๐บ๐ธ
ruusvuu
2026-09-01 01:30:44
(13 hours ago)
Automated abuse report: 15 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /i ...
show more
Automated abuse report: 15 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /index.php/index/install, /sftp-config.json, /wp-json/mcp/v1, /cgi-bin/cgibox, /Setup/index.php/.
Sample log lines:
[review-snippet] [2026-08-31 18:30:39 MST] 4.227.154.219 GET /settings.py 404 - 1.825 ms
[review-snippet] [2026-08-31 18:30:39 MST] 4.227.154.219 GET /settings.py 404 - 1.825 ms
[review-snippet] [2026-08-31 18:30:43 MST] 4.227.154.219 GET /app/settings.py 404 - 1.540 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-08-31 18:14:17
(20 hours ago)
2026/08/31 20:14:12 [error] 3235147#3235147: *543350 open() "/home/user-data/www/default/cgi-bin/cgi ...
show more
2026/08/31 20:14:12 [error] 3235147#3235147: *543350 open() "/home/user-data/www/default/cgi-bin/cgibox" failed (2: No such file or directory), client: 4.227.154.219, server: box.ledemon.us, request: "GET /cgi-bin/cgibox?.cab HTTP/1.1", host: "box.ledemon.us"
2026/08/31 20:14:16 [error] 3235147#3235147: *543350 open() "/home/user-data/www/default/cgi-bin/cgibox" failed (2: No such file or directory), client: 4.227.154.219, server: box.ledemon.us, request: "GET /cgi-bin/cgibox?/nobody HTTP/1.1", host: "box.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐บ๐ธ
ruusvuu
2026-08-30 22:23:10
(1 day ago)
Automated abuse report: 15 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /w ...
show more
Automated abuse report: 15 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /wp-json/wp/v2/eablocks/ea_appointments/, /site_cg/application/configs/application.ini, /config.json, /app.config.json, /src/config.json.
Sample log lines:
[review-snippet] [2026-08-30 15:23:09 MST] 4.227.154.219 GET /wp-config.php.orig 404 - 6.210 ms
[review-snippet] [2026-08-30 15:23:09 MST] 4.227.154.219 GET /wp-config.php.dist 404 - 5.430 ms
[review-snippet] [2026-08-30 15:23:09 MST] 4.227.154.219 GET /wp-config.php.SAVE 404 - 3.888 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐บ๐ธ
ruusvuu
2026-08-30 07:54:28
(2 days ago)
Automated abuse report: 25 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /w ...
show more
Automated abuse report: 25 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /wp-json/wp/v2/eablocks/ea_appointments/, /site_cg/application/configs/application.ini, /config.json, /app.config.json, /src/config.json.
Sample log lines:
[review-snippet] [2026-08-30 00:54:26 MST] 4.227.154.219 GET /bbo-rest/heapdump 404 - 8.055 ms
[review-snippet] [2026-08-30 00:54:26 MST] 4.227.154.219 GET /bbo-token/heapdump 404 - 5.065 ms
[review-snippet] [2026-08-30 00:54:26 MST] 4.227.154.219 GET /bbo-vin/heapdump 404 - 5.218 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐บ๐ธ
pixelmemory.us
2026-08-29 19:09:14
(2 days ago)
2026-08-29T19:01:36 4.227.154.219 GET /cgi-bin/DownloadCfg/RouterCfm.jpg Mozilla/5.0 (Kubuntu; Linux ...
show more
2026-08-29T19:01:36 4.227.154.219 GET /cgi-bin/DownloadCfg/RouterCfm.jpg Mozilla/5.0 (Kubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
...
show less
Bad Web Bot
๐บ๐ธ
ruusvuu
2026-08-29 19:04:34
(2 days ago)
Automated abuse report: 69 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /w ...
show more
Automated abuse report: 69 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /wp-json/wp/v2/eablocks/ea_appointments/, /site_cg/application/configs/application.ini, /config.json, /app.config.json, /src/config.json.
Sample log lines:
[review-snippet] [2026-08-29 04:29:52 MST] 4.227.154.219 GET /id_rsa_3072 404 - 7.273 ms
[review-snippet] [2026-08-29 04:29:52 MST] 4.227.154.219 GET /id_rsa_1024 404 - 12.444 ms
[review-snippet] [2026-08-29 12:04:33 MST] 4.227.154.219 GET /cgi-bin/DownloadCfg/RouterCfm.jpg 404 - 2.523 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐บ๐ธ
ruusvuu
2026-08-29 09:16:22
(3 days ago)
Automated abuse report: 25 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /w ...
show more
Automated abuse report: 25 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /wp-json/wp/v2/eablocks/ea_appointments/, /site_cg/application/configs/application.ini, /config.json, /app.config.json, /src/config.json.
Sample log lines:
[review-snippet] [2026-08-29 02:16:21 MST] 4.227.154.219 GET /assets/config.json 404 - 8.373 ms
[review-snippet] [2026-08-29 02:16:21 MST] 4.227.154.219 GET /app/config.json 404 - 8.612 ms
[review-snippet] [2026-08-29 02:16:21 MST] 4.227.154.219 GET /config/development.json 404 - 4.189 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐บ๐ธ
ruusvuu
2026-08-29 01:29:15
(3 days ago)
Automated abuse report: 25 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /w ...
show more
Automated abuse report: 25 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /wp-json/wp/v2/eablocks/ea_appointments/, /site_cg/application/configs/application.ini.
Sample log lines:
[review-snippet] [2026-08-27 23:41:33 MST] 4.227.154.219 GET /wp-json/wp/v2/eablocks/ea_appointments/ 404 - 2.699 ms
[review-snippet] [2026-08-27 23:41:33 MST] 4.227.154.219 GET /wp-json/wp/v2/eablocks/ea_appointments/ 404 - 2.699 ms
[review-snippet] [2026-08-28 18:29:13 MST] 4.227.154.219 GET /site_cg/application/configs/application.ini 404 - 17.104 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐บ๐ธ
ruusvuu
2026-08-27 20:10:13
(4 days ago)
Automated abuse report: 25 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /w ...
show more
Automated abuse report: 25 attack/probe requests from Microsoft Corporation / US.
Targeted paths: /wp-json/omapp/v1/support, /dav/server.php/files/personal/%2e%2e/%2e%2e//%2e%2e//%2e%2e/data/settings/settiโฆ, /cgi-bin/cgiServer.exx, /ws/km-wsdl/setting/address_book.
Sample log lines:
[review-snippet] [2026-08-27 13:10:11 MST] 4.227.154.219 GET /cgi-bin/cgiServer.exx?download=/etc/passwd 404 - 7.366 ms
[review-snippet] [2026-08-27 13:10:12 MST] 4.227.154.219 POST /ws/km-wsdl/setting/address_book 404 - 4.497 ms
[review-snippet] [2026-08-27 13:10:11 MST] 4.227.154.219 GET /cgi-bin/cgiServer.exx?download=/etc/passwd 404 - 7.366 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 19:40:11
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 4.227.154.219 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 4.227.154.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:40:06.424183 2026] [security2:error] [pid 25571:tid 25571] [client 4.227.154.219:47490] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||netguard.us|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "netguard.us"] [uri "/backupsettings.dat"] [unique_id "apCSlo6vSztpm9OU4b4kQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CBJ
2026-08-27 18:56:36
(4 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:13:26
(4 days ago)
(mod_security) mod_security (id:211190) triggered by 4.227.154.219 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 4.227.154.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:13:18.388751 2026] [security2:error] [pid 23921:tid 24065] [client 4.227.154.219:36166] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||aafmla.aafm.us|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /cgi-bin/cgiServer.exx?download=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafmla.aafm.us"] [uri "/cgi-bin/cgiServer.exx"] [unique_id "apBwLibNpIAoKLk2P_a_sgAAAhg"]
show less
Brute-Force
Bad Web Bot
Web App Attack