๐ฉ๐ช
hbrks
2024-02-27 03:37:45
(2 years ago)
HEAD http://ncs.guru/restore/website.tar
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐ฉ๐ช
hbrks
2024-02-25 16:56:02
(2 years ago)
HEAD http://marche-be.com/old/sftp-config.json
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-02-23 20:56:14
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 23 15:56:08.282778 2024] [security2:error] [pid 29521:tid 47706957420288] [client 157.97.122.2:23595] [client 157.97.122.2] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bluetigertees.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bluetigertees.com"] [uri "/www.sql"] [unique_id "ZdkGaNRDRcWasN68TIX6XAAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-20 23:21:14
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 20 18:21:10.225126 2024] [security2:error] [pid 20006:tid 47955389044480] [client 157.97.122.2:48113] [client 157.97.122.2] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||seattlebasketballservices.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "seattlebasketballservices.com"] [uri "/old/www.sql"] [unique_id "ZdUz5omQ3CBA-uDtGKl5aQAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2024-02-20 23:14:52
(2 years ago)
HEAD http://p4u.xyz/Archive.zip
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐ฉ๐ช
hbrks
2024-02-20 22:56:05
(2 years ago)
HEAD http://p4u.xyz/bak/config.js
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-02-09 18:42:09
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 09 13:42:06.292734 2024] [security2:error] [pid 17759] [client 157.97.122.2:63225] [client 157.97.122.2] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thepinman.org"] [uri "/.env"] [unique_id "ZcZx_pE6SKaVZk6CaGmJfwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
unifr
2024-02-09 03:28:30
(2 years ago)
Unauthorized IMAP connection attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-02-05 19:00:36
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 05 14:00:29.503096 2024] [security2:error] [pid 30204] [client 157.97.122.2:52919] [client 157.97.122.2] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ciptaconindotara.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ciptaconindotara.com"] [uri "/bak/sql.sql"] [unique_id "ZcEwTRAcZwwSMFLMmbbLJgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-05 13:56:47
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 05 08:56:42.045556 2024] [security2:error] [pid 13882] [client 157.97.122.2:50953] [client 157.97.122.2] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hodlmoser.com"] [uri "/backups/.env"] [unique_id "ZcDpGls0wPOzXl3F4vMTGwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
saima.info
2024-02-05 10:33:11
(2 years ago)
Port scanning, proxy abuse
Port Scan
Brute-Force
๐ช๐ธ
saima.info
2024-02-05 10:33:11
(2 years ago)
Port scanning, proxy abuse
Port Scan
Brute-Force
๐ช๐ธ
Reinhard
2024-01-29 19:48:47
(2 years ago)
Msg from utility: IP-Addr: 157.97.122.2, Fehler: /util/showpic2-v01.php?parm=4,26,1198,1032%27nvOpzp ...
show more
Msg from utility: IP-Addr: 157.97.122.2, Fehler: /util/showpic2-v01.php?parm=4,26,1198,1032%27nvOpzp;%20AND%201=1%20OR%20(%3C%27%22%3EiKO)),. Body: Mon, 29 Jan 2024 19:52:07 +0100, IP-Addr:157.97.122.2, Host: 157.97.122.2, Info: SQL injection, parameter error
show less
Hacking
SQL Injection
Web App Attack
๐ฆ๐บ
oncord
2024-01-23 02:51:04
(2 years ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2024-01-21 17:23:48
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 21 12:23:42.785382 2024] [security2:error] [pid 32306] [client 157.97.122.2:51091] [client 157.97.122.2] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.crypto-stamps.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.crypto-stamps.com"] [uri "/sql.sql"] [unique_id "Za1THh6tj4pTVsPSe4JwZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack