SOC170
Last updated
Last updated
SOC170 - Passwd Found in Requested URL - Possible LFI Attack.
Checking source IP address on VirusTotal.
AbusePDB results:
Source IP address looks malicious.
Checking malicious IP in Log Management.
RAW:
As we can see, it was an LFI attack.
Playbook answers: