|
๐ซ๐ท
adembaysal
|
|
Domain : bahukuk.com
Rule : wp-login
2025-11-08 19:50:34 ***hidden-privacy*** GET /wp-login.php - 44 ...
show more
Domain : bahukuk.com
Rule : wp-login
2025-11-08 19:50:34 ***hidden-privacy*** GET /wp-login.php - 443 - 194.99.25.81 HTTP/1.1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 https://www.google.com bahukuk.com 404 0 2 1543 252 189 - -
show less
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 194.99.25.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 194.99.25.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 01:25:19.895830 2025] [security2:error] [pid 626790:tid 626790] [client 194.99.25.81:57311] [client 194.99.25.81] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Churchill II Recliner/Churchill II/Double Fudge/Thumbs.db"] [unique_id "aBmdPxjpCr4sNK7UX7yBJwAAABY"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Churchill%20II%20Recliner/Churchill%20II/Double%20Fudge/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 194.99.25.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 194.99.25.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 01 04:09:07.318660 2024] [security2:error] [pid 3739839:tid 3739839] [client 194.99.25.81:23765] [client 194.99.25.81] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Golden-Technologies/pics/Golden Technologies 2009 Marketing CD/Power Chairs/Alante/Thumbs.db"] [unique_id "Z0wns-3c7J-I8sTJjLfrmAAAAAI"], referer: https://vitalitywebb.com/backstore/Golden-Technologies/pics/Golden%20Technologies%202009%20Marketing%20CD/Power%20Chairs/Alante/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 194.99.25.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 194.99.25.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 17 19:11:18.157268 2024] [security2:error] [pid 3552:tid 3552] [client 194.99.25.81:36693] [client 194.99.25.81] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "ZzqGJiRwQ04pcLV_I-J8wgAAAAg"], referer: http://answers.google.com/answers/threadview/id/552967.html
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ญ
backslash
|
|
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
|
Bad Web Bot
|
|
|
Anonymous
|
|
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
|
Web App Attack
|
|
|
Anonymous
|
|
Web Attack Palo Alto Networks GlobalProtect Authentication Attempt
|
Web App Attack
|
|
|
Anonymous
|
|
Failed password for invalid user HVAC port 443 SSLPVN" "
|
VPN IP
Brute-Force
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
Anonymous
|
|
Failed password for invalid user operator from 194.99.25.81
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 194.99.25.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 194.99.25.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 28 23:48:53.561050 2024] [security2:error] [pid 32029] [client 194.99.25.81:13747] [client 194.99.25.81] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portalvasco.com|F|2"] [data ".vexiafinder.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portalvasco.com"] [uri "/blog/2011/03/crambo-wireless-proceso-logistico-citet/www.vexiafinder.com"] [unique_id "ZeAMtWIAIYPyMAn8VEDG9gAAAAI"], referer: https://portalvasco.com/blog/2011/03/crambo-wireless-proceso-logistico-citet/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ญ
backslash
|
|
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
|
Bad Web Bot
|
|
|
๐จ๐ญ
backslash
|
|
honeypot
|
Bad Web Bot
|
|