๐จ๐ญ
backslash
2025-01-23 14:20:32
(1 year ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
Anonymous
2025-01-20 12:14:01
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-04 14:33:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 47.128.126.5 (ec2-47-128-126-5.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.126.5 (ec2-47-128-126-5.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 04 09:33:32.425691 2025] [security2:error] [pid 2858127:tid 2858127] [client 47.128.126.5:51404] [client 47.128.126.5] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/rucaptcha.com"] [unique_id "Z3lGvLaZ5peWIFhHZvKKBAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Steve
2025-01-04 11:44:23
(1 year ago)
Excessive crawling - not obeying robots.txt
Bad Web Bot
Anonymous
2025-01-03 04:42:33
(1 year ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-01-02 15:03:57
(1 year ago)
47.128.126.5 - - [02/Jan/2025:16:03:56 +0100] "GET /robots.txt HTTP/1.1" 403 4805 "-" "Mozilla/5.0 ( ...
show more
47.128.126.5 - - [02/Jan/2025:16:03:56 +0100] "GET /robots.txt HTTP/1.1" 403 4805 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )"
...
show less
Web App Attack
Anonymous
2024-12-18 20:01:48
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2024-12-18 17:19:33
(1 year ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฎ๐ฉ
hermawan
2024-12-13 00:36:57
(1 year ago)
[Thu Dec 12 13:38:14.953943 2024] [security2:error] [pid 520222:tid 129449609438912] [client 47.128. ...
show more
[Thu Dec 12 13:38:14.953943 2024] [security2:error] [pid 520222:tid 129449609438912] [client 47.128.126.5:23994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.9.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/profil/arsip-artikel?catid=485&id=1189%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-25-oktober-2016-1-november-2016 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/index.php/profil/arsip-artikel"] [unique_id "Z1qE1tt1ooBMe9MN_7_JvAAB7DU"] [staklim-malang.info] [staklim-malang.info] top=[520276] [bQTd9OTr1do] [Z1qE1tt1ooBMe9MN_7_
...
show less
Hacking
Web App Attack
๐ฆ๐บ
MAGIC
2024-12-10 08:05:45
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐น๐ท
selahattinalan
2024-12-05 06:30:24
(1 year ago)
47.128.126.5 - - [05/Dec/2024:09:30:22 +0300] "GET /index.php?order=DESC&product_id=1186&route=produ ...
show more
47.128.126.5 - - [05/Dec/2024:09:30:22 +0300] "GET /index.php?order=DESC&product_id=1186&route=product%2Fproduct&sort=p.price&tag=Krm+No+6827++++-++BMW HTTP/2.0" 200 5282 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.0.0 Safari/537.36"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-12-03 15:39:19
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 47.128.126.5 (ec2-47-128-126-5.ap-southeast-1.c ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.126.5 (ec2-47-128-126-5.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 03 10:39:13.801217 2024] [security2:error] [pid 21055:tid 21055] [client 47.128.126.5:34002] [client 47.128.126.5] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alexgitlin.com|F|2"] [data ".thehighwaystar.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alexgitlin.com"] [uri "/npp/www.thehighwaystar.com"] [unique_id "Z08mIfwa4pe8VmbuvPbI4QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-02 04:58:44
(1 year ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-12-01 02:24:09
(1 year ago)
Ports: 80,443; Direction: 1; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฎ๐ฉ
hermawan
2024-11-30 04:11:05
(1 year ago)
[Sat Nov 30 04:30:07.576270 2024] [security2:error] [pid 881606:tid 126616860591808] [client 47.128. ...
show more
[Sat Nov 30 04:30:07.576270 2024] [security2:error] [pid 881606:tid 126616860591808] [client 47.128.126.5:18848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Feed" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.8.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "61"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Feed found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] ) request_line = GET /index.php/profil/arsip-artikel?catid=472&id=600%3Aprakiraan-cuaca-daerah-malang-dan-batu-seminggu-ke-depan-berlaku-tanggal-7-juli-13-juli-2015&start=160 HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/arsip-artikel"] [unique_id "Z0oyX9-bx9fWs9gBvnFQvAAAtwU"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[881612] [3wIg58vihtc] [Z0oyX9-
...
show less
Hacking
Web App Attack