π«π·
Nicolmn
2024-12-30 09:55:33
(1 year ago)
Web form spam ( id lmn.l )
Web Spam
πΊπΈ
TPI-Abuse
2024-12-15 09:42:42
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 15 04:42:37.327583 2024] [security2:error] [pid 11450:tid 11450] [client 2a0b:f4c2::29:26136] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "okanaganwineclub.net"] [uri "/wp-config.php-bak"] [unique_id "Z16kjcS5SDVnyqkZaSZTeAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2024-12-09 21:10:07
(1 year ago)
Scanning for Laravel vulnerabilities
Web App Attack
πΊπΈ
TPI-Abuse
2024-12-03 04:55:39
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 02 23:55:31.674207 2024] [security2:error] [pid 3517778:tid 3517778] [client 2a0b:f4c2::29:49380] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.railsolutionsmexico.com"] [uri "/.git/config"] [unique_id "Z06PQwUE1E6CwTO5lsDVJwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-12-02 17:49:30
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 02 12:49:22.826952 2024] [security2:error] [pid 19829:tid 19942] [client 2a0b:f4c2::29:62428] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.jeflis.com"] [uri "/.git/config"] [unique_id "Z03zIqiwpfp3aexZk0YU9AAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-11-20 01:46:37
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 20:46:29.239546 2024] [security2:error] [pid 5543:tid 5543] [client 2a0b:f4c2::29:24608] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.memorialtownsquare.com"] [uri "/.git/config"] [unique_id "Zz0_ddxV5zumtV0CCxc6KAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±πΉ
NotACaptcha
2024-11-11 06:23:26
(1 year ago)
webserver:80 [11/Nov/2024] "POST /graphql HTTP/1.1" 404 341 "-" "Go-http-client/1.1"
Web App Attack
Anonymous
2024-11-05 11:40:03
(1 year ago)
| Multiple common web attacks from same source ip. (multiple servers)
Hacking
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2024-10-25 07:39:28
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 25 03:39:19.007922 2024] [security2:error] [pid 12004:tid 12004] [client 2a0b:f4c2::29:52904] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||constructiondomex.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "constructiondomex.com"] [uri "/iondomex.sql"] [unique_id "ZxtLJ490HGkZoAej5laBsQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-19 04:41:39
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 19 00:41:33.917319 2024] [security2:error] [pid 1033:tid 1033] [client 2a0b:f4c2::29:10034] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williams-rodriguez.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williams-rodriguez.org"] [uri "/backup.sql"] [unique_id "ZuurfZY6awoMWJouTYSs8gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-17 16:34:47
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 17 12:34:41.380571 2024] [security2:error] [pid 20490:tid 20490] [client 2a0b:f4c2::29:12240] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.bamedica.com"] [uri "/.git/config"] [unique_id "ZumvobBOAWz2UZW7Znp1PQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-31 02:12:21
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 30 22:12:15.440117 2024] [security2:error] [pid 19084:tid 19084] [client 2a0b:f4c2::29:20464] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||prcomputersolutions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "prcomputersolutions.com"] [uri "/pr.sql"] [unique_id "ZtJ7_2DL_xX5_yRuzJ05FwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-08-29 17:30:15
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 29 13:30:10.984825 2024] [security2:error] [pid 20668:tid 20668] [client 2a0b:f4c2::29:11190] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||viszin.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "viszin.com"] [uri "/wp.sql"] [unique_id "ZtCwInGE0N3zVXVHq7wItgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
MacLotsen
2024-08-28 17:47:34
(2 years ago)
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3 ...
show more
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (SS; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.2.20"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-log
...
show less
Brute-Force
Web App Attack
π©πͺ
Admins@FBN
2024-08-19 15:07:02
(2 years ago)
FW-PortScan: Traffic Blocked srcport=57588 dstport=443
Port Scan