๐ซ๐ฎ
tjs
2024-12-26 16:55:00
(1 year ago)
web attack, shell attempt
Hacking
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2024-12-25 16:42:04
(1 year ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests..
show less
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-12-25 11:47:42
(1 year ago)
209.97.169.211 - - [25/Dec/2024:13:47:41 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php ...
show more
209.97.169.211 - - [25/Dec/2024:13:47:41 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 404 272 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-25 09:52:39
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.97.169.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.97.169.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 25 04:52:32.899301 2024] [security2:error] [pid 5350:tid 5401] [client 209.97.169.211:55517] [client 209.97.169.211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafm.org"] [uri "/wp-config.php"] [unique_id "Z2vV4NsSjVYFEBqgJVX3xQAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-25 09:31:16
(1 year ago)
Brute forcing Wordpress login
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-12-25 04:03:58
(1 year ago)
209.97.169.211 - - [25/Dec/2024:06:03:57 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php ...
show more
209.97.169.211 - - [25/Dec/2024:06:03:57 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 404 279 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-12-25 00:50:47
(1 year ago)
209.97.169.211 - - [25/Dec/2024:02:50:41 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php ...
show more
209.97.169.211 - - [25/Dec/2024:02:50:41 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 404 2850 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-12-24 21:10:02
(1 year ago)
209.97.169.211 - - [24/Dec/2024:23:09:56 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php ...
show more
209.97.169.211 - - [24/Dec/2024:23:09:56 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 404 279 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
209.97.169.211 - - [24/Dec/2024:23:09:59 +0200] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 279 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
...
show less
Web App Attack
๐ฌ๐ง
CrystalMaker
2024-12-21 22:45:05
(1 year ago)
Wordpress attack - GET /wp-content/uploads/wpr-addons/forms/b1ack.php; GET /wp-content/plugins/fix/u ...
show more
Wordpress attack - GET /wp-content/uploads/wpr-addons/forms/b1ack.php; GET /wp-content/plugins/fix/up.php; GET /defaults.php; GET /dropdown.php; GET /wp-admin/user/about.php; GET /simple.php; GET /wp-includes/install.php; GET /wp-content/themes/twentyfive/include.php; GET /install.php; GET /wp-content/uploads/wp-login.php; GET /wp-admin/install.php; GET /about.php; GET /simple.php; GET /dropdown.php; GET /about.php; GET /db.php?u; GET /radio.php; GET /cong.php; GET /Byp.php; GET /mar.php; GET /moon.php; GET /shell20211028.php; GET /wp-class.php; GET /shell.php; GET /mini.php; GET /wso.php; GET /index.php; GET /simple.php; GET /wp-files.php; GET /g3l4y.php; GET /up.php; GET /log.php; GET /chosen.php?p=; GET /1.php; GET /123.php; GET /wp.php; GET /wp-blog.php; GET /wp-edit.php; GET /wp-config.php; GET /cok.php; GET /config.php; GET /phpinfo.php; GET /idk.php; GET /root.php; GET /alfanew.php; GET /alpa.php; GET /alfa.php; GET /alfax.php; GET /memek.php; GET /kontol.php; GET /indoxploit.php; GET /clen.php; GET...
show less
Web App Attack
๐บ๐ธ
TheMadBeaker
2024-12-21 19:54:57
(1 year ago)
Fail2Ban Ban Triggered
Wordpress Attack Attempt
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-12-21 06:07:51
(1 year ago)
209.97.169.211 - - [21/Dec/2024:08:07:47 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php ...
show more
209.97.169.211 - - [21/Dec/2024:08:07:47 +0200] "GET /wp-content/uploads/wpr-addons/forms/b1ack.php HTTP/1.1" 404 278 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
209.97.169.211 - - [21/Dec/2024:08:07:48 +0200] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 278 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-20 15:10:18
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.97.169.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.97.169.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 20 10:10:13.994296 2024] [security2:error] [pid 563505:tid 563505] [client 209.97.169.211:62081] [client 209.97.169.211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lowkeytiki.com"] [uri "/wp-config.php"] [unique_id "Z2WI1dj0xpi44mETB7IEMwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-12-20 12:54:18
(1 year ago)
Large amount of http-requests in short time ([20/Dec/2024:13:48:45.164] )
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-12-18 04:13:03
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 209.97.169.211 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.97.169.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 17 23:12:58.939325 2024] [security2:error] [pid 20591:tid 20591] [client 209.97.169.211:55164] [client 209.97.169.211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buanamegah.com"] [uri "/wp-config.php"] [unique_id "Z2JLyvEOK3b_gnJv8IVUDwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-17 17:22:32
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH