๐ณ๐ฑ
Linuxmalwarehuntingnl
2024-07-01 10:40:44
(1 year ago)
Unauthorized connection attempt
Brute-Force
๐ฆ๐บ
MAGIC
2024-06-21 10:05:40
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ท๐บ
nyuuzyou
2024-06-20 03:59:09
(1 year ago)
{"action": "connection", "dest_ip": "0.0.0.0", "dest_port": "9100", "server": "pjl_server", "src_ip" ...
show more
{"action": "connection", "dest_ip": "0.0.0.0", "dest_port": "9100", "server": "pjl_server", "src_ip": "128.199.207.106", "src_port": "51518", "timestamp": "2024-06-20T03:57:31.916407"}
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2024-06-19 03:26:02
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 18 23:25:58.117199 2024] [security2:error] [pid 1679] [client 128.199.207.106:42866] [client 128.199.207.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||acadianahero.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "acadianahero.com"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZnJPxhqjkOWKEI9mup_ypgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-18 19:49:48
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 18 15:49:41.455085 2024] [security2:error] [pid 9523] [client 128.199.207.106:41558] [client 128.199.207.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "38"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.199|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.199"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZnHk1YjTEp6bq-PrVHJx8gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.Examensfragen.de
2024-06-14 22:49:16
(2 years ago)
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-06-13 08:00:51
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 04:00:47.867051 2024] [security2:error] [pid 4247] [client 128.199.207.106:44112] [client 128.199.207.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.229|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.229"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZmqnLwy-agcoUsplGJm3bQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gu-alvareza
2024-06-13 07:05:35
(2 years ago)
PHP.CGI.Argument.Injection
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 04:31:29
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 00:31:22.743624 2024] [security2:error] [pid 803033] [client 128.199.207.106:48760] [client 128.199.207.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.63|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.63"] [uri "/php-cgi/php-cgi.exe"] [unique_id "Zmp2Gt_0kTYhrVqwa85xPQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 03:46:13
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 12 23:46:08.526259 2024] [security2:error] [pid 7407] [client 128.199.207.106:35186] [client 128.199.207.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.99|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.99"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZmprgFbbzA-mZO_ifJzf7wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 01:57:22
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 12 21:57:18.169250 2024] [security2:error] [pid 24973] [client 128.199.207.106:46236] [client 128.199.207.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.71|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.71"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZmpR_jeVmz8SbmfjfBraBQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 00:33:33
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 12 20:33:25.121705 2024] [security2:error] [pid 5108] [client 128.199.207.106:60888] [client 128.199.207.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.164|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.164"] [uri "/php-cgi/php-cgi.exe"] [unique_id "Zmo-VcbFg2MC21tRX0TN6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
Jim Keir
2024-06-12 23:04:18
(2 years ago)
2024-06-12 23:04:18 128.199.207.106 File scanning, blocking 128.199.207.106 for 5 minutes
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-12 23:00:25
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-12 21:02:39
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 128.199.207.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 12 17:02:34.127459 2024] [security2:error] [pid 12535] [client 128.199.207.106:48536] [client 128.199.207.106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||www.tcit.org|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "www.tcit.org"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZmoM6nLdey9ceAybAYB-RQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack