๐ง๐ท
leolemos
2026-03-26 21:42:32
(2 months ago)
[Thu Mar 26 18:42:30.274448 2026] [proxy_fcgi:error] [pid 1321761] [client 172.69.22.77:13583] AH010 ...
show more
[Thu Mar 26 18:42:30.274448 2026] [proxy_fcgi:error] [pid 1321761] [client 172.69.22.77:13583] AH01071: Got error 'Primary script unknown'
[Thu Mar 26 18:42:30.881032 2026] [proxy_fcgi:error] [pid 1321761] [client 172.69.22.77:13583] AH01071: Got error 'Primary script unknown'
[Thu Mar 26 18:42:31.193914 2026] [proxy_fcgi:error] [pid 1321761] [client 172.69.22.77:13583] AH01071: Got error 'Primary script unknown'
show less
Brute-Force
Web App Attack
๐ฌ๐ง
OptimusGO
2026-02-23 04:00:08
(3 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-02-23 04:00:07 UTC
Log evidence:
02/23/2026-04:00:06.684697 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 172.69.22.77:12468 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
๐ง๐ท
leolemos
2026-02-08 17:32:21
(3 months ago)
[Sun Feb 08 14:31:55.510639 2026] [proxy_fcgi:error] [pid 2799911] [client 172.69.22.77:11416] AH010 ...
show more
[Sun Feb 08 14:31:55.510639 2026] [proxy_fcgi:error] [pid 2799911] [client 172.69.22.77:11416] AH01071: Got error 'Primary script unknown'
[Sun Feb 08 14:31:56.595062 2026] [proxy_fcgi:error] [pid 2799911] [client 172.69.22.77:11416] AH01071: Got error 'Primary script unknown'
[Sun Feb 08 14:32:20.483157 2026] [proxy_fcgi:error] [pid 2816071] [client 172.69.22.77:9410] AH01071: Got error 'Primary script unknown'
show less
Brute-Force
Web App Attack
๐บ๐ธ
MirrorImageGaming
2025-12-11 13:53:20
(5 months ago)
HTTP probe(s) @ TCP 80 US
Port Scan
๐บ๐ธ
thefoofighter
2025-12-06 02:20:36
(6 months ago)
[Sat Dec 06 02:20:36.009173 2025] [:error] [pid 82329] [client 172.69.22.77:14232] [client 172.69.22 ...
show more
[Sat Dec 06 02:20:36.009173 2025] [:error] [pid 82329] [client 172.69.22.77:14232] [client 172.69.22.77] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sarahmcnally.com"] [uri "/app/logs/dev.log"] [unique_id "aTOS9GzNtHAz0Dc-SQrnFwAAAAE"]
[Sat Dec 06 02:20:36.172023 2025] [:error] [pid 82329] [client 172.69.22.77:14232] [client 172.69.22.77] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Paschen J Ki
2025-10-23 06:47:39
(7 months ago)
Blocked by UFW on 1 [8008/tcp]
Source port: 21383
TTL: 51
Packet length: 60
TOS: 0x00
This report w ...
show more
Blocked by UFW on 1 [8008/tcp]
Source port: 21383
TTL: 51
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-23 02:08:43
(1 year ago)
2 port probes: tcp/443 (https), tcp/80 (http)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-20 10:31:52
(1 year ago)
Excessive crawling/scraping
Hacking
Brute-Force
๐ช๐ธ
el-brujo
2025-05-14 22:14:47
(1 year ago)
15/May/2025:00:14:47.395659 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
15/May/2025:00:14:47.395659 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.69.22.77] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.development"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "warzone.elhacker.net"] [uri "/.env.development"] [unique_id "aCUV1wv-fd8jW0wurVKi7gADazg"]
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-03-14 23:56:42
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-02-22 01:05:12
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2025-02-11 10:39:45
(1 year ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2025-01-14 20:23:51
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.69.22.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.22.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 14 15:23:43.839901 2025] [security2:error] [pid 28693:tid 28693] [client 172.69.22.77:46038] [client 172.69.22.77] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gibitdigital.com"] [uri "/.env"] [unique_id "Z4bHz9lK9jOdTYF6m122cQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-01-12 03:44:46
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐ต๐ฐ
sbk97 (https://sayor.net)
2025-01-09 20:53:09
(1 year ago)
"GET /.well-known/ HTTP/2.0 --- Reported by sayor.online Network Telescope"
Web Spam
Hacking
Web App Attack