|
๐ฉ๐ช
www.Examensfragen.de
|
|
|
Web Spam
Bad Web Bot
|
|
|
๐ฉ๐ช
conseilgouz
|
|
ece-22 : 8G : REQUEST_URI error=>/sftp-config.json
|
Hacking
|
|
|
๐ฉ๐ช
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
|
Exploited Host
Web App Attack
|
|
|
๐ซ๐ฎ
oh.mg
|
|
[Fri Jun 13 13:54:43.910000 2025] [security2:error] [pid 1856898:tid 1856929] [client 167.172.66.70: ...
show more
[Fri Jun 13 13:54:43.910000 2025] [security2:error] [pid 1856898:tid 1856929] [client 167.172.66.70:63888] [client 167.172.66.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mmn.on.ca"] [uri "/sftp-config.json"] [unique_id "aEwRgx5lIQJKVATWC2E3swAAABU"]
[Fri Jun 13 13:54:45.059632 2025] [security2:error] [pid 2059336:tid 2059349] [client 167.172.66.70:50308] [client 167.172.66.70] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"
...
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
conseilgouz
|
|
ame-Direct access to plugin not allowed
|
Hacking
|
|
|
๐ธ๐ช
Xpektor
|
|
Scanning for vulnerabilities
|
Hacking
Web App Attack
|
|
|
๐ซ๐ท
conseilgouz
|
|
sce-22 : 8G : REQUEST_URI error=>/sftp-config.json
|
Hacking
|
|
|
๐ซ๐ท
conseilgouz
|
|
sae-22 : 8G : REQUEST_URI error=>/sftp-config.json
|
Hacking
|
|
|
๐จ๐ญ
blinx
|
|
Suspicious activity detected by Modsecurity
|
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
Savoie
|
|
167.172.66.70 ***.*** - [13/Jun/2025:02:31:15 +0200] "GET /sftp-config.json HTTP/1.1" 302 224 "-" "M ...
show more
167.172.66.70 ***.*** - [13/Jun/2025:02:31:15 +0200] "GET /sftp-config.json HTTP/1.1" 302 224 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
167.172.66.70 ***.*** - [13/Jun/2025:02:31:17 +0200] "GET /.vscode/sftp.json HTTP/1.1" 302 224 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 167.172.66.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.66.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 12 20:29:26.085087 2025] [security2:error] [pid 4142196:tid 4142196] [client 167.172.66.70:55144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.calvarycavaliers.org"] [uri "/sftp-config.json"] [unique_id "aEtw5muNJLErOp9NdC3SRQAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
mnsf
|
|
Too many Status 40X (12)
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ท
Savoie
|
|
167.172.66.70 ***.*** - [13/Jun/2025:00:55:25 +0200] "GET /sftp-config.json HTTP/1.1" 302 225 "-" "M ...
show more
167.172.66.70 ***.*** - [13/Jun/2025:00:55:25 +0200] "GET /sftp-config.json HTTP/1.1" 302 225 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
167.172.66.70 ***.*** - [13/Jun/2025:00:55:26 +0200] "GET /.vscode/sftp.json HTTP/1.1" 302 225 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 167.172.66.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.66.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 12 16:33:51.220995 2025] [security2:error] [pid 993786:tid 993786] [client 167.172.66.70:53706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lunarinfrastructure.com"] [uri "/index.html/sftp-config.json"] [unique_id "aEs5r5kWt_Z9pL3F6G9pAgAAAA8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 167.172.66.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.66.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 12 15:44:02.394823 2025] [security2:error] [pid 1596516:tid 1596516] [client 167.172.66.70:52579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffr.com"] [uri "/sftp-config.json"] [unique_id "aEsuAk5OcoDunxIxcOzzjgAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|