Anonymous
2024-07-17 01:45:52
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-07-02 07:08:47
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 02 03:08:25.530142 2024] [security2:error] [pid 26884] [client 179.43.112.98:43110] [client 179.43.112.98] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||glaswood.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "glaswood.com"] [uri "/blog.bak"] [unique_id "ZoOnabfwXiigHetaN9k5OwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-06-26 08:13:44
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ช๐ธ
10dencehispahard SL
2024-06-25 20:02:53
(2 years ago)
Unauthorized login attempts [ bot_accesslogs]
Brute-Force
๐ฉ๐ช
FeG Deutschland
2024-06-25 06:14:02
(2 years ago)
Looking for CMS/PHP/SQL vulnerablilities - 13
Exploited Host
Web App Attack
Anonymous
2024-06-25 03:56:41
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-06-20 11:57:16
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 20 07:57:11.260838 2024] [security2:error] [pid 10015] [client 179.43.112.98:49476] [client 179.43.112.98] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kavahawaii.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kavahawaii.com"] [uri "/data.bak"] [unique_id "ZnQZF517AvXdN2HUqfZUHQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-09 12:51:19
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 09 08:51:13.907332 2024] [security2:error] [pid 11968] [client 179.43.112.98:48564] [client 179.43.112.98] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||britishfolk.org|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "britishfolk.org"] [uri "/britishfolk.bak"] [unique_id "ZmWlQeDVNYbqgBODbC-W9AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-08 14:20:45
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 08 10:20:39.434614 2024] [security2:error] [pid 16532] [client 179.43.112.98:50692] [client 179.43.112.98] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||30daysout.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "30daysout.com"] [uri "/website.bak"] [unique_id "ZmRot-4XBCRnPH2d_3AuOAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-05 05:15:08
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 05 01:15:04.180157 2024] [security2:error] [pid 4112] [client 179.43.112.98:39618] [client 179.43.112.98] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aimer.es|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aimer.es"] [uri "/backup.bak"] [unique_id "Zl_0WJwdI7zNiYK2XiPmpQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-05 01:24:37
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 i ...
show more
(mod_security) mod_security (id:210730) triggered by 179.43.112.98 (vps-3123330-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 04 21:24:31.859333 2024] [security2:error] [pid 11869] [client 179.43.112.98:38008] [client 179.43.112.98] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anenglishcottage.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anenglishcottage.com"] [uri "/wp-admin.bak"] [unique_id "Zl--T8vPhsODR7L4j3usZgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2024-05-31 21:54:28
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack