๐ฎ๐ช
RoboSOC
2023-12-16 09:14:53
(2 years ago)
Apache Struts2 OGNL Remote Code Execution Vulnerability, PTR: static.reserve.wtt.net.hk.
Hacking
๐บ๐ธ
TPI-Abuse
2023-12-16 04:53:25
(2 years ago)
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 ...
show more
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 15 23:53:20.421573 2023] [security2:error] [pid 29422] [client 218.253.193.147:56727] [client 218.253.193.147] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.st-kitts-and-nevis-yacht-registration.com:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.st-kitts-and-nevis-yacht-registration.com"] [uri "/struts2-showcase/index.action"] [unique_id "ZX0tQBuSJemkgvSLCDKneAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-15 02:19:34
(2 years ago)
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 ...
show more
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 14 21:19:26.594717 2023] [security2:error] [pid 19591:tid 47587608573696] [client 218.253.193.147:50256] [client 218.253.193.147] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.progenicyte.com:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.progenicyte.com"] [uri "/struts2-showcase/index.action"] [unique_id "ZXu3roFvOJ_Aj8ndQDVb4AAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-14 00:55:12
(2 years ago)
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 ...
show more
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 13 19:55:08.106081 2023] [security2:error] [pid 14087:tid 47048409749248] [client 218.253.193.147:52891] [client 218.253.193.147] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.maxpowered.jp:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.maxpowered.jp"] [uri "/struts2-showcase/index.action"] [unique_id "ZXpSbIwiyNDQ7sLSJNiE_gAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-13 16:22:36
(2 years ago)
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 ...
show more
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 13 11:22:32.204248 2023] [security2:error] [pid 11768] [client 218.253.193.147:51514] [client 218.253.193.147] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.lifeinsmoke.com:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.lifeinsmoke.com"] [uri "/struts2-showcase/index.action"] [unique_id "ZXnaSNc8kffGXCfR4SpTCAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-10 23:50:54
(2 years ago)
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 ...
show more
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 10 18:50:46.699955 2023] [security2:error] [pid 23990] [client 218.253.193.147:49429] [client 218.253.193.147] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.elderlyassociation.org:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.elderlyassociation.org"] [uri "/struts2-showcase/index.action"] [unique_id "ZXZO1nrIv5rM9Y-oRhMX_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-09 00:07:54
(2 years ago)
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 ...
show more
(mod_security) mod_security (id:243930) triggered by 218.253.193.147 (static.reserve.wtt.net.hk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 08 19:07:49.409156 2023] [security2:error] [pid 276698] [client 218.253.193.147:52231] [client 218.253.193.147] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.alexlacruz.com:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.alexlacruz.com"] [uri "/struts2-showcase/index.action"] [unique_id "ZXOv1XhqHm1wJeoO7zL2qwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2023-11-27 23:15:40
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2023-10-06 00:46:35
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2023-10-04 19:16:51
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2023-10-03 11:06:31
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
Snowdome
2023-10-03 10:10:02
(2 years ago)
218.253.193.147 [:] with UserAgent: targeting domain: was challenged by WAF:,
DetectionCategory:m ...
show more
218.253.193.147 [:] with UserAgent: targeting domain: was challenged by WAF:,
DetectionCategory:manage definite bots, ResponseTime: ms
show less
Web App Attack
Anonymous
2023-10-01 12:49:44
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2023-09-30 06:51:58
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2023-09-29 18:30:32
(2 years ago)
Excessive HTTP/HTTPS connections.
Bad Web Bot