๐บ๐ธ
TPI-Abuse
2024-08-10 00:45:49
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 109.120.152.26 (ready-rat_n1.aeza.network): 1 i ...
show more
(mod_security) mod_security (id:234930) triggered by 109.120.152.26 (ready-rat_n1.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 20:45:43.777385 2024] [security2:error] [pid 4041:tid 4041] [client 109.120.152.26:54802] [client 109.120.152.26] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.mounthoodhistory.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.mounthoodhistory.com"] [uri "/tag/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "Zra4N0uwGzvFZNnxcFZ9PwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-10 00:40:25
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-08-09 22:04:00
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 109.120.152.26 (ready-rat_n1.aeza.network): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 109.120.152.26 (ready-rat_n1.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 18:03:51.881719 2024] [security2:error] [pid 864823:tid 864823] [client 109.120.152.26:57904] [client 109.120.152.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||meganmurph.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "meganmurph.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "ZraSR7PE7WkrkX28IuHEwQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2024-08-09 16:48:08
(2 years ago)
Multiple unauthorized attempts to access web resources
Brute-Force
Web App Attack
๐บ๐ธ
rsa
2024-08-09 16:45:00
(2 years ago)
POST /admin/index.php?route=common/login HTTP/1.1
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 14:33:37
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 109.120.152.26 (ready-rat_n1.aeza.network): 1 i ...
show more
(mod_security) mod_security (id:234930) triggered by 109.120.152.26 (ready-rat_n1.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 10:33:29.826850 2024] [security2:error] [pid 19320:tid 19334] [client 109.120.152.26:49268] [client 109.120.152.26] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.killasgarage.bike|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.killasgarage.bike"] [uri "/uncategorized/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ZrYouWBswx0SWhzqUclslgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2024-08-09 05:19:34
(2 years ago)
Drupal Authentication failure
Brute-Force
Web App Attack
๐ฎ๐ฉ
hermawan
2024-08-09 05:05:48
(2 years ago)
[Fri Aug 09 12:03:43.519973 2024] [authz_core:error] [pid 1108259:tid 134777537562176] [client 109.1 ...
show more
[Fri Aug 09 12:03:43.519973 2024] [authz_core:error] [pid 1108259:tid 134777537562176] [client 109.120.152.26:37690] AH01630: client denied by server configuration: /var/www/administrator/ [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[1108323] [ZVlAEWESGTI] [ZrWjL3RrgKkkhHf5SIIoMwAAANY] keep_alive=[0] [2024-08-09 12:03:43.519979] [R:ZrWjL3RrgKkkhHf5SIIoMwAAANY] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8' Accept-Encoding:'gzip, deflate Accept-Language:'en-US,en;q=0.5 Upgrade-Insecure-Requests:'1
...
show less
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2024-08-09 03:42:24
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2024-08-08 23:28:03
(2 years ago)
1.479 requests to */xmlrpc.php
Brute-Force
Bad Web Bot
๐ฎ๐ฉ
kadosmekaten
2024-08-08 22:58:00
(2 years ago)
109.120.152.26 - - [09/Aug/2024:05:58:29 +0700] "POST /admin/index.php?route=common/login HTTP/1.1" ...
show more
109.120.152.26 - - [09/Aug/2024:05:58:29 +0700] "POST /admin/index.php?route=common/login HTTP/1.1" 200 2603 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
show less
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2024-08-08 20:54:06
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TheMadBeaker
2024-08-08 20:47:54
(2 years ago)
Fail2Ban Ban Triggered
HTTP SQL Injection Attempt
Hacking
SQL Injection
๐ฒ๐พ
syokadmin
2024-08-08 20:47:41
(2 years ago)
(mod_security) mod_security (id:77140834) triggered by 109.120.152.26 (RU/Russia/ready-rat_n1.aeza.n ...
show more
(mod_security) mod_security (id:77140834) triggered by 109.120.152.26 (RU/Russia/ready-rat_n1.aeza.network): 1 in the last 3600 secs
show less
Brute-Force