๐น๐ญ
thaizone.com
2025-05-26 01:09:06
(1 year ago)
Brute Force Attack on a Web Resources (repeated 404) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
construct.net
2025-05-23 06:01:44
(1 year ago)
Triggered rate limiter [PRD-VM-WEB2a]
Bad Web Bot
๐ณ๐ฑ
Site.eu
2025-05-22 04:17:19
(1 year ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-05-21 10:53:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:203:c26::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:203:c26::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 21 06:53:47.815057 2025] [security2:error] [pid 560020:tid 560020] [client 2001:41d0:203:c26::1:49150] [client 2001:41d0:203:c26::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||paulshorrock.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paulshorrock.com"] [uri "/wp-content/plugins/classic-editor/z3thv/\\xe2\\x80\\x9dhttps:/mycrochetpattern.com"] [unique_id "aC2wuz2QMD2IGY0hw0zfQgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2025-05-20 00:52:32
(1 year ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ฌ
Cloudkul Cloudkul
2025-05-16 10:37:43
(1 year ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2025-05-14 08:52:21
(1 year ago)
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked. Matched phrase "MJ12bot" at REQUEST_HEADE ...
show more
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. (1100000-stl2-14)
show less
Bad Web Bot
๐ฉ๐ช
Hazzard
2025-05-13 03:02:16
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-05-11 02:51:20
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:203:c26::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:203:c26::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 10 22:51:14.636572 2025] [security2:error] [pid 2815357:tid 2815357] [client 2001:41d0:203:c26::1:45764] [client 2001:41d0:203:c26::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Steelcase/pics/Gesture/Thumbs.db"] [unique_id "aCAQoszp9Lwh17I5Mu2sAgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 05:46:11
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2001:41d0:203:c26::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210381) triggered by 2001:41d0:203:c26::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 08 01:46:02.858845 2025] [security2:error] [pid 2353143:tid 2353143] [client 2001:41d0:203:c26::1:49206] [client 2001:41d0:203:c26::1] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.quakeprediction.com|F|4"] [data "REQUEST_URI=/Los Angeles Earthquake%2\\xe2\\x80\\xa6"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.quakeprediction.com"] [uri "/Los Angeles Earthquake%2\\xe2\\x80\\xa6"] [unique_id "aBxFGiO85zVtJwSa5lNthAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-05-07 23:10:22
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
Site.eu
2025-05-07 05:19:05
(1 year ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
SpaceHost-Server
2025-05-05 22:26:56
(1 year ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 06:36:50
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2001:41d0:203:c26::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210381) triggered by 2001:41d0:203:c26::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 02:36:45.389743 2025] [security2:error] [pid 1344331:tid 1344331] [client 2001:41d0:203:c26::1:59852] [client 2001:41d0:203:c26::1] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.clinegroup.net|F|4"] [data "REQUEST_URI=/mailers/march-mailer/%UNSUBLINK%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.clinegroup.net"] [uri "/mailers/march-mailer/%UNSUBLINK%"] [unique_id "aBhcfdxWX8Yq13Q0lIuuTwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SpaceHost-Server
2025-05-04 22:26:51
(1 year ago)
Brute-Force
Web App Attack