๐ฉ๐ช
dayda.net
2024-12-04 02:50:02
(1 year ago)
query: option=com_dwgraphs&controller=../../../../../../../../etc/passwd%00
Bad Web Bot
๐ฉ๐ช
ps-center
2024-11-27 02:50:26
(1 year ago)
SS1: Web Attack GET /wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_ms ...
show more
SS1: Web Attack GET /wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php?page=%22%2F%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E%3Cb
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-27 02:32:35
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 26 22:29:50.604152 2024] [security2:error] [pid 12545:tid 12616] [client 161.123.5.131:42767] [client 161.123.5.131] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||autodiscover.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_cartweberp&controller=../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kettlehill.net"] [uri "/index.php"] [unique_id "Zx2lnj4Zp7GZDS7DVHfcrgAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-04 00:35:24
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 20:35:19.966360 2024] [security2:error] [pid 17471:tid 17471] [client 161.123.5.131:39095] [client 161.123.5.131] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stdavids-media.com"] [uri "/wp-content/plugins/wpsite-background-takeover/exports/download.php"] [unique_id "ZterR0UWJXe-Y8ecb_bVGwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-22 10:16:07
(1 year ago)
161.123.5.131 - - [22/Aug/2024:12:16:06 +0200] "GET /index.php?option=com_extplorer&action=show_erro ...
show more
161.123.5.131 - - [22/Aug/2024:12:16:06 +0200] "GET /index.php?option=com_extplorer&action=show_error&dir=..%2F..%2F..%2F%2F..%2F..%2Fetc%2Fpasswd HTTP/1.1" 301 5703 "http://solgar.be/index.php?option=com_extplorer&action=show_error&dir=..%2F..%2F..%2F%2F..%2F..%2Fetc%2Fpasswd" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" 2647
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2024-08-01 00:43:54
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 31 20:43:30.202700 2024] [security2:error] [pid 27402:tid 27413] [client 161.123.5.131:33371] [client 161.123.5.131] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.staging.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?sl=../../../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.kettlehill.com"] [uri "/index.php"] [unique_id "ZqraMgwzJqHzsBLvMCVqVgAAAcU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-07-15 19:20:24
(1 year ago)
SS1: Web Attack GET /admin/error.log
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-07-14 01:02:53
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
Anonymous
2024-05-08 17:02:00
(2 years ago)
XSS attempted, seen in log review
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:01:07
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 06:50:09
(2 years ago)
WP scan
Web App Attack
Anonymous
2024-03-06 01:31:46
(2 years ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-27 23:18:59
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 27 18:17:23.350834 2024] [security2:error] [pid 5379:tid 47108561635072] [client 161.123.5.131:34853] [client 161.123.5.131] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.staging.kettlehill.com"] [uri "/web.config.copy"] [unique_id "Zd5tg3peprykeOeYz0XbXwAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-26 13:27:00
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 161.123.5.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 26 08:26:21.172142 2024] [security2:error] [pid 9782] [client 161.123.5.131:52721] [client 161.123.5.131] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||stdavids-media.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stdavids-media.com"] [uri "/application/logs/default.log"] [unique_id "ZbOy_c81cBLbnrwCeZOuwAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack