๐ณ๐ฑ
BlueWire Hosting
2024-11-02 15:10:58
(1 year ago)
Probing for Wordpress vulnerabilities
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2024-11-02 14:19:59
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
Protocol: HTTP/2 (method GET)
Domain: blocklist.sefinek.net
Endpoint: /generated/v1/0.0.0.0/malicious/DandelionSprout-AntiMalwareHosts.fork.txt
Query: ?_=7
Timestamp: 2024-11-02T12:21:17Z
Ray ID: 8dc415620874ca33
Rule ID: 61a9aeb040004a25a09c35e9bfb80913
UA: Mozilla/5.0 (Android 12; Mobile; rv:128.0) Gecko/128.0 Firefox/128.0
Report generated by Node-Cloudflare-WAF-AbuseIPDB https://github.com/sefinek/Node-Cloudflare-WAF-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-11-01 07:39:36
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 01 03:39:27.610346 2024] [security2:error] [pid 1152:tid 1152] [client 2a0b:f4c2:1::1:16065] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sunshine-trust.com"] [uri "/wp-config.php-original"] [unique_id "ZySFr1hyY_lVeBIcxpyFyQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Admins@FBN
2024-10-30 10:12:57
(1 year ago)
FW-PortScan: Traffic Blocked srcport=57753 dstport=443
Port Scan
๐บ๐ธ
TPI-Abuse
2024-10-30 04:12:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 30 00:12:39.181508 2024] [security2:error] [pid 18530:tid 18530] [client 2a0b:f4c2:1::1:5731] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||constructiondomex.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "constructiondomex.com"] [uri "/constructiondome.sql"] [unique_id "ZyGyNxEBUvvp75UJjhGXnwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-27 14:17:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 27 10:17:10.819201 2024] [security2:error] [pid 15847:tid 15847] [client 2a0b:f4c2:1::1:11641] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stukabird.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stukabird.com"] [uri "/stukabir.sql"] [unique_id "Zx5LZvMd-th3Os7rCsNzwAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-26 08:42:23
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 26 04:42:15.064135 2024] [security2:error] [pid 19403:tid 19403] [client 2a0b:f4c2:1::1:53947] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.maprada92.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.maprada92.com"] [uri "/maprada92.sql"] [unique_id "ZxyrZ9YIH08NQ40PWjQrigAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
SOC [GOLINE SA]
2024-10-24 22:00:48
(1 year ago)
FortiGate detected brute force login from IP 2a0b:f4c2:1::1
Brute-Force
๐ต๐ฑ
sefinek.net
2024-10-17 23:16:16
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
Protocol: HTTP/2 (method GET)
Domain: api.sefinek.net
Endpoint: /docs/v2/moecounter
Timestamp: 2024-10-17T21:15:18Z
Ray ID: 8d434da20a4b4151
Rule ID: 61a9aeb040004a25a09c35e9bfb80913
UA: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Report generated by Node-Cloudflare-WAF-AbuseIPDB https://github.com/sefinek24/Node-Cloudflare-WAF-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-10-07 15:22:09
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 07 11:22:04.703910 2024] [security2:error] [pid 9361:tid 9361] [client 2a0b:f4c2:1::1:35009] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smilingorc.com"] [uri "/wp-config.phpnew"] [unique_id "ZwP8nPajG9pqY3GtbvjAJQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-02 12:59:32
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 02 08:59:22.155462 2024] [security2:error] [pid 967:tid 967] [client 2a0b:f4c2:1::1:16115] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.theintegratedcommerceconnection.com"] [uri "/.git/config"] [unique_id "Zv1DqnkvR1e7ivz2vvgPOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-02 09:14:43
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 02 05:14:36.159929 2024] [security2:error] [pid 4737:tid 4737] [client 2a0b:f4c2:1::1:23013] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||preserveourcommunity.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "preserveourcommunity.com"] [uri "/reserveourcommunity.sql"] [unique_id "Zv0O_LjwLDHJ5qATk7pV8wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ipoac.nl
2024-09-30 15:19:42
(1 year ago)
2024-09-30T17:19:41.608510+02:00 ipoac.nl wordpress(***)[1995248]: Authentication attempt for unknow ...
show more
2024-09-30T17:19:41.608510+02:00 ipoac.nl wordpress(***)[1995248]: Authentication attempt for unknown user a from 2a0b:f4c2:1::1
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-15 15:55:41
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 15 11:55:32.962039 2024] [security2:error] [pid 8917:tid 8917] [client 2a0b:f4c2:1::1:19345] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vanmeer.info|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vanmeer.info"] [uri "/r.sql"] [unique_id "ZucDdDrTfGVgxdwHFZQUIAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-11 00:57:20
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 10 20:57:15.096970 2024] [security2:error] [pid 20738:tid 20738] [client 2a0b:f4c2:1::1:28211] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.skanksex.com"] [uri "/.git/config"] [unique_id "ZuDq6yV2YYBxiTN8lKGrkgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack