๐บ๐ธ
TPI-Abuse
2024-11-13 21:50:28
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 162.158.78.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 162.158.78.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 13 16:50:24.021856 2024] [security2:error] [pid 4880:tid 4880] [client 162.158.78.204:34632] [client 162.158.78.204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 208.97.187.201 (0+1 hits since last alert)|avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avaliantlife.com"] [uri "/xmlrpc.php"] [unique_id "ZzUfIDDbEZvRmoCkirR-UAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
appuni
2024-09-01 01:41:11
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 162.158.78.204 (US/U ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 162.158.78.204 (US/United States/-): (CF_ENABLE)
show less
Bad Web Bot
Anonymous
2024-06-21 01:26:28
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ช๐ธ
el-brujo
2024-06-15 22:54:54
(1 year ago)
16/Jun/2024:00:54:54.171690 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
16/Jun/2024:00:54:54.171690 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 162.158.78.204] ModSecurity: Warning. Pattern match "(?i:sleep\\\\\\\\(\\\\\\\\s*?\\\\\\\\d*?\\\\\\\\s*?\\\\\\\\)|benchmark\\\\\\\\(.*?\\\\\\\\,.*?\\\\\\\\))" at ARGS:image. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "126"] [id "942160"] [msg "Detects blind sqli tests using sleep() or benchmark()"] [data "Matched Data: sleep(15) found within ARGS:image: or 0 in (select sleep(15) ) -- "] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [hostname "warzone.elhacker.net"] [uri "/blog/2007/05/reg.php"] [unique_id "Zm4bvpvhkfFRKhFYUyqtogACOxg"]
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2024-06-14 00:53:16
(1 year ago)
14/Jun/2024:02:53:12.902849 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
14/Jun/2024:02:53:12.902849 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 162.158.78.204] ModSecurity: Warning. Matched phrase "<!--" at ARGS:image. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "251"] [id "941180"] [msg "Node-Validator Blacklist Keywords"] [data "Matched Data: <!-- found within ARGS:image: <!--#exec cmd=\\\\x22dir \\\\x22-->"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/242"] [hostname "warzone.elhacker.net"] [uri "/blog/reg.php"] [unique_id "ZmuUeEhKsk5-e3Yo56vX1gAA7SI"]
...
show less
Hacking
Web App Attack
Anonymous
2024-05-29 04:07:12
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-26 09:17:08
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-04-16 22:38:16
(2 years ago)
(mod_security) mod_security (id:211190) triggered by 162.158.78.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 162.158.78.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 16 18:38:03.096558 2024] [security2:error] [pid 1356] [client 162.158.78.204:44412] [client 162.158.78.204] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||barracuda.assistguide.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /wp-content/plugins/site-editor/editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php?ajax_path=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barracuda.assistguide.com"] [uri "/wp-content/plugins/site-editor/editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php"] [unique_id "Zh79y68oyYzLkPDvf-LAUQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
syokadmin
2024-03-25 08:41:01
(2 years ago)
(mod_security) mod_security (id:77317941) triggered by 162.158.78.204 (US/United States/-): 1 in the ...
show more
(mod_security) mod_security (id:77317941) triggered by 162.158.78.204 (US/United States/-): 1 in the last 3600 secs
show less
Brute-Force
Anonymous
2024-03-16 07:52:30
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2023-08-20 22:22:41
(2 years ago)
(wordpress) Failed wordpress login from 162.158.78.204 (US/United States/-)
Brute-Force
๐ฟ๐ฆ
Birdflew
2023-08-19 23:28:26
(2 years ago)
Wordpress attack
Web App Attack
๐ฉ๐ช
vhnmn
2023-08-19 18:36:22
(2 years ago)
xmlrpc attack blocked attempt from fail2ban
...
Web App Attack
Anonymous
2023-08-18 21:04:21
(2 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2023-07-30 04:11:56
(2 years ago)
Wordpress malicious attack:[octablocked]
Web App Attack