Activity: Web scanning or reconnaissance activity using zgrab
Action: Blocked by firewall
Access L ...
show moreActivity: Web scanning or reconnaissance activity using zgrab
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:22:18:39 +0000] "GET /version HTTP/1.1" 400 150 "-" "Mozilla/5.0 zgrab/0.x" "-"
show less
Activity: Attempted access to environment configuration file, indicative of potential web app attack ...
show moreActivity: Attempted access to environment configuration file, indicative of potential web app attack or reconnaissance
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:22:03:10 +0000] "GET /.env HTTP/1.1" 403 118 "-" "Mozilla/5.0 (PLAYSTATION 3; 2.00)" "-"
show less
Activity: Web Bot activity scanning for web server vulnerabilities
Action: Blocked by firewall
Acc ...
show moreActivity: Web Bot activity scanning for web server vulnerabilities
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:17:37:57 +0000] "GET /ReportServer HTTP/1.1" 400 150 "-" "Mozilla/5.0 zgrab/0.x" "-"
show less
Activity: Web Bot activity attempting to access development server
Action: Blocked by firewall
Acc ...
show moreActivity: Web Bot activity attempting to access development server
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:12:25:25 +0000] "GET /developmentserver/metadatauploader HTTP/1.1" 400 150 "-" "Mozilla/5.0 zgrab/0.x" "-"
show less
Activity: Attempted access to xmlrpc.php, potentially indicating a web app attack or probing for vul ...
show moreActivity: Attempted access to xmlrpc.php, potentially indicating a web app attack or probing for vulnerabilities
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:11:29:12 +0000] "POST /xmlrpc.php HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "-"
show less
Activity: Attempted access to xmlrpc.php, potentially an exploit or attack attempt targeting web app ...
show moreActivity: Attempted access to xmlrpc.php, potentially an exploit or attack attempt targeting web application vulnerabilities
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:11:28:28 +0000] "POST /xmlrpc.php HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "-"
show less
Activity: Web Bot activity scanning for development server endpoints
Action: Blocked by firewall
A ...
show moreActivity: Web Bot activity scanning for development server endpoints
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:08:47:30 +0000] "GET /developmentserver/metadatauploader HTTP/1.1" 400 150 "-" "Mozilla/5.0 zgrab/0.x" "-"
show less
Activity: Web Bot activity scanning for exposed endpoints
Action: Blocked by firewall
Access Log E ...
show moreActivity: Web Bot activity scanning for exposed endpoints
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:06:31:50 +0000] "GET /actuator/health HTTP/1.1" 400 150 "-" "Mozilla/5.0 zgrab/0.x" "-"
show less
Activity: Web Application Attack (attempt to access /v2/_catalog endpoint)
Action: Blocked by firew ...
show moreActivity: Web Application Attack (attempt to access /v2/_catalog endpoint)
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:06:30:11 +0000] "GET /v2/_catalog HTTP/1.1" 400 248 "-" "Go-http-client/1.1" "-"
show less
Activity: Brute-force attempt or unauthorized access attempt
Action: Blocked by firewall
Access Lo ...
show moreActivity: Brute-force attempt or unauthorized access attempt
Action: Blocked by firewall
Access Log Entries:
β’ [04/Jun/2025:04:40:37 +0000] "POST / HTTP/1.1" 403 146 "-" "AnyConnect Windows 5.1.8.105" "-"
show less
Activity: Normal web activity, port scan attempts, potential SQL injection, exploit attempts, and we ...
show moreActivity: Normal web activity, port scan attempts, potential SQL injection, exploit attempts, and web application attacks
Action: Blocked by firewall
Access Log Entries:
β’ [03/Jun/2025:23:07:24 +0000] "x16x03x01x00ux01x00x00qx03x03xDB:x96x05`xE1xE5pxB2xEBx90u7x901xAF>4wx8El~0UxA5x84" 400 150 "-" "-" "-"
β’ [03/Jun/2025:23:07:24 +0000] "x16x03x01x00ux01x00x00qx03x03x05vtxD11%7PkxE4xB9xD7xA0,xFCx13xD5xA5xC8Xx9Fg$xAFx0FxF2WxB7x80ZxE5xBAx00x00x1AxC0/xC0+xC0x11xC0x07xC0x13xC0x09xC0x14xC0" 400 150 "-" "-" "-"
β’ [03/Jun/2025:23:07:24 +0000] "GET /form.html HTTP/1.1" 400 150 "-" "curl/8.1.2" "-"
show less
Port ScanSQL InjectionExploited HostWeb App Attack