๐ฎ๐น
LTM
2025-10-11 06:20:01
(9 months ago)
WebServer - Attempts to exploit
Hacking
Brute-Force
Web App Attack
๐ธ๐ฎ
borisperc
2025-08-03 10:36:29
(11 months ago)
Web Spam
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ช๐ธ
librebit
2025-03-18 11:32:48
(1 year ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-03-18 10:48:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 06:48:55.370424 2025] [security2:error] [pid 32283:tid 32283] [client 23.154.177.25:57420] [client 23.154.177.25] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graciousholding.com"] [uri "/wp-config.php~"] [unique_id "Z9lPlxriYjFrn7aOpRaW2AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-03-17 22:44:35
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฑ๐บ
conseilgouz
2025-03-16 18:50:33
(1 year ago)
arw-Joomla User : try to access forms...
Hacking
๐บ๐ธ
TPI-Abuse
2025-03-16 08:47:24
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 16 04:47:18.506333 2025] [security2:error] [pid 27026:tid 27026] [client 23.154.177.25:25190] [client 23.154.177.25] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerusalem-korczak-home.com"] [uri "/.git/config"] [unique_id "Z9aQFo6jlRj9p9Sn0wkBfwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oncord
2025-03-15 15:46:59
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-03-12 23:07:13
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 12 19:07:10.180715 2025] [security2:error] [pid 32628:tid 32628] [client 23.154.177.25:29034] [client 23.154.177.25] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||empoweruohio.org|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "empoweruohio.org"] [uri "/WS_FTP.log"] [unique_id "Z9ITnkvb6ZGR3qIvHQ9EGQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-03-11 13:01:23
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-03-09 06:36:03
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 01:34:22.934593 2025] [security2:error] [pid 16577:tid 16600] [client 23.154.177.25:48836] [client 23.154.177.25] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "culturallyyours.org"] [uri "/wp-config.php__"] [unique_id "Z802bnFDnISDhoPHvD0QnwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-08 04:48:47
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 23.154.177.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 07 23:48:40.522589 2025] [security2:error] [pid 3798:tid 3798] [client 23.154.177.25:23960] [client 23.154.177.25] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||westernmassaa.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "westernmassaa.net"] [uri "/wester.sql"] [unique_id "Z8vMKIlT5c_yfojPTkYy2gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
subnetprotocol
2025-03-06 23:29:35
(1 year ago)
07/Mar/2025:00:29:33.089946 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
07/Mar/2025:00:29:33.089946 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 23.154.177.25] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 's)UEf' [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "66"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: s)UEf found within ARGS:rememberme: 1') UNION ALL SELECT CONCAT(CONCAT('qqqbq','mzgxwgaJQe'),'qzbjq'),74,74-- jsTh"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.7"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [hostname "www.mignonne.com"] [uri "/messagerie/hd.admin.php"] [unique_id "Z8ov3ZgA4sj2yYt8qdQtHwAAA5U"]
07/Mar/2025:00:29:33.089946 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 23.154.177.25] ModSecurity: Warning. Pattern ma
...
show less
Hacking
Web App Attack
๐ช๐ธ
librebit
2025-03-06 06:58:57
(1 year ago)
Brute force
Brute-Force
Anonymous
2025-03-02 17:53:36
(1 year ago)
23.154.177.25 - - [02/Mar/2025:18:53:24 +0100] "POST /producten/alle-producten?tx_laposta_subscribe% ...
show more
23.154.177.25 - - [02/Mar/2025:18:53:24 +0100] "POST /producten/alle-producten?tx_laposta_subscribe%5Baction%5D=rest&tx_laposta_subscribe%5Bcontroller%5D=Subscriptionlist&cHash=87286a273ad14449b643dd9f4e6483b3 HTTP/2.0" 500 198 "https://www.solgar.nl/producten/alle-producten?tx_laposta_subscribe%5Baction%5D=rest&tx_laposta_subscribe%5Bcontroller%5D=Subscriptionlist&cHash=87286a273ad14449b643dd9f4e6483b3" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
23.154.177.25 - - [02/Mar/2025:18:53:27 +0100] "POST /producten/alle-producten?tx_laposta_subscribe%5Baction%5D=rest&tx_laposta_subscribe%5Bcontroller%5D=Subscriptionlist&cHash=87286a273ad14449b643dd9f4e6483b3 HTTP/2.0" 500 198 "https://www.solgar.nl/producten/alle-producten?tx_laposta_subscribe%5Baction%5D=rest&tx_laposta_subscribe%5Bcontroller%5D=Subscriptionlist&cHash=87286a273ad14449b643dd9f4e6483b3" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML
...
show less
Brute-Force