more info ...)misc-activity        URL
26293EXPLOIT-KIT Sakura exploit kit exploit request (more info ...)trojan-activity        
26294FILE-OTHER Watering Hole Campaign applet download (more info ...)trojan-activity  2013-0422      
26295FILE-OTHER Watering Hole Campaign applet download (more info ...)trojan-activity  2011-3544      
26296EXPLOIT-KIT Styx exploit kit landing page (more info ...)trojan-activity  2013-2423      
26297EXPLOIT-KIT Styx exploit kit redirection page (more info ...)trojan-activity  2013-2423      
26323EXPLOIT-KIT CritX exploit kit redirection page (more info ...)trojan-activity        URL
26326MALWARE-BACKDOOR DarkSeoul related wiper (more info ...)trojan-activity        URL
26328MALWARE-BACKDOOR Windows vernot download (more info ...)trojan-activity        URL
26332MALWARE-BACKDOOR Jokra dropper download (more info ...)trojan-activity        URL
26333SERVER-OTHER HP LeftHand Virtual SAN hydra diag request buffer overflow attempt (more info ...)attempted-admin  2012-3283      URL
26334SERVER-OTHER HP LeftHand Virtual SAN hydra diag request buffer overflow attempt (more info ...)attempted-admin  2012-3283      URL
26337EXPLOIT-KIT Blackhole exploit kit landing page - specific structure (more info ...)trojan-activity  2012-4681      
26338EXPLOIT-KIT IFRAMEr injection detection - leads to exploit kit (more info ...)trojan-activity  2012-4681      
26341EXPLOIT-KIT Nuclear exploit kit landing page (more info ...)trojan-activity  2012-4681      
26342EXPLOIT-KIT Nuclear exploit kit landing page - specific structure (more info ...)trojan-activity  2012-4681      
26343EXPLOIT-KIT Nuclear exploit kit landing page (more info ...)trojan-activity  2012-4681      
26344EXPLOIT-KIT Redkit exploit kit landing page redirection (more info ...)trojan-activity  2013-2423      URL
26345EXPLOIT-KIT Redkit exploit kit landing page (more info ...)trojan-activity  2013-2423      URL
26346EXPLOIT-KIT Redkit exploit kit payload requested (more info ...)trojan-activity  2013-2423      URL
26349EXPLOIT-KIT Redkit exploit kit obfuscated portable executable (more info ...)trojan-activity  2013-2423      URL
26350EXPLOIT-KIT TDS redirection - may lead to exploit kit (more info ...)trojan-activity  2013-2423      
26351EXPLOIT-KIT Redkit exploit kit landing page redirection (more info ...)trojan-activity  2013-2423      URL
26352INDICATOR-OBFUSCATION obfuscated portable executable - seen in exploit kits (more info ...)trojan-activity        URL
26366EXPLOIT-KIT Egypack exploit kit landing page (more info ...)trojan-activity        URL
26367EXPLOIT-KIT Egypack exploit kit outbound connection (more info ...)trojan-activity        URL
26368EXPLOIT-KIT Egypack exploit kit landing page (more info ...)trojan-activity        URL
26380MALWARE-OTHER UTF-8 BOM in zip file attachment detected (more info ...)trojan-activity        
26381MALWARE-OTHER UTF-8 BOM in zip file attachment detected (more info ...)trojan-activity        
26382MALWARE-OTHER UTF-8 BOM in zip file attachment detected (more info ...)trojan-activity        
26383EXPLOIT-KIT Redkit exploit kit landing page (more info ...)trojan-activity  2013-2423      URL
26384EXPLOIT-KIT Redkit exploit kit landing page (more info ...)trojan-activity  2013-2423      URL
26392PROTOCOL-SCADA Schneider Electric IGSS integer underflow attempt (more info ...)attempted-user  2013-0657      
26394SERVER-OTHER Bopup Communications server buffer overflow attempt (more info ...)attempted-user  2009-2227  43836    
26414PROTOCOL-SCADA CODESYS Gateway-Server executable file upload attempt (more info ...)attempted-admin  2012-4705  58032    URL
26415PROTOCOL-SCADA CODESYS Gateway-Server directory traversal attempt (more info ...)attempted-admin  2012-4705  58032    URL
26416SERVER-WEBAPP HP Intelligent Management Center mibFileUpload servlet arbitrary file upload attempt (more info ...)attempted-admin  2012-5201  58385    URL
26417SERVER-WEBAPP HP Intelligent Management Center mibFileUpload servlet arbitrary file upload attempt (more info ...)attempted-admin  2012-5201  58385    URL
26421BROWSER-PLUGINS Metalink file download parameter buffer overflow attempt (more info ...)attempted-user  2008-1602      
26422FILE-IDENTIFY Metalink File file attachment detected (more info ...)misc-activity        
26423FILE-IDENTIFY Metalink File file attachment detected (more info ...)misc-activity        
26424FILE-IDENTIFY Metalink File file download request (more info ...)misc-activity        
26434EXPLOIT-KIT Blackholev2 exploit kit jar file downloaded (more info ...)trojan-activity  2012-4681      
26458FILE-IDENTIFY Stream redirector file download request (more info ...)misc-activity        URL
26470MALWARE-OTHER Win.Trojan.Zeus Spam 2013 dated zip/exe HTTP Response - potential malware download (more info ...)trojan-activity        URL
26488PROTOCOL-SCADA CODESYS Gateway-Server directory traversal attempt (more info ...)attempted-admin  2012-4705  58032    URL
26495FILE-OTHER WellinTech KingView KingMessage log file parsing buffer overflow attempt (more info ...)attempted-admin  2012-4711      
26496FILE-OTHER WellinTech KingView KingMessage log file parsing buffer overflow attempt (more info ...)attempted-admin  2012-4711      
26502PROTOCOL-SCADA 3S CoDeSys Gateway Server stack buffer overflow attempt (more info ...)attempted-admin  2012-4708      
26503PROTOCOL-SCADA 3S CoDeSys Gateway Server stack buffer overflow attempt (more info ...)attempted-admin  2012-4708      
26504PROTOCOL-SCADA 3S CoDeSys Gateway Server stack buffer overflow attempt (more info ...)attempted-admin  2012-4708      
26508EXPLOIT-KIT Multiple exploit kit Payload detection - info.dll (more info ...)trojan-activity  2012-4681      
26511EXPLOIT-KIT Sakura exploit kit redirection structure (more info ...)trojan-activity  2013-2423      URL
26526EXPLOIT-KIT Portable Executable downloaded with bad DOS stub (more info ...)trojan-activity  2013-2423      URL
26534EXPLOIT-KIT Stamp exploit kit portable executable download (more info ...)trojan-activity  2013-0431      
26535EXPLOIT-KIT Multiple exploit kit landing page - specific structure (more info ...)trojan-activity  2013-0431      
26536EXPLOIT-KIT Stamp exploit kit landing page (more info ...)trojan-activity  2013-0431      
26537EXPLOIT-KIT Sakura exploit kit jar download detection (more info ...)trojan-activity  2013-2423      
26538EXPLOIT-KIT Sakura exploit kit landing page received (more info ...)trojan-activity  2013-2423      
26539EXPLOIT-KIT Sakura exploit kit pdf download detection (more info ...)trojan-activity  2013-2423      
26540EXPLOIT-KIT iFramer injection - specific structure (more info ...)trojan-activity  2013-2423      
26541EXPLOIT-KIT Multiple exploit kit successful redirection - jnlp bypass (more info ...)trojan-activity  2013-2423      
26548SERVER-WEBAPP HP OpenView NNM webappmon.exe buffer overflow attempt (more info ...)attempted-admin  2010-2703  41829    
26591EXPLOIT-KIT unknown exploit kit script injection attempt (more info ...)trojan-activity        URL
26599EXPLOIT-KIT Impact/Stamp exploit kit landing page (more info ...)trojan-activity  2013-0431      
26600EXPLOIT-KIT Impact/Stamp exploit kit landing page (more info ...)trojan-activity  2013-0431      
26610MALWARE-BACKDOOR Win.Backdoor.Dulevco.A runtime detection (more info ...)trojan-activity        URL
26611MALWARE-BACKDOOR Win.Backdoor.Dulevco.A runtime detection (more info ...)trojan-activity        URL
26617EXPLOIT-KIT iFramer injection - specific structure (more info ...)trojan-activity  2013-2423      
26653EXPLOIT-KIT Multiple exploit kit landing page - specific structure (more info ...)trojan-activity  2013-2423      URL
26655MALWARE-BACKDOOR Win.Backdoor.PCRat data upload (more info ...)misc-activity        URL
26660MALWARE-OTHER Fake delivery information phishing attack (more info ...)trojan-activity        URL
26664FILE-IMAGE BMP extremely large xpos opcodes (more info ...)attempted-user  2013-2729  59918    URL
26665FILE-IMAGE BMP extremely large xpos opcodes (more info ...)attempted-user  2013-2729      URL
26670MALWARE-OTHER OSX.Trojan.KitM file download (more info ...)trojan-activity        URL
26671MALWARE-OTHER OSX.Trojan.KitM file download (more info ...)trojan-activity        URL
26698MALWARE-OTHER Compromised Website response - leads to Exploit Kit (more info ...)trojan-activity        URL
26773MALWARE-BACKDOOR Trojan.Midwgif.A runtime detection (more info ...)trojan-activity        URL
26778MALWARE-OTHER Win.Trojan.Kazy download attempt (more info ...)trojan-activity        URL
26796MALWARE-OTHER ANDR.Trojan.ZertSecurity encrypted information leak (more info ...)trojan-activity        URL
26797SERVER-WEBAPP Mutiny editdocument servlet arbitrary file access attempt (more info ...)attempted-recon  2013-0136      
26798SERVER-WEBAPP Mutiny editdocument servlet arbitrary file upload attempt (more info ...)attempted-admin  2013-0136      
26805EXPLOIT-KIT Redkit exploit kit encrypted binary download (more info ...)trojan-activity  2013-2423      
26807EXPLOIT-KIT Redkit exploit kit landing page (more info ...)trojan-activity  2013-2423      
26808EXPLOIT-KIT Goon/Infinity/Redkit exploit kit short jar request (more info ...)trojan-activity  2013-2423      
26823MALWARE-BACKDOOR Backdoor.Win32.Neshgai.A runtime detection (more info ...)trojan-activity        URL
26842MALWARE-BACKDOOR Win.Backdoor.Boda Malware Checkin (more info ...)trojan-activity        
26881MALWARE-OTHER HTML.Dropper.Agent uri scheme detected (more info ...)trojan-activity        URL
26902FILE-IDENTIFY Android APK download request (more info ...)misc-activity        
26903FILE-IDENTIFY Android APK download file attachment detected (more info ...)misc-activity        
26904FILE-IDENTIFY Android APK download file attachment detected (more info ...)misc-activity        
26921MALWARE-OTHER Win.Trojan.Kazy download attempt (more info ...)trojan-activity        URL
26929SERVER-WEBAPP SAP ConfigServlet command execution attempt (more info ...)attempted-admin        URL
26933MALWARE-OTHER Clickserver ad harvesting redirection attempt (more info ...)misc-activity        
26934MALWARE-OTHER Clickserver ad harvesting redirection attempt (more info ...)misc-activity        
26949EXPLOIT-KIT DotkaChef/Rmayana/DotCache exploit kit landing page (more info ...)trojan-activity        URL
26951EXPLOIT-KIT DotkaChef/Rmayana/DotCache exploit kit Malvertising Campaign URI request (more info ...)trojan-activity        URL
26956EXPLOIT-KIT Topic exploit kit outbound connection - 1 (more info ...)trojan-activity        URL
26957EXPLOIT-KIT Topic exploit kit outbound connection - 2 (more info ...)trojan-activity        URL
26958EXPLOIT-KIT Topic exploit kit outbound connection - 3 (more info ...)trojan-activity        URL
26959EXPLOIT-KIT Topic exploit kit outbound connection - 4 (more info ...)trojan-activity        URL
26960EXPLOIT-KIT Zuponcic exploit kit landing page (more info ...)trojan-activity        
26961EXPLOIT-KIT Flim exploit kit landing page (more info ...)trojan-activity        
26962EXPLOIT-KIT Flim exploit kit portable executable download (more info ...)trojan-activity        
26963EXPLOIT-KIT Flim exploit kit outbound jar request (more info ...)trojan-activity        
26964EXPLOIT-KIT Flim exploit kit outbound jnlp request (more info ...)trojan-activity        
27005EXPLOIT-KIT Multiple exploit kit Portable Executable downloaded when mp3 is declared (more info ...)trojan-activity        
27006SERVER-WEBAPP HP OpenView Network Node Manager URI rping stack buffer overflow attempt (more info ...)attempted-user  2009-1420  35267    
27024MALWARE-OTHER OSX.Trojan.Netweird.A file download attempt (more info ...)trojan-activity        URL
27026EXPLOIT-KIT Neutrino exploit kit landing page (more info ...)trojan-activity        
27034MALWARE-OTHER Win.Backdoor.Transhell file download (more info ...)trojan-activity        URL
27035MALWARE-OTHER Win.Backdoor.Transhell file download (more info ...)trojan-activity        URL
27040EXPLOIT-KIT Styx exploit kit plugin detection connection jorg (more info ...)trojan-activity  2013-2423      
27041EXPLOIT-KIT Styx exploit kit plugin detection connection jlnp (more info ...)trojan-activity  2013-2423      
27042EXPLOIT-KIT Styx exploit kit plugin detection connection jovf (more info ...)trojan-activity  2013-2423      
27050MALWARE-OTHER Win.Trojan.Dokstormac file download (more info ...)trojan-activity        URL
27051MALWARE-OTHER Win.Trojan.Dokstormac file download (more info ...)trojan-activity        URL
27055MALWARE-OTHER Win.Trojan.Yakes download attempt (more info ...)trojan-activity        URL
27056MALWARE-OTHER Win.Trojan.Yakes download attempt (more info ...)trojan-activity        URL
27059MALWARE-OTHER OSX.Trojan.HackBack file download attempt (more info ...)trojan-activity        URL
27060MALWARE-OTHER OSX.Trojan.HackBack file upload attempt (more info ...)trojan-activity        URL
27067EXPLOIT-KIT Blackholev2 exploit kit landing page - specific structure (more info ...)trojan-activity  2013-2423      
27071EXPLOIT-KIT Blackhole exploit kit landing page retrieval (more info ...)trojan-activity  2012-4681      
27072EXPLOIT-KIT Blackhole exploit kit landing page retrieval (more info ...)trojan-activity  2012-4681      
27073INDICATOR-OBFUSCATION obfuscated getElementsByTagName string - seen in exploit kits (more info ...)trojan-activity        URL
27074INDICATOR-OBFUSCATION obfuscated getElementsByTagName string - seen in exploit kits (more info ...)trojan-activity        URL
27078EXPLOIT-KIT Nailed exploit kit landing page - specific structure (more info ...)trojan-activity        URL
27079EXPLOIT-KIT Nailed exploit kit landing page stage 2 (more info ...)trojan-activity        URL
27080EXPLOIT-KIT Nailed exploit kit Firefox exploit download - autopwn (more info ...)trojan-activity  2013-0757      URL
27083EXPLOIT-KIT Nailed exploit kit jmxbean remote code execution exploit download - autopwn (more info ...)trojan-activity  2013-0422      URL
27084EXPLOIT-KIT Nailed exploit kit rhino remote code execution exploit download - autopwn (more info ...)trojan-activity  2011-3544      URL
27085EXPLOIT-KIT Unknown Malvertising exploit kit Hostile Jar pipe.class (more info ...)trojan-activity        
27086EXPLOIT-KIT Unknown Malvertising exploit kit stage-1 redirect (more info ...)trojan-activity        
27104SERVER-WEBAPP HP System Management arbitrary command injection attempt (more info ...)attempted-admin  2013-3576  60471    
27105SERVER-WEBAPP HP System Management arbitrary command injection attempt (more info ...)attempted-admin  2013-3576  60471    
27108EXPLOIT-KIT Multiple exploit kit malicious jar file downloaded when exe is declared (more info ...)trojan-activity        
27110EXPLOIT-KIT Blackholev2/Cool exploit kit outbound portable executable request (more info ...)trojan-activity        
27113EXPLOIT-KIT DotkaChef/Rmayana/DotCache exploit kit Zeroaccess download attempt (more info ...)trojan-activity  2013-2423      URL
27115MALWARE-OTHER DirtJumper denial of service attack traffic (more info ...)attempted-dos        URL
27121SERVER-OTHER HP OpenView Storage Data Protector - initiate connection (more info ...)protocol-command-decode        
27122SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (more info ...)attempted-admin  2013-2330  60306    URL
27123SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 259 buffer overflow attempt (more info ...)attempted-admin  2013-2329  60304    URL
27124SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (more info ...)attempted-admin  2013-2331  60307    URL
27125SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (more info ...)attempted-admin  2013-2333  60309    URL
27140EXPLOIT-KIT Private exploit kit numerically named exe file dowload (more info ...)trojan-activity  2013-2423      URL
27141EXPLOIT-KIT Private exploit kit landing page (more info ...)trojan-activity  2013-2423      URL
27142EXPLOIT-KIT Private exploit kit landing page (more info ...)trojan-activity  2013-2423      URL
27143EXPLOIT-KIT Private exploit kit landing page (more info ...)trojan-activity  2013-2423      URL
27144EXPLOIT-KIT Private exploit kit outbound traffic (more info ...)trojan-activity  2013-2423      URL
27170SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (more info ...)attempted-admin  2013-2334  60310    URL
27197MALWARE-OTHER OSX.Trojan.Pintsized file download attempt (more info ...)trojan-activity        URL
27198MALWARE-OTHER OSX.Trojan.Pintsized file download attempt (more info ...)trojan-activity        URL
27217SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 260 buffer overflow attempt (more info ...)attempted-admin  2013-2332  60308    URL
27228MALWARE-OTHER OSX.Trojan.Janicab file download attempt (more info ...)attempted-admin        URL
27229MALWARE-OTHER IFRAMEr Tool code injection attack (more info ...)misc-activity        URL
27242EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator (more info ...)trojan-activity        
27246MALWARE-OTHER Mac OSX FBI ransomware (more info ...)trojan-activity        URL
27261SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 215 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
27262SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 263 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
27264SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 227 buffer overflow attempt (more info ...)attempted-admin  2013-2335  60311    URL
27271EXPLOIT-KIT iFramer toolkit injected iframe detected - specific structure (more info ...)trojan-activity  2012-4681      
27273EXPLOIT-KIT Goon/Infinity exploit kit iframe redirection (more info ...)trojan-activity        
27539SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (more info ...)attempted-admin  2013-2326  60301    URL
27542FILE-IDENTIFY Python bytecode file magic detected (more info ...)misc-activity        
27543FILE-IDENTIFY Python bytecode file magic detected (more info ...)misc-activity        
27548MALWARE-OTHER Osx.Trojan.Janicab file download attempt (more info ...)trojan-activity  2012-0158      URL
27549MALWARE-OTHER Osx.Trojan.Janicab file download attempt (more info ...)trojan-activity  2012-0158      URL
27550MALWARE-OTHER Compromised website response - leads to Exploit Kit (more info ...)trojan-activity        
27565MALWARE-OTHER HideMeBetter spam injection variant (more info ...)trojan-activity        URL
27571SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (more info ...)attempted-admin  2013-2325  60300    URL
27598SERVER-WEBAPP Oracle Secure Backup Admin Server command injection attempt (more info ...)web-application-attack  2011-2261  48752    
27617SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 264 buffer overflow attempt (more info ...)attempted-admin  2013-2327  60302    URL
27646SERVER-OTHER HP LeftHand Virtual SAN hydra login request buffer overflow attempt (more info ...)attempted-admin  2013-2343  60884    URL
27656BROWSER-PLUGINS VMWare Remote Console format string code execution attempt (more info ...)attempted-user  2009-3732      
27657BROWSER-PLUGINS VMWare Remote Console format string code execution attempt (more info ...)attempted-user  2009-3732      
27658BROWSER-PLUGINS VMWare Remote Console format string code execution attempt (more info ...)attempted-user  2009-3732      
27695EXPLOIT-KIT Kore exploit kit landing page (more info ...)trojan-activity  2013-2471      URL
27696EXPLOIT-KIT Kore exploit kit landing page (more info ...)trojan-activity  2013-2471      URL
27702EXPLOIT-KIT Gong Da exploit kit landing page (more info ...)trojan-activity  2013-1493      
27706EXPLOIT-KIT Gong Da exploit kit possible jar download (more info ...)trojan-activity  2013-1493      
27738EXPLOIT-KIT Multiple exploit kit landing page (more info ...)trojan-activity        
27739EXPLOIT-KIT Multiple exploit kit redirection page (more info ...)trojan-activity        
27769SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (more info ...)attempted-admin  2013-2324  60299    URL
27770SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (more info ...)attempted-admin  2013-2324  60299    URL
27771SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (more info ...)attempted-admin  2013-2324  60299    URL
27772SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (more info ...)attempted-admin  2013-2324  60299    URL
27773SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (more info ...)attempted-admin  2013-2324  60299    URL
27783EXPLOIT-KIT Neutrino exploit kit plugin detection page (more info ...)trojan-activity        
27813EXPLOIT-KIT Styx exploit kit landing page with payload (more info ...)trojan-activity  2013-2423      
27814EXPLOIT-KIT Styx exploit kit landing page request (more info ...)trojan-activity  2013-2423      
27815EXPLOIT-KIT Styx exploit kit malicious redirection attempt (more info ...)trojan-activity  2013-2423      
27816EXPLOIT-KIT Multiple exploit kit jar file download attempt (more info ...)trojan-activity        
27865EXPLOIT-KIT Blackholev2/Darkleech exploit kit landing page request (more info ...)trojan-activity  2012-4681      
27866EXPLOIT-KIT Blackholev2/Darkleech exploit kit landing page (more info ...)trojan-activity        
27873EXPLOIT-KIT Kore exploit kit outbound payload download attempt (more info ...)trojan-activity        
27876EXPLOIT-KIT DotkaChef/Rmayana/DotCache exploit kit Zeroaccess download (more info ...)trojan-activity        
27877EXPLOIT-KIT Blackholev2/Cool exploit kit landing page (more info ...)trojan-activity        
27878EXPLOIT-KIT Blackholev2/Cool exploit kit landing page (more info ...)trojan-activity        
27885EXPLOIT-KIT Teletubbies exploit kit payload download (more info ...)trojan-activity  2013-2465      URL
27886EXPLOIT-KIT Teletubbies exploit kit payload download (more info ...)trojan-activity  2010-1297      URL
27887EXPLOIT-KIT Teletubbies exploit kit payload download (more info ...)trojan-activity  2010-2884      URL
27888EXPLOIT-KIT Teletubbies exploit kit payload download (more info ...)trojan-activity  2010-0188      URL
27889EXPLOIT-KIT Teletubbies exploit kit payload download (more info ...)trojan-activity  2010-0188      URL
27890EXPLOIT-KIT Teletubbies exploit kit secondary payload (more info ...)trojan-activity        URL
27891EXPLOIT-KIT Teletubbies exploit kit secondary payload (more info ...)trojan-activity        URL
27893EXPLOIT-KIT Teletubbies exploit kit payload download (more info ...)trojan-activity  2008-2992      URL
27894EXPLOIT-KIT Multiple exploit kit Payload detection - about.dll (more info ...)trojan-activity  2012-4681      URL
27895EXPLOIT-KIT Multiple exploit kit Payload detection - info.dll (more info ...)trojan-activity  2012-4681      URL
27896EXPLOIT-KIT Multiple exploit kit Payload detection - contacts.dll (more info ...)trojan-activity  2012-4681      URL
27897EXPLOIT-KIT Multiple exploit kit Payload detection - calc.dll (more info ...)trojan-activity  2012-4681      URL
27898EXPLOIT-KIT Multiple exploit kit Payload detection - readme.dll (more info ...)trojan-activity  2012-4681      URL
27911EXPLOIT-KIT X2O exploit kit landing page (more info ...)trojan-activity        
27912EXPLOIT-KIT X2O exploit kit landing page (more info ...)trojan-activity        
27935EXPLOIT-KIT Styx exploit kit landing page (more info ...)trojan-activity        
27936EXPLOIT-KIT Styx exploit kit portable executable download (more info ...)trojan-activity        
27937SERVER-OTHER HP ProCurve Manager SNAC UpdateCertificatesServlet directory traversal attempt (more info ...)attempted-admin  2013-4812  62348    URL
27941SERVER-OTHER HP ProCurve Manager SNAC UpdateDomainControllerServlet directory traversal attempt (more info ...)attempted-admin  2013-4811  62349    URL
27942SERVER-WEBAPP Sophos Web Protection Appliance sblistpack arbitrary command execution attempt (more info ...)attempted-admin  2013-4984  62265    URL
27956MALWARE-OTHER OSX.Trojan.Renepo rootkit download attempt (more info ...)trojan-activity        URL
27957MALWARE-OTHER OSX.Trojan.Renepo rootkit download attempt (more info ...)trojan-activity        URL
27958MALWARE-OTHER OSX.Trojan.Renepo rootkit download attempt (more info ...)trojan-activity        URL
27959MALWARE-OTHER OSX.Trojan.Renepo rootkit upload attempt (more info ...)trojan-activity        URL
27960MALWARE-OTHER OSX.Trojan.Renepo rootkit upload attempt (more info ...)trojan-activity        URL
27961MALWARE-OTHER OSX.Trojan.Renepo rootkit upload attempt (more info ...)trojan-activity        URL
27982APP-DETECT Dynamic Internet Technology Freegate application executable download attempt (more info ...)misc-activity        URL
27983APP-DETECT Dynamic Internet Technology Freegate application zip download attempt (more info ...)misc-activity        URL
27999APP-DETECT Possible Dynamic Internet Technology Frontgate application PING (more info ...)misc-activity        URL
28000APP-DETECT Dynamic Internet Technology Freegate application executable download attempt (more info ...)misc-activity        URL
28001APP-DETECT Dynamic Internet Technology Freegate application zip download attempt (more info ...)misc-activity        URL
28006MALWARE-OTHER Win.Trojan.Kuluoz outbound download request (more info ...)trojan-activity        URL
28015EXPLOIT-KIT g01pack exploit kit redirection attempt (more info ...)trojan-activity        
28016EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator (more info ...)trojan-activity        
28017EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator (more info ...)trojan-activity        
28018EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator (more info ...)trojan-activity        
28019EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator (more info ...)trojan-activity        
28020EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator (more info ...)trojan-activity        
28021EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator (more info ...)trojan-activity        
28022EXPLOIT-KIT embedded iframe redirection - IFRAMEr injection tool (more info ...)trojan-activity        
28029EXPLOIT-KIT Magnitude/Popads/Nuclear exploit kit jnlp request (more info ...)trojan-activity  2013-0431      
28038EXPLOIT-KIT Sakura exploit kit successful redirection (more info ...)trojan-activity        
28054MALWARE-OTHER VBScript potential executable write attempt (more info ...)trojan-activity        URL
28138EXPLOIT-KIT DotkaChef/Rmayana exploit kit redirection attempt (more info ...)trojan-activity        
28194EXPLOIT-KIT X2O exploit kit landing page (more info ...)trojan-activity        
28196EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
28197EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
28198EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
28199EXPLOIT-KIT Bleeding Life exploit kit module call (more info ...)attempted-user        URL
28213EXPLOIT-KIT Neutrino exploit kit redirection received (more info ...)trojan-activity        
28227SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (more info ...)attempted-admin  2013-2333  60309    URL
28236EXPLOIT-KIT Magnitude/Nuclear exploit kit landing page (more info ...)trojan-activity  2013-0431      
28237EXPLOIT-KIT Magnitude/Nuclear exploit kit outbound pdf download attempt (more info ...)trojan-activity        
28240SERVER-WEBAPP D-Link DIR-100 User-Agent backdoor access attempt (more info ...)attempted-admin  2013-6026  62990    URL
28265EXPLOIT-KIT Sweet Orange exploit kit landing page attempt (more info ...)trojan-activity        
28279PUA-ADWARE Wajam outbound connection - post install (more info ...)trojan-activity        URL
28280PUA-ADWARE Wajam outbound connection - post install (more info ...)trojan-activity        URL
28286FILE-OTHER overly large XML file MSXML heap overflow attempt (more info ...)attempted-user  2013-0006      URL
28289SERVER-WEBAPP Tenda W302R root remote code execution attempt (more info ...)attempted-admin        URL
28290SERVER-WEBAPP Tenda W302R iwpriv remote code execution attempt (more info ...)attempted-admin        URL
28307EXPLOIT-KIT Himan exploit kit landing page (more info ...)trojan-activity  2013-2551      URL
28324PUA-ADWARE FakeAV runtime detection (more info ...)trojan-activity        
28365MALWARE-OTHER Win.Trojan.Stoberox outbound communication attempt (more info ...)trojan-activity        URL
28367FILE-IDENTIFY CIS file magic detected (more info ...)misc-activity        
28368FILE-IDENTIFY CIS file magic detected (more info ...)misc-activity        
28369FILE-IDENTIFY CIS file attachment detected (more info ...)misc-activity        
28370FILE-IDENTIFY CIS file attachment detected (more info ...)misc-activity        
28371PUA-ADWARE UpdateStar CIS file retrieval attempt (more info ...)misc-activity        URL
28372PUA-ADWARE UpdateStar encapsulated installer outbound connection (more info ...)misc-activity        URL
28381MALWARE-OTHER Win.Downloader.Temvice outbound communication attempt (more info ...)trojan-activity        URL
28393SERVER-OTHER EMC Replication Manager irccd remote command execution attempt (more info ...)attempted-admin  2011-0647  46235    
28401OS-MOBILE Android Andr.Trojan.MobileTx APK file download attempt (more info ...)trojan-activity        URL
28402OS-MOBILE Android Andr.Trojan.MobileTx APK file download attempt (more info ...)trojan-activity        URL
28403OS-MOBILE Android Andr.Trojan.MobileTx information disclosure attempt (more info ...)trojan-activity        URL
28407SERVER-WEBAPP HP Intelligent Management Center BIMS UploadServlet arbitrary file upload attempt (more info ...)attempted-admin  2013-4822  62895    URL
28408SERVER-WEBAPP ProcessMaker neoclassic skin arbitrary code execution attempt (more info ...)attempted-admin        URL
28409SERVER-WEBAPP ProcessMaker neoclassic skin arbitrary code execution attempt (more info ...)attempted-admin        URL
28413EXPLOIT-KIT Magnitude exploit kit embedded redirection attempt (more info ...)trojan-activity  2013-0431      
28423EXPLOIT-KIT Multiple exploit kit single digit exe detection (more info ...)trojan-activity        
28428EXPLOIT-KIT Glazunov exploit kit landing page (more info ...)trojan-activity  2013-2471      URL
28429EXPLOIT-KIT Glazunov exploit kit outbound jnlp download attempt (more info ...)trojan-activity  2013-2471      URL
28430EXPLOIT-KIT Glazunov exploit kit zip file download (more info ...)trojan-activity  2013-2471      URL
28449EXPLOIT-KIT Sakura exploit outbound connection attempt (more info ...)trojan-activity        
28450EXPLOIT-KIT Sakura exploit kit exploit payload retrieve attempt (more info ...)trojan-activity        
28474EXPLOIT-KIT Neutrino exploit kit outbound plugin detection response - generic detection (more info ...)trojan-activity  2013-2465      
28475EXPLOIT-KIT Neutrino exploit kit outbound request - generic detection (more info ...)trojan-activity  2013-2465      
28477EXPLOIT-KIT Styx exploit kit outbound pdf request (more info ...)trojan-activity  2013-2423      
28478EXPLOIT-KIT Styx exploit kit landing page request (more info ...)trojan-activity  2013-2423      
28483MALWARE-OTHER Win.Trojan.Magitart outbound communication attempt (more info ...)trojan-activity        URL
28570FILE-IDENTIFY FDF file magic detected (more info ...)misc-activity        URL
28571FILE-IDENTIFY FDF file attachment detected (more info ...)misc-activity        URL
28572FILE-IDENTIFY FDF file attachment detected (more info ...)misc-activity        URL
28573FILE-IDENTIFY FDF file magic detected (more info ...)misc-activity        URL
28574FILE-IDENTIFY FDF file download request (more info ...)misc-activity        URL
28593EXPLOIT-KIT Multiple exploit kit payload download (more info ...)trojan-activity        
28596EXPLOIT-KIT Nuclear exploit kit payload request (more info ...)trojan-activity        
28608EXPLOIT-KIT Sakura exploit kit Atomic exploit download - specific-structure (more info ...)trojan-activity        
28609EXPLOIT-KIT Sakura exploit kit obfuscated exploit payload download (more info ...)trojan-activity        URL
28610EXPLOIT-KIT Sakura exploit kit exploit payload retreive attempt (more info ...)trojan-activity        
28611EXPLOIT-KIT Sakura exploit kit outbound connection attempt (more info ...)trojan-activity        
28612EXPLOIT-KIT Multiple exploit kit Silverlight exploit download (more info ...)trojan-activity  2013-3896      URL
28615EXPLOIT-KIT Angler exploit kit exploit download attempt (more info ...)trojan-activity  2013-3896      URL
28795EXPLOIT-KIT Goon/Infinity exploit kit payload download attempt (more info ...)trojan-activity  2012-0507      URL
28797EXPLOIT-KIT Multiple exploit kit binkey xored binary download attempt (more info ...)trojan-activity        URL
28798EXPLOIT-KIT Multiple exploit kit possibly malicious iframe embedded into a webpage (more info ...)trojan-activity        
28806INDICATOR-COMPROMISE potential malware download - single digit .exe file download (more info ...)trojan-activity        URL
28847MALWARE-OTHER Win.Backdoor.Tavdig download attempt (more info ...)trojan-activity        URL
28848MALWARE-OTHER Win.Backdoor.Tavdig download attempt (more info ...)trojan-activity        URL
28851SERVER-OTHER JBoss EJBInvokerServlet remote code execution attempt (more info ...)web-application-attack  2013-4810  62347    
28883PUA-ADWARE Apponic CIS file retrieval attempt (more info ...)misc-activity        URL
28884PUA-ADWARE Apponic encapsulated installer outbound connection (more info ...)misc-activity        URL
28885PUA-ADWARE Apponic encapsulated installer outbound connection (more info ...)misc-activity        URL
28893BROWSER-OTHER known revoked certificate for Tresor CA (more info ...)bad-unknown        URL
28894FILE-IDENTIFY eSignal .ets file attachment detected (more info ...)misc-activity        URL
28895FILE-IDENTIFY eSignal .por file attachment detected (more info ...)misc-activity        
28896FILE-IDENTIFY eSignal .quo file attachment detected (more info ...)misc-activity        
28897FILE-IDENTIFY eSignal .sum file attachment detected (more info ...)misc-activity        
28898FILE-IDENTIFY eSignal .ets file attachment detected (more info ...)misc-activity        URL
28899FILE-IDENTIFY eSignal .por file attachment detected (more info ...)misc-activity        
28900FILE-IDENTIFY eSignal .sum file attachment detected (more info ...)misc-activity        
28901FILE-IDENTIFY eSignal .ets file download request (more info ...)misc-activity        URL
28902FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
28903FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
28904FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
28905FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
28906FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
28907FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
28911EXPLOIT-KIT Neutrino exploit kit initial outbound request - generic detection (more info ...)trojan-activity  2013-2465      
28929PUA-ADWARE Amonetize installer outbound connection attempt (more info ...)trojan-activity        URL
28966EXPLOIT-KIT HiMan exploit kit outbound POST connection (more info ...)trojan-activity        
28969EXPLOIT-KIT HiMan exploit kit outbound payload retreival - specific string (more info ...)trojan-activity        
29001EXPLOIT-KIT SPL2 exploit kit landing page detection (more info ...)trojan-activity        
29002EXPLOIT-KIT SPL2 exploit kit Silverlight plugin outbound connection attempt (more info ...)trojan-activity        
29003EXPLOIT-KIT SPL2 exploit kit jar exploit download (more info ...)trojan-activity        
29012MALWARE-OTHER Possible Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity        URL
29013MALWARE-OTHER Possible Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity        URL
29017SERVER-WEBAPP HP LoadRunner Virtual User Generator EmulationAdmin directory traversal attempt (more info ...)attempted-admin  2013-4837  63475    URL
29019SERVER-WEBAPP HP LoadRunner Virtual User Generator EmulationAdmin directory traversal attempt (more info ...)attempted-admin  2013-4838  63476    URL
29023MALWARE-OTHER multi-hop iframe campaign client-side exploit attempt (more info ...)trojan-activity  2011-3402      URL
29024MALWARE-OTHER multi-hop iframe campaign client-side exploit attempt (more info ...)trojan-activity  2011-3402      URL
29025MALWARE-OTHER multi-hop iframe campaign client-side exploit attempt (more info ...)trojan-activity  2011-3402      URL
29027SERVER-WEBAPP Zimbra remote code execution attempt (more info ...)attempted-admin        URL
29046SERVER-WEBAPP WhatsUp Gold ExportViewer.asp diretory traversal attempt (more info ...)web-application-attack    52745    
29055MALWARE-BACKDOOR Win.Trojan.Descrantol variant data exfiltration attempt (more info ...)trojan-activity        URL
29090INDICATOR-COMPROMISE suspicious test for public IP - iframe.ip138.com (more info ...)successful-recon-limited        
29094MALWARE-BACKDOOR Win.Trojan.Shatekrat variant initial outbound connection (more info ...)trojan-activity        URL
29105SERVER-WEBAPP ManageEngine Desktop Central LogUploader servlets directory traversal attempt (more info ...)web-application-attack  2021-44515  69493    
29128EXPLOIT-KIT Stamp exploit kit plugin detection page (more info ...)trojan-activity  2013-0431      
29129EXPLOIT-KIT Stamp exploit kit jar exploit download - specific structure (more info ...)trojan-activity  2013-0431      
29130EXPLOIT-KIT Stamp exploit kit malicious payload download attempt (more info ...)trojan-activity  2013-0431      
29131EXPLOIT-KIT Stamp exploit kit PDF exploit retrieval attempt (more info ...)trojan-activity  2013-0431      
29159SERVER-WEBAPP The Bug Genie openid_identifier cross site scripting attempt (more info ...)web-application-attack    64004    
29160SERVER-WEBAPP The Bug Genie openid_identifier cross site scripting attempt (more info ...)web-application-attack    64004    
29162FILE-IDENTIFY CIS file download request (more info ...)misc-activity        
29165EXPLOIT-KIT CritX exploit kit outbound jar request (more info ...)trojan-activity        
29166EXPLOIT-KIT CritX exploit kit payload download attempt (more info ...)trojan-activity        
29167EXPLOIT-KIT CritX exploit kit payload download attempt (more info ...)trojan-activity        
29170SERVER-WEBAPP NetWeaver internet sales module directory traversal attempt (more info ...)web-application-attack        URL
29186EXPLOIT-KIT Nuclear exploit kit outbound connection (more info ...)trojan-activity        
29213INDICATOR-OBFUSCATION potential math library debugging (more info ...)trojan-activity        URL
29296SERVER-WEBAPP Red Hat CloudForms agent controller filename directory traversal attempt (more info ...)attempted-admin  2013-2068  62745    URL
29297SERVER-WEBAPP Red Hat CloudForms agent controller filename directory traversal attempt (more info ...)attempted-admin  2013-2068  62745    URL
29360EXPLOIT-KIT Goon/Infinity exploit kit encrypted binary download (more info ...)trojan-activity        
29361EXPLOIT-KIT Goon/Infinity exploit kit landing page (more info ...)trojan-activity        
29364MALWARE-OTHER Win.Trojan.Esjey outbound communication attempt (more info ...)trojan-activity        URL
29387SERVER-WEBAPP Synology DiskStation Manager SLICEUPLOAD remote command execution attempt (more info ...)attempted-admin  2013-6955  64516    
29390SERVER-WEBAPP EMC Connectrix Manager FileUploadController directory traversal attempt (more info ...)attempted-admin  2013-6810  64242    
29391SERVER-WEBAPP EMC Connectrix Manager FileUploadController directory traversal attempt (more info ...)attempted-admin  2013-6810  64242    
29392SERVER-WEBAPP EMC Connectrix Manager FileUploadController directory traversal attempt (more info ...)attempted-admin  2013-6810  64242    
29439FILE-IDENTIFY MSI file download request (more info ...)misc-activity        
29445EXPLOIT-KIT Styx exploit kit fonts download page (more info ...)trojan-activity  2013-2423      
29446EXPLOIT-KIT Styx exploit kit jar outbound connection (more info ...)trojan-activity  2013-2423      URL
29447EXPLOIT-KIT Multiple exploit kit payload download - scandsk.exe (more info ...)bad-unknown        
29448EXPLOIT-KIT Styx exploit kit landing page (more info ...)trojan-activity  2013-2423      
29449EXPLOIT-KIT Styx exploit kit landing page (more info ...)trojan-activity  2013-2423      
29450EXPLOIT-KIT Styx exploit kit outbound connection attempt (more info ...)trojan-activity  2013-2423      
29452EXPLOIT-KIT Styx exploit kit landing page request (more info ...)trojan-activity  2013-2423      
29453EXPLOIT-KIT Styx exploit kit eot outbound connection (more info ...)trojan-activity  2013-2423      URL
29462INDICATOR-SCAN User-Agent known malicious user-agent The Mole (more info ...)misc-activity        URL
29465FILE-OTHER Corel PDF fusion XPS stack buffer overflow attempt (more info ...)attempted-user  2013-3248      
29467FILE-OTHER Corel PDF fusion XPS stack buffer overflow attempt (more info ...)attempted-user  2013-3248      
29468FILE-OTHER Corel PDF fusion XPS stack buffer overflow attempt (more info ...)attempted-user  2013-3248      
29485SERVER-WEBAPP EMC Connectrix Manager ManualBootImageUpload directory traversal attempt (more info ...)attempted-admin  2013-6810  64242    
29486SERVER-WEBAPP EMC Connectrix Manager ManualBootImageUpload directory traversal attempt (more info ...)attempted-admin  2013-6810  64242    
29487SERVER-WEBAPP EMC Connectrix Manager ManualBootImageUpload directory traversal attempt (more info ...)attempted-admin  2013-6810  64242    
29488SERVER-WEBAPP EMC Connectrix Manager ManualBootImageUpload directory traversal attempt (more info ...)attempted-admin  2013-6810  64242    
29504PROTOCOL-SCADA Schneider Electric IGSS integer underflow attempt (more info ...)attempted-user  2013-0657      
29505PROTOCOL-SCADA IGSS dc.exe file execution directory traversal attempt (more info ...)attempted-admin  2011-1567      
29510INDICATOR-OBFUSCATION Multiple character encodings detected (more info ...)attempted-user        URL
29526FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
29527FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
29528SERVER-OTHER OpenView Network Node Manager ovalarmsrv opcode 46 integer overflow attempt (more info ...)attempted-admin  2008-2438  34738    
29529SERVER-OTHER OpenView Network Node Manager ovalarmsrv opcode 47 integer overflow attempt (more info ...)attempted-admin  2008-2438  34738    
29530SERVER-OTHER OpenView Network Node Manager ovalarmsrv opcode 54 integer overflow attempt (more info ...)attempted-admin  2008-2438  34738    
29531SERVER-OTHER OpenView Network Node Manager ovalarmsrv opcode 25 integer overflow attempt (more info ...)attempted-admin  2008-2438  34738    
29532SERVER-OTHER OpenView Network Node Manager ovalarmsrv opcode 81 integer overflow attempt (more info ...)attempted-admin  2008-2438  34738    
29534PROTOCOL-SCADA CODESYS Gateway-Server invalid memory access attempt (more info ...)attempted-admin  2012-4704  58032    URL
29539FILE-MULTIMEDIA WAV processing buffer overflow attempt (more info ...)misc-activity  2012-4186  56135    
29540FILE-MULTIMEDIA WAV processing buffer overflow attempt (more info ...)misc-activity  2012-4186  56135    
29541FILE-MULTIMEDIA WAV processing buffer overflow attempt (more info ...)misc-activity  2012-4186  56135    
29542FILE-MULTIMEDIA WAV processing buffer overflow attempt (more info ...)misc-activity  2012-4186  56135    
29543FILE-MULTIMEDIA WAV processing buffer overflow attempt (more info ...)misc-activity  2012-4186  56135    
29544FILE-MULTIMEDIA WAV processing buffer overflow attempt (more info ...)misc-activity  2012-4186  56135    
29545FILE-MULTIMEDIA WAV processing buffer overflow attempt (more info ...)misc-activity  2012-4186  56135    
29546FILE-MULTIMEDIA WAV processing buffer overflow attempt (more info ...)misc-activity  2012-4186  56135    
29576FILE-OTHER Oracle Outside In OS2 metafile parser stack buffer overflow attempt (more info ...)attempted-user  2013-5763  63741    URL
29594SERVER-WEBAPP Airlive IP Camera information leak attempt (more info ...)attempted-user  2013-3686  60550    
29603SERVER-OTHER HP OpenView Storage Data Protector buffer overflow attempt (more info ...)suspicious-filename-detect  2011-0922      URL
29604OS-OTHER CoDeSys Gateway Server Denial of Service attempt detected (more info ...)attempted-dos  2012-4707  58032    
29610SERVER-OTHER IBM Cognos TM1 Server tm1admsd.exe buffer overflow attempt (more info ...)attempted-admin  2012-0202  52847    URL
29611SERVER-OTHER IBM Cognos TM1 Server tm1admsd.exe buffer overflow attempt (more info ...)attempted-admin  2012-0202  52847    URL
29612FILE-IDENTIFY XPS file attachment detected (more info ...)misc-activity        
29613FILE-IDENTIFY XPS file attachment detected (more info ...)misc-activity        
29614FILE-IDENTIFY XPS file download request (more info ...)misc-activity        
29630SERVER-OTHER HP OpenView Storage Data Protector buffer overflow attempt (more info ...)suspicious-filename-detect  2011-0922      
29829SERVER-WEBAPP HNAP remote code execution attempt (more info ...)attempted-admin        URL
29830SERVER-WEBAPP Linksys E-series HNAP TheMoon remote code execution attempt (more info ...)attempted-admin        URL
29831SERVER-WEBAPP Linksys E-series HNAP TheMoon remote code execution attempt (more info ...)attempted-admin        URL
29864EXPLOIT-KIT Redkit exploit kit payload request (more info ...)trojan-activity        URL
29874MALWARE-BACKDOOR Win.Trojan.Dremseko outbound username enumeration (more info ...)trojan-activity        URL
29909SERVER-OTHER JBoss JMXInvokerServlet remote code execution attempt (more info ...)misc-attack  2013-4810  62347    
29918MALWARE-OTHER Win.Keylogger.Vacky system information disclosure (more info ...)trojan-activity        URL
29937SERVER-OTHER SAP NetWeaver Dispatcher DiagTraceR3Info buffer overflow attempt (more info ...)attempted-admin  2012-2611  53424    
29991PUA-ADWARE The Best All Codecs App runtime detection (more info ...)misc-activity        URL
30001EXPLOIT-KIT Hello/LightsOut exploit kit landing page detected (more info ...)trojan-activity  2013-1489      URL
30003EXPLOIT-KIT Hello/LightsOut exploit kit payload download attempt (more info ...)trojan-activity  2013-1489      URL
30012SERVER-WEBAPP ESF pfSense Snort log view remote file inclusion attempt (more info ...)attempted-admin    65181    
30013SERVER-WEBAPP ESF pfSense Snort log view remote file inclusion attempt (more info ...)attempted-admin    65181    
30033SERVER-WEBAPP ESF pfSense webConfigurator invalid input attempt (more info ...)attempted-admin        URL
30065INDICATOR-COMPROMISE ZenCart compromise attempt detected (more info ...)trojan-activity        URL
30066INDICATOR-COMPROMISE ZenCart malicious redirect attempt detected (more info ...)trojan-activity        URL
30070MALWARE-OTHER ANDR.Trojan.iBanking outbound connection attempt (more info ...)trojan-activity        URL
30071MALWARE-OTHER ANDR.Trojan.iBanking outbound connection attempt (more info ...)trojan-activity        URL
30072MALWARE-OTHER ANDR.Trojan.iBanking outbound connection attempt (more info ...)trojan-activity        URL
30094SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 214 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
30095SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 216 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
30096SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 219 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
30097SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 257 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
30133EXPLOIT-KIT Stamp exploit kit landing page (more info ...)trojan-activity        
30134EXPLOIT-KIT Stamp exploit kit malicious payload delivery - specific string (more info ...)trojan-activity        
30137MALWARE-OTHER TDS Sutra - RULEZ cookie set (more info ...)trojan-activity        URL
30138MALWARE-OTHER TDS Sutra - RULEZ cookie (more info ...)trojan-activity        URL
30205SERVER-OTHER HP AIO Archive Query Server stack buffer overflow attempt (more info ...)attempted-admin  2013-6189  64557    
30206SERVER-OTHER HP AIO Archive Query Server stack buffer overflow attempt (more info ...)attempted-admin  2013-6189  64557    
30207SERVER-OTHER HP AIO Archive Query Server stack buffer overflow attempt (more info ...)attempted-admin  2013-6189  64557    
30219EXPLOIT-KIT Nuclear exploit kit outbound jar request (more info ...)trojan-activity        
30220EXPLOIT-KIT Nuclear exploit kit outbound payload request (more info ...)trojan-activity        
30229INDICATOR-SHELLCODE Metasploit windows/shell stage transfer attempt (more info ...)shellcode-detect        URL
30230INDICATOR-COMPROMISE suspicious test for public IP - www.dawhois.com (more info ...)trojan-activity        URL
30260PUA-ADWARE Lucky Leap Adware outbound connection (more info ...)trojan-activity        URL
30261PUA-ADWARE Lucky Leap Adware outbound connection (more info ...)trojan-activity        URL
30263SERVER-OTHER HP OpenView Storage Data Protector opcode 42 directory traversal attempt (more info ...)attempted-admin  2013-6194  64647    URL
30264SERVER-OTHER HP OpenView Storage Data Protector opcode 42 directory traversal attempt (more info ...)attempted-admin  2013-6194  64647    URL
30265SERVER-OTHER HP OpenView Storage Data Protector opcode 42 directory traversal attempt (more info ...)attempted-admin  2013-6194  64647    URL
30266SERVER-OTHER HP OpenView Storage Data Protector opcode 42 directory traversal attempt (more info ...)attempted-admin  2013-6194  64647    URL
30267SERVER-OTHER HP OpenView Storage Data Protector opcode 42 directory traversal attempt (more info ...)attempted-admin  2013-6194  64647    URL
30268SERVER-OTHER HP OpenView Storage Data Protector opcode 42 directory traversal attempt (more info ...)attempted-admin  2013-6194  64647    URL
30274SERVER-WEBAPP LifeSize UVC remote code execution attempt (more info ...)attempted-admin        URL
30306EXPLOIT-KIT SofosFO/Stamp exploit kit plugin detection page (more info ...)trojan-activity        
30312EXPLOIT-KIT WhiteLotus exploit kit plugin outbound detection (more info ...)trojan-activity        
30316EXPLOIT-KIT Goon/Infinity exploit kit landing page (more info ...)trojan-activity        
30317EXPLOIT-KIT Goon/Infinity exploit kit landing page (more info ...)trojan-activity        
30319EXPLOIT-KIT Goon/Infinity exploit kit malicious portable executable file request (more info ...)trojan-activity        
30320MALWARE-OTHER connection to malware sinkhole (more info ...)trojan-activity        URL
30325MALWARE-OTHER malicious iframe injection redirect attempt (more info ...)trojan-activity        
30471INDICATOR-SHELLCODE Metasploit payload windows_adduser (more info ...)shellcode-detect        
30480INDICATOR-SHELLCODE Metasploit payload windows_x64_meterpreter_reverse_https (more info ...)shellcode-detect        
30492PUA-ADWARE Win.Adware.Boaxxe suspicious advert traffic related to click fraud (more info ...)trojan-activity        URL
30493PUA-ADWARE Win.Adware.Boaxxe suspicious advert traffic related to click fraud (more info ...)trojan-activity        URL
30496PUA-ADWARE Win.Adware.Boaxxe suspicious advert traffic related to click fraud (more info ...)trojan-activity        URL
30507SERVER-OTHER MiniUPnPd ExecuteSoapAction buffer overflow attempt (more info ...)attempted-admin  2013-0230      
30510SERVER-OTHER OpenSSL SSLv3 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30511SERVER-OTHER OpenSSL TLSv1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30512SERVER-OTHER OpenSSL TLSv1.1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30513SERVER-OTHER OpenSSL TLSv1.2 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30514SERVER-OTHER OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30515SERVER-OTHER OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30516SERVER-OTHER OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30517SERVER-OTHER OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30520SERVER-OTHER OpenSSL SSLv3 heartbeat read overrun attempt - vulnerable client response (more info ...)attempted-recon  2014-0160      
30521SERVER-OTHER OpenSSL TLSv1 heartbeat read overrun attempt - vulnerable client response (more info ...)attempted-recon  2014-0160      
30522SERVER-OTHER OpenSSL TLSv1.1 heartbeat read overrun attempt - vulnerable client response (more info ...)attempted-recon  2014-0160      
30523SERVER-OTHER OpenSSL TLSv1.2 heartbeat read overrun attempt - vulnerable client response (more info ...)attempted-recon  2014-0160      
30524SERVER-OTHER OpenSSL TLSv1.1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30525SERVER-OTHER OpenSSL TLSv1.2 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30533FILE-OTHER Kingsoft Writer long font name buffer overflow attempt (more info ...)attempted-user  2013-3934  61796    
30534FILE-OTHER Kingsoft Writer long font name buffer overflow attempt (more info ...)attempted-user  2013-3934  61796    
30549SERVER-OTHER OpenSSL Heartbleed masscan access exploitation attempt (more info ...)attempted-recon  2014-0160      
30553SERVER-OTHER HP Data Protector Backup Client Service directory traversal attempt (more info ...)attempted-user  2013-2348      URL
30554SERVER-OTHER HP Data Protector Backup Client Service UTF directory traversal attempt (more info ...)attempted-user  2013-2348      URL
30555SERVER-OTHER HP Data Protector Backup Client Service UTF directory traversal attempt (more info ...)attempted-user  2013-2348      URL
30556SERVER-OTHER HP Data Protector Backup Client Service directory traversal attempt (more info ...)attempted-user  2013-2348      URL
30562PROTOCOL-SCADA Yokogawa CENTUM CS 3000 stack buffer overflow attempt (more info ...)attempted-admin  2014-0783      URL
30567MALWARE-OTHER Win.Trojan.Agent E-FAX phishing attempt (more info ...)trojan-activity        URL
30568MALWARE-OTHER Win.Trojan.Agent E-FAX phishing attempt (more info ...)trojan-activity        URL
30569MALWARE-OTHER Win.Trojan.Agent Funeral ceremony phishing attempt (more info ...)trojan-activity        URL
30711SERVER-OTHER OpenVPN OpenSSL SSLv3 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30712SERVER-OTHER OpenVPN OpenSSL SSLv3 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30713SERVER-OTHER OpenVPN OpenSSL TLSv1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30714SERVER-OTHER OpenVPN OpenSSL TLSv1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30715SERVER-OTHER OpenVPN OpenSSL TLSv1.1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30716SERVER-OTHER OpenVPN OpenSSL TLSv1.1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30717SERVER-OTHER OpenVPN OpenSSL TLSv1.2 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30718SERVER-OTHER OpenVPN OpenSSL TLSv1.2 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30719SERVER-OTHER OpenVPN OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30720SERVER-OTHER OpenVPN OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30721SERVER-OTHER OpenVPN OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30722SERVER-OTHER OpenVPN OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30723SERVER-OTHER OpenVPN OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30724SERVER-OTHER OpenVPN OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30725SERVER-OTHER OpenVPN OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30726SERVER-OTHER OpenVPN OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30727SERVER-OTHER OpenVPN OpenSSL SSLv3 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30728SERVER-OTHER OpenVPN OpenSSL SSLv3 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30729SERVER-OTHER OpenVPN OpenSSL TLSv1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30730SERVER-OTHER OpenVPN OpenSSL TLSv1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30731SERVER-OTHER OpenVPN OpenSSL TLSv1.1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30732SERVER-OTHER OpenVPN OpenSSL TLSv1.1 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30733SERVER-OTHER OpenVPN OpenSSL TLSv1.2 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30734SERVER-OTHER OpenVPN OpenSSL TLSv1.2 heartbeat read overrun attempt (more info ...)attempted-recon  2014-0160      
30735SERVER-OTHER OpenVPN OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30736SERVER-OTHER OpenVPN OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30737SERVER-OTHER OpenVPN OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30738SERVER-OTHER OpenVPN OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30739SERVER-OTHER OpenVPN OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30740SERVER-OTHER OpenVPN OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30741SERVER-OTHER OpenVPN OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30742SERVER-OTHER OpenVPN OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30765PUA-TOOLBARS Inbox Public Transport Toolbar outbound connection (more info ...)misc-activity        URL
30766EXPLOIT-KIT Magnitude exploit kit landing page (more info ...)trojan-activity        
30774SERVER-WEBAPP Splunk collect file parameter directory traversal attempt (more info ...)web-application-attack  2013-6771  62632    URL
30777SERVER-OTHER OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30778SERVER-OTHER OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30779SERVER-OTHER OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30780SERVER-OTHER OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30781SERVER-OTHER OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30782SERVER-OTHER OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30783SERVER-OTHER OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30784SERVER-OTHER OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30785SERVER-OTHER OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30786SERVER-OTHER OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30787SERVER-OTHER OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30788SERVER-OTHER OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attempt (more info ...)attempted-recon  2014-0160      
30797PROTOCOL-SCADA Yokogawa CENTUM CS 3000 RETR bkbcopyd buffer overflow attempt (more info ...)attempted-user  2014-0784  66114    
30798PROTOCOL-SCADA Yokogawa CENTUM CS 3000 STOR bkbcopyd buffer overflow attempt (more info ...)attempted-user  2014-0784  66114    
30799PROTOCOL-SCADA Yokogawa CENTUM CS 3000 ATTR bkbcopyd buffer overflow attempt (more info ...)attempted-user  2014-0784  66114    
30800PROTOCOL-SCADA Yokogawa CENTUM CS 3000 XATR bkbcopyd buffer overflow attempt (more info ...)attempted-user  2014-0784  66114    
30801PROTOCOL-SCADA Yokogawa CENTUM CS 3000 PMODE bkbcopyd buffer overflow attempt (more info ...)attempted-user  2014-0784  66114    
30802PROTOCOL-SCADA Yokogawa CENTUM CS 3000 bkclogserv buffer overflow attempt (more info ...)attempted-admin  2014-0781  66130    
30852EXPLOIT-KIT Angler exploit kit landing page - base64 encoded xml/jnlp statement (more info ...)trojan-activity        
30880OS-MOBILE Android Andr.Trojan.Waller information disclosure attempt (more info ...)trojan-activity        URL
30905FILE-OTHER RARLAB WinRAR ZIP format filename spoof attempt (more info ...)attempted-user    66383    URL
30908FILE-OTHER RARLAB WinRAR ZIP format filename spoof attempt (more info ...)attempted-user    66383    URL
30920EXPLOIT-KIT Multiple exploit kit redirection gate (more info ...)trojan-activity        
30927PUA-ADWARE Win.Adware.Linkular variant outbound connection (more info ...)trojan-activity        URL
30928SERVER-OTHER SAP NetWeaver dir content listing attempt (more info ...)attempted-admin        
30934EXPLOIT-KIT Goon/Infinity/Rig exploit kit encrypted binary download (more info ...)trojan-activity        
30935EXPLOIT-KIT Goon/Infinity/Rig exploit kit landing page - specific structure (more info ...)trojan-activity        
30946MALWARE-OTHER Win.Trojan.Wysotot variant download attempt (more info ...)trojan-activity        URL
30948MALWARE-BACKDOOR Win.Backdoor.Hikit outbound banner response (more info ...)trojan-activity        URL
30959BROWSER-OTHER suspicious srcElement child element removal - possible use after free attempt (more info ...)attempted-user        
30968EXPLOIT-KIT CritX exploit kit landing page - redirection to font exploit (more info ...)trojan-activity        
30973EXPLOIT-KIT CritX exploit kit payload request (more info ...)trojan-activity        URL
30996SERVER-OTHER CMSimple remote file inclusion attempt (more info ...)attempted-admin        URL
30997INDICATOR-COMPROMISE Potential malware download - .doc.exe within .zip file (more info ...)trojan-activity        
30998INDICATOR-COMPROMISE Potential malware download - .gif.exe within .zip file (more info ...)trojan-activity        
30999INDICATOR-COMPROMISE Potential malware download - .jpeg.exe within .zip file (more info ...)trojan-activity        
31000INDICATOR-COMPROMISE Potential malware download - .jpg.exe within .zip file (more info ...)trojan-activity        
31001INDICATOR-COMPROMISE Potential malware download - .pdf.exe within .zip file (more info ...)trojan-activity        
31019PUA-ADWARE Win.Adware.OptimumInstaller variant outbound connection (more info ...)policy-violation        URL
31038FILE-IMAGE XnView PCT file processing buffer overflow attempt (more info ...)attempted-user  2013-2577      URL
31039FILE-IMAGE XnView PCT file processing buffer overflow attempt (more info ...)attempted-user  2013-2577      URL
31040FILE-IMAGE XnView PCT file processing buffer overflow attempt (more info ...)attempted-user  2013-2577      URL
31041FILE-IMAGE XnView PCT file processing buffer overflow attempt (more info ...)attempted-user  2013-2577      URL
31042PUA-ADWARE Win.Adware.Outbrowse installation attempt (more info ...)policy-violation        URL
31089PUA-ADWARE Win.Adware.CloseApp variant outbound connection (more info ...)trojan-activity        URL
31091PUA-ADWARE Win.Adware.Inbox/PCFixSpeed/RebateInformer variant outbound connection (more info ...)policy-violation        URL
31094SERVER-WEBAPP Web Terria remote command execution attempt (more info ...)attempted-admin        URL
31146PUA-ADWARE Win.Adware.iBryte variant outbound connection (more info ...)trojan-activity        URL
31161SERVER-OTHER AuraCMS LFI attempt (more info ...)attempted-admin        URL
31184MALWARE-OTHER Win.Trojan.ZBerp variant download attempt (more info ...)trojan-activity        URL
31185MALWARE-OTHER Win.Trojan.ZBerp variant download attempt (more info ...)trojan-activity        URL
31214INDICATOR-COMPROMISE connection to zeus malware sinkhole (more info ...)trojan-activity        URL
31230EXPLOIT-KIT Bleeding Life exploit kit outbound connection (more info ...)trojan-activity        
31231EXPLOIT-KIT Bleeding Life exploit kit outbound connection (more info ...)trojan-activity        
31232EXPLOIT-KIT Bleeding Life exploit kit outbound jar request (more info ...)trojan-activity        
31238SERVER-OTHER Symantec pcAnywhere remote code execution attempt (more info ...)attempted-admin  2011-3478  51592    
31274EXPLOIT-KIT CottonCastle exploit kit encrypted binary download (more info ...)trojan-activity        URL
31275EXPLOIT-KIT CottonCastle exploit kit landing page (more info ...)trojan-activity        URL
31279EXPLOIT-KIT CottonCastle exploit kit decryption page outbound request (more info ...)trojan-activity  2014-0515      URL
31298EXPLOIT-KIT Goon/Infinity exploit kit landing page (more info ...)trojan-activity        
31305SERVER-WEBAPP Rocket Servergraph Admin Center fileRequestor directory traversal attempt (more info ...)attempted-admin  2014-3914  67779    
31313PUA-ADWARE Ticno Multibar installation attempt (more info ...)trojan-activity        URL
31329MALWARE-OTHER Win.Trojan.Zbot variant download attempt (more info ...)trojan-activity        URL
31330SERVER-WEBAPP AlienVault OSSIM av-centerd update_system_info_debian_package command injection attempt (more info ...)attempted-admin  2014-3804  67312    URL
31337SERVER-OTHER Nagios NRPE command execution attempt (more info ...)attempted-admin  2014-2913  66969    
31339SERVER-WEBAPP Supermicro Intelligent Management Controller information disclosure attempt (more info ...)attempted-recon        URL
31340SERVER-WEBAPP Supermicro Intelligent Management Controller information disclosure attempt (more info ...)attempted-recon        URL
31361SERVER-OTHER OpenSSL DTLSv1.0 handshake fragment buffer overrun attempt (more info ...)attempted-admin  2014-0195  67900    URL
31365SERVER-WEBAPP HP Power Manager remote code execution attempt (more info ...)attempted-admin  2010-4113  36933    
31368SERVER-WEBAPP WebBBS arbitrary system command execution attempt (more info ...)attempted-admin  2002-1993  5048    
31370EXPLOIT-KIT Angler exploit kit redirection page (more info ...)trojan-activity        
31430PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1017 attack attempt (more info ...)protocol-command-decode        URL
31431PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1017 attack attempt (more info ...)protocol-command-decode        URL
31432PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1017 attack attempt (more info ...)attempted-dos        
31487MALWARE-OTHER Game Over Zeus executable download detected (more info ...)trojan-activity        URL
31488MALWARE-OTHER Game Over Zeus executable download detected (more info ...)trojan-activity        URL
31505SERVER-WEBAPP AlienVault OSSIM av-centerd get_license command injection attempt (more info ...)attempted-admin  2014-3805  67998    URL
31506SERVER-WEBAPP AlienVault OSSIM av-centerd get_log_line command injection attempt (more info ...)attempted-admin  2014-3805  67998    URL
31510MALWARE-OTHER Win.Trojan.Injector outbound traffic (more info ...)trojan-activity        URL
31525SERVER-OTHER HP AutoPass License Server CommunicationServlet directory traversal attempt (more info ...)attempted-admin  2013-6221  67989    URL
31526SERVER-OTHER HP AutoPass License Server CommunicationServlet directory traversal attempt (more info ...)attempted-admin  2013-6221  67989    URL
31529SERVER-OTHER D-Link Multiple Products HNAP request buffer overflow attempt (more info ...)attempted-admin  2014-3936  67651    
31531INDICATOR-COMPROMISE MinerDeploy monitor request attempt (more info ...)trojan-activity        URL
31559MALWARE-BACKDOOR Win.Backdoor.Andromeda variant outbound connection (more info ...)trojan-activity        URL
31692EXPLOIT-KIT CritX exploit kit landing page detected (more info ...)trojan-activity        
31699EXPLOIT-KIT Hanjuan exploit kit encrypted binary download (more info ...)trojan-activity        URL
31701EXPLOIT-KIT Hanjuan exploit kit Silverlight exploit request (more info ...)trojan-activity        URL
31734EXPLOIT-KIT Nuclear exploit kit landing page detection (more info ...)trojan-activity        
31741SERVER-OTHER Multi-Router Looking Glass remote command injection attempt (more info ...)attempted-admin  2014-3927      URL
31746MALWARE-BACKDOOR Backdoor.Perl.Shellbot outbound communication attempt (more info ...)trojan-activity        URL
31769EXPLOIT-KIT Sweet Orange exploit kit outbound connection on non-standard port (more info ...)trojan-activity        
31771SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt (more info ...)web-application-attack  2015-5371  75515    
31798SERVER-WEBAPP HP Network Virtualization storedNtxFile directory traversal attempt (more info ...)web-application-attack  2014-2625  68849    URL
31817MALWARE-OTHER Win.Trojan.Graftor variant retrieval of a DLL hosted as a JPG (more info ...)trojan-activity        URL
31819SERVER-WEBAPP HP Network Virtualization toServerObject directory traversal attempt (more info ...)web-application-attack  2014-2626  68851    URL
31823SERVER-WEBAPP AlienVault OSSIM remote_task command injection attempt (more info ...)attempted-admin  2014-5210  69239    URL
31846POLICY-OTHER HP Universal CMDB default credentials authentication attempt (more info ...)policy-violation  2014-2617  68363    URL
31857EXPLOIT-KIT Scanbox exploit kit enumeration code detected (more info ...)trojan-activity        URL
31858EXPLOIT-KIT Scanbox exploit kit enumeration code detected (more info ...)trojan-activity        URL
31859EXPLOIT-KIT Scanbox exploit kit exfiltration attempt (more info ...)trojan-activity        URL
31871FILE-IDENTIFY JPEG file magic detection (more info ...)misc-activity        
31873SERVER-WEBAPP Railo thumbnail.cfm remote file include attempt (more info ...)web-application-attack  2014-5468  69761    
31898EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity        
31966EXPLOIT-KIT Astrum exploit kit payload delivery (more info ...)trojan-activity        URL
31967EXPLOIT-KIT Astrum exploit kit payload delivery (more info ...)trojan-activity        URL
31972EXPLOIT-KIT Astrum exploit kit payload delivery (more info ...)trojan-activity        URL
31983OS-OTHER DHCPv6 flood denial of service attempt (more info ...)attempted-dos  2018-0372      URL
31985OS-OTHER Malicious DHCP server bash environment variable injection attempt (more info ...)attempted-admin  2014-7169      
31986FILE-OTHER Wireshark MPEG dissector stack buffer overflow attempt (more info ...)attempted-user  2014-2299  66066    
31987FILE-OTHER Wireshark MPEG dissector stack buffer overflow attempt (more info ...)attempted-user  2014-2299  66066    
31988EXPLOIT-KIT Gong Da exploit kit landing page (more info ...)trojan-activity        
32005MALWARE-BACKDOOR AlienSpy RAT outbound connection (more info ...)trojan-activity        URL
32006MALWARE-BACKDOOR AlienSpy RAT outbound connection (more info ...)trojan-activity        URL
32008MALWARE-OTHER Fake Delta Ticket HTTP Response phishing attack (more info ...)trojan-activity        URL
32038OS-OTHER Bash environment variable injection attempt (more info ...)attempted-admin  2014-7169      
32039OS-OTHER Bash environment variable injection attempt (more info ...)attempted-admin  2014-7169      
32043OS-OTHER Bash environment variable injection attempt (more info ...)attempted-admin  2014-7169      
32045OS-OTHER Bash redir_stack here document handling denial of service attempt (more info ...)attempted-dos  2014-7186      URL
32046OS-OTHER Bash redir_stack here document handling denial of service attempt (more info ...)attempted-dos  2014-7186      URL
32055MALWARE-BACKDOOR Win.Backdoor.Blohi variant outbound connection (more info ...)trojan-activity        URL
32056SERVER-WEBAPP ManageEngine FileCollector servlet directory traversal attempt (more info ...)attempted-admin  2014-6035  70169    URL
32059PROTOCOL-SCADA KingSCADA Alarm Server stack buffer overflow attempt (more info ...)attempted-admin  2014-0787  66709    
32069OS-OTHER Bash environment variable injection attempt (more info ...)attempted-admin  2014-7169      
32084SERVER-OTHER HP Network Node Manager ovopi.dll buffer overflow attempt (more info ...)attempted-admin  2014-2624      URL
32085SERVER-OTHER HP Network Node Manager ovopi.dll buffer overflow attempt (more info ...)attempted-admin  2014-2624      URL
32127SERVER-WEBAPP PineApp Mail-SeCure livelog.htmlcommand injection attempt (more info ...)attempted-admin    61473    
32165FILE-IDENTIFY SVG file magic detected (more info ...)misc-activity        URL
32207PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32208PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32209PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32210PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32211PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32212PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32213PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32214PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32215PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32216PROTOCOL-VOIP missing media application format parameter denial-of-service attempt (more info ...)attempted-user        
32217PROTOCOL-VOIP out of range port specification exploit attempt (more info ...)attempted-dos        
32218PROTOCOL-VOIP out of range port specification exploit attempt (more info ...)attempted-dos        
32251FILE-IDENTIFY Basic Control Engine file attachment detected (more info ...)misc-activity        URL
32252FILE-IDENTIFY Basic Control Engine file attachment detected (more info ...)misc-activity        URL
32253FILE-IDENTIFY Basic Control Engine file download request (more info ...)misc-activity        URL
32254FILE-OTHER GE Cimplicity CimView load remote file attempt (more info ...)attempted-admin        URL
32255FILE-OTHER GE Cimplicity CimView load remote file attempt (more info ...)attempted-admin        URL
32256FILE-OTHER GE Cimplicity bcl file loading external file attempt (more info ...)attempted-admin        URL
32257FILE-OTHER GE Cimplicity CimView load remote file attempt (more info ...)attempted-admin        URL
32258FILE-OTHER GE Cimplicity CimView load remote file attempt (more info ...)attempted-admin        URL
32260MALWARE-OTHER Sinkhole reply - irc-sinkhole.cert.pl (more info ...)trojan-activity        
32261SERVER-WEBAPP PineApp Mail-SeCure conflivelog.pl install license command injection attempt (more info ...)web-application-attack    61472    
32342SERVER-OTHER AlienVault OSSIM framework backup_restore action command injection attempt (more info ...)attempted-admin  2014-5158  68998    URL
32345SERVER-OTHER HP OpenView Storage Data Protector - initiate connection (more info ...)protocol-command-decode        
32347SERVER-WEBAPP ManageEngine FileCollector servlet directory traversal attempt (more info ...)attempted-admin  2014-6035  70169    URL
32348SERVER-WEBAPP ManageEngine FileCollector servlet directory traversal attempt (more info ...)attempted-admin  2014-6034  70167    URL
32349SERVER-WEBAPP ManageEngine FileCollector servlet directory traversal attempt (more info ...)attempted-admin  2014-6035  70169    URL
32370SERVER-OTHER AOL Instant Messenger goaway message buffer overflow attempt (more info ...)misc-attack  2004-0636  10889    
32371SERVER-OTHER HP Network Node Manager ovopi.dll buffer overflow attempt (more info ...)attempted-admin  2014-2624      URL
32378FILE-IDENTIFY bmp file attachment detected (more info ...)misc-activity        URL
32380FILE-IDENTIFY dib file attachment detected (more info ...)misc-activity        URL
32386EXPLOIT-KIT Nuclear exploit kit outbound structure (more info ...)trojan-activity        
32387EXPLOIT-KIT Nuclear exploit kit jar file download (more info ...)trojan-activity        
32388EXPLOIT-KIT Nuclear exploit kit landing page detected (more info ...)trojan-activity        
32390EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity        
32403SERVER-OTHER HP Network Node Manager ovopi.dll buffer overflow attempt (more info ...)attempted-admin  2014-2624      URL
32462SERVER-WEBAPP Belkin Multiple Devices buffer overflow attempt (more info ...)attempted-admin  2014-1635      
32474OS-WINDOWS .NET Framework BinaryServerFormatterSink-ProcessMessage IMessage corruption attempt (more info ...)attempted-user  2014-4149      URL
32475OS-WINDOWS .NET Framework BinaryServerFormatterSink-ProcessMessage IMessage corruption attempt (more info ...)attempted-user  2014-4149      URL
32488INDICATOR-COMPROMISE .com- potentially malicious hostname (more info ...)bad-unknown        
32527SERVER-WEBAPP Visual Mining NetCharts directory traversal attempt (more info ...)attempted-admin  2014-8516  70895    
32528SERVER-WEBAPP Visual Mining NetCharts directory traversal attempt (more info ...)attempted-admin  2014-8516  70895    
32530SERVER-OTHER HP Network Node Manager ovopi.dll buffer overflow attempt (more info ...)attempted-admin  2014-2624      URL
32554EXPLOIT-KIT Hellspawn exploit kit landing page detected (more info ...)trojan-activity        
32563SERVER-WEBAPP Visual Mining NetCharts arbitrary file upload attempt (more info ...)attempted-admin  2014-8516  70895    
32578PUA-OTHER Request for known malware domain pierrejb.agora.eu.org (more info ...)trojan-activity        
32628SERVER-OTHER HP Network Node Manager ovopi.dll buffer overflow attempt (more info ...)attempted-admin  2014-2624      URL
32646INDICATOR-COMPROMISE Potential malware download - _pdf.exe within .zip file (more info ...)trojan-activity        URL
32709BROWSER-IE VBScript RegEx use-after-free attempt (more info ...)attempted-user  2014-6363      URL
32774SERVER-OTHER Siemens Simatic S7-300 PLC backdoor login attempt (more info ...)suspicious-login        URL
32775SERVER-OTHER Siemens Simatic S7-300 PLC remote memory dump (more info ...)web-application-attack        URL
32803EXPLOIT-KIT CK exploit kit landing page (more info ...)trojan-activity        
32845APP-DETECT Absolute Software Computrace outbound connection - 209.53.113.223 (more info ...)misc-activity        URL
32846APP-DETECT Absolute Software Computrace outbound connection - absolute.com (more info ...)misc-activity        URL
32847APP-DETECT Absolute Software Computrace outbound connection - bh.namequery.com (more info ...)misc-activity        URL
32848APP-DETECT Absolute Software Computrace outbound connection - namequery.nettrace.co.za (more info ...)misc-activity        URL
32849APP-DETECT Absolute Software Computrace outbound connection - search.us.namequery.com (more info ...)misc-activity        URL
32850APP-DETECT Absolute Software Computrace outbound connection - search2.namequery.com (more info ...)misc-activity        URL
32851APP-DETECT Absolute Software Computrace outbound connection - search64.namequery.com (more info ...)misc-activity        URL
32879EXPLOIT-KIT Nuclear exploit kit payload delivery (more info ...)trojan-activity        
32880EXPLOIT-KIT Nuclear exploit kit outbound payload request (more info ...)trojan-activity        
32967POLICY-OTHER ManageEngine Desktop Central DCPlugin insecure admin account creation attempt (more info ...)policy-violation  2014-7862  71849    
32997SERVER-OTHER Sophos Web Appliance arbitrary command execution attempt (more info ...)attempted-admin  2014-2850      
32998SERVER-OTHER Sophos Web Appliance arbitrary command execution attempt (more info ...)attempted-admin  2014-2850      
33104SERVER-WEBAPP ManageEngine Multiple Products directory traversal attempt (more info ...)web-application-attack  2014-5301      
33166SERVER-WEBAPP Ruby on Rails arbitrary Ruby object deserialization attempt (more info ...)attempted-user  2014-6140  71424    
33167SERVER-WEBAPP Ruby on Rails arbitrary Ruby object deserialization attempt (more info ...)attempted-user  2014-6140  71424    
33168SERVER-WEBAPP Ruby on Rails arbitrary Ruby object deserialization attempt (more info ...)attempted-user  2014-6140  71424    
33169SERVER-WEBAPP Ruby on Rails arbitrary Ruby object deserialization attempt (more info ...)attempted-user  2014-6140  71424    
33183EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity        
33185EXPLOIT-KIT Angler exploit kit encrypted binary download (more info ...)trojan-activity        
33189SERVER-WEBAPP Samsung AllShare Cast command injection attempt (more info ...)attempted-admin        URL
33190SERVER-WEBAPP Samsung AllShare Cast command injection attempt (more info ...)attempted-admin        URL
33208MALWARE-OTHER Win.Trojan.Bladbindi obfuscated with Yano Obfuscator download attempt (more info ...)trojan-activity        URL
33225SERVER-MAIL Exim gethostbyname heap buffer overflow attempt (more info ...)attempted-admin  2015-0235  72325    URL
33226SERVER-MAIL Exim gethostbyname heap buffer overflow attempt (more info ...)attempted-admin  2015-0235  72325    URL
33280PUA-ADWARE Win.Adware.iBryte variant outbound connection (more info ...)trojan-activity        URL
33292EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity        URL
33304PUA-ADWARE Win.Adware.Gamevance variant outbound connection (more info ...)trojan-activity        URL
33306MALWARE-OTHER connection to malware sinkhole (more info ...)trojan-activity        URL
33311PUA-ADWARE Win.Adware.OptimizerPro variant outbound connection (more info ...)trojan-activity        URL
33446SERVER-WEBAPP Symantec Encryption Management Server command injection attempt (more info ...)web-application-attack  2014-7288  72308    
33447SERVER-WEBAPP Symantec Encryption Management Server command injection attempt (more info ...)web-application-attack  2014-7288  72308    
33448SERVER-WEBAPP Symantec Encryption Management Server command injection attempt (more info ...)web-application-attack  2014-7288  72308    
33452PUA-TOOLBARS Win.Toolbar.Crossrider variant outbound connection (more info ...)trojan-activity        URL
33483PUA-ADWARE Win.Adware.InstallMonster variant outbound connection (more info ...)trojan-activity        URL
33553PUA-ADWARE Win.Adware.iBryte variant outbound connection (more info ...)trojan-activity        URL
33573SERVER-WEBAPP ManageEngine Multiple Products FailOverHelperServlet information disclosure attempt (more info ...)attempted-recon  2014-7863      
33574SERVER-WEBAPP ManageEngine Multiple Products FailOverHelperServlet information disclosure attempt (more info ...)attempted-recon  2014-7863      
33597SERVER-WEBAPP ManageEngine Desktop Central MSP StatusUpdateServlet directory traversal attempt (more info ...)web-application-attack  2014-9404  71910    
33598SERVER-WEBAPP ManageEngine Desktop Central MSP StatusUpdateServlet directory traversal attempt (more info ...)web-application-attack  2014-9404  71910    
33599SERVER-WEBAPP ManageEngine Desktop Central MSP StatusUpdateServlet directory traversal attempt (more info ...)web-application-attack  2014-9404  71910    
33663EXPLOIT-KIT Angler exploit kit outbound uri structure (more info ...)trojan-activity        
33665SERVER-OTHER HP Client Automation command injection attempt (more info ...)attempted-admin  2015-1497  72612    
33711OS-WINDOWS Type one font out of bounds memory access attempt (more info ...)attempted-user  2015-0090      URL
33712OS-WINDOWS Type one font out of bounds memory access attempt (more info ...)attempted-user  2015-0090      URL
33722FILE-OTHER Type 1 font memory out-of-bounds read attempt (more info ...)attempted-user  2015-0092      URL
33723FILE-OTHER Type 1 font memory out-of-bounds read attempt (more info ...)attempted-user  2015-0092      URL
33758MALWARE-OTHER Win.Ransomware.CTB-Locker download attempt (more info ...)trojan-activity        URL
33759MALWARE-OTHER Win.Ransomware.CTB-Locker download attempt (more info ...)trojan-activity        URL
33812SERVER-WEBAPP Seagate NAS remote code execution attempt (more info ...)attempted-admin  2014-8687  72831    
33813SERVER-WEBAPP Eclipse Foundation Jetty HttpParser information disclosure attempt (more info ...)attempted-recon  2015-2080  72768    
33823MALWARE-BACKDOOR Win.Backdoor.Speccom variant outbound connection (more info ...)trojan-activity        URL
33874MALWARE-OTHER Win.Downloader.Latekonsul Runtime Detection (more info ...)trojan-activity        URL
33887SERVER-WEBAPP Citrix NetScaler xen_hotfix object parameter command injection attempt (more info ...)web-application-attack        URL
33888SERVER-WEBAPP Citrix NetScaler xen_hotfix object parameter command injection attempt (more info ...)web-application-attack        URL
33889SERVER-WEBAPP Websense Triton CommandLineServlet command injection attempt (more info ...)web-application-attack        URL
33890SERVER-WEBAPP Websense Triton CommandLineServlet command injection attempt (more info ...)web-application-attack        URL
33894SERVER-WEBAPP TWiki debugenableplugins arbitrary perl code injection attempt (more info ...)web-application-attack  2014-7236  70372    
33895SERVER-WEBAPP TWiki debugenableplugins arbitrary perl code injection attempt (more info ...)web-application-attack  2014-7236  70372    
33905EXPLOIT-KIT Rig exploit kit outbound communication (more info ...)trojan-activity        
33906EXPLOIT-KIT Rig exploit kit outbound communication (more info ...)trojan-activity        
33915SERVER-WEBAPP HP ArcSight Logger directory traversal attempt (more info ...)web-application-attack  2014-7884  73071    
33916SERVER-WEBAPP HP ArcSight Logger directory traversal attempt (more info ...)web-application-attack  2014-7884  73071    
33917SERVER-WEBAPP HP ArcSight Logger directory traversal attempt (more info ...)web-application-attack  2014-7884  73071    
33936SERVER-WEBAPP TRENDnet TN200 Network Storage System command injection attempt (more info ...)web-application-attack  2014-1628      
33937SERVER-WEBAPP TRENDnet TN200 Network Storage System command injection attempt (more info ...)web-application-attack  2014-1628      
33938SERVER-WEBAPP Seagate BlackArmor NAS send_test_email command injection attempt (more info ...)web-application-attack  2014-2701      
33939MALWARE-OTHER Executable control panel file attachment detected (more info ...)misc-activity        URL
33940MALWARE-OTHER Executable control panel file attachment detected (more info ...)misc-activity        URL
33941MALWARE-OTHER Executable control panel file download request (more info ...)misc-activity        URL
33943MALWARE-OTHER Executable control panel file download request (more info ...)misc-activity        URL
33982EXPLOIT-KIT Nuclear exploit kit landing page detected (more info ...)trojan-activity  2015-0336      
33983EXPLOIT-KIT Nuclear exploit kit obfuscated file download (more info ...)trojan-activity  2015-0336      URL
34194SERVER-WEBAPP RevSlider information disclosure attempt (more info ...)web-application-attack  2014-9734      URL
34300SERVER-WEBAPP D-Link multiple products HNAP SOAPAction header command injection attempt (more info ...)attempted-admin  2015-2051      
34336MALWARE-OTHER Html.Phishing.Crea outbound connection attempt (more info ...)trojan-activity        URL
34464SERVER-OTHER AsusWRT infosvr remote command execution attempt (more info ...)attempted-admin  2014-9583  71889    
34471SERVER-WEBAPP Symantec Critical System Protection directory traversal attempt (more info ...)attempted-admin  2014-3440  72091    
34500MALWARE-BACKDOOR Win.Backdoor.Wekby Torn variant outbound connection (more info ...)trojan-activity        URL
34604SERVER-WEBAPP Visual Mining NetCharts saveFile.jsp directory traversal attempt (more info ...)web-application-attack  2015-4031  74792    
34605SERVER-WEBAPP Visual Mining NetCharts saveFile.jsp directory traversal attempt (more info ...)web-application-attack  2015-4031  74792    
34606SERVER-WEBAPP Visual Mining NetCharts saveFile.jsp directory traversal attempt (more info ...)web-application-attack  2015-4031  74792    
34615SERVER-WEBAPP Synology Photo Station exif description command injection attempt (more info ...)web-application-attack        URL
34616SERVER-WEBAPP Synology Photo Station exif description command injection attempt (more info ...)web-application-attack        URL
34617SERVER-WEBAPP Synology Photo Station exif description command injection attempt (more info ...)web-application-attack        URL
34618SERVER-WEBAPP Synology Photo Station exif description command injection attempt (more info ...)web-application-attack        URL
34633SERVER-WEBAPP Visual Mining NetCharts projectContents.jsp directory traversal attempt (more info ...)web-application-attack  2015-4032  74788    
34634SERVER-WEBAPP Visual Mining NetCharts projectContents.jsp directory traversal attempt (more info ...)web-application-attack  2015-4032  74788    
34635SERVER-WEBAPP Visual Mining NetCharts projectContents.jsp directory traversal attempt (more info ...)web-application-attack  2015-4032  74788    
34716SERVER-WEBAPP ManageEngine Desktop Central FileUploadServlet directory traversal attempt (more info ...)web-application-attack  2015-8249      
34717SERVER-WEBAPP ManageEngine Desktop Central FileUploadServlet directory traversal attempt (more info ...)web-application-attack  2015-8249      
34718SERVER-WEBAPP ManageEngine Desktop Central FileUploadServlet directory traversal attempt (more info ...)web-application-attack  2015-8249      
34798SERVER-OTHER HP LoadRunner launcher.dll stack buffer overflow attempt (more info ...)attempted-admin  2015-2110  74737    
34799SERVER-WEBAPP UPnP AddPortMapping SOAP action command injection attempt (more info ...)attempted-admin  2014-8361  74330    
34938SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin  2015-1896  74024    
34939SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin  2015-1896  74024    
34940SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin  2015-1896  74024    
34941SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin  2015-1896  74024    
34942SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin  2015-1896  74024    
34943SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin  2015-1896  74024    
34948SERVER-WEBAPP Rocket Servergraph Admin Center userRequest command injection attempt (more info ...)web-application-attack  2014-3915      
34949SERVER-WEBAPP Rocket Servergraph Admin Center tsmRequest command injection attempt (more info ...)web-application-attack  2014-3915      
34967SERVER-OTHER Fortinet FSSO stack buffer overflow attempt (more info ...)attempted-admin  2015-2281  73206    URL
34969EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity        URL
34970EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity        URL
34976SERVER-WEBAPP SysAid Help Desk getGfiUpgradeFile directory traversal attempt (more info ...)web-application-attack  2015-2996  75038    
34977SERVER-WEBAPP SysAid Help Desk getGfiUpgradeFile directory traversal attempt (more info ...)web-application-attack  2015-2996  75038    
34978SERVER-WEBAPP SysAid Help Desk getGfiUpgradeFile directory traversal attempt (more info ...)web-application-attack  2015-2996  75038    
35003MALWARE-OTHER Win.Trojan.Malumpos malware download attempt (more info ...)trojan-activity        URL
35004MALWARE-OTHER Win.Trojan.Malumpos malware download attempt (more info ...)trojan-activity        URL
35024SERVER-WEBAPP Watchguard XCS mailqueue.spl command injection attempt (more info ...)web-application-attack        URL
35025SERVER-WEBAPP Watchguard XCS mailqueue.spl command injection attempt (more info ...)web-application-attack        URL
35026SERVER-WEBAPP Watchguard XCS mailqueue.spl command injection attempt (more info ...)web-application-attack        URL
35032SERVER-WEBAPP LANDesk Management Suite remote file include attempt (more info ...)web-application-attack  2014-5362  74190    
35033SERVER-WEBAPP LANDesk Management Suite remote file include attempt (more info ...)web-application-attack  2014-5362  74190    
35043SERVER-OTHER Apple Cups cupsd privilege escalation attempt (more info ...)attempted-admin  2015-1158  75098    URL
35054PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1018 attack attempt (more info ...)attempted-recon        
35055PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1018 attack attempt (more info ...)attempted-dos        
35056PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1018 attack attempt (more info ...)attempted-admin        
35057PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1018 attack attempt (more info ...)attempted-admin        
35058PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1018 attack attempt (more info ...)attempted-dos        
35059PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1018 attack attempt (more info ...)attempted-admin        
35061PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1018 attack attempt (more info ...)attempted-dos        
35084EXPLOIT-KIT Null Hole exploit kit binary download request (more info ...)trojan-activity        
35085EXPLOIT-KIT Null Hole exploit kit malicious swf request (more info ...)attempted-user        
35090OS-MOBILE iOS lockdownd plist object buffer overflow attempt (more info ...)attempted-admin        
35091OS-MOBILE iOS lockdownd plist object buffer overflow attempt (more info ...)attempted-admin        
35222INDICATOR-COMPROMISE known malicious SSL certificate - Win.Trojan.Dridex (more info ...)trojan-activity        URL
35243SERVER-WEBAPP Accellion Secure File Sharing Appliance command injection attempt (more info ...)web-application-attack        
35244SERVER-WEBAPP Accellion Secure File Sharing Appliance command injection attempt (more info ...)web-application-attack        
35245SERVER-WEBAPP Accellion Secure File Sharing Appliance command injection attempt (more info ...)web-application-attack        
35246SERVER-WEBAPP Accellion Secure File Sharing Appliance command injection attempt (more info ...)web-application-attack        
35256EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity        
35257SERVER-WEBAPP Accellion FTA verify_oauth_token command injection attempt (more info ...)web-application-attack  2015-2857      
35258SERVER-WEBAPP Accellion FTA verify_oauth_token command injection attempt (more info ...)web-application-attack  2015-2857      
35259SERVER-WEBAPP Accellion FTA verify_oauth_token command injection attempt (more info ...)web-application-attack  2015-2857      
35260SERVER-WEBAPP Accellion FTA verify_oauth_token command injection attempt (more info ...)web-application-attack  2015-2857      
35302SERVER-WEBAPP Accellion FTA arbitrary file read attempt (more info ...)attempted-recon  2015-2856      
35371MALWARE-BACKDOOR Win.Backdoor.Bimteni variant initial outbound connection (more info ...)trojan-activity        URL
35384MALWARE-BACKDOOR Win.Backdoor.Nicabown variant outbound connection (more info ...)trojan-activity        URL
35432FILE-IDENTIFY M4A file magic detected (more info ...)misc-activity        
35433FILE-IDENTIFY M4A file magic detected (more info ...)misc-activity        
35434OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-3829      
35435OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-3829      
35677SERVER-WEBAPP Dell KACE Appliance KSudoClient privilege escalation attempt (more info ...)attempted-admin        
35687SERVER-WEBAPP Semantec Endpoint Protection Manager server elevated privilege code execution attempt (more info ...)attempted-admin  2015-1489      
35688PROTOCOL-OTHER MiniUPNP rootdesc.xml file request (more info ...)misc-activity  2015-6031      URL
35690PROTOCOL-OTHER MiniUPNP rootdesc.xml buffer overflow attempt (more info ...)attempted-user  2015-6031      URL
35721OS-WINDOWS TRUFFLEHUNTER TALOS-2015-0008 attack attempt (more info ...)attempted-admin        URL
35722OS-WINDOWS TRUFFLEHUNTER TALOS-2015-0008 attack attempt (more info ...)attempted-admin        URL
35725FILE-MULTIMEDIA Matroska libmatroska ebml unicode string out of bounds read attempt (more info ...)attempted-user  2015-8789      URL
35726FILE-MULTIMEDIA Matroska libmatroska ebml unicode string out of bounds read attempt (more info ...)attempted-user  2015-8789      URL
35727FILE-OTHER TRUFFLEHUNTER TALOS-2015-0011 attack attempt (more info ...)attempted-user        URL
35728FILE-OTHER TRUFFLEHUNTER TALOS-2015-0011 attack attempt (more info ...)attempted-user        URL
35735OS-OTHER OS X DYLD_PRINT_TO_FILE privilege escalation attempt (more info ...)attempted-admin        URL
35736OS-OTHER OS X DYLD_PRINT_TO_FILE privilege escalation attempt (more info ...)attempted-admin        URL
35745INDICATOR-COMPROMISE Wild Neutron potential exploit attempt (more info ...)trojan-activity        URL
35769MALWARE-BACKDOOR Win.Backdoor.Cobrike inbound connection (more info ...)trojan-activity        URL
35770MALWARE-BACKDOOR Win.Backdoor.Cobrike outbound connection (more info ...)trojan-activity        URL
35795FILE-IDENTIFY ZSoft PCX file attachment detected (more info ...)misc-activity        
35796FILE-IDENTIFY ZSoft PCX file attachment detected (more info ...)misc-activity        
35797FILE-IDENTIFY ZSoft PCX file download request (more info ...)misc-activity        
35834FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-CAN-0043 attack attempt (more info ...)attempted-user        URL
35835FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-CAN-0043 attack attempt (more info ...)attempted-user        URL
35845EXPLOIT-KIT Nuclear exploit kit landing page detected (more info ...)attempted-user        
35850SERVER-OTHER EMC Documentum Content Server privilege escalation attempt (more info ...)attempted-admin  2015-4532      URL
35852FILE-IDENTIFY JPEG file upload detected (more info ...)misc-activity        
35885POLICY-OTHER MBean retrieval attempt (more info ...)attempted-user        URL
35888PROTOCOL-SCADA SCADA Engine OPC Server arbitrary file upload attempt (more info ...)attempted-admin        
35892SERVER-OTHER GE Proficy Real-Time Information Portal arbitrary dll load attempt (more info ...)attempted-admin        
35893SERVER-OTHER GE Proficy Real-Time Information Portal arbitrary dll load attempt (more info ...)attempted-admin        
35894SERVER-OTHER HP OpenView Data Protector Omnilnet command injection attempt (more info ...)attempted-admin        
35896SERVER-OTHER GE Proficy CIMPLICITY Marquee Manager stack buffer overflow attempt (more info ...)attempted-admin        
35897SERVER-OTHER IBM Tivoli Storage Manager FastBack command injection attempt (more info ...)attempted-admin        URL
35898SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin        URL
35899SERVER-OTHER IBM Tivoli Storage Manager FastBack stack buffer overflow attempt (more info ...)attempted-admin        
35900SERVER-OTHER IBM Tivoli Storage Manager FastBack stack buffer overflow attempt (more info ...)attempted-admin        
35901SERVER-OTHER IBM Tivoli Storage Manager FastBack stack buffer overflow attempt (more info ...)attempted-admin        
35902SERVER-OTHER IBM Tivoli Storage Manager FastBack command injection attempt (more info ...)attempted-admin        URL
35903SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin        URL
35905SERVER-OTHER HP Network Node Manager pmd.exe request detected (more info ...)protocol-command-decode        
35906SERVER-OTHER HP Network Node Manager pmd.exe buffer overflow attempt (more info ...)attempted-admin        
35907SERVER-OTHER HP Network Node Manager pmd.exe request detected (more info ...)protocol-command-decode        
35908SERVER-OTHER HP Network Node Manager pmd.exe buffer overflow attempt (more info ...)attempted-admin        
35909SERVER-OTHER Siemens Desigo Insight buffer overflow attempt (more info ...)attempted-admin        URL
35910SERVER-OTHER Siemens Desigo Insight information disclosure attempt (more info ...)attempted-admin        URL
35911SERVER-OTHER Websense TRITON xml namespace buffer overflow attempt (more info ...)attempted-dos        
35912SERVER-OTHER Websense TRITON xml namespace buffer overflow attempt (more info ...)attempted-dos        
35920SERVER-OTHER General Electric Proficy memory leakage request attempt (more info ...)attempted-recon        
35922SERVER-WEBAPP Entrust Authority Enrollment Server stack buffer overflow attempt (more info ...)attempted-admin        
35926SERVER-WEBAPP Oracle Identity Management authorization bypass attempt (more info ...)attempted-admin        
35927SERVER-WEBAPP Oracle Identity Management remote file execution attempt (more info ...)policy-violation        
36052SERVER-WEBAPP Silver Peak VXOA JSON interface hidden credentials authentication attempt (more info ...)attempted-admin        URL
36058FILE-IDENTIFY OLE Document upload detected (more info ...)misc-activity        
36071EXPLOIT-KIT Angler exploit kit browser version detection attempt (more info ...)attempted-recon        
36101SERVER-WEBAPP ManageEngine ServiceDesk ExportImport.do directory traversal attempt (more info ...)web-application-attack        URL
36102SERVER-WEBAPP ManageEngine ServiceDesk ExportImport.do directory traversal attempt (more info ...)web-application-attack        URL
36201EXPLOIT-KIT Scanbox exploit kit exfiltration attempt (more info ...)trojan-activity        URL
36210OS-WINDOWS TRUFFLEHUNTER TALOS-2015-0002 attack attempt (more info ...)attempted-dos        URL
36211OS-WINDOWS TRUFFLEHUNTER TALOS-2015-0002 attack attempt (more info ...)attempted-dos        URL
36212FILE-OTHER Libgraphite LocaLookup out-of-bounds read attempt (more info ...)attempted-user  2016-1521      URL
36213FILE-OTHER Libgraphite LocaLookup out-of-bounds read attempt (more info ...)attempted-user  2016-1521      URL
36214FILE-OTHER TRUFFLEHUNTER TALOS-2020-1119 attack attempt (more info ...)attempted-admin        URL
36215FILE-OTHER TRUFFLEHUNTER TALOS-2020-1119 attack attempt (more info ...)attempted-admin        URL
36216FILE-OTHER libgraphite TTF opcode handling out of bounds read attempt (more info ...)attempted-user  2016-1521      URL
36217FILE-OTHER libgraphite TTF opcode handling out of bounds read attempt (more info ...)attempted-user  2016-1521      URL
36218OS-WINDOWS TRUFFLEHUNTER TALOS-CAN-0056 attack attempt (more info ...)attempted-admin        URL
36219OS-WINDOWS TRUFFLEHUNTER TALOS-CAN-0056 attack attempt (more info ...)attempted-admin        URL
36220OS-WINDOWS TRUFFLEHUNTER TALOS-CAN-0056 attack attempt (more info ...)attempted-admin        URL
36221OS-WINDOWS TRUFFLEHUNTER TALOS-CAN-0056 attack attempt (more info ...)attempted-admin        URL
36222OS-WINDOWS TRUFFLEHUNTER TALOS-2015-0005 attack attempt (more info ...)attempted-user        URL
36223OS-WINDOWS TRUFFLEHUNTER TALOS-2015-0005 attack attempt (more info ...)attempted-user        URL
36225FILE-OTHER Libgraphite empty feature list denial of service attempt (more info ...)denial-of-service  2016-1522      URL
36226FILE-OTHER Libgraphite empty feature list denial of service attempt (more info ...)denial-of-service  2016-1522      URL
36227FILE-OTHER Libgraphite empty feature list denial of service attempt (more info ...)denial-of-service  2016-1522      URL
36228FILE-OTHER Libgraphite empty feature list denial of service attempt (more info ...)denial-of-service  2016-1522      URL
36241MALWARE-OTHER self-signed SSL certificate transfer for EXEPROXY attempt (more info ...)trojan-activity        
36242SERVER-WEBAPP Reprise License Manager edit_lf_get_data directory traversal attempt (more info ...)web-application-attack        URL
36272SERVER-WEBAPP GE MDS PulseNet hidden credentials authentication attempt (more info ...)attempted-admin  2015-6456  76756    URL
36286EXPLOIT-KIT Nuclear exploit kit browser detection attempt (more info ...)attempted-recon        
36307FILE-IMAGE Trimble SketchUp corrupt BMP RLE4 heap buffer overflow attempt (more info ...)attempted-user  2013-3664      
36308FILE-IMAGE Trimble SketchUp corrupt BMP RLE4 heap buffer overflow attempt (more info ...)attempted-user  2013-3664      
36309FILE-IMAGE Trimble SketchUp corrupt BMP RLE4 heap buffer overflow attempt (more info ...)attempted-user  2013-3664      
36310FILE-IMAGE Trimble SketchUp corrupt BMP RLE4 heap buffer overflow attempt (more info ...)attempted-user  2013-3664      
36315EXPLOIT-KIT Angler exploit kit relay traffic detected (more info ...)trojan-activity        
36330SERVER-WEBAPP Kaseya VSA uploader.aspx PathData directory traversal attempt (more info ...)web-application-attack  2015-6922      
36332EXPLOIT-KIT Angler exploit kit relay traffic detected (more info ...)trojan-activity        
36333SERVER-WEBAPP GE MDS PulseNET FileDownloadServlet directory traversal attempt (more info ...)web-application-attack  2015-6459  76756    
36380SERVER-WEBAPP Borland AccuRev SaveContentServiceImpl servlet directory traversal attempt (more info ...)web-application-attack        URL
36385FILE-OTHER SIL LibGraphite BracketPairStack out of bounds access exploit attempt (more info ...)attempted-user  2016-1522      URL
36386FILE-OTHER SIL LibGraphite BracketPairStack out of bounds access exploit attempt (more info ...)attempted-user  2016-1522      URL
36387FILE-OTHER Libgraphite context item handling arbitrary code execution attempt (more info ...)attempted-user  2016-1523      URL
36388FILE-OTHER Libgraphite context item handling arbitrary code execution attempt (more info ...)attempted-user  2016-1523      URL
36457EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
36542SERVER-WEBAPP HP OpenView Network Node Manager HTTP handling buffer overflow attempt (more info ...)attempted-admin  2008-1697  28569    
36543EXPLOIT-KIT Hunter exploit kit landing page detected (more info ...)attempted-user        URL
36544SERVER-WEBAPP pChart script parameter directory traversal attempt (more info ...)web-application-attack        
36635EXPLOIT-KIT Angler exploit kit search uri request attempt (more info ...)attempted-user        
36636EXPLOIT-KIT Angler exploit kit index uri request attempt (more info ...)attempted-user        
36637EXPLOIT-KIT Angler exploit kit viewtopic uri request attempt (more info ...)attempted-user        
36658FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
36659FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
36660FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
36661FILE-OTHER Interactive Data eSignal stack buffer overflow attempt (more info ...)attempted-user  2011-3494      
36748FILE-IDENTIFY TTF file attachment detected (more info ...)misc-activity        
36778SERVER-WEBAPP F5 BIG-IP iControl API arbitrary command execution attempt (more info ...)attempted-admin  2015-3628      URL
36785EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
36788EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
36790EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
36793SERVER-WEBAPP Oracle BeeHive playAudioFile.jsp directory traversal attempt (more info ...)web-application-attack        URL
36794SERVER-WEBAPP Oracle BeeHive playAudioFile.jsp directory traversal attempt (more info ...)web-application-attack        URL
36795SERVER-WEBAPP Oracle BeeHive playAudioFile.jsp directory traversal attempt (more info ...)web-application-attack        URL
36796EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
36798EXPLOIT-KIT GongDa landing page detected (more info ...)attempted-user        
36801EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
36802EXPLOIT-KIT Angler exploit kit browser version detection attempt (more info ...)attempted-recon        
36803SERVER-OTHER HP Intelligent Management Center img buffer overflow attempt (more info ...)attempted-admin  2011-1848  47789    
36808EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
36824EXPLOIT-KIT Known exploit kit obfuscation routine detected (more info ...)attempted-user  2014-6332      URL
36825PUA-ADWARE DealPly Adware variant outbound connection (more info ...)misc-activity        URL
36855FILE-OTHER Wireshark DECT packet dissector overflow attempt (more info ...)attempted-user  2011-1591  47392    
36899EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
36900SERVER-WEBAPP Oracle BeeHive showRecxml.jsp directory traversal attempt (more info ...)web-application-attack  2010-4417  45854    
36901SERVER-WEBAPP Oracle BeeHive showRecxml.jsp directory traversal attempt (more info ...)web-application-attack  2010-4417  45854    
36902SERVER-WEBAPP Oracle BeeHive showRecxml.jsp directory traversal attempt (more info ...)web-application-attack  2010-4417  45854    
37016EXPLOIT-KIT DoloMalo exploit kit packer detected (more info ...)trojan-activity        
37039SERVER-WEBAPP Atlassian HipChat Plugin template injection remote code execution attempt (more info ...)attempted-admin  2015-5603  76698    URL
37130FILE-IDENTIFY Obfuscated .wsf download attempt (more info ...)policy-violation        URL
37132FILE-IDENTIFY Obfuscated .wsf download attempt (more info ...)policy-violation        URL
37138SERVER-WEBAPP ManageEngine ServiceDesk FileDownload.jsp fName directory traversal attempt (more info ...)web-application-attack        URL
37139SERVER-WEBAPP ManageEngine ServiceDesk FileDownload.jsp fName directory traversal attempt (more info ...)web-application-attack        URL
37140SERVER-WEBAPP ManageEngine ServiceDesk FileDownload.jsp fName directory traversal attempt (more info ...)web-application-attack        URL
37146SERVER-OTHER Juniper ScreenOS unauthorized backdoor access attempt (more info ...)attempted-admin  2015-7755      URL
37147SERVER-OTHER Seagate GoFlex Satellite hidden credentials authentication attempt (more info ...)attempted-admin  2015-2874  76547    
37207EXPLOIT-KIT Neutrino exploit kit landing page (more info ...)trojan-activity        
37222MALWARE-OTHER Win.Worm.Pixipos Outbound Connection Attempt (more info ...)trojan-activity        URL
37242SERVER-WEBAPP D-Link DCS-900 Series Network Camera arbitrary file upload attempt (more info ...)attempted-admin  2015-2049      
37285SERVER-OTHER Trend Micro local node.js http command execution attempt (more info ...)attempted-user        URL
37286SERVER-OTHER Trend Micro local node.js http command execution attempt (more info ...)attempted-user        URL
37287SERVER-OTHER Trend Micro local node.js http command execution attempt (more info ...)attempted-user        URL
37289SERVER-OTHER Trend Micro local node.js http command execution attempt (more info ...)attempted-user        URL
37290SERVER-OTHER Trend Micro local node.js http command execution attempt (more info ...)attempted-user        URL
37292SERVER-OTHER Trend Micro local node.js http command execution attempt (more info ...)attempted-user        URL
37312FILE-OTHER Mulitple products external entity data exfiltration attempt (more info ...)misc-attack  2015-5088      URL
37313FILE-OTHER Multiple products external entity data exfiltration attempt (more info ...)misc-attack  2015-5088      URL
37324SERVER-WEBAPP AVM FritzBox dsl_control stack buffer overflow attempt (more info ...)attempted-admin        URL
37411SERVER-WEBAPP SevOne NMS hidden credentials authentication attempt (more info ...)attempted-admin        URL
37446SERVER-OTHER BigAnt server USV command buffer overflow attempt (more info ...)misc-attack    37520    
37493FILE-OTHER lhasa decode_level3_header heap corruption attempt (more info ...)attempted-user  2016-2347      URL
37494FILE-OTHER lhasa decode_level3_header heap corruption attempt (more info ...)attempted-user  2016-2347      URL
37504SERVER-WEBAPP SAP HANA hdbindexserver buffer overflow attempt (more info ...)attempted-admin  2015-7986      URL
37517FILE-OTHER Apple OSX local privilege escalation attempt (more info ...)attempted-user  2016-1743      URL
37518FILE-OTHER Apple OSX local privilege escalation attempt (more info ...)attempted-user  2016-1743      URL
37519FILE-OTHER Intel HD Graphics Windows kernel driver local privilege escalation attempt (more info ...)attempted-user  2016-5647      URL
37520FILE-OTHER Intel HD Graphics Windows kernel driver local privilege escalation attempt (more info ...)attempted-user  2016-5647      URL
37525SERVER-OTHER NTP arbitrary pidfile and driftfile overwrite attempt (more info ...)policy-violation  2015-7703  77278    URL
37526SERVER-OTHER NTP arbitrary pidfile and driftfile overwrite attempt (more info ...)policy-violation  2015-7703  77278    URL
37528EXPLOIT-KIT Nuclear exploit kit outbound uri request attempt (more info ...)attempted-user        URL
37529EXPLOIT-KIT Nuclear exploit kit iframe injection attempt (more info ...)attempted-user        URL
37548EXPLOIT-KIT Malicious iFrame redirection injection attempt (more info ...)trojan-activity        
37549EXPLOIT-KIT Malicious iFrame injection outbound URI request attempt (more info ...)attempted-user        
37550EXPLOIT-KIT Nuclear landing page detected (more info ...)attempted-user        
37551EXPLOIT-KIT Nuclear landing page detected (more info ...)attempted-user        
37622SERVER-WEBAPP Allen-Bradley Compact Logix cross site scripting attempt (more info ...)attempted-user        
37623SERVER-WEBAPP Allen-Bradley Compact Logix cross site scripting attempt (more info ...)attempted-user        
37624SERVER-WEBAPP Allen-Bradley Compact Logix cross site scripting attempt (more info ...)attempted-user        
37642PUA-ADWARE Win.Adware.Dealply outbound POST attempt (more info ...)misc-activity        URL
37651MALWARE-TOOLS Win.Trojan.Downloader outbound connection attempt (more info ...)trojan-activity        
37657SERVER-WEBAPP Headline Portal Engine HPEInc remote file include attempt (more info ...)web-application-attack    19663    
37658SERVER-WEBAPP Headline Portal Engine HPEInc remote file include attempt (more info ...)web-application-attack    19663    
37659SERVER-WEBAPP Headline Portal Engine HPEInc remote file include attempt (more info ...)web-application-attack    19663    
37660SERVER-WEBAPP Headline Portal Engine HPEInc remote file include attempt (more info ...)web-application-attack    19663    
37661SERVER-WEBAPP Headline Portal Engine HPEInc remote file include attempt (more info ...)web-application-attack    19663    
37662SERVER-WEBAPP Headline Portal Engine HPEInc remote file include attempt (more info ...)web-application-attack    19663    
37799FILE-OTHER Kingsoft Writer long font name buffer overflow attempt (more info ...)attempted-user  2013-3934  61796    
37800FILE-OTHER Kingsoft Writer long font name buffer overflow attempt (more info ...)attempted-user  2013-3934  61796    
37871EXPLOIT-KIT Angler exploit kit index uri request attempt (more info ...)attempted-user        
37872EXPLOIT-KIT Angler exploit kit viewthread uri request attempt (more info ...)attempted-user        
37873EXPLOIT-KIT Angler exploit kit view uri request attempt (more info ...)attempted-user        
37919EXPLOIT-KIT Gong da exploit kit landing page (more info ...)trojan-activity        
37957EXPLOIT-KIT Angler exploit kit view uri request attempt (more info ...)attempted-user        
37958EXPLOIT-KIT Angler exploit kit viewthread uri request attempt (more info ...)attempted-user        
38121EXPLOIT-KIT Angler exploit kit search uri request attempt (more info ...)attempted-user        
38133EXPLOIT-KIT Angler exploit kit gate redirector (more info ...)attempted-user        
38160EXPLOIT-KIT Angler exploit kit gate detected (more info ...)trojan-activity        
38161EXPLOIT-KIT Angler exploit kit index uri request attempt (more info ...)attempted-user        
38162EXPLOIT-KIT Angler exploit kit viewthread uri request attempt (more info ...)attempted-user        
38163EXPLOIT-KIT Angler exploit kit view uri request attempt (more info ...)attempted-user        
38164SERVER-WEBAPP Oracle Application Testing Suite UploadFileAction servlet directory traversal attempt (more info ...)web-application-attack  2016-0491  81169    
38248SERVER-OTHER IBM Tivoli Storage Manager FastBack Server opcode 1329 buffer overflow attempt (more info ...)attempted-admin  2015-1924  75447    
38254EXPLOIT-KIT Known malicious redirection attempt (more info ...)attempted-user        URL
38271SERVER-OTHER Wavelink Emulation License Server malicious URI code execution attempt (more info ...)attempted-user  2015-4059      
38275EXPLOIT-KIT Neutrino exploit kit redirection attempt (more info ...)trojan-activity        URL
38279MALWARE-OTHER Win.Trojan.Samas variant download attempt (more info ...)trojan-activity        URL
38280MALWARE-OTHER Win.Trojan.Samas variant download attempt (more info ...)trojan-activity        URL
38286SERVER-WEBAPP Reprise License Manager actserver stack buffer overflow attempt (more info ...)attempted-admin  2015-6946      URL
38287SERVER-WEBAPP Reprise License Manager akey stack buffer overflow attempt (more info ...)attempted-admin  2015-6946      URL
38288SERVER-WEBAPP Reprise License Manager licfile stack buffer overflow attempt (more info ...)attempted-admin  2015-6946      URL
38303SERVER-WEBAPP Bonita BPM themeResource directory traversal attempt (more info ...)web-application-attack  2015-3897  75130    
38312SERVER-OTHER Redis lua script integer overflow attempt (more info ...)attempted-user  2015-8080      
38313SERVER-OTHER Redis lua script integer overflow attempt (more info ...)attempted-user  2015-8080      
38327MALWARE-BACKDOOR ReGeorg proxy read attempt (more info ...)misc-activity        URL
38328MALWARE-BACKDOOR ReGeorg socks proxy connection attempt (more info ...)misc-activity        URL
38329MALWARE-BACKDOOR ReGeorg socks proxy initial connection attempt (more info ...)misc-activity        URL
38360MALWARE-OTHER Win.Trojan.Samas variant download attempt (more info ...)trojan-activity        URL
38361MALWARE-OTHER Win.Trojan.Samas variant download attempt (more info ...)trojan-activity        URL
38372MALWARE-OTHER Win.Trojan.Maktub variant download attempt (more info ...)trojan-activity        URL
38373MALWARE-OTHER Win.Trojan.Maktub variant download attempt (more info ...)trojan-activity        URL
38374MALWARE-OTHER Win.Trojan.Maktub variant download attempt (more info ...)trojan-activity        URL
38375MALWARE-OTHER Win.Trojan.Maktub variant download attempt (more info ...)trojan-activity        URL
38376MALWARE-OTHER Win.Trojan.Maktub variant download attempt (more info ...)trojan-activity        URL
38377MALWARE-OTHER Win.Trojan.Maktub variant download attempt (more info ...)trojan-activity        URL
38389SERVER-WEBAPP HID door command injection attempt (more info ...)attempted-admin        URL
38390SERVER-OTHER HP JetDirect PJL path traversal attempt (more info ...)attempted-recon  2010-4107  44882    
38391SERVER-OTHER HP JetDirect PJL path traversal attempt (more info ...)attempted-recon  2010-4107  44882    
38437EXPLOIT-KIT Angler exploit kit outbound uri structure (more info ...)trojan-activity        
38438EXPLOIT-KIT Angler exploit kit questions uri request attempt (more info ...)attempted-user        
38441MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38442MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38443MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38444MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38445MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38446MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38447MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38448MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38449MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38450MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38451MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38452MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38453MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38454MALWARE-OTHER Win.Trojan.Petya variant download attempt (more info ...)trojan-activity        URL
38518SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack  2016-0481  81097    
38519SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack  2016-0481  81097    
38520SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack  2016-0481  81097    
38521EXPLOIT-KIT Angler exploit kit redirect page detected (more info ...)attempted-user        
38522EXPLOIT-KIT Angler landing page detected (more info ...)attempted-user        
38523EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
38524EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user        
38525MALWARE-OTHER Win.Trojan.Troll dropper document file detected (more info ...)trojan-activity        URL
38526MALWARE-OTHER Win.Trojan.Troll dropper document file detected (more info ...)trojan-activity        URL
38529MALWARE-OTHER XBot CC Social Engineering (more info ...)trojan-activity        URL
38541INDICATOR-OBFUSCATION newline only separator evasion (more info ...)non-standard-protocol        URL
38555EXPLOIT-KIT Angler landing page detected (more info ...)attempted-user        
38579SERVER-WEBAPP Atvise denial of service attempt (more info ...)attempted-dos        URL
38582EXPLOIT-KIT Nuclear exploit kit landing page detected (more info ...)attempted-user        
38589EXPLOIT-KIT vbscript downloading executable attempt (more info ...)attempted-user        
38592EXPLOIT-KIT Nuclear Exploit Kit back end communications attempt (more info ...)trojan-activity        URL
38593EXPLOIT-KIT Nuclear Exploit Kit back end communications attempt (more info ...)trojan-activity        URL
38623FILE-OTHER GDCM DICOM image integer overflow attempt (more info ...)attempted-user  2015-8396      
38624FILE-OTHER GDCM DICOM image integer overflow attempt (more info ...)attempted-user  2015-8396      
38627FILE-OTHER libarchive zip_read_mac_metadata heap buffer overflow attempt (more info ...)attempted-user  2016-1541      URL
38628FILE-OTHER libarchive zip_read_mac_metadata heap buffer overflow attempt (more info ...)attempted-user  2016-1541      URL
38648SERVER-OTHER Trend Micro remote debugging URL handling remote code execution attempt (more info ...)attempted-user        URL
38649SERVER-OTHER Trend Micro remote debugging URL handling remote code execution attempt (more info ...)attempted-user        URL
38650MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38651MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38652MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38653MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38654MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38655MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38656MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38657MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38658MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38659MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38660MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38661MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38662MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38663MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38664MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38665MALWARE-OTHER PWOBot variant download attempt (more info ...)trojan-activity        URL
38671BROWSER-IE SFVRT-1021 attack attempt (more info ...)attempted-user        
38672BROWSER-IE SFVRT-1021 attack attempt (more info ...)attempted-user        
38682EXPLOIT-KIT Angler Exploit Kit email gate (more info ...)trojan-activity        
38683MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38684MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38685MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38686MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38687MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38688MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38689MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38690MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38691MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38692MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38693MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38694MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38695MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38696MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38697MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38698MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38699MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38700MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38701MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38702MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38703MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38704MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38705MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38706MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38707MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38708MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38709MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38710MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38711MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38712MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38713MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38714MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38715MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38716MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38717MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38718MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38719MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
38743FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
38744FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
38745MALWARE-OTHER known phishing x-mailer attempt (more info ...)trojan-activity        
38789SERVER-WEBAPP Oracle application testing suite DownloadServlet directory traversal attempt (more info ...)web-application-attack  2016-0485      
38790SERVER-WEBAPP Oracle application testing suite DownloadServlet directory traversal attempt (more info ...)web-application-attack  2016-0485      
38791SERVER-WEBAPP Oracle application testing suite DownloadServlet directory traversal attempt (more info ...)web-application-attack  2016-0485      
38796SERVER-OTHER Adroit denial of service attempt (more info ...)attempted-dos        
38849OS-WINDOWS Kaspersky Internet Security KLIF driver denial of service attempt (more info ...)attempted-dos  2016-4304      URL
38850OS-WINDOWS Kaspersky Internet Security KLIF driver denial of service attempt (more info ...)attempted-dos  2016-4304      URL
38860FILE-OTHER Oracle OIT ContentAccess libvs_mwkd out of bounds write attempt (more info ...)attempted-user  2016-3593      URL
38861FILE-OTHER Oracle OIT ContentAccess libvs_mwkd out of bounds write attempt (more info ...)attempted-user  2016-3593      URL
38871FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
38876EXPLOIT-KIT Obfuscated exploit download attempt (more info ...)attempted-user        URL
38879SERVER-WEBAPP HP Enterprise Vertica validateAdminConfig command injection attempt (more info ...)web-application-attack  2016-2002      URL
38880SERVER-WEBAPP HP Enterprise Vertica validateAdminConfig command injection attempt (more info ...)web-application-attack  2016-2002      URL
38892MALWARE-OTHER Win.Trojan.Maktub variant download attempt (more info ...)trojan-activity        URL
38893MALWARE-OTHER Win.Trojan.Maktub variant download attempt (more info ...)trojan-activity        URL
38894SERVER-WEBAPP Jenkins CI Server insecure deserialization command execution attempt (more info ...)attempted-admin  2016-0792      URL
38934SERVER-WEBAPP Oracle Application Testing Suite actionservlet directory traversal attempt (more info ...)attempted-user  2016-0487      
38939SERVER-WEBAPP ORACLE-SERVER Oracle Application Testing Suite filename directory traversal attempt (more info ...)web-application-attack  2016-0490      
38945FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
38946FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
38947FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
38948FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
38951PUA-ADWARE Win.Adware.OpenSoftwareUpdater variant outbound connection attempt (more info ...)trojan-activity        URL
38952PUA-ADWARE Win.Adware.OpenSoftwareUpdater variant outbound connection attempt (more info ...)trojan-activity        URL
38953PUA-ADWARE Win.Adware.OpenSoftwareUpdater variant outbound connection attempt (more info ...)trojan-activity        URL
38965SERVER-WEBAPP VMware vCenter Chargeback Manager ImageUploadServlet arbitrary JSP file upload attempt (more info ...)attempted-user  2013-3520  60484    URL
38968SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack  2016-0476      
38969SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack  2016-0476      
38970SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack  2016-0476      
38986SERVER-WEBAPP SAP NetWeaver xMII directory traversal attempt (more info ...)web-application-attack  2016-2389      
38987SERVER-WEBAPP SAP NetWeaver xMII directory traversal attempt (more info ...)web-application-attack  2016-2389      
38988SERVER-WEBAPP SAP NetWeaver xMII directory traversal attempt (more info ...)web-application-attack  2016-2389      
39000FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
39001FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
39002FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
39003FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
39004FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
39005FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
39006FILE-IMAGE ImageMagick WWWDecodeDelegate command injection attempt (more info ...)attempted-user  2016-3714  89848    URL
39058MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
39059MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
39066SERVER-OTHER Magento unauthenticated arbitrary file write attempt (more info ...)attempted-admin  2016-4010      URL
39070SERVER-WEBAPP Dlink local file disclosure attempt (more info ...)web-application-attack    64043    
39078OS-WINDOWS Kaspersky Internet Security KLIF driver denial of service attempt (more info ...)attempted-dos  2016-4305      URL
39079OS-WINDOWS Kaspersky Internet Security KLIF driver denial of service attempt (more info ...)attempted-dos  2016-4305      URL
39087SERVER-WEBAPP Oracle Application Testing Suite arbitrary file read attempt (more info ...)web-application-attack  2016-0482      
39088SERVER-WEBAPP Oracle Application Testing Suite arbitrary file read attempt (more info ...)web-application-attack  2016-0482      
39089SERVER-WEBAPP Oracle Application Testing Suite arbitrary file read attempt (more info ...)web-application-attack  2016-0482      
39090FILE-IMAGE ImageMagick and GraphicsMagick OpenBlob command injection attempt (more info ...)attempted-user  2016-5118      
39091FILE-IMAGE ImageMagick and GraphicsMagick OpenBlob command injection attempt (more info ...)attempted-user  2016-5118      
39092FILE-IMAGE ImageMagick and GraphicsMagick OpenBlob command injection attempt (more info ...)attempted-user  2016-5118      
39093FILE-IMAGE ImageMagick and GraphicsMagick OpenBlob command injection attempt (more info ...)attempted-user  2016-5118      
39094FILE-IMAGE ImageMagick and GraphicsMagick OpenBlob command injection attempt (more info ...)attempted-user  2016-5118      
39095FILE-IMAGE ImageMagick and GraphicsMagick OpenBlob command injection attempt (more info ...)attempted-user  2016-5118      
39096FILE-IMAGE ImageMagick and GraphicsMagick OpenBlob command injection attempt (more info ...)attempted-user  2016-5118      
39097FILE-IMAGE ImageMagick and GraphicsMagick OpenBlob command injection attempt (more info ...)attempted-user  2016-5118      
39128EXPLOIT-KIT Nuclear landing page detected (more info ...)attempted-user        
39129EXPLOIT-KIT Nuclear gate redirect attempt (more info ...)attempted-user        
39130EXPLOIT-KIT Obfuscated exploit download attempt (more info ...)attempted-user        URL
39165SERVER-WEBAPP iperf3 heap overflow remote code execution attempt (more info ...)attempted-user  2016-4303      URL
39188SERVER-WEBAPP Nagios XI backend API server side request forgery attempt (more info ...)web-application-attack        URL
39189PUA-TOOLBARS Win.Toolbar.Crossrider variant outbound connection (more info ...)trojan-activity        URL
39198SERVER-WEBAPP D-Link authentication bypass attempt (more info ...)attempted-admin    45554    
39241EXPLOIT-KIT Neutrino Exploit Kit exploitation attempt (more info ...)attempted-user        
39356MALWARE-OTHER Lamer outbound communication attempt (more info ...)trojan-activity        URL
39357MALWARE-OTHER Flopex outbound communication attempt (more info ...)trojan-activity        URL
39379FILE-EXECUTABLE Norton Antivirus ASPack heap corruption attempt (more info ...)attempted-admin  2016-2208      URL
39385FILE-OTHER Symantec Norton Antivirus ccScanw.dll Unpack ShortLZ memory corruption attempt (more info ...)attempted-user  2016-2207      URL
39386FILE-OTHER Symantec Norton Antivirus ccScanw.dll Unpack ShortLZ memory corruption attempt (more info ...)attempted-user  2016-2207      URL
39387SERVER-WEBAPP D-Link DAP-1160 authentication bypass attempt (more info ...)attempted-admin    41187    
39391PROTOCOL-SCADA 3S CoDeSys Gateway Server stack buffer overflow attempt (more info ...)attempted-admin  2012-4708      
39392SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 214 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
39393SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 215 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
39394SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 216 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
39395SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 219 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
39396SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 257 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
39397SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 263 buffer overflow attempt (more info ...)attempted-admin  2013-6195  64647    URL
39398SERVER-WEBAPP Symantec SEPM management console cross site scripting attempt (more info ...)attempted-user  2016-3652  91444    
39400SERVER-WEBAPP Symantec Decomposer Engine Dec2LHA buffer overflow attempt (more info ...)attempted-user  2016-2210      
39401SERVER-WEBAPP Symantec Decomposer Engine Dec2LHA buffer overflow attempt (more info ...)attempted-user  2016-2210      
39402FILE-OTHER Symantec Antivirus ALPkOldFormatDecompressor out of bounds read attempt (more info ...)attempted-user  2016-3646      URL
39403FILE-OTHER Symantec Antivirus ALPkOldFormatDecompressor out of bounds read attempt (more info ...)attempted-user  2016-3646      URL
39404SERVER-OTHER Symantec Endpoint Protection Manager cross site request forgery attempt (more info ...)attempted-user  2016-3653      URL
39405SERVER-OTHER Symantec Endpoint Protection Manager cross site request forgery attempt (more info ...)attempted-user  2016-3653      URL
39406SERVER-OTHER D-LINK DAP-1160 unauthenticated remote configuration attempt (more info ...)attempted-admin    41187    URL
39407SERVER-OTHER D-LINK DAP-1160 unauthenticated remote configuration attempt (more info ...)attempted-admin    41187    URL
39408SERVER-OTHER D-LINK DAP-1160 unauthenticated remote configuration attempt (more info ...)attempted-admin    41187    URL
39412SERVER-WEBAPP WANem WAN emulator command injection attempt (more info ...)web-application-attack        URL
39416PUA-OTHER RMS rmansys remote management tool cnc communication (more info ...)misc-activity        URL
39431FILE-OTHER Symantec TNEF decoder integer overflow attempt (more info ...)attempted-admin  2016-3645      URL
39432FILE-OTHER Symantec TNEF decoder integer overflow attempt (more info ...)attempted-admin  2016-3645      URL
39459SERVER-WEBAPP Oracle Web Cache HTTP header null byte injection attempt (more info ...)web-application-attack  2004-0385  9868    
39466FILE-EXECUTABLE Symantec Norton Security IDSvix86 out of bounds read attempt (more info ...)attempted-dos  2016-5308      URL
39467FILE-EXECUTABLE Symantec Norton Security IDSvix86 out of bounds read attempt (more info ...)attempted-dos  2016-5308      URL
39468SERVER-WEBAPP ACTi ASOC command injection attempt (more info ...)web-application-attack        URL
39469SERVER-WEBAPP ACTi ASOC command injection attempt (more info ...)web-application-attack        URL
39470SERVER-WEBAPP ACTi ASOC command injection attempt (more info ...)web-application-attack        URL
39471SERVER-WEBAPP ACTi ASOC command injection attempt (more info ...)web-application-attack        URL
39473SERVER-WEBAPP Shopware getTemplateName directory traversal attempt (more info ...)web-application-attack  2016-3109  97979    URL
39601FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39602FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39603FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39604FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39605FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39606FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39607FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2017-2870      URL
39608FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39609FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39610FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39611FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39612FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39613FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39614FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39615FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2017-2870      URL
39616FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39617FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39618FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39619FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39620FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39621FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39622FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39623FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39624FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39625FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39626FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39627FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39628FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39629FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39630FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39631FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39632FILE-IMAGE Multiple products TIFF tile size buffer overflow attempt (more info ...)attempted-user  2016-5875      URL
39634FILE-IMAGE Apple OSX EXR image invalid box2i attribute heap buffer overflow attempt (more info ...)attempted-user  2016-4629      URL
39635FILE-IMAGE Apple OSX EXR image invalid box2i attribute heap buffer overflow attempt (more info ...)attempted-user  2016-4629      URL
39637MALWARE-OTHER Win.Ransomware.Ranscam initial download attempt (more info ...)trojan-activity        URL
39638MALWARE-TOOLS Win.Packer.ConfuserEx packed .NET executable attempt (more info ...)trojan-activity        URL
39639SERVER-WEBAPP WebNMS Framework directory traversal attempt (more info ...)attempted-admin        URL
39640SERVER-WEBAPP WebNMS Framework directory traversal attempt (more info ...)attempted-admin        URL
39641SERVER-WEBAPP WebNMS Framework directory traversal attempt (more info ...)attempted-admin        URL
39645SERVER-WEBAPP Drupal Coder Module insecure remote file deserialization attempt (more info ...)web-application-attack        URL
39683FILE-IMAGE Apple Core Graphics BMP img_decode_read memory corruption attempt (more info ...)attempted-user  2016-4637      URL
39684FILE-IMAGE Apple Core Graphics BMP img_decode_read memory corruption attempt (more info ...)attempted-user  2016-4637      URL
39713MALWARE-OTHER MKVIS outbound communication attempt (more info ...)trojan-activity        
39725SERVER-WEBAPP Drupal RESTWS restws_page_callback command injection attempt (more info ...)attempted-admin        URL
39726SERVER-WEBAPP Drupal RESTWS restws_page_callback command injection attempt (more info ...)attempted-admin        URL
39734MALWARE-OTHER Win.Trojan.Xtrat outbound connection detected (more info ...)trojan-activity        URL
39744MALWARE-TOOLS CKnife penetration testing tool attempt (more info ...)trojan-activity        
39745MALWARE-OTHER Win.Trojan.FakeRean outbound connection detection (more info ...)trojan-activity        URL
39746MALWARE-OTHER Win.Ransomware.Apocalypse download attempt (more info ...)trojan-activity        URL
39747MALWARE-OTHER Win.Ransomware.Apocalypse download attempt (more info ...)trojan-activity        URL
39755MALWARE-OTHER Win.Trojan.Retefe variant malicious certificate installation page (more info ...)trojan-activity        URL
39756MALWARE-OTHER Win.Trojan.Retefe variant malicious certificate installation page (more info ...)trojan-activity        URL
39765SERVER-WEBAPP Ruby on Rails ActionPack inline content rendering code injection attempt (more info ...)web-application-attack  2016-2098      
39766MALWARE-OTHER Win.Downloader.Ogimant outbound connection detected (more info ...)trojan-activity        URL
39768MALWARE-OTHER Win.Ransomware.Alfa download attempt (more info ...)trojan-activity        URL
39769MALWARE-OTHER Win.Ransomware.Alfa download attempt (more info ...)trojan-activity        URL
39771MALWARE-TOOLS CKnife penetration testing tool attempt (more info ...)trojan-activity        
39772MALWARE-TOOLS CKnife penetration testing tool attempt (more info ...)trojan-activity        
39773MALWARE-TOOLS CKnife penetration testing tool attempt (more info ...)trojan-activity        
39803MALWARE-OTHER Win.Adware.Dlhelper outbound connection detected (more info ...)trojan-activity        URL
39804MALWARE-OTHER Win.Adware.Dlhelper outbound connection detected (more info ...)trojan-activity        URL
39805MALWARE-OTHER Win.Adware.Dlhelper outbound connection detected (more info ...)trojan-activity        URL
39806MALWARE-OTHER Win.Adware.Dlhelper outbound connection detected (more info ...)trojan-activity        URL
39807MALWARE-OTHER Win.Trojan.Lethic outbound connection detected (more info ...)trojan-activity        URL
39830MALWARE-OTHER Win.Trojan.CrypMIC outbound connection detected (more info ...)trojan-activity        URL
39845SERVER-WEBAPP Netgear ReadyNAS Surveillance debugging_center_utils command injection attempt (more info ...)web-application-attack  2016-5674      URL
39846SERVER-WEBAPP Netgear ReadyNAS Surveillance debugging_center_utils command injection attempt (more info ...)web-application-attack  2016-5674      URL
39847SERVER-WEBAPP Netgear ReadyNAS Surveillance handle_daylightsaving command injection attempt (more info ...)web-application-attack  2016-5675      URL
39848SERVER-WEBAPP Netgear ReadyNAS Surveillance handle_daylightsaving command injection attempt (more info ...)web-application-attack  2016-5675      URL
39851INDICATOR-COMPROMISE Connection to malware sinkhole - CERT.PL (more info ...)trojan-activity        URL
39876PROTOCOL-SNMP Allen-Bradley MicroLogix PLC SNMP request via undocumented community string attempt (more info ...)attempted-recon  2016-5645      URL
39883FILE-IMAGE FreeImage library XPM handling out of bounds write attempt (more info ...)attempted-user  2016-5684      URL
39884FILE-IMAGE FreeImage library XPM handling out of bounds write attempt (more info ...)attempted-user  2016-5684      URL
39904MALWARE-OTHER Rtf.Dropper.Agent-1404614 download attempt (more info ...)trojan-activity        URL
39906MALWARE-OTHER Rtf.Dropper.Agent-1404614 download attempt (more info ...)trojan-activity        URL
39910SERVER-OTHER Flexera FlexNet Publisher stack buffer overflow attempt (more info ...)attempted-admin  2015-8277      URL
39914BROWSER-PLUGINS KingView clsid access attempt (more info ...)attempted-user  2013-6128      
39915BROWSER-PLUGINS KingView clsid access attempt (more info ...)attempted-user  2013-6128      
39916BROWSER-PLUGINS KingView clsid access attempt (more info ...)attempted-user  2013-6128      
39917BROWSER-PLUGINS KingView clsid access attempt (more info ...)attempted-user  2013-6128      
39924SERVER-OTHER IBM Tivoli Storage Manager FastBack command injection attempt (more info ...)attempted-admin  2015-1949      URL
39930SERVER-WEBAPP Siemens IP-Camera credential disclosure attempt (more info ...)attempted-admin        URL
39974MALWARE-OTHER Andr.Trojan.KungFu variant download (more info ...)trojan-activity        URL
39975MALWARE-OTHER Andr.Trojan.KungFu variant download (more info ...)trojan-activity        URL
40017FILE-IDENTIFY Hierarchal Data Format file download request (more info ...)misc-activity        URL
40018FILE-IDENTIFY Hierarchal Data Format file attachment detected (more info ...)misc-activity        URL
40019FILE-IDENTIFY Hierarchal Data Format file attachment detected (more info ...)misc-activity        URL
40020FILE-IDENTIFY Hierarchal Data Format file magic detected (more info ...)misc-activity        URL
40021FILE-IDENTIFY Hierarchal Data Format file magic detected (more info ...)misc-activity        URL
40035FILE-IDENTIFY XLSB file magic detected (more info ...)misc-activity        
40036FILE-IDENTIFY XLSB file magic detected (more info ...)misc-activity        
40041SERVER-WEBAPP Meinberg LANTIME NTP appliance stack buffer overflow attempt (more info ...)web-application-attack  2016-3962      URL
40042SERVER-WEBAPP Meinberg LANTIME NTP appliance stack buffer overflow attempt (more info ...)web-application-attack  2016-3962      URL
40047SERVER-WEBAPP Belkin F9K1122 webpage buffer overflow attempt (more info ...)attempted-user        URL
40050MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40051MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40052MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40053MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40054MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40055MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40056MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40057MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40132BROWSER-IE VBScript ADODB.Connection object use after free attempt (more info ...)attempted-user  2017-11913      URL
40133BROWSER-IE VBScript ADODB.Connection object use after free attempt (more info ...)attempted-user  2017-11913      URL
40191MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40192MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40193MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40194MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40195MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40196MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40197MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40198MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40199MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40200MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40201MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40202MALWARE-OTHER Win.Trojan.Swabfex download attempt (more info ...)trojan-activity        URL
40233EXPLOIT-KIT Sundown exploit kit landing page detected (more info ...)attempted-user        URL
40241SERVER-OTHER Fortigate Firewall HTTP cookie buffer overflow (more info ...)attempted-admin  2016-6909      URL
40299FILE-OTHER TRUFFLEHUNTER TALOS-2016-0195 attack attempt (more info ...)attempted-user        URL
40300FILE-OTHER TRUFFLEHUNTER TALOS-2016-0195 attack attempt (more info ...)attempted-user        URL
40314FILE-IMAGE OpenJPEG JPEG2000 MCC record parsing heap memory corruption attempt (more info ...)attempted-user  2016-8332      URL
40315FILE-IMAGE OpenJPEG JPEG2000 MCC record parsing heap memory corruption attempt (more info ...)attempted-user  2016-8332      URL
40336FILE-PDF Iceni Argus ipfSetColourStroke stack buffer overflow attempt (more info ...)attempted-user  2016-8333      URL
40337FILE-PDF Iceni Argus ipfSetColourStroke stack buffer overflow attempt (more info ...)attempted-user  2016-8333      URL
40358SERVER-OTHER IBM Tivoli Storage Manager FastBack opcode 1301 remote code execution attempt (more info ...)attempted-admin  2015-1986      URL
40360SERVER-OTHER OpenSSL OCSP Status Request Extension denial of service attempt (more info ...)attempted-dos  2016-6304      URL
40382SERVER-OTHER Easy File Sharing Server remote code execution attempt (more info ...)attempted-user        URL
40387FILE-IDENTIFY Windows registry hive file magic detected (more info ...)misc-activity        
40388FILE-IDENTIFY Windows registry hive file attachment detected (more info ...)misc-activity        
40389FILE-IDENTIFY Windows registry hive file attachment detected (more info ...)misc-activity        
40390FILE-IDENTIFY Windows registry hive file magic detected (more info ...)misc-activity        
40391FILE-IDENTIFY Windows registry hive file download request (more info ...)misc-activity        
40422SERVER-OTHER IBM Tivoli Storage Manager FastBack opcode 4115 remote code execution attempt (more info ...)attempted-admin  2015-4931      URL
40429FILE-PDF Foxit PDF Reader JBIG2 parser out of bounds read attempt (more info ...)attempted-recon  2016-8334      URL
40430FILE-PDF Foxit PDF Reader JBIG2 parser out of bounds read attempt (more info ...)attempted-recon  2016-8334      URL
40446SERVER-WEBAPP Avtech IP Camera unauthenticated config access attempt (more info ...)attempted-admin        URL
40451SERVER-WEBAPP Symantec Messaging Gateway KavaChart Component directory traversal attempt (more info ...)web-application-attack  2016-5312      
40468SERVER-OTHER Memcached append opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8704      URL
40469SERVER-OTHER Memcached append opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8704      URL
40470SERVER-OTHER Memcached prepend opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8704      URL
40471SERVER-OTHER Memcached prepend opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8704      URL
40472SERVER-OTHER Memcached appendq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8704      URL
40473SERVER-OTHER Memcached appendq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8704      URL
40474SERVER-OTHER Memcached prependq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8704      URL
40475SERVER-OTHER Memcached prependq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8704      URL
40476SERVER-OTHER Memcached set opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
40477SERVER-OTHER Memcached setq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
40478SERVER-OTHER Memcached add opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
40479SERVER-OTHER Memcached addq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
40480SERVER-OTHER Memcached replace opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
40481SERVER-OTHER Memcached replaceq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
40482SERVER-OTHER Memcached SASL auth opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8706      URL
40483SERVER-OTHER Memcached SASL auth opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8706      URL
40488FILE-EXECUTABLE Hopper Disassembler ELF section header memory corruption attempt (more info ...)attempted-user  2016-8390      URL
40489FILE-EXECUTABLE Hopper Disassembler ELF section header memory corruption attempt (more info ...)attempted-user  2016-8390      URL
40493SERVER-WEBAPP Ektron ServerControlWS.asmx XSL transform code injection attempt (more info ...)web-application-attack  2015-0931      URL
40524SERVER-WEBAPP Trend Micro SafeSync JSON API ad_sync_now command injection attempt (more info ...)web-application-attack    92919    URL
40750SERVER-WEBAPP D-Link DIR Series Routers HNAP stack buffer overflow attempt (more info ...)attempted-admin  2016-6563  94130    
40753EXPLOIT-KIT Rig exploit kit outbound communication (more info ...)trojan-activity        
40756FILE-PDF Nitro Pro PDF Font Widths tag out of bounds read attempt (more info ...)attempted-user  2016-8711      URL
40757FILE-PDF Nitro Pro PDF Font Widths tag out of bounds read attempt (more info ...)attempted-user  2016-8711      URL
40758SERVER-OTHER Moxa AWK-3131A backdoor root account access attempt (more info ...)attempted-admin  2016-8717      URL
40766SERVER-OTHER IBM Tivoli Storage Manager FastBack directory traversal attempt (more info ...)attempted-admin  2015-1941      URL
40772PUA-ADWARE Win.Trojan.Miuref variant outbound connection (more info ...)misc-activity        URL
40776FILE-PDF Nitro Pro out of bounds memory write attempt (more info ...)attempted-user  2016-8709      URL
40777FILE-PDF Nitro Pro out of bounds memory write attempt (more info ...)attempted-user  2016-8709      URL
40778FILE-PDF Acrobat Reader Open Cascade Library memory corruption attempt (more info ...)attempted-user  2016-6940      URL
40779FILE-PDF Acrobat Reader Open Cascade Library memory corruption attempt (more info ...)attempted-user  2016-6940      URL
40784SERVER-WEBAPP ZyXEL TR-064 SetNTPServers command injection attempt (more info ...)attempted-admin        URL
40785SERVER-WEBAPP Sophos Web Security Appliance command injection attempt (more info ...)web-application-attack        URL
40786SERVER-WEBAPP Sophos Web Security Appliance command injection attempt (more info ...)web-application-attack        URL
40791FILE-OTHER HDF5 msg_dtype H5T_ARRAY heap buffer overflow attempt (more info ...)attempted-user  2016-4330      URL
40792FILE-OTHER HDF5 msg_dtype H5T_ARRAY heap buffer overflow attempt (more info ...)attempted-user  2016-4330      URL
40793FILE-OTHER HDF5 msg_dtype H5T_ARRAY heap buffer overflow attempt (more info ...)attempted-user  2016-4330      URL
40794FILE-OTHER HDF5 msg_dtype H5T_ARRAY heap buffer overflow attempt (more info ...)attempted-user  2016-4330      URL
40801FILE-OTHER HDF5 H5Z_NBIT filter heap buffer overflow attempt (more info ...)attempted-user  2016-4331      URL
40802FILE-OTHER HDF5 H5Z_NBIT filter heap buffer overflow attempt (more info ...)attempted-user  2016-4331      URL
40803FILE-OTHER HDF5 H5O_dtype_decode_helper heap buffer overflow attempt (more info ...)attempted-user  2016-4333      URL
40804FILE-OTHER HDF5 H5O_dtype_decode_helper heap buffer overflow attempt (more info ...)attempted-user  2016-4333      URL
40805FILE-OTHER HDF5 object modification time out of bounds write attempt (more info ...)attempted-user  2016-4332      URL
40806FILE-OTHER HDF5 object modification time out of bounds write attempt (more info ...)attempted-user  2016-4332      URL
40807FILE-OTHER HDF5 symbol table message out of bounds write attempt (more info ...)attempted-user  2016-4332      URL
40808FILE-OTHER HDF5 symbol table message out of bounds write attempt (more info ...)attempted-user  2016-4332      URL
40809FILE-OTHER HDF5 new object modification time out of bounds write attempt (more info ...)attempted-user  2016-4332      URL
40810FILE-OTHER HDF5 new object modification time out of bounds write attempt (more info ...)attempted-user  2016-4332      URL
40829INDICATOR-COMPROMISE potential Squiblydoo application whitelisting bypass attempt (more info ...)attempted-user        URL
40830INDICATOR-COMPROMISE potential Squiblydoo application whitelisting bypass attempt (more info ...)attempted-user        URL
40843SERVER-OTHER OpenSSL SSLv3 warning denial of service attempt (more info ...)attempted-dos  2016-8610      
40855SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40856SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40857SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40858SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40859SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40860SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40861SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40862SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40863SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40864SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40865SERVER-WEBAPP Bassmaster Batch remote code execution attempt (more info ...)attempted-admin  2014-7205      
40866PROTOCOL-OTHER TP-Link TDDP SET_CONFIG type buffer overflow attempt (more info ...)attempted-user        URL
40871MALWARE-OTHER Virut CnC command reply (more info ...)trojan-activity        URL
40880SERVER-WEBAPP Multiple products invalid HTTP request attempt (more info ...)attempted-dos  2016-8723      URL
40889SERVER-WEBAPP Barracuda WAF UPDATE_scan_information_in_use command injection attempt (more info ...)web-application-attack  2017-6320      URL
40897SERVER-OTHER ntpd mrulist control message command null pointer dereference attempt (more info ...)attempted-dos  2016-7434  94448    URL
40898OS-OTHER Joyent SmartOS ioctl integer underflow attempt (more info ...)attempted-admin  2016-9031      URL
40899OS-OTHER Joyent SmartOS ioctl integer underflow attempt (more info ...)attempted-admin  2016-9031      URL
40900OS-OTHER Joyent SmartOS file system name buffer overflow attempt (more info ...)attempted-admin  2016-9034      URL
40901OS-OTHER Joyent SmartOS file system name buffer overflow attempt (more info ...)attempted-admin  2016-9034      URL
40902OS-OTHER Joyent SmartOS file system path buffer overflow attempt (more info ...)attempted-admin  2016-9035      URL
40903OS-OTHER Joyent SmartOS file system path buffer overflow attempt (more info ...)attempted-admin  2016-9035      URL
40905SERVER-WEBAPP Oracle Weblogic default credentials login attempt (more info ...)attempted-admin        URL
40907PROTOCOL-OTHER TP-Link TDDP Get_config configuration leak attempt (more info ...)attempted-recon        URL
40912MALWARE-OTHER Win.Trojan.Flokibot variant download attempt (more info ...)trojan-activity        URL
40913MALWARE-OTHER Win.Trojan.Flokibot variant download attempt (more info ...)trojan-activity        URL
40914FILE-IMAGE ImageMagick LibTIFF invalid SamplesPerPixel buffer overflow attempt (more info ...)attempted-user  2016-8707      URL
40915FILE-IMAGE ImageMagick LibTIFF invalid SamplesPerPixel buffer overflow attempt (more info ...)attempted-user  2016-8707      URL
40919FILE-PDF Iceni ArgusPDF convertor malformed embedded TTF file cmap table memory corruption attempt (more info ...)attempted-user  2016-8386      URL
40920FILE-PDF Iceni ArgusPDF convertor malformed embedded TTF file cmap table memory corruption attempt (more info ...)attempted-user  2016-8386      URL
40923FILE-PDF Iceni Argus PDF font-encoding glyphmap adjustment code execution vulnerability attempt (more info ...)attempted-user  2016-8388      URL
40924FILE-PDF Iceni Argus PDF font-encoding glyphmap adjustment code execution vulnerability attempt (more info ...)attempted-user  2016-8388      URL
40925FILE-PDF Iceni Argus PDF TextToPolys rasterization code execution vulnerability attempt (more info ...)attempted-user  2016-8389      URL
40926FILE-PDF Iceni Argus PDF TextToPolys rasterization code execution vulnerability attempt (more info ...)attempted-user  2016-8389      URL
40934FILE-EXECUTABLE Nvidia Windows kernel mode driver denial of service attempt (more info ...)attempted-user  2016-8823      URL
40935FILE-EXECUTABLE Nvidia Windows kernel mode driver denial of service attempt (more info ...)attempted-user  2016-8823      URL
40979FILE-IDENTIFY ico file download request (more info ...)misc-activity        
40980FILE-IDENTIFY ico file attachment detected (more info ...)misc-activity        
40981FILE-IDENTIFY ico file attachment detected (more info ...)misc-activity        
40995SERVER-OTHER Alcatel Lucent OmniVista arbitrary command execution attempt (more info ...)attempted-admin  2016-9796  94649    
41026SERVER-WEBAPP Advantech WebAccess Dashboard remote code execution attempt (more info ...)attempted-admin  2016-0854  80745    URL
41030SERVER-WEBAPP Nagios Core Configuration Manager command injection attempt (more info ...)web-application-attack  2013-6875      
41035EXPLOIT-KIT Sundown Exploit Kit redirection attempt (more info ...)trojan-activity        
41036SERVER-WEBAPP Trend Micro InterScan WSA ManagePatches servlet command injection attempt (more info ...)web-application-attack        URL
41037SERVER-WEBAPP Trend Micro InterScan WSA domains command injection attempt (more info ...)web-application-attack        URL
41038SERVER-WEBAPP Trend Micro InterScan WSA testConfiguration command injection attempt (more info ...)web-application-attack        URL
41039SERVER-WEBAPP Trend Micro InterScan WSA wmi_domain_controllers command injection attempt (more info ...)web-application-attack        URL
41080SERVER-OTHER Tarantool xrow_header_decode out of bounds read attempt (more info ...)attempted-dos  2016-9037      URL
41081SERVER-OTHER Tarantool initial connection banner detected (more info ...)protocol-command-decode        URL
41082SERVER-OTHER Tarantool Msgpuck mp_check denial of service vulnerability attempt (more info ...)attempted-dos  2016-9036      URL
41084EXPLOIT-KIT Sundown Exploit kit landing page obfuscation detected (more info ...)attempted-user        URL
41085SERVER-WEBAPP Moxa AWK-3131A webSetPingTrace command injection attempt (more info ...)web-application-attack  2016-8721      URL
41092EXPLOIT-KIT Rig Exploit Kit landing page obfuscation detected (more info ...)attempted-user        URL
41095SERVER-WEBAPP Netgear WNR2000 authentication bypass attempt (more info ...)attempted-admin  2016-10176      URL
41096SERVER-WEBAPP Netgear WNR2000 hidden_lang_avi stack buffer overflow attempt (more info ...)attempted-admin  2016-10174      URL
41102SERVER-WEBAPP Moxa AWK-3131A web application cross site scripting attempt (more info ...)attempted-user  2016-8719      URL
41103SERVER-WEBAPP Moxa AWK-3131A web application cross site scripting attempt (more info ...)attempted-user  2016-8719      URL
41104SERVER-WEBAPP Moxa AWK-3131A web application cross site scripting attempt (more info ...)attempted-user  2016-8719      URL
41105SERVER-WEBAPP Moxa AWK-3131A web application cross site scripting attempt (more info ...)attempted-user  2016-8719      URL
41120FILE-IMAGE ImageMagick PostScript decode delegate command injection attempt (more info ...)attempted-user        URL
41121FILE-IMAGE ImageMagick PostScript decode delegate command injection attempt (more info ...)attempted-user        URL
41196FILE-PDF Nitro Pro PDF Reader out of bounds write attempt (more info ...)attempted-user  2016-8713      URL
41197FILE-PDF Nitro Pro PDF Reader out of bounds write attempt (more info ...)attempted-user  2016-8713      URL
41212SERVER-OTHER Aerospike Database Server digest_ripe message field out of bounds read attempt (more info ...)attempted-user  2016-9050      URL
41213SERVER-OTHER Aerospike Database Server client batch request exploit attempt (more info ...)attempted-admin  2016-9051      URL
41216SERVER-OTHER Aerospike Database Server si_prop stack buffer overflow attempt (more info ...)attempted-user  2016-9054      URL
41217OS-OTHER Joyent SmartOS add entries denial of service attempt (more info ...)attempted-dos  2016-9040      URL
41218OS-OTHER Joyent SmartOS add entries denial of service attempt (more info ...)attempted-dos  2016-9040      URL
41224FILE-PDF Artifex MuPDF JBIG2 negative width value out of bounds read attempt (more info ...)attempted-user  2016-8729      URL
41225FILE-PDF Artifex MuPDF JBIG2 negative width value out of bounds read attempt (more info ...)attempted-user  2016-8729      URL
41306FILE-EXECUTABLE Invincea-X SboxDrv.sys local privilege escalation attempt (more info ...)attempted-admin  2016-9038      URL
41307FILE-EXECUTABLE Invincea-X SboxDrv.sys local privilege escalation attempt (more info ...)attempted-admin  2016-9038      URL
41310FILE-IMAGE libBPG restore_tqb_pixel out of bounds write attempt (more info ...)attempted-user  2016-8710      URL
41311FILE-IMAGE libBPG restore_tqb_pixel out of bounds write attempt (more info ...)attempted-user  2016-8710      URL
41312FILE-EXECUTABLE Invincea Dell Protected Workspace InvProtectDrv sandbox escape attempt (more info ...)attempted-user  2016-8732      URL
41313FILE-EXECUTABLE Invincea Dell Protected Workspace InvProtectDrv sandbox escape attempt (more info ...)attempted-user  2016-8732      URL
41314EXPLOIT-KIT Rig exploit kit landing page detected (more info ...)trojan-activity        
41327FILE-PDF Iceni Argus ipStringCreate integer overflow attempt (more info ...)attempted-user  2017-2777      URL
41328FILE-PDF Iceni Argus ipStringCreate integer overflow attempt (more info ...)attempted-user  2017-2777      URL
41344FILE-OTHER CorelDRAW X8 EMF invalid ihBrush field value out of bounds read attempt (more info ...)attempted-user  2016-9043      URL
41345FILE-OTHER CorelDRAW X8 EMF invalid ihBrush field value out of bounds read attempt (more info ...)attempted-user  2016-9043      URL
41346SERVER-WEBAPP Western Digital MyCloud command injection attempt (more info ...)web-application-attack  2016-10108      
41347SERVER-WEBAPP Western Digital MyCloud command injection attempt (more info ...)web-application-attack  2016-10108      
41348SERVER-WEBAPP Western Digital MyCloud command injection attempt (more info ...)web-application-attack  2016-10108      
41349SERVER-WEBAPP Western Digital MyCloud command injection attempt (more info ...)web-application-attack  2016-10108      
41350FILE-OTHER Apple Garageband .band file out of bounds write attempt (more info ...)attempted-user  2017-2372      URL
41351FILE-OTHER Apple Garageband .band file out of bounds write attempt (more info ...)attempted-user  2017-2372      URL
41360FILE-PDF TRUFFLEHUNTER TALOS-2017-0270 attack attempt (more info ...)attempted-user        URL
41361FILE-PDF TRUFFLEHUNTER TALOS-2017-0270 attack attempt (more info ...)attempted-user        URL
41362FILE-PDF TRUFFLEHUNTER TALOS-2017-0270 attack attempt (more info ...)attempted-user        URL
41363FILE-PDF TRUFFLEHUNTER TALOS-2017-0270 attack attempt (more info ...)attempted-user        URL
41364PROTOCOL-OTHER ARM mbed TLS x509 invalid public key remote code execution attempt (more info ...)attempted-user        URL
41367SERVER-OTHER NTPD zero origin timestamp denial of service attempt (more info ...)attempted-dos  2016-9042      URL
41370FILE-OTHER National Instruments LabVIEW LvVarientUnflatten remote code execution attempt (more info ...)attempted-user  2017-2775      URL
41371FILE-OTHER National Instruments LabVIEW LvVarientUnflatten remote code execution attempt (more info ...)attempted-user  2017-2775      URL
41372FILE-IMAGE Oracle Outside In libvs_gif out of bounds write attempt (more info ...)attempted-admin        URL
41373FILE-IMAGE Oracle Outside In libvs_gif out of bounds write attempt (more info ...)attempted-admin        URL
41387SERVER-WEBAPP ZyXEL P660HN ADSL Router logset.asp command injection attempt (more info ...)web-application-attack        URL
41388SERVER-WEBAPP ZyXEL P660HN ADSL Router viewlog.asp command injection attempt (more info ...)web-application-attack        URL
41401SERVER-WEBAPP Billion 5200W ADSL Router adv_remotelog.asp command injection attempt (more info ...)web-application-attack        URL
41402SERVER-WEBAPP Billion 5200W ADSL Router tools_time.asp command injection attempt (more info ...)web-application-attack        URL
41447FILE-OTHER Apple GarageBand out of bounds write attempt (more info ...)attempted-user  2017-2374      URL
41448FILE-OTHER Apple GarageBand out of bounds write attempt (more info ...)attempted-user  2017-2374      URL
41466SERVER-OTHER TRUFFLEHUNTER TALOS-2016-0278 attack attempt (more info ...)attempted-recon  2017-2782      URL
41470FILE-PDF MuPDF Fitz library font glyph scaling code execution vulnerability attempt (more info ...)attempted-user  2016-8728      URL
41471FILE-PDF MuPDF Fitz library font glyph scaling code execution vulnerability attempt (more info ...)attempted-user  2016-8728      URL
41489SERVER-WEBAPP Sophos Web Security Appliance command injection attempt (more info ...)web-application-attack  2016-9553  95853    URL
41490SERVER-WEBAPP Sophos Web Security Appliance command injection attempt (more info ...)web-application-attack  2016-9553  95853    URL
41505SERVER-OTHER Pharos PopUp Printer Client DecodeString heap overflow attempt (more info ...)attempted-admin  2017-2785      URL
41506SERVER-OTHER Pharos PopUp Printer Client DecodeString heap overflow attempt (more info ...)attempted-admin  2017-2785      URL
41508SERVER-OTHER Pharos PopUp Printer Client Memcpy heap overflow attempt (more info ...)attempted-admin  2017-2787      URL
41509SERVER-OTHER Pharos PopUp Printer Client DecodeBinary heap buffer overflow attempt (more info ...)attempted-admin  2017-2788      URL
41510SERVER-OTHER Pharos PopUp Printer Client DecodeBinary heap buffer overflow attempt (more info ...)attempted-admin  2017-2788      URL
41520SERVER-OTHER Ge Fanuc Proficy WebView DOS attempt (more info ...)attempted-dos        URL
41535SERVER-WEBAPP Broadwin WebAccess DOS attempt (more info ...)attempted-dos  2012-0241      
41547SERVER-OTHER TLS client hello session resumption detected (more info ...)protocol-command-decode        URL
41548SERVER-OTHER F5 BIG-IP TLS session ticket implementation uninitialized memory disclosure attempt (more info ...)attempted-recon  2016-9244      URL
41597FILE-OTHER Windows Uniscribe remote code execution vulnerability attempt (more info ...)attempted-user  2017-0014      URL
41598FILE-OTHER Windows Uniscribe remote code execution vulnerability attempt (more info ...)attempted-user  2017-0014      URL
41642SERVER-WEBAPP TP-LINK AC750 ping diagnostic command injection attempt (more info ...)web-application-attack        URL
41646PROTOCOL-SCADA BB-Elec ethernet gateway DOS attempt (more info ...)attempted-dos        URL
41658MALWARE-OTHER Win.Trojan.MagicHound dropper document file detected (more info ...)trojan-activity        URL
41659MALWARE-OTHER Win.Trojan.MagicHound dropper document file detected (more info ...)trojan-activity        URL
41677SERVER-WEBAPP Trend Micro InterScan Web Security Appliance insecure configuration export attempt (more info ...)attempted-recon  2016-9314      URL
41678SERVER-WEBAPP Trend Micro InterScan Web Security Appliance insecure configuration import attempt (more info ...)attempted-admin  2016-9314      URL
41732SERVER-WEBAPP Trend Micro InterScan Messaging Security Appliance command injection attempt (more info ...)web-application-attack        URL
41733SERVER-WEBAPP Trend Micro InterScan Messaging Security Appliance command injection attempt (more info ...)web-application-attack        URL
41734SERVER-WEBAPP Trend Micro InterScan Messaging Security Appliance command injection attempt (more info ...)web-application-attack        URL
41735SERVER-WEBAPP Trend Micro InterScan Messaging Security Appliance command injection attempt (more info ...)web-application-attack        URL
41743PROTOCOL-SCADA TwinCAT PLC DOS attempt (more info ...)attempted-dos        URL
41752PROTOCOL-SCADA PowerNet Twin Client DOS attempt (more info ...)attempted-dos        URL
41771MALWARE-TOOLS slowhttptest DoS tool (more info ...)attempted-dos        URL
41778PROTOCOL-SCADA Yokogawa CS3000 BKFSim_vhfd buffer overflow attempt (more info ...)attempted-admin  2014-3888      
41781SERVER-WEBAPP carel plantvisorpro3 directory traversal attempt (more info ...)web-application-attack        URL
41782SERVER-WEBAPP carel plantvisorpro3 directory traversal attempt (more info ...)web-application-attack        URL
41783EXPLOIT-KIT Rig exploit kit URL outbound communication (more info ...)trojan-activity        
41790SERVER-WEBAPP Brocade Network Advisor CliMonitorReportServlet directory traversal attempt (more info ...)web-application-attack  2016-8207  95691    URL
41808FILE-IMAGE ImageMagick mvg processing command server side request forgery attempt (more info ...)attempted-user  2016-3718      URL
41809FILE-IMAGE ImageMagick mvg processing command server side request forgery attempt (more info ...)attempted-user  2016-3718      URL
41814SERVER-WEBAPP NetGain Enterprise Manager arbitrary command execution attempt (more info ...)attempted-admin        URL
41815SERVER-WEBAPP NetGain Enterprise Manager arbitrary command execution attempt (more info ...)attempted-admin        URL
41917SERVER-WEBAPP Carel PlantVisorPRO default login attempt (more info ...)web-application-attack        URL
41970FILE-IMAGE GDI+ malformed EMF comment heap access violation attempt (more info ...)attempted-user  2017-0060      URL
41971FILE-IMAGE GDI+ malformed EMF comment heap access violation attempt (more info ...)attempted-user  2017-0060      URL
41999OS-OTHER Apple OSX and iOS x509 certificate name constraints parsing use after free attempt (more info ...)attempted-admin  2017-2485      URL
42005SERVER-WEBAPP Logsign JSON API validate_file command injection attempt (more info ...)attempted-admin        URL
42014BROWSER-OTHER TRUFFLEHUNTER SFVRT-1024 attack attempt (more info ...)attempted-recon        
42018EXPLOIT-KIT Exploit Kit EITest Gate redirection attempt detected (more info ...)trojan-activity        
42074PROTOCOL-SCADA TraceMode Runtime DOS attempt (more info ...)attempted-dos        URL
42075PROTOCOL-SCADA TraceMode Runtime DOS attempt (more info ...)attempted-dos        URL
42088FILE-IMAGE Corel Photo Paint invalid ImageLength memory corruption attempt (more info ...)attempted-user  2017-2804      URL
42089FILE-IMAGE Corel Photo Paint invalid ImageLength memory corruption attempt (more info ...)attempted-user  2017-2804      URL
42090FILE-IMAGE Corel Photo Paint invalid ImageLength memory corruption attempt (more info ...)attempted-user  2017-2804      URL
42091FILE-IMAGE Corel Photo Paint invalid ImageLength memory corruption attempt (more info ...)attempted-user  2017-2804      URL
42102SERVER-WEBAPP Trend Micro SafeSync command injection attempt (more info ...)web-application-attack        URL
42103SERVER-WEBAPP Trend Micro SafeSync command injection attempt (more info ...)web-application-attack        URL
42104SERVER-WEBAPP Trend Micro SafeSync command injection attempt (more info ...)web-application-attack        URL
42107SERVER-WEBAPP EyesOfNetwork module command injection attempt (more info ...)web-application-attack  2017-6087      URL
42108SERVER-WEBAPP EyesOfNetwork module command injection attempt (more info ...)web-application-attack  2017-6087      URL
42111INDICATOR-OBFUSCATION Base64 encoded String.fromCharCode (more info ...)misc-activity        URL
42112BROWSER-OTHER multiple browsers content security policy bypass attempt (more info ...)policy-violation  2017-5033      
42131SERVER-WEBAPP Cambium Networks ePMP 1000 command injection attempt (more info ...)web-application-attack        URL
42132SERVER-WEBAPP Cambium Networks ePMP 1000 command injection attempt (more info ...)web-application-attack        URL
42140FILE-IMAGE Corel PHOTO-PAINT X8 GIF Filter Code Execution Vulnerability attempt (more info ...)attempted-user  2016-8730      URL
42141FILE-IMAGE Corel PHOTO-PAINT X8 GIF Filter Code Execution Vulnerability attempt (more info ...)attempted-user  2016-8730      URL
42142FILE-OTHER TRUFFLEHUNTER TALOS-2017-0303 attack attempt (more info ...)attempted-user  2017-2807      URL
42143FILE-OTHER TRUFFLEHUNTER TALOS-2017-0303 attack attempt (more info ...)attempted-user  2017-2807      URL
42146FILE-OTHER TRUFFLEHUNTER TALOS-2017-0304 attack attempt (more info ...)attempted-user  2017-2808      URL
42147FILE-OTHER TRUFFLEHUNTER TALOS-2017-0304 attack attempt (more info ...)attempted-user  2017-2808      URL
42177FILE-OTHER IrfanView JPEG2000 reference tile width value buffer overflow attempt (more info ...)attempted-user  2017-2813      URL
42178FILE-OTHER IrfanView JPEG2000 reference tile width value buffer overflow attempt (more info ...)attempted-user  2017-2813      URL
42179FILE-IMAGE TRUFFLEHUNTER TALOS-2017-2811 attack attempt (more info ...)attempted-user  2017-2811      URL
42180FILE-IMAGE TRUFFLEHUNTER TALOS-2017-2811 attack attempt (more info ...)attempted-user  2017-2811      URL
42191FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0309 attack attempt (more info ...)attempted-user  2017-2812      URL
42192FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0309 attack attempt (more info ...)attempted-user  2017-2812      URL
42193FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0309 attack attempt (more info ...)attempted-user  2017-2812      URL
42194FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0309 attack attempt (more info ...)attempted-user  2017-2812      URL
42195FILE-OTHER Tablib yaml.load code execution attempt (more info ...)attempted-user  2017-2810      URL
42196FILE-OTHER Tablib yaml.load code execution attempt (more info ...)attempted-user  2017-2810      URL
42220SERVER-WEBAPP BlueCoat CAS report-email command injection attempt (more info ...)web-application-attack  2016-9091      URL
42221SERVER-WEBAPP Moxa private key disclosure attempt (more info ...)web-application-attack  2017-7455      
42222SERVER-WEBAPP Moxa MX Studio login page denial of service attempt (more info ...)attempted-dos  2017-7456      
42232SERVER-OTHER TopSec Firewall cookie header command injection attempt (more info ...)attempted-user        URL
42235SERVER-OTHER NTP malformed config request denial of service attempt (more info ...)denial-of-service  2017-6464      URL
42244SERVER-WEBAPP Information Builders WebFOCUS Business Intelligence Portal command injection attempt (more info ...)web-application-attack  2017-9044      URL
42245SERVER-WEBAPP Information Builders WebFOCUS Business Intelligence Portal command injection attempt (more info ...)web-application-attack  2017-9044      URL
42246SERVER-WEBAPP Information Builders WebFOCUS Business Intelligence Portal command injection attempt (more info ...)web-application-attack  2017-9044      URL
42247SERVER-WEBAPP Information Builders WebFOCUS Business Intelligence Portal command injection attempt (more info ...)web-application-attack  2017-9044      URL
42257FILE-IDENTIFY ISO file magic detected (more info ...)misc-activity        URL
42258FILE-IDENTIFY ISO file attachment detected (more info ...)misc-activity        URL
42259FILE-IDENTIFY ISO file attachment detected (more info ...)misc-activity        URL
42260FILE-IDENTIFY ISO file attachment detected (more info ...)misc-activity        URL
42261FILE-IDENTIFY ISO file magic detected (more info ...)misc-activity        URL
42262FILE-IDENTIFY ISO file download request (more info ...)misc-activity        URL
42273FILE-PDF Poppler DCTStream readScan heap buffer overflow attempt (more info ...)attempted-user  2017-2814      URL
42274FILE-PDF Poppler DCTStream readScan heap buffer overflow attempt (more info ...)attempted-user  2017-2814      URL
42285FILE-PDF Multiple Products malformed JP2K codestream out of bounds read attempt (more info ...)attempted-user  2017-8737      URL
42286FILE-PDF Multiple Products malformed JP2K codestream out of bounds read attempt (more info ...)attempted-user  2017-8737      URL
42290SERVER-WEBAPP Openfire userimportexport plugin XML external entity injection attempt (more info ...)web-application-attack  2017-2815      URL
42291SERVER-WEBAPP AlienVault OSSIM API get_host_fqdn host_ip command injection attempt (more info ...)web-application-attack        URL
42311FILE-PDF Multiple Products malformed JP2K codestream out of bounds read attempt (more info ...)attempted-user  2018-8464      URL
42312FILE-PDF Multiple Products malformed JP2K codestream out of bounds read attempt (more info ...)attempted-user  2018-8464      URL
42313FILE-PDF TRUFFLEHUNTER TALOS-2017-0322 attack attempt (more info ...)attempted-user  2017-2821      URL
42314FILE-PDF TRUFFLEHUNTER TALOS-2017-0322 attack attempt (more info ...)attempted-user  2017-2821      URL
42321FILE-OTHER Power Software PowerISO invalid primary volume descriptor header use after free attempt (more info ...)attempted-user  2017-2823      URL
42322FILE-OTHER Power Software PowerISO invalid primary volume descriptor header use after free attempt (more info ...)attempted-user  2017-2823      URL
42326SERVER-OTHER Zabbix Server Trapper code execution attempt (more info ...)attempted-admin  2017-2825      URL
42337INDICATOR-COMPROMISE Zabbix Proxy configuration containing script detected (more info ...)attempted-user  2017-2825      URL
42345SERVER-WEBAPP Tenable Appliance simpleupload.py command injection attempt (more info ...)web-application-attack  2017-8051      URL
42346SERVER-WEBAPP Tenable Appliance simpleupload.py command injection attempt (more info ...)web-application-attack  2017-8051      URL
42347SERVER-WEBAPP Tenable Appliance simpleupload.py command injection attempt (more info ...)web-application-attack  2017-8051      URL
42355SERVER-OTHER 389-ds-base bind code execution attempt (more info ...)attempted-admin  2017-2668      
42356SERVER-OTHER 389-ds-base bind code execution attempt (more info ...)attempted-admin  2017-2668      
42357SERVER-OTHER 389-ds-base bind code execution attempt (more info ...)attempted-admin  2017-2668      
42358SERVER-OTHER 389-ds-base bind code execution attempt (more info ...)attempted-admin  2017-2668      
42359SERVER-OTHER 389-ds-base bind code execution attempt (more info ...)attempted-admin  2017-2668      
42360SERVER-OTHER 389-ds-base bind code execution attempt (more info ...)attempted-admin  2017-2668      
42361SERVER-OTHER 389-ds-base bind code execution attempt (more info ...)attempted-admin  2017-2668      
42362SERVER-OTHER 389-ds-base bind code execution attempt (more info ...)attempted-admin  2017-2668      
42372POLICY-OTHER eicar file detected (more info ...)misc-activity        URL
42373POLICY-OTHER eicar file detected (more info ...)misc-activity        URL
42374POLICY-OTHER eicar file detected (more info ...)misc-activity        URL
42375POLICY-OTHER eicar file detected (more info ...)misc-activity        URL
42376POLICY-OTHER eicar file detected (more info ...)misc-activity        URL
42392SERVER-WEBAPP Yealink VoIP phone directory traversal attempt (more info ...)web-application-attack  2013-5756  68053    
42393SERVER-WEBAPP Yealink VoIP phone directory traversal attempt (more info ...)web-application-attack  2013-5756  68053    
42394SERVER-WEBAPP Yealink VoIP phone directory traversal attempt (more info ...)web-application-attack  2013-5756  68053    
42396EXPLOIT-KIT Blacole inbound malformed pdf download attempt (more info ...)trojan-activity        URL
42397EXPLOIT-KIT Blacole inbound malformed pdf download attempt (more info ...)trojan-activity        URL
42406SERVER-WEBAPP WePresent WiPG admin backdoor login attempt (more info ...)attempted-admin        URL
42410SERVER-WEBAPP WePresent WiPG rdtool backdoor login attempt (more info ...)attempted-admin        URL
42411SERVER-WEBAPP WePresent WiPG session id check bypass attempt (more info ...)attempted-admin        URL
42432SERVER-WEBAPP Foscam IP Camera command injection attempt (more info ...)web-application-attack  2017-2873      URL
42433SERVER-WEBAPP Foscam IP Camera command injection attempt (more info ...)web-application-attack  2017-2873      URL
42434SERVER-WEBAPP Foscam IP Camera command injection attempt (more info ...)web-application-attack  2017-2873      URL
42435SERVER-WEBAPP Foscam IP Camera callbackJson directory traversal attempt (more info ...)web-application-attack  2017-2829      URL
42436SERVER-WEBAPP Foscam IP Camera callbackJson directory traversal attempt (more info ...)web-application-attack  2017-2829      URL
42437SERVER-WEBAPP Foscam IP Camera multipart boundary stack buffer overflow attempt (more info ...)web-application-attack  2017-2830      URL
42467SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      
42468SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      
42469SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      
42470SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      
42471SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42472SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42473SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42474SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42475FILE-PDF malformed embedded JPEG2000 image information disclosure attempt (more info ...)misc-activity  2017-3029      URL
42476FILE-PDF malformed embedded JPEG2000 image information disclosure attempt (more info ...)misc-activity  2017-3029      URL
42477SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42478SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42479SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42480SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42481SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      
42482SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      
42483SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      
42484SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      
42485SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42486SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42487SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42488SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42806EXPLOIT-KIT Rig Exploit Kit URL outbound communication (more info ...)attempted-user        
42822MALWARE-OTHER Win.Downloader.Carp variant download attempt (more info ...)trojan-activity        URL
42823MALWARE-OTHER Win.Downloader.Carp variant download attempt (more info ...)trojan-activity        URL
42824MALWARE-OTHER Win.Downloader.Carp variant download attempt (more info ...)trojan-activity        URL
42825MALWARE-OTHER Win.Downloader.Carp variant download attempt (more info ...)trojan-activity        URL
42826SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42827SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42828SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42829SERVER-WEBAPP Edimax 802.11AC repeater command injection attempt (more info ...)web-application-attack  2015-5536      URL
42842SERVER-WEBAPP Reprise License Manager edit_lf_get_data directory traversal attempt (more info ...)web-application-attack        URL
42843SERVER-WEBAPP Unitrends Enterprise Backup Appliance download-files command injection attempt (more info ...)web-application-attack  2017-7283      URL
42853SERVER-WEBAPP Serviio Media Server checkStreamUrl command injection attempt (more info ...)web-application-attack        URL
42854SERVER-WEBAPP Serviio Media Server checkStreamUrl command injection attempt (more info ...)web-application-attack        URL
42887SERVER-OTHER ntpq flagstr buffer overflow attempt (more info ...)attempted-user  2017-6460      URL
42890FILE-OTHER AfterMidnight post exploitation tool aftermidnight.dll dll-load exploit attempt (more info ...)attempted-user        URL
42891FILE-OTHER AfterMidnight post exploitation tool request for aftermidnight.dll over SMB attempt (more info ...)attempted-user        URL
42910FILE-PDF Acrobat Reader TIFF malformed IFD tag heap overflow attempt (more info ...)attempted-user  2017-3042      URL
42911FILE-PDF Acrobat Reader TIFF malformed IFD tag heap overflow attempt (more info ...)attempted-user  2017-3042      URL
42912FILE-PDF Acrobat Reader TIFF malformed IFD tag heap overflow attempt (more info ...)attempted-user  2017-3042      URL
42913FILE-PDF Acrobat Reader TIFF malformed IFD tag heap overflow attempt (more info ...)attempted-user  2017-3042      URL
42914FILE-PDF Acrobat Reader TIFF malformed IFD tag heap overflow attempt (more info ...)attempted-user  2017-3042      URL
42915FILE-PDF Acrobat Reader TIFF malformed IFD tag heap overflow attempt (more info ...)attempted-user  2017-3042      URL
42918FILE-IDENTIFY ISO file attachment detected (more info ...)misc-activity        
42920SERVER-WEBAPP LogRhythm Network Monitor JSON configuration API command injection attempt (more info ...)web-application-attack        URL
42941PROTOCOL-OTHER FreeRDP PER length integer underflow attempt (more info ...)attempted-user  2017-2835      URL
42947INDICATOR-OBFUSCATION Dridex String.prototype function definition obfuscation attempt (more info ...)misc-activity        URL
42951SERVER-WEBAPP Oracle Fusion Middleware MapViewer arbitrary JSP file upload attempt (more info ...)attempted-admin  2017-3230  97746    URL
42952SERVER-WEBAPP Oracle Fusion Middleware MapViewer directory traversal attempt (more info ...)web-application-attack  2017-3230  97746    URL
42953SERVER-WEBAPP Oracle Fusion Middleware MapViewer directory traversal attempt (more info ...)web-application-attack  2017-3230  97746    URL
42954SERVER-WEBAPP Oracle Fusion Middleware MapViewer directory traversal attempt (more info ...)web-application-attack  2017-3230  97746    URL
42956SERVER-WEBAPP Brocade Network Advisor CliMonitorReportServlet directory traversal attempt (more info ...)web-application-attack  2016-8207  95691    URL
42957SERVER-WEBAPP Brocade Network Advisor CliMonitorReportServlet directory traversal attempt (more info ...)web-application-attack  2016-8207  95691    URL
42973PROTOCOL-OTHER FreeRDP RSA modulus length integer underflow attempt (more info ...)attempted-user  2017-2836      URL
42974PROTOCOL-OTHER FreeRDP invalid cbCompanyName out of bounds read attempt (more info ...)attempted-user  2017-2838      URL
42975PROTOCOL-OTHER FreeRDP invalid EncryptedPlatformChallenge null pointer dereference attempt (more info ...)attempted-user  2017-2839      URL
42998PROTOCOL-OTHER FreeRDP invalid MCS serverRandomLen out of bounds read attempt (more info ...)attempted-user  2017-2837      URL
42999SERVER-WEBAPP Brocade Network Advisor directory traversal attempt (more info ...)web-application-attack  2016-8206      
43004SERVER-SAMBA Samba is_known_pipe arbitrary module load code execution attempt (more info ...)attempted-user  2017-7494      URL
43005SERVER-WEBAPP Foscam setWifiSetting command psk stack buffer overflow attempt (more info ...)attempted-admin  2017-2851      URL
43045SERVER-OTHER RaySharp DVR administrative interface access attempt (more info ...)attempted-admin        URL
43060SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0355 attack attempt (more info ...)attempted-admin  2017-2853      URL
43061SERVER-WEBAPP Foscam changeUserName command passwd file injection attempt (more info ...)attempted-admin  2017-2850      URL
43064SERVER-OTHER NetBackup bprd remote file write attempt (more info ...)attempted-admin  2017-8857      URL
43077SERVER-WEBAPP Trend Micro InterScan WSA ManagePatches servlet command injection attempt (more info ...)web-application-attack        URL
43078SERVER-WEBAPP Trend Micro InterScan WSA ManagePatches servlet command injection attempt (more info ...)web-application-attack        URL
43079SERVER-WEBAPP Trend Micro InterScan WSA ManagePatches servlet command injection attempt (more info ...)web-application-attack        URL
43093SERVER-WEBAPP CA Unified Infrastructure Management download_lar servelet directory traversal attempt (more info ...)web-application-attack  2016-5803      URL
43095FILE-IMAGE ImageMagick SyncExifProfile out-of-bounds memory read attempt (more info ...)attempted-user  2016-7799      URL
43096FILE-IMAGE ImageMagick SyncExifProfile out-of-bounds memory read attempt (more info ...)attempted-user  2016-7799      URL
43097FILE-IMAGE ImageMagick SyncExifProfile out-of-bounds memory read attempt (more info ...)attempted-user  2016-7799      URL
43098FILE-IMAGE ImageMagick SyncExifProfile out-of-bounds memory read attempt (more info ...)attempted-user  2016-7799      URL
43109SERVER-OTHER Magento unauthenticated arbitrary file write attempt (more info ...)attempted-admin  2016-4010      URL
43120FILE-PDF TRUFFLEHUNTER TALOS-2017-0356 attack attempt (more info ...)attempted-user  2017-16367      URL
43121FILE-PDF TRUFFLEHUNTER TALOS-2017-0356 attack attempt (more info ...)attempted-user  2017-16367      URL
43148PROTOCOL-SCADA Rockwell Automation CIP challenge-response buffer overflow attempt (more info ...)attempted-admin        
43149PROTOCOL-SCADA Rockwell Automation CIP certificate request unknown certificate detected (more info ...)policy-violation        
43150SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0362 attack attempt (more info ...)attempted-dos  2017-2858      URL
43151SERVER-WEBAPP Trend Micro InterScan WSA PacFileManagement servlet command injection attempt (more info ...)web-application-attack        URL
43152SERVER-WEBAPP Trend Micro InterScan WSA PacFileManagement servlet command injection attempt (more info ...)web-application-attack        URL
43153SERVER-WEBAPP Trend Micro InterScan WSA PacFileManagement servlet command injection attempt (more info ...)web-application-attack        URL
43154SERVER-WEBAPP Trend Micro InterScan WSA PacFileManagement servlet command injection attempt (more info ...)web-application-attack        URL
43167FILE-PDF TRUFFLEHUNTER TALOS-2017-0361 attack attempt (more info ...)attempted-user        URL
43168FILE-PDF TRUFFLEHUNTER TALOS-2017-0361 attack attempt (more info ...)attempted-user        URL
43178SERVER-WEBAPP VICIdial user_authorization command injection attempt (more info ...)attempted-admin        URL
43181FILE-OTHER Oniguruma expression parser out of bounds write attempt (more info ...)attempted-user  2017-9226      
43182FILE-OTHER Oniguruma expression parser out of bounds write attempt (more info ...)attempted-user  2017-9226      
43191SERVER-WEBAPP Symantec Messaging Gateway performBackupNow.do command injection attempt (more info ...)web-application-attack  2017-6326      URL
43192SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0364 attack attempt (more info ...)attempted-dos  2017-2860      URL
43211SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0365 attack attempt (more info ...)attempted-dos  2017-2861      URL
43212FILE-PDF Iceni Infix PDF parsing out of bounds write attempt (more info ...)attempted-user  2017-2863      URL
43213FILE-PDF Iceni Infix PDF parsing out of bounds write attempt (more info ...)attempted-user  2017-2863      URL
43216INDICATOR-OBFUSCATION HTTP payload not fully gzip compressed attempt (more info ...)misc-activity        URL
43221MALWARE-OTHER Win.Trojan-Downloader.Jadtree GET request of RAR file to server (more info ...)trojan-activity        URL
43237SERVER-WEBAPP SysAid Enterprise auth bypass and remote file upload attempt (more info ...)attempted-admin        
43249SERVER-WEBAPP Nuxeo CMS BatchUploadObject arbitrary JSP file upload attempt (more info ...)attempted-admin  2017-5869  97083    URL
43250SERVER-WEBAPP Nuxeo CMS BatchUploadObject directory traversal attempt (more info ...)web-application-attack  2017-5869  97083    URL
43251SERVER-WEBAPP Trend Micro InterScan WSA LogSettingHandler command injection attempt (more info ...)web-application-attack        URL
43255INDICATOR-SHELLCODE single byte x86 xor decryption routine (more info ...)shellcode-detect        
43256INDICATOR-OBFUSCATION Rig EK fromCharCode offset 33 obfuscated getElementsByTagName call (more info ...)policy-violation        URL
43257SERVER-WEBAPP CA eHealth command injection command injection attempt (more info ...)web-application-attack  2016-6152      URL
43258SERVER-WEBAPP CA eHealth command injection command injection attempt (more info ...)web-application-attack  2016-6152      URL
43272SERVER-WEBAPP Advantech WebAccess openWidget directory traversal attempt directory traversal attempt (more info ...)web-application-attack  2016-0855      URL
43273SERVER-WEBAPP Advantech WebAccess openWidget directory traversal attempt directory traversal attempt (more info ...)web-application-attack  2016-0855      URL
43274SERVER-WEBAPP Advantech WebAccess openWidget directory traversal attempt directory traversal attempt (more info ...)web-application-attack  2016-0855      URL
43291SERVER-WEBAPP Oracle Application Server 9i unauthenticated application deployment attempt (more info ...)attempted-recon  2001-1371      
43307SERVER-WEBAPP csSearch setup attempt (more info ...)web-application-activity  2002-0495  4368    
43366SERVER-WEBAPP Piwigo directory traversal attempt (more info ...)web-application-attack  2013-1469      
43402SERVER-WEBAPP HP Intelligent Management Center directory traversal directory traversal attempt (more info ...)web-application-attack  2014-2618  68540    
43403SERVER-WEBAPP HP Intelligent Management Center directory traversal directory traversal attempt (more info ...)web-application-attack  2014-2618  68540    
43404SERVER-WEBAPP HP Intelligent Management Center directory traversal directory traversal attempt (more info ...)web-application-attack  2014-2618  68540    
43437SERVER-WEBAPP GoAutoDial cpanel command injection attempt (more info ...)web-application-attack  2015-2845  74281    
43438SERVER-WEBAPP GoAutoDial cpanel command injection attempt (more info ...)web-application-attack  2015-2845  74281    
43442MALWARE-OTHER Win.Ransomware.Sorebrect download attempt (more info ...)trojan-activity        URL
43443MALWARE-OTHER Win.Ransomware.Sorebrect download attempt (more info ...)trojan-activity        URL
43464SERVER-OTHER HP Intelligent Management Center dbman RestartDB opcode command injection attempt (more info ...)attempted-admin  2017-5816  98469    URL
43483SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0369 attack attempt (more info ...)attempted-admin        URL
43484SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0369 attack attempt (more info ...)attempted-admin        URL
43485SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0369 attack attempt (more info ...)attempted-admin        URL
43486SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0368 attack attempt (more info ...)attempted-admin        URL
43488SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0372 attack attempt (more info ...)attempted-admin  2017-2890      URL
43489SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0374 attack attempt (more info ...)attempted-admin  2017-2869      URL
43494SERVER-WEBAPP Lets Encrypt SSL certificate for domain resembling appleid (more info ...)misc-attack        
43518SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0373 attack attempt (more info ...)attempted-admin  2017-2867      URL
43545SERVER-WEBAPP HPE System Management Homepage buffer overflow attempt (more info ...)attempted-admin  2016-4395  93961    
43548SERVER-WEBAPP Brocade Network Advisor remote code execution attempt (more info ...)web-application-attack  2016-8204  95695    URL
43549SERVER-WEBAPP AlienVault Unified Security Manager authentication bypass attempt (more info ...)attempted-admin        
43552SERVER-WEBAPP ReadyDesk upload remote code execution attempt (more info ...)web-application-attack        
43553SERVER-WEBAPP ReadyDesk upload remote code execution attempt (more info ...)web-application-attack        
43554SERVER-WEBAPP ReadyDesk upload remote code execution attempt (more info ...)web-application-attack        
43556SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0382 attack attempt (more info ...)attempted-admin  2017-2876      URL
43557SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0384 attack attempt (more info ...)attempted-admin  2017-2877      URL
43558SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0379 attack attempt (more info ...)misc-activity  2017-2872      URL
43559SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0378 attack attempt (more info ...)misc-activity  2017-2871      URL
43561SERVER-OTHER Aerospike Database Server si_prop stack buffer overflow attempt (more info ...)attempted-user  2016-9054      URL
43583SERVER-WEBAPP CA eHealth command injection attempt (more info ...)web-application-attack  2016-6152  80698    URL
43584SERVER-WEBAPP CA eHealth command injection attempt (more info ...)web-application-attack  2016-6152  80698    URL
43585SERVER-WEBAPP CA eHealth command injection attempt (more info ...)web-application-attack  2016-6152  80698    URL
43586SERVER-WEBAPP CA eHealth command injection attempt (more info ...)web-application-attack  2016-6152  80698    URL
43588SERVER-WEBAPP Brocade Network Advisor directory traversal attempt (more info ...)web-application-attack  2016-8205  95694    URL
43589SERVER-WEBAPP Brocade Network Advisor directory traversal attempt (more info ...)web-application-attack  2016-8205  95694    URL
43590SERVER-WEBAPP Brocade Network Advisor directory traversal attempt (more info ...)web-application-attack  2016-8205  95694    URL
43603FILE-OTHER Schneider Electric ClearSCADA malicious OPF file (more info ...)attempted-admin  2014-0779      
43604FILE-OTHER Schneider Electric ClearSCADA malicious OPF file (more info ...)attempted-admin  2014-0779      
43625SERVER-WEBAPP Axis M3004 remote code execution attempt (more info ...)attempted-user  2017-9765      
43645SERVER-WEBAPP SonicWall Secure Remote Access diagnostics command injection attempt (more info ...)web-application-attack  2016-9682  96375    URL
43646SERVER-WEBAPP SonicWall Secure Remote Access diagnostics command injection attempt (more info ...)web-application-attack  2016-9682  96375    URL
43647SERVER-WEBAPP SonicWall Secure Remote Access diagnostics command injection attempt (more info ...)web-application-attack  2016-9682  96375    URL
43684MALWARE-OTHER Win.Trojan.Nemucod variant file download (more info ...)trojan-activity        URL
43685MALWARE-OTHER Win.Trojan.Nemucod variant outbound connection (more info ...)trojan-activity        URL
43686MALWARE-OTHER Win.Trojan.NemucodAES variant outbound connection (more info ...)trojan-activity        URL
43688SERVER-WEBAPP SonicWall Secure Remote Access viewcert command injection attempt (more info ...)web-application-attack  2016-9684  96375    URL
43689SERVER-WEBAPP SonicWall Secure Remote Access viewcert command injection attempt (more info ...)web-application-attack  2016-9684  96375    URL
43690SERVER-WEBAPP SonicWall Secure Remote Access viewcert command injection attempt (more info ...)web-application-attack  2016-9684  96375    URL
43695SERVER-WEBAPP Trend Micro InterScan WSA DeployWizard command injection attempt (more info ...)web-application-attack        URL
43696SERVER-WEBAPP Trend Micro InterScan WSA DeployWizard command injection attempt (more info ...)web-application-attack        URL
43697SERVER-WEBAPP Trend Micro InterScan WSA DeployWizard command injection attempt (more info ...)web-application-attack        URL
43709SERVER-WEBAPP SonicWall Secure Remote Access gencsr command injection attempt (more info ...)web-application-attack        URL
43710SERVER-WEBAPP SonicWall Secure Remote Access gencsr command injection attempt (more info ...)web-application-attack        URL
43711SERVER-WEBAPP SonicWall Secure Remote Access gencsr command injection attempt (more info ...)web-application-attack        URL
43713SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0385 attack attempt (more info ...)attempted-admin  2017-2878      URL
43723SERVER-WEBAPP FCRing sfuss remote file include attempt (more info ...)web-application-attack  2007-1133  22693    
43724SERVER-WEBAPP FCRing sfuss remote file include attempt (more info ...)web-application-attack  2007-1133  22693    
43793SERVER-WEBAPP Symantec SEPM management console cross site scripting attempt (more info ...)attempted-user  2016-3652  91444    
43819SERVER-WEBAPP Kaspersky Anti-Virus directory traversal attempt (more info ...)web-application-attack  2017-9812  99330    URL
43820SERVER-WEBAPP Kaspersky Anti-Virus directory traversal attempt (more info ...)web-application-attack  2017-9812  99330    URL
43821SERVER-WEBAPP Kaspersky Anti-Virus directory traversal attempt (more info ...)web-application-attack  2017-9812  99330    URL
43822SERVER-WEBAPP Advantech SUSIAccess Server downloadCSV.jsp directory traversal attempt (more info ...)web-application-attack  2016-9349  94629    URL
43823SERVER-WEBAPP Advantech SUSIAccess Server downloadCSV.jsp directory traversal attempt (more info ...)web-application-attack  2016-9349  94629    URL
43824SERVER-WEBAPP Advantech SUSIAccess Server downloadCSV.jsp directory traversal attempt (more info ...)web-application-attack  2016-9349  94629    URL
43849SERVER-OTHER HP Intelligent Management Center dbman RestoreZipFile opcode command injection attempt (more info ...)attempted-admin  2017-5821  98493    URL
43850SERVER-OTHER HP Intelligent Management Center dbman BackupZipFile opcode command injection attempt (more info ...)attempted-admin  2017-5820  98493    URL
43855FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0394 attack attempt (more info ...)attempted-user  2017-2887      URL
43856FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0394 attack attempt (more info ...)attempted-user  2017-2887      URL
43857FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0395 attack attempt (more info ...)attempted-user  2019-5087      URL
43858FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0395 attack attempt (more info ...)attempted-user  2019-5087      URL
43859FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0395 attack attempt (more info ...)attempted-user  2019-5087      URL
43860FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0395 attack attempt (more info ...)attempted-user  2019-5087      URL
43861SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0397 attack attempt (more info ...)attempted-admin  2017-2890      URL
43862FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0393 attack attempt (more info ...)attempted-user  2017-2886      URL
43863FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0393 attack attempt (more info ...)attempted-user  2017-2886      URL
43877FILE-PDF Acrobat Reader PDFDocEncoding object WinAnsiEncoding memory corruption attempt (more info ...)attempted-user  2017-11263      URL
43878FILE-PDF Acrobat Reader PDFDocEncoding object WinAnsiEncoding memory corruption attempt (more info ...)attempted-user  2017-11263      URL
43883FILE-PDF Acrobat Reader FontDescriptor object type confusion attempt (more info ...)attempted-user  2017-11221      URL
43884FILE-PDF Acrobat Reader FontDescriptor object type confusion attempt (more info ...)attempted-user  2017-11221      URL
43891MALWARE-OTHER Win.Malware.Emotet variant lateral propagation (more info ...)trojan-activity        URL
43892MALWARE-OTHER Win.Malware.Emotet variant lateral propagation (more info ...)trojan-activity        URL
43895SERVER-WEBAPP SonicWall Secure Remote Access sitecustomization command injection attempt (more info ...)web-application-attack        URL
43896SERVER-WEBAPP SonicWall Secure Remote Access sitecustomization command injection attempt (more info ...)web-application-attack        URL
43897SERVER-WEBAPP SonicWall Secure Remote Access sitecustomization command injection attempt (more info ...)web-application-attack        URL
43898SERVER-WEBAPP SonicWall Secure Remote Access sitecustomization command injection attempt (more info ...)web-application-attack        URL
43931EXPLOIT-KIT RIG exploit kit shellcode detected (more info ...)attempted-user        
43975MALWARE-OTHER Win.Trojan.Hermit variant malicious dropper download attempt (more info ...)trojan-activity        URL
43976MALWARE-OTHER Win.Trojan.Hermit variant malicious dropper download attempt (more info ...)trojan-activity        URL
43986PROTOCOL-SCADA Schneider Electroc ModbusDrv.exe buffer overflow attempt (more info ...)attempted-admin  2013-0662      
44012POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0411 attack attempt (more info ...)policy-violation  2017-2898      URL
44070SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0418 attack attempt (more info ...)misc-attack  2017-2912      URL
44071SERVER-OTHER Objectivity DB lock server buffer overflow attempt (more info ...)attempted-admin        
44078MALWARE-OTHER Win.Trojan.Nemucod file download (more info ...)trojan-activity        URL
44082SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0420 attack attempt (more info ...)misc-attack  2017-2913      URL
44097FILE-PDF Foxit Reader launchURL Command Injection Remote Code Execution attempt (more info ...)attempted-admin  2017-10951      
44116SERVER-WEBAPP Symantec Messaging Gateway localBackupFileSelection command injection attempt (more info ...)web-application-attack  2017-6327  100135    URL
44117SERVER-WEBAPP Symantec Messaging Gateway localBackupFileSelection command injection attempt (more info ...)web-application-attack  2017-6327  100135    URL
44118SERVER-WEBAPP Symantec Messaging Gateway localBackupFileSelection command injection attempt (more info ...)web-application-attack  2017-6327  100135    URL
44151PROTOCOL-SCADA CODESYS Gateway-Server invalid memory access attempt (more info ...)attempted-admin  2012-4704  58032    URL
44160SERVER-OTHER tcpdump ISAKMP parser buffer overflow attempt (more info ...)attempted-user  2017-5205      
44161SERVER-OTHER tcpdump ISAKMP parser buffer overflow attempt (more info ...)attempted-user  2017-5205      
44167FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0412 attack attempt (more info ...)attempted-user  2017-2905      URL
44168FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0412 attack attempt (more info ...)attempted-user  2017-2905      URL
44178FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0427 attack attempt (more info ...)attempted-user  2017-2920      URL
44179FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0427 attack attempt (more info ...)attempted-user  2017-2920      URL
44186FILE-OTHER TRUFFLEHUNTER TALOS-2017-0425 attack attempt (more info ...)attempted-user  2017-2918      URL
44187FILE-OTHER TRUFFLEHUNTER TALOS-2017-0425 attack attempt (more info ...)attempted-user  2017-2918      URL
44189SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0421 attack attempt (more info ...)attempted-user  2017-2914      URL
44191SERVER-OTHER HP Intelligent Management Center dbman BackupDBase opcode command injection attempt (more info ...)attempted-admin  2017-8954  99925    URL
44202SERVER-OTHER Sybase M-Business Anywhere agSoap.exe closing tag buffer overflow attempt (more info ...)attempted-admin    47775    
44223FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0406 attack attempt (more info ...)attempted-user  2017-2899      URL
44224FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0406 attack attempt (more info ...)attempted-user  2017-2899      URL
44225FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0406 attack attempt (more info ...)attempted-user  2017-2899      URL
44226FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0406 attack attempt (more info ...)attempted-user  2017-2899      URL
44227FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0406 attack attempt (more info ...)attempted-user  2017-2899      URL
44228FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0406 attack attempt (more info ...)attempted-user  2017-2899      URL
44229FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0406 attack attempt (more info ...)attempted-user  2017-2899      URL
44230FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0406 attack attempt (more info ...)attempted-user  2017-2899      URL
44237FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0410 attack attempt (more info ...)attempted-user  2017-2903      URL
44238FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0410 attack attempt (more info ...)attempted-user  2017-2903      URL
44239FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0410 attack attempt (more info ...)attempted-user  2017-2903      URL
44240FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0410 attack attempt (more info ...)attempted-user  2017-2903      URL
44241FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0410 attack attempt (more info ...)attempted-user  2017-2903      URL
44242FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0410 attack attempt (more info ...)attempted-user  2017-2903      URL
44243FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0410 attack attempt (more info ...)attempted-user  2017-2903      URL
44244FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0410 attack attempt (more info ...)attempted-user  2017-2903      URL
44245FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0409 attack attempt (more info ...)attempted-user  2017-2902      URL
44246FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0409 attack attempt (more info ...)attempted-user  2017-2902      URL
44247FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0409 attack attempt (more info ...)attempted-user  2017-2902      URL
44248FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0409 attack attempt (more info ...)attempted-user  2017-2902      URL
44249FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0411 attack attempt (more info ...)attempted-user  2017-2904      URL
44250FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0411 attack attempt (more info ...)attempted-user  2017-2904      URL
44251FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0408 attack attempt (more info ...)attempted-user  2017-2901      URL
44252FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0408 attack attempt (more info ...)attempted-user  2017-2901      URL
44253FILE-OTHER TRUFFLEHUNTER TALOS-2017-0415 attack attempt (more info ...)attempted-user  2017-2908      URL
44254FILE-OTHER TRUFFLEHUNTER TALOS-2017-0415 attack attempt (more info ...)attempted-user  2017-2908      URL
44255FILE-OTHER TRUFFLEHUNTER TALOS-2017-0415 attack attempt (more info ...)attempted-user  2017-2908      URL
44256FILE-OTHER TRUFFLEHUNTER TALOS-2017-0415 attack attempt (more info ...)attempted-user  2017-2908      URL
44257FILE-OTHER TRUFFLEHUNTER TALOS-2017-0415 attack attempt (more info ...)attempted-user  2017-2908      URL
44258FILE-OTHER TRUFFLEHUNTER TALOS-2017-0415 attack attempt (more info ...)attempted-user  2017-2908      URL
44259FILE-OTHER TRUFFLEHUNTER TALOS-2017-0415 attack attempt (more info ...)attempted-user  2017-2908      URL
44260FILE-OTHER TRUFFLEHUNTER TALOS-2017-0415 attack attempt (more info ...)attempted-user  2017-2908      URL
44261FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2017-0414 attack attempt (more info ...)attempted-user  2017-2907      URL
44262FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2017-0414 attack attempt (more info ...)attempted-user  2017-2907      URL
44263FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2017-0414 attack attempt (more info ...)attempted-user  2017-2907      URL
44264FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2017-0414 attack attempt (more info ...)attempted-user  2017-2907      URL
44265FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2017-0413 attack attempt (more info ...)attempted-user  2017-2906      URL
44266FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2017-0413 attack attempt (more info ...)attempted-user  2017-2906      URL
44269FILE-OTHER TRUFFLEHUNTER TALOS-2017-0434 attack attempt (more info ...)attempted-user  2017-12082      URL
44270FILE-OTHER TRUFFLEHUNTER TALOS-2017-0434 attack attempt (more info ...)attempted-user  2017-12082      URL
44287FILE-OTHER TRUFFLEHUNTER TALOS-2017-0433 attack attempt (more info ...)attempted-user  2017-12099      URL
44288FILE-OTHER TRUFFLEHUNTER TALOS-2017-0433 attack attempt (more info ...)attempted-user  2017-12099      URL
44294FILE-PDF TRUFFLEHUNTER TALOS-2017-0432 attack attempt (more info ...)attempted-user        URL
44295FILE-PDF TRUFFLEHUNTER TALOS-2017-0432 attack attempt (more info ...)attempted-user        URL
44297SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0435 attack attempt (more info ...)attempted-recon  2017-12083      URL
44310SERVER-WEBAPP Oracle Secure Backup web tool command injection attempt (more info ...)web-application-attack  2011-2261      
44311SERVER-WEBAPP Oracle Secure Backup web tool command injection attempt (more info ...)web-application-attack  2011-2261      
44312SERVER-WEBAPP Oracle Secure Backup web tool command injection attempt (more info ...)web-application-attack  2011-2261      
44318FILE-OTHER TRUFFLEHUNTER TALOS-2017-0438 attack attempt (more info ...)attempted-user  2017-12105      URL
44319FILE-OTHER TRUFFLEHUNTER TALOS-2017-0438 attack attempt (more info ...)attempted-user  2017-12105      URL
44321SERVER-WEBAPP NEC Express Cluster DeleteWorkDirectory.js command injection attempt (more info ...)web-application-attack        URL
44322SERVER-WEBAPP NEC Express Cluster DeleteWorkDirectory.js command injection attempt (more info ...)web-application-attack        URL
44337SERVER-OTHER HP Intelligent Management Center dbman RestoreDBase opcode command injection attempt (more info ...)attempted-admin  2017-5817  98469    URL
44344SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0439 attack attempt (more info ...)attempted-user  2021-1439      URL
44353FILE-OTHER WSDL soap endpoint location code injection attempt (more info ...)attempted-user  2017-8759      URL
44354FILE-OTHER WSDL soap endpoint location code injection attempt (more info ...)attempted-user  2017-8759      URL
44376FILE-OTHER TRUFFLEHUNTER TALOS-2017-0452 attack attempt (more info ...)attempted-user  2017-12100      URL
44377FILE-OTHER TRUFFLEHUNTER TALOS-2017-0452 attack attempt (more info ...)attempted-user  2017-12100      URL
44380SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0450 attack attempt (more info ...)attempted-user  2017-12098      URL
44381SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0449 attack attempt (more info ...)attempted-user  2017-12097      URL
44383SERVER-WEBAPP D-Link router firmware update attempt (more info ...)misc-attack        URL
44384SERVER-WEBAPP D-Link router stack based buffer overflow attempt (more info ...)attempted-admin        URL
44385SERVER-WEBAPP D-Link router stack based buffer overflow attempt (more info ...)attempted-admin        URL
44386SERVER-WEBAPP D-Link router stack based buffer overflow attempt (more info ...)attempted-admin        URL
44387SERVER-WEBAPP D-Link router stack based buffer overflow attempt (more info ...)attempted-admin        URL
44397FILE-OTHER TRUFFLEHUNTER TALOS-2017-0453 attack attempt (more info ...)attempted-user  2017-12101      URL
44398FILE-OTHER TRUFFLEHUNTER TALOS-2017-0453 attack attempt (more info ...)attempted-user  2017-12101      URL
44435SERVER-WEBAPP DenyAll WAF authentication token disclosure attempt (more info ...)attempted-recon        URL
44441FILE-IDENTIFY Blender blend file magic detected (more info ...)misc-activity        
44442FILE-IDENTIFY Blender blend file magic detected (more info ...)misc-activity        
44444FILE-OTHER TRUFFLEHUNTER TALOS-2017-0455 attack attempt (more info ...)attempted-user  2017-12103      URL
44445FILE-OTHER TRUFFLEHUNTER TALOS-2017-0455 attack attempt (more info ...)attempted-user  2017-12103      URL
44446FILE-OTHER TRUFFLEHUNTER TALOS-2017-0454 attack attempt (more info ...)attempted-user  2017-12102      URL
44447FILE-OTHER TRUFFLEHUNTER TALOS-2017-0454 attack attempt (more info ...)attempted-user  2017-12102      URL
44448FILE-OTHER TRUFFLEHUNTER TALOS-2017-0456 attack attempt (more info ...)attempted-user  2017-12104      URL
44449FILE-OTHER TRUFFLEHUNTER TALOS-2017-0456 attack attempt (more info ...)attempted-user  2017-12104      URL
44473FILE-OTHER ZIP file name overflow attempt (more info ...)attempted-user  2016-4519  46375    
44474MALWARE-OTHER GHBkdr TLS Change Cipher spoof runtime detection (more info ...)trojan-activity        URL
44475MALWARE-OTHER GHBkdr TLS Handshake spoof runtime detection (more info ...)trojan-activity        URL
44483SERVER-OTHER Supervisord remote code execution attempt (more info ...)attempted-user  2017-11610      URL
44497SERVER-WEBAPP Faleemi IP Cameras information disclosure attempt (more info ...)attempted-recon        URL
44501SERVER-OTHER Advantech WebAccess buffer overflow attempt (more info ...)attempted-user  2016-0851      URL
44502SERVER-OTHER Advantech WebAccess buffer overflow attempt (more info ...)attempted-user  2016-0851      URL
44504SERVER-WEBAPP Symantec Endpoint Protection Manager directory traversal attempt (more info ...)web-application-attack  2016-5307  91443    
44505SERVER-WEBAPP Symantec Endpoint Protection Manager directory traversal attempt (more info ...)web-application-attack  2016-5307  91443    
44506SERVER-WEBAPP Symantec Endpoint Protection Manager directory traversal attempt (more info ...)web-application-attack  2016-5307  91443    
44508BROWSER-IE scripting engine memory corruption vulnerability attempt (more info ...)attempted-admin  2017-11793      
44509BROWSER-IE scripting engine memory corruption vulnerability attempt (more info ...)attempted-admin  2017-11793      
44524FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0459 attack attempt (more info ...)attempted-user  2017-12107      URL
44525FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0459 attack attempt (more info ...)attempted-user  2017-12107      URL
44537SERVER-WEBAPP NEC ExpressCluster UploadFile.js arbitrary file upload attempt (more info ...)web-application-attack        URL
44538SERVER-WEBAPP NEC ExpressCluster LogCollect.js command injection attempt (more info ...)web-application-attack        URL
44539SERVER-WEBAPP NEC ExpressCluster LogCollect.js command injection attempt (more info ...)web-application-attack        URL
44544FILE-PDF Nitro Pro PDF document field dereference use after free attempt (more info ...)attempted-user        URL
44545FILE-PDF Nitro Pro PDF document field dereference use after free attempt (more info ...)attempted-user        URL
44546FILE-PDF Nitro Pro use after free remote code execution attempt (more info ...)attempted-user        
44547FILE-PDF Nitro Pro use after free remote code execution attempt (more info ...)attempted-user        
44582SERVER-WEBAPP Trend Micro widget system authentication bypass attempt (more info ...)attempted-admin        URL
44624SERVER-WEBAPP TP-Link syslog.filter.json command injection attempt (more info ...)web-application-attack        
44625SERVER-WEBAPP TP-Link syslog.filter.json command injection attempt (more info ...)web-application-attack        
44626SERVER-WEBAPP TP-Link syslog.filter.json command injection attempt (more info ...)web-application-attack        
44627SERVER-WEBAPP TP-Link syslog.filter.json command injection attempt (more info ...)web-application-attack        
44634SERVER-OTHER IBM Tivoli Storage Manager FastBack command injection attempt (more info ...)attempted-admin  2015-1938      URL
44641POLICY-OTHER SERVER-WEBAPP Symantec Endpoint Protection Manager authentication lock bypass attempt (more info ...)attempted-admin  2016-3648      
44646MALWARE-OTHER Win.Ransomware.BadRabbit propagation via SVCCTL remote service attempt (more info ...)trojan-activity        URL
44647MALWARE-OTHER Win.Ransomware.BadRabbit propagation via SMB2 transfer attempt (more info ...)trojan-activity        URL
44648MALWARE-OTHER Win.Ransomware.BadRabbit propagation via SMB transfer attempt (more info ...)trojan-activity        URL
44649MALWARE-OTHER Win.Ransomware.BadRabbit propagation via SMB2 transfer attempt (more info ...)trojan-activity        URL
44650MALWARE-OTHER Win.Ransomware.BadRabbit propagation via SMB transfer attempt (more info ...)trojan-activity        URL
44658SERVER-WEBAPP Unitrends Enterprise Backup storage API command injection attempt (more info ...)web-application-attack  2017-12478      URL
44687SERVER-WEBAPP Netgear DGN1000 series routers authentication bypass attempt (more info ...)attempted-admin    60281    URL
44688SERVER-WEBAPP Netgear DGN1000 series routers arbitrary command execution attempt (more info ...)attempted-admin    60281    URL
44707SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0471 attack attempt (more info ...)attempted-dos  2017-12119      URL
44708SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0471 attack attempt (more info ...)attempted-dos  2017-12119      URL
44709SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0471 attack attempt (more info ...)attempted-dos  2017-12119      URL
44710SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0471 attack attempt (more info ...)attempted-dos  2017-12119      URL
44711SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0471 attack attempt (more info ...)attempted-dos  2017-12119      URL
44712SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0471 attack attempt (more info ...)attempted-dos  2017-12119      URL
44728INDICATOR-COMPROMISE Meterpreter payload download attempt (more info ...)trojan-activity        
44743SERVER-OTHER libupnp command buffer overflow attempt (more info ...)attempted-admin  2012-5962      
44792SERVER-WEBAPP Node.js V8 Debugging Protocol command injection attempt (more info ...)policy-violation        URL
44835SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0472 attack attempt (more info ...)web-application-attack  2017-12120      URL
44836SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0472 attack attempt (more info ...)web-application-attack  2017-12120      URL
44837SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0472 attack attempt (more info ...)web-application-attack  2017-12120      URL
44840SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0473 attack attempt (more info ...)web-application-attack  2017-12121      URL
44841SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0473 attack attempt (more info ...)web-application-attack  2017-12121      URL
44842SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0473 attack attempt (more info ...)web-application-attack  2017-12121      URL
44847SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0482 attack attempt (more info ...)web-application-attack  2017-14434      URL
44848SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0482 attack attempt (more info ...)web-application-attack  2017-14434      URL
44849SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0482 attack attempt (more info ...)web-application-attack  2017-14434      URL
44850SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0477 attack attempt (more info ...)web-application-attack  2017-12125      URL
44851SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0477 attack attempt (more info ...)web-application-attack  2017-12125      URL
44852SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0477 attack attempt (more info ...)web-application-attack  2017-12125      URL
44858SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0474 attack attempt (more info ...)attempted-dos  2017-14437      URL
44863SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0483 attack attempt (more info ...)attempted-admin  2017-14447      URL
44866SERVER-WEBAPP Xplico decoding manager daemon command injection attempt (more info ...)web-application-attack  2017-16666      URL
44875INDICATOR-COMPROMISE Malicious VBA script detected (more info ...)attempted-admin        
44877SERVER-OTHER Citrix XenApp and XenDesktop XML service memory corruption attempt (more info ...)attempted-admin  2008-3257  48898    
44910SERVER-OTHER Altiris Express Server Engine stack buffer overflow attempt (more info ...)attempted-admin        
44949FILE-PDF Acrobat TrueTypeFont file out of bounds read attempt (more info ...)attempted-user  2017-16417      URL
44950FILE-PDF Acrobat TrueTypeFont file out of bounds read attempt (more info ...)attempted-user  2017-16417      URL
44967FILE-PDF Acrobat malformed html tag out of bounds read attempt (more info ...)attempted-user  2017-16394      URL
44968FILE-PDF Acrobat malformed html tag out of bounds read attempt (more info ...)attempted-user  2017-16394      URL
44981MALWARE-OTHER Win.Ransomware.Kristina encryption over SMB attempt (more info ...)trojan-activity        URL
44982MALWARE-OTHER Win.Ransomware.Kristina encryption over SMB attempt (more info ...)trojan-activity        URL
45001SERVER-WEBAPP Netgear WNR2000 information leak attempt (more info ...)attempted-recon  2016-10175      URL
45002FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45003FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45004FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45005FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45006FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45007FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45008FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45009FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45010FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45011FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45012FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45013FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45014FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45015FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45016FILE-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-7525      URL
45017FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0497 attack attempt (more info ...)attempted-user  2018-3839      URL
45018FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0497 attack attempt (more info ...)attempted-user  2018-3839      URL
45019FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0490 attack attempt (more info ...)attempted-user  2020-6082      URL
45020FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0490 attack attempt (more info ...)attempted-user  2020-6082      URL
45021FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0491 attack attempt (more info ...)attempted-user  2017-14442      URL
45022FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0491 attack attempt (more info ...)attempted-user  2017-14442      URL
45025FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0489 attack attempt (more info ...)attempted-user  2017-14440      URL
45026FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0489 attack attempt (more info ...)attempted-user  2017-14440      URL
45033FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0488 attack attempt (more info ...)attempted-user  2017-12122      URL
45034FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0488 attack attempt (more info ...)attempted-user  2017-12122      URL
45037SERVER-WEBAPP Joomla LDAP authentication plugin information disclosure exploitation attempt (more info ...)web-application-attack  2017-14596      URL
45038SERVER-WEBAPP Joomla LDAP authentication plugin information disclosure exploitation attempt (more info ...)web-application-attack  2017-14596      URL
45039SERVER-WEBAPP Joomla LDAP authentication plugin information disclosure exploitation attempt (more info ...)web-application-attack  2017-14596      URL
45046SERVER-OTHER Exim malformed BDAT code execution attempt (more info ...)attempted-admin  2017-16943      
45047FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0499 attack attempt (more info ...)attempted-user  2017-14450      URL
45048FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0499 attack attempt (more info ...)attempted-user  2017-14450      URL
45073SERVER-WEBAPP Wireless IP Camera WIFICAM information leak attempt (more info ...)attempted-recon  2017-8225      
45074SERVER-SAMBA Samba unsigned connections attempt (more info ...)attempted-user  2017-12150      URL
45081SERVER-OTHER Geutebrueck GCore web server buffer overflow attempt (more info ...)attempted-admin  2017-11517      
45088SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0502 attack attempt (more info ...)attempted-user  2017-14455      URL
45089SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0501 attack attempt (more info ...)attempted-admin        URL
45094SERVER-WEBAPP MediaWiki arbitrary file write attempt (more info ...)attempted-user  2017-0372      
45102FILE-PDF TRUFFLEHUNTER TALOS-2017-0505 attack attempt (more info ...)attempted-user        URL
45103FILE-PDF TRUFFLEHUNTER TALOS-2017-0505 attack attempt (more info ...)attempted-user        URL
45105FILE-PDF TRUFFLEHUNTER TALOS-2017-0504 attack attempt (more info ...)attempted-user        URL
45106FILE-PDF TRUFFLEHUNTER TALOS-2017-0504 attack attempt (more info ...)attempted-user        URL
45109SERVER-WEBAPP OrientDB remote code execution attempt (more info ...)attempted-user  2017-11467      URL
45110SERVER-WEBAPP OrientDB privilege escalation attempt (more info ...)attempted-user  2017-11467      URL
45115SERVER-MAIL Multiple products non-ascii sender address spoofing attempt (more info ...)misc-attack  2018-0819      URL
45116SERVER-MAIL Multiple products non-ascii sender address spoofing attempt (more info ...)misc-attack  2018-0819      URL
45117SERVER-WEBAPP Huawei DeviceUpgrade command injection attempt (more info ...)web-application-attack  2017-17215      
45118SERVER-MAIL Multiple products non-ascii sender address spoofing attempt (more info ...)misc-attack  2018-0819      URL
45119SERVER-MAIL Multiple products non-ascii sender address spoofing attempt (more info ...)misc-attack  2018-0819      URL
45136INDICATOR-COMPROMISE Metasploit PowerShell CLI Download and Run attempt (more info ...)attempted-user        URL
45137INDICATOR-COMPROMISE Metasploit run hidden powershell attempt (more info ...)attempted-user        URL
45158FILE-PDF TRUFFLEHUNTER TALOS-2017-0506 attack attempt (more info ...)attempted-user  2017-14458      URL
45159FILE-PDF TRUFFLEHUNTER TALOS-2017-0506 attack attempt (more info ...)attempted-user  2017-14458      URL
45199SERVER-OTHER limited RSA ciphersuite list - possible Bleichenbacher SSL attack attempt (more info ...)attempted-recon  2017-6168      URL
45201SERVER-OTHER limited RSA ciphersuite list - possible Bleichenbacher SSL attack attempt (more info ...)attempted-recon  2017-6168      URL
45216FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2017-0509 attack attempt (more info ...)attempted-dos        URL
45217FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2017-0509 attack attempt (more info ...)attempted-dos        URL
45219SERVER-WEBAPP Embedthis GoAhead LD_preload code execution attempt (more info ...)attempted-admin  2017-17562      
45236SERVER-WEBAPP Palo Alto Networks Firewall cms_changeDeviceContext.esp session injection attempt (more info ...)attempted-admin  2017-15944  102079    URL
45237SERVER-WEBAPP Axis Communications IP camera SSI command injection attempt (more info ...)web-application-attack        URL
45238SERVER-WEBAPP Axis Communications IP camera SSI command injection attempt (more info ...)web-application-attack        URL
45248SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0510 attack attempt (more info ...)attempted-recon  2017-14461      URL
45250SERVER-WEBAPP Delta IEM DIAEnergie file upload attempt (more info ...)attempted-admin        URL
45253SERVER-OTHER Dahua DVR hard-coded root login attempt (more info ...)attempted-admin  2013-3612      
45254SERVER-OTHER Polycom HDX Series remote code execution attempt (more info ...)attempted-user        URL
45255SERVER-SAMBA Samba tree connect andx memory corruption attempt (more info ...)attempted-user  2017-14746      
45261SERVER-WEBAPP Vivotek IP Cameras remote stack buffer overflow attempt (more info ...)attempted-user        URL
45266POLICY-OTHER CoinHive Miner client detected (more info ...)policy-violation        URL
45268POLICY-OTHER CoinHive Miner client detected (more info ...)policy-violation        URL
45304SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-admin  2017-3506  97884    URL
45312SERVER-WEBAPP Vicon Security and Infinova filterIp command injection attempt (more info ...)web-application-attack        URL
45313SERVER-WEBAPP Vicon Security and Infinova filterIp command injection attempt (more info ...)web-application-attack        URL
45318SERVER-WEBAPP Citrix NetScaler SD-WAN command injection attempt (more info ...)web-application-attack  2017-6316      URL
45319SERVER-WEBAPP Citrix NetScaler SD-WAN command injection attempt (more info ...)web-application-attack  2017-6316      URL
45357OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45358OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45359OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45360OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45361OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45362OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45363OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45364OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45365OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45366OS-OTHER Intel x86 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45367OS-OTHER Intel x64 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45368OS-OTHER Intel x64 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45393SERVER-OTHER Quest Privilege Manager pmmasterd buffer overflow attempt (more info ...)attempted-admin  2017-6553      URL
45397PUA-ADWARE Osx.Adware.SurfBuyer adware outbound connection detected (more info ...)trojan-activity        URL
45398PUA-ADWARE Osx.Adware.SurfBuyer adware outbound connection detected (more info ...)trojan-activity        URL
45401SERVER-WEBAPP Fortinet FortiOS redir parameter cross site scripting attempt (more info ...)attempted-user  2017-14186  101955    
45412SERVER-WEBAPP Asus RT-AC88U deleteOfflineClients memory corruption attempt (more info ...)attempted-admin  2017-12754      
45414SERVER-WEBAPP DotNetNuke DNNPersonalization remote code execution attempt (more info ...)attempted-admin  2017-9822      URL
45418OS-OTHER Apple macOS IOHIDeous exploit download attempt (more info ...)attempted-user        URL
45419OS-OTHER Apple macOS IOHIDeous exploit download attempt (more info ...)attempted-user        URL
45441SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0511 attack attempt (more info ...)attempted-admin  2018-3832      URL
45443OS-OTHER Intel x64 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45444OS-OTHER Intel x64 side-channel analysis information leak attempt (more info ...)attempted-recon  2017-5754      
45447SERVER-WEBAPP Linksys WVBR0-25 Wireless Video Bridge command injection attempt (more info ...)attempted-user  2017-17411      
45448SERVER-WEBAPP Linksys WVBR0-25 Wireless Video Bridge command injection attempt (more info ...)attempted-user  2017-17411      
45449SERVER-WEBAPP Linksys WVBR0-25 Wireless Video Bridge command injection attempt (more info ...)attempted-user  2017-17411      
45450SERVER-WEBAPP Linksys WVBR0-25 Wireless Video Bridge command injection attempt (more info ...)attempted-user  2017-17411      
45451SERVER-WEBAPP Linksys WVBR0-25 Wireless Video Bridge command injection attempt (more info ...)attempted-user  2017-17411      
45452SERVER-WEBAPP Linksys WVBR0-25 Wireless Video Bridge command injection attempt (more info ...)attempted-user  2017-17411      
45453SERVER-WEBAPP Linksys WVBR0-25 Wireless Video Bridge command injection attempt (more info ...)attempted-user  2017-17411      
45465SERVER-WEBAPP Splunk daemon default admin credentials login attempt (more info ...)attempted-admin  2018-0095      URL
45480SERVER-WEBAPP Cambium cnPilot r200/r201 directory traversal attempt (more info ...)web-application-attack  2017-5261      URL
45481SERVER-WEBAPP Cambium cnPilot r200/r201 directory traversal attempt (more info ...)web-application-attack  2017-5261      URL
45482SERVER-WEBAPP Cambium cnPilot r200/r201 directory traversal attempt (more info ...)web-application-attack  2017-5261      URL
45484MALWARE-OTHER Win.Ransomware.Samsam propagation via SMB transfer attempt (more info ...)trojan-activity        URL
45485MALWARE-OTHER Win.Ransomware.Samsam propagation via SMB2 transfer attempt (more info ...)trojan-activity        URL
45486MALWARE-OTHER Win.Ransomware.Samsam upload attempt (more info ...)trojan-activity        URL
45493SERVER-WEBAPP Seagate Personal Cloud getLogs.psp command injection attempt (more info ...)web-application-attack  2018-5347      URL
45494SERVER-WEBAPP Seagate Personal Cloud uploadTelemetry.psp command injection attempt (more info ...)web-application-attack  2018-5347      URL
45495SERVER-WEBAPP Seagate Personal Cloud getLogs.psp command injection attempt (more info ...)web-application-attack  2018-5347      URL
45496SERVER-WEBAPP Seagate Personal Cloud uploadTelemetry.psp command injection attempt (more info ...)web-application-attack  2018-5347      URL
45497SERVER-WEBAPP Cambium ePMP and cnPilot command execution attempt (more info ...)attempted-admin  2017-5259      URL
45498SERVER-WEBAPP Cambium ePMP and cnPilot command execution attempt (more info ...)attempted-admin  2017-5259      URL
45502FILE-OTHER TRUFFLEHUNTER TALOS-2018-0515 attack attempt (more info ...)attempted-user  2018-3835      URL
45503FILE-OTHER TRUFFLEHUNTER TALOS-2018-0515 attack attempt (more info ...)attempted-user  2018-3835      URL
45504FILE-OTHER TRUFFLEHUNTER TALOS-2018-0514 attack attempt (more info ...)attempted-user        URL
45505FILE-OTHER TRUFFLEHUNTER TALOS-2018-0514 attack attempt (more info ...)attempted-user        URL
45506FILE-PDF TRUFFLEHUNTER TALOS-2018-0517 attack attempt (more info ...)attempted-user  2018-4996      URL
45507FILE-PDF TRUFFLEHUNTER TALOS-2018-0517 attack attempt (more info ...)attempted-user  2018-4996      URL
45521FILE-PDF TRUFFLEHUNTER TALOS-2018-0518 attack attempt (more info ...)attempted-admin        URL
45522FILE-PDF TRUFFLEHUNTER TALOS-2018-0518 attack attempt (more info ...)attempted-admin        URL
45548FILE-EXECUTABLE Win.Trojan.CoinMiner attempted download (more info ...)trojan-activity        URL
45549PUA-OTHER XMRig cryptocurrency mining pool connection attempt (more info ...)policy-violation        URL
45550PUA-OTHER CPUMiner-Multi cryptocurrency mining pool connection attempt (more info ...)policy-violation        URL
45555SERVER-WEBAPP MikroTik RouterOS jsproxy readPostData memory corruption attempt (more info ...)attempted-admin        URL
45558FILE-OTHER Multiple products XML Import Command buffer overflow attempt (more info ...)attempted-user  2017-7310  97237    
45559FILE-OTHER Multiple products XML Import Command buffer overflow attempt (more info ...)attempted-user  2017-7310  97237    
45565MALWARE-OTHER Win.Trojan.Ursnif variant download attempt (more info ...)trojan-activity        URL
45592SERVER-WEBAPP Cambium cnPilot r200 and r201 configuration file download attempt (more info ...)web-application-attack  2017-5260      URL
45599FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0520 attack attempt (more info ...)attempted-user  2018-3838      URL
45600FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0520 attack attempt (more info ...)attempted-user  2018-3838      URL
45602FILE-OTHER TRUFFLEHUNTER TALOS-2018-0522 attack attempt (more info ...)attempted-dos        URL
45603FILE-OTHER TRUFFLEHUNTER TALOS-2018-0522 attack attempt (more info ...)attempted-dos        URL
45608FILE-PDF TRUFFLEHUNTER TALOS-2018-0525 attack attempt (more info ...)attempted-user  2018-3842      URL
45609FILE-PDF TRUFFLEHUNTER TALOS-2018-0525 attack attempt (more info ...)attempted-user  2018-3842      URL
45682SERVER-OTHER HP Integrated Lights-Out HTTP headers processing buffer overflow attempt (more info ...)attempted-admin  2017-12542  100467    URL
45697FILE-OTHER TRUFFLEHUNTER TALOS-2018-0530 attack attempt (more info ...)attempted-user  2018-3847      URL
45698FILE-OTHER TRUFFLEHUNTER TALOS-2018-0530 attack attempt (more info ...)attempted-user  2018-3847      URL
45699FILE-OTHER TRUFFLEHUNTER TALOS-2018-0530 attack attempt (more info ...)attempted-user  2018-3847      URL
45700FILE-OTHER TRUFFLEHUNTER TALOS-2018-0530 attack attempt (more info ...)attempted-user  2018-3847      URL
45701FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3849      URL
45702FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3849      URL
45703FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45704FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45705FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45706FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45707FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45708FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45709FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45710FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45711FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45712FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45713FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45714FILE-OTHER TRUFFLEHUNTER TALOS-2018-0529 attack attempt (more info ...)attempted-user  2018-3846      URL
45715FILE-PDF TRUFFLEHUNTER TALOS-2018-0532 attack attempt (more info ...)attempted-admin  2018-3850      URL
45716FILE-PDF TRUFFLEHUNTER TALOS-2018-0532 attack attempt (more info ...)attempted-admin  2018-3850      URL
45721SERVER-WEBAPP Ulterius web server directory traversal attempt (more info ...)web-application-attack  2017-16806      URL
45722SERVER-WEBAPP Ulterius web server directory traversal attempt (more info ...)web-application-attack  2017-16806      URL
45752FILE-OTHER TRUFFLEHUNTER TALOS-2018-0533 attack attempt (more info ...)attempted-user        URL
45753FILE-OTHER TRUFFLEHUNTER TALOS-2018-0533 attack attempt (more info ...)attempted-user        URL
45778SERVER-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-17485      URL
45779SERVER-OTHER Jackson databind deserialization remote code execution attempt (more info ...)attempted-user  2017-17485      URL
45782FILE-OTHER EMF EmrText object out of bounds read attempt (more info ...)attempted-user  2018-4883      URL
45783FILE-OTHER EMF EmrText object out of bounds read attempt (more info ...)attempted-user  2018-4883      URL
45804SERVER-OTHER Disk Savvy Enterprise buffer overflow attempt (more info ...)attempted-user        URL
45809INDICATOR-OBFUSCATION Coinhive cryptocurrency miner obfuscated detected (more info ...)misc-activity        
45810INDICATOR-OBFUSCATION Coinhive cryptocurrency miner obfuscated detected (more info ...)misc-activity        
45811FILE-OTHER EMF embedded image out of bound read attempt (more info ...)misc-activity  2018-4884      URL
45812FILE-OTHER EMF embedded image out of bound read attempt (more info ...)misc-activity  2018-4884      URL
45817MALWARE-OTHER Win.Ransomware.Thanatos ransomware inbound download attempt (more info ...)trojan-activity        URL
45818MALWARE-OTHER Win.Ransomware.Thanatos ransomware inbound download attempt (more info ...)trojan-activity        URL
45823FILE-PDF TRUFFLEHUNTER TALOS-2018-0536 attack attempt (more info ...)attempted-user  2018-3853      URL
45824FILE-PDF TRUFFLEHUNTER TALOS-2018-0536 attack attempt (more info ...)attempted-user  2018-3853      URL
45825PUA-OTHER XMR-Stak cryptocurrency mining pool connection attempt (more info ...)policy-violation        URL
45830SERVER-OTHER limited RSA ciphersuite list - possible Bleichenbacher SSL attack attempt (more info ...)attempted-recon  2017-6168      URL
45831MALWARE-TOOLS TLS-Attacker tool connection attempt - known SSL client random (more info ...)network-scan        URL
45837SERVER-ORACLE Oracle Application Test Suite server arbitrary JSP file upload attempt (more info ...)web-application-attack  2016-0491  81169    URL
45840SERVER-WEBAPP SERVER-WEBAPP Open WebMail userstat.pl command injection attempt (more info ...)web-application-attack    10316    
45841SERVER-WEBAPP SERVER-WEBAPP Open WebMail userstat.pl command injection attempt (more info ...)web-application-attack    10316    
45842SERVER-WEBAPP SERVER-WEBAPP Open WebMail userstat.pl command injection attempt (more info ...)web-application-attack    10316    
45843SERVER-WEBAPP SERVER-WEBAPP Open WebMail userstat.pl command injection attempt (more info ...)web-application-attack    10316    
45857SERVER-WEBAPP HPE Intelligent Management Center Platform /rptviewer/servlets/redirectviewer directory traversal attempt (more info ...)web-application-attack  2017-8983      URL
45858SERVER-WEBAPP HPE Intelligent Management Center Platform /rptviewer/servlets/redirectviewer directory traversal attempt (more info ...)web-application-attack  2017-8983      URL
45859SERVER-WEBAPP HPE Intelligent Management Center Platform /rptviewer/servlets/redirectviewer directory traversal attempt (more info ...)web-application-attack  2017-8983      URL
45872SERVER-WEBAPP Reliance SCADA directory traversal attempt (more info ...)web-application-attack        URL
45891SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0539 attack attempt (more info ...)web-application-attack  2018-3856      URL
45904MALWARE-BACKDOOR CobaltStrike inbound beacon download (more info ...)trojan-activity        URL
45905MALWARE-BACKDOOR CobaltStrike inbound beacon download (more info ...)trojan-activity        URL
45911SERVER-WEBAPP ManageEngine Applications Manager testCredential.do command injection attempt (more info ...)web-application-attack  2018-7890      URL
45912SERVER-WEBAPP ManageEngine Applications Manager testCredential.do command injection attempt (more info ...)web-application-attack  2018-7890      URL
45913SERVER-WEBAPP ManageEngine Applications Manager testCredential.do command injection attempt (more info ...)web-application-attack  2018-7890      URL
45922EXPLOIT-KIT Terror EK exe download attempt (more info ...)attempted-user        
45923EXPLOIT-KIT Terror EK dll download attempt (more info ...)attempted-user        
45925EXPLOIT-KIT Terror EK page access attempt (more info ...)attempted-user        
45926SERVER-OTHER Flexense Syncbreeze buffer overflow attempt (more info ...)attempted-user  2018-6537      
45927FILE-OTHER Sophos Tester Tool dll-load exploit attempt (more info ...)attempted-user  2018-6318      URL
45928FILE-OTHER Sophos Tester Tool dll-load exploit attempt (more info ...)attempted-user  2018-6318      URL
45935SERVER-OTHER Memcached set opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
45936SERVER-OTHER Memcached setq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
45937SERVER-OTHER Memcached add opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
45938SERVER-OTHER Memcached addq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
45939SERVER-OTHER Memcached replace opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
45940SERVER-OTHER Memcached replaceq opcode request heap buffer overflow attempt (more info ...)attempted-admin  2017-9951      URL
45949PUA-OTHER Coinhive TLS server hello attempt (more info ...)misc-attack        
45950PUA-OTHER Coinhive TLS client hello attempt (more info ...)misc-attack        
45951PUA-OTHER Authedmine TLS server hello attempt (more info ...)misc-attack        
45952PUA-OTHER Authedmine TLS client hello attempt (more info ...)misc-attack        
45955PUA-OTHER XMRMiner cryptocurrency mining pool connection attempt (more info ...)policy-violation        URL
45976SERVER-WEBAPP Pivotal Spring Data REST PATCH request remote code execution attempt (more info ...)web-application-attack  2017-8046      URL
45981FILE-OTHER TRUFFLEHUNTER TALOS-2018-0540 attack attempt (more info ...)attempted-user        URL
45982FILE-OTHER TRUFFLEHUNTER TALOS-2018-0540 attack attempt (more info ...)attempted-user        URL
45985FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0544 attack attempt (more info ...)attempted-user  2018-3860      URL
45986FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0544 attack attempt (more info ...)attempted-user  2018-3860      URL
45987FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0544 attack attempt (more info ...)attempted-user  2018-3860      URL
45988FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0544 attack attempt (more info ...)attempted-user  2018-3860      URL
45991FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0543 attack attempt (more info ...)attempted-user  2018-3859      URL
45992FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0543 attack attempt (more info ...)attempted-user  2018-3859      URL
45993FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0543 attack attempt (more info ...)attempted-user  2018-3859      URL
45994FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0543 attack attempt (more info ...)attempted-user  2018-3859      URL
45997FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0542 attack attempt (more info ...)attempted-user  2018-3862      URL
45998FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0542 attack attempt (more info ...)attempted-user  2018-3862      URL
45999FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0542 attack attempt (more info ...)attempted-user  2018-3862      URL
46000FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0542 attack attempt (more info ...)attempted-user  2018-3862      URL
46001FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0541 attack attempt (more info ...)attempted-user  2018-3857      URL
46002FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0541 attack attempt (more info ...)attempted-user  2018-3857      URL
46003FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46004FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46005FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46006FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46007FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46008FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46009FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46010FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46011FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46012FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46013FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46014FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46015FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46016FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46017FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46018FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46019FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46020FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46021FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46022FILE-OTHER TRUFFLEHUNTER SFVRT-1035 attack attempt (more info ...)attempted-admin        
46079SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0548 attack attempt (more info ...)attempted-admin  2018-3866      URL
46091MALWARE-OTHER VBscript downloader detected (more info ...)trojan-activity        URL
46092MALWARE-OTHER VBscript downloader detected (more info ...)trojan-activity        URL
46130SERVER-OTHER cPanel Mailman privilege escalation attempt (more info ...)attempted-user        
46131SERVER-OTHER cPanel Mailman privilege escalation attempt (more info ...)attempted-user        
46142SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0551 attack attempt (more info ...)web-application-attack  2017-16349      URL
46149SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0554 attack attempt (more info ...)attempted-admin  2018-3872      URL
46150SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0555 attack attempt (more info ...)attempted-admin  2018-3873      URL
46151SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0555 attack attempt (more info ...)attempted-admin  2018-3874      URL
46152SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0555 attack attempt (more info ...)attempted-admin  2018-3875      URL
46153SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0555 attack attempt (more info ...)attempted-admin  2018-3876      URL
46154SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0555 attack attempt (more info ...)attempted-admin  2018-3877      URL
46155SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0555 attack attempt (more info ...)attempted-admin  2018-3878      URL
46157SERVER-WEBAPP Oracle Hospitality Simphony MICROS directory traversal attempt (more info ...)web-application-attack  2018-2636      
46158SERVER-WEBAPP Oracle Hospitality Simphony MICROS directory traversal attempt (more info ...)web-application-attack  2018-2636      
46159SERVER-WEBAPP Oracle Hospitality Simphony MICROS directory traversal attempt (more info ...)web-application-attack  2018-2636      
46165SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0560 attack attempt (more info ...)web-application-attack  2018-3882      URL
46166SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0560 attack attempt (more info ...)web-application-attack  2018-3882      URL
46167SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0560 attack attempt (more info ...)web-application-attack  2018-3883      URL
46168SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0560 attack attempt (more info ...)web-application-attack  2018-3883      URL
46169SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0560 attack attempt (more info ...)web-application-attack  2018-3884      URL
46170SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0560 attack attempt (more info ...)web-application-attack  2018-3884      URL
46171SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0560 attack attempt (more info ...)web-application-attack  2018-3885      URL
46172SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0560 attack attempt (more info ...)web-application-attack  2018-3885      URL
46173FILE-OTHER TRUFFLEHUNTER TALOS-2018-0568 attack attempt (more info ...)attempted-dos        URL
46174FILE-OTHER TRUFFLEHUNTER TALOS-2018-0568 attack attempt (more info ...)attempted-dos        URL
46175SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0559 attack attempt (more info ...)web-application-attack  2018-3881      URL
46186FILE-OTHER TrueType Font Windows EOT font engine remote code execution attempt (more info ...)attempted-admin  2018-1016      URL
46187FILE-OTHER TrueType Font Windows EOT font engine remote code execution attempt (more info ...)attempted-admin  2018-1016      URL
46211SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0556 attack attempt (more info ...)web-application-attack  2018-3926      URL
46216SERVER-WEBAPP DIAEnergie credential request attempt (more info ...)attempted-admin        
46222FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0561 attack attempt (more info ...)attempted-user  2018-3886      URL
46223FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0561 attack attempt (more info ...)attempted-user  2018-3886      URL
46224FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0562 attack attempt (more info ...)attempted-user  2018-3887      URL
46225FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0562 attack attempt (more info ...)attempted-user  2018-3887      URL
46232SERVER-WEBAPP Mango Automation arbitrary JSP file upload attempt (more info ...)attempted-admin        
46237PUA-OTHER Cryptocurrency Miner outbound connection attempt (more info ...)policy-violation        URL
46241FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0564 attack attempt (more info ...)attempted-user  2018-3889      URL
46242FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0564 attack attempt (more info ...)attempted-user  2018-3889      URL
46273SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46274SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46275SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46276SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46277SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46278SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46279SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46280SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46281SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46282SERVER-SAMBA Samba spoolss denial of service attempt (more info ...)denial-of-service  2018-1050      URL
46288MALWARE-BACKDOOR JSP webshell transfer attempt (more info ...)trojan-activity        
46289MALWARE-BACKDOOR JSP webshell transfer attempt (more info ...)trojan-activity        
46290MALWARE-BACKDOOR JSP webshell backdoor detected (more info ...)trojan-activity        
46291MALWARE-BACKDOOR JSP webshell backdoor file management attempt (more info ...)trojan-activity        
46292FILE-PDF TRUFFLEHUNTER TALOS-2018-0569 attack attempt (more info ...)attempted-user        URL
46293FILE-PDF TRUFFLEHUNTER TALOS-2018-0569 attack attempt (more info ...)attempted-user        URL
46296SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0570 attack attempt (more info ...)attempted-admin  2018-3897      URL
46301SERVER-OTHER QNAP QTS X-Forwarded-For buffer overflow (more info ...)web-application-attack        URL
46303SERVER-WEBAPP Antsle antman authentication bypass attempt (more info ...)web-application-attack  2018-7739      
46305SERVER-WEBAPP QNAP WTS 4.2.1 command injection attempt (more info ...)web-application-attack        
46306SERVER-WEBAPP QNAP WTS 4.2.1 command injection attempt (more info ...)web-application-attack        
46307SERVER-WEBAPP QNAP WTS 4.2.1 command injection attempt (more info ...)web-application-attack        
46308SERVER-WEBAPP QNAP WTS 4.2.1 command injection attempt (more info ...)web-application-attack        
46309SERVER-OTHER QNAP NVR/NAS Heap/Stack Overflow attempt (more info ...)attempted-admin        
46310SERVER-OTHER QNAP NVR/NAS Heap/Stack Overflow attempt (more info ...)attempted-admin        
46316SERVER-WEBAPP Drupal 8 remote code execution attempt (more info ...)attempted-admin  2018-7600      URL
46319SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0573 attack attempt (more info ...)attempted-admin  2018-3905      URL
46321SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0574 attack attempt (more info ...)attempted-admin  2018-3904      URL
46322SERVER-WEBAPP Netgear DGN2200B stored cross-site scripting attempt (more info ...)attempted-user        URL
46323SERVER-WEBAPP Netgear DGN2200B stored cross-site scripting attempt (more info ...)attempted-user        URL
46329SERVER-WEBAPP SearchBlox unauthorized access attempt (more info ...)attempted-user  2015-7919      URL
46330SERVER-WEBAPP SearchBlox unauthorized access attempt (more info ...)attempted-user  2015-7919      URL
46331SERVER-WEBAPP SearchBlox unauthorized access attempt (more info ...)attempted-user  2015-7919      URL
46332SERVER-WEBAPP SearchBlox unauthorized access attempt (more info ...)attempted-user  2015-7919      URL
46348SERVER-WEBAPP NetIQ Access Manager Identity Server directory traversal attempt (more info ...)web-application-attack  2017-14803      
46349SERVER-WEBAPP NetIQ Access Manager Identity Server directory traversal attempt (more info ...)web-application-attack  2017-14803      
46350SERVER-WEBAPP NetIQ Access Manager Identity Server directory traversal attempt (more info ...)web-application-attack  2017-14803      
46365PUA-OTHER CoinHive Miner client detected (more info ...)misc-attack        URL
46366PUA-OTHER CryptoNight webassembly download attempt (more info ...)misc-attack        
46367FILE-IDENTIFY WebAssembly file download detected (more info ...)misc-attack        URL
46368MALWARE-BACKDOOR JSP Web shell upload attempt (more info ...)trojan-activity        URL
46369MALWARE-BACKDOOR JSP Web shell access attempt (more info ...)trojan-activity        URL
46370PUA-OTHER Moonify Miner client detected (more info ...)misc-attack        URL
46371PUA-OTHER Moonify TLS server hello attempt (more info ...)misc-attack        
46372PUA-OTHER Moonify TLS client hello attempt (more info ...)misc-attack        
46377SERVER-OTHER libgd heap-overflow attempt (more info ...)web-application-attack  2016-3074      
46388FILE-OTHER TRUFFLEHUNTER TALOS-2018-0579 attack attempt (more info ...)attempted-dos        URL
46389FILE-OTHER TRUFFLEHUNTER TALOS-2018-0579 attack attempt (more info ...)attempted-dos        URL
46393FILE-IDENTIFY WebAssembly file detected (more info ...)misc-attack        URL
46394FILE-IDENTIFY WebAssembly file attachment detected (more info ...)misc-activity        URL
46396FILE-EXECUTABLE Win.Ransomware.Rapid download attempt (more info ...)trojan-activity        URL
46397FILE-EXECUTABLE Win.Ransomware.Rapid download attempt (more info ...)trojan-activity        URL
46410PUA-OTHER Mineralt TLS client hello attempt (more info ...)misc-attack        
46411PUA-OTHER Mineralt TLS server hello attempt (more info ...)misc-attack        
46429OS-WINDOWS Total Meltdown side-channel information leak attempt (more info ...)attempted-admin  2018-1038      URL
46430OS-WINDOWS Total Meltdown side-channel information leak attempt (more info ...)attempted-admin  2018-1038      URL
46431OS-WINDOWS Total Meltdown side-channel information leak attempt (more info ...)attempted-admin  2018-1038      URL
46432OS-WINDOWS Total Meltdown side-channel information leak attempt (more info ...)attempted-admin  2018-1038      URL
46445SERVER-OTHER Oracle WebLogic unsafe deserialization remote code execution attempt detected (more info ...)attempted-user  2019-2890      URL
46446SERVER-OTHER Oracle Weblogic unsafe deserialization remote code execution attempt detected (more info ...)attempted-user  2018-3245      URL
46451SERVER-WEBAPP Drupal unsafe internal attribute remote code execution attempt (more info ...)attempted-user  2018-7602      URL
46452FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0586 attack attempt (more info ...)attempted-user  2018-3922      URL
46453FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0586 attack attempt (more info ...)attempted-user  2018-3922      URL
46455FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0587 attack attempt (more info ...)attempted-user  2018-3923      URL
46456FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0587 attack attempt (more info ...)attempted-user  2018-3923      URL
46457FILE-PDF TRUFFLEHUNTER TALOS-2018-0588 attack attempt (more info ...)attempted-user  2018-3924      URL
46458FILE-PDF TRUFFLEHUNTER TALOS-2018-0588 attack attempt (more info ...)attempted-user  2018-3924      URL
46459FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0585 attack attempt (more info ...)attempted-user  2018-3921      URL
46460FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0585 attack attempt (more info ...)attempted-user  2018-3921      URL
46466OS-WINDOWS Windows NTFS NtfsFindExistingLcb denial of service attempt (more info ...)denial-of-service        
46467OS-WINDOWS Windows NTFS NtfsFindExistingLcb denial of service attempt (more info ...)denial-of-service        
46473SERVER-OTHER Spring Data Commons remote code execution attempt (more info ...)attempted-user  2018-1273      
46474SERVER-OTHER Quest Appliance NetVault Backup buffer overflow attempt (more info ...)attempted-admin  2018-1161      
46486PUA-ADWARE Slimware Utilities variant outbound connection (more info ...)trojan-activity        URL
46509SERVER-WEBAPP Unitrends Enterprise Backup API command injection attempt (more info ...)web-application-attack  2018-6328      URL
46510SERVER-WEBAPP Belkin N750 F9K1103 wireless router command injection attempt (more info ...)web-application-attack  2018-1143      
46511SERVER-WEBAPP Belkin N750 F9K1103 wireless router command injection attempt (more info ...)web-application-attack  2018-1143      
46512SERVER-WEBAPP Belkin N750 F9K1103 wireless router command injection attempt (more info ...)web-application-attack  2018-1143      
46513SERVER-WEBAPP Belkin N750 F9K1103 wireless router command injection attempt (more info ...)web-application-attack  2018-1143      
46514SERVER-WEBAPP Belkin N750 F9K1103 wireless router command injection attempt (more info ...)web-application-attack  2018-1144      
46515SERVER-WEBAPP Belkin N750 F9K1103 wireless router command injection attempt (more info ...)web-application-attack  2018-1144      
46516SERVER-WEBAPP Belkin N750 F9K1103 wireless router command injection attempt (more info ...)web-application-attack  2018-1144      
46517SERVER-WEBAPP Belkin N750 F9K1103 wireless router command injection attempt (more info ...)web-application-attack  2018-1144      
46520SERVER-WEBAPP WebPort 1.16.2 directory traversal attempt (more info ...)web-application-attack        URL
46521SERVER-WEBAPP WebPort 1.16.2 directory traversal attempt (more info ...)web-application-attack        URL
46522SERVER-WEBAPP WebPort 1.16.2 directory traversal attempt (more info ...)web-application-attack        URL
46524SERVER-WEBAPP OpenEMR 5.0 directory traversal attempt (more info ...)web-application-attack        URL
46525SERVER-WEBAPP OpenEMR 5.0 directory traversal attempt (more info ...)web-application-attack        URL
46526SERVER-WEBAPP OpenEMR 5.0 directory traversal attempt (more info ...)web-application-attack        URL
46527SERVER-WEBAPP LibreEHR 2.0.0 directory traversal attempt (more info ...)web-application-attack        URL
46528SERVER-WEBAPP LibreEHR 2.0.0 directory traversal attempt (more info ...)web-application-attack        URL
46529SERVER-WEBAPP LibreEHR 2.0.0 directory traversal attempt (more info ...)web-application-attack        URL
46530SERVER-WEBAPP Dream Report ASPX file upload attempt (more info ...)web-application-attack        URL
46531SERVER-WEBAPP SearchBlox suspicious configuration upload attempt (more info ...)web-application-attack        URL
46532SERVER-WEBAPP SearchBlox suspicious configuration upload attempt (more info ...)web-application-attack        URL
46534SERVER-WEBAPP NetGear DGN2200B command injection attempt (more info ...)web-application-attack        URL
46535SERVER-WEBAPP NetGear DGN2200B command injection attempt (more info ...)web-application-attack        URL
46536SERVER-WEBAPP NetGear DGN2200B command injection attempt (more info ...)web-application-attack        URL
46537SERVER-WEBAPP NetGear DGN2200B command injection attempt (more info ...)web-application-attack        URL
46541FILE-OTHER TRUFFLEHUNTER TALOS-2018-0589 attack attempt (more info ...)attempted-dos        URL
46542FILE-OTHER TRUFFLEHUNTER TALOS-2018-0589 attack attempt (more info ...)attempted-dos        URL
46550FILE-PDF TRUFFLEHUNTER TALOS-2018-0590 attack attempt (more info ...)attempted-user  2018-12756      URL
46551FILE-PDF TRUFFLEHUNTER TALOS-2018-0590 attack attempt (more info ...)attempted-user  2018-12756      URL
46596OS-WINDOWS dxgkrnl.sys privilege escalation attempt (more info ...)attempted-admin  2018-8165      URL
46597OS-WINDOWS dxgkrnl.sys privilege escalation attempt (more info ...)attempted-admin  2018-8165      URL
46605SERVER-ORACLE Oracle Access Manager authentication bypass attempt (more info ...)attempted-admin  2018-2879      
46610SERVER-MAIL EHLO user overflow attempt (more info ...)attempted-admin  2019-16928  13772    
46620SERVER-WEBAPP SAP Internet Graphics Server image converter information leak attempt (more info ...)web-application-attack  2018-2395      URL
46621SERVER-WEBAPP SAP Internet Graphics Server image converter arbitrary file upload attempt (more info ...)web-application-attack  2018-2395      URL
46622SERVER-WEBAPP SAP Internet Graphics Server buffer overflow attempt (more info ...)attempted-user  2018-2396      
46623SERVER-WEBAPP SAP Internet Graphics Server buffer overflow attempt (more info ...)attempted-user  2018-2394      
46624SERVER-WEBAPP GPON Router authentication bypass and command injection attempt (more info ...)web-application-attack  2018-10562      URL
46625SERVER-WEBAPP GPON Router authentication bypass and command injection attempt (more info ...)web-application-attack  2018-10562      URL
46626SERVER-WEBAPP GPON Router authentication bypass and command injection attempt (more info ...)web-application-attack  2018-10562      URL
46627SERVER-WEBAPP GPON Router authentication bypass and command injection attempt (more info ...)web-application-attack  2018-10562      URL
46634FILE-PDF TRUFFLEHUNTER TALOS-2018-0592 attack attempt (more info ...)attempted-user        URL
46635FILE-PDF TRUFFLEHUNTER TALOS-2018-0592 attack attempt (more info ...)attempted-user        URL
46665SERVER-WEBAPP Digital Guardian Management Console arbitrary file upload attempt (more info ...)web-application-attack  2018-10173      
46666SERVER-WEBAPP Digital Guardian Management Console arbitrary file upload attempt (more info ...)web-application-attack  2018-10173      
46682SERVER-MAIL Multiple products email with crafted MIME parts direct exfiltration attempt (more info ...)attempted-recon        URL
46683SERVER-MAIL Multiple products email with crafted MIME parts direct exfiltration attempt (more info ...)attempted-recon        URL
46684SERVER-MAIL Multiple products email with crafted MIME parts direct exfiltration attempt (more info ...)attempted-recon        URL
46685SERVER-MAIL Multiple products email with crafted MIME parts direct exfiltration attempt (more info ...)attempted-recon        URL
46740SERVER-WEBAPP Kubernetes Kubelet arbitrary command execution attempt (more info ...)attempted-user  2018-0268      URL
46741SERVER-WEBAPP Kubernetes Kubelet arbitrary command execution attempt (more info ...)attempted-user  2018-0268      URL
46751MALWARE-OTHER Win.Ransomware.SynAck download attempt (more info ...)trojan-activity        URL
46752MALWARE-OTHER Win.Ransomware.SynAck download attempt (more info ...)trojan-activity        URL
46775SERVER-WEBAPP Nagios XI command injection attempt (more info ...)web-application-attack  2018-8734      
46776SERVER-WEBAPP Nagios XI command injection attempt (more info ...)web-application-attack  2018-8734      
46777SERVER-WEBAPP Nagios XI command injection attempt (more info ...)web-application-attack  2018-8734      
46778SERVER-WEBAPP Nagios XI command injection attempt (more info ...)web-application-attack  2018-8734      
46793OS-WINDOWS Malicious zip download attempt (more info ...)attempted-user        
46794OS-WINDOWS Malicious vbscript download attempt (more info ...)attempted-user        
46802SERVER-WEBAPP Anti-Web directory traversal attempt (more info ...)web-application-attack  2017-9097      
46803SERVER-WEBAPP Anti-Web directory traversal attempt (more info ...)web-application-attack  2017-9097      
46804SERVER-WEBAPP Anti-Web directory traversal attempt (more info ...)web-application-attack  2017-9097      
46805SERVER-WEBAPP BA Systems BAS Web information disclosure attempt (more info ...)attempted-user  2017-17974      
46806SERVER-WEBAPP BA Systems BAS Web information disclosure attempt (more info ...)attempted-user  2017-17974      
46817SERVER-WEBAPP FLIR Breakstream 2300 unauthenticated information disclosure attempt (more info ...)attempted-user  2018-3813      
46819MALWARE-OTHER Win.Ransomware.Satan payload download (more info ...)trojan-activity        URL
46823SERVER-WEBAPP Spring Security OAuth remote code execution attempt (more info ...)attempted-admin  2018-1260      
46840MALWARE-OTHER GPON exploit download attempt (more info ...)trojan-activity  2018-10561      URL
46841MALWARE-OTHER GPON exploit download attempt (more info ...)trojan-activity  2018-10561      URL
46849SERVER-WEBAPP IBM QRadar SIEM command injection attempt (more info ...)web-application-attack  2018-1418      URL
46850SERVER-WEBAPP IBM QRadar SIEM ForensicsAnalysisServlet authentication bypass attempt (more info ...)web-application-attack  2018-1418      URL
46851SERVER-WEBAPP IBM QRadar SIEM command injection attempt (more info ...)web-application-attack  2018-1418      URL
46852SERVER-WEBAPP IBM QRadar SIEM command injection attempt (more info ...)web-application-attack  2018-1418      URL
46854BROWSER-OTHER Electron nodeIntegration bypass exploit attempt (more info ...)attempted-user  2018-1000136      URL
46855BROWSER-OTHER Electron nodeIntegration bypass exploit attempt (more info ...)attempted-user  2018-1000136      URL
46858OS-OTHER TRUFFLEHUNTER TALOS-2018-0614 attack attempt (more info ...)attempted-admin        URL
46859OS-OTHER TRUFFLEHUNTER TALOS-2018-0614 attack attempt (more info ...)attempted-admin        URL
46864FILE-PDF TRUFFLEHUNTER TALOS-2018-0606 attack attempt (more info ...)attempted-user  2018-3997      URL
46865FILE-PDF TRUFFLEHUNTER TALOS-2018-0606 attack attempt (more info ...)attempted-user  2018-3997      URL
46867SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0604 attack attempt (more info ...)web-application-attack  2018-3937      URL
46868SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0604 attack attempt (more info ...)web-application-attack  2018-3937      URL
46869SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0604 attack attempt (more info ...)web-application-attack  2018-3937      URL
46874PUA-ADWARE Win.Pua.Softonic installer variant outbound connection (more info ...)trojan-activity        URL
46877SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0605 attack attempt (more info ...)attempted-admin  2018-3938      URL
46898SERVER-WEBAPP Atlassian OAuth plugin multiple versions server side request forgery attempt (more info ...)web-application-attack  2017-9506      URL
46921SERVER-WEBAPP Quest DR Series Disk Backup Login.pm command injection attempt (more info ...)web-application-attack  2018-11143      URL
46923SERVER-OTHER Mitsubishi Electric E-Designer Status_bit buffer overflow attempt (more info ...)attempted-admin  2017-9638      
46924SERVER-OTHER Mitsubishi Electric E-Designer Status_bit buffer overflow attempt (more info ...)attempted-admin  2017-9638      
46925SERVER-OTHER Mitsubishi Electric E-Designer font field buffer overflow attempt (more info ...)attempted-admin  2017-9638      
46926SERVER-OTHER Mitsubishi Electric E-Designer font field buffer overflow attempt (more info ...)attempted-admin  2017-9638      
46955OS-WINDOWS Windows 10 access control privilege escalation attempt (more info ...)attempted-admin  2018-1036      URL
46956OS-WINDOWS Windows 10 access control privilege escalation attempt (more info ...)attempted-admin  2018-1036      URL
46961OS-WINDOWS Windows Desktop Bridge privilege escalation attempt (more info ...)attempted-admin  2018-8214      URL
46962OS-WINDOWS Windows Desktop Bridge privilege escalation attempt (more info ...)attempted-admin  2018-8214      URL
46971SERVER-WEBAPP Quest DR Series Disk Backup UsersService.pm update method command injection attempt (more info ...)web-application-attack  2018-11144      URL
46972SERVER-WEBAPP Quest DR Series Disk Backup UsersService.pm update method command injection attempt (more info ...)web-application-attack  2018-11144      URL
46973SERVER-WEBAPP Quest DR Series Disk Backup UsersService.pm delete method command injection attempt (more info ...)web-application-attack  2018-11145      URL
46974SERVER-WEBAPP Quest DR Series Disk Backup UsersService.pm update_pw method command injection attempt (more info ...)web-application-attack  2018-11146      URL
46982SERVER-WEBAPP Quest DR Series Disk Backup SchedulesService.pm command injection attempt (more info ...)web-application-attack  2018-11150      URL
46986MALWARE-OTHER Win.Ransomware.Annabelle file download (more info ...)trojan-activity        URL
46987MALWARE-OTHER Win.Ransomware.Annabelle file download (more info ...)trojan-activity        URL
46988MALWARE-OTHER Win.Ransomware.MBRLock file download (more info ...)trojan-activity        URL
46989MALWARE-OTHER Win.Ransomware.MBRLock file download (more info ...)trojan-activity        URL
46990OS-OTHER Apple macOS and iOS fgetattrlist kernel heap overflow attempt (more info ...)attempted-admin  2018-4243      
46991OS-OTHER Apple macOS and iOS fgetattrlist kernel heap overflow attempt (more info ...)attempted-admin  2018-4243      
46997SERVER-WEBAPP XiongMai NVR login.htm buffer overflow attempt (more info ...)attempted-admin  2018-10088      URL
46999INDICATOR-COMPROMISE SettingContent-ms file type download attempt (more info ...)attempted-user  2018-8414      URL
47000INDICATOR-COMPROMISE SettingContent-ms file type download attempt (more info ...)attempted-user  2018-8414      URL
47001INDICATOR-COMPROMISE SettingContent-ms file type download attempt (more info ...)attempted-user  2018-8414      URL
47002INDICATOR-COMPROMISE SettingContent-ms file type download attempt (more info ...)attempted-user  2018-8414      URL
47017SERVER-WEBAPP Quest DR Series Disk Backup CompressionService.pm command injection attempt (more info ...)web-application-attack  2018-11152      URL
47020MALWARE-OTHER Portable Executable containing CoinHive download attempt (more info ...)policy-violation        URL
47021MALWARE-OTHER Portable Executable containing CoinHive download attempt (more info ...)policy-violation        URL
47022BROWSER-WEBKIT Apple WebKit memory corruption attempt (more info ...)attempted-user  2018-4233      URL
47023BROWSER-WEBKIT Apple WebKit memory corruption attempt (more info ...)attempted-user  2018-4233      URL
47028BROWSER-OTHER TRUFFLEHUNTER TALOS-2018-0621 attack attempt (more info ...)attempted-dos        URL
47029BROWSER-OTHER TRUFFLEHUNTER TALOS-2018-0621 attack attempt (more info ...)attempted-dos        URL
47031SERVER-WEBAPP Quest DR Series Disk Backup LicenseService.pm command injection attempt (more info ...)web-application-attack  2018-11155      URL
47037SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0619 attack attempt (more info ...)attempted-admin  2018-3950      URL
47039SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0618 attack attempt (more info ...)web-application-attack  2018-3949      URL
47040SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0618 attack attempt (more info ...)web-application-attack  2018-3949      URL
47049SERVER-WEBAPP CA Unified Infrastructure Management download_lar servelet directory traversal attempt (more info ...)web-application-attack  2016-5803      URL
47050SERVER-WEBAPP CA Unified Infrastructure Management download_lar servelet directory traversal attempt (more info ...)web-application-attack  2016-5803      URL
47062SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0620 attack attempt (more info ...)attempted-admin  2018-3951      URL
47074FILE-PDF TRUFFLEHUNTER TALOS-2018-0623 attack attempt (more info ...)attempted-user        URL
47075FILE-PDF TRUFFLEHUNTER TALOS-2018-0623 attack attempt (more info ...)attempted-user        URL
47077MALWARE-OTHER HTA script hidden window execution attempt (more info ...)trojan-activity        URL
47085SERVER-WEBAPP Advantech WebAccess authentication bypass attempt (more info ...)web-application-attack  2017-5152      URL
47104SERVER-WEBAPP LibreHealthIO LibreEHR directory traversal attempt (more info ...)web-application-attack        URL
47105SERVER-WEBAPP LibreHealthIO LibreEHR directory traversal attempt (more info ...)web-application-attack        URL
47106SERVER-WEBAPP LibreHealthIO LibreEHR directory traversal attempt (more info ...)web-application-attack        URL
47133SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0625 attack attempt (more info ...)web-application-attack  2018-3955      URL
47134SERVER-WEBAPP ZyXEL Armor Series Routers ozkerz command injection attempt (more info ...)web-application-attack        URL
47135SERVER-WEBAPP ZyXEL Armor Series Routers ozkerz command injection attempt (more info ...)web-application-attack        URL
47136SERVER-WEBAPP HP VAN SDN Controller uninstall action arbitrary command execution attempt (more info ...)attempted-admin        URL
47137SERVER-WEBAPP HP VAN SDN Controller default token authentication attempt (more info ...)attempted-admin        URL
47138SERVER-WEBAPP HP VAN SDN Controller default credentials authentication attempt (more info ...)attempted-admin        URL
47145SERVER-WEBAPP Quest DR Series Disk Backup EmailRelayHostService.pm command injection attempt (more info ...)web-application-attack  2018-11156      URL
47216SERVER-WEBAPP Quest DR Series Disk Backup StorageService.pm command injection attempt (more info ...)web-application-attack  2018-11158      URL
47234SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0627 attack attempt (more info ...)attempted-user  2018-3963      URL
47272OS-OTHER DHCPv6 flood denial of service attempt (more info ...)attempted-dos  2018-0372      URL
47273OS-OTHER DHCPv6 flood denial of service attempt (more info ...)attempted-dos  2018-0372      URL
47278MALWARE-OTHER Win.Ransomware.Gandcrab variant network share encryption attempt (more info ...)trojan-activity        URL
47326MALWARE-OTHER known malicious user-agent string - DanaBot (more info ...)trojan-activity        URL
47336FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0638 attack attempt (more info ...)attempted-user  2018-3976      URL
47337FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0638 attack attempt (more info ...)attempted-user  2018-3976      URL
47340FILE-PDF TRUFFLEHUNTER TALOS-2018-0639 attack attempt (more info ...)attempted-user        URL
47341FILE-PDF TRUFFLEHUNTER TALOS-2018-0639 attack attempt (more info ...)attempted-user        URL
47342SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0637 attack attempt (more info ...)attempted-admin  2018-3972      URL
47347SERVER-WEBAPP QNAP QCenter API account information disclosure attempt (more info ...)attempted-recon  2018-0706      URL
47348SERVER-WEBAPP QNAP QCenter API set_VM_passwd command injection attempt (more info ...)attempted-admin  2018-0707      URL
47349SERVER-WEBAPP QNAP QCenter API set_VM_passwd command injection attempt (more info ...)attempted-admin  2018-0707      URL
47358SERVER-WEBAPP CCTV-DVR command injection attempt (more info ...)attempted-admin        URL
47389SERVER-WEBAPP Oracle WebLogic Server arbitrary JSP file upload attempt (more info ...)attempted-admin  2018-2894  104763    URL
47390SERVER-WEBAPP Oracle WebLogic Server arbitrary JSP file upload attempt (more info ...)attempted-admin  2018-2894  104763    URL
47391SERVER-WEBAPP QNAP QCenter API set_VM_network command injection attempt (more info ...)web-application-attack  2018-0708      URL
47392SERVER-WEBAPP QNAP QCenter API set_VM_network command injection attempt (more info ...)web-application-attack  2018-0708      URL
47393SERVER-WEBAPP QNAP QCenter API command injection attempt (more info ...)attempted-admin  2018-0709      URL
47417PUA-ADWARE Slimware Utilities variant outbound connection (more info ...)trojan-activity        URL
47418PUA-ADWARE Slimware Utilities variant outbound connection (more info ...)trojan-activity        URL
47423SERVER-WEBAPP QNAP QCenter API date_config command injection attempt (more info ...)web-application-attack  2018-0709      URL
47428FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0645 attack attempt (more info ...)attempted-user  2018-3977      URL
47429FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0645 attack attempt (more info ...)attempted-user  2018-3977      URL
47437SERVER-WEBAPP Weblog Expert Web Server denial of service attempt (more info ...)web-application-attack  2018-7582      
47440FILE-OTHER InPage reader remote code execution attemptt (more info ...)attempted-user  2017-12824      
47441FILE-OTHER InPage reader remote code execution attemptt (more info ...)attempted-user  2017-12824      
47453MALWARE-OTHER Win.Trojan.Gorgon attempted download (more info ...)trojan-activity        URL
47454MALWARE-OTHER Win.Trojan.Gorgon attempted download (more info ...)trojan-activity        URL
47458SERVER-WEBAPP Multiple products command injection attempt (more info ...)web-application-attack  2023-27076      
47459SERVER-WEBAPP Multiple products command injection attempt (more info ...)web-application-attack  2023-27076      
47460SERVER-WEBAPP Multiple products command injection attempt (more info ...)web-application-attack  2023-27076      
47470SERVER-WEBAPP HomeMatic CCU2 remote arbitrary code execution attempt (more info ...)attempted-user  2018-7297      
47506SERVER-WEBAPP Sitecore CMS default.aspx directory traversal attempt (more info ...)web-application-attack  2018-7669      URL
47507SERVER-WEBAPP Sitecore CMS default.aspx directory traversal attempt (more info ...)web-application-attack  2018-7669      URL
47508SERVER-WEBAPP Sitecore CMS default.aspx directory traversal attempt (more info ...)web-application-attack  2018-7669      URL
47514SERVER-WEBAPP Quest NetVault Backup Server checksession authentication bypass attempt (more info ...)web-application-attack  2018-1163      
47535PUA-ADWARE Magic Downloader BHO variant outbound connection (more info ...)trojan-activity        URL
47536PUA-ADWARE Magic Downloader BHO variant outbound connection (more info ...)trojan-activity        URL
47542SERVER-WEBAPP Quest DR Series Disk Backup StorageGroupService.pm command injection attempt (more info ...)web-application-attack  2018-11160      URL
47545SERVER-WEBAPP MicroFocus Secure Messaging Gateway command injection attempt (more info ...)web-application-attack  2018-12465      URL
47558SERVER-WEBAPP Advantech WebAccess CertUpdate directory traversal attempt (more info ...)web-application-attack  2018-5445  102781    URL
47559SERVER-WEBAPP Advantech WebAccess CertUpdate directory traversal attempt (more info ...)web-application-attack  2018-5445  102781    URL
47560SERVER-WEBAPP Advantech WebAccess CertUpdate directory traversal attempt (more info ...)web-application-attack  2018-5445  102781    URL
47561SERVER-WEBAPP Schneider Electric U.motion Builder directory traversal attempt (more info ...)web-application-attack  2018-7787  104447    
47562SERVER-WEBAPP Schneider Electric U.motion Builder directory traversal attempt (more info ...)web-application-attack  2018-7787  104447    
47563SERVER-WEBAPP Schneider Electric U.motion Builder directory traversal attempt (more info ...)web-application-attack  2018-7787  104447    
47595OS-OTHER Intel x86 L1 data cache side-channel analysis information leak attempt (more info ...)attempted-recon  2018-3646      
47596OS-OTHER Intel x86 L1 data cache side-channel analysis information leak attempt (more info ...)attempted-recon  2018-3646      
47597OS-OTHER Intel x86 L1 data cache side-channel analysis information leak attempt (more info ...)attempted-recon  2018-3646      
47598OS-OTHER Intel x86 L1 data cache side-channel analysis information leak attempt (more info ...)attempted-recon  2018-3646      
47599SERVER-WEBAPP GitList searchTree git grep arbitrary command execution attempt (more info ...)attempted-user        
47604PROTOCOL-SCADA Rockwell Automation Allen-Bradley MicroLogix controller buffer overflow attempt (more info ...)attempted-dos  2017-16740  102474    URL
47605SERVER-WEBAPP Joomla Gridbox app cross site scripting attempt (more info ...)attempted-user  2018-11690      
47606SERVER-WEBAPP Quest DR Series Disk Backup DiagnosticsService.pm command injection attempt (more info ...)web-application-attack  2018-11165      URL
47613SERVER-WEBAPP Joomla Proclaim biblestudy backup access attempt (more info ...)attempted-recon        
47614SERVER-WEBAPP Quest DR Series Disk Backup ReplicationsService.pm command injection attempt (more info ...)web-application-attack  2018-11166      URL
47622SERVER-WEBAPP Piltz PASvisu denial of service attempt (more info ...)attempted-dos        URL
47632SERVER-WEBAPP Cogent DataHub arbitrary command execution attempt (more info ...)attempted-admin        URL
47641SERVER-WEBAPP IceWarp Mail Server directory traversal attempt (more info ...)web-application-attack  2015-1503      
47642SERVER-WEBAPP IceWarp Mail Server directory traversal attempt (more info ...)web-application-attack  2015-1503      
47643SERVER-WEBAPP IceWarp Mail Server directory traversal attempt (more info ...)web-application-attack  2015-1503      
47644SERVER-WEBAPP IceWarp Mail Server directory traversal attempt (more info ...)web-application-attack  2015-1503      
47645SERVER-WEBAPP IceWarp Mail Server directory traversal attempt (more info ...)web-application-attack  2015-1503      
47646SERVER-WEBAPP IceWarp Mail Server directory traversal attempt (more info ...)web-application-attack  2015-1503      
47651INDICATOR-COMPROMISE SettingContent-ms file type download attempt (more info ...)attempted-user  2018-8414      URL
47652INDICATOR-COMPROMISE SettingContent-ms file type download attempt (more info ...)attempted-user  2018-8414      URL
47653INDICATOR-COMPROMISE SettingContent-ms file type download attempt (more info ...)attempted-user  2018-8414      URL
47654INDICATOR-COMPROMISE SettingContent-ms file type download attempt (more info ...)attempted-user  2018-8414      URL
47664SERVER-WEBAPP Dicoogle directory traversal attempt (more info ...)web-application-attack        URL
47665SERVER-WEBAPP ASUS RP-AC52 SetAVTransportURI SOAP action command injection attempt (more info ...)attempted-admin        URL
47671SERVER-WEBAPP Quest DR Series Disk Backup EmailAlertsService.pm command injection attempt (more info ...)web-application-attack  2018-11174      URL
47673SERVER-WEBAPP Quest DR Series Disk Backup NetworkInterfaceService.pm command injection attempt (more info ...)web-application-attack  2018-11175      URL
47674SERVER-WEBAPP Quest DR Series Disk Backup EncryptionService.pm command injection attempt (more info ...)web-application-attack  2018-11177      URL
47684SERVER-OTHER Mikrotik RouterOS directory traversal attempt (more info ...)attempted-user  2018-14847      
47712SERVER-WEBAPP Quest DR Series Disk Backup CloudPortalService.pm command injection attempt (more info ...)web-application-attack  2018-11180      URL
47716SERVER-WEBAPP HP Client Automation Server directory traversal attempt (more info ...)web-application-attack        URL
47721FILE-OTHER TRUFFLEHUNTER TALOS-2018-0670 attack attempt (more info ...)attempted-user  2019-7358      URL
47722FILE-OTHER TRUFFLEHUNTER TALOS-2018-0670 attack attempt (more info ...)attempted-user  2019-7358      URL
47727FILE-PDF TRUFFLEHUNTER TALOS-2018-0662 attack attempt (more info ...)attempted-user  2018-3994      URL
47728FILE-PDF TRUFFLEHUNTER TALOS-2018-0662 attack attempt (more info ...)attempted-user  2018-3994      URL
47729SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0659 attack attempt (more info ...)attempted-admin  2018-3991      URL
47744SERVER-WEBAPP Quest DR Series Disk Backup CustomerPortalService.pm command injection attempt (more info ...)web-application-attack  2018-11182      URL
47750FILE-OTHER TRUFFLEHUNTER TALOS-2018-0657 attack attempt (more info ...)attempted-admin  2018-3990      URL
47751FILE-OTHER TRUFFLEHUNTER TALOS-2018-0657 attack attempt (more info ...)attempted-admin  2018-3990      URL
47798SERVER-WEBAPP Trend Micro Email Encryption Gateway XML external entity injection attempt (more info ...)web-application-attack  2018-6225      
47801FILE-OTHER TRUFFLEHUNTER TALOS-2018-0673 attack attempt (more info ...)attempted-admin  2018-4005      URL
47802FILE-OTHER TRUFFLEHUNTER TALOS-2018-0673 attack attempt (more info ...)attempted-admin  2018-4005      URL
47803FILE-OTHER TRUFFLEHUNTER TALOS-2018-0675 attack attempt (more info ...)attempted-admin  2018-4008      URL
47804FILE-OTHER TRUFFLEHUNTER TALOS-2018-0675 attack attempt (more info ...)attempted-admin  2018-4008      URL
47810SERVER-WEBAPP Oracle Glassfish unauthenticated directory traversal attempt (more info ...)web-application-attack  2017-1000028      URL
47812SERVER-WEBAPP CloudByte ElastiStor imageUploadServlet arbitrary JSP file upload attempt (more info ...)attempted-admin  2018-15675      URL
47813SERVER-WEBAPP CloudByte ElastiStor imageUploadServlet directory traversal attempt (more info ...)web-application-attack  2018-15675      URL
47814SERVER-WEBAPP CloudByte ElastiStor imageUploadServlet directory traversal attempt (more info ...)web-application-attack  2018-15675      URL
47815SERVER-WEBAPP CloudByte ElastiStor LicenseServlet directory traversal attempt (more info ...)web-application-attack  2018-15675      URL
47816SERVER-WEBAPP CloudByte ElastiStor LicenseServlet arbitrary JSP file upload attempt (more info ...)attempted-admin  2018-15675      URL
47829SERVER-OTHER JBoss Richfaces expression language injection attempt (more info ...)attempted-user  2018-12532      URL
47840FILE-OTHER TRUFFLEHUNTER TALOS-2018-0680 attack attempt (more info ...)attempted-user        URL
47841FILE-OTHER TRUFFLEHUNTER TALOS-2018-0680 attack attempt (more info ...)attempted-user        URL
47844MALWARE-OTHER Win.Downloader.DDECmdExec variant download (more info ...)trojan-activity        URL
47845MALWARE-OTHER Win.Downloader.DDECmdExec variant download (more info ...)trojan-activity        URL
47846MALWARE-OTHER Win.Downloader.DDECmdExec variant download (more info ...)trojan-activity        URL
47847MALWARE-OTHER Win.Downloader.DDECmdExec variant download (more info ...)trojan-activity        URL
47848MALWARE-OTHER Win.Downloader.DDECmdExec variant download (more info ...)trojan-activity        URL
47849MALWARE-OTHER Win.Downloader.DDECmdExec variant download (more info ...)trojan-activity        URL
47861SERVER-WEBAPP Opsview Web Management Console testnotification command injection attempt (more info ...)web-application-attack  2018-16146      URL
47863SERVER-WEBAPP Opsview Web Management Console test_rancid_connection command injection attempt (more info ...)web-application-attack  2018-16144      URL
47864SERVER-WEBAPP Opsview Web Management Console test_rancid_connection command injection attempt (more info ...)web-application-attack  2018-16144      URL
47865SERVER-WEBAPP Opsview Web Management Console test_rancid_connection command injection attempt (more info ...)web-application-attack  2018-16144      URL
47866MALWARE-OTHER Html.Dropper.Xbash variant obfuscated powershell invocation (more info ...)trojan-activity        URL
47867MALWARE-OTHER Html.Dropper.Xbash variant obfuscated powershell invocation (more info ...)trojan-activity        URL
47868MALWARE-OTHER Img.Trojan.Xbash variant PNG file with an embedded Windows executable (more info ...)trojan-activity        URL
47869MALWARE-OTHER Img.Trojan.Xbash variant PNG file with an embedded Windows executable (more info ...)trojan-activity        URL
47913POLICY-OTHER Magecart redirect page detected (more info ...)policy-violation        
47914POLICY-OTHER Magecart js page injection attempt (more info ...)policy-violation        
47915POLICY-OTHER Magecart js page injection attempt (more info ...)policy-violation        
47917FILE-OTHER TRUFFLEHUNTER TALOS-2018-0682 attack attempt (more info ...)attempted-user        URL
47918FILE-OTHER TRUFFLEHUNTER TALOS-2018-0682 attack attempt (more info ...)attempted-user        URL
48038SERVER-OTHER Western Digital My Cloud authentication bypass attempt (more info ...)attempted-admin  2018-17153      
48064SERVER-WEBAPP WP plugin Localize My Post directory traversal attempt (more info ...)web-application-attack  2018-16299      URL
48065SERVER-WEBAPP WP plugin Localize My Post directory traversal attempt (more info ...)web-application-attack  2018-16299      URL
48066SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0685 attack attempt (more info ...)attempted-admin  2018-4014      URL
48067SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0684 attack attempt (more info ...)attempted-admin  2018-4013      URL
48068SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0684 attack attempt (more info ...)attempted-admin  2018-4013      URL
48069SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0689 attack attempt (more info ...)attempted-admin  2018-4018      URL
48070SERVER-WEBAPP WP plugin Wechat Broadcast directory traversal attempt (more info ...)web-application-attack  2018-16283      URL
48071SERVER-WEBAPP WP plugin Wechat Broadcast remote file inclusion attempt (more info ...)web-application-attack  2018-16283      URL
48076PUA-ADWARE Win.Adware.Wajam variant outbound connection (more info ...)trojan-activity        URL
48077PUA-ADWARE Win.Adware.Wajam variant outbound connection (more info ...)trojan-activity        URL
48078PUA-ADWARE Win.Adware.OneSystemCare download attempt (more info ...)trojan-activity        URL
48097SERVER-WEBAPP D-Link DIR-816 syslogIp command injection attempt (more info ...)web-application-attack  2018-17064      URL
48098SERVER-WEBAPP D-Link DIR-816 syslogIp command injection attempt (more info ...)web-application-attack  2018-17064      URL
48099SERVER-WEBAPP D-Link DIR-816 syslogIp command injection attempt (more info ...)web-application-attack  2018-17064      URL
48105FILE-MULTIMEDIA libvorbis VORBIS audio data out of bounds write attempt (more info ...)attempted-user  2018-5146      
48106FILE-MULTIMEDIA libvorbis VORBIS audio data out of bounds write attempt (more info ...)attempted-user  2018-5146      
48110FILE-PDF Foxit Reader uninitialized pointer leak attempt (more info ...)attempted-user  2018-9948      
48111FILE-PDF Foxit Reader text annotations use after free attempt (more info ...)attempted-user  2018-9958      
48112FILE-PDF Foxit Reader uninitialized pointer leak attempt (more info ...)attempted-user  2018-9958      
48113FILE-PDF Foxit Reader text annotations use after free attempt (more info ...)attempted-user  2018-9958      
48141SERVER-WEBAPP D-Link DIR-816 diagnosis command injection attempt (more info ...)web-application-attack  2018-17068      URL
48142SERVER-WEBAPP D-Link DIR-816 diagnosis command injection attempt (more info ...)web-application-attack  2018-17068      URL
48143SERVER-WEBAPP D-Link DIR-816 diagnosis command injection attempt (more info ...)web-application-attack  2018-17068      URL
48159FILE-OTHER WECON LeviStudio UMP file stack buffer overflow attempt (more info ...)attempted-user  2018-10602      
48164SERVER-WEBAPP HPE Intelligent Management Center FileDownloadServlet directory traversal attempt (more info ...)web-application-attack  2017-5795      
48178SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0690 attack attempt (more info ...)web-application-attack  2018-4021      URL
48179SERVER-OTHER HPE Intelligent Management Center imcwlandm stack buffer overflow attempt (more info ...)attempted-admin  2017-5805      
48180SERVER-OTHER HPE Intelligent Management Center imcwlandm stack buffer overflow attempt (more info ...)attempted-admin  2017-5805      
48181SERVER-OTHER HPE Intelligent Management Center imcwlandm stack buffer overflow attempt (more info ...)attempted-admin  2017-5805      
48182SERVER-OTHER HPE Intelligent Management Center imcwlandm stack buffer overflow attempt (more info ...)attempted-admin  2017-5805      
48183SERVER-OTHER HPE Intelligent Management Center imcwlandm stack buffer overflow attempt (more info ...)attempted-admin  2017-5805      
48184SERVER-OTHER HPE Intelligent Management Center imcwlandm stack buffer overflow attempt (more info ...)attempted-admin  2017-5805      
48185SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-admin  2017-5806      
48186SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-admin  2017-5806      
48187SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-admin  2017-5806      
48188SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-admin  2017-5806      
48189SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-admin  2017-5806      
48190SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-admin  2017-5806      
48206SERVER-WEBAPP Netgear WNAP devices boardData command injection attempt (more info ...)web-application-attack  2016-1555      URL
48207SERVER-WEBAPP Netgear WNAP devices boardData command injection attempt (more info ...)web-application-attack  2016-1555      URL
48208SERVER-WEBAPP Netgear WNAP devices boardData command injection attempt (more info ...)web-application-attack  2016-1555      URL
48235SERVER-OTHER NUUO NVRMini2 stack based buffer overflow attempt (more info ...)attempted-admin  2018-1149      URL
48247FILE-PDF Foxit Reader TypedArray uninitialized memory disclosure attempt (more info ...)attempted-user        
48248FILE-PDF Foxit Reader TypedArray uninitialized memory disclosure attempt (more info ...)attempted-user        
48256SERVER-WEBAPP Rubedo CMS Directory Traversal Attempt directory traversal attempt (more info ...)web-application-attack  2018-16836      URL
48257SERVER-WEBAPP Imperva SecureSphere command injection attempt (more info ...)web-application-attack        URL
48273SERVER-WEBAPP Cockpit CMS media API directory traversal attempt (more info ...)web-application-attack  2018-15540      URL
48274SERVER-WEBAPP Cockpit CMS media API directory traversal attempt (more info ...)web-application-attack  2018-15540      URL
48297FILE-OTHER TRUFFLEHUNTER TALOS-2018-0705 attack attempt (more info ...)attempted-admin  2019-5011      URL
48298FILE-OTHER TRUFFLEHUNTER TALOS-2018-0705 attack attempt (more info ...)attempted-admin  2019-5011      URL
48303INDICATOR-OBFUSCATION RTF file objdata hex-escape obfuscation attempt (more info ...)attempted-user        
48304INDICATOR-OBFUSCATION RTF file objdata hex-escape obfuscation attempt (more info ...)attempted-user        
48305INDICATOR-OBFUSCATION RTF file objdata hlsrc obfuscation attempt (more info ...)attempted-user        
48306INDICATOR-OBFUSCATION RTF file objdata hlsrc obfuscation attempt (more info ...)attempted-user        
48380SERVER-WEBAPP Quest DR Series Disk Backup SupportPortalService.pm command injection attempt (more info ...)web-application-attack  2018-11185      URL
48411SERVER-WEBAPP ManageEngine Firewall Analyzer oputilsServlet unauthorized API key disclosure attempt (more info ...)attempted-recon  2018-17283      URL
48418FILE-PDF TRUFFLEHUNTER TALOS-2018-0714 attack attempt (more info ...)attempted-user        URL
48419FILE-PDF TRUFFLEHUNTER TALOS-2018-0714 attack attempt (more info ...)attempted-user        URL
48420MALWARE-OTHER Win.Trojan.Bondupdater payload delivery attempt (more info ...)trojan-activity        URL
48421MALWARE-OTHER Win.Trojan.Bondupdater payload delivery attempt (more info ...)trojan-activity        URL
48427SERVER-WEBAPP Quest DR Series Disk Backup DateTimeService.pm command injection attempt (more info ...)web-application-attack  2018-11186      URL
48428SERVER-WEBAPP Quest DR Series Disk Backup GlobalViewService.pm command injection attempt (more info ...)web-application-attack  2018-11188      URL
48433FILE-OTHER TRUFFLEHUNTER TALOS-2018-0724 attack attempt (more info ...)attempted-admin  2018-4053      URL
48434FILE-OTHER TRUFFLEHUNTER TALOS-2018-0724 attack attempt (more info ...)attempted-admin  2018-4053      URL
48440EXPLOIT-KIT Qadars exploit kit attempt (more info ...)web-application-attack        
48456SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0730 attack attempt (more info ...)web-application-attack  2018-4056      URL
48457SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0730 attack attempt (more info ...)web-application-attack  2018-4056      URL
48459BROWSER-IE TRUFFLEHUNTER TALOS-2018-0734 attack attempt (more info ...)attempted-user        URL
48460BROWSER-IE TRUFFLEHUNTER TALOS-2018-0734 attack attempt (more info ...)attempted-user        URL
48468MALWARE-OTHER Win.Trojan.tRat variant inbound payload attempt (more info ...)trojan-activity        URL
48469MALWARE-OTHER Win.Trojan.tRat variant inbound payload attempt (more info ...)trojan-activity        URL
48481SERVER-OTHER Oracle WebLogic remote code execution attempt (more info ...)attempted-user  2018-3191      URL
48482SERVER-OTHER Oracle WebLogic remote code execution attempt (more info ...)attempted-user  2018-3191      URL
48483SERVER-OTHER Oracle WebLogic remote code execution attempt (more info ...)attempted-user  2018-3191      URL
48500SERVER-OTHER Kubernetes API Server bypass attempt (more info ...)attempted-admin  2018-1002105      URL
48501MALWARE-TOOLS Win.Tool.Delete variant download detected (more info ...)attempted-user        URL
48502MALWARE-TOOLS Win.Tool.Delete variant download detected (more info ...)attempted-user        URL
48522PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2018-0738 attack attempt (more info ...)attempted-dos        URL
48523PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2018-0738 attack attempt (more info ...)attempted-dos        URL
48524PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2018-0735 attack attempt (more info ...)attempted-dos        URL
48525PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2018-0741 attack attempt (more info ...)attempted-user        URL
48529BROWSER-OTHER TRUFFLEHUNTER TALOS-2018-0744 attack attempt (more info ...)attempted-user  2018-4060      URL
48530BROWSER-OTHER TRUFFLEHUNTER TALOS-2018-0744 attack attempt (more info ...)attempted-user  2018-4060      URL
48545SERVER-OTHER LSIS XP-Manager denial of service attempt (more info ...)attempted-dos        
48546BROWSER-WEBKIT WebKit RegEx engine optimization arbitrary code execution attempt (more info ...)attempted-user        URL
48547BROWSER-WEBKIT WebKit RegEx engine optimization arbitrary code execution attempt (more info ...)attempted-user        URL
48548SERVER-OTHER Kubernetes API Server bypass attempt (more info ...)attempted-admin  2018-1002105      URL
48553FILE-IDENTIFY Omron CX-Supervisor project file file download request (more info ...)misc-activity        URL
48554FILE-IDENTIFY Omron CX-Supervisor project file file attachment detected (more info ...)misc-activity        URL
48555FILE-IDENTIFY Omron CX-Supervisor project file file attachment detected (more info ...)misc-activity        URL
48556FILE-IDENTIFY Omron CX-Supervisor project file file attachment detected (more info ...)misc-activity        URL
48557FILE-OTHER Omron CX-Supervisor malicious project file download attempt (more info ...)attempted-user        URL
48563SERVER-WEBAPP Pilz PASvisu arbitrary file upload attempt (more info ...)web-application-attack        
48574INDICATOR-COMPROMISE malicious jquery.js load attempt (more info ...)attempted-user        URL
48575INDICATOR-COMPROMISE malicious jquery.js load attempt (more info ...)attempted-user        URL
48593PROTOCOL-VOIP SIP over SCTP wildcard VIA address attempt (more info ...)attempted-dos  2018-15454      URL
48600SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0755 attack attempt (more info ...)attempted-recon  2018-4071      URL
48603SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0756 attack attempt (more info ...)attempted-user  2018-4073      URL
48614SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0752 attack attempt (more info ...)web-application-attack  2018-4067      URL
48615SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0748 attack attempt (more info ...)attempted-admin  2018-4063      URL
48616SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0748 attack attempt (more info ...)attempted-admin  2018-4063      URL
48617SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0746 attack attempt (more info ...)attempted-admin  2018-4061      URL
48619SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0750 attack attempt (more info ...)attempted-user  2018-4065      URL
48621SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0749 attack attempt (more info ...)attempted-user  2018-4064      URL
48638SERVER-WEBAPP ZyXEL Armor Series Routers photobak command injection attempt (more info ...)web-application-attack        URL
48639SERVER-WEBAPP ZyXEL Armor Series Routers photobak command injection attempt (more info ...)web-application-attack        URL
48689FILE-OTHER TRUFFLEHUNTER SFVRT-1038 attack attempt (more info ...)attempted-admin        
48690FILE-OTHER TRUFFLEHUNTER SFVRT-1038 attack attempt (more info ...)attempted-admin        
48691BROWSER-IE TRUFFLEHUNTER SFVRT-1039 attack attempt (more info ...)attempted-recon        
48692BROWSER-IE TRUFFLEHUNTER SFVRT-1039 attack attempt (more info ...)attempted-recon        
48715MALWARE-OTHER Js.Dropper.Ramnit payload drop attempt (more info ...)trojan-activity        URL
48716MALWARE-OTHER Js.Trojan.MagentoCore infected page detected (more info ...)trojan-activity        URL
48717MALWARE-OTHER Js.Trojan.MagentoCore infected page detected (more info ...)trojan-activity        URL
48718MALWARE-OTHER Win.Trojan.Occamy inbound payload attempt (more info ...)trojan-activity        URL
48719MALWARE-OTHER Js.Trojan.Coinminer variant infected page detected (more info ...)trojan-activity        URL
48720MALWARE-OTHER Js.Trojan.Coinminer variant infected page detected (more info ...)trojan-activity        URL
48735SERVER-WEBAPP MailCleaner managetracing searchAction command injection attempt (more info ...)web-application-attack  2018-20323      URL
48736SERVER-WEBAPP MailCleaner managetracing searchAction command injection attempt (more info ...)web-application-attack  2018-20323      URL
48737SERVER-WEBAPP MailCleaner managetracing searchAction command injection attempt (more info ...)web-application-attack  2018-20323      URL
48740SERVER-WEBAPP Tridium Niagara default administrator account login attempt (more info ...)attempted-admin  2017-16748      URL
48741MALWARE-OTHER Js.Trojan.Agent variant inbound payload attempt (more info ...)trojan-activity        URL
48742MALWARE-OTHER Js.Trojan.Agent variant inbound payload attempt (more info ...)trojan-activity        URL
48743MALWARE-OTHER Js.Trojan.Agent variant inbound payload attempt (more info ...)trojan-activity        URL
48747SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0751 attack attempt (more info ...)web-application-attack  2018-4066      URL
48784MALWARE-OTHER Win.Worm.Shamoon propagation via SMB2 transfer attempt (more info ...)trojan-activity        URL
48803MALWARE-OTHER samsam.exe file name detected (more info ...)trojan-activity        URL
48804MALWARE-OTHER Ransomware SamSam variant detected (more info ...)trojan-activity        URL
48805MALWARE-OTHER Ransomware SamSam variant detected (more info ...)trojan-activity        URL
48811MALWARE-OTHER SamSam associated file (more info ...)trojan-activity        URL
48812MALWARE-OTHER Ransomware SamSam variant detected (more info ...)trojan-activity        URL
48813MALWARE-OTHER Ransomware SamSam variant detected (more info ...)trojan-activity        URL
48814MALWARE-OTHER Ransomware SamSam variant detected (more info ...)trojan-activity        URL
48815SERVER-WEBAPP Kibana Console for Elasticsearch local file inclusion attempt (more info ...)web-application-attack  2018-17246      URL
48826SERVER-WEBAPP Delta Industrial Automation Robot DRAStudio directory traversal attempt (more info ...)web-application-attack        URL
48850FILE-OTHER TRUFFLEHUNTER TALOS-2019-0760 attack attempt (more info ...)attempted-admin  2019-5013      URL
48851FILE-OTHER TRUFFLEHUNTER TALOS-2019-0760 attack attempt (more info ...)attempted-admin  2019-5013      URL
48852FILE-OTHER TRUFFLEHUNTER TALOS-2019-0757 attack attempt (more info ...)attempted-dos        URL
48853FILE-OTHER TRUFFLEHUNTER TALOS-2019-0757 attack attempt (more info ...)attempted-dos        URL
48856MALWARE-OTHER Win.Trojan.L0rdix binary download attempt (more info ...)trojan-activity        URL
48869MALWARE-OTHER Js.Dropper.Agent variant inbound payload download (more info ...)trojan-activity        URL
48870MALWARE-OTHER Js.Dropper.Agent variant inbound payload download (more info ...)trojan-activity        URL
48871MALWARE-OTHER Win.Trojan.Mimikatz inbound payload download (more info ...)trojan-activity        URL
49042PUA-ADWARE Osx.Adware.FairyTail variant outbound connection detected (more info ...)trojan-activity        URL
49043PUA-ADWARE Osx.Adware.Genieo variant outbound connection detected (more info ...)trojan-activity        URL
49044PUA-ADWARE Osx.Adware.MacSearch variant outbound connection detected (more info ...)trojan-activity        URL
49045FILE-OTHER TRUFFLEHUNTER TALOS-2019-0762 attack attempt (more info ...)attempted-user        URL
49046FILE-OTHER TRUFFLEHUNTER TALOS-2019-0762 attack attempt (more info ...)attempted-user        URL
49070MALWARE-OTHER Win.Ransomware.Anatova variant detected (more info ...)trojan-activity        URL
49071MALWARE-OTHER Win.Ransomware.Anatova variant detected (more info ...)trojan-activity        URL
49072MALWARE-OTHER Win.Ransomware.Anatova variant network share encryption attempt (more info ...)trojan-activity        URL
49085FILE-OTHER Ghostscript PostScript remote code execution attempt (more info ...)attempted-user  2019-6116      
49086FILE-OTHER Ghostscript PostScript remote code execution attempt (more info ...)attempted-user  2019-6116      
49088FILE-OTHER TRUFFLEHUNTER TALOS-2019-0773 attack attempt (more info ...)attempted-admin  2019-5015      URL
49089FILE-OTHER TRUFFLEHUNTER TALOS-2019-0773 attack attempt (more info ...)attempted-admin  2019-5015      URL
49090SERVER-SAMBA Samba is_known_pipe arbitrary module load code execution attempt (more info ...)attempted-user  2017-7494      URL
49098SERVER-WEBAPP Joomla Easy Shop local file inclusion attempt (more info ...)web-application-attack        URL
49111PUA-OTHER XMRig cryptocurrency miner download attempt (more info ...)policy-violation        
49171OS-WINDOWS NTLM authentication relay attempt (more info ...)attempted-user  2018-8581      URL
49189FILE-PDF TRUFFLEHUNTER TALOS-2019-0778 attack attempt (more info ...)attempted-user        URL
49190FILE-PDF TRUFFLEHUNTER TALOS-2019-0778 attack attempt (more info ...)attempted-user        URL
49191SERVER-WEBAPP Dell EMC Virtual Appliance Manager undocumented credential use attempt (more info ...)attempted-user  2018-1216      
49194PUA-OTHER XMR-Stak cryptocurrency mining pool connection attempt (more info ...)policy-violation        URL
49195SERVER-OTHER Multiple products runc arbitrary code execution attempt (more info ...)attempted-admin  2019-5736      
49198SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0783 attack attempt (more info ...)web-application-attack  2019-5022      URL
49205FILE-OTHER TRUFFLEHUNTER TALOS-2019-0779 attack attempt (more info ...)attempted-user        URL
49206FILE-OTHER TRUFFLEHUNTER TALOS-2019-0779 attack attempt (more info ...)attempted-user        URL
49237FILE-OTHER TRUFFLEHUNTER TALOS-2019-0781 attack attempt (more info ...)attempted-dos  2019-5020      URL
49238FILE-OTHER TRUFFLEHUNTER TALOS-2019-0781 attack attempt (more info ...)attempted-dos  2019-5020      URL
49252SERVER-OTHER HP iNode Management Center iNodeMngChecker buffer overflow attempt (more info ...)attempted-user  2011-1867      
49282SERVER-WEBAPP Magecart inbound scan for vulnerable plugin attempt (more info ...)web-application-attack        
49289FILE-OTHER WinRAR ACE remote code execution attempt (more info ...)attempted-user  2018-20250      URL
49290FILE-OTHER WinRAR ACE remote code execution attempt (more info ...)attempted-user  2018-20250      URL
49362SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0787 attack attempt (more info ...)attempted-recon  2019-10323      URL
49363SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0786 attack attempt (more info ...)attempted-recon  2019-5025      URL
49418SERVER-WEBAPP Orange LiveBox unauthorized credentials access attempt (more info ...)attempted-recon  2018-20377      URL
49449SERVER-OTHER ASP webshell upload attempt (more info ...)attempted-user        URL
49450SERVER-OTHER CFM webshell upload attempt (more info ...)attempted-user        URL
49451SERVER-OTHER ASP webshell upload attempt (more info ...)attempted-user        URL
49452SERVER-OTHER Perl webshell upload attempt (more info ...)attempted-user        URL
49453SERVER-OTHER CFM webshell upload attempt (more info ...)attempted-user        URL
49454SERVER-OTHER CFM webshell upload attempt (more info ...)attempted-user        URL
49455SERVER-OTHER Perl webshell upload attempt (more info ...)attempted-user        URL
49459SERVER-OTHER Perl webshell upload attempt (more info ...)attempted-user        URL
49460SERVER-OTHER ASP webshell upload attempt (more info ...)attempted-user        URL
49486FILE-OTHER Snapd dirty_sock exploit download attempt (more info ...)attempted-user  2019-7304      URL
49487FILE-OTHER Snapd dirty_sock exploit download attempt (more info ...)attempted-user  2019-7304      URL
49488FILE-OTHER Snapd dirty_sock exploit download attempt (more info ...)attempted-user  2019-7304      URL
49489FILE-OTHER Snapd dirty_sock exploit download attempt (more info ...)attempted-user  2019-7304      URL
49498SERVER-WEBAPP Jenkins Groovy metaprogramming remote code execution attempt (more info ...)attempted-admin  2019-1003002      URL
49499SERVER-WEBAPP Jenkins Groovy metaprogramming remote code execution attempt (more info ...)attempted-admin  2019-1003002      URL
49502SERVER-WEBAPP Ruby on Rails render file directory traversal attempt (more info ...)web-application-attack  2019-5418      
49503SERVER-WEBAPP Ruby on Rails render file directory traversal attempt (more info ...)web-application-attack  2019-5418      
49522SERVER-WEBAPP Magecart infected page outbound request attempt (more info ...)web-application-attack        
49529INDICATOR-COMPROMISE Responder poisoner download attempt (more info ...)misc-attack        URL
49530INDICATOR-COMPROMISE Responder poisoner download attempt (more info ...)misc-attack        URL
49531INDICATOR-COMPROMISE Responder poisoner download attempt (more info ...)misc-attack        URL
49532INDICATOR-COMPROMISE Responder poisoner download attempt (more info ...)misc-attack        URL
49535MALWARE-OTHER Win.Ransomware.Yatron payload download attempt (more info ...)trojan-activity        URL
49536MALWARE-OTHER Win.Ransomware.Yatron payload download attempt (more info ...)trojan-activity        URL
49569MALWARE-OTHER PowerShell invocation with ExecutionPolicy Bypass attempt (more info ...)trojan-activity        URL
49598SERVER-WEBAPP Fiberhome AN5506-04-F RP2669 cross site scripting attempt (more info ...)attempted-user  2019-9556      URL
49620SERVER-WEBAPP Advantech WebAccess Dashboard directory traversal attempt (more info ...)web-application-attack  2018-15706      URL
49621SERVER-WEBAPP Advantech WebAccess Dashboard directory traversal attempt (more info ...)web-application-attack  2018-15706      URL
49622SERVER-WEBAPP Advantech WebAccess Dashboard directory traversal attempt (more info ...)web-application-attack  2018-15706      URL
49628OS-WINDOWS Huawei PCManager device driver privilege escalation attempt (more info ...)attempted-admin  2019-5242      
49629OS-WINDOWS Huawei PCManager device driver privilege escalation attempt (more info ...)attempted-admin  2019-5242      
49630OS-WINDOWS Huawei PCManager device driver privilege escalation attempt (more info ...)attempted-admin  2019-5242      
49631OS-WINDOWS Huawei PCManager device driver privilege escalation attempt (more info ...)attempted-admin  2019-5242      
49642SERVER-WEBAPP Multiple PACS Server directory traversal attempt (more info ...)web-application-attack        URL
49643SERVER-WEBAPP Multiple PACS Server directory traversal attempt (more info ...)web-application-attack        URL
49644SERVER-WEBAPP Multiple PACS Server directory traversal attempt (more info ...)web-application-attack        URL
49648FILE-PDF TRUFFLEHUNTER TALOS-2019-0793 attack attempt (more info ...)attempted-user  2019-5031      URL
49649FILE-PDF TRUFFLEHUNTER TALOS-2019-0793 attack attempt (more info ...)attempted-user  2019-5031      URL
49667SERVER-WEBAPP Flexpaper and Flowpaper command injection attempt (more info ...)web-application-attack  2018-11686      URL
49668SERVER-WEBAPP Flexpaper and Flowpaper deletion of configuration file attempt (more info ...)web-application-attack  2018-11686      URL
49669SERVER-WEBAPP Flexpaper and Flowpaper potential arbitrary file deletion attempt (more info ...)web-application-attack  2018-11686      URL
49670SERVER-OTHER Hashicorp Consul services API remote code execution attempt (more info ...)attempted-admin        URL
49671INDICATOR-COMPROMISE Script execution from TOR attempt (more info ...)attempted-admin        URL
49684FILE-PDF TRUFFLEHUNTER TALOS-2019-0796 attack attempt (more info ...)attempted-user        URL
49685FILE-PDF TRUFFLEHUNTER TALOS-2019-0796 attack attempt (more info ...)attempted-user        URL
49690INDICATOR-SHELLCODE KernelFuzzer system call 64 bit (more info ...)shellcode-detect        
49691INDICATOR-SHELLCODE KernelFuzzer system call 64 bit (more info ...)shellcode-detect        
49694OS-WINDOWS Windows CSRSS privilege escalation attempt (more info ...)attempted-admin  2019-0735      URL
49695OS-WINDOWS Windows CSRSS privilege escalation attempt (more info ...)attempted-admin  2019-0735      URL
49766MALWARE-OTHER Win.Ransomware.Cr1ptT0r download attempt (more info ...)trojan-activity        URL
49767MALWARE-OTHER Win.Ransomware.Cr1ptT0r download attempt (more info ...)trojan-activity        URL
49770MALWARE-OTHER Win.Trojan.Imminent variant download attempt (more info ...)trojan-activity        URL
49771MALWARE-OTHER Win.Trojan.Imminent variant download attempt (more info ...)trojan-activity        URL
49817SERVER-WEBAPP Trend Micro DDEI directory traversal attempt (more info ...)web-application-attack        
49818SERVER-WEBAPP Trend Micro DDEI directory traversal attempt (more info ...)web-application-attack        
49837SERVER-WEBAPP Tpshop remote file include attempt (more info ...)web-application-attack  2018-9919      URL
49838SERVER-WEBAPP Tpshop remote file include attempt (more info ...)web-application-attack  2018-9919      URL
49839SERVER-WEBAPP LG-Ericsson iPECS NMS 30M directory traversal attempt (more info ...)web-application-attack  2018-15138      URL
49840SERVER-WEBAPP LG-Ericsson iPECS NMS 30M directory traversal attempt (more info ...)web-application-attack  2018-15138      URL
49841SERVER-WEBAPP LG-Ericsson iPECS NMS 30M directory traversal attempt (more info ...)web-application-attack  2018-15138      URL
49842SERVER-WEBAPP LG-Ericsson iPECS NMS 30M directory traversal attempt (more info ...)web-application-attack  2018-15138      URL
49850FILE-OTHER TRUFFLEHUNTER TALOS-2019-0804 attack attempt (more info ...)attempted-user        URL
49851FILE-OTHER TRUFFLEHUNTER TALOS-2019-0804 attack attempt (more info ...)attempted-user        URL
49865FILE-OTHER Multiple Products XML external entity information disclosure attempt (more info ...)misc-attack  2019-9670      URL
49888MALWARE-OTHER Doc.Dropper.Emotet malicious dropper download attempt (more info ...)trojan-activity        URL
49889MALWARE-OTHER Doc.Dropper.Emotet malicious dropper download attempt (more info ...)trojan-activity        URL
49890SERVER-OTHER HP OpenView Storage Data Protector arbitrary command execution attempt (more info ...)attempted-admin  2014-2623      
49891SERVER-OTHER HP OpenView Storage Data Protector arbitrary command execution attempt (more info ...)attempted-admin  2014-2623      
49892SERVER-OTHER HP OpenView Storage Data Protector arbitrary command execution attempt (more info ...)attempted-admin  2014-2623      
49893SERVER-OTHER HP OpenView Storage Data Protector arbitrary command execution attempt (more info ...)attempted-admin  2014-2623      
49894FILE-OTHER TRUFFLEHUNTER TALOS-2019-0812 attack attempt (more info ...)attempted-user        URL
49895FILE-OTHER TRUFFLEHUNTER TALOS-2019-0812 attack attempt (more info ...)attempted-user        URL
49896FILE-OTHER TRUFFLEHUNTER TALOS-2019-0813 attack attempt (more info ...)attempted-user        URL
49897FILE-OTHER TRUFFLEHUNTER TALOS-2019-0813 attack attempt (more info ...)attempted-user        URL
49898SERVER-WEBAPP Zimbra SSRF privilege escalation attempt (more info ...)attempted-admin  2019-9621      URL
49899SERVER-WEBAPP Oracle Business Intelligence and XML Publisher XML external entity injection attempt (more info ...)web-application-attack  2019-2616      URL
49900BROWSER-PLUGINS HP OPOS driver stack buffer overflow attempt (more info ...)attempted-admin  2014-7891      
49901BROWSER-PLUGINS HP OPOS ToneIndicator stack buffer overflow attempt (more info ...)attempted-admin  2014-7890      
49902BROWSER-PLUGINS HP OPOS ToneIndicator stack buffer overflow attempt (more info ...)attempted-user  2014-7890      
49903BROWSER-PLUGINS HP OPOS ToneIndicator stack buffer overflow attempt (more info ...)attempted-user  2014-7890      
49906FILE-PDF TRUFFLEHUNTER TALOS-2019-0814 attack attempt (more info ...)attempted-user  2019-5045      URL
49907FILE-PDF TRUFFLEHUNTER TALOS-2019-0814 attack attempt (more info ...)attempted-user  2019-5045      URL
49908FILE-PDF TRUFFLEHUNTER TALOS-2019-0815 attack attempt (more info ...)attempted-user  2019-5046      URL
49909FILE-PDF TRUFFLEHUNTER TALOS-2019-0815 attack attempt (more info ...)attempted-user  2019-5046      URL
49912PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0811 attack attempt (more info ...)attempted-user  2019-5044      URL
49921SERVER-WEBAPP Rocket Servergraph Admin Center userRequest command injection attempt (more info ...)web-application-attack  2014-3915      
49922SERVER-WEBAPP Rocket Servergraph Admin Center userRequest command injection attempt (more info ...)web-application-attack  2014-3915      
49923SERVER-WEBAPP Rocket Servergraph Admin Center userRequest command injection attempt (more info ...)web-application-attack  2014-3915      
49924SERVER-WEBAPP Rocket Servergraph Admin Center tsmRequest command injection attempt (more info ...)web-application-attack  2014-3915      
49925SERVER-WEBAPP Rocket Servergraph Admin Center tsmRequest command injection attempt (more info ...)web-application-attack  2014-3915      
49926SERVER-WEBAPP Rocket Servergraph Admin Center tsmRequest command injection attempt (more info ...)web-application-attack  2014-3915      
49927BROWSER-PLUGINS HP OPOS Point of Sale Driver stack buffer overflow attempt (more info ...)attempted-user  2014-7891      
49933MALWARE-OTHER Xls.Dropper.RogueRobin file download attempt (more info ...)trojan-activity        URL
49934MALWARE-OTHER Xls.Dropper.RogueRobin file download attempt (more info ...)trojan-activity        URL
49935MALWARE-OTHER Win.Trojan.RogueRobin executable file download attempt (more info ...)trojan-activity        URL
49936MALWARE-OTHER Win.Trojan.RogueRobin executable file download attempt (more info ...)trojan-activity        URL
49942SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
49943SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
49944SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
49945SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-admin  2019-2725  97884    URL
49946SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-admin  2019-2725  97884    URL
49958MALWARE-OTHER Win.Ransomware.Clop download attempt (more info ...)attempted-user        URL
49959MALWARE-OTHER Win.Ransomware.Clop download attempt (more info ...)attempted-user        URL
49960MALWARE-OTHER Win.Ransomware.Clop download attempt (more info ...)attempted-user        URL
49961MALWARE-OTHER Win.Ransomware.Clop download attempt (more info ...)attempted-user        URL
49965SERVER-WEBAPP Atlassian confluence widget remote code execution attempt (more info ...)web-application-attack  2019-3396      
49966SERVER-WEBAPP Oracle Business Intelligence directory traversal attempt (more info ...)web-application-attack  2019-2588      URL
49967SERVER-WEBAPP Oracle Business Intelligence directory traversal attempt (more info ...)web-application-attack  2019-2588      URL
49980SERVER-OTHER SAP NetWeaver Gateway arbitrary code execution attempt (more info ...)attempted-user        URL
49981SERVER-OTHER SAP NetWeaver Gateway arbitrary code execution attempt (more info ...)attempted-user        URL
50001SERVER-OTHER SAP NetWeaver Gateway arbitrary command execution attempt (more info ...)attempted-user        URL
50002SERVER-OTHER SAP NetWeaver Gateway arbitrary command execution attempt (more info ...)attempted-user        URL
50003SERVER-OTHER SAP NetWeaver Message Server RFC server registration attempt (more info ...)attempted-user        URL
50014SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50015SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50016SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50017SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50018SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50019SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50020SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50021SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50022SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50023SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50024SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50025SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2725      URL
50033BROWSER-WEBKIT Apple WebKit updateReferencedText use-after-free attempt (more info ...)attempted-user  2018-4315      URL
50034BROWSER-WEBKIT Apple WebKit updateReferencedText use-after-free attempt (more info ...)attempted-user  2018-4315      URL
50041SERVER-WEBAPP Jenkins CI Server ASTTest code execution attempt (more info ...)attempted-user  2018-1000861      URL
50042MALWARE-OTHER Win.Dropper.Fareit variant binary download attempt (more info ...)trojan-activity        URL
50043MALWARE-OTHER Win.Dropper.Fareit variant binary download attempt (more info ...)trojan-activity        URL
50044MALWARE-OTHER Win.Dropper.FormBook variant binary download attempt (more info ...)trojan-activity        URL
50045MALWARE-OTHER Win.Dropper.FormBook variant binary download attempt (more info ...)trojan-activity        URL
50046MALWARE-OTHER Win.Trojan.GenKryptik variant binary download attempt (more info ...)trojan-activity        URL
50047MALWARE-OTHER Win.Trojan.GenKryptik variant binary download attempt (more info ...)trojan-activity        URL
50065MALWARE-OTHER Win.Ransomware.Robinhood variant file transfer attempt (more info ...)trojan-activity        URL
50066MALWARE-OTHER Win.Ransomware.Robinhood variant file transfer attempt (more info ...)trojan-activity        URL
50084OS-WINDOWS Windows Kernel Registry Virtualization privilege escalation attempt (more info ...)attempted-admin  2019-0881      URL
50085OS-WINDOWS Windows Kernel Registry Virtualization privilege escalation attempt (more info ...)attempted-admin  2019-0881      URL
50093INDICATOR-COMPROMISE Responder poisoner HTTP attack attempt (more info ...)misc-attack        URL
50094INDICATOR-COMPROMISE Responder poisoner HTTP attack attempt (more info ...)misc-attack        URL
50095INDICATOR-COMPROMISE Responder poisoner self-signed certificate attempt (more info ...)misc-attack        URL
50096INDICATOR-COMPROMISE Responder poisoner toolkit download attempt (more info ...)misc-attack        URL
50098INDICATOR-COMPROMISE Responder poisoner HTTP attack attempt (more info ...)misc-attack        URL
50099INDICATOR-COMPROMISE Responder poisoner HTTP attack attempt (more info ...)misc-attack        URL
50102INDICATOR-COMPROMISE Responder poisoner LDAP attack attempt (more info ...)misc-attack        URL
50103INDICATOR-COMPROMISE Responder poisoner SMB negotiation attack attempt (more info ...)misc-attack        URL
50104INDICATOR-COMPROMISE Responder poisoner SMB negotiation attack attempt (more info ...)misc-attack        URL
50105INDICATOR-COMPROMISE Responder poisoner SMB negotiation attack attempt (more info ...)misc-attack        URL
50106INDICATOR-COMPROMISE Responder poisoner SMB attack attempt (more info ...)misc-attack        URL
50112MALWARE-OTHER Win.Ransomware.Agent ransom note transfer over SMB (more info ...)trojan-activity        URL
50113MALWARE-OTHER Win.Ransomware.MegaLocker ransom note transfer over SMB (more info ...)trojan-activity        URL
50119FILE-OTHER Windows GDI font out-of-bounds read attempt (more info ...)attempted-user  2019-0758      URL
50120FILE-OTHER Windows GDI font out-of-bounds read attempt (more info ...)attempted-user  2019-0758      URL
50168SERVER-WEBAPP Atlassian Confluence Data Center and Server directory traversal attempt (more info ...)web-application-attack  2019-3398      URL
50169SERVER-WEBAPP Atlassian Confluence Data Center and Server directory traversal attempt (more info ...)web-application-attack  2019-3398      URL
50170SERVER-WEBAPP Atlassian Confluence Data Center and Server directory traversal attempt (more info ...)web-application-attack  2019-3398      URL
50176SERVER-OTHER Horos DICOM Medical Image Viewer stack overflow attempt (more info ...)attempted-user        URL
50198OS-WINDOWS Windows DACL privilege escalation attempt (more info ...)attempted-user  2019-1130      URL
50199OS-WINDOWS Windows DACL privilege escalation attempt (more info ...)attempted-user  2019-1130      URL
50202INDICATOR-COMPROMISE Peppa Pig botnet outbound scan attempt (more info ...)misc-activity        URL
50207OS-WINDOWS Windows Installer bypass privilege escalation attempt (more info ...)attempted-admin        URL
50208OS-WINDOWS Windows Installer bypass privilege escalation attempt (more info ...)attempted-admin        URL
50265FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0842 attack attempt (more info ...)attempted-user  2019-5058      URL
50266FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0842 attack attempt (more info ...)attempted-user  2019-5058      URL
50269FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0843 attack attempt (more info ...)attempted-user  2019-5060      URL
50270FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0843 attack attempt (more info ...)attempted-user  2019-5060      URL
50273FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0841 attack attempt (more info ...)attempted-user  2019-5057      URL
50274FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0841 attack attempt (more info ...)attempted-user  2019-5057      URL
50276MALWARE-BACKDOOR Win.Backdoor.Chopper webshell inbound request attempt (more info ...)trojan-activity        URL
50277MALWARE-BACKDOOR Win.Backdoor.Chopper webshell inbound request attempt (more info ...)trojan-activity        URL
50278MALWARE-BACKDOOR MultiOS.Backdoor.Agent webshell implant attempt (more info ...)trojan-activity        URL
50279MALWARE-OTHER Doc.Trojan.Xshell variant download attempt (more info ...)trojan-activity        URL
50280MALWARE-OTHER Doc.Trojan.Xshell variant download attempt (more info ...)trojan-activity        URL
50293BROWSER-WEBKIT Apple Webkit updateDescendantDependentFlags use-after-free attempt (more info ...)attempted-user  2018-4317      URL
50294BROWSER-WEBKIT Apple Webkit updateDescendantDependentFlags use-after-free attempt (more info ...)attempted-user  2018-4317      URL
50295FILE-OTHER TRUFFLEHUNTER TALOS-2019-0845 attack attempt (more info ...)attempted-user        URL
50296FILE-OTHER TRUFFLEHUNTER TALOS-2019-0845 attack attempt (more info ...)attempted-user        URL
50304SERVER-WEBAPP OpenDreamBox 2.0.0 Plugin WebAdmin command injection attempt (more info ...)web-application-attack  2017-14135      URL
50305SERVER-WEBAPP OpenDreamBox 2.0.0 Plugin WebAdmin command injection attempt (more info ...)web-application-attack  2017-14135      
50307SERVER-WEBAPP OpenDreamBox 2.0.0 Plugin WebAdmin command injection attempt (more info ...)web-application-attack  2017-14135      
50308SERVER-WEBAPP Dell KACE K1000 command injection attempt (more info ...)web-application-attack        URL
50309SERVER-WEBAPP Dell KACE K1000 command injection attempt (more info ...)web-application-attack        URL
50310SERVER-WEBAPP Dell KACE K1000 command injection attempt (more info ...)web-application-attack        URL
50311SERVER-WEBAPP Dell KACE K1000 command injection attempt (more info ...)web-application-attack        URL
50312SERVER-WEBAPP HooToo HT-TMO5 Travel router command injection attempt (more info ...)web-application-attack  2018-20841      
50314SERVER-WEBAPP HooToo HT-TMO5 Travel router command injection attempt (more info ...)web-application-attack  2018-20841      
50315SERVER-WEBAPP HooToo HT-TMO5 Travel router command injection attempt (more info ...)web-application-attack  2018-20841      
50316SERVER-WEBAPP Asus DSL-N12E_C1 1.1.2.3_345 command injection attempt (more info ...)web-application-attack  2018-15887      
50317SERVER-WEBAPP Asus DSL-N12E_C1 1.1.2.3_345 command injection attempt (more info ...)web-application-attack  2018-15887      
50318SERVER-WEBAPP Asus DSL-N12E_C1 1.1.2.3_345 command injection attempt (more info ...)web-application-attack  2018-15887      
50319SERVER-WEBAPP Asus DSL-N12E_C1 1.1.2.3_345 command injection attempt (more info ...)web-application-attack  2018-15887      
50321SERVER-WEBAPP MiCasaVerde VeraLite remote code execution attempt (more info ...)web-application-attack  2016-6255      URL
50322SERVER-WEBAPP MiCasaVerde VeraLite remote code execution attempt (more info ...)web-application-attack  2013-4863      URL
50323SERVER-WEBAPP Crestron AM platform command injection attempt (more info ...)web-application-attack  2019-3929      URL
50324SERVER-WEBAPP Crestron AM platform command injection attempt (more info ...)web-application-attack  2019-3929      URL
50325SERVER-WEBAPP Crestron AM platform command injection attempt (more info ...)web-application-attack  2019-3929      URL
50326SERVER-WEBAPP Crestron AM platform command injection attempt (more info ...)web-application-attack  2019-3929      URL
50327SERVER-WEBAPP LG SuperSignEz CMS command injection attempt (more info ...)web-application-attack  2018-17173      URL
50328SERVER-WEBAPP LG SuperSignEz CMS command injection attempt (more info ...)web-application-attack  2018-17173      URL
50329SERVER-WEBAPP LG SuperSignEz CMS command injection attempt (more info ...)web-application-attack  2018-17173      URL
50330SERVER-WEBAPP LG SuperSignEz CMS command injection attempt (more info ...)web-application-attack  2018-17173      URL
50331SERVER-WEBAPP Asustor ADM command injection attempt (more info ...)web-application-attack  2018-11510      URL
50332SERVER-WEBAPP Asustor ADM command injection attempt (more info ...)web-application-attack  2018-11510      URL
50333SERVER-WEBAPP Asustor ADM command injection attempt (more info ...)web-application-attack  2018-11510      URL
50334SERVER-WEBAPP Asustor ADM command injection attempt (more info ...)web-application-attack  2018-11510      URL
50340SERVER-WEBAPP Schneider Electric U.Motion Builder command injection attempt (more info ...)web-application-attack  2018-7841      URL
50341SERVER-WEBAPP Schneider Electric U.Motion Builder command injection attempt (more info ...)web-application-attack  2018-7841      URL
50342SERVER-WEBAPP Schneider Electric U.Motion Builder command injection attempt (more info ...)web-application-attack  2018-7841      URL
50343SERVER-WEBAPP Schneider Electric U.Motion Builder command injection attempt (more info ...)web-application-attack  2018-7841      URL
50344SERVER-WEBAPP VMWare NSX SD-WAN Edge command injection attempt (more info ...)web-application-attack  2018-6961      URL
50345SERVER-WEBAPP VMWare NSX SD-WAN Edge command injection attempt (more info ...)web-application-attack  2018-6961      URL
50346SERVER-WEBAPP VMWare NSX SD-WAN Edge command injection attempt (more info ...)web-application-attack  2018-6961      URL
50347SERVER-WEBAPP VMWare NSX SD-WAN Edge command injection attempt (more info ...)web-application-attack  2018-6961      URL
50351MALWARE-OTHER Win.Trojan.Karkoff variant download attempt (more info ...)attempted-user        URL
50352MALWARE-OTHER Win.Trojan.Karkoff binary download attempt (more info ...)attempted-user        URL
50354MALWARE-OTHER Win.Trojan.Karkoff variant download attempt (more info ...)attempted-user        URL
50355MALWARE-OTHER Win.Trojan.Karkoff binary download attempt (more info ...)attempted-user        URL
50356SERVER-MAIL Exim remote command execution attempt (more info ...)attempted-admin  2019-10149      URL
50375OS-WINDOWS Windows kernel win32k driver elevation of privilege attempt (more info ...)attempted-admin  2019-1065      URL
50376OS-WINDOWS Windows kernel win32k driver elevation of privilege attempt (more info ...)attempted-admin  2019-1065      URL
50377MALWARE-OTHER Doc.Downloader.Agent variant download attempt (more info ...)trojan-activity        URL
50378MALWARE-OTHER Win.Trojan.Sodinokibi variant download attempt (more info ...)trojan-activity        URL
50379MALWARE-OTHER Doc.Downloader.Agent variant download attempt (more info ...)trojan-activity        URL
50390INDICATOR-COMPROMISE SMBRelay tool use attempt (more info ...)trojan-activity        URL
50391INDICATOR-COMPROMISE SMBRelay tool use attempt (more info ...)trojan-activity        URL
50392SERVER-WEBAPP Belkin Wemo UPnP command injection attempt (more info ...)web-application-attack  2019-12780      URL
50409MALWARE-TOOLS Win.Trojan.OilRig jason bruteforcing tool download attempt (more info ...)trojan-activity        URL
50410MALWARE-TOOLS Win.Trojan.OilRig jason bruteforcing tool download attempt (more info ...)trojan-activity        URL
50411OS-WINDOWS Windows Common Log File System Driver privilege escalation attempt (more info ...)attempted-admin  2019-0984      URL
50412OS-WINDOWS Windows Common Log File System Driver privilege escalation attempt (more info ...)attempted-admin  2019-0984      URL
50428SERVER-WEBAPP Oracle WebLogic Server authenticated arbitrary JSP file upload attempt (more info ...)attempted-admin  2019-2618      URL
50455SERVER-WEBAPP IBM WebSphere Application Server remote code execution attempt (more info ...)attempted-user  2019-4279      URL
50463INDICATOR-COMPROMISE Mimikatz use via SMB attempt (more info ...)misc-attack        URL
50464INDICATOR-COMPROMISE Responder poisoner NetServer enumeration attempt (more info ...)misc-attack        URL
50465INDICATOR-COMPROMISE Responder poisoner SMB negotiation attack attempt (more info ...)misc-attack        URL
50466INDICATOR-COMPROMISE Responder poisoner SMB negotiation attack attempt (more info ...)misc-attack        URL
50467INDICATOR-COMPROMISE Mimikatz use via SMB attempt (more info ...)misc-attack        URL
50468INDICATOR-COMPROMISE Responder poisoner SMB negotiation attack attempt (more info ...)misc-attack        URL
50473SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2729      URL
50474SERVER-ORACLE Oracle WebLogic Server remote command execution attempt (more info ...)attempted-user  2019-2729      URL
50475MALWARE-BACKDOOR JSP Web shell access attempt (more info ...)attempted-user        URL
50476MALWARE-BACKDOOR JSP Web shell transfer attempt (more info ...)attempted-user        URL
50477MALWARE-BACKDOOR JSP Web shell transfer attempt (more info ...)attempted-user        URL
50478MALWARE-TOOLS Win.Trojan.CoinMiner dropper transfer attempt (more info ...)trojan-activity        URL
50479MALWARE-TOOLS Win.Trojan.CoinMiner dropper transfer attempt (more info ...)trojan-activity        URL
50490SERVER-WEBAPP TYPO3 PharStreamWrapper Package directory traversal attempt (more info ...)web-application-attack  2019-11831      URL
50491SERVER-WEBAPP TYPO3 PharStreamWrapper Package directory traversal attempt (more info ...)web-application-attack  2019-11831      URL
50495MALWARE-OTHER Win.Trojan.Waterbug variant malicious VBScript download attempt (more info ...)trojan-activity        URL
50496MALWARE-OTHER Win.Trojan.Waterbug variant malicious VBScript download attempt (more info ...)trojan-activity        URL
50502FILE-OTHER TRUFFLEHUNTER TALOS-2019-0848 attack attempt (more info ...)attempted-dos        URL
50503FILE-OTHER TRUFFLEHUNTER TALOS-2019-0848 attack attempt (more info ...)attempted-dos        URL
50504SERVER-WEBAPP Ruby on Rails Active Storage deserialization remote code execution attempt (more info ...)attempted-user  2019-5420      URL
50505MALWARE-TOOLS Malicious HTML application download attempt (more info ...)trojan-activity        URL
50506MALWARE-TOOLS Malicious HTML application download attempt (more info ...)trojan-activity        URL
50509EXPLOIT-KIT Spelevo Exploit Kit landing page detected (more info ...)attempted-user        
50511EXPLOIT-KIT Spelevo Exploit Kit browser exploit page detected (more info ...)attempted-user        
50517INDICATOR-COMPROMISE undocumented SMB dialect request attempt (more info ...)misc-attack        URL
50619OS-WINDOWS Executable DICOM 10 file download attempt (more info ...)attempted-user  2019-11687      URL
50620OS-WINDOWS Executable DICOM 10 file download attempt (more info ...)attempted-user  2019-11687      URL
50629MALWARE-OTHER Win.Trojan.Bemstour download attempt (more info ...)attempted-admin        
50630MALWARE-OTHER Win.Trojan.Bemstour download attempt (more info ...)attempted-admin        
50631MALWARE-OTHER Win.Trojan.Bemstour download attempt (more info ...)attempted-admin        
50632MALWARE-OTHER Win.Trojan.Bemstour download attempt (more info ...)attempted-admin        
50638SERVER-WEBAPP WIFICAM Wireless IP Camera command injection attempt (more info ...)attempted-user  2017-18377      
50639SERVER-WEBAPP WIFICAM Wireless IP Camera command injection attempt (more info ...)attempted-user  2017-18377      
50640SERVER-WEBAPP WIFICAM Wireless IP Camera command injection attempt (more info ...)attempted-user  2017-18377      
50641SERVER-WEBAPP WIFICAM Wireless IP Camera command injection attempt (more info ...)attempted-user  2017-18377      
50644MALWARE-OTHER Win.Ransomware.Ryuk variant download attempt (more info ...)trojan-activity        
50645MALWARE-OTHER Win.Ransomware.Ryuk variant download attempt (more info ...)trojan-activity        
50659POLICY-OTHER Oracle WebLogic Server blacklisted class use attempt (more info ...)policy-violation  2019-2729      URL
50660POLICY-OTHER Oracle WebLogic Server blacklisted class use attempt (more info ...)policy-violation  2019-2729      URL
50676OS-WINDOWS Windows Remote Desktop Protocol Client information disclosure attempt (more info ...)attempted-user  2019-1108      URL
50677OS-WINDOWS Windows Remote Desktop Protocol Client information disclosure attempt (more info ...)attempted-user  2019-1108      URL
50682OS-WINDOWS Windows kernel win32k driver elevation of privilege attempt (more info ...)attempted-user  2019-1073      URL
50683OS-WINDOWS Windows kernel win32k driver elevation of privilege attempt (more info ...)attempted-admin  2019-1073      URL
50712MALWARE-OTHER Win.Trojan.Trickbot sample download attempt (more info ...)trojan-activity        URL
50713MALWARE-OTHER Win.Trojan.Trickbot sample download attempt (more info ...)trojan-activity        URL
50730FILE-PDF TRUFFLEHUNTER TALOS-2019-0856 attack attempt (more info ...)attempted-user  2019-5067      URL
50731FILE-PDF TRUFFLEHUNTER TALOS-2019-0856 attack attempt (more info ...)attempted-user  2019-5067      URL
50738FILE-PDF TRUFFLEHUNTER TALOS-2019-0855 attack attempt (more info ...)attempted-user  2019-5066      URL
50739FILE-PDF TRUFFLEHUNTER TALOS-2019-0855 attack attempt (more info ...)attempted-user  2019-5066      URL
50746SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0859 attack attempt (more info ...)web-application-attack  2019-5070      URL
50755SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0858 attack attempt (more info ...)web-application-attack  2019-5069      URL
50756SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0858 attack attempt (more info ...)web-application-attack  2019-5069      URL
50757SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0858 attack attempt (more info ...)web-application-attack  2019-5069      URL
50758SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0858 attack attempt (more info ...)web-application-attack  2019-5069      URL
50759SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0858 attack attempt (more info ...)web-application-attack  2019-5069      URL
50760SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0858 attack attempt (more info ...)web-application-attack  2019-5069      URL
50773SERVER-WEBAPP Oracle-BI convert servlet XML external entity injection attempt (more info ...)web-application-attack  2019-2767      
50774FILE-OTHER TRUFFLEHUNTER TALOS-2019-0852 attack attempt (more info ...)attempted-user  2019-5063      URL
50775FILE-OTHER TRUFFLEHUNTER TALOS-2019-0852 attack attempt (more info ...)attempted-user  2019-5063      URL
50776SERVER-WEBAPP Oracle Business Intelligence remote jsp file include attempt (more info ...)web-application-attack  2019-2771      URL
50782SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0861 attack attempt (more info ...)web-application-attack  2019-5072      URL
50783SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0861 attack attempt (more info ...)web-application-attack  2019-5072      URL
50784SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0861 attack attempt (more info ...)web-application-attack  2019-5072      URL
50785SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0861 attack attempt (more info ...)web-application-attack  2019-5072      URL
50786PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0872 attack attempt (more info ...)attempted-dos  2019-5080      URL
50787PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0869 attack attempt (more info ...)attempted-dos  2019-5077      URL
50788PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0862 attack attempt (more info ...)attempted-admin  2019-5075      URL
50789PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0862 attack attempt (more info ...)attempted-admin  2019-5075      URL
50790PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0863 attack attempt (more info ...)attempted-admin  2019-5074      URL
50791PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0873 attack attempt (more info ...)attempted-admin  2019-5081      URL
50792PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0874 attack attempt (more info ...)attempted-admin  2019-5082      URL
50793PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0871 attack attempt (more info ...)attempted-admin  2019-5079      URL
50795PUA-OTHER Win.Trojan.CoinMiner attempted download (more info ...)trojan-activity        URL
50796PUA-OTHER Win.Trojan.CoinMiner attempted download (more info ...)trojan-activity        URL
50797PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0870 attack attempt (more info ...)attempted-dos  2019-5078      URL
50801MALWARE-OTHER Win.Trojan.Ratsnif variant download attempt (more info ...)trojan-activity        URL
50802MALWARE-OTHER Win.Trojan.Ratsnif variant download attempt (more info ...)trojan-activity        URL
50803PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0866 attack attempt (more info ...)attempted-dos        URL
50806FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0875 attack attempt (more info ...)attempted-user  2019-5083      URL
50807FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0875 attack attempt (more info ...)attempted-user  2019-5083      URL
50824FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0876 attack attempt (more info ...)attempted-user  2019-5084      URL
50825FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0876 attack attempt (more info ...)attempted-user  2019-5084      URL
50826FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0876 attack attempt (more info ...)attempted-user  2019-5084      URL
50827FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0876 attack attempt (more info ...)attempted-user  2019-5084      URL
50842FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0878 attack attempt (more info ...)attempted-user  2019-5086      URL
50843FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0878 attack attempt (more info ...)attempted-user  2019-5086      URL
50844FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0878 attack attempt (more info ...)attempted-user  2019-5086      URL
50845FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0878 attack attempt (more info ...)attempted-user  2019-5086      URL
50857SERVER-OTHER TRUFFLEHUNTER TALOS-2019-0877 attack attempt (more info ...)attempted-user  2019-5085      URL
50858SERVER-WEBAPP Siemens TIA Administrator authentication bypass attempt (more info ...)trojan-activity  2019-10915      URL
50860SERVER-WEBAPP Palo Alto GlobalProtect SSL VPN buffer overflow attempt (more info ...)web-application-attack  2019-1579      URL
50861SERVER-WEBAPP Palo Alto GlobalProtect SSL VPN remote code execution attempt (more info ...)web-application-attack  2019-1579      URL
50864FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0880 attack attempt (more info ...)attempted-user  2019-5088      URL
50865FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0880 attack attempt (more info ...)attempted-user  2019-5088      URL
50866FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0880 attack attempt (more info ...)attempted-user  2019-5088      URL
50867FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0880 attack attempt (more info ...)attempted-user  2019-5088      URL
50868FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0881 attack attempt (more info ...)attempted-user  2019-5089      URL
50869FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0881 attack attempt (more info ...)attempted-user  2019-5089      URL
50897FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0884 attack attempt (more info ...)attempted-user  2019-5092      URL
50898FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0884 attack attempt (more info ...)attempted-user  2019-5092      URL
50899SERVER-OTHER TRUFFLEHUNTER TALOS-2019-0882 attack attempt (more info ...)attempted-user  2019-5090      URL
50900SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-admin  2017-5806      
50908SERVER-OTHER TRUFFLEHUNTER TALOS-2019-0885 attack attempt (more info ...)attempted-user  2019-5093      URL
50909SERVER-OTHER TRUFFLEHUNTER TALOS-2019-0883 attack attempt (more info ...)attempted-dos  2019-5091      URL
50981SERVER-WEBAPP LCDS Laquis SCADA command injection attempt (more info ...)web-application-attack  2018-18992      
50982SERVER-WEBAPP LCDS Laquis SCADA command injection attempt (more info ...)web-application-attack  2018-18992      
50983SERVER-WEBAPP LCDS Laquis SCADA command injection attempt (more info ...)web-application-attack  2018-18992      
50984SERVER-WEBAPP LCDS Laquis SCADA command injection attempt (more info ...)web-application-attack  2018-18992      
51021SERVER-WEBAPP Advantech WebAccess directory traversal attempt (more info ...)web-application-attack  2018-7503      URL
51022SERVER-WEBAPP Advantech WebAccess directory traversal attempt (more info ...)web-application-attack  2018-7503      URL
51023SERVER-WEBAPP Advantech WebAccess directory traversal attempt (more info ...)web-application-attack  2018-7503      URL
51045SERVER-OTHER Netatalk attn_quantum authentication bypass attempt (more info ...)attempted-user  2018-1160      URL
51063SERVER-OTHER Memcached SASL auth opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8706      URL
51064SERVER-OTHER Memcached SASL auth opcode request heap buffer overflow attempt (more info ...)attempted-admin  2016-8706      URL
51118MALWARE-OTHER Download of malicious PowerShell script (more info ...)trojan-activity        URL
51120SERVER-WEBAPP GrandNode 4.4 path traversal attempt (more info ...)web-application-attack  2019-12276      
51121SERVER-WEBAPP GrandNode 4.4 path traversal attempt (more info ...)web-application-attack  2019-12276      
51122SERVER-WEBAPP GrandNode 4.4 path traversal attempt (more info ...)web-application-attack  2019-12276      
51241SERVER-WEBAPP Pulse Secure VPN command injection attempt (more info ...)web-application-attack  2019-11539      
51242SERVER-WEBAPP Pulse Secure VPN command injection attempt (more info ...)web-application-attack  2019-11539      
51243SERVER-WEBAPP Pulse Secure VPN command injection attempt (more info ...)web-application-attack  2019-11539      
51260SERVER-WEBAPP Ruby on Rails render file directory traversal attempt (more info ...)web-application-attack  2019-5418      URL
51261SERVER-WEBAPP Ruby on Rails render file directory traversal attempt (more info ...)web-application-attack  2019-5418      URL
51288SERVER-WEBAPP Pulse Secure SSL VPN arbitrary file read attempt (more info ...)web-application-attack  2019-11510      URL
51289SERVER-WEBAPP Pulse Secure SSL VPN directory traversal attempt (more info ...)web-application-attack  2019-11510      URL
51292SERVER-WEBAPP Axway SecureTransport XML external entity injection attempt (more info ...)web-application-attack        URL
51315SERVER-WEBAPP Atlassian Jira ContactAdministrators and SendBulkMail template injection remote code execution attempt (more info ...)attempted-user  2019-11581      
51316SERVER-WEBAPP Atlassian Jira ContactAdministrators and SendBulkMail template injection remote code execution attempt (more info ...)attempted-user  2019-11581      
51317SERVER-WEBAPP Atlassian Jira ContactAdministrators and SendBulkMail template injection remote code execution attempt (more info ...)attempted-user  2019-11581      
51318SERVER-WEBAPP Atlassian Jira ContactAdministrators and SendBulkMail template injection remote code execution attempt (more info ...)attempted-user  2019-11581      
51361MALWARE-OTHER Win.Ransomware.LooCipher variant download attempt (more info ...)trojan-activity        URL
51362MALWARE-OTHER Win.Ransomware.LooCipher variant download attempt (more info ...)trojan-activity        URL
51368MALWARE-BACKDOOR Win.Backdoor.Agent webshell inbound request attempt (more info ...)trojan-activity  2019-0604      URL
51370SERVER-WEBAPP Fortinet FortiOS SSL VPN web portal directory traversal attempt (more info ...)web-application-attack  2018-13379      
51371SERVER-WEBAPP Fortinet FortiOS SSL VPN web portal directory traversal attempt (more info ...)web-application-attack  2018-13379      
51372SERVER-WEBAPP Fortinet FortiOS SSL VPN web portal directory traversal attempt (more info ...)web-application-attack  2018-13379      
51373INDICATOR-COMPROMISE Python reverse shell execution attempt (more info ...)attempted-user        
51374INDICATOR-COMPROMISE Python reverse shell execution attempt (more info ...)attempted-user        
51378SERVER-WEBAPP Roundcube webmail cross-site-scripting attempt (more info ...)attempted-user  2018-19206      
51381BROWSER-WEBKIT Apple WebKit JSArray component out-of-bounds access (more info ...)attempted-user  2019-8518      URL
51382BROWSER-WEBKIT Apple WebKit JSArray component out-of-bounds access (more info ...)attempted-user  2019-8518      URL
51387SERVER-WEBAPP Fortinet Fortigate SSL VPN improper authorization attempt (more info ...)attempted-user  2018-13382      URL
51418SERVER-WEBAPP Telerik UI cryptographic keys disclosure attempt (more info ...)web-application-attack  2017-9248      URL
51447FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0891 attack attempt (more info ...)attempted-user  2019-5099      URL
51448FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0891 attack attempt (more info ...)attempted-user  2019-5099      URL
51461FILE-OTHER TRUFFLEHUNTER TALOS-2019-0890 attack attempt (more info ...)attempted-user  2019-5098      URL
51462FILE-OTHER TRUFFLEHUNTER TALOS-2019-0890 attack attempt (more info ...)attempted-user  2019-5098      URL
51465SERVER-WEBAPP Fortigate SSL VPN cross site scripting attempt (more info ...)attempted-user  2018-13380      URL
51466SERVER-WEBAPP Fortigate SSL VPN cross site scripting attempt (more info ...)attempted-user  2018-13380      URL
51467SERVER-WEBAPP Fortigate SSL VPN cross site scripting attempt (more info ...)attempted-user  2018-13380      URL
51468SERVER-WEBAPP Fortigate SSL VPN cross site scripting attempt (more info ...)attempted-user  2018-13380      URL
51469SERVER-WEBAPP Fortigate SSL VPN cross site scripting attempt (more info ...)attempted-user  2018-13380      URL
51470SERVER-WEBAPP Fortigate SSL VPN cross site scripting attempt (more info ...)attempted-user  2018-13380      URL
51484MALWARE-OTHER ANDR.Trojan.Agent outbound connection attempt (more info ...)trojan-activity        URL
51516MALWARE-OTHER Html.Downloader.Agent download attempt (more info ...)attempted-user        URL
51517MALWARE-OTHER Html.Downloader.Agent download attempt (more info ...)attempted-user        URL
51518MALWARE-OTHER Html.Downloader.Agent download attempt (more info ...)attempted-user        URL
51519MALWARE-OTHER Html.Downloader.Agent download attempt (more info ...)attempted-user        URL
51520MALWARE-OTHER Win.Trojan.Crysis malicious executable download attempt (more info ...)trojan-activity        URL
51521MALWARE-OTHER Win.Exploit.Hacktool malicious executable download attempt (more info ...)trojan-activity        URL
51522MALWARE-OTHER Win.Trojan.Crysis malicious executable download attempt (more info ...)trojan-activity        URL
51523MALWARE-OTHER Win.Trojan.Crysis malicious executable download attempt (more info ...)trojan-activity        URL
51525MALWARE-OTHER Win.Exploit.Hacktool malicious executable download attempt (more info ...)trojan-activity        URL
51526MALWARE-OTHER Win.Trojan.Crysis malicious executable download attempt (more info ...)trojan-activity        URL
51527MALWARE-OTHER Win.Trojan.Crysis malicious executable download attempt (more info ...)trojan-activity        URL
51528MALWARE-OTHER Win.Trojan.Crysis malicious executable download attempt (more info ...)trojan-activity        URL
51529MALWARE-OTHER Win.Trojan.Crysis malicious executable download attempt (more info ...)trojan-activity        URL
51530FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0892 attack attempt (more info ...)attempted-user  2020-6065      URL
51531FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0892 attack attempt (more info ...)attempted-user  2020-6065      URL
51535MALWARE-BACKDOOR TLS certificate securing LocalXpose reverse proxy backdoor (more info ...)trojan-activity        URL
51569SERVER-WEBAPP HPE Network Automation PermissionFilter unauthenticated information disclosure attempt (more info ...)attempted-recon  2017-5812      URL
51575SERVER-WEBAPP HooToo HT-TMO6 Travel router heap buffer overflow attempt (more info ...)web-application-attack  2017-9025      URL
51581SERVER-WEBAPP D-Link DIR-823G routers HNAP1 command injection attempt (more info ...)web-application-attack  2019-7298      
51587SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0911 attack attempt (more info ...)web-application-attack  2019-5123      URL
51588SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0911 attack attempt (more info ...)web-application-attack  2019-5123      URL
51589SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0911 attack attempt (more info ...)web-application-attack  2019-5123      URL
51590SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0910 attack attempt (more info ...)web-application-attack  2019-5120      URL
51591SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0910 attack attempt (more info ...)web-application-attack  2019-5120      URL
51592SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0910 attack attempt (more info ...)web-application-attack  2019-5120      URL
51597SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0908 attack attempt (more info ...)web-application-attack  2019-5119      URL
51598SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0908 attack attempt (more info ...)web-application-attack  2019-5119      URL
51599SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0908 attack attempt (more info ...)web-application-attack  2019-5119      URL
51600SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0907 attack attempt (more info ...)web-application-attack  2019-5116      URL
51601SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0907 attack attempt (more info ...)web-application-attack  2019-5116      URL
51602SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0907 attack attempt (more info ...)web-application-attack  2019-5116      URL
51605SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0906 attack attempt (more info ...)web-application-attack  2019-5114      URL
51606SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0906 attack attempt (more info ...)web-application-attack  2019-5114      URL
51607SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0906 attack attempt (more info ...)web-application-attack  2019-5114      URL
51608SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0905 attack attempt (more info ...)web-application-attack  2019-5113      URL
51609SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0905 attack attempt (more info ...)web-application-attack  2019-5113      URL
51610SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0905 attack attempt (more info ...)web-application-attack  2019-5113      URL
51611SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0904 attack attempt (more info ...)web-application-attack  2019-5112      URL
51612SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0904 attack attempt (more info ...)web-application-attack  2019-5112      URL
51613SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0904 attack attempt (more info ...)web-application-attack  2019-5112      URL
51614SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0903 attack attempt (more info ...)web-application-attack  2019-5110      URL
51615SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0903 attack attempt (more info ...)web-application-attack  2019-5110      URL
51616SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0903 attack attempt (more info ...)web-application-attack  2019-5110      URL
51617SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0902 attack attempt (more info ...)web-application-attack  2019-5109      URL
51618SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0902 attack attempt (more info ...)web-application-attack  2019-5109      URL
51619SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0902 attack attempt (more info ...)web-application-attack  2019-5109      URL
51620SERVER-WEBAPP vBulletin pre-authenticated command injection attempt (more info ...)web-application-attack  2020-17496      URL
51621SERVER-WEBAPP vBulletin pre-authenticated command injection attempt (more info ...)web-application-attack  2020-17496      URL
51637EXPLOIT-KIT Rig exploit kit executable download attempt (more info ...)trojan-activity        URL
51638EXPLOIT-KIT Rig exploit kit executable download attempt (more info ...)trojan-activity        URL
51639SERVER-OTHER AVEVA InduSoft Web Studio and InTouch Edge HMI buffer overflow attempt (more info ...)attempted-admin  2018-17916      
51647SERVER-OTHER Indusoft Web Studio and Intouch Machine Edition stack buffer overflow attempt (more info ...)attempted-user  2018-10620      
51652SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0894 attack attempt (more info ...)attempted-dos        URL
51665FILE-OTHER TRUFFLEHUNTER TALOS-2019-0913 attack attempt (more info ...)attempted-dos  2019-5124      URL
51666FILE-OTHER TRUFFLEHUNTER TALOS-2019-0913 attack attempt (more info ...)attempted-dos  2019-5124      URL
51673FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
51674FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
51675FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
51676FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
51677FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
51678FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
51679FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
51680FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
51684SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0914 attack attempt (more info ...)attempted-dos        URL
51730SERVER-WEBAPP OpenEMR directory traversal attempt (more info ...)web-application-attack  2019-3967      
51731SERVER-WEBAPP OpenEMR directory traversal attempt (more info ...)web-application-attack  2019-3967      
51732SERVER-WEBAPP OpenEMR directory traversal attempt (more info ...)web-application-attack  2019-3967      
51737FILE-PDF TRUFFLEHUNTER TALOS-2019-0915 attack attempt (more info ...)attempted-user  2019-5126      URL
51738FILE-PDF TRUFFLEHUNTER TALOS-2019-0915 attack attempt (more info ...)attempted-user  2019-5126      URL
51802SERVER-WEBAPP Dell EMC Data Protection Advisor XML external entity injection attempt (more info ...)web-application-attack  2018-11048      URL
51803SERVER-WEBAPP Dell EMC Data Protection Advisor XML external entity injection attempt (more info ...)web-application-attack  2018-11048      URL
51834SERVER-WEBAPP vBulletin pre-authenticated command injection attempt (more info ...)web-application-attack  2020-17496      URL
51835SERVER-WEBAPP vBulletin pre-authenticated command injection attempt (more info ...)web-application-attack  2020-17496      URL
51836SERVER-WEBAPP vBulletin pre-authenticated command injection attempt (more info ...)web-application-attack  2020-17496      URL
51837SERVER-WEBAPP vBulletin pre-authenticated command injection attempt (more info ...)web-application-attack  2020-17496      URL
51838SERVER-OTHER Redis server RESP arbitrary code execution attempt (more info ...)attempted-user        
51839SERVER-OTHER Redis server RESP arbitrary code execution attempt (more info ...)attempted-user        
51841SERVER-WEBAPP Tableau XML external entity injection attempt (more info ...)web-application-attack  2019-15637      URL
51842SERVER-WEBAPP Tableau XML external entity injection attempt (more info ...)web-application-attack  2019-15637      URL
51857OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-1538      
51860OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-1538      
51861OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-1538      
51862OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-1538      
51863OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-1538      
51864OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-1538      
51865OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-1538      
51866OS-MOBILE Android Stagefright MP4 buffer overflow attempt (more info ...)attempted-admin  2015-1538      
51929SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0919 attack attempt (more info ...)web-application-attack        URL
51931FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0916 attack attempt (more info ...)attempted-user  2019-5125      URL
51932FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0916 attack attempt (more info ...)attempted-user  2019-5125      URL
51933FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0916 attack attempt (more info ...)attempted-user  2019-5125      URL
51934FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0916 attack attempt (more info ...)attempted-user  2019-5125      URL
51935FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0916 attack attempt (more info ...)attempted-user  2019-5125      URL
51936FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0916 attack attempt (more info ...)attempted-user  2019-5125      URL
51937FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0916 attack attempt (more info ...)attempted-user  2019-5125      URL
51938FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0916 attack attempt (more info ...)attempted-user  2019-5125      URL
51949FILE-PDF TRUFFLEHUNTER TALOS-2019-0935 attack attempt (more info ...)attempted-user  2020-13570      URL
51950FILE-PDF TRUFFLEHUNTER TALOS-2019-0935 attack attempt (more info ...)attempted-user  2020-13570      URL
51951FILE-PDF TRUFFLEHUNTER TALOS-2019-0920 attack attempt (more info ...)attempted-user  2019-5131      URL
51952FILE-PDF TRUFFLEHUNTER TALOS-2019-0920 attack attempt (more info ...)attempted-user  2019-5131      URL
51953OS-MOBILE Android WhatsApp malformed GIF double-free remote code execution attempt (more info ...)attempted-user  2019-11932      URL
51954OS-MOBILE Android WhatsApp malformed GIF double-free remote code execution attempt (more info ...)attempted-user  2019-11932      URL
51955OS-MOBILE Android WhatsApp malformed GIF double-free remote code execution attempt (more info ...)attempted-user  2019-11932      URL
51956OS-MOBILE Android WhatsApp malformed GIF double-free remote code execution attempt (more info ...)attempted-user  2019-11932      URL
51967MALWARE-TOOLS Win.Trojan.Emotet variant download attempt (more info ...)trojan-activity        URL
51968MALWARE-TOOLS Win.Trojan.Emotet variant download attempt (more info ...)trojan-activity        URL
51972SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt (more info ...)web-application-attack  2015-5371  75515    
51973SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt (more info ...)web-application-attack  2015-5371  75515    
51974SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt (more info ...)web-application-attack  2015-5371  75515    
51975SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt (more info ...)web-application-attack  2015-5371  75515    
51976SERVER-WEBAPP SolarWinds Storage Manager directory traversal attempt (more info ...)web-application-attack  2015-5371  75515    
51982SERVER-WEBAPP AlienVault USM and OSSIM FQDN command injection attempt (more info ...)web-application-attack        URL
51983SERVER-WEBAPP AlienVault USM and OSSIM FQDN command injection attempt (more info ...)web-application-attack        URL
51986FILE-OTHER Viber for Desktop URI handler remote code execution attempt (more info ...)attempted-user  2019-12569      
51987FILE-OTHER Viber for Desktop URI handler remote code execution attempt (more info ...)attempted-user  2019-12569      
51995SERVER-WEBAPP Advantech WebAccess SCADA 8.3.2 command injection attempt (more info ...)web-application-attack  2018-15707      
51996SERVER-WEBAPP Advantech WebAccess SCADA 8.3.2 command injection attempt (more info ...)web-application-attack  2018-15707      
51997SERVER-WEBAPP Advantech WebAccess SCADA 8.3.2 command injection attempt (more info ...)web-application-attack  2018-15707      
51998SERVER-WEBAPP Advantech WebAccess SCADA 8.3.2 command injection attempt (more info ...)web-application-attack  2018-15707      
52002BROWSER-WEBKIT WebKit WebCore handleMenuItemSelected use after free attempt (more info ...)attempted-user  2018-4312      
52003BROWSER-WEBKIT WebKit WebCore handleMenuItemSelected use after free attempt (more info ...)attempted-user  2018-4312      
52008FILE-OTHER TRUFFLEHUNTER TALOS-2019-0936 attack attempt (more info ...)denial-of-service  2019-5147      URL
52009FILE-OTHER TRUFFLEHUNTER TALOS-2019-0936 attack attempt (more info ...)denial-of-service  2019-5147      URL
52010SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0930 attack attempt (more info ...)web-application-attack  2019-5141      URL
52011SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0930 attack attempt (more info ...)web-application-attack  2019-5141      URL
52013SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0929 attack attempt (more info ...)web-application-attack  2019-5140      URL
52014SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0929 attack attempt (more info ...)web-application-attack  2019-5140      URL
52015SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0931 attack attempt (more info ...)web-application-attack  2019-5142      URL
52016SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0931 attack attempt (more info ...)web-application-attack  2019-5142      URL
52017SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0931 attack attempt (more info ...)web-application-attack  2019-5142      URL
52018SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0931 attack attempt (more info ...)web-application-attack  2019-5142      URL
52020FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0933 attack attempt (more info ...)attempted-user  2019-5144      URL
52021FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0933 attack attempt (more info ...)attempted-user  2019-5144      URL
52023SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0923 attack attempt (more info ...)web-application-attack  2019-5135      URL
52026MALWARE-OTHER Xml.Phishing.Evernote outbound connection (more info ...)misc-activity        URL
52027MALWARE-OTHER Xml.Phishing.Evernote outbound connection (more info ...)misc-activity        URL
52037SERVER-OTHER ZeroMQ libzmq stack-based buffer overflow attempt (more info ...)attempted-user  2019-13132  109284    
52046FILE-PDF TRUFFLEHUNTER TALOS-2019-0934 attack attempt (more info ...)attempted-user  2019-5145      URL
52047FILE-PDF TRUFFLEHUNTER TALOS-2019-0934 attack attempt (more info ...)attempted-user  2019-5145      URL
52048BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2019-0943 attack attempt (more info ...)attempted-user        URL
52049BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2019-0943 attack attempt (more info ...)attempted-user        URL
52050FILE-OTHER TRUFFLEHUNTER TALOS-2019-0937 attack attempt (more info ...)attempted-dos  2019-5146      URL
52051FILE-OTHER TRUFFLEHUNTER TALOS-2019-0937 attack attempt (more info ...)attempted-dos  2019-5146      URL
52053FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0921 attack attempt (more info ...)attempted-user  2019-5132      URL
52054FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0921 attack attempt (more info ...)attempted-user  2019-5132      URL
52056FILE-IDENTIFY Portable Executable binary file magic detected (more info ...)misc-activity        
52057FILE-IDENTIFY Portable Executable binary file magic detected (more info ...)misc-activity        
52058FILE-EXECUTABLE Norton Antivirus ASPack heap corruption attempt (more info ...)attempted-admin  2016-2208      URL
52070MALWARE-OTHER known malicious browser profiler script download attempt (more info ...)attempted-user  2019-13720      URL
52071MALWARE-OTHER known malicious browser profiler script download attempt (more info ...)attempted-user  2019-13720      URL
52074SERVER-WEBAPP LibreNMS addhost command injection attempt (more info ...)web-application-attack  2018-20434      URL
52075SERVER-WEBAPP LibreNMS addhost command injection attempt (more info ...)web-application-attack  2018-20434      URL
52076SERVER-WEBAPP LibreNMS addhost command injection attempt (more info ...)web-application-attack  2018-20434      URL
52077SERVER-WEBAPP LibreNMS addhost command injection attempt (more info ...)web-application-attack  2018-20434      URL
52081INDICATOR-COMPROMISE Responder poisoner service negotiation attack attempt (more info ...)misc-attack        URL
52082FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0945 attack attempt (more info ...)attempted-user  2019-5154      URL
52083FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0945 attack attempt (more info ...)attempted-user  2019-5154      URL
52095FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0946 attack attempt (more info ...)attempted-user  2020-0738      URL
52096FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0946 attack attempt (more info ...)attempted-user  2020-0738      URL
52097FILE-PDF TRUFFLEHUNTER TALOS-2019-0947 attack attempt (more info ...)attempted-recon        URL
52098FILE-PDF TRUFFLEHUNTER TALOS-2019-0947 attack attempt (more info ...)attempted-recon        URL
52099SERVER-WEBAPP Jenkins SCM Git Client plugin command injection attempt (more info ...)web-application-attack  2019-10392      URL
52115INDICATOR-COMPROMISE Xml.Downloader.PowMet fileless malware variant download attempt (more info ...)trojan-activity        URL
52116INDICATOR-COMPROMISE Win.Downloader.PowMet powershell script download attempt (more info ...)trojan-activity        URL
52117INDICATOR-COMPROMISE Xml.Downloader.PowMet fileless malware variant download attempt (more info ...)trojan-activity        URL
52118INDICATOR-COMPROMISE Win.Downloader.PowMet powershell script download attempt (more info ...)trojan-activity        URL
52131SERVER-OTHER TRUFFLEHUNTER TALOS-2019-0948 attack attempt (more info ...)attempted-admin  2019-5157      URL
52134MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52135MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52136MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52137MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52138MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52139MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52140MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52141MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52142MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52143MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52144MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52145MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52146MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52147MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52237SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0953 attack attempt (more info ...)web-application-attack  2019-5160      URL
52241SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0955 attack attempt (more info ...)attempted-user  2019-5162      URL
52246INDICATOR-COMPROMISE AgentTesla variant outbound connection attempt (more info ...)trojan-activity        URL
52247SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0510 attack attempt (more info ...)attempted-recon  2017-14461      URL
52268SERVER-WEBAPP OpenMRS insecure object deserialization attempt (more info ...)attempted-user  2018-19276      
52269FILE-OTHER TRUFFLEHUNTER TALOS-2019-0957 attack attempt (more info ...)attempted-dos        URL
52270FILE-OTHER TRUFFLEHUNTER TALOS-2019-0957 attack attempt (more info ...)attempted-dos        URL
52276SERVER-WEBAPP Shenzhen TVT Digital Technology API OS buffer overflow attempt (more info ...)attempted-dos        URL
52277SERVER-WEBAPP Shenzhen TVT Digital Technology API OS command injection attempt (more info ...)attempted-admin        URL
52290MALWARE-OTHER Win.Backdoor.Agent malicious DLL loader download attempt (more info ...)trojan-activity        URL
52323SERVER-OTHER ABB PGIM unauthenticated credential disclosure attempt (more info ...)attempted-admin        URL
52330MALWARE-OTHER Win.Dropper.Ramnit-7057830-0 download attempt (more info ...)trojan-activity        URL
52331FILE-PDF TRUFFLEHUNTER TALOS-2019-0959 attack attempt (more info ...)attempted-user        URL
52332FILE-PDF TRUFFLEHUNTER TALOS-2019-0959 attack attempt (more info ...)attempted-user        URL
52339MALWARE-OTHER Win.Dropper.Qakbot-7058183-0 download attempt (more info ...)trojan-activity        URL
52340MALWARE-OTHER Win.Dropper.Qakbot-7058183-0 download attempt (more info ...)trojan-activity        URL
52345SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0960 attack attempt (more info ...)attempted-user  2019-5165      URL
52346PROTOCOL-SNMP TRUFFLEHUNTER TALOS-2019-0960 attack attempt (more info ...)attempted-user  2019-5165      URL
52360MALWARE-OTHER Win.Ransomware.Agent variant payload download attempt (more info ...)trojan-activity        URL
52361MALWARE-OTHER Win.Ransomware.Agent variant payload download attempt (more info ...)trojan-activity        URL
52362MALWARE-OTHER Win.Ransomware.Agent variant payload download attempt (more info ...)trojan-activity        URL
52363MALWARE-OTHER Win.Ransomware.Agent variant payload download attempt (more info ...)trojan-activity        URL
52364MALWARE-OTHER Win.Ransomware.Agent variant payload download attempt (more info ...)trojan-activity        URL
52365MALWARE-OTHER Win.Ransomware.Agent variant payload download attempt (more info ...)trojan-activity        URL
52367FILE-OTHER TRUFFLEHUNTER TALOS-2019-0964 attack attempt (more info ...)attempted-user  2019-5183      URL
52368FILE-OTHER TRUFFLEHUNTER TALOS-2019-0964 attack attempt (more info ...)attempted-user  2019-5183      URL
52373MALWARE-OTHER Winnti Group VMProtected launcher variant download attempt (more info ...)trojan-activity        URL
52374MALWARE-OTHER Winnti Group VMProtected launcher variant download attempt (more info ...)trojan-activity        URL
52375MALWARE-TOOLS Win.Downloader.Get2 download attempt (more info ...)attempted-user        URL
52376MALWARE-TOOLS Win.Downloader.Get2 download attempt (more info ...)attempted-user        URL
52377MALWARE-TOOLS Win.Downloader.Get2 download attempt (more info ...)attempted-user        URL
52378MALWARE-TOOLS Win.Downloader.Get2 download attempt (more info ...)attempted-user        URL
52379MALWARE-TOOLS Win.Downloader.Get2 download attempt (more info ...)attempted-user        URL
52380MALWARE-TOOLS Win.Downloader.Get2 download attempt (more info ...)attempted-user        URL
52381MALWARE-TOOLS Win.Downloader.Get2 download attempt (more info ...)attempted-user        URL
52382MALWARE-TOOLS Win.Downloader.Get2 download attempt (more info ...)attempted-user        URL
52404MALWARE-BACKDOOR Win.Backdoor.NanoCore potential scanning attempt (more info ...)trojan-activity        
52405MALWARE-TOOLS CKnife penetration testing tool attempt (more info ...)trojan-activity        
52406SERVER-WEBAPP Atlassian Jira makeRequest server side request forgery attempt (more info ...)web-application-attack  2019-8451      URL
52408FILE-OTHER TRUFFLEHUNTER TALOS-2019-0962 attack attempt (more info ...)attempted-admin  2019-5186      URL
52409FILE-OTHER TRUFFLEHUNTER TALOS-2019-0962 attack attempt (more info ...)attempted-admin  2019-5175      URL
52412FILE-OTHER TRUFFLEHUNTER TALOS-2019-0963 attack attempt (more info ...)attempted-admin  2019-5185      URL
52413FILE-OTHER TRUFFLEHUNTER TALOS-2019-0966 attack attempt (more info ...)attempted-admin  2019-5186      URL
52414FILE-OTHER TRUFFLEHUNTER TALOS-2019-0965 attack attempt (more info ...)attempted-admin  2019-5184      URL
52415BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2019-0967 attack attempt (more info ...)attempted-user        URL
52416BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2019-0967 attack attempt (more info ...)attempted-user        URL
52427MALWARE-OTHER Win.Ransomware.DoppelPaymer variant download attempt (more info ...)trojan-activity        URL
52432OS-WINDOWS TRUFFLEHUNTER TALOS-2019-0970 attack attempt (more info ...)attempted-admin        URL
52433OS-WINDOWS TRUFFLEHUNTER TALOS-2019-0970 attack attempt (more info ...)attempted-admin        URL
52434MALWARE-OTHER Win.Trojan.WebShellAccessDB variant download attempt (more info ...)trojan-activity        URL
52435MALWARE-OTHER Win.Trojan.WebShellAccessDB variant download attempt (more info ...)trojan-activity        URL
52436MALWARE-OTHER Win.Trojan.Powerkatz variant download attempt (more info ...)trojan-activity        URL
52437MALWARE-OTHER Win.Trojan.Powerkatz variant download attempt (more info ...)trojan-activity        URL
52438MALWARE-OTHER Win.Trojan.PowershellAgent variant download attempt (more info ...)trojan-activity        URL
52439MALWARE-OTHER Win.Trojan.PowershellAgent variant download attempt (more info ...)trojan-activity        URL
52440MALWARE-OTHER Win.Trojan.LazyCat variant download attempt (more info ...)trojan-activity        URL
52441MALWARE-OTHER Win.Trojan.LazyCat variant download attempt (more info ...)trojan-activity        URL
52442MALWARE-OTHER Win.Trojan.Mimikatz variant download attempt (more info ...)trojan-activity        URL
52443MALWARE-OTHER Win.Trojan.Mimikatz variant download attempt (more info ...)trojan-activity        URL
52446MALWARE-OTHER Doc.Malware.Gamaredon variant second stage download detected (more info ...)trojan-activity        URL
52447MALWARE-OTHER Doc.Malware.Gamaredon variant third stage download detected (more info ...)trojan-activity        URL
52448MALWARE-OTHER Doc.Malware.Gamaredon variant third stage download detected (more info ...)trojan-activity        URL
52452MALWARE-OTHER Win.Ransomware.Zeppelin download attempt (more info ...)trojan-activity        URL
52453MALWARE-OTHER Win.Ransomware.Zeppelin download attempt (more info ...)trojan-activity        URL
52478PROTOCOL-SCADA Schneider Electric IGSS integer underflow attempt (more info ...)attempted-user  2013-0657      
52480SERVER-WEBAPP LibreNMS addhost command injection attempt (more info ...)web-application-attack  2018-20434      URL
52490FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0972 attack attempt (more info ...)attempted-user  2019-5187      URL
52491FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0972 attack attempt (more info ...)attempted-user  2019-5187      URL
52492FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0972 attack attempt (more info ...)attempted-user  2019-5187      URL
52493FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0972 attack attempt (more info ...)attempted-user  2019-5187      URL
52495FILE-OTHER TRUFFLEHUNTER TALOS-2019-0971 attack attempt (more info ...)attempted-dos  2019-5183      URL
52496FILE-OTHER TRUFFLEHUNTER TALOS-2019-0971 attack attempt (more info ...)attempted-dos  2019-5183      URL
52505PROTOCOL-OTHER Aruba Mobility Controller PAPI memory corruption attempt (more info ...)attempted-admin  2018-7081      URL
52512SERVER-WEBAPP Citrix ADC and Gateway arbitrary code execution attempt (more info ...)web-application-attack  2019-19781      URL
52513SERVER-WEBAPP Citrix ADC and Gateway arbitrary code execution attempt (more info ...)web-application-attack  2019-19781      URL
52518MALWARE-TOOLS Win.Trojan.ReverseTcpPowershell download attempt (more info ...)trojan-activity        URL
52519MALWARE-TOOLS Win.Trojan.ReverseTcpPowershell download attempt (more info ...)trojan-activity        URL
52551SERVER-WEBAPP Technicolor TD5130v2 TD5336 routers command injection attempt (more info ...)web-application-attack  2019-18396      
52552SERVER-WEBAPP Technicolor TD5130v2 TD5336 routers command injection attempt (more info ...)web-application-attack  2019-18396      
52553SERVER-WEBAPP Technicolor TD5130v2 TD5336 routers command injection attempt (more info ...)web-application-attack  2019-18396      
52570FILE-OTHER TRUFFLEHUNTER TALOS-2019-0973 attack attempt (more info ...)attempted-user  2019-5188      URL
52571FILE-OTHER TRUFFLEHUNTER TALOS-2019-0973 attack attempt (more info ...)attempted-user  2019-5188      URL
52572MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        URL
52573MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        
52574MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        URL
52575MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        URL
52576MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        URL
52577MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        
52578MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        URL
52579MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        URL
52580MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        URL
52581MALWARE-OTHER Win.Trojan.ZeroCleare variant payload download attempt (more info ...)trojan-activity        URL
52584EXPLOIT-KIT BottleEK landing page detected (more info ...)trojan-activity        URL
52585EXPLOIT-KIT BottleEK variant outbound connection (more info ...)trojan-activity        URL
52587EXPLOIT-KIT BottleEK landing page detected (more info ...)trojan-activity        URL
52590SERVER-WEBAPP Enigma NMS command injection attempt (more info ...)web-application-attack  2019-16072      
52591SERVER-WEBAPP Enigma NMS command injection attempt (more info ...)web-application-attack  2019-16072      
52592SERVER-WEBAPP Enigma NMS command injection attempt (more info ...)web-application-attack  2019-16072      
52603SERVER-WEBAPP Citrix ADC and Gateway arbitrary code execution attempt (more info ...)web-application-attack  2019-19781      URL
52615MALWARE-OTHER Win.Downloader.Whiteshadow variant outbound connection detected (more info ...)trojan-activity        URL
52616MALWARE-OTHER Win.Downloader.Whiteshadow variant second stage download detected (more info ...)trojan-activity        URL
52620SERVER-WEBAPP Citrix ADC and Gateway arbitrary code execution attempt (more info ...)web-application-attack  2019-19781      URL
52634INDICATOR-COMPROMISE Website defacement via HTTP PUT request attempt (more info ...)misc-attack        
52635INDICATOR-COMPROMISE Website defacement via HTTP PUT request attempt (more info ...)misc-attack        
52637SERVER-WEBAPP eMerge E3 Access Controller command injection attempt (more info ...)web-application-attack  2019-7256      URL
52638SERVER-WEBAPP eMerge E3 Access Controller command injection attempt (more info ...)web-application-attack  2019-7256      URL
52639SERVER-WEBAPP eMerge E3 Access Controller command injection attempt (more info ...)web-application-attack  2019-7256      URL
52640SERVER-WEBAPP eMerge E3 Access Controller command injection attempt (more info ...)web-application-attack  2019-7256      URL
52650MALWARE-OTHER Win.Trojan.vxCrypter malicious executable download attempt (more info ...)trojan-activity        URL
52651MALWARE-OTHER Win.Trojan.vxCrypter malicious executable download attempt (more info ...)trojan-activity        URL
52652MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52653MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52654MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52655MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52656MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52657MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
52660EXPLOIT-KIT Spelevo Exploit Kit landing page detected (more info ...)attempted-user        URL
52662MALWARE-OTHER Citrix ADC and Gateway backdoor upload attempt (more info ...)web-application-attack  2019-19781      URL
52666FILE-OTHER TRUFFLEHUNTER TALOS-2020-0981 attack attempt (more info ...)attempted-user        URL
52667FILE-OTHER TRUFFLEHUNTER TALOS-2020-0981 attack attempt (more info ...)attempted-user        URL
52668FILE-OTHER TRUFFLEHUNTER TALOS-2020-0982 attack attempt (more info ...)attempted-user        URL
52669FILE-OTHER TRUFFLEHUNTER TALOS-2020-0982 attack attempt (more info ...)attempted-user        URL
52818FILE-OTHER TRUFFLEHUNTER TALOS-2020-0979 attack attempt (more info ...)attempted-user        URL
52819FILE-OTHER TRUFFLEHUNTER TALOS-2020-0979 attack attempt (more info ...)attempted-user        URL
52827SERVER-WEBAPP Tomato router web interface bruteforce scan attempt (more info ...)web-application-attack        
52836PROTOCOL-SNMP TRUFFLEHUNTER TALOS-2020-0976 attack attempt (more info ...)attempted-dos  2020-6059      URL
52838PROTOCOL-SNMP TRUFFLEHUNTER TALOS-2020-0975 attack attempt (more info ...)attempted-dos  2020-6058      URL
52839PROTOCOL-SNMP TRUFFLEHUNTER TALOS-2020-0975 attack attempt (more info ...)attempted-dos  2020-6058      URL
52840PROTOCOL-SNMP TRUFFLEHUNTER TALOS-2020-0975 attack attempt (more info ...)attempted-dos  2020-6058      URL
52841PROTOCOL-SNMP TRUFFLEHUNTER TALOS-2020-0975 attack attempt (more info ...)attempted-dos  2020-6058      URL
52842FILE-OTHER TRUFFLEHUNTER TALOS-2020-0978 attack attempt (more info ...)attempted-user  2020-6101      URL
52843FILE-OTHER TRUFFLEHUNTER TALOS-2020-0978 attack attempt (more info ...)attempted-user  2020-6101      URL
52850FILE-OTHER TRUFFLEHUNTER TALOS-2020-0980 attack attempt (more info ...)attempted-user        URL
52851FILE-OTHER TRUFFLEHUNTER TALOS-2020-0980 attack attempt (more info ...)attempted-user        URL
53000FILE-OTHER TRUFFLEHUNTER TALOS-2020-0983 attack attempt (more info ...)attempted-user        URL
53001FILE-OTHER TRUFFLEHUNTER TALOS-2020-0983 attack attempt (more info ...)attempted-user        URL
53002FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0993 attack attempt (more info ...)attempted-user  2020-6069      URL
53003FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0993 attack attempt (more info ...)attempted-user  2020-6069      URL
53004FILE-OTHER TRUFFLEHUNTER TALOS-2020-0988 attack attempt (more info ...)attempted-user  2020-6070      URL
53005FILE-OTHER TRUFFLEHUNTER TALOS-2020-0988 attack attempt (more info ...)attempted-user  2020-6070      URL
53006FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0998 attack attempt (more info ...)attempted-user  2020-6075      URL
53007FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0998 attack attempt (more info ...)attempted-user  2020-6075      URL
53008FILE-OTHER TRUFFLEHUNTER TALOS-2020-0989 attack attempt (more info ...)attempted-user  2020-6065      URL
53009FILE-OTHER TRUFFLEHUNTER TALOS-2020-0989 attack attempt (more info ...)attempted-user  2020-6065      URL
53011FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0991 attack attempt (more info ...)attempted-user  2020-6067      URL
53012FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0991 attack attempt (more info ...)attempted-user  2020-6067      URL
53013FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0991 attack attempt (more info ...)attempted-user  2020-6067      URL
53014FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0991 attack attempt (more info ...)attempted-user  2020-6067      URL
53018MALWARE-OTHER Win.Dropper.Fareitvb-7564626-0 download attempt (more info ...)trojan-activity        URL
53019MALWARE-OTHER Win.Trojan.VBGeneric-7564976-0 download attempt (more info ...)trojan-activity        URL
53020MALWARE-OTHER Win.Dropper.Ursu-7564978-0 download attempt (more info ...)trojan-activity        URL
53022MALWARE-OTHER Win.Malware.Pakes-7564913-0 download attempt (more info ...)trojan-activity        URL
53023MALWARE-OTHER Win.Ransomware.Ako variant payload download attempt (more info ...)trojan-activity        URL
53024MALWARE-OTHER Win.Ransomware.Ako variant payload download attempt (more info ...)trojan-activity        URL
53026MALWARE-OTHER Win.Dropper.NetWire-7565080-0 download attempt (more info ...)trojan-activity        URL
53027MALWARE-OTHER Win.Dropper.NetWire-7565085-0 download attempt (more info ...)trojan-activity        URL
53028MALWARE-OTHER Win.Dropper.NetWire-7565095-0 download attempt (more info ...)trojan-activity        URL
53030MALWARE-OTHER Win.Dropper.NetWire-7565093-0 download attempt (more info ...)trojan-activity        URL
53049PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1006 attack attempt (more info ...)denial-of-service  2020-6086      URL
53061OS-WINDOWS Windows kernel win32k driver elevation of privilege attempt (more info ...)attempted-admin  2020-0721      URL
53062OS-WINDOWS Windows kernel win32k driver elevation of privilege attempt (more info ...)attempted-admin  2020-0721      URL
53064SERVER-WEBAPP Jenkins Stapler web framework Accept-Language Header directory traversal attempt (more info ...)web-application-attack  2018-1999002      URL
53065FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1004 attack attempt (more info ...)attempted-user  2020-6082      URL
53066FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1004 attack attempt (more info ...)attempted-user  2020-6082      URL
53067FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0999 attack attempt (more info ...)attempted-user  2020-6076      URL
53068FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0999 attack attempt (more info ...)attempted-user  2020-6076      URL
53071SERVER-OTHER TRUFFLEHUNTER TALOS-2020-0996 attack attempt (more info ...)attempted-user  2020-6073      URL
53074SERVER-WEBAPP Axis Network Camera command injection attempt (more info ...)web-application-attack  2018-10660      
53075SERVER-WEBAPP Axis Network Camera authorization bypass attempt (more info ...)web-application-attack  2018-10663      
53077SERVER-WEBAPP Axis Network Camera command injection attempt (more info ...)web-application-attack  2018-10660      
53078SERVER-WEBAPP Axis Network Camera command injection attempt (more info ...)web-application-attack  2018-10660      
53090MALWARE-TOOLS Malicious HTML application download attempt (more info ...)trojan-activity  2017-11882      URL
53093FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1012 attack attempt (more info ...)attempted-user        URL
53094FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1012 attack attempt (more info ...)attempted-user        URL
53097FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1009 attack attempt (more info ...)attempted-user  2020-6089      URL
53098FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1009 attack attempt (more info ...)attempted-user  2020-6089      URL
53099SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1000 attack attempt (more info ...)attempted-user  2020-6077      URL
53105SERVER-ORACLE Oracle WebLogic unsafe deserialization remote code execution attempt (more info ...)attempted-user  2019-2890      URL
53106MALWARE-OTHER Win.Trojan.Snake malicious executable download attempt (more info ...)trojan-activity        URL
53109SERVER-OTHER RabbitMQ X-Reason HTTP header denial-of-service attempt (more info ...)denial-of-service  2019-11287      URL
53114FILE-PDF TRUFFLEHUNTER TALOS-2020-1013 attack attempt (more info ...)attempted-user  2020-6092      URL
53115FILE-PDF TRUFFLEHUNTER TALOS-2020-1013 attack attempt (more info ...)attempted-user  2020-6092      URL
53125PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1005 attack attempt (more info ...)attempted-dos  2020-6083      URL
53126PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1008 attack attempt (more info ...)attempted-dos  2020-6088      URL
53127PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1007 attack attempt (more info ...)attempted-dos  2020-6086      URL
53128PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1007 attack attempt (more info ...)attempted-dos  2020-6087      URL
53129MALWARE-OTHER Doc.Dropper.Carrotbat variant download attempt (more info ...)trojan-activity        
53130MALWARE-OTHER Doc.Downloader.Carrotbat variant download attempt (more info ...)trojan-activity        URL
53133MALWARE-OTHER Doc.Downloader.Carrotbat variant download attempt (more info ...)trojan-activity        URL
53134MALWARE-OTHER Doc.Downloader.Carrotbat variant download attempt (more info ...)trojan-activity        URL
53135MALWARE-OTHER Doc.Dropper.Carrotbat variant download attempt (more info ...)trojan-activity        
53136MALWARE-OTHER Doc.Downloader.Carrotbat variant download attempt (more info ...)trojan-activity        URL
53137MALWARE-OTHER Doc.Downloader.Carrotbat variant download attempt (more info ...)trojan-activity        URL
53138MALWARE-OTHER Doc.Downloader.Carrotbat variant download attempt (more info ...)trojan-activity        URL
53156MALWARE-OTHER Doc.Dropper.CrimsonRAT download attempt (more info ...)trojan-activity        URL
53157MALWARE-OTHER Doc.Dropper.CrimsonRAT download attempt (more info ...)trojan-activity        URL
53158MALWARE-OTHER Win.Trojan.CrimsonRAT download attempt (more info ...)trojan-activity        URL
53159MALWARE-OTHER Win.Trojan.ObliqueRAT download attempt (more info ...)trojan-activity        URL
53160MALWARE-OTHER Win.Trojan.ObliqueRAT download attempt (more info ...)trojan-activity        URL
53161MALWARE-OTHER Win.Trojan.ObliqueRAT download attempt (more info ...)trojan-activity        URL
53162MALWARE-OTHER Win.Trojan.ObliqueRAT download attempt (more info ...)trojan-activity        URL
53163MALWARE-OTHER Doc.Dropper.ObliqueRAT download attempt (more info ...)trojan-activity        URL
53164MALWARE-OTHER Doc.Dropper.ObliqueRat download attempt (more info ...)trojan-activity        URL
53165MALWARE-OTHER Win.Trojan.CrimsonRAT download attempt (more info ...)trojan-activity        URL
53166MALWARE-OTHER Win.Trojan.CrimsonRAT download attempt (more info ...)trojan-activity        URL
53167MALWARE-OTHER Win.Trojan.CrimsonRAT download attempt (more info ...)trojan-activity        URL
53177MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53178MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53179MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53180MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53181MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53182MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53183MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53184MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53185MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53186MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53187MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53188MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53189MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53190MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53191MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53192MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53193MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53194MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53195MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53196MALWARE-OTHER Doc.Trojan.Valyria variant download attempt (more info ...)trojan-activity        URL
53197MALWARE-OTHER Win.Keylogger.WindowsKeylogger variant download attempt (more info ...)trojan-activity        URL
53198MALWARE-OTHER Win.Keylogger.WindowsKeylogger variant download attempt (more info ...)trojan-activity        URL
53207MALWARE-OTHER Win.Trojan.AZORult malicious executable download attempt (more info ...)trojan-activity        URL
53208MALWARE-OTHER Win.Trojan.AZORult malicious executable download attempt (more info ...)trojan-activity        URL
53213PROTOCOL-OTHER MQTT Connect control packet detected (more info ...)misc-activity        URL
53214PROTOCOL-OTHER Cesanta Mongoose MQTT integer overflow attempt (more info ...)attempted-dos  2019-19307      URL
53215MALWARE-OTHER Win.Dropper.Bifrost-7594702-0 download attempt (more info ...)trojan-activity        URL
53216MALWARE-OTHER Win.Dropper.Bifrost-7594703-0 download attempt (more info ...)trojan-activity        URL
53217MALWARE-OTHER Win.Dropper.Bifrost-7594755-0 download attempt (more info ...)trojan-activity        URL
53218MALWARE-OTHER Win.Dropper.Bifrost-7594716-0 download attempt (more info ...)trojan-activity        URL
53219MALWARE-OTHER Win.Trojan.Fakevimes-7594788-0 download attempt (more info ...)trojan-activity        URL
53220MALWARE-OTHER Win.Trojan.Darkkomet-7594783-0 download attempt (more info ...)trojan-activity        URL
53221MALWARE-OTHER Win.Trojan.Aepwbrt-7594784-0 download attempt (more info ...)trojan-activity        URL
53222MALWARE-OTHER Win.Trojan.Fakevimes-7594778-0 download attempt (more info ...)trojan-activity        URL
53223MALWARE-OTHER Win.Dropper.Upatre-7594799-0 download attempt (more info ...)trojan-activity        URL
53224MALWARE-OTHER Win.Trojan.Fakevimes-7594780-0 download attempt (more info ...)trojan-activity        URL
53245SERVER-WEBAPP OpenEMR command injection attempt (more info ...)web-application-attack  2019-3968      URL
53247SERVER-WEBAPP OpenEMR command injection attempt (more info ...)web-application-attack  2019-3968      URL
53248SERVER-WEBAPP OpenEMR command injection attempt (more info ...)web-application-attack  2019-3968      URL
53252FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1017 attack attempt (more info ...)attempted-user  2020-6094      URL
53253FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1017 attack attempt (more info ...)attempted-user  2020-6094      URL
53254FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1017 attack attempt (more info ...)attempted-user  2020-6094      URL
53255FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1017 attack attempt (more info ...)attempted-user  2020-6094      URL
53257OS-WINDOWS TRUFFLEHUNTER TALOS-2020-1016 attack attempt (more info ...)attempted-recon        URL
53258OS-WINDOWS TRUFFLEHUNTER TALOS-2020-1016 attack attempt (more info ...)attempted-recon        URL
53274MALWARE-OTHER Win.Dropper.NetWire-7597092-0 download attempt (more info ...)trojan-activity        URL
53276MALWARE-OTHER Win.Dropper.NetWire-7597059-0 download attempt (more info ...)trojan-activity        URL
53278MALWARE-OTHER Win.Dropper.NetWire-7597060-0 download attempt (more info ...)trojan-activity        URL
53280MALWARE-OTHER Win.Dropper.NetWire-7597094-0 download attempt (more info ...)trojan-activity        URL
53281MALWARE-OTHER Win.Dropper.NetWire-7597061-0 download attempt (more info ...)trojan-activity        URL
53283MALWARE-OTHER Win.Trojan.Xtrat-7597808-0 download attempt (more info ...)trojan-activity        URL
53284MALWARE-OTHER Win.Dropper.Vebzenpak-7597842-0 download attempt (more info ...)trojan-activity        URL
53285MALWARE-OTHER Win.Dropper.NetWire-7597077-0 download attempt (more info ...)trojan-activity        URL
53286MALWARE-OTHER Win.Dropper.NetWire-7597078-0 download attempt (more info ...)trojan-activity        URL
53288MALWARE-OTHER Win.Dropper.NetWire-7597079-0 download attempt (more info ...)trojan-activity        URL
53289MALWARE-OTHER Win.Dropper.NetWire-7597111-0 download attempt (more info ...)trojan-activity        URL
53290MALWARE-OTHER Win.Trojan.Generic-7597876-0 download attempt (more info ...)trojan-activity        URL
53291MALWARE-OTHER Win.Dropper.NetWire-7597112-0 download attempt (more info ...)trojan-activity        URL
53292MALWARE-OTHER Win.Packed.Generic-7596389-0 download attempt (more info ...)trojan-activity        URL
53293MALWARE-OTHER Win.Dropper.NetWire-7597080-0 download attempt (more info ...)trojan-activity        URL
53294MALWARE-OTHER Win.Packed.Generic-7596390-0 download attempt (more info ...)trojan-activity        URL
53296MALWARE-OTHER Win.Dropper.NetWire-7597081-0 download attempt (more info ...)trojan-activity        URL
53298MALWARE-OTHER Win.Packed.Filerepmalware-7596392-0 download attempt (more info ...)trojan-activity        URL
53299MALWARE-OTHER Win.Dropper.NetWire-7597114-0 download attempt (more info ...)trojan-activity        URL
53300MALWARE-OTHER Win.Dropper.NetWire-7597049-0 download attempt (more info ...)trojan-activity        URL
53302MALWARE-OTHER Win.Dropper.NetWire-7597115-0 download attempt (more info ...)trojan-activity        URL
53303MALWARE-OTHER Win.Dropper.NetWire-7597083-0 download attempt (more info ...)trojan-activity        URL
53304MALWARE-OTHER Win.Trojan.Generic-7596394-0 download attempt (more info ...)trojan-activity        URL
53305MALWARE-OTHER Win.Dropper.NetWire-7597050-0 download attempt (more info ...)trojan-activity        URL
53306MALWARE-OTHER Win.Dropper.NetWire-7597084-0 download attempt (more info ...)trojan-activity        URL
53307MALWARE-OTHER Win.Dropper.NetWire-7597116-0 download attempt (more info ...)trojan-activity        URL
53308MALWARE-OTHER Win.Dropper.NetWire-7597051-0 download attempt (more info ...)trojan-activity        URL
53311MALWARE-OTHER Win.Dropper.NetWire-7597117-0 download attempt (more info ...)trojan-activity        URL
53312MALWARE-OTHER Win.Dropper.NetWire-7597052-0 download attempt (more info ...)trojan-activity        URL
53315MALWARE-OTHER Win.Dropper.NetWire-7597118-0 download attempt (more info ...)trojan-activity        URL
53316MALWARE-OTHER Win.Dropper.NetWire-7597053-0 download attempt (more info ...)trojan-activity        URL
53318MALWARE-OTHER Win.Dropper.NetWire-7597086-0 download attempt (more info ...)trojan-activity        URL
53319MALWARE-OTHER Win.Dropper.NetWire-7597087-0 download attempt (more info ...)trojan-activity        URL
53321MALWARE-OTHER Win.Dropper.NetWire-7597120-0 download attempt (more info ...)trojan-activity        URL
53323MALWARE-OTHER Win.Dropper.NetWire-7597055-0 download attempt (more info ...)trojan-activity        URL
53326MALWARE-OTHER Win.Dropper.NetWire-7597056-0 download attempt (more info ...)trojan-activity        URL
53328MALWARE-OTHER Win.Dropper.NetWire-7597090-0 download attempt (more info ...)trojan-activity        URL
53329MALWARE-OTHER Win.Dropper.NetWire-7597057-0 download attempt (more info ...)trojan-activity        URL
53330MALWARE-OTHER Win.Trojan.Jaik-7597790-0 download attempt (more info ...)trojan-activity        URL
53332MALWARE-OTHER Win.Ransomware.Ryuk variant payload download attempt (more info ...)trojan-activity        URL
53333MALWARE-OTHER Win.Ransomware.Ryuk variant payload download attempt (more info ...)trojan-activity        URL
53334MALWARE-OTHER Win.Trojan.Agent variant payload download attempt (more info ...)trojan-activity        URL
53335MALWARE-OTHER Win.Ransomware.Ryuk variant payload download attempt (more info ...)trojan-activity        URL
53336MALWARE-OTHER Win.Ransomware.Ryuk variant payload download attempt (more info ...)trojan-activity        URL
53337MALWARE-OTHER Win.Trojan.Agent variant payload download attempt (more info ...)trojan-activity        URL
53344OS-MOBILE Android Binder use after free exploit attempt (more info ...)attempted-admin  2019-2215      
53345OS-MOBILE Android Binder use after free exploit attempt (more info ...)attempted-admin  2019-2215      
53356MALWARE-TOOLS Win.Worm.Emotet WiFi Spreader variant download attempt (more info ...)trojan-activity        URL
53357MALWARE-TOOLS Win.Worm.Emotet WiFi Spreader variant download attempt (more info ...)trojan-activity        URL
53358MALWARE-TOOLS Win.Worm.Emotet WiFi Spreader variant download attempt (more info ...)trojan-activity        URL
53359MALWARE-TOOLS Win.Worm.Emotet WiFi Spreader variant download attempt (more info ...)trojan-activity        URL
53361MALWARE-OTHER Win.Dropper.Kuluoz-7599049-0 download attempt (more info ...)trojan-activity        URL
53364MALWARE-OTHER Pdf.Downloader.Mozart malicious PDF download attempt (more info ...)trojan-activity        URL
53365MALWARE-OTHER Js.Dropper.Mozart payload download attempt (more info ...)trojan-activity        URL
53366MALWARE-OTHER Pdf.Downloader.Mozart malicious PDF download attempt (more info ...)trojan-activity        URL
53376SERVER-OTHER Exim unauthenticated remote code execution attempt (more info ...)attempted-user  2019-15846      URL
53377SERVER-OTHER Exim unauthenticated remote code execution attempt (more info ...)attempted-user  2019-15846      URL
53378SERVER-OTHER Exim unauthenticated remote code execution attempt (more info ...)attempted-user  2019-15846      URL
53394MALWARE-TOOLS Rat.Trojan.Generic variant download attempt (more info ...)trojan-activity        URL
53395MALWARE-TOOLS Rat.Trojan.Generic variant download attempt (more info ...)trojan-activity        URL
53396MALWARE-TOOLS Win.Trojan.Generic variant download attempt (more info ...)trojan-activity        URL
53398MALWARE-TOOLS Win.Malware.Generic variant download attempt (more info ...)trojan-activity        URL
53418SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1018 attack attempt (more info ...)attempted-dos  2020-6095      URL
53430SERVER-WEBAPP rConfig authenticated remote code execution attempt (more info ...)web-application-attack  2019-19509      URL
53433SERVER-WEBAPP Zoho ManageEngine Desktop Central directory traversal attempt (more info ...)web-application-attack  2020-10189      
53434SERVER-WEBAPP Zoho ManageEngine Desktop Central directory traversal attempt (more info ...)web-application-attack  2020-10189      
53435SERVER-WEBAPP Zoho ManageEngine Desktop Central directory traversal attempt (more info ...)web-application-attack  2020-10189      
53436OS-WINDOWS Windows RDP Gateway Server denial of service attempt (more info ...)attempted-dos  2020-0609      URL
53449SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53450SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53451SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53452SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53453SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53454SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53455SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53456SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53457SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53458SERVER-OTHER Oracle WebLogic Server IIOP remote code execution attempt (more info ...)attempted-user  2020-2551      
53485FILE-PDF TRUFFLEHUNTER TALOS-2020-1028 attack attempt (more info ...)attempted-user  2020-9607      URL
53486FILE-PDF TRUFFLEHUNTER TALOS-2020-1028 attack attempt (more info ...)attempted-user  2020-9607      URL
53507SERVER-WEBAPP Zyxel NAS devices command injection attempt (more info ...)web-application-attack  2020-9054      URL
53508SERVER-WEBAPP Zyxel NAS devices command injection attempt (more info ...)web-application-attack  2020-9054      URL
53509SERVER-WEBAPP Zyxel NAS devices command injection attempt (more info ...)web-application-attack  2020-9054      URL
53510SERVER-WEBAPP Zyxel NAS devices command injection attempt (more info ...)web-application-attack  2020-9054      URL
53511MALWARE-OTHER Win.Trojan.Sodinokibi-7641431-0 download attempt (more info ...)trojan-activity        URL
53512MALWARE-OTHER Win.Trojan.Sodinokibi-7641431-0 download attempt (more info ...)trojan-activity        URL
53525MALWARE-OTHER Win.Dropper.Tdss-7643790-0 download attempt (more info ...)trojan-activity        URL
53526MALWARE-OTHER Win.Dropper.Tdss-7643790-0 download attempt (more info ...)trojan-activity        URL
53531OS-WINDOWS TRUFFLEHUNTER TALOS-2020-1033 attack attempt (more info ...)attempted-admin        URL
53532OS-WINDOWS TRUFFLEHUNTER TALOS-2020-1033 attack attempt (more info ...)attempted-admin        URL
53547SERVER-WEBAPP TP LINK TL-WR849N Access Point command injection attempt (more info ...)web-application-attack  2020-9374      URL
53548SERVER-WEBAPP TP LINK TL-WR849N Access Point command injection attempt (more info ...)web-application-attack  2020-9374      URL
53558SERVER-WEBAPP Codesys V3 WebVisu remote heap overflow attempt (more info ...)attempted-dos  2020-10245      
53562SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1030 attack attempt (more info ...)attempted-dos  2020-6098      URL
53563FILE-PDF TRUFFLEHUNTER TALOS-2020-1031 attack attempt (more info ...)attempted-user  2020-9609      URL
53564FILE-PDF TRUFFLEHUNTER TALOS-2020-1031 attack attempt (more info ...)attempted-user  2020-9609      URL
53569FILE-IDENTIFY BIMx file magic detected (more info ...)misc-activity        
53570FILE-IDENTIFY BIMx file magic detected (more info ...)misc-activity        
53571FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1032 attack attempt (more info ...)attempted-user  2020-6099      URL
53572FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1032 attack attempt (more info ...)attempted-user  2020-6099      URL
53573FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1032 attack attempt (more info ...)attempted-user  2020-6099      URL
53574FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1032 attack attempt (more info ...)attempted-user  2020-6099      URL
53575FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1032 attack attempt (more info ...)attempted-user  2020-6099      URL
53576FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1032 attack attempt (more info ...)attempted-user  2020-6099      URL
53577FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1032 attack attempt (more info ...)attempted-user  2020-6099      URL
53578FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2020-1032 attack attempt (more info ...)attempted-user  2020-6099      URL
53585MALWARE-OTHER Win.Packed.njRAT-7646465-0 download attempt (more info ...)trojan-activity        URL
53586MALWARE-OTHER Win.Packed.njRAT-7646465-0 download attempt (more info ...)trojan-activity        URL
53589SERVER-WEBAPP DrayTek multiple products command injection attempt (more info ...)web-application-attack  2020-8515      URL
53590SERVER-WEBAPP DrayTek multiple products command injection attempt (more info ...)web-application-attack  2020-8515      URL
53591SERVER-WEBAPP DrayTek multiple products command injection attempt (more info ...)web-application-attack  2020-8515      URL
53592SERVER-WEBAPP DrayTek multiple products command injection attempt (more info ...)web-application-attack  2020-8515      URL
53599FILE-PDF TRUFFLEHUNTER TALOS-2020-1044 attack attempt (more info ...)attempted-user        URL
53600FILE-PDF TRUFFLEHUNTER TALOS-2020-1044 attack attempt (more info ...)attempted-user        URL
53601MALWARE-OTHER Win.Dropper.Gh0stRAT-7647657-0 download attempt (more info ...)trojan-activity        URL
53602MALWARE-OTHER Win.Dropper.Gh0stRAT-7647657-0 download attempt (more info ...)trojan-activity        URL
53632MALWARE-OTHER Win.Trojan.Panda malicious DLL loader attempt (more info ...)trojan-activity        URL
53633MALWARE-OTHER Win.Trojan.Panda malicious loader and decryptor attempt (more info ...)trojan-activity        URL
53634MALWARE-OTHER Win.Trojan.Panda malicious DLL loader attempt (more info ...)trojan-activity        URL
53635MALWARE-OTHER Win.Trojan.Panda malicious loader and decryptor attempt (more info ...)trojan-activity        URL
53636MALWARE-OTHER Win.Trojan.Panda malicious DLL loader attempt (more info ...)trojan-activity        URL
53637MALWARE-OTHER Win.Trojan.Panda file download attempt (more info ...)trojan-activity        URL
53638MALWARE-OTHER Win.Trojan.Panda file download attempt (more info ...)trojan-activity        URL
53639MALWARE-OTHER Win.Trojan.Panda file download attempt (more info ...)trojan-activity        URL
53640MALWARE-OTHER Win.Trojan.Panda file download attempt (more info ...)trojan-activity        URL
53641MALWARE-TOOLS Win.Trojan.Panda file loader and decryptor attempt (more info ...)trojan-activity        URL
53642MALWARE-TOOLS Win.Trojan.Panda malicious DLL loader attempt (more info ...)trojan-activity        URL
53643MALWARE-TOOLS Win.Trojan.Panda file loader and decryptor attempt (more info ...)trojan-activity        URL
53644MALWARE-TOOLS Win.Trojan.Panda file loader and decryptor attempt (more info ...)trojan-activity        URL
53645MALWARE-TOOLS Win.Trojan.Panda file loader and decryptor attempt (more info ...)trojan-activity        URL
53646MALWARE-OTHER Win.Trojan.WildPressure malicious executable download attempt (more info ...)trojan-activity        URL
53647MALWARE-OTHER Win.Trojan.WildPressure malicious executable download attempt (more info ...)trojan-activity        URL
53656MALWARE-OTHER Cobalt Strike x86 executable download attempt (more info ...)trojan-activity        URL
53657MALWARE-OTHER Cobalt Strike x86 executable download attempt (more info ...)trojan-activity        URL
53658MALWARE-OTHER Cobalt Strike x64 executable download attempt (more info ...)trojan-activity        URL
53659MALWARE-OTHER Cobalt Strike x64 executable download attempt (more info ...)trojan-activity        URL
53663MALWARE-OTHER Win.Trojan.MedusaLocker malicious executable download attempt (more info ...)trojan-activity        URL
53664MALWARE-OTHER Win.Trojan.MedusaLocker malicious executable download attempt (more info ...)trojan-activity        URL
53665MALWARE-OTHER Win.Trojan.MedusaLocker malicious executable download attempt (more info ...)trojan-activity        URL
53684FILE-OTHER TRUFFLEHUNTER TALOS-2020-1047 attack attempt (more info ...)attempted-user  2020-6107      URL
53685FILE-OTHER TRUFFLEHUNTER TALOS-2020-1047 attack attempt (more info ...)attempted-user  2020-6107      URL
53686BROWSER-OTHER TRUFFLEHUNTER TALOS-2020-1055 attack attempt (more info ...)attempted-user  2020-6109      URL
53690MALWARE-OTHER Win.Trojan.PoetRAT malicious document download attempt (more info ...)trojan-activity        URL
53713MALWARE-OTHER Win.Dropper.Kuluoz-7671761-0 download attempt (more info ...)trojan-activity        URL
53714MALWARE-OTHER Win.Dropper.Kuluoz-7671761-0 download attempt (more info ...)trojan-activity        URL
53729FILE-OTHER TRUFFLEHUNTER TALOS-2020-1050 attack attempt (more info ...)attempted-admin  2020-6108      URL
53730FILE-OTHER TRUFFLEHUNTER TALOS-2020-1050 attack attempt (more info ...)attempted-admin  2020-6108      URL
53731FILE-OTHER TRUFFLEHUNTER TALOS-2020-1046 attack attempt (more info ...)attempted-recon  2020-6104      URL
53732FILE-OTHER TRUFFLEHUNTER TALOS-2020-1046 attack attempt (more info ...)attempted-recon  2020-6104      URL
53733SERVER-WEBAPP IBM Data Risk Manager directory traversal attempt (more info ...)web-application-attack  2020-4430      
53734SERVER-WEBAPP IBM Data Risk Manager nmap scan command execution attempt (more info ...)web-application-attack        
53738MALWARE-OTHER Win.Trojan.Kwampirs malicious executable download attempt (more info ...)trojan-activity        URL
53739MALWARE-OTHER Win.Trojan.Kwampirs malicious executable download attempt (more info ...)trojan-activity        URL
53740MALWARE-OTHER Win.Trojan.Kwampirs malicious executable download attempt (more info ...)trojan-activity        URL
53741MALWARE-OTHER Win.Trojan.Kwampirs malicious executable download attempt (more info ...)trojan-activity        URL
53742FILE-OTHER TRUFFLEHUNTER TALOS-2020-1048 attack attempt (more info ...)attempted-recon  2020-6106      URL
53743FILE-OTHER TRUFFLEHUNTER TALOS-2020-1048 attack attempt (more info ...)attempted-recon  2020-6106      URL
53744SERVER-ORACLE Oracle WebLogic Coherence library remote code execution attempt (more info ...)attempted-user  2020-2883      
53745MALWARE-OTHER Doc.Downloader.Aggah payload download attempt (more info ...)trojan-activity        URL
53746MALWARE-OTHER Doc.Downloader.Aggah payload download attempt (more info ...)trojan-activity        URL
53747MALWARE-OTHER Doc.Downloader.Aggah payload download attempt (more info ...)trojan-activity        URL
53748MALWARE-OTHER Doc.Downloader.Aggah payload download attempt (more info ...)trojan-activity        URL
53757MALWARE-OTHER CobaltStrike beacon.dll download attempt (more info ...)trojan-activity        URL
53758MALWARE-OTHER CobaltStrike beacon.dll download attempt (more info ...)trojan-activity        URL
53759BROWSER-OTHER TRUFFLEHUNTER TALOS-2020-1053 attack attempt (more info ...)attempted-user        URL
53760BROWSER-OTHER TRUFFLEHUNTER TALOS-2020-1053 attack attempt (more info ...)attempted-user        URL
53761BROWSER-OTHER TRUFFLEHUNTER TALOS-2020-1054 attack attempt (more info ...)attempted-user        URL
53762BROWSER-OTHER TRUFFLEHUNTER TALOS-2020-1054 attack attempt (more info ...)attempted-user        URL
53769SERVER-MAIL iOS MobileMail Maild heap overflow attempt (more info ...)attempted-user  2020-9819      URL
53778MALWARE-OTHER Win.Dropper.Kuluoz-7696398-0 download attempt (more info ...)trojan-activity        URL
53779MALWARE-OTHER Win.Dropper.Kuluoz-7696398-0 download attempt (more info ...)trojan-activity        URL
53782MALWARE-OTHER Win.Dropper.DarkKomet-7685261-0 download attempt (more info ...)trojan-activity        URL
53783MALWARE-OTHER Win.Dropper.DarkKomet-7685261-0 download attempt (more info ...)trojan-activity        URL
53784MALWARE-OTHER Win.Worm.Kuluoz-7700057-0 download attempt (more info ...)trojan-activity        URL
53785MALWARE-OTHER Win.Worm.Kuluoz-7700057-0 download attempt (more info ...)trojan-activity        URL
53786MALWARE-OTHER Win.Worm.Kuluoz-7700058-0 download attempt (more info ...)trojan-activity        URL
53787MALWARE-OTHER Win.Worm.Kuluoz-7700058-0 download attempt (more info ...)trojan-activity        URL
53788MALWARE-OTHER Win.Dropper.DarkKomet-7685740-0 download attempt (more info ...)trojan-activity        URL
53789MALWARE-OTHER Win.Dropper.DarkKomet-7685740-0 download attempt (more info ...)trojan-activity        URL
53790MALWARE-OTHER PUA.Win.File.Multiplug-7693689-0 download attempt (more info ...)trojan-activity        URL
53791MALWARE-OTHER PUA.Win.File.Multiplug-7693689-0 download attempt (more info ...)trojan-activity        URL
53793MALWARE-OTHER Win.Dropper.Remcos payload download attempt (more info ...)trojan-activity        URL
53794MALWARE-OTHER Win.Dropper.Remcos payload download attempt (more info ...)trojan-activity        URL
53795MALWARE-OTHER Win.Dropper.Remcos payload download attempt (more info ...)trojan-activity        URL
53796MALWARE-OTHER Win.Dropper.Remcos payload download attempt (more info ...)trojan-activity        URL
53797MALWARE-OTHER Win.Dropper.XtremeRAT-7708589-0 download attempt (more info ...)trojan-activity        URL
53798MALWARE-OTHER Win.Dropper.XtremeRAT-7708589-0 download attempt (more info ...)trojan-activity        URL
53799MALWARE-OTHER Win.Dropper.XtremeRAT-7709124-0 download attempt (more info ...)trojan-activity        URL
53800MALWARE-OTHER Win.Dropper.XtremeRAT-7709124-0 download attempt (more info ...)trojan-activity        URL
53825MALWARE-OTHER Win.Malware.Zbot-7727211-0 download attempt (more info ...)trojan-activity        URL
53826MALWARE-OTHER Win.Malware.Zbot-7727211-0 download attempt (more info ...)trojan-activity        URL
53831MALWARE-OTHER Win.Downloader.Kuluoz-7752297-0 download attempt (more info ...)trojan-activity        URL
53832MALWARE-OTHER Win.Downloader.Kuluoz-7752297-0 download attempt (more info ...)trojan-activity        URL
53837MALWARE-OTHER Win.Trojan.Maze variant download attempt (more info ...)trojan-activity        URL
53846MALWARE-OTHER Win.Trojan.Ursnif malicious outbound connection attempt - gravity generated detection (more info ...)trojan-activity        URL
53854MALWARE-OTHER Win.Packed.Zusy-7759444-0 download attempt (more info ...)trojan-activity        URL
53855MALWARE-OTHER Win.Packed.Zusy-7759444-0 download attempt (more info ...)trojan-activity        URL
53860SERVER-WEBAPP Centurylink router unauthenticated administrator account disable attempt (more info ...)web-application-attack  2019-19639      
53862SERVER-WEBAPP D-Link DIR-859 UPnP subscribe command injection attempt (more info ...)web-application-attack  2019-17621      
53863SERVER-WEBAPP D-Link DIR-859 UPnP subscribe command injection attempt (more info ...)web-application-attack  2019-17621      
53876MALWARE-TOOLS Win.Trojan.EnigmaSpark download attempt (more info ...)trojan-activity        URL
53877MALWARE-TOOLS Win.Trojan.EnigmaSpark download attempt (more info ...)trojan-activity        URL
53888MALWARE-OTHER Win.Dropper.Gh0stRAT-7779557-0 download attempt (more info ...)trojan-activity        URL
53889MALWARE-OTHER Win.Dropper.Gh0stRAT-7779557-0 download attempt (more info ...)trojan-activity        URL
53890MALWARE-OTHER Win.Packed.Zeroaccess-7779678-0 download attempt (more info ...)trojan-activity        URL
53891MALWARE-OTHER Win.Packed.Zeroaccess-7779678-0 download attempt (more info ...)trojan-activity        URL
53910MALWARE-OTHER Win.Dropper.Ursnif-7781451-0 download attempt (more info ...)trojan-activity        URL
53911MALWARE-OTHER Win.Dropper.Ursnif-7781451-0 download attempt (more info ...)trojan-activity        URL
53920MALWARE-OTHER Win.Malware.Genpack-7782249-0 download attempt (more info ...)trojan-activity        URL
53921MALWARE-OTHER Win.Malware.Genpack-7782249-0 download attempt (more info ...)trojan-activity        URL
53922MALWARE-OTHER Win.Trojan.Zusy-7779081-0 download attempt (more info ...)trojan-activity        URL
53923MALWARE-OTHER Win.Trojan.Zusy-7779081-0 download attempt (more info ...)trojan-activity        URL
53938MALWARE-OTHER Win.Dropper.Dorkbot-7781513-0 download attempt (more info ...)trojan-activity        URL
53939MALWARE-OTHER Win.Dropper.Dorkbot-7781513-0 download attempt (more info ...)trojan-activity        URL
53944SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1067 attack attempt (more info ...)web-application-attack  2020-6114      URL
53945SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1067 attack attempt (more info ...)web-application-attack  2020-6114      URL
53949FILE-PDF TRUFFLEHUNTER TALOS-2020-1063 attack attempt (more info ...)attempted-user  2020-6113      URL
53952MALWARE-OTHER Win.Dropper.Agent payload download attempt (more info ...)trojan-activity        URL
53953MALWARE-OTHER Win.Dropper.Agent payload download attempt (more info ...)trojan-activity        URL
53954MALWARE-OTHER Win.Dropper.Agent payload download attempt (more info ...)trojan-activity        URL
53955MALWARE-OTHER Win.Dropper.Agent payload download attempt (more info ...)trojan-activity        URL
53959SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1065 attack attempt (more info ...)attempted-admin        URL
53960MALWARE-OTHER Win.Trojan.Ursnif malicious outbound connection attempt - gravity generated detection (more info ...)trojan-activity        URL
53965MALWARE-OTHER Win.Dropper.Kuluoz-7784063-0 download attempt (more info ...)trojan-activity        URL
53966MALWARE-OTHER Win.Dropper.Kuluoz-7784063-0 download attempt (more info ...)trojan-activity        URL
53967SERVER-WEBAPP TerraMaster NAS user and group creation command injection attempt (more info ...)web-application-attack  2018-13418      URL
53968SERVER-WEBAPP TerraMaster NAS user and group creation command injection attempt (more info ...)web-application-attack  2018-13418      URL
53969SERVER-WEBAPP TerraMaster NAS user and group creation command injection attempt (more info ...)web-application-attack  2018-13418      URL
53970SERVER-WEBAPP TerraMaster NAS user and group creation command injection attempt (more info ...)web-application-attack  2018-13418      URL
53977MALWARE-OTHER Win.Dropper.Agent payload download attempt (more info ...)trojan-activity        
53978MALWARE-OTHER Win.Dropper.Agent payload download attempt (more info ...)trojan-activity        
53979MALWARE-OTHER Win.Dropper.Shiz-7784396-0 download attempt (more info ...)trojan-activity        URL
53980MALWARE-OTHER Win.Dropper.Shiz-7784396-0 download attempt (more info ...)trojan-activity        URL
53983OS-WINDOWS Windows print spooler elevation of privilege attempt (more info ...)attempted-admin  2020-1048      URL
53984OS-WINDOWS Windows print spooler elevation of privilege attempt (more info ...)attempted-admin  2020-1048      URL
53990FILE-PDF TRUFFLEHUNTER TALOS-2020-1062 attack attempt (more info ...)attempted-user  2020-6112      URL
53991FILE-PDF TRUFFLEHUNTER TALOS-2020-1062 attack attempt (more info ...)attempted-user  2020-6112      URL
53992FILE-PDF TRUFFLEHUNTER TALOS-2020-1068 attack attempt (more info ...)attempted-user  2020-6115      URL
53993FILE-PDF TRUFFLEHUNTER TALOS-2020-1068 attack attempt (more info ...)attempted-user  2020-6115      URL
54003SERVER-WEBAPP Axway SecureTransport XML external entity injection attempt (more info ...)web-application-attack  2019-14277      
54007SERVER-ORACLE Oracle Weblogic T3 remote code execution attempt (more info ...)attempted-user  2020-2883      URL
54008SERVER-ORACLE Oracle Weblogic T3 remote code execution attempt (more info ...)attempted-user  2020-2883      URL
54010FILE-PDF TRUFFLEHUNTER TALOS-2020-1070 attack attempt (more info ...)attempted-user  2020-6116      URL
54011FILE-PDF TRUFFLEHUNTER TALOS-2020-1070 attack attempt (more info ...)attempted-user  2020-6116      URL
54013MALWARE-OTHER Win.Trojan.Ursnif malicious outbound connection attempt - gravity generated detection (more info ...)trojan-activity        URL
54015MALWARE-OTHER Win.Dropper.Bifrost-7846624-0 download attempt (more info ...)trojan-activity        URL
54016MALWARE-OTHER Win.Dropper.Bifrost-7846624-0 download attempt (more info ...)trojan-activity        URL
54020MALWARE-OTHER Win.Trojan.Hancitor COVID-19 subject phishing email attempt (more info ...)trojan-activity        URL
54030SERVER-OTHER SaltStack wheel directory traversal attempt (more info ...)web-application-attack  2020-11652      URL
54031SERVER-OTHER SaltStack wheel directory traversal attempt (more info ...)web-application-attack  2020-11652      URL
54032SERVER-OTHER SaltStack wheel directory traversal attempt (more info ...)web-application-attack  2020-11652      URL
54033SERVER-OTHER SaltStack wheel directory traversal attempt (more info ...)web-application-attack  2020-11652      URL
54037MALWARE-OTHER Win.Trojan.Ursnif malicious outbound connection attempt - gravity generated detection (more info ...)trojan-activity        URL
54038MALWARE-OTHER Win.Packed.Zeroaccess-7880797-0 download attempt (more info ...)trojan-activity        URL
54039MALWARE-OTHER Win.Packed.Zeroaccess-7880797-0 download attempt (more info ...)trojan-activity        URL
54044MALWARE-OTHER Win.Dropper.Evilnum malicious LNK file download attempt (more info ...)trojan-activity        URL
54045MALWARE-OTHER Win.Dropper.Evilnum malicious LNK file download attempt (more info ...)trojan-activity        URL
54047FILE-PDF TRUFFLEHUNTER TALOS-2020-1084 attack attempt (more info ...)attempted-user  2020-6146      URL
54048FILE-PDF TRUFFLEHUNTER TALOS-2020-1084 attack attempt (more info ...)attempted-user  2020-6146      URL
54049SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1087 attack attempt (more info ...)web-application-attack        URL
54050SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1087 attack attempt (more info ...)web-application-attack        URL
54056MALWARE-OTHER Win.Trojan.BlackNET variant binary download attempt (more info ...)trojan-activity        URL
54071MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54072MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54073MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54074MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54075MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54076MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54077MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54078MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54079MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity        URL
54089MALWARE-OTHER Win.Dropper.DarkKomet-7946160-0 download attempt (more info ...)trojan-activity        URL
54090MALWARE-OTHER Win.Dropper.DarkKomet-7946160-0 download attempt (more info ...)trojan-activity        URL
54091MALWARE-OTHER Win.Dropper.Kuluoz-7977738-0 download attempt (more info ...)trojan-activity        URL
54092MALWARE-OTHER Win.Dropper.Kuluoz-7977738-0 download attempt (more info ...)trojan-activity        URL
54093MALWARE-OTHER Win.Dropper.Zeus-7944985-0 download attempt (more info ...)trojan-activity        URL
54094MALWARE-OTHER Win.Dropper.Zeus-7944985-0 download attempt (more info ...)trojan-activity        URL
54095MALWARE-OTHER Win.Trojan.CobaltStrike powershell beacon download attempt (more info ...)trojan-activity        URL
54096MALWARE-OTHER Win.Trojan.CobaltStrike powershell beacon download attempt (more info ...)trojan-activity        URL
54097MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity        URL
54098MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity        URL
54099MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity        URL
54100MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity        URL
54101MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity        URL
54108MALWARE-OTHER Win.Trojan.Mikey-7914350-0 download attempt (more info ...)trojan-activity        URL
54109MALWARE-OTHER Win.Trojan.Mikey-7914350-0 download attempt (more info ...)trojan-activity        URL
54110MALWARE-OTHER Html.Trojan.CobaltStrike HTML payload download attempt (more info ...)trojan-activity        URL
54111MALWARE-OTHER Html.Trojan.CobaltStrike HTML payload download attempt (more info ...)trojan-activity        URL
54112MALWARE-OTHER Html.Trojan.CobaltStrike HTML payload download attempt (more info ...)trojan-activity        URL
54113MALWARE-OTHER Html.Trojan.CobaltStrike HTML payload download attempt (more info ...)trojan-activity        URL
54114MALWARE-OTHER Html.Trojan.CobaltStrike powershell payload download attempt (more info ...)trojan-activity        URL
54115MALWARE-OTHER Html.Trojan.CobaltStrike powershell payload download attempt (more info ...)trojan-activity        URL
54116MALWARE-OTHER Html.Trojan.CobaltStrike VBA payload download attempt (more info ...)trojan-activity        URL
54117MALWARE-OTHER Html.Trojan.CobaltStrike VBA payload download attempt (more info ...)trojan-activity        URL
54120FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
54121FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2019-0912 attack attempt (more info ...)attempted-user  2019-1430      URL
54123SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6132      URL
54124SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6132      URL
54125SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6132      URL
54126SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6133      URL
54127SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6133      URL
54128SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6133      URL
54129SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6134      URL
54130SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6134      URL
54131SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1077 attack attempt (more info ...)web-application-attack  2020-6134      URL
54132SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1072 attack attempt (more info ...)web-application-attack  2020-6122      URL
54133SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1072 attack attempt (more info ...)web-application-attack  2020-6122      URL
54134SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1072 attack attempt (more info ...)web-application-attack  2020-6122      URL
54135SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1073 attack attempt (more info ...)web-application-attack  2020-6124      URL
54136SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1073 attack attempt (more info ...)web-application-attack  2020-6124      URL
54137SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1073 attack attempt (more info ...)web-application-attack  2020-6124      URL
54138SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1074 attack attempt (more info ...)web-application-attack  2020-6125      URL
54139SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1075 attack attempt (more info ...)web-application-attack  2020-6128      URL
54140SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1075 attack attempt (more info ...)web-application-attack  2020-6128      URL
54141SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1075 attack attempt (more info ...)web-application-attack  2020-6128      URL
54142SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1076 attack attempt (more info ...)web-application-attack  2020-6131      URL
54143SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1076 attack attempt (more info ...)web-application-attack  2020-6131      URL
54144SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1076 attack attempt (more info ...)web-application-attack  2020-6131      URL
54145MALWARE-OTHER Win.Trojan.Ursnif malicious outbound connection attempt - gravity generated detection (more info ...)trojan-activity        URL
54146MALWARE-OTHER Win.Worm.Dorkbot-7993070-0 download attempt (more info ...)trojan-activity        URL
54147MALWARE-OTHER Win.Worm.Dorkbot-7993070-0 download attempt (more info ...)trojan-activity        URL
54148MALWARE-OTHER Win.Trojan.Vobfus-7994999-0 download attempt (more info ...)trojan-activity        URL
54149MALWARE-OTHER Win.Trojan.Vobfus-7994999-0 download attempt (more info ...)trojan-activity        URL
54150MALWARE-OTHER Win.Adware.Hao123 outbound connection attempt (more info ...)trojan-activity        URL
54151MALWARE-OTHER Win.Adware.Hao123 outbound connection attempt (more info ...)trojan-activity        URL
54152MALWARE-OTHER Win.Adware.Hao123 outbound connection attempt (more info ...)trojan-activity        URL
54153MALWARE-OTHER Win.Trojan.Turla malicious executable download attempt (more info ...)trojan-activity        URL
54154MALWARE-OTHER Win.Trojan.Turla malicious executable download attempt (more info ...)trojan-activity        URL
54156POLICY-OTHER LDAP bind success (more info ...)not-suspicious        URL
54157SERVER-OTHER VMWare Directory Service authentication bypass attempt (more info ...)attempted-admin  2020-3952      URL
54180MALWARE-OTHER Cobalt Strike system profiling attempt (more info ...)trojan-activity        URL
54181MALWARE-OTHER Cobalt Strike system profiling attempt (more info ...)trojan-activity        URL
54182MALWARE-OTHER Cobalt Strike system profiling attempt (more info ...)trojan-activity        URL
54184SERVER-OTHER lodash defaultsDeep prototype pollution attempt (more info ...)attempted-user  2019-10744      
54187MALWARE-OTHER Win.Ransomware.RagnarLocker initial download (more info ...)trojan-activity        URL
54188MALWARE-OTHER Win.Ransomware.RagnarLocker initial download (more info ...)trojan-activity        URL
54195SERVER-WEBAPP TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt (more info ...)web-application-attack  2020-12109      URL
54196SERVER-WEBAPP TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt (more info ...)web-application-attack  2020-12109      URL
54197SERVER-WEBAPP TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt (more info ...)web-application-attack  2020-12109      URL
54198SERVER-WEBAPP TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt (more info ...)web-application-attack  2020-12109      URL
54214SERVER-ORACLE Oracle iPlanet Web Server unauthenticated information disclosure attempt (more info ...)attempted-recon  2020-9315      URL
54218MALWARE-OTHER Win.Packed.Mikey-8009335-0 download attempt (more info ...)trojan-activity        URL
54219MALWARE-OTHER Win.Packed.Mikey-8009335-0 download attempt (more info ...)trojan-activity        URL
54226MALWARE-OTHER Win.Dropper.Ngrbot-8010339-0 download attempt (more info ...)trojan-activity        URL
54227MALWARE-OTHER Win.Dropper.Ngrbot-8010339-0 download attempt (more info ...)trojan-activity        URL
54228MALWARE-OTHER Win.Worm.Vobfus-8010482-0 download attempt (more info ...)trojan-activity        URL
54229MALWARE-OTHER Win.Worm.Vobfus-8010482-0 download attempt (more info ...)trojan-activity        URL
54251SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1080 attack attempt (more info ...)web-application-attack  2020-6140      URL
54252SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1080 attack attempt (more info ...)web-application-attack  2020-6140      URL
54253SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1080 attack attempt (more info ...)web-application-attack  2020-6140      URL
54254SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1082 attack attempt (more info ...)web-application-attack  2020-6142      URL
54255SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1082 attack attempt (more info ...)web-application-attack  2020-6142      URL
54256SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1082 attack attempt (more info ...)web-application-attack  2020-6142      URL
54257SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1083 attack attempt (more info ...)web-application-attack  2020-6144      URL
54258SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1083 attack attempt (more info ...)web-application-attack  2020-6144      URL
54259SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1078 attack attempt (more info ...)web-application-attack  2020-6135      URL
54260SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1078 attack attempt (more info ...)web-application-attack  2020-6135      URL
54261SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1078 attack attempt (more info ...)web-application-attack  2020-6135      URL
54262SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1079 attack attempt (more info ...)web-application-attack  2020-6136      URL
54263SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1079 attack attempt (more info ...)web-application-attack  2020-6136      URL
54264SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1079 attack attempt (more info ...)web-application-attack  2020-6136      URL
54265BROWSER-OTHER TRUFFLEHUNTER TALOS-2020-1088 attack attempt (more info ...)attempted-user        URL
54266BROWSER-OTHER TRUFFLEHUNTER TALOS-2020-1088 attack attempt (more info ...)attempted-user        URL
54267SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1081 attack attempt (more info ...)web-application-attack  2020-6141      URL
54268SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1081 attack attempt (more info ...)web-application-attack  2020-6141      URL
54269SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1081 attack attempt (more info ...)web-application-attack  2020-6141      URL
54272SERVER-WEBAPP Centreon Monitoring tool command injection attempt (more info ...)web-application-attack  2020-9463      URL
54273SERVER-WEBAPP Centreon Monitoring tool command injection attempt (more info ...)web-application-attack  2020-9463      URL
54274MALWARE-OTHER Win.Trojan.Vobfus-8010924-0 download attempt (more info ...)trojan-activity        URL
54275MALWARE-OTHER Win.Trojan.Vobfus-8010924-0 download attempt (more info ...)trojan-activity        URL
54276MALWARE-OTHER Win.Trojan.Ursnif malicious outbound connection attempt - gravity generated detection (more info ...)trojan-activity        URL
54277MALWARE-OTHER Win.Dropper.Zeus-8011051-0 download attempt (more info ...)trojan-activity        URL
54278MALWARE-OTHER Win.Dropper.Zeus-8011051-0 download attempt (more info ...)trojan-activity        URL
54279INDICATOR-COMPROMISE UPnP SUBSCRIBE Callback denial-of-service attempt (more info ...)attempted-dos  2020-12695      URL
54280INDICATOR-COMPROMISE UPnP SUBSCRIBE Callback denial-of-service attempt (more info ...)attempted-dos  2020-12695      URL
54282FILE-PDF TRUFFLEHUNTER TALOS-2020-1092 attack attempt (more info ...)attempted-user        URL
54283FILE-PDF TRUFFLEHUNTER TALOS-2020-1092 attack attempt (more info ...)attempted-user        URL
54290SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1091 attack attempt (more info ...)web-application-attack  2020-6145      URL
54307PUA-ADWARE Js.Adware.Agent variant redirect attempt (more info ...)trojan-activity        URL
54308FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6147      URL
54309FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6147      URL
54310FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6148      URL
54311FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6148      URL
54312FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6149      URL
54313FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6149      URL
54314FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6150      URL
54315FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6150      URL
54374MALWARE-OTHER Win.Trojan.IndigoDrop variant binary download attempt (more info ...)trojan-activity        URL
54377MALWARE-OTHER Win.Trojan.Zbot-8108321-0 download attempt (more info ...)trojan-activity        URL
54378MALWARE-OTHER Win.Trojan.Zbot-8108321-0 download attempt (more info ...)trojan-activity        URL
54385MALWARE-OTHER Win.Trojan.Qbot malicious executable download attempt (more info ...)trojan-activity        URL
54387MALWARE-OTHER Win.Trojan.Qbot malicious executable download attempt (more info ...)trojan-activity        URL
54389PROTOCOL-TELNET netkit-telnet server memory corruption attempt (more info ...)attempted-user  2020-10188      URL
54390FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1096 attack attempt (more info ...)attempted-user  2020-6152      URL
54391FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1096 attack attempt (more info ...)attempted-user  2020-6152      URL
54392OS-WINDOWS TRUFFLEHUNTER TALOS-2020-1098 attack attempt (more info ...)attempted-admin        URL
54393OS-WINDOWS TRUFFLEHUNTER TALOS-2020-1098 attack attempt (more info ...)attempted-admin        URL
54407MALWARE-OTHER Win.Dropper.Zeus-8336989-0 download attempt (more info ...)trojan-activity        URL
54408MALWARE-OTHER Win.Dropper.Zeus-8336989-0 download attempt (more info ...)trojan-activity        URL
54409MALWARE-OTHER Win.Dropper.Waledac-8338517-0 download attempt (more info ...)trojan-activity        URL
54410MALWARE-OTHER Win.Dropper.Waledac-8338517-0 download attempt (more info ...)trojan-activity        URL
54411FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1095 attack attempt (more info ...)attempted-user  2021-21833      URL
54412FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1095 attack attempt (more info ...)attempted-user  2021-21833      URL
54413FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1095 attack attempt (more info ...)attempted-user  2021-21833      URL
54414FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1095 attack attempt (more info ...)attempted-user  2021-21833      URL
54415FILE-OTHER TRUFFLEHUNTER TALOS-2020-1101 attack attempt (more info ...)attempted-user  2020-6155      URL
54416FILE-OTHER TRUFFLEHUNTER TALOS-2020-1101 attack attempt (more info ...)attempted-user  2020-6155      URL
54424MALWARE-OTHER Win.Dropper.NetWire-8359642-0 download attempt (more info ...)trojan-activity        URL
54425MALWARE-OTHER Win.Dropper.NetWire-8359642-0 download attempt (more info ...)trojan-activity        URL
54426MALWARE-OTHER Win.Dropper.Bifrost-8367128-0 download attempt (more info ...)trojan-activity        URL
54427MALWARE-OTHER Win.Dropper.Bifrost-8367128-0 download attempt (more info ...)trojan-activity        URL
54430FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6156      URL
54431FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-6156      URL
54432FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-13493      URL
54433FILE-OTHER TRUFFLEHUNTER TALOS-2020-1094 attack attempt (more info ...)attempted-user  2020-13493      URL
54436MALWARE-OTHER Win.Packed.Remcos-8401633-0 download attempt (more info ...)trojan-activity        URL
54437MALWARE-OTHER Win.Packed.Remcos-8401633-0 download attempt (more info ...)trojan-activity        URL
54438MALWARE-OTHER Win.Malware.Midie-8569260-0 download attempt (more info ...)trojan-activity        URL
54439MALWARE-OTHER Win.Malware.Midie-8569260-0 download attempt (more info ...)trojan-activity        URL
54462SERVER-WEBAPP F5 BIG-IP Traffic Management User Interface remote code execution attempt (more info ...)attempted-admin  2020-5903      URL
54463MALWARE-OTHER Win.Packed.Bladabindi-8460552-0 download attempt (more info ...)trojan-activity        URL
54464MALWARE-OTHER Win.Packed.Bladabindi-8460552-0 download attempt (more info ...)trojan-activity        URL
54465FILE-OTHER TRUFFLEHUNTER TALOS-2020-1102 attack attempt (more info ...)attempted-dos        URL
54466FILE-OTHER TRUFFLEHUNTER TALOS-2020-1102 attack attempt (more info ...)attempted-dos        URL
54467FILE-OTHER TRUFFLEHUNTER TALOS-2020-1105 attack attempt (more info ...)attempted-user  2020-13496      URL
54468FILE-OTHER TRUFFLEHUNTER TALOS-2020-1105 attack attempt (more info ...)attempted-user  2020-13496      URL
54469FILE-OTHER TRUFFLEHUNTER TALOS-2020-1105 attack attempt (more info ...)attempted-user  2020-13497      URL
54470FILE-OTHER TRUFFLEHUNTER TALOS-2020-1105 attack attempt (more info ...)attempted-user  2020-13497      URL
54471FILE-OTHER TRUFFLEHUNTER TALOS-2020-1105 attack attempt (more info ...)attempted-user  2020-13498      URL
54472FILE-OTHER TRUFFLEHUNTER TALOS-2020-1105 attack attempt (more info ...)attempted-user  2020-13498      URL
54473MALWARE-OTHER Win.Downloader.Nemucod variant download attempt (more info ...)attempted-user        URL
54474MALWARE-OTHER Win.Dropper.Adwind variant download attempt (more info ...)attempted-user        URL
54475MALWARE-OTHER Win.Downloader.Nemucod variant download attempt (more info ...)attempted-user        URL
54476MALWARE-OTHER Win.Dropper.Adwind variant download attempt (more info ...)attempted-user        URL
54477SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1097 attack attempt (more info ...)web-application-attack  2020-6153      URL
54478SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1106 attack attempt (more info ...)web-application-attack  2020-13501      URL
54479SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1107 attack attempt (more info ...)web-application-attack  2020-13502      URL
54480SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1108 attack attempt (more info ...)web-application-attack  2020-13521      URL
54481SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1109 attack attempt (more info ...)web-application-attack  2020-13508      URL
54482MALWARE-OTHER Win.Malware.Midie-8650925-0 download attempt (more info ...)trojan-activity        URL
54483MALWARE-OTHER Win.Malware.Midie-8650925-0 download attempt (more info ...)trojan-activity        URL
54484SERVER-WEBAPP F5 BIG-IP Traffic Management User Interface remote code execution attempt (more info ...)attempted-admin  2020-5902      URL
54488FILE-OTHER TRUFFLEHUNTER TALOS-2020-1104 attack attempt (more info ...)attempted-user  2020-13495      URL
54489FILE-OTHER TRUFFLEHUNTER TALOS-2020-1104 attack attempt (more info ...)attempted-user  2020-13495      URL
54490FILE-OTHER TRUFFLEHUNTER TALOS-2020-1104 attack attempt (more info ...)attempted-user  2020-13495      URL
54491FILE-OTHER TRUFFLEHUNTER TALOS-2020-1104 attack attempt (more info ...)attempted-user  2020-13495      URL
54492FILE-OTHER TRUFFLEHUNTER TALOS-2020-1103 attack attempt (more info ...)attempted-user  2020-13494      URL
54493FILE-OTHER TRUFFLEHUNTER TALOS-2020-1103 attack attempt (more info ...)attempted-user  2020-13494      URL
54495SERVER-OTHER Unitrends UEB 9 bpserverd unauthenticated remote command execution attempt (more info ...)attempted-admin  2017-12477      URL
54501OS-OTHER TRUFFLEHUNTER TALOS-2020-1118 attack attempt (more info ...)attempted-dos        URL
54502OS-OTHER TRUFFLEHUNTER TALOS-2020-1118 attack attempt (more info ...)attempted-dos        URL
54519FILE-OTHER TRUFFLEHUNTER TALOS-2020-1120 attack attempt (more info ...)attempted-user  2020-13520      URL
54520FILE-OTHER TRUFFLEHUNTER TALOS-2020-1120 attack attempt (more info ...)attempted-user  2020-13520      URL
54556SERVER-WEBAPP BSA Radar local file inclusion attempt (more info ...)attempted-recon  2020-14946      
54571SERVER-WEBAPP SAP NetWeaver AS LM Configuration Wizard directory traversal attempt (more info ...)web-application-attack  2020-6287      URL
54572SERVER-WEBAPP SAP NetWeaver AS LM Configuration Wizard directory traversal attempt (more info ...)web-application-attack  2020-6287      URL
54579FILE-OTHER TRUFFLEHUNTER TALOS-2020-1122 attack attempt (more info ...)attempted-recon  2020-13523      URL
54580FILE-OTHER TRUFFLEHUNTER TALOS-2020-1122 attack attempt (more info ...)attempted-recon  2020-13523      URL
54581FILE-OTHER TRUFFLEHUNTER TALOS-2020-1121 attack attempt (more info ...)attempted-dos  2020-13522      URL
54582FILE-OTHER TRUFFLEHUNTER TALOS-2020-1121 attack attempt (more info ...)attempted-dos  2020-13522      URL
54583SERVER-WEBAPP Eaton Intelligent Power Manager command injection attempt (more info ...)web-application-attack  2020-6651      URL
54586BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1124 attack attempt (more info ...)attempted-user        URL
54587BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1124 attack attempt (more info ...)attempted-user        URL
54588FILE-OTHER TRUFFLEHUNTER TALOS-2020-1125 attack attempt (more info ...)attempted-user  2020-13524      URL
54589FILE-OTHER TRUFFLEHUNTER TALOS-2020-1125 attack attempt (more info ...)attempted-user  2020-13524      URL
54602SERVER-WEBAPP Laravel Framework PendingCommand arbitrary command execution attempt (more info ...)web-application-attack  2019-9081      URL
54603SERVER-WEBAPP Laravel Framework PendingCommand arbitrary command execution attempt (more info ...)web-application-attack  2019-9081      URL
54604MALWARE-OTHER Win.Dropper.Dorkbot-8975168-0 download attempt (more info ...)trojan-activity        URL
54605MALWARE-OTHER Win.Dropper.Dorkbot-8975168-0 download attempt (more info ...)trojan-activity        URL
54606SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1126 attack attempt (more info ...)web-application-attack  2020-13526      URL
54607SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1126 attack attempt (more info ...)web-application-attack  2020-13526      URL
54608SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1126 attack attempt (more info ...)web-application-attack  2020-13526      URL
54613SERVER-OTHER Zoom client spoofed chat message attempt (more info ...)misc-attack  2018-15715      
54616SERVER-OTHER Zoom client unauthorized conference termination attempt (more info ...)misc-attack  2018-15715      
54631MALWARE-OTHER Vbs.Trojan.Dridex phishing email attempt (more info ...)trojan-activity        URL
54636SERVER-WEBAPP Zoom Client ZoomOpener remote code execution attempt (more info ...)attempted-user  2019-13567      
54637SERVER-WEBAPP Zoom Client ZoomOpener remote code execution attempt (more info ...)attempted-user  2019-13567      
54641MALWARE-OTHER Win.Trojan.Hackbit malicious dropper download attempt (more info ...)trojan-activity        URL
54643MALWARE-OTHER Win.Trojan.Hackbit malicious executable download attempt (more info ...)trojan-activity        URL
54645OS-OTHER TRUFFLEHUNTER TALOS-2020-1128 attack attempt (more info ...)attempted-user        URL
54646OS-OTHER TRUFFLEHUNTER TALOS-2020-1128 attack attempt (more info ...)attempted-user        URL
54647OS-OTHER TRUFFLEHUNTER TALOS-2020-1129 attack attempt (more info ...)attempted-dos        URL
54648OS-OTHER TRUFFLEHUNTER TALOS-2020-1129 attack attempt (more info ...)attempted-dos        URL
54665BROWSER-WEBKIT WebKit JIT compiler common subexpression elimination out of bounds access attempt (more info ...)attempted-user  2020-9802      
54666BROWSER-WEBKIT WebKit JIT compiler common subexpression elimination out of bounds access attempt (more info ...)attempted-user  2020-9802      
54669MALWARE-OTHER Win.Trojan.Ursnif malicious outbound connection attempt - gravity generated detection (more info ...)trojan-activity        URL
54670SERVER-WEBAPP Rockwell FactoryTalk View SE project list disclosure attempt (more info ...)web-application-attack  2020-12027      
54671SERVER-WEBAPP Rockwell FactoryTalk View SE project information disclosure attempt (more info ...)web-application-attack  2020-12027      
54672SERVER-WEBAPP Rockwell FactoryTalk View SE remote code execution attempt (more info ...)web-application-attack  2020-12028      
54673SERVER-WEBAPP Rockwell FactoryTalk View SE remote project backup download attempt (more info ...)web-application-attack  2020-12029      
54674SERVER-WEBAPP Rockwell FactoryTalk View SE remote project copy attempt (more info ...)web-application-attack  2020-12028      
54675SERVER-WEBAPP Rockwell FactoryTalk View SE remote project back directory traversal attempt (more info ...)web-application-attack  2020-12029      
54676MALWARE-OTHER Win.Ransomware.Cerber-9153999-0 download attempt (more info ...)trojan-activity        URL
54677MALWARE-OTHER Win.Ransomware.Cerber-9153999-0 download attempt (more info ...)trojan-activity        URL
54680OS-OTHER TRUFFLEHUNTER TALOS-2020-1131 attack attempt (more info ...)attempted-admin        URL
54681OS-OTHER TRUFFLEHUNTER TALOS-2020-1131 attack attempt (more info ...)attempted-admin        URL
54682OS-OTHER TRUFFLEHUNTER TALOS-2020-1130 attack attempt (more info ...)attempted-recon        URL
54683OS-OTHER TRUFFLEHUNTER TALOS-2020-1130 attack attempt (more info ...)attempted-recon        URL
54693MALWARE-OTHER Win.Trojan.Ursnif malicious outbound connection attempt - gravity generated detection (more info ...)trojan-activity        URL
54701OS-OTHER TRUFFLEHUNTER TALOS-2020-1133 attack attempt (more info ...)attempted-admin        URL
54702OS-OTHER TRUFFLEHUNTER TALOS-2020-1133 attack attempt (more info ...)attempted-admin        URL
54709MALWARE-OTHER Win.Packed.Zusy-9219867-0 download attempt (more info ...)trojan-activity        URL
54710MALWARE-OTHER Win.Packed.Zusy-9219867-0 download attempt (more info ...)trojan-activity        URL
54713MALWARE-OTHER Win.Dropper.Zeus-9220295-0 download attempt (more info ...)trojan-activity        URL
54714MALWARE-OTHER Win.Dropper.Zeus-9220295-0 download attempt (more info ...)trojan-activity        URL
54715MALWARE-OTHER Win.Dropper.Zeus-9220296-0 download attempt (more info ...)trojan-activity        URL
54716MALWARE-OTHER Win.Dropper.Zeus-9220296-0 download attempt (more info ...)trojan-activity        URL
54719MALWARE-OTHER Win.Trojan.Generic-9222527-0 download attempt (more info ...)trojan-activity        URL
54720MALWARE-OTHER Win.Trojan.Generic-9222527-0 download attempt (more info ...)trojan-activity        URL
54723MALWARE-OTHER Win.Downloader.Banload-9221789-0 download attempt (more info ...)trojan-activity        URL
54724MALWARE-OTHER Win.Downloader.Banload-9221789-0 download attempt (more info ...)trojan-activity        URL
54727SERVER-WEBAPP ZoomOpener remote code execution attempt (more info ...)attempted-user  2019-13567      
54728SERVER-WEBAPP ZoomOpener remote code execution attempt (more info ...)attempted-user  2019-13567      
54729OS-OTHER TRUFFLEHUNTER TALOS-2020-1138 attack attempt (more info ...)attempted-user        URL
54730OS-OTHER TRUFFLEHUNTER TALOS-2020-1138 attack attempt (more info ...)attempted-user        URL
54731OS-OTHER TRUFFLEHUNTER TALOS-2020-1134 attack attempt (more info ...)attempted-user        URL
54732OS-OTHER TRUFFLEHUNTER TALOS-2020-1134 attack attempt (more info ...)attempted-user        URL
54747MALWARE-OTHER Win.Ransomware.Nephilim variant binary download attempt (more info ...)trojan-activity        URL
54749MALWARE-OTHER Win.Ransomware.Nephilim variant binary download attempt (more info ...)trojan-activity        URL
54750MALWARE-OTHER Win.Ransomware.Nephilim variant binary download attempt (more info ...)trojan-activity        URL
54755SERVER-ORACLE Oracle Weblogic T3 remote code execution attempt (more info ...)attempted-user  2020-14645      URL
54756FILE-OTHER Grub malicious grub.cfg download attempt (more info ...)attempted-admin  2020-10713      
54757FILE-OTHER Grub malicious grub.cfg download attempt (more info ...)attempted-admin  2020-10713      
54771MALWARE-OTHER PUA.Win.Adware.Icloader-9255803-0 download attempt (more info ...)trojan-activity        URL
54772MALWARE-OTHER PUA.Win.Adware.Icloader-9255803-0 download attempt (more info ...)trojan-activity        URL
54777MALWARE-OTHER Win.Dropper.Cerber-9294966-0 download attempt (more info ...)trojan-activity        URL
54778MALWARE-OTHER Win.Dropper.Cerber-9294966-0 download attempt (more info ...)trojan-activity        URL
54791MALWARE-OTHER Win.Trojan.Kovter variant payload download attempt (more info ...)trojan-activity        URL
54792MALWARE-OTHER Win.Trojan.Kovter variant payload download attempt (more info ...)trojan-activity        URL
54798SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1135 attack attempt (more info ...)web-application-attack  2020-13527      URL
54799SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1135 attack attempt (more info ...)web-application-attack  2020-13527      URL
54800SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1135 attack attempt (more info ...)web-application-attack  2020-13527      URL
54817OS-WINDOWS Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2020-1337      URL
54818OS-WINDOWS Windows Print Spooler elevation of privilege attempt (more info ...)attempted-admin  2020-1337      URL
54823MALWARE-OTHER Doc.Downloader.LokiBot variant payload download attempt (more info ...)trojan-activity        URL
54824SERVER-WEBAPP Intellian Aptus Web arbitrary command execution attempt (more info ...)web-application-attack  2020-7980      URL
54829OS-OTHER TRUFFLEHUNTER TALOS-2020-1139 attack attempt (more info ...)attempted-user        URL
54830OS-OTHER TRUFFLEHUNTER TALOS-2020-1139 attack attempt (more info ...)attempted-user        URL
54832SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1143 attack attempt (more info ...)attempted-dos  2020-13530      URL
54866OS-OTHER TRUFFLEHUNTER TALOS-2020-1141 attack attempt (more info ...)attempted-dos        URL
54867OS-OTHER TRUFFLEHUNTER TALOS-2020-1141 attack attempt (more info ...)attempted-dos        URL
54874MALWARE-OTHER Win.Dropper.Gh0stRAT-9497863-0 download attempt (more info ...)trojan-activity        URL
54875MALWARE-OTHER Win.Dropper.Gh0stRAT-9497863-0 download attempt (more info ...)trojan-activity        URL
54881MALWARE-OTHER Js.Dropper.Duri variant inbound payload drop attempt (more info ...)trojan-activity        URL
54882MALWARE-OTHER Win.Malware.Duri inbound payload download attempt (more info ...)trojan-activity        URL
54883MALWARE-OTHER Js.Dropper.Agent variant inbound payload drop attempt (more info ...)trojan-activity        URL
54884MALWARE-OTHER Win.Malware.Duri inbound payload download attempt (more info ...)trojan-activity        URL
54885INDICATOR-COMPROMISE Win.Trojan.GoldenSpy download attempt (more info ...)trojan-activity        URL
54886INDICATOR-COMPROMISE Win.Trojan.GoldenSpy download attempt (more info ...)trojan-activity        URL
54887INDICATOR-COMPROMISE Win.Trojan.GoldenSpy download attempt (more info ...)trojan-activity        URL
54888INDICATOR-COMPROMISE Win.Trojan.GoldenSpy download attempt (more info ...)trojan-activity        URL
54889INDICATOR-COMPROMISE Win.Trojan.GoldenSpy download attempt (more info ...)trojan-activity        URL
54890INDICATOR-COMPROMISE Win.Trojan.GoldenSpy download attempt (more info ...)trojan-activity        URL
54897MALWARE-OTHER Win.Backdoor.Perlbot script variant download attempt (more info ...)trojan-activity        URL
54898MALWARE-OTHER Win.Backdoor.Perlbot script variant download attempt (more info ...)trojan-activity        URL
54904MALWARE-OTHER Win.Trojan.Dridex malicious file download attempt (more info ...)trojan-activity        URL
54906MALWARE-OTHER Win.Trojan.Dridex malicious executable download attempt (more info ...)trojan-activity        URL
54907MALWARE-OTHER Win.Trojan.Dridex malicious executable download attempt (more info ...)trojan-activity        URL
54910MALWARE-OTHER Win.Ransomware.LockBit ransomware download attempt (more info ...)trojan-activity        URL
54912MALWARE-OTHER Win.Ransomware.LockBit ransomware download attempt (more info ...)trojan-activity        URL
54913MALWARE-OTHER Win.Ransomware.LockBit ransomware download attempt (more info ...)trojan-activity        URL
54915MALWARE-OTHER Win.Ransomware.LockBit ransomware download attempt (more info ...)trojan-activity        URL
54916MALWARE-OTHER Win.Ransomware.LockBit ransomware download attempt (more info ...)trojan-activity        URL
54917MALWARE-OTHER Win.Ransomware.LockBit ransomware download attempt (more info ...)trojan-activity        URL
54920MALWARE-TOOLS Win.Packer.Salfram packed executable download attempt (more info ...)trojan-activity        URL
54921MALWARE-TOOLS Win.Packer.Salfram packed executable download attempt (more info ...)trojan-activity        URL
54922FILE-OTHER TRUFFLEHUNTER TALOS-2020-1145 attack attempt (more info ...)attempted-user  2020-13531      URL
54923FILE-OTHER TRUFFLEHUNTER TALOS-2020-1145 attack attempt (more info ...)attempted-user  2020-13531      URL
54926MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (more info ...)trojan-activity        URL
54927MALWARE-OTHER Win.Downloader.Vobfus-9622213-0 download attempt (more info ...)trojan-activity        URL
54938MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (more info ...)trojan-activity        URL
54939MALWARE-OTHER Win.Downloader.Upatre-9624350-0 download attempt (more info ...)trojan-activity        URL
54946MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (more info ...)trojan-activity        URL
54947MALWARE-OTHER Win.Malware.Upatre-9626237-0 download attempt (more info ...)trojan-activity        URL
54950MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (more info ...)trojan-activity        URL
54951MALWARE-OTHER Win.Malware.Ipamor-9625955-0 download attempt (more info ...)trojan-activity        URL
54962MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (more info ...)trojan-activity        URL
54963MALWARE-OTHER Win.Malware.Upatre-9626227-0 download attempt (more info ...)trojan-activity        URL
54974MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (more info ...)trojan-activity        URL
54975MALWARE-OTHER Win.Malware.Midie-9628915-0 download attempt (more info ...)trojan-activity        URL
54980MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (more info ...)trojan-activity        URL
54981MALWARE-OTHER Win.Packed.Virlock-9629641-0 download attempt (more info ...)trojan-activity        URL
54986MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (more info ...)trojan-activity        URL
54987MALWARE-OTHER Win.Malware.Upatre-9630071-0 download attempt (more info ...)trojan-activity        URL
54990MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (more info ...)trojan-activity        URL
54991MALWARE-OTHER Win.Trojan.Zeroaccess-9631318-0 download attempt (more info ...)trojan-activity        URL
55025MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (more info ...)trojan-activity        URL
55026MALWARE-OTHER Win.Keylogger.Multibanker-9635794-0 download attempt (more info ...)trojan-activity        URL
55027MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (more info ...)trojan-activity        URL
55028MALWARE-OTHER Win.Malware.Upatre-9636020-0 download attempt (more info ...)trojan-activity        URL
55031MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (more info ...)trojan-activity        URL
55032MALWARE-OTHER Win.Malware.Midie-9637278-0 download attempt (more info ...)trojan-activity        URL
55044MALWARE-OTHER Win.Malware.Zusy-9638751-0 download attempt (more info ...)trojan-activity        URL
55045MALWARE-OTHER Win.Malware.Zusy-9638751-0 download attempt (more info ...)trojan-activity        URL
55070MALWARE-OTHER Win.Tool.Zusy-9645230-0 download attempt (more info ...)trojan-activity        URL
55071MALWARE-OTHER Win.Tool.Zusy-9645230-0 download attempt (more info ...)trojan-activity        URL
55104MALWARE-OTHER Win.Malware.Midie-9651428-0 download attempt (more info ...)trojan-activity        URL
55105MALWARE-OTHER Win.Malware.Midie-9651428-0 download attempt (more info ...)trojan-activity        URL
55106MALWARE-OTHER Win.Malware.Midie-9651455-0 download attempt (more info ...)trojan-activity        URL
55107MALWARE-OTHER Win.Malware.Midie-9651455-0 download attempt (more info ...)trojan-activity        URL
55110MALWARE-OTHER Win.Malware.Blackmoon-9653251-0 download attempt (more info ...)trojan-activity        URL
55111MALWARE-OTHER Win.Malware.Blackmoon-9653251-0 download attempt (more info ...)trojan-activity        URL
55112MALWARE-OTHER Win.Worm.Slenfbot-9653263-0 download attempt (more info ...)trojan-activity        URL
55113MALWARE-OTHER Win.Worm.Slenfbot-9653263-0 download attempt (more info ...)trojan-activity        URL
55114MALWARE-OTHER Win.Ircbot.Ircbot-9653265-0 download attempt (more info ...)trojan-activity        URL
55115MALWARE-OTHER Win.Ircbot.Ircbot-9653265-0 download attempt (more info ...)trojan-activity        URL
55124MALWARE-OTHER Win.Malware.Tiny-9653715-0 download attempt (more info ...)trojan-activity        URL
55125MALWARE-OTHER Win.Malware.Tiny-9653715-0 download attempt (more info ...)trojan-activity        URL
55134MALWARE-OTHER Win.Downloader.Upatre-9655589-0 download attempt (more info ...)trojan-activity        URL
55135MALWARE-OTHER Win.Downloader.Upatre-9655589-0 download attempt (more info ...)trojan-activity        URL
55173MALWARE-OTHER Win.Trojan.Fugrafa-9733010-0 download attempt (more info ...)trojan-activity        URL
55174MALWARE-OTHER Win.Trojan.Fugrafa-9733010-0 download attempt (more info ...)trojan-activity        URL
55199MALWARE-OTHER Win.Trojan.Delf-9733756-0 download attempt (more info ...)trojan-activity        URL
55200MALWARE-OTHER Win.Trojan.Delf-9733756-0 download attempt (more info ...)trojan-activity        URL
55207SERVER-OTHER Intel AMT HTTP invalid chunk size attempt (more info ...)web-application-attack  2020-8758      
55208SERVER-OTHER Intel AMT HTTP invalid chunk size attempt (more info ...)web-application-attack  2020-8758      
55209SERVER-OTHER Intel AMT HTTP negative content-length attempt (more info ...)web-application-attack  2020-8758      
55210SERVER-OTHER Intel AMT HTTP negative content-length attempt (more info ...)web-application-attack  2020-8758      
55217MALWARE-OTHER Win.Malware.Agen-9740021-0 download attempt (more info ...)trojan-activity        URL
55218MALWARE-OTHER Win.Malware.Agen-9740021-0 download attempt (more info ...)trojan-activity        URL
55219MALWARE-OTHER Win.Malware.Scar-9741251-0 download attempt (more info ...)trojan-activity        URL
55220MALWARE-OTHER Win.Malware.Scar-9741251-0 download attempt (more info ...)trojan-activity        URL
55223MALWARE-OTHER Win.Ransomware.Darkside binary download attempt (more info ...)trojan-activity        URL
55224MALWARE-OTHER Win.Ransomware.Darkside binary download attempt (more info ...)trojan-activity        URL
55241MALWARE-OTHER Win.Trojan.Malwarex-9752454-0 download attempt (more info ...)trojan-activity        URL
55242MALWARE-OTHER Win.Trojan.Malwarex-9752454-0 download attempt (more info ...)trojan-activity        URL
55267MALWARE-OTHER PUA.Win.Downloader.Softcnapp-9753177-0 download attempt (more info ...)trojan-activity        URL
55268MALWARE-OTHER PUA.Win.Downloader.Softcnapp-9753177-0 download attempt (more info ...)trojan-activity        URL
55269MALWARE-OTHER Win.Packed.Fakesysdef-9753248-0 download attempt (more info ...)trojan-activity        URL
55270MALWARE-OTHER Win.Packed.Fakesysdef-9753248-0 download attempt (more info ...)trojan-activity        URL
55277MALWARE-OTHER Win.Malware.Agen-9753155-0 download attempt (more info ...)trojan-activity        URL
55278MALWARE-OTHER Win.Malware.Agen-9753155-0 download attempt (more info ...)trojan-activity        URL
55305MALWARE-OTHER Win.Malware.Cerbu-9753105-0 download attempt (more info ...)trojan-activity        URL
55306MALWARE-OTHER Win.Malware.Cerbu-9753105-0 download attempt (more info ...)trojan-activity        URL
55317MALWARE-OTHER Win.Packed.Urausy-9753546-0 download attempt (more info ...)trojan-activity        URL
55318MALWARE-OTHER Win.Packed.Urausy-9753546-0 download attempt (more info ...)trojan-activity        URL
55327MALWARE-OTHER Win.Malware.Generic-9753975-0 download attempt (more info ...)trojan-activity        URL
55328MALWARE-OTHER Win.Malware.Generic-9753975-0 download attempt (more info ...)trojan-activity        URL
55329MALWARE-OTHER Win.Packed.Generickdz-9754025-0 download attempt (more info ...)trojan-activity        URL
55330MALWARE-OTHER Win.Packed.Generickdz-9754025-0 download attempt (more info ...)trojan-activity        URL
55349MALWARE-OTHER Win.Ransomware.Reveton-9754374-0 download attempt (more info ...)trojan-activity        URL
55350MALWARE-OTHER Win.Ransomware.Reveton-9754374-0 download attempt (more info ...)trojan-activity        URL
55357MALWARE-OTHER Win.Packed.Urausy-9754886-0 download attempt (more info ...)trojan-activity        URL
55358MALWARE-OTHER Win.Packed.Urausy-9754886-0 download attempt (more info ...)trojan-activity        URL
55381MALWARE-OTHER Win.Packed.Reveton-9755111-0 download attempt (more info ...)trojan-activity        URL
55382MALWARE-OTHER Win.Packed.Reveton-9755111-0 download attempt (more info ...)trojan-activity        URL
55395MALWARE-OTHER Win.Trojan.Redosdru-9754696-0 download attempt (more info ...)trojan-activity        URL
55396MALWARE-OTHER Win.Trojan.Redosdru-9754696-0 download attempt (more info ...)trojan-activity        URL
55397MALWARE-OTHER PUA.Win.File.Neobar-9755067-0 download attempt (more info ...)trojan-activity        URL
55398MALWARE-OTHER PUA.Win.File.Neobar-9755067-0 download attempt (more info ...)trojan-activity        URL
55411MALWARE-OTHER Win.Malware.Bladabindi-9754646-0 download attempt (more info ...)trojan-activity        URL
55412MALWARE-OTHER Win.Malware.Bladabindi-9754646-0 download attempt (more info ...)trojan-activity        URL
55423MALWARE-OTHER Win.Dropper.DarkKomet-9755622-0 download attempt (more info ...)trojan-activity        URL
55424MALWARE-OTHER Win.Dropper.DarkKomet-9755622-0 download attempt (more info ...)trojan-activity        URL
55427MALWARE-OTHER Win.Dropper.DarkKomet-9755671-0 download attempt (more info ...)trojan-activity        URL
55428MALWARE-OTHER Win.Dropper.DarkKomet-9755671-0 download attempt (more info ...)trojan-activity        URL
55447MALWARE-OTHER Win.Trojan.Zbot-9756756-0 download attempt (more info ...)trojan-activity        URL
55448MALWARE-OTHER Win.Trojan.Zbot-9756756-0 download attempt (more info ...)trojan-activity        URL
55449MALWARE-OTHER Win.Downloader.Upatre-9756805-0 download attempt (more info ...)trojan-activity        URL
55450MALWARE-OTHER Win.Downloader.Upatre-9756805-0 download attempt (more info ...)trojan-activity        URL
55457MALWARE-OTHER Win.Trojan.Generickdz-9756772-0 download attempt (more info ...)trojan-activity        URL
55458MALWARE-OTHER Win.Trojan.Generickdz-9756772-0 download attempt (more info ...)trojan-activity        URL
55459MALWARE-OTHER Win.Trojan.Zegost-9756996-0 download attempt (more info ...)trojan-activity        URL
55460MALWARE-OTHER Win.Trojan.Zegost-9756996-0 download attempt (more info ...)trojan-activity        URL
55467MALWARE-OTHER Win.Malware.Magania-9757204-0 download attempt (more info ...)trojan-activity        URL
55468MALWARE-OTHER Win.Malware.Magania-9757204-0 download attempt (more info ...)trojan-activity        URL
55469MALWARE-OTHER Win.Malware.Nitol-9757205-0 download attempt (more info ...)trojan-activity        URL
55470MALWARE-OTHER Win.Malware.Nitol-9757205-0 download attempt (more info ...)trojan-activity        URL
55479MALWARE-OTHER Win.Malware.Zusy-9757531-0 download attempt (more info ...)trojan-activity        URL
55480MALWARE-OTHER Win.Malware.Zusy-9757531-0 download attempt (more info ...)trojan-activity        URL
55481MALWARE-OTHER Win.Packed.Hlux-9757571-0 download attempt (more info ...)trojan-activity        URL
55482MALWARE-OTHER Win.Packed.Hlux-9757571-0 download attempt (more info ...)trojan-activity        URL
55489MALWARE-OTHER Win.Trojan.Zeroaccess-9757775-0 download attempt (more info ...)trojan-activity        URL
55490MALWARE-OTHER Win.Trojan.Zeroaccess-9757775-0 download attempt (more info ...)trojan-activity        URL
55491MALWARE-OTHER Win.Packed.Reveton-9757778-0 download attempt (more info ...)trojan-activity        URL
55492MALWARE-OTHER Win.Packed.Reveton-9757778-0 download attempt (more info ...)trojan-activity        URL
55499MALWARE-OTHER Win.Ircbot.Ircbot-9757805-0 download attempt (more info ...)trojan-activity        URL
55500MALWARE-OTHER Win.Ircbot.Ircbot-9757805-0 download attempt (more info ...)trojan-activity        URL
55501MALWARE-OTHER Win.Trojan.Conjar-9757807-0 download attempt (more info ...)trojan-activity        URL
55502MALWARE-OTHER Win.Trojan.Conjar-9757807-0 download attempt (more info ...)trojan-activity        URL
55505MALWARE-OTHER Win.Packed.Ramnit-9757823-0 download attempt (more info ...)trojan-activity        URL
55506MALWARE-OTHER Win.Packed.Ramnit-9757823-0 download attempt (more info ...)trojan-activity        URL
55519MALWARE-OTHER Win.Trojan.Tinba-9758104-0 download attempt (more info ...)trojan-activity        URL
55520MALWARE-OTHER Win.Trojan.Tinba-9758104-0 download attempt (more info ...)trojan-activity        URL
55521MALWARE-OTHER Win.Packed.Urausy-9758034-0 download attempt (more info ...)trojan-activity        URL
55522MALWARE-OTHER Win.Packed.Urausy-9758034-0 download attempt (more info ...)trojan-activity        URL
55537MALWARE-OTHER Win.Packed.Trojanx-9758137-0 download attempt (more info ...)trojan-activity        URL
55538MALWARE-OTHER Win.Packed.Trojanx-9758137-0 download attempt (more info ...)trojan-activity        URL
55543MALWARE-OTHER Win.Trojan.Dorkbot-9758280-0 download attempt (more info ...)trojan-activity        URL
55544MALWARE-OTHER Win.Trojan.Dorkbot-9758280-0 download attempt (more info ...)trojan-activity        URL
55553MALWARE-OTHER Win.Ransomware.Reveton-9758363-0 download attempt (more info ...)trojan-activity        URL
55554MALWARE-OTHER Win.Ransomware.Reveton-9758363-0 download attempt (more info ...)trojan-activity        URL
55589MALWARE-OTHER Win.Trojan.Sinowal-9759014-0 download attempt (more info ...)trojan-activity        URL
55590MALWARE-OTHER Win.Trojan.Sinowal-9759014-0 download attempt (more info ...)trojan-activity        URL
55605MALWARE-OTHER Win.Worm.Gamarue-9759119-0 download attempt (more info ...)trojan-activity        URL
55606MALWARE-OTHER Win.Worm.Gamarue-9759119-0 download attempt (more info ...)trojan-activity        URL
55613MALWARE-OTHER Win.Packed.Reveton-9759475-0 download attempt (more info ...)trojan-activity        URL
55614MALWARE-OTHER Win.Packed.Reveton-9759475-0 download attempt (more info ...)trojan-activity        URL
55619MALWARE-OTHER Win.Malware.Zusy-9759529-0 download attempt (more info ...)trojan-activity        URL
55620MALWARE-OTHER Win.Malware.Zusy-9759529-0 download attempt (more info ...)trojan-activity        URL
55621MALWARE-OTHER Win.Worm.Zbot-9759575-0 download attempt (more info ...)trojan-activity        URL
55622MALWARE-OTHER Win.Worm.Zbot-9759575-0 download attempt (more info ...)trojan-activity        URL
55633MALWARE-OTHER Win.Trojan.Torr-9759942-0 download attempt (more info ...)trojan-activity        URL
55634MALWARE-OTHER Win.Trojan.Torr-9759942-0 download attempt (more info ...)trojan-activity        URL
55637SERVER-WEBAPP Pulse Connect Secure SSL VPN command injection attempt (more info ...)web-application-attack  2020-8218      URL
55638SERVER-WEBAPP Pulse Connect Secure SSL VPN command injection attempt (more info ...)web-application-attack  2020-8218      URL
55639SERVER-WEBAPP Pulse Connect Secure SSL VPN command injection attempt (more info ...)web-application-attack  2020-8218      URL
55640SERVER-WEBAPP Pulse Connect Secure SSL VPN command injection attempt (more info ...)web-application-attack  2020-8218      URL
55655MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (more info ...)trojan-activity        URL
55656MALWARE-OTHER Win.Packed.Zeroaccess-9760106-0 download attempt (more info ...)trojan-activity        URL
55671MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (more info ...)trojan-activity        URL
55672MALWARE-OTHER Win.Ransomware.Urausy-9760518-0 download attempt (more info ...)trojan-activity        URL
55695MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (more info ...)trojan-activity        URL
55696MALWARE-OTHER Win.Trojan.Rincux-9760859-0 download attempt (more info ...)trojan-activity        URL
55709MALWARE-OTHER Win.Trojan.Zeroaccess-9761339-0 download attempt (more info ...)trojan-activity        URL
55710MALWARE-OTHER Win.Trojan.Zeroaccess-9761339-0 download attempt (more info ...)trojan-activity        URL
55711MALWARE-OTHER Win.Packed.Tdss-9761341-0 download attempt (more info ...)trojan-activity        URL
55712MALWARE-OTHER Win.Packed.Tdss-9761341-0 download attempt (more info ...)trojan-activity        URL
55713MALWARE-OTHER Win.Dropper.Zbot-9761347-0 download attempt (more info ...)trojan-activity        URL
55714MALWARE-OTHER Win.Dropper.Zbot-9761347-0 download attempt (more info ...)trojan-activity        URL
55719MALWARE-OTHER Win.Malware.Nitol-9761421-0 download attempt (more info ...)trojan-activity        URL
55720MALWARE-OTHER Win.Malware.Nitol-9761421-0 download attempt (more info ...)trojan-activity        URL
55721MALWARE-OTHER Win.Malware.Magania-9761424-0 download attempt (more info ...)trojan-activity        URL
55722MALWARE-OTHER Win.Malware.Magania-9761424-0 download attempt (more info ...)trojan-activity        URL
55723MALWARE-OTHER Win.Malware.Magania-9761425-0 download attempt (more info ...)trojan-activity        URL
55724MALWARE-OTHER Win.Malware.Magania-9761425-0 download attempt (more info ...)trojan-activity        URL
55725MALWARE-OTHER Win.Malware.Magania-9761426-0 download attempt (more info ...)trojan-activity        URL
55726MALWARE-OTHER Win.Malware.Magania-9761426-0 download attempt (more info ...)trojan-activity        URL
55729MALWARE-OTHER Win.Trojan.Ircbot-9761414-0 download attempt (more info ...)trojan-activity        URL
55730MALWARE-OTHER Win.Trojan.Ircbot-9761414-0 download attempt (more info ...)trojan-activity        URL
55741FILE-IMAGE Foxit Reader parsing JPEG with ConvertToPDF remote code execution attempt (more info ...)attempted-user  2020-8844      URL
55742FILE-IMAGE Foxit Reader parsing JPEG with ConvertToPDF remote code execution attempt (more info ...)attempted-user  2020-8844      URL
55754MALWARE-OTHER Win.Malware.Nitol-9762149-0 download attempt (more info ...)trojan-activity        URL
55755MALWARE-OTHER Win.Malware.Nitol-9762149-0 download attempt (more info ...)trojan-activity        URL
55758MALWARE-OTHER Win.Malware.Magania-9762151-0 download attempt (more info ...)trojan-activity        URL
55759MALWARE-OTHER Win.Malware.Magania-9762151-0 download attempt (more info ...)trojan-activity        URL
55762MALWARE-OTHER Win.Malware.Magania-9762160-0 download attempt (more info ...)trojan-activity        URL
55763MALWARE-OTHER Win.Malware.Magania-9762160-0 download attempt (more info ...)trojan-activity        URL
55770MALWARE-OTHER Win.Keylogger.Zeroaccess-9762346-0 download attempt (more info ...)trojan-activity        URL
55771MALWARE-OTHER Win.Keylogger.Zeroaccess-9762346-0 download attempt (more info ...)trojan-activity        URL
55779MALWARE-OTHER Win.Malware.Magania-9762933-0 download attempt (more info ...)trojan-activity        URL
55780MALWARE-OTHER Win.Malware.Magania-9762933-0 download attempt (more info ...)trojan-activity        URL
55789MALWARE-OTHER PUA.Win.Adware.Crossrider-9763527-0 download attempt (more info ...)trojan-activity        URL
55790MALWARE-OTHER PUA.Win.Adware.Crossrider-9763527-0 download attempt (more info ...)trojan-activity        URL
55793MALWARE-OTHER Win.Trojan.Hupigon-9763906-0 download attempt (more info ...)trojan-activity        URL
55794MALWARE-OTHER Win.Trojan.Hupigon-9763906-0 download attempt (more info ...)trojan-activity        URL
55803SERVER-OTHER Redis replication arbitrary code execution attempt (more info ...)attempted-user        URL
55811MALWARE-OTHER Win.Trojan.Mekotio variant second stage dropper download attempt (more info ...)trojan-activity        URL
55812MALWARE-OTHER Win.Trojan.Mekotio variant second stage dropper download attempt (more info ...)trojan-activity        URL
55842FILE-PDF TRUFFLEHUNTER TALOS-2020-1156 attack attempt (more info ...)attempted-user        URL
55843FILE-PDF TRUFFLEHUNTER TALOS-2020-1156 attack attempt (more info ...)attempted-user        URL
55844FILE-OTHER TRUFFLEHUNTER TALOS-2020-1155 attack attempt (more info ...)attempted-user  2020-12543      URL
55845FILE-OTHER TRUFFLEHUNTER TALOS-2020-1155 attack attempt (more info ...)attempted-user  2020-12543      URL
55852MALWARE-OTHER Win.Malware.Magania-9769241-0 download attempt (more info ...)trojan-activity        URL
55853MALWARE-OTHER Win.Malware.Magania-9769241-0 download attempt (more info ...)trojan-activity        URL
55854MALWARE-OTHER Win.Packed.Razy-9769405-0 download attempt (more info ...)trojan-activity        URL
55855MALWARE-OTHER Win.Packed.Razy-9769405-0 download attempt (more info ...)trojan-activity        URL
55860MALWARE-OTHER Win.Worm.Gamarue-9769424-0 download attempt (more info ...)trojan-activity        URL
55861MALWARE-OTHER Win.Worm.Gamarue-9769424-0 download attempt (more info ...)trojan-activity        URL
55863MALWARE-OTHER Win.Virus.Ursnif-9769699-0 download attempt (more info ...)trojan-activity        URL
55864MALWARE-OTHER Win.Virus.Ursnif-9769699-0 download attempt (more info ...)trojan-activity        URL
55867MALWARE-OTHER Win.Malware.Agzz8qk-9769774-0 download attempt (more info ...)trojan-activity        URL
55868MALWARE-OTHER Win.Malware.Agzz8qk-9769774-0 download attempt (more info ...)trojan-activity        URL
55875MALWARE-OTHER Win.Malware.Bdld-9770176-0 download attempt (more info ...)trojan-activity        URL
55876MALWARE-OTHER Win.Malware.Bdld-9770176-0 download attempt (more info ...)trojan-activity        URL
55889MALWARE-OTHER PUA.Win.Adware.Browsefox-9771664-0 download attempt (more info ...)trojan-activity        URL
55890MALWARE-OTHER PUA.Win.Adware.Browsefox-9771664-0 download attempt (more info ...)trojan-activity        URL
55893MALWARE-OTHER Win.Worm.Vobfus-9771891-0 download attempt (more info ...)trojan-activity        URL
55894MALWARE-OTHER Win.Worm.Vobfus-9771891-0 download attempt (more info ...)trojan-activity        URL
55917SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1159 attack attempt (more info ...)web-application-attack        URL
55918SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4211      URL
55919SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4211      URL
55920SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4211      URL
55921SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4211      URL
55932SERVER-OTHER Oracle WebLogic malicious RemoteConstructor deserialization attempt (more info ...)attempted-user  2020-14644      URL
55933SERVER-OTHER Oracle WebLogic malicious RemoteConstructor deserialization attempt (more info ...)attempted-user  2020-14644      URL
55936MALWARE-OTHER PUA.Win.Adware.Perion-9775059-0 download attempt (more info ...)trojan-activity        URL
55937MALWARE-OTHER PUA.Win.Adware.Perion-9775059-0 download attempt (more info ...)trojan-activity        URL
55946MALWARE-OTHER PUA.Win.Adware.Opencandy-9775571-0 download attempt (more info ...)trojan-activity        URL
55947MALWARE-OTHER PUA.Win.Adware.Opencandy-9775571-0 download attempt (more info ...)trojan-activity        URL
55950MALWARE-OTHER PUA.Win.Adware.Opencandy-9775689-0 download attempt (more info ...)trojan-activity        URL
55951MALWARE-OTHER PUA.Win.Adware.Opencandy-9775689-0 download attempt (more info ...)trojan-activity        URL
55974MALWARE-OTHER Win.Packed.Clipbanker-9776642-0 download attempt (more info ...)trojan-activity        URL
55975MALWARE-OTHER Win.Packed.Clipbanker-9776642-0 download attempt (more info ...)trojan-activity        URL
55981SERVER-WEBAPP D-Link Central WiFi Manager CWM 100 command injection attempt (more info ...)web-application-attack  2019-13372      URL
55985FILE-OTHER TRUFFLEHUNTER TALOS-2020-1161 attack attempt (more info ...)attempted-user  2020-13544      URL
55986FILE-OTHER TRUFFLEHUNTER TALOS-2020-1161 attack attempt (more info ...)attempted-user  2020-13544      URL
55987FILE-OTHER TRUFFLEHUNTER TALOS-2020-1162 attack attempt (more info ...)attempted-user  2020-13545      URL
55988FILE-OTHER TRUFFLEHUNTER TALOS-2020-1162 attack attempt (more info ...)attempted-user  2020-13545      URL
55991FILE-OTHER TRUFFLEHUNTER TALOS-2020-1163 attack attempt (more info ...)attempted-user  2020-13546      URL
55992FILE-OTHER TRUFFLEHUNTER TALOS-2020-1163 attack attempt (more info ...)attempted-user  2020-13546      URL
56012MALWARE-OTHER Win.Ransomware.Nymaim-9778921-0 download attempt (more info ...)trojan-activity        URL
56013MALWARE-OTHER Win.Ransomware.Nymaim-9778921-0 download attempt (more info ...)trojan-activity        URL
56018MALWARE-OTHER Win.Ransomware.Nymaim-9779119-0 download attempt (more info ...)trojan-activity        URL
56019MALWARE-OTHER Win.Ransomware.Nymaim-9779119-0 download attempt (more info ...)trojan-activity        URL
56020MALWARE-OTHER Win.Ransomware.Cidox-9779147-0 download attempt (more info ...)trojan-activity        URL
56021MALWARE-OTHER Win.Ransomware.Cidox-9779147-0 download attempt (more info ...)trojan-activity        URL
56028MALWARE-OTHER Win.Ransomware.Refinka-9779255-0 download attempt (more info ...)trojan-activity        URL
56029MALWARE-OTHER Win.Ransomware.Refinka-9779255-0 download attempt (more info ...)trojan-activity        URL
56036MALWARE-OTHER Win.Malware.Ppatre-9779748-0 download attempt (more info ...)trojan-activity        URL
56037MALWARE-OTHER Win.Malware.Ppatre-9779748-0 download attempt (more info ...)trojan-activity        URL
56048SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1168 attack attempt (more info ...)web-application-attack  2020-13550      URL
56049SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1168 attack attempt (more info ...)web-application-attack  2020-13550      URL
56050SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1168 attack attempt (more info ...)web-application-attack  2020-13550      URL
56053FILE-PDF TRUFFLEHUNTER TALOS-2020-1171 attack attempt (more info ...)attempted-user  2020-13557      URL
56054FILE-PDF TRUFFLEHUNTER TALOS-2020-1171 attack attempt (more info ...)attempted-user  2020-13557      URL
56059PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2020-1170 attack attempt (more info ...)attempted-user  2020-13556      URL
56060PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2020-1170 attack attempt (more info ...)attempted-user  2020-13556      URL
56063FILE-PDF TRUFFLEHUNTER TALOS-2020-1166 attack attempt (more info ...)attempted-user  2020-13548      URL
56064FILE-PDF TRUFFLEHUNTER TALOS-2020-1166 attack attempt (more info ...)attempted-user  2020-13548      URL
56065FILE-PDF TRUFFLEHUNTER TALOS-2020-1165 attack attempt (more info ...)attempted-user  2020-13547      URL
56066FILE-PDF TRUFFLEHUNTER TALOS-2020-1165 attack attempt (more info ...)attempted-user  2020-13547      URL
56071MALWARE-OTHER Win.Malware.Estiwir-9780541-0 download attempt (more info ...)trojan-activity        URL
56072MALWARE-OTHER Win.Malware.Estiwir-9780541-0 download attempt (more info ...)trojan-activity        URL
56092MALWARE-OTHER Win.Dropper.NetWire-9781821-0 download attempt (more info ...)trojan-activity        URL
56093MALWARE-OTHER Win.Dropper.NetWire-9781821-0 download attempt (more info ...)trojan-activity        URL
56096MALWARE-OTHER Win.Dropper.Cerber-9782626-0 download attempt (more info ...)trojan-activity        URL
56097MALWARE-OTHER Win.Dropper.Cerber-9782626-0 download attempt (more info ...)trojan-activity        URL
56114MALWARE-OTHER Win.Packed.Generic-9783183-0 download attempt (more info ...)trojan-activity        URL
56115MALWARE-OTHER Win.Packed.Generic-9783183-0 download attempt (more info ...)trojan-activity        URL
56122FILE-PDF TRUFFLEHUNTER TALOS-2020-1175 attack attempt (more info ...)attempted-user  2021-21831      URL
56123FILE-PDF TRUFFLEHUNTER TALOS-2020-1175 attack attempt (more info ...)attempted-user  2021-21831      URL
56126BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1172 attack attempt (more info ...)attempted-user  2020-13558      URL
56127BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1172 attack attempt (more info ...)attempted-user  2020-13558      URL
56138SERVER-WEBAPP Citrix ADC and Gateway information disclosure attempt (more info ...)web-application-attack  2020-8195      URL
56143SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1177 attack attempt (more info ...)attempted-user  2020-13563      URL
56144SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1177 attack attempt (more info ...)attempted-user  2020-13563      URL
56145SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1177 attack attempt (more info ...)attempted-user  2020-13564      URL
56146SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1177 attack attempt (more info ...)attempted-user  2020-13564      URL
56147SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1179 attack attempt (more info ...)web-application-attack  2020-13568      URL
56148SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1179 attack attempt (more info ...)web-application-attack  2020-13568      URL
56149SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1179 attack attempt (more info ...)web-application-attack  2020-13568      URL
56152SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1178 attack attempt (more info ...)web-application-attack  2020-13565      URL
56153SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1178 attack attempt (more info ...)web-application-attack  2020-13565      URL
56154SERVER-WEBAPP MobileIron Core & Connector remote code execution attempt (more info ...)attempted-user  2020-15505      URL
56155SERVER-WEBAPP MobileIron Core & Connector remote code execution attempt (more info ...)attempted-user  2020-15505      URL
56158FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1176 attack attempt (more info ...)attempted-user  2020-13561      URL
56159FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1176 attack attempt (more info ...)attempted-user  2020-13561      URL
56160FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1176 attack attempt (more info ...)attempted-user  2020-13561      URL
56161FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1176 attack attempt (more info ...)attempted-user  2020-13561      URL
56162SERVER-WEBAPP Citrix ADC and Gateway information disclosure attempt (more info ...)web-application-attack  2020-8196      URL
56163MALWARE-OTHER Win.Dropper.PyVil download attempt (more info ...)trojan-activity        URL
56164MALWARE-OTHER Win.Dropper.PyVil download attempt (more info ...)trojan-activity        URL
56165MALWARE-OTHER Win.Dropper.PyVil download attempt (more info ...)trojan-activity        URL
56166MALWARE-OTHER Win.Dropper.PyVil outbound communication attempt (more info ...)trojan-activity        URL
56167MALWARE-OTHER Win.Dropper.PyVil download attempt (more info ...)trojan-activity        URL
56178MALWARE-OTHER Win.Malware.Upatre-9784988-0 download attempt (more info ...)trojan-activity        URL
56179MALWARE-OTHER Win.Malware.Upatre-9784988-0 download attempt (more info ...)trojan-activity        URL
56191MALWARE-OTHER Win.Malware.Upatre-9785658-0 download attempt (more info ...)trojan-activity        URL
56192MALWARE-OTHER Win.Malware.Upatre-9785658-0 download attempt (more info ...)trojan-activity        URL
56200SERVER-WEBAPP Oracle WebLogic Server command injection attempt (more info ...)web-application-attack  2020-14882      URL
56201SERVER-WEBAPP Oracle WebLogic Server command injection attempt (more info ...)web-application-attack  2020-14882      URL
56202SERVER-WEBAPP Oracle WebLogic Server command injection attempt (more info ...)web-application-attack  2020-14882      URL
56203SERVER-WEBAPP Oracle WebLogic Server command injection attempt (more info ...)web-application-attack  2020-14882      URL
56208PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1184 attack attempt (more info ...)attempted-dos  2020-13573      URL
56211SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1185 attack attempt (more info ...)attempted-dos  2020-13574      URL
56248MALWARE-OTHER Win.Dropper.Kuluoz-9789055-0 download attempt (more info ...)trojan-activity        URL
56249MALWARE-OTHER Win.Dropper.Kuluoz-9789055-0 download attempt (more info ...)trojan-activity        URL
56275SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1185 attack attempt (more info ...)attempted-dos  2020-13574      URL
56277MALWARE-OTHER Win.Trojan.Crat malicious document download (more info ...)trojan-activity        URL
56279MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity        URL
56281MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity        URL
56284MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity        URL
56285MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity        URL
56293MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity        URL
56299MALWARE-OTHER Win.Downloader.Upatre-9789726-0 download attempt (more info ...)trojan-activity        URL
56300MALWARE-OTHER Win.Downloader.Upatre-9789726-0 download attempt (more info ...)trojan-activity        URL
56322MALWARE-OTHER PUA.Win.Adware.Adf67bab-9789932-0 download attempt (more info ...)trojan-activity        URL
56323MALWARE-OTHER PUA.Win.Adware.Adf67bab-9789932-0 download attempt (more info ...)trojan-activity        URL
56326MALWARE-OTHER Win.Malware.Fusioncoredownldr-9790249-0 download attempt (more info ...)trojan-activity        URL
56327MALWARE-OTHER Win.Malware.Fusioncoredownldr-9790249-0 download attempt (more info ...)trojan-activity        URL
56330MALWARE-OTHER PUA.Win.Adware.Rukoma-9792185-0 download attempt (more info ...)trojan-activity        URL
56331MALWARE-OTHER PUA.Win.Adware.Rukoma-9792185-0 download attempt (more info ...)trojan-activity        URL
56342MALWARE-OTHER Win.Malware.Magania-9793635-0 download attempt (more info ...)trojan-activity        URL
56343MALWARE-OTHER Win.Malware.Magania-9793635-0 download attempt (more info ...)trojan-activity        URL
56346MALWARE-OTHER PUA.Win.Adware.Icloader-9793684-0 download attempt (more info ...)trojan-activity        URL
56347MALWARE-OTHER PUA.Win.Adware.Icloader-9793684-0 download attempt (more info ...)trojan-activity        URL
56348MALWARE-OTHER Win.Malware.Chen-9793785-0 download attempt (more info ...)trojan-activity        URL
56349MALWARE-OTHER Win.Malware.Chen-9793785-0 download attempt (more info ...)trojan-activity        URL
56350MALWARE-OTHER Win.Malware.Magania-9793863-0 download attempt (more info ...)trojan-activity        URL
56351MALWARE-OTHER Win.Malware.Magania-9793863-0 download attempt (more info ...)trojan-activity        URL
56356MALWARE-OTHER Win.Malware.Magania-9794293-0 download attempt (more info ...)trojan-activity        URL
56357MALWARE-OTHER Win.Malware.Magania-9794293-0 download attempt (more info ...)trojan-activity        URL
56370MALWARE-OTHER Win.Trojan.GlitchPOS malicious executable download attempt (more info ...)trojan-activity        URL
56379BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1195 attack attempt (more info ...)attempted-user  2020-13584      URL
56380BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1195 attack attempt (more info ...)attempted-user  2020-13584      URL
56381BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1195 attack attempt (more info ...)attempted-user  2020-13584      URL
56382BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1195 attack attempt (more info ...)attempted-user  2020-13584      URL
56394MALWARE-OTHER Win.Malware.Ursu-9794593-0 download attempt (more info ...)trojan-activity        URL
56395MALWARE-OTHER Win.Malware.Ursu-9794593-0 download attempt (more info ...)trojan-activity        URL
56396MALWARE-OTHER Win.Malware.Zusy-9794604-0 download attempt (more info ...)trojan-activity        URL
56397MALWARE-OTHER Win.Malware.Zusy-9794604-0 download attempt (more info ...)trojan-activity        URL
56432SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4241      URL
56433SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4241      URL
56434SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4241      URL
56435SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4241      URL
56436SERVER-WEBAPP Atlassian Crowd pdkinstall plugin remote code execution attempt (more info ...)web-application-attack  2019-11580      URL
56439POLICY-OTHER Kubernetes Dashboard authentication bypass information disclosure attempt (more info ...)policy-violation  2018-18264      URL
56451FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1196 attack attempt (more info ...)attempted-user  2021-21774      URL
56452FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1196 attack attempt (more info ...)attempted-user  2021-21774      URL
56463MALWARE-OTHER Win.Worm.Morto-9797503-0 download attempt (more info ...)trojan-activity        URL
56464MALWARE-OTHER Win.Worm.Morto-9797503-0 download attempt (more info ...)trojan-activity        URL
56467MALWARE-OTHER PUA.Win.Downloader.Amonetize-9797772-0 download attempt (more info ...)trojan-activity        URL
56468MALWARE-OTHER PUA.Win.Downloader.Amonetize-9797772-0 download attempt (more info ...)trojan-activity        URL
56473MALWARE-OTHER Win.Malware.Budt-9798951-0 download attempt (more info ...)trojan-activity        URL
56474MALWARE-OTHER Win.Malware.Budt-9798951-0 download attempt (more info ...)trojan-activity        URL
56475SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1205 attack attempt (more info ...)web-application-attack  2020-27231      URL
56476SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1205 attack attempt (more info ...)web-application-attack  2020-27231      URL
56477SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1205 attack attempt (more info ...)web-application-attack  2020-27231      URL
56478SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1207 attack attempt (more info ...)web-application-attack  2020-27241      URL
56479SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1207 attack attempt (more info ...)web-application-attack  2020-27241      URL
56480SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1207 attack attempt (more info ...)web-application-attack  2020-27241      URL
56481SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1206 attack attempt (more info ...)web-application-attack  2020-27246      URL
56482SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1206 attack attempt (more info ...)web-application-attack  2020-27246      URL
56483SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1206 attack attempt (more info ...)web-application-attack  2020-27246      URL
56486SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1202 attack attempt (more info ...)web-application-attack  2020-27226      URL
56487SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1202 attack attempt (more info ...)web-application-attack  2020-27226      URL
56488SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1202 attack attempt (more info ...)web-application-attack  2020-27226      URL
56489SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1203 attack attempt (more info ...)web-application-attack  2020-27227      URL
56496SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1198 attack attempt (more info ...)web-application-attack  2020-13587      URL
56500SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1200 attack attempt (more info ...)web-application-attack  2020-13591      URL
56501SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1200 attack attempt (more info ...)web-application-attack  2020-13591      URL
56502SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1200 attack attempt (more info ...)web-application-attack  2020-13591      URL
56503SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1201 attack attempt (more info ...)web-application-attack  2020-13592      URL
56504SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1199 attack attempt (more info ...)web-application-attack  2020-13590      URL
56505SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1199 attack attempt (more info ...)web-application-attack  2020-13590      URL
56506SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1199 attack attempt (more info ...)web-application-attack  2020-13590      URL
56507SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1186 attack attempt (more info ...)attempted-dos  2020-13575      URL
56508SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1186 attack attempt (more info ...)attempted-dos  2020-13575      URL
56509SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1187 attack attempt (more info ...)attempted-user  2020-13576      URL
56510SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1187 attack attempt (more info ...)attempted-user  2020-13576      URL
56520SERVER-WEBAPP QNAP QTS and Photo Station directory traversal attempt (more info ...)web-application-attack  2019-7192      
56521SERVER-WEBAPP QNAP QTS and Photo Station directory traversal attempt (more info ...)web-application-attack  2019-7192      
56522SERVER-WEBAPP QNAP QTS and Photo Station directory traversal attempt (more info ...)web-application-attack        
56531MALWARE-OTHER Win.Trojan.IcedId payload download attempt (more info ...)trojan-activity        URL
56532SERVER-WEBAPP Advantech WebAccess NMS directory traversal attempt (more info ...)web-application-attack  2020-10619      URL
56533SERVER-WEBAPP Advantech WebAccess NMS directory traversal attempt (more info ...)web-application-attack  2020-10619      URL
56534SERVER-WEBAPP Advantech WebAccess NMS directory traversal attempt (more info ...)web-application-attack  2020-10619      URL
56537MALWARE-OTHER Win.Malware.Dexter POS variant download attempt (more info ...)trojan-activity        URL
56538MALWARE-OTHER Win.Malware.Dexter POS variant download attempt (more info ...)trojan-activity        URL
56546MALWARE-OTHER Win.Trojan.Alina variant download attempt (more info ...)trojan-activity        URL
56547MALWARE-OTHER Win.Trojan.Alina variant download attempt (more info ...)trojan-activity        URL
56548OS-OTHER TRUFFLEHUNTER TALOS-2020-1209 attack attempt (more info ...)attempted-user        URL
56549OS-OTHER TRUFFLEHUNTER TALOS-2020-1209 attack attempt (more info ...)attempted-user        URL
56550SERVER-WEBAPP Ruckus IoT Controller Web UI authentication bypass attempt (more info ...)web-application-attack  2020-26879      
56551SERVER-WEBAPP Ruckus IoT Controller Web UI OS username command injection attempt (more info ...)web-application-attack  2020-26878      
56552MALWARE-OTHER TRUFFLEHUNTER SFVRT-1042 attack attempt (more info ...)trojan-activity        
56553MALWARE-OTHER TRUFFLEHUNTER SFVRT-1042 attack attempt (more info ...)trojan-activity        
56555MALWARE-OTHER Win.Trojan.RegretLocker malicious executable download attempt (more info ...)trojan-activity        URL
56556MALWARE-OTHER Win.Trojan.RegretLocker malicious executable download attempt (more info ...)trojan-activity        URL
56566MALWARE-TOOLS Win.Trojan.AnchorInstaller variant download attempt (more info ...)trojan-activity        URL
56570MALWARE-TOOLS Win.Trojan.Memscraper variant download attempt (more info ...)trojan-activity        URL
56578MALWARE-OTHER Lokibot download attempt (more info ...)trojan-activity        URL
56579SERVER-WEBAPP Belkin Wemo Insight Smart Plug libUPnPHndlr.so stack buffer overflow attempt (more info ...)attempted-user  2018-6692      URL
56586SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus arbitrary JSP file upload attempt (more info ...)attempted-admin  2019-8394      URL
56594MALWARE-BACKDOOR MultiOS.Malware.GORAT malware download attempt (more info ...)trojan-activity        URL
56595MALWARE-BACKDOOR MultiOS.Malware.GORAT malware download attempt (more info ...)trojan-activity        URL
56608MALWARE-OTHER Cobalt Strike beacon inbound connection attempt (more info ...)trojan-activity        URL
56609MALWARE-OTHER Cobalt Strike beacon outbound connection attempt (more info ...)trojan-activity        URL
56610MALWARE-OTHER Cobalt Strike beacon outbound connection attempt (more info ...)trojan-activity        URL
56611MALWARE-OTHER Cobalt Strike beacon outbound connection attempt (more info ...)trojan-activity        URL
56614MALWARE-BACKDOOR Cobalt Strike beacon connection attempt (more info ...)trojan-activity        URL
56624SERVER-WEBAPP rConfig command injection attempt (more info ...)web-application-attack  2020-10879      URL
56625SERVER-WEBAPP rConfig command injection attempt (more info ...)web-application-attack  2020-10879      URL
56626SERVER-WEBAPP rConfig command injection attempt (more info ...)web-application-attack  2020-10879      URL
56627SERVER-WEBAPP rConfig command injection attempt (more info ...)web-application-attack  2020-10879      URL
56636MALWARE-OTHER Win.Dropper.Cerber-9806289-0 download attempt (more info ...)trojan-activity        URL
56637MALWARE-OTHER Win.Dropper.Cerber-9806289-0 download attempt (more info ...)trojan-activity        URL
56642MALWARE-OTHER Win.Packed.Upantix-9807018-0 download attempt (more info ...)trojan-activity        URL
56643MALWARE-OTHER Win.Packed.Upantix-9807018-0 download attempt (more info ...)trojan-activity        URL
56644MALWARE-OTHER Win.Dropper.Nanocore-9807037-0 download attempt (more info ...)trojan-activity        URL
56645MALWARE-OTHER Win.Dropper.Nanocore-9807037-0 download attempt (more info ...)trojan-activity        URL
56650MALWARE-OTHER Win.Adware.Esprot-9807942-0 download attempt (more info ...)trojan-activity        URL
56651MALWARE-OTHER Win.Adware.Esprot-9807942-0 download attempt (more info ...)trojan-activity        URL
56652MALWARE-OTHER PUA.Win.Adware.Esprot-9807946-0 download attempt (more info ...)trojan-activity        URL
56653MALWARE-OTHER PUA.Win.Adware.Esprot-9807946-0 download attempt (more info ...)trojan-activity        URL
56658BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1214 attack attempt (more info ...)attempted-user  2020-27648      URL
56659BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2020-1214 attack attempt (more info ...)attempted-user  2020-27648      URL
56671MALWARE-OTHER Win.Packed.Zeroaccess-9809114-0 download attempt (more info ...)trojan-activity        URL
56672MALWARE-OTHER Win.Packed.Zeroaccess-9809114-0 download attempt (more info ...)trojan-activity        URL
56685MALWARE-OTHER Win.Malware.Magania-9809290-0 download attempt (more info ...)trojan-activity        URL
56686MALWARE-OTHER Win.Malware.Magania-9809290-0 download attempt (more info ...)trojan-activity        URL
56721FILE-OTHER TRUFFLEHUNTER TALOS-2020-1213 attack attempt (more info ...)attempted-user  2020-28590      URL
56722FILE-OTHER TRUFFLEHUNTER TALOS-2020-1213 attack attempt (more info ...)attempted-user  2020-28590      URL
56723FILE-OTHER TRUFFLEHUNTER TALOS-2020-1215 attack attempt (more info ...)attempted-user  2020-28591      URL
56724FILE-OTHER TRUFFLEHUNTER TALOS-2020-1215 attack attempt (more info ...)attempted-user  2020-28591      URL
56725FILE-OTHER TRUFFLEHUNTER TALOS-2020-1218 attack attempt (more info ...)attempted-user  2020-28594      URL
56726FILE-OTHER TRUFFLEHUNTER TALOS-2020-1218 attack attempt (more info ...)attempted-user  2020-28594      URL
56727FILE-OTHER TRUFFLEHUNTER TALOS-2020-1219 attack attempt (more info ...)attempted-user  2020-28595      URL
56728FILE-OTHER TRUFFLEHUNTER TALOS-2020-1219 attack attempt (more info ...)attempted-user  2020-28595      URL
56732MALWARE-OTHER Win.Packed.Zeroaccess-9811539-0 download attempt (more info ...)trojan-activity        URL
56733MALWARE-OTHER Win.Packed.Zeroaccess-9811539-0 download attempt (more info ...)trojan-activity        URL
56746MALWARE-OTHER Win.Malware.Ulise-9811997-0 download attempt (more info ...)trojan-activity        URL
56747MALWARE-OTHER Win.Malware.Ulise-9811997-0 download attempt (more info ...)trojan-activity        URL
56756MALWARE-OTHER Win.Packed.Zusy-9812442-0 download attempt (more info ...)trojan-activity        URL
56757MALWARE-OTHER Win.Packed.Zusy-9812442-0 download attempt (more info ...)trojan-activity        URL
56764MALWARE-OTHER Win.Malware.3400da6c-9812978-0 download attempt (more info ...)trojan-activity        URL
56765MALWARE-OTHER Win.Malware.3400da6c-9812978-0 download attempt (more info ...)trojan-activity        URL
56772MALWARE-OTHER Win.Malware.Qbot variant download attempt (more info ...)trojan-activity        URL
56773MALWARE-OTHER Win.Malware.Qbot variant download attempt (more info ...)trojan-activity        URL
56776MALWARE-OTHER Win.Packed.Gamarue-9811452-0 download attempt (more info ...)trojan-activity        URL
56777MALWARE-OTHER Win.Packed.Gamarue-9811452-0 download attempt (more info ...)trojan-activity        URL
56805MALWARE-OTHER Win.Malware.Yddld-9815757-0 download attempt (more info ...)trojan-activity        URL
56806MALWARE-OTHER Win.Malware.Yddld-9815757-0 download attempt (more info ...)trojan-activity        URL
56809MALWARE-OTHER Win.Malware.Yddld-9816553-0 download attempt (more info ...)trojan-activity        URL
56810MALWARE-OTHER Win.Malware.Yddld-9816553-0 download attempt (more info ...)trojan-activity        URL
56815MALWARE-OTHER Win.Packed.Trojanx-9818175-0 download attempt (more info ...)trojan-activity        URL
56816MALWARE-OTHER Win.Packed.Trojanx-9818175-0 download attempt (more info ...)trojan-activity        URL
56822SERVER-WEBAPP Grafana Labs Grafana denial of service attempt (more info ...)denial-of-service  2020-13379      URL
56826SERVER-WEBAPP SolarWinds Orion authentication bypass attempt (more info ...)web-application-attack  2020-10148      URL
56827SERVER-WEBAPP SolarWinds Orion authentication bypass attempt (more info ...)web-application-attack  2020-10148      URL
56828SERVER-WEBAPP SolarWinds Orion authentication bypass attempt (more info ...)web-application-attack  2020-10148      URL
56829SERVER-WEBAPP SolarWinds Orion authentication bypass attempt (more info ...)web-application-attack  2020-10148      URL
56836MALWARE-OTHER Win.Trojan.TroubleGrabber external tools download attempt (more info ...)trojan-activity        URL
56837MALWARE-OTHER Win.Trojan.TroubleGrabber external tools download attempt (more info ...)trojan-activity        URL
56847FILE-OTHER TRUFFLEHUNTER TALOS-2020-1222 attack attempt (more info ...)attempted-user  2020-28598      URL
56848FILE-OTHER TRUFFLEHUNTER TALOS-2020-1222 attack attempt (more info ...)attempted-user  2020-28598      URL
56887MALWARE-BACKDOOR Win.Trojan.BumbleBee webshell access detected (more info ...)trojan-activity        URL
56888MALWARE-BACKDOOR Win.Trojan.BumbleBee webshell transfer attempt (more info ...)trojan-activity        URL
56889MALWARE-BACKDOOR Win.Trojan.BumbleBee webshell access detected (more info ...)trojan-activity        
56890MALWARE-BACKDOOR Win.Trojan.BumbleBee webshell transfer attempt (more info ...)trojan-activity        URL
56916SERVER-WEBAPP SolarWinds Orion authentication bypass attempt (more info ...)web-application-attack  2020-10148      URL
56917SERVER-WEBAPP SolarWinds Orion authentication bypass attempt (more info ...)web-application-attack  2020-10148      URL
56924MALWARE-OTHER Win.Malware.Emotet-9822370-0 download attempt (more info ...)trojan-activity        URL
56925MALWARE-OTHER Win.Malware.Emotet-9822370-0 download attempt (more info ...)trojan-activity        URL
56926MALWARE-TOOLS Win.Trojan.Trickbot Trickboot module download attempt (more info ...)trojan-activity        URL
56927MALWARE-TOOLS Win.Trojan.Trickbot Trickboot module download attempt (more info ...)trojan-activity        URL
56928MALWARE-TOOLS Win.Trojan.Trickbot Trickboot module download attempt (more info ...)trojan-activity        URL
56929MALWARE-TOOLS Win.Trojan.Trickbot Trickboot module download attempt (more info ...)trojan-activity        URL
56930MALWARE-OTHER Win.Trojan.FANCYBEAR variant binary download attempt (more info ...)trojan-activity        URL
56931MALWARE-OTHER Win.Trojan.FANCYBEAR variant binary download attempt (more info ...)trojan-activity        URL
56932MALWARE-OTHER Win.Trojan.FANCYBEAR variant binary download attempt (more info ...)trojan-activity        URL
56933MALWARE-OTHER Win.Trojan.FANCYBEAR variant binary download attempt (more info ...)trojan-activity        URL
56934SERVER-WEBAPP Nagios XI ajaxhelper command injection attempt (more info ...)web-application-attack  2020-15901      URL
56935SERVER-WEBAPP Nagios XI ajaxhelper command injection attempt (more info ...)web-application-attack  2020-15901      URL
56936SERVER-WEBAPP Nagios XI ajaxhelper command injection attempt (more info ...)web-application-attack  2020-15901      URL
56937SERVER-WEBAPP Nagios XI ajaxhelper command injection attempt (more info ...)web-application-attack  2020-15901      URL
56948MALWARE-OTHER Win.Malware.Stantinko-9822477-0 download attempt (more info ...)trojan-activity        URL
56949MALWARE-OTHER Win.Malware.Stantinko-9822477-0 download attempt (more info ...)trojan-activity        URL
56967MALWARE-OTHER Win.Packed.Upatre-9823253-0 download attempt (more info ...)trojan-activity        URL
56968MALWARE-OTHER Win.Packed.Upatre-9823253-0 download attempt (more info ...)trojan-activity        URL
56983MALWARE-OTHER Win.Malware.Emotet-9823901-0 download attempt (more info ...)trojan-activity        URL
56984MALWARE-OTHER Win.Malware.Emotet-9823901-0 download attempt (more info ...)trojan-activity        URL
56994FILE-OTHER TRUFFLEHUNTER TALOS-2021-1226 attack attempt (more info ...)attempted-user  2021-21772      URL
56995FILE-OTHER TRUFFLEHUNTER TALOS-2021-1226 attack attempt (more info ...)attempted-user  2021-21772      URL
57000FILE-OTHER TRUFFLEHUNTER TALOS-2020-1224 attack attempt (more info ...)attempted-user  2020-28600      URL
57001FILE-OTHER TRUFFLEHUNTER TALOS-2020-1224 attack attempt (more info ...)attempted-user  2020-28600      URL
57002SERVER-WEBAPP Belkin Wemo UPnP cross site scripting attempt (more info ...)web-application-attack        URL
57003MALWARE-OTHER Win.Ransomware.Generickdz-9825516-0 download attempt (more info ...)trojan-activity        URL
57004MALWARE-OTHER Win.Ransomware.Generickdz-9825516-0 download attempt (more info ...)trojan-activity        URL
57007MALWARE-OTHER Win.Dropper.Demp-9825500-0 download attempt (more info ...)trojan-activity        URL
57008MALWARE-OTHER Win.Dropper.Demp-9825500-0 download attempt (more info ...)trojan-activity        URL
57011FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1227 attack attempt (more info ...)attempted-user  2021-21773      URL
57012FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1227 attack attempt (more info ...)attempted-user  2021-21773      URL
57013FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1227 attack attempt (more info ...)attempted-user  2021-21773      URL
57014FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1227 attack attempt (more info ...)attempted-user  2021-21773      URL
57015FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1227 attack attempt (more info ...)attempted-user  2021-21773      URL
57016FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1227 attack attempt (more info ...)attempted-user  2021-21773      URL
57017FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1227 attack attempt (more info ...)attempted-user  2021-21773      URL
57018FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1227 attack attempt (more info ...)attempted-user  2021-21773      URL
57031MALWARE-OTHER Win.Trojan.Zbot-9826061-0 download attempt (more info ...)trojan-activity        URL
57032MALWARE-OTHER Win.Trojan.Zbot-9826061-0 download attempt (more info ...)trojan-activity        URL
57039MALWARE-OTHER Win.Malware.Karagany-9826730-0 download attempt (more info ...)trojan-activity        URL
57040MALWARE-OTHER Win.Malware.Karagany-9826730-0 download attempt (more info ...)trojan-activity        URL
57045BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2021-1229 attack attempt (more info ...)attempted-user  2021-21775      URL
57046BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2021-1229 attack attempt (more info ...)attempted-user  2021-21775      URL
57059FILE-PDF TRUFFLEHUNTER TALOS-2021-1233 attack attempt (more info ...)attempted-user        URL
57060FILE-PDF TRUFFLEHUNTER TALOS-2021-1233 attack attempt (more info ...)attempted-user        URL
57061OS-WINDOWS GDI+ printer out of bounds write attempt (more info ...)attempted-user  2021-1648      URL
57062OS-WINDOWS GDI+ printer out of bounds write attempt (more info ...)attempted-user  2021-1648      URL
57111SERVER-OTHER OpenSLP slp_process.c heap overflow attempt (more info ...)attempted-user  2019-5544      URL
57112SERVER-OTHER OpenSLP slp_process.c heap overflow attempt (more info ...)attempted-user  2019-5544      URL
57115SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1237 attack attempt (more info ...)attempted-admin        URL
57116SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1237 attack attempt (more info ...)attempted-admin        URL
57117SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1237 attack attempt (more info ...)attempted-admin        URL
57118SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1237 attack attempt (more info ...)attempted-admin        URL
57119FILE-OTHER TRUFFLEHUNTER TALOS-2021-1231 attack attempt (more info ...)attempted-admin        URL
57120FILE-OTHER TRUFFLEHUNTER TALOS-2021-1231 attack attempt (more info ...)attempted-admin        URL
57121FILE-OTHER TRUFFLEHUNTER TALOS-2021-1230 attack attempt (more info ...)attempted-admin        URL
57122FILE-OTHER TRUFFLEHUNTER TALOS-2021-1230 attack attempt (more info ...)attempted-admin        URL
57124FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1244 attack attempt (more info ...)attempted-user  2021-21782      URL
57125FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1244 attack attempt (more info ...)attempted-user  2021-21782      URL
57126SERVER-WEBAPP Monstra CMS cross-site scripting attempt (more info ...)attempted-user  2018-11472      
57127SERVER-WEBAPP Monstra CMS cross-site scripting attempt (more info ...)attempted-user  2018-11472      
57134BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2021-1238 attack attempt (more info ...)attempted-user  2021-21779      URL
57135BROWSER-WEBKIT TRUFFLEHUNTER TALOS-2021-1238 attack attempt (more info ...)attempted-user  2021-21779      URL
57139OS-OTHER TRUFFLEHUNTER TALOS-2021-1247 attack attempt (more info ...)attempted-user        URL
57140OS-OTHER TRUFFLEHUNTER TALOS-2021-1247 attack attempt (more info ...)attempted-user        URL
57154MALWARE-OTHER Win.Trojan.Masslogger download request attempt (more info ...)trojan-activity        
57158SERVER-WEBAPP Oracle WebLogic consolejndi remote code execution attempt (more info ...)attempted-admin  2021-2109      URL
57159SERVER-WEBAPP Oracle WebLogic consolejndi remote code execution attempt (more info ...)attempted-admin  2021-2109      URL
57161SERVER-OTHER SolarWinds Orion MSMQ remote code execution attempt (more info ...)attempted-admin  2021-25274      
57166OS-OTHER TRUFFLEHUNTER TALOS-2021-1249 attack attempt (more info ...)attempted-user        URL
57167OS-OTHER TRUFFLEHUNTER TALOS-2021-1249 attack attempt (more info ...)attempted-user        URL
57176SERVER-WEBAPP MikroTik RouterOS buffer overflow attempt (more info ...)attempted-user  2018-1156      URL
57177SERVER-WEBAPP MikroTik RouterOS buffer overflow attempt (more info ...)attempted-user  2018-1156      URL
57178SERVER-WEBAPP Monstra CMS registration form cross site scripting attempt (more info ...)attempted-user  2018-11473      
57179SERVER-WEBAPP Monstra CMS registration form cross site scripting attempt (more info ...)attempted-user  2018-11473      
57182SERVER-WEBAPP VMware administrative configurator component command injection attempt (more info ...)web-application-attack  2020-4006      
57183SERVER-WEBAPP VMware administrative configurator component command injection attempt (more info ...)web-application-attack  2020-4006      
57184SERVER-WEBAPP VMware administrative configurator component command injection attempt (more info ...)web-application-attack  2020-4006      
57185SERVER-WEBAPP VMware administrative configurator component command injection attempt (more info ...)web-application-attack  2020-4006      
57186OS-OTHER TRUFFLEHUNTER TALOS-2021-1250 attack attempt (more info ...)attempted-admin        URL
57187OS-OTHER TRUFFLEHUNTER TALOS-2021-1250 attack attempt (more info ...)attempted-admin        URL
57189FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2021-1255 attack attempt (more info ...)attempted-recon  2021-21792      URL
57190FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2021-1255 attack attempt (more info ...)attempted-recon  2021-21792      URL
57197SERVER-OTHER Multiple products outbound HTTP request to SIP port and potential NAT slipstreaming attack attempt (more info ...)misc-attack        URL
57198SERVER-OTHER Multiple products outbound HTTP request to H.323 port and potential NAT slipstreaming attack attempt (more info ...)misc-attack        URL
57199SERVER-OTHER Multiple products outbound HTTP request to SIP port and potential NAT slipstreaming attack attempt (more info ...)misc-attack        URL
57200SERVER-OTHER Multiple products outbound HTTP request to H.323 port and potential NAT slipstreaming attack attempt (more info ...)misc-attack        URL
57201SERVER-OTHER SolarWinds Orion platform unrestricted database access attempt (more info ...)attempted-user  2021-25275      URL
57202SERVER-OTHER SolarWinds Orion platform unrestricted database access attempt (more info ...)attempted-user  2021-25275      URL
57217SERVER-WEBAPP SAP Solution Manager EEM uploadResource command execution attempt (more info ...)attempted-admin  2020-6207      URL
57218SERVER-WEBAPP SAP Solution Manager EEM uploadResource server side request forgery attempt (more info ...)web-application-attack  2020-6207      URL
57224SERVER-WEBAPP Trend Micro Control Manager directory traversal attempt (more info ...)web-application-attack        URL
57225SERVER-WEBAPP Trend Micro Control Manager directory traversal attempt (more info ...)web-application-attack        URL
57226SERVER-WEBAPP Trend Micro Control Manager directory traversal attempt (more info ...)web-application-attack        URL
57227FILE-OTHER TRUFFLEHUNTER TALOS-2020-1225 attack attempt (more info ...)attempted-user  2020-28601      URL
57228FILE-OTHER TRUFFLEHUNTER TALOS-2020-1225 attack attempt (more info ...)attempted-user  2020-28601      URL
57229SERVER-WEBAPP VMware vSphere Client vROPs plugin remote code execution attempt (more info ...)attempted-admin  2021-21972      URL
57230FILE-OTHER TRUFFLEHUNTER TALOS-2020-1223 attack attempt (more info ...)attempted-user  2020-28599      URL
57231FILE-OTHER TRUFFLEHUNTER TALOS-2020-1223 attack attempt (more info ...)attempted-user  2020-28599      URL
57248MALWARE-OTHER Win.Ransomware.ColdChristmas variant binary download attempt (more info ...)trojan-activity        URL
57249FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1257 attack attempt (more info ...)attempted-user  2021-21793      URL
57250FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1257 attack attempt (more info ...)attempted-user  2021-21793      URL
57266OS-OTHER TRUFFLEHUNTER TALOS-2021-1262 attack attempt (more info ...)attempted-admin        URL
57267OS-OTHER TRUFFLEHUNTER TALOS-2021-1262 attack attempt (more info ...)attempted-admin        URL
57270FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1261 attack attempt (more info ...)attempted-user  2021-21794      URL
57271FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1261 attack attempt (more info ...)attempted-user  2021-21794      URL
57272FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1261 attack attempt (more info ...)attempted-user  2021-21794      URL
57273FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1261 attack attempt (more info ...)attempted-user  2021-21794      URL
57284MALWARE-BACKDOOR DEWMODE webshell upload attempt (more info ...)attempted-user        URL
57285MALWARE-BACKDOOR DEWMODE webshell cleanup attempt (more info ...)attempted-user        URL
57286MALWARE-BACKDOOR DEWMODE webshell cleanup attempt (more info ...)attempted-user        URL
57287MALWARE-BACKDOOR DEWMODE webshell file download attempt (more info ...)attempted-user        URL
57288MALWARE-BACKDOOR DEWMODE webshell file download attempt (more info ...)attempted-user        URL
57289MALWARE-BACKDOOR DEWMODE webshell outbound connection attempt (more info ...)attempted-user        URL
57290SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1270 attack attempt (more info ...)attempted-user  2021-21799      URL
57291SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1270 attack attempt (more info ...)attempted-user  2021-21799      URL
57292SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1271 attack attempt (more info ...)attempted-user  2021-21800      URL
57293SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1271 attack attempt (more info ...)attempted-user  2021-21800      URL
57294FILE-PDF TRUFFLEHUNTER TALOS-2021-1265 attack attempt (more info ...)attempted-user  2021-21796      URL
57295FILE-PDF TRUFFLEHUNTER TALOS-2021-1265 attack attempt (more info ...)attempted-user  2021-21796      URL
57296FILE-PDF TRUFFLEHUNTER TALOS-2021-1267 attack attempt (more info ...)attempted-user  2021-21798      URL
57297FILE-PDF TRUFFLEHUNTER TALOS-2021-1267 attack attempt (more info ...)attempted-user  2021-21798      URL
57298SERVER-WEBAPP F5 iControl REST interface command injection attempt (more info ...)web-application-attack  2021-22986      URL
57301FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1264 attack attempt (more info ...)attempted-user  2021-21795      URL
57302FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1264 attack attempt (more info ...)attempted-user  2021-21795      URL
57303FILE-PDF TRUFFLEHUNTER TALOS-2021-1266 attack attempt (more info ...)attempted-user  2021-21797      URL
57304FILE-PDF TRUFFLEHUNTER TALOS-2021-1266 attack attempt (more info ...)attempted-user  2021-21797      URL
57305SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1272 attack attempt (more info ...)attempted-user  2021-21803      URL
57306SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1272 attack attempt (more info ...)attempted-user  2021-21803      URL
57307SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1274 attack attempt (more info ...)web-application-attack  2021-21805      URL
57308SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1274 attack attempt (more info ...)web-application-attack  2021-21805      URL
57309SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1274 attack attempt (more info ...)web-application-attack  2021-21805      URL
57314MALWARE-BACKDOOR Asp.Trojan.Hafnium web shell upload attempt (more info ...)attempted-admin        
57315MALWARE-BACKDOOR Asp.Trojan.Hafnium web shell upload attempt (more info ...)attempted-admin        
57316MALWARE-BACKDOOR Asp.Trojan.Hafnium web shell upload attempt (more info ...)attempted-admin        
57317MALWARE-BACKDOOR Asp.Trojan.Hafnium web shell upload attempt (more info ...)attempted-admin        
57318MALWARE-BACKDOOR Asp.Trojan.Hafnium web shell upload attempt (more info ...)attempted-admin        
57319MALWARE-BACKDOOR Asp.Trojan.Hafnium web shell upload attempt (more info ...)attempted-admin        
57320MALWARE-BACKDOOR Asp.Trojan.Hafnium web shell upload attempt (more info ...)attempted-admin        
57321MALWARE-BACKDOOR Asp.Trojan.Hafnium web shell upload attempt (more info ...)attempted-admin        
57323MALWARE-OTHER Win.Ransomware.DoejoCrypt variant binary download attempt (more info ...)trojan-activity        URL
57324SERVER-WEBAPP Netis WF2419 router command injection attempt (more info ...)web-application-attack  2019-19356      URL
57326SERVER-WEBAPP Netis WF2419 router command injection attempt (more info ...)web-application-attack  2019-19356      URL
57327SERVER-WEBAPP Netis WF2419 router command injection attempt (more info ...)web-application-attack  2019-19356      URL
57332SERVER-WEBAPP Netgear ProSAFE Plus unauthenticated command injection attempt (more info ...)web-application-attack  2020-26919      URL
57334SERVER-WEBAPP Netgear ProSAFE Plus unauthenticated command injection attempt (more info ...)web-application-attack  2020-26919      URL
57335SERVER-WEBAPP Netgear ProSAFE Plus unauthenticated command injection attempt (more info ...)web-application-attack  2020-26919      URL
57337SERVER-WEBAPP F5 iControl REST interface ssrf attempt (more info ...)web-application-attack  2021-22986      URL
57338SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1273 attack attempt (more info ...)web-application-attack  2021-21804      URL
57339SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1273 attack attempt (more info ...)web-application-attack  2021-21804      URL
57361MALWARE-BACKDOOR PAS webshell inbound connection attempt (more info ...)trojan-activity        URL
57362MALWARE-BACKDOOR PAS webshell outbound connection attempt (more info ...)trojan-activity        URL
57363MALWARE-BACKDOOR PAS webshell inbound connection attempt (more info ...)trojan-activity        URL
57364MALWARE-BACKDOOR PAS webshell outbound connection attempt (more info ...)trojan-activity        URL
57367SERVER-WEBAPP Yealink Device Management server side request forgery attempt (more info ...)attempted-admin  2021-27562      URL
57371SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1277 attack attempt (more info ...)web-application-attack  2021-21809      URL
57372SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1277 attack attempt (more info ...)web-application-attack  2021-21809      URL
57373SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1277 attack attempt (more info ...)web-application-attack  2021-21809      URL
57374SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1277 attack attempt (more info ...)web-application-attack  2021-21809      URL
57377SERVER-ORACLE Oracle Weblogic ExternalizableLite T3 remote code execution attempt (more info ...)attempted-user  2020-14756      
57378FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1275 attack attempt (more info ...)attempted-user  2021-21807      URL
57379FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1275 attack attempt (more info ...)attempted-user  2021-21807      URL
57389SERVER-WEBAPP Advantech iView DeviceTreeTable directory traversal attempt (more info ...)web-application-attack  2020-16245      URL
57390SERVER-WEBAPP Advantech iView DeviceTreeTable directory traversal attempt (more info ...)web-application-attack  2020-16245      URL
57391SERVER-WEBAPP Advantech iView DeviceTreeTable directory traversal attempt (more info ...)web-application-attack  2020-16245      URL
57406SERVER-WEBAPP Palo Alto Networks management interface command injection attempt (more info ...)web-application-attack  2020-2038      
57407SERVER-WEBAPP Palo Alto Networks management interface command injection attempt (more info ...)web-application-attack  2020-2038      
57408SERVER-WEBAPP Palo Alto Networks management interface command injection attempt (more info ...)web-application-attack  2020-2038      
57409SERVER-WEBAPP Palo Alto Networks management interface command injection attempt (more info ...)web-application-attack  2020-2038      
57427FILE-PDF TRUFFLEHUNTER TALOS-2020-1157 attack attempt (more info ...)attempted-user  2020-24435      URL
57428FILE-PDF TRUFFLEHUNTER TALOS-2020-1157 attack attempt (more info ...)attempted-user  2020-24435      URL
57436SERVER-WEBAPP VMware View Planner logupload directory traversal attempt (more info ...)web-application-attack  2021-21978      
57437SERVER-WEBAPP VMware View Planner logupload directory traversal attempt (more info ...)web-application-attack  2021-21978      
57438SERVER-WEBAPP VMware View Planner logupload arbitrary file upload attempt (more info ...)web-application-attack  2021-21978      
57439SERVER-WEBAPP VMware View Planner logupload arbitrary file upload attempt (more info ...)web-application-attack  2021-21978      
57442SERVER-WEBAPP Terramaster TOS command injection attempt (more info ...)web-application-attack  2020-28188      URL
57443SERVER-WEBAPP Terramaster TOS command injection attempt (more info ...)web-application-attack  2020-28188      URL
57444SERVER-WEBAPP Terramaster TOS command injection attempt (more info ...)web-application-attack  2020-28188      URL
57445SERVER-WEBAPP Terramaster TOS command injection attempt (more info ...)web-application-attack  2020-28188      URL
57449SERVER-WEBAPP F5 TMM crafted IPv6 URI buffer overflow attempt (more info ...)attempted-user  2021-22991      URL
57452SERVER-WEBAPP Pulse Connect Secure template injection attempt (more info ...)attempted-admin  2020-8243      URL
57453SERVER-WEBAPP Pulse Connect Secure remote code execution attempt (more info ...)attempted-admin  2020-8243      URL
57454POLICY-OTHER Pulse Connect Secure vulnerable URI access attempt (more info ...)misc-activity  2021-22893      URL
57455POLICY-OTHER Pulse Connect Secure vulnerable URI access attempt (more info ...)misc-activity  2021-22893      URL
57456POLICY-OTHER Pulse Connect Secure vulnerable URI access attempt (more info ...)misc-activity  2021-22893      URL
57457POLICY-OTHER Pulse Connect Secure vulnerable URI access attempt (more info ...)misc-activity  2021-22893      URL
57458POLICY-OTHER Pulse Connect Secure vulnerable URI access attempt (more info ...)misc-activity  2021-22893      URL
57459POLICY-OTHER Pulse Connect Secure gzip configuration upload (more info ...)misc-activity  2020-8260      
57461MALWARE-BACKDOOR Perl.Backdoor.PULSECHECK variant cnc connection (more info ...)trojan-activity        URL
57462MALWARE-BACKDOOR Perl.Backdoor.STEADYPULSE webshell variant access (more info ...)trojan-activity        URL
57463MALWARE-BACKDOOR Perl.Backdoor.STEADYPULSE webshell variant access (more info ...)trojan-activity        URL
57464MALWARE-BACKDOOR Perl.Backdoor.HARDPULSE variant inbound cnc connection (more info ...)trojan-activity        URL
57465MALWARE-BACKDOOR Perl.Backdoor.STEADYPULSE variant inbound cnc connection (more info ...)trojan-activity        URL
57466MALWARE-BACKDOOR Perl.Backdoor.ATRIUM variant inbound cnc connection (more info ...)trojan-activity        URL
57467MALWARE-BACKDOOR Perl.Backdoor.SLIGHTPULSE variant inbound cnc connection (more info ...)trojan-activity        URL
57468MALWARE-BACKDOOR Perl.Backdoor.SLIGHTPULSE variant inbound cnc connection (more info ...)trojan-activity        URL
57469MALWARE-OTHER Win.Malware.Agent malicious script payload download attempt (more info ...)attempted-user        URL
57470MALWARE-OTHER Win.Malware.Agent malicious script payload download attempt (more info ...)attempted-user        URL
57471MALWARE-OTHER Win.Malware.LemonDuck variant payload download attempt (more info ...)attempted-user        URL
57472MALWARE-OTHER Win.Malware.LemonDuck variant payload download attempt (more info ...)attempted-user        URL
57473MALWARE-OTHER Win.Malware.LemonDuck variant payload download attempt (more info ...)attempted-user        URL
57475SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1284 attack attempt (more info ...)attempted-user  2021-21820      URL
57476SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1284 attack attempt (more info ...)attempted-user  2021-21820      URL
57479FILE-PDF TRUFFLEHUNTER TALOS-2021-1287 attack attempt (more info ...)attempted-user  2021-21870      URL
57480FILE-PDF TRUFFLEHUNTER TALOS-2021-1287 attack attempt (more info ...)attempted-user  2021-21870      URL
57481SERVER-WEBAPP ManageEngine OpManager directory traversal attempt (more info ...)web-application-attack  2021-20078      URL
57482SERVER-WEBAPP ManageEngine OpManager directory traversal attempt (more info ...)web-application-attack  2021-20078      URL
57483SERVER-WEBAPP ManageEngine OpManager directory traversal attempt (more info ...)web-application-attack  2021-20078      URL
57497INDICATOR-COMPROMISE Outbound request for known ProxyLogon cryptomining payload (more info ...)misc-attack        URL
57498INDICATOR-COMPROMISE Inbound request for known ProxyLogon cryptomining payload (more info ...)misc-attack        URL
57501FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1289 attack attempt (more info ...)attempted-user  2021-21824      URL
57502FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1289 attack attempt (more info ...)attempted-user  2021-21824      URL
57505FILE-OTHER TRUFFLEHUNTER TALOS-2021-1279 attack attempt (more info ...)attempted-user  2021-21811      URL
57506FILE-OTHER TRUFFLEHUNTER TALOS-2021-1279 attack attempt (more info ...)attempted-user  2021-21811      URL
57507FILE-OTHER TRUFFLEHUNTER TALOS-2021-1278 attack attempt (more info ...)attempted-user  2021-21810      URL
57508FILE-OTHER TRUFFLEHUNTER TALOS-2021-1278 attack attempt (more info ...)attempted-user  2021-21810      URL
57541MALWARE-BACKDOOR Perl.Backdoor.ATRIUM variant inbound cnc connection (more info ...)trojan-activity        URL
57546FILE-OTHER TRUFFLEHUNTER TALOS-2021-1295 attack attempt (more info ...)attempted-user  2021-21832      URL
57547FILE-OTHER TRUFFLEHUNTER TALOS-2021-1295 attack attempt (more info ...)attempted-user  2021-21832      URL
57585FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57586FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57587FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57588FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57589FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57590FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57591FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57592FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57593FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57594FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57595FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57596FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57597FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57598FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57599FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57600FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57601FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57602FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57603FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57604FILE-OTHER TRUFFLEHUNTER TALOS-2021-1304 attack attempt (more info ...)attempted-user  2021-21867      URL
57607FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21853      URL
57608FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21854      URL
57609FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21855      URL
57610FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21856      URL
57611FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21857      URL
57612FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21858      URL
57613FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21853      URL
57614FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21854      URL
57615FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21855      URL
57616FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21856      URL
57617FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21857      URL
57618FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1299 attack attempt (more info ...)attempted-user  2021-21858      URL
57619INDICATOR-SHELLCODE TRUFFLEHUNTER TALOS-2021-1300 attack attempt (more info ...)attempted-user  2021-21869      URL
57620INDICATOR-SHELLCODE TRUFFLEHUNTER TALOS-2021-1300 attack attempt (more info ...)attempted-user  2021-21869      URL
57621MALWARE-OTHER Win.Ransomware.REvil variant binary download attempt (more info ...)trojan-activity        URL
57622MALWARE-OTHER Win.Ransomware.REvil variant binary download attempt (more info ...)trojan-activity        URL
57623FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1298 attack attempt (more info ...)attempted-user  2021-21859      URL
57624FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1298 attack attempt (more info ...)attempted-user  2021-21859      URL
57625FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1298 attack attempt (more info ...)attempted-user  2021-21860      URL
57626FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1298 attack attempt (more info ...)attempted-user  2021-21860      URL
57627FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1298 attack attempt (more info ...)attempted-user  2021-21861      URL
57628FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1298 attack attempt (more info ...)attempted-user  2021-21861      URL
57629FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1298 attack attempt (more info ...)attempted-user  2021-21862      URL
57630FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1298 attack attempt (more info ...)attempted-user  2021-21862      URL
57635FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21834      URL
57636FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21834      URL
57637FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21835      URL
57638FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21835      URL
57639FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21836      URL
57640FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21836      URL
57641FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21837      URL
57642FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21837      URL
57643FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21838      URL
57644FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21838      URL
57645FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21839      URL
57646FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21839      URL
57647FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21840      URL
57648FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21840      URL
57649FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21841      URL
57650FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21841      URL
57651FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21842      URL
57652FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21842      URL
57653FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21843      URL
57654FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21843      URL
57655FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21844      URL
57656FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21844      URL
57657FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21845      URL
57658FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21845      URL
57659FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21846      URL
57660FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21846      URL
57661FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21847      URL
57662FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21847      URL
57663FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21848      URL
57664FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21848      URL
57665FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21849      URL
57666FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21849      URL
57667FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21850      URL
57668FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21850      URL
57669FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21851      URL
57670FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21851      URL
57671FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21852      URL
57672FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1297 attack attempt (more info ...)attempted-user  2021-21852      URL
57675MALWARE-OTHER Sliver HTTP implant outbound public key request attempt (more info ...)trojan-activity        URL
57676MALWARE-OTHER Sliver HTTP implant outbound public key request attempt (more info ...)trojan-activity        URL
57677MALWARE-OTHER Sliver HTTP implant outbound session initialization attempt (more info ...)trojan-activity        URL
57678MALWARE-OTHER Sliver HTTP implant outbound message attempt (more info ...)trojan-activity        URL
57679MALWARE-OTHER Sliver HTTP implant outbound message attempt (more info ...)trojan-activity        URL
57680MALWARE-OTHER Sliver HTTP implant outbound message attempt (more info ...)trojan-activity        URL
57681MALWARE-OTHER Sliver HTTP implant outbound poll attempt (more info ...)trojan-activity        URL
57682MALWARE-OTHER Sliver HTTP implant outbound public key request attempt (more info ...)trojan-activity        URL
57687MALWARE-OTHER Win.Trojan.Nobelium malicious shortcut download attempt (more info ...)trojan-activity        
57688MALWARE-OTHER Win.Trojan.Nobelium ISO download attempt (more info ...)trojan-activity        URL
57689MALWARE-OTHER Win.Trojan.Nobelium malicious shortcut download attempt (more info ...)trojan-activity        
57690MALWARE-OTHER Win.Trojan.Nobelium ISO download attempt (more info ...)trojan-activity        URL
57691MALWARE-OTHER Win.Trojan.Nobelium CobaltStrike beacon download attempt (more info ...)trojan-activity        URL
57692MALWARE-OTHER Win.Trojan.Nobelium CobaltStrike beacon download attempt (more info ...)trojan-activity        URL
57693MALWARE-TOOLS Py.Trojan.NecroBot TODELETE ious download attempt (more info ...)trojan-activity        URL
57694MALWARE-TOOLS Py.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57695MALWARE-TOOLS Py.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57696MALWARE-TOOLS Py.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57697MALWARE-TOOLS Html.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57698MALWARE-TOOLS Py.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57699MALWARE-TOOLS Html.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57700MALWARE-TOOLS Js.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57701MALWARE-TOOLS Js.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57702MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57703MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57704MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57705MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57709MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57710MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57711MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57712MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57713MALWARE-TOOLS Win.Trojan.NecroBot malicious download attempt (more info ...)trojan-activity        URL
57720SERVER-WEBAPP VMWare vSphere Client remote code execution attempt (more info ...)attempted-user  2021-21985      URL
57721MALWARE-BACKDOOR Win.Trojan.Moserpass outbound request attempt (more info ...)trojan-activity        URL
57728FILE-OTHER TRUFFLEHUNTER TALOS-2021-1308 attack attempt (more info ...)attempted-user  2021-21871      URL
57729FILE-OTHER TRUFFLEHUNTER TALOS-2021-1308 attack attempt (more info ...)attempted-user  2021-21871      URL
57732OS-WINDOWS Windows NTFS elevation of privilege attempt (more info ...)attempted-user  2021-31956      URL
57733OS-WINDOWS Windows NTFS elevation of privilege attempt (more info ...)attempted-user  2021-31956      URL
57739MALWARE-OTHER Win.Trojan.C3Framework payload download attempt (more info ...)trojan-activity        URL
57740MALWARE-OTHER Win.Trojan.C3Framework payload download attempt (more info ...)trojan-activity        URL
57741MALWARE-OTHER Win.Trojan.C3Framework payload download attempt (more info ...)trojan-activity        URL
57742MALWARE-OTHER Win.Trojan.C3Framework payload download attempt (more info ...)trojan-activity        URL
57745OS-OTHER TRUFFLEHUNTER TALOS-2021-1309 attack attempt (more info ...)attempted-recon        URL
57746OS-OTHER TRUFFLEHUNTER TALOS-2021-1309 attack attempt (more info ...)attempted-recon        URL
57747OS-OTHER TRUFFLEHUNTER TALOS-2021-1311 attack attempt (more info ...)attempted-dos        URL
57748OS-OTHER TRUFFLEHUNTER TALOS-2021-1311 attack attempt (more info ...)attempted-dos        URL
57749SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1319 attack attempt (more info ...)attempted-user        URL
57750SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1319 attack attempt (more info ...)attempted-user        URL
57751SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1318 attack attempt (more info ...)attempted-user        URL
57752SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1318 attack attempt (more info ...)attempted-user        URL
57753SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1312 attack attempt (more info ...)web-application-attack  2021-21872      URL
57754SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1312 attack attempt (more info ...)web-application-attack  2021-21872      URL
57755SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1312 attack attempt (more info ...)web-application-attack  2021-21872      URL
57757SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1327 attack attempt (more info ...)web-application-attack  2021-21883      URL
57758SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1327 attack attempt (more info ...)web-application-attack  2021-21883      URL
57759SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1327 attack attempt (more info ...)web-application-attack  2021-21883      URL
57761SERVER-WEBAPP TP-Link WiFi router authenticated PingIframeRpm stack buffer overflow attempt (more info ...)attempted-user  2017-13772      
57762SERVER-WEBAPP TP-Link WiFi router authenticated WanStaticIpV6CfgRpm stack buffer overflow attempt (more info ...)attempted-user  2017-13772      
57764SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1315 attack attempt (more info ...)web-application-attack  2021-21877      URL
57765SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1315 attack attempt (more info ...)web-application-attack  2021-21877      URL
57766SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1315 attack attempt (more info ...)web-application-attack  2021-21877      URL
57767SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1325 attack attempt (more info ...)web-application-attack  2021-21881      URL
57768SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1325 attack attempt (more info ...)web-application-attack  2021-21881      URL
57769SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1325 attack attempt (more info ...)web-application-attack  2021-21881      URL
57774SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1326 attack attempt (more info ...)web-application-attack  2021-21882      URL
57775SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1326 attack attempt (more info ...)web-application-attack  2021-21882      URL
57776SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1326 attack attempt (more info ...)web-application-attack  2021-21882      URL
57777SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1328 attack attempt (more info ...)web-application-attack  2021-21888      URL
57778SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1328 attack attempt (more info ...)web-application-attack  2021-21888      URL
57779SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1328 attack attempt (more info ...)web-application-attack  2021-21888      URL
57783SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1324 attack attempt (more info ...)web-application-attack  2021-21896      URL
57784SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1324 attack attempt (more info ...)web-application-attack  2021-21896      URL
57785SERVER-MAIL Exim spool file command injection attempt (more info ...)attempted-admin  2020-28021      URL
57786MALWARE-OTHER Win.Packed.SmokeLoader ransomware executable download attempt (more info ...)trojan-activity        URL
57787MALWARE-OTHER Win.Malware.Agent malicious executable download attempt (more info ...)trojan-activity        URL
57788MALWARE-OTHER Win.Trojan.Lazagne malicious executable download attempt (more info ...)trojan-activity        URL
57789MALWARE-OTHER Win.Trojan.Lazagne malicious executable download attempt (more info ...)trojan-activity        URL
57790MALWARE-OTHER Win.Malware.Agent malicious executable download attempt (more info ...)trojan-activity        URL
57791MALWARE-OTHER Win.Packed.SmokeLoader ransomware executable download attempt (more info ...)trojan-activity        URL
57792SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1314 attack attempt (more info ...)web-application-attack  2021-21875      URL
57793SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1314 attack attempt (more info ...)web-application-attack  2021-21875      URL
57794SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1314 attack attempt (more info ...)web-application-attack  2021-21875      URL
57795SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1314 attack attempt (more info ...)web-application-attack  2021-21875      URL
57796SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1323 attack attempt (more info ...)web-application-attack  2021-21879      URL
57798SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1320 attack attempt (more info ...)web-application-attack        URL
57799SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1320 attack attempt (more info ...)web-application-attack        URL
57800SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1331 attack attempt (more info ...)web-application-attack  2021-21887      URL
57801SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1331 attack attempt (more info ...)web-application-attack  2021-21887      URL
57802SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1317 attack attempt (more info ...)attempted-admin        URL
57803SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1313 attack attempt (more info ...)web-application-attack        URL
57804SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1334 attack attempt (more info ...)web-application-attack  2021-21891      URL
57805SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1335 attack attempt (more info ...)web-application-attack  2021-21892      URL
57806SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1333 attack attempt (more info ...)web-application-attack  2021-21889      URL
57814MALWARE-OTHER Win.Trojan.Deadwood download attempt (more info ...)trojan-activity        URL
57815MALWARE-OTHER Win.Trojan.Apostle download attempt (more info ...)trojan-activity        URL
57816MALWARE-OTHER ASPXSpy webshell download attempt (more info ...)trojan-activity        URL
57817MALWARE-OTHER ASPXSpy webshell upload attempt (more info ...)trojan-activity        URL
57818MALWARE-OTHER Win.Backdoor.IPSecHelper download attempt (more info ...)trojan-activity        URL
57819MALWARE-OTHER ASPXSpy webshell upload attempt (more info ...)trojan-activity        URL
57820MALWARE-OTHER ASPXSpy webshell download attempt (more info ...)trojan-activity        URL
57821MALWARE-OTHER Win.Trojan.Deadwood upload attempt (more info ...)trojan-activity        URL
57822MALWARE-OTHER Win.Trojan.Apostle upload attempt (more info ...)trojan-activity        URL
57829SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1316 attack attempt (more info ...)attempted-user        URL
57830FILE-PDF TRUFFLEHUNTER TALOS-2021-1336 attack attempt (more info ...)attempted-user  2021-21893      URL
57831FILE-PDF TRUFFLEHUNTER TALOS-2021-1336 attack attempt (more info ...)attempted-user  2021-21893      URL
57834SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center remote code execution attempt (more info ...)attempted-user  2019-5386      
57835SERVER-WEBAPP Nagios XI command injection attempt (more info ...)web-application-attack  2021-25298      URL
57836SERVER-WEBAPP Nagios XI command injection attempt (more info ...)web-application-attack  2021-25298      URL
57841SERVER-WEBAPP Nagios Fusion command injection attempt (more info ...)web-application-attack  2020-28905      URL
57850MALWARE-OTHER Win.Backdoor.VictoryDll variant download attempt (more info ...)trojan-activity        URL
57851MALWARE-OTHER Doc.Dropper.RoyalRoadRTF variant download attempt (more info ...)trojan-activity        URL
57852MALWARE-OTHER Win.Downloader.VictoryDll variant download attempt (more info ...)trojan-activity        URL
57853MALWARE-OTHER Win.Backdoor.VictoryDll variant download attempt (more info ...)trojan-activity        URL
57854MALWARE-OTHER Doc.Dropper.RoyalRoadRTF variant download attempt (more info ...)trojan-activity        URL
57855MALWARE-OTHER Win.Downloader.VictoryDll variant download attempt (more info ...)trojan-activity        URL
57859MALWARE-OTHER Win.Trojan.BazaCall variant phishing e-mail detected (more info ...)trojan-activity        URL
57860SERVER-WEBAPP Trend Micro SafeSync for Enterprise command injection attempt (more info ...)web-application-attack        
57861SERVER-WEBAPP Trend Micro SafeSync for Enterprise command injection attempt (more info ...)web-application-attack        
57862SERVER-WEBAPP Trend Micro SafeSync for Enterprise command injection attempt (more info ...)web-application-attack        
57863SERVER-WEBAPP Trend Micro SafeSync for Enterprise command injection attempt (more info ...)web-application-attack        
57872SERVER-WEBAPP Facade Ignition remote code execution attempt (more info ...)attempted-user  2021-3129      URL
57873MALWARE-OTHER Win.Ransomware.Babuk payload download attempt (more info ...)trojan-activity        URL
57874MALWARE-OTHER Win.Ransomware.Babuk payload download attempt (more info ...)trojan-activity        URL
57879INDICATOR-COMPROMISE Revil Kaseya ransomware log clearing http upload (more info ...)web-application-attack        URL
57880OS-WINDOWS TRUFFLEHUNTER SFVRT-1044 attack attempt (more info ...)attempted-dos        
57881OS-WINDOWS TRUFFLEHUNTER SFVRT-1044 attack attempt (more info ...)attempted-dos        
57888OS-OTHER TRUFFLEHUNTER TALOS-2021-1339 attack attempt (more info ...)attempted-recon        URL
57889OS-OTHER TRUFFLEHUNTER TALOS-2021-1339 attack attempt (more info ...)attempted-recon        URL
57898SERVER-OTHER SolarWinds Network Performance Monitor insecure deserialization attempt (more info ...)attempted-user  2021-31474      URL
57899OS-OTHER TRUFFLEHUNTER TALOS-2021-1340 attack attempt (more info ...)attempted-recon        URL
57900OS-OTHER TRUFFLEHUNTER TALOS-2021-1340 attack attempt (more info ...)attempted-recon        URL
57902SERVER-WEBAPP HPE Systems Insight Manager remote code execution attempt (more info ...)attempted-user  2020-7200      URL
57903SERVER-OTHER Kaseya authentication bypass attempt (more info ...)attempted-user        
57904SERVER-OTHER Kaseya authentication bypass attempt (more info ...)attempted-user        
57905SERVER-OTHER Kaseya authentication bypass attempt (more info ...)attempted-user        
57912SERVER-WEBAPP ForgeRock Open Access Manager remote code execution attempt (more info ...)attempted-admin  2021-35464      URL
57913SERVER-WEBAPP ForgeRock Open Access Manager remote code execution attempt (more info ...)attempted-admin  2021-35464      URL
57931FILE-OTHER ExifTool DjVu metadata command injection injection attempt (more info ...)attempted-user  2021-22205      URL
57932FILE-OTHER ExifTool DjVu metadata command injection injection attempt (more info ...)attempted-user  2021-22204      URL
57933FILE-OTHER ExifTool DjVu metadata command injection injection attempt (more info ...)attempted-user  2021-22204      URL
57936MALWARE-OTHER Win.Dropper.Raccoon malicious file download attempt (more info ...)trojan-activity        URL
57937MALWARE-OTHER Win.Dropper.Raccoon malicious file download attempt (more info ...)trojan-activity        URL
57963OS-OTHER TRUFFLEHUNTER TALOS-2021-1347 attack attempt (more info ...)attempted-dos        URL
57964OS-OTHER TRUFFLEHUNTER TALOS-2021-1347 attack attempt (more info ...)attempted-dos        URL
57967FILE-OTHER TRUFFLEHUNTER TALOS-2021-1350 attack attempt (more info ...)attempted-user  2021-21899      URL
57968FILE-OTHER TRUFFLEHUNTER TALOS-2021-1350 attack attempt (more info ...)attempted-user  2021-21899      URL
57969BROWSER-OTHER TRUFFLEHUNTER TALOS-2021-1345 attack attempt (more info ...)attempted-user        URL
57970BROWSER-OTHER TRUFFLEHUNTER TALOS-2021-1345 attack attempt (more info ...)attempted-user        URL
57971FILE-OTHER TRUFFLEHUNTER TALOS-2021-1346 attack attempt (more info ...)attempted-user  2021-21897      URL
57972FILE-OTHER TRUFFLEHUNTER TALOS-2021-1346 attack attempt (more info ...)attempted-user  2021-21897      URL
57976FILE-OTHER TRUFFLEHUNTER TALOS-2021-1349 attack attempt (more info ...)attempted-user  2021-21898      URL
57977FILE-OTHER TRUFFLEHUNTER TALOS-2021-1349 attack attempt (more info ...)attempted-user  2021-21898      URL
57978FILE-OTHER TRUFFLEHUNTER TALOS-2021-1351 attack attempt (more info ...)attempted-user  2021-21900      URL
57979FILE-OTHER TRUFFLEHUNTER TALOS-2021-1351 attack attempt (more info ...)attempted-user  2021-21900      URL
57990MALWARE-OTHER Muhstik botnet outbound HTTP scanner request (more info ...)attempted-recon        URL
58010SERVER-OTHER Advantech WebAccess pointer dereference remote code execution attempt (more info ...)attempted-admin  2017-12719      
58014SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1356 attack attempt (more info ...)attempted-admin  2021-21909      URL
58017SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1357 attack attempt (more info ...)attempted-admin  2021-21905      URL
58018SERVER-WEBAPP Fortinet FortiWeb SAML server configuration page command injection attempt (more info ...)web-application-attack        URL
58019SERVER-WEBAPP Fortinet FortiWeb SAML server configuration page command injection attempt (more info ...)web-application-attack        URL
58020SERVER-WEBAPP Fortinet FortiWeb SAML server configuration page command injection attempt (more info ...)web-application-attack        URL
58021SERVER-WEBAPP Fortinet FortiWeb SAML server configuration page command injection attempt (more info ...)web-application-attack        URL
58024MALWARE-OTHER Win.Ransomware.Lockbit download attempt (more info ...)trojan-activity        URL
58025MALWARE-OTHER Win.Ransomware.Lockbit upload attempt (more info ...)trojan-activity        URL
58034SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1363 attack attempt (more info ...)web-application-attack  2021-21917      URL
58035SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1363 attack attempt (more info ...)web-application-attack  2021-21917      URL
58036SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1366 attack attempt (more info ...)web-application-attack  2021-21937      URL
58037SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1366 attack attempt (more info ...)web-application-attack  2021-21937      URL
58038SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1365 attack attempt (more info ...)web-application-attack  2021-21923      URL
58039SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1365 attack attempt (more info ...)web-application-attack  2021-21923      URL
58040SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1364 attack attempt (more info ...)web-application-attack  2021-21919      URL
58041SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1364 attack attempt (more info ...)web-application-attack  2021-21919      URL
58046FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1362 attack attempt (more info ...)attempted-user  2021-21914      URL
58047FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1362 attack attempt (more info ...)attempted-user  2021-21914      URL
58052SERVER-WEBAPP Realtek Jungle SDK command injection attempt (more info ...)web-application-attack  2021-35395      
58053SERVER-WEBAPP Realtek Jungle SDK command injection attempt (more info ...)web-application-attack  2021-35395      
58054SERVER-WEBAPP Realtek Jungle SDK command injection attempt (more info ...)web-application-attack  2021-35395      
58055SERVER-WEBAPP Realtek Jungle SDK command injection attempt (more info ...)web-application-attack  2021-35395      
58056SERVER-WEBAPP Realtek Jungle SDK command injection attempt (more info ...)web-application-attack  2021-35395      
58057SERVER-WEBAPP Realtek Jungle SDK command injection attempt (more info ...)web-application-attack  2021-35395      
58058SERVER-WEBAPP Realtek Jungle SDK command injection attempt (more info ...)web-application-attack  2021-35395      
58059SERVER-WEBAPP Realtek Jungle SDK command injection attempt (more info ...)web-application-attack  2021-35395      
58063SERVER-WEBAPP Kentico CMS unsafe deserialization remote code execution attempt (more info ...)attempted-admin  2019-10068      
58064SERVER-WEBAPP Kentico CMS unsafe deserialization remote code execution attempt (more info ...)attempted-admin  2019-10068      
58065SERVER-WEBAPP Nagios XI command injection attempt (more info ...)web-application-attack  2021-25298      URL
58066SERVER-WEBAPP Nagios XI command injection attempt (more info ...)web-application-attack  2021-25298      URL
58073FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1368 attack attempt (more info ...)attempted-user  2021-21939      URL
58074FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1368 attack attempt (more info ...)attempted-user  2021-21939      URL
58075SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1369 attack attempt (more info ...)attempted-user  2021-21940      URL
58076SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1369 attack attempt (more info ...)attempted-user  2021-21940      URL
58077SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1369 attack attempt (more info ...)attempted-user  2021-21940      URL
58078SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1369 attack attempt (more info ...)attempted-user  2021-21940      URL
58079SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1369 attack attempt (more info ...)attempted-user  2021-21940      URL
58080SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1369 attack attempt (more info ...)attempted-user  2021-21940      URL
58083MALWARE-OTHER Vbs.Worm.HWorm variant script download attempt (more info ...)trojan-activity        
58084MALWARE-OTHER Vbs.Worm.HWorm variant script download attempt (more info ...)trojan-activity        
58085MALWARE-OTHER Win.Trojan.Aspire variant binary download attempt (more info ...)trojan-activity        URL
58093SERVER-WEBAPP Atlassian Confluence OGNL injection remote code execution attempt (more info ...)attempted-admin  2021-26084      URL
58094SERVER-WEBAPP Atlassian Confluence OGNL injection remote code execution attempt (more info ...)attempted-admin  2021-26084      URL
58095MALWARE-OTHER Asp.Webshell.Ajan download attempt (more info ...)trojan-activity        URL
58096MALWARE-OTHER Asp.Webshell.Ajan upload attempt (more info ...)trojan-activity        URL
58100FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1367 attack attempt (more info ...)attempted-user  2021-21938      URL
58101FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1367 attack attempt (more info ...)attempted-user  2021-21938      URL
58146SERVER-OTHER Realtek Wifi Simple Config UPnP SUBSCRIBE callback buffer overflow attempt (more info ...)attempted-user  2021-35393      
58147MALWARE-OTHER ASP.Webshell.RemExp download attempt (more info ...)trojan-activity        URL
58148MALWARE-OTHER ASP.Webshell.RemExp upload attempt (more info ...)trojan-activity        URL
58156FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1371 attack attempt (more info ...)attempted-user  2021-21942      URL
58157FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1371 attack attempt (more info ...)attempted-user  2021-21942      URL
58158FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1371 attack attempt (more info ...)attempted-user  2021-21942      URL
58159FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1371 attack attempt (more info ...)attempted-user  2021-21942      URL
58163MALWARE-OTHER Asp.Webshell.Zehir upload attempt (more info ...)trojan-activity        URL
58164MALWARE-OTHER Asp.Webshell.Zehir download attempt (more info ...)trojan-activity        URL
58174MALWARE-OTHER Asp.Webshell.Cmd download attempt (more info ...)trojan-activity        URL
58175MALWARE-OTHER Asp.Webshell.Cmd download attempt (more info ...)trojan-activity        URL
58176MALWARE-OTHER Asp.Webshell.Cmd upload attempt (more info ...)trojan-activity        URL
58177MALWARE-OTHER Asp.Webshell.Cmd upload attempt (more info ...)trojan-activity        URL
58178MALWARE-OTHER Asp.Webshell.Cmd download attempt (more info ...)trojan-activity        URL
58179MALWARE-OTHER Asp.Webshell.Cmd upload attempt (more info ...)trojan-activity        URL
58180MALWARE-OTHER Jsp.Webshell.Hsxa download attempt (more info ...)trojan-activity        URL
58181MALWARE-OTHER Jsp.Webshell.Hsxa upload attempt (more info ...)trojan-activity        URL
58192OS-OTHER Apple macOS Finder remote code execution inetloc file download attempt (more info ...)attempted-user        URL
58193OS-OTHER Apple macOS Finder remote code execution inetloc file download attempt (more info ...)attempted-user        URL
58194MALWARE-OTHER Win.Trojan.Bandidos inbound delivery attempt (more info ...)trojan-activity        URL
58195MALWARE-OTHER Win.Trojan.Bandidos inbound delivery attempt (more info ...)trojan-activity        URL
58200MALWARE-OTHER Webshell.Backdoor.Agent variant upload detected (more info ...)attempted-admin        URL
58201SERVER-WEBAPP Zoho ManageEngine ADSelfService Plus RestAPI authentication bypass attempt (more info ...)attempted-user  2021-40539      URL
58202MALWARE-OTHER Standard Bank credential phishing attempt (more info ...)attempted-user        
58203MALWARE-OTHER Banking credential phishing attempt (more info ...)attempted-user        
58204MALWARE-OTHER Absa Bank credential phishing attempt (more info ...)attempted-user        
58206MALWARE-OTHER Standard Bank credential phishing attempt (more info ...)attempted-user        
58207MALWARE-OTHER Banking credential phishing attempt (more info ...)attempted-user        
58208MALWARE-OTHER Absa Bank credential phishing attempt (more info ...)attempted-user        
58210MALWARE-OTHER Standard Bank credential phishing attempt (more info ...)attempted-user        
58211MALWARE-OTHER Standard Bank credential phishing attempt (more info ...)attempted-user        
58212MALWARE-OTHER Absa Bank credential phishing attempt (more info ...)attempted-user        
58213MALWARE-OTHER Absa Bank credential phishing attempt (more info ...)attempted-user        
58214MALWARE-OTHER Email credential phishing attempt (more info ...)attempted-user        
58215MALWARE-OTHER Email credential phishing attempt (more info ...)attempted-user        
58217SERVER-WEBAPP VMware vCenter Server remote code execution attempt (more info ...)web-application-attack  2021-22005      URL
58218SERVER-WEBAPP VMware vCenter Server file upload attempt (more info ...)web-application-attack  2021-22017      URL
58219SERVER-WEBAPP VMware vCenter Server file upload attempt (more info ...)web-application-attack  2021-22005      URL
58220FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1375 attack attempt (more info ...)attempted-user  2021-21946      URL
58221FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1375 attack attempt (more info ...)attempted-user  2021-21947      URL
58222FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1375 attack attempt (more info ...)attempted-user  2021-21946      URL
58223FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1375 attack attempt (more info ...)attempted-user  2021-21947      URL
58227SERVER-WEBAPP Dell EMC Virtual Appliance Manager undocumented credential use attempt (more info ...)attempted-user  2018-1216      
58230SERVER-WEBAPP QNAP NAS Malware Remover directory traversal attempt (more info ...)web-application-attack  2020-36198      
58231SERVER-WEBAPP QNAP NAS Malware Remover directory traversal attempt (more info ...)web-application-attack  2020-36198      
58232SERVER-WEBAPP QNAP NAS Malware Remover directory traversal attempt (more info ...)web-application-attack  2020-36198      
58233FILE-OTHER TRUFFLEHUNTER TALOS-2021-1376 attack attempt (more info ...)attempted-user  2021-21948      URL
58234FILE-OTHER TRUFFLEHUNTER TALOS-2021-1376 attack attempt (more info ...)attempted-user  2021-21948      URL
58235FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1377 attack attempt (more info ...)attempted-user  2021-21949      URL
58236FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1377 attack attempt (more info ...)attempted-user  2021-21949      URL
58237MALWARE-TOOLS Win.Ransomware.BlackMatter variant download attempt (more info ...)trojan-activity        URL
58245SERVER-WEBAPP UDP Technology IP Camera command injection attempt (more info ...)web-application-attack  2021-33544      
58246SERVER-WEBAPP UDP Technology IP Camera command injection attempt (more info ...)web-application-attack  2021-33544      
58247SERVER-WEBAPP UDP Technology IP Camera command injection attempt (more info ...)web-application-attack  2021-33544      
58248SERVER-WEBAPP UDP Technology IP Camera command injection attempt (more info ...)web-application-attack  2021-33544      
58250PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2021-1381 attack attempt (more info ...)attempted-admin  2021-21954      URL
58251PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2021-1379 attack attempt (more info ...)attempted-admin  2021-21952      URL
58252FILE-OTHER TRUFFLEHUNTER TALOS-2021-1383 attack attempt (more info ...)attempted-admin  2021-21956      URL
58253FILE-OTHER TRUFFLEHUNTER TALOS-2021-1383 attack attempt (more info ...)attempted-admin  2021-21956      URL
58263SERVER-WEBAPP MailEnable Enterprise Premium directory traversal attempt (more info ...)web-application-attack  2019-12925      
58264SERVER-WEBAPP MailEnable Enterprise Premium directory traversal attempt (more info ...)web-application-attack  2019-12925      
58265SERVER-WEBAPP MailEnable Enterprise Premium directory traversal attempt (more info ...)web-application-attack  2019-12925      
58266SERVER-WEBAPP MailEnable Enterprise Premium directory traversal attempt (more info ...)web-application-attack  2019-12925      
58267SERVER-WEBAPP MailEnable Enterprise Premium directory traversal attempt (more info ...)web-application-attack  2019-12925      
58268SERVER-WEBAPP MailEnable Enterprise Premium directory traversal attempt (more info ...)web-application-attack  2019-12925      
58269SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4222      
58270SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4222      
58271SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4222      
58272SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack  2020-4222      
58273SERVER-WEBAPP QNAP HBS 3 authorization bypass attempt (more info ...)web-application-activity  2021-28799      URL
58274SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center faultDevParasSet expression language injection attempt (more info ...)web-application-attack        URL
58275SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center faultDevParasSet expression language injection attempt (more info ...)web-application-attack        URL
58284SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center FileUploadServlet Unrestricted arbitrary JSP file upload attempt (more info ...)attempted-admin        
58285SERVER-WEBAPP Trend Micro Control Manager ProductTree_RightWindow XML external entity injection attempt (more info ...)web-application-attack        
58290SERVER-WEBAPP Trend Micro Encryption for Email Gateway registration command injection attempt (more info ...)web-application-attack  2018-10354      
58291SERVER-WEBAPP Trend Micro Encryption for Email Gateway registration command injection attempt (more info ...)web-application-attack  2018-10354      
58292SERVER-WEBAPP Trend Micro Encryption for Email Gateway registration command injection attempt (more info ...)web-application-attack  2018-10354      
58293SERVER-WEBAPP Trend Micro Encryption for Email Gateway registration command injection attempt (more info ...)web-application-attack  2018-10354      
58298PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2021-1378 attack attempt (more info ...)attempted-admin  2021-21951      URL
58326SERVER-WEBAPP ARRIS VAP2500 list_mac_address macaddr command injection attempt (more info ...)web-application-attack        
58327SERVER-WEBAPP ARRIS VAP2500 list_mac_address macaddr command injection attempt (more info ...)web-application-attack        
58328SERVER-WEBAPP ARRIS VAP2500 list_mac_address macaddr command injection attempt (more info ...)web-application-attack        
58329SERVER-WEBAPP ARRIS VAP2500 list_mac_address macaddr command injection attempt (more info ...)web-application-attack        
58333SERVER-WEBAPP Trend Micro Control Manager DeploymentPlan_Event_Handler XML external entity injection attempt (more info ...)web-application-attack        
58352SERVER-WEBAPP GE MDS PulseNET IntegrationXMLProcessorServlet UpdateProblemTickets XML external entity injection attempt (more info ...)web-application-attack  2018-10613      
58360MALWARE-OTHER Andr.Downloader.AndroSpy shell script download attempt (more info ...)trojan-activity        
58361MALWARE-OTHER Andr.Downloader.AndroSpy shell script download attempt (more info ...)trojan-activity        
58367FILE-PDF TRUFFLEHUNTER TALOS-2021-1387 attack attempt (more info ...)attempted-user        URL
58368FILE-PDF TRUFFLEHUNTER TALOS-2021-1387 attack attempt (more info ...)attempted-user        URL
58375SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center iccSelectCommand expression language injection attempt (more info ...)web-application-attack        
58376SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center iccSelectCommand expression language injection attempt (more info ...)web-application-attack        
58377SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center eventInfo_content expression language injection attempt (more info ...)web-application-attack        
58378SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center eventInfo_content expression language injection attempt (more info ...)web-application-attack        
58386SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1390 attack attempt (more info ...)attempted-admin  2021-21962      URL
58387SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1393 attack attempt (more info ...)attempted-recon  2021-21966      URL
58388SERVER-WEBAPP ARRIS VAP2500 config_wds command injection attempt (more info ...)web-application-attack        
58399SERVER-WEBAPP Nagios XI directory traversal attempt (more info ...)web-application-attack  2021-37343      
58400SERVER-WEBAPP Nagios XI directory traversal attempt (more info ...)web-application-attack  2021-37343      
58401SERVER-WEBAPP Nagios XI directory traversal attempt (more info ...)web-application-attack  2021-37343      
58403SERVER-WEBAPP Nagios XI Watchguard wizard command injection attempt (more info ...)web-application-attack  2021-37346      
58404SERVER-WEBAPP Nagios XI Watchguard wizard command injection attempt (more info ...)web-application-attack  2021-37346      
58405SERVER-WEBAPP Nagios XI Watchguard wizard command injection attempt (more info ...)web-application-attack  2021-37346      
58406SERVER-WEBAPP Nagios XI Watchguard wizard command injection attempt (more info ...)web-application-attack  2021-37346      
58414SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1395 attack attempt (more info ...)attempted-admin  2021-21968      URL
58415SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1396 attack attempt (more info ...)attempted-admin  2021-21969      URL
58416SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1396 attack attempt (more info ...)attempted-admin  2021-21970      URL
58417SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1394 attack attempt (more info ...)attempted-admin  2021-21967      URL
58418SERVER-WEBAPP ReadyDesk 9.1 OpenAttach2 directory traversal attempt (more info ...)web-application-attack  2016-5049      
58419SERVER-WEBAPP ReadyDesk 9.1 OpenAttach2 directory traversal attempt (more info ...)web-application-attack  2016-5049      
58420SERVER-WEBAPP ReadyDesk 9.1 OpenAttach2 directory traversal attempt (more info ...)web-application-attack  2016-5049      
58424SERVER-WEBAPP Schneider Electric Umotion Builder Virtual Appliance Css directory traversal attempt (more info ...)web-application-attack        
58425SERVER-WEBAPP Schneider Electric Umotion Builder Virtual Appliance Css directory traversal attempt (more info ...)web-application-attack        
58426SERVER-WEBAPP Schneider Electric Umotion Builder Virtual Appliance Css directory traversal attempt (more info ...)web-application-attack        
58427SERVER-WEBAPP Trend Micro Control Manager widget_old_SP1 dlp_policy directory traversal attempt (more info ...)web-application-attack        
58449SERVER-WEBAPP Sophos SG UTM WebAdmin command injection attempt (more info ...)web-application-attack  2020-25223      
58450SERVER-WEBAPP Sophos SG UTM WebAdmin command injection attempt (more info ...)web-application-attack  2020-25223      
58454SERVER-WEBAPP ARRIS VAP2500 assoc_table command injection attempt (more info ...)web-application-attack        
58455SERVER-WEBAPP ARRIS VAP2500 assoc_table command injection attempt (more info ...)web-application-attack        
58456SERVER-WEBAPP ARRIS VAP2500 assoc_table command injection attempt (more info ...)web-application-attack        
58457SERVER-WEBAPP ARRIS VAP2500 assoc_table command injection attempt (more info ...)web-application-attack        
58458SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1397 attack attempt (more info ...)attempted-admin  2021-21971      URL
58464SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance File Deletion directory traversal attempt (more info ...)web-application-attack        
58465SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance File Deletion directory traversal attempt (more info ...)web-application-attack        
58466SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance File Deletion directory traversal attempt (more info ...)web-application-attack        
58467SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance directory traversal attempt (more info ...)web-application-attack        
58468SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance directory traversal attempt (more info ...)web-application-attack        
58469SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance directory traversal attempt (more info ...)web-application-attack        
58475SERVER-WEBAPP Oracle WebLogic Server DeploymentService directory traversal attempt (more info ...)web-application-attack  2019-2827      
58476SERVER-WEBAPP Oracle WebLogic Server DeploymentService directory traversal attempt (more info ...)web-application-attack  2019-2827      
58491MALWARE-OTHER Tool.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58492MALWARE-OTHER Tool.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58493MALWARE-OTHER Tool.Webshell.Generic upload attempt (more info ...)trojan-activity        URL
58494MALWARE-OTHER Tool.Webshell.Generic download attempt (more info ...)trojan-activity        URL
58499SERVER-WEBAPP Zyxel Unified Security Gateway undocumented administrator account login attempt (more info ...)attempted-user  2020-29583      
58500SERVER-WEBAPP Zyxel Unified Security Gateway undocumented administrator account login attempt (more info ...)attempted-user  2020-29583      
58501SERVER-OTHER Zyxel Unified Security Gateway undocumented administrator account login attempt (more info ...)attempted-user  2020-29583      
58502SERVER-WEBAPP SonicWall Email Security directory traversal attempt (more info ...)web-application-attack  2021-20023      
58503SERVER-WEBAPP SonicWall Email Security directory traversal attempt (more info ...)web-application-attack  2021-20023      
58504SERVER-WEBAPP SonicWall Email Security directory traversal attempt (more info ...)web-application-attack  2021-20023      
58505SERVER-WEBAPP Tenda Router command injection attempt (more info ...)web-application-attack  2022-32054      
58506SERVER-WEBAPP Tenda Router command injection attempt (more info ...)web-application-attack  2022-32054      
58507SERVER-WEBAPP Tenda Router command injection attempt (more info ...)web-application-attack  2022-32054      
58508SERVER-WEBAPP Tenda Router command injection attempt (more info ...)web-application-attack  2022-32054      
58517SERVER-WEBAPP GE MDS PulseNET IntegrationXMLProcessorServlet AlarmActions XML external entity injection attempt (more info ...)web-application-attack  2018-10613      
58518SERVER-OTHER D-Link DIR-825 R1 buffer overflow attempt (more info ...)attempted-user  2020-29557      
58525SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center directory traversal attempt (more info ...)web-application-attack  2017-5794      
58529SERVER-WEBAPP Buffalo WSR router configuration injection attempt (more info ...)web-application-attack  2021-20091      URL
58530SERVER-WEBAPP Buffalo WSR router configuration injection attempt (more info ...)web-application-attack  2021-20091      URL
58531SERVER-WEBAPP Buffalo WSR router configuration injection attempt (more info ...)web-application-attack  2021-20091      URL
58532SERVER-WEBAPP Buffalo WSR router configuration injection attempt (more info ...)web-application-attack  2021-20091      URL
58533SERVER-WEBAPP Buffalo WSR router configuration injection attempt (more info ...)web-application-attack  2021-20091      URL
58538SERVER-WEBAPP Arcadyan routers path traversal attempt (more info ...)web-application-attack  2021-20090      URL
58551SERVER-WEBAPP Micro Focus OBR command injection attempt (more info ...)web-application-attack  2021-22502      
58552SERVER-WEBAPP Micro Focus OBR command injection attempt (more info ...)web-application-attack  2021-22502      
58553FILE-PDF TRUFFLEHUNTER TALOS-2021-1410 attack attempt (more info ...)attempted-user        URL
58554FILE-PDF TRUFFLEHUNTER TALOS-2021-1410 attack attempt (more info ...)attempted-user        URL
58562SERVER-WEBAPP Oracle WebLogic Server remote code execution attempt (more info ...)web-application-attack  2020-14883      
58565FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1414 attack attempt (more info ...)attempted-user        URL
58566FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1414 attack attempt (more info ...)attempted-user        URL
58567SERVER-WEBAPP Roundcube Webmail file disclosure attempt (more info ...)attempted-user  2017-16651      
58568SERVER-WEBAPP Roundcube Webmail file disclosure attempt (more info ...)attempted-user  2017-16651      
58569SERVER-WEBAPP Roundcube Webmail file disclosure attempt (more info ...)attempted-user  2017-16651      
58571FILE-OTHER MacOS TTC bypass vulnerability exploit download attempt (more info ...)attempted-admin  2021-30713      
58572FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1411 attack attempt (more info ...)attempted-user  2021-40398      URL
58573FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1411 attack attempt (more info ...)attempted-user  2021-40398      URL
58576SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        URL
58577SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        URL
58578SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        URL
58579SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        URL
58580MALWARE-TOOLS TeamViewer shared AES key decryption tool download attempt (more info ...)attempted-user  2019-18988      URL
58581MALWARE-TOOLS TeamViewer shared AES key decryption tool download attempt (more info ...)attempted-user  2019-18988      URL
58588SERVER-WEBAPP SolarWinds Network Configuration Manager remote file include attempt (more info ...)web-application-attack  2020-27871      
58589SERVER-WEBAPP SolarWinds Network Configuration Manager remote file include attempt (more info ...)web-application-attack  2020-27871      
58592SERVER-WEBAPP SaltStack pillar_roots directory traversal attempt (more info ...)web-application-attack  2021-25282      
58593SERVER-WEBAPP SaltStack pillar_roots directory traversal attempt (more info ...)web-application-attack  2021-25282      
58594SERVER-WEBAPP SaltStack pillar_roots directory traversal attempt (more info ...)web-application-attack  2021-25282      
58605SERVER-WEBAPP Citrix StoreFront Server XML external entity injection attempt (more info ...)web-application-attack  2019-13608      
58618SERVER-OTHER Amcrest Dahua NVR Camera IP2M-841 denial of service attempt (more info ...)attempted-dos  2020-5735      
58621FILE-OTHER Apple iOS Webkit universal XSS attempt (more info ...)attempted-user  2021-1879      
58622FILE-OTHER Apple iOS Webkit universal XSS attempt (more info ...)attempted-user  2021-1879      
58632SERVER-OTHER SolarWinds Orion MSMQ remote code execution attempt (more info ...)attempted-admin  2021-25274      
58633FILE-OTHER TRUFFLEHUNTER TALOS-2021-1416 attack attempt (more info ...)attempted-user  2021-40402      URL
58634FILE-OTHER TRUFFLEHUNTER TALOS-2021-1416 attack attempt (more info ...)attempted-user  2021-40402      URL
58646SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        
58647SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        
58648SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        
58649SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        
58673POLICY-OTHER Dell SonicWall Email Security administrator account creation attempt (more info ...)policy-violation  2021-20021      URL
58674POLICY-OTHER Dell SonicWall Email Security administrator account creation attempt (more info ...)policy-violation  2021-20021      URL
58675POLICY-OTHER Dell SonicWall Email Security administrator account creation attempt (more info ...)policy-violation  2021-20021      URL
58676SERVER-WEBAPP GE MDS PulseNET FileServlet directory traversal attempt (more info ...)web-application-attack  2018-10615      
58677SERVER-WEBAPP GE MDS PulseNET FileServlet directory traversal attempt (more info ...)web-application-attack  2018-10615      
58678SERVER-WEBAPP GE MDS PulseNET FileServlet directory traversal attempt (more info ...)web-application-attack  2018-10615      
58679SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        
58680SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        
58681SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        
58682SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack        
58685FILE-OTHER HP Multi-Function Printer memory corruption attempt (more info ...)attempted-user  2021-39238      URL
58686FILE-OTHER HP Multi-Function Printer memory corruption attempt (more info ...)attempted-user  2021-39238      URL
58687SERVER-WEBAPP Movable Type CMS command injection attempt (more info ...)web-application-attack  2021-20837      
58688SERVER-WEBAPP Movable Type CMS command injection attempt (more info ...)web-application-attack  2021-20837      
58689FILE-OTHER TRUFFLEHUNTER TALOS-2021-1419 attack attempt (more info ...)attempted-dos        URL
58690FILE-OTHER TRUFFLEHUNTER TALOS-2021-1419 attack attempt (more info ...)attempted-dos        URL
58691SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1424 attack attempt (more info ...)web-application-attack  2021-40409      URL
58692SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1424 attack attempt (more info ...)web-application-attack  2021-40411      URL
58693SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1424 attack attempt (more info ...)web-application-attack  2021-40412      URL
58694SERVER-WEBAPP Mitsubishi Electric SmartRTU command injection attempt (more info ...)web-application-attack  2019-14931      URL
58695SERVER-WEBAPP Mitsubishi Electric SmartRTU command injection attempt (more info ...)web-application-attack  2019-14931      URL
58696SERVER-WEBAPP Zoho ManageEngine Service Desk arbitrary file upload attempt (more info ...)web-application-attack  2021-44077      URL
58697OS-OTHER IGEL OS Secure Terminal and Shadow Service command injection attempt (more info ...)attempted-user        URL
58703SERVER-WEBAPP Zoho ManageEngine ADSelfService Plus RestAPI authentication bypass attempt (more info ...)attempted-user  2021-40539      URL
58704SERVER-WEBAPP FaceSentry Access Control Remote Command Injection command injection attempt (more info ...)web-application-attack  2019-5523      URL
58705SERVER-WEBAPP FaceSentry Access Control Remote Command Injection command injection attempt (more info ...)web-application-attack  2019-5523      URL
58706SERVER-WEBAPP FaceSentry Access Control Remote Command Injection command injection attempt (more info ...)web-application-attack  2019-5523      URL
58707SERVER-WEBAPP FaceSentry Access Control Remote Command Injection command injection attempt (more info ...)web-application-attack  2019-5523      URL
58708SERVER-WEBAPP IBM Data Risk Manager command execution attempt (more info ...)web-application-attack  2020-4428      
58711MALWARE-OTHER Asp.Webshell.NewCon2 upload attempt (more info ...)trojan-activity        URL
58712MALWARE-OTHER Asp.Webshell.NewCon2 download attempt (more info ...)trojan-activity        URL
58714POLICY-OTHER Zoho ManageEngine Site24x7 agent installation attempt (more info ...)policy-violation  2021-44077      URL
58715POLICY-OTHER Zoho ManageEngine Site24x7 agent installation attempt (more info ...)policy-violation  2021-44077      URL
58716FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1427 attack attempt (more info ...)attempted-user  2021-40418      URL
58717FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1427 attack attempt (more info ...)attempted-user  2021-40418      URL
58718SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1420 attack attempt (more info ...)web-application-attack  2021-40404      URL
58721SERVER-WEBAPP Grafana getPluginAssets path traversal attempt (more info ...)web-application-attack  2021-43798      URL
58745SERVER-WEBAPP TP-Link TL-WR840N EU v5 command injection attempt (more info ...)web-application-attack  2021-41653      
58746SERVER-WEBAPP TP-Link TL-WR840N EU v5 command injection attempt (more info ...)web-application-attack  2021-41653      
58747SERVER-WEBAPP TP-Link TL-WR840N EU v5 command injection attempt (more info ...)web-application-attack  2021-41653      
58748SERVER-WEBAPP TP-Link TL-WR840N EU v5 command injection attempt (more info ...)web-application-attack  2021-41653      
58749FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1426 attack attempt (more info ...)attempted-user  2021-40417      URL
58750FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1426 attack attempt (more info ...)attempted-user  2021-40417      URL
58758MALWARE-OTHER Email.Dropper.Agent phishing email download attempt (more info ...)trojan-activity        URL
58759MALWARE-OTHER Win.Trojan.Agent variant payload download attempt (more info ...)trojan-activity        URL
58760MALWARE-OTHER Win.Dropper.Agent HCrypt PowerShell payload download attempt (more info ...)trojan-activity        URL
58761MALWARE-OTHER Win.Dropper.Agent HCrypt PowerShell payload download attempt (more info ...)trojan-activity        URL
58764MALWARE-OTHER Vbs.Downloader.Agent payload download attempt (more info ...)trojan-activity        URL
58765MALWARE-OTHER Vbs.Downloader.Agent payload download attempt (more info ...)trojan-activity        URL
58792MALWARE-OTHER Win.Ransomware.Blackbyte malicious executable file download attempt (more info ...)trojan-activity        URL
58794MALWARE-OTHER Win.Ransomware.Blackbyte malicious executable file download attempt (more info ...)trojan-activity        URL
58797SERVER-WEBAPP LibreNMS Collectd command injection attempt (more info ...)web-application-attack  2019-10669      
58798SERVER-WEBAPP LibreNMS Collectd command injection attempt (more info ...)web-application-attack  2019-10669      
58799SERVER-WEBAPP LibreNMS Collectd command injection attempt (more info ...)web-application-attack  2019-10669      
58800SERVER-WEBAPP LibreNMS Collectd command injection attempt (more info ...)web-application-attack  2019-10669      
58801INDICATOR-COMPROMISE JNDI LDAP searchResEntry dynamic code download attempt (more info ...)trojan-activity  2021-45105      URL
58811SERVER-OTHER VMWare vSphere log4shell exploit attempt (more info ...)attempted-user  2021-45105      
58812SERVER-OTHER VMWare vSphere log4shell exploit attempt (more info ...)attempted-user  2021-45105      
58813SERVER-OTHER VMWare vSphere log4shell exploit attempt (more info ...)attempted-user  2021-45105      
58815FILE-EXECUTABLE GIGABYTE GPCIDrv and GDrv driver privilege escalation attempt (more info ...)attempted-admin  2018-19323      URL
58816FILE-EXECUTABLE GIGABYTE GPCIDrv and GDrv driver privilege escalation attempt (more info ...)attempted-admin  2018-19323      URL
58817SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1428 attack attempt (more info ...)attempted-admin  2021-40419      URL
58818FILE-PDF TRUFFLEHUNTER TALOS-2021-1429 attack attempt (more info ...)attempted-user  2023-33866      URL
58819FILE-PDF TRUFFLEHUNTER TALOS-2021-1429 attack attempt (more info ...)attempted-user  2023-33866      URL
58821SERVER-WEBAPP WebSVN search command injection attempt (more info ...)web-application-attack  2021-32305      URL
58822SERVER-WEBAPP WebSVN search command injection attempt (more info ...)web-application-attack  2021-32305      URL
58823SERVER-WEBAPP WebSVN search command injection attempt (more info ...)web-application-attack  2021-32305      URL
58824SERVER-WEBAPP WebSVN search command injection attempt (more info ...)web-application-attack  2021-32305      URL
58825SERVER-WEBAPP DLINK DWL-2600 Authenticated command injection attempt (more info ...)web-application-attack  2019-20499      
58826SERVER-WEBAPP DLINK DWL-2600 Authenticated command injection attempt (more info ...)web-application-attack  2019-20499      
58827SERVER-WEBAPP DLINK DWL-2600 Authenticated command injection attempt (more info ...)web-application-attack  2019-20499      
58828SERVER-WEBAPP DLINK DWL-2600 Authenticated command injection attempt (more info ...)web-application-attack  2019-20499      
58829SERVER-WEBAPP DLINK DWL-2600 Authenticated Config Upgrade command injection attempt (more info ...)web-application-attack  2019-20501      
58830SERVER-WEBAPP DLINK DWL-2600 Authenticated Config Upgrade command injection attempt (more info ...)web-application-attack  2019-20501      
58831SERVER-WEBAPP DLINK DWL-2600 Authenticated Config Upgrade command injection attempt (more info ...)web-application-attack  2019-20501      
58832SERVER-WEBAPP DLINK DWL-2600 Authenticated Config Upgrade command injection attempt (more info ...)web-application-attack  2019-20501      
58833SERVER-WEBAPP Nagios XI remote command execution attempt (more info ...)attempted-user  2019-15949      URL
58834SERVER-OTHER MongoDB mongo-express insecure document processing code execution attempt (more info ...)attempted-user  2019-10758      URL
58836FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1434 attack attempt (more info ...)attempted-user  2021-40426      URL
58837FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2021-1434 attack attempt (more info ...)attempted-user  2021-40426      URL
58850MALWARE-OTHER Win.Ransomware.Rollcoast download attempt (more info ...)trojan-activity        URL
58851MALWARE-OTHER Win.Ransomware.Rollcoast download attempt (more info ...)trojan-activity        URL
58853SERVER-OTHER RealTek UDPServer command injection attempt (more info ...)attempted-user  2021-35394      URL
58857SERVER-WEBAPP Tendar Router AC11 stack buffer overflow attempt (more info ...)attempted-user  2021-31755      
58858SERVER-WEBAPP Tendar Router AC11 stack buffer overflow attempt (more info ...)attempted-user  2021-31755      
58861SERVER-WEBAPP ManageEngine Desktop Central LogUploader servlets directory traversal attempt (more info ...)web-application-attack  2021-44515      
58862SERVER-WEBAPP ManageEngine Desktop Central LogUploader servlets directory traversal attempt (more info ...)web-application-attack  2021-44515      
58863SERVER-WEBAPP ManageEngine Desktop Central authentication bypass attempt (more info ...)web-application-attack  2021-44515      
58864SERVER-WEBAPP ManageEngine Desktop Central LogUploader servlets directory traversal attempt (more info ...)web-application-attack  2021-44515      
58876SERVER-OTHER H2 database console RCE attempt (more info ...)attempted-user  2021-42392      
58877SERVER-OTHER H2 database console RCE attempt (more info ...)attempted-user  2021-42392      
58880FILE-OTHER TRUFFLEHUNTER TALOS-2021-1435 attack attempt (more info ...)attempted-user        URL
58881FILE-OTHER TRUFFLEHUNTER TALOS-2021-1435 attack attempt (more info ...)attempted-user        URL
58882FILE-OTHER TRUFFLEHUNTER TALOS-2021-1436 attack attempt (more info ...)attempted-user        URL
58883FILE-OTHER TRUFFLEHUNTER TALOS-2021-1436 attack attempt (more info ...)attempted-user        URL
58884SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1441 attack attempt (more info ...)web-application-attack  2022-22149      URL
58885SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1441 attack attempt (more info ...)web-application-attack  2022-22149      URL
58886SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1441 attack attempt (more info ...)web-application-attack  2022-22149      URL
58887SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1442 attack attempt (more info ...)attempted-user  2022-21145      URL
58888SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1442 attack attempt (more info ...)attempted-user  2022-21145      URL
58889SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1444 attack attempt (more info ...)web-application-attack  2022-21210      URL
58890SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1444 attack attempt (more info ...)web-application-attack  2022-21210      URL
58891SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1444 attack attempt (more info ...)web-application-attack  2022-21210      URL
58892SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1443 attack attempt (more info ...)web-application-attack  2022-21234      URL
58893SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1443 attack attempt (more info ...)web-application-attack  2022-21234      URL
58894SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1443 attack attempt (more info ...)web-application-attack  2022-21234      URL
58895FILE-OTHER TRUFFLEHUNTER TALOS-2021-1437 attack attempt (more info ...)attempted-user        URL
58896FILE-OTHER TRUFFLEHUNTER TALOS-2021-1437 attack attempt (more info ...)attempted-user        URL
58897FILE-PDF TRUFFLEHUNTER TALOS-2022-1439 attack attempt (more info ...)attempted-user  2022-22150      URL
58898FILE-PDF TRUFFLEHUNTER TALOS-2022-1439 attack attempt (more info ...)attempted-user  2022-22150      URL
58899SERVER-WEBAPP Dlink DWL-2600 authenticated config save command injection attempt (more info ...)web-application-attack  2019-20500      
58900SERVER-WEBAPP Dlink DWL-2600 authenticated config save command injection attempt (more info ...)web-application-attack  2019-20500      
58901SERVER-WEBAPP Dlink DWL-2600 authenticated config save command injection attempt (more info ...)web-application-attack  2019-20500      
58902SERVER-WEBAPP Dlink DWL-2600 authenticated config save command injection attempt (more info ...)web-application-attack  2019-20500      
58908POLICY-OTHER Multiple Products Werkzeug debug console access attempt (more info ...)policy-violation  2022-20649      URL
58910FILE-OTHER TRUFFLEHUNTER TALOS-2021-1438 attack attempt (more info ...)attempted-user        URL
58911FILE-OTHER TRUFFLEHUNTER TALOS-2021-1438 attack attempt (more info ...)attempted-user        URL
58926SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1446 attack attempt (more info ...)attempted-recon  2022-21236      URL
58928SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1445 attack attempt (more info ...)attempted-admin  2022-21217      URL
58929MALWARE-OTHER Pdf.Downloader.MuddyWater variant download attempt (more info ...)trojan-activity        URL
58930MALWARE-OTHER Ps1.Downloader.MuddyWater payload download attempt (more info ...)trojan-activity        URL
58931MALWARE-OTHER Ps1.Downloader.MuddyWater payload download attempt (more info ...)trojan-activity        URL
58932MALWARE-OTHER Pdf.Downloader.MuddyWater variant download attempt (more info ...)trojan-activity        URL
58933MALWARE-OTHER Xls.Dropper.MuddyWater variant download attempt (more info ...)trojan-activity        URL
58934MALWARE-OTHER Xls.Dropper.MuddyWater variant download attempt (more info ...)trojan-activity        URL
58935MALWARE-OTHER Xls.Dropper.MuddyWater variant download attempt (more info ...)trojan-activity        URL
58936MALWARE-OTHER Xls.Dropper.MuddyWater variant download attempt (more info ...)trojan-activity        URL
58947FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1449 attack attempt (more info ...)attempted-user  2022-22137      URL
58948FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1449 attack attempt (more info ...)attempted-user  2022-22137      URL
58951SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1451 attack attempt (more info ...)attempted-admin  2022-21796      URL
58952SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1451 attack attempt (more info ...)attempted-admin  2022-21796      URL
58953SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1450 attack attempt (more info ...)attempted-dos  2022-21801      URL
58954SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1450 attack attempt (more info ...)attempted-dos  2022-21801      URL
58960SERVER-WEBAPP Aviatrix Controller directory traversal attempt (more info ...)web-application-attack  2021-40870      
58961SERVER-WEBAPP Aviatrix Controller directory traversal attempt (more info ...)web-application-attack  2021-40870      
58962SERVER-WEBAPP Aviatrix Controller directory traversal attempt (more info ...)web-application-attack  2021-40870      
58980SERVER-WEBAPP System Information Library for node.js command injection attempt (more info ...)web-application-attack  2021-21315      
58981SERVER-WEBAPP System Information Library for node.js command injection attempt (more info ...)web-application-attack  2021-21315      
58982SERVER-WEBAPP System Information Library for node.js command injection attempt (more info ...)web-application-attack  2021-21315      
58983SERVER-WEBAPP System Information Library for node.js command injection attempt (more info ...)web-application-attack  2021-21315      
58991MALWARE-OTHER Windows Defender disable script detected (more info ...)trojan-activity        
58995SERVER-WEBAPP Gemtek WVRTM-127ACN command injection attempt (more info ...)web-application-attack  2020-24365      
58996SERVER-WEBAPP Gemtek WVRTM-127ACN command injection attempt (more info ...)web-application-attack  2020-24365      
58997SERVER-WEBAPP Gemtek WVRTM-127ACN command injection attempt (more info ...)web-application-attack  2020-24365      
58998SERVER-WEBAPP Gemtek WVRTM-127ACN command injection attempt (more info ...)web-application-attack  2020-24365      
59006OS-WINDOWS Windows Common log file system driver elevation of privilege attempt (more info ...)attempted-admin  2022-22000      URL
59007OS-WINDOWS Windows Common log file system driver elevation of privilege attempt (more info ...)attempted-admin  2022-22000      URL
59010FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1464 attack attempt (more info ...)attempted-user  2022-21154      URL
59011FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1464 attack attempt (more info ...)attempted-user  2022-21154      URL
59013SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1463 attack attempt (more info ...)attempted-admin  2022-24029      URL
59020SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1456 attack attempt (more info ...)attempted-admin  2022-21201      URL
59026SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1455 attack attempt (more info ...)attempted-admin  2022-23918      URL
59027SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1455 attack attempt (more info ...)attempted-admin  2022-23919      URL
59028SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1454 attack attempt (more info ...)attempted-admin  2022-23399      URL
59029SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1454 attack attempt (more info ...)attempted-admin  2022-23399      URL
59030FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1465 attack attempt (more info ...)attempted-user  2022-23400      URL
59031FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1465 attack attempt (more info ...)attempted-user  2022-23400      URL
59046BROWSER-OTHER Slack command injection attempt (more info ...)attempted-user  2018-1000006      
59047BROWSER-OTHER Slack command injection attempt (more info ...)attempted-user  2018-1000006      
59058SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1458 attack attempt (more info ...)attempted-admin  2022-22140      URL
59059SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1457 attack attempt (more info ...)attempted-admin  2022-21178      URL
59072SERVER-WEBAPP D-Link Routers command injection attempt (more info ...)web-application-attack  2018-10823      
59073SERVER-WEBAPP D-Link Routers command injection attempt (more info ...)web-application-attack  2018-10823      
59074SERVER-WEBAPP D-Link Routers command injection attempt (more info ...)web-application-attack  2018-10823      
59075SERVER-WEBAPP D-Link Routers command injection attempt (more info ...)web-application-attack  2018-10823      
59076SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1466 attack attempt (more info ...)attempted-dos        URL
59099MALWARE-OTHER Win.Malware.HermeticWiper binary download attempt (more info ...)trojan-activity        URL
59100MALWARE-OTHER Win.Malware.HermeticWiper binary download attempt (more info ...)trojan-activity        URL
59103SERVER-WEBAPP October CMS authentication bypass attempt (more info ...)attempted-user  2021-32648      
59109SERVER-WEBAPP Oracle WebLogic core server remote code execution attempt (more info ...)attempted-user  2021-2394      URL
59125SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1473 attack attempt (more info ...)attempted-admin  2022-26085      URL
59129SERVER-WEBAPP VMware vCenter Server file upload attempt (more info ...)web-application-attack  2021-22005      URL
59131MALWARE-OTHER Win.Trojan.Generic download attempt (more info ...)trojan-activity        URL
59132MALWARE-OTHER Win.Trojan.Generic upload attempt (more info ...)trojan-activity        URL
59146MALWARE-OTHER Win.Trojan.Redline variant upload attempt (more info ...)trojan-activity        URL
59147MALWARE-OTHER Win.Trojan.Redline variant download attempt (more info ...)trojan-activity        URL
59148MALWARE-OTHER Win.Trojan.Redline variant download attempt (more info ...)trojan-activity        URL
59154MALWARE-OTHER Win.Ransomware.HermeticRansom binary download attempt (more info ...)trojan-activity        URL
59155MALWARE-OTHER Win.Ransomware.HermeticRansom binary download attempt (more info ...)trojan-activity        URL
59156MALWARE-OTHER Win.Ransomware.HermeticRansom binary download attempt (more info ...)trojan-activity        URL
59157MALWARE-OTHER Win.Ransomware.HermeticRansom binary download attempt (more info ...)trojan-activity        URL
59163MALWARE-TOOLS Win.Malware.IsaacWiper variant download attempt (more info ...)trojan-activity        URL
59164MALWARE-TOOLS Win.Malware.IsaacWiper variant download attempt (more info ...)trojan-activity        URL
59171MALWARE-OTHER Xls.Downloader.SunSeed payload download attempt (more info ...)trojan-activity        URL
59172MALWARE-OTHER Xls.Downloader.SunSeed payload download attempt (more info ...)trojan-activity        URL
59174MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59175MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59176MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59177MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59178MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59179MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59180MALWARE-OTHER Win.Trojan.WhisperGate backwards DLL download attempt (more info ...)trojan-activity        URL
59181MALWARE-OTHER Win.Trojan.WhisperGate backwards DLL download attempt (more info ...)trojan-activity        URL
59184MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59185MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59186MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59187MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59188MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59189MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59190MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59191MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59194MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59195MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59196MALWARE-OTHER Win.Loader.Agent download attempt (more info ...)trojan-activity        URL
59197MALWARE-OTHER Win.Loader.Agent upload attempt (more info ...)trojan-activity        URL
59198MALWARE-OTHER Win.Downloader.Saintbot download attempt (more info ...)trojan-activity        URL
59199MALWARE-OTHER Win.Downloader.Saintbot upload attempt (more info ...)trojan-activity        URL
59200MALWARE-OTHER Win.Infostealer.Vidar download attempt (more info ...)trojan-activity        URL
59201MALWARE-OTHER Win.Infostealer.Vidar download attempt (more info ...)trojan-activity        URL
59204MALWARE-OTHER Win.Trojan.Saintbot variant binary download attempt (more info ...)trojan-activity        URL
59205MALWARE-OTHER Win.Trojan.Saintbot variant binary upload attempt (more info ...)trojan-activity        URL
59206MALWARE-OTHER Win.Trojan.Ursnif variant binary upload attempt (more info ...)trojan-activity        URL
59207MALWARE-OTHER Win.Trojan.Ursnif variant binary download attempt (more info ...)trojan-activity        URL
59222MALWARE-OTHER Win.Downloader.TransparentTribe outbound connection attempt (more info ...)trojan-activity        URL
59224SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1469 attack attempt (more info ...)attempted-user  2022-21238      URL
59225SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1469 attack attempt (more info ...)attempted-user  2022-21238      URL
59236SERVER-WEBAPP Sitecore XP insecure deserialization attempt (more info ...)web-application-attack  2021-42237      URL
59239MALWARE-OTHER Win.Trojan.Generic download attempt (more info ...)trojan-activity        
59240MALWARE-OTHER Win.Trojan.Generic download attempt (more info ...)trojan-activity        
59241MALWARE-OTHER Win.Trojan.Generic upload attempt (more info ...)trojan-activity        
59242MALWARE-OTHER Win.Trojan.Generic upload attempt (more info ...)trojan-activity        
59244MALWARE-OTHER Win.Trojan.Raccoon download attempt (more info ...)trojan-activity        URL
59245MALWARE-OTHER Win.Trojan.Raccoon download attempt (more info ...)trojan-activity        URL
59247SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1471 attack attempt (more info ...)attempted-admin  2022-24910      URL
59250MALWARE-TOOLS Win.Malware.HermeticWizard variant download attempt (more info ...)trojan-activity        
59251MALWARE-TOOLS Win.Malware.HermeticWizard variant download attempt (more info ...)trojan-activity        
59254MALWARE-OTHER Win.Infostealer.PhoenixStealer download attempt (more info ...)trojan-activity        URL
59255MALWARE-OTHER Win.Infostealer.PhoenixStealer download attempt (more info ...)trojan-activity        URL
59267SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1480 attack attempt (more info ...)attempted-dos  2022-26073      URL
59268MALWARE-OTHER Win.Trojan.CaddyWiper download attempt (more info ...)trojan-activity        URL
59269MALWARE-OTHER Win.Trojan.CaddyWiper download attempt (more info ...)trojan-activity        URL
59270SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1476 attack attempt (more info ...)attempted-admin  2022-26002      URL
59271SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1475 attack attempt (more info ...)attempted-admin  2022-26007      URL
59272SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1477 attack attempt (more info ...)attempted-admin  2022-27172      URL
59273SERVER-WEBAPP DOTNETNUKE DNNPersonalization Cookie Deserialization RCE (more info ...)attempted-user  2018-18326      URL
59287SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1478 attack attempt (more info ...)misc-activity  2022-26042      URL
59288SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1478 attack attempt (more info ...)attempted-admin  2022-26042      URL
59289SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1483 attack attempt (more info ...)attempted-admin  2022-26009      URL
59290SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1484 attack attempt (more info ...)attempted-admin  2022-26342      URL
59291SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1482 attack attempt (more info ...)attempted-admin  2022-25996      URL
59292SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus SiteLookup.do cross site scripting attempt (more info ...)attempted-user  2019-12538      
59293SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus SiteLookup.do cross site scripting attempt (more info ...)attempted-user  2019-12538      
59294SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1481 attack attempt (more info ...)attempted-admin  2022-26781      URL
59295SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1481 attack attempt (more info ...)attempted-admin  2022-26782      URL
59296FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1485 attack attempt (more info ...)attempted-user  2022-25972      URL
59297FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1485 attack attempt (more info ...)attempted-user  2022-25972      URL
59298SERVER-WEBAPP Spring Cloud Gateway Spring Expression Language injection attempt (more info ...)web-application-attack  2022-22947      
59299SERVER-WEBAPP Spring Cloud Gateway Spring Expression Language injection attempt (more info ...)web-application-attack  2022-22947      
59303FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1486 attack attempt (more info ...)attempted-user  2022-25942      URL
59304FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1486 attack attempt (more info ...)attempted-user  2022-25942      URL
59305SERVER-WEBAPP OCS Inventory NG command injection attempt (more info ...)web-application-attack  2020-14947      
59306SERVER-WEBAPP OCS Inventory NG command injection attempt (more info ...)web-application-attack  2020-14947      
59307SERVER-WEBAPP OCS Inventory NG command injection attempt (more info ...)web-application-attack  2020-14947      
59308SERVER-WEBAPP OCS Inventory NG command injection attempt (more info ...)web-application-attack  2020-14947      
59319SERVER-WEBAPP Advantech WISE-PaaS RMM UpgradeMgmt upload_ota directory traversal attempt (more info ...)web-application-attack  2019-13551      
59320SERVER-WEBAPP Advantech WISE-PaaS RMM UpgradeMgmt upload_ota directory traversal attempt (more info ...)web-application-attack  2019-13551      
59321SERVER-WEBAPP Advantech WISE-PaaS RMM UpgradeMgmt upload_ota directory traversal attempt (more info ...)web-application-attack  2019-13551      
59355SERVER-WEBAPP Zoho ManageEngine Desktop Central directory traversal attempt (more info ...)web-application-attack  2018-12999      
59356SERVER-WEBAPP Zoho ManageEngine Desktop Central directory traversal attempt (more info ...)web-application-attack  2018-12999      
59357SERVER-WEBAPP Zoho ManageEngine Desktop Central directory traversal attempt (more info ...)web-application-attack  2018-12999      
59368SERVER-WEBAPP GitLab Wiki API Attachments command injection attempt (more info ...)web-application-attack  2018-18649      
59369SERVER-WEBAPP GitLab Wiki API Attachments command injection attempt (more info ...)web-application-attack  2018-18649      
59370SERVER-WEBAPP GitLab Wiki API Attachments command injection attempt (more info ...)web-application-attack  2018-18649      
59371SERVER-WEBAPP GitLab Wiki API Attachments command injection attempt (more info ...)web-application-attack  2018-18649      
59372SERVER-WEBAPP NetGain Systems Enterprise Manager directory traversal attempt (more info ...)web-application-attack  2017-16599      
59373SERVER-WEBAPP NetGain Systems Enterprise Manager directory traversal attempt (more info ...)web-application-attack  2017-16599      
59374SERVER-WEBAPP NetGain Systems Enterprise Manager directory traversal attempt (more info ...)web-application-attack  2017-16599      
59385SERVER-WEBAPP Advantech WebAccess NMS download directory traversal attempt (more info ...)web-application-attack  2020-10631      
59386SERVER-WEBAPP Advantech WebAccess NMS download directory traversal attempt (more info ...)web-application-attack  2020-10631      
59387SERVER-WEBAPP Advantech WebAccess NMS download directory traversal attempt (more info ...)web-application-attack  2020-10631      
59388SERVER-WEBAPP Spring Cloud Gateway Spring Expression Language injection attempt (more info ...)web-application-attack  2022-22963      URL
59415SERVER-OTHER Tarantool xrow_header_decode out of bounds read attempt (more info ...)attempted-dos  2016-9037      URL
59441SERVER-OTHER OpenSLP slp_process.c heap overflow attempt (more info ...)attempted-user  2019-5544      URL
59442SERVER-OTHER OpenSLP slp_process.c heap overflow attempt (more info ...)attempted-user  2019-5544      URL
59443SERVER-WEBAPP Trend Micro Interscan MailNotification buffer overflow attempt (more info ...)attempted-user  2020-28579      URL
59444SERVER-WEBAPP Trend Micro Interscan MailNotification buffer overflow attempt (more info ...)attempted-user  2020-28579      URL
59450OS-OTHER TRUFFLEHUNTER TALOS-2022-1497 attack attempt (more info ...)attempted-recon        URL
59451OS-OTHER TRUFFLEHUNTER TALOS-2022-1497 attack attempt (more info ...)attempted-recon        URL
59452FILE-OTHER 7-Zip crafted RAR solid compression memory corruption attempt (more info ...)attempted-user  2018-10115      
59453FILE-OTHER 7-Zip crafted RAR solid compression memory corruption attempt (more info ...)attempted-user  2018-10115      
59454FILE-OTHER Perl archive tar arbitrary file overwrite attempt (more info ...)attempted-user  2018-12015      
59455FILE-OTHER Perl archive tar arbitrary file overwrite attempt (more info ...)attempted-user  2018-12015      
59456FILE-OTHER Perl archive tar arbitrary file overwrite attempt (more info ...)attempted-user  2018-12015      
59457FILE-OTHER Perl archive tar arbitrary file overwrite attempt (more info ...)attempted-user  2018-12015      
59465FILE-OTHER Fuji Electric V-Server VPR heap buffer overflow attempt (more info ...)attempted-user  2019-18240      
59466FILE-OTHER Fuji Electric V-Server VPR heap buffer overflow attempt (more info ...)attempted-user  2019-18240      
59467FILE-PDF Foxit Reader and PhantonPDF XFA gotoURL command injection attempt (more info ...)attempted-user  2017-10953      
59468FILE-PDF Foxit Reader and PhantonPDF XFA gotoURL command injection attempt (more info ...)attempted-user  2017-10953      
59482SERVER-WEBAPP Oracle Business Intelligencee BIRemotingServlet deserialization remote code execution attempt (more info ...)attempted-user  2020-2950      URL
59489SERVER-WEBAPP Oracle WebLogic Server FileDistributionServlet information disclosure attempt (more info ...)attempted-user  2019-2615      
59490SERVER-WEBAPP Oracle WebLogic Server FileDistributionServlet information disclosure attempt (more info ...)attempted-user  2019-2615      
59491SERVER-WEBAPP Oracle WebLogic Server FileDistributionServlet information disclosure attempt (more info ...)attempted-user  2019-2615      
59499SERVER-WEBAPP Symantec Encryption Management Server command injection attempt (more info ...)web-application-attack  2014-7288  72308    
59500PUA-OTHER XMRig cryptocurrency miner outbound connection (more info ...)policy-violation        URL
59507FILE-OTHER ClamAV OLE2 uniq_add out of bounds write attempt (more info ...)attempted-dos  2019-1788      
59508FILE-OTHER ClamAV OLE2 uniq_add out of bounds write attempt (more info ...)attempted-dos  2019-1788      
59509FILE-OTHER ClamAV OLE2 uniq_add out of bounds write attempt (more info ...)attempted-dos  2019-1788      
59510FILE-OTHER ClamAV OLE2 uniq_add out of bounds write attempt (more info ...)attempted-dos  2019-1788      
59514SERVER-WEBAPP CentOS Web Panel authentication bypass attempt (more info ...)web-application-attack  2021-45467      URL
59525OS-WINDOWS Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-24542      URL
59526OS-WINDOWS Windows Win32k elevation of privilege attempt (more info ...)attempted-admin  2022-24542      URL
59528PROTOCOL-OTHER cURL libcurl NtLM type 3 stack based buffer overflow attempt (more info ...)attempted-user  2019-3822      
59538BROWSER-OTHER Electronic Arts Origin Client template injection attempt (more info ...)attempted-user  2019-11354      
59539SERVER-WEBAPP Zoho ManageEngine DataSecurity Plus Xnode default credential authentication attempt (more info ...)attempted-admin  2020-11532      URL
59540SERVER-WEBAPP Zoho ManageEngine DataSecurity Plus Xnode directory traversal attempt (more info ...)web-application-attack  2020-11531      URL
59541SERVER-WEBAPP Harbor Project Harbor admin account creation attempt (more info ...)attempted-admin  2019-16097      URL
59599PROTOCOL-SCADA OPCUA authentication brute force attempt (more info ...)attempted-admin        URL
59601SERVER-OTHER Schneider Electric Codesys PLC denial of service attempt (more info ...)attempted-dos        URL
59602SERVER-OTHER Schneider Electric Codesys PLC unauthorized login attempt (more info ...)attempted-admin        URL
59603SERVER-OTHER Schneider Electric Codesys PLC unauthorized login attempt (more info ...)attempted-admin        URL
59604SERVER-WEBAPP OmronShell telnetExploit command attempt (more info ...)attempted-admin        URL
59605SERVER-WEBAPP OmronShell telnetExploit command attempt (more info ...)attempted-admin        URL
59637OS-WINDOWS TRUFFLEHUNTER TALOS-2022-1514 attack attempt (more info ...)attempted-dos        URL
59638OS-WINDOWS TRUFFLEHUNTER TALOS-2022-1514 attack attempt (more info ...)attempted-dos        URL
59642OS-WINDOWS TRUFFLEHUNTER TALOS-2022-1515 attack attempt (more info ...)attempted-dos        URL
59643OS-WINDOWS TRUFFLEHUNTER TALOS-2022-1515 attack attempt (more info ...)attempted-dos        URL
59644FILE-PDF TRUFFLEHUNTER TALOS-2022-1516 attack attempt (more info ...)attempted-user        URL
59645FILE-PDF TRUFFLEHUNTER TALOS-2022-1516 attack attempt (more info ...)attempted-user        URL
59647SERVER-WEBAPP Netgear R8500 command injection attempt (more info ...)web-application-attack  2022-27945      
59648SERVER-WEBAPP Netgear R8500 command injection attempt (more info ...)web-application-attack  2022-27945      
59649SERVER-WEBAPP Netgear R8500 command injection attempt (more info ...)web-application-attack  2022-27945      
59650SERVER-WEBAPP Netgear R8500 command injection attempt (more info ...)web-application-attack  2022-27945      
59652SERVER-WEBAPP WSO2 multiple products directory traversal attempt (more info ...)web-application-attack  2022-29464      
59671SERVER-OTHER HPE Intelligence Management Center RMI remote code execution attempt (more info ...)attempted-admin  2017-5792      URL
59710SERVER-WEBAPP HPE Intelligent Management Center ByteMessageResource insecure deserialization attempt (more info ...)attempted-admin  2019-11956      
59711SERVER-WEBAPP HPE Intelligent Management Center ByteMessageResource insecure deserialization attempt (more info ...)attempted-admin  2019-11956      
59718SERVER-WEBAPP Xinuos Openserver command injection attempt (more info ...)web-application-attack  2020-25494      URL
59719SERVER-WEBAPP Xinuos Openserver command injection attempt (more info ...)web-application-attack  2020-25494      URL
59720SERVER-WEBAPP Xinuos Openserver command injection attempt (more info ...)web-application-attack  2020-25494      
59721SERVER-WEBAPP Xinuos Openserver command injection attempt (more info ...)web-application-attack  2020-25494      URL
59735SERVER-WEBAPP F5 BIG-IP iControl remote code execution attempt (more info ...)attempted-user  2022-1388      
59738OS-WINDOWS Windows Network File System remote code execution attempt (more info ...)attempted-admin  2022-26937      URL
59740OS-WINDOWS Windows Network File System remote code execution attempt (more info ...)attempted-admin  2022-26937      URL
59790MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59791MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59793MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59794MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity        URL
59804SERVER-WEBAPP LG N1A1 NAS command injection attempt (more info ...)web-application-attack  2018-14839      
59805SERVER-WEBAPP LG N1A1 NAS command injection attempt (more info ...)web-application-attack  2018-14839      
59806SERVER-WEBAPP LG N1A1 NAS command injection attempt (more info ...)web-application-attack  2018-14839      
59807SERVER-WEBAPP LG N1A1 NAS command injection attempt (more info ...)web-application-attack  2018-14839      
59808SERVER-WEBAPP LG N1A1 NAS command injection attempt (more info ...)web-application-attack  2018-14839      
59809SERVER-WEBAPP LG N1A1 NAS command injection attempt (more info ...)web-application-attack  2018-14839      
59810SERVER-WEBAPP LG N1A1 NAS command injection attempt (more info ...)web-application-attack  2018-14839      
59811SERVER-WEBAPP LG N1A1 NAS command injection attempt (more info ...)web-application-attack  2018-14839      
59813SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (more info ...)web-application-attack  2019-12991      URL
59814SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (more info ...)web-application-attack  2019-12991      URL
59815SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (more info ...)web-application-attack  2019-12991      URL
59816SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (more info ...)web-application-attack  2019-12991      URL
59817SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (more info ...)web-application-attack  2022-27946      
59818SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (more info ...)web-application-attack  2022-27946      
59819SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (more info ...)web-application-attack  2022-27946      
59820SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (more info ...)web-application-attack  2022-27946      
59823SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (more info ...)attempted-admin  2022-22954      URL
59824SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (more info ...)attempted-admin  2022-22954      URL
59832SERVER-OTHER WatchGuard Firebox and XTM remote code execution attempt (more info ...)attempted-user  2022-26318      
59865SERVER-ORACLE Oracle WebLogic Coherence library remote code execution attempt (more info ...)attempted-user  2020-2555      
59866SERVER-OTHER Debian Redis Lua sandbox escape attempt (more info ...)attempted-user  2022-0543      
59867SERVER-OTHER Debian Redis Lua sandbox escape attempt (more info ...)attempted-user  2022-0543      
59877FILE-OTHER PEAR Archive Tar code deserialization attempt (more info ...)attempted-user  2020-28949      URL
59878FILE-OTHER PEAR Archive Tar code deserialization attempt (more info ...)attempted-user  2020-28949      URL
59881SERVER-OTHER Citrix FileShare remote file inclusion attempt (more info ...)attempted-user  2021-22941      URL
59886SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1522 attack attempt (more info ...)web-application-attack  2022-29888      URL
59895SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1524 attack attempt (more info ...)attempted-admin  2022-29496      URL
59916SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (more info ...)attempted-user  2020-26919      URL
59921SERVER-WEBAPP Netgear R8500 command injection attempt (more info ...)web-application-attack  2022-27947      
59922SERVER-WEBAPP Netgear R8500 command injection attempt (more info ...)web-application-attack  2022-27947      
59923SERVER-WEBAPP Netgear R8500 command injection attempt (more info ...)web-application-attack  2022-27947      
59924SERVER-WEBAPP Netgear R8500 command injection attempt (more info ...)web-application-attack  2022-27947      
59925SERVER-WEBAPP Multiple products OGNL expression injection attempt (more info ...)attempted-admin        
59926INDICATOR-COMPROMISE Python remote shell spawn attempt (more info ...)misc-attack        
59927MALWARE-BACKDOOR Jsp.Webshell.TinyUploader upload attempt (more info ...)trojan-activity  2022-26134      URL
59928MALWARE-BACKDOOR Jsp.Webshell.Chopper webshell download attempt (more info ...)trojan-activity  2022-26134      URL
59929MALWARE-BACKDOOR Jsp.Webshell.Behinder download attempt (more info ...)trojan-activity  2022-26134      URL
59930MALWARE-BACKDOOR Jsp.Webshell.Noop download attempt (more info ...)trojan-activity  2022-26134      URL
59931MALWARE-BACKDOOR Jsp.Webshell.Chopper upload attempt (more info ...)trojan-activity  2022-26134      URL
59932MALWARE-BACKDOOR Jsp.Webshell.Behinder upload attempt (more info ...)trojan-activity  2022-26134      URL
59933MALWARE-BACKDOOR Jsp.Webshell.Noop upload attempt (more info ...)trojan-activity  2022-26134      URL
59934SERVER-WEBAPP Atlassian Confluence OGNL expression injection attempt (more info ...)attempted-user  2022-26134      
59939SERVER-WEBAPP Zyxel Firewall command injection attempt (more info ...)web-application-attack  2022-30525      
59940SERVER-WEBAPP DotCMS directory traversal attempt (more info ...)web-application-attack  2022-26352      
59941SERVER-WEBAPP Atlassian Confluence OGNL expression injection attempt (more info ...)attempted-user  2022-26134      
59942FILE-PDF TRUFFLEHUNTER TALOS-2022-1525 attack attempt (more info ...)attempted-user        URL
59943FILE-PDF TRUFFLEHUNTER TALOS-2022-1525 attack attempt (more info ...)attempted-user        URL
59947SERVER-WEBAPP Atlassian Confluence OGNL expression injection attempt (more info ...)attempted-user  2022-26134      
59948SERVER-WEBAPP Atlassian Confluence OGNL expression injection attempt (more info ...)attempted-user  2022-26134      
59951SERVER-WEBAPP D-Link router command injection attempt (more info ...)web-application-attack  2021-45382      
59952SERVER-WEBAPP D-Link router command injection attempt (more info ...)web-application-attack  2021-45382      
59953SERVER-WEBAPP D-Link router command injection attempt (more info ...)web-application-attack  2021-45382      
59954SERVER-WEBAPP D-Link router command injection attempt (more info ...)web-application-attack  2021-45382      
59959SERVER-WEBAPP D-Link command injection attempt (more info ...)web-application-attack  2019-16920      
59960SERVER-WEBAPP D-Link command injection attempt (more info ...)web-application-attack  2019-16920      
59961SERVER-WEBAPP D-Link command injection attempt (more info ...)web-application-attack  2019-16920      
59962SERVER-WEBAPP D-Link command injection attempt (more info ...)web-application-attack  2019-16920      
59963SERVER-WEBAPP FatPipe WARP and VPN arbitrary JSP file upload attempt (more info ...)attempted-admin  2021-27860      
59964SERVER-WEBAPP SonicWall SMA and SRA Appliances directory traversal attempt (more info ...)web-application-attack  2019-7483      
59965SERVER-WEBAPP SonicWall SMA and SRA Appliances directory traversal attempt (more info ...)web-application-attack  2019-7483      
59966SERVER-WEBAPP SonicWall SMA and SRA Appliances directory traversal attempt (more info ...)web-application-attack  2019-7483      
59973SERVER-WEBAPP SonicWall SMA 100 remote unauthenticated buffer overflow attempt (more info ...)attempted-user  2021-20038      URL
59982MALWARE-OTHER Win.Trojan.Mimikatz binary download (more info ...)trojan-activity        
59983MALWARE-OTHER Win.Trojan.Mimikatz binary download (more info ...)trojan-activity        
59984MALWARE-OTHER Win.Ransomware.AvosLocker ransomware binary download (more info ...)trojan-activity        
59985MALWARE-OTHER Win.Ransomware.AvosLocker ransomware binary download (more info ...)trojan-activity        
59988SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1539 attack attempt (more info ...)attempted-user  2022-30690      URL
59989SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1539 attack attempt (more info ...)attempted-user  2022-30690      URL
59990SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1531 attack attempt (more info ...)web-application-attack  2022-27498      URL
59991SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1531 attack attempt (more info ...)web-application-attack  2022-27498      URL
59992SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1531 attack attempt (more info ...)web-application-attack  2022-27498      URL
59993SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1540 attack attempt (more info ...)attempted-user  2022-28712      URL
59994SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1540 attack attempt (more info ...)attempted-user  2022-28712      URL
59995SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1546 attack attempt (more info ...)web-application-attack  2022-32572      URL
59996SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1546 attack attempt (more info ...)web-application-attack  2022-32572      URL
59997SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1546 attack attempt (more info ...)web-application-attack  2022-32572      URL
59998SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1546 attack attempt (more info ...)web-application-attack  2022-32572      URL
59999SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1541 attack attempt (more info ...)attempted-user  2022-32763      URL
60000SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1541 attack attempt (more info ...)attempted-user  2022-32763      URL
60001SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1532 attack attempt (more info ...)attempted-user  2022-28703      URL
60002SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1532 attack attempt (more info ...)attempted-user  2022-28703      URL
60003SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1538 attack attempt (more info ...)attempted-user  2022-32770      URL
60004SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1538 attack attempt (more info ...)attempted-user  2022-32771      URL
60005SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1538 attack attempt (more info ...)attempted-user  2022-32772      URL
60006SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1537 attack attempt (more info ...)attempted-user  2022-26842      URL
60007SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33325      URL
60008SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33325      URL
60009SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33325      URL
60010SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33325      URL
60011SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33326      URL
60012SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33326      URL
60013SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33326      URL
60014SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33326      URL
60015SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33328      URL
60016SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33328      URL
60017SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33328      URL
60018SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33328      URL
60019SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33329      URL
60020SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33329      URL
60021SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33329      URL
60022SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1573 attack attempt (more info ...)web-application-attack  2022-33329      URL
60023SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33312      URL
60024SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33312      URL
60025SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33312      URL
60026SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33312      URL
60027SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33313      URL
60028SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33313      URL
60029SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33313      URL
60030SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33313      URL
60031SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33314      URL
60032SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33314      URL
60033SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33314      URL
60034SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1572 attack attempt (more info ...)web-application-attack  2022-33314      URL
60043SERVER-WEBAPP Comtrend VR-3033 routers command injection attempt (more info ...)web-application-attack  2020-10173      URL
60044SERVER-WEBAPP Comtrend VR-3033 routers command injection attempt (more info ...)web-application-attack  2020-10173      URL
60045SERVER-WEBAPP Comtrend VR-3033 routers command injection attempt (more info ...)web-application-attack  2020-10173      URL
60046SERVER-WEBAPP Comtrend VR-3033 routers command injection attempt (more info ...)web-application-attack  2020-10173      URL
60054SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1528 attack attempt (more info ...)web-application-attack  2022-32573      URL
60055SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1528 attack attempt (more info ...)web-application-attack  2022-32573      URL
60056SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1528 attack attempt (more info ...)web-application-attack  2022-32573      URL
60062SERVER-WEBAPP Sonic Wall SRA and SMA command injection attempt (more info ...)web-application-attack  2019-7486      
60063SERVER-WEBAPP Sonic Wall SRA and SMA command injection attempt (more info ...)web-application-attack  2019-7486      
60064SERVER-WEBAPP Sonic Wall SRA and SMA command injection attempt (more info ...)web-application-attack  2019-7486      
60065SERVER-WEBAPP Sonic Wall SRA and SMA command injection attempt (more info ...)web-application-attack  2019-7486      
60071SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1547 attack attempt (more info ...)web-application-attack  2022-30547      URL
60072SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1547 attack attempt (more info ...)web-application-attack  2022-30547      URL
60079SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1534 attack attempt (more info ...)attempted-user  2022-29468      URL
60080SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1534 attack attempt (more info ...)attempted-user  2022-29468      URL
60092SERVER-WEBAPP Kaseya VSA arbitrary JSP file upload attempt (more info ...)attempted-admin  2021-30118      
60096SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1566 attack attempt (more info ...)web-application-attack  2022-29472      URL
60097SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1566 attack attempt (more info ...)web-application-attack  2022-29472      URL
60098SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1566 attack attempt (more info ...)web-application-attack  2022-29472      URL
60099SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1566 attack attempt (more info ...)web-application-attack  2022-29472      URL
60100SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1562 attack attempt (more info ...)web-application-attack  2022-30603      URL
60101SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1562 attack attempt (more info ...)web-application-attack  2022-30603      URL
60102SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1562 attack attempt (more info ...)web-application-attack  2022-30603      URL
60103SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1562 attack attempt (more info ...)web-application-attack  2022-30603      URL
60105SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1563 attack attempt (more info ...)web-application-attack  2022-32586      URL
60106SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1563 attack attempt (more info ...)web-application-attack  2022-32586      URL
60107SERVER-WEBAPP QNAP QTS command injection attempt (more info ...)web-application-attack  2020-2509      URL
60108SERVER-WEBAPP QNAP QTS command injection attempt (more info ...)web-application-attack  2020-2509      URL
60109SERVER-WEBAPP QNAP QTS command injection attempt (more info ...)web-application-attack  2020-2509      URL
60110SERVER-WEBAPP QNAP QTS command injection attempt (more info ...)web-application-attack  2020-2509      URL
60111SERVER-WEBAPP SAP NetWeaver arbitrary JSP file upload attempt (more info ...)attempted-admin  2021-38163      
60112SERVER-WEBAPP SAP NetWeaver directory traversal attempt (more info ...)web-application-attack  2021-38163      
60113SERVER-WEBAPP SAP NetWeaver directory traversal attempt (more info ...)web-application-attack  2021-38163      
60114SERVER-WEBAPP SAP NetWeaver directory traversal attempt (more info ...)web-application-attack  2021-38163      
60121SERVER-WEBAPP MiVoice Connect command injection attempt (more info ...)attempted-user  2022-29499      URL
60122SERVER-WEBAPP MiVoice Connect command injection attempt (more info ...)attempted-user  2022-29499      URL
60123SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1556 attack attempt (more info ...)attempted-admin  2022-32773      URL
60124SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1558 attack attempt (more info ...)attempted-admin  2022-33189      URL
60125SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1557 attack attempt (more info ...)attempted-admin  2022-30541      URL
60126SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1561 attack attempt (more info ...)attempted-admin  2022-29520      URL
60127SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1560 attack attempt (more info ...)attempted-admin  2022-32454      URL
60128SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1555 attack attempt (more info ...)attempted-dos  2022-32760      URL
60129SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1568 attack attempt (more info ...)web-application-attack  2022-33207      URL
60130SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1568 attack attempt (more info ...)web-application-attack  2022-33207      URL
60131SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1568 attack attempt (more info ...)web-application-attack  2022-33207      URL
60132SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1568 attack attempt (more info ...)web-application-attack  2022-33207      URL
60133SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)attempted-admin  2022-33192      URL
60134SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)attempted-admin  2022-33194      URL
60135SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)attempted-admin  2022-33195      URL
60136SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)web-application-attack  2022-33195      URL
60137SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)web-application-attack  2022-33195      URL
60138SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)web-application-attack  2022-33195      URL
60139SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)web-application-attack  2022-33195      URL
60140SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)web-application-attack  2022-33195      URL
60141SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1559 attack attempt (more info ...)web-application-attack  2022-33195      URL
60142SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1529 attack attempt (more info ...)web-application-attack  2022-29517      URL
60143SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1529 attack attempt (more info ...)web-application-attack  2022-29517      URL
60144SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1529 attack attempt (more info ...)web-application-attack  2022-29517      URL
60145SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33147      URL
60146SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33147      URL
60147SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33147      URL
60148SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33148      URL
60149SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33148      URL
60150SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33148      URL
60151SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33149      URL
60152SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33149      URL
60153SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1551 attack attempt (more info ...)web-application-attack  2022-33149      URL
60156SERVER-WEBAPP Tenda Router formPing command injection attempt (more info ...)web-application-attack  2022-30023      
60157SERVER-WEBAPP Tenda Router formPing command injection attempt (more info ...)web-application-attack  2022-30023      
60158SERVER-WEBAPP Tenda Router formPing command injection attempt (more info ...)web-application-attack  2022-30023      
60159SERVER-WEBAPP Tenda Router formPing command injection attempt (more info ...)web-application-attack  2022-30023      
60160SERVER-WEBAPP Joomla Core directory traversal attempt (more info ...)web-application-attack  2019-10945      
60161SERVER-WEBAPP Joomla Core directory traversal attempt (more info ...)web-application-attack  2019-10945      
60162SERVER-WEBAPP Joomla Core directory traversal attempt (more info ...)web-application-attack  2019-10945      
60163SERVER-WEBAPP DLINK HNAP command injection attempt (more info ...)web-application-attack        URL
60164SERVER-WEBAPP DLINK HNAP command injection attempt (more info ...)web-application-attack  2023-24762      URL
60167SERVER-WEBAPP QNAP NAS command injection attempt (more info ...)web-application-attack  2018-19949      
60168SERVER-WEBAPP QNAP NAS command injection attempt (more info ...)web-application-attack  2018-19949      
60169SERVER-WEBAPP QNAP NAS command injection attempt (more info ...)web-application-attack  2018-19949      
60170SERVER-WEBAPP QNAP NAS command injection attempt (more info ...)web-application-attack  2018-19949      
60176SERVER-WEBAPP Zoho ManageEngine ADAudit Plus XML external entity injection attempt (more info ...)web-application-attack  2022-28219      
60184SERVER-WEBAPP Oracle ADF RemoteApplicationResourceLoader potential unsafe deserialization attempt (more info ...)web-application-attack  2022-21445      
60197SERVER-WEBAPP D-Link SetNTPserverSeting command injection attempt (more info ...)web-application-attack  2022-28573      
60200SERVER-OTHER IBM TM1 Planning Analytics unauthenticated remote code execution attempt (more info ...)attempted-admin  2019-4716      URL
60204SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1549 attack attempt (more info ...)attempted-recon  2022-32761      URL
60205SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1549 attack attempt (more info ...)attempted-recon  2022-32761      URL
60208SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1550 attack attempt (more info ...)attempted-recon  2022-28710      URL
60209SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1571 attack attempt (more info ...)attempted-dos  2022-33897      URL
60210SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1571 attack attempt (more info ...)attempted-dos  2022-33897      URL
60211SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1571 attack attempt (more info ...)attempted-dos  2022-33897      URL
60217SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1554 attack attempt (more info ...)web-application-attack  2022-29477      URL
60218SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1564 attack attempt (more info ...)web-application-attack  2022-32775      URL
60219SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1530 attack attempt (more info ...)attempted-recon  2022-29511      URL
60224SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1565 attack attempt (more info ...)attempted-dos  2022-32574      URL
60225FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1544 attack attempt (more info ...)attempted-user  2022-32588      URL
60226FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1544 attack attempt (more info ...)attempted-user  2022-32588      URL
60230SERVER-WEBAPP NETGEAR router remote code execution attempt (more info ...)attempted-user  2017-6862      URL
60231SERVER-WEBAPP Festo CECC-X-M1 cecc-x-acknerr-request command injection attempt (more info ...)web-application-attack  2022-30310      
60232SERVER-WEBAPP Festo CECC-X-M1 cecc-x-acknerr-request command injection attempt (more info ...)web-application-attack  2022-30310      
60233SERVER-WEBAPP Festo CECC-X-M1 cecc-x-refresh-request command injection attempt (more info ...)web-application-attack  2022-30311      
60234SERVER-WEBAPP Festo CECC-X-M1 cecc-x-refresh-request command injection attempt (more info ...)web-application-attack  2022-30311      
60235SERVER-WEBAPP Festo CECC-X-M1 cecc-x-web-viewer-request command injection attempt (more info ...)web-application-attack  2022-30309      
60236SERVER-WEBAPP Festo CECC-X-M1 cecc-x-web-viewer-request command injection attempt (more info ...)web-application-attack  2022-30309      
60237OS-WINDOWS Dell dbutil driver escalation of privilege attempt (more info ...)attempted-admin  2021-21551      
60238OS-WINDOWS Dell dbutil driver escalation of privilege attempt (more info ...)attempted-admin  2021-21551      
60239MALWARE-OTHER Win.Ransomware.Magniber download attempt (more info ...)trojan-activity        URL
60240SERVER-WEBAPP Spring Cloud Config directory traversal attempt (more info ...)web-application-attack  2020-5410      
60247MALWARE-OTHER MultiOS.Backdoor.GoMet agent download attempt (more info ...)trojan-activity        URL
60248MALWARE-OTHER MultiOS.Backdoor.GoMet agent download attempt (more info ...)trojan-activity        URL
60249MALWARE-OTHER MultiOS.Backdoor.GoMet agent download attempt (more info ...)trojan-activity        URL
60250MALWARE-OTHER MultiOS.Backdoor.GoMet agent download attempt (more info ...)trojan-activity        URL
60253MALWARE-OTHER MultiOS.Backdoor.GoMet agent download attempt (more info ...)trojan-activity        URL
60257SERVER-WEBAPP Oracle Business Intelligence Enterprise Edition getPreviewImage directory traversal attempt (more info ...)web-application-attack  2020-14864      
60258SERVER-WEBAPP Oracle Business Intelligence Enterprise Edition getPreviewImage directory traversal attempt (more info ...)web-application-attack  2020-14864      
60259SERVER-WEBAPP Oracle Business Intelligence Enterprise Edition getPreviewImage directory traversal attempt (more info ...)web-application-attack  2020-14864      
60260OS-OTHER Apple CoreGraphics library out of bounds write attempt (more info ...)attempted-user  2021-30860      URL
60261OS-OTHER Apple CoreGraphics library out of bounds write attempt (more info ...)attempted-user  2021-30860      URL
60262SERVER-WEBAPP WatchGuard Firebox and XTM appliances privilege escalation attempt (more info ...)attempted-admin  2022-23176      
60263SERVER-WEBAPP WatchGuard Firebox and XTM appliances privilege escalation attempt (more info ...)attempted-admin  2022-23176      
60265MALWARE-OTHER Win.Backdoor.TreeTrunk download attempt (more info ...)trojan-activity        URL
60267MALWARE-OTHER Win.Backdoor.TreeTrunk download attempt (more info ...)attempted-user        URL
60280SERVER-WEBAPP Atlassian Confluence hardcoded credentials use attempt (more info ...)web-application-attack  2022-26138      URL
60281SERVER-WEBAPP Atlassian Confluence hardcoded credentials use attempt (more info ...)web-application-attack  2022-26138      URL
60287SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1582 attack attempt (more info ...)attempted-admin  2022-35244      URL
60288SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1584 attack attempt (more info ...)attempted-admin  2022-33938      URL
60303SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1581 attack attempt (more info ...)attempted-admin  2022-35874      URL
60304SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1581 attack attempt (more info ...)attempted-admin  2022-35875      URL
60305SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1581 attack attempt (more info ...)attempted-admin  2022-33877      URL
60306SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1581 attack attempt (more info ...)web-application-attack  2022-35877      URL
60307SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1581 attack attempt (more info ...)web-application-attack  2022-35877      URL
60308SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1581 attack attempt (more info ...)web-application-attack  2022-35877      URL
60309SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1581 attack attempt (more info ...)web-application-attack  2022-35877      URL
60310SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1585 attack attempt (more info ...)web-application-attack  2022-35887      URL
60311SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1585 attack attempt (more info ...)web-application-attack  2022-35887      URL
60326OS-OTHER Apple multiple products memory corruption attempt (more info ...)attempted-admin  2021-30900      URL
60327OS-OTHER Apple multiple products memory corruption attempt (more info ...)attempted-admin  2021-30900      URL
60328SERVER-WEBAPP Atlassian Jira Seraph authentication bypass attempt (more info ...)attempted-user  2022-0540      URL
60329SERVER-WEBAPP Atlassian Jira Seraph authentication bypass attempt (more info ...)attempted-user  2022-0540      URL
60332SERVER-WEBAPP UPnP SOAP request detected (more info ...)protocol-command-decode        URL
60333SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1583 attack attempt (more info ...)attempted-admin  2022-35880      URL
60334SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1583 attack attempt (more info ...)attempted-admin  2022-35881      URL
60335SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1583 attack attempt (more info ...)attempted-admin  2022-35881      URL
60336SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1583 attack attempt (more info ...)attempted-admin  2022-35879      URL
60364SERVER-WEBAPP AudioCode 400HD command injection attempt (more info ...)web-application-attack  2018-10093      
60365SERVER-WEBAPP AudioCode 400HD command injection attempt (more info ...)web-application-attack  2018-10093      URL
60379OS-WINDOWS Windows Win32k escalation of privileges attempt (more info ...)attempted-admin  2022-34699      URL
60380OS-WINDOWS Windows Win32k escalation of privileges attempt (more info ...)attempted-admin  2022-34699      URL
60385SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1577 attack attempt (more info ...)web-application-attack  2022-33150      URL
60388SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1578 attack attempt (more info ...)web-application-attack  2022-34850      URL
60389SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1578 attack attempt (more info ...)web-application-attack  2022-34850      URL
60390SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1578 attack attempt (more info ...)web-application-attack  2022-34850      URL
60391SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1578 attack attempt (more info ...)web-application-attack  2022-34850      URL
60394SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1586 attack attempt (more info ...)attempted-admin  2022-35401      URL
60397MALWARE-OTHER Robin Banks credential phishing attempt (more info ...)trojan-activity        URL
60398MALWARE-OTHER Robin Banks credential phishing attempt (more info ...)trojan-activity        URL
60403SERVER-WEBAPP VMware Workspace ONE Access and vRealize Automation authentication bypass attempt (more info ...)attempted-user  2022-31656      URL
60404OS-MOBILE Apple iOS cfprefsd daemon privilege escalation attempt (more info ...)attempted-admin  2019-7286      URL
60405OS-MOBILE Apple iOS cfprefsd daemon privilege escalation attempt (more info ...)attempted-admin  2019-7286      URL
60406OS-MOBILE Android Binder out of bounds write attempt (more info ...)attempted-admin  2020-0041      URL
60407OS-MOBILE Android Binder out of bounds write attempt (more info ...)attempted-admin  2020-0041      URL
60408SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1588 attack attempt (more info ...)attempted-dos        URL
60409SERVER-WEBAPP Zimbra Collaboration memcached command injection attempt (more info ...)attempted-user  2022-27924      
60410SERVER-WEBAPP Zimbra Collaboration memcached command injection attempt (more info ...)attempted-user  2022-27924      
60411BROWSER-WEBKIT Apple WebKit property names type confusion attempt (more info ...)attempted-user  2021-1789      
60412BROWSER-WEBKIT Apple WebKit property names type confusion attempt (more info ...)attempted-user  2021-1789      
60415SERVER-OTHER VMware Workspace ONE Access privilege escalation attempt (more info ...)attempted-admin  2022-31659      URL
60418SERVER-WEBAPP HID Mercury Access Controller command injection attempt (more info ...)web-application-attack  2022-31479      URL
60419SERVER-WEBAPP HID Mercury Access Controller command injection attempt (more info ...)web-application-attack  2022-31479      URL
60420SERVER-WEBAPP HID Mercury Access Controller command injection attempt (more info ...)web-application-attack  2022-31479      URL
60421SERVER-WEBAPP HID Mercury Access Controller command injection attempt (more info ...)web-application-attack  2022-31479      URL
60434SERVER-WEBAPP Zimbra directory traversal remote code execution attempt (more info ...)web-application-attack  2022-37042      URL
60441MALWARE-OTHER Win.Trojan.Redline variant download attempt (more info ...)trojan-activity        URL
60442MALWARE-OTHER Win.Trojan.Redline variant download attempt (more info ...)trojan-activity        URL
60443MALWARE-OTHER Win.Trojan.Matanbuchus variant binary download attempt (more info ...)trojan-activity        URL
60444MALWARE-OTHER Win.Trojan.Matanbuchus variant binary download attempt (more info ...)trojan-activity        URL
60446PROTOCOL-VOIP Realtek eCos SDK SIP parsing stack buffer overflow attempt (more info ...)attempted-admin  2022-27255      URL
60447PROTOCOL-VOIP Realtek eCos SDK SIP parsing stack buffer overflow attempt (more info ...)attempted-admin  2022-27255      URL
60448PROTOCOL-VOIP Realtek eCos SDK SIP parsing stack buffer overflow attempt (more info ...)attempted-admin  2022-27255      URL
60449PROTOCOL-VOIP Realtek eCos SDK SIP parsing stack buffer overflow attempt (more info ...)attempted-admin  2022-27255      URL
60455SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1576 attack attempt (more info ...)attempted-admin  2022-32765      URL
60456FILE-OTHER UnRAR directory traversal attempt (more info ...)attempted-user  2022-30333      URL
60457FILE-OTHER UnRAR directory traversal attempt (more info ...)attempted-user  2022-30333      URL
60458SERVER-OTHER WatchGuard Firebox and XTM remote code execution attempt (more info ...)attempted-user  2022-26318      
60473SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1592 attack attempt (more info ...)attempted-dos  2022-38393      URL
60474SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1596 attack attempt (more info ...)web-application-attack  2022-37337      URL
60475SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1596 attack attempt (more info ...)web-application-attack  2022-37337      URL
60476SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1596 attack attempt (more info ...)web-application-attack  2022-37337      URL
60477SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1596 attack attempt (more info ...)web-application-attack  2022-37337      URL
60487SERVER-WEBAPP Sophos Firewall User Portal and Webadmin authentication bypass attempt (more info ...)attempted-admin  2022-1040      
60488MALWARE-OTHER PacketWhisper decloakify.py download attempt (more info ...)trojan-activity        
60489MALWARE-OTHER PacketWhisper decloakify.py download attempt (more info ...)trojan-activity        
60490MALWARE-OTHER PacketWhisper cloakify.py download attempt (more info ...)trojan-activity        
60491MALWARE-OTHER PacketWhisper cloakify.py download attempt (more info ...)trojan-activity        
60492MALWARE-OTHER PacketWhisper download attempt (more info ...)trojan-activity        
60493MALWARE-OTHER PacketWhisper download attempt (more info ...)trojan-activity        
60499SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1597 attack attempt (more info ...)attempted-admin  2022-36429      URL
60509SERVER-WEBAPP Grafana authentication bypass attempt (more info ...)web-application-attack  2021-39226      URL
60510SERVER-WEBAPP Grafana authentication bypass attempt (more info ...)web-application-attack  2021-39226      URL
60511SERVER-WEBAPP Grafana authentication bypass attempt (more info ...)web-application-attack  2021-39226      URL
60512MALWARE-OTHER Win.Trojan.Matanbuchus variant Cobalt Strike inbound connection (more info ...)trojan-activity        URL
60513MALWARE-OTHER Win.Trojan.Matanbuchus variant Cobalt Strike inbound connection (more info ...)trojan-activity        URL
60540FILE-OTHER TRUFFLEHUNTER TALOS-2022-1593 attack attempt (more info ...)attempted-user  2022-36788      URL
60541FILE-OTHER TRUFFLEHUNTER TALOS-2022-1593 attack attempt (more info ...)attempted-user  2022-36788      URL
60542FILE-OTHER TRUFFLEHUNTER TALOS-2022-1593 attack attempt (more info ...)attempted-user  2022-36788      URL
60543FILE-OTHER TRUFFLEHUNTER TALOS-2022-1593 attack attempt (more info ...)attempted-user  2022-36788      URL
60544FILE-OTHER TRUFFLEHUNTER TALOS-2022-1594 attack attempt (more info ...)attempted-user  2022-38072      URL
60545FILE-OTHER TRUFFLEHUNTER TALOS-2022-1594 attack attempt (more info ...)attempted-user  2022-38072      URL
60548SERVER-WEBAPP Sophos Firewall User Portal and Webadmin authentication bypass attempt (more info ...)attempted-admin  2022-1040      
60551OS-WINDOWS DirectX Graphics kernel use after free attempt (more info ...)attempted-admin  2022-37954      URL
60552OS-WINDOWS DirectX Graphics kernel use after free attempt (more info ...)attempted-admin  2022-37954      URL
60553OS-WINDOWS ALPC Port Object elevation of privilege attempt (more info ...)attempted-admin  2022-34725      URL
60554OS-WINDOWS ALPC Port Object elevation of privilege attempt (more info ...)attempted-admin  2022-34725      URL
60555OS-WINDOWS Windows Common Log File System driver escalation of privileges attempt (more info ...)attempted-admin  2022-35803      URL
60556OS-WINDOWS Windows Common Log File System driver escalation of privileges attempt (more info ...)attempted-admin  2022-35803      URL
60557OS-WINDOWS Windows Common Log File System driver escalation of privileges attempt (more info ...)attempted-admin  2022-35803      URL
60558OS-WINDOWS Windows Common Log File System driver escalation of privileges attempt (more info ...)attempted-admin  2022-35803      URL
60559SERVER-WEBAPP Atlassian Confluence information disclosure attempt (more info ...)web-application-attack  2021-26085      URL
60560SERVER-WEBAPP Atlassian Confluence information disclosure attempt (more info ...)web-application-attack  2021-26085      URL
60561SERVER-WEBAPP D-Link DIR-820L command injection attempt (more info ...)web-application-attack  2022-26258      
60562SERVER-WEBAPP D-Link DIR-820L command injection attempt (more info ...)web-application-attack  2022-26258      
60563SERVER-WEBAPP D-Link DIR-820L command injection attempt (more info ...)web-application-attack  2022-26258      
60564SERVER-WEBAPP D-Link DIR-820L command injection attempt (more info ...)web-application-attack  2022-26258      
60565SERVER-WEBAPP D-Link getcfg value command injection attempt (more info ...)web-application-attack  2022-28958      
60566SERVER-WEBAPP D-Link getcfg value command injection attempt (more info ...)web-application-attack  2022-28958      
60567SERVER-WEBAPP D-Link getcfg value command injection attempt (more info ...)web-application-attack  2022-28958      
60568SERVER-WEBAPP D-Link getcfg value command injection attempt (more info ...)web-application-attack  2022-28958      
60570MALWARE-TOOLS Win.Trojan.Amadey malware tools download attempt (more info ...)trojan-activity        URL
60571MALWARE-TOOLS Win.Trojan.Amadey malware tools download attempt (more info ...)trojan-activity        URL
60572MALWARE-TOOLS Win.Trojan.Amadey malware tools download attempt (more info ...)trojan-activity        URL
60580SERVER-WEBAPP KeySight N6854A and N6841A RF Sensor directory traversal attempt (more info ...)attempted-user  2022-1661      
60581SERVER-WEBAPP GitLab project import command injection attempt (more info ...)web-application-attack  2022-2185      URL
60582MALWARE-OTHER Perl.Webshell.GammaShell upload attempt (more info ...)trojan-activity        URL
60583MALWARE-OTHER Perl.Webshell.GammaShell download attempt (more info ...)trojan-activity        URL
60588MALWARE-OTHER Perl.Webshell.GoShell upload attempt (more info ...)trojan-activity        URL
60592FILE-PDF TRUFFLEHUNTER TALOS-2022-1602 attack attempt (more info ...)attempted-user  2022-37332      URL
60593FILE-PDF TRUFFLEHUNTER TALOS-2022-1602 attack attempt (more info ...)attempted-user  2022-37332      URL
60594FILE-PDF TRUFFLEHUNTER TALOS-2022-1600 attack attempt (more info ...)attempted-user  2022-32774      URL
60595FILE-PDF TRUFFLEHUNTER TALOS-2022-1600 attack attempt (more info ...)attempted-user  2022-32774      URL
60598SERVER-WEBAPP pfSense pfBlockerNG plugin command injection attempt (more info ...)attempted-user  2022-40624      
60600MALWARE-TOOLS Win.Trojan.Mansabo Cobalt Strike download attempt (more info ...)trojan-activity        URL
60604FILE-PDF TRUFFLEHUNTER TALOS-2022-1601 attack attempt (more info ...)attempted-user  2022-38097      URL
60605FILE-PDF TRUFFLEHUNTER TALOS-2022-1601 attack attempt (more info ...)attempted-user  2022-38097      URL
60606FILE-OTHER TRUFFLEHUNTER TALOS-2022-1604 attack attempt (more info ...)attempted-user        URL
60607FILE-OTHER TRUFFLEHUNTER TALOS-2022-1604 attack attempt (more info ...)attempted-user        URL
60608SERVER-WEBAPP Atlassian Bitbucket Server and Data Center remote code execution attempt (more info ...)attempted-user  2022-36804      URL
60609SERVER-WEBAPP D-Link DCS-930L devices OS command injection attempt (more info ...)attempted-admin  2016-11021      
60610SERVER-WEBAPP D-Link DCS-930L devices OS command injection attempt (more info ...)attempted-admin        
60611FILE-OTHER TRUFFLEHUNTER TALOS-2022-1603 attack attempt (more info ...)attempted-user        URL
60612FILE-OTHER TRUFFLEHUNTER TALOS-2022-1603 attack attempt (more info ...)attempted-user        URL
60613OS-WINDOWS Windows DACL privilege escalation attempt (more info ...)attempted-user  2019-1130      URL
60614OS-WINDOWS Windows DACL privilege escalation attempt (more info ...)attempted-user  2019-1130      URL
60619FILE-PDF TRUFFLEHUNTER TALOS-2022-1614 attack attempt (more info ...)attempted-user  2022-40129      URL
60620FILE-PDF TRUFFLEHUNTER TALOS-2022-1614 attack attempt (more info ...)attempted-user  2022-40129      URL
60621SERVER-OTHER WatchGuard Firebox and XTM remote code execution attempt (more info ...)attempted-user  2022-26318      
60622MALWARE-TOOLS Win.Trojan.LockBit variant binary download attempt (more info ...)trojan-activity        URL
60623MALWARE-TOOLS Win.Trojan.LockBit variant binary download attempt (more info ...)trojan-activity        URL
60633SERVER-WEBAPP Cayin Signage Media Player command injection attempt (more info ...)web-application-attack        URL
60634SERVER-WEBAPP Cayin Signage Media Player command injection attempt (more info ...)web-application-attack        URL
60635SERVER-WEBAPP Cayin Signage Media Player command injection attempt (more info ...)web-application-attack        URL
60636SERVER-WEBAPP Cayin Signage Media Player command injection attempt (more info ...)web-application-attack        URL
60640MALWARE-OTHER MultiOS.Backdoor.Agent implant attempt (more info ...)trojan-activity        URL
60649SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1608 attack attempt (more info ...)attempted-admin  2022-38459      URL
60650SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1608 attack attempt (more info ...)attempted-admin  2022-38459      URL
60651SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1605 attack attempt (more info ...)attempted-admin  2022-36279      URL
60652SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1605 attack attempt (more info ...)attempted-admin  2022-36279      URL
60653SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1606 attack attempt (more info ...)web-application-attack  2022-40701      URL
60654SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1606 attack attempt (more info ...)web-application-attack  2022-40701      URL
60655SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1606 attack attempt (more info ...)web-application-attack  2022-40701      URL
60656SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1609 attack attempt (more info ...)web-application-attack  2022-38088      URL
60657SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1609 attack attempt (more info ...)web-application-attack  2022-38088      URL
60658SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1609 attack attempt (more info ...)web-application-attack  2022-38088      URL
60659SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1607 attack attempt (more info ...)web-application-attack  2022-40969      URL
60660SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1607 attack attempt (more info ...)web-application-attack  2022-40969      URL
60661SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1607 attack attempt (more info ...)web-application-attack  2022-40969      URL
60662SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1607 attack attempt (more info ...)web-application-attack  2022-40969      URL
60663SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1610 attack attempt (more info ...)attempted-admin  2022-38715      URL
60664SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1610 attack attempt (more info ...)attempted-admin  2022-38715      URL
60667SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1611 attack attempt (more info ...)web-application-attack  2022-39045      URL
60679SERVER-WEBAPP Advantech iView NetworkServlet command injection attempt (more info ...)web-application-attack  2022-2143      
60680SERVER-WEBAPP Advantech iView NetworkServlet command injection attempt (more info ...)web-application-attack  2022-2143      
60708OS-WINDOWS Windows Win32k.sys bSimpleFill elevation of privilege attempt (more info ...)attempted-admin  2022-38051      URL
60709OS-WINDOWS Windows Win32k.sys bSimpleFill elevation of privilege attempt (more info ...)attempted-admin  2022-38051      URL
60713FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1632 attack attempt (more info ...)attempted-dos  2022-41684      URL
60714FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1632 attack attempt (more info ...)attempted-dos  2022-41684      URL
60715FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1632 attack attempt (more info ...)attempted-dos  2022-41684      URL
60716FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1632 attack attempt (more info ...)attempted-dos  2022-41684      URL
60717FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1632 attack attempt (more info ...)attempted-dos  2022-41684      URL
60718FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1632 attack attempt (more info ...)attempted-dos  2022-41684      URL
60719FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1632 attack attempt (more info ...)attempted-dos  2022-41684      URL
60720FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1632 attack attempt (more info ...)attempted-dos  2022-41684      URL
60721SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1641 attack attempt (more info ...)web-application-attack  2022-42484      URL
60722SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1641 attack attempt (more info ...)web-application-attack  2022-42484      URL
60723SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1641 attack attempt (more info ...)web-application-attack  2022-42484      URL
60724SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1641 attack attempt (more info ...)web-application-attack  2022-42484      URL
60725SERVER-OTHER Fortinet FortiOS and FortiProxy authentication bypass attempt (more info ...)attempted-admin  2022-40684      
60726SERVER-OTHER Fortinet FortiOS and FortiProxy authentication bypass attempt (more info ...)attempted-admin  2022-40684      
60727POLICY-OTHER OWASP Amass default User-Agent recon traffic detected (more info ...)attempted-recon        URL
60729SERVER-WEBAPP vm2 remote code execution attempt (more info ...)attempted-user  2022-36067      
60730FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1633 attack attempt (more info ...)attempted-user  2022-41639      URL
60731FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1633 attack attempt (more info ...)attempted-user  2022-41639      URL
60733FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1630 attack attempt (more info ...)attempted-user  2022-38143      URL
60734FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1630 attack attempt (more info ...)attempted-user  2022-38143      URL
60735FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1628 attack attempt (more info ...)attempted-user  2022-41981      URL
60736FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1628 attack attempt (more info ...)attempted-user  2022-41981      URL
60746SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1619 attack attempt (more info ...)attempted-user  2022-41313      URL
60747SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1619 attack attempt (more info ...)attempted-user  2022-41313      URL
60757FILE-OTHER GNU gzip zgrep arbitrary file write attempt (more info ...)attempted-user  2022-1271      
60758FILE-OTHER GNU gzip zgrep arbitrary file write attempt (more info ...)attempted-user  2022-1271      
60760MALWARE-OTHER Win.Trojan.Astaroth download attempt (more info ...)trojan-activity        URL
60761SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1642 attack attempt (more info ...)web-application-attack  2022-38451      URL
60762SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1642 attack attempt (more info ...)web-application-attack  2022-38451      URL
60763SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1642 attack attempt (more info ...)web-application-attack  2022-38451      URL
60764SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1686 attack attempt (more info ...)web-application-attack  2022-47195      URL
60765SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1686 attack attempt (more info ...)web-application-attack  2022-47197      URL
60766FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1629 attack attempt (more info ...)attempted-recon  2022-36354      URL
60767FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1629 attack attempt (more info ...)attempted-recon  2022-36354      URL
60768SERVER-WEBAPP Sophos Firewall User Portal and Webadmin authentication bypass attempt (more info ...)attempted-admin  2022-1040      
60769SERVER-WEBAPP Sophos Firewall User Portal and Webadmin authentication bypass attempt (more info ...)attempted-admin  2022-1040      
60770SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1624 attack attempt (more info ...)web-application-attack  2022-41654      URL
60771SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1640 attack attempt (more info ...)attempted-admin  2022-42490      URL
60772SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1640 attack attempt (more info ...)attempted-admin  2022-42491      URL
60773SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1640 attack attempt (more info ...)attempted-admin  2022-42492      URL
60774SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1640 attack attempt (more info ...)attempted-admin  2022-42493      URL
60775SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1638 attack attempt (more info ...)attempted-admin  2022-40222      URL
60776SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1637 attack attempt (more info ...)attempted-admin  2022-41154      URL
60777SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1639 attack attempt (more info ...)attempted-admin  2022-41991      URL
60778FILE-OTHER GIGABYTE Kernel Driver elevation of privilege attempt (more info ...)attempted-admin  2018-19322      
60779FILE-OTHER GIGABYTE Kernel Driver elevation of privilege attempt (more info ...)attempted-admin  2018-19322      
60780SERVER-WEBAPP Zimbra Collaboration Suite remote code execution attempt (more info ...)attempted-user  2022-41352      
60781SERVER-WEBAPP Zimbra Collaboration Suite remote code execution attempt (more info ...)attempted-user  2022-41352      
60790SERVER-OTHER OpenSSL x509 crafted email address buffer overflow attempt (more info ...)attempted-user  2022-3786      URL
60793SERVER-WEBAPP VMware Cloud Foundation NSX Manager XStream remote code execution attempt (more info ...)attempted-admin  2022-31678      URL
60796FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1643 attack attempt (more info ...)attempted-user  2022-41988      URL
60797FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1643 attack attempt (more info ...)attempted-user  2022-41988      URL
60798FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1643 attack attempt (more info ...)attempted-user  2022-41988      URL
60799FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1643 attack attempt (more info ...)attempted-user  2022-41988      URL
60805FILE-OTHER TRUFFLEHUNTER TALOS-2022-1644 attack attempt (more info ...)attempted-user  2022-41992      URL
60806FILE-OTHER TRUFFLEHUNTER TALOS-2022-1644 attack attempt (more info ...)attempted-user  2022-41992      URL
60807FILE-OTHER TRUFFLEHUNTER TALOS-2022-1648 attack attempt (more info ...)attempted-dos  2022-43589      URL
60808FILE-OTHER TRUFFLEHUNTER TALOS-2022-1648 attack attempt (more info ...)attempted-dos  2022-43589      URL
60809FILE-OTHER TRUFFLEHUNTER TALOS-2022-1649 attack attempt (more info ...)attempted-dos  2022-43590      URL
60810FILE-OTHER TRUFFLEHUNTER TALOS-2022-1649 attack attempt (more info ...)attempted-dos  2022-43590      URL
60811FILE-OTHER TRUFFLEHUNTER TALOS-2022-1647 attack attempt (more info ...)attempted-dos  2022-43588      URL
60812FILE-OTHER TRUFFLEHUNTER TALOS-2022-1647 attack attempt (more info ...)attempted-dos  2022-43588      URL
60813FILE-OTHER GIGABYTE GPCIDrv and GDrv driver privilege escalation attempt (more info ...)attempted-admin  2018-19320      URL
60814FILE-OTHER GIGABYTE GPCIDrv and GDrv driver privilege escalation attempt (more info ...)attempted-admin  2018-19320      URL
60818OS-WINDOWS Windows Win32 Kernel subsystem elevation of privilege attempt (more info ...)attempted-admin  2022-41113      URL
60819OS-WINDOWS Windows Win32 Kernel subsystem elevation of privilege attempt (more info ...)attempted-admin  2022-41113      URL
60826OS-WINDOWS GIGABYTE GPCI and GIO driver privilege escalation attempt (more info ...)attempted-admin  2018-19321      URL
60827OS-WINDOWS GIGABYTE GPCI and GIO driver privilege escalation attempt (more info ...)attempted-admin  2018-19321      URL
60829MALWARE-OTHER Win.Backdoor.Hoaxshell payload template download attempt (more info ...)trojan-activity        URL
60830MALWARE-OTHER Win.Backdoor.Hoaxshell payload template download attempt (more info ...)trojan-activity        URL
60837OS-WINDOWS MSI afterburner privilege escalation attempt (more info ...)attempted-admin  2019-16098      URL
60838OS-WINDOWS MSI afterburner privilege escalation attempt (more info ...)attempted-admin  2019-16098      URL
60851FILE-OTHER TRUFFLEHUNTER TALOS-2022-1634 attack attempt (more info ...)attempted-user  2022-41838      URL
60852FILE-OTHER TRUFFLEHUNTER TALOS-2022-1634 attack attempt (more info ...)attempted-user  2022-41838      URL
60885SERVER-WEBAPP Nostromo httpd directory traversal attempt (more info ...)web-application-attack  2019-16278      URL
60893MALWARE-OTHER Shikata Ga Nai polymorphic encoder encoded shellcode download attempt (more info ...)trojan-activity        URL
60894MALWARE-OTHER Shikata Ga Nai polymorphic encoder encoded shellcode download attempt (more info ...)trojan-activity        URL
60904FILE-OTHER TRUFFLEHUNTER TALOS-2022-1635 attack attempt (more info ...)attempted-dos  2022-41999      URL
60905FILE-OTHER TRUFFLEHUNTER TALOS-2022-1635 attack attempt (more info ...)attempted-dos  2022-41999      URL
60919FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1636 attack attempt (more info ...)attempted-user  2022-41837      URL
60920FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1636 attack attempt (more info ...)attempted-user  2022-41837      URL
60921FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1636 attack attempt (more info ...)attempted-user  2022-41837      URL
60922FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1636 attack attempt (more info ...)attempted-user  2022-41837      URL
60923FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1636 attack attempt (more info ...)attempted-user  2022-41837      URL
60924FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1636 attack attempt (more info ...)attempted-user  2022-41837      URL
60925FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1636 attack attempt (more info ...)attempted-user  2022-41837      URL
60926FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1636 attack attempt (more info ...)attempted-user  2022-41837      URL
60927SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1621 attack attempt (more info ...)attempted-recon  2022-40691      URL
60928FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1626 attack attempt (more info ...)attempted-user  2022-41794      URL
60929FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1626 attack attempt (more info ...)attempted-user  2022-41794      URL
60930FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1627 attack attempt (more info ...)attempted-recon  2022-41977      URL
60931FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1627 attack attempt (more info ...)attempted-recon  2022-41977      URL
60932FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1627 attack attempt (more info ...)attempted-recon  2022-41977      URL
60933FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1627 attack attempt (more info ...)attempted-recon  2022-41977      URL
60942SERVER-WEBAPP VMware vSphere Client vROPs plugin remote code execution attempt (more info ...)attempted-admin  2021-21972      URL
60946SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1645 attack attempt (more info ...)attempted-dos  2022-43441      URL
60948MALWARE-TOOLS Win.Trojan.Teleport download attempt (more info ...)trojan-activity        URL
60949MALWARE-TOOLS Win.Trojan.Teleport download attempt (more info ...)trojan-activity        URL
60954MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
60955MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
60956MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
60957MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
60958MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
60959MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
60960MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
60961MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
60964MALWARE-TOOLS Win.Dropper.KopiLuwak download attempt (more info ...)trojan-activity        URL
60965MALWARE-TOOLS Win.Dropper.KopiLuwak download attempt (more info ...)trojan-activity        URL
60966SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1679 attack attempt (more info ...)attempted-dos        URL
60967SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1679 attack attempt (more info ...)attempted-dos        URL
60968MALWARE-OTHER Win.Ransomware.Endurance variant download attempt (more info ...)trojan-activity        URL
60969MALWARE-OTHER Win.Ransomware.Endurance variant download attempt (more info ...)trojan-activity        URL
60970SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1678 attack attempt (more info ...)attempted-admin        URL
60971SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1678 attack attempt (more info ...)attempted-admin        URL
60983PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2022-1662 attack attempt (more info ...)attempted-admin  2022-43605      URL
60984PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2022-1661 attack attempt (more info ...)attempted-admin  2022-43604      URL
60985PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2022-1663 attack attempt (more info ...)attempted-dos  2022-43606      URL
60988MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
60989MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
60992MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
60993MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
60994MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        
60995MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        
60996MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        
60997MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        
60998MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
60999MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
61000MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
61001MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
61002MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
61003MALWARE-OTHER Win.Malware.Gazer loader variant download attempt (more info ...)trojan-activity        URL
61044MALWARE-OTHER Win.Downloader.BatLoader malicious PowerShell script download attempt (more info ...)trojan-activity        URL
61045MALWARE-OTHER Win.Downloader.BatLoader malicious PowerShell script download attempt (more info ...)trojan-activity        URL
61066SERVER-WEBAPP TIBCO JasperReports reportresource directory traversal attempt (more info ...)web-application-attack  2018-18809      URL
61067SERVER-WEBAPP TIBCO JasperReports reportresource directory traversal attempt (more info ...)web-application-attack  2018-18809      URL
61068SERVER-WEBAPP TIBCO JasperReports reportresource directory traversal attempt (more info ...)web-application-attack  2018-18809      URL
61069SERVER-WEBAPP TIBCO JasperReports flow.html directory traversal attempt (more info ...)web-application-attack  2018-5430      URL
61070SERVER-WEBAPP TIBCO JasperReports flow.html directory traversal attempt (more info ...)web-application-attack  2018-5430      URL
61071SERVER-WEBAPP TIBCO JasperReports flow.html directory traversal attempt (more info ...)web-application-attack  2018-5430      URL
61072MALWARE-OTHER JSP.Webshell.JSPShell upload attempt (more info ...)trojan-activity        URL
61073MALWARE-OTHER JSP.Webshell.JSPShell download attempt (more info ...)trojan-activity        URL
61075MALWARE-OTHER Win.Ransomware.Agenda variant binary download attempt (more info ...)trojan-activity        URL
61076MALWARE-OTHER Win.Ransomware.Agenda variant binary download attempt (more info ...)trojan-activity        URL
61081SERVER-WEBAPP mojoPortal Forums txtTitle cross site scripting attempt (more info ...)attempted-user        URL
61082SERVER-WEBAPP mojoPortal Forums txtTitle cross site scripting attempt (more info ...)attempted-user        URL
61085MALWARE-OTHER HTML.Exploit.C99 suspicious file upload (more info ...)trojan-activity        URL
61093PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2022-1674 attack attempt (more info ...)attempted-user  2022-43663      URL
61095MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
61096MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
61097MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
61098MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
61103SERVER-WEBAPP ZenTao Pro command injection attempt (more info ...)web-application-attack  2020-7361      URL
61104SERVER-WEBAPP ZenTao Pro command injection attempt (more info ...)web-application-attack  2020-7361      URL
61105SERVER-WEBAPP ZenTao Pro command injection attempt (more info ...)web-application-attack  2020-7361      URL
61107SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61108SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61109SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61110SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61111SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61113SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61114SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61115SERVER-WEBAPP Fscan scanner arbitrary JSP file upload attempt (more info ...)attempted-admin        URL
61116SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61119SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61121SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61122SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61123SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61124SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61125SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61126SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61127SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61129SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61133SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61134SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61135SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61136SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61137SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61138SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61139SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61141SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61143SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61145SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61146SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61147SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61148SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61150SERVER-WEBAPP Fscan scanner directory traversal attempt (more info ...)web-application-attack        URL
61152SERVER-WEBAPP Fscan scanner command injection attempt (more info ...)web-application-attack        URL
61156MALWARE-OTHER JSP.Webshell.JSP2Shell download attempt (more info ...)trojan-activity        URL
61157MALWARE-OTHER JSP.Webshell.JSP2Shell upload attempt (more info ...)trojan-activity        URL
61167SERVER-WEBAPP Lexmark MC3224adwe server side request forgery attempt (more info ...)web-application-attack        URL
61168SERVER-WEBAPP Lexmark MC3224adwe Web UI ImportFaxLogo command injection attempt (more info ...)web-application-attack        URL
61171SERVER-WEBAPP Zoho ManageEngine multiple products remote code execution attempt (more info ...)attempted-user  2022-47966      URL
61172SERVER-WEBAPP Zoho ManageEngine multiple products remote code execution attempt (more info ...)attempted-user  2022-47966      URL
61173MALWARE-OTHER Win.Malware.LightNeuron mail transfer agent download (more info ...)trojan-activity        URL
61174MALWARE-OTHER Win.Malware.LightNeuron mail transfer agent download (more info ...)trojan-activity        URL
61175MALWARE-OTHER Win.Malware.LightNeuron mail transfer agent download (more info ...)trojan-activity        URL
61176MALWARE-OTHER Win.Malware.LightNeuron mail transfer agent download (more info ...)trojan-activity        URL
61180SERVER-WEBAPP SugarCRM EmailTemplates authentication bypass attempt (more info ...)web-application-attack  2023-22952      URL
61181SERVER-WEBAPP SugarCRM EmailTemplates authentication bypass attempt (more info ...)web-application-attack  2023-22952      URL
61183MALWARE-OTHER Windows.Malware.Dacls malware file download attempt (more info ...)trojan-activity        URL
61184MALWARE-OTHER Windows.Malware.Dacls malware file download attempt (more info ...)trojan-activity        URL
61185MALWARE-OTHER Windows.Malware.Dacls malware file download attempt (more info ...)trojan-activity        URL
61186MALWARE-OTHER Windows.Malware.Dacls malware file download attempt (more info ...)trojan-activity        URL
61194SERVER-WEBAPP Centos Web Panel 7 unauthenticated command injection attempt (more info ...)web-application-attack  2022-44877      
61195SERVER-WEBAPP Centos Web Panel 7 unauthenticated command injection attempt (more info ...)web-application-attack  2022-44877      
61196MALWARE-TOOLS Win.Tool.WinPwn toolkit download attempt (more info ...)trojan-activity        
61197MALWARE-TOOLS Powershell AMSI bypass toolkit download attempt (more info ...)trojan-activity        
61198MALWARE-TOOLS Powershell AMSI bypass toolkit download attempt (more info ...)trojan-activity        
61200SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1697 attack attempt (more info ...)web-application-attack  2023-23902      URL
61201OS-OTHER TRUFFLEHUNTER TALOS-2022-1689 attack attempt (more info ...)attempted-admin        URL
61202MALWARE-OTHER PowerSploit toolkit download attempt (more info ...)trojan-activity        URL
61203MALWARE-OTHER PowerSCCM toolkit download attempt (more info ...)trojan-activity        URL
61204MALWARE-TOOLS PowerSploit script download attempt (more info ...)trojan-activity        URL
61205MALWARE-TOOLS PowerSploit script download attempt (more info ...)trojan-activity        URL
61209SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1695 attack attempt (more info ...)web-application-attack  2023-23547      URL
61210SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1695 attack attempt (more info ...)web-application-attack  2023-23547      URL
61211SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1695 attack attempt (more info ...)web-application-attack  2023-23547      URL
61213MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        
61214MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        
61215MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
61216MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
61217MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
61218MALWARE-OTHER Win.Malware.Gazer variant download attempt (more info ...)trojan-activity        URL
61219MALWARE-OTHER WinPWN Powershell toolkit outbound connection attempt (more info ...)trojan-activity        URL
61220MALWARE-OTHER WinPWN Powershell toolkit outbound connection attempt (more info ...)trojan-activity        URL
61221MALWARE-OTHER WinPWN Powershell toolkit outbound connection attempt (more info ...)trojan-activity        URL
61222MALWARE-OTHER WinPWN Powershell toolkit outbound connection attempt (more info ...)trojan-activity        URL
61225INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Mimikatz download attempt (more info ...)trojan-activity        URL
61226INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Mimikatz download attempt (more info ...)trojan-activity        URL
61227INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Mimikatz download attempt (more info ...)trojan-activity        URL
61228INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Mimikatz download attempt (more info ...)trojan-activity        URL
61229INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Inveigh download attempt (more info ...)trojan-activity        URL
61230INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Inveigh download attempt (more info ...)trojan-activity        URL
61231INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit PE injector download attempt (more info ...)shellcode-detect        URL
61232INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit PE injector download attempt (more info ...)shellcode-detect        URL
61233INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        
61234INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        
61235INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61236INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61237INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61238INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61239MALWARE-TOOLS Win.Tool.TruffleSnout download attempt (more info ...)trojan-activity        
61240MALWARE-TOOLS Win.Tool.TruffleSnout download attempt (more info ...)trojan-activity        
61244SERVER-OTHER VMware vRealize Log Insight directory traversal attempt (more info ...)attempted-admin  2022-31706      URL
61245SERVER-OTHER VMware vRealize Log Insight directory traversal attempt (more info ...)attempted-admin  2022-31706      URL
61246SERVER-OTHER VMware vRealize Log Insight broken access control attempt (more info ...)attempted-admin  2022-31704      URL
61247SERVER-OTHER VMware vRealize Log Insight configuration information leak attempt (more info ...)attempted-recon  2022-31711      URL
61248SERVER-OTHER VMware vRealize Log Insight directory traversal attempt (more info ...)attempted-admin  2022-31706      URL
61249SERVER-OTHER VMware vRealize Log Insight directory traversal attempt (more info ...)attempted-admin  2022-31706      URL
61254SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1712 attack attempt (more info ...)web-application-attack  2023-22299      URL
61255SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1704 attack attempt (more info ...)web-application-attack  2023-24497      URL
61256SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1704 attack attempt (more info ...)web-application-attack  2023-24497      URL
61257SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1710 attack attempt (more info ...)attempted-user  2023-24582      URL
61258SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1710 attack attempt (more info ...)attempted-user  2023-24583      URL
61260SERVER-OTHER VMware ESXi SLVPd remote code execution attempt (more info ...)attempted-admin  2021-21974      URL
61261MALWARE-OTHER Win.Ransomware.MortalKombat variant binary download attempt (more info ...)trojan-activity        URL
61262MALWARE-OTHER Win.Ransomware.MortalKombat variant binary download attempt (more info ...)trojan-activity        URL
61266SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1703 attack attempt (more info ...)web-application-attack  2023-22371      URL
61267SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1703 attack attempt (more info ...)web-application-attack  2023-22371      URL
61268SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1715 attack attempt (more info ...)web-application-attack  2023-24018      URL
61269SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1714 attack attempt (more info ...)web-application-attack  2023-22653      URL
61270SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1706 attack attempt (more info ...)web-application-attack  2023-24520      URL
61271FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1707 attack attempt (more info ...)attempted-recon  2023-24473      URL
61272FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1707 attack attempt (more info ...)attempted-recon  2023-24473      URL
61273MALWARE-OTHER Win.Trojan.Turla Crutch backdoor download (more info ...)trojan-activity        URL
61274MALWARE-OTHER Win.Trojan.Turla Crutch backdoor download (more info ...)trojan-activity        URL
61275INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61276INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61277INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity  2017-0148      URL
61278INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity  2017-0148      URL
61279INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity  2016-0099      URL
61280INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity  2016-0099      URL
61281INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity  2016-7255      URL
61282INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity  2016-7255      URL
61283INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Zerologon download attempt (more info ...)trojan-activity  2020-1472      URL
61284INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Zerologon download attempt (more info ...)trojan-activity  2020-1472      URL
61285INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61286INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61287INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit PrintNightmare download attempt (more info ...)trojan-activity  2021-1675      URL
61288INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit PrintNightmare download attempt (more info ...)trojan-activity  2021-1675      URL
61289INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit JuicyPotato download attempt (more info ...)trojan-activity        URL
61290INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit JuicyPotato download attempt (more info ...)trojan-activity        URL
61291SERVER-OTHER FortiOS SSLVPNd Content-Length memory corruption attempt (more info ...)attempted-admin  2022-42475      URL
61293MALWARE-TOOLS Win.Tool.WinPWN UAC bypass module download attempt (more info ...)trojan-activity        URL
61294MALWARE-TOOLS Win.Tool.WinPWN UAC bypass module download attempt (more info ...)trojan-activity        URL
61295MALWARE-TOOLS Win.Tool.WinPWN UAC bypass module download attempt (more info ...)trojan-activity        URL
61296MALWARE-TOOLS Win.Tool.WinPWN UAC bypass module download attempt (more info ...)trojan-activity        URL
61297MALWARE-TOOLS Win.Tool.WinPWN Disk Cleanup UAC bypass module download attempt (more info ...)trojan-activity        URL
61298MALWARE-TOOLS Win.Tool.WinPWN Disk Cleanup UAC bypass module download attempt (more info ...)trojan-activity        URL
61299MALWARE-TOOLS Win.Tool.WinPWN amsi module download attempt (more info ...)trojan-activity        URL
61300MALWARE-TOOLS Win.Tool.WinPWN amsi module download attempt (more info ...)trojan-activity        URL
61301MALWARE-TOOLS Win.Tool.WinPWN adpass module download attempt (more info ...)trojan-activity        URL
61302MALWARE-TOOLS Win.Tool.WinPWN adpass module download attempt (more info ...)trojan-activity        URL
61316FILE-OTHER Visual Studio Code malicious ipynb download attempt (more info ...)attempted-user  2022-41034      URL
61317FILE-OTHER Visual Studio Code malicious ipynb download attempt (more info ...)attempted-user  2022-41034      URL
61318MALWARE-TOOLS Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61319MALWARE-TOOLS Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61322INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit TeamViewerDecrypt download attempt (more info ...)trojan-activity        URL
61323INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit TeamViewerDecrypt download attempt (more info ...)trojan-activity        URL
61324INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit SpoolerScan download attempt (more info ...)trojan-activity        URL
61325INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit SpoolerScan download attempt (more info ...)trojan-activity        URL
61328INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-Vulmap download attempt (more info ...)trojan-activity        URL
61329INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-Vulmap download attempt (more info ...)trojan-activity        URL
61330INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-SMBNegotiate download attempt (more info ...)trojan-activity        URL
61331INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-SMBNegotiate download attempt (more info ...)trojan-activity        URL
61332INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-SharpPrinter download attempt (more info ...)trojan-activity        URL
61333INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-SharpPrinter download attempt (more info ...)trojan-activity        URL
61334INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-SharpLdapRelayScan download attempt (more info ...)trojan-activity        URL
61335INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-SharpLdapRelayScan download attempt (more info ...)trojan-activity        URL
61336INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-PowerDump download attempt (more info ...)trojan-activity        URL
61337INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-PowerDump download attempt (more info ...)trojan-activity        URL
61338INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-LdapSignCheck download attempt (more info ...)trojan-activity        URL
61339INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-LdapSignCheck download attempt (more info ...)trojan-activity        URL
61340INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-HandleKatz download attempt (more info ...)trojan-activity        URL
61341INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-HandleKatz download attempt (more info ...)trojan-activity        URL
61342INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-EventLogParser download attempt (more info ...)trojan-activity        URL
61343INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Invoke-EventLogParser download attempt (more info ...)trojan-activity        URL
61344INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Get-DotNetServices download attempt (more info ...)trojan-activity        URL
61345INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Get-DotNetServices download attempt (more info ...)trojan-activity        URL
61348INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Find-Fruit download attempt (more info ...)trojan-activity        URL
61349INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit Find-Fruit download attempt (more info ...)trojan-activity        URL
61350INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit BlueKeep scanner download attempt (more info ...)trojan-activity  2019-0708      URL
61351INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit BlueKeep scanner download attempt (more info ...)trojan-activity  2019-0708      URL
61352INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit ADRecon download attempt (more info ...)trojan-activity        URL
61353INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit ADRecon download attempt (more info ...)trojan-activity        URL
61354INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61355INDICATOR-COMPROMISE Win.Tool.WinPWN toolkit download attempt (more info ...)trojan-activity        URL
61356SERVER-WEBAPP Oracle E-Business Suite unauthenticated RCE attempt (more info ...)attempted-user  2022-21587      
61358SERVER-OTHER F5 iControl SOAP format string attempt (more info ...)attempted-admin  2023-22374      URL
61365MALWARE-OTHER Doc.Dropper.Agent payload download attempt (more info ...)trojan-activity        
61366MALWARE-OTHER Doc.Dropper.Agent payload download attempt (more info ...)trojan-activity        
61368FILE-OTHER ClamAV HFS+ partition scanning buffer overflow attempt (more info ...)attempted-user  2023-20032      URL
61369FILE-OTHER ClamAV HFS+ partition scanning buffer overflow attempt (more info ...)attempted-user  2023-20032      URL
61370SERVER-WEBAPP TerraMaster TOS unauthenticated command injection attempt (more info ...)web-application-attack  2022-24990      URL
61371SERVER-WEBAPP TerraMaster TOS unauthenticated command injection attempt (more info ...)web-application-attack  2022-24990      URL
61372SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt (more info ...)attempted-admin  2023-0669      
61373SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt (more info ...)attempted-admin  2023-0669      
61374SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt (more info ...)attempted-admin  2023-0669      
61375SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt (more info ...)attempted-admin  2023-0669      
61384FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1708 attack attempt (more info ...)attempted-user  2023-22845      URL
61385FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1708 attack attempt (more info ...)attempted-user  2023-22845      URL
61386FILE-OTHER TRUFFLEHUNTER TALOS-2023-1719 attack attempt (more info ...)attempted-user        URL
61387FILE-OTHER TRUFFLEHUNTER TALOS-2023-1719 attack attempt (more info ...)attempted-user        URL
61392SERVER-OTHER Fortinet Fortinac keyUpload.jsp remote code execution attempt (more info ...)attempted-admin  2022-39952      
61395SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1716 attack attempt (more info ...)web-application-attack  2023-25124      URL
61396SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1716 attack attempt (more info ...)web-application-attack  2023-25124      URL
61397SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1716 attack attempt (more info ...)web-application-attack  2023-25124      URL
61398FILE-OTHER TRUFFLEHUNTER TALOS-2023-1720 attack attempt (more info ...)attempted-user        URL
61399FILE-OTHER TRUFFLEHUNTER TALOS-2023-1720 attack attempt (more info ...)attempted-user        URL
61400MALWARE-OTHER Iso.Trojan.BruteRatel binary download attempt (more info ...)trojan-activity        URL
61401MALWARE-OTHER Iso.Trojan.BruteRatel binary download attempt (more info ...)trojan-activity        URL
61402MALWARE-OTHER Win.Trojan.BruteRatel binary download attempt (more info ...)trojan-activity        URL
61403MALWARE-OTHER Win.Trojan.BruteRatel binary download attempt (more info ...)trojan-activity        URL
61404MALWARE-OTHER Win.Trojan.BruteRatel binary download attempt (more info ...)trojan-activity        URL
61405MALWARE-OTHER Win.Trojan.BruteRatel binary download attempt (more info ...)trojan-activity        URL
61406SERVER-WEBAPP Cacti remote_agent command injection attempt (more info ...)web-application-attack  2022-46169      URL
61407SERVER-WEBAPP Cacti remote_agent command injection attempt (more info ...)web-application-attack  2022-46169      URL
61408SERVER-WEBAPP Cacti remote_agent command injection attempt (more info ...)web-application-attack  2022-46169      URL
61409SERVER-WEBAPP Cacti remote_agent command injection attempt (more info ...)web-application-attack  2022-46169      URL
61410FILE-OTHER TRUFFLEHUNTER TALOS-2023-1721 attack attempt (more info ...)attempted-user        URL
61411FILE-OTHER TRUFFLEHUNTER TALOS-2023-1721 attack attempt (more info ...)attempted-user        URL
61414SERVER-WEBAPP Zivif PR115-204-P-RS web camera command injection attempt (more info ...)web-application-attack  2017-17105      URL
61415SERVER-WEBAPP Zivif PR115-204-P-RS web camera command injection attempt (more info ...)web-application-attack  2017-17105      URL
61416SERVER-WEBAPP Zivif PR115-204-P-RS web camera command injection attempt (more info ...)web-application-attack  2017-17105      URL
61417SERVER-WEBAPP Zivif PR115-204-P-RS web camera command injection attempt (more info ...)web-application-attack  2017-17105      URL
61418SERVER-WEBAPP Grandstream GXV31XX unauthenticated command injection attempt (more info ...)web-application-attack  2019-10655      URL
61419SERVER-WEBAPP Grandstream GXV31XX unauthenticated command injection attempt (more info ...)web-application-attack  2019-10655      URL
61420SERVER-WEBAPP Grandstream GXV31XX unauthenticated command injection attempt (more info ...)web-application-attack  2019-10655      URL
61421SERVER-WEBAPP Grandstream GXV31XX unauthenticated command injection attempt (more info ...)web-application-attack  2019-10655      URL
61422SERVER-WEBAPP Roxy-WI unauthenticated command injection attempt (more info ...)web-application-attack  2022-31137      URL
61423SERVER-WEBAPP Roxy-WI unauthenticated command injection attempt (more info ...)web-application-attack  2022-31137      URL
61424SERVER-WEBAPP Roxy-WI unauthenticated command injection attempt (more info ...)web-application-attack  2022-31137      URL
61425SERVER-WEBAPP Roxy-WI unauthenticated command injection attempt (more info ...)web-application-attack  2022-31137      URL
61432PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2023-1727 attack attempt (more info ...)attempted-admin        URL
61433PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2023-1727 attack attempt (more info ...)attempted-admin        URL
61434SERVER-WEBAPP IBM Aspera Faspex YAML deserialization command injection attempt (more info ...)attempted-user  2022-47986      URL
61444SERVER-WEBAPP ZK Framework AuUploader authentication bypass attempt (more info ...)web-application-attack  2022-36537      URL
61451SERVER-WEBAPP Zoho ManageEngine multiple products remote code execution attempt (more info ...)attempted-user  2022-47966      URL
61452SERVER-WEBAPP Zoho ManageEngine multiple products remote code execution attempt (more info ...)attempted-user  2022-47966      URL
61453SERVER-WEBAPP Zoho ManageEngine multiple products remote code execution attempt (more info ...)attempted-user  2022-47966      URL
61455SERVER-WEBAPP Joomla unauthorized configuration access attempt (more info ...)attempted-user  2023-23752      
61456SERVER-WEBAPP Joomla unauthorized configuration access attempt (more info ...)attempted-recon  2023-23752      
61462MALWARE-OTHER HTA VBScript powershell payload download attempt (more info ...)trojan-activity        URL
61463MALWARE-OTHER HTA VBScript powershell payload download attempt (more info ...)trojan-activity        URL
61474SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1731 attack attempt (more info ...)attempted-admin  2023-25076      URL
61477SERVER-WEBAPP Inspur ClusterEngine 4.0 command injection attempt (more info ...)web-application-attack  2020-21224      URL
61480SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1731 attack attempt (more info ...)attempted-admin  2023-25076      URL
61481MALWARE-OTHER Win.Backdoor.MQsTTang variant download attempt (more info ...)trojan-activity        URL
61482MALWARE-OTHER Win.Backdoor.MQsTTang variant download attempt (more info ...)trojan-activity        URL
61483SERVER-WEBAPP Zoho ManageEngine ADSelfService Plus default credentials login attempt (more info ...)attempted-admin  2022-28810      URL
61484SERVER-WEBAPP Zoho ManageEngine ADSelfService Plus default credentials login attempt (more info ...)attempted-admin  2022-28810      URL
61485SERVER-WEBAPP FLIR AX8 Camera command injection attempt (more info ...)attempted-user  2022-37061      
61486SERVER-WEBAPP FLIR AX8 Camera command injection attempt (more info ...)attempted-user  2022-37061      
61490MALWARE-OTHER Win.Ransomware.Mallox variant binary SMB transfer attempt (more info ...)trojan-activity        URL
61491MALWARE-OTHER Win.Ransomware.Mallox variant binary download attempt (more info ...)trojan-activity        URL
61492MALWARE-OTHER Win.Ransomware.Mallox variant binary download attempt (more info ...)trojan-activity        URL
61495MALWARE-OTHER Ps1.Malware.Powercat shell download attempt (more info ...)trojan-activity        
61496MALWARE-OTHER Ps1.Malware.Powercat shell download attempt (more info ...)trojan-activity        
61497MALWARE-OTHER Ps1.Malware.Powercat shell download attempt (more info ...)trojan-activity        
61499SERVER-WEBAPP Plex Media Server arbitrary file upload attempt (more info ...)attempted-admin  2020-5741      URL
61500SERVER-WEBAPP Plex Media Server arbitrary file upload attempt (more info ...)attempted-admin  2020-5741      URL
61501SERVER-WEBAPP Oracle WebLogic Server unauthenticated RMI code execution attempt (more info ...)attempted-user  2023-21839      URL
61502SERVER-WEBAPP Oracle WebLogic Server unauthenticated RMI code execution attempt (more info ...)attempted-user  2023-21839      URL
61515SERVER-WEBAPP pgAdmin validate_binary_path command injection attempt (more info ...)attempted-user  2022-4223      
61516SERVER-OTHER SolarWinds Network Performance Monitor insecure deserialization attempt (more info ...)attempted-user  2022-38108      
61517MALWARE-OTHER OneNote.Dropper.Emotet variant download attempt (more info ...)trojan-activity        URL
61518MALWARE-OTHER OneNote.Dropper.Emotet variant download attempt (more info ...)trojan-activity        URL
61519MALWARE-OTHER OneNote.Dropper.Emotet variant download attempt (more info ...)trojan-activity        URL
61520MALWARE-OTHER OneNote.Dropper.Emotet variant download attempt (more info ...)trojan-activity        URL
61521MALWARE-OTHER OneNote.Dropper.Emotet variant download attempt (more info ...)trojan-activity        URL
61522MALWARE-OTHER OneNote.Dropper.Emotet variant download attempt (more info ...)trojan-activity        URL
61525SERVER-OTHER FortiOS SSLVPNd Content-Length memory corruption attempt (more info ...)attempted-admin  2022-42475      URL
61526OS-WINDOWS SPNEGO unchecked header length remote code execution attempt (more info ...)attempted-admin  2022-37958      URL
61531SERVER-WEBAPP Sophos Firewall remote code execution attempt (more info ...)attempted-admin  2022-3236      URL
61532MALWARE-OTHER Win.Trojan.Typhon variant download attempt (more info ...)trojan-activity        URL
61533MALWARE-OTHER Win.Trojan.Typhon variant download attempt (more info ...)trojan-activity        URL
61535SERVER-WEBAPP Avaya Aura Device Services cross site scripting attempt (more info ...)attempted-user        URL
61536SERVER-WEBAPP Avaya Aura Device Services cross site scripting attempt (more info ...)attempted-user        URL
61539MALWARE-OTHER Win.Trojan.Rhadamanthys variant payload download attempt (more info ...)trojan-activity        URL
61550MALWARE-BACKDOOR Win.Backdoor.Chollima shellcode runner download attempt (more info ...)trojan-activity        URL
61551MALWARE-BACKDOOR Win.Backdoor.Chollima shellcode runner download attempt (more info ...)trojan-activity        URL
61552MALWARE-BACKDOOR Win.Backdoor.Chollima obfuscated .ico download attempt (more info ...)trojan-activity        URL
61553MALWARE-BACKDOOR Win.Backdoor.Chollima obfuscated .ico download attempt (more info ...)trojan-activity        URL
61558MALWARE-OTHER Win.Trojan.Emotet variant download attempt (more info ...)trojan-activity        URL
61559MALWARE-OTHER Win.Trojan.Emotet variant download attempt (more info ...)trojan-activity        URL
61562MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
61563MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity        URL
61568MALWARE-OTHER Win.Trojan.XLoader variant download attempt (more info ...)trojan-activity        URL
61569MALWARE-OTHER Win.Trojan.XLoader variant download attempt (more info ...)trojan-activity        URL
61570MALWARE-OTHER Win.Trojan.AgentTesla variant download attempt (more info ...)trojan-activity        URL
61571MALWARE-OTHER Win.Trojan.AgentTesla variant download attempt (more info ...)trojan-activity        URL
61573SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1736 attack attempt (more info ...)attempted-dos  2023-22325      URL
61579SERVER-WEBAPP CONTEC CONPROSYS HMI System command injection attempt (more info ...)attempted-user  2022-44456      
61580SERVER-WEBAPP CONTEC CONPROSYS HMI System command injection attempt (more info ...)attempted-user  2022-44456      
61581SERVER-WEBAPP CONTEC CONPROSYS HMI System command injection attempt (more info ...)attempted-user  2022-44456      
61582MALWARE-OTHER Win.Ransomware.Royal variant helper script download attempt (more info ...)trojan-activity        URL
61583MALWARE-OTHER Win.Ransomware.Royal variant helper script download attempt (more info ...)trojan-activity        URL
61584MALWARE-OTHER Win.Ransomware.Royal variant helper script download attempt (more info ...)trojan-activity        URL
61585MALWARE-OTHER Win.Ransomware.Royal variant helper script download attempt (more info ...)trojan-activity        URL
61586MALWARE-OTHER Win.Ransomware.Royal variant download attempt (more info ...)trojan-activity        URL
61587MALWARE-OTHER Win.Ransomware.Royal variant download attempt (more info ...)trojan-activity        URL
61589MALWARE-OTHER Win.Ransomware.Royal variant helper script download attempt (more info ...)trojan-activity        URL
61590MALWARE-OTHER Win.Ransomware.Royal variant helper script download attempt (more info ...)trojan-activity        URL
61600SERVER-WEBAPP Zimbra Collaboration cross site scripting attempt (more info ...)attempted-user  2022-27926      URL
61601SERVER-WEBAPP Zimbra Collaboration cross site scripting attempt (more info ...)attempted-user  2022-27926      URL
61602SERVER-WEBAPP Zimbra Collaboration cross site scripting attempt (more info ...)attempted-user  2021-35207      URL
61603SERVER-WEBAPP Zimbra Collaboration cross site scripting attempt (more info ...)attempted-user  2021-35207      URL
61604FILE-OTHER Node.js vm2 prepareStackTrace sandbox escape attempt (more info ...)attempted-user  2023-29017      
61605FILE-OTHER Node.js vm2 prepareStackTrace sandbox escape attempt (more info ...)attempted-user  2023-29017      
61624SERVER-WEBAPP Azure Service Fabric Explorer Super FabriXss cross site scripting attempt (more info ...)attempted-user  2023-23383      URL
61625FILE-PDF TRUFFLEHUNTER TALOS-2023-1739 attack attempt (more info ...)attempted-user  2023-28744      URL
61626FILE-PDF TRUFFLEHUNTER TALOS-2023-1739 attack attempt (more info ...)attempted-user  2023-28744      URL
61633OS-OTHER Apple macOS and iOS IOSurfaceAccelerator out-of-bounds write attempt (more info ...)attempted-admin  2023-28206      
61634OS-OTHER Apple macOS and iOS IOSurfaceAccelerator out-of-bounds write attempt (more info ...)attempted-admin  2023-28206      
61635OS-OTHER Apple macOS and iOS IOSurfaceAccelerator out-of-bounds write attempt (more info ...)attempted-admin  2023-28206      
61636OS-OTHER Apple macOS and iOS IOSurfaceAccelerator out-of-bounds write attempt (more info ...)attempted-admin  2023-28206      
61637OS-OTHER Apple macOS and iOS IOSurfaceAccelerator out-of-bounds write attempt (more info ...)attempted-admin  2023-28206      
61638OS-OTHER Apple macOS and iOS IOSurfaceAccelerator out-of-bounds write attempt (more info ...)attempted-admin  2023-28206      
61652MALWARE-BACKDOOR Win.Backdoor.Chollima file download attempt (more info ...)trojan-activity        
61653MALWARE-BACKDOOR Win.Backdoor.Chollima file download attempt (more info ...)trojan-activity        
61654OS-MOBILE Android Andr.Trojan.Pinduoduo APK file download attempt (more info ...)trojan-activity  2023-20963      URL
61655OS-MOBILE Android Andr.Trojan.Pinduoduo APK file download attempt (more info ...)trojan-activity  2023-20963      URL
61656MALWARE-OTHER Osx.Exploit.Keysteal download attempt (more info ...)trojan-activity  2019-8526      URL
61657MALWARE-OTHER Osx.Exploit.Keysteal download attempt (more info ...)trojan-activity  2019-8526      URL
61658MALWARE-OTHER Osx.Exploit.Keysteal download attempt (more info ...)trojan-activity  2019-8526      URL
61659MALWARE-OTHER Osx.Exploit.Keysteal download attempt (more info ...)trojan-activity  2019-8526      URL
61660MALWARE-OTHER Osx.Exploit.Keysteal download attempt (more info ...)trojan-activity  2019-8526      URL
61661MALWARE-OTHER Osx.Exploit.Keysteal download attempt (more info ...)trojan-activity  2019-8526      URL
61662MALWARE-OTHER Osx.Exploit.Keysteal download attempt (more info ...)trojan-activity  2019-8526      URL
61663MALWARE-OTHER Osx.Exploit.Keysteal download attempt (more info ...)trojan-activity  2019-8526      URL
61668MALWARE-OTHER Win.Trojan.IcedID variant binary download attempt (more info ...)trojan-activity        URL
61669MALWARE-OTHER Win.Trojan.IcedID variant binary download attempt (more info ...)trojan-activity        URL
61670MALWARE-OTHER One.Dropper.Qakbot variant binary download attempt (more info ...)trojan-activity        URL
61671MALWARE-OTHER One.Dropper.Qakbot variant binary download attempt (more info ...)trojan-activity        URL
61672MALWARE-OTHER One.Dropper.IcedID variant binary download attempt (more info ...)trojan-activity        URL
61673MALWARE-OTHER One.Dropper.IcedID variant binary download attempt (more info ...)trojan-activity        URL
61674MALWARE-OTHER One.Dropper.Remcos variant binary download attempt (more info ...)trojan-activity        URL
61675MALWARE-OTHER One.Dropper.Remcos variant binary download attempt (more info ...)trojan-activity        URL
61677SERVER-WEBAPP PaperCut MF/NG PrintScript sandbox setting modification attempt (more info ...)web-application-attack  2023-27350      URL
61678SERVER-WEBAPP PaperCut MF/NG PrintScript remote code execution attempt (more info ...)web-application-attack  2023-27350      URL
61692POLICY-OTHER MinIO REST API information disclosure attempt (more info ...)policy-violation  2023-28432      URL
61693FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1742 attack attempt (more info ...)attempted-user  2023-28393      URL
61694FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1742 attack attempt (more info ...)attempted-user  2023-28393      URL
61695FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1742 attack attempt (more info ...)attempted-user  2023-28393      URL
61696FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1742 attack attempt (more info ...)attempted-user  2023-28393      URL
61697SERVER-WEBAPP Zoho ManageEngine ADSelfService Plus command injection attempt (more info ...)web-application-attack  2022-28810      URL
61698SERVER-WEBAPP Zoho ManageEngine Network Configuration Manager Ping command injection attempt (more info ...)web-application-attack  2021-43319      URL
61699SERVER-WEBAPP Zoho ManageEngine Network Configuration Manager Ping command injection attempt (more info ...)web-application-attack  2021-43319      URL
61700SERVER-WEBAPP Zoho ManageEngine Network Configuration Manager Ping command injection attempt (more info ...)web-application-attack  2021-43319      URL
61701SERVER-WEBAPP Zoho ManageEngine Network Configuration Manager Ping command injection attempt (more info ...)web-application-attack  2021-43319      URL
61708MALWARE-OTHER Win.Trojan.Greatness outbound communication attempt (more info ...)trojan-activity        
61709SERVER-WEBAPP TP-Link Archer Router command injection attempt (more info ...)web-application-attack  2023-1389      URL
61710SERVER-WEBAPP TP-Link Archer Router command injection attempt (more info ...)web-application-attack  2023-1389      URL
61711SERVER-WEBAPP TP-Link Archer Router command injection attempt (more info ...)web-application-attack  2023-1389      URL
61712SERVER-WEBAPP TP-Link Archer Router command injection attempt (more info ...)web-application-attack  2023-1389      URL
61730FILE-IMAGE ImageMagick tEXt profile arbitrary file read attempt (more info ...)attempted-admin  2022-44268      URL
61731FILE-IMAGE ImageMagick tEXt profile arbitrary file read attempt (more info ...)attempted-admin  2022-44268      URL
61732MALWARE-OTHER Ps1.Downloader.Agent download attempt (more info ...)trojan-activity        URL
61733MALWARE-OTHER Ps1.Downloader.Agent download attempt (more info ...)trojan-activity        URL
61737MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61738MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61739MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61740MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61741MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61742MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61743MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61744MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61745MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61746MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61747MALWARE-OTHER Andr.Trojan.AridViper webshell download attempt (more info ...)trojan-activity        URL
61748MALWARE-OTHER Andr.Trojan.AridViper webshell download attempt (more info ...)trojan-activity        URL
61749MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61750MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61751MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61752MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61753MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61754MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61755MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61756MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61757MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61758MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61759MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61760MALWARE-OTHER Andr.Trojan.AridViper binary download attempt (more info ...)trojan-activity        URL
61763MALWARE-OTHER Win.Ransomware.Babuk variant transfer attempt (more info ...)trojan-activity        URL
61764MALWARE-OTHER Win.Ransomware.Babuk variant transfer attempt (more info ...)trojan-activity        URL
61766SERVER-WEBAPP PaperCut MF/NG remote code execution attempt (more info ...)web-application-attack  2023-27350      URL
61783SERVER-WEBAPP Keysight N6854A and N6841A insecure deserialization attempt (more info ...)attempted-admin  2022-1660      
61784SERVER-WEBAPP D-Link HNAP1 buffer overflow attempt (more info ...)attempted-user  2022-41140      URL
61794SERVER-WEBAPP Sophos Virtual Web Appliance unauthenticated command injection attempt (more info ...)attempted-admin  2023-1671      URL
61795SERVER-WEBAPP Sophos Virtual Web Appliance unauthenticated command injection attempt (more info ...)attempted-admin  2023-1671      URL
61799SERVER-WEBAPP NETGEAR Nighthawk RAX30 router SOAP authentication bypass attempt (more info ...)web-application-attack  2023-27369      URL
61800POLICY-OTHER NETGEAR Nighthawk RAX30 router SOAP API information disclosure attempt (more info ...)web-application-attack  2023-27357      URL
61801SERVER-WEBAPP Netgate pfSense restore_rrddata filename command injection attempt (more info ...)web-application-attack  2023-27253      URL
61806MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61807MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61808MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61809MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61810MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61811MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61812MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61813MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61814MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61815MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61816MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61817MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61818MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61819MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61820MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61821MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61822MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61823MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61824MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61825MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61826MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61827MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61828MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61829MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61830MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61831MALWARE-OTHER Revoked.CRT.HookSignTool maliciously signed driver download (more info ...)trojan-activity        URL
61832SERVER-WEBAPP Bitrix CMS HTML Editor Module arbitrary code injection attempt (more info ...)web-application-attack  2022-27228      URL
61833SERVER-WEBAPP Bitrix CMS Vote Module arbitrary code injection attempt (more info ...)web-application-attack  2022-27228      URL
61837SERVER-WEBAPP Ruckus Wireless Admin command injection attempt (more info ...)web-application-attack  2023-25717      URL
61838SERVER-WEBAPP Ruckus Wireless Admin command injection attempt (more info ...)web-application-attack  2023-25717      URL
61840MALWARE-OTHER Win.Trojan.Horabot phishing attempt (more info ...)trojan-activity        
61843MALWARE-OTHER Html.Downloader.Horabot trojan phishing attempt (more info ...)trojan-activity        
61844MALWARE-OTHER Html.Downloader.Horabot trojan phishing attempt (more info ...)trojan-activity        
61857MALWARE-OTHER Ps1.Downloader.Horabot malicious file download attempt (more info ...)trojan-activity        
61858MALWARE-OTHER Ps1.Downloader.Horabot malicious file download attempt (more info ...)trojan-activity        
61859MALWARE-OTHER Win.Trojan.Cerbu file download (more info ...)trojan-activity        
61860MALWARE-OTHER Win.Trojan.Cerbu file download (more info ...)trojan-activity        
61861INDICATOR-OBFUSCATION .zip top-level domain unicode forward slash obfuscation attempt (more info ...)misc-activity        URL
61862INDICATOR-OBFUSCATION .zip top-level domain unicode forward slash obfuscation attempt (more info ...)misc-activity        URL
61863INDICATOR-OBFUSCATION .zip top-level domain unicode forward slash obfuscation attempt (more info ...)misc-activity        URL
61864INDICATOR-OBFUSCATION .zip top-level domain unicode forward slash obfuscation attempt (more info ...)misc-activity        URL
61865SERVER-WEBAPP Zyxel unauthenticated IKEv2 command injection attempt (more info ...)attempted-admin  2023-28771      URL
61866SERVER-WEBAPP TP-Link MiniDLNA remote code execution attempt (more info ...)attempted-admin  2023-28760      URL
61867SERVER-WEBAPP TP-Link MiniDLNA remote code execution attempt (more info ...)attempted-admin  2023-28760      URL
61870INDICATOR-SHELLCODE Windows Donut x64 loader download attempt (more info ...)shellcode-detect        URL
61871INDICATOR-SHELLCODE Windows Donut x64 loader download attempt (more info ...)shellcode-detect        URL
61872INDICATOR-SHELLCODE Windows Donut x86 loader download attempt (more info ...)shellcode-detect        URL
61873INDICATOR-SHELLCODE Windows Donut x86 loader download attempt (more info ...)shellcode-detect        URL
61874FILE-PDF TRUFFLEHUNTER TALOS-2023-1747 attack attempt (more info ...)attempted-user        URL
61875FILE-PDF TRUFFLEHUNTER TALOS-2023-1747 attack attempt (more info ...)attempted-user        URL
61876MALWARE-BACKDOOR Asp.Backdoor.MoveITShell connection attempt (more info ...)trojan-activity  2023-34362      URL
61877MALWARE-BACKDOOR Asp.Backdoor.MoveITShell connection attempt (more info ...)trojan-activity  2023-34362      URL
61878MALWARE-BACKDOOR Asp.Backdoor.MoveITShell upload attempt (more info ...)trojan-activity  2023-34362      URL
61879MALWARE-BACKDOOR Asp.Backdoor.MoveITShell download attempt (more info ...)trojan-activity  2023-34362      URL
61881INDICATOR-COMPROMISE Veeam Backup Server credential stealer script download attempt (more info ...)misc-activity        URL
61882INDICATOR-COMPROMISE Veeam Backup Server credential stealer script download attempt (more info ...)misc-activity        URL
61883MALWARE-TOOLS Win.Proxy.EarthWorm download attempt (more info ...)trojan-activity        URL
61884MALWARE-TOOLS Win.Proxy.EarthWorm download attempt (more info ...)trojan-activity        URL
61887FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1749 attack attempt (more info ...)attempted-user  2023-32614      URL
61888FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1749 attack attempt (more info ...)attempted-user  2023-32614      URL
61889MALWARE-TOOLS Win.Loader.Meterpreter download attempt (more info ...)trojan-activity        URL
61890MALWARE-TOOLS Win.Loader.Meterpreter download attempt (more info ...)trojan-activity        URL
61897SERVER-WEBAPP Centreon Web Application command injection attempt (more info ...)web-application-attack  2019-15298      
61898SERVER-WEBAPP Centreon Web Application command injection attempt (more info ...)web-application-attack  2019-15298      
61899SERVER-WEBAPP Centreon Web Application command injection attempt (more info ...)web-application-attack  2019-15298      
61900SERVER-WEBAPP Centreon Web Application command injection attempt (more info ...)web-application-attack  2019-15298      
61917SERVER-WEBAPP Barracuda Email Security Gateway malicious .tar upload attempt (more info ...)web-application-attack  2023-2868      URL
61918SERVER-WEBAPP Barracuda Email Security Gateway malicious .tar upload attempt (more info ...)web-application-attack  2023-2868      URL
61919SERVER-WEBAPP Barracuda Email Security Gateway malicious .tar upload attempt (more info ...)web-application-attack  2023-2868      URL
61920SERVER-WEBAPP Barracuda Email Security Gateway malicious .tar upload attempt (more info ...)web-application-attack  2023-2868      URL
61921SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt (more info ...)attempted-admin  2023-0669      
61922SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt (more info ...)attempted-admin  2023-0669      
61923SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt (more info ...)attempted-admin  2023-0669      
61924SERVER-WEBAPP Fortra GoAnywhere MFT remote code execution attempt (more info ...)attempted-admin  2023-0669      
61925PROTOCOL-SCADA TRUFFLEHUNTER SFVRT-1050 attack attempt (more info ...)attempted-admin        
61926PROTOCOL-SCADA TRUFFLEHUNTER SFVRT-1050 attack attempt (more info ...)attempted-admin        
61927PROTOCOL-SCADA Rockwell Automation ControlLogix CIP read socket object exploit attempt (more info ...)attempted-admin  2023-3596      
61928PROTOCOL-SCADA Rockwell Automation ControlLogix CIP read socket object exploit attempt (more info ...)attempted-admin  2023-3596      
61929PROTOCOL-SCADA Rockwell Automation ControlLogix CIP exploit attempt (more info ...)attempted-admin  2023-3596      
61930PROTOCOL-SCADA Rockwell Automation ControlLogix CIP exploit attempt (more info ...)attempted-admin  2023-3596      
61931PROTOCOL-SCADA Rockwell Automation ControlLogix CIP exploit attempt (more info ...)attempted-admin  2023-3596      
61932PROTOCOL-SCADA Rockwell Automation ControlLogix CIP exploit attempt (more info ...)attempted-admin  2023-3596      
61934MALWARE-OTHER Win.Exploit.CVE_2023_28310 download attempt (more info ...)trojan-activity  2023-28310      URL
61935MALWARE-OTHER Win.Exploit.CVE_2023_28310 download attempt (more info ...)trojan-activity  2023-28310      URL
61936SERVER-WEBAPP MOVEit Transfer moveitisapi.dll server side request forgery attempt (more info ...)web-application-attack  2023-34362      URL
61940SERVER-WEBAPP FortiOS SSL VPN heap overflow attempt (more info ...)attempted-admin  2023-27997      URL
61941SERVER-WEBAPP FortiOS SSL VPN heap overflow attempt (more info ...)attempted-admin  2023-27997      URL
61942SERVER-WEBAPP GitLab CE/EE 16.0.0 directory traversal attempt (more info ...)web-application-attack  2023-2825      URL
61943SERVER-WEBAPP VMware vRealize Network Insight createSupportBundle command injection attempt (more info ...)web-application-attack  2023-20887      URL
61944SERVER-WEBAPP VMware vRealize Network Insight restricted endpoint bypass attempt (more info ...)web-application-attack        URL
61947MALWARE-OTHER Win.Trojan.Barys file download attempt (more info ...)trojan-activity        
61948MALWARE-OTHER Win.Trojan.Barys file download attempt (more info ...)trojan-activity        
61949MALWARE-OTHER Win.Trojan.Barys file download attempt (more info ...)trojan-activity        
61950MALWARE-OTHER Win.Trojan.Barys file download attempt (more info ...)trojan-activity        
61951SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1752 attack attempt (more info ...)attempted-admin  2023-32645      URL
61952FILE-PDF TRUFFLEHUNTER TALOS-2023-1756 attack attempt (more info ...)attempted-user  2023-27379      URL
61953FILE-PDF TRUFFLEHUNTER TALOS-2023-1756 attack attempt (more info ...)attempted-user  2023-27379      URL
61954SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1754 attack attempt (more info ...)attempted-user  2023-27516      URL
61955SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1767 attack attempt (more info ...)attempted-admin  2023-32632      URL
61956SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1767 attack attempt (more info ...)attempted-admin  2023-32632      URL
61959SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1764 attack attempt (more info ...)attempted-user  2023-34346      URL
61961SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1778 attack attempt (more info ...)web-application-attack  2023-34356      URL
61962SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1778 attack attempt (more info ...)web-application-attack  2023-34356      URL
61963SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1778 attack attempt (more info ...)web-application-attack  2023-34356      URL
61964SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1778 attack attempt (more info ...)web-application-attack  2023-34356      URL
61969SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1761 attack attempt (more info ...)attempted-admin  2023-35056      URL
61970SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1761 attack attempt (more info ...)attempted-admin  2023-35056      URL
61971SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1761 attack attempt (more info ...)attempted-admin  2023-35056      URL
61972SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1761 attack attempt (more info ...)attempted-admin  2023-35056      URL
61973SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1761 attack attempt (more info ...)attempted-admin  2023-35056      URL
61974SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1761 attack attempt (more info ...)attempted-admin  2023-35056      URL
61975SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1761 attack attempt (more info ...)attempted-admin  2023-35056      URL
61976SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1761 attack attempt (more info ...)attempted-admin  2023-35056      URL
61977FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1760 attack attempt (more info ...)attempted-user  2023-35002      URL
61978FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1760 attack attempt (more info ...)attempted-user  2023-35002      URL
61979SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1779 attack attempt (more info ...)web-application-attack  2023-27381      URL
61980SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1779 attack attempt (more info ...)web-application-attack  2023-27381      URL
61981SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1779 attack attempt (more info ...)web-application-attack  2023-27381      URL
61982SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1779 attack attempt (more info ...)web-application-attack  2023-27381      URL
61983SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1782 attack attempt (more info ...)web-application-attack  2023-35194      URL
61984SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1782 attack attempt (more info ...)web-application-attack  2023-35194      URL
61985SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1782 attack attempt (more info ...)web-application-attack  2023-35194      URL
61986SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1782 attack attempt (more info ...)web-application-attack  2023-35194      URL
61987INDICATOR-COMPROMISE Win.Tool.EDRSandBlast EDR bypass download attempt (more info ...)misc-activity        URL
61988INDICATOR-COMPROMISE Win.Tool.EDRSandBlast EDR bypass download attempt (more info ...)misc-activity        URL
61989OS-WINDOWS MSI Afterburner driver privilege escalation attempt (more info ...)attempted-admin  2019-16098      URL
61990OS-WINDOWS MSI Afterburner driver privilege escalation attempt (more info ...)attempted-admin  2019-16098      URL
61995SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1781 attack attempt (more info ...)attempted-user  2023-34354      URL
61996SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1781 attack attempt (more info ...)attempted-user  2023-34354      URL
61997SERVER-WEBAPP Zyxel ZyWALL authentication bypass attempt (more info ...)web-application-attack  2022-0342      
61998SERVER-WEBAPP Barracuda Email Security Gateway malicious .tar upload attempt (more info ...)web-application-attack  2023-2868      URL
61999SERVER-WEBAPP Barracuda Email Security Gateway malicious .tar upload attempt (more info ...)web-application-attack  2023-2868      URL
62000SERVER-WEBAPP Barracuda Email Security Gateway malicious .tar upload attempt (more info ...)web-application-attack  2023-2868      URL
62001SERVER-WEBAPP Barracuda Email Security Gateway malicious .tar upload attempt (more info ...)web-application-attack  2023-2868      URL
62002FILE-IDENTIFY TAR file download request (more info ...)misc-activity        
62005FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1750 attack attempt (more info ...)attempted-user  2023-32284      URL
62006FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1750 attack attempt (more info ...)attempted-user  2023-32284      URL
62007FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1750 attack attempt (more info ...)attempted-user  2023-32284      URL
62008FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1750 attack attempt (more info ...)attempted-user  2023-32284      URL
62009SERVER-WEBAPP LB-Link Multiple BLRouters command injection attempt (more info ...)web-application-attack  2023-26801      
62014MALWARE-OTHER Win.Trojan.SmokeLoader variant download attempt (more info ...)trojan-activity        URL
62015MALWARE-OTHER Win.Trojan.SmokeLoader variant download attempt (more info ...)trojan-activity        URL
62016MALWARE-OTHER Win.Trojan.SmokeLoader variant download attempt (more info ...)trojan-activity        URL
62017MALWARE-OTHER Win.Trojan.SmokeLoader variant download attempt (more info ...)trojan-activity        URL
62018MALWARE-OTHER Win.Trojan.SmokeLoader variant download attempt (more info ...)trojan-activity        URL
62019MALWARE-OTHER Win.Trojan.SmokeLoader variant download attempt (more info ...)trojan-activity        URL
62020MALWARE-OTHER Win.Trojan.SmokeLoader variant download attempt (more info ...)trojan-activity        URL
62021MALWARE-OTHER Win.Trojan.SmokeLoader variant download attempt (more info ...)trojan-activity        URL
62028PROTOCOL-SCADA Rockwell Automation ControlLogix CIP read socket object exploit attempt (more info ...)attempted-admin  2023-3596      
62029PROTOCOL-SCADA Rockwell Automation ControlLogix CIP read socket object exploit attempt (more info ...)attempted-admin  2023-3596      
62030PROTOCOL-SCADA Rockwell Automation ControlLogix CIP exploit attempt (more info ...)attempted-admin  2023-3596      
62031PROTOCOL-SCADA Rockwell Automation ControlLogix CIP exploit attempt (more info ...)attempted-admin  2023-3596      
62032PROTOCOL-SCADA Rockwell Automation ControlLogix CIP exploit attempt (more info ...)attempted-admin  2023-3596      
62033PROTOCOL-SCADA Rockwell Automation ControlLogix CIP exploit attempt (more info ...)attempted-admin  2023-3596      
62036SERVER-WEBAPP LB-Link Multiple BL Routers command injection attempt (more info ...)web-application-attack  2023-26801      
62037SERVER-WEBAPP Multiple products command injection attempt (more info ...)web-application-attack  2023-27076      
62043SERVER-WEBAPP Zyxel NAS web interface command injection attempt (more info ...)web-application-attack  2023-27992      URL
62044SERVER-WEBAPP Zyxel NAS web interface command injection attempt (more info ...)web-application-attack  2023-27992      URL
62045SERVER-WEBAPP Zyxel NAS web interface command injection attempt (more info ...)web-application-attack  2023-27992      URL
62046SERVER-WEBAPP Zyxel NAS web interface command injection attempt (more info ...)web-application-attack  2023-27992      URL
62049SERVER-WEBAPP DCN DCBI-Netlog-LAB command injection attempt (more info ...)web-application-attack  2023-26802      URL
62050SERVER-WEBAPP DCN DCBI-Netlog-LAB command injection attempt (more info ...)web-application-attack  2023-26802      URL
62051SERVER-WEBAPP DCN DCBI-Netlog-LAB command injection attempt (more info ...)web-application-attack  2023-26802      URL
62052SERVER-WEBAPP DCN DCBI-Netlog-LAB command injection attempt (more info ...)web-application-attack  2023-26802      URL
62058FILE-PDF TRUFFLEHUNTER TALOS-2023-1795 attack attempt (more info ...)attempted-user  2023-32664      URL
62059FILE-PDF TRUFFLEHUNTER TALOS-2023-1795 attack attempt (more info ...)attempted-user  2023-32664      URL
62062FILE-PDF TRUFFLEHUNTER TALOS-2023-1794 attack attempt (more info ...)attempted-user        URL
62063FILE-PDF TRUFFLEHUNTER TALOS-2023-1794 attack attempt (more info ...)attempted-user        URL
62064MALWARE-OTHER Win.Ransomware.Trigona variant download attempt (more info ...)trojan-activity        URL
62065MALWARE-OTHER Win.Ransomware.Trigona variant download attempt (more info ...)trojan-activity        URL
62066MALWARE-OTHER Win.Ransomware.Trigona variant download attempt (more info ...)trojan-activity        URL
62067MALWARE-OTHER Win.Ransomware.Trigona variant download attempt (more info ...)trojan-activity        URL
62068MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62069MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62070MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62071MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62072MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62073MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62074MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62075MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62076MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62077MALWARE-OTHER Win.Trojan.RomCom variant download attempt (more info ...)trojan-activity        URL
62078MALWARE-OTHER Win.Ransomware.IndustrialSpy variant download attempt (more info ...)trojan-activity        URL
62079MALWARE-OTHER Win.Ransomware.IndustrialSpy variant download attempt (more info ...)trojan-activity        URL
62080MALWARE-OTHER Win.Ransomware.IndustrialSpy variant download attempt (more info ...)trojan-activity        URL
62081MALWARE-OTHER Win.Ransomware.IndustrialSpy variant download attempt (more info ...)trojan-activity        URL
62082MALWARE-OTHER Win.Ransomware.Underground variant download attempt (more info ...)trojan-activity        URL
62083MALWARE-OTHER Win.Ransomware.Underground variant download attempt (more info ...)trojan-activity        URL
62087FILE-OTHER TRUFFLEHUNTER TALOS-2023-1797 attack attempt (more info ...)attempted-user  2023-36864      URL
62088FILE-OTHER TRUFFLEHUNTER TALOS-2023-1797 attack attempt (more info ...)attempted-user  2023-36864      URL
62089FILE-OTHER TRUFFLEHUNTER TALOS-2023-1793 attack attempt (more info ...)attempted-user  2023-36747      URL
62090FILE-OTHER TRUFFLEHUNTER TALOS-2023-1793 attack attempt (more info ...)attempted-user  2023-36747      URL
62093SERVER-WEBAPP Zimbra Collaboration Suite cross site scripting attempt (more info ...)attempted-user  2023-34192      URL
62094SERVER-WEBAPP Zimbra Collaboration Suite cross site scripting attempt (more info ...)attempted-user  2023-34192      URL
62095SERVER-WEBAPP SolarView Compact command injection vulnerability (more info ...)attempted-user  2022-29303      
62098SERVER-WEBAPP SolarView Compact command injection attempt (more info ...)attempted-user  2022-29303      
62099SERVER-WEBAPP SolarView Compact command injection attempt (more info ...)attempted-user  2022-29303      
62100SERVER-WEBAPP SolarView Compact command injection attempt (more info ...)attempted-user  2022-29303      
62101SERVER-WEBAPP SolarView Compact command injection attempt (more info ...)attempted-user  2022-29303      
62107SERVER-OTHER Rockwell Automation Thinmanger Thinserver directory traversal attempt (more info ...)attempted-user  2023-27856      URL
62108SERVER-WEBAPP Roundcube Webmail cross site scripting attempt (more info ...)web-application-attack  2020-35730      URL
62109SERVER-WEBAPP Citrix ADC Gateway remote code execution attempt (more info ...)web-application-attack  2023-3519      URL
62110SERVER-WEBAPP Citrix ADC Gateway remote code execution attempt (more info ...)web-application-attack  2023-3519      URL
62123SERVER-WEBAPP Atlassian Bitbucket command injection attempt (more info ...)web-application-attack  2022-43781      
62124SERVER-WEBAPP Atlassian Bitbucket command injection attempt (more info ...)web-application-attack  2022-43781      
62125SERVER-WEBAPP Atlassian Bitbucket command injection attempt (more info ...)web-application-attack  2022-43781      
62127SERVER-WEBAPP Dolibarr ERP & CRM command injection attempt (more info ...)web-application-attack  2022-40871      URL
62128SERVER-WEBAPP Dolibarr ERP & CRM command injection attempt (more info ...)web-application-attack  2022-40871      URL
62129SERVER-WEBAPP Dolibarr ERP & CRM command injection attempt (more info ...)web-application-attack  2022-40871      URL
62130SERVER-WEBAPP Dolibarr ERP & CRM command injection attempt (more info ...)web-application-attack  2022-40871      URL
90011conficker.a shellcode (more info ...)        
90022conficker.b shellcode (more info ...)        


# of warning rules in this group: 15232

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
105MALWARE-BACKDOOR - Dagger_1.4.0 (more info ...)misc-activity    
108MALWARE-BACKDOOR QAZ Worm Client Login access (more info ...)misc-activity    
110MALWARE-BACKDOOR netbus getinfo (more info ...)trojan-activity    
115MALWARE-BACKDOOR NetBus Pro 2.0 connection established (more info ...)trojan-activity    
117MALWARE-BACKDOOR Infector.1.x (more info ...)misc-activity   11157 
118MALWARE-BACKDOOR SatansBackdoor.2.0.Beta (more info ...)trojan-activity    URL
119MALWARE-BACKDOOR Doly 2.0 access (more info ...)misc-activity    
121MALWARE-BACKDOOR Infector 1.6 Client to Server Connection Request (more info ...)misc-activity   11157 
141MALWARE-BACKDOOR HackAttack 1.20 Connect (more info ...)misc-activity    
146MALWARE-BACKDOOR NetSphere access (more info ...)trojan-activity    
152MALWARE-BACKDOOR BackConstruction 2.1 Connection (more info ...)misc-activity    
161MALWARE-BACKDOOR Matrix 2.0 Client connect (more info ...)misc-activity    
162MALWARE-BACKDOOR Matrix 2.0 Server access (more info ...)misc-activity    
163MALWARE-BACKDOOR WinCrash 1.0 Server Active (more info ...)misc-activity    
185MALWARE-BACKDOOR CDK (more info ...)misc-activity    
195MALWARE-BACKDOOR DeepThroat 3.1 Server Response (more info ...)trojan-activity   10053 
208MALWARE-BACKDOOR PhaseZero Server Active on Network (more info ...)trojan-activity    URL
209MALWARE-BACKDOOR w00w00 attempt (more info ...)attempted-admin    
210MALWARE-BACKDOOR attempt (more info ...)attempted-admin    
211MALWARE-BACKDOOR MISC r00t attempt (more info ...)attempted-admin    
212MALWARE-BACKDOOR MISC rewt attempt (more info ...)attempted-admin    
217MALWARE-BACKDOOR MISC sm4ck attempt (more info ...)attempted-admin    
219MALWARE-BACKDOOR HidePak backdoor attempt (more info ...)misc-activity    
220MALWARE-BACKDOOR HideSource backdoor attempt (more info ...)misc-activity    
223MALWARE-OTHER Trin00 Daemon to Master PONG message detected (more info ...)attempted-dos 2000-0138   
230MALWARE-OTHER shaft client login to handler (more info ...)attempted-dos 2000-0138   URL
231MALWARE-OTHER Trin00 Daemon to Master message detected (more info ...)attempted-dos 2000-0138   
232MALWARE-OTHER Trin00 Daemon to Master *HELLO* message detected (more info ...)attempted-dos 2000-0138   URL
239MALWARE-OTHER shaft handler to agent (more info ...)attempted-dos 2000-0138   
240MALWARE-OTHER shaft agent to handler (more info ...)attempted-dos 2000-0138   
243MALWARE-OTHER mstream agent to handler (more info ...)attempted-dos 2000-0138   
244MALWARE-OTHER mstream handler to agent (more info ...)attempted-dos 2000-0138   
245MALWARE-OTHER mstream handler ping to agent (more info ...)attempted-dos 2000-0138   
246MALWARE-OTHER mstream agent pong to handler (more info ...)attempted-dos 2000-0138   
247MALWARE-OTHER mstream client to handler (more info ...)attempted-dos 2000-0138   
248MALWARE-OTHER mstream handler to client (more info ...)attempted-dos 2000-0138   
250MALWARE-OTHER mstream handler to client (more info ...)attempted-dos 2000-0138   
258SERVER-OTHER Bind Buffer Overflow via NXT records (more info ...)attempted-admin 1999-0833 788  
259SERVER-OTHER Bind Buffer Overflow via NXT records named overflow ADM (more info ...)attempted-admin 1999-0833 788  
260SERVER-OTHER Bind Buffer Overflow via NXT records named overflow ADMROCKS (more info ...)attempted-admin 1999-0833 788  URL
261SERVER-OTHER Bind named overflow attempt (more info ...)attempted-admin    URL
266OS-OTHER x86 FreeBSD overflow attempt (more info ...)attempted-admin    
276SERVER-OTHER RealNetworks Audio Server denial of service attempt (more info ...)attempted-dos 1999-0271  10183 
277SERVER-OTHER RealNetworks Server template.html (more info ...)attempted-dos 2000-0474 1288 10461 
278SERVER-OTHER RealNetworks Server template.html (more info ...)attempted-dos 2000-0474 1288  
283BROWSER-OTHER Netscape 4.7 client overflow (more info ...)attempted-user 2000-1187 822  
286PROTOCOL-POP EXPLOIT x86 BSD overflow (more info ...)attempted-admin 1999-0006 133 10196 
287PROTOCOL-POP EXPLOIT x86 BSD overflow (more info ...)attempted-admin    
290PROTOCOL-POP EXPLOIT qpopper overflow (more info ...)attempted-admin 1999-0822 830 10184 
301SERVER-OTHER LPRng overflow (more info ...)attempted-admin 2000-0917 1712  
303SERVER-OTHER Bind Buffer Overflow named tsig overflow attempt (more info ...)attempted-admin 2001-0010 2302 10605 
305SERVER-OTHER delegate proxy overflow (more info ...)attempted-admin 2000-0165 808  
306SERVER-OTHER VQServer admin (more info ...)attempted-admin 2000-0766 1610 10354 URL
307SERVER-OTHER CHAT IRC topic overflow (more info ...)attempted-user 1999-0672 573  
309SERVER-MAIL sniffit overflow (more info ...)attempted-admin 2000-0343 1158  
310SERVER-MAIL x86 windows MailMax overflow (more info ...)attempted-admin 1999-0404 2312  
311BROWSER-OTHER Netscape 4.7 unsucessful overflow (more info ...)unsuccessful-user 2000-1187 822  
314SERVER-OTHER Bind Buffer Overflow named tsig overflow attempt (more info ...)attempted-admin 2001-0010 2302  
320PROTOCOL-FINGER cmd_rootsh backdoor attempt (more info ...)attempted-admin   10070 URL
321PROTOCOL-FINGER account enumeration attempt (more info ...)attempted-recon   10788 
322PROTOCOL-FINGER search query (more info ...)attempted-recon 1999-0259   
323PROTOCOL-FINGER root query (more info ...)attempted-recon    
324PROTOCOL-FINGER null request (more info ...)attempted-recon 1999-0612   
326PROTOCOL-FINGER remote command execution attempt (more info ...)attempted-user 1999-0150 974  
327PROTOCOL-FINGER remote command pipe execution attempt (more info ...)attempted-user 1999-0152 2220  
328PROTOCOL-FINGER bomb attempt (more info ...)attempted-dos 1999-0106   
330PROTOCOL-FINGER redirection attempt (more info ...)attempted-recon 1999-0105  10073 
331PROTOCOL-FINGER cybercop query (more info ...)attempted-recon 1999-0612   
332PROTOCOL-FINGER 0 query (more info ...)attempted-recon 1999-0197  10069 
333PROTOCOL-FINGER . query (more info ...)attempted-recon 1999-0198  10072 
492PROTOCOL-TELNET login failed (more info ...)bad-unknown    
493APP-DETECT psyBNC access (more info ...)bad-unknown    
495INDICATOR-COMPROMISE command error (more info ...)bad-unknown    
498INDICATOR-COMPROMISE id check returned root (more info ...)bad-unknown    
507PUA-OTHER PCAnywhere Attempted Administrator Login (more info ...)attempted-admin    
508SERVER-OTHER gopher proxy (more info ...)bad-unknown    
510POLICY-OTHER HP JetDirect LCD modification attempt (more info ...)misc-activity  2245  
512PUA-OTHER PCAnywhere Failed Login (more info ...)unsuccessful-user    
514SERVER-OTHER ramen worm (more info ...)bad-unknown    
516PROTOCOL-SNMP NT UserList (more info ...)attempted-recon   10546 
530OS-WINDOWS NT NULL session (more info ...)attempted-recon 2000-0347 1163  
555POLICY-OTHER WinGate telnet server response (more info ...)misc-activity 1999-0657   
556PUA-P2P Outbound GNUTella client request (more info ...)policy-violation    
557PUA-P2P GNUTella client request (more info ...)policy-violation    
568POLICY-OTHER HP JetDirect LCD modification attempt (more info ...)misc-activity  2245  
607PROTOCOL-SERVICES rsh bin (more info ...)attempted-user    
608PROTOCOL-SERVICES rsh echo + + (more info ...)attempted-user    
609PROTOCOL-SERVICES rsh froot (more info ...)attempted-admin    
611PROTOCOL-SERVICES rlogin login failure (more info ...)unsuccessful-user    
613INDICATOR-SCAN myscan (more info ...)attempted-recon    URL
614MALWARE-BACKDOOR hack-a-tack attempt (more info ...)attempted-recon    
616INDICATOR-SCAN ident version request (more info ...)attempted-recon    URL
619INDICATOR-SCAN cybercop os probe (more info ...)attempted-recon    URL
622INDICATOR-SCAN ipEye SYN scan (more info ...)attempted-recon    URL
626INDICATOR-SCAN cybercop os PA12 attempt (more info ...)attempted-recon    URL
627INDICATOR-SCAN cybercop os SFU12 probe (more info ...)attempted-recon    URL
630INDICATOR-SCAN synscan portscan (more info ...)attempted-recon    URL
631SERVER-MAIL ehlo cybercop attempt (more info ...)protocol-command-decode    
632SERVER-MAIL expn cybercop attempt (more info ...)protocol-command-decode    
638INDICATOR-SHELLCODE SGI NOOP (more info ...)shellcode-detect    
639INDICATOR-SHELLCODE SGI NOOP (more info ...)shellcode-detect    
642INDICATOR-SHELLCODE HP-UX NOOP (more info ...)shellcode-detect    
643INDICATOR-SHELLCODE HP-UX NOOP (more info ...)shellcode-detect    
644INDICATOR-SHELLCODE sparc NOOP (more info ...)shellcode-detect    
645INDICATOR-SHELLCODE sparc NOOP (more info ...)shellcode-detect    
646INDICATOR-SHELLCODE sparc NOOP (more info ...)shellcode-detect    
647INDICATOR-SHELLCODE Oracle sparc setuid 0 (more info ...)system-call-detect    
660SERVER-MAIL expn root (more info ...)attempted-recon   10249 
661SERVER-MAIL Majordomo ifs (more info ...)attempted-admin 1999-0207 2310  
672SERVER-MAIL vrfy decode (more info ...)attempted-recon 1999-0096   
691INDICATOR-SHELLCODE shellcode attempt (more info ...)shellcode-detect    
692INDICATOR-SHELLCODE shellcode attempt (more info ...)shellcode-detect    
693INDICATOR-SHELLCODE shellcode attempt (more info ...)shellcode-detect    
694INDICATOR-SHELLCODE shellcode attempt (more info ...)attempted-user    
709PROTOCOL-TELNET 4Dgifts SGI account attempt (more info ...)suspicious-login 1999-0501  11243 
710PROTOCOL-TELNET EZsetup account attempt (more info ...)suspicious-login 1999-0501  11244 
711PROTOCOL-TELNET SGI telnetd format bug (more info ...)attempted-admin 2000-0733 1572  
712PROTOCOL-TELNET ld_library_path (more info ...)attempted-admin 1999-0073 459  
713PROTOCOL-TELNET livingston DOS (more info ...)attempted-dos 1999-0218 2225  
714PROTOCOL-TELNET resolv_host_conf (more info ...)attempted-admin 2001-0170 2181  
715PROTOCOL-TELNET Attempted SU from wrong group (more info ...)attempted-admin    
717PROTOCOL-TELNET not on console (more info ...)bad-unknown    
718PROTOCOL-TELNET login incorrect (more info ...)bad-unknown    
719PROTOCOL-TELNET root login (more info ...)suspicious-login    
804SERVER-WEBAPP SWSoft ASPSeek Overflow attempt (more info ...)web-application-attack 2001-0476 2492  
805SERVER-WEBAPP Progress webspeed access (more info ...)attempted-user 2000-0127 969 10304 
806SERVER-WEBAPP yabb directory traversal attempt (more info ...)attempted-recon 2000-0853 1668 10512 
807SERVER-WEBAPP /wwwboard/passwd.txt access (more info ...)attempted-recon 1999-0954 649 10321 
808SERVER-WEBAPP webdriver access (more info ...)attempted-recon  2166 10592 
811SERVER-WEBAPP websitepro path access (more info ...)attempted-recon 2000-0066 932 10303 
812SERVER-WEBAPP webplus version access (more info ...)attempted-recon 2000-0282 1102  
813SERVER-WEBAPP webplus directory traversal (more info ...)web-application-attack 2000-0282 1102 10367 
820SERVER-WEBAPP anaconda directory traversal attempt (more info ...)web-application-attack 2001-0308 2388 10536 
821SERVER-WEBAPP imagemap.exe overflow attempt (more info ...)web-application-attack 1999-0951 739 10122 
825SERVER-WEBAPP glimpse access (more info ...)attempted-recon 1999-0147 2026 10095 
826SERVER-WEBAPP htmlscript access (more info ...)attempted-recon 1999-0264 2001 10106 
827SERVER-WEBAPP info2www access (more info ...)attempted-recon 1999-0266 1995 10127 
828SERVER-WEBAPP maillist.pl access (more info ...)attempted-recon    
833SERVER-WEBAPP rguest.exe access (more info ...)attempted-recon 1999-0287 2024  
834SERVER-WEBAPP rwwwshell.pl access (more info ...)attempted-recon    URL
836SERVER-WEBAPP textcounter.pl access (more info ...)attempted-recon 1999-1479 2265 11451 
837SERVER-WEBAPP uploader.exe access (more info ...)attempted-recon 2000-0769 1611 10291 
838SERVER-WEBAPP webgais access (more info ...)attempted-recon 1999-0176 2058 10300 
839SERVER-WEBAPP finger access (more info ...)attempted-recon 1999-0612  10071 
842SERVER-WEBAPP aglimpse access (more info ...)attempted-recon 1999-0147 2026 10095 
843SERVER-WEBAPP anform2 access (more info ...)attempted-recon 1999-0066 719  
844SERVER-WEBAPP args.bat access (more info ...)attempted-recon 1999-1180  11465 
847SERVER-WEBAPP campas access (more info ...)attempted-recon 1999-0146 1975 10035 
848SERVER-WEBAPP view-source directory traversal (more info ...)web-application-attack 1999-0174 8883  
849SERVER-WEBAPP view-source access (more info ...)attempted-recon 1999-0174 8883  
850SERVER-WEBAPP wais.pl access (more info ...)attempted-recon    
851SERVER-WEBAPP files.pl access (more info ...)attempted-recon 1999-1081   
852SERVER-WEBAPP wguest.exe access (more info ...)attempted-recon 1999-0467 2024  
857SERVER-WEBAPP faxsurvey access (more info ...)web-application-activity 1999-0262 2056 10067 
858SERVER-WEBAPP filemail access (more info ...)attempted-recon 1999-1154   
859SERVER-WEBAPP man.sh access (more info ...)attempted-recon 1999-1179 2276  
860SERVER-WEBAPP snork.bat access (more info ...)attempted-recon 1999-0233 2023  
866SERVER-WEBAPP post-query access (more info ...)attempted-recon 2001-0291 6752  
867SERVER-WEBAPP visadmin.exe access (more info ...)attempted-recon 1999-0970 1808 10295 
869SERVER-WEBAPP dumpenv.pl access (more info ...)attempted-recon 1999-1178  10060 
870SERVER-WEBAPP snorkerz.cmd access (more info ...)attempted-recon    
875SERVER-WEBAPP win-c-sample.exe access (more info ...)attempted-recon 1999-0178 2078 10008 
878SERVER-WEBAPP w3tvars.pm access (more info ...)attempted-recon    
879SERVER-WEBAPP admin.pl access (more info ...)attempted-recon 2002-1748 3839  URL
880SERVER-WEBAPP LWGate access (more info ...)attempted-recon    URL
881SERVER-WEBAPP archie access (more info ...)attempted-recon    
883SERVER-WEBAPP flexform access (more info ...)attempted-recon    URL
888SERVER-WEBAPP wwwadmin.pl access (more info ...)attempted-recon    
892SERVER-WEBAPP AnyForm2 access (more info ...)attempted-recon 1999-0066 719 10277 
894SERVER-WEBAPP bb-hist.sh access (more info ...)attempted-recon 1999-1462 142 10025 
896SERVER-WEBAPP way-board access (more info ...)web-application-activity 2001-0214 2370 10610 
899SERVER-WEBAPP Amaya templates sendtemp.pl directory traversal attempt (more info ...)web-application-attack 2001-0272 2504 10614 
902SERVER-WEBAPP tstisapi.dll access (more info ...)attempted-recon 2001-0302 2381  
976SERVER-WEBAPP .bat? access (more info ...)web-application-activity 2019-0232 4335  URL
989MALWARE-CNC sensepost.exe command shell (more info ...)web-application-activity   11003 
1001SERVER-WEBAPP carbo.dll access (more info ...)attempted-recon 1999-1069 2126  
1047SERVER-WEBAPP Netscape Enterprise DOS (more info ...)web-application-attack 2001-0251 2294  
1048SERVER-WEBAPP Netscape Enterprise directory listing attempt (more info ...)web-application-attack 2001-0250 2285 10691 
1050SERVER-WEBAPP iPlanet GETPROPERTIES attempt (more info ...)web-application-attack 2001-0746 2732  
1062SERVER-WEBAPP nc.exe attempt (more info ...)web-application-activity    
1064SERVER-WEBAPP wsh attempt (more info ...)web-application-activity    
1065SERVER-WEBAPP rcmd attempt (more info ...)web-application-activity    
1066SERVER-WEBAPP telnet attempt (more info ...)web-application-activity    
1067SERVER-WEBAPP net attempt (more info ...)web-application-activity    
1073SERVER-WEBAPP webhits.exe access (more info ...)web-application-activity 2000-0097 950  
1080SERVER-WEBAPP unify eWave ServletExec upload (more info ...)web-application-attack 2000-1025 1876 10570 
1081SERVER-WEBAPP Netscape Servers suite DOS (more info ...)web-application-attack 2000-1025 1868  
1082SERVER-WEBAPP amazon 1-click cookie theft (more info ...)web-application-attack 2000-0439 1194  
1083SERVER-WEBAPP unify eWave ServletExec DOS (more info ...)web-application-activity 2000-1025 1868  
1084SERVER-WEBAPP Allaire JRUN DOS attempt (more info ...)web-application-attack 2000-1049 2337  
1085SERVER-WEBAPP strings overflow (more info ...)web-application-attack  802  
1086SERVER-WEBAPP strings overflow (more info ...)web-application-attack 2000-0967 1786  
1088SERVER-WEBAPP eXtropia webstore directory traversal (more info ...)web-application-attack 2000-1005 1774 10532 
1089SERVER-WEBAPP shopping cart directory traversal (more info ...)web-application-attack 2000-0921 1777  
1090SERVER-WEBAPP Allaire Pro Web Shell attempt (more info ...)web-application-attack    URL
1091SERVER-WEBAPP ICQ Webfront HTTP DOS (more info ...)web-application-attack 2000-1078 1463  
1092SERVER-WEBAPP Armada Style Master Index directory traversal (more info ...)web-application-attack 2000-0924 1772 10562 URL
1095SERVER-WEBAPP Talentsoft Web+ Source Code view access (more info ...)web-application-attack  1722  URL
1096SERVER-WEBAPP Talentsoft Web+ internal IP Address access (more info ...)web-application-activity  1720  URL
1097SERVER-WEBAPP Talentsoft Web+ exploit attempt (more info ...)web-application-attack  1725  
1099SERVER-WEBAPP cybercop scan (more info ...)web-application-activity    
1100INDICATOR-SCAN L3retriever HTTP Probe (more info ...)web-application-activity    URL
1101INDICATOR-SCAN Webtrends HTTP probe (more info ...)web-application-activity    URL
1102SERVER-WEBAPP nessus 1.X 404 probe (more info ...)web-application-attack    
1103SERVER-WEBAPP Netscape admin passwd (more info ...)web-application-attack  1579 10468 
1105SERVER-WEBAPP BigBrother access (more info ...)attempted-recon 2000-0638 1455 10460 
1106SERVER-WEBAPP Poll-it access (more info ...)web-application-activity 2000-0590 1431 10459 
1109SERVER-WEBAPP ROXEN directory list attempt (more info ...)attempted-recon 2000-0671 1510 10479 
1116SERVER-WEBAPP Lotus DelDoc attempt (more info ...)attempted-recon    
1118SERVER-WEBAPP ls 20-l (more info ...)attempted-recon    
1119SERVER-WEBAPP mlog.phtml access (more info ...)attempted-recon 1999-0346 713  
1120SERVER-WEBAPP mylog.phtml access (more info ...)attempted-recon 1999-0346 713  
1123SERVER-WEBAPP ?PageServices access (more info ...)attempted-recon 1999-0269 7621  
1124SERVER-WEBAPP Ecommerce check.txt access (more info ...)attempted-recon    
1125SERVER-WEBAPP webcart access (more info ...)attempted-recon 1999-0610  10298 
1126SERVER-WEBAPP AuthChangeUrl access (more info ...)attempted-recon 1999-0407 2110  
1127SERVER-WEBAPP convert.bas access (more info ...)attempted-recon 1999-0175 2025  
1128SERVER-WEBAPP cpshost.dll access (more info ...)attempted-recon 1999-0360 4002  
1133INDICATOR-SCAN cybercop os probe (more info ...)attempted-recon    URL
1134SERVER-WEBAPP Phorum admin access (more info ...)attempted-recon 2000-1228 2271  
1136SERVER-WEBAPP cd.. (more info ...)attempted-recon    
1137SERVER-WEBAPP Phorum authentication access (more info ...)attempted-recon 2000-1230 2274  
1139SERVER-WEBAPP whisker HEAD/./ (more info ...)attempted-recon    URL
1140SERVER-WEBAPP guestbook.pl access (more info ...)attempted-recon 1999-1053 776 10099 
1146SERVER-WEBAPP Ecommerce import.txt access (more info ...)attempted-recon    
1147SERVER-WEBAPP cat_ access (more info ...)attempted-recon 1999-0039 374  
1148SERVER-WEBAPP Ecommerce import.txt access (more info ...)attempted-recon    
1155SERVER-WEBAPP Ecommerce checks.txt access (more info ...)attempted-recon  2281  
1157SERVER-WEBAPP Netscape PublishingXpert access (more info ...)web-application-activity 2000-1196  10364 
1158SERVER-WEBAPP windmail.exe access (more info ...)attempted-recon 2000-0242 1073 10365 
1159SERVER-WEBAPP webplus access (more info ...)attempted-recon 2000-1005 1725  
1162SERVER-WEBAPP cart 32 AdminPwd access (more info ...)attempted-recon 2000-0429 1153  
1164SERVER-WEBAPP shopping cart access (more info ...)attempted-recon 2000-1188 2049  
1167SERVER-WEBAPP rpm_query access (more info ...)attempted-recon 2000-0192 1036 10340 
1168SERVER-WEBAPP mall log order access (more info ...)attempted-recon 1999-0606 2266  
1173SERVER-WEBAPP architext_query.pl access (more info ...)attempted-recon 1999-0279 2248 10064 URL
1175SERVER-WEBAPP wwwboard.pl access (more info ...)attempted-recon 1999-0954 649  
1178SERVER-WEBAPP Phorum read access (more info ...)attempted-recon    
1179SERVER-WEBAPP Phorum violation access (more info ...)attempted-recon 2000-1234 2272  
1180SERVER-WEBAPP get32.exe access (more info ...)attempted-recon 1999-0885 770 10011 
1181SERVER-WEBAPP Annex Terminal DOS attempt (more info ...)attempted-dos 1999-1070  10017 
1185SERVER-WEBAPP bizdbsearch attempt (more info ...)web-application-attack 2000-0287 1104 10383 
1187SERVER-WEBAPP SalesLogix Eviewer web command attempt (more info ...)web-application-attack 2000-0289 1089 10361 
1193SERVER-WEBAPP oracle web arbitrary command execution attempt (more info ...)web-application-attack 2000-0169 1053 10348 
1196SERVER-WEBAPP SGI InfoSearch fname attempt (more info ...)web-application-attack 2000-0207 1031 10128 
1197SERVER-WEBAPP Phorum code access (more info ...)attempted-recon    
1199SERVER-WEBAPP Compaq Insight directory traversal (more info ...)web-application-attack 1999-0771 282  
1202SERVER-WEBAPP search.vts access (more info ...)attempted-recon  162  
1207SERVER-WEBAPP htgrep access (more info ...)web-application-activity 2000-0832  10495 
1212SERVER-WEBAPP Admin_files access (more info ...)attempted-recon    
1215SERVER-WEBAPP ministats admin access (more info ...)web-application-activity    
1216SERVER-WEBAPP filemail access (more info ...)attempted-recon 1999-1155   URL
1217SERVER-WEBAPP plusmail access (more info ...)attempted-recon 2000-0074 2653 10181 
1220SERVER-WEBAPP ultraboard access (more info ...)attempted-recon 2000-0426 1175 11748 
1224SERVER-WEBAPP ROADS search.pl attempt (more info ...)attempted-recon 2001-0215 2371 10627 
1231SERVER-WEBAPP VirusWall catinfo access (more info ...)attempted-recon 2001-0432 2808 10650 
1239OS-WINDOWS RFParalyze Attempt (more info ...)attempted-recon 2000-0347 1163 10392 
1240SERVER-OTHER MDBMS overflow (more info ...)attempted-admin 2000-0446 1252 10422 
1241SERVER-WEBAPP SWEditServlet directory traversal attempt (more info ...)attempted-user 2001-0555 2868  
1252PROTOCOL-TELNET bsd telnet exploit response (more info ...)attempted-admin 2001-0554 3064 10709 
1253PROTOCOL-TELNET bsd exploit client finishing (more info ...)successful-admin 2001-0554 3064 10709 
1257SERVER-OTHER Winnuke attack (more info ...)attempted-dos 1999-0153 2010  
1259SERVER-WEBAPP SWEditServlet access (more info ...)attempted-recon  2868  
1284SERVER-OTHER readme.eml download attempt (more info ...)attempted-user    URL
1290FILE-OTHER readme.eml autoload attempt (more info ...)attempted-user    URL
1291SERVER-WEBAPP sml3com access (more info ...)web-application-activity 2001-0740 2721  
1295INDICATOR-COMPROMISE nimda RICHED20.DLL (more info ...)bad-unknown    URL
1302SERVER-WEBAPP console.exe access (more info ...)attempted-recon 2001-1252 3375  
1303SERVER-WEBAPP cs.exe access (more info ...)attempted-recon 2001-1252 3375  
1323SERVER-OTHER rwhoisd format string attempt (more info ...)misc-attack 2001-0838 3474 10790 
1375SERVER-WEBAPP sadmind worm access (more info ...)attempted-recon    URL
1376SERVER-WEBAPP jrun directory browse attempt (more info ...)web-application-attack 2001-1510 3592  
1382SERVER-OTHER CHAT IRC Ettercap parse overflow attempt (more info ...)misc-attack    URL
1397SERVER-WEBAPP wayboard attempt (more info ...)web-application-attack 2001-0214 2370 10610 
1398SERVER-OTHER CDE dtspcd exploit attempt (more info ...)misc-attack 2001-0803 3517 10833 URL
1423SERVER-WEBAPP content-disposition memchr overflow (more info ...)web-application-attack 2002-0081 4183 10867 
1426PROTOCOL-SNMP PROTOS test-suite-req-app attempt (more info ...)misc-attack    URL
1432PUA-P2P GNUTella client request (more info ...)policy-violation    
1433SERVER-WEBAPP .history access (more info ...)web-application-attack    
1434SERVER-WEBAPP .bash_history access (more info ...)web-application-attack 1999-0408 337  URL
1450SERVER-MAIL Vintra Mailserver expn *@ (more info ...)misc-attack 1999-1200   
1451SERVER-WEBAPP NPH-maillist access (more info ...)attempted-recon 2001-0400 2563 10164 
1452SERVER-WEBAPP args.cmd access (more info ...)attempted-recon 1999-1180  11465 
1454SERVER-WEBAPP wwwwais access (more info ...)attempted-recon 2001-0223  10597 
1455SERVER-WEBAPP calendar.pl access (more info ...)attempted-recon 2000-0432 1215  
1456SERVER-WEBAPP calender_admin.pl access (more info ...)attempted-recon 2000-0432  10506 
1457SERVER-WEBAPP user_update_admin.pl access (more info ...)attempted-recon 2000-0627 1486  
1458SERVER-WEBAPP user_update_passwd.pl access (more info ...)attempted-recon 2000-0627 1486  
1459SERVER-WEBAPP bb-histlog.sh access (more info ...)attempted-recon 1999-1462 142 10025 
1460SERVER-WEBAPP bb-histsvc.sh access (more info ...)attempted-recon 1999-1462 142  
1461SERVER-WEBAPP bb-rep.sh access (more info ...)attempted-recon 1999-1462 142  
1462SERVER-WEBAPP bb-replog.sh access (more info ...)attempted-recon 1999-1462 142  
1464INDICATOR-COMPROMISE oracle one hour install (more info ...)bad-unknown   10737 
1470SERVER-WEBAPP listrec.pl access (more info ...)attempted-recon 2001-0997 3328 10769 
1474SERVER-WEBAPP cal_make.pl access (more info ...)web-application-activity 2001-0463 2663 10664 
1475SERVER-WEBAPP mailit.pl access (more info ...)attempted-recon   10417 
1478SERVER-WEBAPP Simple Web Counter URI Parameter Buffer Overflow attempt (more info ...)attempted-user  6581 10493 
1482SERVER-WEBAPP view_source access (more info ...)attempted-recon 1999-0174 2251 10294 
1483SERVER-WEBAPP ustorekeeper.pl access (more info ...)web-application-activity 2001-0466  10645 
1492SERVER-WEBAPP RBS ISP /newuser directory traversal attempt (more info ...)web-application-attack 2000-1036 1704 10521 
1493SERVER-WEBAPP RBS ISP /newuser access (more info ...)web-application-activity 2000-1036 1704 10521 
1500SERVER-WEBAPP ExAir access (more info ...)web-application-activity 1999-0449 193 10004 
1503SERVER-WEBAPP admentor admin.asp access (more info ...)web-application-activity 2002-0308 4152 10880 URL
1504POLICY-OTHER AFS access (more info ...)misc-activity   10441 
1507SERVER-WEBAPP alibaba.pl arbitrary command execution attempt (more info ...)web-application-attack 1999-0885 770 10013 
1508SERVER-WEBAPP alibaba.pl access (more info ...)web-application-activity 1999-0885 770 10013 
1509SERVER-WEBAPP AltaVista Intranet Search directory traversal attempt (more info ...)web-application-attack 2000-0039 896 10015 
1510SERVER-WEBAPP test.bat arbitrary command execution attempt (more info ...)web-application-attack 1999-0947 762 10016 
1511SERVER-WEBAPP test.bat access (more info ...)web-application-activity 1999-0947 762 10016 
1512SERVER-WEBAPP input.bat arbitrary command execution attempt (more info ...)web-application-attack 1999-0947 762 10016 
1513SERVER-WEBAPP input.bat access (more info ...)web-application-activity 1999-0947 762 10016 
1514SERVER-WEBAPP input2.bat arbitrary command execution attempt (more info ...)web-application-attack 1999-0947 762 10016 
1515SERVER-WEBAPP input2.bat access (more info ...)web-application-activity 1999-0947 762 10016 
1516SERVER-WEBAPP envout.bat arbitrary command execution attempt (more info ...)web-application-attack 1999-0947 762 10016 
1517SERVER-WEBAPP envout.bat access (more info ...)web-application-activity 1999-0947 762 10016 
1522SERVER-WEBAPP ans.pl attempt (more info ...)web-application-attack 2002-0307 4149 10875 
1523SERVER-WEBAPP ans.pl access (more info ...)web-application-activity 2002-0307 4149 10875 
1524SERVER-WEBAPP Axis Storpoint CD attempt (more info ...)web-application-attack 2000-0191 1025 10023 
1525SERVER-WEBAPP Axis Storpoint CD access (more info ...)web-application-activity 2000-0191 1025 10023 
1528SERVER-WEBAPP BBoard access (more info ...)web-application-activity 2000-0629 1459 10507 
1531SERVER-WEBAPP bb-hist.sh attempt (more info ...)web-application-attack 1999-1462 142 10025 
1532SERVER-WEBAPP bb-hostscv.sh attempt (more info ...)web-application-attack 2000-0638 1455 10460 
1533SERVER-WEBAPP bb-hostscv.sh access (more info ...)web-application-activity 2000-0638 1455 10460 
1535SERVER-WEBAPP bizdbsearch access (more info ...)web-application-activity 2000-0287 1104 10383 
1536SERVER-WEBAPP calendar_admin.pl arbitrary command execution attempt (more info ...)web-application-attack 2000-0432 1215 10506 
1537SERVER-WEBAPP calendar_admin.pl access (more info ...)web-application-activity 2000-0432 1215 10506 
1538PROTOCOL-NNTP AUTHINFO USER overflow attempt (more info ...)attempted-admin 2000-0341 1156 10388 
1541PROTOCOL-FINGER version query (more info ...)attempted-recon    
1549SERVER-MAIL HELO overflow attempt (more info ...)attempted-admin 2000-0042 895 11674 
1550SERVER-MAIL ETRN overflow attempt (more info ...)attempted-admin 2000-0490 7515 10438 
1555SERVER-WEBAPP DCShop access (more info ...)web-application-activity 2001-0821 2889  
1556SERVER-WEBAPP DCShop orders.txt access (more info ...)web-application-activity 2001-0821 2889  
1557SERVER-WEBAPP DCShop auth_user_file.txt access (more info ...)web-application-activity 2001-0821 2889  
1559SERVER-WEBAPP /doc/packages access (more info ...)web-application-activity 2000-1016 1707 11032 
1560SERVER-WEBAPP /doc/ access (more info ...)web-application-activity 1999-0678 318  
1563SERVER-WEBAPP login.htm attempt (more info ...)web-application-activity 1999-1533 665  
1565SERVER-WEBAPP eshop.pl arbitrary command execution attempt (more info ...)web-application-attack 2001-1014 3340  
1566SERVER-WEBAPP eshop.pl access (more info ...)web-application-activity 2001-1014 3340  
1588SERVER-WEBAPP SalesLogix Eviewer access (more info ...)web-application-activity 2000-0289 1089  
1589SERVER-WEBAPP musicat empower attempt (more info ...)web-application-attack 2001-0224 2374 10609 
1600SERVER-WEBAPP htsearch arbitrary configuration file attempt (more info ...)web-application-attack 2001-0834 3410  
1601SERVER-WEBAPP htsearch arbitrary file read attempt (more info ...)web-application-attack 2000-0208 1026 10105 
1602SERVER-WEBAPP htsearch access (more info ...)web-application-activity 2000-0208 1026 10105 
1605SERVER-OTHER iParty DOS attempt (more info ...)misc-attack 1999-1566 6844 10111 
1606SERVER-WEBAPP icat access (more info ...)web-application-activity 1999-1069   
1608SERVER-WEBAPP htmlscript attempt (more info ...)web-application-attack 1999-0264 2001 10106 
1611SERVER-WEBAPP eXtropia webstore access (more info ...)web-application-activity 2000-1005 1774 10532 
1613SERVER-WEBAPP handler attempt (more info ...)web-application-attack 1999-0148 380 10100 
1615SERVER-WEBAPP htgrep attempt (more info ...)web-application-attack 2000-0832  10495 
1635PROTOCOL-POP APOP overflow attempt (more info ...)attempted-admin 2000-0841 1652 10559 
1636SERVER-OTHER Xtramail Username overflow attempt (more info ...)attempted-admin 1999-1511 791 10323 
1637SERVER-WEBAPP yabb access (more info ...)attempted-recon 2000-0853 1668 10512 
1641SERVER-OTHER DB2 dos attempt (more info ...)denial-of-service 2001-1143 3010 10871 
1642SERVER-WEBAPP document.d2w access (more info ...)web-application-activity 2000-1110 2017  
1643SERVER-WEBAPP db2www access (more info ...)web-application-activity 2000-0677   
1650SERVER-WEBAPP tst.bat access (more info ...)web-application-activity 1999-0885 770 10014 
1651SERVER-WEBAPP environ.pl access (more info ...)web-application-activity    
1652SERVER-WEBAPP campas attempt (more info ...)web-application-attack 1999-0146 1975 10035 
1654SERVER-WEBAPP cart32.exe access (more info ...)web-application-activity  1153 10389 
1663SERVER-WEBAPP *%20.pl access (more info ...)web-application-attack   11007 URL
1664SERVER-WEBAPP mkplog.exe access (more info ...)web-application-activity    
1671SERVER-WEBAPP /home/www access (more info ...)web-application-activity   11032 
1673SERVER-ORACLE EXECUTE_SYSTEM attempt (more info ...)system-call-detect    
1674SERVER-ORACLE connect_data remote version detection attempt (more info ...)protocol-command-decode    
1675SERVER-ORACLE misparsed login response (more info ...)suspicious-login    
1676SERVER-ORACLE select union attempt (more info ...)protocol-command-decode    
1677SERVER-ORACLE select like '%' attempt (more info ...)protocol-command-decode    
1678SERVER-ORACLE select like '%' attempt backslash escaped (more info ...)protocol-command-decode    
1679SERVER-ORACLE describe attempt (more info ...)protocol-command-decode    
1680SERVER-ORACLE all_constraints access (more info ...)protocol-command-decode    
1681SERVER-ORACLE all_views access (more info ...)protocol-command-decode    
1682SERVER-ORACLE all_source access (more info ...)protocol-command-decode    
1683SERVER-ORACLE all_tables access (more info ...)protocol-command-decode    
1684SERVER-ORACLE all_tab_columns access (more info ...)protocol-command-decode    
1685SERVER-ORACLE all_tab_privs access (more info ...)protocol-command-decode    
1686SERVER-ORACLE dba_tablespace access (more info ...)protocol-command-decode    
1688SERVER-ORACLE user_tablespace access (more info ...)protocol-command-decode    
1689SERVER-ORACLE sys.all_users access (more info ...)protocol-command-decode    
1691SERVER-ORACLE ALTER USER attempt (more info ...)protocol-command-decode    
1692SERVER-ORACLE drop table attempt (more info ...)protocol-command-decode    
1693SERVER-ORACLE create table attempt (more info ...)protocol-command-decode    
1694SERVER-ORACLE alter table attempt (more info ...)protocol-command-decode    
1695SERVER-ORACLE truncate table attempt (more info ...)protocol-command-decode    
1696SERVER-ORACLE create database attempt (more info ...)protocol-command-decode    
1697SERVER-ORACLE alter database attempt (more info ...)protocol-command-decode    
1700SERVER-WEBAPP imagemap.exe access (more info ...)web-application-activity 1999-0951 739 10122 
1701SERVER-WEBAPP calendar-admin.pl access (more info ...)web-application-activity 2000-0432 1215 10506 
1702SERVER-WEBAPP Amaya templates sendtemp.pl access (more info ...)web-application-activity 2001-0272 2504  
1704SERVER-WEBAPP cal_make.pl directory traversal attempt (more info ...)web-application-attack 2001-0463 2663 10664 
1705SERVER-WEBAPP echo.bat arbitrary command execution attempt (more info ...)web-application-attack 2000-0213 1002 10246 
1706SERVER-WEBAPP echo.bat access (more info ...)web-application-activity 2000-0213 1002 10246 
1707SERVER-WEBAPP hello.bat arbitrary command execution attempt (more info ...)web-application-attack 2000-0213 1002 10246 
1708SERVER-WEBAPP hello.bat access (more info ...)web-application-activity 2000-0213 1002 10246 
1714SERVER-WEBAPP newdesk access (more info ...)web-application-activity    
1722SERVER-WEBAPP MachineInfo access (more info ...)web-application-activity 1999-1067   
1727SERVER-WEBAPP SGI InfoSearch fname access (more info ...)web-application-activity 2000-0207 1031  
1730SERVER-WEBAPP ustorekeeper.pl directory traversal attempt (more info ...)web-application-attack 2001-0466 2536 10645 
1731SERVER-WEBAPP a1stats access (more info ...)web-application-activity 2001-0561 2705 10669 
1736SERVER-WEBAPP squirrel mail spell-check arbitrary command attempt (more info ...)web-application-attack  3952  
1737SERVER-WEBAPP squirrel mail theme arbitrary command attempt (more info ...)web-application-attack 2002-0516 4385  
1738SERVER-WEBAPP global.inc access (more info ...)web-application-attack 2002-0614 4612  
1744SERVER-WEBAPP SecureSite authentication bypass attempt (more info ...)web-application-attack  4621  
1751SERVER-OTHER cachefsd buffer overflow attempt (more info ...)misc-attack 2002-0084 4631 10951 
1757SERVER-WEBAPP b2 arbitrary command execution attempt (more info ...)web-application-attack 2002-1466 4673 11667 
1766SERVER-WEBAPP search.dll directory listing attempt (more info ...)web-application-attack 2000-0835 1684 10514 
1767SERVER-WEBAPP search.dll access (more info ...)web-application-activity 2000-0835 1684 10514 
1769SERVER-WEBAPP .DS_Store access (more info ...)web-application-activity    URL
1770SERVER-WEBAPP .FBCIndex access (more info ...)web-application-activity    URL
1771POLICY-OTHER IPSec PGPNet connection attempt (more info ...)protocol-command-decode    
1792PROTOCOL-NNTP return code buffer overflow attempt (more info ...)protocol-command-decode 2002-0909 4900  
1819SERVER-OTHER Alcatel PABX 4400 connection attempt (more info ...)misc-activity   11019 
1820SERVER-WEBAPP IBM Net.Commerce orderdspc.d2w access (more info ...)web-application-activity 2001-0319 2350 11020 
1821SERVER-OTHER LPD dvips remote command execution attempt (more info ...)system-call-detect 2001-1002 3241 11023 
1828SERVER-WEBAPP iPlanet Search directory traversal attempt (more info ...)web-application-attack 2002-1042 5191 11043 
1831SERVER-WEBAPP jigsaw dos attempt (more info ...)web-application-attack 2002-1052 5258 11047 
1832POLICY-SOCIAL ICQ forced user addition (more info ...)policy-violation 2001-1305 3226  
1835SERVER-WEBAPP Macromedia SiteSpring cross site scripting attempt (more info ...)web-application-attack 2002-1027 5249  
1839SERVER-WEBAPP mailman cross site scripting attempt (more info ...)web-application-attack 2002-0855 5298 14984 
1843MALWARE-BACKDOOR trinity connection attempt (more info ...)attempted-admin 2000-0138  10501 
1847SERVER-WEBAPP webalizer access (more info ...)web-application-activity 2001-0835 3473 10816 
1848SERVER-WEBAPP webcart-lite access (more info ...)web-application-activity 1999-0610  10298 
1849SERVER-WEBAPP webfind.exe access (more info ...)web-application-activity 2000-0622 1487 10475 
1851SERVER-WEBAPP active.log access (more info ...)web-application-activity 2000-0642 1497 10470 
1853MALWARE-BACKDOOR win-trin00 connection attempt (more info ...)attempted-admin 2000-0138  10307 
1857SERVER-WEBAPP robot.txt access (more info ...)web-application-activity   10302 
1866PROTOCOL-POP USER overflow attempt (more info ...)attempted-admin 2006-4364 789 10311 URL
1868SERVER-WEBAPP Interactive Story story.pl arbitrary file read attempt (more info ...)default-login-attempt 2001-0804 3028 10817 
1869SERVER-WEBAPP Interactive Story story.pl access (more info ...)default-login-attempt 2001-0804 3028 10817 
1877SERVER-WEBAPP printenv access (more info ...)web-application-activity 2000-0868 1658 10503 
1881SERVER-WEBAPP bad HTTP 1.1 request - potential worm attack (more info ...)web-application-activity    URL
1882INDICATOR-COMPROMISE id check returned userid (more info ...)bad-unknown    
1887SERVER-OTHER OpenSSL Worm traffic (more info ...)web-application-attack    URL
1889MALWARE-CNC slapper worm admin traffic (more info ...)trojan-activity    URL
1893PROTOCOL-SNMP missing community string attempt (more info ...)misc-attack 1999-0517 2112  
1894INDICATOR-SHELLCODE kadmind buffer overflow attempt (more info ...)shellcode-detect 2002-1235 6024 15015 URL
1895INDICATOR-SHELLCODE kadmind buffer overflow attempt (more info ...)shellcode-detect 2002-1235 6024  URL
1896INDICATOR-SHELLCODE kadmind buffer overflow attempt (more info ...)shellcode-detect 2002-1235 6024  URL
1897INDICATOR-SHELLCODE kadmind buffer overflow attempt (more info ...)shellcode-detect 2002-1235 6024  URL
1898INDICATOR-SHELLCODE kadmind buffer overflow attempt (more info ...)shellcode-detect 2002-1235 6024  URL
1899INDICATOR-SHELLCODE kadmind buffer overflow attempt (more info ...)shellcode-detect 2002-1235 6024  URL
1900SERVER-OTHER successful kadmind buffer overflow attempt (more info ...)successful-admin 2002-1235 6024  URL
1901SERVER-OTHER successful kadmind buffer overflow attempt (more info ...)successful-admin 2002-1235 6024  URL
1936PROTOCOL-POP AUTH overflow attempt (more info ...)attempted-admin 1999-0822 830 10184 
1937PROTOCOL-POP LIST overflow attempt (more info ...)attempted-admin 2000-0096 948 10197 
1938PROTOCOL-POP XTND overflow attempt (more info ...)attempted-admin    
1943SERVER-WEBAPP /Carello/add.exe access (more info ...)web-application-activity 2000-0396 1245 11776 
1944SERVER-WEBAPP /ecscripts/ecware.exe access (more info ...)web-application-activity  6066  
1969SERVER-WEBAPP ion-p access (more info ...)web-application-activity 2002-1559 6091 11729 
1977SERVER-WEBAPP xp_regwrite attempt (more info ...)web-application-activity    
1978SERVER-WEBAPP xp_regdeletekey attempt (more info ...)web-application-activity    
1979SERVER-WEBAPP perl post attempt (more info ...)web-application-attack 2002-1436 5520 11158 
1981MALWARE-BACKDOOR DeepThroat 3.1 Connection attempt on port 3150 (more info ...)trojan-activity   10053 
1982MALWARE-BACKDOOR DeepThroat 3.1 Server Response on port 3150 (more info ...)trojan-activity   10053 
1983MALWARE-BACKDOOR DeepThroat 3.1 Connection attempt on port 4120 (more info ...)trojan-activity   10053 
1984MALWARE-BACKDOOR DeepThroat 3.1 Server Response on port 4120 (more info ...)trojan-activity   10053 
1985MALWARE-BACKDOOR Doly variant outbound connection attempt (more info ...)trojan-activity    URL
1987SERVER-OTHER xfs overflow attempt (more info ...)misc-activity 2002-1317 6241 11188 
2039SERVER-OTHER bootp hostname format string attempt (more info ...)misc-attack 2002-0702 4701 11312 
2044POLICY-OTHER PPTP Start Control Request attempt (more info ...)attempted-admin    
2047SERVER-OTHER rsyncd module list access (more info ...)misc-activity    
2056SERVER-WEBAPP TRACE attempt (more info ...)web-application-attack 2010-0360 9561 11213 
2057SERVER-WEBAPP helpout.exe access (more info ...)web-application-activity 2002-1169 6002 11162 
2058SERVER-WEBAPP MsmMask.exe attempt (more info ...)web-application-attack   11163 
2059SERVER-WEBAPP MsmMask.exe access (more info ...)web-application-activity   11163 
2060SERVER-WEBAPP DB4Web access (more info ...)web-application-activity   11180 
2062SERVER-WEBAPP iPlanet .perf access (more info ...)web-application-activity   11220 
2065SERVER-WEBAPP Lotus Notes .csp script source download attempt (more info ...)web-application-attack    
2066SERVER-WEBAPP Lotus Notes .pl script source download attempt (more info ...)web-application-attack 2003-1408 6841  
2068SERVER-WEBAPP BitKeeper arbitrary command attempt (more info ...)web-application-attack  6588  
2069SERVER-WEBAPP chip.ini access (more info ...)web-application-activity 2001-0771 2775  
2070SERVER-WEBAPP post32.exe arbitrary command attempt (more info ...)web-application-attack  1485  
2071SERVER-WEBAPP post32.exe access (more info ...)web-application-activity  1485  
2072SERVER-WEBAPP lyris.pl access (more info ...)web-application-activity 2000-0758 1584  
2073SERVER-WEBAPP globals.pl access (more info ...)web-application-activity 2001-0330 2671  
2087SERVER-MAIL From comment overflow attempt (more info ...)attempted-admin 2002-1337 6991  URL
2100MALWARE-BACKDOOR SubSeven 2.1 Gold server connection response (more info ...)trojan-activity   10409 
2104INDICATOR-COMPROMISE rexec username too long response (more info ...)unsuccessful-user 2003-1097 7459  
2108PROTOCOL-POP CAPA overflow attempt (more info ...)attempted-admin    
2109PROTOCOL-POP TOP overflow attempt (more info ...)attempted-admin    
2110PROTOCOL-POP STAT overflow attempt (more info ...)attempted-admin    
2111PROTOCOL-POP DELE overflow attempt (more info ...)attempted-admin    
2112PROTOCOL-POP RSET overflow attempt (more info ...)attempted-admin    
2113PROTOCOL-SERVICES rexec username overflow attempt (more info ...)attempted-admin    
2115SERVER-WEBAPP album.pl access (more info ...)web-application-activity 2003-1456 7444 11581 
2121PROTOCOL-POP DELE negative argument attempt (more info ...)misc-attack 2002-1539 7445 11570 
2122PROTOCOL-POP UIDL negative argument attempt (more info ...)misc-attack 2002-1539 6053 11570 
2124MALWARE-BACKDOOR Remote PC Access connection (more info ...)trojan-activity   11673 
2135SERVER-WEBAPP philboard.mdb access (more info ...)web-application-activity   11682 
2136SERVER-WEBAPP philboard_admin.asp authentication bypass attempt (more info ...)web-application-attack  7739 11675 
2137SERVER-WEBAPP philboard_admin.asp access (more info ...)web-application-activity  7739 11675 
2138SERVER-WEBAPP logicworks.ini access (more info ...)web-application-activity 2003-1383 6996 11639 
2139SERVER-WEBAPP /*.shtml access (more info ...)web-application-activity 2000-0683 1517 11604 
2155SERVER-WEBAPP ttforum remote file include attempt (more info ...)web-application-attack 2003-1459 7543 11615 
2156SERVER-WEBAPP mod_gzip_status access (more info ...)web-application-activity   11685 
2158SERVER-OTHER BGP invalid length (more info ...)bad-unknown 2002-1350 6213 15043 URL
2159SERVER-OTHER BGP invalid type 0 (more info ...)bad-unknown 2002-1350 6213 15043 
2180PUA-P2P BitTorrent announce request (more info ...)policy-violation    
2181PUA-P2P BitTorrent transfer (more info ...)policy-violation    
2226SERVER-WEBAPP pmachine remote file include attempt (more info ...)web-application-attack  7919 11739 
2231SERVER-WEBAPP register.dll access (more info ...)web-application-activity 2001-0958 3327 11747 
2232SERVER-WEBAPP ContentFilter.dll access (more info ...)web-application-activity 2001-0958 3327 11747 
2233SERVER-WEBAPP SFNofitication.dll access (more info ...)web-application-activity 2001-0958 3327 11747 
2234SERVER-WEBAPP TOP10.dll access (more info ...)web-application-activity 2001-0958 3327 11747 
2235SERVER-WEBAPP SpamExcp.dll access (more info ...)web-application-activity 2001-0958 3327 11747 
2236SERVER-WEBAPP spamrule.dll access (more info ...)web-application-activity 2001-0958 3327 11747 
2238SERVER-WEBAPP WebLogic ConsoleHelp view source attempt (more info ...)web-application-attack 2000-0682 1518 11724 
2239SERVER-WEBAPP redirect.exe access (more info ...)web-application-activity 2000-0401 1256 11723 
2240SERVER-WEBAPP changepw.exe access (more info ...)web-application-activity 2000-0401 1256 11723 
2241SERVER-WEBAPP cwmail.exe access (more info ...)web-application-activity 2002-0273 4093 11727 
2244SERVER-WEBAPP VsSetCookie.exe access (more info ...)web-application-activity 2002-0236 3784 11731 
2245SERVER-WEBAPP Webnews.exe access (more info ...)web-application-activity 2002-0290 4124 11732 
2246SERVER-WEBAPP webadmin.dll access (more info ...)web-application-activity 2003-0471 8024 11771 
2250PROTOCOL-POP USER format string attempt (more info ...)attempted-admin 2003-0391 7667 11742 
2259SERVER-MAIL EXPN overflow attempt (more info ...)attempted-admin 2003-0161 7230  
2260SERVER-MAIL VRFY overflow attempt (more info ...)attempted-admin 2003-0161 7230  
2271MALWARE-BACKDOOR FsSniffer connection attempt (more info ...)trojan-activity   11854 
2274PROTOCOL-POP login brute force attempt (more info ...)suspicious-login    URL
2275SERVER-MAIL AUTH LOGON brute force attempt (more info ...)suspicious-login    URL
2276SERVER-WEBAPP oracle portal demo access (more info ...)web-application-activity   11918 
2284SERVER-WEBAPP rolis guestbook remote file include attempt (more info ...)web-application-attack  9057  
2285SERVER-WEBAPP rolis guestbook access (more info ...)web-application-activity  9057  
2306SERVER-WEBAPP gallery remote file include attempt (more info ...)web-application-attack 2003-1227 8814 11876 
2307SERVER-WEBAPP PayPal Storefront remote file include attempt (more info ...)web-application-attack  8791 11873 
2319SERVER-OTHER ebola PASS overflow attempt (more info ...)attempted-admin  9156  
2320SERVER-OTHER ebola USER overflow attempt (more info ...)attempted-admin  9156  
2327SERVER-WEBAPP bsml.pl access (more info ...)web-application-activity  9311 11973 
2331SERVER-WEBAPP MatrikzGB privilege escalation attempt (more info ...)web-application-activity  8430  
2341SERVER-WEBAPP DCP-Portal remote file include editor script attempt (more info ...)web-application-attack  6525  
2342SERVER-WEBAPP DCP-Portal remote file include lib script attempt (more info ...)web-application-attack  6525  
2369SERVER-WEBAPP ISAPISkeleton.dll access (more info ...)web-application-activity 2004-2128 9516  
2370SERVER-WEBAPP BugPort config.conf file access (more info ...)attempted-recon 2004-2353 9542  
2371SERVER-WEBAPP Sample_showcode.html access (more info ...)web-application-activity 2004-2170 9555  
2375MALWARE-CNC DoomJuice/mydoom.a backdoor upload/execute (more info ...)trojan-activity    URL
2376SERVER-OTHER ISAKMP first payload certificate request length overflow attempt (more info ...)attempted-admin 2004-0040 9582  
2377SERVER-OTHER ISAKMP second payload certificate request length overflow attempt (more info ...)attempted-admin 2004-0040 9582  
2378SERVER-OTHER ISAKMP third payload certificate request length overflow attempt (more info ...)attempted-admin 2004-0040 9582  
2379SERVER-OTHER ISAKMP forth payload certificate request length overflow attempt (more info ...)attempted-admin 2004-0040 9582  
2380SERVER-OTHER ISAKMP fifth payload certificate request length overflow attempt (more info ...)attempted-admin 2004-0040 9582  
2393SERVER-WEBAPP /_admin access (more info ...)web-application-activity 2007-1156 9537 12032 
2394SERVER-WEBAPP Compaq web-based management agent denial of service attempt (more info ...)web-application-attack  8014  
2395SERVER-WEBAPP InteractiveQuery.jsp access (more info ...)web-application-activity 2003-0624 8938  
2400SERVER-WEBAPP edittag.pl access (more info ...)web-application-activity 2003-1351 6675  
2406PROTOCOL-TELNET APC SmartSlot default admin account attempt (more info ...)suspicious-login 2004-0311 9681 12066 URL
2407SERVER-WEBAPP util.pl access (more info ...)web-application-activity 2004-2379 9748  
2409PROTOCOL-POP APOP USER overflow attempt (more info ...)attempted-admin 2004-2375 9794  
2411SERVER-WEBAPP RealNetworks RealSystem Server DESCRIBE buffer overflow attempt (more info ...)web-application-attack 2003-0725 8476 11642 URL
2412INDICATOR-COMPROMISE successful cross site scripting forced download attempt (more info ...)successful-user    
2413SERVER-OTHER ISAKMP delete hash with empty hash attempt (more info ...)misc-attack 2004-0164 9417  
2414SERVER-OTHER ISAKMP initial contact notification without SPI attempt (more info ...)misc-attack 2004-0164 9417  
2415SERVER-OTHER ISAKMP second payload initial contact notification without SPI attempt (more info ...)misc-attack 2004-0164 9417  
2424PROTOCOL-NNTP sendsys overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
2425PROTOCOL-NNTP senduuname overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
2426PROTOCOL-NNTP version overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
2427PROTOCOL-NNTP checkgroups overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
2428PROTOCOL-NNTP ihave overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
2429PROTOCOL-NNTP sendme overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
2430PROTOCOL-NNTP newgroup overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
2431PROTOCOL-NNTP rmgroup overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
2432PROTOCOL-NNTP article post without path attempt (more info ...)attempted-admin    
2441SERVER-WEBAPP NetObserve authentication bypass attempt (more info ...)web-application-attack  9319  
2442SERVER-WEBAPP generic server user-agent buffer overflow attempt (more info ...)web-application-attack 2008-0550 9735  
2447SERVER-WEBAPP ServletManager access (more info ...)web-application-activity 2001-1195 3697 12122 
2448SERVER-WEBAPP setinfo.hts access (more info ...)web-application-activity 2004-1857 9973 12120 
2464SERVER-OTHER Ethereal EIGRP prefix length overflow attempt (more info ...)attempted-admin 2004-0367 9952  
2484SERVER-WEBAPP source.jsp access (more info ...)web-application-activity   12119 
2486SERVER-OTHER ISAKMP invalid identification payload attempt (more info ...)attempted-dos 2004-0184 10004  
2487SERVER-MAIL WinZip MIME content-type buffer overflow (more info ...)attempted-user 2004-0333 9758 12621 
2488SERVER-MAIL WinZip MIME content-disposition buffer overflow (more info ...)attempted-user 2004-0333 9758 12621 
2489SERVER-OTHER esignal STREAMQUOTE buffer overflow attempt (more info ...)attempted-admin 2004-1868 9978  
2490SERVER-OTHER esignal SNAPQUOTE buffer overflow attempt (more info ...)attempted-admin 2004-1868 9978  
2523SERVER-OTHER BGP spoofed connection reset attempt (more info ...)attempted-dos 2004-0230 10183  URL
2545SERVER-OTHER AFP FPLoginExt username buffer overflow attempt (more info ...)attempted-admin 2004-0430 10271  URL
2547SERVER-OTHER HP Web JetAdmin remote file upload attempt (more info ...)web-application-activity 2004-1856 9971  
2549SERVER-OTHER HP Web JetAdmin file write attempt (more info ...)web-application-activity  9973  
2561SERVER-OTHER rsync backup-dir directory traversal attempt (more info ...)string-detect 2004-0426 10247 12230 
2567SERVER-WEBAPP Emumail init.emu access (more info ...)web-application-activity 2004-2385 9861 12095 
2569SERVER-WEBAPP cPanel resetpass access (more info ...)web-application-activity 2004-1769 9848  
2576SERVER-ORACLE dbms_repcat.generate_replication_support buffer overflow attempt (more info ...)attempted-user    URL
2577FILE-OTHER local resource redirection attempt (more info ...)attempted-user 2004-0549   URL
2581SERVER-WEBAPP SAP Crystal Reports crystalimagehandler.aspx access (more info ...)web-application-activity 2004-0204   URL
2582OS-WINDOWS SAP Crystal Reports crystalImageHandler.asp directory traversal attempt (more info ...)web-application-attack 2004-0204 10260 12271 URL
2584SERVER-OTHER eMule buffer overflow attempt (more info ...)attempted-user 2004-1892 10039 12233 
2585SERVER-WEBAPP nessus 2.x 404 probe (more info ...)attempted-recon   10386 
2587PUA-P2P eDonkey server response (more info ...)policy-violation    URL
2588SERVER-WEBAPP TUTOS path disclosure attempt (more info ...)web-application-activity  10129  URL
2599SERVER-ORACLE dbms_repcat.add_grouped_column buffer overflow attempt (more info ...)attempted-user    
2601SERVER-ORACLE dbms_repcat.drop_master_repgroup buffer overflow attempt (more info ...)attempted-user    
2603SERVER-ORACLE dbms_repcat.create_mview_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2605SERVER-ORACLE dbms_repcat.compare_old_values buffer overflow attempt (more info ...)attempted-user    URL
2606SERVER-ORACLE dbms_repcat.comment_on_repobject buffer overflow attempt (more info ...)attempted-user    URL
2608SERVER-ORACLE sysdbms_repcat_rgt.check_ddl_text buffer overflow attempt (more info ...)attempted-user    URL
2609SERVER-ORACLE dbms_repcat.cancel_statistics buffer overflow attempt (more info ...)attempted-user    
2611SERVER-ORACLE LINK metadata buffer overflow attempt (more info ...)attempted-user 2005-0297 7453 11563 URL
2612SERVER-ORACLE sys.dbms_repcat_auth.revoke_surrogate_repcat buffer overflow attempt (more info ...)attempted-user    URL
2614SERVER-ORACLE time_zone buffer overflow attempt (more info ...)attempted-user 2003-1208 9587 12047 URL
2615SERVER-ORACLE sys.dbms_repcat_auth.grant_surrogate_repcat buffer overflow attempt (more info ...)attempted-user    URL
2617SERVER-ORACLE sys.dbms_repcat.alter_mview_propagation buffer overflow attempt (more info ...)attempted-user    URL
2619SERVER-ORACLE dbms_repcat.alter_master_repobject buffer overflow attempt (more info ...)attempted-user    URL
2621SERVER-ORACLE dbms_repcat_sna_utl.register_flavor_change buffer overflow attempt (more info ...)attempted-user    URL
2624SERVER-ORACLE dbms_repcat_admin.unregister_user_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2626SERVER-ORACLE dbms_repcat.send_old_values buffer overflow attempt (more info ...)attempted-user    URL
2627SERVER-ORACLE dbms_repcat.repcat_import_check buffer overflow attempt (more info ...)attempted-user    URL
2629SERVER-ORACLE dbms_repcat_admin.register_user_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2633SERVER-ORACLE sys.dbms_rectifier_diff.rectify buffer overflow attempt (more info ...)attempted-user    URL
2637SERVER-ORACLE dbms_repcat.drop_master_repobject buffer overflow attempt (more info ...)attempted-user    URL
2639SERVER-ORACLE dbms_repcat.drop_mview_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2641SERVER-ORACLE dbms_repcat_instantiate.drop_site_instantiation buffer overflow attempt (more info ...)attempted-user    
2643SERVER-ORACLE sys.dbms_repcat_fla.ensure_not_published buffer overflow attempt (more info ...)attempted-user    URL
2644SERVER-ORACLE from_tz buffer overflow attempt (more info ...)attempted-user    URL
2645SERVER-ORACLE dbms_repcat_instantiate.instantiate_offline buffer overflow attempt (more info ...)attempted-user    
2649SERVER-ORACLE Oracle 9i TNS Listener SERVICE_NAME Remote Buffer Overflow attempt (more info ...)attempted-user 2002-0965   
2650SERVER-ORACLE user name buffer overflow attempt (more info ...)attempted-user 2003-0095 6849  URL
2651SERVER-ORACLE NUMTODSINTERVAL/NUMTOYMINTERVAL buffer overflow attempt (more info ...)attempted-user 2003-1208 9587  URL
2652SERVER-ORACLE dbms_offline_og.begin_load buffer overflow attempt (more info ...)attempted-user    URL
2655SERVER-OTHER HP Web JetAdmin ExecuteFile admin access (more info ...)attempted-admin  10224  
2656SERVER-WEBAPP SSLv2 Client_Hello Challenge Length overflow attempt (more info ...)attempted-admin 2004-0826 11015  
2663SERVER-WEBAPP Ipswitch WhatsUpGold instancename overflow attempt (more info ...)web-application-attack 2004-0798 11043  
2666PROTOCOL-POP PASS format string attempt (more info ...)attempted-admin 2004-0777 10976  
2668SERVER-WEBAPP processit access (more info ...)web-application-activity   10649 
2669SERVER-WEBAPP ibillpm.pl access (more info ...)web-application-activity 2001-0839 3476 11083 
2670SERVER-WEBAPP pgpmail.pl access (more info ...)web-application-activity 2001-0937 3605 11070 
2672SERVER-WEBAPP sresult.exe access (more info ...)web-application-activity 2004-2528 10837 14186 
2674SERVER-ORACLE dbms_repcat.add_delete_resolution buffer overflow attempt (more info ...)attempted-user    
2675SERVER-ORACLE dbms_repcat_rgt.instantiate_offline buffer overflow attempt (more info ...)attempted-user    
2677SERVER-ORACLE dbms_repcat_rgt.instantiate_online buffer overflow attempt (more info ...)attempted-user    
2678SERVER-ORACLE ctx_output.start_log buffer overflow attempt (more info ...)attempted-user    
2679SERVER-ORACLE sys.dbms_system.ksdwrt buffer overflow attempt (more info ...)attempted-user    
2680SERVER-ORACLE ctxsys.driddlr.subindexpopulate buffer overflow attempt (more info ...)attempted-user    
2681SERVER-ORACLE mdsys.sdo_admin.sdo_code_size buffer overflow attempt (more info ...)attempted-user    
2682SERVER-ORACLE mdsys.md2.validate_geom buffer overflow attempt (more info ...)attempted-user    
2683SERVER-ORACLE mdsys.md2.sdo_code_size buffer overflow attempt (more info ...)attempted-user    
2684SERVER-ORACLE sys.ltutil.pushdeferredtxns buffer overflow attempt (more info ...)attempted-user    
2685SERVER-ORACLE sys.dbms_repcat_rq.add_column buffer overflow attempt (more info ...)attempted-user    
2686SERVER-ORACLE sys.dbms_rectifier_diff.differences buffer overflow attempt (more info ...)attempted-user 2004-1371 10871  URL
2687SERVER-ORACLE sys.dbms_internal_repcat.validate buffer overflow attempt (more info ...)attempted-user    
2688SERVER-ORACLE sys.dbms_internal_repcat.enable_receiver_trace buffer overflow attempt (more info ...)attempted-user    
2689SERVER-ORACLE sys.dbms_internal_repcat.disable_receiver_trace buffer overflow attempt (more info ...)attempted-user    
2690SERVER-ORACLE sys.dbms_defer_repcat.enable_propagation_to_dblink buffer overflow attempt (more info ...)attempted-user    
2691SERVER-ORACLE sys.dbms_defer_internal_sys.parallel_push_recovery buffer overflow attempt (more info ...)attempted-user    
2692SERVER-ORACLE sys.dbms_aqadm_sys.verify_queue_types buffer overflow attempt (more info ...)attempted-user    
2693SERVER-ORACLE sys.dbms_aqadm.verify_queue_types_no_queue buffer overflow attempt (more info ...)attempted-user    
2694SERVER-ORACLE sys.dbms_aqadm.verify_queue_types_get_nrp buffer overflow attempt (more info ...)attempted-user    
2695SERVER-ORACLE sys.dbms_aq_import_internal.aq_table_defn_update buffer overflow attempt (more info ...)attempted-user    
2696SERVER-ORACLE sys.dbms_repcat_utl.is_master buffer overflow attempt (more info ...)attempted-user    
2697SERVER-ORACLE alter file buffer overflow attempt (more info ...)attempted-user    
2698SERVER-ORACLE create file buffer overflow attempt (more info ...)attempted-user    
2699SERVER-ORACLE TO_CHAR buffer overflow attempt (more info ...)attempted-user 2004-1364 10871  
2708SERVER-ORACLE dbms_offline_og.begin_flavor_change buffer overflow attempt (more info ...)attempted-user    URL
2709SERVER-ORACLE dbms_offline_og.begin_instantiation buffer overflow attempt (more info ...)attempted-user    URL
2711SERVER-ORACLE dbms_offline_og.end_flavor_change buffer overflow attempt (more info ...)attempted-user    URL
2712SERVER-ORACLE dbms_offline_og.end_instantiation buffer overflow attempt (more info ...)attempted-user    URL
2713SERVER-ORACLE dbms_offline_og.end_load buffer overflow attempt (more info ...)attempted-user    URL
2714SERVER-ORACLE dbms_offline_og.resume_subset_of_masters buffer overflow attempt (more info ...)attempted-user    URL
2715SERVER-ORACLE dbms_offline_snapshot.begin_load buffer overflow attempt (more info ...)attempted-user    URL
2716SERVER-ORACLE dbms_offline_snapshot.end_load buffer overflow attempt (more info ...)attempted-user    URL
2717SERVER-ORACLE dbms_rectifier_diff.differences buffer overflow attempt (more info ...)attempted-user    URL
2718SERVER-ORACLE dbms_rectifier_diff.rectify buffer overflow attempt (more info ...)attempted-user    URL
2719SERVER-ORACLE dbms_repcat.abort_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2720SERVER-ORACLE dbms_repcat.add_column_group_to_flavor buffer overflow attempt (more info ...)attempted-user    URL
2721SERVER-ORACLE dbms_repcat.add_columns_to_flavor buffer overflow attempt (more info ...)attempted-user    URL
2722SERVER-ORACLE dbms_repcat.add_object_to_flavor buffer overflow attempt (more info ...)attempted-user    URL
2723SERVER-ORACLE dbms_repcat.add_priority_char buffer overflow attempt (more info ...)attempted-user    URL
2724SERVER-ORACLE dbms_repcat.add_priority_date buffer overflow attempt (more info ...)attempted-user    URL
2725SERVER-ORACLE dbms_repcat.add_priority_nchar buffer overflow attempt (more info ...)attempted-user    URL
2726SERVER-ORACLE dbms_repcat.add_priority_number buffer overflow attempt (more info ...)attempted-user    URL
2727SERVER-ORACLE dbms_repcat.add_priority_nvarchar2 buffer overflow attempt (more info ...)attempted-user    URL
2728SERVER-ORACLE dbms_repcat.add_priority_raw buffer overflow attempt (more info ...)attempted-user    URL
2729SERVER-ORACLE dbms_repcat.add_priority_varchar2 buffer overflow attempt (more info ...)attempted-user    URL
2730SERVER-ORACLE dbms_repcat.add_site_priority_site buffer overflow attempt (more info ...)attempted-user    URL
2731SERVER-ORACLE dbms_repcat.add_unique_resolution buffer overflow attempt (more info ...)attempted-user    URL
2732SERVER-ORACLE dbms_repcat.add_update_resolution buffer overflow attempt (more info ...)attempted-user    URL
2733SERVER-ORACLE dbms_repcat.alter_master_propagation buffer overflow attempt (more info ...)attempted-user    URL
2734SERVER-ORACLE dbms_repcat.alter_mview_propagation buffer overflow attempt (more info ...)attempted-user    URL
2735SERVER-ORACLE dbms_repcat.alter_priority_char buffer overflow attempt (more info ...)attempted-user    URL
2736SERVER-ORACLE dbms_repcat.alter_priority_date buffer overflow attempt (more info ...)attempted-user    URL
2737SERVER-ORACLE dbms_repcat.alter_priority_nchar buffer overflow attempt (more info ...)attempted-user    URL
2738SERVER-ORACLE dbms_repcat.alter_priority_number buffer overflow attempt (more info ...)attempted-user    URL
2739SERVER-ORACLE dbms_repcat.alter_priority_nvarchar2 buffer overflow attempt (more info ...)attempted-user    URL
2740SERVER-ORACLE dbms_repcat.alter_priority_raw buffer overflow attempt (more info ...)attempted-user    URL
2741SERVER-ORACLE dbms_repcat.alter_priority buffer overflow attempt (more info ...)attempted-user    URL
2742SERVER-ORACLE dbms_repcat.alter_priority_varchar2 buffer overflow attempt (more info ...)attempted-user    URL
2743SERVER-ORACLE dbms_repcat.alter_site_priority_site buffer overflow attempt (more info ...)attempted-user    URL
2744SERVER-ORACLE dbms_repcat.alter_site_priority buffer overflow attempt (more info ...)attempted-user    URL
2745SERVER-ORACLE dbms_repcat.alter_snapshot_propagation buffer overflow attempt (more info ...)attempted-user    URL
2746SERVER-ORACLE dbms_repcat_auth.revoke_surrogate_repcat buffer overflow attempt (more info ...)attempted-user    URL
2747SERVER-ORACLE dbms_repcat.begin_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2748SERVER-ORACLE dbms_repcat.comment_on_column_group buffer overflow attempt (more info ...)attempted-user    URL
2749SERVER-ORACLE dbms_repcat.comment_on_delete_resolution buffer overflow attempt (more info ...)attempted-user    URL
2750SERVER-ORACLE dbms_repcat.comment_on_mview_repsites buffer overflow attempt (more info ...)attempted-user    URL
2751SERVER-ORACLE dbms_repcat.comment_on_priority_group buffer overflow attempt (more info ...)attempted-user    URL
2752SERVER-ORACLE dbms_repcat.comment_on_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2753SERVER-ORACLE dbms_repcat.comment_on_repsites buffer overflow attempt (more info ...)attempted-user    URL
2754SERVER-ORACLE dbms_repcat.comment_on_site_priority buffer overflow attempt (more info ...)attempted-user    URL
2755SERVER-ORACLE dbms_repcat.comment_on_unique_resolution buffer overflow attempt (more info ...)attempted-user    URL
2756SERVER-ORACLE dbms_repcat.comment_on_update_resolution buffer overflow attempt (more info ...)attempted-user    URL
2757SERVER-ORACLE dbms_repcat.create_master_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2758SERVER-ORACLE dbms_repcat.create_master_repobject buffer overflow attempt (more info ...)attempted-user    URL
2759SERVER-ORACLE dbms_repcat.create_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2760SERVER-ORACLE dbms_repcat.define_column_group buffer overflow attempt (more info ...)attempted-user    URL
2761SERVER-ORACLE dbms_repcat.define_priority_group buffer overflow attempt (more info ...)attempted-user    URL
2762SERVER-ORACLE dbms_repcat.define_site_priority buffer overflow attempt (more info ...)attempted-user    URL
2763SERVER-ORACLE dbms_repcat.do_deferred_repcat_admin buffer overflow attempt (more info ...)attempted-user    URL
2764SERVER-ORACLE dbms_repcat.drop_column_group_from_flavor buffer overflow attempt (more info ...)attempted-user    URL
2765SERVER-ORACLE dbms_repcat.drop_column_group buffer overflow attempt (more info ...)attempted-user    URL
2766SERVER-ORACLE dbms_repcat.drop_columns_from_flavor buffer overflow attempt (more info ...)attempted-user    URL
2767SERVER-ORACLE dbms_repcat.drop_delete_resolution buffer overflow attempt (more info ...)attempted-user    URL
2768SERVER-ORACLE dbms_repcat.drop_grouped_column buffer overflow attempt (more info ...)attempted-user    URL
2769SERVER-ORACLE dbms_repcat.drop_mview_repobject buffer overflow attempt (more info ...)attempted-user    URL
2770SERVER-ORACLE dbms_repcat.drop_object_from_flavor buffer overflow attempt (more info ...)attempted-user    URL
2771SERVER-ORACLE dbms_repcat.drop_priority_char buffer overflow attempt (more info ...)attempted-user    URL
2772SERVER-ORACLE dbms_repcat.drop_priority_date buffer overflow attempt (more info ...)attempted-user    URL
2773SERVER-ORACLE dbms_repcat.drop_priority_nchar buffer overflow attempt (more info ...)attempted-user    URL
2774SERVER-ORACLE dbms_repcat.drop_priority_number buffer overflow attempt (more info ...)attempted-user    URL
2775SERVER-ORACLE dbms_repcat.drop_priority_nvarchar2 buffer overflow attempt (more info ...)attempted-user    URL
2776SERVER-ORACLE dbms_repcat.drop_priority_raw buffer overflow attempt (more info ...)attempted-user    URL
2777SERVER-ORACLE dbms_repcat.drop_priority buffer overflow attempt (more info ...)attempted-user    URL
2778SERVER-ORACLE dbms_repcat.drop_priority_varchar2 buffer overflow attempt (more info ...)attempted-user    URL
2779SERVER-ORACLE dbms_repcat.drop_site_priority_site buffer overflow attempt (more info ...)attempted-user    URL
2780SERVER-ORACLE dbms_repcat.drop_site_priority buffer overflow attempt (more info ...)attempted-user    URL
2781SERVER-ORACLE dbms_repcat.drop_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2782SERVER-ORACLE dbms_repcat.drop_snapshot_repobject buffer overflow attempt (more info ...)attempted-user    URL
2783SERVER-ORACLE dbms_repcat.drop_unique_resolution buffer overflow attempt (more info ...)attempted-user    URL
2784SERVER-ORACLE dbms_repcat.drop_update_resolution buffer overflow attempt (more info ...)attempted-user    URL
2785SERVER-ORACLE dbms_repcat.execute_ddl buffer overflow attempt (more info ...)attempted-user    URL
2786SERVER-ORACLE dbms_repcat.generate_replication_package buffer overflow attempt (more info ...)attempted-user    URL
2787SERVER-ORACLE dbms_repcat_instantiate.instantiate_online buffer overflow attempt (more info ...)attempted-user    URL
2788SERVER-ORACLE dbms_repcat.make_column_group buffer overflow attempt (more info ...)attempted-user    URL
2789SERVER-ORACLE dbms_repcat.obsolete_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2790SERVER-ORACLE dbms_repcat.publish_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2791SERVER-ORACLE dbms_repcat.purge_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2792SERVER-ORACLE dbms_repcat.purge_master_log buffer overflow attempt (more info ...)attempted-user    URL
2793SERVER-ORACLE dbms_repcat.purge_statistics buffer overflow attempt (more info ...)attempted-user    URL
2794SERVER-ORACLE dbms_repcat.refresh_mview_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2795SERVER-ORACLE dbms_repcat.refresh_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2796SERVER-ORACLE dbms_repcat.register_mview_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2797SERVER-ORACLE dbms_repcat.register_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2798SERVER-ORACLE dbms_repcat.register_statistics buffer overflow attempt (more info ...)attempted-user    URL
2799SERVER-ORACLE dbms_repcat.relocate_masterdef buffer overflow attempt (more info ...)attempted-user    URL
2800SERVER-ORACLE dbms_repcat.rename_shadow_column_group buffer overflow attempt (more info ...)attempted-user    URL
2801SERVER-ORACLE dbms_repcat.resume_master_activity buffer overflow attempt (more info ...)attempted-user    URL
2802SERVER-ORACLE dbms_repcat_rgt.check_ddl_text buffer overflow attempt (more info ...)attempted-user    URL
2803SERVER-ORACLE dbms_repcat_rgt.drop_site_instantiation buffer overflow attempt (more info ...)attempted-user    URL
2804SERVER-ORACLE dbms_repcat.send_and_compare_old_values buffer overflow attempt (more info ...)attempted-user    URL
2805SERVER-ORACLE dbms_repcat.set_columns buffer overflow attempt (more info ...)attempted-user    URL
2806SERVER-ORACLE dbms_repcat.set_local_flavor buffer overflow attempt (more info ...)attempted-user    URL
2807SERVER-ORACLE dbms_repcat.specify_new_masters buffer overflow attempt (more info ...)attempted-user    URL
2808SERVER-ORACLE dbms_repcat.suspend_master_activity buffer overflow attempt (more info ...)attempted-user    URL
2809SERVER-ORACLE dbms_repcat.unregister_mview_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2810SERVER-ORACLE dbms_repcat.unregister_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2811SERVER-ORACLE dbms_repcat.validate_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2812SERVER-ORACLE dbms_repcat.validate_for_local_flavor buffer overflow attempt (more info ...)attempted-user    URL
2813SERVER-ORACLE sys.dbms_repcat_fla.abort_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2814SERVER-ORACLE sys.dbms_repcat_fla.add_object_to_flavor buffer overflow attempt (more info ...)attempted-user    URL
2815SERVER-ORACLE sys.dbms_repcat_fla.begin_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2816SERVER-ORACLE sys.dbms_repcat_fla.drop_object_from_flavor buffer overflow attempt (more info ...)attempted-user    URL
2817SERVER-ORACLE sys.dbms_repcat_fla_mas.add_column_group_to_flavor buffer overflow attempt (more info ...)attempted-user    URL
2818SERVER-ORACLE sys.dbms_repcat_fla_mas.add_columns_to_flavor buffer overflow attempt (more info ...)attempted-user    URL
2819SERVER-ORACLE sys.dbms_repcat_fla_mas.drop_column_group_from_flavor buffer overflow attempt (more info ...)attempted-user    URL
2820SERVER-ORACLE sys.dbms_repcat_fla_mas.drop_columns_from_flavor buffer overflow attempt (more info ...)attempted-user    URL
2821SERVER-ORACLE sys.dbms_repcat_fla_mas.obsolete_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2822SERVER-ORACLE sys.dbms_repcat_fla_mas.publish_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2823SERVER-ORACLE sys.dbms_repcat_fla_mas.purge_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2824SERVER-ORACLE sys.dbms_repcat_fla.set_local_flavor buffer overflow attempt (more info ...)attempted-user    URL
2825SERVER-ORACLE sys.dbms_repcat_fla.validate_flavor_definition buffer overflow attempt (more info ...)attempted-user    URL
2826SERVER-ORACLE sys.dbms_repcat_fla.validate_for_local_flavor buffer overflow attempt (more info ...)attempted-user    URL
2827SERVER-ORACLE sys.dbms_repcat_mas.alter_master_repobject buffer overflow attempt (more info ...)attempted-user    URL
2828SERVER-ORACLE sys.dbms_repcat_mas.comment_on_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2829SERVER-ORACLE sys.dbms_repcat_mas.comment_on_repobject buffer overflow attempt (more info ...)attempted-user    URL
2830SERVER-ORACLE sys.dbms_repcat_mas.create_master_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2831SERVER-ORACLE sys.dbms_repcat_mas.create_master_repobject buffer overflow attempt (more info ...)attempted-user    URL
2832SERVER-ORACLE sys.dbms_repcat_mas.do_deferred_repcat_admin buffer overflow attempt (more info ...)attempted-user    URL
2833SERVER-ORACLE sys.dbms_repcat_mas.drop_master_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2834SERVER-ORACLE sys.dbms_repcat_mas.generate_replication_package buffer overflow attempt (more info ...)attempted-user    URL
2835SERVER-ORACLE sys.dbms_repcat_mas.purge_master_log buffer overflow attempt (more info ...)attempted-user    URL
2836SERVER-ORACLE sys.dbms_repcat_mas.relocate_masterdef buffer overflow attempt (more info ...)attempted-user    URL
2837SERVER-ORACLE sys.dbms_repcat_mas.rename_shadow_column_group buffer overflow attempt (more info ...)attempted-user    URL
2838SERVER-ORACLE sys.dbms_repcat_mas.resume_master_activity buffer overflow attempt (more info ...)attempted-user    URL
2839SERVER-ORACLE sys.dbms_repcat_mas.suspend_master_activity buffer overflow attempt (more info ...)attempted-user    URL
2840SERVER-ORACLE sys.dbms_repcat_sna_utl.alter_snapshot_propagation buffer overflow attempt (more info ...)attempted-user    URL
2841SERVER-ORACLE sys.dbms_repcat_sna_utl.create_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2842SERVER-ORACLE sys.dbms_repcat_sna_utl.drop_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2843SERVER-ORACLE sys.dbms_repcat_sna_utl.drop_snapshot_repobject buffer overflow attempt (more info ...)attempted-user    URL
2844SERVER-ORACLE sys.dbms_repcat_sna_utl.refresh_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2845SERVER-ORACLE sys.dbms_repcat_sna_utl.register_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2846SERVER-ORACLE sys.dbms_repcat_sna_utl.repcat_import_check buffer overflow attempt (more info ...)attempted-user    URL
2847SERVER-ORACLE sys.dbms_repcat_sna_utl.unregister_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2848SERVER-ORACLE sys.dbms_repcat_utl4.drop_master_repobject buffer overflow attempt (more info ...)attempted-user    URL
2849SERVER-ORACLE sys.dbms_repcat_utl.drop_an_object buffer overflow attempt (more info ...)attempted-user    URL
2850SERVER-ORACLE dbms_repcat.create_mview_repobject buffer overflow attempt (more info ...)attempted-user    URL
2851SERVER-ORACLE dbms_repcat.create_snapshot_repobject buffer overflow attempt (more info ...)attempted-user    URL
2852SERVER-ORACLE dbms_repcat.generate_mview_support buffer overflow attempt (more info ...)attempted-user    URL
2853SERVER-ORACLE dbms_repcat.generate_replication_trigger buffer overflow attempt (more info ...)attempted-user    URL
2854SERVER-ORACLE dbms_repcat.generate_snapshot_support buffer overflow attempt (more info ...)attempted-user    URL
2855SERVER-ORACLE dbms_repcat.remove_master_databases buffer overflow attempt (more info ...)attempted-user    URL
2856SERVER-ORACLE dbms_repcat.switch_mview_master buffer overflow attempt (more info ...)attempted-user    URL
2857SERVER-ORACLE dbms_repcat.switch_snapshot_master buffer overflow attempt (more info ...)attempted-user    URL
2858SERVER-ORACLE sys.dbms_repcat_conf.add_delete_resolution buffer overflow attempt (more info ...)attempted-user    URL
2859SERVER-ORACLE sys.dbms_repcat_conf.add_priority_char buffer overflow attempt (more info ...)attempted-user    URL
2860SERVER-ORACLE sys.dbms_repcat_conf.add_priority_date buffer overflow attempt (more info ...)attempted-user    URL
2861SERVER-ORACLE sys.dbms_repcat_conf.add_priority_nchar buffer overflow attempt (more info ...)attempted-user    URL
2862SERVER-ORACLE sys.dbms_repcat_conf.add_priority_number buffer overflow attempt (more info ...)attempted-user    URL
2863SERVER-ORACLE sys.dbms_repcat_conf.add_priority_nvarchar2 buffer overflow attempt (more info ...)attempted-user    URL
2864SERVER-ORACLE sys.dbms_repcat_conf.add_priority_raw buffer overflow attempt (more info ...)attempted-user    URL
2865SERVER-ORACLE sys.dbms_repcat_conf.add_priority_varchar2 buffer overflow attempt (more info ...)attempted-user    URL
2866SERVER-ORACLE sys.dbms_repcat_conf.add_site_priority_site buffer overflow attempt (more info ...)attempted-user    URL
2867SERVER-ORACLE sys.dbms_repcat_conf.add_unique_resolution buffer overflow attempt (more info ...)attempted-user    URL
2868SERVER-ORACLE sys.dbms_repcat_conf.add_update_resolution buffer overflow attempt (more info ...)attempted-user    URL
2869SERVER-ORACLE sys.dbms_repcat_conf.alter_priority_char buffer overflow attempt (more info ...)attempted-user    URL
2870SERVER-ORACLE sys.dbms_repcat_conf.alter_priority_date buffer overflow attempt (more info ...)attempted-user    URL
2871SERVER-ORACLE sys.dbms_repcat_conf.alter_priority_nchar buffer overflow attempt (more info ...)attempted-user    URL
2872SERVER-ORACLE sys.dbms_repcat_conf.alter_priority_number buffer overflow attempt (more info ...)attempted-user    URL
2873SERVER-ORACLE sys.dbms_repcat_conf.alter_priority_nvarchar2 buffer overflow attempt (more info ...)attempted-user    URL
2874SERVER-ORACLE sys.dbms_repcat_conf.alter_priority_raw buffer overflow attempt (more info ...)attempted-user    URL
2875SERVER-ORACLE sys.dbms_repcat_conf.alter_priority buffer overflow attempt (more info ...)attempted-user    URL
2876SERVER-ORACLE sys.dbms_repcat_conf.alter_priority_varchar2 buffer overflow attempt (more info ...)attempted-user    URL
2877SERVER-ORACLE sys.dbms_repcat_conf.alter_site_priority_site buffer overflow attempt (more info ...)attempted-user    URL
2878SERVER-ORACLE sys.dbms_repcat_conf.alter_site_priority buffer overflow attempt (more info ...)attempted-user    URL
2879SERVER-ORACLE sys.dbms_repcat_conf.cancel_statistics buffer overflow attempt (more info ...)attempted-user    URL
2880SERVER-ORACLE sys.dbms_repcat_conf.comment_on_delete_resolution buffer overflow attempt (more info ...)attempted-user    URL
2881SERVER-ORACLE sys.dbms_repcat_conf.comment_on_priority_group buffer overflow attempt (more info ...)attempted-user    URL
2882SERVER-ORACLE sys.dbms_repcat_conf.comment_on_site_priority buffer overflow attempt (more info ...)attempted-user    URL
2883SERVER-ORACLE sys.dbms_repcat_conf.comment_on_unique_resolution buffer overflow attempt (more info ...)attempted-user    URL
2884SERVER-ORACLE sys.dbms_repcat_conf.comment_on_update_resolution buffer overflow attempt (more info ...)attempted-user    URL
2885SERVER-ORACLE sys.dbms_repcat_conf.define_priority_group buffer overflow attempt (more info ...)attempted-user    URL
2886SERVER-ORACLE sys.dbms_repcat_conf.define_site_priority buffer overflow attempt (more info ...)attempted-user    URL
2887SERVER-ORACLE sys.dbms_repcat_conf.drop_delete_resolution buffer overflow attempt (more info ...)attempted-user    URL
2888SERVER-ORACLE sys.dbms_repcat_conf.drop_priority_char buffer overflow attempt (more info ...)attempted-user    URL
2889SERVER-ORACLE sys.dbms_repcat_conf.drop_priority_date buffer overflow attempt (more info ...)attempted-user    URL
2890SERVER-ORACLE sys.dbms_repcat_conf.drop_priority_nchar buffer overflow attempt (more info ...)attempted-user    URL
2891SERVER-ORACLE sys.dbms_repcat_conf.drop_priority_number buffer overflow attempt (more info ...)attempted-user    URL
2892SERVER-ORACLE sys.dbms_repcat_conf.drop_priority_nvarchar2 buffer overflow attempt (more info ...)attempted-user    URL
2893SERVER-ORACLE sys.dbms_repcat_conf.drop_priority_raw buffer overflow attempt (more info ...)attempted-user    URL
2894SERVER-ORACLE sys.dbms_repcat_conf.drop_priority buffer overflow attempt (more info ...)attempted-user    URL
2895SERVER-ORACLE sys.dbms_repcat_conf.drop_priority_varchar2 buffer overflow attempt (more info ...)attempted-user    URL
2896SERVER-ORACLE sys.dbms_repcat_conf.drop_site_priority_site buffer overflow attempt (more info ...)attempted-user    URL
2897SERVER-ORACLE sys.dbms_repcat_conf.drop_site_priority buffer overflow attempt (more info ...)attempted-user    URL
2898SERVER-ORACLE sys.dbms_repcat_conf.drop_unique_resolution buffer overflow attempt (more info ...)attempted-user    URL
2899SERVER-ORACLE sys.dbms_repcat_conf.drop_update_resolution buffer overflow attempt (more info ...)attempted-user    URL
2900SERVER-ORACLE sys.dbms_repcat_conf.purge_statistics buffer overflow attempt (more info ...)attempted-user    URL
2901SERVER-ORACLE sys.dbms_repcat_conf.register_statistics buffer overflow attempt (more info ...)attempted-user    URL
2902SERVER-ORACLE sys.dbms_repcat_sna.alter_snapshot_propagation buffer overflow attempt (more info ...)attempted-user    URL
2903SERVER-ORACLE sys.dbms_repcat_sna.create_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2904SERVER-ORACLE sys.dbms_repcat_sna.create_snapshot_repobject buffer overflow attempt (more info ...)attempted-user    URL
2905SERVER-ORACLE sys.dbms_repcat_sna.create_snapshot_repschema buffer overflow attempt (more info ...)attempted-user    URL
2906SERVER-ORACLE sys.dbms_repcat_sna.drop_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2907SERVER-ORACLE sys.dbms_repcat_sna.drop_snapshot_repobject buffer overflow attempt (more info ...)attempted-user    URL
2908SERVER-ORACLE sys.dbms_repcat_sna.drop_snapshot_repschema buffer overflow attempt (more info ...)attempted-user    URL
2909SERVER-ORACLE sys.dbms_repcat_sna.generate_snapshot_support buffer overflow attempt (more info ...)attempted-user    URL
2910SERVER-ORACLE sys.dbms_repcat_sna.refresh_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2911SERVER-ORACLE sys.dbms_repcat_sna.refresh_snapshot_repschema buffer overflow attempt (more info ...)attempted-user    URL
2912SERVER-ORACLE sys.dbms_repcat_sna.register_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2913SERVER-ORACLE sys.dbms_repcat_sna.repcat_import_check buffer overflow attempt (more info ...)attempted-user    URL
2914SERVER-ORACLE sys.dbms_repcat_sna.set_local_flavor buffer overflow attempt (more info ...)attempted-user    URL
2915SERVER-ORACLE sys.dbms_repcat_sna.switch_snapshot_master buffer overflow attempt (more info ...)attempted-user    URL
2916SERVER-ORACLE sys.dbms_repcat_sna.unregister_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
2917SERVER-ORACLE sys.dbms_repcat_sna_utl.switch_snapshot_master buffer overflow attempt (more info ...)attempted-user    URL
2918SERVER-ORACLE sys.dbms_repcat_sna.validate_for_local_flavor buffer overflow attempt (more info ...)attempted-user    URL
2919SERVER-ORACLE sys.dbms_repcat_untrusted.register_snapshot_repgroup buffer overflow attempt (more info ...)attempted-user    URL
3006SERVER-OTHER Volition Freespace 2 buffer overflow attempt (more info ...)misc-attack  9785  
3009MALWARE-BACKDOOR NetBus Pro 2.0 connection request (more info ...)misc-activity    
3010MALWARE-CNC RUX the Tick get windows directory (more info ...)misc-activity    
3011MALWARE-CNC RUX the Tick get system directory (more info ...)misc-activity    
3012MALWARE-CNC RUX the Tick upload/execute arbitrary file (more info ...)misc-activity    
3013MALWARE-CNC Asylum 0.1 connection request (more info ...)misc-activity    
3014MALWARE-CNC Asylum 0.1 connection (more info ...)misc-activity    
3015MALWARE-CNC Insane Network 4.0 connection (more info ...)misc-activity    
3016MALWARE-CNC Insane Network 4.0 connection port 63536 (more info ...)misc-activity    
3061APP-DETECT distccd remote command execution attempt (more info ...)policy-violation    URL
3063MALWARE-BACKDOOR Vampire 1.2 connection request (more info ...)misc-activity    
3064MALWARE-BACKDOOR Vampire 1.2 connection confirmation (more info ...)misc-activity    
3080SERVER-OTHER Unreal Tournament secure overflow attempt (more info ...)misc-attack 2004-0608 10570  
3081MALWARE-BACKDOOR Y3KRAT 1.5 Connect (more info ...)misc-activity    
3082MALWARE-BACKDOOR Y3KRAT 1.5 Connect Client Response (more info ...)misc-activity    
3083MALWARE-BACKDOOR Y3KRAT 1.5 Connection confirmation (more info ...)misc-activity    
3086SERVER-WEBAPP 3Com 3CRADSL72 ADSL 11g Wireless Router app_sta.stm access attempt (more info ...)web-application-activity 2004-1596 11408  
3089SERVER-OTHER squid WCCP I_SEE_YOU message overflow attempt (more info ...)attempted-user 2005-0095 12275  
3131SERVER-WEBAPP mailman directory traversal attempt (more info ...)web-application-attack 2005-0202   
3147PROTOCOL-TELNET login buffer overflow attempt (more info ...)attempted-admin 2001-0797 3681 10827 
3151PROTOCOL-FINGER / execution attempt (more info ...)attempted-recon 2000-0915   
3155MALWARE-BACKDOOR BackOrifice 2000 Inbound Traffic (more info ...)trojan-activity    
3234OS-WINDOWS Messenger message little endian overflow attempt (more info ...)attempted-admin 2003-0717 8826  
3235OS-WINDOWS Messenger message overflow attempt (more info ...)attempted-admin 2003-0717 8826  
3274PROTOCOL-TELNET login buffer non-evasive overflow attempt (more info ...)attempted-admin 2001-0797 3681 10827 
3455SERVER-OTHER Bontago Game Server Nickname buffer overflow (more info ...)attempted-user 2005-0501 12603  URL
3459PUA-P2P Manolito Search Query (more info ...)policy-violation    URL
3464SERVER-WEBAPP awstats.pl command execution attempt (more info ...)web-application-attack  12572 16456 
3465SERVER-WEBAPP RiSearch show.pl proxy attempt (more info ...)web-application-activity 2004-2061 10812  
3469SERVER-WEBAPP Ipswitch WhatsUp Gold dos attempt (more info ...)attempted-dos 2004-0799 11110  URL
3512SERVER-ORACLE utl_file.fcopy directory traversal attempt (more info ...)attempted-user  12749  
3513SERVER-ORACLE utl_file.fopen_nchar directory traversal attempt (more info ...)attempted-user  12749  
3514SERVER-ORACLE utl_file.fopen directory traversal attempt (more info ...)attempted-user  12749  
3515SERVER-ORACLE utl_file.fremove directory traversal attempt (more info ...)attempted-user  12749  
3516SERVER-ORACLE utl_file.frename directory traversal attempt (more info ...)attempted-user  12749  
3520SERVER-OTHER Computer Associates license GCR NETWORK overflow attempt (more info ...)attempted-user 2005-0581 12705  
3521SERVER-OTHER Computer Associates license GCR CHECKSUMS overflow attempt (more info ...)attempted-user 2005-0581 12705  
3522SERVER-OTHER Computer Associates license GETCONFIG server overflow attempt (more info ...)attempted-user 2005-0581 12705  
3524SERVER-OTHER Computer Associates license invalid GCR CHECKSUMS attempt (more info ...)attempted-dos 2005-0581 12705  
3525SERVER-OTHER Computer Associates license invalid GCR NETWORK attempt (more info ...)attempted-dos 2005-0581 12705  
3529SERVER-OTHER Computer Associates license GETCONFIG client overflow attempt (more info ...)attempted-user 2005-0581 12705  
3533PROTOCOL-TELNET client LINEMODE SLC overflow attempt (more info ...)attempted-user 2005-0469 12918  
3537PROTOCOL-TELNET client ENV OPT escape overflow attempt (more info ...)attempted-user 2005-0469 12918  
3546SERVER-WEBAPP TrackerCam User-Agent buffer overflow attempt (more info ...)web-application-attack 2005-0481 12592  
3548SERVER-WEBAPP TrackerCam negative Content-Length attempt (more info ...)web-application-attack 2005-0481 12592  
3551FILE-IDENTIFY HTA file download request (more info ...)misc-activity    URL
3627SERVER-MAIL X-LINK2STATE CHUNK command attempt (more info ...)protocol-command-decode 2005-0560 13118 18024 URL
3629SERVER-WEBAPP sambar /search/results.stm access (more info ...)web-application-activity 2004-2086 9607 18650 
3635MALWARE-BACKDOOR Amanda 2.0 connection established (more info ...)trojan-activity    
3636MALWARE-BACKDOOR Crazzy Net 5.0 connection established (more info ...)trojan-activity    
3637SERVER-OTHER Computer Associates license PUTOLF directory traversal attempt (more info ...)attempted-user 2005-0581 12705  
3653SERVER-MAIL SAML overflow attempt (more info ...)attempted-user 2004-1546 11238  
3654SERVER-MAIL SOML overflow attempt (more info ...)attempted-user 2004-1546 11238  
3655SERVER-MAIL SEND overflow attempt (more info ...)attempted-user 2004-1546 11238  
3656SERVER-MAIL MDaemon 6.5.1 and prior versions MAIL overflow attempt (more info ...)attempted-user 2004-1546 11238  
3657SERVER-ORACLE ctxsys.driload attempt (more info ...)attempted-user 2004-0637 11099 16209 
3664SERVER-OTHER PPTP echo request buffer overflow attempt (more info ...)attempted-admin 2003-0213 7316 11540 URL
3674SERVER-WEBAPP db4web_c directory traversal attempt (more info ...)web-application-attack 2002-1483 5723 11182 
3675SERVER-OTHER IBM DB2 DTS empty format string dos attempt (more info ...)attempted-dos 2005-4869 11400  URL
3676SERVER-WEBAPP newsscript.pl admin attempt (more info ...)web-application-attack 2005-0735 12761 17309 
3680PUA-P2P AOL Instant Messenger file send attempt (more info ...)policy-violation    
3681PUA-P2P AOL Instant Messenger file receive attempt (more info ...)policy-violation    
3682SERVER-MAIL spoofed MIME-Type auto-execution attempt (more info ...)attempted-admin 2001-0154 2524  URL
3693SERVER-WEBAPP IBM WebSphere j_security_check overflow attempt (more info ...)attempted-admin 2005-1872 13853  
3813SERVER-WEBAPP awstats.pl configdir command injection attempt (more info ...)web-application-attack 2005-0116   
3816SERVER-WEBAPP BadBlue ext.dll buffer overflow attempt (more info ...)attempted-admin 2005-0595 12673  
3819FILE-IDENTIFY CHM file download request (more info ...)misc-activity    URL
4060APP-DETECT remote desktop protocol attempted administrator connection request (more info ...)misc-activity 2005-1218 14259  URL
4140SERVER-OTHER tcpdump tcp LDP print zero length message denial of service attempt (more info ...)attempted-dos 2005-1279 13389  URL
4142SERVER-ORACLE Oracle reports servlet command execution attempt (more info ...)attempted-user 2005-2371 14316  URL
4143SERVER-OTHER lpd receive printer job cascade adaptor protocol request (more info ...)protocol-command-decode    
4638SERVER-OTHER RSVP Protocol zero length object DoS attempt (more info ...)attempted-dos    URL
4639SERVER-OTHER Ethereal Distcc ARGV buffer overflow attempt (more info ...)attempted-dos    URL
4640SERVER-OTHER Ethereal Distcc SERR buffer overflow attempt (more info ...)attempted-dos    URL
4641SERVER-OTHER Ethereal Distcc SOUT buffer overflow attempt (more info ...)attempted-dos    URL
4676SERVER-ORACLE Enterprise Manager Application Server Control web parameter overflow attempt (more info ...)attempted-admin  15146  URL
4677SERVER-ORACLE Enterprise Manager Application Server Control GET parameter overflow attempt (more info ...)attempted-admin  15146  URL
4985SERVER-WEBAPP Twiki rdiff rev command injection attempt (more info ...)attempted-admin 2005-2877 14834  
4986SERVER-WEBAPP Twiki view rev command injection attempt (more info ...)attempted-admin 2005-2877 14834  
4987SERVER-WEBAPP Twiki viewfile rev command injection attempt (more info ...)attempted-admin 2005-2877 14834  
4988SERVER-WEBAPP Barracuda IMG.PL directory traversal attempt (more info ...)attempted-admin 2005-2847 14712  
5317SERVER-OTHER pcAnywhere buffer overflow attempt (more info ...)attempted-dos 2005-3934 15646  
5709SERVER-WEBAPP file upload directory traversal (more info ...)misc-attack    URL
5739SERVER-MAIL headers too long server response (more info ...)bad-unknown 2006-0058 17192  
5742MALWARE-OTHER Keylogger activitylogger runtime detection (more info ...)successful-recon-limited    URL
5743PUA-ADWARE Hijacker actualnames outbound connection - plugin list (more info ...)misc-activity    URL
5745PUA-ADWARE Hijacker adultlinks outbound connection - redirect (more info ...)misc-activity    URL
5746PUA-ADWARE Hijacker adultlinks outbound connection - load url (more info ...)misc-activity    URL
5747PUA-ADWARE Hijacker adultlinks outbound connection - log hits (more info ...)misc-activity    URL
5748PUA-ADWARE Hijacker adultlinks outbound connection - ads (more info ...)misc-activity    URL
5750PUA-TOOLBARS Adware dogpile runtime detection (more info ...)misc-activity    URL
5751PUA-ADWARE Adware exactsearch runtime detection - switch search engine 1 (more info ...)misc-activity    URL
5752PUA-ADWARE Adware exactsearch runtime detection - switch search engine 2 (more info ...)misc-activity    URL
5753PUA-ADWARE Adware exactsearch runtime detection - topsearches (more info ...)misc-activity    URL
5754PUA-ADWARE Hijacker ezcybersearch outbound connection - ie auto search hijack (more info ...)misc-activity    URL
5755PUA-ADWARE Hijacker ezcybersearch outbound connection - check update (more info ...)misc-activity    URL
5756PUA-ADWARE Hijacker ezcybersearch outbound connection - add coolsites to ie favorites (more info ...)misc-activity    URL
5757PUA-TOOLBARS Hijacker ezcybersearch runtime detection - check toolbar setting (more info ...)misc-activity    URL
5758PUA-ADWARE Hijacker ezcybersearch outbound connection - download fastclick pop-under code (more info ...)misc-activity    URL
5759MALWARE-OTHER Keylogger fearlesskeyspy runtime detection (more info ...)successful-recon-limited    URL
5760MALWARE-CNC User-Agent known malicious user agent - OSSProxy (more info ...)misc-activity    URL
5761PUA-ADWARE Trickler bearshare outbound connection - ads popup (more info ...)misc-activity    URL
5762PUA-ADWARE Trickler bearshare outbound connection - p2p information request (more info ...)misc-activity    URL
5763PUA-ADWARE Trickler bearshare outbound connection - chat request (more info ...)misc-activity    URL
5765PUA-TOOLBARS Hijacker begin2search runtime detection - ico query (more info ...)misc-activity    URL
5766PUA-ADWARE Hijacker begin2search outbound connection - install spyware trafficsector (more info ...)misc-activity    URL
5767PUA-ADWARE Hijacker begin2search outbound connection - download unauthorized code (more info ...)misc-activity    URL
5768PUA-ADWARE Hijacker begin2search outbound connection - pass information (more info ...)misc-activity    URL
5769PUA-ADWARE Hijacker begin2search outbound connection - play bingo ads (more info ...)misc-activity    URL
5770MALWARE-CNC User-Agent known malicious user agent - Casino (more info ...)successful-recon-limited    URL
5771PUA-ADWARE Screen-Scraper farsighter outbound connection - initial connection (more info ...)successful-recon-limited    URL
5772PUA-ADWARE Screen-Scraper farsighter outbound connection - initial connection (more info ...)successful-recon-limited    URL
5773PUA-ADWARE Adware forbes runtime detection (more info ...)misc-activity    URL
5774MALWARE-CNC User-Agent known malicious user agent - FSW (more info ...)misc-activity    URL
5775PUA-ADWARE Hijacker freescratch outbound connection - scratch card (more info ...)misc-activity    URL
5776PUA-ADWARE Trickler grokster outbound connection (more info ...)misc-activity    URL
5777MALWARE-OTHER Keylogger gurl watcher runtime detection (more info ...)successful-recon-limited    URL
5778MALWARE-OTHER Keylogger runtime detection - hwpe windows activity logs (more info ...)successful-recon-limited    URL
5779MALWARE-OTHER Keylogger runtime detection - hwpe shell file logs (more info ...)successful-recon-limited    URL
5781MALWARE-OTHER Keylogger runtime detection - hwae windows activity logs (more info ...)successful-recon-limited    URL
5783MALWARE-OTHER Keylogger runtime detection - hwae keystrokes log (more info ...)successful-recon-limited    URL
5784MALWARE-OTHER Keylogger runtime detection - hwae urls browsed log (more info ...)successful-recon-limited    URL
5785PUA-ADWARE Adware hithopper runtime detection - get xml setting (more info ...)misc-activity    URL
5786PUA-ADWARE Adware hithopper runtime detection - redirect (more info ...)misc-activity    URL
5787PUA-ADWARE Adware hithopper runtime detection - search (more info ...)misc-activity    URL
5788PUA-TOOLBARS Adware hithopper runtime detection - click toolbar buttons (more info ...)misc-activity    URL
5789MALWARE-CNC User-Agent known malicious user agent - ActMon (more info ...)successful-recon-limited    URL
5791PUA-ADWARE Dialer pluginaccess outbound connection - get pin (more info ...)misc-activity    URL
5792PUA-ADWARE Dialer pluginaccess outbound connection - active proxy (more info ...)misc-activity    URL
5793PUA-ADWARE Dialer pluginaccess outbound connection - redirect (more info ...)misc-activity    URL
5794PUA-ADWARE Hijacker coolwebsearch.aboutblank variant outbound connection (more info ...)misc-activity    URL
5795PUA-ADWARE Adware ist powerscan runtime detection (more info ...)misc-activity    URL
5796PUA-ADWARE Adware keenvalue runtime detection (more info ...)misc-activity    URL
5800MALWARE-CNC User-Agent known malicious user agent - MyWay (more info ...)successful-recon-limited    URL
5801PUA-TOOLBARS Trackware myway speedbar / mywebsearch toolbar runtime detection - track activity 1 (more info ...)successful-recon-limited    URL
5802PUA-TOOLBARS Trackware myway speedbar / mywebsearch toolbar runtime detection - track activity 2 (more info ...)successful-recon-limited    URL
5803PUA-TOOLBARS Trackware myway speedbar / mywebsearch toolbar runtime detection - collect information (more info ...)successful-recon-limited    URL
5805MALWARE-OTHER Trackware myway speedbar runtime detection - switch engines (more info ...)successful-recon-limited    URL
5807PUA-ADWARE Hijacker shopathomeselect outbound connection (more info ...)misc-activity    URL
5808MALWARE-CNC User-Agent known malicious user agent - SAH Agent (more info ...)misc-activity    
5809PUA-ADWARE Hijacker shop at home select merchant redirect in progress (more info ...)misc-activity    
5810PUA-ADWARE Hijacker shop at home select installation in progress (more info ...)misc-activity    
5811PUA-ADWARE shop at home select installation in progress - clsid detected (more info ...)misc-activity    URL
5812MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - email notification (more info ...)misc-activity    URL
5815MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - destory redirection (more info ...)misc-activity    
5816MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - destory redirection (more info ...)misc-activity    URL
5817MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - check status (more info ...)misc-activity    
5818MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - check status (more info ...)misc-activity    
5819MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - check status (more info ...)misc-activity    URL
5820MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - destory log (more info ...)misc-activity    
5821MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - destory log (more info ...)misc-activity    URL
5822MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - view netstat (more info ...)misc-activity    
5823MALWARE-TOOLS Hacker-Tool stealthredirector runtime detection - view netstat (more info ...)misc-activity    URL
5824MALWARE-CNC User-Agent known malicious user agent - Strip-Player (more info ...)misc-activity    URL
5825PUA-ADWARE Adware broadcasturban tuner runtime detection - start tuner (more info ...)misc-activity    URL
5826PUA-ADWARE Adware broadcasturban tuner runtime detection - pass user info to server (more info ...)misc-activity    URL
5827PUA-ADWARE Adware broadcasturban tuner runtime detection - get gateway (more info ...)misc-activity    URL
5828PUA-ADWARE Adware broadcasturban tuner runtime detection - connect to station (more info ...)misc-activity    URL
5829PUA-ADWARE Trickler clipgenie outbound connection (more info ...)misc-activity    URL
5835PUA-ADWARE Adware gamespy_arcade runtime detection (more info ...)misc-activity    URL
5836PUA-ADWARE Trickler nictech.bm2 outbound connection (more info ...)misc-activity    URL
5838MALWARE-CNC User-Agent known malicious user agent - EI (more info ...)successful-recon-limited    URL
5839MALWARE-OTHER Trackware ucmore runtime detection - click sponsor/ad link (more info ...)successful-recon-limited    URL
5840PUA-ADWARE Hijacker sep outbound connection (more info ...)misc-activity    URL
5841PUA-ADWARE Trickler minibug outbound connection - retrieve weather information (more info ...)misc-activity    URL
5842PUA-ADWARE Trickler minibug outbound connection - ads (more info ...)misc-activity    URL
5843PUA-ADWARE Hijacker surfsidekick outbound connection - hijack ie auto search (more info ...)misc-activity    URL
5844PUA-ADWARE Hijacker surfsidekick outbound connection - post request (more info ...)misc-activity    URL
5845PUA-ADWARE Hijacker surfsidekick outbound connection - update request (more info ...)misc-activity    URL
5846PUA-ADWARE Trickler VX2/DLmax/BestOffers/Aurora outbound connection (more info ...)misc-activity    URL
5847PUA-ADWARE Adware warez_p2p runtime detection - p2p client home (more info ...)misc-activity    URL
5849PUA-ADWARE Adware warez_p2p runtime detection - update request (more info ...)misc-activity    URL
5850PUA-ADWARE Adware warez_p2p runtime detection - check update (more info ...)misc-activity    URL
5851PUA-ADWARE Adware warez_p2p runtime detection - .txt .dat and .lst requests (more info ...)misc-activity    URL
5852PUA-ADWARE Adware warez_p2p runtime detection - cache.dat request (more info ...)misc-activity    URL
5853PUA-ADWARE Adware warez_p2p runtime detection - download ads (more info ...)misc-activity    URL
5854PUA-ADWARE Adware warez_p2p runtime detection - pass user information (more info ...)misc-activity    URL
5855PUA-ADWARE Hijacker funbuddyicons outbound connection - request config (more info ...)misc-activity    URL
5857MALWARE-CNC User-Agent known malicious user agent - MyWebSearchSearchAssistance (more info ...)misc-activity    URL
5858PUA-TOOLBARS Adware praizetoolbar runtime detection (more info ...)misc-activity    URL
5859PUA-ADWARE Hijacker daosearch outbound connection - information request (more info ...)misc-activity    URL
5860PUA-ADWARE Hijacker daosearch outbound connection - search hijack (more info ...)misc-activity    URL
5861PUA-TOOLBARS Hijacker isearch runtime detection - toolbar information request (more info ...)misc-activity    URL
5862PUA-ADWARE Hijacker isearch outbound connection - search hijack 1 (more info ...)misc-activity    URL
5863PUA-ADWARE Hijacker isearch outbound connection - search hijack 2 (more info ...)misc-activity    URL
5864PUA-TOOLBARS Hijacker isearch runtime detection - search in toolbar (more info ...)misc-activity    URL
5865PUA-ADWARE Adware zapspot runtime detection - pop up ads (more info ...)misc-activity    URL
5866PUA-TOOLBARS Hijacker couponbar runtime detection - download new coupon offers and links (more info ...)misc-activity    URL
5867PUA-TOOLBARS Hijacker couponbar runtime detection - get updates to toolbar buttons (more info ...)misc-activity    URL
5868PUA-ADWARE Hijacker couponbar outbound connection - view coupon offers (more info ...)misc-activity    URL
5871PUA-ADWARE Trickler VX2/ABetterInternet transponder thinstaller outbound connection - post information (more info ...)misc-activity    URL
5872PUA-ADWARE Snoopware hyperlinker outbound connection (more info ...)successful-recon-limited    URL
5873PUA-ADWARE Snoopware pc acme pro outbound connection (more info ...)successful-recon-limited    URL
5874PUA-ADWARE Snoopware pc acme pro outbound connection (more info ...)successful-recon-limited    URL
5875MALWARE-TOOLS Hacker-Tool eraser runtime detection - detonate (more info ...)misc-activity    URL
5876MALWARE-TOOLS Hacker-Tool eraser runtime detection - disinfect (more info ...)misc-activity    URL
5882MALWARE-OTHER Keylogger spyagent runtime detect - alert notification (more info ...)successful-recon-limited    URL
5883PUA-ADWARE Other-Technologies saria 1.0 outbound connection - send user information (more info ...)misc-activity    URL
5884PUA-TOOLBARS Hijacker copernic meta toolbar runtime detection - check toolbar & category info (more info ...)misc-activity    URL
5885PUA-TOOLBARS Hijacker copernic meta toolbar runtime detection - ie autosearch & search assistant hijack (more info ...)misc-activity    URL
5886PUA-TOOLBARS Hijacker copernic meta toolbar runtime detection - pass info to server (more info ...)misc-activity    URL
5887PUA-ADWARE Hijacker shopnav outbound connection - ie search assistant hijack (more info ...)misc-activity    URL
5888PUA-ADWARE Hijacker shopnav outbound connection - ie auto search hijack (more info ...)misc-activity    URL
5889PUA-ADWARE Hijacker shopnav outbound connection - collect information (more info ...)misc-activity    URL
5890PUA-ADWARE Hijacker shopnav outbound connection - self-update request 1 (more info ...)misc-activity    URL
5891PUA-ADWARE Hijacker shopnav outbound connection - self-update request 2 (more info ...)misc-activity    URL
5894MALWARE-TOOLS Hacker-Tool timbuktu pro runtime detection - smb (more info ...)misc-activity    URL
5895MALWARE-TOOLS Hacker-Tool timbuktu pro runtime detection - tcp port 407 (more info ...)misc-activity    
5897MALWARE-TOOLS Hacker-Tool timbuktu pro runtime detection - udp port 407 (more info ...)misc-activity    URL
5900MALWARE-CNC User-Agent known malicious user agent - Async HTTP Agent (more info ...)successful-recon-limited    URL
5901MALWARE-CNC User-Agent known malicious user agent - AdTools (more info ...)successful-recon-limited    URL
5902PUA-ADWARE Adware download accelerator plus runtime detection - startup (more info ...)misc-activity    URL
5903PUA-ADWARE Adware download accelerator plus runtime detection - get ads (more info ...)misc-activity    URL
5904PUA-ADWARE Adware download accelerator plus runtime detection - download files (more info ...)misc-activity    URL
5905PUA-ADWARE Adware download accelerator plus runtime detection - games center request (more info ...)misc-activity    URL
5906PUA-ADWARE Adware download accelerator plus runtime detection - update (more info ...)misc-activity    URL
5907MALWARE-OTHER Trackware e2give runtime detection - check update (more info ...)successful-recon-limited    URL
5908MALWARE-OTHER Trackware e2give runtime detection - redirect affiliate site request 1 (more info ...)successful-recon-limited    URL
5909MALWARE-OTHER Trackware e2give runtime detection - redirect affiliate site request 2 (more info ...)successful-recon-limited    URL
5911PUA-ADWARE Adware smartpops runtime detection (more info ...)misc-activity    URL
5913MALWARE-CNC User-Agent known malicious user agent - My Agent (more info ...)misc-activity    URL
5914PUA-TOOLBARS Hijacker locatorstoolbar runtime detection - configuration download (more info ...)misc-activity    URL
5915PUA-TOOLBARS Hijacker locatorstoolbar runtime detection - autosearch hijack (more info ...)misc-activity    URL
5916PUA-TOOLBARS Hijacker locatorstoolbar runtime detection - sidebar search (more info ...)misc-activity    URL
5917PUA-TOOLBARS Hijacker locatorstoolbar runtime detection - toolbar search (more info ...)misc-activity    URL
5918PUA-ADWARE Hijacker painter outbound connection - ping 'alive' signal (more info ...)misc-activity    URL
5919PUA-ADWARE Hijacker painter outbound connection - redirect to klikvipsearch (more info ...)misc-activity    URL
5920PUA-ADWARE Hijacker painter outbound connection - redirect yahoo search through online-casino-searcher (more info ...)misc-activity    URL
5921PUA-TOOLBARS Trackware fftoolbar toolbar runtime detection - send user url request (more info ...)successful-recon-limited    URL
5922PUA-TOOLBARS Trackware fftoolbar toolbar runtime detection - display advertisement news (more info ...)successful-recon-limited    URL
5923PUA-ADWARE Adware active shopper runtime detection - side search request (more info ...)misc-activity    URL
5924PUA-ADWARE Adware active shopper runtime detection - redirect (more info ...)misc-activity    URL
5925PUA-ADWARE Adware active shopper runtime detection - check (more info ...)misc-activity    URL
5926PUA-ADWARE Adware active shopper runtime detection - collect information (more info ...)misc-activity    URL
5927PUA-ADWARE Adware cashbar runtime detection - .smx requests (more info ...)misc-activity    URL
5928PUA-ADWARE Adware cashbar runtime detection - ads request (more info ...)misc-activity    URL
5929PUA-ADWARE Adware cashbar runtime detection - pop-up ad 1 (more info ...)misc-activity    URL
5930PUA-ADWARE Adware cashbar runtime detection - pop-up ad 2 (more info ...)misc-activity    URL
5932PUA-ADWARE Adware cashbar runtime detection - stats track (more info ...)misc-activity    URL
5933PUA-ADWARE Hijacker dropspam outbound connection - search request 1 (more info ...)misc-activity    URL
5934PUA-ADWARE Hijacker dropspam outbound connection - search request 2 (more info ...)misc-activity    URL
5935PUA-ADWARE Hijacker dropspam outbound connection - search request 3 (more info ...)misc-activity    URL
5936PUA-ADWARE Hijacker dropspam outbound connection - side search (more info ...)misc-activity    URL
5937PUA-ADWARE Hijacker dropspam outbound connection - pass information to its controlling server (more info ...)misc-activity    URL
5938PUA-ADWARE Hijacker dropspam outbound connection - third party information collection (more info ...)misc-activity    URL
5939PUA-TOOLBARS Trackware supreme toolbar runtime detection - get cfg (more info ...)successful-recon-limited    URL
5940PUA-TOOLBARS Trackware supreme toolbar runtime detection - search request (more info ...)successful-recon-limited    URL
5941PUA-TOOLBARS Trackware supreme toolbar runtime detection - track (more info ...)successful-recon-limited    URL
5942PUA-TOOLBARS Trackware supreme toolbar runtime detection - pass information to its controlling server (more info ...)successful-recon-limited    URL
5943PUA-TOOLBARS Trackware supreme toolbar runtime detection - third party information collection (more info ...)successful-recon-limited    URL
5944PUA-ADWARE Adware free access bar runtime detection 1 (more info ...)misc-activity    URL
5946PUA-ADWARE Adware weirdontheweb runtime detection - monitor user web activity (more info ...)misc-activity    URL
5947PUA-ADWARE Adware weirdontheweb runtime detection - log url (more info ...)misc-activity    URL
5948PUA-ADWARE Adware weirdontheweb runtime detection - update notifier (more info ...)misc-activity    URL
5949PUA-TOOLBARS Trackware iggsey toolbar detection - simpleticker.htm request (more info ...)successful-recon-limited    URL
5951PUA-TOOLBARS Trackware iggsey toolbar detection - search request (more info ...)successful-recon-limited    URL
5952PUA-ADWARE Hijacker 123mania outbound connection - autosearch hijacking (more info ...)misc-activity    URL
5953PUA-ADWARE Hijacker 123mania outbound connection - sidesearch hijacking (more info ...)misc-activity    URL
5954MALWARE-CNC User-Agent known malicious user agent - Browser Pal (more info ...)successful-recon-limited    URL
5955MALWARE-CNC User-Agent known malicious user agent - Popup Stopper (more info ...)successful-recon-limited    URL
5956MALWARE-TOOLS Hacker-Tool ghostvoice 1.02 icq notification of server installation (more info ...)misc-activity    URL
5957MALWARE-TOOLS Hacker-Tool ghostvoice 1.02 runtime detection (more info ...)misc-activity    
5960PUA-ADWARE Hijacker raxsearch detection - pop-up raxsearch window (more info ...)misc-activity    URL
5961PUA-ADWARE Hijacker searchfast detection - news ticker (more info ...)misc-activity    URL
5963PUA-ADWARE Hijacker searchfast detection - search request (more info ...)misc-activity    URL
5964PUA-TOOLBARS Hijacker searchfast detection - track user activity & get 'relates links' of the toolbar (more info ...)misc-activity    URL
5965PUA-TOOLBARS Hijacker searchfast detection - get toolbar cfg (more info ...)misc-activity    URL
5966PUA-ADWARE trackware searchinweb detection - search request (more info ...)successful-recon-limited    URL
5967PUA-ADWARE trackware searchinweb detection - click result links (more info ...)successful-recon-limited    URL
5968PUA-ADWARE trackware searchinweb detection - redirect (more info ...)successful-recon-limited    URL
5969PUA-ADWARE trackware searchinweb detection - collect information (more info ...)successful-recon-limited    URL
5970MALWARE-CNC User-Agent known malicious user agent - Feat2 Updater (more info ...)misc-activity    URL
5972PUA-ADWARE hijacker smart finder detection - ie autosearch hijack 1 (more info ...)misc-activity    URL
5973PUA-ADWARE hijacker smart finder detection - search engines hijack (more info ...)misc-activity    URL
5974PUA-ADWARE hijacker smart finder detection - pop-up ads (more info ...)misc-activity    URL
5975PUA-ADWARE hijacker topfive searchassistant detection - search request (more info ...)misc-activity    URL
5976PUA-ADWARE hijacker topfive searchassistant detection - side search (more info ...)misc-activity    URL
5978MALWARE-CNC User-Agent known malicious user agent - TM_SEARCH3 (more info ...)misc-activity    URL
5979PUA-TOOLBARS Trackware anwb toolbar runtime detection - track user ip address (more info ...)successful-recon-limited    URL
5980PUA-TOOLBARS Trackware anwb toolbar runtime detection - display advertisement (more info ...)successful-recon-limited    URL
5981PUA-TOOLBARS Hijacker seeqtoolbar runtime detection - autosearch hijack or search in toolbar (more info ...)misc-activity    URL
5982PUA-TOOLBARS Hijacker seeqtoolbar runtime detection - email login page (more info ...)misc-activity    URL
5983PUA-ADWARE Adware powerstrip runtime detection (more info ...)misc-activity    URL
5984PUA-TOOLBARS Trackware push toolbar installtime detection - user information collect (more info ...)successful-recon-limited    URL
5985PUA-TOOLBARS Trackware push toolbar runtime detection - toolbar information request (more info ...)successful-recon-limited    URL
5986MALWARE-CNC User-Agent known malicious user agent - TeomaBar (more info ...)misc-activity    URL
5987PUA-TOOLBARS Hijacker wishbone runtime detection (more info ...)misc-activity    URL
5988MALWARE-CNC User-Agent known malicious user agent - ZC-Bridge (more info ...)successful-recon-limited    
5989PUA-ADWARE Adware broadcastpc runtime detection - get config (more info ...)misc-activity    URL
5990PUA-ADWARE Adware broadcastpc runtime detection - get up-to-date movie/tv/ad information (more info ...)misc-activity    URL
5993PUA-ADWARE Hijacker getmirar outbound connection - track activity (more info ...)misc-activity    URL
5994PUA-ADWARE Hijacker getmirar outbound connection - click related button (more info ...)misc-activity    URL
5995PUA-ADWARE Adware offeragent runtime detection - information checking (more info ...)misc-activity    URL
5996PUA-ADWARE Adware offeragent runtime detection - ads request (more info ...)misc-activity    URL
5997SERVER-WEBAPP WinProxy host header port buffer overflow attempt (more info ...)attempted-admin 2005-4085 16147  URL
6012MALWARE-BACKDOOR coolcat runtime connection detection - tcp 1 (more info ...)trojan-activity    URL
6013MALWARE-BACKDOOR coolcat runtime connection detection - tcp 2 (more info ...)trojan-activity    URL
6014MALWARE-BACKDOOR coolcat runtime connection detection - tcp 3 (more info ...)trojan-activity    URL
6015MALWARE-BACKDOOR dsk lite 1.0 runtime detection - initial connection (more info ...)trojan-activity    URL
6016MALWARE-BACKDOOR dsk lite 1.0 runtime detection - initial connection (more info ...)trojan-activity    URL
6018MALWARE-CNC dsk lite 1.0 variant outbound connection icq notification (more info ...)trojan-activity    URL
6021MALWARE-BACKDOOR silent spy 2.10 command response port 4225 (more info ...)trojan-activity    URL
6022MALWARE-BACKDOOR silent spy 2.10 command response port 4226 (more info ...)trojan-activity    URL
6023MALWARE-CNC silent spy 2.10 variant outbound connection icq notification (more info ...)trojan-activity    URL
6024MALWARE-BACKDOOR nuclear rat v6_21 runtime detection (more info ...)trojan-activity    URL
6025MALWARE-BACKDOOR tequila bandita 1.2 runtime detection - reverse connection (more info ...)trojan-activity    URL
6026MALWARE-BACKDOOR dimbus 1.0 runtime detection - get pc info (more info ...)trojan-activity    URL
6028MALWARE-BACKDOOR cyberpaky runtime detection (more info ...)trojan-activity    URL
6029MALWARE-CNC fkwp 2.0 variant outbound connection icq notification (more info ...)trojan-activity    URL
6035MALWARE-BACKDOOR minicommand runtime detection - initial connection server-to-client (more info ...)trojan-activity    URL
6037MALWARE-BACKDOOR netbus 1.7 runtime detection - email notification (more info ...)trojan-activity    URL
6039MALWARE-CNC fade 1.0 variant outbound connection notification (more info ...)trojan-activity    URL
6040MALWARE-BACKDOOR fade 1.0 runtime detection - enable keylogger (more info ...)trojan-activity    URL
6041MALWARE-BACKDOOR fade 1.0 runtime detection - enable keylogger (more info ...)trojan-activity    URL
6044MALWARE-BACKDOOR fear 0.2 runtime detection - initial connection (more info ...)trojan-activity    URL
6045MALWARE-BACKDOOR fear 0.2 runtime detection - initial connection (more info ...)trojan-activity    URL
6046MALWARE-BACKDOOR fear 0.2 runtime detection - initial connection (more info ...)trojan-activity    URL
6047MALWARE-BACKDOOR fun factory runtime detection - connect (more info ...)trojan-activity    URL
6048MALWARE-BACKDOOR fun factory runtime detection - connect (more info ...)trojan-activity    URL
6049MALWARE-BACKDOOR fun factory runtime detection - upload (more info ...)trojan-activity    URL
6050MALWARE-BACKDOOR fun factory runtime detection - upload (more info ...)trojan-activity    URL
6051MALWARE-BACKDOOR fun factory runtime detection - set volume (more info ...)trojan-activity    URL
6052MALWARE-BACKDOOR fun factory runtime detection - set volume (more info ...)trojan-activity    URL
6053MALWARE-BACKDOOR fun factory runtime detection - do script remotely (more info ...)trojan-activity    URL
6054MALWARE-BACKDOOR fun factory runtime detection - do script remotely (more info ...)trojan-activity    URL
6055MALWARE-BACKDOOR bifrose 1.1 runtime detection (more info ...)trojan-activity    URL
6056MALWARE-BACKDOOR bifrose 1.1 runtime detection (more info ...)trojan-activity    URL
6057MALWARE-BACKDOOR bifrose 1.1 runtime detection (more info ...)trojan-activity    URL
6058MALWARE-CNC neurotickat1.3 variant outbound connection icq notification (more info ...)trojan-activity    URL
6060MALWARE-BACKDOOR neurotickat1.3 runtime detection - initial connection (more info ...)trojan-activity    URL
6061MALWARE-BACKDOOR neurotickat1.3 runtime detection - initial connection (more info ...)trojan-activity    URL
6062MALWARE-BACKDOOR neurotickat1.3 runtime detection - initial connection (more info ...)trojan-activity    URL
6063MALWARE-BACKDOOR schwindler 1.82 runtime detection (more info ...)trojan-activity    URL
6064MALWARE-BACKDOOR schwindler 1.82 runtime detection (more info ...)trojan-activity    URL
6066MALWARE-BACKDOOR optixlite 1.0 runtime detection - connection success server-to-client (more info ...)trojan-activity    URL
6069MALWARE-CNC optixlite 1.0 variant outbound connection icq notification (more info ...)trojan-activity    URL
6070MALWARE-BACKDOOR freak 1.0 runtime detection - irc notification (more info ...)trojan-activity    URL
6071MALWARE-CNC freak 1.0 variant outbound connection icq notification (more info ...)trojan-activity    URL
6073MALWARE-BACKDOOR freak 1.0 runtime detection - initial connection server-to-client (more info ...)trojan-activity    URL
6074MALWARE-BACKDOOR xhx 1.6 runtime detection - initial connection client-to-server (more info ...)trojan-activity    URL
6075MALWARE-BACKDOOR xhx 1.6 runtime detection - initial connection server-to-client (more info ...)trojan-activity    URL
6076MALWARE-BACKDOOR amiboide uploader runtime detection - init connection (more info ...)trojan-activity    URL
6077MALWARE-BACKDOOR autospy runtime detection - get information (more info ...)trojan-activity    
6078MALWARE-BACKDOOR autospy runtime detection - get information (more info ...)trojan-activity    URL
6079MALWARE-BACKDOOR autospy runtime detection - show autospy (more info ...)trojan-activity    
6080MALWARE-BACKDOOR autospy runtime detection - show autospy (more info ...)trojan-activity    URL
6081MALWARE-BACKDOOR autospy runtime detection - show nude pic (more info ...)trojan-activity    
6082MALWARE-BACKDOOR autospy runtime detection - show nude pic (more info ...)trojan-activity    URL
6083MALWARE-BACKDOOR autospy runtime detection - hide taskbar (more info ...)trojan-activity    
6084MALWARE-BACKDOOR autospy runtime detection - hide taskbar (more info ...)trojan-activity    URL
6085MALWARE-BACKDOOR autospy runtime detection - make directory (more info ...)trojan-activity    
6086MALWARE-BACKDOOR autospy runtime detection - make directory (more info ...)trojan-activity    URL
6087MALWARE-BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity    
6088MALWARE-BACKDOOR a trojan 2.0 runtime detection - init connection (more info ...)trojan-activity    URL
6089MALWARE-BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity    
6090MALWARE-BACKDOOR a trojan 2.0 runtime detection - get memory info (more info ...)trojan-activity    URL
6091MALWARE-BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity    
6092MALWARE-BACKDOOR a trojan 2.0 runtime detection - get harddisk info (more info ...)trojan-activity    URL
6093MALWARE-BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity    
6094MALWARE-BACKDOOR a trojan 2.0 runtime detection - get drive info (more info ...)trojan-activity    URL
6095MALWARE-BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity    
6096MALWARE-BACKDOOR a trojan 2.0 runtime detection - get system info (more info ...)trojan-activity    URL
6097MALWARE-BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity    
6098MALWARE-BACKDOOR alvgus 2000 runtime detection - check server (more info ...)trojan-activity    URL
6099MALWARE-BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity    
6100MALWARE-BACKDOOR alvgus 2000 runtime detection - view content of directory (more info ...)trojan-activity    URL
6101MALWARE-BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity    
6102MALWARE-BACKDOOR alvgus 2000 runtime detection - execute command (more info ...)trojan-activity    URL
6103MALWARE-BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity    
6104MALWARE-BACKDOOR alvgus 2000 runtime detection - upload file (more info ...)trojan-activity    URL
6105MALWARE-BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity    
6106MALWARE-BACKDOOR alvgus 2000 runtime detection - download file (more info ...)trojan-activity    URL
6107MALWARE-BACKDOOR backage 3.1 runtime detection (more info ...)trojan-activity    URL
6108MALWARE-BACKDOOR dagger v1.1.40 runtime detection (more info ...)trojan-activity    URL
6109MALWARE-BACKDOOR dagger v1.1.40 runtime detection (more info ...)trojan-activity    URL
6110MALWARE-BACKDOOR forced entry v1.1 beta runtime detection (more info ...)trojan-activity    URL
6111MALWARE-BACKDOOR optix 1.32 runtime detection - init conn (more info ...)trojan-activity    URL
6112MALWARE-BACKDOOR optix 1.32 runtime detection - init conn (more info ...)trojan-activity    URL
6113MALWARE-BACKDOOR optix 1.32 runtime detection - init conn (more info ...)trojan-activity    URL
6114MALWARE-BACKDOOR optix 1.32 runtime detection - email notification (more info ...)trojan-activity    URL
6115MALWARE-CNC optix 1.32 variant outbound connection icq notification (more info ...)trojan-activity    URL
6116MALWARE-BACKDOOR fore v1.0 beta runtime detection - init conn (more info ...)trojan-activity    URL
6117MALWARE-BACKDOOR fore v1.0 beta runtime detection - init conn (more info ...)trojan-activity    URL
6118MALWARE-BACKDOOR net runner runtime detection - initial connection client-to-server (more info ...)trojan-activity    URL
6119MALWARE-BACKDOOR net runner runtime detection - initial connection server-to-client (more info ...)trojan-activity    URL
6120MALWARE-BACKDOOR net runner runtime detection - download file client-to-server (more info ...)trojan-activity    URL
6121MALWARE-BACKDOOR net runner runtime detection - download file server-to-client (more info ...)trojan-activity    URL
6122MALWARE-BACKDOOR millenium v1.0 runtime detection (more info ...)trojan-activity    URL
6123MALWARE-BACKDOOR ambush 1.0 runtime detection - ping client-to-server (more info ...)trojan-activity    URL
6124MALWARE-BACKDOOR ambush 1.0 runtime detection - ping server-to-client (more info ...)trojan-activity    URL
6127MALWARE-BACKDOOR dkangel runtime detection - udp client-to-server (more info ...)trojan-activity    URL
6129MALWARE-BACKDOOR chupacabra 1.0 runtime detection (more info ...)trojan-activity    
6130MALWARE-BACKDOOR chupacabra 1.0 runtime detection - get computer name (more info ...)trojan-activity    URL
6131MALWARE-BACKDOOR chupacabra 1.0 runtime detection (more info ...)trojan-activity    
6132MALWARE-BACKDOOR chupacabra 1.0 runtime detection - get user name (more info ...)trojan-activity    URL
6133MALWARE-BACKDOOR chupacabra 1.0 runtime detection - send messages (more info ...)trojan-activity    URL
6134MALWARE-BACKDOOR chupacabra 1.0 runtime detection - delete file (more info ...)trojan-activity    URL
6136MALWARE-BACKDOOR clindestine 1.0 runtime detection - capture big screen (more info ...)trojan-activity    URL
6137MALWARE-BACKDOOR clindestine 1.0 runtime detection - capture small screen (more info ...)trojan-activity    URL
6138MALWARE-BACKDOOR clindestine 1.0 runtime detection - get computer info (more info ...)trojan-activity    URL
6139MALWARE-BACKDOOR clindestine 1.0 runtime detection - get system directory (more info ...)trojan-activity    URL
6141MALWARE-BACKDOOR hellzaddiction v1.0e runtime detection - init conn (more info ...)trojan-activity    URL
6143MALWARE-BACKDOOR dark connection inside v1.2 runtime detection (more info ...)trojan-activity    URL
6144MALWARE-BACKDOOR mantis runtime detection - sent notify option client-to-server 1 (more info ...)trojan-activity    URL
6145MALWARE-BACKDOOR mantis runtime detection - sent notify option server-to-client (more info ...)trojan-activity    URL
6146MALWARE-BACKDOOR mantis runtime detection - sent notify option client-to-server 2 (more info ...)trojan-activity    URL
6147MALWARE-BACKDOOR mantis runtime detection - go to address client-to-server (more info ...)trojan-activity    URL
6148MALWARE-BACKDOOR mantis runtime detection - go to address server-to-client (more info ...)trojan-activity    URL
6149MALWARE-BACKDOOR netcontrol v1.0.8 runtime detection (more info ...)trojan-activity    URL
6150MALWARE-BACKDOOR netcontrol v1.0.8 runtime detection (more info ...)trojan-activity    URL
6151MALWARE-BACKDOOR back attack v1.4 runtime detection (more info ...)trojan-activity    URL
6152MALWARE-BACKDOOR dirtxt runtime detection - chdir client-to-server (more info ...)trojan-activity    URL
6153MALWARE-BACKDOOR dirtxt runtime detection - chdir server-to-client (more info ...)trojan-activity    URL
6154MALWARE-BACKDOOR dirtxt runtime detection - info client-to-server (more info ...)trojan-activity    URL
6155MALWARE-BACKDOOR dirtxt runtime detection - info server-to-client (more info ...)trojan-activity    URL
6156MALWARE-BACKDOOR dirtxt runtime detection - view client-to-server (more info ...)trojan-activity    URL
6157MALWARE-BACKDOOR dirtxt runtime detection - view server-to-client (more info ...)trojan-activity    URL
6159MALWARE-BACKDOOR delirium of disorder runtime detection - enable keylogger (more info ...)trojan-activity    URL
6160MALWARE-BACKDOOR delirium of disorder runtime detection - stop keylogger (more info ...)trojan-activity    URL
6161MALWARE-BACKDOOR furax 1.0 b2 runtime detection (more info ...)trojan-activity    URL
6164MALWARE-BACKDOOR psyrat 1.0 runtime detection (more info ...)trojan-activity    URL
6165MALWARE-BACKDOOR psyrat 1.0 runtime detection (more info ...)trojan-activity    URL
6166MALWARE-BACKDOOR unicorn runtime detection - initial connection (more info ...)trojan-activity    URL
6167MALWARE-BACKDOOR unicorn runtime detection - set wallpaper client-to-server (more info ...)trojan-activity    URL
6168MALWARE-BACKDOOR unicorn runtime detection - set wallpaper server-to-client (more info ...)trojan-activity    URL
6169MALWARE-BACKDOOR digital rootbeer runtime detection (more info ...)trojan-activity    URL
6170MALWARE-BACKDOOR digital rootbeer runtime detection (more info ...)trojan-activity    URL
6171MALWARE-BACKDOOR cookie monster 0.24 runtime detection (more info ...)trojan-activity    
6172MALWARE-BACKDOOR cookie monster 0.24 runtime detection - get version info (more info ...)trojan-activity    URL
6173MALWARE-BACKDOOR cookie monster 0.24 runtime detection (more info ...)trojan-activity    
6174MALWARE-BACKDOOR cookie monster 0.24 runtime detection - file explorer (more info ...)trojan-activity    URL
6175MALWARE-BACKDOOR cookie monster 0.24 runtime detection - kill kernel (more info ...)trojan-activity    URL
6176MALWARE-BACKDOOR guptachar 2.0 runtime detection (more info ...)trojan-activity    URL
6177MALWARE-BACKDOOR ultimate destruction runtime detection - kill process client-to-server (more info ...)trojan-activity    URL
6178MALWARE-BACKDOOR ultimate destruction runtime detection - kill windows client-to-server (more info ...)trojan-activity    URL
6179MALWARE-BACKDOOR bladerunner 0.80 runtime detection (more info ...)trojan-activity    URL
6180MALWARE-BACKDOOR netraider 0.0 runtime detection (more info ...)trojan-activity    URL
6181MALWARE-BACKDOOR netraider 0.0 runtime detection (more info ...)trojan-activity    URL
6183PUA-ADWARE Adware 180Search assistant runtime detection - tracked event URL (more info ...)misc-activity    URL
6184PUA-ADWARE Adware 180Search assistant runtime detection - config upload (more info ...)misc-activity    URL
6186MALWARE-CNC User-Agent known malicious user agent - SpywareStrike (more info ...)misc-activity    URL
6187PUA-ADWARE Adware ISTBar runtime detection - scripts (more info ...)misc-activity    URL
6188PUA-ADWARE Adware ISTBar runtime detection - bar (more info ...)misc-activity    URL
6189PUA-TOOLBARS Trackware try2find detection (more info ...)successful-recon-limited    URL
6190MALWARE-OTHER Keylogger eblaster 5.0 runtime detection (more info ...)successful-recon-limited    URL
6191PUA-TOOLBARS Trackware onetoolbar runtime detection (more info ...)successful-recon-limited    URL
6193PUA-ADWARE Adware seekmo runtime detection - pop up ads (more info ...)misc-activity    URL
6194PUA-ADWARE Adware seekmo runtime detection - config upload (more info ...)misc-activity    URL
6195PUA-ADWARE Adware seekmo runtime detection - download .cab (more info ...)misc-activity    URL
6196PUA-ADWARE Hijacker smart shopper outbound connection - services requests (more info ...)misc-activity    URL
6197MALWARE-CNC User-Agent known malicious user agent - smrtshpr-cs (more info ...)misc-activity    URL
6198MALWARE-CNC User-Agent known malicious user agent - SQTR_VERIFY (more info ...)successful-recon-limited    URL
6199PUA-ADWARE Hijacker smart search outbound connection - hijack/ads (more info ...)misc-activity    URL
6200PUA-ADWARE Hijacker smart search outbound connection - get settings (more info ...)misc-activity    URL
6201PUA-ADWARE Adware twaintec runtime detection (more info ...)misc-activity    URL
6203PUA-ADWARE Trickler farmmext outbound connection - drk.syn request (more info ...)misc-activity    URL
6204PUA-ADWARE Trickler farmmext outbound connection - track activity (more info ...)misc-activity    URL
6205MALWARE-TOOLS Hacker-Tool freak 88 das runtime detection (more info ...)misc-activity    URL
6206MALWARE-TOOLS Hacker-Tool sin stealer 1.1 runtime detection (more info ...)misc-activity    URL
6209PUA-ADWARE Adware deskwizz/zquest runtime detection - get config information / ad banner (more info ...)misc-activity    URL
6211PUA-ADWARE Adware deskwizz runtime detection - pop-up ad request (more info ...)misc-activity    URL
6212PUA-ADWARE Adware commonname runtime detection (more info ...)misc-activity    URL
6213PUA-ADWARE Hijacker 7fasst outbound connection - auto requests (more info ...)misc-activity    URL
6214PUA-ADWARE Hijacker 7fasst outbound connection - search (more info ...)misc-activity    URL
6215PUA-ADWARE Hijacker 7fasst outbound connection - track (more info ...)misc-activity    URL
6216PUA-ADWARE Adware aornum/iwon copilot runtime detection - config (more info ...)misc-activity    URL
6218PUA-ADWARE Adware aornum/iwon copilot runtime detection - ads (more info ...)misc-activity    URL
6219PUA-ADWARE Adware bonzibuddy runtime detection (more info ...)misc-activity    URL
6220MALWARE-OTHER Keylogger boss everyware runtime detection (more info ...)successful-recon-limited    URL
6221MALWARE-OTHER Keylogger computerspy runtime detection (more info ...)successful-recon-limited    URL
6222PUA-ADWARE Adware delfin media viewer runtime detection - contact server (more info ...)misc-activity    URL
6223PUA-ADWARE Adware delfin media viewer runtime detection - retrieve schedule (more info ...)misc-activity    URL
6224PUA-ADWARE Hijacker ieplugin outbound connection - search (more info ...)misc-activity    URL
6230PUA-TOOLBARS Hijacker i-lookup runtime detection (more info ...)misc-activity    URL
6233PUA-ADWARE Adware mirar runtime detection - delayed (more info ...)misc-activity    URL
6236PUA-ADWARE Adware lop runtime detection - pass info to server (more info ...)misc-activity    URL
6237PUA-ADWARE Adware lop runtime detection - check update request (more info ...)misc-activity    
6238PUA-ADWARE Adware lop runtime detection - collect info request 1 (more info ...)misc-activity    URL
6239PUA-ADWARE Adware lop runtime detection - collect info request 2 (more info ...)misc-activity    URL
6240PUA-ADWARE Adware lop runtime detection - pop up ads (more info ...)misc-activity    URL
6241PUA-ADWARE Adware lop runtime detection - ie autosearch hijack (more info ...)misc-activity    URL
6242PUA-ADWARE Hijacker coolwebsearch.cameup outbound connection (more info ...)misc-activity    URL
6243PUA-ADWARE Hijacker coolwebsearch cameup outbound connection - home page hijack (more info ...)misc-activity    URL
6244PUA-ADWARE Hijacker coolwebsearch cameup outbound connection - ie auto search hijack (more info ...)misc-activity    URL
6245PUA-ADWARE Hijacker coolwebsearch startpage outbound connection (more info ...)misc-activity    URL
6246PUA-ADWARE Hijacker exact navisearch outbound connection - search hijack (more info ...)misc-activity    URL
6247PUA-ADWARE Adware ezula toptext runtime detection - help redirect (more info ...)misc-activity    URL
6248PUA-ADWARE Adware ezula toptext runtime detection - popup (more info ...)misc-activity    URL
6249PUA-ADWARE Adware ezula toptext runtime detection - redirect (more info ...)misc-activity    URL
6250PUA-ADWARE Adware hotbar runtime detection - hotbar user-agent (more info ...)misc-activity    URL
6251PUA-ADWARE Adware hotbar runtime detection - hostie user-agent (more info ...)misc-activity    URL
6252PUA-TOOLBARS Trackware quicksearch toolbar runtime detection - search request (more info ...)successful-recon-limited    URL
6253PUA-TOOLBARS Trackware quicksearch toolbar runtime detection - log user ativity (more info ...)successful-recon-limited    URL
6254PUA-TOOLBARS Trackware quicksearch toolbar runtime detection - redirect (more info ...)successful-recon-limited    URL
6255PUA-TOOLBARS Trackware quicksearch toolbar runtime detection - update (more info ...)successful-recon-limited    URL
6256PUA-ADWARE Adware searchsquire installtime/auto-update (more info ...)misc-activity    URL
6257PUA-ADWARE Adware searchsquire runtime detection - testgeonew query (more info ...)misc-activity    URL
6258PUA-ADWARE Adware searchsquire runtime detection - get engine file (more info ...)misc-activity    URL
6259PUA-ADWARE Adware searchsquire runtime detection - search forward (more info ...)misc-activity    URL
6260PUA-ADWARE Adware overpro runtime detection (more info ...)misc-activity    URL
6261PUA-TOOLBARS Trickler slinkyslate toolbar runtime detection (more info ...)misc-activity    URL
6263PUA-ADWARE Hijacker gigatech superbar outbound connection - collect information (more info ...)misc-activity    URL
6264PUA-ADWARE Hijacker gigatech superbar outbound connection - self update - movie (more info ...)misc-activity    URL
6265PUA-ADWARE Hijacker gigatech superbar outbound connection - self update - engine (more info ...)misc-activity    URL
6266PUA-ADWARE Hijacker gigatech superbar outbound connection - self update - check update (more info ...)misc-activity    URL
6267PUA-ADWARE Hijacker gigatech superbar outbound connection - self update - get update (more info ...)misc-activity    URL
6268PUA-ADWARE Hijacker gigatech superbar outbound connection - self update - download exe (more info ...)misc-activity    URL
6269PUA-ADWARE Hijacker gigatech superbar outbound connection - track event (more info ...)misc-activity    URL
6270MALWARE-CNC User-Agent known malicious user agent - MyBrowser (more info ...)misc-activity    URL
6271PUA-ADWARE Trickler bundleware runtime detection (more info ...)misc-activity    URL
6274MALWARE-CNC User-Agent known malicious user agent - Stubby (more info ...)misc-activity    URL
6275PUA-ADWARE Hijacker incredifind outbound connection - cookie (more info ...)misc-activity    URL
6279PUA-ADWARE Hijacker sidefind outbound connection (more info ...)misc-activity    URL
6280PUA-ADWARE Hijacker sidefind outbound connection - cookie (more info ...)misc-activity    URL
6281MALWARE-CNC User-Agent known malicious user agent - istsvc (more info ...)misc-activity    URL
6282PUA-TOOLBARS Hijacker customtoolbar runtime detection (more info ...)misc-activity    URL
6283PUA-ADWARE Hijacker websearch outbound connection - sitereview (more info ...)misc-activity    URL
6284PUA-ADWARE Hijacker websearch outbound connection - webstat (more info ...)misc-activity    URL
6285MALWARE-BACKDOOR antilamer 1.1 runtime detection - set flowbit (more info ...)trojan-activity    URL
6286MALWARE-BACKDOOR antilamer 1.1 runtime detection (more info ...)trojan-activity    URL
6287MALWARE-BACKDOOR fictional daemon 4.4 runtime detection - telent (more info ...)trojan-activity    URL
6289MALWARE-BACKDOOR netspy runtime detection - command pattern client-to-server (more info ...)trojan-activity    URL
6291MALWARE-CNC justjoke v2.6 variant outbound connection (more info ...)trojan-activity    URL
6292MALWARE-BACKDOOR joker ddos v1.0.1 runtime detection - initial connection (more info ...)trojan-activity    URL
6293MALWARE-BACKDOOR joker ddos v1.0.1 runtime detection - bomb - initial flowbit (more info ...)trojan-activity    URL
6294MALWARE-BACKDOOR joker ddos v1.0.1 runtime detection - bomb - second flowbit (more info ...)trojan-activity    URL
6295MALWARE-BACKDOOR joker ddos v1.0.1 runtime detection - bomb (more info ...)trojan-activity    URL
6296MALWARE-CNC insurrection 1.1.0 variant outbound connection icq notification 1 (more info ...)trojan-activity    URL
6297MALWARE-CNC insurrection 1.1.0 variant outbound connection icq notification 2 (more info ...)trojan-activity    URL
6299MALWARE-BACKDOOR insurrection 1.1.0 runtime detection - initial connection (more info ...)trojan-activity    URL
6300MALWARE-CNC cia 1.3 variant outbound connection icq notification (more info ...)trojan-activity    URL
6302MALWARE-BACKDOOR cia runtime detection - initial connection - set flowbit (more info ...)trojan-activity    URL
6303MALWARE-BACKDOOR cia runtime detection - initial connection (more info ...)trojan-activity    URL
6304MALWARE-BACKDOOR softwar shadowthief runtime detection - initial connection - set flowbit (more info ...)trojan-activity    URL
6305MALWARE-BACKDOOR softwar shadowthief runtime detection - initial connection (more info ...)trojan-activity    URL
6306MALWARE-BACKDOOR shit heep runtime detection (more info ...)trojan-activity    URL
6307MALWARE-BACKDOOR lamespy runtime detection - initial connection - set flowbit (more info ...)trojan-activity    URL
6308MALWARE-BACKDOOR lamespy runtime detection - initial connection (more info ...)trojan-activity    URL
6312MALWARE-BACKDOOR net demon runtime detection - message send (more info ...)trojan-activity    URL
6313MALWARE-BACKDOOR net demon runtime detection - message response (more info ...)trojan-activity    
6314MALWARE-BACKDOOR net demon runtime detection - open browser request (more info ...)trojan-activity    URL
6315MALWARE-BACKDOOR net demon runtime detection - open browser response (more info ...)trojan-activity    
6316MALWARE-BACKDOOR net demon runtime detection - file manager request (more info ...)trojan-activity    URL
6317MALWARE-BACKDOOR net demon runtime detection - file manager response (more info ...)trojan-activity    
6318MALWARE-BACKDOOR rtb666 runtime detection (more info ...)trojan-activity    URL
6320MALWARE-BACKDOOR ptakks2.1 runtime detection - keepalive (more info ...)trojan-activity    URL
6321MALWARE-BACKDOOR ptakks2.1 runtime detection - keepalive acknowledgement (more info ...)trojan-activity    URL
6322MALWARE-BACKDOOR ptakks2.1 runtime detection - command pattern (more info ...)trojan-activity    URL
6323MALWARE-BACKDOOR 3xBackdoor runtime detection - set flowbit (more info ...)trojan-activity    URL
6324MALWARE-BACKDOOR 3xBackdoor runtime detection (more info ...)trojan-activity    URL
6325MALWARE-BACKDOOR fucktrojan 1.2 runtime detection - initial connection (more info ...)trojan-activity    URL
6326MALWARE-BACKDOOR fucktrojan 1.2 runtime detection - flood (more info ...)trojan-activity    
6327MALWARE-BACKDOOR fucktrojan 1.2 runtime detection - flood (more info ...)trojan-activity    URL
6328MALWARE-BACKDOOR commando runtime detection - initial connection (more info ...)trojan-activity    URL
6329MALWARE-BACKDOOR commando runtime detection - chat client-to-server (more info ...)trojan-activity    URL
6330MALWARE-BACKDOOR commando runtime detection - chat server-to-client (more info ...)trojan-activity    URL
6331MALWARE-CNC globalkiller1.0 variant outbound connection notification (more info ...)trojan-activity    URL
6332MALWARE-BACKDOOR globalkiller1.0 runtime detection - initial connection (more info ...)trojan-activity    URL
6333MALWARE-BACKDOOR wincrash 2.0 runtime detection (more info ...)trojan-activity    URL
6334MALWARE-BACKDOOR backlash runtime detection (more info ...)trojan-activity    URL
6335MALWARE-BACKDOOR buttman v0.9p runtime detection - remote control - set flowbit (more info ...)trojan-activity    URL
6336MALWARE-BACKDOOR buttman v0.9p runtime detection - remote control (more info ...)trojan-activity    URL
6337MALWARE-BACKDOOR hatredfriend file manage command - set flowbit (more info ...)trojan-activity    URL
6338MALWARE-BACKDOOR hatredfriend file manage command (more info ...)trojan-activity    URL
6339MALWARE-BACKDOOR hatredfriend email notification detection (more info ...)trojan-activity    URL
6340MALWARE-OTHER Keylogger handy keylogger runtime detection (more info ...)successful-recon-limited    URL
6341MALWARE-CNC User-Agent known malicious user agent - Spedia (more info ...)misc-activity    URL
6342PUA-ADWARE Hijacker spediabar outbound connection - info check (more info ...)misc-activity    URL
6344PUA-ADWARE Adware excite search bar runtime detection - config (more info ...)misc-activity    URL
6345PUA-ADWARE Adware excite search bar runtime detection - search (more info ...)misc-activity    URL
6346PUA-ADWARE Adware stationripper update detection (more info ...)misc-activity    URL
6347PUA-ADWARE Adware stationripper ad display detection (more info ...)misc-activity    URL
6348PUA-ADWARE Snoopware zenosearch outbound connection (more info ...)successful-recon-limited    URL
6349PUA-ADWARE Hijacker richfind update detection (more info ...)misc-activity    URL
6350PUA-ADWARE Hijacker richfind auto search redirect detection (more info ...)misc-activity    URL
6351PUA-ADWARE Hijacker adblock update detection (more info ...)misc-activity    URL
6352PUA-ADWARE Hijacker adblock auto search redirect detection (more info ...)misc-activity    URL
6353PUA-ADWARE Hijacker adblock ie search assistant redirect detection (more info ...)misc-activity    URL
6354MALWARE-CNC User-Agent known malicious user agent - ProxyDown (more info ...)misc-activity    URL
6355PUA-ADWARE Trickler wsearch outbound connection - mp3 search (more info ...)misc-activity    URL
6356PUA-ADWARE Trickler wsearch outbound connection - desktop search (more info ...)misc-activity    URL
6357MALWARE-CNC User-Agent known malicious user agent - Need2Find (more info ...)misc-activity    URL
6358PUA-ADWARE Hijacker need2find search query detection (more info ...)misc-activity    URL
6359PUA-ADWARE Adware altnet runtime detection - initial retrieval (more info ...)misc-activity    URL
6360PUA-ADWARE Adware altnet runtime detection - update (more info ...)misc-activity    URL
6361PUA-ADWARE Adware altnet runtime detection - status report (more info ...)misc-activity    URL
6362MALWARE-CNC User-Agent known malicious user agent - MGS-Internal-Web-Manager (more info ...)misc-activity    URL
6363MALWARE-CNC User-Agent known malicious user agent - SAcc (more info ...)misc-activity    URL
6364MALWARE-CNC User-Agent known malicious user agent - iMeshBar (more info ...)misc-activity    URL
6365MALWARE-OTHER Sony rootkit runtime detection (more info ...)misc-activity    URL
6366MALWARE-CNC User-Agent known malicious user agent - eAnthMngr (more info ...)misc-activity    URL
6367PUA-ADWARE Trickler eacceleration downloadreceiver outbound connection - stop-sign ads (more info ...)misc-activity    URL
6372PUA-ADWARE Trickler spyblocs eblocs detection - get wsliveup.dat (more info ...)misc-activity    URL
6373PUA-ADWARE Trickler spyblocs eblocs detection - stbarpat.dat (more info ...)misc-activity    URL
6374PUA-ADWARE Trickler spyblocs eblocs detection - get spyblpat.dat/spyblini.ini (more info ...)misc-activity    URL
6375PUA-ADWARE Trickler spyblocs.eblocs detection - register request (more info ...)misc-activity    URL
6376PUA-TOOLBARS Hijacker girafa toolbar - toolbar update (more info ...)misc-activity    URL
6377PUA-TOOLBARS Hijacker girafa toolbar - browser hijack (more info ...)misc-activity    URL
6378PUA-ADWARE Hijacker adbars outbound connection - homepage hijack (more info ...)misc-activity    URL
6379PUA-TOOLBARS Hijacker adbars runtime detection - search in toolbar (more info ...)misc-activity    URL
6380PUA-TOOLBARS Hijacker dotcomtoolbar runtime detection - toolbar information retrieve (more info ...)misc-activity    URL
6381PUA-TOOLBARS Hijacker dotcomtoolbar runtime detection - search in toolbar (more info ...)misc-activity    URL
6382PUA-TOOLBARS Hijacker dotcomtoolbar runtime detection - url hook (more info ...)misc-activity    URL
6383MALWARE-OTHER Keylogger stealthwatcher 2000 runtime detection - tcp connection setup (more info ...)successful-recon-limited    URL
6385MALWARE-OTHER Keylogger stealthwatcher 2000 runtime detection - agent status monitoring (more info ...)successful-recon-limited    URL
6386MALWARE-OTHER Keylogger stealthwatcher 2000 runtime detection - agent up notification (more info ...)successful-recon-limited    URL
6387PUA-ADWARE Hijacker internet optimizer outbound connection - autosearch hijack (more info ...)misc-activity    URL
6388PUA-ADWARE Hijacker internet optimizer outbound connection - error page hijack (more info ...)misc-activity    URL
6389PUA-ADWARE Adware esyndicate runtime detection - postinstall request (more info ...)misc-activity    URL
6390PUA-ADWARE Adware esyndicate runtime detection - ads popup (more info ...)misc-activity    
6391PUA-ADWARE Adware esyndicate runtime detection - ads popup (more info ...)misc-activity    URL
6392PUA-ADWARE Hijacker zeropopup outbound connection (more info ...)misc-activity    URL
6394MALWARE-CNC User-Agent known malicious user agent - CodeguruBrowser (more info ...)misc-activity    URL
6395MALWARE-CNC a-311 death variant outbound connection server-to-client (more info ...)trojan-activity    URL
6396MALWARE-CNC a-311 death user-agent string detected (more info ...)trojan-activity    URL
6398MALWARE-BACKDOOR http rat runtime detection - http (more info ...)trojan-activity    URL
6399MALWARE-BACKDOOR rad 1.2.3 runtime detection (more info ...)trojan-activity    URL
6400MALWARE-BACKDOOR snowdoor runtime detection client-to-server (more info ...)trojan-activity    URL
6401MALWARE-BACKDOOR snowdoor runtime detection server-to-client (more info ...)trojan-activity    URL
6402MALWARE-BACKDOOR netangel connection client-to-server (more info ...)trojan-activity    URL
6403SERVER-WEBAPP horde help module arbitrary command execution attempt (more info ...)web-application-attack 2006-1491 17292  
6408POLICY-SOCIAL webshots desktop traffic (more info ...)misc-activity    URL
6469SERVER-OTHER RealVNC connection attempt (more info ...)protocol-command-decode    
6470SERVER-OTHER RealVNC authentication types without None type sent attempt (more info ...)protocol-command-decode    
6472MALWARE-BACKDOOR bugs runtime detection - file manager client-to-server (more info ...)trojan-activity    URL
6473MALWARE-BACKDOOR bugs runtime detection - file manager server-to-client (more info ...)trojan-activity    URL
6474MALWARE-CNC Win.Trojan.loosky.gen variant outbound connection notification (more info ...)trojan-activity    URL
6475MALWARE-BACKDOOR badrat 1.1 runtime detection - flowbit set (more info ...)trojan-activity    URL
6476MALWARE-BACKDOOR badrat 1.1 runtime detection (more info ...)trojan-activity    URL
6478PUA-TOOLBARS Trackware searchingall toolbar runtime detection - send user url request (more info ...)successful-recon-limited    URL
6479PUA-ADWARE Snoopware totalvelocity zsearch outbound connection (more info ...)successful-recon-limited    URL
6480PUA-ADWARE Hijacker cws.cameup outbound connection - home page (more info ...)misc-activity    URL
6481PUA-ADWARE Hijacker cws.cameup outbound connection - search (more info ...)misc-activity    URL
6482PUA-TOOLBARS Hijacker makemesearch toolbar runtime detection - get info (more info ...)misc-activity    URL
6483PUA-TOOLBARS Hijacker makemesearch toolbar runtime detection - home page hijacker (more info ...)misc-activity    URL
6484PUA-TOOLBARS Hijacker makemesearch toolbar runtime detection - search (more info ...)misc-activity    URL
6487PUA-TOOLBARS Adware searchnugget toolbar runtime detection - check updates (more info ...)misc-activity    URL
6488PUA-TOOLBARS Adware searchnugget toolbar runtime detection - redirect mistyped urls (more info ...)misc-activity    URL
6489PUA-ADWARE Hijacker analyze IE outbound connection - default page hijacker (more info ...)misc-activity    URL
6491MALWARE-CNC User-Agent known malicious user agent - snprtzdialno (more info ...)misc-activity    URL
6492MALWARE-BACKDOOR Trickler Backdoor-BAC.gen.e runtime detection - notification (more info ...)misc-activity    URL
6493MALWARE-BACKDOOR Trickler Backdoor-BAC.gen.e runtime detection - post data (more info ...)misc-activity    URL
6494PUA-ADWARE Adware yourenhancement runtime detection (more info ...)misc-activity    URL
6495PUA-ADWARE Hijacker troj_spywad.x outbound connection (more info ...)misc-activity    URL
6496PUA-ADWARE Adware adpowerzone runtime detection (more info ...)misc-activity    URL
6497MALWARE-BACKDOOR exploiter 1.0 runtime detection (more info ...)trojan-activity    URL
6498MALWARE-BACKDOOR exploiter 1.0 runtime detection (more info ...)trojan-activity    URL
6499MALWARE-BACKDOOR omerta 1.3 runtime detection (more info ...)trojan-activity    URL
6500MALWARE-BACKDOOR omerta 1.3 runtime detection (more info ...)trojan-activity    URL
6511SERVER-WEBAPP ALT-N WebAdmin user param overflow attempt (more info ...)attempted-admin 2003-0471 8024  
6513PROTOCOL-VOIP Digium Asterisk IAX2 truncated video mini-frame packet overflow attempt (more info ...)attempted-admin 2006-2898 18295  
6514PROTOCOL-VOIP Digium Asterisk IAX2 truncated full-frame packet overflow attempt (more info ...)attempted-admin 2006-2923 18307  
6515PROTOCOL-VOIP Digium Asterisk IAX2 truncated mini-frame packet overflow attempt (more info ...)attempted-admin 2006-2923 18307  
7049PUA-ADWARE Hijacker extreme biz outbound connection - uniq1 (more info ...)misc-activity    URL
7050PUA-TOOLBARS Hijacker freecruise toolbar runtime detection (more info ...)misc-activity    
7051PUA-ADWARE Trickler generic downloader.g outbound connection - spyware injection (more info ...)misc-activity    URL
7052PUA-ADWARE Trickler generic downloader.g outbound connection - adv (more info ...)misc-activity    URL
7053PUA-ADWARE Adware webredir runtime detection (more info ...)misc-activity    URL
7054PUA-ADWARE Trickler download arq variant outbound connection (more info ...)misc-activity    URL
7055PUA-ADWARE Hijacker vip01 biz outbound connection - adv (more info ...)misc-activity    URL
7057MALWARE-BACKDOOR charon runtime detection - initial connection (more info ...)trojan-activity    URL
7058MALWARE-BACKDOOR charon runtime detection - download file flowbit 1 (more info ...)trojan-activity    URL
7059MALWARE-BACKDOOR charon runtime detection - download file/log flowbit 2 (more info ...)trojan-activity    URL
7060MALWARE-BACKDOOR charon runtime detection - download file/log (more info ...)trojan-activity    URL
7061MALWARE-BACKDOOR charon runtime detection - download log flowbit 1 (more info ...)trojan-activity    URL
7064MALWARE-BACKDOOR cybernetic 1.62 runtime detection - email notification (more info ...)trojan-activity    URL
7065MALWARE-BACKDOOR cybernetic 1.62 runtime detection - reverse connection flowbit 1 (more info ...)trojan-activity    URL
7068MALWARE-BACKDOOR delta source 0.5 beta runtime detection - ping (more info ...)trojan-activity    URL
7069MALWARE-BACKDOOR delta source 0.5 beta runtime detection - pc info (more info ...)trojan-activity    URL
7072MALWARE-BACKDOOR fraggle rock 2.0 lite runtime detection - pc info (more info ...)trojan-activity    URL
7073MALWARE-CNC Win.Trojan.dumaru.gen variant outbound connection notification (more info ...)trojan-activity    URL
7074MALWARE-CNC Win.Trojan.dumaru.gen variant outbound connection cmd (more info ...)trojan-activity    URL
7075MALWARE-BACKDOOR bandook 1.0 runtime detection (more info ...)trojan-activity    URL
7077MALWARE-CNC minimo v0.6 variant outbound connection icq notification (more info ...)trojan-activity    
7078MALWARE-BACKDOOR up and run v1.0 beta runtime detection flowbit 1 (more info ...)trojan-activity    URL
7079MALWARE-BACKDOOR up and run v1.0 beta runtime detection flowbit 2 (more info ...)trojan-activity    URL
7080MALWARE-BACKDOOR up and run v1.0 beta runtime detection flowbit 3 (more info ...)trojan-activity    URL
7081MALWARE-BACKDOOR up and run v1.0 beta runtime detection (more info ...)trojan-activity    URL
7082MALWARE-BACKDOOR mosucker3.0 runtime detection - client-to-server (more info ...)trojan-activity    URL
7083MALWARE-BACKDOOR mosucker3.0 runtime detection - server-to-client1 (more info ...)trojan-activity    URL
7084MALWARE-BACKDOOR erazer v1.1 runtime detection - sin notification (more info ...)trojan-activity    URL
7085MALWARE-BACKDOOR erazer v1.1 runtime detection (more info ...)trojan-activity    URL
7086MALWARE-BACKDOOR erazer v1.1 runtime detection - init connection (more info ...)trojan-activity    URL
7101MALWARE-BACKDOOR gwboy 0.92 runtime detection (more info ...)trojan-activity    URL
7103MALWARE-CNC gwboy 0.92 variant outbound connection (more info ...)trojan-activity    URL
7104MALWARE-BACKDOOR aol admin runtime detection (more info ...)trojan-activity    URL
7106MALWARE-BACKDOOR girlfriend runtime detection (more info ...)trojan-activity    URL
7107MALWARE-BACKDOOR girlfriend runtime detection (more info ...)trojan-activity    URL
7113MALWARE-BACKDOOR Win.Trojan.DonaldDick variant inbound connection detection (more info ...)trojan-activity    URL
7114MALWARE-BACKDOOR Win.Trojan.DonaldDick variant outbound connection detection (more info ...)trojan-activity    URL
7116MALWARE-CNC y3k 1.2 variant outbound connection icq notification (more info ...)trojan-activity    URL
7118MALWARE-CNC y3k 1.2 variant outbound connection user-agent string detected (more info ...)trojan-activity    URL
7119MALWARE-BACKDOOR y3k 1.2 runtime detection (more info ...)trojan-activity    URL
7120MALWARE-BACKDOOR y3k 1.2 runtime detection - init connection 1 (more info ...)trojan-activity    URL
7121MALWARE-BACKDOOR y3k 1.2 runtime detection (more info ...)trojan-activity    URL
7122MALWARE-BACKDOOR y3k 1.2 runtime detection - init connection 2 (more info ...)trojan-activity    URL
7123PUA-ADWARE Other-Technologies alfacleaner outbound connection - update (more info ...)misc-activity    URL
7124PUA-ADWARE Other-Technologies alfacleaner outbound connection - buy (more info ...)misc-activity    URL
7125PUA-ADWARE Hijacker traffbest biz outbound connection - adv (more info ...)misc-activity    URL
7126PUA-ADWARE Hijacker trojan proxy atiup outbound connection - notification (more info ...)misc-activity    URL
7127PUA-ADWARE Hijacker wowok mp3 bar outbound connection - tracking (more info ...)misc-activity    
7128PUA-ADWARE Hijacker wowok mp3 bar outbound connection - advertising 1 (more info ...)misc-activity    
7129PUA-ADWARE Hijacker wowok mp3 bar outbound connection - advertising 2 (more info ...)misc-activity    
7130PUA-ADWARE Hijacker wowok mp3 bar outbound connection - search assissant hijacking (more info ...)misc-activity    
7135MALWARE-CNC User-Agent known malicious user agent - IEP (more info ...)misc-activity    URL
7136PUA-ADWARE Hijacker dsrch outbound connection - search assistant redirect (more info ...)misc-activity    URL
7137PUA-ADWARE Hijacker dsrch outbound connection - side search redirect (more info ...)misc-activity    URL
7138PUA-ADWARE Other-Technologies clicktrojan outbound connection - version check (more info ...)misc-activity    URL
7139PUA-ADWARE Other-Technologies clicktrojan outbound connection - fake search query (more info ...)misc-activity    URL
7140PUA-ADWARE Adware pay-per-click runtime detection - configuration (more info ...)misc-activity    URL
7141PUA-ADWARE Adware pay-per-click runtime detection - update (more info ...)misc-activity    URL
7143PUA-ADWARE Adware digink.com runtime detection (more info ...)misc-activity    URL
7144PUA-ADWARE Hijacker cool search outbound connection (more info ...)misc-activity    URL
7145MALWARE-CNC User-Agent known malicious user agent - adfsgecoiwnf (more info ...)misc-activity    URL
7147MALWARE-CNC Hacker-Tool sars notifier variant outbound connection icq notification (more info ...)misc-activity    URL
7150MALWARE-CNC Hacker-Tool sars notifier variant outbound connection irc notification (more info ...)misc-activity    URL
7151MALWARE-CNC Hacker-Tool sars notifier variant outbound connection net send notification (more info ...)misc-activity    URL
7152PUA-ADWARE Hijacker cnsmin 3721 outbound connection - installation (more info ...)misc-activity    URL
7153PUA-ADWARE Hijacker cnsmin 3721 outbound connection - hijacking (more info ...)misc-activity    URL
7154MALWARE-OTHER Keylogger active keylogger home runtime detection (more info ...)successful-recon-limited    URL
7155PUA-ADWARE Trickler jubster outbound connection (more info ...)misc-activity    URL
7156MALWARE-OTHER Keylogger win-spy runtime detection - email delivery (more info ...)successful-recon-limited    URL
7157MALWARE-OTHER Keylogger win-spy runtime detection - remote conn client-to-server (more info ...)successful-recon-limited    URL
7158MALWARE-OTHER Keylogger win-spy runtime detection - remote conn server-to-client (more info ...)successful-recon-limited    URL
7159MALWARE-OTHER Keylogger win-spy runtime detection - upload file client-to-server (more info ...)successful-recon-limited    URL
7160MALWARE-OTHER Keylogger win-spy runtime detection - upload file server-to-client (more info ...)successful-recon-limited    URL
7161MALWARE-OTHER Keylogger win-spy runtime detection - download file client-to-server (more info ...)successful-recon-limited    URL
7162MALWARE-OTHER Keylogger win-spy runtime detection - download file server-to-client (more info ...)successful-recon-limited    URL
7163MALWARE-OTHER Keylogger win-spy runtime detection - execute file client-to-server (more info ...)successful-recon-limited    URL
7164MALWARE-OTHER Keylogger win-spy runtime detection - execute file server-to-client (more info ...)successful-recon-limited    URL
7175MALWARE-OTHER Keylogger ab system spy runtime detection - log retrieve (more info ...)successful-recon-limited    URL
7176MALWARE-OTHER Keylogger ab system spy runtime detection - log retrieve (more info ...)successful-recon-limited    URL
7177MALWARE-OTHER Keylogger ab system spy runtime detection - info send through email (more info ...)successful-recon-limited    URL
7178MALWARE-OTHER Keylogger desktop detective 2000 runtime detection - init connection (more info ...)successful-recon-limited    URL
7179MALWARE-OTHER Keylogger desktop detective 2000 runtime detection - init connection (more info ...)successful-recon-limited    URL
7180MALWARE-OTHER Keylogger desktop detective 2000 runtime detection - init connection (more info ...)successful-recon-limited    URL
7183MALWARE-CNC Snoopware barok variant outbound connection (more info ...)successful-recon-limited    URL
7186MALWARE-OTHER Keylogger kgb Keylogger runtime detection (more info ...)successful-recon-limited    URL
7187MALWARE-CNC User-Agent known malicious user agent - SAH Agent (more info ...)successful-recon-limited    URL
7188PUA-ADWARE Hijacker shop at home select - merchant redirect in progress (more info ...)successful-recon-limited    URL
7189MALWARE-OTHER Trackware shopathome runtime detection - setcookie request (more info ...)successful-recon-limited    URL
7190PUA-ADWARE Adware trustyfiles v3.1.0.1 runtime detection - host retrieval (more info ...)misc-activity    URL
7191PUA-ADWARE Adware trustyfiles v3.1.0.1 runtime detection - url retrieval (more info ...)misc-activity    URL
7192PUA-ADWARE Adware trustyfiles v3.1.0.1 runtime detection - sponsor selection (more info ...)misc-activity    URL
7193PUA-ADWARE Adware trustyfiles v3.1.0.1 runtime detection - startup access (more info ...)misc-activity    URL
7194PUA-ADWARE Hijacker shopprreports outbound connection - services requests (more info ...)misc-activity    URL
7195MALWARE-CNC User-Agent known malicious user agent - shprrprt-cs- (more info ...)misc-activity    URL
7206SERVER-ORACLE DBMS_EXPORT_EXTENSION access attempt (more info ...)attempted-user    
7208SERVER-ORACLE DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_METADATA access attempt (more info ...)attempted-user 2006-2081 17699  
7421SERVER-ORACLE DBMS_EXPORT_EXTENSION.GET_V2_DOMAIN_INDEX_TABLES access attempt (more info ...)attempted-user 2006-1887 17590  
7506MALWARE-TOOLS Hacker-Tool coma runtime detection - init connection - flowbit set (more info ...)misc-activity    
7507MALWARE-TOOLS Hacker-Tool coma runtime detection - init connection (more info ...)misc-activity    URL
7508MALWARE-TOOLS Hacker-Tool coma runtime detection - ping - flowbit set (more info ...)misc-activity    
7509MALWARE-TOOLS Hacker-Tool coma runtime detection - ping (more info ...)misc-activity    URL
7510PUA-ADWARE Trickler edonkey2000 outbound connection - version verification (more info ...)misc-activity    URL
7511MALWARE-CNC User-Agent known malicious user agent - ed2k edonkey2000 runtime detection (more info ...)misc-activity    URL
7512MALWARE-OTHER Keylogger watchdog runtime detection - init connection - flowbit set (more info ...)successful-recon-limited    URL
7513MALWARE-OTHER Keylogger watchdog runtime detection - init connection (more info ...)successful-recon-limited    URL
7514MALWARE-OTHER Keylogger watchdog runtime detection - send out info to server periodically (more info ...)successful-recon-limited    URL
7515MALWARE-OTHER Keylogger watchdog runtime detection - remote monitoring (more info ...)successful-recon-limited    URL
7516PUA-TOOLBARS Trickler hmtoolbar runtime detection (more info ...)misc-activity    URL
7518PUA-TOOLBARS Trackware earthlink toolbar runtime detection - get up-to-date news info (more info ...)successful-recon-limited    URL
7520PUA-TOOLBARS Trackware earthlink toolbar runtime detection - ie autosearch hijack (more info ...)successful-recon-limited    URL
7521PUA-TOOLBARS Trackware earthlink toolbar runtime detection - search toolbar request 1 (more info ...)successful-recon-limited    URL
7522PUA-TOOLBARS Trackware earthlink toolbar runtime detection - search toolbar request 2 (more info ...)successful-recon-limited    URL
7525PUA-TOOLBARS Trackware hotblox toolbar runtime detection - barad.asp request (more info ...)successful-recon-limited    URL
7526PUA-TOOLBARS Trackware hotblox toolbar runtime detection - stat counter (more info ...)successful-recon-limited    URL
7527PUA-TOOLBARS Trackware hotblox toolbar runtime detection - toolbar find function (more info ...)successful-recon-limited    URL
7528PUA-TOOLBARS Trackware hotblox toolbar runtime detection - ie autosearch hijack (more info ...)successful-recon-limited    URL
7529PUA-ADWARE Snoopware halflife jacker outbound connection (more info ...)successful-recon-limited    URL
7530PUA-ADWARE Trickler mediaseek.pl client outbound connection - trickler (more info ...)misc-activity    URL
7531PUA-ADWARE Trickler mediaseek.pl client outbound connection - login (more info ...)misc-activity    URL
7532PUA-ADWARE Adware piolet runtime detection - user-agent (more info ...)misc-activity    URL
7533PUA-ADWARE Adware piolet runtime detection - ads request (more info ...)misc-activity    URL
7535PUA-ADWARE Hijacker clearsearch variant outbound connection - pass information (more info ...)misc-activity    URL
7536PUA-ADWARE Hijacker clearsearch variant outbound connection - popup (more info ...)misc-activity    URL
7537MALWARE-CNC User-Agent known malicious user agent - Arrow Search (more info ...)successful-recon-limited    URL
7538PUA-ADWARE Screen-Scraper hidden camera outbound connection (more info ...)successful-recon-limited    URL
7540MALWARE-CNC User-Agent known malicious user agent - http protocol (more info ...)misc-activity    URL
7541MALWARE-OTHER Keylogger starlogger runtime detection (more info ...)successful-recon-limited    URL
7542MALWARE-TOOLS Hacker-Tool mini oblivion runtime detection - successful init connection (more info ...)misc-activity    URL
7543PUA-ADWARE Hijacker 2020search outbound connection (more info ...)misc-activity    URL
7544MALWARE-OTHER Keylogger PerfectKeylogger runtime detection - flowbit set 1 (more info ...)successful-recon-limited    URL
7545MALWARE-OTHER Keylogger PerfectKeylogger runtime detection - flowbit set 2 (more info ...)successful-recon-limited    URL
7546MALWARE-OTHER Keylogger PerfectKeylogger runtime detection (more info ...)successful-recon-limited    URL
7547MALWARE-OTHER Keylogger activity monitor 3.8 runtime detection - agent status monitoring (more info ...)successful-recon-limited    URL
7548MALWARE-OTHER Keylogger activity monitor 3.8 runtime detection - agent up notification (more info ...)successful-recon-limited    URL
7549MALWARE-OTHER Keylogger activity monitor 3.8 runtime detection (more info ...)successful-recon-limited    URL
7550PUA-ADWARE Adware adroar runtime detection (more info ...)misc-activity    URL
7553PUA-ADWARE Adware hxdl runtime detection - hxlogonly user-agent (more info ...)misc-activity    URL
7554PUA-ADWARE Adware hxdl runtime detection - hxdownload user-agent (more info ...)misc-activity    URL
7556PUA-ADWARE Hijacker blazefind outbound connection - search bar (more info ...)misc-activity    URL
7557MALWARE-OTHER Trackware purityscan runtime detection - start up (more info ...)successful-recon-limited    URL
7558MALWARE-OTHER Trackware purityscan runtime detection - installation notify (more info ...)successful-recon-limited    URL
7559MALWARE-OTHER Trackware purityscan runtime detection - track user activity and status (more info ...)successful-recon-limited    URL
7560MALWARE-OTHER Trackware purityscan runtime detection - self update (more info ...)successful-recon-limited    URL
7561MALWARE-OTHER Trackware purityscan runtime detection - opt out of interstitial advertising (more info ...)successful-recon-limited    URL
7562PUA-ADWARE Adware morpheus runtime detection - ad 1 (more info ...)misc-activity    URL
7563PUA-ADWARE Adware morpheus runtime detection - ad 2 (more info ...)misc-activity    URL
7564PUA-ADWARE Hijacker startnow outbound connection (more info ...)misc-activity    URL
7565PUA-ADWARE Hijacker adshooter.searchforit outbound connection - search engine (more info ...)misc-activity    URL
7566PUA-ADWARE Hijacker adshooter.searchforit outbound connection - redirector (more info ...)misc-activity    URL
7568MALWARE-OTHER Trackware webhancer runtime detection (more info ...)successful-recon-limited    URL
7569PUA-ADWARE Adware lordofsearch runtime detection (more info ...)misc-activity    URL
7570PUA-ADWARE Hijacker linkspider search bar outbound connection - ads (more info ...)misc-activity    URL
7571PUA-TOOLBARS Hijacker linkspider search bar runtime detection - toolbar search (more info ...)misc-activity    URL
7573PUA-ADWARE Trickler album galaxy outbound connection - p2p gnutella (more info ...)misc-activity    URL
7574MALWARE-OTHER Keylogger proagent 2.0 runtime detection (more info ...)successful-recon-limited    URL
7575PUA-TOOLBARS Hijacker starware toolbar runtime detection - weather request (more info ...)misc-activity    URL
7576PUA-TOOLBARS Hijacker starware toolbar runtime detection - hijack ie browser (more info ...)misc-activity    URL
7577PUA-TOOLBARS Hijacker starware toolbar runtime detection - collect information (more info ...)misc-activity    URL
7578PUA-TOOLBARS Hijacker starware toolbar runtime detection - reference (more info ...)misc-activity    URL
7579PUA-TOOLBARS Hijacker starware toolbar runtime detection - smileys (more info ...)misc-activity    URL
7580PUA-TOOLBARS Hijacker starware toolbar runtime detection - update (more info ...)misc-activity    URL
7582MALWARE-CNC User-Agent known malicious user agent - Pcast Live (more info ...)misc-activity    URL
7583MALWARE-TOOLS Hacker-Tool clandestine runtime detection - flowbit set big (more info ...)misc-activity    URL
7584MALWARE-TOOLS Hacker-Tool clandestine runtime detection - flowbit set open (more info ...)misc-activity    URL
7585MALWARE-TOOLS Hacker-Tool clandestine runtime detection - flowbit set image (more info ...)misc-activity    URL
7586MALWARE-TOOLS Hacker-Tool clandestine runtime detection - image transferred (more info ...)misc-activity    URL
7587MALWARE-CNC User-Agent known malicious user agent - URLBlaze (more info ...)misc-activity    URL
7588PUA-ADWARE Trickler urlblaze outbound connection - files search or download (more info ...)misc-activity    URL
7589PUA-ADWARE Trickler urlblaze outbound connection - irc notification (more info ...)misc-activity    URL
7590PUA-TOOLBARS Hijacker swbar runtime detection (more info ...)misc-activity    URL
7591MALWARE-OTHER Keylogger keylogger pro runtime detection - flowbit set (more info ...)successful-recon-limited    URL
7592MALWARE-OTHER Keylogger keylogger pro runtime detection (more info ...)successful-recon-limited    URL
7593PUA-TOOLBARS Trackware trellian toolbarbrowser runtime detection (more info ...)successful-recon-limited    URL
7594PUA-ADWARE Adware comedy planet runtime detection - ads (more info ...)misc-activity    URL
7595PUA-ADWARE Adware comedy planet runtime detection - collect user information (more info ...)misc-activity    URL
7596MALWARE-OTHER Keylogger spy lantern keylogger runtime detection - flowbit set (more info ...)successful-recon-limited    URL
7597MALWARE-OTHER Keylogger spy lantern keylogger runtime detection (more info ...)successful-recon-limited    URL
7598PUA-TOOLBARS Snoopware 2-seek runtime detection - search in toolbar (more info ...)successful-recon-limited    URL
7599PUA-TOOLBARS Snoopware 2-seek runtime detection - user info collection (more info ...)successful-recon-limited    URL
7600PUA-ADWARE Hijacker adtraffic outbound connection - notfound website search hijack and redirection (more info ...)misc-activity    URL
7601PUA-ADWARE Snoopware big brother v3.5.1 outbound connection - connect to keyserver (more info ...)successful-recon-limited    URL
7602PUA-ADWARE Snoopware big brother v3.5.1 outbound connection - connect to receiver - flowbit set (more info ...)successful-recon-limited    URL
7603PUA-ADWARE Snoopware big brother v3.5.1 outbound connection - connect to receiver (more info ...)successful-recon-limited    URL
7604MALWARE-BACKDOOR katux 2.0 runtime detection - screen capture - flowbit set (more info ...)trojan-activity    
7605MALWARE-BACKDOOR katux 2.0 runtime detection - screen capture (more info ...)trojan-activity    URL
7606MALWARE-BACKDOOR katux 2.0 runtime detection - get system info - flowbit set (more info ...)trojan-activity    
7607MALWARE-BACKDOOR katux 2.0 runtime detection - get system info (more info ...)trojan-activity    URL
7608MALWARE-BACKDOOR katux 2.0 runtime detection - chat - flowbit set (more info ...)trojan-activity    
7609MALWARE-BACKDOOR katux 2.0 runtime detection - chat (more info ...)trojan-activity    URL
7620MALWARE-BACKDOOR remote control 1.7 runtime detection - connection request flowbit 1 (more info ...)trojan-activity    
7621MALWARE-BACKDOOR remote control 1.7 runtime detection - connection request - flowbit 2 (more info ...)trojan-activity    
7622MALWARE-BACKDOOR remote control 1.7 runtime detection - connection request - flowbit 3 (more info ...)trojan-activity    
7623MALWARE-BACKDOOR remote control 1.7 runtime detection - connection request (more info ...)trojan-activity    URL
7624MALWARE-BACKDOOR remote control 1.7 runtime detection - data connection (more info ...)trojan-activity    URL
7625MALWARE-BACKDOOR skyrat show runtime detection - initial connection - flowbit 1 (more info ...)trojan-activity    
7626MALWARE-BACKDOOR skyrat show runtime detection - initial connection - flowbit 2 (more info ...)trojan-activity    
7627MALWARE-BACKDOOR skyrat show runtime detection - initial connection - flowbit 3 (more info ...)trojan-activity    
7628MALWARE-BACKDOOR skyrat show runtime detection - initial connection - flowbit 4 (more info ...)trojan-activity    
7629MALWARE-BACKDOOR skyrat show runtime detection - initial connection (more info ...)trojan-activity    URL
7630MALWARE-BACKDOOR helios 3.1 runtime detection - initial connection (more info ...)trojan-activity    URL
7631MALWARE-BACKDOOR hornet 1.0 runtime detection - fetch system info - flowbit set (more info ...)trojan-activity    URL
7632MALWARE-BACKDOOR hornet 1.0 runtime detection - fetch system info (more info ...)trojan-activity    URL
7633MALWARE-BACKDOOR hornet 1.0 runtime detection - irc connection - flowbit set (more info ...)trojan-activity    URL
7634MALWARE-BACKDOOR hornet 1.0 runtime detection - irc connection (more info ...)trojan-activity    URL
7635MALWARE-BACKDOOR hornet 1.0 runtime detection - fetch process list - flowbit set (more info ...)trojan-activity    URL
7636MALWARE-BACKDOOR hornet 1.0 runtime detection - fetch processes list (more info ...)trojan-activity    URL
7637MALWARE-CNC hornet 1.0 variant outbound connection icq notification (more info ...)trojan-activity    URL
7638MALWARE-BACKDOOR Win.Exploit.Backdoor ncph runtime detection - initial connection (more info ...)trojan-activity    URL
7640MALWARE-CNC air variant outbound connection webmail notification (more info ...)trojan-activity    URL
7641MALWARE-BACKDOOR am remote client runtime detection - client-to-server (more info ...)trojan-activity    URL
7642MALWARE-BACKDOOR am remote client runtime detection - client response (more info ...)trojan-activity    URL
7643MALWARE-BACKDOOR netcontrol takeover runtime detection (more info ...)trojan-activity    URL
7644MALWARE-BACKDOOR ullysse runtime detection - client-to-server (more info ...)trojan-activity    URL
7645MALWARE-BACKDOOR snipernet 2.1 runtime detection - flowbit set (more info ...)trojan-activity    URL
7646MALWARE-BACKDOOR snipernet 2.1 runtime detection (more info ...)trojan-activity    URL
7647MALWARE-BACKDOOR minicom lite runtime detection - udp (more info ...)trojan-activity    URL
7650MALWARE-BACKDOOR small uploader 1.01 runtime detection - initial connection - flowbit set (more info ...)trojan-activity    
7651MALWARE-BACKDOOR small uploader 1.01 runtime detection - initial connection (more info ...)trojan-activity    
7658MALWARE-BACKDOOR jodeitor 1.1 runtime detection - initial connection (more info ...)trojan-activity    URL
7659MALWARE-BACKDOOR lan filtrator 1.1 runtime detection - sin notification (more info ...)trojan-activity    URL
7660MALWARE-BACKDOOR lan filtrator 1.1 runtime detection - initial connection request - flowbit set (more info ...)trojan-activity    
7661MALWARE-BACKDOOR lan filtrator 1.1 runtime detection - initial connection request (more info ...)trojan-activity    URL
7662MALWARE-BACKDOOR snid x2 v1.2 runtime detection - initial connection - flowbit set (more info ...)trojan-activity    
7663MALWARE-BACKDOOR snid x2 v1.2 runtime detection - initial connection (more info ...)trojan-activity    URL
7664MALWARE-BACKDOOR screen control 1.0 runtime detection - flowbit set (more info ...)trojan-activity    URL
7665MALWARE-BACKDOOR screen control 1.0 runtime detection - initial connection (more info ...)trojan-activity    URL
7667MALWARE-BACKDOOR screen control 1.0 runtime detection - capture on port 2208 (more info ...)trojan-activity    URL
7668MALWARE-BACKDOOR screen control 1.0 runtime detection - capture on port 2213 - flowbit set (more info ...)trojan-activity    URL
7669MALWARE-BACKDOOR screen control 1.0 runtime detection - capture on port 2213 (more info ...)trojan-activity    URL
7670MALWARE-BACKDOOR digital upload runtime detection - initial connection (more info ...)trojan-activity    URL
7671MALWARE-BACKDOOR digital upload runtime detection - chat (more info ...)trojan-activity    URL
7672MALWARE-BACKDOOR remoter runtime detection - initial connection (more info ...)trojan-activity    URL
7673MALWARE-BACKDOOR remote havoc runtime detection - flowbit set 1 (more info ...)trojan-activity    URL
7674MALWARE-BACKDOOR remote havoc runtime detection - flowbit set 2 (more info ...)trojan-activity    URL
7675MALWARE-BACKDOOR remote havoc runtime detection (more info ...)trojan-activity    URL
7676MALWARE-BACKDOOR cool remote control or crackdown runtime detection - initial connection - flowbit set (more info ...)trojan-activity    URL
7677MALWARE-BACKDOOR cool remote control or crackdown runtime detection - initial connection (more info ...)trojan-activity    URL
7678MALWARE-BACKDOOR cool remote control 1.12 runtime detection - upload file - flowbit set (more info ...)trojan-activity    URL
7679MALWARE-BACKDOOR cool remote control 1.12 runtime detection - upload file (more info ...)trojan-activity    URL
7680MALWARE-BACKDOOR cool remote control 1.12 runtime detection - download file - flowbit set (more info ...)trojan-activity    URL
7681MALWARE-BACKDOOR cool remote control 1.12 runtime detection - download file (more info ...)trojan-activity    URL
7682MALWARE-BACKDOOR acid head 1.00 runtime detection - flowbit set (more info ...)trojan-activity    URL
7683MALWARE-BACKDOOR acid head 1.00 runtime detection (more info ...)trojan-activity    URL
7684MALWARE-BACKDOOR hrat 1.0 runtime detection (more info ...)trojan-activity    URL
7685MALWARE-BACKDOOR illusion runtime detection - get remote info client-to-server (more info ...)trojan-activity    URL
7686MALWARE-BACKDOOR illusion runtime detection - get remote info server-to-client (more info ...)trojan-activity    URL
7687MALWARE-BACKDOOR illusion runtime detection - file browser client-to-server (more info ...)trojan-activity    URL
7688MALWARE-BACKDOOR illusion runtime detection - file browser server-to-client (more info ...)trojan-activity    URL
7689MALWARE-BACKDOOR evade runtime detection - initial connection (more info ...)trojan-activity    URL
7690MALWARE-BACKDOOR evade runtime detection - file manager - flowbit set (more info ...)trojan-activity    URL
7691MALWARE-BACKDOOR evade runtime detection - file manager (more info ...)trojan-activity    URL
7692MALWARE-BACKDOOR exception 1.0 runtime detection - notification (more info ...)trojan-activity    URL
7695MALWARE-BACKDOOR hanky panky 1.1 runtime detection - initial connection - flowbit set 1 (more info ...)trojan-activity    URL
7696MALWARE-BACKDOOR hanky panky 1.1 runtime detection - initial connection - flowbit set 2 (more info ...)trojan-activity    URL
7697MALWARE-BACKDOOR hanky panky 1.1 runtime detection - initial connection (more info ...)trojan-activity    URL
7698MALWARE-BACKDOOR brain wiper runtime detection - launch application - flowbit set (more info ...)trojan-activity    URL
7699MALWARE-BACKDOOR brain wiper runtime detection - launch application (more info ...)trojan-activity    URL
7700MALWARE-BACKDOOR brain wiper runtime detection - chat - flowbit set (more info ...)trojan-activity    URL
7701MALWARE-BACKDOOR brain wiper runtime detection - chat (more info ...)trojan-activity    URL
7702MALWARE-BACKDOOR roach 1.0 runtime detection - remote control actions - flowbit set (more info ...)trojan-activity    
7703MALWARE-BACKDOOR roach 1.0 runtime detection - remote control actions (more info ...)trojan-activity    URL
7704MALWARE-CNC roach 1.0 server installation notification - email (more info ...)trojan-activity    URL
7705MALWARE-BACKDOOR omniquad instant remote control runtime detection - initial connection - flowbit set (more info ...)trojan-activity    
7706MALWARE-BACKDOOR omniquad instant remote control runtime detection - initial connection (more info ...)trojan-activity    URL
7707MALWARE-CNC omniquad instant remote control runtime detection - file transfer setup (more info ...)trojan-activity    URL
7708MALWARE-BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection - flowbit set (more info ...)trojan-activity    URL
7709MALWARE-BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection - flowbit set (more info ...)trojan-activity    URL
7710MALWARE-BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection (more info ...)trojan-activity    URL
7711MALWARE-BACKDOOR Amitis runtime command detection attacker to victim (more info ...)trojan-activity    URL
7712MALWARE-BACKDOOR Amitis runtime detection victim to attacker (more info ...)trojan-activity    URL
7713MALWARE-BACKDOOR Amitis v1.3 runtime detection - email notification (more info ...)trojan-activity    URL
7714MALWARE-BACKDOOR netdevil runtime detection - flowbit set 1 (more info ...)trojan-activity    URL
7717MALWARE-BACKDOOR snake trojan runtime detection (more info ...)trojan-activity    URL
7718MALWARE-BACKDOOR dameware mini remote control runtime detection - initial connection - flowbit set (more info ...)trojan-activity    URL
7719MALWARE-BACKDOOR dameware mini remote control runtime detection - initial connection (more info ...)trojan-activity    URL
7721MALWARE-BACKDOOR prorat 1.9 initial connection detection (more info ...)trojan-activity    URL
7723MALWARE-BACKDOOR wollf runtime detection (more info ...)trojan-activity    URL
7724MALWARE-BACKDOOR reversable ver1.0 runtime detection - initial connection - flowbit set (more info ...)trojan-activity    
7726MALWARE-BACKDOOR reversable ver1.0 runtime detection - execute command - flowbit set (more info ...)trojan-activity    
7727MALWARE-BACKDOOR reversable ver1.0 runtime detection - execute command (more info ...)trojan-activity    URL
7728MALWARE-BACKDOOR radmin runtime detection - client-to-server (more info ...)trojan-activity    URL
7729MALWARE-BACKDOOR radmin runtime detection - server-to-client (more info ...)trojan-activity    URL
7730MALWARE-BACKDOOR outbreak_0.2.7 runtime detection - reverse connection (more info ...)trojan-activity    URL
7731MALWARE-BACKDOOR outbreak_0.2.7 runtime detection - ring server-to-client (more info ...)trojan-activity    URL
7732MALWARE-BACKDOOR outbreak_0.2.7 runtime detection - ring client-to-server (more info ...)trojan-activity    URL
7733MALWARE-BACKDOOR outbreak_0.2.7 runtime detection - initial connection (more info ...)trojan-activity    URL
7734MALWARE-BACKDOOR bionet 4.05 runtime detection - initial connection - flowbit set (more info ...)trojan-activity    URL
7735MALWARE-BACKDOOR bionet 4.05 runtime detection - initial connection (more info ...)trojan-activity    URL
7738MALWARE-BACKDOOR alexmessomalex runtime detection - initial connection (more info ...)trojan-activity    URL
7739MALWARE-BACKDOOR alexmessomalex runtime detection - grab (more info ...)trojan-activity    URL
7740MALWARE-BACKDOOR nova 1.0 runtime detection - initial connection with pwd set - flowbit set (more info ...)trojan-activity    URL
7741MALWARE-BACKDOOR nova 1.0 runtime detection - initial connection with pwd set (more info ...)trojan-activity    URL
7744MALWARE-BACKDOOR phoenix 2.1 runtime detection - flowbit set (more info ...)trojan-activity    
7745MALWARE-BACKDOOR phoenix 2.1 runtime detection (more info ...)trojan-activity    URL
7746MALWARE-BACKDOOR bobo 1.0 runtime detection - initial connection - flowbit set (more info ...)trojan-activity    
7747MALWARE-BACKDOOR bobo 1.0 runtime detection - initial connection (more info ...)trojan-activity    URL
7748MALWARE-BACKDOOR bobo 1.0 runtime detection - send message - flowbit set (more info ...)trojan-activity    
7749MALWARE-BACKDOOR bobo 1.0 runtime detection - send message (more info ...)trojan-activity    URL
7753MALWARE-BACKDOOR buschtrommel 1.22 runtime detection - spy function - flowbit set 1 (more info ...)trojan-activity    
7754MALWARE-BACKDOOR buschtrommel 1.22 runtime detection - spy function - flowbit set 2 (more info ...)trojan-activity    
7755MALWARE-BACKDOOR buschtrommel 1.22 runtime detection - spy function (more info ...)trojan-activity    URL
7758MALWARE-BACKDOOR glacier runtime detection - initial connection and directory browse (more info ...)trojan-activity    URL
7759MALWARE-BACKDOOR glacier runtime detection - screen capture (more info ...)trojan-activity    URL
7763MALWARE-BACKDOOR nt remote controller 2000 runtime detection - services client-to-server (more info ...)trojan-activity    URL
7764MALWARE-BACKDOOR nt remote controller 2000 runtime detection - sysinfo client-to-server (more info ...)trojan-activity    URL
7765MALWARE-BACKDOOR nt remote controller 2000 runtime detection - sysinfo server-to-client (more info ...)trojan-activity    URL
7766MALWARE-BACKDOOR nt remote controller 2000 runtime detection - foldermonitor client-to-server (more info ...)trojan-activity    URL
7767MALWARE-BACKDOOR nt remote controller 2000 runtime detection - foldermonitor server-to-client (more info ...)trojan-activity    URL
7769MALWARE-BACKDOOR data rape runtime detection - execute program server-to-client (more info ...)trojan-activity    URL
7770MALWARE-BACKDOOR messiah 4.0 runtime detection - get server info - flowbit set (more info ...)trojan-activity    
7771MALWARE-BACKDOOR messiah 4.0 runtime detection - get server info (more info ...)trojan-activity    URL
7772MALWARE-BACKDOOR messiah 4.0 runtime detection - enable keylogger - flowbit set (more info ...)trojan-activity    URL
7773MALWARE-BACKDOOR messiah 4.0 runtime detection - enable keylogger (more info ...)trojan-activity    URL
7774MALWARE-BACKDOOR messiah 4.0 runtime detection - screen capture - flowbit set (more info ...)trojan-activity    
7775MALWARE-BACKDOOR messiah 4.0 runtime detection - screen capture (more info ...)trojan-activity    URL
7776MALWARE-BACKDOOR messiah 4.0 runtime detection - get drives - flowbit set (more info ...)trojan-activity    
7777MALWARE-BACKDOOR messiah 4.0 runtime detection - get drives (more info ...)trojan-activity    URL
7778MALWARE-BACKDOOR elfrat runtime detection - initial connection (more info ...)trojan-activity    URL
7782MALWARE-BACKDOOR netdevil runtime detection - file manager - flowbit set (more info ...)trojan-activity    URL
7783MALWARE-BACKDOOR netdevil runtime detection - file manager (more info ...)trojan-activity    URL
7788MALWARE-BACKDOOR forced control uploader runtime detection directory listing - client to server (more info ...)trojan-activity    
7789MALWARE-BACKDOOR forced control uploader runtime detection directory listing - server to client (more info ...)trojan-activity    
7791MALWARE-BACKDOOR remote anything 5.11.22 runtime detection - victim response (more info ...)trojan-activity    URL
7792MALWARE-BACKDOOR remote anything 5.11.22 runtime detection - chat with victim (more info ...)trojan-activity    URL
7793MALWARE-BACKDOOR remote anything 5.11.22 runtime detection - chat with attacker (more info ...)trojan-activity    URL
7794MALWARE-BACKDOOR fraggle rock 2.0 lite runtime detection - pc info - flowbit set (more info ...)trojan-activity    URL
7795MALWARE-BACKDOOR incommand 1.7 runtime detection - init connection (more info ...)trojan-activity    
7796MALWARE-BACKDOOR incommand 1.7 runtime detection - init connection (more info ...)trojan-activity    URL
7797MALWARE-BACKDOOR incommand 1.7 runtime detection - file manage 1 (more info ...)trojan-activity    
7798MALWARE-BACKDOOR incommand 1.7 runtime detection - file manage 1 (more info ...)trojan-activity    URL
7799MALWARE-BACKDOOR incommand 1.7 runtime detection - file manage 2 (more info ...)trojan-activity    
7800MALWARE-BACKDOOR incommand 1.7 runtime detection - file manage 2 (more info ...)trojan-activity    URL
7801MALWARE-BACKDOOR portal of doom runtime detection - udp cts (more info ...)trojan-activity    URL
7802MALWARE-BACKDOOR portal of doom runtime detection - udp stc (more info ...)trojan-activity    URL
7803MALWARE-BACKDOOR war trojan ver1.0 runtime detection - send messages (more info ...)trojan-activity    URL
7804MALWARE-BACKDOOR war trojan ver1.0 runtime detection - disable ctrl+alt+del (more info ...)trojan-activity    URL
7805MALWARE-CNC war trojan ver1.0 variant outbound connection ie hijacker (more info ...)trojan-activity    URL
7806MALWARE-BACKDOOR fatal wound 1.0 runtime detection - initial connection (more info ...)trojan-activity    URL
7807MALWARE-BACKDOOR fatal wound 1.0 runtime detection - execute file (more info ...)trojan-activity    URL
7808MALWARE-BACKDOOR fatal wound 1.0 runtime detection - upload (more info ...)trojan-activity    URL
7809MALWARE-BACKDOOR fatal wound 1.0 runtime detection - upload (more info ...)trojan-activity    URL
7810MALWARE-BACKDOOR nuclear uploader 1.0 runtime detection (more info ...)trojan-activity    URL
7811MALWARE-BACKDOOR abacab runtime detection - telnet initial (more info ...)trojan-activity    URL
7812MALWARE-BACKDOOR abacab runtime detection - banner (more info ...)trojan-activity    URL
7813MALWARE-BACKDOOR darkmoon initial connection detection - cts (more info ...)trojan-activity    URL
7814MALWARE-BACKDOOR darkmoon initial connection detection - stc (more info ...)trojan-activity    URL
7815MALWARE-BACKDOOR darkmoon reverse connection detection - stc (more info ...)trojan-activity    URL
7816MALWARE-BACKDOOR darkmoon reverse connection detection - cts (more info ...)trojan-activity    URL
7817MALWARE-BACKDOOR infector v1.0 runtime detection - init conn (more info ...)trojan-activity    URL
7818MALWARE-BACKDOOR infector v1.0 runtime detection - init conn (more info ...)trojan-activity    URL
7821MALWARE-BACKDOOR nightcreature beta 0.01 runtime detection (more info ...)trojan-activity    URL
7822MALWARE-BACKDOOR xbkdr runtime detection (more info ...)trojan-activity    URL
7823PUA-ADWARE Adware whenu runtime detection - datachunksgz (more info ...)misc-activity    URL
7824PUA-ADWARE Trickler whenu.clocksync outbound connection (more info ...)misc-activity    URL
7825PUA-ADWARE Adware whenu.savenow runtime detection (more info ...)misc-activity    URL
7826PUA-ADWARE Trickler whenu.weathercast outbound connection - check (more info ...)misc-activity    URL
7827PUA-ADWARE Adware whenu runtime detection - search request 1 (more info ...)misc-activity    URL
7828PUA-ADWARE Adware whenu runtime detection - search request 2 (more info ...)misc-activity    URL
7829PUA-ADWARE Adware gator user-agent detected (more info ...)misc-activity    URL
7830PUA-ADWARE Botnet dacryptic outbound connection (more info ...)trojan-activity    URL
7831PUA-ADWARE Adware downloadplus runtime detection (more info ...)misc-activity    URL
7832MALWARE-CNC User-Agent known malicious user agent - Navhelper (more info ...)misc-activity    URL
7834MALWARE-TOOLS Hacker-Tool nettracker runtime detection - report browsing (more info ...)misc-activity    
7835MALWARE-TOOLS Hacker-Tool nettracker runtime detection - report browsing (more info ...)misc-activity    URL
7836MALWARE-TOOLS Hacker-Tool nettracker runtime detection - report send through email (more info ...)misc-activity    URL
7837MALWARE-OTHER Keylogger spyoutside runtime detection - email delivery (more info ...)successful-recon-limited    URL
7838PUA-ADWARE Adware smiley central runtime detection (more info ...)misc-activity    URL
7839PUA-TOOLBARS Hijacker rx toolbar runtime detection (more info ...)misc-activity    URL
7840PUA-TOOLBARS Hijacker instafinder initial configuration detection (more info ...)misc-activity    URL
7841PUA-ADWARE Hijacker instafinder error redirect detection (more info ...)misc-activity    URL
7842MALWARE-TOOLS Hacker-Tool davps runtime detection (more info ...)misc-activity    URL
7843PUA-ADWARE Hijacker avenuemedia.dyfuca outbound connection - search engine hijack (more info ...)misc-activity    URL
7844PUA-ADWARE Hijacker avenuemedia.dyfuca outbound connection - post data (more info ...)misc-activity    URL
7845MALWARE-OTHER Keylogger clogger 1.0 runtime detection (more info ...)successful-recon-limited    URL
7846MALWARE-OTHER Keylogger clogger 1.0 runtime detection (more info ...)successful-recon-limited    URL
7847MALWARE-OTHER Keylogger clogger 1.0 runtime detection - send log through email (more info ...)successful-recon-limited    URL
7848PUA-TOOLBARS Hijacker netguide runtime detection (more info ...)misc-activity    URL
7849PUA-TOOLBARS Trickler maxsearch runtime detection - toolbar download (more info ...)misc-activity    URL
7850PUA-ADWARE Trickler maxsearch outbound connection - retrieve command (more info ...)misc-activity    URL
7851PUA-ADWARE Trickler maxsearch outbound connection - ack (more info ...)misc-activity    URL
7852PUA-ADWARE Trickler maxsearch outbound connection - advertisement (more info ...)misc-activity    URL
7853PUA-ADWARE Adware web-nexus runtime detection - ad url 1 (more info ...)misc-activity    URL
7854PUA-ADWARE Adware web-nexus runtime detection - config retrieval (more info ...)misc-activity    URL
7855PUA-ADWARE Adware web-nexus runtime detection - ad url 2 (more info ...)misc-activity    URL
7857MALWARE-OTHER Keylogger EliteKeylogger runtime detection (more info ...)successful-recon-limited    URL
7858PUA-TOOLBARS Google Desktop initial install - firstuse request (more info ...)policy-violation    
7860PUA-TOOLBARS Google Desktop search query (more info ...)policy-violation    
7861APP-DETECT Google Desktop activity (more info ...)policy-violation    
8056SERVER-OTHER ISC DHCP server 2 client_id length denial of service attempt (more info ...)attempted-dos 2006-3122   URL
8060SERVER-OTHER UltraVNC VNCLog buffer overflow (more info ...)attempted-admin 2006-1652 17378  
8071PUA-ADWARE Hijacker findthewebsiteyouneed outbound connection - search hijack (more info ...)misc-activity    URL
8072PUA-ADWARE Hijacker findthewebsiteyouneed outbound connection - surf monitor (more info ...)misc-activity    URL
8073PUA-TOOLBARS Adware zango toolbar runtime detection (more info ...)misc-activity    URL
8074MALWARE-BACKDOOR mithril runtime detection - init connection (more info ...)trojan-activity    URL
8075MALWARE-BACKDOOR mithril runtime detection - get system information (more info ...)trojan-activity    URL
8076MALWARE-BACKDOOR mithril runtime detection - get system information (more info ...)trojan-activity    URL
8077MALWARE-BACKDOOR mithril runtime detection - get process list (more info ...)trojan-activity    URL
8078MALWARE-BACKDOOR mithril runtime detection - get process list (more info ...)trojan-activity    URL
8079MALWARE-BACKDOOR x2a runtime detection - init connection (more info ...)trojan-activity    URL
8080MALWARE-CNC x2a variant outbound connection client update (more info ...)trojan-activity    URL
8085SERVER-WEBAPP HP OpenView Network Node Manager connectedNodes.ovpl command injection attempt (more info ...)attempted-admin 2005-2773 14662  
8086SERVER-WEBAPP HP OpenView Network Node Manager cdpView.ovpl command injection attempt (more info ...)attempted-admin 2005-2773 14662  
8087SERVER-WEBAPP HP OpenView Network Node Manager freeIPaddrs.ovpl command injection attempt (more info ...)attempted-admin 2005-2773 14662  
8088SERVER-WEBAPP HP OpenView Network Node Manager connectedNodes.ovpl command injection attempt (more info ...)attempted-admin 2005-2773 14662  
8089SERVER-WEBAPP HP OpenView Network Node Manager cdpView.ovpl command injection attempt (more info ...)attempted-admin 2005-2773 14662  
8090SERVER-WEBAPP HP OpenView Network Node Manager freeIPaddrs.ovpl command injection attempt (more info ...)attempted-admin 2005-2773 14662  
8352PUA-ADWARE Adware desktopmedia runtime detection - ads popup (more info ...)misc-activity    URL
8353PUA-ADWARE Adware desktopmedia runtime detection - auto update (more info ...)misc-activity    URL
8354PUA-ADWARE Adware desktopmedia runtime detection - surf monitoring (more info ...)misc-activity    URL
8355MALWARE-OTHER Keylogger spybuddy 3.72 runtime detection (more info ...)successful-recon-limited    URL
8356MALWARE-OTHER Keylogger spybuddy 3.72 runtime detection - send log out through email (more info ...)successful-recon-limited    URL
8357MALWARE-OTHER Keylogger spybuddy 3.72 runtime detection - send alert out through email (more info ...)successful-recon-limited    URL
8359PUA-ADWARE Hijacker yok supersearch outbound connection - target website display (more info ...)misc-activity    URL
8360PUA-ADWARE Hijacker yok supersearch outbound connection - search info collect (more info ...)misc-activity    URL
8361MALWARE-BACKDOOR black curse 4.0 runtime detection - inverse init connection (more info ...)trojan-activity    URL
8362MALWARE-BACKDOOR black curse 4.0 runtime detection - normal init connection (more info ...)trojan-activity    URL
8413FILE-OTHER HCP URI uplddrvinfo access (more info ...)misc-activity 2002-0974 5478  URL
8444SERVER-WEBAPP Trend Micro atxconsole format string server response attempt (more info ...)attempted-user 2006-5157 20284  
8461MALWARE-OTHER Trackware duduaccelerator runtime detection - send userinfo (more info ...)successful-recon-limited    URL
8462MALWARE-OTHER Trackware duduaccelerator runtime detection - trace info downloaded (more info ...)successful-recon-limited    URL
8463MALWARE-OTHER Trackware duduaccelerator runtime detection - trace login info (more info ...)successful-recon-limited    URL
8464PUA-ADWARE Adware henbang runtime detection (more info ...)misc-activity    URL
8465MALWARE-OTHER Keylogger netobserve runtime detection - email notification (more info ...)successful-recon-limited    URL
8466MALWARE-OTHER Keylogger netobserve runtime detection - email notification (more info ...)successful-recon-limited    URL
8467MALWARE-OTHER Keylogger netobserve runtime detection - remote login response (more info ...)successful-recon-limited    URL
8468PUA-ADWARE Hijacker accoona outbound connection - collect info (more info ...)misc-activity    URL
8469PUA-ADWARE Hijacker accoona outbound connection - open sidebar search url (more info ...)misc-activity    URL
8482POLICY-SOCIAL Xfire session initiated (more info ...)policy-violation    URL
8483POLICY-SOCIAL Xfire login attempted (more info ...)policy-violation    URL
8484POLICY-SOCIAL Xfire login successful (more info ...)policy-violation    URL
8541SERVER-ORACLE sdo_cs.transform_layer buffer overflow attempt (more info ...)attempted-user 2006-5372 20588  URL
8542MALWARE-OTHER Trackware deluxecommunications runtime detection - collect info (more info ...)successful-recon-limited    URL
8543MALWARE-OTHER Trackware deluxecommunications runtime detection - display popup ads (more info ...)successful-recon-limited    URL
8545PUA-ADWARE Adware roogoo runtime detection - surfing monitor (more info ...)misc-activity    URL
8546PUA-ADWARE Adware roogoo runtime detection - show ads (more info ...)misc-activity    URL
8547MALWARE-BACKDOOR zzmm 2.0 runtime detection - init connection (more info ...)trojan-activity    
8548MALWARE-BACKDOOR zzmm 2.0 runtime detection - init connection (more info ...)trojan-activity    URL
8549MALWARE-BACKDOOR zxshell runtime detection - setting information retrieve (more info ...)trojan-activity    URL
8550SERVER-ORACLE dbms_mview.register_mview buffer overflow attempt (more info ...)attempted-user    URL
8551SERVER-ORACLE dbms_mview.unregister_mview buffer overflow attempt (more info ...)attempted-user    URL
8704SERVER-MAIL Yahoo YPOPS Banner (more info ...)not-suspicious    
8705SERVER-MAIL Yahoo YPOPS buffer overflow attempt (more info ...)attempted-admin 2004-1558 11256  
8706SERVER-MAIL YPOPS buffer overflow attempt (more info ...)attempted-admin 2004-1558 11256  
8712SERVER-WEBAPP cacti graph_image arbitrary command execution attempt (more info ...)web-application-attack 2005-1524 14129  
8729SERVER-OTHER Shixxnote font buffer overflow attempt (more info ...)attempted-user 2004-1595 11409  
9324POLICY-OTHER TOR traffic anonymizer server request (more info ...)policy-violation    
9325SERVER-OTHER Citrix IMA DOS event data length denial of service attempt (more info ...)denial-of-service 2006-5861 20986  
9339MALWARE-OTHER klez.g web propagation detection (more info ...)trojan-activity    URL
9340MALWARE-OTHER klez.i web propagation detection (more info ...)trojan-activity    URL
9346MALWARE-OTHER klez.b web propagation detection (more info ...)trojan-activity    URL
9347MALWARE-OTHER klez.b netshare propagation detection (more info ...)trojan-activity    URL
9351MALWARE-OTHER lovgate.a netshare propagation detection (more info ...)trojan-activity    URL
9353MALWARE-OTHER deborm.x netshare propagation detection (more info ...)trojan-activity    URL
9354MALWARE-OTHER deborm.y netshare propagation detection (more info ...)trojan-activity    URL
9355MALWARE-OTHER deborm.u netshare propagation detection (more info ...)trojan-activity    URL
9356MALWARE-OTHER deborm.q netshare propagation detection (more info ...)trojan-activity    URL
9357MALWARE-OTHER deborm.r netshare propagation detection (more info ...)trojan-activity    URL
9363MALWARE-OTHER klez.d web propagation detection (more info ...)trojan-activity    URL
9364MALWARE-OTHER klez.e web propagation detection (more info ...)trojan-activity    URL
9387MALWARE-OTHER klez.j web propagation detection (more info ...)trojan-activity    URL
9390MALWARE-OTHER deborm.d netshare propagation detection (more info ...)trojan-activity    URL
9395MALWARE-OTHER deborm.j netshare propagation detection (more info ...)trojan-activity    URL
9396MALWARE-OTHER deborm.t netshare propagation detection (more info ...)trojan-activity    URL
9401MALWARE-OTHER gokar http propagation detection (more info ...)trojan-activity    URL
9407MALWARE-OTHER lovgate.b netshare propagation detection (more info ...)trojan-activity    URL
9412MALWARE-OTHER sinmsn.b msn propagation detection (more info ...)trojan-activity    URL
9418MALWARE-CNC bagle.a http notification detection (more info ...)trojan-activity    URL
9419MALWARE-OTHER sasser attempt (more info ...)trojan-activity 2003-0533 10108 12205 URL
9420MALWARE-OTHER korgo attempt (more info ...)trojan-activity 2003-0533 10108 12205 URL
9424MALWARE-OTHER /winnt/explorer.exe unicode klez infection (more info ...)trojan-activity    
9425MALWARE-OTHER netsky attachment (more info ...)trojan-activity    
9426MALWARE-OTHER mydoom.ap attachment (more info ...)trojan-activity    
9434FILE-OTHER Ultravox-Max-Msg header integer overflow attempt (more info ...)attempted-user 2006-5567 20744  URL
9619FILE-OTHER Gnu gv buffer overflow attempt (more info ...)attempted-user 2006-5864 20978  
9620SERVER-WEBAPP Pajax call_dispatcher remote code execution attempt (more info ...)attempted-admin 2006-1551 17519  
9622SERVER-OTHER Spiffit UDP denial of service attempt (more info ...)attempted-dos 1999-0194   
9644PUA-ADWARE Adware imnames runtime detection (more info ...)misc-activity    URL
9646PUA-TOOLBARS Hijacker sogou runtime detection - search through sogou toolbar (more info ...)misc-activity    URL
9647MALWARE-OTHER Keylogger system surveillance pro runtime detection (more info ...)successful-recon-limited    URL
9648MALWARE-OTHER Keylogger emailspypro runtime detection (more info ...)successful-recon-limited    URL
9649MALWARE-OTHER Keylogger ghost Keylogger runtime detection - flowbit set (more info ...)successful-recon-limited    URL
9650MALWARE-OTHER Keylogger ghost Keylogger runtime detection (more info ...)successful-recon-limited    URL
9651PUA-ADWARE Hijacker ricercadoppia outbound connection (more info ...)misc-activity    URL
9652PUA-ADWARE Hijacker oemji bar outbound connection (more info ...)misc-activity    URL
9654MALWARE-BACKDOOR apofis 1.0 runtime detection - remote controlling (more info ...)trojan-activity    
9655MALWARE-BACKDOOR apofis 1.0 runtime detection - remote controlling (more info ...)trojan-activity    URL
9656MALWARE-BACKDOOR bersek 1.0 runtime detection (more info ...)trojan-activity    
9657MALWARE-BACKDOOR bersek 1.0 runtime detection - init connection (more info ...)trojan-activity    URL
9658MALWARE-BACKDOOR bersek 1.0 runtime detection (more info ...)trojan-activity    
9659MALWARE-BACKDOOR bersek 1.0 runtime detection - file manage (more info ...)trojan-activity    URL
9660MALWARE-BACKDOOR bersek 1.0 runtime detection (more info ...)trojan-activity    
9661MALWARE-BACKDOOR bersek 1.0 runtime detection - show processes (more info ...)trojan-activity    URL
9662MALWARE-BACKDOOR bersek 1.0 runtime detection (more info ...)trojan-activity    
9663MALWARE-BACKDOOR bersek 1.0 runtime detection - start remote shell (more info ...)trojan-activity    URL
9664MALWARE-BACKDOOR crossbow 1.12 runtime detection (more info ...)trojan-activity    
9665MALWARE-BACKDOOR crossbow 1.12 runtime detection - init connection (more info ...)trojan-activity    URL
9666MALWARE-BACKDOOR superra runtime detection - success init connection (more info ...)trojan-activity    
9667MALWARE-BACKDOOR superra runtime detection - issue remote control command (more info ...)trojan-activity    
9790SERVER-OTHER HP-UX lpd command execution attempt (more info ...)attempted-admin 2005-3277 15136  
9791SERVER-WEBAPP .cmd? access (more info ...)web-application-activity 2019-0232 4335  
9813SERVER-OTHER Symantec NetBackup connect_options buffer overflow attempt (more info ...)attempted-admin 2006-5822 21565  
9830MALWARE-OTHER Keylogger supreme spy runtime detection (more info ...)successful-recon-limited    URL
9831PUA-ADWARE Adware u88 runtime detection (more info ...)misc-activity    URL
9832MALWARE-BACKDOOR ieva 1.0 runtime detection - send message (more info ...)trojan-activity    URL
9833MALWARE-BACKDOOR ieva 1.0 runtime detection - fake delete harddisk message (more info ...)trojan-activity    URL
9834MALWARE-BACKDOOR ieva 1.0 runtime detection - black screen (more info ...)trojan-activity    URL
9835MALWARE-BACKDOOR ieva 1.0 runtime detection - swap mouse (more info ...)trojan-activity    URL
9836MALWARE-BACKDOOR ieva 1.0 runtime detection - crazy mouse (more info ...)trojan-activity    URL
9837MALWARE-BACKDOOR sun shadow 1.70 runtime detection - init connection (more info ...)trojan-activity    
9838MALWARE-BACKDOOR sun shadow 1.70 runtime detection - init connection (more info ...)trojan-activity    URL
9839MALWARE-BACKDOOR sun shadow 1.70 runtime detection - keep alive (more info ...)trojan-activity    URL
9844FILE-MULTIMEDIA VLC Media Player udp URI format string attempt (more info ...)attempted-user 2007-0017 21852  URL
10064SERVER-OTHER Peercast URL Parameter overflow attempt (more info ...)attempted-user 2006-1148 17040  
10090PUA-ADWARE Trickler zango easymessenger outbound connection (more info ...)misc-activity    URL
10091MALWARE-TOOLS Hacker-Tool spylply.a runtime detection (more info ...)misc-activity    URL
10092MALWARE-OTHER Trackware russian searchbar runtime detection (more info ...)successful-recon-limited    URL
10093PUA-TOOLBARS Hijacker kuaiso toolbar runtime detection (more info ...)misc-activity    URL
10094PUA-ADWARE Adware borlan runtime detection (more info ...)misc-activity    URL
10095MALWARE-OTHER Trackware bydou runtime detection (more info ...)successful-recon-limited    URL
10096MALWARE-OTHER Keylogger win32.remotekeylog.b runtime detection - keylog (more info ...)successful-recon-limited    URL
10097MALWARE-OTHER Keylogger win32.remotekeylog.b runtime detection (more info ...)successful-recon-limited    URL
10098MALWARE-OTHER Keylogger win32.remotekeylog.b runtime detection - get system info (more info ...)successful-recon-limited    URL
10099MALWARE-OTHER Keylogger win32.remotekeylog.b runtime detection (more info ...)successful-recon-limited    URL
10100MALWARE-OTHER Keylogger win32.remotekeylog.b runtime detection - open website (more info ...)successful-recon-limited    URL
10101MALWARE-BACKDOOR crossfires trojan 3.0 runtime detection - delete file (more info ...)trojan-activity    URL
10102MALWARE-BACKDOOR crossfires trojan 3.0 runtime detection - chat with victim (more info ...)trojan-activity    URL
10103MALWARE-BACKDOOR hav-rat 1.1 runtime detection (more info ...)trojan-activity    
10104MALWARE-BACKDOOR hav-rat 1.1 runtime detection (more info ...)trojan-activity    
10105MALWARE-BACKDOOR hav-rat 1.1 runtime detection - retrieve pc info (more info ...)trojan-activity    URL
10109MALWARE-BACKDOOR k-msnrat 1.0.0 runtime detection - init connection (more info ...)trojan-activity    URL
10110MALWARE-BACKDOOR poison ivy 2.1.2 runtime detection (more info ...)trojan-activity    
10111MALWARE-BACKDOOR poison ivy 2.1.2 runtime detection - init connection (more info ...)trojan-activity    URL
10112MALWARE-BACKDOOR rix3 1.0 runtime detection - init connection (more info ...)trojan-activity    URL
10113MALWARE-CNC Win.Trojan.Peacomm command and control propagation detected (more info ...)trojan-activity    
10114MALWARE-CNC Win.Trojan.Peacomm command and control propagation detected (more info ...)trojan-activity    
10124PROTOCOL-VOIP PA168 chipset based IP phone authentication bypass (more info ...)attempted-admin 2007-0528 22191  URL
10125SERVER-OTHER bomberclone buffer overflow attempt (more info ...)attempted-user 2006-0460 16697  
10164PUA-ADWARE Adware adclicker-ej runtime detection (more info ...)misc-activity    URL
10165MALWARE-OTHER Keylogger mybr Keylogger runtime detection (more info ...)successful-recon-limited    URL
10166MALWARE-OTHER Trackware baigoo runtime detection (more info ...)successful-recon-limited    URL
10167MALWARE-OTHER Keylogger radar spy 1.0 runtime detection - send html log (more info ...)successful-recon-limited    URL
10168MALWARE-BACKDOOR one runtime detection (more info ...)trojan-activity    URL
10169MALWARE-BACKDOOR matrix 1.03 by mtronic runtime detection - init connection (more info ...)trojan-activity    URL
10172SERVER-WEBAPP uTorrent announce buffer overflow attempt (more info ...)attempted-user 2007-0927 22530  
10179MALWARE-CNC User-Agent known malicious user agent - BysooTB (more info ...)successful-recon-limited    URL
10180PUA-TOOLBARS Adware eqiso runtime detection (more info ...)misc-activity    URL
10181MALWARE-OTHER Keylogger systemsleuth runtime detection (more info ...)successful-recon-limited    URL
10182PUA-ADWARE Adware newweb runtime detection (more info ...)misc-activity    URL
10183MALWARE-OTHER Keylogger activity Keylogger runtime detection (more info ...)successful-recon-limited    URL
10184MALWARE-BACKDOOR wow 23 runtime detection (more info ...)trojan-activity    URL
10186SERVER-MAIL ClamAV mime parsing directory traversal (more info ...)attempted-user 2007-0898 22581  URL
10195SERVER-WEBAPP Content-Length buffer overflow attempt (more info ...)attempted-admin 2007-1260   URL
10403MALWARE-CNC Win.Trojan.Duntek Checkin GET Request (more info ...)trojan-activity    URL
10435MALWARE-OTHER Trackware admedia runtime detection (more info ...)successful-recon-limited    URL
10436MALWARE-OTHER Keylogger keyspy runtime detection (more info ...)successful-recon-limited    URL
10437PUA-ADWARE Hijacker bazookabar outbound connection (more info ...)misc-activity    URL
10439PUA-ADWARE Adware mokead runtime detection (more info ...)misc-activity    URL
10441MALWARE-TOOLS Hacker-Tool statwin runtime detection (more info ...)misc-activity    URL
10442MALWARE-BACKDOOR nirvana 2.0 runtime detection - explore c drive (more info ...)trojan-activity    URL
10443MALWARE-BACKDOOR acidbattery 1.0 runtime detection - sniff info (more info ...)trojan-activity    URL
10446MALWARE-BACKDOOR acidbattery 1.0 runtime detection - get server info (more info ...)trojan-activity    URL
10447MALWARE-CNC 51d 1b variant outbound connection icq notification (more info ...)trojan-activity    URL
10448MALWARE-BACKDOOR acessor 2.0 runtime detection - init connection (more info ...)trojan-activity    URL
10449MALWARE-BACKDOOR acid shivers runtime detection - init telnet connection (more info ...)trojan-activity    URL
10450MALWARE-BACKDOOR only 1 rat runtime detection - control command (more info ...)trojan-activity    
10451MALWARE-BACKDOOR only 1 rat runtime detection - control command (more info ...)trojan-activity    URL
10454MALWARE-BACKDOOR [x]-ztoo 1.0 runtime detection - init connection (more info ...)trojan-activity    URL
10455MALWARE-BACKDOOR [x]-ztoo 1.0 runtime detection - get system info (more info ...)trojan-activity    
10456MALWARE-BACKDOOR [x]-ztoo 1.0 runtime detection - get system info (more info ...)trojan-activity    URL
10457MALWARE-BACKDOOR [x]-ztoo 1.0 runtime detection - start keylogger (more info ...)trojan-activity    URL
10458MALWARE-BACKDOOR [x]-ztoo 1.0 or illusion runtime detection - open file manager (more info ...)trojan-activity    URL
10459MALWARE-BACKDOOR wineggdrop shell pro runtime detection - init connection (more info ...)trojan-activity    URL
10460MALWARE-BACKDOOR winicabras 1.1 runtime detection - get system info (more info ...)trojan-activity    
10461MALWARE-BACKDOOR winicabras 1.1 runtime detection - get system info (more info ...)trojan-activity    URL
10462MALWARE-BACKDOOR winicabras 1.1 runtime detection - explorer (more info ...)trojan-activity    
10463MALWARE-BACKDOOR winicabras 1.1 runtime detection - explorer (more info ...)trojan-activity    URL
10480SERVER-OTHER imail ldap buffer overflow exploit attempt (more info ...)attempted-admin 2004-0297   URL
10504INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
10505INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
10990SERVER-WEBAPP encoded cross site scripting HTML Image tag attempt (more info ...)web-application-attack 2002-0840 5847  
10997SERVER-WEBAPP SSLv2 OpenSSl KEY_ARG buffer overflow attempt (more info ...)misc-attack 2002-0656 5362  
10999SERVER-WEBAPP chetcpasswd access (more info ...)web-application-activity 2006-6679 6472  
11175SERVER-ORACLE dbms_cdc_ipublish.chgtab_cache buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  
11185SERVER-OTHER CA eTrust key handling dos via username attempt (more info ...)denial-of-service 2007-1005 22743  
11203SERVER-ORACLE sys.dbms_apply_user_agent.set_registration_handler access attempt (more info ...)attempted-user    URL
11205SERVER-ORACLE sys.dbms_upgrade_internal access attempt (more info ...)attempted-user    URL
11223SERVER-WEBAPP google proxystylesheet arbitrary command execution attempt (more info ...)web-application-attack 2005-3757 15509  URL
11266SERVER-OTHER Kerio Personal Firewall authentication buffer overflow attempt (more info ...)attempted-admin 2003-0220 7180  
11306PUA-ADWARE Snoopware childwebguardian outbound connection - udp broadcast (more info ...)successful-recon-limited    URL
11307MALWARE-OTHER Keylogger computer monitor Keylogger runtime detection (more info ...)successful-recon-limited    URL
11308MALWARE-CNC User-Agent known malicious user agent - SpyDawn (more info ...)misc-activity    URL
11309MALWARE-OTHER Keylogger sskc v2.0 runtime detection (more info ...)successful-recon-limited    URL
11310PUA-ADWARE Trickler iowa webdownloader - icq notification (more info ...)misc-activity    URL
11311MALWARE-OTHER Keylogger pcsentinelsoftware Keylogger runtime detection - upload infor (more info ...)successful-recon-limited    URL
11312MALWARE-OTHER Trackware uplink runtime detection (more info ...)successful-recon-limited    URL
11313MALWARE-CNC User-Agent known malicious user agent - Spy-Locked (more info ...)misc-activity    URL
11314MALWARE-BACKDOOR shadownet remote spy 2.0 runtime detection (more info ...)trojan-activity    URL
11316MALWARE-BACKDOOR lurker 1.1 runtime detection - init connection (more info ...)trojan-activity    URL
11317MALWARE-BACKDOOR abremote pro 3.1 runtime detection - init connection (more info ...)trojan-activity    URL
11318MALWARE-BACKDOOR boer runtime detection - init connection (more info ...)trojan-activity    URL
11319MALWARE-BACKDOOR netwindow runtime detection - init connection request (more info ...)trojan-activity    URL
11320MALWARE-BACKDOOR netwindow runtime detection - reverse mode init connection request (more info ...)trojan-activity    URL
11321MALWARE-BACKDOOR netwindow runtime detection - udp broadcast (more info ...)trojan-activity    URL
11322MALWARE-BACKDOOR sohoanywhere runtime detection (more info ...)trojan-activity    
11323MALWARE-BACKDOOR sohoanywhere runtime detection (more info ...)trojan-activity    URL
11681SERVER-OTHER Openview Omni II command bypass attempt (more info ...)attempted-admin 2001-0311 11032  
11682SERVER-OTHER niprint_lpd module attack attempt (more info ...)attempted-admin 2003-1141 8968  
11948PUA-TOOLBARS Hijacker snap toolbar runtime detection - cookie (more info ...)misc-activity    URL
11949MALWARE-BACKDOOR lame rat v1.0 runtime detection (more info ...)trojan-activity    URL
11950MALWARE-CNC killav_gj (more info ...)trojan-activity    URL
11953MALWARE-BACKDOOR supervisor plus runtime detection (more info ...)trojan-activity    
11954MALWARE-BACKDOOR supervisor plus runtime detection (more info ...)trojan-activity    URL
11971PROTOCOL-VOIP CSeq buffer overflow attempt (more info ...)attempted-dos 2009-2726 36015 18986 URL
11972PROTOCOL-VOIP Max-Forwards value over 70 (more info ...)misc-activity    URL
11973PROTOCOL-VOIP Via header hostname buffer overflow attempt (more info ...)attempted-user 2007-3369 24542  URL
11975PROTOCOL-VOIP Via header missing SIP field (more info ...)misc-activity    URL
11976PROTOCOL-VOIP SIP URI type overflow attempt (more info ...)attempted-user    URL
11977PROTOCOL-VOIP TEL URI type overflow attempt (more info ...)attempted-user    URL
11979PROTOCOL-VOIP Media header port field invalid value (more info ...)attempted-user    URL
11980PROTOCOL-VOIP Attribute header buffer overflow attempt (more info ...)attempted-user 2006-0189 16213  URL
11982PROTOCOL-VOIP To header contains recursive URL-encoded data (more info ...)attempted-dos    URL
11983PROTOCOL-VOIP Time header contains negative value (more info ...)attempted-user    URL
11984PROTOCOL-VOIP Time header contains long value (more info ...)attempted-user    URL
11985PROTOCOL-VOIP Expires header overflow attempt (more info ...)attempted-user    URL
11986PROTOCOL-VOIP Authorization header invalid characters in response parameter (more info ...)attempted-user    URL
11987PROTOCOL-VOIP Via header format string attempt (more info ...)attempted-dos    URL
11988PROTOCOL-VOIP From header format string attempt (more info ...)attempted-dos    URL
11989PROTOCOL-VOIP Call-ID header format string attempt (more info ...)attempted-dos    URL
11990PROTOCOL-VOIP Contact header format string attempt (more info ...)attempted-dos    URL
11991PROTOCOL-VOIP CSeq header format string attempt (more info ...)attempted-dos    URL
11992PROTOCOL-VOIP Content-Type header format string attempt (more info ...)attempted-dos    URL
11993PROTOCOL-VOIP Call-ID header invalid characters detected (more info ...)attempted-dos    URL
11994PROTOCOL-VOIP Contact header invalid characters detected (more info ...)attempted-dos    URL
11995PROTOCOL-VOIP Content-Type header invalid characters detected (more info ...)attempted-dos    URL
11996PROTOCOL-VOIP CSeq header invalid characters detected (more info ...)attempted-dos    URL
11997PROTOCOL-VOIP From header invalid characters detected (more info ...)attempted-dos    URL
11998PROTOCOL-VOIP To header invalid characters detected (more info ...)attempted-dos    URL
11999PROTOCOL-VOIP Via header invalid characters detected (more info ...)attempted-dos    URL
12001PROTOCOL-VOIP Version header overflow attempt (more info ...)attempted-dos    URL
12005PROTOCOL-VOIP Connection header invalid value (more info ...)attempted-dos    URL
12044SERVER-ORACLE Oracle Web Cache denial of service attempt (more info ...)attempted-dos 2002-0386 5902  URL
12045SERVER-ORACLE Oracle Web Cache denial of service attempt (more info ...)attempted-dos 2002-0386 5902  URL
12047PUA-ADWARE Adware yayad runtime detection (more info ...)misc-activity    URL
12048MALWARE-OTHER Keylogger computer Keylogger runtime detection (more info ...)successful-recon-limited    URL
12049MALWARE-OTHER Keylogger apophis spy 1.0 runtime detection (more info ...)successful-recon-limited    URL
12050PUA-TOOLBARS Hijacker ez-greets toolbar runtime detection (more info ...)misc-activity    URL
12051MALWARE-BACKDOOR ultimate rat 2.1 runtime detection (more info ...)trojan-activity    URL
12052MALWARE-BACKDOOR the[x] 1.2 runtime detection - execute command (more info ...)trojan-activity    URL
12053MALWARE-BACKDOOR trail of destruction 2.0 runtime detection - get system info (more info ...)trojan-activity    URL
12054MALWARE-BACKDOOR tron runtime detection - init connection - flowbit set (more info ...)trojan-activity    
12055MALWARE-BACKDOOR tron runtime detection - init connection (more info ...)trojan-activity    URL
12057SERVER-WEBAPP Ipswitch WhatsUpGold configuration access (more info ...)web-application-activity 2004-0798 11109  
12065POLICY-OTHER Outbound Teredo traffic detected (more info ...)policy-violation 2007-3038   URL
12066POLICY-OTHER Inbound Teredo traffic detected (more info ...)policy-violation 2007-3038   URL
12067POLICY-OTHER Outbound Teredo traffic detected (more info ...)policy-violation 2007-3038   URL
12068POLICY-OTHER Inbound Teredo traffic detected (more info ...)policy-violation 2007-3038   URL
12081SERVER-OTHER BakBone NetVault server heap overflow attempt (more info ...)attempted-admin 2005-1009 12967  
12082SERVER-ORACLE Oracle 9i TNS denial of service attempt (more info ...)attempted-dos 2002-0509 4391  
12112PROTOCOL-VOIP Sivus scanner detected (more info ...)network-scan    URL
12113PROTOCOL-VOIP SIP URI overflow attempt (more info ...)misc-activity    URL
12114SERVER-MAIL Ipswitch IMail search command buffer overflow attempt (more info ...)attempted-admin 2007-3925 24962  URL
12115SERVER-MAIL Ipswitch IMail search command buffer overflow attempt (more info ...)attempted-admin 2007-3925 24962  URL
12120PUA-ADWARE Adware pprich runtime detection - version check (more info ...)misc-activity    URL
12121PUA-ADWARE Adware pprich runtime detection - udp info sent out (more info ...)misc-activity    URL
12122PUA-TOOLBARS Trackware spynova runtime detection (more info ...)successful-recon-limited    URL
12123PUA-ADWARE Hijacker lookquick outbound connection - hijack ie (more info ...)misc-activity    URL
12124PUA-ADWARE Hijacker lookquick outbound connection - monitor and collect user info (more info ...)misc-activity    URL
12125PUA-TOOLBARS Trackware lookster toolbar runtime detection - hijack ie search assistant (more info ...)successful-recon-limited    URL
12126PUA-TOOLBARS Trackware lookster toolbar runtime detection - collect user information (more info ...)successful-recon-limited    URL
12127PUA-TOOLBARS Trackware lookster toolbar runtime detection - ads (more info ...)successful-recon-limited    URL
12128MALWARE-OTHER Keylogger remotekeylog.b runtime detection - init connection (more info ...)successful-recon-limited    URL
12129MALWARE-OTHER Keylogger remotekeylog.b runtime detection - get sys info (more info ...)successful-recon-limited    URL
12130MALWARE-OTHER Keylogger remotekeylog.b runtime detection - get sys info (more info ...)successful-recon-limited    URL
12131MALWARE-OTHER Keylogger remotekeylog.b runtime detection - keylogging (more info ...)successful-recon-limited    URL
12132MALWARE-OTHER Keylogger remotekeylog.b runtime detection - keylogging (more info ...)successful-recon-limited    URL
12133MALWARE-OTHER Keylogger remotekeylog.b runtime detection - open url (more info ...)successful-recon-limited    URL
12134MALWARE-OTHER Keylogger remotekeylog.b runtime detection - open url (more info ...)successful-recon-limited    URL
12135MALWARE-OTHER Keylogger remotekeylog.b runtime detection - fun (more info ...)successful-recon-limited    URL
12136MALWARE-OTHER Keylogger remotekeylog.b runtime detection - fun (more info ...)successful-recon-limited    URL
12137MALWARE-OTHER Keylogger Keylogger king home 2.3 runtime detection (more info ...)successful-recon-limited    URL
12138PUA-ADWARE Adware zamingo runtime detection (more info ...)misc-activity    URL
12139MALWARE-OTHER Trackware stealth website logger 3.4 runtime detection (more info ...)successful-recon-limited    URL
12140PUA-ADWARE Hijacker cnnic update outbound connection (more info ...)misc-activity    URL
12141MALWARE-OTHER Keylogger logit v1.0 runtime detection (more info ...)successful-recon-limited    URL
12142MALWARE-BACKDOOR access remote pc runtime detection - init connection (more info ...)trojan-activity    
12143MALWARE-BACKDOOR access remote pc runtime detection - init connection (more info ...)trojan-activity    URL
12146MALWARE-BACKDOOR blue eye 1.0b runtime detection - init connection (more info ...)trojan-activity    
12147MALWARE-BACKDOOR blue eye 1.0b runtime detection - init connection (more info ...)trojan-activity    URL
12148MALWARE-BACKDOOR back orifice 2006 - v1.1.5 runtime detection - init connection (more info ...)trojan-activity    
12149MALWARE-BACKDOOR back orifice 2006 - v1.1.5 runtime detection - init connection (more info ...)trojan-activity    URL
12150MALWARE-BACKDOOR cafeini 1.0 runtime detection - init connection (more info ...)trojan-activity    
12151MALWARE-BACKDOOR cafeini 1.0 runtime detection (more info ...)trojan-activity    URL
12152MALWARE-BACKDOOR optix pro v1.32 runtime detection - init connection (more info ...)trojan-activity    URL
12153MALWARE-BACKDOOR optix pro v1.32 runtime detection - download file (more info ...)trojan-activity    
12154MALWARE-BACKDOOR optix pro v1.32 runtime detection - download file (more info ...)trojan-activity    
12155MALWARE-BACKDOOR optix pro v1.32 runtime detection - download file (more info ...)trojan-activity    URL
12156MALWARE-BACKDOOR optix pro v1.32 runtime detection - upload file (more info ...)trojan-activity    
12157MALWARE-BACKDOOR optix pro v1.32 runtime detection - upload file (more info ...)trojan-activity    
12158MALWARE-BACKDOOR optix pro v1.32 runtime detection - upload file (more info ...)trojan-activity    URL
12159MALWARE-BACKDOOR optix pro v1.32 runtime detection - keylogging (more info ...)trojan-activity    URL
12160MALWARE-BACKDOOR optix pro v1.32 runtime detection - screen capturing (more info ...)trojan-activity    
12161MALWARE-BACKDOOR optix pro v1.32 runtime detection - screen capturing (more info ...)trojan-activity    
12162MALWARE-BACKDOOR optix pro v1.32 runtime detection - screen capturing (more info ...)trojan-activity    URL
12163MALWARE-BACKDOOR cobra uploader 1.0 runtime detection (more info ...)trojan-activity    
12164MALWARE-BACKDOOR cobra uploader 1.0 runtime detection (more info ...)trojan-activity    URL
12165MALWARE-CNC lithium 1.02 variant outbound connection (more info ...)trojan-activity    
12166MALWARE-CNC lithium 1.02 variant outbound connection (more info ...)trojan-activity    URL
12167PROTOCOL-VOIP SIP URI multiple at signs in message (more info ...)misc-activity    URL
12197SERVER-OTHER CA message queuing server buffer overflow attempt (more info ...)attempted-admin 2007-0060 25051  URL
12199SERVER-OTHER RIM BlackBerry SRP negative string size (more info ...)attempted-dos 2005-2342 16100  
12202SERVER-OTHER Ingres long message heap buffer overflow attempt (more info ...)attempted-admin 2007-3334   
12209PUA-P2P P2PTv TVAnt udp traffic detected (more info ...)policy-violation    
12210PUA-P2P P2PTv TVAnts TCP tracker connect traffic detected (more info ...)policy-violation    
12211PUA-P2P P2PTv TVAnts TCP connection traffic detected (more info ...)policy-violation    
12212SERVER-MAIL Ipswitch IMail literal search date command buffer overflow attempt (more info ...)attempted-admin 2007-3925 24962  URL
12213SERVER-MAIL Ipswitch IMail search date command buffer overflow attempt (more info ...)attempted-admin 2007-3925 24962  URL
12216SERVER-OTHER Borland interbase Create Request opcode string length buffer overflow attempt (more info ...)attempted-admin 2007-3566 25048  
12217SERVER-OTHER Borland interbase string length buffer overflow attempt (more info ...)attempted-admin 2007-3566 25048  
12218SERVER-OTHER Borland interbase string length buffer overflow attempt (more info ...)attempted-admin 2007-3566 25048  
12220SERVER-OTHER IBM Informix Dynamic Server long username buffer overflow attempt (more info ...)attempted-admin 2006-3854 19264  
12221SERVER-WEBAPP file upload GLOBAL variable overwrite attempt (more info ...)web-application-attack 2005-3390 15250  
12222SERVER-OTHER Squid proxy long WCCP packet (more info ...)attempted-user 2005-0211 12432  
12224PUA-ADWARE Adware enbrowser snackman runtime detection (more info ...)misc-activity    URL
12225PUA-TOOLBARS Adware zango2007 toolbar runtime detection (more info ...)misc-activity    URL
12226MALWARE-OTHER Keylogger overspy runtime detection (more info ...)successful-recon-limited    URL
12227PUA-TOOLBARS Trackware snap ultrasearch/desktop toolbar runtime detection - search (more info ...)successful-recon-limited    URL
12228PUA-TOOLBARS Trackware snap ultrasearch/desktop toolbar runtime detection - cookie (more info ...)successful-recon-limited    URL
12229PUA-ADWARE Adware vroomsearch runtime detection (more info ...)misc-activity    URL
12230MALWARE-TOOLS Hacker-Tool hippynotify 2.0 runtime detection (more info ...)misc-activity    URL
12231PUA-ADWARE Adware vroomsearch runtime detection (more info ...)misc-activity    URL
12232PUA-ADWARE Adware errorsafe runtime detection (more info ...)misc-activity    URL
12239MALWARE-BACKDOOR webcenter v1.0 Backdoor - init connection (more info ...)trojan-activity    URL
12240MALWARE-BACKDOOR genie 1.7 runtime detection - init connection (more info ...)trojan-activity    
12241MALWARE-BACKDOOR genie 1.7 runtime detection - init connection (more info ...)trojan-activity    URL
12242MALWARE-BACKDOOR hotmail hacker log edition 5.0 runtime detection - init connection (more info ...)trojan-activity    
12243MALWARE-BACKDOOR hotmail hacker log edition 5.0 runtime detection - init connection (more info ...)trojan-activity    URL
12244MALWARE-BACKDOOR itadem trojan 3.0 runtime detection (more info ...)trojan-activity    URL
12245MALWARE-BACKDOOR furax 1.0 b3 runtime detection (more info ...)trojan-activity    URL
12255SERVER-WEBAPP CSGuestbook setup attempt (more info ...)web-application-activity 2002-1750 4448  
12287PUA-TOOLBARS Hijacker scn toolbar runtime detection - ebrss request (more info ...)misc-activity    URL
12288PUA-TOOLBARS Hijacker scn toolbar runtime detection - hijack ie searches (more info ...)misc-activity    URL
12289PUA-TOOLBARS Hijacker scn toolbar runtime detection - get updates (more info ...)misc-activity    URL
12290PUA-ADWARE Hijacker newdotnet quick! search outbound connection (more info ...)misc-activity    URL
12291PUA-TOOLBARS Trackware vmn toolbar runtime detection (more info ...)successful-recon-limited    URL
12292PUA-TOOLBARS Hijacker morpheus toolbar runtime detection - hijack/search (more info ...)misc-activity    URL
12293PUA-TOOLBARS Hijacker morpheus toolbar runtime detection - get cfg info (more info ...)misc-activity    URL
12294PUA-TOOLBARS Hijacker 3search runtime detection - counter (more info ...)misc-activity    URL
12295PUA-ADWARE Hijacker 3search outbound connection - hijacking (more info ...)misc-activity    URL
12296PUA-TOOLBARS Hijacker 3search runtime detection - update (more info ...)misc-activity    URL
12297MALWARE-BACKDOOR bifrost v1.2.1 runtime detection (more info ...)trojan-activity    
12298MALWARE-BACKDOOR bifrost v1.2.1 runtime detection (more info ...)trojan-activity    URL
12303POLICY-SOCIAL Google Chat web client connection (more info ...)policy-violation    
12304POLICY-SOCIAL AOL Instant Messenger web client connection (more info ...)policy-violation    
12305POLICY-SOCIAL Yahoo Messenger web client connection (more info ...)policy-violation    
12358SERVER-OTHER Helix DNA Server RTSP require tag heap overflow attempt (more info ...)attempted-admin 2007-4561 25440  
12359PROTOCOL-VOIP Digium Asterisk data length field overflow attempt (more info ...)attempted-user 2006-5444 20617  URL
12361PUA-ADWARE Infostealer.Monstres outbound connection (more info ...)misc-activity    URL
12363PUA-ADWARE Other-Technologies malware-stopper outbound connection (more info ...)misc-activity    URL
12364PUA-TOOLBARS Hijacker proventactics 3.5 runtime detection - get cfg information (more info ...)misc-activity    URL
12365PUA-ADWARE Hijacker proventactics 3.5 outbound connection - redirect searches (more info ...)misc-activity    URL
12366PUA-TOOLBARS Hijacker proventactics 3.5 runtime detection - toolbar search function (more info ...)misc-activity    URL
12367PUA-ADWARE Hijacker imesh mediabar outbound connection - hijack ie searches (more info ...)misc-activity    URL
12368PUA-ADWARE Hijacker imesh mediabar outbound connection - hijack ie side search (more info ...)misc-activity    URL
12369PUA-ADWARE Hijacker imesh mediabar outbound connection - collect user information (more info ...)misc-activity    URL
12370PUA-TOOLBARS Hijacker imesh mediabar runtime detection - auto update (more info ...)misc-activity    URL
12371MALWARE-CNC User-Agent known malicious user agent - SpamBlockerUtility (more info ...)misc-activity    URL
12372MALWARE-OTHER Keylogger mg-shadow 2.0 runtime detection (more info ...)successful-recon-limited    URL
12373MALWARE-BACKDOOR radmin 3.0 runtime detection - initial connection (more info ...)trojan-activity    
12374MALWARE-BACKDOOR radmin 3.0 runtime detection - initial connection (more info ...)trojan-activity    URL
12375MALWARE-BACKDOOR radmin 3.0 runtime detection - login & remote control (more info ...)trojan-activity    
12376MALWARE-BACKDOOR radmin 3.0 runtime detection - login & remote control (more info ...)trojan-activity    URL
12377MALWARE-BACKDOOR shark 2.3.2 runtime detection (more info ...)trojan-activity    
12378MALWARE-BACKDOOR shark 2.3.2 runtime detection (more info ...)trojan-activity    URL
12392SERVER-MAIL GNU Mailutils request tag format string vulnerability attempt (more info ...)attempted-admin 2005-1523 13764  
12421SERVER-OTHER RealNetworks Helix RTSP long transport header (more info ...)attempted-user 2002-1643 6454  
12422SERVER-OTHER RealNetworks Helix RTSP long describe request exploit attempt (more info ...)attempted-user 2002-1643 6454  
12425PUA-P2P Ruckus P2P client activity (more info ...)policy-violation    
12426PUA-P2P Ruckus P2P broadcast domain probe (more info ...)policy-violation    
12427PUA-P2P Ruckus P2P encrypted authentication connection (more info ...)policy-violation    
12464PROTOCOL-NNTP cancel overflow attempt (more info ...)attempted-admin 2004-0045 9382 11984 
12481PUA-TOOLBARS Hijacker 411web toolbar runtime detection (more info ...)misc-activity    URL
12482MALWARE-CNC User-Agent known malicious user agent - ZOMBIES_HTTP_GET (more info ...)misc-activity    URL
12483PUA-ADWARE Other-Technologies virusprotectpro 3.7 outbound connection (more info ...)misc-activity    URL
12484PUA-ADWARE Adware instant buzz runtime detection - ads for members (more info ...)misc-activity    URL
12485PUA-ADWARE Adware instant buzz runtime detection - random text ads (more info ...)misc-activity    URL
12486PUA-TOOLBARS Hijacker soso toolbar runtime detection - get weather information (more info ...)misc-activity    URL
12487PUA-TOOLBARS Hijacker soso toolbar runtime detection - hijack ie auto searches / soso toolbar searches requests (more info ...)misc-activity    URL
12594SERVER-OTHER Oracle TNS Service_CurLoad command (more info ...)attempted-dos 2002-1118 5678  
12597SERVER-OTHER utf8 filename transfer attempt (more info ...)suspicious-filename-detect 2005-3573 15408  
12620PUA-ADWARE Adware drive cleaner 1.0.111 runtime detection (more info ...)misc-activity    URL
12621PUA-TOOLBARS Trackware extra toolbar 1.0 runtime detection (more info ...)successful-recon-limited    URL
12622PUA-TOOLBARS Trackware extra toolbar 1.0 runtime detection - file download (more info ...)successful-recon-limited    URL
12623PUA-ADWARE Hijacker onestepsearch 1.0.118 outbound connection (more info ...)misc-activity    URL
12624PUA-ADWARE Hijacker onestepsearch 1.0.118 outbound connection - upgrade (more info ...)misc-activity    URL
12625MALWARE-OTHER Keylogger windows family safety 2.0 runtime detection (more info ...)successful-recon-limited    URL
12630INDICATOR-SHELLCODE unescape unicode encoded shellcode (more info ...)shellcode-detect    
12636PROTOCOL-NNTP XHDR buffer overflow attempt (more info ...)attempted-user 2007-3897   URL
12652PUA-ADWARE Hijacker new.net domain 7.2.2 outbound connection - hijack browser (more info ...)misc-activity    URL
12653PUA-ADWARE Hijacker new.net domain 7.2.2 outbound connection - download code (more info ...)misc-activity    URL
12654PUA-ADWARE Hijacker rabio 4.2 outbound connection - hijack browser (more info ...)misc-activity    URL
12655PUA-ADWARE Hijacker rabio 4.2 outbound connection - download updates (more info ...)misc-activity    URL
12656PUA-ADWARE Adware icoo loader 2.5 runtime detection 1 (more info ...)misc-activity    URL
12657PUA-ADWARE Adware icoo loader 2.5 runtime detection 2 (more info ...)misc-activity    URL
12658PUA-ADWARE Adware winantivirus pro 2007 runtime detection (more info ...)misc-activity    URL
12659PUA-ADWARE Trickler zlob media codec outbound connection - automatic updates (more info ...)misc-activity    URL
12660PUA-ADWARE Trickler zlob media codec outbound connection - download redirect domains (more info ...)misc-activity    URL
12661MALWARE-CNC troll.a variant outbound connection (more info ...)trojan-activity    URL
12665SERVER-OTHER CA BrightStor LGSever username buffer overflow attempt (more info ...)attempted-admin 2007-5004 24348  
12666SERVER-OTHER HP OpenView OVTrace buffer overflow attempt (more info ...)attempted-admin 2007-3872 25255  
12672PUA-TOOLBARS Trackware searchmiracle elitebar runtime detection - get ads (more info ...)successful-recon-limited    URL
12674MALWARE-CNC User-Agent known malicious user agent - iebar (more info ...)successful-recon-limited    URL
12675MALWARE-BACKDOOR Versi TheTheef Detection (more info ...)misc-activity    
12676PUA-ADWARE Conspy Update Checking Detected (more info ...)misc-activity    URL
12677PUA-ADWARE Adware ISTBar runtime detection - softwares (more info ...)misc-activity    URL
12678PUA-ADWARE SpyTech Realtime Spy Detection (more info ...)misc-activity    URL
12679PUA-TOOLBARS Trackware myway speedbar / mywebsearch toolbar user-agent detection (more info ...)successful-recon-limited    URL
12680PROTOCOL-VOIP Via header hostname buffer overflow attempt (more info ...)attempted-user 2007-3369 24542  URL
12681PROTOCOL-VOIP SIP URI overflow attempt (more info ...)misc-activity    URL
12682PROTOCOL-VOIP From header field buffer overflow attempt (more info ...)attempted-user 2003-1115 6904  URL
12683PROTOCOL-VOIP From header field buffer overflow attempt (more info ...)attempted-user 2003-1115 6904  URL
12684MALWARE-BACKDOOR Sygate Remote Administration Engine (more info ...)misc-activity 2000-0113 952  URL
12685SERVER-OTHER IBM Tivoli Storage Manager Express CAD Host buffer overflow (more info ...)attempted-admin 2007-4880 25743  
12686POLICY-SOCIAL AIM Express usage (more info ...)policy-violation    URL
12691PUA-P2P Outbound Joltid PeerEnabler traffic detected (more info ...)policy-violation    URL
12693PUA-ADWARE Hijacker personalweb outbound connection (more info ...)misc-activity    URL
12694PUA-ADWARE Adware avsystemcare runtime detection (more info ...)misc-activity    URL
12695PUA-ADWARE Adware coopen 3.6.1 runtime detection - initial connection (more info ...)misc-activity    URL
12696PUA-ADWARE Adware coopen 3.6.1 runtime detection - automatic upgrade (more info ...)misc-activity    URL
12697MALWARE-OTHER Trackware browser accelerator runtime detection - pass user information to server (more info ...)successful-recon-limited    URL
12698MALWARE-OTHER Keylogger net vizo 5.2 runtime detection (more info ...)successful-recon-limited    URL
12699MALWARE-BACKDOOR poison ivy 2.3.0 runtime detection - init connection (more info ...)trojan-activity    
12700MALWARE-BACKDOOR poison ivy 2.3.0 runtime detection - init connection (more info ...)trojan-activity    URL
12704SERVER-MAIL IBM Lotus Notes MIF viewer MIFFILE comment overflow (more info ...)attempted-user 2007-5910 26175  
12705SERVER-MAIL IBM Lotus Notes MIF viewer statement overflow (more info ...)attempted-user 2007-5910 26175  
12710SERVER-OTHER ASN.1 constructed bit string (more info ...)attempted-admin 2005-1935 9633  URL
12712PROTOCOL-SNMP oversized sysName set request (more info ...)attempted-admin 2007-5381 26001  
12713SERVER-ORACLE Oracle Database Server pitrig_dropmetadata buffer overflow attempt (more info ...)attempted-admin 2007-4517 26374  
12718PUA-ADWARE Hijacker side find 1.0 outbound connection - initial connection (more info ...)misc-activity    URL
12719PUA-ADWARE Hijacker side find 1.0 outbound connection - hijacks search engine (more info ...)misc-activity    URL
12720PUA-ADWARE Adware pestbot runtime detection - update (more info ...)misc-activity    URL
12721PUA-ADWARE Adware pestbot runtime detection - purchase (more info ...)misc-activity    URL
12722PUA-ADWARE Hijacker sexyvideoscreensaver outbound connection (more info ...)misc-activity    URL
12723MALWARE-CNC User-Agent known malicious user agent - WakeSpace (more info ...)successful-recon-limited    URL
12724MALWARE-BACKDOOR dark moon 4.11 runtime detection (more info ...)trojan-activity    
12725MALWARE-BACKDOOR dark moon 4.11 runtime detection (more info ...)trojan-activity    URL
12726MALWARE-BACKDOOR bandook 1.35 runtime detection (more info ...)trojan-activity    
12727MALWARE-BACKDOOR bandook 1.35 runtime detection (more info ...)trojan-activity    URL
12728FILE-MULTIMEDIA RealNetworks SMIL wallclock stack overflow attempt (more info ...)attempted-user 2007-3410 24658  
12743FILE-MULTIMEDIA FLAC libFLAC picture description metadata buffer overflow attempt (more info ...)attempted-user 2007-4619 26042  
12745FILE-MULTIMEDIA FLAC libFLAC picture metadata buffer overflow attempt (more info ...)attempted-user 2007-4619 26042  
12758MALWARE-OTHER Keylogger/RAT digi watcher 2.32 runtime detection (more info ...)successful-recon-limited    URL
12759MALWARE-OTHER Keylogger/RAT digi watcher 2.32 runtime detection (more info ...)successful-recon-limited    URL
12760MALWARE-OTHER Keylogger powered Keylogger 2.2 runtime detection (more info ...)successful-recon-limited    URL
12761MALWARE-OTHER Keylogger powered Keylogger 2.2 runtime detection (more info ...)successful-recon-limited    URL
12789PUA-ADWARE Adware sunshine spy 1.0 runtime detection - check update (more info ...)misc-activity    URL
12790MALWARE-OTHER Trackware partypoker runtime detection (more info ...)successful-recon-limited    URL
12791PUA-TOOLBARS Adware gophoria toolbar runtime detection (more info ...)misc-activity    URL
12792MALWARE-OTHER Keylogger spy lantern Keylogger pro 6.0 runtime detection (more info ...)successful-recon-limited    URL
12793MALWARE-OTHER Keylogger spy lantern Keylogger pro 6.0 runtime detection (more info ...)successful-recon-limited    URL
12794PUA-ADWARE Hijacker gralicwrap outbound connection - search frauddb process (more info ...)misc-activity    URL
12795PUA-ADWARE Hijacker gralicwrap outbound connection - display frauddb information (more info ...)misc-activity    URL
12796PUA-TOOLBARS Trackware happytofind toolbar runtime detection (more info ...)successful-recon-limited    URL
12797PUA-ADWARE Adware x-con spyware destroyer eh 3.2.8 runtime detection (more info ...)misc-activity    URL
12807FILE-IDENTIFY Lotus 123 file attachment (more info ...)suspicious-filename-detect 2007-6593 27835  URL
13236MALWARE-OTHER Keylogger active Keylogger 3.9.2 runtime detection (more info ...)successful-recon-limited    URL
13237MALWARE-OTHER Keylogger active Keylogger 3.9.2 runtime detection (more info ...)successful-recon-limited    URL
13238PUA-ADWARE Adware adult p2p 1.5 runtime detection (more info ...)misc-activity    URL
13239PUA-TOOLBARS Hijacker blue wave adult links toolbar runtime detection (more info ...)misc-activity    URL
13240PUA-ADWARE Adware live protection 2.1 runtime detection - redirects to purchase page (more info ...)misc-activity    URL
13241PUA-ADWARE Adware live protection 2.1 runtime detection - application updates (more info ...)misc-activity    URL
13242PUA-ADWARE Adware netpumper 1.26 runtime detection (more info ...)misc-activity    URL
13243MALWARE-OTHER Keylogger computer monitor 1.1 by lastcomfort runtime detection (more info ...)successful-recon-limited    URL
13244MALWARE-OTHER Keylogger computer monitor 1.1 by lastcomfort runtime detection (more info ...)successful-recon-limited    URL
13246MALWARE-BACKDOOR troya 1.4 inbound connection (more info ...)trojan-activity    URL
13247MALWARE-BACKDOOR yuri 1.2 runtime detection - init connection (more info ...)trojan-activity    
13248MALWARE-CNC yuri 1.2 variant outbound connection (more info ...)trojan-activity    URL
13269OS-WINDOWS Multiple product nntp uri handling code execution attempt (more info ...)attempted-user 2007-4041 25945  URL
13270OS-WINDOWS Multiple product news uri handling code execution attempt (more info ...)attempted-user 2007-4041 25945  URL
13271OS-WINDOWS Multiple product telnet uri handling code execution attempt (more info ...)attempted-user 2007-4041 25945  URL
13272OS-WINDOWS Multiple product mailto uri handling code execution attempt (more info ...)attempted-user 2007-4041 25945  URL
13278MALWARE-OTHER Keylogger advanced spy 4.0 runtime detection (more info ...)successful-recon-limited    URL
13279MALWARE-OTHER Keylogger advanced spy 4.0 runtime detection (more info ...)successful-recon-limited    URL
13280MALWARE-OTHER Keylogger email spy monitor 6.9 runtime detection (more info ...)successful-recon-limited    URL
13281MALWARE-OTHER Keylogger email spy monitor 6.9 runtime detection (more info ...)successful-recon-limited    URL
13282PUA-TOOLBARS Adware jily ie toolbar runtime detection (more info ...)misc-activity    URL
13283PUA-ADWARE Hijacker dreambar outbound connection (more info ...)misc-activity    URL
13284PUA-ADWARE Adware netguarder web cleaner runtime detection (more info ...)misc-activity    URL
13285PUA-ADWARE Hijacker phazebar outbound connection (more info ...)misc-activity    URL
13286PUA-ADWARE Adware 3wplayer 1.7 runtime detection (more info ...)misc-activity    URL
13291SERVER-SAMBA Samba send_mailslot buffer overflow attempt (more info ...)attempted-admin 2007-6015 26791  
13316FILE-MULTIMEDIA 3ivx MP4 file parsing ART buffer overflow attempt (more info ...)attempted-user 2007-6402 26773  
13318FILE-MULTIMEDIA 3ivx MP4 file parsing cmt buffer overflow attempt (more info ...)attempted-user 2007-6402 26773  
13319FILE-MULTIMEDIA 3ivx MP4 file parsing des buffer overflow attempt (more info ...)attempted-user 2007-6402 26773  
13320FILE-MULTIMEDIA 3ivx MP4 file parsing cpy buffer overflow attempt (more info ...)attempted-user 2007-6402 26773  
13339PUA-TOOLBARS Hijacker direct toolbar runtime detection (more info ...)misc-activity    URL
13340PUA-ADWARE Hijacker search4top outbound connection - hijack ie searches and error pages (more info ...)misc-activity    URL
13341PUA-ADWARE Hijacker search4top outbound connection - popup ads (more info ...)misc-activity    URL
13342PUA-TOOLBARS Hijacker ditto toolbar runtime detection (more info ...)misc-activity    URL
13343PUA-ADWARE Adware 2005-search loader runtime detection (more info ...)misc-activity    URL
13344PUA-ADWARE Adware yourprivacyguard runtime detection - presale request (more info ...)misc-activity    URL
13345PUA-ADWARE Adware yourprivacyguard runtime detection - update (more info ...)misc-activity    URL
13346PUA-ADWARE Snoopware remote desktop inspector outbound connection - init connection (more info ...)successful-recon-limited    URL
13347PUA-ADWARE Snoopware remote desktop inspector runtime detection - init connection (more info ...)successful-recon-limited    URL
13361FILE-OTHER ClamAV MEW PE file integer overflow attempt (more info ...)attempted-user 2007-6335 26927  
13415SERVER-OTHER CA BrightStor cheyenneds mailslot overflow (more info ...)attempted-admin 2006-5142 20364  
13417SERVER-OTHER Citrix MetaFrame IMA authentication processing buffer overflow attempt (more info ...)attempted-admin 2006-5821 20986  URL
13418SERVER-OTHER IBM Tivoli Director LDAP server invalid DN message buffer overflow attempt (more info ...)attempted-dos 2011-0917 16593  URL
13425SERVER-OTHER openldap server bind request denial of service attempt (more info ...)denial-of-service 2006-5779 20939  
13479MALWARE-OTHER Keylogger findnot guarddog 4.0 runtime detection (more info ...)successful-recon-limited    URL
13480MALWARE-OTHER Keylogger findnot guarddog 4.0 runtime detection (more info ...)successful-recon-limited    URL
13481PUA-TOOLBARS Hijacker baidu toolbar runtime detection - hijacks search engine (more info ...)misc-activity    URL
13482PUA-TOOLBARS Hijacker baidu toolbar runtime detection - discloses information (more info ...)misc-activity    URL
13483PUA-TOOLBARS Hijacker baidu toolbar runtime detection - updates automatically (more info ...)misc-activity    
13484PUA-TOOLBARS Hijacker baidu toolbar runtime detection - updates automatically (more info ...)misc-activity    URL
13485PUA-TOOLBARS Hijacker sofa toolbar runtime detection - hijacks search engine (more info ...)misc-activity    URL
13486PUA-TOOLBARS Hijacker sofa toolbar runtime detection - records search information (more info ...)misc-activity    URL
13487PUA-ADWARE Adware elite protector runtime detection (more info ...)misc-activity    URL
13488PUA-TOOLBARS Hijacker people pal toolbar runtime detection - automatic upgrade (more info ...)misc-activity    URL
13489PUA-TOOLBARS Hijacker people pal toolbar runtime detection - traffic for searching (more info ...)misc-activity    URL
13490PUA-ADWARE Adware spy shredder 2.1 runtime detection - presale request (more info ...)misc-activity    URL
13491PUA-ADWARE Adware spy shredder 2.1 runtime detection - update (more info ...)misc-activity    URL
13492PUA-TOOLBARS Hijacker deepdo toolbar runtime detection - redirects search engine (more info ...)misc-activity    URL
13493PUA-TOOLBARS Hijacker deepdo toolbar runtime detection - automatic update (more info ...)misc-activity    URL
13494MALWARE-OTHER Keylogger smart pc Keylogger runtime detection (more info ...)successful-recon-limited    URL
13495PUA-TOOLBARS Hijacker ez-tracks toolbar runtime detection - initial traffic 1 (more info ...)misc-activity    URL
13496PUA-TOOLBARS Hijacker ez-tracks toolbar runtime detection - initial traffic 2 (more info ...)misc-activity    URL
13497PUA-TOOLBARS Hijacker ez-tracks toolbar runtime detection - tracking traffic (more info ...)misc-activity    URL
13498PUA-ADWARE Hijacker hbtbar outbound connection - search traffic 1 (more info ...)misc-activity    URL
13499PUA-ADWARE Hijacker hbtbar outbound connection - search traffic 2 (more info ...)misc-activity    URL
13500PUA-ADWARE Hijacker hbtbar outbound connection - log information (more info ...)misc-activity    URL
13501PUA-ADWARE Adware contravirus runtime detection - presale request (more info ...)misc-activity    URL
13502PUA-ADWARE Adware contravirus runtime detection - update (more info ...)misc-activity    URL
13504PUA-ADWARE Adware iedefender runtime detection - presale request (more info ...)misc-activity    URL
13505PUA-ADWARE Adware iedefender runtime detection - update (more info ...)misc-activity    URL
13506MALWARE-BACKDOOR evilotus 1.3.2 runtime detection - init connection (more info ...)trojan-activity    
13507MALWARE-CNC evilotus 1.3.2 variant outbound connection (more info ...)trojan-activity    URL
13508MALWARE-CNC xploit 1.4.5 variant outbound connection (more info ...)trojan-activity    
13509MALWARE-CNC xploit 1.4.5 pc variant outbound connection (more info ...)trojan-activity    URL
13559PUA-TOOLBARS Hijacker kompass toolbar runtime detection - initial connection (more info ...)misc-activity    URL
13560PUA-TOOLBARS Hijacker kompass toolbar runtime detection - search traffic (more info ...)misc-activity    URL
13561PUA-ADWARE Adware malware alarm runtime detection - presale request (more info ...)misc-activity    URL
13562PUA-ADWARE Adware malware alarm runtime detection - update request (more info ...)misc-activity    URL
13563PUA-ADWARE Adware system doctor runtime detection - presale request (more info ...)misc-activity    URL
13564PUA-ADWARE Adware system doctor runtime detection - update status (more info ...)misc-activity    URL
13565PUA-ADWARE Trickler iecodec outbound connection - initial traffic (more info ...)misc-activity    URL
13566PUA-ADWARE Trickler iecodec outbound connection - message dialog (more info ...)misc-activity    URL
13567MALWARE-OTHER Keylogger msn spy monitor runtime detection (more info ...)successful-recon-limited    URL
13568MALWARE-OTHER Keylogger sys keylog 1.3 advanced runtime detection (more info ...)successful-recon-limited    URL
13617SERVER-ORACLE Oracle database version 8 username buffer overflow attempt (more info ...)attempted-admin 2003-0095 6849  URL
13618SERVER-ORACLE Oracle database version 9 username buffer overflow attempt (more info ...)attempted-admin 2003-0095 6849  URL
13625MALWARE-CNC MBR rootkit HTTP POST activity detected (more info ...)trojan-activity    URL
13631SERVER-OTHER McAfee ePolicy Orchestrator Framework Services log handling format string attempt (more info ...)attempted-admin 2008-1357 28228  
13632SERVER-OTHER Zango adware installation request (more info ...)policy-violation    URL
13635PUA-ADWARE Trickler downloader trojan.gen outbound connection - get malicious link (more info ...)misc-activity    URL
13636PUA-ADWARE Trickler downloader trojan.gen outbound connection - download malicious link (more info ...)misc-activity    URL
13637PUA-ADWARE Adware virus heat runtime detection - presale request (more info ...)misc-activity    URL
13638MALWARE-CNC User-Agent known Adware user-agent string - Win.Adware.VirusHeat (more info ...)trojan-activity    URL
13639PUA-TOOLBARS Hijacker locmag toolbar runtime detection - connection to toolbar (more info ...)misc-activity    URL
13640PUA-TOOLBARS Hijacker locmag toolbar runtime detection - hijacks address bar (more info ...)misc-activity    URL
13641PUA-TOOLBARS Hijacker eclickz toolbar runtime detection - search traffic (more info ...)misc-activity    URL
13642MALWARE-OTHER Keylogger easy Keylogger runtime detection (more info ...)successful-recon-limited    URL
13643PUA-TOOLBARS Hijacker zztoolbar runtime detection - toolbar traffic (more info ...)misc-activity    URL
13644PUA-TOOLBARS Hijacker zztoolbar runtime detection - search traffic (more info ...)misc-activity    URL
13645PUA-TOOLBARS Hijacker mxs toolbar runtime detection (more info ...)misc-activity    URL
13646PUA-ADWARE Adware registry defender runtime detection - presale request (more info ...)misc-activity    URL
13647PUA-ADWARE Adware registry defender runtime detection - error report request (more info ...)misc-activity    URL
13648PUA-ADWARE Hijacker mysearch bar 2.0.2.28 runtime detection (more info ...)misc-activity    URL
13649PUA-ADWARE Adware spyware stop runtime detection - presale request (more info ...)misc-activity    URL
13650PUA-ADWARE Adware spyware stop runtime detection - auto updates (more info ...)misc-activity    URL
13652PUA-ADWARE Keylogger all in one Keylogger runtime detection (more info ...)successful-recon-limited    URL
13653PUA-ADWARE Adware cashfiesta adbar runtime detection - updates traffic (more info ...)misc-activity    URL
13654MALWARE-CNC nuclear rat 2.1 variant outbound connection (more info ...)trojan-activity    
13655MALWARE-CNC nuclear rat 2.1 variant outbound connection (more info ...)trojan-activity    URL
13664PROTOCOL-VOIP Remote-Party-ID header hexadecimal characters in IP address field (more info ...)attempted-admin 2007-1542 23047  URL
13693PROTOCOL-VOIP Attribute header rtpmap field invalid payload type (more info ...)attempted-user 2008-1289 28308  URL
13694SERVER-OTHER RealNetworks Helix RTSP long get request exploit attempt (more info ...)attempted-user 2002-1643 6454  
13695SERVER-OTHER RealNetworks Helix RTSP long setup request exploit attempt (more info ...)attempted-user 2002-1643 6454  
13762PUA-ADWARE Adware system defender runtime detection (more info ...)misc-activity    URL
13764PUA-ADWARE Snoopware xpress remote outbound connection - init connection (more info ...)successful-recon-limited    URL
13765PUA-ADWARE Adware winxdefender runtime detection - presale request (more info ...)misc-activity    URL
13766PUA-ADWARE Adware winxdefender runtime detection - auto update (more info ...)misc-activity    URL
13767MALWARE-OTHER Keylogger cyber sitter runtime detection (more info ...)successful-recon-limited    URL
13768MALWARE-OTHER Keylogger cyber sitter runtime detection (more info ...)successful-recon-limited    URL
13769PUA-TOOLBARS Hijacker searchnine toolbar runtime detection - hijacks address bar (more info ...)misc-activity    URL
13770PUA-TOOLBARS Hijacker searchnine toolbar runtime detection - redirects search function (more info ...)misc-activity    URL
13771PUA-TOOLBARS Hijacker music of faith toolbar runtime detection - hijacks search engine traffic #1 (more info ...)misc-activity    URL
13772PUA-TOOLBARS Hijacker music of faith toolbar runtime detection - hijacks search engine traffic #2 (more info ...)misc-activity    URL
13774PUA-ADWARE Trickler trojan ecodec outbound connection - initial server connection #1 (more info ...)misc-activity    URL
13775PUA-ADWARE Trickler trojan ecodec outbound connection - initial server connection #2 (more info ...)misc-activity    URL
13776MALWARE-OTHER Trackware syscleaner runtime detection - presale traffic (more info ...)successful-recon-limited    URL
13777MALWARE-CNC User-Agent known malicious user agent - SysCleaner (more info ...)successful-recon-limited    URL
13778MALWARE-OTHER Keylogger kgb employee monitor runtime detection (more info ...)successful-recon-limited    URL
13779PUA-TOOLBARS Trackware proofile toolbar runtime detection (more info ...)successful-recon-limited    URL
13780PUA-TOOLBARS Hijacker find.fm toolbar runtime detection - automatic updates (more info ...)misc-activity    URL
13781PUA-TOOLBARS Hijacker find.fm toolbar runtime detection - hijacks address bar (more info ...)misc-activity    URL
13782MALWARE-CNC User-Agent known malicious user agent - EzReward (more info ...)misc-activity    URL
13797FILE-IDENTIFY Portable Executable compact binary file magic detected (more info ...)misc-activity    
13808PUA-ADWARE Adware ie antivirus runtime detection - presale request (more info ...)misc-activity    URL
13809PUA-ADWARE Adware ie antivirus runtime detection - update request (more info ...)misc-activity    URL
13811PUA-ADWARE Adware xp antivirus runtime detection (more info ...)misc-activity    URL
13812MALWARE-OTHER Keylogger refog Keylogger runtime detection (more info ...)successful-recon-limited    URL
13813PUA-ADWARE Trickler mm.exe outbound connection (more info ...)misc-activity    URL
13815MALWARE-CNC zombget.03 variant outbound connection (more info ...)trojan-activity    URL
13844SERVER-MAIL BDAT size longer than contents exploit attempt (more info ...)attempted-dos 2002-0055   
13845SERVER-MAIL BDAT size public exploit attempt (more info ...)attempted-dos 2002-0055   
13847PUA-ADWARE Adware phoenician casino runtime detection (more info ...)misc-activity    URL
13848PUA-ADWARE Trickler zwinky runtime detection (more info ...)misc-activity    URL
13849PUA-ADWARE Hijacker rcse 4.4 outbound connection - hijack ie browser (more info ...)misc-activity    URL
13850PUA-ADWARE Adware roogoo 2.0 runtime detection - popup ads (more info ...)misc-activity    URL
13851PUA-ADWARE Adware roogoo 2.0 runtime detection - upgrade (more info ...)misc-activity    URL
13852PUA-ADWARE Hijacker bitroll 5.0 outbound connection (more info ...)misc-activity    URL
13853PUA-TOOLBARS Hijacker alot toolbar runtime detection - weather request (more info ...)misc-activity    URL
13854PUA-TOOLBARS Hijacker alot toolbar runtime detection - auto update (more info ...)misc-activity    URL
13855MALWARE-CNC User-Agent known malicious user agent - SpeedRunner (more info ...)successful-recon-limited    URL
13856MALWARE-CNC Win.Trojan.wintrim.z variant outbound connection (more info ...)trojan-activity    URL
13861POLICY-SOCIAL Habbo chat client avatar control (more info ...)policy-violation    URL
13862POLICY-SOCIAL Habbo chat client item information download (more info ...)policy-violation    URL
13863POLICY-SOCIAL Habbo chat client successful login (more info ...)policy-violation    URL
13866MALWARE-OTHER Trackware adclicker-fc.gen.a runtime detection - popup ads (more info ...)successful-recon-limited    URL
13867MALWARE-OTHER Trackware adclicker-fc.gen.a runtime detection (more info ...)successful-recon-limited    URL
13868PUA-ADWARE Adware antispywaremaster runtime detection - start fake scanning (more info ...)misc-activity    URL
13869PUA-ADWARE Adware antispywaremaster runtime detection - sale/register request (more info ...)misc-activity    URL
13870PUA-ADWARE Adware coopen 5.0.0.87 runtime detection - init conn (more info ...)misc-activity    URL
13871PUA-ADWARE Adware coopen 5.0.0.87 runtime detection - ads (more info ...)misc-activity    URL
13872PUA-ADWARE Trickler fushion 1.2.4.17 outbound connection - notice (more info ...)misc-activity    URL
13873PUA-ADWARE Trickler fushion 1.2.4.17 outbound connection - underground traffic (more info ...)misc-activity    URL
13874PUA-ADWARE Adware malware destructor 4.5 runtime detection - order request (more info ...)misc-activity    URL
13875PUA-ADWARE Adware malware destructor 4.5 runtime detection - auto update (more info ...)misc-activity    URL
13876MALWARE-CNC zlob.acc variant outbound connection (more info ...)trojan-activity    URL
13877MALWARE-CNC Win.Trojan.delf.uv variant outbound connection (more info ...)trojan-activity    
13878MALWARE-CNC Win.Trojan.delf.uv inbound connection (more info ...)trojan-activity    URL
13902SERVER-OTHER IBM Lotus Sametime multiplexer stack buffer overflow attempt (more info ...)attempted-admin 2008-2499 29328  
13915FILE-IDENTIFY BAK file download request (more info ...)misc-activity    
13916SERVER-WEBAPP Alt-N SecurityGateway username buffer overflow attempt (more info ...)attempted-admin 2008-4193 29457  URL
13930PUA-ADWARE Trickler pc privacy cleaner outbound connection - order/register request (more info ...)misc-activity    URL
13931MALWARE-CNC User-Agent known malicious user agent - PcPcUpdater (more info ...)misc-activity    URL
13933MALWARE-OTHER Trackware rightonadz.biz adrotator runtime detection - ads (more info ...)successful-recon-limited    URL
13934MALWARE-CNC Hijacker mediatubecodec 1.470.0 variant outbound connection hijack ie (more info ...)misc-activity    URL
13935MALWARE-CNC Hijacker mediatubecodec 1.470.0 variant outbound connection download other malware (more info ...)misc-activity    URL
13936MALWARE-CNC Trickler dropper agent.rqg variant outbound connection call home (more info ...)misc-activity    URL
13937PUA-ADWARE Hijacker adware.win32.ejik.ec variant runtime detection - call home (more info ...)misc-activity    URL
13938PUA-ADWARE Hijacker adware.win32.ejik.ec variant outbound connection (more info ...)misc-activity    
13939PUA-ADWARE Hijacker adware.win32.ejik.ec variant runtime detection - auto update (more info ...)misc-activity    URL
13940PUA-ADWARE Hijacker win32.bho.bgf outbound connection (more info ...)misc-activity    URL
13941MALWARE-CNC Win.Trojan.agent.nac variant outbound connection click fraud (more info ...)trojan-activity    URL
13942MALWARE-CNC Win.Trojan.agent.nac variant outbound connection call home (more info ...)trojan-activity    URL
13943PUA-ADWARE Trickler dropper agent.rqg outbound connection (more info ...)trojan-activity    
13944MALWARE-CNC Win.Trojan.small.gy variant outbound connection get whitelist (more info ...)trojan-activity    URL
13945MALWARE-CNC Win.Trojan.small.gy variant outbound connection update (more info ...)trojan-activity    URL
13946FILE-IMAGE Apple PICT/Quickdraw image converter packType 4 buffer overflow exploit attempt (more info ...)attempted-user 2008-3021   URL
13947FILE-IMAGE Apple PICT/Quickdraw image converter packType 3 buffer overflow exploit attempt (more info ...)attempted-user 2008-3018   URL
13951SERVER-WEBAPP Oracle Database Server buffer overflow attempt (more info ...)misc-attack 2008-2607 30177  
13953MALWARE-CNC Asprox trojan initial query (more info ...)trojan-activity    URL
14018FILE-IDENTIFY PLS multimedia playlist file download request (more info ...)misc-activity    URL
14019FILE-MULTIMEDIA CyberLink PowerDVD playlist file handling stack overflow attempt (more info ...)attempted-user  30341  
14020FILE-MULTIMEDIA CyberLink PowerDVD playlist file handling stack overflow attempt (more info ...)attempted-user  30341  
14039FILE-OTHER GNOME Project libxslt RC4 key string buffer overflow attempt (more info ...)attempted-user 2008-2935 30467  URL
14040SERVER-OTHER GNOME Project libxslt RC4 key string buffer overflow attempt (more info ...)attempted-user 2008-2935 30467  URL
14041SERVER-OTHER GNOME Project libxslt RC4 key string buffer overflow attempt - 2 (more info ...)attempted-user 2008-2935 30467  URL
14054PUA-ADWARE Adware AdwareALERT runtime detection - auto update (more info ...)misc-activity    URL
14055PUA-TOOLBARS Hijacker rediff toolbar runtime detection - hijack ie auto search (more info ...)misc-activity    URL
14056PUA-TOOLBARS Hijacker rediff toolbar runtime detection - get news info (more info ...)misc-activity    URL
14057MALWARE-CNC User-Agent known malicious user agent - DMFR (more info ...)successful-recon-limited    URL
14058PUA-ADWARE Hijacker cpush 2 outbound connection - pass info to controlling server (more info ...)misc-activity    URL
14059MALWARE-CNC User-Agent known malicious user agent - CPUSH_HOMEPAGE (more info ...)misc-activity    URL
14060MALWARE-CNC User-Agent known malicious user agent - CPUSH_UPDATER (more info ...)misc-activity    URL
14061PUA-ADWARE Trickler antimalware guard runtime detection - order/register request (more info ...)misc-activity    URL
14062PUA-ADWARE Trickler antimalware guard runtime detection - auto update (more info ...)misc-activity    URL
14063PUA-ADWARE Hijacker cashon outbound connection - hijack ie searches (more info ...)misc-activity    URL
14064PUA-ADWARE Hijacker cashon outbound connection - auto update (more info ...)misc-activity    URL
14065MALWARE-OTHER Keylogger emptybase j runtime detection (more info ...)successful-recon-limited    URL
14067PUA-ADWARE Adware swizzor runtime detection (more info ...)misc-activity    URL
14068PUA-ADWARE Adware rond runtime detection (more info ...)misc-activity    URL
14069PUA-ADWARE Adware brave sentry runtime detection - order request (more info ...)misc-activity    URL
14070PUA-ADWARE Adware brave sentry runtime detection - self update (more info ...)misc-activity    URL
14071PUA-ADWARE Hijacker Adware bho.gen runtime detection - pop-up window traffic #1 (more info ...)misc-activity    URL
14072PUA-ADWARE Hijacker Adware bho.gen runtime detection - pop-up window traffic #2 (more info ...)misc-activity    URL
14073PUA-ADWARE Hijacker Adware bho.gen runtime detection - prompt download page (more info ...)misc-activity    URL
14074MALWARE-OTHER Keylogger spybosspro 4.2 runtime detection (more info ...)successful-recon-limited    URL
14075MALWARE-OTHER Keylogger ultimate Keylogger pro runtime detection (more info ...)successful-recon-limited    URL
14076PUA-ADWARE Hijacker Adware win32 mostofate runtime detection - hijack search (more info ...)misc-activity    URL
14077PUA-ADWARE Hijacker Adware win32 mostofate runtime detection - redirect search results (more info ...)misc-activity    URL
14081MALWARE-CNC Win.Trojan.agent.aarm variant outbound connection call home (more info ...)trojan-activity    URL
14082MALWARE-CNC Win.Trojan.agent.aarm variant outbound connection spread via spam (more info ...)trojan-activity    URL
14083MALWARE-CNC Win.Trojan.agent.aarm variant outbound connection download other malware (more info ...)trojan-activity    URL
14084MALWARE-CNC infostealer.banker.c variant outbound connection download cfg.bin (more info ...)trojan-activity    URL
14085MALWARE-CNC infostealer.banker.c variant outbound connection collect user info (more info ...)trojan-activity    URL
14086MALWARE-CNC Adware.Win32.Agent.BM variant outbound connection 1 (more info ...)trojan-activity    URL
14087MALWARE-CNC Adware.Win32.Agent.BM variant outbound connection 2 (more info ...)trojan-activity    URL
14230SERVER-WEBAPP SAP DB web server stack buffer overflow attempt (more info ...)attempted-admin 2007-3614 24773  
14265PROTOCOL-SCADA Multiple Schneider Electric SCADA products buffer overflow attempt (more info ...)attempted-admin 2008-2639 29634  URL
14600SERVER-OTHER SAP Message Server Heap buffer overflow attempt (more info ...)attempted-user 2007-3624 24765  
14602SERVER-OTHER Borland Interbase open_marker_file overflow attempt (more info ...)attempted-user 2007-5244 25917  
14608PROTOCOL-VOIP T.38 fax rate management attribute buffer overflow attempt (more info ...)attempted-admin 2007-2293 23648  
14609PROTOCOL-VOIP T.38 fax EC attribute buffer overflow attempt (more info ...)attempted-admin 2007-2293 23648  
14646OS-WINDOWS Active Directory malformed baseObject denial of service attempt (more info ...)attempted-dos 2008-4023   URL
14986INDICATOR-SHELLCODE x86 fldz get eip shellcode (more info ...)shellcode-detect    
14992SERVER-WEBAPP Openwsman HTTP basic authentication buffer overflow attempt (more info ...)attempted-user 2008-2234 30694  
15071PROTOCOL-SCADA Modbus exception returned (more info ...)protocol-command-decode    URL
15074PROTOCOL-SCADA Modbus user-defined function code - 65 to 72 (more info ...)protocol-command-decode    URL
15075PROTOCOL-SCADA Modbus user-defined function code - 100 to 110 (more info ...)protocol-command-decode    URL
15078SERVER-OTHER HP Openview Network Node Manager OValarmsrv buffer overflow attempt (more info ...)attempted-admin 2008-1852   
15080FILE-MULTIMEDIA VideoLAN VLC Media Player WAV processing integer overflow attempt (more info ...)misc-activity 2008-2430 30058  
15124OS-WINDOWS Web-based NTLM replay attack attempt (more info ...)attempted-user 2015-0005   URL
15145SERVER-OTHER Apple CUPS TrueColor PNG filter overly large image height integer overflow attempt (more info ...)attempted-admin 2008-5286 32518  URL
15146SERVER-OTHER Apple CUPS RGB+Alpha PNG filter overly large image height integer overflow attempt (more info ...)attempted-admin 2008-5286 32518  URL
15149SERVER-ORACLE Oracle Internet Directory pre-auth ldap denial of service attempt (more info ...)attempted-dos 2008-2595 30177  URL
15157FILE-MULTIMEDIA VideoLAN VLC Media Player XSPF memory corruption attempt (more info ...)attempted-user 2008-4558   
15158FILE-IDENTIFY XML Shareable Playlist Format file download request (more info ...)misc-activity    URL
15165MALWARE-CNC Pushdo client communication (more info ...)trojan-activity    URL
15166FILE-MULTIMEDIA VideoLAN VLC Media Player RealText buffer overflow attempt (more info ...)attempted-user 2008-5036   
15170POLICY-SOCIAL XBOX Netflix client activity (more info ...)policy-violation    
15171POLICY-SOCIAL XBOX Marketplace http request (more info ...)policy-violation    
15172POLICY-SOCIAL XBOX avatar retrieval request (more info ...)policy-violation    
15183POLICY-SOCIAL Yahoo messenger http link transmission attempt (more info ...)trojan-activity    URL
15185APP-DETECT Nintendo Wii SSL Server Hello (more info ...)policy-violation    
15188SERVER-OTHER Multiple vendors CUPS HPGL filter remote code execution attempt (more info ...)attempted-user 2008-3641 31688  URL
15190SERVER-WEBAPP Youngzsoft CCProxy CONNECT Request buffer overflow attempt (more info ...)attempted-user 2008-6415 31416  
15236FILE-IMAGE ACD Systems ACDSee XPM file format overflow attempt (more info ...)attempted-user 2007-2193 23620  
15239FILE-IDENTIFY RealNetworks RealMedia format file download request (more info ...)misc-activity    URL
15240FILE-IDENTIFY RealNetworks RealMedia format file download request (more info ...)misc-activity    URL
15241FILE-MULTIMEDIA VideoLAN VLC real.c ReadRealIndex real demuxer integer overflow attempt (more info ...)attempted-user 2008-5276 32545  
15256SERVER-ORACLE BPEL process manager XSS injection attempt (more info ...)web-application-attack 2008-4014   URL
15296MALWARE-CNC Win.Trojan.Bankpatch malicious file download (more info ...)trojan-activity    URL
15297MALWARE-CNC Win.Trojan.Bankpatch report home (more info ...)trojan-activity    URL
15364SERVER-OTHER Ganglia Meta Daemon process_path stack buffer overflow attempt (more info ...)attempted-user 2009-0241 33299  URL
15382SERVER-OTHER X.Org X Font Server QueryXBitmaps and QueryXExtents Handlers integer overflow attempt (more info ...)attempted-admin 2007-4568 25898  
15389PROTOCOL-SCADA OMRON-FINS memory area write attempt (more info ...)protocol-command-decode    URL
15390PROTOCOL-SCADA OMRON-FINS memory area fill attempt (more info ...)protocol-command-decode    URL
15391PROTOCOL-SCADA OMRON-FINS memory area transfer attempt (more info ...)protocol-command-decode    URL
15392PROTOCOL-SCADA OMRON-FINS parameter area write attempt (more info ...)protocol-command-decode    URL
15393PROTOCOL-SCADA OMRON-FINS parameter area clear attempt (more info ...)protocol-command-decode    URL
15394PROTOCOL-SCADA OMRON-FINS program area protect attempt (more info ...)protocol-command-decode    URL
15396PROTOCOL-SCADA OMRON-FINS program area write attempt (more info ...)protocol-command-decode    URL
15397PROTOCOL-SCADA OMRON-FINS program area clear attempt (more info ...)protocol-command-decode    URL
15398PROTOCOL-SCADA OMRON-FINS RUN attempt (more info ...)protocol-command-decode    URL
15399PROTOCOL-SCADA OMRON-FINS STOP attempt (more info ...)protocol-command-decode    URL
15400PROTOCOL-SCADA OMRON-FINS clock write attempt (more info ...)protocol-command-decode    URL
15401PROTOCOL-SCADA OMRON-FINS access right acquire attempt (more info ...)protocol-command-decode    URL
15402PROTOCOL-SCADA OMRON-FINS access right forced acquire attempt (more info ...)protocol-command-decode    URL
15403PROTOCOL-SCADA OMRON-FINS single file write attempt (more info ...)protocol-command-decode    URL
15404PROTOCOL-SCADA OMRON-FINS file delete attempt (more info ...)protocol-command-decode    URL
15405PROTOCOL-SCADA OMRON-FINS forced set/reset attempt (more info ...)protocol-command-decode    URL
15406PROTOCOL-SCADA OMRON-FINS forced set/reset cancel attempt (more info ...)protocol-command-decode    URL
15407PROTOCOL-SCADA OMRON-FINS file memory write attempt (more info ...)protocol-command-decode    URL
15408PROTOCOL-SCADA OMRON-FINS data link table write attempt (more info ...)protocol-command-decode    URL
15409PROTOCOL-SCADA OMRON-FINS RESET attempt (more info ...)protocol-command-decode    URL
15410PROTOCOL-SCADA OMRON-FINS name delete attempt (more info ...)protocol-command-decode    URL
15411PROTOCOL-SCADA OMRON-FINS memory card format attempt (more info ...)protocol-command-decode    URL
15412PROTOCOL-SCADA OMRON-FINS memory area write overflow attempt (more info ...)protocol-command-decode    URL
15413PROTOCOL-SCADA OMRON-FINS memory area fill overflow attempt (more info ...)protocol-command-decode    URL
15414PROTOCOL-SCADA OMRON-FINS program area protect clear brute force attempt (more info ...)protocol-command-decode    URL
15423MALWARE-CNC Clampi virus communication detected (more info ...)trojan-activity    URL
15426FILE-IDENTIFY MAKI file download request (more info ...)misc-activity    
15435SERVER-OTHER IBM Director CIM server consumer name handling denial of service attempt (more info ...)attempted-dos 2009-0879 34061  
15445SERVER-ORACLE Application Server BPEL module cross site scripting attempt (more info ...)attempted-user 2008-4014   
15451MALWARE-CNC possible Conficker.C HTTP traffic 1 (more info ...)trojan-activity    URL
15452MALWARE-CNC possible Conficker.C HTTP traffic 2 (more info ...)trojan-activity    URL
15453OS-WINDOWS SMB replay attempt via NTLMSSP - overlapping encryption keys detected (more info ...)attempted-user 2015-0005   URL
15456SERVER-OTHER WinHTTP SSL/TLS impersonation attempt (more info ...)misc-attack 2009-0089   URL
15472FILE-MULTIMEDIA Multiple MP3 player PLS buffer overflow attempt (more info ...)attempted-user 2009-0476 33589  
15473FILE-MULTIMEDIA Multiple media players M3U playlist file handling buffer overflow attempt (more info ...)attempted-user 2006-6063 21206  
15476PUA-ADWARE Waledac spam bot HTTP POST request (more info ...)misc-activity    URL
15481MALWARE-CNC Zeus/Zbot malware config file download request (more info ...)trojan-activity    URL
15485SERVER-MAIL IBM Lotus Notes DOC attachment viewer buffer overflow (more info ...)attempted-user 2007-5544 26146  
15491SERVER-WEBAPP Subversion 1.0.2 dated-rev-report buffer overflow over http attempt (more info ...)attempted-user 2004-0397 10386  
15509SERVER-OTHER IBM DB2 database server CONNECT denial of service attempt (more info ...)denial-of-service 2009-0172   
15514SERVER-OTHER Multiple Vendors NTP Daemon Autokey stack buffer overflow attempt (more info ...)attempted-admin 2009-1252 35017  URL
15518FILE-IDENTIFY Embedded Open Type Font file download request (more info ...)misc-activity    URL
15553MALWARE-CNC Sality virus HTTP GET request (more info ...)trojan-activity    URL
15555SERVER-OTHER Symantec Alert Management System Intel Alert Originator Service buffer overflow attempt (more info ...)attempted-admin 2009-1430 34672  URL
15563MALWARE-CNC RSPlug Win.Trojan.server connection (more info ...)trojan-activity    URL
15564MALWARE-CNC RSPlug Win.Trojan.file download (more info ...)misc-activity    URL
15565MALWARE-CNC RSPlug Win.Trojan.file download (more info ...)misc-activity    URL
15566PUA-ADWARE Gumblar HTTP GET request attempt (more info ...)trojan-activity    URL
15567PUA-ADWARE Martuz HTTP GET request attempt (more info ...)trojan-activity    URL
15572SERVER-OTHER Curse of Silence Nokia SMS DoS attempt (more info ...)attempted-dos  33072  
15579SERVER-OTHER Squid NTLM fakeauth_auth Helper denial of service attempt (more info ...)attempted-dos 2005-0097 12220  
15580SERVER-OTHER Squid oversized reply header handling exploit attempt (more info ...)bad-unknown 2005-0241 12412  
15582FILE-IDENTIFY ARJ format file download request (more info ...)misc-activity    URL
15583FILE-OTHER F-Secure AntiVirus library heap overflow attempt (more info ...)attempted-user 2005-0350 12515  
15683SERVER-OTHER ISA Server OTP-based Forms-authorization fallback policy bypass attempt (more info ...)attempted-user 2009-1135   URL
15684OS-WINDOWS Multiple product snews uri handling code execution attempt (more info ...)attempted-user 2007-4041 25945  URL
15711PUA-OTHER mIRC PRIVMSG message processing overflow attempt (more info ...)attempted-user 2008-4449 31552  
15719PROTOCOL-SCADA DNP3 link service not supported (more info ...)protocol-command-decode    URL
15730MALWARE-CNC Win.Trojan.Delf variant outbound connection (more info ...)trojan-activity    URL
15847OS-WINDOWS Telnet-based NTLM replay attack attempt (more info ...)attempted-user 2015-0005   URL
15850OS-WINDOWS Remote Desktop orderType remote code execution attempt (more info ...)attempted-user 2009-1133 35971  URL
15870FILE-IDENTIFY 4XM file download request (more info ...)misc-activity    URL
15871FILE-MULTIMEDIA FFmpeg 4xm processing memory corruption attempt (more info ...)attempted-user 2009-0385 33502  
15882SERVER-OTHER McAfee E-Business Server remote preauth code execution attempt (more info ...)attempted-admin 2008-0127   URL
15892SERVER-OTHER SAPLPD 0x53 command denial of service attempt (more info ...)attempted-dos 2008-0621 27613  
15893FILE-OTHER fCreateShellLink function use - potential attack (more info ...)misc-activity 2008-2959 29792  
15902INDICATOR-SHELLCODE x86 win2k-2k3 decoder base shellcode (more info ...)attempted-user 2006-3439 19409  
15903INDICATOR-SHELLCODE x86 PoC CVE-2003-0605 (more info ...)attempted-user 2003-0605   
15922FILE-IDENTIFY MP3 file download request (more info ...)misc-activity    URL
15937SERVER-OTHER protos h323 buffer overflow (more info ...)attempted-admin    URL
15938MALWARE-CNC SubSeven client connection to server (more info ...)trojan-activity    URL
15941SERVER-OTHER Squid Proxy TRACE request remote DoS attempt (more info ...)attempted-admin 2007-1560 23085  
15945FILE-IDENTIFY RSS file download request (more info ...)misc-activity    URL
15948SERVER-OTHER CA License Software invalid command overflow attempt (more info ...)attempted-admin 2005-0581 12705  
15949FILE-OTHER McAfee LHA file handling overflow attempt (more info ...)attempted-user 2005-0643 10243  
15950SERVER-OTHER McAfee LHA Type-2 file handling overflow attempt (more info ...)attempted-user 2005-0644 12832  
15953SERVER-WEBAPP Ipswitch IMail Calendaring arbitrary file read attempt (more info ...)attempted-recon 2005-1252 13727  
15954SERVER-MAIL SpamAssassin malformed email header DoS attempt (more info ...)attempted-dos 2005-1266 13978  
15957FILE-OTHER Sophos Anti-Virus zip file handling DoS attempt (more info ...)attempted-dos 2005-1530 14270  
15961SERVER-OTHER 3Com Network Supervisor directory traversal attempt (more info ...)attempted-recon 2005-2020 14715  
15962SERVER-WEBAPP Sybase EAServer WebConsole overflow attempt (more info ...)attempted-user 2005-2297 14287  
15969SERVER-OTHER Symantec Multiple Products ISAKMPd denial of service attempt (more info ...)attempted-dos 2004-0369 11039  
15979SERVER-OTHER Check Point VPN-1 ASN.1 Decoding heap overflow attempt (more info ...)attempted-dos 2004-0699 10820  
15981FILE-OTHER zlib Denial of Service (more info ...)attempted-user 2004-0797 11051  
15982SERVER-WEBAPP Ipswitch WhatsUp Gold DOS Device HTTP request denial of service attempt (more info ...)attempted-dos 2004-0799 11110  
15983SERVER-SAMBA Samba arbitrary file access exploit attempt (more info ...)misc-attack 2004-0815 11281  
15984SERVER-SAMBA Samba Printer Change Notification Request DoS attempt (more info ...)attempted-dos 2004-0829 11055  
15989SERVER-OTHER Squid ASN.1 header parsing denial of service attempt (more info ...)attempted-dos 2004-0918 11385  
15990SERVER-WEBAPP Multiple Vendor server file disclosure attempt (more info ...)web-application-attack 2006-3853 19106  
15992FILE-OTHER Trend Micro Products Antivirus Library overflow attempt (more info ...)attempted-user 2005-0533 12643  
15994SERVER-OTHER Squid strListGetItem denial of service attempt (more info ...)attempted-dos 2009-2855 36091  
15998SERVER-OTHER HP OpenView Client Configuration Manager Radia Notify Daemon code execution attempt (more info ...)attempted-admin 2006-5782 20971  
16002FILE-OTHER Apple Mac OS X installer package filename format string vulnerability (more info ...)attempted-admin 2007-0465   
16003FILE-OTHER Apple Mac OS X installer package filename format string vulnerability (more info ...)attempted-admin 2007-0465   
16004FILE-OTHER Apple Mac OS X installer package filename format string vulnerability (more info ...)attempted-admin 2007-0465   
16013SERVER-OTHER IBM solidDB logging function format string exploit attempt (more info ...)attempted-user 2008-1705 28468  
16018SERVER-OTHER HP OpenView network node manager buffer overflow (more info ...)attempted-admin 2008-1842 28689  
16039SERVER-OTHER EMC Dantz Retrospect Backup Agent denial of service attempt (more info ...)denial-of-service 2006-0995   
16040SERVER-OTHER SpamAssassin spamd vpopmail and paranoid options code execution attempt (more info ...)attempted-user 2006-2447 18290  
16053FILE-OTHER GNU tar PAX extended headers handling overflow attempt (more info ...)attempted-dos 2006-0300 16764  
16056SERVER-WEBAPP Symantec Scan Engine authentication bypass attempt (more info ...)attempted-recon 2006-0230 17637  
16061FILE-IDENTIFY X PixMap file download request (more info ...)misc-activity    URL
16062FILE-OTHER ACD Systems ACDSee Products XPM values section buffer overflow attempt (more info ...)attempted-user 2007-6009 26554  
16069SERVER-OTHER IBM Informix server argument processing overflow attempt (more info ...)attempted-admin 2008-0727 28198  
16070FILE-OTHER X.org PCF parsing buffer overflow attempt (more info ...)attempted-user 2008-0006 27352  
16072SERVER-OTHER CUPS server query metacharacter buffer overflow attempt (more info ...)attempted-admin 2008-0047 28307  
16076SERVER-OTHER Tripwire format string vulnerability nfs exploit attempt (more info ...)attempted-admin 2004-0536 10454  
16079SERVER-WEBAPP uselang code injection (more info ...)web-application-attack 2005-4031 15703  
16087FILE-OTHER Multiple vendor AV gateway virus detection bypass attempt (more info ...)misc-attack 2005-0218 12269  
16092MALWARE-BACKDOOR Win.Trojan.delf.jwh runtime detection (more info ...)trojan-activity    URL
16093MALWARE-CNC bugsprey variant inbound connection (more info ...)trojan-activity    
16094MALWARE-CNC Win.Trojan.exchan.gen variant outbound connection (more info ...)trojan-activity    URL
16095MALWARE-CNC td.exe variant outbound connection getfile (more info ...)trojan-activity    URL
16096MALWARE-CNC td.exe variant outbound connection download (more info ...)trojan-activity    URL
16097MALWARE-CNC Win.Trojan.agent.vvm variant outbound connection (more info ...)trojan-activity    URL
16098MALWARE-CNC Win.Trojan.cekar variant outbound connection (more info ...)trojan-activity    URL
16099MALWARE-CNC Win.Trojan.agent.wdv variant outbound connection (more info ...)trojan-activity    URL
16101MALWARE-CNC Win.Trojan.delf.phh variant outbound connection 57329.exe (more info ...)trojan-activity    URL
16102MALWARE-CNC Win.Trojan.delf.phh variant outbound connection sft_ver1.1454.0.exe (more info ...)trojan-activity    URL
16103MALWARE-CNC lost door 3.0 variant outbound connection (more info ...)trojan-activity    
16104MALWARE-CNC lost door 3.0 variant outbound connection (more info ...)trojan-activity    
16105MALWARE-CNC Win.Trojan.zlob variant outbound connection topqualityads (more info ...)trojan-activity    URL
16106MALWARE-CNC synrat 2.1 pro variant outbound connection (more info ...)trojan-activity    
16107MALWARE-CNC synrat 2.1 pro variant outbound connection (more info ...)trojan-activity    
16109MALWARE-CNC Win.Trojan.zlob.wwv variant outbound connection onestoponlineshop (more info ...)trojan-activity    URL
16110MALWARE-CNC Win.Trojan.zlob.wwv variant outbound connection childhe (more info ...)trojan-activity    URL
16111MALWARE-CNC Win.Trojan.zlob.wwv installtime detection (more info ...)trojan-activity    URL
16112MALWARE-CNC Win.Trojan.agent.vhb variant outbound connection contact remote server (more info ...)trojan-activity    URL
16113MALWARE-CNC Win.Trojan.agent.vhb variant outbound connection request login page (more info ...)trojan-activity    URL
16114PUA-TOOLBARS Hijacker cramtoolbar runtime detection - hijack (more info ...)misc-activity    URL
16115PUA-TOOLBARS Hijacker cramtoolbar runtime detection - search (more info ...)misc-activity    URL
16116MALWARE-OTHER Trackware rightonadz.biz adrotator runtime detection - pass user info to remote server (more info ...)successful-recon-limited    URL
16117MALWARE-OTHER Trackware rightonadz.biz adrotator runtime detection - ads (more info ...)successful-recon-limited    URL
16118PUA-ADWARE Adware winreanimator runtime detection - register request (more info ...)misc-activity    URL
16119PUA-ADWARE Adware winreanimator runtime detection - daily update (more info ...)misc-activity    URL
16120PUA-TOOLBARS Trackware 6sq toolbar runtime detection (more info ...)successful-recon-limited    URL
16121PUA-ADWARE Hijacker weatherstudio outbound connection (more info ...)misc-activity    URL
16122PUA-ADWARE rogue antivirus xp 2008 runtime detection - buy (more info ...)misc-activity    URL
16123PUA-ADWARE rogue antivirus xp 2008 runtime detection - update (more info ...)misc-activity    URL
16124MALWARE-CNC Win.Trojan.nsis.agent.s variant outbound connection (more info ...)misc-activity    URL
16125MALWARE-OTHER Keylogger spyyahoo v2.2 runtime detection (more info ...)successful-recon-limited    URL
16126PUA-ADWARE Trickler virusremover 2008 outbound connection (more info ...)misc-activity    URL
16127PUA-ADWARE Adware superiorads runtime detection (more info ...)misc-activity    URL
16129MALWARE-OTHER Keylogger kamyab Keylogger v.3 runtime detection (more info ...)successful-recon-limited    URL
16130MALWARE-OTHER Keylogger lord spy pro 1.4 runtime detection (more info ...)successful-recon-limited    URL
16131MALWARE-OTHER Trackware adclicker trojan zlob.dnz runtime detection - ads (more info ...)successful-recon-limited    
16132MALWARE-OTHER Trackware owlforce runtime detection - remote server #1 (more info ...)successful-recon-limited    URL
16133MALWARE-OTHER Trackware owlforce runtime detection - remote server #2 (more info ...)successful-recon-limited    URL
16134PUA-ADWARE Adware spyware guard 2008 runtime detection - contacts remote server (more info ...)misc-activity    URL
16135PUA-ADWARE Adware spyware guard 2008 runtime detection - purchase page (more info ...)misc-activity    URL
16136PUA-ADWARE Hijacker xp antispyware 2009 runtime detection - pre-sale webpage (more info ...)misc-activity    URL
16137MALWARE-OTHER Keylogger cheat monitor runtime detection (more info ...)successful-recon-limited    URL
16138MALWARE-TOOLS Hacker-Tool 0desa msn pass stealer 8.5 runtime detection (more info ...)misc-activity    
16139MALWARE-CNC Win.Trojan.gen2 variant outbound connection scanner page (more info ...)misc-activity    URL
16140MALWARE-CNC torpig-mebroot command and control checkin (more info ...)trojan-activity    URL
16141SERVER-OTHER Kaspersky Online Scanner trojaned Dll download attempt (more info ...)trojan-activity    URL
16144MALWARE-CNC Bredolab bot variant outbound connection (more info ...)trojan-activity    URL
16195SERVER-WEBAPP HTTP request with negative Content-Length attempt (more info ...)attempted-user 2020-3304   URL
16197SERVER-OTHER OpenLDAP ber_get_next BER decoding denial of service attempt (more info ...)attempted-dos 2008-2952 30013  
16199SERVER-MAIL SpamAssassin long message header denial of service attempt (more info ...)attempted-dos 2005-3351 15373  
16214SERVER-OTHER Squid Proxy invalid HTTP response code denial of service attempt (more info ...)denial-of-service 2009-2622 35812  
16215SERVER-ORACLE Oracle Application Server Portal cross site scripting attempt (more info ...)attempted-user    URL
16222FILE-IMAGE Malformed BMP dimensions arbitrary code execution attempt (more info ...)attempted-user 2013-3259   URL
16227SERVER-OTHER Web Service on Devices API WSDAPI URL processing buffer corruption attempt (more info ...)attempted-user 2009-2512   URL
16232OS-WINDOWS Windows TrueType font file parsing integer overflow attempt (more info ...)attempted-admin 2010-2741   URL
16242MALWARE-CNC downloader-ash.gen.b variant outbound connection adload (more info ...)trojan-activity    URL
16244PUA-ADWARE rogue software xp police antivirus runtime detection - purchase (more info ...)trojan-activity    URL
16245PUA-ADWARE rogue software xp police antivirus install-timedetection (more info ...)trojan-activity    URL
16246PUA-ADWARE rogue software spyware protect 2009 outbound connection - purchase request (more info ...)trojan-activity    URL
16247PUA-ADWARE rogue software spyware protect 2009 outbound connection - block (more info ...)trojan-activity    URL
16248PUA-ADWARE rogue software ms antispyware 2009 runtime detection - start (more info ...)trojan-activity    URL
16249PUA-ADWARE rogue software ms antispyware 2009 runtime detection - pay (more info ...)trojan-activity    URL
16250PUA-ADWARE rogue software win pc defender outbound connection (more info ...)trojan-activity    URL
16251PUA-ADWARE rogue software win pc defender outbound connection (more info ...)trojan-activity    URL
16252PUA-ADWARE rogue software pro antispyware 2009 runtime detection - purchase (more info ...)trojan-activity    URL
16253PUA-ADWARE rogue software system security 2009 outbound connection (more info ...)trojan-activity    URL
16254PUA-ADWARE rogue software system security 2009 outbound connection (more info ...)trojan-activity    URL
16255PUA-ADWARE rogue software system security 2009 outbound connection (more info ...)trojan-activity    URL
16256PUA-ADWARE rogue software coreguard antivirus 2009 runtime detection (more info ...)trojan-activity    URL
16257PUA-ADWARE rogue software perfect defender 2009 outbound connection - update (more info ...)trojan-activity    URL
16258PUA-ADWARE rogue software perfect defender 2009 outbound connection - purchase (more info ...)trojan-activity    URL
16259PUA-ADWARE rogue software antivirusdoktor2009 runtime detection (more info ...)trojan-activity    URL
16260PUA-ADWARE rogue software xp antivirus protection runtime detection - installation (more info ...)trojan-activity    URL
16261PUA-ADWARE rogue software xp antivirus protection runtime detection - runtime (more info ...)trojan-activity    URL
16262PUA-ADWARE rogue software xp-shield outbound connection (more info ...)trojan-activity    URL
16263PUA-ADWARE rogue software xp-shield outbound connection - installation (more info ...)trojan-activity    URL
16264PUA-ADWARE rogue software 007 anti-spyware runtime detection - update (more info ...)trojan-activity    URL
16265PUA-ADWARE rogue software 007 anti-spyware runtime detection - register (more info ...)trojan-activity    URL
16266PUA-ADWARE rogue software pc antispyware 2010 runtime detection - buy (more info ...)trojan-activity    URL
16267PUA-ADWARE rogue software pc antispyware 2010 runtime detection - files (more info ...)trojan-activity    URL
16268MALWARE-CNC Win.Trojan.tdss.1.gen install-time detection - yournewsblog.net (more info ...)trojan-activity    URL
16269MALWARE-CNC Win.Trojan.tdss.1.gen install-time detection - findzproportal1.com (more info ...)trojan-activity    URL
16271MALWARE-CNC Win.Trojan.TDSS.1.Gen keepalive detection (more info ...)trojan-activity    URL
16272MALWARE-CNC Trojan-dropper.irc.tkb variant outbound connection lordhack (more info ...)trojan-activity    URL
16273MALWARE-CNC Trojan-dropper.irc.tkb variant outbound connection dxcpm (more info ...)trojan-activity    URL
16274MALWARE-CNC Trickler trojan-spy.win32.pophot variant outbound connection connect to server (more info ...)misc-activity    URL
16275MALWARE-CNC Trickler trojan-spy.win32.pophot variant outbound connection download files (more info ...)misc-activity    URL
16276PUA-ADWARE Trickler win32-fakealert.kl outbound connection (more info ...)misc-activity    URL
16277PUA-ADWARE Trickler win32-fakealert.kl outbound connection - downloads malicious files (more info ...)misc-activity    URL
16278PUA-ADWARE Trickler win32-fakealert.kl installime detection - updates remote server (more info ...)misc-activity    URL
16279PUA-ADWARE rogue-software windows antivirus 2008 runtime detection - pre-sale page (more info ...)trojan-activity    URL
16280PUA-ADWARE rogue-software windows antivirus 2008 runtime detection - registration and payment page (more info ...)trojan-activity    URL
16281PUA-P2P BitTorrent scrape request (more info ...)policy-violation    URL
16282PUA-P2P Bittorrent uTP peer request (more info ...)policy-violation    URL
16283SERVER-WEBAPP Borland StarTeam Multicast Service buffer overflow attempt (more info ...)attempted-admin 2008-0311 28602  
16289MALWARE-CNC Clob bot traffic (more info ...)trojan-activity    URL
16313FILE-EXECUTABLE download of executable content (more info ...)policy-violation    URL
16335FILE-PDF XPDF ObjectStream integer overflow (more info ...)attempted-user 2009-3608 37167  
16341SERVER-OTHER IBM DB2 Database Server invalid data stream denial of service attempt (more info ...)attempted-dos 2009-0173 33258  
16345FILE-OTHER IBM Informix Client SDK NFX file HostList processing stack buffer overflow attempt (more info ...)attempted-user 2009-3691 36588  
16346FILE-OTHER IBM Informix Client SDK NFX file InformixServerList processing stack buffer overflow attempt (more info ...)attempted-user 2009-3691 36588  
16351PROTOCOL-VOIP CSeq buffer overflow attempt (more info ...)attempted-dos 2009-2726 36015 18986 URL
16355FILE-PDF Xpdf Splash DrawImage integer overflow attempt (more info ...)attempted-user 2009-3604 36703  
16358MALWARE-CNC bugsprey variant outbound connection (more info ...)trojan-activity    URL
16362MALWARE-CNC SpyForms malware call home (more info ...)trojan-activity    URL
16365PUA-ADWARE OnlineGames download attempt (more info ...)trojan-activity    
16368MALWARE-CNC Win.Trojan.Hydraq variant outbound connection (more info ...)trojan-activity    URL
16374SERVER-OTHER Oracle Internet Directory heap corruption attempt (more info ...)attempted-admin    
16375SERVER-OTHER LDAP object parameter name buffer overflow attempt (more info ...)attempted-admin    
16384SERVER-OTHER VMware Server ISAPI Extension remote denial of service attempt (more info ...)attempted-dos 2008-3697 30935  URL
16391MALWARE-CNC Gozi Win.Trojan.connection to C&C (more info ...)trojan-activity    URL
16439MALWARE-CNC Possible Zeus User-Agent - _TEST_ (more info ...)trojan-activity    URL
16440MALWARE-CNC Possible Zeus User-Agent - ie (more info ...)trojan-activity    URL
16441MALWARE-CNC Possible Zeus User-Agent - Download (more info ...)trojan-activity    URL
16445PROTOCOL-VOIP Digium Asterisk IAX2 ack response denial of service attempt (more info ...)attempted-dos 2008-1897 28901  URL
16455MALWARE-OTHER Keylogger egyspy keylogger 1.13 runtime detection (more info ...)successful-recon-limited    URL
16456PUA-ADWARE Rogue-Software ang antivirus 09 runtime detection (more info ...)trojan-activity    URL
16457MALWARE-CNC Win.Trojan.Cutwail.AI variant outbound connection (more info ...)trojan-activity    URL
16459MALWARE-CNC Win.Trojan.command and control communication (more info ...)trojan-activity    URL
16483MALWARE-CNC Koobface worm submission of collected data to C&C server (more info ...)trojan-activity    URL
16484MALWARE-CNC Koobface variant outbound connection (more info ...)trojan-activity    URL
16485MALWARE-CNC Koobface request for captcha (more info ...)trojan-activity    URL
16489MALWARE-CNC Bobax botnet variant outbound connection (more info ...)trojan-activity    URL
16493MALWARE-CNC TT-bot botnet variant outbound connection (more info ...)trojan-activity    URL
16494PUA-ADWARE Cutwail spambot server communication attempt (more info ...)trojan-activity    
16495MALWARE-CNC Rustock botnet variant outbound connection (more info ...)trojan-activity    URL
16496MALWARE-CNC Win.Trojan.hacktool variant outbound connection (more info ...)trojan-activity    URL
16497MALWARE-CNC User-Agent known malicious user agent - Tear Application (more info ...)trojan-activity    URL
16498PUA-ADWARE PC Antispyware 2010 FakeAV download/update attempt (more info ...)trojan-activity    
16516SERVER-ORACLE Database sys.olapimpl_t package odcitablestart overflow attempt (more info ...)attempted-user 2008-3974   
16517FILE-OTHER Free Download Manager .torrent parsing comment overflow attempt (more info ...)attempted-user 2009-0184 33555  
16518FILE-OTHER Free Download Manager .torrent parsing announce overflow attempt (more info ...)attempted-user 2009-0184 33555  
16519FILE-OTHER Free Download Manager .torrent parsing name overflow attempt (more info ...)attempted-user 2009-0184 33555  
16520FILE-OTHER Free Download Manager .torrent parsing path overflow attempt (more info ...)attempted-user 2009-0184 33555  
16523FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
16526MALWARE-CNC VanBot IRC communication (more info ...)trojan-activity    URL
16527MALWARE-CNC Zbot malware config file download request (more info ...)trojan-activity    URL
16528MALWARE-CNC Zbot malware config file download request (more info ...)trojan-activity    URL
16530OS-WINDOWS CAB SIP authenticode alteration attempt (more info ...)attempted-user 2010-0487   URL
16551MALWARE-CNC User-Agent known malicious user agent - malware (more info ...)trojan-activity    URL
16556FILE-OTHER 2imaegshack/lmageshack IM worm get request attempt (more info ...)misc-activity    URL
16557FILE-OTHER 2imaegshack/lmageshack IM worm inbound communication attempt (more info ...)misc-activity    URL
16558MALWARE-CNC SdBot IRC Win.Trojan.server to client communication (more info ...)trojan-activity    URL
16579PUA-OTHER mIRC IRC URL buffer overflow attempt (more info ...)attempted-user 2003-1336 8819  
16582FILE-OTHER Un4seen Developments XMPlay crafted ASX file buffer overflow attempt (more info ...)attempted-user 2006-6063 21206  
16594PROTOCOL-POP STAT command (more info ...)protocol-command-decode    
16598SERVER-OTHER Green Dam URL handling overflow attempt (more info ...)attempted-user    URL
16600MALWARE-CNC Otlard Win.Trojan.activity (more info ...)trojan-activity    URL
16606SERVER-ORACLE BEA WebLogic Server Plug-ins Certificate overflow attempt (more info ...)attempted-user 2009-1016 34461  
16669MALWARE-CNC Spyeye bot variant outbound connection (more info ...)trojan-activity    URL
16670MALWARE-CNC Koobface worm executable download (more info ...)trojan-activity    URL
16678SERVER-WEBAPP Tandberg VCS local file disclosure attempt (more info ...)web-application-attack 2009-4511   URL
16681SERVER-WEBAPP Basic Authorization string overflow attempt (more info ...)attempted-dos 2003-0727 8375  
16682SERVER-WEBAPP Oracle ONE Web Server JSP source code disclosure attempt (more info ...)misc-attack 2009-2445   
16684SERVER-SAMBA Samba smbd Session Setup AndX security blob length dos attempt (more info ...)denial-of-service 2010-1642 40097  URL
16686SERVER-OTHER IBM WebSphere application server cross site scripting attempt (more info ...)misc-attack 2009-0855 34001  
16688SERVER-OTHER iscsi target format string code execution attempt (more info ...)attempted-admin 2010-0743   
16689SERVER-OTHER Palo Alto Networks Firewall editUser.esp XSS attempt (more info ...)web-application-attack 2010-0475   
16691FILE-IDENTIFY PLF playlist file download request (more info ...)misc-activity    
16692FILE-MULTIMEDIA PLF playlist name buffer overflow attempt (more info ...)attempted-user 2006-6199 21337  
16695MALWARE-CNC Rogue AV download/update (more info ...)trojan-activity    URL
16696FILE-OTHER Astonsoft Deepburner db file path buffer overflow attempt (more info ...)attempted-user 2006-6665 21657  
16709SERVER-OTHER RealNetworks Helix Server RTSP SET_PARAMETERS empty DataConvertBuffer header denial of service attempt (more info ...)attempted-dos 2009-2533 35731  
16710SERVER-OTHER Oracle BEA Weblogic server console-help.portal cross-site scripting attempt (more info ...)attempted-user 2009-1975 35673  
16716FILE-IMAGE multiple products PNG processing buffer overflow attempt (more info ...)attempted-user 2017-3077 34240  URL
16717SERVER-ORACLE Oracle Secure Enterprise Search search_p_groups cross-site scripting attempt (more info ...)attempted-user 2009-1968 35681  
16719FILE-OTHER CA multiple product AV engine CAB header parsing stack overflow attempt (more info ...)attempted-user 2007-2864 24330  
16720FILE-MULTIMEDIA VideoLAN VLC Media Player TY processing buffer overflow attempt (more info ...)attempted-user 2008-4654 31813  
16721FILE-OTHER Orbital Viewer .orb stack buffer overflow attempt (more info ...)attempted-user 2010-0688 38436  
16725BROWSER-PLUGINS ActivePDF WebGrabber APWebGrb.ocx GetStatus method overflow attempt (more info ...)attempted-user    
16726FILE-OTHER gAlan malformed file stack overflow attempt (more info ...)attempted-user    
16727FILE-OTHER IDEAL Administration IPJ file handling stack overflow attempt (more info ...)attempted-user 2009-4265   
16730FILE-OTHER ProShow Gold PSH file handling overflow attempt (more info ...)attempted-user 2009-3214   
16731FILE-OTHER ProShow Gold PSH file handling overflow attempt (more info ...)attempted-user 2009-3214   
16732FILE-OTHER SafeNet SoftRemote multiple policy file local overflow attempt (more info ...)attempted-user 2009-3861   
16733FILE-OTHER UltraISO CCD file handling overflow attempt (more info ...)attempted-user 2009-1260   
16734FILE-OTHER multiple products malformed CUE file buffer overflow attempt (more info ...)attempted-user 2007-2888 33960  
16735FILE-OTHER URSoft W32Dasm Import/Export function buffer overflow attempt (more info ...)attempted-user 2005-0308 12352  
16736FILE-OTHER VariCAD multiple products DWB file handling overflow attempt (more info ...)attempted-user  38815  
16737FILE-MULTIMEDIA Xenorate Media Player XPL file handling overflow attempt - 1 (more info ...)attempted-user    
16738FILE-MULTIMEDIA Xenorate Media Player XPL file handling overflow attempt - 2 (more info ...)attempted-user    
16742FILE-IDENTIFY remote desktop configuration file download request (more info ...)misc-activity    URL
16743FILE-OTHER Cain & Abel Remote Desktop Protocol file handling buffer overflow attempt (more info ...)attempted-user 2008-5405 32543  URL
16744FILE-MULTIMEDIA Worldweaver DX Studio Player plug-in command injection attempt (more info ...)attempted-user 2009-2011 35273  
16751FILE-MULTIMEDIA VideoLAN VLC Media Player SMB module Win32AddConnection buffer overflow attempt (more info ...)attempted-user 2009-2484 35500  
16752FILE-MULTIMEDIA VideoLAN VLC Media Player SMB module Win32AddConnection buffer overflow attempt (more info ...)attempted-user 2009-2484 35500  
16753SERVER-WEBAPP VideoLAN VLC Media Player SMB module Win32AddConnection buffer overflow attempt (more info ...)attempted-user 2009-2484 35500  
16777SERVER-ORACLE Secure Backup NDMP packet handling DoS attempt (more info ...)attempted-dos 2008-5441 33177  
16778SERVER-ORACLE Secure Backup NDMP packet handling DoS attempt (more info ...)attempted-dos 2008-5441 33177  
16785BROWSER-PLUGINS AwingSoft Winds3D Player SceneURL method command execution attempt (more info ...)attempted-user 2009-4850   
16788SERVER-OTHER RealVNC VNC Server ClientCutText message memory corruption attempt (more info ...)attempted-admin  39895  
16799SERVER-MAIL Eureka Mail 2.2q server error response overflow attempt (more info ...)misc-attack 2009-3837   URL
16804MALWARE-CNC Win.Trojan.Qakbot.E - initial load (more info ...)trojan-activity    URL
16805MALWARE-CNC Win.Trojan.Qakbot.E config check (more info ...)trojan-activity    URL
16808MALWARE-CNC Win.Trojan.Qakbot.E - register client (more info ...)trojan-activity    URL
16809MALWARE-CNC Win.Trojan.FraudPack variant outbound connection (more info ...)trojan-activity    URL
16810MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16811MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16812MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16813MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16814MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16815MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16816MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16817MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16818MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16819MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16820MALWARE-CNC Win.Trojan.Kryptik variant outbound connection (more info ...)trojan-activity    URL
16821MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16822MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16823MALWARE-CNC Win.Trojan.FlyStudio known command and control channel traffic (more info ...)trojan-activity    URL
16824MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16825MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16826MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16827MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16828MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16829MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16830MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16831MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16832MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16833MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
16911MALWARE-CNC URI request for known malicious URI - ucsp0416.exe?t= (more info ...)trojan-activity    URL
16912MALWARE-CNC URI request for known malicious URI - net/cfg2.bin (more info ...)trojan-activity    URL
16914MALWARE-CNC URI request for known malicious URI - .bin?ucsp (more info ...)trojan-activity    URL
16915MALWARE-CNC URI request for known malicious URI - /MNG/Download/?File=AZF (more info ...)trojan-activity    URL
16916MALWARE-CNC URI request for known malicious URI - /jarun/jezerce (more info ...)trojan-activity    URL
16917MALWARE-CNC URI request for known malicious URI - /ekaterina/velika (more info ...)trojan-activity    URL
16918MALWARE-CNC URI request for known malicious URI - /ultimate/fight (more info ...)trojan-activity    URL
16919MALWARE-CNC URI request for known malicious URI - /tmp/pm.exe?t= (more info ...)trojan-activity    URL
16920MALWARE-CNC URI request for known malicious URI - /DownLoadFile/BaePo/ver (more info ...)trojan-activity    URL
16921MALWARE-CNC URI request for known malicious URI - /s1/launcher/update/Update/data/ (more info ...)trojan-activity    URL
16928MALWARE-CNC URI request for known malicious URI - /stat.html?0dPg0uXTraCSqrOdlrKpmpyorePbz (more info ...)trojan-activity    URL
16930MALWARE-CNC URI request for known malicious URI - count.asp?mac= (more info ...)trojan-activity    URL
16932MALWARE-CNC URI request for known malicious URI - /qqnongchang/qqkj. (more info ...)trojan-activity    URL
16933MALWARE-CNC URI request for known malicious URI - /root/9 frt.rar (more info ...)trojan-activity    URL
16934POLICY-SPAM pku-edp.cn known spam email attempt (more info ...)policy-violation    
16935POLICY-SPAM sjtu-edp.cn known spam email attempt (more info ...)policy-violation    
16936POLICY-SPAM xoposuhop.cn xoposuhop.cn known spam email attempt (more info ...)policy-violation    
16937POLICY-SPAM bestdrug-store.com known spam email attempt (more info ...)policy-violation    
16938POLICY-SPAM pharmrik66y.ru known spam email attempt (more info ...)policy-violation    
16939POLICY-SPAM refillleonardo59y.ru known spam email attempt (more info ...)policy-violation    
16940POLICY-SPAM medfreddie55a.ru known spam email attempt (more info ...)policy-violation    
16941POLICY-SPAM drugshershel38w.ru known spam email attempt (more info ...)policy-violation    
16942POLICY-SPAM drugshayyim77n.ru known spam email attempt (more info ...)policy-violation    
16943POLICY-SPAM erectguthry99c.ru known spam email attempt (more info ...)policy-violation    
16944POLICY-SPAM pilldory92n.ru known spam email attempt (more info ...)policy-violation    
16945POLICY-SPAM tabwinn77t.ru known spam email attempt (more info ...)policy-violation    
16946POLICY-SPAM pillrenault15j.ru known spam email attempt (more info ...)policy-violation    
16947POLICY-SPAM pharmrolland95h.ru known spam email attempt (more info ...)policy-violation    
16948POLICY-SPAM onlineheindrick60i.ru known spam email attempt (more info ...)policy-violation    
16949POLICY-SPAM erectnormie71a.ru known spam email attempt (more info ...)policy-violation    
16951POLICY-SPAM drugsjudd45f.ru known spam email attempt (more info ...)policy-violation    
16952POLICY-SPAM pharmharman55y.ru known spam email attempt (more info ...)policy-violation    
16953POLICY-SPAM medgaultiero11e.ru known spam email attempt (more info ...)policy-violation    
16954POLICY-SPAM pillgaylor21n.ru known spam email attempt (more info ...)policy-violation    
16955POLICY-SPAM drugspenn84f.ru known spam email attempt (more info ...)policy-violation    
16956POLICY-SPAM medebeneser68c.ru known spam email attempt (more info ...)policy-violation    
16957POLICY-SPAM tabmario94r.ru known spam email attempt (more info ...)policy-violation    
16958POLICY-SPAM tablennard88q.ru known spam email attempt (more info ...)policy-violation    
16959POLICY-SPAM medforster79j.ru known spam email attempt (more info ...)policy-violation    
16960POLICY-SPAM erectvincent21v.ru known spam email attempt (more info ...)policy-violation    
16961POLICY-SPAM drugsdemott21o.ru known spam email attempt (more info ...)policy-violation    
16962POLICY-SPAM onlinelovell30p.ru known spam email attempt (more info ...)policy-violation    
16963POLICY-SPAM erecttaylor49i.ru known spam email attempt (more info ...)policy-violation    
16964POLICY-SPAM smellexact.ru known spam email attempt (more info ...)policy-violation    
16965POLICY-SPAM givehome.ru known spam email attempt (more info ...)policy-violation    
16966POLICY-SPAM thingpath.ru known spam email attempt (more info ...)policy-violation    
16967POLICY-SPAM wereif.ru known spam email attempt (more info ...)policy-violation    
16968POLICY-SPAM bassmax.ru known spam email attempt (more info ...)policy-violation    
16969POLICY-SPAM steadfig.ru known spam email attempt (more info ...)policy-violation    
16970POLICY-SPAM drugsmayne5a.ru known spam email attempt (more info ...)policy-violation    
16971POLICY-SPAM mystick.ru known spam email attempt (more info ...)policy-violation    
16972POLICY-SPAM drugsrey95a.ru known spam email attempt (more info ...)policy-violation    
16973POLICY-SPAM milklowly.ru known spam email attempt (more info ...)policy-violation    
16974POLICY-SPAM numberenough.ru known spam email attempt (more info ...)policy-violation    
16975POLICY-SPAM oldsheer.ru known spam email attempt (more info ...)policy-violation    
16976POLICY-SPAM logzest.ru known spam email attempt (more info ...)policy-violation    
16977POLICY-SPAM energypotent.ru known spam email attempt (more info ...)policy-violation    
16978POLICY-SPAM outhave.ru known spam email attempt (more info ...)policy-violation    
16979POLICY-SPAM solvecalm.ru known spam email attempt (more info ...)policy-violation    
16980POLICY-SPAM stillvisit.ru known spam email attempt (more info ...)policy-violation    
16981POLICY-SPAM livelycall.ru known spam email attempt (more info ...)policy-violation    
16982POLICY-SPAM 64.com1.ru known spam email attempt (more info ...)policy-violation    
16983POLICY-SPAM heatsettle.ru known spam email attempt (more info ...)policy-violation    
16984POLICY-SPAM freshmuch.ru known spam email attempt (more info ...)policy-violation    
16985POLICY-SPAM extoleye.ru known spam email attempt (more info ...)policy-violation    
16987POLICY-SPAM tabemmerich86b.ru known spam email attempt (more info ...)policy-violation    
16988POLICY-SPAM moderneight.ru known spam email attempt (more info ...)policy-violation    
16989POLICY-SPAM tabferd49a.ru known spam email attempt (more info ...)policy-violation    
16990POLICY-SPAM nextmail.ru known spam email attempt (more info ...)policy-violation    
16991POLICY-SPAM fruitone.ru known spam email attempt (more info ...)policy-violation    
16992POLICY-SPAM liquideat.ru known spam email attempt (more info ...)policy-violation    
16993POLICY-SPAM tabwinn2a.ru known spam email attempt (more info ...)policy-violation    
16994POLICY-SPAM abletool.ru known spam email attempt (more info ...)policy-violation    
16995POLICY-SPAM miltyrefil.ru known spam email attempt (more info ...)policy-violation    
16996POLICY-SPAM quincytab.ru known spam email attempt (more info ...)policy-violation    
16997POLICY-SPAM giacoporx.ru known spam email attempt (more info ...)policy-violation    
16998POLICY-SPAM drugsnevile.ru known spam email attempt (more info ...)policy-violation    
16999POLICY-SPAM jasemed.ru known spam email attempt (more info ...)policy-violation    
17000POLICY-SPAM ximenezdrug.ru known spam email attempt (more info ...)policy-violation    
17001POLICY-SPAM dillonline.ru known spam email attempt (more info ...)policy-violation    
17002POLICY-SPAM swellliquid.ru known spam email attempt (more info ...)policy-violation    
17003POLICY-SPAM younglaugh.ru known spam email attempt (more info ...)policy-violation    
17004POLICY-SPAM 2047757.kaskad-travel.ru known spam email attempt (more info ...)policy-violation    
17005POLICY-SPAM paintwater.ru known spam email attempt (more info ...)policy-violation    
17006POLICY-SPAM lovingover.ru known spam email attempt (more info ...)policy-violation    
17007POLICY-SPAM pharmerastus.ru known spam email attempt (more info ...)policy-violation    
17008POLICY-SPAM hisoffer.ru known spam email attempt (more info ...)policy-violation    
17009POLICY-SPAM butleft.ru known spam email attempt (more info ...)policy-violation    
17010POLICY-SPAM starknow.ru known spam email attempt (more info ...)policy-violation    
17011POLICY-SPAM beginwisdom.ru known spam email attempt (more info ...)policy-violation    
17012POLICY-SPAM oneus.ru known spam email attempt (more info ...)policy-violation    
17013POLICY-SPAM reapcomfy.ru known spam email attempt (more info ...)policy-violation    
17014POLICY-SPAM rowsay.ru known spam email attempt (more info ...)policy-violation    
17015POLICY-SPAM pamperletter.ru known spam email attempt (more info ...)policy-violation    
17016POLICY-SPAM boxdouble.ru known spam email attempt (more info ...)policy-violation    
17017POLICY-SPAM beatmoon.ru known spam email attempt (more info ...)policy-violation    
17018POLICY-SPAM ensureequate.ru known spam email attempt (more info ...)policy-violation    
17020POLICY-SPAM sheerwheel.ru known spam email attempt (more info ...)policy-violation    
17021POLICY-SPAM nearpass.ru known spam email attempt (more info ...)policy-violation    
17022POLICY-SPAM thatmile.ru known spam email attempt (more info ...)policy-violation    
17023POLICY-SPAM hillfoot.ru known spam email attempt (more info ...)policy-violation    
17024POLICY-SPAM writeobject.ru known spam email attempt (more info ...)policy-violation    
17025POLICY-SPAM thoughthese.ru known spam email attempt (more info ...)policy-violation    
17026POLICY-SPAM redlead.ru known spam email attempt (more info ...)policy-violation    
17029POLICY-SPAM tenderpower.ru known spam email attempt (more info ...)policy-violation    
17030POLICY-SPAM fewvalley.ru known spam email attempt (more info ...)policy-violation    
17031POLICY-SPAM burnshy.ru known spam email attempt (more info ...)policy-violation    
17032POLICY-SPAM centtry.ru known spam email attempt (more info ...)policy-violation    
17033POLICY-SPAM signpearl.ru known spam email attempt (more info ...)policy-violation    
17041SERVER-OTHER ISA Server OTP-based Forms-authorization fallback policy bypass attempt (more info ...)attempted-user 2009-1135   URL
17050SERVER-WEBAPP Oracle Secure Backup Administration Server authentication bypass attempt (more info ...)attempted-admin 2010-0904 41596  
17055SERVER-ORACLE Oracle Database DBMS TNS Listener denial of service attempt (more info ...)attempted-dos 2009-0991 34461  URL
17104FILE-OTHER FeedDemon OPML file handling buffer overflow attempt (more info ...)attempted-user 2009-0546 33630  
17105FILE-OTHER FeedDemon unicode OPML file handling buffer overflow attempt (more info ...)attempted-user 2009-0546 33630  
17106FILE-IDENTIFY download of RMF file - potentially malicious (more info ...)misc-activity 2010-0842 39077  
17110APP-DETECT VxWorks remote debugging agent login attempt (more info ...)protocol-command-decode 2010-2965   URL
17137SERVER-WEBAPP HP Intelligent Management Center information disclosure attempt (more info ...)misc-attack  40298  URL
17138SERVER-OTHER iSCSI target multiple implementations iSNS stack buffer overflow attempt (more info ...)attempted-admin 2010-2221 41327  
17139SERVER-OTHER Symantec Alert Management System HNDLRSVC arbitrary command execution attempt (more info ...)attempted-admin 2010-0110 41959  
17140SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
17148FILE-MULTIMEDIA VideoLAN VLC renamed zip file handling code execution attempt - 1 (more info ...)attempted-user  40428  
17149FILE-MULTIMEDIA VideoLAN VLC renamed zip file handling code execution attempt - 2 (more info ...)attempted-user  40428  
17150FILE-MULTIMEDIA VideoLAN VLC renamed zip file handling code execution attempt - 3 (more info ...)attempted-user  40428  
17152SERVER-SAMBA Samba smbd flags2 header parsing denial of service attempt (more info ...)attempted-dos 2010-1635 40097  
17155SERVER-OTHER Multiple vendors OPIE off-by-one stack buffer overflow attempt (more info ...)attempted-admin 2010-1938 40403  
17157SERVER-WEBAPP HP Intelligent Management Center database credentials information disclosure attempt - 1 (more info ...)attempted-user  40298  URL
17158SERVER-WEBAPP HP Intelligent Management Center database credentials information disclosure attempt - 2 (more info ...)attempted-user  40298  URL
17159SERVER-WEBAPP HP Intelligent Management Center database credentials information disclosure attempt - 3 (more info ...)attempted-user  40298  URL
17207SERVER-OTHER IBM Cognos Server backdoor account remote code execution attempt (more info ...)attempted-admin 2010-0557 38084  
17208SERVER-OTHER Squid Proxy HTCP packet processing denial of service attempt (more info ...)attempted-dos 2010-0639 38212  
17225SERVER-OTHER Alt-N MDaemon WorldClient invalid user attempt (more info ...)attempted-dos 2008-2631   
17234MALWARE-CNC VBMania mass mailing worm activity (more info ...)trojan-activity    URL
17235MALWARE-CNC VBMania mass mailing worm download (more info ...)trojan-activity    URL
17238FILE-OTHER ACD Systems ACDSee Products XBM file handling buffer overflow attempt (more info ...)attempted-user  37685  
17244FILE-OTHER Antivirus ACE file handling buffer overflow attempt (more info ...)attempted-user 2005-2720   
17264SERVER-ORACLE Permission declaration exploit attempt (more info ...)attempted-admin 2010-0866 38115  
17266FILE-OTHER Multiple vendor malformed ZIP archive Antivirus detection bypass attempt (more info ...)attempted-user  12793  URL
17267FILE-OTHER Multiple vendor malformed ZIP archive Antivirus detection bypass attempt (more info ...)attempted-user  12793  URL
17269PROTOCOL-TELNET Client env_opt_add Buffer Overflow attempt (more info ...)attempted-dos 2005-0468 12919  
17275SERVER-MAIL Symantec Brightmail AntiSpam nested Zip handling denial of service attempt (more info ...)attempted-dos  14757  URL
17277FILE-OTHER Multiple vendor Antivirus magic byte detection evasion attempt (more info ...)attempted-user 2005-3382   
17278FILE-OTHER Multiple vendor Antivirus magic byte detection evasion attempt (more info ...)attempted-user 2005-3382   
17279SERVER-WEBAPP Ipswitch WhatsUp Small Business directory traversal attempt (more info ...)attempted-user 2005-1939 15291  
17280SERVER-WEBAPP Ipswitch WhatsUp Small Business directory traversal attempt (more info ...)attempted-user 2005-1939 15291  
17281FILE-OTHER Panda Antivirus ZOO archive decompression buffer overflow attempt (more info ...)attempted-user 2005-3922   
17282SERVER-OTHER Multiple products RAR archive decompression buffer overflow attempt (more info ...)attempted-user 2005-4438   
17283SERVER-MAIL Mercury Mail Transport System buffer overflow attempt (more info ...)attempted-user 2005-4411 16396  
17289FILE-OTHER GNU gzip LZH decompression make_table overflow attempt (more info ...)attempted-user 2006-4335   URL
17291INDICATOR-OBFUSCATION base64-encoded uri data object found (more info ...)policy-violation    URL
17293SERVER-ORACLE sdo_lrs.convert_to_lrs_layer buffer overflow attempt (more info ...)attempted-user 2006-5340 20588  
17298SERVER-OTHER IBM Tivoli Monitoring Express Universal Agent Buffer Overflow (more info ...)attempted-admin 2007-2137 23558  
17299SERVER-OTHER ISC BIND RRSIG query denial of service attempt (more info ...)attempted-dos 2007-2241 23738  
17309FILE-OTHER CoolPlayer Playlist File Handling Buffer Overflow (more info ...)attempted-user 2008-3408 30418  
17313SERVER-ORACLE database server crafted view privelege escalation attempt (more info ...)attempted-admin 2006-1705 17246  
17326SERVER-OTHER Citrix Program Neighborhood Client buffer overflow attempt (more info ...)attempted-user 2005-3652 15907  
17327SERVER-MAIL Qualcomm WorldMail Server Response (more info ...)protocol-command-decode    
17331SERVER-MAIL IBM Lotus Notes HTML Speed Reader Long URL buffer overflow attempt (more info ...)attempted-user 2005-2618 16576  
17335INDICATOR-SHELLCODE x86 OS agnostic fnstenv geteip byte xor decoder (more info ...)shellcode-detect    
17336INDICATOR-SHELLCODE x86 OS agnostic call geteip byte xor decoder (more info ...)shellcode-detect    
17341INDICATOR-SHELLCODE x86 OS agnostic alpha UTF8 tolower avoidance decoder (more info ...)shellcode-detect    
17342INDICATOR-SHELLCODE x86 OS agnostic unicode mixed case decoder (more info ...)shellcode-detect    
17343INDICATOR-SHELLCODE x86 OS agnostic unicode upper case decoder (more info ...)shellcode-detect    
17346SERVER-OTHER IBM Lotus Notes Cross Site Scripting attempt (more info ...)string-detect 2005-2175 14164  
17350SERVER-ORACLE Oracle Application Server forms arbitrary system command execution attempt (more info ...)attempted-user 2005-2372 14319  
17352FILE-OTHER ClamAV CHM File Handling Integer Overflow attempt (more info ...)attempted-user 2005-2450 14359  
17356FILE-OTHER NOD32 Anti-Virus ARJ Archive Handling Buffer Overflow attempt (more info ...)attempted-admin 2005-2903 14773  
17357PUA-OTHER AOL GAIM AIM-ICQ Protocol Handling buffer overflow attempt (more info ...)attempted-user 2005-2103 14531  
17358FILE-EXECUTABLE ClamAV UPX File Handling Buffer Overflow attempt (more info ...)attempted-user 2005-2920 14866  
17359FILE-IDENTIFY XBM image file download request (more info ...)misc-activity    URL
17363FILE-OTHER Apple OSX Finder DMG volume name memory corruption attempt (more info ...)attempted-user 2007-0197   
17369SERVER-MAIL MailEnable service APPEND command handling buffer overflow attempt (more info ...)attempted-admin 2007-1301 22792  
17370SERVER-WEBAPP Squid authentication headers handling denial of service attempt (more info ...)protocol-command-decode 2005-2917 14977  
17371SERVER-WEBAPP Squid authentication headers handling denial of service attempt (more info ...)attempted-dos 2005-2917 14977  
17376SERVER-WEBAPP IBM Lotus Expeditor cai URI handler command execution attempt (more info ...)attempted-user 2008-1965   URL
17390FILE-IMAGE ClamAV Antivirus Function Denial of Service attempt (more info ...)attempted-dos 2008-5314 32555  
17416SERVER-ORACLE Database Intermedia Denial of Service Attempt (more info ...)denial-of-service  13239  
17417SERVER-ORACLE Database Intermedia Denial of Service Attempt (more info ...)denial-of-service  13239  
17418SERVER-ORACLE Oracle connection established (more info ...)attempted-user    
17420SERVER-WEBAPP Citrix Program Neighborhood Agent Arbitrary Shortcut Creation attempt (more info ...)attempted-user 2004-1077 13379  
17423SERVER-WEBAPP Citrix Program Neighborhood Agent Buffer Overflow attempt (more info ...)attempted-user 2004-1078 13373  
17427SERVER-ORACLE Oracle database DBMS_Scheduler privilege escalation attempt (more info ...)attempted-user 2005-1496 13509  
17430FILE-PDF BitDefender Antivirus PDF processing memory corruption attempt (more info ...)attempted-user 2008-5409 32396  
17432SERVER-WEBAPP Squid Gopher protocol handling buffer overflow attempt (more info ...)attempted-dos 2005-0094 12276  
17450SERVER-WEBAPP CommuniGate Systems CommuniGate Pro LDAP Server buffer overflow attempt (more info ...)attempted-user 2006-0468 16407  URL
17458FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
17459FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
17460FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
17469FILE-MULTIMEDIA Mplayer Real Demuxer stream_read heap overflow attempt (more info ...)attempted-user 2008-3827 31473  
17473SERVER-ORACLE DBMS_CDC_SUBSCRIBE.EXTEND_WINDOW arbitrary command execution attempt (more info ...)misc-attack 2005-1197 13236  
17474SERVER-ORACLE DBMS_CDC_SUBSCRIBE.CREATE_SUBSCRIPTION arbitrary command execution attempt (more info ...)misc-attack 2005-1197 13236  
17475SERVER-ORACLE DBMS_CDC_SUBSCRIBE.ACTIVATE_SUBSCRIPTION arbitrary command execution attempt (more info ...)misc-attack 2005-1197 13236  
17476SERVER-ORACLE DBMS_CDC_SUBSCRIBE.PURGE_WINDOW arbitrary command execution attempt (more info ...)misc-attack 2005-1197 13236  
17477SERVER-ORACLE DBMS_CDC_SUBSCRIBE.DROP_SUBSCRIPTION arbitrary command execution attempt (more info ...)misc-attack 2005-1197 13236  
17478SERVER-ORACLE DBMS_CDC_SUBSCRIBE.SUBSCRIBE arbitrary command execution attempt (more info ...)misc-attack 2005-1197 13236  
17479SERVER-ORACLE DBMS_CDC_ISUBSCRIBE.SUBSCRIBE arbitrary command execution attempt (more info ...)misc-attack 2005-1197 13236  
17480SERVER-ORACLE DBMS_CDC_ISUBSCRIBE.CREATE_SUBSCRIPTION arbitrary command execution attempt (more info ...)misc-attack 2005-1197 13236  
17486SERVER-WEBAPP Trend Micro Control Manager Chunked overflow attempt (more info ...)attempted-admin 2005-1929 15865  
17493FILE-OTHER ClamAV UPX FileHandling Heap overflow attempt (more info ...)attempted-user 2006-4018 19381  
17524SERVER-OTHER Fujitsu SystemcastWizard Lite PXEService UDP Handling Buffer Overflow (more info ...)attempted-admin 2009-0270 33342  
17527FILE-MULTIMEDIA VideoLAN VLC Media Player MP4_BoxDumpStructure Buffer Overflow (more info ...)attempted-user 2009-1122 35232  
17528SERVER-WEBAPP nginx URI parsing buffer overflow attempt (more info ...)attempted-admin 2009-2629 36384  
17534SERVER-OTHER IPP Application Content (more info ...)protocol-command-decode    
17535SERVER-OTHER Apple CUPS Text to PostScript Filter Integer Overflow attempt (more info ...)attempted-user 2008-3640 31690  
17541FILE-OTHER Avast Antivirus Engine Remote LHA buffer overflow attempt (more info ...)attempted-admin 2006-4626 19903  
17544SERVER-OTHER Wireshark LWRES Dissector getaddrsbyname buffer overflow attempt (more info ...)attempted-dos 2010-0304 37985  
17547FILE-IDENTIFY SMIL file download request (more info ...)misc-activity    URL
17556SERVER-OTHER Firebird database invalid state integer overflow attempt (more info ...)attempted-dos 2008-0387 27403  
17558FILE-IMAGE CUPS Gif Decoding Routine Buffer Overflow attempt (more info ...)attempted-user 2008-1373 28544  
17559FILE-OTHER IBM Lotus Notes Applix Graphics Parsing Buffer Overflow (more info ...)attempted-admin 2007-5405 28454  
17567SERVER-OTHER LANDesk Management Suite Alerting Service buffer overflow attempt (more info ...)attempted-admin 2007-1674 23483  
17569SERVER-OTHER BEA Weblogic Admin Console Cross Site Scripting Vulnerability attempt (more info ...)web-application-attack 2005-1747 13793  
17573FILE-MULTIMEDIA ffdshow codec URL parsing buffer overflow attempt (more info ...)attempted-user 2008-5381 32438  
17584SERVER-ORACLE UTL_FILE directory traversal attempt (more info ...)misc-attack 2005-0701 12749  
17598SERVER-OTHER IBM DB2 Universal Database accsec command without rdbnam (more info ...)attempted-dos 2006-4257 19586  
17599SERVER-OTHER IBM DB2 Universal Database rdbname denial of service attempt (more info ...)attempted-dos 2006-4257 19586  
17600FILE-IDENTIFY XUL file download request (more info ...)misc-activity    URL
17602FILE-OTHER ClamAV antivirus CHM file handling DOS (more info ...)attempted-dos 2008-1389 30994  URL
17607SERVER-OTHER Xi Software Net Transport eDonkey Protocol Buffer Overflow attempt (more info ...)attempted-user  40617  
17619SERVER-ORACLE database server crafted view privelege escalation attempt (more info ...)attempted-admin 2006-1705 17246  
17639SERVER-SAMBA Samba Root File System access bypass attempt (more info ...)attempted-recon 2009-0022 33118  
17641FILE-PDF CUPS and Xpdf JBIG2 symbol dictionary buffer overflow attempt (more info ...)attempted-user 2009-0195   URL
17651FILE-OTHER Multiple AV vendor invalid archive checksum bypass attempt (more info ...)attempted-user  12771  URL
17657SERVER-OTHER Symantec NetBackup BPCD Daemon exploit attempt (more info ...)attempted-admin 2006-6222 21565  
17659SERVER-ORACLE xdb.dbms_xmlschema buffer overflow attempt (more info ...)string-detect 2006-0272 16287  
17661SERVER-SAMBA Samba send_mailslot buffer overflow attempt (more info ...)attempted-admin 2007-6015 26791  
17662SERVER-OTHER VMware Workstation DHCP service integer overflow attempt (more info ...)attempted-admin 2007-0064 14687  
17663SERVER-OTHER Apple CUPS SGI image decoding buffer overflow attempt (more info ...)attempted-user 2008-3639 31690  
17669SERVER-ORACLE Oracle Application Server 10g OPMN service format string vulnerability exploit attempt (more info ...)attempted-admin 2009-0993 34461  URL
17679FILE-IDENTIFY Apple disk image file download request (more info ...)misc-activity    URL
17681SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100166 (more info ...)unknown    
17683SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100167 (more info ...)unknown    
17699PROTOCOL-SNMP Multiple vendor SNMPv3 HMAC handling authentication bypass attempt (more info ...)attempted-admin 2008-0960 29623  
17704FILE-OTHER McAfee LHA file parsing buffer overflow attempt (more info ...)attempted-user 2005-0643 10243  
17716SERVER-MAIL IBM Lotus Notes DOC attachment viewer buffer overflow (more info ...)attempted-user 2007-5544 26146  
17717SERVER-MAIL IBM Lotus Notes HTML input tag buffer overflow attempt (more info ...)attempted-user 2007-4222 26200  URL
17718SERVER-ORACLE Oracle MDSYS drop table trigger injection attempt (more info ...)attempted-admin 2008-3979 33177  
17722SERVER-ORACLE XDB.XDB_PITRIG_PKG buffer overflow attempt (more info ...)attempted-admin 2008-0339 27229  URL
17727FILE-OTHER Oracle JDK image parsing library ICC buffer overflow attempt (more info ...)attempted-user 2007-2788 24004  URL
17736SERVER-OTHER McAfee LHA Type-2 file handling overflow attempt (more info ...)attempted-user 2005-0644 12832  
17765OS-WINDOWS OpenType Font file parsing buffer overflow attempt (more info ...)attempted-user 2010-2740   URL
17775INDICATOR-SHELLCODE Shikata Ga Nai x86 polymorphic shellcode decoder detected (more info ...)shellcode-detect    
17777SERVER-MAIL IBM Lotus Notes WPD attachment handling buffer overflow attempt (more info ...)attempted-admin 2008-4564 34086  
17778FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
17805MALWARE-CNC Worm.Win32.Neeris.BF variant outbound connection (more info ...)trojan-activity    URL
17810INDICATOR-COMPROMISE potential malware - download of server32.exe (more info ...)suspicious-filename-detect    URL
17811INDICATOR-COMPROMISE potential malware - download of svchost.exe (more info ...)suspicious-filename-detect    
17812INDICATOR-COMPROMISE potential malware - download of iexplore.exe (more info ...)suspicious-filename-detect    
17813INDICATOR-COMPROMISE potential malware - download of iprinp.dll (more info ...)suspicious-filename-detect    
17814INDICATOR-COMPROMISE potential malware - download of winzf32.dll (more info ...)suspicious-filename-detect    
17815MALWARE-CNC Thinkpoint fake antivirus - user display (more info ...)trojan-activity    URL
17816MALWARE-CNC Thinkpoint fake antivirus - credit card submission (more info ...)trojan-activity    URL
17817SERVER-OTHER Thinkpoint fake antivirus binary download (more info ...)trojan-activity    URL
17899MALWARE-CNC URI request for known malicious URI - /reques0.asp?kind=006&mac= (more info ...)trojan-activity    URL
17900MALWARE-CNC URI request for known malicious URI - /basic/cn3c2/c.*dll (more info ...)trojan-activity    URL
17901MALWARE-CNC URI request for known malicious URI - /mybackup21.rar (more info ...)trojan-activity    URL
17902MALWARE-CNC URI request for known malicious URI - /?getexe=loader.exe (more info ...)trojan-activity    URL
17903MALWARE-CNC URI request for known malicious URI - stid= (more info ...)trojan-activity    URL
17907MALWARE-CNC URI request for known malicious URI - /MNG/Download/?File=AZF DATADIR Download (more info ...)trojan-activity    URL
17908MALWARE-CNC URI request for known malicious URI - /images/crypt_22.exe (more info ...)trojan-activity    URL
17909MALWARE-CNC URI request for known malicious URI - /images/css/1.exe (more info ...)trojan-activity    URL
17910MALWARE-CNC URI request for known malicious URI - /7xdown.exe (more info ...)trojan-activity    URL
17911MALWARE-CNC URI request for known malicious URI - /winhelper.exe (more info ...)trojan-activity    URL
17912MALWARE-CNC URI request for known malicious URI - /upopwin/count.asp?mac= (more info ...)trojan-activity    URL
17913MALWARE-CNC URI request for known malicious URI - /ok.exe (more info ...)trojan-activity    URL
17914MALWARE-CNC URI request for known malicious URI - /LjBin/Bin.Dll (more info ...)trojan-activity    URL
17915MALWARE-CNC URI request for known malicious URI - /1001ns/cfg3n.bin (more info ...)trojan-activity    URL
17916MALWARE-CNC URI request for known malicious URI - /dh/stats.bin (more info ...)trojan-activity    URL
17917MALWARE-CNC URI request for known malicious URI - /zeus/config.bin (more info ...)trojan-activity    URL
17918POLICY-SPAM aaof.onlinelewiss22r.ru known spam email attempt (more info ...)policy-violation    
17919POLICY-SPAM akiq.onlinetommie54y.ru known spam email attempt (more info ...)policy-violation    
17920POLICY-SPAM aobuii.onlinelewiss22r.ru known spam email attempt (more info ...)policy-violation    
17921POLICY-SPAM argue.medrayner44c.ru known spam email attempt (more info ...)policy-violation    
17922POLICY-SPAM ava.refilleldredge89r.ru known spam email attempt (more info ...)policy-violation    
17923POLICY-SPAM axoseb.medicdrugsxck.ru known spam email attempt (more info ...)policy-violation    
17924POLICY-SPAM azo.onlinetommie54y.ru known spam email attempt (more info ...)policy-violation    
17925POLICY-SPAM back.pharmroyce83b.ru known spam email attempt (more info ...)policy-violation    
17926POLICY-SPAM by.pharmroyce83b.ru known spam email attempt (more info ...)policy-violation    
17927POLICY-SPAM cardinals.refilldud86o.ru known spam email attempt (more info ...)policy-violation    
17928POLICY-SPAM chemist.onlineruggiero33q.ru known spam email attempt (more info ...)policy-violation    
17929POLICY-SPAM chula.pharmroyce83b.ru known spam email attempt (more info ...)policy-violation    
17930POLICY-SPAM classification.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
17931POLICY-SPAM compensate.refilldud86o.ru known spam email attempt (more info ...)policy-violation    
17932POLICY-SPAM cswjlxey.ru known spam email attempt (more info ...)policy-violation    
17933POLICY-SPAM current.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
17934POLICY-SPAM cyacaz.pilltodd73p.ru known spam email attempt (more info ...)policy-violation    
17935POLICY-SPAM deepcenter.ru known spam email attempt (more info ...)policy-violation    
17936POLICY-SPAM delegate.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
17937POLICY-SPAM diet.medrayner44c.ru known spam email attempt (more info ...)policy-violation    
17938POLICY-SPAM direct.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
17939POLICY-SPAM divyo.pillking74s.ru known spam email attempt (more info ...)policy-violation    
17940POLICY-SPAM drugsgeorge65g.ru known spam email attempt (more info ...)policy-violation    
17941POLICY-SPAM dux.erectnoll24k.ru known spam email attempt (more info ...)policy-violation    
17942POLICY-SPAM dypoh.erectjefferey85n.ru known spam email attempt (more info ...)policy-violation    
17943POLICY-SPAM eaihar.refilleldredge89r.ru known spam email attempt (more info ...)policy-violation    
17944POLICY-SPAM eeez.onlinehamel83i.ru known spam email attempt (more info ...)policy-violation    
17945POLICY-SPAM egi.refilleldredge89r.ru known spam email attempt (more info ...)policy-violation    
17946POLICY-SPAM ehyw.cumedicdrugsx.ru known spam email attempt (more info ...)policy-violation    
17947POLICY-SPAM eka.onlinehamel83i.ru known spam email attempt (more info ...)policy-violation    
17948POLICY-SPAM election.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
17949POLICY-SPAM elik.drugslevy46b.ru known spam email attempt (more info ...)policy-violation    
17950POLICY-SPAM epeno.onlinelewiss22r.ru known spam email attempt (more info ...)policy-violation    
17951POLICY-SPAM erectgodart30s.ru known spam email attempt (more info ...)policy-violation    
17952POLICY-SPAM erol.camedicdrugsx.ru known spam email attempt (more info ...)policy-violation    
17953POLICY-SPAM exa.drugslevy46b.ru known spam email attempt (more info ...)policy-violation    
17954POLICY-SPAM eyu.onlinehamel83i.ru known spam email attempt (more info ...)policy-violation    
17955POLICY-SPAM fashionchannel.ru known spam email attempt (more info ...)policy-violation    
17956POLICY-SPAM fauxy.pillking74s.ru known spam email attempt (more info ...)policy-violation    
17957POLICY-SPAM food.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
17958POLICY-SPAM generality.onlinehill21q.ru known spam email attempt (more info ...)policy-violation    
17959POLICY-SPAM goyry.ramedicdrugsx.ru known spam email attempt (more info ...)policy-violation    
17960POLICY-SPAM gueepa.erectnoll24k.ru known spam email attempt (more info ...)policy-violation    
17961POLICY-SPAM has.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
17962POLICY-SPAM have.medrayner44c.ru known spam email attempt (more info ...)policy-violation    
17963POLICY-SPAM headtest.ru known spam email attempt (more info ...)policy-violation    
17964POLICY-SPAM huhuh.pilltodd73p.ru known spam email attempt (more info ...)policy-violation    
17965POLICY-SPAM hyem.pilltodd73p.ru known spam email attempt (more info ...)policy-violation    
17966POLICY-SPAM icysa.refilleldredge89r.ru known spam email attempt (more info ...)policy-violation    
17967POLICY-SPAM iiy.refilleldredge89r.ru known spam email attempt (more info ...)policy-violation    
17968POLICY-SPAM iki.onlinetommie54y.ru known spam email attempt (more info ...)policy-violation    
17969POLICY-SPAM iner.medicdrugsxdl.ru known spam email attempt (more info ...)policy-violation    
17970POLICY-SPAM in.onlinehill21q.ru known spam email attempt (more info ...)policy-violation    
17971POLICY-SPAM intelpost.ru known spam email attempt (more info ...)policy-violation    
17972POLICY-SPAM inunuw.medicdrugsxpo.ru known spam email attempt (more info ...)policy-violation    
17973POLICY-SPAM ipiig.drugslevy46b.ru known spam email attempt (more info ...)policy-violation    
17974POLICY-SPAM iqor.pilltodd73p.ru known spam email attempt (more info ...)policy-violation    
17975POLICY-SPAM is.medrayner44c.ru known spam email attempt (more info ...)policy-violation    
17976POLICY-SPAM itaca.erectnoll24k.ru known spam email attempt (more info ...)policy-violation    
17977POLICY-SPAM ive.pilltodd73p.ru known spam email attempt (more info ...)policy-violation    
17978POLICY-SPAM iweqyz.erectjefferey85n.ru known spam email attempt (more info ...)policy-violation    
17979POLICY-SPAM iycyde.medicdrugsxco.ru known spam email attempt (more info ...)policy-violation    
17980POLICY-SPAM iyw.refilleldredge89r.ru known spam email attempt (more info ...)policy-violation    
17981POLICY-SPAM jaecoh.erectnoll24k.ru known spam email attempt (more info ...)policy-violation    
17982POLICY-SPAM jael.pillking74s.ru known spam email attempt (more info ...)policy-violation    
17983POLICY-SPAM jex.remedicdrugsx.ru known spam email attempt (more info ...)policy-violation    
17984POLICY-SPAM john.onlinehill21q.ru known spam email attempt (more info ...)policy-violation    
17985POLICY-SPAM joseph.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
17986POLICY-SPAM jyn.medicdrugsxdl.ru known spam email attempt (more info ...)policy-violation    
17987POLICY-SPAM jyzyv.refilleldredge89r.ru known spam email attempt (more info ...)policy-violation    
17988POLICY-SPAM koosaf.erectnoll24k.ru known spam email attempt (more info ...)policy-violation    
17989POLICY-SPAM lybah.pilltodd73p.ru known spam email attempt (more info ...)policy-violation    
17990POLICY-SPAM manila.onlinephilbert42f.ru known spam email attempt (more info ...)policy-violation    
17991POLICY-SPAM masa.erectjefferey85n.ru known spam email attempt (more info ...)policy-violation    
17992POLICY-SPAM medpenny17j.ru known spam email attempt (more info ...)policy-violation    
17993POLICY-SPAM minionspre.ru known spam email attempt (more info ...)policy-violation    
17994POLICY-SPAM nazuwu.onlinelewiss22r.ru known spam email attempt (more info ...)policy-violation    
17995POLICY-SPAM negotiations.refilldud86o.ru known spam email attempt (more info ...)policy-violation    
17996POLICY-SPAM niqiv.erectjefferey85n.ru known spam email attempt (more info ...)policy-violation    
17997POLICY-SPAM odimys.medicdrugsxlb.ru known spam email attempt (more info ...)policy-violation    
17998POLICY-SPAM odoog.onlinelewiss22r.ru known spam email attempt (more info ...)policy-violation    
17999POLICY-SPAM oekaka.aimedicdrugsx.ru known spam email attempt (more info ...)policy-violation    
18000POLICY-SPAM oeqio.erectnoll24k.ru known spam email attempt (more info ...)policy-violation    
18001POLICY-SPAM of.onlinephilbert42f.ru known spam email attempt (more info ...)policy-violation    
18002POLICY-SPAM of.refilldud86o.ru known spam email attempt (more info ...)policy-violation    
18003POLICY-SPAM of.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
18004POLICY-SPAM oipek.onlinehamel83i.ru known spam email attempt (more info ...)policy-violation    
18005POLICY-SPAM oji.medicdrugsxto.ru known spam email attempt (more info ...)policy-violation    
18006POLICY-SPAM onotye.onlinelewiss22r.ru known spam email attempt (more info ...)policy-violation    
18007POLICY-SPAM opy.erectjefferey85n.ru known spam email attempt (more info ...)policy-violation    
18008POLICY-SPAM orderbuzz.ru known spam email attempt (more info ...)policy-violation    
18009POLICY-SPAM ouu.almedicdrugsx.ru known spam email attempt (more info ...)policy-violation    
18010POLICY-SPAM oxuc.pillking74s.ru known spam email attempt (more info ...)policy-violation    
18011POLICY-SPAM pillrolfe64l.ru known spam email attempt (more info ...)policy-violation    
18012POLICY-SPAM recently.refilldud86o.ru known spam email attempt (more info ...)policy-violation    
18013POLICY-SPAM records.onlinephilbert42f.ru known spam email attempt (more info ...)policy-violation    
18014POLICY-SPAM reobaj.onlinehamel83i.ru known spam email attempt (more info ...)policy-violation    
18015POLICY-SPAM research.onlinehill21q.ru known spam email attempt (more info ...)policy-violation    
18016POLICY-SPAM returning.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
18017POLICY-SPAM right.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
18018POLICY-SPAM riwaro.erectjefferey85n.ru known spam email attempt (more info ...)policy-violation    
18019POLICY-SPAM ruuav.erectnoll24k.ru known spam email attempt (more info ...)policy-violation    
18020POLICY-SPAM ryhux.medicdrugsxpa.ru known spam email attempt (more info ...)policy-violation    
18021POLICY-SPAM software-buyshop-7.ru known spam email attempt (more info ...)policy-violation    
18022POLICY-SPAM specialyou.ru known spam email attempt (more info ...)policy-violation    
18023POLICY-SPAM starring.pharmroyce83b.ru known spam email attempt (more info ...)policy-violation    
18024POLICY-SPAM store-softwarebuy-7.ru known spam email attempt (more info ...)policy-violation    
18025POLICY-SPAM sya.onlinehamel83i.ru known spam email attempt (more info ...)policy-violation    
18026POLICY-SPAM tabdarin80s.ru known spam email attempt (more info ...)policy-violation    
18027POLICY-SPAM tabgordan13n.ru known spam email attempt (more info ...)policy-violation    
18028POLICY-SPAM tablangston19a.ru known spam email attempt (more info ...)policy-violation    
18029POLICY-SPAM tabwebster77c.ru known spam email attempt (more info ...)policy-violation    
18030POLICY-SPAM tanuen.dimedicdrugsx.ru known spam email attempt (more info ...)policy-violation    
18031POLICY-SPAM the.onlinehill21q.ru known spam email attempt (more info ...)policy-violation    
18032POLICY-SPAM the.onlineruggiero33q.ru known spam email attempt (more info ...)policy-violation    
18033POLICY-SPAM to.medrayner44c.ru known spam email attempt (more info ...)policy-violation    
18034POLICY-SPAM trails.pharmroyce83b.ru known spam email attempt (more info ...)policy-violation    
18035POLICY-SPAM trusting-me.ru known spam email attempt (more info ...)policy-violation    
18036POLICY-SPAM twodays.ru known spam email attempt (more info ...)policy-violation    
18037POLICY-SPAM tyqaja.pilltodd73p.ru known spam email attempt (more info ...)policy-violation    
18038POLICY-SPAM uboi.onlinehamel83i.ru known spam email attempt (more info ...)policy-violation    
18039POLICY-SPAM uf.drugslevy46b.ru known spam email attempt (more info ...)policy-violation    
18040POLICY-SPAM uielij.pillking74s.ru known spam email attempt (more info ...)policy-violation    
18041POLICY-SPAM unasu.medicdrugsxto.ru known spam email attempt (more info ...)policy-violation    
18042POLICY-SPAM upazo.pilltodd73p.ru known spam email attempt (more info ...)policy-violation    
18043POLICY-SPAM utuqaj.pillking74s.ru known spam email attempt (more info ...)policy-violation    
18044POLICY-SPAM uuji.refilleldredge89r.ru known spam email attempt (more info ...)policy-violation    
18045POLICY-SPAM variation.refilldud86o.ru known spam email attempt (more info ...)policy-violation    
18046POLICY-SPAM via.refillreade47j.ru known spam email attempt (more info ...)policy-violation    
18047POLICY-SPAM voiceless.pharmroyce83b.ru known spam email attempt (more info ...)policy-violation    
18048POLICY-SPAM was.medrayner44c.ru known spam email attempt (more info ...)policy-violation    
18050POLICY-SPAM world.onlinehill21q.ru known spam email attempt (more info ...)policy-violation    
18051POLICY-SPAM www.buhni.ru known spam email attempt (more info ...)policy-violation    
18052POLICY-SPAM www.visitcover.ru known spam email attempt (more info ...)policy-violation    
18053POLICY-SPAM xob.erectnoll24k.ru known spam email attempt (more info ...)policy-violation    
18054POLICY-SPAM ygy.onlinetommie54y.ru known spam email attempt (more info ...)policy-violation    
18055POLICY-SPAM yit.medicdrugsxor.ru known spam email attempt (more info ...)policy-violation    
18056POLICY-SPAM ylum.onlinelewiss22r.ru known spam email attempt (more info ...)policy-violation    
18057POLICY-SPAM ymyuto.onlinelewiss22r.ru known spam email attempt (more info ...)policy-violation    
18058POLICY-SPAM yomy.pillking74s.ru known spam email attempt (more info ...)policy-violation    
18059POLICY-SPAM yzugez.pillking74s.ru known spam email attempt (more info ...)policy-violation    
18060POLICY-SPAM zeroprices.ru known spam email attempt (more info ...)policy-violation    
18061POLICY-SPAM zueuz.onlinehamel83i.ru known spam email attempt (more info ...)policy-violation    
18098MALWARE-CNC URI request for known malicious URI - Carberp (more info ...)trojan-activity    URL
18099MALWARE-CNC URI request for known malicious URI - Carberp (more info ...)trojan-activity    URL
18100MALWARE-CNC Tidserv malware command and control channel traffic (more info ...)trojan-activity    URL
18101SERVER-OTHER Sun Directory Server LDAP denial of service attempt (more info ...)attempted-dos 2006-0647   URL
18171OS-WINDOWS Multiple product mailto uri handling code execution attempt (more info ...)attempted-user 2007-5020 25945  URL
18172OS-WINDOWS Multiple product mailto uri handling code execution attempt (more info ...)attempted-user 2007-4041 25945  URL
18173OS-WINDOWS Multiple product mailto uri handling code execution attempt (more info ...)attempted-user 2007-4041 25945  URL
18179INDICATOR-SCAN Proxyfire.net anonymous proxy scan (more info ...)network-scan    URL
18188BROWSER-FIREFOX Multiple browser marquee tag denial of service attempt (more info ...)attempted-dos 2006-2723 18165  
18247MALWARE-CNC User-Agent known malicious User-Agent ErrCode - W32/Fujacks.htm (more info ...)trojan-activity    URL
18273FILE-IDENTIFY BAT file download request (more info ...)misc-activity    
18279MALWARE-CNC Win.Trojan.Karagany.A variant outbound connection (more info ...)trojan-activity    URL
18281MALWARE-CNC Win.Trojan.VB.njz variant outbound connection (more info ...)trojan-activity    URL
18312SERVER-OTHER Subversion 1.0.2 get-dated-rev buffer overflow attempt (more info ...)attempted-user 2004-0397 10386  
18317SERVER-MAIL Ipswitch IMail RCPT TO proxy overflow attempt (more info ...)attempted-admin 2006-4379 19885  URL
18336MALWARE-CNC User-Agent known malicious user-agent string gbot/2.3 (more info ...)trojan-activity    URL
18337MALWARE-CNC User-Agent known malicious user-agent string iamx/3.11 (more info ...)trojan-activity    URL
18338MALWARE-CNC User-Agent known malicious user-agent string NSISDL/1.2 (more info ...)trojan-activity    URL
18340MALWARE-CNC User-Agent known malicious user-agent string ClickAdsByIE 0.7.5 (more info ...)trojan-activity    URL
18341MALWARE-CNC User-Agent known malicious user-agent string UtilMind HTTPGet (more info ...)trojan-activity    URL
18342MALWARE-CNC User-Agent known malicious user-agent string NSIS_DOWNLOAD (more info ...)trojan-activity    URL
18343MALWARE-CNC User-Agent known malicious user-agent string WSEnrichment (more info ...)trojan-activity    URL
18346MALWARE-CNC User-Agent known malicious user-agent string GPRecover (more info ...)trojan-activity    URL
18347MALWARE-CNC User-Agent known malicious user-agent string AutoIt (more info ...)trojan-activity    URL
18349MALWARE-CNC User-Agent known malicious user-agent string Flipopia (more info ...)trojan-activity    URL
18350MALWARE-CNC User-Agent known malicious user-agent string GabPath (more info ...)trojan-activity    URL
18351MALWARE-CNC User-Agent known malicious user-agent string GPUpdater (more info ...)trojan-activity    URL
18352MALWARE-CNC User-Agent known malicious user-agent string PinballCorp-BSAI/VER_STR_COMMA (more info ...)trojan-activity    URL
18353MALWARE-CNC User-Agent request for known PUA user agent - SelectRebates (more info ...)trojan-activity    URL
18355MALWARE-CNC User-Agent known malicious user-agent string Se2011 (more info ...)trojan-activity    URL
18356MALWARE-CNC User-Agent known malicious user-agent string random (more info ...)trojan-activity    URL
18357MALWARE-CNC User-Agent known malicious user-agent string Setup Factory (more info ...)trojan-activity    URL
18358MALWARE-CNC User-Agent known malicious user-agent string NSIS_INETLOAD (more info ...)trojan-activity    URL
18359MALWARE-CNC User-Agent known malicious user-agent string Shareaza (more info ...)trojan-activity    URL
18360MALWARE-CNC User-Agent known malicious user-agent string Oncues (more info ...)trojan-activity    URL
18361MALWARE-CNC User-Agent known malicious user-agent string Downloader1.1 (more info ...)trojan-activity    URL
18362MALWARE-CNC User-Agent known malicious user-agent string Search Toolbar 1.1 (more info ...)trojan-activity    URL
18363MALWARE-CNC User-Agent known malicious user-agent string GPRecover (more info ...)trojan-activity    URL
18364MALWARE-CNC User-Agent known malicious user-agent string msndown (more info ...)trojan-activity    URL
18365MALWARE-CNC User-Agent known malicious user-agent string Agentcc (more info ...)trojan-activity    URL
18366MALWARE-CNC User-Agent known malicious user-agent string OCInstaller (more info ...)trojan-activity    URL
18367MALWARE-CNC User-Agent known malicious user-agent string FPRecover (more info ...)trojan-activity    URL
18368MALWARE-CNC User-Agent known malicious user-agent string Our_Agent (more info ...)trojan-activity    URL
18369MALWARE-CNC User-Agent known malicious user-agent string iexp-get (more info ...)trojan-activity    URL
18371MALWARE-CNC User-Agent known malicious user-agent string QvodDown (more info ...)trojan-activity    URL
18373MALWARE-CNC User-Agent known malicious user-agent string Installer (more info ...)trojan-activity    URL
18374MALWARE-CNC User-Agent known malicious user-agent string SurfBear (more info ...)trojan-activity    URL
18375MALWARE-CNC User-Agent known malicious user-agent string HTTP Wininet (more info ...)trojan-activity    URL
18376MALWARE-CNC User-Agent known malicious user-agent string Trololo (more info ...)trojan-activity    URL
18377MALWARE-CNC User-Agent known malicious user-agent string malware (more info ...)trojan-activity    URL
18378MALWARE-CNC User-Agent known malicious user-agent string AutoHotkey (more info ...)trojan-activity    URL
18379MALWARE-CNC User-Agent known malicious user-agent string AskInstallChecker (more info ...)trojan-activity    URL
18380MALWARE-CNC User-Agent known malicious user-agent string FPUpdater (more info ...)trojan-activity    URL
18381MALWARE-CNC User-Agent known malicious user-agent string Travel Update (more info ...)trojan-activity    URL
18382MALWARE-CNC User-Agent known malicious user-agent string WMUpdate (more info ...)trojan-activity    URL
18383MALWARE-CNC User-Agent known malicious user-agent string GPInstaller (more info ...)trojan-activity    URL
18386MALWARE-CNC User-Agent known malicious user-agent string AHTTPConnection (more info ...)trojan-activity    URL
18387MALWARE-CNC User-Agent known malicious user-agent string dwplayer (more info ...)trojan-activity    URL
18388MALWARE-CNC User-Agent known malicious user-agent string RookIE/1.0 (more info ...)trojan-activity    URL
18389MALWARE-CNC User-Agent known malicious user-agent string 3653Client (more info ...)trojan-activity    URL
18390MALWARE-CNC User-Agent known malicious user-agent string Delphi 5.x (more info ...)trojan-activity    URL
18391MALWARE-CNC User-Agent known malicious user-agent string MyLove (more info ...)trojan-activity    URL
18392MALWARE-CNC User-Agent known malicious user-agent string qixi (more info ...)trojan-activity    URL
18393MALWARE-CNC User-Agent known malicious user-agent string vyre32 (more info ...)trojan-activity    URL
18394MALWARE-CNC User-Agent known malicious user-agent string OCRecover (more info ...)trojan-activity    URL
18395MALWARE-CNC User-Agent known malicious user-agent string Duckling/1.0 (more info ...)trojan-activity    URL
18397SERVER-OTHER HP DDMI Agent spoofing - command execution (more info ...)attempted-admin 2009-1419 35250  
18458MALWARE-CNC Night Dragon initial beacon (more info ...)trojan-activity    
18459MALWARE-CNC Night Dragon keepalive message (more info ...)trojan-activity    
18460SERVER-WEBAPP Symantec Alert Management System pin number buffer overflow attempt (more info ...)attempted-user 2010-0110   URL
18465SERVER-WEBAPP FreePBX recording interface file upload code execution attempt (more info ...)attempted-admin 2010-3490 43454  
18466SERVER-WEBAPP raSMP User-Agent XSS injection attempt (more info ...)attempted-admin 2006-0084 16138  
18467SERVER-WEBAPP raSMP User-Agent XSS injection attempt (more info ...)attempted-admin 2006-0084 16138  
18477SERVER-MAIL Lotus Notes MIF viewer statement data overflow 2 (more info ...)attempted-user 2007-5910 26175  
18487SERVER-OTHER Ingres Database iidbms heap overflow attempt (more info ...)attempted-user  38001  
18509SERVER-OTHER PeerCast format string exploit attempt (more info ...)attempted-admin 2005-1806 13808  
18511SERVER-OTHER Sourcefire Snort packet fragmentation reassembly denial of service attempt (more info ...)attempted-dos 2007-1398 22872  
18524SERVER-OTHER Multiple vendor anti-virus extended ASCII filename scan bypass attempt (more info ...)misc-attack    
18528SERVER-ORACLE Oracle TimesTen In-Memory Database HTTP request denial of service attempt (more info ...)attempted-dos  38019  
18532OS-WINDOWS Multiple Vendors request for iacenc.dll over SMB attempt (more info ...)attempted-user 2010-3150 42730  URL
18559SERVER-WEBAPP HP OpenView Performance Insight Server backdoor account code execution attempt (more info ...)attempted-admin 2011-0276 46079  
18560SERVER-WEBAPP HP OpenView Performance Insight Server backdoor account code execution attempt (more info ...)attempted-admin 2011-0276 46079  
18562MALWARE-CNC RogueSoftware.Win32.LivePcCare variant outbound connection (more info ...)trojan-activity    URL
18563MALWARE-CNC Win.Trojan.Gaboc variant outbound connection (more info ...)trojan-activity    URL
18564MALWARE-CNC RussKill botnet variant outbound connection (more info ...)trojan-activity    URL
18565INDICATOR-COMPROMISE fraudulent digital certificate for mail.google.com detected (more info ...)misc-attack    URL
18566INDICATOR-COMPROMISE fraudulent digital certificate for www.google.com detected (more info ...)misc-attack    URL
18567INDICATOR-COMPROMISE fraudulent digital certificate for login.yahoo.com detected (more info ...)misc-attack    URL
18568INDICATOR-COMPROMISE fraudulent digital certificate for login.yahoo.com detected (more info ...)misc-attack    URL
18569INDICATOR-COMPROMISE fraudulent digital certificate for login.yahoo.com detected (more info ...)misc-attack    URL
18572INDICATOR-COMPROMISE fraudulent digital certificate for login.live.com detected (more info ...)misc-attack    URL
18573INDICATOR-COMPROMISE fraudulent digital certificate for global trustee detected (more info ...)misc-attack    URL
18574SERVER-MAIL RCPT TO overflow (more info ...)attempted-admin 2009-0410 9696  
18576INDICATOR-COMPROMISE fraudulent digital certificate from usertrust.com detected (more info ...)misc-attack    URL
18577MALWARE-CNC Win.Trojan.Banker.agum variant outbound connection (more info ...)trojan-activity    URL
18591FILE-OTHER CoolPlayer Playlist File Handling Buffer Overflow (more info ...)attempted-user 2008-3408 30418  
18603SERVER-MAIL IBM Lotus Notes Applix Graphics Parsing Buffer Overflow (more info ...)attempted-admin 2007-5405 28454  
18604MALWARE-OTHER lizamoon script injection (more info ...)misc-activity    URL
18605PROTOCOL-SCADA Tecnomatix FactoryLink CSService path overflow attempt (more info ...)attempted-admin  46934  
18606PROTOCOL-SCADA Tecnomatix FactoryLink CSService file access attempt (more info ...)attempted-user  46934  
18607PROTOCOL-SCADA Tecnomatix FactoryLink CSService file information access attempt (more info ...)attempted-user  46934  
18608APP-DETECT Dropbox desktop software in use (more info ...)policy-violation    
18609APP-DETECT Dropbox desktop software in use (more info ...)policy-violation    
18610PROTOCOL-SCADA Tecnomatix FactoryLink vrn.exe opcode 9 or 10 string parsing overflow attempt (more info ...)attempted-user  46934  
18614PROTOCOL-SCADA Tecnomatix FactoryLink vrn.exe file access attempt (more info ...)attempted-user  46934  
18617SERVER-OTHER Tecnomatix FactoryLink CSService null pointer attempt (more info ...)attempted-dos  46934  
18618MALWARE-CNC Win.Trojan.Scar.dpvy/Parkchicers.A/Delf checkin (more info ...)trojan-activity    URL
18658PROTOCOL-SCADA RealWin 2.1 FC_CONNECT_FCS_LOGIN overflow attempt (more info ...)attempted-admin    URL
18682FILE-PDF transfer of a PDF with OpenAction object attempt (more info ...)policy-violation 2014-8450   URL
18684FILE-PDF PDF file with embedded PDF object (more info ...)policy-violation    URL
18700MALWARE-CNC Win.Trojan.BHO.argt checkin (more info ...)trojan-activity    URL
18707MALWARE-CNC RogueSoftware.Win32.ControlCenter variant outbound connection (more info ...)trojan-activity    URL
18708MALWARE-CNC RogueSoftware.Win32.AntivirusSoft variant outbound connection (more info ...)trojan-activity    URL
18709MALWARE-CNC Win.Trojan.Banker.aufm variant outbound connection (more info ...)trojan-activity    URL
18711MALWARE-CNC RogueSoftware.Win32.SecurityCentral variant outbound connection (more info ...)trojan-activity    URL
18712MALWARE-CNC RogueSoftware.Win32.XJRAntivirus variant outbound connection (more info ...)trojan-activity    URL
18713SERVER-OTHER OpenSSL TLS connection record handling denial of service attempt (more info ...)attempted-dos 2010-0740 39013  
18714SERVER-OTHER OpenSSL TLS connection record handling denial of service attempt (more info ...)attempted-dos 2010-0740 39013  
18715MALWARE-CNC Ozdok botnet communication with C&C server (more info ...)trojan-activity    URL
18716MALWARE-CNC Win.Trojan.Banker.H variant outbound connection (more info ...)trojan-activity    URL
18717MALWARE-CNC Win.Trojan.Banker.QO variant outbound connection (more info ...)trojan-activity    URL
18718MALWARE-CNC RogueSoftware.Win32.AdvancedDefender variant outbound connection (more info ...)trojan-activity    URL
18719MALWARE-CNC Win.Trojan.IRCBot.CBY variant outbound connection (more info ...)trojan-activity    URL
18720MALWARE-CNC Win.Trojan.Terzib.A variant outbound connection (more info ...)trojan-activity    URL
18721PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x1C84 integer overflow attempt (more info ...)attempted-admin    URL
18722PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x1C84 integer overflow attempt (more info ...)attempted-admin    URL
18723MALWARE-CNC RogueSoftware.Win32.CleanV variant outbound connection (more info ...)trojan-activity    URL
18724MALWARE-CNC RogueSoftware.Win32.ZeroClean variant outbound connection (more info ...)trojan-activity    URL
18725PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B0 heap overflow attempt (more info ...)attempted-admin    URL
18726PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B2 heap overflow attempt (more info ...)attempted-admin    URL
18727PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B5 heap overflow attempt (more info ...)attempted-admin    URL
18728PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x0DAE heap overflow attempt (more info ...)attempted-admin    URL
18729PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x1BBC heap overflow attempt (more info ...)attempted-admin    URL
18730PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x089A integer overflow attempt (more info ...)attempted-admin    URL
18731PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x0453 integer overflow attempt (more info ...)attempted-admin    URL
18732PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B0 integer overflow attempt (more info ...)attempted-admin    URL
18733PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B0 integer overflow attempt (more info ...)attempted-admin    URL
18734PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B0 integer overflow attempt (more info ...)attempted-admin    URL
18735PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B0 integer overflow attempt (more info ...)attempted-admin    URL
18736PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B0 integer overflow attempt (more info ...)attempted-admin    URL
18737PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B0 integer overflow attempt (more info ...)attempted-admin    URL
18738PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B2 integer overflow attempt (more info ...)attempted-admin    URL
18739MALWARE-CNC Worm.Win32.Koobface.D variant outbound connection (more info ...)trojan-activity    URL
18742SERVER-WEBAPP IBM WebSphere Expect header cross-site scripting (more info ...)web-application-attack 2007-5944 26457  
18743SERVER-WEBAPP VLC player web interface format string attack (more info ...)attempted-admin 2007-6682 27015  
18744FILE-MULTIMEDIA VideoLAN vlc player subtitle buffer overflow attempt (more info ...)attempted-admin 2007-6681 27015  
18746PROTOCOL-SCADA RealWin 2.1 FC_CTAGLIST_FCS_XTAG overflow attempt (more info ...)attempted-admin    URL
18747PROTOCOL-SCADA RealWin 2.1 FC_BINFILE_FCS_xFILE overflow attempt (more info ...)attempted-admin    URL
18748PROTOCOL-SCADA RealWin 2.1 FC_MISC_FCS_MSGx overflow attempt (more info ...)attempted-admin    URL
18749PROTOCOL-SCADA RealWin 2.1 FC_CTAGLIST_FCS_XTAG overflow attempt (more info ...)attempted-admin    URL
18750PROTOCOL-SCADA RealWin 2.1 FC_SCRIPT_FCS_STARTPROG overflow attempt (more info ...)attempted-admin    URL
18752PROTOCOL-SCADA RealWin 2.1 FC_INFOTAG_SET_CONTROL overflow attempt (more info ...)attempted-admin    URL
18761SERVER-WEBAPP Majordomo2 http directory traversal attempt (more info ...)web-application-attack 2011-0049 46127  
18762MALWARE-CNC URI request for known malicious URI /blog.updata?v= - Win32-Agent-GRW (more info ...)trojan-activity    
18763SERVER-OTHER ActFax Server LPD/LPR Remote Buffer Overflow (more info ...)attempted-admin    URL
18766SERVER-OTHER OpenSSL CMS structure OriginatorInfo memory corruption attempt (more info ...)attempted-user 2010-0742 40502  
18774MALWARE-CNC URI request for known malicious URI (more info ...)trojan-activity    
18775MALWARE-CNC URI request for known malicious URI - /gpdcount (more info ...)trojan-activity    
18777SERVER-OTHER HP data protector OmniInet service NULL dereference denial of service attempt (more info ...)denial-of-service    URL
18778PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B5 integer overflow attempt (more info ...)attempted-admin    URL
18779PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x04B5 integer overflow attempt (more info ...)attempted-admin    URL
18780PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x07D0 integer overflow attempt (more info ...)attempted-admin    URL
18781PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x07D0 integer overflow attempt (more info ...)attempted-admin    URL
18782MALWARE-CNC URI Request for known malicious URI - Chinese Rootkit.Win32.Fisp.a (more info ...)trojan-activity    URL
18783PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x0DAE integer overflow attempt (more info ...)attempted-admin    URL
18784PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x0DB0 integer overflow attempt (more info ...)attempted-admin    URL
18785PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x0FA4 integer overflow attempt (more info ...)attempted-admin    URL
18786PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x0FA7 integer overflow attempt (more info ...)attempted-admin    URL
18787PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x1BBC integer overflow attempt (more info ...)attempted-admin    URL
18788PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x1BBD integer overflow attempt (more info ...)attempted-admin    URL
18789PROTOCOL-SCADA Iconics Genesis 32/64 GenBroker opcode 0x26AC integer overflow attempt (more info ...)attempted-admin    URL
18804SERVER-WEBAPP OpenLDAP Modrdn utf-8 string code execution attempt (more info ...)attempted-admin 2010-0211 41770  
18807SERVER-OTHER OpenLDAP Modrdn RDN NULL string denial of service attempt (more info ...)attempted-dos 2010-0212 41770  
18808SERVER-MAIL Ipswitch IMail Server List Mailer Reply-To address buffer overflow attempt (more info ...)attempted-admin  41717  
18900MALWARE-CNC URI request for known malicious URI -- W32.Swizzor (more info ...)trojan-activity    URL
18905SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18906SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18907SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18908SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18909SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18910SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18911SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18912SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18913SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18914SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18915SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18916SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18917SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18918SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18919SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18920SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18921SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18922SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18923SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18924SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18925SERVER-WEBAPP OpenView Network Node Manager cookie buffer overflow attempt (more info ...)attempted-user 2010-2709 42154  
18929SERVER-ORACLE Oracle Secure Backup Administration objectname variable command injection attempt (more info ...)web-application-attack 2010-0906 41597  
18932SERVER-WEBAPP Jboss default configuration unauthorized application add attempt (more info ...)web-application-attack    URL
18934MALWARE-CNC known command and control channel traffic -- Coreflood (more info ...)trojan-activity    URL
18935SERVER-OTHER ISC DHCP server zero length client ID denial of service attempt (more info ...)attempted-dos 2010-2156 40775  
18936MALWARE-CNC URI request for known malicious URI - Win.Trojan.FakeAV (more info ...)trojan-activity    URL
18937MALWARE-CNC URI request for known malicious URI - Win.Trojan.Krap (more info ...)trojan-activity    URL
18939MALWARE-CNC known command and control channel traffic (more info ...)trojan-activity    URL
18940MALWARE-CNC URI request for known malicious URI - Sality (more info ...)trojan-activity    URL
18941MALWARE-CNC URI request for known malicious URI - FakeAV (more info ...)trojan-activity    URL
18942MALWARE-CNC URI request for known malicious URI - MacProtector (more info ...)trojan-activity    URL
18943MALWARE-CNC URI request for known malicious URI - MacDefender (more info ...)trojan-activity    URL
18945MALWARE-CNC Virus.Win32.Feberr variant outbound connection (more info ...)trojan-activity    URL
18946MALWARE-CNC Win.Trojan.IRCBot.FC variant outbound connection (more info ...)trojan-activity    URL
18947MALWARE-CNC Win.Trojan.IRCBot.FC variant outbound connection (more info ...)trojan-activity    URL
18953FILE-OTHER rich text format unexpected field type memory corruption attempt (more info ...)attempted-user 2010-1901   URL
18954FILE-OTHER rich text format unexpected field type memory corruption attempt (more info ...)attempted-user 2010-1901   URL
18959SERVER-WEBAPP VMware SpringSource Spring Framework class.classloader remote code execution attempt (more info ...)attempted-admin 2010-1622 40954  
18972SERVER-ORACLE Oracle Secure Backup Administration selector variable command injection attempt (more info ...)web-application-attack 2010-0906 41597  
18976MALWARE-CNC Rogue-Software.AVCare variant outbound connection (more info ...)trojan-activity    URL
18977MALWARE-CNC Win.Trojan.Proxy variant outbound connection (more info ...)trojan-activity    URL
18978MALWARE-CNC Win.Trojan.Pasta.aoq variant outbound connection (more info ...)trojan-activity    URL
18979MALWARE-CNC Worm.Win32.AutoRun.fmo variant outbound connection (more info ...)trojan-activity    URL
18984MALWARE-CNC URI request for known malicious URI - Win32/Trojanclicker (more info ...)trojan-activity    URL
18993SERVER-WEBAPP HP OpenView Network Node Manager server name exploit attempt (more info ...)attempted-admin 2011-0263 45762  URL
19006SERVER-OTHER HP Data Protector Express DtbClsLogin buffer overflow attempt (more info ...)attempted-user 2010-3007 43105  
19007SERVER-SAMBA Samba SID parsing overflow attempt (more info ...)attempted-admin 2010-3069 43212  
19016MALWARE-CNC MacBack Win.Trojan.variant outbound connection (more info ...)trojan-activity    URL
19017MALWARE-CNC MacBack Win.Trojan.variant outbound connection (more info ...)trojan-activity    URL
19018MALWARE-CNC MacBack Win.Trojan.variant outbound connection (more info ...)trojan-activity    URL
19019MALWARE-CNC MacBack Win.Trojan.variant outbound connection (more info ...)trojan-activity    URL
19021MALWARE-CNC Win.Trojan-Downloader.Win32.FraudLoad.dzm variant outbound connection (more info ...)trojan-activity    URL
19022MALWARE-CNC Win.Trojan-Downloader.Win32.FraudLoad.dzm variant outbound connection (more info ...)trojan-activity    URL
19023MALWARE-CNC IRC.Zapchast.zwrc variant outbound connection (more info ...)trojan-activity    URL
19024MALWARE-CNC Win.Trojan.StartPage variant outbound connection (more info ...)trojan-activity    URL
19025MALWARE-CNC Win.Trojan-Banker.Win32.Bancos.etf variant outbound connection (more info ...)trojan-activity    URL
19026PUA-ADWARE Smart Protector outbound connection (more info ...)successful-recon-limited    URL
19027MALWARE-CNC BrowserModifier.Win32.Kerlofost variant outbound connection (more info ...)trojan-activity    URL
19028MALWARE-CNC Win.Trojan.Mailbot variant outbound connection (more info ...)trojan-activity    URL
19029MALWARE-CNC Win.Trojan.PcClient.AI variant outbound connection (more info ...)trojan-activity    URL
19030MALWARE-CNC Win.Trojan.Uloadis variant outbound connection (more info ...)trojan-activity    URL
19031MALWARE-CNC iPRIVACY variant outbound connection (more info ...)trojan-activity    URL
19032MALWARE-CNC Win.Trojan.Cornfemo variant outbound connection (more info ...)trojan-activity    URL
19033MALWARE-CNC Win.Trojan.Cornfemo variant outbound connection (more info ...)trojan-activity    URL
19034MALWARE-CNC Win.Trojan.Kbot.qd variant outbound connection (more info ...)trojan-activity    URL
19035MALWARE-CNC Win.Trojan.Vilsel.baqb variant outbound connection (more info ...)trojan-activity    URL
19036MALWARE-CNC Win.Trojan.IRCBrute.I variant outbound connection (more info ...)trojan-activity    URL
19037MALWARE-CNC Win.Trojan.IRCBrute.I variant outbound connection (more info ...)trojan-activity    URL
19038MALWARE-CNC Win.Trojan.Jzzer.A variant outbound connection (more info ...)trojan-activity    URL
19039MALWARE-CNC Win.Trojan.Linkbot.alr variant outbound connection (more info ...)trojan-activity    URL
19040MALWARE-CNC Win.Trojan.Linkbot.alr variant outbound connection (more info ...)trojan-activity    URL
19041MALWARE-CNC Win.Trojan.Carberp.C variant outbound connection (more info ...)trojan-activity    URL
19042MALWARE-CNC Win.Trojan.Banker.ACQE variant outbound connection (more info ...)trojan-activity    URL
19043PUA-ADWARE RogueSoftware.Win32.BestBoan outbound connection (more info ...)trojan-activity    URL
19044PUA-ADWARE RogueSoftware.Win32.ThinkPoint outbound connection (more info ...)trojan-activity    URL
19045MALWARE-CNC Win.Trojan.Bancos.XQ variant outbound connection (more info ...)trojan-activity    URL
19046PUA-ADWARE RogueSoftware.Win32.Winwebsec outbound connection (more info ...)trojan-activity    URL
19047MALWARE-CNC User-Agent known malicious user agent - RCleanT (more info ...)trojan-activity    URL
19048MALWARE-CNC Win.Trojan.Darkness variant outbound connection (more info ...)trojan-activity    URL
19049MALWARE-CNC Win.Trojan.Gigade variant outbound connection (more info ...)trojan-activity    URL
19050MALWARE-CNC Win.Trojan.Banbra.fxe variant outbound connection (more info ...)trojan-activity    URL
19052MALWARE-CNC Win.Trojan.Httpbot.qdc variant outbound connection (more info ...)trojan-activity    URL
19053MALWARE-CNC Worm.Win32.Nusump.A variant outbound connection (more info ...)trojan-activity    URL
19054MALWARE-CNC Win.Trojan.Sisron.nelo variant outbound connection (more info ...)trojan-activity    URL
19055MALWARE-CNC Win.Trojan.Gosik.A registration (more info ...)trojan-activity    URL
19056MALWARE-CNC Win.Trojan.QQFish variant outbound connection (more info ...)trojan-activity    URL
19057MALWARE-CNC Win.Trojan.QQFish variant outbound connection (more info ...)trojan-activity    URL
19058MALWARE-CNC Worm.Win32.Faketube update request (more info ...)trojan-activity    URL
19059PUA-ADWARE RogueSoftware.Win32.SystemDefragmenter outbound connection (more info ...)trojan-activity    URL
19060MALWARE-CNC Win.Trojan.Ponmocup.A variant outbound connection (more info ...)trojan-activity    URL
19061PUA-ADWARE Adware.Win32.Cashtitan contact to server attempt (more info ...)trojan-activity    URL
19062MALWARE-CNC Win.Trojan.FakePlus variant outbound connection (more info ...)trojan-activity    URL
19072SERVER-OTHER RealNetworks Helix Server NTLM authentication heap overflow attempt (more info ...)attempted-admin 2010-1317 39490  
19073SERVER-OTHER Squid Proxy Expect header null pointer denial of service attempt (more info ...)attempted-dos 2010-3072 42982  
19081INDICATOR-OBFUSCATION known suspicious decryption routine (more info ...)misc-activity    URL
19106MALWARE-OTHER Keylogger Ardamax keylogger runtime detection - http (more info ...)trojan-activity    URL
19110SERVER-WEBAPP IBM Rational Quality Manager and Test Lab Manager policy bypass attempt (more info ...)default-login-attempt 2010-4094 44172  
19116SERVER-OTHER IBM Tivoli Storage Manager FastBack mount service code execution attempt (more info ...)attempted-admin 2010-3058 42549  
19120SERVER-OTHER IBM Informix DBINFO stack buffer overflow (more info ...)attempted-admin 2010-4069 44190  
19121SERVER-OTHER IBM Informix EXPLAIN stack buffer overflow attempt (more info ...)attempted-admin 2010-4053 44192  
19122POLICY-SPAM appledownload.com known spam email attempt (more info ...)policy-violation    URL
19123MALWARE-CNC Dropper Win.Trojan.Cefyns.A variant outbound connection (more info ...)trojan-activity    URL
19135MALWARE-BACKDOOR Win.Trojan.Buterat Checkin (more info ...)trojan-activity    URL
19159SERVER-OTHER HP Data Protector Manager RDS attempt (more info ...)denial-of-service 2011-0514 45725  
19160SERVER-OTHER NetSupport Manager client buffer overflow attempt (more info ...)attempted-admin 2011-0404 45728  
19161SERVER-OTHER NetSupport Manager client buffer overflow attempt (more info ...)attempted-admin 2011-0404 45728  
19162SERVER-ORACLE get_domain_index_metadata privilege escalation attempt (more info ...)attempted-admin 2006-2081 17590  
19163SERVER-ORACLE get_v2_domain_index_tables privilege escalation attempt (more info ...)attempted-admin 2006-2081 17590  
19164MALWARE-CNC Win.Trojan.SpyEye variant outbound connection (more info ...)trojan-activity    URL
19167PROTOCOL-VOIP Digium Asterisk UDPTL processing overflow attempt (more info ...)attempted-admin 2011-1147 46474  
19168SERVER-WEBAPP Oracle GoldenGate Veridata Server soap request overflow attempt (more info ...)attempted-admin 2010-4416 45868  
19175MALWARE-CNC User-Agent known malicious User-Agent wget 3.0 (more info ...)trojan-activity    URL
19176SERVER-WEBAPP cookiejacking attempt (more info ...)attempted-recon    URL
19177SERVER-WEBAPP cookiejacking attempt (more info ...)attempted-recon    URL
19199OS-WINDOWS Smb2Create_Finalize malformed EndOfFile field exploit attempt (more info ...)attempted-admin 2011-1268   URL
19206SERVER-OTHER IBM DB2 Universal Database receiveDASMessage buffer overflow attempt (more info ...)attempted-admin 2011-0731 46052  
19207SERVER-OTHER Symantec Alert Management System AMSSendAlertAck stack buffer overflow attempt (more info ...)attempted-admin 2010-0110   
19209SERVER-WEBAPP Symantec Alert Management System modem string buffer overflow attempt (more info ...)attempted-user 2010-0110   URL
19210SERVER-OTHER IBM Informix Dynamic Server set environment buffer overflow attempt (more info ...)attempted-admin 2011-1033   
19213SERVER-MAIL Ipswitch IMail Server Mailing List Message Subject buffer overflow (more info ...)attempted-admin    URL
19223SERVER-OTHER SAP Crystal Reports 2008 directory traversal attempt (more info ...)web-application-attack  45980  
19228SERVER-WEBAPP Oracle Secure Backup Administration preauth variable command injection attempt (more info ...)attempted-admin 2010-0906 41597  
19252FILE-IDENTIFY language.engtesselate.ln file download request (more info ...)misc-activity    
19256MALWARE-CNC URI request for known malicious URI - greenherbalteagirlholdingcup (more info ...)trojan-activity    
19281INDICATOR-SHELLCODE x86 OS agnostic single-byte xor countodwn encoder (more info ...)shellcode-detect    
19282INDICATOR-SHELLCODE x86 OS agnostic cpuid-based context keyed encoder (more info ...)shellcode-detect    
19283INDICATOR-SHELLCODE x86 OS agnostic stat-based context keyed encoder (more info ...)shellcode-detect    
19284INDICATOR-SHELLCODE x86 OS agnostic time-based context keyed encoder (more info ...)shellcode-detect    
19285INDICATOR-SHELLCODE x86 OS agnostic non-alpha/non-upper encoder (more info ...)shellcode-detect    
19286INDICATOR-SHELLCODE x86 OS agnostic unicode uppercase encoder (more info ...)shellcode-detect    
19287INDICATOR-SHELLCODE x86 OS agnostic unicode mixed encoder (more info ...)shellcode-detect    
19288INDICATOR-SHELLCODE x86 OS agnostic unicode tolower encoder (more info ...)shellcode-detect    
19297SERVER-OTHER sidename.js script injection (more info ...)attempted-user    URL
19298SERVER-OTHER cssminibar.js script injection (more info ...)attempted-user    URL
19299SERVER-OTHER banner.txt access - possible compromised multi-mesh injection server (more info ...)misc-activity    URL
19300FILE-OTHER probable multi-mesh injection attack (more info ...)attempted-user    URL
19301PROTOCOL-VOIP Expires header invalid characters detected (more info ...)attempted-dos    URL
19302PROTOCOL-VOIP Max-Forwards header invalid characters detected (more info ...)attempted-dos    URL
19309PUA-ADWARE hijacker starware videos outbound connection (more info ...)trojan-activity    URL
19310MALWARE-CNC Win.Trojan.Gen3 variant outbound connection (more info ...)trojan-activity    URL
19311PUA-ADWARE Keylogger aspy v2.12 runtime detection (more info ...)successful-recon-limited    URL
19312MALWARE-CNC Win.Trojan.Agent.aah variant outbound connection (more info ...)trojan-activity    URL
19313SERVER-OTHER Symantec Antivirus Intel Service DoS Attempt (more info ...)attempted-dos 2010-0111 45935  
19318MALWARE-OTHER Dos.Tool.LOIC UDP default U dun goofed attack (more info ...)attempted-dos    URL
19319MALWARE-OTHER Dos.Tool.LOIC TCP default U dun goofed attack (more info ...)attempted-dos    URL
19324MALWARE-OTHER Keylogger WL-Keylogger inbound connection (more info ...)trojan-activity    URL
19325MALWARE-OTHER Keylogger WL-Keylogger outbound connection (more info ...)trojan-activity    URL
19326PUA-ADWARE Classroom Spy Professional outbound connection - initial connection (more info ...)trojan-activity    URL
19327PUA-ADWARE Classroom Spy Professional outbound connection - initial connection (more info ...)trojan-activity    URL
19328MALWARE-CNC PointGuide variant outbound connection (more info ...)trojan-activity    URL
19329MALWARE-CNC Faceback.exe variant outbound connection (more info ...)trojan-activity    URL
19330MALWARE-CNC Adclicker Win.Trojan.Zlob.dnz variant outbound connection (more info ...)trojan-activity    URL
19331MALWARE-CNC Adclicker Win.Trojan.Zlob.dnz variant outbound connection (more info ...)trojan-activity    URL
19332MALWARE-CNC Win.Trojan.Clampi variant outbound connection (more info ...)trojan-activity    URL
19333PROTOCOL-VOIP Content-Type header invalid format too many slashes (more info ...)attempted-dos    URL
19334PROTOCOL-VOIP Content-Type header invalid format too many slashes (more info ...)attempted-dos    URL
19335PROTOCOL-VOIP Content-Type header invalid format missing slash (more info ...)attempted-dos    URL
19336PROTOCOL-VOIP Content-Type header invalid format missing slash (more info ...)attempted-dos    URL
19337PROTOCOL-VOIP invalid SIP-Version field (more info ...)attempted-dos    URL
19338PROTOCOL-VOIP invalid SIP-Version field (more info ...)attempted-dos    URL
19339MALWARE-CNC Win.Trojan.Dropper Win.Trojan.Agent.alda variant outbound connection (more info ...)trojan-activity    URL
19340MALWARE-CNC Win.Trojan.Fakeav TREAntivirus variant outbound connection (more info ...)trojan-activity    URL
19341MALWARE-CNC Worm MSIL.AiO.a variant outbound connection (more info ...)trojan-activity    URL
19342MALWARE-CNC Adware Professional variant outbound connection (more info ...)trojan-activity    URL
19343MALWARE-CNC Adware Pro variant outbound connection (more info ...)trojan-activity    URL
19344MALWARE-CNC AntiMalware Pro variant outbound connection (more info ...)trojan-activity    URL
19345MALWARE-CNC REAnti variant outbound connection (more info ...)trojan-activity    URL
19346MALWARE-CNC Additional Guard variant outbound connection (more info ...)trojan-activity    URL
19347MALWARE-CNC Win.Trojan.Poison.banr variant outbound connection (more info ...)trojan-activity    URL
19348MALWARE-CNC Win.Trojan.Downloader Win.Trojan.FraudLoad.emq variant outbound connection (more info ...)trojan-activity    URL
19349MALWARE-CNC Fakeav Vaccineclear variant outbound connection (more info ...)trojan-activity    URL
19351MALWARE-CNC Win.Trojan.Clicker Win.Trojan.Hatigh.C variant outbound connection (more info ...)trojan-activity    URL
19352MALWARE-CNC Win.Trojan.Small.D variant outbound connection (more info ...)trojan-activity    URL
19353MALWARE-CNC Win.Trojan.Banker.bkhu variant outbound connection (more info ...)trojan-activity    URL
19354MALWARE-BACKDOOR Win.Trojan.Agent.bhxn variant outbound connection (more info ...)trojan-activity    URL
19356MALWARE-CNC Win.Trojan.Fibbit.ax variant outbound connection (more info ...)trojan-activity    URL
19357MALWARE-CNC Win.Worm.Sohanad.ila variant outbound connection (more info ...)trojan-activity    URL
19358MALWARE-CNC Win.Trojan.XYTvn.A variant outbound connection (more info ...)trojan-activity    URL
19359MALWARE-CNC Win.Trojan.Dcbavict.A variant outbound connection (more info ...)trojan-activity    URL
19360MALWARE-CNC Win.Trojan.Dcbavict.A variant outbound connection (more info ...)trojan-activity    URL
19361MALWARE-CNC Win.Trojan.Dcbavict.A variant outbound connection (more info ...)trojan-activity    URL
19362MALWARE-OTHER generic IRC botnet connection (more info ...)trojan-activity    URL
19363MALWARE-CNC Win.Trojan.Dorkbot.B variant outbound connection (more info ...)trojan-activity    URL
19365PROTOCOL-VOIP Time Stop Header invalid value (more info ...)attempted-dos    URL
19366MALWARE-CNC Win.Trojan.HXWAN.A variant outbound connection (more info ...)trojan-activity    URL
19367MALWARE-CNC Win.Worm.Vaubeg.A variant outbound connection (more info ...)trojan-activity    URL
19368MALWARE-CNC Win.Trojan.Carberp.D variant outbound connection (more info ...)trojan-activity    URL
19369MALWARE-CNC Win.Trojan.Carberp.D variant outbound connection (more info ...)trojan-activity    URL
19370MALWARE-CNC Win.Trojan.Carberp.D variant outbound connection (more info ...)trojan-activity    URL
19371MALWARE-CNC Win.Trojan.Banker.IC variant outbound connection (more info ...)trojan-activity    URL
19373PROTOCOL-VOIP Origin header overflow attempt (more info ...)attempted-dos    URL
19374PROTOCOL-VOIP Origin header overflow attempt (more info ...)attempted-dos    URL
19375PROTOCOL-VOIP Origin header format string attempt (more info ...)attempted-dos    URL
19376PROTOCOL-VOIP Origin header format string attempt (more info ...)attempted-dos    URL
19377PROTOCOL-VOIP Origin invalid header (more info ...)attempted-dos    URL
19378PROTOCOL-VOIP Origin invalid header (more info ...)attempted-dos    URL
19379PROTOCOL-VOIP Session Name header overflow attempt (more info ...)attempted-dos    URL
19380PROTOCOL-VOIP Session Name header overflow attempt (more info ...)attempted-dos    URL
19381PROTOCOL-VOIP Session Name header format string attempt (more info ...)attempted-dos    URL
19382PROTOCOL-VOIP Session Name header format string attempt (more info ...)attempted-dos    URL
19383PROTOCOL-VOIP Session Name invalid header attempt (more info ...)attempted-dos    URL
19384PROTOCOL-VOIP Session Name invalid header attempt (more info ...)attempted-dos    URL
19385PROTOCOL-VOIP Media header description field overflow attempt (more info ...)attempted-dos    URL
19386PROTOCOL-VOIP Media header description field overflow attempt (more info ...)attempted-dos    URL
19387PROTOCOL-VOIP Media header description field format string attempt (more info ...)attempted-dos    URL
19388PROTOCOL-VOIP Media header description field format string attempt (more info ...)attempted-dos    URL
19391PUA-ADWARE Lost Door v3.0 (more info ...)trojan-activity    URL
19392MALWARE-OTHER Keylogger Monitor.win32.perflogger (more info ...)trojan-activity    URL
19393MALWARE-OTHER Keylogger Monitor.win32.perflogger (more info ...)trojan-activity    URL
19394MALWARE-CNC Win.Trojan.Tidserv variant outbound connection (more info ...)trojan-activity    URL
19395MALWARE-CNC Win.Trojan.Downloader Win.Trojan.Monkif.J inbound connection - dest ip infected (more info ...)trojan-activity    URL
19396MALWARE-CNC Win.Trojan.Beastdoor.b variant outbound connection (more info ...)trojan-activity    URL
19397MALWARE-CNC Win.Trojan.UltimateDefender.xv variant outbound connection (more info ...)trojan-activity    URL
19398MALWARE-CNC Win.Trojan.BAT.Shutdown.ef variant outbound connection (more info ...)trojan-activity    URL
19399MALWARE-CNC Email Worm Win32.Zhelatin.ch variant outbound connection (more info ...)trojan-activity    URL
19400MALWARE-CNC Win.Worm.Sddrop.D variant outbound connection (more info ...)trojan-activity    URL
19401MALWARE-CNC Win.Worm.Sddrop.D variant outbound connection (more info ...)trojan-activity    URL
19402MALWARE-CNC P2P Worm.Win32.Malas.r variant outbound connection (more info ...)trojan-activity    URL
19404MALWARE-CNC Win.Trojan.Ozdok variant outbound connection (more info ...)trojan-activity    URL
19416OS-MOBILE Apple iOS 4.3.3 jailbreak for iPad download attempt (more info ...)attempted-admin    URL
19417OS-MOBILE Apple iOS 4.3.3 jailbreak for iPad download attempt (more info ...)attempted-admin    URL
19418OS-MOBILE Apple iOS 4.3.3 jailbreak for iPhone download attempt (more info ...)attempted-admin    URL
19419OS-MOBILE Apple iOS 4.3.3 jailbreak for iPod download attempt (more info ...)attempted-admin    URL
19420FILE-MULTIMEDIA VideoLAN VLC Media Player Subtitle StripTags Heap Buffer Overflow (more info ...)attempted-user 2011-0522 46008  
19421FILE-MULTIMEDIA VideoLAN VLC Media Player Subtitle StripTags Heap Buffer Overflow (more info ...)attempted-user 2011-0522 46008  
19422FILE-IDENTIFY matroska file magic detected (more info ...)misc-activity    
19423FILE-IDENTIFY MKV file download request (more info ...)misc-activity    URL
19424FILE-IDENTIFY MKA file download request (more info ...)misc-activity    URL
19425FILE-IDENTIFY MKS file download request (more info ...)misc-activity    URL
19426MALWARE-CNC Win.Trojan.Downloader Win.Trojan.Crypter.i variant outbound connection (more info ...)trojan-activity    URL
19427MALWARE-CNC Win.Trojan.Agent.amjz variant outbound connection (more info ...)trojan-activity    URL
19428MALWARE-CNC Win.Trojan.Downloader Win.Trojan.Adload.BG variant outbound connection (more info ...)trojan-activity    URL
19429MALWARE-CNC Win.Trojan.Proxy Win.Trojan.Dosenjo.C variant outbound connection (more info ...)trojan-activity    URL
19433MALWARE-CNC Win.Trojan.Fujacks.aw variant outbound connection (more info ...)trojan-activity    URL
19434MALWARE-CNC User-Agent known malicious user-agent string ErrCode (more info ...)trojan-activity    URL
19435MALWARE-CNC Win.Trojan.Litmus.203 variant outbound connection (more info ...)trojan-activity    URL
19441SERVER-WEBAPP Oracle Virtual Server Agent command injection attempt (more info ...)attempted-admin 2010-3585 44031  URL
19451SERVER-OTHER Oracle VM server agent command injection (more info ...)attempted-user 2010-3582   
19452SERVER-OTHER Oracle VM server agent command injection (more info ...)attempted-user 2010-3582   
19453PUA-ADWARE Sus.BancDI-B trojan outbound connection (more info ...)trojan-activity    URL
19454MALWARE-CNC Win.Trojan.PWS.Win32.QQPass.IK variant outbound connection (more info ...)trojan-activity    URL
19455MALWARE-CNC Worm.Win32.AutoRun.aw variant outbound connection (more info ...)trojan-activity    URL
19456MALWARE-CNC Packed.Win32.Klone.bj variant outbound connection (more info ...)trojan-activity    URL
19457MALWARE-CNC Trojan-Clicker.Win32.Vesloruki.ajb variant outbound connection (more info ...)trojan-activity    URL
19477MALWARE-CNC Win.Trojan.Krap.af variant outbound connection (more info ...)trojan-activity    URL
19478MALWARE-CNC Worm.Win32.Taterf.B variant outbound connection (more info ...)trojan-activity    URL
19479MALWARE-CNC Net-Worm.Win32.Piloyd.m variant outbound connection - request html (more info ...)trojan-activity    URL
19480MALWARE-CNC User-Agent known malicious user-agent string STORMDDOS - Backdoor.Win32.Inject.ctt (more info ...)trojan-activity    URL
19481MALWARE-CNC Email-Worm.Win32.Agent.bx variant outbound connection (more info ...)trojan-activity    URL
19482MALWARE-CNC User-Agent known malicious user-agent string ErrorFix (more info ...)trojan-activity    URL
19483MALWARE-CNC Win.Trojan.Reload.fy variant outbound connection (more info ...)trojan-activity    URL
19484MALWARE-CNC Win.Trojan.Gh0st variant outbound connection (more info ...)trojan-activity    URL
19485MALWARE-CNC User-Agent known malicious user agent - RAV1 (more info ...)trojan-activity    URL
19486PUA-ADWARE W32.Fiala.A outbound connection (more info ...)trojan-activity    URL
19487MALWARE-CNC Win.Trojan.Agent.kih variant outbound connection (more info ...)trojan-activity    URL
19488MALWARE-CNC Worm.Win32.Failnum.A variant outbound connection (more info ...)trojan-activity    URL
19489MALWARE-CNC Win.Trojan.DeAlfa.fa variant outbound connection (more info ...)trojan-activity    URL
19490MALWARE-CNC Win.Trojan.Koceg.B variant outbound connection (more info ...)trojan-activity    URL
19491MALWARE-CNC Win.Trojan.Downloader Win.Trojan.Genome.vau variant outbound connection (more info ...)trojan-activity    URL
19492MALWARE-CNC Windows System Defender variant outbound connection (more info ...)trojan-activity    URL
19493MALWARE-CNC URI request for known malicious uri config.ini on 3322.org domain (more info ...)trojan-activity    URL
19494MALWARE-CNC Win.Trojan.Licum variant outbound connection (more info ...)trojan-activity    URL
19495MALWARE-CNC Win.Worm.Pilleuz variant outbound connection (more info ...)trojan-activity    URL
19551MALWARE-OTHER self-signed SSL certificate with default Internet Widgits Pty Ltd organization name (more info ...)policy-violation    URL
19554MALWARE-CNC Win.Trojan.Fakeav Antivirus Xp Pro variant outbound connection (more info ...)trojan-activity    URL
19555MALWARE-CNC Win.Trojan.Small variant outbound connection (more info ...)trojan-activity    URL
19556MALWARE-CNC Win.Trojan.Homa variant outbound connection (more info ...)trojan-activity    URL
19557MALWARE-CNC Win.Trojan.Shark.ag variant outbound connection (more info ...)trojan-activity    URL
19558SERVER-WEBAPP JBoss expression language actionOutcome remote code execution (more info ...)attempted-admin 2010-1871 41994  
19566PUA-ADWARE W32.Ackantta.C.mm mass-mailer outbound connection (more info ...)trojan-activity    URL
19567PUA-ADWARE W32.Ackantta.C.mm mass-mailer outbound connection (more info ...)trojan-activity    URL
19568MALWARE-CNC Trojan-Spy.Win32.PerfectKeylogger variant outbound connection (more info ...)trojan-activity    URL
19569MALWARE-CNC Win.Trojan.Perkesh variant outbound connection (more info ...)trojan-activity    URL
19570MALWARE-CNC User-Agent known malicious user agent - ie 11.0 sp6 (more info ...)trojan-activity    URL
19571PUA-ADWARE Antivirus Agent Pro outbound connection (more info ...)trojan-activity    URL
19572MALWARE-CNC Win.Trojan.FFSearch variant outbound connection (more info ...)trojan-activity    URL
19573MALWARE-CNC Win.Worm.Chiviper.C variant outbound connection (more info ...)trojan-activity    URL
19574MALWARE-CNC Win.Worm.Chiviper.C variant outbound connection (more info ...)trojan-activity    URL
19575MALWARE-CNC Win.Worm.Emold.U variant outbound connection (more info ...)trojan-activity    URL
19576PUA-ADWARE Antivirus Pro 2010 outbound connection (more info ...)trojan-activity    URL
19577MALWARE-CNC Win.Trojan.Dropper Win.Trojan.Dogrobot.E variant outbound connection (more info ...)trojan-activity    URL
19578PUA-ADWARE Personal Guard 2009 outbound connection (more info ...)trojan-activity    URL
19579MALWARE-CNC Win.Trojan.Potao.A variant outbound connection (more info ...)trojan-activity    URL
19580MALWARE-CNC Win.Worm.Basun.wsc inbound connection (more info ...)trojan-activity    URL
19581MALWARE-CNC Win.Trojan.Downloader.Win32.Apher.gpd variant outbound connection (more info ...)trojan-activity    URL
19582MALWARE-CNC Win.Trojan.Downloader.Win32.Apher.gpd variant outbound connection (more info ...)trojan-activity    URL
19583MALWARE-CNC Win.Trojan.Bumat.rts variant outbound connection (more info ...)trojan-activity    URL
19584MALWARE-CNC Win.Worm.Dref.C variant outbound connection (more info ...)trojan-activity    URL
19585MALWARE-CNC Win.Worm.Dref.C variant outbound connection - notification (more info ...)trojan-activity    URL
19586MALWARE-CNC Win.Trojan.Clicker Win.Trojan.Agent.dlg variant outbound connection (more info ...)trojan-activity    URL
19587MALWARE-CNC Win.Trojan.Sereki.B variant outbound connection (more info ...)trojan-activity    URL
19588MALWARE-CNC Win.Trojan.Sereki.B successful connection (more info ...)trojan-activity    URL
19589MALWARE-CNC User-Agent known malicious User-Agent string MacProtector (more info ...)trojan-activity    URL
19590MALWARE-CNC Win.Trojan.Savnut.B variant outbound connection (more info ...)trojan-activity    URL
19591MALWARE-CNC Win.Trojan.Powp.pyv variant outbound connection (more info ...)trojan-activity    URL
19592MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)misc-activity    URL
19594PUA-ADWARE Win32.Fruspam outbound connection (more info ...)misc-activity    URL
19595MALWARE-OTHER known malicious email string - You have received a Hallmark E-Card (more info ...)misc-activity    URL
19596MALWARE-CNC Poison Ivy variant outbound connection (more info ...)misc-activity    URL
19597MALWARE-CNC Win.Trojan.Agent.cws variant outbound connection (more info ...)misc-activity    URL
19598PUA-ADWARE Infostealer.Gampass outbound connection (more info ...)misc-activity    URL
19605SERVER-ORACLE Glass Fish Server malformed username cross site scripting attempt (more info ...)attempted-user 2011-2260   
19608MALWARE-CNC Win.Trojan.Wisscmd.A variant outbound connection (more info ...)trojan-activity    URL
19611MALWARE-CNC User-Agent known malicious User-Agent string INet - Win32.Virus.Jusabli.A (more info ...)trojan-activity    URL
19612MALWARE-CNC Win.Trojan.Downloader.Win32.Banload.bvk variant outbound connection (more info ...)trojan-activity    URL
19613MALWARE-CNC Rogue Software Registry Cleaner Pro variant outbound connection (more info ...)trojan-activity    URL
19614MALWARE-CNC Win.Trojan.IRCBot.kkr variant outbound connection (more info ...)trojan-activity    URL
19615MALWARE-CNC Win.Trojan.IRCBot.kkr variant outbound connection (more info ...)trojan-activity    URL
19616MALWARE-CNC Win.Trojan.Banker.Win32.Banbra.mcq variant outbound connection (more info ...)trojan-activity    URL
19618FILE-OTHER Multiple products request for dwmapi.dll over SMB attempt (more info ...)attempted-user 2017-17069 62836  URL
19621FILE-MULTIMEDIA MultiMedia Soft Components AdjMmsEng.dll PLS file processing buffer overflow attempt (more info ...)attempted-user 2009-5109 33589  
19622MALWARE-CNC URI request for known malicious URI - pte.aspx?ver= (more info ...)trojan-activity    URL
19623MALWARE-CNC URI request for known malicious URI - vic.aspx?ver= (more info ...)trojan-activity    URL
19626MALWARE-CNC URI request for known malicious URI - /setup_b.asp?prj= (more info ...)trojan-activity    URL
19627MALWARE-CNC URI request for known malicious URI - /r_autoidcnt.asp?mer_seq= (more info ...)trojan-activity    URL
19631MALWARE-CNC URI request for known malicious URI - AnSSip= (more info ...)trojan-activity    URL
19635MALWARE-CNC URI request for known malicious URI - /app/?prj= (more info ...)trojan-activity    URL
19636MALWARE-CNC URI request for known malicious URI - /blog/images/3521.jpg?v (more info ...)trojan-activity    URL
19637MALWARE-CNC URI request for known malicious URI - /install.asp?mac= (more info ...)trojan-activity    URL
19638MALWARE-CNC URI request for known malicious URI - /kx4.txt (more info ...)trojan-activity    URL
19645SERVER-WEBAPP cross-site scripting attempt via form data attempt (more info ...)attempted-user 2013-2618   
19646FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
19647FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
19648FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
19652MALWARE-CNC Teevsock C variant outbound connection (more info ...)trojan-activity    URL
19654MALWARE-CNC Trojan-Spy.Win32.Zbot.wti variant outbound connection (more info ...)trojan-activity    URL
19655MALWARE-CNC Trojan-Dropper.Agent.IK variant outbound connection (more info ...)trojan-activity    URL
19656MALWARE-CNC Trojan-Dropper.Win32.Peace.lh variant outbound connection (more info ...)trojan-activity    URL
19657MALWARE-CNC Win.Trojan.FakeAV variant traffic (more info ...)trojan-activity    URL
19658MALWARE-CNC Win.Trojan.MCnovogic.A variant outbound connection (more info ...)trojan-activity    URL
19659MALWARE-CNC Win.Trojan.Soleseq.A variant outbound connection (more info ...)trojan-activity    URL
19660MALWARE-CNC Win.Trojan.Riern.K variant outbound connection (more info ...)trojan-activity    URL
19695MALWARE-CNC Win.Trojan.Downloader.Win32.VB.nec variant outbound connection (more info ...)trojan-activity    URL
19696MALWARE-CNC Win.Trojan.SdBot.nng inbound connection (more info ...)trojan-activity    URL
19697MALWARE-CNC Win.Trojan.Spy.Win32.VB.btm variant outbound connection (more info ...)trojan-activity    URL
19698MALWARE-CNC Win.Trojan.Prosti.AG variant outbound connection (more info ...)trojan-activity    URL
19699MALWARE-CNC TrojanDownloader.Win32.Korklic.A variant outbound connection (more info ...)trojan-activity    URL
19700MALWARE-CNC Win.Trojan.Agent.tnr variant outbound connection (more info ...)trojan-activity    URL
19701MALWARE-CNC Win.Trojan.Hassar.A variant outbound connection (more info ...)trojan-activity    URL
19702MALWARE-CNC Win.Trojan.Zboter.E variant outbound connection (more info ...)trojan-activity    URL
19703MALWARE-CNC Win.Worm.Dusta.br outbound connnection (more info ...)trojan-activity    URL
19704MALWARE-CNC Win.Trojan.Agent.grdm variant outbound connection (more info ...)trojan-activity    URL
19705MALWARE-CNC Win.Trojan.Agent.grdm variant outbound connection (more info ...)trojan-activity    URL
19706MALWARE-CNC Win.Trojan.Agent.cer variant outbound connection (more info ...)trojan-activity    URL
19711MALWARE-CNC Win.Trojan.Jorik variant outbound connection (more info ...)trojan-activity    URL
19712MALWARE-CNC Win.Trojan.Downloader variant outbound connection (more info ...)trojan-activity    URL
19715MALWARE-CNC Win.Trojan.URLZone variant outbound connection (more info ...)trojan-activity    URL
19716MALWARE-CNC TrojanSpy.Win32.Banker.OO variant outbound connection (more info ...)trojan-activity    URL
19717PUA-ADWARE Virus.Win32.Virut.ce outbound connection (more info ...)trojan-activity    URL
19718MALWARE-CNC Trojan-Downloader.Win32.Agent.bkap variant outbound connection (more info ...)trojan-activity    URL
19719MALWARE-CNC Email-Worm.Win32.Bagle.of variant outbound connection (more info ...)trojan-activity    URL
19720MALWARE-CNC Trojan-Downloader.Win32.Onestage.ws variant outbound connection (more info ...)trojan-activity    URL
19721MALWARE-CNC Win.Trojan.IRCBot.mlh variant outbound connection (more info ...)trojan-activity    URL
19722MALWARE-CNC Win.Trojan.Poshtroper variant outbound connection (more info ...)trojan-activity    URL
19723MALWARE-CNC Win.Trojan.Pherbot variant outbound connection (more info ...)trojan-activity    URL
19724MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
19725MALWARE-CNC Win.Trojan.Poison variant outbound connection (more info ...)trojan-activity    URL
19726MALWARE-CNC Win.Trojan.Poison variant outbound connection (more info ...)trojan-activity    URL
19727MALWARE-CNC Win.Trojan.Bancos.DI variant outbound connection (more info ...)trojan-activity    URL
19728MALWARE-CNC Win.Trojan.Yayih variant outbound connection (more info ...)trojan-activity    URL
19729MALWARE-CNC Win.Trojan.Yayih variant outbound connection (more info ...)trojan-activity    URL
19730MALWARE-CNC Win.Trojan.KukuBot variant outbound connection (more info ...)trojan-activity    URL
19731MALWARE-CNC Win.Trojan.Darkwebot variant outbound connection (more info ...)trojan-activity    URL
19732MALWARE-CNC Win.Trojan.Idicaf variant outbound connection (more info ...)trojan-activity    URL
19733MALWARE-CNC Win.Trojan.Jorik.BRU variant outbound connection (more info ...)trojan-activity    URL
19739MALWARE-CNC Win.Trojan.Apptom variant outbound connection (more info ...)trojan-activity    URL
19740MALWARE-CNC Worm.Win32.AutoRun.aczu variant outbound connection (more info ...)trojan-activity    URL
19742MALWARE-CNC Win.Trojan.Agent.atff variant outbound connection (more info ...)trojan-activity    URL
19743MALWARE-CNC Win.Trojan.Hupigon.eqlo variant outbound connection (more info ...)trojan-activity    URL
19744MALWARE-CNC Worm.Win32.Deecee.a variant outbound connection (more info ...)misc-activity    URL
19745MALWARE-CNC Win.Trojan.FraudLoad.dyl variant outbound connection (more info ...)trojan-activity    URL
19746MALWARE-CNC Win.Trojan.Agent.biiw variant outbound connection (more info ...)trojan-activity    URL
19748MALWARE-CNC Win.Trojan.Crypt.ULPM.Gen IRC variant outbound connection (more info ...)trojan-activity    URL
19749MALWARE-CNC Win.Trojan.Agent.chgp variant outbound connection (more info ...)trojan-activity    URL
19750MALWARE-CNC PWS.Win32.Zbot.PJ variant outbound connection (more info ...)trojan-activity    URL
19751MALWARE-CNC Worm.Win32.Sohanad.bm variant outbound connection (more info ...)trojan-activity    URL
19752MALWARE-CNC Win.Trojan.Downloader variant outbound connection (more info ...)trojan-activity    URL
19753MALWARE-CNC Win.Trojan.TrojanSpy.Win32.Zbot.gen.C variant outbound connection (more info ...)trojan-activity    URL
19754MALWARE-CNC Win.Trojan.Downloader.Delf.RGL variant outbound connection (more info ...)trojan-activity    URL
19755MALWARE-CNC Win.Trojan.Alphabet variant outbound connection (more info ...)trojan-activity    URL
19757MALWARE-CNC Win.Trojan.Agent.bqlu variant outbound connection (more info ...)trojan-activity    URL
19758MALWARE-CNC Win.Trojan.Small.yw variant outbound connection (more info ...)trojan-activity    URL
19759MALWARE-CNC Trojan-PSW.Win32.FireThief.h variant outbound connection (more info ...)trojan-activity    URL
19760MALWARE-CNC Win.Trojan.Arsinfoder variant outbound connection (more info ...)trojan-activity    URL
19762MALWARE-CNC Win.Trojan.RDPdoor.AE variant outbound connection (more info ...)trojan-activity    URL
19763MALWARE-CNC Win.Trojan.RDPdoor.AE variant outbound connection (more info ...)trojan-activity    URL
19764MALWARE-CNC Win.Trojan.RDPdoor.AE variant outbound connection (more info ...)trojan-activity    URL
19765MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
19766MALWARE-CNC Win.Worm.Autorun variant outbound connection (more info ...)trojan-activity    URL
19767MALWARE-CNC Win.Trojan.Msposer.A variant outbound connection (more info ...)trojan-activity    URL
19769MALWARE-CNC Win.Trojan.Yoddos outbound indicator (more info ...)trojan-activity    URL
19770MALWARE-CNC Win.Trojan.Yoddos variant outbound connection (more info ...)trojan-activity    URL
19771MALWARE-CNC Win.Trojan.Yoddos variant outbound connection (more info ...)trojan-activity    URL
19772MALWARE-CNC Virus.Win32.Parite.B variant outbound connection (more info ...)trojan-activity    URL
19773MALWARE-CNC Virus.Win32.Parite.B variant outbound connection (more info ...)trojan-activity    URL
19774MALWARE-CNC Gen-Trojan.Heur variant outbound connection (more info ...)trojan-activity    URL
19775PUA-ADWARE PWS.Win32.Ldpinch.gen outbound connection (more info ...)trojan-activity    URL
19776MALWARE-CNC Win.Trojan.Agent2.guy dropper variant outbound connection (more info ...)trojan-activity    URL
19777PUA-ADWARE Fast Antivirus 2009 outbound connection (more info ...)trojan-activity    URL
19781MALWARE-CNC Trojan-Dropper.Win32.Agent.aqpn variant outbound connection (more info ...)trojan-activity    URL
19782MALWARE-CNC Win.Trojan.AVKill.bc variant outbound connection (more info ...)trojan-activity    URL
19783MALWARE-CNC Win.Trojan.Banload.agcw variant outbound connection (more info ...)trojan-activity    URL
19784MALWARE-CNC Worm.Win32.AutoRun.sde variant outbound connection (more info ...)trojan-activity    URL
19785MALWARE-CNC Win.Trojan.Downloader.Win32.Malushka.T variant outbound connection (more info ...)trojan-activity    URL
19787MALWARE-CNC Exploit-PDF.t variant outbound connection (more info ...)trojan-activity    URL
19788MALWARE-CNC Win.Trojan.Downloader.Win32.VB.pnc variant outbound connection (more info ...)trojan-activity    URL
19789MALWARE-CNC P2P Worm Win.Trojan.SpyBot.pgh variant outbound connection (more info ...)trojan-activity    URL
19790MALWARE-CNC P2P Worm Win.Trojan.SpyBot.pgh variant outbound connection (more info ...)trojan-activity    URL
19791MALWARE-CNC Trojan-Dropper.Win32.Small.awa variant outbound connection (more info ...)trojan-activity    URL
19792MALWARE-CNC Win.Trojan.Downloader Win.Trojan.Caxnet.A variant outbound connection (more info ...)trojan-activity    URL
19793MALWARE-CNC Win.Trojan.Downloader Win.Trojan.SillyFDC-DS variant outbound connection (more info ...)trojan-activity    URL
19794MALWARE-CNC Win.Trojan.Fnumbot variant outbound connection (more info ...)trojan-activity    URL
19795MALWARE-CNC Win.Trojan.FakeAV NoAdware variant outbound connection (more info ...)trojan-activity    URL
19796MALWARE-CNC Win.Trojan.DL.CashnJoy.A variant outbound connection (more info ...)trojan-activity    URL
19797MALWARE-CNC Safety Center variant outbound connection (more info ...)trojan-activity    URL
19798MALWARE-CNC Win.Trojan.Agent2.kxu variant outbound connection (more info ...)trojan-activity    URL
19799MALWARE-CNC PWS.Win32.Zbot.gen.Q variant outbound connection (more info ...)trojan-activity    URL
19800MALWARE-CNC Win.Trojan.Pher.ij variant outbound connection (more info ...)trojan-activity    URL
19801MALWARE-CNC Win.Trojan.Tracur variant outbound connection (more info ...)trojan-activity    URL
19802MALWARE-CNC Win.Trojan.Wixud.B variant outbound connection (more info ...)trojan-activity    URL
19803MALWARE-CNC Win.Trojan.Renos.FH variant outbound connection (more info ...)trojan-activity    URL
19804MALWARE-CNC Win.Trojan.VB.ktq variant outbound connection (more info ...)trojan-activity    URL
19805MALWARE-CNC Win.Trojan.Smser.cx variant outbound connection (more info ...)trojan-activity    URL
19819MALWARE-CNC Win.Trojan.Ertfor.A variant outbound connection (more info ...)trojan-activity    URL
19820MALWARE-CNC Win.Trojan.Ertfor.A variant outbound connection (more info ...)trojan-activity    URL
19821MALWARE-CNC Worm.Win32.Bagle.gen.C variant outbound connection (more info ...)trojan-activity    URL
19822MALWARE-CNC Win.Trojan.Banload.HH variant outbound connection (more info ...)trojan-activity    URL
19823PUA-ADWARE Downloader.Banload.AKBB outbound connection (more info ...)trojan-activity    URL
19824MALWARE-CNC Gen-Trojan.Heur variant outbound connection (more info ...)trojan-activity    URL
19827PUA-ADWARE PWS-QQGame outbound connection (more info ...)trojan-activity    URL
19828MALWARE-CNC Win.Trojan.SpyAgent.B variant outbound connection (more info ...)trojan-activity    URL
19829MALWARE-CNC Win.Trojan.Rbot.gen variant outbound connection (more info ...)trojan-activity    URL
19830MALWARE-CNC Win.Trojan.Poebot.BP variant outbound connection (more info ...)trojan-activity    URL
19831MALWARE-CNC Win.Trojan.Zbot.SO variant outbound connection (more info ...)trojan-activity    URL
19832MALWARE-CNC Win.Trojan.Veslorn.gen.A variant outbound connection (more info ...)trojan-activity    URL
19833MALWARE-CNC Win.Trojan.Banload.bda variant outbound connection (more info ...)trojan-activity    URL
19834MALWARE-CNC Win.Trojan.ZBot.RD variant outbound connection (more info ...)trojan-activity    URL
19835PUA-ADWARE Delphi-Piette Windows (more info ...)misc-activity    URL
19836MALWARE-CNC Spy-Net 0.7 runtime (more info ...)trojan-activity    URL
19837PUA-ADWARE Spyware Guard 2008 outbound connection (more info ...)misc-activity    URL
19838PUA-ADWARE Spyware Guard 2008 outbound connection (more info ...)misc-activity    URL
19839PUA-ADWARE Antivirus XP 2008 runtime detection (more info ...)misc-activity    URL
19840PUA-ADWARE XP Antispyware 2009 outbound connection (more info ...)trojan-activity    URL
19842PUA-ADWARE Windows Antivirus 2008 (more info ...)trojan-activity    URL
19843PUA-ADWARE Windows Antivirus 2008 (more info ...)trojan-activity    URL
19848PUA-ADWARE Adware.Virtumonde runtime detection (more info ...)trojan-activity    URL
19849PUA-ADWARE Adware.Virtumonde runtime detection (more info ...)trojan-activity    URL
19850MALWARE-CNC Worm.Win32.AutoRun.qgg variant outbound connection (more info ...)trojan-activity    URL
19851MALWARE-CNC Worm.Win32.AutoRun.qgg variant outbound connection (more info ...)trojan-activity    URL
19852MALWARE-CNC Win.Trojan.Downloader.Win32.Delf.tbv variant outbound connection (more info ...)trojan-activity    URL
19853PUA-ADWARE Wowpa KI outbound connection (more info ...)trojan-activity    URL
19856MALWARE-CNC Packed.Win32.Krap.i variant outbound connection (more info ...)trojan-activity    URL
19857MALWARE-CNC Win.Trojan.Hupigon.hhbd variant outbound connection - Windows (more info ...)trojan-activity    URL
19858MALWARE-CNC Win.Trojan.Hupigon.hhbd variant outbound connection - non-Windows (more info ...)trojan-activity    URL
19859PUA-ADWARE XP Deluxe Protector outbound connection (more info ...)trojan-activity    URL
19860PUA-ADWARE Trust Warrior outbound connection (more info ...)trojan-activity    URL
19861MALWARE-CNC Win.Trojan.Agent.cqcv variant outbound connection (more info ...)trojan-activity    URL
19862MALWARE-CNC Win.Trojan.Scar.iej variant outbound connection (more info ...)trojan-activity    URL
19863MALWARE-CNC Win.Trojan.Httpbot.yi variant outbound connection (more info ...)trojan-activity    URL
19864MALWARE-CNC Win.Trojan.Nvbpass variant outbound connection (more info ...)trojan-activity    URL
19865MALWARE-CNC Win.Trojan.Arhost.D variant outbound connection (more info ...)trojan-activity    URL
19868INDICATOR-OBFUSCATION hidden 1x1 div tag - potential malware obfuscation (more info ...)misc-activity    URL
19870MALWARE-TOOLS Anonymous Perl RefRef DoS tool (more info ...)attempted-dos    URL
19882MALWARE-CNC URI request for known malicious URI - /160.rar - Win32/Morto.A (more info ...)trojan-activity    URL
19883FILE-MULTIMEDIA VideoLAN VLC Media Player libdirectx_plugin.dll AMV parsing buffer overflow attempt (more info ...)attempted-user 2010-3275   
19884INDICATOR-OBFUSCATION String.fromCharCode with multiple encoding types detected (more info ...)policy-violation    URL
19889INDICATOR-OBFUSCATION base64-encoded data object found (more info ...)policy-violation    URL
19895MALWARE-CNC Win.Trojan.Delf.jwh variant outbound connection (more info ...)trojan-activity    URL
19896PUA-ADWARE Adware.Win32.Frosty Goes Skiing Screen Saver 2.2 Install Detection (more info ...)misc-activity    URL
19897PUA-TOOLBARS Adware.Win32.Frosty Goes Skiing Screen Saver 2.2 Runtime Detection (more info ...)misc-activity    URL
19898MALWARE-CNC Cinmus Variant variant outbound connection (more info ...)trojan-activity    URL
19899MALWARE-OTHER Tong Keylogger outbound connectiooutbound connection (more info ...)trojan-activity    URL
19900MALWARE-OTHER Tong Keylogger outbound connection (more info ...)trojan-activity    URL
19901MALWARE-OTHER Tong Keylogger outbound connection (more info ...)trojan-activity    URL
19902PUA-ADWARE Targetedbanner.biz Adrotator outbound connection (more info ...)misc-activity    URL
19903PUA-ADWARE Win32.Agent.vvm outbound connection (more info ...)misc-activity    URL
19904PUA-ADWARE WinReanimator outbound connection (more info ...)misc-activity    URL
19905MALWARE-CNC Win.Trojan.Small.jog variant outbound connection (more info ...)trojan-activity    URL
19906PUA-TOOLBARS 6SQ Toolbar runtime detection (more info ...)misc-activity    URL
19912MALWARE-CNC Win.Trojan.DelfInject.gen!X variant outbound connection (more info ...)trojan-activity    URL
19914MALWARE-CNC Win.Trojan.Quivoe.A variant outbound connection (more info ...)trojan-activity    URL
19915MALWARE-CNC Win.Trojan.Gnutler.apd variant outbound connection (more info ...)trojan-activity    URL
19916MALWARE-CNC Win.Trojan.Bancos.ACB variant outbound connection (more info ...)trojan-activity    URL
19917MALWARE-CNC Win.Trojan.Sogu.A variant outbound connection (more info ...)trojan-activity    URL
19918MALWARE-CNC Win.Worm.Ganelp.B variant outbound connection (more info ...)trojan-activity    URL
19919MALWARE-CNC Win.Trojan.Murcy.A variant outbound connection (more info ...)trojan-activity    URL
19920MALWARE-CNC Win.Trojan.Reppserv.A outbond connection (more info ...)trojan-activity    URL
19921MALWARE-CNC Win.Trojan.Puprlehzae.A variant outbound connection (more info ...)trojan-activity    URL
19922MALWARE-CNC Win.Trojan.Shiz.ivr variant outbound connection (more info ...)trojan-activity    URL
19923MALWARE-CNC Win.Trojan.Venik.B variant outbound connection (more info ...)trojan-activity    URL
19924MALWARE-CNC Win.Trojan.Spidern.A variant outbound connection (more info ...)trojan-activity    URL
19927MALWARE-BACKDOOR BRX Rat 0.02 inbound connection (more info ...)trojan-activity    URL
19928MALWARE-BACKDOOR BRX Rat 0.02 inbound connection (more info ...)trojan-activity    URL
19929MALWARE-BACKDOOR BRX Rat 0.02 inbound connection (more info ...)trojan-activity    URL
19930MALWARE-BACKDOOR BRX Rat 0.02 inbound connection (more info ...)trojan-activity    URL
19931MALWARE-CNC Win.Trojan.Lineage.Gen.Pac.3 variant outbound connection (more info ...)trojan-activity    URL
19933INDICATOR-SCAN DirBuster brute forcing tool detected (more info ...)web-application-attack    URL
19934MALWARE-CNC User-Agent known malicious user-agent string MYURL (more info ...)trojan-activity    URL
19935MALWARE-CNC Win.Trojan.Dropper Win.Trojan.Delf.aba variant outbound connection (more info ...)trojan-activity    URL
19936MALWARE-CNC Win.Trojan.Dropper Win.Trojan.Delf.aba variant outbound connection (more info ...)trojan-activity    URL
19939PUA-ADWARE WeatherStudio outbound connection (more info ...)misc-activity    URL
19940MALWARE-CNC Trojan-Dropper.IRC.TKB variant outbound connection - dir4you (more info ...)trojan-activity    URL
19941MALWARE-CNC TrojanSpy Win.Trojan.Zbot.Gen variant outbound connection (more info ...)trojan-activity    URL
19942MALWARE-CNC TrojanSpy Win.Trojan.Zbot.Gen variant outbound connection (more info ...)trojan-activity    URL
19944MALWARE-CNC Win.Trojan.Downloader.Win32.Banload.ykl variant outbound connection (more info ...)trojan-activity    URL
19945MALWARE-CNC Win.Trojan.Downloader.Win32.Agent.amwd variant outbound connection (more info ...)trojan-activity    URL
19946MALWARE-CNC Win.Trojan.Downloader.Win32.Agent.amwd variant outbound connection (more info ...)trojan-activity    URL
19947MALWARE-CNC Win.Trojan.Agent.amwd variant outbound connection (more info ...)trojan-activity    URL
19948MALWARE-CNC Win.Trojan.Agent.asjk variant outbound connection (more info ...)trojan-activity    URL
19949MALWARE-CNC Win.Trojan.Agent.asjk variant outbound connection (more info ...)trojan-activity    URL
19950MALWARE-CNC Win.Trojan.Defsel inbound connection (more info ...)trojan-activity    URL
19951MALWARE-CNC Win.Trojan.Defsel variant outbound connection (more info ...)trojan-activity    URL
19952MALWARE-CNC Biodox inbound connection (more info ...)trojan-activity    URL
19953MALWARE-CNC Biodox variant outbound connection (more info ...)trojan-activity    URL
19954MALWARE-CNC Hack Style RAT variant outbound connection (more info ...)trojan-activity    URL
19955MALWARE-CNC PaiN RAT 0.1 variant outbound connection (more info ...)trojan-activity    URL
19957MALWARE-CNC Arabian-Attacker 1.1.0 variant outbound connection (more info ...)trojan-activity    URL
19958MALWARE-CNC Win.Trojan.Agent.aulk variant outbound connection (more info ...)trojan-activity    URL
19959MALWARE-CNC Win.Trojan.Agent.aulk variant outbound connection (more info ...)trojan-activity    URL
19960MALWARE-CNC Win.Trojan.Agent.aulk variant outbound connection (more info ...)trojan-activity    URL
19961MALWARE-CNC Fouad 1.0 variant outbound connection (more info ...)trojan-activity    URL
19962MALWARE-CNC Email-Worm.CryptBox-A variant outbound connection (more info ...)trojan-activity    URL
19963MALWARE-CNC Win.Trojan.Downloader.Win32.Banload.aajs variant outbound connection (more info ...)trojan-activity    URL
19964MALWARE-CNC Win.Trojan.Sality variant outbound connection (more info ...)trojan-activity    URL
19965MALWARE-CNC Win.Trojan.Downloader.Win32.Agent.avzz variant outbound connection (more info ...)trojan-activity    URL
19966MALWARE-CNC Octopus 0.1 inbound connection (more info ...)trojan-activity    URL
19967MALWARE-CNC Trojan-PSW.Win32.Papras.dm variant outbound connection (more info ...)trojan-activity    URL
19968MALWARE-CNC Win.Trojan.PSW.QQPass.amx variant outbound connection (more info ...)trojan-activity    URL
19969MALWARE-CNC Win.Trojan.Crypt.CY variant outbound connection (more info ...)trojan-activity    URL
19970MALWARE-CNC Win.Trojan.Smalltroj.MHYR variant outbound connection (more info ...)trojan-activity    URL
19971MALWARE-CNC Win.Trojan.Mudrop.lj variant outbound connection (more info ...)misc-activity    URL
19973MALWARE-CNC Worm.Win.Trojan.Nebuler.D variant outbound connection (more info ...)trojan-activity    URL
19974MALWARE-CNC Win.Trojan.Small.bwj variant outbound connection (more info ...)trojan-activity    URL
19975MALWARE-CNC Win.Trojan.Crypt.vb variant outbound connection (more info ...)trojan-activity    URL
19977MALWARE-CNC Win.Trojan.LooksLike.Zaplot variant outbound connection (more info ...)trojan-activity    URL
19978MALWARE-CNC Viking.JB Worm runtime traffic detected (more info ...)trojan-activity    URL
19979MALWARE-CNC IRCBot runtime traffic detected (more info ...)trojan-activity    URL
19980MALWARE-CNC IRCBot runtime traffic detected (more info ...)trojan-activity    URL
19981MALWARE-CNC Win.Trojan.Micstus.A runtime traffic detected (more info ...)trojan-activity    URL
19982MALWARE-CNC Win.Trojan.Agent.wwe variant outbound connection (more info ...)trojan-activity    URL
19983MALWARE-CNC Win.Trojan.Kolabc.fic variant outbound connection (more info ...)trojan-activity    URL
19984PUA-ADWARE Antivirus 2010 outbound connection (more info ...)trojan-activity    URL
19985PUA-ADWARE AntivirusPC2009 runtime traffic detected (more info ...)trojan-activity    URL
19986PUA-ADWARE AntivirusPC2009 install-time traffic detected (more info ...)trojan-activity    URL
19987PUA-ADWARE PCLiveGuard outbound connection (more info ...)trojan-activity    URL
19988MALWARE-CNC Asprox variant outbound connection (more info ...)trojan-activity    URL
19989PUA-ADWARE Total Protect 2009 outbound connection (more info ...)trojan-activity    URL
19990PUA-ADWARE Total Protect 2009 outbound connection (more info ...)trojan-activity    URL
19991MALWARE-CNC Win.Trojan.Zbot.PG runtime traffic detected (more info ...)trojan-activity    URL
19992MALWARE-CNC Trojan-Dropper.Win32.Farfli.A runtime traffic detected (more info ...)trojan-activity    URL
19993MALWARE-CNC Win32 Poebot runtime traffic detected (more info ...)trojan-activity    URL
19994PUA-ADWARE Antivirus 360 outbound connection (more info ...)trojan-activity    URL
19995MALWARE-CNC Waledac variant outbound connection (more info ...)trojan-activity    URL
19996MALWARE-CNC Worm Brontok.C variant outbound connection (more info ...)trojan-activity    URL
19997MALWARE-CNC Win.Trojan.PSW.Win32.QQPass.gam variant outbound connection (more info ...)trojan-activity    URL
19999PUA-ADWARE ThreatNuker outbound connection (more info ...)trojan-activity    URL
20001MALWARE-CNC Allaple.e variant outbound connection (more info ...)trojan-activity    URL
20002MALWARE-CNC Allaple.e variant outbound connection (more info ...)trojan-activity    URL
20003MALWARE-CNC Win.Trojan.Spy Pilonoc runtime traffic detected (more info ...)trojan-activity    URL
20004MALWARE-CNC Win.Trojan.Spy Pilonoc install-time traffic detected (more info ...)trojan-activity    URL
20005MALWARE-CNC Win32 Lecna.cr runtime traffic detected (more info ...)trojan-activity    URL
20006MALWARE-CNC Worm Plurp.A runtime traffic detected (more info ...)trojan-activity    URL
20007PUA-ADWARE Cinmus.asaq outbound connection (more info ...)trojan-activity    URL
20008MALWARE-CNC Malware PDFMarca.A runtime traffic detected (more info ...)trojan-activity    URL
20009MALWARE-CNC User-Agent known malicious User-Agent string Baby Remote - Win32/Babmote.A (more info ...)trojan-activity    URL
20010MALWARE-CNC Win32/Babmote.A runtime TCP traffic detected (more info ...)trojan-activity    URL
20011MALWARE-CNC Briewots.A runtime traffic detected (more info ...)trojan-activity    URL
20012MALWARE-CNC User-Agent known malicious user-agent string feranet/0.4 - Win32/Ferabsa.A (more info ...)trojan-activity    URL
20013SERVER-WEBAPP HP OpenView Network Node Manager webappmon.exe host header buffer overflow attempt (more info ...)attempted-admin 2009-4177 37341  URL
20014MALWARE-CNC Kaju variant outbound connection - confirmation (more info ...)trojan-activity    URL
20015MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
20016MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
20017MALWARE-CNC Win.Worm.Koobface.dq variant outbound connection (more info ...)trojan-activity    URL
20018MALWARE-CNC Win.Worm.Autorun variant outbound connection (more info ...)trojan-activity    URL
20019MALWARE-CNC User-Agent known malicious user agent - test (more info ...)trojan-activity    URL
20020MALWARE-CNC Win.Trojan.MalwareDoctor variant outbound connection (more info ...)trojan-activity    URL
20021MALWARE-CNC Win.Worm.Brontok user-agent outbound connection (more info ...)trojan-activity    URL
20022MALWARE-CNC Win.Worm.Padobot.z variant outbound connection (more info ...)trojan-activity    URL
20023MALWARE-CNC Advanced Virus Remover variant outbound connection (more info ...)trojan-activity    URL
20024MALWARE-CNC Win.Trojan.Dreamy.bc variant outbound connection (more info ...)trojan-activity    URL
20025PUA-ADWARE VirusBye outbound connection (more info ...)trojan-activity    URL
20026MALWARE-CNC Win.Trojan.Downloader.Win32.Banker.abg.b variant outbound connection (more info ...)trojan-activity    URL
20028MALWARE-CNC Windows Antivirus Pro variant outbound connection (more info ...)trojan-activity    URL
20032FILE-IDENTIFY MIME file type file download request (more info ...)misc-activity    
20034FILE-OTHER ESTsoft ALZip MIM file buffer overflow attempt (more info ...)attempted-user 2011-1336   
20035MALWARE-CNC Win.Trojan.Win32 Coinbit.A runtime traffic detected (more info ...)trojan-activity    URL
20036MALWARE-CNC Win.Trojan.Win32 Agent.ndau runtime traffic detected (more info ...)trojan-activity    URL
20037MALWARE-CNC Win.Trojan.Agent.cve runtime traffic detected (more info ...)trojan-activity    URL
20038MALWARE-CNC Win.Trojan.Agent.cve runtime traffic detected (more info ...)trojan-activity    URL
20039MALWARE-CNC User-Agent known malicious user-agent string Hardcore Software (more info ...)trojan-activity    URL
20040MALWARE-CNC Win.Trojan.KSpyPro.A variant outbound connection (more info ...)trojan-activity    URL
20041PUA-ADWARE Adware.BB outbound connection (more info ...)trojan-activity    URL
20042MALWARE-CNC Win.Trojan.Sinowal outbond connection (more info ...)trojan-activity    URL
20043MALWARE-CNC Adware Kraddare.AZ variant outbound connection (more info ...)trojan-activity    URL
20044BROWSER-PLUGINS F-Secure Anti-Virus fsresh.dll clsid access (more info ...)attempted-user    URL
20048SERVER-OTHER Trend Micro Control Manager CasLogDirectInsertHandler.cs cross site request forgery attempt (more info ...)attempted-user    URL
20051SERVER-OTHER SAP MaxDB malformed handshake request buffer overflow attempt (more info ...)attempted-admin 2010-1185 38769  
20054SERVER-OTHER HP OpenView Network Node Manager denial of service attempt (more info ...)denial-of-service 2009-3840   
20057MALWARE-CNC BitCoin Miner IP query (more info ...)trojan-activity    URL
20058SERVER-OTHER VMWare authorization service user credential parsing DoS attempt (more info ...)attempted-dos 2009-3707 36630  
20063PUA-ADWARE SecurityTool outbound connection (more info ...)trojan-activity    URL
20064MALWARE-CNC Malware Win.Trojan.Clemag.A variant outbound connection (more info ...)trojan-activity    URL
20066MALWARE-CNC Win.Trojan.Win32 SensLiceld.A runtime traffic detected (more info ...)trojan-activity    URL
20067MALWARE-CNC Win.Trojan.Win32 Zatvex.A runtime traffic detected (more info ...)trojan-activity    URL
20068MALWARE-CNC Win.Trojan.Jetilms.A runtime activity detected (more info ...)trojan-activity    URL
20069MALWARE-CNC Win.Trojan.VB.alhq runtime traffic detected (more info ...)trojan-activity    URL
20074MALWARE-CNC Win.Trojan.IRCBot.iseee variant outbound connection (more info ...)trojan-activity    URL
20075MALWARE-CNC Win.Trojan.Ruskill.abl variant outbound connection (more info ...)trojan-activity    URL
20076MALWARE-CNC Win.Trojan.Agobot.ast variant outbound connection (more info ...)trojan-activity    URL
20077MALWARE-CNC Win.Trojan.Agobot.ast variant outbound connection (more info ...)trojan-activity    URL
20078MALWARE-CNC Win.Trojan.Russkill.C variant outbound connection (more info ...)trojan-activity    URL
20079MALWARE-CNC Win.Trojan.Russkill.C variant outbound connection (more info ...)trojan-activity    URL
20080MALWARE-CNC Win.Trojan.Derusbi.A variant outbound connection (more info ...)trojan-activity    URL
20081MALWARE-CNC Win.Trojan.Downloader.Win32.Yakes.cbi variant outbound connection (more info ...)trojan-activity    URL
20082MALWARE-CNC Win.Trojan.Inject.raw variant outbound connection (more info ...)trojan-activity    URL
20083MALWARE-CNC Win.Trojan.Fucobha.A variant outbound connection (more info ...)trojan-activity    URL
20084SERVER-OTHER ALTAP Salamander PE Viewer PDB Filename Buffer Overflow (more info ...)attempted-user 2007-3314   URL
20085MALWARE-CNC Win.Trojan.Veebuu.BX variant outbound connection (more info ...)trojan-activity    URL
20086MALWARE-CNC Win.Trojan.Banload.ABY variant outbound connection (more info ...)trojan-activity    URL
20087MALWARE-CNC Win.Trojan.Banker.FGU variant outbound connection (more info ...)trojan-activity    URL
20088MALWARE-CNC Win.Trojan.Emudbot.A variant outbound connection (more info ...)trojan-activity    URL
20089INDICATOR-COMPROMISE IRC nick change on non-standard port (more info ...)trojan-activity    
20090INDICATOR-COMPROMISE IRC DCC file transfer request on non-standard port (more info ...)trojan-activity    
20091INDICATOR-COMPROMISE IRC DCC chat request on non-standard port (more info ...)trojan-activity    
20092INDICATOR-COMPROMISE IRC channel join on non-standard port (more info ...)trojan-activity    
20093INDICATOR-COMPROMISE IRC channel notice on non-standard port (more info ...)trojan-activity    
20094INDICATOR-COMPROMISE IRC message on non-standard port (more info ...)trojan-activity    
20096MALWARE-CNC Win.Trojan.Agent.dcir variant outbound connection (more info ...)trojan-activity    URL
20097MALWARE-CNC Win.Trojan.Agent.dcir infected host at destination ip (more info ...)trojan-activity    URL
20098MALWARE-CNC Win.Trojan.KeyLogger.wav variant outbound connection (more info ...)trojan-activity    URL
20099MALWARE-CNC Win.Trojan.Xtrat.A variant outbound connection (more info ...)trojan-activity    URL
20100PUA-ADWARE Adware Arcade Web - installation/update (more info ...)misc-activity    
20101PUA-ADWARE Adware Arcade Web - User-Agent (more info ...)misc-activity    URL
20102PUA-ADWARE Adware Arcade Web - X-Arcadeweb header (more info ...)misc-activity    URL
20103PUA-ADWARE Adware playsushi - User-Agent (more info ...)misc-activity    URL
20104MALWARE-CNC User-Agent known malicious user-agent string - InfoBot (more info ...)trojan-activity    URL
20105MALWARE-CNC User-Agent known malicious user-agent string - IPHONE (more info ...)trojan-activity    URL
20106MALWARE-CNC User-Agent known malicious user-agent string - darkness (more info ...)trojan-activity    URL
20107MALWARE-CNC Win.Trojan.Downloader.Win32.Small.Cns variant outbound connection (more info ...)trojan-activity    URL
20108MALWARE-CNC Win.Trojan.Banker.Pher variant outbound connection (more info ...)trojan-activity    URL
20109MALWARE-CNC Win.Trojan.Zombie.sm variant outbound connection (more info ...)trojan-activity    URL
20133FILE-OTHER MHTML XSS attempt (more info ...)attempted-user 2014-1747   URL
20138SERVER-OTHER Nortel Networks Multiple UNIStim VoIP Products Remote Eavesdrop Attempt (more info ...)attempted-recon 2007-5637 26120  
20143PUA-ADWARE Adware mightymagoo/playpickle/livingplay - User-Agent (more info ...)misc-activity    
20146FILE-PDF attempted download of a PDF with embedded PICT image (more info ...)policy-violation    
20151FILE-PDF attempted download of a PDF with embedded PCX image (more info ...)policy-violation    
20157SERVER-ORACLE Oracle GlassFish Server war file upload attempt (more info ...)attempted-admin 2011-0807 47438  
20158SERVER-WEBAPP Oracle GlassFish Server default credentials login attempt (more info ...)attempted-admin 2012-0551 53136  URL
20159SERVER-WEBAPP Oracle GlassFish Server authentication bypass attempt (more info ...)attempted-admin 2011-0807 47438  
20160SERVER-WEBAPP Oracle GlassFish Server successful authentication bypass attempt (more info ...)attempted-admin 2011-0807 47438  
20172FILE-IDENTIFY Metastock mwl file magic detected (more info ...)misc-activity    URL
20173PROTOCOL-SCADA Cogent DataHub server-side information disclosure (more info ...)web-application-attack 2011-3502   
20174PROTOCOL-SCADA Cogent DataHub server-side information disclosure (more info ...)web-application-attack 2011-3502   
20178PROTOCOL-SCADA RSLogix rna protocol denial of service attempt (more info ...)attempted-dos 2011-3489   URL
20185INDICATOR-SHELLCODE Metasploit meterpreter stdapi_fs_method request/response attempt (more info ...)shellcode-detect    URL
20186INDICATOR-SHELLCODE Metasploit meterpreter stdapi_sys_process_method request/response attempt (more info ...)shellcode-detect    URL
20187INDICATOR-SHELLCODE Metasploit meterpreter stdapi_sys_eventlog_method request/response attempt (more info ...)shellcode-detect    URL
20188INDICATOR-SHELLCODE Metasploit meterpreter stdapi_sys_config_method request/response attempt (more info ...)shellcode-detect    URL
20189INDICATOR-SHELLCODE Metasploit meterpreter stdapi_ui_method request/response attempt (more info ...)shellcode-detect    URL
20190INDICATOR-SHELLCODE Metasploit meterpreter stdapi_registry_method request/response attempt (more info ...)shellcode-detect    URL
20191INDICATOR-SHELLCODE Metasploit meterpreter stdapi_net_method request/response attempt (more info ...)shellcode-detect    URL
20192INDICATOR-SHELLCODE Metasploit meterpreter incognito_method request/response attempt (more info ...)shellcode-detect    URL
20193INDICATOR-SHELLCODE Metasploit meterpreter webcam_method request/response attempt (more info ...)shellcode-detect    URL
20194INDICATOR-SHELLCODE Metasploit meterpreter sniffer_method request/response attempt (more info ...)shellcode-detect    URL
20195INDICATOR-SHELLCODE Metasploit meterpreter priv_method request/response attempt (more info ...)shellcode-detect    URL
20196INDICATOR-SHELLCODE Metasploit meterpreter lanattacks_method request/response attempt (more info ...)shellcode-detect    URL
20197INDICATOR-SHELLCODE Metasploit meterpreter espia_method request/response attempt (more info ...)shellcode-detect    URL
20198INDICATOR-SHELLCODE Metasploit meterpreter networkpug_method request/response attempt (more info ...)shellcode-detect    URL
20199INDICATOR-SHELLCODE Metasploit meterpreter stdapi_railgun_method request/response attempt (more info ...)shellcode-detect    URL
20201MALWARE-CNC User-Agent known malicious user-agent string - meterpreter (more info ...)trojan-activity    URL
20202MALWARE-CNC Apple OSX.Revir-1 variant outbound connection (more info ...)trojan-activity    URL
20204MALWARE-CNC Win.Trojan.Taidoor variant outbound connection (more info ...)trojan-activity 2011-0611   URL
20205MALWARE-CNC Win32/Poison beaconing request (more info ...)trojan-activity    URL
20207PROTOCOL-SCADA Cogent unicode buffer overflow attempt (more info ...)attempted-admin 2011-3493   
20208PROTOCOL-SCADA Cogent unicode buffer overflow attempt (more info ...)attempted-admin 2011-3493   
20209PROTOCOL-SCADA Cogent unicode buffer overflow attempt (more info ...)attempted-admin 2011-3493   
20210PROTOCOL-SCADA Cogent unicode buffer overflow attempt (more info ...)attempted-admin 2011-3493   
20212SERVER-OTHER SSL CBC encryption mode weakness brute force attempt (more info ...)attempted-recon 2011-3389   URL
20213MALWARE-CNC Win.Trojan.Swisyn variant outbound connection (more info ...)trojan-activity    URL
20216PROTOCOL-SCADA Beckhoff TwinCAT DoS (more info ...)attempted-dos 2011-3486   
20217MALWARE-CNC Win.Trojan.Ramagedos.A variant outbound connection (more info ...)trojan-activity    URL
20218MALWARE-CNC Win.Trojan.Ramagedos.A variant outbound connection (more info ...)trojan-activity    URL
20219MALWARE-CNC Win.Trojan.ToriaSpy.A variant outbound connection (more info ...)trojan-activity    URL
20220PUA-ADWARE Adware.Wizpop outbound connection (more info ...)trojan-activity    URL
20221MALWARE-CNC Win.Trojan.Injector variant outbound connection (more info ...)trojan-activity    URL
20222MALWARE-CNC Win.Trojan.Payazol.B variant outbound connection (more info ...)trojan-activity    URL
20223FILE-IDENTIFY SMI file download request (more info ...)misc-activity  49149  URL
20224FILE-MULTIMEDIA MPlayer SMI file buffer overflow attempt (more info ...)attempted-user  49149  
20225FILE-OTHER SMI file download request (more info ...)misc-activity  49149  
20226FILE-OTHER MPlayer SMI file buffer overflow attempt (more info ...)attempted-user  49149  
20227FILE-MULTIMEDIA VideoLAN VLC webm memory corruption attempt (more info ...)attempted-user 2011-0531 46060  URL
20228MALWARE-CNC Win.Trojan.Hupigon variant outbound connection (more info ...)trojan-activity    URL
20229MALWARE-CNC Win.Trojan.Jinchodz variant outbound connection (more info ...)trojan-activity    URL
20230MALWARE-CNC User-Agent known malicious user-agent string 0pera 10 (more info ...)trojan-activity    URL
20232MALWARE-CNC Win.Trojan.Cycbot variant outbound connection (more info ...)trojan-activity    URL
20233MALWARE-CNC Win.Trojan.Virut variant outbound connection (more info ...)trojan-activity    URL
20234MALWARE-CNC Win.Trojan.Ceckno.cmz runtime traffic detected (more info ...)trojan-activity    URL
20250SERVER-OTHER IBM Tivoli Storage Manager Client Remote Heap Buffer Overflow (more info ...)attempted-admin 2008-4801   
20251SERVER-OTHER PointBase 4.6 database DoS (more info ...)attempted-dos 2003-1573   
20252MALWARE-CNC DroidKungFu check-in (more info ...)trojan-activity    URL
20269FILE-IDENTIFY FON font file download request (more info ...)misc-activity 2011-2003   URL
20276INDICATOR-OBFUSCATION standard ASCII encoded with UTF-8 possible evasion detected (more info ...)policy-violation    URL
20280MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
20281MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
20282FILE-IDENTIFY S3M file download request (more info ...)misc-activity    URL
20287FILE-IDENTIFY QCP file download request (more info ...)misc-activity    URL
20289MALWARE-CNC Win.Trojan.Doschald.A variant outbound connection (more info ...)trojan-activity    URL
20290MALWARE-CNC Win.Trojan.Doschald.A inbound connection (more info ...)trojan-activity    URL
20291MALWARE-CNC Win.Trojan.Mybios.A variant outbound connection (more info ...)trojan-activity    URL
20292MALWARE-CNC Win.Trojan.FresctSpy.A variant outbound connection (more info ...)trojan-activity    URL
20293MALWARE-CNC User-Agent known malicious user-agent string MBVDFRESCT (more info ...)trojan-activity    URL
20295FILE-IMAGE Public LibTiff Exploit (more info ...)attempted-user 2006-3459   
20300PROTOCOL-VOIP SIP URI type overflow attempt (more info ...)attempted-user    URL
20301PROTOCOL-VOIP TEL URI type overflow attempt (more info ...)attempted-user    URL
20302PROTOCOL-VOIP SIP URI multiple at signs in message (more info ...)misc-activity    URL
20305PROTOCOL-VOIP CSeq header format string attempt (more info ...)attempted-dos    URL
20306PROTOCOL-VOIP CSeq header invalid characters detected (more info ...)attempted-dos    URL
20308PROTOCOL-VOIP CSeq header method mismatch attempt (more info ...)attempted-dos    URL
20311PROTOCOL-VOIP Max-Forwards value over 70 (more info ...)misc-activity    URL
20312PROTOCOL-VOIP Max-Forwards header invalid characters detected (more info ...)attempted-dos    URL
20313PROTOCOL-VOIP Via header missing SIP field (more info ...)misc-activity    URL
20314PROTOCOL-VOIP Via header format string attempt (more info ...)attempted-dos    URL
20315PROTOCOL-VOIP Via header invalid characters detected (more info ...)attempted-dos    URL
20316PROTOCOL-VOIP Via header invalid separators (more info ...)attempted-dos    URL
20317PROTOCOL-VOIP Via header invalid seperators (more info ...)attempted-dos    URL
20318PROTOCOL-VOIP From header format string attempt (more info ...)attempted-dos    URL
20319PROTOCOL-VOIP From header invalid characters detected (more info ...)attempted-dos    URL
20320PROTOCOL-VOIP From header XSS injection attempt (more info ...)misc-attack    
20321PROTOCOL-VOIP From header XSS injection attempt (more info ...)misc-attack    
20323PROTOCOL-VOIP From header format string attempt (more info ...)attempted-dos    URL
20324PROTOCOL-VOIP From header whitespace in field attempt (more info ...)attempted-dos    URL
20325PROTOCOL-VOIP From header whitespace in field attempt (more info ...)attempted-dos    URL
20326PROTOCOL-VOIP From header unquoted tokens in field attempt (more info ...)attempted-dos    URL
20327PROTOCOL-VOIP From header unquoted tokens in field attempt (more info ...)attempted-dos    URL
20328PROTOCOL-VOIP From header missing terminating quote (more info ...)attempted-dos    URL
20329PROTOCOL-VOIP From header missing terminating quote (more info ...)attempted-dos    URL
20332PROTOCOL-VOIP To header contains recursive URL-encoded data (more info ...)attempted-dos    URL
20333PROTOCOL-VOIP To header invalid characters detected (more info ...)attempted-dos    URL
20334PROTOCOL-VOIP To header XSS injection attempt (more info ...)misc-attack    
20335PROTOCOL-VOIP To header XSS injection attempt (more info ...)misc-attack    
20336PROTOCOL-VOIP To header format string attempt (more info ...)attempted-dos    URL
20337PROTOCOL-VOIP To header format string attempt (more info ...)attempted-dos    URL
20338PROTOCOL-VOIP To header whitespace in field attempt (more info ...)attempted-dos    URL
20339PROTOCOL-VOIP To header whitespace in field attempt (more info ...)attempted-dos    URL
20340PROTOCOL-VOIP To header unquoted tokens in field attempt (more info ...)attempted-dos    URL
20341PROTOCOL-VOIP To header unquoted tokens in field attempt (more info ...)attempted-dos    URL
20342PROTOCOL-VOIP To header invalid seperators (more info ...)attempted-dos    URL
20343PROTOCOL-VOIP To header invalid seperators (more info ...)attempted-dos    URL
20344PROTOCOL-VOIP To header missing terminating quote (more info ...)attempted-dos    URL
20345PROTOCOL-VOIP To header missing terminating quote (more info ...)attempted-dos    URL
20348PROTOCOL-VOIP Subject header XSS injection attempt (more info ...)misc-attack    
20349PROTOCOL-VOIP Subject header XSS injection attempt (more info ...)misc-attack    
20350PROTOCOL-VOIP Subject header format string attempt (more info ...)attempted-dos    URL
20351PROTOCOL-VOIP Subject header format string attempt (more info ...)attempted-dos    URL
20352PROTOCOL-VOIP Expires header overflow attempt (more info ...)attempted-user    URL
20353PROTOCOL-VOIP Expires header invalid characters detected (more info ...)attempted-dos    URL
20354PROTOCOL-VOIP Call-ID header format string attempt (more info ...)attempted-dos    URL
20355PROTOCOL-VOIP Call-ID header invalid characters detected (more info ...)attempted-dos    URL
20356PROTOCOL-VOIP Call-ID header XSS injection attempt (more info ...)misc-attack    
20357PROTOCOL-VOIP Call-ID header XSS injection attempt (more info ...)misc-attack    
20358PROTOCOL-VOIP Call-ID header format string attempt (more info ...)attempted-dos    URL
20359PROTOCOL-VOIP Call-ID header format string attempt (more info ...)attempted-dos    URL
20360PROTOCOL-VOIP Call-ID header invalid seperators (more info ...)attempted-dos    URL
20361PROTOCOL-VOIP Call-ID header invalid seperators (more info ...)attempted-dos    URL
20364PROTOCOL-VOIP Contact header format string attempt (more info ...)attempted-dos    URL
20365PROTOCOL-VOIP Contact header invalid characters detected (more info ...)attempted-dos    URL
20366PROTOCOL-VOIP Contact header XSS injection attempt (more info ...)misc-attack    
20367PROTOCOL-VOIP Contact header XSS injection attempt (more info ...)misc-attack    
20370PROTOCOL-VOIP Contact header whitespace in field attempt (more info ...)attempted-dos    URL
20371PROTOCOL-VOIP Contact header whitespace in field attempt (more info ...)attempted-dos    URL
20373PROTOCOL-VOIP Contact header unquoted tokens in field attempt (more info ...)attempted-dos    URL
20374PROTOCOL-VOIP Contact header missing terminating quote (more info ...)attempted-dos    URL
20375PROTOCOL-VOIP Contact header missing terminating quote (more info ...)attempted-dos    URL
20376PROTOCOL-VOIP Content-Type header format string attempt (more info ...)attempted-dos    URL
20377PROTOCOL-VOIP Content-Type header invalid characters detected (more info ...)attempted-dos    URL
20378PROTOCOL-VOIP Date header invalid characters detected (more info ...)misc-activity    URL
20379PROTOCOL-VOIP Date header invalid characters detected (more info ...)misc-activity    URL
20380PROTOCOL-VOIP Authorization header invalid characters in response parameter (more info ...)attempted-user    URL
20381PROTOCOL-VOIP Remote-Party-ID header hexadecimal characters in IP address field (more info ...)attempted-admin 2007-1542 23047  URL
20382PROTOCOL-VOIP Media header port field invalid value (more info ...)attempted-user    URL
20383PROTOCOL-VOIP Time header contains negative value (more info ...)attempted-user    URL
20384PROTOCOL-VOIP Time header contains long value (more info ...)attempted-user    URL
20385PROTOCOL-VOIP Version header overflow attempt (more info ...)attempted-dos    URL
20386PROTOCOL-VOIP Connection header invalid value (more info ...)attempted-dos    URL
20387PROTOCOL-VOIP T.38 fax rate management attribute buffer overflow attempt (more info ...)attempted-admin 2007-2293 23648  
20388PROTOCOL-VOIP T.38 fax EC attribute buffer overflow attempt (more info ...)attempted-admin 2007-2293 23648  
20389PROTOCOL-VOIP Attribute header buffer overflow attempt (more info ...)attempted-user 2006-0189 16213  URL
20390PROTOCOL-VOIP Attribute header rtpmap field invalid payload type (more info ...)attempted-user 2008-1289 28308  URL
20424PROTOCOL-VOIP Sivus scanner detected (more info ...)network-scan    URL
20428MALWARE-CNC Win.Trojan.Zewit.A variant outbound connection (more info ...)trojan-activity    URL
20431FILE-OTHER Wireshark DECT packet dissector overflow attempt (more info ...)attempted-user 2011-1591 47392  
20432MALWARE-CNC Win.Trojan.Hiloti variant outbound connection (more info ...)trojan-activity    URL
20433PUA-ADWARE XP Guardian 2010 anutayadokalug host outbound connection (more info ...)trojan-activity    URL
20434PUA-ADWARE XP Guardian 2010 proantivirus21 host runtime traffic detection (more info ...)trojan-activity    URL
20435MALWARE-CNC TrojanSpy Win.Trojan.Zbot.Svr runtime traffic detected (more info ...)trojan-activity    URL
20436MALWARE-TOOLS THC SSL renegotiation DOS attempt (more info ...)attempted-dos 2011-5094   URL
20437MALWARE-TOOLS THC SSL renegotiation DOS attempt (more info ...)attempted-dos 2011-5094   URL
20438MALWARE-TOOLS THC SSL renegotiation DOS attempt (more info ...)attempted-dos 2011-5094   URL
20439MALWARE-TOOLS THC SSL renegotiation DOS attempt (more info ...)attempted-dos 2011-5094   URL
20440SERVER-OTHER CA BrightStor cheyenneds mailslot overflow (more info ...)attempted-admin 2006-5142 20364  
20441SERVER-OTHER CA BrightStor cheyenneds mailslot overflow (more info ...)attempted-admin 2006-5142 20364  
20442SERVER-OTHER CA BrightStor cheyenneds mailslot overflow (more info ...)attempted-admin 2006-5142 20364  
20443APP-DETECT Apple OSX Remote Mouse usage (more info ...)policy-violation    URL
20445FILE-PDF Foxit Reader title overflow attempt (more info ...)attempted-user  43785  
20446SERVER-WEBAPP DiskPulseServer GetServerInfo request buffer overflow (more info ...)attempted-user  43919  
20447MALWARE-CNC Win.Trojan.Agent.JAAK variant outbound connection (more info ...)trojan-activity    URL
20448MALWARE-CNC Win.Trojan.Meciv.A variant outbound connection (more info ...)trojan-activity    URL
20449MALWARE-CNC Win.Worm.Busifom.A variant outbound connection (more info ...)trojan-activity    URL
20456FILE-IDENTIFY RealNetworks Real Media file magic detected (more info ...)misc-activity    
20460FILE-IDENTIFY MP3 file magic detected (more info ...)misc-activity    
20475FILE-IDENTIFY ARJ file magic detected (more info ...)misc-activity    
20481FILE-IDENTIFY MP3 file magic detected (more info ...)misc-activity    
20514FILE-IDENTIFY dmg file magic detected (more info ...)misc-activity    
20518FILE-IDENTIFY rmf file download request (more info ...)misc-activity    
20521FILE-IDENTIFY Flac file magic detected (more info ...)misc-activity    URL
20522FILE-IDENTIFY VideoLAN VLC file magic detected (more info ...)misc-activity    URL
20525MALWARE-CNC Win.Trojan.Duqu variant outbound connection (more info ...)trojan-activity    URL
20527MALWARE-CNC Sirefef initial C&C connection variant outbound connection (more info ...)trojan-activity    URL
20530SERVER-WEBAPP HP OpenView Storage Data Protector directory traversal attempt (more info ...)attempted-recon 2011-1736   
20531SERVER-WEBAPP HP OpenView Storage Data Protector directory traversal attempt (more info ...)attempted-recon 2011-1736   
20546SERVER-OTHER BakBone NetVault client heap overflow attempt (more info ...)attempted-admin 2005-1009 12967  
20552SERVER-MAIL Mercury Mail Transport System buffer overflow attempt (more info ...)attempted-user 2005-4411 16396  
20553FILE-MULTIMEDIA Un4seen Developments XMPlay crafted ASX file buffer overflow attempt (more info ...)attempted-user 2006-6063 21206  
20561MALWARE-CNC Win.Trojan.PWSBanker.SHE variant outbound connection (more info ...)trojan-activity    URL
20562MALWARE-CNC Win.Trojan.PWSBanker.SHE variant outbound connection (more info ...)trojan-activity    URL
20563FILE-IDENTIFY amf file download request (more info ...)misc-activity    
20564FILE-IDENTIFY amf file magic detected (more info ...)misc-activity    
20569MALWARE-CNC Win.Trojan.Small.kb variant outbound connection (more info ...)trojan-activity    URL
20570MALWARE-CNC Win.Trojan.Small.kb variant outbound connection (more info ...)trojan-activity    URL
20571MALWARE-CNC Win.Trojan.Small.kb variant outbound connection (more info ...)trojan-activity    URL
20578SERVER-MAIL Qualcomm Eudora url buffer overflow attempt (more info ...)attempted-user 2002-1770 10298  
20587MALWARE-CNC Win.Trojan.Larchik.A variant outbound connection (more info ...)trojan-activity    URL
20588FILE-IDENTIFY CDR file download request (more info ...)misc-activity    URL
20589FILE-IDENTIFY CDR file magic detected (more info ...)misc-activity    URL
20594SERVER-ORACLE Outside In CorelDRAW file parser integer overflow attempt (more info ...)attempted-admin 2011-3541   URL
20595MALWARE-CNC Win.Trojan.Ixeshe.F variant outbound connection (more info ...)trojan-activity    URL
20596MALWARE-CNC Win.Trojan.Smoaler.A variant outbound connection (more info ...)trojan-activity    URL
20597MALWARE-CNC Win.Trojan.Smoaler.A variant outbound connection (more info ...)trojan-activity    URL
20598MALWARE-CNC Win.Trojan.Smoaler.A variant outbound connection (more info ...)trojan-activity    URL
20599MALWARE-CNC Win.Trojan.Smoaler.A variant outbound connection (more info ...)trojan-activity    URL
20601PROTOCOL-SERVICES rlogin nobody (more info ...)attempted-user    
20602PROTOCOL-SERVICES rlogin guest (more info ...)attempted-user    
20604MALWARE-CNC Win.Trojan.Buzus.isqy variant outbound connection (more info ...)trojan-activity    URL
20605MALWARE-CNC Win.Trojan.R2d2.A contact to cnc server (more info ...)trojan-activity    URL
20606MALWARE-CNC Win.Trojan.Domsingx.A variant outbound connection (more info ...)trojan-activity    URL
20609SERVER-OTHER Sunway ForceControl SNMP NetDBServer stack buffer overflow attempt (more info ...)attempted-user    URL
20616SERVER-OTHER Peercast Basic HTTP authentication buffer overflow attempt (more info ...)attempted-user 2008-2040   URL
20617SERVER-WEBAPP Sage SalesLogix admin authentication bypass attempt (more info ...)attempted-admin 2004-1612 11450  
20618SERVER-OTHER Sage SalesLogix database credential disclosure attempt (more info ...)attempted-admin 2004-1612 11450  URL
20619SERVER-WEBAPP CoreHTTP Long buffer overflow attempt (more info ...)attempted-user 2007-4060 25120  URL
20620SERVER-WEBAPP CoreHTTP Long buffer overflow attempt (more info ...)attempted-user 2007-4060 25120  URL
20626MALWARE-CNC Win.Trojan.Shylock.A variant outbound connection (more info ...)trojan-activity    URL
20627MALWARE-CNC Win.Trojan.Shylock.A C&C server response (more info ...)trojan-activity    URL
20630MALWARE-CNC Win.Trojan.Winnti.A contact to cnc server (more info ...)trojan-activity    URL
20638PROTOCOL-SCADA Progea Movicon/PowerHMI EIDP over HTTP memory corruption attempt (more info ...)attempted-admin 2011-3499 49605  
20639MALWARE-CNC Malware Win.Trojan.Higest.N variant outbound connection (more info ...)trojan-activity    URL
20655PUA-OTHER Yahoo Messenger iframe injection status change attempt (more info ...)web-application-activity    URL
20661MALWARE-CNC Simbda variant outbound connection (more info ...)trojan-activity    URL
20662SERVER-OTHER Dameware Mini Remote Control username buffer overflow (more info ...)attempted-admin 2005-2842 14707  
20668EXPLOIT-KIT URI request for known malicious URI - /content/v1.jar (more info ...)trojan-activity    URL
20670PROTOCOL-VOIP Digium Asterisk data length field overflow attempt (more info ...)attempted-user 2006-5444 20617  URL
20673FILE-MULTIMEDIA invalid VLC media player SMB URI download attempt (more info ...)misc-attack    URL
20674SERVER-WEBAPP Sourceforge Gallery search engine cross-site scripting attempt (more info ...)attempted-admin 2003-0614   URL
20676MALWARE-CNC Win.Trojan.EggDrop.acn variant outbound connection (more info ...)trojan-activity    URL
20677MALWARE-CNC Win.Trojan.EggDrop.acn variant outbound connection (more info ...)trojan-activity    URL
20678MALWARE-CNC Trojan-Downloader.Win32.Genome.aior variant outbound connection (more info ...)trojan-activity    URL
20679MALWARE-CNC Win.Trojan.Syrutrk variant outbound connection (more info ...)trojan-activity    URL
20681MALWARE-CNC Trojan-Downloader.Win32.Agent.NMS variant outbound connection (more info ...)trojan-activity    URL
20682MALWARE-CNC Trojan-Downloader.Win32.Agent.NMS variant outbound connection (more info ...)trojan-activity    URL
20683MALWARE-CNC Cleanvaccine variant outbound connection (more info ...)trojan-activity    URL
20684MALWARE-CNC Cleanvaccine variant outbound connection (more info ...)trojan-activity    URL
20685MALWARE-CNC Win.Trojan.Heloag.A variant outbound connection (more info ...)trojan-activity    URL
20686MALWARE-CNC Win.Trojan.Virut.BM connect to client (more info ...)trojan-activity    URL
20687MALWARE-CNC Trojan-Downloader.Win32.Genome.akhg variant outbound connection (more info ...)trojan-activity    URL
20688MALWARE-CNC Trojan-Spy.Win32.Zbot.Jeib variant outbound connection (more info ...)trojan-activity    URL
20689MALWARE-CNC Trojan-Spy.Win32.Zbot.Jeib variant outbound connection (more info ...)trojan-activity    URL
20690SERVER-OTHER Quest NetVault SmartDisk libnvbasics.dll denial of service attempt (more info ...)denial-of-service  48029  URL
20693MALWARE-CNC Win.Trojan.Blackcontrol.A variant outbound connection (more info ...)trojan-activity    URL
20694MALWARE-CNC Win.Trojan.SSonce.A variant outbound connection (more info ...)trojan-activity    URL
20695MALWARE-CNC Win.Trojan.Banker.GZW connect to cnc server (more info ...)trojan-activity    URL
20696MALWARE-CNC Win.Trojan.Ransom.CK connect to cnc server (more info ...)trojan-activity    URL
20697MALWARE-CNC Win.Trojan.Ransom.CK connect to cnc server (more info ...)trojan-activity    URL
20698FILE-OTHER Telnet protocol specifier command injection attempt (more info ...)attempted-user 2004-0473 10358  
20726SERVER-WEBAPP F-Secure web console username overflow attempt (more info ...)attempted-admin 2006-2838 18201  
20737SERVER-WEBAPP 427BB cookie-based authentication bypass attempt (more info ...)attempted-admin 2006-0153   
20738SERVER-OTHER Check Point vpn-1 ISAKMP buffer overflow attempt (more info ...)attempted-user 2004-0040   
20743BROWSER-OTHER Multiple web browser window injection attempt (more info ...)misc-attack 2004-1155   
20745SERVER-OTHER Ethereal Netflow dissector buffer overflow attempt (more info ...)attempted-admin 2004-0176 9952  URL
20748SERVER-OTHER Yahoo Messenger possible file transfer spoofing (more info ...)attempted-user 2005-0243   
20749SERVER-OTHER EMC Retrospect client crafted packet buffer overflow attempt (more info ...)attempted-admin 2006-2391 17948  
20750FILE-IDENTIFY webm file magic detected (more info ...)misc-activity    
20751FILE-IDENTIFY webm file download request (more info ...)misc-activity    
20752PUA-ADWARE Win32.GameVance outbound connection (more info ...)trojan-activity    URL
20753PUA-ADWARE Win32.GamePlayLabs outbound connection (more info ...)trojan-activity    URL
20754MALWARE-CNC Win.Trojan.Virut-3 variant outbound connection (more info ...)trojan-activity    URL
20755MALWARE-CNC Win.Trojan.Krap variant outbound connection (more info ...)trojan-activity    URL
20758POLICY-OTHER Progrea Movicon TCPUploadServer.exe unauthenticated access attempt (more info ...)attempted-admin 2011-2963 46907  
20759MALWARE-CNC Win.Trojan.Gbot.oce variant outbound connection (more info ...)trojan-activity    URL
20763MALWARE-CNC Win.Trojan.Spyeye-206 variant outbound connection (more info ...)trojan-activity    URL
20764SERVER-WEBAPP SyBase MBusiness xml closing tag overflow attempt (more info ...)attempted-user  47775  
20800FILE-IDENTIFY MIME file type file attachment detected (more info ...)misc-activity    
20801FILE-IDENTIFY MIME file type file attachment detected (more info ...)misc-activity    
20819SERVER-WEBAPP ACal Calendar Project cookie based authentication bypass attempt (more info ...)attempted-user 2006-0182   
20824OS-WINDOWS generic web server hashing collision attack (more info ...)attempted-dos 2011-3414   URL
20825SERVER-WEBAPP generic web server hashing collision attack (more info ...)attempted-dos 2011-5037   URL
20826SERVER-WEBAPP OABoard forum script remote file injection attempt (more info ...)attempted-user 2006-0076 16105  
20830MALWARE-CNC Win.Trojan.Banbra.amdu variant outbound connection (more info ...)trojan-activity    URL
20836MALWARE-CNC Win.Trojan.Zusy.A runtime traffic detected (more info ...)trojan-activity    URL
20837MALWARE-CNC Win.Trojan.Mecklow.C runtime traffic detected (more info ...)trojan-activity    URL
20838MALWARE-CNC Win.Trojan.Smokebot.A runtime traffic detected (more info ...)trojan-activity    URL
20844MALWARE-CNC Win.Trojan.Banker.smxy runtime traffic detected (more info ...)trojan-activity    URL
20845SERVER-WEBAPP HP Network Node Manager cross site scripting attempt (more info ...)web-application-attack 2011-4155   URL
20848FILE-IDENTIFY MAKI file attachment detected (more info ...)misc-activity    
20849FILE-IDENTIFY MAKI file attachment detected (more info ...)misc-activity    
20852FILE-IDENTIFY DAZ Studio script download request (more info ...)misc-activity    
20853FILE-OTHER DAZ Studio dangerous scripting method attempt (more info ...)attempted-user 2009-4148 37176  
20859FILE-IDENTIFY Autodesk Maya embedded language script download request (more info ...)misc-activity    
20860FILE-IDENTIFY Autodesk Maya file magic detected (more info ...)misc-activity    
20861FILE-OTHER Autodesk Maya dangerous scripting method attempt (more info ...)attempted-user 2009-3578 36636  
20862SERVER-WEBAPP Jive Software Openfire logviewer.jsp XSS attempt (more info ...)web-application-attack 2009-0496 32935  
20863SERVER-WEBAPP Jive Software Openfire log.jsp XSS attempt (more info ...)web-application-attack 2009-0496 32935  
20864SERVER-WEBAPP Jive Software Openfire group-summary.jsp XSS attempt (more info ...)web-application-attack 2009-0496 32935  
20865SERVER-WEBAPP Jive Software Openfire user-properties.jsp XSS attempt (more info ...)web-application-attack 2009-0496 32935  
20866SERVER-WEBAPP Jive Software Openfire audit-policy.jsp XSS attempt (more info ...)web-application-attack 2009-0496 32935  
20867SERVER-WEBAPP Jive Software Openfire server-properties.jsp XSS attempt (more info ...)web-application-attack 2009-0496 32935  
20868SERVER-WEBAPP Jive Software Openfire muc-room-edit-form.jsp XSS attempt (more info ...)web-application-attack 2009-0496 32935  
20869FILE-IDENTIFY Autodesk 3D Studio Maxscript download request (more info ...)misc-activity    
20870FILE-OTHER Autodesk 3D Studio Maxscript dangerous scripting method attempt (more info ...)attempted-user 2009-3577 36634  
20871SERVER-WEBAPP Worldweaver DX Studio Player shell.execute command execution attempt (more info ...)attempted-user 2009-2011 35273  
20872SERVER-WEBAPP Worldweaver DX Studio Player shell.execute command execution attempt (more info ...)attempted-user 2009-2011 35273  
20873POLICY-OTHER TRACE attempt (more info ...)web-application-attack 2011-1511 47818  
20876SERVER-OTHER IBM solidDB solid.exe authentication bypass attempt (more info ...)attempted-user  47137  URL
20877MALWARE-CNC RunTime Worm.Win32.Warezov.gs variant outbound connection (more info ...)trojan-activity    URL
20888FILE-IDENTIFY Video Spirit visprj download attempt (more info ...)misc-activity    
20889FILE-OTHER Video Spirit visprj buffer overflow (more info ...)attempted-user 2011-0499   
20890MALWARE-CNC Win.Trojan.VB.adbp runtime traffic detected (more info ...)trojan-activity    URL
20891MALWARE-CNC Win.Trojan.VB.adbp runtime traffic detected (more info ...)trojan-activity    URL
20892MALWARE-CNC Worm.Win32.Skopvel.A runtime traffic detected (more info ...)trojan-activity    URL
20893FILE-IDENTIFY Video Spirit file attachment detected (more info ...)misc-activity    
20894FILE-IDENTIFY Video Spirit file attachment detected (more info ...)misc-activity    
20895FILE-IDENTIFY AutoDesk 3D Studio Maxscript file attachment detected (more info ...)misc-activity    
20896FILE-IDENTIFY AutoDesk 3D Studio Maxscript file attachment detected (more info ...)misc-activity    
20905FILE-IDENTIFY X PixMap file attachment detected (more info ...)misc-activity    
20906FILE-IDENTIFY X PixMap file attachment detected (more info ...)misc-activity    
20913FILE-IDENTIFY XML Shareable Playlist Format file attachment detected (more info ...)misc-activity    
20914FILE-IDENTIFY XML Shareable Playlist Format file attachment detected (more info ...)misc-activity    
20917FILE-IDENTIFY BAK file attachment detected (more info ...)misc-activity    
20918FILE-IDENTIFY BAK file attachment detected (more info ...)misc-activity    
20924FILE-IDENTIFY PLS file magic detected (more info ...)misc-activity    
20927MALWARE-CNC Win.Trojan.Spyeye-207 variant outbound connection (more info ...)trojan-activity    URL
20928FILE-IDENTIFY SMIL file magic detected (more info ...)misc-activity    URL
20929FILE-IDENTIFY MKV file attachment detected (more info ...)misc-activity    
20930FILE-IDENTIFY MKV file attachment detected (more info ...)misc-activity    
20931FILE-IDENTIFY MKS file attachment detected (more info ...)misc-activity    
20932FILE-IDENTIFY MKS file attachment detected (more info ...)misc-activity    
20933FILE-IDENTIFY MKA file attachment detected (more info ...)misc-activity    
20934FILE-IDENTIFY MKA file attachment detected (more info ...)misc-activity    
20935FILE-IDENTIFY QCP file attachment detected (more info ...)misc-activity    
20936FILE-IDENTIFY QCP file attachment detected (more info ...)misc-activity    
20960FILE-IDENTIFY Flac file download request (more info ...)misc-activity    URL
20964FILE-IDENTIFY SAMI file download request (more info ...)misc-activity    URL
20968FILE-IDENTIFY Apple disk image file download request (more info ...)misc-activity    URL
20988MALWARE-CNC User-Agent known malicious user-agent string ZmEu - vulnerability scanner (more info ...)network-scan    URL
20989INDICATOR-SHELLCODE x86 OS agnostic single_static_bit encoder (more info ...)shellcode-detect    
20990INDICATOR-SHELLCODE x86 OS agnostic avoid_utf8_tolower encoder (more info ...)shellcode-detect    
20992FILE-IDENTIFY SAMI file magic detected (more info ...)misc-activity    
20997BROWSER-WEBKIT Apple Webkit Display box rendering corruption attempt (more info ...)attempted-user 2011-2818 48960  
21003MALWARE-CNC Cute Pack cute-ie.html request (more info ...)trojan-activity 2010-0806   URL
21004MALWARE-CNC Cute Pack cute-ie.html landing page (more info ...)trojan-activity 2010-0806   URL
21005MALWARE-CNC Yang Pack yg.htm download request (more info ...)trojan-activity    URL
21006MALWARE-CNC Yang Pack yg.htm landing page (more info ...)trojan-activity 2011-3544   URL
21012FILE-IDENTIFY Cytel Studio cy3 file download request (more info ...)misc-activity    
21013FILE-IDENTIFY Cytel Studio cy3 file attachment detected (more info ...)misc-activity    
21014FILE-IDENTIFY Cytel Studio cy3 file attachment detected (more info ...)misc-activity    
21015FILE-IDENTIFY cy3 Cytel Studio file magic detected (more info ...)misc-activity    
21016FILE-IDENTIFY Cytel Studio cyb file attachment detected (more info ...)misc-activity    
21017FILE-IDENTIFY cyb Cytel Studio file attachment detected (more info ...)misc-activity    
21018FILE-IDENTIFY cyb Cytel Studio file download request (more info ...)misc-activity    
21019FILE-OTHER Cytel Studio string stack overflow attempt (more info ...)attempted-user  49924  URL
21020FILE-OTHER Cytel Studio row overflow attempt (more info ...)attempted-user  49924  URL
21021FILE-OTHER Cytel Studio USE command overflow attempt (more info ...)attempted-user  49924  URL
21028MALWARE-CNC Win.Trojan.Usinec connect to server (more info ...)trojan-activity    URL
21038INDICATOR-OBFUSCATION String.fromCharCode with multiple encoding types detected (more info ...)policy-violation    URL
21047MALWARE-CNC known malicious SSL certificate - Sykipot C&C (more info ...)trojan-activity    URL
21050SERVER-OTHER HP Diagnostics Server magentservice.exe stack overflow attempt (more info ...)attempted-admin 2011-4789 51398  
21051SERVER-WEBAPP Apple OSX software update command execution attempt (more info ...)attempted-admin 2007-5863   
21052FILE-IDENTIFY UltraISO CUE file download request (more info ...)misc-activity    
21053FILE-IDENTIFY UltraISO CUE file attachment detected (more info ...)misc-activity    
21054FILE-IDENTIFY UltraISO CUE file attachment detected (more info ...)misc-activity    
21055MALWARE-CNC Win.Trojan.Utka.A variant outbound connection (more info ...)trojan-activity    URL
21058MALWARE-CNC Win.Trojan.AutoIt.pm runtime traffic detected (more info ...)trojan-activity    URL
21060SERVER-WEBAPP Symantec IM Manager Administrator console site injection attempt (more info ...)attempted-user 2011-0554   
21061FILE-IDENTIFY AVI file attachment detected (more info ...)misc-activity    
21062FILE-IDENTIFY AVI file attachment detected (more info ...)misc-activity    
21065SERVER-WEBAPP Symantec IM Manager Edituser cross site scripting attempt (more info ...)attempted-user 2011-0552 49739  
21066SERVER-WEBAPP Symantec IM Manager Systemdashboard cross site scripting attempt (more info ...)attempted-user 2011-0552 49739  
21067SERVER-WEBAPP Symantec IM Manager TOC_simple cross site scripting attempt (more info ...)attempted-user 2011-0552 49739  
21079PROTOCOL-SCADA Siemens SIMATIC HMI Administrator cookie detected (more info ...)policy-violation 2011-4508   URL
21087MALWARE-CNC Bindow.Worm runtime traffic detected (more info ...)trojan-activity    URL
21093FILE-MULTIMEDIA A-PDF Wav to mp3 converter buffer overfow (more info ...)attempted-user    
21095FILE-PDF Foxit Reader malicious pdf file write access (more info ...)attempted-user    URL
21105SERVER-OTHER Avaya WinPDM Unite host router buffer overflow attempt (more info ...)attempted-user  47947  
21107FILE-MULTIMEDIA MJM Quickplayer s3m buffer overflow (more info ...)attempted-user    
21117INDICATOR-COMPROMISE WSO web shell (more info ...)trojan-activity    URL
21118INDICATOR-COMPROMISE WSO web shell security information display (more info ...)trojan-activity    URL
21119INDICATOR-COMPROMISE WSO web shell interactive file system information display (more info ...)trojan-activity    URL
21120INDICATOR-COMPROMISE WSO web shell interactive console display (more info ...)trojan-activity    URL
21122MALWARE-CNC Win.Trojan.Bandok.zp runtime traffic detected (more info ...)trojan-activity    URL
21123MALWARE-CNC Win.Trojan.Flymux.A runtime traffic detected (more info ...)trojan-activity    URL
21124MALWARE-CNC Win.Trojan.Opachki.A runtime traffic detected (more info ...)trojan-activity    URL
21125MALWARE-CNC Win.Trojan.Alureon.DG runtime traffic detected (more info ...)trojan-activity    URL
21126MALWARE-CNC Win.Trojan.Koutodoor.C runtime traffic detected (more info ...)trojan-activity    URL
21127MALWARE-CNC Win.Trojan.Setfic.A runtime traffic detected (more info ...)trojan-activity    URL
21128MALWARE-CNC Win.Trojan.Dromedan.A runtime traffic detected (more info ...)trojan-activity    URL
21129INDICATOR-COMPROMISE Mulcishell web shell (more info ...)trojan-activity    URL
21130INDICATOR-COMPROMISE Mulcishell web shell enumeration page (more info ...)trojan-activity    URL
21131INDICATOR-COMPROMISE Mulcishell web shell domain lookup page (more info ...)trojan-activity    URL
21133INDICATOR-COMPROMISE Mulcishell web shell encoder page (more info ...)trojan-activity    URL
21134INDICATOR-COMPROMISE Mulcishell web shell security information page (more info ...)trojan-activity    URL
21136INDICATOR-COMPROMISE Mulcishell web shell security bypass page (more info ...)trojan-activity    URL
21137INDICATOR-COMPROMISE Mulcishell web shell tools page (more info ...)trojan-activity    URL
21138INDICATOR-COMPROMISE Mulcishell web shell database parsing page (more info ...)trojan-activity    URL
21139INDICATOR-COMPROMISE Mulcishell web shell spread shell page (more info ...)trojan-activity    URL
21140INDICATOR-COMPROMISE Mulcishell web shell kill shell page (more info ...)trojan-activity    URL
21142MALWARE-CNC Win.Trojan.Zbot.PKJ runtime traffic detected (more info ...)trojan-activity    URL
21143MALWARE-CNC Win.Trojan.Zbot.PKJ runtime traffic detected (more info ...)trojan-activity    URL
21144MALWARE-CNC Win.Trojan.Zbot.PKJ runtime traffic detected (more info ...)trojan-activity    URL
21145MALWARE-CNC Win.Trojan.Neraweq.A runtime traffic detected (more info ...)trojan-activity    URL
21146PROTOCOL-SCADA Sunway ForceControl SNMP NetDBServer integer signedness buffer overflow attempt (more info ...)attempted-user    URL
21147PROTOCOL-SCADA Sunway ForceControl SNMP NetDBServer integer signedness buffer overflow attempt (more info ...)attempted-user    URL
21148PROTOCOL-SCADA Sunway ForceControl SNMP NetDBServer integer signedness buffer overflow attempt (more info ...)attempted-user    URL
21149PROTOCOL-SCADA Sunway ForceControl SNMP NetDBServer integer signedness buffer overflow attempt (more info ...)attempted-user    URL
21150PROTOCOL-VOIP Grandstream networks denial of service (more info ...)attempted-dos 2007-4498 25399  
21151MALWARE-CNC Win.Trojan.Stegae.A runtime traffic detected (more info ...)trojan-activity    URL
21152FILE-IDENTIFY S3M file attachment detected (more info ...)misc-activity    
21153FILE-IDENTIFY S3M file attachment detected (more info ...)misc-activity    
21164SERVER-SAMBA Samba username map script command injection attempt (more info ...)attempted-admin 2007-2447   URL
21169PUA-ADWARE Apperhand SDK advertising data request - Counterclank (more info ...)misc-activity    URL
21171APP-DETECT Thunder p2p application activity detection (more info ...)policy-violation    URL
21172APP-DETECT Thunder p2p application activity detection (more info ...)policy-violation    URL
21173FILE-EXECUTABLE APP-CONTROL Thunder p2p application download detection (more info ...)policy-violation    URL
21175MALWARE-CNC User-Agent known malicious user-agent string Win32 Amti (more info ...)trojan-activity    URL
21176PUA-ADWARE Win32.WindowsOptimizationAndSecurity outbound connection (more info ...)trojan-activity    URL
21177MALWARE-CNC Win.Trojan.Ganipin.A inbound connection (more info ...)trojan-activity    URL
21178MALWARE-CNC Win.Trojan.Downloader Win.Trojan.Chekafe.A variant outbound connection (more info ...)trojan-activity    URL
21179MALWARE-CNC Win.Trojan.Coofus.RFM variant outbound connection (more info ...)trojan-activity    URL
21180MALWARE-CNC Worm.Win32.Magania.clfv variant outbound connection (more info ...)trojan-activity    URL
21181MALWARE-CNC Win.Trojan.Agent.czgu variant outbound connection (more info ...)trojan-activity    URL
21182MALWARE-CNC Win.Trojan.MeSub.ac variant outbound connection (more info ...)trojan-activity    URL
21183MALWARE-CNC Win.Trojan.Agent.alfu variant outbound connection (more info ...)trojan-activity    URL
21184PUA-ADWARE Internet Security 2010 outbound connection (more info ...)trojan-activity    URL
21185MALWARE-CNC Worm.Win32.Kufgal.A inbound connection (more info ...)trojan-activity    URL
21186SERVER-ORACLE MDSYS drop table trigger injection attempt (more info ...)attempted-admin 2008-3979 33177  
21187MALWARE-CNC Win.Trojan.Xlahlah.A variant outbound connection (more info ...)trojan-activity    URL
21188MALWARE-CNC User-Agent known malicious user-agent string API Guide test program (more info ...)trojan-activity    URL
21192MALWARE-CNC Win.Trojan.Syswrt.dvd variant outbound connection (more info ...)trojan-activity    URL
21193MALWARE-CNC Win.Trojan.Dalbot.A variant outbound connection (more info ...)trojan-activity    URL
21194MALWARE-CNC Win.Trojan.Wealwedst.A variant outbound connection (more info ...)trojan-activity    URL
21195MALWARE-CNC Win.Trojan.Protux.B variant outbound connection (more info ...)trojan-activity    URL
21196MALWARE-CNC Win.Trojan.Caphaw.A variant outbound connection (more info ...)trojan-activity    URL
21197MALWARE-CNC Win.Trojan.Caphaw.A variant outbound connection (more info ...)trojan-activity    URL
21198MALWARE-CNC Win.Trojan.Qinubot.A variant outbound connection (more info ...)trojan-activity    URL
21199MALWARE-CNC Win.Trojan.Qinubot.A variant outbound connection (more info ...)trojan-activity    URL
21200MALWARE-CNC Win.Trojan.Yakes.cmu variant outbound connection (more info ...)trojan-activity    URL
21201MALWARE-CNC Win.Trojan.Yakes.cmu variant outbound connection (more info ...)trojan-activity    URL
21202MALWARE-CNC Win.Trojan.Scapzilla.A variant outbound connection (more info ...)trojan-activity    URL
21203MALWARE-CNC Virus Win.Trojan.Induc.B variant outbound connection (more info ...)trojan-activity    URL
21204MALWARE-CNC Virus Win.Trojan.Induc.B variant outbound connection (more info ...)trojan-activity    URL
21205MALWARE-CNC Virus Win.Trojan.Induc.B variant outbound connection (more info ...)trojan-activity    URL
21206MALWARE-CNC User-Agent known malicious user-agent string Aldi Bot (more info ...)trojan-activity    URL
21207MALWARE-CNC Win.Trojan.Dekara.A variant outbound connection (more info ...)trojan-activity    URL
21208MALWARE-CNC Win.Trojan.RShot.brw variant outbound connection (more info ...)trojan-activity    URL
21209MALWARE-CNC Win.Trojan.Enviserv.A variant outbound connection (more info ...)trojan-activity    URL
21210MALWARE-CNC Win.Trojan.Rallovs.A variant outbound connection (more info ...)trojan-activity    URL
21211MALWARE-CNC Win.Trojan.Banker.slrj variant outbound connection (more info ...)trojan-activity    URL
21212MALWARE-CNC Win.Trojan.Hupigon.nkor variant outbound connection (more info ...)trojan-activity    URL
21213MALWARE-CNC Worm.Win32.Cridex.B variant outbound connection (more info ...)trojan-activity    URL
21215MALWARE-CNC Win.Trojan.Banker.Am variant outbound connection (more info ...)trojan-activity    URL
21216MALWARE-CNC Win.Trojan.Banker.Am variant outbound connection (more info ...)trojan-activity    URL
21217MALWARE-CNC Win.Trojan.Banker.Am variant outbound connection (more info ...)trojan-activity    URL
21218MALWARE-CNC Win.Trojan.Sodager.C variant outbound connection (more info ...)trojan-activity    URL
21219MALWARE-CNC Win.Trojan.Sysckbc variant outbound connection (more info ...)trojan-activity    URL
21220MALWARE-CNC Win.Trojan.Susnatache.A inbound connection (more info ...)trojan-activity    URL
21221MALWARE-CNC Win.Trojan.Susnatache.A variant outbound connection (more info ...)trojan-activity    URL
21222MALWARE-CNC Win.Trojan.Kcahneila.A variant outbound connection (more info ...)trojan-activity    URL
21223MALWARE-CNC Win.Trojan.Gyplit.A variant outbound connection (more info ...)trojan-activity    URL
21224MALWARE-CNC Win.Trojan.MacOS.DevilRobber.A variant outbound connection (more info ...)trojan-activity    URL
21225MALWARE-CNC User-Agent known malicious user-agent string Flag (more info ...)trojan-activity    URL
21226MALWARE-CNC Win.Trojan.Louisdreyfu.A variant outbound connection (more info ...)trojan-activity    URL
21227MALWARE-CNC Win.Trojan.Bulknet variant outbound connection (more info ...)trojan-activity    URL
21228MALWARE-CNC Win.Trojan.Cerberat variant outbound connection (more info ...)trojan-activity    URL
21229MALWARE-CNC Win.Trojan.Synljdos variant outbound connection (more info ...)trojan-activity    URL
21230MALWARE-CNC Win.Trojan.Betad variant outbound connection (more info ...)trojan-activity    URL
21231MALWARE-CNC Win.Trojan.Bedobot variant outbound connection (more info ...)trojan-activity    URL
21232SERVER-OTHER Remote Desktop Protocol brute force attempt (more info ...)misc-activity 2015-0079   URL
21235SERVER-WEBAPP LOCK WebDAV Stack Buffer Overflow attempt (more info ...)attempted-admin 2003-0109 7116  URL
21239MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
21240MALWARE-CNC Win.Trojan.MsUpdater variant outbound connection (more info ...)trojan-activity    URL
21241MALWARE-CNC Win.Trojan.MsUpdater initial variant outbound connection (more info ...)trojan-activity    URL
21242MALWARE-CNC Win.Trojan.MsUpdater variant outbound connection (more info ...)trojan-activity    URL
21246MALWARE-CNC User-Agent known malicious user-agent string DataCha0s (more info ...)network-scan    URL
21248SERVER-OTHER multiple vendors host buffer overflow attempt (more info ...)web-application-attack 2013-4115 6870  
21249MALWARE-CNC Win.Trojan.VBasddsa.A runtime traffic detected (more info ...)trojan-activity    URL
21250MALWARE-CNC Win.Trojan.VBasddsa.A runtime traffic detected (more info ...)trojan-activity    URL
21251MALWARE-CNC Win.Trojan.Sirefef.P variant outbound connection (more info ...)trojan-activity    URL
21252MALWARE-CNC Win.Trojan.Sirefef.P variant outbound connection (more info ...)trojan-activity    URL
21254FILE-PDF Foxit Reader createDataObject file write attempt (more info ...)attempted-user    URL
21257MALWARE-CNC URI - known scanner tool muieblackcat (more info ...)network-scan    URL
21258INDICATOR-SHELLCODE Feng-Shui heap grooming using Oleaut32 (more info ...)shellcode-detect    URL
21261SERVER-OTHER Xitami if-modified-since header buffer overflow attempt (more info ...)attempted-user 2007-5067 25772  
21263SERVER-OTHER Embarcadero Interbase connect request buffer overflow attempt (more info ...)misc-attack    URL
21265INDICATOR-SHELLCODE Piecemeal exploit and shellcode construction (more info ...)shellcode-detect    URL
21266MALWARE-CNC User-Agent known malicious user-agent string Morfeus Scanner (more info ...)network-scan    
21267POLICY-OTHER TRENDnet IP Camera anonymous access attempt (more info ...)policy-violation    URL
21269MALWARE-CNC Win.Trojan.Cycbot variant outbound connection (more info ...)trojan-activity    URL
21270SERVER-WEBAPP Devellion CubeCart multiple parameter XSS vulnerability (more info ...)web-application-attack    URL
21273MALWARE-CNC Win.Trojan.Tusha variant runtime traffic detected (more info ...)trojan-activity    URL
21274MALWARE-CNC Win.Trojan.Tusha variant runtime traffic detected (more info ...)trojan-activity    URL
21275MALWARE-CNC Hupigon.hddn runtime traffic detected (more info ...)trojan-activity    URL
21276MALWARE-CNC Hupigon.hddn install time traffic detected (more info ...)trojan-activity    URL
21277MALWARE-CNC Win.Trojan.Shexie.A runtime traffic detected (more info ...)trojan-activity    URL
21278MALWARE-CNC User-Agent known malicious user-agent string Google Bot (more info ...)trojan-activity    URL
21279MALWARE-CNC Win.Trojan.Kbot.s runtime traffic detected (more info ...)trojan-activity    URL
21280MALWARE-CNC Win32 Turkojan.C runtime traffic detected (more info ...)trojan-activity    URL
21294MALWARE-CNC Win.Trojan.Bancodor.be runtime traffic detected (more info ...)trojan-activity    URL
21295FILE-IDENTIFY FON file attachment detected (more info ...)misc-activity    
21296FILE-IDENTIFY FON file attachment detected (more info ...)misc-activity    
21303MALWARE-CNC Win32 Initor.ag runtime traffic detected (more info ...)trojan-activity    URL
21306MALWARE-CNC Win.Trojan.Spyeye variant outbound connectivity check (more info ...)trojan-activity    URL
21311MALWARE-CNC Win.Trojan.Dofoil variant outbound connection (more info ...)trojan-activity    URL
21313MALWARE-CNC Win.Trojan.Dofoil variant outbound connection (more info ...)trojan-activity    URL
21314SERVER-WEBAPP HP Insight Diagnostics XSS attempt (more info ...)web-application-attack 2010-3003   
21315SERVER-OTHER Quest NetVault SmartDisk libnvbasics.dll DOS attempt (more info ...)denial-of-service    URL
21317FILE-OTHER BACnet OPC client csv file buffer overflow attempt (more info ...)attempted-user 2010-4740 43289  
21318MALWARE-CNC Win.Trojan.FakeAV TDSS/PurpleHaze variant outbound connection - base64 encoded (more info ...)trojan-activity    URL
21319FILE-OTHER Multiple products request for version.dll over SMB attempt (more info ...)attempted-user 2016-6804   URL
21322FILE-OTHER Multiple products version.dll dll-load exploit attempt (more info ...)attempted-user 2016-6804   URL
21327MALWARE-CNC User-Agent ASafaWeb Scan (more info ...)network-scan    URL
21328SERVER-OTHER Synergy clipboard format server integer overflow attempt (more info ...)attempted-user    
21329SERVER-OTHER Synergy clipboard format client integer overflow attempt (more info ...)attempted-user    
21330SERVER-OTHER Synergy clipboard format server integer overflow attempt (more info ...)attempted-user    
21331SERVER-OTHER Synergy clipboard format client integer overflow attempt (more info ...)attempted-user    
21332APP-DETECT Synergy network kvm usage detected (more info ...)attempted-admin    URL
21333SERVER-WEBAPP Openswan/Strongswan Pluto IKE daemon ISAKMP DPD malformed packet DOS attempt (more info ...)attempted-dos 2009-0790 34296  
21334SERVER-WEBAPP Openswan/Strongswan Pluto IKE daemon ISAKMP DPD malformed packet DOS attempt (more info ...)attempted-dos 2009-0790 34296  
21351SERVER-OTHER IBM Tivoli kuddb2 denial of service attempt (more info ...)attempted-dos 2010-0472   
21359MALWARE-CNC Win.Trojan.VB.jju runtime traffic detected (more info ...)trojan-activity    URL
21360MALWARE-CNC Win32 Agent.dbzx runtime traffic detected (more info ...)trojan-activity    URL
21361MALWARE-CNC Worm.Win32.TDownland.ca runtime traffic detected (more info ...)trojan-activity    URL
21362MALWARE-CNC Win.Trojan.TDSS.aa runtime traffic detected (more info ...)trojan-activity    URL
21364MALWARE-CNC DOQ.gen.y RUNTIME traffic detected (more info ...)trojan-activity    URL
21365MALWARE-CNC DOQ.gen.y RUNTIME traffic detected (more info ...)trojan-activity    URL
21366MALWARE-CNC DOQ.gen.y INSTALL traffic detected (more info ...)trojan-activity    URL
21367MALWARE-CNC Win32 VB.abcl runtime traffic detected (more info ...)trojan-activity    URL
21368MALWARE-CNC Win.Trojan.Wallop.de runtime traffic detected (more info ...)trojan-activity    URL
21369MALWARE-CNC Win.Trojan.Wallop.de runtime traffic detected (more info ...)trojan-activity    URL
21370SERVER-SAMBA Samba name mangling buffer overflow attempt (more info ...)attempted-admin 2004-0686 10781  
21372MALWARE-CNC Malware Defense runtime traffic detected (more info ...)trojan-activity    URL
21373MALWARE-CNC Malware Defense runtime traffic detected (more info ...)trojan-activity    URL
21374MALWARE-CNC Win.Trojan.Bifrose.EF runtime traffic detected (more info ...)trojan-activity    URL
21375SERVER-WEBAPP Remote Execution Backdoor Attempt Against Horde (more info ...)web-application-attack 2012-0209   URL
21376MALWARE-CNC Win.Trojan.Microjoin activity detected (more info ...)trojan-activity    URL
21379MALWARE-CNC Win.Trojan.Genome.Amqj runtime traffic detected (more info ...)trojan-activity    URL
21380MALWARE-CNC User-Agent known malicious user-agent string - QvodDown (more info ...)trojan-activity    URL
21381MALWARE-CNC Win.Trojan.Dialer.ngb runtime traffic detected (more info ...)trojan-activity    URL
21382MALWARE-CNC Win.Trojan.Nuqel.Q host setting3.yeahost.com runtime traffic detected (more info ...)trojan-activity    URL
21383MALWARE-CNC Win.Trojan.Nuqel.Q host 9999mb.com runtime traffic detected (more info ...)trojan-activity    URL
21384MALWARE-CNC Win.Trojan.Nuqel.Q host freewebs.com runtime traffic detected (more info ...)trojan-activity    URL
21386MALWARE-CNC Win.Trojan.Wadolin.A runtime traffic detected (more info ...)trojan-activity    URL
21390MALWARE-CNC Win.Trojan.Agobot.dl runtime traffic detected (more info ...)trojan-activity    URL
21391MALWARE-CNC Win.Trojan.Agent.dcac runtime traffic detected (more info ...)trojan-activity    URL
21393FILE-MULTIMEDIA Magix Musik Maker 16 buffer overflow attempt (more info ...)attempted-user    
21397FILE-MULTIMEDIA MicroP mppl stack buffer overflow (more info ...)trojan-activity    
21398FILE-IDENTIFY MPPL file download request (more info ...)misc-activity    
21400MALWARE-CNC Win.Trojan.Kenzor.B variant outbound connection (more info ...)trojan-activity    URL
21401MALWARE-CNC Win.Trojan.Kenzor.B variant outbound connection (more info ...)trojan-activity    URL
21402MALWARE-CNC Win.Trojan.Ponfoy.A variant outbound connection (more info ...)trojan-activity    URL
21403MALWARE-CNC Worm.Win32.Vobfus.DL variant outbound connection (more info ...)trojan-activity    URL
21404MALWARE-CNC Worm.Win32.Vobfus.DL variant outbound connection cont (more info ...)trojan-activity    URL
21413FILE-OTHER PeaZip command injection attempt (more info ...)attempted-user 2009-2261   
21416MALWARE-CNC Win.Trojan.Bankpatch authentication string detected (more info ...)trojan-activity    URL
21417FILE-PDF hostile PDF associated with Laik exploit kit (more info ...)trojan-activity    
21418MALWARE-CNC Win.Trojan.FareIt variant outbound connection (more info ...)trojan-activity    URL
21424MALWARE-CNC Win.Trojan.Ghodow.A connect to cnc (more info ...)trojan-activity    URL
21425MALWARE-CNC Win.Trojan.Ghodow.A exe file download (more info ...)trojan-activity    URL
21426MALWARE-CNC Win.Trojan.Scar variant outbound connection (more info ...)trojan-activity    URL
21427MALWARE-CNC Win.Trojan.Delf variant outbound connection (more info ...)trojan-activity    
21428MALWARE-CNC Win.Trojan.Generic-24 variant outbound connection (more info ...)trojan-activity    URL
21430MALWARE-CNC Win.Trojan.BeeOne runtime traffic detected (more info ...)trojan-activity    URL
21431FILE-PDF Possible malicious pdf - new pdf exploit (more info ...)attempted-user    
21432FILE-IDENTIFY MPPL file attachment detected (more info ...)misc-activity    
21433FILE-IDENTIFY MPPL file attachment detected (more info ...)misc-activity    
21434MALWARE-CNC Win.Trojan.Mentor variant outbound connection (more info ...)trojan-activity    URL
21435MALWARE-CNC Win.Trojan.Mentor inbound connection - post infection (more info ...)trojan-activity    URL
21436MALWARE-CNC Win.Trojan.Startpage variant outbound connection (more info ...)trojan-activity    URL
21440MALWARE-CNC Win.Trojan.Murofet variant outbound connection (more info ...)trojan-activity    URL
21441MALWARE-CNC Win.Trojan.Delf variant outbound connection (more info ...)trojan-activity    URL
21442MALWARE-CNC URI request for known malicious URI - base64 encoded (more info ...)trojan-activity    URL
21444MALWARE-CNC Win.Trojan.TDSS variant outbound connection (more info ...)trojan-activity    URL
21448MALWARE-CNC Win.Trojan.Webmoner.zu connect to server (more info ...)trojan-activity    URL
21449MALWARE-CNC Trojan-Downloader.Win32.Obitel install (more info ...)trojan-activity    URL
21450MALWARE-CNC Trojan-Downloader.Win32.Obitel connect to cnc server (more info ...)trojan-activity    URL
21451MALWARE-CNC Win.Trojan.Agent.djvk malicious hosts file download (more info ...)trojan-activity    URL
21452MALWARE-CNC Win.Trojan.Agent.djvk connect to server (more info ...)trojan-activity    URL
21454MALWARE-CNC Win.Trojan.Banbra.vec variant outbound connection (more info ...)trojan-activity    URL
21455MALWARE-CNC User-Agent known malicious user-agent string psi (more info ...)trojan-activity    URL
21463MALWARE-CNC Win.Trojan.Bibei variant inbound connection (more info ...)trojan-activity    URL
21464MALWARE-CNC Downloader-CEW.b runtime traffic detected (more info ...)trojan-activity    URL
21465SERVER-WEBAPP HTTP response splitting attempt (more info ...)attempted-user    
21466MALWARE-CNC Autorun.BDS runtime traffic detected (more info ...)trojan-activity    URL
21467MALWARE-CNC Win.Trojan.IRCBot variant outbound connection (more info ...)trojan-activity    URL
21468MALWARE-CNC Win.Trojan.Dama variant outbound connection (more info ...)trojan-activity    URL
21469MALWARE-CNC User-Agent known malicious user-agent string 1234567890 (more info ...)trojan-activity    URL
21470MALWARE-CNC Win.Trojan.Krap.Gy connect to server (more info ...)trojan-activity    URL
21471MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
21472MALWARE-CNC Win.Trojan.Delf.tzp download (more info ...)trojan-activity    URL
21473MALWARE-CNC Win.Trojan.GameThief variant outbound connection (more info ...)trojan-activity    URL
21474MALWARE-CNC Win.Trojan.Lancafdo.A variant outbound connection (more info ...)trojan-activity    URL
21475MALWARE-CNC User-Agent known malicious user-agent string core-project (more info ...)misc-activity    
21476MALWARE-CNC User-Agent known malicious user agent YZF (more info ...)trojan-activity    URL
21477MALWARE-CNC Win.Trojan.Noobot variant outbound connection (more info ...)trojan-activity    URL
21478FILE-IDENTIFY CHM file attachment detected (more info ...)misc-activity    URL
21479FILE-IDENTIFY CHM file attachment detected (more info ...)misc-activity    URL
21483PROTOCOL-SCADA Moxa Device Manager buffer overflow attempt (more info ...)attempted-user 2010-4741   URL
21485SERVER-OTHER EMC RepliStor denial of service attempt (more info ...)attempted-dos 2009-3744   
21486MALWARE-CNC Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity    URL
21487MALWARE-CNC Win.Trojan.Palevo variant outbound connection (more info ...)trojan-activity    URL
21490PROTOCOL-SCADA General Electric d20me configuration retrieval attempt (more info ...)attempted-recon    URL
21491PROTOCOL-SCADA Sielco Sistemi Winlog Pro stack buffer overflow attempt (more info ...)attempted-admin 2011-0517 45813  
21494PROTOCOL-SCADA General Electric D20ME backdoor attempt (more info ...)attempted-admin    URL
21495MALWARE-CNC Win.Trojan.Vilsel variant outbound connection (more info ...)trojan-activity    URL
21496MALWARE-CNC Win.Trojan.Saeeka variant outbound connection (more info ...)trojan-activity    URL
21497MALWARE-CNC Win.Trojan.Saeeka variant outbound connection (more info ...)trojan-activity    URL
21502MALWARE-CNC Win.Trojan.VBbot.V connect to server (more info ...)trojan-activity    URL
21511MALWARE-CNC Win.Trojan.Vaxpy variant outbound connection (more info ...)trojan-activity    URL
21512MALWARE-BACKDOOR Win.Backdoor.Zegost.B runtime detection (more info ...)trojan-activity    URL
21514MALWARE-CNC Win.Trojan.Banbra connect to server (more info ...)trojan-activity    URL
21516SERVER-WEBAPP JBoss JMX console access attempt (more info ...)attempted-recon 2013-2185   URL
21518MALWARE-CNC Win.Trojan.Agent-59544 connect to server (more info ...)trojan-activity    URL
21520MALWARE-CNC Win.Trojan.Bayrob variant outbound connection (more info ...)trojan-activity    URL
21521MALWARE-CNC Win.Trojan.Bayrob update connection (more info ...)trojan-activity    URL
21523MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
21525MALWARE-CNC Win.Trojan.Downloader variant outbound connection (more info ...)trojan-activity    URL
21526MALWARE-CNC User-Agent known malicious user agent TCYWinHTTPDownload (more info ...)trojan-activity    URL
21527MALWARE-CNC Win.Trojan.Downloader registration connection detection (more info ...)trojan-activity    URL
21528MALWARE-CNC Win.Trojan.Downloader keep-alive connection detection (more info ...)trojan-activity    URL
21538MALWARE-CNC Win.Trojan.Dofoil variant outbound payload request (more info ...)trojan-activity    URL
21540MALWARE-CNC Win.Trojan.Buzus application download (more info ...)trojan-activity    URL
21541MALWARE-CNC Win.Trojan.Buzus connect to server (more info ...)trojan-activity    URL
21542MALWARE-CNC Win.Trojan.Buzus firefox extension download (more info ...)trojan-activity    URL
21543MALWARE-CNC Win.Trojan.Buzus html page download (more info ...)trojan-activity    URL
21547MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
21548MALWARE-CNC Cutwail landing page connection (more info ...)trojan-activity    URL
21551MALWARE-CNC Win.Trojan.Kahn variant outbound connection (more info ...)trojan-activity    URL
21552MALWARE-CNC Win.Trojan.Kahn variant outbound connection (more info ...)trojan-activity    URL
21553MALWARE-CNC Win.Trojan.Agent.cpze connect to server (more info ...)trojan-activity    URL
21557FILE-OTHER Apple OSX ZIP archive shell script execution attempt (more info ...)attempted-user 2006-0848 16736  URL
21562MALWARE-CNC Win.Trojan.Bredolab variant outbound connection (more info ...)trojan-activity    URL
21563MALWARE-CNC Win.Trojan.Kelihos variant outbound connection (more info ...)trojan-activity    URL
21564MALWARE-CNC Win.Trojan.Kelihos variant outbound connection (more info ...)trojan-activity    URL
21565MALWARE-CNC Win.Trojan.Kelihos variant outbound connection (more info ...)trojan-activity    URL
21582FILE-PDF PDF obfuscation attempt (more info ...)attempted-user    URL
21583FILE-PDF Possible malicious pdf detection - qwe123 (more info ...)trojan-activity    
21591MALWARE-CNC User-Agent known Adware user agent Gamevance tl_v (more info ...)trojan-activity    URL
21593MALWARE-CNC Win.Trojan.Dropper variant outbound connection (more info ...)misc-activity    URL
21594SERVER-WEBAPP Gravity GTD objectname parameter injection attempt (more info ...)attempted-admin 2008-5962   
21595OS-MOBILE Android/Nickispy.D initialization request detection (more info ...)trojan-activity    URL
21596OS-MOBILE Android/Nickispy.D initialization response detection (more info ...)trojan-activity    URL
21597OS-MOBILE Android/Nickispy.D sms logging request detection (more info ...)trojan-activity    URL
21598OS-MOBILE Android/Nickispy.D sms logging response detection (more info ...)trojan-activity    URL
21607FILE-OTHER IBM Installation Manager iim uri code execution attempt (more info ...)attempted-user 2009-3518 36549  
21608PROTOCOL-VOIP Digium Asterisk IAX2 call number denial of service (more info ...)attempted-dos 2009-2346   
21609SERVER-WEBAPP SurgeMail webmail.exe page format string exploit attempt (more info ...)web-application-attack 2008-1055 27990  URL
21610MALWARE-CNC Win.Trojan.Refroso.azyg variant outbound connection (more info ...)trojan-activity    URL
21615FILE-IDENTIFY WMF file attachment detected (more info ...)misc-activity    
21616FILE-IDENTIFY WMF file attachment detected (more info ...)misc-activity    
21617FILE-IDENTIFY RT file attachment detected (more info ...)misc-activity    
21618FILE-IDENTIFY RT file attachment detected (more info ...)misc-activity    
21621FILE-IDENTIFY AVI file magic detected (more info ...)misc-activity    
21622MALWARE-CNC Win.Trojan.Georbot variant outbound connection (more info ...)trojan-activity    URL
21629FILE-OTHER ELF file parsing in different antivirus evasion attempt (more info ...)bad-unknown 2012-1431   URL
21630FILE-OTHER ELF file parsing in different antivirus evasion attempt (more info ...)bad-unknown 2012-1430   URL
21632MALWARE-CNC Win.Trojan.Ransom variant outbound connection (more info ...)trojan-activity    URL
21635MALWARE-CNC Win.Trojan.Phdet.gen.A variant outbound connection (more info ...)trojan-activity    URL
21636MALWARE-CNC User-Agent known Adware user agent gbot (more info ...)trojan-activity    URL
21637POLICY-SPAM local user attempted to fill out paypal phishing form (more info ...)suspicious-login    URL
21638MALWARE-CNC Win.Trojan.Aluereon TDSS infection variant outbound connection (more info ...)trojan-activity    URL
21639MALWARE-CNC User-Agent known Adware user agent mus - TDSS related (more info ...)trojan-activity    URL
21641MALWARE-OTHER Possible banking trojan with known banking strings (more info ...)trojan-activity    
21642MALWARE-OTHER Possible malicious jar file download page (more info ...)attempted-user    
21643MALWARE-CNC Win.Trojan.Bredolab variant outbound connection (more info ...)trojan-activity    URL
21644PUA-ADWARE Adware.MediaGetInstaller inbound connection - destination ip infected (more info ...)misc-activity    URL
21645PUA-ADWARE Adware.MediaGetInstaller outbound connection - source ip infected (more info ...)misc-activity    URL
21662SERVER-OTHER Blue Coat Systems WinProxy telnet denial of service attempt (more info ...)attempted-dos 2005-3654   
21669PROTOCOL-VOIP Digium Asterisk missing SIP version denial of service attempt (more info ...)attempted-dos 2014-2154 20835  
21671SERVER-WEBAPP PECL zip URL wrapper buffer overflow attempt (more info ...)attempted-user 2007-1399 22883  URL
21672PROTOCOL-VOIP Digium Asterisk SCCP capabilities response message capabilities count overflow attempt (more info ...)attempted-dos 2007-4280   
21673PROTOCOL-VOIP Digium Asterisk SCCP overly large mem copy attempt (more info ...)attempted-user 2007-3764 24950  
21687FILE-IDENTIFY PLS file attachment detected (more info ...)misc-activity    
21688FILE-IDENTIFY PLS file attachment detected (more info ...)misc-activity    
21691FILE-IDENTIFY SMIL file attachment detected (more info ...)misc-activity    
21692FILE-IDENTIFY SMIL file attachment detected (more info ...)misc-activity    
21693FILE-IDENTIFY FLAC file attachment detected (more info ...)misc-activity    
21694FILE-IDENTIFY FLAC file attachment detected (more info ...)misc-activity    
21695FILE-IDENTIFY SMI file attachment detected (more info ...)misc-activity    
21696FILE-IDENTIFY SMI file attachment detected (more info ...)misc-activity    
21697FILE-IDENTIFY SAMI file attachment detected (more info ...)misc-activity    
21698FILE-IDENTIFY SAMI file attachment detected (more info ...)misc-activity    
21703FILE-IDENTIFY 4XM file attachment detected (more info ...)misc-activity    
21704FILE-IDENTIFY 4XM file attachment detected (more info ...)misc-activity    
21705FILE-IDENTIFY BitTorrent torrent file attachment detected (more info ...)misc-activity    
21706FILE-IDENTIFY BitTorrent torrent file attachment detected (more info ...)misc-activity    
21724FILE-IDENTIFY ANI file download request (more info ...)misc-activity    
21725FILE-IDENTIFY ANI file attachment detected (more info ...)misc-activity    
21726FILE-IDENTIFY ANI file attachment detected (more info ...)misc-activity    
21727FILE-IDENTIFY ANI file magic detection (more info ...)misc-activity    
21742FILE-IDENTIFY Embedded Open Type Font file attachment detected (more info ...)misc-activity    
21743FILE-IDENTIFY Embedded Open Type Font file attachment detected (more info ...)misc-activity    
21748FILE-IDENTIFY HPJ file download request (more info ...)misc-activity    
21749FILE-IDENTIFY HPJ file attachment detected (more info ...)misc-activity    
21750FILE-IDENTIFY HPJ file attachment detected (more info ...)misc-activity    
21751FILE-IDENTIFY HPJ file magic detected (more info ...)misc-activity    
21753PROTOCOL-VOIP Digium Asterisk Management Interface HTTP digest authentication stack buffer overflow attempt (more info ...)attempted-admin    URL
21760MALWARE-CNC Win.Trojan.Swisyn variant outbound connection (more info ...)trojan-activity    URL
21761MALWARE-CNC Win.Trojan.Swisyn variant outbound connection (more info ...)trojan-activity    URL
21762SERVER-WEBAPP Youngzsoft CMailServer CMailCOM buffer overflow attempt (more info ...)attempted-admin 2008-6922 30098  
21767PROTOCOL-VOIP Digium Asterisk IAX2 Channel Driver DoS attempt (more info ...)denial-of-service 2007-3763   
21768PROTOCOL-VOIP Digium Asterisk IAX2 Channel Driver DoS attempt (more info ...)denial-of-service 2007-3763   
21769MALWARE-CNC Win.Trojan.LogonInvader.a variant outbound connection (more info ...)trojan-activity    URL
21782INDICATOR-OBFUSCATION script tag in POST parameters - likely cross-site scripting (more info ...)web-application-attack 2015-1653   URL
21783INDICATOR-OBFUSCATION encoded script tag in POST parameters - likely cross-site scripting (more info ...)web-application-attack    URL
21784INDICATOR-OBFUSCATION encoded script tag in POST parameters - likely cross-site scripting (more info ...)web-application-attack    URL
21802FILE-IDENTIFY HT-MP3Player file download request (more info ...)misc-activity    
21803FILE-IDENTIFY HT-MP3Player file attachment detected (more info ...)misc-activity    
21804FILE-IDENTIFY HT-MP3Player file attachment detected (more info ...)misc-activity    
21805FILE-MULTIMEDIA HT-MP3Player file parsing boundary buffer overflow attempt (more info ...)attempted-user 2009-2485 43811  
21818SERVER-WEBAPP System variable directory traversal attempt - %ALLUSERSPROFILE% (more info ...)attempted-recon    
21819SERVER-WEBAPP System variable directory traversal attempt - %PROGRAMDATA% (more info ...)attempted-recon    
21820SERVER-WEBAPP System variable directory traversal attempt - %APPDATA% (more info ...)attempted-recon    
21821SERVER-WEBAPP System variable directory traversal attempt - %COMMONPROGRAMFILES% (more info ...)attempted-recon    
21822SERVER-WEBAPP System variable directory traversal attempt - %COMMONPROGRAMFILES - x86% (more info ...)attempted-recon    
21823SERVER-WEBAPP System variable directory traversal attempt - %COMSPEC% (more info ...)attempted-recon    
21824SERVER-WEBAPP System variable directory traversal attempt - %HOMEDRIVE% (more info ...)attempted-recon    
21825SERVER-WEBAPP System variable directory traversal attempt - %HOMEPATH% (more info ...)attempted-recon    
21826SERVER-WEBAPP System variable directory traversal attempt - %LOCALAPPDATA% (more info ...)attempted-recon    
21827SERVER-WEBAPP System variable directory traversal attempt - %PROGRAMFILES% (more info ...)attempted-recon    
21828SERVER-WEBAPP System variable directory traversal attempt - %PROGRAMFILES - X86% (more info ...)attempted-recon    
21829SERVER-WEBAPP System variable directory traversal attempt - %SystemDrive% (more info ...)attempted-recon    
21830SERVER-WEBAPP System variable directory traversal attempt - %SystemRoot% (more info ...)attempted-recon    
21831SERVER-WEBAPP System variable directory traversal attempt - %TEMP% (more info ...)attempted-recon    
21832SERVER-WEBAPP System variable directory traversal attempt - %TMP% (more info ...)attempted-recon    
21833SERVER-WEBAPP System variable directory traversal attempt - %USERDATA% (more info ...)attempted-recon    
21834SERVER-WEBAPP System variable directory traversal attempt - %USERNAME% (more info ...)attempted-recon    
21835SERVER-WEBAPP System variable directory traversal attempt - %USERPROFILE% (more info ...)attempted-recon    
21836SERVER-WEBAPP System variable directory traversal attempt - %WINDIR% (more info ...)attempted-recon    
21837SERVER-WEBAPP System variable directory traversal attempt - %PUBLIC% (more info ...)attempted-recon    
21838SERVER-WEBAPP System variable directory traversal attempt - %PSModulePath% (more info ...)attempted-recon    
21839SERVER-WEBAPP System variable in URI attempt - %COMPUTERNAME% (more info ...)attempted-recon    
21840SERVER-WEBAPP System variable in URI attempt - %LOGONSERVER% (more info ...)attempted-recon    
21841SERVER-WEBAPP System variable in URI attempt - %PATH% (more info ...)attempted-recon    
21842SERVER-WEBAPP System variable in URI attempt - %PATHEXT% (more info ...)attempted-recon    
21843SERVER-WEBAPP System variable in URI attempt - %PROMPT% (more info ...)attempted-recon    
21844SERVER-WEBAPP System variable in URI attempt - %USERDOMAIN% (more info ...)attempted-recon    
21848MALWARE-OTHER TDS Sutra - page redirecting to a SutraTDS (more info ...)trojan-activity    URL
21849MALWARE-OTHER TDS Sutra - HTTP header redirecting to a SutraTDS (more info ...)trojan-activity    URL
21852MALWARE-CNC Win.Trojan.Orsam variant outbound connection (more info ...)trojan-activity    URL
21860MALWARE-CNC Phoenix exploit kit post-compromise behavior (more info ...)successful-user 2012-0779   URL
21870FILE-IDENTIFY CNT file attachment detected (more info ...)misc-activity    
21871FILE-IDENTIFY CNT file attachment detected (more info ...)misc-activity    
21877MALWARE-CNC Apple OSX.Sabpub variant outbound connection (more info ...)trojan-activity    URL
21911MALWARE-CNC Aldi variant outbound connection C&C checkin (more info ...)trojan-activity    URL
21912MALWARE-CNC Aldi bot variant outbound connection user-agent (more info ...)trojan-activity    URL
21913SERVER-OTHER EMC data protection advisor DOS attempt (more info ...)attempted-dos    URL
21920SERVER-ORACLE Oracle Outside In CorelDRAW file parser buffer overflow attempt (more info ...)attempted-user 2011-2264   URL
21921SERVER-ORACLE Oracle Outside In CorelDRAW file parser buffer overflow attempt (more info ...)attempted-user 2011-2264   URL
21922FILE-OTHER VLC mms hostname buffer overflow attempt (more info ...)attempted-user 2012-1775   URL
21924PUA-ADWARE Adware.Downware variant outbound connection attempt (more info ...)trojan-activity    URL
21925MALWARE-CNC User-Agent known malicious user agent BOT/0.1 (more info ...)trojan-activity    URL
21934PUA-ADWARE 888Poker install outbound connection attempt (more info ...)trojan-activity    
21936SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100168 (more info ...)unknown    
21944SERVER-OTHER IBM Tivoli Endpoint Manager Web Reports xss attempt (more info ...)attempted-user 2012-0719   URL
21945MALWARE-CNC Win.Trojan.Litmpuca.A variant outbound connection (more info ...)trojan-activity    URL
21946MALWARE-CNC Win.Trojan.Litmpuca.A variant outbound connection (more info ...)trojan-activity    URL
21947MALWARE-CNC Win.Trojan.VicSpy.A variant outbound connection (more info ...)trojan-activity    URL
21958MALWARE-CNC QDIGIT protocol connection to server (more info ...)trojan-activity    URL
21959MALWARE-CNC UPDATE communication protocol connection to server (more info ...)trojan-activity    URL
21960MALWARE-CNC LURK communication protocol connection to server (more info ...)trojan-activity    URL
21961MALWARE-CNC IP2B communication protocol connection to server (more info ...)trojan-activity    URL
21962MALWARE-CNC BB communication protocol connection to server (more info ...)trojan-activity    URL
21963MALWARE-CNC X-Shell 601 communication protocol connection to server (more info ...)trojan-activity    URL
21964MALWARE-CNC Murcy protocol connection to server (more info ...)trojan-activity    URL
21965MALWARE-CNC User-Agent known malicious user agent VB WININET (more info ...)trojan-activity    URL
21966MALWARE-CNC Win.Trojan.Pasmu connect to server (more info ...)trojan-activity    URL
21967MALWARE-BACKDOOR Rebhip.A runtime detection (more info ...)trojan-activity    URL
21968MALWARE-BACKDOOR Win.Backdoor.Rebhip.A variant outbound connection type A (more info ...)trojan-activity    
21969MALWARE-BACKDOOR Win.Backdoor.Rebhip.A variant outbound connection type B (more info ...)trojan-activity    
21970MALWARE-BACKDOOR Win.Backdoor.Zlob.P variant outbound connection (more info ...)trojan-activity    URL
21971MALWARE-BACKDOOR Win.Backdoor.Zlob.P variant inbound connection (more info ...)trojan-activity    URL
21972MALWARE-BACKDOOR Win.Backdoor.ZZSlash variant outbound connection (more info ...)trojan-activity    URL
21973MALWARE-BACKDOOR Win.Backdoor.ZZSlash runtime detection (more info ...)trojan-activity    URL
21974MALWARE-CNC Worm.Expichu variant inbound connection (more info ...)trojan-activity    URL
21975MALWARE-CNC Worm.Expichu variant inbound connection (more info ...)trojan-activity    URL
21976MALWARE-CNC Trojan-Downloader.Win32.Lapurd.D variant outbound connection (more info ...)trojan-activity    URL
21977MALWARE-BACKDOOR Win.Backdoor.Pinit variant outbound connection (more info ...)trojan-activity    URL
21978MALWARE-BACKDOOR Win.Backdoor.Nervos variant outbound connection (more info ...)trojan-activity    
21979MALWARE-BACKDOOR Win.Backdoor.Nervos variant inbound connection (more info ...)trojan-activity    
21980MALWARE-CNC Win.Trojan.Winac variant outbound connection (more info ...)trojan-activity    
21981MALWARE-CNC Win.Trojan.Selvice variant outbound connection (more info ...)trojan-activity    URL
21982MALWARE-CNC Win.Trojan.Insain variant outbound connection (more info ...)trojan-activity    URL
21983MALWARE-CNC Win.Trojan.BamCompiled variant outbound connection (more info ...)trojan-activity    URL
21984MALWARE-CNC Win.Trojan.BamCompiled variant inbound updates (more info ...)trojan-activity    URL
21995MALWARE-CNC Win.Trojan.Dorkbot variant outbound connection (more info ...)trojan-activity    URL
21996MALWARE-CNC Win.Trojan.Dorkbot variant outbound connection (more info ...)trojan-activity    URL
21997MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
21998MALWARE-CNC Win.Trojan.Banload variant outbound connection (more info ...)trojan-activity    URL
22000MALWARE-CNC Win.Worm.amna variant outbound connection (more info ...)trojan-activity    URL
22001MALWARE-CNC Win.Worm.amna variant outbound connection (more info ...)trojan-activity    URL
22029FILE-OTHER Visual Studio DBP file handling buffer overflow attempt (more info ...)attempted-user 2006-1043   URL
22030FILE-OTHER Visual Studio PKP file handling buffer overflow attempt (more info ...)attempted-user 2006-1043   URL
22031FILE-OTHER Visual Studio SLN file handling buffer overflow attempt (more info ...)attempted-user 2006-1043   URL
22032FILE-OTHER Visual Studio VAP file handling buffer overflow attempt (more info ...)attempted-user 2006-1043   URL
22043FILE-IDENTIFY XM file download request (more info ...)misc-activity    
22044FILE-IDENTIFY XM file attachment detected (more info ...)misc-activity    
22045FILE-IDENTIFY XM file attachment detected (more info ...)misc-activity    
22046FILE-IDENTIFY XM file magic detected (more info ...)misc-activity    
22047MALWARE-CNC Win.Trojan.Jokbot variant outbound connection (more info ...)trojan-activity    URL
22048MALWARE-CNC Win.Trojan.Zeus P2P outbound connection (more info ...)trojan-activity    URL
22053MALWARE-CNC Win.Trojan.Insomnia variant inbound connection - post infection (more info ...)trojan-activity    URL
22054MALWARE-CNC Win.Trojan.Prorat variant outbound connection (more info ...)trojan-activity    URL
22056MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
22058MALWARE-CNC Win.Trojan.Kbot variant outbound connection (more info ...)trojan-activity    URL
22059MALWARE-CNC Win.Trojan.Downloader variant outbound connection (more info ...)trojan-activity    URL
22060MALWARE-CNC Win.Trojan.Fepgul variant outbound connection (more info ...)trojan-activity    URL
22062MALWARE-CNC Win.Trojan.Winpawr variant outbound connection (more info ...)trojan-activity    URL
22065MALWARE-CNC Win.Trojan.Zeprox variant outbound connection (more info ...)trojan-activity    URL
22098INDICATOR-COMPROMISE hex-encoded create_function detected (more info ...)attempted-user    
22099MALWARE-CNC Win.Trojan.Piroxcc variant outbound connection (more info ...)trojan-activity    URL
22100MALWARE-CNC Win.Trojan.Midhos variant outbound connection (more info ...)trojan-activity    URL
22103MALWARE-CNC Win.Trojan.Coswid.klk variant outbound connection (more info ...)trojan-activity    URL
22104FILE-IMAGE libpng chunk decompression integer overflow attempt (more info ...)attempted-admin 2011-3045 52453  
22105FILE-IMAGE libpng chunk decompression integer overflow attempt (more info ...)attempted-admin 2011-3045 52453  
22106FILE-IMAGE libpng chunk decompression integer overflow attempt (more info ...)attempted-admin 2011-3045 52453  
22107FILE-IMAGE libpng chunk decompression integer overflow attempt (more info ...)attempted-admin 2011-3045 52453  
22108FILE-IMAGE libpng chunk decompression integer overflow attempt (more info ...)attempted-admin 2011-3045 52453  
22109FILE-IMAGE libpng chunk decompression integer overflow attempt (more info ...)attempted-admin 2011-3045 52453  
22110SERVER-MAIL Metamail format string exploit attempt (more info ...)attempted-admin 2004-0104 9692  
22111SERVER-MAIL Metamail format string exploit attempt (more info ...)attempted-admin 2004-0104 9692  
22112SERVER-MAIL Metamail format string exploit attempt (more info ...)attempted-admin 2004-0104 9692  
22113SERVER-MAIL Metamail header length exploit attempt (more info ...)attempted-admin 2004-0104 9692  
22114SERVER-MAIL Metamail header length exploit attempt (more info ...)attempted-admin 2004-0104 9692  
22115SERVER-MAIL Metamail header length exploit attempt (more info ...)attempted-admin 2004-0104 9692  
22937MALWARE-CNC Win.Trojan.Proxyier variant outbound connection (more info ...)trojan-activity    URL
22939MALWARE-CNC User-Agent known malicious user agent RAbcLib (more info ...)trojan-activity    URL
22940INDICATOR-COMPROMISE Win32.Virut web propagation detection (more info ...)trojan-activity    URL
22941FILE-PDF Possible malicious PDF detection - qweqwe= (more info ...)trojan-activity    
22943FILE-IDENTIFY NAB file download request (more info ...)misc-activity    
22944FILE-IDENTIFY NAB file attachment detected (more info ...)misc-activity    
22945FILE-IDENTIFY NAB file attachment detected (more info ...)misc-activity    
22946FILE-IDENTIFY NAB file magic detected (more info ...)misc-activity    
22948PROTOCOL-VOIP Avaya WinPDM header buffer overflow attempt (more info ...)attempted-admin  47947  
22950SERVER-WEBAPP EXIF header parsing integer overflow attempt big endian (more info ...)web-application-attack 2011-4566   
22951SERVER-WEBAPP EXIF header parsing integer overflow attempt little endian (more info ...)web-application-attack 2011-4566   
22953MALWARE-TOOLS Hulk denial of service attempt (more info ...)attempted-dos    URL
22955FILE-IDENTIFY AMF file attachment detected (more info ...)misc-activity    
22956FILE-IDENTIFY AMF file attachment detected (more info ...)misc-activity    
22969FILE-IDENTIFY remote desktop configuration file attachment detected (more info ...)misc-activity    URL
22970FILE-IDENTIFY remote desktop configuration file attachment detected (more info ...)misc-activity    URL
23004PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime stack buffer overflow attempt (more info ...)attempted-admin 2011-4875   URL
23005PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime stack buffer overflow attempt (more info ...)attempted-admin 2011-4875   URL
23006PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime stack buffer overflow attempt (more info ...)attempted-admin 2011-4875   URL
23007PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime stack buffer overflow attempt (more info ...)attempted-admin 2011-4875   URL
23011FILE-IDENTIFY Collada file download request (more info ...)misc-activity    
23012FILE-IDENTIFY Collada file attachment detected (more info ...)misc-activity    
23013FILE-IDENTIFY Collada file attachment detected (more info ...)misc-activity    
23016INDICATOR-COMPROMISE base64-encoded c99shell download (more info ...)trojan-activity    URL
23017INDICATOR-COMPROMISE c99shell comment (more info ...)trojan-activity    
23018INDICATOR-OBFUSCATION eval of base64-encoded data (more info ...)trojan-activity    URL
23019MALWARE-CNC User-Agent known malicious user agent - Flame malware (more info ...)trojan-activity    URL
23043FILE-PDF Unknown malicious PDF - CreationDate (more info ...)trojan-activity    
23044FILE-PDF Unknown malicious PDF - CreationDate (more info ...)trojan-activity    
23045FILE-PDF Unknown malicious PDF - Title (more info ...)trojan-activity    
23046SERVER-WEBAPP Oracle GlassFish Enterprise server cross site scripting attempt (more info ...)web-application-attack 2012-0551   URL
23047SERVER-WEBAPP Oracle GlassFish Enterprise server cross site scripting attempt (more info ...)web-application-attack 2012-0551   URL
23051MALWARE-CNC Dybalom.A runtime traffic detected (more info ...)trojan-activity    URL
23052SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt (more info ...)unknown    
23053SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt (more info ...)unknown    
23097SERVER-OTHER IBM solidDB SELECT statement denial of service attempt (more info ...)denial-of-service 2011-4890 51629  URL
23099SERVER-OTHER SAP NetWeaver Dispatcher DiagTraceHex denial of service attempt (more info ...)attempted-dos 2012-2612 53424  
23103MALWARE-CNC Win.Trojan.Bublik variant outbound connection (more info ...)trojan-activity    URL
23104MALWARE-CNC Win.Trojan.Scar variant outbound connection (more info ...)trojan-activity    URL
23109MALWARE-CNC Win.Trojan.Lolbot variant outbound connection (more info ...)trojan-activity    URL
23112SERVER-OTHER SAP NetWeaver Dispatcher denial of service attempt (more info ...)attempted-dos 2012-2514   URL
23113INDICATOR-OBFUSCATION eval gzinflate base64_decode call - likely malicious (more info ...)misc-activity    URL
23140FILE-PDF Unknown Malicious PDF - CreationDate (more info ...)attempted-user    
23152FILE-OTHER OpenType Font file integer overflow attempt (more info ...)attempted-user 2010-2741   URL
23153FILE-OTHER OpenType Font file integer overflow attempt (more info ...)attempted-user 2010-2741   URL
23154FILE-OTHER OpenType Font file integer overflow attempt (more info ...)attempted-user 2010-2741   URL
23155FILE-OTHER OpenType Font file integer overflow attempt (more info ...)attempted-user 2010-2741   URL
23173OS-MOBILE Android Zitmo trojan command and control channel traffic (more info ...)trojan-activity    URL
23176MALWARE-CNC Donbot.A runtime traffic detected (more info ...)trojan-activity    URL
23179INDICATOR-COMPROMISE script before DOCTYPE possible malicious redirect attempt (more info ...)web-application-attack    
23208PROTOCOL-VOIP Digium Asterisk Manager Interface initial banner (more info ...)misc-activity    
23209PROTOCOL-VOIP Digium Asterisk Manager command shell execution attempt (more info ...)policy-violation 2012-2414 53206  URL
23210PROTOCOL-VOIP Digium Asterisk Manager command shell execution attempt (more info ...)policy-violation 2012-2414 53206  URL
23214MALWARE-CNC Win.Trojan.Waprox.A variant outbound connection (more info ...)trojan-activity    URL
23215MALWARE-CNC Win.Trojan.Waprox.A variant outbound connection (more info ...)trojan-activity    URL
23234MALWARE-CNC Frethog.MK runtime traffic detected (more info ...)trojan-activity    URL
23235MALWARE-CNC PBin.A runtime traffic detected (more info ...)trojan-activity    URL
23242MALWARE-CNC Win.Trojan.Banker.boxg connect to cnc server (more info ...)trojan-activity    URL
23244MALWARE-CNC Win.Trojan.Kuluoz variant outbound connection (more info ...)trojan-activity    URL
23246PUA-ADWARE Wajam Monitizer url outbound connection - post install (more info ...)trojan-activity    URL
23247PUA-ADWARE Wajam Monitizer outbound connection - post install (more info ...)trojan-activity    URL
23251MALWARE-CNC Win.Trojan.Spyeye variant outbound connection (more info ...)trojan-activity    URL
23252MALWARE-CNC MacOS.MacKontrol variant outbound connection (more info ...)trojan-activity    URL
23254MALWARE-CNC Win.Trojan.Delf.CL variant outbound connection (more info ...)trojan-activity    URL
23255MALWARE-CNC Win.Trojan.Duojeen variant outbound connection (more info ...)trojan-activity    URL
23257MALWARE-CNC Win.Trojan.Duojeen variant outbound connection (more info ...)trojan-activity    URL
23258SERVER-WEBAPP LANDesk Thinkmanagement Suite ServerSetup directory traversal attempt (more info ...)attempted-user 2012-1196 52023  
23259SERVER-WEBAPP LANDesk Thinkmanagement Suite ServerSetup directory traversal attempt (more info ...)attempted-user 2012-1195 52023  
23260SERVER-WEBAPP SAP NetWeaver cross site scripting attempt (more info ...)web-application-attack    URL
23261MALWARE-CNC known command and control traffic - Pushbot (more info ...)trojan-activity    URL
23262MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
23306MALWARE-CNC Win.Trojan.Stealer connect to server (more info ...)trojan-activity    URL
23307MALWARE-CNC Win.Trojan.Dropper connect to server (more info ...)trojan-activity    URL
23308MALWARE-CNC Win.Trojan.Downloader.Bucriv variant outbound connection (more info ...)trojan-activity    URL
23309FILE-EXECUTABLE Portable Executable multiple antivirus evasion attempt (more info ...)attempted-user 2012-1436   
23310FILE-EXECUTABLE Portable Executable multiple antivirus evasion attempt (more info ...)attempted-user 2012-1435   
23311FILE-EXECUTABLE Portable Executable multiple antivirus evasion attempt (more info ...)attempted-user 2012-1434   
23312FILE-EXECUTABLE Portable Executable multiple antivirus evasion attempt (more info ...)attempted-user 2012-1433   
23313FILE-EXECUTABLE Portable Executable multiple antivirus evasion attempt (more info ...)attempted-user 2012-1432   
23317MALWARE-CNC Win.Trojan.Dropper initial variant outbound connection (more info ...)trojan-activity    URL
23318FILE-OTHER ELF multiple antivirus evasion attempts (more info ...)attempted-user 2012-1429   
23323FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1420   
23324FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1426   
23325FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1425   
23326FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1424   
23327FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1423   
23328FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1422   
23329FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1421   
23331MALWARE-CNC Win.Trojan.Mybot variant outbound connection (more info ...)trojan-activity    
23332MALWARE-CNC Win.Trojan.Dishigy variant outbound connection (more info ...)trojan-activity    
23333MALWARE-CNC Win.Trojan.Banker initial C&C checkin (more info ...)trojan-activity    URL
23334MALWARE-CNC Win.Trojan.Downloader initial C&C checkin (more info ...)trojan-activity    URL
23335MALWARE-CNC Win.Trojan.Swisyn variant outbound connection (more info ...)trojan-activity    URL
23336MALWARE-CNC Linfo.A variant outbound connection (more info ...)trojan-activity    URL
23337MALWARE-CNC Bluenet.A variant outbound connection (more info ...)trojan-activity    URL
23338MALWARE-BACKDOOR Spindest.A runtime detection - initial connection (more info ...)trojan-activity    URL
23339MALWARE-CNC Prier.A variant outbound connection (more info ...)trojan-activity    URL
23340MALWARE-CNC Win.Trojan.Nitol.B variant outbound connection (more info ...)trojan-activity    URL
23342MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
23343MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
23344MALWARE-CNC Win.Trojan.Harvso.A variant outbound connection (more info ...)trojan-activity    URL
23345MALWARE-CNC RunTime Win.Trojan.tchfro.A variant outbound connection (more info ...)trojan-activity    URL
23346FILE-OTHER Oracle outside in Lotus 1-2-3 heap overflow attempt (more info ...)attempted-user 2012-0110   URL
23347FILE-IDENTIFY Lotus file download request (more info ...)misc-activity    
23348FILE-IDENTIFY Lotus file attachment detected (more info ...)misc-activity    
23349FILE-IDENTIFY Lotus file attachment detected (more info ...)misc-activity    
23350MALWARE-OTHER potential clickjacking via css pointer-events attempt (more info ...)policy-violation    URL
23351FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1419   
23357FILE-OTHER ELF multiple antivirus evasion attempts (more info ...)attempted-user 2012-1430   
23358FILE-OTHER TAR multiple antivirus evasion attempt (more info ...)attempted-user 2012-1428   
23369PUA-ADWARE Adware.Phono post infection download attempt (more info ...)trojan-activity    URL
23377MALWARE-CNC Win.Trojan.Sasfis variant outbound connection (more info ...)trojan-activity    URL
23378MALWARE-CNC Win.Trojan.Sasfis variant outbound connection (more info ...)trojan-activity    URL
23379MALWARE-CNC Win.Trojan.Leepload variant outbound connection (more info ...)trojan-activity    URL
23380MALWARE-CNC Win.Trojan.Ventana initial variant outbound connection (more info ...)trojan-activity    URL
23381MALWARE-BACKDOOR Win.Trojan.Thoper.C runtime detection (more info ...)trojan-activity    URL
23382MALWARE-CNC Win.Trojan.SpyEye variant outbound connection (more info ...)trojan-activity    URL
23383MALWARE-CNC Win.Trojan.Chaori.A variant outbound connection (more info ...)trojan-activity    URL
23387MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
23388MALWARE-CNC Win.Trojan.FakeMSN.I variant outbound connection (more info ...)trojan-activity    URL
23391MALWARE-CNC Win.Trojan.Hioles.C variant outbound connection (more info ...)trojan-activity    URL
23392SERVER-OTHER IBM SolidDB redundant where clause DoS attempt (more info ...)attempted-dos 2012-0200   URL
23394MALWARE-CNC Win.Trojan.Vbvoleur.a variant outbound connection (more info ...)trojan-activity    URL
23399MALWARE-CNC Win.Trojan.Govdi.A variant outbound connection (more info ...)trojan-activity    URL
23401SERVER-WEBAPP Oracle GlassFish server REST interface cross site request forgery attempt (more info ...)attempted-user 2012-0550   
23407SERVER-WEBAPP Apple iChat url format string exploit attempt (more info ...)attempted-user 2007-0021 22146  
23435SERVER-MAIL Alt-N MDaemon file attachment directory traversal attempt (more info ...)misc-attack  14400  
23444SERVER-OTHER Flexera FlexNet License Server buffer overflow attempt (more info ...)attempted-admin  52718  URL
23446MALWARE-CNC Win.Trojan.Sojax.A variant outbound connection (more info ...)trojan-activity    URL
23447MALWARE-CNC Win.Trojan.Sojax.A variant outbound connection (more info ...)trojan-activity    URL
23448MALWARE-CNC Win.Worm.Psyokym variant outbound connection (more info ...)trojan-activity    URL
23449MALWARE-CNC Win.Trojan.Servstart.ax variant outbound connection (more info ...)trojan-activity    URL
23450MALWARE-CNC Win.Trojan.McRat connect to server (more info ...)trojan-activity    URL
23451MALWARE-CNC Win.Trojan.RedSip.A variant outbound connection (more info ...)trojan-activity    URL
23456SERVER-OTHER IBM Tivoli name overflow attempt (more info ...)attempted-user 2009-3853   
23460MALWARE-CNC Win.Trojan.Belesak.A variant outbound connection (more info ...)trojan-activity    URL
23466SERVER-WEBAPP IBM System Storage DS storage manager profiler XSS attempt (more info ...)web-application-attack 2012-2172 54112  URL
23467MALWARE-CNC Win.Trojan.Mazben file download (more info ...)trojan-activity    URL
23468MALWARE-CNC Win.Trojan.Dropper variant outbound connection (more info ...)trojan-activity    URL
23469MALWARE-CNC Win.Trojan.Dropper variant outbound connection (more info ...)trojan-activity    URL
23472PUA-ADWARE FakeAV landing page request (more info ...)trojan-activity    URL
23473MALWARE-CNC URI request for runforestrun - JS.Runfore (more info ...)trojan-activity    URL
23474FILE-IDENTIFY PLP file download request (more info ...)misc-activity    
23475FILE-IDENTIFY PLP file attachment detected (more info ...)misc-activity    
23476FILE-IDENTIFY PLP file attachment detected (more info ...)misc-activity    
23477FILE-IDENTIFY PLP file magic detected (more info ...)misc-activity    
23478FILE-OTHER ACDSee FotoSlate PLP file buffer overflow attempt (more info ...)attempted-user 2011-2595 49558  
23479FILE-OTHER ACDSee FotoSlate PLP file buffer overflow attempt (more info ...)attempted-user 2011-2595 49558  
23481INDICATOR-OBFUSCATION hex escaped characters in setTimeout call (more info ...)bad-unknown    URL
23482INDICATOR-OBFUSCATION hex escaped characters in addEventListener call (more info ...)bad-unknown    URL
23483MALWARE-BACKDOOR Win.Backdoor.Georbot file download (more info ...)trojan-activity    URL
23491MALWARE-CNC Win.Trojan.Kura variant outbound connection (more info ...)trojan-activity    URL
23492MALWARE-CNC Win.Trojan.ZeroAccess outbound connection (more info ...)trojan-activity    URL
23493MALWARE-CNC Win.Trojan.ZeroAccess outbound connection (more info ...)trojan-activity    URL
23494MALWARE-CNC Win.Trojan.Onitab.A outbound connection (more info ...)trojan-activity    URL
23495MALWARE-CNC Win.Trojan.Kugdifod.A variant outbound connection (more info ...)trojan-activity    URL
23496FILE-IDENTIFY CUR file download request (more info ...)misc-activity    
23497FILE-IDENTIFY CUR file attachment detected (more info ...)misc-activity    
23498FILE-IDENTIFY CUR file attachment detected (more info ...)misc-activity    
23513FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
23514FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
23515FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
23516FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
23593MALWARE-CNC Win.Trojan.Smoaler variant outbound connection (more info ...)trojan-activity    URL
23594MALWARE-CNC Win.Trojan.Papras variant outbound connection (more info ...)trojan-activity    URL
23595MALWARE-CNC Win.Trojan.Papras variant outbound connection (more info ...)trojan-activity    URL
23596INDICATOR-COMPROMISE iframe before DOCTYPE possible malicious redirect attempt (more info ...)web-application-attack    
23597MALWARE-CNC Win.Trojan.VB.DHD variant outbound connection (more info ...)trojan-activity    URL
23598MALWARE-CNC Win.Trojan.Slagent outgoing connection (more info ...)trojan-activity    URL
23599MALWARE-CNC Win.Trojan.Slagent outgoing connection (more info ...)trojan-activity    URL
23600MALWARE-CNC Win.Trojan.Gamarue outbound connection (more info ...)trojan-activity    URL
23601INDICATOR-SCAN Skipfish scan default agent string (more info ...)network-scan    URL
23602INDICATOR-SCAN Skipfish scan Firefox agent string (more info ...)network-scan    URL
23603INDICATOR-SCAN Skipfish scan MSIE agent string (more info ...)network-scan    URL
23604INDICATOR-SCAN Skipfish scan iPhone agent string (more info ...)network-scan    URL
23606MALWARE-CNC Win.Trojan.Sofacy.A outbound connection (more info ...)trojan-activity    URL
23607MALWARE-CNC Win.Trojan.Sofacy.A outbound connection (more info ...)trojan-activity    URL
23610MALWARE-CNC Worm.Crass.A variant outbound connection (more info ...)trojan-activity    URL
23613SERVER-WEBAPP Arbitrary file location upload attempt (more info ...)web-application-activity 2004-0959 11190  
23615MALWARE-CNC ACAD.Medre.A variant outbound connection (more info ...)trojan-activity    URL
23616APP-DETECT Amazon Kindle 3.0 User-Agent string requested (more info ...)misc-activity    
23621INDICATOR-OBFUSCATION known packer routine with secondary obfuscation (more info ...)misc-activity    URL
23627MALWARE-CNC User-Agent known malicious user agent - PoisonIvy RAT (more info ...)trojan-activity    URL
23628MALWARE-CNC Win.Trojan.Pincav variant outbound connection (more info ...)trojan-activity    URL
23630MALWARE-CNC Win.Trojan.YMrelay variant outbound connection (more info ...)trojan-activity    URL
23633MALWARE-CNC Win.Trojan.Kegotip variant report to cnc-server (more info ...)trojan-activity    URL
23634MALWARE-CNC Win.Trojan.Kegotip variant outbound connection (more info ...)trojan-activity    URL
23635MALWARE-CNC Gozi trojan checkin (more info ...)trojan-activity    URL
23645FILE-IDENTIFY RealNetworks Real Media file magic detected (more info ...)misc-activity    
23648FILE-IDENTIFY MP3 file magic detected (more info ...)misc-activity    
23661FILE-IDENTIFY ARJ file magic detected (more info ...)misc-activity    
23666FILE-IDENTIFY MP3 file magic detected (more info ...)misc-activity    
23691FILE-IDENTIFY dmg file magic detected (more info ...)misc-activity    
23695FILE-IDENTIFY Flac file magic detected (more info ...)misc-activity    URL
23696FILE-IDENTIFY VideoLAN VLC file magic detected (more info ...)misc-activity    URL
23704FILE-IDENTIFY Ultimate Packer for Executables/UPX v0.51-v0.61 packed file magic detected (more info ...)misc-activity    URL
23706FILE-IDENTIFY Ultimate Packer for Executables/UPX v2.90 v2.93-v3.00 packed file magic detected (more info ...)misc-activity    URL
23713FILE-IDENTIFY Metastock mwl file magic detected (more info ...)misc-activity    URL
23726FILE-IDENTIFY Portable Executable compact binary file magic detected (more info ...)misc-activity    
23728FILE-IDENTIFY matroska file magic detected (more info ...)misc-activity    
23730FILE-IDENTIFY amf file magic detected (more info ...)misc-activity    
23731FILE-IDENTIFY CDR file magic detected (more info ...)misc-activity    URL
23733FILE-IDENTIFY webm file magic detected (more info ...)misc-activity    
23734FILE-IDENTIFY Autodesk Maya file magic detected (more info ...)misc-activity    
23736FILE-IDENTIFY PLS file magic detected (more info ...)misc-activity    
23737FILE-IDENTIFY SMIL file magic detected (more info ...)misc-activity    URL
23749FILE-IDENTIFY SAMI file magic detected (more info ...)misc-activity    
23752FILE-IDENTIFY cy3 Cytel Studio file magic detected (more info ...)misc-activity    
23756FILE-IDENTIFY New Executable binary file magic detected (more info ...)misc-activity    URL
23761FILE-IDENTIFY AVI file magic detected (more info ...)misc-activity    
23763FILE-IDENTIFY HPJ file magic detected (more info ...)misc-activity    
23773FILE-IDENTIFY XM file magic detected (more info ...)misc-activity    
23774FILE-IDENTIFY NAB file magic detected (more info ...)misc-activity    
23776FILE-IDENTIFY PLP file magic detected (more info ...)misc-activity    
23778MALWARE-CNC Win.Trojan.Bublik variant outbound connection (more info ...)trojan-activity    URL
23780MALWARE-CNC Win.Trojan.Begfanit.A outbound connection (more info ...)trojan-activity    URL
23782MALWARE-CNC Win.Trojan.Buzus.kych variant outbound connection (more info ...)trojan-activity    URL
23787MALWARE-CNC Win.Trojan.Locotout variant outbound connection (more info ...)trojan-activity    URL
23788MALWARE-CNC Win.Trojan.Locotout variant outbound connection (more info ...)trojan-activity    URL
23793SERVER-WEBAPP use-after-free in substr_replace attempt (more info ...)misc-activity 2011-1148   
23794MALWARE-CNC known command and control traffic (more info ...)trojan-activity    URL
23796SERVER-WEBAPP exif invalid tag data buffer overflow attempt (more info ...)denial-of-service 2011-0708 46365  
23806FILE-OTHER Oracle Outside-In JPEG2000 QCD segment processing heap buffer overflow attempt (more info ...)attempted-admin 2012-1769 54500  
23824MALWARE-CNC Gauss malware check-in (more info ...)trojan-activity    URL
23825MALWARE-CNC FinFisher initial variant outbound connection (more info ...)trojan-activity    URL
23826MALWARE-CNC FinFisher variant outbound connection (more info ...)trojan-activity    URL
23827SERVER-WEBAPP Joomla Remote File Include upload attempt (more info ...)attempted-user    URL
23828SERVER-WEBAPP Joomla Remote File Include upload attempt (more info ...)attempted-user    URL
23829INDICATOR-COMPROMISE Loaderz Web Shell (more info ...)trojan-activity    URL
23830INDICATOR-COMPROMISE Alsa3ek Web Shell (more info ...)trojan-activity    URL
23851FILE-PDF Blackhole exploit kit related malicious file detection (more info ...)trojan-activity    
23852FILE-PDF Blackhole exploit kit related malicious file detection (more info ...)trojan-activity    
23857INDICATOR-SHELLCODE heapspray characters detected - ASCII (more info ...)attempted-user    
23858FILE-OTHER heapspray characters detected - binary (more info ...)attempted-user    
23859INDICATOR-SHELLCODE heapspray characters detected - hexadecimal encoding (more info ...)attempted-user    
23860INDICATOR-SHELLCODE heapspray characters detected - ASCII (more info ...)attempted-user    
23862INDICATOR-SHELLCODE heapspray characters detected - hexadecimal encoding (more info ...)attempted-user    
23863PUA-ADWARE LiveSecurityPlatinum.A outbound connection - initial connection (more info ...)trojan-activity    URL
23876MALWARE-CNC Win.Trojan.Scirib variant outbound connection (more info ...)trojan-activity    URL
23877MALWARE-CNC Win.Trojan.Dtfanri variant outbound connection (more info ...)trojan-activity    URL
23893MALWARE-CNC Win.Trojan.DistTrack command and control traffic (more info ...)trojan-activity    
23894SERVER-WEBAPP truncated crypt function attempt (more info ...)attempted-admin 2012-2143   
23903MALWARE-CNC User-Agent known malicious user agent - you (more info ...)trojan-activity    
23905INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23906INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23907INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23908INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23909INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23910INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23911INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23912INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23913INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23914INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23915INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23916INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23917INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23918INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23919INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23920INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23921INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23922INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23923INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23924INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23925INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23926INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23927INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23928INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23929INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23930INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23931INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23932INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23933INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - execute dropped file (more info ...)trojan-activity    URL
23935MALWARE-CNC Win.Trojan.Zakahic variant outbound connection (more info ...)trojan-activity    URL
23936MALWARE-CNC Win.Trojan.Zakahic variant outbound connection (more info ...)trojan-activity    URL
23937SERVER-WEBAPP Invalid global flag attachment attempt (more info ...)denial-of-service 2011-1471 49252  
23938MALWARE-CNC Win.Trojan.Ibabyfa.dldr variant outbound connection (more info ...)trojan-activity    URL
23941MALWARE-CNC OSX.Trojan.Aharm variant outbound connection (more info ...)trojan-activity    URL
23942MALWARE-CNC Win.Trojan.C0D0SO0 variant outbound traffic (more info ...)trojan-activity    URL
23945MALWARE-CNC Win.Trojan.Backdoor variant outbound connection (more info ...)trojan-activity    URL
23946MALWARE-CNC Win.Trojan.Backdoor file download (more info ...)trojan-activity    URL
23948MALWARE-CNC Win.Trojan.Sicisono variant outbound connection (more info ...)trojan-activity    URL
23949MALWARE-CNC Win.Trojan.TKcik variant outbound connection (more info ...)trojan-activity    URL
23952MALWARE-TOOLS Tors Hammer slow post flood attempt (more info ...)denial-of-service    
23953MALWARE-CNC Win.Trojan.Comfoo variant outbound connection (more info ...)trojan-activity    URL
23954OS-MOBILE Android SMSZombie APK file download attempt (more info ...)trojan-activity    URL
23955MALWARE-CNC Xhuna.A variant outbound connection (more info ...)trojan-activity    URL
23963MALWARE-CNC Win.Trojan.Runagry variant outbound connection (more info ...)trojan-activity    URL
23968MALWARE-CNC Win.Trojan.Crisis variant outbound connection (more info ...)trojan-activity    URL
23969OS-MOBILE Android SMSZombie APK file download (more info ...)trojan-activity    URL
23971MALWARE-CNC Win.Trojan.Kabwak variant outbound connection (more info ...)trojan-activity    URL
23972MALWARE-CNC Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity    URL
23973MALWARE-CNC Win.Trojan.Vampols variant inbound connection (more info ...)trojan-activity    URL
23974SERVER-WEBAPP calendar conversion remote integer overflow attempt (more info ...)attempted-user 2011-1466 46967  
23975SERVER-WEBAPP calendar conversion remote integer overflow attempt (more info ...)attempted-user 2011-1466 46967  
23976MALWARE-CNC Win.Trojan.Genome initial variant outbound connection (more info ...)trojan-activity    URL
23977MALWARE-CNC Win.Trojan.Genome runtime update to cnc-server (more info ...)trojan-activity    URL
23978MALWARE-CNC Win.Trojan.Hostposer variant outbound connection (more info ...)trojan-activity    URL
23984SERVER-WEBAPP LongTail Video JW Player XSS attempt link param (more info ...)web-application-attack 2012-3351 54101  
23987MALWARE-CNC Win.Trojan.Kryptik.Kazy variant outbound connection (more info ...)trojan-activity    URL
23988SERVER-WEBAPP ocPortal cms cross site request forgery attempt (more info ...)attempted-admin    URL
23990POLICY-SOCIAL Apple Messages client side certificate request attempt (more info ...)policy-violation    URL
23991POLICY-SOCIAL Apple Messages service server request attempt (more info ...)policy-violation    URL
23993SERVER-OTHER Dhcpcd packet size buffer overflow attempt (more info ...)attempted-admin 2012-2152 53354  
23994SERVER-WEBAPP zend_strndup null pointer dereference attempt (more info ...)attempted-dos 2011-4153   
23995SERVER-WEBAPP libtidy null pointer dereference attempt (more info ...)attempted-dos 2011-4153   
24008POLICY-OTHER use of psexec remote administration tool (more info ...)policy-violation    URL
24010MALWARE-CNC runtime Trojan.Radil variant outbound connection (more info ...)trojan-activity    URL
24011MALWARE-CNC Win.Trojan.Ransomer variant outbound connection (more info ...)trojan-activity    URL
24012MALWARE-CNC Win.Trojan.Cbot variant outbound connection - inital contact (more info ...)trojan-activity    URL
24013MALWARE-CNC Win.Trojan.Cbot variant outbound connection - inital contact (more info ...)trojan-activity    URL
24014MALWARE-CNC Win.Trojan.Cbot variant outbound connection - inital contact (more info ...)trojan-activity    URL
24015MALWARE-CNC Win.Trojan.Magania variant outbound connection (more info ...)trojan-activity    URL
24016MALWARE-CNC Win.Trojan.Madon variant outbound connection - variant outbound connection (more info ...)trojan-activity    URL
24018MALWARE-CNC URI request for known malicious URI - hello.icon.pk (more info ...)trojan-activity    URL
24019MALWARE-CNC URI request for known malicious URI - ok.XXX4.net/meeting/hi.exe (more info ...)trojan-activity    URL
24029FILE-OTHER Oracle outside in Lotus 1-2-3 heap overflow attempt (more info ...)attempted-user 2012-0110   URL
24035MALWARE-CNC Downloader.Inject variant outbound connection (more info ...)trojan-activity    URL
24059SERVER-WEBAPP 5.3.3 mt_rand integer overflow attempt (more info ...)misc-activity 2011-0755   
24062MALWARE-CNC Win.Trojan.Hufysk variant outbound connection (more info ...)trojan-activity    URL
24067FILE-OTHER Expat xml UTF-8 buffer over-read attempt (more info ...)denial-of-service 2009-3720 36097  
24068FILE-OTHER Expat xml UTF-8 bufer over-read attempt (more info ...)denial-of-service 2009-3720 36097  
24069FILE-OTHER Expat xml UTF-8 buffer over-read attempt (more info ...)denial-of-service 2009-3720 36097  
24070FILE-OTHER Expat xml UTF-8 buffer over-read attempt (more info ...)denial-of-service 2009-3720 36097  
24074FILE-IDENTIFY MP3 file download request (more info ...)misc-activity    
24075FILE-IDENTIFY MP3 file attachment detected (more info ...)misc-activity    
24076FILE-IDENTIFY MP3 file attachment detected (more info ...)misc-activity    
24077MALWARE-CNC Win.Trojan.Upof variant outbound connection (more info ...)trojan-activity    URL
24078FILE-IDENTIFY RMF file attachment detected (more info ...)misc-activity    
24079FILE-IDENTIFY RMF file attachment detected (more info ...)misc-activity    
24082MALWARE-CNC Win.Trojan.Banbra variant outbound connection (more info ...)trojan-activity    URL
24083FILE-OTHER ESTsoft ALZip MIM file buffer overflow attempt (more info ...)attempted-user 2011-1336   
24086PUA-ADWARE Adware.AdultAds outbound connection (more info ...)trojan-activity    URL
24087MALWARE-CNC Win.Trojan.Bledoor TCP tunnel in UDP (more info ...)trojan-activity    URL
24091SERVER-WEBAPP SAP NetWeaver SOAP interface command injection attempt (more info ...)attempted-admin    URL
24092MALWARE-CNC Win.Trojan.Clisbot variant outbound connection (more info ...)trojan-activity    URL
24093SERVER-WEBAPP RFC1867 file-upload implementation denial of service attempt (more info ...)attempted-dos 2012-1172   
24095APP-DETECT Teamviewer installer download attempt (more info ...)policy-violation    URL
24100FILE-IDENTIFY PLF file attachment detected (more info ...)misc-activity    
24101FILE-IDENTIFY PLF file attachment detected (more info ...)misc-activity    
24103MALWARE-OTHER HTTP POST request to a JPG file (more info ...)non-standard-protocol    URL
24104MALWARE-OTHER HTTP POST request to a JPEG file (more info ...)non-standard-protocol    URL
24105MALWARE-OTHER HTTP POST request to a GIF file (more info ...)non-standard-protocol    URL
24106MALWARE-OTHER HTTP POST request to a PNG file (more info ...)non-standard-protocol    URL
24107MALWARE-OTHER HTTP POST request to a BMP file (more info ...)non-standard-protocol    URL
24108MALWARE-OTHER HTTP POST request to a RAR file (more info ...)non-standard-protocol    URL
24109MALWARE-OTHER HTTP POST request to a ZIP file (more info ...)non-standard-protocol    URL
24110MALWARE-OTHER HTTP POST request to an MP3 file (more info ...)non-standard-protocol    URL
24111MALWARE-CNC User-Agent known malicious user agent - Post (more info ...)trojan-activity    URL
24123MALWARE-BACKDOOR Virus.Win32.Xpaj.A variant outbound connection (more info ...)trojan-activity    URL
24127INDICATOR-COMPROMISE Win.Trojan.DistTrack propagation - QUERY_PATH_INFO csrss.exe (more info ...)trojan-activity    URL
24131OS-WINDOWS Visual Studio Team Web Access console cross site scripting attempt (more info ...)web-application-attack 2012-1892   URL
24132OS-WINDOWS Visual Studio Team Web Access console cross site scripting attempt (more info ...)web-application-attack 2012-1892   URL
24133OS-WINDOWS Visual Studio Team Web Access console cross site scripting attempt (more info ...)web-application-attack 2012-1892   URL
24134OS-WINDOWS Visual Studio Team Web Access console cross site scripting attempt (more info ...)web-application-attack 2012-1892   URL
24135OS-WINDOWS Visual Studio Team Web Access console cross site scripting attempt (more info ...)web-application-attack 2012-1892   URL
24136OS-WINDOWS Visual Studio Team Web Access console cross site scripting attempt (more info ...)web-application-attack 2012-1892   URL
24137OS-WINDOWS Visual Studio Team Web Access console cross site scripting attempt (more info ...)web-application-attack 2012-1892   URL
24156FILE-IDENTIFY .rtx file download request (more info ...)misc-activity    
24157FILE-IDENTIFY .rtx file attachment detected (more info ...)misc-activity    
24158FILE-IDENTIFY .rtx file attachment detected (more info ...)misc-activity    
24159FILE-OTHER AOL Desktop RTX file parsing buffer overflow attempt (more info ...)attempted-user  46129  URL
24160FILE-OTHER AOL Desktop RTX file parsing buffer overflow attempt (more info ...)attempted-user  46129  URL
24161FILE-OTHER AOL Desktop RTX file parsing buffer overflow attempt (more info ...)attempted-user  46129  URL
24162FILE-OTHER AOL Desktop RTX file parsing buffer overflow attempt (more info ...)attempted-user  46129  URL
24163FILE-OTHER AOL Desktop RTX file parsing buffer overflow attempt (more info ...)attempted-user  46129  URL
24164FILE-OTHER AOL Desktop RTX file parsing buffer overflow attempt (more info ...)attempted-user  46129  URL
24165FILE-OTHER AOL Desktop RTX file parsing buffer overflow attempt (more info ...)attempted-user  46129  URL
24166FILE-OTHER AOL Desktop RTX file parsing buffer overflow attempt (more info ...)attempted-user  46129  URL
24167INDICATOR-OBFUSCATION document write of unescaped value with remote script (more info ...)trojan-activity    URL
24168INDICATOR-OBFUSCATION hidden iframe - potential include of malicious content (more info ...)bad-unknown    URL
24169MALWARE-CNC Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity    URL
24173MALWARE-BACKDOOR Trojan-Downloader.Win32.Doneltart.A runtime detection (more info ...)trojan-activity    URL
24174MALWARE-CNC Win.Trojan.Lataa variant outbound connection (more info ...)trojan-activity    URL
24175MALWARE-CNC Win.Trojan.Lataa variant outbound connection (more info ...)trojan-activity    URL
24176FILE-OTHER eZip Wizard stack overflow attempt (more info ...)attempted-user 2009-1028 34044  
24177FILE-OTHER eZip Wizard stack overflow attempt (more info ...)attempted-user 2009-1028 34044  
24178FILE-OTHER eZip Wizard stack overflow attempt (more info ...)attempted-user 2009-1028 34044  
24179FILE-OTHER eZip Wizard stack overflow attempt (more info ...)attempted-user 2009-1028 34044  
24180FILE-OTHER eZip Wizard stack overflow attempt (more info ...)attempted-user 2009-1028 34044  
24181FILE-OTHER eZip Wizard stack overflow attempt (more info ...)attempted-user 2009-1028 34044  
24182MALWARE-CNC Win.Worm.Helompy variant outbound connection (more info ...)trojan-activity    URL
24184MALWARE-CNC Win.Worm.Rokiwobi variant outbound connection (more info ...)trojan-activity    URL
24185MALWARE-CNC Win.Work.Rokiwobi inbound command from C&C (more info ...)trojan-activity    URL
24189FILE-IMAGE XPM file format overflow attempt (more info ...)attempted-user 2007-2193 23620  
24190FILE-IDENTIFY X PixMap file magic detected (more info ...)misc-activity    
24191MALWARE-CNC Win.Trojan.Raven variant outbound connection (more info ...)trojan-activity    URL
24192SERVER-WEBAPP socket_connect buffer overflow attempt (more info ...)attempted-user 2011-1938 49241  
24193SERVER-WEBAPP socket_connect buffer overflow attempt (more info ...)attempted-user 2011-1938 49241  
24194SERVER-WEBAPP socket_connect buffer overflow attempt (more info ...)attempted-user 2011-1938 49241  
24195SERVER-WEBAPP socket_connect buffer overflow attempt (more info ...)attempted-user 2011-1938 49241  
24207FILE-OTHER IBM Lotus Notes LZH Attachment Viewer buffer overflow (more info ...)attempted-user 2011-1213 48018  
24208FILE-OTHER IBM Lotus Notes LZH Attachment Viewer buffer overflow (more info ...)attempted-user 2011-1213 48018  
24209FILE-OTHER IBM Lotus Notes LZH Attachment Viewer buffer overflow (more info ...)attempted-user 2011-1213 48018  
24211MALWARE-CNC Win.Trojan.Xamtrav update protocol connection (more info ...)trojan-activity    URL
24214MALWARE-CNC Win.Trojan.Seveto variant outbound connection (more info ...)trojan-activity    URL
24215MALWARE-CNC Win.Trojan.Banload variant outbound connection (more info ...)trojan-activity    URL
24216MALWARE-CNC Win.Trojan.Biloky variant outbound connection (more info ...)trojan-activity    URL
24217MALWARE-CNC Win.Trojan.Spy variant outbound connection (more info ...)trojan-activity    URL
24218FILE-IDENTIFY SMIL file magic detected (more info ...)misc-activity    URL
24219FILE-IDENTIFY SMIL file magic detected (more info ...)misc-activity    URL
24224MALWARE-CNC Win.Trojan.Zeroaccess variant outbound connection (more info ...)trojan-activity    URL
24230FILE-OTHER RealNetworks Netzip Classic zip archive long filename buffer overflow attempt (more info ...)attempted-user  46059  
24235MALWARE-CNC Win.Trojan.Wuwo initial infection variant outbound connection (more info ...)trojan-activity    URL
24236MALWARE-CNC Win.Trojan.Wuwo post infection variant outbound connection (more info ...)trojan-activity    URL
24237FILE-EXECUTABLE ClamAV UPX File Handling Heap overflow attempt (more info ...)attempted-user 2006-4018 19381  
24238FILE-EXECUTABLE ClamAV UPX File Handling Heap overflow attempt (more info ...)attempted-user 2006-4018 19381  
24243MALWARE-CNC URI request for known malicious URI - base64 encoded (more info ...)trojan-activity    URL
24250SERVER-OTHER telephone URI to USSD code for factory reset (more info ...)attempted-dos    URL
24251OS-MOBILE Android/Fakelash.A!tr.spy trojan command and control channel traffic (more info ...)trojan-activity    URL
24253INDICATOR-COMPROMISE IP only webpage redirect attempt (more info ...)bad-unknown    
24263FILE-PDF Overly large CreationDate within a pdf - likely malicious (more info ...)misc-activity    
24264FILE-PDF Overly large CreationDate within a pdf - likely malicious (more info ...)misc-activity    
24266FILE-PDF xpdf ObjectStream integer overflow (more info ...)attempted-user 2009-3608 37167  
24270PROTOCOL-VOIP Digium Asterisk RTP comfort noise denial of service attempt (more info ...)denial-of-service 2009-4055 37153  
24271MALWARE-CNC Win.Trojan.Spy.Bancos variant outbound connection (more info ...)trojan-activity    URL
24283FILE-MULTIMEDIA VideoLAN VLC webm memory corruption attempt (more info ...)attempted-user 2011-0531 46060  URL
24285MALWARE-CNC Win.Trojan.Nomno variant outbound connection (more info ...)trojan-activity    URL
24286MALWARE-CNC Win.Trojan.Lurk variant outbound connection (more info ...)trojan-activity    URL
24288MALWARE-CNC Win.Trojan.Flexty variant outbound connection (more info ...)trojan-activity    URL
24289SERVER-WEBAPP Fortinet FortiOS appliedTags field cross site scripting attempt (more info ...)web-application-attack  51708  
24290SERVER-OTHER Fortinet FortiOS appliedTags field cross site scripting attempt (more info ...)attempted-user  51708  
24307MALWARE-CNC Win.Trojan.Workir variant outbound connection (more info ...)trojan-activity    URL
24308MALWARE-CNC Win.Trojan.Workir variant outbound connection (more info ...)trojan-activity    URL
24321SERVER-OTHER HP StorageWorks File Migration Agent buffer overflow attempt (more info ...)attempted-admin    
24324SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24325SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24326SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24327SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24328SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24329SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24330SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24331SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24332SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24333SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24334MALWARE-CNC Win.Trojan.Spy.Agent variant connect to cnc-server (more info ...)trojan-activity    URL
24335BROWSER-PLUGINS Citrix Access Gateway plug-in buffer overflow attempt (more info ...)attempted-user 2011-2592 54754  URL
24339SERVER-WEBAPP XML entity parsing information disclosure attempt (more info ...)attempted-recon 2017-5644 65051  
24340MALWARE-CNC Win.Trojan.Bredolab initial CNC connection (more info ...)trojan-activity    URL
24341MALWARE-CNC Win.Trojan.Spy variant outbound connection (more info ...)trojan-activity    URL
24345MALWARE-CNC Win.Trojan.Drexonin variant outbound connection (more info ...)trojan-activity    URL
24346MALWARE-CNC Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity    URL
24347MALWARE-CNC Win.Trojan.Downloader.Bloropac variant outbound connection (more info ...)trojan-activity    URL
24349MALWARE-CNC Win.Trojan.Spy variant outbound connection (more info ...)trojan-activity    URL
24350MALWARE-CNC Win.Trojan.Spy variant outbound connection (more info ...)trojan-activity    URL
24361MALWARE-CNC Win.Trojan.Gozi.Prinimalka variant outbound connection (more info ...)trojan-activity    URL
24373MALWARE-CNC Win.Trojan.Dropper.Agent variant outbound connection (more info ...)trojan-activity    URL
24374MALWARE-CNC Win.Trojan.Dropper.Agent variant outbound connection (more info ...)trojan-activity    URL
24375MALWARE-CNC Win.Trojan.VB variant outbound connection (more info ...)trojan-activity    URL
24376MALWARE-BACKDOOR Trojan.Delf.KDV runtime detection (more info ...)trojan-activity    URL
24377MALWARE-BACKDOOR Trojan.FakeAV.FakeAlert runtime detection (more info ...)trojan-activity    URL
24381MALWARE-CNC Win.Trojan.XBlocker outbound connection (more info ...)trojan-activity    URL
24382MALWARE-CNC Win.Trojan.XBlocker outbound connection (more info ...)trojan-activity    URL
24383MALWARE-CNC Win.Trojan.Dipwit outbound connection (more info ...)trojan-activity    URL
24384MALWARE-CNC Win.Trojan.Tracur variant outbound connection (more info ...)trojan-activity    URL
24385MALWARE-CNC Win.Trojan.Tracur variant outbound connection (more info ...)trojan-activity    URL
24388INDICATOR-COMPROMISE itsoknoproblembro file upload (more info ...)policy-violation    URL
24389INDICATOR-COMPROMISE itsoknoproblembro status check (more info ...)policy-violation    URL
24390INDICATOR-COMPROMISE itsoknoproblembro start perl (more info ...)policy-violation    URL
24392INDICATOR-COMPROMISE itsoknoproblembro write file (more info ...)policy-violation    URL
24393INDICATOR-COMPROMISE itsoknoproblembro stop attack (more info ...)policy-violation    URL
24394INDICATOR-COMPROMISE itsoknoproblembro start attack (more info ...)policy-violation    URL
24395MALWARE-OTHER itsoknoproblembro TCP flood (more info ...)attempted-dos    URL
24396MALWARE-OTHER itsoknoproblembro UDP flood (more info ...)attempted-dos    URL
24398MALWARE-CNC Win.Trojan.Mooochq variant outbound connection (more info ...)trojan-activity    URL
24399MALWARE-CNC Win.Trojan.Mooochq variant outbound connection (more info ...)trojan-activity    URL
24400MALWARE-BACKDOOR Backdoor.Win32.Protos.A runtime detection (more info ...)trojan-activity    URL
24401OS-WINDOWS PCT Client_Hello overflow attempt (more info ...)attempted-admin 2003-0719 10116 12205 URL
24402MALWARE-BACKDOOR Trojan.KDV.QLO install time detection (more info ...)trojan-activity    URL
24403MALWARE-BACKDOOR Trojan.KDV.QLO runtime detection (more info ...)trojan-activity    URL
24404MALWARE-BACKDOOR Trojan.KDV.QLO runtime detection (more info ...)trojan-activity    URL
24405MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
24406MALWARE-CNC Win.Trojan.MiniFlame variant outbound connection (more info ...)trojan-activity    URL
24407MALWARE-CNC Win.Trojan.MiniFlame variant outbound connection (more info ...)trojan-activity    URL
24416MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
24417MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
24418MALWARE-CNC Win.Trojan.Vundo variant outbound connection (more info ...)trojan-activity    URL
24419MALWARE-CNC Win.Trojan.Vundo variant outbound connection (more info ...)trojan-activity    URL
24420MALWARE-CNC Win.Trojan.Misun variant outbound connection (more info ...)trojan-activity    URL
24432BROWSER-OTHER HTML5 canvas element heap spray attempt (more info ...)shellcode-detect    URL
24433BROWSER-OTHER HTML5 canvas element heap spray attempt (more info ...)shellcode-detect    URL
24437MALWARE-CNC Win.Trojan.Mirage variant outbound connection (more info ...)trojan-activity    URL
24438MALWARE-CNC Win.Trojan.Mirage variant outbound connection (more info ...)trojan-activity    URL
24439MALWARE-CNC Win.Trojan.Encriyoko variant outbound connection (more info ...)trojan-activity    URL
24440MALWARE-CNC Win.Trojan.Chiviper variant outbound connection (more info ...)trojan-activity    URL
24441MALWARE-CNC User-Agent known malicious user agent - Testing (more info ...)trojan-activity    URL
24442MALWARE-CNC User-Agent known malicious user agent - Alerter COM (more info ...)trojan-activity    URL
24443MALWARE-CNC Win.Trojan.Medfos variant outbound connection (more info ...)trojan-activity    URL
24444MALWARE-CNC Win.Trojan.Medfos variant outbound connection (more info ...)trojan-activity    URL
24445MALWARE-CNC Win.Trojan.Medfos variant outbound connection (more info ...)trojan-activity    URL
24450MALWARE-CNC Win.Trojan.Tibeli variant outbound connection (more info ...)trojan-activity    URL
24451MALWARE-CNC Win.Trojan.Quervar variant outbound connection (more info ...)trojan-activity    URL
24453FILE-IDENTIFY Webm file attachment detected (more info ...)misc-activity    
24454FILE-IDENTIFY Webm file attachment detected (more info ...)misc-activity    
24474BROWSER-OTHER Puffin Browser usage detected (more info ...)policy-violation    URL
24476PROTOCOL-SCADA DATAC RealWin System buffer overflow attempt (more info ...)attempted-user 2011-1563   
24477PROTOCOL-SCADA DATAC RealWin System buffer overflow attempt (more info ...)attempted-user 2011-1563   
24478PROTOCOL-SCADA DATAC RealWin System buffer overflow attempt (more info ...)attempted-user 2011-1563   
24479PROTOCOL-SCADA DATAC RealWin System buffer overflow attempt (more info ...)attempted-user 2011-1563   
24481PROTOCOL-SCADA DATAC RealWin System buffer overflow attempt (more info ...)attempted-user 2011-1563   
24482MALWARE-CNC Win.Trojan.Chif variant outbound connection (more info ...)trojan-activity    URL
24483FILE-IDENTIFY Embedded Open Type Font file magic detected (more info ...)misc-activity    URL
24484FILE-IDENTIFY Embedded Open Type Font file magic detected (more info ...)misc-activity    URL
24491MALWARE-CNC Win.Trojan.Vundo redirection landing page pre-infection (more info ...)trojan-activity    URL
24492MALWARE-CNC Win.Trojan.Vundo variant outbound connection (more info ...)bad-unknown    
24493MALWARE-CNC Win.Trojan.Vundo variant outbound connection (more info ...)trojan-activity    
24494MALWARE-CNC Win.Trojan.Vundo variant outbound connection (more info ...)trojan-activity    
24495MALWARE-CNC Win.Trojan.Vundo variant outbound connection (more info ...)trojan-activity    
24496MALWARE-CNC Win.Trojan.Vundo variant outbound connection (more info ...)trojan-activity    
24497MALWARE-CNC Win.Trojan.Vundo variant outbound connection (more info ...)trojan-activity    
24504MALWARE-CNC Win.Trojan.VB variant outbound connection (more info ...)trojan-activity    URL
24505MALWARE-CNC Win.Trojan.BanSpy variant outbound connection (more info ...)trojan-activity    URL
24509FILE-IDENTIFY rmf file download request (more info ...)attempted-user 2010-0842 39077  
24514MALWARE-CNC Win.Trojan.Lucuis variant outbound connection (more info ...)trojan-activity    URL
24521SERVER-WEBAPP OpenStack Compute directory traversal attempt (more info ...)attempted-admin 2012-3361   
24523MALWARE-CNC Win.Backdoor.MautoitRAT variant outbound connection (more info ...)trojan-activity    URL
24525BROWSER-PLUGINS Samsung Kies arbitrary file execution attempt (more info ...)attempted-user 2012-3807   
24526BROWSER-PLUGINS Samsung Kies arbitrary file execution attempt (more info ...)attempted-user 2012-3810   
24527BROWSER-PLUGINS Samsung Kies arbitrary file execution attempt (more info ...)attempted-user 2012-3806   
24528BROWSER-PLUGINS Samsung Kies arbitrary file execution attempt (more info ...)attempted-user 2012-3810   
24529MALWARE-CNC Win.Trojan.Begman variant connection to cnc-server (more info ...)trojan-activity    URL
24533MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
24534MALWARE-CNC Win.Trojan.Banbra variant outbound connection (more info ...)trojan-activity    URL
24539MALWARE-CNC Win.Trojan.Ransom variant outbound connection (more info ...)trojan-activity    URL
24540MALWARE-BACKDOOR Win.Trojan.Spy.Heur variant outbound connection attempt (more info ...)trojan-activity    URL
24541MALWARE-CNC Win.Trojan.Unebot variant outbound connection (more info ...)trojan-activity    URL
24542MALWARE-CNC Win.Trojan.Beystreet variant outbound connection (more info ...)trojan-activity    URL
24545MALWARE-BACKDOOR am remote client runtime detection - client response (more info ...)trojan-activity    URL
24562MALWARE-CNC Win.Trojan.VB variant outbound connection (more info ...)trojan-activity    URL
24563MALWARE-CNC Win.Trojan.Veli variant outbound connection (more info ...)trojan-activity    URL
24564MALWARE-CNC Win.Trojan.Helai variant outbound connection (more info ...)trojan-activity    URL
24565MALWARE-CNC Win.Trojan.Msposer variant outbound connection (more info ...)trojan-activity    URL
24566MALWARE-CNC Win.Trojan.Jorik variant outbound connection (more info ...)trojan-activity    URL
24567MALWARE-CNC Win.Trojan.Olmarik variant outbound connection (more info ...)trojan-activity    URL
24569MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
24576MALWARE-CNC Win.Trojan.Spy.Barus variant outbound connection (more info ...)trojan-activity    URL
24586MALWARE-CNC Win.Trojan.Barkiofork variant outbound connection (more info ...)trojan-activity    URL
24598POLICY-SPAM 1.usa.gov URL in email, possible spam redirect (more info ...)bad-unknown    URL
24623MALWARE-CNC Win.Trojan.Jorik variant outbound connection (more info ...)trojan-activity    URL
24625FILE-PDF Sophos Antivirus PDF parsing stack overflow attempt (more info ...)attempted-user    URL
24626FILE-PDF Sophos Antivirus PDF parsing stack overflow attempt (more info ...)attempted-user    URL
24627SERVER-OTHER Quest NetVault SmartDisk libnvbasics.dll denial of service attempt (more info ...)denial-of-service  48029  URL
24630MALWARE-CNC Win.Trojan.Klovbot variant outbound connection (more info ...)trojan-activity    URL
24631MALWARE-CNC User-Agent known malicious user agent - Lizard/1.0 (more info ...)trojan-activity    URL
24632MALWARE-CNC Win.Trojan.VaccinePC variant outbound connection (more info ...)trojan-activity    URL
24633MALWARE-CNC User-Agent known malicious user agent - test_hInternet (more info ...)trojan-activity    URL
24634MALWARE-CNC User-Agent known malicious user agent - vaccinepc (more info ...)trojan-activity    URL
24635MALWARE-CNC Win.Trojan.Dropper.Dycler variant outbound connection (more info ...)trojan-activity    URL
24648MALWARE-OTHER HTML.Exploit.C99 suspicious file download (more info ...)trojan-activity    URL
24686SERVER-OTHER HP StorageWorks file migration agent buffer overflow attempt (more info ...)attempted-admin    
24706SERVER-WEBAPP Netop Remote Control dws file buffer overflow attempt (more info ...)attempted-user  47631  
24707SERVER-WEBAPP Netop Remote Control dws file buffer overflow attempt (more info ...)attempted-user  47631  
24708FILE-IDENTIFY Netop Remote Control file download request (more info ...)misc-activity    
24709FILE-IDENTIFY Netop Remote Control file attachment detected (more info ...)misc-activity    
24710FILE-IDENTIFY Netop Remote Control file attachment detected (more info ...)misc-activity    
24711FILE-IMAGE Oracle Outside In JPEG COD parameter buffer overflow attempt (more info ...)attempted-user 2011-4516   
24712FILE-IMAGE Oracle Outside In JPEG COC parameter buffer overflow attempt (more info ...)attempted-user 2011-4516   
24713FILE-IMAGE Oracle Outside In JPEG COD parameter buffer overflow attempt (more info ...)attempted-user 2011-4516   
24714FILE-IMAGE Oracle Outside In JPEG COC parameter buffer overflow attempt (more info ...)attempted-user 2011-4516   
24715FILE-IMAGE Oracle Outside In JPEG COD parameter buffer overflow attempt (more info ...)attempted-user 2011-4516   
24716FILE-IMAGE Oracle Outside In JPEG COC parameter buffer overflow attempt (more info ...)attempted-user 2011-4516   
24717FILE-IMAGE Oracle Outside In JPEG COD parameter buffer overflow attempt (more info ...)attempted-user 2011-4516   
24718FILE-IMAGE Oracle Outside In JPEG COC parameter buffer overflow attempt (more info ...)attempted-user 2011-4516   
24719PROTOCOL-VOIP Digium Asterisk SCCP call state message offhook (more info ...)attempted-dos 2012-2415   
24720PROTOCOL-VOIP Digium Asterisk SCCP keypad button message denial of service attempt (more info ...)attempted-dos 2012-2415   
24728SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24729SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24730SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24731SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24732SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24733SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24734SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24735SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24736SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24737SERVER-WEBAPP Oracle GlassFish cross site scripting attempt (more info ...)web-application-attack 2012-0551 53136  
24738SERVER-OTHER EMC AutoStart ftAgent.exe integer overflow attempt (more info ...)attempted-admin 2012-0409   
24739SERVER-OTHER Gimp Script-Fu server buffer overflow attempt (more info ...)attempted-admin 2012-2763 53741  URL
24763FILE-PDF Sophos Antivirus PDF parsing stack overflow attempt (more info ...)attempted-user    URL
24764FILE-PDF Sophos Antivirus PDF parsing stack overflow attempt (more info ...)attempted-user    URL
24792MALWARE-CNC User-Agent known malicious user-agent - Google page (more info ...)trojan-activity    URL
24803PROTOCOL-SCADA GE Proficy Real-Time Information Portal directory traversal attempt (more info ...)attempted-admin 2012-0232 52439  URL
24805SERVER-OTHER lighthttpd connection header denial of service attempt (more info ...)denial-of-service 2012-5533   
24814PROTOCOL-SNMP Samsung printer default community string (more info ...)attempted-admin    URL
24818FILE-IDENTIFY M4V file magic detected (more info ...)misc-activity    
24819FILE-IDENTIFY M4V file magic detected (more info ...)misc-activity    
24857MALWARE-CNC Win.Trojan.Spy.Agent variant outbound connection (more info ...)trojan-activity    URL
24858MALWARE-CNC Win.Trojan.Quarian variant outbound connection - proxy connection (more info ...)trojan-activity    URL
24873MALWARE-CNC Win.Trojan.Gnutler variant outbound connection (more info ...)trojan-activity    URL
24885MALWARE-CNC Potential Banking Trojan Config File Download (more info ...)trojan-activity    URL
24886MALWARE-CNC Win.Trojan.Dorkbot variant outbound connection (more info ...)trojan-activity    URL
24916MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
24917MALWARE-CNC Win.Trojan.Spy.Turspy variant outbound connection (more info ...)trojan-activity    URL
24918MALWARE-CNC Win.Trojan.Spy.Turspy variant outbound connection (more info ...)trojan-activity    URL
24955FILE-MULTIMEDIA AVI file chunk length integer overflow attempt (more info ...)attempted-user 2011-3834   URL
24976MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
24988MALWARE-OTHER itsoknoproblembro v2 UDP flood attempt (more info ...)attempted-dos    URL
24995SERVER-OTHER Free Software Foundation GnuTLS record application integer overflow attempt (more info ...)attempted-admin 2012-1573   
24996SERVER-OTHER Free Software Foundation GnuTLS record application integer overflow attempt (more info ...)attempted-admin 2012-1573   
25007MALWARE-CNC Win.Trojan.Wealwedst variant outbound connection (more info ...)trojan-activity    URL
25008SERVER-WEBAPP PmWiki pagelist injection attempt (more info ...)web-application-attack 2011-4453 50776  
25009MALWARE-CNC User-Agent known malicious user agent - User-Agent User-Agent (more info ...)trojan-activity    URL
25010MALWARE-CNC Win.Trojan.Perflog variant outbound connection (more info ...)trojan-activity    URL
25011MALWARE-CNC Win.Trojan.Perflog variant outbound connection (more info ...)trojan-activity    URL
25016MALWARE-CNC Win.Trojan.IRCBot variant outbound connection (more info ...)trojan-activity    URL
25017SERVER-WEBAPP httpdx tolog function format string code execution attempt (more info ...)attempted-admin 2009-4769   
25021MALWARE-CNC Win.Trojan.Azbreg variant outbound connection (more info ...)trojan-activity    URL
25022MALWARE-CNC Win.Trojan.Dapato variant outbound connection (more info ...)trojan-activity    URL
25023MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
25024MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
25025MALWARE-CNC Win.Trojan.Downloader.Recslurp variant outbound connection (more info ...)trojan-activity    URL
25026MALWARE-CNC Win.Trojan.Juasek variant outbound connection (more info ...)trojan-activity    URL
25027MALWARE-CNC Win.Trojan.Opachki variant connect to cnc-server (more info ...)trojan-activity    URL
25028MALWARE-CNC Win.Trojan.Peed variant outbound connection (more info ...)trojan-activity    URL
25029MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
25030MALWARE-CNC Win.Trojan.Nevsyn variant outbound connection (more info ...)trojan-activity    URL
25049MALWARE-CNC Win.Trojan.Jorik.Kolilks variant outbound connection (more info ...)trojan-activity    URL
25050MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    
25054MALWARE-CNC ZeroAccess Clickserver callback (more info ...)trojan-activity    
25057PROTOCOL-SCADA Tridium Niagara directory traversal config.bog access attempt (more info ...)attempted-admin 2012-4027   
25058SERVER-OTHER IBM Director CIM server alert indication request dll injection attempt (more info ...)attempted-admin 2009-0880 34065  
25065FILE-IMAGE libpng chunk decompression integer overflow attempt (more info ...)attempted-admin 2011-3045 52453  
25066FILE-IMAGE libpng chunk decompression integer overflow attempt (more info ...)attempted-admin 2011-3045 52453  
25067MALWARE-CNC Win.Trojan.Riler variant outbound connection (more info ...)trojan-activity 2010-3333   URL
25068MALWARE-CNC Win.Trojan.Riler inbound connection (more info ...)trojan-activity 2010-3333   URL
25070MALWARE-CNC Win.Trojan.Injector variant outbound connection (more info ...)trojan-activity    URL
25071MALWARE-CNC Win.Trojan.Macnsed variant outbound connection (more info ...)trojan-activity    URL
25072MALWARE-CNC Win.Trojan.Dulom variant outbound connection (more info ...)trojan-activity    URL
25073MALWARE-CNC Win.Trojan.Lowzone variant outbound connection (more info ...)trojan-activity    URL
25074MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
25075MALWARE-CNC Win.Trojan.Spy variant outbound connection (more info ...)trojan-activity    URL
25076MALWARE-CNC Win.Worm.Joanap variant variant outbound connection (more info ...)trojan-activity    URL
25077MALWARE-CNC Win.Trojan.Halnine variant outbound connection (more info ...)trojan-activity    URL
25082APP-DETECT Apple Messages client side certificate request attempt (more info ...)policy-violation    URL
25083APP-DETECT Apple Messages service server request attempt (more info ...)policy-violation    URL
25093MALWARE-CNC Win.Trojan.Hacktool variant outbound connection (more info ...)trojan-activity    URL
25098MALWARE-CNC Win.Trojan.Dropper.Daws variant outbound connection (more info ...)trojan-activity    URL
25099MALWARE-CNC Win.Trojan.Dropper.Daws variant outbound connection (more info ...)trojan-activity    URL
25100MALWARE-CNC Win.Trojan.Njrat variant outbound connection (more info ...)trojan-activity    URL
25102SERVER-OTHER Zabbix Agent net.tcp.listen command injection attempt (more info ...)attempted-admin 2009-4502   
25103SERVER-OTHER Zabbix Server arbitrary command execution attempt (more info ...)attempted-admin 2009-4498 37989  
25104SERVER-WEBAPP Symantec Messaging Gateway directory traversal attempt (more info ...)attempted-admin 2012-4347   URL
25105SERVER-WEBAPP Symantec Messaging Gateway directory traversal attempt (more info ...)attempted-admin 2012-4347   URL
25106MALWARE-BACKDOOR UnrealIRCd backdoor command execution attempt (more info ...)attempted-admin 2010-2075 40820  URL
25107MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
25108MALWARE-CNC Win.Trojan.Proxy.Agent variant outbound connection (more info ...)trojan-activity    URL
25109MALWARE-CNC Autoit.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25119MALWARE-CNC User-Agent known malicious user agent - NewBrandTest (more info ...)trojan-activity    URL
25124BROWSER-OTHER suspicious named empty form detected (more info ...)attempted-user    
25224MALWARE-CNC Win.Trojan.ZeroAccess URI and Referer (more info ...)trojan-activity    
25229MALWARE-CNC Win.Trojan.Darkkomet variant inbound connection (more info ...)trojan-activity    URL
25230MALWARE-CNC Win.Trojan.Darkkomet variant outbound connection (more info ...)trojan-activity    URL
25231MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
25232BROWSER-FIREFOX appendChild multiple parent nodes stack corruption attempt (more info ...)attempted-user 2011-2378   
25233BROWSER-FIREFOX appendChild multiple parent nodes stack corruption attempt (more info ...)attempted-user 2011-2378   
25237MALWARE-CNC Win.Trojan.Firelog variant outbound connection (more info ...)trojan-activity    URL
25239MALWARE-CNC Win.Trojan.IRCBot variant outbound connection (more info ...)trojan-activity    URL
25240MALWARE-CNC Win.Trojan.Menti variant inbound connection (more info ...)trojan-activity    URL
25241MALWARE-CNC Win.Trojan.NetTrash variant outbound connection (more info ...)trojan-activity    URL
25242MALWARE-CNC Win.Trojan.Duapz variant outbound connection (more info ...)trojan-activity    URL
25243MALWARE-CNC User-Agent known malicious user agent - 04/XP (more info ...)trojan-activity    URL
25244MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
25245MALWARE-CNC User-Agent known malicious user agent - me0hoi (more info ...)trojan-activity    URL
25247FILE-OTHER Lattice PAC Designer symbol value buffer overflow attempt (more info ...)attempted-user 2012-2915   
25248FILE-OTHER Lattice PAC Designer symbol value buffer overflow attempt (more info ...)attempted-user 2012-2915   
25249MALWARE-CNC Win.Trojan.Basutra variant outbound connection (more info ...)trojan-activity    URL
25256MALWARE-CNC Win.Worm.Gamarue variant outbound connection (more info ...)trojan-activity    
25257MALWARE-CNC Win.Trojan.Skintrim variant outbound connection (more info ...)trojan-activity    URL
25258MALWARE-CNC Win.Trojan.Rombrast variant outbound connection (more info ...)trojan-activity    URL
25259MALWARE-CNC Win.Trojan.BancosBanload variant outbound connection (more info ...)trojan-activity    URL
25260MALWARE-CNC User-Agent known malicious user-agent string Mozila (more info ...)trojan-activity    URL
25261MALWARE-CNC User-Agent known malicious user-agent string MSIE (more info ...)trojan-activity    URL
25262MALWARE-CNC User-Agent known malicious user-agent string IEToolbar (more info ...)trojan-activity    URL
25263SERVER-WEBAPP fraudulent digital certificate for google.com detected (more info ...)misc-attack    URL
25264SERVER-WEBAPP revoked subsidiary CA certificate for e-islem.kktcmerkezbankasi.org detected (more info ...)misc-attack    URL
25265SERVER-WEBAPP revoked subsidiary CA certificate for ego.gov.tr detected (more info ...)misc-attack    URL
25268MALWARE-CNC Win.Trojan.IRCBot variant outbound connection (more info ...)trojan-activity    URL
25269MALWARE-CNC Win.Trojan.Buterat variant outbound connection (more info ...)trojan-activity    URL
25271MALWARE-CNC Win.Trojan.Buzus variant outbound connection (more info ...)trojan-activity    
25276SERVER-OTHER Multiple products oversized Content-Length memory corruption attempt (more info ...)attempted-admin 2013-2686   URL
25286SERVER-WEBAPP MoinMoin arbitrary file upload attempt (more info ...)attempted-admin 2012-6081 57082  
25287SERVER-OTHER Rails XML parameter parsing vulnerability exploitation attempt (more info ...)attempted-admin 2013-0156   
25288SERVER-OTHER Rails XML parameter parsing vulnerability exploitation attempt (more info ...)attempted-admin 2013-0156   
25315SERVER-ORACLE Oracle TNS listener service registration (more info ...)policy-violation 2012-1675 53308  
25316BROWSER-PLUGINS InduSoft ISSymbol InternationalSeparator heap overflow attempt (more info ...)attempted-user 2011-0340   
25321SERVER-ORACLE Oracle Database tablefunc_asown buffer overflow attempt (more info ...)attempted-admin 2011-2301   URL
25342SERVER-OTHER ISC dhcpd bootp request missing options field DOS attempt (more info ...)attempted-dos 2011-2749 49120  URL
25345SERVER-WEBAPP Symantec IM Manager Web interface arbitrary command execution attempt (more info ...)attempted-user 2011-0554 49742  
25352SERVER-OTHER HP HP Intelligent Management Center syslog remote code execution attempt (more info ...)attempted-admin 2011-1854   
25356SERVER-OTHER Squid Gopher response processing buffer overflow attempt (more info ...)attempted-user 2011-3205 49356  URL
25358APP-DETECT Acunetix web vulnerability scan attempt (more info ...)web-application-attack    URL
25359APP-DETECT Acunetix web vulnerability scanner probe attempt (more info ...)web-application-attack    URL
25360APP-DETECT Acunetix web vulnerability scanner authentication attempt (more info ...)web-application-attack    URL
25361APP-DETECT Acunetix web vulnerability scanner RFI attempt (more info ...)web-application-attack    URL
25362APP-DETECT Acunetix web vulnerability scanner base64 XSS attempt (more info ...)web-application-attack    URL
25363APP-DETECT Acunetix web vulnerability scanner URI injection attempt (more info ...)web-application-attack    URL
25364APP-DETECT Acunetix web vulnerability scanner prompt XSS attempt (more info ...)web-application-attack    URL
25365APP-DETECT Acunetix web vulnerability scanner XSS attempt (more info ...)web-application-attack    URL
25369OS-WINDOWS NVIDIA graphics driver nvsr named pipe buffer overflow attempt (more info ...)attempted-user    
25371MALWARE-CNC Win.Trojan.Ruskill variant outbound connection (more info ...)trojan-activity    URL
25372MALWARE-CNC User-Agent known malicious user agent - wh (more info ...)trojan-activity    URL
25380SERVER-OTHER EMC AutoStart domain name logging stack buffer overflow attempt (more info ...)attempted-user 2011-2735 49238  
25448MALWARE-CNC Win.Trojan.Downloader.Jinch variant outbound connection (more info ...)trojan-activity    URL
25465MALWARE-CNC Win.Trojan.Downloader variant outbound connection (more info ...)trojan-activity    URL
25470MALWARE-CNC Win.Trojan.LoDo variant outbound connection (more info ...)trojan-activity    URL
25471MALWARE-CNC Pushdo Spiral Traffic (more info ...)trojan-activity    URL
25474SERVER-OTHER Citrix Access Gateway legacy authentication attempt (more info ...)attempted-admin 2010-4566   URL
25477MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25478POLICY-SOCIAL IRC G-line active (more info ...)policy-violation    URL
25479POLICY-SOCIAL IRC K-line active (more info ...)policy-violation    URL
25511MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
25512OS-MOBILE Android ANDR.Trojan.SMSsend variant outbound connection (more info ...)trojan-activity    URL
25518OS-MOBILE Apple iPod User-Agent detected (more info ...)policy-violation    
25519OS-MOBILE Apple iPad User-Agent detected (more info ...)policy-violation    
25520OS-MOBILE Apple iPhone User-Agent detected (more info ...)policy-violation    
25521OS-MOBILE Android User-Agent detected (more info ...)policy-violation    
25522OS-MOBILE Nokia User-Agent detected (more info ...)policy-violation    
25523OS-MOBILE Samsung User-Agent detected (more info ...)policy-violation    
25524OS-MOBILE Kindle User-Agent detected (more info ...)policy-violation    
25525OS-OTHER Nintendo User-Agent detected (more info ...)policy-violation    
25528SERVER-WEBAPP Moveable Type unauthenticated remote command execution attempt (more info ...)attempted-admin 2013-0209   URL
25529MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
25530MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25531MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25532MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25533MALWARE-CNC User-Agent known malicious user-agent - al (more info ...)trojan-activity    URL
25541MALWARE-CNC Win.Trojan.Sigly variant outbound connection (more info ...)trojan-activity    URL
25543MALWARE-CNC Win.Trojan.Downloader.VB variant outbound connection (more info ...)trojan-activity    URL
25544MALWARE-CNC User-Agent known malicious user agent - ctwopop (more info ...)trojan-activity    URL
25545MALWARE-CNC Win.Trojan.Printlove variant outbound connection (more info ...)trojan-activity    URL
25546MALWARE-CNC Win.Trojan.Proxy.Agent variant outbound connection (more info ...)trojan-activity    URL
25547MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25548MALWARE-CNC Win.Trojan.Perflog variant outbound connection (more info ...)trojan-activity    URL
25551MALWARE-CNC Win.Worm.Dipasik variant outbound connection (more info ...)trojan-activity    URL
25552SERVER-OTHER Rails JSON to YAML parsing deserialization attempt (more info ...)attempted-user 2013-0333   
25553MALWARE-CNC Win.Trojan.Dexter variant outbound connection (more info ...)trojan-activity    URL
25556SERVER-OTHER RaySharp CCTV derivative user credential retrieval attempt (more info ...)attempted-admin    URL
25557SERVER-OTHER RaySharp CCTV derivative command injection attempt (more info ...)attempted-admin    URL
25570MALWARE-CNC Win.Trojan.Medialabs variant outbound connection (more info ...)trojan-activity    URL
25571MALWARE-CNC Win.Trojan.Medialabs variant outbound connection (more info ...)trojan-activity    URL
25572MALWARE-CNC Win.Trojan.Virut variant outbound connection (more info ...)trojan-activity    URL
25577MALWARE-CNC Win.Rootkit.Necurs possible URI with encrypted POST (more info ...)trojan-activity    URL
25586SERVER-WEBAPP Nagios Core get_history buffer overflow attempt (more info ...)attempted-admin 2012-6096 56879  
25599MALWARE-CNC Win.Trojan.Gupboot variant outbound connection (more info ...)trojan-activity    URL
25600MALWARE-CNC Win.Trojan.Dilavtor variant outbound connection (more info ...)trojan-activity    URL
25602SERVER-OTHER Sybase Open Server TDS login request (more info ...)protocol-command-decode    URL
25603SERVER-OTHER Sybase Open Server TDS login packet stack memory corruption attempt (more info ...)attempted-admin    URL
25604FILE-IDENTIFY cSounds.com Csound audio file file download request (more info ...)misc-activity    
25605FILE-IDENTIFY cSounds.com Csound audio file file attachment detected (more info ...)misc-activity    
25606FILE-IDENTIFY cSounds.com Csound audio file file attachment detected (more info ...)misc-activity    
25607FILE-OTHER cSounds.com Csound hetro audio file buffer overflow attempt (more info ...)attempted-user 2012-0270   
25608FILE-OTHER cSounds.com Csound hetro audio file buffer overflow attempt (more info ...)attempted-user 2012-0270   
25609MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
25610MALWARE-CNC Win.Trojan.Mofsmall variant outbound connection (more info ...)trojan-activity    URL
25615OS-MOBILE Apple iOS 6.x jailbreak download attempt (more info ...)attempted-admin    URL
25616OS-MOBILE Apple iOS 6.x jailbreak download attempt (more info ...)attempted-admin    URL
25623MALWARE-CNC Win.Trojan.Jimpime variant outbound connection (more info ...)trojan-activity    URL
25625MALWARE-CNC Win.Trojan.Daws variant outbound connection (more info ...)trojan-activity    URL
25626MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
25627MALWARE-CNC Win.Trojan.Reventon variant outbound connection (more info ...)trojan-activity    URL
25628MALWARE-CNC Win.Trojan.Spy.Banker variant connect to cnc-server (more info ...)trojan-activity    URL
25632MALWARE-CNC Win.Trojan.Golisy variant outbound connection (more info ...)trojan-activity    URL
25633FILE-OTHER ELF file parsing in different antivirus evasion attempt (more info ...)bad-unknown 2012-1431   URL
25634INDICATOR-SHELLCODE unescape encoder shellcode (more info ...)shellcode-detect    
25635INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25636INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25637INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25638INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25639INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25640INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25641INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25642INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25643INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
25652MALWARE-CNC Win.Trojan.Kryptic variant outbound connection (more info ...)trojan-activity    URL
25659MALWARE-CNC User-Agent known malicious user agent - spam_bot (more info ...)trojan-activity    URL
25660MALWARE-CNC Win.Trojan.Medfos variant outbound connection (more info ...)trojan-activity    URL
25661MALWARE-CNC Win.Trojan.Buzus variant outbound connection (more info ...)trojan-activity    URL
25662MALWARE-CNC Win.Trojan.Chowspy variant outbound connection (more info ...)trojan-activity    URL
25663MALWARE-CNC Win.Trojan.Rimod variant outbound connection (more info ...)trojan-activity    URL
25664SERVER-OTHER MiniUPnPd SSDP request buffer overflow attempt (more info ...)denial-of-service 2013-2600   
25665MALWARE-CNC Win.Trojan.Sycomder variant outbound connection (more info ...)trojan-activity    URL
25666MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
25667MALWARE-CNC Win.Trojan.Nflog variant outbound connection (more info ...)trojan-activity    URL
25668MALWARE-CNC Win.Trojan.Nflog variant outbound connection (more info ...)trojan-activity    URL
25669MALWARE-CNC Win.Trojan.Selasloot variant outbound connection (more info ...)trojan-activity    URL
25670MALWARE-CNC Win.Trojan.Swisyn variant outbound connection (more info ...)trojan-activity    URL
25671MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
25672MALWARE-CNC Win.Trojan.Matsnu variant outbound connection (more info ...)trojan-activity    URL
25673MALWARE-CNC Win.Trojan.Spy.QQDragon variant outbound connection (more info ...)trojan-activity    URL
25674MALWARE-CNC Win.Trojan.Shimwoc variant outbound connection (more info ...)trojan-activity    URL
25765MALWARE-CNC Trojan Agent YEH variant outbound connection (more info ...)trojan-activity    URL
25766MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
25782MALWARE-OTHER WIN.Trojan.Nap Malicious executable file download from webroot (more info ...)bad-unknown    
25797FILE-MULTIMEDIA VideoLAN VLC Media Player XSPF memory corruption attempt (more info ...)attempted-user 2008-4558   
25799EXPLOIT-KIT Stamp exploit kit pdf request (more info ...)trojan-activity 2013-0431   URL
25802EXPLOIT-KIT Stamp exploit kit encoded portable executable request (more info ...)trojan-activity 2013-0431   URL
25807MALWARE-CNC Win.Trojan.Urausy Botnet variant outbound connection (more info ...)trojan-activity    URL
25810FILE-OTHER VMWare OVF Tool format string exploit attempt (more info ...)attempted-user 2012-3569 56468  URL
25811FILE-OTHER VMWare OVF Tool format string exploit attempt (more info ...)attempted-user 2012-3569 56468  URL
25812FILE-OTHER VMWare OVF Tool format string exploit attempt (more info ...)attempted-user 2012-3569 56468  URL
25813FILE-OTHER VMWare OVF Tool format string exploit attempt (more info ...)attempted-user 2012-3569 56468  URL
25825SERVER-OTHER TLSv1.0 plaintext recovery attempt (more info ...)attempted-recon 2013-0169   
25826SERVER-OTHER TLSv1.1 plaintext recovery attempt (more info ...)attempted-recon 2013-0169   
25827SERVER-OTHER TLSv1.2 plaintext recovery attempt (more info ...)attempted-recon 2013-0169   
25828SERVER-OTHER SSLv3 plaintext recovery attempt (more info ...)attempted-recon 2013-0169   
25829MALWARE-CNC Trojan Banker FTC variant outbound connection (more info ...)trojan-activity    URL
25836INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Virtuallythere (more info ...)trojan-activity    URL
25837INDICATOR-COMPROMISE known malicious SSL certificate - APT1 IBM (more info ...)trojan-activity    URL
25838INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Webmail (more info ...)trojan-activity    URL
25839INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Alpha (more info ...)trojan-activity    URL
25840INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Email (more info ...)trojan-activity    URL
25841INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Lame (more info ...)trojan-activity    URL
25842INDICATOR-COMPROMISE known malicious SSL certificate - APT1 NS (more info ...)trojan-activity    URL
25843INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Server (more info ...)trojan-activity    URL
25844INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Sur (more info ...)trojan-activity    URL
25845INDICATOR-COMPROMISE known malicious SSL certificate - APT1 AOL (more info ...)trojan-activity    URL
25846INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Yahoo (more info ...)trojan-activity    URL
25847INDICATOR-COMPROMISE known malicious SSL certificate - APT1 Moon-Night (more info ...)trojan-activity    URL
25848INDICATOR-COMPROMISE known malicious SSL certificate - APT1 No-Name (more info ...)trojan-activity    URL
25850PROTOCOL-SCADA Schneider Electric IGSS integer underflow attempt (more info ...)attempted-user 2013-0657   
25854MALWARE-CNC Win.Trojan.Zeus variant outbound connection - MSIE7 No Referer No Cookie (more info ...)trojan-activity    URL
25855SERVER-WEBAPP Nagios XI alert cloud cross site scripting attempt (more info ...)web-application-attack    
25856PROTOCOL-TELNET Client env_opt_add Buffer Overflow attempt (more info ...)attempted-dos 2005-0468 12919  
25863MALWARE-CNC Win.Trojan.Downloader.QBundle variant outbound connection (more info ...)trojan-activity    URL
25864OS-MOBILE Android AngryBirdsRioUnlocker initial device info send (more info ...)trojan-activity    URL
25865MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25866MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25867MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25868OS-MOBILE Android.Trojan.Rus.SMS outbound communication attempt (more info ...)trojan-activity    URL
25947APP-DETECT Ammyy remote access tool (more info ...)policy-violation    URL
25949MALWARE-CNC Win.Trojan.Zebrocy outbound data connection (more info ...)trojan-activity    URL
25973MALWARE-CNC Win.Trojan.Boolflot variant outbound connection (more info ...)trojan-activity    URL
25974MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25978MALWARE-CNC Win.Trojan.Lukprofin variant outbound connection (more info ...)trojan-activity    URL
25979MALWARE-CNC Win.Trojan.Lukprofin variant outbound connection (more info ...)trojan-activity    URL
25980MALWARE-CNC User-Agent known malicious user agent - Pass (more info ...)trojan-activity    URL
25987MALWARE-CNC Win.Trojan.Upof variant outbound connection (more info ...)trojan-activity    URL
25990MALWARE-CNC Win.Trojan.Spy.Agent variant connect to cnc-server (more info ...)trojan-activity    URL
25991MALWARE-CNC Win.Trojan.Spy.Agent variant connect to cnc-server (more info ...)trojan-activity    URL
25992MALWARE-CNC Win.Trojan.Buzus variant outbound connection (more info ...)trojan-activity    URL
25993MALWARE-CNC Win.Trojan.Buzus variant outbound connection (more info ...)trojan-activity    URL
25994MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
25995MALWARE-CNC Win.Downloader.Banload variant outbound connection (more info ...)trojan-activity    URL
25996MALWARE-CNC Win.Trojan.Reswor variant outbound connection (more info ...)trojan-activity    URL
25997OS-MOBILE Android jSMSHider initial encrypted device info send (more info ...)trojan-activity    URL
25998OS-MOBILE Android ADRD encrypted information leak (more info ...)trojan-activity    URL
25999OS-MOBILE Android ADRD encrypted information leak (more info ...)trojan-activity    URL
26010MALWARE-CNC CNC Dirtjumper variant outbound connection (more info ...)trojan-activity    URL
26011MALWARE-CNC CNC Dirtjumper variant outbound connection (more info ...)trojan-activity    URL
26015OS-MOBILE Android Lovetrap initial connection (more info ...)trojan-activity    URL
26016OS-MOBILE Android GGTracker server communication (more info ...)trojan-activity    URL
26017OS-MOBILE Android GGTracker leak of device phone number (more info ...)trojan-activity    URL
26018OS-MOBILE Android GGTracker installation call out (more info ...)trojan-activity    URL
26022FILE-PDF EmbeddedFile contained within a PDF (more info ...)trojan-activity    
26024MALWARE-CNC Win.Trojan.Wecod variant outbound connection (more info ...)trojan-activity    URL
26026OS-MOBILE Android Gmaster device information send (more info ...)trojan-activity    URL
26073SERVER-OTHER SAP NetWeaver Message Server buffer overflow attempt (more info ...)attempted-admin 2013-1592   URL
26074SERVER-OTHER SAP NetWeaver Message Server buffer overflow attempt (more info ...)attempted-admin 2013-1593   URL
26078FILE-PDF transfer of a PDF with OpenAction object attempt (more info ...)policy-violation 2014-8450   URL
26079FILE-PDF PDF file with embedded PDF object (more info ...)policy-violation    URL
26081MALWARE-CNC URI request for known malicious URI - Suspected Crimepack (more info ...)trojan-activity    URL
26082FILE-PDF Nuance PDF reader launch overflow attempt (more info ...)attempted-admin    
26086MALWARE-CNC Win.Trojan.Exicon variant outbound connection (more info ...)trojan-activity    URL
26087OS-MOBILE Android GoneIn60Seconds data upload (more info ...)trojan-activity    URL
26088MALWARE-CNC Win.Trojan.Encriyoko variant outbound connection (more info ...)trojan-activity    URL
26102OS-MOBILE Android GoldDream device registration (more info ...)trojan-activity    URL
26104OS-MOBILE Android KMin imei imsi leakage (more info ...)trojan-activity    URL
26106MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    
26114OS-MOBILE Android Zitmo trojan intercepted sms upload (more info ...)trojan-activity    URL
26115MALWARE-CNC NSIS.Downloader.Agent variant outbound connection (more info ...)trojan-activity    URL
26116MALWARE-CNC NSIS.Downloader.Agent variant outbound connection (more info ...)trojan-activity    URL
26117MALWARE-CNC Win.Trojan.Tarctox variant outbound connection (more info ...)trojan-activity    URL
26118MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
26119MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
26120MALWARE-CNC AutoIT.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
26121MALWARE-CNC AutoIT.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
26122FILE-OTHER Lattice Semiconductor ispXCF version attribute overflow attempt (more info ...)attempted-user  53562  
26123FILE-OTHER Lattice Semiconductor ispXCF version attribute overflow attempt (more info ...)attempted-user  53562  
26178MALWARE-CNC Win.Trojan.Hiloti variant outbound connection (more info ...)trojan-activity    URL
26189OS-MOBILE Android YZHC device registration (more info ...)trojan-activity    URL
26190OS-MOBILE Android YZHC device registration (more info ...)trojan-activity    URL
26192OS-MOBILE Android CruseWind imei leakage (more info ...)trojan-activity    URL
26201MALWARE-CNC Win.Trojan.Lobparck variant outbound connection (more info ...)trojan-activity    URL
26202MALWARE-CNC VBS.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
26203MALWARE-CNC Win.Trojan.Gupd variant outbound connection (more info ...)trojan-activity    URL
26204MALWARE-CNC Win.Trojan.Malex variant outbound connection (more info ...)trojan-activity    URL
26206FILE-IDENTIFY CyberLink Power2Go file download request (more info ...)misc-activity    
26207FILE-IDENTIFY CyberLink Power2Go file attachment detected (more info ...)misc-activity    
26208FILE-IDENTIFY CyberLink Power2Go file attachment detected (more info ...)misc-activity    
26209FILE-OTHER CyberLink Power2Go name parameter overflow attempt (more info ...)attempted-user 2011-5171 50997  
26210FILE-OTHER CyberLink Power2Go name parameter overflow attempt (more info ...)attempted-user 2011-5171 50997  
26211MALWARE-CNC Win.Trojan.Eldorado variant outbound connection (more info ...)trojan-activity    URL
26212MALWARE-CNC Win.Trojan.Proxyier variant outbound connection (more info ...)trojan-activity    
26238MALWARE-CNC Win.Trojan.Snopexy variant outbound connection (more info ...)trojan-activity    URL
26239MALWARE-CNC Win.Trojan.Stehlox variant outbound connection (more info ...)trojan-activity    URL
26240MALWARE-CNC Win.Trojan.Vkeikooc variant outbound connection (more info ...)trojan-activity    URL
26242FILE-MULTIMEDIA CCMPlayer m3u buffer overflow attempt (more info ...)attempted-admin 2011-5170 50859  
26243FILE-MULTIMEDIA CCMPlayer m3u buffer overflow attempt (more info ...)attempted-admin 2011-5170 50859  
26244MALWARE-CNC Win.Trojan.Troll variant outbound connection (more info ...)trojan-activity    URL
26245MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
26246OS-MOBILE Android ANDR.Trojan.PremiumSMS APK file download attempt (more info ...)trojan-activity    URL
26247OS-MOBILE Android ANDR.Trojan.PremiumSMS APK file download attempt (more info ...)trojan-activity    URL
26248MALWARE-CNC User-Agent known malicious user agent cibabam (more info ...)trojan-activity    URL
26250BROWSER-PLUGINS Google Apps mailto URI argument injection attempt (more info ...)attempted-user  36581  
26257OS-MOBILE Android ANDR-WIN.MSIL variant PC-USB Malicious executable file download (more info ...)trojan-activity    URL
26260MALWARE-CNC Win.Trojan.Downloader.Vectmp variant outbound connection (more info ...)trojan-activity    URL
26262SERVER-OTHER MongoDB nativeHelper.apply method command injection attempt (more info ...)attempted-admin 2013-1892 58695  
26264MALWARE-CNC Dapato banking Trojan variant outbound connection (more info ...)trojan-activity    URL
26272OS-MOBILE Android ANDR.Trojan.Chuli APK file download attempt (more info ...)trojan-activity    URL
26273OS-MOBILE Android ANDR.Trojan.Chuli APK file download attempt (more info ...)trojan-activity    URL
26280FILE-PDF Foxit Reader remote query string buffer overflow attempt (more info ...)attempted-user  57174  URL
26281FILE-PDF Foxit Reader remote query string buffer overflow attempt (more info ...)attempted-user  57174  URL
26282FILE-PDF Foxit Reader remote query string buffer overflow attempt (more info ...)attempted-user  57174  URL
26283FILE-PDF Foxit Reader remote query string buffer overflow attempt (more info ...)attempted-user  57174  URL
26284MALWARE-CNC Win.Trojan.Surok variant outbound connection (more info ...)trojan-activity    URL
26285MALWARE-CNC Win.Trojan.Downloader.Garveep variant outbound connection (more info ...)trojan-activity    URL
26288MALWARE-CNC Brontok Worm variant outbound connection (more info ...)trojan-activity    URL
26289MALWARE-CNC Daws Trojan Outbound Plaintext over SSL Port (more info ...)trojan-activity    URL
26290OS-MOBILE Android ANDR.Trojan.RootSmart outbound communication attempt (more info ...)trojan-activity    URL
26291OS-MOBILE Android Ksapp device registration (more info ...)trojan-activity    URL
26298SERVER-WEBAPP Media Wiki script injection attempt (more info ...)web-application-attack 2006-2611   
26317FILE-MULTIMEDIA Cool Player Plus M3U buffer overflow attempt (more info ...)attempted-user    URL
26318FILE-MULTIMEDIA Cool Player Plus M3U buffer overflow attempt (more info ...)attempted-user    URL
26319MALWARE-CNC file path used as User-Agent - potential Trojan (more info ...)trojan-activity    URL
26320SERVER-WEBAPP Redmine SCM rev parameter command injection attempt (more info ...)attempted-admin 2011-4929   URL
26325MALWARE-CNC Win.Trojan.Scar variant outbound connection (more info ...)trojan-activity    URL
26331MALWARE-CNC Win.Trojan.Qhost variant outbound connection (more info ...)trojan-activity    URL
26335MALWARE-CNC FBI Ransom Trojan variant outbound connection (more info ...)trojan-activity    
26370MALWARE-CNC Win.Trojan.Bancos variant outbound connection - ksa.txt (more info ...)trojan-activity    URL
26371MALWARE-CNC Win.Trojan.Bancos variant outbound connection - op POST (more info ...)trojan-activity    URL
26372FILE-IMAGE ClamAV Antivirus Function Denial of Service attempt (more info ...)attempted-dos 2008-5314 32555  
26373FILE-IMAGE ClamAV Antivirus Function Denial of Service attempt (more info ...)attempted-dos 2008-5314 32555  
26374FILE-IMAGE ClamAV Antivirus Function Denial of Service attempt (more info ...)attempted-dos 2008-5314 32555  
26379SERVER-OTHER Squid proxy Accept-Language denial of service attempt (more info ...)denial-of-service 2013-1839 58316  
26386SERVER-OTHER Polycom HDX authorization bypass attempt (more info ...)attempted-admin  58523  
26387OS-MOBILE Android Stels initial server contact (more info ...)trojan-activity    URL
26388OS-MOBILE Android Stels server response (more info ...)trojan-activity    URL
26389SERVER-OTHER BigAnt Document Service DUPF command arbitrary file upload attempt (more info ...)attempted-admin 2012-6274 57214  
26390SERVER-OTHER BigAnt Document Service DUPF command arbitrary file upload attempt (more info ...)attempted-admin 2012-6274 57214  
26391PROTOCOL-POP libcurl MD5 digest buffer overflow attempt (more info ...)attempted-user 2013-0249 57842  
26395APP-DETECT Ufasoft bitcoin miner possible data upload (more info ...)policy-violation    URL
26398MALWARE-CNC Win.Trojan.Gamarue variant outbound connection (more info ...)trojan-activity    URL
26410INDICATOR-COMPROMISE IP address check to j.maxmind.com detected (more info ...)misc-activity    
26411MALWARE-OTHER Win.Worm.Dorkbot folder snkb0ptz creation attempt SMB (more info ...)trojan-activity    
26412MALWARE-OTHER Win.Worm.Dorkbot executable snkb0ptz.exe creation attempt SMB (more info ...)trojan-activity    
26413MALWARE-OTHER Win.Worm.Dorkbot Desktop.ini snkb0ptz.exe creation attempt SMB (more info ...)trojan-activity    
26418SERVER-WEBAPP HP System Management iprange parameter buffer overflow attempt (more info ...)attempted-admin 2013-2362   URL
26428MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
26435MALWARE-CNC Win.Trojan.Duqu variant outbound connection (more info ...)trojan-activity    URL
26436SERVER-WEBAPP HP Intelligent Management Center FaultDownloadServlet information disclosure attempt (more info ...)attempted-recon 2014-2620 68544  URL
26437PUA-OTHER Bitcoin inbound response attempt (more info ...)policy-violation    URL
26438PUA-OTHER Bitcoin outbound request attempt (more info ...)policy-violation    URL
26442OS-MOBILE Android MDK encrypted information leak (more info ...)trojan-activity    URL
26443OS-MOBILE Android MDK encrypted information leak (more info ...)trojan-activity    URL
26444MALWARE-CNC Win.Trojan.Downloader.Agent variant outbound connection (more info ...)trojan-activity    URL
26446MALWARE-CNC Win.Trojan.Downloader.Agent variant outbound connection (more info ...)trojan-activity    URL
26447MALWARE-CNC Win.Trojan.Smoaler variant outbound connection (more info ...)trojan-activity    URL
26448MALWARE-CNC Win.Trojan.Fakesig variant outbound connection (more info ...)trojan-activity    URL
26449MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
26450MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
26452MALWARE-CNC Win.Trojan.Buterat variant outbound connection (more info ...)trojan-activity    URL
26454SERVER-OTHER UltraVNC Listening mode stack buffer overflow attempt (more info ...)attempted-user 2008-0610   
26455SERVER-OTHER UltraVNC Listening mode stack buffer overflow attempt (more info ...)attempted-user 2008-0610   
26459FILE-OTHER Shadow Stream Recorder asx file buffer overflow attempt (more info ...)attempted-user 2009-1645 34864  
26460FILE-OTHER Shadow Stream Recorder asx file buffer overflow attempt (more info ...)attempted-user 2009-1645 34864  
26461FILE-OTHER Shadow Stream Recorder asx file buffer overflow attempt (more info ...)attempted-user 2009-1645 34864  
26462FILE-OTHER Shadow Stream Recorder asx file buffer overflow attempt (more info ...)attempted-user 2009-1645 34864  
26463MALWARE-CNC Win.Trojan.Linog.A variant outbound connection (more info ...)trojan-activity    URL
26464MALWARE-CNC Win.Trojan.Linog.A variant outbound connection (more info ...)trojan-activity    URL
26465FILE-IDENTIFY XUL file attachment detected (more info ...)misc-activity    
26466FILE-IDENTIFY XUL file attachment detected (more info ...)misc-activity    
26467MALWARE-CNC Win.Trojan.Magic variant inbound connection (more info ...)trojan-activity    URL
26468SERVER-ORACLE Oracle WebCenter FatWire Satellite Server header injection on blobheadername2 attempt (more info ...)web-application-attack 2013-1509   URL
26469SERVER-ORACLE Oracle WebCenter FatWire Satellite Server header injection on blobheadername2 attempt (more info ...)web-application-attack 2013-1509   URL
26473FILE-OTHER CoolPlayer playlist file handling buffer overflow attempt (more info ...)attempted-user 2008-3408 30418  
26474FILE-OTHER CoolPlayer playlist file handling buffer overflow attempt (more info ...)attempted-user 2008-3408 30418  
26475FILE-OTHER CoolPlayer playlist file handling buffer overflow attempt (more info ...)attempted-user 2008-3408 30418  
26476FILE-OTHER CoolPlayer playlist file handling buffer overflow attempt (more info ...)attempted-user 2008-3408 30418  
26477FILE-OTHER CoolPlayer playlist file handling buffer overflow attempt (more info ...)attempted-user 2008-3408 30418  
26478FILE-OTHER CoolPlayer playlist file handling buffer overflow attempt (more info ...)attempted-user 2008-3408 30418  
26479SERVER-OTHER ActFax LPD Server data field buffer overflow attempt (more info ...)attempted-admin  57789  
26480MALWARE-CNC Win.Trojan.Zbot fake PNG config file download without User-Agent (more info ...)trojan-activity    
26482MALWARE-CNC Unknown Thinner Encrypted POST botnet C&C (more info ...)trojan-activity    URL
26491SERVER-OTHER Nagios NRPE command execution attempt (more info ...)attempted-admin 2013-1362 58142  
26492FILE-IDENTIFY KingView KingMessage log file download request (more info ...)misc-activity    
26493FILE-IDENTIFY KingView KingMessage log file attachment detected (more info ...)misc-activity    
26494FILE-IDENTIFY KingView KingMessage log file attachment detected (more info ...)misc-activity    
26501SERVER-OTHER BigAnt Document Service DDNF request stack buffer overflow attempt (more info ...)attempted-admin    
26505SERVER-WEBAPP HP Intelligent Management Center IctDownloadServlet information disclosure attempt (more info ...)attempted-recon 2014-2621 68546  URL
26514FILE-IDENTIFY maplet file download attempt (more info ...)misc-activity    
26515FILE-IDENTIFY maplet file attachment detected (more info ...)misc-activity    
26516FILE-IDENTIFY maplet file attachment detected (more info ...)misc-activity    
26517FILE-IDENTIFY maplet bin file download attempt (more info ...)misc-activity    
26520FILE-OTHER Maple Maplet File Creation and Command Execution attempt (more info ...)attempted-user    
26521FILE-OTHER Maple Maplet File Creation and Command Execution attempt (more info ...)attempted-user    
26522MALWARE-CNC User-Agent known malicious user agent NOKIAN95/WEB (more info ...)trojan-activity    URL
26523SERVER-WEBAPP HP Intelligent Management Center ReportImgServlet information disclosure attempt (more info ...)attempted-recon 2012-5203 58672  URL
26533MALWARE-CNC Unknown malware - Incorrect headers - Referer HTTP/1.0 (more info ...)trojan-activity    
26542SERVER-OTHER Autonomy Ultraseek cs.html url parameter with url - possible malicious redirection attempt (more info ...)misc-attack 2009-0347   
26553PUA-ADWARE Win.Adware.BProtector browser hijacker dll list download attempt (more info ...)misc-activity    
26558MALWARE-CNC User-Agent known Malicious user agent Brutus AET (more info ...)misc-activity    URL
26560MALWARE-CNC Win.Trojan.Bancos variant outbound connection - getcomando POST data (more info ...)trojan-activity    URL
26561MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    
26562EXPLOIT-KIT Nuclear exploit kit Spoofed Host Header .com- requests (more info ...)trojan-activity    
26563MALWARE-CNC Harakit botnet traffic (more info ...)trojan-activity    URL
26565INDICATOR-OBFUSCATION base64-encoded nop sled detected (more info ...)trojan-activity    URL
26566INDICATOR-OBFUSCATION base64-encoded nop sled detected (more info ...)trojan-activity    URL
26567INDICATOR-OBFUSCATION base64-encoded nop sled detected (more info ...)trojan-activity    URL
26568INDICATOR-OBFUSCATION eval of base64-encoded data (more info ...)trojan-activity    URL
26578MALWARE-CNC Win.Trojan.Kazy/FakeAV Checkin with IE6 User-Agent (more info ...)trojan-activity    URL
26579MALWARE-CNC Win.Trojan.Kazy/FakeAV Checkin with IE6 User-Agent (more info ...)trojan-activity    URL
26594PROTOCOL-VOIP Digium Asterisk Management Interface HTTP digest authentication stack buffer overflow attempt (more info ...)attempted-admin    URL
26598FILE-OTHER .tar multiple antivirus evasion attempt (more info ...)attempted-user 2012-1427   
26604MALWARE-CNC Win.Trojan.Bydra variant outbound connection (more info ...)trojan-activity    URL
26605MALWARE-CNC Win.Trojan.Bydra variant outbound connection (more info ...)trojan-activity    URL
26606MALWARE-CNC Win.Trojan.Sosork variant outbound connection (more info ...)trojan-activity    URL
26607MALWARE-CNC Win.Trojan.Korlia variant outbound connection (more info ...)trojan-activity    URL
26608MALWARE-CNC Win.Trojan.Rocra variant outbound connection (more info ...)trojan-activity    URL
26609MALWARE-CNC OSX.Trojan.Dockster variant outbound connection (more info ...)trojan-activity    URL
26613MALWARE-CNC Medfos Trojan variant outbound connection (more info ...)trojan-activity    URL
26619INDICATOR-OBFUSCATION multiple comment tags used in embedded RTF object - potentially malicious (more info ...)misc-attack    URL
26620INDICATOR-OBFUSCATION multiple comment tags used in embedded RTF object - potentially malicious (more info ...)misc-attack    URL
26644SERVER-OTHER SSL TLS DEFLATE compression detected (more info ...)misc-activity    
26645SERVER-OTHER SSL TLS deflate compression weakness brute force attempt (more info ...)attempted-recon 2012-4929 55704  URL
26657MALWARE-CNC Win.Trojan.Shiz variant outbound connection (more info ...)trojan-activity    URL
26662FILE-PDF PDF with click-to-launch executable (more info ...)misc-activity 2010-1240   URL
26669SERVER-WEBAPP HP Intelligent Management Center SyslogDownloadServlet information disclosure attempt (more info ...)attempted-recon 2012-5206 58385  URL
26677MALWARE-CNC Win.Trojan.Kuluoz variant inbound run command from cnc (more info ...)trojan-activity    URL
26678MALWARE-CNC Win.Trojan.Kuluoz variant inbound run command from cnc (more info ...)trojan-activity    URL
26679MALWARE-CNC Win.Trojan.Kuluoz variant inbound run command from cnc (more info ...)trojan-activity    URL
26680MALWARE-CNC Win.Trojan.Kuluoz variant inbound run command from cnc (more info ...)trojan-activity    URL
26681MALWARE-CNC Win.Trojan.Kuluoz variant inbound run command from cnc (more info ...)trojan-activity    URL
26683MALWARE-CNC Win.Trojan.Shyape variant outbound connection (more info ...)trojan-activity    URL
26684MALWARE-CNC Win.Trojan.Neshax variant outbound connection (more info ...)trojan-activity    URL
26685MALWARE-CNC User-Agent known malicious user-agent string J13A (more info ...)trojan-activity    URL
26686MALWARE-CNC User-Agent known malicious user agent - Alina (more info ...)trojan-activity    URL
26689OS-MOBILE Android Denofow phone information exfiltration (more info ...)trojan-activity    URL
26690MALWARE-CNC Miniduke server contact (more info ...)trojan-activity    URL
26691MALWARE-CNC Win.Trojan.UFRStealer variant outbound connection (more info ...)trojan-activity    URL
26692MALWARE-CNC Win.Trojan.Spyremoav variant outbound connection (more info ...)trojan-activity    URL
26693OS-MOBILE Android Antammi device information exfiltration (more info ...)trojan-activity    URL
26695MALWARE-CNC Win.Trojan.Namihno variant outbound request (more info ...)trojan-activity    
26696MALWARE-CNC Cbeplay Ransomware variant outbound connection - Abnormal HTTP Headers (more info ...)trojan-activity    URL
26697MALWARE-CNC Cbeplay Ransomware variant outbound connection - POST Body (more info ...)trojan-activity    URL
26702MALWARE-CNC User-Agent known malicious user agent - Win (more info ...)trojan-activity    URL
26703MALWARE-CNC Win.Trojan.Upero variant outbound connection (more info ...)trojan-activity    URL
26704SERVER-WEBAPP LANDesk Thinkmanagement Suite ServerSetup directory traversal attempt (more info ...)attempted-user 2012-1196 52023  
26705OS-MOBILE Android Ewalls device information exfiltration (more info ...)trojan-activity    URL
26712MALWARE-CNC Kazy Trojan check-in (more info ...)trojan-activity    URL
26713MALWARE-CNC Win.Trojan.BlackRev rev 1 outbound traffic (more info ...)trojan-activity    URL
26714MALWARE-CNC Win.Trojan.BlackRev rev 2 outbound traffic (more info ...)trojan-activity    URL
26715MALWARE-CNC Win.Trojan.BlackRev rev 3 outbound traffic (more info ...)trojan-activity    URL
26719MALWARE-CNC Win.Trojan.Kbot variant outbound connection (more info ...)trojan-activity    URL
26720MALWARE-CNC Win.Trojan.Kbot variant outbound connection (more info ...)trojan-activity    URL
26721MALWARE-CNC Pushdo Spiral Traffic (more info ...)trojan-activity    URL
26722MALWARE-CNC Bancos fake JPG encrypted config file download (more info ...)trojan-activity    
26723MALWARE-CNC Trojan Downloader7 (more info ...)trojan-activity    URL
26725MALWARE-CNC Win.Trojan.BlackRev cnc http command (more info ...)trojan-activity    URL
26726MALWARE-CNC Win.Trojan.BlackRev cnc stop command (more info ...)trojan-activity    URL
26727MALWARE-CNC Win.Trojan.BlackRev cnc die command (more info ...)trojan-activity    URL
26728MALWARE-CNC Win.Trojan.BlackRev cnc sleep command (more info ...)trojan-activity    URL
26729MALWARE-CNC Win.Trojan.BlackRev cnc simple command (more info ...)trojan-activity    URL
26730MALWARE-CNC Win.Trojan.BlackRev cnc loginpost command (more info ...)trojan-activity    URL
26731MALWARE-CNC Win.Trojan.BlackRev cnc datapost command (more info ...)trojan-activity    URL
26732MALWARE-CNC Win.Trojan.BlackRev cnc syn command (more info ...)trojan-activity    URL
26733MALWARE-CNC Win.Trojan.BlackRev cnc udp command (more info ...)trojan-activity    URL
26734MALWARE-CNC Win.Trojan.BlackRev cnc udpdata command (more info ...)trojan-activity    URL
26735MALWARE-CNC Win.Trojan.BlackRev cnc data command (more info ...)trojan-activity    URL
26737MALWARE-CNC Win.Trojan.BlackRev cnc tcpdata command (more info ...)trojan-activity    URL
26738MALWARE-CNC Win.Trojan.BlackRev cnc dataget command (more info ...)trojan-activity    URL
26739MALWARE-CNC Win.Trojan.BlackRev cnc connect command (more info ...)trojan-activity    URL
26741MALWARE-CNC Win.Trojan.BlackRev cnc exec command (more info ...)trojan-activity    URL
26742MALWARE-CNC Win.Trojan.BlackRev cnc resolve command (more info ...)trojan-activity    URL
26743MALWARE-CNC Win.Trojan.BlackRev cnc antiddos command (more info ...)trojan-activity    URL
26744MALWARE-CNC Win.Trojan.BlackRev cnc range command (more info ...)trojan-activity    URL
26746MALWARE-CNC Win.Trojan.BlackRev cnc download command (more info ...)trojan-activity    URL
26747MALWARE-CNC Win.Trojan.BlackRev cnc fastddos command (more info ...)trojan-activity    URL
26748MALWARE-CNC Win.Trojan.BlackRev cnc slowhttp command (more info ...)trojan-activity    URL
26749MALWARE-CNC Win.Trojan.BlackRev cnc allhttp command (more info ...)trojan-activity    URL
26750MALWARE-CNC Win.Trojan.BlackRev cnc full command (more info ...)trojan-activity    URL
26751MALWARE-CNC User-Agent known malicious user agent - msctls_progress32 (more info ...)trojan-activity    URL
26756MALWARE-CNC Win.Trojan.Dropper.Datcaen variant outbound connection (more info ...)trojan-activity    URL
26757MALWARE-CNC Win.Trojan.Dropper.Datcaen variant outbound connection (more info ...)trojan-activity    URL
26758MALWARE-CNC Win.Trojan.Elefin variant outbound connection (more info ...)trojan-activity    URL
26760OS-MOBILE Android Fakeinst device information leakage (more info ...)trojan-activity    URL
26761OS-MOBILE Android Fakeinst device information leakage (more info ...)trojan-activity    URL
26763MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
26768OS-MOBILE Android Fakedoc device information leakage (more info ...)trojan-activity    URL
26770MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
26771MALWARE-CNC Win.Trojan.Spy.Banker variant outbound connection (more info ...)trojan-activity    URL
26774MALWARE-CNC Win.Worm.Luder variant outbound connection (more info ...)trojan-activity    URL
26775MALWARE-CNC Win.Trojan.Blocker variant outbound connection HTTP Header Structure (more info ...)trojan-activity    URL
26776MALWARE-CNC Win.Trojan.Blocker variant outbound connection POST (more info ...)trojan-activity    URL
26777MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
26779MALWARE-CNC Win.Trojan.Cridex encrypted POST check-in (more info ...)trojan-activity    URL
26780MALWARE-CNC cridex HTTP Response - default0.js (more info ...)trojan-activity    URL
26783OS-MOBILE Android ANDR.Trojan.Opfake APK file download (more info ...)trojan-activity    URL
26784MALWARE-CNC Win.Trojan.Nivdort variant outbound connection (more info ...)trojan-activity    URL
26785MALWARE-CNC Win.Trojan.Qrmon variant outbound connection (more info ...)trojan-activity    URL
26788INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
26789INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
26790INDICATOR-SHELLCODE unescape encoded shellcode (more info ...)shellcode-detect    
26792MALWARE-CNC Win.Trojan.Vbula variant outbound connection (more info ...)trojan-activity    URL
26793MALWARE-CNC Win.Trojan.Vbula variant initial CNC contact (more info ...)trojan-activity    URL
26794SERVER-WEBAPP HP Intelligent Management Center UAM acmServletDownload information disclosure attempt (more info ...)attempted-recon 2012-5211 58385  URL
26795OS-MOBILE Android ANDR.Trojan.ZertSecurity apk download (more info ...)trojan-activity    URL
26809MALWARE-CNC Win.Trojan.Backdoor.Tomvode variant outbound connection (more info ...)trojan-activity    URL
26811MALWARE-CNC XP Fake Antivirus Payment Page Request (more info ...)trojan-activity    URL
26812MALWARE-CNC XP Fake Antivirus Check-in (more info ...)trojan-activity    URL
26813MALWARE-CNC Win.Trojan.Dapato CMS spambot check-in (more info ...)trojan-activity    URL
26814EXPLOIT-KIT Blackholev2 exploit kit Initial Gate from Linked-In Mailing Campaign (more info ...)trojan-activity    
26815MALWARE-CNC OSX.Trojan.KitM variant outbound connection user-agent (more info ...)trojan-activity    URL
26816MALWARE-CNC OSX.Trojan.KitM variant outbound connection (more info ...)trojan-activity    URL
26818MALWARE-CNC Win.Trojan.Downloader.Zawat variant outbound connection (more info ...)trojan-activity    URL
26819MALWARE-CNC Win.Trojan.Datash variant outbound connection (more info ...)trojan-activity    URL
26820MALWARE-CNC Win.Trojan.Datash variant outbound connection (more info ...)trojan-activity    URL
26822MALWARE-CNC Win.Trojan.Buterat variant outbound connection (more info ...)trojan-activity    URL
26826OS-MOBILE Android ANDR.Trojan.Opfake credential theft attempt (more info ...)trojan-activity    URL
26827OS-MOBILE Android ANDR.Trojan.Opfake device information disclosure attempt (more info ...)trojan-activity    URL
26828MALWARE-CNC Win.Trojan.Uperti variant outbound connection (more info ...)trojan-activity    URL
26835MALWARE-CNC RDN Banker POST variant outbound connection (more info ...)trojan-activity    URL
26836MALWARE-CNC RDN Banker Strange Google Traffic (more info ...)trojan-activity    URL
26837MALWARE-CNC BitBot Idle C2 response (more info ...)trojan-activity    
26838EXPLOIT-KIT Blackholev2 exploit kit Initial Gate from NatPay Mailing Campaign (more info ...)trojan-activity    
26840MALWARE-CNC Win.Trojan.Spy.Agent variant outbound connection (more info ...)trojan-activity    URL
26841MALWARE-CNC Win.Trojan.Spy.Agent variant outbound connection (more info ...)trojan-activity    URL
26879BROWSER-OTHER local loopback address in html (more info ...)unknown    URL
26880MALWARE-CNC Win.Trojan.Zotob.E gc.exe download (more info ...)trojan-activity    
26905SERVER-WEBAPP FosWiki and TWiki MAKETEXT macro memory consumption denial of service attempt (more info ...)attempted-dos 2012-6330 56950  URL
26906SERVER-OTHER Foswiki/Twiki MAKETEXT command execution attempt (more info ...)attempted-admin 2012-6329 56950  
26907SERVER-WEBAPP TWiki search function remote code execution attempt (more info ...)attempted-user 2004-1037 11674  
26908SERVER-WEBAPP TWiki search function remote code execution attempt (more info ...)attempted-user 2004-1037 11674  
26910MALWARE-CNC ZeroAccess Encrypted 128-byte POST No Accept Headers (more info ...)trojan-activity    
26911MALWARE-CNC Win.Trojan.Rombrast Trojan outbound connection (more info ...)trojan-activity    URL
26912MALWARE-CNC Win.Trojan.Rombrast Trojan outbound connection (more info ...)trojan-activity    URL
26924MALWARE-CNC Potential Gozi Trojan HTTP Header Structure (more info ...)trojan-activity    
26926FILE-OTHER Multiple products ZIP archive virus detection bypass attempt (more info ...)bad-unknown 2004-0932 11448  
26931MALWARE-CNC Win.Trojan.Zeroaccess variant outbound connection (more info ...)trojan-activity    
26932MALWARE-CNC Win.Trojan.Zeroaccess variant outbound connection (more info ...)trojan-activity    
26938OS-MOBILE Android Tetus device information leakage (more info ...)trojan-activity    URL
26939OS-MOBILE Android Tetus device information leakage variant (more info ...)trojan-activity    URL
26941MALWARE-CNC Win.Trojan.PipCreat RAT dropper download (more info ...)trojan-activity    URL
26944MALWARE-CNC Win.Trojan.Post_Show RAT beacon (more info ...)trojan-activity    
26945MALWARE-CNC Win.Trojan.Bisonal RAT beacon (more info ...)trojan-activity    
26946MALWARE-CNC Win.Trojan.Uptime RAT beacon (more info ...)trojan-activity    
26952MALWARE-CNC Win.Trojan.Orcim variant outbound connection (more info ...)trojan-activity    URL
26953SERVER-WEBAPP D-Link DIR-300/DIR-600 unauthenticated remote command execution attempt (more info ...)attempted-admin  57734  URL
26954MALWARE-CNC Win.Backdoor.Talsab variant outbound connection (more info ...)trojan-activity    URL
26955MALWARE-CNC Win.Backdoor.Talsab variant outbound connection (more info ...)trojan-activity    URL
26965MALWARE-CNC Win.Trojan.Win32 Facebook Secure Cryptor C2 (more info ...)trojan-activity    URL
26966MALWARE-CNC Win32/Autorun.JN variant outbound connection (more info ...)trojan-activity    URL
26967MALWARE-CNC Win.Trojan.Kuluoz variant outbound connection (more info ...)trojan-activity    URL
26968MALWARE-CNC Win.Trojan.Gozi Data Theft POST Data (more info ...)trojan-activity    URL
26969MALWARE-CNC Win.Trojan.Gozi Trojan Data Theft POST URL (more info ...)trojan-activity    URL
26970MALWARE-CNC Win.Trojan.Pirminay variant outbound connection (more info ...)trojan-activity    URL
26972SERVER-OTHER CUPS IPP multi-valued attribute memory corruption attempt (more info ...)attempted-admin 2010-2941 44530  URL
26984MALWARE-CNC Win.Trojan.Injector Info Stealer Trojan variant outbound connection (more info ...)trojan-activity    URL
26986MALWARE-CNC Win.Trojan.Xenil variant outbound connection (more info ...)trojan-activity    URL
26987MALWARE-CNC Win.Trojan.Cyvadextr variant outbound connection (more info ...)trojan-activity    URL
26989FILE-OTHER Multiple products ZIP archive virus detection bypass attempt (more info ...)bad-unknown 2004-0932 11448  
26995MALWARE-CNC Win.Trojan.Downloader.Agent variant outbound connection (more info ...)trojan-activity    URL
26996MALWARE-CNC Win.Trojan.Downloader.Agent variant outbound connection (more info ...)trojan-activity    URL
26997MALWARE-CNC OSX.Trojan.Morcut variant outbound connection (more info ...)trojan-activity    URL
26998MALWARE-CNC OSX.Trojan.Morcut file download (more info ...)trojan-activity    URL
26999MALWARE-CNC Win.Trojan.Chinoxy variant outbound connection (more info ...)trojan-activity    URL
27000MALWARE-CNC Win.Trojan.Chinoxy variant outbound connection (more info ...)trojan-activity    URL
27002MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
27003MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
27007MALWARE-CNC Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity    URL
27010MALWARE-CNC Win.Trojan.Zbot payment .scr download (more info ...)trojan-activity    URL
27012MALWARE-CNC Win.Trojan.Phoenot variant outbound connection (more info ...)trojan-activity    URL
27013MALWARE-CNC Win.Trojan.Phoenot variant inbound connection (more info ...)trojan-activity    URL
27014MALWARE-CNC Win.Trojan.Epipenwa variant outbound connection (more info ...)trojan-activity    URL
27015MALWARE-CNC User-Agent known malicious user-agent string iexplorer (more info ...)trojan-activity    URL
27016OS-MOBILE Android AnserverBot initial contact (more info ...)trojan-activity    URL
27017MALWARE-CNC Win.Trojan.Dapato variant inbound response connection (more info ...)trojan-activity    URL
27021MALWARE-CNC Win.Trojan.Layvam variant outbound connection (more info ...)trojan-activity    URL
27022MALWARE-CNC Win.Trojan.Netweird.A outbound connection (more info ...)trojan-activity    URL
27023MALWARE-CNC Win.Trojan.Netweird.A outbound connection (more info ...)trojan-activity    URL
27031OS-MOBILE Android Satfi device information leakage (more info ...)trojan-activity    URL
27032OS-MOBILE Android Walkinwat / Wandt information leakage generic (more info ...)trojan-activity    URL
27033MALWARE-CNC Win.Backdoor.Transhell variant outbound connection user-agent (more info ...)trojan-activity    URL
27037OS-MOBILE Android Vidro / EClips sms send instructions (more info ...)trojan-activity    URL
27038OS-MOBILE Android Vidro / EClips device information leakage (more info ...)trojan-activity    URL
27039MALWARE-CNC Win.Trojan.OnlineGameHack variant outbound connection (more info ...)trojan-activity    URL
27044MALWARE-CNC User-Agent known malicious user-agent string pb - Htbot (more info ...)trojan-activity    URL
27045MALWARE-CNC Win.Trojan.Blocker Download (more info ...)trojan-activity    URL
27047INDICATOR-COMPROMISE Unknown ?1 redirect (more info ...)bad-unknown    
27049MALWARE-CNC Win.Trojan.Dokstormac variant outbound connection (more info ...)trojan-activity    URL
27054MALWARE-CNC Win.Trojan.Yakes variant outbound connection (more info ...)trojan-activity    URL
27057MALWARE-CNC Win.Trojan.Dalbot variant outbound connection (more info ...)trojan-activity    URL
27058MALWARE-CNC OSX.Trojan.HackBack variant outbound connection (more info ...)trojan-activity    URL
27064OS-MOBILE Android Spy2Mobile device information leakage (more info ...)trojan-activity    URL
27068EXPLOIT-KIT Blackholev2 exploit kit malicious jar file download (more info ...)trojan-activity    
27069EXPLOIT-KIT Blackholev2 exploit kit malicious portable executable download (more info ...)trojan-activity    
27091MALWARE-CNC Win.Trojan.Weavun variant outbound connection (more info ...)trojan-activity    URL
27093MALWARE-CNC Win.Trojan.Medfos variant outbound connection (more info ...)trojan-activity    
27094OS-MOBILE Android ANDR.Trojan.FakeToken information disclosure attempt (more info ...)trojan-activity    URL
27095OS-MOBILE Android ANDR.Trojan.FakeToken APK file download attempt (more info ...)trojan-activity    URL
27096FILE-OTHER XML exponential entity expansion attack attempt (more info ...)attempted-user 2013-1821   
27097OS-MOBILE Android ANDR.Trojan.SMSSilence APK file download attempt (more info ...)trojan-activity    URL
27098OS-MOBILE Android ANDR.Trojan.SMSSilence unsolicited sms attempt (more info ...)trojan-activity    URL
27099OS-MOBILE Android ANDR.Trojan.SMSSilence device information disclosure attempt (more info ...)trojan-activity    URL
27106EXPLOIT-KIT Blackholev2 exploit kit malicious jar download (more info ...)trojan-activity    
27107EXPLOIT-KIT Blackholev2 exploit kit malicious jar download (more info ...)trojan-activity    
27109EXPLOIT-KIT Blackholev2/Cool exploit kit malicious jar download (more info ...)trojan-activity    
27114MALWARE-CNC Win.Trojan.Agent.xii variant outbound connection (more info ...)trojan-activity    URL
27116OS-MOBILE Android Androrat device information leakage (more info ...)trojan-activity    URL
27117OS-MOBILE Android Androrat sms message leakage (more info ...)trojan-activity    URL
27118OS-MOBILE Android Androrat contact list leakage (more info ...)trojan-activity    URL
27119INDICATOR-OBFUSCATION multiple plugin version detection attempt (more info ...)attempted-recon    URL
27120MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
27158MALWARE-CNC Win.Trojan.Eliseantry variant outbound connection (more info ...)trojan-activity    URL
27159MALWARE-CNC Win.Trojan.Pesut variant outbound connection (more info ...)trojan-activity    URL
27160MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
27161SERVER-WEBAPP Dasdec unauthenticated information disclosure vulnerability (more info ...)web-application-activity    URL
27162SERVER-WEBAPP Dasdec unauthenticated information disclosure vulnerability (more info ...)web-application-activity    URL
27163SERVER-WEBAPP Dasdec unauthenticated information disclosure vulnerability (more info ...)web-application-activity    URL
27164SERVER-WEBAPP Dasdec unauthenticated information disclosure vulnerability (more info ...)web-application-activity    URL
27169MALWARE-CNC Win.Trojan.Atezag variant outbound connection (more info ...)trojan-activity    URL
27178MALWARE-CNC Win.Trojan.Wergimog variant outbound connection (more info ...)trojan-activity    URL
27199MALWARE-CNC Win.Trojan.Meredrop variant outbound connection GET Request (more info ...)trojan-activity    URL
27200MALWARE-CNC Win.Trojan.Meredrop variant outbound connection POST Request (more info ...)trojan-activity    URL
27201MALWARE-CNC Win.Trojan.Neurevt variant outbound connection (more info ...)trojan-activity    
27204MALWARE-CNC Potential Bancos Brazilian Banking Trojan Browser Proxy Autoconfig File (more info ...)trojan-activity    
27210SERVER-OTHER IPMI RAKP cipher zero remote authentication bypass attempt (more info ...)attempted-admin 2013-4784   URL
27240SERVER-OTHER multiple vendors IPMI RAKP username brute force attempt (more info ...)attempted-admin 2019-1908   URL
27241EXPLOIT-KIT Blackholev2 exploit kit landing page detected (more info ...)trojan-activity    
27248MALWARE-CNC Win.Trojan.Gamarue - Mozi1la User-Agent (more info ...)trojan-activity    URL
27252MALWARE-CNC Win.Trojan.ZeroAccess 111-byte URL variant outbound connection (more info ...)trojan-activity    
27253MALWARE-CNC Win.Trojan.Cridex Encrypted POST w/ URL Pattern (more info ...)trojan-activity    URL
27254MALWARE-CNC Yakes Trojan HTTP Header Structure (more info ...)trojan-activity    URL
27255INDICATOR-COMPROMISE All Numbers .EXE file name from abnormally ordered HTTP headers - Potential Yakes Trojan Download (more info ...)trojan-activity    URL
27256MALWARE-CNC Win.Trojan.Kryptik Drive-by Download Malware (more info ...)trojan-activity    URL
27257MALWARE-CNC Win.Trojan.Kryptic 7-byte URI Invalid Firefox Headers - no Accept-Language (more info ...)trojan-activity    URL
27258INDICATOR-OBFUSCATION eval large block of fromCharCode (more info ...)attempted-user    URL
27259INDICATOR-OBFUSCATION eval large block of fromCharCode (more info ...)attempted-user    URL
27263MALWARE-CNC User-Agent known malicious user agent - yahoonews (more info ...)trojan-activity    URL
27275FILE-IDENTIFY Trimble SketchUp file attachment detected (more info ...)misc-activity    
27276FILE-IDENTIFY Trimble SketchUp file attachment detected (more info ...)misc-activity    
27277FILE-IDENTIFY Trimble SketchUp file download request (more info ...)misc-activity    
27278FILE-OTHER Trimble SketchUp PICT color entries buffer overflow attempt (more info ...)attempted-user 2013-3664 60248  
27279FILE-OTHER Trimble SketchUp PICT color entries buffer overflow attempt (more info ...)attempted-user 2013-3664 60248  
27280FILE-OTHER Trimble SketchUp PICT color entries buffer overflow attempt (more info ...)attempted-user 2013-3664 60248  
27281FILE-OTHER Trimble SketchUp PICT color entries buffer overflow attempt (more info ...)attempted-user 2013-3664 60248  
27525FILE-IMAGE Directshow GIF logical width overflow attempt (more info ...)attempted-user 2013-3174   
27526FILE-IMAGE Directshow GIF logical height overflow attempt (more info ...)attempted-user 2013-3174   
27527FILE-IMAGE Directshow GIF logical height overflow attempt (more info ...)attempted-user 2013-3174   
27528FILE-IMAGE Directshow GIF logical width overflow attempt (more info ...)attempted-user 2013-3174   
27529FILE-IMAGE Directshow GIF logical height overflow attempt (more info ...)attempted-user 2013-3174   
27530FILE-IMAGE Directshow GIF logical height overflow attempt (more info ...)attempted-user 2013-3174   
27532SERVER-MAIL Exim and Dovecot mail from remote command execution attempt (more info ...)attempted-admin    URL
27533MALWARE-CNC Potential Win.Trojan.Kraziomel Download - 000.jpg (more info ...)trojan-activity    URL
27538MALWARE-OTHER self-signed SSL certificate with default MyCompany Ltd organization name (more info ...)policy-violation    URL
27544MALWARE-CNC Osx.Trojan.Janicab runtime traffic detected (more info ...)trojan-activity 2012-0158   URL
27545MALWARE-CNC Osx.Trojan.Janicab outbound connection (more info ...)trojan-activity 2012-0158   URL
27546MALWARE-CNC Osx.Trojan.Janicab outbound connection (more info ...)trojan-activity 2012-0158   URL
27547MALWARE-CNC Osx.Trojan.Janicab outbound connection (more info ...)trojan-activity 2012-0158   URL
27551MALWARE-CNC Win.Trojan.Lorapu variant outbound connection (more info ...)trojan-activity    URL
27552OS-MOBILE Android Exploit Extra_Field APK file download attempt (more info ...)trojan-activity    
27558MALWARE-CNC Win.Trojan.Bezigate variant outbound connection (more info ...)trojan-activity    URL
27567MALWARE-CNC Win.Trojan.Rovnix malicious download request (more info ...)trojan-activity    URL
27569FILE-IMAGE JPEG parser multipacket heap overflow attempt (more info ...)attempted-admin 2017-16392 11173  URL
27577MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
27578SERVER-OTHER OpenX POST to known backdoored file (more info ...)attempted-admin 2013-4211   URL
27579SERVER-OTHER Sybase Open Server function pointer array code execution attempt (more info ...)attempted-admin  48934  URL
27580FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
27581FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
27584FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
27585FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
27586FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
27587FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
27588FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
27589FILE-OTHER BitDefender Internet Security script code execution attempt (more info ...)attempted-user 2009-0850   
27596MALWARE-CNC Win.Trojan.Redyms variant outbound connection (more info ...)trojan-activity    URL
27600MALWARE-CNC Win.Trojan.Nawpers variant connection (more info ...)trojan-activity    URL
27601MALWARE-CNC Win.Trojan.Noobot variant connection (more info ...)trojan-activity    URL
27602EXPLOIT-KIT Blackholev2 exploit kit landing page - specific structure (more info ...)trojan-activity    
27603EXPLOIT-KIT Blackholev2 exploit kit landing page (more info ...)trojan-activity    
27604POLICY-SPAM FedEX spam campaign outbound connection (more info ...)trojan-activity    
27629MALWARE-CNC Win.Backdoor.Aumlib variant outbound connection (more info ...)trojan-activity    
27630MALWARE-CNC Win.Backdoor.Aumlib variant outbound connection (more info ...)trojan-activity    
27631MALWARE-CNC Win.Backdoor.Aumlib variant outbound connection (more info ...)trojan-activity    
27633MALWARE-CNC Worm.Silly variant outbound connection (more info ...)trojan-activity    URL
27636MALWARE-CNC Win.Trojan.Likseput variant connection (more info ...)trojan-activity    URL
27637MALWARE-CNC Win.Trojan.Syhcmd variant connection (more info ...)trojan-activity    URL
27638SERVER-WEBAPP Hedgehog-CMS Directory traversal attempt (more info ...)web-application-attack 2008-2898 33710  
27639MALWARE-CNC Win.Trojan.Epipenwa variant connection (more info ...)trojan-activity    URL
27640MALWARE-CNC Win.Trojan.Chekafe variant connection (more info ...)trojan-activity    URL
27641MALWARE-CNC Win.Trojan.Meilat variant connection (more info ...)trojan-activity    URL
27642MALWARE-CNC Win.Trojan.Downbot variant connection (more info ...)trojan-activity    URL
27643MALWARE-CNC Win.Trojan.Betabot variant connection (more info ...)trojan-activity    URL
27644MALWARE-CNC Win.Trojan.Merong variant connection (more info ...)trojan-activity    URL
27645MALWARE-CNC Win.Trojan.Binjo variant outbound connection (more info ...)trojan-activity    URL
27647MALWARE-CNC Win.Trojan.Nelaja variant outbound connection (more info ...)trojan-activity    URL
27648MALWARE-CNC Win.Trojan.SpyBanker.ZSL variant outbound connection (more info ...)trojan-activity    URL
27649MALWARE-CNC Brazilian Banking Trojan data theft (more info ...)trojan-activity    
27654MALWARE-CNC Win.Backdoor.Agent variant outbound connection (more info ...)trojan-activity    URL
27655MALWARE-CNC Win.Trojan.Enchanim variant connection (more info ...)trojan-activity    URL
27659MALWARE-CNC Win.Trojan.Gapz variant connection (more info ...)trojan-activity    URL
27660MALWARE-CNC Win.Trojan.Reabfrus variant connection (more info ...)trojan-activity    URL
27661MALWARE-CNC Win.Trojan.Reabfrus variant connection (more info ...)trojan-activity    URL
27662MALWARE-CNC Win.Trojan.Galfun variant outbound connection (more info ...)trojan-activity    URL
27664MALWARE-CNC Win.Trojan.Castov variant connection (more info ...)trojan-activity    URL
27665MALWARE-CNC Win.Trojan.Castov variant connection (more info ...)trojan-activity    URL
27668APP-DETECT Heyoka initial outbound connection attempt (more info ...)policy-violation    
27669APP-DETECT Heyoka outbound communication attempt (more info ...)policy-violation    
27670MALWARE-CNC Win.Trojan.Agent.evf variant connection (more info ...)trojan-activity    URL
27678MALWARE-CNC Win.Trojan.Goolelo variant connection (more info ...)trojan-activity    URL
27679MALWARE-CNC Win.Trojan.Kuluoz variant outbound connection (more info ...)trojan-activity    URL
27680MALWARE-CNC Win.Trojan.ZeroAccess variant outbound connection (more info ...)trojan-activity    
27688SERVER-WEBAPP mxBB MX Faq module_root_path file inclusion attempt (more info ...)web-application-attack 2007-2493 23758  
27690FILE-PDF Foxit PDF Reader authentication bypass attempt (more info ...)attempted-user 2009-0836   URL
27699MALWARE-CNC Win.Trojan.Tartober variant connection (more info ...)trojan-activity    URL
27708MALWARE-CNC Win.Ransomware.Urausy outbound connection (more info ...)trojan-activity    URL
27709MALWARE-CNC User-Agent known malicious user-agent string umbra (more info ...)trojan-activity    URL
27710MALWARE-CNC User-Agent known malicious user-agent string IExplore (more info ...)trojan-activity    URL
27711MALWARE-CNC Win.Trojan.FakeAV variant outbound connection (more info ...)trojan-activity    URL
27712EXPLOIT-KIT Blackholev2 exploit kit redirection injection (more info ...)trojan-activity    
27713EXPLOIT-KIT Blackholev2 exploit kit redirection injection (more info ...)trojan-activity    
27715EXPLOIT-KIT Blackholev2 exploit kit redirection page (more info ...)trojan-activity    
27720MALWARE-CNC Win.Trojan.Kolok variant connection (more info ...)trojan-activity    URL
27726MALWARE-CNC Orbit Downloader denial of service update (more info ...)trojan-activity    URL
27727MALWARE-CNC Orbit Downloader denial of service update (more info ...)trojan-activity    URL
27728MALWARE-CNC Orbit Downloader denial of service update (more info ...)trojan-activity    URL
27729INDICATOR-COMPROMISE request for potential web shell - /Silic.jsp (more info ...)misc-activity    URL
27730INDICATOR-COMPROMISE request for potential web shell - /css3.jsp (more info ...)misc-activity    URL
27731INDICATOR-COMPROMISE request for potential web shell - /inback.jsp (more info ...)misc-activity    URL
27732INDICATOR-COMPROMISE request for potential web shell - /jspspy.jsp (more info ...)misc-activity    URL
27747MALWARE-CNC Win.Trojan.Banechant outbound variant connection (more info ...)trojan-activity    URL
27759MALWARE-CNC Win.Trojan.Treizt variant connection (more info ...)trojan-activity    URL
27774MALWARE-CNC RDN Banker Data Exfiltration (more info ...)trojan-activity    URL
27775MALWARE-CNC Win.Trojan.Fareit variant outbound connection (more info ...)trojan-activity    
27802MALWARE-CNC Win.Trojan.PRISM variant outbound connection (more info ...)trojan-activity    URL
27803MALWARE-CNC Win.Trojan.PRISM variant outbound connection (more info ...)trojan-activity    URL
27804MALWARE-CNC Win.Trojan.PRISM variant outbound connection (more info ...)trojan-activity    URL
27805MALWARE-CNC Win.Trojan.Bisonha variant outbound connection (more info ...)trojan-activity    URL
27806MALWARE-CNC Win.Trojan.Retruse variant connection (more info ...)trojan-activity    URL
27810EXPLOIT-KIT Fiesta exploit kit redirection (more info ...)trojan-activity    
27811MALWARE-CNC Win.Trojan.Mindweq variant connection (more info ...)trojan-activity    URL
27817MALWARE-CNC Win.Trojan.Tenavt connection (more info ...)trojan-activity    URL
27861SERVER-ORACLE Oracle Enterprise Manager Database Control directory traversal attempt (more info ...)attempted-admin 2010-3600 45883  URL
27863SERVER-WEBAPP Ektron CMS XSLT transform remote code execution attempt (more info ...)attempted-admin 2012-5357 56816  URL
27864MALWARE-CNC Win.Trojan.Sinowal variant connection (more info ...)trojan-activity    URL
27867MALWARE-CNC Win.Trojan.Dropper outbound connection (more info ...)trojan-activity    URL
27868MALWARE-CNC User-Agent known malicious user agent - dt12012 (more info ...)trojan-activity    URL
27905MALWARE-CNC Win.Trojan.Helauto variant connection (more info ...)trojan-activity    URL
27907EXPLOIT-KIT Blackholev2/Cool exploit kit payload download attempt (more info ...)trojan-activity    
27913PUA-ADWARE Vittalia adware - get ads (more info ...)trojan-activity    URL
27914PUA-ADWARE Vittalia adware - post install (more info ...)trojan-activity    URL
27915PUA-ADWARE Vittalia adware outbound connection - pre install (more info ...)trojan-activity    URL
27916PUA-TOOLBARS Vittalia adware outbound connection - Eazel toolbar install (more info ...)trojan-activity    URL
27917PUA-TOOLBARS Vittalia adware outbound connection - offers (more info ...)trojan-activity    URL
27918MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
27919MALWARE-CNC Win.Trojan.Zeus encrypted POST Data exfiltration (more info ...)trojan-activity    URL
27921SERVER-ORACLE Oracle Endeca Server createDataStore remote command injection attempt (more info ...)attempted-admin 2013-3763 61217  URL
27922APP-DETECT Splashtop outbound connection attempt (more info ...)policy-violation    URL
27923APP-DETECT Splashtop connection negotiation attempt (more info ...)policy-violation    URL
27924APP-DETECT Splashtop Streamer download attempt (more info ...)policy-violation    URL
27925APP-DETECT Splashtop Personal download attempt (more info ...)policy-violation    URL
27927APP-DETECT Splashtop inbound connection negotiation attempt (more info ...)policy-violation    URL
27928APP-DETECT Splashtop connection attempt (more info ...)policy-violation    URL
27929APP-DETECT Splashtop communication attempt (more info ...)policy-violation    URL
27933APP-DETECT Splashtop streamer download attempt (more info ...)policy-violation    URL
27934APP-DETECT Splashtop personal download attempt (more info ...)policy-violation    URL
27939MALWARE-CNC Win.Trojan.Galock variant connection (more info ...)trojan-activity    URL
27955MALWARE-CNC Win.Trojan.Mevade variant outbound connection (more info ...)trojan-activity    URL
27963MALWARE-CNC Win.Trojan.Lolbot variant outbound connection (more info ...)trojan-activity    URL
27964MALWARE-CNC Win.Trojan.Gh0st variant outbound connection (more info ...)trojan-activity    URL
27965MALWARE-CNC Win.Trojan.Eupuds variant connection (more info ...)trojan-activity    URL
27966MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
27967MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
27968MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
27969MALWARE-CNC Win.Trojan.Updays variant connection (more info ...)trojan-activity    URL
27970MALWARE-CNC Win.Trojan.Zeus dropper variant connection (more info ...)trojan-activity    URL
28002INDICATOR-SCAN UPnP WANPPPConnection (more info ...)network-scan    URL
28003INDICATOR-SCAN UPnP WANIPConnection (more info ...)network-scan    URL
28005MALWARE-CNC Win.Trojan.Kuluoz outbound command (more info ...)trojan-activity    URL
28007MALWARE-CNC BLYPT installer startupkey outbound traffic (more info ...)trojan-activity    URL
28008MALWARE-CNC BLYPT installer reuse outbound traffic (more info ...)trojan-activity    URL
28009MALWARE-CNC BLYPT installer configkey outbound traffic (more info ...)trojan-activity    URL
28010MALWARE-CNC BLYPT installer tserror outbound traffic (more info ...)trojan-activity    URL
28011MALWARE-CNC BLYPT installer createproc outbound traffic (more info ...)trojan-activity    URL
28012MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
28026EXPLOIT-KIT Blackholev2 exploit kit landing page (more info ...)trojan-activity    
28028EXPLOIT-KIT Blackholev2/Cool exploit kit exploit download attempt (more info ...)trojan-activity    
28033MALWARE-CNC Win.Ransomware.Urausy variant outbound connection (more info ...)trojan-activity    URL
28040MALWARE-CNC Win.Trojan.Dofoil variant outbound connection (more info ...)trojan-activity    
28042MALWARE-CNC Win.Trojan.Caphaw variant outbound connection (more info ...)trojan-activity    URL
28044MALWARE-CNC Win.Trojan.CryptoLocker variant connection (more info ...)trojan-activity    URL
28045MALWARE-CNC Win.Trojan.VBKrypt variant connection (more info ...)trojan-activity    URL
28046OS-MOBILE Android fake iMessage app download (more info ...)trojan-activity    URL
28047SERVER-WEBAPP RaidSonic Multiple Products arbitrary command injection attempt (more info ...)attempted-admin  57958  
28055OS-MOBILE Android ANDR.Trojan.FakeAV outbound communication attempt (more info ...)trojan-activity    URL
28056OS-MOBILE Android ANDR.Trojan.FakeAV APK file download attempt (more info ...)trojan-activity    URL
28057OS-MOBILE Android ANDR.Trojan.FakeAV APK file download attempt (more info ...)trojan-activity    URL
28068APP-DETECT 360.cn Safeguard runtime outbound communication (more info ...)misc-activity    URL
28071APP-DETECT 360.cn SafeGuard local HTTP management console access attempt (more info ...)trojan-activity    URL
28072MALWARE-CNC Win.Trojan.Omexo outbound connection (more info ...)trojan-activity    URL
28073MALWARE-CNC Win.Trojan.Win32.Kimsuky variant file stealing (more info ...)trojan-activity    URL
28074MALWARE-CNC Win.Trojan.ADKR connection (more info ...)trojan-activity    URL
28075MALWARE-CNC Win.Trojan.gzfw connection (more info ...)trojan-activity    URL
28076SERVER-WEBAPP Drupal Core OpenID information disclosure attempt (more info ...)web-application-attack 2012-4554   
28079MALWARE-CNC Win.Trojan.Napolar variant outbound connection (more info ...)trojan-activity    URL
28080MALWARE-CNC Win.Trojan.Napolar data theft (more info ...)trojan-activity    URL
28081OS-MOBILE Android ANDR.Trojan.Malapp APK file download attempt (more info ...)trojan-activity    URL
28082OS-MOBILE Android ANDR.Trojan.Malapp APK file download attempt (more info ...)trojan-activity    URL
28084MALWARE-CNC Win.Trojan.Hupigon variant connection (more info ...)trojan-activity    URL
28086OS-MOBILE Android ANDR.Trojan.SmsSpy APK file download attempt (more info ...)trojan-activity    URL
28087OS-MOBILE Android ANDR.Trojan.SmsSpy APK file download attempt (more info ...)trojan-activity    URL
28088POLICY-SOCIAL Pidgin MXIT emoticon integer overflow attempt (more info ...)attempted-user 2013-6489   
28089POLICY-SOCIAL multiple chat protocols link to local file attempt (more info ...)attempted-user 2013-6486   
28090POLICY-SOCIAL multiple chat protocols link to local file attempt (more info ...)attempted-user 2013-6486   
28094MALWARE-CNC Win.Trojan.Liteol variant connection (more info ...)trojan-activity    URL
28095MALWARE-CNC Win.Trojan.Liteol variant connection (more info ...)trojan-activity    URL
28096MALWARE-CNC Win.Trojan.Spynet variant connection (more info ...)trojan-activity    URL
28097MALWARE-CNC Win.Trojan.Ohlat variant connection (more info ...)trojan-activity    URL
28105MALWARE-CNC Win.Trojan.Banload variant outbound connection (more info ...)trojan-activity    URL
28106MALWARE-CNC Win.Trojan.Banload information upload (more info ...)trojan-activity    URL
28107MALWARE-CNC Win.Trojan.Banload download (more info ...)trojan-activity    URL
28114MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /default.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28115MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /file.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28116MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /home.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28117MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /install.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28118MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /login.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28119MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /search.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28120MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /start.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28121MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /welcome.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28122MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /index.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28123MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /setup.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28124FILE-OTHER PCRE character class heap buffer overflow attempt (more info ...)attempted-user 2007-3944 25002  
28125MALWARE-CNC Win.Trojan.Banbra variant connection (more info ...)trojan-activity    URL
28134MALWARE-CNC Win.Trojan.Dorkbot variant connection (more info ...)trojan-activity    URL
28139SERVER-WEBAPP Python Pickle remote code execution attempt (more info ...)attempted-user 2013-5093 61894  
28140PUA-ADWARE Win.Adware.Schmidti outbound communication attempt (more info ...)misc-activity    URL
28141MALWARE-CNC Win.Trojan.banker outbound connection (more info ...)trojan-activity    URL
28143MALWARE-CNC Win.Trojan.Medfos outbound connection (more info ...)trojan-activity    URL
28144MALWARE-CNC Win.Trojan.Win32.Wpbrutebot variant connection (more info ...)trojan-activity    URL
28145SERVER-WEBAPP OpenEMR information disclosure attempt (more info ...)web-application-attack    
28146MALWARE-CNC Win.Trojan.Salgorea variant connection (more info ...)trojan-activity    URL
28147MALWARE-CNC Win.Trojan.Conficker variant outbound connection (more info ...)trojan-activity    URL
28148MALWARE-CNC Win.Trojan.Mevade variant outbound connection (more info ...)trojan-activity    URL
28149SERVER-OTHER Quest Software Big Brother attempted arbitrary file deletion (more info ...)attempted-user    URL
28150SERVER-OTHER Quest Software Big Brother attempted arbitrary file upload (more info ...)attempted-user    
28153MALWARE-CNC Win.Trojan.Foreign variant outbound connection - /html2/ (more info ...)trojan-activity    URL
28154MALWARE-CNC Win.Trojan.Foreign variant outbound connection - MSIE 7.1 (more info ...)trojan-activity    URL
28155MALWARE-CNC Win.Trojan.Foreign variant outbound connection - MSIE 7.2 (more info ...)trojan-activity    URL
28156PUA-ADWARE Linkury outbound time check (more info ...)trojan-activity    URL
28164MALWARE-CNC Win.Trojan.FakeAV attempted file download (more info ...)trojan-activity    URL
28166MALWARE-CNC Win.Trojan.Bifrose variant connection (more info ...)trojan-activity    URL
28192MALWARE-CNC Win.Trojan.Kuluoz Potential Phishing URL (more info ...)trojan-activity    URL
28209MALWARE-CNC Win.Worm.IRCbot outbound connection (more info ...)trojan-activity    URL
28210MALWARE-CNC Win.Worm.IRCbot outbound connection (more info ...)trojan-activity    URL
28211MALWARE-CNC Win.Worm.IRCbot outbound connection (more info ...)trojan-activity    URL
28212MALWARE-CNC Win.Trojan.Bitsto variant connection (more info ...)trojan-activity    URL
28230MALWARE-CNC Boot.Bootroot Variant data upload (more info ...)trojan-activity    URL
28233EXPLOIT-KIT Blackholev2/Cool exploit kit payload download attempt (more info ...)trojan-activity    
28234MALWARE-CNC Win.Trojan.Hdslogger outbound connection (more info ...)trojan-activity    URL
28238EXPLOIT-KIT Multiple exploit kits malicious pdf download (more info ...)trojan-activity    
28239MALWARE-CNC Win.Trojan.Tuxido outbound connection (more info ...)trojan-activity    URL
28242MALWARE-CNC Win.Trojan.KanKan variant connection (more info ...)trojan-activity    URL
28244MALWARE-CNC Win.Trojan.Phrovon outbound connection (more info ...)trojan-activity    URL
28245APP-DETECT Bizhi Sogou Wallpaper application outbound connection attempt (more info ...)misc-activity    URL
28246APP-DETECT Bizhi Sogou Wallpaper application download schema response (more info ...)misc-activity    URL
28247MALWARE-CNC Win.Trojan.Dropper variant outbound connection (more info ...)trojan-activity    URL
28250MALWARE-CNC Security Cleaner Pro Install Confirmation (more info ...)trojan-activity    URL
28254MALWARE-CNC Win.Trojan.Perl.Shellbot variant outbound connection (more info ...)trojan-activity    URL
28255MALWARE-CNC Win.Trojan.Kuluoz Potential phishing URL (more info ...)trojan-activity    URL
28285MALWARE-CNC Win.Trojan.hdog connectivity check-in version 2 (more info ...)trojan-activity    URL
28291EXPLOIT-KIT Blackholev2/Cool exploit kit exploit download attempt (more info ...)trojan-activity    
28300MALWARE-CNC Win.Trojan.Agent variant connection (more info ...)trojan-activity    URL
28301INDICATOR-SCAN User-Agent known malicious user-agent Masscan (more info ...)misc-activity    URL
28305MALWARE-CNC Win.Trojan.Mecifg variant outbound connection (more info ...)trojan-activity    URL
28323MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
28325MALWARE-CNC Win.Backdoor.Zuza variant outbound connection (more info ...)trojan-activity    URL
28326MALWARE-CNC Win.Backdoor.Zuza variant outbound connection (more info ...)trojan-activity    URL
28328MALWARE-CNC Win.Backdoor.Hupigon variant outbound connection (more info ...)trojan-activity    URL
28347MALWARE-OTHER SimpleTDS - page redirecting to a SimpleTDS (more info ...)misc-activity    URL
28362MALWARE-CNC User-Agent known malicious user-agent string SUiCiDE/1.5 (more info ...)trojan-activity    
28366MALWARE-CNC Win.Backdoor.Venik variant outbound connection (more info ...)trojan-activity    URL
28373MALWARE-CNC Win.Trojan.Mutopy variant outbound connection (more info ...)trojan-activity    URL
28382FILE-IDENTIFY HTML Help Index file download request (more info ...)misc-activity    
28383FILE-IDENTIFY HTML Help Index download file attachment detected (more info ...)misc-activity    
28384FILE-IDENTIFY HTML Help Index download file attachment detected (more info ...)misc-activity    
28392FILE-MULTIMEDIA MultiMedia Soft Components AdjMmsEng.dll PLS file processing buffer overflow attempt (more info ...)attempted-user 2009-5109 33589  
28394SERVER-OTHER EMC AlphaStore format string vulnerability exploit attempt (more info ...)attempted-admin 2013-0929   
28395SERVER-OTHER EMC AlphaStore format string vulnerability exploit attempt (more info ...)attempted-admin 2013-0929   
28396SERVER-OTHER EMC AlphaStore format string vulnerability exploit attempt (more info ...)attempted-admin 2013-0929   
28397SERVER-OTHER EMC AlphaStore format string vulnerability exploit attempt (more info ...)attempted-admin 2013-0929   
28398SERVER-OTHER EMC AlphaStore format string vulnerability exploit attempt (more info ...)attempted-admin 2013-0929   
28405MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
28406MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
28410MALWARE-CNC Win.Trojan.CoinMiner variant outbound connection (more info ...)trojan-activity    URL
28411MALWARE-CNC Win.Trojan.CoinMiner variant outbound connection (more info ...)trojan-activity    URL
28415MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
28416MALWARE-CNC Win.Trojan.CryptoLocker outbound connection (more info ...)trojan-activity    URL
28417MALWARE-CNC Win.Trojan.Molgomsg variant outbound connection (more info ...)trojan-activity    URL
28418MALWARE-CNC Win.Trojan.Downloader.Dtcontx outbound connection (more info ...)trojan-activity    URL
28419MALWARE-CNC Win.Trojan.Tesch variant outbound connection (more info ...)trojan-activity    URL
28439MALWARE-CNC Win.Trojan.Bspire variant connection (more info ...)trojan-activity 2013-0422 57246  URL
28444MALWARE-CNC Win.Backdoor.CBgate variant outbound connection (more info ...)trojan-activity    URL
28448SERVER-WEBAPP HP Intelligent Management Center BIMS bimsDownload directory traversal attempt (more info ...)attempted-recon 2013-4823 62897  URL
28482MALWARE-CNC Win.Trojan.Terminator RAT variant outbound connection (more info ...)trojan-activity 2012-0158   
28484MALWARE-CNC Win.Trojan.Delpbank variant outbound connection (more info ...)trojan-activity    URL
28485MALWARE-CNC Win.Trojan.Khalog variant outbound connection (more info ...)trojan-activity    URL
28486MALWARE-CNC Win.Trojan.Codiltak variant outbound connection (more info ...)trojan-activity    URL
28493MALWARE-CNC DeputyDog diskless method outbound connection (more info ...)trojan-activity 2013-3918   URL
28528MALWARE-CNC Win.Trojan.Qadars variant outbound connection (more info ...)misc-activity    URL
28529MALWARE-CNC Win.Trojan.Qadars variant outbound connection (more info ...)misc-activity    URL
28530PUA-TOOLBARS Babylon toolbar outbound connection (more info ...)misc-activity    URL
28531PUA-ADWARE FreePDS installer outbound connection (more info ...)trojan-activity    URL
28532MALWARE-TOOLS PyLoris http DoS tool (more info ...)attempted-dos 2012-5568   
28538MALWARE-CNC Win.Trojan.Asprox/Kuluoz variant connection (more info ...)trojan-activity    URL
28541MALWARE-CNC Win.Trojan.ZeroAccess Download Headers (more info ...)trojan-activity    URL
28542MALWARE-CNC Win.Trojan.Conficker variant outbound connection (more info ...)trojan-activity    URL
28543MALWARE-CNC Win.Trojan.Conficker variant outbound connection (more info ...)trojan-activity    URL
28547MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
28548MALWARE-CNC Win.Trojan.chfx variant outbound connection (more info ...)trojan-activity    URL
28552INDICATOR-SCAN inbound probing for IPTUX messenger port (more info ...)misc-activity    URL
28553MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /main.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28554MALWARE-CNC Win.Trojan.Fareit variant outbound connection - /online.htm GET Encrypted Payload (more info ...)trojan-activity    URL
28558MALWARE-CNC User-Agent known malicious user-agent string getURLdown (more info ...)trojan-activity    URL
28559MALWARE-CNC Win.Trojan.Castov variant connection (more info ...)trojan-activity    URL
28561MALWARE-CNC Win.Trojan.Plugx outbound connection (more info ...)trojan-activity    URL
28562MALWARE-CNC Win.Trojan.Sidopa variant outbound connection (more info ...)trojan-activity    URL
28565MALWARE-CNC Win.Trojan.Sluegot variant connection (more info ...)trojan-activity    URL
28599MALWARE-CNC Win.Backdoor.Lesirt variant outbound connection (more info ...)trojan-activity    URL
28604MALWARE-CNC Win.Trojan.Kasnam variant connection (more info ...)trojan-activity    URL
28605MALWARE-CNC Win.Trojan.Kasnam variant connection (more info ...)trojan-activity    URL
28606MALWARE-CNC Win.Trojan.Surtr variant connection (more info ...)trojan-activity    URL
28607MALWARE-CNC Win.Trojan.Fareit variant outbound connection (more info ...)trojan-activity    URL
28613EXPLOIT-KIT Angler exploit kit landing page - specific-structure (more info ...)trojan-activity 2013-3896   URL
28614EXPLOIT-KIT Angler exploit kit landing page (more info ...)trojan-activity 2013-3896   URL
28616EXPLOIT-KIT Angler exploit kit payload download attempt (more info ...)trojan-activity 2013-3896   URL
28630INDICATOR-OBFUSCATION obfuscated script encoding detected (more info ...)misc-activity    URL
28724MALWARE-CNC Win.Trojan.Agent outbound connection (more info ...)trojan-activity    URL
28746SERVER-WEBAPP SAP NetWeaver SXPG_CALL_SYSTEM remote code execution attempt (more info ...)attempted-user    URL
28799MALWARE-CNC Win.Trojan.Mxtcycle variant outbound connection (more info ...)trojan-activity    URL
28800MALWARE-CNC Win.Trojan.Zeus outbound connection (more info ...)trojan-activity    URL
28802MALWARE-CNC Win.Trojan.Bancos outbound connection (more info ...)trojan-activity    URL
28803MALWARE-CNC Win.Trojan.Injector inbound connection (more info ...)trojan-activity    URL
28804MALWARE-CNC Win.Trojan.Injector outbound connection (more info ...)trojan-activity    URL
28805MALWARE-CNC Win.Trojan.Palevo outbound connection (more info ...)trojan-activity    URL
28807MALWARE-CNC Win.Trojan.Injector variant outbound connection (more info ...)trojan-activity    URL
28808MALWARE-CNC Win.Backdoor.Ptiger variant outbound connection (more info ...)trojan-activity    URL
28809MALWARE-CNC Win.Trojan.Dofoil inbound connection (more info ...)trojan-activity    URL
28810MALWARE-CNC Win.Trojan.Zeus variant outbound connection - MSIE7 No Referer No Cookie (more info ...)trojan-activity    URL
28813MALWARE-CNC Win.Trojan.Ufraie variant outbound connection (more info ...)trojan-activity    URL
28814MALWARE-CNC Win.Trojan.Gozi/Neverquest variant outbound connection (more info ...)trojan-activity    URL
28815MALWARE-CNC Win.Trojan.Gozi/Neverquest variant outbound connection (more info ...)trojan-activity    URL
28816MALWARE-CNC Win.Trojan.Siluhdur variant outbound connection (more info ...)trojan-activity    URL
28817MALWARE-CNC Win.Backdoor.Iniduoh variant outbound connection (more info ...)trojan-activity    URL
28818FILE-OTHER 7-Zip ARJ archive handling buffer overflow attempt (more info ...)attempted-user 2005-3051 21208  
28819FILE-OTHER 7-Zip ARJ archive handling buffer overflow attempt (more info ...)attempted-user 2005-3051 21208  
28820MALWARE-CNC Win.Trojan.Egamipload variant outbound connection (more info ...)trojan-activity    URL
28821SERVER-OTHER McAfee ePolicy Orchestrator XSS attempt (more info ...)attempted-admin 2013-0141 59505  URL
28822SERVER-OTHER McAfee ePolicy Orchestrator XSS attempt (more info ...)attempted-admin 2013-0141 59505  URL
28823SERVER-OTHER McAfee ePolicy Orchestrator XSS attempt (more info ...)attempted-admin 2013-0141 59505  URL
28824SERVER-OTHER McAfee ePolicy Orchestrator XSS attempt (more info ...)attempted-admin 2013-0141 59505  URL
28825SERVER-OTHER McAfee ePolicy Orchestrator XSS attempt (more info ...)attempted-admin 2013-0141 59505  URL
28826SERVER-OTHER McAfee ePolicy Orchestrator XSS attempt (more info ...)attempted-admin 2013-0141 59505  URL
28827SERVER-OTHER McAfee ePolicy Orchestrator XSS attempt (more info ...)attempted-admin 2013-0141 59505  URL
28837FILE-OTHER Corel PaintShop Pro d2d1.dll dll-load exploit attempt (more info ...)attempted-user 2013-0733 62836  URL
28842FILE-OTHER Corel PaintShop Pro wintab32.dll dll-load exploit attempt (more info ...)attempted-user 2013-0733 62836  URL
28853MALWARE-CNC Win.Trojan.Dipverdle variant outbound connection (more info ...)trojan-activity    URL
28856MALWARE-CNC Win.Trojan.Yowdab variant connection (more info ...)trojan-activity    URL
28857MALWARE-CNC Adwind UNRECOM connnection back to cnc server (more info ...)trojan-activity    URL
28858MALWARE-CNC Adwind UNRECOM connnection back to cnc server (more info ...)trojan-activity    URL
28859MALWARE-CNC User-Agent known malicious user-agent z00sAgent - Win.Trojan.Zbot (more info ...)trojan-activity    URL
28860MALWARE-CNC User-Agent known malicious user-agent - Win.Trojan.Nitedrem (more info ...)trojan-activity    URL
28861MALWARE-CNC Win.Trojan.Roxfora variant outbound connection (more info ...)trojan-activity    URL
28864MALWARE-CNC Win.Trojan.Tofsee variant outbound connection (more info ...)trojan-activity    URL
28879MALWARE-CNC Win.Backdoor.Tavdig variant outbound connection (more info ...)trojan-activity    URL
28886MALWARE-CNC Win.Trojan.Scar variant outbound connection (more info ...)trojan-activity    URL
28913MALWARE-BACKDOOR Zollard variant outbound connection attempt (more info ...)trojan-activity    URL
28914MALWARE-CNC Win.Trojan.Anony variant connection (more info ...)trojan-activity    URL
28917PROTOCOL-SCADA Microsys Promotic directory traversal attempt (more info ...)attempted-user 2011-4518 50133  URL
28918MALWARE-CNC Win.Trojan.Symmi variant network connectivity check (more info ...)trojan-activity    URL
28919MALWARE-CNC Win.Trojan.Symmi variant network connectivity check (more info ...)trojan-activity    URL
28930MALWARE-CNC Win.Trojan.Fakeav variant outbound data connection (more info ...)trojan-activity    
28934PUA-ADWARE InstallBrain software download attempt (more info ...)misc-activity    URL
28935PUA-ADWARE InstallBrain software download attempt (more info ...)misc-activity    URL
28936SERVER-WEBAPP Horde groupware webmail edition ingo filter cross-site request forgery attempt (more info ...)attempted-user 2013-6275   
28940MALWARE-CNC Win.Trojan.Rovnix malicious download (more info ...)trojan-activity    URL
28942SERVER-WEBAPP BoonEx Dolphin 6.1.2 remote file include attempt (more info ...)attempted-user 2008-3167 30136  
28943SERVER-WEBAPP BoonEx Dolphin 6.1.2 remote file include attempt (more info ...)attempted-user 2008-3167 30136  
28944SERVER-WEBAPP BoonEx Dolphin 6.1.2 remote file include attempt (more info ...)attempted-user 2008-3167 30136  
28945INDICATOR-COMPROMISE exe.exe download (more info ...)trojan-activity    URL
28947MALWARE-CNC Win.Trojan.Tapaoux variant connection (more info ...)trojan-activity    URL
28948MALWARE-CNC Win.Trojan.Kishlog variant outbound connection (more info ...)trojan-activity    URL
28949MALWARE-CNC Win.Trojan.Kishlog variant outbound connection (more info ...)trojan-activity    URL
28955SERVER-OTHER Squid HTTP Host header port parameter denial of service attempt (more info ...)attempted-user 2013-4123   
28958MALWARE-CNC Win.Trojan.Jussuc variant outbound connection (more info ...)trojan-activity    URL
28960MALWARE-CNC Win.Trojan.Alurewo outbound connection (more info ...)trojan-activity    URL
28967EXPLOIT-KIT HiMan exploit kit outbound exploit retrieval connection (more info ...)trojan-activity    
28970SERVER-WEBAPP Fortinet FortiAnalyzer cross-site request forgery attempt. (more info ...)attempted-admin    
28971SERVER-WEBAPP Fortinet FortiAnalyzer cross-site request forgery attempt. (more info ...)attempted-admin    
28976MALWARE-CNC Win.Trojan.Agent.DF - Data Exfiltration (more info ...)trojan-activity    URL
28977MALWARE-CNC Win.Trojan.Agent.DF - User-Agent Missing Bracket (more info ...)trojan-activity    URL
28978FILE-OTHER CHM LZX compression reset interval anti-virus evasion attempt (more info ...)trojan-activity 2012-1458   URL
28979FILE-OTHER CHM LZX compression reset interval anti-virus evasion attempt (more info ...)trojan-activity 2012-1458   URL
28982MALWARE-CNC Win.Worm.Steckt IRCbot requesting URL through IRC (more info ...)trojan-activity    URL
28983MALWARE-CNC Win.Trojan.Steckt IRCbot executable download (more info ...)trojan-activity    URL
28984MALWARE-CNC Win.Worm.Steckt IRCbot executable download (more info ...)trojan-activity    URL
28985MALWARE-CNC Win.Worm.Steckt IRCbot executable download (more info ...)trojan-activity    URL
28986MALWARE-CNC Win.Worm.Neeris IRCbot variant outbound connection (more info ...)trojan-activity    URL
28987MALWARE-CNC Win.Worm.Steckt IRCbot variant outbound connection (more info ...)trojan-activity    URL
28988MALWARE-CNC Win.Worm.Steckt IRCbot variant outbound connection (more info ...)trojan-activity    URL
28989MALWARE-CNC Win.Trojan.Egobot variant outbound connection (more info ...)trojan-activity 2011-0609   URL
28990MALWARE-CNC Win.Trojan.Qakbot connection to cnc server (more info ...)trojan-activity    URL
28994MALWARE-CNC Win.Trojan.Backdoor Remote Shell Server download (more info ...)trojan-activity    URL
28995MALWARE-CNC Win.Trojan.Backdoor Remote Shell Server download (more info ...)trojan-activity    URL
28996MALWARE-CNC Win.Trojan.Bunitu variant outbound connection (more info ...)trojan-activity    URL
29005SERVER-WEBAPP IBM Platform Symphony SOAP request processing buffer overflow attempt (more info ...)attempted-user 2013-5387   
29006FILE-IDENTIFY XWD image file attachment detected (more info ...)misc-activity    
29007FILE-IDENTIFY XWD image file attachment detected (more info ...)misc-activity    
29008FILE-IDENTIFY XWD image file download request (more info ...)misc-activity    
29009FILE-OTHER GIMP XWD file heap buffer overflow attempt (more info ...)attempted-user 2013-1978   
29010FILE-OTHER GIMP XWD file heap buffer overflow attempt (more info ...)attempted-user 2013-1978   
29011MALWARE-CNC Win.Trojan.Dotconta variant outbound connection (more info ...)trojan-activity    URL
29016MALWARE-CNC Win.Trojan.Cordmix variant outbound connection (more info ...)trojan-activity    URL
29026MALWARE-CNC Win.Trojan.Limlspy variant outbound connection (more info ...)trojan-activity    URL
29031MALWARE-CNC Win.Trojan.Banload variant inbound connection (more info ...)trojan-activity    URL
29038MALWARE-CNC Win.Trojan.Shiz variant initial outbound connection (more info ...)trojan-activity    URL
29039MALWARE-CNC Win.Trojan.Shiz variant outbound connection (more info ...)trojan-activity    URL
29040SERVER-WEBAPP Zimbra remote code execution attempt (more info ...)attempted-admin 2013-7091 64149  
29044MALWARE-CNC Win.Trojan.Lorask variant outbound connection (more info ...)trojan-activity    URL
29045MALWARE-CNC Win.Trojan.Lorask variant outbound connection (more info ...)trojan-activity    URL
29056MALWARE-CNC Win.Trojan.Descrantol variant outbound connection (more info ...)trojan-activity    URL
29057MALWARE-CNC Installation Win.Trojan.Umberial variant outbound connection (more info ...)trojan-activity    URL
29058MALWARE-CNC Win.Trojan.Umberial variant outbound connection (more info ...)trojan-activity    URL
29066EXPLOIT-KIT Angler exploit kit XORed payload download attempt (more info ...)trojan-activity 2013-3896   URL
29068MALWARE-CNC Win.Trojan.Tapazom variant outbound connection (more info ...)trojan-activity    URL
29071MALWARE-CNC Win.Trojan.Wcvalep variant outbound connection (more info ...)trojan-activity    URL
29073MALWARE-CNC Win.Trojan.Maetdik variant initial outbound connection (more info ...)trojan-activity    URL
29074MALWARE-CNC Win.Trojan.Maetdik variant outbound connection (more info ...)trojan-activity    URL
29075MALWARE-CNC Win.Trojan.Firefly outbound communcation (more info ...)trojan-activity    URL
29076MALWARE-CNC Win.Trojan.Epixed variant outbound connection (more info ...)trojan-activity    URL
29077MALWARE-CNC Win.Trojan.Platidium variant outbound connection (more info ...)trojan-activity    URL
29079MALWARE-CNC Win.Trojan.Inftob variant outbound connection (more info ...)trojan-activity    URL
29081MALWARE-CNC Win.Trojan.Budir initial variant outbound connection (more info ...)trojan-activity    URL
29082MALWARE-CNC Win.Trojan.Ldmon variant outbound connection (more info ...)trojan-activity    URL
29087MALWARE-CNC Win.Trojan.Kboy variant outbound connection (more info ...)trojan-activity    URL
29091MALWARE-CNC Win.Trojan.Choxy variant outbound connection (more info ...)trojan-activity    URL
29103MALWARE-CNC Win.Trojan.Korhigh variant outbound connection (more info ...)trojan-activity    URL
29104MALWARE-CNC Win.Trojan.Iniptad variant outbound connection (more info ...)trojan-activity    URL
29108MALWARE-CNC Win.Trojan.SixMuch variant outbound connection (more info ...)trojan-activity    URL
29109MALWARE-CNC Win.Trojan.Drafukey variant outbound connection (more info ...)trojan-activity    URL
29110SERVER-WEBAPP Symantec Messaging Gateway save.do cross site request forgery attempt (more info ...)attempted-user 2012-0308   
29112MALWARE-CNC Win.Trojan.Drafukey variant outbound connection (more info ...)trojan-activity    URL
29113MALWARE-CNC Win.Trojan.Conrec variant outbound connection (more info ...)trojan-activity    URL
29114MALWARE-CNC Win.Trojan.Sotark variant outbound connection (more info ...)trojan-activity    URL
29115MALWARE-CNC Win.Trojan.Alset variant outbound connection (more info ...)trojan-activity    URL
29117MALWARE-CNC Win.Trojan.Tyaui variant outbound connection (more info ...)trojan-activity    URL
29124MALWARE-OTHER Win.Trojan.InstallMonster variant outbound connection (more info ...)trojan-activity    URL
29125MALWARE-CNC Win.Trojan.Valden variant outbound connection (more info ...)trojan-activity    URL
29127MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    
29133MALWARE-CNC Win.Trojan.Goobraz variant outbound connection (more info ...)trojan-activity    URL
29135MALWARE-CNC Win.Trojan.Bfddos variant outbound connection (more info ...)trojan-activity    URL
29136MALWARE-CNC Win.Trojan.Neos variant outbound connection (more info ...)trojan-activity    URL
29138MALWARE-CNC Win.Trojan.Mojap variant outbound connection (more info ...)trojan-activity    URL
29139MALWARE-CNC User-Agent known malicious User-Agent string HTTP 1.1 - Win.Trojan.Tapslix (more info ...)trojan-activity    URL
29140MALWARE-CNC Win.Trojan.Tearspear variant outbound connection (more info ...)trojan-activity    URL
29143MALWARE-CNC User-Agent known malicious User-Agent - Win.Trojan.Secciv (more info ...)trojan-activity    URL
29146MALWARE-CNC Win.Trojan.RansomCrypt variant outbound connection (more info ...)trojan-activity    URL
29148MALWARE-CNC Win.Trojan.Huxerox variant outbound connection (more info ...)trojan-activity    URL
29149MALWARE-CNC Win.Trojan.Janicab outbound connection (more info ...)trojan-activity    URL
29150MALWARE-CNC User-Agent suspicious user-agent WarpHTTP - Win.Trojan.Yohakest (more info ...)trojan-activity    URL
29152MALWARE-CNC Win.Trojan.Yohakest variant initial runtime outbound connection (more info ...)trojan-activity    URL
29153MALWARE-CNC Win.Trojan.Yohakest variant file upload outbound connection (more info ...)trojan-activity    URL
29154MALWARE-CNC Win.Trojan.Yohakest variant followup outbound connection (more info ...)trojan-activity    URL
29155MALWARE-CNC Win.Trojan.Vwealer outbound connection (more info ...)trojan-activity    URL
29163EXPLOIT-KIT CritX exploit kit outbound exploit request (more info ...)trojan-activity    
29174MALWARE-CNC User-Agent known malicious user-agent string fortis (more info ...)trojan-activity    URL
29175MALWARE-CNC Win.Trojan.Sitrof variant outbound connection (more info ...)trojan-activity    URL
29176MALWARE-CNC Win.Trojan.Retsaw variant outbound connection (more info ...)trojan-activity    URL
29179MALWARE-CNC Win.Trojan.Tenad variant outbound connection (more info ...)trojan-activity    URL
29180MALWARE-CNC User-Agent known malicious User-Agent Update1.0 - Win.Trojan.Downbini (more info ...)trojan-activity    URL
29187EXPLOIT-KIT Nuclear exploit kit outbound pdf request (more info ...)trojan-activity    
29188EXPLOIT-KIT Magnitude exploit kit embedded open type font file request (more info ...)trojan-activity    
29192SERVER-WEBAPP Zimbra remote code execution attempt (more info ...)attempted-admin 2013-7091 64149  
29193SERVER-WEBAPP Zimbra remote code execution attempt (more info ...)attempted-admin 2013-7091 64149  
29216MALWARE-CNC Win.Trojan.Androm variant outbound connection (more info ...)trojan-activity    URL
29220MALWARE-CNC Win.Trojan.Strictor variant outbound connection (more info ...)trojan-activity    URL
29259MALWARE-CNC Win.Trojan.Graftor variant outbound connection (more info ...)trojan-activity    URL
29260MALWARE-CNC Win.Trojan.Graftor variant outbound connection (more info ...)trojan-activity    URL
29261MALWARE-CNC Win.Trojan.Dropper variant outbound connection (more info ...)trojan-activity    URL
29274FILE-IDENTIFY XFDL file attachment detected (more info ...)misc-activity    URL
29275FILE-IDENTIFY XFDL file attachment detected (more info ...)misc-activity    URL
29276FILE-IDENTIFY XFDL file download request (more info ...)misc-activity    URL
29277FILE-OTHER IBM Forms Viewer XFDL form processing stack buffer overflow attempt (more info ...)attempted-user 2013-5447   URL
29278FILE-OTHER IBM Forms Viewer XFDL form processing stack buffer overflow attempt (more info ...)attempted-user 2013-5447   URL
29279FILE-OTHER IBM Forms Viewer XFDL form processing stack buffer overflow attempt (more info ...)attempted-user 2013-5447   URL
29280FILE-OTHER IBM Forms Viewer XFDL form processing stack buffer overflow attempt (more info ...)attempted-user 2013-5447   URL
29289MALWARE-CNC Win.Trojan.Kmnokay outbound connection (more info ...)trojan-activity    URL
29291MALWARE-CNC Win.Trojan.Stitur variant outbound connection (more info ...)trojan-activity    URL
29292MALWARE-CNC Win.Trojan.Chulastran variant outbound connection (more info ...)trojan-activity    URL
29293MALWARE-CNC Win.Trojan.Chulastran variant initial version check outbound connection (more info ...)trojan-activity    URL
29294MALWARE-CNC Win.Trojan.Boda variant outbound connection (more info ...)trojan-activity    URL
29295MALWARE-CNC Win.Trojan.Boda variant initial outbound connection (more info ...)trojan-activity    URL
29299MALWARE-CNC Win.Trojan.Nineblog variant outbound connection (more info ...)trojan-activity    URL
29300MALWARE-CNC Win.Trojan.Graftor variant inbound connection (more info ...)trojan-activity    URL
29301MALWARE-CNC Win.Trojan.Mizzmo variant outbound connection (more info ...)trojan-activity    URL
29302MALWARE-CNC Win.Trojan.Diswenshow outbound connection (more info ...)trojan-activity    URL
29304MALWARE-CNC Win.Trojan.Verbscut variant outbound connection (more info ...)trojan-activity    URL
29306MALWARE-CNC Win.Trojan.Popyerd variant outbound connection (more info ...)trojan-activity    URL
29307MALWARE-CNC Win.Trojan.Fraxytime outbound connection (more info ...)trojan-activity    URL
29308MALWARE-CNC TRUFFLEHUNTER SFVRT-1013 attack attempt (more info ...)trojan-activity    
29309MALWARE-CNC TRUFFLEHUNTER SFVRT-1013 attack attempt (more info ...)trojan-activity    
29310MALWARE-CNC TRUFFLEHUNTER SFVRT-1013 attack attempt (more info ...)trojan-activity    
29311MALWARE-CNC TRUFFLEHUNTER SFVRT-1013 attack attempt (more info ...)trojan-activity    
29312MALWARE-CNC TRUFFLEHUNTER SFVRT-1013 attack attempt (more info ...)trojan-activity    
29313MALWARE-CNC Win.Trojan.Proxydown variant connection (more info ...)trojan-activity    URL
29314PROTOCOL-SCADA Modbus function scan (more info ...)protocol-command-decode    URL
29315PROTOCOL-SCADA Modbus list scan (more info ...)protocol-command-decode    URL
29316PROTOCOL-SCADA Modbus value scan (more info ...)protocol-command-decode    URL
29317PROTOCOL-SCADA Modbus invalid exception message (more info ...)protocol-command-decode    URL
29318PROTOCOL-SCADA Modbus invalid encapsulated interface response (more info ...)protocol-command-decode    URL
29319PROTOCOL-SCADA Modbus invalid encapsulated interface request (more info ...)protocol-command-decode    URL
29320APP-DETECT Baidu IME download attempt (more info ...)policy-violation    URL
29321APP-DETECT Baidu IME download attempt (more info ...)policy-violation    URL
29322APP-DETECT Baidu IME runtime detection - remote sync (more info ...)attempted-recon    URL
29324MALWARE-CNC Win.Trojan.Vivia variant outbound connection (more info ...)trojan-activity    URL
29325MALWARE-CNC Win.Trojan.Horsamaz outbound connection (more info ...)trojan-activity    URL
29330MALWARE-CNC Win.Trojan.Piedacon variant outbound connection (more info ...)trojan-activity    URL
29331MALWARE-CNC Win.Trojan.Aokaspid outbound connection using modem (more info ...)trojan-activity    URL
29332MALWARE-CNC Win.Trojan.Aokaspid outbound connection using lan (more info ...)trojan-activity    URL
29333MALWARE-CNC Win.Trojan.Aokaspid outbound connection using proxy server (more info ...)trojan-activity    URL
29334MALWARE-CNC Win.Trojan.Aokaspid outbound connection using other (more info ...)trojan-activity    URL
29335MALWARE-CNC OSX.Trojan.CallMe variant outbound connection (more info ...)trojan-activity    URL
29337MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
29339MALWARE-CNC Win.Trojan.Kishop variant initial runtime outbound connection (more info ...)trojan-activity    URL
29340MALWARE-CNC Win.Trojan.Plusau outbound connection (more info ...)trojan-activity    URL
29341MALWARE-CNC User-Agent known malicious User-Agent string CustomSpy - Win.Trojan.Etek (more info ...)trojan-activity    URL
29344MALWARE-CNC Win.Trojan.Dondat variant outbound connection (more info ...)trojan-activity    URL
29345MALWARE-CNC Win.Trojan.Dondat variant outbound connection (more info ...)trojan-activity    URL
29348MALWARE-CNC Win.Trojan.Chifan variant outbound connection (more info ...)trojan-activity    URL
29349MALWARE-CNC Win.Trojan.Zusy variant outbound connection (more info ...)trojan-activity    URL
29351MALWARE-CNC Win.Trojan.Bulilit variant outbound connection (more info ...)trojan-activity    URL
29352MALWARE-CNC Win.Trojan.Typdec variant outbound connection (more info ...)trojan-activity    URL
29353MALWARE-CNC Win.Trojan.Zeagle outbound connection (more info ...)trojan-activity    URL
29354APP-DETECT Foca file scanning attempt (more info ...)attempted-recon    URL
29356MALWARE-CNC Win.Trojan.Cidox variant outbound connection (more info ...)trojan-activity    URL
29357PUA-P2P Vuze BitTorrent client outbound connection (more info ...)policy-violation    URL
29358MALWARE-CNC User-Agent known malicious user-agent - Win.Trojan.Mowfote (more info ...)trojan-activity    URL
29359MALWARE-CNC Win.Trojan.Mowfote variant initial outbound connection (more info ...)trojan-activity    URL
29363MALWARE-CNC Win.Trojan.Pacbootini variant outbound connection (more info ...)trojan-activity    URL
29367MALWARE-CNC Win.Trojan.Boato variant outbound connection (more info ...)trojan-activity    URL
29368MALWARE-CNC Win.Trojan.Boato variant followup outbound connection (more info ...)trojan-activity    URL
29370MALWARE-CNC Win.Trojan.Agent.ADJI variant outbound connection (more info ...)trojan-activity    URL
29371MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Dluca (more info ...)trojan-activity    URL
29376MALWARE-CNC Win.Trojan.CryptoLocker.B connection test (more info ...)trojan-activity    URL
29378MALWARE-CNC Win.Trojan.Dropper inbound encrypted traffic (more info ...)trojan-activity    URL
29379MALWARE-CNC Win.Trojan.Dropper outbound encrypted traffic - potential exfiltration (more info ...)trojan-activity    URL
29380MALWARE-CNC Win.Trojan.Dropper outbound encrypted traffic (more info ...)trojan-activity    URL
29389MALWARE-CNC Win.Trojan.Alusins variant outbound connection (more info ...)trojan-activity    URL
29393SERVER-OTHER ntp monlist denial of service attempt (more info ...)attempted-dos 2013-5211   URL
29395MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
29396POLICY-SPAM Potential phishing attack - .zip receipt filename download with .exe name within .zip the same (more info ...)trojan-activity    URL
29397POLICY-SPAM Potential phishing attack - .zip shipping filename download with .exe name within .zip the same (more info ...)trojan-activity    URL
29398POLICY-SPAM Potential phishing attack - .zip voicemail filename download with .exe name within .zip the same (more info ...)trojan-activity    URL
29399POLICY-SPAM Potential phishing attack - .zip statement filename download with .exe name within .zip the same (more info ...)trojan-activity    URL
29400SERVER-WEBAPP vTiger CRM AddEmailAttachment directory traversal attempt (more info ...)attempted-admin 2013-3214 61558  URL
29411EXPLOIT-KIT Angler exploit kit landing page (more info ...)trojan-activity    
29413EXPLOIT-KIT Angler exploit kit encrypted binary download (more info ...)trojan-activity    
29414EXPLOIT-KIT Angler exploit kit encrypted binary download (more info ...)trojan-activity    
29416MALWARE-CNC Win.Trojan.vSkimmer outbound connection (more info ...)trojan-activity    URL
29417MALWARE-CNC Win.Trojan.Solimba download attempt (more info ...)trojan-activity    URL
29418OS-MOBILE Android signature validation bypass APK file download attempt (more info ...)trojan-activity 2013-6792 64529  URL
29419OS-MOBILE Android signature validation bypass APK file download attempt (more info ...)trojan-activity 2013-6792 64529  URL
29422MALWARE-CNC Win.Trojan.Rhubot variant outbound connection (more info ...)trojan-activity    URL
29423MALWARE-CNC Win.Trojan.MaxerDDos variant connection (more info ...)trojan-activity    URL
29424MALWARE-CNC Win.Trojan.Dldr variant outbound connection (more info ...)trojan-activity    URL
29426MALWARE-CNC Win.Trojan.Etomertg variant outbound connection (more info ...)trojan-activity    URL
29428MALWARE-CNC Win.Trojan.Zatincel variant outbound connection (more info ...)trojan-activity    URL
29430MALWARE-CNC Win.Trojan.Icefog variant outbound connection (more info ...)trojan-activity    URL
29431MALWARE-CNC User-Agent known malicious user-agent - Win.Trojan.Tirips (more info ...)trojan-activity    URL
29437OS-MOBILE Android Goodix gt915 touchscreen driver improper bounds-check privileged access attempt (more info ...)attempted-user 2013-6122 63661  URL
29438OS-MOBILE Android Goodix gt915 touchscreen driver improper bounds-check privileged access attempt (more info ...)attempted-user 2013-6122 63661  URL
29440MALWARE-CNC Win.Trojan.Chewbacca outbound connection (more info ...)trojan-activity    URL
29443EXPLOIT-KIT Fiesta exploit kit outbound connection attempt (more info ...)trojan-activity    
29459MALWARE-CNC Win.Trojan.Fexel variant outbound connection (more info ...)trojan-activity    URL
29460MALWARE-CNC Win.Trojan.Pabueri variant outbound connection (more info ...)trojan-activity    URL
29461MALWARE-CNC Win.Trojan.Norekab variant outbound connection (more info ...)trojan-activity    URL
29464MALWARE-CNC Win.Trojan.SniperSpy variant outbound connection (more info ...)trojan-activity    URL
29483MALWARE-CNC Win.Trojan.Botime variant connection (more info ...)trojan-activity    URL
29484MALWARE-CNC Win.Trojan.POSCardStealer variant outbound connection (more info ...)trojan-activity    URL
29489MALWARE-CNC Win.Trojan.Gaertob variant outbound connection (more info ...)trojan-activity    URL
29495MALWARE-CNC Win.Trojan.Kopdel variant outbound connection (more info ...)trojan-activity    URL
29496MALWARE-CNC Win.Trojan.Bicololo variant outbound connection (more info ...)trojan-activity    URL
29497MALWARE-CNC Win.Trojan.Graftor variant outbound connection (more info ...)trojan-activity    URL
29498SERVER-WEBAPP HP Intelligent Management Center sdFileDownload information disclosure attempt (more info ...)attempted-recon 2013-4826 62898  URL
29499SERVER-WEBAPP HP Intelligent Management Center sdFileDownload information disclosure attempt (more info ...)attempted-recon 2013-4826 62898  URL
29500PUA-ADWARE 4Shared Downloader outbound connection attempt (more info ...)misc-activity    URL
29501PUA-ADWARE 4Shared Downloader executable file download attempt (more info ...)misc-activity    URL
29509INDICATOR-OBFUSCATION Multiple character encodings detected (more info ...)attempted-user    URL
29547SERVER-WEBAPP IBM Rational Focal Point webservice Axis Gateway GET vulnerability attempt (more info ...)attempted-user 2013-5398   URL
29548SERVER-WEBAPP IBM Rational Focal Point webservice Axis Gateway POST vulnerability attempt (more info ...)attempted-user 2013-5398   URL
29550MALWARE-CNC Win.Trojan.Doneste variant outbound connection (more info ...)trojan-activity    URL
29555MALWARE-CNC Win.Trojan.Spyex variant outbound connection (more info ...)trojan-activity    URL
29556MALWARE-CNC Win.Trojan.Loxes variant outbound connection (more info ...)trojan-activity    URL
29557MALWARE-CNC Win.Trojan.Marten variant outbound connection (more info ...)trojan-activity    URL
29559MALWARE-CNC Win.Trojan.Sydigu variant outbound connection (more info ...)trojan-activity    URL
29561MALWARE-CNC Win.Trojan.Lechiket variant outbound connection (more info ...)trojan-activity    URL
29562MALWARE-CNC Win.Trojan.Blobrsa variant outbound connection (more info ...)trojan-activity    URL
29563MALWARE-CNC Win.Trojan.Blobrsa variant outbound connection (more info ...)trojan-activity    URL
29565MALWARE-CNC Win.Trojan.Banker.AALV variant outbound connection (more info ...)trojan-activity    URL
29566MALWARE-CNC Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity    URL
29570FILE-OTHER Oracle Outside In OS2 metafile parser stack buffer overflow attempt (more info ...)attempted-user 2013-5763 63741  URL
29571FILE-OTHER Oracle Outside In OS2 metafile parser stack buffer overflow attempt (more info ...)attempted-user 2013-5763 63741  URL
29572FILE-OTHER Oracle Outside In OS2 metafile parser stack buffer overflow attempt (more info ...)attempted-user 2013-5763 63741  URL
29573FILE-OTHER Oracle Outside In OS2 metafile parser stack buffer overflow attempt (more info ...)attempted-user 2013-5763 63741  URL
29574FILE-OTHER Oracle Outside In OS2 metafile parser stack buffer overflow attempt (more info ...)attempted-user 2013-5763 63741  URL
29575FILE-OTHER Oracle Outside In OS2 metafile parser stack buffer overflow attempt (more info ...)attempted-user 2013-5763 63741  URL
29577FILE-OTHER Oracle Outside In OS2 metafile parser stack buffer overflow attempt (more info ...)attempted-user 2013-5763 63741  URL
29582SERVER-OTHER Mediawiki DjVu and PDF handling code execution attempt (more info ...)attempted-admin 2014-1610   
29583SERVER-WEBAPP HP Intelligent Management Center information disclosure attempt (more info ...)web-application-attack 2012-5208   
29593SERVER-WEBAPP Airlive IP Camera CSRF attempt (more info ...)policy-violation 2013-3540 60547  
29595SERVER-WEBAPP Airlive IP Camera directory traversal attempt (more info ...)web-application-attack 2013-3541 60549  
29615MALWARE-CNC Win.Trojan.Keylogger outbound connection (more info ...)trojan-activity 2014-0497   URL
29616MALWARE-CNC Win.Trojan.Keylogger inbound connection (more info ...)trojan-activity 2014-0497   URL
29635MALWARE-CNC Win.Trojan.Nursteal variant outbound connection (more info ...)trojan-activity    URL
29636MALWARE-CNC Win.Trojan.Blocker.cbuf variant outbound connection (more info ...)trojan-activity    URL
29637MALWARE-CNC Win.Trojan.Lumbko variant outbound connection (more info ...)trojan-activity    URL
29638MALWARE-CNC Win.Trojan.Lumbko variant initial outbound connection (more info ...)trojan-activity    URL
29644MALWARE-CNC Win.Trojan.Sdconsent outbound connection (more info ...)trojan-activity 2013-0158   URL
29645MALWARE-CNC User-Agent known malicious user-agent - Win.Trojan.Mimunita (more info ...)trojan-activity    URL
29646SERVER-WEBAPP SkyBlueCanvas CMS contact page command injection attempt (more info ...)web-application-attack 2014-1683 65129  
29652MALWARE-CNC User-Agent known malicious user-agent - Win.Trojan.Truado (more info ...)trojan-activity    URL
29660FILE-OTHER Norton Anti-Virus decompression bomb denial of service attempt (more info ...)attempted-dos    URL
29661FILE-OTHER Norton Anti-Virus decompression bomb denial of service attempt (more info ...)attempted-dos    URL
29663MALWARE-CNC Win.Trojan.Dampt variant outbound connection (more info ...)trojan-activity    URL
29664MALWARE-CNC Win.Trojan.DomaIQ variant outbound connection (more info ...)trojan-activity    URL
29665MALWARE-CNC Win.Trojan.Graftor variant outbound connection (more info ...)trojan-activity    URL
29666MALWARE-CNC Win.Trojan.Linkup outbound connection (more info ...)trojan-activity    URL
29670MALWARE-CNC Win.Trojan.Caphaw outbound connection (more info ...)trojan-activity    URL
29740MALWARE-CNC Win.Trojan.Sarvdap variant outbound connection (more info ...)trojan-activity    URL
29745INDICATOR-OBFUSCATION Alternating character encodings - JS variable (more info ...)policy-violation    URL
29750SERVER-WEBAPP HP Intelligent Management Center SOM authentication bypass attempt (more info ...)attempted-user 2013-4824 62902  URL
29751SERVER-WEBAPP HP Intelligent Management Center SOM authentication bypass attempt (more info ...)attempted-user 2013-4824 62902  URL
29752SERVER-WEBAPP HP Intelligent Management Center SOM authentication bypass attempt (more info ...)attempted-user 2013-4824 62902  URL
29760MALWARE-CNC User-Agent known malicious user-agent string MSIE 4.01 - Win.Trojan.Careto (more info ...)trojan-activity    URL
29788MALWARE-CNC Win.Trojan.Careto outbound connection (more info ...)trojan-activity    URL
29789MALWARE-CNC Win.Trojan.Careto plugin download (more info ...)trojan-activity    URL
29790MALWARE-CNC Win.Trojan.Careto plugin download (more info ...)trojan-activity    URL
29791MALWARE-CNC Win.Trojan.Careto plugin download (more info ...)trojan-activity    URL
29793SERVER-OTHER D-Link IP Cameras execution of commands from administration web interface (more info ...)attempted-user 2013-1599   URL
29794SERVER-OTHER D-Link IP Cameras access to the video stream via HTTP (more info ...)attempted-user 2013-1600   URL
29795SERVER-OTHER D-Link IP Cameras access the ASCII video stream via image luminance (more info ...)attempted-user 2013-1601   URL
29798SERVER-WEBAPP CuteFlow pre-authenticated admin account creation attempt (more info ...)attempted-admin    URL
29799SERVER-WEBAPP CuteFlow pre-authenticated admin account creation attempt (more info ...)attempted-admin    URL
29800FILE-OTHER XML exponential entity expansion attack attempt (more info ...)attempted-user 2015-0677   URL
29807INDICATOR-OBFUSCATION Alternating character encodings - JS array (more info ...)policy-violation    URL
29808SERVER-WEBAPP Nagios XI alert cloud cross site scripting attempt (more info ...)attempted-user    
29813INDICATOR-OBFUSCATION randomized HTML number encodings detected in clsid access attempt (more info ...)policy-violation    URL
29816MALWARE-CNC Win.Trojan.Jackpos outbound connection (more info ...)trojan-activity    URL
29817MALWARE-CNC Win.Trojan.Jackpos outbound connection (more info ...)trojan-activity    URL
29824MALWARE-CNC User-Agent known malicious user agent - TixDll - Win.Trojan.Adload.dyhq (more info ...)trojan-activity    URL
29828MALWARE-CNC Win.Trojan.Adload.dyhq variant outbound connection (more info ...)trojan-activity    URL
29861MALWARE-CNC Win.Trojan.Brabat variant outbound connection (more info ...)trojan-activity    URL
29862MALWARE-CNC Win.Trojan.Pirminay variant outbout connection (more info ...)trojan-activity    URL
29863MALWARE-CNC Win.Trojan.Pirminay variant outbound connection (more info ...)trojan-activity    URL
29865MALWARE-CNC Win.Trojan.Kuluoz outbound connection (more info ...)trojan-activity    URL
29869MALWARE-CNC Win.Trojan.Napolar phishing attack (more info ...)trojan-activity    URL
29870MALWARE-CNC Win.Trojan.Pony HTTP response connection (more info ...)trojan-activity    URL
29871SERVER-ORACLE Oracle Reports server remote code execution attempt (more info ...)attempted-admin 2012-3153   URL
29873MALWARE-CNC Win.Trojan.Hanove variant outbound connection (more info ...)trojan-activity    URL
29877MALWARE-CNC Win.Trojan.Chikdos.A outbound information disclosure (more info ...)trojan-activity    URL
29882MALWARE-CNC Win.Trojan.WEC variant outbound connection (more info ...)trojan-activity    URL
29883MALWARE-CNC Win.Trojan.Tohwen variant outbound connection (more info ...)trojan-activity    URL
29884MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    
29885MALWARE-CNC Win.Trojan.Crypi.A outbound information disclosure (more info ...)trojan-activity    URL
29886MALWARE-CNC Win.Trojan.Crypi.A outbound keylogger traffic (more info ...)trojan-activity    URL
29887MALWARE-CNC User-Agent known malicious user-agent string Updates downloader - Win.Trojan.Upatre (more info ...)trojan-activity    URL
29893MALWARE-CNC Win.Trojan.Pyteconte variant outbound connection (more info ...)trojan-activity    URL
29895MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
29897MALWARE-CNC Win.Trojan.ExplorerHijack variant outbound connection (more info ...)trojan-activity    URL
29898MALWARE-CNC Win.Trojan.Zygtab variant outbound connection (more info ...)trojan-activity    URL
29899MALWARE-CNC Win.Trojan.Pmkype variant outbound connection (more info ...)trojan-activity    URL
29901MALWARE-CNC Win.Trojan.Comowba variant outbound connection (more info ...)trojan-activity    URL
29907MALWARE-CNC Win.Trojan.Madnedos outbound system information disclosure (more info ...)trojan-activity    URL
29908MALWARE-CNC TRUFFLEHUNTER SFVRT-1015 attack attempt (more info ...)trojan-activity    
29911MALWARE-CNC Win.Trojan.Nortusa variant outbound system information disclosure (more info ...)trojan-activity    URL
29916MALWARE-CNC Win.Trojan.Matsnu system information disclosure (more info ...)trojan-activity    URL
29920MALWARE-CNC Win.Trojan.ZhiZhu variant outbound connection (more info ...)trojan-activity    URL
29921MALWARE-CNC Win.Trojan.ZhiZhu variant inbound connection (more info ...)trojan-activity    URL
29922MALWARE-CNC Andr.Trojan.Bazuc initial outbound connection (more info ...)trojan-activity    URL
29923MALWARE-CNC Andr.Trojan.Bazuc jobs check outbound connection (more info ...)trojan-activity    URL
29924MALWARE-CNC Win.Trojan.Farfli outbound connection (more info ...)trojan-activity    URL
29925MALWARE-CNC Win.Trojan.Verxbot variant outbound connection (more info ...)trojan-activity    URL
29938SERVER-OTHER InduSoft Web Studio Remote Agent buffer overflow attempt (more info ...)attempted-user 2011-4052   
29939SERVER-OTHER EMC AlphaStore buffer overflow attempt (more info ...)attempted-admin 2013-0946   
29940SERVER-OTHER EMC AlphaStore buffer overflow attempt (more info ...)attempted-admin 2013-0946   
29941SERVER-OTHER EMC AlphaStore buffer overflow attempt (more info ...)attempted-admin 2013-0930   
29942SERVER-OTHER EMC AlphaStore buffer overflow attempt (more info ...)attempted-admin 2013-0930   
29946SERVER-OTHER IBM DB2 Universal Database receiveDASMessage buffer overflow attempt (more info ...)attempted-admin 2011-0731 46052  
29947SERVER-OTHER IBM DB2 Universal Database receiveDASMessage buffer overflow attempt (more info ...)attempted-admin 2011-0731 46052  
29948SERVER-OTHER IBM DB2 Universal Database receiveDASMessage buffer overflow attempt (more info ...)attempted-admin 2011-0731 46052  
29950SERVER-OTHER TP-Link TL-WR740N wireless router remote denial of service attempt (more info ...)attempted-dos  58623  URL
29951SERVER-OTHER HylaFAX plus LDAP authentication username buffer overflow attempt (more info ...)attempted-admin 2013-5680 62729  
29952SERVER-OTHER HP LoadRunner XDR handling heap buffer overflow (more info ...)attempted-user 2013-4799   URL
29953SERVER-OTHER Ubiquiti airCam RTSP service buffer overflow attempt (more info ...)attempted-admin 2013-1606 60487  URL
29954PROTOCOL-SCADA CODESYS Gateway-Server heap buffer overflow attempt (more info ...)attempted-admin 2012-4706   
29958SERVER-OTHER multiple products HTTP HEAD request buffer overflow attempt (more info ...)attempted-user 2012-5876   
29959PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime stack buffer overflow attempt (more info ...)attempted-admin 2011-4875   URL
29960PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime DoS attempt (more info ...)attempted-admin 2011-4877   URL
29961PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime DoS attempt (more info ...)attempted-admin 2011-4877   URL
29962PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime DoS attempt (more info ...)attempted-admin 2011-4877   URL
29963PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime DoS attempt (more info ...)attempted-admin 2011-4877   URL
29964PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime directory traversal attempt (more info ...)attempted-admin 2011-4876   URL
29966SERVER-OTHER Ubiquiti airCam RTSP service buffer overflow attempt (more info ...)attempted-admin 2013-1606 60487  URL
29967SERVER-OTHER Python socket.recvfrom_into remote buffer overflow attempt (more info ...)attempted-user 2014-1912 65379  URL
29968SERVER-OTHER Python socket.recvfrom_into remote buffer overflow attempt (more info ...)attempted-user 2014-1912 65379  URL
29973MALWARE-CNC Win.Trojan.Bublik.Zusy runtime detection (more info ...)trojan-activity    URL
29975MALWARE-CNC Win.Trojan.Svekifc system information disclosure (more info ...)trojan-activity    URL
29976MALWARE-CNC Win.Trojan.Svekifc outbound persistent connection (more info ...)trojan-activity    URL
29978MALWARE-CNC ANDR.Trojan.FakeApp outbound connection (more info ...)trojan-activity    URL
29979SERVER-WEBAPP Symantec Endpoint Protection Manager Unauthenticated XML External Entity Injection attempt (more info ...)attempted-user 2013-5015   
29980MALWARE-CNC Win.Trojan.Fucom outbound connection (more info ...)trojan-activity    URL
29981MALWARE-CNC Win.Trojan.Tiny variant outbound connection (more info ...)trojan-activity    URL
29982MALWARE-CNC Win.Trojan.Oshidor variant outbound connection (more info ...)trojan-activity    URL
29985MALWARE-CNC Win.Trojan.Bicolo variant outbound connection (more info ...)trojan-activity    URL
29987MALWARE-CNC Win.Trojan.Meac malware component download request (more info ...)trojan-activity    URL
29990MALWARE-CNC Win.Trojan.Seruda system information disclosure (more info ...)trojan-activity    URL
29998MALWARE-CNC Win.Trojan.Horsum outbound system information disclosure (more info ...)trojan-activity    URL
29999MALWARE-CNC User-Agent known malicious user-agent string - MSIE 9.0 in version 10 format (more info ...)trojan-activity    URL
30000MALWARE-BACKDOOR FireCrotch exploit kit backdoor attempt (more info ...)misc-activity    
30014FILE-IDENTIFY OS/2 Metafile file magic detected (more info ...)misc-activity    URL
30015FILE-IDENTIFY OS/2 Metafile file attachment detected (more info ...)misc-activity    URL
30016FILE-IDENTIFY OS/2 Metafile file attachment detected (more info ...)misc-activity    URL
30017FILE-IDENTIFY OS/2 Metafile file magic detected (more info ...)misc-activity    URL
30018FILE-IDENTIFY OS/2 Metafile file download request (more info ...)misc-activity    URL
30019FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30020FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30021FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30022FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30023FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30024FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30025FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30026FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30027FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30028FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30029FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30030FILE-OTHER Oracle Outside In OS/2 Metafile parser stack overflow attempt (more info ...)attempted-user 2013-5879 64825  
30032SERVER-OTHER Borland VisiBroker Smart Agent heap overflow attempt (more info ...)attempted-user 2008-7126 28084  URL
30034MALWARE-CNC Win.Trojan.Donanbot outbound connection (more info ...)trojan-activity    URL
30035MALWARE-CNC Win.Trojan.Sylonif variant outbound connection (more info ...)trojan-activity    URL
30036MALWARE-CNC Win.Trojan.Ovnavart variant outbound connection (more info ...)trojan-activity    URL
30037MALWARE-CNC Win.Trojan.Zaleelq variant outbound connection (more info ...)trojan-activity 2012-0158   URL
30038PUA-TOOLBARS Babylon toolbar outbound connection (more info ...)misc-activity    URL
30047MALWARE-CNC Win.Trojan.Crowti variant outbound connection (more info ...)trojan-activity    URL
30057MALWARE-CNC Win.Trojan.Peronspy outbound system information disclosure (more info ...)trojan-activity    URL
30060MALWARE-CNC Win.Trojan.Coresh outbound identification request (more info ...)trojan-activity    URL
30061MALWARE-CNC Win.Trojan.Tyleny variant outbound connection (more info ...)trojan-activity    URL
30063MALWARE-CNC Win.Trojan.Zbot outbound connection (more info ...)trojan-activity    URL
30064MALWARE-CNC Win.Trojan.Zbot outbound connection (more info ...)trojan-activity    URL
30068MALWARE-CNC Win.Trojan.Androm variant outbound connection (more info ...)trojan-activity    URL
30073MALWARE-CNC Win.Trojan.Kuluoz variant outbound connection (more info ...)trojan-activity    URL
30074MALWARE-CNC Win.Trojan.Nemim variant outbound connection (more info ...)trojan-activity    URL
30076MALWARE-CNC Win.Trojan.Stealzilla variant outbound connection (more info ...)trojan-activity    URL
30078MALWARE-CNC Win.Trojan.Momibot outbound system information disclosure (more info ...)trojan-activity    URL
30087MALWARE-CNC Win.Trojan.Gamut configuration download (more info ...)trojan-activity    URL
30088MALWARE-CNC Win.Trojan.Hupigon variant outbound connection (more info ...)trojan-activity    URL
30090MALWARE-CNC Win.Trojan.Nitol variant outbound connection (more info ...)trojan-activity    URL
30091MALWARE-CNC Win.Trojan.Necurs variant outbound connection (more info ...)trojan-activity    URL
30099MALWARE-CNC Win.Trojan.Reedum BlackPoS stolen data transfer to internal staging area (more info ...)trojan-activity    URL
30167MALWARE-CNC Russian Bank scam malware GET request to server (more info ...)trojan-activity    
30168MALWARE-CNC Russian Bank scam malware POST to server (more info ...)trojan-activity    
30191MALWARE-CNC Win.Trojan.Uroburos usermode-centric client request (more info ...)trojan-activity    URL
30192MALWARE-CNC Win.Trojan.Uroburos inbound command (more info ...)trojan-activity    URL
30193MALWARE-CNC Win.Trojan.Uroburos inbound encrypted data (more info ...)trojan-activity    URL
30195APP-DETECT Paros proxy outbound connection attempt (more info ...)policy-violation    URL
30196MALWARE-CNC Win.Trojan.Androm variant outbound connection (more info ...)trojan-activity    URL
30198MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
30202SERVER-MAIL Mortal Universe POP Peeper uidl header overflow attempt (more info ...)attempted-user 2009-1029   URL
30203MALWARE-CNC Win.Trojan.TDSS variant outbound connection (more info ...)trojan-activity    URL
30204MALWARE-CNC Win.Trojan.TDSS variant outbound connection (more info ...)trojan-activity    URL
30208MALWARE-CNC Win.Trojan.Nakcos variant outbound connection (more info ...)trojan-activity    URL
30210MALWARE-CNC User-Agent known malicious user-agnet string Win.Trojan.ZeusVM (more info ...)trojan-activity    URL
30211MALWARE-CNC Win.Trojan.ZeusVM embedded image config file download (more info ...)trojan-activity    URL
30214MALWARE-CNC Win.Trojan.Sharik variant outbound connection (more info ...)trojan-activity    URL
30216MALWARE-CNC Win.Trojan.ShadyRAT variant outbound connection (more info ...)trojan-activity    URL
30225INDICATOR-SHELLCODE possible /bin/sh shellcode transfer attempt (more info ...)shellcode-detect    URL
30226INDICATOR-SHELLCODE Metasploit windows/meterpreter stage transfer attempt (more info ...)shellcode-detect    URL
30227INDICATOR-SHELLCODE Metasploit windows/reverse_tcp stager transfer attempt (more info ...)shellcode-detect    URL
30228INDICATOR-SHELLCODE Metasploit windows/shell stage transfer attempt (more info ...)shellcode-detect    URL
30231MALWARE-CNC Win.Trojan.Eybog variant outbound connection (more info ...)trojan-activity    URL
30234MALWARE-CNC Win.Trojan.Graftor variant outbound connection (more info ...)trojan-activity    URL
30235MALWARE-CNC Win.Trojan.Qadars variant outbound connection (more info ...)trojan-activity    URL
30237PUA-ADWARE InstallMonster initial runtime outbound connection (more info ...)misc-activity    URL
30238PUA-ADWARE InstallMonster follow-up outbound connection (more info ...)misc-activity    URL
30239MALWARE-CNC Win.Trojan.Name variant outbound connection (more info ...)trojan-activity    URL
30250MALWARE-CNC User-Agent known malicious user agent - logogo.exe (more info ...)trojan-activity    URL
30251MALWARE-CNC Win.Trojan.Mumawow outbound connection (more info ...)trojan-activity    URL
30253APP-DETECT Anyplace proxy header detected (more info ...)web-application-activity    URL
30254APP-DETECT Anyplace usage attempt (more info ...)web-application-activity    URL
30255MALWARE-CNC Win.Trojan.Strictor HTTP Response - Brazil Geolocated Infected User (more info ...)trojan-activity    URL
30256MALWARE-CNC Win.Trojan.Strictor HTTP Response - Non-Brazil Geolocated Infected User (more info ...)trojan-activity    URL
30257MALWARE-CNC Win.Trojan.ExplorerHijack variant outbound connection (more info ...)trojan-activity    URL
30258MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
30259MALWARE-CNC Win.Trojan.Strictor variant outbound connection (more info ...)trojan-activity    URL
30262MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
30270MALWARE-CNC Win.Trojan.Zbot configuration file download (more info ...)trojan-activity    URL
30271MALWARE-CNC Win.Trojan.Zbot drop zone file upload (more info ...)trojan-activity    URL
30276MALWARE-CNC Win.Trojan.Sloth variant command and control traffic (more info ...)trojan-activity    URL
30277MALWARE-CNC Win.Trojan.Sloth variant command and control traffic (more info ...)trojan-activity    URL
30278MALWARE-CNC Win.Trojan.Sloth variant command and control traffic (more info ...)trojan-activity    URL
30279MALWARE-CNC Win.Trojan.Sloth variant command and control traffic (more info ...)trojan-activity    URL
30281POLICY-OTHER use of psexec remote administration tool SMBv2 (more info ...)policy-violation    URL
30284MALWARE-CNC Win.Trojan.Recub variant outbound connection (more info ...)trojan-activity    URL
30288MALWARE-CNC Win.Trojan.Glupteba.M initial outbound connection (more info ...)trojan-activity    URL
30290MALWARE-CNC Win.Trojan.Bruterdep variant outbound connection (more info ...)trojan-activity    URL
30291SERVER-WEBAPP Digium Asterisk cookie stack buffer overflow attempt (more info ...)attempted-dos 2014-2286 66093  
30292SERVER-WEBAPP Digium Asterisk cookie stack buffer overflow attempt (more info ...)attempted-dos 2014-2286 66093  
30293SERVER-WEBAPP Digium Asterisk cookie stack buffer overflow attempt (more info ...)attempted-dos 2014-2286 66093  
30297SERVER-WEBAPP Katello update_roles method privilege escalation attempt (more info ...)attempted-admin 2013-2143 66434  
30298MALWARE-CNC Win.Backdoor.Cloudoten variant inbound connection (more info ...)trojan-activity    URL
30299MALWARE-CNC Win.Trojan.Projecthook variant outbound connection (more info ...)trojan-activity    URL
30300MALWARE-CNC Win.Trojan.Projecthook variant outbound connection (more info ...)trojan-activity    URL
30301MALWARE-CNC User-Agent known malicious user agent InetAll - Win.Trojan.Pennonec (more info ...)trojan-activity    URL
30302MALWARE-CNC Win.Trojan.Rajdze variant outbound connection (more info ...)trojan-activity    URL
30304MALWARE-CNC Win.Trojan.Noctabor variant outbound connection (more info ...)trojan-activity    URL
30307SERVER-WEBAPP EMC Connectrix Manager FileUploadController directory traversal attempt (more info ...)attempted-recon 2014-2276 66308  
30308MALWARE-CNC User-Agent known malicious user agent - Win.Backdoor.Jolob (more info ...)trojan-activity    URL
30309MALWARE-CNC User-Agent known malicious user agent - Win.Backdoor.Jolob (more info ...)trojan-activity    URL
30310MALWARE-CNC Win.Backdoor.Comdinter variant outbound connection (more info ...)trojan-activity    URL
30311MALWARE-CNC Win.Backdoor.Comdinter variant outbound connection (more info ...)trojan-activity    URL
30314MALWARE-CNC User-Agent known malicious User-Agent getcmd - Win.Trojan.Burnwoo (more info ...)trojan-activity    URL
30315MALWARE-CNC User-Agent known malicious User-Agent getcmdw23 - Win.Trojan.Burnwoo (more info ...)trojan-activity    URL
30323MALWARE-CNC Win.Trojan.Drawnetz variant outbound connection (more info ...)trojan-activity    URL
30327INDICATOR-OBFUSCATION multiple binary tags in close proximity - potentially malicious (more info ...)misc-attack 2012-0158   URL
30328INDICATOR-OBFUSCATION multiple binary tags in close proximity - potentially malicious (more info ...)misc-attack 2012-0158   URL
30329SERVER-OTHER McAfee Asset Manager downloadReport information disclosure attempt (more info ...)attempted-recon 2014-2588 66302  
30330SERVER-OTHER McAfee Asset Manager downloadReport information disclosure attempt (more info ...)attempted-recon 2014-2588 66302  
30331MALWARE-CNC User-Agent known malicious User-Agent ebot - Win.Trojan.Modulog (more info ...)trojan-activity    URL
30332MALWARE-CNC Win.Trojan.ProjectHook configuration file download attempt (more info ...)trojan-activity    URL
30333MALWARE-CNC Win.Trojan.ProjectHook information disclosure attempt (more info ...)trojan-activity    URL
30334MALWARE-CNC Win.Trojan.ProjectHook initial outbound connection (more info ...)trojan-activity    URL
30344MALWARE-CNC User-Agent known malicious User-Agent EyeS_Client_1.0 - Win.Trojan.Seey (more info ...)trojan-activity    URL
30346SERVER-OTHER TRUFFLEHUNTER SFVRT-1016 attack attempt (more info ...)attempted-admin    
30354INDICATOR-SHELLCODE Metasploit payload android_shell_reverse_tcp (more info ...)shellcode-detect    
30355INDICATOR-SHELLCODE Metasploit payload bsd_sparc_shell_bind_tcp (more info ...)shellcode-detect    
30356INDICATOR-SHELLCODE Metasploit payload bsd_sparc_shell_reverse_tcp (more info ...)shellcode-detect    
30357INDICATOR-SHELLCODE Metasploit payload bsd_x86_exec (more info ...)shellcode-detect    
30358INDICATOR-SHELLCODE Metasploit payload bsd_x86_shell_bind_ipv6_tcp (more info ...)shellcode-detect    
30359INDICATOR-SHELLCODE Metasploit payload bsd_x86_shell_bind_tcp (more info ...)shellcode-detect    
30360INDICATOR-SHELLCODE Metasploit payload bsd_x86_shell_find_port (more info ...)shellcode-detect    
30361INDICATOR-SHELLCODE Metasploit payload bsd_x86_shell_reverse_ipv6_tcp (more info ...)shellcode-detect    
30362INDICATOR-SHELLCODE Metasploit payload bsd_x86_shell_reverse_tcp (more info ...)shellcode-detect    
30363INDICATOR-SHELLCODE Metasploit payload bsdi_x86_shell_find_port (more info ...)shellcode-detect    
30386INDICATOR-SHELLCODE Metasploit payload cmd_windows_adduser (more info ...)shellcode-detect    
30387INDICATOR-SHELLCODE Metasploit payload cmd_windows_bind_perl (more info ...)shellcode-detect    
30388INDICATOR-SHELLCODE Metasploit payload cmd_windows_bind_perl_ipv6 (more info ...)shellcode-detect    
30389INDICATOR-SHELLCODE Metasploit payload cmd_windows_bind_ruby (more info ...)shellcode-detect    
30390INDICATOR-SHELLCODE Metasploit payload cmd_windows_download_exec_vbs (more info ...)shellcode-detect    
30391INDICATOR-SHELLCODE Metasploit payload cmd_windows_reverse_perl (more info ...)shellcode-detect    
30392INDICATOR-SHELLCODE Metasploit payload cmd_windows_reverse_powershell (more info ...)shellcode-detect    URL
30393INDICATOR-SHELLCODE Metasploit payload cmd_windows_reverse_ruby (more info ...)shellcode-detect    
30394INDICATOR-SHELLCODE Metasploit payload firefox_exec (more info ...)shellcode-detect    
30395INDICATOR-SHELLCODE Metasploit payload firefox_shell_bind_tcp (more info ...)shellcode-detect    
30432INDICATOR-SHELLCODE Metasploit payload netware_shell_reverse_tcp (more info ...)shellcode-detect    
30433INDICATOR-SHELLCODE Metasploit payload nodejs_shell_bind_tcp (more info ...)shellcode-detect    
30434INDICATOR-SHELLCODE Metasploit payload osx_armle_shell_bind_tcp (more info ...)shellcode-detect    
30435INDICATOR-SHELLCODE Metasploit payload osx_armle_shell_reverse_tcp (more info ...)shellcode-detect    
30436INDICATOR-SHELLCODE Metasploit payload osx_armle_vibrate (more info ...)shellcode-detect    
30437INDICATOR-SHELLCODE Metasploit payload osx_ppc_shell_bind_tcp (more info ...)shellcode-detect    
30438INDICATOR-SHELLCODE Metasploit payload osx_ppc_shell_find_tag (more info ...)shellcode-detect    
30439INDICATOR-SHELLCODE Metasploit payload osx_ppc_shell_reverse_tcp (more info ...)shellcode-detect    
30440INDICATOR-SHELLCODE Metasploit payload osx_x64_dupandexecve_bind_tcp (more info ...)shellcode-detect    
30441INDICATOR-SHELLCODE Metasploit payload osx_x64_dupandexecve_reverse_tcp (more info ...)shellcode-detect    
30442INDICATOR-SHELLCODE Metasploit payload osx_x64_exec (more info ...)shellcode-detect    
30443INDICATOR-SHELLCODE Metasploit payload osx_x64_say (more info ...)shellcode-detect    
30444INDICATOR-SHELLCODE Metasploit payload osx_x64_shell_find_tag (more info ...)shellcode-detect    
30445INDICATOR-SHELLCODE Metasploit payload osx_x64_shell_reverse_tcp (more info ...)shellcode-detect    
30446INDICATOR-SHELLCODE Metasploit payload osx_x86_exec (more info ...)shellcode-detect    
30447INDICATOR-SHELLCODE Metasploit payload osx_x86_isight_bind_tcp (more info ...)shellcode-detect    
30448INDICATOR-SHELLCODE Metasploit payload osx_x86_isight_reverse_tcp (more info ...)shellcode-detect    
30449INDICATOR-SHELLCODE Metasploit payload osx_x86_shell_find_port (more info ...)shellcode-detect    
30450INDICATOR-SHELLCODE Metasploit payload osx_x86_vforkshell_bind_tcp (more info ...)shellcode-detect    
30451INDICATOR-SHELLCODE Metasploit payload osx_x86_vforkshell_reverse_tcp (more info ...)shellcode-detect    
30460INDICATOR-SHELLCODE Metasploit payload python_meterpreter_bind_tcp (more info ...)shellcode-detect    
30461INDICATOR-SHELLCODE Metasploit payload python_shell_reverse_tcp_ssl (more info ...)shellcode-detect    
30462INDICATOR-SHELLCODE Metasploit payload ruby_shell_bind_tcp (more info ...)shellcode-detect    
30463INDICATOR-SHELLCODE Metasploit payload ruby_shell_reverse_tcp (more info ...)shellcode-detect    
30464INDICATOR-SHELLCODE Metasploit payload ruby_shell_reverse_tcp_ssl (more info ...)shellcode-detect    
30472INDICATOR-SHELLCODE Metasploit payload windows_messagebox (more info ...)shellcode-detect    
30473INDICATOR-SHELLCODE Metasploit payload windows_meterpreter_bind_nonx_tcp (more info ...)shellcode-detect    
30474INDICATOR-SHELLCODE Metasploit payload windows_meterpreter_bind_tcp (more info ...)shellcode-detect    
30475INDICATOR-SHELLCODE Metasploit payload windows_meterpreter_find_tag (more info ...)shellcode-detect    
30476INDICATOR-SHELLCODE Metasploit payload windows_meterpreter_reverse_ord_tcp (more info ...)shellcode-detect    
30477INDICATOR-SHELLCODE Metasploit payload windows_shell_bind_tcp_xpfw (more info ...)shellcode-detect    
30478INDICATOR-SHELLCODE Metasploit payload windows_speak_pwned (more info ...)shellcode-detect    
30479INDICATOR-SHELLCODE Metasploit payload windows_x64_exec (more info ...)shellcode-detect    
30482MALWARE-CNC Win.Trojan.Zbot/Bublik inbound connection (more info ...)trojan-activity    URL
30483MALWARE-CNC Win.Trojan.Zbot/Bublik outbound connection (more info ...)trojan-activity    URL
30484MALWARE-CNC Win.Trojan.Zbot/Bublik outbound connection (more info ...)trojan-activity    URL
30487SERVER-OTHER Zilab Chat and Instant Messaging server heap overflow attempt (more info ...)attempted-user  27940  URL
30488SERVER-OTHER Zilab Chat and Instant Messaging server channel join heap overflow attempt (more info ...)attempted-user  27940  URL
30489SERVER-OTHER Zilab Chat and Instant Messaging server connection heap overflow attempt (more info ...)attempted-user  27940  URL
30494MALWARE-CNC Win.Trojan.Boaxxe variant outbound connection (more info ...)trojan-activity    URL
30495MALWARE-CNC Win.Trojan.Boaxxe variant outbound connection (more info ...)trojan-activity    URL
30518MALWARE-CNC User-Agent known malicious User-Agent Neutrino/2.1 - Win.Trojan.Necurs (more info ...)trojan-activity    URL
30519MALWARE-CNC Win.Trojan.Necurs variant outbound connection (more info ...)trojan-activity    URL
30526SERVER-WEBAPP Joomla komento extension cross site scripting attempt (more info ...)attempted-user 2014-0793 64659  
30527SERVER-WEBAPP Joomla komento extension cross site scripting attempt (more info ...)attempted-user 2014-0793 64659  
30530FILE-MULTIMEDIA CoCSoft Stream Down SEH based buffer overflow attempt (more info ...)attempted-user 2011-5052 51190  
30531FILE-MULTIMEDIA CoCSoft Stream Down SEH based buffer overflow attempt (more info ...)attempted-user 2011-5052 51190  
30532FILE-MULTIMEDIA CoCSoft Stream Download session (more info ...)attempted-user 2011-5052 51190  
30547MALWARE-CNC Win.Trojan.Ramdo variant outbound connection (more info ...)trojan-activity    URL
30548MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
30551MALWARE-CNC Malicious BitCoiner Miner download - Win.Trojan.Minerd (more info ...)trojan-activity    URL
30552MALWARE-CNC Malicious BitCoiner Miner download - Win.Trojan.Systema (more info ...)trojan-activity    URL
30559MALWARE-CNC Win.Trojan.Uniemv variant outbound connection (more info ...)trojan-activity    URL
30560MALWARE-CNC Win.Trojan.Megesat variant outbound connection (more info ...)trojan-activity    URL
30570MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
30571SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100400 (more info ...)misc-activity    
30572SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100401 (more info ...)misc-activity    
30573SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100402 (more info ...)misc-activity    
30574SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100403 (more info ...)misc-activity    
30580SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100170 (more info ...)misc-activity    
30582SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100172 (more info ...)misc-activity    
30597SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100019 (more info ...)misc-activity    
30619SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100050 (more info ...)misc-activity    
30664SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100102 (more info ...)misc-activity    
30686SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100149 (more info ...)unknown    
30695SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100187 (more info ...)misc-activity    
30698SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100191 (more info ...)misc-activity    
30699SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100193 (more info ...)misc-activity    
30701SERVER-OTHER TRUFFLEHUNTER SFVRT-1008 attack attempt 100207 (more info ...)misc-activity    
30702SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100217 (more info ...)misc-activity    
30705SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100222 (more info ...)misc-activity    
30706SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100231 (more info ...)misc-activity    
30709SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100302 (more info ...)misc-activity    
30710SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100303 (more info ...)misc-activity    
30743MALWARE-CNC Win.Trojan.Chabava outbound connection (more info ...)trojan-activity    URL
30751MALWARE-CNC Win.Trojan.Ransom variant outbound connection (more info ...)trojan-activity    URL
30752MALWARE-CNC Win.Trojan.Tesyong outbound connection (more info ...)trojan-activity    URL
30753MALWARE-CNC Win.Trojan.Rehacker outbound connection (more info ...)trojan-activity    URL
30756FILE-IDENTIFY ABC Music Notation file attachment detected (more info ...)misc-activity    URL
30757FILE-IDENTIFY ABC Music Notation file attachment detected (more info ...)misc-activity    URL
30758FILE-IDENTIFY ABC Music Notation file attachment detected (more info ...)misc-activity    URL
30759FILE-IDENTIFY ABC Music Notation file attachment detected (more info ...)misc-activity    URL
30760FILE-IDENTIFY ABC Music Notation file download request (more info ...)misc-activity    URL
30761FILE-MULTIMEDIA VideoLAN VLC Media Player abc file parts heap integer overflow attempt (more info ...)attempted-user 2013-4233   
30762FILE-MULTIMEDIA VideoLAN VLC Media Player abc file parts heap integer overflow attempt (more info ...)attempted-user 2013-4233   
30763FILE-MULTIMEDIA VideoLAN VLC Media Player abc file parts heap integer overflow attempt (more info ...)attempted-user 2013-4233   
30764FILE-MULTIMEDIA VideoLAN VLC Media Player abc file parts heap integer overflow attempt (more info ...)attempted-user 2013-4233   
30770FILE-PDF Foxit Reader CFF CharStrings buffer overflow attempt (more info ...)attempted-user 2010-1797   URL
30771FILE-PDF Foxit Reader CFF CharStrings buffer overflow attempt (more info ...)attempted-user 2010-1797   URL
30773MALWARE-CNC Win.Trojan.Kuluoz variant download request (more info ...)trojan-activity    URL
30776MALWARE-CNC Win.Trojan.Targnik variant outbound connection (more info ...)trojan-activity    URL
30789SERVER-WEBAPP Acunetix web vulnerability scanner fake URL exploit attempt (more info ...)attempted-admin    URL
30804MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30805MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30806MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30807MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30808MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30809MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30810MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30811MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30812MALWARE-CNC Win.Trojan.Hulpob outbound connection (more info ...)trojan-activity    URL
30815MALWARE-CNC Andr.Trojan.Oldboot variant outbound connection (more info ...)trojan-activity    URL
30882MALWARE-CNC Win.Trojan.Rbrute inbound connection (more info ...)trojan-activity    URL
30883MALWARE-CNC Win.Trojan.Rbrute inbound connection (more info ...)trojan-activity    URL
30889PROTOCOL-VOIP Content-Type media type overflow denial of service attempt (more info ...)attempted-dos 2014-2163   URL
30890PROTOCOL-VOIP Content-Type media type overflow denial of service attempt (more info ...)attempted-dos 2014-2163   URL
30896MALWARE-CNC Win.Backdoor.DarkKomet variant outbound connection (more info ...)trojan-activity    URL
30897MALWARE-CNC Win.Backdoor.DarkKomet variant outbound connection (more info ...)trojan-activity    URL
30900MALWARE-CNC Win.Trojan.Tuhao variant outbound connection (more info ...)trojan-activity    URL
30904FILE-OTHER RARLAB WinRAR ZIP format filename spoof attempt (more info ...)attempted-user  66383  URL
30906FILE-OTHER RARLAB WinRAR ZIP format filename spoof attempt (more info ...)attempted-user  66383  URL
30907FILE-OTHER RARLAB WinRAR ZIP format filename spoof attempt (more info ...)attempted-user  66383  URL
30909FILE-OTHER RARLAB WinRAR ZIP format filename spoof attempt (more info ...)attempted-user  66383  URL
30910SERVER-WEBAPP Drupal VideoWhisper Webcam plugin XSS attempt (more info ...)web-application-attack 2014-2715   URL
30911SERVER-WEBAPP Drupal VideoWhisper Webcam plugin XSS attempt (more info ...)web-application-attack 2014-2715   URL
30914MALWARE-CNC Win.Trojan.SpySmall variant outbound connection (more info ...)trojan-activity    URL
30915MALWARE-CNC Win.Trojan.SpySmall variant outbound connection (more info ...)trojan-activity    URL
30917MALWARE-CNC Win.Worm.Phelshap variant outbound connection (more info ...)trojan-activity    URL
30919MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
30923MALWARE-CNC Win.Trojan.Sefnit outbound connection (more info ...)trojan-activity    URL
30924MALWARE-CNC Win.Trojan.Hd backdoor inbound connection (more info ...)trojan-activity    URL
30925MALWARE-CNC Win.Trojan.Hd backdoor outbound connection (more info ...)trojan-activity    URL
30926MALWARE-CNC Win.Trojan.Hd backdoor outbound secure-connection (more info ...)trojan-activity    URL
30930PUA-ADWARE Win.Adware.FakeAV variant outbound connection (more info ...)trojan-activity    URL
30936EXPLOIT-KIT Goon/Infinity/Rig exploit kit outbound uri structure (more info ...)trojan-activity    
30937EXPLOIT-KIT Nuclear exploit kit outbound PDF request (more info ...)trojan-activity    
30947MALWARE-CNC Win.Backdoor.Botintin outbound connection (more info ...)trojan-activity    URL
30950SERVER-MAIL BitDefender Antivirus logging function format string remote code execution attempt (more info ...)attempted-user 2005-3154 14968  
30953MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
30954MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
30955MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
30958BROWSER-OTHER suspicious srcElement child element removal - possible use after free attempt (more info ...)attempted-user    
30960EXPLOIT-KIT Sweet Orange exploit kit outbound jnlp request (more info ...)trojan-activity    
30977MALWARE-CNC Win.Trojan.Jaik variant outbound connection (more info ...)trojan-activity    URL
30978MALWARE-CNC Win.Trojan.Rbrute inbound connection (more info ...)trojan-activity    URL
30979MALWARE-CNC Win.Trojan.Gisetik information disclosure attempt (more info ...)trojan-activity    URL
30982MALWARE-CNC Win.Trojan.Karnos variant outbound connection (more info ...)trojan-activity    URL
30983MALWARE-CNC Win.Trojan.Karnos variant outbound connection (more info ...)trojan-activity    URL
30984MALWARE-CNC Win.Trojan.Vonriamt outbound connection (more info ...)trojan-activity    URL
30986MALWARE-CNC Win.Trojan.Tenexmed inbound shell command attempt (more info ...)trojan-activity    URL
30987MALWARE-CNC Win.Trojan.Vondola configuration file download attempt (more info ...)trojan-activity    URL
30988MALWARE-CNC Win.Trojan.Vondola information disclosure attempt (more info ...)trojan-activity    URL
30990MALWARE-CNC Shiqiang Gang malicious XLS targeted attack detection (more info ...)trojan-activity 2012-0158   URL
30991MALWARE-CNC Shiqiang Gang malicious XLS targeted attack detection (more info ...)trojan-activity 2012-0158   URL
30992FILE-OTHER invalid ELF padding field value attempt (more info ...)trojan-activity 2012-1439   
30993FILE-OTHER invalid ELF padding field value attempt (more info ...)trojan-activity 2012-1439   
30994INDICATOR-COMPROMISE possible TAR file oversize length field (more info ...)trojan-activity 2012-1457   
30995INDICATOR-COMPROMISE possible TAR file oversize length field (more info ...)trojan-activity 2012-1457   
31002MALWARE-CNC Win.Trojan.Kimsuky variant outbound connection (more info ...)trojan-activity    URL
31004MALWARE-CNC Win.Trojan.Nethief information disclosure attempt (more info ...)trojan-activity    URL
31005MALWARE-CNC Win.Trojan.Nethief information disclosure attempt (more info ...)trojan-activity    URL
31006MALWARE-CNC Win.Trojan.Nethief initial outbound connection (more info ...)trojan-activity    URL
31007MALWARE-CNC Win.Trojan.Iplorko.A runtime detection (more info ...)trojan-activity    URL
31010MALWARE-CNC Win.Trojan.Sisbot variant outbound IRC connection (more info ...)trojan-activity    URL
31014MALWARE-CNC Win.Trojan.Cryptowall variant outbound connection (more info ...)trojan-activity    
31020MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
31033MALWARE-CNC Win.Trojan.Cryptodefence variant outbound connection (more info ...)trojan-activity    URL
31036MALWARE-CNC Win.Trojan.SpyBanker variant outbound connection (more info ...)trojan-activity    URL
31037PROTOCOL-SCADA Yokogawa CS3000 BKESimmgr.exe buffer overflow attempt (more info ...)attempted-user 2014-0782   URL
31045SERVER-OTHER Oracle Demantra arbitrary file retrieval with authentication bypass attempt (more info ...)attempted-user 2013-5880 64836  
31046EXPLOIT-KIT Angler exploit kit outbound URL structure (more info ...)trojan-activity    
31047SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 99999 (more info ...)misc-activity    
31048PUA-ADWARE Win.Adware.PCSpeedUp variant outbound connection (more info ...)policy-violation    URL
31051MALWARE-CNC Win.Trojan.Hesperbot variant outbound connection (more info ...)trojan-activity    URL
31052PUA-ADWARE Win.Adware.Kdupd variant outbound connection (more info ...)policy-violation    URL
31053MALWARE-CNC Win.Trojan.MadnessPro outbound connection (more info ...)trojan-activity    URL
31055MALWARE-CNC Win.Trojan.Banload variant outbound connection (more info ...)trojan-activity    URL
31056PROTOCOL-SNMP Motorola Netopia 3347 series WEP key enumeration attempt (more info ...)attempted-recon    URL
31057PROTOCOL-SNMP Motorola Netopia 3347 series WPA key enumeration attempt (more info ...)attempted-recon    URL
31058PROTOCOL-SNMP Brocade snAgentUserAccntName enumeration attempt (more info ...)attempted-recon    URL
31062MALWARE-CNC Win.Trojan.Expone variant outbound connection (more info ...)trojan-activity    URL
31064MALWARE-CNC Win.Trojan.Diatraha variant outbound connection (more info ...)trojan-activity    URL
31066MALWARE-CNC Win.Trojan.Tobinload variant outbound connection (more info ...)trojan-activity    URL
31068SERVER-OTHER F5 BIG-IP iControl API hostname command injection attempt (more info ...)attempted-admin 2014-2928 67278  URL
31070MALWARE-CNC Win.Rootkit.Necurs outbound connection (more info ...)trojan-activity    URL
31072MALWARE-CNC Win.Trojan.Cryfile variant outbound connection (more info ...)trojan-activity    URL
31073MALWARE-CNC RemoteSpy connection to CNC server (more info ...)trojan-activity    URL
31074PUA-TOOLBARS AVG anti-virus toolbar download attempt - download-toolbar.avg.com (more info ...)misc-activity    URL
31075PUA-TOOLBARS AVG anti-virus toolbar download attempt - mmi.explabs.net (more info ...)misc-activity    URL
31076PUA-TOOLBARS Babylon toolbar download attempt - stat.info-stream.net (more info ...)misc-activity    URL
31079MALWARE-CNC Win.Trojan.Alurewo outbound connection (more info ...)trojan-activity    URL
31080MALWARE-CNC Win.Trojan.Alurewo outbound connection (more info ...)trojan-activity    URL
31083MALWARE-CNC Win.Trojan.Bexelets variant outbound connection (more info ...)trojan-activity    URL
31084MALWARE-CNC Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity    URL
31085FILE-OTHER Autodesk AutoCAD insecure acad.fas file load attempt (more info ...)attempted-user 2014-0818 65745  
31086FILE-OTHER Autodesk AutoCAD insecure acad.fas file load attempt (more info ...)attempted-user 2014-0818 65745  
31087FILE-OTHER Sophos RAR virtual machine filters memory corruption attempt (more info ...)attempted-user    URL
31088FILE-OTHER Sophos RAR virtual machine filters memory corruption attempt (more info ...)attempted-user    URL
31090MALWARE-CNC User-Agent known malicious user agent - User-Agent hello crazyk (more info ...)trojan-activity    URL
31095PROTOCOL-SNMP Ubee DDW3611 series WEP key enumeration attempt (more info ...)attempted-recon    
31096PROTOCOL-SNMP Ubee DDW3611 series WPA key enumeration attempt (more info ...)attempted-recon    
31098PROTOCOL-SNMP Ubee U10C019 series WEP key enumeration attempt (more info ...)attempted-recon    
31099PROTOCOL-SNMP Ubee U10C019 series WPA key enumeration attempt (more info ...)attempted-recon    
31101SERVER-OTHER Sharetronix cross site request forgery attempt (more info ...)attempted-admin 2014-3414 67681  
31102SERVER-OTHER TrendMicro InterScan Viruswall directory traversal attempt (more info ...)misc-activity 2004-1859   URL
31113MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
31114MALWARE-CNC Win.Trojan.Rfusclient outbound connection (more info ...)trojan-activity    URL
31116MALWARE-CNC Win.Trojan.Garsuni variant outbound connection (more info ...)trojan-activity    URL
31119MALWARE-CNC Win.Trojan.Marmoolak variant outbound connection (more info ...)trojan-activity    URL
31121MALWARE-CNC Win.Trojan.Cahecon outbound connection (more info ...)trojan-activity    URL
31122MALWARE-CNC User-Agent known malicious user agent - User-Agent svchost (more info ...)trojan-activity    URL
31124MALWARE-CNC Win.Trojan.Pyrtomsop outbound connection (more info ...)trojan-activity    URL
31130EXPLOIT-KIT Angler exploit kit encrypted binary download (more info ...)trojan-activity    
31131MALWARE-CNC Win.Trojan.Petun variant outbound connection (more info ...)trojan-activity    URL
31132MALWARE-CNC Win.Trojan.Petun variant outbound connection (more info ...)trojan-activity    URL
31135MALWARE-CNC Win.Trojan.Deedevil variant outbound connection (more info ...)trojan-activity    URL
31136MALWARE-CNC Win.Trojan.ZeroAccess inbound connection (more info ...)trojan-activity    URL
31142MALWARE-CNC Win.Trojan.Sloft variant outbound connection (more info ...)trojan-activity    URL
31143SERVER-WEBAPP CA ERwin Web Portal ConfigServiceProvider directory traversal attempt (more info ...)attempted-admin 2014-2210 66644  URL
31144MALWARE-CNC Win.Trojan.Spyrat variant inbound backdoor keep-alive (more info ...)trojan-activity    URL
31145MALWARE-CNC Win.Trojan.Spyrat variant outbound backdoor response (more info ...)trojan-activity    URL
31147MALWARE-CNC Win.Trojan.Zadnilay variant outbound connection (more info ...)trojan-activity    URL
31157SERVER-WEBAPP Cogent DataHub getpermissions.asp command injection attempt (more info ...)attempted-admin 2014-3789 67486  
31158SERVER-WEBAPP Cogent DataHub getpermissions.asp command injection attempt (more info ...)attempted-admin 2014-3789 67486  
31159SERVER-WEBAPP Cogent DataHub getpermissions.asp command injection attempt (more info ...)attempted-admin 2014-3789 67486  
31160SERVER-WEBAPP Cogent DataHub getpermissions.asp command injection attempt (more info ...)attempted-admin 2014-3789 67486  
31162SERVER-OTHER Beetel 450TC2 CSRF attempt (more info ...)attempted-admin 2014-3792 67169  
31166PUA-ADWARE InstallRex bundled installer outbound activity (more info ...)misc-activity    URL
31167PUA-ADWARE InstallRex bundled installer outbound activity (more info ...)misc-activity    URL
31168MALWARE-CNC Win.Trojan.Guise outbound connection (more info ...)trojan-activity    URL
31171MALWARE-CNC Win.Trojan.Scarpnex variant outbound connection (more info ...)trojan-activity    URL
31172MALWARE-CNC Win.Trojan.Scarpnex variant outbound connection (more info ...)trojan-activity    URL
31173MALWARE-CNC Win.Trojan.Scarpnex variant outbound connection (more info ...)trojan-activity    URL
31174MALWARE-CNC Win.Trojan.Sapart variant outbound connection (more info ...)trojan-activity    URL
31176SERVER-OTHER GnuTLS Server Hello Session ID heap overflow attempt (more info ...)attempted-user 2014-3466 67741  URL
31177SERVER-OTHER GnuTLS Server Hello Session ID heap overflow attempt (more info ...)attempted-user 2014-3466 67741  URL
31178SERVER-OTHER GnuTLS Server Hello Session ID heap overflow attempt (more info ...)attempted-user 2014-3466 67741  URL
31179SERVER-OTHER GnuTLS Server Hello Session ID heap overflow attempt (more info ...)attempted-user 2014-3466 67741  URL
31180SERVER-OTHER OpenSSL DTLS handshake recursion denial of service attempt (more info ...)attempted-dos 2014-0221   URL
31181SERVER-OTHER OpenSSL DTLS handshake recursion denial of service attempt (more info ...)attempted-dos 2014-0221   URL
31183MALWARE-CNC Win.Trojan.Bankeiya outbound connection (more info ...)trojan-activity    URL
31212INDICATOR-COMPROMISE http GET request smuggling attempt (more info ...)misc-attack 2014-0099   
31213INDICATOR-COMPROMISE http POST request smuggling attempt (more info ...)misc-attack 2014-0099   
31218MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    
31221MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
31222MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
31223MALWARE-CNC Win.Trojan.CryptoWall variant outbound connection (more info ...)trojan-activity    URL
31224MALWARE-CNC Win.Trojan.Cryptor outbound connection (more info ...)trojan-activity    URL
31225MALWARE-CNC User-Agent known malicious User-Agent rome0321 - Win.Trojan.Soraya (more info ...)trojan-activity    URL
31228MALWARE-CNC Win.Trojan.Soraya variant initial outbound connection (more info ...)trojan-activity    URL
31234MALWARE-CNC Win.Trojan.Nuckam variant inbound connection (more info ...)trojan-activity    URL
31235MALWARE-CNC Win.Trojan.Nuckam variant outbound connection (more info ...)trojan-activity    URL
31236MALWARE-CNC Win.Trojan.Hidead outbound connection (more info ...)trojan-activity    URL
31237EXPLOIT-KIT Nuclear exploit kit outbound swf request (more info ...)trojan-activity    
31240MALWARE-CNC Win.Trojan.Dosoloid variant outbound connection (more info ...)trojan-activity    URL
31241MALWARE-CNC Win.Trojan.Dosoloid variant outbound connection (more info ...)trojan-activity    URL
31242MALWARE-CNC Win.Trojan.Utishaf variant outbound connection (more info ...)trojan-activity    URL
31243MALWARE-CNC Win.Trojan.Necurs variant outbound connection (more info ...)trojan-activity    URL
31244MALWARE-CNC Win.Trojan.Kuluoz outbound connection (more info ...)trojan-activity    URL
31254MALWARE-CNC Win.Trojan.HAVEX-RAT inbound connection to infected host (more info ...)trojan-activity    URL
31255MALWARE-CNC Win.Trojan.HAVEX-RAT variant outbound connection (more info ...)trojan-activity    URL
31258MALWARE-CNC Win.Trojan.Destoplug variant outbound connection (more info ...)trojan-activity    URL
31260MALWARE-CNC Win.Trojan.Andromeda HTTP proxy response attempt (more info ...)trojan-activity    URL
31261MALWARE-CNC Win.Trojan.Symmi outbound connection (more info ...)trojan-activity    URL
31262MALWARE-CNC Win.Worm.VBNA variant outbound connection (more info ...)trojan-activity    URL
31271MALWARE-CNC Win.Trojan.Vectecoin information disclosure attempt (more info ...)trojan-activity    URL
31272MALWARE-CNC Win.Trojan.Vectecoin outbound command request attempt (more info ...)trojan-activity    URL
31273MALWARE-CNC Win.Trojan.Vectecoin coin mining program download attempt (more info ...)trojan-activity    URL
31288MALWARE-CNC Win.Downloader.Bladabindi variant outbound download request (more info ...)trojan-activity    URL
31289SERVER-WEBAPP /etc/passwd file access attempt (more info ...)attempted-admin    URL
31290MALWARE-CNC Win.Trojan.Vextstl outbound connection (more info ...)trojan-activity    URL
31295MALWARE-CNC Win.Trojan.Zusy variant outbound connection (more info ...)trojan-activity    URL
31297SERVER-WEBAPP VMWare vSphere API SOAP request RetrieveProperties remote denial of service attempt (more info ...)attempted-dos 2012-5703 56571  URL
31299MALWARE-CNC Win.Trojan.Necurs or Win.Trojan.Locky variant outbound detection (more info ...)trojan-activity    
31303MALWARE-CNC Win.Trojan.Hadeki variant outbound connection (more info ...)trojan-activity    URL
31304SERVER-WEBAPP PocketPAD brute-force login attempt (more info ...)suspicious-login    
31306MALWARE-CNC Win.Trojan.Toumlec variant outbound connection (more info ...)trojan-activity    URL
31307MALWARE-CNC Win.Trojan.Toumlec variant outbound connection (more info ...)trojan-activity    URL
31314MALWARE-CNC Win.Trojan.Daikou variant outbound connection (more info ...)trojan-activity    URL
31315MALWARE-CNC Win.Trojan.MSIL variant outbound connection (more info ...)trojan-activity    URL
31316MALWARE-CNC Win.Trojan.Matsnu variant outbound connection (more info ...)trojan-activity    URL
31317MALWARE-CNC Win.Trojan.Orbot variant outbound connection (more info ...)trojan-activity    URL
31319MALWARE-CNC Win.Trojan.Zediv outbound connection (more info ...)trojan-activity    URL
31323FILE-OTHER Apple OSX Finder DMG volume name memory corruption attempt (more info ...)attempted-user 2007-0197   
31324FILE-OTHER Apple OSX Finder DMG volume name memory corruption attempt (more info ...)attempted-user 2007-0197   
31325FILE-OTHER Apple OSX Finder DMG volume name memory corruption attempt (more info ...)attempted-user 2007-0197   
31328MALWARE-CNC Win.Trojan.Rofin variant outbound connection (more info ...)trojan-activity    URL
31331EXPLOIT-KIT Angler exploit kit encrypted binary download (more info ...)trojan-activity    
31332EXPLOIT-KIT Angler exploit kit outbound URL structure (more info ...)trojan-activity    
31338SERVER-OTHER OpenAFS GetStatistics buffer overflow attempt (more info ...)denial-of-service 2014-0159 66776  
31343MALWARE-CNC Win.Trojan.Mecklow variant outbound connection system information disclosure (more info ...)trojan-activity    URL
31344MALWARE-CNC Win.Trojan.Levyatan variant outbound connection (more info ...)trojan-activity    URL
31345MALWARE-CNC Win.Trojan.Mcdravsm variant outbound connection (more info ...)trojan-activity    URL
31346MALWARE-CNC Win.Trojan.Ajtonj variant outbound connection (more info ...)trojan-activity    URL
31355MALWARE-CNC Win.Trojan.Bicololo outbound connection (more info ...)trojan-activity    URL
31359MALWARE-CNC Win.Trojan.Httneilc variant outbound connection (more info ...)trojan-activity    URL
31371EXPLOIT-KIT Angler exploit kit outbound URL structure (more info ...)trojan-activity    
31406SERVER-OTHER Samsung TV denial of service attempt (more info ...)attempted-dos 2013-4890   
31417MALWARE-CNC User-Agent known malicious user-agent blacksun - Win.Trojan.Blacksun (more info ...)trojan-activity    URL
31418MALWARE-CNC Win.Trojan.Subla variant outbound connection (more info ...)trojan-activity    URL
31422MALWARE-CNC User-Agent known malicious user-agent string Cactus (more info ...)trojan-activity    URL
31424MALWARE-CNC Kegis.A outbound connection (more info ...)trojan-activity    URL
31433MALWARE-CNC MSIL Worm command and control connection (more info ...)suspicious-login    URL
31442MALWARE-CNC Win.Trojan.Injector variant outbound connection (more info ...)trojan-activity    URL
31449MALWARE-CNC Win.Trojan.CryptoWall downloader attempt (more info ...)trojan-activity    URL
31450MALWARE-CNC Win.Trojan.CryptoWall outbound connection (more info ...)trojan-activity    URL
31452MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
31453MALWARE-CNC Win.Trojan.ChoHeap variant outbound connection (more info ...)trojan-activity    URL
31454MALWARE-CNC Win.Trojan.ChoHeap variant outbound connection (more info ...)trojan-activity    URL
31455EXPLOIT-KIT Rig Exploit Kit Outbound DGA Request (more info ...)trojan-activity    URL
31458MALWARE-CNC Win.Trojan.SDBot variant outbound connection (more info ...)trojan-activity    URL
31459MALWARE-CNC Win.Trojan.Jaktinier outbound connection (more info ...)trojan-activity    URL
31465MALWARE-CNC Win.Trojan.Androm Click Fraud Request (more info ...)trojan-activity    URL
31466MALWARE-CNC Win.Trojan.Androm Click Fraud Request (more info ...)trojan-activity    URL
31467MALWARE-CNC Win.Trojan.Androm variant outbound connection (more info ...)trojan-activity    URL
31468MALWARE-CNC Win.Trojan.Papras variant outbound connection (more info ...)trojan-activity    URL
31477SERVER-OTHER OpenSSL SSL ChangeCipherSpec man-in-the-middle exploitation attempt (more info ...)attempted-dos 2014-0224 67899  URL
31478SERVER-OTHER OpenSSL TLSv1.0 ChangeCipherSpec man-in-the-middle exploitation attempt (more info ...)attempted-dos 2014-0224 67899  URL
31479SERVER-OTHER OpenSSL TLSv1.1 ChangeCipherSpec man-in-the-middle exploitation attempt (more info ...)attempted-dos 2014-0224 67899  URL
31480SERVER-OTHER OpenSSL TLSv1.2 ChangeCipherSpec man-in-the-middle exploitation attempt (more info ...)attempted-dos 2014-0224 67899  URL
31481SERVER-OTHER OpenSSL SSL ChangeCipherSpec man-in-the-middle exploitation attempt (more info ...)attempted-dos 2014-0224 67899  URL
31482SERVER-OTHER OpenSSL TLSv1.0 ChangeCipherSpec man-in-the-middle exploitation attempt (more info ...)attempted-dos 2014-0224 67899  URL
31483SERVER-OTHER OpenSSL TLSv1.1 ChangeCipherSpec man-in-the-middle exploitation attempt (more info ...)attempted-dos 2014-0224 67899  URL
31484SERVER-OTHER OpenSSL TLSv1.2 ChangeCipherSpec man-in-the-middle exploitation attempt (more info ...)attempted-dos 2014-0224 67899  URL
31497SERVER-WEBAPP Oracle Event Processing FileUploadServlet directory traversal attempt (more info ...)attempted-admin 2014-2424 66871  URL
31498SERVER-WEBAPP Oracle Event Processing FileUploadServlet directory traversal attempt (more info ...)attempted-admin 2014-2424 66871  URL
31507MALWARE-CNC Win.Trojan.HW32 variant spam attempt (more info ...)trojan-activity    URL
31513BROWSER-FIREFOX Multiple browser pressure function denial of service attempt (more info ...)denial-of-service 2014-1512   
31530MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
31532APP-DETECT Xolominer outbound connection attempt (more info ...)policy-violation    URL
31533MALWARE-CNC Win.Trojan.Xolominer malicious user detected (more info ...)trojan-activity    URL
31543MALWARE-CNC User-Agent known malicious user-agent string - MSIE 7.0 na - Win.Trojan.Koobface (more info ...)trojan-activity    URL
31544MALWARE-CNC Win.Trojan.Koobface variant outbound connection (more info ...)trojan-activity    URL
31545MALWARE-CNC Win.Trojan.Koobface variant outbound connection (more info ...)trojan-activity    URL
31547MALWARE-CNC Win.Trojan.Yakes variant inbound connection (more info ...)trojan-activity    URL
31548MALWARE-CNC Win.Trojan.Yakes variant inbound connection (more info ...)trojan-activity    URL
31563MALWARE-CNC Backdoor Elirks.A command and control traffic (more info ...)trojan-activity    URL
31567SERVER-WEBAPP Gitlist remote command injection attempt (more info ...)attempted-admin 2014-4511 68888  
31568SERVER-WEBAPP Invsionix Roaming System remote file include attempt (more info ...)web-application-attack 2006-4237   
31571FILE-IMAGE GIMP XWD BlueMask file-handling stack buffer overflow attempt (more info ...)attempted-user 2012-5576 56647  
31572FILE-IMAGE GIMP XWD GreenMask file-handling stack buffer overflow attempt (more info ...)attempted-user 2012-5576 56647  
31573FILE-IMAGE GIMP XWD RedMask file-handling stack buffer overflow attempt (more info ...)attempted-user 2012-5576 56647  
31574FILE-IMAGE GIMP XWD BlueMask file-handling stack buffer overflow attempt (more info ...)attempted-user 2012-5576 56647  
31575FILE-IMAGE GIMP XWD GreenMask file-handling stack buffer overflow attempt (more info ...)attempted-user 2012-5576 56647  
31576FILE-IMAGE GIMP XWD RedMask file-handling stack buffer overflow attempt (more info ...)attempted-user 2012-5576 56647  
31586MALWARE-CNC Win.Trojan.Backoff initial outbound connection (more info ...)trojan-activity    URL
31593MALWARE-CNC Andr.Trojan.SMSSend outbound connection (more info ...)trojan-activity    URL
31603MALWARE-CNC Win.Trojan.Glupteba C&C server HELLO request to client (more info ...)trojan-activity    URL
31604MALWARE-CNC Win.Trojan.Glupteba C&C server READD command to client (more info ...)trojan-activity    URL
31605MALWARE-CNC Win.Trojan.Glupteba C&C server READY command to client (more info ...)trojan-activity    URL
31606MALWARE-CNC Win.Trojan.Glupteba payload download request (more info ...)trojan-activity    URL
31607MALWARE-CNC Win.Trojan.Glupteba client response/authenticate to C&C server (more info ...)trojan-activity    URL
31633MALWARE-CNC Noniem.A outbound connection (more info ...)trojan-activity    URL
31637SERVER-WEBAPP Ad Fundum Integrateable News Script remote include path attempt (more info ...)web-application-attack 2007-0570 22259  
31641MALWARE-CNC Win.Tinybanker variant outbound connection (more info ...)trojan-activity    URL
31642MALWARE-CNC Win.Tinybanker variant outbound connection (more info ...)trojan-activity    URL
31644MALWARE-CNC Andr.Trojan.Scarelocker outbound connection (more info ...)trojan-activity    URL
31647SERVER-WEBAPP AVM FritzBox webcm command injection attempt (more info ...)attempted-admin  65520  
31648SERVER-WEBAPP AVM FritzBox webcm command injection attempt (more info ...)attempted-admin  65520  
31649MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
31669MALWARE-CNC Win.Trojan.Dexter variant outbound connection (more info ...)trojan-activity    URL
31670FILE-OTHER Symantec Endpoint Protection Sysplant kernel pool overflow exploit attempt (more info ...)attempted-user 2014-3434 68946  
31671FILE-OTHER Symantec Endpoint Protection Sysplant kernel pool overflow exploit attempt (more info ...)attempted-user 2014-3434 68946  
31680MALWARE-CNC Win.Trojan.Tirabot variant outbound connection (more info ...)trojan-activity    URL
31681MALWARE-CNC Win.Trojan.Badur download attempt (more info ...)trojan-activity    URL
31682MALWARE-CNC Win.Trojan.Badur download attempt (more info ...)trojan-activity    URL
31683MALWARE-CNC Win.Trojan.Badur variant outbound connection (more info ...)trojan-activity    URL
31688MALWARE-CNC User-Agent known malicious user-agent string - Downloader 1.8 - Win.Trojan.Graftor (more info ...)trojan-activity    URL
31689MALWARE-CNC Win.Trojan.Graftor variant outbound connection (more info ...)trojan-activity    URL
31691MALWARE-CNC Win.Trojan.Kronos variant outbound connection (more info ...)trojan-activity    URL
31693MALWARE-CNC Win.Trojan.Korplug Poisoned Hurricane Malware outbound connection (more info ...)trojan-activity    URL
31694EXPLOIT-KIT Angler exploit kit encrypted binary download (more info ...)trojan-activity    
31695EXPLOIT-KIT Angler exploit kit encrypted binary download (more info ...)trojan-activity    
31696SERVER-WEBAPP Jira Issue Collector Plugin directory traversal attempt (more info ...)web-application-attack 2014-2314 65849  
31697SERVER-WEBAPP Jira Issue Collector Plugin directory traversal attempt (more info ...)web-application-attack 2014-2314 65849  
31698SERVER-WEBAPP Jira Issue Collector Plugin directory traversal attempt (more info ...)web-application-attack 2014-2314 65849  
31700EXPLOIT-KIT Hanjuan exploit kit landing page detection (more info ...)trojan-activity    URL
31704SERVER-OTHER FCKeditor textinputs cross site scripting attempt (more info ...)web-application-attack 2014-4037   
31706MALWARE-CNC Win.Trojan.Korgapam outbound connection (more info ...)trojan-activity    URL
31709SERVER-OTHER Cougar-LG configuration file access attempt (more info ...)attempted-recon 2014-3928   URL
31712MALWARE-CNC Win.Trojan.Ragua variant outbound connection (more info ...)trojan-activity    URL
31713MALWARE-CNC Win.Trojan.Ragua variant outbound connection (more info ...)trojan-activity    URL
31714MALWARE-CNC Win.Trojan.Ragua variant outbound connection (more info ...)trojan-activity    URL
31715MALWARE-CNC Win.Trojan.Ragua variant outbound connection (more info ...)trojan-activity    URL
31716MALWARE-CNC Win.Trojan.Otupsys variant outbound connection (more info ...)trojan-activity 2012-0158   URL
31718MALWARE-CNC Win.Trojan.Critroni outbound connection (more info ...)trojan-activity    URL
31722MALWARE-CNC Win.Trojan.Waski variant outbound connection (more info ...)trojan-activity    URL
31727SERVER-OTHER Cistron-LG configuration file access attempt (more info ...)attempted-recon 2014-3930   URL
31735MALWARE-CNC Win.Trojan.Upatre variant outbound connection (more info ...)trojan-activity    URL
31736MALWARE-CNC Win.Trojan.Upatre variant outbound connection (more info ...)trojan-activity    URL
31744MALWARE-CNC Win.Trojan.Eratoma outbound connection (more info ...)trojan-activity    URL
31745SERVER-WEBAPP vTiger CRM install module command injection attempt (more info ...)attempted-admin 2014-2268 66758  
31748MALWARE-CNC Win.Trojan.Qulkonwi outbound connection (more info ...)trojan-activity    URL
31753MALWARE-CNC Win.Trojan.Elpapok outbound connection (more info ...)trojan-activity    URL
31755MALWARE-CNC Win.Trojan.Miras variant outbound connection (more info ...)trojan-activity    URL
31766SERVER-OTHER Cougar-LG addr parameter XSS attempt (more info ...)misc-attack 2014-3926   URL
31767SERVER-OTHER MRLG fastping echo reply memory corruption attempt (more info ...)misc-attack 2014-3931   URL
31768MALWARE-CNC Win.Trojan.Ecsudown outbound connection (more info ...)trojan-activity    URL
31770EXPLOIT-KIT Sweet Orange exploit kit jquery_datepicker domain decode attempt (more info ...)trojan-activity    URL
31772MALWARE-CNC Win.Trojan.Cridex variant outbound connection (more info ...)trojan-activity    URL
31774FILE-IDENTIFY BitTorrent torrent file attachment detected (more info ...)misc-activity    URL
31775FILE-IDENTIFY BitTorrent torrent file attachment detected (more info ...)misc-activity    URL
31776FILE-IDENTIFY BitTorrent torrent file attachment detected (more info ...)misc-activity    URL
31777FILE-OTHER Free Download Manager .torrent parsing announce overflow attempt (more info ...)attempted-user 2009-0184 33555  
31778FILE-OTHER Free Download Manager .torrent parsing comment overflow attempt (more info ...)attempted-user 2009-0184 33555  
31779FILE-OTHER Free Download Manager .torrent parsing name overflow attempt (more info ...)attempted-user 2009-0184 33555  
31780FILE-OTHER Free Download Manager .torrent parsing path overflow attempt (more info ...)attempted-user 2009-0184 33555  
31805MALWARE-CNC Win.Trojan.Dizk variant outbound connection (more info ...)trojan-activity    URL
31806MALWARE-CNC Win.Trojan.Nighthunter data exfiltration attempt (more info ...)trojan-activity    URL
31807MALWARE-CNC Win.Trojan.Nighthunter data exfiltration attempt (more info ...)trojan-activity    URL
31813MALWARE-CNC Win.Trojan.Expiro outbound connection (more info ...)trojan-activity    URL
31818SERVER-WEBAPP ManageEngine DesktopCentral statusUpdate servlet directory traversal attempt (more info ...)web-application-attack 2014-5005 69494  
31820MALWARE-CNC Win.Banker.Delf variant outbound connection (more info ...)trojan-activity    URL
31824MALWARE-CNC Win.Trojan.Graftor variant outbound connection (more info ...)trojan-activity    URL
31826MALWARE-CNC Win.Trojan.Delf variant HTTP Response (more info ...)trojan-activity    URL
31827MALWARE-CNC Win.Trojan.Delf variant outbound connection (more info ...)trojan-activity    URL
31832MALWARE-CNC Win.Trojan.Pfinet outbound connection (more info ...)trojan-activity    URL
31833MALWARE-CNC Win.Trojan.Chkbot outbound connection (more info ...)trojan-activity    URL
31834MALWARE-CNC Win.Trojan-Downloader.Delorado variant outbound connection (more info ...)trojan-activity    URL
31835MALWARE-CNC Win.Trojan.Yesudac variant outbound connection (more info ...)trojan-activity    URL
31836MALWARE-CNC Win.Trojan.MSIL.Seribe variant outbound connection (more info ...)trojan-activity    URL
31837MALWARE-CNC Win.Trojan.Retgate variant outbound connection (more info ...)trojan-activity    URL
31838SERVER-WEBAPP ManageEngine Eventlog Analyzer directory traversal attempt (more info ...)web-application-attack 2014-6037 69482  
31851PROTOCOL-SNMP Arris DG950A 128 bit WEP key enumeration attempt (more info ...)attempted-recon 2014-4863 69631  
31852PROTOCOL-SNMP Arris DG950A 64 bit WEP key enumeration attempt (more info ...)attempted-recon 2014-4863 69631  
31853PROTOCOL-SNMP Arris DG950A WPA key enumeration attempt (more info ...)attempted-recon 2014-4863 69631  
31854PROTOCOL-SNMP Multiple Products 128 bit WEP key enumeration attempt (more info ...)attempted-recon 2014-4862 69630  
31855PROTOCOL-SNMP Multiple Products 64 bit WEP key enumeration attempt (more info ...)attempted-recon 2014-4862 69630  
31856PROTOCOL-SNMP Multiple Products WPA key enumeration attempt (more info ...)attempted-recon 2014-4862 69630  
31860SERVER-OTHER Apple CUPS web interface cross site scripting attempt (more info ...)web-application-attack 2015-1159 75106  URL
31883MALWARE-CNC Win.Trojan.Waterspout outbound connection (more info ...)trojan-activity    URL
31885MALWARE-CNC Win.Trojan.Threebyte variant outbound connection (more info ...)trojan-activity    URL
31889SERVER-MAIL Exim Dovecot LDA sender_address command injection attempt (more info ...)attempted-user    
31890SERVER-MAIL Exim Dovecot LDA sender_address command injection attempt (more info ...)attempted-user    
31895MALWARE-CNC Win.Trojan.Toupi variant outbound connection (more info ...)trojan-activity    URL
31896MALWARE-CNC Win.Trojan.Magnetor vairant outbound connection (more info ...)trojan-activity    URL
31897MALWARE-CNC Win.Trojan.Dexter variant outbound connection (more info ...)trojan-activity    URL
31904MALWARE-CNC Win.Trojan.Banload variant outbound connection (more info ...)trojan-activity    URL
31907MALWARE-CNC Win.Trojan.MSIL.Honerep variant outbound connection (more info ...)trojan-activity    URL
31909MALWARE-CNC Win.Trojan.Basostab variant outbound connection (more info ...)trojan-activity    URL
31911MALWARE-CNC Win.Trojan.MSIL.Gareme variant outbound connection (more info ...)trojan-activity    URL
31912SERVER-WEBAPP cPanel 9.01 multiple URI parameters cross site scripting attempt (more info ...)web-application-attack 2004-1875   
31913MALWARE-CNC Win.Trojan.Maozhi variant outbound connection (more info ...)trojan-activity    URL
31915MALWARE-CNC WIN.Trojan.Ziyazo variant outbound connection (more info ...)trojan-activity    URL
31916MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
31923MALWARE-CNC Win.Trojan.Symmi variant HTTP response attempt (more info ...)trojan-activity    URL
31924MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
31928MALWARE-CNC Win.Trojan-Downloader.Becontr variant outbound connection (more info ...)trojan-activity    URL
31929MALWARE-CNC Win.Trojan.Kanav variant outbound connection (more info ...)trojan-activity    URL
31930MALWARE-CNC Win.Trojan.Kanav variant outbound connection (more info ...)trojan-activity    URL
31941MALWARE-CNC Win.Trojan-Downloader.Pedrp variant outbound connection (more info ...)trojan-activity    URL
31944MALWARE-CNC Win.Trojan.Tavdig outbound connection (more info ...)trojan-activity    URL
31947MALWARE-CNC User-Agent known malicious user-agent string - HttpCall - Win.Trojan.Rukypee (more info ...)trojan-activity    URL
31948MALWARE-CNC User-Agent known malicious user-agent string - MyProgramm - Win.Trojan.Rukypee (more info ...)trojan-activity    URL
31954MALWARE-CNC Win.Trojan.Ezbro variant outbound connection (more info ...)trojan-activity    URL
31955MALWARE-CNC Win.Trojan.Ezbro variant outbound connection (more info ...)trojan-activity    URL
31956SERVER-WEBAPP Rejetto HttpFileServer command injection attempt (more info ...)web-application-attack 2014-6287 69782  
31957MALWARE-CNC Win.Backdoor.MSIL.Torct variant outbound connection (more info ...)trojan-activity    URL
31964MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
31965EXPLOIT-KIT Astrum exploit kit landing page (more info ...)trojan-activity    URL
31970EXPLOIT-KIT Astrum exploit kit redirection attempt (more info ...)trojan-activity    URL
31971EXPLOIT-KIT Astrum exploit kit multiple exploit download request (more info ...)trojan-activity    URL
31973MALWARE-CNC Win.Trojan.Chebri variant outbound connection (more info ...)trojan-activity    URL
31974MALWARE-CNC Win.Trojan.Zegorg variant outbound connection (more info ...)trojan-activity    URL
31990MALWARE-CNC User-Agent known malicious user-agent string - Install - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
31991MALWARE-CNC User-Agent known malicious user-agent string - Treck - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
31992MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
31993MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
31994MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
31995MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
31996MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
31997MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
31998MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
31999MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
32000MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
32001MALWARE-CNC Win.Backdoor.Upatre SSL Cert inbound (more info ...)trojan-activity    URL
32002MALWARE-CNC Win.Worm.Zorenium variant outbound connection (more info ...)trojan-activity    URL
32003SERVER-WEBAPP Drupal xmlrp internal entity expansion denial of service attempt (more info ...)attempted-dos 2014-5265   URL
32004SERVER-WEBAPP Drupal xmlrp internal entity expansion denial of service attempt (more info ...)attempted-dos 2014-5265   URL
32012MALWARE-CNC Win.Trojan-Downloader.Bipamid variant outbound connection (more info ...)trojan-activity    URL
32015MALWARE-CNC Win.Backdoor.Zeus variant outbound connection (more info ...)trojan-activity    URL
32016MALWARE-CNC Win.Trojan.MSIL.Menteni variant outbound connection (more info ...)trojan-activity    URL
32017MALWARE-CNC Win.Trojan.Memlog SMB file transfer (more info ...)trojan-activity    URL
32018MALWARE-CNC Win.Backdoor.Hupigon.NYK variant outbound connection (more info ...)trojan-activity    URL
32020MALWARE-CNC Win.Backdoor.Krompt variant outbound connection (more info ...)trojan-activity    URL
32023MALWARE-CNC Win.Trojan.Sinpid variant outbound connection (more info ...)trojan-activity    URL
32028MALWARE-CNC Win.Backdoor.Klabcon variant outbound connection (more info ...)trojan-activity    URL
32029BROWSER-OTHER Android WebView same origin policy bypass attempt (more info ...)misc-activity 2014-6041 69548  
32030MALWARE-CNC User-Agent known malicious user-agent string Decibal - Win.Trojan.Decibal (more info ...)trojan-activity    URL
32031MALWARE-CNC Win.Trojan.Decibal variant outbound connection (more info ...)trojan-activity    URL
32033MALWARE-CNC Win.Trojan.Larosden variant outbound connection (more info ...)trojan-activity    URL
32034MALWARE-CNC Win.Trojan.Larefervt variant outbound connection (more info ...)trojan-activity    URL
32035MALWARE-CNC Win.Trojan.Boleteiro variant outbound connection (more info ...)trojan-activity    URL
32036MALWARE-CNC Win.Trojan.Somoca vaniant outbound connection (more info ...)trojan-activity    URL
32037MALWARE-CNC Win.Trojan.Banload.awt variant outbound connection (more info ...)trojan-activity    URL
32044SERVER-WEBAPP ManageEngine Eventlog Analyzer directory traversal attempt (more info ...)web-application-attack 2014-6037 69482  
32048MALWARE-CNC Win.Trojan.Lecpetex variant outbound connection (more info ...)trojan-activity    URL
32050MALWARE-CNC Win.Trojan.MSIL.Larosden variant outbound connection (more info ...)trojan-activity    URL
32052MALWARE-CNC User-Agent Xsser mRAT user-agent (more info ...)trojan-activity    URL
32053MALWARE-CNC Xsser mRAT GPS data upload (more info ...)trojan-activity    URL
32054MALWARE-CNC Xsser mRAT file upload (more info ...)trojan-activity    URL
32057SERVER-WEBAPP ManageEngine multipartRequest servlet directory traversal attempt (more info ...)attempted-admin 2014-6036 70172  URL
32058MALWARE-CNC Win.Backdoor.Masatekar variant outbound connection (more info ...)trojan-activity    URL
32060MALWARE-CNC User-Agent known malicious user agent string - httptestman - Win.Backdoor.Rabasheeta (more info ...)trojan-activity    URL
32061MALWARE-CNC Win.Trojan-Downloader.Nekill variant outbound connection (more info ...)trojan-activity    URL
32065MALWARE-CNC Win.Trojan.Asprox inbound connection (more info ...)trojan-activity    URL
32066MALWARE-CNC Win.Trojan.Asprox outbound connection (more info ...)trojan-activity    URL
32067MALWARE-CNC Win.Trojan.Asprox outbound connection (more info ...)trojan-activity    URL
32068POLICY-OTHER SolarWinds Log and Event Manager default credentials authentication attempt (more info ...)policy-violation 2014-5504 69559  URL
32070MALWARE-CNC Win.Trojan.Dalgan variant outbound connection (more info ...)trojan-activity    URL
32071MALWARE-CNC Win.Backdoor.Zapchast variant outbound connection (more info ...)trojan-activity    URL
32072MALWARE-CNC Win.Trojan.Zemot configuration download attempt (more info ...)trojan-activity    URL
32073MALWARE-CNC Win.Trojan.Zemot outbound connection (more info ...)trojan-activity    URL
32074MALWARE-CNC Win.Trojan.Zemot payload download attempt (more info ...)trojan-activity    URL
32075MALWARE-CNC Win.Trojan.Small variant outbound connection (more info ...)trojan-activity    URL
32076SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 directory traversal attempt (more info ...)attempted-admin 2014-5160 68856  
32086MALWARE-CNC Win.Backdoor.Corkow variant outbound connection (more info ...)trojan-activity    URL
32087FILE-OTHER GNU tar PAX extended headers handling overflow attempt (more info ...)attempted-dos 2006-0300 16764  
32088FILE-OTHER GNU tar PAX extended headers handling overflow attempt (more info ...)attempted-dos 2006-0300 16764  
32089FILE-OTHER GNU tar PAX extended headers handling overflow attempt (more info ...)attempted-dos 2006-0300 16764  
32090MALWARE-CNC Win.Trojan.Saaglup variant outbound connection (more info ...)trojan-activity    URL
32091MALWARE-CNC Win.Backdoor.PcertStealer variant outbound connection (more info ...)trojan-activity    URL
32092POLICY-OTHER ManageEngine DeviceExpert user credentials enumeration attempt (more info ...)policy-violation 2014-5377 69443  
32093MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
32096MALWARE-CNC Win.Trojan.Puver variant outbound connection (more info ...)trojan-activity    URL
32109SERVER-WEBAPP Easy File Management stack buffer overflow attempt (more info ...)attempted-admin  67542  
32117PUA-ADWARE MplayerX malvertising browser hijacker (more info ...)misc-activity    URL
32118PUA-ADWARE MplayerX malvertising connectivity check (more info ...)misc-activity    URL
32119PUA-ADWARE Vsearch installer User-Agent (more info ...)misc-activity    URL
32120PUA-ADWARE Vsearch installer request (more info ...)misc-activity    URL
32121MALWARE-CNC Win.Trojan.Kryptik variant outbound connection (more info ...)trojan-activity    URL
32123MALWARE-CNC Win.Trojan.Zbot variant outbound connection (more info ...)trojan-activity    URL
32125MALWARE-CNC User-Agent known malicious user-agent string - update - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
32126MALWARE-CNC Win.Trojan.Lizarbot outbound connection (more info ...)trojan-activity    URL
32129MALWARE-CNC Win.Trojan.Downloader variant outbound connection (more info ...)trojan-activity    URL
32130MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
32134FILE-IDENTIFY XBM file attachment detected (more info ...)misc-activity    URL
32135FILE-IDENTIFY XBM file attachment detected (more info ...)misc-activity    URL
32136FILE-OTHER GNU gzip LZH decompression make_table overflow attempt (more info ...)attempted-user 2006-4335   URL
32172MALWARE-CNC Win.Trojan.BlackPOS stolen data transfer to internal staging area (more info ...)trojan-activity    URL
32175MALWARE-CNC Osx.Backdoor.iWorm variant outbound connection (more info ...)trojan-activity    URL
32179MALWARE-CNC WIN.Trojan.Plugx variant outbound connection (more info ...)trojan-activity    URL
32180MALWARE-CNC Win.Backdoor.ZxShell connection incoming attempt (more info ...)trojan-activity    URL
32181MALWARE-CNC Win.Backdoor.ZxShell connection outgoing attempt (more info ...)trojan-activity    URL
32188MALWARE-CNC Win.Trojan.BlackEnergy3 outbound connection (more info ...)trojan-activity    URL
32189MALWARE-CNC Win.Trojan.BlackEnergy2 outbound connection (more info ...)trojan-activity    URL
32192MALWARE-CNC Win.Trojan.Zxshell variant outbound connection (more info ...)trojan-activity    URL
32193MALWARE-CNC Win.Trojan.Dubrute variant outbound connection (more info ...)trojan-activity    URL
32194MALWARE-CNC Win.Trojan.Dubrute variant outbound connection (more info ...)trojan-activity    URL
32195MALWARE-CNC Win.Trojan.Palebot variant outbound connection (more info ...)trojan-activity    URL
32196MALWARE-CNC Win.Trojan.Graftor variant outbound connection (more info ...)trojan-activity    URL
32197MALWARE-CNC Win.Trojan.Zerolocker variant outbound connection (more info ...)trojan-activity    URL
32198MALWARE-CNC Win.Trojan.Mujormel outbound connection (more info ...)trojan-activity    URL
32199SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 directory traversal attempt (more info ...)attempted-admin 2014-5160 68855  
32202MALWARE-CNC Win.Trojan.Soaphrish variant outbound connection (more info ...)trojan-activity    URL
32204SERVER-OTHER SSLv3 POODLE CBC padding brute force attempt (more info ...)attempted-recon 2014-3568   URL
32205SERVER-OTHER SSLv3 POODLE CBC padding brute force attempt (more info ...)attempted-recon 2014-3568   URL
32220MALWARE-CNC Win.Trojan.Kazy download detected (more info ...)trojan-activity    URL
32221MALWARE-CNC Win.Trojan.Kazy download detected (more info ...)trojan-activity    URL
32222MALWARE-CNC Win.Backdoor.MSIL.Liroospu variant outbound connection (more info ...)trojan-activity    URL
32223SERVER-OTHER Firebird database invalid state integer overflow attempt (more info ...)attempted-dos 2008-0387 27403  
32224SERVER-OTHER Firebird database invalid state integer overflow attempt (more info ...)attempted-dos 2008-0387 27403  
32225MALWARE-CNC Win.Trojan.Cryptowall variant outbound connection (more info ...)trojan-activity    URL
32240SERVER-OTHER rsyslog remote PRI out of bounds attempt (more info ...)denial-of-service 2014-3683   URL
32243MALWARE-CNC WIN.Trojan.Clemint variant outbound connection (more info ...)trojan-activity    URL
32250MALWARE-CNC Win.Trojan.Hydraq.variant outbound detected (more info ...)trojan-activity    
32259MALWARE-CNC Win.Trojan.BlackEnergy INF file download attempt (more info ...)trojan-activity    URL
32270MALWARE-CNC Win.Trojan.Tinba variant outbound connection (more info ...)trojan-activity    URL
32272MALWARE-CNC WIN.Trojan.Hesechca variant outbound connection (more info ...)trojan-activity    URL
32273MALWARE-CNC Win.Trojan.Spamnost variant outbound connection (more info ...)trojan-activity    URL
32274OS-MOBILE Apple iOS 8.x jailbreak download attempt (more info ...)attempted-admin    URL
32275OS-MOBILE Apple iOS 8.x jailbreak download attempt (more info ...)attempted-admin    URL
32285MALWARE-CNC Win.Trojan.Zoxpng variant outbound connection (more info ...)trojan-activity    URL
32287MALWARE-CNC Win.Trojan.Sapertilz variant outbound connection (more info ...)trojan-activity    URL
32289MALWARE-CNC Win.Trojan.Cryptolocker download detected (more info ...)trojan-activity    URL
32290MALWARE-CNC Win.Trojan.Cryptolocker download detected (more info ...)trojan-activity    URL
32291MALWARE-CNC Win.Trojan.Cryptolocker download detected (more info ...)trojan-activity    URL
32292MALWARE-CNC Win.Trojan.Cryptolocker download detected (more info ...)trojan-activity    URL
32293MALWARE-CNC Win.Trojan.Acanas variant outbound connection (more info ...)trojan-activity    URL
32294MALWARE-CNC User-Agent known malicious user agent BloodguyBrowser-_- (more info ...)trojan-activity    URL
32295MALWARE-CNC User-Agent known malicious user-agent string http - Win.Trojan.Waski (more info ...)trojan-activity    URL
32296MALWARE-CNC User-Agent known malicious user-agent string update - Win.Trojan.Waski (more info ...)trojan-activity    URL
32310MALWARE-CNC Win.Trojan.Farfli variant outbound connection (more info ...)trojan-activity    URL
32311MALWARE-CNC Win.Trojan.Rehtesyk outbound connection (more info ...)trojan-activity    URL
32321SERVER-OTHER Generic JPEG stored cross site scripting attempt (more info ...)web-application-attack    URL
32322SERVER-OTHER Generic JPEG stored cross site scripting attempt (more info ...)web-application-attack    URL
32328MALWARE-CNC Win.Trojan.Maener variant download request (more info ...)trojan-activity    URL
32329MALWARE-CNC Win.Trojan.Maener variant outbound connection (more info ...)trojan-activity    URL
32330MALWARE-CNC Win.Trojan.Maener variant outbound connection (more info ...)trojan-activity    URL
32332MALWARE-CNC Win.Trojan.Hancitor variant outbound connection (more info ...)trojan-activity    URL
32333MALWARE-CNC User-Agent known malicious user-agent string fast uax (more info ...)trojan-activity    URL
32334MALWARE-CNC Win.Trojan.Stantinko variant outbound connection (more info ...)trojan-activity    URL
32338MALWARE-CNC Win.Trojan.Ropest variant outbound connection (more info ...)trojan-activity    URL
32339PUA-ADWARE Nosibay Bubble Dock freeware auto update outbound connection (more info ...)misc-activity    URL
32341MALWARE-CNC Win.Trojan.Cakwerd variant outbound connection (more info ...)trojan-activity    URL
32343MALWARE-CNC Win.Trojan.Graftor variant inbound spam attempt (more info ...)attempted-user    URL
32344MALWARE-CNC Win.Trojan.Graftor variant outbound spam attempt (more info ...)attempted-user    URL
32346SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 directory traversal attempt (more info ...)attempted-admin 2014-5160 68856  
32350SERVER-WEBAPP ManageEngine multipartRequest servlet directory traversal attempt (more info ...)attempted-admin 2014-6036 70172  URL
32351SERVER-WEBAPP ManageEngine multipartRequest servlet directory traversal attempt (more info ...)attempted-admin 2014-6036 70172  URL
32357MALWARE-CNC Win.Trojan.Akaza variant outbound connection (more info ...)trojan-activity    URL
32366OS-OTHER Bash environment variable injection attempt (more info ...)attempted-admin 2014-7169   
32367MALWARE-CNC Win.Trojan.GameOverZeus variant outbound connection (more info ...)trojan-activity    URL
32368MALWARE-CNC Win.Trojan.Cridex variant outbound connection (more info ...)trojan-activity    URL
32372MALWARE-CNC Win.Trojan.Drepitt variant outbound connection (more info ...)trojan-activity    URL
32373MALWARE-CNC Win.Trojan.Broonject variant outbound connection (more info ...)trojan-activity    URL
32374MALWARE-CNC Win.Trojan.Androm variant outbound connection (more info ...)trojan-activity    URL
32375BROWSER-OTHER WGet symlink arbitrary file write attempt (more info ...)attempted-user 2014-4877 70751  
32376SERVER-OTHER Citrix NetScaler stack buffer overflow attempt (more info ...)attempted-admin    URL
32379MALWARE-CNC Win.Trojan.Baccamun variant outbound connection (more info ...)trojan-activity    URL
32382SERVER-OTHER OpenSSL DTLS SRTP extension parsing denial-of-service attempt (more info ...)attempted-dos 2014-3513 70584  URL
32383MALWARE-CNC User-Agent known malicious user-agent string - connect - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
32384MALWARE-CNC User-Agent known malicious user-agent string - myupdate - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
32400MALWARE-CNC Win.Backdoor.Parama attempted outbound connection (more info ...)trojan-activity    URL
32401MALWARE-CNC Win.Backdoor.Kivars outbound connection (more info ...)trojan-activity    URL
32402MALWARE-CNC User-Agent known malicious user agent globalupdate - Osx.Trojan.Wirelurker (more info ...)trojan-activity    URL
32451MALWARE-CNC Win.Trojan.Backoff initial outbound connection (more info ...)trojan-activity    URL
32455MALWARE-CNC User-Agent known malicious user agent VUPHTTP - Win.Trojan.Puvespia (more info ...)trojan-activity    URL
32456MALWARE-CNC Win.Backdoor.Effseart variant outbound connection (more info ...)trojan-activity    URL
32457MALWARE-CNC Win.Backdoor.Effseart variant inbound connection (more info ...)trojan-activity    URL
32464MALWARE-CNC Win.Trojan.TorrentLocker variant outbound connection (more info ...)trojan-activity    URL
32465SERVER-OTHER OpenSSL TLS large number of session tickets sent - possible dos attempt (more info ...)attempted-dos 2014-3567 70586  
32466SERVER-OTHER OpenSSL TLS large number of session tickets sent - possible dos attempt (more info ...)attempted-dos 2014-3567 70586  
32467SERVER-OTHER OpenSSL TLS large number of session tickets sent - possible dos attempt (more info ...)attempted-dos 2014-3567 70586  
32468SERVER-OTHER OpenSSL TLS large number of session tickets sent - possible dos attempt (more info ...)attempted-dos 2014-3567 70586  
32469MALWARE-CNC Win.Trojan.Bankeiya outbound connection (more info ...)trojan-activity    URL
32486MALWARE-CNC Win.Backdoor.Exadog outbound connection (more info ...)trojan-activity    URL
32487MALWARE-CNC Win.Backdoor.Exadog variant outbound connection (more info ...)trojan-activity    URL
32506MALWARE-CNC Win.Trojan.Secdeskinf outbound connection (more info ...)trojan-activity    URL
32511MALWARE-CNC PCRat variant outbound connection (more info ...)trojan-activity    URL
32512MALWARE-CNC PCRat variant outbound connection (more info ...)trojan-activity    URL
32513MALWARE-CNC Win.Backdoor.Havex outbound connection (more info ...)trojan-activity    URL
32521MALWARE-CNC Win.Trojan.Cryptowall 2.0 possible TOR client retrieval attempt (more info ...)trojan-activity    URL
32526POLICY-OTHER Visual Mining NetCharts default credentials authentication attempt (more info ...)policy-violation 2014-8516 70895  URL
32529MALWARE-CNC Win.Backdoor.Vkont variant outbound connection (more info ...)trojan-activity    URL
32546SERVER-WEBAPP F5 BIG-IP Enterprise Manager XML entity injection attempt (more info ...)attempted-user 2014-6032   
32547SERVER-WEBAPP F5 BIG-IP Enterprise Manager XML entity injection attempt (more info ...)attempted-user 2014-6032   
32548MALWARE-CNC Mac.Backdoor.iWorm attempted outbound connection (more info ...)trojan-activity    URL
32550MALWARE-CNC Win.Trojan.Extant variant outbound connection (more info ...)trojan-activity    URL
32551MALWARE-CNC Win.Trojan.Coreshell variant outbound connection (more info ...)trojan-activity    URL
32556MALWARE-CNC Win.Trojan.Bayoboiz outbound connection (more info ...)trojan-activity    URL
32557MALWARE-CNC Win.Trojan.Bayoboiz outbound connection (more info ...)trojan-activity    URL
32566POLICY-OTHER SSLv3 CBC client connection attempt (more info ...)attempted-recon 2014-3566   
32579SERVER-WEBAPP Reflected file download attempt (more info ...)web-application-attack    URL
32580SERVER-WEBAPP Reflected file download attempt (more info ...)web-application-attack    URL
32583MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
32584MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
32585MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
32586MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
32598MALWARE-CNC Win.Backdoor.Mysayad file wipe attempt (more info ...)trojan-activity    URL
32599MALWARE-CNC Win.Backdoor.Mysayad outbound connection (more info ...)trojan-activity    URL
32600MALWARE-CNC Win.Backdoor.Mysayad file wipe attempt (more info ...)trojan-activity    URL
32602POLICY-OTHER ManageEngine Eventlog Analyzer credential disclosure attempt (more info ...)attempted-recon 2014-6039   URL
32603POLICY-OTHER ManageEngine Eventlog Analyzer information disclosure attempt (more info ...)attempted-recon 2014-6038   
32604MALWARE-CNC Win.Trojan.Geodo variant outbound connection (more info ...)trojan-activity    URL
32605MALWARE-CNC Win.Worm.Jenxcus variant outbound connection (more info ...)trojan-activity    URL
32606MALWARE-CNC Win.Trojan.Sodebral variant outbound connection (more info ...)trojan-activity    URL
32607MALWARE-CNC Win.Trojan.Sodebral HTTP Response attempt (more info ...)trojan-activity    URL
32608MALWARE-CNC Win.Trojan.Sodebral HTTP Response attempt (more info ...)trojan-activity    URL
32609MALWARE-CNC Win.Trojan.NetWiredRC variant registration message (more info ...)trojan-activity    URL
32610MALWARE-CNC Win.Trojan.NetWiredRC variant keepalive (more info ...)trojan-activity    URL
32613MALWARE-CNC Win.Downloader.Jadowndec attempted outbound connection (more info ...)trojan-activity    URL
32614MALWARE-CNC Win.Downloader.Jadowndec attempted outbound connection (more info ...)trojan-activity    URL
32619FILE-OTHER MostGear EasyLanFolderShare serial key overflow attempt (more info ...)attempted-user 2013-6079   
32620FILE-OTHER MostGear EasyLanFolderShare serial key overflow attempt (more info ...)attempted-user 2013-6079   
32621MALWARE-CNC Win.Trojan.Regin outbound connection (more info ...)trojan-activity    URL
32622MALWARE-CNC Win.Trojan.Regin outbound connection (more info ...)trojan-activity    URL
32623MALWARE-CNC Win.Trojan.Regin outbound connection (more info ...)trojan-activity    URL
32624MALWARE-CNC Win.Trojan.Regin outbound connection (more info ...)trojan-activity    URL
32636FILE-OTHER fCreateShellLink function use - potential attack (more info ...)misc-activity 2008-2959   
32640EXPLOIT-KIT Sweet Orange exploit kit outbound payload detection (more info ...)trojan-activity    
32645MALWARE-CNC User-Agent known malicious user-agent string RUpdate (more info ...)trojan-activity    URL
32665MALWARE-CNC Win.Trojan.Chopstick variant outbound request (more info ...)trojan-activity    URL
32667MALWARE-CNC Win.Trojan.Chopstick variant outbound request (more info ...)trojan-activity    URL
32670MALWARE-CNC Win.Dropper.Ch variant outbound connection (more info ...)trojan-activity    URL
32671FILE-OTHER LibYAML yaml_parser_scan_uri_escapes heap buffer overflow attempt (more info ...)attempted-user 2014-2525   
32673SERVER-OTHER Web Service on Devices API WSDAPI URL processing buffer corruption attempt (more info ...)denial-of-service 2009-2512   
32674MALWARE-CNC Win.Trojan.Wiper variant outbound connection (more info ...)trojan-activity    URL
32677MALWARE-CNC Win.Trojan.Dridex variant outbound connection (more info ...)trojan-activity    URL
32678MALWARE-CNC Win.Trojan.Dridex variant outbound connection (more info ...)trojan-activity    URL
32706MALWARE-CNC Win.Trojan.Kuluoz variant outbound connection (more info ...)trojan-activity    URL
32727MALWARE-CNC Win.Backdoor.Uclinu variant outbound connection (more info ...)trojan-activity    URL
32728MALWARE-CNC Win.Trojan.Olegb variant outbound connection (more info ...)trojan-activity    URL
32729POLICY-OTHER HP Network Node Manager ovopi.dll command 685 insecure pointer dereference attempt (more info ...)policy-violation 2014-2624   URL
32734MALWARE-CNC Win.Backdoor.Typideg variant outbound connection (more info ...)trojan-activity    URL
32740POLICY-OTHER Arris VAP2500 default credentials authentication attempt (more info ...)policy-violation 2014-8424 71297  URL
32741POLICY-OTHER Arris VAP2500 default credentials authentication attempt (more info ...)policy-violation 2014-8424 71297  URL
32743MALWARE-CNC VGABot IRC communication attempt (more info ...)trojan-activity    URL
32744SERVER-WEBAPP ManageEngine NetFlow Analyzer DisplayChartPDF directory traversal attempt (more info ...)attempted-recon 2014-5446 71404  
32747MALWARE-CNC Win.Trojan.Ragebot variant outbound connection (more info ...)trojan-activity    URL
32748SERVER-OTHER Ecava IntegraXor HMI /res buffer overflow attempt (more info ...)attempted-user 2014-0753   
32755SERVER-OTHER TLSv1.0 POODLE CBC padding brute force attempt (more info ...)attempted-recon 2014-8730   URL
32756SERVER-OTHER TLSv1.1 POODLE CBC padding brute force attempt (more info ...)attempted-recon 2014-8730   URL
32757SERVER-OTHER TLSv1.2 POODLE CBC padding brute force attempt (more info ...)attempted-recon 2014-8730   URL
32758SERVER-OTHER TLSv1.0 POODLE CBC padding brute force attempt (more info ...)attempted-recon 2014-8730   URL
32759SERVER-OTHER TLSv1.1 POODLE CBC padding brute force attempt (more info ...)attempted-recon 2014-8730   URL
32760SERVER-OTHER TLSv1.2 POODLE CBC padding brute force attempt (more info ...)attempted-recon 2014-8730   URL
32769MALWARE-CNC Win.Trojan.WOWCheckC Attempted CNC (more info ...)attempted-user    URL
32770MALWARE-CNC Win.Trojan.Androm variant outbound connection (more info ...)trojan-activity    URL
32773SERVER-WEBAPP Symantec messaging gateway management console cross-site scripting attempt (more info ...)attempted-user 2014-1648   URL
32776MALWARE-CNC FIN4 VBA Macro credentials upload attempt (more info ...)trojan-activity    URL
32780MALWARE-CNC Win.Backdoor.Eskaetee outbound connection (more info ...)trojan-activity    URL
32781MALWARE-CNC Win.Backdoor.Eskaetee outbound connection (more info ...)trojan-activity    URL
32791MALWARE-CNC Win.Virus.Ransomlock outbound connection (more info ...)trojan-activity    URL
32792MALWARE-CNC Win.Virus.Ransomlock inbound connection (more info ...)trojan-activity    URL
32821FILE-PDF Cross Domain potentially malicious redirection attempt (more info ...)attempted-user 2014-8453   URL
32822FILE-PDF Cross Domain potentially malicious redirection attempt (more info ...)attempted-user 2014-8453   URL
32823MALWARE-CNC Win.Trojan.Darkhotel outbound connection (more info ...)trojan-activity    URL
32824MALWARE-CNC Win.Trojan.Darkhotel variant outbound connection (more info ...)trojan-activity    URL
32825MALWARE-CNC Win.Trojan.Darkhotel outbound connection (more info ...)trojan-activity    URL
32826MALWARE-CNC Win.Trojan.Darkhotel data upload attempt (more info ...)trojan-activity    URL
32827MALWARE-CNC Win.Trojan.Darkhotel response connection attempt (more info ...)trojan-activity    URL
32852MALWARE-CNC Win.Trojan.Poolfiend variant outbound connection (more info ...)trojan-activity    URL
32853MALWARE-CNC Win.Trojan.Poolfiend variant outbound connection (more info ...)trojan-activity    URL
32854MALWARE-CNC Win.Trojan.Loodir outbound connection (more info ...)trojan-activity    URL
32866APP-DETECT I2P UPNP query attempt (more info ...)misc-activity    URL
32871OS-WINDOWS Multiple product mailto uri handling code execution attempt (more info ...)attempted-user 2007-4041 25945  URL
32875MALWARE-TOOLS BlackSpider Tool ali.txt file upload attempt (more info ...)misc-activity    URL
32882MALWARE-CNC Win.Trojan.Ksypypro outbound connection (more info ...)trojan-activity    URL
32890SERVER-OTHER ntpd multiple vector buffer overflow attempt (more info ...)attempted-user 2014-9295   URL
32892MALWARE-CNC Win.Trojan.TorLocker variant outbound connection (more info ...)trojan-activity    URL
32893MALWARE-CNC Win.Trojan.Finforst outbound connection (more info ...)trojan-activity    URL
32901FILE-OTHER Advantech ADAMView GeniDAQ display designer stack buffer overflow attempt (more info ...)attempted-admin 2014-8386 71191  
32902FILE-OTHER Advantech ADAMView GeniDAQ display designer stack buffer overflow attempt (more info ...)attempted-admin 2014-8386 71191  
32903FILE-OTHER Oracle Database Server XML stack buffer overflow attempt (more info ...)attempted-user 2013-3751   URL
32904FILE-OTHER Oracle Database Server XML stack buffer overflow attempt (more info ...)attempted-user 2013-3751   URL
32907POLICY-OTHER PirateBrowser User-Agent detected (more info ...)policy-violation    URL
32908MALWARE-CNC Win.Trojan.TinyZBot outbound connection (more info ...)trojan-activity    URL
32909MALWARE-CNC Win.Trojan.TinyZBot outbound connection (more info ...)trojan-activity    URL
32910MALWARE-CNC Win.Trojan.TinyZBot outbound connection (more info ...)trojan-activity    URL
32911MALWARE-BACKDOOR Win.Trojan.Wiper inbound communication attempt (more info ...)trojan-activity    URL
32912MALWARE-BACKDOOR Win.Trojan.Wiper outbound communication attempt (more info ...)trojan-activity    URL
32913MALWARE-BACKDOOR Win.Trojan.Wiper download attempt (more info ...)trojan-activity    URL
32914MALWARE-BACKDOOR Win.Trojan.Wiper download attempt (more info ...)trojan-activity    URL
32915MALWARE-BACKDOOR Win.Trojan.Wiper inbound communication attempt (more info ...)trojan-activity    URL
32916MALWARE-BACKDOOR Win.Trojan.Wiper outbound communication attempt (more info ...)trojan-activity    URL
32917MALWARE-BACKDOOR Win.Trojan.Wiper inbound communication attempt (more info ...)trojan-activity    URL
32918MALWARE-BACKDOOR Win.Trojan.Wiper download attempt (more info ...)trojan-activity    URL
32919MALWARE-OTHER Win.Trojan.Wiper download attempt (more info ...)trojan-activity    URL
32920MALWARE-OTHER Win.Trojan.Wiper download attempt (more info ...)trojan-activity    URL
32921MALWARE-OTHER Win.Trojan.Wiper download attempt (more info ...)trojan-activity    URL
32922MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32923MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32924MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32925MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32926MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32927MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32928MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32929MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32930MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32931MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32932MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32933MALWARE-OTHER Win.Trojan.Wiper listener download attempt (more info ...)trojan-activity    URL
32934MALWARE-OTHER Win.Trojan.Wiper download attempt (more info ...)trojan-activity    URL
32935MALWARE-OTHER Win.Trojan.Wiper download attempt (more info ...)trojan-activity    URL
32936MALWARE-TOOLS Win.Trojan.Wiper proxy tools download attempt (more info ...)trojan-activity    URL
32937MALWARE-TOOLS Win.Trojan.Wiper proxy communication attempt (more info ...)trojan-activity    URL
32938MALWARE-TOOLS Win.Trojan.Wiper proxy tool download attempt (more info ...)trojan-activity    URL
32945FILE-IDENTIFY .scr executable screensaver file attachment detected (more info ...)misc-activity    URL
32946FILE-IDENTIFY .scr executable screensaver file attachment detected (more info ...)misc-activity    URL
32947FILE-IDENTIFY .scr executable screensaver file download request (more info ...)misc-activity    URL
32948INDICATOR-COMPROMISE Download of executable screensaver file (more info ...)policy-violation    URL
32949MALWARE-OTHER Download of executable screensaver file (more info ...)policy-violation    URL
32950MALWARE-CNC Win.Trojan.Bladabindi variant outbound connection (more info ...)trojan-activity    URL
32951POLICY-OTHER base64 encoded executable file download (more info ...)policy-violation    URL
32952SERVER-WEBAPP iCloud Apple ID brute-force login attempt (more info ...)suspicious-login    
32953SERVER-OTHER XCat Blind XPath Injection attempt (more info ...)web-application-attack    URL
32954SERVER-OTHER XCat Blind XPath Injection attempt (more info ...)web-application-attack    URL
32955SERVER-OTHER XCat Blind XPath Injection attempt (more info ...)web-application-attack    URL
32956MALWARE-CNC Android.CoolReaper.Trojan outbound connection (more info ...)trojan-activity    URL
32957MALWARE-CNC Win.Trojan.TinyZBot outbound SOAP connection attempt (more info ...)trojan-activity    URL
32958MALWARE-CNC Win.Trojan.TinyZBot response connection attempt (more info ...)trojan-activity    URL
32968SERVER-WEBAPP F5 BIG-IP name parameter directory traversal attempt (more info ...)web-application-attack 2014-8727 71063  
32969SERVER-WEBAPP F5 BIG-IP name parameter directory traversal attempt (more info ...)web-application-attack 2014-8727 71063  
32970SERVER-WEBAPP F5 BIG-IP name parameter directory traversal attempt (more info ...)web-application-attack 2014-8727 71063  
32971SERVER-WEBAPP HP System Management iprange parameter buffer overflow attempt (more info ...)attempted-admin 2013-2362   URL
32973MALWARE-CNC Win.Trojan.Twerket variant outbound connection (more info ...)trojan-activity    URL
32974OS-MOBILE Android ObjectInputStream privilege escalation attempt (more info ...)attempted-user 2014-7911 71176  
32975OS-MOBILE Android ObjectInputStream privilege escalation attempt (more info ...)attempted-user 2014-7911 71176  
32976MALWARE-CNC Win.Trojan.Kuluos variant outbound connection (more info ...)trojan-activity    URL
32977MALWARE-CNC Win.Trojan.Kuluos variant outbound connection (more info ...)trojan-activity    URL
32978MALWARE-CNC User-Agent known malicious user agent - extra IE version (more info ...)trojan-activity    URL
32979MALWARE-CNC User-Agent known malicious user agent - extra IE version (more info ...)trojan-activity    URL
32980MALWARE-CNC User-Agent known malicious user agent - multi-browser (more info ...)trojan-activity    URL
32986MALWARE-CNC Win.Trojan.Toopu dll embedded in png download attempt (more info ...)trojan-activity    URL
32987MALWARE-CNC Win.Trojan.Graftor outbound connection (more info ...)trojan-activity    URL
32988MALWARE-CNC Win.Trojan.Graftor outbound connection (more info ...)trojan-activity    URL
32989MALWARE-CNC Win.Trojan.Graftor outbound connection (more info ...)trojan-activity    URL
32990MALWARE-CNC Win.Trojan.Toopu outbound connection (more info ...)trojan-activity    URL
32991SERVER-OTHER SAP NetWeaver SXPG_COMMAND_EXECUTE remote command execution attempt (more info ...)web-application-attack    URL
32992SERVER-OTHER SAP NetWeaver SXPG_COMMAND_EXECUTE remote command execution attempt (more info ...)web-application-attack    URL
32999PROTOCOL-SCADA Advantech WebAccess SCADA command execution attempt (more info ...)attempted-user 2014-0773   URL
33000PROTOCOL-SCADA Advantech WebAccess SCADA command execution attempt (more info ...)attempted-user 2014-0773   URL
33001PROTOCOL-SCADA Advantech WebAccess SCADA command execution attempt (more info ...)attempted-user 2014-0773   URL
33002PROTOCOL-SCADA Advantech WebAccess SCADA command execution attempt (more info ...)attempted-user 2014-0773   URL
33005SERVER-WEBAPP Advantec WebAccess SCADA webvact.ocx NodeName buffer overflow attempt (more info ...)attempted-user 2014-0764 66718  URL
33006SERVER-WEBAPP Advantec WebAccess SCADA webvact.ocx NodeName buffer overflow attempt (more info ...)attempted-user 2014-0764 66718  URL
33007SERVER-WEBAPP Advantec WebAccess SCADA webvact.ocx NodeName buffer overflow attempt (more info ...)attempted-user 2014-0764 66718  URL
33008SERVER-WEBAPP Advantec WebAccess SCADA webvact.ocx NodeName buffer overflow attempt (more info ...)attempted-user 2014-0764 66718  URL
33009SERVER-WEBAPP Advantec WebAccess SCADA webvact.ocx UserName buffer overflow attempt (more info ...)attempted-user 2014-0770 66733  URL
33010SERVER-WEBAPP Advantec WebAccess SCADA webvact.ocx UserName buffer overflow attempt (more info ...)attempted-user 2014-0770 66733  URL
33011SERVER-WEBAPP Advantec WebAccess SCADA webvact.ocx UserName buffer overflow attempt (more info ...)attempted-user 2014-0770 66733  URL
33012SERVER-WEBAPP Advantec WebAccess SCADA webvact.ocx UserName buffer overflow attempt (more info ...)attempted-user 2014-0770 66733  URL
33015PROTOCOL-SCADA ABB MicroSCADA wserver.exe EXECUTE remote code execution attempt (more info ...)attempted-user    URL
33026FILE-IDENTIFY Publish-iT PUI file attachment detected (more info ...)misc-activity    
33027FILE-IDENTIFY Publish-iT PUI file attachment detected (more info ...)misc-activity    
33028FILE-IDENTIFY Publish-iT PUI file download request (more info ...)misc-activity    
33029FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33030FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33031FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33032FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33033FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33034FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33035FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33036FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33037FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33038FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33039FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33040FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
33043FILE-MULTIMEDIA Multiple media players M3U playlist file handling buffer overflow attempt (more info ...)attempted-user 2006-6063 21206  
33047MALWARE-CNC User-Agent known malicious user-agent string - realupdate - Win.Backdoor.Upatre (more info ...)trojan-activity    
33054MALWARE-CNC Win.Trojan.Joanap outbound connection (more info ...)trojan-activity    URL
33058MALWARE-CNC Win.Backdoor.Medusa variant inbound connection (more info ...)trojan-activity    
33059MALWARE-CNC Win.Backdoor.Medusa variant outbound connection (more info ...)trojan-activity    
33060MALWARE-CNC Win.Backdoor.Medusa variant outbound connection (more info ...)trojan-activity    
33061MALWARE-CNC Win.Trojan.Lagulon.A outbound connection (more info ...)trojan-activity    URL
33081MALWARE-CNC OnionDuke variant outbound connection (more info ...)trojan-activity    URL
33082MALWARE-CNC Win.Trojan.Nocpos initial outbound connection (more info ...)trojan-activity    URL
33083MALWARE-CNC Win.Trojan.Nocpos information disclosure attempt (more info ...)trojan-activity    URL
33084MALWARE-CNC Win.Trojan.Tosct variant outbound connection (more info ...)trojan-activity    URL
33087FILE-PDF Foxit Reader remote query string buffer overflow attempt (more info ...)attempted-user  57174  URL
33114SERVER-WEBAPP HP System Management Homepage cross site scripting attempt (more info ...)attempted-user 2014-2640 70206  URL
33145MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33149MALWARE-CNC Win.Worm.Ultramine outbound connection (more info ...)trojan-activity    URL
33152MALWARE-CNC Win.Trojan.Nurjax.A outbound connection (more info ...)trojan-activity    URL
33153MALWARE-CNC Win.Trojan.Heur variant outbound connection (more info ...)trojan-activity    URL
33155OS-WINDOWS CryptProtectMemory Impersonation Check Bypass attempt (more info ...)attempted-admin 2015-0010   
33156OS-WINDOWS CryptProtectMemory Impersonation Check Bypass attempt (more info ...)attempted-admin 2015-0010   
33161MALWARE-CNC Win.Spyware.Rombertik outbound connection (more info ...)attempted-user    URL
33165MALWARE-CNC Win.Trojan.Poweliks outbound connection (more info ...)trojan-activity    URL
33197SERVER-OTHER BMC Track-It FileStorageService directory traversal attempt (more info ...)attempted-admin 2014-4872 70264  
33199MALWARE-CNC Win.Trojan.MSIL.Sabeba outbound connection (more info ...)trojan-activity    URL
33200MALWARE-CNC Win.Trojan.Pisces variant outbound connection (more info ...)trojan-activity    URL
33205FILE-MULTIMEDIA VideoLAN VLC 2.1.5 Media Player libavcodex memory corruption attempt (more info ...)attempted-user 2014-9598   
33206FILE-MULTIMEDIA VideoLAN VLC 2.1.5 Media Player libavcodex memory corruption attempt (more info ...)attempted-user 2014-9598   
33207MALWARE-CNC User-Agent known malicious user-agent string - Mazilla/5.0 - Win.Backdoor.Upatre (more info ...)trojan-activity    
33211MALWARE-CNC Win.Trojan.Upatre variant outbound connection (more info ...)trojan-activity    URL
33218MALWARE-CNC Win.Trojan.Cendode system information disclosure attempt (more info ...)trojan-activity    URL
33219MALWARE-CNC Win.Trojan.Gamarue variant outbound connection (more info ...)trojan-activity    URL
33220MALWARE-CNC Win.Trojan.HawkEye keylogger exfiltration attempt (more info ...)trojan-activity    URL
33221MALWARE-CNC Win.Trojan.HawkEye Keylogger exfiltration attempt - clipboard and screenshot (more info ...)trojan-activity    URL
33222MALWARE-CNC Win.Trojan.HawkEye Keylogger exfiltration attempt - clipboard and screenshot (more info ...)trojan-activity    URL
33223MALWARE-CNC Win.Trojan.HawkEye Keylogger exfiltration attempt - clipboard and screenshot (more info ...)trojan-activity    URL
33224INDICATOR-COMPROMISE Win.Trojan.Blocker variant outbound connection attempt (more info ...)misc-activity    URL
33228MALWARE-CNC Win.Trojan.Kovter variant outbound connection (more info ...)trojan-activity    URL
33230MALWARE-CNC User-Agent known malicious user-agent string - Firefox - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33231MALWARE-CNC User-Agent known malicious user-agent string - Firefox/5.0 - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33232MALWARE-CNC User-Agent known malicious user-agent string - AppUpdate - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33233MALWARE-CNC User-Agent known malicious user-agent string - 2608cw-1 - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33234MALWARE-CNC User-Agent known malicious user-agent string - 2508Inst - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33235MALWARE-CNC User-Agent known malicious user-agent string - 2608cw-2 - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33236MALWARE-CNC User-Agent known malicious user-agent string - 2808inst - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33237MALWARE-CNC User-Agent known malicious user-agent string - Player - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33238MALWARE-CNC User-Agent known malicious user-agent string - Wurst - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33239MALWARE-CNC User-Agent known malicious user-agent string - Installer/1.0 - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33240MALWARE-CNC User-Agent known malicious user-agent string - FixUpdate - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33242MALWARE-CNC User-Agent known malicious user-agent string - Explorer - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33247MALWARE-CNC User-Agent known malicious user-agent string - PPKHandler - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33248MALWARE-CNC User-Agent known malicious user-agent string - Peers12 - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33249MALWARE-CNC User-Agent known malicious user-agent string - SLSSoapClient - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33250MALWARE-CNC User-Agent known malicious user-agent string - Tintin - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33251MALWARE-CNC User-Agent known malicious user-agent string - USER_CHECK - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33252MALWARE-CNC User-Agent known malicious user-agent string - WATClient - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33253MALWARE-CNC User-Agent known malicious user-agent string - bbbbbbbbbb - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33254MALWARE-CNC User-Agent known malicious user-agent string - hi - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33255MALWARE-CNC User-Agent known malicious user-agent string - iMacros - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33256MALWARE-CNC User-Agent known malicious user-agent string - macrotest - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33257MALWARE-CNC User-Agent known malicious user-agent string - onlymacros - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33258MALWARE-CNC User-Agent known malicious user-agent string - Updates downloader - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33259MALWARE-CNC User-Agent known malicious user-agent string - testupdate - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33260MALWARE-CNC User-Agent known malicious user-agent string - onlyupdate - Win.Backdoor.Upatre (more info ...)trojan-activity    URL
33279SERVER-WEBAPP McAfee ePolicy Orchestrator XML external entity injection attempt (more info ...)web-application-attack 2015-0921 71881  
33282MALWARE-CNC Win.Trojan.Upatre variant outbound connection (more info ...)trojan-activity    URL
33284MALWARE-CNC Win.Trojan.OnLineGames variant outbound connection (more info ...)trojan-activity    URL
33285MALWARE-CNC Win.Trojan.Bavload outbound download request attempt (more info ...)trojan-activity    URL
33289MALWARE-CNC Win.Trojan.Rawpos incoming backdoor connection attempt (more info ...)trojan-activity    URL
33299MALWARE-CNC Win.Trojan.Foxy variant outbound connection (more info ...)trojan-activity    URL
33305MALWARE-CNC Win.Trojan.Rubinurd variant outbound connection (more info ...)trojan-activity    URL
33309FILE-OTHER libxml2 entity reference name heap buffer overflow attempt (more info ...)attempted-user 2011-3919   
33310FILE-OTHER libxml2 entity reference name heap buffer overflow attempt (more info ...)attempted-user 2011-3919   
33328MALWARE-CNC Osx.Trojan.Yinli outbound connection (more info ...)attempted-user    URL
33329MALWARE-CNC Osx.Trojan.Yinli outbound connection (more info ...)attempted-user    URL
33330MALWARE-CNC Osx.Trojan.Yinli outbound connection (more info ...)attempted-user    URL
33339INDICATOR-SHELLCODE ASCII heapspray characters detected (more info ...)attempted-user    URL
33342MALWARE-CNC Doc.Downloader.Dridex outbound connection (more info ...)attempted-user    URL
33411MALWARE-CNC Doc.Downloader.Dridex outbound connection (more info ...)attempted-user    URL
33430APP-DETECT I2P traffic transmission attempt (more info ...)policy-violation    URL
33431MALWARE-CNC Win.Trojan.Cryptowall 3.0 variant outbound connection (more info ...)trojan-activity    URL
33432MALWARE-CNC Win.Trojan.Cryptowall 3.0 variant outbound connection (more info ...)trojan-activity    URL
33433MALWARE-CNC Win.Trojan.Cryptowall 3.0 variant outbound connection (more info ...)trojan-activity    URL
33434MALWARE-CNC Win.Trojan.Cryptowall 3.0 variant outbound connection (more info ...)trojan-activity    URL
33435MALWARE-CNC Win.Trojan.Cryptowall 3.0 variant outbound connection (more info ...)trojan-activity    URL
33439MALWARE-CNC Win.Trojan.Gefetroe variant outbound connection (more info ...)trojan-activity    URL
33443MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
33444MALWARE-CNC Win.Trojan.SpyBanker variant outbound connection (more info ...)trojan-activity    URL
33449MALWARE-CNC Win.Trojan.FileEncoder IP geolocation checkin attempt (more info ...)trojan-activity    URL
33450MALWARE-CNC Win.Trojan.FileEncoder variant outbound connection (more info ...)trojan-activity    URL
33453MALWARE-CNC Win.Trojan.Kovter variant outbound connection (more info ...)trojan-activity    URL
33456MALWARE-CNC Doc.Downloader.Dridex outbound connection (more info ...)attempted-user    URL
33457MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
33464MALWARE-CNC Win.Trojan.Dynamer variant outbound connection (more info ...)trojan-activity    URL
33480PUA-ADWARE Win.Adware.DownloadGuide variant outbound connection (more info ...)trojan-activity    URL
33482MALWARE-CNC Win.Worm.Enosch variant outbound connection (more info ...)trojan-activity    URL
33496MALWARE-CNC Win.Trojan.Andromeda variant outbound connection (more info ...)trojan-activity    URL
33519MALWARE-CNC User-Agent known malicious user agent - ALIZER (more info ...)trojan-activity    URL
33520MALWARE-CNC Win.Trojan.Zusy inbound CNC response (more info ...)trojan-activity    URL
33521MALWARE-CNC Win.Trojan.Zusy variant outbound connection (more info ...)trojan-activity    URL
33531PUA-ADWARE MediaBuzz malvertising browser redirect attempt (more info ...)misc-activity    URL
33532PUA-ADWARE MediaBuzz malvertising browser redirect attempt (more info ...)misc-activity    URL
33543MALWARE-CNC Win.Trojan.Equation outbound connection (more info ...)trojan-activity    URL
33545MALWARE-CNC Win.Trojan.Equation outbound connection (more info ...)trojan-activity    URL
33546MALWARE-CNC Win.Trojan.Equation outbound connection (more info ...)trojan-activity    URL
33547MALWARE-CNC Win.Trojan.Turla outbound connection (more info ...)trojan-activity    URL
33561SERVER-OTHER OpenSSL fragmented protocol downgrade attempt (more info ...)policy-violation 2014-3511   URL
33564SERVER-MAIL GNU Mailman date field buffer overflow attempt (more info ...)attempted-user 2005-4153   
33565SERVER-OTHER McAfee E-Business Server remote preauth code execution attempt (more info ...)attempted-user    URL
33580PUA-ADWARE SuperFish adware outbound connection attempt (more info ...)policy-violation    URL
33581SERVER-WEBAPP nginx URI processing security bypass attempt (more info ...)attempted-user 2013-4547 63814  
33594MALWARE-CNC Win.Trojan.Upatre variant outbound connection (more info ...)trojan-activity    URL
33595SERVER-OTHER GnuTLS TLSA record heap buffer overflow attempt (more info ...)attempted-user 2013-4466   
33596SERVER-OTHER GnuTLS TLSA record heap buffer overflow attempt (more info ...)attempted-user 2013-4466   
33600MALWARE-CNC Win.Trojan.Ramnit variant outbound detected (more info ...)trojan-activity    URL
33607SERVER-WEBAPP cron access (more info ...)attempted-recon    
33608SERVER-WEBAPP bin access (more info ...)attempted-recon    
33609SERVER-WEBAPP .wwwpasswd access (more info ...)web-application-activity    
33610SERVER-WEBAPP .wwwgroup access (more info ...)web-application-activity    
33611SERVER-WEBAPP httpd.conf access (more info ...)web-application-activity    
33612SERVER-WEBAPP stronghold-status access (more info ...)web-application-activity    
33613SERVER-WEBAPP stronghold-info access (more info ...)web-application-activity    
33614SERVER-WEBAPP caucho-status access (more info ...)web-application-activity    
33618MALWARE-BACKDOOR Win.Trojan.lubot download (more info ...)trojan-activity    URL
33619MALWARE-BACKDOOR Win.Trojan.lubot download (more info ...)trojan-activity    URL
33633MALWARE-CNC User-Agent known malicious user-agent - Downing - Win.Trojan.Otwycal (more info ...)trojan-activity    URL
33640FILE-IDENTIFY Apple Motion file download request (more info ...)misc-activity    
33641FILE-IDENTIFY Apple Motion file attachment detected (more info ...)misc-activity    
33642FILE-IDENTIFY Apple Motion file attachment detected (more info ...)misc-activity    
33643FILE-OTHER Apple Motion OZDocumentparseElement Integer Overflow attempt (more info ...)attempted-user 2013-6114   
33644FILE-OTHER Apple Motion OZDocumentparseElement Integer Overflow attempt (more info ...)attempted-user 2013-6114   
33645PUA-ADWARE SuperFish adware outbound connection attempt (more info ...)policy-violation    URL
33649MALWARE-CNC User-Agent known malicious user agent - Google Omaha - Win.Trojan.ExtenBro (more info ...)trojan-activity    URL
33650MALWARE-CNC Win.Trojan.Tinba outbound connection (more info ...)trojan-activity    URL
33655SERVER-OTHER Squid Proxy invalid HTTP response code denial of service attempt (more info ...)denial-of-service 2009-2622 35812  
33656MALWARE-CNC Win.Trojan.Carbanak data exfiltration attempt (more info ...)trojan-activity    URL
33660MALWARE-CNC Win.Trojan.Vawtrak variant outbound connection (more info ...)trojan-activity    URL
33664BROWSER-OTHER Network Security Services NSS library RSA signature forgery attempt (more info ...)misc-activity 2014-1568 70116  URL
33666FILE-IDENTIFY PIF Program Information File file download request (more info ...)misc-activity    
33667FILE-IDENTIFY PIF Program Information File file attachment detected (more info ...)misc-activity    
33668FILE-IDENTIFY PIF Program Information File file attachment detected (more info ...)misc-activity    
33669FILE-OTHER Executable disguised as PIF file (more info ...)attempted-user    URL
33670SERVER-OTHER Symantec AMS Intel handler service overly large size1 dos attempt (more info ...)attempted-dos 2010-3268   
33671SERVER-OTHER Symantec AMS Intel handler service overly large size2 dos attempt (more info ...)attempted-dos 2010-3268   
33672SERVER-OTHER Symantec AMS Intel handler service overly large size3 dos attempt (more info ...)attempted-dos 2010-3268   
33674MALWARE-CNC Win.Trojan.Athena variant outbound connection (more info ...)trojan-activity    URL
33675MALWARE-CNC Win.Trojan.Athena variant outbound connection (more info ...)trojan-activity    URL
33677MALWARE-CNC Win.Trojan.Babar outbound connection (more info ...)trojan-activity    URL
33678MALWARE-CNC Win.Trojan.FannyWorm outbound connection (more info ...)trojan-activity    URL
33681MALWARE-CNC Win.Trojan.Carbanak connection to server (more info ...)trojan-activity    URL
33704MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33728OS-WINDOWS ATLMFD.DLL improperly terminated encrypted charstrings in type 1 font attempt (more info ...)attempted-user 2015-0087   URL
33729OS-WINDOWS ATLMFD.DLL improperly terminated encrypted charstrings in type 1 font attempt (more info ...)attempted-user 2015-0087   URL
33745MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33746MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33747MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33748MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33749MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33750MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33751MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33752MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33753MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33754MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33755MALWARE-CNC Win.Trojan.Dridex initial outbound connection (more info ...)trojan-activity    URL
33756MALWARE-CNC Win.Ransomware.CTB-Locker outbound connection (more info ...)trojan-activity    URL
33757MALWARE-CNC Win.Ransomware.CTB-Locker outbound connection (more info ...)trojan-activity    URL
33777SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33778SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33779SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33780SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33781SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33782SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33783SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33784SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33785SERVER-OTHER SSL request for export grade cipher suite attempt (more info ...)policy-violation 2015-4000   URL
33786SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33787SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33788SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33789SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33790SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33791SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33792SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33793SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33794SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33795SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33796SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33797SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33798SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33799SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33800SERVER-OTHER SSL export grade ciphersuite server negotiation attempt (more info ...)policy-violation 2015-4000   URL
33801SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33802SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33803SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33804SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33805SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33806SERVER-OTHER SSL request for export grade ciphersuite attempt (more info ...)policy-violation 2015-4000   URL
33814SERVER-OTHER ElasticSearch script remote code execution attempt (more info ...)attempted-user 2015-1427   URL
33815PUA-ADWARE Adware Goobzo/CrossRider variant outbound connection (more info ...)misc-activity    URL
33816PUA-ADWARE Adware Goobzo/CrossRider variant outbound connection (more info ...)misc-activity    URL
33817SERVER-OTHER Lighttpd Host header directory traversal attempt (more info ...)attempted-admin 2014-2324   URL
33818MALWARE-CNC Win.Trojan.Egamipload variant outbound connection (more info ...)trojan-activity    URL
33819MALWARE-CNC Win.Trojan.Egamipload variant outbound connection (more info ...)trojan-activity    URL
33820MALWARE-CNC Win.Trojan.Egamipload variant outbound connection (more info ...)trojan-activity    URL
33821MALWARE-CNC Win.Trojan.Egamipload variant outbound connection (more info ...)trojan-activity    URL
33822MALWARE-CNC Win.Trojan.Egamipload variant outbound connection (more info ...)trojan-activity    URL
33830SERVER-OTHER ElasticSearch script remote code execution attempt (more info ...)attempted-user 2014-3120   URL
33831MALWARE-CNC User-Agent known malicious user agent DownloadMR - Solimba (more info ...)trojan-activity    URL
33833PUA-ADWARE User-Agent adware OutBrowse/Amonitize (more info ...)trojan-activity    
33834PUA-ADWARE User-Agent adware OutBrowse/Amonitize (more info ...)trojan-activity    
33835PUA-ADWARE User-Agent adware OutBrowse/Amonitize (more info ...)trojan-activity    
33851MALWARE-CNC Win.Trojan.Poseidon outbound connection (more info ...)trojan-activity    URL
33852MALWARE-CNC Win.Trojan.Poseidon outbound connection (more info ...)trojan-activity    URL
33853SERVER-WEBAPP D-Link multiple products ping.ccp command injection attempt (more info ...)attempted-admin 2015-1187 72848  
33854MALWARE-CNC Win.Trojan.LogPOS variant outbound connection (more info ...)trojan-activity    URL
33857MALWARE-CNC Win.Trojan.PwnPOS data exfiltration attempt (more info ...)trojan-activity    URL
33858SERVER-OTHER rsyslog remote PRI out of bounds attempt (more info ...)denial-of-service 2014-3683   URL
33859MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33860MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33861MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33862MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33863MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33864MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33865MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33866MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33867MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33868MALWARE-CNC Win.Trojan.Dridex3 initial outbound connection (more info ...)trojan-activity    URL
33872MALWARE-CNC Win.Worm.Urahu outbound connection (more info ...)trojan-activity    URL
33873MALWARE-CNC Win.Trojan.Tepoyx outbound connection detection (more info ...)trojan-activity    URL
33876MALWARE-CNC Win.Trojan.Meowner runtime detection (more info ...)trojan-activity    URL
33877MALWARE-CNC Win.Trojan.Meowner runtime detection (more info ...)trojan-activity    URL
33878MALWARE-CNC Win.Trojan.Meowner runtime detection (more info ...)trojan-activity    URL
33879MALWARE-CNC Win.Trojan.Meowner runtime detection (more info ...)trojan-activity    URL
33880MALWARE-CNC Win.Backdoor.Casper outbound connection (more info ...)trojan-activity    URL
33883MALWARE-CNC Win.Trojan.Jadtre variant outbound connection (more info ...)trojan-activity    URL
33884MALWARE-CNC User-Agent known malicious user-agent string dolit (more info ...)trojan-activity    URL
33885MALWARE-CNC Win.Trojan.Gh0st variant outbound connection (more info ...)trojan-activity    URL
33886MALWARE-CNC WIn.Trojan.HawkEye keylogger variant outbound connection (more info ...)trojan-activity    URL
33892MALWARE-CNC Win.Trojan.Xerq outbound connection (more info ...)trojan-activity    URL
33893MALWARE-CNC Win.Trojan.TeslaCrypt outbound connection (more info ...)trojan-activity    URL
33896SERVER-WEBAPP OpenNMS XML external entity injection attempt (more info ...)web-application-attack 2015-0975   
33907MALWARE-CNC User-Agent known malicious user-agent - KAIIOOOO871 - Win.Trojan.Dridex (more info ...)trojan-activity    URL
33910BROWSER-WEBKIT Apple Webkit rowspan denial of service attempt (more info ...)attempted-dos 2007-0342   
33911BROWSER-WEBKIT Apple Webkit rowspan denial of service attempt (more info ...)attempted-dos 2007-0342   
33912MALWARE-CNC Cryptofortress Decryption Software Purchase Tor Website (more info ...)trojan-activity    URL
33913MALWARE-CNC Win.Trojan.Concbak outbound connection (more info ...)trojan-activity    URL
33914MALWARE-CNC User-Agent known malicious user-agent - Win.Trojan.Barys (more info ...)trojan-activity    URL
33930MALWARE-CNC Vicepass outbound connection initial request to the CNC sending system information (more info ...)misc-activity    URL
33931MALWARE-CNC Win.Worm.Goldrv variant outbound connection (more info ...)trojan-activity    URL
33932MALWARE-CNC Win.Trojan.Tempedreve Samba probe (more info ...)trojan-activity    URL
33933MALWARE-CNC Win.Trojan.Penget variant outbound connection (more info ...)trojan-activity    URL
33942MALWARE-OTHER Executable control panel file download request (more info ...)misc-activity    URL
33963POLICY-OTHER Evercookie persistent cookie storage attempt (more info ...)policy-violation    URL
33964POLICY-OTHER Evercookie persistent cookie storage attempt (more info ...)policy-violation    URL
33966MALWARE-CNC Win.Worm.Mafusc variant outbound connection (more info ...)trojan-activity    URL
33987SERVER-OTHER Symantec System Center Alert Management System untrusted command execution attempt (more info ...)policy-violation 2009-1431 34675  
33989MALWARE-CNC Win.Trojan.Trioptid outbound connection (more info ...)trojan-activity    URL
33990MALWARE-CNC Win.Trojan.Trioptid outbound connection (more info ...)trojan-activity    URL
33992MALWARE-CNC Win.Trojan.Insidious outbound connection (more info ...)trojan-activity    URL
33993MALWARE-CNC Win.Trojan.Insidious outbound connection (more info ...)trojan-activity    URL
33994MALWARE-CNC Win.Downloader.Beshida outbound connection (more info ...)misc-activity    URL
33996MALWARE-CNC Win.Trojan.Pwexes variant outbound connection (more info ...)trojan-activity    URL
33997MALWARE-CNC Win.Trojan.Pwexes variant outbound connection (more info ...)trojan-activity    URL
34001MALWARE-CNC Win.Trojan.Picommex outbound connection (more info ...)trojan-activity    URL
34002MALWARE-CNC Win.Trojan.Picommex outbound connection (more info ...)trojan-activity    URL
34003MALWARE-CNC Win.Trojan.Picommex outbound connection (more info ...)trojan-activity    URL
34004MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34005MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34006MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34007MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34008MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34009MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34010MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34011MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34012MALWARE-CNC Win.Trojan.Explosive variant outbound connection (more info ...)trojan-activity    URL
34013MALWARE-CNC Win.Trojan.Ayuther variant outbound connection (more info ...)trojan-activity    URL
34018INDICATOR-SHELLCODE percent encoded heapspray detected (more info ...)shellcode-detect    
34019INDICATOR-SHELLCODE percent encoded heapspray detected (more info ...)shellcode-detect    
34023PROTOCOL-VOIP Unity Conversation Manager record-route INVITE anomaly denial of service attempt (more info ...)denial-of-service 2015-0613   
34025MALWARE-CNC Win.Trojan.Endstar variant outbound connection (more info ...)trojan-activity    URL
34026MALWARE-CNC Win.Trojan.Endstar variant outbound connection (more info ...)trojan-activity    URL
34028MALWARE-CNC Win.Trojan.Bruecimig variant outbound connection (more info ...)trojan-activity    URL
34029MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
34030MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34031MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34032MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34033MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34034MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34035MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34036MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34037MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34038MALWARE-CNC Win.Trojan.Dridex4 initial outbound connection (more info ...)trojan-activity    URL
34039MALWARE-CNC Win.Trojan.Banklaed variant outbound connection (more info ...)trojan-activity    URL
34041MALWARE-CNC Win.Backdoor.Igliveforg variant initial outbound connection (more info ...)trojan-activity    URL
34042MALWARE-CNC Win.Backdoor.Igliveforg variant outbound connection (more info ...)trojan-activity    URL
34044MALWARE-CNC Win.Trojan.Exacrytion variant outbound connection (more info ...)trojan-activity    URL
34045MALWARE-CNC Win.Trojan.Eitenckay initial outbound connection (more info ...)trojan-activity    URL
34046MALWARE-CNC Win.Trojan.Expilan variant outbound connection (more info ...)trojan-activity    URL
34049MALWARE-CNC Win.Backdoor.EvilBunny variant outbound connection (more info ...)trojan-activity    URL
34050MALWARE-CNC Win.Backdoor.Nepigon variant outbound connection (more info ...)trojan-activity    URL
34052MALWARE-CNC Win.Trojan.NewPos outbound connection (more info ...)trojan-activity    URL
34097FILE-OTHER Multiple products external entity injection attempt (more info ...)attempted-admin 2018-8533   URL
34098FILE-OTHER Multiple products external entity injection attempt (more info ...)attempted-admin 2018-8533   URL
34108MALWARE-CNC Win.Trojan.Scarsi variant outbound connection (more info ...)trojan-activity    URL
34111MALWARE-CNC Win.Trojan.Chrozil variant outbound connection (more info ...)trojan-activity    URL
34112SERVER-OTHER NTP mode 6 REQ_NONCE denial of service attempt (more info ...)attempted-dos 2013-5211   URL
34113MALWARE-CNC Win.Trojan.Agent beacon reply attempt (more info ...)trojan-activity    URL
34114SERVER-OTHER NTP mode 6 UNSETTRAP denial of service attempt (more info ...)attempted-dos 2013-5211   URL
34115MALWARE-CNC MacOS.Trojan.Wirelurker variant outbound connection (more info ...)trojan-activity    URL
34116MALWARE-CNC MacOS.Trojan.Wirelurker variant outbound connection (more info ...)trojan-activity    URL
34117MALWARE-CNC Win.Backdoor.Zupdax variant outbound connection (more info ...)trojan-activity    URL
34119PUA-ADWARE InstallMetrix precheck stage outbound connection (more info ...)misc-activity    URL
34120PUA-ADWARE InstallMetrix fetch offers stage outbound connection (more info ...)misc-activity    URL
34121PUA-ADWARE InstallMetrix reporting binary installation stage status (more info ...)misc-activity    URL
34122PUA-ADWARE InstallMetrix reporting fetch offers stage status (more info ...)misc-activity    URL
34125PUA-ADWARE User-Agent Vitruvian (more info ...)misc-activity    URL
34126PUA-ADWARE Vitruvian outbound connection (more info ...)misc-activity    URL
34127PUA-ADWARE Vitruvian outbound connection (more info ...)misc-activity    URL
34128MALWARE-CNC Win.Trojan.WIntruder outbound connection (more info ...)trojan-activity    URL
34130MALWARE-CNC Win.Trojan.Banload variant outbound connection (more info ...)trojan-activity    URL
34132MALWARE-CNC Win.Backdoor.Erotimpact variant outbound connection (more info ...)trojan-activity    URL
34137PUA-ADWARE SearchProtect user-agent detection (more info ...)misc-activity    URL
34138MALWARE-CNC Win.Downloader.Netkrypt inbound response (more info ...)trojan-activity    URL
34140MALWARE-CNC Win.Trojan.Dyre publickey outbound connection (more info ...)trojan-activity    URL
34141SERVER-OTHER Oracle CorelDRAW file parser heap buffer overflow attempt (more info ...)attempted-admin 2013-0418   
34142SERVER-OTHER Oracle CorelDRAW file parser heap buffer overflow attempt (more info ...)attempted-admin 2013-0418   
34143MALWARE-CNC Win.Trojan.Crypvault outbound connection (more info ...)trojan-activity    URL
34144PUA-ADWARE SuperOptimizer installation status (more info ...)misc-activity    URL
34145PUA-ADWARE SuperOptimizer encrypted data transmission (more info ...)misc-activity    URL
34146PUA-ADWARE SuperOptimizer geolocation request (more info ...)misc-activity    URL
34155MALWARE-CNC MacOS.Backdoor.Xslcmd outbound connection (more info ...)trojan-activity    URL
34160SERVER-OTHER Oracle Outside In Paradox database denial of service attempt (more info ...)attempted-dos 2013-0393 57357  URL
34161MALWARE-CNC Win.Trojan.Punkey outbound connection (more info ...)trojan-activity    URL
34181MALWARE-CNC Win.Trojan.Bartallex outbound connection (more info ...)trojan-activity    URL
34182MALWARE-CNC Win.Trojan.Bartallex outbound connection (more info ...)trojan-activity    URL
34183MALWARE-CNC Win.Trojan.Bartallex outbound connection (more info ...)trojan-activity    URL
34184SERVER-WEBAPP ESF pfSense services_unbound_acls cross site scripting attempt (more info ...)attempted-user 2015-2294 73344  
34185SERVER-WEBAPP ESF pfSense status_captiveportal cross site scripting attempt (more info ...)attempted-user 2015-2294 73344  
34214MALWARE-CNC Win.Trojan.Capimac variant outbound connection (more info ...)trojan-activity    URL
34215SERVER-WEBAPP ESF pfSense diag_logs_filter cross site scripting attempt (more info ...)attempted-user 2015-2294 73344  
34216MALWARE-CNC Win.Trojan.FighterPOS variant outbound connection (more info ...)trojan-activity    URL
34217MALWARE-CNC Win.Trojan.Aytoke variant outbound connection (more info ...)trojan-activity    URL
34219MALWARE-CNC Win.Trojan.Nanocore variant outbound connection (more info ...)trojan-activity    URL
34223MALWARE-CNC Win.Backdoor.Yebot variant outbound connection (more info ...)trojan-activity    URL
34226INDICATOR-OBFUSCATION Multiple AV products evasion attempt (more info ...)misc-activity 2012-1461   URL
34227INDICATOR-OBFUSCATION Multiple AV products evasion attempt (more info ...)misc-activity 2012-1461   URL
34236PUA-ADWARE Eorezo outbound connection (more info ...)misc-activity    URL
34237PUA-ADWARE Eorezo get advertisement (more info ...)misc-activity    URL
34246MALWARE-CNC Win.Trojan.AAEH variant outbound connection (more info ...)trojan-activity    URL
34280MALWARE-CNC Win.Trojan.TeslaCrypt outbound connection (more info ...)trojan-activity    URL
34281MALWARE-CNC Win.Trojan.Bartallex outbound connection (more info ...)trojan-activity    URL
34282MALWARE-CNC Win.Trojan.Bartallex outbound connection (more info ...)trojan-activity    URL
34283MALWARE-CNC Win.Trojan.Bartallex outbound connection (more info ...)trojan-activity    URL
34284SERVER-WEBAPP ESF pfSense firewall_rules cross site scripting attempt (more info ...)attempted-user 2015-2294 73344  
34285SERVER-WEBAPP ESF pfSense firewall_shaper cross site scripting attempt (more info ...)attempted-user 2015-2294 73344  
34286MALWARE-CNC Win.Trojan.Mudrop variant outbound connection (more info ...)trojan-activity    URL
34287SERVER-WEBAPP vBulletin XSS redirect attempt (more info ...)web-application-attack    URL
34288SERVER-OTHER Windows iSCSI target login request Denial of Service attempt (more info ...)attempted-dos 2014-0255   URL
34289MALWARE-CNC Win.Backdoor.Plez outbound connection (more info ...)trojan-activity    URL
34290MALWARE-CNC Win.Backdoor.Plez outbound connection (more info ...)trojan-activity    URL
34291MALWARE-CNC User-Agent known malicious user-agent string crackim (more info ...)trojan-activity    URL
34292MALWARE-CNC Win.Trojan.Kraken outbound connection (more info ...)trojan-activity    URL
34296MALWARE-CNC Win.Trojan.Simda variant outbound connection (more info ...)trojan-activity    URL
34297MALWARE-CNC Win.Trojan.Simda variant outbound connection (more info ...)trojan-activity    URL
34301SERVER-OTHER GNU Mailman listname directory traversal attempt (more info ...)attempted-user 2015-2775   
34306SERVER-WEBAPP Subversion HTTP excessive REPORT requests denial of service attempt (more info ...)attempted-dos 2015-0202   URL
34307MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34308MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34309MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34310MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34311MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34312MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34313MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34314MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34315MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34316MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34317MALWARE-CNC Win.Trojan.DesertFalcon variant outbound connection (more info ...)trojan-activity    URL
34318MALWARE-CNC Win.Trojan.CryptoWall variant outbound connection (more info ...)trojan-activity    URL
34319MALWARE-CNC Win.Worm.Klogwjds variant outbound connection (more info ...)trojan-activity    URL
34322MALWARE-CNC Win.Trojan.Farfli outbound connection (more info ...)trojan-activity    URL
34323MALWARE-CNC Win.Trojan.Fulairo variant outbound connection (more info ...)trojan-activity    URL
34324MALWARE-CNC Win.Downloader.Siromost variant outbound connection (more info ...)trojan-activity    URL
34325MALWARE-CNC Win.Trojan.Sanhotan variant outbound connection (more info ...)trojan-activity    URL
34326MALWARE-CNC Win.Trojan.Sanhotan variant outbound connection (more info ...)trojan-activity    URL
34327MALWARE-CNC Win.Trojan.Bedepshel variant outbound connection (more info ...)trojan-activity    URL
34329MALWARE-CNC Cryptolocker variant inbound connection (more info ...)trojan-activity    URL
34337MALWARE-CNC Backdoor.Win32.Chkngrbot.A outbound connection (more info ...)trojan-activity    URL
34338MALWARE-CNC Backdoor.Win32.Chkngrbot.A outbound connection (more info ...)trojan-activity    URL
34339MALWARE-CNC Win.Backdoor.Cybergate outbound connection (more info ...)trojan-activity    URL
34343FILE-MULTIMEDIA VideoLAN VLC Media Player XSPF integer overflow attempt (more info ...)attempted-dos 2011-2194 48171  URL
34344FILE-MULTIMEDIA VideoLAN VLC Media Player XSPF integer overflow attempt (more info ...)attempted-dos 2011-2194 48171  URL
34346MALWARE-CNC Win.Trojan.Backspace outbound connection (more info ...)trojan-activity    URL
34347MALWARE-CNC Win.Trojan.Cheprobnk variant outbound connection (more info ...)trojan-activity    URL
34348EXPLOIT-KIT Angler exploit kit payload download (more info ...)trojan-activity    
34349SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin 2015-0119 73917  
34350SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin 2015-0119 73917  
34351SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin 2015-0119 73917  
34352SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin 2015-0119 73917  
34353SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin 2015-0119 73917  
34358SERVER-WEBAPP Dell SonicWALL SonicOS macIpSpoofView cross site scripting attempt (more info ...)attempted-user 2015-3447   
34359SERVER-WEBAPP ESF pfSense deletefile directory traversal attempt (more info ...)web-application-attack 2015-2295 73344  
34360SERVER-WEBAPP ESF pfSense deletefile directory traversal attempt (more info ...)web-application-attack 2015-2295 73344  
34361SERVER-WEBAPP ESF pfSense deletefile directory traversal attempt (more info ...)web-application-attack 2015-2295 73344  
34362MALWARE-CNC Win.Trojan.Mantal variant outbound connection (more info ...)trojan-activity    URL
34365SERVER-WEBAPP Magento remote code execution attempt (more info ...)attempted-admin 2015-1398   
34366MALWARE-CNC Win.Trojan.Beebone outbound connection (more info ...)trojan-activity    URL
34367MALWARE-CNC Win.Trojan.Banload variant outbound connection (more info ...)trojan-activity    URL
34368MALWARE-CNC Win.Trojan.Banload variant outbound connection (more info ...)trojan-activity    URL
34446MALWARE-CNC Win.Trojan.Odlanor information exfiltration attempt (more info ...)trojan-activity    URL
34452MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
34453MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
34458MALWARE-CNC Win.Trojan.Tendrit variant outbound connection (more info ...)trojan-activity    URL
34459MALWARE-CNC Win.Trojan.Pvzin variant outbound connection (more info ...)trojan-activity    URL
34460MALWARE-CNC Win.Worm.Mozibe variant outbound connection (more info ...)trojan-activity    URL
34463APP-DETECT TeamViewer remote administration tool outbound connection attempt (more info ...)policy-violation    URL
34465INDICATOR-COMPROMISE known malicious SSL certificate - APT28 Lisuife (more info ...)trojan-activity    URL
34469MALWARE-CNC Win.Backdoor.Nirunte variant outbound connection (more info ...)trojan-activity    URL
34470MALWARE-CNC Win.Backdoor.Nirunte variant outbound connection (more info ...)trojan-activity    URL
34476MALWARE-CNC Win.Trojan.Kriptovor variant outbound connection (more info ...)trojan-activity    URL
34481OS-OTHER QEMU floppy disk controller buffer overflow attempt (more info ...)attempted-admin 2015-3456 74640  
34482OS-OTHER QEMU floppy disk controller buffer overflow attempt (more info ...)attempted-admin 2015-3456 74640  
34483OS-OTHER QEMU floppy disk controller buffer overflow attempt (more info ...)attempted-admin 2015-3456 74640  
34484OS-OTHER QEMU floppy disk controller buffer overflow attempt (more info ...)attempted-admin 2015-3456 74640  
34485OS-OTHER QEMU floppy disk controller buffer overflow attempt (more info ...)attempted-admin 2015-3456 74640  
34486OS-OTHER QEMU floppy disk controller buffer overflow attempt (more info ...)attempted-admin 2015-3456 74640  
34487OS-OTHER QEMU floppy disk controller buffer overflow attempt (more info ...)attempted-admin 2015-3456 74640  
34488OS-OTHER QEMU floppy disk controller buffer overflow attempt (more info ...)attempted-admin 2015-3456 74640  
34489MALWARE-CNC Win.Trojan.Nalodew variant outbound connection (more info ...)trojan-activity    URL
34491MALWARE-CNC Win.Trojan.MalPutty variant outbound connection (more info ...)trojan-activity    URL
34501MALWARE-CNC Win.Backdoor.Wekby Torn variant outbound connection (more info ...)trojan-activity    URL
34540MALWARE-CNC Win.Trojan.Dalexis variant outbound connection (more info ...)trojan-activity    URL
34541MALWARE-CNC Win.Trojan.Dalexis variant outbound connection (more info ...)trojan-activity    URL
34567MALWARE-CNC MacOS.Trojan.MacVX outbound connection (more info ...)trojan-activity    URL
34572MALWARE-CNC Win.Trojan.Zinnemls variant outbound connection (more info ...)trojan-activity    URL
34581MALWARE-CNC Win.Trojan.Mathanuc outbound connection (more info ...)trojan-activity    URL
34595SERVER-OTHER OpenSSL handshake with potentially unseeded PRNG information disclosure attempt (more info ...)attempted-recon 2015-0285 73234  URL
34596MALWARE-CNC Win.Trojan.Atrax variant outbound connection (more info ...)trojan-activity    URL
34597MALWARE-CNC Win.Trojan.Atrax variant outbound connection (more info ...)trojan-activity    URL
34598MALWARE-CNC Win.Trojan.Kjdoom outbound connection (more info ...)trojan-activity    URL
34599MALWARE-CNC Win.Trojan.Kjdoom outbound connection (more info ...)trojan-activity    URL
34600MALWARE-CNC Win.Trojan.Kjdoom outbound connection (more info ...)trojan-activity    URL
34601MALWARE-CNC Win.Trojan.Teqimp outbound connection (more info ...)trojan-activity    URL
34603SERVER-OTHER IBM Tivoli Storage Manager FastBack buffer overflow attempt (more info ...)attempted-admin 2015-0120 74021  
34607MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Punkey (more info ...)trojan-activity    URL
34608MALWARE-CNC Win.Trojan.Punkey variant outbound connection (more info ...)trojan-activity    URL
34609MALWARE-CNC Trojan.NitLove variant outbound connection (more info ...)trojan-activity    URL
34610MALWARE-CNC Win.Trojan.Kayfcbk outbound connection (more info ...)trojan-activity    URL
34611MALWARE-CNC Win.Trojan.Dujfudg outbound connection (more info ...)trojan-activity    URL
34614MALWARE-CNC Win.Trojan.Enkalogs outbound connection (more info ...)trojan-activity    URL
34622MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
34624MALWARE-CNC Win.Trojan.Crypaura variant outbound connection (more info ...)trojan-activity    URL
34632SERVER-MAIL IBM Lotus Notes WPD attachment handling buffer overflow attempt (more info ...)attempted-admin 2008-4564 34086  
34636MALWARE-CNC Win.Trojan.Flactionbot outbound connection (more info ...)trojan-activity    URL
34637MALWARE-CNC Win.Trojan.Flactionbot outbound connection (more info ...)trojan-activity    URL
34645SERVER-MAIL Exim buffer overflow attempt (more info ...)attempted-admin 2004-0400   
34720EXPLOIT-KIT Angler exploit kit exploit download (more info ...)trojan-activity    
34818MALWARE-CNC Win.Trojan.Emdivi outbound connection (more info ...)attempted-user    URL
34831MALWARE-CNC Win.Trojan.Cozybear variant outbound connection (more info ...)trojan-activity    URL
34832MALWARE-CNC Win.Trojan.Cozybear variant outbound connection (more info ...)trojan-activity    URL
34833MALWARE-CNC Win.Trojan.Werdlod variant outbound connection (more info ...)trojan-activity    URL
34835MALWARE-CNC Win.Trojan.Neos outbound connection (more info ...)trojan-activity    URL
34840MALWARE-CNC Win.Trojan.DownExecute outbound connection (more info ...)trojan-activity    URL
34841MALWARE-CNC Win.Trojan.DownExecute outbound connection (more info ...)trojan-activity    URL
34842MALWARE-CNC Win.Trojan.DownExecute outbound connection (more info ...)trojan-activity    URL
34843MALWARE-CNC User-Agent known malicious user agent - EMERY - Win.Trojan.W97M (more info ...)trojan-activity    URL
34844MALWARE-CNC Win.Trojan.Adelinoq outbound connection (more info ...)trojan-activity    URL
34857MALWARE-CNC Win.Trojan.Fanny outbound connection (more info ...)trojan-activity 2010-2568   URL
34862MALWARE-CNC Win.Trojan.Wheelsof variant outbound connection (more info ...)trojan-activity    URL
34863MALWARE-CNC Win.Trojan.Wheelsof variant outbound connection (more info ...)trojan-activity    URL
34864INDICATOR-COMPROMISE Metasploit Meterpreter reverse HTTPS certificate (more info ...)misc-activity    URL
34865MALWARE-CNC Win.Trojan.Saibipoc outbound connection (more info ...)trojan-activity    URL
34866MALWARE-CNC Win.Trojan.Saibipoc outbound connection (more info ...)trojan-activity    URL
34867MALWARE-CNC Win.Trojan.Xobtide outbound connection (more info ...)trojan-activity    URL
34868MALWARE-CNC Win.Trojan.Rovnix variant outbound connection (more info ...)trojan-activity    URL
34869MALWARE-CNC Win.Trojan.XTalker outbound connection (more info ...)trojan-activity    URL
34870MALWARE-CNC Win.Trojan.Logreaz variant outbound connection (more info ...)trojan-activity    URL
34871MALWARE-CNC Win.Trojan.Logreaz variant outbound connection (more info ...)trojan-activity    URL
34872MALWARE-CNC Win.Trojan.Compfolder variant outbound connection (more info ...)trojan-activity    URL
34875SERVER-WEBAPP ManageEngine EventLog Analyzer cross site request forgery attempt (more info ...)attempted-user 2014-4930 74743  
34876MALWARE-CNC Win.Fudu outbound variant connection (more info ...)trojan-activity    URL
34877MALWARE-CNC Win.Trojan.Jemerr variant outbound connection (more info ...)trojan-activity    URL
34884BROWSER-PLUGINS Samsung iPOLiS device manager clsid access attempt (more info ...)attempted-user 2014-3912 67823  
34885BROWSER-PLUGINS Samsung iPOLiS device manager clsid access attempt (more info ...)attempted-user 2014-3912 67823  
34886MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
34887MALWARE-CNC Win.Trojan.Sojax variant outbound connection (more info ...)trojan-activity    URL
34888MALWARE-CNC Win.Trojan.Sojax variant outbound connection (more info ...)trojan-activity    URL
34889SERVER-OTHER OpenSSL denial-of-service via crafted x.509 certificate attempt (more info ...)attempted-dos 2015-0286   
34890FILE-OTHER Corel PaintShop Pro u32ZLib.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34891FILE-OTHER Corel PaintShop Pro u32Zlib.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34893FILE-OTHER Corel PaintShop Pro quserex.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34894FILE-OTHER Corel PaintShop Pro FxManagedCommands dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34895FILE-OTHER Corel PaintShop Pro FxManagedCommands dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34896FILE-OTHER Corel PaintShop Pro TD_Mgd_3.08_9.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34897FILE-OTHER Corel PaintShop Pro TD_Mgd_3.08_9.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34898FILE-OTHER Corel PaintShop Pro wacommt.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34899FILE-OTHER Corel PaintShop Pro wacommt.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34900FILE-OTHER Corel PaintShop Pro igfxcmrt32.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34901FILE-OTHER Corel PaintShop Pro igfxcmrt32.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34902FILE-OTHER Corel PaintShop Pro ipl.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34903FILE-OTHER Corel PaintShop Pro MSPStyleLib.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34904FILE-OTHER Corel PaintShop Pro MSPStyleLib.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34905FILE-OTHER Corel PaintShop Pro uFioUtil.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34906FILE-OTHER Corel PaintShop Pro uFioUtil.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34907FILE-OTHER Corel PaintShop Pro uhDSPlay.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34908FILE-OTHER Corel PaintShop Pro uhDSPlay.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34909FILE-OTHER Corel PaintShop Pro uipl.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34910FILE-OTHER Corel PaintShop Pro uvipl.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34911FILE-OTHER Corel PaintShop Pro VC1DecDll.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34912FILE-OTHER Corel PaintShop Pro VC1DecDll.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34913FILE-OTHER Corel PaintShop Pro VC1DecDll_SSE3.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34914FILE-OTHER Corel PaintShop Pro VC1DecDll_SSE3.dll dll-load exploit attempt (more info ...)attempted-user 2014-8393   URL
34927PUA-ADWARE PullUpdate installer outbound connection (more info ...)misc-activity    URL
34930MALWARE-OTHER Win.Trojan.Urausy outbound traffic attempt (more info ...)trojan-activity    URL
34931MALWARE-CNC Win.Trojan.Bancos variant outbound connection (more info ...)trojan-activity    URL
34932MALWARE-CNC Win.Trojan.Shindo outbound connection (more info ...)trojan-activity    URL
34934MALWARE-CNC Win.Trojan.Pheloyx outbound connection (more info ...)trojan-activity    URL
34935MALWARE-CNC Win.Trojan.Zutwoxy outbound connection (more info ...)trojan-activity    URL
34936MALWARE-CNC Win.Trojan.Swaylib variant outbound connection (more info ...)trojan-activity    URL
34950MALWARE-CNC Win.Trojan.Prok variant outbound connection (more info ...)trojan-activity    URL
34952SERVER-OTHER OpenSSL invalid PSS parameter denial of service attempt (more info ...)attempted-dos 2015-0208   
34953SERVER-OTHER OpenSSL invalid PSS parameter denial of service attempt (more info ...)attempted-dos 2015-0208   
34955SERVER-OTHER OpenSSL invalid PSS parameter denial of service attempt (more info ...)attempted-dos 2015-0208   
34957MALWARE-CNC Win.Trojan.Sysmain outbound connection (more info ...)trojan-activity    URL
34958MALWARE-CNC Win.Trojan.Androm variant outbound connection (more info ...)trojan-activity    URL
34959MALWARE-CNC Win.Trojan.SpyBanker variant outbound connection (more info ...)trojan-activity    URL
34960SERVER-WEBAPP SysAid Help Desk RdsLogsEntry servlet directory traversal attempt (more info ...)web-application-attack 2015-2995 75038  
34961SERVER-WEBAPP SysAid Help Desk RdsLogsEntry servlet directory traversal attempt (more info ...)web-application-attack 2015-2995 75038  
34962SERVER-WEBAPP SysAid Help Desk RdsLogsEntry servlet directory traversal attempt (more info ...)web-application-attack 2015-2995 75038  
34963MALWARE-CNC Win.Trojan.Threebyte outbound connection (more info ...)trojan-activity    URL
34964PUA-ADWARE Win.Adware.Sendori user-agent detection (more info ...)misc-activity    URL
34965MALWARE-CNC Win.Trojan.Cryptolocker outbound connection (more info ...)trojan-activity    URL
34966MALWARE-CNC Win.Trojan.Cyvadextr variant outbound connection (more info ...)trojan-activity    URL
34979SERVER-WEBAPP SysAid Help Desk getAgentLogFile directory traversal attempt (more info ...)web-application-attack 2015-2997 75038  
34980SERVER-WEBAPP SysAid Help Desk getAgentLogFile directory traversal attempt (more info ...)web-application-attack 2015-2997 75038  
34981SERVER-WEBAPP SysAid Help Desk getAgentLogFile directory traversal attempt (more info ...)web-application-attack 2015-2997 75038  
34982MALWARE-CNC Win.Trojan.Msnmm variant outbound connection (more info ...)trojan-activity    URL
34984FILE-OTHER VMWare Workstation JPEG2000 stack overflow attempt (more info ...)attempted-admin 2012-0897   URL
34985FILE-OTHER VMWare Workstation JPEG2000 stack overflow attempt (more info ...)attempted-admin 2012-0897   URL
34986FILE-OTHER VMWare Workstation JPEG2000 stack overflow attempt (more info ...)attempted-admin 2012-0897   URL
34987FILE-OTHER VMWare Workstation JPEG2000 stack overflow attempt (more info ...)attempted-admin 2012-0897   URL
34994MALWARE-CNC Win.Trojan.Banbra variant outbound connection (more info ...)trojan-activity    URL
34995MALWARE-CNC Win.Trojan.Banbra HTTP Header Structure (more info ...)trojan-activity    URL
34996MALWARE-CNC Win.Trojan.Agent-ALPW variant outbound connection (more info ...)trojan-activity    URL
34997MALWARE-CNC Win.Trojan.Graftor variant HTTP Response (more info ...)trojan-activity    URL
34998MALWARE-CNC Win.Trojan.Bossabot outbound connection (more info ...)trojan-activity    URL
35005MALWARE-CNC Win.Trojan.Vcaredrix variant outbound connection (more info ...)trojan-activity    URL
35027MALWARE-CNC known malicious SSL certificate - Troldesh C&C (more info ...)trojan-activity    URL
35029MALWARE-CNC Win.Keylogger.Lotronc variant outbound connection (more info ...)trojan-activity    URL
35030MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
35031MALWARE-CNC Win.Trojan.Konus outbound connection (more info ...)trojan-activity    URL
35034MALWARE-CNC Win.Downloader.Boltolog variant outbound connection download request (more info ...)trojan-activity    URL
35035MALWARE-CNC Win.Trojan.Taleretzbj outbound connection (more info ...)trojan-activity    URL
35036MALWARE-CNC Backdoor.Perl.Santy inbound variant connection (more info ...)trojan-activity    URL
35037MALWARE-CNC Backdoor.Perl.Santy outbound variant connection (more info ...)trojan-activity    URL
35038SERVER-OTHER Trustwave ModSecurity chunked transfer encoding policy bypass attempt (more info ...)attempted-user 2013-5705   URL
35042POLICY-OTHER Apple Cups cupsd.conf change attempt (more info ...)policy-violation    
35047MALWARE-CNC Win.Trojan.Scar variant outbound connection (more info ...)trojan-activity    URL
35050MALWARE-CNC Win.Trojan.Elise variant outbound connection (more info ...)trojan-activity    URL
35060PROTOCOL-OTHER TRUFFLEHUNTER SFVRT-1018 attack attempt (more info ...)attempted-dos    
35069MALWARE-CNC Win.Trojan.Dino variant outbound connection (more info ...)trojan-activity    URL
35076MALWARE-CNC Win.Zusy variant outbound connection (more info ...)trojan-activity    URL
35080MALWARE-CNC Win.Trojan.Tenbus outbound connection (more info ...)trojan-activity    URL
35081MALWARE-CNC Win.Trojan.Tenbus outbound connection (more info ...)trojan-activity    URL
35083MALWARE-CNC Win.Trojan.Regiskazi outbound connection (more info ...)trojan-activity    URL
35097POLICY-OTHER IPv6 neighbor solicitation - THC-IPv6 tool indicator attempt (more info ...)misc-activity    URL
35098POLICY-OTHER IPv6 neighbor solicitation - THC-IPv6 tool indicator attempt (more info ...)misc-activity    URL
35101MALWARE-CNC Win.Trojan.Dridex variant outbound connection (more info ...)trojan-activity    URL
35104MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
35111SERVER-OTHER OpenSSL anomalous x509 certificate with default org name and certificate chain detected (more info ...)misc-attack 2015-1793   URL
35221MALWARE-CNC Win.Dropper.Agent inbound connection (more info ...)trojan-activity    URL
35251SERVER-OTHER Advantech ADAMView conditional bitmap buffer overflow attempt (more info ...)attempted-user 2014-8386   URL
35252SERVER-OTHER Advantech ADAMView conditional bitmap buffer overflow attempt (more info ...)attempted-user 2014-8386   URL
35254MALWARE-CNC Win.trojan.Seaduke outbound connection (more info ...)trojan-activity    URL
35300MALWARE-CNC Win.Trojan.Lpdsuite GET request (more info ...)trojan-activity    URL
35301MALWARE-CNC Win.Trojan.Lpdsuite POST request (more info ...)trojan-activity    URL
35303MALWARE-CNC Win.Trojan.ProxyChange (more info ...)trojan-activity    URL
35306MALWARE-CNC Trojan.Win32.Cigamve request (more info ...)trojan-activity    URL
35307SERVER-OTHER OpenSSL alternative chains certificate forgery attempt (more info ...)misc-attack 2015-1793   URL
35312MALWARE-CNC Win.Trojan.Ursnif outbound connection (more info ...)trojan-activity    URL
35313MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
35316MALWARE-CNC User-Agent known malicious user-agent string EI Plugin updater (more info ...)trojan-activity    URL
35317MALWARE-CNC Win.Trojan.Directate outbound connection (more info ...)trojan-activity    URL
35318MALWARE-CNC Win.Trojan.Jemerr outbound connection (more info ...)trojan-activity    URL
35344MALWARE-CNC Win.Trojan.Cryptowall click fraud response (more info ...)trojan-activity    URL
35348MALWARE-CNC Trojan.Win32.Ralminey POST request (more info ...)trojan-activity    URL
35353MALWARE-CNC Win.Trojan.Elise.B variant outbound connection (more info ...)trojan-activity    URL
35355MALWARE-CNC Win.Trojan.Usteal outbound connection (more info ...)trojan-activity    URL
35386MALWARE-CNC Win.Trojan.Bedep initial outbound connection (more info ...)trojan-activity    URL
35387MALWARE-CNC Win.Trojan.Andromeda initial outbound connection (more info ...)trojan-activity    URL
35388MALWARE-CNC Win.Trojan.Andromeda download request (more info ...)trojan-activity    URL
35393MALWARE-CNC Win.Trojan.TorrentLocker/Teerac self-signed certificate (more info ...)trojan-activity    URL
35394MALWARE-CNC Win.Trojan.TorrentLocker/Teerac payment page request (more info ...)trojan-activity    URL
35396BROWSER-PLUGINS Oracle Data Quality DateTimeWrapper onchange untrusted pointer dereference attempt (more info ...)attempted-user 2014-2416   URL
35397BROWSER-PLUGINS Oracle Data Quality DateTimeWrapper onchange untrusted pointer dereference attempt (more info ...)attempted-user 2014-2416   URL
35398BROWSER-PLUGINS Oracle Data Quality DateTimeWrapper onchange untrusted pointer dereference attempt (more info ...)attempted-user 2014-2416   URL
35400MALWARE-CNC Win.Trojan.Inexsmar variant outbound connection (more info ...)trojan-activity    URL
35402BROWSER-PLUGINS Oracle Data Quality Postcard PreviewInt onclose untrusted pointer dereference attempt (more info ...)attempted-user 2014-2415   URL
35403BROWSER-PLUGINS Oracle Data Quality Postcard PreviewInt onclose untrusted pointer dereference attempt (more info ...)attempted-user 2014-2415   URL
35404BROWSER-PLUGINS Oracle Data Quality Postcard PreviewInt onclose untrusted pointer dereference attempt (more info ...)attempted-user 2014-2415   URL
35405SERVER-OTHER HP Release Control authenticated privilege escalation attempt (more info ...)attempted-admin    URL
35413FILE-MULTIMEDIA Apple iLife iPhoto Photocast XML format string code injection attempt (more info ...)attempted-user 2007-0051 21871  
35414FILE-MULTIMEDIA Apple iLife iPhoto Photocast XML format string code injection attempt (more info ...)attempted-user 2007-0051 21871  
35415MALWARE-CNC Win.Trojan.Sakurel outbound connection (more info ...)trojan-activity    URL
35416MALWARE-CNC Win.Trojan.Mivast outbound connection (more info ...)trojan-activity    URL
35417SERVER-OTHER Fortinet Single Sign On hello message denial of service attempt (more info ...)denial-of-service 2015-2281 73206  
35418SERVER-OTHER Fortinet Single Sign On hello message denial of service attempt (more info ...)denial-of-service 2015-2281 73206  
35419BROWSER-PLUGINS Scneider Electric IsObjectModel RemoveParameter buffer overflow attempt (more info ...)attempted-user 2014-9200   URL
35420BROWSER-PLUGINS Scneider Electric IsObjectModel RemoveParameter buffer overflow attempt (more info ...)attempted-user 2014-9200   URL
35422BROWSER-PLUGINS Scneider Electric IsObjectModel RemoveParameter buffer overflow attempt (more info ...)attempted-user 2014-9200   URL
35426MALWARE-CNC Win.Trojan.Heur outbound connection (more info ...)trojan-activity    URL
35436MALWARE-CNC Win.Trojan.BlackCoffee outbound connection (more info ...)trojan-activity    URL
35437MALWARE-CNC Win.Downloader.Jrml variant outbound connection (more info ...)trojan-activity    URL
35444BROWSER-PLUGINS Oracle Data Quality LoaderWizard DataPreview type confusion attempt (more info ...)attempted-user 2015-0446   
35445BROWSER-PLUGINS Oracle Data Quality LoaderWizard DataPreview type confusion attempt (more info ...)attempted-user 2015-0446   
35446BROWSER-PLUGINS Oracle Data Quality LoaderWizard DataPreview type confusion attempt (more info ...)attempted-user 2015-0446   
35447BROWSER-PLUGINS Oracle Data Quality LoaderWizard DataPreview type confusion attempt (more info ...)attempted-user 2015-0446   
35448MALWARE-CNC Win.Trojan.Bedep variant outbound connection (more info ...)trojan-activity    URL
35462MALWARE-CNC Win.Trojan.Kazy outbound connection (more info ...)trojan-activity    URL
35471MALWARE-CNC Win.Trojan.Baisogu outbound connection (more info ...)trojan-activity    URL
35472MALWARE-CNC Win.Trojan.Bergard outbound connection (more info ...)trojan-activity    URL
35538POLICY-OTHER EMC AutoStart ftagent insecure opcode 20 subcode 2060 access attempt (more info ...)policy-violation 2015-0538 74426  
35539POLICY-OTHER EMC AutoStart ftagent insecure opcode 20 subcode 2219 access attempt (more info ...)policy-violation 2015-0538 74426  
35549MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
35550EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity    
35551MALWARE-CNC Win.Trojan.BlackCoffee outbound connection (more info ...)trojan-activity    URL
35552SERVER-MAIL cURL protocol file path URL parsing control character injection attempt (more info ...)attempted-user 2012-0036 51665  URL
35553SERVER-MAIL cURL protocol file path URL parsing control character injection attempt (more info ...)attempted-user 2012-0036 51665  URL
35554SERVER-MAIL cURL protocol file path URL parsing control character injection attempt (more info ...)attempted-user 2012-0036 51665  URL
35555SERVER-MAIL cURL protocol file path URL parsing control character injection attempt (more info ...)attempted-user 2012-0036 51665  URL
35570MALWARE-CNC Win.Trojan.NetEagle variant outbound connection (more info ...)trojan-activity    URL
35594SERVER-WEBAPP Websense Triton Content Manager handle_debug_network stack buffer overflow attempt (more info ...)attempted-admin 2015-5718 75160  
35596MALWARE-CNC Win.Trojan.Nibagem outbound variant connection (more info ...)trojan-activity    URL
35597MALWARE-CNC Win.Trojan.Nibagem outbound variant connection (more info ...)trojan-activity    URL
35611SERVER-WEBAPP Symantec Endpoint Protection directory traversal attempt (more info ...)web-application-attack 2015-1488   URL
35612SERVER-WEBAPP Symantec Endpoint Protection directory traversal attempt (more info ...)web-application-attack 2015-1488   URL
35613SERVER-WEBAPP Symantec Endpoint Protection directory traversal attempt (more info ...)web-application-attack 2015-1488   URL
35630SERVER-OTHER LibVNCServer rfbProcessClientNormalMessage msg.ssc.scale denial of service attempt (more info ...)denial-of-service 2014-6054   URL
35631SERVER-OTHER LibVNCServer rfbProcessClientNormalMessage msg.ssc.scale denial of service attempt (more info ...)denial-of-service 2014-6054   URL
35689PROTOCOL-OTHER MiniUPNP rootdesc.xml buffer overflow attempt (more info ...)attempted-user 2015-6031   URL
35707SERVER-WEBAPP Pimcore CMS add-asset-compatibility directory traversal attempt (more info ...)web-application-attack 2015-4425 75729  
35708SERVER-WEBAPP Pimcore CMS add-asset-compatibility directory traversal attempt (more info ...)web-application-attack 2015-4425 75729  
35709SERVER-WEBAPP Pimcore CMS add-asset-compatibility directory traversal attempt (more info ...)web-application-attack 2015-4425 75729  
35729OS-WINDOWS TRUFFLEHUNTER TALOS-2015-0009 attack attempt (more info ...)attempted-admin    URL
35730OS-WINDOWS TRUFFLEHUNTER TALOS-2015-0009 attack attempt (more info ...)attempted-admin    URL
35732MALWARE-CNC Win.Trojan.Naberkalara variant outbound connection (more info ...)trojan-activity    URL
35733MALWARE-CNC Win.Trojan.Potao outbound connection (more info ...)trojan-activity    URL
35734SERVER-WEBAPP Netgear WNDR4700 and R6200 admin interface authentication bypass attempt (more info ...)attempted-admin 2013-3071 59406  
35746MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
35749MALWARE-CNC Win.Backdoor.IsSpace outbound connection (more info ...)trojan-activity    URL
35750MALWARE-CNC Win.Backdoor.IsSpace initial outbound connection (more info ...)trojan-activity    URL
35763SERVER-OTHER gnuTLS _asn1_extract_der_octet memory error inbound malicious server dos attempt (more info ...)attempted-dos 2015-3622 74419  URL
35764SERVER-OTHER gnuTLS _asn1_extract_der_octet memory error inbound malicious server dos attempt (more info ...)attempted-dos 2015-3622 74419  URL
35765SERVER-OTHER gnuTLS _asn1_extract_der_octet memory error inbound malicious client dos attempt (more info ...)attempted-dos 2015-3622 74419  URL
35766SERVER-OTHER gnuTLS _asn1_extract_der_octet memory error inbound malicious client dos attempt (more info ...)attempted-dos 2015-3622 74419  URL
35773FILE-MULTIMEDIA Matroska libmatroska track video double free attempt (more info ...)attempted-user 2015-8790   URL
35774FILE-MULTIMEDIA Matroska libmatroska track video double free attempt (more info ...)attempted-user 2015-8790   URL
35775FILE-MULTIMEDIA Matroska libmatroska track video double free attempt (more info ...)attempted-user 2015-8790   URL
35776FILE-MULTIMEDIA Matroska libmatroska track video double free attempt (more info ...)attempted-user 2015-8790   URL
35777FILE-MULTIMEDIA Matroska libmatroska track video double free attempt (more info ...)attempted-user 2015-8790   URL
35778FILE-MULTIMEDIA Matroska libmatroska track video double free attempt (more info ...)attempted-user 2015-8790   URL
35783MALWARE-CNC Win.Trojan.Jiripbot variant outbound connection (more info ...)trojan-activity    URL
35794MALWARE-CNC Win.Trojan.TeslaCrypt outbound connection (more info ...)trojan-activity    URL
35804MALWARE-CNC Win.Trojan.Seyelifon variant outbound connection (more info ...)trojan-activity    URL
35817SERVER-WEBAPP Oracle Endeca Server RenameFile method directory traversal attempt (more info ...)attempted-admin 2015-2606 75758  
35818SERVER-WEBAPP Oracle Endeca Server RenameFile method directory traversal attempt (more info ...)attempted-admin 2015-2606 75758  
35826FILE-OTHER TAR archive with absolute path detected (more info ...)policy-violation 2014-3697   URL
35827FILE-OTHER TAR archive with absolute path detected (more info ...)policy-violation 2014-3697   URL
35831SERVER-OTHER multiple vendors NTP daemon integer overflow attempt (more info ...)attempted-dos 2015-7848   URL
35842MALWARE-CNC Win.Trojan.Namospu variant outbound connection (more info ...)trojan-activity    URL
35843SERVER-WEBAPP Oracle Endeca Server MoveFile method directory traversal attempt (more info ...)attempted-admin 2015-2605 75756  
35844SERVER-WEBAPP Oracle Endeca Server MoveFile method directory traversal attempt (more info ...)attempted-admin 2015-2605 75756  
35847SERVER-WEBAPP Oracle Endeca server directory traversal attempt (more info ...)attempted-admin 2015-4745 75758  
35851SERVER-OTHER QEMU VNC set-pixel-format memory corruption attempt (more info ...)attempted-user 2014-7815 70998  
35884POLICY-OTHER MBean retrieval attempt (more info ...)policy-violation    URL
35889PROTOCOL-SCADA Kaskad SCADA arbitrary command execution attempt (more info ...)policy-violation    
35895SERVER-OTHER Hewlett-Packard Radia Client Automation VerbData buffer overflow attempt (more info ...)attempted-admin    
35904SERVER-OTHER SCADA InduSoft Web Studio buffer overflow attempt (more info ...)attempted-user    
35914SERVER-OTHER EMC AutoStart ftAgent.exe trigger creation attempt (more info ...)policy-violation    
35915SERVER-OTHER EMC AutoStart ftAgent.exe rule creation attempt (more info ...)policy-violation    
35916SERVER-OTHER Websense Triton Web Security untrusted remote file creation attempt (more info ...)policy-violation    
35917SERVER-OTHER Websense Triton Web Security untrusted remote file creation attempt (more info ...)policy-violation    
35918SERVER-OTHER EMC NetWorker server overflow attempt (more info ...)attempted-admin    
35919SERVER-OTHER Vinzant Global ECS Agent untrusted command execution attempt (more info ...)policy-violation    
35921SERVER-OTHER General Electric Proficy malicious log forwarding request attempt (more info ...)attempted-recon    
35923SERVER-WEBAPP LANDesk Management Suite arbitrary remote file upload attempt (more info ...)web-application-attack    
35924SERVER-WEBAPP Oracle Directory Services Manager remote jsp code execution attempt (more info ...)attempted-admin    
35925SERVER-WEBAPP Oracle Directory Services Manager LDAP plugin field null byte injection attempt (more info ...)attempted-admin    
35939FILE-MULTIMEDIA PLF playlist name buffer overflow attempt (more info ...)attempted-user 2006-6199 21337  
35988FILE-EXECUTABLE NtGdiStretchBlt buffer overflow privilege escalation attempt (more info ...)attempted-admin 2015-2512   URL
35989FILE-EXECUTABLE NtGdiStretchBlt buffer overflow privilege escalation attempt (more info ...)attempted-admin 2015-2512   URL
36025SERVER-OTHER Multiple Products TLS certificate common name null byte validation bypass attempt (more info ...)misc-attack 2022-20813 74022  URL
36048MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
36054MALWARE-CNC Ios.Backdoor.SYNful inbound connection (more info ...)trojan-activity    URL
36060MALWARE-CNC Win.Trojan.Shifu variant outbound connection (more info ...)trojan-activity    URL
36064MALWARE-CNC Win.Trojan.Bagsu variant outbound connection (more info ...)trojan-activity    URL
36065MALWARE-CNC Win.Trojan.Bagsu variant outbound connection (more info ...)trojan-activity    URL
36066MALWARE-CNC Win.Trojan.Bagsu variant outbound connection (more info ...)trojan-activity    URL
36067SERVER-OTHER ElasticSearch script remote code execution attempt (more info ...)attempted-user 2015-1427   URL
36072SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36073SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36074SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36075SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36076SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36077SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36078SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36079SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36080SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36081SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36082SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36083SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36084SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36085SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36086SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36087SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36088SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36089SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36090SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36091SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36092SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36093SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36094SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36095SERVER-OTHER Dell Netvault Backup remote denial of service attempt (more info ...)attempted-dos 2015-5696 76122  URL
36096SERVER-OTHER OpenSSL DTLS handshake oversized fragment length denial of service attempt (more info ...)attempted-dos 2014-3506 69076  URL
36100SERVER-WEBAPP ManageEngine OpManager default credentials authentication attempt (more info ...)attempted-admin 2015-7765   URL
36105MALWARE-CNC Win.Trojan.Hodoor APT variant (more info ...)trojan-activity    URL
36106MALWARE-CNC Win.Trojan.Hodoor APT variant outbound connection (more info ...)trojan-activity    URL
36107MALWARE-CNC Win.Trojan.FakeAV variant outbound connection (more info ...)trojan-activity    URL
36108MALWARE-CNC Win.Trojan.Nimisi variant outbound connection (more info ...)trojan-activity    URL
36115MALWARE-CNC Win.Backdoor.Liudoor outbound connection (more info ...)trojan-activity    URL
36131MALWARE-CNC User-Agent known malicious user-agent string - MyIE 3.01 (more info ...)trojan-activity    URL
36132MALWARE-CNC Win.Trojan.Mitozhan initial outbound connection (more info ...)trojan-activity    URL
36133MALWARE-CNC Win.Trojan.Mitozhan initial outbound connection server response (more info ...)trojan-activity    URL
36134MALWARE-CNC Win.Trojan.Mitozhan initial outbound connection (more info ...)trojan-activity    URL
36182SERVER-WEBAPP Ignite Realtime Openfire server-session-details cross site scripting attempt (more info ...)attempted-user    URL
36183SERVER-WEBAPP Ignite Realtime Openfire create-bookmark cross site scripting attempt (more info ...)attempted-user 2015-6972   
36184SERVER-WEBAPP Ignite Realtime Openfire group-summary cross site scripting attempt (more info ...)attempted-user 2015-6972   
36186MALWARE-CNC Win.Trojan.Qytags variant outbound connection (more info ...)trojan-activity    URL
36194POLICY-OTHER BitTorrent distributed reflected denial-of-service attempt (more info ...)attempted-dos    URL
36195SERVER-WEBAPP Reprise license manager actserver and akey HTTP parameters parsing stack buffer overflow attempt (more info ...)attempted-user    URL
36196SERVER-WEBAPP Reprise license manager actserver and akey HTTP parameters parsing stack buffer overflow attempt (more info ...)attempted-user    URL
36198MALWARE-CNC Win.Trojan.Yakes variant certificate (more info ...)trojan-activity    URL
36199MALWARE-CNC Win.Trojan.Yakes variant outbound connection (more info ...)trojan-activity    URL
36202MALWARE-CNC Win.Trojan.Yakes variant dropper (more info ...)trojan-activity    URL
36231MALWARE-CNC Win.Trojan.SdBot variant outbound connection (more info ...)trojan-activity    URL
36232MALWARE-CNC Win.Trojan.Kapento variant outbound connection (more info ...)trojan-activity    URL
36233MALWARE-CNC Win.Trojan.Kapento variant outbound connection (more info ...)trojan-activity    URL
36234MALWARE-CNC Win.Trojan.Kapento variant outbound connection (more info ...)trojan-activity    URL
36243SERVER-WEBAPP LANDesk Management Suite frm_splitfrm remote file include attempt (more info ...)web-application-attack 2014-5362   URL
36247SERVER-OTHER IRC w3wt0rk pitbull perl bot remote command execution attempt (more info ...)attempted-user    URL
36248SERVER-OTHER IRC w3wt0rk pitbull perl bot remote command execution attempt (more info ...)attempted-user    URL
36250SERVER-OTHER ntpd keyfile buffer overflow attempt (more info ...)attempted-admin 2015-7854   URL
36251SERVER-OTHER ntpq atoascii memory corruption attempt (more info ...)attempted-user 2015-7852   URL
36252SERVER-OTHER ntpd remote configuration denial of service attempt (more info ...)attempted-dos 2015-7850   URL
36253SERVER-OTHER ntpd saveconfig directory traversal attempt (more info ...)attempted-admin 2015-7851   URL
36254SERVER-WEBAPP IBM Rational Focal Point webservice Axis Gateway GET vulnerability attempt (more info ...)attempted-user 2013-5398   URL
36255SERVER-WEBAPP IBM Rational Focal Point webservice Axis Gateway POST vulnerability attempt (more info ...)attempted-user 2013-5398   URL
36256SERVER-OTHER ElasticSearch information disclosure attempt (more info ...)policy-violation 2014-3120   URL
36267MALWARE-CNC Win.Trojan.Rusrushel variant outbound connection (more info ...)trojan-activity    URL
36268MALWARE-CNC Win.Trojan.Rusrushel variant outbound connection (more info ...)trojan-activity    URL
36269MALWARE-CNC Win.Trojan.Rusrushel variant outbound connection (more info ...)trojan-activity    URL
36275MALWARE-CNC Win.Trojan.Corebot variant outbound connection (more info ...)trojan-activity    URL
36276MALWARE-CNC Win.Trojan.Corebot variant outbound connection (more info ...)trojan-activity    URL
36281EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)trojan-activity    
36294MALWARE-CNC Win.Backdoor.Nisinul variant outbound connection (more info ...)trojan-activity    URL
36303MALWARE-CNC Win.Trojan.Mitozhan initial outbound connection server response (more info ...)trojan-activity    URL
36304MALWARE-CNC Win.Trojan.WinPlock variant outbound connection (more info ...)trojan-activity    URL
36305FILE-PDF Foxit Reader PNG to PDF conversion heap buffer overflow attempt (more info ...)attempted-user    URL
36306FILE-PDF Foxit Reader PNG to PDF conversion heap buffer overflow attempt (more info ...)attempted-user    URL
36325MALWARE-CNC Win.Trojan.MSIL.Misnt variant outbound connection (more info ...)trojan-activity    URL
36326MALWARE-CNC Win.Trojan.MSIL.Misnt variant outbound connection (more info ...)trojan-activity    URL
36327MALWARE-CNC Win.Trojan.MSIL.Misnt variant outbound connection (more info ...)trojan-activity    URL
36328MALWARE-CNC Win.Trojan.MSIL.Misnt variant outbound connection (more info ...)trojan-activity    URL
36329MALWARE-CNC Win.Trojan.MSIL.Misnt variant outbound connection (more info ...)trojan-activity    URL
36331MALWARE-CNC Win.Trojan.Alina variant outbound connection (more info ...)trojan-activity    URL
36335SERVER-WEBAPP Ignite Realtime Openfire user-create cross site request forgery attempt (more info ...)attempted-user 2015-6973   
36336SERVER-WEBAPP Ignite Realtime Openfire server properties cross site request forgery attempt (more info ...)attempted-user 2015-6973   
36337SERVER-WEBAPP Ignite Realtime Openfire permitted-clients cross site request forgery attempt (more info ...)attempted-user 2015-6973   
36359SERVER-WEBAPP pfSense WebGui Zone Parameter cross-site scripting attempt (more info ...)attempted-user 2015-4029   URL
36363SERVER-WEBAPP Typo3 CMS show_rechis cross site scripting attempt (more info ...)attempted-user 2015-5956   URL
36364SERVER-WEBAPP Typo3 CMS index cross site scripting attempt (more info ...)attempted-user 2015-5956   URL
36365SERVER-WEBAPP Typo3 CMS show_rechis cross site scripting attempt (more info ...)attempted-user 2015-5956   URL
36366SERVER-WEBAPP Typo3 CMS index cross site scripting attempt (more info ...)attempted-user 2015-5956   URL
36376SERVER-OTHER IBM Tivoli Management Framework lcfd endpoint daemon buffer overflow attempt (more info ...)attempted-user 2011-1220 48049  URL
36396MALWARE-CNC Win.Trojan.DustySky variant outbound connection (more info ...)trojan-activity    URL
36397MALWARE-CNC Win.Trojan.DustySky variant outbound connection (more info ...)trojan-activity    URL
36400SERVER-WEBAPP OpenDocMan redirection parameter cross site scripting attempt (more info ...)attempted-user 2015-5625 76627  URL
36407OS-WINDOWS RDP client dll-load exploit attempt (more info ...)attempted-user 2015-6051   URL
36408OS-WINDOWS RDP client dll-load exploit attempt (more info ...)attempted-user 2015-6051   URL
36409OS-WINDOWS RDP client dll-load exploit attempt (more info ...)attempted-user 2015-6051   URL
36410OS-WINDOWS RDP client dll-load exploit attempt (more info ...)attempted-user 2015-6051   URL
36454SERVER-OTHER multiple products WinExec function remote code execution attempt (more info ...)attempted-user 2015-7374   URL
36455SERVER-OTHER Schneider Electric InduSoft Web Studio Remote Agent remote code execution attempt (more info ...)attempted-user 2015-7374   URL
36456FILE-MULTIMEDIA MultiMedia Soft Components AdjMmsEng.dll PLS file processing buffer overflow attempt (more info ...)attempted-user 2009-5109 33589  
36460MALWARE-CNC Win.Trojan.CenterPos outbound connection (more info ...)trojan-activity    URL
36463SERVER-OTHER IBM Tivoli Storage Manager FastBack Server opcode 1332 buffer overflow attempt (more info ...)attempted-admin 2015-1925 75449  
36468MALWARE-CNC Win.Trojan.AridViper variant outbound connection (more info ...)trojan-activity    URL
36469MALWARE-CNC Win.Trojan.AridViper variant outbound connection (more info ...)trojan-activity    URL
36471MALWARE-CNC Andr.Trojan.Kemoge outbound connection (more info ...)trojan-activity    URL
36492EXPLOIT-KIT Neutrino exploit kit gate detected (more info ...)attempted-user    URL
36497MALWARE-CNC Win.Trojan.Hangman.A outbound connection (more info ...)trojan-activity    URL
36506MALWARE-CNC Win.Trojan.Njrat variant outbound connection (more info ...)trojan-activity    URL
36511SERVER-WEBAPP Ignite Realtime Openfire server properties cross site request forgery attempt (more info ...)attempted-user 2015-6973   
36522MALWARE-CNC Win.Trojan.Banker.NWT variant outbound connection (more info ...)trojan-activity    URL
36523EXPLOIT-KIT Sundown exploit kit landing page detected (more info ...)attempted-user    URL
36526MALWARE-CNC Win.Trojan.MSIL.Misnt variant outbound connection (more info ...)trojan-activity    URL
36535EXPLOIT-KIT Neutrino exploit kit landing page detected (more info ...)attempted-user    
36536SERVER-OTHER NTP crypto-NAK packet flood attempt (more info ...)misc-activity 2016-1550   URL
36540MALWARE-CNC Win.Trojan.Brolux variant outbound connection (more info ...)trojan-activity    URL
36541POLICY-OTHER Polycom Botnet inbound connection attempt (more info ...)trojan-activity    URL
36545SERVER-OTHER Avast Antivirus X.509 Common Name remote code execution attempt (more info ...)attempted-user    
36546SERVER-OTHER Avast Antivirus X.509 Common Name remote code execution attempt (more info ...)attempted-user    
36547SERVER-OTHER Avast Antivirus X.509 Common Name remote code execution attempt (more info ...)attempted-user    
36548SERVER-OTHER Avast Antivirus X.509 Common Name remote code execution attempt (more info ...)attempted-user    
36564FILE-MULTIMEDIA libav LZO integer overflow attempt (more info ...)attempted-user 2014-4609 68217  
36565FILE-MULTIMEDIA libav LZO integer overflow attempt (more info ...)attempted-user 2014-4609 68217  
36566MALWARE-CNC Win.Trojan.MSIL.Troloscup outbound variant connection (more info ...)trojan-activity    URL
36567MALWARE-CNC Win.Trojan.MSIL.Troloscup outbound variant connection (more info ...)trojan-activity    URL
36568MALWARE-CNC Win.Trojan.MSIL.Troloscup outbound variant connection (more info ...)trojan-activity    URL
36569MALWARE-CNC Win.Trojan.MSIL.Troloscup outbound variant connection (more info ...)trojan-activity    URL
36570MALWARE-CNC Win.Trojan.MSIL.Troloscup outbound variant connection (more info ...)trojan-activity    URL
36571MALWARE-CNC Win.Trojan.MSIL.Troloscup outbound variant connection (more info ...)trojan-activity    URL
36572MALWARE-CNC Win.Trojan.MSIL.Troloscup outbound variant connection (more info ...)trojan-activity    URL
36577MALWARE-CNC Win.Trojan.MSIL.Stimilik outbound variant connection (more info ...)trojan-activity    URL
36578MALWARE-CNC Win.Trojan.MSIL.Stimilik outbound variant connection (more info ...)trojan-activity    URL
36579MALWARE-CNC Win.Trojan.Slackbot variant outbound connection (more info ...)trojan-activity    URL
36580MALWARE-CNC Win.Trojan.Slackbot variant outbound connection (more info ...)trojan-activity    URL
36601MALWARE-CNC Win.Trojan.QVKeylogger outbound variant connection (more info ...)trojan-activity    URL
36602MALWARE-CNC Win.Trojan.QVKeylogger outbound variant connection (more info ...)trojan-activity    URL
36603MALWARE-CNC Win.Trojan.QVKeylogger outbound variant connection (more info ...)trojan-activity    URL
36610MALWARE-CNC Win.Trojan.Panskeg outbound connection (more info ...)trojan-activity    URL
36611INDICATOR-COMPROMISE Metasploit Meterpreter reverse HTTPS certificate (more info ...)misc-activity    URL
36612INDICATOR-COMPROMISE Metasploit Meterpreter reverse HTTPS certificate (more info ...)misc-activity    URL
36613SERVER-WEBAPP McAfee Cloud Single Sign ExtensionAccessServlet directory traversal attempt (more info ...)web-application-attack 2014-2536 66181  
36614SERVER-WEBAPP McAfee Cloud Single Sign ExtensionAccessServlet directory traversal attempt (more info ...)web-application-attack 2014-2536 66181  
36622MALWARE-CNC Win.Trojan.Wedots outbound variant connection (more info ...)trojan-activity    URL
36623MALWARE-CNC Win.Trojan.Wedots outbound variant connection (more info ...)trojan-activity    URL
36624MALWARE-CNC Win.Trojan.Wedots outbound variant connection (more info ...)trojan-activity    URL
36625MALWARE-CNC Windows.Backdoor.Quaverse outbound variant connection (more info ...)trojan-activity    URL
36626MALWARE-CNC Windows.Backdoor.Quaverse outbound variant connection (more info ...)trojan-activity    URL
36627MALWARE-CNC Win.Trojan.Tanmar outbound connection (more info ...)trojan-activity    URL
36628MALWARE-CNC Win.Trojan.Recodler variant outbound connection (more info ...)trojan-activity    URL
36629MALWARE-CNC Win.Trojan.Teabevil variant outbound connection (more info ...)trojan-activity    URL
36630MALWARE-CNC Win.Trojan.Teabevil variant outbound connection (more info ...)trojan-activity    URL
36632SERVER-OTHER NTP decodenetnum assertion failure denial of service attempt (more info ...)attempted-dos 2015-7855   URL
36633SERVER-OTHER NTP decodenetnum assertion failure denial of service attempt (more info ...)attempted-dos 2015-7855   URL
36639MALWARE-CNC Win.Trojan.Tavex outbound connection (more info ...)trojan-activity    URL
36666MALWARE-CNC Win.Trojan.Tentobr outbound connection (more info ...)trojan-activity    URL
36670MALWARE-CNC Win.Trojan.Sathurbot outbound connection (more info ...)trojan-activity    URL
36732MALWARE-CNC Win.Trojan.Sefnit variant outbound connection (more info ...)trojan-activity    URL
36765MALWARE-CNC Win.Trojan.Stupeval variant outbound connection (more info ...)trojan-activity    URL
36770MALWARE-CNC Win.Trojan.Redcontrole variant outbound connection (more info ...)trojan-activity    URL
36777MALWARE-CNC Win.Trojan.Zimwervi variant outbound connection (more info ...)trojan-activity    URL
36781MALWARE-CNC Win.Trojan.Gokawa variant outbound connection (more info ...)trojan-activity    URL
36786FILE-OTHER Apple SceneKit qlmanage setelementname buffer overflow attempt (more info ...)attempted-user 2015-3783 76340  URL
36787FILE-OTHER Apple SceneKit qlmanage setelementname buffer overflow attempt (more info ...)attempted-user 2015-3783 76340  URL
36797EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user    
36800MALWARE-CNC Win.Trojan.Ruinmail outbound connection (more info ...)trojan-activity    URL
36807MALWARE-CNC Win.Trojan.Nodslit variant outbound connection (more info ...)trojan-activity    URL
36810MALWARE-CNC OSX.Trojan.Mabouia outbound connection (more info ...)trojan-activity    URL
36823SERVER-OTHER IBM Tivoli Storage Manager FastBack Server buffer overflow attempt (more info ...)attempted-admin 2015-1929 75451  URL
36833MALWARE-CNC User-Agent known malicious user-agent string - Mozila (more info ...)trojan-activity    URL
36834MALWARE-CNC Win.Trojan.Banload outbound connection (more info ...)trojan-activity    URL
36835MALWARE-CNC Win.Trojan.Banload inbound connection (more info ...)trojan-activity    URL
36841MALWARE-CNC Win.Trojan.Leralogs variant outbound connection (more info ...)trojan-activity    URL
36854FILE-OTHER IDEAL Administration IPJ file handling stack overflow attempt (more info ...)attempted-user 2009-4265   
36887POLICY-OTHER self-signed SSL certificate eDellRoot use attempt (more info ...)policy-violation    
36889MALWARE-CNC TinyDropper variant outbound connection (more info ...)trojan-activity    URL
36890MALWARE-CNC AbbadonPOS variant outbound connection (more info ...)trojan-activity    URL
36893MALWARE-CNC Win.Trojan.Trfijan outbound connection (more info ...)trojan-activity    URL
36894SERVER-WEBAPP Zend Technologies Zend Framework heuristicScan XML external entity injection attempt (more info ...)web-application-attack 2015-5161 76117  
36895SERVER-WEBAPP Zend Technologies Zend Framework heuristicScan XML external entity injection attempt (more info ...)web-application-attack 2015-5161 76117  
36911MALWARE-CNC GlassRAT handshake beacon (more info ...)trojan-activity    URL
36916MALWARE-CNC Milkoad.A First Request (more info ...)trojan-activity    URL
37014EXPLOIT-KIT Angler exploit kit landing page detected (more info ...)attempted-user    
37020MALWARE-CNC Win.Trojan.Gh0st variant outbound connection (more info ...)trojan-activity    URL
37024MALWARE-CNC Win.Trojan.Sofacy outbound connection (more info ...)trojan-activity    URL
37027MALWARE-CNC Win.Trojan.Alina variant outbound connection (more info ...)trojan-activity    URL
37028PROTOCOL-OTHER Websocket upgrade request without a client key detected (more info ...)misc-activity 2015-8027   
37036MALWARE-CNC Win.Trojan.ModPOS outbound connection (more info ...)trojan-activity    URL
37037MALWARE-CNC Win.Trojan.Arfadinf variant outbound connection (more info ...)trojan-activity    URL
37045MALWARE-CNC Win.Trojan.Kovter outbound connection (more info ...)trojan-activity    URL
37047MALWARE-CNC Win.Trojan.Vonterra outbound connection (more info ...)trojan-activity    URL
37048MALWARE-CNC Win.Trojan.Bookworm variant outbound connection (more info ...)trojan-activity    URL
37049MALWARE-CNC Win.Trojan.Geratid variant outbound connection (more info ...)trojan-activity    URL
37050MALWARE-CNC ATSEngine initial beacon (more info ...)trojan-activity    URL
37051MALWARE-CNC ATSEngine credit card number sent via URL parameter (more info ...)trojan-activity    URL
37052MALWARE-CNC Win.Trojan.TeslaCrypt outbound connection (more info ...)trojan-activity    URL
37053MALWARE-CNC Win.Trojan.Tdrop2 variant dropper download attempt (more info ...)trojan-activity    URL
37054FILE-OTHER BACnet OPC client csv file buffer overflow attempt (more info ...)attempted-user 2010-4740 43289  
37055FILE-OTHER BACnet OPC client csv file buffer overflow attempt (more info ...)attempted-user 2010-4740 43289  
37063MALWARE-CNC Win.Trojan.Paligenpo outbound connection (more info ...)trojan-activity    URL
37064MALWARE-CNC Win.Trojan.Telehot outbound connection (more info ...)trojan-activity    URL
37065MALWARE-CNC Win.Backdoor.Venik outbound connection (more info ...)trojan-activity    URL
37066MALWARE-CNC Win.Trojan.Banload (more info ...)trojan-activity    URL
37067MALWARE-CNC Win.Trojan.Droot outbound connection (more info ...)trojan-activity    URL
37068MALWARE-CNC Win.Trojan.Flusihoc variant outbound connection (more info ...)trojan-activity    URL
37100MALWARE-CNC Win.Trojan.Dashikut outbound connection (more info ...)trojan-activity    URL
37101MALWARE-CNC Win.Trojan.Nessfi outbound connection (more info ...)trojan-activity    URL
37102MALWARE-CNC Win.Trojan.Nessfi outbound connection (more info ...)trojan-activity    URL
37117MALWARE-CNC Win.Trojan.Cetsiol outbound connection (more info ...)trojan-activity    URL
37127MALWARE-CNC Win.Trojan.Batec outbound connection (more info ...)trojan-activity    URL
37141MALWARE-CNC Win.Trojan.Collicky variant inbound command attempt (more info ...)trojan-activity    URL
37154SERVER-OTHER OpenSSL invalid RSASSA-PSS certificate denial of service attempt (more info ...)attempted-dos 2015-3194   URL
37155SERVER-OTHER OpenSSL invalid RSASSA-PSS certificate denial of service attempt (more info ...)attempted-dos 2015-3194   URL
37164MALWARE-CNC Win.Trojan.Hpastal outbound email attempt (more info ...)trojan-activity    URL
37212MALWARE-CNC Win.Trojan.Pmabot outbound connection (more info ...)trojan-activity    URL
37213MALWARE-CNC Win.Trojan.Pmabot outbound connection (more info ...)trojan-activity    URL
37214MALWARE-CNC Win.Trojan.Pmabot outbound connection (more info ...)trojan-activity    URL
37215MALWARE-CNC Win.Trojan.Pmabot outbound connection (more info ...)trojan-activity    URL
37225MALWARE-CNC Win.Trojan.Isniffer outbound connection (more info ...)trojan-activity    URL
37226MALWARE-CNC Win.Trojan.Isniffer outbound connection (more info ...)trojan-activity    URL
37227MALWARE-CNC Win.Trojan.Isniffer outbound connection (more info ...)trojan-activity    URL
37228MALWARE-CNC Win.Trojan.Isniffer outbound connection (more info ...)trojan-activity    URL
37233SERVER-WEBAPP ManageEngine ServiceDesk Plus FileUploader servlet directory traversal attempt (more info ...)web-application-attack    URL
37245MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
37288SERVER-OTHER Trend Micro local node.js http command execution attempt (more info ...)attempted-user    URL
37291SERVER-OTHER Trend Micro local node.js http command execution attempt (more info ...)attempted-user    URL
37296MALWARE-CNC Win.Trojan.Sesramot variant outbound connection (more info ...)trojan-activity    URL
37297MALWARE-CNC Win.Trojan.Sesramot variant outbound connection (more info ...)trojan-activity    URL
37298APP-DETECT Hola VPN installation attempt (more info ...)policy-violation    URL
37299APP-DETECT Hola VPN installation attempt (more info ...)policy-violation    URL
37300APP-DETECT Hola VPN startup attempt (more info ...)policy-violation    URL
37301APP-DETECT Hola VPN startup attempt (more info ...)policy-violation    URL
37302APP-DETECT Hola VPN X-Hola-Version header nonstandard port attempt (more info ...)policy-violation    URL
37303APP-DETECT Hola VPN X-Hola-Version header attempt (more info ...)policy-violation    URL
37304APP-DETECT Hola VPN non-http port ping (more info ...)policy-violation    URL
37305APP-DETECT Hola VPN tunnel keep alive (more info ...)policy-violation    URL
37306APP-DETECT Hola VPN startup attempt (more info ...)policy-violation    URL
37317MALWARE-CNC Win.Trojan.Radamant inbound connection (more info ...)attempted-user    URL
37320MALWARE-CNC Win.Trojan.Sakurel variant outbound connection (more info ...)trojan-activity    URL
37323MALWARE-CNC Win.Trojan.Direvex variant outbound connection (more info ...)trojan-activity    URL
37348SERVER-WEBAPP Limesurvey unauthenticated file download attempt (more info ...)web-application-attack    URL
37349SERVER-WEBAPP Limesurvey unauthenticated file download attempt (more info ...)web-application-attack    URL
37354APP-DETECT Jenkins Groovy script access through script console attempt (more info ...)policy-violation    URL
37355EXPLOIT-KIT Sweet Orange exploit kit landing page detected (more info ...)attempted-user    
37359MALWARE-CNC MultiOS.Trojan.Pbot inbound command attempt (more info ...)trojan-activity    URL
37360MALWARE-CNC MultiOS.Trojan.Pbot outbound IRC channel join attempt (more info ...)trojan-activity    URL
37361EXPLOIT-KIT DarkLeech iframe injection tool detected (more info ...)trojan-activity    
37370MALWARE-CNC Win.Trojan.Trochulis variant outbound connection (more info ...)trojan-activity    URL
37374MALWARE-CNC Win.Trojan.Derkziel variant outbound connection (more info ...)trojan-activity    URL
37401FILE-OTHER librtmp invalid pointer dereference attempt (more info ...)attempted-dos 2015-8270   URL
37402FILE-OTHER librtmp invalid pointer dereference attempt (more info ...)attempted-dos 2015-8270   URL
37404SERVER-OTHER Easy Chat server authentication request username parameter overflow attempt (more info ...)misc-attack 2004-2466   
37407FILE-OTHER librtmp invalid pointer dereference attempt (more info ...)attempted-user 2015-8271   URL
37415SERVER-WEBAPP JBoss expression language actionOutcome remote code execution attempt (more info ...)attempted-admin 2010-1871 41994  
37416MALWARE-BACKDOOR Adzok RAT download (more info ...)trojan-activity    URL
37417MALWARE-BACKDOOR Adzok RAT server file download (more info ...)trojan-activity    URL
37418MALWARE-BACKDOOR Adzok RAT inbound connection (more info ...)trojan-activity    URL
37419MALWARE-BACKDOOR Adzok RAT inbound connection (more info ...)trojan-activity    URL
37420MALWARE-BACKDOOR Adzok RAT initial connection (more info ...)trojan-activity    URL
37421MALWARE-BACKDOOR Adzok RAT download (more info ...)trojan-activity    URL
37422MALWARE-BACKDOOR Adzok RAT server file download (more info ...)trojan-activity    URL
37447MALWARE-CNC Win.Backdoor.Evilgrab outbound connection (more info ...)trojan-activity    URL
37457MALWARE-CNC Win.Trojan.Sovfo variant outbound connection (more info ...)trojan-activity    URL
37466MALWARE-CNC Win.Trojan.Blackmoon outbound connection (more info ...)trojan-activity    URL
37467MALWARE-CNC Win.Trojan.Vawtrak variant outbound connection (more info ...)trojan-activity    URL
37468SERVER-WEBAPP InterWoven WorkDocs XSS attempt (more info ...)web-application-attack    
37471SERVER-WEBAPP F-Secure web console username overflow attempt (more info ...)attempted-admin 2006-2838 18201  
37506FILE-PDF TRUFFLEHUNTER TALOS-CAN-0086 attack attempt (more info ...)attempted-user    URL
37516MALWARE-CNC Win.Trojan.Sality variant outbound connection (more info ...)trojan-activity    URL
37521MALWARE-CNC Win.Trojan.iSpySoft variant outbound connection (more info ...)trojan-activity    URL
37522MALWARE-CNC Win.Trojan.iSpySoft variant outbound connection (more info ...)trojan-activity    URL
37523MALWARE-CNC Win.Trojan.iSpySoft variant outbound connection (more info ...)trojan-activity    URL
37524FILE-OTHER ReGet Deluxe wjr file buffer overflow attempt (more info ...)misc-attack  37511  
37534MALWARE-CNC Win.Trojan.Derusbi outbound connection (more info ...)trojan-activity    URL
37535MALWARE-CNC Win.Trojan.Derusbi outbound connection (more info ...)trojan-activity    URL
37536MALWARE-CNC Win.Trojan.Derusbi outbound connection (more info ...)trojan-activity    URL
37552MALWARE-CNC Win.Trojan.Engr variant outbound connection (more info ...)trojan-activity    URL
37618POLICY-OTHER SupRemo remote desktop outbound connection attempt (more info ...)policy-violation    URL
37619SERVER-OTHER InterSystems Cache UtilConfigHome.csp buffer overflow attempt (more info ...)misc-attack  37177  
37620PUA-ADWARE Genieo Adware framework variant outbound connection (more info ...)trojan-activity    URL
37621PUA-ADWARE Genieo Adware framework User-Agent (more info ...)trojan-activity    URL
37636MALWARE-CNC Win.Trojan.Graftor outbound connection (more info ...)trojan-activity    URL
37637MALWARE-CNC Win.Trojan.Graftor outbound connection (more info ...)trojan-activity    URL
37646MALWARE-CNC Win.Trojan.Symmi variant dropper download connection (more info ...)trojan-activity    URL
37647MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    URL
37649FILE-OTHER Sophos Anti-Virus reserved device name handling vulnerability attempt (more info ...)misc-activity 2004-0552   
37650FILE-OTHER CA BrightStor stack buffer overflow attempt (more info ...)web-application-attack 2006-6917   
37681POLICY-OTHER junk rule to autoenable vnetd.bpspsserver.connection flowbit (more info ...)misc-activity    
37682POLICY-OTHER junk rule to autoenable smb.session.negotiate flowbit (more info ...)misc-activity    
37686MALWARE-CNC Win.Trojan.Agent outbound POST attempt (more info ...)trojan-activity    URL
37717MALWARE-CNC Win.Trojan.Teslacrypt outbound POST attempt (more info ...)trojan-activity    URL
37718MALWARE-CNC Win.Trojan.Teslacrypt outbound POST attempt (more info ...)trojan-activity    URL
37719MALWARE-CNC Win.Trojan.Teslacrypt outbound POST attempt (more info ...)trojan-activity    URL
37725SERVER-OTHER CA message queuing server buffer overflow attempt (more info ...)attempted-admin 2007-0060 25051  URL
37728INDICATOR-OBFUSCATION SWF with large DefineBinaryData tag (more info ...)attempted-user 2015-3113   URL
37733MALWARE-CNC Win.Trojan.Dridex dropper variant outbound connection (more info ...)trojan-activity    URL
37813POLICY-OTHER junk rule to autoenable vnc.server.auth.types flowbit (more info ...)misc-activity    
37814POLICY-OTHER Polycom Botnet inbound connection attempt (more info ...)trojan-activity    URL
37815POLICY-OTHER Polycom Botnet inbound connection attempt (more info ...)trojan-activity    URL
37816MALWARE-CNC Win.Trojan.Kazy variant outbound connection (more info ...)trojan-activity    URL
37830FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
37831FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
37832FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
37833FILE-OTHER Poster Software Publish-It buffer overflow attempt (more info ...)attempted-user 2014-0980 65366  
37834MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
37835MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
37838MALWARE-CNC Win.Trojan.Zeus outbound connection (more info ...)trojan-activity    URL
37841SERVER-OTHER ntpd reference clock impersonation attempt (more info ...)misc-attack 2016-1551   URL
37842SERVER-OTHER ntpd reference clock impersonation attempt (more info ...)misc-attack 2016-1551   URL
37843SERVER-OTHER NTP crypto-NAK possible DoS attempt (more info ...)attempted-dos 2016-1547   URL
37844MALWARE-CNC Win.Ransomware.LeChiffre outbound connection (more info ...)trojan-activity    URL
37851FILE-OTHER Oracle Outside-In invalid CRG segment memory corruption attempt (more info ...)attempted-user 2011-4517   
37852FILE-OTHER Oracle Outside-In invalid CRG segment memory corruption attempt (more info ...)attempted-user 2011-4517   
37854SERVER-WEBAPP D-Link DSL router cross site scripting attempt (more info ...)attempted-user 2015-1028 72725  
37855SERVER-WEBAPP D-Link DSL router cross site scripting attempt (more info ...)attempted-user 2015-1028 72725  
37856SERVER-WEBAPP D-Link DSL router cross site scripting attempt (more info ...)attempted-user 2015-1028 72725  
37857SERVER-WEBAPP D-Link DSL router cross site scripting attempt (more info ...)attempted-user 2015-1028 72725  
37858SERVER-WEBAPP Thru Managed File Transfer Portal command injection attempt (more info ...)web-application-attack    URL
37861SERVER-OTHER SafeNEt SoftRemote IKE service buffer overflow attempt (more info ...)attempted-user 2009-1943   
37862FILE-PDF Oracle Outside In libvs_pdf integer overflow attempt (more info ...)attempted-user 2016-3575   URL
37863FILE-PDF Oracle Outside In libvs_pdf integer overflow attempt (more info ...)attempted-user 2016-3575   URL
37864FILE-PDF Oracle Outside In libvs_pdf xref offset out of bounds read attempt (more info ...)attempted-user 2016-3580   URL
37865FILE-PDF Oracle Outside In libvs_pdf xref offset out of bounds read attempt (more info ...)attempted-user 2016-3580   URL
37866FILE-PDF Oracle Outside In libvs_pdf arbitrary pointer access attempt (more info ...)attempted-recon 2016-3579   URL
37867FILE-PDF Oracle Outside In libvs_pdf arbitrary pointer access attempt (more info ...)attempted-recon 2016-3579   URL
37868FILE-PDF Oracle Outside In libvs_pdf integer overflow attempt (more info ...)attempted-user 2016-3574   URL
37869FILE-PDF Oracle Outside In libvs_pdf integer overflow attempt (more info ...)attempted-user 2016-3574   URL
37890SERVER-WEBAPP Netgear ProSafe NMS arbitrary JSP file upload attempt (more info ...)attempted-admin 2016-1525 82630  
37893FILE-OTHER Oracle Outside In tag parsing buffer overflow attempt (more info ...)attempted-user    URL
37894FILE-OTHER Oracle Outside In tag parsing buffer overflow attempt (more info ...)attempted-user    URL
37895FILE-OTHER Oracle Outside In tag parsing buffer overflow attempt (more info ...)attempted-user    URL
37896FILE-OTHER Oracle Outside In tag parsing buffer overflow attempt (more info ...)attempted-user    URL
37897FILE-OTHER Oracle Outside In tag parsing buffer overflow attempt (more info ...)attempted-user    URL
37898FILE-OTHER Oracle Outside In tag parsing buffer overflow attempt (more info ...)attempted-user    URL
37903INDICATOR-OBFUSCATION fromCharcode known obfuscation attempt (more info ...)misc-activity    URL
37904INDICATOR-OBFUSCATION fromCharcode known obfuscation attempt (more info ...)misc-activity    URL
37912POLICY-OTHER SSL/TLS weak RC4 cipher suite use attempt (more info ...)policy-violation 2015-2808 73684  
37913POLICY-OTHER SSL/TLS weak RC4 cipher suite use attempt (more info ...)policy-violation 2015-2808 73684  
37914POLICY-OTHER SSL/TLS weak RC4 cipher suite use attempt (more info ...)policy-violation 2015-2808 73684  
37915POLICY-OTHER SSL/TLS weak RC4 cipher suite use attempt (more info ...)policy-violation 2015-2808 73684  
37916POLICY-OTHER SSL/TLS weak RC4 cipher suite use attempt (more info ...)policy-violation 2015-2808 73684  
37917SERVER-WEBAPP AMX backdoor username login attempt (more info ...)default-login-attempt 2016-1984   URL
37950INDICATOR-OBFUSCATION email of heavily compressed PDF attempt (more info ...)misc-activity    URL
37960SERVER-OTHER Pidgin MSN MSNP2P message integer overflow attempt (more info ...)attempted-user 2008-2927 29956  URL
37971INDICATOR-OBFUSCATION obfuscated script encoding detected (more info ...)misc-activity    URL
37972INDICATOR-OBFUSCATION obfuscated script encoding detected (more info ...)misc-activity    URL
38017MALWARE-CNC Win.Trojan.TeslaCrypt server reply (more info ...)misc-activity    URL
38018MALWARE-CNC Win.Trojan.Dridex outbound connection (more info ...)trojan-activity    URL
38116MALWARE-CNC Osx.Trojan.Keranger outbound connection (more info ...)trojan-activity    URL
38131SERVER-WEBAPP Netgear ProSafe NMS image.do directory traversal attempt (more info ...)web-application-attack 2016-1524 82630  
38132SERVER-WEBAPP Netgear ProSafe NMS image.do directory traversal attempt (more info ...)web-application-attack 2016-1524 82630  
38134MALWARE-CNC known malicious SSL certificate - Win.Trojan.Adwind (more info ...)trojan-activity    URL
38135BROWSER-OTHER Apple iOS CoreGraphics library PDF embedded image handling information leak attempt (more info ...)attempted-recon 2014-4378 69915  URL
38136SERVER-MAIL excessive email recipients - potential spam attempt (more info ...)misc-activity    
38145MALWARE-CNC Win.Trojan.Kovter variant outbound connection (more info ...)trojan-activity    URL
38150MALWARE-CNC Win.Trojan.TeslaCrypt variant outbound connection (more info ...)trojan-activity    URL
38156SERVER-WEBAPP 29o3 CMS LibDir parameter multiple remote file include attempt (more info ...)web-application-attack 2010-1922 40049  
38157SERVER-WEBAPP 29o3 CMS LibDir parameter multiple remote file include attempt (more info ...)web-application-attack 2010-1922 40049  
38158SERVER-WEBAPP 29o3 CMS LibDir parameter multiple remote file include attempt (more info ...)web-application-attack 2010-1922 40049  
38159SERVER-WEBAPP 29o3 CMS LibDir parameter multiple remote file include attempt (more info ...)web-application-attack 2010-1922 40049  
38234MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.FighterPOS (more info ...)trojan-activity    URL
38235MALWARE-CNC Win.Trojan.FighterPOS variant outbound connection (more info ...)trojan-activity    URL
38242SERVER-WEBAPP VmWare Tools command injection attempt (more info ...)web-application-attack 2010-4297 45166  
38243SERVER-WEBAPP VmWare Tools command injection attempt (more info ...)web-application-attack 2010-4297 45166  
38251INDICATOR-OBFUSCATION HTML entity encoded script language declaration detected (more info ...)misc-activity    URL
38259MALWARE-CNC PowerShell Empire variant outbound connection (more info ...)trojan-activity    URL
38260MALWARE-CNC PowerShell Empire variant outbound connection (more info ...)trojan-activity    URL
38261MALWARE-CNC PowerShell Empire variant outbound connection (more info ...)trojan-activity    URL
38263SERVER-OTHER CUPS Filters command injection attempt (more info ...)attempted-user 2014-2707 66624  
38270SERVER-OTHER Wavelink Emulation License Server HTTP header overflow attempt (more info ...)attempted-user 2015-4059   
38289FILE-PDF Oracle IOT IX SDK libvs_pdf null pointer dereference attempt (more info ...)attempted-user 2016-3576   URL
38290FILE-PDF Oracle IOT IX SDK libvs_pdf null pointer dereference attempt (more info ...)attempted-user 2016-3576   URL
38291FILE-IDENTIFY UDF file magic detected (more info ...)misc-activity    URL
38292FILE-IDENTIFY UDF file magic detected (more info ...)misc-activity    URL
38293FILE-OTHER 7zip UDF partition reference out of bounds read attempt (more info ...)attempted-user 2016-2335   URL
38294FILE-OTHER 7zip UDF partition reference out of bounds read attempt (more info ...)attempted-user 2016-2335   URL
38295FILE-OTHER 7zip UDF partition reference out of bounds read attempt (more info ...)attempted-user 2016-2335   URL
38296FILE-OTHER 7zip UDF partition reference out of bounds read attempt (more info ...)attempted-user 2016-2335   URL
38304MALWARE-CNC User-Agent known malicious user-agent string - JexBoss (more info ...)trojan-activity    URL
38306FILE-IDENTIFY DMG com.apple.decmpfs file magic detected (more info ...)misc-activity    URL
38307FILE-IDENTIFY DMG com.apple.decmpfs file magic detected (more info ...)misc-activity    URL
38314SERVER-WEBAPP Borland AccuRev Reprise License Server directory traversal attempt (more info ...)web-application-attack    
38315SERVER-WEBAPP Borland AccuRev Reprise License Server directory traversal attempt (more info ...)web-application-attack    
38316SERVER-WEBAPP Borland AccuRev Reprise License Server directory traversal attempt (more info ...)web-application-attack    
38323FILE-OTHER 7zip HFS+ handling heap buffer overflow attempt (more info ...)attempted-user 2016-2334   URL
38324FILE-OTHER 7zip HFS+ handling heap buffer overflow attempt (more info ...)attempted-user 2016-2334   URL
38331MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
38332INDICATOR-OBFUSCATION HTTP header dual colon evasion attempt (more info ...)non-standard-protocol    URL
38337INDICATOR-OBFUSCATION HTTP header illegal character prior to encoding type evasion attempt (more info ...)non-standard-protocol    URL
38340INDICATOR-OBFUSCATION HTTP multiple encodings per line attempt (more info ...)non-standard-protocol    URL
38341INDICATOR-OBFUSCATION Multiple Encodings header evasion attempt (more info ...)non-standard-protocol    URL
38342FILE-PDF Oracle Outside In libvs_pdf Root xref stack exhaustion attempt (more info ...)attempted-user 2016-3577   URL
38343FILE-PDF Oracle Outside In libvs_pdf Root xref stack exhaustion attempt (more info ...)attempted-user 2016-3577   URL
38348SERVER-OTHER McAfee ePolicy Orchestrator Framework Services buffer overflow attempt (more info ...)attempted-admin 2008-1855 28573  
38349SERVER-OTHER McAfee ePolicy Orchestrator Framework Services buffer overflow attempt (more info ...)attempted-admin 2008-1855 28573  
38352MALWARE-CNC Win.Trojan.NetWiredRC variant check logs (more info ...)trojan-activity    URL
38353MALWARE-CNC Win.Trojan.NetWiredRC variant connection setup (more info ...)trojan-activity    URL
38354MALWARE-CNC Win.Trojan.NetWiredRC variant failed read logs (more info ...)trojan-activity    URL
38355MALWARE-CNC Win.Trojan.NetWiredRC variant keepalive (more info ...)trojan-activity    URL
38356MALWARE-CNC Win.Trojan.NetWiredRC variant read logs (more info ...)trojan-activity    URL
38357MALWARE-CNC Win.Trojan.NetWiredRC variant send credentials (more info ...)trojan-activity    URL
38358MALWARE-CNC Win.Trojan.NetWiredRC variant send logs (more info ...)trojan-activity    URL
38359MALWARE-CNC Win.Trojan.NetWiredRC variant send mail credentials (more info ...)trojan-activity    URL
38365SERVER-OTHER TCPDUMP ISAKMP payload handling denial of service attempt (more info ...)attempted-dos 2004-0183   
38367MALWARE-CNC Win.Trojan.Bedep.variant CNC server response (more info ...)trojan-activity    URL
38368INDICATOR-OBFUSCATION HTTP illegal chars after encoding type evasion attempt (more info ...)non-standard-protocol    URL
38369INDICATOR-OBFUSCATION HTTP header whitespace evasion attempt (more info ...)non-standard-protocol    URL
38370SERVER-WEBAPP IPESOFT D2000 directory traversal attempt (more info ...)web-application-attack    URL
38379MALWARE-CNC Win.Trojan.Dridex file download attempt (more info ...)trojan-activity    URL
38380MALWARE-CNC Win.Trojan.Dridex file download attempt (more info ...)trojan-activity    URL
38381BROWSER-OTHER HTTP characters prior to header evasion attempt (more info ...)non-standard-protocol    
38382BROWSER-OTHER ICY HTTP version evasion attempt (more info ...)non-standard-protocol    
38394INDICATOR-OBFUSCATION Gzip invalid extra field evasion attempt (more info ...)non-standard-protocol    URL
38395SERVER-WEBAPP Oracle Application Testing Suite Grid Control directory traversal attempt (more info ...)web-application-attack 2016-0489 81184  
38396SERVER-WEBAPP Oracle Application Testing Suite Grid Control directory traversal attempt (more info ...)web-application-attack 2016-0489 81184  
38439EXPLOIT-KIT Angler exploit kit news uri structure (more info ...)trojan-activity    
38497MALWARE-OTHER samsam delfiletype.exe file load attempt (more info ...)trojan-activity    
38498MALWARE-OTHER samsam samsam.exe file load attempt (more info ...)trojan-activity    
38500MALWARE-OTHER samsam delfiletype.exe file load attempt (more info ...)trojan-activity    
38501MALWARE-OTHER samsam samsam.exe file load attempt (more info ...)trojan-activity    
38509MALWARE-CNC Win.Trojan.Boaxxe variant outbound connection (more info ...)trojan-activity    URL
38510MALWARE-CNC Win.Trojan.iSpySoft variant exfiltration attempt (more info ...)trojan-activity    URL
38514MALWARE-CNC Win.Trojan.Sweeper outbound connection (more info ...)trojan-activity    URL
38515MALWARE-CNC Win.Trojan.Sweeper outbound connection (more info ...)trojan-activity    URL
38516MALWARE-CNC Win.Trojan.Sweeper outbound connection (more info ...)trojan-activity    URL
38517MALWARE-CNC binary download while video expected (more info ...)trojan-activity    URL
38528MALWARE-CNC XBot Command Request get_action (more info ...)trojan-activity    URL
38542MALWARE-CNC VBS Trojan Downloading Encoded Executable (more info ...)trojan-activity    URL
38544SERVER-OTHER TRUFFLEHUNTER TALOS-CAN-0121 attack attempt (more info ...)attempted-user    URL
38545SERVER-OTHER Pidgin mxit_update_contact out of bounds read attempt (more info ...)attempted-user 2016-2373   URL
38546SERVER-OTHER Pidgin MXIT table markup command out of bounds read attempt (more info ...)attempted-user 2016-2366   URL
38547SERVER-OTHER Pidgin MXIT table markup command out of bounds read attempt (more info ...)attempted-user 2016-2366   URL
38548SERVER-OTHER Pidgin MXIT protocol handling null pointer dereference attempt (more info ...)attempted-user 2016-2369   URL
38549SERVER-OTHER Pidgin mxit_parse_cmd_extprofile out of bounds read attempt (more info ...)attempted-user 2016-2371   URL
38550SERVER-OTHER Pidgin MXIT protocol handling splash_remove directory traversal attempt (more info ...)attempted-user 2016-4323   URL
38551SERVER-OTHER Pidgin MXIT protocol handling splash_remove directory traversal attempt (more info ...)attempted-user 2016-4323   URL
38552EXPLOIT-KIT Angler landing page detected (more info ...)attempted-user    
38553EXPLOIT-KIT Angler landing page detected (more info ...)attempted-user    
38556EXPLOIT-KIT Angler landing page detected (more info ...)attempted-user    
38557MALWARE-CNC Win.Trojan.GateKeylogger outbound connection (more info ...)trojan-activity    URL
38558MALWARE-CNC Win.Trojan.GateKeylogger outbound connection (more info ...)trojan-activity    URL
38559MALWARE-CNC Win.Trojan.GateKeylogger outbound connection - keystorkes (more info ...)trojan-activity    URL
38560MALWARE-CNC Win.Trojan.GateKeylogger outbound connection - screenshot (more info ...)trojan-activity    URL
38561MALWARE-CNC Win.Trojan.GateKeylogger plugins download attempt (more info ...)trojan-activity    URL
38562MALWARE-CNC Win.Trojan.GateKeylogger initial exfiltration attempt (more info ...)trojan-activity    URL
38563MALWARE-CNC Win.Trojan.GateKeylogger fake 404 response (more info ...)trojan-activity    URL
38564MALWARE-CNC Win.Trojan.GateKeylogger keylog exfiltration attempt (more info ...)trojan-activity    URL
38565MALWARE-CNC Win.Trojan.Sweeper variant dropper initial download attempt (more info ...)trojan-activity    URL
38566MALWARE-CNC Win.Trojan.Sweeper variant dropper download attempt (more info ...)trojan-activity    URL
38567MALWARE-CNC Win.Trojan.Coverton variant outbound connection (more info ...)trojan-activity    URL
38568SERVER-OTHER Smart Software Solutions Codesys Gateway Server projectName heap buffer overflow attempt (more info ...)attempted-admin 2015-6460 76754  
38569FILE-OTHER ABC file instruction field parsing exploitation attempt (more info ...)attempted-user 2013-4234   URL
38570FILE-OTHER ABC file instruction field parsing exploitation attempt (more info ...)attempted-user 2013-4234   URL
38571FILE-OTHER ABC file instruction field parsing exploitation attempt (more info ...)attempted-user 2013-4234   URL
38572FILE-OTHER ABC file instruction field parsing exploitation attempt (more info ...)attempted-user 2013-4234   URL
38573MALWARE-CNC Win.Trojan.TreasureHunter variant handshake beacon (more info ...)trojan-activity    URL
38574MALWARE-CNC Win.Trojan.TreasureHunter variant outbound connection (more info ...)trojan-activity    URL
38578SERVER-OTHER Pidgin multimx_message_received out of bounds read attempt (more info ...)attempted-user 2016-2374   URL
38583SERVER-OTHER Pidgin mxit_parse_cmd_suggestcontacts out of bounds read attempt (more info ...)attempted-user 2016-2375   URL
38594APP-DETECT Bloomberg web crawler outbound connection (more info ...)misc-activity    URL
38595INDICATOR-OBFUSCATION Invalid HTTP version evasion attempt (more info ...)non-standard-protocol    URL
38596INDICATOR-OBFUSCATION HTTP header null byte evasion attempt (more info ...)non-standard-protocol    URL
38597INDICATOR-OBFUSCATION HTTP header null byte evasion attempt (more info ...)non-standard-protocol    URL
38598INDICATOR-OBFUSCATION invalid HTTP header evasion attempt (more info ...)non-standard-protocol    URL
38599INDICATOR-OBFUSCATION Invalid HTTP 100 response followed by 200 evasion attempt (more info ...)non-standard-protocol    URL
38600INDICATOR-OBFUSCATION Invalid HTTP response code evasion attempt (more info ...)non-standard-protocol    URL
38601INDICATOR-OBFUSCATION Invalid HTTP header format evasion attempt (more info ...)non-standard-protocol    URL
38602INDICATOR-OBFUSCATION mixed case HTTP header evasion attempt (more info ...)non-standard-protocol    URL
38603MALWARE-CNC Win.Trojan.UP007 variant outbound connection (more info ...)trojan-activity    URL
38606MALWARE-CNC Win.Trojan.Qakbot variant network speed test (more info ...)trojan-activity    URL
38607MALWARE-CNC Win.Trojan.Qakbot variant outbound connection (more info ...)trojan-activity    URL
38608MALWARE-CNC Win.Trojan.RockLoader variant outbound connection (more info ...)trojan-activity    URL
38610MALWARE-CNC Win.Trojan.Godzilla downloader successful base64 binary download (more info ...)trojan-activity    URL
38613MALWARE-CNC Win.Trojan.Wallex variant outbound connection (more info ...)trojan-activity    URL
38614INDICATOR-OBFUSCATION carriage return only separator evasion (more info ...)non-standard-protocol    URL
38616INDICATOR-OBFUSCATION carriage return only separator evasion (more info ...)non-standard-protocol    URL
38617INDICATOR-OBFUSCATION carriage return only separator evasion (more info ...)non-standard-protocol    URL
38618INDICATOR-OBFUSCATION newline only separator evasion (more info ...)non-standard-protocol    URL
38619INDICATOR-COMPROMISE Content-Type text/plain containing Portable Executable data (more info ...)trojan-activity    URL
38622SERVER-OTHER ISC BIND malformed control channel authentication message denial of service attempt (more info ...)attempted-dos 2016-1285   URL
38637INDICATOR-OBFUSCATION Invalid HTTP response code evasion attempt (more info ...)non-standard-protocol    URL
38638MALWARE-CNC Win.Trojan.GozNym variant outbound connection (more info ...)trojan-activity    URL
38641INDICATOR-OBFUSCATION Invalid header line evasion attempt (more info ...)non-standard-protocol    URL
38642INDICATOR-OBFUSCATION Invalid HTTP 301 response evasion attempt (more info ...)non-standard-protocol    URL
38643MALWARE-CNC Win.Trojan.Jadowndec outbound connection (more info ...)trojan-activity    URL
38644MALWARE-CNC Win.Trojan.Jadowndec outbound connection (more info ...)trojan-activity    URL
38645MALWARE-CNC Win.Trojan.Jadowndec outbound connection (more info ...)trojan-activity    URL
38646MALWARE-CNC Win.Trojan.Jadowndec outbound connection (more info ...)trojan-activity    URL
38647MALWARE-CNC Win.Trojan.Jadowndec outbound connection (more info ...)trojan-activity    URL
38666INDICATOR-OBFUSCATION HTTP header invalid entry evasion attempt (more info ...)non-standard-protocol    URL
38667INDICATOR-OBFUSCATION Mixed case encoding type evasion attempt (more info ...)non-standard-protocol    URL
38668MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
38673SERVER-WEBAPP Oracle Application Testing Suite DownloadServlet directory traversal attempt (more info ...)web-application-attack 2016-0484 81102  URL
38674MALWARE-CNC Win.Trojan.Koohipa outbound beacon attempt (more info ...)trojan-activity    URL
38676MALWARE-CNC Win.Trojan.BBSwift variant outbound connection (more info ...)trojan-activity    URL
38677INDICATOR-OBFUSCATION UTF-8 evasion attempt (more info ...)non-standard-protocol    URL
38678INDICATOR-OBFUSCATION UTF-8 evasion attempt (more info ...)non-standard-protocol    URL
38679INDICATOR-OBFUSCATION non HTTP 1.1 version with 1.1 headers evasion attempt (more info ...)non-standard-protocol    URL
38680MALWARE-CNC Win.Trojan.Tooka GET attempt (more info ...)trojan-activity    URL
38681MALWARE-CNC Win.Trojan.Tooka POST attempt (more info ...)trojan-activity    URL
38724MALWARE-CNC Win.Trojan.Renegin outbound GET attempt (more info ...)trojan-activity    URL
38731SERVER-OTHER Squid Proxy range header denial of service attempt (more info ...)denial-of-service 2014-3609   
38732MALWARE-CNC Win.Trojan.VBDos Runtime Detection (more info ...)trojan-activity    URL
38733MALWARE-CNC Win.Trojan.Ransom variant outbound connection (more info ...)trojan-activity    URL
38734INDICATOR-OBFUSCATION HTTP header value without key evasion attempt (more info ...)non-standard-protocol    URL
38746MALWARE-CNC CTFMONv4 beacon attempt (more info ...)trojan-activity    
38747MALWARE-CNC FF-RAT outbound connection attempt (more info ...)trojan-activity    
38748MALWARE-CNC FF-RAT outbound connection attempt (more info ...)trojan-activity    
38749MALWARE-CNC FF-RAT outbound connection attempt (more info ...)trojan-activity    
38750MALWARE-CNC FF-RAT outbound connection attempt (more info ...)trojan-activity    
38751MALWARE-CNC Jimini outbound connection attempt (more info ...)trojan-activity    
38752MALWARE-CNC HILIGHT outbound connection attempt (more info ...)trojan-activity    
38754MALWARE-CNC XDOT outbound connection attempt (more info ...)trojan-activity    
38755MALWARE-CNC PlugX outbound connection attempt (more info ...)trojan-activity    
38756MALWARE-CNC PlugX outbound communication attempt (more info ...)trojan-activity    
38757MALWARE-CNC PlugX outbound communication attempt (more info ...)trojan-activity    
38767INDICATOR-COMPROMISE potential abuse of originating page privileges by new tab (more info ...)policy-violation    URL
38784MALWARE-CNC CryptXXX initial outbound connection (more info ...)trojan-activity    URL
38834MALWARE-CNC Win.Trojan.Locky variant outbound connection attempt (more info ...)trojan-activity    URL
38851FILE-IDENTIFY Hancom Hangul HCell file download request (more info ...)misc-activity    
38852FILE-IDENTIFY Hancom Hangul HCell file attachment detected (more info ...)misc-activity    
38853FILE-IDENTIFY Hancom Hangul HCell file attachment detected (more info ...)misc-activity    
38854FILE-IDENTIFY Hancom Hangul HCell file magic detected (more info ...)misc-activity    
38855FILE-IDENTIFY Hancom Hangul HCell file magic detected (more info ...)misc-activity    
38867SERVER-OTHER Pidgin mxit_chunk_parse_get_avatar out of bounds read attempt (more info ...)attempted-user 2016-2367   URL
38870SERVER-OTHER Pidgin mxit_chunk_parse_cr out of bounds read attempt (more info ...)attempted-user 2016-2370   URL
38885MALWARE-CNC Win.Trojan.Cerber outbound registration attempt (more info ...)trojan-activity    URL
38886MALWARE-CNC Win.Trojan.Bayrob variant outbound connection (more info ...)trojan-activity    URL
38887MALWARE-CNC Win.Trojan.Locky JS dropper outbound connection (more info ...)trojan-activity    URL
38888MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
38889SERVER-ORACLE Oracle Application Test Suite server authentication bypass attempt (more info ...)attempted-admin 2016-0492 81158  URL
38890MALWARE-CNC Win.Trojan.Kirts exfiltration attempt (more info ...)trojan-activity    URL
38891MALWARE-CNC Win.Trojan.Kirts initial registration (more info ...)trojan-activity    URL
38913SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack 2016-0486 81107  URL
38916MALWARE-CNC Win.Trojan.Dridex download attempt (more info ...)trojan-activity    URL
38917MALWARE-CNC Win.Trojan.Dridex variant CNC traffic (more info ...)trojan-activity    URL
38922INDICATOR-OBFUSCATION Brotli encoding evasion attempt (more info ...)non-standard-protocol    URL
38933INDICATOR-COMPROMISE IRC nick change on non-standard port (more info ...)trojan-activity    
38940SERVER-WEBAPP Oracle Application Testing Suite DownloadServlet servlet directory traversal attempt (more info ...)web-application-attack 2016-0477 81153  
38941SERVER-WEBAPP Oracle Application Testing Suite DownloadServlet servlet directory traversal attempt (more info ...)web-application-attack 2016-0477 81153  
38942SERVER-WEBAPP Oracle Application Testing Suite DownloadServlet servlet directory traversal attempt (more info ...)web-application-attack 2016-0477 81153  
38949MALWARE-CNC Win.Trojan.TeslaCrypt variant outbound connection (more info ...)trojan-activity    URL
38961MALWARE-CNC User-Agent known malicious user-agent string - fsrhrsrg - Win.Trojan.Nemucod (more info ...)trojan-activity    URL
38962MALWARE-CNC User-Agent known malicious user-agent string - uguogo - Win.Trojan.Nemucod (more info ...)trojan-activity    URL
38964POLICY-OTHER VMware vCenter Chargeback Manager ImageUploadServlet arbitrary JSP file upload attempt (more info ...)policy-violation 2013-3520 60484  URL
38989MALWARE-TOOLS TorStresser http DoS tool (more info ...)attempted-dos    URL
38994MALWARE-CNC Win.Trojan.Zeus config file download (more info ...)trojan-activity    URL
38995MALWARE-CNC Win.Trojan.Zeus variant outbound connection (more info ...)trojan-activity    URL
39034FILE-OTHER libarchive mtree parse_device stack buffer overflow attempt (more info ...)attempted-user 2016-4301   URL
39035FILE-OTHER libarchive mtree parse_device stack buffer overflow attempt (more info ...)attempted-user 2016-4301   URL
39040MALWARE-CNC Win.Trojan.TeslaCrypt variant outbound connection (more info ...)trojan-activity    URL
39045FILE-OTHER libarchive RAR RestartModel out of bounds write attempt (more info ...)attempted-user 2016-4302   URL
39046FILE-OTHER libarchive RAR RestartModel out of bounds write attempt (more info ...)attempted-user 2016-4302   URL
39047FILE-EXECUTABLE Kaspersky Internet Security kl1.sys out of bounds read attempt (more info ...)attempted-user 2016-4307   URL
39048FILE-EXECUTABLE Kaspersky Internet Security kl1.sys out of bounds read attempt (more info ...)attempted-user 2016-4307   URL
39052MALWARE-CNC Win.Trojan.Adialer variant outbound connection (more info ...)trojan-activity    URL
39053MALWARE-CNC Win.Trojan.7ev3n variant outbound connection (more info ...)trojan-activity    URL
39056MALWARE-CNC Win.Trojan.Rofin variant outbound connection (more info ...)trojan-activity    URL
39063MALWARE-CNC Win.Trojan.Qakbot outbound POST attempt (more info ...)trojan-activity    URL
39064MALWARE-CNC Win.Trojan.Sinrin initial JS dropper outbound connection (more info ...)trojan-activity    URL
39071SERVER-OTHER Aruba Networks IAP PAPI authentication bypass attempt (more info ...)attempted-admin 2016-2031   URL
39072SERVER-WEBAPP Aruba Networks IAP insecure disclosure of environment variables attempt (more info ...)attempted-recon 2016-2031   URL
39080MALWARE-CNC Win.Trojan.NetWiredRC variant connection setup (more info ...)trojan-activity    URL
39084MALWARE-CNC Win.Trojan.Cript outbound connection (more info ...)trojan-activity    URL
39085MALWARE-CNC Win.Trojan.Cript outbound connection (more info ...)trojan-activity    URL
39086MALWARE-CNC Win.Trojan.Cript outbound connection (more info ...)trojan-activity    URL
39106MALWARE-CNC Win.Trojan.LuminosityLink RAT variant outbound connection (more info ...)trojan-activity    URL
39107MALWARE-CNC Win.Trojan.LuminosityLink RAT variant inbound connection (more info ...)trojan-activity    URL
39116MALWARE-CNC Win.Trojan.DMALocker variant outbound connection (more info ...)trojan-activity    URL
39117MALWARE-CNC Win.Trojan.Symmi variant outbound connection (more info ...)trojan-activity    
39150SERVER-OTHER Pidgin MXIT negative message length underflow attempt (more info ...)attempted-user 2016-2376   URL
39151SERVER-OTHER Pidgin MXIT message length overflow attempt (more info ...)attempted-user 2016-2376   URL
39159MALWARE-CNC Win.Backdoor.JRat inbound self-signed SSL certificate (more info ...)trojan-activity    URL
39160MALWARE-CNC Win.Backdoor.JRat inbound self-signed SSL certificate (more info ...)trojan-activity    URL
39173MALWARE-CNC Win.Ransomware.BlackShades Crypter outbound connection (more info ...)trojan-activity    URL
39176MALWARE-CNC Win.Trojan.Helminth variant outbound connection (more info ...)trojan-activity    URL
39182SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack 2016-0478   
39183SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack 2016-0478   
39184SERVER-WEBAPP Oracle Application Testing Suite directory traversal attempt (more info ...)web-application-attack 2016-0478   
39197SERVER-WEBAPP AirTies RT hardcoded credentials login attempt (more info ...)attempted-admin    URL
39240EXPLOIT-KIT Neutrino Exploit Kit exploitation attempt (more info ...)attempted-user    
39320INDICATOR-OBFUSCATION HTTP header invalid entry evasion attempt (more info ...)non-standard-protocol    URL
39321INDICATOR-OBFUSCATION Gzip encoded with reserved bit set evasion attempt (more info ...)non-standard-protocol    URL
39322MALWARE-CNC Win.Trojan.GozNym variant outbound connection (more info ...)trojan-activity    URL
39323INDICATOR-OBFUSCATION Gzip encoded with invalid CRC16 evasion attempt (more info ...)non-standard-protocol    URL
39327MALWARE-CNC Win.Trojan.CryptoRoger outbound POST attempt (more info ...)trojan-activity    URL
39341MALWARE-CNC Win.Trojan.FastPOS credit card data exfiltration (more info ...)trojan-activity    URL
39342MALWARE-CNC Win.Trojan.FastPOS initial outbound connection (more info ...)trojan-activity    URL
39343MALWARE-CNC Win.Trojan.FastPOS keylog exfiltration (more info ...)trojan-activity    URL
39344MALWARE-CNC Win.Trojan.FastPOS status update (more info ...)trojan-activity    URL
39345MALWARE-CNC Win.Trojan.FastPOS update request (more info ...)trojan-activity    URL
39348SERVER-WEBAPP SAP servlet authentication bypass attempt (more info ...)attempted-admin 2010-5326   
39351SERVER-WEBAPP SAP NetWeaver CrashFileDownloadServlet directory traversal attempt (more info ...)web-application-attack 2016-3976   URL
39352SERVER-WEBAPP SAP NetWeaver CrashFileDownloadServlet directory traversal attempt (more info ...)web-application-attack 2016-3976   URL
39360MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
39361MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Batlopma (more info ...)trojan-activity    URL
39362INDICATOR-COMPROMISE User-Agent blank user-agent string (more info ...)misc-activity    URL
39369MALWARE-CNC Win.Trojan.Lorozoad variant outbound connection (more info ...)trojan-activity    URL
39409MALWARE-CNC Win.Trojan.iSpy variant initial outbound connection (more info ...)trojan-activity    URL
39410MALWARE-CNC Win.Trojan.iSpy variant exfiltration outbound connection (more info ...)trojan-activity    URL
39411MALWARE-CNC Win.Trojan.Qbot variant outbound connection (more info ...)trojan-activity    URL
39413SERVER-WEBAPP WANem WAN emulator command injection attempt (more info ...)web-application-attack    URL
39414SERVER-WEBAPP WANem WAN emulator command injection attempt (more info ...)web-application-attack    URL
39415SERVER-WEBAPP WANem WAN emulator command injection attempt (more info ...)web-application-attack    URL
39430MALWARE-CNC Win.Malware.Furtim variant outbound connection (more info ...)trojan-activity    URL
39433MALWARE-CNC Win.Trojan.Zcryptor variant outbound connection (more info ...)trojan-activity    URL
39434MALWARE-CNC Win.Trojan.Zcryptor variant outbound connection (more info ...)trojan-activity    URL
39442SERVER-WEBAPP Oracle E-Business Suite Arbitrary Document Download attempt (more info ...)web-application-attack 2007-2135 23532  URL
39443PUA-ADWARE Win.Adware.InstallFaster variant outbound connection attempt (more info ...)misc-activity    URL
39448MALWARE-CNC Win.Trojan.Renos variant outbound connection (more info ...)trojan-activity    URL
39463FILE-EXECUTABLE McAfee LiveSafe malformed executable denial of service attempt (more info ...)attempted-dos 2016-4535   
39464FILE-EXECUTABLE McAfee LiveSafe malformed executable denial of service attempt (more info ...)attempted-dos 2016-4535   
39465MALWARE-CNC Win.Trojan.Unlock92 outbound connection (more info ...)trojan-activity    URL
39501POLICY-OTHER Google Chromium ClusterFuzz fuzzer generated code detected (more info ...)policy-violation    URL
39502POLICY-OTHER Google Chromium ClusterFuzz fuzzer generated code detected (more info ...)policy-violation    URL
39573MALWARE-CNC Win.Backdoor.NanoBot variant outbound connection (more info ...)trojan-activity    URL
39574MALWARE-CNC Win.Backdoor.NanoBot variant outbound connection (more info ...)trojan-activity    URL
39575MALWARE-CNC Win.Backdoor.NanoBot variant outbound connection (more info ...)trojan-activity    URL
39576MALWARE-CNC Win.Backdoor.NanoBot variant outbound connection (more info ...)trojan-activity    URL
39577MALWARE-CNC Win.Backdoor.NanoBot variant outbound connection (more info ...)trojan-activity    URL
39578MALWARE-CNC Win.Backdoor.NanoBot variant inbound connection (more info ...)trojan-activity    URL
39579MALWARE-CNC Win.Backdoor.NanoBot variant outbound connection (more info ...)trojan-activity    URL
39580MALWARE-CNC Win.Backdoor.NanoBot variant outbound connection (more info ...)trojan-activity    URL
39581MALWARE-CNC Win.Trojan.NanoBot/Perseus initial outbound connection (more info ...)trojan-activity    URL
39582MALWARE-CNC Win.Trojan.NanoBot/Perseus server heartbeat request attempt (more info ...)trojan-activity    URL
39583MALWARE-CNC Win.Trojan.NanoBot/Perseus client heartbeat response attempt (more info ...)trojan-activity    URL
39584SERVER-OTHER EasyCafe Server remote file access attempt (more info ...)attempted-user    URL
39586PUA-ADWARE Win.Adware.Antivirus Container.exe referral link attempt (more info ...)misc-activity    URL
39587PUA-ADWARE Win.Adware.Antivirus Container.exe referral link attempt (more info ...)misc-activity    URL
39588SERVER-WEBAPP WebNMS Framework arbitrary file upload attempt (more info ...)attempted-admin    URL
39589SERVER-WEBAPP WebNMS Framework arbitrary file upload attempt (more info ...)attempted-admin    URL
39593FILE-IMAGE Oracle OIT BMP file parsing heap buffer overflow attempt (more info ...)attempted-user 2016-3596   URL
39594FILE-IMAGE Oracle OIT BMP file parsing heap buffer overflow attempt (more info ...)attempted-user 2016-3596   URL
39595FILE-IMAGE Oracle OIT BMP file parsing heap buffer overflow attempt (more info ...)attempted-user 2016-3596   URL
39596FILE-IMAGE Oracle OIT BMP file parsing heap buffer overflow attempt (more info ...)attempted-user 2016-3596   URL
39597FILE-MULTIMEDIA Apple OSX SceneKit invalid COLLADA file geometry attribute type confusion attempt (more info ...)attempted-user 2016-1850   URL
39598FILE-MULTIMEDIA Apple OSX SceneKit invalid COLLADA file geometry attribute type confusion attempt (more info ...)attempted-user 2016-1850   URL
39599FILE-IMAGE Apple OSX EXR image tile size heap buffer overflow attempt (more info ...)attempted-user 2016-4630   URL
39600FILE-IMAGE Apple OSX EXR image tile size heap buffer overflow attempt (more info ...)attempted-user 2016-4630   URL
39633PUA-ADWARE Win.Adware.Mizenota outbound connection (more info ...)trojan-activity    URL
39636MALWARE-CNC Win.Ransomware.Ranscam request.html response (more info ...)trojan-activity    URL
39642SERVER-WEBAPP WebNMS framework server credential disclosure attempt (more info ...)attempted-admin    URL
39650MALWARE-CNC Win.Trojan.Kirts variant CNC IRC response attempt (more info ...)trojan-activity    URL
39653MALWARE-CNC Win.Trojan.Mangit initial outbound connection (more info ...)trojan-activity    URL
39660FILE-OTHER Oracle OIT gem metafile n_integers heap buffer overflow attempt (more info ...)attempted-user 2016-3595   URL
39661FILE-OTHER Oracle OIT gem metafile n_integers heap buffer overflow attempt (more info ...)attempted-user 2016-3595   URL
39663FILE-OTHER Oracle OIT ContentAccess libvs_mwkd VwStreamReadRecord out of bounds write attempt (more info ...)attempted-user 2016-3591   URL
39664FILE-OTHER Oracle OIT ContentAccess libvs_mwkd VwStreamReadRecord out of bounds write attempt (more info ...)attempted-user 2016-3591   URL
39673FILE-IMAGE Oracle OIT CYMK TIFF parsing heap buffer overflow attempt (more info ...)attempted-user 2016-3582   URL
39674FILE-IMAGE Oracle OIT CYMK TIFF parsing heap buffer overflow attempt (more info ...)attempted-user 2016-3582   URL
39675FILE-IMAGE Oracle OIT CYMK TIFF parsing heap buffer overflow attempt (more info ...)attempted-user 2016-3582   URL
39676FILE-IMAGE Oracle OIT CYMK TIFF parsing heap buffer overflow attempt (more info ...)attempted-user 2016-3582   URL
39677EXPLOIT-KIT Pseudo-Darkleech gate redirect attempt (more info ...)trojan-activity    
39682PUA-ADWARE Win.Adware.EoRezo outbound ad download attempt (more info ...)trojan-activity    URL
39685MALWARE-CNC Win.Trojan.Tinba variant outbound connection (more info ...)trojan-activity    URL
39686MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
39705MALWARE-CNC Win.Trojan.Zeus variant inbound connection (more info ...)trojan-activity    URL
39729INDICATOR-COMPROMISE Content-Type image containing Portable Executable data (more info ...)trojan-activity    URL
39730MALWARE-CNC Win.Adware.Xiazai outbound connection (more info ...)trojan-activity    URL
39735FILE-OTHER Multiple Products XML buffer overflow attempt (more info ...)attempted-admin 2013-6935   URL
39736FILE-OTHER Multiple Products XML buffer overflow attempt (more info ...)attempted-admin 2013-6935   URL
39738MALWARE-CNC Win.Trojan.Trans variant outbound connection (more info ...)trojan-activity    URL
39741PUA-ADWARE Win.Adware.StartPage variant outbound connection (more info ...)misc-activity    URL
39767MALWARE-CNC Win.Ransomware.Alfa outbound connection (more info ...)trojan-activity    URL
39770SERVER-WEBAPP GoAhead Embedded Web Server directory traversal attempt (more info ...)attempted-admin 2014-9707   URL
39774MALWARE-CNC Win.Trojan.Qarallax initial outbound connection (more info ...)trojan-activity    URL
39775EXPLOIT-KIT malicious script detected via RBF classifier (more info ...)attempted-user    
39776FILE-IDENTIFY Heroes of Might and Magic III map file attachment detected (more info ...)misc-activity    
39777FILE-IDENTIFY Heroes of Might and Magic III map file attachment detected (more info ...)misc-activity    
39778FILE-IDENTIFY Heroes of Might and Magic III map file download request (more info ...)misc-activity    
39779FILE-OTHER Ubisoft Heroes of Might and Magic III .h3m map file buffer overflow attempt (more info ...)attempted-admin    URL
39780FILE-OTHER Ubisoft Heroes of Might and Magic III .h3m map file buffer overflow attempt (more info ...)attempted-admin    URL
39781FILE-OTHER Ubisoft Heroes of Might and Magic III .h3m map file buffer overflow attempt (more info ...)attempted-admin    URL
39785MALWARE-CNC Win.Trojan.Lientchtp variant outbound connection (more info ...)trojan-activity    URL
39786PUA-ADWARE Win.Dowadmin.Adware outbound connection detected (more info ...)trojan-activity    URL
39787PUA-ADWARE Win.Dowadmin.Adware outbound connection detected (more info ...)trojan-activity    URL
39800MALWARE-CNC Win.Trojan.Hancitor variant outbound connection (more info ...)trojan-activity    URL
39801MALWARE-CNC Win.Trojan.Spyrat variant outbound connection (more info ...)trojan-activity    URL
39852MALWARE-CNC Win.Trojan.Sharik variant connectivity check (more info ...)trojan-activity    URL
39853MALWARE-CNC Win.Trojan.Sharik variant connectivity check (more info ...)trojan-activity    URL
39854MALWARE-CNC Win.Trojan.Sharik variant connectivity check (more info ...)trojan-activity    URL
39855MALWARE-CNC Win.Trojan.Sharik variant connectivity check (more info ...)trojan-activity    URL
39856MALWARE-CNC Win.Trojan.Sharik variant executable download (more info ...)trojan-activity    URL
39857MALWARE-CNC Win.Trojan.Sharik variant executable download (more info ...)trojan-activity    URL
39861MALWARE-CNC Win.Trojan.NanHaiShu variant outbound connection (more info ...)trojan-activity    URL
39870INDICATOR-COMPROMISE Oracle E-Business Suite arbitrary node deletion (more info ...)misc-activity 2007-2170 23532  URL
39877PROTOCOL-SNMP Allen-Bradley MicroLogix PLC firmware update detected (more info ...)policy-violation 2016-5645   URL
39882MALWARE-CNC Win.Trojan.Vibro outbound connection detected (more info ...)trojan-activity    URL
39886MALWARE-CNC User-Agent known Adware user-agent string - Win.Adware.Prepscram (more info ...)trojan-activity    URL
39887MALWARE-CNC Win.Trojan.Toga variant outbound connection (more info ...)trojan-activity    URL
39888PUA-ADWARE Dorv Adware variant outbound connection (more info ...)trojan-activity    URL
39899PUA-ADWARE Win.Adware.Techsnab outbound connection detected (more info ...)misc-activity    URL
39900PUA-ADWARE Win.Adware.Techsnab outbound connection detected (more info ...)misc-activity    URL
39901PUA-ADWARE Win.Adware.Techsnab outbound connection detected (more info ...)misc-activity    URL
39902PUA-ADWARE Win.Adware.Techsnab outbound connection detected (more info ...)misc-activity    URL
39908SERVER-WEBAPP Multiple Products long multipart POST boundary attack attempt (more info ...)denial-of-service 2023-20158 91453  URL
39909MALWARE-CNC Win.Trojan.Adnel outbound connection detected (more info ...)trojan-activity    URL
39911MALWARE-CNC Win.Trojan.HawkEye keylogger exfiltration attempt (more info ...)trojan-activity    URL
39918FILE-EXECUTABLE Kaspersky Anti-Virus unhandled windows messages denial of service vulnerability attempt (more info ...)attempted-dos 2016-4329   URL
39919FILE-EXECUTABLE Kaspersky Anti-Virus unhandled windows messages denial of service vulnerability attempt (more info ...)attempted-dos 2016-4329   URL
39920MALWARE-CNC Neutrino outbound connection (more info ...)trojan-activity    
39921MALWARE-CNC Neutrino outbound connection (more info ...)trojan-activity    
39931MALWARE-CNC Win.Trojan.BlackEnergy outbound connection (more info ...)trojan-activity    URL
39937FILE-PDF TRUFFLEHUNTER TALOS-CAN-0194 attack attempt (more info ...)attempted-recon    URL
39938FILE-PDF TRUFFLEHUNTER TALOS-CAN-0194 attack attempt (more info ...)attempted-recon    URL
39941SERVER-WEBAPP Schneider Electric Accutech http request overflow attempt (more info ...)attempted-admin 2013-0658 57651  
39958MALWARE-CNC Win.Trojan.Folyris outbound connection detected (more info ...)trojan-activity    URL
39968MALWARE-CNC Win.Trojan.Donoff outbound connection detected (more info ...)trojan-activity    URL
39969MALWARE-CNC Win.Trojan.Donoff outbound connection detected (more info ...)trojan-activity    URL
39976SERVER-OTHER BGP bad marker strings (more info ...)bad-unknown    
39977SERVER-OTHER BGP invalid length (more info ...)bad-unknown 2002-1350 6213 15043 
39993SERVER-OTHER Netcore router backdoor access attempt (more info ...)attempted-admin    URL
40007MALWARE-CNC Win.Trojan.Nemim outbound connection detected (more info ...)trojan-activity    URL
40011MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
40012MALWARE-CNC User-Agent known malicious user-agent string DetoxCrypto2 (more info ...)trojan-activity    URL
40016MALWARE-CNC Win.Trojan.Madeba outbound connection detected (more info ...)trojan-activity    
40027MALWARE-CNC Win.Trojan.Shakti variant outbound connection (more info ...)trojan-activity    URL
40028POLICY-OTHER AutoItv3 Aut2Exe interpreter - compiled script (more info ...)policy-violation    URL
40029POLICY-OTHER AutoItv3 Aut2Exe interpreter - compiled script (more info ...)policy-violation    URL
40034EXPLOIT-KIT Exploit kit embedded iframe redirection attempt (more info ...)attempted-user    
40043MALWARE-CNC Win.Ransomware.Fantom outbound connection (more info ...)trojan-activity    URL
40044MALWARE-CNC Win.Ransomware.Fantom post encryption outbound connection (more info ...)trojan-activity    URL
40045MALWARE-CNC Win.Ransomware.Fantom post encryption outbound connection (more info ...)trojan-activity    URL
40059MALWARE-CNC Win.Trojan.Hadsruda outbound connection detected (more info ...)trojan-activity    URL
40060MALWARE-CNC Win.Trojan.Hadsruda outbound connection detected (more info ...)trojan-activity    URL
40061MALWARE-CNC Win.Backdoor.Morel variant outbound connection (more info ...)trojan-activity    URL
40062MALWARE-CNC Win.Backdoor.Morel variant inbound connection (more info ...)trojan-activity    URL
40066MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.LokiBot (more info ...)trojan-activity    URL
40067MALWARE-CNC Win.Trojan.LokiBot outbound connection (more info ...)trojan-activity    URL
40081PUA-OTHER User-Agent known PUA user-agent string - TopTools100 (more info ...)misc-activity    URL
40084INDICATOR-COMPROMISE TextDecorationBlink property use (more info ...)attempted-recon 2016-3324   URL
40085INDICATOR-COMPROMISE TextDecorationLineNone property use (more info ...)attempted-recon 2016-3324   URL
40086INDICATOR-COMPROMISE TextDecorationLineOverline property use (more info ...)attempted-recon 2016-3324   URL
40087INDICATOR-COMPROMISE TextDecorationLineThrough property use (more info ...)attempted-recon 2016-3324   URL
40088INDICATOR-COMPROMISE TextDecorationLineUnderline property use (more info ...)attempted-recon 2016-3324   URL
40089INDICATOR-COMPROMISE TextDecorationBlink property use (more info ...)attempted-recon 2016-3324   URL
40090INDICATOR-COMPROMISE TextDecorationLineNone property use (more info ...)attempted-recon 2016-3324   URL
40091INDICATOR-COMPROMISE TextDecorationLineOverline property use (more info ...)attempted-recon 2016-3324   URL
40092INDICATOR-COMPROMISE TextDecorationLineThrough property use (more info ...)attempted-recon 2016-3324   URL
40093INDICATOR-COMPROMISE TextDecorationLineUnderline property use (more info ...)attempted-recon 2016-3324   URL
40182SERVER-WEBAPP AirOS authentication bypass attempt (more info ...)attempted-admin  51178  
40183MALWARE-CNC Win.Trojan.Malex variant outbound connection (more info ...)trojan-activity    URL
40185SERVER-WEBAPP WebNMS framework server .jsp file retrieval attempt (more info ...)attempted-admin    URL
40187POLICY-OTHER SSL weak 3DES cipher suite use attempt (more info ...)policy-violation 2016-2183 92630  
40188POLICY-OTHER SSL weak 3DES cipher suite use attempt (more info ...)policy-violation 2016-2183 92630  
40203MALWARE-CNC Win.Trojan.Drolnux variant outbound connection (more info ...)trojan-activity    URL
40204MALWARE-CNC Win.Trojan.Qiwmonk outbound connection detected (more info ...)trojan-activity    URL
40205MALWARE-CNC Win.Trojan.Comisproc outbound connection detected (more info ...)trojan-activity    URL
40206MALWARE-CNC Win.Trojan.Comisproc outbound connection detected (more info ...)trojan-activity    URL
40207MALWARE-CNC Win.Trojan.Comisproc outbound connection detected (more info ...)trojan-activity    URL
40209MALWARE-CNC Win.Trojan.Bulta external connection attempt (more info ...)trojan-activity    URL
40211PUA-ADWARE Win.Adware.EoRezo outbound connection (more info ...)misc-activity    URL
40212MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Darkshell (more info ...)trojan-activity    URL
40213MALWARE-CNC Win.Trojan.DarkShell external connection attempt (more info ...)trojan-activity    URL
40214MALWARE-CNC Win.Downloader.Ogimant outbound connection detected (more info ...)trojan-activity    URL
40215MALWARE-CNC Win.Downloader.Ogimant outbound connection detected (more info ...)trojan-activity    URL
40216MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.VBInject (more info ...)trojan-activity    URL
40217MALWARE-CNC User-Agent known malicious user-agent string - F.5.E.C (more info ...)web-application-attack    
40223MALWARE-CNC Win.Trojan.Injector external connection attempt (more info ...)trojan-activity    URL
40232MALWARE-CNC Win.Trojan.CeeInject external connection (more info ...)trojan-activity    URL
40238MALWARE-CNC Win.Keylogger.AgentTesla variant outbound connection (more info ...)trojan-activity    URL
40242MALWARE-CNC Win.Trojan.iSpy variant outbound connection (more info ...)trojan-activity    URL
40249MALWARE-CNC Win.Downloader.QuantLoader external connection attempt (more info ...)trojan-activity    URL
40251MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Perseus (more info ...)trojan-activity    URL
40252MALWARE-CNC Win.Perseus variant outbound connection (more info ...)trojan-activity    URL
40258MALWARE-CNC Osx.Trojan.Keydnap variant backdoor detected (more info ...)trojan-activity    URL
40259MALWARE-CNC Osx.Trojan.Keydnap variant backdoor detected (more info ...)trojan-activity    URL
40260MALWARE-CNC Osx.Trojan.Keydnap variant initial backdoor download attempt (more info ...)trojan-activity    URL
40261MALWARE-CNC Osx.Trojan.Keydnap variant backdoor detected (more info ...)trojan-activity    URL
40262MALWARE-CNC Osx.Trojan.Keydnap variant backdoor detected (more info ...)trojan-activity    URL
40288MALWARE-CNC Win.Trojan.Poxters external connection (more info ...)trojan-activity    URL
40289MALWARE-CNC Win.Trojan.Philadelphia variant initial outbound connection (more info ...)trojan-activity    
40290MALWARE-CNC Win.Trojan.Philadelphia variant status update outbound connection (more info ...)trojan-activity    URL
40291SERVER-WEBAPP Advantech WebAccess openWidget directory traversal attempt (more info ...)web-application-attack 2016-0855   URL
40292SERVER-WEBAPP Advantech WebAccess openWidget directory traversal attempt (more info ...)web-application-attack 2016-0855   URL
40293SERVER-WEBAPP Advantech WebAccess openWidget directory traversal attempt (more info ...)web-application-attack 2016-0855   URL
40301SERVER-OTHER Redis CONFIG SET array index out of bounds attempt (more info ...)attempted-admin 2016-8339   URL
40305PUA-ADWARE Win.Adware.SupTab external connection attempt (more info ...)misc-activity    URL
40308MALWARE-CNC Backdoor.MSIL.Kazybot.A botnet server connection attempt (more info ...)trojan-activity    URL
40309MALWARE-CNC Win.Trojan.Randrew variant outbound connection (more info ...)trojan-activity    URL
40310MALWARE-CNC Osx.Trojan.Keydnap variant dropper detected (more info ...)trojan-activity    URL
40311MALWARE-CNC Osx.Trojan.Keydnap variant dropper detected (more info ...)trojan-activity    URL
40322SERVER-OTHER CA weblogic default credential login attempt (more info ...)default-login-attempt    URL
40326SERVER-OTHER JBoss directory traversal attempt (more info ...)attempted-recon    
40328SERVER-OTHER Railo directory traversal attempt (more info ...)attempted-recon    
40329SERVER-OTHER Axis2 directory traversal attempt (more info ...)attempted-recon    
40330SERVER-OTHER JBoss directory traversal attempt (more info ...)attempted-recon    
40331SERVER-WEBAPP JBoss default credential login attempt (more info ...)default-login-attempt    URL
40332SERVER-WEBAPP Ruby on Rails Web Console remote code execution attempt (more info ...)web-application-attack 2015-3224   URL
40333PROTOCOL-SCADA Rockwell firmware upload attempt (more info ...)policy-violation 2012-6437   URL
40334MALWARE-CNC Win.Trojan.Sality variant outbound connection (more info ...)trojan-activity    URL
40335APP-DETECT OpenVAS Scanner User-Agent attempt (more info ...)web-application-activity    
40338MALWARE-CNC Win.Trojan.Bartallex outbound connection detected (more info ...)trojan-activity    URL
40339MALWARE-CNC Win.Trojan.Cry variant outbound connection (more info ...)trojan-activity    
40340MALWARE-CNC Win.Trojan.Cry variant outbound connection (more info ...)trojan-activity    
40353SERVER-OTHER Linknat Vos Manager potential directory traversal attempt (more info ...)suspicious-filename-detect    URL
40356PUA-ADWARE Win.Trojan.InstantAccess variant outbound connection (more info ...)misc-activity    URL
40357PUA-ADWARE Win.Trojan.InstantAccess variant outbound connection (more info ...)misc-activity    URL
40361BROWSER-OTHER Android Browser potential denial of service attempt (more info ...)denial-of-service 2012-6301   URL
40432MALWARE-CNC Win.Trojan.Marsjoke variant post infection beacon (more info ...)trojan-activity    URL
40433MALWARE-CNC Win.Trojan.Marsjoke variant post infection beacon (more info ...)trojan-activity    URL
40444MALWARE-CNC Doc.Dropper.Agent variant outbound connection (more info ...)trojan-activity    URL
40445MALWARE-CNC Doc.Dropper.Agent variant outbound connection (more info ...)trojan-activity    URL
40449MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
40450MALWARE-CNC Doc.Downloader.Agent file download attempt (more info ...)trojan-activity    URL
40454SERVER-WEBAPP Nibbleblog remote code execution attempt (more info ...)attempted-user 2015-6967   
40457PUA-ADWARE Win.Downloader.OpenCandy variant outbound connection (more info ...)misc-activity    URL
40458BROWSER-OTHER Android browser file exfiltration attempt (more info ...)attempted-recon    URL
40461MALWARE-CNC Win.Trojan.Deshacop variant outbound connection (more info ...)trojan-activity    URL
40465MALWARE-CNC Win.Trojan.Kapahyku variant outbound connection (more info ...)trojan-activity    URL
40466MALWARE-CNC Win.Trojan.Kapahyku variant outbound connection (more info ...)trojan-activity    URL
40467MALWARE-CNC Win.Trojan.Hades outbound connection (more info ...)trojan-activity    URL
40484FILE-PDF Iceni Argus ipNameAdd stack buffer overflow attempt (more info ...)attempted-admin 2016-8335   URL
40485FILE-PDF Iceni Argus ipNameAdd stack buffer overflow attempt (more info ...)attempted-admin 2016-8335   URL
40486FILE-PDF Iceni Argus ipNameAdd stack buffer overflow attempt (more info ...)attempted-admin 2016-8335   URL
40487FILE-PDF Iceni Argus ipNameAdd stack buffer overflow attempt (more info ...)attempted-admin 2016-8335   URL
40492PUA-ADWARE Win.Adware.DownloadManager outbound connection (more info ...)misc-activity    URL
40500MALWARE-CNC Andr.Tool.Snowfox Androidbauts/snowfox outbound connection (more info ...)trojan-activity    URL
40501MALWARE-CNC Andr.Tool.Snowfox Androidbauts/snowfox outbound connection (more info ...)trojan-activity    URL
40517PROTOCOL-SCADA Rockwell Controllogix Network Policy Change attempt (more info ...)policy-violation    
40518PROTOCOL-SCADA Rockwell Controllogix Stop CPU attempt (more info ...)policy-violation    
40525FILE-IMAGE LibTIFF tiff2pdf JPEG compression tables heap buffer overflow attempt (more info ...)attempted-user 2016-5652   URL
40526FILE-IMAGE LibTIFF tiff2pdf JPEG compression tables heap buffer overflow attempt (more info ...)attempted-user 2016-5652   URL
40527MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
40528MALWARE-CNC User-Agent known malicious user-agent string Instally (more info ...)trojan-activity    URL
40529PUA-ADWARE Win.Downloader.Instally variant outbound connection attempt (more info ...)misc-activity    URL
40530PUA-ADWARE Win.Downloader.Instally variant outbound connection attempt (more info ...)misc-activity    URL
40531PUA-ADWARE Win.Downloader.Instally variant outbound connection attempt (more info ...)misc-activity    URL
40532PUA-ADWARE Win.Downloader.Instally variant outbound connection attempt (more info ...)misc-activity    URL
40533FILE-IMAGE LibTIFF FAX IFD entry parsing type confusion attempt (more info ...)attempted-user 2016-8331   URL
40534FILE-IMAGE LibTIFF FAX IFD entry parsing type confusion attempt (more info ...)attempted-user 2016-8331   URL
40535FILE-IMAGE LibTIFF FAX IFD entry parsing type confusion attempt (more info ...)attempted-user 2016-8331   URL
40536FILE-IMAGE LibTIFF FAX IFD entry parsing type confusion attempt (more info ...)attempted-user 2016-8331   URL
40537FILE-IMAGE LibTIFF FAX IFD entry parsing type confusion attempt (more info ...)attempted-user 2016-8331   URL
40538FILE-IMAGE LibTIFF FAX IFD entry parsing type confusion attempt (more info ...)attempted-user 2016-8331   URL
40541MALWARE-CNC Win.Trojan.Satana ransomware outbound connection (more info ...)trojan-activity    URL
40548MALWARE-CNC Win.Trojan.Redosdru variant outbound connection (more info ...)trojan-activity    URL
40549MALWARE-CNC Win.Trojan.CryPy ransomware variant outbound connection (more info ...)trojan-activity    URL
40550MALWARE-CNC Win.Trojan.Dexter Banker variant second stage download attempt (more info ...)trojan-activity    URL
40551MALWARE-CNC Win.Trojan.Dexter Banker variant successful installation report attempt (more info ...)trojan-activity    URL
40559MALWARE-CNC Win.Trojan.iSpy variant outbound connection (more info ...)trojan-activity    URL
40567MALWARE-CNC known malicious SSL certificate - Odinaff C&C (more info ...)trojan-activity    URL
40568INDICATOR-COMPROMISE wsf inside zip potential malicious file download attempt (more info ...)attempted-user    URL
40593PUA-ADWARE Win.Adware.CoolMirage outbound ad download attempt (more info ...)trojan-activity    URL
40594PUA-ADWARE Win.Adware.CoolMirage outbound ad download attempt (more info ...)trojan-activity    URL
40595PUA-ADWARE Win.Adware.CoolMirage outbound ad download attempt (more info ...)trojan-activity    URL
40596MALWARE-CNC Win.Trojan.Berbew variant outbound connection (more info ...)trojan-activity    URL
40597INDICATOR-COMPROMISE shell script download with wget from external source (more info ...)suspicious-filename-detect    
40598INDICATOR-COMPROMISE shell script download with curl from external source (more info ...)suspicious-filename-detect    
40605MALWARE-CNC Win.Trojan.Sality variant outbound connection (more info ...)trojan-activity    URL
40606MALWARE-CNC Win.Trojan.Sality variant outbound connection (more info ...)trojan-activity    URL
40611MALWARE-CNC Win.Trojan.Zeus variant download attempt (more info ...)trojan-activity    URL
40613SERVER-WEBAPP Oracle Application Testing Suite authentication bypass attempt (more info ...)attempted-admin 2016-0488   URL
40614SERVER-WEBAPP Oracle Application Testing Suite authentication bypass attempt (more info ...)attempted-admin 2016-0488   URL
40615SERVER-WEBAPP Oracle Application Testing Suite authentication bypass attempt (more info ...)attempted-admin 2016-0488   URL
40616SERVER-WEBAPP Oracle Application Testing Suite authentication bypass attempt (more info ...)attempted-admin 2016-0488   URL
40617SERVER-WEBAPP Oracle Application Testing Suite authentication bypass attempt (more info ...)attempted-admin 2016-0488   URL
40637POLICY-OTHER TL1 ACT-USER login detected (more info ...)policy-violation 2016-6441   URL
40643MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.TrickBot (more info ...)trojan-activity    URL
40644MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.TrickBot (more info ...)trojan-activity    URL
40709MALWARE-CNC Osx.Trojan.Komplex outbound connection (more info ...)trojan-activity    URL
40710MALWARE-CNC Osx.Trojan.Komplex outbound connection (more info ...)trojan-activity    URL
40733MALWARE-CNC User-Agent known malicious user-agent string - Sality (more info ...)trojan-activity    URL
40751MALWARE-CNC Win.Trojan.Autoit-73 configuration file download attempt (more info ...)trojan-activity    URL
40752MALWARE-CNC Win.Trojan.Autoit-73 configuration file download attempt (more info ...)trojan-activity    URL
40760SERVER-OTHER OpenLDAP deref control denial of service attempt (more info ...)attempted-dos 2015-1545   URL
40761MALWARE-CNC Win.Trojan.Syscan outbound connection (more info ...)trojan-activity    URL
40762MALWARE-CNC Android.Trojan.SpyNote RAT variant inbound connection (more info ...)trojan-activity    URL
40763MALWARE-CNC Android.Trojan.SpyNote RAT variant getSMS command response (more info ...)trojan-activity    URL
40764MALWARE-CNC Android.Trojan.SpyNote RAT variant getContacts command response (more info ...)trojan-activity    URL
40771MALWARE-CNC Win.Trojan.Miuref variant outbound connection (more info ...)trojan-activity    URL
40773FILE-PDF Oracle Outside In Technology remote code execution attempt (more info ...)attempted-admin 2017-3271   URL
40774FILE-PDF Oracle Outside In Technology remote code execution attempt (more info ...)attempted-admin 2017-3271   URL
40775MALWARE-CNC Win.Trojan.Banker variant outbound connection (more info ...)trojan-activity    URL
40782MALWARE-CNC User-Agent known malicious user-agent string - Venik (more info ...)trojan-activity    URL
40783SERVER-WEBAPP ZyXEL TR-064 GetSecurityKeys information disclosure attempt (more info ...)attempted-recon    URL
40795MALWARE-CNC Nesxlh variant outbound connection (more info ...)trojan-activity    URL
40796MALWARE-CNC Nesxlh variant outbound connection (more info ...)trojan-activity    URL
40797MALWARE-CNC Nesxlh variant outbound connection (more info ...)trojan-activity    URL
40800MALWARE-CNC User-Agent known malicious user-agent string - Crypton (more info ...)trojan-activity    URL
40811SERVER-OTHER NTP origin timestamp denial of service attempt (more info ...)attempted-dos 2015-7704   URL
40812MALWARE-CNC Rtf.Trojan.Mauris outbound download attempt (more info ...)trojan-activity    URL
40816MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
40820SERVER-WEBAPP Moxa AWK-3131A systemlog.log information disclosure attempt (more info ...)attempted-recon 2016-8725   URL
40821SERVER-WEBAPP Moxa AWK-3131A makeonekey.gz information disclosure attempt (more info ...)attempted-recon 2016-8727   URL
40822SERVER-WEBAPP Moxa AWK-3131A getonekey.gz information disclosure attempt (more info ...)attempted-recon 2016-8727   URL
40823MALWARE-CNC Win.Trojan.Gendwndrop variant outbound connection (more info ...)trojan-activity    URL
40824MALWARE-CNC Logbro variant outbound connection (more info ...)trojan-activity    URL
40827PUA-ADWARE MindSpark framework installer attempt (more info ...)trojan-activity    URL
40828INDICATOR-COMPROMISE Malicious script redirect attempt (more info ...)attempted-user    
40831MALWARE-CNC Win.Backdoor.Houdini variant initial outbound connection (more info ...)trojan-activity    
40832MALWARE-CNC Win.Backdoor.Houdini variant keylogger inbound init command attempt (more info ...)trojan-activity    URL
40833MALWARE-CNC Win.Backdoor.Houdini variant screenshot inbound init command attempt (more info ...)trojan-activity    
40834MALWARE-CNC Win.Backdoor.Houdini variant screenshot inbound silence command attempt (more info ...)trojan-activity    
40835MALWARE-CNC Win.Backdoor.Houdini variant screen_thumb inbound init command attempt (more info ...)trojan-activity    
40836MALWARE-CNC Win.Backdoor.Houdini variant file enumeration inbound init/root/faf command attempt (more info ...)trojan-activity    
40839PUA-ADWARE Sokuxuan outbound connection attempt (more info ...)trojan-activity    URL
40840PUA-OTHER Bitcoin Mining subscribe Stratum protocol client request attempt (more info ...)policy-violation    URL
40841PUA-OTHER Bitcoin Mining authorize Stratum protocol client request attempt (more info ...)policy-violation    URL
40842PUA-OTHER Bitcoin Mining extranonce Stratum protocol subscribe client request attempt (more info ...)policy-violation    URL
40844SERVER-OTHER OpenSSL Invalid CMS structure null pointer dereference attempt (more info ...)attempted-dos 2016-7053   URL
40850SERVER-WEBAPP VTSCADA WAP information disclosure attempt (more info ...)attempted-user 2016-4510   
40851SERVER-WEBAPP VTSCADA WAP information disclosure attempt (more info ...)attempted-user 2016-4510   
40852SERVER-WEBAPP VTSCADA WAP information disclosure attempt (more info ...)attempted-user 2016-4510   
40853SERVER-WEBAPP VTSCADA WAP information disclosure attempt (more info ...)attempted-user 2016-4510   
40854SERVER-WEBAPP VTSCADA WAP information disclosure attempt (more info ...)attempted-user 2016-4510   
40869MALWARE-CNC User-Agent known malicious user-agent string - Virut (more info ...)trojan-activity    URL
40870MALWARE-CNC User-Agent known malicious user-agent string - Virut (more info ...)trojan-activity    URL
40872FILE-PDF Iceni Argus loadTrailer heap corruption attempt (more info ...)attempted-user 2016-8715   URL
40873FILE-PDF Iceni Argus loadTrailer heap corruption attempt (more info ...)attempted-user 2016-8715   URL
40874FILE-PDF Iceni Argus icnChainAlloc heap corruption attempt (more info ...)attempted-user 2016-8715   URL
40875FILE-PDF Iceni Argus icnChainAlloc heap corruption attempt (more info ...)attempted-user 2016-8715   URL
40876SERVER-OTHER Pidgin MXIT file transfer length memory disclosure attempt (more info ...)attempted-user 2016-2372   URL
40878FILE-EXECUTABLE TRUFFLEHUNTER TALOS-CAN-0188 attack attempt (more info ...)attempted-dos    URL
40879FILE-EXECUTABLE TRUFFLEHUNTER TALOS-CAN-0188 attack attempt (more info ...)attempted-dos    URL
40890SERVER-WEBAPP Flexense DiskPulse Disk Change Monitor login buffer overflow attempt (more info ...)attempted-admin    URL
40891FILE-IDENTIFY R Programming Language source file file download request (more info ...)misc-activity    
40892FILE-IDENTIFY R Programming Language source file file attachment detected (more info ...)misc-activity    
40893FILE-IDENTIFY R Programming Language source file file attachment detected (more info ...)misc-activity    
40894FILE-OTHER R Project PDF encoding buffer overflow attempt (more info ...)attempted-user 2016-8714   URL
40895FILE-OTHER R Project PDF encoding buffer overflow attempt (more info ...)attempted-user 2016-8714   URL
40904SERVER-WEBAPP Oracle Weblogic default credentials login attempt (more info ...)attempted-admin    URL
40906MALWARE-CNC Win.Malware.Disttrack variant outbound connection (more info ...)trojan-activity    URL
40910MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    
40911MALWARE-CNC Win.Rootkit.Sednit variant outbound connection (more info ...)trojan-activity    URL
40916SERVER-WEBAPP Moxa AWK-3131A asqc.asp information disclosure attempt (more info ...)attempted-recon 2016-8722   URL
40921FILE-PDF Iceni Argus loadLZWBuffer out of bounds write attempt (more info ...)attempted-user 2016-8387   URL
40922FILE-PDF Iceni Argus loadLZWBuffer out of bounds write attempt (more info ...)attempted-user 2016-8387   URL
40990OS-WINDOWS empty PostScript Type 1 font pfb file null dereference attempt (more info ...)attempted-user 2016-7259   URL
41031MALWARE-CNC Win.Trojan.Athena variant outbound connection (more info ...)trojan-activity    URL
41033MALWARE-CNC Win.Trojan.Proteus outbound connection (more info ...)trojan-activity    URL
41034MALWARE-CNC Win.Trojan.Sality variant outbound connection (more info ...)trojan-activity    URL
41042PROTOCOL-SCADA Rockwell Controllogix Dump Boot Code attempt (more info ...)denial-of-service 2012-6441   URL
41043PROTOCOL-SCADA Rockwell Controllogix Ethernet Reset attempt (more info ...)denial-of-service 2012-6442   URL
41044PROTOCOL-SCADA Rockwell Controllogix Crash CPU attempt (more info ...)denial-of-service 2012-6436   URL
41088MALWARE-CNC Win.Trojan.MrWhite out bound communication attempt (more info ...)trojan-activity    
41089MALWARE-CNC Win.Trojan.Ostap out bound communication attempt (more info ...)trojan-activity    
41090SERVER-OTHER Rockwell Factorytalk RNADiagReceiver denial of service attempt (more info ...)denial-of-service 2012-0222   
41091PROTOCOL-SCADA Rockwell Controllogix Crash Ethernet attempt (more info ...)denial-of-service 2012-6438   URL
41093POLICY-OTHER Docker management traffic detected (more info ...)policy-violation 2016-9223   URL
41097SERVER-OTHER Moxa AWK-3131A serviceAgent information disclosure attempt (more info ...)attempted-recon 2016-8724   URL
41118SERVER-OTHER OpenSSL ChaCha20 Poly1305 heap-buffer overflow attempt (more info ...)attempted-dos 2016-7054   URL
41119SERVER-WEBAPP SourceBans advsearch banlist cross site scripting attempt (more info ...)attempted-user 2015-8349   URL
41133MALWARE-CNC Win.Trojan.Agent variant compromise download attempt (more info ...)trojan-activity    URL
41134MALWARE-CNC Win.Trojan.Agent variant compromise download attempt (more info ...)trojan-activity    URL
41135MALWARE-CNC Win.Trojan.Agent variant compromise download attempt (more info ...)trojan-activity    URL
41136MALWARE-CNC Win.Trojan.Agent variant compromise download attempt (more info ...)trojan-activity    URL
41162MALWARE-CNC Js.Trojan.Nemucod variant (more info ...)trojan-activity    URL
41173MALWARE-CNC Win.Trojan.August variant outbound connection (more info ...)trojan-activity    URL
41174MALWARE-CNC Win.Trojan.August variant outbound connection (more info ...)trojan-activity    URL
41175MALWARE-CNC Win.Trojan.August variant outbound connection (more info ...)trojan-activity    URL
41176MALWARE-CNC Win.Trojan.August variant outbound connection (more info ...)trojan-activity    URL
41177MALWARE-CNC Win.Trojan.August variant outbound connection (more info ...)trojan-activity    URL
41178MALWARE-CNC Win.Trojan.August variant outbound connection (more info ...)trojan-activity    URL
41179MALWARE-CNC Win.Trojan.August variant post compromise download attempt (more info ...)trojan-activity    URL
41180MALWARE-CNC Win.Trojan.August variant post compromise download attempt (more info ...)trojan-activity    URL
41206SERVER-OTHER Aerospike Database Server index name buffer overflow attempt (more info ...)attempted-admin 2016-9052   URL
41209SERVER-OTHER Aerospike Database Server Fabric particle_vtable out of bounds read attempt (more info ...)attempted-user 2016-9053   URL
41219SERVER-OTHER Aerospike Database Server Fabric denial of service attempt (more info ...)attempted-user 2016-9049   URL
41220SERVER-WEBAPP Moxa AWK-3131A web application HTTP response parameter injection attempt (more info ...)attempted-user 2016-8720   URL
41221SERVER-WEBAPP Moxa AWK-3131A web application HTTP response parameter injection attempt (more info ...)attempted-user 2016-8720   URL
41222SERVER-WEBAPP Moxa AWK-3131A web application web_runScript access attempt (more info ...)attempted-dos 2016-8726   URL
41227INDICATOR-SHELLCODE BSDi x86 bind stage (more info ...)shellcode-detect    
41228INDICATOR-SHELLCODE BSDi x86 reverse connect stage (more info ...)shellcode-detect    
41229INDICATOR-SHELLCODE BSDi x86 shell (more info ...)shellcode-detect    
41230INDICATOR-SHELLCODE BSDi x86 shell toupper (more info ...)shellcode-detect    
41231INDICATOR-SHELLCODE BSD PPC shell (more info ...)shellcode-detect    
41232INDICATOR-SHELLCODE BSD SPARC bind shell (more info ...)shellcode-detect    
41233INDICATOR-SHELLCODE BSD x86 bind stage (more info ...)shellcode-detect    
41234INDICATOR-SHELLCODE BSD x86 chroot (more info ...)shellcode-detect    
41235INDICATOR-SHELLCODE BSD x86 execute (more info ...)shellcode-detect    
41236INDICATOR-SHELLCODE BSD x86 FindRecv stage (more info ...)shellcode-detect    
41237INDICATOR-SHELLCODE BSD x86 FindSock shell (more info ...)shellcode-detect    
41238INDICATOR-SHELLCODE BSD x86 mail passwd (more info ...)shellcode-detect    
41239INDICATOR-SHELLCODE BSD x86 reverse connect shell (more info ...)shellcode-detect    
41240INDICATOR-SHELLCODE BSD x86 reverse connect shell (more info ...)shellcode-detect    
41241INDICATOR-SHELLCODE BSD x86 reverse stage (more info ...)shellcode-detect    
41242INDICATOR-SHELLCODE BSD x86 setuid shell (more info ...)shellcode-detect    
41243INDICATOR-SHELLCODE BSD x86 shell (more info ...)shellcode-detect    
41244INDICATOR-SHELLCODE BSD x86 shell - evade (more info ...)shellcode-detect    
41245INDICATOR-SHELLCODE BSD x86 shell - evade (more info ...)shellcode-detect    
41246INDICATOR-SHELLCODE freeBSD x86 kldload (more info ...)shellcode-detect    
41247INDICATOR-SHELLCODE freeBSD x86 shell - chown/chmod/exec (more info ...)shellcode-detect    
41248INDICATOR-SHELLCODE freeBSD x86 shell (more info ...)shellcode-detect    
41249INDICATOR-SHELLCODE freeBSD x86 shell (more info ...)shellcode-detect    
41250INDICATOR-SHELLCODE HP-UX PA-RISC shell (more info ...)shellcode-detect    
41251INDICATOR-SHELLCODE IRIX MIPS shell (more info ...)shellcode-detect    
41265INDICATOR-SHELLCODE Mac OS X PPC add user (more info ...)shellcode-detect    
41266INDICATOR-SHELLCODE Mac OS X PPC create setuid (more info ...)shellcode-detect    
41267INDICATOR-SHELLCODE Mac OS X PPC INETD backdoor (more info ...)shellcode-detect    
41268INDICATOR-SHELLCODE Mac OS X PPC reboot (more info ...)shellcode-detect    
41269INDICATOR-SHELLCODE Mac OS X PPC reverse shell (more info ...)shellcode-detect    
41270INDICATOR-SHELLCODE Mac OS X PPC reverse stage (more info ...)shellcode-detect    
41271INDICATOR-SHELLCODE Mac OS X PPC reverse stage null free (more info ...)shellcode-detect    
41272INDICATOR-SHELLCODE Mac OS X PPC shell (more info ...)shellcode-detect    
41273INDICATOR-SHELLCODE Mac OS X PPC shell setuid (more info ...)shellcode-detect    
41274INDICATOR-SHELLCODE Mac OS X PPC Xterm execution (more info ...)shellcode-detect    
41276INDICATOR-SHELLCODE Multi-OS shell - osx x86/ppc (more info ...)shellcode-detect    
41279INDICATOR-SHELLCODE NetBSD x86 reverse connect shell (more info ...)shellcode-detect    
41280INDICATOR-SHELLCODE NetBSD x86 shell (more info ...)shellcode-detect    
41281INDICATOR-SHELLCODE NetBSD x86 shell (more info ...)shellcode-detect    
41282INDICATOR-SHELLCODE NetBSD x86 shell (more info ...)shellcode-detect    
41283INDICATOR-SHELLCODE OpenBSD x86 add user (more info ...)shellcode-detect    
41284INDICATOR-SHELLCODE OpenBSD x86 bind shell (more info ...)shellcode-detect    
41289INDICATOR-SHELLCODE Windows x86 add user (more info ...)shellcode-detect    
41290INDICATOR-SHELLCODE Windows x86 download execute (more info ...)shellcode-detect    
41291INDICATOR-SHELLCODE Windows x86 EMET disable (more info ...)shellcode-detect    
41292INDICATOR-SHELLCODE Windows x86 PassiveX stage (more info ...)shellcode-detect    
41293INDICATOR-SHELLCODE x86 decoder (more info ...)shellcode-detect    
41294INDICATOR-SHELLCODE x86 decoder (more info ...)shellcode-detect    
41295INDICATOR-SHELLCODE x86 decoder (more info ...)shellcode-detect    
41296INDICATOR-SHELLCODE x86 decoder (more info ...)shellcode-detect    
41297INDICATOR-SHELLCODE x86 decoder (more info ...)shellcode-detect    
41308FILE-OTHER Dell Precision Optimizer dll-load exploit attempt (more info ...)attempted-user    URL
41309FILE-OTHER Dell Precision Optimizer dll-load exploit attempt (more info ...)attempted-user    URL
41315MALWARE-CNC Win.Trojan.DragonOK variant outbound connection (more info ...)trojan-activity    URL
41316MALWARE-CNC Win.Trojan.DragonOK variant outbound connection (more info ...)trojan-activity    URL
41317MALWARE-CNC Win.Trojan.DragonOK variant outbound connection (more info ...)trojan-activity    URL
41318MALWARE-CNC User-Agent known malicious user-agent string - Visbot (more info ...)trojan-activity    URL
41331MALWARE-CNC Win.Trojan.Scudy outbound connection (more info ...)trojan-activity    URL
41334MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
41335MALWARE-CNC Win.Trojan.Locky variant outbound connection (more info ...)trojan-activity    URL
41336MALWARE-CNC Andr.Trojan.Sysch variant outbound connection (more info ...)trojan-activity    URL
41337MALWARE-CNC Andr.Trojan.Sysch variant outbound connection (more info ...)trojan-activity    URL
41352SERVER-WEBAPP Moxa AWK-3131A Series cross-site request forgery attempt (more info ...)attempted-user 2016-8718   URL
41359SERVER-WEBAPP Trihedral VTScada WAP URI null byte injection attempt (more info ...)web-application-attack 2016-4532 91077  URL
41366SERVER-OTHER IBM Tivoli Storage Manager FastBack server denial of service attempt (more info ...)attempted-dos 2015-8523   URL
41368FILE-OTHER TRUFFLEHUNTER TALOS-2017-0273 attack attempt (more info ...)attempted-admin 2017-2779   URL
41369FILE-OTHER TRUFFLEHUNTER TALOS-2017-0273 attack attempt (more info ...)attempted-admin 2017-2779   URL
41374MALWARE-CNC Win.Trojan.NetWiredRC variant registration message (more info ...)trojan-activity    URL
41375MALWARE-CNC Win.Trojan.NetWiredRC variant check logs (more info ...)trojan-activity    URL
41376MALWARE-CNC Win.Trojan.NetWiredRC variant keepalive (more info ...)trojan-activity    URL
41379SERVER-OTHER Squid HTTP Vary response header denial of service attempt (more info ...)denial-of-service 2016-2569   URL
41380SERVER-OTHER OpenLDAP BER Message denial of service attempt (more info ...)attempted-dos 2015-6908   
41381SERVER-OTHER OpenLDAP BER Message denial of service attempt (more info ...)attempted-dos 2015-6908   
41382SERVER-OTHER OpenLDAP BER Message denial of service attempt (more info ...)attempted-dos 2015-6908   
41403MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda (more info ...)trojan-activity    URL
41424MALWARE-CNC Win.Trojan.Cerber outbound connection (more info ...)trojan-activity    URL
41434MALWARE-CNC Win.Trojan.Oilrig variant outbound connection (more info ...)trojan-activity    URL
41435MALWARE-CNC Win.Trojan.Oilrig variant outbound connection (more info ...)trojan-activity    URL
41436MALWARE-CNC Win.Trojan.Oilrig variant outbound connection (more info ...)trojan-activity    URL
41437MALWARE-CNC Win.Trojan.Oilrig variant outbound connection (more info ...)trojan-activity    URL
41438MALWARE-CNC Win.Trojan.Oilrig variant outbound connection (more info ...)trojan-activity    URL
41439MALWARE-CNC Dos.Tool.LOIC variant IRC command detected (more info ...)trojan-activity    URL
41440MALWARE-OTHER Dos.Tool.LOIC TCP default U dun goofed attack (more info ...)attempted-dos    URL
41441MALWARE-CNC User-Agent known malicious user-agent string - X-Mas (more info ...)trojan-activity    URL
41442MALWARE-CNC Win.Ransomware.X-Mas outbound connection (more info ...)trojan-activity    URL
41443MALWARE-CNC Win.Ransomware.X-Mas variant keylogger outbound connection (more info ...)trojan-activity    URL
41444MALWARE-CNC Win.Ransomware.X-Mas variant keylogger outbound connection (more info ...)trojan-activity    URL
41445SERVER-OTHER QNAP remote buffer overflow attempt (more info ...)attempted-admin    URL
41456MALWARE-CNC User-Agent known malicious user-agent string - Elite Keylogger (more info ...)trojan-activity    URL
41457MALWARE-CNC User-Agent known malicious user-agent string - Elite Keylogger (more info ...)trojan-activity    URL
41458MALWARE-CNC Osx.Keylogger.Elite variant outbound connection (more info ...)trojan-activity    URL
41459MALWARE-CNC Osx.Keylogger.Elite variant outbound connection (more info ...)trojan-activity    URL
41460MALWARE-CNC Osx.Keylogger.Elite variant outbound connection (more info ...)trojan-activity    URL
41461MALWARE-CNC Osx.Keylogger.Elite variant outbound connection (more info ...)trojan-activity    URL
41467SERVER-OTHER InsideSecure MatrixSSL x509 IssuerDomainPolicy remote code execution attempt (more info ...)attempted-user 2017-2781   URL
41476MALWARE-CNC Win.Trojan.Locky payload download - 987t67g (more info ...)trojan-activity    URL
41477MALWARE-CNC Win.Trojan.Vibrio file download - 4g3vg334 (more info ...)trojan-activity    URL
41478MALWARE-CNC Win.Trojan.Locky payload download - result (more info ...)trojan-activity    URL
41483FILE-OTHER LexMark Perceptive Document Filters BZIP2 convert out of bounds write attempt (more info ...)attempted-user 2016-4336   URL
41484FILE-OTHER LexMark Perceptive Document Filters BZIP2 convert out of bounds write attempt (more info ...)attempted-user 2016-4336   URL
41491BROWSER-PLUGINS NTR Check buffer overflow attempt (more info ...)attempted-user 2012-0266   URL
41492BROWSER-PLUGINS NTR Check buffer overflow attempt (more info ...)attempted-user 2012-0266   URL
41498MALWARE-CNC Win.Ransomware.CryptoLocker binary download response attempt (more info ...)trojan-activity    URL
41507SERVER-OTHER Pharos PopUp Printer Client DecodeString denial of service attempt (more info ...)denial-of-service 2017-2786   URL
41524INDICATOR-COMPROMISE SOCKS5 proxy server method negotiation on non-standard port (more info ...)trojan-activity    URL
41525INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41526INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41527INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41528INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41529INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41530INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41531INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41532INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41533INDICATOR-COMPROMISE SOCKS5 proxy inbound connection on non-standard port (more info ...)trojan-activity    URL
41534INDICATOR-COMPROMISE SOCKS5 proxy server method negotiation on non-standard port (more info ...)trojan-activity    URL
41537SERVER-OTHER Siemens WinCC TIA Portal DOS attempt (more info ...)attempted-dos    URL
41539MALWARE-CNC User-Agent known malicious user-agent string - Win.Malware.DistTrack (more info ...)trojan-activity    URL
41540MALWARE-CNC Win.Malware.Disttrack variant outbound connection (more info ...)trojan-activity    URL
41541SERVER-ORACLE Oracle reports servlet command execution attempt (more info ...)attempted-user 2005-2371 14316  URL
41542SERVER-ORACLE Oracle reports servlet command execution attempt (more info ...)attempted-user 2005-2371 14316  URL
41640FILE-EXECUTABLE QuickHeal Internet Security malformed Mach-O file buffer overflow attempt (more info ...)attempted-admin 2017-5005   
41641FILE-EXECUTABLE QuickHeal Internet Security malformed Mach-O file buffer overflow attempt (more info ...)attempted-admin 2017-5005   
41648PROTOCOL-SCADA SCADA Trace Mode DoS attempt (more info ...)attempted-dos    URL
41651SERVER-OTHER Schneider Electric ETY Telnet DOS attempt (more info ...)attempted-dos    URL
41656MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.MagicHound (more info ...)trojan-activity    URL
41657MALWARE-CNC Win.Trojan.MagicHound variant outbound connection (more info ...)trojan-activity    URL
41660MALWARE-OTHER VBScript potential executable write attempt (more info ...)trojan-activity    URL
41661MALWARE-CNC Osx.Downloader.MacDownloader variant outbound connection (more info ...)trojan-activity    URL
41662MALWARE-CNC Osx.Downloader.MacDownloader variant outbound connection (more info ...)trojan-activity    URL
41663MALWARE-CNC Osx.Downloader.MacDownloader variant outbound connection (more info ...)trojan-activity    URL
41664PUA-ADWARE Win.Adware.Xiazai variant outbound connection (more info ...)misc-activity    URL
41665MALWARE-CNC Win.Trojan.Mirai variant outbound connection (more info ...)trojan-activity    URL
41670SERVER-WEBAPP Netgear ReadyNAS np_handler command injection attempt (more info ...)web-application-attack 2013-2751   
41671SERVER-WEBAPP Netgear ReadyNAS np_handler command injection attempt (more info ...)web-application-attack 2013-2751   
41672SERVER-WEBAPP Netgear ReadyNAS np_handler command injection attempt (more info ...)web-application-attack 2013-2751   
41682MALWARE-CNC Win.Trojan.Malear variant outbound connection (more info ...)trojan-activity    URL
41683MALWARE-CNC Win.Trojan.Malear variant outbound connection (more info ...)trojan-activity    URL
41684MALWARE-CNC Win.Trojan.Malear variant outbound connection (more info ...)trojan-activity    URL
41685MALWARE-CNC Win.Trojan.Malear variant outbound connection (more info ...)trojan-activity    URL
41686MALWARE-CNC Win.Trojan.Malear variant outbound connection (more info ...)trojan-activity    URL
41687MALWARE-CNC Win.Trojan.Malear variant outbound connection (more info ...)trojan-activity    URL
41691SERVER-WEBAPP Siemens WinCC DoS attempt (more info ...)attempted-dos    URL
41702MALWARE-CNC Win.Adware.Winwrapper outbound connection (more info ...)trojan-activity    URL
41711MALWARE-CNC Win.Trojan.Houdini variant initial outbound connection (more info ...)trojan-activity    URL
41712MALWARE-CNC Win.Trojan.Houdini backdoor file download request (more info ...)trojan-activity    URL
41713SERVER-WEBAPP DotNetNuke installation attempt detected (more info ...)attempted-admin 2015-2794   URL
41714INDICATOR-OBFUSCATION rfc822 HTTP transfer encoding attempt (more info ...)policy-violation    URL
41721SERVER-WEBAPP Mikrotik Syslog Server DoS attempt (more info ...)attempted-dos    URL
41736SERVER-OTHER Beck IPC CHIP DoS attempt (more info ...)attempted-dos 2001-1337   
41737PROTOCOL-SCADA Sunway DOS attempt (more info ...)attempted-dos    URL
41738PROTOCOL-SCADA Sunway DOS attempt (more info ...)attempted-dos    URL
41739PROTOCOL-SCADA Moxa Mass Config Tool DOS attempt (more info ...)attempted-dos    URL
41780MALWARE-CNC Win.Trojan.Ratankba variant outbound connection (more info ...)trojan-activity    URL
41784INDICATOR-COMPROMISE clorius controls information gathering attempt (more info ...)attempted-recon    URL
41785SERVER-WEBAPP carel plantvisor directory traversal exploitation attempt (more info ...)web-application-attack    URL
41799SERVER-OTHER IBM Tivoli Storage Manager Fastback buffer overflow attempt (more info ...)attempted-admin 2015-8521   
41800SERVER-OTHER IBM Tivoli Storage Manager Fastback buffer overflow attempt (more info ...)attempted-admin 2015-8520   
41801SERVER-OTHER IBM Tivoli Storage Manager Fastback buffer overflow attempt (more info ...)attempted-admin 2015-8522   
41802SERVER-OTHER IBM Tivoli Storage Manager Fastback buffer overflow attempt (more info ...)attempted-admin 2015-8519   
41820SERVER-WEBAPP Reprise License Manager diagnostics_doit outputfile directory traversal attempt (more info ...)web-application-attack    
41823SERVER-OTHER Nagios Core privilege escalation attempt (more info ...)attempted-admin 2016-9566   URL
41824SERVER-OTHER Nagios Core privilege escalation attempt (more info ...)attempted-admin 2016-9566   URL
41827BROWSER-PLUGINS WebGate eDVR Manager WESPPlayback access attempt (more info ...)attempted-admin 2015-2098   
41828BROWSER-PLUGINS WebGate eDVR Manager WESPPlayback access attempt (more info ...)attempted-admin 2015-2098   
41830BROWSER-PLUGINS WebGate eDVR Manager WESPPlayback access attempt (more info ...)attempted-admin 2015-2098   
41831BROWSER-PLUGINS WebGate eDVR Manager WESPPTZ access attempt (more info ...)attempted-admin 2015-2098   
41832BROWSER-PLUGINS WebGate eDVR Manager WESPPTZ access attempt (more info ...)attempted-admin 2015-2098   
41833BROWSER-PLUGINS WebGate eDVR Manager WESPPTZ access attempt (more info ...)attempted-admin 2015-2098   
41834BROWSER-PLUGINS WebGate eDVR Manager WESPPTZ access attempt (more info ...)attempted-admin 2015-2098   
41835BROWSER-PLUGINS WebGate eDVR Manager WESPEvent access attempt (more info ...)attempted-admin 2015-2098   
41836BROWSER-PLUGINS WebGate eDVR Manager WESPEvent access attempt (more info ...)attempted-admin 2015-2098   
41837BROWSER-PLUGINS WebGate eDVR Manager WESPEvent access attempt (more info ...)attempted-admin 2015-2098   
41838BROWSER-PLUGINS WebGate eDVR Manager WESPEvent access attempt (more info ...)attempted-admin 2015-2098   
41851SERVER-OTHER Valhala Honeypot ABOR command buffer overflow attempt (more info ...)attempted-user    URL
41856SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41857SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2018-10602   
41858SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2018-10602   
41859SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41860SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41861SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41862SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41863SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41864SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41865SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41866SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41867SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41868SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41869SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41870SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41871SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41872SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41873SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41874SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41875SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41876SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41877SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41878SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41879SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41880SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41881SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2016-5781   
41883SERVER-OTHER ImageMagick mvg label arbitrary file read attempt (more info ...)attempted-admin 2016-3717   
41884SERVER-OTHER ImageMagick mvg label arbitrary file read attempt (more info ...)attempted-admin 2016-3717   
41885SERVER-OTHER ImageMagick mvg label arbitrary file read attempt (more info ...)attempted-admin 2016-3717   
41886SERVER-OTHER ImageMagick mvg label arbitrary file read attempt (more info ...)attempted-admin 2016-3717   
41887SERVER-OTHER ImageMagick mvg label arbitrary file read attempt (more info ...)attempted-admin 2016-3717   
41888SERVER-OTHER ImageMagick mvg label arbitrary file read attempt (more info ...)attempted-admin 2016-3717   
41889POLICY-OTHER ImageMagick magick vector graphics msl access attempt (more info ...)policy-violation 2016-3716   
41890POLICY-OTHER ImageMagick magick vector graphics msl access attempt (more info ...)policy-violation 2016-3716   
41891POLICY-OTHER ImageMagick magick vector graphics msl access attempt (more info ...)policy-violation 2016-3716   
41892POLICY-OTHER ImageMagick magick vector graphics msl access attempt (more info ...)policy-violation 2016-3716   
41893POLICY-OTHER ImageMagick magick vector graphics msl access attempt (more info ...)policy-violation 2016-3716   
41894POLICY-OTHER ImageMagick magick vector graphics msl access attempt (more info ...)policy-violation 2016-3716   
41897POLICY-OTHER ImageMagick magick vector graphics ephemeral access attempt (more info ...)policy-violation 2016-3715   
41898POLICY-OTHER ImageMagick magick vector graphics ephemeral access attempt (more info ...)policy-violation 2016-3715   
41899POLICY-OTHER ImageMagick magick vector graphics ephemeral access attempt (more info ...)policy-violation 2016-3715   
41900POLICY-OTHER ImageMagick magick vector graphics ephemeral access attempt (more info ...)policy-violation 2016-3715   
41901POLICY-OTHER ImageMagick magick vector graphics ephemeral access attempt (more info ...)policy-violation 2016-3715   
41902POLICY-OTHER ImageMagick magick vector graphics ephemeral access attempt (more info ...)policy-violation 2016-3715   
41907POLICY-OTHER SSL/TLS weak RC4 cipher suite use attempt (more info ...)policy-violation 2015-2808 73684  
41908EXPLOIT-KIT Exploit kit Pseudo-Darkleech Gate redirection attempt (more info ...)attempted-user    
41913SERVER-WEBAPP InterSystem Cache DOS attempt (more info ...)web-application-attack    URL
41921SERVER-WEBAPP PAESSLER PRTG DoS attempt (more info ...)attempted-dos    URL
41924FILE-OTHER Notepad++ request for scilexer.dll over SMB attempt (more info ...)attempted-user    URL
41925FILE-OTHER Notepad++ scilexer.dll dll-load exploit attempt (more info ...)attempted-user    URL
41947FILE-IMAGE GDI+ malformed EMF description out of bounds read attempt (more info ...)attempted-admin 2018-12849   URL
42000SERVER-OTHER WolfSSL X509 parsing off-by-one code execution attempt (more info ...)attempted-user 2017-2800   URL
42015SERVER-OTHER Randombit Botan Library X509 DistinguishedName out of bounds read attempt (more info ...)attempted-user 2017-2801   URL
42017INDICATOR-OBFUSCATION Gzip encoded HTTP response with no Content-Length or chunked Transfer-Encoding header (more info ...)non-standard-protocol    URL
42019MALWARE-CNC User-Agent known malicious user-agent string - Andr.Trojan.Agent (more info ...)trojan-activity    URL
42020MALWARE-CNC User-Agent known malicious user-agent string - Andr.Trojan.Agent (more info ...)trojan-activity    URL
42021MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
42022MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
42023MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
42024MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
42025MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
42026MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
42027MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
42028MALWARE-CNC Andr.Trojan.Agent variant file download attempt (more info ...)trojan-activity    URL
42029MALWARE-CNC Andr.Trojan.Agent variant file download attempt (more info ...)trojan-activity    URL
42030MALWARE-CNC Andr.Trojan.Agent variant file download attempt (more info ...)trojan-activity    URL
42031MALWARE-CNC Andr.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
42054PROTOCOL-SCADA Moxa get SNMP read string attempt (more info ...)attempted-admin    URL
42057PROTOCOL-SCADA Moxa unlock function code attempt (more info ...)attempted-admin    URL
42058PROTOCOL-SCADA Moxa unlock function code attempt (more info ...)attempted-admin    URL
42059MALWARE-CNC Win.Ransomware.Sage variant outbound connection (more info ...)trojan-activity    URL
42062SERVER-WEBAPP xArrow heap corruption exploitation attempt (more info ...)attempted-dos 2012-2427   URL
42063SERVER-WEBAPP xArrow null pointer denial of service exploitation attempt (more info ...)attempted-dos 2012-2426   URL
42064SERVER-OTHER kaskad SCADA daserver heap overflow exploitation attempt (more info ...)attempted-user    URL
42065SERVER-OTHER kaskad SCADA daserver heap overflow exploitation attempt (more info ...)attempted-user    URL
42067POLICY-OTHER Aviosys IP Power 9258 W2 management.asp information disclosure (more info ...)web-application-attack    URL
42068POLICY-OTHER Aviosys IP Power 9258 W2 default login attempt (more info ...)web-application-attack    URL
42072SERVER-WEBAPP Aultware pwStore denial of service attempt (more info ...)web-application-attack 2013-5657   
42073PROTOCOL-SCADA TraceMode Runtime DOS attempt (more info ...)attempted-dos    URL
42079MALWARE-CNC Win.Trojan.Jenxcus outbound connection with unique User-Agent (more info ...)trojan-activity    URL
42080MALWARE-CNC Win.Trojan.Jenxcus outbound connection with unique User-Agent (more info ...)trojan-activity    URL
42081MALWARE-CNC Win.Trojan.Jenxcus outbound POST request attempt (more info ...)trojan-activity    URL
42082INDICATOR-COMPROMISE Request for external IP address detected (more info ...)trojan-activity    URL
42083MALWARE-CNC Win.Trojan.Downeks variant initial outbound connection (more info ...)trojan-activity    URL
42084FILE-IMAGE Corel Photo Paint invalid NewSubFileType memory corruption attempt (more info ...)attempted-user 2017-2803   URL
42085FILE-IMAGE Corel Photo Paint invalid NewSubFileType memory corruption attempt (more info ...)attempted-user 2017-2803   URL
42086FILE-IMAGE Corel Photo Paint invalid NewSubFileType memory corruption attempt (more info ...)attempted-user 2017-2803   URL
42087FILE-IMAGE Corel Photo Paint invalid NewSubFileType memory corruption attempt (more info ...)attempted-user 2017-2803   URL
42092POLICY-OTHER NetBiter WebSCADA ws100/ws200 logo modification attempt (more info ...)web-application-attack 2010-4732   URL
42094SERVER-WEBAPP NetBiter WebSCADA ws100/ws200 information gathering attempt (more info ...)web-application-attack 2010-4731   URL
42095SERVER-WEBAPP NetBiter WebSCADA ws100/ws200 directory traversal attempt (more info ...)web-application-attack 2010-4730   URL
42098MALWARE-CNC Win.Trojan.Winpud encoded payload download attempt (more info ...)trojan-activity    URL
42099MALWARE-CNC Win.Trojan.Winpud encoded payload download attempt (more info ...)trojan-activity    URL
42100FILE-EXECUTABLE AnC MMU side channel ASLR bypass attack (more info ...)attempted-recon 2017-5927   URL
42101FILE-EXECUTABLE AnC MMU side channel ASLR bypass attack (more info ...)attempted-recon 2017-5927   URL
42109PROTOCOL-SCADA invalid modbus protocol identifier (more info ...)misc-activity    URL
42126MALWARE-CNC Win.Trojan.Acronym variant outbound connection (more info ...)trojan-activity    URL
42127PROTOCOL-SCADA Eaton Network Pi3Web DOS attempt (more info ...)attempted-dos 2003-0276   
42128MALWARE-CNC Win.Trojan.Ismdoor variant outbound connection (more info ...)trojan-activity    URL
42129MALWARE-CNC Win.Trojan.Ismdoor variant outbound connection (more info ...)trojan-activity    URL
42134SERVER-WEBAPP GE Proficy CimWeb substitute.bcl arbitrary file access attempt (more info ...)web-application-attack 2013-0653   URL
42135SERVER-WEBAPP GE Proficy CimWeb substitute.bcl arbitrary file access attempt (more info ...)web-application-attack 2013-0653   URL
42136SERVER-WEBAPP Infinite Automation Mango Automation info leak attempt (more info ...)attempted-recon 2015-7900   
42171MALWARE-CNC Win.Downloader.Agent variant outbound connection (more info ...)trojan-activity    URL
42172MALWARE-CNC Win.Downloader.Agent variant certificate negotiation (more info ...)trojan-activity    URL
42223FILE-IDENTIFY AOP file download request (more info ...)misc-activity    
42224SERVER-OTHER Moxa MX-AOPC XML external entity injection attempt (more info ...)attempted-admin 2017-7457   
42225MALWARE-CNC Win.Trojan.RedLeaves outbound connection (more info ...)trojan-activity    URL
42227SERVER-OTHER NTP Config Unpeer denial of service attempt (more info ...)denial-of-service 2017-6463   URL
42228MALWARE-CNC Win.Trojan.DocumentCrypt variant outbound connection (more info ...)trojan-activity    URL
42229INDICATOR-COMPROMISE RTF url moniker COM file download attempt (more info ...)misc-activity 2017-0199   
42230INDICATOR-COMPROMISE RTF url moniker COM file download attempt (more info ...)misc-activity 2017-0199   
42233MALWARE-CNC Win.Trojan.Mikcer variant outbound connection (more info ...)trojan-activity    URL
42242MALWARE-CNC Win.Downloader.Dimnie file download attempt (more info ...)trojan-activity    URL
42243MALWARE-CNC Win.Trojan.Dimnie outbound connection (more info ...)trojan-activity    URL
42263FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42264FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42265FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42266FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42267FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42268FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42269FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42270FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42271FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42272FILE-OTHER Power Software PowerISO stack buffer overflow attempt (more info ...)attempted-user 2017-2817   URL
42277FILE-OTHER TRUFFLEHUNTER TALOS-2017-0317 attack attempt (more info ...)attempted-user 2017-2816   URL
42278FILE-OTHER TRUFFLEHUNTER TALOS-2017-0317 attack attempt (more info ...)attempted-user 2017-2816   URL
42284PROTOCOL-SCADA 3S CoDeSys Gateway Server DOS attempt (more info ...)attempted-dos    URL
42295SERVER-WEBAPP Events HMI information disclosure attempt (more info ...)attempted-recon    
42300SERVER-WEBAPP SensorIP2 default credentials enumeration attempt (more info ...)web-application-attack    URL
42301MALWARE-CNC Win.Trojan.Kuaibu inbound server configuration response (more info ...)trojan-activity    URL
42302MALWARE-CNC Win.Trojan.Kuaibu outbound connection (more info ...)trojan-activity    URL
42303MALWARE-CNC Win.Trojan.Kuaibu outbound file download attempt (more info ...)trojan-activity    URL
42304FILE-OTHER fwpuclnt dll-load exploit attempt (more info ...)attempted-user    URL
42305FILE-OTHER fwpuclnt dll-load exploit attempt (more info ...)attempted-user    URL
42319FILE-PDF Poppler PDF library embedded jp2 COD levels integer overflow attempt (more info ...)attempted-admin 2017-2820   URL
42320FILE-PDF Poppler PDF library embedded jp2 COD levels integer overflow attempt (more info ...)attempted-admin 2017-2820   URL
42323SERVER-WEBAPP IOServer OPC Server directory traversal exploitation attempt (more info ...)web-application-attack 2012-4680   URL
42329MALWARE-CNC Win.Trojan.Doublepulsar variant successful ping response (more info ...)trojan-activity    URL
42330MALWARE-CNC Win.Trojan.Doublepulsar variant successful injection response (more info ...)trojan-activity    URL
42331MALWARE-CNC Win.Trojan.Doublepulsar variant process injection command (more info ...)trojan-activity    URL
42332MALWARE-CNC Win.Trojan.Doublepulsar variant ping command (more info ...)trojan-activity    URL
42348MALWARE-CNC Win.Trojan.QQPass variant outbound connection (more info ...)trojan-activity    URL
42349PROTOCOL-SCADA InduSoft Web Studio CEServer buffer overflow attempt (more info ...)misc-activity    URL
42350PROTOCOL-SCADA InduSoft Web Studio CEServer buffer overflow attempt (more info ...)misc-activity    URL
42351PROTOCOL-SCADA InduSoft Web Studio CEServer buffer overflow attempt (more info ...)misc-activity 2011-4052   URL
42352FILE-PDF Poppler readProgressiveSOF out of bounds write attempt (more info ...)attempted-user 2017-2818   URL
42353FILE-PDF Poppler readProgressiveSOF out of bounds write attempt (more info ...)attempted-user 2017-2818   URL
42363FILE-IDENTIFY bzip2 compressed file detected (more info ...)misc-activity    
42364FILE-IDENTIFY bzip2 compressed file detected (more info ...)misc-activity    
42365FILE-IDENTIFY bzip2 compressed file detected (more info ...)misc-activity    
42366FILE-IDENTIFY XZ compressed file detected (more info ...)misc-activity    
42367FILE-IDENTIFY XZ compressed file detected (more info ...)misc-activity    
42368FILE-IDENTIFY XZ compressed file detected (more info ...)misc-activity    
42369FILE-IDENTIFY gzip compressed file detected (more info ...)misc-activity    
42370FILE-IDENTIFY gzip compressed file detected (more info ...)misc-activity    
42371FILE-IDENTIFY gzip compressed file detected (more info ...)misc-activity    
42378SERVER-OTHER Yealink VoIP phone remote code execution attempt (more info ...)attempted-admin 2013-5758 68052  
42379SERVER-WEBAPP OpenCart directory traversal attempt (more info ...)web-application-attack 2013-1891   
42380SERVER-WEBAPP OpenCart directory traversal attempt (more info ...)web-application-attack 2013-1891   
42381SERVER-WEBAPP OpenCart directory traversal attempt (more info ...)web-application-attack 2013-1891   
42385MALWARE-CNC Win.Trojan.Moonwind outbound connection (more info ...)trojan-activity    URL
42386MALWARE-CNC Win.Trojan.Mikcer variant outbound connection (more info ...)trojan-activity    URL
42387SERVER-WEBAPP DataRate SCADA directory traversal attempt (more info ...)web-application-attack 2007-6483   
42388SERVER-WEBAPP DataRate SCADA directory traversal attempt (more info ...)web-application-attack 2008-0760   
42390MALWARE-CNC Win.Trojan.Moarider variant outbound connection (more info ...)trojan-activity    URL
42391MALWARE-CNC Win.Trojan.Moarider variant outbound connection (more info ...)trojan-activity    URL
42395MALWARE-CNC Win.Trojan.Oddjob outbound connection (more info ...)trojan-activity    URL
42398MALWARE-CNC Win.Trojan.RedLeaves outbound connection (more info ...)trojan-activity    URL
42399FILE-PDF TRUFFLEHUNTER TALOS-2017-0323 attack attempt (more info ...)attempted-user 2017-2822   URL
42400FILE-PDF TRUFFLEHUNTER TALOS-2017-0323 attack attempt (more info ...)attempted-user 2017-2822   URL
42401SERVER-WEBAPP multiple product version scan attempt (more info ...)attempted-recon    URL
42402SERVER-WEBAPP multiple product command injection attempt (more info ...)attempted-admin    URL
42418FILE-EXECUTABLE Win.Trojan.DoubleAgent download attempt (more info ...)attempted-user    URL
42419FILE-EXECUTABLE Win.Trojan.DoubleAgent download attempt (more info ...)attempted-user    URL
42421MALWARE-CNC Win.Trojan.Cerber variant inbound connection attempt (more info ...)trojan-activity    URL
42425MALWARE-CNC Win.Trojan.ChChes set cookie tag inbound connection (more info ...)trojan-activity    URL
42439MALWARE-CNC Win.Trojan.Axespec outbound request (more info ...)trojan-activity    URL
42447MALWARE-CNC Win.Trojan.Batlopma variant outbound connection (more info ...)trojan-activity    URL
42452MALWARE-CNC Win.Trojan.Frethog variant outbound connection (more info ...)trojan-activity    URL
42453MALWARE-CNC Win.Trojan.Frethog variant inbound connection attempt (more info ...)trojan-activity    URL
42454MALWARE-CNC User-Agent known malicious user-agent string - Frethog (more info ...)trojan-activity    URL
42463FILE-IMAGE Foxit Reader malformed DataSubBlock size attempt (more info ...)denial-of-service 2015-2790   
42464FILE-IMAGE Foxit Reader malformed DataSubBlock size attempt (more info ...)denial-of-service 2015-2790   
42465SERVER-WEBAPP triple dot directory traversal attempt (more info ...)web-application-attack 2012-5972   
42492APP-DETECT Intel AMT DHCP boot request detected (more info ...)policy-violation    URL
42494FILE-EXECUTABLE XOR 0x01 encrypted portable executable file download attempt (more info ...)policy-violation    
42495FILE-EXECUTABLE XOR 0x02 encrypted portable executable file download attempt (more info ...)policy-violation    
42496FILE-EXECUTABLE XOR 0x03 encrypted portable executable file download attempt (more info ...)policy-violation    
42497FILE-EXECUTABLE XOR 0x04 encrypted portable executable file download attempt (more info ...)policy-violation    
42498FILE-EXECUTABLE XOR 0x05 encrypted portable executable file download attempt (more info ...)policy-violation    
42499FILE-EXECUTABLE XOR 0x06 encrypted portable executable file download attempt (more info ...)policy-violation    
42500FILE-EXECUTABLE XOR 0x07 encrypted portable executable file download attempt (more info ...)policy-violation    
42501FILE-EXECUTABLE XOR 0x08 encrypted portable executable file download attempt (more info ...)policy-violation    
42502FILE-EXECUTABLE XOR 0x09 encrypted portable executable file download attempt (more info ...)policy-violation    
42503FILE-EXECUTABLE XOR 0x0a encrypted portable executable file download attempt (more info ...)policy-violation    
42504FILE-EXECUTABLE XOR 0x0b encrypted portable executable file download attempt (more info ...)policy-violation    
42505FILE-EXECUTABLE XOR 0x0c encrypted portable executable file download attempt (more info ...)policy-violation    
42506FILE-EXECUTABLE XOR 0x0d encrypted portable executable file download attempt (more info ...)policy-violation    
42507FILE-EXECUTABLE XOR 0x0e encrypted portable executable file download attempt (more info ...)policy-violation    
42508FILE-EXECUTABLE XOR 0x0f encrypted portable executable file download attempt (more info ...)policy-violation    
42509FILE-EXECUTABLE XOR 0x10 encrypted portable executable file download attempt (more info ...)policy-violation    
42511FILE-EXECUTABLE XOR 0x12 encrypted portable executable file download attempt (more info ...)policy-violation    
42512FILE-EXECUTABLE XOR 0x13 encrypted portable executable file download attempt (more info ...)policy-violation    
42513FILE-EXECUTABLE XOR 0x14 encrypted portable executable file download attempt (more info ...)policy-violation    
42514FILE-EXECUTABLE XOR 0x15 encrypted portable executable file download attempt (more info ...)policy-violation    
42515FILE-EXECUTABLE XOR 0x16 encrypted portable executable file download attempt (more info ...)policy-violation    
42516FILE-EXECUTABLE XOR 0x17 encrypted portable executable file download attempt (more info ...)policy-violation    
42517FILE-EXECUTABLE XOR 0x18 encrypted portable executable file download attempt (more info ...)policy-violation    
42518FILE-EXECUTABLE XOR 0x19 encrypted portable executable file download attempt (more info ...)policy-violation    
42519FILE-EXECUTABLE XOR 0x1a encrypted portable executable file download attempt (more info ...)policy-violation    
42520FILE-EXECUTABLE XOR 0x1b encrypted portable executable file download attempt (more info ...)policy-violation    
42521FILE-EXECUTABLE XOR 0x1c encrypted portable executable file download attempt (more info ...)policy-violation    
42522FILE-EXECUTABLE XOR 0x1d encrypted portable executable file download attempt (more info ...)policy-violation    
42523FILE-EXECUTABLE XOR 0x1e encrypted portable executable file download attempt (more info ...)policy-violation    
42524FILE-EXECUTABLE XOR 0x1f encrypted portable executable file download attempt (more info ...)policy-violation    
42525FILE-EXECUTABLE XOR 0x20 encrypted portable executable file download attempt (more info ...)policy-violation    
42526FILE-EXECUTABLE XOR 0x21 encrypted portable executable file download attempt (more info ...)policy-violation    
42527FILE-EXECUTABLE XOR 0x22 encrypted portable executable file download attempt (more info ...)policy-violation    
42528FILE-EXECUTABLE XOR 0x23 encrypted portable executable file download attempt (more info ...)policy-violation    
42529FILE-EXECUTABLE XOR 0x24 encrypted portable executable file download attempt (more info ...)policy-violation    
42530FILE-EXECUTABLE XOR 0x25 encrypted portable executable file download attempt (more info ...)policy-violation    
42531FILE-EXECUTABLE XOR 0x26 encrypted portable executable file download attempt (more info ...)policy-violation    
42532FILE-EXECUTABLE XOR 0x27 encrypted portable executable file download attempt (more info ...)policy-violation    
42533FILE-EXECUTABLE XOR 0x28 encrypted portable executable file download attempt (more info ...)policy-violation    
42534FILE-EXECUTABLE XOR 0x29 encrypted portable executable file download attempt (more info ...)policy-violation    
42535FILE-EXECUTABLE XOR 0x2a encrypted portable executable file download attempt (more info ...)policy-violation    
42536FILE-EXECUTABLE XOR 0x2b encrypted portable executable file download attempt (more info ...)policy-violation    
42537FILE-EXECUTABLE XOR 0x2c encrypted portable executable file download attempt (more info ...)policy-violation    
42538FILE-EXECUTABLE XOR 0x2d encrypted portable executable file download attempt (more info ...)policy-violation    
42539FILE-EXECUTABLE XOR 0x2e encrypted portable executable file download attempt (more info ...)policy-violation    
42540FILE-EXECUTABLE XOR 0x2f encrypted portable executable file download attempt (more info ...)policy-violation    
42541FILE-EXECUTABLE XOR 0x30 encrypted portable executable file download attempt (more info ...)policy-violation    
42542FILE-EXECUTABLE XOR 0x31 encrypted portable executable file download attempt (more info ...)policy-violation    
42543FILE-EXECUTABLE XOR 0x32 encrypted portable executable file download attempt (more info ...)policy-violation    
42544FILE-EXECUTABLE XOR 0x33 encrypted portable executable file download attempt (more info ...)policy-violation    
42545FILE-EXECUTABLE XOR 0x34 encrypted portable executable file download attempt (more info ...)policy-violation    
42546FILE-EXECUTABLE XOR 0x35 encrypted portable executable file download attempt (more info ...)policy-violation    
42547FILE-EXECUTABLE XOR 0x36 encrypted portable executable file download attempt (more info ...)policy-violation    
42548FILE-EXECUTABLE XOR 0x37 encrypted portable executable file download attempt (more info ...)policy-violation    
42549FILE-EXECUTABLE XOR 0x38 encrypted portable executable file download attempt (more info ...)policy-violation    
42550FILE-EXECUTABLE XOR 0x39 encrypted portable executable file download attempt (more info ...)policy-violation    
42551FILE-EXECUTABLE XOR 0x3a encrypted portable executable file download attempt (more info ...)policy-violation    
42552FILE-EXECUTABLE XOR 0x3b encrypted portable executable file download attempt (more info ...)policy-violation    
42553FILE-EXECUTABLE XOR 0x3c encrypted portable executable file download attempt (more info ...)policy-violation    
42554FILE-EXECUTABLE XOR 0x3d encrypted portable executable file download attempt (more info ...)policy-violation    
42555FILE-EXECUTABLE XOR 0x3e encrypted portable executable file download attempt (more info ...)policy-violation    
42556FILE-EXECUTABLE XOR 0x3f encrypted portable executable file download attempt (more info ...)policy-violation    
42557FILE-EXECUTABLE XOR 0x40 encrypted portable executable file download attempt (more info ...)policy-violation    
42558FILE-EXECUTABLE XOR 0x41 encrypted portable executable file download attempt (more info ...)policy-violation    
42559FILE-EXECUTABLE XOR 0x42 encrypted portable executable file download attempt (more info ...)policy-violation    
42560FILE-EXECUTABLE XOR 0x43 encrypted portable executable file download attempt (more info ...)policy-violation    
42561FILE-EXECUTABLE XOR 0x44 encrypted portable executable file download attempt (more info ...)policy-violation    
42562FILE-EXECUTABLE XOR 0x45 encrypted portable executable file download attempt (more info ...)policy-violation    
42563FILE-EXECUTABLE XOR 0x46 encrypted portable executable file download attempt (more info ...)policy-violation    
42564FILE-EXECUTABLE XOR 0x47 encrypted portable executable file download attempt (more info ...)policy-violation    
42565FILE-EXECUTABLE XOR 0x48 encrypted portable executable file download attempt (more info ...)policy-violation    
42566FILE-EXECUTABLE XOR 0x49 encrypted portable executable file download attempt (more info ...)policy-violation    
42567FILE-EXECUTABLE XOR 0x4a encrypted portable executable file download attempt (more info ...)policy-violation    
42568FILE-EXECUTABLE XOR 0x4b encrypted portable executable file download attempt (more info ...)policy-violation    
42569FILE-EXECUTABLE XOR 0x4c encrypted portable executable file download attempt (more info ...)policy-violation    
42570FILE-EXECUTABLE XOR 0x4d encrypted portable executable file download attempt (more info ...)policy-violation    
42571FILE-EXECUTABLE XOR 0x4e encrypted portable executable file download attempt (more info ...)policy-violation    
42572FILE-EXECUTABLE XOR 0x4f encrypted portable executable file download attempt (more info ...)policy-violation    
42573FILE-EXECUTABLE XOR 0x50 encrypted portable executable file download attempt (more info ...)policy-violation    
42574FILE-EXECUTABLE XOR 0x51 encrypted portable executable file download attempt (more info ...)policy-violation    
42575FILE-EXECUTABLE XOR 0x52 encrypted portable executable file download attempt (more info ...)policy-violation    
42576FILE-EXECUTABLE XOR 0x53 encrypted portable executable file download attempt (more info ...)policy-violation    
42577FILE-EXECUTABLE XOR 0x54 encrypted portable executable file download attempt (more info ...)policy-violation    
42578FILE-EXECUTABLE XOR 0x55 encrypted portable executable file download attempt (more info ...)policy-violation    
42579FILE-EXECUTABLE XOR 0x56 encrypted portable executable file download attempt (more info ...)policy-violation    
42580FILE-EXECUTABLE XOR 0x57 encrypted portable executable file download attempt (more info ...)policy-violation    
42581FILE-EXECUTABLE XOR 0x58 encrypted portable executable file download attempt (more info ...)policy-violation    
42582FILE-EXECUTABLE XOR 0x59 encrypted portable executable file download attempt (more info ...)policy-violation    
42583FILE-EXECUTABLE XOR 0x5a encrypted portable executable file download attempt (more info ...)policy-violation    
42584FILE-EXECUTABLE XOR 0x5b encrypted portable executable file download attempt (more info ...)policy-violation    
42585FILE-EXECUTABLE XOR 0x5c encrypted portable executable file download attempt (more info ...)policy-violation    
42586FILE-EXECUTABLE XOR 0x5d encrypted portable executable file download attempt (more info ...)policy-violation    
42587FILE-EXECUTABLE XOR 0x5e encrypted portable executable file download attempt (more info ...)policy-violation    
42588FILE-EXECUTABLE XOR 0x5f encrypted portable executable file download attempt (more info ...)policy-violation    
42589FILE-EXECUTABLE XOR 0x60 encrypted portable executable file download attempt (more info ...)policy-violation    
42590FILE-EXECUTABLE XOR 0x61 encrypted portable executable file download attempt (more info ...)policy-violation    
42591FILE-EXECUTABLE XOR 0x62 encrypted portable executable file download attempt (more info ...)policy-violation    
42592FILE-EXECUTABLE XOR 0x63 encrypted portable executable file download attempt (more info ...)policy-violation    
42593FILE-EXECUTABLE XOR 0x64 encrypted portable executable file download attempt (more info ...)policy-violation    
42594FILE-EXECUTABLE XOR 0x65 encrypted portable executable file download attempt (more info ...)policy-violation    
42595FILE-EXECUTABLE XOR 0x66 encrypted portable executable file download attempt (more info ...)policy-violation    
42596FILE-EXECUTABLE XOR 0x67 encrypted portable executable file download attempt (more info ...)policy-violation    
42597FILE-EXECUTABLE XOR 0x68 encrypted portable executable file download attempt (more info ...)policy-violation    
42598FILE-EXECUTABLE XOR 0x69 encrypted portable executable file download attempt (more info ...)policy-violation    
42599FILE-EXECUTABLE XOR 0x6a encrypted portable executable file download attempt (more info ...)policy-violation    
42600FILE-EXECUTABLE XOR 0x6b encrypted portable executable file download attempt (more info ...)policy-violation    
42601FILE-EXECUTABLE XOR 0x6c encrypted portable executable file download attempt (more info ...)policy-violation    
42602FILE-EXECUTABLE XOR 0x6d encrypted portable executable file download attempt (more info ...)policy-violation    
42603FILE-EXECUTABLE XOR 0x6e encrypted portable executable file download attempt (more info ...)policy-violation    
42604FILE-EXECUTABLE XOR 0x6f encrypted portable executable file download attempt (more info ...)policy-violation    
42605FILE-EXECUTABLE XOR 0x70 encrypted portable executable file download attempt (more info ...)policy-violation    
42606FILE-EXECUTABLE XOR 0x71 encrypted portable executable file download attempt (more info ...)policy-violation    
42607FILE-EXECUTABLE XOR 0x72 encrypted portable executable file download attempt (more info ...)policy-violation    
42608FILE-EXECUTABLE XOR 0x73 encrypted portable executable file download attempt (more info ...)policy-violation    
42609FILE-EXECUTABLE XOR 0x74 encrypted portable executable file download attempt (more info ...)policy-violation    
42610FILE-EXECUTABLE XOR 0x75 encrypted portable executable file download attempt (more info ...)policy-violation    
42611FILE-EXECUTABLE XOR 0x76 encrypted portable executable file download attempt (more info ...)policy-violation    
42612FILE-EXECUTABLE XOR 0x77 encrypted portable executable file download attempt (more info ...)policy-violation    
42613FILE-EXECUTABLE XOR 0x78 encrypted portable executable file download attempt (more info ...)policy-violation    
42614FILE-EXECUTABLE XOR 0x79 encrypted portable executable file download attempt (more info ...)policy-violation    
42615FILE-EXECUTABLE XOR 0x7a encrypted portable executable file download attempt (more info ...)policy-violation    
42616FILE-EXECUTABLE XOR 0x7b encrypted portable executable file download attempt (more info ...)policy-violation    
42617FILE-EXECUTABLE XOR 0x7c encrypted portable executable file download attempt (more info ...)policy-violation    
42618FILE-EXECUTABLE XOR 0x7d encrypted portable executable file download attempt (more info ...)policy-violation    
42619FILE-EXECUTABLE XOR 0x7e encrypted portable executable file download attempt (more info ...)policy-violation    
42620FILE-EXECUTABLE XOR 0x7f encrypted portable executable file download attempt (more info ...)policy-violation    
42621FILE-EXECUTABLE XOR 0x80 encrypted portable executable file download attempt (more info ...)policy-violation    
42622FILE-EXECUTABLE XOR 0x81 encrypted portable executable file download attempt (more info ...)policy-violation    
42623FILE-EXECUTABLE XOR 0x82 encrypted portable executable file download attempt (more info ...)policy-violation    
42624FILE-EXECUTABLE XOR 0x83 encrypted portable executable file download attempt (more info ...)policy-violation    
42625FILE-EXECUTABLE XOR 0x84 encrypted portable executable file download attempt (more info ...)policy-violation    
42626FILE-EXECUTABLE XOR 0x85 encrypted portable executable file download attempt (more info ...)policy-violation    
42627FILE-EXECUTABLE XOR 0x86 encrypted portable executable file download attempt (more info ...)policy-violation    
42628FILE-EXECUTABLE XOR 0x87 encrypted portable executable file download attempt (more info ...)policy-violation    
42629FILE-EXECUTABLE XOR 0x88 encrypted portable executable file download attempt (more info ...)policy-violation    
42630FILE-EXECUTABLE XOR 0x89 encrypted portable executable file download attempt (more info ...)policy-violation    
42631FILE-EXECUTABLE XOR 0x8a encrypted portable executable file download attempt (more info ...)policy-violation    
42632FILE-EXECUTABLE XOR 0x8b encrypted portable executable file download attempt (more info ...)policy-violation    
42633FILE-EXECUTABLE XOR 0x8c encrypted portable executable file download attempt (more info ...)policy-violation    
42634FILE-EXECUTABLE XOR 0x8d encrypted portable executable file download attempt (more info ...)policy-violation    
42635FILE-EXECUTABLE XOR 0x8e encrypted portable executable file download attempt (more info ...)policy-violation    
42636FILE-EXECUTABLE XOR 0x8f encrypted portable executable file download attempt (more info ...)policy-violation    
42637FILE-EXECUTABLE XOR 0x90 encrypted portable executable file download attempt (more info ...)policy-violation    
42638FILE-EXECUTABLE XOR 0x91 encrypted portable executable file download attempt (more info ...)policy-violation    
42639FILE-EXECUTABLE XOR 0x92 encrypted portable executable file download attempt (more info ...)policy-violation    
42640FILE-EXECUTABLE XOR 0x93 encrypted portable executable file download attempt (more info ...)policy-violation    
42641FILE-EXECUTABLE XOR 0x94 encrypted portable executable file download attempt (more info ...)policy-violation    
42642FILE-EXECUTABLE XOR 0x95 encrypted portable executable file download attempt (more info ...)policy-violation    
42643FILE-EXECUTABLE XOR 0x96 encrypted portable executable file download attempt (more info ...)policy-violation    
42644FILE-EXECUTABLE XOR 0x97 encrypted portable executable file download attempt (more info ...)policy-violation    
42645FILE-EXECUTABLE XOR 0x98 encrypted portable executable file download attempt (more info ...)policy-violation    
42646FILE-EXECUTABLE XOR 0x99 encrypted portable executable file download attempt (more info ...)policy-violation    
42647FILE-EXECUTABLE XOR 0x9a encrypted portable executable file download attempt (more info ...)policy-violation    
42648FILE-EXECUTABLE XOR 0x9b encrypted portable executable file download attempt (more info ...)policy-violation    
42649FILE-EXECUTABLE XOR 0x9c encrypted portable executable file download attempt (more info ...)policy-violation    
42650FILE-EXECUTABLE XOR 0x9d encrypted portable executable file download attempt (more info ...)policy-violation    
42651FILE-EXECUTABLE XOR 0x9e encrypted portable executable file download attempt (more info ...)policy-violation    
42652FILE-EXECUTABLE XOR 0x9f encrypted portable executable file download attempt (more info ...)policy-violation    
42653FILE-EXECUTABLE XOR 0xa0 encrypted portable executable file download attempt (more info ...)policy-violation    
42654FILE-EXECUTABLE XOR 0xa1 encrypted portable executable file download attempt (more info ...)policy-violation    
42655FILE-EXECUTABLE XOR 0xa2 encrypted portable executable file download attempt (more info ...)policy-violation    
42656FILE-EXECUTABLE XOR 0xa3 encrypted portable executable file download attempt (more info ...)policy-violation    
42657FILE-EXECUTABLE XOR 0xa4 encrypted portable executable file download attempt (more info ...)policy-violation    
42658FILE-EXECUTABLE XOR 0xa5 encrypted portable executable file download attempt (more info ...)policy-violation    
42659FILE-EXECUTABLE XOR 0xa6 encrypted portable executable file download attempt (more info ...)policy-violation    
42660FILE-EXECUTABLE XOR 0xa7 encrypted portable executable file download attempt (more info ...)policy-violation    
42661FILE-EXECUTABLE XOR 0xa8 encrypted portable executable file download attempt (more info ...)policy-violation    
42662FILE-EXECUTABLE XOR 0xa9 encrypted portable executable file download attempt (more info ...)policy-violation    
42663FILE-EXECUTABLE XOR 0xaa encrypted portable executable file download attempt (more info ...)policy-violation    
42664FILE-EXECUTABLE XOR 0xab encrypted portable executable file download attempt (more info ...)policy-violation    
42665FILE-EXECUTABLE XOR 0xac encrypted portable executable file download attempt (more info ...)policy-violation    
42666FILE-EXECUTABLE XOR 0xad encrypted portable executable file download attempt (more info ...)policy-violation    
42667FILE-EXECUTABLE XOR 0xae encrypted portable executable file download attempt (more info ...)policy-violation    
42668FILE-EXECUTABLE XOR 0xaf encrypted portable executable file download attempt (more info ...)policy-violation    
42669FILE-EXECUTABLE XOR 0xb0 encrypted portable executable file download attempt (more info ...)policy-violation    
42670FILE-EXECUTABLE XOR 0xb1 encrypted portable executable file download attempt (more info ...)policy-violation    
42671FILE-EXECUTABLE XOR 0xb2 encrypted portable executable file download attempt (more info ...)policy-violation    
42672FILE-EXECUTABLE XOR 0xb3 encrypted portable executable file download attempt (more info ...)policy-violation    
42673FILE-EXECUTABLE XOR 0xb4 encrypted portable executable file download attempt (more info ...)policy-violation    
42674FILE-EXECUTABLE XOR 0xb5 encrypted portable executable file download attempt (more info ...)policy-violation    
42675FILE-EXECUTABLE XOR 0xb6 encrypted portable executable file download attempt (more info ...)policy-violation    
42676FILE-EXECUTABLE XOR 0xb7 encrypted portable executable file download attempt (more info ...)policy-violation    
42677FILE-EXECUTABLE XOR 0xb8 encrypted portable executable file download attempt (more info ...)policy-violation    
42678FILE-EXECUTABLE XOR 0xb9 encrypted portable executable file download attempt (more info ...)policy-violation    
42679FILE-EXECUTABLE XOR 0xba encrypted portable executable file download attempt (more info ...)policy-violation    
42680FILE-EXECUTABLE XOR 0xbb encrypted portable executable file download attempt (more info ...)policy-violation    
42681FILE-EXECUTABLE XOR 0xbc encrypted portable executable file download attempt (more info ...)policy-violation    
42682FILE-EXECUTABLE XOR 0xbd encrypted portable executable file download attempt (more info ...)policy-violation    
42683FILE-EXECUTABLE XOR 0xbe encrypted portable executable file download attempt (more info ...)policy-violation    
42684FILE-EXECUTABLE XOR 0xbf encrypted portable executable file download attempt (more info ...)policy-violation    
42685FILE-EXECUTABLE XOR 0xc0 encrypted portable executable file download attempt (more info ...)policy-violation    
42686FILE-EXECUTABLE XOR 0xc1 encrypted portable executable file download attempt (more info ...)policy-violation    
42687FILE-EXECUTABLE XOR 0xc2 encrypted portable executable file download attempt (more info ...)policy-violation    
42688FILE-EXECUTABLE XOR 0xc3 encrypted portable executable file download attempt (more info ...)policy-violation    
42689FILE-EXECUTABLE XOR 0xc4 encrypted portable executable file download attempt (more info ...)policy-violation    
42690FILE-EXECUTABLE XOR 0xc5 encrypted portable executable file download attempt (more info ...)policy-violation    
42691FILE-EXECUTABLE XOR 0xc6 encrypted portable executable file download attempt (more info ...)policy-violation    
42692FILE-EXECUTABLE XOR 0xc7 encrypted portable executable file download attempt (more info ...)policy-violation    
42693FILE-EXECUTABLE XOR 0xc8 encrypted portable executable file download attempt (more info ...)policy-violation    
42694FILE-EXECUTABLE XOR 0xc9 encrypted portable executable file download attempt (more info ...)policy-violation    
42695FILE-EXECUTABLE XOR 0xca encrypted portable executable file download attempt (more info ...)policy-violation    
42696FILE-EXECUTABLE XOR 0xcb encrypted portable executable file download attempt (more info ...)policy-violation    
42697FILE-EXECUTABLE XOR 0xcc encrypted portable executable file download attempt (more info ...)policy-violation    
42698FILE-EXECUTABLE XOR 0xcd encrypted portable executable file download attempt (more info ...)policy-violation    
42699FILE-EXECUTABLE XOR 0xce encrypted portable executable file download attempt (more info ...)policy-violation    
42700FILE-EXECUTABLE XOR 0xcf encrypted portable executable file download attempt (more info ...)policy-violation    
42701FILE-EXECUTABLE XOR 0xd0 encrypted portable executable file download attempt (more info ...)policy-violation    
42702FILE-EXECUTABLE XOR 0xd1 encrypted portable executable file download attempt (more info ...)policy-violation    
42703FILE-EXECUTABLE XOR 0xd2 encrypted portable executable file download attempt (more info ...)policy-violation    
42704FILE-EXECUTABLE XOR 0xd3 encrypted portable executable file download attempt (more info ...)policy-violation    
42705FILE-EXECUTABLE XOR 0xd4 encrypted portable executable file download attempt (more info ...)policy-violation    
42706FILE-EXECUTABLE XOR 0xd5 encrypted portable executable file download attempt (more info ...)policy-violation    
42707FILE-EXECUTABLE XOR 0xd6 encrypted portable executable file download attempt (more info ...)policy-violation    
42708FILE-EXECUTABLE XOR 0xd7 encrypted portable executable file download attempt (more info ...)policy-violation    
42709FILE-EXECUTABLE XOR 0xd8 encrypted portable executable file download attempt (more info ...)policy-violation    
42710FILE-EXECUTABLE XOR 0xd9 encrypted portable executable file download attempt (more info ...)policy-violation    
42711FILE-EXECUTABLE XOR 0xda encrypted portable executable file download attempt (more info ...)policy-violation    
42712FILE-EXECUTABLE XOR 0xdb encrypted portable executable file download attempt (more info ...)policy-violation    
42713FILE-EXECUTABLE XOR 0xdc encrypted portable executable file download attempt (more info ...)policy-violation    
42714FILE-EXECUTABLE XOR 0xdd encrypted portable executable file download attempt (more info ...)policy-violation    
42715FILE-EXECUTABLE XOR 0xde encrypted portable executable file download attempt (more info ...)policy-violation    
42716FILE-EXECUTABLE XOR 0xdf encrypted portable executable file download attempt (more info ...)policy-violation    
42717FILE-EXECUTABLE XOR 0xe0 encrypted portable executable file download attempt (more info ...)policy-violation    
42718FILE-EXECUTABLE XOR 0xe1 encrypted portable executable file download attempt (more info ...)policy-violation    
42719FILE-EXECUTABLE XOR 0xe2 encrypted portable executable file download attempt (more info ...)policy-violation    
42720FILE-EXECUTABLE XOR 0xe3 encrypted portable executable file download attempt (more info ...)policy-violation    
42721FILE-EXECUTABLE XOR 0xe4 encrypted portable executable file download attempt (more info ...)policy-violation    
42722FILE-EXECUTABLE XOR 0xe5 encrypted portable executable file download attempt (more info ...)policy-violation    
42723FILE-EXECUTABLE XOR 0xe6 encrypted portable executable file download attempt (more info ...)policy-violation    
42724FILE-EXECUTABLE XOR 0xe7 encrypted portable executable file download attempt (more info ...)policy-violation    
42725FILE-EXECUTABLE XOR 0xe8 encrypted portable executable file download attempt (more info ...)policy-violation    
42726FILE-EXECUTABLE XOR 0xe9 encrypted portable executable file download attempt (more info ...)policy-violation    
42727FILE-EXECUTABLE XOR 0xea encrypted portable executable file download attempt (more info ...)policy-violation    
42728FILE-EXECUTABLE XOR 0xeb encrypted portable executable file download attempt (more info ...)policy-violation    
42729FILE-EXECUTABLE XOR 0xec encrypted portable executable file download attempt (more info ...)policy-violation    
42730FILE-EXECUTABLE XOR 0xed encrypted portable executable file download attempt (more info ...)policy-violation    
42731FILE-EXECUTABLE XOR 0xee encrypted portable executable file download attempt (more info ...)policy-violation    
42732FILE-EXECUTABLE XOR 0xef encrypted portable executable file download attempt (more info ...)policy-violation    
42733FILE-EXECUTABLE XOR 0xf0 encrypted portable executable file download attempt (more info ...)policy-violation    
42734FILE-EXECUTABLE XOR 0xf1 encrypted portable executable file download attempt (more info ...)policy-violation    
42735FILE-EXECUTABLE XOR 0xf2 encrypted portable executable file download attempt (more info ...)policy-violation    
42736FILE-EXECUTABLE XOR 0xf3 encrypted portable executable file download attempt (more info ...)policy-violation    
42737FILE-EXECUTABLE XOR 0xf4 encrypted portable executable file download attempt (more info ...)policy-violation    
42738FILE-EXECUTABLE XOR 0xf5 encrypted portable executable file download attempt (more info ...)policy-violation    
42739FILE-EXECUTABLE XOR 0xf6 encrypted portable executable file download attempt (more info ...)policy-violation    
42740FILE-EXECUTABLE XOR 0xf7 encrypted portable executable file download attempt (more info ...)policy-violation    
42741FILE-EXECUTABLE XOR 0xf8 encrypted portable executable file download attempt (more info ...)policy-violation    
42742FILE-EXECUTABLE XOR 0xf9 encrypted portable executable file download attempt (more info ...)policy-violation    
42743FILE-EXECUTABLE XOR 0xfa encrypted portable executable file download attempt (more info ...)policy-violation    
42744FILE-EXECUTABLE XOR 0xfb encrypted portable executable file download attempt (more info ...)policy-violation    
42745FILE-EXECUTABLE XOR 0xfc encrypted portable executable file download attempt (more info ...)policy-violation    
42746FILE-EXECUTABLE XOR 0xfd encrypted portable executable file download attempt (more info ...)policy-violation    
42747FILE-EXECUTABLE XOR 0xfe encrypted portable executable file download attempt (more info ...)policy-violation    
42748FILE-EXECUTABLE XOR 0xff encrypted portable executable file download attempt (more info ...)policy-violation    
42786PROTOCOL-SCADA Moxa unlock function code attempt (more info ...)attempted-admin    URL
42804SERVER-WEBAPP IntegraXor directory traversal attempt (more info ...)web-application-attack 2010-4598   
42830MALWARE-CNC User-Agent known malicious user-agent string - Sublink (more info ...)trojan-activity    URL
42831MALWARE-CNC User-Agent known malicious user agent - micro (more info ...)trojan-activity    URL
42832MALWARE-CNC User-Agent known malicious user agent - SessionI (more info ...)trojan-activity    URL
42833MALWARE-CNC Kasperagent outbound connection detected (more info ...)trojan-activity    URL
42834MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
42835MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
42836MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
42837MALWARE-CNC Win.Backdoor.Chopper web shell connection (more info ...)trojan-activity    URL
42838MALWARE-CNC User-Agent known malicious user-agent string - Win.Backdoor.Chopper (more info ...)trojan-activity    URL
42857SERVER-WEBAPP MVPower DVR Shell arbitrary command execution attempt (more info ...)attempted-admin    URL
42866SERVER-WEBAPP GE Proficy RT Portal information disclosure attempt (more info ...)attempted-recon 2013-0651   
42867SERVER-WEBAPP GE Proficy RT Portal information disclosure attempt (more info ...)attempted-recon 2013-0651   
42880MALWARE-CNC Deputy Dog implant outbound connection (more info ...)trojan-activity    
42881MALWARE-CNC Deputy Dog implant outbound connection (more info ...)trojan-activity    
42882MALWARE-CNC ZoxPNG initial outbound connection (more info ...)trojan-activity    
42883MALWARE-CNC Win.Trojan.MadMax implant outbound connection attempt (more info ...)trojan-activity    
42884MALWARE-CNC Win.Trojan.MadMax implant outbound connection (more info ...)trojan-activity    
42885MALWARE-CNC WashingTon ssl certificate negotiation attempt (more info ...)trojan-activity    
42886MALWARE-CNC HttpBrowser User-Agent outbound communication attmept (more info ...)trojan-activity    
42893SERVER-WEBAPP Eaton VURemote denial of service attempt (more info ...)denial-of-service    URL
42894MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
42895MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
42898SERVER-WEBAPP Eaton Network Shutdown Module remote code execution attempt (more info ...)attempted-user  54161  
42899MALWARE-CNC Jaff ransomware outbound connection (more info ...)trojan-activity    
42919FILE-IDENTIFY ISO file attachment with executable detected (more info ...)misc-activity    
42925MALWARE-CNC Js.Keylogger.Scanbox outbound connection (more info ...)trojan-activity    URL
42926MALWARE-CNC Js.Keylogger.Scanbox outbound connection (more info ...)trojan-activity    URL
42929MALWARE-CNC Win.Trojan.Niramdat variant initial outbound connection (more info ...)trojan-activity    URL
42934PROTOCOL-SCADA GE Proficy Historian buffer overflow attempt (more info ...)attempted-admin 2011-1918   
42935FILE-OTHER Everest Software PeakHMI malicious .bsu file buffer overflow attempt (more info ...)misc-activity    URL
42936FILE-OTHER Everest Software PeakHMI malicious .bsu file buffer overflow attempt (more info ...)misc-activity    URL
42945MALWARE-CNC Win.Trojan.Adylkuzz variant initial outbound connection (more info ...)trojan-activity    URL
42946INDICATOR-OBFUSCATION Hex escaped valueOf function name obfuscation attempt (more info ...)misc-activity    URL
42948INDICATOR-OBFUSCATION Hex escaped split function name obfuscation attempt (more info ...)misc-activity    URL
42949INDICATOR-OBFUSCATION URL encoded document class name obfuscation attempt (more info ...)misc-activity    URL
42950INDICATOR-OBFUSCATION URL encoded vbscript tag obfuscation attempt (more info ...)misc-activity    URL
42993SERVER-WEBAPP ReadyDesk arbitrary file upload attempt (more info ...)web-application-attack 2016-5050   
42994SERVER-WEBAPP ReadyDesk arbitrary file upload attempt (more info ...)web-application-attack 2016-5050   
42995PROTOCOL-SCADA Weintek EB Pro denial of service attempt (more info ...)attempted-dos    URL
42996MALWARE-CNC Win.Trojan.Spesseo variant outbound connection (more info ...)trojan-activity    URL
42997MALWARE-CNC Win.Trojan.Spesseo variant outbound connection (more info ...)trojan-activity    URL
43000FILE-OTHER TRUFFLEHUNTER TALOS-2017-0342 attack attempt (more info ...)attempted-user 2017-2840   URL
43001FILE-OTHER TRUFFLEHUNTER TALOS-2017-0342 attack attempt (more info ...)attempted-user 2017-2840   URL
43006SERVER-WEBAPP MailStore Server cross site scripting attempt (more info ...)attempted-user    URL
43044SERVER-OTHER RaySharp DVR administrative interface access attempt (more info ...)attempted-admin    URL
43049MALWARE-CNC Win.Trojan.Gasonen variant outbound connection (more info ...)trojan-activity    URL
43050SERVER-WEBAPP Schneider Electric ClearSCADA information disclosure attempt (more info ...)attempted-recon    URL
43062SERVER-WEBAPP Cogent Datahub EvalExpresssion remote code execution attempt (more info ...)attempted-admin    URL
43063MALWARE-CNC Win.Trojan.Kabob outbound connection (more info ...)trojan-activity    
43076SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0354 attack attempt (more info ...)attempted-dos 2017-2852   URL
43080BROWSER-OTHER Foscam IP Camera User-Agent string detected (more info ...)misc-activity    
43081BROWSER-OTHER TRUFFLEHUNTER TALOS-2017-0357 attack attempt (more info ...)attempted-admin 2017-2856   URL
43082BROWSER-OTHER TRUFFLEHUNTER TALOS-2017-0360 attack attempt (more info ...)attempted-admin 2017-2857   URL
43084FILE-IDENTIFY Rhinoceros 3D 3dm file attachment detected (more info ...)misc-activity    
43085FILE-IDENTIFY Rhinoceros 3D 3dm file attachment detected (more info ...)misc-activity    
43086FILE-IDENTIFY Rhinoceros 3D 3dm file attachment detected (more info ...)misc-activity    
43087FILE-IDENTIFY FLIC animation file download request (more info ...)misc-activity    
43088FILE-IDENTIFY FLIC animation file attachment detected (more info ...)misc-activity    
43089FILE-IDENTIFY FLIC animation file attachment detected (more info ...)misc-activity    
43090FILE-IDENTIFY FLIC animation file attachment detected (more info ...)misc-activity    
43091SERVER-WEBAPP AggreGate SCADA HMI web form upload xml external entity attack attempt (more info ...)web-application-attack    URL
43092INDICATOR-COMPROMISE OLE attachment with embedded PICT attempt (more info ...)misc-activity 2017-8487   
43094SERVER-OTHER Ecava IntegraXor SCADA information leak attempt (more info ...)attempted-admin    URL
43099SERVER-WEBAPP Simple SCADA web-socket connection initialization attempt (more info ...)misc-activity    URL
43100SERVER-WEBAPP Simple SCADA web-socket remote command execution attempt (more info ...)misc-activity    URL
43101SERVER-WEBAPP Beckhoff CX9020 remote configuration modification attempt (more info ...)web-application-attack 2015-4051   URL
43102SERVER-WEBAPP Mango Automation arbitrary JSP code upload attempt (more info ...)attempted-admin 2015-7904   
43103PROTOCOL-SCADA Weintek EasyBuilder Pro denial of service attempt (more info ...)attempted-dos    URL
43104PROTOCOL-SCADA OPC Systems denial of service attempt (more info ...)attempted-dos    URL
43105SERVER-OTHER Novus WS10 Data Server buffer overflow attempt (more info ...)attempted-admin    URL
43107FILE-OTHER FreeBSD bspatch utility remote code execution attempt (more info ...)attempted-user 2014-9862   
43108FILE-OTHER FreeBSD bspatch utility remote code execution attempt (more info ...)attempted-user 2014-9862   
43112SERVER-WEBAPP Schneider Electric IGSS dashboard overwrite attempt (more info ...)web-application-attack    URL
43113SERVER-WEBAPP Schneider Electric IGSS dashboard deletion attempt (more info ...)web-application-attack    URL
43116SERVER-OTHER Moore Industries NCS denial of service attempt (more info ...)attempted-dos    URL
43119SERVER-WEBAPP CyberPower Systems PowerPanel XXE out of band data retrieval attempt (more info ...)web-application-attack    URL
43127POLICY-OTHER Beck IPC network configuration enumeration attempt (more info ...)attempted-recon    URL
43128POLICY-OTHER Beck IPC network configuration overwrite attempt (more info ...)misc-activity    URL
43129MALWARE-CNC Win.Trojan.Fareit variant outbound connection (more info ...)trojan-activity    URL
43135POLICY-OTHER JBoss Management console access detected (more info ...)policy-violation 2017-6640   URL
43137FILE-OTHER INSAT MasterSCADA malicious project command execution attempt (more info ...)misc-activity    URL
43138FILE-OTHER INSAT MasterSCADA malicious project command execution attempt (more info ...)misc-activity    URL
43139PROTOCOL-SCADA Pro-Face Pro-ServerEX large data allocation denial of service attempt (more info ...)denial-of-service 2012-3794   
43140PROTOCOL-SCADA Pro-Face Pro-ServerEX large size value denial of service attempt (more info ...)denial-of-service 2012-3796   
43141PROTOCOL-SCADA Pro-Face Pro-ServerEX large data allocation denial of service attempt (more info ...)denial-of-service 2012-3794   
43142PROTOCOL-SCADA Pro-Face Pro-ServerEX large size value denial of service attempt (more info ...)denial-of-service 2012-3796   
43143PROTOCOL-SCADA Pro-Face Pro-ServerEX arbitrary memory disclosure attempt (more info ...)denial-of-service 2012-3795   
43144PROTOCOL-SCADA Pro-Face Pro-ServerEX arbitrary memory disclosure attempt (more info ...)denial-of-service 2012-3795   
43145POLICY-OTHER Pro-Face Pro-ServerEX find node invalid memory access attempt (more info ...)misc-activity 2012-3792   
43146POLICY-OTHER Pro-Face Pro-ServerEX find node invalid memory access attempt (more info ...)misc-activity 2012-3792   
43177PROTOCOL-SCADA Siemens SIPROTEC V4.24 crafted packet denial of service attempt (more info ...)attempted-dos 2015-5374   URL
43183MALWARE-CNC Win.Trojan.Matsnu variant outbound conection (more info ...)trojan-activity    URL
43184MALWARE-CNC Win.Trojan.Matsnu variant outbound conection (more info ...)trojan-activity    URL
43187EXPLOIT-KIT Rig Exploit Kit URL outbound communication (more info ...)attempted-user    
43190MALWARE-CNC Win.Trojan.Konus variant outbound connection detected (more info ...)trojan-activity    URL
43193MALWARE-CNC Win.Trojan.HiddenCobra variant outbound connection (more info ...)trojan-activity    URL
43194MALWARE-CNC Win.Trojan.HiddenCobra variant outbound connection (more info ...)trojan-activity    URL
43214FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0366 attack attempt (more info ...)attempted-user 2017-2862   URL
43215FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0366 attack attempt (more info ...)attempted-user 2017-2862   URL
43217EXPLOIT-KIT Rig Exploit Kit redirection attempt (more info ...)trojan-activity    
43218PUA-ADWARE Win.Adware.Hotbar variant outbound connection (more info ...)misc-activity    URL
43219PUA-ADWARE Win.Adware.Hotbar variant outbound connection (more info ...)misc-activity    URL
43220MALWARE-CNC User-Agent known malicious user-agent string - Hotbar (more info ...)trojan-activity    URL
43222MALWARE-CNC Win.Trojan.Micropsia outbound connection (more info ...)trojan-activity    URL
43223MALWARE-CNC Win.Trojan.Micropsia outbound connection (more info ...)trojan-activity    URL
43224MALWARE-CNC Win.Trojan.Micropsia outbound connection (more info ...)trojan-activity    URL
43227PROTOCOL-SCADA IEC 104 force off denial of service attempt (more info ...)attempted-dos    URL
43238SERVER-WEBAPP Imatix Xitami web server head processing denial of service attempt (more info ...)attempted-dos    URL
43252PROTOCOL-SCADA IEC 61850 device connection enumeration attempt (more info ...)attempted-recon    URL
43253PROTOCOL-SCADA IEC 61850 virtual manufacturing device domain variable enumeration attempt (more info ...)attempted-recon    URL
43254INDICATOR-SHELLCODE KUSER_SHARED_DATA NtMajorVersion and NtMinorVersion offsets (more info ...)shellcode-detect    
43280SERVER-WEBAPP Advantech WebAccess cross site scripting attempt (more info ...)attempted-user 2012-0233   
43281SERVER-WEBAPP .NET AjaxControlToolkit directory traversal remote code execution attempt (more info ...)attempted-user 2015-4670   
43282SERVER-WEBAPP .NET AjaxControlToolkit directory traversal remote code execution attempt (more info ...)attempted-user 2015-4670   
43283SERVER-WEBAPP .NET AjaxControlToolkit directory traversal remote code execution attempt (more info ...)attempted-user 2015-4670   
43285SERVER-WEBAPP /.svn/entries file access attempt (more info ...)attempted-recon    
43287SERVER-WEBAPP /etc/inetd.conf file access attempt (more info ...)attempted-recon    URL
43288SERVER-WEBAPP /etc/motd file access attempt (more info ...)attempted-recon    URL
43289SERVER-WEBAPP /etc/shadow file access attempt (more info ...)attempted-recon    URL
43292MALWARE-CNC Andr.Adware.Judy malicious dex file download attempt (more info ...)trojan-activity    URL
43296SERVER-WEBAPP IP3 Networks NetAccess directory traversal attempt (more info ...)web-application-attack 2007-0883   
43299SERVER-WEBAPP Belkin N150 abitrary file read attempt (more info ...)web-application-attack 2014-2962   
43304SERVER-WEBAPP csChatRBox setup attempt (more info ...)web-application-activity 2002-1752 4452  
43305SERVER-WEBAPP csLiveSupport setup attempt (more info ...)web-application-activity 2002-1751 4450  
43306SERVER-WEBAPP csNewsRemote setup attempt (more info ...)web-application-activity 2002-1753 4451  
43324SERVER-WEBAPP Trihedral VTScada directory traversal attempt (more info ...)web-application-attack 2016-4532 91077  URL
43325SERVER-WEBAPP Trihedral VTScada directory traversal attempt (more info ...)web-application-attack 2016-4532 91077  URL
43326SERVER-WEBAPP Trihedral VTScada directory traversal attempt (more info ...)web-application-attack 2016-4532 91077  URL
43332EXPLOIT-KIT Rig Exploit Kit Landing Page Request Attempt (more info ...)attempted-user    
43333FILE-OTHER ProShow Gold PSH file handling overflow attempt (more info ...)attempted-user 2009-3214   
43334SERVER-WEBAPP OpenFiler NetworkCard command execution attempt (more info ...)attempted-admin  55490  
43339FILE-OTHER Cytel Studio string stack overflow attempt (more info ...)attempted-user  49924  URL
43340FILE-OTHER Cytel Studio row overflow attempt (more info ...)attempted-user  49924  URL
43341FILE-OTHER Cytel Studio USE command overflow attempt (more info ...)attempted-user  49924  URL
43348PROTOCOL-SCADA Advantech Studio DOS attempt (more info ...)attempted-dos    URL
43352SERVER-WEBAPP Oracle Application Server 9i unauthenticated dms access attempt (more info ...)attempted-recon 2002-0563   
43353SERVER-WEBAPP Oracle Application Server 9i unauthenticated dms access attempt (more info ...)attempted-recon 2002-0563   
43354SERVER-WEBAPP Oracle Application Server 9i unauthenticated dms access attempt (more info ...)attempted-recon 2002-0563   
43355SERVER-WEBAPP Oracle Application Server 9i unauthenticated dms access attempt (more info ...)attempted-recon 2002-0563   
43356SERVER-WEBAPP Oracle Application Server 9i unauthenticated dms access attempt (more info ...)attempted-recon 2002-0563   
43357SERVER-WEBAPP Oracle Application Server 9i unauthenticated dms access attempt (more info ...)attempted-recon 2002-0563   
43368FILE-OTHER Compface xbm long declaration buffer overflow attempt (more info ...)denial-of-service 2009-2286   
43369FILE-OTHER Compface xbm long declaration buffer overflow attempt (more info ...)denial-of-service 2009-2286   
43379SERVER-WEBAPP CA ERwin Web Portal ProfileIconServlet directory traversal attempt (more info ...)web-application-attack 2014-2210   
43388OS-OTHER Apple OSX CFNetwork HTTP response denial of service attempt (more info ...)denial-of-service 2007-0464   
43389INDICATOR-COMPROMISE Symantec Endpoint Protection potential binary planting RCE attempt (more info ...)attempted-user 2015-1492   URL
43390SERVER-WEBAPP Netgear Prosafe startup config information disclosure attempt (more info ...)attempted-recon 2013-4775   
43397SERVER-OTHER Proface GP-Pro EX EX-ED BeginPreRead stack buffer overflow attempt (more info ...)attempted-user 2016-2292   
43399FILE-IMAGE multiple products PNG processing buffer overflow attempt (more info ...)attempted-user 2017-3077 34240  URL
43436SERVER-WEBAPP GE Fanuc Real Time Information Portal arbitrary file write attempt (more info ...)web-application-attack 2008-0175 27446  URL
43444SERVER-WEBAPP XML entity parsing information disclosure attempt (more info ...)attempted-recon 2014-0054   
43449POLICY-OTHER log file access detected (more info ...)attempted-recon 2017-6709   URL
43457MALWARE-CNC Win.Trojan.Eorezo variant outbound connection (more info ...)trojan-activity    URL
43459MALWARE-CNC Win.Trojan.Doublepulsar variant successful ping response (more info ...)trojan-activity    URL
43467MALWARE-CNC Win.Trojan.Fireball variant outbound connection (more info ...)trojan-activity    URL
43468MALWARE-CNC Win.Trojan.Fireball variant outbound connection (more info ...)trojan-activity    URL
43475MALWARE-CNC Win.Dropper.Agent ransomware downloader outbound connection detected (more info ...)trojan-activity    URL
43476MALWARE-CNC Win.Dropper.Agent ransomware downloader outbound connection detected (more info ...)trojan-activity    URL
43477MALWARE-CNC Win.Dropper.Agent ransomware downloader outbound connection detected (more info ...)trojan-activity    URL
43481FILE-OTHER Vim modelines remote command execution attempt (more info ...)attempted-user 2016-1248   
43482FILE-OTHER Vim modelines remote command execution attempt (more info ...)attempted-user 2016-1248   
43487SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0370 attack attempt (more info ...)attempted-user 2017-2864   URL
43495SERVER-WEBAPP Lets Encrypt SSL certificate for domain resembling paypal (more info ...)misc-attack    
43496SERVER-WEBAPP Lets Encrypt SSL certificate issuer detected (more info ...)misc-attack    
43523MALWARE-CNC Win.Trojan.Donvibs variant outbound connection (more info ...)trojan-activity    URL
43524MALWARE-CNC Win.Trojan.Donvibs variant outbound connection (more info ...)trojan-activity    URL
43526MALWARE-CNC Win.Trojan.Deltasource variant outbound connection detected (more info ...)trojan-activity    URL
43527MALWARE-CNC Win.Trojan.Deltasource variant outbound connection detected (more info ...)trojan-activity    URL
43539SERVER-WEBAPP Koha directory traversal attempt (more info ...)web-application-attack 2011-4715   
43540FILE-OTHER Multiple products media player wma file buffer overflow attempt (more info ...)attempted-user 2012-0904   URL
43541FILE-OTHER Multiple products media player wma file buffer overflow attempt (more info ...)attempted-user 2012-0904   URL
43542SERVER-OTHER CCProxy telnet ping buffer overflow attempt (more info ...)attempted-user 2004-2685   
43546INDICATOR-COMPROMISE Juniper vSRX Application Firewall IPv6 REJECT buffer overflow attempt (more info ...)attempted-admin    
43555POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0381 attack attempt (more info ...)attempted-recon 2017-2874   URL
43560FILE-OTHER Oracle Outside-In JPEG2000 QCD segment processing heap buffer overflow attempt (more info ...)attempted-admin 2012-1769 54500  
43562POLICY-OTHER Teleopti WFM database information request detected (more info ...)attempted-recon    URL
43563POLICY-OTHER Teleopti WFM administrative user credentials request detected (more info ...)attempted-recon    URL
43564POLICY-OTHER Teleopti WFM administrative user creation detected (more info ...)attempted-admin    URL
43565APP-DETECT HTTPTunnel proxy outbound connection detected (more info ...)policy-violation    URL
43566SERVER-OTHER LAN Messenger initiation request buffer overflow attempt (more info ...)denial-of-service 2012-3845   
43567SERVER-WEBAPP Oracle Application Framework diagnostic information disclosure attempt (more info ...)attempted-recon 2013-0397   
43568SERVER-WEBAPP Oracle Application Framework diagnostic information disclosure attempt (more info ...)attempted-recon 2013-0397   
43569SERVER-WEBAPP Zavio Cam command injection attempt (more info ...)web-application-attack 2013-2568   
43570SERVER-WEBAPP Zavio Cam command injection attempt (more info ...)web-application-attack 2013-2568   
43571SERVER-WEBAPP Zavio Cam command injection attempt (more info ...)web-application-attack 2013-2568   
43572SERVER-WEBAPP Zavio Cam command injection attempt (more info ...)web-application-attack 2013-2568   
43575MALWARE-CNC Win32.Trojan.NeutrinoPOS connection attempt (more info ...)trojan-activity    URL
43576INDICATOR-COMPROMISE possible Samsung DVR authentication bypass attempt (more info ...)attempted-admin 2013-3586   
43577SERVER-WEBAPP Oracle BPEL Process Manager directory traversal attempt (more info ...)attempted-user 2013-3828 63058  
43582FILE-OTHER multiple vulnerabilities malformed .wav file buffer overflow attempt (more info ...)attempted-user 2009-4962   
43591SERVER-WEBAPP IBM Tealeaf testconn_host command injection attempt (more info ...)web-application-attack 2013-6719 65984  
43592SERVER-WEBAPP IBM Tealeaf testconn_host command injection attempt (more info ...)web-application-attack 2013-6719 65984  
43593SERVER-WEBAPP IBM Tealeaf testconn_host command injection attempt (more info ...)web-application-attack 2013-6719 65984  
43594SERVER-WEBAPP IBM Tealeaf testconn_host command injection attempt (more info ...)web-application-attack 2013-6719 65984  
43595SERVER-WEBAPP Netgear Prosafe filesystem denial of service attempt (more info ...)denial-of-service 2013-4776   
43596SERVER-OTHER Oracle Demantra information disclosure attempt (more info ...)attempted-recon 2013-5877 64831  
43597MALWARE-CNC Win.Trojan.BlackEnergy outbound connection (more info ...)trojan-activity    URL
43600FILE-OTHER Wireshark ENTTEC DMX RLE buffer overflow attempt (more info ...)attempted-admin 2010-4538   
43601FILE-OTHER Wireshark ENTTEC DMX RLE buffer overflow attempt (more info ...)attempted-admin 2010-4538   
43602SERVER-OTHER Wireshark ENTTEC DMX RLE buffer overflow attempt (more info ...)attempted-admin 2010-4538   
43608FILE-OTHER Multiple Products SGI ZSIZE handling buffer overflow attempt (more info ...)attempted-user 2018-5040 19507  URL
43609FILE-OTHER Multiple Products SGI ZSIZE handling buffer overflow attempt (more info ...)attempted-user 2018-5040 19507  URL
43610SERVER-OTHER Piwigo LocalFiles editor cross-site request forgery attempt (more info ...)web-application-attack 2013-1468   
43611SERVER-OTHER Piwigo LocalFiles editor cross-site request forgery attempt (more info ...)web-application-attack 2013-1468   
43615FILE-OTHER Orbital Viewer .orb stack buffer overflow attempt (more info ...)attempted-user 2010-0688 38436  
43616SERVER-WEBAPP E-Mail Security Virtual Appliance command injection attempt (more info ...)web-application-attack    URL
43617SERVER-WEBAPP E-Mail Security Virtual Appliance command injection attempt (more info ...)web-application-attack    URL
43618SERVER-WEBAPP E-Mail Security Virtual Appliance command injection attempt (more info ...)web-application-attack    URL
43619SERVER-WEBAPP E-Mail Security Virtual Appliance command injection attempt (more info ...)web-application-attack    URL
43620SERVER-OTHER Real Networks Helix Server RTSP denial of service attempt (more info ...)denial-of-service 2004-0389   
43621SERVER-OTHER Real Networks Helix Server RTSP denial of service attempt (more info ...)denial-of-service 2004-0389   
43623FILE-OTHER IBM Informix Client SDK NFX file HostList processing stack buffer overflow attempt (more info ...)attempted-user 2009-3691 36588  
43624FILE-OTHER IBM Informix Client SDK NFX file InformixServerList processing stack buffer overflow attempt (more info ...)attempted-user 2009-3691 36588  
43626FILE-OTHER Schneider Electric MaxStream Configuration X-CTU code execution attempt (more info ...)attempted-user    URL
43627FILE-OTHER Schneider Electric MaxStream Configuration X-CTU code execution attempt (more info ...)attempted-user    URL
43632FILE-EXECUTABLE SandboxEscaper WER download attempt (more info ...)attempted-user    
43633FILE-EXECUTABLE SandboxEscaper WER download attempt (more info ...)attempted-user    
43634SERVER-WEBAPP Zenoss call home remote code execution attempt (more info ...)attempted-user 2014-6261   
43637SERVER-WEBAPP SAP Internet Transaction Server cross site scripting attempt (more info ...)attempted-user 2003-0749   
43660SERVER-ORACLE Oracle Reports Server information disclosure attempt (more info ...)attempted-recon 2012-3152   URL
43661SERVER-ORACLE Oracle Reports Servlet information disclosure attempt (more info ...)attempted-recon 2012-3153   URL
43662SERVER-ORACLE Oracle Reports Servlet information disclosure attempt (more info ...)attempted-recon 2012-3153   URL
43666SERVER-WEBAPP VirtualSystem VS-News-System remote file include attempt (more info ...)web-application-attack 2007-1017   
43667SERVER-WEBAPP VirtualSystem VS-News-System remote file include attempt (more info ...)web-application-attack 2007-1017   
43669FILE-OTHER Node.js JS-YAML js function tag code execution attempt (more info ...)attempted-user 2013-4660   
43670FILE-OTHER Node.js JS-YAML js function tag code execution attempt (more info ...)attempted-user 2013-4660   
43676FILE-PDF FreeType PostScript Type1 font parsing memory corruption attempt (more info ...)attempted-user 2011-0226   
43677FILE-PDF FreeType PostScript Type1 font parsing memory corruption attempt (more info ...)attempted-user 2011-0226   
43682FILE-OTHER Xion Media Player AIFF denial of service attempt (more info ...)denial-of-service    URL
43683FILE-OTHER Xion Media Player AIFF denial of service attempt (more info ...)denial-of-service    URL
43700SERVER-OTHER Monkey HTTPD null request denial of service attempt (more info ...)denial-of-service 2013-3724   
43705SERVER-OTHER HPE LoadRunner buffer overflow exploitation attempt (more info ...)attempted-user 2016-4359 90975  
43708INDICATOR-OBFUSCATION obfuscated vbscript detected (more info ...)misc-activity    URL
43712POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0389 attack attempt (more info ...)policy-violation 2017-2882   URL
43714POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0389 attack attempt (more info ...)policy-violation 2017-2881   URL
43715POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0390 attack attempt (more info ...)policy-violation 2017-2883   URL
43716POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0391 attack attempt (more info ...)attempted-user 2017-2884   URL
43717SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0386 attack attempt (more info ...)attempted-admin 2017-2879   URL
43720SERVER-WEBAPP SAP Internet Transaction Server directory traversal attempt (more info ...)web-application-attack 2003-0748 8516  
43721SERVER-WEBAPP SAP Internet Transaction Server directory traversal attempt (more info ...)web-application-attack 2003-0748 8516  
43722SERVER-WEBAPP SAP Internet Transaction Server directory traversal attempt (more info ...)web-application-attack 2003-0748 8516  
43725FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0387 attack attempt (more info ...)attempted-user 2017-2880   URL
43726FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0387 attack attempt (more info ...)attempted-user 2017-2880   URL
43728SERVER-OTHER XChat heap buffer overflow attempt (more info ...)attempted-admin 2011-5129   
43729EXPLOIT-KIT Rig/Grandsoft Exploit Kit IE exploit attempt (more info ...)attempted-admin    
43730SERVER-OTHER multiple vulnerabilities malformed mp3 buffer overflow attempt (more info ...)attempted-admin 2012-6044   
43750FILE-OTHER Sorensoft Media Player asz file buffer overflow attempt (more info ...)denial-of-service    URL
43751FILE-OTHER Sorensoft Media Player asz file buffer overflow attempt (more info ...)denial-of-service    URL
43755SERVER-OTHER FreeBSD Routing Information Protocol assertion failure attempt (more info ...)policy-violation 2015-5674   
43757SERVER-WEBAPP ScadaBR remote credential export attempt (more info ...)web-application-attack    URL
43769SERVER-OTHER D-Link DSL-2740B cross site request forgery attempt (more info ...)attempted-admin 2013-5730   
43770SERVER-OTHER D-Link DSL-2740B cross site request forgery attempt (more info ...)attempted-admin 2013-5730   
43771SERVER-OTHER D-Link DSL-2740B cross site request forgery attempt (more info ...)attempted-admin 2013-5730   
43772SERVER-OTHER D-Link DSL-2740B cross site request forgery attempt (more info ...)attempted-admin 2013-5730   
43773SERVER-OTHER D-Link DSL-2740B cross site request forgery attempt (more info ...)attempted-admin 2013-5730   
43774SERVER-OTHER D-Link DSL-2740B cross site request forgery attempt (more info ...)attempted-admin 2013-5730   
43780SERVER-WEBAPP D-Link DIR-645 router buffer overflow attempt (more info ...)attempted-admin 2013-7389   
43781SERVER-WEBAPP D-Link DIR-645 router cross site scripting attempt (more info ...)attempted-user 2013-7389   
43782SERVER-WEBAPP D-Link DIR-645 router cross site scripting attempt (more info ...)attempted-user 2013-7389   
43783SERVER-WEBAPP D-Link DIR-645 router cross site scripting attempt (more info ...)attempted-user 2013-7389   
43786SERVER-ORACLE Oracle Application Test Suite server authentication bypass attempt (more info ...)attempted-admin 2016-0492 81158  URL
43787SERVER-ORACLE Oracle Application Test Suite server authentication bypass attempt (more info ...)attempted-admin 2016-0492 81158  URL
43788SERVER-ORACLE Oracle Application Test Suite server authentication bypass attempt (more info ...)attempted-admin 2016-0492 81158  URL
43794FILE-OTHER Schneider Electric VAMSET CFG file heap buffer overflow attempt (more info ...)attempted-admin 2014-8390   
43795FILE-OTHER Schneider Electric VAMSET CFG file heap buffer overflow attempt (more info ...)attempted-admin 2014-8390   
43797FILE-OTHER Schneider Electric VAMSET CFG file heap buffer overflow attempt (more info ...)attempted-admin 2014-8390   
43798FILE-OTHER Schneider Electric VAMSET CFG file heap buffer overflow attempt (more info ...)attempted-admin 2014-8390   
43806MALWARE-BACKDOOR HVL Rat inbound command (more info ...)trojan-activity    URL
43825MALWARE-CNC Osx.Trojan.XAgent outbound connection (more info ...)trojan-activity    URL
43828FILE-OTHER Snackamp malformed AIFF buffer overflow attempt (more info ...)denial-of-service 2012-5917   
43829SERVER-OTHER IBM Tivoli Storage Manager FastBack mount service code execution attempt (more info ...)attempted-admin 2010-3058 42549  
43834FILE-OTHER Bmxplay malformed BMX buffer overflow attempt (more info ...)denial-of-service 2009-4759   
43839INDICATOR-COMPROMISE backwards executable download (more info ...)attempted-user    
43840FILE-OTHER Wireshark PROFINET DCP response format string exploit attempt (more info ...)attempted-admin 2009-1210   
43841FILE-OTHER Wireshark PROFINET DCP request format string exploit attempt (more info ...)attempted-admin 2009-1210   
43842FILE-OTHER Wireshark PROFINET DCP response format string exploit attempt (more info ...)attempted-admin 2009-1210   
43843FILE-OTHER Wireshark PROFINET DCP request format string exploit attempt (more info ...)attempted-admin 2009-1210   
43844FILE-OTHER Wireshark PROFINET DCP request format string exploit attempt (more info ...)attempted-admin 2009-1210   
43845FILE-OTHER Wireshark PROFINET DCP request format string exploit attempt (more info ...)attempted-admin 2009-1210   
43846SERVER-OTHER ISC BIND malformed control channel authentication message denial of service attempt (more info ...)attempted-dos 2016-1285   URL
43864POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0371 attack attempt (more info ...)policy-violation 2017-2865   URL
43885EXPLOIT-KIT Exploit Kit malicious redirection attempt (more info ...)attempted-user    
43890MALWARE-CNC Win.Malware.Emotet variant outbound connection (more info ...)trojan-activity    URL
43899MALWARE-CNC Win.Trojan.Biggluck variant inbound response (more info ...)trojan-activity    
43929MALWARE-CNC Win.Trojan.Poogetad Variant connection attempt (more info ...)trojan-activity    URL
43930MALWARE-CNC Win.Malware.GamKer variant outbound connection (more info ...)trojan-activity    URL
43933INDICATOR-COMPROMISE VBScript accessing scripting API for WMI (more info ...)attempted-user    
43942FILE-OTHER Abbs Media Player LST buffer overflow attempt (more info ...)attempted-admin    URL
43943MALWARE-BACKDOOR Win.Trojan.DonaldDick variant outbound connection detection (more info ...)trojan-activity    URL
43944FILE-OTHER multiple products malformed CUE file buffer overflow attempt (more info ...)attempted-user 2007-2888 33960  
43945FILE-OTHER Magic Music Editor malformed CDA buffer overflow attempt (more info ...)attempted-admin    URL
43946FILE-OTHER Guitar Pro malformed GPX buffer overflow attempt (more info ...)denial-of-service 2012-6048   
43947FILE-OTHER Guitar Pro malformed GPX buffer overflow attempt (more info ...)denial-of-service 2012-6048   
43950MALWARE-CNC Win.Trojan.Globeimposter outbound connection (more info ...)trojan-activity    URL
43952FILE-OTHER VLC Media Player malformed AMR buffer overflow attempt (more info ...)attempted-admin 2012-0904   
43953FILE-OTHER VLC Media Player malformed AMR buffer overflow attempt (more info ...)attempted-admin 2012-0904   
43957SERVER-WEBAPP Ubiquiti Networks UniFi Cloud Key Firm v0.6.1 Host Remote Command Execution attempt (more info ...)web-application-attack    URL
43958SERVER-WEBAPP SoapUI WSDL types element remote code execution attempt (more info ...)attempted-user 2014-1202   URL
43959SERVER-OTHER Sybase Open Server function pointer array code execution attempt (more info ...)attempted-admin  48934  URL
43969MALWARE-CNC Win.Trojan.Kradod connection attempt (more info ...)trojan-activity    URL
43972MALWARE-CNC Win.Trojan.Fareit variant outbound connection (more info ...)trojan-activity    URL
43981MALWARE-CNC Andr.Trojan.Femas variant outbound connection (more info ...)trojan-activity    URL
43982MALWARE-CNC Andr.Trojan.Femas variant outbound connection (more info ...)trojan-activity    URL
43985MALWARE-CNC Win.Trojan.Rortiem outbound connection (more info ...)trojan-activity    URL
43989INDICATOR-OBFUSCATION newlines embedded in rtf header (more info ...)misc-attack 2012-0158   URL
43990INDICATOR-OBFUSCATION RTF obfuscation string (more info ...)misc-attack 2012-0158   URL
44011MALWARE-CNC Win.Trojan.Hippo variant outbound connection (more info ...)trojan-activity    
44019FILE-IMAGE malformed png missing IHDR (more info ...)attempted-user    
44020FILE-IMAGE malformed png missing IHDR (more info ...)attempted-user    
44021SERVER-WEBAPP Dell OpenManage server application field buffer overflow attempt (more info ...)attempted-user 2004-0331   
44027MALWARE-CNC Win.Trojan.Locky dropper variant outbound request detected (more info ...)trojan-activity    URL
44028MALWARE-CNC Win.Trojan.Locky dropper variant outbound request detected (more info ...)trojan-activity    URL
44038SERVER-OTHER LCDproc parse_all_client_messages buffer overflow attempt (more info ...)attempted-admin 2004-1915   
44039FILE-PDF Foxit PDF Reader Launch action buffer overflow attempt (more info ...)attempted-user 2009-0837 34035  URL
44041SERVER-OTHER LCDproc test_func buffer overflow attempt (more info ...)attempted-admin  10085  
44042MALWARE-CNC Win.Trojan.Hupigon Connection attempt (more info ...)trojan-activity    URL
44096MALWARE-TOOLS Request to service that provices external IP address detected (more info ...)trojan-activity    URL
44105SERVER-OTHER WebPageTests upload feature remote file upload attempt (more info ...)attempted-user    URL
44123FILE-OTHER EMF EMR_EXTTEXTOUTW record memory corruption attempt (more info ...)misc-activity    
44124FILE-OTHER EMF EMR_EXTTEXTOUTW record memory corruption attempt (more info ...)misc-activity    URL
44133SERVER-WEBAPP OPENi-CMS Seitenschutz plugin remote file include attempt (more info ...)web-application-attack 2007-0881   
44134SERVER-WEBAPP OPENi-CMS Seitenschutz plugin remote file include attempt (more info ...)web-application-attack 2007-0881   
44142POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0424 attack attempt (more info ...)policy-violation 2017-2917   URL
44143SERVER-OTHER LCDproc test_func format string code execution attempt (more info ...)attempted-admin 2004-1917   
44150SERVER-WEBAPP IBM Websphere cross site scripting attempt (more info ...)attempted-user 2009-0856   
44162POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0422 attack attempt (more info ...)policy-violation 2017-2915   URL
44165SERVER-WEBAPP websocket protocol upgrade request detected (more info ...)protocol-command-decode    URL
44166SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0428 attack attempt (more info ...)attempted-user 2017-2921   URL
44171MALWARE-CNC Win.Trojan.Zurgop variant outbound beaconing connection (more info ...)trojan-activity    URL
44172INDICATOR-OBFUSCATION suspicious dynamic http link creation attempt (more info ...)attempted-user    URL
44177MALWARE-CNC Win.Trojan.Cerber variant outbound connection (more info ...)trojan-activity    URL
44180FILE-OTHER Bluezone Desktop buffer overflow attempt (more info ...)attempted-user    URL
44181FILE-OTHER Bluezone Desktop buffer overflow attempt (more info ...)attempted-user    URL
44190MALWARE-CNC Win.Trojan.Cyfshent variant outbound connection (more info ...)trojan-activity    URL
44194FILE-MULTIMEDIA multiple audio players playlist file handling heap overflow attempt (more info ...)attempted-user 2013-7409 62926  URL
44201SERVER-OTHER Verso NetPerformer frame relay access device telnet buffer overflow attempt (more info ...)denial-of-service  19989  
44203SERVER-OTHER HP Data Protector memory corruption attempt (more info ...)attempted-user    URL
44204FILE-OTHER VideoLAN VLC Media Player Ogg/Vorbis denial of service attempt (more info ...)attempted-admin 2007-3316   
44205FILE-OTHER VideoLAN VLC Media Player Ogg/Vorbis denial of service attempt (more info ...)attempted-admin 2007-3316   
44210MALWARE-CNC Win.Trojan.Bullrat variant outbound connection (more info ...)trojan-activity    URL
44211MALWARE-CNC Win.Trojan.Tarayt outbound connection (more info ...)trojan-activity    URL
44212MALWARE-CNC Win.Trojan.Tarayt outbound connection (more info ...)trojan-activity    URL
44213MALWARE-CNC User-Agent known malicious user-agent - ace4956e-736e-11e6-9584-d7165ca591df - Win.Trojan.Tarayt (more info ...)trojan-activity    URL
44214MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Graftor (more info ...)trojan-activity    URL
44215SERVER-OTHER Sybase Open Server TDS login packet stack memory corruption attempt (more info ...)attempted-admin    URL
44220MALWARE-CNC Win.Ransomware.SyncCrypt variant initial outbound connection (more info ...)trojan-activity    URL
44221MALWARE-CNC Win.Ransomware.SyncCrypt variant initial outbound connection (more info ...)trojan-activity    URL
44222MALWARE-CNC Win.Ransomware.SyncCrypt variant initial outbound connection (more info ...)trojan-activity    URL
44267POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0436 attack attempt (more info ...)policy-violation 2017-12084   URL
44268POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0437 attack attempt (more info ...)policy-violation 2017-12085   URL
44276MALWARE-CNC Win.Trojan.Chthonic outbound file download attempt (more info ...)trojan-activity    URL
44277MALWARE-CNC Win.Trojan.Chthonic outbound file download attempt (more info ...)trojan-activity    URL
44278MALWARE-CNC Win.Trojan.CrystalAttack outbound file download attempt (more info ...)trojan-activity    URL
44279MALWARE-CNC Win.Ransomware.FlatChestWare varint outbound connection (more info ...)trojan-activity    
44298SERVER-WEBAPP AT&T U-verse modem command injection attempt (more info ...)web-application-attack    URL
44299SERVER-WEBAPP AT&T U-verse modem information disclosure attempt (more info ...)attempted-recon    URL
44300SERVER-WEBAPP AT&T U-verse modem authentication bypass attempt (more info ...)web-application-attack 2017-14117   URL
44301SERVER-WEBAPP AT&T U-verse modem information disclosure attempt (more info ...)attempted-recon    URL
44302SERVER-WEBAPP AT&T U-verse modem firmware upload attempt (more info ...)attempted-admin    URL
44307MALWARE-CNC Win.Downloader.Razy variant outbound connection (more info ...)trojan-activity    URL
44313MALWARE-CNC Win.Trojan.Totbrick variant outbound connection (more info ...)trojan-activity    URL
44314MALWARE-CNC Win.Trojan.Totbrick variant inbound connection attempt (more info ...)trojan-activity    URL
44316MALWARE-CNC Win.Trojan.Ellell variant outbound connection (more info ...)trojan-activity    URL
44317MALWARE-CNC User-Agent known malicious user-agent - Version/100 - Win.Trojan.Tarayt (more info ...)trojan-activity    URL
44323FILE-OTHER RAR file malformed header antivirus evasion attempt (more info ...)misc-activity 2012-1443   
44325FILE-OTHER ZIP file malformed header antivirus evasion attempt (more info ...)misc-activity 2012-1462   
44355FILE-IMAGE Free Opener malformed JPEG file buffer overflow attempt (more info ...)attempted-user    URL
44358PUA-ADWARE DealPly Adware variant outbound connection (more info ...)misc-activity    URL
44362MALWARE-CNC User-Agent known malicious user-agent string - Sality (more info ...)trojan-activity    URL
44365MALWARE-CNC Win.Trojan.Paradise ransomware outbound post (more info ...)trojan-activity    URL
44366MALWARE-CNC Win.Trojan.Paradise ransomware inbound executable (more info ...)trojan-activity    URL
44367MALWARE-CNC Win.Trojan.Paradise ransomware inbound executable (more info ...)trojan-activity    URL
44368PROTOCOL-SCADA CoDeSys GatewayService heap overrun attempt (more info ...)attempted-user 2011-5008 50849  
44369FILE-PDF Nitro Pro malformed object index buffer overflow attempt (more info ...)attempted-user    URL
44370FILE-PDF Nitro Pro malformed object index buffer overflow attempt (more info ...)attempted-user    URL
44373SERVER-WEBAPP XStream void primitive denial of service attempt (more info ...)denial-of-service 2018-1327   URL
44382SERVER-OTHER D-Link router remote reboot attempt (more info ...)misc-activity    URL
44391MALWARE-CNC Win.Trojan.Konus variant outbound connection detected (more info ...)trojan-activity    URL
44392MALWARE-CNC Win.Trojan.Konus variant outbound connection detected (more info ...)trojan-activity    URL
44393MALWARE-CNC Win.Trojan.Konus variant outbound connection detected (more info ...)trojan-activity    URL
44394PUA-ADWARE Win.Adware.Techsnab variant outbound connection detected (more info ...)misc-activity    URL
44395PUA-ADWARE Win.Adware.Techsnab variant outbound connection detected (more info ...)misc-activity    URL
44396MALWARE-CNC Win.Trojan.KediRAT outbound connection (more info ...)trojan-activity    URL
44403MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44404MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44405MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44406MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44407MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44408MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44409MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44410MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44411MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44412MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44413MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44414MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44415MALWARE-CNC Win.Trojan.Trickbot malicious communication attempt (more info ...)trojan-activity    URL
44419PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2017-0445 attack attempt (more info ...)denial-of-service 2017-12093   URL
44420PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2017-0440 attack attempt (more info ...)denial-of-service 2017-12088   URL
44421POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0441 attack attempt (more info ...)policy-violation 2017-12089   URL
44422POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0441 attack attempt (more info ...)policy-violation 2017-12089   URL
44423POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0444 attack attempt (more info ...)policy-violation 2017-12092   URL
44424POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0443 attack attempt (more info ...)policy-violation 2017-12091   URL
44425POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0443 attack attempt (more info ...)policy-violation 2017-12091   URL
44426POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0443 attack attempt (more info ...)policy-violation 2017-12091   URL
44427POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0443 attack attempt (more info ...)policy-violation 2017-12091   URL
44428POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0443 attack attempt (more info ...)policy-violation 2017-12091   URL
44429POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0443 attack attempt (more info ...)policy-violation 2017-12091   URL
44438MALWARE-CNC Win.Backdoor.Poison variant outbound connection detected (more info ...)trojan-activity    URL
44439MALWARE-CNC Win.Backdoor.Poison variant outbound connection detected (more info ...)trojan-activity    URL
44440MALWARE-CNC User-Agent known malicious user-agent string - Poison (more info ...)trojan-activity    URL
44443MALWARE-CNC Win.Trojan.Popureb variant outbound connection detected (more info ...)trojan-activity    URL
44450MALWARE-CNC Win.Trojan.Buterat variant outbount connection detected (more info ...)trojan-activity    URL
44451FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0458 attack attempt (more info ...)attempted-user 2017-12106   URL
44452FILE-IMAGE TRUFFLEHUNTER TALOS-2017-0458 attack attempt (more info ...)attempted-user 2017-12106   URL
44455FILE-IMAGE Apple PICT Quickdraw image converter packType 4 buffer overflow attempt (more info ...)attempted-user 2008-3021 30598  
44456FILE-IMAGE Apple PICT Quickdraw image converter packType 4 buffer overflow attempt (more info ...)attempted-user 2008-3021 30598  
44468SERVER-OTHER SAP Netweaver Dynpro Engine denial of service attempt (more info ...)attempted-dos 2017-9845 96874  URL
44476PUA-ADWARE Win.Adware.OutBrowse variant outbound connection detected (more info ...)misc-activity    URL
44507SERVER-WEBAPP Symantec Endpoint Protection Manager information disclosure attempt (more info ...)attempted-recon 2016-3649 91440  
44540SERVER-OTHER Jiangmin Anti-Virus Network Edition information disclosure attempt (more info ...)attempted-recon    URL
44541SERVER-OTHER Jiangmin Anti-Virus Network Edition configuration change attempt (more info ...)misc-activity    URL
44542SERVER-OTHER Jiangmin Anti-Virus Network Edition remote code execution attempt (more info ...)attempted-admin    URL
44543SERVER-OTHER Jiangmin Anti-Virus Network Edition information disclosure attempt (more info ...)attempted-recon    
44554MALWARE-CNC Andr.Trojan.Congur variant outbound connection detected (more info ...)trojan-activity    URL
44561MALWARE-CNC PowerShell Empire variant outbound connection (more info ...)trojan-activity    URL
44562MALWARE-CNC PowerShell Empire variant outbound connection (more info ...)trojan-activity    URL
44563MALWARE-CNC PowerShell Empire variant outbound connection (more info ...)trojan-activity    URL
44564MALWARE-CNC PowerShell Empire variant outbound connection (more info ...)trojan-activity    URL
44565SERVER-WEBAPP Trend Micro SPS and IMS diagnostic.log session disclosure attempt (more info ...)attempted-recon 2017-11398 102275  URL
44569MALWARE-CNC Win.Trojan.Fareit variant outbound connection (more info ...)trojan-activity    URL
44570MALWARE-CNC Win.Trojan.Fareit variant outbound connection (more info ...)trojan-activity    URL
44574SERVER-OTHER Ipass Client control pipe remote code execution attempt (more info ...)attempted-admin    URL
44575SERVER-WEBAPP Ignite Realtime Openfire user-create cross site request forgery attempt (more info ...)attempted-user 2015-6973   
44576SERVER-OTHER Samsung Security Manager ActiveMQ arbitrary file upload attempt (more info ...)attempted-admin 2015-3435   
44577SERVER-OTHER Samsung Security Manager ActiveMQ cross site scripting attempt (more info ...)web-application-attack 2015-3435   
44610MALWARE-CNC Win.Trojan.Locky dropper variant outbound request detected (more info ...)trojan-activity    URL
44611MALWARE-CNC Win.Trojan.Locky dropper variant outbound request detected (more info ...)trojan-activity    URL
44612INDICATOR-COMPROMISE VBscript downloader detected (more info ...)trojan-activity    URL
44613INDICATOR-COMPROMISE VBscript downloader detected (more info ...)trojan-activity    URL
44616MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
44617MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
44618MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
44619MALWARE-CNC Android Red Alert Trojan outbound connection (more info ...)trojan-activity    URL
44620MALWARE-CNC Android Red Alert Trojan outbound connection (more info ...)trojan-activity    URL
44621MALWARE-CNC Android Red Alert Trojan outbound connection (more info ...)trojan-activity    URL
44622MALWARE-CNC Android Red Alert Trojan outbound connection (more info ...)trojan-activity    URL
44623POLICY-OTHER EMC Autostart default domain login attempt (more info ...)default-login-attempt    URL
44639MALWARE-CNC Win.Trojan.Quimonk variant outbound connection detected (more info ...)trojan-activity    URL
44640POLICY-OTHER WPA2 key reuse tool attempt (more info ...)attempted-user 2017-13088   URL
44643SERVER-OTHER Mikrotik RouterOS denial of service attempt (more info ...)denial-of-service 2012-6050   
44652MALWARE-CNC Win.Zusy variant outbound connection (more info ...)trojan-activity    URL
44653MALWARE-CNC IoT Reaper botnet (more info ...)trojan-activity    URL
44654MALWARE-CNC IoT Reaper botnet CNC (more info ...)trojan-activity    URL
44655MALWARE-CNC IoT Reaper botnet dropper (more info ...)trojan-activity    URL
44656MALWARE-CNC IoT Reaper botnet CNC (more info ...)trojan-activity    URL
44659MALWARE-CNC Win.Trojan.Wraut variant outbound connection (more info ...)trojan-activity    URL
44660SERVER-OTHER D-Link multiple routers command execution attempt (more info ...)attempted-admin 2020-9377   URL
44661SERVER-OTHER D-Link DIR-300 and DIR-600 information disclosure attempt (more info ...)attempted-recon    URL
44662SERVER-OTHER D-Link DIR-300 and DIR-600 information disclosure attempt (more info ...)attempted-recon    URL
44663SERVER-OTHER Mikrotik RouterOS SNMP security bypass attempt (more info ...)attempted-admin 2008-6976   
44665SERVER-OTHER Easy Chat Server buffer overflow attempt (more info ...)attempted-admin 2004-2466 67384  
44666SERVER-OTHER Easy Chat Server buffer overflow attempt (more info ...)attempted-admin 2004-2466 67384  
44668SERVER-WEBAPP Advantech WebAccess cross site scripting attempt (more info ...)attempted-user 2012-0233   
44675SERVER-OTHER iSCSI target multiple implementations iSNS stack buffer overflow attempt (more info ...)attempted-admin 2010-2221 41327  
44676SERVER-OTHER Wireshark Sigcomp buffer overflow attempt (more info ...)attempted-user 2010-2287   
44677MALWARE-CNC Win.Trojan.Nemucod outbound connection (more info ...)trojan-activity    
44678POLICY-OTHER NetSupport Manager RAT outbound connection detected (more info ...)trojan-activity    URL
44679SERVER-OTHER Beetel Connection Manager username buffer overflow attempt (more info ...)attempted-user  63414  
44680SERVER-OTHER Beetel Connection Manager username buffer overflow attempt (more info ...)attempted-user  63414  
44685SERVER-OTHER TVMOBiLi HttpUtils.dll denial of service attempt (more info ...)attempted-admin 2012-5451   
44686SERVER-OTHER TVMOBiLi HttpUtils.dll denial of service attempt (more info ...)attempted-admin 2012-5451   
44689MALWARE-CNC Win.Trojan.Gen variant outbound connection (more info ...)trojan-activity    URL
44690SERVER-OTHER ElasticSearch script remote code execution attempt (more info ...)attempted-admin 2014-3120   URL
44691PUA-ADWARE Win.Adware.Clover outbound connection (more info ...)misc-activity    URL
44692INDICATOR-OBFUSCATION CoinHive cryptocurrency mining attempt (more info ...)misc-attack    URL
44693INDICATOR-OBFUSCATION CoinHive cryptocurrency mining attempt (more info ...)misc-attack    URL
44697MALWARE-CNC SquirrelMail directory traversal attempt (more info ...)web-application-attack 2006-2842   URL
44698SERVER-WEBAPP Internal field separator use in HTTP URI attempt (more info ...)web-application-attack    
44699SERVER-WEBAPP Internal field separator use in HTTP URI attempt (more info ...)web-application-attack    
44702POLICY-OTHER Inedo BuildMaster web server login with default credentials attempt (more info ...)policy-violation    URL
44713POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0464 attack attempt (more info ...)policy-violation 2017-12114   URL
44714POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0464 attack attempt (more info ...)policy-violation 2017-12118   URL
44715SERVER-OTHER Oracle GoldenGate Collector process remote start attempt (more info ...)policy-violation 2016-0451   URL
44716SERVER-OTHER Oracle GoldenGate arbitrary file write attempt (more info ...)policy-violation 2016-0451   URL
44717SERVER-OTHER Oracle GoldenGate Collector process remote start attempt (more info ...)policy-violation 2016-0451   URL
44718SERVER-OTHER Oracle GoldenGate arbitrary file write attempt (more info ...)policy-violation 2016-0451   URL
44719SERVER-OTHER Oracle GoldenGate arbitrary file write attempt (more info ...)policy-violation 2016-0451   URL
44720SERVER-OTHER Oracle GoldenGate arbitrary file write attempt (more info ...)policy-violation 2016-0451   URL
44721SERVER-OTHER Oracle GoldenGate Manager process arbitrary file execution attempt (more info ...)policy-violation 2016-0451   URL
44753MALWARE-CNC Win.Trojan.Stimilina variant outbound connection detected (more info ...)trojan-activity    URL
44756SERVER-OTHER NTP crypto-NAK denial of service attempt (more info ...)denial-of-service 2016-4957   URL
44757FILE-OTHER LibYAML yaml_parser_scan_uri_escapes heap buffer overflow attempt (more info ...)attempted-user 2014-2525   
44758FILE-OTHER LibYAML yaml_parser_scan_uri_escapes heap buffer overflow attempt (more info ...)attempted-user 2014-2525   
44759FILE-OTHER LibYAML yaml_parser_scan_uri_escapes heap buffer overflow attempt (more info ...)attempted-user 2014-2525   
44760MALWARE-CNC Win.Trojan.Reyptson ransomware download (more info ...)trojan-activity    URL
44761MALWARE-CNC Win.Trojan.Reyptson ransomware download (more info ...)trojan-activity    URL
44762MALWARE-CNC Win.Trojan.KopiLuwak variant outbound request detected (more info ...)trojan-activity    URL
44763MALWARE-CNC Win.Trojan.KopiLuwak variant outbound request detected (more info ...)trojan-activity    URL
44768MALWARE-CNC Win.Trojan.Silence outbound request (more info ...)attempted-admin    URL
44769MALWARE-CNC Win.Trojan.Silence inbound download (more info ...)attempted-admin    URL
44770MALWARE-CNC Win.Trojan.Silence cnc module download (more info ...)attempted-admin    URL
44771MALWARE-CNC Win.Trojan.Silence monitoring module download (more info ...)attempted-admin    URL
44772MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Datper (more info ...)trojan-activity    URL
44773MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Datper (more info ...)trojan-activity    URL
44774MALWARE-CNC Win.Trojan.xxmm variant initial outbound connection detected (more info ...)trojan-activity    URL
44775MALWARE-CNC Win.Trojan.xxmm variant initial outbound connection detected (more info ...)trojan-activity    URL
44776MALWARE-CNC Win.Trojan.xxmm variant initial outbound connection detected (more info ...)trojan-activity    URL
44777MALWARE-CNC Win.Trojan.xxmm variant initial outbound connection detected (more info ...)trojan-activity    URL
44778MALWARE-CNC Win.Trojan.xxmm variant initial outbound connection detected (more info ...)trojan-activity    URL
44779MALWARE-CNC Win.Trojan.xxmm variant initial outbound connection detected (more info ...)trojan-activity    URL
44780MALWARE-CNC Win.Trojan.Locky outbound callout (more info ...)trojan-activity    URL
44781MALWARE-CNC Win.Trojan.Locky outbound callout (more info ...)trojan-activity    URL
44782MALWARE-CNC Win.Trojan.Locky outbound callout (more info ...)trojan-activity    URL
44783FILE-IDENTIFY UltraPlayer USK file buffer overflow attempt (more info ...)misc-activity    
44784FILE-IDENTIFY UltraPlayer USK file buffer overflow attempt (more info ...)misc-activity    
44785FILE-IDENTIFY UltraPlayer USK file buffer overflow attempt (more info ...)misc-activity    
44786FILE-IDENTIFY UltraPlayer USK file buffer overflow attempt (more info ...)misc-activity    
44787MALWARE-CNC Win.Trojan.Godzilla outbound connection (more info ...)trojan-activity    URL
44788MALWARE-CNC Win.Trojan.Nymaim variant outbound connection (more info ...)trojan-activity    URL
44789MALWARE-CNC Win.Trojan.Nymaim variant outbound connection (more info ...)trojan-activity    URL
44790SERVER-WEBAPP MikroTik RouterOS cross site request forgery attempt (more info ...)policy-violation 2015-2350 73013  
44791MALWARE-CNC Win.Trojan.Retadup variant outbound connection (more info ...)trojan-activity    URL
44855POLICY-OTHER TRUFFLEHUNTER TALOS-2017-0480 attack attempt (more info ...)policy-violation 2017-12128   URL
44876MALWARE-CNC Malicious VBA Dropper outbound connection detected (more info ...)trojan-activity    
44878SERVER-OTHER Mako Web Server arbitrary file upload attempt (more info ...)attempted-user    URL
44886MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Volgmer (more info ...)trojan-activity    URL
44889PUA-TOOLBARS WidgiToolbar toolbar runtime detection (more info ...)misc-activity    URL
44895MALWARE-CNC Win.Trojan.CoinMiner inbound connection detected (more info ...)trojan-activity    URL
44896MALWARE-CNC Win.Trojan.CoinMiner outbound connection (more info ...)trojan-activity    URL
44897MALWARE-CNC Win.Trojan.CoinMiner outbound connection (more info ...)trojan-activity    URL
44898MALWARE-CNC Win.Trojan.CoinMiner outbound connection (more info ...)trojan-activity    URL
44899MALWARE-CNC Win.Trojan.CoinMiner inbound connection detected (more info ...)trojan-activity    URL
44911MALWARE-CNC Osx.Trojan.Fruitfly variant outbound connection detected (more info ...)trojan-activity    URL
44943MALWARE-CNC Win.Trojan.FallChill variant outbound connection (more info ...)trojan-activity    URL
44944MALWARE-CNC Win.Trojan.FallChill variant outbound connection (more info ...)trojan-activity    URL
44945MALWARE-CNC Win.Trojan.FallChill variant outbound connection (more info ...)trojan-activity    URL
44946MALWARE-CNC Win.Trojan.FallChill variant outbound connection (more info ...)trojan-activity    URL
44972MALWARE-CNC Win.Trojan.Ramnit variant outbound connection (more info ...)trojan-activity    URL
44973MALWARE-CNC Win.Trojan.Ramnit variant outbound connection (more info ...)trojan-activity    URL
44979FILE-PDF Foxit Reader and PhantomPDF util printf information disclosure attempt (more info ...)attempted-recon 2019-13318   
44980FILE-PDF Foxit Reader and PhantomPDF util printf information disclosure attempt (more info ...)attempted-recon 2019-13318   
44985SERVER-OTHER Galil RIO-47100 denial of service attempt (more info ...)denial-of-service 2013-0699   
44986SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0486 attack attempt (more info ...)attempted-dos 2017-12130   URL
44992SERVER-WEBAPP ManageEngine ServiceDesk Plus policy bypass attempt (more info ...)web-application-attack 2015-1480   
44993SERVER-WEBAPP ManageEngine ServiceDesk Plus policy bypass attempt (more info ...)web-application-attack 2015-1480   
44994SERVER-WEBAPP ManageEngine ServiceDesk Plus policy bypass attempt (more info ...)web-application-attack 2015-1480   
44996SERVER-WEBAPP ManageEngine ServiceDesk Plus policy bypass attempt (more info ...)web-application-attack 2015-1480   
44997MALWARE-CNC Legend irc bot cnc attempt (more info ...)trojan-activity    
44998MALWARE-CNC Legend irc bot cnc attempt (more info ...)trojan-activity    
44999SERVER-WEBAPP Ruby on Rails file inclusion attempt (more info ...)attempted-user 2016-0752   URL
45000SERVER-WEBAPP Ruby on Rails file inclusion attempt (more info ...)attempted-user 2016-0752   URL
45029FILE-PDF JPEG2000 image coding style default information disclosure attempt (more info ...)misc-activity 2017-16387   URL
45030FILE-PDF JPEG2000 image coding style default information disclosure attempt (more info ...)misc-activity 2017-16387   URL
45049SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0493 attack attempt (more info ...)attempted-recon 2017-14444   URL
45050MALWARE-CNC Win.Trojan.IcedId outbound connection (more info ...)trojan-activity    URL
45051MALWARE-CNC User-Agent known malicious user-agent string - Win.Tool.SMSBomber (more info ...)trojan-activity    URL
45062MALWARE-CNC Win.Trojan.Neuron variant inbound service request detected (more info ...)trojan-activity    URL
45063MALWARE-CNC Win.Trojan.Neuron variant inbound service request detected (more info ...)trojan-activity    URL
45064MALWARE-CNC Win.Trojan.Neuron variant inbound service request detected (more info ...)trojan-activity    URL
45065MALWARE-CNC Win.Trojan.Neuron variant inbound service request detected (more info ...)trojan-activity    URL
45068SERVER-OTHER Oracle Identity Manager default login attempt (more info ...)attempted-admin 2017-10151   URL
45069SERVER-SAMBA Samba write andx command memory leak attempt (more info ...)attempted-user 2017-12163   URL
45070SERVER-SAMBA Samba write and close command memory leak attempt (more info ...)attempted-user 2017-12163   URL
45072SERVER-SAMBA Samba write command memory leak attempt (more info ...)attempted-user 2017-12163   URL
45078SERVER-WEBAPP TP-Link WR1043ND router cross site request forgery attempt (more info ...)web-application-attack 2013-2645   
45079SERVER-WEBAPP TP-Link WR1043ND router cross site request forgery attempt (more info ...)web-application-attack 2013-2645   
45082SERVER-WEBAPP Ruby on Rails log file manipulation attempt (more info ...)attempted-recon 2016-0752   URL
45086SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0494 attack attempt (more info ...)attempted-admin 2017-14445   URL
45087SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0495 attack attempt (more info ...)attempted-admin 2017-14446   URL
45090MALWARE-CNC Win.Backdoor.StoneDrill server selection outbound connection (more info ...)trojan-activity    URL
45091MALWARE-CNC Win.Backdoor.StoneDrill login outbound connection (more info ...)trojan-activity    URL
45092MALWARE-CNC Win.Backdoor.StoneDrill get commands outbound connection (more info ...)trojan-activity    URL
45095MALWARE-CNC Win.Ransomware.Gibon variant outbound connection (more info ...)trojan-activity    URL
45096MALWARE-CNC Win.Ransomware.Gibon variant inbound connection (more info ...)trojan-activity    URL
45097MALWARE-CNC Win.Downloader.SnatchLoader variant inbound connection (more info ...)trojan-activity    URL
45098MALWARE-CNC Win.Downloader.SnatchLoader variant outbound connection (more info ...)trojan-activity    URL
45104MALWARE-CNC Win.Malware.Recam variant outbound connection (more info ...)trojan-activity    URL
45107SERVER-OTHER Fatek Automation PLC WinProladder buffer overflow attempt (more info ...)attempted-user 2016-8377 94938  
45111SERVER-WEBAPP OrientDB database query attempt (more info ...)attempted-recon 2017-11467   URL
45157SERVER-OTHER SSDP M-SEARCH ssdp-all potential amplified distributed denial-of-service attempt (more info ...)attempted-dos 2013-5211   URL
45191PROTOCOL-TELNET TippingPoint IPS telnet login failure xss attempt (more info ...)misc-attack    
45194MALWARE-CNC Win.Trojan.FileCryptor variant outbound connection (more info ...)trojan-activity    URL
45195SERVER-WEBAPP Zavio IP Cameras command injection attempt (more info ...)web-application-attack 2013-2570 60188  URL
45196SERVER-WEBAPP Zavio IP Cameras command injection attempt (more info ...)web-application-attack 2013-2570 60188  URL
45197SERVER-WEBAPP Zavio IP Cameras command injection attempt (more info ...)web-application-attack 2013-2570 60188  URL
45200SERVER-OTHER limited RSA ciphersuite list - possible Bleichenbacher SSL attack attempt (more info ...)attempted-recon 2017-6168   URL
45204SERVER-WEBAPP ActiveCalendar css cross site scripting attempt (more info ...)web-application-attack 2007-1111   
45205SERVER-OTHER HP Data Protector Express DtbClsLogin buffer overflow attempt (more info ...)attempted-user 2010-3007 43105  
45207PROTOCOL-SCADA WelinTech Kingview History Server denial of service attempt (more info ...)attempted-dos    URL
45208MALWARE-CNC Win.Trojan.VEye2 remote access tool download (more info ...)trojan-activity    URL
45209MALWARE-CNC Win.Trojan.VEye2 remote access tool download (more info ...)trojan-activity    URL
45220SERVER-OTHER TRUFFLEHUNTER TALOS-2017-0507 attack attempt (more info ...)attempted-admin 2017-14459   URL
45221MALWARE-CNC Win.Trojan.Nautilus outbound call (more info ...)trojan-activity    URL
45222SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0508 attack attempt (more info ...)attempted-recon 2017-14460   URL
45223SERVER-WEBAPP TRUFFLEHUNTER TALOS-2017-0508 attack attempt (more info ...)attempted-recon 2017-14460   URL
45226SERVER-WEBAPP FreePBX recording interface file upload code execution attempt (more info ...)web-application-attack 2010-3490 43454  
45227SERVER-OTHER Docker Rancher Server remote code execution attempt (more info ...)attempted-user    URL
45228SERVER-OTHER Medal Of Honor Allied Assault getinfo buffer overflow attempt (more info ...)attempted-user 2004-0735 10743  
45229MALWARE-CNC User-Agent known malicious user-agent string - SocStealer (more info ...)trojan-activity    URL
45230MALWARE-CNC User-Agent known malicious user-agent string - SocStealer (more info ...)trojan-activity    URL
45231MALWARE-CNC Win.Trojan.DDEDownloader variant outbound connection detected (more info ...)trojan-activity    URL
45232MALWARE-CNC Win.Trojan.CactusTorch download attempt detected (more info ...)attempted-admin    URL
45233PROTOCOL-SCADA Schneider Modicon Quantum modbus stop command attempt (more info ...)misc-activity    URL
45234PROTOCOL-SCADA Schneider Modicon Quantum modbus start command attempt (more info ...)misc-activity    URL
45239MALWARE-CNC Win.Malware.Freenki variant outbound connection (more info ...)trojan-activity    URL
45249SERVER-WEBAPP UAParser.js library regular expression denial of service attempt (more info ...)denial-of-service    URL
45251MALWARE-CNC Win.Ransomware.Spider variant download attempt detected (more info ...)trojan-activity    URL
45252MALWARE-CNC Win.Ransomware.Spider variant download attempt detected (more info ...)trojan-activity    URL
45256BROWSER-OTHER IBM Notes denial of service attempt (more info ...)denial-of-service 2017-1130 100632  URL
45257BROWSER-OTHER IBM Notes denial of service attempt (more info ...)denial-of-service 2017-1130 100632  URL
45260MALWARE-CNC Win.Backdoor.Triton Triton ICS malware upload attempt (more info ...)trojan-activity    URL
45262SERVER-WEBAPP Google App Engine open redirect attempt (more info ...)web-application-attack    URL
45263SERVER-WEBAPP CMS Made Simple server side template injection attempt (more info ...)web-application-attack 2017-16783   
45264SERVER-WEBAPP CMS Made Simple server side template injection attempt (more info ...)web-application-attack 2017-16783   
45302BROWSER-OTHER Multiple browser long unicode string denial of service attempt (more info ...)denial-of-service    URL
45303BROWSER-OTHER Multiple browser long unicode string denial of service attempt (more info ...)denial-of-service    URL
45305FILE-IMAGE Qt library BMP image parser heap overflow exploit attempt (more info ...)attempted-user 2004-0691   
45306FILE-IMAGE Qt library BMP image parser heap overflow exploit attempt (more info ...)attempted-user 2004-0691   
45317SERVER-WEBAPP Chipmunk Guestbook cross site scripting attempt (more info ...)attempted-user 2006-0069   
45320SERVER-WEBAPP Dahua DVR serial number query attempt (more info ...)attempted-recon 2013-6117 63742  
45321SERVER-WEBAPP Dahua DVR firmware version query attempt (more info ...)attempted-recon 2013-6117 63742  
45322SERVER-WEBAPP Dahua DVR channel information query attempt (more info ...)attempted-recon 2013-6117 63742  
45323SERVER-WEBAPP Dahua DVR email configuration download attempt (more info ...)attempted-recon 2013-6117 63742  
45326SERVER-WEBAPP Dahua DVR user group information query attempt (more info ...)attempted-recon 2013-6117 63742  
45327SERVER-WEBAPP Dahua DVR NAS configuration download attempt (more info ...)attempted-recon 2013-6117 63742  
45329SERVER-WEBAPP Dahua DVR clear logs request attempt (more info ...)misc-activity 2013-6117 63742  
45330SERVER-WEBAPP raSMP User-Agent XSS injection attempt (more info ...)web-application-attack 2006-0084 16138  
45331MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45332MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45333MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45334MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45335MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45336MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45337MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45338MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45339MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45340MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45341MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45342MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45343MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45344MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45352MALWARE-CNC PowerShell Empire HTTP listener response (more info ...)trojan-activity    URL
45373SERVER-WEBAPP Trend Micro Smart Protection Server directory traversal attempt (more info ...)web-application-attack 2017-14095 102275  URL
45380SERVER-OTHER Sixnet SixView Manager directory traversal attempt (more info ...)attempted-admin 2014-2976   
45381SERVER-WEBAPP Symantec Endpoint Protection cross site scripting attempt (more info ...)web-application-attack 2014-3438   
45382SERVER-WEBAPP Huawei router command injection attempt (more info ...)web-application-attack    
45385OS-OTHER Mac OS X setuid privilege esclatation exploit attempt (more info ...)attempted-admin 2007-0345   
45386OS-OTHER Mac OS X setuid privilege esclatation exploit attempt (more info ...)attempted-admin 2007-0345   
45400MALWARE-CNC Osx.Trojan.OceanLotus outbound connection attempt (more info ...)trojan-activity    URL
45417POLICY-OTHER Stratum mining protocol outbound connection attempt (more info ...)policy-violation    URL
45420SERVER-WEBAPP Drupal HTTP Strict Transport Security module security bypass attempt (more info ...)web-application-attack 2015-5505   URL
45422POLICY-OTHER TRUFFLEHUNTER TALOS-2018-0512 attack attempt (more info ...)misc-activity 2018-3834   URL
45423PROTOCOL-SCADA MMS Confirmed-RequestPDU (more info ...)protocol-command-decode    URL
45424PROTOCOL-SCADA MMS Confirmed-ResponsePDU (more info ...)protocol-command-decode    URL
45425PROTOCOL-SCADA MMS Confirmed-ErrorPDU (more info ...)protocol-command-decode    URL
45426PROTOCOL-SCADA MMS UnconfirmedPDU (more info ...)protocol-command-decode    URL
45427PROTOCOL-SCADA MMS RejectPDU (more info ...)protocol-command-decode    URL
45428PROTOCOL-SCADA MMS Cancel-RequestPDU (more info ...)protocol-command-decode    URL
45429PROTOCOL-SCADA MMS Cancel-ResponsePDU (more info ...)protocol-command-decode    URL
45430PROTOCOL-SCADA MMS Cancel-ErrorPDU (more info ...)protocol-command-decode    URL
45431PROTOCOL-SCADA MMS Initiate-RequestPDU (more info ...)protocol-command-decode    URL
45432PROTOCOL-SCADA MMS Initiate-ResponsePDU (more info ...)protocol-command-decode    URL
45433PROTOCOL-SCADA MMS Initiate-ErrorPDU (more info ...)protocol-command-decode    URL
45434PROTOCOL-SCADA MMS Conclude-RequestPDU (more info ...)protocol-command-decode    URL
45435PROTOCOL-SCADA MMS Conclude-ResponsePDU (more info ...)protocol-command-decode    URL
45436PROTOCOL-SCADA MMS Conclude-ErrorPDU (more info ...)protocol-command-decode    URL
45440SERVER-OTHER HP LoadRunner remote command execution attempt (more info ...)attempted-admin 2010-1549   URL
45442SERVER-OTHER Hewlett Packard Enterprise Intelligent Management Center FileDownloadServlet information disclosure attempt (more info ...)attempted-recon 2017-5797   
45454SERVER-WEBAPP PostfixAdmin protected alias deletion attempt (more info ...)policy-violation 2017-5930 96142  URL
45455EXPLOIT-KIT Rig Exploit Kit URI redirect attempt (more info ...)attempted-user    
45468MALWARE-CNC SambaCry ransomware download attempt (more info ...)trojan-activity    URL
45469MALWARE-CNC SambaCry ransomware download attempt (more info ...)trojan-activity    URL
45470MALWARE-CNC SambaCry ransomware download attempt (more info ...)trojan-activity    URL
45471MALWARE-CNC SambaCry ransomware download attempt (more info ...)trojan-activity    URL
45472MALWARE-CNC SambaCry ransomware download attempt (more info ...)trojan-activity    URL
45473MALWARE-CNC SambaCry ransomware download attempt (more info ...)trojan-activity    URL
45477MALWARE-CNC Win.Backdoor.Triton Triton ICS malware transfer attempt (more info ...)trojan-activity    URL
45478MALWARE-CNC Win.Backdoor.Triton Triton ICS malware transfer attempt (more info ...)trojan-activity    URL
45483MALWARE-CNC Pdf.Phishing.Agent variant outbound connection detected (more info ...)trojan-activity    URL
45499SERVER-OTHER ISC DHCPD remote denial of service attempt (more info ...)attempted-dos 2017-3144   URL
45510MALWARE-CNC Win.Trojan.Rokrat file upload attempt (more info ...)trojan-activity    URL
45514BROWSER-IE toStaticHTML CSS import XSS exploit attempt (more info ...)attempted-user 2010-3324   URL
45527EXPLOIT-KIT Rig Exploit Kit URI redirect attempt (more info ...)attempted-user    
45528EXPLOIT-KIT Rig Exploit Kit URI redirect attempt (more info ...)attempted-user    
45529EXPLOIT-KIT Rig Exploit Kit URI redirect attempt (more info ...)attempted-user    
45530EXPLOIT-KIT Rig Exploit Kit URI redirect attempt (more info ...)attempted-user    
45531EXPLOIT-KIT Rig Exploit Kit URI redirect attempt (more info ...)attempted-user    
45533FILE-OTHER Ghostscript rsdparams type confusion attempt (more info ...)attempted-user 2017-8291 98476  URL
45534FILE-OTHER Ghostscript rsdparams type confusion attempt (more info ...)attempted-user 2017-8291 98476  URL
45535FILE-OTHER Ghostscript eqproc type confusion attempt (more info ...)attempted-user 2017-8291 98476  URL
45536FILE-OTHER Ghostscript eqproc type confusion attempt (more info ...)attempted-user 2017-8291 98476  URL
45540SERVER-ORACLE Oracle Database Server mdsys.md2.sdo_code_size buffer overflow attempt (more info ...)attempted-user 2004-1774 13145  
45541FILE-OTHER WinAce TAR file directory traversal attempt (more info ...)attempted-user 2006-0981   
45542FILE-OTHER WinAce TAR file directory traversal attempt (more info ...)attempted-user 2006-0981   
45543FILE-OTHER WinAce RAR file directory traversal attempt (more info ...)attempted-user 2006-0981   
45544FILE-OTHER WinAce RAR file directory traversal attempt (more info ...)attempted-user 2006-0981   
45545MALWARE-CNC Osx.Trojan.SHLayer variant outbound connection (more info ...)trojan-activity    URL
45551MALWARE-CNC Win.Trojan.Velso ransomware download (more info ...)trojan-activity    URL
45552MALWARE-CNC Win.Trojan.Velso ransomware download (more info ...)trojan-activity    URL
45560MALWARE-CNC Win.Trojan.LockPoS outbound connection attempt (more info ...)trojan-activity    URL
45561MALWARE-CNC Win.Trojan.LockPoS outbound connection attempt (more info ...)trojan-activity    URL
45562MALWARE-CNC Win.Trojan.LockPoS outbound connection attempt (more info ...)trojan-activity    URL
45566MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45567MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45568SERVER-SAMBA Samba LDAP Server libldb denial of service attempt (more info ...)denial-of-service 2015-3223   
45569SERVER-WEBAPP Squid host header cache poisoning attempt (more info ...)attempted-user 2016-4553   URL
45571SERVER-OTHER Commvault Communications Service command injection attempt (more info ...)attempted-admin    URL
45574MALWARE-CNC Win.Trojan.xxmm second stage configuration download attempt (more info ...)trojan-activity    URL
45587SERVER-OTHER Firefly Media Server malformed HTTP request denial of service attempt (more info ...)denial-of-service 2012-5875   
45588SERVER-OTHER Firefly Media Server malformed HTTP request denial of service attempt (more info ...)denial-of-service 2012-5875   
45589SERVER-OTHER Firefly Media Server malformed HTTP request denial of service attempt (more info ...)denial-of-service 2012-5875   
45590SERVER-OTHER Firefly Media Server malformed HTTP request denial of service attempt (more info ...)denial-of-service 2012-5875   
45604SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0524 attack attempt (more info ...)denial-of-service 2018-3841   URL
45605FILE-OTHER TRUFFLEHUNTER TALOS-2018-0519 attack attempt (more info ...)attempted-recon 2018-3837   URL
45606FILE-OTHER TRUFFLEHUNTER TALOS-2018-0519 attack attempt (more info ...)attempted-recon 2018-3837   URL
45607MALWARE-CNC Win.Trojan.Rokrat variant outbound connection detected (more info ...)trojan-activity    URL
45610SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0523 attack attempt (more info ...)attempted-admin 2018-3840   URL
45611PROTOCOL-SNMP Cambium cnPilot SNMP request with read-only community string attempt (more info ...)attempted-recon 2017-5262   URL
45618PROTOCOL-SNMP Cambium ePMP SNMP request with read-only community string attempt (more info ...)attempted-recon 2017-7922 99083  URL
45638SERVER-MAIL SqWebMail print_header_ua cross site scripting attempt (more info ...)attempted-admin 2004-0591   
45639SERVER-MAIL SqWebMail print_header_ua cross site scripting attempt (more info ...)attempted-admin 2004-0591   
45642MALWARE-CNC Vbs.Trojan.Agent outbound connection (more info ...)trojan-activity    URL
45643MALWARE-CNC Vbs.Trojan.Agent inbound payload download (more info ...)trojan-activity    URL
45644MALWARE-CNC Vbs.Trojan.Agent inbound payload download (more info ...)trojan-activity    URL
45645MALWARE-CNC Vbs.Trojan.Agent inbound payload download (more info ...)trojan-activity    URL
45646MALWARE-CNC Vbs.Trojan.Agent outbound system information disclosure (more info ...)trojan-activity    URL
45647MALWARE-CNC Doc.Dropper.Lazarus initial download (more info ...)trojan-activity    URL
45648MALWARE-CNC Doc.Dropper.Lazarus initial download (more info ...)trojan-activity    URL
45651MALWARE-CNC Win.Trojan.Vermin outbound connection attempt (more info ...)trojan-activity    URL
45652FILE-PDF TRUFFLEHUNTER TALOS-2018-0526 attack attempt (more info ...)attempted-user 2018-3843   URL
45653FILE-PDF TRUFFLEHUNTER TALOS-2018-0526 attack attempt (more info ...)attempted-user 2018-3843   URL
45658MALWARE-CNC Win.Trojan.Agent outbound connection (more info ...)trojan-activity    URL
45675MALWARE-CNC Win.Trojan.Ursnif variant outbound connection attempt (more info ...)trojan-activity    URL
45693SERVER-OTHER NTP crypto-NAK denial of service attempt (more info ...)denial-of-service 2016-4957   URL
45694MALWARE-CNC Win.Ransomware.GandCrab outbound connection (more info ...)trojan-activity    URL
45738SERVER-OTHER ISC BIND malformed data channel authentication message denial of service attempt (more info ...)attempted-dos 2016-1285   URL
45745SERVER-OTHER CloudMe Sync Client stack buffer overflow attempt (more info ...)attempted-user 2018-6892   URL
45746SERVER-OTHER CloudMe Sync Client stack buffer overflow attempt (more info ...)attempted-user 2018-6892   
45747SERVER-OTHER CloudMe Sync Client stack buffer overflow attempt (more info ...)attempted-user 2018-6892   
45754MALWARE-CNC Win.Trojan.Saturn initial download (more info ...)trojan-activity    URL
45755MALWARE-CNC Win.Trojan.Saturn initial download (more info ...)trojan-activity    URL
45756SERVER-OTHER Squid HTTP Accept Encoding response header denial of service attempt (more info ...)denial-of-service 2016-3948   URL
45757SERVER-OTHER Squid HTTP Vary response header denial of service attempt (more info ...)denial-of-service 2016-3948   URL
45758POLICY-OTHER AutomationDirect Point Of View guest login attempt (more info ...)attempted-user    URL
45759POLICY-OTHER AutomationDirect Point Of View built-in function WebGetFile usage attempt (more info ...)attempted-user    URL
45771MALWARE-CNC Win.Trojan.CannibalRAT initial outbound connection (more info ...)trojan-activity    URL
45772MALWARE-CNC Win.Trojan.CannibalRAT outbound reporting attempt (more info ...)trojan-activity    URL
45773MALWARE-CNC Win.Trojan.CannibalRAT outbound upload attempt (more info ...)trojan-activity    URL
45816MALWARE-CNC User-Agent known malicious user-agent string - Win.Ransomware.Thanatos (more info ...)trojan-activity    URL
45826MALWARE-CNC Win.Trojan.Smominru outbound call (more info ...)trojan-activity    URL
45827MALWARE-CNC Win.Trojan.Smominru outbound call (more info ...)trojan-activity    URL
45829SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0535 attack attempt (more info ...)attempted-dos 2018-3852   URL
45834SERVER-WEBAPP /bin/sh access (more info ...)web-application-attack    
45835SERVER-ORACLE Oracle Application Test Suite server authentication bypass attempt (more info ...)attempted-admin 2016-0492 81158  URL
45836SERVER-ORACLE Oracle Application Test Suite server authentication bypass attempt (more info ...)attempted-admin 2016-0492 81158  URL
45853SERVER-OTHER Fatek Automation PLC WinProladder buffer overflow attempt (more info ...)attempted-user 2016-8377 94938  
45871PROTOCOL-SCADA IntegraXor 6x denial of service attempt (more info ...)attempted-dos    URL
45886SERVER-WEBAPP Potential Misfortune Cookie probe attempt (more info ...)attempted-admin 2014-9222 71744  
45892FILE-OTHER ZIP file directory traversal attempt (more info ...)attempted-user 2021-20022   URL
45893FILE-OTHER ZIP file directory traversal attempt (more info ...)attempted-user 2021-20022   URL
45894FILE-OTHER ZIP file directory traversal attempt (more info ...)attempted-user 2021-20022   URL
45895FILE-OTHER ZIP file directory traversal attempt (more info ...)attempted-user 2021-20022   URL
45909MALWARE-CNC CobaltStrike trial version inbound beacon response (more info ...)trojan-activity    URL
45910MALWARE-CNC Cobalt Strike outbound beacon command result (more info ...)trojan-activity    URL
45919EXPLOIT-KIT Sundown/Terror EK landing page attempt (more info ...)attempted-user    
45921EXPLOIT-KIT Terror EK resource access attempt (more info ...)attempted-user    
45929MALWARE-CNC Win.Trojan.Dridex initial file download (more info ...)trojan-activity    URL
45930MALWARE-CNC Win.Trojan.Dridex initial file download (more info ...)trojan-activity    URL
45931MALWARE-CNC Win.Trojan.Dridex initial file download (more info ...)trojan-activity    URL
45932MALWARE-CNC Win.Trojan.Dridex initial file download (more info ...)trojan-activity    URL
45933FILE-EXECUTABLE Binutils objdump integer overflow attempt (more info ...)denial-of-service 2018-6543   
45934FILE-EXECUTABLE Binutils objdump integer overflow attempt (more info ...)denial-of-service 2018-6543   
45942SERVER-OTHER Memcached DDoS reflective attempt (more info ...)attempted-dos 2018-1000115   URL
45943MALWARE-CNC known malicious SSL certificate - Odinaff C&C (more info ...)trojan-activity    URL
45944MALWARE-CNC known malicious SSL certificate - Odinaff C&C (more info ...)trojan-activity    URL
45945MALWARE-CNC Win.Trojan.DarkSky variant outbound connection (more info ...)trojan-activity    URL
45946MALWARE-CNC Win.Trojan.OilRig variant outbound connection attempt (more info ...)trojan-activity    URL
45947MALWARE-CNC Win.Trojan.OilRig variant outbound connection attempt (more info ...)trojan-activity    URL
45948MALWARE-CNC Win.Trojan.OilRig variant outbound connection attempt (more info ...)trojan-activity    URL
45959SERVER-WEBAPP ZEIT Next.js /_next namespace directory traversal attempt (more info ...)web-application-attack 2018-6184   URL
45960MALWARE-CNC Win.Trojan.Silverstar outbound connection (more info ...)trojan-activity    URL
45961MALWARE-CNC Win.Trojan.Revenge RAT initial outbound connection (more info ...)trojan-activity    URL
45962MALWARE-CNC Win.Trojan.Revenge RAT inbound heartbeat check (more info ...)trojan-activity    URL
45963MALWARE-CNC Win.Trojan.UDPOS outbound command and control IP address check (more info ...)trojan-activity    URL
45964MALWARE-CNC Win.Trojan.UDPOS outbound system information disclousre (more info ...)trojan-activity    URL
45966MALWARE-CNC Win.Trojan.UDPOS outbound heartbeat (more info ...)trojan-activity    URL
45967MALWARE-CNC Win.Trojan.UDPOS outbound data exfiltration (more info ...)trojan-activity    URL
45968MALWARE-CNC Win.Trojan.UDPOS outbound data exfiltration (more info ...)trojan-activity    URL
45969SERVER-WEBAPP SugarCRM cross site scripting attempt (more info ...)web-application-attack 2018-5715   
45970SERVER-WEBAPP SugarCRM cross site scripting attempt (more info ...)web-application-attack 2018-5715   
45972MALWARE-CNC Win.Trojan.Chafer malicious communication attempt (more info ...)trojan-activity    URL
45973MALWARE-CNC Win.Trojan.Chafer malicious communication attempt (more info ...)trojan-activity    URL
45979MALWARE-CNC MultiOS.Trojan.OSCelestial variant outbound connection (more info ...)trojan-activity    URL
45980MALWARE-CNC MultiOS.Trojan.OSCelestial variant inbound connection (more info ...)trojan-activity    URL
45983POLICY-OTHER Sandvine PacketLogic http redirection attempt (more info ...)misc-activity    URL
45995SERVER-WEBAPP CoreOS etcd service private keys listing attempt (more info ...)attempted-recon    URL
45996SERVER-WEBAPP CoreOS etcd service private keys listing attempt (more info ...)attempted-recon    URL
46023OS-OTHER FreeBSD sctp6_ctlinput null pointer dereference attempt (more info ...)attempted-dos 2016-1879   URL
46031SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100500 (more info ...)misc-activity    
46032SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100501 (more info ...)misc-activity    
46033SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100502 (more info ...)misc-activity    
46034SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100503 (more info ...)misc-activity    
46035SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100504 (more info ...)misc-activity    
46036SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100505 (more info ...)misc-activity    
46037SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100506 (more info ...)misc-activity    
46038SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100507 (more info ...)misc-activity    
46039SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100508 (more info ...)misc-activity    
46040SERVER-WEBAPP Dell EMC Storage Manager EmConfigMigration servlet directory traversal attempt (more info ...)web-application-attack 2017-14384 103467  URL
46047MALWARE-CNC Win.Trojan.Mobef variant outbound connection attempt (more info ...)attempted-user    URL
46048MALWARE-CNC Win.Trojan.Gen variant outbound communication (more info ...)trojan-activity    URL
46049MALWARE-CNC Win.Trojan.Fosniw variant connection attempt (more info ...)trojan-activity    URL
46050MALWARE-CNC Win.Trojan.CrossRAT outbound connection attempt (more info ...)trojan-activity    URL
46051MALWARE-CNC Win.Trojan.Bandook/Anbacas outbound connection attempt (more info ...)trojan-activity    URL
46052MALWARE-CNC User-Agent known malicious user-agent string Uploador - Win.Trojan.CrossRAT (more info ...)trojan-activity    URL
46065MALWARE-CNC Win.Ransomware.Sigma outbound connection (more info ...)trojan-activity    URL
46066MALWARE-CNC Win.Trojan.yty second stage downloader initial outbound connection (more info ...)trojan-activity    URL
46067MALWARE-CNC Win.Trojan.yty plugin downloader initial outbound connection (more info ...)trojan-activity    URL
46068MALWARE-CNC Win.Trojan.yty module download request (more info ...)trojan-activity    URL
46069MALWARE-CNC Win.Trojan.yty module request (more info ...)trojan-activity    URL
46070MALWARE-CNC Win.Trojan.yty file exfiltration outbound request (more info ...)trojan-activity    URL
46072FILE-OTHER Python lib wave.py wav zero channel denial of service attempt (more info ...)attempted-user 2017-18207   URL
46073FILE-OTHER Python lib wave.py wav zero channel denial of service attempt (more info ...)attempted-user 2017-18207   URL
46077FILE-IMAGE Gifsicle gifread double-free attempt (more info ...)attempted-user 2017-18120   
46078FILE-IMAGE Gifsicle gifread double-free attempt (more info ...)denial-of-service 2017-18120   
46090SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0549 attack attempt (more info ...)policy-violation 2018-3867   URL
46094FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0550 attack attempt (more info ...)attempted-user 2018-3868   URL
46098PROTOCOL-OTHER Routing Information Protocol version 1 potential amplified distributed denial of service attempt (more info ...)attempted-dos    URL
46099MALWARE-CNC Win.Trojan.Modimer Trojanized MediaGet outbound connection (more info ...)trojan-activity    URL
46112SERVER-WEBAPP Advantech WebAccess directory traversal attempt (more info ...)web-application-attack    URL
46113SERVER-WEBAPP Advantech WebAccess directory traversal attempt (more info ...)web-application-attack    URL
46114SERVER-WEBAPP Advantech WebAccess directory traversal attempt (more info ...)web-application-attack    URL
46129MALWARE-CNC Win.Trojan.HW32 variant outbound connection (more info ...)trojan-activity    URL
46134MALWARE-CNC Win.Trojan.Krodown variant connection attempt (more info ...)trojan-activity    URL
46135MALWARE-CNC Win.Trojan.Krodown variant connection attempt (more info ...)trojan-activity    URL
46136MALWARE-CNC Win.Trojan.Banbra variant outbound connection (more info ...)trojan-activity    
46137MALWARE-CNC Win.Trojan.Cidox variant outbound connection attempt (more info ...)trojan-activity    
46138MALWARE-CNC Win.Ransomware.Bandarchor variant outbound connection (more info ...)trojan-activity    URL
46139MALWARE-CNC Win.Ransomware.Bandarchor variant outbound connection (more info ...)trojan-activity    URL
46140MALWARE-CNC Win.Ransomware.Bandarchor variant outbound connection (more info ...)trojan-activity    URL
46141MALWARE-CNC Win.Ransomware.Bandarchor variant outbound connection (more info ...)trojan-activity    URL
46143FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0553 attack attempt (more info ...)attempted-user 2019-5051   URL
46144FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0553 attack attempt (more info ...)attempted-user 2019-5051   URL
46145FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0553 attack attempt (more info ...)attempted-user 2019-5051   URL
46146FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0553 attack attempt (more info ...)attempted-user 2019-5051   URL
46147FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0552 attack attempt (more info ...)attempted-user 2018-3870   URL
46148FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0552 attack attempt (more info ...)attempted-user 2018-3870   URL
46156MALWARE-CNC Coldroot RAT outbound connection (more info ...)trojan-activity    URL
46190SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0567 attack attempt (more info ...)misc-activity    
46191SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0567 attack attempt (more info ...)attempted-admin 2018-3892   URL
46202MALWARE-CNC Win.Downloader.Wannaminer malicious Powershell download attempt (more info ...)trojan-activity    URL
46203MALWARE-CNC Win.Downloader.Wannamine malicious Powershell download attempt (more info ...)trojan-activity    URL
46210MALWARE-CNC Win.Trojan.Blackshades variant outbound communication (more info ...)trojan-activity    URL
46217POLICY-OTHER TRUFFLEHUNTER TALOS-2018-0557 attack attempt (more info ...)policy-violation 2018-3880   URL
46235MALWARE-CNC Dofoil outbound connection attempt (more info ...)trojan-activity    URL
46236MALWARE-CNC Dofoil file download attempt (more info ...)trojan-activity    URL
46238MALWARE-CNC Win.Trojan.Rarog outbound communication attempt (more info ...)trojan-activity    
46239MALWARE-CNC Win.Trojan.Rarog outbound communication attempt (more info ...)trojan-activity    
46240MALWARE-CNC Win.Trojan.Rarog user-agent outbound communication attempt (more info ...)trojan-activity    
46249MALWARE-CNC Win.Trojan.Rovnix outbound connection attempt (more info ...)trojan-activity    URL
46250MALWARE-CNC Win.Trojan.Rovnix outbound connection attempt (more info ...)trojan-activity    URL
46251MALWARE-CNC Win.Trojan.Rovnix outbound connection attempt (more info ...)trojan-activity    URL
46252MALWARE-CNC Win.Trojan.Rovnix outbound connection attempt (more info ...)trojan-activity    URL
46253MALWARE-CNC Win.Trojan.Rovnix file upload attempt (more info ...)trojan-activity    URL
46268MALWARE-CNC Win.Downloader.Agent variant payload download attempt (more info ...)trojan-activity    URL
46270MALWARE-CNC Win.Downloader.Agent variant payload download attempt (more info ...)trojan-activity    URL
46284MALWARE-CNC Win.Trojan.Bandios user agent outbound communication attempt (more info ...)trojan-activity    URL
46285MALWARE-CNC Win.Trojan.Bandios inbound delivery attempt (more info ...)trojan-activity    URL
46286MALWARE-CNC Win.Trojan.Bandios inbound delivery attempt (more info ...)trojan-activity    URL
46287SERVER-WEBAPP Linksys E series denial of service attempt (more info ...)denial-of-service    
46294SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0572 attack attempt (more info ...)misc-activity    
46295SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0572 attack attempt (more info ...)attempted-admin 2018-3900   URL
46297SERVER-WEBAPP QNAP VioStor NVR and QNAP NAS command injection attempt (more info ...)web-application-attack 2013-0143   
46298SERVER-WEBAPP QNAP VioStor NVR and QNAP NAS command injection attempt (more info ...)web-application-attack 2013-0143   
46299SERVER-WEBAPP QNAP VioStor NVR and QNAP NAS command injection attempt (more info ...)web-application-attack 2013-0143   
46300SERVER-WEBAPP QNAP VioStor NVR and QNAP NAS command injection attempt (more info ...)web-application-attack 2013-0143   
46312SERVER-WEBAPP Netgear WNR2000 information disclosure attempt (more info ...)attempted-recon    URL
46313SERVER-WEBAPP Netgear WNR2000 information disclosure attempt (more info ...)attempted-recon    URL
46314SERVER-WEBAPP Netgear WNR2000 information disclosure attempt (more info ...)attempted-recon    URL
46317SERVER-OTHER NETGEAR TelnetEnable attempt (more info ...)attempted-admin    
46318SERVER-OTHER NETGEAR TelnetEnable attempt (more info ...)attempted-admin    
46320POLICY-OTHER TRUFFLEHUNTER TALOS-2018-0576 attack attempt (more info ...)policy-violation 2018-3906   URL
46335SERVER-OTHER QNAP QTS hard coded credential access attempt (more info ...)default-login-attempt 2015-7261   
46339MALWARE-CNC Win.Ransomware.Matrix outbound connection (more info ...)trojan-activity    URL
46341SERVER-WEBAPP Akeeba Kickstart cross site request forgery attempt (more info ...)web-application-attack 2014-7229   
46342SERVER-OTHER QNAP QTS cross site request forgery attempt (more info ...)attempted-admin 2013-0144   
46344SERVER-WEBAPP ManageEngine ServiceDesk directory traversal attempt (more info ...)web-application-attack 2017-11512   
46345SERVER-WEBAPP ManageEngine ServiceDesk directory traversal attempt (more info ...)web-application-attack 2017-11512   
46346SERVER-WEBAPP ManageEngine ServiceDesk directory traversal attempt (more info ...)web-application-attack 2017-11512   
46353SERVER-WEBAPP ManageEngine ServiceDesk download-file directory traversal attempt (more info ...)web-application-attack 2017-11511   
46354SERVER-WEBAPP ManageEngine ServiceDesk download-file directory traversal attempt (more info ...)web-application-attack 2017-11511   
46355SERVER-WEBAPP ManageEngine ServiceDesk download-file directory traversal attempt (more info ...)web-application-attack 2017-11511   
46356MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46357MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46358MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46359MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46360MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46361MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46362MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46363MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46364MALWARE-CNC Andr.Trojan.Wroba outbound connection (more info ...)trojan-activity    URL
46373PROTOCOL-OTHER CLDAP potential reflected distributed denial of service attempt (more info ...)attempted-dos    URL
46374PROTOCOL-OTHER CLDAP potential reflected distributed denial of service attempt (more info ...)attempted-dos    URL
46375SERVER-OTHER DualDesk v20 Proxy.exe long string denial of service attempt (more info ...)attempted-dos 2018-7583   
46376SERVER-OTHER libgd heap-overflow attempt (more info ...)web-application-attack 2016-3074   
46378MALWARE-CNC Win.Trojan.Dropper variant outbound connection (more info ...)trojan-activity    URL
46381INDICATOR-COMPROMISE Potential data exfiltration through Google form submission (more info ...)misc-activity    URL
46387SERVER-OTHER Multiple Vendors NTP zero-origin timestamp denial of service attempt (more info ...)attempted-dos 2018-7185   URL
46390SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0577 attack attempt (more info ...)web-application-attack 2018-3909   URL
46391SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0577 attack attempt (more info ...)web-application-attack 2018-3909   URL
46392SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0577 attack attempt (more info ...)web-application-attack 2018-3909   URL
46395SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0578 attack attempt (more info ...)web-application-attack 2018-3918   URL
46406MALWARE-CNC Bitvote miner kernel driver outbound request attempt (more info ...)trojan-activity    URL
46407MALWARE-CNC Bitvote miner kernel driver payload download attempt (more info ...)trojan-activity    URL
46408SERVER-WEBAPP Moodle PoodLL Filter plugin cross site scripting attempt (more info ...)web-application-attack 2017-5945 96212  
46416MALWARE-CNC Win.Spyware.Autoit outbound connection (more info ...)trojan-activity    URL
46417SERVER-OTHER X.509 IPAddressFamily extension buffer overread attempt (more info ...)attempted-recon 2017-3735   
46418SERVER-OTHER X.509 IPAddressFamily extension buffer overread attempt (more info ...)attempted-recon 2017-3735   
46421MALWARE-CNC Win.Trojan.Kraens delivery attempt (more info ...)trojan-activity    URL
46422MALWARE-CNC Win.Trojan.Kraens delivery attempt (more info ...)trojan-activity    URL
46423MALWARE-CNC Win.Trojan.Kraens initial outbound request (more info ...)trojan-activity    URL
46433MALWARE-CNC Win.Adware.Doyo initial connection (more info ...)trojan-activity    URL
46434MALWARE-CNC Win.Adware.Doyo client outbound connection (more info ...)trojan-activity    URL
46435MALWARE-CNC Vbs.Downloader.Kryptik known malicious user-agent string (more info ...)trojan-activity    URL
46436MALWARE-CNC Vbs.Downloader.Agent inbound connection (more info ...)trojan-activity    URL
46437MALWARE-CNC Vbs.Downloader.Agent inbound connection (more info ...)trojan-activity    URL
46438MALWARE-CNC Vbs.Downloader.Agent inbound connection (more info ...)trojan-activity    URL
46439MALWARE-CNC Vbs.Downloader.Agent inbound delivery attempt (more info ...)trojan-activity    URL
46443BROWSER-OTHER HTTP encoding header evasion attempt (more info ...)policy-violation    
46444BROWSER-OTHER HTTP encoding header evasion attempt (more info ...)policy-violation    
46447POLICY-OTHER TP-Link device reboot attempt (more info ...)misc-activity    URL
46448POLICY-OTHER TP-Link device enable remote management attempt (more info ...)misc-activity    URL
46450SERVER-WEBAPP Elasticsearch snapshot directory traversal attempt (more info ...)web-application-attack 2015-5531 75935  
46454SERVER-WEBAPP Node.js zlib createDeflateRaw denial of service attempt (more info ...)denial-of-service 2017-14919   
46475MALWARE-CNC Win.Trojan.SquirtDanger get module list outbound request (more info ...)trojan-activity    URL
46476MALWARE-CNC Win.Trojan.SquirtDanger inbound delivery attempt (more info ...)trojan-activity    URL
46477MALWARE-CNC Win.Trojan.SquirtDanger inbound delivery attempt (more info ...)trojan-activity    URL
46478MALWARE-CNC Win.Trojan.SquirtDanger inbound delivery attempt (more info ...)trojan-activity    URL
46479MALWARE-CNC Win.Trojan.SquirtDanger inbound delivery attempt (more info ...)trojan-activity    URL
46482MALWARE-CNC Installation Keylogger Osx.Trojan.Mokes data exfiltration (more info ...)trojan-activity    URL
46485SERVER-WEBAPP TwonkyMedia server directory listing attempt (more info ...)web-application-attack 2018-7171   
46487MALWARE-CNC Win.Trojan.Ammy heartbeat (more info ...)trojan-activity    
46488MALWARE-CNC Win.Trojan.Ammy download attempt (more info ...)trojan-activity    
46495SERVER-OTHER HTTP request smuggling attempt (more info ...)web-application-activity 2015-3183   
46500POLICY-OTHER Docker API ContainerCreate request detected (more info ...)policy-violation 2018-0262   URL
46501MALWARE-CNC Win.Trojan.Agent outbound request (more info ...)trojan-activity    URL
46502MALWARE-CNC Win.Trojan.Agent outbound request (more info ...)trojan-activity    URL
46518SERVER-WEBAPP Belkin N750 F9K1103 wireless router remote telnet enable attempt (more info ...)policy-violation 2018-1146   
46519SERVER-WEBAPP Belkin N750 F9K1103 wireless router remote telnet enable attempt (more info ...)policy-violation 2018-1146   
46523SERVER-OTHER malicious HTML file transfer attempt (more info ...)misc-activity    
46533SERVER-WEBAPP DHCP cross site scripting attempt (more info ...)attempted-user 2014-0615   
46543SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0591 attack attempt (more info ...)attempted-admin 2018-3925   URL
46566SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100510 (more info ...)misc-activity    
46568SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100512 (more info ...)misc-activity    
46570SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100514 (more info ...)misc-activity    
46572SERVER-OTHER TRUFFLEHUNTER SFVRT-1009 attack attempt 100516 (more info ...)misc-activity    
46574MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46575MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46576MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46577MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46578MALWARE-CNC Win.Trojan.Banload malicious system information disclosure (more info ...)trojan-activity    URL
46579MALWARE-CNC Win.Trojan.Banload malicious system information disclosure (more info ...)trojan-activity    URL
46580MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46581MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46582MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46583MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46584MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46585MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46586MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46587MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46588MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46589MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46590MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46591MALWARE-CNC Win.Trojan.Banload malicious file download (more info ...)trojan-activity    URL
46608MALWARE-CNC Win.Trojan.Blackshades variant outbound communication (more info ...)trojan-activity    URL
46609MALWARE-CNC Win.Trojan.BlackIce variant outbound connection (more info ...)trojan-activity    URL
46611MALWARE-CNC Win.Trojan.Banload second stage download request (more info ...)trojan-activity    
46612MALWARE-CNC Win.Trojan.Unruy outbound callout (more info ...)trojan-activity    
46628MALWARE-CNC Rubella Macro Builder generated payload (more info ...)trojan-activity    URL
46629MALWARE-CNC Rubella Macro Builder generated payload (more info ...)trojan-activity    URL
46630MALWARE-CNC Rubella Macro Builder generated payload (more info ...)trojan-activity    URL
46631MALWARE-CNC Rubella Macro Builder generated payload (more info ...)trojan-activity    URL
46636MALWARE-CNC Win.Ransomware.Gandcrab variant outbound connection (more info ...)trojan-activity    URL
46640INDICATOR-COMPROMISE Win.Worm.Brontok outbound HTTP request attempt (more info ...)trojan-activity    URL
46641INDICATOR-COMPROMISE Win.Worm.Brontok outbound HTTP request attempt (more info ...)trojan-activity    URL
46642MALWARE-CNC Win.Worm.Brontok user-agent outbound connection (more info ...)trojan-activity    URL
46661POLICY-OTHER TRUFFLEHUNTER TALOS-2018-0594 attack attempt (more info ...)policy-violation 2018-3927   URL
46663INDICATOR-COMPROMISE Outbound telize.com geo-IP location connection attempt (more info ...)trojan-activity    URL
46664INDICATOR-COMPROMISE Outbound freegeoip.net geo-IP location connection attempt (more info ...)trojan-activity    URL
46679INDICATOR-COMPROMISE Request for external IP address detected (more info ...)trojan-activity    
46700MALWARE-CNC Osx.Downloader.Crossrider outbound download request (more info ...)trojan-activity    URL
46742MALWARE-CNC Win.Trojan.Dropper malicious script download attempt (more info ...)trojan-activity    URL
46743MALWARE-CNC Win.Trojan.Dropper initial outbound connection attempt (more info ...)trojan-activity    URL
46744MALWARE-CNC Win.Trojan.Dropper malicious executable download attempt (more info ...)trojan-activity    URL
46747MALWARE-CNC Win.Trojan.Qarallax outbound connection (more info ...)trojan-activity    URL
46748MALWARE-CNC Win.Trojan.Qarallax outbound connection (more info ...)trojan-activity    URL
46779SERVER-WEBAPP Nagios XI database settings modification attempt (more info ...)web-application-attack 2018-8734   
46780SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0595 attack attempt (more info ...)attempted-dos 2018-3928   URL
46785MALWARE-CNC Win.Downloader.Zebrocy known malicious user-agent string (more info ...)trojan-activity    URL
46786MALWARE-CNC Win.Downloader.Zebrocy initial outbound request (more info ...)trojan-activity    URL
46787MALWARE-CNC Andr.Trojan.ZooPark outbound connection attempt (more info ...)trojan-activity    URL
46788MALWARE-CNC Andr.Trojan.ZooPark outbound connection attempt (more info ...)trojan-activity    URL
46789MALWARE-CNC Andr.Trojan.ZooPark outbound connection attempt (more info ...)trojan-activity    URL
46790MALWARE-CNC Andr.Trojan.ZooPark outbound connection attempt (more info ...)trojan-activity    URL
46792MALWARE-CNC Outbound malicious vbscript attempt (more info ...)attempted-user    
46795MALWARE-CNC Dharma ransomware dropper initial outbound connection (more info ...)trojan-activity    URL
46796MALWARE-CNC Dharma ransomware dropper outbound connection (more info ...)trojan-activity    URL
46818MALWARE-CNC Win.Ransomware.Satan outbound connection (more info ...)trojan-activity    URL
46820MALWARE-CNC Win.Downloader.QuantLoader variant outbound connection attempt (more info ...)trojan-activity    URL
46821MALWARE-CNC Win.Trojan.N40 variant outbound connection (more info ...)trojan-activity    URL
46824SERVER-WEBAPP DotNetNuke DreamSlider arbitrary file download attempt (more info ...)web-application-attack    
46827MALWARE-CNC Win.Trojan.Dunihi outbound connection (more info ...)trojan-activity    URL
46836MALWARE-CNC Win.Dropper.Vega variant outbound connection detected (more info ...)trojan-activity    URL
46837MALWARE-CNC Win.Dropper.Vega variant outbound connection detected (more info ...)trojan-activity    URL
46838MALWARE-CNC Win.Trojan.Vega variant outbound connection detected (more info ...)trojan-activity    URL
46839MALWARE-CNC Win.Trojan.RedLeaves variant outbound connection (more info ...)trojan-activity    URL
46842MALWARE-CNC GPON botnet outbound communication (more info ...)trojan-activity 2018-10561   URL
46853MALWARE-CNC TRUFFLEHUNTER SFVRT-1036 attack attempt (more info ...)trojan-activity    
46870SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0602 attack attempt (more info ...)attempted-dos 2018-3935   URL
46871MALWARE-CNC Win.Dropper.NavRat payload download (more info ...)trojan-activity    URL
46872MALWARE-CNC Win.Trojan.CowerSnail command and control response detected (more info ...)trojan-activity    URL
46873MALWARE-CNC Win.Trojan.CowerSnail initial outbound connection attempt (more info ...)trojan-activity    URL
46878SERVER-OTHER BMC Server Automation RSCD Agent remote code execution attempt (more info ...)attempted-user 2016-1543   
46879SERVER-OTHER BMC Server Automation RSCD Agent remote code execution attempt (more info ...)attempted-user 2016-1543   URL
46880SERVER-OTHER BMC Server Automation RSCD Agent remote code execution attempt (more info ...)attempted-user 2016-1543   
46881SERVER-WEBAPP Elasticsearch directory traversal attempt (more info ...)web-application-attack 2015-3337   
46885MALWARE-CNC Win.Trojan.Joanap variant outbound connection (more info ...)trojan-activity    URL
46894MALWARE-CNC Vbs.Worm.SysinfY2X outbound beacon (more info ...)trojan-activity    URL
46895MALWARE-CNC Win.Trojan.Nocturnal outbound connection (more info ...)trojan-activity    URL
46896SERVER-WEBAPP Joomla component GeoContent typename parameter cross site scripting attempt (more info ...)attempted-user    
46900BROWSER-OTHER invalid final chunk size evasion attempt (more info ...)misc-activity    
46901BROWSER-OTHER http chunked transfer encoding flowbit attempt (more info ...)misc-activity    
46902BROWSER-OTHER invalid final chunk size evasion attempt (more info ...)misc-activity    
46915FILE-MULTIMEDIA VideoLAN VLC Media Player abc file parts heap integer overflow attempt (more info ...)attempted-user 2013-4233   
46916FILE-MULTIMEDIA VideoLAN VLC Media Player abc file parts heap integer overflow attempt (more info ...)attempted-user 2013-4233   
46922MALWARE-CNC Win.Trojan.Fareit variant outbound connection (more info ...)trojan-activity    URL
46936MALWARE-CNC Win.Trojan.Dropper outbound connection (more info ...)trojan-activity    URL
46946MALWARE-CNC Js.Downloader.Cryptojacking miner download attempt (more info ...)trojan-activity    URL
46959MALWARE-CNC Win.Trojan.DarkSeoul variant payload download (more info ...)trojan-activity    URL
46963MALWARE-CNC Win.Adware.Taplika toolbar download attempt (more info ...)trojan-activity    URL
46964MALWARE-CNC Win.Trojan.Ammyy RAT outbound connection (more info ...)trojan-activity    URL
46966MALWARE-CNC Win.Trojan.Danabot outbound connection (more info ...)trojan-activity    URL
46967MALWARE-CNC Win.Trojan.Danabot outbound connection (more info ...)trojan-activity    URL
46968MALWARE-CNC Win.Trojan.Danabot outbound connection (more info ...)trojan-activity    URL
46969MALWARE-CNC Win.Trojan.Autophyte dropper variant outbound connection (more info ...)trojan-activity    URL
46970MALWARE-CNC Win.Trojan.Autophyte RAT variant outbound connection (more info ...)trojan-activity    URL
46981MALWARE-CNC Win.Trojan.Orcus RAT inbound SSL certificate (more info ...)trojan-activity    URL
46984MALWARE-CNC Win.Trojan.Yoban RAT outbound connection (more info ...)trojan-activity    URL
46985MALWARE-CNC Win.Trojan.Yoban RAT outbound connection (more info ...)trojan-activity    URL
47005MALWARE-CNC Win.Trojan.SocketPlayer outbound connection (more info ...)trojan-activity    URL
47006MALWARE-CNC Win.Trojan.SocketPlayer outbound connection (more info ...)trojan-activity    URL
47007SERVER-WEBAPP Spring Web Flow arbitrary code exeuction attempt (more info ...)attempted-user 2017-4971   
47016MALWARE-CNC Win.Spyware.Invisimole CnC outbound connection (more info ...)trojan-activity    URL
47024INDICATOR-COMPROMISE Request for external IP address detected (more info ...)policy-violation    URL
47025MALWARE-CNC Win.Trojan.Syndicasec variant outbound connection (more info ...)trojan-activity    URL
47026MALWARE-CNC Win.Trojan.Agent variant outbound connection detected (more info ...)trojan-activity    
47027MALWARE-CNC Win.Trojan.Agent variant outbound connection detected (more info ...)trojan-activity    
47030MALWARE-CNC Win.Malware.Innaput variant outbound connection (more info ...)trojan-activity    URL
47034EXPLOIT-KIT Sundown/Terror/Grandsoft/Magnitude exploit kit landing page detected (more info ...)attempted-user    
47035POLICY-OTHER TRUFFLEHUNTER TALOS-2018-0622 attack attempt (more info ...)policy-violation 2018-4010   URL
47036POLICY-OTHER TRUFFLEHUNTER TALOS-2018-0622 attack attempt (more info ...)policy-violation 2018-4010   URL
47038SERVER-WEBAPP TheWebForum cross site scripting attempt (more info ...)attempted-user 2006-0134 16161  
47043INDICATOR-COMPROMISE Atvise SCADA user enumeration attempt (more info ...)attempted-recon    URL
47044INDICATOR-COMPROMISE Atvise SCADA privilege escalation attempt (more info ...)attempted-admin    URL
47047FILE-OTHER FreeBSD bspatch utility remote code execution attempt (more info ...)attempted-user 2014-9862   
47048FILE-OTHER FreeBSD bspatch utility remote code execution attempt (more info ...)attempted-user 2014-9862   
47051MALWARE-CNC Win.Trojan.ICLoader outbound connection (more info ...)trojan-activity    URL
47067MALWARE-CNC Win.Trojan.TechSupportScam installed binary outbound connection (more info ...)trojan-activity    URL
47068MALWARE-CNC Win.Trojan.TechSupportScam installed binary outbound connection (more info ...)trojan-activity    URL
47069MALWARE-CNC Win.Trojan.TechSupportScam installed binary outbound connection (more info ...)trojan-activity    URL
47070POLICY-OTHER Arris VAP2500 default credentials authentication attempt (more info ...)policy-violation    URL
47073MALWARE-CNC Win.Trojan.Smokeloader outbound response (more info ...)trojan-activity    URL
47076MALWARE-CNC Powershell PRB backdoor initial outbound communication attempt (more info ...)trojan-activity    URL
47086MALWARE-CNC Win.Trojan.TYPEFRAME malware download attempt (more info ...)trojan-activity    URL
47087MALWARE-CNC Win.Trojan.TYPEFRAME malware download attempt (more info ...)trojan-activity    URL
47088MALWARE-CNC Win.Trojan.TYPEFRAME malware download attempt (more info ...)trojan-activity    URL
47089MALWARE-CNC Win.Trojan.TYPEFRAME malware download attempt (more info ...)trojan-activity    URL
47090MALWARE-CNC Win.Trojan.TYPEFRAME malware download attempt (more info ...)trojan-activity    URL
47093PUA-ADWARE Win.Adware.Pbot variant outbound connection (more info ...)misc-activity    URL
47094PUA-ADWARE Win.Adware.Pbot variant outbound connection (more info ...)misc-activity    URL
47095PUA-ADWARE Win.Adware.Pbot variant outbound connection (more info ...)misc-activity    URL
47115SERVER-MAIL Zerofont phishing attempt (more info ...)attempted-user    URL
47116SERVER-MAIL Zerofont phishing attempt (more info ...)attempted-user    URL
47143FILE-OTHER Multiple Products SGI ZSIZE handling buffer overflow attempt (more info ...)attempted-user 2019-7124 19507  URL
47144FILE-OTHER Multiple Products SGI ZSIZE handling buffer overflow attempt (more info ...)attempted-user 2019-7124 19507  URL
47146POLICY-OTHER Siemens SICAM PAS hard coded factory account usage attempt (more info ...)attempted-user 2016-8567   
47147MALWARE-CNC Win.Trojan.Ursnif malicious file download (more info ...)trojan-activity    URL
47148MALWARE-CNC Win.Trojan.Ursnif malicious file download (more info ...)trojan-activity    URL
47177MALWARE-CNC Win.Trojan.NukeSped RAT variant outbound communication (more info ...)trojan-activity    URL
47178MALWARE-CNC Win.Trojan.NukeSped RAT variant outbound connection (more info ...)trojan-activity    URL
47229SERVER-WEBAPP Oracle PeopleSoft information disclosure attempt (more info ...)attempted-user 2017-3548   
47235MALWARE-CNC Win.Trojan.Bankshot variant outbound connection (more info ...)trojan-activity    URL
47241MALWARE-CNC Win.Trojan.Mylobot additional payload download (more info ...)trojan-activity    URL
47242MALWARE-CNC Win.Trojan.Mylobot additional payload download (more info ...)trojan-activity    URL
47243MALWARE-CNC Win.Trojan.Mylobot inbound connection (more info ...)trojan-activity    URL
47244MALWARE-CNC Win.Malware.Ramnit outbound REGISTER_BOT beacon (more info ...)trojan-activity    URL
47264MALWARE-CNC Win.Trojan.ICLoader outbound connection (more info ...)trojan-activity    URL
47265MALWARE-CNC Win.Trojan.ICLoader outbound connection (more info ...)trojan-activity    URL
47295FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2018-0635 attack attempt (more info ...)attempted-recon 2018-3970   URL
47296FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2018-0635 attack attempt (more info ...)attempted-recon 2018-3970   URL
47299MALWARE-CNC Win.Trojan.Remcos variant outbound connection (more info ...)trojan-activity    URL
47300MALWARE-CNC Win.Trojan.Remcos variant inbound payload download (more info ...)trojan-activity    URL
47301MALWARE-CNC Win.Trojan.Remcos variant outbound connection (more info ...)trojan-activity    URL
47302MALWARE-CNC Win.Trojan.Remcos variant outbound connection (more info ...)trojan-activity    URL
47303MALWARE-CNC Win.Trojan.Remcos variant outbound connection (more info ...)trojan-activity    URL
47304MALWARE-CNC Win.Trojan.Remcos variant outbound connection (more info ...)trojan-activity    URL
47305MALWARE-CNC Win.Trojan.Remcos variant outbound connection (more info ...)trojan-activity    URL
47320MALWARE-CNC Js.Trojan.Agent JS Sniffer beacon connection (more info ...)trojan-activity    
47321MALWARE-CNC Js.Trojan.Agent JS Sniffer outbound connection (more info ...)trojan-activity    
47322MALWARE-CNC Js.Trojan.Agent JS Sniffer outbound connection (more info ...)trojan-activity    
47323MALWARE-CNC Js.Trojan.Agent JS Sniffer outbound connection (more info ...)trojan-activity    
47324MALWARE-CNC Js.Trojan.Agent JS Sniffer compromised website (more info ...)trojan-activity    
47325MALWARE-CNC Js.Trojan.Agent JS Sniffer compromised website (more info ...)trojan-activity    
47327MALWARE-CNC Win.Trojan.Luoxk malicious payload download attempt (more info ...)trojan-activity    URL
47338MALWARE-CNC Win.Trojan.ARS VBS loader outbound connection (more info ...)trojan-activity    URL
47339MALWARE-CNC Win.Trojan.AZORult variant outbound connection (more info ...)trojan-activity    URL
47373MALWARE-CNC Win.Coinminer.PyroMineIoT outbound connection (more info ...)trojan-activity    URL
47374MALWARE-CNC Win.Coinminer.PyroMineIoT outbound connection (more info ...)trojan-activity    URL
47375MALWARE-CNC Win.Coinminer.PyroMineIoT outbound connection (more info ...)trojan-activity    URL
47376MALWARE-CNC Win.Coinminer.PyroMineIoT outbound connection (more info ...)trojan-activity    URL
47386SERVER-WEBAPP Oracle WebLogic Server unauthenticated modified JSP access attempt (more info ...)attempted-recon 2018-2894 104763  URL
47387SERVER-WEBAPP Oracle WebLogic Server potential unauthenticated reconnaissance attempt (more info ...)attempted-recon 2018-2894 104763  URL
47388SERVER-WEBAPP Oracle WebLogic Server potential precursor to keystore attack attempt (more info ...)attempted-recon 2018-2894 104763  URL
47414MALWARE-CNC Osx.Trojan.Calisto outbound connection (more info ...)trojan-activity    URL
47415MALWARE-CNC Osx.Trojan.Calisto outbound connection (more info ...)trojan-activity    URL
47419SERVER-WEBAPP Easy Hosting Control Panel cross site scripting attempt (more info ...)attempted-user 2018-6361   
47420MALWARE-CNC Win.Trojan.Kuping variant outbound connection (more info ...)trojan-activity    URL
47421SERVER-WEBAPP Joomla Core com_fields cross site scripting attempt (more info ...)attempted-user 2018-6377   
47422FILE-OTHER SAP GUI ABAP code arbitrary dll-load attempt (more info ...)attempted-user 2017-6950   URL
47425SERVER-WEBAPP Raptr Plays.tv unauthenticated remote arbitrary file execution attempt (more info ...)attempted-admin 2018-6546   
47427MALWARE-CNC Win.Trojan.Mapoyun variant outbound connection attempt (more info ...)trojan-activity    URL
47430FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0644 attack attempt (more info ...)attempted-recon    URL
47431FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0644 attack attempt (more info ...)attempted-recon    URL
47432FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0644 attack attempt (more info ...)attempted-recon    URL
47433FILE-IMAGE TRUFFLEHUNTER TALOS-2018-0644 attack attempt (more info ...)attempted-recon    URL
47434MALWARE-CNC Win.Coinminer.HiddenShock variant outbound connection (more info ...)trojan-activity    URL
47435MALWARE-CNC Win.Dropper.IcedID payload download (more info ...)trojan-activity    URL
47436MALWARE-CNC Win.Dropper.IcedID outbound connection (more info ...)trojan-activity    URL
47442BROWSER-OTHER TRUFFLEHUNTER TALOS-2018-0647 attack attempt (more info ...)attempted-dos 2018-3979   URL
47443BROWSER-OTHER TRUFFLEHUNTER TALOS-2018-0647 attack attempt (more info ...)attempted-dos 2018-3979   URL
47444MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47445MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47446MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47447MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47448MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47449MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47450MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47451MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47452MALWARE-CNC Win.Trojan.Gorgon outbound connection (more info ...)trojan-activity    URL
47471SERVER-WEBAPP Advantech WebAccess gmicons.asp picfile arbitrary file upload attempt (more info ...)attempted-admin 2017-16736   URL
47472SERVER-WEBAPP Advantech WebAccess gmicons.asp directory traversal attempt (more info ...)web-application-attack 2017-16736   URL
47473SERVER-WEBAPP Kodi playlist creation persistent cross site scripting attempt (more info ...)attempted-user 2018-8831   
47494SERVER-WEBAPP Easy File Sharing stack buffer overflow attempt (more info ...)attempted-user 2018-9059   
47505MALWARE-CNC Py.Malware.EvilOSX 404 Error Page Payload/Command Delivery (more info ...)trojan-activity    URL
47511MALWARE-CNC Win32.Backdoor.Ropindo variant outbound post detected (more info ...)trojan-activity    URL
47525MALWARE-CNC Win.Trojan.Grobios outbound connection (more info ...)trojan-activity    URL
47526MALWARE-CNC Win.Trojan.Grobios C2 inbound server command (more info ...)trojan-activity    URL
47541SERVER-MAIL EHLO user overflow attempt (more info ...)attempted-admin 2018-6789 13772  
47546MALWARE-CNC Win.Trojan.Keywsec variant outbound request detected (more info ...)trojan-activity    URL
47547MALWARE-CNC Win.Trojan.Keywsec variant post-compromise outbound request detected (more info ...)trojan-activity    URL
47548MALWARE-CNC Win.Trojan.Keywsec variant outbound request for malicious dll exe and js detected (more info ...)trojan-activity    URL
47549SERVER-WEBAPP Easy Hosting Control Panel action cross site scripting attempt (more info ...)attempted-user 2018-6362   
47557MALWARE-CNC Win.Trojan.PLEAD downloader outbound connection (more info ...)trojan-activity    URL
47567MALWARE-CNC Win.Trojan.Zegost variant outbound connection (more info ...)trojan-activity    URL
47578SERVER-WEBAPP NetGain Systems Enterprise Manager directory traversal attempt (more info ...)web-application-attack 2017-16603   
47581SERVER-WEBAPP GitStack unauthenticated REST API add user attempt (more info ...)policy-violation 2018-5955   
47582SERVER-WEBAPP GitStack unauthenticated REST API repository modification attempt (more info ...)policy-violation 2018-5955   
47583SERVER-WEBAPP GitStack unauthenticated REST API repository modification attempt (more info ...)policy-violation 2018-5955   
47584SERVER-WEBAPP Dolibarr Carte cross site scripting attempt (more info ...)attempted-user 2018-10095   
47585SERVER-OTHER ntpq decode array buffer overflow attempt (more info ...)attempted-user 2018-7183   URL
47586FILE-OTHER Info-ZIP UnZip heap buffer overflow attempt (more info ...)attempted-user 2018-1000035   
47587FILE-OTHER Info-ZIP UnZip heap buffer overflow attempt (more info ...)attempted-user 2018-1000035   
47588SERVER-WEBAPP Subsonic Subscribe to Podcast cross site scripting attempt (more info ...)attempted-user 2017-9414   
47589SERVER-WEBAPP Subsonic Subscribe to Podcast cross site scripting attempt (more info ...)attempted-user 2017-9414   
47590SERVER-WEBAPP Subsonic Subscribe to Podcast cross site scripting attempt (more info ...)attempted-user 2017-9414   
47593MALWARE-CNC Fake PDFEscape font pack cryptominer (more info ...)trojan-activity    
47594MALWARE-CNC Fake PDFEscape font pack cryptominer (more info ...)trojan-activity    
47600MALWARE-CNC Win.Trojan.Waldek variant initial outbound connection detected (more info ...)trojan-activity    
47601MALWARE-CNC Win.Trojan.Betabot variant outbound connection detected (more info ...)trojan-activity    URL
47602MALWARE-CNC Win.Trojan.AzoRult variant outbound connection detected (more info ...)trojan-activity    URL
47607SERVER-WEBAPP Advantech WebAccess Dashboard Viewer arbitrary file upload attempt (more info ...)web-application-attack    URL
47608SERVER-WEBAPP Advantech WebAccess Dashboard Viewer arbitrary file upload attempt (more info ...)web-application-attack    URL
47609SERVER-WEBAPP Advantech WebAccess Dashboard Viewer arbitrary file upload attempt (more info ...)web-application-attack    URL
47610SERVER-WEBAPP Advantech WebAccess Dashboard Viewer arbitrary file upload attempt (more info ...)web-application-attack    URL
47611FILE-OTHER Easy MPEG to DVD Burner buffer overflow attempt (more info ...)attempted-user    
47612FILE-OTHER Easy MPEG to DVD Burner buffer overflow attempt (more info ...)attempted-user    
47616MALWARE-CNC Win.Trojan.Emotet variant download (more info ...)trojan-activity    URL
47617MALWARE-CNC Win.Trojan.Emotet variant download (more info ...)trojan-activity    URL
47618MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
47619SERVER-WEBAPP Symfony HttpFoundation component potential security bypass attempt (more info ...)web-application-attack 2018-14773   URL
47620SERVER-WEBAPP Symfony HttpFoundation component potential security bypass attempt (more info ...)web-application-attack 2018-14773   URL
47621MALWARE-CNC Win.Ransomware.Princess variant outbound connection attempt (more info ...)trojan-activity    URL
47627MALWARE-CNC Win.Trojan.KeyPass variant inbound connection attempt (more info ...)trojan-activity    URL
47633POLICY-OTHER Accelerite Endpoint Management default credentials login attempt (more info ...)policy-violation    URL
47650MALWARE-CNC Win.Trojan.Marap outbound beacon detected (more info ...)trojan-activity    URL
47662SERVER-WEBAPP Cogent DataHub ASP script injection attempt (more info ...)attempted-admin    
47663SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0653 attack attempt (more info ...)attempted-admin 2018-3985   URL
47670SERVER-WEBAPP LSIS wXP arbitrary file upload attempt (more info ...)attempted-admin    
47677SERVER-WEBAPP Dell SonicWall Scrutinizer hidden webmin credentials login attempt (more info ...)default-login-attempt    
47678MALWARE-CNC Win.Trojan.Torpplar variant outbound connection (more info ...)trojan-activity    URL
47692MALWARE-CNC Win.Ransomware.Shrug2 outbound connection (more info ...)trojan-activity    URL
47693SERVER-WEBAPP Manage Engine Recovery Manager cross site scripting attempt (more info ...)attempted-user 2018-9163   URL
47694SERVER-WEBAPP Manage Engine Recovery Manager cross site scripting attempt (more info ...)attempted-user 2018-9163   URL
47695MALWARE-CNC User-Agent known malicious user-agent string - Win.Downloader.Powload (more info ...)trojan-activity    URL
47696MALWARE-CNC User-Agent known malicious user-agent string - Win.Downloader.Powload (more info ...)trojan-activity    URL
47697MALWARE-CNC User-Agent known malicious user-agent string - Win.Downloader.Powload (more info ...)trojan-activity    URL
47701MALWARE-CNC Win.Backdoor.Iniduoh variant outbound connection (more info ...)trojan-activity    URL
47708MALWARE-CNC Win.Trojan.Fallchill variant outbound connection (more info ...)trojan-activity    URL
47723MALWARE-CNC Andr.Trojan.MysteryBot outbound connection (more info ...)trojan-activity    URL
47724SERVER-OTHER Memcached DDoS attempt (more info ...)attempted-dos 2018-1000115   URL
47725SERVER-OTHER Memcached DDoS attempt (more info ...)attempted-dos 2018-1000115   URL
47726SERVER-OTHER Memcached DDoS attempt (more info ...)attempted-dos 2018-1000115   URL
47766MALWARE-CNC Win.Ransomware.GandCrab outbound connection (more info ...)trojan-activity    URL
47767SERVER-WEBAPP ClipBucket file_uploader command injection attempt (more info ...)web-application-attack 2018-7664   
47773MALWARE-CNC Win32.Backdoor.Turla variant outbound connection (more info ...)trojan-activity    URL
47790SERVER-WEBAPP Trend Micro Email Encryption Gateway cross site scripting attempt (more info ...)attempted-user 2018-6227   
47791SERVER-WEBAPP Trend Micro Email Encryption Gateway cross site scripting attempt (more info ...)attempted-user 2018-6227   
47792SERVER-WEBAPP Trend Micro Email Encryption Gateway cross site scripting attempt (more info ...)attempted-user 2018-6226   
47793SERVER-WEBAPP Trend Micro Email Encryption Gateway cross site scripting attempt (more info ...)attempted-user 2018-6226   
47820SERVER-OTHER OpenSSL invalid Diffie-Hellman parameter NULL pointer dereference attempt (more info ...)denial-of-service 2017-3730   
47821SERVER-OTHER OpenSSL invalid Diffie-Hellman parameter NULL pointer dereference attempt (more info ...)denial-of-service 2017-3730   
47822MALWARE-CNC Win.Trojan.njrat njRAT trojan outbound attempt (more info ...)trojan-activity    URL
47823MALWARE-CNC Win.Trojan.njrat njRAT trojan variant download (more info ...)trojan-activity    URL
47824MALWARE-CNC Win.Trojan.njrat njRAT trojan variant download (more info ...)trojan-activity    URL
47825MALWARE-CNC Win.Trojan.njrat njRAT trojan variant download (more info ...)trojan-activity    URL
47826MALWARE-CNC Win.Trojan.njrat njRAT trojan variant download (more info ...)trojan-activity    URL
47835MALWARE-CNC Win.Trojan.DownloadGuide variant outbound traffic (more info ...)trojan-activity    URL
47836MALWARE-CNC Win.Trojan.DownloadGuide variant outbound traffic (more info ...)trojan-activity    URL
47837MALWARE-CNC Win.Trojan.DownloadGuide variant outbound traffic (more info ...)trojan-activity    URL
47860MALWARE-CNC Andr.Trojan.Xamaria variant outbound connection (more info ...)trojan-activity    URL
47876MALWARE-CNC Andr.Trojan.AnubisCrypt variant outbound post detected (more info ...)trojan-activity    URL
47877MALWARE-CNC Andr.Trojan.AnubisCrypt variant outbound post detected (more info ...)trojan-activity    URL
47882FILE-OTHER Ghostscript -dSAFER sandbox bypass attempt (more info ...)attempted-admin 2018-16509   
47895BROWSER-PLUGINS Tor Browser 7.x NoScript secure mode bypass attempt (more info ...)attempted-user    URL
47896SERVER-OTHER Alt-N MDaemon buffer overflow attempt (more info ...)attempted-admin    URL
47897SERVER-OTHER Alt-N MDaemon buffer overflow attempt (more info ...)attempted-admin    URL
47898MALWARE-CNC Win.Trojan.OilRig variant outbound connection (more info ...)attempted-user    URL
47899MALWARE-CNC Win.Trojan.OilRig variant outbound connection (more info ...)attempted-user    URL
47900MALWARE-CNC Win.Trojan.OilRig variant outbound connection (more info ...)attempted-user    URL
47901MALWARE-CNC Win.Trojan.CobInt outbound connection (more info ...)trojan-activity    URL
47902MALWARE-CNC Win.Trojan.CobInt outbound connection (more info ...)trojan-activity    URL
47903MALWARE-CNC Win.Trojan.CobInt outbound connection (more info ...)attempted-user    URL
47904MALWARE-CNC Win.Trojan.CobInt outbound connection (more info ...)trojan-activity    URL
47905MALWARE-CNC Win.Trojan.CobInt outbound connection (more info ...)trojan-activity    URL
47906MALWARE-CNC Win.Trojan.CobInt outbound connection (more info ...)trojan-activity    URL
47934MALWARE-CNC Win.Trojan.MSDownloader variant outbound connection (more info ...)trojan-activity    URL
47935MALWARE-CNC Win.Trojan.MSDownloader variant download (more info ...)trojan-activity    URL
47936MALWARE-CNC Win.Trojan.MSDownloader variant download (more info ...)trojan-activity    URL
48022MALWARE-CNC Win.Ransomware.Viro variant outbound connection (more info ...)trojan-activity    URL
48024MALWARE-CNC Win.Trojan.PyLocky outbound connection attempt (more info ...)trojan-activity    URL
48025MALWARE-CNC BabaYaga inbound connection (more info ...)trojan-activity    URL
48026MALWARE-CNC BabaYaga outbound connection (more info ...)trojan-activity    URL
48027MALWARE-CNC BabaYaga outbound connection (more info ...)trojan-activity    URL
48028MALWARE-CNC Win.Trojan.Turla outbound connection (more info ...)trojan-activity    URL
48035MALWARE-CNC Win.Trojan.AcridRain outbound connection (more info ...)trojan-activity    URL
48036MALWARE-CNC Win.Trojan.AcridRain outbound connection (more info ...)trojan-activity    URL
48079MALWARE-CNC Win.Trojan.Ramnit variant outbound connection (more info ...)trojan-activity    URL
48080MALWARE-CNC Win.Trojan.Ramnit variant outbound connection (more info ...)trojan-activity    URL
48081MALWARE-CNC Win.Trojan.Ramnit variant outbound connection (more info ...)trojan-activity    URL
48082MALWARE-CNC Win.Trojan.Agent download attempt (more info ...)trojan-activity    URL
48083MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48084MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48085MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48086MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48087MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48088MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48089MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48090MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48091MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48092MALWARE-CNC Win.Trojan.MirageFox variant outbound connection (more info ...)trojan-activity    URL
48093MALWARE-CNC Win.Trojan.MirageFox variant outbound connection (more info ...)trojan-activity    URL
48094SERVER-WEBAPP SAP Internet Transaction Server directory traversal attempt (more info ...)web-application-attack 2003-0748 8516  
48095SERVER-WEBAPP SAP Internet Transaction Server directory traversal attempt (more info ...)web-application-attack 2003-0748 8516  
48096SERVER-WEBAPP SAP Internet Transaction Server directory traversal attempt (more info ...)web-application-attack 2003-0748 8516  
48114SERVER-OTHER Delta Industrial Automation Robot DRAStudio Arbitrary File Disclosure attempt (more info ...)attempted-user    URL
48115MALWARE-CNC Win.Trojan.ITranslator variant outbound connection (more info ...)trojan-activity    URL
48116MALWARE-CNC Win.Trojan.ITranslator variant outbound connection (more info ...)trojan-activity    URL
48117MALWARE-CNC Win.Trojan.ITranslator variant outbound connection (more info ...)trojan-activity    URL
48118MALWARE-CNC Win.Trojan.ITranslator variant outbound connection (more info ...)trojan-activity    URL
48119MALWARE-CNC Win.Trojan.ITranslator variant outbound connection (more info ...)trojan-activity    URL
48120MALWARE-CNC Win.Trojan.ITranslator variant outbound connection (more info ...)trojan-activity    URL
48121SERVER-OTHER LSIS wXP Denial of Service attempt (more info ...)denial-of-service    URL
48127SERVER-OTHER Reliance SCADA Control Server Denial of Service attempt (more info ...)attempted-user    URL
48140MALWARE-CNC Win.Downloader.XAgent variant outbound connection (more info ...)trojan-activity    URL
48144FILE-OTHER McAfee True Key dll-load exploit attempt (more info ...)attempted-admin 2018-6661   URL
48145FILE-OTHER McAfee True Key dll-load exploit attempt (more info ...)attempted-admin 2018-6661   URL
48146MALWARE-BACKDOOR Rebhip variant runtime detection (more info ...)trojan-activity    URL
48147MALWARE-CNC Win.Worm.Redhip variant outbound connection (more info ...)trojan-activity    URL
48148MALWARE-CNC Win.Worm.Redhip variant outbound connection (more info ...)trojan-activity    URL
48149MALWARE-CNC Win.Worm.Redhip variant outbound connection (more info ...)trojan-activity    URL
48150MALWARE-CNC Win.Worm.Redhip variant outbound connection (more info ...)trojan-activity    URL
48151MALWARE-CNC JS.Trojan.Generic malicious file download (more info ...)trojan-activity    URL
48152MALWARE-CNC JS.Trojan.Generic malicious file download (more info ...)trojan-activity    URL
48153MALWARE-CNC JS.Trojan.Generic variant outbound connection (more info ...)trojan-activity    URL
48154MALWARE-CNC JS.Trojan.Generic variant outbound connection (more info ...)trojan-activity    URL
48155MALWARE-CNC JS.Trojan.Generic variant outbound connection (more info ...)trojan-activity    URL
48156MALWARE-CNC JS.Trojan.Generic variant outbound connection (more info ...)trojan-activity    URL
48157MALWARE-CNC JS.Trojan.Generic variant outbound connection (more info ...)trojan-activity    URL
48158FILE-OTHER WECON LeviStudio UMP file stack buffer overflow attempt (more info ...)attempted-user 2018-10602   
48167SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-user    
48168SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-user    
48169SERVER-OTHER HPE Intelligent Management Center imcwlandm buffer overflow attempt (more info ...)attempted-user    
48175MALWARE-CNC Win.Trojan.GhostPuppet malicious document download attempt (more info ...)trojan-activity    URL
48176MALWARE-CNC Win.Trojan.GhostPuppet malicious document download attempt (more info ...)trojan-activity    URL
48197MALWARE-CNC Win.Trojan.Datper variant outbound request detected (more info ...)trojan-activity    URL
48198MALWARE-CNC Win.Trojan.Datper variant outbound request detected (more info ...)trojan-activity    URL
48199MALWARE-CNC Win.Trojan.Emdivi variant outbound request detected (more info ...)trojan-activity    URL
48202MALWARE-CNC Andr.Trojan.Xamaria variant outbound connection (more info ...)trojan-activity    URL
48203MALWARE-CNC Andr.Trojan.Xamaria variant outbound connection (more info ...)trojan-activity    URL
48209FILE-OTHER TRUFFLEHUNTER TALOS-2018-0693 attack attempt (more info ...)attempted-recon    URL
48210FILE-OTHER TRUFFLEHUNTER TALOS-2018-0693 attack attempt (more info ...)attempted-recon    URL
48213FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2018-0694 attack attempt (more info ...)attempted-user 2018-4022   URL
48214FILE-MULTIMEDIA TRUFFLEHUNTER TALOS-2018-0694 attack attempt (more info ...)attempted-user 2018-4022   URL
48222FILE-PDF Foxit Reader and PhantomPDF use after free exploitation attempt (more info ...)attempted-user    
48223FILE-PDF Foxit Reader and PhantomPDF use after free exploitation attempt (more info ...)attempted-user    
48249SERVER-OTHER GP ProEX WinGP Runtime directory traversal attempt (more info ...)attempted-user    URL
48250SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0697 attack attempt (more info ...)attempted-dos 2018-4025   URL
48251SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0699 attack attempt (more info ...)attempted-dos 2018-4027   URL
48253SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0698 attack attempt (more info ...)attempted-dos 2018-4026   URL
48254SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0696 attack attempt (more info ...)attempted-dos 2018-4024   URL
48255SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0695 attack attempt (more info ...)attempted-admin 2018-4023   URL
48258MALWARE-CNC Win.Trojan.Octopus outbound connection attempt (more info ...)trojan-activity    URL
48259MALWARE-CNC Win.Trojan.Octopus outbound connection attempt (more info ...)trojan-activity    URL
48260MALWARE-CNC Win.Trojan.Octopus outbound connection attempt (more info ...)trojan-activity    URL
48261SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0703 attack attempt (more info ...)attempted-admin 2018-4031   URL
48262SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0703 attack attempt (more info ...)attempted-admin 2018-4031   URL
48276MALWARE-CNC Win.Trojan.Felixroot variant command-and-control communication attempt (more info ...)trojan-activity    URL
48277MALWARE-CNC Win.Trojan.Felixroot variant download attempt (more info ...)trojan-activity    URL
48278MALWARE-CNC Win.Trojan.Felixroot variant download attempt (more info ...)trojan-activity    URL
48279MALWARE-CNC Rtf.Trojan.Felixroot variant download attempt (more info ...)trojan-activity    URL
48280MALWARE-CNC Rtf.Trojan.Felixroot variant download attempt (more info ...)trojan-activity    URL
48287MALWARE-CNC Win.Trojan.FormBook variant outbound request detected (more info ...)trojan-activity    URL
48288MALWARE-CNC Win.Trojan.FormBook variant outbound request detected (more info ...)trojan-activity    URL
48295FILE-OTHER out-of-bounds write attempt with malicious MAR file detected (more info ...)misc-activity 2018-12379   URL
48296FILE-OTHER out-of-bounds write attempt with malicious MAR file detected (more info ...)misc-activity 2018-12379   URL
48299MALWARE-CNC Win.Trojan.Telebot variant outbound connection (more info ...)trojan-activity    URL
48300MALWARE-CNC Win.Trojan.Telebot variant outbound connection (more info ...)trojan-activity    URL
48301MALWARE-CNC Win.Trojan.Telebot variant outbound connection (more info ...)trojan-activity    URL
48302MALWARE-CNC Win.Trojan.Telebot variant outbound connection (more info ...)trojan-activity    URL
48307MALWARE-CNC Win.Doc.GrayEnergy malicious document download attempt (more info ...)trojan-activity    URL
48308MALWARE-CNC Win.Doc.GrayEnergy malicious document download attempt (more info ...)trojan-activity    URL
48355MALWARE-CNC Win.Trojan.Banking download attempt initiated (more info ...)trojan-activity    URL
48356MALWARE-CNC Win.Trojan.Banking download attempt initiated (more info ...)trojan-activity    URL
48395MALWARE-CNC Win.Trojan.Zebrocy outbound connection (more info ...)trojan-activity    URL
48396MALWARE-CNC Win.Trojan.Zebrocy outbound connection (more info ...)trojan-activity    URL
48397MALWARE-CNC Win.Trojan.Zebrocy TLS server hello attempt (more info ...)trojan-activity    URL
48402MALWARE-CNC Win.Trojan.Emotet variant outbound connection attempt (more info ...)trojan-activity    URL
48422MALWARE-CNC Win.Trojan.Bondupdater outbound cnc connection (more info ...)trojan-activity    URL
48429MALWARE-CNC Win.Trojan.Cannon outbound connection (more info ...)trojan-activity    URL
48430MALWARE-CNC Win.Trojan.Cannon outbound connection (more info ...)trojan-activity    URL
48431MALWARE-CNC Win.Trojan.Zebrocy outbound connection (more info ...)trojan-activity    URL
48432MALWARE-CNC Win.Trojan.Zebrocy outbound connection (more info ...)trojan-activity    URL
48435MALWARE-CNC Win.Trojan.OlympicDestroyer variant outbound connection (more info ...)trojan-activity    URL
48436MALWARE-CNC Win.Trojan.OlympicDestroyer variant outbound connection (more info ...)trojan-activity    URL
48437MALWARE-CNC Win.Trojan.12percent ransomware generator download (more info ...)trojan-activity    
48438MALWARE-CNC Win.Trojan.12percent ransomware generator download (more info ...)trojan-activity    
48439INDICATOR-COMPROMISE Request for external IP address/location detected (more info ...)trojan-activity    
48446MALWARE-CNC Win.Trojan.Sofacy outbound connection (more info ...)trojan-activity    URL
48447MALWARE-CNC Win.Trojan.Sofacy outbound connection (more info ...)trojan-activity    URL
48448SERVER-WEBAPP Drupal open redirect external URL injection attempt (more info ...)attempted-admin    URL
48449MALWARE-CNC Win.Trojan.Exaramel outbound cnc connection (more info ...)trojan-activity    URL
48450FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2018-0729 attack attempt (more info ...)attempted-user 2018-4055   URL
48451FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2018-0729 attack attempt (more info ...)attempted-user 2018-4055   URL
48452FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2018-0728 attack attempt (more info ...)attempted-user 2018-4054   URL
48453FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2018-0728 attack attempt (more info ...)attempted-user 2018-4054   URL
48458SERVER-OTHER TRUFFLEHUNTER TALOS-2018-0733 attack attempt (more info ...)attempted-admin 2018-4059   URL
48461MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48462MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48463MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48464MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48465MALWARE-CNC Js.Worm.Bondat inbound connection attempt (more info ...)trojan-activity    URL
48466MALWARE-CNC Win.Trojan.tRat variant outbound cnc connection (more info ...)trojan-activity    URL
48467MALWARE-CNC Win.Trojan.tRat variant outbound cnc connection (more info ...)trojan-activity    URL
48476MALWARE-CNC Win.Trojan.Carrotbat outbound connection attempt (more info ...)trojan-activity    URL
48477MALWARE-CNC Win.Trojan.Agent outbound connection attempt (more info ...)trojan-activity    URL
48478MALWARE-CNC Win.Trojan.Agent outbound connection attempt (more info ...)trojan-activity    URL
48480MALWARE-CNC Win.Trojan.Carrotbat outbound connection attempt (more info ...)trojan-activity    URL
48485SERVER-WEBAPP Loytec LWEB-900 directory traversal attempt (more info ...)web-application-attack    URL
48497MALWARE-CNC 4th Stage Oilrig CNC connection attempt (more info ...)trojan-activity    URL
48498MALWARE-CNC 2nd Stage Oilrig CNC connection attempt (more info ...)trojan-activity    URL
48499MALWARE-CNC Win.Trojan.ZeusPanda outbound cnc connection (more info ...)trojan-activity    URL
48503MALWARE-CNC Win.Trojan.Hancitor outbound cnc connection (more info ...)trojan-activity    URL
48504MALWARE-CNC Win.Trojan.ZeusPanda outbound cnc connection (more info ...)trojan-activity    URL
48505MALWARE-CNC Win.Trojan.Ursnif outbound connection attempt (more info ...)trojan-activity    URL
48506MALWARE-CNC Win.Trojan.ZeusPanda outbound connection attempt (more info ...)trojan-activity    URL
48507MALWARE-CNC Win.Trojan.ZeusPanda outbound connection attempt (more info ...)trojan-activity    URL
48508MALWARE-CNC Win.Trojan.ZeusPanda outbound connection attempt (more info ...)trojan-activity    URL
48521PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2018-0739 attack attempt (more info ...)attempted-recon    URL
48526PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2018-0740 attack attempt (more info ...)attempted-recon    URL
48527PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2018-0737 attack attempt (more info ...)attempted-dos    URL
48528PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2018-0736 attack attempt (more info ...)attempted-dos    URL
48552MALWARE-CNC Win.Trojan.Azorult outbound connection (more info ...)trojan-activity    URL
48558MALWARE-CNC Win.Trojan.Dofoil variant outbound connection (more info ...)trojan-activity    URL
48559MALWARE-CNC Win.Trojan.Powermud variant outbound connection (more info ...)trojan-activity    
48560MALWARE-CNC Win.Trojan.Powermud variant outbound connection (more info ...)trojan-activity    
48561MALWARE-CNC Win.Trojan.Powermud variant outbound connection (more info ...)trojan-activity    
48562MALWARE-CNC Win.Trojan.Powermud variant outbound connection (more info ...)trojan-activity    
48568MALWARE-CNC Osx.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
48588MALWARE-CNC Doc.Downloader.Cannon payload download attempt (more info ...)trojan-activity    
48589MALWARE-CNC Doc.Downloader.Cannon payload download attempt (more info ...)trojan-activity    URL
48590MALWARE-CNC Win.Trojan.Zebrocy variant outbound cnc connection (more info ...)trojan-activity    URL
48591MALWARE-CNC Doc.Downloader.Cannon payload download attempt (more info ...)trojan-activity    URL
48592MALWARE-CNC Win.Trojan.Zebrocy variant outbound cnc connection (more info ...)trojan-activity    
48618POLICY-OTHER TRUFFLEHUNTER TALOS-2018-0747 attack attempt (more info ...)policy-violation 2018-4062   URL
48620POLICY-OTHER TRUFFLEHUNTER TALOS-2018-0754 attack attempt (more info ...)policy-violation 2018-4069   URL
48635SERVER-WEBAPP TRUFFLEHUNTER TALOS-2018-0753 attack attempt (more info ...)attempted-recon 2018-4068   URL
48721MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48722MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48723MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48724MALWARE-CNC Win.Trojan.Occamy variant outbound connection (more info ...)trojan-activity    URL
48732MALWARE-CNC Win.Trojan.Zekapab variant outbound connection (more info ...)trojan-activity    URL
48764MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48765MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48766MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48767MALWARE-CNC Win.Trojan.Zebrocy variant payload download attempt (more info ...)trojan-activity    URL
48791MALWARE-CNC Vbs.Trojan.Agent inbound payload download (more info ...)trojan-activity    URL
48792MALWARE-CNC Vbs.Trojan.Agent inbound payload download (more info ...)trojan-activity    URL
48818MALWARE-CNC Js.Trojan.Agent variant outbound connection (more info ...)trojan-activity    
48819MALWARE-CNC Js.Trojan.Agent variant inbound payload download (more info ...)trojan-activity    
48820MALWARE-CNC Win.Ransomware.Criakl variant outbound connection (more info ...)trojan-activity    URL
48821MALWARE-CNC Win.Trojan.Uppercut variant outbound connection (more info ...)trojan-activity    URL
48822MALWARE-CNC Win.Trojan.Uppercut inbound payload download (more info ...)trojan-activity    URL
48823POLICY-OTHER C-More Programming Simulator denial of service attempt (more info ...)attempted-dos    URL
48844MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48845MALWARE-CNC Osx.Trojan.WindTail outbound connection (more info ...)trojan-activity    URL
48846MALWARE-CNC Osx.Trojan.WindTail outbound connection (more info ...)trojan-activity    URL
48847MALWARE-CNC Osx.Trojan.WindTail outbound connection (more info ...)trojan-activity    URL
48854PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0758 attack attempt (more info ...)attempted-dos 2019-5010   URL
48855PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0758 attack attempt (more info ...)attempted-dos 2019-5010   URL
48857MALWARE-CNC Win.Trojan.L0rdix send client settings attempt (more info ...)trojan-activity    URL
48858MALWARE-CNC Win.Trojan.L0rdix send system log attempt (more info ...)trojan-activity    URL
48859MALWARE-CNC MuddyWater variant malicious document download attempt (more info ...)trojan-activity    URL
48860MALWARE-CNC MuddyWater variant malicious document download attempt (more info ...)trojan-activity    URL
48861INDICATOR-OBFUSCATION Potential Z-WASP malicious URL obfuscation attempt (more info ...)misc-activity    URL
48862INDICATOR-OBFUSCATION Potential Z-WASP malicious URL obfuscation attempt (more info ...)misc-activity    URL
48863INDICATOR-OBFUSCATION Potential Z-WASP malicious URL obfuscation attempt (more info ...)misc-activity    URL
48864INDICATOR-OBFUSCATION Potential Z-WASP malicious URL obfuscation attempt (more info ...)misc-activity    URL
48865MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
48866MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
48867MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
48868MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
48872MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    
48873MALWARE-CNC Win.Trojan.BitterRAT variant outbound connection (more info ...)trojan-activity    URL
48874MALWARE-CNC Win.Trojan.BitterRAT variant outbound connection (more info ...)trojan-activity    URL
48875MALWARE-CNC Win.Trojan.BitterRAT variant outbound connection (more info ...)trojan-activity    URL
48876MALWARE-CNC Win.Trojan.BitterRAT variant outbound connection (more info ...)trojan-activity    URL
48877MALWARE-CNC Win.Trojan.BitterRAT variant outbound connection (more info ...)trojan-activity    URL
48878MALWARE-CNC Win.Trojan.BitterRAT variant outbound connection (more info ...)trojan-activity    URL
48879MALWARE-CNC Win.Trojan.FlawedGrace outbound connection (more info ...)trojan-activity    URL
48880MALWARE-CNC Win.Trojan.FlawedGrace outbound connection (more info ...)trojan-activity    URL
48881MALWARE-CNC Win.Trojan.FlawedGrace outbound connection (more info ...)trojan-activity    URL
48882MALWARE-CNC Win.Trojan.FlawedGrace outbound connection (more info ...)trojan-activity    URL
48883MALWARE-CNC Win.Trojan.ServHelper outbound connection (more info ...)trojan-activity    URL
48884MALWARE-CNC Win.Trojan.ServHelper outbound connection (more info ...)trojan-activity    URL
48885MALWARE-CNC Win.Trojan.ServHelper outbound connection (more info ...)trojan-activity    URL
48886MALWARE-CNC Win.Trojan.FlawedGrace outbound connection (more info ...)trojan-activity    URL
48887MALWARE-CNC Win.Trojan.ServHelper outbound connection (more info ...)trojan-activity    URL
48895POLICY-SPAM Potential phishing attack - Web Open Font Format evasion attempt (more info ...)policy-violation    URL
48904MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
48907MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
48908MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
48937FILE-IMAGE Imagemagick XBM tranformation information leak attempt (more info ...)attempted-recon 2018-16323   
48940MALWARE-CNC Win.Trojan.TA505 malicious dropper download attempt (more info ...)trojan-activity    URL
48941MALWARE-CNC Win.Trojan.TA505 malicious dropper download attempt (more info ...)trojan-activity    URL
48975PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0767 attack attempt (more info ...)attempted-dos    URL
48976PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0769 attack attempt (more info ...)attempted-recon    URL
48977PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0770 attack attempt (more info ...)attempted-dos    URL
48978PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0768 attack attempt (more info ...)attempted-dos    URL
48979PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0764 attack attempt (more info ...)attempted-dos    URL
48980PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0766 attack attempt (more info ...)attempted-dos    URL
48981PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0765 attack attempt (more info ...)attempted-dos    URL
48982MALWARE-CNC Win.Ransomware.MongoLock outbound connection (more info ...)trojan-activity    URL
48984PROTOCOL-SCADA PCOM Identification ASCII request (more info ...)attempted-recon    URL
48985PROTOCOL-SCADA PCOM Init Device ASCII request (more info ...)attempted-dos    URL
48986PROTOCOL-SCADA PCOM Set UnitID ASCII request (more info ...)attempted-recon    URL
48987PROTOCOL-SCADA PCOM Get UnitID ASCII request (more info ...)attempted-recon    URL
48988PROTOCOL-SCADA PCOM Read Inputs ASCII request (more info ...)attempted-recon    URL
48989PROTOCOL-SCADA PCOM Set RTC ASCII request (more info ...)attempted-recon    URL
48990PROTOCOL-SCADA PCOM Read Ouputs ASCII request (more info ...)attempted-recon    URL
48991PROTOCOL-SCADA PCOM Read System Bits ASCII request (more info ...)attempted-recon    URL
48992PROTOCOL-SCADA PCOM Read Memory Integers ASCII request (more info ...)attempted-recon    URL
48993PROTOCOL-SCADA PCOM Read Memory Longs ASCII request (more info ...)attempted-recon    URL
48994PROTOCOL-SCADA PCOM Write System Integers ASCII request (more info ...)attempted-recon    URL
48995PROTOCOL-SCADA PCOM Write System Bits ASCII request (more info ...)attempted-recon    URL
48996PROTOCOL-SCADA PCOM Read System Longs ASCII request (more info ...)attempted-recon    URL
48997PROTOCOL-SCADA PCOM Read System Integers ASCII request (more info ...)attempted-recon    URL
48998PROTOCOL-SCADA PCOM Read Memory Bits ASCII request (more info ...)attempted-recon    URL
48999PROTOCOL-SCADA PCOM Write Ouputs ASCII request (more info ...)attempted-recon    URL
49000PROTOCOL-SCADA PCOM Stop Device ASCII request (more info ...)attempted-dos    URL
49001PROTOCOL-SCADA PCOM Start Device ASCII request (more info ...)attempted-dos    URL
49002PROTOCOL-SCADA PCOM Write System Longs ASCII request (more info ...)attempted-recon    URL
49003PROTOCOL-SCADA PCOM Get RTC ASCII request (more info ...)attempted-recon    URL
49004PROTOCOL-SCADA PCOM Write Memory Bits ASCII request (more info ...)attempted-recon    URL
49005PROTOCOL-SCADA PCOM Reset Device ASCII request (more info ...)attempted-dos    URL
49006PROTOCOL-SCADA PCOM Write Memory Longs ASCII request (more info ...)attempted-recon    URL
49007PROTOCOL-SCADA PCOM Write Memory Integers ASCII request (more info ...)attempted-recon    URL
49009PROTOCOL-SCADA PCOM Set UnitID ASCII reply (more info ...)attempted-recon    URL
49010PROTOCOL-SCADA PCOM Get RTC ASCII reply (more info ...)attempted-recon    URL
49011PROTOCOL-SCADA PCOM Identification ASCII reply (more info ...)attempted-recon    URL
49012PROTOCOL-SCADA PCOM Write Data Table binary request (more info ...)attempted-recon    URL
49013PROTOCOL-SCADA PCOM Get UnitID ASCII reply (more info ...)attempted-recon    URL
49014PROTOCOL-SCADA PCOM Read Data Table binary request (more info ...)attempted-recon    URL
49015PROTOCOL-SCADA PCOM Get PLC Name binary request (more info ...)attempted-recon    URL
49016PROTOCOL-SCADA PCOM Set RTC ASCII reply (more info ...)attempted-recon    URL
49017PROTOCOL-SCADA PCOM Read Inputs ASCII reply (more info ...)attempted-recon    URL
49018PROTOCOL-SCADA PCOM Read System Bits ASCII reply (more info ...)attempted-recon    URL
49019PROTOCOL-SCADA PCOM Read Longs ASCII reply (more info ...)attempted-recon    URL
49020PROTOCOL-SCADA PCOM Read System Integers ASCII reply (more info ...)attempted-recon    URL
49021PROTOCOL-SCADA PCOM Read Ouputs ASCII reply (more info ...)attempted-recon    URL
49022PROTOCOL-SCADA PCOM Read Memory Bits ASCII reply (more info ...)attempted-recon    URL
49023PROTOCOL-SCADA PCOM Read Memory Integers ASCII reply (more info ...)attempted-recon    URL
49024PROTOCOL-SCADA PCOM Write Memory Bits ASCII reply (more info ...)attempted-recon    URL
49025PROTOCOL-SCADA PCOM Write System Integers ASCII reply (more info ...)attempted-recon    URL
49026PROTOCOL-SCADA PCOM Write System Bits ASCII reply (more info ...)attempted-recon    URL
49027PROTOCOL-SCADA PCOM Write Ouputs ASCII reply (more info ...)attempted-recon    URL
49028PROTOCOL-SCADA PCOM Write Memory Integers ASCII reply (more info ...)attempted-recon    URL
49029PROTOCOL-SCADA PCOM Write Longs ASCII reply (more info ...)attempted-recon    URL
49031PROTOCOL-SCADA PCOM Get PLC Name binary reply (more info ...)attempted-recon    URL
49032PROTOCOL-SCADA PCOM Write Data Table binary reply (more info ...)attempted-recon    URL
49033PROTOCOL-SCADA PCOM Read Data Table binary reply (more info ...)attempted-recon    URL
49034MALWARE-CNC Win.Trojan.Qakbot malicious executable download attempt (more info ...)trojan-activity    URL
49035MALWARE-CNC Win.Trojan.Qakbot malicious executable download attempt (more info ...)trojan-activity    URL
49047PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0763 attack attempt (more info ...)attempted-admin    URL
49050PROTOCOL-SCADA Siemens SIMATIC S7-1500 remote denial of service attempt (more info ...)attempted-dos 2016-3963   URL
49051SERVER-OTHER Ewon router default credential login attempt (more info ...)attempted-user    URL
49052SERVER-OTHER Moxa router default credential login attempt (more info ...)attempted-user    URL
49053SERVER-OTHER Moxa router default credential login attempt (more info ...)attempted-user    URL
49054SERVER-OTHER Moxa router default credential login attempt (more info ...)attempted-user    URL
49055SERVER-OTHER Moxa router default credential login attempt (more info ...)attempted-user    URL
49056SERVER-OTHER Moxa router default credential login attempt (more info ...)attempted-user    URL
49057SERVER-OTHER Moxa router default credential login attempt (more info ...)attempted-user    URL
49058SERVER-OTHER Sierra Wireless router default credential login attempt (more info ...)attempted-user    URL
49059SERVER-OTHER Sierra Wireless router default credential login attempt (more info ...)attempted-user    URL
49060SERVER-OTHER Sierra Wireless router default credential login attempt (more info ...)attempted-user    URL
49061SERVER-OTHER Sierra Wireless router default credential login attempt (more info ...)attempted-user    URL
49062SERVER-OTHER Sierra Wireless router default credential login attempt (more info ...)attempted-user    URL
49063SERVER-OTHER Sierra Wireless router default credential login attempt (more info ...)attempted-user    URL
49064SERVER-OTHER Westermo router default credential login attempt (more info ...)attempted-user    URL
49068MALWARE-CNC Win.Doc.Dropper GandCrab ramsomware download attempt (more info ...)trojan-activity    URL
49069MALWARE-CNC Win.Doc.Dropper GandCrab ramsomware download attempt (more info ...)trojan-activity    URL
49087POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0775 attack attempt (more info ...)policy-violation 2019-5017   URL
49091MALWARE-CNC Win.Trojan.Dragonok variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
49092MALWARE-CNC Win.Trojan.Dragonok variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
49093SERVER-WEBAPP Coaster CMS stored cross site scripting attempt (more info ...)attempted-user 2018-17876   URL
49101MALWARE-CNC Win.Trojan.Qealler outbound connection attempt (more info ...)trojan-activity    URL
49102MALWARE-CNC Win.Trojan.Qealler outbound connection attempt (more info ...)trojan-activity    URL
49103MALWARE-CNC Win.Trojan.Qealler outbound connection attempt (more info ...)trojan-activity    URL
49104MALWARE-CNC Osx.Trojan.DarthMiner variant outbound connection (more info ...)trojan-activity    URL
49105MALWARE-CNC Osx.Trojan.DarthMiner variant outbound connection (more info ...)trojan-activity    URL
49106MALWARE-CNC Osx.Trojan.DarthMiner variant outbound connection (more info ...)trojan-activity    URL
49107MALWARE-CNC Osx.Trojan.DarthMiner variant outbound connection (more info ...)trojan-activity    URL
49108MALWARE-CNC Osx.Trojan.DarthMiner variant outbound connection (more info ...)trojan-activity    URL
49109MALWARE-CNC Osx.Trojan.DarthMiner variant outbound connection (more info ...)trojan-activity    URL
49110MALWARE-CNC Osx.Trojan.DarthMiner variant outbound connection (more info ...)trojan-activity    URL
49215MALWARE-CNC Win.Trojan.Keymarble malicious executable download attempt (more info ...)trojan-activity    URL
49216MALWARE-CNC Win.Trojan.Keymarble malicious executable download attempt (more info ...)trojan-activity    URL
49217MALWARE-CNC Win.Trojan.Keymarble malicious executable download attempt (more info ...)trojan-activity    URL
49218MALWARE-CNC Win.Trojan.Keymarble malicious executable download attempt (more info ...)trojan-activity    URL
49219MALWARE-CNC Win.Dropper.Brusha malicious payload download attempt (more info ...)trojan-activity    URL
49220MALWARE-CNC Win.Dropper.Brusha malicious payload download attempt (more info ...)trojan-activity    URL
49221MALWARE-CNC Win.Dropper.Brusha malicious payload download attempt (more info ...)trojan-activity    URL
49222MALWARE-CNC Win.Dropper.Brusha malicious payload download attempt (more info ...)trojan-activity    URL
49223MALWARE-CNC Win.Dropper.Brusha malicious payload download attempt (more info ...)trojan-activity    URL
49224MALWARE-CNC Win.Dropper.Brusha malicious payload download attempt (more info ...)trojan-activity    URL
49291FILE-OTHER WinRAR ACE remote code execution attempt (more info ...)attempted-user 2018-20250   URL
49292FILE-OTHER WinRAR ACE remote code execution attempt (more info ...)attempted-user 2018-20250   URL
49297FILE-OTHER IBM Lotus Notes LZH Attachment Viewer buffer overflow attempt (more info ...)attempted-user 2011-1213 48018  
49304SERVER-OTHER Google Golang GET command injection attempt (more info ...)attempted-user 2018-7187   
49319SERVER-WEBAPP CentOS Web Panel persistent cross site scripting attempt (more info ...)attempted-user 2019-7646   URL
49320SERVER-WEBAPP CentOS Web Panel persistent cross site scripting attempt (more info ...)attempted-user 2019-7646   URL
49321SERVER-WEBAPP CentOS Web Panel persistent cross site scripting attempt (more info ...)attempted-user 2019-7646   URL
49322SERVER-WEBAPP CentOS Web Panel persistent cross site scripting attempt (more info ...)attempted-user 2019-7646   URL
49326SERVER-WEBAPP Rockwell Automation Allen-Bradley PowerMonitor 1000 cross site scripting attempt (more info ...)attempted-user 2018-19615   
49327MALWARE-CNC Win.Ransomware.Crytekk variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
49328MALWARE-CNC Win.Ransomware.Crytekk variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
49329MALWARE-CNC Win.Ransomware.Crytekk variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
49330MALWARE-CNC Win.Ransomware.Crytekk variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
49331MALWARE-CNC Win.Trojan.Arescrypt malicious ransomware download attempt (more info ...)trojan-activity    URL
49332MALWARE-CNC Win.Trojan.Arescrypt malicious ransomware download attempt (more info ...)trojan-activity    URL
49351MALWARE-CNC Win.Trojan.FrameworkPoS variant outbound connection attempt (more info ...)trojan-activity    
49352MALWARE-CNC Win.Trojan.FrameworkPoS malicious executable download attempt (more info ...)trojan-activity    
49353MALWARE-CNC Win.Trojan.FrameworkPoS malicious executable download attempt (more info ...)trojan-activity    
49354MALWARE-CNC Win.Trojan.KerrDown variant outbound connection (more info ...)trojan-activity    URL
49355MALWARE-CNC Win.Trojan.KerrDown variant outbound connection (more info ...)trojan-activity    URL
49356MALWARE-CNC Win.Trojan.KerrDown download attempt (more info ...)trojan-activity    URL
49357MALWARE-CNC Win.Trojan.KerrDown download attempt (more info ...)trojan-activity    URL
49358MALWARE-CNC Win.Trojan.KerrDown download attempt (more info ...)trojan-activity    URL
49359MALWARE-CNC Win.Trojan.KerrDown download attempt (more info ...)trojan-activity    URL
49366INDICATOR-COMPROMISE Windows SMBv1 information disclosure attempt (more info ...)attempted-recon 2019-0703   URL
49367INDICATOR-COMPROMISE Windows SMBv2 information disclosure attempt (more info ...)attempted-recon 2019-0703   URL
49370POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0788 attack attempt (more info ...)policy-violation 2019-5027   URL
49373POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0789 attack attempt (more info ...)policy-violation 2019-5028   URL
49396MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
49397MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
49398MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
49408SERVER-WEBAPP Simple Scada directory traversal attempt (more info ...)web-application-attack    URL
49409FILE-OTHER Elipse Software Elipse32 dll-load exploit attempt (more info ...)attempted-user    URL
49410FILE-OTHER Elipse Software Elipse32 dll-load exploit attempt (more info ...)attempted-user    URL
49416SERVER-OTHER Samsung Integrated Management System Data Management Server hardcoded credentials attempt (more info ...)default-login-attempt    
49417SERVER-OTHER Samsung Integrated Management System Data Management Server hardcoded credentials attempt (more info ...)default-login-attempt    
49424MALWARE-CNC Win.Trojan.Danabot download attempt (more info ...)trojan-activity    URL
49425MALWARE-CNC Win.Trojan.Danabot download attempt (more info ...)trojan-activity    URL
49429SERVER-WEBAPP MyBB Bans List Extension cross site scripting attempt (more info ...)attempted-user 2018-14724   URL
49430SERVER-WEBAPP MyBB Bans List Extension cross site scripting attempt (more info ...)attempted-user 2018-14724   URL
49433SERVER-WEBAPP Sitecom Home Storage Center directory traversal attempt (more info ...)web-application-attack    URL
49434SERVER-WEBAPP Sitecom Home Storage Center directory traversal attempt (more info ...)web-application-attack    URL
49435SERVER-WEBAPP Sitecom Home Storage Center directory traversal attempt (more info ...)web-application-attack    URL
49436POLICY-OTHER Linksys WAP610N command injection attempt (more info ...)successful-admin    URL
49437FILE-OTHER Schneider Electric GP-Pro EX ParseAPI heap buffer overflow attempt (more info ...)attempted-user 2016-2290   URL
49438SERVER-OTHER QNX Neutrino qconn unauthenticated command execution attempt (more info ...)attempted-admin    URL
49439SERVER-OTHER Interactive Graphical SCADA System arbitrary file read attempt (more info ...)attempted-recon    URL
49440SERVER-OTHER SCADA DataRate remote code execution attempt (more info ...)attempted-admin    URL
49441SERVER-OTHER SCADA DataRate remote code execution attempt (more info ...)attempted-admin    URL
49466MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    
49467MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    
49468MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    URL
49469MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    URL
49470MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    URL
49471MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    URL
49472MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    
49473MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    URL
49474MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    
49475MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    URL
49476MALWARE-CNC Win.Trojan.RisingSun variant outbound connection (more info ...)trojan-activity    
49477MALWARE-CNC Doc.Dropper.RisingSun variant download attempt (more info ...)trojan-activity    URL
49478MALWARE-CNC Doc.Dropper.RisingSun variant download attempt (more info ...)trojan-activity    URL
49479MALWARE-CNC Doc.Dropper.RisingSun variant download attempt (more info ...)trojan-activity    URL
49480SERVER-OTHER IBM solidDB denial of service attempt (more info ...)attempted-dos 2010-4056   
49481SERVER-OTHER Sagem Fast 3304-V1 denial of service attempt (more info ...)attempted-dos    
49484SERVER-OTHER Western Digital MyNet unauthenticated configuration disclosure attempt (more info ...)attempted-recon 2013-5006   
49485SERVER-OTHER IBM solidDB denial of service attempt (more info ...)attempted-dos 2010-4055   
49490SERVER-WEBAPP QNAP Zip Upload command injection attempt (more info ...)web-application-attack    
49491SERVER-WEBAPP QNAP Zip Upload command injection attempt (more info ...)web-application-attack    
49492SERVER-WEBAPP QNAP Zip Upload command injection attempt (more info ...)web-application-attack    
49493SERVER-WEBAPP QNAP Zip Upload command injection attempt (more info ...)web-application-attack    
49506POLICY-OTHER Thomson TWG850-4 unauthenticated backup download attempt (more info ...)attempted-recon    
49507MALWARE-CNC Win.Trojan.Shade malicious executable download attempt (more info ...)trojan-activity    URL
49508MALWARE-CNC Win.Trojan.Shade malicious executable download attempt (more info ...)trojan-activity    URL
49521POLICY-OTHER Sagem Fast Router default credentials login attempt (more info ...)default-login-attempt    
49523SERVER-WEBAPP Zyxel ZyWALL information disclosure attempt (more info ...)attempted-recon    
49533MALWARE-CNC Win.Ransomware.Yatron variant outbound connection (more info ...)trojan-activity    URL
49534MALWARE-CNC Win.Ransomware.Yatron variant outbound connection (more info ...)trojan-activity    URL
49544MALWARE-CNC Win.Trojan.IcedID variant post-config websocket outbound connection attempt (more info ...)trojan-activity    URL
49548MALWARE-CNC Win.Trojan.AZORult variant payload download attempt (more info ...)trojan-activity    URL
49553MALWARE-CNC Win.Trojan.IcedID variant payload download attempt (more info ...)trojan-activity    URL
49554SERVER-OTHER OpenMRS getExactPatients.action information disclosure attempt (more info ...)attempted-admin    URL
49555INDICATOR-COMPROMISE AutoBase Studio project remote code execution attempt (more info ...)attempted-user    URL
49556INDICATOR-COMPROMISE AutoBase Studio project remote code execution attempt (more info ...)attempted-user    URL
49558FILE-PDF Cool PDF Reader buffer overflow attempt (more info ...)attempted-user 2012-4914   
49559FILE-PDF Cool PDF Reader buffer overflow attempt (more info ...)attempted-user 2012-4914   
49560FILE-PDF Cool PDF Reader buffer overflow attempt (more info ...)attempted-user 2012-4914   
49561FILE-PDF Cool PDF Reader buffer overflow attempt (more info ...)attempted-user 2012-4914   
49562FILE-PDF Cool PDF Reader buffer overflow attempt (more info ...)attempted-user 2012-4914   
49563FILE-PDF Cool PDF Reader buffer overflow attempt (more info ...)attempted-user 2012-4914   
49564FILE-PDF Cool PDF Reader buffer overflow attempt (more info ...)attempted-user 2012-4914   
49565FILE-PDF Cool PDF Reader buffer overflow attempt (more info ...)attempted-user 2012-4914   
49566MALWARE-CNC Win.Trojan.FlawedAmmyy variant outbound connection (more info ...)trojan-activity    URL
49567MALWARE-CNC Doc.Downloader.FlawedAmmyy download attempt (more info ...)trojan-activity    URL
49568MALWARE-CNC Doc.Downloader.FlawedAmmyy download attempt (more info ...)trojan-activity    URL
49571MALWARE-CNC Win.Trojan.Fakewmi variant outbound connection attempt (more info ...)trojan-activity    URL
49572MALWARE-CNC Win.Trojan.Fakewmi variant outbound connection attempt (more info ...)trojan-activity    URL
49575FILE-IMAGE SketchUp BMP RLE8 parsing buffer overflow attempt (more info ...)attempted-user 2013-3663   
49576FILE-IMAGE SketchUp BMP RLE8 parsing buffer overflow attempt (more info ...)attempted-user 2013-3663   
49577SERVER-WEBAPP ElectronJS Exodus remote code execution attempt (more info ...)attempted-user 2018-1000006   URL
49578SERVER-WEBAPP ElectronJS Exodus remote code execution attempt (more info ...)attempted-user 2018-1000006   URL
49579SERVER-WEBAPP ElectronJS Exodus remote code execution attempt (more info ...)attempted-user 2018-1000006   URL
49580SERVER-WEBAPP ElectronJS Exodus remote code execution attempt (more info ...)attempted-user 2018-1000006   URL
49581SERVER-WEBAPP ElectronJS Exodus remote code execution attempt (more info ...)attempted-user 2018-1000006   URL
49582SERVER-WEBAPP ElectronJS Exodus remote code execution attempt (more info ...)attempted-user 2018-1000006   URL
49592MALWARE-CNC Win.Trojan.SectorA05 outbound connection attempt (more info ...)trojan-activity    URL
49593MALWARE-CNC Win.Trojan.SectorA05 outbound connection attempt (more info ...)trojan-activity    URL
49594MALWARE-CNC Win.Trojan.SectorA05 outbound connection attempt (more info ...)trojan-activity    URL
49595MALWARE-CNC Win.Trojan.SectorA05 outbound connection attempt (more info ...)trojan-activity    URL
49596MALWARE-CNC Win.Trojan.GlobeImposter malicious executable download attempt (more info ...)trojan-activity    URL
49597MALWARE-CNC Win.Trojan.GlobeImposter malicious executable download attempt (more info ...)trojan-activity    URL
49601SERVER-OTHER Century Star SCADA directory traversal attempt (more info ...)attempted-admin    URL
49602SERVER-OTHER Century Star SCADA directory traversal attempt (more info ...)attempted-admin    URL
49623MALWARE-CNC Win.Trojan.Redaman outbound connection (more info ...)trojan-activity    URL
49624MALWARE-CNC Win.Trojan.Redaman outbound connection (more info ...)trojan-activity    URL
49625MALWARE-CNC Win.Trojan.Redaman outbound connection (more info ...)trojan-activity    URL
49632SERVER-OTHER Atvise SCADA arbitrary file disclosure attempt (more info ...)web-application-attack    URL
49633SERVER-OTHER Atvise SCADA arbitrary file disclosure attempt (more info ...)web-application-attack    URL
49634SERVER-OTHER Atvise SCADA arbitrary file disclosure attempt (more info ...)web-application-attack    URL
49652SERVER-OTHER ipTime G104BE directory traversal attempt (more info ...)web-application-attack    URL
49653MALWARE-CNC Win.Trojan.Rietspoof variant outbound connection (more info ...)trojan-activity    URL
49665SERVER-WEBAPP DirectAdmin admin account creation attempt (more info ...)attempted-admin 2019-9625   
49676MALWARE-CNC Win.Ransomware.Lockergoga binary download attempt (more info ...)trojan-activity    URL
49677MALWARE-CNC Win.Ransomware.Lockergoga binary download attempt (more info ...)trojan-activity    URL
49678MALWARE-CNC Win.Ransomware.Lockergoga binary download attempt (more info ...)trojan-activity    URL
49679MALWARE-CNC Win.Ransomware.Lockergoga binary download attempt (more info ...)trojan-activity    URL
49680MALWARE-CNC Win.Ransomware.Lockergoga binary download attempt (more info ...)trojan-activity    URL
49681MALWARE-CNC Android.Trojan.Banking outbound beacon attempt (more info ...)trojan-activity    URL
49682MALWARE-CNC Android.Trojan.Banking command-and-control communication attempt (more info ...)trojan-activity    URL
49772MALWARE-CNC Win.Trojan.Imminent variant inbound response (more info ...)trojan-activity    URL
49773MALWARE-CNC Win.Trojan.Imminent variant outbound connection (more info ...)trojan-activity    URL
49774MALWARE-CNC Win.Trojan.Imminent variant outbound connection (more info ...)trojan-activity    URL
49777MALWARE-CNC Win.Trojan.HawkEye variant outbound cnc connection (more info ...)trojan-activity    URL
49778MALWARE-CNC Win.Trojan.HawkEye variant outbound cnc connection (more info ...)trojan-activity    URL
49779MALWARE-CNC Win.Trojan.HawkEye variant outbound cnc connection (more info ...)trojan-activity    URL
49780PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0806 attack attempt (more info ...)attempted-dos    URL
49781FILE-OTHER Go binary dll-load exploit attempt (more info ...)attempted-user 2019-9634   URL
49782FILE-OTHER Go binary dll-load exploit attempt (more info ...)attempted-user 2019-9634   URL
49783FILE-OTHER Go binary dll-load exploit attempt (more info ...)attempted-user 2019-9634   URL
49784FILE-OTHER Go binary dll-load exploit attempt (more info ...)attempted-user 2019-9634   URL
49785FILE-OTHER Go binary dll-load exploit attempt (more info ...)attempted-user 2019-9634   URL
49786FILE-OTHER Go binary bll-load exploit attempt (more info ...)attempted-user 2019-9634   URL
49787PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2019-0807 attack attempt (more info ...)attempted-dos    URL
49788MALWARE-CNC Win.Trojan.Zacinlo outbound connection (more info ...)trojan-activity    URL
49789MALWARE-CNC Win.Trojan.Zacinlo outbound connection (more info ...)trojan-activity    URL
49790MALWARE-CNC Win.Trojan.Zacinlo outbound connection (more info ...)trojan-activity    URL
49797PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0798 attack attempt (more info ...)attempted-user 2019-5035   URL
49798PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0798 attack attempt (more info ...)attempted-user 2019-5035   URL
49801PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0800 attack attempt (more info ...)attempted-user 2019-5037   URL
49802PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0800 attack attempt (more info ...)attempted-user 2019-5037   URL
49803PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0799 attack attempt (more info ...)attempted-dos 2019-5036   URL
49804PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0799 attack attempt (more info ...)attempted-dos 2019-5036   URL
49813FILE-OTHER TRUFFLEHUNTER TALOS-2019-0802 attack attempt (more info ...)attempted-user 2019-5039   URL
49814FILE-OTHER TRUFFLEHUNTER TALOS-2019-0802 attack attempt (more info ...)attempted-user 2019-5039   URL
49815FILE-OTHER TRUFFLEHUNTER TALOS-2019-0802 attack attempt (more info ...)attempted-user 2019-5039   URL
49816FILE-OTHER TRUFFLEHUNTER TALOS-2019-0802 attack attempt (more info ...)attempted-user 2019-5039   URL
49843PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0797 attack attempt (more info ...)attempted-recon 2019-5034   URL
49844PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0797 attack attempt (more info ...)attempted-recon 2019-5034   URL
49854PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0803 attack attempt (more info ...)attempted-recon 2019-5040   URL
49855PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0803 attack attempt (more info ...)attempted-recon 2019-5040   URL
49856FILE-OTHER TRUFFLEHUNTER TALOS-2019-0801 attack attempt (more info ...)attempted-user 2019-5038   URL
49857FILE-OTHER TRUFFLEHUNTER TALOS-2019-0801 attack attempt (more info ...)attempted-user 2019-5038   URL
49860POLICY-OTHER TP-Link TL-WA850RE remote reboot attempt (more info ...)policy-violation 2018-12694   URL
49872SERVER-OTHER Drager X-Dock dxmanager denial of service attempt (more info ...)attempted-dos    
49880SERVER-OTHER Corosync 2.3+ with sha1 integer overflow attempt detected (more info ...)misc-attack 2018-1084   URL
49881SERVER-OTHER Corosync 2.3+ with md5 integer overflow attempt detected (more info ...)misc-attack 2018-1084   URL
49882SERVER-OTHER Corosync 2.3+ with sha256 integer overflow attempt detected (more info ...)misc-attack 2018-1084   URL
49883SERVER-OTHER Corosync 2.3+ with sha384 integer overflow attempt detected (more info ...)misc-attack 2018-1084   URL
49884SERVER-OTHER Corosync 2.3+ with sha512 integer overflow attempt detected (more info ...)misc-attack 2018-1084   URL
49910FILE-PDF TRUFFLEHUNTER TALOS-2019-0816 attack attempt (more info ...)attempted-user 2019-5047   URL
49911FILE-PDF TRUFFLEHUNTER TALOS-2019-0816 attack attempt (more info ...)attempted-user 2019-5047   URL
49913MALWARE-CNC Win.Malware.JasperLoader file download request (more info ...)trojan-activity    URL
49914MALWARE-CNC Win.Downloader.JasperLoader outbound connection (more info ...)trojan-activity    URL
49915MALWARE-CNC Win.Downloader.JasperLoader outbound connection (more info ...)trojan-activity    URL
49916MALWARE-CNC Win.Malware.JasperLoader update request (more info ...)trojan-activity    URL
49919SERVER-WEBAPP generic session fixation attempt (more info ...)attempted-recon    URL
49920SERVER-WEBAPP generic cross site scripting via url attempt (more info ...)attempted-recon    URL
49928SERVER-WEBAPP Multiple products HTML5 ping DDoS attempt (more info ...)denial-of-service    URL
49937SERVER-WEBAPP Tenda Wireless N150 Router cross-site request forgery attempt (more info ...)attempted-admin 2015-5996   URL
49938SERVER-WEBAPP Tenda Wireless N150 Router cross-site request forgery attempt (more info ...)attempted-admin 2015-5996   URL
49941MALWARE-CNC Win.Trojan.Qakbot variant outbound connection attempt (more info ...)trojan-activity    
49948FILE-PDF TRUFFLEHUNTER TALOS-2019-0817 attack attempt (more info ...)attempted-user 2019-5048   URL
49949FILE-PDF TRUFFLEHUNTER TALOS-2019-0817 attack attempt (more info ...)attempted-user 2019-5048   URL
49952MALWARE-CNC Win.Downloader.AutoIt outbound connection (more info ...)trojan-activity    URL
49953MALWARE-CNC Win.Downloader.AutoIt outbound connection (more info ...)trojan-activity    URL
49954MALWARE-CNC Js.Trojan.Agent JS Sniffer compromised website (more info ...)trojan-activity    URL
49955MALWARE-CNC Js.Trojan.Agent JS Sniffer compromised website (more info ...)trojan-activity    URL
49956MALWARE-CNC Js.Trojan.Agent JS Sniffer outbound connection (more info ...)trojan-activity    URL
49957MALWARE-CNC Js.Trojan.Agent JS Sniffer compromised website (more info ...)trojan-activity    URL
49978FILE-OTHER TRUFFLEHUNTER TALOS-2019-0818 attack attempt (more info ...)attempted-user 2019-5049   URL
49979FILE-OTHER TRUFFLEHUNTER TALOS-2019-0818 attack attempt (more info ...)attempted-user 2019-5049   URL
49982POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0822 attack attempt (more info ...)policy-violation    URL
49983POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0827 attack attempt (more info ...)policy-violation    URL
50008MALWARE-CNC Win.Doc.Dropper SectorB06 malicious rtf dropper download attempt (more info ...)trojan-activity 2018-0798   URL
50009MALWARE-CNC Win.Doc.Dropper SectorB06 malicious rtf dropper download attempt (more info ...)trojan-activity 2018-0798   URL
50010MALWARE-CNC Win.Trojan.SectorB06 malicious executable download attempt (more info ...)trojan-activity    URL
50011MALWARE-CNC Win.Trojan.SectorB06 malicious executable download attempt (more info ...)trojan-activity    URL
50012MALWARE-CNC Win.Trojan.SectorB06 malicious executable download attempt (more info ...)trojan-activity    URL
50013MALWARE-CNC Win.Trojan.SectorB06 malicious executable download attempt (more info ...)trojan-activity    URL
50028PUA-ADWARE Osx.Adware.TotalAdviseSearch variant download attempt (more info ...)misc-activity    
50029PUA-ADWARE Osx.Adware.TotalAdviseSearch variant download attempt (more info ...)misc-activity    
50030SERVER-WEBAPP Dojo Toolkit SDK cross site scripting attempt (more info ...)attempted-user 2010-2275   URL
50031SERVER-WEBAPP Dojo Toolkit SDK cross site scripting attempt (more info ...)attempted-user 2010-2275   URL
50032SERVER-WEBAPP Dojo Toolkit SDK cross site scripting attempt (more info ...)attempted-user 2010-2275   URL
50035FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0821 attack attempt (more info ...)attempted-user 2019-5052   URL
50036FILE-IMAGE TRUFFLEHUNTER TALOS-2019-0821 attack attempt (more info ...)attempted-user 2019-5052   URL
50038FILE-PDF TRUFFLEHUNTER TALOS-2019-0819 attack attempt (more info ...)attempted-user 2019-5050   URL
50039FILE-PDF TRUFFLEHUNTER TALOS-2019-0819 attack attempt (more info ...)attempted-user 2019-5050   URL
50040SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0831 attack attempt (more info ...)attempted-dos 2019-5054   URL
50048MALWARE-CNC Win.Dropper.Fareit variant outbound connection (more info ...)trojan-activity    URL
50049MALWARE-CNC Win.Dropper.FormBook variant outbound connection (more info ...)trojan-activity    URL
50050MALWARE-CNC Win.Trojan.Pirpi malicious executable download attempt (more info ...)trojan-activity    URL
50051MALWARE-CNC Win.Trojan.Pirpi malicious executable download attempt (more info ...)trojan-activity    URL
50052MALWARE-CNC Win.Trojan.Pirpi malicious executable download attempt (more info ...)trojan-activity    URL
50053MALWARE-CNC Win.Trojan.Pirpi malicious executable download attempt (more info ...)trojan-activity    URL
50054MALWARE-CNC Win.Trojan.HTran malicious executable download attempt (more info ...)trojan-activity    URL
50055MALWARE-CNC Win.Trojan.HTran malicious executable download attempt (more info ...)trojan-activity    URL
50056MALWARE-CNC Win.Trojan.Buckeye malicious executable download attempt (more info ...)trojan-activity    URL
50057MALWARE-CNC Win.Trojan.Buckeye malicious executable download attempt (more info ...)trojan-activity    URL
50058MALWARE-CNC Win.Trojan.Filensfer malicious executable download attempt (more info ...)trojan-activity    URL
50059MALWARE-CNC Win.Trojan.Filensfer malicious executable download attempt (more info ...)trojan-activity    URL
50060MALWARE-CNC Win.Trojan.Buckeye malicious executable download attempt (more info ...)trojan-activity    URL
50061MALWARE-CNC Win.Trojan.Buckeye malicious executable download attempt (more info ...)trojan-activity    URL
50062MALWARE-CNC Win.Trojan.Filensfer malicious executable download attempt (more info ...)trojan-activity    URL
50063MALWARE-CNC Win.Trojan.Filensfer malicious executable download attempt (more info ...)trojan-activity    URL
50064MALWARE-CNC Win.Trojan.Filensfer variant outbound connection (more info ...)trojan-activity    URL
50067MALWARE-CNC Win.Trojan.CrackXTSR variant outbound response attempt (more info ...)trojan-activity    URL
50092MALWARE-CNC Win.Trojan.Filensfer connection attempt (more info ...)trojan-activity    
50107MALWARE-CNC Win.Trojan.Agent variant outbound cnc connection (more info ...)trojan-activity    URL
50108MALWARE-CNC Win.Trojan.Agent variant outbound cnc connection (more info ...)trojan-activity    URL
50109MALWARE-CNC Win.Trojan.Agent variant outbound cnc connection (more info ...)trojan-activity    URL
50110SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0836 attack attempt (more info ...)web-application-attack    URL
50111SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0839 attack attempt (more info ...)attempted-recon    URL
50114SERVER-WEBAPP TRUFFLEHUNTER TALOS-2019-0833 attack attempt (more info ...)web-application-attack    URL
50125MALWARE-CNC Win.Trojan.Kpot variant outbound connection (more info ...)trojan-activity    URL
50138MALWARE-CNC Win.Dropper.ELECTRICFISH variant outbound connection (more info ...)trojan-activity    URL
50145SERVER-WEBAPP CAS Server LDAP authentication bypass attempt (more info ...)attempted-user 2015-1169   URL
50148SERVER-WEBAPP SirsiDynix e-Library cross site scripting attempt (more info ...)attempted-user 2018-20503   URL
50149SERVER-WEBAPP SirsiDynix e-Library cross site scripting attempt (more info ...)attempted-user 2018-20503   URL
50154MALWARE-CNC Win.Malware.JasperLoader variant outbound connection (more info ...)trojan-activity    URL
50155MALWARE-CNC Win.Download.JasperLoader variant initial stage download request (more info ...)trojan-activity    URL
50156MALWARE-CNC Win.Malware.JasperLoader variant outbound connection (more info ...)trojan-activity    URL
50157MALWARE-CNC Win.Download.JasperLoader variant file download request (more info ...)trojan-activity    URL
50158MALWARE-CNC Win.Download.JasperLoader variant file download request (more info ...)trojan-activity    URL
50159MALWARE-CNC Win.Download.JasperLoader variant initial stage download request (more info ...)trojan-activity    URL
50160BROWSER-WEBKIT Apple Webkit SVGTextLayoutAttributes use-after-free attempt (more info ...)attempted-user 2018-4318   URL
50161BROWSER-WEBKIT Apple Webkit SVGTextLayoutAttributes use-after-free attempt (more info ...)attempted-user 2018-4318   URL
50172SERVER-WEBAPP Allied Telesis 8100L cross site scripting attempt (more info ...)attempted-user 2018-20503   
50173SERVER-WEBAPP Allied Telesis 8100L cross site scripting attempt (more info ...)attempted-user 2018-20503   
50177MALWARE-CNC Win.Trojan.Buckeye malicious executable download attempt (more info ...)trojan-activity    URL
50178MALWARE-CNC Win.Trojan.Buckeye malicious executable download attempt (more info ...)trojan-activity    URL
50179MALWARE-CNC Win.Trojan.Buckeye malicious executable download attempt (more info ...)trojan-activity    URL
50180MALWARE-CNC Win.Trojan.Buckeye malicious executable download attempt (more info ...)trojan-activity    URL
50191BROWSER-WEBKIT Apple Webkit updateMinimumColumnHeight use-after-free attempt (more info ...)attempted-user 2018-4323   URL
50192BROWSER-WEBKIT Apple Webkit updateMinimumColumnHeight use-after-free attempt (more info ...)attempted-user 2018-4323   URL
50193POLICY-OTHER Intel AMT IDE Redirection session establishment attempt (more info ...)policy-violation    URL
50200MALWARE-CNC Win.Trojan.Remexi variant outbound connection (more info ...)trojan-activity    URL
50201MALWARE-CNC Win.Trojan.Remexi variant outbound connection (more info ...)trojan-activity    URL
50203MALWARE-CNC Win.Trojan.OceanLotus variant outbound connection (more info ...)trojan-activity    
50204MALWARE-CNC Win.Trojan.OceanLotus variant outbound connection (more info ...)trojan-activity    
50215MALWARE-CNC Win.Trojan.Reaver malicious executable download attempt (more info ...)trojan-activity    URL
50216MALWARE-CNC Win.Trojan.Reaver variant outbound connection attempt (more info ...)trojan-activity    URL
50217MALWARE-CNC Win.Trojan.Reaver malicious executable download attempt (more info ...)trojan-activity    URL
50218MALWARE-CNC Win.Trojan.Reaver malicious executable download attempt (more info ...)trojan-activity    URL
50219MALWARE-CNC Win.Trojan.Reaver malicious executable download attempt (more info ...)trojan-activity    URL
50258MALWARE-CNC Win.Downloader.TeamBot outbound cnc connection (more info ...)trojan-activity    URL
50259MALWARE-CNC Win.Trojan.TeamBot outbound cnc connection (more info ...)trojan-activity    URL
50260MALWARE-CNC Win.Downloader.TeamBot additional payload download attempt (more info ...)trojan-activity    URL
50261MALWARE-CNC Win.Trojan.TeamBot outbound cnc connection (more info ...)trojan-activity    URL
50262MALWARE-CNC Win.Downloader.TeamBot additional payload download attempt (more info ...)trojan-activity    URL
50263MALWARE-CNC Win.Trojan.TeamBot outbound cnc connection (more info ...)trojan-activity    URL
50264MALWARE-CNC Win.Downloader.TeamBot outbound cnc connection (more info ...)trojan-activity    URL
50300MALWARE-CNC Win.Trojan.TRITON attack tool outbound connection (more info ...)trojan-activity    
50301MALWARE-CNC Win.Trojan.TRITON attack tool outbound connection (more info ...)trojan-activity    
50302MALWARE-CNC Win.Trojan.TRITON attack tool outbound connection (more info ...)trojan-activity    URL
50303MALWARE-CNC Win.Trojan.TRITON attack tool outbound connection (more info ...)trojan-activity    URL
50306SERVER-WEBAPP OpenDreamBox 2.0.0 Plugin WebAdmin command injection attempt (more info ...)web-application-attack 2017-14135   
50380MALWARE-CNC Win.Trojan.PlugX variant outbound connection (more info ...)trojan-activity    URL
50381MALWARE-CNC Win.Trojan.Quasar variant outbound connection (more info ...)trojan-activity    URL
50382MALWARE-CNC Win.Trojan.Quasar variant outbound connection (more info ...)trojan-activity    URL
50383MALWARE-CNC Win.Trojan.Quasar variant outbound connection (more info ...)trojan-activity    URL
50384POLICY-OTHER Remote Command Executor remote administration tool use attempt (more info ...)policy-violation    URL
50385POLICY-OTHER Remote Command Executor remote administration tool use attempt (more info ...)policy-violation    URL
50386MALWARE-CNC MultiOS.Backdoor.Antak webshell access attempt (more info ...)trojan-activity    URL
50387MALWARE-CNC MultiOS.Backdoor.Antak webshell communication attempt (more info ...)trojan-activity    URL
50388MALWARE-CNC MultiOS.Backdoor.Antak webshell communication attempt (more info ...)trojan-activity    URL
50389MALWARE-CNC MultiOS.Backdoor.Termite communication attempt (more info ...)trojan-activity    URL
50415SERVER-WEBAPP Infomir Ministra authentication bypass attempt (more info ...)web-application-attack    URL
50416MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
50417MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
50418MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
50419MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
50420MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
50421MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
50422MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
50423MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
50424MALWARE-CNC User-Agent known malicious user agent - BURAN - Win.Trojan.Buran (more info ...)trojan-activity    URL
50425MALWARE-CNC Win.Trojan.Buran malicious Buran ransomware download attempt (more info ...)trojan-activity    URL
50426MALWARE-CNC Win.Trojan.Buran malicious Buran ransomware download attempt (more info ...)trojan-activity    URL
50429MALWARE-CNC Andr.Spyware.Reptilicus variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50430MALWARE-CNC Andr.Spyware.Reptilicus variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50431MALWARE-CNC Andr.Spyware.Reptilicus variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50432MALWARE-CNC Andr.Spyware.Reptilicus variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50433MALWARE-CNC Andr.Spyware.Reptilicus variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50434MALWARE-CNC Andr.Spyware.Reptilicus variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50435MALWARE-CNC Andr.Spyware.iSpyoo variant post-compromise outbound connection (more info ...)trojan-activity    URL
50436MALWARE-CNC Andr.Spyware.iSpyoo variant post-compromise outbound connection (more info ...)trojan-activity    URL
50437MALWARE-CNC Andr.Spyware.iSpyoo variant post-compromise outbound connection (more info ...)trojan-activity    URL
50438MALWARE-CNC Andr.Spyware.iSpyoo variant post-compromise outbound connection (more info ...)trojan-activity    URL
50439MALWARE-CNC Andr.Spyware.iSpyoo variant post-compromise outbound connection (more info ...)trojan-activity    URL
50440MALWARE-CNC Win.Malware.Ramnit inbound VERIFY_HOST response (more info ...)trojan-activity    URL
50445MALWARE-CNC Win.Downloader.TeamBot additional payload download attempt (more info ...)trojan-activity    URL
50446MALWARE-CNC Win.Downloader.TeamBot outbound cnc connection (more info ...)trojan-activity    URL
50451FILE-OTHER VMWare OVF Tool format string exploit attempt (more info ...)attempted-user 2012-3569 56468  URL
50453FILE-IMAGE Directshow GIF logical width overflow attempt (more info ...)attempted-user 2013-3174   
50454FILE-IMAGE Directshow GIF logical height overflow attempt (more info ...)attempted-user 2013-3174   
50480MALWARE-CNC Andr.Spyware.Catwatchful variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50481MALWARE-CNC Andr.Spyware.Catwatchful variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50482MALWARE-CNC Andr.Spyware.Catwatchful variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50483MALWARE-CNC Andr.Spyware.Catwatchful client app variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50484MALWARE-CNC Andr.Spyware.Catwatchful client app variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50493MALWARE-CNC Andr.Spyware.AppSpy variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50494MALWARE-CNC Andr.Spyware.AppSpy variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
50497MALWARE-CNC Win.Trojan.Waterbug variant outbound connection (more info ...)trojan-activity    
50498MALWARE-CNC Win.Trojan.Netwire variant payload download attempt (more info ...)trojan-activity    URL
50501MALWARE-CNC Win.Coinminer.Vools variant outbound connection (more info ...)trojan-activity    URL
50516PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0849 attack attempt (more info ...)attempted-dos 2019-5061   URL
50520MALWARE-CNC Doc.Malware.HWPRokrat variant outbound connection (more info ...)trojan-activity    URL
50521MALWARE-CNC Doc.Malware.HWPRokrat variant outbound connection (more info ...)trojan-activity    URL
50523MALWARE-CNC Win.Trojan.Scranos variant outbound connection (more info ...)trojan-activity    URL
50524MALWARE-CNC Win.Trojan.Scranos variant outbound connection (more info ...)trojan-activity    URL
50525MALWARE-CNC Win.Trojan.Scranos variant outbound connection (more info ...)trojan-activity    URL
50526MALWARE-CNC Win.Trojan.Scranos variant payload download attempt (more info ...)trojan-activity    URL
50527MALWARE-CNC Win.Trojan.Scranos variant payload download attempt (more info ...)trojan-activity    URL
50528MALWARE-CNC Win.Trojan.Scranos variant payload download attempt (more info ...)trojan-activity    URL
50529MALWARE-CNC Win.Trojan.Scranos variant outbound connection (more info ...)trojan-activity    URL
50530MALWARE-CNC Win.Trojan.Scranos variant outbound connection (more info ...)trojan-activity    URL
50531MALWARE-CNC Win.Trojan.Scranos variant outbound attempt (more info ...)trojan-activity    URL
50532MALWARE-CNC Win.Trojan.Scranos variant outbound connection (more info ...)trojan-activity    URL
50621MALWARE-CNC Win.Coinminer.Vools variant outbound connection (more info ...)trojan-activity    URL
50623FILE-OTHER ZIP file directory traversal attempt (more info ...)attempted-user 2019-1889   URL
50624FILE-OTHER ZIP file directory traversal attempt (more info ...)attempted-user 2019-1889   URL
50634MALWARE-CNC Win.Ransomware.Matrix variant outbound connection (more info ...)trojan-activity    URL
50635MALWARE-CNC Win.Ransomware.Matrix variant download attempt (more info ...)trojan-activity    URL
50636MALWARE-CNC Win.Ransomware.Matrix variant download attempt (more info ...)trojan-activity    URL
50654SERVER-WEBAPP Sitefinity WCMS cross site scripting attempt (more info ...)attempted-user 2018-17054   URL
50655SERVER-WEBAPP Sitefinity WCMS cross site scripting attempt (more info ...)attempted-user 2018-17056   URL
50656SERVER-WEBAPP Sitefinity WCMS cross-site scripting attempt (more info ...)attempted-user 2018-17056   URL
50657SERVER-WEBAPP Sitefinity WCMS cross site scripting attempt (more info ...)attempted-user 2018-17054   URL
50658SERVER-WEBAPP Sitefinity WCMS arbitrary file upload attempt (more info ...)attempted-user 2018-17055   URL
50686MALWARE-CNC Win.Trojan.Swizzor variant outbound connection attempt (more info ...)trojan-activity    URL
50689MALWARE-CNC Win.Trojan.RoyalRoad APT campaign outbound connection (more info ...)trojan-activity    URL
50698MALWARE-CNC Win.Trojan.Beapy variant payload download attempt (more info ...)trojan-activity    URL
50699MALWARE-CNC Win.Trojan.Beapy variant outbound cnc connection (more info ...)trojan-activity    URL
50700MALWARE-CNC Win.Trojan.Beapy variant outbound cnc connection (more info ...)trojan-activity    URL
50701MALWARE-CNC Win.Trojan.Beapy variant payload download attempt (more info ...)trojan-activity    
50702MALWARE-CNC Win.Trojan.Beapy variant outbound cnc connection (more info ...)trojan-activity    URL
50703MALWARE-CNC Win.Trojan.Beapy variant outbound cnc connection (more info ...)trojan-activity    URL
50715MALWARE-CNC Win.Trojan.Trickbot sample download attempt (more info ...)trojan-activity    URL
50716MALWARE-CNC Win.Trojan.Plurox variant outbound connection (more info ...)trojan-activity    URL
50717MALWARE-CNC Win.Trojan.Plurox variant outbound connection (more info ...)trojan-activity    URL
50734MALWARE-CNC Andr.Trojan.Anubis variant outbound connection (more info ...)trojan-activity    URL
50735MALWARE-CNC Andr.Trojan.Anubis variant outbound connection (more info ...)trojan-activity    URL
50736MALWARE-CNC Andr.Trojan.Anubis variant outbound connection (more info ...)trojan-activity    URL
50737MALWARE-CNC Andr.Trojan.Anubis variant outbound connection (more info ...)trojan-activity    URL
50770PROTOCOL-OTHER TRUFFLEHUNTER TALOS-2019-0854 attack attempt (more info ...)attempted-recon 2019-5065   URL
50771MALWARE-CNC Win.Trojan.Azorult outbound connection (more info ...)trojan-activity    URL
50780POLICY-OTHER InduSoft Web Studio DBProcessCall remote connection open attempt (more info ...)policy-violation 2019-6545   
50781SERVER-OTHER InduSoft Web Studio remote code execution attempt (more info ...)attempted-admin 2019-6545   
50799MALWARE-CNC Win.Trojan.SoftCell variant outbound connection (more info ...)trojan-activity    URL
50800MALWARE-CNC Win.Trojan.Ratsnif variant outbound connection (more info ...)trojan-activity    URL
50804POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0866 attack attempt (more info ...)policy-violation    URL
50805POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0868 attack attempt (more info ...)policy-violation    URL
50871SERVER-OTHER Quagga telnet CLI buffer overflow attempt (more info ...)denial-of-service 2017-5495   
50880SERVER-WEBAPP awstats.pl configdir command injection attempt (more info ...)web-application-attack 2005-0116   
50881SERVER-WEBAPP awstats.pl configdir command injection attempt (more info ...)web-application-attack 2005-0116   
50882SERVER-WEBAPP awstats.pl configdir command injection attempt (more info ...)web-application-attack 2005-0116   
50886SERVER-WEBAPP HPE System Management Homepage cross site scripting attempt (more info ...)attempted-user 2017-12544   URL
50887SERVER-WEBAPP HPE System Management Homepage cross site scripting attempt (more info ...)attempted-user 2017-12544   URL
50901SERVER-OTHER OpenBSD ISAKMP denial of service attempt (more info ...)denial-of-service 2004-0222   
50912SERVER-WEBAPP Subsonic Subscribe to Podcast cross site scripting attempt (more info ...)attempted-user 2017-9414   
50913SERVER-OTHER nfs-utils TCP connection termination denial-of-service attempt (more info ...)denial-of-service 2004-1014   
50914SERVER-OTHER Blue Coat BCAAA buffer overflow attempt (more info ...)attempted-admin 2011-5124   URL
50915SERVER-WEBAPP Belkin N150 abitrary file read attempt (more info ...)web-application-attack 2014-2962   
50916SERVER-WEBAPP Belkin N150 abitrary file read attempt (more info ...)web-application-attack 2014-2962   
50917SERVER-WEBAPP Belkin N150 abitrary file read attempt (more info ...)web-application-attack 2014-2962   
50918SERVER-WEBAPP Git client path validation command execution attempt (more info ...)attempted-user 2014-9390   
50921SERVER-WEBAPP Oracle 9i Application Server OWA_UTIL information disclosure attempt (more info ...)web-application-attack 2002-0560   URL
50934MALWARE-CNC Win.Malware.Lookback outbound connection to a known URI path (more info ...)trojan-activity    URL
50935MALWARE-CNC Win.Malware.Lookback outbound connection (more info ...)trojan-activity    URL
50944FILE-OTHER VideoLAN VLC media player out-of-bounds read attempt (more info ...)attempted-user 2018-19857   URL
50945FILE-OTHER VideoLAN VLC media player out-of-bounds read attempt (more info ...)attempted-user 2018-19857   URL
50946SERVER-OTHER GnuTLS x509 certificate validation policy bypass attempt (more info ...)attempted-user 2014-0092   
50958SERVER-OTHER Chicken of the VNC ServerInit denial of service attempt (more info ...)denial-of-service 2007-0756   
50965FILE-MULTIMEDIA MPlayer SMI file buffer overflow attempt (more info ...)attempted-user  49149  
50975FILE-OTHER OMRON CX-One arbitrary code execution attempt (more info ...)attempted-user 2018-18993   URL
50976FILE-OTHER OMRON CX-One arbitrary code execution attempt (more info ...)attempted-user 2018-18993   URL
50989MALWARE-CNC Win.Dropper.Clipbanker variant outbound connection (more info ...)trojan-activity    URL
50997SERVER-OTHER Network Time Server denial of service attempt (more info ...)denial-of-service 2018-7658   
51017PROTOCOL-OTHER Losant Arduino MQTT Client buffer overflow attempt (more info ...)attempted-user 2018-17614   URL
51018SERVER-OTHER DualDesk v20 Proxy.exe long string denial of service attempt (more info ...)attempted-dos 2018-7583   
51024FILE-IDENTIFY Embedded Open Type Font file attachment detected (more info ...)misc-activity    
51031SERVER-WEBAPP Symantec Endpoint Protection cross site scripting attempt (more info ...)web-application-attack 2014-3438   
51032SERVER-WEBAPP Symantec Endpoint Protection cross site scripting attempt (more info ...)attempted-user 2014-3438   
51033MALWARE-CNC Win.Dropper.Clipbanker file download attempt (more info ...)trojan-activity    URL
51042SERVER-OTHER ZeroMQ libzmq pointer overflow attempt (more info ...)attempted-user 2019-6250   URL
51043MALWARE-CNC Win.Trojan.Lazarus variant outbound connection (more info ...)trojan-activity    URL
51044MALWARE-CNC Win.Trojan.Lazarus variant outbound connection (more info ...)trojan-activity    URL
51047FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51048FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51049FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51050FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51051FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51052FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51053FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51054FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51055FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51056FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51057FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51058FILE-OTHER Gitlab directory traversal attempt (more info ...)attempted-user 2018-14364   URL
51072FILE-OTHER CA Products AV Engine CHM file handling denial of service attempt (more info ...)attempted-dos 2007-3875   
51073FILE-OTHER CA Products AV Engine CHM file handling denial of service attempt (more info ...)attempted-dos 2007-3875   
51094FILE-IMAGE Multiple products JBIG compressed TIFF buffer overflow attempt (more info ...)attempted-user 2018-18557   
51095FILE-IMAGE Multiple products JBIG compressed TIFF buffer overflow attempt (more info ...)attempted-user 2018-18557   
51096FILE-IMAGE Multiple products JBIG compressed TIFF buffer overflow attempt (more info ...)attempted-user 2018-18557   
51097FILE-IMAGE Multiple products JBIG compressed TIFF buffer overflow attempt (more info ...)attempted-user 2018-18557   
51104PROTOCOL-OTHER Eclipse MQTT Message Broker Topic denial of service attempt (more info ...)denial-of-service 2017-7650   
51111OS-OTHER VxWorks TCP URG memory corruption attempt (more info ...)attempted-admin 2019-12261   URL
51112MALWARE-CNC Win.Spyware.StrongPity outbound connection (more info ...)trojan-activity    URL
51113MALWARE-CNC Win.Spyware.StrongPity outbound connection (more info ...)trojan-activity    URL
51114MALWARE-CNC Win.Spyware.StrongPity outbound connection (more info ...)trojan-activity    URL
51115MALWARE-CNC Win.Spyware.StrongPity outbound connection (more info ...)trojan-activity    URL
51116MALWARE-CNC Win.Spyware.StrongPity outbound connection (more info ...)trojan-activity    URL
51117MALWARE-CNC Win.Coinminer.PCASTLE outbound connection (more info ...)trojan-activity    URL
51128MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51129MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51130MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51131MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51132MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51133MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51134MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51135MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51136MALWARE-CNC Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51137MALWARE-CNC edit Andr.Spyware.SpyPhoneApp variant post-compromise outbound connection detected (more info ...)trojan-activity    URL
51141SERVER-OTHER Oracle Tuxedo Jolt server heap overflow attempt (more info ...)attempted-user 2017-10278   
51144SERVER-OTHER ISC BIND multiple ENDS Key Tag options denial of service attempt (more info ...)denial-of-service 2018-5744   
51145SERVER-OTHER HPE Intelligent Management Center 10001 buffer overflow attempt (more info ...)attempted-user 2018-7115   
51146SERVER-WEBAPP FasterXML Jackson Databind unsafe deserialization attempt (more info ...)attempted-user 2018-7489   
51148SERVER-WEBAPP ManageEngine Desktop Central cross site scripting attempt (more info ...)attempted-user 2018-16833   
51149SERVER-WEBAPP ManageEngine Desktop Central cross site scripting attempt (more info ...)attempted-user 2018-16833   
51174SERVER-WEBAPP vCard Create Card cross site scripting attempt (more info ...)attempted-user 2006-1230   
51175SERVER-WEBAPP vCard Create Card cross site scripting attempt (more info ...)attempted-user 2006-1230   
51176SERVER-WEBAPP vCard Toprated cross site scripting attempt (more info ...)attempted-user 2006-1230   
51177SERVER-WEBAPP vCard Toprated cross site scripting attempt (more info ...)attempted-user 2006-1230   
51178SERVER-WEBAPP vCard New Card cross site scripting attempt (more info ...)attempted-user 2006-1230   
51179SERVER-WEBAPP vCard New Card cross site scripting attempt (more info ...)attempted-user 2006-1230   
51181SERVER-OTHER NTPsec ntp_control out-of-bounds read attempt (more info ...)attempted-user 2019-6444   URL
51191FILE-OTHER OMRON CX-One MCI file stack buffer overflow attempt (more info ...)attempted-user 2018-7541   URL
51192FILE-OTHER OMRON CX-One MCI file stack buffer overflow attempt (more info ...)attempted-user 2018-7541   URL
51209SERVER-WEBAPP Forum Livre busca2.asp cross site scripting attempt (more info ...)attempted-user 2007-0589   URL
51210SERVER-WEBAPP Forum Livre busca2.asp cross site scripting attempt (more info ...)attempted-user 2007-0589   URL
51215SERVER-OTHER OpenSSL DTLS zero-length fragments denial of service attempt (more info ...)attempted-dos 2014-3507   
51217FILE-OTHER Omron CX-On Project file parsing heap buffer overflow attempt (more info ...)attempted-user 2018-8834   
51218FILE-OTHER Omron CX-On Project file parsing heap buffer overflow attempt (more info ...)attempted-user 2018-8834   
51219OS-OTHER OpenBSD TCP Timestamp handling denial of service attempt (more info ...)denial-of-service 2005-0740   
51234SERVER-OTHER Advantech WebAccess Viewdll1 buffer overflow attempt (more info ...)attempted-user 2018-8845   
51235FILE-OTHER VCFtools crafted VCF remote code execution attempt (more info ...)attempted-user 2018-11130   URL
51236FILE-OTHER VCFtools crafted VCF remote code execution attempt (more info ...)attempted-user 2018-11130   URL
51237SERVER-OTHER BlackIce ISS ICQ parser buffer overflow attempt (more info ...)attempted-admin 2004-0362   URL
51264SERVER-WEBAPP Open-AudIT Community Store cross site scripting attempt (more info ...)attempted-user 2018-14493   URL
51265SERVER-WEBAPP Open-AudIT Community Store cross site scripting attempt (more info ...)attempted-user 2018-14493   URL
51281SERVER-WEBAPP Webadmin history parameter cross site scripting attempt (more info ...)attempted-user 2018-19191   URL
51282SERVER-WEBAPP Webadmin history parameter cross site scripting attempt (more info ...)attempted-user 2018-19191   URL
51283SERVER-WEBAPP Webadmin history parameter cross site scripting attempt (more info ...)web-application-attack 2018-9250   URL
51284FILE-IMAGE Nokia N95 JPG parsing denial of service attempt (more info ...)attempted-user    URL
51285FILE-IMAGE Nokia N95 JPG parsing denial of service attempt (more info ...)attempted-user    URL
51286SERVER-OTHER LCDproc parse_all_client_messages buffer overflow attempt (more info ...)attempted-admin 2004-1915   
51290OS-MOBILE Google Android Kernel local denial of service attempt (more info ...)denial-of-service 2013-1773   URL
51291OS-MOBILE Google Android Kernel local denial of service attempt (more info ...)denial-of-service 2013-1773   URL
51296PROTOCOL-OTHER Colloquy INVITE request format string DoS attempt (more info ...)attempted-user 2007-0344   URL
51297PROTOCOL-OTHER Colloquy INVITE request format string DoS attempt (more info ...)attempted-user 2007-0344   URL
51301SERVER-OTHER Exim malformed BDAT code execution attempt (more info ...)attempted-admin 2017-16943   
51309MALWARE-CNC Win.Trojan.Pistacchietto variant outbound connection (more info ...)trojan-activity    URL
51312SERVER-WEBAPP WSO2 Carbon persistent cross site scripting attempt (more info ...)attempted-user 2018-8716   URL
51319SERVER-OTHER Mosca MQTT broker regular expression denial of service attempt (more info ...)denial-of-service 2018-11615   
51320MALWARE-CNC Win.Trojan.BlackMoon variant outbound connection (more info ...)trojan-activity    URL
51331SERVER-WEBAPP GoAhead Embedded Web Server use after free attempt (more info ...)attempted-admin 2019-5096   URL
51332SERVER-WEBAPP GoAhead Embedded Web Server use after free attempt (more info ...)attempted-admin 2019-5096   URL
51342MALWARE-CNC User-Agent known malicious user-agent string - Nemty (more info ...)trojan-activity    URL
51347SERVER-OTHER OpenSSL TLS anomalous ascii session ticket (more info ...)attempted-dos 2014-3567   URL
51348SERVER-OTHER OpenSSL TLS anomalous ascii session ticket (more info ...)attempted-dos 2014-3567   URL
51349SERVER-OTHER OpenSSL TLS anomalous ascii session ticket (more info ...)attempted-dos 2014-3567   URL
51350SERVER-OTHER OpenSSL TLS anomalous ascii session ticket (more info ...)attempted-dos 2014-3567   URL
51351SERVER-OTHER OpenSSL TLS anomalous ascii client session ticket (more info ...)attempted-dos 2014-3567   URL
51352SERVER-OTHER OpenSSL TLS anomalous ascii client session ticket (more info ...)attempted-dos 2014-3567   URL
51353SERVER-OTHER OpenSSL TLS anomalous ascii client session ticket (more info ...)attempted-dos 2014-3567   URL
51359SERVER-OTHER OpenSSL DTLS duplicate record denial of service attempt (more info ...)denial-of-service 2015-0206   
51360MALWARE-CNC Win.Ransomware.LooCipher variant outbound connection (more info ...)trojan-activity    URL
51400SERVER-OTHER Heimdal KDC malformed as-req denial of service attempt (more info ...)denial-of-service 2017-17439   URL
51441SERVER-WEBAPP Laquis SCADA Nome command injection attempt (more info ...)web-application-attack 2018-18996   
51442SERVER-WEBAPP Laquis SCADA Nome command injection attempt (more info ...)web-application-attack 2018-18996   
51443SERVER-WEBAPP Laquis SCADA Nome command injection attempt (more info ...)web-application-attack 2018-18996   
51444SERVER-WEBAPP Laquis SCADA Nome command injection attempt (more info ...)web-application-attack 2018-18996   
51471POLICY-OTHER Supermicro BMC Virtual Media service default credentials use attempt (more info ...)policy-violation    URL
51478SERVER-OTHER NFS server /etc/passwd symlink creation attempt (more info ...)misc-activity 2019-11538   
51495PROTOCOL-VOIP SIP Torture negative Content-Length attempt (more info ...)misc-activity    URL
51501PROTOCOL-VOIP SIP Torture overly large Warning header value attempt (more info ...)misc-activity    URL
51502PROTOCOL-VOIP SIP Torture invalid Date header time zone attempt (more info ...)misc-activity    URL
51503PROTOCOL-VOIP SIP Torture overly large Expires header value attempt (more info ...)misc-activity    URL
51505PROTOCOL-VOIP SIP Torture overly large CSeq header value attempt (more info ...)misc-activity    URL
51506PROTOCOL-VOIP SIP Torture invalid Proxy-Require header value attempt (more info ...)misc-activity    URL
51514PROTOCOL-VOIP SIP Torture overly large CSeq header value attempt (more info ...)misc-activity    URL
51532MALWARE-CNC Win.Trojan.BlackRAT variant outbound connection (more info ...)trojan-activity    URL
51533MALWARE-CNC Win.Trojan.BlackRAT variant inbound connection (more info ...)trojan-activity    URL
51539INDICATOR-SHELLCODE BSD x86 reverse connect shell (more info ...)shellcode-detect    
51540INDICATOR-SHELLCODE BSD x86 reverse connect shell (more info ...)shellcode-detect    
51541MALWARE-CNC Win.Trojan.ModularInstaller variant outbound connection detected (more info ...)trojan-activity    URL
51542MALWARE-CNC Win.Trojan.ModularInstaller variant outbound connection detected (more info ...)trojan-activity    URL
51543MALWARE-CNC Win.Trojan.ModularInstaller variant outbound connection detected (more info ...)trojan-activity    URL
51544MALWARE-CNC Win.Trojan.ModularInstaller variant outbound connection detected (more info ...)trojan-activity    URL
51545MALWARE-CNC Win.Trojan.ModularInstaller variant outbound connection detected (more info ...)trojan-activity    URL
51546MALWARE-CNC Win.Trojan.ModularInstaller variant outbound connection detected (more info ...)trojan-activity    URL
51548MALWARE-CNC Win.Malware.Divergent variant outbound connection (more info ...)trojan-activity    
51549MALWARE-CNC Win.Malware.Divergent variant outbound connection (more info ...)trojan-activity    
51550MALWARE-CNC Win.Malware.Divergent variant outbound connection (more info ...)trojan-activity    
51551MALWARE-CNC Win.Malware.Divergent variant outbound connection (more info ...)trojan-activity    
51552MALWARE-CNC Win.Malware.Divergent variant outbound connection (more info ...)trojan-activity    
51559SERVER-WEBAPP Ignite Realtime Openfire cross site scripting attempt (more info ...)attempted-user 2018-11688   URL
51560SERVER-WEBAPP Ignite Realtime Openfire cross site scripting attempt (more info ...)attempted-user 2018-11688   URL
51583SERVER-WEBAPP Lighttpd url-path-2f-decode denial of service attempt (more info ...)web-application-attack 2019-11072   URL
51593MALWARE-CNC Win.Adware.BrowserAssistant variant outbound connection (more info ...)trojan-activity    URL
51634MALWARE-CNC Win.Trojan.Ordinypt malicious executable download attempt (more info ...)trojan-activity    URL
51635MALWARE-CNC Win.Trojan.Ordinypt malicious executable download attempt (more info ...)trojan-activity    URL
51636MALWARE-CNC Win.Trojan.Amadey botnet outbound connection (more info ...)trojan-activity    URL
51642MALWARE-CNC Osx.Trojan.Gmera variant outbound connection (more info ...)trojan-activity    URL
51650POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0898 attack attempt (more info ...)policy-violation 2019-5107   URL
51651POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0896 attack attempt (more info ...)policy-violation 2019-5104   URL
51654POLICY-OTHER InduSoft Web Studio MTCheckFileFunctionsTimeout remote code execution attempt (more info ...)policy-violation 2018-17914   
51655SERVER-WEBAPP B-net Software cross site scripting attempt (more info ...)attempted-user 2006-0078   
51656SERVER-WEBAPP B-net Software cross site scripting attempt (more info ...)attempted-user 2006-0078   
51657SERVER-WEBAPP B-net Software cross site scripting attempt (more info ...)attempted-user 2006-0078   
51658SERVER-WEBAPP Responsive FileManager directory traversal attempt (more info ...)web-application-attack    URL
51659SERVER-WEBAPP Responsive FileManager directory traversal attempt (more info ...)web-application-attack    URL
51660SERVER-WEBAPP Responsive FileManager cross site scripting attempt (more info ...)attempted-user    URL
51661SERVER-WEBAPP Responsive FileManager directory traversal attempt (more info ...)web-application-attack    URL
51664SERVER-WEBAPP Cesanta Mongoose buffer overflow attempt (more info ...)web-application-attack 2019-12951   URL
51670MALWARE-CNC Win.Trojan.Silence variant outbound connection detected (more info ...)trojan-activity    URL
51671MALWARE-CNC Win.Trojan.Silence variant outbound connection detected (more info ...)trojan-activity    URL
51672MALWARE-CNC Andr.Trojan.Moonshine outbound connection (more info ...)trojan-activity    URL
51685SERVER-OTHER Symantec AMS Intel handler service overly large size1 dos attempt (more info ...)attempted-dos 2010-3268   
51720MALWARE-CNC Win.Trojan.Alreay malicious executable download attempt (more info ...)trojan-activity    URL
51721MALWARE-CNC Win.Trojan.Alreay malicious executable download attempt (more info ...)trojan-activity    URL
51722MALWARE-CNC Win.Trojan.Alreay malicious executable download attempt (more info ...)trojan-activity    URL
51723MALWARE-CNC Win.Trojan.Alreay malicious executable download attempt (more info ...)trojan-activity    URL
51725SERVER-WEBAPP HAProxy H2 Frame heap memory corruption attempt (more info ...)web-application-attack 2018-10184   
51726MALWARE-CNC Win.Trojan.Silence variant proxy connection detected (more info ...)trojan-activity    URL
51727MALWARE-CNC Win.Trojan.Silence variant proxy connection detected (more info ...)trojan-activity    URL
51743PROTOCOL-VOIP SIP Torture overly-large SIP response code attempt (more info ...)misc-activity    
51744PROTOCOL-VOIP SIP Torture request missing Call-ID header attempt (more info ...)misc-activity    
51745PROTOCOL-VOIP SIP Torture request invalid Content-Length attempt (more info ...)misc-activity    
51756PROTOCOL-VOIP SIP Torture overly large Warning header value attempt (more info ...)misc-activity    URL
51758PROTOCOL-VOIP SIP Torture invalid Proxy-Require header value attempt (more info ...)misc-activity    URL
51764PROTOCOL-VOIP SIP Torture request URI with atypical scheme attempt (more info ...)misc-activity    URL
51765PROTOCOL-VOIP SIP Torture overly large CSeq header value attempt (more info ...)misc-activity    URL
51766PROTOCOL-VOIP SIP Torture overly large Expires header value attempt (more info ...)misc-activity    URL
51768PROTOCOL-VOIP SIP Torture overly large CSeq header value attempt (more info ...)misc-activity    URL
51769PROTOCOL-VOIP SIP Torture unknown URI scheme in Contact field attempt (more info ...)misc-activity    URL
51770PROTOCOL-VOIP SIP Torture request Max-Forwards header of zero attempt (more info ...)misc-activity    URL
51771PROTOCOL-VOIP SIP Torture unknown Content-Type attempt (more info ...)misc-activity    URL
51772PROTOCOL-VOIP SIP Torture request missing Call-ID header attempt (more info ...)misc-activity    
51773PROTOCOL-VOIP SIP Torture request invalid Content-Length attempt (more info ...)misc-activity    
51774PROTOCOL-VOIP SIP Torture overly-large SIP response code attempt (more info ...)misc-activity    
51779SERVER-WEBAPP generic cross-site scripting attempt (more info ...)web-application-attack    
51908MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51909MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51910MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51911MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51912MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51913MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51914MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51915MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51916MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51917MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51918MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51919MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51920MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51921MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51922MALWARE-CNC Andr.Trojan.Gustuff variant outbound cnc connection (more info ...)trojan-activity    URL
51948POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0918 attack attempt (more info ...)policy-violation    URL
51962SERVER-OTHER multiple products HTTP GET request buffer overflow attempt (more info ...)attempted-user 2012-5876   
51963SERVER-OTHER multiple products HTTP GET request buffer overflow attempt (more info ...)attempted-user 2012-5876   
51964SERVER-OTHER multiple products HTTP OPTIONS request buffer overflow attempt (more info ...)attempted-user 2012-5876   
51965SERVER-OTHER Multiple products HTTP referer header buffer overflow attempt (more info ...)attempted-user 2012-5876   
51969MALWARE-TOOLS Win.Trojan.Emotet variant download attempt (more info ...)trojan-activity    URL
51970MALWARE-TOOLS Win.Trojan.Emotet variant download attempt (more info ...)trojan-activity    URL
51971MALWARE-CNC Win.Trojan.Emotet variant outbound beacon attempt (more info ...)trojan-activity    URL
51984SERVER-MAIL Mail.app AppleSingleDouble command execution attempt (more info ...)attempted-user 2016-0395   
51985SERVER-MAIL Mail.app AppleSingleDouble command execution attempt (more info ...)attempted-user 2016-0395   
52004MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
52005MALWARE-CNC Win.Trojan.OceanLotus variant download attempt (more info ...)trojan-activity    URL
52006SERVER-OTHER Eclipse Mosquitto MQTT SUBSCRIBE request topic parsing buffer overflow attempt (more info ...)attempted-user 2019-11779   
52012POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0927 attack attempt (more info ...)policy-violation 2019-5138   URL
52024SERVER-OTHER TRUFFLEHUNTER TALOS-2019-0932 attack attempt (more info ...)attempted-user 2019-5143   URL
52025SERVER-OTHER TRUFFLEHUNTER TALOS-2019-0932 attack attempt (more info ...)attempted-user 2019-5143   URL
52029MALWARE-CNC Win.Trojan.Emotet variant outbound beacon attempt (more info ...)trojan-activity    URL
52042SERVER-OTHER OpenSSL ECDH malformed Client Hello denial of service attempt (more info ...)denial-of-service 2011-3210   
52063FILE-OTHER PowerShell Empire python launcher download attempt (more info ...)trojan-activity    
52064FILE-OTHER PowerShell Empire python launcher download attempt (more info ...)trojan-activity    
52078SERVER-OTHER ISC BIND DHCP client DNAME resource record parsing denial of service attempt (more info ...)attempted-user 2016-8864   
52086POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0944 attack attempt (more info ...)policy-violation 2019-5153   URL
52087PROTOCOL-VOIP SIP Torture request embedded linear white space in URI attempt (more info ...)misc-activity    URL
52089PROTOCOL-VOIP SIP Torture request overly large Warning header value attempt (more info ...)misc-activity    URL
52090PROTOCOL-VOIP SIP Torture request overly large CSeq header value attempt (more info ...)misc-activity    URL
52091PROTOCOL-VOIP SIP Torture request embedded linear white space in URI attempt (more info ...)misc-activity    URL
52092PROTOCOL-VOIP SIP Torture request missing transaction identifier attempt (more info ...)misc-activity    URL
52093PROTOCOL-VOIP SIP Torture request overly large CSeq header value attempt (more info ...)misc-activity    URL
52094PROTOCOL-VOIP SIP Torture request overly large Warning header value attempt (more info ...)misc-activity    URL
52112SERVER-WEBAPP Git client path validation command execution attempt (more info ...)attempted-user 2014-9390   
52113FILE-OTHER Oracle Outside-In library CorelDRAW parsing integer overflow attempt (more info ...)attempted-user 2011-2264   
52114FILE-OTHER Oracle Outside-In library CorelDRAW parsing integer overflow attempt (more info ...)attempted-user 2011-2264   
52132FILE-OTHER Libmspack cabd_sys_read_block off-by-one heap overflow attempt (more info ...)attempted-user 2018-18584   URL
52133FILE-OTHER Libmspack cabd_sys_read_block off-by-one heap overflow attempt (more info ...)attempted-user 2018-18584   URL
52148MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)attempted-user    URL
52149MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)attempted-user    URL
52204PROTOCOL-SCADA MMS Confirmed-RequestPDU informationReport message (more info ...)protocol-command-decode    URL
52235SERVER-WEBAPP Wget HTTP non-200 negative chunk-size buffer overflow attempt (more info ...)web-application-attack 2017-13089 101592  URL
52238POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0954 attack attempt (more info ...)policy-violation 2019-5161   URL
52252MALWARE-CNC Win.Adware.DomaIQ variant outbound connection (more info ...)trojan-activity    URL
52253FILE-OTHER libexpat internal entity heap over-read attempt (more info ...)attempted-user 2019-15903   
52254FILE-OTHER libexpat internal entity heap over-read attempt (more info ...)attempted-user 2019-15903   
52255MALWARE-CNC Win.Trojan.PowerShell variant outbound connection (more info ...)trojan-activity    URL
52256MALWARE-CNC Win.Trojan.Dridex variant outbound connection (more info ...)trojan-activity    URL
52258MALWARE-CNC Win.Trojan.Dridex variant inbound connection (more info ...)trojan-activity    URL
52260MALWARE-CNC Js.Trojan.FakeUpdate outbound connection (more info ...)trojan-activity    URL
52262MALWARE-CNC Win.Trojan.Dridex variant inbound connection (more info ...)trojan-activity    URL
52263MALWARE-CNC Win.Trojan.Dridex variant inbound connection (more info ...)trojan-activity    URL
52264MALWARE-CNC Win.Trojan.Dridex variant inbound connection (more info ...)trojan-activity    URL
52274POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0951 attack attempt (more info ...)policy-violation 2019-5159   URL
52275POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0951 attack attempt (more info ...)policy-violation 2019-5159   URL
52278SERVER-WEBAPP Shenzhen TVT Digital Technology API OS command injection attempt (more info ...)attempted-admin    URL
52280POLICY-OTHER Shenzhen TVT Digital Technology API OS admin default credentials login attempt (more info ...)attempted-admin    URL
52281POLICY-OTHER Shenzhen TVT Digital Technology API OS telnet root default credentials login attempt (more info ...)attempted-admin    URL
52282POLICY-OTHER Shenzhen TVT Digital Technology API OS telnet root default credentials login attempt (more info ...)attempted-admin    URL
52287SERVER-OTHER Hummingbird InetD LPD buffer overflow attempt (more info ...)attempted-user 2005-1815   
52291SERVER-WEBAPP MDaemon auto responder remote code execution attempt (more info ...)attempted-user    URL
52292SERVER-WEBAPP MDaemon auto responder remote code execution attempt (more info ...)attempted-user    URL
52293SERVER-WEBAPP MDaemon auto responder remote code execution attempt (more info ...)attempted-user    URL
52294SERVER-WEBAPP MDaemon auto responder remote code execution attempt (more info ...)attempted-user    URL
52295SERVER-WEBAPP MDaemon auto responder remote code execution attempt (more info ...)attempted-user    URL
52296SERVER-WEBAPP MDaemon auto responder remote code execution attempt (more info ...)attempted-user    URL
52306FILE-IMAGE Mutiple products libpng extra row heap overflow attempt (more info ...)attempted-user 2010-1205   
52307FILE-IMAGE Mutiple products libpng extra row heap overflow attempt (more info ...)attempted-user 2010-1205   
52308MALWARE-CNC Win.Trojan.Ursnif malicious document download attempt (more info ...)trojan-activity    URL
52309MALWARE-CNC Win.Trojan.Ursnif malicious executable download attempt (more info ...)trojan-activity    URL
52310MALWARE-CNC Win.Trojan.Ursnif malicious executable download attempt (more info ...)trojan-activity    URL
52311MALWARE-CNC Win.Trojan.Ursnif malicious document download attempt (more info ...)trojan-activity    URL
52312FILE-IMAGE Imagemagick XBM tranformation information leak attempt (more info ...)attempted-recon 2018-16323   
52319FILE-OTHER VLC Media Player malformed APE buffer overflow attempt (more info ...)attempted-admin 2012-0904   
52327PROTOCOL-VOIP SIP Torture request missing transaction identifier attempt (more info ...)misc-activity    URL
52328SERVER-WEBAPP Asus RT-N10 Repeater Mode command injection attempt (more info ...)web-application-attack    URL
52329SERVER-WEBAPP Asus RT-N10 Repeater Mode command injection attempt (more info ...)web-application-attack    URL
52336MALWARE-CNC Win.Trojan.Hoplight variant binary download attempt (more info ...)trojan-activity    URL
52337MALWARE-CNC Win.Trojan.Hoplight variant binary download attempt (more info ...)trojan-activity    URL
52343SERVER-OTHER ISC BIND deny-answer-aliases denial of service attempt (more info ...)denial-of-service 2018-5740   
52344SERVER-OTHER ISC BIND deny-answer-aliases denial of service attempt (more info ...)denial-of-service 2018-5740   
52370PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime stack buffer overflow attempt (more info ...)attempted-admin 2011-4875   URL
52371PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime stack buffer overflow attempt (more info ...)attempted-admin 2011-4875   URL
52372SERVER-OTHER Alt-N MDaemon default credentials login attempt (more info ...)attempted-admin    URL
52393SERVER-OTHER LibVNCServer file transfer extension heap buffer overflow attempt (more info ...)attempted-user 2018-15127   URL
52394SERVER-OTHER LibVNCServer file transfer extension heap buffer overflow attempt (more info ...)attempted-user 2018-15127   URL
52395SERVER-OTHER LibVNCServer file transfer extension heap buffer overflow attempt (more info ...)attempted-user 2018-15127   URL
52396SERVER-OTHER LibVNCServer file transfer extension heap buffer overflow attempt (more info ...)attempted-user 2018-15127   URL
52397SERVER-OTHER LibVNCServer file transfer extension heap buffer overflow attempt (more info ...)attempted-user 2018-15127   URL
52398FILE-IMAGE Foxit Reader malformed GIF LZW minimum code size memory corruption attempt (more info ...)denial-of-service 2015-2790   
52399FILE-IMAGE Foxit Reader malformed GIF LZW minimum code size memory corruption attempt (more info ...)denial-of-service 2015-2790   
52407POLICY-OTHER TRUFFLEHUNTER TALOS-2019-0961 attack attempt (more info ...)policy-violation 2019-5186   URL
52445MALWARE-CNC Doc.Malware.Gamaredon variant outbound connection (more info ...)trojan-activity    URL
52450SERVER-OTHER Multiple products HTTP Host header buffer overflow attempt (more info ...)attempted-user 2020-8450   URL
52451MALWARE-CNC Win.Ransomware.Zeppelin outbound communication (more info ...)trojan-activity    URL
52501SERVER-OTHER ZeroMQ libzmq pointer overflow attempt (more info ...)attempted-user 2019-6250   URL
52514SERVER-WEBAPP Chimera Web Portal System cross site scripting attempt (more info ...)attempted-user 2006-0136 16113  
52515SERVER-WEBAPP Chimera Web Portal System cross site scripting attempt (more info ...)attempted-user 2006-0136 16113  
52548MALWARE-CNC Win.Trojan.XpertRAT inbound connection (more info ...)trojan-activity    URL
52549MALWARE-CNC Win.Trojan.XpertRAT outbound connection (more info ...)trojan-activity    URL
52612MALWARE-CNC Win.Trojan.AgentTesla variant outbound connection detected (more info ...)trojan-activity    URL
52613MALWARE-CNC Win.Trojan.AgentTesla variant outbound connection detected (more info ...)trojan-activity    URL
52614MALWARE-CNC Win.Trojan.Remcos variant outbound connection detected (more info ...)trojan-activity    URL
52623MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
52624MALWARE-CNC Win.Trojan.Agent variant outbound connection (more info ...)trojan-activity    URL
52625SERVER-OTHER OpenSSL anonymous ECDH denial of service attempt (more info ...)attempted-dos 2014-3470   
52626SERVER-OTHER OpenSSL anonymous ECDH denial of service attempt (more info ...)attempted-dos 2014-3470   
52636POLICY-OTHER HTTP PUT request for Default.aspx attempt (more info ...)misc-activity    
52665MALWARE-OTHER Win.Packed.Nymaim-7542552-1 download attempt (more info ...)trojan-activity    URL
52844MALWARE-CNC Win.Trojan.COMRat outbound communication attempt (more info ...)trojan-activity    URL
52845MALWARE-CNC Win.Trojan.COMRat outbound communication attempt (more info ...)trojan-activity    URL
52846MALWARE-CNC Win.Trojan.COMRat outbound communication attempt (more info ...)trojan-activity    URL
52847MALWARE-CNC Win.Trojan.COMRat outbound communication attempt (more info ...)trojan-activity    URL
52848MALWARE-CNC Win.Trojan.COMRat outbound communication attempt (more info ...)trojan-activity    URL
52849MALWARE-CNC Win.Trojan.COMRat outbound communication attempt (more info ...)trojan-activity    URL
53010POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1003 attack attempt (more info ...)policy-violation 2020-6081   URL
53015FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0987 attack attempt (more info ...)attempted-user 2020-6064   URL
53016FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0987 attack attempt (more info ...)attempted-user 2020-6064   URL
53017SERVER-WEBAPP NeoFrag CMS database information disclosure attempt (more info ...)misc-attack    URL
53021MALWARE-OTHER Win.Packed.Agen-7564562-0 download attempt (more info ...)trojan-activity    URL
53025MALWARE-OTHER Win.Trojan.VBGeneric-7564971-0 download attempt (more info ...)trojan-activity    URL
53029MALWARE-OTHER Win.Dropper.NetWire-7565106-0 download attempt (more info ...)trojan-activity    URL
53031MALWARE-CNC Win.Malware.Loda RAT beacon detected (more info ...)trojan-activity    URL
53032FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0986 attack attempt (more info ...)attempted-user 2020-6063   URL
53033FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0986 attack attempt (more info ...)attempted-user 2020-6063   URL
53034FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0986 attack attempt (more info ...)attempted-user 2020-6063   URL
53035FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0986 attack attempt (more info ...)attempted-user 2020-6063   URL
53036FILE-PDF TRUFFLEHUNTER TALOS-2020-0997 attack attempt (more info ...)attempted-user 2020-6074   URL
53037FILE-PDF TRUFFLEHUNTER TALOS-2020-0997 attack attempt (more info ...)attempted-user 2020-6074   URL
53038FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0990 attack attempt (more info ...)attempted-user 2020-6066   URL
53039FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0990 attack attempt (more info ...)attempted-user 2020-6066   URL
53040FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0990 attack attempt (more info ...)attempted-user 2020-6066   URL
53041FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0990 attack attempt (more info ...)attempted-user 2020-6066   URL
53042FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0990 attack attempt (more info ...)attempted-user 2020-6066   URL
53043FILE-IMAGE TRUFFLEHUNTER TALOS-2020-0990 attack attempt (more info ...)attempted-user 2020-6066   URL
53044SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-0984 attack attempt (more info ...)attempted-admin 2020-6061   URL
53045SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-0985 attack attempt (more info ...)attempted-dos 2020-6062   URL
53069POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1011 attack attempt (more info ...)policy-violation 2020-6091   URL
53070POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1011 attack attempt (more info ...)policy-violation 2020-6091   URL
53081POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1010 attack attempt (more info ...)policy-violation 2020-6090   URL
53102SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1002 attack attempt (more info ...)attempted-dos 2020-6079   URL
53103SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1002 attack attempt (more info ...)attempted-dos 2020-6080   URL
53107MALWARE-OTHER Win.Trojan.Snake malicious executable download attempt (more info ...)trojan-activity    URL
53108MALWARE-CNC Win.Trojan.Emotet variant outbound connection (more info ...)trojan-activity    URL
53112MALWARE-TOOLS Win.Dropper.WiryJMPer variant download attempt (more info ...)trojan-activity    URL
53113MALWARE-TOOLS Win.Dropper.WiryJMPer variant download attempt (more info ...)trojan-activity    URL
53140MALWARE-CNC Doc.Downloader.Carrotball variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53141MALWARE-CNC Win.Downloader.Carrotball variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53147MALWARE-CNC Win.Downloader.Agent variant payload download attempt (more info ...)trojan-activity    URL
53152MALWARE-CNC Win.Trojan.CrimsonRAT outbound connection (more info ...)trojan-activity    URL
53153MALWARE-CNC Win.Trojan.CrimsonRAT inbound command (more info ...)trojan-activity    URL
53154MALWARE-CNC Win.Trojan.ObliqueRAT outbound connection (more info ...)trojan-activity    URL
53155MALWARE-CNC Win.Trojan.ObliqueRAT outbound connection (more info ...)trojan-activity    URL
53199BROWSER-PLUGINS HP Sprinter Tidestone Formula One DefaultFontName buffer overflow attempt (more info ...)attempted-user 2014-2638   
53200BROWSER-PLUGINS HP Sprinter Tidestone Formula One DefaultFontName buffer overflow attempt (more info ...)attempted-user 2014-2638   
53201BROWSER-PLUGINS HP Sprinter Tidestone Formula One DefaultFontName buffer overflow attempt (more info ...)attempted-user 2014-2638   
53202BROWSER-PLUGINS HP Sprinter Tidestone Formula One DefaultFontName buffer overflow attempt (more info ...)attempted-user 2014-2638   
53204INDICATOR-OBFUSCATION Win.Dropper.Vivin download attempt (more info ...)trojan-activity    URL
53205INDICATOR-OBFUSCATION Win.Dropper.Vivin download attempt (more info ...)trojan-activity    URL
53210MALWARE-OTHER Win.Trojan.AZORult malicious executable download attempt (more info ...)trojan-activity    URL
53211MALWARE-OTHER Win.Trojan.AZORult malicious executable download attempt (more info ...)trojan-activity    URL
53225MALWARE-OTHER Win.Dropper.NetWire-7594896-0 download attempt (more info ...)trojan-activity    URL
53226MALWARE-OTHER Win.Dropper.NetWire-7594962-0 download attempt (more info ...)trojan-activity    URL
53227MALWARE-OTHER Win.Dropper.NetWire-7594897-0 download attempt (more info ...)trojan-activity    URL
53228MALWARE-OTHER Win.Dropper.NetWire-7594996-0 download attempt (more info ...)trojan-activity    URL
53229MALWARE-OTHER Win.Dropper.NetWire-7594931-0 download attempt (more info ...)trojan-activity    URL
53230MALWARE-OTHER Win.Dropper.NetWire-7594932-0 download attempt (more info ...)trojan-activity    URL
53231MALWARE-OTHER Win.Dropper.NetWire-7594898-0 download attempt (more info ...)trojan-activity    URL
53232MALWARE-OTHER Win.Dropper.NetWire-7594964-0 download attempt (more info ...)trojan-activity    URL
53233MALWARE-OTHER Win.Dropper.NetWire-7594899-0 download attempt (more info ...)trojan-activity    URL
53234MALWARE-OTHER Win.Dropper.NetWire-7594998-0 download attempt (more info ...)trojan-activity    URL
53235MALWARE-OTHER Win.Dropper.NetWire-7594965-0 download attempt (more info ...)trojan-activity    URL
53236MALWARE-OTHER Win.Dropper.NetWire-7594933-0 download attempt (more info ...)trojan-activity    URL
53237MALWARE-OTHER Win.Dropper.NetWire-7594999-0 download attempt (more info ...)trojan-activity    URL
53238MALWARE-OTHER Win.Dropper.NetWire-7594966-0 download attempt (more info ...)trojan-activity    URL
53239MALWARE-OTHER Win.Dropper.NetWire-7595000-0 download attempt (more info ...)trojan-activity    URL
53240MALWARE-OTHER Win.Dropper.NetWire-7594967-0 download attempt (more info ...)trojan-activity    URL
53243MALWARE-OTHER Win.Dropper.NetWire-7594977-0 download attempt (more info ...)trojan-activity    URL
53244MALWARE-OTHER Win.Dropper.NetWire-7594972-0 download attempt (more info ...)trojan-activity    URL
53259MALWARE-OTHER Win.Dropper.NetWire-7594928-0 download attempt (more info ...)trojan-activity    URL
53265FILE-PDF TRUFFLEHUNTER TALOS-2020-1014 attack attempt (more info ...)attempted-user 2020-6093   URL
53266FILE-PDF TRUFFLEHUNTER TALOS-2020-1014 attack attempt (more info ...)attempted-user 2020-6093   URL
53267MALWARE-OTHER Win.Dropper.NetWire-7594994-0 download attempt (more info ...)trojan-activity    URL
53270MALWARE-OTHER Win.Packed.Generic-7596403-0 download attempt (more info ...)trojan-activity    URL
53271MALWARE-OTHER Win.Worm.Zeroll-7596404-0 download attempt (more info ...)trojan-activity    URL
53272MALWARE-OTHER Win.Packed.Gamarue-7596406-0 download attempt (more info ...)trojan-activity    URL
53273MALWARE-OTHER Win.Dropper.NetWire-7597058-0 download attempt (more info ...)trojan-activity    URL
53275MALWARE-OTHER Win.Worm.Zeroll-7596408-0 download attempt (more info ...)trojan-activity    URL
53277MALWARE-OTHER Win.Worm.Zeroll-7596409-0 download attempt (more info ...)trojan-activity    URL
53279MALWARE-OTHER Win.Packed.Generic-7596410-0 download attempt (more info ...)trojan-activity    URL
53282MALWARE-OTHER Win.Worm.Zeroll-7596435-0 download attempt (more info ...)trojan-activity    URL
53287MALWARE-OTHER Win.Worm.Zeroll-7596437-0 download attempt (more info ...)trojan-activity    URL
53295MALWARE-OTHER Win.Packed.Generic-7596391-0 download attempt (more info ...)trojan-activity    URL
53297MALWARE-OTHER Win.Trojan.Zbot-7597775-0 download attempt (more info ...)trojan-activity    URL
53301MALWARE-OTHER Win.Dropper.Zbot-7596393-0 download attempt (more info ...)trojan-activity    URL
53309MALWARE-OTHER Win.Packed.Generic-7596397-0 download attempt (more info ...)trojan-activity    URL
53310MALWARE-OTHER Win.Trojan.Xtrat-7597778-0 download attempt (more info ...)trojan-activity    URL
53313MALWARE-OTHER Win.Packed.Generic-7596398-0 download attempt (more info ...)trojan-activity    URL
53314MALWARE-OTHER Win.Keylogger.Banbra-7597779-0 download attempt (more info ...)trojan-activity    URL
53317MALWARE-OTHER Win.Packed.Generic-7596399-0 download attempt (more info ...)trojan-activity    URL
53320MALWARE-OTHER Win.Dropper.NetWire-7597054-0 download attempt (more info ...)trojan-activity    URL
53322MALWARE-OTHER Win.Dropper.Leer-7597784-0 download attempt (more info ...)trojan-activity    URL
53324MALWARE-OTHER Win.Dropper.NetWire-7597089-0 download attempt (more info ...)trojan-activity    URL
53325MALWARE-OTHER Win.Worm.Szq7apnib-7597786-0 download attempt (more info ...)trojan-activity    URL
53327MALWARE-OTHER Win.Malware.Midie-7597854-0 download attempt (more info ...)trojan-activity    URL
53339MALWARE-CNC Win.Trojan.Ftcode variant download attempt (more info ...)trojan-activity    URL
53352MALWARE-CNC Win.Trojan.AZORult variant outbound connection (more info ...)trojan-activity    URL
53353MALWARE-CNC Win.Worm.Emotet WiFi Spreader variant outbound connection (more info ...)trojan-activity    URL
53354MALWARE-CNC Win.Worm.Emotet WiFi Spreader variant outbound connection (more info ...)trojan-activity    URL
53360MALWARE-TOOLS Win.Worm.Emotet WiFi Spreader variant download attempt (more info ...)trojan-activity    URL
53362MALWARE-OTHER Win.Downloader.Upatre-7599441-0 download attempt (more info ...)trojan-activity    URL
53363MALWARE-OTHER Win.Downloader.Upatre-7600019-0 download attempt (more info ...)trojan-activity    URL
53367MALWARE-CNC Win.Trojan.Mozart outbound CNC connection (more info ...)trojan-activity    URL
53368MALWARE-CNC Win.Trojan.Mozart outbound CNC connection (more info ...)trojan-activity    URL
53369MALWARE-CNC Win.Trojan.Mozart outbound CNC connection (more info ...)trojan-activity    URL
53370MALWARE-CNC Win.Trojan.Mozart outbound CNC connection (more info ...)trojan-activity    URL
53371MALWARE-CNC Win.Trojan.Mozart outbound cnc connection attempt (more info ...)trojan-activity    URL
53372MALWARE-CNC Win.Trojan.Mozart outbound CNC connection (more info ...)trojan-activity    URL
53373MALWARE-CNC Win.Trojan.Mozart outbound CNC connection (more info ...)trojan-activity    URL
53379MALWARE-OTHER Win.Dropper.Drooptroop-7604355-0 download attempt (more info ...)trojan-activity    URL
53397MALWARE-TOOLS Win.Trojan.Generic variant download attempt (more info ...)trojan-activity    URL
53399MALWARE-TOOLS Win.Malware.Generic variant download attempt (more info ...)trojan-activity    URL
53437MALWARE-CNC Win.Trojan.Parallax variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53438MALWARE-CNC Win.Trojan.Parallax variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53439MALWARE-CNC Win.Trojan.Parallax variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53440MALWARE-CNC Win.Trojan.Parallax variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53441PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1020 attack attempt (more info ...)attempted-dos    URL
53442PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1021 attack attempt (more info ...)attempted-dos    URL
53443PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1022 attack attempt (more info ...)attempted-dos    URL
53444PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1023 attack attempt (more info ...)attempted-dos    URL
53445PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1024 attack attempt (more info ...)attempted-dos    URL
53484PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1025 attack attempt (more info ...)attempted-dos    URL
53504FILE-OTHER TAR file directory traversal attempt (more info ...)attempted-user 2020-3383   URL
53513MALWARE-OTHER Win.Dropper.XtremeRAT-7641498-0 download attempt (more info ...)trojan-activity    URL
53514MALWARE-OTHER Win.Dropper.XtremeRAT-7641498-0 download attempt (more info ...)trojan-activity    URL
53515MALWARE-OTHER Win.Downloader.Upatre-7640443-0 download attempt (more info ...)trojan-activity    URL
53516MALWARE-OTHER Win.Downloader.Upatre-7640443-0 download attempt (more info ...)trojan-activity    URL
53540POLICY-OTHER NetSupport Manager outbound connection attempt (more info ...)trojan-activity    URL
53541MALWARE-CNC Doc.Trojan.Agent variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53542MALWARE-CNC Doc.Trojan.Agent variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53543MALWARE-CNC Doc.Trojan.Agent variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53544MALWARE-CNC Win.Trojan.Agent variant outbound connection attempt (more info ...)trojan-activity    URL
53555MALWARE-OTHER Win.Downloader.Zbot-7647437-0 download attempt (more info ...)trojan-activity    URL
53556MALWARE-OTHER Win.Downloader.Zbot-7647437-0 download attempt (more info ...)trojan-activity    URL
53557SERVER-OTHER Codesys V3 Gateway denial of service attempt (more info ...)attempted-dos 2020-7052   
53559MALWARE-OTHER Win.Trojan.Generickdz-7648973-0 download attempt (more info ...)trojan-activity    URL
53560MALWARE-OTHER Win.Trojan.Generickdz-7648973-0 download attempt (more info ...)trojan-activity    URL
53579PROTOCOL-VOIP Asterisk Manager Interface Originate action arbitrary command execution attempt (more info ...)attempted-user 2019-18610   
53582INDICATOR-COMPROMISE RTF document with Equation and BITSAdmin download attempt (more info ...)trojan-activity    
53583INDICATOR-COMPROMISE RTF document with Equation and BITSAdmin download attempt (more info ...)trojan-activity    
53584MALWARE-CNC Win.Trojan.FormBook variant outbound connection (more info ...)trojan-activity    
53587MALWARE-CNC Win.Trojan.hacktool CheckAdmin tool download attempt (more info ...)trojan-activity    URL
53588MALWARE-CNC Win.Trojan.hacktool CheckAdmin tool download attempt (more info ...)trojan-activity    URL
53597MALWARE-OTHER Win.Ransomware.Hiddentears-7648972-0 download attempt (more info ...)trojan-activity    URL
53598MALWARE-OTHER Win.Ransomware.Hiddentears-7648972-0 download attempt (more info ...)trojan-activity    URL
53603MALWARE-OTHER Win.Packed.Razy-7649790-0 download attempt (more info ...)trojan-activity    URL
53604MALWARE-OTHER Win.Packed.Razy-7649790-0 download attempt (more info ...)trojan-activity    URL
53605MALWARE-OTHER Win.Dropper.Gozi-7647568-0 download attempt (more info ...)trojan-activity    URL
53606MALWARE-OTHER Win.Dropper.Gozi-7647568-0 download attempt (more info ...)trojan-activity    URL
53607MALWARE-OTHER Win.Trojan.Usteal-7652807-0 download attempt (more info ...)trojan-activity    URL
53608MALWARE-OTHER Win.Trojan.Usteal-7652807-0 download attempt (more info ...)trojan-activity    URL
53609MALWARE-OTHER Win.Packed.Aak5d3ci-7652809-0 download attempt (more info ...)trojan-activity    URL
53610MALWARE-OTHER Win.Packed.Aak5d3ci-7652809-0 download attempt (more info ...)trojan-activity    URL
53611MALWARE-OTHER Win.Packed.Acv93xci-7652812-0 download attempt (more info ...)trojan-activity    URL
53612MALWARE-OTHER Win.Packed.Acv93xci-7652812-0 download attempt (more info ...)trojan-activity    URL
53615MALWARE-OTHER Win.Dropper.Upatre-7659504-0 download attempt (more info ...)trojan-activity    URL
53616MALWARE-OTHER Win.Dropper.Upatre-7659504-0 download attempt (more info ...)trojan-activity    URL
53617MALWARE-OTHER Win.Dropper.Upatre-7659544-0 download attempt (more info ...)trojan-activity    URL
53618MALWARE-OTHER Win.Dropper.Upatre-7659544-0 download attempt (more info ...)trojan-activity    URL
53631MALWARE-CNC Win.Trojan.Panda variant outbound connection attempt (more info ...)trojan-activity    URL
53648MALWARE-CNC Win.Trojan.WildPressure variant outbound connection attempt (more info ...)trojan-activity    URL
53662MALWARE-OTHER Win.Trojan.MedusaLocker malicious executable download attempt (more info ...)trojan-activity    URL
53691MALWARE-OTHER Win.Trojan.PoetRAT malicious document download attempt (more info ...)trojan-activity    URL
53692MALWARE-CNC Win.Ransomware.Hiddentears variant outbound connection (more info ...)trojan-activity    URL
53693MALWARE-CNC Win.Ransomware.Hiddentears variant outbound connection (more info ...)trojan-activity    URL
53694MALWARE-CNC Win.Ransomware.Hiddentears variant outbound connection (more info ...)trojan-activity    URL
53695MALWARE-OTHER Win.Malware.Reconyc-7663171-0 download attempt (more info ...)trojan-activity    URL
53696MALWARE-OTHER Win.Malware.Reconyc-7663171-0 download attempt (more info ...)trojan-activity    URL
53703MALWARE-OTHER Win.Dropper.Gepys-7667037-0 download attempt (more info ...)trojan-activity    URL
53704MALWARE-OTHER Win.Dropper.Gepys-7667037-0 download attempt (more info ...)trojan-activity    URL
53705MALWARE-OTHER Win.Worm.Vobfus-7667850-0 download attempt (more info ...)trojan-activity    URL
53706MALWARE-OTHER Win.Worm.Vobfus-7667850-0 download attempt (more info ...)trojan-activity    URL
53709MALWARE-OTHER Win.Worm.Vobfus-7670131-0 download attempt (more info ...)trojan-activity    URL
53710MALWARE-OTHER Win.Worm.Vobfus-7670131-0 download attempt (more info ...)trojan-activity    URL
53711MALWARE-OTHER Win.Packed.Zbot-7671047-0 download attempt (more info ...)trojan-activity    URL
53712MALWARE-OTHER Win.Packed.Zbot-7671047-0 download attempt (more info ...)trojan-activity    URL
53715MALWARE-OTHER Win.Dropper.Kuluoz-7671762-0 download attempt (more info ...)trojan-activity    URL
53716MALWARE-OTHER Win.Dropper.Kuluoz-7671762-0 download attempt (more info ...)trojan-activity    URL
53717MALWARE-OTHER Win.Dropper.XtremeRAT-7672139-0 download attempt (more info ...)trojan-activity    URL
53718MALWARE-OTHER Win.Dropper.XtremeRAT-7672139-0 download attempt (more info ...)trojan-activity    URL
53719MALWARE-OTHER Win.Worm.Vobfus-7672805-0 download attempt (more info ...)trojan-activity    URL
53720MALWARE-OTHER Win.Worm.Vobfus-7672805-0 download attempt (more info ...)trojan-activity    URL
53721MALWARE-OTHER Win.Trojan.Sdbot-7674653-0 download attempt (more info ...)trojan-activity    URL
53722MALWARE-OTHER Win.Trojan.Sdbot-7674653-0 download attempt (more info ...)trojan-activity    URL
53723MALWARE-OTHER Win.Worm.Vobfus-7674660-0 download attempt (more info ...)trojan-activity    URL
53724MALWARE-OTHER Win.Worm.Vobfus-7674660-0 download attempt (more info ...)trojan-activity    URL
53725MALWARE-OTHER Win.Trojan.Sdbot-7674650-0 download attempt (more info ...)trojan-activity    URL
53726MALWARE-OTHER Win.Trojan.Sdbot-7674650-0 download attempt (more info ...)trojan-activity    URL
53727FILE-OTHER Visual Studio Code Python extension arbitrary code execution attempt (more info ...)attempted-user    URL
53728FILE-OTHER Visual Studio Code Python extension arbitrary code execution attempt (more info ...)attempted-user    URL
53736MALWARE-OTHER Win.Trojan.Zbot-7678962-0 download attempt (more info ...)trojan-activity    URL
53737MALWARE-OTHER Win.Trojan.Zbot-7678962-0 download attempt (more info ...)trojan-activity    URL
53749MALWARE-CNC Andr.Trojan.Basbanke variant outbound connection (more info ...)trojan-activity    URL
53750MALWARE-CNC Andr.Trojan.Basbanke variant outbound connection (more info ...)trojan-activity    URL
53755SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1051 attack attempt (more info ...)attempted-dos    URL
53756SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1051 attack attempt (more info ...)attempted-dos    URL
53763MALWARE-OTHER Win.Trojan.Generic-7679561-0 download attempt (more info ...)trojan-activity    URL
53764MALWARE-OTHER Win.Trojan.Generic-7679561-0 download attempt (more info ...)trojan-activity    URL
53765MALWARE-OTHER Win.Downloader.Kuluoz-7684621-0 download attempt (more info ...)trojan-activity    URL
53766MALWARE-OTHER Win.Downloader.Kuluoz-7684621-0 download attempt (more info ...)trojan-activity    URL
53767MALWARE-OTHER Win.Dropper.DarkKomet-7685267-0 download attempt (more info ...)trojan-activity    URL
53768MALWARE-OTHER Win.Dropper.DarkKomet-7685267-0 download attempt (more info ...)trojan-activity    URL
53770MALWARE-OTHER Win.Dropper.Emotet-7691064-0 download attempt (more info ...)trojan-activity    URL
53771MALWARE-OTHER Win.Dropper.Emotet-7691064-0 download attempt (more info ...)trojan-activity    URL
53772MALWARE-OTHER Win.Packed.Generickdz-7691284-0 download attempt (more info ...)trojan-activity    URL
53773MALWARE-OTHER Win.Packed.Generickdz-7691284-0 download attempt (more info ...)trojan-activity    URL
53774MALWARE-OTHER Win.Trojan.Cryptolocker-7691287-0 download attempt (more info ...)trojan-activity    URL
53775MALWARE-OTHER Win.Trojan.Cryptolocker-7691287-0 download attempt (more info ...)trojan-activity    URL
53776MALWARE-OTHER Win.Dropper.Kuluoz-7696245-0 download attempt (more info ...)trojan-activity    URL
53777MALWARE-OTHER Win.Dropper.Kuluoz-7696245-0 download attempt (more info ...)trojan-activity    URL
53780MALWARE-OTHER Win.Packed.Barys-7699954-0 download attempt (more info ...)trojan-activity    URL
53781MALWARE-OTHER Win.Packed.Barys-7699954-0 download attempt (more info ...)trojan-activity    URL
53792MALWARE-CNC Win.Malware.Remcos variant outbound cnc connection (more info ...)trojan-activity    URL
53801MALWARE-OTHER Win.Dropper.Dorkbot-7725478-0 download attempt (more info ...)trojan-activity    URL
53802MALWARE-OTHER Win.Dropper.Dorkbot-7725478-0 download attempt (more info ...)trojan-activity    URL
53803MALWARE-OTHER Win.Packed.Kuluoz-7725577-0 download attempt (more info ...)trojan-activity    URL
53804MALWARE-OTHER Win.Packed.Kuluoz-7725577-0 download attempt (more info ...)trojan-activity    URL
53805MALWARE-OTHER Win.Packed.Upatre-7725946-0 download attempt (more info ...)trojan-activity    URL
53806MALWARE-OTHER Win.Packed.Upatre-7725946-0 download attempt (more info ...)trojan-activity    URL
53807MALWARE-OTHER Win.Downloader.Auqxpmli-7727237-0 download attempt (more info ...)trojan-activity    URL
53808MALWARE-OTHER Win.Downloader.Auqxpmli-7727237-0 download attempt (more info ...)trojan-activity    URL
53809MALWARE-OTHER Win.Downloader.Auqxpmli-7727238-0 download attempt (more info ...)trojan-activity    URL
53810MALWARE-OTHER Win.Downloader.Auqxpmli-7727238-0 download attempt (more info ...)trojan-activity    URL
53811MALWARE-OTHER Win.Keylogger.Multibanker-7729242-0 download attempt (more info ...)trojan-activity    URL
53812MALWARE-OTHER Win.Keylogger.Multibanker-7729242-0 download attempt (more info ...)trojan-activity    URL
53813MALWARE-OTHER Win.Worm.Dorkbot-7729710-0 download attempt (more info ...)trojan-activity    URL
53814MALWARE-OTHER Win.Worm.Dorkbot-7729710-0 download attempt (more info ...)trojan-activity    URL
53815MALWARE-OTHER Win.Packed.Zeroaccess-7730394-0 download attempt (more info ...)trojan-activity    URL
53816MALWARE-OTHER Win.Packed.Zeroaccess-7730394-0 download attempt (more info ...)trojan-activity    URL
53817MALWARE-OTHER Win.Packed.Zusy-7730667-0 download attempt (more info ...)trojan-activity    URL
53818MALWARE-OTHER Win.Packed.Zusy-7730667-0 download attempt (more info ...)trojan-activity    URL
53819MALWARE-OTHER Win.Packed.Zeroaccess-7730732-0 download attempt (more info ...)trojan-activity    URL
53820MALWARE-OTHER Win.Packed.Zeroaccess-7730732-0 download attempt (more info ...)trojan-activity    URL
53821MALWARE-OTHER Win.Packed.Zeroaccess-7730819-0 download attempt (more info ...)trojan-activity    URL
53822MALWARE-OTHER Win.Packed.Zeroaccess-7730819-0 download attempt (more info ...)trojan-activity    URL
53823MALWARE-OTHER Win.Trojan.Gh0stRAT-7737919-0 download attempt (more info ...)trojan-activity    URL
53824MALWARE-OTHER Win.Trojan.Gh0stRAT-7737919-0 download attempt (more info ...)trojan-activity    URL
53827MALWARE-OTHER Win.Dropper.Gh0stRAT-7751494-0 download attempt (more info ...)trojan-activity    URL
53828MALWARE-OTHER Win.Dropper.Gh0stRAT-7751494-0 download attempt (more info ...)trojan-activity    URL
53829MALWARE-OTHER Win.Dropper.Gh0stRAT-7752290-0 download attempt (more info ...)trojan-activity    URL
53830MALWARE-OTHER Win.Dropper.Gh0stRAT-7752290-0 download attempt (more info ...)trojan-activity    URL
53833MALWARE-OTHER Win.Dropper.Cerber-7752430-0 download attempt (more info ...)trojan-activity    URL
53834MALWARE-OTHER Win.Dropper.Cerber-7752430-0 download attempt (more info ...)trojan-activity    URL
53838MALWARE-OTHER Win.Trojan.Maze variant download attempt (more info ...)trojan-activity    URL
53839POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1059 attack attempt (more info ...)policy-violation    URL
53840POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1060 attack attempt (more info ...)policy-violation    URL
53841MALWARE-CNC Win.Malware.Agent variant outbound cnc connection attempt (more info ...)trojan-activity    
53842MALWARE-OTHER Win.Packed.Zusy-7752919-0 download attempt (more info ...)trojan-activity    URL
53843MALWARE-OTHER Win.Packed.Zusy-7752919-0 download attempt (more info ...)trojan-activity    URL
53848MALWARE-OTHER Win.Packed.Clipbanker-7764305-0 download attempt (more info ...)trojan-activity    URL
53849MALWARE-OTHER Win.Packed.Clipbanker-7764305-0 download attempt (more info ...)trojan-activity    URL
53852MALWARE-OTHER Win.Packed.Razy-7767366-0 download attempt (more info ...)trojan-activity    URL
53853MALWARE-OTHER Win.Packed.Razy-7767366-0 download attempt (more info ...)trojan-activity    URL
53856MALWARE-CNC Embedded.Exploit.Hoaxcalls variant outbound connection (more info ...)trojan-activity    URL
53861MALWARE-CNC Win.Trojan.Astaroth outbound beacon (more info ...)trojan-activity    URL
53872MALWARE-OTHER Win.Ransomware.Petr-7770233-0 download attempt (more info ...)trojan-activity    URL
53873MALWARE-OTHER Win.Ransomware.Petr-7770233-0 download attempt (more info ...)trojan-activity    URL
53874MALWARE-OTHER Win.Dropper.Ursnif-7770520-0 download attempt (more info ...)trojan-activity    URL
53875MALWARE-OTHER Win.Dropper.Ursnif-7770520-0 download attempt (more info ...)trojan-activity    URL
53880INDICATOR-OBFUSCATION Executable packed with EnigmaProtector detected (more info ...)policy-violation    URL
53881INDICATOR-OBFUSCATION Executable packed with EnigmaProtector detected (more info ...)policy-violation    URL
53883MALWARE-OTHER Win.Packed.Ursnif-7770512-0 download attempt (more info ...)trojan-activity    URL
53884MALWARE-OTHER Win.Packed.Ursnif-7770512-0 download attempt (more info ...)trojan-activity    URL
53886MALWARE-OTHER Win.Dropper.Bifrost-7776555-0 download attempt (more info ...)trojan-activity    URL
53887MALWARE-OTHER Win.Dropper.Bifrost-7776555-0 download attempt (more info ...)trojan-activity    URL
53892MALWARE-OTHER Win.Worm.Worpof-7779679-0 download attempt (more info ...)trojan-activity    URL
53893MALWARE-OTHER Win.Worm.Worpof-7779679-0 download attempt (more info ...)trojan-activity    URL
53894MALWARE-OTHER Win.Packed.Zeroaccess-7779785-0 download attempt (more info ...)trojan-activity    URL
53895MALWARE-OTHER Win.Packed.Zeroaccess-7779785-0 download attempt (more info ...)trojan-activity    URL
53896MALWARE-OTHER Win.Packed.Zeroaccess-7779786-0 download attempt (more info ...)trojan-activity    URL
53897MALWARE-OTHER Win.Packed.Zeroaccess-7779786-0 download attempt (more info ...)trojan-activity    URL
53898MALWARE-OTHER Win.Packed.Zeroaccess-7779787-0 download attempt (more info ...)trojan-activity    URL
53899MALWARE-OTHER Win.Packed.Zeroaccess-7779787-0 download attempt (more info ...)trojan-activity    URL
53900MALWARE-OTHER Win.Packed.Zeroaccess-7779788-0 download attempt (more info ...)trojan-activity    URL
53901MALWARE-OTHER Win.Packed.Zeroaccess-7779788-0 download attempt (more info ...)trojan-activity    URL
53902MALWARE-OTHER PUA.Win.Downloader.Loadmoney-7779808-0 download attempt (more info ...)trojan-activity    URL
53903MALWARE-OTHER PUA.Win.Downloader.Loadmoney-7779808-0 download attempt (more info ...)trojan-activity    URL
53904MALWARE-OTHER Win.Ransomware.Cerber-7780045-0 download attempt (more info ...)trojan-activity    URL
53905MALWARE-OTHER Win.Ransomware.Cerber-7780045-0 download attempt (more info ...)trojan-activity    URL
53906MALWARE-OTHER Win.Dropper.Nitol-7780618-0 download attempt (more info ...)trojan-activity    URL
53907MALWARE-OTHER Win.Dropper.Nitol-7780618-0 download attempt (more info ...)trojan-activity    URL
53908MALWARE-OTHER Win.Dropper.Bunitu-7780594-0 download attempt (more info ...)trojan-activity    URL
53909MALWARE-OTHER Win.Dropper.Bunitu-7780594-0 download attempt (more info ...)trojan-activity    URL
53912MALWARE-OTHER Win.Packed.Mikey-7782296-0 download attempt (more info ...)trojan-activity    URL
53913MALWARE-OTHER Win.Packed.Mikey-7782296-0 download attempt (more info ...)trojan-activity    URL
53914MALWARE-OTHER Win.Trojan.Zusy-7782261-0 download attempt (more info ...)trojan-activity    URL
53915MALWARE-OTHER Win.Trojan.Zusy-7782261-0 download attempt (more info ...)trojan-activity    URL
53934MALWARE-OTHER Win.Trojan.Zusy-7779639-0 download attempt (more info ...)trojan-activity    URL
53935MALWARE-OTHER Win.Trojan.Zusy-7779639-0 download attempt (more info ...)trojan-activity    URL
53936MALWARE-OTHER Win.Malware.Zusy-7781049-0 download attempt (more info ...)trojan-activity    URL
53937MALWARE-OTHER Win.Malware.Zusy-7781049-0 download attempt (more info ...)trojan-activity    URL
53946MALWARE-OTHER Win.Ransomware.Cerber-7782997-0 download attempt (more info ...)trojan-activity    URL
53947MALWARE-OTHER Win.Ransomware.Cerber-7782997-0 download attempt (more info ...)trojan-activity    URL
53956MALWARE-CNC Win.Malware.Agent variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53957MALWARE-CNC Win.Malware.Agent variant outbound cnc connection (more info ...)trojan-activity    URL
53958MALWARE-CNC Win.Malware.Agent variant outbound cnc connection attempt (more info ...)trojan-activity    URL
53961MALWARE-OTHER Win.Dropper.Gh0stRAT-7783851-0 download attempt (more info ...)trojan-activity    URL
53962MALWARE-OTHER Win.Dropper.Gh0stRAT-7783851-0 download attempt (more info ...)trojan-activity    URL
53963MALWARE-OTHER Win.Dropper.Kuluoz-7784064-0 download attempt (more info ...)trojan-activity    URL
53964MALWARE-OTHER Win.Dropper.Kuluoz-7784064-0 download attempt (more info ...)trojan-activity    URL
53971MALWARE-CNC Win.Trojan.Andariel outbound connection attempt (more info ...)trojan-activity    
53981MALWARE-OTHER Win.Packed.Palevo-7785322-0 download attempt (more info ...)trojan-activity    URL
53982MALWARE-OTHER Win.Packed.Palevo-7785322-0 download attempt (more info ...)trojan-activity    URL
53986MALWARE-OTHER Win.Malware.Bstx-7792801-0 download attempt (more info ...)trojan-activity    URL
53987MALWARE-OTHER Win.Malware.Bstx-7792801-0 download attempt (more info ...)trojan-activity    URL
53988MALWARE-OTHER Win.Dropper.Cerber-7792881-0 download attempt (more info ...)trojan-activity    URL
53989MALWARE-OTHER Win.Dropper.Cerber-7792881-0 download attempt (more info ...)trojan-activity    URL
53994MALWARE-CNC Win.Trojan.WINNTI variant outbound connection (more info ...)trojan-activity    URL
53995MALWARE-CNC Win.Trojan.WINNTI variant outbound connection (more info ...)trojan-activity    URL
53996MALWARE-CNC Win.Malware.Hancitor variant outbound connection (more info ...)trojan-activity    URL
53998MALWARE-CNC Win.Malware.Hancitor variant inbound connection (more info ...)trojan-activity    URL
53999MALWARE-CNC Win.Malware.Hancitor variant outbound connection (more info ...)trojan-activity    URL
54000MALWARE-CNC Win.Malware.Hancitor variant outbound connection (more info ...)trojan-activity    URL
54001MALWARE-OTHER Win.Worm.Refpron-7794056-0 download attempt (more info ...)trojan-activity    URL
54002MALWARE-OTHER Win.Worm.Refpron-7794056-0 download attempt (more info ...)trojan-activity    URL
54009POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1071 attack attempt (more info ...)policy-violation    URL
54014MALWARE-CNC Win.Malware.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54017MALWARE-OTHER Win.Packed.Dorkbot-7847299-0 download attempt (more info ...)trojan-activity    URL
54018MALWARE-OTHER Win.Packed.Dorkbot-7847299-0 download attempt (more info ...)trojan-activity    URL
54019MALWARE-CNC Win.Trojan.ApolloZeus Loader beaconing attempt (more info ...)trojan-activity    URL
54021MALWARE-CNC Win.Trojan.Andariel outbound connection attempt (more info ...)trojan-activity    URL
54029MALWARE-CNC Win.Malware.Rifdoor outbound cnc registration attempt (more info ...)trojan-activity    URL
54035MALWARE-OTHER Win.Dropper.Fareitvb-7861078-0 download attempt (more info ...)trojan-activity    URL
54036MALWARE-OTHER Win.Dropper.Fareitvb-7861078-0 download attempt (more info ...)trojan-activity    URL
54040MALWARE-CNC Win.Trojan.Evilnum variant outbound connection (more info ...)trojan-activity    URL
54041MALWARE-CNC Win.Trojan.Evilnum variant outbound connection (more info ...)trojan-activity    URL
54042MALWARE-CNC Win.Trojan.Evilnum variant outbound connection (more info ...)trojan-activity    URL
54043MALWARE-CNC Win.Trojan.Evilnum variant inbound connection (more info ...)trojan-activity    URL
54046MALWARE-CNC Win.Malware.Qealler variant outbound connection (more info ...)trojan-activity    URL
54053MALWARE-CNC Win.Trojan.Copperhedge outbound connection (more info ...)trojan-activity    URL
54054MALWARE-CNC Win.Trojan.Copperhedge outbound connection (more info ...)trojan-activity    URL
54055MALWARE-CNC Win.Trojan.Copperhedge outbound connection (more info ...)trojan-activity    URL
54057MALWARE-OTHER Win.Trojan.BlackNET variant binary download attempt (more info ...)trojan-activity    URL
54058MALWARE-CNC Win.Trojan.Blacknet variant outbound connection (more info ...)trojan-activity    URL
54059MALWARE-CNC Win.Trojan.Blacknet variant outbound connection (more info ...)trojan-activity    URL
54060MALWARE-CNC Win.Trojan.Blacknet variant outbound connection (more info ...)trojan-activity    URL
54062MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54063MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54064MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54065MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54066MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54067MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54068MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54069MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54070MALWARE-OTHER Win.Trojan.TrickBot malicious executable download attempt (more info ...)trojan-activity    URL
54080INDICATOR-COMPROMISE Win.Trojan.TrickBot variant outbound connection attempt (more info ...)trojan-activity    URL
54081MALWARE-CNC Win.Trojan.Ursnif variant outbound cnc connection (more info ...)trojan-activity    URL
54082MALWARE-CNC Win.Trojan.Ursnif variant outbound cnc connection (more info ...)trojan-activity    URL
54087MALWARE-OTHER Win.Dropper.Zeus-7945000-0 download attempt (more info ...)trojan-activity    URL
54088MALWARE-OTHER Win.Dropper.Zeus-7945000-0 download attempt (more info ...)trojan-activity    URL
54102MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity    URL
54103MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity    URL
54104MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity    URL
54105MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity    URL
54106MALWARE-OTHER Win.Trojan.Mokes malicious executable download attempt (more info ...)trojan-activity    URL
54107MALWARE-CNC Win.Trojan.Mokes variant outbound connection (more info ...)trojan-activity    URL
54118MALWARE-OTHER Win.Trojan.Ircbot-7910553-0 download attempt (more info ...)trojan-activity    URL
54119MALWARE-OTHER Win.Trojan.Ircbot-7910553-0 download attempt (more info ...)trojan-activity    URL
54165MALWARE-OTHER Win.Ransomware.Razy-7997331-0 download attempt (more info ...)trojan-activity    URL
54166MALWARE-OTHER Win.Ransomware.Razy-7997331-0 download attempt (more info ...)trojan-activity    URL
54167MALWARE-OTHER Win.Malware.Genpack-7998106-0 download attempt (more info ...)trojan-activity    URL
54168MALWARE-OTHER Win.Malware.Genpack-7998106-0 download attempt (more info ...)trojan-activity    URL
54175INDICATOR-COMPROMISE Cobalt Strike default signed applet attack URI (more info ...)trojan-activity    URL
54176MALWARE-OTHER Win.Ircbot.Zusy-8002902-0 download attempt (more info ...)trojan-activity    URL
54177MALWARE-OTHER Win.Ircbot.Zusy-8002902-0 download attempt (more info ...)trojan-activity    URL
54178MALWARE-OTHER Win.Ircbot.Zusy-8002903-0 download attempt (more info ...)trojan-activity    URL
54179MALWARE-OTHER Win.Ircbot.Zusy-8002903-0 download attempt (more info ...)trojan-activity    URL
54183INDICATOR-COMPROMISE Cobalt Strike default smart applet attack URI (more info ...)trojan-activity    URL
54185MALWARE-OTHER Win.Packed.Samas-7998113-0 download attempt (more info ...)trojan-activity    URL
54186MALWARE-OTHER Win.Packed.Samas-7998113-0 download attempt (more info ...)trojan-activity    URL
54199MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54200MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54201MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54202MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54203MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54204MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54205MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54206MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54207MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54208MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54209MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54210MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54211MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54212MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54213MALWARE-CNC Win.Trojan.Trickbot variant outbound connection (more info ...)trojan-activity    URL
54220MALWARE-OTHER PUA.Win.Packed.Amg0fxii-8010198-0 download attempt (more info ...)trojan-activity    URL
54221MALWARE-OTHER PUA.Win.Packed.Amg0fxii-8010198-0 download attempt (more info ...)trojan-activity    URL
54222SERVER-ORACLE Oracle iPlanet admin panel image injection attempt (more info ...)web-application-attack 2020-9314   URL
54223SERVER-ORACLE Oracle iPlanet admin panel image injection CSRF attempt (more info ...)web-application-attack 2020-9314   URL
54224SERVER-ORACLE Oracle iPlanet admin panel image injection attempt (more info ...)web-application-attack 2020-9314   URL
54225SERVER-ORACLE Oracle iPlanet admin panel image injection CSRF attempt (more info ...)web-application-attack 2020-9314   URL
54234SERVER-WEBAPP TerraMaster NAS cross site scripting attempt (more info ...)attempted-user 2018-13334   URL
54235SERVER-WEBAPP TerraMaster NAS cross site scripting attempt (more info ...)attempted-user 2018-13334   URL
54284MALWARE-OTHER Win.Dropper.NetWire-8014470-0 download attempt (more info ...)trojan-activity    URL
54285MALWARE-OTHER Win.Dropper.NetWire-8014470-0 download attempt (more info ...)trojan-activity    URL
54286MALWARE-OTHER Win.Worm.Vobfus-8014472-0 download attempt (more info ...)trojan-activity    URL
54287MALWARE-OTHER Win.Worm.Vobfus-8014472-0 download attempt (more info ...)trojan-activity    URL
54288MALWARE-OTHER Win.Worm.Vobfus-8014473-0 download attempt (more info ...)trojan-activity    URL
54289MALWARE-OTHER Win.Worm.Vobfus-8014473-0 download attempt (more info ...)trojan-activity    URL
54291MALWARE-OTHER Doc.Trojan.AZORult phishing document download attempt (more info ...)trojan-activity    URL
54292MALWARE-OTHER Doc.Trojan.AZORult phishing document download attempt (more info ...)trojan-activity    URL
54293MALWARE-CNC Win.Trojan.Neutrino variant payload download (more info ...)trojan-activity    URL
54294MALWARE-CNC Win.Trojan.AZORult variant payload download attempt (more info ...)trojan-activity    URL
54295MALWARE-CNC Win.Trojan.AZORult variant payload download attempt (more info ...)trojan-activity    URL
54298MALWARE-OTHER Win.Dropper.Tinba-8025802-0 download attempt (more info ...)trojan-activity    URL
54299MALWARE-OTHER Win.Dropper.Tinba-8025802-0 download attempt (more info ...)trojan-activity    URL
54302MALWARE-OTHER Win.Dropper.Kuluoz-8027829-0 download attempt (more info ...)trojan-activity    URL
54303MALWARE-OTHER Win.Dropper.Kuluoz-8027829-0 download attempt (more info ...)trojan-activity    URL
54316MALWARE-OTHER Win.Downloader.Jqht-8069377-0 download attempt (more info ...)trojan-activity    URL
54317MALWARE-OTHER Win.Downloader.Jqht-8069377-0 download attempt (more info ...)trojan-activity    URL
54318MALWARE-CNC Win.Trojan.Azorult variant outbound connection attempt (more info ...)trojan-activity    URL
54357MALWARE-CNC Win.Trojan.Sarwent variant outbound connection (more info ...)trojan-activity    URL
54373MALWARE-OTHER Win.Trojan.IndigoDrop variant binary download attempt (more info ...)trojan-activity    URL
54375MALWARE-OTHER Win.Trojan.IndigoDrop variant binary download attempt (more info ...)trojan-activity    URL
54376MALWARE-OTHER Win.Trojan.IndigoDrop variant binary download attempt (more info ...)trojan-activity    URL
54381MALWARE-OTHER Win.Dropper.Vidar-8170701-0 download attempt (more info ...)trojan-activity    URL
54382MALWARE-OTHER Win.Dropper.Vidar-8170701-0 download attempt (more info ...)trojan-activity    URL
54384MALWARE-OTHER Win.Trojan.Qbot malicious executable download attempt (more info ...)trojan-activity    URL
54386MALWARE-OTHER Win.Trojan.Qbot malicious executable download attempt (more info ...)trojan-activity    URL
54394MALWARE-CNC Win.Trojan.Banload variant outbound connection attempt (more info ...)trojan-activity    URL
54395MALWARE-OTHER Win.Trojan.Shiz-8295940-0 download attempt (more info ...)trojan-activity    URL
54396MALWARE-OTHER Win.Trojan.Shiz-8295940-0 download attempt (more info ...)trojan-activity    URL
54397MALWARE-OTHER Win.Trojan.Barys-8338518-0 download attempt (more info ...)trojan-activity    URL
54398MALWARE-OTHER Win.Trojan.Barys-8338518-0 download attempt (more info ...)trojan-activity    URL
54401MALWARE-CNC Win.Trojan.Valak malicious outbound connection attempt (more info ...)trojan-activity    URL
54402MALWARE-CNC Win.Trojan.Valak malicious outbound connection attempt (more info ...)trojan-activity    URL
54403MALWARE-CNC Win.Trojan.Valak malicious outbound connection attempt (more info ...)trojan-activity    URL
54404MALWARE-CNC Win.Trojan.Valak malicious outbound connection attempt (more info ...)trojan-activity    URL
54419MALWARE-OTHER Win.Dropper.NetWire-8356485-0 download attempt (more info ...)trojan-activity    URL
54420MALWARE-OTHER Win.Dropper.NetWire-8356485-0 download attempt (more info ...)trojan-activity    URL
54421MALWARE-CNC Win.Trojan.TroyStealer outbound connection attempt (more info ...)trojan-activity    URL
54434MALWARE-OTHER Win.Malware.Midie-8568669-0 download attempt (more info ...)trojan-activity    URL
54435MALWARE-OTHER Win.Malware.Midie-8568669-0 download attempt (more info ...)trojan-activity    URL
54440FILE-OTHER TRUFFLEHUNTER TALOS-2020-1110 attack attempt (more info ...)attempted-admin 2020-13509   URL
54441FILE-OTHER TRUFFLEHUNTER TALOS-2020-1110 attack attempt (more info ...)attempted-admin 2020-13509   URL
54442FILE-OTHER TRUFFLEHUNTER TALOS-2020-1110 attack attempt (more info ...)attempted-admin 2020-13510   URL
54443FILE-OTHER TRUFFLEHUNTER TALOS-2020-1110 attack attempt (more info ...)attempted-admin 2020-13510   URL
54444FILE-OTHER TRUFFLEHUNTER TALOS-2020-1110 attack attempt (more info ...)attempted-admin 2020-13511   URL
54445FILE-OTHER TRUFFLEHUNTER TALOS-2020-1110 attack attempt (more info ...)attempted-admin 2020-13511   URL
54446FILE-OTHER TRUFFLEHUNTER TALOS-2020-1111 attack attempt (more info ...)attempted-admin 2020-13512   URL
54447FILE-OTHER TRUFFLEHUNTER TALOS-2020-1111 attack attempt (more info ...)attempted-admin 2020-13512   URL
54448FILE-OTHER TRUFFLEHUNTER TALOS-2020-1111 attack attempt (more info ...)attempted-admin 2020-13513   URL
54449FILE-OTHER TRUFFLEHUNTER TALOS-2020-1111 attack attempt (more info ...)attempted-admin 2020-13513   URL
54450FILE-OTHER TRUFFLEHUNTER TALOS-2020-1111 attack attempt (more info ...)attempted-admin 2020-13514   URL
54451FILE-OTHER TRUFFLEHUNTER TALOS-2020-1111 attack attempt (more info ...)attempted-admin 2020-13514   URL
54452FILE-OTHER TRUFFLEHUNTER TALOS-2020-1112 attack attempt (more info ...)attempted-admin 2020-13515   URL
54453FILE-OTHER TRUFFLEHUNTER TALOS-2020-1112 attack attempt (more info ...)attempted-admin 2020-13515   URL
54454FILE-OTHER TRUFFLEHUNTER TALOS-2020-1113 attack attempt (more info ...)attempted-admin 2020-13516   URL
54455FILE-OTHER TRUFFLEHUNTER TALOS-2020-1113 attack attempt (more info ...)attempted-admin 2020-13516   URL
54456FILE-OTHER TRUFFLEHUNTER TALOS-2020-1114 attack attempt (more info ...)attempted-admin 2020-13517   URL
54457FILE-OTHER TRUFFLEHUNTER TALOS-2020-1114 attack attempt (more info ...)attempted-admin 2020-13517   URL
54458FILE-OTHER TRUFFLEHUNTER TALOS-2020-1115 attack attempt (more info ...)attempted-admin 2020-13518   URL
54459FILE-OTHER TRUFFLEHUNTER TALOS-2020-1115 attack attempt (more info ...)attempted-admin 2020-13518   URL
54460FILE-OTHER TRUFFLEHUNTER TALOS-2020-1116 attack attempt (more info ...)attempted-admin 2020-13519   URL
54461FILE-OTHER TRUFFLEHUNTER TALOS-2020-1116 attack attempt (more info ...)attempted-admin 2020-13519   URL
54494SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1100 attack attempt (more info ...)attempted-dos 2020-6154   URL
54496MALWARE-CNC Win.Trojan.NetSupportManager outbound connection attempt (more info ...)trojan-activity    URL
54499MALWARE-CNC Win.Ransomware.Maze variant outbound connection (more info ...)trojan-activity    URL
54500MALWARE-CNC Win.Ransomware.Maze variant outbound connection (more info ...)trojan-activity    URL
54503OS-OTHER TRUFFLEHUNTER TALOS-2020-1117 attack attempt (more info ...)attempted-dos    URL
54504OS-OTHER TRUFFLEHUNTER TALOS-2020-1117 attack attempt (more info ...)attempted-dos    URL
54505MALWARE-OTHER Win.Malware.Generic-8798012-0 download attempt (more info ...)trojan-activity    URL
54506MALWARE-OTHER Win.Malware.Generic-8798012-0 download attempt (more info ...)trojan-activity    URL
54507MALWARE-OTHER Win.Malware.Genpack-8799099-0 download attempt (more info ...)trojan-activity    URL
54508MALWARE-OTHER Win.Malware.Genpack-8799099-0 download attempt (more info ...)trojan-activity    URL
54554MALWARE-CNC Win.Trojan.Ursnif variant payload download attempt (more info ...)trojan-activity    URL
54555MALWARE-CNC Win.Trojan.Ursnif variant payload download attempt (more info ...)trojan-activity    URL
54578SERVER-OTHER Multiple products RAR archive decompression buffer overflow attempt (more info ...)attempted-user 2005-4438   
54594MALWARE-OTHER Win.Dropper.Ap0calypseRAT-8992619-0 download attempt (more info ...)trojan-activity    URL
54595MALWARE-OTHER Win.Dropper.Ap0calypseRAT-8992619-0 download attempt (more info ...)trojan-activity    URL
54609SERVER-OTHER Hummingbird InetD LPD buffer overflow attempt (more info ...)attempted-user 2005-1815   
54610MALWARE-CNC Win.Trojan.Prometei variant outbound connection (more info ...)trojan-activity    URL
54611MALWARE-CNC Win.Trojan.Prometei variant outbound connection (more info ...)trojan-activity    URL
54612MALWARE-CNC Win.Trojan.Prometei variant outbound connection (more info ...)trojan-activity    URL
54626MALWARE-CNC Vbs.Trojan.Dridex variant payload outbound download attempt (more info ...)trojan-activity    URL
54627MALWARE-CNC Vbs.Trojan.Dridex variant payload inbound download attempt (more info ...)trojan-activity    URL
54628MALWARE-CNC Vbs.Trojan.Dridex variant payload inbound download attempt (more info ...)trojan-activity    URL
54632MALWARE-OTHER Win.Dropper.QQpass-9093595-0 download attempt (more info ...)trojan-activity    URL
54633MALWARE-OTHER Win.Dropper.QQpass-9093595-0 download attempt (more info ...)trojan-activity    URL
54634MALWARE-OTHER Win.Dropper.QQpass-9102183-0 download attempt (more info ...)trojan-activity    URL
54635MALWARE-OTHER Win.Dropper.QQpass-9102183-0 download attempt (more info ...)trojan-activity    URL
54640MALWARE-OTHER Win.Trojan.Hackbit malicious executable download attempt (more info ...)trojan-activity    URL
54642MALWARE-OTHER Win.Trojan.Hackbit malicious dropper download attempt (more info ...)trojan-activity    URL
54651MALWARE-OTHER Win.Dropper.Nanocore-9025522-0 download attempt (more info ...)trojan-activity    URL
54652MALWARE-OTHER Win.Dropper.Nanocore-9025522-0 download attempt (more info ...)trojan-activity    URL
54653MALWARE-OTHER Win.Dropper.Gh0stRAT-9107742-0 download attempt (more info ...)trojan-activity    URL
54654MALWARE-OTHER Win.Dropper.Gh0stRAT-9107742-0 download attempt (more info ...)trojan-activity    URL
54657MALWARE-OTHER Win.Dropper.Bunitu-9128889-0 download attempt (more info ...)trojan-activity    URL
54658MALWARE-OTHER Win.Dropper.Bunitu-9128889-0 download attempt (more info ...)trojan-activity    URL
54659MALWARE-OTHER Win.Dropper.Bunitu-9127509-0 download attempt (more info ...)trojan-activity    URL
54660MALWARE-OTHER Win.Dropper.Bunitu-9127509-0 download attempt (more info ...)trojan-activity    URL
54661MALWARE-OTHER Win.Ransomware.Cerber-9130272-0 download attempt (more info ...)trojan-activity    URL
54662MALWARE-OTHER Win.Ransomware.Cerber-9130272-0 download attempt (more info ...)trojan-activity    URL
54663MALWARE-OTHER Win.Ransomware.Cerber-9130422-0 download attempt (more info ...)trojan-activity    URL
54664MALWARE-OTHER Win.Ransomware.Cerber-9130422-0 download attempt (more info ...)trojan-activity    URL
54667FILE-OTHER TAR file directory traversal attempt (more info ...)attempted-user 2020-3383   URL
54678MALWARE-OTHER Win.Ransomware.Cerber-9204933-0 download attempt (more info ...)trojan-activity    URL
54679MALWARE-OTHER Win.Ransomware.Cerber-9204933-0 download attempt (more info ...)trojan-activity    URL
54707MALWARE-OTHER Win.Packed.Agentb-9219640-0 download attempt (more info ...)trojan-activity    URL
54708MALWARE-OTHER Win.Packed.Agentb-9219640-0 download attempt (more info ...)trojan-activity    URL
54711MALWARE-OTHER Win.Dropper.Zeus-9220292-0 download attempt (more info ...)trojan-activity    URL
54712MALWARE-OTHER Win.Dropper.Zeus-9220292-0 download attempt (more info ...)trojan-activity    URL
54717MALWARE-OTHER Win.Packed.Zeroaccess-9220863-0 download attempt (more info ...)trojan-activity    URL
54718MALWARE-OTHER Win.Packed.Zeroaccess-9220863-0 download attempt (more info ...)trojan-activity    URL
54721MALWARE-OTHER Win.Downloader.Banload-9221778-0 download attempt (more info ...)trojan-activity    URL
54722MALWARE-OTHER Win.Downloader.Banload-9221778-0 download attempt (more info ...)trojan-activity    URL
54725MALWARE-OTHER Win.Dropper.SpyEye-9225535-0 download attempt (more info ...)trojan-activity    URL
54726MALWARE-OTHER Win.Dropper.SpyEye-9225535-0 download attempt (more info ...)trojan-activity    URL
54748MALWARE-OTHER Win.Ransomware.Nephilim variant binary download attempt (more info ...)trojan-activity    URL
54751MALWARE-OTHER Win.Ransomware.Nephilim variant binary download attempt (more info ...)trojan-activity    URL
54752MALWARE-OTHER Win.Ransomware.Nephilim variant binary download attempt (more info ...)trojan-activity    URL
54758MALWARE-OTHER Win.Dropper.Ap0calypseRAT-9216554-0 download attempt (more info ...)trojan-activity    URL
54759MALWARE-OTHER Win.Dropper.Ap0calypseRAT-9216554-0 download attempt (more info ...)trojan-activity    URL
54760MALWARE-OTHER Win.Malware.Midie-9242514-0 download attempt (more info ...)trojan-activity    URL
54761MALWARE-OTHER Win.Malware.Midie-9242514-0 download attempt (more info ...)trojan-activity    URL
54762POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1135 attack attempt (more info ...)policy-violation 2020-13527   URL
54763POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1135 attack attempt (more info ...)policy-violation 2020-13527   URL
54764POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1135 attack attempt (more info ...)policy-violation 2020-13527   URL
54769MALWARE-OTHER Win.Dropper.Nanocore-9253782-0 download attempt (more info ...)trojan-activity    URL
54770MALWARE-OTHER Win.Dropper.Nanocore-9253782-0 download attempt (more info ...)trojan-activity    URL
54773SERVER-WEBAPP TerraMaster NAS URL reflected cross site scripting attempt (more info ...)attempted-user 2018-13329   
54774SERVER-WEBAPP TerraMaster NAS URL reflected cross site scripting attempt (more info ...)attempted-user 2018-13329   
54775MALWARE-OTHER Win.Malware.Johnnie-9294701-0 download attempt (more info ...)trojan-activity    URL
54776MALWARE-OTHER Win.Malware.Johnnie-9294701-0 download attempt (more info ...)trojan-activity    URL
54779MALWARE-OTHER Win.Worm.Ircbot-9310443-0 download attempt (more info ...)trojan-activity    URL
54780MALWARE-OTHER Win.Worm.Ircbot-9310443-0 download attempt (more info ...)trojan-activity    URL
54801MALWARE-CNC Win.Trojan.Taidoor variant outbound connection (more info ...)trojan-activity    URL
54802MALWARE-OTHER Win.Trojan.Poison-9371279-0 download attempt (more info ...)trojan-activity    URL
54803MALWARE-OTHER Win.Trojan.Poison-9371279-0 download attempt (more info ...)trojan-activity    URL
54804MALWARE-OTHER Win.Trojan.Emotet-9371545-0 download attempt (more info ...)trojan-activity    URL
54805MALWARE-OTHER Win.Trojan.Emotet-9371545-0 download attempt (more info ...)trojan-activity    URL
54806MALWARE-OTHER Win.Packed.Zeroaccess-9371729-0 download attempt (more info ...)trojan-activity    URL
54807MALWARE-OTHER Win.Packed.Zeroaccess-9371729-0 download attempt (more info ...)trojan-activity    URL
54810MALWARE-OTHER Win.Malware.Fdld-9371797-0 download attempt (more info ...)trojan-activity    URL
54811MALWARE-OTHER Win.Malware.Fdld-9371797-0 download attempt (more info ...)trojan-activity    URL
54812MALWARE-OTHER Win.Dropper.Kuluoz-9372655-0 download attempt (more info ...)trojan-activity    URL
54813MALWARE-OTHER Win.Dropper.Kuluoz-9372655-0 download attempt (more info ...)trojan-activity    URL
54828MALWARE-CNC Win.Trojan.RDAT EWS cnc outbound communication (more info ...)trojan-activity    URL
54831POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1142 attack attempt (more info ...)policy-violation 2020-13529   URL
54838MALWARE-OTHER Win.Dropper.Vundo-9406789-0 download attempt (more info ...)trojan-activity    URL
54839MALWARE-OTHER Win.Dropper.Vundo-9406789-0 download attempt (more info ...)trojan-activity    URL
54840MALWARE-OTHER Win.Trojan.Zeroaccess-9406344-0 download attempt (more info ...)trojan-activity    URL
54841MALWARE-OTHER Win.Trojan.Zeroaccess-9406344-0 download attempt (more info ...)trojan-activity    URL
54842MALWARE-OTHER Win.Packed.Zeus-9415830-0 download attempt (more info ...)trojan-activity    URL
54843MALWARE-OTHER Win.Packed.Zeus-9415830-0 download attempt (more info ...)trojan-activity    URL
54844MALWARE-OTHER Win.Packed.Atraps-9427196-0 download attempt (more info ...)trojan-activity    URL
54845MALWARE-OTHER Win.Packed.Atraps-9427196-0 download attempt (more info ...)trojan-activity    URL
54846MALWARE-OTHER Win.Packed.Atraps-9427203-0 download attempt (more info ...)trojan-activity    URL
54847MALWARE-OTHER Win.Packed.Atraps-9427203-0 download attempt (more info ...)trojan-activity    URL
54850MALWARE-OTHER Win.Dropper.Remcos-9446016-0 download attempt (more info ...)trojan-activity    URL
54851MALWARE-OTHER Win.Dropper.Remcos-9446016-0 download attempt (more info ...)trojan-activity    URL
54852MALWARE-OTHER Win.Dropper.Remcos-9446018-0 download attempt (more info ...)trojan-activity    URL
54853MALWARE-OTHER Win.Dropper.Remcos-9446018-0 download attempt (more info ...)trojan-activity    URL
54854MALWARE-OTHER Win.Trojan.Nebuler-9446495-0 download attempt (more info ...)trojan-activity    URL
54855MALWARE-OTHER Win.Trojan.Nebuler-9446495-0 download attempt (more info ...)trojan-activity    URL
54856MALWARE-OTHER Win.Trojan.Ircbot-9446722-0 download attempt (more info ...)trojan-activity    URL
54857MALWARE-OTHER Win.Trojan.Ircbot-9446722-0 download attempt (more info ...)trojan-activity    URL
54858MALWARE-OTHER Win.Dropper.QQpass-9454056-0 download attempt (more info ...)trojan-activity    URL
54859MALWARE-OTHER Win.Dropper.QQpass-9454056-0 download attempt (more info ...)trojan-activity    URL
54860MALWARE-OTHER Win.Dropper.QQpass-9455117-0 download attempt (more info ...)trojan-activity    URL
54861MALWARE-OTHER Win.Dropper.QQpass-9455117-0 download attempt (more info ...)trojan-activity    URL
54862MALWARE-OTHER Win.Malware.Tiny-9467540-0 download attempt (more info ...)trojan-activity    URL
54863MALWARE-OTHER Win.Malware.Tiny-9467540-0 download attempt (more info ...)trojan-activity    URL
54864MALWARE-OTHER Win.Malware.Tiny-9467542-0 download attempt (more info ...)trojan-activity    URL
54865MALWARE-OTHER Win.Malware.Tiny-9467542-0 download attempt (more info ...)trojan-activity    URL
54868MALWARE-OTHER Win.Malware.Zusy-9480629-0 download attempt (more info ...)trojan-activity    URL
54869MALWARE-OTHER Win.Malware.Zusy-9480629-0 download attempt (more info ...)trojan-activity    URL
54870MALWARE-OTHER PUA.Win.Tool.Procpatcher-9481109-0 download attempt (more info ...)trojan-activity    URL
54871MALWARE-OTHER PUA.Win.Tool.Procpatcher-9481109-0 download attempt (more info ...)trojan-activity    URL
54872MALWARE-OTHER Win.Malware.Midie-9497741-0 download attempt (more info ...)trojan-activity    URL
54873MALWARE-OTHER Win.Malware.Midie-9497741-0 download attempt (more info ...)trojan-activity    URL
54876MALWARE-OTHER Win.Ransomware.Spora-9525060-0 download attempt (more info ...)trojan-activity    URL
54877MALWARE-OTHER Win.Ransomware.Spora-9525060-0 download attempt (more info ...)trojan-activity    URL
54878MALWARE-OTHER Win.Packed.Zeroaccess-9525066-0 download attempt (more info ...)trojan-activity    URL
54879MALWARE-OTHER Win.Packed.Zeroaccess-9525066-0 download attempt (more info ...)trojan-activity    URL
54880MALWARE-CNC Win.Malware.Duri variant payload download attempt (more info ...)trojan-activity    URL
54891MALWARE-CNC Win.Trojan.GoldenSpy variant outbound beaconing attempt (more info ...)trojan-activity    URL
54892MALWARE-CNC Win.Trojan.GoldenSpy variant outbound beaconing attempt (more info ...)trojan-activity    URL
54893MALWARE-CNC Win.Trojan.GoldenSpy variant outbound beaconing attempt (more info ...)trojan-activity    URL
54900MALWARE-OTHER Win.Packed.Emotet-9527878-0 download attempt (more info ...)trojan-activity    URL
54901MALWARE-OTHER Win.Packed.Emotet-9527878-0 download attempt (more info ...)trojan-activity    URL
54905MALWARE-OTHER Win.Trojan.Dridex malicious executable download attempt (more info ...)trojan-activity    URL
54908MALWARE-OTHER Win.Trojan.Dridex malicious file download attempt (more info ...)trojan-activity    URL
54909MALWARE-OTHER Win.Trojan.Dridex malicious executable download attempt (more info ...)trojan-activity    URL
54924MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (more info ...)trojan-activity    URL
54925MALWARE-OTHER Win.Malware.Emotet-9620982-0 download attempt (more info ...)trojan-activity    URL
54928MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (more info ...)trojan-activity    URL
54929MALWARE-OTHER Win.Malware.Midie-9622173-0 download attempt (more info ...)trojan-activity    URL
54930MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (more info ...)trojan-activity    URL
54931MALWARE-OTHER Win.Malware.Midie-9622177-0 download attempt (more info ...)trojan-activity    URL
54932MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (more info ...)trojan-activity    URL
54933MALWARE-OTHER Win.Malware.Midie-9622157-0 download attempt (more info ...)trojan-activity    URL
54934MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (more info ...)trojan-activity    URL
54935MALWARE-OTHER Win.Virus.Wapomi-9623880-0 download attempt (more info ...)trojan-activity    URL
54936MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (more info ...)trojan-activity    URL
54937MALWARE-OTHER Win.Malware.Zusy-9623918-0 download attempt (more info ...)trojan-activity    URL
54940MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (more info ...)trojan-activity    URL
54941MALWARE-OTHER Win.Downloader.Upatre-9624358-0 download attempt (more info ...)trojan-activity    URL
54942MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (more info ...)trojan-activity    URL
54943MALWARE-OTHER Win.Downloader.Upatre-9624093-0 download attempt (more info ...)trojan-activity    URL
54944MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (more info ...)trojan-activity    URL
54945MALWARE-OTHER Win.Malware.Midie-9624674-0 download attempt (more info ...)trojan-activity    URL
54948MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (more info ...)trojan-activity    URL
54949MALWARE-OTHER Win.Malware.Genpack-9625450-0 download attempt (more info ...)trojan-activity    URL
54952MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (more info ...)trojan-activity    URL
54953MALWARE-OTHER Win.Malware.Genpack-9625456-0 download attempt (more info ...)trojan-activity    URL
54954MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (more info ...)trojan-activity    URL
54955MALWARE-OTHER Win.Malware.Genpack-9625465-0 download attempt (more info ...)trojan-activity    URL
54956MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (more info ...)trojan-activity    URL
54957MALWARE-OTHER Win.Malware.Tiny-9625603-0 download attempt (more info ...)trojan-activity    URL
54958MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (more info ...)trojan-activity    URL
54959MALWARE-OTHER Win.Malware.Zusy-9625604-0 download attempt (more info ...)trojan-activity    URL
54960MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (more info ...)trojan-activity    URL
54961MALWARE-OTHER Win.Malware.Upatre-9626207-0 download attempt (more info ...)trojan-activity    URL
54966MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (more info ...)trojan-activity    URL
54967MALWARE-OTHER Win.Malware.Upatre-9628660-0 download attempt (more info ...)trojan-activity    URL
54968MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (more info ...)trojan-activity    URL
54969MALWARE-OTHER PUA.Win.File.Zegost-9629018-0 download attempt (more info ...)trojan-activity    URL
54970MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (more info ...)trojan-activity    URL
54971MALWARE-OTHER Win.Malware.Midie-9628903-0 download attempt (more info ...)trojan-activity    URL
54972MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (more info ...)trojan-activity    URL
54973MALWARE-OTHER Win.Malware.Midie-9628909-0 download attempt (more info ...)trojan-activity    URL
54976MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (more info ...)trojan-activity    URL
54977MALWARE-OTHER Win.Packed.Razy-9629621-0 download attempt (more info ...)trojan-activity    URL
54978MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (more info ...)trojan-activity    URL
54979MALWARE-OTHER Win.Trojan.Delf-9629623-0 download attempt (more info ...)trojan-activity    URL
54982MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (more info ...)trojan-activity    URL
54983MALWARE-OTHER Win.Trojan.Razy-9629407-0 download attempt (more info ...)trojan-activity    URL
54984MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (more info ...)trojan-activity    URL
54985MALWARE-OTHER Win.Packed.Virlock-9629553-0 download attempt (more info ...)trojan-activity    URL
54988MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (more info ...)trojan-activity    URL
54989MALWARE-OTHER Win.Packed.Upantix-9631864-0 download attempt (more info ...)trojan-activity    URL
54992MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (more info ...)trojan-activity    URL
54993MALWARE-OTHER Win.Packed.Upantix-9631863-0 download attempt (more info ...)trojan-activity    URL
54996MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (more info ...)trojan-activity    URL
54997MALWARE-OTHER Win.Malware.Zusy-9632958-0 download attempt (more info ...)trojan-activity    URL
54998MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (more info ...)trojan-activity    URL
54999MALWARE-OTHER Win.Malware.Blackmoon-9632943-0 download attempt (more info ...)trojan-activity    URL
55002MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (more info ...)trojan-activity    URL
55003MALWARE-OTHER Win.Packed.Trickbot-9633223-0 download attempt (more info ...)trojan-activity    URL
55004MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (more info ...)trojan-activity    URL
55005MALWARE-OTHER Win.Packed.Trickbot-9633236-0 download attempt (more info ...)trojan-activity    URL
55006MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (more info ...)trojan-activity    URL
55007MALWARE-OTHER Win.Downloader.Upatre-9633079-0 download attempt (more info ...)trojan-activity    URL
55008MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (more info ...)trojan-activity    URL
55009MALWARE-OTHER Win.Worm.Cynic-9634045-0 download attempt (more info ...)trojan-activity    URL
55010MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (more info ...)trojan-activity    URL
55011MALWARE-OTHER Win.Malware.Blackmoon-9634189-0 download attempt (more info ...)trojan-activity    URL
55014MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (more info ...)trojan-activity    URL
55015MALWARE-OTHER Win.Packed.Razy-9634380-0 download attempt (more info ...)trojan-activity    URL
55019MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (more info ...)trojan-activity    URL
55020MALWARE-OTHER Win.Packed.Upatre-9635731-0 download attempt (more info ...)trojan-activity    URL
55021MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (more info ...)trojan-activity    URL
55022MALWARE-OTHER Win.Malware.Upatre-9635944-0 download attempt (more info ...)trojan-activity    URL
55023MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (more info ...)trojan-activity    URL
55024MALWARE-OTHER Win.Malware.Upatre-9635959-0 download attempt (more info ...)trojan-activity    URL
55029MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (more info ...)trojan-activity    URL
55030MALWARE-OTHER Win.Malware.Razy-9636401-0 download attempt (more info ...)trojan-activity    URL
55033MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (more info ...)trojan-activity    URL
55034MALWARE-OTHER Win.Malware.Ipamor-9637309-0 download attempt (more info ...)trojan-activity    URL
55038MALWARE-OTHER Win.Malware.Dropperx-9637493-0 download attempt (more info ...)trojan-activity    URL
55039MALWARE-OTHER Win.Malware.Dropperx-9637493-0 download attempt (more info ...)trojan-activity    URL
55040MALWARE-OTHER Win.Downloader.Upatre-9638383-0 download attempt (more info ...)trojan-activity    URL
55041MALWARE-OTHER Win.Downloader.Upatre-9638383-0 download attempt (more info ...)trojan-activity    URL
55042MALWARE-OTHER Win.Malware.Zusy-9638741-0 download attempt (more info ...)trojan-activity    URL
55043MALWARE-OTHER Win.Malware.Zusy-9638741-0 download attempt (more info ...)trojan-activity    URL
55046MALWARE-OTHER Win.Malware.Genpack-9638414-0 download attempt (more info ...)trojan-activity    URL
55047MALWARE-OTHER Win.Malware.Genpack-9638414-0 download attempt (more info ...)trojan-activity    URL
55048MALWARE-OTHER Win.Malware.Genpack-9638419-0 download attempt (more info ...)trojan-activity    URL
55049MALWARE-OTHER Win.Malware.Genpack-9638419-0 download attempt (more info ...)trojan-activity    URL
55052MALWARE-OTHER Win.Malware.Agentb-9639796-0 download attempt (more info ...)trojan-activity    URL
55053MALWARE-OTHER Win.Malware.Agentb-9639796-0 download attempt (more info ...)trojan-activity    URL
55054MALWARE-OTHER Win.Malware.Upatre-9641287-0 download attempt (more info ...)trojan-activity    URL
55055MALWARE-OTHER Win.Malware.Upatre-9641287-0 download attempt (more info ...)trojan-activity    URL
55056MALWARE-OTHER Win.Worm.Sytro-9640596-0 download attempt (more info ...)trojan-activity    URL
55057MALWARE-OTHER Win.Worm.Sytro-9640596-0 download attempt (more info ...)trojan-activity    URL
55058MALWARE-OTHER Win.Malware.Midie-9642391-0 download attempt (more info ...)trojan-activity    URL
55059MALWARE-OTHER Win.Malware.Midie-9642391-0 download attempt (more info ...)trojan-activity    URL
55060MALWARE-OTHER Win.Worm.Sytro-9644119-0 download attempt (more info ...)trojan-activity    URL
55061MALWARE-OTHER Win.Worm.Sytro-9644119-0 download attempt (more info ...)trojan-activity    URL
55062MALWARE-OTHER Win.Malware.Upantix-9644504-0 download attempt (more info ...)trojan-activity    URL
55063MALWARE-OTHER Win.Malware.Upantix-9644504-0 download attempt (more info ...)trojan-activity    URL
55064MALWARE-OTHER Win.Malware.Upantix-9644516-0 download attempt (more info ...)trojan-activity    URL
55065MALWARE-OTHER Win.Malware.Upantix-9644516-0 download attempt (more info ...)trojan-activity    URL
55066MALWARE-OTHER Win.Malware.Razy-9644138-0 download attempt (more info ...)trojan-activity    URL
55067MALWARE-OTHER Win.Malware.Razy-9644138-0 download attempt (more info ...)trojan-activity    URL
55068MALWARE-OTHER Win.Malware.Nitol-9644345-0 download attempt (more info ...)trojan-activity    URL
55069MALWARE-OTHER Win.Malware.Nitol-9644345-0 download attempt (more info ...)trojan-activity    URL
55072MALWARE-OTHER Win.Tool.Zusy-9645231-0 download attempt (more info ...)trojan-activity    URL
55073MALWARE-OTHER Win.Tool.Zusy-9645231-0 download attempt (more info ...)trojan-activity    URL
55074MALWARE-OTHER Win.Packed.Razy-9645233-0 download attempt (more info ...)trojan-activity    URL
55075MALWARE-OTHER Win.Packed.Razy-9645233-0 download attempt (more info ...)trojan-activity    URL
55076MALWARE-OTHER Win.Malware.Zusy-9645326-0 download attempt (more info ...)trojan-activity    URL
55077MALWARE-OTHER Win.Malware.Zusy-9645326-0 download attempt (more info ...)trojan-activity    URL
55080MALWARE-OTHER Win.Malware.Zusy-9645329-0 download attempt (more info ...)trojan-activity    URL
55081MALWARE-OTHER Win.Malware.Zusy-9645329-0 download attempt (more info ...)trojan-activity    URL
55082MALWARE-OTHER Win.Malware.Zusy-9645330-0 download attempt (more info ...)trojan-activity    URL
55083MALWARE-OTHER Win.Malware.Zusy-9645330-0 download attempt (more info ...)trojan-activity    URL
55084MALWARE-OTHER Win.Packed.Razy-9645384-0 download attempt (more info ...)trojan-activity    URL
55085MALWARE-OTHER Win.Packed.Razy-9645384-0 download attempt (more info ...)trojan-activity    URL
55086MALWARE-OTHER Win.Malware.Bqrf-9645595-0 download attempt (more info ...)trojan-activity    URL
55087MALWARE-OTHER Win.Malware.Bqrf-9645595-0 download attempt (more info ...)trojan-activity    URL
55088MALWARE-OTHER Win.Downloader.Upatre-9645450-0 download attempt (more info ...)trojan-activity    URL
55089MALWARE-OTHER Win.Downloader.Upatre-9645450-0 download attempt (more info ...)trojan-activity    URL
55090MALWARE-OTHER Win.Packed.Mikey-9645700-0 download attempt (more info ...)trojan-activity    URL
55091MALWARE-OTHER Win.Packed.Mikey-9645700-0 download attempt (more info ...)trojan-activity    URL
55092MALWARE-OTHER Win.Malware.Zusy-9645872-0 download attempt (more info ...)trojan-activity    URL
55093MALWARE-OTHER Win.Malware.Zusy-9645872-0 download attempt (more info ...)trojan-activity    URL
55094MALWARE-OTHER Win.Malware.Midie-9646220-0 download attempt (more info ...)trojan-activity    URL
55095MALWARE-OTHER Win.Malware.Midie-9646220-0 download attempt (more info ...)trojan-activity    URL
55096MALWARE-OTHER PUA.Win.Tool.Kuaizip-9646234-0 download attempt (more info ...)trojan-activity    URL
55097MALWARE-OTHER PUA.Win.Tool.Kuaizip-9646234-0 download attempt (more info ...)trojan-activity    URL
55098MALWARE-OTHER Win.Malware.Blackmoon-9649168-0 download attempt (more info ...)trojan-activity    URL
55099MALWARE-OTHER Win.Malware.Blackmoon-9649168-0 download attempt (more info ...)trojan-activity    URL
55100MALWARE-OTHER Win.Packed.Generickdz-9651402-0 download attempt (more info ...)trojan-activity    URL
55101MALWARE-OTHER Win.Packed.Generickdz-9651402-0 download attempt (more info ...)trojan-activity    URL
55102MALWARE-OTHER Win.Packed.Urausy-9652317-0 download attempt (more info ...)trojan-activity    URL
55103MALWARE-OTHER Win.Packed.Urausy-9652317-0 download attempt (more info ...)trojan-activity    URL
55108MALWARE-OTHER Win.Malware.Zusy-9652796-0 download attempt (more info ...)trojan-activity    URL
55109MALWARE-OTHER Win.Malware.Zusy-9652796-0 download attempt (more info ...)trojan-activity    URL
55116MALWARE-OTHER Win.Malware.Azzf-9653274-0 download attempt (more info ...)trojan-activity    URL
55117MALWARE-OTHER Win.Malware.Azzf-9653274-0 download attempt (more info ...)trojan-activity    URL
55118MALWARE-OTHER Win.Malware.Azzo-9653275-0 download attempt (more info ...)trojan-activity    URL
55119MALWARE-OTHER Win.Malware.Azzo-9653275-0 download attempt (more info ...)trojan-activity    URL
55120MALWARE-OTHER Win.Malware.Midie-9653298-0 download attempt (more info ...)trojan-activity    URL
55121MALWARE-OTHER Win.Malware.Midie-9653298-0 download attempt (more info ...)trojan-activity    URL
55122MALWARE-OTHER Win.Malware.Dexter-9654223-0 download attempt (more info ...)trojan-activity    URL
55123MALWARE-OTHER Win.Malware.Dexter-9654223-0 download attempt (more info ...)trojan-activity    URL
55126MALWARE-OTHER Win.Trojan.Powerspider-9654501-0 download attempt (more info ...)trojan-activity    URL
55127MALWARE-OTHER Win.Trojan.Powerspider-9654501-0 download attempt (more info ...)trojan-activity    URL
55128MALWARE-OTHER Win.Malware.Ulise-9654608-0 download attempt (more info ...)trojan-activity    URL
55129MALWARE-OTHER Win.Malware.Ulise-9654608-0 download attempt (more info ...)trojan-activity    URL
55130MALWARE-OTHER Win.Trojan.Farfli-9654634-0 download attempt (more info ...)trojan-activity    URL
55131MALWARE-OTHER Win.Trojan.Farfli-9654634-0 download attempt (more info ...)trojan-activity    URL
55132MALWARE-OTHER Win.Downloader.Upatre-9655576-0 download attempt (more info ...)trojan-activity    URL
55133MALWARE-OTHER Win.Downloader.Upatre-9655576-0 download attempt (more info ...)trojan-activity    URL
55136MALWARE-OTHER Win.Malware.Urelas-9655843-0 download attempt (more info ...)trojan-activity    URL
55137MALWARE-OTHER Win.Malware.Urelas-9655843-0 download attempt (more info ...)trojan-activity    URL
55138MALWARE-CNC Win.Trojan.Pioneer outbound communication attempt (more info ...)trojan-activity    URL
55147MALWARE-OTHER PUA.Win.Adware.Burden-9681817-0 download attempt (more info ...)trojan-activity    URL
55148MALWARE-OTHER PUA.Win.Adware.Burden-9681817-0 download attempt (more info ...)trojan-activity    URL
55149MALWARE-OTHER Win.Trojan.Generickdz-9681016-0 download attempt (more info ...)trojan-activity    URL
55150MALWARE-OTHER Win.Trojan.Generickdz-9681016-0 download attempt (more info ...)trojan-activity    URL
55151MALWARE-OTHER Win.Malware.Upatre-9683280-0 download attempt (more info ...)trojan-activity    URL
55152MALWARE-OTHER Win.Malware.Upatre-9683280-0 download attempt (more info ...)trojan-activity    URL
55153MALWARE-OTHER Win.Downloader.Upatre-9683289-0 download attempt (more info ...)trojan-activity    URL
55154MALWARE-OTHER Win.Downloader.Upatre-9683289-0 download attempt (more info ...)trojan-activity    URL
55155MALWARE-OTHER Win.Malware.Upatre-9683300-0 download attempt (more info ...)trojan-activity    URL
55156MALWARE-OTHER Win.Malware.Upatre-9683300-0 download attempt (more info ...)trojan-activity    URL
55157MALWARE-OTHER Win.Packed.Generickdz-9684939-0 download attempt (more info ...)trojan-activity    URL
55158MALWARE-OTHER Win.Packed.Generickdz-9684939-0 download attempt (more info ...)trojan-activity    URL
55159MALWARE-OTHER Win.Malware.Midie-9684412-0 download attempt (more info ...)trojan-activity    URL
55160MALWARE-OTHER Win.Malware.Midie-9684412-0 download attempt (more info ...)trojan-activity    URL
55163MALWARE-OTHER Win.Packed.Urausy-9732721-0 download attempt (more info ...)trojan-activity    URL
55164MALWARE-OTHER Win.Packed.Urausy-9732721-0 download attempt (more info ...)trojan-activity    URL
55165MALWARE-OTHER Win.Malware.Midie-9732633-0 download attempt (more info ...)trojan-activity    URL
55166MALWARE-OTHER Win.Malware.Midie-9732633-0 download attempt (more info ...)trojan-activity    URL
55167MALWARE-OTHER Win.Malware.Upantix-9732988-0 download attempt (more info ...)trojan-activity    URL
55168MALWARE-OTHER Win.Malware.Upantix-9732988-0 download attempt (more info ...)trojan-activity    URL
55171MALWARE-OTHER Win.Trojan.Fugrafa-9733007-0 download attempt (more info ...)trojan-activity    URL
55172MALWARE-OTHER Win.Trojan.Fugrafa-9733007-0 download attempt (more info ...)trojan-activity    URL
55175MALWARE-OTHER Win.Malware.Midie-9733145-0 download attempt (more info ...)trojan-activity    URL
55176MALWARE-OTHER Win.Malware.Midie-9733145-0 download attempt (more info ...)trojan-activity    URL
55181MALWARE-OTHER Win.Malware.Upatre-9733416-0 download attempt (more info ...)trojan-activity    URL
55182MALWARE-OTHER Win.Malware.Upatre-9733416-0 download attempt (more info ...)trojan-activity    URL
55183MALWARE-OTHER Win.Trojan.Trustezeb-9733534-0 download attempt (more info ...)trojan-activity    URL
55184MALWARE-OTHER Win.Trojan.Trustezeb-9733534-0 download attempt (more info ...)trojan-activity    URL
55185MALWARE-OTHER Win.Dropper.Urausy-9733639-0 download attempt (more info ...)trojan-activity    URL
55186MALWARE-OTHER Win.Dropper.Urausy-9733639-0 download attempt (more info ...)trojan-activity    URL
55189MALWARE-OTHER Win.Dropper.Urausy-9733671-0 download attempt (more info ...)trojan-activity    URL
55190MALWARE-OTHER Win.Dropper.Urausy-9733671-0 download attempt (more info ...)trojan-activity    URL
55191MALWARE-OTHER Win.Malware.Midie-9733689-0 download attempt (more info ...)trojan-activity    URL
55192MALWARE-OTHER Win.Malware.Midie-9733689-0 download attempt (more info ...)trojan-activity    URL
55201MALWARE-OTHER Win.Packed.Zbot-9733739-0 download attempt (more info ...)trojan-activity    URL
55202MALWARE-OTHER Win.Packed.Zbot-9733739-0 download attempt (more info ...)trojan-activity    URL
55205MALWARE-CNC Win.Trojan.SoreFang initial outbound connection attempt (more info ...)trojan-activity    URL
55211MALWARE-OTHER Win.Ransomware.Urausy-9734874-0 download attempt (more info ...)trojan-activity    URL
55212MALWARE-OTHER Win.Ransomware.Urausy-9734874-0 download attempt (more info ...)trojan-activity    URL
55213MALWARE-OTHER Win.Packed.Midie-9739435-0 download attempt (more info ...)trojan-activity    URL
55214MALWARE-OTHER Win.Packed.Midie-9739435-0 download attempt (more info ...)trojan-activity    URL
55215MALWARE-OTHER Win.Malware.Delf-9739875-0 download attempt (more info ...)trojan-activity    URL
55216MALWARE-OTHER Win.Malware.Delf-9739875-0 download attempt (more info ...)trojan-activity    URL
55221MALWARE-OTHER Win.Packed.Virlock-9743340-0 download attempt (more info ...)trojan-activity    URL
55222MALWARE-OTHER Win.Packed.Virlock-9743340-0 download attempt (more info ...)trojan-activity    URL
55225MALWARE-OTHER Win.Virus.Wapomi-9751900-0 download attempt (more info ...)trojan-activity    URL
55226MALWARE-OTHER Win.Virus.Wapomi-9751900-0 download attempt (more info ...)trojan-activity    URL
55227MALWARE-OTHER Win.Ransomware.Hiddentear-9752356-0 download attempt (more info ...)trojan-activity    URL
55228MALWARE-OTHER Win.Ransomware.Hiddentear-9752356-0 download attempt (more info ...)trojan-activity    URL
55229MALWARE-OTHER PUA.Win.Adware.Crossrider-9752404-0 download attempt (more info ...)trojan-activity    URL
55230MALWARE-OTHER PUA.Win.Adware.Crossrider-9752404-0 download attempt (more info ...)trojan-activity    URL
55231MALWARE-OTHER PUA.Win.Adware.Crossrider-9752406-0 download attempt (more info ...)trojan-activity    URL
55232MALWARE-OTHER PUA.Win.Adware.Crossrider-9752406-0 download attempt (more info ...)trojan-activity    URL
55233MALWARE-OTHER Win.Trojan.Generic-9752335-0 download attempt (more info ...)trojan-activity    URL
55234MALWARE-OTHER Win.Trojan.Generic-9752335-0 download attempt (more info ...)trojan-activity    URL
55235MALWARE-OTHER PUA.Win.Adware.Xetapp-9752373-0 download attempt (more info ...)trojan-activity    URL
55236MALWARE-OTHER PUA.Win.Adware.Xetapp-9752373-0 download attempt (more info ...)trojan-activity    URL
55237MALWARE-OTHER Win.Keylogger.Ursu-9752377-0 download attempt (more info ...)trojan-activity    URL
55238MALWARE-OTHER Win.Keylogger.Ursu-9752377-0 download attempt (more info ...)trojan-activity    URL
55239MALWARE-OTHER Win.Trojan.Fugrafa-9752450-0 download attempt (more info ...)trojan-activity    URL
55240MALWARE-OTHER Win.Trojan.Fugrafa-9752450-0 download attempt (more info ...)trojan-activity    URL
55243MALWARE-OTHER Win.Trojan.Elzob-9752485-0 download attempt (more info ...)trojan-activity    URL
55244MALWARE-OTHER Win.Trojan.Elzob-9752485-0 download attempt (more info ...)trojan-activity    URL
55245MALWARE-OTHER Win.Malware.Awdfvxk-9752552-0 download attempt (more info ...)trojan-activity    URL
55246MALWARE-OTHER Win.Malware.Awdfvxk-9752552-0 download attempt (more info ...)trojan-activity    URL
55247MALWARE-OTHER Win.Malware.Trojanx-9752983-0 download attempt (more info ...)trojan-activity    URL
55248MALWARE-OTHER Win.Malware.Trojanx-9752983-0 download attempt (more info ...)trojan-activity    URL
55249MALWARE-OTHER Win.Malware.Tiny-9752957-0 download attempt (more info ...)trojan-activity    URL
55250MALWARE-OTHER Win.Malware.Tiny-9752957-0 download attempt (more info ...)trojan-activity    URL
55251MALWARE-OTHER Win.Malware.Ulise-9752577-0 download attempt (more info ...)trojan-activity    URL
55252MALWARE-OTHER Win.Malware.Ulise-9752577-0 download attempt (more info ...)trojan-activity    URL
55253MALWARE-OTHER Win.Trojan.Emotet-9753016-0 download attempt (more info ...)trojan-activity    URL
55254MALWARE-OTHER Win.Trojan.Emotet-9753016-0 download attempt (more info ...)trojan-activity    URL
55255MALWARE-OTHER PUA.Win.Adware.Linkury-9752549-0 download attempt (more info ...)trojan-activity    URL
55256MALWARE-OTHER PUA.Win.Adware.Linkury-9752549-0 download attempt (more info ...)trojan-activity    URL
55257MALWARE-OTHER Win.Malware.Xga5jam-9753060-0 download attempt (more info ...)trojan-activity    URL
55258MALWARE-OTHER Win.Malware.Xga5jam-9753060-0 download attempt (more info ...)trojan-activity    URL
55259MALWARE-OTHER Win.Downloader.Karagany-9753243-0 download attempt (more info ...)trojan-activity    URL
55260MALWARE-OTHER Win.Downloader.Karagany-9753243-0 download attempt (more info ...)trojan-activity    URL
55261MALWARE-OTHER Win.Trojan.Urausy-9753337-0 download attempt (more info ...)trojan-activity    URL
55262MALWARE-OTHER Win.Trojan.Urausy-9753337-0 download attempt (more info ...)trojan-activity    URL
55263MALWARE-OTHER Win.Malware.Cerbu-9753116-0 download attempt (more info ...)trojan-activity    URL
55264MALWARE-OTHER Win.Malware.Cerbu-9753116-0 download attempt (more info ...)trojan-activity    URL
55265MALWARE-OTHER Win.Trojan.Reveton-9753409-0 download attempt (more info ...)trojan-activity    URL
55266MALWARE-OTHER Win.Trojan.Reveton-9753409-0 download attempt (more info ...)trojan-activity    URL
55271MALWARE-OTHER PUA.Win.Downloader.Softcnapp-9753183-0 download attempt (more info ...)trojan-activity    URL
55272MALWARE-OTHER PUA.Win.Downloader.Softcnapp-9753183-0 download attempt (more info ...)trojan-activity    URL
55273MALWARE-OTHER Win.Ransomware.Hlux-9753302-0 download attempt (more info ...)trojan-activity    URL
55274MALWARE-OTHER Win.Ransomware.Hlux-9753302-0 download attempt (more info ...)trojan-activity    URL
55275MALWARE-OTHER Win.Malware.Razy-9753125-0 download attempt (more info ...)trojan-activity    URL
55276MALWARE-OTHER Win.Malware.Razy-9753125-0 download attempt (more info ...)trojan-activity    URL
55279MALWARE-OTHER Win.Packed.Karagany-9753308-0 download attempt (more info ...)trojan-activity    URL
55280MALWARE-OTHER Win.Packed.Karagany-9753308-0 download attempt (more info ...)trojan-activity    URL
55281MALWARE-OTHER Win.Trojan.Zegost-9753424-0 download attempt (more info ...)trojan-activity    URL
55282MALWARE-OTHER Win.Trojan.Zegost-9753424-0 download attempt (more info ...)trojan-activity    URL
55283MALWARE-OTHER Win.Trojan.Bublik-9753310-0 download attempt (more info ...)trojan-activity    URL
55284MALWARE-OTHER Win.Trojan.Bublik-9753310-0 download attempt (more info ...)trojan-activity    URL
55285MALWARE-OTHER Win.Ransomware.Zusy-9753315-0 download attempt (more info ...)trojan-activity    URL
55286MALWARE-OTHER Win.Ransomware.Zusy-9753315-0 download attempt (more info ...)trojan-activity    URL
55287MALWARE-OTHER PUA.Win.File.Razy-9753095-0 download attempt (more info ...)trojan-activity    URL
55288MALWARE-OTHER PUA.Win.File.Razy-9753095-0 download attempt (more info ...)trojan-activity    URL
55289MALWARE-OTHER PUA.Win.File.Razy-9753096-0 download attempt (more info ...)trojan-activity    URL
55290MALWARE-OTHER PUA.Win.File.Razy-9753096-0 download attempt (more info ...)trojan-activity    URL
55291MALWARE-OTHER Win.Trojan.Bublik-9753317-0 download attempt (more info ...)trojan-activity    URL
55292MALWARE-OTHER Win.Trojan.Bublik-9753317-0 download attempt (more info ...)trojan-activity    URL
55293MALWARE-OTHER Win.Trojan.Bublik-9753312-0 download attempt (more info ...)trojan-activity    URL
55294MALWARE-OTHER Win.Trojan.Bublik-9753312-0 download attempt (more info ...)trojan-activity    URL
55295MALWARE-OTHER PUA.Win.File.Razy-9753099-0 download attempt (more info ...)trojan-activity    URL
55296MALWARE-OTHER PUA.Win.File.Razy-9753099-0 download attempt (more info ...)trojan-activity    URL
55297MALWARE-OTHER PUA.Win.File.Razy-9753100-0 download attempt (more info ...)trojan-activity    URL
55298MALWARE-OTHER PUA.Win.File.Razy-9753100-0 download attempt (more info ...)trojan-activity    URL
55299MALWARE-OTHER PUA.Win.File.Razy-9753102-0 download attempt (more info ...)trojan-activity    URL
55300MALWARE-OTHER PUA.Win.File.Razy-9753102-0 download attempt (more info ...)trojan-activity    URL
55301MALWARE-OTHER Win.Malware.Razy-9753197-0 download attempt (more info ...)trojan-activity    URL
55302MALWARE-OTHER Win.Malware.Razy-9753197-0 download attempt (more info ...)trojan-activity    URL
55303MALWARE-OTHER PUA.Win.File.Razy-9753103-0 download attempt (more info ...)trojan-activity    URL
55304MALWARE-OTHER PUA.Win.File.Razy-9753103-0 download attempt (more info ...)trojan-activity    URL
55307MALWARE-OTHER Win.Dropper.Urausy-9753391-0 download attempt (more info ...)trojan-activity    URL
55308MALWARE-OTHER Win.Dropper.Urausy-9753391-0 download attempt (more info ...)trojan-activity    URL
55309MALWARE-OTHER Win.Packed.Kovter-9753452-0 download attempt (more info ...)trojan-activity    URL
55310MALWARE-OTHER Win.Packed.Kovter-9753452-0 download attempt (more info ...)trojan-activity    URL
55311MALWARE-OTHER Win.Trojan.Farfli-9753454-0 download attempt (more info ...)trojan-activity    URL
55312MALWARE-OTHER Win.Trojan.Farfli-9753454-0 download attempt (more info ...)trojan-activity    URL
55313MALWARE-OTHER Win.Trojan.Urausy-9753468-0 download attempt (more info ...)trojan-activity    URL
55314MALWARE-OTHER Win.Trojan.Urausy-9753468-0 download attempt (more info ...)trojan-activity    URL
55315MALWARE-OTHER Win.Trojan.Redosdru-9753542-0 download attempt (more info ...)trojan-activity    URL
55316MALWARE-OTHER Win.Trojan.Redosdru-9753542-0 download attempt (more info ...)trojan-activity    URL
55319MALWARE-OTHER Win.Trojan.Poison-9753599-0 download attempt (more info ...)trojan-activity    URL
55320MALWARE-OTHER Win.Trojan.Poison-9753599-0 download attempt (more info ...)trojan-activity    URL
55321MALWARE-OTHER Win.Ransomware.Generickdz-9753680-0 download attempt (more info ...)trojan-activity    URL
55322MALWARE-OTHER Win.Ransomware.Generickdz-9753680-0 download attempt (more info ...)trojan-activity    URL
55323MALWARE-OTHER Win.Packed.Zbot-9753857-0 download attempt (more info ...)trojan-activity    URL
55324MALWARE-OTHER Win.Packed.Zbot-9753857-0 download attempt (more info ...)trojan-activity    URL
55325MALWARE-OTHER Win.Ransomware.Reveton-9753942-0 download attempt (more info ...)trojan-activity    URL
55326MALWARE-OTHER Win.Ransomware.Reveton-9753942-0 download attempt (more info ...)trojan-activity    URL
55331MALWARE-OTHER Win.Trojan.Zusy-9754178-0 download attempt (more info ...)trojan-activity    URL
55332MALWARE-OTHER Win.Trojan.Zusy-9754178-0 download attempt (more info ...)trojan-activity    URL
55333MALWARE-OTHER Win.Worm.Palevo-9754103-0 download attempt (more info ...)trojan-activity    URL
55334MALWARE-OTHER Win.Worm.Palevo-9754103-0 download attempt (more info ...)trojan-activity    URL
55335MALWARE-OTHER PUA.Win.Tool.Patcher-9753989-0 download attempt (more info ...)trojan-activity    URL
55336MALWARE-OTHER PUA.Win.Tool.Patcher-9753989-0 download attempt (more info ...)trojan-activity    URL
55337MALWARE-OTHER Win.Packed.Upatre-9754286-0 download attempt (more info ...)trojan-activity    URL
55338MALWARE-OTHER Win.Packed.Upatre-9754286-0 download attempt (more info ...)trojan-activity    URL
55339MALWARE-OTHER Win.Packed.Fareit-9754219-0 download attempt (more info ...)trojan-activity    URL
55340MALWARE-OTHER Win.Packed.Fareit-9754219-0 download attempt (more info ...)trojan-activity    URL
55341MALWARE-OTHER Win.Dropper.Reveton-9754019-0 download attempt (more info ...)trojan-activity    URL
55342MALWARE-OTHER Win.Dropper.Reveton-9754019-0 download attempt (more info ...)trojan-activity    URL
55343MALWARE-OTHER Win.Malware.Magania-9754156-0 download attempt (more info ...)trojan-activity    URL
55344MALWARE-OTHER Win.Malware.Magania-9754156-0 download attempt (more info ...)trojan-activity    URL
55345MALWARE-OTHER Win.Dropper.Urausy-9754318-0 download attempt (more info ...)trojan-activity    URL
55346MALWARE-OTHER Win.Dropper.Urausy-9754318-0 download attempt (more info ...)trojan-activity    URL
55347MALWARE-OTHER Win.Dropper.Zbot-9754356-0 download attempt (more info ...)trojan-activity    URL
55348MALWARE-OTHER Win.Dropper.Zbot-9754356-0 download attempt (more info ...)trojan-activity    URL
55351MALWARE-OTHER Win.Packed.Zbot-9754450-0 download attempt (more info ...)trojan-activity    URL
55352MALWARE-OTHER Win.Packed.Zbot-9754450-0 download attempt (more info ...)trojan-activity    URL
55353MALWARE-OTHER Win.Trojan.Barys-9754805-0 download attempt (more info ...)trojan-activity    URL
55354MALWARE-OTHER Win.Trojan.Barys-9754805-0 download attempt (more info ...)trojan-activity    URL
55355MALWARE-OTHER Win.Malware.Tiny-9754577-0 download attempt (more info ...)trojan-activity    URL
55356MALWARE-OTHER Win.Malware.Tiny-9754577-0 download attempt (more info ...)trojan-activity    URL
55359MALWARE-OTHER Win.Dropper.Zbot-9754812-0 download attempt (more info ...)trojan-activity    URL
55360MALWARE-OTHER Win.Dropper.Zbot-9754812-0 download attempt (more info ...)trojan-activity    URL
55361MALWARE-OTHER Win.Trojan.Battdil-9755096-0 download attempt (more info ...)trojan-activity    URL
55362MALWARE-OTHER Win.Trojan.Battdil-9755096-0 download attempt (more info ...)trojan-activity    URL
55363MALWARE-OTHER Win.Trojan.Zbot-9755097-0 download attempt (more info ...)trojan-activity    URL
55364MALWARE-OTHER Win.Trojan.Zbot-9755097-0 download attempt (more info ...)trojan-activity    URL
55367MALWARE-OTHER Win.Ransomware.Urausy-9754748-0 download attempt (more info ...)trojan-activity    URL
55368MALWARE-OTHER Win.Ransomware.Urausy-9754748-0 download attempt (more info ...)trojan-activity    URL
55369MALWARE-OTHER PUA.Win.Adware.Kranet-9754977-0 download attempt (more info ...)trojan-activity    URL
55370MALWARE-OTHER PUA.Win.Adware.Kranet-9754977-0 download attempt (more info ...)trojan-activity    URL
55371MALWARE-OTHER Win.Trojan.Farfli-9754465-0 download attempt (more info ...)trojan-activity    URL
55372MALWARE-OTHER Win.Trojan.Farfli-9754465-0 download attempt (more info ...)trojan-activity    URL
55373MALWARE-OTHER Win.Packed.Generickdz-9754466-0 download attempt (more info ...)trojan-activity    URL
55374MALWARE-OTHER Win.Packed.Generickdz-9754466-0 download attempt (more info ...)trojan-activity    URL
55375MALWARE-OTHER Win.Packed.Upatre-9754980-0 download attempt (more info ...)trojan-activity    URL
55376MALWARE-OTHER Win.Packed.Upatre-9754980-0 download attempt (more info ...)trojan-activity    URL
55377MALWARE-OTHER PUA.Win.Adware.Linkury-9755039-0 download attempt (more info ...)trojan-activity    URL
55378MALWARE-OTHER PUA.Win.Adware.Linkury-9755039-0 download attempt (more info ...)trojan-activity    URL
55379MALWARE-OTHER Win.Malware.Presenoker-9754467-0 download attempt (more info ...)trojan-activity    URL
55380MALWARE-OTHER Win.Malware.Presenoker-9754467-0 download attempt (more info ...)trojan-activity    URL
55383MALWARE-OTHER Win.Packed.Hlux-9754904-0 download attempt (more info ...)trojan-activity    URL
55384MALWARE-OTHER Win.Packed.Hlux-9754904-0 download attempt (more info ...)trojan-activity    URL
55385MALWARE-OTHER Win.Packed.Zbot-9754905-0 download attempt (more info ...)trojan-activity    URL
55386MALWARE-OTHER Win.Packed.Zbot-9754905-0 download attempt (more info ...)trojan-activity    URL
55387MALWARE-OTHER Win.Packed.Hlux-9754909-0 download attempt (more info ...)trojan-activity    URL
55388MALWARE-OTHER Win.Packed.Hlux-9754909-0 download attempt (more info ...)trojan-activity    URL
55389MALWARE-OTHER PUA.Win.Adware.Kranet-9754985-0 download attempt (more info ...)trojan-activity    URL
55390MALWARE-OTHER PUA.Win.Adware.Kranet-9754985-0 download attempt (more info ...)trojan-activity    URL
55391MALWARE-OTHER Win.Malware.Ponmocup-9754986-0 download attempt (more info ...)trojan-activity    URL
55392MALWARE-OTHER Win.Malware.Ponmocup-9754986-0 download attempt (more info ...)trojan-activity    URL
55393MALWARE-OTHER Win.Dropper.Tofsee-9754919-0 download attempt (more info ...)trojan-activity    URL
55394MALWARE-OTHER Win.Dropper.Tofsee-9754919-0 download attempt (more info ...)trojan-activity    URL
55399MALWARE-OTHER Win.Trojan.Urausy-9754492-0 download attempt (more info ...)trojan-activity    URL
55400MALWARE-OTHER Win.Trojan.Urausy-9754492-0 download attempt (more info ...)trojan-activity    URL
55401MALWARE-OTHER Win.Dropper.Urausy-9754785-0 download attempt (more info ...)trojan-activity    URL
55402MALWARE-OTHER Win.Dropper.Urausy-9754785-0 download attempt (more info ...)trojan-activity    URL
55403MALWARE-OTHER Win.Trojan.Aqaatbp-9754496-0 download attempt (more info ...)trojan-activity    URL
55404MALWARE-OTHER Win.Trojan.Aqaatbp-9754496-0 download attempt (more info ...)trojan-activity    URL
55405MALWARE-OTHER Win.Trojan.Istartsurf-9755079-0 download attempt (more info ...)trojan-activity    URL
55406MALWARE-OTHER Win.Trojan.Istartsurf-9755079-0 download attempt (more info ...)trojan-activity    URL
55407MALWARE-OTHER PUA.Win.Adware.Istartsurf-9755081-0 download attempt (more info ...)trojan-activity    URL
55408MALWARE-OTHER PUA.Win.Adware.Istartsurf-9755081-0 download attempt (more info ...)trojan-activity    URL
55409MALWARE-OTHER Win.Trojan.Lurk-9754564-0 download attempt (more info ...)trojan-activity    URL
55410MALWARE-OTHER Win.Trojan.Lurk-9754564-0 download attempt (more info ...)trojan-activity    URL
55413MALWARE-OTHER Win.Trojan.Winwebsec-9754570-0 download attempt (more info ...)trojan-activity    URL
55414MALWARE-OTHER Win.Trojan.Winwebsec-9754570-0 download attempt (more info ...)trojan-activity    URL
55415MALWARE-OTHER Win.Trojan.Battdil-9755088-0 download attempt (more info ...)trojan-activity    URL
55416MALWARE-OTHER Win.Trojan.Battdil-9755088-0 download attempt (more info ...)trojan-activity    URL
55417MALWARE-OTHER Win.Trojan.Zbot-9755091-0 download attempt (more info ...)trojan-activity    URL
55418MALWARE-OTHER Win.Trojan.Zbot-9755091-0 download attempt (more info ...)trojan-activity    URL
55419MALWARE-OTHER Win.Dropper.Zeus-9755181-0 download attempt (more info ...)trojan-activity    URL
55420MALWARE-OTHER Win.Dropper.Zeus-9755181-0 download attempt (more info ...)trojan-activity    URL
55421MALWARE-OTHER Win.Dropper.Gh0stRAT-9755251-0 download attempt (more info ...)trojan-activity    URL
55422MALWARE-OTHER Win.Dropper.Gh0stRAT-9755251-0 download attempt (more info ...)trojan-activity    URL
55425MALWARE-OTHER Win.Dropper.Zeus-9755634-0 download attempt (more info ...)trojan-activity    URL
55426MALWARE-OTHER Win.Dropper.Zeus-9755634-0 download attempt (more info ...)trojan-activity    URL
55429MALWARE-OTHER Win.Dropper.DarkKomet-9755779-0 download attempt (more info ...)trojan-activity    URL
55430MALWARE-OTHER Win.Dropper.DarkKomet-9755779-0 download attempt (more info ...)trojan-activity    URL
55431MALWARE-OTHER Win.Dropper.Gh0stRAT-9755640-0 download attempt (more info ...)trojan-activity    URL
55432MALWARE-OTHER Win.Dropper.Gh0stRAT-9755640-0 download attempt (more info ...)trojan-activity    URL
55433MALWARE-OTHER Win.Dropper.DarkKomet-9755764-0 download attempt (more info ...)trojan-activity    URL
55434MALWARE-OTHER Win.Dropper.DarkKomet-9755764-0 download attempt (more info ...)trojan-activity    URL
55435MALWARE-OTHER Win.Dropper.XtremeRAT-9756061-0 download attempt (more info ...)trojan-activity    URL
55436MALWARE-OTHER Win.Dropper.XtremeRAT-9756061-0 download attempt (more info ...)trojan-activity    URL
55437MALWARE-OTHER Win.Trojan.Lockscreen-9756656-0 download attempt (more info ...)trojan-activity    URL
55438MALWARE-OTHER Win.Trojan.Lockscreen-9756656-0 download attempt (more info ...)trojan-activity    URL
55439MALWARE-OTHER Win.Ransomware.Urausy-9756790-0 download attempt (more info ...)trojan-activity    URL
55440MALWARE-OTHER Win.Ransomware.Urausy-9756790-0 download attempt (more info ...)trojan-activity    URL
55441MALWARE-OTHER Win.Packed.Upatre-9756930-0 download attempt (more info ...)trojan-activity    URL
55442MALWARE-OTHER Win.Packed.Upatre-9756930-0 download attempt (more info ...)trojan-activity    URL
55443MALWARE-OTHER Win.Trojan.Generickdz-9756791-0 download attempt (more info ...)trojan-activity    URL
55444MALWARE-OTHER Win.Trojan.Generickdz-9756791-0 download attempt (more info ...)trojan-activity    URL
55445MALWARE-OTHER Win.Trojan.Zbot-9756755-0 download attempt (more info ...)trojan-activity    URL
55446MALWARE-OTHER Win.Trojan.Zbot-9756755-0 download attempt (more info ...)trojan-activity    URL
55451MALWARE-OTHER Win.Dropper.Reveton-9756813-0 download attempt (more info ...)trojan-activity    URL
55452MALWARE-OTHER Win.Dropper.Reveton-9756813-0 download attempt (more info ...)trojan-activity    URL
55453MALWARE-OTHER Win.Trojan.Zbot-9756766-0 download attempt (more info ...)trojan-activity    URL
55454MALWARE-OTHER Win.Trojan.Zbot-9756766-0 download attempt (more info ...)trojan-activity    URL
55455MALWARE-OTHER Win.Trojan.Generickdz-9756770-0 download attempt (more info ...)trojan-activity    URL
55456MALWARE-OTHER Win.Trojan.Generickdz-9756770-0 download attempt (more info ...)trojan-activity    URL
55461MALWARE-OTHER Win.Packed.Fareit-9756837-0 download attempt (more info ...)trojan-activity    URL
55462MALWARE-OTHER Win.Packed.Fareit-9756837-0 download attempt (more info ...)trojan-activity    URL
55463MALWARE-OTHER Win.Downloader.Upatre-9756916-0 download attempt (more info ...)trojan-activity    URL
55464MALWARE-OTHER Win.Downloader.Upatre-9756916-0 download attempt (more info ...)trojan-activity    URL
55465MALWARE-OTHER Win.Malware.Deepscan-9757176-0 download attempt (more info ...)trojan-activity    URL
55466MALWARE-OTHER Win.Malware.Deepscan-9757176-0 download attempt (more info ...)trojan-activity    URL
55471MALWARE-OTHER Win.Malware.Ursu-9757272-0 download attempt (more info ...)trojan-activity    URL
55472MALWARE-OTHER Win.Malware.Ursu-9757272-0 download attempt (more info ...)trojan-activity    URL
55473MALWARE-OTHER Win.Packed.Ursu-9757277-0 download attempt (more info ...)trojan-activity    URL
55474MALWARE-OTHER Win.Packed.Ursu-9757277-0 download attempt (more info ...)trojan-activity    URL
55475MALWARE-OTHER Win.Ransomware.Ransomer-9757261-0 download attempt (more info ...)trojan-activity    URL
55476MALWARE-OTHER Win.Ransomware.Ransomer-9757261-0 download attempt (more info ...)trojan-activity    URL
55477MALWARE-OTHER PUA.Win.Adware.Kranet-9757293-0 download attempt (more info ...)trojan-activity    URL
55478MALWARE-OTHER PUA.Win.Adware.Kranet-9757293-0 download attempt (more info ...)trojan-activity    URL
55483MALWARE-OTHER Win.Trojan.Zusy-9757564-0 download attempt (more info ...)trojan-activity    URL
55484MALWARE-OTHER Win.Trojan.Zusy-9757564-0 download attempt (more info ...)trojan-activity    URL
55485MALWARE-OTHER Win.Dropper.Reveton-9757590-0 download attempt (more info ...)trojan-activity    URL
55486MALWARE-OTHER Win.Dropper.Reveton-9757590-0 download attempt (more info ...)trojan-activity    URL
55487MALWARE-OTHER Win.Packed.Urausy-9757600-0 download attempt (more info ...)trojan-activity    URL
55488MALWARE-OTHER Win.Packed.Urausy-9757600-0 download attempt (more info ...)trojan-activity    URL
55493MALWARE-OTHER Win.Packed.Zbot-9757645-0 download attempt (more info ...)trojan-activity    URL
55494MALWARE-OTHER Win.Packed.Zbot-9757645-0 download attempt (more info ...)trojan-activity    URL
55495MALWARE-OTHER Win.Packed.Zbot-9757656-0 download attempt (more info ...)trojan-activity    URL
55496MALWARE-OTHER Win.Packed.Zbot-9757656-0 download attempt (more info ...)trojan-activity    URL
55497MALWARE-OTHER Win.Dropper.Urausy-9757745-0 download attempt (more info ...)trojan-activity    URL
55498MALWARE-OTHER Win.Dropper.Urausy-9757745-0 download attempt (more info ...)trojan-activity    URL
55503MALWARE-OTHER Win.Packed.Ramnit-9757820-0 download attempt (more info ...)trojan-activity    URL
55504MALWARE-OTHER Win.Packed.Ramnit-9757820-0 download attempt (more info ...)trojan-activity    URL
55509MALWARE-OTHER Win.Packed.Urausy-9758012-0 download attempt (more info ...)trojan-activity    URL
55510MALWARE-OTHER Win.Packed.Urausy-9758012-0 download attempt (more info ...)trojan-activity    URL
55511MALWARE-OTHER Win.Packed.Urausy-9758052-0 download attempt (more info ...)trojan-activity    URL
55512MALWARE-OTHER Win.Packed.Urausy-9758052-0 download attempt (more info ...)trojan-activity    URL
55513MALWARE-OTHER Win.Packed.Urausy-9758013-0 download attempt (more info ...)trojan-activity    URL
55514MALWARE-OTHER Win.Packed.Urausy-9758013-0 download attempt (more info ...)trojan-activity    URL
55515MALWARE-OTHER Win.Ransomware.Urausy-9758053-0 download attempt (more info ...)trojan-activity    URL
55516MALWARE-OTHER Win.Ransomware.Urausy-9758053-0 download attempt (more info ...)trojan-activity    URL
55517MALWARE-OTHER Win.Trojan.Tinba-9758102-0 download attempt (more info ...)trojan-activity    URL
55518MALWARE-OTHER Win.Trojan.Tinba-9758102-0 download attempt (more info ...)trojan-activity    URL
55523MALWARE-OTHER Win.Malware.Tinba-9758106-0 download attempt (more info ...)trojan-activity    URL
55524MALWARE-OTHER Win.Malware.Tinba-9758106-0 download attempt (more info ...)trojan-activity    URL
55525MALWARE-OTHER Win.Ransomware.Urausy-9758117-0 download attempt (more info ...)trojan-activity    URL
55526MALWARE-OTHER Win.Ransomware.Urausy-9758117-0 download attempt (more info ...)trojan-activity    URL
55527MALWARE-OTHER Win.Packed.Zbot-9757974-0 download attempt (more info ...)trojan-activity    URL
55528MALWARE-OTHER Win.Packed.Zbot-9757974-0 download attempt (more info ...)trojan-activity    URL
55529MALWARE-OTHER Win.Packed.Zbot-9757870-0 download attempt (more info ...)trojan-activity    URL
55530MALWARE-OTHER Win.Packed.Zbot-9757870-0 download attempt (more info ...)trojan-activity    URL
55531MALWARE-OTHER Win.Dropper.Urausy-9758048-0 download attempt (more info ...)trojan-activity    URL
55532MALWARE-OTHER Win.Dropper.Urausy-9758048-0 download attempt (more info ...)trojan-activity    URL
55533MALWARE-OTHER Win.Trojan.Winwebsec-9758126-0 download attempt (more info ...)trojan-activity    URL
55534MALWARE-OTHER Win.Trojan.Winwebsec-9758126-0 download attempt (more info ...)trojan-activity    URL
55535MALWARE-OTHER Win.Ransomware.Urausy-9758127-0 download attempt (more info ...)trojan-activity    URL
55536MALWARE-OTHER Win.Ransomware.Urausy-9758127-0 download attempt (more info ...)trojan-activity    URL
55539MALWARE-OTHER Win.Trojan.Spyeye-9758171-0 download attempt (more info ...)trojan-activity    URL
55540MALWARE-OTHER Win.Trojan.Spyeye-9758171-0 download attempt (more info ...)trojan-activity    URL
55541MALWARE-OTHER Win.Malware.Agen-9758186-0 download attempt (more info ...)trojan-activity    URL
55542MALWARE-OTHER Win.Malware.Agen-9758186-0 download attempt (more info ...)trojan-activity    URL
55545MALWARE-OTHER Win.Trojan.Urausy-9758291-0 download attempt (more info ...)trojan-activity    URL
55546MALWARE-OTHER Win.Trojan.Urausy-9758291-0 download attempt (more info ...)trojan-activity    URL
55547MALWARE-OTHER Win.Trojan.Urausy-9758294-0 download attempt (more info ...)trojan-activity    URL
55548MALWARE-OTHER Win.Trojan.Urausy-9758294-0 download attempt (more info ...)trojan-activity    URL
55549MALWARE-OTHER Win.Trojan.Zegost-9758347-0 download attempt (more info ...)trojan-activity    URL
55550MALWARE-OTHER Win.Trojan.Zegost-9758347-0 download attempt (more info ...)trojan-activity    URL
55551MALWARE-OTHER Win.Malware.Regrun-9758329-0 download attempt (more info ...)trojan-activity    URL
55552MALWARE-OTHER Win.Malware.Regrun-9758329-0 download attempt (more info ...)trojan-activity    URL
55555MALWARE-OTHER Win.Packed.Manna-9758481-0 download attempt (more info ...)trojan-activity    URL
55556MALWARE-OTHER Win.Packed.Manna-9758481-0 download attempt (more info ...)trojan-activity    URL
55559MALWARE-OTHER Win.Packed.Zbot-9758572-0 download attempt (more info ...)trojan-activity    URL
55560MALWARE-OTHER Win.Packed.Zbot-9758572-0 download attempt (more info ...)trojan-activity    URL
55561MALWARE-OTHER Win.Dropper.Urausy-9758579-0 download attempt (more info ...)trojan-activity    URL
55562MALWARE-OTHER Win.Dropper.Urausy-9758579-0 download attempt (more info ...)trojan-activity    URL
55563MALWARE-OTHER Win.Trojan.Farfli-9758633-0 download attempt (more info ...)trojan-activity    URL
55564MALWARE-OTHER Win.Trojan.Farfli-9758633-0 download attempt (more info ...)trojan-activity    URL
55565MALWARE-OTHER Win.Trojan.Plugx-9758632-0 download attempt (more info ...)trojan-activity    URL
55566MALWARE-OTHER Win.Trojan.Plugx-9758632-0 download attempt (more info ...)trojan-activity    URL
55567MALWARE-OTHER Win.Trojan.Magania-9758831-0 download attempt (more info ...)trojan-activity    URL
55568MALWARE-OTHER Win.Trojan.Magania-9758831-0 download attempt (more info ...)trojan-activity    URL
55569MALWARE-OTHER Win.Dropper.Urausy-9758586-0 download attempt (more info ...)trojan-activity    URL
55570MALWARE-OTHER Win.Dropper.Urausy-9758586-0 download attempt (more info ...)trojan-activity    URL
55571MALWARE-OTHER Win.Dropper.Zbot-9758839-0 download attempt (more info ...)trojan-activity    URL
55572MALWARE-OTHER Win.Dropper.Zbot-9758839-0 download attempt (more info ...)trojan-activity    URL
55573MALWARE-OTHER Win.Trojan.Farfli-9758840-0 download attempt (more info ...)trojan-activity    URL
55574MALWARE-OTHER Win.Trojan.Farfli-9758840-0 download attempt (more info ...)trojan-activity    URL
55575MALWARE-OTHER Win.Trojan.Farfli-9758597-0 download attempt (more info ...)trojan-activity    URL
55576MALWARE-OTHER Win.Trojan.Farfli-9758597-0 download attempt (more info ...)trojan-activity    URL
55577MALWARE-OTHER Win.Trojan.Fusing-9758602-0 download attempt (more info ...)trojan-activity    URL
55578MALWARE-OTHER Win.Trojan.Fusing-9758602-0 download attempt (more info ...)trojan-activity    URL
55579MALWARE-OTHER Win.Packed.Zbot-9758659-0 download attempt (more info ...)trojan-activity    URL
55580MALWARE-OTHER Win.Packed.Zbot-9758659-0 download attempt (more info ...)trojan-activity    URL
55581MALWARE-OTHER Win.Trojan.Zegost-9758623-0 download attempt (more info ...)trojan-activity    URL
55582MALWARE-OTHER Win.Trojan.Zegost-9758623-0 download attempt (more info ...)trojan-activity    URL
55583MALWARE-OTHER Win.Dropper.Ngrbot-9758910-0 download attempt (more info ...)trojan-activity    URL
55584MALWARE-OTHER Win.Dropper.Ngrbot-9758910-0 download attempt (more info ...)trojan-activity    URL
55585MALWARE-OTHER Win.Packed.Upatre-9758965-0 download attempt (more info ...)trojan-activity    URL
55586MALWARE-OTHER Win.Packed.Upatre-9758965-0 download attempt (more info ...)trojan-activity    URL
55587MALWARE-OTHER Win.Downloader.Banload-9758978-0 download attempt (more info ...)trojan-activity    URL
55588MALWARE-OTHER Win.Downloader.Banload-9758978-0 download attempt (more info ...)trojan-activity    URL
55591MALWARE-OTHER Win.Keylogger.Emotet-9759052-0 download attempt (more info ...)trojan-activity    URL
55592MALWARE-OTHER Win.Keylogger.Emotet-9759052-0 download attempt (more info ...)trojan-activity    URL
55593MALWARE-OTHER Win.Malware.Smartfortress-9759254-0 download attempt (more info ...)trojan-activity    URL
55594MALWARE-OTHER Win.Malware.Smartfortress-9759254-0 download attempt (more info ...)trojan-activity    URL
55595MALWARE-OTHER Win.Packed.Fareit-9759311-0 download attempt (more info ...)trojan-activity    URL
55596MALWARE-OTHER Win.Packed.Fareit-9759311-0 download attempt (more info ...)trojan-activity    URL
55597MALWARE-OTHER PUA.Win.Adware.Addlyrics-9759168-0 download attempt (more info ...)trojan-activity    URL
55598MALWARE-OTHER PUA.Win.Adware.Addlyrics-9759168-0 download attempt (more info ...)trojan-activity    URL
55599MALWARE-OTHER Win.Packed.Urausy-9759316-0 download attempt (more info ...)trojan-activity    URL
55600MALWARE-OTHER Win.Packed.Urausy-9759316-0 download attempt (more info ...)trojan-activity    URL
55601MALWARE-OTHER Win.Downloader.Jrcx-9759211-0 download attempt (more info ...)trojan-activity    URL
55602MALWARE-OTHER Win.Downloader.Jrcx-9759211-0 download attempt (more info ...)trojan-activity    URL
55603MALWARE-OTHER Win.Packed.Kovter-9759186-0 download attempt (more info ...)trojan-activity    URL
55604MALWARE-OTHER Win.Packed.Kovter-9759186-0 download attempt (more info ...)trojan-activity    URL
55607MALWARE-OTHER Win.Worm.Gamarue-9759120-0 download attempt (more info ...)trojan-activity    URL
55608MALWARE-OTHER Win.Worm.Gamarue-9759120-0 download attempt (more info ...)trojan-activity    URL
55609MALWARE-OTHER Win.Ransomware.Zusy-9759193-0 download attempt (more info ...)trojan-activity    URL
55610MALWARE-OTHER Win.Ransomware.Zusy-9759193-0 download attempt (more info ...)trojan-activity    URL
55611MALWARE-OTHER Win.Malware.Rincux-9759478-0 download attempt (more info ...)trojan-activity    URL
55612MALWARE-OTHER Win.Malware.Rincux-9759478-0 download attempt (more info ...)trojan-activity    URL
55615MALWARE-OTHER Win.Packed.Generickdz-9759456-0 download attempt (more info ...)trojan-activity    URL
55616MALWARE-OTHER Win.Packed.Generickdz-9759456-0 download attempt (more info ...)trojan-activity    URL
55617MALWARE-OTHER Win.Packed.Reveton-9759474-0 download attempt (more info ...)trojan-activity    URL
55618MALWARE-OTHER Win.Packed.Reveton-9759474-0 download attempt (more info ...)trojan-activity    URL
55623MALWARE-OTHER Win.Packed.Zpack-9759629-0 download attempt (more info ...)trojan-activity    URL
55624MALWARE-OTHER Win.Packed.Zpack-9759629-0 download attempt (more info ...)trojan-activity    URL
55625MALWARE-OTHER Win.Trojan.Zbot-9759650-0 download attempt (more info ...)trojan-activity    URL
55626MALWARE-OTHER Win.Trojan.Zbot-9759650-0 download attempt (more info ...)trojan-activity    URL
55627MALWARE-OTHER Win.Dropper.Urausy-9759663-0 download attempt (more info ...)trojan-activity    URL
55628MALWARE-OTHER Win.Dropper.Urausy-9759663-0 download attempt (more info ...)trojan-activity    URL
55629MALWARE-OTHER Win.Trojan.Generic-9759774-0 download attempt (more info ...)trojan-activity    URL
55630MALWARE-OTHER Win.Trojan.Generic-9759774-0 download attempt (more info ...)trojan-activity    URL
55631MALWARE-OTHER Win.Trojan.Ircbot-9759926-0 download attempt (more info ...)trojan-activity    URL
55632MALWARE-OTHER Win.Trojan.Ircbot-9759926-0 download attempt (more info ...)trojan-activity    URL
55635MALWARE-OTHER Win.Malware.Syddldg-9759963-0 download attempt (more info ...)trojan-activity    URL
55636MALWARE-OTHER Win.Malware.Syddldg-9759963-0 download attempt (more info ...)trojan-activity    URL
55641FILE-OTHER TRUFFLEHUNTER TALOS-2020-1151 attack attempt (more info ...)attempted-user 2020-13541   URL
55642FILE-OTHER TRUFFLEHUNTER TALOS-2020-1151 attack attempt (more info ...)attempted-user 2020-13541   URL
55643FILE-OTHER TRUFFLEHUNTER TALOS-2020-1151 attack attempt (more info ...)attempted-user 2020-13541   URL
55644FILE-OTHER TRUFFLEHUNTER TALOS-2020-1151 attack attempt (more info ...)attempted-user 2020-13541   URL
55645FILE-OTHER TRUFFLEHUNTER TALOS-2020-1151 attack attempt (more info ...)attempted-user 2020-13541   URL
55646FILE-OTHER TRUFFLEHUNTER TALOS-2020-1151 attack attempt (more info ...)attempted-user 2020-13541   URL
55649MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (more info ...)trojan-activity    URL
55650MALWARE-OTHER Win.Packed.Reveton-9759981-0 download attempt (more info ...)trojan-activity    URL
55651MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (more info ...)trojan-activity    URL
55652MALWARE-OTHER Win.Packed.Zeroaccess-9760099-0 download attempt (more info ...)trojan-activity    URL
55653MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (more info ...)trojan-activity    URL
55654MALWARE-OTHER Win.Packed.Zeroaccess-9760103-0 download attempt (more info ...)trojan-activity    URL
55657MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (more info ...)trojan-activity    URL
55658MALWARE-OTHER Win.Packed.Zbot-9760150-0 download attempt (more info ...)trojan-activity    URL
55659MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (more info ...)trojan-activity    URL
55660MALWARE-OTHER Win.Downloader.Karagany-9760168-0 download attempt (more info ...)trojan-activity    URL
55661MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (more info ...)trojan-activity    URL
55662MALWARE-OTHER Win.Trojan.Zeroaccess-9760197-0 download attempt (more info ...)trojan-activity    URL
55663MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (more info ...)trojan-activity    URL
55664MALWARE-OTHER PUA.Win.File.Neobar-9760284-0 download attempt (more info ...)trojan-activity    URL
55665MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (more info ...)trojan-activity    URL
55666MALWARE-OTHER Win.Trojan.Pcclient-9760332-0 download attempt (more info ...)trojan-activity    URL
55667MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (more info ...)trojan-activity    URL
55668MALWARE-OTHER Win.Malware.Farfli-9760391-0 download attempt (more info ...)trojan-activity    URL
55669MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (more info ...)trojan-activity    URL
55670MALWARE-OTHER Win.Trojan.Zbot-9760447-0 download attempt (more info ...)trojan-activity    URL
55673MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (more info ...)trojan-activity    URL
55674MALWARE-OTHER Win.Dropper.Urausy-9760560-0 download attempt (more info ...)trojan-activity    URL
55675MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (more info ...)trojan-activity    URL
55676MALWARE-OTHER Win.Malware.Dalexis-9760553-0 download attempt (more info ...)trojan-activity    URL
55677MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (more info ...)trojan-activity    URL
55678MALWARE-OTHER Win.Packed.Urausy-9760556-0 download attempt (more info ...)trojan-activity    URL
55679MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (more info ...)trojan-activity    URL
55680MALWARE-OTHER Win.Trojan.Zbot-9760594-0 download attempt (more info ...)trojan-activity    URL
55681MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (more info ...)trojan-activity    URL
55682MALWARE-OTHER Win.Trojan.Farfli-9760677-0 download attempt (more info ...)trojan-activity    URL
55685MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (more info ...)trojan-activity    URL
55686MALWARE-OTHER Win.Trojan.Slenfbot-9760649-0 download attempt (more info ...)trojan-activity    URL
55687MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (more info ...)trojan-activity    URL
55688MALWARE-OTHER Win.Trojan.Elzob-9760696-0 download attempt (more info ...)trojan-activity    URL
55689MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (more info ...)trojan-activity    URL
55690MALWARE-OTHER Win.Trojan.Pakes-9760698-0 download attempt (more info ...)trojan-activity    URL
55691MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (more info ...)trojan-activity    URL
55692MALWARE-OTHER Win.Packed.Zbot-9760798-0 download attempt (more info ...)trojan-activity    URL
55693MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (more info ...)trojan-activity    URL
55694MALWARE-OTHER Win.Malware.Magania-9760939-0 download attempt (more info ...)trojan-activity    URL
55697MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (more info ...)trojan-activity    URL
55698MALWARE-OTHER Win.Packed.Zeroaccess-9761006-0 download attempt (more info ...)trojan-activity    URL
55699MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (more info ...)trojan-activity    URL
55700MALWARE-OTHER Win.Dropper.Urausy-9761062-0 download attempt (more info ...)trojan-activity    URL
55701MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (more info ...)trojan-activity    URL
55702MALWARE-OTHER Win.Dropper.Urausy-9761063-0 download attempt (more info ...)trojan-activity    URL
55705MALWARE-OTHER Win.Packed.Cryptowall-9761312-0 download attempt (more info ...)trojan-activity    URL
55706MALWARE-OTHER Win.Packed.Cryptowall-9761312-0 download attempt (more info ...)trojan-activity    URL
55707MALWARE-OTHER Win.Packed.Urausy-9761337-0 download attempt (more info ...)trojan-activity    URL
55708MALWARE-OTHER Win.Packed.Urausy-9761337-0 download attempt (more info ...)trojan-activity    URL
55727MALWARE-OTHER Win.Malware.Magania-9761427-0 download attempt (more info ...)trojan-activity    URL
55728MALWARE-OTHER Win.Malware.Magania-9761427-0 download attempt (more info ...)trojan-activity    URL
55731MALWARE-OTHER Win.Trojan.Generickdz-9761624-0 download attempt (more info ...)trojan-activity    URL
55732MALWARE-OTHER Win.Trojan.Generickdz-9761624-0 download attempt (more info ...)trojan-activity    URL
55733MALWARE-OTHER Win.Packed.Zeroaccess-9761753-0 download attempt (more info ...)trojan-activity    URL
55734MALWARE-OTHER Win.Packed.Zeroaccess-9761753-0 download attempt (more info ...)trojan-activity    URL
55735MALWARE-OTHER Win.Packed.Zeroaccess-9762029-0 download attempt (more info ...)trojan-activity    URL
55736MALWARE-OTHER Win.Packed.Zeroaccess-9762029-0 download attempt (more info ...)trojan-activity    URL
55737MALWARE-OTHER Win.Trojan.Ircbot-9762035-0 download attempt (more info ...)trojan-activity    URL
55738MALWARE-OTHER Win.Trojan.Ircbot-9762035-0 download attempt (more info ...)trojan-activity    URL
55739MALWARE-OTHER Win.Keylogger.Zeroaccess-9762049-0 download attempt (more info ...)trojan-activity    URL
55740MALWARE-OTHER Win.Keylogger.Zeroaccess-9762049-0 download attempt (more info ...)trojan-activity    URL
55744MALWARE-OTHER PUA.Win.Adware.Eorezo-9762085-0 download attempt (more info ...)trojan-activity    URL
55745MALWARE-OTHER PUA.Win.Adware.Eorezo-9762085-0 download attempt (more info ...)trojan-activity    URL
55746MALWARE-OTHER Win.Malware.Trojanx-9762074-0 download attempt (more info ...)trojan-activity    URL
55747MALWARE-OTHER Win.Malware.Trojanx-9762074-0 download attempt (more info ...)trojan-activity    URL
55750MALWARE-OTHER Win.Packed.Zeroaccess-9762111-0 download attempt (more info ...)trojan-activity    URL
55751MALWARE-OTHER Win.Packed.Zeroaccess-9762111-0 download attempt (more info ...)trojan-activity    URL
55752MALWARE-OTHER Win.Dropper.Urausy-9762145-0 download attempt (more info ...)trojan-activity    URL
55753MALWARE-OTHER Win.Dropper.Urausy-9762145-0 download attempt (more info ...)trojan-activity    URL
55756MALWARE-OTHER Win.Malware.Magania-9762150-0 download attempt (more info ...)trojan-activity    URL
55757MALWARE-OTHER Win.Malware.Magania-9762150-0 download attempt (more info ...)trojan-activity    URL
55760MALWARE-OTHER Win.Packed.Fareit-9762193-0 download attempt (more info ...)trojan-activity    URL
55761MALWARE-OTHER Win.Packed.Fareit-9762193-0 download attempt (more info ...)trojan-activity    URL
55764MALWARE-OTHER Win.Ransomware.Generickdz-9762176-0 download attempt (more info ...)trojan-activity    URL
55765MALWARE-OTHER Win.Ransomware.Generickdz-9762176-0 download attempt (more info ...)trojan-activity    URL
55766MALWARE-OTHER Win.Packed.Zeroaccess-9762177-0 download attempt (more info ...)trojan-activity    URL
55767MALWARE-OTHER Win.Packed.Zeroaccess-9762177-0 download attempt (more info ...)trojan-activity    URL
55768MALWARE-OTHER Win.Malware.Magania-9762179-0 download attempt (more info ...)trojan-activity    URL
55769MALWARE-OTHER Win.Malware.Magania-9762179-0 download attempt (more info ...)trojan-activity    URL
55772MALWARE-OTHER Win.Trojan.Zeroaccess-9762336-0 download attempt (more info ...)trojan-activity    URL
55773MALWARE-OTHER Win.Trojan.Zeroaccess-9762336-0 download attempt (more info ...)trojan-activity    URL
55774MALWARE-OTHER Win.Keylogger.Ardamax-9762361-0 download attempt (more info ...)trojan-activity    URL
55775MALWARE-OTHER Win.Keylogger.Ardamax-9762361-0 download attempt (more info ...)trojan-activity    URL
55776MALWARE-OTHER Win.Trojan.Variadic-9762514-0 download attempt (more info ...)trojan-activity    URL
55777MALWARE-OTHER Win.Trojan.Variadic-9762514-0 download attempt (more info ...)trojan-activity    URL
55781MALWARE-OTHER Win.Keylogger.Emotet-9762950-0 download attempt (more info ...)trojan-activity    URL
55782MALWARE-OTHER Win.Keylogger.Emotet-9762950-0 download attempt (more info ...)trojan-activity    URL
55783MALWARE-OTHER PUA.Win.File.Avira-9762997-0 download attempt (more info ...)trojan-activity    URL
55784MALWARE-OTHER PUA.Win.File.Avira-9762997-0 download attempt (more info ...)trojan-activity    URL
55785MALWARE-OTHER Win.Malware.Zusy-9763167-0 download attempt (more info ...)trojan-activity    URL
55786MALWARE-OTHER Win.Malware.Zusy-9763167-0 download attempt (more info ...)trojan-activity    URL
55787MALWARE-OTHER Win.Packed.Emotet-9763169-0 download attempt (more info ...)trojan-activity    URL
55788MALWARE-OTHER Win.Packed.Emotet-9763169-0 download attempt (more info ...)trojan-activity    URL
55791MALWARE-OTHER Win.Trojan.Farfli-9763835-0 download attempt (more info ...)trojan-activity    URL
55792MALWARE-OTHER Win.Trojan.Farfli-9763835-0 download attempt (more info ...)trojan-activity    URL
55813SERVER-OTHER Symantec Endpoint Protection tamper protection bypass attempt (more info ...)attempted-user 2017-6331   
55814SERVER-OTHER Symantec Endpoint Protection tamper protection bypass attempt (more info ...)attempted-user 2017-6331   
55821SERVER-WEBAPP Ruby on Rails command injection attempt (more info ...)web-application-attack 2020-8163   URL
55841MALWARE-CNC Win.Trojan.Uppercut inbound payload download (more info ...)trojan-activity    URL
55846MALWARE-OTHER Win.Malware.Delf-9768673-0 download attempt (more info ...)trojan-activity    URL
55847MALWARE-OTHER Win.Malware.Delf-9768673-0 download attempt (more info ...)trojan-activity    URL
55848MALWARE-OTHER Win.Malware.Delf-9768956-0 download attempt (more info ...)trojan-activity    URL
55849MALWARE-OTHER Win.Malware.Delf-9768956-0 download attempt (more info ...)trojan-activity    URL
55850MALWARE-OTHER Win.Malware.Auqyqcbi-9769106-0 download attempt (more info ...)trojan-activity    URL
55851MALWARE-OTHER Win.Malware.Auqyqcbi-9769106-0 download attempt (more info ...)trojan-activity    URL
55856MALWARE-OTHER Win.Packed.Ulise-9769434-0 download attempt (more info ...)trojan-activity    URL
55857MALWARE-OTHER Win.Packed.Ulise-9769434-0 download attempt (more info ...)trojan-activity    URL
55858MALWARE-OTHER Win.Malware.Agen-9769447-0 download attempt (more info ...)trojan-activity    URL
55859MALWARE-OTHER Win.Malware.Agen-9769447-0 download attempt (more info ...)trojan-activity    URL
55865MALWARE-OTHER Win.Packed.Bulz-9769773-0 download attempt (more info ...)trojan-activity    URL
55866MALWARE-OTHER Win.Packed.Bulz-9769773-0 download attempt (more info ...)trojan-activity    URL
55869MALWARE-OTHER Win.Keylogger.Emotet-9769987-0 download attempt (more info ...)trojan-activity    URL
55870MALWARE-OTHER Win.Keylogger.Emotet-9769987-0 download attempt (more info ...)trojan-activity    URL
55871MALWARE-OTHER Win.Malware.Zusy-9770089-0 download attempt (more info ...)trojan-activity    URL
55872MALWARE-OTHER Win.Malware.Zusy-9770089-0 download attempt (more info ...)trojan-activity    URL
55873MALWARE-OTHER Win.Keylogger.Emotet-9770097-0 download attempt (more info ...)trojan-activity    URL
55874MALWARE-OTHER Win.Keylogger.Emotet-9770097-0 download attempt (more info ...)trojan-activity    URL
55877MALWARE-OTHER Win.Worm.Drolnux-9770173-0 download attempt (more info ...)trojan-activity    URL
55878MALWARE-OTHER Win.Worm.Drolnux-9770173-0 download attempt (more info ...)trojan-activity    URL
55879MALWARE-OTHER Win.Packed.Zbot-9770611-0 download attempt (more info ...)trojan-activity    URL
55880MALWARE-OTHER Win.Packed.Zbot-9770611-0 download attempt (more info ...)trojan-activity    URL
55881MALWARE-OTHER Win.Ransomware.Cerber-9770992-0 download attempt (more info ...)trojan-activity    URL
55882MALWARE-OTHER Win.Ransomware.Cerber-9770992-0 download attempt (more info ...)trojan-activity    URL
55883MALWARE-OTHER Win.Packed.Cutwail-9771166-0 download attempt (more info ...)trojan-activity    URL
55884MALWARE-OTHER Win.Packed.Cutwail-9771166-0 download attempt (more info ...)trojan-activity    URL
55885MALWARE-OTHER Win.Downloader.Upatre-9771263-0 download attempt (more info ...)trojan-activity    URL
55886MALWARE-OTHER Win.Downloader.Upatre-9771263-0 download attempt (more info ...)trojan-activity    URL
55887MALWARE-OTHER Win.Ransomware.Reveton-9771413-0 download attempt (more info ...)trojan-activity    URL
55888MALWARE-OTHER Win.Ransomware.Reveton-9771413-0 download attempt (more info ...)trojan-activity    URL
55891MALWARE-OTHER Win.Malware.Kovter-9771867-0 download attempt (more info ...)trojan-activity    URL
55892MALWARE-OTHER Win.Malware.Kovter-9771867-0 download attempt (more info ...)trojan-activity    URL
55895MALWARE-OTHER Win.Worm.Vobfus-9772275-0 download attempt (more info ...)trojan-activity    URL
55896MALWARE-OTHER Win.Worm.Vobfus-9772275-0 download attempt (more info ...)trojan-activity    URL
55897MALWARE-OTHER Win.Trojan.Fakesysdef-9772554-0 download attempt (more info ...)trojan-activity    URL
55898MALWARE-OTHER Win.Trojan.Fakesysdef-9772554-0 download attempt (more info ...)trojan-activity    URL
55899MALWARE-OTHER Win.Packed.Razy-9772677-0 download attempt (more info ...)trojan-activity    URL
55900MALWARE-OTHER Win.Packed.Razy-9772677-0 download attempt (more info ...)trojan-activity    URL
55901MALWARE-OTHER Win.Packed.Zbot-9772681-0 download attempt (more info ...)trojan-activity    URL
55902MALWARE-OTHER Win.Packed.Zbot-9772681-0 download attempt (more info ...)trojan-activity    URL
55903MALWARE-OTHER Win.Malware.Sdyn-9772921-0 download attempt (more info ...)trojan-activity    URL
55904MALWARE-OTHER Win.Malware.Sdyn-9772921-0 download attempt (more info ...)trojan-activity    URL
55905MALWARE-OTHER Win.Trojan.Generic-9773106-0 download attempt (more info ...)trojan-activity    URL
55906MALWARE-OTHER Win.Trojan.Generic-9773106-0 download attempt (more info ...)trojan-activity    URL
55907MALWARE-OTHER Win.Packed.Zbot-9773294-0 download attempt (more info ...)trojan-activity    URL
55908MALWARE-OTHER Win.Packed.Zbot-9773294-0 download attempt (more info ...)trojan-activity    URL
55909MALWARE-OTHER Win.Malware.Battdil-9773289-0 download attempt (more info ...)trojan-activity    URL
55910MALWARE-OTHER Win.Malware.Battdil-9773289-0 download attempt (more info ...)trojan-activity    URL
55911MALWARE-OTHER Win.Malware.Battdil-9773282-0 download attempt (more info ...)trojan-activity    URL
55912MALWARE-OTHER Win.Malware.Battdil-9773282-0 download attempt (more info ...)trojan-activity    URL
55913MALWARE-OTHER Win.Packed.Ramnit-9773470-0 download attempt (more info ...)trojan-activity    URL
55914MALWARE-OTHER Win.Packed.Ramnit-9773470-0 download attempt (more info ...)trojan-activity    URL
55915MALWARE-OTHER PUA.Win.File.Neobar-9773833-0 download attempt (more info ...)trojan-activity    URL
55916MALWARE-OTHER PUA.Win.File.Neobar-9773833-0 download attempt (more info ...)trojan-activity    URL
55926MALWARE-CNC Win.Dropper.LemonDuck variant outbound connection (more info ...)trojan-activity    URL
55927MALWARE-CNC Win.Dropper.LemonDuck variant script download attempt (more info ...)trojan-activity    URL
55928MALWARE-CNC Win.Dropper.LemonDuck variant script download attempt (more info ...)trojan-activity    URL
55929MALWARE-OTHER Win.Keylogger.Emotet-9774504-0 download attempt (more info ...)trojan-activity    URL
55930MALWARE-OTHER Win.Keylogger.Emotet-9774504-0 download attempt (more info ...)trojan-activity    URL
55931MALWARE-CNC Win.Trojan.Emotet variant outbound connection attempt (more info ...)trojan-activity    URL
55934MALWARE-OTHER Win.Malware.Ulise-9774716-0 download attempt (more info ...)trojan-activity    URL
55935MALWARE-OTHER Win.Malware.Ulise-9774716-0 download attempt (more info ...)trojan-activity    URL
55938MALWARE-OTHER Win.Tool.Shadowbrokers-9775051-0 download attempt (more info ...)trojan-activity    URL
55939MALWARE-OTHER Win.Tool.Shadowbrokers-9775051-0 download attempt (more info ...)trojan-activity    URL
55940MALWARE-OTHER Win.Malware.Upatre-9775385-0 download attempt (more info ...)trojan-activity    URL
55941MALWARE-OTHER Win.Malware.Upatre-9775385-0 download attempt (more info ...)trojan-activity    URL
55944MALWARE-OTHER Win.Malware.Buzus-9775511-0 download attempt (more info ...)trojan-activity    URL
55945MALWARE-OTHER Win.Malware.Buzus-9775511-0 download attempt (more info ...)trojan-activity    URL
55948MALWARE-OTHER Win.Trojan.Ramnit-9775593-0 download attempt (more info ...)trojan-activity    URL
55949MALWARE-OTHER Win.Trojan.Ramnit-9775593-0 download attempt (more info ...)trojan-activity    URL
55952MALWARE-OTHER Win.Trojan.Generic-9775770-0 download attempt (more info ...)trojan-activity    URL
55953MALWARE-OTHER Win.Trojan.Generic-9775770-0 download attempt (more info ...)trojan-activity    URL
55954MALWARE-OTHER Win.Malware.Zusy-9776100-0 download attempt (more info ...)trojan-activity    URL
55955MALWARE-OTHER Win.Malware.Zusy-9776100-0 download attempt (more info ...)trojan-activity    URL
55956MALWARE-OTHER PUA.Win.Adware.Addlyrics-9776340-0 download attempt (more info ...)trojan-activity    URL
55957MALWARE-OTHER PUA.Win.Adware.Addlyrics-9776340-0 download attempt (more info ...)trojan-activity    URL
55958MALWARE-OTHER Win.Malware.Scar-9776391-0 download attempt (more info ...)trojan-activity    URL
55959MALWARE-OTHER Win.Malware.Scar-9776391-0 download attempt (more info ...)trojan-activity    URL
55960MALWARE-OTHER Win.Ransomware.Zbot-9776404-0 download attempt (more info ...)trojan-activity    URL
55961MALWARE-OTHER Win.Ransomware.Zbot-9776404-0 download attempt (more info ...)trojan-activity    URL
55962MALWARE-OTHER Win.Ransomware.Upatre-9776436-0 download attempt (more info ...)trojan-activity    URL
55963MALWARE-OTHER Win.Ransomware.Upatre-9776436-0 download attempt (more info ...)trojan-activity    URL
55964MALWARE-OTHER Win.Malware.Upatre-9776419-0 download attempt (more info ...)trojan-activity    URL
55965MALWARE-OTHER Win.Malware.Upatre-9776419-0 download attempt (more info ...)trojan-activity    URL
55966MALWARE-OTHER PUA.Win.Adware.Addlyrics-9776406-0 download attempt (more info ...)trojan-activity    URL
55967MALWARE-OTHER PUA.Win.Adware.Addlyrics-9776406-0 download attempt (more info ...)trojan-activity    URL
55968MALWARE-OTHER Win.Malware.Upatre-9776422-0 download attempt (more info ...)trojan-activity    URL
55969MALWARE-OTHER Win.Malware.Upatre-9776422-0 download attempt (more info ...)trojan-activity    URL
55970MALWARE-OTHER Win.Ransomware.Upatre-9776543-0 download attempt (more info ...)trojan-activity    URL
55971MALWARE-OTHER Win.Ransomware.Upatre-9776543-0 download attempt (more info ...)trojan-activity    URL
55972MALWARE-OTHER Win.Trojan.Gamarue-9776559-0 download attempt (more info ...)trojan-activity    URL
55973MALWARE-OTHER Win.Trojan.Gamarue-9776559-0 download attempt (more info ...)trojan-activity    URL
55976MALWARE-OTHER Win.Downloader.Upatre-9776833-0 download attempt (more info ...)trojan-activity    URL
55977MALWARE-OTHER Win.Downloader.Upatre-9776833-0 download attempt (more info ...)trojan-activity    URL
55995MALWARE-OTHER PUA.Win.Adware.Dotdo-9777352-0 download attempt (more info ...)trojan-activity    URL
55996MALWARE-OTHER PUA.Win.Adware.Dotdo-9777352-0 download attempt (more info ...)trojan-activity    URL
55997MALWARE-OTHER Win.Worm.Beebone-9777703-0 download attempt (more info ...)trojan-activity    URL
55998MALWARE-OTHER Win.Worm.Beebone-9777703-0 download attempt (more info ...)trojan-activity    URL
56003MALWARE-CNC Win.Trojan.Emotet variant initial outbound request detected (more info ...)trojan-activity    URL
56004SERVER-WEBAPP D-Link Central WiFi Manager CMW 100 cross site scripting attempt (more info ...)attempted-user 2019-13374   URL
56010MALWARE-OTHER Win.Trojan.Generic-9778253-0 download attempt (more info ...)trojan-activity    URL
56011MALWARE-OTHER Win.Trojan.Generic-9778253-0 download attempt (more info ...)trojan-activity    URL
56014MALWARE-OTHER Win.Packed.Vundo-9779004-0 download attempt (more info ...)trojan-activity    URL
56015MALWARE-OTHER Win.Packed.Vundo-9779004-0 download attempt (more info ...)trojan-activity    URL
56016MALWARE-OTHER Win.Packed.Vundo-9779009-0 download attempt (more info ...)trojan-activity    URL
56017MALWARE-OTHER Win.Packed.Vundo-9779009-0 download attempt (more info ...)trojan-activity    URL
56022MALWARE-OTHER Win.Packed.Razy-9779199-0 download attempt (more info ...)trojan-activity    URL
56023MALWARE-OTHER Win.Packed.Razy-9779199-0 download attempt (more info ...)trojan-activity    URL
56024MALWARE-OTHER Win.Ransomware.Cerber-9779208-0 download attempt (more info ...)trojan-activity    URL
56025MALWARE-OTHER Win.Ransomware.Cerber-9779208-0 download attempt (more info ...)trojan-activity    URL
56026MALWARE-OTHER Win.Malware.Cdtq-9779262-0 download attempt (more info ...)trojan-activity    URL
56027MALWARE-OTHER Win.Malware.Cdtq-9779262-0 download attempt (more info ...)trojan-activity    URL
56030MALWARE-OTHER Win.Ransomware.Cerber-9779257-0 download attempt (more info ...)trojan-activity    URL
56031MALWARE-OTHER Win.Ransomware.Cerber-9779257-0 download attempt (more info ...)trojan-activity    URL
56032MALWARE-OTHER Win.Malware.98fa8f-9779729-0 download attempt (more info ...)trojan-activity    URL
56033MALWARE-OTHER Win.Malware.98fa8f-9779729-0 download attempt (more info ...)trojan-activity    URL
56034MALWARE-OTHER Win.Packed.Upatre-9779721-0 download attempt (more info ...)trojan-activity    URL
56035MALWARE-OTHER Win.Packed.Upatre-9779721-0 download attempt (more info ...)trojan-activity    URL
56038MALWARE-OTHER Win.Packed.Upatre-9779742-0 download attempt (more info ...)trojan-activity    URL
56039MALWARE-OTHER Win.Packed.Upatre-9779742-0 download attempt (more info ...)trojan-activity    URL
56040MALWARE-OTHER Win.Packed.Msilperseus-9780360-0 download attempt (more info ...)trojan-activity    URL
56041MALWARE-OTHER Win.Packed.Msilperseus-9780360-0 download attempt (more info ...)trojan-activity    URL
56046MALWARE-OTHER Win.Dropper.Emotet-9778600-0 download attempt (more info ...)trojan-activity    URL
56047MALWARE-OTHER Win.Dropper.Emotet-9778600-0 download attempt (more info ...)trojan-activity    URL
56055MALWARE-OTHER Win.Malware.Idyfrid-9780483-0 download attempt (more info ...)trojan-activity    URL
56056MALWARE-OTHER Win.Malware.Idyfrid-9780483-0 download attempt (more info ...)trojan-activity    URL
56057MALWARE-OTHER Win.Malware.Estiwir-9780493-0 download attempt (more info ...)trojan-activity    URL
56058MALWARE-OTHER Win.Malware.Estiwir-9780493-0 download attempt (more info ...)trojan-activity    URL
56061MALWARE-OTHER Win.Packed.Tpyn-9780502-0 download attempt (more info ...)trojan-activity    URL
56062MALWARE-OTHER Win.Packed.Tpyn-9780502-0 download attempt (more info ...)trojan-activity    URL
56067MALWARE-OTHER Win.Malware.Upatre-9780514-0 download attempt (more info ...)trojan-activity    URL
56068MALWARE-OTHER Win.Malware.Upatre-9780514-0 download attempt (more info ...)trojan-activity    URL
56073MALWARE-OTHER Win.Malware.Agentb-9780545-0 download attempt (more info ...)trojan-activity    URL
56074MALWARE-OTHER Win.Malware.Agentb-9780545-0 download attempt (more info ...)trojan-activity    URL
56075MALWARE-OTHER Win.Malware.Upatre-9780601-0 download attempt (more info ...)trojan-activity    URL
56076MALWARE-OTHER Win.Malware.Upatre-9780601-0 download attempt (more info ...)trojan-activity    URL
56077MALWARE-OTHER Win.Malware.Upatre-9780656-0 download attempt (more info ...)trojan-activity    URL
56078MALWARE-OTHER Win.Malware.Upatre-9780656-0 download attempt (more info ...)trojan-activity    URL
56079MALWARE-OTHER Win.Malware.Upatre-9780659-0 download attempt (more info ...)trojan-activity    URL
56080MALWARE-OTHER Win.Malware.Upatre-9780659-0 download attempt (more info ...)trojan-activity    URL
56081MALWARE-CNC Andr.Trojan.Donot variant outbound connection (more info ...)trojan-activity    URL
56094MALWARE-OTHER Win.Malware.Alyak-9781952-0 download attempt (more info ...)trojan-activity    URL
56095MALWARE-OTHER Win.Malware.Alyak-9781952-0 download attempt (more info ...)trojan-activity    URL
56098MALWARE-OTHER Win.Tool.Patcher-9782697-0 download attempt (more info ...)trojan-activity    URL
56099MALWARE-OTHER Win.Tool.Patcher-9782697-0 download attempt (more info ...)trojan-activity    URL
56100MALWARE-OTHER Win.Malware.Ulise-9782745-0 download attempt (more info ...)trojan-activity    URL
56101MALWARE-OTHER Win.Malware.Ulise-9782745-0 download attempt (more info ...)trojan-activity    URL
56102MALWARE-OTHER Win.Malware.Upatre-9782798-0 download attempt (more info ...)trojan-activity    URL
56103MALWARE-OTHER Win.Malware.Upatre-9782798-0 download attempt (more info ...)trojan-activity    URL
56104MALWARE-OTHER Win.Malware.Xkjdi-9782808-0 download attempt (more info ...)trojan-activity    URL
56105MALWARE-OTHER Win.Malware.Xkjdi-9782808-0 download attempt (more info ...)trojan-activity    URL
56106MALWARE-OTHER Win.Packed.Clipbanker-9782972-0 download attempt (more info ...)trojan-activity    URL
56107MALWARE-OTHER Win.Packed.Clipbanker-9782972-0 download attempt (more info ...)trojan-activity    URL
56108MALWARE-OTHER Win.Trojan.Redyms-9783100-0 download attempt (more info ...)trojan-activity    URL
56109MALWARE-OTHER Win.Trojan.Redyms-9783100-0 download attempt (more info ...)trojan-activity    URL
56110MALWARE-OTHER Win.Malware.Reconyc-9783104-0 download attempt (more info ...)trojan-activity    URL
56111MALWARE-OTHER Win.Malware.Reconyc-9783104-0 download attempt (more info ...)trojan-activity    URL
56112MALWARE-OTHER Win.Packed.Razy-9783140-0 download attempt (more info ...)trojan-activity    URL
56113MALWARE-OTHER Win.Packed.Razy-9783140-0 download attempt (more info ...)trojan-activity    URL
56116MALWARE-OTHER Win.Malware.Nitol-9783298-0 download attempt (more info ...)trojan-activity    URL
56117MALWARE-OTHER Win.Malware.Nitol-9783298-0 download attempt (more info ...)trojan-activity    URL
56118MALWARE-OTHER Win.Downloader.Cosmu-9783404-0 download attempt (more info ...)trojan-activity    URL
56119MALWARE-OTHER Win.Downloader.Cosmu-9783404-0 download attempt (more info ...)trojan-activity    URL
56120MALWARE-OTHER Win.Malware.Upatre-9783664-0 download attempt (more info ...)trojan-activity    URL
56121MALWARE-OTHER Win.Malware.Upatre-9783664-0 download attempt (more info ...)trojan-activity    URL
56124MALWARE-OTHER Win.Ransomware.Cerber-9783912-0 download attempt (more info ...)trojan-activity    URL
56125MALWARE-OTHER Win.Ransomware.Cerber-9783912-0 download attempt (more info ...)trojan-activity    URL
56128PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1174 attack attempt (more info ...)attempted-dos 2020-13559   URL
56129PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2020-1174 attack attempt (more info ...)attempted-dos 2020-13559   URL
56137POLICY-OTHER TRUFFLEHUNTER TALOS-2020-1173 attack attempt (more info ...)attempted-recon    URL
56139MALWARE-OTHER Win.Malware.Czxz-9784395-0 download attempt (more info ...)trojan-activity    URL
56140MALWARE-OTHER Win.Malware.Czxz-9784395-0 download attempt (more info ...)trojan-activity    URL
56141MALWARE-OTHER Win.Ransomware.Zusy-9784403-0 download attempt (more info ...)trojan-activity    URL
56142MALWARE-OTHER Win.Ransomware.Zusy-9784403-0 download attempt (more info ...)trojan-activity    URL
56168MALWARE-OTHER PUA.Win.Adware.Komodia-9784770-0 download attempt (more info ...)trojan-activity    URL
56169MALWARE-OTHER PUA.Win.Adware.Komodia-9784770-0 download attempt (more info ...)trojan-activity    URL
56170MALWARE-OTHER Win.Malware.Emotet-9784823-0 download attempt (more info ...)trojan-activity    URL
56171MALWARE-OTHER Win.Malware.Emotet-9784823-0 download attempt (more info ...)trojan-activity    URL
56172MALWARE-OTHER Win.Malware.Komodia-9784896-0 download attempt (more info ...)trojan-activity    URL
56173MALWARE-OTHER Win.Malware.Komodia-9784896-0 download attempt (more info ...)trojan-activity    URL
56174MALWARE-OTHER PUA.Win.Adware.Addlyrics-9784897-0 download attempt (more info ...)trojan-activity    URL
56175MALWARE-OTHER PUA.Win.Adware.Addlyrics-9784897-0 download attempt (more info ...)trojan-activity    URL
56176MALWARE-OTHER PUA.Win.Adware.Addlyrics-9784898-0 download attempt (more info ...)trojan-activity    URL
56177MALWARE-OTHER PUA.Win.Adware.Addlyrics-9784898-0 download attempt (more info ...)trojan-activity    URL
56180MALWARE-OTHER Win.Malware.Upatre-9784989-0 download attempt (more info ...)trojan-activity    URL
56181MALWARE-OTHER Win.Malware.Upatre-9784989-0 download attempt (more info ...)trojan-activity    URL
56182MALWARE-OTHER Win.Malware.Ursu-9785115-0 download attempt (more info ...)trojan-activity    URL
56183MALWARE-OTHER Win.Malware.Ursu-9785115-0 download attempt (more info ...)trojan-activity    URL
56184MALWARE-OTHER Win.Packed.Banload-9785270-0 download attempt (more info ...)trojan-activity    URL
56185MALWARE-OTHER Win.Packed.Banload-9785270-0 download attempt (more info ...)trojan-activity    URL
56186FILE-OTHER Citrix Gateway executable search order hijack attempt (more info ...)attempted-admin 2020-8258   URL
56187FILE-OTHER Citrix Gateway executable search order hijack attempt (more info ...)attempted-admin 2020-8258   URL
56188FILE-OTHER Citrix Gateway executable search order hijack attempt (more info ...)attempted-admin 2020-8258   URL
56189MALWARE-OTHER Win.Malware.Upatre-9785657-0 download attempt (more info ...)trojan-activity    URL
56190MALWARE-OTHER Win.Malware.Upatre-9785657-0 download attempt (more info ...)trojan-activity    URL
56193MALWARE-OTHER Win.Malware.Upatre-9785801-0 download attempt (more info ...)trojan-activity    URL
56194MALWARE-OTHER Win.Malware.Upatre-9785801-0 download attempt (more info ...)trojan-activity    URL
56195MALWARE-OTHER Win.Malware.Ursu-9785971-0 download attempt (more info ...)trojan-activity    URL
56196MALWARE-OTHER Win.Malware.Ursu-9785971-0 download attempt (more info ...)trojan-activity    URL
56197MALWARE-OTHER Win.Malware.Qbot-9785980-0 download attempt (more info ...)trojan-activity    URL
56198MALWARE-OTHER Win.Malware.Qbot-9785980-0 download attempt (more info ...)trojan-activity    URL
56199SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1193 attack attempt (more info ...)attempted-dos 2020-13582   URL
56204MALWARE-CNC Doc.Dropper.Kimsuky variant outbound connection (more info ...)trojan-activity    URL
56205MALWARE-CNC Win.Trojan.Kimsuky variant outbound connection (more info ...)trojan-activity    URL
56206MALWARE-CNC Doc.Dropper.Kimsuky variant outbound connection (more info ...)trojan-activity    URL
56207MALWARE-CNC Doc.Dropper.Kimsuky variant outbound connection (more info ...)trojan-activity    URL
56214MALWARE-OTHER Win.Malware.Zusy-9786645-0 download attempt (more info ...)trojan-activity    URL
56215MALWARE-OTHER Win.Malware.Zusy-9786645-0 download attempt (more info ...)trojan-activity    URL
56232MALWARE-OTHER Win.Worm.Scar-9787415-0 download attempt (more info ...)trojan-activity    URL
56233MALWARE-OTHER Win.Worm.Scar-9787415-0 download attempt (more info ...)trojan-activity    URL
56234MALWARE-OTHER Win.Worm.Scar-9787423-0 download attempt (more info ...)trojan-activity    URL
56235MALWARE-OTHER Win.Worm.Scar-9787423-0 download attempt (more info ...)trojan-activity    URL
56236MALWARE-OTHER Win.Dropper.Nitol-9787439-0 download attempt (more info ...)trojan-activity    URL
56237MALWARE-OTHER Win.Dropper.Nitol-9787439-0 download attempt (more info ...)trojan-activity    URL
56238MALWARE-OTHER Win.Dropper.Kuluoz-9787440-0 download attempt (more info ...)trojan-activity    URL
56239MALWARE-OTHER Win.Dropper.Kuluoz-9787440-0 download attempt (more info ...)trojan-activity    URL
56240MALWARE-OTHER Win.Worm.Scar-9787525-0 download attempt (more info ...)trojan-activity    URL
56241MALWARE-OTHER Win.Worm.Scar-9787525-0 download attempt (more info ...)trojan-activity    URL
56242MALWARE-OTHER Win.Worm.Scar-9787528-0 download attempt (more info ...)trojan-activity    URL
56243MALWARE-OTHER Win.Worm.Scar-9787528-0 download attempt (more info ...)trojan-activity    URL
56244MALWARE-OTHER Win.Dropper.Nitol-9787572-0 download attempt (more info ...)trojan-activity    URL
56245MALWARE-OTHER Win.Dropper.Nitol-9787572-0 download attempt (more info ...)trojan-activity    URL
56246MALWARE-OTHER Win.Malware.Cerbu-9789017-0 download attempt (more info ...)trojan-activity    URL
56247MALWARE-OTHER Win.Malware.Cerbu-9789017-0 download attempt (more info ...)trojan-activity    URL
56250MALWARE-OTHER Win.Packed.Razy-9789215-0 download attempt (more info ...)trojan-activity    URL
56251MALWARE-OTHER Win.Packed.Razy-9789215-0 download attempt (more info ...)trojan-activity    URL
56252MALWARE-OTHER Win.Malware.Burda-9789442-0 download attempt (more info ...)trojan-activity    URL
56253MALWARE-OTHER Win.Malware.Burda-9789442-0 download attempt (more info ...)trojan-activity    URL
56276MALWARE-CNC Win.Trojan.Crat variant outbound connection (more info ...)trojan-activity    URL
56278MALWARE-OTHER Win.Trojan.Crat malicious document download (more info ...)trojan-activity    URL
56280MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity    URL
56282MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity    URL
56283MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity    URL
56291MALWARE-OTHER Win.Trojan.Crat malicious executable download attempt (more info ...)trojan-activity    URL
56292MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity    URL
56294MALWARE-CNC Win.Trojan.Zebrocy variant outbound connection (more info ...)trojan-activity    URL
56297SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1189 attack attempt (more info ...)attempted-dos 2020-13578   URL
56298SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1189 attack attempt (more info ...)attempted-dos 2020-13578   URL
56307SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1188 attack attempt (more info ...)attempted-dos 2020-13577   URL
56308SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1188 attack attempt (more info ...)attempted-dos 2020-13577   URL
56313MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity    URL
56314MALWARE-OTHER Win.Trojan.Crat malicious executable download (more info ...)trojan-activity    URL
56315MALWARE-OTHER Win.Malware.Ursu-9790943-0 download attempt (more info ...)trojan-activity    URL
56316MALWARE-OTHER Win.Malware.Ursu-9790943-0 download attempt (more info ...)trojan-activity    URL
56317MALWARE-OTHER PUA.Win.Adware.Amonetize-9791097-0 download attempt (more info ...)trojan-activity    URL
56318MALWARE-OTHER PUA.Win.Adware.Amonetize-9791097-0 download attempt (more info ...)trojan-activity    URL
56319MALWARE-OTHER Win.Packed.Yifgvsfb-9791273-0 download attempt (more info ...)trojan-activity    URL
56320MALWARE-OTHER Win.Packed.Yifgvsfb-9791273-0 download attempt (more info ...)trojan-activity    URL
56321POLICY-OTHER IBM Spectrum Protect Plus admin credentials reset attempt (more info ...)policy-violation 2020-4208   URL
56328MALWARE-OTHER Win.Malware.Zusy-9791863-0 download attempt (more info ...)trojan-activity    URL
56329MALWARE-OTHER Win.Malware.Zusy-9791863-0 download attempt (more info ...)trojan-activity    URL
56332MALWARE-OTHER Win.Trojan.Zbot-9792718-0 download attempt (more info ...)trojan-activity    URL
56333MALWARE-OTHER Win.Trojan.Zbot-9792718-0 download attempt (more info ...)trojan-activity    URL
56334MALWARE-OTHER PUA.Win.Adware.Ursu-9792860-0 download attempt (more info ...)trojan-activity    URL
56335MALWARE-OTHER PUA.Win.Adware.Ursu-9792860-0 download attempt (more info ...)trojan-activity    URL
56336MALWARE-OTHER PUA.Win.File.Zusy-9792896-0 download attempt (more info ...)trojan-activity    URL
56337MALWARE-OTHER PUA.Win.File.Zusy-9792896-0 download attempt (more info ...)trojan-activity    URL
56338MALWARE-OTHER PUA.Win.Adware.Dagava-9793006-0 download attempt (more info ...)trojan-activity    URL
56339MALWARE-OTHER PUA.Win.Adware.Dagava-9793006-0 download attempt (more info ...)trojan-activity    URL
56340MALWARE-OTHER Win.Malware.Daws-9793378-0 download attempt (more info ...)trojan-activity    URL
56341MALWARE-OTHER Win.Malware.Daws-9793378-0 download attempt (more info ...)trojan-activity    URL
56344MALWARE-OTHER Win.Malware.Magania-9793638-0 download attempt (more info ...)trojan-activity    URL
56345MALWARE-OTHER Win.Malware.Magania-9793638-0 download attempt (more info ...)trojan-activity    URL
56352MALWARE-OTHER Win.Malware.Magania-9793788-0 download attempt (more info ...)trojan-activity    URL
56353MALWARE-OTHER Win.Malware.Magania-9793788-0 download attempt (more info ...)trojan-activity    URL
56354MALWARE-OTHER Win.Malware.Magania-9793953-0 download attempt (more info ...)trojan-activity    URL
56355MALWARE-OTHER Win.Malware.Magania-9793953-0 download attempt (more info ...)trojan-activity    URL
56358MALWARE-OTHER Win.Trojan.Ulise-9794347-0 download attempt (more info ...)trojan-activity    URL
56359MALWARE-OTHER Win.Trojan.Ulise-9794347-0 download attempt (more info ...)trojan-activity    URL
56360MALWARE-OTHER PUA.Win.File.Playtech-9794342-0 download attempt (more info ...)trojan-activity    URL
56361MALWARE-OTHER PUA.Win.File.Playtech-9794342-0 download attempt (more info ...)trojan-activity    URL
56362MALWARE-OTHER Win.Ransomware.Cerber-9794403-0 download attempt (more info ...)trojan-activity    URL
56363MALWARE-OTHER Win.Ransomware.Cerber-9794403-0 download attempt (more info ...)trojan-activity    URL
56365FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1183 attack attempt (more info ...)attempted-user 2020-13572   URL
56366FILE-IMAGE TRUFFLEHUNTER TALOS-2020-1183 attack attempt (more info ...)attempted-user 2020-13572   URL
56367MALWARE-CNC Win.Trojan.GlitchPOS variant outbound connection attempt (more info ...)trojan-activity    URL
56368MALWARE-CNC Win.Trojan.GlitchPOS variant outbound connection attempt (more info ...)trojan-activity    URL
56371MALWARE-CNC Win.Trojan.ComRAT variant binary download attempt (more info ...)trojan-activity    URL
56372MALWARE-CNC Win.Trojan.ComRAT variant binary download attempt (more info ...)trojan-activity    URL
56373MALWARE-CNC Win.Trojan.ComRAT variant download attempt (more info ...)trojan-activity    URL
56376MALWARE-CNC Win.Trojan.ComRAT variant download attempt (more info ...)trojan-activity    URL
56377MALWARE-CNC Win.Trojan.ComRAT variant binary download attempt (more info ...)trojan-activity    URL
56378MALWARE-CNC Win.Trojan.ComRAT variant binary download attempt (more info ...)trojan-activity    URL
56383PROTOCOL-SCADA Advantech DiagAnywhere remote code execution attempt (more info ...)attempted-user 2019-18257   
56384PROTOCOL-SCADA Advantech DiagAnywhere remote code execution attempt (more info ...)attempted-user 2019-18257   
56385PROTOCOL-SCADA Advantech DiagAnywhere remote code execution attempt (more info ...)attempted-user 2019-18257   
56386PROTOCOL-SCADA Advantech DiagAnywhere remote code execution attempt (more info ...)attempted-user 2019-18257   
56387MALWARE-CNC Win.Trojan.Raccoon CNC decryption key response (more info ...)trojan-activity    
56388MALWARE-CNC Win.Trojan.Raccoon data exfiltration attempt (more info ...)trojan-activity    URL
56391MALWARE-CNC Win.Trojan.Racoon outbound connection attempt (more info ...)trojan-activity    URL
56392MALWARE-OTHER Win.Packed.Razy-9794567-0 download attempt (more info ...)trojan-activity    URL
56393MALWARE-OTHER Win.Packed.Razy-9794567-0 download attempt (more info ...)trojan-activity    URL
56398MALWARE-OTHER Win.Malware.Qbot-9794652-0 download attempt (more info ...)trojan-activity    URL
56399MALWARE-OTHER Win.Malware.Qbot-9794652-0 download attempt (more info ...)trojan-activity    URL
56400MALWARE-OTHER Win.Packed.Razy-9794901-0 download attempt (more info ...)trojan-activity    URL
56401MALWARE-OTHER Win.Packed.Razy-9794901-0 download attempt (more info ...)trojan-activity    URL
56402MALWARE-OTHER Win.Dropper.Kuluoz-9795078-0 download attempt (more info ...)trojan-activity    URL
56403MALWARE-OTHER Win.Dropper.Kuluoz-9795078-0 download attempt (more info ...)trojan-activity    URL
56425MALWARE-OTHER Win.Packed.Genpack-9795954-0 download attempt (more info ...)trojan-activity    URL
56426MALWARE-OTHER Win.Packed.Genpack-9795954-0 download attempt (more info ...)trojan-activity    URL
56427SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack 2020-4206   URL
56428SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack 2020-4206   URL
56429SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack 2020-4206   URL
56430SERVER-WEBAPP IBM Spectrum Protect Plus command injection attempt (more info ...)web-application-attack 2020-4206   URL
56446EXPLOIT-KIT RIG EK GandCrab page access attempt (more info ...)attempted-user    
56455MALWARE-OTHER PUA.Win.Adware.Crossrider-9797289-0 download attempt (more info ...)trojan-activity    URL
56456MALWARE-OTHER PUA.Win.Adware.Crossrider-9797289-0 download attempt (more info ...)trojan-activity    URL
56457MALWARE-OTHER Win.Packed.Nwh1dlg-9797380-0 download attempt (more info ...)trojan-activity    URL
56458MALWARE-OTHER Win.Packed.Nwh1dlg-9797380-0 download attempt (more info ...)trojan-activity    URL
56459MALWARE-OTHER Win.Dropper.Kuluoz-9797422-0 download attempt (more info ...)trojan-activity    URL
56460MALWARE-OTHER Win.Dropper.Kuluoz-9797422-0 download attempt (more info ...)trojan-activity    URL
56461MALWARE-OTHER Win.Packed.Zbot-9797509-0 download attempt (more info ...)trojan-activity    URL
56462MALWARE-OTHER Win.Packed.Zbot-9797509-0 download attempt (more info ...)trojan-activity    URL
56465MALWARE-OTHER PUA.Win.Adware.Amonetize-9797769-0 download attempt (more info ...)trojan-activity    URL
56466MALWARE-OTHER PUA.Win.Adware.Amonetize-9797769-0 download attempt (more info ...)trojan-activity    URL
56469MALWARE-OTHER Win.Trojan.Uztub-9798162-0 download attempt (more info ...)trojan-activity    URL
56470MALWARE-OTHER Win.Trojan.Uztub-9798162-0 download attempt (more info ...)trojan-activity    URL
56471MALWARE-OTHER Win.Malware.Budt-9798777-0 download attempt (more info ...)trojan-activity    URL
56472MALWARE-OTHER Win.Malware.Budt-9798777-0 download attempt (more info ...)trojan-activity    URL
56484MALWARE-OTHER Win.Packed.Ursu-9799226-0 download attempt (more info ...)trojan-activity    URL
56485MALWARE-OTHER Win.Packed.Ursu-9799226-0 download attempt (more info ...)trojan-activity    URL
56490MALWARE-OTHER Win.Packed.Razy-9799256-0 download attempt (more info ...)trojan-activity    URL
56491MALWARE-OTHER Win.Packed.Razy-9799256-0 download attempt (more info ...)trojan-activity    URL
56498SERVER-WEBAPP Oracle ADF Faces potential ViewState deserialization remote code execution attempt (more info ...)attempted-user 2019-2904   URL
56499SERVER-WEBAPP Oracle ADF Faces potential ViewState deserialization remote code execution attempt (more info ...)attempted-user 2019-2904   URL
56513MALWARE-OTHER Win.Dropper.Kuluoz-9800462-0 download attempt (more info ...)trojan-activity    URL
56514MALWARE-OTHER Win.Dropper.Kuluoz-9800462-0 download attempt (more info ...)trojan-activity    URL
56517MALWARE-OTHER Win.Dropper.Remcos-9801059-0 download attempt (more info ...)trojan-activity    URL
56518MALWARE-OTHER Win.Dropper.Remcos-9801059-0 download attempt (more info ...)trojan-activity    URL
56528MALWARE-OTHER Win.Dropper.Emotet-9801895-0 download attempt (more info ...)trojan-activity    URL
56529MALWARE-OTHER Win.Dropper.Emotet-9801895-0 download attempt (more info ...)trojan-activity    URL
56530MALWARE-CNC Win.Trojan.IcedId outbound communication attempt (more info ...)trojan-activity    URL
56535MALWARE-OTHER Win.Dropper.Emotet-9802270-0 download attempt (more info ...)trojan-activity    URL
56536MALWARE-OTHER Win.Dropper.Emotet-9802270-0 download attempt (more info ...)trojan-activity    URL
56539FILE-OTHER TRUFFLEHUNTER TALOS-2020-1212 attack attempt (more info ...)attempted-user 2020-28589   URL
56540FILE-OTHER TRUFFLEHUNTER TALOS-2020-1212 attack attempt (more info ...)attempted-user 2020-28589   URL
56564MALWARE-CNC Win.Trojan.PowerRatankba variant download attempt (more info ...)trojan-activity    URL
56577MALWARE-CNC Lokibot outbound connection attempt (more info ...)trojan-activity    URL
56596MALWARE-CNC MultiOS.Malware.GORAT outbound communications attempt (more info ...)trojan-activity    URL
56597MALWARE-CNC MultiOS.Malware.GORAT outbound communications attempt (more info ...)trojan-activity    URL
56598MALWARE-CNC Win.Backdoor.CSBundle_Original inbound connection attempt (more info ...)trojan-activity    URL
56599MALWARE-CNC Win.Backdoor.CSBundle_Original stager outbound connection attempt (more info ...)trojan-activity    URL
56600MALWARE-CNC Win.Backdoor.CSBundle_Original outbound connection attempt (more info ...)trojan-activity    URL
56601MALWARE-CNC Win.Backdoor.CSBundle_Original Stager 2 download attempt (more info ...)trojan-activity    URL
56602MALWARE-CNC Win.Backdoor.CSBundle_Original Server 3 inbound beacon attempt (more info ...)trojan-activity    URL
56603MALWARE-CNC Win.Backdoor.CSBundle_Original outbound connection attempt (more info ...)trojan-activity    URL
56605MALWARE-CNC Rat.Tool.CSBundleUSATodayServer variant inbound command attempt (more info ...)trojan-activity    URL
56606MALWARE-CNC Rat.Tool.CSBundleUSATodayServer variant inbound command attempt (more info ...)trojan-activity    URL
56607MALWARE-CNC potential Rat.Tool.CSBundleUSAToday connectivity check (more info ...)trojan-activity    URL
56612MALWARE-CNC Rat.Tool.FeyeYelp variant outbound beacon attempt (more info ...)trojan-activity    URL
56613MALWARE-CNC Rat.Tool.FeyeYelp variant outbound beacon attempt (more info ...)trojan-activity    URL
56615MALWARE-CNC Cobalt Strike beacon outbound connection attempt (more info ...)attempted-user    URL
56616MALWARE-CNC Cobalt Strike beacon outbound connection attempt (more info ...)attempted-user    URL
56617MALWARE-CNC Cobalt Strike beacon inbound connection attempt (more info ...)attempted-user    URL
56618MALWARE-OTHER Win.Worm.Waldek-9805060-0 download attempt (more info ...)trojan-activity    URL
56619MALWARE-OTHER Win.Worm.Waldek-9805060-0 download attempt (more info ...)trojan-activity    URL
56620MALWARE-OTHER Win.Dropper.Emotet-9805443-0 download attempt (more info ...)trojan-activity    URL
56621MALWARE-OTHER Win.Dropper.Emotet-9805443-0 download attempt (more info ...)trojan-activity    URL
56622MALWARE-OTHER Win.Dropper.Bunitu-9805453-0 download attempt (more info ...)trojan-activity    URL
56623MALWARE-OTHER Win.Dropper.Bunitu-9805453-0 download attempt (more info ...)trojan-activity    URL
56628MALWARE-OTHER Win.Dropper.Ap0calypseRAT-9805570-0 download attempt (more info ...)trojan-activity    URL
56629MALWARE-OTHER Win.Dropper.Ap0calypseRAT-9805570-0 download attempt (more info ...)trojan-activity    URL
56630MALWARE-OTHER PUA.Win.Adware.Opesup-9805608-0 download attempt (more info ...)trojan-activity    URL
56631MALWARE-OTHER PUA.Win.Adware.Opesup-9805608-0 download attempt (more info ...)trojan-activity    URL
56632MALWARE-OTHER PUA.Win.File.Ezsoftwareupdater-9805635-0 download attempt (more info ...)trojan-activity    URL
56633MALWARE-OTHER PUA.Win.File.Ezsoftwareupdater-9805635-0 download attempt (more info ...)trojan-activity    URL
56634MALWARE-OTHER Win.Downloader.Jpbv-9805695-0 download attempt (more info ...)trojan-activity    URL
56635MALWARE-OTHER Win.Downloader.Jpbv-9805695-0 download attempt (more info ...)trojan-activity    URL
56640MALWARE-OTHER Win.Malware.Zusy-9806564-0 download attempt (more info ...)trojan-activity    URL
56641MALWARE-OTHER Win.Malware.Zusy-9806564-0 download attempt (more info ...)trojan-activity    URL
56646MALWARE-OTHER PUA.Win.Adware.Crossrider-9807047-0 download attempt (more info ...)trojan-activity    URL
56647MALWARE-OTHER PUA.Win.Adware.Crossrider-9807047-0 download attempt (more info ...)trojan-activity    URL
56648MALWARE-OTHER PUA.Win.Adware.Crossrider-9807045-0 download attempt (more info ...)trojan-activity    URL
56649MALWARE-OTHER PUA.Win.Adware.Crossrider-9807045-0 download attempt (more info ...)trojan-activity    URL
56654MALWARE-OTHER Win.Dropper.Smalltrojan-9807963-0 download attempt (more info ...)trojan-activity    URL
56655MALWARE-OTHER Win.Dropper.Smalltrojan-9807963-0 download attempt (more info ...)trojan-activity    URL
56660MALWARE-CNC Win.Backdoor.Sunburst outbound connection attempt (more info ...)trojan-activity    URL
56661MALWARE-CNC Win.Backdoor.Sunburst outbound connection attempt (more info ...)trojan-activity    URL
56662MALWARE-CNC Win.Backdoor.Sunburst inbound connection attempt (more info ...)trojan-activity    URL
56663MALWARE-CNC Win.Backdoor.Sunburst inbound connection attempt (more info ...)trojan-activity    URL
56664MALWARE-CNC Win.Backdoor.Sunburst inbound connection attempt (more info ...)trojan-activity    URL
56665MALWARE-CNC Win.Backdoor.Sunburst outbound connection attempt (more info ...)trojan-activity    URL
56666MALWARE-CNC Win.Backdoor.Sunburst inbound connection attempt (more info ...)trojan-activity    URL
56667MALWARE-CNC Win.Backdoor.Sunburst inbound connection attempt (more info ...)trojan-activity    URL
56668MALWARE-CNC Win.Backdoor.Sunburst outbound connection attempt (more info ...)trojan-activity    URL
56669MALWARE-OTHER Win.Virus.Ramnit-9808983-0 download attempt (more info ...)trojan-activity    URL
56670MALWARE-OTHER Win.Virus.Ramnit-9808983-0 download attempt (more info ...)trojan-activity    URL
56673MALWARE-OTHER Win.Malware.Magania-9809232-0 download attempt (more info ...)trojan-activity    URL
56674MALWARE-OTHER Win.Malware.Magania-9809232-0 download attempt (more info ...)trojan-activity    URL
56675MALWARE-OTHER Win.Malware.Magania-9809233-0 download attempt (more info ...)trojan-activity    URL
56676MALWARE-OTHER Win.Malware.Magania-9809233-0 download attempt (more info ...)trojan-activity    URL
56677MALWARE-OTHER Win.Malware.Magania-9809234-0 download attempt (more info ...)trojan-activity    URL
56678MALWARE-OTHER Win.Malware.Magania-9809234-0 download attempt (more info ...)trojan-activity    URL
56679MALWARE-OTHER Win.Malware.Magania-9809236-0 download attempt (more info ...)trojan-activity    URL
56680MALWARE-OTHER Win.Malware.Magania-9809236-0 download attempt (more info ...)trojan-activity    URL
56681MALWARE-OTHER Win.Malware.Magania-9809289-0 download attempt (more info ...)trojan-activity    URL
56682MALWARE-OTHER Win.Malware.Magania-9809289-0 download attempt (more info ...)trojan-activity    URL
56683MALWARE-OTHER Win.Malware.Magania-9809288-0 download attempt (more info ...)trojan-activity    URL
56684MALWARE-OTHER Win.Malware.Magania-9809288-0 download attempt (more info ...)trojan-activity    URL
56687MALWARE-OTHER Win.Malware.Magania-9809291-0 download attempt (more info ...)trojan-activity    URL
56688MALWARE-OTHER Win.Malware.Magania-9809291-0 download attempt (more info ...)trojan-activity    URL
56689MALWARE-OTHER Win.Malware.Magania-9809292-0 download attempt (more info ...)trojan-activity    URL
56690MALWARE-OTHER Win.Malware.Magania-9809292-0 download attempt (more info ...)trojan-activity    URL
56691MALWARE-OTHER Win.Malware.Magania-9809293-0 download attempt (more info ...)trojan-activity    URL
56692MALWARE-OTHER Win.Malware.Magania-9809293-0 download attempt (more info ...)trojan-activity    URL
56693MALWARE-OTHER Win.Malware.Magania-9809302-0 download attempt (more info ...)trojan-activity    URL
56694MALWARE-OTHER Win.Malware.Magania-9809302-0 download attempt (more info ...)trojan-activity    URL
56695MALWARE-OTHER Win.Malware.Zusy-9809303-0 download attempt (more info ...)trojan-activity    URL
56696MALWARE-OTHER Win.Malware.Zusy-9809303-0 download attempt (more info ...)trojan-activity    URL
56697MALWARE-OTHER Win.Malware.Magania-9809310-0 download attempt (more info ...)trojan-activity    URL
56698MALWARE-OTHER Win.Malware.Magania-9809310-0 download attempt (more info ...)trojan-activity    URL
56699MALWARE-OTHER Win.Malware.Magania-9809311-0 download attempt (more info ...)trojan-activity    URL
56700MALWARE-OTHER Win.Malware.Magania-9809311-0 download attempt (more info ...)trojan-activity    URL
56701MALWARE-OTHER Win.Trojan.Napolar-9809317-0 download attempt (more info ...)trojan-activity    URL
56702MALWARE-OTHER Win.Trojan.Napolar-9809317-0 download attempt (more info ...)trojan-activity    URL
56703MALWARE-OTHER Win.Malware.Mikey-9809358-0 download attempt (more info ...)trojan-activity    URL
56704MALWARE-OTHER Win.Malware.Mikey-9809358-0 download attempt (more info ...)trojan-activity    URL
56705MALWARE-OTHER Win.Malware.Magania-9809405-0 download attempt (more info ...)trojan-activity    URL
56706MALWARE-OTHER Win.Malware.Magania-9809405-0 download attempt (more info ...)trojan-activity    URL
56707MALWARE-OTHER Win.Malware.Magania-9809423-0 download attempt (more info ...)trojan-activity    URL
56708MALWARE-OTHER Win.Malware.Magania-9809423-0 download attempt (more info ...)trojan-activity    URL
56709MALWARE-OTHER Win.Malware.Magania-9809425-0 download attempt (more info ...)trojan-activity    URL
56710MALWARE-OTHER Win.Malware.Magania-9809425-0 download attempt (more info ...)trojan-activity    URL
56711MALWARE-OTHER Win.Malware.Ppatre-9809656-0 download attempt (more info ...)trojan-activity    URL
56712MALWARE-OTHER Win.Malware.Ppatre-9809656-0 download attempt (more info ...)trojan-activity    URL
56713MALWARE-OTHER Win.Malware.Emotet-9809680-0 download attempt (more info ...)trojan-activity    URL
56714MALWARE-OTHER Win.Malware.Emotet-9809680-0 download attempt (more info ...)trojan-activity    URL
56715MALWARE-OTHER PUA.Win.Adware.Priplut-9809769-0 download attempt (more info ...)trojan-activity    URL
56716MALWARE-OTHER PUA.Win.Adware.Priplut-9809769-0 download attempt (more info ...)trojan-activity    URL
56717MALWARE-CNC Win.Ransomware.Egregor variant outbound connection (more info ...)trojan-activity    URL
56718MALWARE-CNC Win.Trojan.xDLL variant outbound communication attempt (more info ...)trojan-activity    URL
56719MALWARE-CNC Win.Trojan.xDLL variant outbound communication attempt (more info ...)trojan-activity    URL
56720SERVER-WEBAPP Citrix ADC and Gateway authentication bypass attempt (more info ...)web-application-attack 2020-8193   URL
56729SERVER-OTHER TRUFFLEHUNTER TALOS-2020-1217 attack attempt (more info ...)attempted-admin 2020-28593   URL
56730MALWARE-OTHER Win.Trojan.Fareit-9810681-0 download attempt (more info ...)trojan-activity    URL
56731MALWARE-OTHER Win.Trojan.Fareit-9810681-0 download attempt (more info ...)trojan-activity    URL
56734MALWARE-OTHER Win.Malware.Pcclient-9811524-0 download attempt (more info ...)trojan-activity    URL
56735MALWARE-OTHER Win.Malware.Pcclient-9811524-0 download attempt (more info ...)trojan-activity    URL
56736MALWARE-OTHER Win.Malware.Generic-9812011-0 download attempt (more info ...)trojan-activity    URL
56737MALWARE-OTHER Win.Malware.Generic-9812011-0 download attempt (more info ...)trojan-activity    URL
56738MALWARE-OTHER Win.Malware.Generickdz-9812035-0 download attempt (more info ...)trojan-activity    URL
56739MALWARE-OTHER Win.Malware.Generickdz-9812035-0 download attempt (more info ...)trojan-activity    URL
56740MALWARE-OTHER Win.Malware.Generickdz-9812036-0 download attempt (more info ...)trojan-activity    URL
56741MALWARE-OTHER Win.Malware.Generickdz-9812036-0 download attempt (more info ...)trojan-activity    URL
56742MALWARE-OTHER Win.Malware.Generickdz-9812037-0 download attempt (more info ...)trojan-activity    URL
56743MALWARE-OTHER Win.Malware.Generickdz-9812037-0 download attempt (more info ...)trojan-activity    URL
56744MALWARE-OTHER Win.Malware.Cerbu-9811987-0 download attempt (more info ...)trojan-activity    URL
56745MALWARE-OTHER Win.Malware.Cerbu-9811987-0 download attempt (more info ...)trojan-activity    URL
56748MALWARE-OTHER Win.Malware.Generickdz-9812114-0 download attempt (more info ...)trojan-activity    URL
56749MALWARE-OTHER Win.Malware.Generickdz-9812114-0 download attempt (more info ...)trojan-activity    URL
56750MALWARE-OTHER Win.Malware.Generickdz-9812058-0 download attempt (more info ...)trojan-activity    URL
56751MALWARE-OTHER Win.Malware.Generickdz-9812058-0 download attempt (more info ...)trojan-activity    URL
56752MALWARE-OTHER Win.Malware.Ulise-9812070-0 download attempt (more info ...)trojan-activity    URL
56753MALWARE-OTHER Win.Malware.Ulise-9812070-0 download attempt (more info ...)trojan-activity    URL
56754MALWARE-OTHER Win.Malware.Generickdz-9812083-0 download attempt (more info ...)trojan-activity    URL
56755MALWARE-OTHER Win.Malware.Generickdz-9812083-0 download attempt (more info ...)trojan-activity    URL
56758MALWARE-OTHER Win.Packed.Ceeinject-9812597-0 download attempt (more info ...)trojan-activity    URL
56759MALWARE-OTHER Win.Packed.Ceeinject-9812597-0 download attempt (more info ...)trojan-activity    URL
56760MALWARE-OTHER Win.Malware.Mikey-9812612-0 download attempt (more info ...)trojan-activity    URL
56761MALWARE-OTHER Win.Malware.Mikey-9812612-0 download attempt (more info ...)trojan-activity    URL
56762MALWARE-OTHER Win.Packed.Upantix-9812630-0 download attempt (more info ...)trojan-activity    URL
56763MALWARE-OTHER Win.Packed.Upantix-9812630-0 download attempt (more info ...)trojan-activity    URL
56766MALWARE-OTHER Win.Dropper.Shiz-9814645-0 download attempt (more info ...)trojan-activity    URL
56767MALWARE-OTHER Win.Dropper.Shiz-9814645-0 download attempt (more info ...)trojan-activity    URL
56768MALWARE-CNC Win.Trojan.Supernova Webshell Command and Control attempt (more info ...)trojan-activity    URL
56769MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56770MALWARE-CNC Win.Trojan.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56771MALWARE-CNC Win.Trojan.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56774MALWARE-OTHER Win.Malware.Qbot variant download attempt (more info ...)trojan-activity    URL
56775MALWARE-OTHER Win.Malware.Qbot variant download attempt (more info ...)trojan-activity    URL
56778SERVER-WEBAPP ARRIS VAP2500 list_mac_address cmb_macaddrfilter command injection attempt (more info ...)web-application-attack    URL
56779SERVER-WEBAPP ARRIS VAP2500 list_mac_address cmb_macaddrfilter command injection attempt (more info ...)web-application-attack    URL
56780MALWARE-OTHER Win.Dropper.Cerber-9815517-0 download attempt (more info ...)trojan-activity    URL
56781MALWARE-OTHER Win.Dropper.Cerber-9815517-0 download attempt (more info ...)trojan-activity    URL
56782MALWARE-OTHER Win.Dropper.Bunitu-9815611-0 download attempt (more info ...)trojan-activity    URL
56783MALWARE-OTHER Win.Dropper.Bunitu-9815611-0 download attempt (more info ...)trojan-activity    URL
56784MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56785MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56786MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56787MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56788MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56789MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56790MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56791MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56792MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56793MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56794MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56795MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56796MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56798MALWARE-CNC Win.Downloader.Qbot outbound connection attempt (more info ...)trojan-activity    URL
56802MALWARE-OTHER Win.Dropper.Kuluoz-9815697-0 download attempt (more info ...)trojan-activity    URL
56803MALWARE-OTHER Win.Dropper.Kuluoz-9815697-0 download attempt (more info ...)trojan-activity    URL
56807MALWARE-OTHER Win.Malware.Ulise-9815758-0 download attempt (more info ...)trojan-activity    URL
56808MALWARE-OTHER Win.Malware.Ulise-9815758-0 download attempt (more info ...)trojan-activity    URL
56811MALWARE-OTHER Win.Trojan.Bladabindi-9816601-0 download attempt (more info ...)trojan-activity    URL
56812MALWARE-OTHER Win.Trojan.Bladabindi-9816601-0 download attempt (more info ...)trojan-activity    URL
56813MALWARE-OTHER Win.Packed.Qbot-9817504-0 download attempt (more info ...)trojan-activity    URL
56814MALWARE-OTHER Win.Packed.Qbot-9817504-0 download attempt (more info ...)trojan-activity    URL
56817MALWARE-OTHER Win.Malware.Quchispy-9818300-0 download attempt (more info ...)trojan-activity    URL
56818MALWARE-OTHER Win.Malware.Quchispy-9818300-0 download attempt (more info ...)trojan-activity    URL
56825POLICY-OTHER SolarWinds Orion version lookup attempt (more info ...)attempted-recon 2020-10148   URL
56832SERVER-WEBAPP TRUFFLEHUNTER TALOS-2020-1221 attack attempt (more info ...)attempted-user 2020-28597   URL
56834MALWARE-CNC Win.Trojan.TroubleGrabber outbound communication attempt (more info ...)trojan-activity    URL
56835MALWARE-CNC Win.Trojan.TroubleGrabber outbound communication attempt (more info ...)trojan-activity    URL
56862MALWARE-CNC MultiOS.Malware.GORAT outbound communication attempt (more info ...)trojan-activity    URL
56863MALWARE-CNC MultiOS.Malware.GORAT command and control response attempt (more info ...)trojan-activity    URL
56864MALWARE-CNC MultiOS.Malware.GORAT command and control SSL certificate (more info ...)trojan-activity    URL
56886EXPLOIT-KIT RIG EK GandCrab page access attempt (more info ...)attempted-user    
56891MALWARE-CNC Win.Trojan.BasicPipeShell variant communication attempt (more info ...)trojan-activity    URL
56892MALWARE-CNC Win.Trojan.BasicPipeShell variant communication attempt (more info ...)trojan-activity    URL
56893FILE-OTHER OpenSSL configuration arbitrary DLL load attempt (more info ...)attempted-user 2021-1280   URL
56894FILE-OTHER OpenSSL configuration arbitrary DLL load attempt (more info ...)attempted-user 2021-1280   URL
56895MALWARE-OTHER Win.Packed.Xowgc8j-9819208-0 download attempt (more info ...)trojan-activity    URL
56896MALWARE-OTHER Win.Packed.Xowgc8j-9819208-0 download attempt (more info ...)trojan-activity    URL
56897MALWARE-OTHER Win.Malware.Mikey-9819490-0 download attempt (more info ...)trojan-activity    URL
56898MALWARE-OTHER Win.Malware.Mikey-9819490-0 download attempt (more info ...)trojan-activity    URL
56899MALWARE-OTHER Win.Malware.Tiny-9819505-0 download attempt (more info ...)trojan-activity    URL
56900MALWARE-OTHER Win.Malware.Tiny-9819505-0 download attempt (more info ...)trojan-activity    URL
56901MALWARE-OTHER Win.Malware.Zusy-9819756-0 download attempt (more info ...)trojan-activity    URL
56902MALWARE-OTHER Win.Malware.Zusy-9819756-0 download attempt (more info ...)trojan-activity    URL
56903MALWARE-OTHER Win.Malware.Mikey-9820100-0 download attempt (more info ...)trojan-activity    URL
56904MALWARE-OTHER Win.Malware.Mikey-9820100-0 download attempt (more info ...)trojan-activity    URL
56906MALWARE-OTHER Win.Packed.Emotet-9821266-0 download attempt (more info ...)trojan-activity    URL
56907MALWARE-OTHER Win.Packed.Emotet-9821266-0 download attempt (more info ...)trojan-activity    URL
56908MALWARE-OTHER Win.Downloader.Upatre-9821529-0 download attempt (more info ...)trojan-activity    URL
56909MALWARE-OTHER Win.Downloader.Upatre-9821529-0 download attempt (more info ...)trojan-activity    URL
56912MALWARE-OTHER Win.Malware.Ursu-9821797-0 download attempt (more info ...)trojan-activity    URL
56913MALWARE-OTHER Win.Malware.Ursu-9821797-0 download attempt (more info ...)trojan-activity    URL
56914MALWARE-OTHER Win.Malware.Cerbu-9822059-0 download attempt (more info ...)trojan-activity    URL
56915MALWARE-OTHER Win.Malware.Cerbu-9822059-0 download attempt (more info ...)trojan-activity    URL
56918MALWARE-OTHER Win.Malware.Qqpass-9822210-0 download attempt (more info ...)trojan-activity    URL
56919MALWARE-OTHER Win.Malware.Qqpass-9822210-0 download attempt (more info ...)trojan-activity    URL
56920MALWARE-OTHER Win.Malware.Qqpass-9822211-0 download attempt (more info ...)trojan-activity    URL
56921MALWARE-OTHER Win.Malware.Qqpass-9822211-0 download attempt (more info ...)trojan-activity    URL
56922MALWARE-OTHER Win.Malware.Qqpass-9822241-0 download attempt (more info ...)trojan-activity    URL
56923MALWARE-OTHER Win.Malware.Qqpass-9822241-0 download attempt (more info ...)trojan-activity    URL
56951MALWARE-OTHER Win.Packed.Medfos-9822521-0 download attempt (more info ...)trojan-activity    URL
56952MALWARE-OTHER Win.Packed.Medfos-9822521-0 download attempt (more info ...)trojan-activity    URL
56964MALWARE-OTHER Win.Malware.Kovter-9822841-0 download attempt (more info ...)trojan-activity    URL
56965MALWARE-OTHER Win.Malware.Kovter-9822841-0 download attempt (more info ...)trojan-activity    URL
56966MALWARE-CNC Win.Trojan.IcedId outbound communication attempt (more info ...)trojan-activity    URL
56969MALWARE-OTHER Win.Ransomware.Emotet-9823374-0 download attempt (more info ...)trojan-activity    URL
56970MALWARE-OTHER Win.Ransomware.Emotet-9823374-0 download attempt (more info ...)trojan-activity    URL
56975MALWARE-OTHER Win.Packed.Upatre-9823510-0 download attempt (more info ...)trojan-activity    URL
56976MALWARE-OTHER Win.Packed.Upatre-9823510-0 download attempt (more info ...)trojan-activity    URL
56981MALWARE-OTHER Win.Malware.Ulise-9823887-0 download attempt (more info ...)trojan-activity    URL
56982MALWARE-OTHER Win.Malware.Ulise-9823887-0 download attempt (more info ...)trojan-activity    URL
56985MALWARE-OTHER Win.Malware.Ulise-9823969-0 download attempt (more info ...)trojan-activity    URL
56986MALWARE-OTHER Win.Malware.Ulise-9823969-0 download attempt (more info ...)trojan-activity    URL
56987MALWARE-CNC Win.Trojan.IcedID variant extra payload download attempt (more info ...)trojan-activity    URL
56988MALWARE-CNC Win.Trojan.IcedID variant extra payload download attempt (more info ...)trojan-activity    URL
56991MALWARE-CNC Win.Trojan.ElectroRat outbound connection attempt (more info ...)trojan-activity    URL
56992MALWARE-CNC Win.Trojan.ElectroRat outbound connection attempt (more info ...)trojan-activity    URL
56993MALWARE-CNC Win.Trojan.ElectroRat outbound connection attempt (more info ...)trojan-activity    URL
56996MALWARE-OTHER Win.Trojan.Urelas-9825378-0 download attempt (more info ...)trojan-activity    URL
56997MALWARE-OTHER Win.Trojan.Urelas-9825378-0 download attempt (more info ...)trojan-activity    URL
56998MALWARE-OTHER Win.Malware.Cowq-9825380-0 download attempt (more info ...)trojan-activity    URL
56999MALWARE-OTHER Win.Malware.Cowq-9825380-0 download attempt (more info ...)trojan-activity    URL
57005MALWARE-OTHER Win.Packed.Zbot-9825410-0 download attempt (more info ...)trojan-activity    URL
57006MALWARE-OTHER Win.Packed.Zbot-9825410-0 download attempt (more info ...)trojan-activity    URL
57009MALWARE-OTHER Win.Ransomware.Cerber-9825486-0 download attempt (more info ...)trojan-activity    URL
57010MALWARE-OTHER Win.Ransomware.Cerber-9825486-0 download attempt (more info ...)trojan-activity    URL
57019MALWARE-OTHER Win.Trojan.Generickdz-9825913-0 download attempt (more info ...)trojan-activity    URL
57020MALWARE-OTHER Win.Trojan.Generickdz-9825913-0 download attempt (more info ...)trojan-activity    URL
57021MALWARE-OTHER Win.Malware.Ceyc-9825747-0 download attempt (more info ...)trojan-activity    URL
57022MALWARE-OTHER Win.Malware.Ceyc-9825747-0 download attempt (more info ...)trojan-activity    URL
57023MALWARE-OTHER Win.Ransomware.RansomLock-9825921-0 download attempt (more info ...)trojan-activity    URL
57024MALWARE-OTHER Win.Ransomware.RansomLock-9825921-0 download attempt (more info ...)trojan-activity    URL
57025MALWARE-OTHER Win.Trojan.Urausy-9825941-0 download attempt (more info ...)trojan-activity    URL
57026MALWARE-OTHER Win.Trojan.Urausy-9825941-0 download attempt (more info ...)trojan-activity    URL
57027MALWARE-OTHER Win.Malware.Fugrafa-9826021-0 download attempt (more info ...)trojan-activity    URL
57028MALWARE-OTHER Win.Malware.Fugrafa-9826021-0 download attempt (more info ...)trojan-activity    URL
57029MALWARE-OTHER Win.Trojan.Lockscreen-9826040-0 download attempt (more info ...)trojan-activity    URL
57030MALWARE-OTHER Win.Trojan.Lockscreen-9826040-0 download attempt (more info ...)trojan-activity    URL
57033MALWARE-OTHER Win.Ransomware.Urausy-9826539-0 download attempt (more info ...)trojan-activity    URL
57034MALWARE-OTHER Win.Ransomware.Urausy-9826539-0 download attempt (more info ...)trojan-activity    URL
57035MALWARE-OTHER Win.Ransomware.Urausy-9826537-0 download attempt (more info ...)trojan-activity    URL
57036MALWARE-OTHER Win.Ransomware.Urausy-9826537-0 download attempt (more info ...)trojan-activity    URL
57037MALWARE-OTHER Win.Ransomware.Generickdz-9826546-0 download attempt (more info ...)trojan-activity    URL
57038MALWARE-OTHER Win.Ransomware.Generickdz-9826546-0 download attempt (more info ...)trojan-activity    URL
57041MALWARE-OTHER Win.Malware.Nymaim-9826797-0 download attempt (more info ...)trojan-activity    URL
57042MALWARE-OTHER Win.Malware.Nymaim-9826797-0 download attempt (more info ...)trojan-activity    URL
57043MALWARE-OTHER Win.Malware.Fugrafa-9826819-0 download attempt (more info ...)trojan-activity    URL
57044MALWARE-OTHER Win.Malware.Fugrafa-9826819-0 download attempt (more info ...)trojan-activity    URL
57047MALWARE-CNC Win.Trojan.Covicli variant download attempt (more info ...)trojan-activity    URL
57050MALWARE-OTHER Win.Packed.Generickdz-9827137-0 download attempt (more info ...)trojan-activity    URL
57051MALWARE-OTHER Win.Packed.Generickdz-9827137-0 download attempt (more info ...)trojan-activity    URL
57052FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1232 attack attempt (more info ...)attempted-user 2021-21776   URL
57053FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1232 attack attempt (more info ...)attempted-user 2021-21776   URL
57054INDICATOR-COMPROMISE RTF objdata file download attempt (more info ...)attempted-user 2017-11882   URL
57055INDICATOR-COMPROMISE RTF objdata file download attempt (more info ...)misc-activity 2017-11882   URL
57056PROTOCOL-SCADA TRUFFLEHUNTER TALOS-2021-1234 attack attempt (more info ...)attempted-recon 2021-21777   URL
57067SERVER-OTHER HP Web JetAdmin file write attempt (more info ...)web-application-activity  9973  
57070SERVER-WEBAPP Reprise License Manager diagnostics_doit outputfile directory traversal attempt (more info ...)web-application-attack    
57071SERVER-WEBAPP Reprise License Manager diagnostics_doit outputfile directory traversal attempt (more info ...)web-application-attack    
57129SERVER-OTHER ElasticSearch information disclosure attempt (more info ...)policy-violation 2014-3120   URL
57130SERVER-OTHER ElasticSearch information disclosure attempt (more info ...)policy-violation 2014-3120   URL
57131SERVER-OTHER ElasticSearch information disclosure attempt (more info ...)policy-violation 2014-3120   URL
57132SERVER-WEBAPP Barcodes Generator cross site scripting attempt (more info ...)attempted-user    URL
57133SERVER-WEBAPP Barcodes Generator cross site scripting attempt (more info ...)attempted-user    URL
57141MALWARE-OTHER Win.Trojan.Masslogger variant E binary download attempt (more info ...)attempted-admin    
57142MALWARE-OTHER Win.Trojan.Masslogger variant F binary download attempt (more info ...)trojan-activity    
57143MALWARE-OTHER Win.Trojan.Masslogger variant F binary download attempt (more info ...)attempted-admin    
57144MALWARE-OTHER Win.Trojan.Masslogger variant C binary download attempt (more info ...)attempted-admin    
57145MALWARE-OTHER Win.Trojan.Masslogger variant G binary download attempt (more info ...)attempted-admin    
57146MALWARE-OTHER Win.Trojan.Masslogger variant D binary download attempt (more info ...)attempted-admin    
57147MALWARE-OTHER Win.Trojan.Masslogger variant A binary download attempt (more info ...)trojan-activity    
57148MALWARE-OTHER Win.Trojan.Masslogger variant G binary download attempt (more info ...)trojan-activity    
57149MALWARE-OTHER Win.Trojan.Masslogger variant E binary download attempt (more info ...)trojan-activity    
57150MALWARE-OTHER Win.Trojan.Masslogger variant D binary download attempt (more info ...)trojan-activity    
57151MALWARE-OTHER Win.Trojan.Masslogger variant C binary download attempt (more info ...)trojan-activity    
57152MALWARE-OTHER Win.Trojan.Masslogger variant B binary download attempt (more info ...)trojan-activity    
57153MALWARE-OTHER Win.Trojan.Masslogger variant B binary download attempt (more info ...)attempted-admin    
57155PROTOCOL-SCADA Real-time Automation Ethernet/IP buffer over flow attempt (more info ...)attempted-user 2020-25159   
57162FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1248 attack attempt (more info ...)attempted-user 2021-21784   URL
57163FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1248 attack attempt (more info ...)attempted-user 2021-21784   URL
57164FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1248 attack attempt (more info ...)attempted-user 2021-21784   URL
57165FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1248 attack attempt (more info ...)attempted-user 2021-21784   URL
57168MALWARE-CNC Win.Backdoor.ObliqueRAT outbound connection attempt (more info ...)trojan-activity    URL
57169MALWARE-CNC Win.Backdoor.ObliqueRAT outbound connection attempt (more info ...)trojan-activity    URL
57170MALWARE-CNC Win.Backdoor.ObliqueRAT outbound connection attempt (more info ...)trojan-activity    URL
57171MALWARE-CNC Win.Backdoor.ObliqueRAT outbound connection attempt (more info ...)trojan-activity    URL
57172MALWARE-CNC Win.Backdoor.ObliqueRAT outbound connection attempt (more info ...)trojan-activity    URL
57173MALWARE-CNC Win.Backdoor.ObliqueRAT outbound connection attempt (more info ...)trojan-activity    URL
57174MALWARE-CNC Win.Backdoor.ObliqueRAT outbound connection attempt (more info ...)trojan-activity    URL
57175MALWARE-CNC Win.Backdoor.ObliqueRAT outbound connection attempt (more info ...)trojan-activity    URL
57194MALWARE-CNC Doc.Dropper.Gamaredon variant outbound connection (more info ...)trojan-activity    URL
57195MALWARE-CNC Doc.Dropper.Gamaredon variant outbound connection (more info ...)trojan-activity    URL
57196MALWARE-CNC Win.Dropper.Gamaredon variant outbound connection (more info ...)trojan-activity    URL
57203MALWARE-CNC Win.Trojan.Stantinko outbound connection attempt (more info ...)trojan-activity    URL
57204MALWARE-CNC Win.Trojan.Amadey outbound connection attempt (more info ...)trojan-activity    URL
57209SERVER-WEBAPP Monstra CMS cross site scripting attempt (more info ...)attempted-user 2018-16978   
57210SERVER-WEBAPP Monstra CMS cross site scripting attempt (more info ...)attempted-user 2018-16978   
57211MALWARE-CNC Win.Downloader.Agent variant binary download attempt (more info ...)trojan-activity    URL
57212MALWARE-CNC Win.Downloader.Agent variant binary download attempt (more info ...)trojan-activity    URL
57213MALWARE-CNC Win.Downloader.Agent variant binary download attempt (more info ...)trojan-activity    URL
57214MALWARE-CNC Win.Downloader.Agent variant binary download attempt (more info ...)trojan-activity    URL
57215MALWARE-CNC Win.Trojan.CrimsonRAT inbound connection attempt (more info ...)trojan-activity    URL
57216MALWARE-CNC Win.Trojan.CrimsonRAT inbound connection attempt (more info ...)trojan-activity    URL
57219POLICY-OTHER SAP Solution Manager EEM endpoint external access attempt (more info ...)policy-violation 2020-6207   URL
57220MALWARE-CNC Win.Trojan.Micropsia variant outbound connection attempt (more info ...)trojan-activity    URL
57221MALWARE-CNC Win.Trojan.PyMicropsia variant outbound connection attempt (more info ...)trojan-activity    URL
57235MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57236MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57237MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57238MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57239MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57240MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57247MALWARE-OTHER Win.Ransomware.ColdChristmas variant binary download attempt (more info ...)trojan-activity    URL
57311MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57312MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57313MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57322MALWARE-OTHER Win.Ransomware.DoejoCrypt variant binary download attempt (more info ...)trojan-activity    URL
57341MALWARE-CNC Win.Trojan.Patchwork variant beaconing attempt (more info ...)trojan-activity    URL
57342MALWARE-CNC Html.Webshell.Hafnium inbound request attempt (more info ...)trojan-activity    URL
57380MALWARE-CNC Win.Backdoor.Sunburst outbound connection attempt (more info ...)trojan-activity    URL
57405MALWARE-CNC Win.Backdoor.Sunburst SUNSHUTTLE variant outbound connection attempt (more info ...)trojan-activity    URL
57416MALWARE-CNC Win.Trojan.Raindrop variant outbound connection attempt (more info ...)trojan-activity    URL
57417MALWARE-CNC Win.Trojan.Raindrop variant outbound connection attempt (more info ...)trojan-activity    URL
57418MALWARE-CNC Win.Trojan.Raindrop variant outbound connection attempt (more info ...)trojan-activity    URL
57419MALWARE-CNC Win.Trojan.Raindrop variant outbound connection attempt (more info ...)trojan-activity    URL
57422MALWARE-CNC TRUFFLEHUNTER SFVRT-1043 attack attempt (more info ...)trojan-activity    
57431MALWARE-CNC Win.Trojan.Remcos variant outbound connection (more info ...)trojan-activity    URL
57450SERVER-OTHER F5 WAF/ASM crafted reponse header buffer overflow attempt (more info ...)attempted-user 2021-22992   URL
57474MALWARE-CNC Win.Malware.LemonDuck variant outbound cnc connection (more info ...)attempted-user    URL
57477POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1282 attack attempt (more info ...)policy-violation 2021-21818   URL
57478SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1281 attack attempt (more info ...)attempted-recon 2021-21816   URL
57503POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1290 attack attempt (more info ...)policy-violation 2021-21830   URL
57504POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1290 attack attempt (more info ...)policy-violation 2021-21830   URL
57509FILE-PDF TRUFFLEHUNTER TALOS-2021-1286 attack attempt (more info ...)attempted-user 2021-21821   URL
57510FILE-PDF TRUFFLEHUNTER TALOS-2021-1286 attack attempt (more info ...)attempted-user 2021-21821   URL
57551MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57552MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57553MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57554MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57555MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57556MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57557MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57558MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57559MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57560MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57561MALWARE-CNC Win.Spyware.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57562MALWARE-CNC Win.Trojan.CrimsonRat outbound connection attempt (more info ...)trojan-activity    URL
57563SERVER-WEBAPP PineApp Mail-SeCure conflivelog.pl install license command injection attempt (more info ...)web-application-attack  61472  
57564SERVER-WEBAPP PineApp Mail-SeCure conflivelog.pl install license command injection attempt (more info ...)web-application-attack  61472  
57565SERVER-WEBAPP PineApp Mail-SeCure conflivelog.pl install license command injection attempt (more info ...)web-application-attack  61472  
57577MALWARE-CNC Win.Trojan.IcedID outbound connection attempt (more info ...)trojan-activity    URL
57606SERVER-WEBAPP MyBB Visual Editor cross site scripting attempt (more info ...)attempted-user 2018-17128   URL
57631PUA-OTHER WeChat User-Agent string - MicroMessenger (more info ...)misc-activity    
57632PUA-OTHER Known unwanted User-Agent string - LieBaoFast (more info ...)misc-activity    
57633PUA-OTHER Known unwanted User-Agent string - Mb2345Browser (more info ...)misc-activity    
57634PUA-OTHER Known unwanted User-Agent string - PetalBot (more info ...)misc-activity    
57673SERVER-WEBAPP Oracle BEA WebLogic overlong JESSIONID buffer overflow attempt (more info ...)misc-attack 2008-5457   
57674SERVER-WEBAPP Oracle BEA WebLogic overlong JESSIONID buffer overflow attempt (more info ...)misc-attack 2008-5457   
57683PROTOCOL-VOIP SIP Torture Retry-After field with overly-large value attempt (more info ...)misc-activity    URL
57684PROTOCOL-VOIP SIP Torture Retry-After field with overly-large value attempt (more info ...)misc-activity    URL
57685PROTOCOL-VOIP SIP Torture Retry-After field with overly-large value attempt (more info ...)misc-activity    URL
57686PROTOCOL-VOIP SIP Torture Retry-After field with overly-large value attempt (more info ...)misc-activity    URL
57714MALWARE-CNC Multios.Trojan.NecroBot outbound connection attempt (more info ...)trojan-activity    URL
57715MALWARE-CNC Multios.Trojan.NecroBot outbound connection attempt (more info ...)trojan-activity    URL
57716MALWARE-CNC Multios.Trojan.NecroBot outbound connection attempt (more info ...)trojan-activity    URL
57717MALWARE-CNC Multios.Trojan.NecroBot outbound connection attempt (more info ...)trojan-activity    URL
57738POLICY-OTHER Active Directory Federation Services policy store transfer service request detected (more info ...)misc-activity    URL
57760OS-WINDOWS Generic HyperLink buffer overflow attempt (more info ...)attempted-user 2017-17099 37184  URL
57763SERVER-OTHER ElasticSearch script remote code execution attempt (more info ...)attempted-user 2015-1427   URL
57773MALWARE-CNC Win.Trojan.Bazaloader variant outbound request detected (more info ...)trojan-activity    
57780MALWARE-CNC Win.Backdoor.IPsecHelper outbound connection attempt (more info ...)trojan-activity    URL
57781MALWARE-CNC Win.Backdoor.IPsecHelper outbound connection attempt (more info ...)trojan-activity    URL
57782MALWARE-CNC Win.Backdoor.IPsecHelper outbound connection attempt (more info ...)trojan-activity    URL
57807POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1322 attack attempt (more info ...)policy-violation 2021-21878   URL
57813SERVER-OTHER Citrix NetScaler Gateway DTLS client hello denial of service attempt (more info ...)attempted-dos    URL
57823MALWARE-CNC ASPXSpy webshell outbound connection attempt (more info ...)trojan-activity    URL
57824MALWARE-CNC ASPXSpy webshell outbound connection attempt (more info ...)trojan-activity    URL
57825MALWARE-CNC ASPXSpy webshell inbound connection attempt (more info ...)trojan-activity    URL
57826MALWARE-CNC ASPXSpy webshell inbound connection attempt (more info ...)trojan-activity    URL
57827MALWARE-CNC ASPXSpy webshell inbound connection attempt (more info ...)trojan-activity    URL
57828MALWARE-CNC ASPXSpy webshell outbound connection attempt (more info ...)trojan-activity    URL
57832OS-OTHER Apple macOS Gatekeeper bypass attempt (more info ...)attempted-user 2021-30657   
57833OS-OTHER Apple macOS Gatekeeper bypass attempt (more info ...)attempted-user 2021-30657   
57842MALWARE-CNC Win.Trojan.ActionRAT variant outbound connection (more info ...)trojan-activity    URL
57843MALWARE-CNC Win.Trojan.ActionRAT variant outbound connection (more info ...)trojan-activity    URL
57844MALWARE-CNC Win.Trojan.ActionRAT variant outbound connection (more info ...)trojan-activity    URL
57845MALWARE-CNC Win.Trojan.ActionRAT variant outbound connection (more info ...)trojan-activity    URL
57846MALWARE-CNC Win.Trojan.ActionRAT variant outbound connection (more info ...)trojan-activity    URL
57847MALWARE-CNC Win.Trojan.CetaRAT variant outbound connection (more info ...)trojan-activity    URL
57848MALWARE-CNC Win.Trojan.CetaRAT variant outbound connection (more info ...)trojan-activity    URL
57849MALWARE-CNC Win.Trojan.CetaRAT variant outbound connection (more info ...)trojan-activity    URL
57858MALWARE-CNC Win.Downloader.VictoryDll outbound connection attempt (more info ...)trojan-activity    URL
57864MALWARE-CNC Netfilter rootkit outbound connection attempt (more info ...)trojan-activity    URL
57865MALWARE-CNC Netfilter rootkit download attempt (more info ...)trojan-activity    URL
57866MALWARE-CNC Netfilter rootkit outbound connection attempt (more info ...)trojan-activity    URL
57867MALWARE-CNC Netfilter rootkit download attempt (more info ...)trojan-activity    URL
57868MALWARE-CNC Netfilter rootkit outbound connection attempt (more info ...)trojan-activity    URL
57869MALWARE-CNC Netfilter rootkit outbound connection attempt (more info ...)trojan-activity    URL
57870MALWARE-CNC Netfilter rootkit outbound connection attempt (more info ...)trojan-activity    URL
57871MALWARE-CNC Netfilter rootkit download attempt (more info ...)trojan-activity    URL
57892SERVER-WEBAPP Oracle GlassFish administration console authentication bypass attempt (more info ...)web-application-attack 2011-1511 47818  
57893MALWARE-CNC Win.Trojan.TrickBot outbound connection attempt (more info ...)trojan-activity    URL
57901MALWARE-CNC Doc.Downloader.Emotet variant outbound connection attempt (more info ...)trojan-activity    URL
57918SERVER-WEBAPP Hewlett Packard Enterprise Intelligent Management Center MibFileServlet directory traversal attempt (more info ...)web-application-attack 2017-12560   
57919MALWARE-CNC Osx.Trojan.Shlayer second stage download attempt (more info ...)trojan-activity    URL
57920MALWARE-CNC Osx.Trojan.Shlayer second stage download attempt (more info ...)trojan-activity    URL
57922MALWARE-CNC Html.Webshell.ASPXSpy inbound connection attempt (more info ...)trojan-activity    URL
57923MALWARE-CNC Html.Webshell.ASPXSpy inbound connection attempt (more info ...)trojan-activity    URL
57924MALWARE-CNC Html.Webshell.ASPXSpy inbound connection attempt (more info ...)trojan-activity    URL
57926MALWARE-CNC Html.Webshell.ASPXSpy inbound connection attempt (more info ...)trojan-activity    URL
57927MALWARE-CNC Html.Webshell.ASPXSpy inbound connection attempt (more info ...)trojan-activity    URL
57928MALWARE-CNC Html.Webshell.ASPXSpy inbound connection attempt (more info ...)trojan-activity    URL
57929MALWARE-CNC Html.Webshell.ASPXSpy inbound connection attempt (more info ...)trojan-activity    URL
57930MALWARE-CNC Html.Webshell.ASPXSpy inbound connection attempt (more info ...)trojan-activity    URL
57934OS-OTHER TRUFFLEHUNTER TALOS-2021-1342 attack attempt (more info ...)attempted-admin    URL
57935OS-OTHER TRUFFLEHUNTER TALOS-2021-1342 attack attempt (more info ...)attempted-admin    URL
57940MALWARE-CNC Win.Trojan.Raccoon outbound communication attempt (more info ...)trojan-activity    URL
57941MALWARE-CNC Win.Trojan.Raccoon binary download attempt (more info ...)trojan-activity    URL
57948MALWARE-CNC Win.Trojan.Trickbot VNC module outbound connection attempt (more info ...)trojan-activity    URL
57949MALWARE-CNC Win.Trojan.Trickbot VNC module outbound connection attempt (more info ...)trojan-activity    URL
57950MALWARE-CNC Win.Trojan.Trickbot VNC module outbound connection attempt (more info ...)trojan-activity    URL
57955MALWARE-CNC Aspx.Webshell.Caterpillar inbound connection attempt (more info ...)trojan-activity    URL
57956MALWARE-CNC Aspx.Webshell.Caterpillar inbound connection attempt (more info ...)trojan-activity    URL
57957MALWARE-CNC Aspx.Webshell.Caterpillar inbound connection attempt (more info ...)trojan-activity    URL
57958MALWARE-CNC Aspx.Webshell.Caterpillar inbound connection attempt (more info ...)trojan-activity    URL
57959MALWARE-CNC Aspx.Webshell.Caterpillar inbound connection attempt (more info ...)trojan-activity    URL
57960MALWARE-CNC Aspx.Webshell.Caterpillar inbound connection attempt (more info ...)trojan-activity    URL
57961MALWARE-CNC Aspx.Webshell.Caterpillar inbound connection attempt (more info ...)trojan-activity    URL
57962MALWARE-CNC Aspx.Webshell.Caterpillar inbound connection attempt (more info ...)trojan-activity    URL
57973MALWARE-CNC Win.Trojan.Uran second stage download attempt (more info ...)trojan-activity    
57974MALWARE-CNC Win.Trojan.Uran variant outbound connection (more info ...)trojan-activity    
57975MALWARE-CNC Win.Trojan.Raccoon variant outbound request detected (more info ...)trojan-activity    URL
57991MALWARE-CNC Win.Trojan.Bandidos outbound connection attempt (more info ...)trojan-activity    URL
57995MALWARE-CNC Jsp.Webshell.JspFileBrowser inbound connection attempt (more info ...)trojan-activity    URL
58000MALWARE-CNC Zloader command and control outbound connection attempt (more info ...)trojan-activity    
58007MALWARE-CNC Win.Trojan.Redline variant outbound request detected (more info ...)trojan-activity    URL
58013SERVER-OTHER TRUFFLEHUNTER TALOS-2021-1355 attack attempt (more info ...)attempted-admin 2021-21903   URL
58015POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1354 attack attempt (more info ...)protocol-command-decode 2021-21902   URL
58016POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1354 attack attempt (more info ...)policy-violation 2021-21902   URL
58029MALWARE-CNC Win.Trojan.Locky outbound connection attempt (more info ...)trojan-activity    URL
58030MALWARE-CNC Win.Miner.Honeygain outbound connection attempt (more info ...)trojan-activity    URL
58031MALWARE-CNC Win.Miner.Honeygain outbound connection attempt (more info ...)trojan-activity    URL
58032MALWARE-CNC Win.Miner.Honeygain outbound connection attempt (more info ...)trojan-activity    URL
58033MALWARE-CNC Win.Miner.Honeygain outbound connection attempt (more info ...)trojan-activity    URL
58044PROTOCOL-OTHER OpenLDAP Search Parsing serialNumberAndIssuerCheck integer overflow attempt (more info ...)denial-of-service 2020-36221   URL
58045PROTOCOL-OTHER OpenLDAP Search Parsing serialNumberAndIssuerCheck integer overflow attempt (more info ...)denial-of-service 2020-36221   URL
58060MALWARE-CNC Win.Downloader.Pingbed outbound connection (more info ...)trojan-activity    URL
58086MALWARE-OTHER Win.Trojan.Aspire variant binary download attempt (more info ...)trojan-activity    URL
58087MALWARE-CNC Win.Trojan.njRAT variant outbound connection (more info ...)trojan-activity    URL
58088MALWARE-CNC Win.Trojan.Aspire variant outbound connection (more info ...)trojan-activity    URL
58104POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1361 attack attempt (more info ...)policy-violation 2021-21913   URL
58105MALWARE-CNC Win.Trojan.HolesWarm outbound connection (more info ...)trojan-activity    URL
58106MALWARE-CNC Win.Trojan.HolesWarm outbound connection (more info ...)trojan-activity    URL
58107MALWARE-CNC Win.Trojan.Turla variant outbound request detected (more info ...)trojan-activity    URL
58116MALWARE-CNC Win.Trojan.Ursu variant outbound connection (more info ...)trojan-activity    URL
58117MALWARE-CNC Win.Trojan.Ursu variant outbound connection (more info ...)trojan-activity    URL
58118MALWARE-CNC Win.Dropper.Johnnie variant outbound connection (more info ...)trojan-activity    URL
58119MALWARE-CNC Win.Dropper.Johnnie variant outbound connection (more info ...)trojan-activity    URL
58153FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1373 attack attempt (more info ...)attempted-user 2021-21943   URL
58154FILE-IMAGE TRUFFLEHUNTER TALOS-2021-1373 attack attempt (more info ...)attempted-user 2021-21943   URL
58155MALWARE-CNC Win.Trojan.Ursnif variant outbound beacon (more info ...)trojan-activity    URL
58160INDICATOR-SHELLCODE Metasploit windows/meterpreter stage transfer attempt (more info ...)shellcode-detect    URL
58216MALWARE-CNC Banking credential stealer credential exfiltration attempt (more info ...)attempted-user    
58238MALWARE-TOOLS Win.Ransomware.BlackMatter variant download attempt (more info ...)trojan-activity    URL
58239SERVER-OTHER OpenSSL TLS large handshake out of bounds read attempt (more info ...)attempted-user    URL
58240SERVER-OTHER OpenSSL TLS large handshake out of bounds read attempt (more info ...)attempted-user    URL
58241SERVER-OTHER OpenSSL TLS large handshake out of bounds read attempt (more info ...)attempted-user    URL
58277MALWARE-CNC Xls.Dropper.SquirrelWaffle download attempt (more info ...)trojan-activity    URL
58278MALWARE-CNC Xls.Dropper.SquirrelWaffle download attempt (more info ...)trojan-activity    URL
58280MALWARE-CNC Doc.Dropper.SquirrelWaffle download attempt (more info ...)trojan-activity    URL
58281MALWARE-CNC Win.Dropper.SquirrelWaffle C2 HTTP response (more info ...)trojan-activity    URL
58299POLICY-OTHER Alibaba Nacos potential authentication bypass attempt (more info ...)policy-violation 2021-29441   URL
58300POLICY-OTHER Alibaba Nacos potential authentication bypass attempt (more info ...)policy-violation 2021-29441   URL
58301POLICY-OTHER Alibaba Nacos potential authentication bypass attempt (more info ...)policy-violation 2021-29441   URL
58302SERVER-WEBAPP GE MDS PulseNET IntegrationXMLProcessorServlet Write XML external entity injection attempt (more info ...)web-application-attack 2018-10613   
58307SERVER-WEBAPP Trend Micro Control Manager ProductTree XML external entity injection attempt (more info ...)web-application-attack    
58354SERVER-WEBAPP MailEnable Enterprise Premium unauthenticated XML external entity injection attempt (more info ...)web-application-attack 2019-12924   
58356MALWARE-CNC Win.Trojan.DCRAT variant outbound connection (more info ...)trojan-activity    URL
58357MALWARE-CNC Win.Trojan.DCRAT variant outbound connection (more info ...)trojan-activity    URL
58358MALWARE-CNC Win.Trojan.Quasar variant outbound connection (more info ...)trojan-activity    URL
58359MALWARE-CNC Win.Trojan.DCRAT variant outbound connection (more info ...)trojan-activity    URL
58363SERVER-WEBAPP Online Learning Management System 1.0 RCE attempt (more info ...)attempted-user    
58364SERVER-WEBAPP Online Learning Management System 1.0 RCE attempt (more info ...)attempted-user    
58374SERVER-WEBAPP GE MDS PulseNET MagnumEmulator Servlet XML external entity injection attempt (more info ...)web-application-attack 2018-10613   
58395SERVER-WEBAPP GE MDS PulseNET XmlAdapterServlet XML external entity injection attempt (more info ...)web-application-attack 2018-10613   
58402SERVER-WEBAPP Hewlett Packard Enterprise Network Automation authentication bypass attempt (more info ...)web-application-attack 2017-5812   
58429MALWARE-CNC Win.Trojan.MirrorBlast outbound connection (more info ...)trojan-activity    URL
58430MALWARE-CNC Win.Trojan.MirrorBlast outbound connection (more info ...)trojan-activity    URL
58432MALWARE-CNC Win.Trojan.MirrorBlast outbound connection (more info ...)trojan-activity    URL
58433MALWARE-CNC Win.Trojan.MirrorBlast outbound connection (more info ...)trojan-activity    URL
58448MALWARE-CNC Win.Trojan.STRRAT variant outbound request detected (more info ...)trojan-activity    URL
58459POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1401 attack attempt (more info ...)policy-violation 2021-40390   URL
58460POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1401 attack attempt (more info ...)policy-violation 2021-40390   URL
58461POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1392 attack attempt (more info ...)policy-violation 2021-21964   URL
58462POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1392 attack attempt (more info ...)policy-violation 2021-21965   URL
58463POLICY-OTHER TRUFFLEHUNTER TALOS-2021-1392 attack attempt (more info ...)policy-violation 2021-21965   URL
58474SERVER-WEBAPP Trend Micro Control Manager TreeUserControl_process_tree_event XML external entity injection attempt (more info ...)web-application-attack    
58477POLICY-OTHER Quest Foglight Evolve hardcoded credentials login attempt (more info ...)policy-violation 2020-8868   
58495MALWARE-CNC Win.Ransomware.Magniber variant beacon (more info ...)trojan-activity    URL
58497MALWARE-CNC Win.Trojan.Kimsuky outbound connection (more info ...)trojan-activity    URL
58498MALWARE-CNC Win.Trojan.Kimsuky outbound connection (more info ...)trojan-activity    URL
58526MALWARE-CNC Win.Trojan.STRRAT variant outbound connection (more info ...)trojan-activity    URL
58527MALWARE-CNC Win.Trojan.STRRAT variant outbound connection (more info ...)trojan-activity    URL
58528SERVER-OTHER OpenLDAP IssuerAndThisUpdateCheck integer underflow attempt (more info ...)attempted-user 2020-36228   
58534FILE-OTHER TRUFFLEHUNTER TALOS-2021-1405 attack attempt (more info ...)attempted-user 2021-40394   URL
58535FILE-OTHER TRUFFLEHUNTER TALOS-2021-1405 attack attempt (more info ...)attempted-user 2021-40394   URL
58536FILE-OTHER TRUFFLEHUNTER TALOS-2021-1404 attack attempt (more info ...)attempted-user 2021-40393   URL
58537FILE-OTHER TRUFFLEHUNTER TALOS-2021-1404 attack attempt (more info ...)attempted-user 2021-40393   URL
58545SERVER-WEBAPP Trend Micro Control Manager ProductTree_LeftWindow XML external entity injection attempt (more info ...)web-application-attack    
58558SERVER-WEBAPP EMC VMAX3 VASA Provider virtual appliance UploadConfigurator arbitrary JSP file upload attempt (more info ...)attempted-admin 2017-4997   
58564MALWARE-CNC Win.Trojan.SquirrelWaffle beacon attempt (more info ...)trojan-activity    URL
58570FILE-OTHER MacOS TTC bypass vulnerability exploit upload attempt (more info ...)attempted-admin 2021-30713   
58582POLICY-OTHER Dahua Console NetKeyboard potential authentication bypass attempt (more info ...)policy-violation 2021-33044   
58583POLICY-OTHER Dahua Console NetKeyboard potential authentication bypass attempt (more info ...)policy-violation 2021-33044   
58584POLICY-OTHER Dahua Console Loopback potential authentication bypass attempt (more info ...)policy-violation 2021-33045   
58585POLICY-OTHER Dahua Console Loopback potential authentication bypass attempt (more info ...)policy-violation 2021-33045   
58590SERVER-OTHER OpenLDAP Slapd CancelRequest infinite loop denial of service attempt (more info ...)attempted-dos 2020-36227   URL
58591SERVER-OTHER OpenLDAP Slapd CancelRequest infinite loop denial of service attempt (more info ...)attempted-dos 2020-36227   URL
58597FILE-OTHER TRUFFLEHUNTER TALOS-2021-1413 attack attempt (more info ...)attempted-user 2021-40400   URL
58598FILE-OTHER TRUFFLEHUNTER TALOS-2021-1413 attack attempt (more info ...)attempted-user 2021-40400   URL
58601SERVER-WEBAPP Joomla mod_breadcrumbs Title Store cross site scripting attempt (more info ...)attempted-user 2021-23124   
58602SERVER-WEBAPP Joomla mod_breadcrumbs Title Store cross site scripting attempt (more info ...)attempted-user 2021-23124   
58609OS-OTHER Apple macOS kernel memory leak attempt (more info ...)attempted-admin 2020-27950   
58610OS-OTHER Apple macOS kernel memory leak attempt (more info ...)attempted-admin 2020-27950   
58623SERVER-OTHER OpenLDAP slap_parse_user denial of service attempt (more info ...)attempted-dos 2020-36222   
58624SERVER-OTHER OpenLDAP slap_parse_user denial of service attempt (more info ...)attempted-dos 2020-36222   
58625SERVER-OTHER OpenLDAP slap_parse_user denial of service attempt (more info ...)attempted-dos 2020-36222   
58626SERVER-OTHER OpenLDAP slap_parse_user denial of service attempt (more info ...)attempted-dos 2020-36222   
58627MALWARE-CNC TRUFFLEHUNTER SFVRT-1045 attack attempt (more info ...)trojan-activity    
58628MALWARE-CNC TRUFFLEHUNTER SFVRT-1045 attack attempt (more info ...)trojan-activity    
58629MALWARE-CNC TRUFFLEHUNTER SFVRT-1045 attack attempt (more info ...)trojan-activity    
58630FILE-OTHER VMware Fusion privilege escalation attempt (more info ...)attempted-admin 2020-3950   
58631FILE-OTHER VMware Fusion privilege escalation attempt (more info ...)attempted-admin 2020-3950   
58650MALWARE-CNC Win.Backdoor.Magnat outbound connection (more info ...)trojan-activity    URL
58651MALWARE-CNC Win.Trojan.MagnatExtension outbound connection (more info ...)trojan-activity    URL
58656SERVER-OTHER OpenLDAP slap_parse_user denial of service attempt (more info ...)attempted-dos 2020-36222   
58657SERVER-OTHER OpenLDAP slap_parse_user denial of service attempt (more info ...)attempted-dos 2020-36222   
58658MALWARE-CNC Win.Trojan.DarkSide outbound connection attempt (more info ...)trojan-activity    URL
58659FILE-OTHER TRUFFLEHUNTER TALOS-2021-1417 attack attempt (more info ...)attempted-recon 2021-40403   URL
58660FILE-OTHER TRUFFLEHUNTER TALOS-2021-1417 attack attempt (more info ...)attempted-recon 2021-40403   URL
58661FILE-OTHER TRUFFLEHUNTER TALOS-2021-1417 attack attempt (more info ...)attempted-recon 2021-40403   URL
58662FILE-OTHER TRUFFLEHUNTER TALOS-2021-1417 attack attempt (more info ...)attempted-recon 2021-40403   URL
58663FILE-OTHER TRUFFLEHUNTER TALOS-2021-1417 attack attempt (more info ...)attempted-recon 2021-40403   URL
58664FILE-OTHER TRUFFLEHUNTER TALOS-2021-1417 attack attempt (more info ...)attempted-recon 2021-40403   URL
58665FILE-OTHER TRUFFLEHUNTER TALOS-2021-1415 attack attempt (more info ...)attempted-user 2021-40401   URL
58666FILE-OTHER TRUFFLEHUNTER TALOS-2021-1415 attack attempt (more info ...)attempted-user 2021-40401   URL
58667FILE-OTHER TRUFFLEHUNTER TALOS-2021-1415 attack attempt (more info ...)attempted-user 2021-40401   URL
58668FILE-OTHER TRUFFLEHUNTER TALOS-2021-1415 attack attempt (more info ...)attempted-user 2021-40401   URL
58669SERVER-WEBAPP Trend Micro Control Manager ProductTree_TreeManagement1 XML external entity injection attempt (more info ...)web-application-attack    
58698SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1423 attack attempt (more info ...)attempted-dos 2021-40406   URL
58699SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1423 attack attempt (more info ...)attempted-dos 2021-40406   URL
58710SERVER-WEBAPP GE MDS PulseNET Servlet XML external entity injection attempt (more info ...)web-application-attack 2018-10613   
58713MALWARE-CNC Asp.Webshell.NewCon2 outbound connection attempt (more info ...)trojan-activity    URL
58719SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1421 attack attempt (more info ...)attempted-dos 2021-40423   URL
58720SERVER-WEBAPP TRUFFLEHUNTER TALOS-2021-1421 attack attempt (more info ...)attempted-dos 2021-40423   URL
58766MALWARE-CNC Rat.Trojan.Nanocore variant cnc connection (more info ...)trojan-activity    URL
58767MALWARE-CNC Rat.Trojan.Nanocore variant cnc connection (more info ...)trojan-activity    URL
58768MALWARE-CNC Rat.Trojan.Nanocore variant cnc connection (more info ...)trojan-activity    URL
58769MALWARE-CNC Rat.Trojan.Nanocore variant cnc connection (more info ...)trojan-activity    URL
58770MALWARE-CNC Rat.Trojan.Nanocore variant cnc connection (more info ...)trojan-activity    URL
58771MALWARE-CNC Rat.Trojan.Netwire variant cnc connection (more info ...)trojan-activity    URL
58772MALWARE-CNC Rat.Trojan.Netwire variant cnc connection (more info ...)trojan-activity    URL
58773MALWARE-CNC Rat.Trojan.AsyncRAT variant cnc connection (more info ...)trojan-activity    URL
58777MALWARE-CNC Win.Trojan.FormBook outbound connection attempt (more info ...)trojan-activity    URL
58778MALWARE-CNC Win.Infostealer.RedLine outbound connection (more info ...)trojan-activity    URL
58779MALWARE-CNC Win.Infostealer.RedLine outbound connection (more info ...)trojan-activity    URL
58780MALWARE-CNC Win.Infostealer.RedLine outbound connection (more info ...)trojan-activity    URL
58781MALWARE-CNC Win.Infostealer.RedLine outbound connection (more info ...)trojan-activity    URL
58796MALWARE-CNC Win.Backdoor.FatalRat variant beaconing attempt (more info ...)trojan-activity    URL
58835MALWARE-CNC Win.Trojan.IcedId outbound connection (more info ...)trojan-activity    URL
58840SERVER-WEBAPP Trend Micro Control Manager AdHocQuery_Result XML external entity injection attempt (more info ...)web-application-attack    
58846PROTOCOL-OTHER libcurl mqtt use after free attempt (more info ...)attempted-user 2021-22945   URL
58852MALWARE-CNC Win.Trojan.BazarLoader outbound connection (more info ...)trojan-activity    URL
58865MALWARE-CNC Win.Trojan.Beacon outbound connection (more info ...)trojan-activity    URL
58903MALWARE-CNC Win.Trojan.Qakbot variant beaconing attempt (more info ...)trojan-activity    URL
58904MALWARE-CNC Win.Trojan.Qakbot variant beaconing attempt (more info ...)trojan-activity    URL
58906PROTOCOL-SCADA Modbus Write File Record overly large sub request record length attempt (more info ...)attempted-dos 2022-20685   URL
58907PROTOCOL-SCADA Modbus Write File Record overly large sub request record length attempt (more info ...)attempted-dos 2022-20685   URL
58909POLICY-OTHER Multiple Products Golang pprof debug access attempt (more info ...)policy-violation 2022-20648   URL
58927POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1447 attack attempt (more info ...)policy-violation 2022-21134   URL
58937MALWARE-CNC Ps1.Malware.MuddyWater outbound cnc connection (more info ...)trojan-activity    URL
58938MALWARE-CNC Ps1.Malware.MuddyWater outbound cnc connection (more info ...)trojan-activity    
58941FILE-OTHER PEAR Archive TAR symbolic link file overwrite attempt (more info ...)attempted-user 2020-36193   
58942FILE-OTHER PEAR Archive TAR symbolic link file overwrite attempt (more info ...)attempted-user 2020-36193   
58943MALWARE-CNC Win.Malware.Emotet cnc outbound connection attempt (more info ...)trojan-activity    URL
58944MALWARE-CNC Win.Ransomware.Conti variant network share readme file detected (more info ...)trojan-activity    URL
58945FILE-OTHER PEAR Archive Tar code deserialization attempt (more info ...)attempted-user 2020-28949   URL
58946FILE-OTHER PEAR Archive Tar code deserialization attempt (more info ...)attempted-user 2020-28949   URL
58949MALWARE-CNC Win.Trojan.Qakbot variant outbound connection (more info ...)trojan-activity    URL
58950SERVER-WEBAPP OneDev pre-authentication token leak attempt (more info ...)attempted-user 2021-21246   
58957MALWARE-CNC Win.RAT.AridViper outbound connection (more info ...)trojan-activity    URL
58958MALWARE-CNC Win.RAT.AridViper outbound connection (more info ...)trojan-activity    URL
58990MALWARE-CNC Win.Trojan.Saintbot variant outbound connection (more info ...)trojan-activity    
58992MALWARE-CNC User-Agent known malicious user-agent string - Mirai (more info ...)trojan-activity    URL
59012POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1461 attack attempt (more info ...)policy-violation 2022-21184   URL
59014FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2022-1452 attack attempt (more info ...)attempted-user 2022-21147   URL
59015FILE-EXECUTABLE TRUFFLEHUNTER TALOS-2022-1452 attack attempt (more info ...)attempted-user 2022-21147   URL
59034SERVER-WEBAPP HiSilicon Video Encoders unauthenticated command injection attempt (more info ...)web-application-attack 2020-24217   
59061POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1459 attack attempt (more info ...)policy-violation 2022-22144   URL
59062SERVER-WEBAPP Trend Micro InterScan Messaging Security Suite DetailReportAction directory traversal attempt (more info ...)web-application-attack    
59063SERVER-WEBAPP Trend Micro InterScan Messaging Security Suite DetailReportAction directory traversal attempt (more info ...)web-application-attack    
59064SERVER-WEBAPP Trend Micro InterScan Messaging Security Suite DetailReportAction directory traversal attempt (more info ...)web-application-attack    
59071SERVER-WEBAPP Trend Micro SafeSync for Enterprise license command injection attempt (more info ...)web-application-attack    
59083SERVER-WEBAPP D-Link router httpd server directory traversal attempt (more info ...)web-application-attack 2018-10822   
59089SERVER-WEBAPP Trend Micro SafeSync for Enterprise storage API command injection attempt (more info ...)web-application-attack    
59110MALWARE-CNC Win.Trojan.Patchwork RAT variant outbound connection (more info ...)trojan-activity    URL
59111MALWARE-CNC Win.Trojan.Patchwork RAT variant outbound connection (more info ...)trojan-activity    URL
59112MALWARE-CNC Win.Trojan.Patchwork RAT variant outbound connection (more info ...)trojan-activity    URL
59113MALWARE-CNC Win.Trojan.Patchwork RAT variant outbound connection (more info ...)trojan-activity    URL
59116PROTOCOL-OTHER Git LFS clone arbitrary code execution attempt (more info ...)attempted-user 2021-21300   URL
59117PROTOCOL-OTHER Git LFS object request detected (more info ...)protocol-command-decode 2021-21300   URL
59130MALWARE-TOOLS Bombardier http DoS tool (more info ...)attempted-dos    URL
59133MALWARE-CNC Win.Trojan.AgentTesla outbound connection attempt (more info ...)trojan-activity    URL
59145MALWARE-OTHER Win.Trojan.Redline variant download attempt (more info ...)trojan-activity    URL
59149MALWARE-CNC Win.Trojan.Redline variant outbound request detected (more info ...)trojan-activity    URL
59150MALWARE-CNC Win.Trojan.Redline variant outbound request detected (more info ...)trojan-activity    URL
59151SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1468 attack attempt (more info ...)web-application-attack 2022-21809   URL
59152POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1474 attack attempt (more info ...)policy-violation 2022-26020   URL
59153POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1472 attack attempt (more info ...)policy-violation 2022-25932   URL
59158MALWARE-OTHER Win.Ransomware.HermeticRansom binary download attempt (more info ...)trojan-activity    URL
59159MALWARE-OTHER Win.Ransomware.HermeticRansom binary download attempt (more info ...)trojan-activity    URL
59160MALWARE-CNC Win.Trojan.Redline variant outbound request detected (more info ...)trojan-activity    URL
59161MALWARE-OTHER Win.Ransomware.WhiteBlackCrypt variant binary download attempt (more info ...)trojan-activity    URL
59162MALWARE-OTHER Win.Ransomware.WhiteBlackCrypt variant binary download attempt (more info ...)trojan-activity    URL
59165MALWARE-CNC Win.Malware.SunSeed outbound cnc connection attempt (more info ...)trojan-activity    URL
59166MALWARE-CNC Xls.Downloader.SunSeed payload download attempt (more info ...)trojan-activity    URL
59167MALWARE-CNC Xls.Downloader.SunSeed payload download attempt (more info ...)trojan-activity    URL
59168MALWARE-CNC Win.Malware.SunSeed outbound cnc connection attempt (more info ...)trojan-activity    URL
59169MALWARE-CNC Win.Malware.SunSeed payload download attempt attempt (more info ...)trojan-activity    URL
59170MALWARE-CNC Win.Malware.SunSeed payload download attempt attempt (more info ...)trojan-activity    URL
59173MALWARE-CNC Xls.Downloader.SunSeed payload download attempt (more info ...)trojan-activity    URL
59182MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity    URL
59183MALWARE-OTHER Win.Trojan.WhisperGate download attempt (more info ...)trojan-activity    URL
59202MALWARE-CNC Win.Infostealer.Vidar outbound connection attempt (more info ...)trojan-activity    URL
59203MALWARE-CNC Win.Infostealer.Vidar outbound connection attempt (more info ...)trojan-activity    URL
59208MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
59209MALWARE-CNC Win.Trojan.Ursnif variant outbound connection (more info ...)trojan-activity    URL
59223MALWARE-CNC Win.Trojan.TransparentTribe outbound connection attempt (more info ...)trojan-activity    URL
59226MALWARE-CNC Win.Trojan.MuddyWater outbound connection attempt (more info ...)trojan-activity    URL
59227MALWARE-CNC Win.Trojan.MuddyWater download attempt (more info ...)trojan-activity    URL
59228MALWARE-CNC Win.Trojan.MuddyWater download attempt (more info ...)trojan-activity    URL
59229MALWARE-CNC Win.Trojan.MuddyWater outbound connection attempt (more info ...)trojan-activity    URL
59230MALWARE-CNC Win.Trojan.MuddyWater outbound connection attempt (more info ...)trojan-activity    URL
59231SERVER-SAMBA Samba SMB SET_INFO heap overwrite attempt (more info ...)attempted-user 2021-44142   
59243MALWARE-CNC Win.Trojan.Raccoon variant RC4 encrypted outbound request attempt (more info ...)trojan-activity    URL
59252MALWARE-CNC Win.Infostealer.PhoenixStealer outbound connection (more info ...)trojan-activity    URL
59253MALWARE-CNC Win.Infostealer.PhoenixStealer outbound connection (more info ...)trojan-activity    URL
59275POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1492 attack attempt (more info ...)policy-violation 2022-26082   URL
59276POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1492 attack attempt (more info ...)policy-violation 2022-26303   URL
59277POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1490 attack attempt (more info ...)policy-violation 2022-26082   URL
59278POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1490 attack attempt (more info ...)policy-violation 2022-27169   URL
59279POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1490 attack attempt (more info ...)policy-violation 2022-26077   URL
59282SERVER-WEBAPP Trend Micro Smart Protection Server wcs_bwlists_handler command injection attempt (more info ...)web-application-attack    
59283SERVER-WEBAPP Trend Micro Smart Protection Server wcs_bwlists_handler command injection attempt (more info ...)web-application-attack    
59284SERVER-WEBAPP Trend Micro Smart Protection Server wcs_bwlists_handler command injection attempt (more info ...)web-application-attack    
59285SERVER-WEBAPP Trend Micro Smart Protection Server wcs_bwlists_handler command injection attempt (more info ...)web-application-attack    
59286SERVER-WEBAPP Trend Micro Control Manager Widget modDLPTemplateMatch_drildown directory traversal attempt (more info ...)web-application-attack    
59300FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1487 attack attempt (more info ...)attempted-user 2022-26061   URL
59301FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1487 attack attempt (more info ...)attempted-user 2022-26061   URL
59309SERVER-WEBAPP Symantec Web Gateway cross site scripting attempt (more info ...)attempted-user 2014-1652   
59310SERVER-WEBAPP Symantec Web Gateway cross site scripting attempt (more info ...)attempted-user 2014-1652   
59322SERVER-WEBAPP Advantech WISE-PaaS RMM UpgradeMgmt upload_ota arbitrary JSP file upload attempt (more info ...)attempted-admin 2019-13551   
59332SERVER-WEBAPP Car Rental Management System local file inclusion attempt (more info ...)web-application-attack 2020-29227   URL
59335SERVER-WEBAPP Micro Focus GroupWise Admin Console cross site scripting attempt (more info ...)attempted-user 2016-5760   
59336SERVER-WEBAPP Micro Focus GroupWise Admin Console cross site scripting attempt (more info ...)web-application-attack 2016-5760   
59337SERVER-WEBAPP Micro Focus GroupWise Admin Console cross site scripting attempt (more info ...)attempted-user 2016-5760   
59338SERVER-WEBAPP Micro Focus GroupWise Admin Console cross site scripting attempt (more info ...)attempted-user 2016-5760   
59345SERVER-WEBAPP Oracle E-Business Suite Common Applications Calendar cross site scripting attempt (more info ...)attempted-user 2021-2114   
59346SERVER-WEBAPP Oracle E-Business Suite Common Applications Calendar cross site scripting attempt (more info ...)attempted-user 2021-2114   
59365SERVER-WEBAPP Twitter TwitterServer HistogramQueryHandler cross site scripting attempt (more info ...)attempted-user 2020-35774   URL
59366SERVER-WEBAPP SolarWinds Orion IPAM cross site scripting attempt (more info ...)attempted-user 2012-4939   
59367SERVER-WEBAPP SolarWinds Orion IPAM cross site scripting attempt (more info ...)attempted-user 2012-4939   
59406POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1502 attack attempt (more info ...)policy-violation 2022-27660   URL
59407POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1504 attack attempt (more info ...)policy-violation 2022-27630   URL
59408POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1503 attack attempt (more info ...)policy-violation 2022-27633   URL
59409POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1505 attack attempt (more info ...)policy-violation 2022-27185   URL
59410POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1507 attack attempt (more info ...)policy-violation 2022-26346   URL
59411POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1506 attack attempt (more info ...)policy-violation 2022-27178   URL
59412SERVER-WEBAPP Jenkins Gitlab Hook Plugin cross site scripting attempt (more info ...)attempted-user 2020-2096   
59413SERVER-WEBAPP Jenkins Gitlab Hook Plugin cross site scripting attempt (more info ...)attempted-user 2020-2096   
59414POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1495 attack attempt (more info ...)policy-violation 2022-26510   URL
59420MALWARE-CNC Win.Trojan.GraphSteel outbound connection (more info ...)trojan-activity    URL
59421MALWARE-CNC Win.Infostealer.MarsStealer outbound connection (more info ...)trojan-activity    URL
59423FILE-OTHER LAquis SCADA LGX report file parsing out-of-bounds write attempt (more info ...)attempted-user 2018-18986   
59424FILE-OTHER LAquis SCADA LGX report arbitrary file write attempt (more info ...)attempted-user 2018-18988   
59425FILE-OTHER LAquis SCADA LGX report arbitrary file write attempt (more info ...)attempted-user 2018-18988   
59426SERVER-WEBAPP Red Hat JBoss BPM Suite Tasks List cross site scripting attempt (more info ...)web-application-attack 2017-2674   
59427SERVER-WEBAPP Red Hat JBoss BPM Suite Tasks List cross site scripting attempt (more info ...)web-application-attack 2017-2674   
59428FILE-OTHER OMRON CX-One CX-Protocol CSCU type confusion attempt (more info ...)attempted-user 2018-19027   
59429FILE-OTHER OMRON CX-One CX-Protocol CSCU type confusion attempt (more info ...)attempted-user 2018-19027   
59447PROTOCOL-SCADA WeCon LeviStudioU HFT font buffer overflow attempt (more info ...)attempted-admin 2020-16243   
59458SERVER-OTHER strongSwan gmp plugin denial of service attempt (more info ...)attempted-dos 2017-11185   
59459SERVER-OTHER strongSwan x509 plugin denial of service attempt (more info ...)attempted-dos 2017-9023   
59460FILE-OTHER GNU Libextractor ZIP file comment out-of-bounds read attempt (more info ...)attempted-dos 2018-16430   
59461FILE-OTHER GNU Libextractor ZIP file comment out-of-bounds read attempt (more info ...)attempted-dos 2018-16430   
59462PROTOCOL-SCADA Rockwell Automation RSLinx Classic buffer overflow attempt (more info ...)attempted-user 2019-6553   
59464SERVER-OTHER Squid Proxy ESI response processing denial of service attempt (more info ...)attempted-dos 2016-4555   
59469FILE-IMAGE JasPer jp2_decode out of bounds read attempt (more info ...)attempted-user 2017-9782   
59470FILE-IMAGE JasPer jp2_decode out of bounds read attempt (more info ...)attempted-user 2017-9782   
59471SERVER-OTHER Qognify Ocularis Event Coordinator insecure deserialization attempt (more info ...)attempted-admin 2020-27868   URL
59484PROTOCOL-SCADA Schneider Electric IGSS update service arbitrary file read attempt (more info ...)attempted-admin 2020-7479   URL
59487FILE-IMAGE LibTIFF tiffcrop integer overflow attempt (more info ...)attempted-user 2016-9537   
59488FILE-IMAGE LibTIFF tiffcrop integer overflow attempt (more info ...)attempted-user 2016-9537   
59494SERVER-OTHER HPE Intelligent Management Center dbman decryptMsgAes buffer overflow attempt (more info ...)attempted-user 2018-7114   
59495SERVER-WEBAPP pfSense ACME Package cross site scripting attempt (more info ...)web-application-attack 2019-12347   URL
59501MALWARE-CNC Win.Infostealer.ZingoStealer outbound connection (more info ...)trojan-activity    URL
59506FILE-OTHER Symantec Norton Antivirus ccScanw.dll Unpack ShortLZ memory corruption attempt (more info ...)attempted-user 2016-2207   URL
59537BROWSER-OTHER Electronic Arts Origin Client template injection attempt (more info ...)attempted-user 2019-11354   
59542SERVER-OTHER Redis HyperLogLog hllSparseToDense heap buffer overflow attempt (more info ...)attempted-user 2019-10192   
59543FILE-OTHER Red Lion Crimson CD3 file port list type confusion attempt (more info ...)attempted-user 2019-10996   
59544FILE-OTHER Red Lion Crimson CD3 file port list type confusion attempt (more info ...)attempted-user 2019-10996   
59545FILE-OTHER HP LoadRunner Controller Scenario file stack buffer overflow attempt (more info ...)attempted-user 2015-5426   
59546FILE-OTHER HP LoadRunner Controller Scenario file stack buffer overflow attempt (more info ...)attempted-user 2015-5426   
59547SERVER-OTHER REDIS HyperLogLog hllCount stack buffer overflow attempt (more info ...)attempted-user 2019-10193   
59548FILE-IMAGE ImageMagick GIF comment off-by-one buffer overflow attempt (more info ...)attempted-user 2013-4298   
59549FILE-IMAGE ImageMagick GIF comment off-by-one buffer overflow attempt (more info ...)attempted-user 2013-4298   
59550SERVER-OTHER Quagga BGP daemon BGP capabilities parsing denial of service attempt (more info ...)attempted-dos 2018-5381   
59551SERVER-OTHER Quagga BGP Daemon bgp_update_receive double free attempt (more info ...)attempted-user 2018-5379   
59556PROTOCOL-SCADA RedLion cd3 untrusted pointer dereference attempt (more info ...)attempted-user 2019-10984   
59557SERVER-WEBAPP Oracle WebLogic Server insecure deserialization exploit attempt (more info ...)web-application-attack 2020-2798   URL
59558SERVER-WEBAPP Oracle WebLogic Server insecure deserialization exploit attempt (more info ...)web-application-attack 2020-2963   URL
59559SERVER-OTHER NTPsec ntp_control null pointer dereference attempt (more info ...)attempted-user 2019-6445   
59580FILE-OTHER Delta Industrial Automation CNCSoft ScreenEditor dpb PanelName stack buffer overflow attempt (more info ...)attempted-user 2019-10947   
59581FILE-OTHER Delta Industrial Automation CNCSoft ScreenEditor dpb PanelName stack buffer overflow attempt (more info ...)attempted-user 2019-10947   
59582FILE-OTHER Delta Industrial Automation CNCSoft ScreenEditor dpb PanelName stack buffer overflow attempt (more info ...)attempted-user 2019-10947   
59583FILE-OTHER Delta Industrial Automation CNCSoft ScreenEditor dpb PanelName stack buffer overflow attempt (more info ...)attempted-user 2019-10947   
59586SERVER-OTHER TightVNC viewer rfbServerCutText handler integer overflow attempt (more info ...)attempted-user 2019-15678   
59588POLICY-OTHER Omron device management request detected (more info ...)policy-violation    URL
59589POLICY-OTHER Omron EtherCAT request detected (more info ...)policy-violation    URL
59590POLICY-OTHER Omron system information request detected (more info ...)policy-violation    URL
59591POLICY-OTHER Omron device CPU state change request detected (more info ...)policy-violation    URL
59592POLICY-OTHER Omron device CPU clear memory request detected (more info ...)policy-violation    URL
59593POLICY-OTHER Omron device CPU reset request detected (more info ...)policy-violation    URL
59594POLICY-OTHER Omron FINS get info request detected (more info ...)policy-violation    URL
59595POLICY-OTHER OPCUA ReadRequest detected (more info ...)policy-violation    URL
59596POLICY-OTHER OPCUA WriteRequest detected (more info ...)policy-violation    URL
59598POLICY-OTHER OPCUA GetEndpointsRequest detected (more info ...)policy-violation    URL
59606SERVER-WEBAPP Smart Software Solutions CODESYS ControlService stack buffer overflow attempt (more info ...)attempted-user 2011-5007   
59607MALWARE-CNC Doc.Dropper.Lazarus variant outbound connection (more info ...)trojan-activity    URL
59611SERVER-OTHER Free Software Foundation GnuTLS record application integer overflow attempt (more info ...)attempted-admin 2012-1573   
59612SERVER-OTHER Squid Proxy ESI response denial of service attempt (more info ...)denial-of-service 2018-1000024   URL
59619SERVER-OTHER Facebook Fizz Plaintext Record Layer integer overflow denial of service attempt (more info ...)attempted-dos 2019-3560   
59620PROTOCOL-VOIP Digium Asterisk chan_skinny SCCP session denial of service attempt (more info ...)attempted-dos 2017-17090   URL
59621PROTOCOL-VOIP Digium Asterisk chan_skinny SCCP session denial of service attempt (more info ...)attempted-dos 2017-17090   URL
59622MALWARE-CNC Win.Downloader.PlugX outbound connection (more info ...)trojan-activity    URL
59623MALWARE-CNC Win.Downloader.PlugX outbound connection (more info ...)trojan-activity    URL
59624MALWARE-CNC Win.Downloader.PlugX outbound connection (more info ...)trojan-activity    URL
59625MALWARE-CNC Win.Downloader.PlugX download attempt (more info ...)trojan-activity    URL
59628SERVER-OTHER IBM Tivoli Storage Manager Fastback remote code execution attempt (more info ...)attempted-admin 2015-1953   URL
59629SERVER-OTHER TurboVNC fence message stack based buffer overflow attempt (more info ...)attempted-user 2019-15683   URL
59630PROTOCOL-TELNET CHIYU IoT device authentication bypass attempt (more info ...)attempted-user 2021-31251   URL
59631SERVER-OTHER LibVNC LibVNCClient heap buffer overflow attempt (more info ...)attempted-user 2018-20020   
59634SERVER-OTHER Quagga BGP daemon BGP UPDATE message out-of-bounds read attempt (more info ...)attempted-dos 2018-5378   
59635SERVER-OTHER NLNet Labs Unbound NOTIFY denial of service attempt (more info ...)attempted-dos 2019-16866   
59646SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (more info ...)attempted-dos 2015-1789   URL
59657POLICY-OTHER Red Hat 389 Directory Server Server-Side-Sort denial of service attempt (more info ...)attempted-dos 2018-10935   
59672SERVER-OTHER TightVNC vncviewer HandleCoRREBPP buffer overflow attempt (more info ...)attempted-user 2019-8287   
59673SERVER-OTHER EMC Data Protection Advisor default credential attempt (more info ...)attempted-admin 2017-8013   
59674SERVER-OTHER EMC Data Protection Advisor default credential attempt (more info ...)attempted-admin 2017-8013   
59675SERVER-OTHER EMC Data Protection Advisor default credential attempt (more info ...)attempted-admin 2017-8013   
59676SERVER-OTHER HP Enterprise Intelligent Management Center dbman stack-based buffer attempt (more info ...)attempted-admin 2017-8956   URL
59677SERVER-OTHER Delta Electronics Delta Industrial Automation COMMGR 1.08 stack buffer overflow attempt (more info ...)attempted-user 2018-10594   
59682SERVER-OTHER Red Hat Directory Server vslapd denial of service attempt (more info ...)attempted-dos 2018-14624   
59683SERVER-OTHER Red Hat Directory Server vslapd denial of service attempt (more info ...)attempted-dos 2018-14624   
59684SERVER-OTHER Red Hat Directory Server vslapd denial of service attempt (more info ...)attempted-dos 2018-14624   
59685SERVER-OTHER Red Hat Directory Server vslapd denial of service attempt (more info ...)attempted-dos 2018-14624   
59686SERVER-OTHER Red Hat Directory Server vslapd denial of service attempt (more info ...)attempted-dos 2018-14624   
59689SERVER-OTHER Advantech Webaccess BwPAlarm.dll buffer overflow attempt (more info ...)attempted-user 2018-18999   
59691SERVER-OTHER Quagga BGP Daemon bgp_update_receive double free attempt (more info ...)attempted-user 2018-5379   
59697FILE-IMAGE Apple CUPS gif_read_lzw heap buffer overflow attempt (more info ...)attempted-user 2011-3170   
59698FILE-IMAGE Apple CUPS gif_read_lzw heap buffer overflow attempt (more info ...)attempted-user 2011-3170   
59700POLICY-OTHER Golang get remote command execution attempt (more info ...)attempted-user 2018-16873   URL
59701POLICY-OTHER Golang get remote command execution attempt (more info ...)attempted-user 2018-16873   URL
59702POLICY-OTHER Golang get remote command execution attempt (more info ...)attempted-user 2018-16873   URL
59703POLICY-OTHER Golang get remote command execution attempt (more info ...)attempted-user 2018-16873   URL
59704POLICY-OTHER Golang get remote command execution attempt (more info ...)attempted-user 2018-16873   URL
59705SERVER-WEBAPP vBulletin cross-site scripting attempt (more info ...)web-application-attack    URL
59706SERVER-WEBAPP vBulletin cross-site scripting attempt (more info ...)web-application-attack    URL
59714FILE-IMAGE Directshow GIF logical height overflow attempt (more info ...)attempted-user 2013-3174   
59715FILE-IMAGE Directshow GIF logical height overflow attempt (more info ...)attempted-user 2013-3174   
59716FILE-IMAGE Directshow GIF logical width overflow attempt (more info ...)attempted-user 2013-3174   
59717FILE-IMAGE Directshow GIF logical width overflow attempt (more info ...)attempted-user 2013-3174   
59732POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1513 attack attempt (more info ...)policy-violation 2022-26833   URL
59736MALWARE-CNC Win.Trojan.ZxxZ variant outbound connection (more info ...)trojan-activity    URL
59752FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59753FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59754FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59755FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59756FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59757FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59758FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59759FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59760FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59761FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59762FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59763FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59764FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59765FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59766FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59767FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59768FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59769FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59770FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59771FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59772FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59773FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59774FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59775FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59776FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59777FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59778FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59779FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59780FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59781FILE-OTHER Info-ZIP Unzip malformed extra field buffer overflow attempt (more info ...)attempted-admin 2014-9636   
59787PROTOCOL-SCADA VIPA Automation WinPLC7 buffer overflow attempt (more info ...)attempted-user 2017-5177   
59788FILE-OTHER ABB Panel Builder BeModBus CommandLineOptions stack-based buffer overflow attempt (more info ...)attempted-user 2018-10616   
59789FILE-OTHER ABB Panel Builder BeModBus CommandLineOptions stack-based buffer overflow attempt (more info ...)attempted-user 2018-10616   
59792SERVER-OTHER ISC BIND lightweight resolver protocol denial of service (more info ...)attempted-dos 2016-2775   
59795POLICY-OTHER IBM Data Risk Management administrative login attempt (more info ...)attempted-admin 2020-4427   
59797SERVER-OTHER NetGain Enterprise Manager arbitrary RMI registry insecure deserialization attempt (more info ...)attempted-user 2017-17406   
59798SERVER-OTHER NetGain Enterprise Manager arbitrary RMI registry insecure deserialization attempt (more info ...)attempted-user 2017-17406   
59799SERVER-OTHER NetGain Enterprise Manager arbitrary RMI registry insecure deserialization attempt (more info ...)attempted-user 2017-17406   
59802SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (more info ...)attempted-user 2016-9941   URL
59803SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (more info ...)attempted-user 2016-9941   URL
59825SERVER-OTHER OpenVPN read_key buffer overflow attempt (more info ...)attempted-user 2017-12166   URL
59833SERVER-MAIL Dovecot denial of service attempt (more info ...)attempted-dos 2016-8652   
59834SERVER-MAIL Dovecot denial of service attempt (more info ...)attempted-dos 2016-8652   
59835SERVER-MAIL Dovecot denial of service attempt (more info ...)attempted-dos 2016-8652   
59842SERVER-OTHER ISC BIND rndc control channel denial of service attempt (more info ...)attempted-dos 2017-3138   URL
59846SERVER-OTHER HP LoadRunner mxdr_string heap buffer overflow attempt (more info ...)attempted-user 2017-5789   URL
59847FILE-OTHER Delta Industrial Automation CNCSoft ScreenEditor DPB GIFFILE stack buffer overflow attempt (more info ...)attempted-user 2020-7002   URL
59848FILE-OTHER Delta Industrial Automation CNCSoft ScreenEditor DPB GIFFILE stack buffer overflow attempt (more info ...)attempted-user 2020-7002   URL
59850FILE-OTHER Eaton HMiSoft VU3 GIFFILE stack buffer overflow attempt (more info ...)attempted-user 2020-10639   
59852SERVER-ORACLE Oracle WebLogic Server IIOP JNDI injection attempt (more info ...)attempted-user 2020-14841   URL
59855FILE-OTHER Delta Industrial Automation CNCSoft ScreenEditor stack buffer overflow attempt (more info ...)attempted-user 2020-16199   
59857FILE-OTHER Omron CX-One CX-Programmer malicious cxp file download attempt (more info ...)attempted-user 2019-6556   
59860FILE-MULTIMEDIA AVI file chunk length integer overflow attempt (more info ...)attempted-user 2011-3834   URL
59861FILE-MULTIMEDIA AVI file chunk length integer overflow attempt (more info ...)attempted-user 2011-3834   URL
59868OS-WINDOWS DHCP failover relationship name denial of service attempt (more info ...)attempted-dos 2019-1206   URL
59869FILE-OTHER Phoenix Contact Automationworx PLCOpen XML stack buffer overflow attempt (more info ...)attempted-user 2020-12497   
59870FILE-OTHER Phoenix Contact Automationworx PLCOpen XML stack buffer overflow attempt (more info ...)attempted-user 2020-12497   
59871SERVER-OTHER ISC DHCP TCP session exhaustion denial of service attempt (more info ...)attempted-dos 2016-2774   
59872FILE-OTHER Fatek Automation PLC WinProladder Tab stack buffer overflow attempt (more info ...)attempted-user 2020-16234   
59879SERVER-OTHER OpenSSL SRP ciphersuite detected (more info ...)protocol-command-decode 2014-3512   URL
59880SERVER-OTHER OpenSSL SRP heap buffer overflow attempt (more info ...)attempted-admin 2014-3512   URL
59882POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1518 attack attempt (more info ...)policy-violation 2022-29481   URL
59883POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1521 attack attempt (more info ...)policy-violation 2022-28689   URL
59884POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1520 attack attempt (more info ...)policy-violation 2022-26023   URL
59885SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1519 attack attempt (more info ...)attempted-admin 2022-30543   URL
59887SERVER-WEBAPP HAProxy HTTP2 HPACK out of bounds write attempt (more info ...)web-application-attack 2020-11100   URL
59888SERVER-WEBAPP HAProxy HTTP2 HPACK out of bounds write attempt (more info ...)web-application-attack 2020-11100   URL
59896MALWARE-CNC Andr.Trojan.WolfRAT variant outbound connection (more info ...)trojan-activity    URL
59897MALWARE-CNC Andr.Trojan.WolfRAT variant outbound connection (more info ...)trojan-activity    URL
59898MALWARE-CNC Andr.Trojan.WolfRAT variant outbound connection (more info ...)trojan-activity    URL
59899MALWARE-CNC Andr.Trojan.WolfRAT variant outbound connection (more info ...)trojan-activity    URL
59900MALWARE-CNC Andr.Trojan.WolfRAT variant outbound connection (more info ...)trojan-activity    URL
59901MALWARE-CNC Andr.Trojan.WolfRAT variant outbound connection (more info ...)trojan-activity    URL
59902MALWARE-CNC Andr.Trojan.WolfRAT variant outbound connection (more info ...)trojan-activity    URL
59903MALWARE-CNC Andr.Trojan.WolfRAT variant outbound connection (more info ...)trojan-activity    URL
59907SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (more info ...)web-application-attack 2018-12031   
59908SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (more info ...)web-application-attack 2018-12031   
59909SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (more info ...)web-application-attack 2018-12031   
59917SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (more info ...)attempted-user 2021-28797   
59918SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (more info ...)attempted-user 2021-28797   
59935SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
59936SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
59937SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
59938SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
59975SERVER-WEBAPP Git client path validation command execution attempt (more info ...)attempted-user 2014-9390   
59980SERVER-WEBAPP Splunk search directory traversal attempt (more info ...)web-application-attack 2022-26889   URL
59981SERVER-WEBAPP Splunk search directory traversal attempt (more info ...)web-application-attack 2022-26889   URL
60049MALWARE-CNC Win.Rootkit.Daxin HTTP Tunneling attempt (more info ...)trojan-activity    URL
60053MALWARE-CNC Win.Trojan.DarkVNC variant outbound connection (more info ...)trojan-activity    URL
60057MALWARE-CNC Win.Trojan.Qakbot variant outbound connection (more info ...)trojan-activity    URL
60058SERVER-OTHER Hewlett Packard Enterprise Intelligent Management Center imiccdm service directory traversal file write attempt (more info ...)attempted-user 2018-7102   
60059MALWARE-CNC Win.Trojan.Gallium variant outbound beaconing attempt (more info ...)trojan-activity    URL
60060MALWARE-CNC Win.Trojan.Gallium variant outbound beaconing attempt (more info ...)trojan-activity    URL
60061MALWARE-CNC Win.Trojan.Gallium variant outbound beaconing attempt (more info ...)trojan-activity    URL
60066SERVER-WEBAPP Parallels H-Sphere cross site scripting attempt (more info ...)attempted-user 2022-30777   
60067SERVER-WEBAPP Parallels H-Sphere cross site scripting attempt (more info ...)attempted-user 2022-30777   
60068SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
60069SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
60070SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
60081SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
60082SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
60083SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
60084SERVER-WEBAPP Trend Micro InterScan Web Security Virtual Appliance command injection attempt (more info ...)web-application-attack    
60088SERVER-WEBAPP Kaseya VSA cross site scripting attempt (more info ...)attempted-user 2021-30119   
60089SERVER-WEBAPP Kaseya VSA cross site scripting attempt (more info ...)attempted-user 2021-30119   
60090SERVER-WEBAPP Kaseya VSA cross site scripting attempt (more info ...)attempted-user 2021-30119   
60091SERVER-WEBAPP Kaseya VSA cross site scripting attempt (more info ...)attempted-user 2021-30119   
60104SERVER-WEBAPP PlaySMS unauthenticated template injection attempt (more info ...)attempted-user 2020-8664   
60115FILE-OTHER Fuji Electric Frenic Loader stack-based buffer overflow attempt (more info ...)attempted-user 2018-14802   
60116FILE-OTHER Fuji Electric Frenic Loader stack-based buffer overflow attempt (more info ...)attempted-user 2018-14802   
60118SERVER-WEBAPP Kaseya VSA XML external entity injection attempt (more info ...)web-application-attack 2021-30201   
60180MALWARE-CNC Win.Trojan.CrimsonRAT outbound communication attempt (more info ...)trojan-activity    URL
60181MALWARE-CNC Win.Trojan.CrimsonRAT outbound communication attempt (more info ...)trojan-activity    URL
60182MALWARE-CNC Win.Trojan.CrimsonRAT outbound communication attempt (more info ...)trojan-activity    URL
60183MALWARE-CNC Win.Trojan.CrimsonRAT outbound communication attempt (more info ...)trojan-activity    URL
60185FILE-OTHER Wecon LeviStudioU DataLogTool history curve set stack-based buffer overflow attempt (more info ...)attempted-user 2019-6537   
60186FILE-OTHER Wecon LeviStudioU DataLogTool history curve set stack-based buffer overflow attempt (more info ...)attempted-user 2019-6537   
60189FILE-OTHER Wecon LeviStudioU DataLogTool history curve set stack-based buffer overflow attempt (more info ...)attempted-user 2019-6537   
60190FILE-OTHER Wecon LeviStudioU DataLogTool history curve set stack-based buffer overflow attempt (more info ...)attempted-user 2019-6537   
60193SERVER-WEBAPP Tenda Router SetIPv6Status command injection attempt (more info ...)web-application-attack 2022-28572   
60194SERVER-WEBAPP Tenda Router SetIPv6Status command injection attempt (more info ...)web-application-attack 2022-28572   
60195SERVER-WEBAPP Tenda Router SetIPv6Status command injection attempt (more info ...)web-application-attack 2022-28572   
60196SERVER-WEBAPP Tenda Router SetIPv6Status command injection attempt (more info ...)web-application-attack 2022-28572   
60212POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1552 attack attempt (more info ...)policy-violation 2022-27805   URL
60215POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1553 attack attempt (more info ...)policy-violation 2022-29475   URL
60216POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1553 attack attempt (more info ...)policy-violation 2022-29475   URL
60228FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1526 attack attempt (more info ...)attempted-user 2022-29465   URL
60229FILE-IMAGE TRUFFLEHUNTER TALOS-2022-1526 attack attempt (more info ...)attempted-user 2022-29465   URL
60243SERVER-WEBAPP Accellion FTA SSRF to command injection attempt (more info ...)attempted-user 2021-27102   URL
60245FILE-OTHER McAfee Total Protection MTP arbitrary process execution attempt (more info ...)attempted-admin 2021-23874   
60246FILE-OTHER McAfee Total Protection MTP arbitrary process execution attempt (more info ...)attempted-admin 2021-23874   
60264MALWARE-CNC Win.Backdoor.TreeTrunk outbound connection (more info ...)trojan-activity    URL
60266MALWARE-CNC Win.Backdoor.TreeTrunk outbound connection (more info ...)trojan-activity    URL
60268MALWARE-CNC Win.Backdoor.TreeTrunk outbound connection (more info ...)trojan-activity    URL
60269MALWARE-CNC Win.Backdoor.TreeTrunk outbound connection (more info ...)trojan-activity    URL
60270MALWARE-CNC Win.Backdoor.TreeTrunk outbound connection (more info ...)trojan-activity    URL
60271POLICY-OTHER Docker container registry access detected (more info ...)policy-violation 2022-20858   URL
60272POLICY-OTHER Docker container registry access detected (more info ...)policy-violation 2022-20858   URL
60275MALWARE-CNC Win.Trojan.Manjusaka outbound connection (more info ...)trojan-activity    
60289SERVER-WEBAPP PrimeTek PrimeFaces plugin expression language injection attempt (more info ...)attempted-user 2017-1000486   
60312FILE-OTHER Omron CX-Supervisor malicious project file download attempt (more info ...)attempted-user 2018-19015   
60313FILE-OTHER Omron CX-Supervisor malicious project file download attempt (more info ...)attempted-user 2018-19015   
60318SERVER-WEBAPP Pi-hole AdminLTE AddMAC authenticated command injection attempt (more info ...)attempted-user 2020-8816   URL
60319SERVER-OTHER TeamSpeak Server denial of service attempt (more info ...)attempted-dos    URL
60320SERVER-OTHER AmongUs Game Server denial of service attempt (more info ...)attempted-dos    URL
60321SERVER-OTHER Garry Mod Physics Sandbox denial of service attempt (more info ...)attempted-dos    URL
60322SERVER-OTHER Valve Source Engine Query denial of service attempt (more info ...)attempted-dos    URL
60323SERVER-OTHER Counter-Strike Global Offensive denial of service attempt (more info ...)attempted-dos    URL
60324MALWARE-CNC MultiOS.Trojan.DarkUtilities variant outbound connection (more info ...)trojan-activity    URL
60325MALWARE-CNC MultiOS.Trojan.DarkUtilities variant outbound connection (more info ...)trojan-activity    URL
60330SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1583 attack attempt (more info ...)attempted-admin 2022-35878   URL
60331SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1583 attack attempt (more info ...)attempted-admin 2022-35878   URL
60341SERVER-WEBAPP DELL EMC Avamar ADMe information disclosure attempt (more info ...)web-application-attack 2019-3737   
60342SERVER-WEBAPP DELL EMC Avamar ADMe information disclosure attempt (more info ...)web-application-attack 2019-3737   
60343SERVER-WEBAPP DELL EMC Avamar ADMe information disclosure attempt (more info ...)web-application-attack 2019-3737   
60346SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus SolutionSearch.do cross site scripting attempt (more info ...)web-application-attack 2019-12541   
60347SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus SolutionSearch.do cross site scripting attempt (more info ...)web-application-attack 2019-12541   
60348SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus SearchN.do cross site scripting attempt (more info ...)web-application-attack 2019-12542   
60349SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus SearchN.do cross site scripting attempt (more info ...)web-application-attack 2019-12542   
60350SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus SolutionSearch.do cross site scripting attempt (more info ...)web-application-attack 2019-12543   
60351SERVER-WEBAPP Zoho ManageEngine ServiceDesk Plus PurchaseRequest.do cross site scripting attempt (more info ...)web-application-attack 2019-12543   
60392POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1580 attack attempt (more info ...)policy-violation 2022-34845   URL
60393SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1575 attack attempt (more info ...)attempted-dos 2022-35271   URL
60428MALWARE-CNC Win.Trojan.BoratRat outbound connection request (more info ...)trojan-activity    URL
60433POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1587 attack attempt (more info ...)policy-violation    URL
60435SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2018-10602   
60436SERVER-WEBAPP WECON LeviStudio multiple xml parameter overflows attempt (more info ...)attempted-admin 2018-10602   
60437MALWARE-CNC Win.Trojan.ModernLoader inbound communication attempt (more info ...)trojan-activity    URL
60438MALWARE-CNC Win.Trojan.ModernLoader inbound communication attempt (more info ...)trojan-activity    URL
60439MALWARE-CNC Win.Trojan.ModernLoader outbound communication attempt (more info ...)trojan-activity    URL
60440MALWARE-CNC Win.Trojan.ModernLoader outbound communication attempt (more info ...)trojan-activity    URL
60450MALWARE-CNC Win.Trojan.SVCReady outbound connection attempt (more info ...)trojan-activity    URL
60454SERVER-WEBAPP Zimbra Calendar cross site scripting attempt (more info ...)attempted-user 2022-24682   
60459MALWARE-CNC Win.Malware.VSingle variant outbound connection (more info ...)trojan-activity    URL
60460MALWARE-CNC Win.Malware.VSingle variant outbound connection (more info ...)trojan-activity    URL
60461MALWARE-CNC Win.Malware.VSingle variant outbound connection (more info ...)trojan-activity    URL
60462MALWARE-CNC Win.Backdoor.YamaBot variant outbound connection (more info ...)trojan-activity    URL
60463MALWARE-CNC Win.Backdoor.TigerRAT variant outbound connection (more info ...)trojan-activity    URL
60464MALWARE-CNC Win.Backdoor.TigerRAT variant outbound connection (more info ...)trojan-activity    URL
60507MALWARE-CNC Win.Trojan.Matanbuchus payload download attempt (more info ...)trojan-activity    URL
60508MALWARE-CNC Win.Trojan.Matanbuchus malicious transfer attempt (more info ...)trojan-activity    URL
60516MALWARE-CNC Win.Trojan.IcedID download attempt (more info ...)trojan-activity    URL
60517MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60518MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60519MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60520MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60521MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60522MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60523MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60524MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60525MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60526MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60527MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60528MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60529MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60530MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60531MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60532MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60533MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60534MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60535MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60536MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60537MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60538MALWARE-CNC Lnk.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60539MALWARE-CNC Doc.Dropper.Gamaredon malicious download attempt (more info ...)trojan-activity    URL
60573POLICY-OTHER Nortek Linear eMerge E3-Series information disclosure attempt (more info ...)policy-violation 2022-31269   
60574OS-OTHER Apple OS X rootpipe privilege escalation attempt (more info ...)attempted-admin 2015-1130   URL
60575OS-OTHER Apple OS X rootpipe privilege escalation attempt (more info ...)attempted-admin 2015-1130   URL
60576OS-MOBILE GingerBreak escalation of privilege attempt (more info ...)attempted-admin 2011-1823   URL
60577OS-MOBILE GingerBreak escalation of privilege attempt (more info ...)attempted-admin 2011-1823   URL
60584MALWARE-CNC Perl.Webshell.GammaShell inbound connection attempt (more info ...)trojan-activity    URL
60585MALWARE-CNC Perl.Webshell.GammaShell inbound connection attempt (more info ...)trojan-activity    URL
60586MALWARE-CNC Perl.Webshell.GammaShell inbound connection attempt (more info ...)trojan-activity    URL
60587MALWARE-CNC Perl.Webshell.GammaShell outbound connection attempt (more info ...)trojan-activity    URL
60590MALWARE-CNC Perl.Webshell.GoShell inbound connection attempt (more info ...)trojan-activity    URL
60591MALWARE-CNC Perl.Webshell.GoShell outbound connection attempt (more info ...)trojan-activity    URL
60599POLICY-OTHER FortiGate and FortiADC LDAP Connectivity Test credential leak attempt (more info ...)policy-violation 2018-13374   
60602OS-MOBILE Mali GPU memory alias privilege escalation attempt (more info ...)attempted-admin 2022-38181   URL
60603OS-MOBILE Mali GPU memory alias privilege escalation attempt (more info ...)attempted-admin 2022-38181   URL
60625OS-OTHER Apple Mac iOS IOKit keyboard driver privilege escalation attempt (more info ...)attempted-admin 2014-4404   
60626OS-OTHER Apple Mac iOS IOKit keyboard driver privilege escalation attempt (more info ...)attempted-admin 2014-4404   
60630SERVER-WEBAPP Sickbeard URI parameter remote command injection attempt (more info ...)attempted-user    URL
60631SERVER-WEBAPP Sickbeard URI parameter remote command injection attempt (more info ...)attempted-user    URL
60638MALWARE-CNC Win.Backdoor.Agent inbound connection attempt (more info ...)trojan-activity    URL
60639MALWARE-CNC Win.Backdoor.Agent inbound connection attempt (more info ...)trojan-activity    URL
60641MALWARE-CNC MultiOS.Backdoor.Agent inbound connection attempt (more info ...)trojan-activity    URL
60645BROWSER-OTHER WhatsApp Desktop persistent cross-site scripting attempt (more info ...)attempted-user 2019-18426   
60665OS-MOBILE Android ACDB driver ioctl overflow attempt (more info ...)attempted-admin 2013-2597   URL
60666OS-MOBILE Android ACDB driver ioctl overflow attempt (more info ...)attempted-admin 2013-2597   URL
60668OS-WINDOWS Virtual Box kernel address tampering attempt (more info ...)attempted-admin 2008-3431   URL
60669OS-WINDOWS Virtual Box kernel address tampering attempt (more info ...)attempted-admin 2008-3431   URL
60681OS-MOBILE Android sk_buff use-after-free attempt (more info ...)attempted-admin 2021-0920   URL
60682OS-MOBILE Android sk_buff use-after-free attempt (more info ...)attempted-admin 2021-0920   URL
60690FILE-OTHER TRUFFLEHUNTER TALOS-2022-1617 attack attempt (more info ...)attempted-user 2022-40983   URL
60691FILE-OTHER TRUFFLEHUNTER TALOS-2022-1617 attack attempt (more info ...)attempted-user 2022-40983   URL
60692POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1613 attack attempt (more info ...)policy-violation 2022-41030   URL
60728MALWARE-CNC Win.Trojan.HannabiGrabber info stealer outbound communication (more info ...)trojan-activity    URL
60732SERVER-OTHER Acme mini_httpd 1.18 escape sequence command injection attempt (more info ...)attempted-user 2009-4490   
60743SERVER-WEBAPP Multiple products OpenSSL c_rehash command injection attempt (more info ...)web-application-attack 2022-1292   
60744SERVER-WEBAPP Multiple products OpenSSL c_rehash command injection attempt (more info ...)web-application-attack 2022-1292   
60745SERVER-WEBAPP Multiple products OpenSSL c_rehash command injection attempt (more info ...)web-application-attack 2022-1292   
60748MALWARE-CNC Win.Infostealer.MetaStealer outbound connection (more info ...)trojan-activity    URL
60749MALWARE-CNC Win.Infostealer.MetaStealer outbound connection (more info ...)trojan-activity    URL
60755MALWARE-CNC Win.Trojan.Astaroth outbound connection attempt (more info ...)trojan-activity    URL
60756MALWARE-CNC Win.Trojan.Astaroth outbound connection attempt (more info ...)trojan-activity    URL
60759MALWARE-CNC Ppt.Downloader.Wirte outbound connection (more info ...)trojan-activity    URL
60794MALWARE-CNC Win.InfoStealer.Raccoon variant outbound connection (more info ...)trojan-activity    URL
60795MALWARE-CNC Win.InfoStealer.Raccoon variant outbound connection (more info ...)trojan-activity    URL
60828MALWARE-CNC Win.Backdoor.Hoaxshell outbound connection attempt (more info ...)trojan-activity    URL
60835MALWARE-CNC Win.Trojan.TurlaMosquito outbound connection (more info ...)trojan-activity    URL
60836MALWARE-CNC Win.Trojan.TurlaMosquito outbound connection (more info ...)trojan-activity    URL
60843MALWARE-CNC Win.Backdoor.TurlaMosquito outbound connection (more info ...)trojan-activity    URL
60844MALWARE-CNC Win.Backdoor.Truebot variant outbound connection (more info ...)trojan-activity    URL
60845MALWARE-CNC Win.Backdoor.Truebot variant outbound connection (more info ...)trojan-activity    URL
60846SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1615 attack attempt (more info ...)attempted-admin 2022-38066   URL
60847SERVER-WEBAPP TRUFFLEHUNTER TALOS-2022-1615 attack attempt (more info ...)attempted-admin 2022-38066   URL
60853INDICATOR-COMPROMISE JXPath remote code execution attempt (more info ...)web-application-attack 2022-41852   URL
60854INDICATOR-COMPROMISE JXPath remote code execution attempt (more info ...)web-application-attack 2022-41852   URL
60855SERVER-WEBAPP JXPath remote code execution attempt (more info ...)web-application-attack 2022-41852   URL
60858SERVER-WEBAPP Zimbra ZmMailMsgView.getAttachmentLinkHtml XSS attempt (more info ...)web-application-attack 2018-6882   URL
60859SERVER-WEBAPP D-Link DSL-2760U Web-UI WiFi SSID cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60860SERVER-WEBAPP D-Link DSL-2760U Web-UI WiFi SSID cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60861SERVER-WEBAPP D-Link DSL-2760U Web-UI SAMBA Configuration cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60862SERVER-WEBAPP D-Link DSL-2760U Web-UI SAMBA Configuration cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60863SERVER-WEBAPP D-Link DSL-2760U Web-UI Printer Server cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60864SERVER-WEBAPP D-Link DSL-2760U Web-UI Printer Server cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60865SERVER-WEBAPP D-Link DSL-2760U Web-UI Policy Routing cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60866SERVER-WEBAPP D-Link DSL-2760U Web-UI Policy Routing cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60867SERVER-WEBAPP D-Link DSL-2760U Web-UI Incoming IP Filter cross site scripting attempt (more info ...)attempted-user 2013-5223   URL
60868SERVER-WEBAPP D-Link DSL-2760U Web-UI Incoming IP Filter cross site scripting attempt (more info ...)attempted-user 2013-5223   URL
60869SERVER-WEBAPP D-Link DSL-2760U Web-UI SNMP cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60870SERVER-WEBAPP D-Link DSL-2760U Web-UI SNMP cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60871SERVER-WEBAPP D-Link DSL-2760U Web-UI Interface Grouping cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60872SERVER-WEBAPP D-Link DSL-2760U Web-UI Interface Grouping cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60873SERVER-WEBAPP D-Link DSL-2760U Web-UI IP Filtering cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60874SERVER-WEBAPP D-Link DSL-2760U Web-UI IP Filtering cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60875SERVER-WEBAPP D-Link DSL-2760U Web-UI NAT Port Triggering cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60876SERVER-WEBAPP D-Link DSL-2760U Web-UI NAT Port Triggering cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60877SERVER-WEBAPP D-Link DSL-2760U Web-UI URL Filtering cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60878SERVER-WEBAPP D-Link DSL-2760U Web-UI URL Filtering cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60879SERVER-WEBAPP D-Link DSL-2760U Web-UI Parental Control cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60880SERVER-WEBAPP D-Link DSL-2760U Web-UI Parental Control cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60883SERVER-WEBAPP D-Link DSL-2760U Web-UI NTS Settings cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60884SERVER-WEBAPP D-Link DSL-2760U Web-UI NTS Settings cross site scripting attempt (more info ...)web-application-attack 2013-5223   URL
60889SERVER-WEBAPP ES File Explorer File Manager policy bypass attempt (more info ...)web-application-attack 2019-6447   URL
60890SERVER-WEBAPP ES File Explorer File Manager policy bypass attempt (more info ...)web-application-attack 2019-6447   URL
60891MALWARE-OTHER Doc.Downloader.MetaStealer file download attempt (more info ...)trojan-activity    URL
60892MALWARE-OTHER Doc.Downloader.MetaStealer file download attempt (more info ...)trojan-activity    URL
60902MALWARE-CNC Win.Infostealer.MetaStealer variant outbound connection (more info ...)trojan-activity    URL
60903MALWARE-CNC Xls.Downloader.AXQ variant outbound connection (more info ...)trojan-activity    URL
60906POLICY-OTHER SAP NetWeaver JWFTestAddAssignees potential disclosure vulnerable page (more info ...)policy-violation 2016-2388   URL
60910SERVER-WEBAPP TP-Link Router Web Server directory traversal attempt (more info ...)web-application-attack 2015-3035   URL
60911SERVER-WEBAPP TP-Link Router Web Server directory traversal attempt (more info ...)web-application-attack 2015-3035   URL
60912FILE-OTHER TRUFFLEHUNTER TALOS-2022-1650 attack attempt (more info ...)attempted-user 2022-43591   URL
60913FILE-OTHER TRUFFLEHUNTER TALOS-2022-1650 attack attempt (more info ...)attempted-user 2022-43591   URL
60914POLICY-OTHER TRUFFLEHUNTER TALOS-2022-1612 attack attempt (more info ...)policy-violation 2022-40220   URL
60934SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1659 attack attempt (more info ...)attempted-dos 2023-23539   URL
60935SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1659 attack attempt (more info ...)attempted-dos 2023-23539   URL
60936SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1659 attack attempt (more info ...)attempted-dos 2023-23539   URL
60937SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1659 attack attempt (more info ...)attempted-dos 2023-23539   URL
60938SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1658 attack attempt (more info ...)attempted-user    URL
60939SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1658 attack attempt (more info ...)attempted-user    URL
60940SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1658 attack attempt (more info ...)attempted-user    URL
60941SERVER-OTHER TRUFFLEHUNTER TALOS-2022-1658 attack attempt (more info ...)attempted-user    URL
60943MALWARE-CNC Win.Trojan.Gamaredon outbound communication attempt (more info ...)trojan-activity    URL
60962MALWARE-TOOLS Win.Dropper.KopiLuwak browser extension download attempt (more info ...)trojan-activity    URL
60963MALWARE-TOOLS Win.Dropper.KopiLuwak browser extension download attempt (more info ...)trojan-activity    URL
60976INDICATOR-COMPROMISE VMware vSphere Client vROps plugin potential server side request forgery attempt (more info ...)web-application-attack 2021-21973   URL
60979MALWARE-CNC Win.Trojan.FormBook malicious XLL outbound connection attempt (more info ...)trojan-activity    URL
60980MALWARE-CNC Win.Trojan.FormBook malicious XLL outbound connection attempt (more info ...)trojan-activity    URL
60981MALWARE-CNC Win.Trojan.FormBook malicious XLL outbound connection attempt (more info ...)trojan-activity    URL
60982MALWARE-CNC Win.Ransomware.Royal variant network share readme file detected (more info ...)trojan-activity    URL
61004POLICY-OTHER Oracle Access Manager deprecated OpenSSO access attempt (more info ...)attempted-user 2021-35587   URL
61005FILE-OTHER TRUFFLEHUNTER TALOS-2022-1667 attack attempt (more info ...)attempted-user 2022-41793   URL
61006FILE-OTHER TRUFFLEHUNTER TALOS-2022-1667 attack attempt (more info ...)attempted-user 2022-41793   URL
61007FILE-OTHER TRUFFLEHUNTER TALOS-2022-1672 attack attempt (more info ...)attempted-user 2022-37331   URL
61008FILE-OTHER TRUFFLEHUNTER TALOS-2022-1672 attack attempt (more info ...)attempted-user 2022-37331   URL
61009FILE-OTHER TRUFFLEHUNTER TALOS-2022-1668 attack attempt (more info ...)attempted-user 2022-42885   URL
61010FILE-OTHER TRUFFLEHUNTER TALOS-2022-1668 attack attempt (more info ...)attempted-user 2022-42885   URL
61013MALWARE-CNC Win.Trojan.FlawedGrace outbound communication attempt (more info ...)trojan-activity    URL
61014POLICY-OTHER Foxit Reader exportAsFDF potential arbitrary file write attempt (more info ...)policy-violation 2018-14280   
61015POLICY-OTHER Foxit Reader exportAsFDF potential arbitrary file write attempt (more info ...)policy-violation 2018-14280   
61016POLICY-OTHER Foxit Reader exportAsFDF potential arbitrary file write attempt (more info ...)policy-violation 2018-14280   
61017POLICY-OTHER Foxit Reader exportAsFDF potential arbitrary file write attempt (more info ...)policy-violation 2018-14280   
61018FILE-OTHER TRUFFLEHUNTER TALOS-2022-1670 attack attempt (more info ...)attempted-user 2022-46280   URL
61019FILE-OTHER TRUFFLEHUNTER TALOS-2022-1670 attack attempt (more info ...)attempted-user 2022-46280   URL
61020FILE-OTHER TRUFFLEHUNTER TALOS-2022-1671 attack attempt (more info ...)attempted-user 2022-43467   URL
61021FILE-OTHER TRUFFLEHUNTER TALOS-2022-1671 attack attempt (more info ...)attempted-user 2022-43467   URL
61022FILE-IDENTIFY Tripos Mol2 file download request (more info ...)misc-activity    
61023FILE-IDENTIFY Tripos Mol2 file attachment detected (more info ...)misc-activity    
61024FILE-IDENTIFY Tripos Mol2 file attachment detected (more info ...)misc-activity    
61025FILE-IDENTIFY Tripos Mol2 file attachment detected (more info ...)misc-activity    
61026FILE-OTHER TRUFFLEHUNTER TALOS-2022-1664 attack attempt (more info ...)attempted-user 2022-43607   URL
61027FILE-OTHER TRUFFLEHUNTER TALOS-2022-1664 attack attempt (more info ...)attempted-user 2022-43607   URL
61028MALWARE-CNC Win.Backdoor.Turla outbound connection (more info ...)trojan-activity    
61035FILE-OTHER TRUFFLEHUNTER TALOS-2022-1665 attack attempt (more info ...)attempted-user 2022-46289   URL
61036FILE-OTHER TRUFFLEHUNTER TALOS-2022-1665 attack attempt (more info ...)attempted-user 2022-46289   URL
61037FILE-OTHER TRUFFLEHUNTER TALOS-2022-1665 attack attempt (more info ...)attempted-user 2022-46290   URL
61038FILE-OTHER TRUFFLEHUNTER TALOS-2022-1665 attack attempt (more info ...)attempted-user 2022-46290   URL
61039FILE-OTHER TRUFFLEHUNTER TALOS-2022-1669 attack attempt (more info ...)attempted-user 2022-44451   URL
61040FILE-OTHER TRUFFLEHUNTER TALOS-2022-1669 attack attempt (more info ...)attempted-user 2022-44451   URL
61048FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46291   URL
61049FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46291   URL
61050FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46292   URL
61051FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46292   URL
61052FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46293   URL
61053FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46293   URL
61054FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46294   URL
61055FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46294   URL
61056FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46294   URL
61057FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46294   URL
61058FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46295   URL
61059FILE-OTHER TRUFFLEHUNTER TALOS-2022-1666 attack attempt (more info ...)attempted-user 2022-46295   URL
61074MALWARE-CNC JSP.Webshell.JSPShell outbound connection (more info ...)trojan-activity    URL
61094POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1692 attack attempt (more info ...)policy-violation    URL
61154SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1690 attack attempt (more info ...)misc-attack    URL
61155SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1690 attack attempt (more info ...)misc-attack    URL
61160MALWARE-CNC JSP.Webshell.JSP2Shell outbound connection (more info ...)trojan-activity    URL
61161MALWARE-CNC JSP.Webshell.JSP2Shell inbound connection (more info ...)trojan-activity    URL
61182MALWARE-CNC Win.Spyware.Carbon outbound connection attempt (more info ...)trojan-activity    URL
61192POLICY-OTHER Veeam Backup and Replication empty user name login detected (more info ...)policy-violation 2022-26501   URL
61193OS-OTHER TRUFFLEHUNTER TALOS-2022-1688 attack attempt (more info ...)attempted-recon    URL
61199PROTOCOL-OTHER BGP EVPN MAC/IP Advertisement address length overflow attempt (more info ...)attempted-dos 2017-12319   
61206SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1701 attack attempt (more info ...)web-application-attack 2023-22319   URL
61207SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1701 attack attempt (more info ...)web-application-attack 2023-22319   URL
61208SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1701 attack attempt (more info ...)web-application-attack 2023-22319   URL
61212POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1698 attack attempt (more info ...)policy-violation 2023-25583   URL
61223MALWARE-CNC User-Agent Sality malicious user agent (more info ...)trojan-activity    
61224MALWARE-CNC User-Agent Houdini malicious user agent (more info ...)trojan-activity    
61250MALWARE-CNC Win.Dropper.Rhadamanthys variant outbound connection (more info ...)trojan-activity    URL
61251MALWARE-CNC Win.Dropper.Rhadamanthys variant outbound connection (more info ...)trojan-activity    URL
61253MALWARE-CNC Win.Trojan.StrongPity variant outbound connection (more info ...)trojan-activity    URL
61259MALWARE-CNC Win.Trojan.Gamaredon variant outbound connection (more info ...)trojan-activity    
61263MALWARE-CNC Win.Trojan.LaplasClipper variant outbound connection (more info ...)trojan-activity    URL
61264MALWARE-CNC Win.Trojan.LaplasClipper variant outbound connection (more info ...)trojan-activity    URL
61265MALWARE-CNC Win.Downloader.BatLoader variant outbound connection (more info ...)trojan-activity    URL
61304MALWARE-CNC Win.Trojan.njRAT variant download attempt (more info ...)trojan-activity    URL
61305MALWARE-CNC Win.Trojan.njRAT variant download attempt (more info ...)trojan-activity    URL
61306MALWARE-CNC Win.Trojan.njRAT variant download attempt (more info ...)trojan-activity    URL
61307MALWARE-CNC Win.Trojan.njRAT variant download attempt (more info ...)trojan-activity    URL
61308MALWARE-CNC Win.Trojan.njRAT variant download attempt (more info ...)trojan-activity    URL
61309MALWARE-CNC Win.Trojan.njRAT variant download attempt (more info ...)trojan-activity    URL
61310MALWARE-CNC Win.Trojan.njRAT variant download attempt (more info ...)trojan-activity    URL
61311MALWARE-CNC Win.Trojan.njRAT variant download attempt (more info ...)trojan-activity    URL
61376POLICY-OTHER Fortra GoAnywhere MFT potential remote code execution attempt (more info ...)policy-violation 2023-0669   
61377POLICY-OTHER Fortra GoAnywhere MFT potential remote code execution attempt (more info ...)policy-violation 2023-0669   
61378FILE-OTHER Intel Network Adapter Diagnostic Driver exploitation attempt (more info ...)attempted-dos 2015-2291   
61379FILE-OTHER Intel Network Adapter Diagnostic Driver exploitation attempt (more info ...)attempted-dos 2015-2291   
61380FILE-OTHER Intel Network Adapter Diagnostic Driver exploitation attempt (more info ...)attempted-dos 2015-2291   
61381FILE-OTHER Intel Network Adapter Diagnostic Driver exploitation attempt (more info ...)attempted-dos 2015-2291   
61382FILE-OTHER Intel Network Adapter Diagnostic Driver exploitation attempt (more info ...)attempted-dos 2015-2291   
61383FILE-OTHER Intel Network Adapter Diagnostic Driver exploitation attempt (more info ...)attempted-dos 2015-2291   
61388MALWARE-OTHER Win.Malware.Agent malicious PowerShell script download attempt (more info ...)trojan-activity    
61389MALWARE-OTHER Win.Malware.Agent malicious PowerShell script download attempt (more info ...)trojan-activity    
61391MALWARE-CNC Win.Malware.Agent data exfiltration attempt (more info ...)trojan-activity    
61426MALWARE-CNC Win.Trojan.Prometei variant outbound connection (more info ...)trojan-activity    URL
61427MALWARE-CNC Win.Trojan.Prometei variant outbound connection (more info ...)trojan-activity    URL
61428MALWARE-CNC Win.Trojan.Prometei variant outbound connection (more info ...)trojan-activity    URL
61429MALWARE-CNC Win.Trojan.Prometei variant outbound connection (more info ...)trojan-activity    URL
61443POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1728 attack attempt (more info ...)attempted-recon    URL
61461MALWARE-CNC Win.Malware.Agent variant outbound cnc beacon detected (more info ...)trojan-activity    
61473MALWARE-CNC Win.Trojan.BlackLotus variant outbound connection (more info ...)trojan-activity    URL
61475FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1729 attack attempt (more info ...)attempted-user 2023-23567   URL
61476FILE-IMAGE TRUFFLEHUNTER TALOS-2023-1729 attack attempt (more info ...)attempted-user 2023-23567   URL
61489MALWARE-CNC Win.Ransomware.Mallox variant outbound connection (more info ...)trojan-activity    URL
61507MALWARE-CNC Win.Trojan.Chinotto variant outbound connection (more info ...)trojan-activity    URL
61508MALWARE-CNC Win.Trojan.Chinotto variant outbound connection (more info ...)trojan-activity    URL
61509MALWARE-CNC Win.Trojan.Chinotto variant outbound connection (more info ...)trojan-activity    URL
61510MALWARE-CNC Win.Trojan.Chinotto variant outbound connection (more info ...)trojan-activity    URL
61511MALWARE-CNC Win.Trojan.Chinotto variant outbound connection (more info ...)trojan-activity    URL
61512MALWARE-CNC Win.Trojan.Chinotto variant outbound connection (more info ...)trojan-activity    URL
61513MALWARE-CNC Win.Trojan.Chinotto variant outbound connection (more info ...)trojan-activity    URL
61514POLICY-OTHER Veeam Backup and Replication credential dump attempt (more info ...)policy-violation 2023-27532   URL
61527MALWARE-OTHER Win.Trojan.Agent variant payload download attempt (more info ...)trojan-activity    URL
61528MALWARE-OTHER Win.Trojan.Agent variant payload download attempt (more info ...)trojan-activity    URL
61529MALWARE-OTHER Win.Trojan.Agent variant payload download attempt (more info ...)trojan-activity    URL
61530MALWARE-OTHER Win.Trojan.Agent variant payload download attempt (more info ...)trojan-activity    URL
61556MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity    URL
61557MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity    URL
61560MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity    URL
61561MALWARE-OTHER Win.Trojan.Agent variant download attempt (more info ...)trojan-activity    URL
61564MALWARE-CNC Win.Trojan.AgentTesla variant outbound connection (more info ...)trojan-activity    URL
61565MALWARE-CNC Win.Trojan.AgentTesla variant outbound connection (more info ...)trojan-activity    URL
61566MALWARE-CNC Win.Trojan.AgentTesla variant outbound connection (more info ...)trojan-activity    URL
61567MALWARE-CNC Win.Trojan.AgentTesla variant outbound connection (more info ...)trojan-activity    URL
61572SERVER-OTHER TRUFFLEHUNTER TALOS-2023-1735 attack attempt (more info ...)attempted-admin 2023-27395   URL
61576OS-MOBILE Samsung Galaxy AppStore unauthorized application install attempt (more info ...)attempted-user 2023-21433   
61588MALWARE-CNC Win.Ransomware.Royal variant outbound connection attempt (more info ...)trojan-activity    URL
61612MALWARE-CNC Win.Ransomware.Lockbit variant network share readme file detected (more info ...)trojan-activity    URL
61627MALWARE-CNC Win.Downloader.BrokenDynamo second stage download attempt (more info ...)trojan-activity    URL
61628MALWARE-CNC TRUFFLEHUNTER SFVRT-1049 attack attempt (more info ...)trojan-activity    
61632SERVER-WEBAPP GitLab project import command injection attempt (more info ...)web-application-attack 2022-2185   URL
61639MALWARE-CNC Win.Trojan.SysUpdate variant beaconing attempt (more info ...)trojan-activity    URL
61664MALWARE-CNC Osx.Nukesped.Downloader beacon attempt (more info ...)trojan-activity    URL
61665MALWARE-CNC Osx.Nukesped.Downloader beacon attempt (more info ...)trojan-activity    URL
61676MALWARE-CNC MultiOS.Backdoor.Chollima beacon attempt (more info ...)trojan-activity    URL
61679MALWARE-CNC Win.Trojan.Agent variant inbound connection attempt (more info ...)trojan-activity    URL
61680MALWARE-CNC Win.Trojan.Agent variant inbound connection attempt (more info ...)trojan-activity    URL
61681MALWARE-CNC Win.Trojan.Agent variant inbound connection attempt (more info ...)trojan-activity    URL
61682MALWARE-CNC Win.Trojan.Agent variant inbound connection attempt (more info ...)trojan-activity    URL
61683MALWARE-CNC Win.Trojan.Agent variant inbound connection attempt (more info ...)trojan-activity    URL
61684MALWARE-CNC Win.Trojan.Agent variant inbound connection attempt (more info ...)trojan-activity    URL
61685SERVER-OTHER Django large multipart form denial of service attempt (more info ...)attempted-dos 2023-24580   URL
61686SERVER-OTHER Multiple products oversized HTTP Content-Length header value (more info ...)attempted-dos 2023-24580   URL
61689MALWARE-CNC Win.Ransomware.CryptoLocker variant outbound connection (more info ...)trojan-activity    URL
61702POLICY-OTHER Industrial Control Links ScadaFlex II arbitrary file delete attempt (more info ...)policy-violation 2022-25359   URL
61703POLICY-OTHER Industrial Control Links ScadaFlex II arbitrary file write attempt (more info ...)policy-violation 2022-25359   URL
61721SERVER-WEBAPP Zyxel remote support attempt (more info ...)suspicious-login 2023-28771   URL
61734FILE-IMAGE ImageMagick tEXt profile denial of service attempt (more info ...)attempted-dos 2022-44267   URL
61735FILE-IMAGE ImageMagick tEXt profile denial of service attempt (more info ...)attempted-dos 2022-44267   URL
61761MALWARE-CNC Win.Ransomware.Babuk encrypted file exfiltration attempt (more info ...)trojan-activity    URL
61762MALWARE-CNC Win.Ransomware.Babuk encrypted file exfiltration attempt (more info ...)trojan-activity    URL
61765SERVER-WEBAPP Multiple products cross site scripting attempt (more info ...)web-application-attack    
61839MALWARE-CNC Win.Trojan.Horabot data exfiltration attempt (more info ...)trojan-activity    
61841MALWARE-CNC Ps1.Trojan.Horabot malicious file download attempt (more info ...)trojan-activity    
61842MALWARE-CNC Ps1.Trojan.Horabot malicious file download attempt (more info ...)trojan-activity    
61845MALWARE-CNC Win.Trojan.Horabot malicious file download attempt (more info ...)trojan-activity    
61846MALWARE-CNC Win.Trojan.Horabot malicious file download attempt (more info ...)trojan-activity    
61847MALWARE-CNC Ps1.Trojan.Horabot malicious file download attempt (more info ...)trojan-activity    
61848MALWARE-CNC Ps1.Trojan.Horabot malicious file download attempt (more info ...)trojan-activity    
61849MALWARE-CNC Win.Downloader.Horabot malicious file download attempt (more info ...)trojan-activity    
61850MALWARE-CNC Win.Downloader.Horabot malicious file download attempt (more info ...)trojan-activity    
61851MALWARE-CNC Win.Downloader.Horabot malicious file download attempt (more info ...)trojan-activity    
61852MALWARE-CNC Win.Downloader.Horabot malicious file download attempt (more info ...)trojan-activity    
61853MALWARE-CNC Win.Downloader.Horabot malicious file download attempt (more info ...)trojan-activity    
61854MALWARE-CNC Win.Downloader.Horabot malicious file download attempt (more info ...)trojan-activity    
61855MALWARE-CNC Ps1.Trojan.Horabot malicious file download attempt (more info ...)trojan-activity    
61856MALWARE-CNC Ps1.Trojan.Horabot malicious file download attempt (more info ...)trojan-activity    
61880MALWARE-CNC Win.Trojan.RedLine inbound command and control attempt (more info ...)trojan-activity    URL
61891MALWARE-TOOLS Win.Tool.RemComSvc download attempt (more info ...)trojan-activity    URL
61892MALWARE-TOOLS Win.Tool.RemComSvc download attempt (more info ...)trojan-activity    URL
61901MALWARE-CNC Win.Trojan.Redline malicious file download (more info ...)trojan-activity    URL
61902MALWARE-CNC Win.Trojan.Redline malicious file download (more info ...)trojan-activity    URL
61903MALWARE-CNC Win.Trojan.Gozi malicious file download (more info ...)trojan-activity    URL
61904MALWARE-CNC Win.Trojan.Gozi malicious file download (more info ...)trojan-activity    URL
61913MALWARE-TOOLS Win.Proxy.frp download attempt (more info ...)trojan-activity    URL
61914MALWARE-TOOLS Win.Proxy.frp download attempt (more info ...)trojan-activity    URL
61945POLICY-OTHER Draytek Vigor device registration attempt (more info ...)policy-violation 2023-33778   URL
61960POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1762 attack attempt (more info ...)policy-violation 2023-34365   URL
61965SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1766 attack attempt (more info ...)attempted-admin 2023-34426   URL
61966SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1765 attack attempt (more info ...)attempted-admin 2023-31272   URL
61967SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1765 attack attempt (more info ...)attempted-admin 2023-31272   URL
61968SERVER-WEBAPP TRUFFLEHUNTER TALOS-2023-1765 attack attempt (more info ...)attempted-admin 2023-31272   URL
61991POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1773 attack attempt (more info ...)policy-violation 2023-34994   URL
61992POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1771 attack attempt (more info ...)policy-violation 2023-32615   URL
61993POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1772 attack attempt (more info ...)policy-violation 2023-34317   URL
61994POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1774 attack attempt (more info ...)policy-violation 2023-32271   URL
62003POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1769 attack attempt (more info ...)policy-violation 2023-31242   URL
62004POLICY-OTHER TRUFFLEHUNTER TALOS-2023-1775 attack attempt (more info ...)attempted-recon 2023-35124   URL
62060MALWARE-CNC Osx.Backdoor.Rustbucket stage two download attempt (more info ...)trojan-activity    URL
62061MALWARE-CNC Osx.Backdoor.Rustbucket stage three download attempt (more info ...)trojan-activity    URL
62084MALWARE-CNC Win.Trojan.RomCom outbound connection attempt (more info ...)trojan-activity    URL
62085MALWARE-CNC Win.Trojan.RomCom outbound connection attempt (more info ...)trojan-activity    URL
62086MALWARE-CNC Win.Trojan.RomCom outbound connection attempt (more info ...)trojan-activity    URL
62091SERVER-WEBAPP Zimbra Collaboration Suite cross site scripting attempt (more info ...)attempted-user 2023-34192   URL
62092SERVER-WEBAPP Zimbra Collaboration Suite cross site scripting attempt (more info ...)attempted-user 2023-34192   URL
62102SERVER-WEBAPP OpenSSL c_rehash command injection attempt (more info ...)web-application-attack 2022-2068   URL
62103SERVER-WEBAPP OpenSSL c_rehash command injection attempt (more info ...)web-application-attack 2022-2068   URL
62105FILE-PDF pdfio denial of service attempt (more info ...)attempted-dos 2023-28428   URL
62106FILE-PDF pdfio denial of service attempt (more info ...)attempted-dos 2023-28428   URL
62126MALWARE-CNC Win.Trojan.Agent Fake AnyDesk variant outbound connection (more info ...)trojan-activity    URL

 goto Top

Group: Malware / Trojans

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Malware / DoS

# of attack rules in this group: 0

# of warning rules in this group: 0