π³π±
Linuxmalwarehuntingnl
2024-07-03 08:56:56
(2 years ago)
Unauthorized connection attempt
Brute-Force
π¬π§
jethro1
2024-05-22 16:13:00
(2 years ago)
Thousands of wp- type urls over a short space of time often the same urls over and over again all b ...
show more
Thousands of wp- type urls over a short space of time often the same urls over and over again all blocked - amature nuisance
show less
Hacking
πΊπΈ
TPI-Abuse
2024-05-20 00:57:37
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 19 20:57:32.495972 2024] [security2:error] [pid 26129:tid 47435724404480] [client 194.233.88.234:55908] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||15thfar.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "15thfar.org"] [uri "/site/default/settings.php.BAK"] [unique_id "Zkqf_D1F9otiD7xruT5wBwAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ps-center
2024-05-19 22:50:58
(2 years ago)
C1: Web Attack GET /wp-admin/css/colors/blue/CasperExV1.php GET /wp-content/index.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
hostseries
2024-05-19 17:18:27
(2 years ago)
Trigger: LF_MODSEC
Brute-Force
πΊπΈ
TPI-Abuse
2024-05-19 14:34:19
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 19 10:34:13.957131 2024] [security2:error] [pid 2098026] [client 194.233.88.234:57218] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||annyoneyoga.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "annyoneyoga.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZkoN5QCubHRz4v49-nBWJQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-05-19 10:03:00
(2 years ago)
Repeated amateurish hacking attempts - over 2000 in just a few hours - now tarpitted for LIFE - ...
show more
Repeated amateurish hacking attempts - over 2000 in just a few hours - now tarpitted for LIFE - well done, you got nowhere!
show less
Hacking
Brute-Force
Anonymous
2024-05-19 05:05:10
(2 years ago)
server 1
Web App Attack
πΊπΈ
TPI-Abuse
2024-05-19 01:26:13
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 18 21:26:06.591716 2024] [security2:error] [pid 17764] [client 194.233.88.234:59685] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||roigcorporativo.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "roigcorporativo.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZklVLlmOlvHdYzNU9swDtwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-05-18 17:40:40
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 18 13:40:31.694207 2024] [security2:error] [pid 27718] [client 194.233.88.234:56752] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shay.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shay.org"] [uri "/site/default/settings.php.BAK"] [unique_id "ZkjoD05_0_0cnxLrUnO0vAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-05-18 14:20:53
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 18 10:20:48.499260 2024] [security2:error] [pid 2951] [client 194.233.88.234:56310] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "book-arts-press.com"] [uri "/wp-config.php"] [unique_id "Zki5QII68hgOT_dkZyrb0wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-05-18 12:09:48
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 18 08:09:40.673703 2024] [security2:error] [pid 18890] [client 194.233.88.234:60786] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||isaacsonpaintings.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "isaacsonpaintings.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZkiahET9vhpcXZ4qKMHPBAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-05-18 05:05:16
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 18 01:05:08.374187 2024] [security2:error] [pid 5763] [client 194.233.88.234:61290] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||nielectricalsales.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nielectricalsales.com"] [uri "/site/default/settings.php.BAK"] [unique_id "Zkg3BHxX_gtmB7KrSUsgSwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-05-18 04:40:33
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 18 00:40:27.827687 2024] [security2:error] [pid 25743] [client 194.233.88.234:50775] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arcdesign.me|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arcdesign.me"] [uri "/site/default/settings.php.BAK"] [unique_id "ZkgxOyq_XfN42PQIyeI38gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-05-18 03:09:25
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 194.233.88.234 (vmi1865465.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 17 23:09:18.234140 2024] [security2:error] [pid 10753] [client 194.233.88.234:58488] [client 194.233.88.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||weathercarib.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "weathercarib.com"] [uri "/site/default/settings.php.BAK"] [unique_id "Zkgb3qTzbYkdW4Ikm1ySxgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack