๐ง๐ช
cmbplf
2024-06-10 13:59:12
(2 years ago)
13.617 4xx requests in 1 hour (2w1d2h)
Brute-Force
Bad Web Bot
๐ฉ๐ช
SCHAPPY
2024-06-07 14:53:58
(2 years ago)
Bad bot identified by user agent
Bad Web Bot
๐ฆ๐บ
MAGIC
2024-06-07 03:12:18
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฆ๐บ
clapper
2024-06-05 08:17:28
(2 years ago)
(mod_security) mod_security (id:980001) triggered by 64.124.8.92 (US/United States/64.124.8.92.avail ...
show more
(mod_security) mod_security (id:980001) triggered by 64.124.8.92 (US/United States/64.124.8.92.available.above.net): 5 in the last 3600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐ฆ๐บ
clapper
2024-06-02 22:35:37
(2 years ago)
(mod_security) mod_security (id:980001) triggered by 64.124.8.92 (US/United States/64.124.8.92.avail ...
show more
(mod_security) mod_security (id:980001) triggered by 64.124.8.92 (US/United States/64.124.8.92.available.above.net): 5 in the last 3600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐ฉ๐ฐ
buusbudde.dk
2024-06-02 19:36:06
(2 years ago)
[Sun Jun 02 21:36:05.557584 2024] [security2:error] [pid 4102029] [client 64.124.8.92:48729] [client ...
show more
[Sun Jun 02 21:36:05.557584 2024] [security2:error] [pid 4102029] [client 64.124.8.92:48729] [client 64.124.8.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.buusbudde.dk"] [uri "/robots.txt"] [unique_id "ZlzJpZ4PzwdvuNZeBMYRogAAAAQ"]
[Sun Jun 02 21:36:05.713759 2024] [security2:error] [pid 4102029] [client 64.124.8.92:48729] [client 64.124.8.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver
...
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2024-06-02 04:32:17
(2 years ago)
[Sun Jun 02 11:32:15.427079 2024] [security2:error] [pid 467698:tid 127392026723904] [client 64.124. ...
show more
[Sun Jun 02 11:32:15.427079 2024] [security2:error] [pid 467698:tid 127392026723904] [client 64.124.8.92:44381] [client 64.124.8.92] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Image" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "37"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Image found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; ImagesiftBot; +imagesift.com) request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "Zlv1z-yGalFAZgHUitrDdAAAyCc"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[467738] [iX19s1BhNnE] [Zlv1z-yGalFAZgHUitrDdAAAyCc] keep_alive=[1] [2024-06-02 11:32:15.427082] [R:Zlv1z-yGalFAZgHUitrDdAAAyCc] UA:'Mozilla/5.0 (compatible; ImagesiftBot; +imagesift.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/html,application/xhtml+xml,appl
...
show less
Hacking
Web App Attack
๐ซ๐ท
Sklurk
2024-05-26 08:49:53
(2 years ago)
Web App Attack
Web App Attack
๐ฎ๐ฉ
hermawan
2024-05-24 18:20:51
(2 years ago)
[Sat May 25 01:20:49.110998 2024] [security2:error] [pid 929169:tid 140614094030400] [client 64.124. ...
show more
[Sat May 25 01:20:49.110998 2024] [security2:error] [pid 929169:tid 140614094030400] [client 64.124.8.92:8797] [client 64.124.8.92] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "Image" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.0.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "37"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: Image found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (compatible; ImagesiftBot; +imagesift.com) request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "ZlDagSVt3EGZ-RQuv06NogAADQE"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[929171] [1pMVOscDl7Q] [ZlDagSVt3EGZ-RQuv06NogAADQE] keep_alive=[1] [2024-05-25 01:20:49.111001] [R:ZlDagSVt3EGZ-RQuv06NogAADQE] UA:'Mozilla/5.0 (compatible; ImagesiftBot; +imagesift.com)' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'text/html,application/xhtml+xml,appli
...
show less
Hacking
Web App Attack
๐ซ๐ท
Sklurk
2024-05-24 17:57:49
(2 years ago)
Web App Attack
Web App Attack
๐ฆ๐บ
MAGIC
2024-05-24 04:04:28
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ซ๐ท
oh.mg
2024-05-24 00:27:31
(2 years ago)
(mod_security) mod_security (id:949110) triggered by 64.124.8.92 (US/United States/64.124.8.92.avail ...
show more
(mod_security) mod_security (id:949110) triggered by 64.124.8.92 (US/United States/64.124.8.92.available.above.net): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Fri May 24 00:27:28.763928 2024] [:error] [pid 3866328:tid 139656909784832] [client 64.124.8.92:39889] [client 64.124.8.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "oh.mg"] [uri "/robots.txt"] [unique_id "Zk-e8JJ5frMDSGC9bJHx3wAAAMc"]
show less
Port Scan
๐ฉ๐ช
SCHAPPY
2024-05-23 17:57:34
(2 years ago)
Bad bot identified by user agent
Bad Web Bot
๐ฆ๐บ
clapper
2024-05-14 15:05:42
(2 years ago)
(mod_security) mod_security (id:980001) triggered by 64.124.8.92 (US/United States/64.124.8.92.avail ...
show more
(mod_security) mod_security (id:980001) triggered by 64.124.8.92 (US/United States/64.124.8.92.available.above.net): 5 in the last 3600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
mwgbr
2024-05-13 21:16:30
(2 years ago)
64.124.8.92 (US/United States/64.124.8.92.available.above.net), more than 10 Apache 403 hits
Hacking