๐ฆ๐น
nomzamo
2025-01-22 03:48:18
(1 year ago)
Fail2Ban reported: nginx-badbots
Brute-Force
Bad Web Bot
๐บ๐ธ
chronos
2024-08-09 19:36:25
(2 years ago)
[AUTORAVALT][[09/08/2024 - 16:36:25 -03:00 UTC]
Attack from [Amazon Technologies Inc.]
[3.21.127.180 ...
show more
[AUTORAVALT][[09/08/2024 - 16:36:25 -03:00 UTC]
Attack from [Amazon Technologies Inc.]
[3.21.127.180][ec2-3-21-127-180.us-east-2.compute.amazonaws.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, f]
...
show less
Hacking
Web App Attack
๐บ๐ธ
chronos
2024-08-09 19:11:19
(2 years ago)
[AUTORAVALT][[09/08/2024 - 16:11:18 -03:00 UTC]
Attack from [Amazon Technologies Inc.]
[3.21.127.180 ...
show more
[AUTORAVALT][[09/08/2024 - 16:11:18 -03:00 UTC]
Attack from [Amazon Technologies Inc.]
[3.21.127.180][ec2-3-21-127-180.us-east-2.compute.amazonaws.com]
Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐ฉ๐ช
GAS
2024-08-09 19:06:07
(2 years ago)
Port Scan
Hacking
Anonymous
2024-08-09 07:26:52
(2 years ago)
[08/Aug/2024:07:05:39 -0400] \"GET /.env HTTP/1.1\" \"python-requests/2.32.3\"
[08/Aug/2024:07:05:39 ...
show more
[08/Aug/2024:07:05:39 -0400] \"GET /.env HTTP/1.1\" \"python-requests/2.32.3\"
[08/Aug/2024:07:05:39 -0400] \"GET /.env HTTP/1.1\" \"python-requests/2.32.3\"
[08/Aug/2024:07:20:19 -0400] \"GET /_profiler/phpinfo HTTP/1.1\" \"python-requests/2.32.3\"
[08/Aug/2024:07:20:19 -0400] \"GET /_profiler/phpinfo HTTP/1.1\" \"python-requests/2.32.3\"
show less
Hacking
๐ฌ๐ง
openstrike.co.uk
2024-08-09 05:12:58
(2 years ago)
2 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
๐ง๐ช
sid3windr
2024-08-08 14:45:39
(2 years ago)
GET /.git/config (Tarpitted for 4h41m43s, wasted 990.35kB)
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2024-08-08 14:10:04
(2 years ago)
Scanning for Laravel vulnerabilities
Web App Attack
๐ฎ๐ฉ
hermawan
2024-08-08 12:55:29
(2 years ago)
[Thu Aug 08 17:23:27.968133 2024] [security2:error] [pid 598937:tid 134780997862976] [client 3.21.12 ...
show more
[Thu Aug 08 17:23:27.968133 2024] [security2:error] [pid 598937:tid 134780997862976] [client 3.21.127.180:58614] [client 3.21.127.180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "157"] [id "913101"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.32.3 request_line = GET /.env HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "matomo.staklim-malang.info"] [uri "/.env"] [unique_id "ZrScn4Dq4Pt2zcTUxn7taAAAAQM"] [matomo.staklim-malang.info] [matomo.staklim-malang.info] top=[598982] [K6zjarFPUi
...
show less
Hacking
Web App Attack
Anonymous
2024-08-08 12:32:29
(2 years ago)
[07/Aug/2024:01:29:29 -0400] \"GET / HTTP/1.1\" \"Wget/1.12 (freebsd8.1)\"
[07/Aug/2024:04:49:34 -04 ...
show more
[07/Aug/2024:01:29:29 -0400] \"GET / HTTP/1.1\" \"Wget/1.12 (freebsd8.1)\"
[07/Aug/2024:04:49:34 -0400] \"GET /.git/config HTTP/1.1\" \"Mozilla/5.0 (Linux; U; Android 4.0.3; en-us; KFTT Build/IML74K) AppleWebKit/535.19 (KHTML, like Gecko) Silk/2.1 Mobile Safari/535.19 Silk-Accelerated=true\"
[07/Aug/2024:04:49:43 -0400] \"GET /.git/config HTTP/1.1\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36\"
show less
Hacking
๐ณ๐ฑ
rshict
2024-08-08 12:32:18
(2 years ago)
Hacking, Brute-Force, Web App Attack
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
jasperedv.de
2024-08-08 12:29:13
(2 years ago)
Apache Login - Brutforcing
Brute-Force
Web App Attack
๐ฉ๐ช
ut-addicted.com
2024-08-08 11:37:59
(2 years ago)
\[Thu Aug 08 13:37:57.319680 2024\] \[:error\] \[pid 3303:tid 140449299760896\] \[client 3.21.127.18 ...
show more
\[Thu Aug 08 13:37:57.319680 2024\] \[:error\] \[pid 3303:tid 140449299760896\] \[client 3.21.127.180:55082\] \[client 3.21.127.180\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 8\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "78.46.187.162"\] \[uri "/.git/config"\] \[unique_id "ZrSuFY0CAE4nPXiEfIO75wAAANE"\]
show less
Brute-Force
Web App Attack
Anonymous
2024-08-08 11:13:48
(2 years ago)
[Thu Aug 08 07:13:47.665990 2024] [:error] [pid 13403] [client 3.21.127.180] ModSecurity: Access den ...
show more
[Thu Aug 08 07:13:47.665990 2024] [:error] [pid 13403] [client 3.21.127.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "[mungedIP2]"] [uri "/.env"] [unique_id "ZrSoa38AAAEAADRboZkAAAAE"]
[Thu Aug 08 07:13:47.733958 2024] [:error] [pid 13406] [client 3.21.127.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
ozisp.com.au
2024-08-08 11:12:28
(2 years ago)
US_Amazon_<33>1723115547 [1:2525014:1057] ET 3CORESec Poor Reputation IP TCP group 8 [Classification ...
show more
US_Amazon_<33>1723115547 [1:2525014:1057] ET 3CORESec Poor Reputation IP TCP group 8 [Classification: Misc Attack] [Priority: 2] {TCP} 3.21.127.180:54046
show less
Hacking