๐บ๐ธ
TPI-Abuse
2025-04-29 17:28:28
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 185.38.175.133 (torexit.labitat.dk): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 185.38.175.133 (torexit.labitat.dk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 13:28:20.403142 2025] [security2:error] [pid 1425275:tid 1425275] [client 185.38.175.133:37260] [client 185.38.175.133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "datebynumber.com"] [uri "/wp-config.php.CloudTech_bak"] [unique_id "aBEMNFPVSwZARdIHgmjzcgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Samsteve169
2025-04-25 23:04:00
(1 year ago)
Received DDoS attack through Cloudflare
DDoS Attack
๐ฉ๐ช
LRob
2025-04-18 11:15:08
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ง๐ช
cmbplf
2025-04-18 03:58:11
(1 year ago)
16.388 POST requests in 1 hour (2w4d12h)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2025-04-13 13:57:29
(1 year ago)
15 attempts against mh-mag-login-ban on neon
Web App Attack
๐ฆ๐บ
MAGIC
2025-04-04 05:00:50
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-03-30 14:41:58
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฎ๐น
Progetto1
2025-03-27 00:34:02
(1 year ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฆ๐บ
oncord
2025-03-23 00:05:24
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-03-22 00:20:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.38.175.133 (torexit.labitat.dk): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 185.38.175.133 (torexit.labitat.dk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 21 20:20:24.920085 2025] [security2:error] [pid 15902:tid 15902] [client 185.38.175.133:37160] [client 185.38.175.133] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tntserv.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tntserv.com"] [uri "/wp.sql"] [unique_id "Z94CSIXSCb2OEP5B6-hSeQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-18 01:16:31
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Packets-Decreaser.NET
2025-03-17 22:42:58
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-03-07 04:32:44
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 185.38.175.133 (torexit.labitat.dk): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 185.38.175.133 (torexit.labitat.dk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 06 23:32:36.688627 2025] [security2:error] [pid 18866:tid 18868] [client 185.38.175.133:58242] [client 185.38.175.133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "culturallyyours.org"] [uri "/wp-config.php-work"] [unique_id "Z8p25OKNUm9j9epFfaw4twAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-01 16:45:27
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 185.38.175.133 (torexit.labitat.dk): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 185.38.175.133 (torexit.labitat.dk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 01 11:45:21.653436 2025] [security2:error] [pid 11939:tid 11939] [client 185.38.175.133:45292] [client 185.38.175.133] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||add-a-heading.xyz|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "add-a-heading.xyz"] [uri "/add-a-headin.sql"] [unique_id "Z8M5obOaq7Z324I3S5KWNgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-10 06:19:01
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH