๐ณ๐ฑ
Linuxmalwarehuntingnl
2024-07-03 07:02:36
(2 years ago)
Unauthorized connection attempt
Brute-Force
๐ซ๐ท
Laurent-1971
2024-03-15 09:13:22
(2 years ago)
/static.cloudflareinsights.com/beacon.min.js [ Mozilla/5.0 (Linux; Android 4.4.2; LGMS323 Build/KOT4 ...
show more
/static.cloudflareinsights.com/beacon.min.js [ Mozilla/5.0 (Linux; Android 4.4.2; LGMS323 Build/KOT49I.MS32310b) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.103 ]
show less
Web App Attack
Anonymous
2024-03-15 04:48:00
(2 years ago)
Blocked: hostile provider - AS14618 AMAZON
Port Scan
Hacking
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
Anonymous
2024-03-15 03:52:42
(2 years ago)
Web App Attack
๐ซ๐ท
oh.mg
2024-03-15 03:29:58
(2 years ago)
(mod_security) mod_security (id:949110) triggered by 34.201.23.132 (US/United States/ec2-34-201-23-1 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.201.23.132 (US/United States/ec2-34-201-23-132.compute-1.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Fri Mar 15 03:29:52.608649 2024] [:error] [pid 1499738:tid 140098167351040] [client 34.201.23.132:36970] [client 34.201.23.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "omg.sus.fr"] [uri "/"] [unique_id "ZfPAsJHlKkUIkHYeFT5IZQAAAJc"]
show less
Port Scan
๐ฉ๐ช
iNetWorker
2024-03-15 02:20:06
(2 years ago)
firewall-block, port(s): 80/tcp, 443/tcp
Port Scan
๐จ๐ฑ
ifiguero
2024-03-15 02:09:16
(2 years ago)
Web Attack (\x00\x00\x00\x00\x00). 7d ban
Web App Attack
๐ฉ๐ช
Stefan Dreher
2024-03-15 00:21:05
(2 years ago)
34.201.23.132 - - [15/Mar/2024:01:21:04 +0100] "GET /holder.min.js HTTP/1.1" 404 125 "-" "Mozilla/5. ...
show more
34.201.23.132 - - [15/Mar/2024:01:21:04 +0100] "GET /holder.min.js HTTP/1.1" 404 125 "-" "Mozilla/5.0 (compatible; Konqueror/3.5; SunOS) KHTML/3.5.1 (like Gecko)"
34.201.23.132 - - [15/Mar/2024:01:21:04 +0100] "GET /manifest.js HTTP/1.1" 404 125 "-" "Nokia7250/1.0 (3.14) Profile/MIDP-1.0 Configuration/CLDC-1.0"
34.201.23.132 - - [15/Mar/2024:01:21:04 +0100] "GET /bootstrap.min.js HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36"
34.201.23.132 - - [15/Mar/2024:01:21:04 +0100] "GET //oss.maxcdn.com/libs/html5shiv/3.7.0/html5shiv.js HTTP/1.1" 404 125 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0"
34.201.23.132 - - [15/Mar/2024:01:21:04 +0100] "GET /ie10-viewport-bug-workaround.js HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Linux; Android 12; SM-G780G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Mobile Safari/537.36"
...
show less
Hacking
Brute-Force
Anonymous
2024-03-14 22:07:38
(2 years ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.201.23.132 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.201.23.132 (US/United States/ec2-34-201-23-132.compute-1.amazonaws.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-03-14 21:33:38
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 34.201.23.132 (ec2-34-201-23-132.compute-1.amaz ...
show more
(mod_security) mod_security (id:210831) triggered by 34.201.23.132 (ec2-34-201-23-132.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 14 17:33:33.433084 2024] [security2:error] [pid 30185] [client 34.201.23.132:60938] [client 34.201.23.132] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.rick18.cc|F|4"] [data "EmailWolf"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.rick18.cc"] [uri "/"] [unique_id "ZfNtLTaNDTeelUrwu_rrYgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2024-03-14 20:50:02
(2 years ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
iNetWorker
2024-03-14 20:43:16
(2 years ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ฐ
buusbudde.dk
2024-03-14 20:26:55
(2 years ago)
[Thu Mar 14 21:20:28.060092 2024] [security2:error] [pid 1670403] [client 34.201.23.132:51648] [clie ...
show more
[Thu Mar 14 21:20:28.060092 2024] [security2:error] [pid 1670403] [client 34.201.23.132:51648] [client 34.201.23.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/"] [unique_id "ZfNcDApVnRS4TgPm-UHPHQAAAAE"]
[Thu Mar 14 21:26:54.270131 2024] [security2:error] [pid 1663717] [client 34.201.23.132:42706] [client 34.201.23.132] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "O
...
show less
Web App Attack
๐จ๐ฆ
Justmee
2024-03-14 20:08:56
(2 years ago)
Mar 14 14:08:52 server1 kernel: [15488395.261675] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42 ...
show more
Mar 14 14:08:52 server1 kernel: [15488395.261675] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=34.201.23.132 DST=192.168.100.3 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=38994 DF PROTO=TCP SPT=34414 DPT=443 WINDOW=62727 RES=0x00 SYN URGP=0
Mar 14 14:08:53 server1 kernel: [15488396.281848] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=34.201.23.132 DST=192.168.100.3 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=38995 DF PROTO=TCP SPT=34414 DPT=443 WINDOW=62727 RES=0x00 SYN URGP=0
Mar 14 14:08:55 server1 kernel: [15488398.297836] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=34.201.23.132 DST=192.168.100.3 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=38996 DF PROTO=TCP SPT=34414 DPT=443 WINDOW=62727 RES=0x00 SYN URGP=0
...
show less
Hacking
Brute-Force
๐ซ๐ท
LOGiST
2024-03-14 07:52:01
(2 years ago)
Bot attack detected : webscan vulnerability
SonyEricssonZ800/R1Y Browser/SEMC-Browser/4.1 Profile/MI ...
show more
Bot attack detected : webscan vulnerability
SonyEricssonZ800/R1Y Browser/SEMC-Browser/4.1 Profile/MIDP-2.0 Configuration/CLDC-1.1 UP.Link/6.3.0.0.0
show less
Bad Web Bot