๐ฆ๐บ
MAGIC
2024-04-20 06:04:43
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
hermawan
2024-04-19 04:11:22
(2 years ago)
[Fri Apr 19 11:11:20.849146 2024] [security2:error] [pid 265354:tid 129503634392640] [client 47.128. ...
show more
[Fri Apr 19 11:11:20.849146 2024] [security2:error] [pid 265354:tid 129503634392640] [client 47.128.126.42:33078] [client 47.128.126.42] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "37"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/analisis-kondisi-dinamika-atmosfer-laut-dasarian/3958-analisis-kondisi-dinamika-atmosfer-laut-dasarian-tahun-2019/555557387-analisis-dan-prediksi-dasarian-dinamika-atmosfer-dan-prediksi-curah-hujan-update-dasarian-ii-juni-2019 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/analisis-kondisi-dinamika-atmosfer-laut-dasari
...
show less
Hacking
Web App Attack
๐บ๐ธ
toolsource.com
2024-04-14 05:14:52
(2 years ago)
47.128.126.42 - - [14/Apr/2024:01:14:51 -0400] "GET /images/prod_images/FIB112_1200Wx1200H.jpg HTTP/ ...
show more
47.128.126.42 - - [14/Apr/2024:01:14:51 -0400] "GET /images/prod_images/FIB112_1200Wx1200H.jpg HTTP/2.0" 200 133769 "https://caribbeanrestaurantweek.us/Honey-Body-Filler-Thinner-Fibreglass-Evercoat-2216515.html" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
...
show less
Bad Web Bot
๐ฎ๐ฉ
hermawan
2024-04-11 05:36:51
(2 years ago)
[Thu Apr 11 12:36:49.348764 2024] [security2:error] [pid 95351:tid 125389307381312] [client 47.128.1 ...
show more
[Thu Apr 11 12:36:49.348764 2024] [security2:error] [pid 95351:tid 125389307381312] [client 47.128.126.42:14138] [client 47.128.126.42] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "36"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/monitoring-hari-tanpa-hujan-berturut-turut/4162-monitoring-hari-tanpa-hujan-berturut-turut-propinsi-jawa-timur/analisis-dasarian-monitoring-hari-tanpa-hujan-berturut-turut-provinsi-jawa-timur-tahun-2023/555559907-analisis-dasarian-monitoring-hari-tanpa-hujan-berturut-tu..."] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/monitorin
...
show less
Hacking
Web App Attack
๐บ๐ธ
toolsource.com
2024-04-09 19:27:03
(2 years ago)
47.128.126.42 - - [09/Apr/2024:15:27:02 -0400] "GET /hot-deals-c-912/mr01-inspection-tel-mirror-pkg- ...
show more
47.128.126.42 - - [09/Apr/2024:15:27:02 -0400] "GET /hot-deals-c-912/mr01-inspection-tel-mirror-pkg-p-294315.html HTTP/2.0" 301 118 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Anonymous
2024-04-09 09:53:26
(2 years ago)
Ports: 20,21,25,53,80,110,143,443,465,587,993,995,2077,2078,2079,2080,2082,2083,2086,2087,2095,2096, ...
show more
Ports: 20,21,25,53,80,110,143,443,465,587,993,995,2077,2078,2079,2080,2082,2083,2086,2087,2095,2096,3306,2195; Direction: 0; Trigger: LF_CUSTOMTRIGGER
show less
Brute-Force
SSH
๐ฆ๐บ
MAGIC
2024-04-08 18:09:29
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-04-07 04:07:32
(2 years ago)
(mod_security) mod_security (id:243420) triggered by 47.128.126.42 (ec2-47-128-126-42.ap-southeast-1 ...
show more
(mod_security) mod_security (id:243420) triggered by 47.128.126.42 (ec2-47-128-126-42.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 00:07:25.832797 2024] [security2:error] [pid 30832:tid 47345015240448] [client 47.128.126.42:56768] [client 47.128.126.42] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:/upload/2022/10/01/20221001072036-2854b078-xs.png" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.ajbruner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.ajbruner.com"] [uri "/ct/artlib/i.php"] [unique_id "ZhIb_XjtAaDadsosXBgAQwAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2024-04-06 09:56:46
(2 years ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2024-04-03 03:03:48
(2 years ago)
Web App Attack
Web App Attack
๐ซ๐ท
bigorre.org
2024-04-01 04:58:07
(2 years ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ฆ๐บ
MAGIC
2024-03-31 09:00:12
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ซ๐ท
Sklurk
2024-03-29 18:03:01
(2 years ago)
Web App Attack
Web App Attack
Anonymous
2024-03-29 11:22:25
(2 years ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
toolsource.com
2024-03-28 11:13:30
(2 years ago)
47.128.126.42 - - [28/Mar/2024:07:13:29 -0400] "GET /supplies-c-34_72/?display=1&filter_id=22202&pag ...
show more
47.128.126.42 - - [28/Mar/2024:07:13:29 -0400] "GET /supplies-c-34_72/?display=1&filter_id=22202&page=10&sort=20a HTTP/2.0" 200 61389 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
...
show less
Bad Web Bot