Just noticed that my AWS hosted site added a new instance to the LB, and went in to see why. Didn't really see any major upticks, so i checked the logs. Found this (I have replaced a few numbers in the IIP numbers for safety):
2017-10-12 03:18:40 172.X.X.152 HEAD /MySite_deploy/db/phpmyadmin3/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:41 172.X.X.152 HEAD /MySite_deploy/administrator/phpmyadmin/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:42 172.X.X.152 HEAD /MySite_deploy/administrator/web/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 15
2017-10-12 03:18:45 172.X.X.152 HEAD /MySite_deploy/administrator/admin/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:46 172.X.X.152 HEAD /MySite_deploy/phpMyAdmin4/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:47 172.X.X.152 HEAD /MySite_deploy/PMA2011/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:47 172.X.X.152 GET /MySite_deploy/default.aspx - 80 - 172.31.8.111 ELB-HealthChecker/1.0 - 200 0 0 0
2017-10-12 03:18:47 172.X.X.152 HEAD /MySite_deploy/PMA2013/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:49 172.X.X.152 GET /MySite_deploy/default.aspx - 80 - 172.Y.Y.203 ELB-HealthChecker/1.0 - 200 0 0 0
2017-10-12 03:18:49 172.X.X.152 HEAD /MySite_deploy/PMA2015/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:50 172.X.X.152 HEAD /MySite_deploy/PMA2018/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:52 172.X.X.152 HEAD /MySite_deploy/pma2013/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:54 172.X.X.152 HEAD /MySite_deploy/pma2016/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:55 172.X.X.152 HEAD /MySite_deploy/phpmyadmin2011/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:56 172.X.X.152 HEAD /MySite_deploy/phpmyadmin2014/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:57 172.X.X.152 HEAD /MySite_deploy/phpmyadmin2017/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 0
2017-10-12 03:18:57 172.X.X.152 HEAD /MySite_deploy/phpmanager/ - 80 - 172.Y.Y.203 Mozilla/5.0+Jorgee - 404 0 2 15
I someone trying to gain access? How can I prevent attacks like this? Can I even?
Regards,
Bob