๐ณ๐ฑ
Linuxmalwarehuntingnl
2024-07-02 07:08:42
(2 years ago)
Unauthorized connection attempt
Brute-Force
๐ฎ๐ฉ
hermawan
2024-01-17 13:56:43
(2 years ago)
[Wed Jan 17 20:56:40.560020 2024] [security2:error] [pid 279514:tid 127882204546624] [client 45.201. ...
show more
[Wed Jan 17 20:56:40.560020 2024] [security2:error] [pid 279514:tid 127882204546624] [client 45.201.190.3:54079] [client 45.201.190.3] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "182"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json request_line = GET /sftp-config.json HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/sftp-config.json"] [unique_id "ZafcmD4IiRhFXzhov9W18AAAATk"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[279599] [WrrFnRxcgEY] [ZafcmD4IiRhFXzhov9W18AAAATk] keep_alive=[0] [202
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-01-16 11:13:09
(2 years ago)
[Tue Jan 16 18:13:05.799735 2024] [security2:error] [pid 171522:tid 125407911216704] [client 45.201. ...
show more
[Tue Jan 16 18:13:05.799735 2024] [security2:error] [pid 171522:tid 125407911216704] [client 45.201.190.3:63462] [client 45.201.190.3] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "182"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env request_line = GET /.env HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/.env"] [unique_id "ZaZkwYeGeX7l-rk0KvkPWgAAAJc"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[171645] [+CztNr4eL2A] [ZaZkwYeGeX7l-rk0KvkPWgAAAJc] keep_alive=[0] [2024-01-16 18:13:05.799739] [R:ZaZkwYeGeX7l-rk0KvkPWgAAAJc] Hos
...
show less
Hacking
Web App Attack
๐ฒ๐พ
syokadmin
2024-01-13 15:48:18
(2 years ago)
(cpanel) Failed cPanel login from 45.201.190.3 (KH/Cambodia/-): 1 in the last 3600 secs
Brute-Force
Web App Attack
๐ฒ๐พ
syokadmin
2024-01-12 15:26:49
(2 years ago)
(cpanel) Failed cPanel login from 45.201.190.3 (KH/Cambodia/-): 1 in the last 3600 secs
Brute-Force
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2024-01-03 11:01:10
(2 years ago)
apache-auth-111
Brute-Force
๐ฎ๐ฉ
hermawan
2024-01-01 07:36:45
(2 years ago)
[Mon Jan 01 14:36:40.701485 2024] [security2:error] [pid 987678:tid 140688709338688] [client 45.201. ...
show more
[Mon Jan 01 14:36:40.701485 2024] [security2:error] [pid 987678:tid 140688709338688] [client 45.201.190.3:58609] [client 45.201.190.3] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^[\\\\w/.+-]+(?:\\\\s?;\\\\s?(?:action|boundary|charset|type|start(?:-info)?)\\\\s?=\\\\s?['\\"\\\\w.()+,/:=?<>@-]+)*$" against "REQUEST_HEADERS:Content-type" required. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1311"] [id "920470"] [msg "Illegal Content-Type header"] [data "Matched Data: */* found within REQUEST_HEADERS:Content-type: */* request_line = GET /.well-known/ HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/.well-known/"] [unique_id "ZZJriPSKesliU-HA_h9JigAAAS4"] [staklim-jatim.bmkg.go.id] [stak
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2023-12-31 11:05:11
(2 years ago)
[Sun Dec 31 18:05:07.631300 2023] [security2:error] [pid 536905:tid 140439491425856] [client 45.201. ...
show more
[Sun Dec 31 18:05:07.631300 2023] [security2:error] [pid 536905:tid 140439491425856] [client 45.201.190.3:59520] [client 45.201.190.3] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^[\\\\w/.+-]+(?:\\\\s?;\\\\s?(?:action|boundary|charset|type|start(?:-info)?)\\\\s?=\\\\s?['\\"\\\\w.()+,/:=?<>@-]+)*$" against "REQUEST_HEADERS:Content-type" required. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1309"] [id "920470"] [msg "Illegal Content-Type header"] [data "Matched Data: */* found within REQUEST_HEADERS:Content-type: */* request_line = GET /.well-known/ HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153"] [tag "PCI/12.1"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/.well-known/"] [unique_id "ZZFK4-W8r0Nhw4BkyzYCDAAAAcA"] [staklim-jatim.bmkg.go.id] [stak
...
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2023-12-27 06:38:53
(2 years ago)
45.201.190.3 - - [27/Dec/2023:08:38:51 +0200] "GET /cgi-bin/ HTTP/1.1" 404 5238 "-" "Mozilla/5.0 (X1 ...
show more
45.201.190.3 - - [27/Dec/2023:08:38:51 +0200] "GET /cgi-bin/ HTTP/1.1" 404 5238 "-" "Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/540.0 (KHTML,like Gecko) Chrome/9.1.0.0 Safari/540.0"
45.201.190.3 - - [27/Dec/2023:08:38:52 +0200] "GET /cgi-bin/ HTTP/1.1" 404 5238 "-" "Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/540.0 (KHTML,like Gecko) Chrome/9.1.0.0 Safari/540.0"
...
show less
Web App Attack
๐บ๐ธ
gu-alvareza
2023-12-25 07:05:05
(2 years ago)
PHPUnit.Eval-stdin.PHP.Remote.Code.Execution
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2023-12-23 17:25:09
(2 years ago)
45.201.190.3 - - [23/Dec/2023:19:25:08 +0200] "GET /.env HTTP/1.1" 404 285 "-" ""
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-23 11:43:27
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 45.201.190.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.201.190.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 23 06:43:21.832786 2023] [security2:error] [pid 24709:tid 47726901360384] [client 45.201.190.3:59257] [client 45.201.190.3] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbpuertadelsol.com"] [uri "/.env"] [unique_id "ZYbH2YTG2nRsw52in5yErAAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
hermawan
2023-12-23 11:42:21
(2 years ago)
[Sat Dec 23 18:42:17.548164 2023] [security2:error] [pid 488606:tid 139915111155264] [client 45.201. ...
show more
[Sat Dec 23 18:42:17.548164 2023] [security2:error] [pid 488606:tid 139915111155264] [client 45.201.190.3:19328] [client 45.201.190.3] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-3.3.5/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "151"] [id "913101"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.28.1 request_line = GET //admin/ HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/admin/"] [unique_id "ZYbHmd6H5lssOECJhO7cPwAAABU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[488714] [i9Mh01usrjI
...
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2023-12-23 11:23:31
(2 years ago)
45.201.190.3 - - [23/Dec/2023:13:23:11 +0200] "GET /.env HTTP/1.1" 404 285 "-" "Mozilla/5.0 (X11; Li ...
show more
45.201.190.3 - - [23/Dec/2023:13:23:11 +0200] "GET /.env HTTP/1.1" 404 285 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
45.201.190.3 - - [23/Dec/2023:13:23:31 +0200] "GET /.env HTTP/1.1" 404 4831 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
oonux.net
2023-12-13 17:42:28
(2 years ago)
RouterOS: The host 45.201.190.3 trying to use anonymous proxy
Hacking
Bad Web Bot
Exploited Host