|
Anonymous
|
|
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
|
Open Proxy
|
|
|
Anonymous
|
|
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
|
Open Proxy
|
|
|
Anonymous
|
|
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
|
Open Proxy
|
|
|
๐ช๐ธ
el-brujo
|
|
Proxies digitalstress[.]su used for attacking
|
DDoS Attack
|
|
|
Anonymous
|
|
Ports: *; Direction: 0; Trigger: CT_LIMIT
|
Brute-Force
SSH
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 09 17:46:00.184634 2024] [security2:error] [pid 31633] [client 89.187.162.69:54512] [client 89.187.162.69] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.solcargomiami.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.solcargomiami.com"] [uri "/"] [unique_id "Zj1EGHv5xraROUOoIKx7kwAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Excessive HTTP/HTTPS connections.
|
Bad Web Bot
|
|
|
๐จ๐ฟ
feds1337
|
|
HTTPS Flood Attack
|
DDoS Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 20 00:13:22.949834 2024] [security2:error] [pid 2900941] [client 89.187.162.69:39152] [client 89.187.162.69] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.steinrauffamilylaw.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.steinrauffamilylaw.com"] [uri "/"] [unique_id "ZiNA4koFvBmYK7O3_nexFAAAABQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ต๐ฑ
Revolut CTI
|
|
"DDoS Attack"
|
DDoS Attack
|
|
|
๐ฎ๐ธ
ISPLtd
|
|
Apr 7 10:05:13 SRC=89.187.162.69 PROTO=TCP SPT=44512 DPT=25565 SYN
Apr 7 10:05:14 SRC=89.187.162.6 ...
show more
Apr 7 10:05:13 SRC=89.187.162.69 PROTO=TCP SPT=44512 DPT=25565 SYN
Apr 7 10:05:14 SRC=89.187.162.69 PROTO=TCP SPT=44512 DPT=25565 SYN
Apr 7 10:05:14 SRC=89.187.162.69 PROTO=TCP SPT=47708 DPT=25565
...
show less
|
Port Scan
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 06 10:24:21.026784 2024] [security2:error] [pid 29306] [client 89.187.162.69:57158] [client 89.187.162.69] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.studiopilates.net|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.studiopilates.net"] [uri "/"] [unique_id "ZhFbFZuxk_lxsk2QLBoSkgAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 01 16:53:47.575494 2024] [security2:error] [pid 17941] [client 89.187.162.69:50056] [client 89.187.162.69] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||mrflatpeople.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "mrflatpeople.com"] [uri "/"] [unique_id "Zgse2x0pBICIFOts35XotgAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ช๐ธ
10dencehispahard SL
|
|
Unauthorized login attempts [ accesslogs]
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 ...
show more
(mod_security) mod_security (id:210740) triggered by 89.187.162.69 (unn-89-187-162-69.cdn77.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 29 07:32:17.668218 2024] [security2:error] [pid 15852:tid 47149951747840] [client 89.187.162.69:49186] [client 89.187.162.69] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.oldnorthwestlandco.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.oldnorthwestlandco.com"] [uri "/"] [unique_id "ZgamwZq90iKahz4wtkGD_AAAANA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|