๐ฎ๐ฉ
David Koswari
2026-03-02 02:02:00
(6 months ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ฎ๐ณ
liveaspankaj
2026-02-13 03:52:22
(7 months ago)
DDoS attack: 251 requests in 5m (GET / or repair.php).
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-09-18 02:13:40
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 22:13:35.822482 2025] [security2:error] [pid 5796:tid 5796] [client 77.111.247.129:22575] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||homenetserv.com|F|2"] [data ".dat.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "homenetserv.com"] [uri "/wallet.dat.backup"] [unique_id "aMtqz_d6l9JpOhYlJBfaQgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-17 18:01:42
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 14:01:35.944544 2025] [security2:error] [pid 7270:tid 7270] [client 77.111.247.129:47273] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||monteriggioni.net|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "monteriggioni.net"] [uri "/wallet.dat"] [unique_id "aMr3f0QsWGomEeMPEaHUSwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-17 02:00:07
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 16 21:59:59.722172 2025] [security2:error] [pid 31530:tid 31530] [client 77.111.247.129:52417] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||1derfulwaysrv.com|F|2"] [data ".dat.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "1derfulwaysrv.com"] [uri "/wallet.dat.backup"] [unique_id "aMoWH-dxNlfOnmBBrVyMKgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-16 06:53:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 16 02:53:48.242948 2025] [security2:error] [pid 23307:tid 23315] [client 77.111.247.129:32651] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||expozium.com|F|2"] [data ".dat.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "expozium.com"] [uri "/wallet.dat.backup"] [unique_id "aMkJfDEpD0t3YfKE-4QTcAAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-13 18:55:50
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 13 14:55:43.215338 2025] [security2:error] [pid 31102:tid 31102] [client 77.111.247.129:33451] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aikomp.net|F|2"] [data ".dat.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aikomp.net"] [uri "/foodworms.htm/wallet.dat.backup"] [unique_id "aMW-LxSQ2u6xYqiqfUATigAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BestFans.com
2025-08-07 06:56:51
(1 year ago)
Credential brute-force attacks on webpage logins
Brute-Force
๐ณ๐ฑ
MM-bot
2025-06-10 10:45:04
(1 year ago)
URL-probe: HTTP/1.1 GET request on /sites/all/modules/fckeditor/fckeditor/editor/filemanager/connect ...
show more
URL-probe: HTTP/1.1 GET request on /sites/all/modules/fckeditor/fckeditor/editor/filemanager/connectors/php/connector.php (2025-06-10 12:45:04 UTC+2)
show less
Hacking
Web App Attack
๐ซ๐ท
IRISIO
2025-06-02 08:23:04
(1 year ago)
scans/SQL injection/spam posts : 6 queries
SQL Injection
Web App Attack
Anonymous
2025-06-01 02:05:20
(1 year ago)
77.111.247.129 - - [01/Jun/2025:04:05:19 +0200] "GET /admin/fckeditor/editor/filemanager/connectors/ ...
show more
77.111.247.129 - - [01/Jun/2025:04:05:19 +0200] "GET /admin/fckeditor/editor/filemanager/connectors/php/connector.php?Command=GetFoldersAndFiles&Type=File&CurrentFolder=%2F HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
BestFans.com
2025-05-22 10:01:58
(1 year ago)
Credential brute-force attacks on webpage logins
Brute-Force
๐ซ๐ท
IRISIO
2025-05-09 07:24:29
(1 year ago)
scans/SQL injection/spam posts : 2 queries
SQL Injection
Web App Attack
๐ฏ๐ต
Valhalla
2025-05-04 16:39:44
(1 year ago)
/sites/all/libraries/fckeditor/editor/filemanager/connectors/php/connector.php?Command=GetFoldersAnd ...
show more
/sites/all/libraries/fckeditor/editor/filemanager/connectors/php/connector.php?Command=GetFoldersAndFiles&Type=File&CurrentFolder=%2F
show less
Hacking
Web App Attack
๐บ๐ธ
brantknudson.org
2025-05-04 06:10:32
(1 year ago)
Client attempted attack using request path '/admin/fckeditor/editor/filemanager/connectors/php/conne ...
show more
Client attempted attack using request path '/admin/fckeditor/editor/filemanager/connectors/php/connector.php' to honeypot.
show less
Web App Attack