Anonymous
2025-07-25 09:29:17
(1 year ago)
XMLRPC Hack Attempts
Hacking
Brute-Force
๐ฆ๐บ
MAGIC
2025-07-19 05:07:29
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-07-02 02:25:21
(1 year ago)
XMLRPC Hack Attempts
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-07-01 04:11:55
(1 year ago)
(mod_security) mod_security (id:210831) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 01 00:11:49.033170 2025] [security2:error] [pid 24421:tid 24421] [client 196.198.211.117:43914] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||backstore.com|F|4"] [data "a href="] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "backstore.com"] [uri "/"] [unique_id "aGNgBa2z6kjXj_hSHSi_FQAAABM"], referer: https://11-winner.xyz/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oncord
2024-06-21 17:19:44
(2 years ago)
Form spam
Web Spam
Anonymous
2024-06-20 05:09:20
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-06-15 00:19:41
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
oncord
2024-06-10 21:44:12
(2 years ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2024-06-05 01:25:52
(2 years ago)
(mod_security) mod_security (id:217280) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217280) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 04 21:25:45.012530 2024] [security2:error] [pid 3267408] [client 196.198.211.117:39539] [client 196.198.211.117] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||www.cajunpicasso.com|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.cajunpicasso.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "Zl--mbBD1GMEknmlOcARWwAAAA8"], referer: http://www.cajunpicasso.com/contact/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oncord
2024-06-03 16:07:11
(2 years ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2024-05-30 20:53:14
(2 years ago)
(mod_security) mod_security (id:217280) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217280) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 30 16:53:06.309693 2024] [security2:error] [pid 29427] [client 196.198.211.117:41555] [client 196.198.211.117] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||www.hawarcenter.com|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.hawarcenter.com"] [uri "/"] [unique_id "ZljnMoAOQ5Auo-O-Yn69ZAAAABQ"], referer: http://www.hawarcenter.com/?page_id=336
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oncord
2024-05-30 19:31:21
(2 years ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2024-05-29 20:27:26
(2 years ago)
(mod_security) mod_security (id:217280) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217280) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 29 16:27:18.591728 2024] [security2:error] [pid 18624] [client 196.198.211.117:45234] [client 196.198.211.117] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||nypdkids.org|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "nypdkids.org"] [uri "/php/send_email.php"] [unique_id "ZlePpoKiq-Ko5Y4h9WAChwAAAAs"], referer: http://nypdkids.org/contact-donate-nypd-kids.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oncord
2024-05-29 16:03:35
(2 years ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2024-05-24 17:27:58
(2 years ago)
(mod_security) mod_security (id:217280) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217280) triggered by 196.198.211.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 24 13:27:52.536574 2024] [security2:error] [pid 3061] [client 196.198.211.117:34549] [client 196.198.211.117] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||www.namisushionline.com|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.namisushionline.com"] [uri "/action.php"] [unique_id "ZlDOGHtndlUIfvy4TqQrCgAAAA4"], referer: https://www.namisushionline.com
show less
Brute-Force
Bad Web Bot
Web App Attack