๐บ๐ธ
TPI-Abuse
2024-12-04 02:22:36
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 03 21:22:30.762962 2024] [security2:error] [pid 8806:tid 8806] [client 185.51.134.77:51655] [client 185.51.134.77] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||usbea.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "usbea.com"] [uri "/sql.sql"] [unique_id "Z0-85plYI4h4ovTEbF3vYwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
invalidLuca
2024-12-04 01:25:14
(1 year ago)
[UFW] Unauthorized connection attempt from 185.51.134.77
Port Scan
๐ฉ๐ช
KPS
2024-12-04 00:46:43
(1 year ago)
PortscanM
Port Scan
๐ฉ๐ช
iNetWorker
2024-12-03 22:38:58
(1 year ago)
trying to access non-authorized port
Port Scan
๐ฉ๐ช
Admins@FBN
2024-12-03 19:48:23
(1 year ago)
FW-PortScan: Traffic Blocked srcport=5064 dstport=5038
Port Scan
๐ฉ๐ช
Admins@FBN
2024-12-03 19:48:23
(1 year ago)
FW-PortScan: Traffic Blocked srcport=46473 dstport=5038
Port Scan
Anonymous
2024-12-03 18:21:14
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2024-11-22 13:33:26
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 22 08:33:21.861805 2024] [security2:error] [pid 12152:tid 12152] [client 185.51.134.77:49877] [client 185.51.134.77] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||csgohub.gg|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "csgohub.gg"] [uri "/bak/backup.sql"] [unique_id "Z0CIIUjQrRXnStkzGrW-hAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-19 09:21:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 04:21:28.586956 2024] [security2:error] [pid 30021:tid 30021] [client 185.51.134.77:6923] [client 185.51.134.77] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||symbarenewables.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "symbarenewables.com"] [uri "/old/dump.sql"] [unique_id "ZzxYmHxpWWv4JL4n9N19OwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
CryptoYakari
2024-11-19 09:16:16
(1 year ago)
185.51.134.77 - - [19/Nov/2024:12:16:07 +0300] "HEAD /restore/dump.sql HTTP/1.0" 404 436 "-" "-"
185 ...
show more
185.51.134.77 - - [19/Nov/2024:12:16:07 +0300] "HEAD /restore/dump.sql HTTP/1.0" 404 436 "-" "-"
185.51.134.77 - - [19/Nov/2024:12:16:08 +0300] "GET /backups/directory.gz HTTP/1.0" 404 28936 "-" "-"
185.51.134.77 - - [19/Nov/2024:12:16:09 +0300] "GET /back/directory.tar HTTP/1.0" 404 28915 "-" "-"
185.51.134.77 - - [19/Nov/2024:12:16:11 +0300] "GET /bak/bak.zip HTTP/1.0" 404 28851 "-" "-"
185.51.134.77 - - [19/Nov/2024:12:16:14 +0300] "HEAD /restore/config.json HTTP/1.0" 404 436 "-" "-"
...
show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-15 14:47:18
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 15 09:47:10.504091 2024] [security2:error] [pid 3468232:tid 3468232] [client 185.51.134.77:21727] [client 185.51.134.77] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ourhotmail.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ourhotmail.com"] [uri "/back/backup.sql"] [unique_id "Zzde7k5zNdSz0k8nAG4uSwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-14 12:11:54
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 14 07:11:47.043188 2024] [security2:error] [pid 7543:tid 7543] [client 185.51.134.77:1033] [client 185.51.134.77] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mrepoch.art|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mrepoch.art"] [uri "/backups/sql.sql"] [unique_id "ZzXpA72mNgG5th2QmLcN1QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-12 04:35:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 11 23:35:10.187829 2024] [security2:error] [pid 13041:tid 13041] [client 185.51.134.77:51031] [client 185.51.134.77] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pcga.golf|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pcga.golf"] [uri "/back/sql.sql"] [unique_id "ZzLa_p6yWrNIxOkNi9rS7gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-11-09 00:01:13
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-11-03 14:27:53
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.51.134.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 03 09:27:48.015588 2024] [security2:error] [pid 12616:tid 12616] [client 185.51.134.77:36493] [client 185.51.134.77] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swhowell.com"] [uri "/backups/sftp-config.json"] [unique_id "ZyeIZJkPAmVIRDHj12CO9AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack