๐ณ๐ฑ
Linuxmalwarehuntingnl
2024-07-01 10:53:04
(1 year ago)
Unauthorized connection attempt
Brute-Force
๐ซ๐ท
tecnicorioja
2024-04-18 22:01:08
(2 years ago)
(Mod_security) [18/Apr/2024:19:48:19.518654
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Incidents Response Neptus Team
2024-04-18 17:14:00
(2 years ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-18 17:07:25
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 93.100.205.244 (93.100.205.244.pool.sknt.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 93.100.205.244 (93.100.205.244.pool.sknt.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 18 13:07:20.811664 2024] [security2:error] [pid 16074:tid 47071737358080] [client 93.100.205.244:49466] [client 93.100.205.244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yourwitch.com"] [uri "/.git/HEAD"] [unique_id "ZiFTSCxVtoSvgZqBVtGH0AAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
GoodOldTOS
2024-04-18 17:06:46
(2 years ago)
Highly suspect IP
Hacking
Web App Attack
๐บ๐ธ
woof
2024-04-18 16:45:09
(2 years ago)
This IP accessed a banned path "/.git/HEAD" with User Agent "Python-urllib/3.11". (ListenCaddy)
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-18 16:43:42
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 93.100.205.244 (93.100.205.244.pool.sknt.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 93.100.205.244 (93.100.205.244.pool.sknt.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 18 12:43:36.564358 2024] [security2:error] [pid 17840] [client 93.100.205.244:54378] [client 93.100.205.244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astrology7.com"] [uri "/.git/HEAD"] [unique_id "ZiFNuP_Qos6q1BTnmQoaWgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Incidents Response Neptus Team
2024-04-18 16:23:00
(2 years ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-18 16:08:12
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 93.100.205.244 (93.100.205.244.pool.sknt.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 93.100.205.244 (93.100.205.244.pool.sknt.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 18 12:08:06.668005 2024] [security2:error] [pid 19025] [client 93.100.205.244:59858] [client 93.100.205.244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alisonchristen.com"] [uri "/.git/HEAD"] [unique_id "ZiFFZkN8hn_jTMT7_9626AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
pa4080
2024-04-18 15:43:09
(2 years ago)
Detected by ModSecurity. Request URI: /.git/HEAD
Web App Attack
๐ซ๐ท
oh.mg
2024-04-18 15:32:03
(2 years ago)
(mod_security) mod_security (id:949110) triggered by 93.100.205.244 (RU/Russia/93.100.205.244.pool.s ...
show more
(mod_security) mod_security (id:949110) triggered by 93.100.205.244 (RU/Russia/93.100.205.244.pool.sknt.ru): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Thu Apr 18 15:32:01.171944 2024] [:error] [pid 219026:tid 139936342701824] [client 93.100.205.244:52842] [client 93.100.205.244] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "oh.mg"] [uri "/.git/HEAD"] [unique_id "ZiE88UQ5elUlnZsUNG2KWgAAAMs"]
show less
Port Scan
๐ฉ๐ช
Mr-Money
2024-04-18 15:19:57
(2 years ago)
93.100.205.244 - - [18/Apr/2024:17:19:56 +0200] "GET /.git/HEAD HTTP/1.1" 404 440 "-" "Python-urllib ...
show more
93.100.205.244 - - [18/Apr/2024:17:19:56 +0200] "GET /.git/HEAD HTTP/1.1" 404 440 "-" "Python-urllib/3.11"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-18 15:00:23
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 93.100.205.244 (93.100.205.244.pool.sknt.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 93.100.205.244 (93.100.205.244.pool.sknt.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 18 11:00:17.093169 2024] [security2:error] [pid 26173] [client 93.100.205.244:56214] [client 93.100.205.244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerusalem-temple-today.com"] [uri "/.git/HEAD"] [unique_id "ZiE1gRowEx5881F4KLkUtwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jcbriar
2024-04-18 14:52:13
(2 years ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐ฉ๐ช
dwmp
2024-04-18 14:44:25
(2 years ago)
Url probing: /.git/HEAD
Web App Attack