๐ฉ๐ช
host.slimatic.be
2024-09-19 09:12:41
(2 years ago)
Blocked by UFW (TCP on port 59062).
Source port: 12359
TTL: 54
Packet length: 588
TOS: 0x00
Timestam ...
show more
Blocked by UFW (TCP on port 59062).
Source port: 12359
TTL: 54
Packet length: 588
TOS: 0x00
Timestamp: [Europe/Warsaw]
This report (for 2.57.214.195) was generated by:
https://github.com/sefinek24/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
octageeks.com
2024-09-14 04:10:05
(2 years ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
octageeks.com
2024-09-13 04:10:00
(2 years ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
octageeks.com
2024-09-12 04:09:41
(2 years ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
lnklnx
2024-09-12 00:56:26
(2 years ago)
nextcloud.lnklnx.com:80 2.57.214.195 - - [11/Sep/2024:19:56:25 -0500] "GET /.git/config HTTP/1.1" 30 ...
show more
nextcloud.lnklnx.com:80 2.57.214.195 - - [11/Sep/2024:19:56:25 -0500] "GET /.git/config HTTP/1.1" 301 453 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐ฉ๐ช
paissangroup
2024-09-11 01:26:03
(2 years ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
polycoda
2024-09-10 16:19:05
(2 years ago)
๐ Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack
๐ฎ๐น
LTM
2024-09-10 06:20:02
(2 years ago)
WebServer - Attempts to exploit
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-10 00:58:24
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 09 20:58:16.659625 2024] [security2:error] [pid 28802:tid 28802] [client 2.57.214.195:59632] [client 2.57.214.195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsenaultartistmanagement.com"] [uri "/wp-config.phpOLD"] [unique_id "Zt-ZqGrEUpb8tYvFdjE5lQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-09 14:52:05
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 09 10:51:58.416197 2024] [security2:error] [pid 28974:tid 28974] [client 2.57.214.195:51522] [client 2.57.214.195] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||madisonjazzorchestra.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "madisonjazzorchestra.com"] [uri "/madi.sql"] [unique_id "Zt8LjtmlNVMEVATrQmYjhQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-09 12:24:19
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 09 08:24:13.674397 2024] [security2:error] [pid 26512:tid 26512] [client 2.57.214.195:45554] [client 2.57.214.195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.badwaterclaims.helpkccare.org"] [uri "/.git/config"] [unique_id "Zt7o7U-JmCupFg084Ejh4wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-09-09 10:02:43
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-09 06:50:02
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 09 02:49:53.586189 2024] [security2:error] [pid 645796:tid 645796] [client 2.57.214.195:37110] [client 2.57.214.195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainjaytherapy.com"] [uri "/wp-config.php5"] [unique_id "Zt6akbpPtShYSuNsjdgoJwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2024-09-09 06:13:07
(2 years ago)
honeypot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-08 21:30:25
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 2.57.214.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 08 17:30:22.012542 2024] [security2:error] [pid 26046:tid 26046] [client 2.57.214.195:51056] [client 2.57.214.195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mariarozella.com"] [uri "/.git/config"] [unique_id "Zt4XbgwJcQV7XO5FrJIlLgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack