|
π©πͺ
Sentinel1Filter
|
|
ip=45.142.122.34 F2B blocked Mail Porno/Phishing SpamScore above:14
|
DNS Compromise
|
|
|
π©πͺ
sebaro11
|
|
Portscan on 80/TCP blocked by UFW
|
Port Scan
|
|
|
πͺπΈ
10dencehispahard SL
|
|
Suspicious activity detected by Modsecurity [Application attack LFI]
|
Hacking
Web App Attack
|
|
|
π¨π
zynex
|
|
URL Probing: /.env
|
Web App Attack
|
|
|
π¨π
unifr
|
|
Unauthorized IMAP connection attempt
|
Brute-Force
|
|
|
π·πΊ
ITShelter Security
|
|
2022/08/05 00:39:54 +03:00 req: GET /.env HTTP/1.1, host: ***.pro
2022/08/05 00:54:48 +03:00 req: GE ...
show more
2022/08/05 00:39:54 +03:00 req: GET /.env HTTP/1.1, host: ***.pro
2022/08/05 00:54:48 +03:00 req: GET /.env HTTP/1.1, host: ***.pro
show less
|
Bad Web Bot
Web App Attack
|
|
|
πΊπ¦
URAN Publishing Service
|
|
45.142.122.34 - - [05/Aug/2022:00:52:15 +0300] "GET /.env HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; L ...
show more
45.142.122.34 - - [05/Aug/2022:00:52:15 +0300] "GET /.env HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
45.142.122.34 - - [05/Aug/2022:00:53:31 +0300] "GET /.env HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
πΊπ¦
URAN Publishing Service
|
|
45.142.122.34 - - [29/Jul/2022:08:43:47 +0300] "GET /wp-content/plugins/photoxhibit/common/inc/pages ...
show more
45.142.122.34 - - [29/Jul/2022:08:43:47 +0300] "GET /wp-content/plugins/photoxhibit/common/inc/pages/build.php?gid=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E HTTP/1.1" 404 272 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
45.142.122.34 - - [29/Jul/2022:08:43:52 +0300] "GET /cgi-bin/mj_wwwusr?passw=&list=GLOBAL&user=&func=help&extra=/../../../../../../../../etc/passwd HTTP/1.1" 404 454 "-" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
πΊπ¦
MakselPr
|
|
2022/07/13 18:51:24 [error] 299525#299525: *20754 open() "/var/www/html/cgi-bin/awstats/awredir.pl" ...
show more
2022/07/13 18:51:24 [error] 299525#299525: *20754 open() "/var/www/html/cgi-bin/awstats/awredir.pl" failed (2: No such file or directory), client: 45.142.122.34, server: localhost, request: "GET /cgi-bin/awstats/awredir.pl?url=%3Cscript%3Ealert(document.domain)%3C/script%3E HTTP/1.1", host: "enot.dp.ua"
2022/07/16 09:28:00 [error] 392868#392868: *26039 open() "/var/www/html/cgi-bin/;cat$IFS/etc/passwd" failed (2: No such file or directory), client: 45.142.122.34, server: localhost, request: "GET /cgi-bin/;cat$IFS/etc/passwd HTTP/1.1", host: "enot.dp.ua"
...
show less
|
Brute-Force
|
|
|
Anonymous
|
|
Fail2Ban triggered
|
Web App Attack
|
|
|
πΊπΈ
APT-HUNTERc7e352007
|
|
Log4J VmWare Exploitation
|
Hacking
|
|
|
πΊπ¦
URAN Publishing Service
|
|
[Tue Jun 07 18:22:17.977143 2022] [authz_core:error] [pid 2963941] [client 45.142.122.34:36826] AH01 ...
show more
[Tue Jun 07 18:22:17.977143 2022] [authz_core:error] [pid 2963941] [client 45.142.122.34:36826] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
[Tue Jun 07 18:26:06.445229 2022] [authz_core:error] [pid 2964339] [client 45.142.122.34:52524] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
[Tue Jun 07 18:26:09.073632 2022] [authz_core:error] [pid 2964312] [client 45.142.122.34:54062] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
...
show less
|
Web App Attack
|
|
|
πΊπ¦
URAN Publishing Service
|
|
[Tue Jun 07 17:22:19.214225 2022] [authz_core:error] [pid 2961772] [client 45.142.122.34:42574] AH01 ...
show more
[Tue Jun 07 17:22:19.214225 2022] [authz_core:error] [pid 2961772] [client 45.142.122.34:42574] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
[Tue Jun 07 17:22:19.760394 2022] [authz_core:error] [pid 2961813] [client 45.142.122.34:39646] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
[Tue Jun 07 17:22:26.090381 2022] [authz_core:error] [pid 2961745] [client 45.142.122.34:47056] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
...
show less
|
Web App Attack
|
|
|
πΊπ¦
URAN Publishing Service
|
|
[Tue Jun 07 16:57:52.488791 2022] [authz_core:error] [pid 2960630] [client 45.142.122.34:58440] AH01 ...
show more
[Tue Jun 07 16:57:52.488791 2022] [authz_core:error] [pid 2960630] [client 45.142.122.34:58440] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
[Tue Jun 07 16:59:38.750634 2022] [authz_core:error] [pid 2960726] [client 45.142.122.34:44422] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
[Tue Jun 07 17:00:31.186626 2022] [authz_core:error] [pid 2960749] [client 45.142.122.34:54594] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
...
show less
|
Web App Attack
|
|
|
πΊπ¦
URAN Publishing Service
|
|
[Tue Jun 07 16:37:07.826262 2022] [authz_core:error] [pid 2959260] [client 45.142.122.34:35210] AH01 ...
show more
[Tue Jun 07 16:37:07.826262 2022] [authz_core:error] [pid 2959260] [client 45.142.122.34:35210] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
[Tue Jun 07 16:37:08.920578 2022] [authz_core:error] [pid 2959541] [client 45.142.122.34:35558] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
[Tue Jun 07 16:37:10.575806 2022] [authz_core:error] [pid 2959637] [client 45.142.122.34:35930] AH01630: client denied by server configuration: /home/ojs/ojs/server-status
...
show less
|
Web App Attack
|
|