๐ซ๐ท
dynamix
2025-12-18 13:57:30
(8 months ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฟ
Antinson
2025-12-18 10:50:22
(8 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2025-12-16 04:58:35
(8 months ago)
45.67.99.35 - - [16/Dec/2025:06:58:32 +0200] "GET //wp-content/plugins/so-pinyin-slugs/inc/main_json ...
show more
45.67.99.35 - - [16/Dec/2025:06:58:32 +0200] "GET //wp-content/plugins/so-pinyin-slugs/inc/main_json.php HTTP/1.1" 404 277 "-" "Go-http-client/1.1"
45.67.99.35 - - [16/Dec/2025:06:58:35 +0200] "GET //wp-content/plugins/SecurityFin/SecurityFin.php HTTP/1.1" 404 277 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-16 04:37:44
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.67.99.35 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.67.99.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 15 23:37:41.528969 2025] [security2:error] [pid 10053:tid 10053] [client 45.67.99.35:22505] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mpaexchangeinc.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mpaexchangeinc.com"] [uri "/backup/wallet.dat"] [unique_id "aUDiFTlEUeqT9QJRItbwaAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-12-16 01:00:18
(8 months ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ฎ๐ฉ
Burayot
2025-12-15 23:31:29
(8 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.67.99.35 (-): 2 in the last 3600 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.67.99.35 (-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
Penny Packer
2025-12-11 23:27:46
(8 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 21:21:39
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.67.99.35 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.67.99.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 16:21:35.590738 2025] [security2:error] [pid 6658:tid 6658] [client 45.67.99.35:42955] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||aico-sal.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aico-sal.com"] [uri "/bak/sql.sql"] [unique_id "aTSeXw36I9a28vLbWrnJ9wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
sms.ru
2025-11-25 11:28:00
(9 months ago)
//wp-admin/js/index.php
Web App Attack
๐บ๐ธ
mnsf
2025-11-25 10:05:30
(9 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:56:05
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 45.67.99.35 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.67.99.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:56:00.087093 2025] [security2:error] [pid 21394:tid 21394] [client 45.67.99.35:30889] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pcga.golf|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pcga.golf"] [uri "/bak/sql.sql"] [unique_id "aSUawIQEZ3JD9Rg1To5WLwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-11-22 21:05:47
(9 months ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2025-11-22 04:50:03
(9 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 22:53:33
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 45.67.99.35 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.67.99.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 17:53:25.914518 2025] [security2:error] [pid 28134:tid 28134] [client 45.67.99.35:37417] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crypto-stamps.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crypto-stamps.com"] [uri "/www.sql"] [unique_id "aSDtZRYJBEvPbnxlpT3a7gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-11-21 20:06:45
(9 months ago)
Too many Status 40X (15)
Brute-Force
Web App Attack