๐ญ๐ฐ
Mehmet_The_Script_Kiddie
2024-07-02 01:40:10
(2 years ago)
GET //wp-json/wp/v2/users/ HTTP/1.1
Hacking
Bad Web Bot
๐ฎ๐ฉ
hermawan
2024-06-28 09:47:12
(2 years ago)
[Fri Jun 28 16:45:10.110803 2024] [security2:error] [pid 553824:tid 123724573443648] [client 164.152 ...
show more
[Fri Jun 28 16:45:10.110803 2024] [security2:error] [pid 553824:tid 123724573443648] [client 164.152.167.129:55899] [client 164.152.167.129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "300" at REQUEST_HEADERS:Keep-Alive. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "119"] [id "440004"] [msg "Keep Alive Header"] [data "Matched Data: 300 found within REQUEST_HEADERS:Keep-Alive: 300 request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "Zn6GJrm86I095bXf4Hr5qgAAAA4"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[553880] [TgBzGsC3+fw] [Zn6GJrm86I095bXf4Hr5qgAAAA4] keep_alive=[0] [2024-06-28 16:45:10.110806] [R:Zn6GJrm86I095bXf4Hr5qgAAAA4] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,
...
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2024-06-28 09:40:03
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2024-06-27 06:03:14
(2 years ago)
Multiple WP scan detected from same source ip.-111
Web App Attack
๐ฎ๐ฉ
hermawan
2024-06-26 12:32:40
(2 years ago)
[Wed Jun 26 19:30:37.598793 2024] [security2:error] [pid 24435:tid 129095574750784] [client 164.152. ...
show more
[Wed Jun 26 19:30:37.598793 2024] [security2:error] [pid 24435:tid 129095574750784] [client 164.152.167.129:61859] [client 164.152.167.129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "300" at REQUEST_HEADERS:Keep-Alive. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "119"] [id "440004"] [msg "Keep Alive Header"] [data "Matched Data: 300 found within REQUEST_HEADERS:Keep-Alive: 300 request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "ZnwJ7V_MKIoaE-ExIYuNywAAApg"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[24501] [erN9LnpGLrw] [ZnwJ7V_MKIoaE-ExIYuNywAAApg] keep_alive=[0] [2024-06-26 19:30:37.598796] [R:ZnwJ7V_MKIoaE-ExIYuNywAAApg] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,*/
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-26 11:46:00
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 164.152.167.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 164.152.167.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 26 07:45:52.732790 2024] [security2:error] [pid 4172] [client 164.152.167.129:55182] [client 164.152.167.129] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.buanamegah.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.buanamegah.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Znv_cKlXh18byLAk2xjZFQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐ฐ
Mehmet_The_Script_Kiddie
2024-06-26 11:44:14
(2 years ago)
AUTOMATED REPORT: Suspicous path traversal: //wp-includes/wlwmanifest.xml
Hacking
Bad Web Bot
๐ธ๐ฌ
Cloudkul Cloudkul
2024-06-26 07:48:04
(2 years ago)
Multiple unauthorized attempts to access web resources
Brute-Force
Web App Attack
Anonymous
2024-06-26 07:13:32
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฎ๐ฉ
Incidents Response Neptus Team
2024-06-26 06:03:00
(2 years ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
mawan
2024-06-26 03:37:43
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2024-06-26 03:02:16
(2 years ago)
Multiple WP scan detected from same source ip.-111
Brute-Force
๐ฎ๐ฉ
hermawan
2024-05-30 06:38:02
(2 years ago)
[Thu May 30 13:35:58.024429 2024] [security2:error] [pid 266546:tid 130795668768320] [client 164.152 ...
show more
[Thu May 30 13:35:58.024429 2024] [security2:error] [pid 266546:tid 130795668768320] [client 164.152.167.129:56010] [client 164.152.167.129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "300" at REQUEST_HEADERS:Keep-Alive. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "84"] [id "440004"] [msg "Keep Alive Header"] [data "Matched Data: 300 found within REQUEST_HEADERS:Keep-Alive: 300 request_line = GET / HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/"] [unique_id "ZlgeTuYWUJo_AaLPwp-SegAAAJI"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[266606] [YApqFJaW6dc] [ZlgeTuYWUJo_AaLPwp-SegAAAJI] keep_alive=[0] [2024-05-30 13:35:58.024432] [R:ZlgeTuYWUJo_AaLPwp-SegAAAJI] UA:'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,*
...
show less
Hacking
Web App Attack
๐ธ๐ฌ
pusathosting.com
2024-05-29 11:54:03
(2 years ago)
2ds22 bruteforce
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2024-05-29 11:53:33
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack