๐ง๐ช
madeit
2026-08-22 12:44:48
(18 hours ago)
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2025-07-11 23:28:21
(1 year ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2025-05-12 04:58:58
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-03-19 11:10:47
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-03-05 14:15:06
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-02-27 18:37:22
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 13:34:00.729438 2025] [security2:error] [pid 447352:tid 447352] [client 172.69.58.35:42782] [client 172.69.58.35] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webfrog.ws"] [uri "/restricted/.git/config"] [unique_id "Z8CwGBmoR4miGxu_fulsPQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-02-23 15:28:23
(1 year ago)
Form spam
Web Spam
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-01-31 01:16:30
(1 year ago)
Port probe to tcp/443 (https)
[srv130]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-14 16:39:09
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 14 11:39:04.537923 2025] [security2:error] [pid 3918:tid 3918] [client 172.69.58.35:22400] [client 172.69.58.35] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.virtualizecr.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.virtualizecr.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z4aTKHMzPx5BvTy9U49pKAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-01-05 00:04:34
(1 year ago)
Port probe to tcp/443 (https)
[srv130]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-03 22:44:26
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 03 17:44:19.526722 2025] [security2:error] [pid 898992:tid 898992] [client 172.69.58.35:64852] [client 172.69.58.35] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rodrigoaldecoa.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z3hoQ9ATw3RVcsobKrjsPwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2024-12-31 07:17:27
(1 year ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ณ๐ฑ
Study Bitcoin ๐ค
2024-12-13 00:52:33
(1 year ago)
Port probe to tcp/443 (https)
[srv130]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-19 20:25:13
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 15:24:27.878914 2024] [security2:error] [pid 14851:tid 14851] [client 172.69.58.35:45948] [client 172.69.58.35] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pixacast.com"] [uri "/admin/.env"] [unique_id "Zzzz-8rkUWYgrnDuqVs2BQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-26 00:30:36
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 172.69.58.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 25 20:30:28.643876 2024] [security2:error] [pid 5572:tid 5572] [client 172.69.58.35:37298] [client 172.69.58.35] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.38.175.68 (0+1 hits since last alert)|www.yggdrasil.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.yggdrasil.org"] [uri "/xmlrpc.php"] [unique_id "ZsvMpBOXrlnAFhbZUZZ4WwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack