Page 1 of 1

Has my Apache been hacked?

PostPosted: 29. March 2018 09:36
by kaspencer
For the past few days I have noted a great many lines similar to that shown below, in my logs of one of my sites:

195.154.44.62 - - [28/Mar/2018:07:59:34 +0100] "GET / HTTP/1.1" 200 4995 "http://verbflexdabbfi.soup.io" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0"

The redirected address shown in the GET clause varies a bit between 4 or 5 different sites. Only one of three virtual domains are affected, not the entire server.
This looks like illegal activity, but I am not sure exactly what is happening. As a safety measure I have added the IP addresses to my deny list.

Does anyone have any ideas?

Thanks,

Kenneth Spencer

Re: Has my Apache been hacked?

PostPosted: 29. March 2018 16:45
by Nobbie
I cannot see any illegal activity there.

Re: Has my Apache been hacked?

PostPosted: 01. March 2021 01:45
by MattPayne
Looks pretty fine in terms of bad activity