๐บ๐ธ
leasj
2026-05-26 17:44:00
(2 weeks ago)
RequestURLs
["/robots.txt","/WebInterface/login.html","/_adminer.php","/_all_dbs","/_phpmyadmin/"," ...
show more
RequestURLs
["/robots.txt","/WebInterface/login.html","/_adminer.php","/_all_dbs","/_phpmyadmin/","/account","/admin","/admin.php","/admin/","/admin/index.html","/admin/login","/admin/login.html","/admin/login/?next=/admin/","/admin/phpmyadmin/","/admin/spider.php","/adminer.php","/adminer/","/administrator/","/administrator/components/com_joommyadmin/phpmyadmin/","/aims/ps/","/apache-default/phpmyadmin/","/auth/admin/master/console/","/authorization.do","/bitrix/admin/","/blog/phpmyadmin/","/calendar/admin/cal_login.php","/calendarix/admin/cal_login.php","/carbon/admin/login.jsp","/cgi-bin/webcm?getpage=../html/login.html","/cluster/cluster"]
SrcIpAddr
167.99.96.133
show less
Web App Attack
๐ณ๐ฑ
maxxsense
2024-06-26 16:22:35
(1 year ago)
*Port Scan* detected from 167.99.96.133 (US/United States/-).
Port Scan
๐ช๐ธ
10dencehispahard SL
2024-06-19 06:08:52
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-19 03:44:53
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 18 23:44:47.934678 2024] [security2:error] [pid 29567] [client 167.99.96.133:39382] [client 167.99.96.133] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.92|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.92"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZnJUL2j-lcRWtGeq6ZLifQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-18 20:16:24
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 18 16:16:17.477565 2024] [security2:error] [pid 6348] [client 167.99.96.133:47074] [client 167.99.96.133] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.244|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.244"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZnHrEcnCadecWC38DUoYaAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-18 19:39:44
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 18 15:39:40.650186 2024] [security2:error] [pid 30293] [client 167.99.96.133:49028] [client 167.99.96.133] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.62|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.62"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZnHifAyNFK0H5-2ZGKf5xgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
Jim Keir
2024-06-18 01:14:33
(1 year ago)
2024-06-18 01:14:32 167.99.96.133 File scanning, blocking 167.99.96.133 for 5 minutes
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 08:28:52
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 04:28:46.864316 2024] [security2:error] [pid 11343] [client 167.99.96.133:46984] [client 167.99.96.133] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "38"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.151.9|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.151.9"] [uri "/php-cgi/php-cgi.exe"] [unique_id "Zmqtvhrh1fzIj5IwCH-xnQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-13 07:07:41
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 13 03:07:38.822554 2024] [security2:error] [pid 30094] [client 167.99.96.133:37760] [client 167.99.96.133] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.229|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.229"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZmqauqGLXC5T9Qmwn7ZW0AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-06-13 04:55:04
(2 years ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-12 23:26:14
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 12 19:26:09.741390 2024] [security2:error] [pid 12857] [client 167.99.96.133:50176] [client 167.99.96.133] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.19|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.19"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZmoukfVFLdkFRmcFCVDWcwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-12 20:56:28
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 12 16:56:24.129192 2024] [security2:error] [pid 607218] [client 167.99.96.133:56874] [client 167.99.96.133] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.50|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.50"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZmoLeNYnX5CGSBNvrIU9IgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-12 16:45:17
(2 years ago)
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 167.99.96.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 12 12:45:08.036316 2024] [security2:error] [pid 8277] [client 167.99.96.133:35104] [client 167.99.96.133] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||barigby.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "barigby.com"] [uri "/php-cgi/php-cgi.exe"] [unique_id "ZmnQlDu7M2UgBz-FFH5RCQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Block Rockin' Beats
2024-06-12 08:05:02
(2 years ago)
Scanning for exploitable scripts
Hacking
Web App Attack
๐ฉ๐ช
ISPLtd
2024-06-11 00:17:26
(2 years ago)
Jun 10 21:17:23 SRC=167.99.96.133 PROTO=TCP SPT=46326 DPT=8080 SYN
Jun 10 21:17:24 SRC=167.99.96.133 ...
show more
Jun 10 21:17:23 SRC=167.99.96.133 PROTO=TCP SPT=46326 DPT=8080 SYN
Jun 10 21:17:24 SRC=167.99.96.133 PROTO=TCP SPT=46326 DPT=8080 SYN
Jun 10 21:17:26 SRC=167.99.96.133 PROTO=TCP SPT=46326 DPT=8080
...
show less
Port Scan