๐บ๐ธ
threatx
2024-11-27 22:58:38
(1 year ago)
Common blacklisted IPs across tenants
DDoS Attack
Bad Web Bot
Web App Attack
๐บ๐ธ
threatx
2024-11-26 08:22:06
(1 year ago)
Common blacklisted IPs across tenants
DDoS Attack
Bad Web Bot
Web App Attack
Anonymous
2024-11-21 19:11:04
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-11-21 18:22:32
(1 year ago)
wordpress-trap
Web App Attack
๐ฆ๐บ
MAGIC
2024-11-21 04:07:48
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐น๐ท
rtbh.com.tr
2024-11-20 20:53:13
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ป๐ณ
Xuan Can
2024-11-20 15:35:25
(1 year ago)
(mod_security) mod_security (id:6) triggered by 52.169.50.79 (IE/Ireland/-): 1 in the last 3600 secs ...
show more
(mod_security) mod_security (id:6) triggered by 52.169.50.79 (IE/Ireland/-): 1 in the last 3600 secs; Ports: 80,443; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 20 22:35:16.517786 2024] [security2:error] [pid 625:tid 655] [client 52.169.50.79:2630] [client 52.169.50.79] ModSecurity: Access denied with connection close (phase 2). Pattern match "wp-login.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "62"] [id "6"] [severity "CRITICAL"] [hostname "kb.pavietnam.vn"] [uri "/wp-login.php"] [unique_id "Zz4BtKRXDaVJ_Spy3gm7KAAAAEM"]
show less
Brute-Force
SSH
๐ช๐ธ
robotstxt
2024-11-19 22:33:59
(1 year ago)
52.169.50.79 - - [19/Nov/2024:22:33:08 +0000] "GET /cgi-bin/wp-login.php HTTP/1.1" 404 156473 "-" rt ...
show more
52.169.50.79 - - [19/Nov/2024:22:33:08 +0000] "GET /cgi-bin/wp-login.php HTTP/1.1" 404 156473 "-" rt="0.334" "-" "-" h="economipedia.com" sn="economipedia.com" ru="/cgi-bin/wp-login.php" u="/index.php" ucs="-" ua="unix:/var/run/php/economipedia74.sock" us="404" uct="0.000" urt="0.334"
52.169.50.79 - - [19/Nov/2024:22:33:09 +0000] "GET /cgi-bin/themes.php HTTP/1.1" 404 156465 "-" rt="0.320" "-" "-" h="economipedia.com" sn="economipedia.com" ru="/cgi-bin/themes.php" u="/index.php" ucs="-" ua="unix:/var/run/php/economipedia74.sock" us="404" uct="0.000" urt="0.320"
52.169.50.79 - - [19/Nov/2024:22:33:08 +0000] "GET /cgi-bin/wp-login.php HTTP/1.1" 404 156473 "-" "-" "-"
52.169.50.79 - - [19/Nov/2024:22:33:09 +0000] "GET /cgi-bin/themes.php HTTP/1.1" 404 156465 "-" "-" "-"
52.169.50.79 - - [19/Nov/2024:22:33:20 +0000] "GET /cgi-bin/file.php HTTP/1.1" 404 156465 "-" "-" "-"
...
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2024-11-19 21:39:58
(1 year ago)
Cloudflare WAF: Request Path: /wp-content/plugins/ioptimization/IOptimize.php Request Query: ?rchk H ...
show more
Cloudflare WAF: Request Path: /wp-content/plugins/ioptimization/IOptimize.php Request Query: ?rchk Host: elhacker.net userAgent: Action: log Source: firewallManaged ASN Description: MICROSOFT-CORP-MSN-AS-BLOCK Country: IE Method: GET Timestamp: 2024-11-19T21:39:58Z ruleId: 9f35644b7f734c87a57cfd6d8b036974. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐น๐ท
rtbh.com.tr
2024-11-19 20:53:12
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ช๐ธ
el-brujo
2024-11-19 19:23:14
(1 year ago)
Cloudflare WAF: Request Path: /wp-content/plugins/ioptimization/IOptimize.php Request Query: ?rchk H ...
show more
Cloudflare WAF: Request Path: /wp-content/plugins/ioptimization/IOptimize.php Request Query: ?rchk Host: ns2.elhacker.net userAgent: Action: log Source: firewallManaged ASN Description: MICROSOFT-CORP-MSN-AS-BLOCK Country: IE Method: GET Timestamp: 2024-11-19T19:23:14Z ruleId: 9f35644b7f734c87a57cfd6d8b036974. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2024-11-19 19:22:35
(1 year ago)
19/Nov/2024:20:22:35.430836 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
19/Nov/2024:20:22:35.430836 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 52.169.50.79] ModSecurity: Warning. Matched phrase "gzdecode" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-933-APPLICATION-ATTACK-PHP.conf"] [line "295"] [id "933150"] [msg "PHP Injection Attack: High-Risk PHP Function Name Found"] [data "Matched Data: gzdecode found within REQUEST_FILENAME: /wp-includes/simplepie/gzdecodes.php.suspected"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-php"] [tag "platform-multi"] [tag "attack-injection-php"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "ns2.elhacker.net"] [uri "/wp-includes/SimplePie/gzdecodes.php.suspected"] [unique_id "Zzzle19Vj3YOXlp0_5dloQACajM"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
hostseries
2024-11-19 18:30:39
(1 year ago)
Trigger: LF_MODSEC
Brute-Force
๐ณ๐ฑ
hostio.solutions
2024-11-19 14:23:12
(1 year ago)
Failed login attempt detected by Fail2Ban in recidive jail
Brute-Force
๐ฉ๐ช
botreporter
2024-11-19 11:48:01
(1 year ago)
CMS vulnerability/installation scanning
Brute-Force
Web App Attack