๐จ๐ฑ
rvalderrama
2022-12-19 09:50:10
(3 years ago)
Reporte abuso de IP | PHP/Agent.NFA!tr
Brute-Force
Exploited Host
๐จ๐ญ
backslash
2022-12-08 03:55:37
(3 years ago)
Bad Web Bot
๐ง๐ช
Ivo Vynckier
2022-11-18 13:58:13
(3 years ago)
Brute-force PHP/Wordpress attack.
Brute-Force
Web App Attack
Anonymous
2022-11-17 14:20:56
(3 years ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/style.php
Web App Attack
๐ฎ๐ฉ
hermawan
2022-11-17 07:55:59
(3 years ago)
[Thu Nov 17 19:55:56.524947 2022] [-:error] [pid 81923:tid 140438892750400] [client 13.59.239.178:49 ...
show more
[Thu Nov 17 19:55:56.524947 2022] [-:error] [pid 81923:tid 140438892750400] [client 13.59.239.178:49722] [client 13.59.239.178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "155"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-includes/css/wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/wp-includes/css/wp-config.php"] [unique_id "Y3YvXFhK3CBYVnXtY1TmtQAAALw"], referer www.bing.com [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[81958] [XnQlHBrcpKk] [Y3YvXFhK3CBYVnXtY1TmtQAAALw] keep_alive=[0
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2022-11-16 14:20:00
(3 years ago)
[Thu Nov 17 02:19:56.644009 2022] [-:error] [pid 73945:tid 139735265572416] [client 13.59.239.178:61 ...
show more
[Thu Nov 17 02:19:56.644009 2022] [-:error] [pid 73945:tid 139735265572416] [client 13.59.239.178:61748] [client 13.59.239.178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "155"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-includes/css/wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/wp-includes/css/wp-config.php"] [unique_id "Y3U33DxKZIflellKO7hYOwAAAAs"], referer www.bing.com [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[73978] [50GJW6vms7w] [Y3U33DxKZIflellKO7hYOwAAAAs] keep_alive=[0
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Secmon
2022-11-16 07:16:03
(3 years ago)
Attack Web
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2022-11-16 06:13:56
(3 years ago)
[Wed Nov 16 18:12:42.975865 2022] [-:error] [pid 328087:tid 140196860421696] [client 13.59.239.178:5 ...
show more
[Wed Nov 16 18:12:42.975865 2022] [-:error] [pid 328087:tid 140196860421696] [client 13.59.239.178:55312] [client 13.59.239.178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "155"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: wp-config.php found within REQUEST_FILENAME: /wp-includes/css/wp-config.php"] [severity "CRITICAL"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/wp-includes/css/wp-config.php"] [unique_id "Y3TFqk2kEtH5yAytYDVIyQAAAB0"], referer www.bing.com [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[328113] [QnghjeQa93s] [Y3TFqk2kEtH5yAytYDVIyQAAAB0] keep_alive=
...
show less
Hacking
Web App Attack
๐ฌ๐ง
Apache
2022-11-12 06:24:53
(3 years ago)
(mod_security) mod_security (id:20000010) triggered by 13.59.239.178 (US/United States/ec2-13-59-239 ...
show more
(mod_security) mod_security (id:20000010) triggered by 13.59.239.178 (US/United States/ec2-13-59-239-178.us-east-2.compute.amazonaws.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
gu-alvareza
2022-11-10 13:15:44
(3 years ago)
WordPress.REST.API.Username.Enumeration.Information.Disclosure
Web App Attack
๐บ๐ธ
SiliSoftware
2022-11-10 09:35:49
(3 years ago)
/wp-content/themes/seotheme/db.php?u
Web App Attack
๐บ๐ธ
TheMadBeaker
2022-11-10 00:25:25
(3 years ago)
Fail2Ban Ban Triggered
Wordpress Attack Attempt
Brute-Force
Web App Attack
๐ช๐ธ
10dencehispahard SL
2022-11-09 23:39:16
(3 years ago)
Abusive use detected
Brute-Force
๐ฎ๐ฉ
hermawan
2022-11-08 17:25:09
(3 years ago)
[Wed Nov 09 05:25:00.076060 2022] [-:error] [pid 222831:tid 140172540577344] [client 13.59.239.178:5 ...
show more
[Wed Nov 09 05:25:00.076060 2022] [-:error] [pid 222831:tid 140172540577344] [client 13.59.239.178:51274] [client 13.59.239.178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0-rc1/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "144"] [id "913101"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.28.1"] [severity "CRITICAL"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "karangploso.jatim.bmkg.go.id"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "Y2rXPORPS2ejXfUO8WMjvwAAADY"] [karangploso.jatim.bmkg.go.id] [karangploso.jatim.bmkg.go.id] top=[222857] [nW24Ao1
...
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2022-11-08 10:04:12
(3 years ago)
Too many Status 40X (21)
Brute-Force
Web App Attack