๐ซ๐ท
geot
2025-04-12 15:29:04
(1 year ago)
POST / HTTP/1.1
GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
GET /.env HTTP/1.1
Port Scan
Hacking
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2025-04-11 15:36:30
(1 year ago)
2025-04-11 @ 17:36:29 (CET) ~ Blocked for trying to access: /vendor/phpunit/phpunit/src/Util/PHP/eva ...
show more
2025-04-11 @ 17:36:29 (CET) ~ Blocked for trying to access: /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
show less
Web App Attack
๐ฌ๐ง
www.elivecd.org
2025-04-11 15:36:26
(1 year ago)
2025/04/11 16:36:25 [error] 3039157#3039157: *20643 FastCGI sent in stderr: "; PHP message: BOT WARN ...
show more
2025/04/11 16:36:25 [error] 3039157#3039157: *20643 FastCGI sent in stderr: "; PHP message: BOT WARNING: visitor used the honeypot: 45.153.231.119, you should ban it for long time (honeypot form function-abuseipdb)" while reading response header from upstream, client: 45.153.231.119, server: www.elivecd.org, request: "POST / HTTP/1.1", upstream: "fastcgi://unix:/run/php/php8.2-fpm-elivewp.sock:", host: "78.141.243.157"
...
show less
Web Spam
Email Spam
๐ฉ๐ช
ut-addicted.com
2025-04-11 14:45:33
(1 year ago)
\[Fri Apr 11 16:45:31.825199 2025\] \[:error\] \[pid 11062:tid 140571974764288\] \[client 45.153.231 ...
show more
\[Fri Apr 11 16:45:31.825199 2025\] \[:error\] \[pid 11062:tid 140571974764288\] \[client 45.153.231.119:51405\] \[client 45.153.231.119\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 8\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "78.46.187.162"\] \[uri "/.env"\] \[unique_id "Z-krC8jVzmb27U0Hs8TTvAAAANE"\]
show less
Brute-Force
Web App Attack
๐ซ๐ท
jk jk
2025-04-11 13:36:09
(1 year ago)
GoPot Honeypot 1
Hacking
Web App Attack
๐ซ๐ฎ
kumiko
2025-04-11 13:20:36
(1 year ago)
[2025-04-11 13:20:36] Probing for dotfiles
"GET /.env HTTP/1.1" 403
Bad Web Bot
Web App Attack
๐ฉ๐ช
ut-addicted.com
2025-04-11 12:52:54
(1 year ago)
\[11/Apr/2025:14:52:50 +0200\] Z-kQosjVzmb27U0Hs8TQPgAAANE 45.153.231.119 55402 78.46.187.162 80
\[1 ...
show more
\[11/Apr/2025:14:52:50 +0200\] Z-kQosjVzmb27U0Hs8TQPgAAANE 45.153.231.119 55402 78.46.187.162 80
\[11/Apr/2025:14:52:52 +0200\] Z-kQoz0ZiqAKzjGBZxhpxwAAAJY 45.153.231.119 55429 78.46.187.162 80
\[11/Apr/2025:14:52:53 +0200\] Z-kQpcjVzmb27U0Hs8TQPwAAAMY 45.153.231.119 55475 78.46.187.162 443
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ut-addicted.com
2025-04-11 10:11:44
(1 year ago)
\[Fri Apr 11 12:11:42.008376 2025\] \[:error\] \[pid 11062:tid 140572006233856\] \[client 45.153.231 ...
show more
\[Fri Apr 11 12:11:42.008376 2025\] \[:error\] \[pid 11062:tid 140572006233856\] \[client 45.153.231.119:62932\] \[client 45.153.231.119\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 8\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "78.46.187.162"\] \[uri "/.env"\] \[unique_id "Z-jq3sjVzmb27U0Hs8TJlwAAAM4"\]
show less
Brute-Force
Web App Attack
๐ฌ๐ง
Shadymint
2025-04-11 08:30:01
(1 year ago)
url probing from IP marked as abusive
Web App Attack
๐ซ๐ฎ
oh.mg
2025-04-11 06:15:29
(1 year ago)
[Fri Apr 11 08:15:26.755007 2025] [security2:error] [pid 3769612:tid 3769624] [client 45.153.231.119 ...
show more
[Fri Apr 11 08:15:26.755007 2025] [security2:error] [pid 3769612:tid 3769624] [client 45.153.231.119:57008] [client 45.153.231.119] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "95.216.72.247"] [uri "/.env"] [unique_id "Z_izfpvufT0W6MTRfUYPzgAAAAg"]
[Fri Apr 11 08:15:28.420367 2025] [security2:error] [pid 2998314:tid 2998337] [client 45.153.231.119:57044] [client 45.153.231.119] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [t
...
show less
Bad Web Bot
Web App Attack
๐ช๐น
Bete
2025-03-14 05:36:00
(1 year ago)
This IP address was observed engaging in malicious web-based activity, as evidenced by access logs. ...
show more
This IP address was observed engaging in malicious web-based activity, as evidenced by access logs. The behavior included repeated attempts to exploit vulnerabilities, like unauthorized access attempts to sensitive endpoints.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-13 15:56:06
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.153.231.119 (vm1243106.stark-industries.solu ...
show more
(mod_security) mod_security (id:210492) triggered by 45.153.231.119 (vm1243106.stark-industries.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 13 11:55:59.846522 2025] [security2:error] [pid 24534:tid 24534] [client 45.153.231.119:56299] [client 45.153.231.119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.117"] [uri "/.env"] [unique_id "Z9MAD9GYj88IJI2h-jbC7gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-13 15:36:24
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.153.231.119 (vm1243106.stark-industries.solu ...
show more
(mod_security) mod_security (id:210492) triggered by 45.153.231.119 (vm1243106.stark-industries.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 13 11:36:19.275424 2025] [security2:error] [pid 10529:tid 10529] [client 45.153.231.119:60737] [client 45.153.231.119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.193"] [uri "/.env"] [unique_id "Z9L7c5t_DlsyNJDa2AXuHgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-13 15:17:01
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.153.231.119 (vm1243106.stark-industries.solu ...
show more
(mod_security) mod_security (id:210492) triggered by 45.153.231.119 (vm1243106.stark-industries.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 13 11:16:58.395367 2025] [security2:error] [pid 2664054:tid 2664054] [client 45.153.231.119:61257] [client 45.153.231.119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.102"] [uri "/.env"] [unique_id "Z9L26ltiU60XmURfs_J0BQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-13 14:53:47
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.153.231.119 (vm1243106.stark-industries.solu ...
show more
(mod_security) mod_security (id:210492) triggered by 45.153.231.119 (vm1243106.stark-industries.solutions): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 13 10:53:42.520548 2025] [security2:error] [pid 25380:tid 25511] [client 45.153.231.119:65289] [client 45.153.231.119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.81"] [uri "/.env"] [unique_id "Z9LxdmlW5NeerZCNo6JL7AAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack