Anonymous
2024-01-11 12:21:09
(2 years ago)
apache vulnerability scan
Web App Attack
Anonymous
2023-12-14 01:31:16
(2 years ago)
[01:31:16] 11: Scanning for Exploits - /xmlrpc.php (Repeat abuser, 10 other attacks previously recor ...
show more
[01:31:16] 11: Scanning for Exploits - /xmlrpc.php (Repeat abuser, 10 other attacks previously recorded.)
show less
Hacking
Web App Attack
Anonymous
2023-12-12 14:32:00
(2 years ago)
"Illegal file type"
Brute-Force
๐ณ๐ฑ
Lentini
2023-12-10 06:34:09
(2 years ago)
visuitslagen.nl: malicious request:/xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-10 04:32:52
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 09 23:32:45.048063 2023] [security2:error] [pid 672320] [client 43.138.172.19:45020] [client 43.138.172.19] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.172.19 (+1 hits since last alert)|www.calogerolawfirm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.calogerolawfirm.com"] [uri "/xmlrpc.php"] [unique_id "ZXU_bRZUUz3BZS5GsvTu-QAAAAU"], referer: http://www.calogerolawfirm.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-10 02:31:47
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 09 21:31:41.526730 2023] [security2:error] [pid 2849151] [client 43.138.172.19:51276] [client 43.138.172.19] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.172.19 (+1 hits since last alert)|gamerah.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gamerah.net"] [uri "/xmlrpc.php"] [unique_id "ZXUjDQnhrQgk23BN5I8MdQAAABQ"], referer: https://gamerah.net/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-09 16:34:23
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 09 11:34:20.260945 2023] [security2:error] [pid 16522:tid 47679128254208] [client 43.138.172.19:48924] [client 43.138.172.19] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.172.19 (+1 hits since last alert)|www.stmarysmarietta.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.stmarysmarietta.org"] [uri "/xmlrpc.php"] [unique_id "ZXSXDE8F0OtzrTJkx8lk8QAAABc"], referer: http://www.stmarysmarietta.org/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-07 11:34:50
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 07 06:34:46.910395 2023] [security2:error] [pid 923] [client 43.138.172.19:47298] [client 43.138.172.19] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.172.19 (+1 hits since last alert)|grabagame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grabagame.com"] [uri "/xmlrpc.php"] [unique_id "ZXGt1hr-tj12h2ONAvIEGAAAAAQ"], referer: https://grabagame.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-06 15:32:17
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 06 10:32:10.937768 2023] [security2:error] [pid 14785] [client 43.138.172.19:35066] [client 43.138.172.19] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.172.19 (+1 hits since last alert)|www.geriterry.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.geriterry.com"] [uri "/xmlrpc.php"] [unique_id "ZXCT-v6B3ZwooL32yyV3jQAAABM"], referer: https://www.geriterry.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-12-05 13:35:08
(2 years ago)
Trawling for Open Source CMS installs
Hacking
Brute-Force
Anonymous
2023-12-03 13:33:56
(2 years ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-02 17:35:15
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 02 12:35:11.016723 2023] [security2:error] [pid 26506] [client 43.138.172.19:54126] [client 43.138.172.19] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.172.19 (+1 hits since last alert)|www.kimbrothersusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.kimbrothersusa.com"] [uri "/xmlrpc.php"] [unique_id "ZWtqz00WutKIZ4sbcMdtEQAAABI"], referer: https://www.kimbrothersusa.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-02 12:34:38
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.172.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 02 07:34:34.274429 2023] [security2:error] [pid 4915] [client 43.138.172.19:38486] [client 43.138.172.19] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.172.19 (+1 hits since last alert)|www.realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.realclean.net"] [uri "/xmlrpc.php"] [unique_id "ZWskWkVcR8RtNn2HIT9jzwAAAA8"], referer: https://www.realclean.net/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2023-11-30 14:49:58
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2023-11-30 05:31:00
(2 years ago)
"Illegal file type"
Brute-Force