๐ซ๐ท
geot
2025-05-26 11:58:53
(1 year ago)
POST /oauth/token HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-27 07:52:31
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 02:52:23.473320 2025] [security2:error] [pid 11967:tid 11967] [client 2402:1f00:8000:800::11a5:52628] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "75"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||gsrsv.org|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/gsrsv.org.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "gsrsv.org"] [uri "/\\"/><style>@import'/gsrsv.org.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z8AZt_3oZb1m1KIgPeyfkAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-26 16:15:38
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 26 11:15:35.316173 2025] [security2:error] [pid 2710353:tid 2710353] [client 2402:1f00:8000:800::11a5:52000] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "75"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||fitflex.com|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/fitflex.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "fitflex.com"] [uri "/\\"/><style>@import'/fitflex.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z78-J2bOg2H0FGs3NU4OsgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-23 23:39:57
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 23 18:39:53.885921 2025] [security2:error] [pid 552179:tid 552179] [client 2402:1f00:8000:800::11a5:47578] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "75"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||gpaarch.com|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/gpaarch.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "gpaarch.com"] [uri "/\\"/><style>@import'/gpaarch.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z7uxybIVbAWtx7gpWREjIAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-02-22 11:01:50
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-02-21 23:09:07
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 18:09:01.776738 2025] [security2:error] [pid 2632008:tid 2632008] [client 2402:1f00:8000:800::11a5:35712] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "78"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||tomweston.net|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/tomweston.net.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "tomweston.net"] [uri "/\\"/><style>@import'/tomweston.net.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z7kHjVRZPg4Tgpxkq6IEsAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
geot
2025-02-21 13:36:52
(1 year ago)
GET /%22/%3E%3Cstyle%3E@import%27//<<removed>>.com.<<removed>>.oast.fun%27%3C/style%3E HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-21 13:26:11
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 08:26:06.028673 2025] [security2:error] [pid 14370:tid 14370] [client 2402:1f00:8000:800::11a5:52342] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "75"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||palacio.org|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/palacio.org.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "palacio.org"] [uri "/\\"/><style>@import'/palacio.org.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z7h-7qRi10xK8thuIFU0rgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-21 01:46:53
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 20 20:46:45.534824 2025] [security2:error] [pid 7909:tid 7909] [client 2402:1f00:8000:800::11a5:50706] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "75"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||linguistes.com|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/linguistes.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "linguistes.com"] [uri "/\\"/><style>@import'/linguistes.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z7fbBRUKaoZpIjUVB4F3aQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-02-21 00:53:12
(1 year ago)
Cloudflare WAF: Request Path: /%22/%3E%3Cstyle%3E@import%27//elhacker.net.kairxoqhvkwuefjidbdc6xqu5c ...
show more
Cloudflare WAF: Request Path: /%22/%3E%3Cstyle%3E@import%27//elhacker.net.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun%27%3C/style%3E Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0 Action: block Source: firewallManaged ASN Description: OVH Country: SG Method: GET Timestamp: 2025-02-21T00:53:12Z ruleId: 3ef34ac2e1df4ed9900c9966128f1556. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-20 09:30:37
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 20 04:30:32.385048 2025] [security2:error] [pid 17049:tid 17049] [client 2402:1f00:8000:800::11a5:44602] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "78"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||elefen.org|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/elefen.org.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "elefen.org"] [uri "/\\"/><style>@import'/elefen.org.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z7b2OPfNljhj5wA9d14LQgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-19 05:45:27
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 19 00:45:21.648064 2025] [security2:error] [pid 14097:tid 14097] [client 2402:1f00:8000:800::11a5:45368] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "75"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||drrw.net|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/drrw.net.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "drrw.net"] [uri "/\\"/><style>@import'/drrw.net.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z7Vv8eITlr9k3f85EWB2nwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
beehivesafety
2025-02-19 03:21:15
(1 year ago)
Malicious activity detected from 16276 OVH towards host beehive.systems (GET HTTP/1.1) @ 2025-02-19 ...
show more
Malicious activity detected from 16276 OVH towards host beehive.systems (GET HTTP/1.1) @ 2025-02-19T03:21:15Z
show less
Open Proxy
VPN IP
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-18 19:09:33
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 18 14:09:26.493422 2025] [security2:error] [pid 31516:tid 31516] [client 2402:1f00:8000:800::11a5:49664] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "75"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||medicalpdq.com|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/medicalpdq.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "medicalpdq.com"] [uri "/\\"/><style>@import'/medicalpdq.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z7Ta5n1XB3wZwgkHhlzaHwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-18 11:46:18
(1 year ago)
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh. ...
show more
(mod_security) mod_security (id:212800) triggered by 2402:1f00:8000:800::11a5 (vps-f96b1b42.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 18 06:46:11.477075 2025] [security2:error] [pid 21603:tid 21603] [client 2402:1f00:8000:800::11a5:54954] [client 2402:1f00:8000:800::11a5] ModSecurity: Access denied with code 403 (phase 2). Match of "rx (?:body|content|description|post|desc|html_message|text)=" against "MATCHED_VAR" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "75"] [id "212800"] [rev "8"] [msg "COMODO WAF: XSS Attack Detected||kbalan.com|F|2"] [data "Matched Data: @import found within MATCHED_VAR: /\\x22/><style>@import'/kbalan.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "kbalan.com"] [uri "/\\"/><style>@import'/kbalan.com.kairxoqhvkwuefjidbdc6xqu5c32s8cjg.oast.fun'</style>"] [unique_id "Z7RzAxDXyvFzChU0NgJl7wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack