πΊπΈ
TPI-Abuse
2025-03-31 19:28:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 217.138.202.70 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 217.138.202.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 31 15:28:00.320018 2025] [security2:error] [pid 3422126:tid 3422126] [client 217.138.202.70:26709] [client 217.138.202.70] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nationalenq.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nationalenq.com"] [uri "/dump.sql"] [unique_id "Z-rswHilVzw9NOTBEnuhhgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
hbrks
2025-03-29 14:03:36
(1 year ago)
GET http://ncs.guru/
Web Spam
Hacking
Bad Web Bot
πΊπΈ
vestibtech
2025-03-28 19:53:00
(1 year ago)
217.138.202.70 - - [28/Mar/2025:13:52:59 -0600] "HEAD /sftp-config.json HTTP/2.0" 404 1332 "-" "-"
. ...
show more
217.138.202.70 - - [28/Mar/2025:13:52:59 -0600] "HEAD /sftp-config.json HTTP/2.0" 404 1332 "-" "-"
...
show less
Web App Attack
πΈπ¬
Cloudkul Cloudkul
2025-03-27 03:54:17
(1 year ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
π©πͺ
Vegascosmetics
2025-03-24 22:51:45
(1 year ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
π©πͺ
bescared
2025-03-24 21:34:36
(1 year ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
Penny Packer
2025-03-21 13:43:19
(1 year ago)
Fail2Ban apache-tripwires
Web App Attack
πͺπΈ
librebit
2025-03-19 08:04:19
(1 year ago)
Brute force
Brute-Force
πΊπΈ
TPI-Abuse
2025-03-19 04:12:13
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 217.138.202.70 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 217.138.202.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 00:12:08.332235 2025] [security2:error] [pid 11143:tid 11143] [client 217.138.202.70:2511] [client 217.138.202.70] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qualityelevatorcabs.com"] [uri "/.env"] [unique_id "Z9pEGPNgTX1i0DSz2yBUiAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-18 21:14:32
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 217.138.202.70 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 217.138.202.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 17:14:28.359731 2025] [security2:error] [pid 708615:tid 708615] [client 217.138.202.70:21049] [client 217.138.202.70] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebullmemecoin.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebullmemecoin.com"] [uri "/bak/www.sql"] [unique_id "Z9niNHb9wu9l4E69sY-NLgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
rtbh.com.tr
2025-03-18 20:48:49
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
πΉπ·
rtbh.com.tr
2025-03-17 20:48:51
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
πΊπΈ
TPI-Abuse
2025-03-17 13:43:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 217.138.202.70 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 217.138.202.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 09:43:45.842674 2025] [security2:error] [pid 7922:tid 7949] [client 217.138.202.70:59597] [client 217.138.202.70] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ethniclivesmatter.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ethniclivesmatter.com"] [uri "/back/dump.sql"] [unique_id "Z9gnEftFE0mLGetgdOLN6AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
octageeks.com
2025-03-17 04:10:10
(1 year ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π©πͺ
ghostwarriors
2025-03-16 20:20:05
(1 year ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack