πΉπ·
neron
2026-07-26 11:20:49
(12 hours ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
π³π±
Linuxmalwarehuntingnl
2024-07-03 08:55:15
(2 years ago)
Unauthorized connection attempt
Brute-Force
πΊπΈ
TPI-Abuse
2024-04-15 13:58:40
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 09:58:32.846985 2024] [security2:error] [pid 24545] [client 199.249.230.187:49808] [client 199.249.230.187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.penguinexpressmag.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.penguinexpressmag.com"] [uri "/penguinexpre.sql"] [unique_id "Zh0yiAF64SgPm83lxTmfjgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
rsiddall
2024-04-15 13:57:25
(2 years ago)
199.249.230.187 - - [15/Apr/2024:09:57:25 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5 ...
show more
199.249.230.187 - - [15/Apr/2024:09:57:25 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36"
199.249.230.187 - - [15/Apr/2024:09:57:25 -0400] "POST /xmlrpc.php HTTP/1.1" 403 1809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36"
...
show less
Brute-Force
π©πͺ
niceshops.com
2024-04-15 13:49:48
(2 years ago)
Web Attack multi (Apr 24 15:49:48 Matching rules: Detect possible SQL injection - Too many SQL keyw ...
show more
Web Attack multi (Apr 24 15:49:48 Matching rules: Detect possible SQL injection - Too many SQL keywords (more than 3 times),Detect possible SQL injection - E.g. Sleep(5),Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-15 11:04:34
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 07:04:28.666245 2024] [security2:error] [pid 17989] [client 199.249.230.187:59586] [client 199.249.230.187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||savingshvac.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "savingshvac.com"] [uri "/savingshvac.sql"] [unique_id "Zh0JvJjLcT7sCVQD5qWRjQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-15 07:37:59
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 03:37:55.430128 2024] [security2:error] [pid 14652] [client 199.249.230.187:57958] [client 199.249.230.187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gellertdealers.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gellertdealers.com"] [uri "/gellertdeale.sql"] [unique_id "ZhzZUzTdf79bngC-YbqmMwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-14 15:25:35
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 14 11:25:30.478598 2024] [security2:error] [pid 1017:tid 47681219946240] [client 199.249.230.187:32868] [client 199.249.230.187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mcdonaldmountainranch.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mcdonaldmountainranch.com"] [uri "/backup-2022.sql"] [unique_id "Zhv1aqwx3jaBepKunIuLMAAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Kreapptivo
2024-04-14 11:34:12
(2 years ago)
[14/Apr/2024:13:34:11 +0200] Web-Request: "POST /wp-login.php", User-Agent: "Mozilla/5.0 (Macintosh; ...
show more
[14/Apr/2024:13:34:11 +0200] Web-Request: "POST /wp-login.php", User-Agent: "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_31_88) AppleWebKit/532.82.39 (KHTML, like Gecko) Chrome/56.2.7068.2796 Safari/532.11 Edge/36.15171"
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-14 06:39:04
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 14 02:38:58.336079 2024] [security2:error] [pid 21255] [client 199.249.230.187:51626] [client 199.249.230.187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||soereng.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "soereng.com"] [uri "/daily.sql"] [unique_id "Zht6Aps9IiXj7iq3ILGvdAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
webbfabriken
2024-04-14 03:10:32
(2 years ago)
spam or other hacking activities reported by webbfabriken security servers
Attack reported by Webbf ...
show more
spam or other hacking activities reported by webbfabriken security servers
Attack reported by Webbfabiken Security API - WFSecAPI
show less
Web Spam
πΊπΈ
TPI-Abuse
2024-04-13 09:25:28
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.187 (tor98.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 13 05:25:25.151134 2024] [security2:error] [pid 10527] [client 199.249.230.187:60742] [client 199.249.230.187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kawkacevents.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kawkacevents.com"] [uri "/awkacevents.sql"] [unique_id "ZhpPhZUzUHEt6pR5d4rjGQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-04-12 20:19:11
(2 years ago)
Bot / seems abusive / Apache connections: 22
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
π©πͺ
Dadelinux
2024-04-12 15:37:40
(2 years ago)
199.249.230.187 - - [12/Apr/2024:17:37:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5475 "-" "Mozilla/5 ...
show more
199.249.230.187 - - [12/Apr/2024:17:37:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5475 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.1.2 Safari/603.3.8"
199.249.230.187 - - [12/Apr/2024:17:37:34 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5475 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.1.2 Safari/603.3.8"
199.249.230.187 - - [12/Apr/2024:17:37:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5475 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.1.2 Safari/603.3.8"
show less
SQL Injection
Web App Attack
π«π·
Sklurk
2024-04-12 12:16:05
(2 years ago)
Web App Attack
Web App Attack