๐ฉ๐ช
bogdanv
2024-11-12 14:50:54
(1 year ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bogdanv
2024-10-24 05:15:18
(1 year ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bogdanv
2024-08-27 07:57:18
(2 years ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bogdanv
2024-07-18 06:56:49
(2 years ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Linuxmalwarehuntingnl
2024-07-01 10:36:29
(2 years ago)
Unauthorized connection attempt
Brute-Force
๐ฉ๐ช
bogdanv
2024-06-28 11:45:28
(2 years ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bogdanv
2024-06-27 06:40:42
(2 years ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Steve
2024-06-25 03:53:17
(2 years ago)
Excessive crawling - not obeying robots.txt
Bad Web Bot
Anonymous
2024-06-24 23:07:07
(2 years ago)
suspicious behavior
Brute-Force
Web App Attack
๐ฉ๐ช
bogdanv
2024-06-20 17:38:35
(2 years ago)
$f2bV_matches
DDoS Attack
Web Spam
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-08 12:16:53
(2 years ago)
(mod_security) mod_security (id:217291) triggered by 64.124.8.23 (64.124.8.23.available.above.net): ...
show more
(mod_security) mod_security (id:217291) triggered by 64.124.8.23 (64.124.8.23.available.above.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 08 08:16:48.032009 2024] [security2:error] [pid 21124] [client 64.124.8.23:25251] [client 64.124.8.23] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||furball.global|F|2"] [data "Matched Data: \\x0a found within ARGS_NAMES:\\x5cnfromwhere: \\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "furball.global"] [uri "/g12aboutsite.php"] [unique_id "ZmRLsN6CPjdlVkJB-nCuzgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2024-06-08 11:19:56
(2 years ago)
08/Jun/2024:13:19:56.479109 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
08/Jun/2024:13:19:56.479109 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 64.124.8.23] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "parrot.elhacker.net"] [uri "/index.db"] [unique_id "Z
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2024-06-08 07:27:35
(2 years ago)
08/Jun/2024:09:27:35.595328 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
08/Jun/2024:09:27:35.595328 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 64.124.8.23] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "parrot.elhacker.net"] [uri "/vindex.db"] [unique_id "
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-06-08 04:41:04
(2 years ago)
[Sat Jun 08 11:40:41.890739 2024] [security2:error] [pid 81634:tid 135112018626112] [client 64.124.8 ...
show more
[Sat Jun 08 11:40:41.890739 2024] [security2:error] [pid 81634:tid 135112018626112] [client 64.124.8.23:25497] [client 64.124.8.23] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Image" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.3.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "38"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Image found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; ImagesiftBot; +imagesift.com) request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "ZmPgyUjrTbjZHYL2C6M32gAAigM"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[81638] [RU65hGnTdlU] [ZmPgyUjrTbjZHYL2C6M32gAAigM] keep_alive=[1] [2024-06-08 11:40:41.890742] [R:ZmPgyUjrTbjZHYL2C6M32gAAigM] UA:'Mozilla/5.0 (compatible; ImagesiftBot; +imagesift.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/html,application/xhtml+xml,applic
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2024-06-08 04:19:43
(2 years ago)
08/Jun/2024:06:19:43.184796 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
08/Jun/2024:06:19:43.184796 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 64.124.8.23] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".db"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "parrot.elhacker.net"] [uri "/index.iso.db"] [unique_i
...
show less
Hacking
Web App Attack