|
๐น๐ท
neron
|
|
CrowdSec blocked: http:exploit detected via OPNsense firewall
|
Hacking
Web App Attack
|
|
|
๐ฒ๐ฝ
octageeks.com
|
|
Wordpress malicious attack:[octaflood]
|
Web App Attack
|
|
|
๐บ๐ธ
mnsf
|
|
Scanning/Probing (34)
|
Brute-Force
Web App Attack
|
|
|
๐ฆ๐บ
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|
|
Anonymous
|
|
[server.tmg.gr] httpd-suspicious-path: sites=ird2020.gr; logs=/var/log/httpd/domains/ird2020.gr.log; ...
show more
[server.tmg.gr] httpd-suspicious-path: sites=ird2020.gr; logs=/var/log/httpd/domains/ird2020.gr.log; samples=/wp-content/plugins/really-simple-ssl-pro/readme.txt | /wp-content/plugins/wp-user-avatar/readme.txt | /wp-content/plugins/woocommerce-payments/readme.txt
show less
|
Hacking
Web App Attack
|
|
|
๐จ๐ญ
backslash
|
|
|
Bad Web Bot
|
|
|
๐ฆ๐บ
RedBear IT
|
|
"DDoS against public endpoint"
|
DDoS Attack
|
|
|
๐บ๐ธ
mnsf
|
|
Scanning/Probing (11)
|
Brute-Force
Web App Attack
|
|
|
๐จ๐ฆ
SSH-Admin
|
|
Probing for Exploits
|
Exploited Host
Web App Attack
|
|
|
๐จ๐ฆ
SSH-Admin
|
|
Probing for Exploits
|
Exploited Host
Web App Attack
|
|
|
๐ฉ๐ช
hbrks
|
|
1 attack(s) detected, such as these: {"event":"dns_block","ip":"45.3.49.177","host":"kasm.life","req ...
show more
1 attack(s) detected, such as these: {"event":"dns_block","ip":"45.3.49.177","host":"kasm.life","request":"GET /.env HTTP/1.1","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36","reason":"request:malformed","timestamp":"2025-11-25T19:33:31 00:00","logentry":"kasm.life 45.3.49.177 - - [25/Nov/2025:19:33:31 0000] GET /.env HTTP/1.1 403 146 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 - matched:request:malformed"} * Report Details *: https://p4u.xyz/8G7UUIAY5H0/1* IP Details *: https://p4u.xyz/8G7UUIAY5H0/2
show less
|
Web Spam
Hacking
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.3.49.177 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:46:06.986250 2025] [security2:error] [pid 804441:tid 804441] [client 45.3.49.177:31647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pasamugo.com"] [uri "/.svn/wc.db"] [unique_id "aSU0jntiofPVcQQsVpBNZwAAAA8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.3.49.177 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:56:34.987008 2025] [security2:error] [pid 17142:tid 17142] [client 45.3.49.177:35497] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ronniescedarinn.com"] [uri "/.env"] [unique_id "aSUo8tZrmXJ0ytn08toywwAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.3.49.177 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:58:38.865248 2025] [security2:error] [pid 23728:tid 23728] [client 45.3.49.177:28779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.beirutbazar.com"] [uri "/.svn/wc.db"] [unique_id "aSUbXiWU2ttIYR2sNEZ-jgAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 45.3.49.177 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.49.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:03:25.857324 2025] [security2:error] [pid 25499:tid 25499] [client 45.3.49.177:58881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.waggonerfinancial.com"] [uri "/.svn/wc.db"] [unique_id "aSUObW_3NKs25Zfi6GEVdAAAABE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|