Anonymous
2023-12-14 16:32:54
(2 years ago)
Bad Web Bot
Web App Attack
Anonymous
2023-12-13 23:29:00
(2 years ago)
"Illegal file type"
Brute-Force
๐บ๐ธ
TPI-Abuse
2023-12-11 18:32:26
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 11 13:32:23.180208 2023] [security2:error] [pid 7220] [client 114.132.153.43:53318] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|www.beirutbazar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.beirutbazar.com"] [uri "/xmlrpc.php"] [unique_id "ZXdVt57Tpr2JB53-f4ONIgAAAAM"], referer: http://www.beirutbazar.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2023-12-10 19:31:42
(2 years ago)
114.132.153.43 - [10/Dec/2023:21:31:39 +0200] "POST /xmlrpc.php HTTP/1.1" 403 235 "https://www.fluen ...
show more
114.132.153.43 - [10/Dec/2023:21:31:39 +0200] "POST /xmlrpc.php HTTP/1.1" 403 235 "https://www.fluentprogress.fi/xmlrpc.php" "python-requests/2.25.1" "1.86"
114.132.153.43 - [10/Dec/2023:21:31:41 +0200] "POST /xmlrpc.php HTTP/1.1" 403 235 "https://www.fluentprogress.fi/xmlrpc.php" "python-requests/2.25.1" "1.86"
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-10 03:31:49
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 09 22:31:42.028562 2023] [security2:error] [pid 1995207] [client 114.132.153.43:54382] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|ultratecnologia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ultratecnologia.com"] [uri "/xmlrpc.php"] [unique_id "ZXUxHqfGqmadA1mNkutx7QAAAAc"], referer: https://ultratecnologia.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-09 16:32:34
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 09 11:32:26.921455 2023] [security2:error] [pid 16168] [client 114.132.153.43:53474] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|miroddi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "miroddi.com"] [uri "/xmlrpc.php"] [unique_id "ZXSWmtmuAcIw_LVGfqu-NgAAAAY"], referer: http://miroddi.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-12-06 11:30:00
(2 years ago)
"Illegal file type"
Brute-Force
๐บ๐ธ
TPI-Abuse
2023-12-05 05:30:32
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 05 00:30:26.124660 2023] [security2:error] [pid 14884] [client 114.132.153.43:58610] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|www.grasslakepizzatime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.grasslakepizzatime.com"] [uri "/xmlrpc.php"] [unique_id "ZW61cseKctxLmDJ05F9kXwAAABc"], referer: https://www.grasslakepizzatime.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-03 12:31:28
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 03 07:31:25.462178 2023] [security2:error] [pid 1457413] [client 114.132.153.43:43530] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|www.fgrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.fgrotary.org"] [uri "/xmlrpc.php"] [unique_id "ZWx1HVveU6ICEce_VP8R8gAAAAg"], referer: http://www.fgrotary.org/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-28 17:30:13
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 28 12:30:10.698361 2023] [security2:error] [pid 94612] [client 114.132.153.43:47954] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|akistech.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "akistech.com"] [uri "/xmlrpc.php"] [unique_id "ZWYjouEBHm-IQCLmHAm01wAAABg"], referer: https://akistech.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-28 14:29:53
(2 years ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-28 12:32:54
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 28 07:32:48.419452 2023] [security2:error] [pid 3287] [client 114.132.153.43:48840] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|meganmurph.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "meganmurph.com"] [uri "/xmlrpc.php"] [unique_id "ZWXd8CZeEM4eUs4gGP3vsgAAAA4"], referer: http://meganmurph.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-28 04:33:07
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 27 23:33:04.619173 2023] [security2:error] [pid 2572276] [client 114.132.153.43:54892] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|www.stantontownship.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.stantontownship.org"] [uri "/xmlrpc.php"] [unique_id "ZWVtgNszxp24yKI-R0T4XwAAAAI"], referer: https://www.stantontownship.org/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ธ
Smel
2023-11-27 23:37:01
(2 years ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-25 21:30:24
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 114.132.153.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 25 16:30:16.545663 2023] [security2:error] [pid 22826] [client 114.132.153.43:36414] [client 114.132.153.43] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.132.153.43 (+1 hits since last alert)|jerielster.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jerielster.com"] [uri "/xmlrpc.php"] [unique_id "ZWJnaLfxsnl7S8xoWi4hPgAAAAI"], referer: http://jerielster.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack