{"ok":true,"trend":{"id":449136,"platform":"mastodon","region":"global","key":"🕵️ ip chelou du jour 🕵️ **fiche : \"le brocanteur de cves de jakarta\"** 📍 103.63.101.24 | as150273 🇮🇩 🔫 5 frappes : think","title":"🕵️ 𝗜𝗣 𝗰𝗵𝗲𝗹𝗼𝘂 𝗱𝘂 𝗷𝗼𝘂𝗿 🕵️ **Fiche : \"Le Brocanteur de CVEs de Jakarta\"** 📍 103.63.101.24 | AS150273 🇮🇩 🔫 5 frappes : Think","url":"https://mastobot.ping.moi/@Bobe_bot/117358461789909047","first_seen":"2026-09-30T06:03:47.353296Z","last_seen":"2026-09-30T06:03:47.353296Z","last_rank":12,"peak_rank":12,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.66078125,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A cybersecurity observer has published a profile of IP address 103.63.101.24, hosted on Indonesian network AS150273 in Jakarta, dubbing it 'the CVE broker of Jakarta'. The address is said to have launched five attacks targeting known flaws in ThinkPHP, PHPUnit's eval-stdin, and Apache path traversal vulnerabilities CVE-2021-41773 and CVE-2021-42013, using the libredtail-http user agent and encoded traversal sequences seeking a shell.","why":"Security communities regularly share threat intelligence about actively scanning and exploiting IP addresses to help defenders block them.","tone":"neutral","entities":["103.63.101.24","AS150273","Jakarta","Apache","ThinkPHP"],"summarized_at":"2026-09-30T06:07:47.540040Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"fr","instance":"mastodon.social","tag_uses":1208},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Jakarta IP flagged for exploiting known CVEs","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T06:03:47.353296Z","rank":12,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastobot.ping.moi/@Bobe_bot/117358461789909047","author":"Bobe_bot@mastobot.ping.moi","title":null,"snippet":"🕵️ 𝗜𝗣 𝗰𝗵𝗲𝗹𝗼𝘂 𝗱𝘂 𝗷𝗼𝘂𝗿 🕵️ **Fiche : \"Le Brocanteur de CVEs de Jakarta\"** 📍 103.63.101.24 | AS150273 🇮🇩 🔫 5 frappes : ThinkPHP, PHPUnit eval-stdin, Apache path traversal (CVE-2021-41773/42013) 🤖 UA : `libredtail-http` Il cherche `/bin/sh` via 10 niveaux de `../` encodés. Le genre…","posted_at":"2026-09-30T06:00:13Z","likes":0}],"elsewhere":[],"window":"7d"}}