CVE-2017-9841: PHPUnit - Remote Code Execution

HoneyLabs honeypots recorded 2,426 probes matching CVE-2017-9841 from 50 distinct source IP addresses in the last 7 days. Severity is rated critical.

This CVE is on CISA's Known Exploited Vulnerabilities list.

Request paths that identify it

  • /lib/phpunit/Util/PHP/eval-stdin.php
  • /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
  • /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php
  • /lib/phpunit/phpunit/Util/PHP/eval-stdin.php
  • /phpunit/phpunit/src/Util/PHP/eval-stdin.php
  • /phpunit/Util/PHP/eval-stdin.php

Addresses probing it

Source IPProbesNetworkCountry
31.132.90.3216Kar-Tel LLCKazakhstan
95.173.161.147144Netinternet Bilisim Teknolojileri ASTürkiye
138.2.102.66144Oracle CorporationSingapore
171.244.14.216108CHT Compamy LtdVietnam
223.123.92.77108CMPak LimitedPakistan
212.47.66.21872Contabo GmbHFrance
87.192.253.11072Uzbektelekom Joint Stock CompanyUzbekistan
103.46.186.14872PT Air Lintas KomunikasiIndonesia

Networks it comes from

ASNOrganisationProbesSource IPs
AS197556Kar-Tel LLC2161
AS51167Contabo GmbH1804
AS31898Oracle Corporation1441
AS51559Netinternet Bilisim Teknolojileri AS1441
AS59257CMPak Limited1442
AS38731CHT Compamy Ltd1081

Captured requests

  • /vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
  • /vendor/phpunit/src/Util/PHP/eval-stdin.php
  • /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php
  • /phpunit/phpunit/src/Util/PHP/eval-stdin.php

HTTP client fingerprints (JA4H)

  • ge11nn0700_3161ce9d7233
  • ge11nn0700_c5a94e7539c9
  • ge11nn0600_285c7a41a4af
  • ge11nn0700_7d7c303481e6

CVE report

CVE report

Open a specific CVE from the CVE tracker.