๐บ๐ธ
cfultz
2026-05-11 15:50:50
(4 months ago)
Historical portscan caught by UFW/Fail2ban on Bertha
Port Scan
๐ฉ๐ช
stinpriza
2024-12-24 10:04:37
(1 year ago)
Drupal Authentication failure
Brute-Force
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2024-12-23 05:28:36
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted] 109.107.181.112 (DE/Germany/ecret-holid ...
show more
(mod_security) mod_security triggered on hostname [redacted] 109.107.181.112 (DE/Germany/ecret-holiday-n7.aeza.network)
show less
SQL Injection
๐บ๐ธ
rsiddall
2024-12-23 02:48:55
(1 year ago)
2024-12-22T21:48:53.221303linnet.elirion.net drupal[13738]: https://huumanists.org|1734922133|user|1 ...
show more
2024-12-22T21:48:53.221303linnet.elirion.net drupal[13738]: https://huumanists.org|1734922133|user|109.107.181.112|https://huumanists.org/?q=user||0||Login attempt failed for admin.
2024-12-22T21:48:53.606906linnet.elirion.net drupal[13250]: https://huumanists.org|1734922133|user|109.107.181.112|https://huumanists.org/?q=user||0||Login attempt failed for administrator.
2024-12-22T21:48:53.862404linnet.elirion.net drupal[11359]: https://huumanists.org|1734922133|user|109.107.181.112|https://huumanists.org/?q=user||0||Login attempt failed for editor.
2024-12-22T21:48:54.153048linnet.elirion.net drupal[13738]: https://huumanists.org|1734922134|user|109.107.181.112|https://huumanists.org/?q=user||0||Login attempt failed for root.
2024-12-22T21:48:54.450783linnet.elirion.net drupal[13250]: https://huumanists.org|1734922134|user|109.107.181.112|https://huumanists.org/?q=user||0||Login attempt failed for user.
...
show less
Brute-Force
๐บ๐ธ
kosada.com
2024-12-22 19:12:04
(1 year ago)
Web vulnerability probing
Web App Attack
๐ฎ๐ช
RoboSOC
2024-12-22 19:08:07
(1 year ago)
ElFinder Command Injection Vulnerability, PTR: ecret-holiday-n7.aeza.network.
Hacking
๐บ๐ธ
TPI-Abuse
2024-12-22 17:27:28
(1 year ago)
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network) ...
show more
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 22 12:27:24.714542 2024] [security2:error] [pid 11909:tid 11909] [client 109.107.181.112:58570] [client 109.107.181.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.famagustacyprus.eu|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.famagustacyprus.eu"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "Z2hL_Dkb1Y_Ux0BbOKy-ZQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2024-12-22 16:25:54
(1 year ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-22 15:55:36
(1 year ago)
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network) ...
show more
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 22 10:55:31.781930 2024] [security2:error] [pid 1045710:tid 1045710] [client 109.107.181.112:46692] [client 109.107.181.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.lumentravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.lumentravel.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "Z2g2c_w-M2pAauewo5-PnAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-22 15:27:53
(1 year ago)
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network) ...
show more
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 22 10:27:48.391403 2024] [security2:error] [pid 30444:tid 30444] [client 109.107.181.112:38226] [client 109.107.181.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.mavikalem.org"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "Z2gv9E1_MMZuZ9IFKyyOJQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-22 14:46:36
(1 year ago)
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network) ...
show more
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 22 09:46:30.206133 2024] [security2:error] [pid 848:tid 848] [client 109.107.181.112:42964] [client 109.107.181.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.doctoredwinalvarez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.doctoredwinalvarez.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "Z2gmRqtVwdsY9Xe_lXUY-AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-22 13:40:34
(1 year ago)
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network) ...
show more
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 22 08:40:28.859389 2024] [security2:error] [pid 389141:tid 389141] [client 109.107.181.112:47008] [client 109.107.181.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.glendaleheritage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.glendaleheritage.org"] [uri "/glendale/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "Z2gWzCchxWGzoP22Y54cgwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-22 13:09:28
(1 year ago)
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network) ...
show more
(mod_security) mod_security (id:234930) triggered by 109.107.181.112 (ecret-holiday-n7.aeza.network): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 22 08:09:24.120921 2024] [security2:error] [pid 25030:tid 25030] [client 109.107.181.112:54670] [client 109.107.181.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||newhopepetgrooming.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "newhopepetgrooming.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "Z2gPhJr-nPuE4T1plWZXOwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-22 12:33:38
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-12-22 11:47:52
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH