Scans Targeting Hospitality Applications, (Wed, Sep 16th)
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Industries
- Healthcare
- Reported by
- 1 outlet
Earlier today, I noted an odd request showing up in our "First Seen" report:
GET /PIAF-HMS/ HTTP/1.1 Host: [redacted] User-Agent: Farez-Sorter/1.0 Accept-Encoding: gzip
This request is linked to a rather old application, a "PBX in a Flash Hospitality Management System" [1]. The last update, the addition of a license file, happened 10 years ago, and I would consider the project abandoned. However, I also noted a new vulnerability reported a couple of months ago: An SQL injection issue. A quick scan of the code shows many more, and the author does not believe in input validation at all. I am also not seeing any authentication and access control, but I have a suspicion that this code may never have been used, and may be intended more as a lab/experiment to test some Asterix PBX integration. With that, I was about to move on.
However, looking at the somewhat odd user agent, I found a few other similar requests:
/admin/
/admin/config.php
/ucp/
/hms/
/hotel/
The scans started yesterday and have been continuing today. The only source IP for the scans is 94.102.49.125. This IP address is associated with IP Volume ( AS202425), which is often considered a bulletproof hoster. Hotels are often "soft targets" for attackers seeking to steal valuable personal data. In some cases, they have been compromised to launch MitM attacks against guests. The focus on PBX systems is interesting, and maybe there are some tricks that could be played on guests if an attacker can appear to call from "inside" the property.
Please let me know if you have some insight as to what is going on here.
[1] https://github.com/claudiopizzillo/PIAF-HMS
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|
Originally published by SANS Internet Storm Center. © SANS Internet Storm Center.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-16 18:44 UTC
Related stories
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
The Hacker News · 2026-10-02
- Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Infosecurity Magazine · 2026-10-02
- ISC Stormcast For Friday, October 2nd, 2026 https://isc.sans.edu/podcastdetail/10120, (Fri, Oct 2nd)
SANS Internet Storm Center · 2026-10-02
- Microsoft says threat actors are ahead in the early AI race
BleepingComputer · 2026-10-01
- Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
The Record · 2026-10-01