|
๐ณ๐ฑ
exxos
|
|
HTTP1.x attacks
|
DDoS Attack
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐จ๐ญ
backslash
|
|
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 09 14:08:10.067776 2024] [security2:error] [pid 1421421:tid 1421421] [client 45.148.125.137:21275] [client 45.148.125.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Briarwood II/Thumbs.db"] [unique_id "Zy-zGhDRkmQMAW07LXop7QAAAA0"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Briarwood%20II/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 01 16:13:19.977798 2024] [security2:error] [pid 22753:tid 22780] [client 45.148.125.137:10405] [client 45.148.125.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||certifiedprojectmanager.eu|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "certifiedprojectmanager.eu"] [uri "/wlmailhtml:{BC25F619-F50E-4AF3-8308-F040D6391EB3}mid:/00001780/!x-usc:mailto:[email protected]"] [unique_id "ZyU2X89HOowBCaUdw54-6gAAABA"], referer: https://certifiedprojectmanager.eu/CONTACT.html
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217280) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217280) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 30 15:42:02.765728 2024] [security2:error] [pid 26962:tid 26962] [client 45.148.125.137:29173] [client 45.148.125.137] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||royalnetworking.net|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "royalnetworking.net"] [uri "/contact.html"] [unique_id "ZyKMCn6zrCrlrVVuSkU-wAAAAAY"], referer: http://royalnetworking.net/contact.html
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Malicious activity detected
|
Hacking
Web App Attack
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
๐ฆ๐บ
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|
|
๐จ๐ฆ
wil.com
|
|
GlobalProtect login attempts with user aowens.
|
VPN IP
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 17 05:59:38.814935 2024] [security2:error] [pid 19039:tid 19039] [client 45.148.125.137:63053] [client 45.148.125.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogerg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogerg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ZulTCjW3YcMITxC-1GyWMwAAAAI"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 08 16:32:08.872184 2024] [security2:error] [pid 31995:tid 31995] [client 45.148.125.137:32221] [client 45.148.125.137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aldonchem.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aldonchem.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Zt4JyKphTIfNh9YqZB3lNgAAABM"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 28 06:58:39.557607 2024] [security2:error] [pid 32687] [client 45.148.125.137:35145] [client 45.148.125.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portalvasco.com|F|2"] [data ".beltronics.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portalvasco.com"] [uri "/blog/2012/10/garantias-de-equipos-de-eeuu/www.beltronics.com"] [unique_id "ZlW439ESR7gkkr6X9AkWgwAAAA8"], referer: https://portalvasco.com/blog/2012/10/garantias-de-equipos-de-eeuu/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.148.125.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 16 13:27:25.964034 2024] [security2:error] [pid 30351] [client 45.148.125.137:19929] [client 45.148.125.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.accordionstars.com|F|2"] [data ".accordionfactory.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.accordionstars.com"] [uri "/www.accordionfactory.com"] [unique_id "Zh60_YbClZ6_9GEHq6AIXQAAAAE"], referer: http://www.accordionstars.com/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|