๐ฉ๐ช
elm-st
2025-03-27 08:43:00
(1 year ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2025-03-26 20:29:18
(1 year ago)
nginx:Illicit login attempts to the CMS, or investigation into CMS plugins with vulnerabilities.
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 19:06:04
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 15:05:58.908782 2025] [security2:error] [pid 1555508:tid 1555508] [client 172.177.67.163:8412] [client 172.177.67.163] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||herstonfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "herstonfarm.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-RQFujNgnYtyn7AxXSfggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-03-26 19:05:40
(1 year ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2025-03-26 19:05:22
(1 year ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
๐ง๐ท
leolemos
2025-03-26 17:23:56
(1 year ago)
[Wed Mar 26 14:21:21.064267 2025] [proxy_fcgi:error] [pid 2842724:tid 259464737255616] [client 172.1 ...
show more
[Wed Mar 26 14:21:21.064267 2025] [proxy_fcgi:error] [pid 2842724:tid 259464737255616] [client 172.177.67.163:0] AH01071: Got error 'Primary script unknown'
[Wed Mar 26 14:22:59.402071 2025] [proxy_fcgi:error] [pid 2669986:tid 259464694984896] [client 172.177.67.163:0] AH01071: Got error 'Primary script unknown'
[Wed Mar 26 14:23:54.533980 2025] [proxy_fcgi:error] [pid 2886516:tid 259465979097280] [client 172.177.67.163:0] AH01071: Got error 'Primary script unknown'
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 14:44:13
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 10:44:08.942041 2025] [security2:error] [pid 21718:tid 21718] [client 172.177.67.163:5082] [client 172.177.67.163] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||eefinchco.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "eefinchco.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-QSuAJedzDqii0JHKNWjQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 13:25:25
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 09:25:19.334579 2025] [security2:error] [pid 6264:tid 6264] [client 172.177.67.163:7034] [client 172.177.67.163] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||photojeniq.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "photojeniq.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-QAPxCmQJjwxLQI9mTrcwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 12:48:08
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 08:48:02.595985 2025] [security2:error] [pid 19256:tid 19309] [client 172.177.67.163:4929] [client 172.177.67.163] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||wallstreetglobe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "wallstreetglobe.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-P3gnrmk7ZLgOOqeukZxgAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-03-26 12:03:36
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
antlac1
2025-03-26 11:42:44
(1 year ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2025-03-26 11:32:48
(1 year ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 172.177.67.163 (US/Unite ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 172.177.67.163 (US/United States/-)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-03-26 11:17:20
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 07:17:14.460137 2025] [security2:error] [pid 4991:tid 4991] [client 172.177.67.163:11147] [client 172.177.67.163] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||microdot.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "microdot.net"] [uri "/images/stories/admin-post.php"] [unique_id "Z-PiOmBJWmnNlzOQMdj7DgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-03-26 10:59:22
(1 year ago)
15.641 4xx requests in 1 hour (2w2d11h)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-03-26 10:13:49
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 172.177.67.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 06:13:42.353260 2025] [security2:error] [pid 32141:tid 32141] [client 172.177.67.163:9735] [client 172.177.67.163] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||natasways.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "natasways.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-PTVjd4TDhxdRM4wNHoywAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack