๐ฉ๐ช
HandyTreff.de
2026-03-10 23:15:31
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -26.163 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -26.163 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa
show less
Web App Attack
Bad Web Bot
๐ฒ๐พ
Rizzy
2024-01-24 10:39:47
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2023-12-19 17:51:27
(2 years ago)
Malicious activity detected
Hacking
Brute-Force
Bad Web Bot
Exploited Host
๐ฉ๐ช
juutis
2023-12-19 05:54:35
(2 years ago)
[Tue Dec 19 06:54:14.263921 2023] [authz_core:error] [pid 1432569:tid 140191666784000] [client 191.1 ...
show more
[Tue Dec 19 06:54:14.263921 2023] [authz_core:error] [pid 1432569:tid 140191666784000] [client 191.101.41.191:0] AH01630: client denied by server configuration: /var/www/vhosts/taidesuunnistus.net/httpdocs/wp-content/uploads/index.php, referer: http://taidesuunnistus.net//wp-content/uploads/
[Tue Dec 19 06:54:14.843021 2023] [authz_core:error] [pid 1432569:tid 140192044259072] [client 191.101.41.191:0] AH01630: client denied by server configuration: /var/www/vhosts/taidesuunnistus.net/httpdocs/wp-content/plugins/index.php, referer: http://taidesuunnistus.net//wp-content/plugins/
[Tue Dec 19 06:54:34.853161 2023] [authz_core:error] [pid 1432630:tid 140191079589632] [client 191.101.41.191:0] AH01630: client denied by server configuration: /var/www/vhosts/taidesuunnistus.net/httpdocs/wp-content/plugins/install.php, referer: http://taidesuunnistus.net//wp-content/plugins/install.php
show less
Hacking
Brute-Force
๐ฒ๐พ
Rizzy
2023-12-19 02:39:37
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
uhlhosting
2023-12-17 16:42:01
(2 years ago)
taxigut.ch 191.101.41.191 - - [17/Dec/2023:17:41:56.756070 +0100] "GET //fox.php HTTP/1.1" 403 199 " ...
show more
taxigut.ch 191.101.41.191 - - [17/Dec/2023:17:41:56.756070 +0100] "GET //fox.php HTTP/1.1" 403 199 "-" "-" ZX8k1AHAnbU3d9PXnesJfgAAAAk "-" /apache/20231217/20231217-1741/20231217-174156-ZX8k1AHAnbU3d9PXnesJfgAAAAk 0 1650 md5:3afadcd111edab37f42016028a5780c5
taxigut.ch 191.101.41.191 - - [17/Dec/2023:17:41:57.171935 +0100] "GET //wp-content/plugins/linkpreview/wp-blog.php HTTP/1.1" 403 199 "-" "-" ZX8k1QHAnbU3d9PXnesJfwAAAAw "-" /apache/20231217/20231217-1741/20231217-174157-ZX8k1QHAnbU3d9PXnesJfwAAAAw 0 1720 md5:f23aef3ae3eb4561108053e94f9f38e8
taxigut.ch 191.101.41.191 - - [17/Dec/2023:17:41:57.627640 +0100] "GET //xx.php HTTP/1.1" 403 199 "-" "-" ZX8k1QHAnbU3d9PXnesJgAAAAAY "-" /apache/20231217/20231217-1741/20231217-174157-ZX8k1QHAnbU3d9PXnesJgAAAAAY 0 1648 md5:ffb3a083955fcae80a978c10370f9b3c
taxigut.ch 191.101.41.191 - - [17/Dec/2023:17:41:59.612613 +0100] "GET //sites/default/files/HolaDR7_70778.php HTTP/1.1" 403 199 "-" "-" ZX8k1wHAnbU3d9PXnesJgQAAAAM "-" /apache/20231217/202
...
show less
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2023-12-17 09:45:31
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 17 04:45:27.755240 2023] [security2:error] [pid 8537:tid 47811047470848] [client 191.101.41.191:19819] [client 191.101.41.191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexplows.org"] [uri "/.env"] [unique_id "ZX7DNwC7tV3vTx3H7OZpbgAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 04:55:11
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 16 23:55:06.806475 2023] [security2:error] [pid 14068] [client 191.101.41.191:18123] [client 191.101.41.191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "judithcaldwell.com"] [uri "/.env"] [unique_id "ZX5_KvIDAmdcvgNEYIWjVwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 02:44:12
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 16 21:44:06.234741 2023] [security2:error] [pid 3689] [client 191.101.41.191:26287] [client 191.101.41.191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samadmiraly.com"] [uri "/.env"] [unique_id "ZX5gdt6uBEJLTrysvWXOwQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-17 01:43:16
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 16 20:43:13.493898 2023] [security2:error] [pid 27203] [client 191.101.41.191:14213] [client 191.101.41.191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dancingorchidvillas.com"] [uri "/.env"] [unique_id "ZX5SMR6jhEKa3YCpgZkIOwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-16 22:53:59
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 16 17:53:54.263361 2023] [security2:error] [pid 7747:tid 47853927167744] [client 191.101.41.191:42399] [client 191.101.41.191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3penguinsphotography.com"] [uri "/.env"] [unique_id "ZX4qghoF2hIXXG38HQfL_wAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-16 17:44:10
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 191.101.41.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 16 12:44:06.440979 2023] [security2:error] [pid 5361] [client 191.101.41.191:44167] [client 191.101.41.191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "learningbyshipping.com"] [uri "/.env"] [unique_id "ZX3h5m3NfNjSw4hKUhOg9AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-12-16 12:23:02
(2 years ago)
Bot / scanning and/or hacking attempts: GET /1.php HTTP/1.1, GET //1.php HTTP/1.1, GET /classwithtos ...
show more
Bot / scanning and/or hacking attempts: GET /1.php HTTP/1.1, GET //1.php HTTP/1.1, GET /classwithtostring.php HTTP/1.1, GET //wp-content/plugins/index.php HTTP/1.1, GET //0z.php HTTP/1.1, GET //mini.php HTTP/1.1, GET /wp.php HTTP/1.1, GET //wp.php HTTP/1.1, GET //cloud.php HTTP/1.1, GET /user.php HTTP/1.1, GET /smm.php HTTP/1.1, GET /admin.php HTTP/1.1, GET //admin.php HTTP/1.1, GET //user.php HTTP/1.1, GET //classwithtostring.php HTTP/1.1, GET //byp.php HTTP/1.1, GET //gecko.php HTTP/1.1, GET /gecko.php HTTP/1.1, GET /cloud.php HTTP/1.1, GET /mini.php HTTP/1.1, GET /0z.php HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2023-12-16 12:02:49
(2 years ago)
Scanning/Probing (12)
Request Overload (223)
Brute-Force
Web App Attack
๐ณ๐ฑ
mawan
2023-12-16 10:39:03
(2 years ago)
Suspected of having performed illicit activity on AMS server.
Web App Attack