π«π·
Murazaki
2025-09-03 22:01:47
(11 months ago)
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [03/Sep/2025:03:09:59 +0200] "CONNECT lemmy.balamb.fr:443 HTT ...
show more
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [03/Sep/2025:03:09:59 +0200] "CONNECT lemmy.balamb.fr:443 HTTP/1.1" 500 170 "-" "-" "-"
...
show less
Hacking
π«π·
Murazaki
2025-09-02 22:03:32
(11 months ago)
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [02/Sep/2025:12:48:02 +0200] "CONNECT lemmy.balamb.fr:443 HTT ...
show more
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [02/Sep/2025:12:48:02 +0200] "CONNECT lemmy.balamb.fr:443 HTTP/1.1" 500 170 "-" "-" "-"
...
show less
Hacking
π©πͺ
CommanderRoot
2025-08-30 18:33:14
(11 months ago)
Invalid HTTP request flood
DDoS Attack
Web Spam
π©πͺ
Packets-Decreaser.NET
2025-08-30 11:23:53
(11 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-06-27 09:47:39
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 05:47:32.723655 2025] [security2:error] [pid 2017980:tid 2017980] [client 2800:ba0:28:c1:64ec:15ff:fe0c:9099:2738] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ik3co.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ik3co.com"] [uri "/mailto:[email protected] "] [unique_id "aF5otKd4MUmroo46rfIxjgAAAAQ"], referer: http://ik3co.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-26 17:05:21
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 26 13:05:13.888315 2025] [security2:error] [pid 1957301:tid 1957301] [client 2800:ba0:28:c1:64ec:15ff:fe0c:9099:8526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ronniescedarinn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ronniescedarinn.com"] [uri "/mailto:[email protected] "] [unique_id "aF19yVETgu1WEFcGSninqgAAAAc"], referer: http://ronniescedarinn.com/contact_us.htm
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-24 13:12:48
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 24 09:12:41.600760 2025] [security2:error] [pid 1190066:tid 1190066] [client 2800:ba0:28:c1:64ec:15ff:fe0c:9099:33872] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thevillageartcenter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thevillageartcenter.com"] [uri "/mailto:[email protected] "] [unique_id "aFqkSQpz58iSiF9dDSKlQAAAAAI"], referer: http://thevillageartcenter.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-22 10:09:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 22 06:09:30.088951 2025] [security2:error] [pid 2374035:tid 2374035] [client 2800:ba0:28:c1:64ec:15ff:fe0c:9099:43222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rcrgalicia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rcrgalicia.com"] [uri "/mailto:[email protected] "] [unique_id "aFfWWvRuVgrSwcksfJdwjwAAAAU"], referer: http://rcrgalicia.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-21 09:01:10
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 21 05:01:05.065811 2025] [security2:error] [pid 2898953:tid 2898964] [client 2800:ba0:28:c1:64ec:15ff:fe0c:9099:36704] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adventuresdotcom.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adventuresdotcom.com"] [uri "/mailto:[email protected] "] [unique_id "aFZ00RAEA6QL3u1w_19vlQAAAEc"], referer: http://adventuresdotcom.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
elijahr
2025-06-16 03:09:31
(1 year ago)
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [15/Jun/2025:23:09:13 -0400] "CONNECT elijahr.dev:443:443 HTT ...
show more
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [15/Jun/2025:23:09:13 -0400] "CONNECT elijahr.dev:443:443 HTTP/1.1" 400 157 "-" "-"
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [15/Jun/2025:23:09:19 -0400] "CONNECT elijahr.dev:443:443 HTTP/1.1" 400 157 "-" "-"
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [15/Jun/2025:23:09:22 -0400] "CONNECT elijahr.dev:443:443 HTTP/1.1" 400 157 "-" "-"
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [15/Jun/2025:23:09:23 -0400] "CONNECT elijahr.dev:443:443 HTTP/1.1" 400 157 "-" "-"
...
show less
Brute-Force
π¨π
SOC [GOLINE SA]
2025-02-15 15:02:27
(1 year ago)
*Port Scan* detected from 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (AR/Argentina/Cordoba/-/-/[AS263812 SON ...
show more
*Port Scan* detected from 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (AR/Argentina/Cordoba/-/-/[AS263812 SONDATECH S.A.S.]). 21 hits in the last 76 seconds; IP: 2800:ba0:28:c1:64ec:15ff:fe0c:9099; Ports: *; Direction: 0; Trigger: PS_LIMIT; Logs:
show less
Brute-Force
πΈπͺ
sweplox.se
2024-08-25 05:10:35
(1 year ago)
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [10/Aug/2024:18:31:56 +0000] "GET https://cryptoforum.ovh/mem ...
show more
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [10/Aug/2024:18:31:56 +0000] "GET https://cryptoforum.ovh/member.php?action=profile HTTP/1.0" 301 162 "https://cryptoforum.ovh/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 YaBrowser/22.7.0 Yowser/2.5 Safari/537.36"
2800:ba0:28:c1:64ec:15ff:fe0c:9099 - - [25/Aug/2024:05:10:34 +0000] "GET https://cryptoforum.ovh/newthread.php?fid=70 HTTP/1.0" 301 162 "https://cryptoforum.ovh/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 YaBrowser/22.7.0 Yowser/2.5 Safari/537.36"
...
show less
Bad Web Bot
SSH
π©πͺ
CommanderRoot
2024-07-05 05:07:23
(2 years ago)
Invalid HTTP request flood
DDoS Attack
Web Spam
π©πͺ
Reinhard
2024-06-18 17:04:00
(2 years ago)
Msg from error-handling: IP-Addr: 2800:ba0:28:c1:64ec:15ff:fe0c:9099, Fehler: /wp-login.php?action=r ...
show more
Msg from error-handling: IP-Addr: 2800:ba0:28:c1:64ec:15ff:fe0c:9099, Fehler: /wp-login.php?action=register. Body: Tue, 18 Jun 2024 19:04:26 +0200, IP-Addr:2800:ba0:28:c1:64ec:15ff:fe0c:9099, Host: 2800:ba0:28:c1:64ec:15ff:fe0c:9099
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2024-03-25 03:26:15
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2800:ba0:28:c1:64ec:15ff:fe0c:9099 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 24 23:26:07.620888 2024] [security2:error] [pid 7123] [client 2800:ba0:28:c1:64ec:15ff:fe0c:9099:8870] [client 2800:ba0:28:c1:64ec:15ff:fe0c:9099] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.unigroupeu.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.unigroupeu.com"] [uri "/mailto:[email protected] "] [unique_id "ZgDuz2bkZ-dFUowtFHQ5eAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack