πΊπΈ
BSG Webmaster
2023-11-21 23:12:57
(2 years ago)
Hacking Attempt using path /static/css/app.a9993daf676fbc0a430012ea8d96d7a7.css on 2023-11-21 08:47: ...
show more
Hacking Attempt using path /static/css/app.a9993daf676fbc0a430012ea8d96d7a7.css on 2023-11-21 08:47:53
show less
Hacking
π¦πΊ
MAGIC
2023-11-21 11:00:37
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π±πΊ
Tha_14
2023-11-17 09:17:12
(2 years ago)
Incoming TCP Connection from 154.91.138.25 to port: 80. Honeypot was triggered at 11/17/2023 08:16:1 ...
show more
Incoming TCP Connection from 154.91.138.25 to port: 80. Honeypot was triggered at 11/17/2023 08:16:16 AM.
show less
Port Scan
Hacking
πΊπΈ
TPI-Abuse
2023-11-17 07:29:19
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 02:29:12.207307 2023] [security2:error] [pid 16421] [client 154.91.138.25:49716] [client 154.91.138.25] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||americancryonics.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "americancryonics.org"] [uri "/"] [unique_id "ZVcWSPOJ_m4luOayF4cwcgAAAAE"], referer: http://americancryonics.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 18:27:51
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 13:27:48.148767 2023] [security2:error] [pid 8201] [client 154.91.138.25:39490] [client 154.91.138.25] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.amateurindex.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.amateurindex.com"] [uri "/links/solo.php"] [unique_id "ZVZfJH7sdzetN-KzPatJLAAAAAs"], referer: http://annawood.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 18:11:15
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 13:11:12.020260 2023] [security2:error] [pid 18181] [client 154.91.138.25:35464] [client 154.91.138.25] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||barnesandbrower.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "barnesandbrower.com"] [uri "/"] [unique_id "ZVZbQJJuP3BW7xiCwfx3lQAAABk"], referer: http://barnesandbrower.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 17:16:50
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 12:16:43.763781 2023] [security2:error] [pid 23304] [client 154.91.138.25:37046] [client 154.91.138.25] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||1234family.macooh.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "1234family.macooh.com"] [uri "/"] [unique_id "ZVZOe8mZ66OwK3R_T6vtVgAAABA"], referer: http://1234family.macooh.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 16:15:29
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 11:15:24.702237 2023] [security2:error] [pid 26318] [client 154.91.138.25:54674] [client 154.91.138.25] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||brevardzen.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "brevardzen.org"] [uri "/"] [unique_id "ZVZAHGtIHc4CCQXll8UhEgAAABE"], referer: http://brevardzen.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 11:42:24
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 06:42:22.691659 2023] [security2:error] [pid 32461] [client 154.91.138.25:48748] [client 154.91.138.25] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||advmach.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "advmach.com"] [uri "/"] [unique_id "ZVYAHpf6GUM_7rUV2jv4YwAAAAg"], referer: http://advmach.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2023-11-16 11:06:29
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 154.91.138.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 16 06:06:26.247223 2023] [security2:error] [pid 10806] [client 154.91.138.25:44988] [client 154.91.138.25] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bernarrmacfadden.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bernarrmacfadden.com"] [uri "/"] [unique_id "ZVX3sv7Vjss2HPE3PBa07gAAAAk"], referer: http://bernarrmacfadden.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-04 21:34:52
(2 years ago)
FAKE UA - BLOCKED
Brute-Force
Bad Web Bot
π¦πΊ
MAGIC
2023-11-03 10:00:24
(2 years ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2023-11-03 04:00:37
(2 years ago)
GET /static
Web App Attack
π¬π§
CrystalMaker
2023-11-02 18:25:32
(2 years ago)
Vulnerability scan - GET /zyms/ubox.js; GET /common/modelCommon/notice/js/dialog-plus-min.js; GET /c ...
show more
Vulnerability scan - GET /zyms/ubox.js; GET /common/modelCommon/notice/js/dialog-plus-min.js; GET /common/js/knockout-3.4.2.js; GET /popups/v1/register.bundle.js; GET /skin/index/static/common.js; GET /lbtu/zsygd.js
show less
Hacking
π¦πΊ
MAGIC
2023-11-02 05:09:23
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot