๐บ๐ธ
TPI-Abuse
2024-07-22 15:25:14
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 22 11:25:04.614439 2024] [security2:error] [pid 31245:tid 31245] [client 2a0f:df00:0:255::206:41299] [client 2a0f:df00:0:255::206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.wnysnowsports.com"] [uri "/.git/config"] [unique_id "Zp550Jn4NSKgj4lq2phVTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-12 19:27:40
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 12 15:27:31.097347 2024] [security2:error] [pid 5023] [client 2a0f:df00:0:255::206:23757] [client 2a0f:df00:0:255::206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||butterflymornings.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "butterflymornings.com"] [uri "/mailto:[email protected] "] [unique_id "ZpGDo5aHD0BLH57zQPaXqgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Linuxmalwarehuntingnl
2024-07-04 23:17:54
(1 year ago)
Honeypot HIT
Brute-Force
๐ณ๐ฑ
Linuxmalwarehuntingnl
2024-06-28 22:54:05
(1 year ago)
Honeypot HIT
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-22 13:59:30
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 22 09:59:25.880102 2024] [security2:error] [pid 4772] [client 2a0f:df00:0:255::206:59899] [client 2a0f:df00:0:255::206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||suswastima.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "suswastima.com"] [uri "/astima.sql"] [unique_id "ZnbYvW3tyknjniaBwgoN0QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2024-04-26 02:00:33
(2 years ago)
Wordpress related. [1714096336] [0] [*] [#7777349] [0] [2] [2a0f:df00:0:255::206] [403] [GET] [/inde ...
show more
Wordpress related. [1714096336] [0] [*] [#7777349] [0] [2] [2a0f:df00:0:255::206] [403] [GET] [/index.php] [WordPress: Blocked access to the WP REST API] [hex:2f77702d6a736f6e2f6f656d6265642f312e302f656d6265643f75726c3d2f67632f26]
[1714096336] [0] [*] [#7777349] [0] [2] [2a0f:df00:0:255::206] [403] [GET] [/index.php] [WordPress: Blocked access to the WP REST API] [hex:2f77702d6a736f6e2f6f656d6265642f312e302f656d6265643f75726c3d2f67632f26]
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-23 12:39:17
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 23 08:39:10.374693 2024] [security2:error] [pid 19584] [client 2a0f:df00:0:255::206:1569] [client 2a0f:df00:0:255::206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||viszin.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "viszin.com"] [uri "/wp.sql"] [unique_id "Zf7NbgK_5kG82MhKTh_7ZwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-13 20:53:47
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 13 16:53:40.980686 2024] [security2:error] [pid 26238] [client 2a0f:df00:0:255::206:13519] [client 2a0f:df00:0:255::206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.enjoy2dance.com"] [uri "/.git/config"] [unique_id "ZfISVJLevqze1XvEtVUjQwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-02 02:19:10
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0f:df00:0:255::206 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 01 21:19:05.419506 2024] [security2:error] [pid 28709] [client 2a0f:df00:0:255::206:32841] [client 2a0f:df00:0:255::206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||texaspamman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "texaspamman.com"] [uri "/mailto:[email protected] "] [unique_id "ZbxRGej2Bkvof3XsfLFx9wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hobby Bob
2022-10-20 14:03:47
(3 years ago)
Oct 20 20:03:46 mail dovecot: imap-login: Disconnected (no auth attempts in 0 secs): user=, rip=2a0f ...
show more
Oct 20 20:03:46 mail dovecot: imap-login: Disconnected (no auth attempts in 0 secs): user=, rip=2a0f:df00:0:255::206, lip=X.X.X.X session=
show less
Port Scan
Hacking