πΊπΈ
TPI-Abuse
2024-03-31 03:07:06
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 30 23:07:01.238084 2024] [security2:error] [pid 19504] [client 157.97.122.8:58647] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gcigmbh.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gcigmbh.com"] [uri "/mysql.sql"] [unique_id "ZgjTVcrvqc-czU90azCtqwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-03-30 12:57:31
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 30 08:57:27.155225 2024] [security2:error] [pid 13247] [client 157.97.122.8:13421] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pigspolygon.xyz|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pigspolygon.xyz"] [uri "/mysql.sql"] [unique_id "ZggMN8HRO7p56ZlMEbJEqwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
10dencehispahard SL
2024-03-29 03:04:44
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
πΊπΈ
TPI-Abuse
2024-02-17 13:37:12
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 17 08:37:07.912087 2024] [security2:error] [pid 27635] [client 157.97.122.8:5709] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/old/emiltabet.com.sql"] [unique_id "ZdC2gwvmSir7hKSOhdPlhgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-17 13:15:33
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 17 08:15:30.603319 2024] [security2:error] [pid 18790:tid 47609269745408] [client 157.97.122.8:11039] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||liquido.cocoonprojects.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "liquido.cocoonprojects.com"] [uri "/bak/www.sql"] [unique_id "ZdCxcmn57d7eJ8N_PCbKaAAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-17 12:58:58
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 17 07:58:51.574480 2024] [security2:error] [pid 21745] [client 157.97.122.8:49865] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thegoldentether.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thegoldentether.com"] [uri "/bak/thegoldentether.com.sql"] [unique_id "ZdCti913oWtzhQyrjhc8rAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
MPL
2024-02-13 12:29:50
(2 years ago)
tcp/443 (18 or more attempts)
Port Scan
πΊπΈ
TPI-Abuse
2024-02-09 18:23:27
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 09 13:23:19.768822 2024] [security2:error] [pid 23144] [client 157.97.122.8:42683] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.panesarlaw.com"] [uri "/.env"] [unique_id "ZcZtlzP90mjztpnt-glZpQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-09 14:06:02
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 09 09:05:54.911007 2024] [security2:error] [pid 19464] [client 157.97.122.8:16413] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rcjlawfirm.com"] [uri "/.env"] [unique_id "ZcYxQhIknEM4koCa60XabQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-05 09:19:52
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 05 04:19:45.518550 2024] [security2:error] [pid 3655] [client 157.97.122.8:20299] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crypto-stamps.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crypto-stamps.com"] [uri "/backup/www.sql"] [unique_id "ZcCoMUe2nVrwZq--xSYMNQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-05 09:01:48
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 05 04:01:43.237324 2024] [security2:error] [pid 14589] [client 157.97.122.8:5745] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qualityelevatorcabs.com"] [uri "/back/.env"] [unique_id "ZcCj9wyxF1vDgborGmG1yQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΈ
Smel
2024-02-02 14:22:12
(2 years ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-01 21:46:57
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 01 16:46:52.409272 2024] [security2:error] [pid 6615] [client 157.97.122.8:20847] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dudleyanddudley.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dudleyanddudley.com"] [uri "/dudleyappraisers.com.sql"] [unique_id "ZbwRTGw1KCczK2I0P3CxrgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-31 02:40:56
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 157.97.122.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 30 21:40:50.364882 2024] [security2:error] [pid 15083] [client 157.97.122.8:2971] [client 157.97.122.8] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nationalenq.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nationalenq.com"] [uri "/backups/www.sql"] [unique_id "ZbmzMoaSy-syH8SKj5AADQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
oncord
2024-01-30 21:17:05
(2 years ago)
Form spam
Web Spam