๐บ๐ธ
TheMadBeaker
2024-11-25 08:22:43
(1 year ago)
Fail2Ban Ban Triggered
HTTP SQL Injection Attempt
Hacking
SQL Injection
๐ณ๐ฑ
Savvii
2024-08-26 17:31:16
(2 years ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-22 08:28:15
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 22 04:28:11.309834 2024] [security2:error] [pid 22866:tid 22866] [client 198.98.183.144:1336] [client 198.98.183.144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "erinrusso.com"] [uri "/wp-config.php"] [unique_id "Zsb2m33CAoiVs2Y3_UsmqgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-19 02:25:06
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 22:24:58.452245 2024] [security2:error] [pid 1607392:tid 1607392] [client 198.98.183.144:1401] [client 198.98.183.144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ctjcisenate.org"] [uri "/wp-config.php"] [unique_id "ZsKs-qFUv_FZOp_1hcbxMQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 20:28:39
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 16:28:34.404987 2024] [security2:error] [pid 13136:tid 13154] [client 198.98.183.144:1369] [client 198.98.183.144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosureinternetservices.com"] [uri "/wp-config.php"] [unique_id "Zr5k8vqV9qbIrAHyoxYxCAAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-15 03:48:31
(2 years ago)
wordpress-trap
Web App Attack
๐ฉ๐ช
updown.io
2024-08-13 00:05:55
(2 years ago)
{"level":"info","ts":1723507535.8203847,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1723507535.8203847,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"198.98.183.144","remote_port":"1872","proto":"HTTP/1.1","method":"GET","host":"4gz4.status.updown.io","uri":"/templates/beez_20/","headers":{"User-Agent":["fasthttp"]}},"user_id":"","duration":0.000047411,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://4gz4.status.updown.io/templates/beez_20/"],"Content-Type":[]}}
{"level":"info","ts":1723507536.016591,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"198.98.183.144","remote_port":"1925","proto":"HTTP/1.1","method":"GET","host":"4gz4.status.updown.io","uri":"/images/icons/","headers":{"User-Agent":["fasthttp"]}},"user_id":"","duration":0.000049323,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://4gz4.status.updown.io/images/icons/"],"Content-Type":[]}}
{"level":"info","ts":1723507536.2
...
show less
DDoS Attack
Web App Attack
Anonymous
2024-08-11 16:50:12
(2 years ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-11 12:32:41
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 08:32:37.757786 2024] [security2:error] [pid 16955:tid 16955] [client 198.98.183.144:1132] [client 198.98.183.144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitalitywebb.com"] [uri "/wp-config.php"] [unique_id "ZrivZU6P7GsvgWwqgQqBFQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-10 21:28:51
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 17:28:44.429722 2024] [security2:error] [pid 811:tid 811] [client 198.98.183.144:1183] [client 198.98.183.144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homebuilt.org"] [uri "/wp-config.php"] [unique_id "ZrfbjLUKaJhx0CwrtSUIbAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2024-08-10 20:06:11
(2 years ago)
Scanning/Probing (42)
Request Overload (1250)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-10 19:40:26
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 15:40:22.407647 2024] [security2:error] [pid 27578:tid 27578] [client 198.98.183.144:2452] [client 198.98.183.144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billdavidow.virlouise.com"] [uri "/wp-config.php"] [unique_id "ZrfCJnPQx2jLufUtSOk8lgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-10 12:22:56
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.98.183.144 (r-144-183-98-198.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 10 08:22:52.496554 2024] [security2:error] [pid 7935:tid 7935] [client 198.98.183.144:1089] [client 198.98.183.144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title23.com"] [uri "/wp-config.php"] [unique_id "ZrdbnG4J_W5zoRw67voj7QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-10 08:12:34
(2 years ago)
198.98.183.144 - - [10/Aug/2024:10:12:02 +0200] "GET /wp-includes/sodium_compat/ HTTP/1.1" 404 447 " ...
show more
198.98.183.144 - - [10/Aug/2024:10:12:02 +0200] "GET /wp-includes/sodium_compat/ HTTP/1.1" 404 447 "-" "fasthttp"
198.98.183.144 - - [10/Aug/2024:10:12:02 +0200] "GET /wps/wp-includes/widgets/ HTTP/1.1" 404 447 "-" "fasthttp"
198.98.183.144 - - [10/Aug/2024:10:12:02 +0200] "GET /wp-includes/js/codemirror/ HTTP/1.1" 404 447 "-" "fasthttp"
198.98.183.144 - - [10/Aug/2024:10:12:03 +0200] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 404 447 "-" "fasthttp"
198.98.183.144 - - [10/Aug/2024:10:12:03 +0200] "GET /wp-includes/Requests/Transport/ HTTP/1.1" 404 447 "-" "fasthttp"
198.98.183.144 - - [10/Aug/2024:10:12:03 +0200] "GET /wp-admin/css/colors/ocean/ HTTP/1.1" 404 447 "-" "fasthttp"
198.98.183.144 - - [10/Aug/2024:10:12:03 +0200] "GET /wp-admin/css/colors/sunrise/ HTTP/1.1" 404 447 "-" "fasthttp"
198.98.183.144 - - [10/Aug/2024:10:12:03 +0200] "GET /wp-includes/rest-api/fields/ HTTP/1.1" 404 447 "-" "fasthttp"
198.98.183.144 - - [10/Aug/2024:10:12:03 +0200] "GET /wp-includes/images/cry
...
show less
DDoS Attack
๐ง๐ช
cmbplf
2024-08-09 17:38:31
(2 years ago)
213 requests to */.well-known/pki-validation/*.php
Brute-Force
Bad Web Bot