๐บ๐ธ
mnsf
2025-08-29 03:05:15
(11 months ago)
Too many Status 40X (11)
Too many Status 50X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-28 15:23:39
(11 months ago)
(mod_security) mod_security (id:243930) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com ...
show more
(mod_security) mod_security (id:243930) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 28 11:23:35.217768 2025] [security2:error] [pid 11161:tid 11161] [client 107.173.154.205:53186] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6743"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.branze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.branze.com"] [uri "/"] [unique_id "aLB0d-zO1cwRGs5zMgXRCwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-08-28 11:15:19
(11 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ง๐ช
beruys.com
2025-08-28 10:41:56
(11 months ago)
[Thu Aug 28 12:41:47.300779 2025] [core:error] [pid 3561720:tid 3561818] [client 107.173.154.205:462 ...
show more
[Thu Aug 28 12:41:47.300779 2025] [core:error] [pid 3561720:tid 3561818] [client 107.173.154.205:46246] AH10244: invalid URI path (/icons/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd)
[Thu Aug 28 12:41:49.329042 2025] [core:error] [pid 3561719:tid 3561791] [client 107.173.154.205:46784] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd)
[Thu Aug 28 12:41:51.312426 2025] [core:error] [pid 3561720:tid 3561814] [client 107.173.154.205:47274] AH10244: invalid URI path (/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/bin/sh)
...
show less
DDoS Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-08-26 01:12:23
(1 year ago)
(mod_security) mod_security (id:243930) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com ...
show more
(mod_security) mod_security (id:243930) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 25 21:12:15.745433 2025] [security2:error] [pid 15796:tid 15796] [client 107.173.154.205:52524] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6752"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.tjwus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.tjwus.com"] [uri "/"] [unique_id "aK0J7yEX0M91q83WA97vBgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2025-08-25 15:15:04
(1 year ago)
tcp/443; Probing for WordPress configuration files, probable credential harvesting: "GET /wp-config. ...
show more
tcp/443; Probing for WordPress configuration files, probable credential harvesting: "GET /wp-config.php.bk" @ 2025-08-25T15:10:45Z [proxy]
show less
Web App Attack
Anonymous
2025-08-15 00:00:43
(1 year ago)
Aggressive web scan
SQL Injection
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2025-08-13 20:03:49
(1 year ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-13 03:14:27
(1 year ago)
(mod_security) mod_security (id:243930) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com ...
show more
(mod_security) mod_security (id:243930) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 12 23:14:20.033727 2025] [security2:error] [pid 2019:tid 2019] [client 107.173.154.205:44642] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?:\\\\w+\\\\/[\\\\w\\\\-\\\\.]+)(?:;(?:charset=[\\\\w\\\\-]{1,18}|boundary=[\\\\w\\\\-]+)?)?$" against "REQUEST_HEADERS:Content-Type" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6752"] [id "243930"] [rev "2"] [msg "COMODO WAF: Remote code execution in Apache Struts versions 2.3.31 - 2.3.5 and 2.5 - 2.5.10 (CVE-2017-5638)||www.chyps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.chyps.com"] [uri "/"] [unique_id "aJwDDA11bC_YksMf9IzFgwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-08-09 07:40:07
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
myagent.site
2025-08-08 18:10:15
(1 year ago)
Blocking for trying to access an exploit file: /wp-config.php.bak
Hacking
๐บ๐ธ
TPI-Abuse
2025-07-01 08:56:44
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com ...
show more
(mod_security) mod_security (id:210492) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 01 04:56:37.188067 2025] [security2:error] [pid 16228:tid 16240] [client 107.173.154.205:40002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.m3sxa.com"] [uri "/.wp-config.php.swp"] [unique_id "aGOixfXXxlh0vkEOH8y7gAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-01 04:59:12
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com ...
show more
(mod_security) mod_security (id:210492) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 01 00:59:09.601480 2025] [security2:error] [pid 11294:tid 11294] [client 107.173.154.205:36200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mhext.com"] [uri "/wp-config.php.bk"] [unique_id "aGNrHWaQibVOrzwgtAtfuQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-30 16:02:43
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com ...
show more
(mod_security) mod_security (id:210730) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 30 12:02:36.605190 2025] [security2:error] [pid 14859:tid 14859] [client 107.173.154.205:54324] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jresm.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jresm.com"] [uri "/wp-config.backup"] [unique_id "aGK1HFS_JixRMgZDRLjCaAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-28 13:05:15
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com ...
show more
(mod_security) mod_security (id:210492) triggered by 107.173.154.205 (writingdesklid.cyanfrigate.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 28 09:05:10.098657 2025] [security2:error] [pid 3800773:tid 3800773] [client 107.173.154.205:34784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fwa51.com"] [uri "/wp-config.php~"] [unique_id "aF_ohoiZ4Sb8qwExNRi3OQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack