MAGIC
2025-03-27 16:02:34
(17 hours ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-03-23 04:09:35
(5 days ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
librebit
2025-03-21 06:23:59
(1 week ago)
Brute force
Brute-Force
Anonymous
2025-03-18 18:18:28
(1 week ago)
Excessive crawling/scraping
Hacking
Brute-Force
Anonymous
2025-03-14 16:57:26
(1 week ago)
Reported from Nginx log analysis 18. Log: 47.128.126.4 - - [14/Mar/2025:xx:xx:xx 0100] "GET /?C=M;O ... show more Reported from Nginx log analysis 18. Log: 47.128.126.4 - - [14/Mar/2025:xx:xx:xx 0100] "GET /?C=M;O=D HTTP/2.0" xxx xxx "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )" "-" "SG Singapore Singapore" "AS16509" "AMAZON-02" show less
Port Scan
Brute-Force
SSH
Anonymous
2025-03-11 17:35:25
(2 weeks ago)
Excessive crawling/scraping
Hacking
Brute-Force
Mendip_Defender
2025-03-10 15:25:37
(2 weeks ago)
47.128.126.4 - - [10/Mar/2025:15:25:35 +0000] "GET /?%3Fs=f0df5911f6cf969ddcdac4f7802cb3e4 HTTP/1.0" ... show more 47.128.126.4 - - [10/Mar/2025:15:25:35 +0000] "GET /?%3Fs=f0df5911f6cf969ddcdac4f7802cb3e4 HTTP/1.0" 200 12378 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
... show less
Bad Web Bot
Anonymous
2025-03-07 10:19:52
(2 weeks ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Burayot
2025-03-07 07:42:33
(3 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 47.128.126.4 (SG/Singapore/ec2-47-1 ... show more LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 47.128.126.4 (SG/Singapore/ec2-47-128-126-4.ap-southeast-1.compute.amazonaws.com): 1 in the last 3600 secs show less
Web App Attack
Steve
2025-03-02 10:32:11
(3 weeks ago)
Excessive crawling - not obeying robots.txt
Bad Web Bot
backslash
2025-02-25 09:10:12
(1 month ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
Anonymous
2025-02-23 00:34:08
(1 month ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
hermawan
2025-02-19 12:33:18
(1 month ago)
[Wed Feb 19 17:32:03.819778 2025] [security2:error] [pid 118617:tid 140022200137408] [client 47.128. ... show more [Wed Feb 19 17:32:03.819778 2025] [security2:error] [pid 118617:tid 140022200137408] [client 47.128.126.4:25850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.10.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "165"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/profil/meteorologi/list-all-categories/4083-klimatologi/infografis/infografis-klimatologi/infografis-dasarian/infografis-dasarian-tahun-2021/555559106-infografis-dasarian-informasi-iklim-jatim-update-10-november-2021 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/meteorologi/list-all-categories/4083-klimatologi/infografis/infografis-klima
... show less
Hacking
Web App Attack
ipblock.com
2025-02-19 09:51:29
(1 month ago)
IPBlock protected site ID [1365-l].
Bad agent
Bad Web Bot
Mendip_Defender
2025-02-14 23:19:23
(1 month ago)
47.128.126.4 - - [14/Feb/2025:23:19:21 +0000] "GET /?mode=threaded&p=39721 HTTP/1.0" 404 42398 "-" " ... show more 47.128.126.4 - - [14/Feb/2025:23:19:21 +0000] "GET /?mode=threaded&p=39721 HTTP/1.0" 404 42398 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
... show less
Bad Web Bot