๐ฑ๐น
141.98.10.197
25 Oct 2021
Oct 25 12:17:17 megastar postfix/smtpd[4884]: warning: unknown[141.98.10.197]: SASL LOGIN authentica ...
show more
Oct 25 12:17:17 megastar postfix/smtpd[4884]: warning: unknown[141.98.10.197]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 25 12:37:56 megastar postfix/smtpd[6512]: warning: unknown[141.98.10.197]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 25 12:56:27 megastar postfix/smtpd[8019]: warning: unknown[141.98.10.197]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
show less
Brute-Force
๐ฑ๐น
141.98.10.210
25 Oct 2021
Oct 25 12:16:49 megastar postfix/smtpd[4884]: warning: unknown[141.98.10.210]: SASL LOGIN authentica ...
show more
Oct 25 12:16:49 megastar postfix/smtpd[4884]: warning: unknown[141.98.10.210]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 25 12:37:45 megastar postfix/smtpd[6512]: warning: unknown[141.98.10.210]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 25 12:56:00 megastar postfix/smtpd[8019]: warning: unknown[141.98.10.210]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
show less
Brute-Force
๐ฎ๐ฉ
180.250.18.115
07 Oct 2021
Oct 7 04:27:58 megastar sshd[30852]: Invalid user access from 180.250.18.115 port 38024
Oct 7 04: ...
show more
Oct 7 04:27:58 megastar sshd[30852]: Invalid user access from 180.250.18.115 port 38024
Oct 7 04:28:15 megastar sshd[30874]: Invalid user admin from 180.250.18.115 port 52242
Oct 7 04:28:33 megastar sshd[30892]: Invalid user admin from 180.250.18.115 port 38252
show less
Brute-Force
SSH
๐ป๐ณ
103.167.92.101
07 Oct 2021
Oct 7 03:29:38 megastar postfix/smtpd[24857]: warning: unknown[103.167.92.101]: SASL LOGIN authenti ...
show more
Oct 7 03:29:38 megastar postfix/smtpd[24857]: warning: unknown[103.167.92.101]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 7 03:29:45 megastar postfix/smtpd[24857]: warning: unknown[103.167.92.101]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 7 03:29:56 megastar postfix/smtpd[24857]: warning: unknown[103.167.92.101]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
show less
Brute-Force
๐บ๐ธ
35.238.156.93
07 Oct 2021
Oct 6 22:42:07 megastar postfix/smtpd[2098]: warning: 93.156.238.35.bc.googleusercontent.com[35.238 ...
show more
Oct 6 22:42:07 megastar postfix/smtpd[2098]: warning: 93.156.238.35.bc.googleusercontent.com[35.238.156.93]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 6 22:59:41 megastar postfix/smtpd[3392]: warning: 93.156.238.35.bc.googleusercontent.com[35.238.156.93]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Oct 6 23:17:00 megastar postfix/smtpd[4736]: warning: 93.156.238.35.bc.googleusercontent.com[35.238.156.93]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
show less
Brute-Force
๐ฐ๐ท
121.184.169.234
23 Sep 2021
Sep 23 12:13:59 megastar postfix/smtpd[23701]: warning: unknown[121.184.169.234]: SASL LOGIN authent ...
show more
Sep 23 12:13:59 megastar postfix/smtpd[23701]: warning: unknown[121.184.169.234]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Sep 23 12:14:07 megastar postfix/smtpd[23709]: warning: unknown[121.184.169.234]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Sep 23 12:14:19 megastar postfix/smtpd[23717]: warning: unknown[121.184.169.234]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
show less
Brute-Force
๐บ๐ธ
34.122.249.118
16 Sep 2021
[Thu Sep 16 04:35:36.376416 2021] [:error] [pid 31442:tid 140628411238144] [client 34.122.249.118:56 ...
show more
[Thu Sep 16 04:35:36.376416 2021] [:error] [pid 31442:tid 140628411238144] [client 34.122.249.118:56084] [client 34.122.249.118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xxx"] [uri "/.env"] [unique_id "YUKteM-W5VcyxDctD7n9aQAAAE0"]
show less
Web App Attack
๐ฉ๐ฐ
37.120.131.252
16 Sep 2021
[Thu Sep 16 02:09:37.552584 2021] [:error] [pid 1805:tid 140269529818880] [client 37.120.131.252:547 ...
show more
[Thu Sep 16 02:09:37.552584 2021] [:error] [pid 1805:tid 140269529818880] [client 37.120.131.252:54758] [client 37.120.131.252] ModSecurity: Access denied with code 403 (phase 2). String match "/wp-admin/admin-post.php" at REQUEST_FILENAME. [file "/usr/local/apache/modsecurity-cwaf/rules/27_Apps_WPPlugin.conf"] [line "6482"] [id "232920"] [rev "1"] [msg "COMODO WAF: RFI vulnerability in social warfare plugin before 3.5.3 for WordPress(CVE-2019-9978)||x|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "x"] [uri "/wp-admin/admin-post.php"] [unique_id "YUKLQfLywf-WHcQhsh2FTQAAAM8"]
show less
Web App Attack
๐บ๐ธ
216.128.134.97
16 Sep 2021
[Thu Sep 16 01:09:52.559275 2021] [:error] [pid 1430:tid 140269454284544] [client 216.128.134.97:541 ...
show more
[Thu Sep 16 01:09:52.559275 2021] [:error] [pid 1430:tid 140269454284544] [client 216.128.134.97:54142] [client 216.128.134.97] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xxx"] [uri "/.env"] [unique_id "YUJ9QK3XVGhSwDbnx83PxwAAABg"]
show less
Web App Attack
๐ฌ๐ง
45.143.147.10
15 Sep 2021
[Wed Sep 15 11:07:21.828570 2021] [:error] [pid 17942:tid 139705647605504] [client 45.143.147.10:417 ...
show more
[Wed Sep 15 11:07:21.828570 2021] [:error] [pid 17942:tid 139705647605504] [client 45.143.147.10:41708] [client 45.143.147.10] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xxx"] [uri "/.env"] [unique_id "YUG3yZnA7-6zpyogofOZXQAAAMs"]
show less
Web App Attack
๐ต๐ฑ
193.169.255.113
15 Sep 2021
Sep 15 03:39:41 pop3-login: Info: Aborted login (auth failed, 1 attempts in 2 secs): user=<sales>, m ...
show more
Sep 15 03:39:41 pop3-login: Info: Aborted login (auth failed, 1 attempts in 2 secs): user=<sales>, method=PLAIN, rip=193.169.255.113, lip=xxx, session=<+7uJxf7LPMfBqf9x>
show less
Brute-Force
๐ณ๐ฑ
77.247.110.219
10 Sep 2021
Sep 10 13:49:40 megastar postfix/smtpd[30038]: warning: unknown[77.247.110.219]: SASL LOGIN authenti ...
show more
Sep 10 13:49:40 megastar postfix/smtpd[30038]: warning: unknown[77.247.110.219]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Sep 10 13:49:47 megastar postfix/smtpd[30038]: warning: unknown[77.247.110.219]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Sep 10 13:49:57 megastar postfix/smtpd[30038]: warning: unknown[77.247.110.219]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
show less
Brute-Force
๐ณ๐ฑ
167.71.13.196
10 Sep 2021
[Fri Sep 10 04:14:35.145614 2021] [:error] [pid 24916:tid 140246719899392] [client 167.71.13.196:569 ...
show more
[Fri Sep 10 04:14:35.145614 2021] [:error] [pid 24916:tid 140246719899392] [client 167.71.13.196:56962] [client 167.71.13.196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "x"] [uri "/.env"] [unique_id "YTq-i9WanxyirpPMbmop4QAAAMA"]
show less
Web App Attack
๐บ๐ธ
64.43.124.41
07 Sep 2021
[Tue Sep 07 12:48:40.701794 2021] [:error] [pid 32374:tid 139800766011136] [client 64.43.124.41:5971 ...
show more
[Tue Sep 07 12:48:40.701794 2021] [:error] [pid 32374:tid 139800766011136] [client 64.43.124.41:59716] [client 64.43.124.41] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "x"] [uri "/.env"] [unique_id "YTdDiIOaEiab@vCbYpLwnwAAAA4"]
show less
Web App Attack
๐ฉ๐ช
85.14.222.243
06 Sep 2021
[Mon Sep 06 10:45:08.905440 2021] [:error] [pid 16715:tid 140642554455808] [client 85.14.222.243:388 ...
show more
[Mon Sep 06 10:45:08.905440 2021] [:error] [pid 16715:tid 140642554455808] [client 85.14.222.243:38872] [client 85.14.222.243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "x"] [uri "/.env"] [unique_id "YTXVFMQtiM8T4i1L9LTMiwAAAEk"]
show less
Web App Attack
๐บ๐ธ
3.137.202.64
06 Sep 2021
[Mon Sep 06 02:00:50.946888 2021] [:error] [pid 19639:tid 139770902599424] [client 3.137.202.64:3307 ...
show more
[Mon Sep 06 02:00:50.946888 2021] [:error] [pid 19639:tid 139770902599424] [client 3.137.202.64:33076] [client 3.137.202.64] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "x"] [uri "/.env"] [unique_id "YTVaMhHvFrhvMbaTo8MzyQAAAIM"]
show less
Web App Attack
๐ฉ๐ช
78.159.113.194
06 Sep 2021
[Sun Sep 05 23:38:33.901158 2021] [:error] [pid 19629:tid 139770776708864] [client 78.159.113.194:59 ...
show more
[Sun Sep 05 23:38:33.901158 2021] [:error] [pid 19629:tid 139770776708864] [client 78.159.113.194:59682] [client 78.159.113.194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "x"] [uri "/.env"] [unique_id "YTU42YeiTBjZBcMPEmuA0AAAABI"]
show less
Web App Attack
๐ณ๐ฑ
37.0.8.34
05 Sep 2021
[Sun Sep 05 07:57:03.394669 2021] [:error] [pid 19629:tid 139770894206720] [client 37.0.8.34:50168] ...
show more
[Sun Sep 05 07:57:03.394669 2021] [:error] [pid 19629:tid 139770894206720] [client 37.0.8.34:50168] [client 37.0.8.34] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "x"] [uri "/.env"] [unique_id "YTRcL4eiTBjZBcMPEmt8fwAAAAQ"]
show less
Web App Attack
๐ท๐บ
46.158.47.84
05 Sep 2021
[Sun Sep 05 04:29:27.440479 2021] [:error] [pid 19630:tid 139770768316160] [client 46.158.47.84:4831 ...
show more
[Sun Sep 05 04:29:27.440479 2021] [:error] [pid 19630:tid 139770768316160] [client 46.158.47.84:48314] [client 46.158.47.84] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/usr/local/apache/modsecurity-cwaf/rules/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "x"] [uri "/wp-admin/admin-ajax.php"] [unique_id "YTQrh9MQkU1gStVRZ9mZJQAAAFM"]
show less
Web App Attack
๐ฉ๐ช
157.230.116.84
05 Sep 2021
Sep 5 03:12:36 megastar sshd[16928]: Did not receive identification string from 157.230.116.84 port ...
show more
Sep 5 03:12:36 megastar sshd[16928]: Did not receive identification string from 157.230.116.84 port 47768
Sep 5 03:12:52 megastar sshd[16943]: Invalid user user from 157.230.116.84 port 53032
Sep 5 03:12:52 megastar sshd[16947]: Invalid user binux from 157.230.116.84 port 53640
show less
SSH
๐ฎ๐ช
3.250.185.36
25 Aug 2021
Aug 25 10:59:59 megastar postfix/smtpd[23787]: warning: ec2-3-250-185-36.eu-west-1.compute.amazonaws ...
show more
Aug 25 10:59:59 megastar postfix/smtpd[23787]: warning: ec2-3-250-185-36.eu-west-1.compute.amazonaws.com[3.250.185.36]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Aug 25 11:02:59 megastar postfix/smtpd[24092]: warning: ec2-3-250-185-36.eu-west-1.compute.amazonaws.com[3.250.185.36]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
Aug 25 11:03:25 megastar postfix/smtpd[24123]: warning: ec2-3-250-185-36.eu-west-1.compute.amazonaws.com[3.250.185.36]: SASL LOGIN authentication failed: UGFzc3dvcmQ6
show less
Brute-Force
๐ท๐บ
62.176.26.200
25 Aug 2021
Aug 25 10:37:59 megastar sshd[22378]: Invalid user access from 62.176.26.200 port 22927
Aug 25 10:3 ...
show more
Aug 25 10:37:59 megastar sshd[22378]: Invalid user access from 62.176.26.200 port 22927
Aug 25 10:38:19 megastar sshd[22396]: Invalid user admin from 62.176.26.200 port 31989
Aug 25 10:38:38 megastar sshd[22411]: Invalid user admin from 62.176.26.200 port 31651
show less
Brute-Force
SSH
๐ธ๐ฌ
188.166.179.135
24 Aug 2021
[Tue Aug 24 21:05:10.542108 2021] [:error] [pid 10545:tid 140189536052992] [client 188.166.179.135:5 ...
show more
[Tue Aug 24 21:05:10.542108 2021] [:error] [pid 10545:tid 140189536052992] [client 188.166.179.135:52116] [client 188.166.179.135] ModSecurity: Access denied with code 403 (phase 2). Found 2 byte(s) in REQUEST_HEADERS:Cookie outside range: 1-255. [file "/usr/local/apache/modsecurity-cwaf/rules/12_HTTP_Protocol.conf"] [line "95"] [id "210410"] [rev "4"] [msg "COMODO WAF: Invalid character in request||xxx|F|3"] [data "REQUEST_HEADERS:Cookie=35=+.(\\xca\\xcc+I\\x03\\x00; 1=; 0=array23; 3=; 2=; 5=; 4=; 7=; 6=; 9=; 8=; 74=nflate; 70=+\\xc8(\\xc8\\xccK\\xcb\\x07\\x00; 11=%s; 10=; 13=; 12=; 15=; 14=; 17=; 16=; 18=; 53=gzi"] [severity "ERROR"] [tag "CWAF"] [tag "Protocol"] [hostname "xxx"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "YSVC5pJv4GPCpltHPsabCQAAAJA"], referer: http://xxx//wp-admin/js/widgets/index.php
show less
Web App Attack
161.35.87.56
14 Aug 2021
Aug 14 19:34:19 megastar sshd[2418]: Did not receive identification string from 161.35.87.56 port 34 ...
show more
Aug 14 19:34:19 megastar sshd[2418]: Did not receive identification string from 161.35.87.56 port 34034
Aug 14 19:34:36 megastar sshd[2431]: Invalid user cat from 161.35.87.56 port 34422
Aug 14 19:34:36 megastar sshd[2430]: Invalid user user from 161.35.87.56 port 34274
show less
Brute-Force
SSH
212.192.246.14
12 Aug 2021
Aug 12 18:53:55 megastar postfix/smtpd[6747]: warning: unknown[212.192.246.14]: SASL PLAIN authentic ...
show more
Aug 12 18:53:55 megastar postfix/smtpd[6747]: warning: unknown[212.192.246.14]: SASL PLAIN authentication failed:
Aug 12 18:53:55 megastar postfix/smtpd[6745]: warning: unknown[212.192.246.14]: SASL PLAIN authentication failed:
Aug 12 18:53:55 megastar postfix/smtpd[6741]: warning: unknown[212.192.246.14]: SASL PLAIN authentication failed:
show less
Brute-Force