|
๐จ๐ฆ
polycoda
|
|
๐ฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
|
DDoS Attack
|
|
|
๐ฎ๐น
VHosting
|
|
Detected mail brute force attack from 4 different servers
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217210) triggered by 103.166.103.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217210) triggered by 103.166.103.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 00:43:50.258516 2026] [security2:error] [pid 30708:tid 30708] [client 103.166.103.71:59408] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||moon7weights.xyz|F|4"] [data "GET http://moon7weights.xyz HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "moon7weights.xyz"] [uri "/"] [unique_id "afA7BnT1Km1yIV1yTq304wAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
Mรถlkky
|
|
DDOS Attack (by infected device ?)
|
Web App Attack
|
|
|
๐บ๐ธ
kosada.com
|
|
Web bot: DDoS
|
DDoS Attack
Bad Web Bot
|
|
|
๐บ๐ธ
stechusa
|
|
[Askari] ELEVATED_THREAT | 13 IPs targeting /brand/satco-products-inc.html | Facet request during el ...
show more
[Askari] ELEVATED_THREAT | 13 IPs targeting /brand/satco-products-inc.html | Facet request during elevated threat (facet_ratio=0.83, unique_ips=61) | Recv-Q=1489 bytes on ESTABLISHED connection (threshold=1000) | Signals: http1_on_tls, concurrent_facet_load, path_concentration, recv_q_stall
show less
|
Web App Attack
Hacking
Web Spam
|
|
|
๐บ๐ธ
stechusa
|
|
ELEVATED_THREAT | 13 IPs targeting /brand/satco-products-inc.html | Facet request during elevated th ...
show more
ELEVATED_THREAT | 13 IPs targeting /brand/satco-products-inc.html | Facet request during elevated threat (facet_ratio=0.83, unique_ips=61) | Recv-Q=1489 bytes on ESTABLISHED connection (threshold=1000)
show less
|
Web App Attack
Hacking
Web Spam
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 103.166.103.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 103.166.103.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 12:22:06.210450 2025] [security2:error] [pid 30113:tid 30113] [client 103.166.103.71:44768] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.player-care.com|F|2"] [data ".spencerserolls.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.player-care.com"] [uri "/cb/www.spencerserolls.com"] [unique_id "aS3OviN8onlb60DeRIpQSwAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ญ
backslash
|
|
block ruleset DA4A07AEE48B136A3922182BE8AA8BFBC1840803
|
Bad Web Bot
|
|
|
Anonymous
|
|
scanning http requests from known botnet
|
Web App Attack
|
|
|
๐ฉ๐ช
Packets-Decreaser.NET
|
|
Incoming Layer 7 Flood Detected
|
DDoS Attack
Web Spam
|
|