本報告彙整了 2ns.org 監測節點偵測到的即時攻擊行為。包含 SQL Injection、XSS 跨站腳本 以及非法檔案存取嘗試。提供管理者作為防火牆黑名單設定參考。
最後更新:2026-08-01 23:22:51 📥 下載完整報告
| 時間 | 攻擊名稱 | 來源 IP (下載威脅IP清單) | 動作 |
|---|---|---|---|
| - | Multiple.Routers.GPON.formLogin.Remote.Command.Injection | 94.154.43.210 | dropped |
| - | Apache.HTTP.Server.cgi-bin.Path.Traversal | 34.23.186.31 | dropped |
| - | HTTP.URI.SQL.Injection | 34.23.186.31 | dropped |
| - | HTTP.URI.SQL.Injection | 34.23.186.31 | dropped |
| - | HTTP.URI.SQL.Injection | 34.23.186.31 | dropped |
| - | Spring.Boot.Actuator.Unauthorized.Access | 34.23.186.31 | dropped |
| - | Gh0st.Rat.Botnet | 66.240.205.34 | dropped |
| - | Apache.HTTP.Server.cgi-bin.Path.Traversal | 34.26.36.243 | dropped |
| - | HTTP.URI.SQL.Injection | 34.26.36.243 | dropped |
| - | HTTP.URI.SQL.Injection | 34.26.36.243 | dropped |
| - | HTTP.URI.SQL.Injection | 34.26.36.243 | dropped |
| - | Spring.Boot.Actuator.Unauthorized.Access | 34.26.36.243 | dropped |
| - | Apache.HTTP.Server.cgi-bin.Path.Traversal | 35.240.59.95 | dropped |
| - | HTTP.URI.SQL.Injection | 35.240.59.95 | dropped |
| - | HTTP.URI.SQL.Injection | 35.240.59.95 | dropped |
| - | HTTP.URI.SQL.Injection | 35.240.59.95 | dropped |
| - | Spring.Boot.Actuator.Unauthorized.Access | 35.240.59.95 | dropped |
| - | Apache.HTTP.Server.cgi-bin.Path.Traversal | 89.126.211.166 | dropped |
| - | Web.Server.Password.File.Access | 5.61.209.224 | dropped |
| - | ALFA.TEaM.Web.Shell | 142.93.223.31 | dropped |
| - | Cross.Site.Scripting | 187.124.46.249 | detected |
| - | Web.Server.Password.File.Access | 187.124.46.249 | dropped |
| - | ThinkPHP.Controller.Parameter.Remote.Code.Execution | 70.39.202.96 | dropped |
| - | ThinkPHP.Controller.Parameter.Remote.Code.Execution | 70.39.202.96 | dropped |
| - | ThinkPHP.Controller.Parameter.Remote.Code.Execution | 70.39.202.96 | dropped |
| - | Web.Server.Password.File.Access | 65.109.100.164 | dropped |
| - | Web.Server.Password.File.Access | 65.109.100.164 | dropped |
| - | Web.Server.Password.File.Access | 65.109.100.164 | dropped |
| - | Cross.Site.Scripting | 65.109.100.164 | detected |
| - | Cross.Site.Scripting | 65.109.100.164 | detected |
| - | Cross.Site.Scripting | 65.109.100.164 | detected |
| - | Web.Server.Password.File.Access | 65.109.100.164 | dropped |
| - | Apache.HTTP.Server.cgi-bin.Path.Traversal | 168.144.35.118 | dropped |
| - | HTPasswd.Access | 172.182.253.37 | dropped |
| - | Telerik.Web.UI.RadAsyncUpload.Handling.Arbitrary.File.Upload | 109.105.210.87 | dropped |
| - | Web.Server.Password.File.Access | 183.81.168.186 | dropped |
| - | Apache.HTTP.Server.cgi-bin.Path.Traversal | 45.156.128.177 | dropped |
| - | Apache.HTTP.Server.cgi-bin.Path.Traversal | 45.156.128.176 | dropped |
| - | Telerik.Web.UI.RadAsyncUpload.Handling.Arbitrary.File.Upload | 45.156.128.179 | dropped |
| - | PHP.CGI.Argument.Injection | 176.123.1.163 | dropped |
| - | Spring.Boot.Actuator.Unauthorized.Access | 45.194.92.75 | dropped |
| - | Spring.Boot.Actuator.Unauthorized.Access | 45.194.92.75 | dropped |
| - | HTTP.URI.SQL.Injection | 38.255.57.105 | dropped |
| - | HTTP.URI.SQL.Injection | 38.255.57.105 | dropped |
| - | Spring.Boot.Actuator.Unauthorized.Access | 45.194.92.53 | dropped |
| - | Spring.Boot.Actuator.Unauthorized.Access | 45.194.92.53 | dropped |
| - | HTTP.URI.SQL.Injection | 8.216.88.236 | dropped |
| - | HTTP.URI.SQL.Injection | 8.216.88.236 | dropped |
| - | HTTP.URI.SQL.Injection | 8.216.88.236 | dropped |
| - | HTTP.URI.SQL.Injection | 8.216.88.236 | dropped |