๐บ๐ธ
TPI-Abuse
2024-08-20 00:59:26
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 77.105.147.233 (flowery-bone.aeza.network): 1 i ...
show more
(mod_security) mod_security (id:234930) triggered by 77.105.147.233 (flowery-bone.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 19 20:59:20.364296 2024] [security2:error] [pid 1813989:tid 1813989] [client 77.105.147.233:43928] [client 77.105.147.233] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.letmespeakpodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.letmespeakpodcast.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ZsPqaFKwgXM6lj5XZXs9tAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2024-08-19 23:54:12
(2 years ago)
Drupal Authentication failure
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2024-08-19 20:39:36
(2 years ago)
Cloudflare WAF: Request Path: /php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (i ...
show more
Cloudflare WAF: Request Path: /php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (iPhone; CPU iPhone OS 5_0 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A334 Safari/7534.48.3 Action: block Source: firewallManaged ASN Description: AEZA-AS Country: DE Method: GET Timestamp: 2024-08-19T20:39:36Z ruleId: 609b158b7e0f4d67ba7cde1d4d4a06fe. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐จ๐ฆ
minorOffense
2024-08-19 17:43:00
(2 years ago)
Attempting to exploit CMS vulnerabilities
Hacking
Web App Attack
๐บ๐ธ
DJ
2024-08-19 16:00:00
(2 years ago)
form honeypot
Web Spam
Exploited Host
Web App Attack
Anonymous
2024-08-19 14:04:34
(2 years ago)
[15:04:32] 4: Exploit attempt against non-existent file - /vendor/phpunit/phpunit/src/Util/PHP/eval- ...
show more
[15:04:32] 4: Exploit attempt against non-existent file - /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php (Repeat abuser, 2 other attacks previously recorded.)
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-08-19 13:59:47
(2 years ago)
77.105.147.233 - - [19/Aug/2024:16:59:46 +0300] "GET /administrator/index.php HTTP/1.1" 404 275 "-" ...
show more
77.105.147.233 - - [19/Aug/2024:16:59:46 +0300] "GET /administrator/index.php HTTP/1.1" 404 275 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-19 11:19:28
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 77.105.147.233 (flowery-bone.aeza.network): 1 i ...
show more
(mod_security) mod_security (id:234930) triggered by 77.105.147.233 (flowery-bone.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 19 07:19:22.590789 2024] [security2:error] [pid 16932:tid 16932] [client 77.105.147.233:50754] [client 77.105.147.233] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.crep-psych.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.crep-psych.org"] [uri "/crepcon2024/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ZsMqOm54lBc05ZwcwMNz4gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-19 10:56:59
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 77.105.147.233 (flowery-bone.aeza.network): 1 i ...
show more
(mod_security) mod_security (id:234930) triggered by 77.105.147.233 (flowery-bone.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 19 06:56:52.747443 2024] [security2:error] [pid 3128:tid 3140] [client 77.105.147.233:40446] [client 77.105.147.233] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.killasgarage.bike|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.killasgarage.bike"] [uri "/uncategorized/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ZsMk9LUECyJ9zFcUvj-lkAAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2024-08-19 10:12:07
(2 years ago)
19/Aug/2024:12:12:07.089938 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
19/Aug/2024:12:12:07.089938 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 77.105.147.233] ModSecurity: Warning. Matched phrase ".htaccess" at ARGS:name[#markup]. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "98"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: .htaccess found within ARGS:name[#markup]: echo 77u/r0lgodlhowo8p3boccakzxjyb3jfcmvwb3j0aw5nkevfquxmif4grv9ot1rjq0upowply2hvicc8c2nyaxb0pgpkb2n1bwvudc50axrszsa9igf0b2ioilywrkdjrupavuvgvfv5qlzvrxhquvvsrlvnpt0iktskd2luzg93lmfkzev2zw50tglzdgvuzxioikrptunvbnrlbnrmb2fkzwqilgz1bmn0aw9ukcl7bgv0igu9zg9jdw1lbnquy3jlyxrlrwxlbwvudcgizm9ybsipo2uubwv0ag9kpsjwb3n0iixllmvuy3r5cgu9im11bhrpcgfydc9mb3jtlwrhdgeio2xldcb0pwrvy3vtzw50lmnyzwf0zuvszw1lbnqoimluchv0iik7dc50exblpsjmawxliix0lm5hbwu9imzpbguilhqucmvxdwl..."] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2024-08-19 08:33:08
(2 years ago)
Cloudflare WAF: Request Path: /php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (i ...
show more
Cloudflare WAF: Request Path: /php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (iPhone; CPU iPhone OS 5_0 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A334 Safari/7534.48.3 Action: block Source: firewallManaged ASN Description: AEZA-AS Country: DE Method: GET Timestamp: 2024-08-19T08:33:08Z ruleId: 609b158b7e0f4d67ba7cde1d4d4a06fe. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2024-08-19 04:28:31
(2 years ago)
[05:28:29] 4: Exploit attempt against non-existent file - /vendor/phpunit/phpunit/src/Util/PHP/eval- ...
show more
[05:28:29] 4: Exploit attempt against non-existent file - /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-19 00:41:57
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 77.105.147.233 (flowery-bone.aeza.network): 1 i ...
show more
(mod_security) mod_security (id:234930) triggered by 77.105.147.233 (flowery-bone.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 20:41:52.579271 2024] [security2:error] [pid 29951:tid 29951] [client 77.105.147.233:33572] [client 77.105.147.233] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.ideaofauniversity.website|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.ideaofauniversity.website"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ZsKU0D3q-ReFR7unrobmQgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-08-18 23:00:18
(2 years ago)
77.105.147.233 - - [19/Aug/2024:02:00:18 +0300] "GET /.env HTTP/1.1" 404 270 "-" "Mozilla/5.0 (X11; ...
show more
77.105.147.233 - - [19/Aug/2024:02:00:18 +0300] "GET /.env HTTP/1.1" 404 270 "-" "Mozilla/5.0 (X11; Ubuntu; 2923 ;Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
...
show less
Web App Attack
๐ฌ๐ง
SilverZippo
2024-08-18 22:36:26
(2 years ago)
Web App Attack
Web App Attack