|
๐ฉ๐ช
EGP Abuse Dept
|
|
Scanning for web/db/file exploits on tpc-001.mach3builders.nl
|
SQL Injection
Bad Web Bot
Web App Attack
|
|
|
๐ง๐ฌ
Stoyko Stoykov
|
|
38.154.194.186 - - [18/Mar/2026:04:46:14 +0200] "GET /dashboard/phpinfo.php HTTP/1.1" 301 162 "-" "M ...
show more
38.154.194.186 - - [18/Mar/2026:04:46:14 +0200] "GET /dashboard/phpinfo.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36"
...
show less
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 38.154.194.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 38.154.194.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 04:11:13.934923 2026] [security2:error] [pid 26837:tid 26837] [client 38.154.194.186:53167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nbcnewsradio.com"] [uri "/_.htaccess"] [unique_id "aWoAsZYEGrmzy7VYR-ODaQAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 38.154.194.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 38.154.194.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 19:20:23.064652 2025] [security2:error] [pid 13416:tid 13416] [client 38.154.194.186:35215] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.farmers123.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.farmers123.com"] [uri "/mail.db"] [unique_id "aS-CR_JP1PJ_v2t-TzPZkAAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
| Common web attack.
|
Hacking
SQL Injection
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 38.154.194.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 38.154.194.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 05:57:29.762774 2025] [security2:error] [pid 4219:tid 4219] [client 38.154.194.186:45455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.com"] [uri "/.env.stage"] [unique_id "aRRoGRfdBjf3kiYEZQYxGwAAABo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 38.154.194.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 38.154.194.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 11:00:25.763085 2025] [security2:error] [pid 27531:tid 27535] [client 38.154.194.186:54019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aQYgiX2WO2IkxYJ6zsIQNAAAAQI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฌ๐ง
Bytemark
|
|
38.154.194.186 - - [03/Feb/2024:13:30:36 +0000] "GET /course/access-to-he-diploma/ HTTP/1.1" 301 737 ...
show more
38.154.194.186 - - [03/Feb/2024:13:30:36 +0000] "GET /course/access-to-he-diploma/ HTTP/1.1" 301 7372 "-" "python-requests/2.31.0"
show less
|
Brute-Force
Web App Attack
|
|