๐บ๐ธ
TPI-Abuse
2025-09-11 11:24:44
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 45.202.79.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.202.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 07:24:40.793706 2025] [security2:error] [pid 17830:tid 17830] [client 45.202.79.238:40373] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.club.ic1.biz|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.club.ic1.biz"] [uri "/s3cmd.ini"] [unique_id "aMKxeCM1-Q46baPn9D3uNwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2025-09-09 18:03:12
(10 months ago)
(From [email protected] ) Dear Sales Team,
Iโm Ken Forbes, owner of Unbox Dealsi. Iโm in ...
show more
(From [email protected] ) Dear Sales Team,
Iโm Ken Forbes, owner of Unbox Dealsi. Iโm interested in sourcing products from your company for shipment to our office in the El Savador.
Before moving forward, could you please confirm:
Do you accept U.S. MasterCard or Visa payments?
Are you able to work with our shipping partner for product pickup and logistics?
Looking forward to your response.
Best regards,
Ken Forbes
Owner, Unbox Deals
show less
Phishing
Web Spam
๐บ๐ธ
nowyouknow
2025-09-08 03:05:40
(10 months ago)
(From [email protected] ) Dear Sales Team,
My name is Ken Forbes, and Iโm the owner of U ...
show more
(From [email protected] ) Dear Sales Team,
My name is Ken Forbes, and Iโm the owner of Unbox Deals, based in Dubai. Weโre currently looking to source products from reliable suppliers and are interested in establishing a partnership with your company.
Before proceeding, Iโd appreciate it if you could confirm the following:
Do you accept U.S.-issued MasterCard or Visa for payments?
Would you be able to coordinate with our designated shipping partner for product pickup and logistics?
I look forward to your response and hope we can explore a potential collaboration.
Best regards,
Ken Forbes
Owner, Unbox Deals
show less
Phishing
Web Spam
๐บ๐ธ
TPI-Abuse
2025-09-06 23:40:37
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.202.79.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.202.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 19:40:29.311242 2025] [security2:error] [pid 25089:tid 25089] [client 45.202.79.238:39439] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.beambags.us.book-arts.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aLzGbVXRZ4txKMJssI3kBwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 18:32:47
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 45.202.79.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.202.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 14:32:44.040667 2025] [security2:error] [pid 2936:tid 2936] [client 45.202.79.238:29917] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bernard.gonzalez.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bernard.gonzalez.com"] [uri "/s3cmd.ini"] [unique_id "aLx-TIZRtTZc64nPsbESHgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Netrix
2025-06-18 16:32:00
(1 year ago)
L7 Flood botnet hosted by 3xK Tech
DDoS Attack
Web Spam
SSH
Anonymous
2025-06-18 09:15:41
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Packets-Decreaser.NET
2025-05-04 16:05:22
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฌ๐ง
uira.live
2025-05-04 15:54:47
(1 year ago)
Malicious activity detected from 200373 DREI-K-TECH-GMBH towards host uira.live (GET HTTP/2) @ 2025- ...
show more
Malicious activity detected from 200373 DREI-K-TECH-GMBH towards host uira.live (GET HTTP/2) @ 2025-05-04T15:54:47Z (1 occurrences)
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-01-20 10:44:33
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.202.79.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.202.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 20 05:44:28.712548 2025] [security2:error] [pid 12444:tid 12444] [client 45.202.79.238:35771] [client 45.202.79.238] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cottrillcyclodyne.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cottrillcyclodyne.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z44pDFWhW-1SirdInFZZqgAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-14 20:08:59
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ซ๐ท
Jean Valjean
2025-01-06 19:30:18
(1 year ago)
Fail2ban Caboom : wp-login.php Bruteforce
Brute-Force
Web App Attack
๐ฉ๐ช
qli.de
2025-01-04 15:33:34
(1 year ago)
45.202.79.238 - - [30/Dec/2024:16:02:33 +0100] "POST /xmlrpc.php HTTP/1.1" 200 346 "-" "Apache-HttpC ...
show more
45.202.79.238 - - [30/Dec/2024:16:02:33 +0100] "POST /xmlrpc.php HTTP/1.1" 200 346 "-" "Apache-HttpClient/4.5.13 (Java/11.0.25)"
45.202.79.238 - - [30/Dec/2024:16:02:38 +0100] "POST /wp-login.php HTTP/1.1" 200 7608 "https://www.qli.de/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Hacking
Anonymous
2024-12-31 15:06:33
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
qli.de
2024-12-30 15:02:39
(1 year ago)
45.202.79.238 - - [30/Dec/2024:16:02:33 +0100] "POST /xmlrpc.php HTTP/1.1" 200 346 "-" "Apache-HttpC ...
show more
45.202.79.238 - - [30/Dec/2024:16:02:33 +0100] "POST /xmlrpc.php HTTP/1.1" 200 346 "-" "Apache-HttpClient/4.5.13 (Java/11.0.25)"
45.202.79.238 - - [30/Dec/2024:16:02:38 +0100] "POST /wp-login.php HTTP/1.1" 200 7608 "https://www.qli.de/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Hacking