Threat LevelCRITICAL78/1002 rule types
19 incidents · 2 rule types · active attack detected · persistent 18-day campaign · seen 2h ago
| PTR | mail.halo-egroup.com |
| Org / ASN | Contabo GmbH |
| Country | 🇫🇷 France |
| City | Lauterbourg, Grand Est |
| Timezone | Europe/Paris |
Attack Analysis
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
Webshell Upload Scan
This IP rapidly probed multiple non-existent PHP paths in under 60 seconds — a hallmark of automated webshell scanning tools hunting for previously uploaded backdoors or vulnerable file-upload endpoints. If successful, a webshell grants the attacker full remote code execution on the server.
Reports (19)
| Date | Severity | Description |
|---|---|---|
| 30 Sep 2026 - 00:05 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 29 Sep 2026 - 00:50 | medium | IDS: Suricata alert — ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt |
| 27 Sep 2026 - 00:55 | medium | IDS: Suricata alert — ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt |
| 26 Sep 2026 - 00:31 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 25 Sep 2026 - 00:53 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 24 Sep 2026 - 00:40 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 23 Sep 2026 - 00:26 | medium | IDS: Suricata alert — ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt |
| 23 Sep 2026 - 00:21 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 22 Sep 2026 - 01:02 | medium | IDS: Suricata alert — ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt |
| 22 Sep 2026 - 00:57 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 20 Sep 2026 - 00:51 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 19 Sep 2026 - 00:29 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 17 Sep 2026 - 00:42 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 16 Sep 2026 - 00:44 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 15 Sep 2026 - 00:18 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 14 Sep 2026 - 00:31 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 12 Sep 2026 - 01:13 | medium | IDS: Suricata alert — ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2 |
| 12 Sep 2026 - 01:13 | high | Web: Webshell scan — 3+ unknown PHP probes in 60s |
| 12 Sep 2026 - 01:13 | high | IDS: Suricata alert |
EagleEye Intelligence