๐ฉ๐ช
LRob.fr
2025-09-21 05:02:48
(9 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
uhlhosting
2025-09-20 05:21:42
(9 months ago)
Fail2Ban - Malware rules Mod-Security detected - Bad Bots - Unwanted Crawler
...
Brute-Force
๐ซ๐ท
dynamix
2025-09-20 05:05:50
(9 months ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob.fr
2025-09-19 03:01:50
(9 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-18 03:27:51
(9 months ago)
(mod_security) mod_security (id:217200) triggered by 154.12.245.191 (vmi2771199.contaboserver.net): ...
show more
(mod_security) mod_security (id:217200) triggered by 154.12.245.191 (vmi2771199.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 23:27:46.576307 2025] [security2:error] [pid 10097:tid 10097] [client 154.12.245.191:38438] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||grouchytrump.com.gregquinn.com|F|2"] [data "/guest_auth/guestisup.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "grouchytrump.com.gregquinn.com"] [uri "/guest_auth/guestIsUp.php"] [unique_id "aMt8MuIGo5_WfTjrtmuOVgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2025-09-17 03:16:33
(9 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-12 03:35:29
(9 months ago)
(mod_security) mod_security (id:211190) triggered by 154.12.245.191 (vmi2771199.contaboserver.net): ...
show more
(mod_security) mod_security (id:211190) triggered by 154.12.245.191 (vmi2771199.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 23:35:22.241727 2025] [security2:error] [pid 30702:tid 30702] [client 154.12.245.191:46608] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||lawrencehale.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /export/classroom-course-statistics?fileNames[]=../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawrencehale.net"] [uri "/export/classroom-course-statistics"] [unique_id "aMOU-jkSHeSTZOiaQVSKUgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 03:32:11
(9 months ago)
(mod_security) mod_security (id:217200) triggered by 154.12.245.191 (vmi2771199.contaboserver.net): ...
show more
(mod_security) mod_security (id:217200) triggered by 154.12.245.191 (vmi2771199.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 23:32:03.505400 2025] [security2:error] [pid 6016:tid 6016] [client 154.12.245.191:60812] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||phalanxemail.axiomemail.net|F|2"] [data "/guest_auth/guestisup.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "phalanxemail.axiomemail.net"] [uri "/guest_auth/guestIsUp.php"] [unique_id "aMJCs-mjUdK8TrUXNJ_KrwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ROCKETLAB
2025-09-10 21:14:00
(9 months ago)
Scanning for various config files and using a massive amount of inbound data to do so.
Brute-Force
๐ณ๐ฟ
reddog
2025-09-08 21:54:00
(9 months ago)
Blocked for SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauth ...
show more
Blocked for SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
show less
DDoS Attack
Hacking
Anonymous
2025-09-08 09:52:00
(9 months ago)
Exceeded the maximum global requests per minute for crawlers or humans.
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-09-08 06:16:09
(9 months ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
cmbplf
2025-09-06 18:27:41
(9 months ago)
697 requests with url.path *config.json
Brute-Force
Bad Web Bot
Anonymous
2025-09-06 16:52:02
(9 months ago)
Bot / scanning and/or hacking attempts: GET //.env HTTP/1.1, GET //.env.prod HTTP/1.1, GET //.env.lo ...
show more
Bot / scanning and/or hacking attempts: GET //.env HTTP/1.1, GET //.env.prod HTTP/1.1, GET //.env.local HTTP/1.1, GET //.env.backup HTTP/1.1, GET //.env.old HTTP/1.1, GET //.env.production.local HTTP/1.1, GET //.env.stage HTTP/1.1, GET //.env.example HTTP/1.1, GET //.env.www HTTP/1.1, GET //.env.production HTTP/1.1, GET //.env.development.local HTTP/1.1, GET //.env.save HTTP/1.1, GET //api/.env HTTP/1.1, GET //.env.communikeet HTTP/1.1, GET //.env.prod.local HTTP/1.1, GET //.env_sample HTTP/1.1
show less
Hacking
Web App Attack
๐ฎ๐น
LTM
2025-09-06 06:20:01
(9 months ago)
WebServer - Attempts to exploit
Hacking
Brute-Force
Web App Attack