๐บ๐ธ
TPI-Abuse
2024-08-19 19:28:34
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 19 15:28:26.449306 2024] [security2:error] [pid 27523:tid 27523] [client 139.59.235.87:61929] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "triplecrownfundraising.com"] [uri "/wp-config.php"] [unique_id "ZsOc2qwt3zT-wYzcEVehXgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 19:21:07
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 15:21:03.076617 2024] [security2:error] [pid 12291:tid 12291] [client 139.59.235.87:60189] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eileensinc.com"] [uri "/wp-config.php"] [unique_id "ZsJJnzSV9U7PgXUbryFKLwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 09:17:53
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 05:17:44.814874 2024] [security2:error] [pid 20299:tid 20299] [client 139.59.235.87:63721] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intersession.net"] [uri "/wp-config.php"] [unique_id "ZsG8ODtGVDERa4DFsT7-lgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2024-08-17 17:16:51
(2 years ago)
{"level":"info","ts":1723915002.9886918,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1723915002.9886918,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"139.59.235.87","remote_port":"62594","client_ip":"139.59.235.87","proto":"HTTP/1.1","method":"GET","host":"pdyb.status.updown.io","uri":"/.well-known/about.php","headers":{"User-Agent":["fasthttp"]}},"bytes_read":0,"user_id":"","duration":0.00007841,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://pdyb.status.updown.io/.well-known/about.php"],"Content-Type":[]}}
{"level":"info","ts":1723915003.1520476,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"139.59.235.87","remote_port":"62640","client_ip":"139.59.235.87","proto":"HTTP/1.1","method":"GET","host":"pdyb.status.updown.io","uri":"/vendor/phpunit/phpunit/src/Util/PHP/","headers":{"User-Agent":["fasthttp"]}},"bytes_read":0,"user_id":"","duration":0.000051228,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
ps-center
2024-08-17 10:37:11
(2 years ago)
C1: Web Attack GET /wp-content/plugins/classic-editor/wp-login.php
GET /wordpress/
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-17 08:45:29
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 04:45:23.087370 2024] [security2:error] [pid 29636:tid 29636] [client 139.59.235.87:57012] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sanjuangrange.org"] [uri "/wp-config.php"] [unique_id "ZsBjI82fKJ4PXikNt0-XLwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
rafamiga
2024-08-17 08:04:00
(2 years ago)
n Force"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:44 +0000] "GET /wp-includes/assets/atomlib.php ...
show more
n Force"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:44 +0000] "GET /wp-includes/assets/atomlib.php HTTP/1.1" 404 341 "fasthttp"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:44 +0000] "GET /wp/wp-includes/menu.php HTTP/1.1" 404 341 "fasthttp"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:45 +0000] "GET /wp-includes/Text/Diff/Engine/Renderer.php HTTP/1.1" 404 341 "fasthttp"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:45 +0000] "GET /wp-includes/jquery.php HTTP/1.1" 404 341 "fasthttp"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:45 +0000] "GET /blog/wp-content/plugins/fix/up.php HTTP/1.1" 404 341 "fasthttp"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:45 +0000] "GET /images/class.php HTTP/1.1" 404 341 "fasthttp"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:46 +0000] "GET /wp-includes/IXR/settings.php HTTP/1.1" 404 341 "fasthttp"
[139.59.235.87 SG] *.net [17/Aug/2024:08:04:46 +0000] "GET /wp-admin/css/colors/trike.php HTTP/1.1" 404 341 "fasthttp"
show less
Port Scan
Brute-Force
๐ณ๐ฑ
Savvii
2024-08-17 07:24:24
(2 years ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 20:50:38
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 16:50:30.644732 2024] [security2:error] [pid 20992:tid 20992] [client 139.59.235.87:54679] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ancientleather.theflyingdutchman.us"] [uri "/wp-config.php"] [unique_id "Zr-7lg7VZ7Q-8dK7z8iCPAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 15:03:20
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 11:03:12.615315 2024] [security2:error] [pid 3652880:tid 3652880] [client 139.59.235.87:63768] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gayebrown.tulsatvmemories.com"] [uri "/wp-config.php"] [unique_id "Zr9qMMi2P790te0DWe-wTgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-16 06:37:32
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 16 02:37:24.616844 2024] [security2:error] [pid 6106:tid 6106] [client 139.59.235.87:56987] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagesbyaubrey.com"] [uri "/wp-config.php"] [unique_id "Zr7zpI6k8nX2QYHy-eqVIgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 23:36:35
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 19:36:29.305095 2024] [security2:error] [pid 4009:tid 4009] [client 139.59.235.87:55478] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tone57.com"] [uri "/wp-config.php"] [unique_id "Zr6Q_f3Qfzu3-URPRY9nGQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2024-08-15 20:15:03
(2 years ago)
WordPress brute force
Brute-Force
๐จ๐ญ
zynex
2024-08-15 19:10:36
(2 years ago)
URL Probing: /x/index.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 01:22:28
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 139.59.235.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 14 21:22:23.078544 2024] [security2:error] [pid 9075:tid 9075] [client 139.59.235.87:61725] [client 139.59.235.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petersartworks.com"] [uri "/wp-config.php"] [unique_id "Zr1YT3tHbPQsFaCfV_2YugAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack