๐ฌ๐ง
CrystalMaker
2024-07-17 00:15:18
(2 years ago)
Vulnerability scan - GET /Ueditor/net/controller.ashx?action=catchimage
Hacking
๐ซ๐ท
oh.mg
2024-07-16 19:07:56
(2 years ago)
(mod_security) mod_security (id:949110) triggered by 103.127.124.27 (KR/South Korea/-): 1 in the las ...
show more
(mod_security) mod_security (id:949110) triggered by 103.127.124.27 (KR/South Korea/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Tue Jul 16 19:07:52.121666 2024] [:error] [pid 2386166:tid 140431811454720] [client 103.127.124.27:54426] [client 103.127.124.27] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "oh.mg"] [uri "/install/index.php.bak"] [unique_id "ZpbFCFzHVqxVk2ua9msecQAAAIA"], referer: https://oh.mg/install/index.php.bak?step=11&insLockfile=a&s_lang=a&install_demo_name=hktlh.php&updateHost=http:///
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2024-07-16 17:46:07
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 103.127.124.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 103.127.124.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 16 13:46:01.642477 2024] [security2:error] [pid 31753:tid 31772] [client 103.127.124.27:62332] [client 103.127.124.27] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanacademyofprojectmanagement.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanacademyofprojectmanagement.com"] [uri "/install/index.php.bak"] [unique_id "Zpax2RwtWHY_ThEa4mOxVQAAAEo"], referer: https://americanacademyofprojectmanagement.com/install/index.php.bak?step=11&insLockfile=a&s_lang=a&install_demo_name=zwkqa.php&updateHost=http:///
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-07-16 17:02:15
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐ณ๐ฟ
Tripwire
2024-06-15 22:52:26
(2 years ago)
Scanning for exploits - /Ueditor/net/controller.ashx?action=catchimage
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-15 10:30:24
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 103.127.124.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 103.127.124.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 15 06:30:16.779218 2024] [security2:error] [pid 21841] [client 103.127.124.27:61526] [client 103.127.124.27] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||engravingbyangela.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "engravingbyangela.com"] [uri "/install/index.php.bak"] [unique_id "Zm1tOBh5nXrwfmaYRWXQxQAAAA4"], referer: https://engravingbyangela.com/install/index.php.bak?step=11&insLockfile=a&s_lang=a&install_demo_name=ipzfm.php&updateHost=http:///
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2024-06-15 03:34:53
(2 years ago)
121 requests to *.php.bak
Brute-Force
Bad Web Bot
๐ฎ๐ฉ
Incidents Response Neptus Team
2024-06-12 06:12:00
(2 years ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐ซ๐ท
oh.mg
2024-06-11 21:16:59
(2 years ago)
(mod_security) mod_security (id:949110) triggered by 103.127.124.27 (KR/South Korea/-): 1 in the las ...
show more
(mod_security) mod_security (id:949110) triggered by 103.127.124.27 (KR/South Korea/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Tue Jun 11 21:16:54.815921 2024] [:error] [pid 146665:tid 139656851035904] [client 103.127.124.27:65528] [client 103.127.124.27] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "oh.mg"] [uri "/install/index.php.bak"] [unique_id "Zmi@xm6oFSWsjo5vgBuBAwAAAE4"], referer: https://oh.mg/install/index.php.bak?step=11&insLockfile=a&s_lang=a&install_demo_name=rydyp.php&updateHost=http:///
show less
Port Scan
๐ฆ๐บ
MAGIC
2024-06-05 10:05:27
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-06-04 06:19:34
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 103.127.124.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 103.127.124.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 04 02:19:28.593674 2024] [security2:error] [pid 14400] [client 103.127.124.27:59286] [client 103.127.124.27] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tomdaughertyorchestra.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tomdaughertyorchestra.com"] [uri "/install/index.php.bak"] [unique_id "Zl6x8FQr8Dpv3vcevd7piQAAABk"], referer: http://www.tomdaughertyorchestra.com/install/index.php.bak?step=11&insLockfile=a&s_lang=a&install_demo_name=yidil.php&updateHost=http:///
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Incidents Response Neptus Team
2024-06-04 02:41:00
(2 years ago)
Report Abuse IP
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-04 00:04:22
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 103.127.124.27 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 103.127.124.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 03 20:04:17.050247 2024] [security2:error] [pid 29101] [client 103.127.124.27:57378] [client 103.127.124.27] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goldengatecorgis.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goldengatecorgis.org"] [uri "/install/index.php.bak"] [unique_id "Zl5aAYTnO9FaZZLyg3xVBgAAAAM"], referer: http://goldengatecorgis.org/install/index.php.bak?step=11&insLockfile=a&s_lang=a&install_demo_name=lhkzz.php&updateHost=http:///
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
CrystalMaker
2024-06-03 19:11:59
(2 years ago)
Vulnerability scan - GET /Ueditor/net/controller.ashx?action=catchimage; GET /Ueditor/net/controller ...
show more
Vulnerability scan - GET /Ueditor/net/controller.ashx?action=catchimage; GET /Ueditor/net/controller.ashx?action=catchimage
show less
Hacking
๐ซ๐ท
oh.mg
2024-06-03 13:16:25
(2 years ago)
(mod_security) mod_security (id:949110) triggered by 103.127.124.27 (KR/South Korea/-): 1 in the las ...
show more
(mod_security) mod_security (id:949110) triggered by 103.127.124.27 (KR/South Korea/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Mon Jun 03 13:16:18.901017 2024] [:error] [pid 1420470:tid 139656960141056] [client 103.127.124.27:55616] [client 103.127.124.27] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "184"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.0.0-rc1"] [tag "anomaly-evaluation"] [hostname "oh.mg"] [uri "/install/index.php.bak"] [unique_id "Zl3CIrydFJrCnwnBFtBAlwAAAEE"], referer: https://oh.mg/install/index.php.bak?step=11&insLockfile=a&s_lang=a&install_demo_name=umsxl.php&updateHost=http:///
show less
Port Scan