๐บ๐ธ
TPI-Abuse
2024-06-09 13:32:06
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 09 09:31:58.036819 2024] [security2:error] [pid 10776] [client 2a0b:f4c2:1::1:50069] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pancakesyrupy.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pancakesyrupy.com"] [uri "/pan.sql"] [unique_id "ZmWuzsHzqpmTjf2AmUJ10AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-07 14:29:36
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 07 10:29:31.845135 2024] [security2:error] [pid 3838336] [client 2a0b:f4c2:1::1:11845] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leirstein.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leirstein.com"] [uri "/leirst.sql"] [unique_id "ZmMZSxahaHGXMGHVrr7YAgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-04 08:52:00
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 04 04:51:55.546756 2024] [security2:error] [pid 20273:tid 47618130499328] [client 2a0b:f4c2:1::1:50171] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artmarialeon.com"] [uri "/wp-config.phpd"] [unique_id "Zl7Vq4r7CuJmVIhCDWWQAAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
sweplox.se
2024-05-28 20:51:09
(2 years ago)
2a0b:f4c2:1::1 - - [28/May/2024:20:42:56 +0000] "GET /member.php?action=profile&uid=1 HTTP/1.1" 301 ...
show more
2a0b:f4c2:1::1 - - [28/May/2024:20:42:56 +0000] "GET /member.php?action=profile&uid=1 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:103.0) Gecko/20100101 Firefox/103.0"
2a0b:f4c2:1::1 - - [28/May/2024:20:44:37 +0000] "GET /forumdisplay.php?fid=5 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:103.0) Gecko/20100101 Firefox/103.0"
2a0b:f4c2:1::1 - - [28/May/2024:20:46:48 +0000] "GET /forumdisplay.php?fid=32 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:103.0) Gecko/20100101 Firefox/103.0"
2a0b:f4c2:1::1 - - [28/May/2024:20:47:27 +0000] "GET /forumdisplay.php?fid=64 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:103.0) Gecko/20100101 Firefox/103.0"
2a0b:f4c2:1::1 - - [28/May/2024:20:48:00 +0000] "GET /forumdisplay.php?fid=35 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:103.0) Gecko/20100101 Firefox/103.0"
2a0b:f4c2:1::1 - - [28/May/2024:20:51:09 +0000] "GET /attachment.php?aid=57 HT
...
show less
Bad Web Bot
SSH
๐บ๐ธ
TPI-Abuse
2024-05-24 02:42:39
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 23 22:42:30.859118 2024] [security2:error] [pid 22129:tid 47505679886080] [client 2a0b:f4c2:1::1:35947] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||itsnotjustmeisit.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "itsnotjustmeisit.com"] [uri "/mailto:[email protected] "] [unique_id "Zk_-lgze3L375M--9rxulwAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MHuiG
2024-05-23 22:06:29
(2 years ago)
The IP has triggered Cloudflare WAF. action: block source: firewallCustom clientAsn: 60729 clientASN ...
show more
The IP has triggered Cloudflare WAF. action: block source: firewallCustom clientAsn: 60729 clientASNDescription: TORSERVERS-NET clientCountryName: DE clientIP: 2a0b:f4c2:1::1 clientRequestHTTPHost: api.mhuig.top clientRequestHTTPMethodName: GET clientRequestHTTPProtocol: HTTP/2 clientRequestPath: /wp-login.php clientRequestQuery: datetime: 2024-05-23T20:09:52Z rayName: 8887afa7addaca68 ruleId: 62370dc6b7504b8c983f836ea0faec20 userAgent: Mozilla/5.0 (Android 10; Mobile; rv:109.0) Gecko/115.0 Firefox/115.0. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Open Proxy
VPN IP
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
MarkGGN
2024-04-26 02:00:34
(2 years ago)
Wordpress related. [1714096358] [0] [*] [#2610655] [0] [2] [2a0b:f4c2:1::1] [403] [GET] [/index.php] ...
show more
Wordpress related. [1714096358] [0] [*] [#2610655] [0] [2] [2a0b:f4c2:1::1] [403] [GET] [/index.php] [WordPress: Blocked access to the WP REST API] [hex:2f77702d6a736f6e2f6f656d6265642f312e302f656d6265643f75726c3d2f72656973656e2f26]
[1714096358] [0] [*] [#2610655] [0] [2] [2a0b:f4c2:1::1] [403] [GET] [/index.php] [WordPress: Blocked access to the WP REST API] [hex:2f77702d6a736f6e2f6f656d6265642f312e302f656d6265643f75726c3d2f72656973656e2f26]
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-15 14:48:25
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 10:48:18.688025 2024] [security2:error] [pid 21249] [client 2a0b:f4c2:1::1:42853] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teenybikinigirls.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teenybikinigirls.com"] [uri "/irls.sql"] [unique_id "Zh0-MicAPK4hJjRLjspdsQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-04-08 18:50:45
(2 years ago)
DNS Compromise
DDoS Attack
๐บ๐ธ
TPI-Abuse
2024-04-08 11:05:53
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 08 07:05:45.921118 2024] [security2:error] [pid 23098] [client 2a0b:f4c2:1::1:63767] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.odinathletes.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.odinathletes.com"] [uri "/todo-lo-que-necesitas-en-un-unico-lugar/mailto:[email protected] "] [unique_id "ZhPPiUFjhxLWtwEaFfoqiwAAAAg"], referer: https://odinathletes.com/todo-lo-que-necesitas-en-un-unico-lugar/mailto:[email protected]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-31 07:46:12
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 31 03:46:08.705093 2024] [security2:error] [pid 1536] [client 2a0b:f4c2:1::1:40533] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||marjosse.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marjosse.com"] [uri "/ma.sql"] [unique_id "ZgkUwJuJK0QFehC1nCqDPwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 22:08:59
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 18:08:53.560545 2024] [security2:error] [pid 477442] [client 2a0b:f4c2:1::1:11791] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.z-mgmt.com"] [uri "/.git/config"] [unique_id "ZgXqdeosICI6-q1dJH_d5wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-28 19:33:02
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 28 15:32:58.290647 2024] [security2:error] [pid 15030] [client 2a0b:f4c2:1::1:25105] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.mandel.vc"] [uri "/.git/config"] [unique_id "ZgXF6qyYE1I9WjJ8F_qfFwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-21 16:13:40
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 21 12:13:34.086301 2024] [security2:error] [pid 16075] [client 2a0b:f4c2:1::1:21231] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.johnmueller.org"] [uri "/.git/config"] [unique_id "ZfxcrtqdCZvPSJaHshJdKwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-21 10:29:54
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 21 06:29:48.702328 2024] [security2:error] [pid 13523] [client 2a0b:f4c2:1::1:42661] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.barkan.us"] [uri "/.git/config"] [unique_id "ZfwMHLW_6k7yVCmX1by5NQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack