Anonymous
2025-01-27 05:15:42
(1 year ago)
wordpress-trap
Web App Attack
Anonymous
2025-01-23 03:49:09
(1 year ago)
wordpress-trap
Web App Attack
๐ซ๐ฎ
oh.mg
2025-01-22 13:55:40
(1 year ago)
[Wed Jan 22 14:55:38.067106 2025] [security2:error] [pid 1160348:tid 1160361] [client 212.30.36.66:4 ...
show more
[Wed Jan 22 14:55:38.067106 2025] [security2:error] [pid 1160348:tid 1160361] [client 212.30.36.66:49647] [client 212.30.36.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "oh.mg"] [uri "/wp-admin/css/colors/index.php"] [unique_id "Z5D42gL_OlsS1JEI2pN_ZQAAAIo"]
[Wed Jan 22 14:55:40.400779 2025] [security2:error] [pid 1160349:tid 1160393] [client 212.30.36.66:25089] [client 212.30.36.66] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
0xffffffff
2025-01-22 06:39:39
(1 year ago)
[2025-01-22 08:36:29.807781] [authz_core:error] [pid 3127614:tid 136630631401152] [client 212.30.36. ...
show more
[2025-01-22 08:36:29.807781] [authz_core:error] [pid 3127614:tid 136630631401152] [client 212.30.36.66:0] AH01630: client denied by server configuration: /var/www/*/wp-includes/Text/Diff/Engine/index.php , error_notes:missing-php , URI:'/wp-includes/Text/Diff/Engine/index.php'
[2025-01-22 08:36:45.531753] [authz_core:error] [pid 3127614:tid 136630746744512] [client 212.30.36.66:0] AH01630: client denied by server configuration: /var/www/*/wp-includes/blocks/index.php , URI:'/wp-includes/blocks/index.php'
[2025-01-22 08:39:38.421645] [authz_core:error] [pid 3127615:tid 136630799173312] [client 212.30.36.66:0] AH01630: client denied by server configuration: /var/www/*/wp-includes/blocks/quote/index.php , error_notes:missing-php , URI:'/wp-includes/blocks/quote/index.php'
show less
Bad Web Bot
Web App Attack
Anonymous
2025-01-21 04:33:22
(1 year ago)
wordpress-trap
Web App Attack
๐ฆ๐บ
weblite
2025-01-21 04:15:12
(1 year ago)
WP_MALWARE_PROBE
Hacking
Web App Attack
๐จ๐ฆ
wil.com
2025-01-21 03:56:44
(1 year ago)
GlobalProtect login attempts with user DeatonS.
VPN IP
Brute-Force
Anonymous
2025-01-20 10:47:21
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
MAGIC
2025-01-20 02:02:23
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-01-18 20:59:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.30.36.66 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.36.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 18 15:59:27.722302 2025] [security2:error] [pid 13330:tid 13330] [client 212.30.36.66:44225] [client 212.30.36.66] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||boat-accessories.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boat-accessories.net"] [uri "/bak/backup.sql"] [unique_id "Z4wWL-eceIQxnlEciDxNngAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2024-12-25 22:06:50
(1 year ago)
Suspicious Activity Detected: /bak/website.tar
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-21 07:55:09
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.30.36.66 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.36.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 21 02:55:04.785747 2024] [security2:error] [pid 27489:tid 27489] [client 212.30.36.66:17355] [client 212.30.36.66] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||loriatrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "loriatrading.com"] [uri "/bak/mysql.sql"] [unique_id "Z2Z0WLeG5Aza1WLKJOkY5wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
Staging
2024-12-19 17:34:00
(1 year ago)
Crapola
Hacking
Bad Web Bot
๐ฆ๐บ
MAGIC
2024-12-19 17:02:24
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฎ๐น
Progetto1
2024-12-19 10:22:04
(1 year ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack