๐บ๐ธ
TPI-Abuse
2024-04-15 14:03:41
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 10:03:34.669496 2024] [security2:error] [pid 1609] [client 199.249.230.107:59948] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||penguinexpressmag.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "penguinexpressmag.com"] [uri "/ssmag.sql"] [unique_id "Zh0ztkjdEpPufW-50MLULQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-15 11:34:36
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 07:34:29.094437 2024] [security2:error] [pid 26761] [client 199.249.230.107:54210] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bluemarineboats.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bluemarineboats.com"] [uri "/arineboats.sql"] [unique_id "Zh0QxRknPBGeLUGAit4UvgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-15 05:43:30
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 01:43:24.559025 2024] [security2:error] [pid 25307] [client 199.249.230.107:33956] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nancyscafeandcatering.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nancyscafeandcatering.com"] [uri "/backups.sql"] [unique_id "Zhy-fJV9eeWxIQgFsCWS8QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-15 03:56:22
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 14 23:56:16.430314 2024] [security2:error] [pid 29234] [client 199.249.230.107:49854] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nimbusclub.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nimbusclub.com"] [uri "/nimbus.sql"] [unique_id "ZhylYP3iHVv6jDODH5fH5AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-04-15 02:50:25
(2 years ago)
Large amount of http-requests in short time ([15/Apr/2024:04:41:02.975] )
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-04-14 22:50:53
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 14 18:50:45.970398 2024] [security2:error] [pid 20875] [client 199.249.230.107:51034] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desertalfas.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desertalfas.org"] [uri "/d.sql"] [unique_id "ZhxdxVlr5IT4UvqlmXpPSgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2024-04-14 21:25:19
(2 years ago)
Form spam
Web Spam
๐ฌ๐ง
Steve
2024-04-14 20:36:37
(2 years ago)
Abuse of XMLRPC
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-13 15:26:03
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 13 11:25:55.968248 2024] [security2:error] [pid 28664] [client 199.249.230.107:50936] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lasertherapyoc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lasertherapyoc.com"] [uri "/rtherapyoc.sql"] [unique_id "ZhqkA-bbOv7idOuSIroVbwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-13 08:47:09
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 13 04:47:02.031092 2024] [security2:error] [pid 32639] [client 199.249.230.107:53606] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||puckerbikini.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puckerbikini.com"] [uri "/bak.db"] [unique_id "ZhpGhmaYZ8IvhLuMInrYhwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-04-12 17:31:32
(2 years ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-12 17:20:51
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 12 13:20:48.412874 2024] [security2:error] [pid 3409296] [client 199.249.230.107:59938] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chrisbilder.com"] [uri "/wp-config.php_disabled"] [unique_id "ZhltcI6p7441pwX82WAu1AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-12 02:38:51
(2 years ago)
(mod_security) mod_security (id:210831) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210831) triggered by 199.249.230.107 (tor17.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 11 22:38:45.658054 2024] [security2:error] [pid 7009] [client 199.249.230.107:36850] [client 199.249.230.107] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.schadwick.net|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.schadwick.net"] [uri "/"] [unique_id "ZhietaSS8i8XIZM9A2VwRQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2024-04-11 23:21:20
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2024-04-11 07:06:24
(2 years ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack