๐ฆ๐บ
MAGIC
2024-01-22 04:23:02
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-01-08 02:01:00
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 07 21:00:52.701549 2024] [security2:error] [pid 23728] [client 42.0.30.157:50096] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jresm.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jresm.org"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZtXVKlH_qmbjeX6SbjlJAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-07 23:28:24
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 07 18:28:17.919226 2024] [security2:error] [pid 8042] [client 42.0.30.157:39390] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||radiointernational.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "radiointernational.net"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZszkRceGRA6OJwnxU1a0QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-07 13:15:29
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 07 08:15:23.992702 2024] [security2:error] [pid 20062] [client 42.0.30.157:43652] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||insearchofacure.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "insearchofacure.org"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZqj615YTJc2RJ7PXxlgNAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2024-01-07 13:01:49
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
ps-center
2024-01-07 11:11:43
(2 years ago)
C1: Web Attack GET /wp-includes/radio.php
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-07 11:11:06
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 07 06:11:01.308609 2024] [security2:error] [pid 25606] [client 42.0.30.157:59596] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||howtosellmorepizza.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "howtosellmorepizza.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZqGxbl5Wm7PijeMgh1S9QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WebpodsLLC
2024-01-07 05:42:01
(2 years ago)
Direction: in Trigger: LF_MODSEC;
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-07 05:20:54
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 07 00:20:51.489279 2024] [security2:error] [pid 629] [client 42.0.30.157:60958] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.castriotadesign.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.castriotadesign.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZo0s1vzGTVuNksQuonTiwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-07 03:48:00
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 22:47:55.618933 2024] [security2:error] [pid 8414] [client 42.0.30.157:49126] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sigi.biz|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sigi.biz"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZoe65q3bh1ieYMVzFLdJQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-01-07 01:55:44
(2 years ago)
42.0.30.157 - - [07/Jan/2024:03:55:41 +0200] "GET /wp-content/plugins/content-management/content.php ...
show more
42.0.30.157 - - [07/Jan/2024:03:55:41 +0200] "GET /wp-content/plugins/content-management/content.php HTTP/1.1" 404 277 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
42.0.30.157 - - [07/Jan/2024:03:55:44 +0200] "GET /wp-content/plugins/core-plugin/include.php HTTP/1.1" 404 277 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-07 01:13:33
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 20:13:28.060239 2024] [security2:error] [pid 16231] [client 42.0.30.157:40354] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aperturecontrols.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aperturecontrols.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZn6uIYn3V6OboZQDjTdcgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-07 00:00:34
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 19:00:27.703380 2024] [security2:error] [pid 16824] [client 42.0.30.157:47392] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bayareasbestkarate.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bayareasbestkarate.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZnpm9aPQSQKrGlDkWKDAAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 23:16:58
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 18:16:54.383574 2024] [security2:error] [pid 9326] [client 42.0.30.157:44104] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raaksystems.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raaksystems.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZnfZub337O9Dy59w7-aFQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-06 22:52:50
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 42.0.30.157 (jrtux.emplacce.me.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 06 17:52:45.647457 2024] [security2:error] [pid 24448] [client 42.0.30.157:40760] [client 42.0.30.157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||dismain.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dismain.com"] [uri "/site/default/settings.php.BAK"] [unique_id "ZZnZvSnX4PtiY5_j5CuqewAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack