๐ซ๐ท
oh.mg
2024-12-05 14:59:42
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 146.56.46.125 (KR/South Korea/-): 1 in the last ...
show more
(mod_security) mod_security (id:949110) triggered by 146.56.46.125 (KR/South Korea/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Thu Dec 05 14:59:36.464060 2024] [:error] [pid 2686191:tid 140622681839360] [client 146.56.46.125:12997] [client 146.56.46.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "oh.mg"] [uri "/php-cgi/php-cgi.exe"] [unique_id "Z1G-2O8jxeNVwCRjpyRI5QAAAFI"], referer: http://oh.mg/php-cgi/php-cgi.exe?%add+allow_url_include%3d1+%add+auto_prepend_file%3dphp://input
show less
Port Scan
๐ฎ๐ช
RoboSOC
2024-12-05 12:37:26
(1 year ago)
ThinkPHP Remote Code Execution Vulnerability , PTR: PTR record not found
Web App Attack
๐บ๐ธ
AbuseIPDB
AbuseIPDB Official
2024-12-05 08:20:18
(1 year ago)
Suspicious Operation. Request content:
_method=__construct&method=GET&filter[]=system&get[]=echo ^xi ...
show more
Suspicious Operation. Request content:
_method=__construct&method=GET&filter[]=system&get[]=echo ^xinghuoxise^--xinghuoxise >xxxx.php
show less
Web App Attack
๐จ๐ญ
zynex
2024-11-20 00:06:38
(1 year ago)
Backdoor file upload: 1.asp
Web App Attack
๐ฏ๐ต
VXG-NET
2024-11-19 20:26:41
(1 year ago)
port=80, indicator_type=sql-injection
SQL Injection
๐ฏ๐ต
VXG-NET
2024-11-19 20:26:41
(1 year ago)
port=80, indicator_type=sql-injection
SQL Injection
๐ซ๐ท
geot
2024-11-19 13:45:27
(1 year ago)
26 requests, including :
GET /wp-includes/css/admin-bar.css HTTP/1.1
GET /<<removed>>/index.php?c=l ...
show more
26 requests, including :
GET /wp-includes/css/admin-bar.css HTTP/1.1
GET /<<removed>>/index.php?c=login HTTP/1.1
GET /template/pc/index.htm HTTP/1.1
GET /e/tool/feedback/temp/test.txt HTTP/1.1
GET /cswl/index.php?c=login HTTP/1.1
GET /zb_users/theme/default/theme.xml HTTP/1.1
GET /admin_2024/index.php?c=login HTTP/1.1
GET /cswls_2024/index.php?c=login HTTP/1.1
GET /data/admin/allowurl.txt HTTP/1.1
GET /zb_users/THEME/default/theme.xml HTTP/1.1
GET /static/js/at.js HTTP/1.1
GET /template/default/index.html HTTP/1.1
GET /admin/index.php?c=login HTTP/1.1
show less
Web App Attack
Anonymous
2024-11-18 17:35:23
(1 year ago)
wordpress-trap
Web App Attack
๐ฉ๐ช
ps-center
2024-11-17 22:37:31
(1 year ago)
HHV: Web Attack GET /admin/index.php?c=login
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Charles
2024-11-16 20:01:56
(1 year ago)
146.56.46.125 - - [17/Nov/2024:04:01:54 +0800] "GET /data/admin/allowurl.txt HTTP/1.1" 404 2110 "htt ...
show more
146.56.46.125 - - [17/Nov/2024:04:01:54 +0800] "GET /data/admin/allowurl.txt HTTP/1.1" 404 2110 "http://www.amstarcreative.com/data/admin/allowurl.txt" "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)"
...
show less
Web Spam
Email Spam
Brute-Force
Bad Web Bot
Web App Attack
SSH
๐จ๐ฆ
polycoda
2024-11-11 11:15:49
(1 year ago)
๐ Probes for tons of inexistent files and PHP scripts
Hacking
Web App Attack
๐ต๐น
Information Security
2024-11-10 17:51:36
(1 year ago)
Web App Attack
Web App Attack
๐บ๐ธ
AbuseIPDB
AbuseIPDB Official
2024-11-09 11:19:25
(1 year ago)
Suspicious Operation. Request content:
_method=__construct&method=GET&filter[]=system&get[]=echo ^xi ...
show more
Suspicious Operation. Request content:
_method=__construct&method=GET&filter[]=system&get[]=echo ^xinghuoxise^--xinghuoxise >xxxx.php
show less
Web App Attack
๐ซ๐ท
oh.mg
2024-11-09 10:44:00
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 146.56.46.125 (KR/South Korea/-): 1 in the last ...
show more
(mod_security) mod_security (id:949110) triggered by 146.56.46.125 (KR/South Korea/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Sat Nov 09 10:43:50.452418 2024] [:error] [pid 3037362:tid 140622945052416] [client 146.56.46.125:27961] [client 146.56.46.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "oh.mg"] [uri "/index.php"] [unique_id "Zy885qJNb2pEiXC7YU9VPwAAAMQ"], referer: https://oh.mg/index.php?s=captcha
show less
Port Scan
๐ณ๐ฑ
Roderic
2024-11-05 15:09:15
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 146.56.46.125 (KR/So ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 146.56.46.125 (KR/South Korea/-)
show less
Bad Web Bot