๐บ๐ธ
TPI-Abuse
2024-12-31 03:17:09
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 30 22:17:05.562250 2024] [security2:error] [pid 4288:tid 4288] [client 212.30.37.16:31187] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cvgandhes.investments|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cvgandhes.investments"] [uri "/backups/sql.sql"] [unique_id "Z3NiMdR-NbbNowXsAPvf8gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-12-29 06:47:32
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-23 11:05:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 23 06:05:10.220230 2024] [security2:error] [pid 12276:tid 12276] [client 212.30.37.16:22295] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barnesandbrower.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barnesandbrower.com"] [uri "/mysql.sql"] [unique_id "Z2lD5o9mf_AOasvfx2-deQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyuuzyou
2024-12-14 01:31:47
(1 year ago)
Intensive scraping: /web?s=Chemical%20exporter%20Newark&country=mrj-mrj&scraper=brave. User-Agent: M ...
show more
Intensive scraping: /web?s=Chemical%20exporter%20Newark&country=mrj-mrj&scraper=brave. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36.
show less
Bad Web Bot
๐จ๐ฆ
wil.com
2024-12-04 12:43:05
(1 year ago)
GlobalProtect login attempts with user mpena.
VPN IP
Brute-Force
Anonymous
2024-12-03 19:47:46
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-12-01 03:47:59
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 30 22:47:55.870331 2024] [security2:error] [pid 8784:tid 8784] [client 212.30.37.16:20913] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dudleyanddudley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dudleyanddudley.com"] [uri "/backups/mysql.sql"] [unique_id "Z0vca2Pabw14OUbpTP4RcAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyuuzyou
2024-11-25 16:00:36
(1 year ago)
Intensive scraping: /web?s=%D9%81%D8%B1%D9%88%D8%B4%DA%AF%D8%A7%D9%87&country=fa-fa&scraper=ddg. Use ...
show more
Intensive scraping: /web?s=%D9%81%D8%B1%D9%88%D8%B4%DA%AF%D8%A7%D9%87&country=fa-fa&scraper=ddg. User-Agent: Mozilla/5.0 (Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0.
show less
Bad Web Bot
๐ฆ๐บ
MAGIC
2024-11-21 05:08:38
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2024-11-18 00:01:18
(1 year ago)
Account archive download attempts
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-11-15 00:44:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 14 19:43:56.652093 2024] [security2:error] [pid 23905:tid 23905] [client 212.30.37.16:38931] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sailingcharterburma.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sailingcharterburma.com"] [uri "/backup/sql.sql"] [unique_id "ZzaZTGN-91UrNdsozkEI0AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyuuzyou
2024-11-11 05:47:45
(1 year ago)
Intensive scraping: /web?s=Top%20commercial%20real%20estate%20firms%20in%20California&country=ne-ne& ...
show more
Intensive scraping: /web?s=Top%20commercial%20real%20estate%20firms%20in%20California&country=ne-ne&scraper=yandex. User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-10-27 08:15:07
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 27 04:15:01.255091 2024] [security2:error] [pid 26951:tid 26951] [client 212.30.37.16:31029] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrepoch.art"] [uri "/sftp-config.json"] [unique_id "Zx32hWOGYqmSQTBFiy6p_wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-23 02:36:00
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-10-09 19:50:21
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 09 15:50:17.395423 2024] [security2:error] [pid 511:tid 531] [client 212.30.37.16:43047] [client 212.30.37.16] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magazineofwallstreet.com"] [uri "/backups/sftp-config.json"] [unique_id "ZwbeeduPC64ap8xnTZEdsQAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack