๐ฉ๐ช
C C
2026-02-25 14:31:50
(3 months ago)
Distributed proxy crawl wave (184 requests, 184 unique IPs, 68 ASNs in 760 sec); unauth. bot traffic ...
show more
Distributed proxy crawl wave (184 requests, 184 unique IPs, 68 ASNs in 760 sec); unauth. bot traffic w/o verification; first observed at 2026-02-25T00:03:31+01:00
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-27 02:37:05
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 45.61.118.147 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 45.61.118.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 26 22:36:55.583837 2024] [security2:error] [pid 12715:tid 12901] [client 45.61.118.147:47927] [client 45.61.118.147] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||autodiscover.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /wavemaker/studioService.download?method=getContent&inUrl=file///etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kettlehill.net"] [uri "/wavemaker/studioService.download"] [unique_id "Zx2nRyzF41ATo4exCwv0PAAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-04 00:43:07
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 45.61.118.147 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 45.61.118.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 20:42:59.143197 2024] [security2:error] [pid 25466:tid 25466] [client 45.61.118.147:53797] [client 45.61.118.147] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "80"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||webmail.stdavids-media.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stdavids-media.com"] [uri "/cgi-bin/status"] [unique_id "ZtetE2MMItiWEBYjjf7M7QAAAAM"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-23 05:06:34
(1 year ago)
45.61.118.147 - - [23/Aug/2024:07:06:33 +0200] "GET /?action=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2 ...
show more
45.61.118.147 - - [23/Aug/2024:07:06:33 +0200] "GET /?action=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00 HTTP/1.1" 301 5655 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" 4660
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2024-07-27 20:22:10
(1 year ago)
(mod_security) mod_security (id:212620) triggered by 45.61.118.147 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 45.61.118.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 16:21:59.785801 2024] [security2:error] [pid 5466:tid 5544] [client 45.61.118.147:33537] [client 45.61.118.147] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||staging.kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /oauth/idp/logout?post_logout_redirect_uri=<script>console.log(`xss`)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "staging.kettlehill.com"] [uri "/oauth/idp/logout"] [unique_id "ZqVW5_YoJo47UgPCj7zu4wAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-07-15 19:16:51
(1 year ago)
SS1: Web Attack GET /wp-admin/admin.php?page=wp_ajax_rsvp-form&tribe_tickets_redirect_to=https://exa ...
show more
SS1: Web Attack GET /wp-admin/admin.php?page=wp_ajax_rsvp-form&tribe_tickets_redirect_to=https://example.com
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-07-14 02:05:55
(1 year ago)
Unauthorized login attempts [ access_predict, admin.php, action, id]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-05-15 01:49:51
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 45.61.118.147 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.61.118.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 14 21:49:40.533219 2024] [security2:error] [pid 5014:tid 47952267273984] [client 45.61.118.147:49393] [client 45.61.118.147] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.net"] [uri "/vpns/cfg/smb.conf"] [unique_id "ZkQUtODW24d8EzRQX0RDwQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2024-05-09 02:09:40
(2 years ago)
Form spam
Web Spam
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:59:30
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2024-05-07 20:41:30
(2 years ago)
Web Spam
๐บ๐ธ
oncord
2024-05-06 01:29:10
(2 years ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2024-05-04 18:57:36
(2 years ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2024-05-01 03:34:55
(2 years ago)
Form spam
Web Spam