๐ต๐น
compulab.pt
2025-10-23 18:53:23
(11 months ago)
WHMCS reset password brute force
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-23 00:47:58
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 22 20:47:52.642693 2024] [security2:error] [pid 19007:tid 19007] [client 37.143.63.112:57867] [client 37.143.63.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.neff.family.name|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.neff.family.name"] [uri "/unwiki/doku.php"] [unique_id "ZxhHuNLLjP32GR6YrbxqaAAAAAg"], referer: https://www.neff.family.name/unwiki/doku.php?id=un:111_werrahelba
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-19 00:59:07
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 18 20:59:01.403593 2024] [security2:error] [pid 26380:tid 26380] [client 37.143.63.112:39723] [client 37.143.63.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||goseethenurse.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "goseethenurse.com"] [uri "/wp-login.php"] [unique_id "ZxMEVU5kmUXJalkQRDHdtwAAAAs"], referer: http://goseethenurse.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-15 15:24:19
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-10-14 02:50:35
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 13 22:50:28.161412 2024] [security2:error] [pid 3475:tid 3475] [client 37.143.63.112:64345] [client 37.143.63.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.mms-boss.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mms-boss.net"] [uri "/"] [unique_id "ZwyG9LwM3brKnQ4GBw3IBgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
botreporter
2024-10-12 00:12:03
(1 year ago)
bot wiki account creation attempts
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-10-10 19:49:34
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 10 15:49:28.279342 2024] [security2:error] [pid 8568:tid 8568] [client 37.143.63.112:47671] [client 37.143.63.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.keysenterprise.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.keysenterprise.net"] [uri "/index.php"] [unique_id "ZwgvyPOXRuCDN1_P3uuh5wAAAA0"], referer: https://www.keysenterprise.net/grandhaven/register?view=remind
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
botreporter
2024-10-08 11:56:58
(1 year ago)
bot wiki account creation attempts
Web Spam
Bad Web Bot
๐ฉ๐ช
botreporter
2024-09-28 03:19:33
(2 years ago)
bot wiki account creation attempts
Web Spam
Bad Web Bot
๐ฆ๐บ
MAGIC
2024-09-17 11:11:35
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-12 14:24:19
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 12 10:24:12.232061 2024] [security2:error] [pid 26148:tid 26213] [client 37.143.63.112:46575] [client 37.143.63.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||batonrougegazette.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "batonrougegazette.com"] [uri "/wp-login.php"] [unique_id "ZuL5jL6bKVogZVwjqiKFcgAAAcU"], referer: https://batonrougegazette.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
botreporter
2024-09-12 02:58:28
(2 years ago)
bot wiki account creation attempts
Web Spam
Bad Web Bot
๐ฉ๐ช
botreporter
2024-09-09 18:58:05
(2 years ago)
bot wiki account creation attempts
Web Spam
Bad Web Bot
๐บ๐ธ
MortimerCat
2024-09-08 02:29:53
(2 years ago)
Unauthorised use of XMLRPC
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-07 10:16:25
(2 years ago)
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 37.143.63.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 07 06:16:19.950355 2024] [security2:error] [pid 13437:tid 13437] [client 37.143.63.112:25913] [client 37.143.63.112] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||amzsci.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "amzsci.com"] [uri "/de/"] [unique_id "Ztwn87n8W-v6kK47PhogGgAAAAA"], referer: https://aquienpr.com/
show less
Brute-Force
Bad Web Bot
Web App Attack