24.234.133.216
Technical source observed on EudorIA perimeter controls. All the events listed were blocked, contained or detected by the defensive systems.
Estimated origin
- Country
- United States (US)
- City
- Las Vegas
- ASN
- AS22773
- ASN operator / holder
- ASN-CXA-ALL-CCI-22773-RDC - Cox Communications Inc., US
- Announced prefix
- 24.234.0.0/16
- Reverse DNS
- wsip-24-234-133-216.lv.lv.cox.net
Anomalous web request
- Public destination
- eudoria.it
- Service
- HTTPS protetto da WAF
- Rule
- 100604
- Technical reason
- EudorIA WAF blocked an external request with a high anomaly score from 24.234.133.216.
- Outcome
- Blocked / detected
Observed evidence
Anomalous web request
mediumEudorIA WAF blocked an external request with a high anomaly score from 24.234.133.216.
- Destination
- eudoria.it
- Service
- HTTPS protetto da WAF
- Method
- POST
- Resource
/hello.world- Anomaly score
- 33
- Outcome
- Blocked
IPS detection
highET WEB_SERVER Possible SQL Injection (exec) in HTTP Request Body
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET WEB_SERVER Generic PHP Remote File Include
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET WEB_SERVER PHP.//Input in HTTP POST
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET WEB_SERVER auto_prepend_file PHP config option in uri
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET WEB_SERVER allow_url_include PHP config option in uri
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET WEB_SERVER PHP tags in HTTP POST
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected
IPS detection
highET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt
- Destination
- eudoria.it
- Service
- HTTP
- Outcome
- Detected