๐บ๐ธ
TPI-Abuse
2024-03-28 19:41:58
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 15:41:50.626513 2024] [security2:error] [pid 16726] [client 13.90.76.116:2361] [client 13.90.76.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stepiz62.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stepiz62.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZgXH_jDExOldb-0hk4ot4AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
sinan
2024-03-28 19:36:00
(2 years ago)
WP admin attacks
Web App Attack
๐จ๐ญ
zynex
2024-03-28 18:06:58
(2 years ago)
URL Probing: /1.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 17:50:07
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 13:49:59.491469 2024] [security2:error] [pid 28060] [client 13.90.76.116:3349] [client 13.90.76.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fishleadership.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fishleadership.org"] [uri "/site/default/settings.php.BAK"] [unique_id "ZgWtxzfmO0ORk26RDXLdAwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 16:26:08
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 12:26:00.971421 2024] [security2:error] [pid 21930] [client 13.90.76.116:1792] [client 13.90.76.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||butkiewiczfamilyfarm.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "butkiewiczfamilyfarm.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZgWaGHiacjw9UjZMsuFGBgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-03-28 16:16:27
(2 years ago)
13.90.76.116 - - [28/Mar/2024:18:16:26 +0200] "GET /wp-admin/css/colors/blue/CasperExV1.php HTTP/1.1 ...
show more
13.90.76.116 - - [28/Mar/2024:18:16:26 +0200] "GET /wp-admin/css/colors/blue/CasperExV1.php HTTP/1.1" 404 274 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 16:04:38
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 12:04:32.900306 2024] [security2:error] [pid 32465] [client 13.90.76.116:1057] [client 13.90.76.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.3wf.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.3wf.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZgWVENayWyXnBgAV5wNDOwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 15:35:21
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 11:35:15.319805 2024] [security2:error] [pid 32397] [client 13.90.76.116:3031] [client 13.90.76.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||register-yacht-cayman.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "register-yacht-cayman.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZgWOM-M2XnHNWm6Vbiu5HwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-03-28 14:41:53
(2 years ago)
C1: Web Attack GET /wp-includes/radio.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 14:30:45
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 10:30:37.091036 2024] [security2:error] [pid 29772] [client 13.90.76.116:1550] [client 13.90.76.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.csme-eprr.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.csme-eprr.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZgV_DcLCYqDtkidjiFOFewAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
QT
2024-03-28 14:21:27
(2 years ago)
Website hack attempted at 2024-03-29 00:21:24 +1000
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-03-28 14:00:49
(2 years ago)
13.90.76.116 - - [28/Mar/2024:16:00:49 +0200] "GET /wp-admin/css/colors/blue/CasperExV1.php HTTP/1.1 ...
show more
13.90.76.116 - - [28/Mar/2024:16:00:49 +0200] "GET /wp-admin/css/colors/blue/CasperExV1.php HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 13:25:22
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 09:25:16.058732 2024] [security2:error] [pid 21796] [client 13.90.76.116:1601] [client 13.90.76.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.styxwetworld.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.styxwetworld.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZgVvvM5VWzwaCprNH14VYgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 12:55:00
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 13.90.76.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 08:54:53.281180 2024] [security2:error] [pid 16095:tid 47743678576384] [client 13.90.76.116:3445] [client 13.90.76.116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mentzlaw.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mentzlaw.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZgVonSpVMXUhMaDjWFIP7wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-03-28 12:43:58
(2 years ago)
Fail2Ban apache-noscript
Bad Web Bot