Your server 188.40.110.28 has been registered as an attack source Incident report Dear provider, I am Mark Bacsko, Incident Analyst at BitNinja Server Security. I’m writing to inform you that we have detected malicious requests targeting our clients’ servers from the IP 188.40.110.28 you own based on a public database. We’ve been able to stop these requests and prevent future attacks by adding your IP to our greylist , but we wanted to reach out and inform you, as you might not be aware. Timestamp (UTC): 2022-12-01 15:45:15 Sometimes it’s not easy to notice that your servers are used as a “bot” sending malicious attacks over the Internet. AGENT LOGS If this is the case with you, you can take steps to protect your and others’ servers. To help you to fix this problem, I’ve collected the 3 earliest logs below, which have led to your IP being blocked. Under the link, you can find the freshest 100 logs that may help you disinfect your server.
Manually added by user.
Url: [citlos.gr/wp-content/plugins/LayerSlider/.svn/prop-base/] Headers: [array ( 'BN-TP-Dstport' => '80', 'BN-TP-Proto' => 'http', 'Host' => 'citlos.gr', 'BN-Client-Port' => '63612', 'BN-Frontend' => 'waf-http', 'Referer' => 'http://citlos.gr/wp-content/plugins/LayerSlider/.svn/prop-base/', 'BN-X-Forwarded-Port' => '', 'X-Forwarded-Port' => '80', 'BN-TP-Dstip' => '88.99.193.221', 'BN-TP-Clientip' => '188.40.110.28', 'User-Agent' => 'Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36', 'BN-X-Forwarded-Proto' => '', 'X-Forwarded-Proto' => 'http', 'Accept' => 'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8', 'BN-X-Forwarded-For' => '', 'X-Forwarded-For' => '188.40.110.28', )] Matched: [ ModSecurity id: [930130] revision [1] msg [Restricted File Access Attempt] match [Matched "Operator `PmFromFile' with parameter `restricted-files.data' against variable `REQUEST_FILENAME' (Value: `/wp-content/plugins/LayerSlider/.svn/prop-base/' )] logdata [Matched Data: /.svn/ found within REQUEST_FILENAME: /wp-content/plugins/layerslider/.svn/prop-base/] severity [CRITICAL] Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=0,RFI=0,LFI=5,RCE=0,PHPI=0,HTTP=0,SESS=0): Restricted File Access Attempt ]
Url: [www.staglee.com/join/registration] Remote connection: [188.40.110.28:57164] Headers: [array ( 'Host' => 'www.staglee.com', 'cf-ipcountry' => 'DE', 'cdn-loop' => 'cloudflare', 'accept-encoding' => 'gzip', 'x-forwarded-for' => '188.40.110.28', 'cf-ray' => '76e0bc3dfc13696f-NRT', 'cf-visitor' => '{"scheme":"https"}', 'accept' => 'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8', 'user-agent' => 'Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.72 Safari/537.36 Edg/90.0.818.42', 'referer' => 'https://www.staglee.com/join/registration?task=registration.activate&token=79e2a4f0f988ac687b2d499771e0839b', 'cf-connecting-ip' => '188.40.110.28', 'host' => 'www.staglee.com', 'X-Forwarded-Port' => '443', 'BN-Trusted-Proxy' => '162.158.118.146', 'BN-Frontend' => 'tp-https-frontend', 'X-Forwarded-Proto' => 'https', 'BN-Client-Port' => '13974', 'X-Forwarded-For' => '162.158.118.146', )] Get data: [Array ( [task] => registration.activate [token] => 79e2a4f0f988ac687b2d499771e0839b ) ]
GO TO INCIDENTS Please keep in mind that after the first intrusion we log all traffic between your server and the BitNinja-protected servers until the IP is removed from the greylist. This means you may see valid logs beside the malicious actions in the link above. If you need help finding the malicious logs, please don’t hesitate to contact our incident experts by replying to this e-mail. Have an amazing week: The BitNinja Team