🇬🇧
findlab
2024-02-04 06:00:32
(2 years ago)
Backdrop CMS module - forbidden user agent
Bad Web Bot
Web App Attack
🇬🇧
Swiptly
2024-02-02 05:12:10
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
🇧🇷
diego
2024-01-31 16:57:22
(2 years ago)
[kvm3859] 01/31/2024-13:57:21.917935, 191.252.111.55, Protocol: 6, ET TOR Known Tor Exit Node Traffi ...
show more
[kvm3859] 01/31/2024-13:57:21.917935, 191.252.111.55, Protocol: 6, ET TOR Known Tor Exit Node Traffic group 61
show less
Hacking
🇧🇷
diego
2024-01-31 15:39:02
(2 years ago)
[kvm3859] 01/31/2024-12:39:02.322206, 191.252.111.55, Protocol: 6, ET TOR Known Tor Exit Node Traffi ...
show more
[kvm3859] 01/31/2024-12:39:02.322206, 191.252.111.55, Protocol: 6, ET TOR Known Tor Exit Node Traffic group 61
show less
Hacking
🇩🇪
niceshops.com
2024-01-30 18:20:22
(2 years ago)
Web Attack ([30/Jan/2024:19:20:13 +0100] )
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-01-29 08:26:28
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 191.252.111.55 (vps40865.publiccloud.com.br): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 191.252.111.55 (vps40865.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 29 03:26:25.152721 2024] [security2:error] [pid 16478] [client 191.252.111.55:55654] [client 191.252.111.55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ciamedicare.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ciamedicare.com"] [uri "/ciamedicar.sql"] [unique_id "ZbdhMVjNn4DW3W-95YQ-iAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-01-29 05:44:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 191.252.111.55 (vps40865.publiccloud.com.br): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 191.252.111.55 (vps40865.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 29 00:44:22.927778 2024] [security2:error] [pid 17883:tid 47222431422208] [client 191.252.111.55:50930] [client 191.252.111.55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kosho-ryu-kenpo.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kosho-ryu-kenpo.com"] [uri "/1.sql"] [unique_id "Zbc7NvCIh3ZtBBAHN_5pfwAAAZQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-01-28 06:17:55
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 191.252.111.55 (vps40865.publiccloud.com.br): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 191.252.111.55 (vps40865.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 28 01:17:49.877632 2024] [security2:error] [pid 22528] [client 191.252.111.55:37462] [client 191.252.111.55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||somehand.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "somehand.com"] [uri "/somehan.sql"] [unique_id "ZbXxjaWOYIYelXgrXfaiNAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-01-27 00:38:30
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 191.252.111.55 (vps40865.publiccloud.com.br): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 191.252.111.55 (vps40865.publiccloud.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 26 19:38:24.192861 2024] [security2:error] [pid 3094] [client 191.252.111.55:43162] [client 191.252.111.55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gjbenches.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gjbenches.com"] [uri "/benches.sql"] [unique_id "ZbRQgI4TiIVz02yEQ3k-6gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Packets-Decreaser.NET
2024-01-25 16:00:32
(2 years ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇺🇸
icllc-webadmin
2024-01-25 14:07:29
(2 years ago)
[Thu Jan 25 08:07:26.772172 2024] [access_compat:error] [pid 6859] [client 191.252.111.55:49948] AH0 ...
show more
[Thu Jan 25 08:07:26.772172 2024] [access_compat:error] [pid 6859] [client 191.252.111.55:49948] AH01797: client denied by server configuration: /var/www/gaylydaily.us/html/xmlrpc.php
[Thu Jan 25 08:07:27.633149 2024] [access_compat:error] [pid 6859] [client 191.252.111.55:49948] AH01797: client denied by server configuration: /var/www/gaylydaily.us/html/xmlrpc.php
[Thu Jan 25 08:07:28.282724 2024] [access_compat:error] [pid 6859] [client 191.252.111.55:49948] AH01797: client denied by server configuration: /var/www/gaylydaily.us/html/xmlrpc.php
[Thu Jan 25 08:07:29.074784 2024] [access_compat:error] [pid 6859] [client 191.252.111.55:49948] AH01797: client denied by server configuration: /var/www/gaylydaily.us/html/xmlrpc.php
...
show less
Hacking
Brute-Force
Anonymous
2024-01-19 12:16:47
(2 years ago)
www.fahrlehrerfortbildung-hessen.de 191.252.111.55 [19/Jan/2024:13:16:42 +0100] "POST /xmlrpc.php HT ...
show more
www.fahrlehrerfortbildung-hessen.de 191.252.111.55 [19/Jan/2024:13:16:42 +0100] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36"
www.fahrlehrerfortbildung-hessen.de 191.252.111.55 [19/Jan/2024:13:16:46 +0100] "POST /xmlrpc.php HTTP/1.1" 200 5498 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36"
show less
Web App Attack
🇩🇪
niceshops.com
2024-01-18 16:57:10
(2 years ago)
Web Attack multi (Jan 24 17:57:10 Matching rules: Detect possible SQL injection - E.g. Select * fro ...
show more
Web Attack multi (Jan 24 17:57:10 Matching rules: Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
MAGIC
2024-01-16 18:10:58
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇩🇪
niceshops.com
2024-01-13 21:24:48
(2 years ago)
Web Attack multi (Jan 24 22:24:47 Matching rules: Detect possible SQL injection - E.g. Select * fro ...
show more
Web Attack multi (Jan 24 22:24:47 Matching rules: Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack