๐ฎ๐ณ
Altis Shield
2025-12-01 04:05:35
(7 months ago)
GET /phpmyadmin/ HTTP/1.1" 403 - "Nikto/2.1.6"
Web Spam
Port Scan
Hacking
Anonymous
2025-03-23 19:48:19
(1 year ago)
$f2bV_matches
Brute-Force
๐ซ๐ฎ
oh.mg
2025-03-21 09:24:09
(1 year ago)
[Fri Mar 21 10:24:08.989623 2025] [security2:error] [pid 1757949:tid 1757963] [client 41.216.188.168 ...
show more
[Fri Mar 21 10:24:08.989623 2025] [security2:error] [pid 1757949:tid 1757963] [client 41.216.188.168:0] [client 41.216.188.168] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mrman.net"] [uri "/siteheads.php"] [unique_id "Z90wOOXNBty2ZGaAyAV7JwAAAMc"], referer: www.google.com
[Fri Mar 21 10:24:09.557138 2025] [security2:error] [pid 1757949:tid 1757975] [client 41.216.188.168:0] [client 41.216.188.168] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWA
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-03-21 03:26:11
(1 year ago)
[Fri Mar 21 04:25:52.907056 2025] [proxy_fcgi:error] [pid 3327606:tid 3328853] [client 41.216.188.16 ...
show more
[Fri Mar 21 04:25:52.907056 2025] [proxy_fcgi:error] [pid 3327606:tid 3328853] [client 41.216.188.168:56106] AH01071: Got error 'Primary script unknown', referer: www.google.com
[Fri Mar 21 04:26:10.209895 2025] [proxy_fcgi:error] [pid 3327602:tid 3328784] [client 41.216.188.168:51564] AH01071: Got error 'Primary script unknown', referer: www.google.com
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-03-21 02:51:36
(1 year ago)
Cloudflare WAF: Request Path: //hplfuns.php Request Query: Host: ns2.elhacker.net userAgent: Mozlil ...
show more
Cloudflare WAF: Request Path: //hplfuns.php Request Query: Host: ns2.elhacker.net userAgent: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 Action: block Source: firewallManaged ASN Description: PRIVATEHOSTING-NET Country: DE Method: GET Timestamp: 2025-03-21T02:51:36Z ruleId: 0242110ae62e44028a13bf4834780914. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2025-03-21 02:22:44
(1 year ago)
41.216.188.168 (DE/Germany/-), more than 20 Apache 403 hits
Hacking
๐ฉ๐ช
/dev/null
2025-03-21 01:35:57
(1 year ago)
CMS Bruteforce / WebApp Attack attempt
Hacking
Web App Attack
๐บ๐ธ
Epimetheus
2025-03-20 14:12:45
(1 year ago)
Unauthorized access attempts:
From:
41.216.188.168
Method:
HTTP GET
URI Path:
//classfuns.php
...
show more
Unauthorized access attempts:
From:
41.216.188.168
Method:
HTTP GET
URI Path:
//classfuns.php
UA:
"Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
show less
Web App Attack
๐ณ๐ฑ
CryptoYakari
2025-03-20 05:02:14
(1 year ago)
41.216.188.168 - - [20/Mar/2025:08:00:21 +0300] "GET /siteheads.php HTTP/1.0" 404 28865 "www.google. ...
show more
41.216.188.168 - - [20/Mar/2025:08:00:21 +0300] "GET /siteheads.php HTTP/1.0" 404 28865 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
41.216.188.168 - - [20/Mar/2025:08:00:35 +0300] "GET /wp-content/siteheads.php HTTP/1.0" 404 28962 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
41.216.188.168 - - [20/Mar/2025:08:01:00 +0300] "GET /ajax/siteheads.php HTTP/1.0" 404 28902 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
41.216.188.168 - - [20/Mar/2025:08:01:40 +0300] "GET /assets/images/siteheads.php HTTP/1.0" 404 28985 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTM
...
show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
botreporter
2025-03-20 00:29:54
(1 year ago)
CMS vulnerability/installation scanning
Brute-Force
Web App Attack
Anonymous
2025-03-19 21:35:59
(1 year ago)
Automated report (2025-03-19T21:35:59+00:00). User agent cited by various attack tools, rootkits, ba ...
show more
Automated report (2025-03-19T21:35:59+00:00). User agent cited by various attack tools, rootkits, backdoors, webshells, and malware detected.
show less
Open Proxy
Hacking
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
niceshops.com
2025-03-19 18:01:19
(1 year ago)
Web Attack (19/Mar/2025:18:51:13.108", "frontend": "frontend_disco", "backend": "frontend_disco", "b ...
show more
Web Attack (19/Mar/2025:18:51:13.108", "frontend": "frontend_disco", "backend": "frontend_disco", "backend_server": "<NOSRV>", "time_request": 0, "time_wait": -1, "time_connect": -1, "time_response": -1, "time_active": 0, "status": 301, "bytes_read": 163, "termination_state": "LR--", "actconn": 153, "feconn": 152, "beconn": 0, "srv_conn": 0, "retries": 0, "srv_queue": 0, "backend_queue": 0, "capture_request": "{|||||||||||||||||||||||}", "capture_response GET //wp-content/siteheads.php)
show less
Web App Attack
๐ซ๐ฎ
oh.mg
2025-03-19 15:37:34
(1 year ago)
[Wed Mar 19 16:37:20.953003 2025] [security2:error] [pid 2295888:tid 2295896] [client 41.216.188.168 ...
show more
[Wed Mar 19 16:37:20.953003 2025] [security2:error] [pid 2295888:tid 2295896] [client 41.216.188.168:63918] [client 41.216.188.168] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.mmn.name"] [uri "/siteheads.php"] [unique_id "Z9rksJz4bp4uqnJCheF9BAAAAMY"], referer: www.google.com
[Wed Mar 19 16:37:33.842485 2025] [security2:error] [pid 2295888:tid 2295913] [client 41.216.188.168:59123] [client 41.216.188.168] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2025-03-19 10:01:05
(1 year ago)
(mod_security) mod_security (id:980001) triggered by 41.216.188.168 (DE/Germany/-): 5 in the last 36 ...
show more
(mod_security) mod_security (id:980001) triggered by 41.216.188.168 (DE/Germany/-): 5 in the last 3600 secs; ID: Dan
show less
Brute-Force
Bad Web Bot
๐ฆ๐บ
MAGIC
2025-03-19 08:00:32
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot