๐ช๐ธ
10dencehispahard SL
2024-04-15 15:00:03
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-04-14 08:37:21
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.160 (tor71.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.160 (tor71.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 14 04:37:18.024235 2024] [security2:error] [pid 17240] [client 199.249.230.160:56306] [client 199.249.230.160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||onlinesuretybonds.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "onlinesuretybonds.com"] [uri "/online.sql"] [unique_id "ZhuVvlKYoWtk-2BwAR3ucgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2024-04-13 00:51:50
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
Kreapptivo
2024-04-12 23:28:46
(2 years ago)
[13/Apr/2024:01:28:45 +0200] Web-Request: "POST /wp-login.php", User-Agent: "Mozilla/5.0 (Windows NT ...
show more
[13/Apr/2024:01:28:45 +0200] Web-Request: "POST /wp-login.php", User-Agent: "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/535.28.71 (KHTML, like Gecko) Chrome/53.8.3004.8376 Safari/531.88"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-11 04:22:16
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.160 (tor71.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.160 (tor71.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 11 00:22:10.959823 2024] [security2:error] [pid 17640] [client 199.249.230.160:52388] [client 199.249.230.160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kerrywood.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kerrywood.com"] [uri "/ke.sql"] [unique_id "ZhdlcrgSradjsAJEsztyOAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2024-04-08 16:23:50
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ง๐ท
leolemos
2024-02-14 21:33:02
(2 years ago)
199.249.230.160 - - [14/Feb/2024:18:32:55 -0300] "POST /xmlrpc.php HTTP/1.1" 200 6887 "-" "Mozilla/5 ...
show more
199.249.230.160 - - [14/Feb/2024:18:32:55 -0300] "POST /xmlrpc.php HTTP/1.1" 200 6887 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:65.0) Gecko/20100101 Firefox/65.0"
199.249.230.160 - - [14/Feb/2024:18:32:57 -0300] "POST /xmlrpc.php HTTP/1.1" 200 6887 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:65.0) Gecko/20100101 Firefox/65.0"
199.249.230.160 - - [14/Feb/2024:18:32:59 -0300] "POST /xmlrpc.php HTTP/1.1" 200 6887 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:65.0) Gecko/20100101 Firefox/65.0"
199.249.230.160 - - [14/Feb/2024:18:33:01 -0300] "POST /xmlrpc.php HTTP/1.1" 200 6887 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:65.0) Gecko/20100101 Firefox/65.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2024-02-14 13:11:43
(2 years ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ต๐ฑ
strefapi_com
2024-02-12 14:14:04
(2 years ago)
Brute-force web
...
Hacking
Brute-Force
Web App Attack
๐ฆ๐บ
MAGIC
2024-02-12 10:05:43
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฆ๐บ
ozisp.com.au
2024-02-12 09:55:36
(2 years ago)
US_Quintex_<33>1707731735 [1:2522075:5430] ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic ...
show more
US_Quintex_<33>1707731735 [1:2522075:5430] ET TOR Known Tor Relay/Router (Not Exit) Node TCP Traffic group 76 [Classification: Misc Attack] [Priority: 2] {TCP} 199.249.230.160:42394
show less
Open Proxy
๐บ๐ธ
TPI-Abuse
2024-02-12 03:52:54
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.160 (tor71.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.160 (tor71.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 11 22:52:47.016781 2024] [security2:error] [pid 23195] [client 199.249.230.160:48110] [client 199.249.230.160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||webersource.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webersource.com"] [uri "/daily.sql"] [unique_id "ZcmWD96XU_Nty_29NzFb3wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-11 10:48:34
(2 years ago)
Web Attack ([11/Feb/2024:11:48:25 +0100] )
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-10 11:07:05
(2 years ago)
Web Attack ([10/Feb/2024:12:07:00 +0100] )
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-09 12:04:42
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.160 (tor71.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.160 (tor71.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 09 07:04:35.875451 2024] [security2:error] [pid 11026] [client 199.249.230.160:46882] [client 199.249.230.160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ahsigns.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ahsigns.com"] [uri "/ahsigns.sql"] [unique_id "ZcYU0w0R24G9iXGNpYBDTwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack