๐ช๐ธ
el-brujo
2024-02-06 09:24:19
(2 years ago)
DDoS Attack Layer 7 using Mikrotik devices
DDoS Attack
๐ท๐บ
nyuuzyou
2024-02-03 07:11:26
(2 years ago)
{"action": "connection", "dest_ip": "0.0.0.0", "dest_port": "22", "server": "ssh_server", "src_ip": ...
show more
{"action": "connection", "dest_ip": "0.0.0.0", "dest_port": "22", "server": "ssh_server", "src_ip": "103.166.29.127", "src_port": "36824", "timestamp": "2024-02-03T07:11:07.145395"}
show less
Brute-Force
SSH
Anonymous
2024-01-23 11:20:00
(2 years ago)
Spam-Bot-Netz kompromittiertes Postfach
Exploited Host
Anonymous
2024-01-23 11:20:00
(2 years ago)
Spam-Bot-Netz kompromittiertes Postfach
Exploited Host
๐ฉ๐ช
Packets-Decreaser.NET
2024-01-23 10:13:08
(2 years ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2024-01-14 23:10:55
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 103.166.29.127 (rdns-103-166-29-127.gmdp.net.id ...
show more
(mod_security) mod_security (id:210730) triggered by 103.166.29.127 (rdns-103-166-29-127.gmdp.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 14 18:10:47.310974 2024] [security2:error] [pid 17489:tid 47501673506560] [client 103.166.29.127:43683] [client 103.166.29.127] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||quantumgaze.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "quantumgaze.com"] [uri "/wp-content/mysql.sql"] [unique_id "ZaRp97kkRGtrkti51JafhQAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2023-12-12 12:02:32
(2 years ago)
[Tue Dec 12 19:02:30.957741 2023] [security2:error] [pid 16640:tid 139750350501440] [client 103.166. ...
show more
[Tue Dec 12 19:02:30.957741 2023] [security2:error] [pid 16640:tid 139750350501440] [client 103.166.29.127:50461] [client 103.166.29.127] ModSecurity: Access denied with code 403 (phase 1). String match within "/accept-charset/ /content-encoding/ /content-range/ /identity/ /if/ /lock-token/ /proxy/ /x-http-method/ /x-http-method-override/ /x-method-override/ " at TX:header_name_accept-charset. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1500"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: Matched Data: cookie found within TX:header_name_accept-charset: /accept-charset/ request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/555560378-prakiraan-bulanan-curah-hujan-bulan-desember-tahun-2023-update-dari-analisis-bulan-agustus-tahun-2023-di-provinsi-jawa-timur HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-mul
...
show less
Hacking
Web App Attack
๐จ๐ญ
unifr
2023-12-03 05:50:19
(2 years ago)
Unauthorized IMAP connection attempt
Brute-Force
๐ณ๐ฑ
Samuil Warshan
2023-11-17 13:46:37
(2 years ago)
F2B blocked SSH BF
Brute-Force
SSH
๐ฎ๐ฉ
hermawan
2023-11-08 10:32:57
(2 years ago)
[Wed Nov 08 17:32:54.515831 2023] [security2:error] [pid 448295:tid 139675138250304] [client 103.166 ...
show more
[Wed Nov 08 17:32:54.515831 2023] [security2:error] [pid 448295:tid 139675138250304] [client 103.166.29.127:54437] [client 103.166.29.127] ModSecurity: Access denied with code 403 (phase 2). String match within "/accept-charset/ /content-encoding/ /identity/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ " at TX:header_name_accept-charset. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1402"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: Matched Data: cookie found within TX:header_name_accept-charset: /accept-charset/ request_line = GET /index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-bojonegoro HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2023-09-28 06:45:11
(2 years ago)
[Thu Sep 28 13:45:10.879418 2023] [security2:error] [pid 29895:tid 139817560045120] [client 103.166. ...
show more
[Thu Sep 28 13:45:10.879418 2023] [security2:error] [pid 29895:tid 139817560045120] [client 103.166.29.127:51620] [client 103.166.29.127] ModSecurity: Access denied with code 403 (phase 2). String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1397"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: Matched Data: cookie found within TX:header_name_accept-charset: /accept-charset/ request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/555560272-prakiraan-bulanan-curah-hujan-bulan-oktober-tahun-2023-update-dari-analisis-bulan-juni-tahun-2023-di-provinsi-jawa-timur HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [t
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2023-09-01 11:44:53
(3 years ago)
[Fri Sep 01 18:44:50.097993 2023] [security2:error] [pid 579447:tid 140422334576192] [client 103.166 ...
show more
[Fri Sep 01 18:44:50.097993 2023] [security2:error] [pid 579447:tid 140422334576192] [client 103.166.29.127:41352] [client 103.166.29.127] ModSecurity: Access denied with code 403 (phase 1). Match of "pm www.google.com myactivity.google.com applebot iPhone bingbot https://yandex.com/ https://www.google.com.tw sih3.dpuair.jatimprov.go.id duckduckgo.com neeva.com mail.google.com dpuair.jatimprov.go.id facebookbot https://www.ecosia.org/ https://duckduck ..." against "REQUEST_HEADERS:Referer" required. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "59"] [id "440067"] [msg "BAD Referer"] [data "Matched Data: staklim-jatim.bmkg.go.id found within REQUEST_HEADERS:Referer: https://homepage.mintnav.com/ request_line = GET /index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-bojonegoro HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-of-all-tags/prakiraan-cuaca-bojonegoro"] [u
...
show less
Hacking
Web App Attack
๐จ๐ฆ
basedchad
2023-08-24 01:34:42
(3 years ago)
This IP was blocked and reported due to suspicious activity recorded on one of https://loadtesting.m ...
show more
This IP was blocked and reported due to suspicious activity recorded on one of https://loadtesting.me servers.
show less
DDoS Attack
Port Scan
Brute-Force
๐จ๐ฆ
basedchad
2023-08-21 04:08:07
(3 years ago)
This IP was blocked and reported due to suspicious activity recorded on one of https://loadtesting.m ...
show more
This IP was blocked and reported due to suspicious activity recorded on one of https://loadtesting.me servers.
show less
DDoS Attack
Port Scan
Brute-Force
๐ณ๐ฑ
true.nl
2023-08-17 11:47:00
(3 years ago)
This IP participated in a 80.000 requests a second HTTP ddos flood on www.kanker.nl ipv4: 87.233.198 ...
show more
This IP participated in a 80.000 requests a second HTTP ddos flood on www.kanker.nl ipv4: 87.233.198.114 ipv6: 2001:9a8:a6:0:87:233:198:114
show less
DDoS Attack