π«π·
LOGiST
2023-12-10 00:13:18
(2 years ago)
Bot attack detected : webscan vulnerability
Mozilla/5.0 (Linux; Android 9; ONEPLUS A6003) AppleWebKi ...
show more
Bot attack detected : webscan vulnerability
Mozilla/5.0 (Linux; Android 9; ONEPLUS A6003) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36
show less
Bad Web Bot
πΈπͺ
Per-Erik Runebert
2023-12-09 09:39:06
(2 years ago)
Excessive unauthorized requests
Hacking
π«π·
bzhH29280
2023-12-09 06:24:15
(2 years ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2023-12-09 06:01:24
(2 years ago)
Illegitimate and/or suspicious requests.
Hacking
π«π·
Lunik
2023-12-09 04:55:45
(2 years ago)
Malicious access
Web Spam
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-09 02:59:22
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 44.201.5.96 (ec2-44-201-5-96.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210831) triggered by 44.201.5.96 (ec2-44-201-5-96.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 08 21:59:15.324273 2023] [security2:error] [pid 26158] [client 44.201.5.96:39232] [client 44.201.5.96] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.nealschon.global|F|4"] [data "EmailWolf"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.nealschon.global"] [uri "/"] [unique_id "ZXPYA8j5SaQENGJioPfYEAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
oh.mg
2023-12-09 01:56:31
(2 years ago)
(mod_security) mod_security (id:949110) triggered by 44.201.5.96 (US/United States/ec2-44-201-5-96.c ...
show more
(mod_security) mod_security (id:949110) triggered by 44.201.5.96 (US/United States/ec2-44-201-5-96.compute-1.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Sat Dec 09 01:56:26.867436 2023] [:error] [pid 729049:tid 140546320344832] [client 44.201.5.96:33712] [client 44.201.5.96] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "kwc.freeboxos.fr"] [uri "/"] [unique_id "ZXPJSvFXuFapf-SKnQyYjQAAAE0"]
show less
Port Scan
Anonymous
2023-12-08 22:14:34
(2 years ago)
Multiple connection attempts tcp 443
Bad Web Bot
πΊπΈ
TPI-Abuse
2023-12-08 17:55:39
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 44.201.5.96 (ec2-44-201-5-96.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210831) triggered by 44.201.5.96 (ec2-44-201-5-96.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 08 12:55:35.054382 2023] [security2:error] [pid 14232] [client 44.201.5.96:54176] [client 44.201.5.96] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||r58coupe.com|F|4"] [data "grub-client"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "r58coupe.com"] [uri "/"] [unique_id "ZXNYl7vGSJ5y2okx5DwmigAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-08 16:59:51
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 44.201.5.96 (ec2-44-201-5-96.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210831) triggered by 44.201.5.96 (ec2-44-201-5-96.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 08 11:59:48.873234 2023] [security2:error] [pid 6586] [client 44.201.5.96:50530] [client 44.201.5.96] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||scott-tax.com|F|4"] [data "Microsoft URL"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "scott-tax.com"] [uri "/"] [unique_id "ZXNLhG_CDD6W7yW1vRHZsAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-12-08 16:01:04
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 44.201.5.96 (ec2-44-201-5-96.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210831) triggered by 44.201.5.96 (ec2-44-201-5-96.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 08 11:00:56.613133 2023] [security2:error] [pid 3076364] [client 44.201.5.96:39562] [client 44.201.5.96] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||randlephoto.com|F|4"] [data "grub-client"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "randlephoto.com"] [uri "/jquery.js"] [unique_id "ZXM9uKS1Qup0n_idOPLSmQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-12-08 15:59:04
(2 years ago)
Malicious activity detected
Hacking
Web App Attack
π©πͺ
SCHAPPY
2023-12-08 15:45:53
(2 years ago)
Brute-force attack to non-existent web resources
Brute-Force
Web App Attack
π¬π§
mangomad
2023-12-08 15:28:36
(2 years ago)
Repeated Apache mod_security rule triggers
Brute-Force
Web App Attack
π¬π§
rakkor
2023-12-08 14:46:01
(2 years ago)
2023/12/08 14:45:59 [error] 3414#3414: *396729 open() "/var/services/web/oss.maxcdn.com/libs/respond ...
show more
2023/12/08 14:45:59 [error] 3414#3414: *396729 open() "/var/services/web/oss.maxcdn.com/libs/respond.js/1.4.2/respond.min.js" failed (2: No such file or directory), client: 44.201.5.96, server: , request: "GET //oss.maxcdn.com/libs/respond.js/1.4.2/respond.min.js HTTP/1.1", host: "rakkor.com"
...
show less
Hacking
Brute-Force
Web App Attack