🔥 IPS 威脅報告與惡意 IP 監控

本報告彙整了 2ns.org 監測節點偵測到的即時攻擊行為。包含 SQL InjectionXSS 跨站腳本 以及非法檔案存取嘗試。提供管理者作為防火牆黑名單設定參考。

最後更新:2026-09-19 03:22:15   📥 下載完整報告

時間攻擊名稱來源 IP (下載威脅IP清單)動作
-Bladabindi.Botnet66.240.205.34dropped
-zlib.Library.inflateGetHeader.Handling.Buffer.Overflow54.159.98.248dropped
-PHP.CGI.Argument.Injection45.156.87.125dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal45.156.129.112dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal45.156.129.112dropped
-Telerik.Web.UI.RadAsyncUpload.Handling.Arbitrary.File.Upload45.156.129.112dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal45.156.128.175dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal45.156.128.174dropped
-Telerik.Web.UI.RadAsyncUpload.Handling.Arbitrary.File.Upload45.156.128.175dropped
-Backdoor.Chisel195.170.172.118dropped
-Spring.Boot.Actuator.Unauthorized.Access38.43.93.233dropped
-Bladabindi.Botnet146.190.134.221dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-zlib.Library.inflateGetHeader.Handling.Buffer.Overflow18.215.112.101dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal134.195.89.159dropped
-AndroxGh0st.Malware216.144.225.2dropped
-D-Link.Devices.HNAP.SOAPAction-Header.Command.Execution175.107.12.59dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal165.99.207.153dropped
-HTTP.URI.SQL.Injection45.43.65.144dropped
-HTTP.URI.SQL.Injection188.215.5.214dropped
-HTTP.URI.SQL.Injection45.43.64.151dropped
-HTTP.URI.SQL.Injection104.143.245.115dropped
-WordPress.REST.API.batch-route.SQL.Injection62.60.130.230dropped
-WordPress.REST.API.batch-route.SQL.Injection62.60.130.230dropped
-HTTP.URI.SQL.Injection92.112.171.198dropped
-React.Server.Components.react-flight.Remote.Code.Execution82.29.165.252dropped
-PHP.CGI.Argument.Injection45.156.87.125dropped
-React.Server.Components.react-flight.Remote.Code.Execution187.127.116.81dropped
-HTTP.Negative.Content.Length172.233.189.197dropped
-HTTP.Negative.Content.Length172.233.189.197dropped
-HTTP.Negative.Content.Length172.233.189.197dropped
-HTTP.Negative.Content.Length172.233.189.197dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass34.27.109.32dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass35.237.25.109dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass34.26.87.206dropped
-HTTP.URI.SQL.Injection179.97.71.131dropped
-HTTP.URI.SQL.Injection179.97.71.131dropped
-HTTP.URI.SQL.Injection179.97.71.131dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass34.62.226.41dropped
-React.Server.Components.react-flight.Remote.Code.Execution52.185.93.127dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass104.199.183.223dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass35.194.244.188dropped
-NETGEAR.DGN1000.CGI.Unauthenticated.Remote.Code.Execution175.107.216.91dropped
-Cross.Site.Scripting59.120.73.33detected
-Cross.Site.Scripting5.175.189.35detected
-Generic.Path.Traversal.Detection5.175.189.35dropped
IPS 網路威脅即時報告與惡意 IP 監控 - 2ns.org

🔥 IPS 威脅報告與惡意 IP 監控

本報告彙整了 2ns.org 監測節點偵測到的即時攻擊行為。包含 SQL InjectionXSS 跨站腳本 以及非法檔案存取嘗試。提供管理者作為防火牆黑名單設定參考。

最後更新:2026-09-19 03:22:15   📥 下載完整報告

時間攻擊名稱來源 IP (下載威脅IP清單)動作
-Bladabindi.Botnet66.240.205.34dropped
-zlib.Library.inflateGetHeader.Handling.Buffer.Overflow54.159.98.248dropped
-PHP.CGI.Argument.Injection45.156.87.125dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal45.156.129.112dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal45.156.129.112dropped
-Telerik.Web.UI.RadAsyncUpload.Handling.Arbitrary.File.Upload45.156.129.112dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal45.156.128.175dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal45.156.128.174dropped
-Telerik.Web.UI.RadAsyncUpload.Handling.Arbitrary.File.Upload45.156.128.175dropped
-Backdoor.Chisel195.170.172.118dropped
-Spring.Boot.Actuator.Unauthorized.Access38.43.93.233dropped
-Bladabindi.Botnet146.190.134.221dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-PHPUnit.Eval-stdin.PHP.Remote.Code.Execution212.200.238.150dropped
-zlib.Library.inflateGetHeader.Handling.Buffer.Overflow18.215.112.101dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal134.195.89.159dropped
-AndroxGh0st.Malware216.144.225.2dropped
-D-Link.Devices.HNAP.SOAPAction-Header.Command.Execution175.107.12.59dropped
-Apache.HTTP.Server.cgi-bin.Path.Traversal165.99.207.153dropped
-HTTP.URI.SQL.Injection45.43.65.144dropped
-HTTP.URI.SQL.Injection188.215.5.214dropped
-HTTP.URI.SQL.Injection45.43.64.151dropped
-HTTP.URI.SQL.Injection104.143.245.115dropped
-WordPress.REST.API.batch-route.SQL.Injection62.60.130.230dropped
-WordPress.REST.API.batch-route.SQL.Injection62.60.130.230dropped
-HTTP.URI.SQL.Injection92.112.171.198dropped
-React.Server.Components.react-flight.Remote.Code.Execution82.29.165.252dropped
-PHP.CGI.Argument.Injection45.156.87.125dropped
-React.Server.Components.react-flight.Remote.Code.Execution187.127.116.81dropped
-HTTP.Negative.Content.Length172.233.189.197dropped
-HTTP.Negative.Content.Length172.233.189.197dropped
-HTTP.Negative.Content.Length172.233.189.197dropped
-HTTP.Negative.Content.Length172.233.189.197dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass34.27.109.32dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass35.237.25.109dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass34.26.87.206dropped
-HTTP.URI.SQL.Injection179.97.71.131dropped
-HTTP.URI.SQL.Injection179.97.71.131dropped
-HTTP.URI.SQL.Injection179.97.71.131dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass34.62.226.41dropped
-React.Server.Components.react-flight.Remote.Code.Execution52.185.93.127dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass104.199.183.223dropped
-Vercel.Next.js.x-middleware-subrequest.Authentication.Bypass35.194.244.188dropped
-NETGEAR.DGN1000.CGI.Unauthenticated.Remote.Code.Execution175.107.216.91dropped
-Cross.Site.Scripting59.120.73.33detected
-Cross.Site.Scripting5.175.189.35detected
-Generic.Path.Traversal.Detection5.175.189.35dropped