MyBB Community Forums

Full Version: Is it some hacking attack?
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
My VPS got banned and I just now figured out that somebody is making unending hack requests at my Mybb forum
I've temporarily disabled my forum due to it. Scan at sitecheck.sucuri.net/scanner has come clean.

partial access log from Cpanel(full is shown 80MB) here, pl scroll to middle or so: :

What kind of attack it could be?

Quote:"http://www.usatoday.com/search/results?q=GZALR" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; Win64; x64; Trident/4.0)"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?JVLZYBR=BEWEPMAW HTTP/1.1" 200 72419 "http://forum.indiaconsumercomplaints.com/EXIHHK" "Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?WIE=TCMZ HTTP/1.1" 200 72411 "http://www.google.com/?q=KITLSCEFU" "Mozilla/4.0 (compatible; MSIE 6.1; Windows XP)"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?VZLXENDF=UTKXFBTBJ HTTP/1.1" 200 72421 "http://forum.indiaconsumercomplaints.com/YARXJF" "Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?RGBM=DQJFUIUXRJ HTTP/1.1" 200 72418 "http://forum.indiaconsumercomplaints.com/XBMQVXZ" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; Win64; x64; Trident/4.0)"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?ZMFVVIGKOP=BFGLI HTTP/1.1" 200 72419 "http://forum.indiaconsumercomplaints.com/QFDCCUPGOU" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?WGYTQ=SUSXRISDZN HTTP/1.1" 200 72419 "http://www.google.com/?q=USQFQ" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?VYL=BUZUUZ HTTP/1.1" 200 72413 "http://www.google.com/?q=KCWIOUF" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.3) Gecko/20090913 Firefox/3.5.3"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?RLRCQSTJ=NYGFWD HTTP/1.1" 200 72418 "http://www.usatoday.com/search/results?q=IVXKQH" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.1 (KHTML, like Gecko) Chrome/4.0.219.6 Safari/532.1"
50.23.129.218 - - [22/Feb/2014:21:13:35 +0530] "GET /Thread-Airwil-Intellicity?MRRAQZZUF=WDPIRMFKF HTTP/1.1" 200 72422 "http://www.usatoday.com/search/results?q=MGHMEE" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.1 (KHTML, like Gecko) Chrome/4.0.219.6 Safari/532.1"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?FYCZS=KDAOHSG HTTP/1.1" 200 72416 "http://www.google.com/?q=ACYEG" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; InfoPath.2)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?OIRN=OBPCZJOG HTTP/1.1" 200 72416 "http://engadget.search.aol.com/search?q=PTKWBQD" "Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?LDC=XOHTGSMDT HTTP/1.1" 200 72416 "http://www.google.com/?q=SUUTCRT" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.1) Gecko/20090718 Firefox/3.5.1"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?TYHU=MIJJK HTTP/1.1" 200 72413 "http://forum.indiaconsumercomplaints.com/HBGUV" "Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?YDU=PLZT HTTP/1.1" 200 72411 "http://www.google.com/?q=UUJKV" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.1 (KHTML, like Gecko) Chrome/4.0.219.6 Safari/532.1"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?WPUNB=XBJZ HTTP/1.1" 200 72413 "http://engadget.search.aol.com/search?q=YXIIPYZYAZ" "Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?AWXJJLZG=PKRD HTTP/1.1" 200 72416 "http://www.usatoday.com/search/results?q=CFASF" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.3) Gecko/20090913 Firefox/3.5.3"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?UWFMW=UTGLPYJU HTTP/1.1" 200 72417 "http://www.usatoday.com/search/results?q=PFNHXK" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.1 (KHTML, like Gecko) Chrome/4.0.219.6 Safari/532.1"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?AUF=QOMRCZVKOQ HTTP/1.1" 200 72417 "http://engadget.search.aol.com/search?q=SHFAHYNYFS" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.1) Gecko/20090718 Firefox/3.5.1"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?TRD=QQFMTC HTTP/1.1" 200 72413 "http://engadget.search.aol.com/search?q=UDQOJL" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?BXVNJAGX=DDH HTTP/1.1" 200 72415 "http://engadget.search.aol.com/search?q=MTFAK" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?SZNG=ZVTZUAHOF HTTP/1.1" 200 72417 "http://forum.indiaconsumercomplaints.com/DBNXW" "Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?ERFEYOMJNR=SSSBBPUG HTTP/1.1" 200 72422 "http://www.google.com/?q=KMOVE" "Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?OUHRUW=MMF HTTP/1.1" 200 72413 "http://www.google.com/?q=JKQPLCEXV" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; Win64; x64; Trident/4.0)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?SVTH=YGZ HTTP/1.1" 200 72411 "http://www.usatoday.com/search/results?q=AGQVL" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SV1; .NET CLR 2.0.50727; InfoPath.2)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?BESSJWGMI=XVCASBL HTTP/1.1" 200 72420 "http://www.usatoday.com/search/results?q=VHDIRYEOOJ" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?NQMNXI=NQEHYB HTTP/1.1" 200 72416 "http://www.google.com/?q=YOTNUEWWRT" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?UOOLLXN=YZLHSHRRI HTTP/1.1" 200 72420 "http://www.usatoday.com/search/results?q=PLPSOWGID" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.1 (KHTML, like Gecko) Chrome/4.0.219.6 Safari/532.1"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?WFTIOF=IXCYK HTTP/1.1" 200 72415 "http://forum.indiaconsumercomplaints.com/BJDXVAPCJ" "Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?VTINDI=PGGVVOW HTTP/1.1" 200 72417 "http://engadget.search.aol.com/search?q=OISQJPMIA" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.1) Gecko/20090718 Firefox/3.5.1"
50.23.129.218 - - [22/Feb/2014:21:13:36 +0530] "GET /Thread-Airwil-Intellicity?NEZ=AJLUN HTTP/1.1" 200 72412 "http://engadget.search.aol.com/search?q=WHQNY" "Mozilla/4.0 (compatible; MSIE 6.1; Windows XP)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?XTSZIRN=JKUXORCEFQ HTTP/1.1" 200 72421 "http://forum.indiaconsumercomplaints.com/OYCNIWE" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; InfoPath.2)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?KQAI=QVSOSV HTTP/1.1" 200 72414 "http://engadget.search.aol.com/search?q=FMHZDY" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?SHSWO=FDBK HTTP/1.1" 200 72413 "http://engadget.search.aol.com/search?q=KGZYPBIPGO" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?TQNVSAR=MYDMTNDNJ HTTP/1.1" 200 72420 "http://www.google.com/?q=BFWYGA" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?GNRNQV=SEHWNTSI HTTP/1.1" 200 72418 "http://forum.indiaconsumercomplaints.com/QUEMAO" "Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)"
5.10.83.93 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Low-mileage-of-the-car?pid=145 HTTP/1.1" 200 11489 "-" "Mozilla/5.0 (compatible; AhrefsBot/5.0; +http://ahrefs.com/robot/)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?TSUWHESCEB=OTCGVVUP HTTP/1.1" 200 72422 "http://www.usatoday.com/search/results?q=JJBAR" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; Win64; x64; Trident/4.0)"
106.219.35.226 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-i-want-call-incoming-and-out-going-details HTTP/1.1" 200 11079 "http://forum.indiaconsumercomplaints.com/Forum-Prepaid" "Mastone_G9_TD/V2.00 Release/3.19.2012 Mozilla/5.0 (Linux; U; Android 2.3.5) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?XLA=REHZJR HTTP/1.1" 200 72413 "http://www.google.com/?q=UGEFN" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?VAPZZEF=UCHF HTTP/1.1" 200 72415 "http://www.usatoday.com/search/results?q=GVTTI" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.5.30729; .NET CLR 3.0.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?PBABNLEQW=GNAVT HTTP/1.1" 200 72418 "http://www.usatoday.com/search/results?q=XQOEYDJBP" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.1) Gecko/20090718 Firefox/3.5.1"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?TVWWPPIY=LTJGNGVBS HTTP/1.1" 200 72421 "http://forum.indiaconsumercomplaints.com/EUZFX" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.3) Gecko/20090913 Firefox/3.5.3"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?IQX=XHTIJX HTTP/1.1" 200 72413 "http://www.google.com/?q=MOYKI" "Mozilla/5.0 (Windows; U; MSIE 7.0; Windows NT 6.0; en-US)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?CQC=FYUPDPXN HTTP/1.1" 200 72415 "http://engadget.search.aol.com/search?q=DLTVJFQD" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.1 (KHTML, like Gecko) Chrome/4.0.219.6 Safari/532.1"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?ZFWEMAQA=EAUPA HTTP/1.1" 200 72417 "http://www.google.com/?q=BKUFDT" "Mozilla/4.0 (compatible; MSIE 6.1; Windows XP)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?ATBWHKQA=OSHO HTTP/1.1" 200 72416 "http://www.google.com/?q=QFAOIUH" "Mozilla/4.0 (compatible; MSIE 6.1; Windows XP)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?EELH=XVPAJ HTTP/1.1" 200 72413 "http://forum.indiaconsumercomplaints.com/BYCKG" "Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?WWTJV=ZLMPL HTTP/1.1" 200 72414 "http://forum.indiaconsumercomplaints.com/RBKQPZRUCT" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.1.3) Gecko/20090913 Firefox/3.5.3"
50.23.129.218 - - [22/Feb/2014:21:13:38 +0530] "GET /Thread-Airwil-Intellicity?MSZJKSGTWG=HGZPH HTTP/1.1" 200 72419 "http://engadget.search.aol.com/search?q=SJUFD" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:37 +0530] "GET /Thread-Airwil-Intellicity?LGENXKYF=WNDUELKPXO HTTP/1.1" 200 72422 "http://forum.indiaconsumercomplaints.com/PYSTXEL" "Mozilla/4.0 (compatible; MSIE 6.1; Windows XP)"
50.23.129.218 - - [22/Feb/2014:21:13:38 +0530] "GET /Thread-Airwil-Intellicity?SBEHBK=OVMEAWLD HTTP/1.1" 200 72418 "http://www.google.com/?q=QJJQSQMJT" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:38 +0530] "GET /Thread-Airwil-Intellicity?ZOS=KPTQHMZ HTTP/1.1" 200 72414 "http://www.google.com/?q=QIZQWPAY" "Mozilla/4.0 (compatible; MSIE 6.1; Windows XP)"
50.23.129.218 - - [22/Feb/2014:21:13:38 +0530] "GET /Thread-Airwil-Intellicity?PJWUFQJXBN=KRRJOJSH HTTP/1.1" 200 72422 "http://forum.indiaconsumercomplaints.com/QAOLBB" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; InfoPath.2)"
50.23.129.218 - - [22/Feb/2014:21:13:38 +0530] "GET /Thread-Airwil-Intellicity?UDU=QKTJLBB HTTP/1.1" 200 72414 "http://www.usatoday.com/search/results?q=DPIDLBQOTY" "Mozilla/4.0 (compatible; MSIE 6.1; Windows XP)"
50.23.129.218 - - [22/Feb/2014:21:13:38 +0530] "GET /Thread-Airwil-Intellicity?ECDGMIXCKA=LAQDJQWB HTTP/1.1" 200 72422 "http://forum.indiaconsumercomplaints.com/FJZDJLRB" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729)"
50.23.129.218 - - [22/Feb/2014:21:13:38 +0530] "GET /Thread-Airwil-Intellicity?HKEJTWMZ=TXGWFEEVY HTTP/1.1" 200 72421 "http://forum.indiaconsumercomplaints.com/SEJDGR" "Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51"
50.23.129.218 - - [22/Fe
It doesn't look like an attack. It looks like referrer spam.

http://en.wikipedia.org/wiki/Referer_spam