๐จ๐ฆ
JuicyJ
2025-02-26 11:35:33
(1 year ago)
Excessive crawling/scraping
Web App Attack
Anonymous
2025-02-25 11:26:22
(1 year ago)
Fail2ban block
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ท
Sklurk
2025-02-25 03:12:30
(1 year ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-25 02:26:46
(1 year ago)
(mod_security) mod_security (id:217280) triggered by 72.1.169.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217280) triggered by 72.1.169.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 24 21:26:40.135787 2025] [security2:error] [pid 30806:tid 30806] [client 72.1.169.221:46187] [client 72.1.169.221] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||onerealopportunity.com|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "onerealopportunity.com"] [uri "/mailto:webmaster"] [unique_id "Z70qYLf24PNpoZEK3dcKNgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-02-24 23:02:09
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
exxos
2025-02-24 20:21:24
(1 year ago)
Traversal attacks
Hacking
๐ซ๐ฎ
000rosiu
2025-02-22 16:58:36
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 0 (-Reserved AS-)
Protoc ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 0 (-Reserved AS-)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.production.local
Timestamp: 2025-02-22T16:54:05Z
Ray ID: 91607efdcbb43126
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
ipblock.com
2025-02-22 01:40:21
(1 year ago)
IPBlock protected site ID [4055-d].
Exploit request
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-02-22 00:41:44
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 14
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-22 00:00:22
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 72.1.169.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.1.169.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 19:00:01.763477 2025] [security2:error] [pid 7819:tid 7819] [client 72.1.169.221:56529] [client 72.1.169.221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "architech.com"] [uri "/.env.www"] [unique_id "Z7kTgbQMi50IdPgcq3FlnwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-21 22:52:46
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 72.1.169.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.1.169.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 17:52:29.275057 2025] [security2:error] [pid 16839:tid 16839] [client 72.1.169.221:57393] [client 72.1.169.221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cinesonline.com"] [uri "/.env.production"] [unique_id "Z7kDranM05ood4I4ft-ZiAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-21 18:41:22
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 72.1.169.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 72.1.169.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 13:41:10.725834 2025] [security2:error] [pid 17533:tid 17533] [client 72.1.169.221:56495] [client 72.1.169.221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.env.live"] [unique_id "Z7jIxhSMRn05haHyR5n3wwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jeff Mash
2025-02-21 16:38:00
(1 year ago)
Hundreds of simultaneous connections/crawling.
Brute-Force
Web App Attack
๐ง๐ฌ
pa4080
2025-02-21 11:40:50
(1 year ago)
Detected by ModSecurity. Request URI: /wiki/Home
Hacking
Web App Attack
Anonymous
2025-02-20 18:05:01
(1 year ago)
wordpress-trap
Web App Attack