[Sat May 03 10:46:53.263223 2025] [security2:error] [pid 376324:tid 140330521298624] [client 157.66. ...
show more[Sat May 03 10:46:53.263223 2025] [security2:error] [pid 376324:tid 140330521298624] [client 157.66.37.6:56581] ModSecurity: Access denied with code 403 (phase 2). Match of "rx [0-9]\\\\s*\\\\'\\\\s*[0-9]" against "MATCHED_VAR" required. [file "/etc/modsecurity/coreruleset-4.13.0/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "1747"] [id "932240"] [msg "Remote Command Execution: Unix Command Injection evasion attempt detected"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: s1746244009$o1 found within MATCHED_VAR: GS2.1.s1746244009$o1$g0$t1746244009$j0$l0$h0 request_line = GET /bmkg-192.png HTTP/2.0 Request URI RAW = /bmkg-192.png Request Basename = bmkg-192.png"] [severity "CRITICAL"] [ver "OWASP_CRS/4.13.0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "paranoia-level/2"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-RCE"] [tag "capec/1000/152/248/88"] [tag "PCI/6.5.2
...
show less
Hacking
Web App Attack
Anonymous
(CT) IP 157.66.37.6 (ID/Indonesia/-) found to have 690 connections; Ports: 27960; SRV: 1; Action: 1; ...
show more(CT) IP 157.66.37.6 (ID/Indonesia/-) found to have 690 connections; Ports: 27960; SRV: 1; Action: 1; Trigger: CT_LIMIT
show less
Intensive scraping: /web?s=%22Website%20powered%20by%20Docmint%22%20variiert&country=vo-vo&scraper=m ...
show moreIntensive scraping: /web?s=%22Website%20powered%20by%20Docmint%22%20variiert&country=vo-vo&scraper=mwmbl. User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68.
show less
Malicious Web Traffic - Exploit probing, request floods, etc. on a server hosted by PulseServers.com ...
show moreMalicious Web Traffic - Exploit probing, request floods, etc. on a server hosted by PulseServers.com - ISUS1
...
show less