๐ง๐ช
beruys.com
2025-04-16 07:47:25
(1 year ago)
[Wed Apr 16 09:47:23.618125 2025] [proxy_fcgi:error] [pid 1978578:tid 140170108053056] [client 52.16 ...
show more
[Wed Apr 16 09:47:23.618125 2025] [proxy_fcgi:error] [pid 1978578:tid 140170108053056] [client 52.169.76.76:10151] AH01071: Got error 'Primary script unknown'
[Wed Apr 16 09:47:23.749183 2025] [proxy_fcgi:error] [pid 1978578:tid 140170728818240] [client 52.169.76.76:10151] AH01071: Got error 'Primary script unknown'
[Wed Apr 16 09:47:23.781526 2025] [proxy_fcgi:error] [pid 1978578:tid 140170842568256] [client 52.169.76.76:10151] AH01071: Got error 'Primary script unknown'
...
show less
DDoS Attack
SSH
๐บ๐ธ
WebpodsLLC
2025-04-16 06:17:16
(1 year ago)
(mod_security) mod_security (id:14203) triggered by 52.169.76.76 (IE/Ireland/-): 3 in the last 3600 ...
show more
(mod_security) mod_security (id:14203) triggered by 52.169.76.76 (IE/Ireland/-): 3 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: 0; Trigger: LF_MODSEC;
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
COMAITE
2025-04-16 02:25:36
(1 year ago)
Multiple web server 400 error codes from same source ip 52.169.76.76.
Web App Attack
Anonymous
2025-04-16 02:14:22
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted] 52.169.76.76 (IE/Ireland/-)
SQL Injection
๐บ๐ธ
Charlesiv
2025-04-16 00:40:45
(1 year ago)
Triggered Cloudflare WAF (botFight) from IE.
Action taken: MANAGED_CHALLENGE
ASN: 8075 (MICROSOFT-CO ...
show more
Triggered Cloudflare WAF (botFight) from IE.
Action taken: MANAGED_CHALLENGE
ASN: 8075 (MICROSOFT-CORP-MSN-AS-BLOCK)
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-includes/Requests/file.php
Timestamp: 2025-04-16T00:29:18Z
Ray ID: 930f914e888bbe4b
UA: Empty string
show less
Bad Web Bot
๐ซ๐ท
dynamix
2025-04-16 00:34:59
(1 year ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2025-04-16 00:26:57
(1 year ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2025-04-15 12:16:59
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Ha1fdan
2025-04-15 06:48:54
(1 year ago)
52.169.76.76 - - [15/Apr/2025:08:48:48 +0200] "GET /cgi-bin/fm.php HTTP/2.0" 404 36 "-" "-"
52.169.7 ...
show more
52.169.76.76 - - [15/Apr/2025:08:48:48 +0200] "GET /cgi-bin/fm.php HTTP/2.0" 404 36 "-" "-"
52.169.76.76 - - [15/Apr/2025:08:48:53 +0200] "GET /cgi-bin/1.php HTTP/2.0" 404 36 "-" "-"
52.169.76.76 - - [15/Apr/2025:08:48:53 +0200] "GET /cgi-bin/admin.php HTTP/2.0" 404 36 "-" "-"
52.169.76.76 - - [15/Apr/2025:08:48:53 +0200] "GET /cgi-bin/about.php HTTP/2.0" 404 36 "-" "-"
52.169.76.76 - - [15/Apr/2025:08:48:53 +0200] "GET /cgi-bin/xmrlpc.php HTTP/2.0" 404 36 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-04-14 22:31:52
(1 year ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
Apache
2025-04-14 16:45:19
(1 year ago)
(mod_security) mod_security (id:20000010) triggered by 52.169.76.76 (IE/Ireland/-): 5 in the last 30 ...
show more
(mod_security) mod_security (id:20000010) triggered by 52.169.76.76 (IE/Ireland/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-14 10:59:36
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 52.169.76.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 52.169.76.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 06:59:33.278859 2025] [security2:error] [pid 2373723:tid 2373723] [client 52.169.76.76:13417] [client 52.169.76.76] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||warpedweed.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "warpedweed.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z_zqlTdv5UcqUV1eMwP-SgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-14 10:25:15
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 52.169.76.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 52.169.76.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 06:25:11.135551 2025] [security2:error] [pid 15507:tid 15507] [client 52.169.76.76:5320] [client 52.169.76.76] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||medpact.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "medpact.net"] [uri "/images/stories/admin-post.php"] [unique_id "Z_zihzqKHSzbbRkoKn58XgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-14 10:09:49
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 52.169.76.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 52.169.76.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 06:09:46.723307 2025] [security2:error] [pid 3387893:tid 3387893] [client 52.169.76.76:10119] [client 52.169.76.76] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||afjm.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "afjm.org"] [uri "/images/stories/admin-post.php"] [unique_id "Z_ze6lNBLyngWakfuSHJzgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-04-14 08:05:06
(1 year ago)
Too many Status 40X (13)
Brute-Force
Web App Attack