๐บ๐ธ
TPI-Abuse
2024-04-15 14:43:56
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.112 (tor32.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.112 (tor32.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 10:43:48.740383 2024] [security2:error] [pid 2872] [client 199.249.230.112:55756] [client 199.249.230.112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||realclean.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "realclean.net"] [uri "/re.sql"] [unique_id "Zh09JBrrvAZ7cCBquA_AUQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2024-04-14 14:10:34
(2 years ago)
Probing for Wordpress vulnerabilities
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-04-14 09:02:09
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐ท๐บ
sms.ru
2024-04-11 21:45:04
(2 years ago)
SMS pumping attack from foreign country
DDoS Attack
๐ฌ๐ง
Steve
2024-04-11 02:43:39
(2 years ago)
Abuse of XMLRPC
Brute-Force
Web App Attack
๐ฉ๐ช
Ba-Yu
2024-04-10 18:41:03
(2 years ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-14 21:57:34
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.112 (tor32.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.112 (tor32.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 14 16:57:30.859580 2024] [security2:error] [pid 4632] [client 199.249.230.112:58462] [client 199.249.230.112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||buyabsinthe.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "buyabsinthe.net"] [uri "/buyabsi.sql"] [unique_id "Zc03Sk9rvL92k2cEX_sW_gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-02-14 16:10:39
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-02-14 09:38:49
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 199.249.230.112 (tor32.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 199.249.230.112 (tor32.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 14 04:38:42.946192 2024] [security2:error] [pid 16402] [client 199.249.230.112:55424] [client 199.249.230.112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.seacoastlocalknowledge.com"] [uri "/.git/config"] [unique_id "ZcyKIvFC9SmBqpxTyLTtBwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
ozisp.com.au
2024-02-14 09:17:25
(2 years ago)
US_Quintex_<33>1707902244 [1:2522072:5434] ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic ...
show more
US_Quintex_<33>1707902244 [1:2522072:5434] ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 73 [Classification: Misc Attack] [Priority: 2] {TCP} 199.249.230.112:37472
show less
Open Proxy
๐ฉ๐ช
niceshops.com
2024-02-13 17:02:02
(2 years ago)
Web Attack (Feb 24 18:02:02 ScriptKiddie: request for /administrator/ )
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2024-02-13 16:52:27
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฆ๐บ
MAGIC
2024-02-13 09:11:27
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-02-12 18:44:02
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.112 (tor32.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.112 (tor32.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 12 13:43:55.404845 2024] [security2:error] [pid 24559] [client 199.249.230.112:36336] [client 199.249.230.112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bernsteinip.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bernsteinip.com"] [uri "/b.sql"] [unique_id "Zcpm6wGOXdLoNtJbdudEJgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-12 11:21:36
(2 years ago)
Web Attack ([12/Feb/2024:12:21:29 +0100] )
Brute-Force
Bad Web Bot
Web App Attack