๐ฎ๐ฉ
[email protected]
2024-06-25 07:32:00
(2 years ago)
Attempts to find pages that do not exist on my site.
Web App Attack
๐ฎ๐ฉ
hermawan
2024-06-08 00:24:31
(2 years ago)
[Sat Jun 08 07:24:25.680942 2024] [security2:error] [pid 493113:tid 123554643314240] [client 157.230 ...
show more
[Sat Jun 08 07:24:25.680942 2024] [security2:error] [pid 493113:tid 123554643314240] [client 157.230.35.50:60695] [client 157.230.35.50] ModSecurity: Access denied with code 403 (phase 2). Pattern match "." at ARGS_NAMES:bx. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-921-PROTOCOL-ATTACK.conf"] [line "643"] [id "921170"] [msg "HTTP Parameter Pollution ()"] [data "Matched Data: b found within ARGS_NAMES:bx: bx request_line = GET /alfacgiapi/radio.php?bx=0e215962017 HTTP/1.1"] [ver "OWASP_CRS/4.3.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "capec/1000/152/137/15/460"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/alfacgiapi/radio.php"] [unique_id "ZmOkuWpbWDwfqo-i4b4dVgAAAJ4"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[493185] [E9lB8D1jS/A] [ZmOkuWpbWDwfqo-i4b4dVgAAAJ4] keep_alive=[0] [2024-06-08 07:24:25.680947] [R:ZmOkuWpbWDwfqo-i4b4dVgAAAJ4] UA:'Mozilla/5.0 (Linux; Android 11; Red
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Incidents Response Neptus Team
2024-06-07 06:16:00
(2 years ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐ฎ๐ฉ
Incidents Response Neptus Team
2024-06-07 03:55:00
(2 years ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐ฎ๐ฉ
hermawan
2024-06-06 13:07:27
(2 years ago)
[Thu Jun 06 20:07:23.161459 2024] [authz_core:error] [pid 1006796:tid 137782641034816] [client 157.2 ...
show more
[Thu Jun 06 20:07:23.161459 2024] [authz_core:error] [pid 1006796:tid 137782641034816] [client 157.230.35.50:65419] AH01630: client denied by server configuration: /usr/lib/cgi-bin/alfacgiapi [staklim-malang.info] [staklim-malang.info] top=[1006849] [1NwfXUhdcL8] [ZmG0iyVI8VWS8g3mYZOhigAAAgs] keep_alive=[0] [2024-06-06 20:07:23.161464] [R:ZmG0iyVI8VWS8g3mYZOhigAAAgs] UA:'Mozilla/5.0 (Linux; Android 11; Redmi Note 9 Pro Build/RKQ1.200826.002; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/90.0.4430.210 Mobile Safari/537.36' Host:'staklim-malang.info' COOKIE:'fb66df88cff4414b0afe6309464db212=abncjjnd8j7s8i87qhug59487l' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9' Accept-Encoding:'gzip, deflate
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-06-06 08:51:02
(2 years ago)
[Thu Jun 06 15:50:59.515645 2024] [security2:error] [pid 821538:tid 137783354066496] [client 157.230 ...
show more
[Thu Jun 06 15:50:59.515645 2024] [security2:error] [pid 821538:tid 137783354066496] [client 157.230.35.50:53951] [client 157.230.35.50] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Mozlila" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "58"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: Mozlila found within REQUEST_HEADERS:User-Agent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36Team Anon Force request_line = GET /simple.php HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/4.3.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/simple.php"]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2024-06-06 06:03:32
(2 years ago)
Multiple WP scan detected from same source ip.-112
Bad Web Bot
๐ฎ๐ฉ
hermawan
2024-06-06 05:35:48
(2 years ago)
[Thu Jun 06 12:35:46.369626 2024] [security2:error] [pid 625689:tid 134794985866816] [client 157.230 ...
show more
[Thu Jun 06 12:35:46.369626 2024] [security2:error] [pid 625689:tid 134794985866816] [client 157.230.35.50:51305] [client 157.230.35.50] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Mozlila" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "58"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: Mozlila found within REQUEST_HEADERS:User-Agent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36Team Anon Force request_line = GET /simple.php HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/4.3.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "staklim-malang.info"] [uri "/simple.php"] [uni
...
show less
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2024-06-06 05:14:21
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
COMAITE
2024-06-04 02:30:17
(2 years ago)
Multiple web server 400 error codes from same source ip 157.230.35.50.
Web App Attack
๐ฉ๐ช
niceshops.com
2024-06-03 16:37:35
(2 years ago)
Web Attack (Jun 24 18:37:35 ScriptKiddie: request for /wp-content/alfacgiapi/perl.alfa )
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rdpguard.com
2024-06-03 13:50:06
(2 years ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2024-06-03 11:50:00
(2 years ago)
PHPUnit.Eval-stdin.PHP.Remote.Code.Execution
Hacking
๐ฉ๐ช
niceshops.com
2024-06-03 02:38:11
(2 years ago)
Web Attack (Jun 24 04:38:10 ScriptKiddie: request for /wp-content/alfacgiapi/perl.alfa )
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rdpguard.com
2024-06-02 06:00:09
(2 years ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force