|
๐ซ๐ท
Gygy
|
|
To many error 403 + 404.
|
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
Savvii
|
|
20 attempts against mh-misbehave-ban on redirect
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
Ba-Yu
|
|
WordPress hacking/exploits/scanning
|
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
|
|
|
๐ฉ๐ช
uhlhosting
|
|
taxigut.ch 13.74.142.5 - - [10/Aug/2024:02:50:28.205544 +0200] "GET /.well-known/about.php HTTP/1.1" ...
show more
taxigut.ch 13.74.142.5 - - [10/Aug/2024:02:50:28.205544 +0200] "GET /.well-known/about.php HTTP/1.1" 403 199 "-" "-" Zra5VGPi0JTo6kDB1ShI6wAAAAI "-" /apache/20240810/20240810-0250/20240810-025028-Zra5VGPi0JTo6kDB1ShI6wAAAAI 0 1123 md5:2f77c6e0a2fba4b15abd0cf347bda4d8
taxigut.ch 13.74.142.5 - - [10/Aug/2024:02:50:30.813894 +0200] "GET /wp-includes/style-engine/about.php HTTP/1.1" 403 199 "-" "-" Zra5VmPi0JTo6kDB1ShJDwAAAAU "-" /apache/20240810/20240810-0250/20240810-025030-Zra5VmPi0JTo6kDB1ShJDwAAAAU 0 1116 md5:0ebac3a761062c0a1f953f812f85ef73
taxigut.ch 13.74.142.5 - - [10/Aug/2024:02:50:32.009178 +0200] "GET /wp-includes/pm.php HTTP/1.1" 403 199 "-" "-" Zra5WGPi0JTo6kDB1ShJIAAAAAE "-" /apache/20240810/20240810-0250/20240810-025032-Zra5WGPi0JTo6kDB1ShJIAAAAAE 0 1094 md5:a18a14e8c091c1c4e4909bca5acd97b1
taxigut.ch 13.74.142.5 - - [10/Aug/2024:02:50:35.272580 +0200] "GET /wp-includes/ID3/class.api.php HTTP/1.1" 403 199 "-" "-" Zra5W2Pi0JTo6kDB1ShJSgAAABE "-" /apache/20240810/20240810-
...
show less
|
DDoS Attack
Brute-Force
|
|
|
๐บ๐ธ
hostseries
|
|
Trigger: LF_MODSEC
|
Brute-Force
|
|
|
๐ฉ๐ช
updown.io
|
|
{"level":"info","ts":1723236422.9411283,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1723236422.9411283,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"13.74.142.5","remote_port":"2500","proto":"HTTP/1.1","method":"GET","host":"status.btcex.cz","uri":"/.well-known/about.php","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0"],"Insecure-Flag":["1"]}},"user_id":"","duration":0.000072207,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://status.btcex.cz/.well-known/about.php"],"Content-Type":[]}}
{"level":"info","ts":1723236423.2831655,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"13.74.142.5","remote_port":"2843","proto":"HTTP/1.1","method":"GET","host":"status.btcex.cz","uri":"/simple.php","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0"],"Insecure-Flag":["1"]}},"user_id":"","duration":0.000067699,"size":0,"status":308,"resp_
...
show less
|
DDoS Attack
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 10:27:41.658113 2024] [security2:error] [pid 2902817:tid 2902817] [client 13.74.142.5:4309] [client 13.74.142.5] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leonardodecaprio.com"] [uri "/wp-config.php"] [unique_id "ZrYnXSHYKeakBkSXueNiGQAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
rdpguard.com
|
|
RdpGuard detected brute-force attempt on HTTP
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 08:57:04.214335 2024] [security2:error] [pid 9722:tid 9722] [client 13.74.142.5:1611] [client 13.74.142.5] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pleasurecube.com"] [uri "/wp-config.php"] [unique_id "ZrYSIC_iW_uIH0jT3ZZ9AwAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 07:18:02.508383 2024] [security2:error] [pid 16933:tid 16933] [client 13.74.142.5:4090] [client 13.74.142.5] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "otrantocapital.com"] [uri "/wp-config.php"] [unique_id "ZrX66iAOP-py-luqhfOpiQAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 05:10:17.471158 2024] [security2:error] [pid 20842:tid 20842] [client 13.74.142.5:3217] [client 13.74.142.5] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jolankagroup.com"] [uri "/wp-config.php"] [unique_id "ZrXc-eFKMPpZ_AOZ6w1e-wAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 02:43:39.847634 2024] [security2:error] [pid 15341:tid 15341] [client 13.74.142.5:1146] [client 13.74.142.5] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessejamesbook.com"] [uri "/wp-config.php"] [unique_id "ZrW6m6MA1tAnqbtAj71PUgAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
Savvii
|
|
20 attempts against mh-misbehave-ban on redirect
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ฆ
polycoda
|
|
EXTREMELY AGGRESSIVE SCANNER results in +1000 errors in an hour (404 errors)
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 13.74.142.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 08 13:33:48.639356 2024] [security2:error] [pid 24795:tid 24795] [client 13.74.142.5:2126] [client 13.74.142.5] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maurnavy.com"] [uri "/wp-config.php"] [unique_id "ZrUBfA52OcE5iKgJFBVDgwAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|