CVE report
CVE-2024-44000high
LiteSpeed Cache <= 6.4.1 - Sensitive Information Exposure
Events 90d
167
Distinct IPs
126
Severity
high
CISA KEV
Not listed
Detection signature
An event counts toward CVE-2024-44000 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- · /wp-content/debug.log
Pre-disclosure activity
all early actors →Analysing probe history around the publication date…
Recent probe volume (last 7 days)
peak: 53 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2024-44000
- 195.128.248.339 eventsUkraine· Virtual Systems LLC
- 104.248.117.796 eventsUnited States· DigitalOcean, LLC
- 38.127.60.254 eventsUnited States· Enzu Inc
- 147.182.181.393 eventsUnited States· DigitalOcean, LLC
- 163.192.193.2123 eventsUnited States· Oracle Corporation
- 206.189.197.1433 eventsUnited States· DigitalOcean, LLC
- 45.148.10.183 eventsThe Netherlands· Techoff Srv Limited
- 195.178.110.723 eventsBulgaria· Techoff Srv Limited
- 147.139.178.2143 eventsIndonesia· Alibaba (US) Technology Co., Ltd.
- 192.34.56.162 eventsUnited States· DigitalOcean, LLC
- 51.81.153.402 eventsUnited States· OVH SAS
- 67.205.130.32 eventsUnited States· DigitalOcean, LLC
- 45.148.10.282 eventsThe Netherlands· Techoff Srv Limited
- 195.178.110.1332 eventsBulgaria· Techoff Srv Limited
- 62.182.82.2392 eventsUkraine· Virtual Systems LLC
- 137.184.53.2042 eventsUnited States· DigitalOcean, LLC
- 134.122.58.2542 eventsNetherlands· DigitalOcean, LLC
- 157.245.247.712 eventsUnited States· DigitalOcean, LLC
- 162.243.172.1152 eventsUnited States· DigitalOcean, LLC
- 103.168.67.1592 eventsUnited States· DIGI VPS
- 142.248.80.2452 eventsUnited States· Advin Services LLC
- 161.35.3.742 eventsUnited States· DigitalOcean, LLC
- 142.93.251.401 eventsUnited States· DigitalOcean, LLC
- 159.89.55.2151 eventsUnited States· DigitalOcean, LLC
- 195.178.110.1041 eventsBulgaria· Techoff Srv Limited
- 192.241.130.1201 eventsUnited States· DigitalOcean, LLC
- 103.168.66.2371 eventsUnited States· DIGI VPS
- 146.190.222.2291 eventsUnited States· DigitalOcean, LLC
- 137.220.43.791 eventsUnited States
- 104.248.228.1381 eventsUnited States· DigitalOcean, LLC
Top networks the attempts come from
- AS14061 DigitalOcean, LLC98 IPs · 114 ev
- AS48090 Techoff Srv Limited9 IPs · 15 ev
- AS6698 Virtual Systems LLC1 IPs · 9 ev
- AS18978 Enzu Inc1 IPs · 4 ev
- AS142430 DIGI VPS3 IPs · 4 ev
- AS31898 Oracle Corporation2 IPs · 4 ev
- AS45102 Alibaba (US) Technology Co., Ltd.1 IPs · 3 ev
- AS211590 Bucklog SARL3 IPs · 3 ev
- AS16276 OVH SAS1 IPs · 2 ev
- AS22295 Advin Services LLC1 IPs · 2 ev
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
ja4h: ge11nn0400_88d30a62b7adja4h: ge11nr18en_a257ebcb3fdeja4h: ge11nn0400_cf1edba2959cja4h: ge11nn0200_fdb5000be5f4ja4h: ge11nn05en_813e32c09d15ja4h: ge11nn0300_042112399351ja4: t13i311000_e8f1e7e78f70_d41ae481755eja4: t13i130900_f57a46bbacb6_e7c285222651ja4: t13i1010h1_61a7ad8aa9b6_3a8073edd8efja4: t13i151000_8daaf6152771_ab7e3b40a677ja4: t13i131000_f57a46bbacb6_ab7e3b40a677
Sample request paths observed
- /wp-content/debug.log?_=4i2o7gju&v=62kzx
- /logs/wp-content/debug.log
- /wp-content/debug.log?_=q8vphiae&v=o2z2b
- /wp-content/debug.log?_=bxyh43no&v=hjj58
- /wp-content/debug.log
- /wp-content/debug.log?_=iy9s3c7d&v=9o2gg
- /wp-content/uploads/wp-content/debug.log
- /wp-content/debug.log?_=h6tyjf7m&v=x1u5y
- /wp-content/debug.log?_=a5r1afeo&v=352dx
- /wp-content/debug.log?_=0n8cjsnt&v=2vi7m