|
π§πͺ
cmbplf
|
|
1 /?zyhr=icck (3mos4w23h)
|
Brute-Force
Bad Web Bot
|
|
|
π§πͺ
cmbplf
|
|
1 /?ZLCAm=IkM (4w20h47m)
|
Brute-Force
Bad Web Bot
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 45.32.105.6 (45.32.105.6.vultrusercontent.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 45.32.105.6 (45.32.105.6.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 04 20:03:17.323514 2024] [security2:error] [pid 636:tid 636] [client 45.32.105.6:35063] [client 45.32.105.6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.32.105.6 (+1 hits since last alert)|karenbernsteinlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "karenbernsteinlaw.com"] [uri "/xmlrpc.php"] [unique_id "ZrAWxb35-rM0agn7aYPJAwAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 45.32.105.6 (45.32.105.6.vultrusercontent.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 45.32.105.6 (45.32.105.6.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 04 17:43:56.076991 2024] [security2:error] [pid 31866:tid 31866] [client 45.32.105.6:36891] [client 45.32.105.6] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.32.105.6 (+1 hits since last alert)|www.athletefirst.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.athletefirst.org"] [uri "/xmlrpc.php"] [unique_id "Zq_2HDN-dtHnnQuHajVCvgAAABc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
|
Brute-Force
SSH
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:217291) triggered by 45.32.105.6 (45.32.105.6.vultrusercontent.com): ...
show more
(mod_security) mod_security (id:217291) triggered by 45.32.105.6 (45.32.105.6.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 26 07:01:21.362959 2024] [security2:error] [pid 24106] [client 45.32.105.6:42903] [client 45.32.105.6] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||killeramps.com|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cnfromwhere: \\x0d\\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "killeramps.com"] [uri "/g12contact.php"] [unique_id "Znv1AZzMauEJbAO_ES2xqAAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Ports: 25,2525,465,587,2525; Direction: 0; Trigger: LF_DISTATTACK
|
Brute-Force
SSH
|
|
|
π§πͺ
cmbplf
|
|
1 /?BQMbf=NgX (2mos2w11h)
|
Brute-Force
Bad Web Bot
|
|
|
π²πΎ
Rizzy
|
|
Multiple WAF Violations
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
Ports: *; Direction: 0; Trigger: LF_DISTSMTP
|
Brute-Force
SSH
|
|
|
π¦πΊ
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:217291) triggered by 45.32.105.6 (45.32.105.6.vultrusercontent.com): ...
show more
(mod_security) mod_security (id:217291) triggered by 45.32.105.6 (45.32.105.6.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 21 15:04:29.735945 2024] [security2:error] [pid 26335] [client 45.32.105.6:45849] [client 45.32.105.6] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||furballrecords.com|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cnfromwhere: \\x0d\\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "furballrecords.com"] [uri "/g12contactnolog.php"] [unique_id "ZkzwPeJkC0S_Z9Z8WOumZAAAAAQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
[email protected]
|
|
contact form abuse
|
Web Spam
Email Spam
Brute-Force
|
|
|
π§πͺ
taivas.nl
|
|
Bad_requests
|
Bad Web Bot
|
|
|
π¬π§
Swiptly
|
|
Multiple critical ModSecurity events
...
|
Web Spam
Bad Web Bot
|
|