๐จ๐ญ
abdullah
2023-06-16 04:07:43
(3 years ago)
Unauthorized connection attempt detected from IP address 52.146.13.149 to port 8080 (maple)
Port Scan
๐ฉ๐ช
derLoosi
2023-06-16 01:11:30
(3 years ago)
HV1.1 Blocked by UFW
Port Scan
Anonymous
2023-06-15 21:30:10
(3 years ago)
2:Unauthorized connection attempt detected
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2023-06-14 04:32:26
(3 years ago)
Many_bad_calls
Web App Attack
๐ธ๐ฌ
oh.mg
2023-06-14 04:11:04
(3 years ago)
(mod_security) mod_security (id:949110) triggered by 52.146.13.149 (US/United States/-): 1 in the la ...
show more
(mod_security) mod_security (id:949110) triggered by 52.146.13.149 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_TRIGGER; Logs: [Wed Jun 14 04:11:00.640665 2023] [:error] [pid 1005030:tid 140471980508864] [client 52.146.13.149:56222] [client 52.146.13.149] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset-3.3.0/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "159.223.54.230"] [uri "/.env"] [unique_id "ZIk91KqQKxKHPbmwGZOBZQAAAEc"]
show less
Brute-Force
SSH
๐ฆ๐บ
oh.mg
2023-06-14 03:54:55
(3 years ago)
(mod_security) mod_security (id:949110) triggered by 52.146.13.149 (-): 1 in the last 3600 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 52.146.13.149 (-): 1 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_TRIGGER; Logs: [Wed Jun 14 03:54:50.818946 2023] [:error] [pid 3493253:tid 140475696608960] [client 52.146.13.149:59686] [client 52.146.13.149] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset-3.3.0/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "170.64.170.178"] [uri "/.env"] [unique_id "ZIk6Cty7Mysn0V576cMd_wAAABc"]
show less
Brute-Force
SSH
๐ณ๐ฑ
oh.mg
2023-06-14 03:21:29
(3 years ago)
(mod_security) mod_security (id:949110) triggered by 52.146.13.149 (US/United States/-): 1 in the la ...
show more
(mod_security) mod_security (id:949110) triggered by 52.146.13.149 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_TRIGGER; Logs: [Wed Jun 14 03:21:28.189756 2023] [:error] [pid 407681:tid 140195798165184] [client 52.146.13.149:65253] [client 52.146.13.149] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset-3.3.0/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "178.128.246.40"] [uri "/.env"] [unique_id "ZIkyOIcxqVgadLgXUHr7EAAAAMU"]
show less
Brute-Force
SSH
๐ณ๐ฑ
kumiko
2023-06-14 02:23:55
(3 years ago)
[2023-06-14 02:23:54] Probing for dotfiles
"GET /.env HTTP/1.1" 403
Bad Web Bot
Web App Attack
๐บ๐ธ
PlexLads
2023-06-14 01:05:40
(3 years ago)
52.146.13.149 - - [13/Jun/2023:18:05:38 -0700] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 396 " ...
show more
52.146.13.149 - - [13/Jun/2023:18:05:38 -0700] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 52.146.13.149 - - [13/Jun/2023:18:05:38 -0700] "GET /feed/ HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 52.146.13.149 - - [13/Jun/2023:18:05:38 -0700] "GET /xmlrpc.php?rsd HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 52.146.13.149 - - [13/Jun/2023:18:05:38 -0700] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 52.146.13.149 - - [13/Jun/2023:18:05:38 -0700] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Hacking
Web App Attack
๐บ๐ธ
jimhill10
2023-06-14 00:50:28
(3 years ago)
(mod_security) mod_security (id:390613) triggered by 52.146.13.149 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:390613) triggered by 52.146.13.149 (US/United States/-): 5 in the last 3600 secs
show less
Brute-Force
Anonymous
2023-06-14 00:28:00
(3 years ago)
[Tue Jun 13 21:27:59.871298 2023] [php:error] [pid 847292] [client 52.146.13.149:56744] script '/var ...
show more
[Tue Jun 13 21:27:59.871298 2023] [php:error] [pid 847292] [client 52.146.13.149:56744] script '/var/www/html/colegioamen/xmlrpc.php' not found or unable to stat
...
show less
Web App Attack
๐บ๐ธ
Floofie
2023-06-14 00:25:44
(3 years ago)
52.146.13.149 - - [13/Jun/2023:20:25:44 -0400] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
52.146.13.149 - - [13/Jun/2023:20:25:44 -0400] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
52.146.13.149 - - [13/Jun/2023:20:25:44 -0400] "GET /wp-includes/ID3/license.txt HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
52.146.13.149 - - [13/Jun/2023:20:25:44 -0400] "GET /feed/ HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RiSec
2023-06-13 23:21:51
(3 years ago)
[Tue Jun 13 23:21:50.896652 2023] [:error] [pid 1010237] [client 52.146.13.149:59723] [client 52.146 ...
show more
[Tue Jun 13 23:21:50.896652 2023] [:error] [pid 1010237] [client 52.146.13.149:59723] [client 52.146.13.149] ModSecurity: Access denied with code 403 (phase 2). Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "696"] [id "920350"] [msg "Host header is a numeric IP address"] [data "178.128.134.179"] [severity "WARNING"] [ver "OWASP_CRS/3.2.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "178.128.134.179"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "ZIj6DoR0k4GfIxmX3nFRuQAAAAw"]
[Tue Jun 13 23:21:50.906243 2023] [:error] [pid 1010237] [client 52.146.13.149:59723] [client 52.146.13.149] ModSecurity: Access denied with code 403 (phase 2). Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr
...
show less
Web App Attack
๐ง๐ช
taivas.nl
2023-06-13 22:32:12
(3 years ago)
Bad_requests
Bad Web Bot
๐ณ๐ฑ
Pornomens
2023-06-13 21:39:17
(3 years ago)
52.146.13.149 - - [13/Jun/2023:23:39:17 +0200] "GET / HTTP/1.1" 403 473 "-" "Mozilla/5.0 (Windows NT ...
show more
52.146.13.149 - - [13/Jun/2023:23:39:17 +0200] "GET / HTTP/1.1" 403 473 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
52.146.13.149 - - [13/Jun/2023:23:39:17 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 403 472 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
52.146.13.149 - - [13/Jun/2023:23:39:17 +0200] "GET /feed/ HTTP/1.1" 403 472 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack