๐น๐ท
rtbh.com.tr
2024-11-23 20:53:03
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2024-11-22 20:53:03
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2024-11-21 20:53:13
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐จ๐ฆ
minorOffense
2024-11-21 19:55:00
(1 year ago)
Scraping and attempting to create accounts.
Web App Attack
๐ช๐ธ
el-brujo
2024-11-21 17:55:39
(1 year ago)
21/Nov/2024:18:55:38.773320 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
21/Nov/2024:18:55:38.773320 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 83.147.251.113] ModSecurity: Warning. Match of "rx ^0?$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "178"] [id "920170"] [msg "GET or HEAD Request with Body Content"] [data "2274"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "elhacker.info"] [uri "/Cursos/node/1"] [unique_id "Zz90Gj0-Jl5RF6fysHTNAgAAAAE"]
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2024-11-21 14:40:23
(1 year ago)
[Thu Nov 21 21:38:18.136054 2024] [authz_core:error] [pid 83632:tid 136754292053696] [client 83.147. ...
show more
[Thu Nov 21 21:38:18.136054 2024] [authz_core:error] [pid 83632:tid 136754292053696] [client 83.147.251.113:40014] AH01630: client denied by server configuration: /var/www/modules/mod_simplefileuploadv1.3 [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[83788] [+9+YN9X18Is] [Zz9F2ipY3eifqSgq9X2UEwAABz4] keep_alive=[0] [2024-11-21 21:38:18.136060] [R:Zz9F2ipY3eifqSgq9X2UEwAABz4] UA:'Mozilla/5.0 (Windows NT 6.1; 7078 ; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36' Host:'staklim-jatim.bmkg.go.id' ACCEPT:'*/*' Accept-Encoding:'gzip, deflate, br
...
show less
Hacking
Web App Attack
Anonymous
2024-11-21 13:44:13
(1 year ago)
Web App Attack
Web App Attack
๐ง๐ช
taivas.nl
2024-11-21 13:02:13
(1 year ago)
Bad_requests
Bad Web Bot
๐ฎ๐ฉ
hermawan
2024-11-21 12:05:10
(1 year ago)
[Thu Nov 21 18:37:40.240726 2024] [security2:error] [pid 38617:tid 129882344773312] [client 83.147.2 ...
show more
[Thu Nov 21 18:37:40.240726 2024] [security2:error] [pid 38617:tid 129882344773312] [client 83.147.251.113:38568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.8.0/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "168"] [id "913101"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.27.1 request_line = POST /index.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager&method=form&action=upload HTTP/1.1 Request URI RAW = /index.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager&method=form&action=upload Request Basename = index.php"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [t
...
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-11-21 10:53:05
(1 year ago)
83.147.251.113 - - [21/Nov/2024:12:53:04 +0200] "GET /administrator/index.php HTTP/1.1" 404 273 "-" ...
show more
83.147.251.113 - - [21/Nov/2024:12:53:04 +0200] "GET /administrator/index.php HTTP/1.1" 404 273 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
MortimerCat
2024-11-21 10:02:34
(1 year ago)
Unauthorised use of XMLRPC
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-11-21 08:57:40
(1 year ago)
83.147.251.113 - - [21/Nov/2024:10:57:37 +0200] "GET /administrator/index.php HTTP/1.1" 404 276 "-" ...
show more
83.147.251.113 - - [21/Nov/2024:10:57:37 +0200] "GET /administrator/index.php HTTP/1.1" 404 276 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
83.147.251.113 - - [21/Nov/2024:10:57:38 +0200] "GET /administrator/index.php HTTP/1.1" 404 270 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2024-11-21 05:50:09
(1 year ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
hermawan
2024-11-21 04:53:37
(1 year ago)
[Thu Nov 21 10:36:55.458256 2024] [security2:error] [pid 99589:tid 125683485370048] [client 83.147.2 ...
show more
[Thu Nov 21 10:36:55.458256 2024] [security2:error] [pid 99589:tid 125683485370048] [client 83.147.251.113:51926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.7.0/rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "165"] [id "913101"] [msg "Found User-Agent associated with scripting/generic HTTP client"] [data "Matched Data: python-requests found within REQUEST_HEADERS:User-Agent: python-requests/2.27.1 request_line = POST /analisis-iklim/index.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager&method=form&action=upload HTTP/1.1"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scripting"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [tag "paranoia-level/2"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/analisis-iklim/index.php"] [unique_id "Zz6q176
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-21 03:46:24
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 83.147.251.113 (pumped-pest-n6.aeza.network): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 83.147.251.113 (pumped-pest-n6.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 20 22:46:20.782844 2024] [security2:error] [pid 20350:tid 20364] [client 83.147.251.113:48000] [client 83.147.251.113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.landmarkocchealth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.landmarkocchealth.com"] [uri "/uncategorized/wp-json/wp/v2/users/1"] [unique_id "Zz6tDJsf8kl6HH-Ug8atxwAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack