๐ฏ๐ต
Valhalla
2024-12-09 15:40:15
(1 year ago)
Suspicious Activity Detected: /backups/credentials.txt
Hacking
Web App Attack
Anonymous
2024-11-27 13:15:15
(1 year ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
Anonymous
2024-11-12 12:40:01
(1 year ago)
| Suspicious URL access.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-11 20:37:46
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 11 15:37:37.338349 2024] [security2:error] [pid 7602:tid 7602] [client 64.64.123.39:26879] [client 64.64.123.39] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ccbank.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ccbank.net"] [uri "/site_name_com.sql"] [unique_id "ZzJrEZmbLF6rlQ8Ez3fDEwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-11 20:12:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 11 15:12:46.502540 2024] [security2:error] [pid 14281:tid 14281] [client 64.64.123.39:55669] [client 64.64.123.39] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crypto-stamps.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crypto-stamps.com"] [uri "/restore/mysql.sql"] [unique_id "ZzJlPhprALEO5q4UsDlovAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyuuzyou
2024-11-11 18:54:46
(1 year ago)
Intensive scraping: /web?s=%22Utah%20tattoo%20shops%22&country=bo-bo&scraper=yandex. User-Agent: Moz ...
show more
Intensive scraping: /web?s=%22Utah%20tattoo%20shops%22&country=bo-bo&scraper=yandex. User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 OPR/89.0.4447.51.
show less
Bad Web Bot
Anonymous
2024-11-05 01:23:09
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ญ
backslash
2024-11-04 05:56:14
(1 year ago)
Web Spam
Anonymous
2024-11-04 00:10:08
(1 year ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
๐ฆ๐บ
MAGIC
2024-11-03 19:05:40
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-10-29 20:18:09
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 29 16:18:04.150859 2024] [security2:error] [pid 21625:tid 21732] [client 64.64.123.39:56493] [client 64.64.123.39] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dpscsde.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dpscsde.com"] [uri "/backup/sql.sql"] [unique_id "ZyFC_MMGrAS0N_ZevytNGgAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-20 14:24:38
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 20 10:24:30.723076 2024] [security2:error] [pid 24683:tid 24683] [client 64.64.123.39:13291] [client 64.64.123.39] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asiabeef.network"] [uri "/restore/sftp-config.json"] [unique_id "ZxUSnlbiVMWBcdGtTQfJTAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-18 05:08:46
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 18 01:08:40.429912 2024] [security2:error] [pid 2671:tid 2671] [client 64.64.123.39:32905] [client 64.64.123.39] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mjkhan.com"] [uri "/old/sftp-config.json"] [unique_id "ZxHtWMEudxwfWJ-7GIqw_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-16 01:50:17
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.64.123.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 15 21:50:13.919423 2024] [security2:error] [pid 18239:tid 18239] [client 64.64.123.39:46823] [client 64.64.123.39] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pellman-world.com"] [uri "/sftp-config.json"] [unique_id "Zw8b1UwOZ-8W8Awpe4PHMwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-15 02:03:38
(1 year ago)
Account archive download attempts
Hacking
Brute-Force