π©πͺ
HERA - Operations
2024-04-25 06:20:21
(2 years ago)
sensobox - searching for vulnerable scripts: config 2024/04/25 06:20:20
Web App Attack
π©πͺ
Mr-Money
2024-04-25 04:51:43
(2 years ago)
172.233.14.76 - - [25/Apr/2024:06:51:43 +0200] "GET /.git/config HTTP/1.1" 404 5985 "-" "Mozilla/5.0 ...
show more
172.233.14.76 - - [25/Apr/2024:06:51:43 +0200] "GET /.git/config HTTP/1.1" 404 5985 "-" "Mozilla/5.0 (compatible; Konqueror/4.5; Windows) KHTML/4.5.4 (like Gecko)"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-25 04:31:03
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 172.233.14.76 (172-233-14-76.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 172.233.14.76 (172-233-14-76.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 25 00:30:59.007231 2024] [security2:error] [pid 28088] [client 172.233.14.76:48654] [client 172.233.14.76] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "omintara.com"] [uri "/.git/config"] [unique_id "Zincg891GyKq2CPaWJ5hJwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Mr-Money
2024-04-25 01:21:07
(2 years ago)
172.233.14.76 - - [25/Apr/2024:03:21:07 +0200] "GET /.git/config HTTP/1.1" 404 5589 "-" "Mozilla/5.0 ...
show more
172.233.14.76 - - [25/Apr/2024:03:21:07 +0200] "GET /.git/config HTTP/1.1" 404 5589 "-" "Mozilla/5.0 (X11; Linux i686; rv:8.0) Gecko/20100101 Firefox/8.0"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
π©πͺ
Bedios GmbH
2024-04-25 01:06:26
(2 years ago)
Login credentials theft attempt
Hacking
πͺπΈ
10dencehispahard SL
2024-04-25 00:13:27
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
π©πͺ
barbarella
2024-04-25 00:10:08
(2 years ago)
hacking attempt of version control system (GET /.git/config)
Hacking
Web App Attack
Anonymous
2024-04-24 23:47:36
(2 years ago)
172.233.14.76 - - [25/Apr/2024:01:47:35 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
172.233.14.76 - - [25/Apr/2024:01:47:35 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (iPad; CPU OS 12_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0 Mobile/15E148 Safari/604.1"
show less
Web App Attack
π©πͺ
Mr-Money
2024-04-24 23:35:31
(2 years ago)
172.233.14.76 - - [25/Apr/2024:01:35:30 +0200] "GET /.git/config HTTP/1.1" 404 6650 "-" "Mozilla/5.0 ...
show more
172.233.14.76 - - [25/Apr/2024:01:35:30 +0200] "GET /.git/config HTTP/1.1" 404 6650 "-" "Mozilla/5.0 (Linux; Android 5.0.1; SCH-R970 Build/LRX22C) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.84 Mobile Safari/537.36"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
π§πͺ
cmbplf
2024-04-24 23:18:13
(2 years ago)
207 requests to /.git/config
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-04-24 22:54:10
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 172.233.14.76 (172-233-14-76.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 172.233.14.76 (172-233-14-76.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 24 18:54:05.248837 2024] [security2:error] [pid 11386] [client 172.233.14.76:39766] [client 172.233.14.76] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ds12bonn.de"] [uri "/.git/config"] [unique_id "ZimNjSnOXstisXWctzfvrQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
rh24
2024-04-24 22:17:48
(2 years ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 172.233.14.76 (BR/Br ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 172.233.14.76 (BR/Brazil/172-233-14-76.ip.linodeusercontent.com)
show less
Bad Web Bot
π©πͺ
HERA - Operations
2024-04-24 22:03:42
(2 years ago)
club-herrmann - searching for vulnerable scripts: config 2024/04/25 00:03:42
Web App Attack
π©πͺ
Mr-Money
2024-04-24 21:20:31
(2 years ago)
172.233.14.76 - - [24/Apr/2024:23:20:30 +0200] "GET /.git/config HTTP/1.1" 404 3798 "-" "BlackBerry7 ...
show more
172.233.14.76 - - [24/Apr/2024:23:20:30 +0200] "GET /.git/config HTTP/1.1" 404 3798 "-" "BlackBerry7520/4.0.0 Profile/MIDP-2.0 Configuration/CLDC-1.1 UP.Browser/5.0.3.3 UP.Link/5.1.2.12 (Google WAP Proxy/1.0)"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
π©πͺ
hfbusiness.de
2024-04-24 20:53:55
(2 years ago)
172.233.14.76 - - [24/Apr/2024:22:53:54 +0200] "GET /.git/config HTTP/1.1" 404 10480 "-" "Mozilla/5. ...
show more
172.233.14.76 - - [24/Apr/2024:22:53:54 +0200] "GET /.git/config HTTP/1.1" 404 10480 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.88 Safari/537.36 Vivaldi/2.4.1488.36"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack