๐ฉ๐ช
SCHAPPY
2025-08-11 22:50:04
(10 months ago)
IP was involved in L7 DDoS attack.
DDoS Attack
๐ฉ๐ช
ps-center
2024-11-27 08:05:19
(1 year ago)
SS1: Web Attack GET /wp-admin/admin-ajax.php?action=swpm_validate_email&fieldId=%22%3Cscript%3Ealert ...
show more
SS1: Web Attack GET /wp-admin/admin-ajax.php?action=swpm_validate_email&fieldId=%22%3Cscript%3Ealert(document.domain)%3C/script%3E
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-26 23:17:11
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 198.46.202.184 (198-46-202-184-host.colocrossin ...
show more
(mod_security) mod_security (id:221260) triggered by 198.46.202.184 (198-46-202-184-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 26 18:13:50.745813 2024] [security2:error] [pid 25797:tid 25829] [client 198.46.202.184:49859] [client 198.46.202.184] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||whm.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.kettlehill.com"] [uri "/cgi-bin/status"] [unique_id "Z0ZWLvOl7Gndrsk5ZlXKOwAAAUw"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2024-11-22 03:36:50
(1 year ago)
query: ../../../../../../../../etc/passwd
Bad Web Bot
Anonymous
2024-10-18 00:25:21
(1 year ago)
Malicious activity detected
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-09-01 01:51:24
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 198.46.202.184 (198-46-202-184-host.colocrossin ...
show more
(mod_security) mod_security (id:211190) triggered by 198.46.202.184 (198-46-202-184-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:51:06.126888 2024] [security2:error] [pid 3087700:tid 3087734] [client 198.46.202.184:48947] [client 198.46.202.184] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /horde/util/barcode.php?type=../../../../../../../../../../../etc/./passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kettlehill.net"] [uri "/horde/util/barcode.php"] [unique_id "ZtPIityH84duF-C5mXVFVAAAAYQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-07-02 12:51:17
(1 year ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-29 18:03:13
(1 year ago)
Suspicious activity detected by Modsecurity [Suspicious IP found on 6 endpoints 17 hits. Reincident ...
show more
Suspicious activity detected by Modsecurity [Suspicious IP found on 6 endpoints 17 hits. Reincident by 0. Rules:]
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-27 06:49:48
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 198.46.202.184 (198-46-202-184-host.colocrossin ...
show more
(mod_security) mod_security (id:225170) triggered by 198.46.202.184 (198-46-202-184-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 02:47:36.203511 2024] [security2:error] [pid 12188:tid 47878022117120] [client 198.46.202.184:50177] [client 198.46.202.184] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "staging.kettlehill.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zn0LCAhxD9A54knTHIMdQgAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:41:03
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2024-04-10 05:35:03
(2 years ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-03 18:32:50
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 198.46.202.184 (198-46-202-184-host.colocrossin ...
show more
(mod_security) mod_security (id:210730) triggered by 198.46.202.184 (198-46-202-184-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 03 14:32:46.302999 2024] [security2:error] [pid 29639:tid 47764755175168] [client 198.46.202.184:51167] [client 198.46.202.184] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||staging.kettlehill.com|F|2"] [data ".com.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staging.kettlehill.com"] [uri "/kettlehill.com.db"] [unique_id "Zg2gzkMbCuCCUcnq7J_G4QAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 06:46:40
(2 years ago)
WP scan
Web App Attack