๐บ๐ธ
gu-alvareza
2024-09-04 07:05:24
(2 years ago)
ALFA.TEaM.Web.Shell
Hacking
๐บ๐ธ
rdpguard.com
2024-09-03 22:06:48
(2 years ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฌ๐ง
David Gebler
2024-09-03 21:34:24
(2 years ago)
94.156.68.167 - - [03/Sep/2024:21:34:24 +0000] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 4 ...
show more
94.156.68.167 - - [03/Sep/2024:21:34:24 +0000] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 5113 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
on-com
2024-09-03 21:24:15
(2 years ago)
URL scan
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2024-09-03 21:16:38
(2 years ago)
Cloudflare WAF: Request Path: /style.php Request Query: Host: ns2.elhacker.net userAgent: Mozlila/5 ...
show more
Cloudflare WAF: Request Path: /style.php Request Query: Host: ns2.elhacker.net userAgent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 Action: block Source: firewallManaged ASN Description: LIMENET Country: NL Method: GET Timestamp: 2024-09-03T21:16:38Z ruleId: 0242110ae62e44028a13bf4834780914. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2024-09-03 20:42:48
(2 years ago)
03/Sep/2024:22:42:47.798686 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
03/Sep/2024:22:42:47.798686 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 94.156.68.167] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at REQUEST_COOKIES:g. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: echo found within REQUEST_COOKIES:g: echo Sp3ctra"] [severity "CRITICAL"] [ver "
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2024-09-03 20:42:47
(2 years ago)
Cloudflare WAF: Request Path: /wp-content/themes/seotheme/db.php Request Query: ?u Host: ns2.elhacke ...
show more
Cloudflare WAF: Request Path: /wp-content/themes/seotheme/db.php Request Query: ?u Host: ns2.elhacker.net userAgent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 Action: block Source: firewallManaged ASN Description: LIMENET Country: NL Method: GET Timestamp: 2024-09-03T20:42:47Z ruleId: 0242110ae62e44028a13bf4834780914. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
SilverZippo
2024-09-03 20:20:43
(2 years ago)
Web App Attack
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2024-09-03 20:16:27
(2 years ago)
Multiple web server 400 error codes from same source ip.-240
Bad Web Bot
๐ฌ๐ง
David Gebler
2024-09-03 20:11:25
(2 years ago)
94.156.68.167 - - [03/Sep/2024:20:11:25 +0000] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 463 ...
show more
94.156.68.167 - - [03/Sep/2024:20:11:25 +0000] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 4632 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
MM-bot
2024-09-03 20:04:27
(2 years ago)
URL-probe: HTTP/1.1 GET request on //wp-content/plugins/fix/up.php (2024-09-03 22:04:27 UTC+2)
Hacking
Web App Attack
๐ฌ๐ง
CrystalMaker
2024-09-03 20:04:24
(2 years ago)
Wordpress attack - GET /wp-content/plugins/fix/up.php; GET /simple.php; GET /chosen.php; GET /simple ...
show more
Wordpress attack - GET /wp-content/plugins/fix/up.php; GET /simple.php; GET /chosen.php; GET /simple.php; GET /about.php?520; GET /wp-content/about.php?520; GET /admin.php?520; GET /wp-content/admin.php?520; GET /style.php; POST /wp-plain.php; GET /wp-content/themes/seotheme/db.php?u; POST /ALFA_DATA/alfacgiapi/perl.alfa; GET /wp-content/themes/seotheme/db.php?u; GET /fcjwsvde.php?Fox=d3wL7; POST /alfacgiapi/perl.alfa
show less
Web App Attack
๐บ๐ธ
WebpodsLLC
2024-09-03 19:51:50
(2 years ago)
Direction: in Trigger: LF_MODSEC;
Port Scan
Brute-Force
Web App Attack
Anonymous
2024-09-03 17:41:58
(2 years ago)
Infected user bad webscan
Exploited Host
Anonymous
2024-09-03 17:05:00
(2 years ago)
"Evasion technique detected,Illegal file type,Access from malicious IP address"
Brute-Force