๐ฌ๐ง
Shepley
2025-07-24 13:30:22
(1 year ago)
RdpGuard detected brute-force attempt on RDP
Brute-Force
๐บ๐ธ
gu-alvareza
2025-03-20 07:05:04
(1 year ago)
Web.Server.Password.File.Access
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-03-20 07:03:47
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 20 03:03:40.628852 2025] [security2:error] [pid 6963:tid 7023] [client 103.120.235.93:56296] [client 103.120.235.93] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||192.64.150.79|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /pictureproxy.php?url=file%3A%2F%2F%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.79"] [uri "/pictureproxy.php"] [unique_id "Z9u9zLfb1ylXmbQPWbgFuQAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NXTwoThou
2025-03-20 04:59:56
(1 year ago)
/pictureproxy.php%3Furl=file%3A%2F%2F%2Fetc%2Fpasswd
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-20 02:31:11
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 22:31:06.525404 2025] [security2:error] [pid 2127900:tid 2127900] [client 103.120.235.93:53998] [client 103.120.235.93] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||192.64.150.250|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /pictureproxy.php?url=file%3A%2F%2F%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.250"] [uri "/pictureproxy.php"] [unique_id "Z9t96n1FAeidW_UDd6IOXgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-19 18:28:55
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 14:28:52.104513 2025] [security2:error] [pid 26849:tid 26849] [client 103.120.235.93:64211] [client 103.120.235.93] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||192.64.150.49|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /pictureproxy.php?url=file%3A%2F%2F%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.49"] [uri "/pictureproxy.php"] [unique_id "Z9sM5PE1ABpAL282GAXaWAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-19 17:26:49
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 13:26:44.173836 2025] [security2:error] [pid 1631573:tid 1631573] [client 103.120.235.93:63469] [client 103.120.235.93] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||192.64.150.100|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /pictureproxy.php?url=file%3A%2F%2F%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.100"] [uri "/pictureproxy.php"] [unique_id "Z9r-VNVcUKiEfXRYeNA1sgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-19 16:13:55
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 12:13:50.682907 2025] [security2:error] [pid 834:tid 834] [client 103.120.235.93:57013] [client 103.120.235.93] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||192.64.151.20|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /pictureproxy.php?url=file%3A%2F%2F%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.20"] [uri "/pictureproxy.php"] [unique_id "Z9rtPuTj-qN1j89IspAdkAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gu-alvareza
2025-03-19 07:05:10
(1 year ago)
Web.Server.Password.File.Access
Brute-Force
๐บ๐ธ
ISAFE
2025-03-18 21:13:14
(1 year ago)
103.120.235.93 - - [18/Mar/2025:14:13:13 -0700] "GET /pictureproxy.php?url=file%3A%2F%2F%2Fetc%2Fpas ...
show more
103.120.235.93 - - [18/Mar/2025:14:13:13 -0700] "GET /pictureproxy.php?url=file%3A%2F%2F%2Fetc%2Fpasswd HTTP/1.1" 404 492 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Mobile/15E148 Safari/604.1"
...
show less
Brute-Force
SSH
๐ฆ๐บ
ozisp.com.au
2025-03-18 19:13:27
(1 year ago)
null_null_<33>1742325205 [1:2049400:1] ET WEB_SERVER /etc/passwd Detected in URI [Classification: At ...
show more
null_null_<33>1742325205 [1:2049400:1] ET WEB_SERVER /etc/passwd Detected in URI [Classification: Attempted Information Leak] [Priority: 2] {TCP} 103.120.235.93:59301
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-03-18 17:30:45
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 103.120.235.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 13:30:40.630281 2025] [security2:error] [pid 8061:tid 8061] [client 103.120.235.93:52489] [client 103.120.235.93] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||192.64.150.15|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /pictureproxy.php?url=file%3A%2F%2F%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.15"] [uri "/pictureproxy.php"] [unique_id "Z9mtwPhJVu_w5LAycB6nOgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack