๐ซ๐ท
Sklurk
2025-06-09 13:35:20
(1 year ago)
Web App Attack
Web App Attack
๐ฌ๐ง
myintarweb
2025-01-19 22:56:43
(1 year ago)
124.156.192.98 - - [19/Dec/2024:06:21:57 +0000] 443 "GET /kirton-pigot-1828-9/courthouse.jpg HTTP/1. ...
show more
124.156.192.98 - - [19/Dec/2024:06:21:57 +0000] 443 "GET /kirton-pigot-1828-9/courthouse.jpg HTTP/1.1" 403 5282 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:72.0) Gecko/20100101 Firefox/72.0"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-15 07:13:16
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 15 02:13:11.999810 2025] [security2:error] [pid 2023:tid 2023] [client 124.156.192.98:21993] [client 124.156.192.98] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.nationalenq.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nationalenq.com"] [uri "/wp-content/uploads/2020/05/National-ENQ-NationalENQ.com-Jeff-Bezos-Amazon-Unfair-Competition-US-Congress-Competing-Products-American-Export-Import-AmericanExportImport.com_-600x500.jpg, https:/imgv1.face-caption.com/split_00026/000116316.jpg"] [unique_id "Z4dgB4X1YAgDdsf044lgvAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-15 06:56:53
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 15 01:56:48.507687 2025] [security2:error] [pid 11384:tid 11384] [client 124.156.192.98:13017] [client 124.156.192.98] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.artbytracyjane.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.artbytracyjane.com"] [uri "/wp-content/uploads/2014/04/ep_quilt2300204.jpg, https:/imgv1.face-caption.com/split_00026/000016212.jpg"] [unique_id "Z4dcMLSoPvTucQS-S9Gc3AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2025-01-14 17:43:37
(1 year ago)
Web App Attack
Web App Attack
๐ฉ๐ช
LRob
2025-01-14 13:45:05
(1 year ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-14 01:53:54
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 20:53:51.644400 2025] [security2:error] [pid 31046:tid 31046] [client 124.156.192.98:41417] [client 124.156.192.98] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.texasbordertours.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.texasbordertours.com"] [uri "/Website_Pictures/mom_and_son_on_a_horse.jpg, https:/imgv1.face-caption.com/split_00015/001398221.jpg"] [unique_id "Z4XDryiGSnEXg-kCECT0wAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2025-01-13 17:35:00
(1 year ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-13 16:54:20
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 11:54:13.541971 2025] [security2:error] [pid 2633411:tid 2633411] [client 124.156.192.98:48565] [client 124.156.192.98] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||persnicketyinc.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "persnicketyinc.com"] [uri "/wp-content/uploads/Getting-Married.jpg, https:/imgv1.face-caption.com/split_00013/000142851.jpg"] [unique_id "Z4VFNSTJu5cSofqFYZE6qwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-13 14:31:45
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 09:31:40.481423 2025] [security2:error] [pid 2119306:tid 2119306] [client 124.156.192.98:12240] [client 124.156.192.98] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||modmove.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "modmove.com"] [uri "/wp-content/uploads/2019/11/TheIrishmanMovieReview.jpg, https:/imgv1.face-caption.com/split_00001/001534184.jpg"] [unique_id "Z4UjzBRr0qsQArE6CWC5kQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-01-13 14:00:06
(1 year ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-13 13:51:33
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 08:51:29.008689 2025] [security2:error] [pid 3387000:tid 3387040] [client 124.156.192.98:25358] [client 124.156.192.98] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.jofdt.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jofdt.com"] [uri "/wp-content/uploads/2017/05/Dr.-wakins_Page_2-480x270.jpg, https:/imgv1.face-caption.com/split_00001/001037203.jpg"] [unique_id "Z4UaYSeaZS22dH2kTV3rvQAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-01-13 13:15:09
(1 year ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-13 12:06:48
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 07:06:43.154125 2025] [security2:error] [pid 29186:tid 29186] [client 124.156.192.98:6415] [client 124.156.192.98] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.mavikalem.org|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mavikalem.org"] [uri "/wp-content/uploads/2016/09/syrians-660x330.jpg, https:/imgv1.face-caption.com/split_00011/001192520.jpg"] [unique_id "Z4UB03tgtTwcZ08eciHtWgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-13 11:34:29
(1 year ago)
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 124.156.192.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 13 06:34:21.563441 2025] [security2:error] [pid 610054:tid 610054] [client 124.156.192.98:32528] [client 124.156.192.98] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.fashionmenswear.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.fashionmenswear.com"] [uri "/store/media/catalog/product/cache/1/small_image/400x600/9df78eab33525d08d6e5fb8d27136e95/t/u/tux_sh_navy.jpg, https:/imgv1.face-caption.com/split_00011/000809391.jpg"] [unique_id "Z4T6PcAcQgVm1hc_aaot_AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack