Anonymous
2025-02-02 22:00:00
(1 year ago)
Web Form attack / spam
Web Spam
Anonymous
2025-01-14 14:40:59
(1 year ago)
Session Crossing
Hacking
๐ฌ๐ง
AvonleaConsulting
2025-01-11 16:29:45
(1 year ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2025-01-11 13:08:33
(1 year ago)
apache-alfa-111
Web App Attack
๐ฉ๐ช
mxinfra
2025-01-11 08:16:09
(1 year ago)
Blocked by Fail2Ban (plesk-modsecurity)
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
dwmp
2025-01-11 05:32:59
(1 year ago)
[11/Jan/2025:06:32:56.541804 +0100] Z4ICiJXH5v9mZRlUDqL-DAAAAAQ 27.124.45.118 41028 38.242.227.117 7 ...
show more
[11/Jan/2025:06:32:56.541804 +0100] Z4ICiJXH5v9mZRlUDqL-DAAAAAQ 27.124.45.118 41028 38.242.227.117 7081
[11/Jan/2025:06:32:57.444048 +0100] Z4ICiZXH5v9mZRlUDqL-DgAAAAE 27.124.45.118 41032 38.242.227.117 7081
[11/Jan/2025:06:32:58.264425 +0100] Z4ICipXH5v9mZRlUDqL-DwAAABQ 27.124.45.118 41034 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-01-11 04:30:20
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 27.124.45.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 27.124.45.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 10 23:30:12.925233 2025] [security2:error] [pid 3176731:tid 3176731] [client 27.124.45.118:62745] [client 27.124.45.118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eandgenergy.com"] [uri "/.svn/entries"] [unique_id "Z4Hz1P3TL-gMln5NYNxwQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-11 02:16:30
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 27.124.45.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 27.124.45.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 10 21:16:24.202351 2025] [security2:error] [pid 32278:tid 32278] [client 27.124.45.118:62886] [client 27.124.45.118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whoownsmyhome.com"] [uri "/.svn/entries"] [unique_id "Z4HUeAWEOoYe0VhcDMTzVgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
advena
2025-01-08 07:30:56
(1 year ago)
27.124.45.118 (AS152194 CTGSERVERLIMITED-AS-AP CTG Server Limited) was intercepted at 2025-01-08T07: ...
show more
27.124.45.118 (AS152194 CTGSERVERLIMITED-AS-AP CTG Server Limited) was intercepted at 2025-01-08T07:24:58Z after violating WAF directive: 23548ee2b36547a1be09bb2c0550c529. Pre-cautionary/corrective action applied: block.
show less
Web Spam
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
XICTRON
2025-01-08 01:00:04
(1 year ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-01-07 20:45:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 27.124.45.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 27.124.45.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 07 15:45:49.272826 2025] [security2:error] [pid 3276572:tid 3276572] [client 27.124.45.118:65195] [client 27.124.45.118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ibken.com"] [uri "/.svn/entries"] [unique_id "Z32SfQT3xqGRuw9BOcwfmgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
smallbottle
2025-01-07 15:37:08
(1 year ago)
The IP has triggered Cloudflare WAF. action: block source: firewallCustom clientAsn: 152194 clientAS ...
show more
The IP has triggered Cloudflare WAF. action: block source: firewallCustom clientAsn: 152194 clientASNDescription: CTGSERVERLIMITED-AS-AP CTG Server Limited clientCountryName: US clientIP: 27.124.45.118 clientRequestHTTPMethodName: GET clientRequestHTTPProtocol: HTTP/1.1 clientRequestPath: /.git/config clientRequestQuery: datetime: 2025-01-07T06:41:47Z rayName: 8fe1f6cdd8ca85ed ruleId: 6dca9ba97f7549f780347124a866d733 userAgent: Go-http-client/1.1. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Web Spam
Bad Web Bot
๐ญ๐ฐ
mutebot.net
2025-01-07 15:23:39
(1 year ago)
Tried access sensitive path:
/.git/config
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-01-07 15:10:10
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 27.124.45.118 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 27.124.45.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 07 10:10:03.730151 2025] [security2:error] [pid 8577:tid 8584] [client 27.124.45.118:59190] [client 27.124.45.118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maritimeclinic.net"] [uri "/.svn/entries"] [unique_id "Z31Dy7pmptaP1akN77dHNgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mxinfra
2025-01-07 08:48:11
(1 year ago)
Blocked by Fail2Ban (plesk-modsecurity)
Hacking
Brute-Force
Web App Attack