π¨π
SOC [GOLINE SA]
2025-01-28 20:12:52
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Tue Jan 28 21:12:51.822526 2025] [security2:error] [pid 3005616:tid 3005718] [client 2a12:5940:15a9::2:38988] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z5k6Qy5a731q-hP7Uta8DAAAAFc"]
show less
Brute-Force
π¬π§
Swiptly
2025-01-25 03:36:50
(1 year ago)
Aggressive SEO Bots
...
Bad Web Bot
π©πͺ
on-com
2025-01-24 18:11:59
(1 year ago)
URL scan
Brute-Force
Web App Attack
π¨π
SOC [GOLINE SA]
2025-01-22 06:58:31
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Wed Jan 22 07:58:27.696004 2025] [security2:error] [pid 1310435:tid 1310515] [client 2a12:5940:15a9::2:41252] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z5CXE6-W12RZACqMTduLngAAABQ"]
show less
Brute-Force
π¨π
SOC [GOLINE SA]
2025-01-20 15:10:52
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Mon Jan 20 16:10:51.242785 2025] [security2:error] [pid 1028892:tid 1028948] [client 2a12:5940:15a9::2:51480] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z45nez4nBR6uILbLayLodQAAAAM"]
show less
Brute-Force
π¨π
SOC [GOLINE SA]
2025-01-20 10:52:08
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Mon Jan 20 11:52:07.394223 2025] [security2:error] [pid 1028893:tid 1028970] [client 2a12:5940:15a9::2:60638] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z44q1yiGG6DjQKPUeaJP3QAAAEU"]
show less
Brute-Force
π¨π
SOC [GOLINE SA]
2025-01-20 00:58:09
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Mon Jan 20 01:58:09.214528 2025] [security2:error] [pid 1018348:tid 1018445] [client 2a12:5940:15a9::2:54676] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z42fofGcWDt8J-jU303QLwAAAFI"]
show less
Brute-Force
π¨π
SOC [GOLINE SA]
2025-01-18 04:47:30
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Sat Jan 18 05:47:25.441622 2025] [security2:error] [pid 864489:tid 864589] [client 2a12:5940:15a9::2:58844] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z4syXbpnrASYTL2UvcMaLwAAAFg"]
show less
Brute-Force
π¨π
SOC [GOLINE SA]
2025-01-16 10:55:39
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Thu Jan 16 11:55:39.147459 2025] [security2:error] [pid 724749:tid 724809] [client 2a12:5940:15a9::2:48716] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z4jlq5JsI-uMMn1SMrauXgAAAEw"]
show less
Brute-Force
π©πͺ
www.Examensfragen.de
2025-01-14 22:03:45
(1 year ago)
Web Spam
Bad Web Bot
π©πͺ
on-com
2025-01-14 00:59:07
(1 year ago)
URL scan
Brute-Force
Web App Attack
π¨π
SOC [GOLINE SA]
2025-01-13 23:10:15
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Tue Jan 14 00:10:12.699727 2025] [security2:error] [pid 572860:tid 572932] [client 2a12:5940:15a9::2:40322] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z4WdVFRYRw99_cPZx76mjwAAABg"]
show less
Brute-Force
π¨π
SOC [GOLINE SA]
2025-01-12 05:32:12
(1 year ago)
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Hol ...
show more
(mod_security) mod_security (id:949110) triggered by 2a12:5940:15a9::2 (NL/The Netherlands/North Holland/Amsterdam/-/[AS210644 Aeza International Ltd]): 1 in the last 3600 secs; IP: 2a12:5940:15a9::2; Ports: *; Direction: 0; Trigger: LF_TRIGGER; Logs: [Sun Jan 12 06:32:09.965504 2025] [security2:error] [pid 439060:tid 439154] [client 2a12:5940:15a9::2:36204] [client 2a12:5940:15a9::2] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.goline.ch"] [uri "/"] [unique_id "Z4NT2SUS9xeE2X-xr6oITQAAAE8"]
show less
Brute-Force
πΊπΈ
mawan
2025-01-11 11:58:35
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π©πͺ
KiekerJan
2025-01-08 06:55:50
(1 year ago)
2a12:5940:15a9::2 - - [08/Jan/2025:07:55:49 +0100] "GET /wp-content/plugins/wp-automatic/css/style.c ...
show more
2a12:5940:15a9::2 - - [08/Jan/2025:07:55:49 +0100] "GET /wp-content/plugins/wp-automatic/css/style.css HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.3; Trident/4.0)"
2a12:5940:15a9::2 - - [08/Jan/2025:07:55:49 +0100] "GET /wp-content/plugins/wp-automatic/css/style.css HTTP/1.1" 404 181 "-" "Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.3; Trident/4.0)"
...
show less
Web App Attack