๐บ๐ธ
inspectorgdgt
2025-07-04 01:27:29
(1 year ago)
"Failed password for invalid user"
Brute-Force
๐บ๐ธ
inspectorgdgt
2025-07-04 01:27:29
(1 year ago)
"Failed password for invalid user root from 170.130.55.85"
Brute-Force
๐ญ๐บ
szasa
2025-06-22 11:49:46
(1 year ago)
2025/06/22 13:49:33 [error] 1465036#1465036: *8478259 access forbidden by rule, client: 170.130.55.8 ...
show more
2025/06/22 13:49:33 [error] 1465036#1465036: *8478259 access forbidden by rule, client: 170.130.55.85, server: datamentor.hu, request: "GET /.git/config HTTP/1.1", host: "datamentor.hu"
2025/06/22 13:49:41 [error] 1465036#1465036: *8478268 access forbidden by rule, client: 170.130.55.85, server: datamentor.hu, request: "GET /.DS_Store HTTP/1.1", host: "datamentor.hu"
2025/06/22 13:49:42 [error] 1465036#1465036: *8478281 access forbidden by rule, client: 170.130.55.85, server: datamentor.hu, request: "GET /.env HTTP/1.1", host: "datamentor.hu"
2025/06/22 13:49:45 [error] 1465036#1465036: *8478282 access forbidden by rule, client: 170.130.55.85, server: datamentor.hu, request: "POST /.env HTTP/1.1", host: "datamentor.hu"
...
show less
Web App Attack
Anonymous
2025-06-21 10:34:37
(1 year ago)
[Sat Jun 21 05:30:58.060353 2025] [proxy_fcgi:error] [pid 401687:tid 401687] [client 170.130.55.85:4 ...
show more
[Sat Jun 21 05:30:58.060353 2025] [proxy_fcgi:error] [pid 401687:tid 401687] [client 170.130.55.85:49531] AH01071: Got error 'Primary script unknown'
[Sat Jun 21 05:34:20.289815 2025] [proxy_fcgi:error] [pid 404371:tid 404371] [client 170.130.55.85:53629] AH01071: Got error 'Primary script unknown'
[Sat Jun 21 05:34:37.248682 2025] [proxy_fcgi:error] [pid 401691:tid 401691] [client 170.130.55.85:55322] AH01071: Got error 'Primary script unknown'
...
show less
Web App Attack
Anonymous
2025-06-21 01:03:15
(1 year ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
Anonymous
2025-06-20 23:01:49
(1 year ago)
Hacking Attempt
Hacking
Web App Attack
๐ธ๐ช
Lemmy
2025-06-20 11:02:45
(1 year ago)
Web App Attack
Anonymous
2025-06-18 08:08:10
(1 year ago)
Attempted search for exploits and vulnerabilities detected by fail2ban noscript
...
Brute-Force
Web App Attack
๐ฉ๐ช
DEV-DNS
2025-06-18 03:46:11
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ธ๐ช
Lemmy
2025-06-17 01:44:36
(1 year ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-16 11:23:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 16 07:23:39.847260 2025] [security2:error] [pid 2265020:tid 2265020] [client 170.130.55.85:57339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "niftythrifty.net"] [uri "/.env.production"] [unique_id "aE_-u81GbRA3DdHfjwnNNwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-16 10:51:48
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 16 06:51:45.695116 2025] [security2:error] [pid 2163782:tid 2163782] [client 170.130.55.85:65413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gormish.org"] [uri "/sftp-config.json"] [unique_id "aE_3Qb2br5TLRqN5xSFeTAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-16 02:56:32
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 15 22:56:28.399198 2025] [security2:error] [pid 2729482:tid 2729482] [client 170.130.55.85:59808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robertet.co"] [uri "/redmine/.env"] [unique_id "aE-H3A3F-IT6iJ_Ed6qD2wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-15 18:10:46
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 15 14:10:42.270373 2025] [security2:error] [pid 2736147:tid 2736147] [client 170.130.55.85:60079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chipnado.com"] [uri "/.env"] [unique_id "aE8MonRC0qRxMHOCzzcAjQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-15 13:17:56
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.130.55.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 15 09:17:53.525711 2025] [security2:error] [pid 245047:tid 245047] [client 170.130.55.85:57689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amyisms.com"] [uri "/.git/config"] [unique_id "aE7IAQzX8WFWn-B3__TRngAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack