|
๐ฌ๐ท
setupgr
|
|
(mod_security) mod_security (id:11000011) triggered by 34.62.66.207 (BE/Belgium/Brussels Capital/Bru ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.62.66.207 (BE/Belgium/Brussels Capital/Brussels/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Sep 09 15:01:55.048053 2026] [security2:error] [pid 235435:tid 235614] [client 34.62.66.207:62034] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 207.66.62.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "154.57.7.73"] [uri "/"] [unique_id "aqFKsnEYAYOXwbcsqCHI9wAABJg"]
show less
|
Port Scan
|
|
|
๐ฏ๐ต
VXG-NET
|
|
port=80, indicator_type=hacktool
|
Hacking
|
|
|
๐ฉ๐ช
bescared
|
|
F2B - Malicious activity detected. URL Probing. -8ff06ede-
|
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ญ
Ribeye375
|
|
HIPS nginx-anti-botnet - Block tcp/0:65535
|
Bad Web Bot
|
|
|
๐บ๐ธ
KayCee
|
|
34.62.66.207 - - [09/Sep/2026:03:11:19 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03}\xB0\x15 ...
show more
34.62.66.207 - - [09/Sep/2026:03:11:19 -0400] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03}\xB0\x15\x0E\x9A[\x18\x88A\xEE\x7F\xEE\x06P\xEE\xD3W\xB8v\xE1\xF6\xAE[E\xA8}\xB6~\xD5/O\xF3 L\xA2\x8C \x9CHUq\xF3\xFD%\xD7k\xC3\xCD\xF7\x5C\x8E@\xBAG\xC0W\x1A\xCE>\x80\x1E\x08\x83\xF3\x01\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-" "-"
34.62.66.207 - - [09/Sep/2026:03:11:24 -0400] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-" "-"
34.62.66.207 - - [09/Sep/2026:03:11:24 -0400] "A\xB3\x99\xB4\xE2t:_@\x924\xA2\x12UY\xE1_\x8C\xF1\x8Fjxd\xB7\xB0\xF8\x90/\x955\xB1\x1E\xB0\xDD\xAC\xB3\x13\xFB\x1F\x1A\x15\xBCY\xCBK\x835K\x9B\xB3\x8F!\xDF\xED|V&\xE4\x1E\xAAy\xF8\x85X" 400 150 "-" "-" "-"
34.62.66.207 - - [09/Sep/2026:03:12:03 -0400] "\x00\x1E\x91\xFC\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x07version\x04bind\x00\x00\
...
show less
|
Web App Attack
|
|
|
Anonymous
|
|
Web application attack detected.
|
Web App Attack
|
|
|
Anonymous
|
|
crawler behavior: HTTP GET on a non-existent endpoint
|
Web App Attack
|
|
|
Anonymous
|
|
34.62.66.207 - - [09/Sep/2026:08:31:35 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10 ...
show more
34.62.66.207 - - [09/Sep/2026:08:31:35 +0200] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.62.66.207 - - [09/Sep/2026:08:31:35 +0200] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xEE\xF0?\xEF\xECyF\xA7\xFF\xCE\xAA\xA4n\x18 \xC2>\xE6\x90\xFB9\xAC\xCEk\x03\x86\xB7\xBB5!" 400 150 "-" "-"
...
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ท๐บ
mysh38
|
|
fail2ban: nginx-bots jail ban
|
Web App Attack
|
|
|
๐บ๐ธ
gu-alvareza
|
|
Nmap.Script.Scanner
|
Port Scan
|
|
|
Anonymous
|
|
34.62.66.207 - - [09/Sep/2026:05:03:26 +0000] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x8F\xA2\ ...
show more
34.62.66.207 - - [09/Sep/2026:05:03:26 +0000] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\x8F\xA2\x5C\xB1\xC6\x1F+&\xCDd>H\xAD,a\x96L\xE6\x9A8\xC1\xD38\x90\x9A\xEEk\xDF:\xE8\x93\xDC @2\x09}\xC10w\xE0\xC3\xD1\xF2+\x83Cn\xD7\x1BTl\x9D\xAB\xC6\x11\xBA\x86\x96T\xEC\xB8\xEA#\xD0\x002\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "-" "-" "-"
34.62.66.207 - - [09/Sep/2026:05:03:32 +0000] ";\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\xD4\x07\x00\x00\x00\x00\x00\x00admin.$cmd\x00\x00\x00\x00\x00\xFF\xFF\xFF\xFF\x14\x00\x00\x00\x01hello\x00\x00\x00\x00\x00\x00\x00\xF0?\x00" 400 150 "-" "-" "-"
...
show less
|
Port Scan
Brute-Force
|
|
|
๐จ๐ฆ
lakered
|
|
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol ...
show more
Detectors: [NGINX, nginx_monitor] | Reasons: Nginx: Default server trap hit | Invalid HTTP protocol or SSTP scan attempt detected on sinkhole | Evidence: High-Criminality-Signature (p0f:*:64:0:*:mss*30,7:mss,sok,ts,nop,ws:df,id+:0 - Ratio:0.97), OS-Signature-Mismatch (UA:Windows/p0f:Linux) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 | TCP Fingerprint: Linux (Legacy/Embedded) (Link:generic tunnel or VPN, Uptime:33654m)
show less
|
Port Scan
Exploited Host
|
|
|
๐ซ๐ท
GoodOldTOS
|
|
Unexpected binary data sent to an endpoint
|
Hacking
Bad Web Bot
|
|
|
๐ฆ๐บ
gregoo23
|
|
34.62.66.207 - - [09/Sep/2026:13:59:26 +1000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10 ...
show more
34.62.66.207 - - [09/Sep/2026:13:59:26 +1000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
34.62.66.207 - - [09/Sep/2026:13:59:27 +1000] "\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03\xF4\xED\x7F\xD8$O\x13Nu\xFB}\xB3D\xF3\xB4\xDA\x1E\xC2\x9CvK5\xFD%\x18\xFB\xAE!?\xDA\xC2\x92 \xC9\xDC\xAF9M\xD7M\xDF8#{\x17t\x07\xF4\xBB\x7F\xA9\xDF\x1E2" 400 154 "-" "-"
34.62.66.207 - - [09/Sep/2026:13:59:28 +1000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
...
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ฌ๐ง
thetomtaylor.co.uk
|
|
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [ice02]
|
Hacking
SQL Injection
Web App Attack
|
|