๐บ๐ธ
deskpass.com
2024-01-06 15:58:40
(2 years ago)
GET /wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 14:36:36
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 09:36:32.532347 2024] [security2:error] [pid 9221] [client 13.79.4.61:1967] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brookspowell.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brookspowell.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZllcHj16xWb_NTrfazSUAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 14:10:21
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 09:10:13.244189 2024] [security2:error] [pid 1167] [client 13.79.4.61:2594] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jackieherbach.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jackieherbach.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZlfRUZFGZlRLheqDSKG9gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 13:36:18
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 08:36:13.155290 2024] [security2:error] [pid 14265] [client 13.79.4.61:2571] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.khaoula.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.khaoula.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZlXTYArcGWEFKOfi8GrjQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 13:13:48
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 08:13:43.471052 2024] [security2:error] [pid 10369] [client 13.79.4.61:2952] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.studiopilates.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.studiopilates.net"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZlSB594byU-zaQIiH4yHgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 12:44:07
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 07:44:02.767636 2024] [security2:error] [pid 24028] [client 13.79.4.61:4013] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kreweofblackbeardsrevenge.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kreweofblackbeardsrevenge.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZlLErN9-Nnyv0EaxFX9dwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 11:15:45
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 06:15:41.534907 2024] [security2:error] [pid 30188] [client 13.79.4.61:2562] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.naghmehfarahmand.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.naghmehfarahmand.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZk2XSvxit68CafAqKk16gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 10:46:28
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 05:46:21.664977 2024] [security2:error] [pid 20155] [client 13.79.4.61:4084] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.turnofthecenturyfinearts.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.turnofthecenturyfinearts.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZkvffbG88oKI-wUZWzIHQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 09:07:30
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 04:07:26.482912 2024] [security2:error] [pid 25932] [client 13.79.4.61:1613] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hotpay.co|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hotpay.co"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZkYTjEhO2G0N0Zw7skQTQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 07:06:39
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 13.79.4.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 02:06:35.686723 2024] [security2:error] [pid 9903:tid 47497531094784] [client 13.79.4.61:2148] [client 13.79.4.61] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||slugshield.com.anthonydalessandro.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "slugshield.com.anthonydalessandro.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZj7-95_9q7qVAQFYKfTAAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2024-01-06 04:35:17
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
[email protected]
2024-01-05 21:19:45
(2 years ago)
Brute force 217 attempts
DDoS Attack
SQL Injection
Brute-Force
SSH
๐ฌ๐ง
AFRICARGUS
2024-01-05 19:13:31
(2 years ago)
Brute force attacks plus around 300 malicious GET requests within 30 seconds including:
13.79.4.6 ...
show more
Brute force attacks plus around 300 malicious GET requests within 30 seconds including:
13.79.4.61 [05/Jan/2024:19:00:51 +0000] GET "/ovatools.php" HTTP/1.1 301
13.79.4.61 [05/Jan/2024:19:01:15 +0000] GET "/wp-includes/wp-includes/" HTTP/1.1 301
13.79.4.61 [05/Jan/2024:19:01:15 +0000] GET "/wp-includes/images/smilies/" HTTP/1.1 301
13.79.4.61 [05/Jan/2024:19:01:17 +0000] GET "/wp-content/plugins/zaen/includes/" HTTP/1.1 301
13.79.4.61 [05/Jan/2024:19:01:18 +0000] GET "/up/.well-known/" HTTP/1.1 301
show less
Hacking
Brute-Force
Web App Attack
๐ต๐ฑ
strefapi_com
2024-01-05 01:00:40
(2 years ago)
Brute-force web
...
Hacking
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2024-01-04 19:34:20
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack