๐บ๐ธ
TPI-Abuse
2024-04-15 05:44:39
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 01:44:35.653316 2024] [security2:error] [pid 15569] [client 199.249.230.152:33816] [client 199.249.230.152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nancyscafeandcatering.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nancyscafeandcatering.com"] [uri "/nancyscafean.sql"] [unique_id "Zhy-w1xpf1moir8o2KPq6QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-04-13 23:00:51
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐ท๐บ
sms.ru
2024-04-13 10:55:03
(2 years ago)
SMS pumping attack (request flood from TOR)
DDoS Attack
๐บ๐ธ
TPI-Abuse
2024-04-13 04:39:33
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 13 00:39:26.342331 2024] [security2:error] [pid 9526:tid 47978658023168] [client 199.249.230.152:57290] [client 199.249.230.152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||certifiedebusinessconsultant.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "certifiedebusinessconsultant.com"] [uri "/htdocs.db"] [unique_id "ZhoMfiJ1cs4FOA8kw2pdAgAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
ozisp.com.au
2024-04-11 13:49:50
(2 years ago)
US_Quintex_<33>1712843389 [1:2522071:5491] ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic ...
show more
US_Quintex_<33>1712843389 [1:2522071:5491] ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 72 [Classification: Misc Attack] [Priority: 2] {TCP} 199.249.230.152:58902
show less
Open Proxy
๐บ๐ธ
TPI-Abuse
2024-04-11 13:33:21
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 11 09:33:14.153522 2024] [security2:error] [pid 19054] [client 199.249.230.152:41538] [client 199.249.230.152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||metcomarine.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "metcomarine.com"] [uri "/e.sql"] [unique_id "ZhfmmsSxIQ2RcsuxbXFYcwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-12 20:04:25
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 12 15:04:18.419610 2024] [security2:error] [pid 28215] [client 199.249.230.152:44618] [client 199.249.230.152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||inverzona.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "inverzona.com"] [uri "/zona.sql"] [unique_id "Zcp5wuAUFPVFfat5WDbt8gAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
EscapeR
2024-02-12 16:18:19
(2 years ago)
abuseipdb
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-12 09:45:25
(2 years ago)
Web Attack ([12/Feb/2024:10:45:20 +0100] )
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-11 11:49:32
(2 years ago)
Web Attack multi (Feb 24 12:49:32 Matching rules: Detect possible SQL injection - Too many SQL keyw ...
show more
Web Attack multi (Feb 24 12:49:32 Matching rules: Detect possible SQL injection - Too many SQL keywords (more than 3 times),Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-11 04:07:53
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 10 23:07:46.213565 2024] [security2:error] [pid 430] [client 199.249.230.152:50882] [client 199.249.230.152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grace.michaelward.com"] [uri "/.git/config"] [unique_id "ZchIEkzYT5tYOcRsFEE99AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-11 00:02:28
(2 years ago)
Web Attack ([11/Feb/2024:01:02:21 +0100] )
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-10 08:56:57
(2 years ago)
Web Attack multi (Feb 24 09:56:56 Matching rules: Detect possible SQL injection - Too many SQL keyw ...
show more
Web Attack multi (Feb 24 09:56:56 Matching rules: Detect possible SQL injection - Too many SQL keywords (more than 3 times),Detect possible SQL injection - E.g. Sleep(5),Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-09 21:35:21
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.152 (tor63.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 09 16:35:15.982054 2024] [security2:error] [pid 25805] [client 199.249.230.152:47578] [client 199.249.230.152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arellasoc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arellasoc.com"] [uri "/arellas.sql"] [unique_id "Zcaak5YzAaNdFlD2wb6AMgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-09 20:12:25
(2 years ago)
Web Attack ([09/Feb/2024:21:12:16 +0100] )
Brute-Force
Bad Web Bot
Web App Attack