|
πΊπΈ
wswd.net
|
|
AutoBlocked by WSWD Security
|
Port Scan
Hacking
Brute-Force
SSH
|
|
|
π·π΄
INTEQ
|
|
SMTP without rDNS from 154.6.94.5
|
Spoofing
|
|
|
π¦πΊ
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|
|
Anonymous
|
|
Aggressive web scan
|
Web App Attack
|
|
|
πΊπΈ
octageeks.com
|
|
Wordpress malicious attack:[octa404]
|
Web App Attack
|
|
|
πΊπΈ
octageeks.com
|
|
Wordpress malicious attack:[octa404]
|
Web App Attack
|
|
|
Anonymous
|
|
(mod_security) mod_security triggered on hostname [redacted] 154.6.94.5 (US/United States/-)
|
SQL Injection
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 24 01:28:09.764004 2023] [security2:error] [pid 3694776] [client 154.6.94.5:58982] [client 154.6.94.5] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.bocprivatebkhk.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.bocprivatebkhk.com"] [uri "/robots.txt"] [unique_id "ZWBCeU0CpMMHiWfPtX9GKAAAAAw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΏπ¦
Birdflew
|
|
Port scanning
|
Hacking
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 23 07:33:56.519669 2023] [security2:error] [pid 25328] [client 154.6.94.5:58992] [client 154.6.94.5] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.goikopro.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.goikopro.com"] [uri "/robots.txt"] [unique_id "ZV9GtLaS79LGG9XcCZBkfQAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 23 01:01:15.900033 2023] [security2:error] [pid 30229] [client 154.6.94.5:35294] [client 154.6.94.5] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.yongmeihu.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.yongmeihu.com"] [uri "/robots.txt"] [unique_id "ZV7qqwYwNXvV_Q7e8T2D8QAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 22 22:52:25.396711 2023] [security2:error] [pid 32142] [client 154.6.94.5:46500] [client 154.6.94.5] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.cityforsalefilm.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.cityforsalefilm.com"] [uri "/robots.txt"] [unique_id "ZV7MedqfC4pcCaUJp20KWgAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 22 19:45:22.720631 2023] [security2:error] [pid 1548] [client 154.6.94.5:51740] [client 154.6.94.5] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.riccardiagency.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.riccardiagency.com"] [uri "/robots.txt"] [unique_id "ZV6gorTEGjSZj6vPKm3kagAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210831) triggered by 154.6.94.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 22 18:19:30.667173 2023] [security2:error] [pid 595512] [client 154.6.94.5:57232] [client 154.6.94.5] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.guardmagic.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.guardmagic.com"] [uri "/robots.txt"] [unique_id "ZV6MgjLzeRFOWkQraRv9jQAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π«π·
uhlhosting
|
|
www.ravenselfdefense.com 154.6.94.5 - - [22/Nov/2023:22:27:26.129709 +0100] "GET /robots.txt HTTP/1. ...
show more
www.ravenselfdefense.com 154.6.94.5 - - [22/Nov/2023:22:27:26.129709 +0100] "GET /robots.txt HTTP/1.1" 403 199 "-" "-" ZV5yPqFgMupUyKoeKGxdbwAAAQI "-" /apache/20231122/20231122-2227/20231122-222726-ZV5yPqFgMupUyKoeKGxdbwAAAQI 0 1777 md5:747673a42b5278fce088efae9efa3099
www.ravenselfdefense.com 154.6.94.5 - - [22/Nov/2023:22:27:26.689259 +0100] "GET / HTTP/1.1" 403 199 "-" "-" ZV5yPqFgMupUyKoeKGxdcgAAAQA "-" /apache/20231122/20231122-2227/20231122-222726-ZV5yPqFgMupUyKoeKGxdcgAAAQA 0 1770 md5:ad82c4109330eef7f4c899b4a55b92d1
www.ravenselfdefense.com 154.6.94.5 - - [22/Nov/2023:22:27:26.890501 +0100] "GET /robots.txt HTTP/1.1" 403 199 "-" "-" ZV5yPqFgMupUyKoeKGxdcwAAAQM "-" /apache/20231122/20231122-2227/20231122-222726-ZV5yPqFgMupUyKoeKGxdcwAAAQM 0 1774 md5:6bd4b30c3a56e5b33d5b9eea68301385
www.ravenselfdefense.com 154.6.94.5 - - [22/Nov/2023:22:27:28.105099 +0100] "GET / HTTP/1.1" 403 199 "-" "-" ZV5yQHmVqZFNpx-EVkmaEgAAAEM "-" /apache/20231122/20231122-2227/20231122-222728-ZV5yQHmVq
...
show less
|
DDoS Attack
Brute-Force
|
|