๐บ๐ธ
octageeks.com
2023-06-05 04:27:00
(3 years ago)
Wordpress malicious attack:[octa404]
Web App Attack
๐ณ๐ฑ
CryptoYakari
2023-06-05 02:06:55
(3 years ago)
45.92.1.148 - - [05/Jun/2023:05:06:53 +0300] "GET / HTTP/1.0" 403 568 "-" "Mozlila/5.0 (Linux; Andro ...
show more
45.92.1.148 - - [05/Jun/2023:05:06:53 +0300] "GET / HTTP/1.0" 403 568 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
45.92.1.148 - - [05/Jun/2023:05:06:53 +0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.0" 403 566 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
45.92.1.148 - - [05/Jun/2023:05:06:53 +0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.0" 403 567 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
CryptoYakari
2023-06-04 22:37:58
(3 years ago)
45.92.1.148 - - [05/Jun/2023:01:37:55 +0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.0" 404 359 ...
show more
45.92.1.148 - - [05/Jun/2023:01:37:55 +0300] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.0" 404 3594 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
45.92.1.148 - - [05/Jun/2023:01:37:55 +0300] "POST /wp-plain.php HTTP/1.0" 404 542 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
45.92.1.148 - - [05/Jun/2023:01:37:55 +0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.0" 404 3594 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
45.92.1.148 - - [05/Jun/2023:01:37:56 +0300] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.0" 404 3594 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebK
...
show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2023-06-04 22:16:30
(3 years ago)
$f2bV_matches
Brute-Force
๐ฉ๐ช
DAILYKANBAN.COM
2023-06-04 22:07:47
(3 years ago)
(mod_security) mod_security (id:1000001) triggered by 45.92.1.148 (DE/Germany/-): 2 in the last 600 ...
show more
(mod_security) mod_security (id:1000001) triggered by 45.92.1.148 (DE/Germany/-): 2 in the last 600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Jun 04 22:07:45.197938 2023] [security2:error] [pid 3264148:tid 22640737937152] [client 45.92.1.148:0] [client 45.92.1.148] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/blog" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "9"] [id "1000001"] [msg "Restricted File Probe"] [data "Matched Data: /blog found within REQUEST_URI"] [severity "CRITICAL"] [tag "paranoia-level/2"] [hostname "magicalmysteryplanttour.group"] [uri "/blog"] [unique_id "ZH0LMfXZQUEH8b8uHSNfXwAAARY"]
[Sun Jun 04 22:07:45.312521 2023] [security2:error] [pid 3264148:tid 22640746342144] [client 45.92.1.148:0] [client 45.92.1.148] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/blog" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "9"] [id "1000001"] [msg "Restricted F
show less
Web App Attack
๐บ๐ธ
mawan
2023-06-04 21:40:58
(3 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐จ๐ฆ
Mediashaker
2023-06-04 20:15:03
(3 years ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 45.92.1.148 (NL/Netherla ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 45.92.1.148 (NL/Netherlands/-)
show less
Port Scan
๐ณ๐ฑ
0xffffffff
2023-06-04 19:10:10
(3 years ago)
[2023-06-04 22:10:09.031434] [authz_core:error] [pid 2782798:tid 140665984038464] [client 45.92.1.14 ...
show more
[2023-06-04 22:10:09.031434] [authz_core:error] [pid 2782798:tid 140665984038464] [client 45.92.1.148:0] AH01630: client denied by server configuration: /var/www/*/wordpress , error_notes:non-dirs , URI:'/wordpress'
[2023-06-04 22:10:09.066287] [authz_core:error] [pid 2782798:tid 140665984038464] [client 45.92.1.148:0] AH01630: client denied by server configuration: /var/www/*/wp-admin/setup-config.php , URI:'/wp-admin/setup-config.php'
[2023-06-04 22:10:09.089027] [authz_core:error] [pid 2782798:tid 140665984038464] [client 45.92.1.148:0] AH01630: client denied by server configuration: /var/www/*/wp-admin/install.php , URI:'/wp-admin/install.php'
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
CryptoYakari
2023-06-04 19:09:01
(3 years ago)
45.92.1.148 - - [04/Jun/2023:22:08:59 +0300] "GET /wordpress HTTP/1.0" 404 3594 "-" "-"
45.92.1.148 ...
show more
45.92.1.148 - - [04/Jun/2023:22:08:59 +0300] "GET /wordpress HTTP/1.0" 404 3594 "-" "-"
45.92.1.148 - - [04/Jun/2023:22:08:59 +0300] "GET /wp-admin/setup-config.php HTTP/1.0" 404 3594 "-" "-"
45.92.1.148 - - [04/Jun/2023:22:08:59 +0300] "GET /wp-admin/install.php HTTP/1.0" 404 3594 "-" "-"
45.92.1.148 - - [04/Jun/2023:22:08:59 +0300] "GET /wp HTTP/1.0" 404 3594 "-" "-"
45.92.1.148 - - [04/Jun/2023:22:08:59 +0300] "GET /blog HTTP/1.0" 404 3594 "-" "-"
...
show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2023-06-04 18:36:08
(3 years ago)
POST requests to non-existent URL's
Hacking
Brute-Force
๐บ๐ธ
Major Hostility
2023-06-04 16:41:48
(3 years ago)
"GET /wordpress HTTP/1.1" 404
"GET /wp-admin/setup-config.php HTTP/1.1" 404
"GET /wp-admin/install.p ...
show more
"GET /wordpress HTTP/1.1" 404
"GET /wp-admin/setup-config.php HTTP/1.1" 404
"GET /wp-admin/install.php HTTP/1.1" 404
"GET /wp HTTP/1.1" 404
"GET /blog HTTP/1.1" 404
"GET /new HTTP/1.1" 404
"GET /old HTTP/1.1" 404
"GET /newsite HTTP/1.1" 404
"GET /test HTTP/1.1" 404
"GET /main HTTP/1.1" 404
"GET /testing HTTP/1.1" 404
"GET /site HTTP/1.1" 404
"GET /backup HTTP/1.1" 404
"GET /demo HTTP/1.1" 404
"GET /home HTTP/1.1" 404
"GET /tmp HTTP/1.1" 404
"GET /dev HTTP/1.1" 404
"GET /cms HTTP/1.1" 404
"GET /portal HTTP/1.1" 404
"GET /web HTTP/1.1" 404
"GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404
"POST /wp-plain.php HTTP/1.1" 404
%2
show less
Web App Attack
๐ฉ๐ช
dwmp
2023-06-04 16:03:35
(3 years ago)
[Sun Jun 04 18:03:28.953282 2023] [authz_core:error] [pid 1897644:tid 140464288167680] [client 45.92 ...
show more
[Sun Jun 04 18:03:28.953282 2023] [authz_core:error] [pid 1897644:tid 140464288167680] [client 45.92.1.148:50854] AH01630: client denied by server configuration: /var/www/vhosts/xforming.it/httpdocs/wp-admin/setup-config.php
[Sun Jun 04 18:03:34.212393 2023] [authz_core:error] [pid 1897606:tid 140464950830848] [client 45.92.1.148:55171] AH01630: client denied by server configuration: /var/www/vhosts/assicurazionemodena.it/httpdocs/wp-admin/setup-config.php
[Sun Jun 04 18:03:34.239586 2023] [authz_core:error] [pid 2136034:tid 140463952623360] [client 45.92.1.148:49275] AH01630: client denied by server configuration: /var/www/vhosts/assicurazioneparma.it/httpdocs/wp-admin/setup-config.php
[Sun Jun 04 18:03:35.104941 2023] [authz_core:error] [pid 2136034:tid 140463902267136] [client 45.92.1.148:62671] AH01630: client denied by server configuration: /var/www/vhosts/feikar-karate-difesapersonale.it/httpdocs/wp-admin/setup-config.php
[Sun Jun 04 18:03:35.240477 2023] [authz_core:error] [pid
...
show less
Brute-Force
๐บ๐ธ
etu brutus
2023-06-01 22:55:54
(3 years ago)
45.92.1.148 has been banned for [Control Panel abuse]
...
Hacking
Brute-Force
๐จ๐ฆ
ISPLtd
2023-06-01 22:36:48
(3 years ago)
45.92.1.148 - /wp-admin/setup-config.php [01/Jun/2023:19:36:47 -0300] "GET /wp-admin/setup-config.ph ...
show more
45.92.1.148 - /wp-admin/setup-config.php [01/Jun/2023:19:36:47 -0300] "GET /wp-admin/setup-config.php
45.92.1.148 - /wp-admin/setup-config.php [01/Jun/2023:19:36:47 -0300] "GET /wp-admin/setup-config.php
...
show less
Hacking
Web App Attack
Anonymous
2023-05-31 13:31:33
(3 years ago)
GET /.env HTTP/1.1
Web App Attack