๐ง๐ท
Sipo Chutรฃo
2025-08-19 03:00:01
(1 year ago)
/upl.php
Hacking
๐บ๐ธ
wtran
2025-08-14 00:00:00
(1 year ago)
Potentially Malcious IP Targeting Public Facing System
Port Scan
๐บ๐ธ
wtran
2025-08-14 00:00:00
(1 year ago)
Potentially Malcious IP Targeting Public Facing System
Port Scan
๐ญ๐บ
btimon
2025-08-11 12:31:00
(1 year ago)
SystemBC.Botnet
Bad Web Bot
๐บ๐ธ
chronos
2025-08-11 06:33:21
(1 year ago)
[AUTORAVALT][[11/08/2025 - 03:33:21 -03:00 UTC]
Attack from [DigitalOcean, LLC]
[152.42.201.88] Acti ...
show more
[AUTORAVALT][[11/08/2025 - 03:33:21 -03:00 UTC]
Attack from [DigitalOcean, LLC]
[152.42.201.88] Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
Web App Attack -> Attempts to probe f]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐บ๐ธ
chronos
2025-08-11 06:16:44
(1 year ago)
[AUTORAVALT][[11/08/2025 - 03:16:44 -03:00 UTC]
Attack from [DigitalOcean, LLC]
[152.42.201.88] Acti ...
show more
[AUTORAVALT][[11/08/2025 - 03:16:44 -03:00 UTC]
Attack from [DigitalOcean, LLC]
[152.42.201.88] Action: BLocKed
Bad Web Bot -> Webpage scraping (email extraction, content, etc.) crawlers that do not respect robots.txt. Excessive requests and user agent spoofing.
]
...
show less
Bad Web Bot
Anonymous
2025-08-11 00:20:06
(1 year ago)
Hacking
Anonymous
2025-08-11 00:07:52
(1 year ago)
Aggressive web scan
SQL Injection
Bad Web Bot
Web App Attack
Anonymous
2025-08-10 13:28:47
(1 year ago)
[Sun Aug 10 08:28:42.289906 2025] [proxy_fcgi:error] [pid 54447:tid 54447] [client 152.42.201.88:580 ...
show more
[Sun Aug 10 08:28:42.289906 2025] [proxy_fcgi:error] [pid 54447:tid 54447] [client 152.42.201.88:58032] AH01071: Got error 'Primary script unknown'
[Sun Aug 10 08:28:44.293819 2025] [proxy_fcgi:error] [pid 62465:tid 62465] [client 152.42.201.88:58080] AH01071: Got error 'Primary script unknown'
[Sun Aug 10 08:28:45.292107 2025] [proxy_fcgi:error] [pid 39078:tid 39078] [client 152.42.201.88:58090] AH01071: Got error 'Primary script unknown'
...
show less
Web App Attack
๐ซ๐ฎ
Flock4325
2025-08-10 12:35:14
(1 year ago)
Attempted direct HTTP(s) request to server IP. URI: /
Brute-Force
๐บ๐ฆ
he1zen
2025-08-10 12:25:00
(1 year ago)
443/tcp
Port Scan
๐ณ๐ฑ
Jordy
2025-08-10 11:53:20
(1 year ago)
10/Aug/2025:13:53:19.122408 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
10/Aug/2025:13:53:19.122408 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 152.42.201.88] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "141.224.196.208"] [severity "WARNING"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "141.224.196.208"] [uri "/form.html"] [unique_id "aJiIL2cba0TAqY1kI0ZeqgAAAAI"]
10/Aug/2025:13:53:19.460447 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 152.42.201.88] ModSecurity: Warning. Pattern match "^[\\\\\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "H
...
show less
Web App Attack
๐ฉ๐ช
Nightreaver
2025-08-10 09:23:46
(1 year ago)
152.42.201.88 - - [10/Aug/2025:11:23:42 0200] "GET /form.html HTTP/1.1" 404 438 "-" "curl/8.1.2"
15 ...
show more
152.42.201.88 - - [10/Aug/2025:11:23:42 0200] "GET /form.html HTTP/1.1" 404 438 "-" "curl/8.1.2"
152.42.201.88 - - [10/Aug/2025:11:23:43 0200] "GET /upl.php HTTP/1.1" 404 438 "-" "Mozilla/5.0"
152.42.201.88 - - [10/Aug/2025:11:23:43 0200] "GET /t4 HTTP/1.1" 404 438 "-" "Mozilla/5.0"
152.42.201.88 - - [10/Aug/2025:11:23:44 0200] "GET /geoip/ HTTP/1.1" 404 438 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
152.42.201.88 - - [10/Aug/2025:11:23:44 0200] "GET /favicon.ico HTTP/1.1" 404 438 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
152.42.201.88 - - [10/Aug/2025:11:23:44 0200] "GET /1.php HTTP/1.1" 404 438 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
152.42.201.88 - - [10/Aug/2025:11:23:45 0200] "GET /systembc/password.php HTTP/1.1" 404 438 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64[...]
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Roper123
2025-08-10 08:46:39
(1 year ago)
Web app attack
Web App Attack
๐ฆ๐บ
ipv4.fr
2025-08-10 08:29:19
(1 year ago)
152.42.201.88 - - [10/Aug/2025:08:29:19 +0000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
152.42.201.88 - - [10/Aug/2025:08:29:19 +0000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack