๐ณ๐ฑ
vestibtech
2024-04-08 20:39:39
(2 years ago)
152.42.214.213 - - [08/Apr/2024:14:39:39 -0600] "GET /modules/mod_simplefileuploadv1.3/elements/udd. ...
show more
152.42.214.213 - - [08/Apr/2024:14:39:39 -0600] "GET /modules/mod_simplefileuploadv1.3/elements/udd.php HTTP/1.1" 301 521 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2024-04-07 20:26:47
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 17:45:49
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 13:45:44.526228 2024] [security2:error] [pid 29425] [client 152.42.214.213:52841] [client 152.42.214.213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oss-in-atm.info|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oss-in-atm.info"] [uri "/site/default/settings.php.BAK"] [unique_id "ZhLbyDcRHr7MI5cDSPbLdgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Zandro
2024-04-07 14:33:52
(2 years ago)
GET /wp-admin/css/colors/blue/CasperExV1.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 13:24:40
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 09:24:35.726104 2024] [security2:error] [pid 19632] [client 152.42.214.213:56960] [client 152.42.214.213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hotelkona.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hotelkona.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZhKek31ePlBAMBARU_qYfwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 11:32:07
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 07:32:03.537769 2024] [security2:error] [pid 30770] [client 152.42.214.213:52731] [client 152.42.214.213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||southriverrescue.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "southriverrescue.org"] [uri "/site/default/settings.php.BAK"] [unique_id "ZhKEM59LZoh-Uu_qc_DuCAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 10:19:21
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 06:19:15.915868 2024] [security2:error] [pid 29900] [client 152.42.214.213:64846] [client 152.42.214.213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||collectablecryptos.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "collectablecryptos.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZhJzI0ogeNClnHyfBK00-wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-04-07 04:25:57
(2 years ago)
Fail2Ban apache-noscript
Bad Web Bot
๐ฉ๐ช
ps-center
2024-04-07 00:26:20
(2 years ago)
C1: Web Attack GET /wp-includes/radio.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-06 22:41:44
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 06 18:41:40.734420 2024] [security2:error] [pid 9467] [client 152.42.214.213:49322] [client 152.42.214.213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||generationedm.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "generationedm.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZhHPpG6sEiRCs5iu1-_IogAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
R.G.
2024-04-06 19:02:09
(2 years ago)
(ScanningForFiles) Scanning for files triggerd 152.42.214.213 (SG/Singapore/-): 10 in the last 900 s ...
show more
(ScanningForFiles) Scanning for files triggerd 152.42.214.213 (SG/Singapore/-): 10 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-06 13:31:55
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 06 09:31:51.990723 2024] [security2:error] [pid 24696] [client 152.42.214.213:54328] [client 152.42.214.213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dennisangellismusic.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dennisangellismusic.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZhFOxxUZFe-R5x9jTpiY0gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-04-06 11:56:00
(2 years ago)
$f2bV_matches
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2024-04-06 00:20:02
(2 years ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-05 19:22:40
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 152.42.214.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 05 15:22:35.128081 2024] [security2:error] [pid 28276] [client 152.42.214.213:59716] [client 152.42.214.213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||register-yacht-cayman.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "register-yacht-cayman.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZhBPe4DIXpp75T9RYcZc5gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack