πΊπΈ
TPI-Abuse
2024-07-30 12:47:50
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 141.95.59.92 (ip92.ip-141-95-59.eu): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 141.95.59.92 (ip92.ip-141-95-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 30 08:47:43.482688 2024] [security2:error] [pid 21996:tid 21996] [client 141.95.59.92:38930] [client 141.95.59.92] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.madronabluff.com"] [uri "/.git/config"] [unique_id "Zqjg76HgCALjOnlKBi9OMwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
ozisp.com.au
2024-07-30 11:24:13
(2 years ago)
GB__<33>1722338651 [1:2522013:5601] ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group ...
show more
GB__<33>1722338651 [1:2522013:5601] ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 14 [Classification: Misc Attack] [Priority: 2] {TCP} 141.95.59.92:48724
show less
Open Proxy
πΊπΈ
TPI-Abuse
2024-07-29 21:42:18
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 141.95.59.92 (ip92.ip-141-95-59.eu): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 141.95.59.92 (ip92.ip-141-95-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 29 17:42:15.926284 2024] [security2:error] [pid 26073:tid 26073] [client 141.95.59.92:41306] [client 141.95.59.92] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.barkerbehavior.com"] [uri "/wp-config.php.public"] [unique_id "ZqgMt6DOWbTn3-j6BTSFaAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
MacLotsen
2024-07-29 16:01:25
(2 years ago)
[Mon Jul 29 18:01:23.222835 2024] [access_compat:error] [pid 65905] [client 141.95.59.92:45228] AH01 ...
show more
[Mon Jul 29 18:01:23.222835 2024] [access_compat:error] [pid 65905] [client 141.95.59.92:45228] AH01797: client denied by server configuration: /var/www/ingestoffer.nl/xmlrpc.php
[Mon Jul 29 18:01:24.337119 2024] [access_compat:error] [pid 65979] [client 141.95.59.92:45228] AH01797: client denied by server configuration: /var/www/ingestoffer.nl/xmlrpc.php
[Mon Jul 29 18:01:24.950050 2024] [access_compat:error] [pid 65907] [client 141.95.59.92:45228] AH01797: client denied by server configuration: /var/www/ingestoffer.nl/xmlrpc.php
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-28 14:07:44
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 141.95.59.92 (ip92.ip-141-95-59.eu): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 141.95.59.92 (ip92.ip-141-95-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 28 10:07:36.144348 2024] [security2:error] [pid 27720:tid 27720] [client 141.95.59.92:49490] [client 141.95.59.92] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sentinel-sg.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sentinel-sg.com"] [uri "/s.sql"] [unique_id "ZqZQqBYfUraOJr9C07roRwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2024-07-28 12:47:02
(2 years ago)
Looking for CMS/PHP/SQL vulnerablilities - 13
Exploited Host
Web App Attack
π©πͺ
CommanderRoot
2024-07-28 04:34:43
(2 years ago)
Invalid HTTP request flood
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2024-07-27 15:20:48
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 141.95.59.92 (ip92.ip-141-95-59.eu): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 141.95.59.92 (ip92.ip-141-95-59.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 11:20:40.923972 2024] [security2:error] [pid 1339:tid 1450] [client 141.95.59.92:38370] [client 141.95.59.92] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.txt" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fibertechsystems.com"] [uri "/wp-config.txt"] [unique_id "ZqUQSPrvUPq7bes8yfMT3AAAAlM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2024-07-27 03:44:02
(2 years ago)
Looking for CMS/PHP/SQL vulnerablilities - 13
Exploited Host
Web App Attack
π©πͺ
ger-stg-sifi1
2024-07-26 22:06:28
(2 years ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π²πΎ
Rizzy
2024-07-26 04:54:30
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π©πͺ
BestFans.com
2024-07-24 21:49:22
(2 years ago)
Credential brute-force attacks on webpage logins
Brute-Force
π©πͺ
FeG Deutschland
2024-07-24 06:51:01
(2 years ago)
Looking for CMS/PHP/SQL vulnerablilities - 13
Exploited Host
Web App Attack
πΊπΈ
dxavsoul
2024-07-24 05:06:00
(2 years ago)
wp_xmlrpc admin (1 lockouts)
Hacking
Brute-Force
π¦πΊ
MAGIC
2024-07-23 09:00:13
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot