Anonymous
2025-07-07 14:53:00
(1 year ago)
Web App Attack
Web App Attack
๐ซ๐ท
masterguru
2025-07-06 02:28:19
(1 year ago)
COMODO WAF: SQLmap attack detected. 403, (218500-180)
Hacking
๐บ๐ธ
TPI-Abuse
2025-07-06 01:46:35
(1 year ago)
(mod_security) mod_security (id:248270) triggered by 164.68.99.200 (vmi2696039.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:248270) triggered by 164.68.99.200 (vmi2696039.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 05 21:46:29.123166 2025] [security2:error] [pid 8912:tid 8912] [client 164.68.99.200:43010] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\$\\\\{jndi:(ldaps?|rmi|dns|iiop|nis|nds|corba|\\\\$\\\\{(?:lower|upper)):" at ARGS:x. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "7626"] [id "248270"] [rev "1"] [msg "COMODO WAF: Remote code execution in Apache log4j||ticket.goalsnet.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ticket.goalsnet.net"] [uri "/"] [unique_id "aGnVdWp7FF9AlgCI2ea7awAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-07-05 23:50:06
(1 year ago)
550 limiting connections by zone (1h39m59s)
DDoS Attack
๐จ๐ฟ
Countryman
2025-07-05 22:36:56
(1 year ago)
IPS detection: Apache.OFBiz.CVE-2021-26295.Insecure.Deserialization
Hacking
๐จ๐ฟ
Countryman
2025-07-05 22:36:56
(1 year ago)
IPS detection: Apache.OFBiz.CVE-2021-26295.Insecure.Deserialization
Hacking
๐ง๐ช
cmbplf
2025-07-05 20:50:01
(1 year ago)
568 limiting connections by zone (11m59s)
DDoS Attack
๐ซ๐ท
Security_Whaller
2025-07-05 18:35:24
(1 year ago)
Malicious activity detected on Honeypot.
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
COMAITE
2025-07-05 17:49:38
(1 year ago)
Common web attack from 164.68.99.200.
Web App Attack
๐ฎ๐น
VHosting
2025-07-05 16:25:49
(1 year ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐ฌ๐ง
WebNiraj
2025-07-05 15:20:46
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 164.68.99.200 (DE/Germany/vmi2696039.contaboser ...
show more
(mod_security) mod_security (id:949110) triggered by 164.68.99.200 (DE/Germany/vmi2696039.contaboserver.net): 5 in the last 3600 secs [ZETA]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-07-05 14:47:47
(1 year ago)
(mod_security) mod_security (id:248270) triggered by 164.68.99.200 (vmi2696039.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:248270) triggered by 164.68.99.200 (vmi2696039.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 05 10:47:43.731429 2025] [security2:error] [pid 24027:tid 24027] [client 164.68.99.200:52914] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\$\\\\{jndi:(ldaps?|rmi|dns|iiop|nis|nds|corba|\\\\$\\\\{(?:lower|upper)):" at ARGS:x. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "7626"] [id "248270"] [rev "1"] [msg "COMODO WAF: Remote code execution in Apache log4j||test.altruaglobalsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "test.altruaglobalsolutions.com"] [uri "/"] [unique_id "aGk7DzcHtnHvfa4whFdL6AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-05 14:43:12
(1 year ago)
164.68.99.200 - - [05/Jul/2025:16:43:10 +0200] "GET /solr/solrdefault/debug/dump?param=ContentStream ...
show more
164.68.99.200 - - [05/Jul/2025:16:43:10 +0200] "GET /solr/solrdefault/debug/dump?param=ContentStreams&stream.url=file://c:/windows/win.ini HTTP/1.1" 404 5457 "-" "Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/118.0"
164.68.99.200 - - [05/Jul/2025:16:43:10 +0200] "GET /?id=%25%7B%28%23instancemanager%3D%23application%5B%22org.apache.tomcat.InstanceManager%22%5D%29.%28%23stack%3D%23attr%5B%22com.opensymphony.xwork2.util.ValueStack.ValueStack%22%5D%29.%28%23bean%3D%23instancemanager.newInstance%28%22org.apache.commons.collections.BeanMap%22%29%29.%28%23bean.setBean%28%23stack%29%29.%28%23context%3D%23bean.get%28%22context%22%29%29.%28%23bean.setBean%28%23context%29%29.%28%23macc%3D%23bean.get%28%22memberAccess%22%29%29.%28%23bean.setBean%28%23macc%29%29.%28%23emptyset%3D%23instancemanager.newInstance%28%22java.util.HashSet%22%29%29.%28%23bean.put%28%22excludedClasses%22%2C%23emptyset%29%29.%28%23bean.put%28%22excludedPackageNames%22%2C%23emptyset%29%29.%28%23arglist%3D%23
...
show less
Hacking
๐จ๐ญ
Elysium Security
2025-07-05 11:25:31
(1 year ago)
Mass scanning for Web CVE
Web App Attack
๐ฆ๐บ
AWW-Admin
2025-07-05 10:39:38
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted] 164.68.99.200 (FR/France/vmi2696039.con ...
show more
(mod_security) mod_security triggered on hostname [redacted] 164.68.99.200 (FR/France/vmi2696039.contaboserver.net)
show less
SQL Injection