๐บ๐ธ
octageeks.com
2025-07-25 04:25:16
(10 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2025-06-27 12:00:58
(11 months ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐ฌ๐ง
pinguin
2025-06-18 15:15:57
(11 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
thefoofighter
2025-05-14 16:56:39
(1 year ago)
[Wed May 14 16:56:19.399625 2025] [:error] [pid 3213456] [client 172.70.34.81:41686] [client 172.70. ...
show more
[Wed May 14 16:56:19.399625 2025] [:error] [pid 3213456] [client 172.70.34.81:41686] [client 172.70.34.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 18)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.cathalmcnally.com"] [uri "/comeonin/admin-ajax.php"] [unique_id "aCTLM5sanCTv2E9dIay1nwAAAAw"]
[Wed May 14 16:56:38.713502 2025] [:error] [pid 3214079] [client 172.70.34.81:47014] [client 172.70.34.81] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 18)"] [severity "CRITICAL"]
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
creations.works
2025-05-09 05:39:47
(1 year ago)
Blocked by UFW on vds [80/tcp]
Source port: 24384
TTL: 58
Packet length: 60
TOS: 0x00
This report w ...
show more
Blocked by UFW on vds [80/tcp]
Source port: 24384
TTL: 58
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 02:17:23
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 07 22:17:15.276310 2025] [security2:error] [pid 1407729:tid 1407729] [client 172.70.34.81:45644] [client 172.70.34.81] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sportsbookcommission.com"] [uri "/.git/config"] [unique_id "aBwUK_hB7TARp4ubiNE35QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-29 00:32:31
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 28 20:32:26.069126 2025] [security2:error] [pid 29504:tid 29504] [client 172.70.34.81:40434] [client 172.70.34.81] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/.env"] [unique_id "aBAeGuk3IAd6HpCb2CV4XgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-24 03:10:35
(1 year ago)
(mod_security) mod_security (id:243420) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:243420) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 23:10:27.985655 2025] [security2:error] [pid 1351279:tid 1351279] [client 172.70.34.81:33792] [client 172.70.34.81] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:p" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6649"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||webdisk.easy-byte.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "webdisk.easy-byte.net"] [uri "/.cpanel/dcv"] [unique_id "aAmrowBNrTBUWbmAFwfG8wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-21 08:10:37
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
mawan
2025-04-17 03:22:37
(1 year ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-07 16:32:39
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-06 03:02:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 05 23:02:55.497343 2025] [security2:error] [pid 10993:tid 10993] [client 172.70.34.81:57220] [client 172.70.34.81] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gibit.me"] [uri "/admin/.git/config"] [unique_id "Z_Hu32S-kFSFxmY3ez0wmwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-30 09:25:37
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.34.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 30 05:25:32.633577 2025] [security2:error] [pid 3949863:tid 3949863] [client 172.70.34.81:37896] [client 172.70.34.81] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.upskirtcrazy.com"] [uri "/docker/.env"] [unique_id "Z-kODCxsSOSg2mppfQ1QtwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-03-15 21:13:22
(1 year ago)
Form spam
Web Spam
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-03-09 05:58:51
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack