Anonymous
2024-12-16 09:10:09
(1 year ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
Anonymous
2024-12-13 09:05:11
(1 year ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
π¦πΊ
MAGIC
2024-12-08 03:04:15
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-12-08 03:01:48
(1 year ago)
(mod_security) mod_security (id:217280) triggered by 64.64.123.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217280) triggered by 64.64.123.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 07 22:01:44.463184 2024] [security2:error] [pid 27512:tid 27512] [client 64.64.123.54:39443] [client 64.64.123.54] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||www.kreweofblackbeardsrevenge.com|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kreweofblackbeardsrevenge.com"] [uri "/contact_us.html"] [unique_id "Z1UMGOAK6NiMmiiYWTlZWQAAAAA"], referer: https://www.kreweofblackbeardsrevenge.com/contact_us.html
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
oncord
2024-12-08 02:43:43
(1 year ago)
Form spam
Web Spam
Anonymous
2024-11-28 22:50:09
(1 year ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
π©πͺ
netclix.gr
2024-11-27 21:04:43
(1 year ago)
(CT) IP 64.64.123.54 (GB/United Kingdom/England/London/-) found to have 14 connections; Ports: *; Di ...
show more
(CT) IP 64.64.123.54 (GB/United Kingdom/England/London/-) found to have 14 connections; Ports: *; Direction: inout; Trigger: CT_LIMIT; Logs: tcp: 64.64.123.54:6205 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:34213 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:36321 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:57849 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:15455 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:33431 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:1793 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:55009 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:5073 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:56367 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:23057 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:1685 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:46315 -> 148.251.44.120:443 (TIME_WAIT)
tcp: 64.64.123.54:2085 -> 148.251.44.120:443 (TIME_WAIT)
show less
Port Scan
Anonymous
2024-11-25 22:50:08
(1 year ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking
π¦πͺ
abusiveIntelligence
2024-11-23 02:00:00
(1 year ago)
RDP Local Account Slowly Brute-force Attempt
Brute-Force
π¦πͺ
abusiveIntelligence
2024-11-22 15:00:00
(1 year ago)
RDP Local Account Slowly Brute-force Attempt
Brute-Force
π¦πΉ
CTK
2024-11-22 14:47:23
(1 year ago)
Customer Site (Grieskirchen FP)
Brute-Force
πΊπΈ
TPI-Abuse
2024-11-21 21:34:26
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.64.123.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 21 16:34:21.850229 2024] [security2:error] [pid 1548:tid 1548] [client 64.64.123.54:8939] [client 64.64.123.54] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ciptaconindotara.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ciptaconindotara.com"] [uri "/restore/www.sql"] [unique_id "Zz-nXVsaB-npUyNpjrFrwgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
guillaume illien
2024-11-11 13:45:03
(1 year ago)
64.64.123.54 - - [11/Nov/2024:13:45:00 +0000] "HEAD /backups/index.zip HTTP/1.1" 301 0 "-" "-"
64.64 ...
show more
64.64.123.54 - - [11/Nov/2024:13:45:00 +0000] "HEAD /backups/index.zip HTTP/1.1" 301 0 "-" "-"
64.64.123.54 - - [11/Nov/2024:13:45:01 +0000] "HEAD /backups/sql.sql HTTP/1.1" 301 0 "-" "-"
64.64.123.54 - - [11/Nov/2024:13:45:01 +0000] "HEAD /restore/public_html.zip HTTP/1.1" 301 0 "-" "-"
64.64.123.54 - - [11/Nov/2024:13:45:02 +0000] "HEAD /back/www.sql HTTP/1.1" 301 0 "-" "-"
64.64.123.54 - - [11/Nov/2024:13:45:02 +0000] "HEAD /backup/public_html.zip HTTP/1.1" 301 0 "-" "-"
64.64.123.54 - - [11/Nov/2024:13:45:02 +0000] "HEAD /restore/bak.tar.gz HTTP/1.1" 301 0 "-" "-"
64.64.123.54 - - [11/Nov/2024:13:45:03 +0000] "HEAD /bak/application.zip HTTP/1.1" 301 0 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
πΊπΈ
TPI-Abuse
2024-11-08 22:46:02
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.64.123.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 08 17:45:57.347109 2024] [security2:error] [pid 17052:tid 17052] [client 64.64.123.54:34383] [client 64.64.123.54] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barnesandbrower.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barnesandbrower.com"] [uri "/backup/wallet.dat"] [unique_id "Zy6UpbEJ4lXfhr4MVBlidgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-08 13:05:09
(1 year ago)
Unauthorized connection attempt detected in the last 24 hours
Hacking