πΊπΈ
TPI-Abuse
2024-08-30 04:50:00
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 30 00:49:53.755352 2024] [security2:error] [pid 1747918:tid 1747918] [client 153.92.223.117:45194] [client 153.92.223.117] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drwolberg.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drwolberg.com"] [uri "/database.sql"] [unique_id "ZtFPcaksM00XzI6sTJiurgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-30 03:26:00
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2024-08-30 01:28:05
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 29 21:27:57.900502 2024] [security2:error] [pid 21459:tid 21459] [client 153.92.223.117:56610] [client 153.92.223.117] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crescendoconsultltd.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crescendoconsultltd.com"] [uri "/backup.sql"] [unique_id "ZtEgHRj69rPdSHGAEt-0dwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-30 00:39:46
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 29 20:39:40.227918 2024] [security2:error] [pid 4058242:tid 4058242] [client 153.92.223.117:33474] [client 153.92.223.117] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||concentricsteel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "concentricsteel.com"] [uri "/backup.sql"] [unique_id "ZtEUzDRNO2KNI0zug210yAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-29 22:23:41
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 29 18:23:35.403017 2024] [security2:error] [pid 19365:tid 19365] [client 153.92.223.117:37216] [client 153.92.223.117] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casamoresc.it|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casamoresc.it"] [uri "/dump.sql"] [unique_id "ZtD05zZ-ZlH51pRyzBgO6gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-29 18:09:02
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 29 14:08:56.254516 2024] [security2:error] [pid 612215:tid 612230] [client 153.92.223.117:58984] [client 153.92.223.117] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||atlasrecordssearch.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "atlasrecordssearch.com"] [uri "/backup.sql"] [unique_id "ZtC5ONnI0o1WXOYQhf8MAwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-29 15:48:23
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 153.92.223.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 29 11:48:17.608158 2024] [security2:error] [pid 2018026:tid 2018026] [client 153.92.223.117:60542] [client 153.92.223.117] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||airtechconsulting.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "airtechconsulting.com"] [uri "/db.sql"] [unique_id "ZtCYQdNOGqLNa_UegKHt6wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2024-06-15 22:06:08
(2 years ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2024-06-14 22:05:11
(2 years ago)
Too many Status 40X (28)
Request Overload (224)
Brute-Force
Web App Attack
Anonymous
2024-06-14 11:05:00
(2 years ago)
POST /wp-admin/admin-ajax.php - Blocked access to admin-ajax.php - [bot detection is enabled]
Web App Attack
πͺπΈ
10dencehispahard SL
2024-06-14 08:02:47
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
π¦πΊ
MAGIC
2024-06-14 00:00:31
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2024-06-13 23:11:41
(2 years ago)
153.92.223.117 - - [14/Jun/2024:01:11:40 +0200] "GET /wp-json HTTP/1.1" 401 3978 "-" "Mozilla/5.0 (W ...
show more
153.92.223.117 - - [14/Jun/2024:01:11:40 +0200] "GET /wp-json HTTP/1.1" 401 3978 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36"
153.92.223.117 - - [14/Jun/2024:01:11:40 +0200] "GET /wp-json HTTP/1.1" 401 3978 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0"
153.92.223.117 - - [14/Jun/2024:01:11:40 +0200] "GET /author/admim HTTP/1.1" 401 3978 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36"
...
show less
Web App Attack
π΅π±
mkrufczyk
2024-06-13 22:14:00
(2 years ago)
wp-admin
Bad Web Bot
πΊπΈ
mnsf
2024-06-13 22:03:09
(2 years ago)
Too many Status 40X (12)
Brute-Force
Web App Attack