Anonymous
2024-09-23 20:38:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
Ridley
2024-07-02 15:03:00
(1 year ago)
Unauthorized connection/login attempts
Hacking
Brute-Force
๐ฉ๐ช
uhlhosting
2024-06-30 17:58:17
(1 year ago)
im-corona.ch 45.92.229.122 - - [30/Jun/2024:19:58:12.208955 +0200] "GET /xlt.php HTTP/1.1" 403 199 " ...
show more
im-corona.ch 45.92.229.122 - - [30/Jun/2024:19:58:12.208955 +0200] "GET /xlt.php HTTP/1.1" 403 199 "-" "-" ZoGctG7IL-hzngsN0rYk7wAAAQM "-" /apache/20240630/20240630-1958/20240630-195812-ZoGctG7IL-hzngsN0rYk7wAAAQM 0 1648 md5:b2e3bdbabbc03a746fae3fa1fa0715c1
im-corona.ch 45.92.229.122 - - [30/Jun/2024:19:58:13.370886 +0200] "GET /wp-content/plugins/xt/index.php HTTP/1.1" 403 199 "-" "-" ZoGctW7IL-hzngsN0rYk8AAAARA "-" /apache/20240630/20240630-1958/20240630-195813-ZoGctW7IL-hzngsN0rYk8AAAARA 0 1697 md5:af65346688a82f7ff237f2b81d596035
im-corona.ch 45.92.229.122 - - [30/Jun/2024:19:58:14.018077 +0200] "GET /wp-content/xleet.php HTTP/1.1" 403 199 "-" "-" ZoGctm7IL-hzngsN0rYk8QAAAQ4 "-" /apache/20240630/20240630-1958/20240630-195814-ZoGctm7IL-hzngsN0rYk8QAAAQ4 0 1673 md5:9d3aa14b7ebb52365e47469aa14655fa
im-corona.ch 45.92.229.122 - - [30/Jun/2024:19:58:15.558465 +0200] "GET /wp-admin/xleet-shell.php HTTP/1.1" 403 199 "-" "-" ZoGct27IL-hzngsN0rYk8gAAARI "-" /apache/20240630/20240630-1958
...
show less
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-30 14:22:50
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.92.229.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.92.229.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 30 10:22:47.271115 2024] [security2:error] [pid 22638] [client 45.92.229.122:53975] [client 45.92.229.122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaldaragroup.com"] [uri "/wp-config.php"] [unique_id "ZoFqN-Tcu2ZMTAgN416X-QAAAAM"], referer: http://kaldaragroup.com/wp-config.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2024-06-30 12:06:35
(1 year ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2024-06-30 01:08:50
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted] 45.92.229.122 (PT/Portugal/-): (CF_ENA ...
show more
(mod_security) mod_security triggered on hostname [redacted] 45.92.229.122 (PT/Portugal/-): (CF_ENABLE)
show less
SQL Injection
๐ง๐ช
cmbplf
2024-06-30 00:26:17
(1 year ago)
5 requests to /indoxploit.php
Brute-Force
Bad Web Bot
๐ช๐ธ
10dencehispahard SL
2024-06-29 00:17:39
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐ง๐ท
diego
2024-06-11 23:49:54
(1 year ago)
Events: TCP SYN Discovery or Flooding, Seen 4 times in the last 10800 seconds
DDoS Attack
๐ฎ๐ช
Jim Keir
2024-06-09 21:14:53
(1 year ago)
2024-06-09 21:14:53 45.92.229.122 File scanning, blocking 45.92.229.122 for 5 minutes
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-02 19:00:15
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-05-02 18:20:39
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 45.92.229.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.92.229.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 02 14:20:33.782877 2024] [security2:error] [pid 2505955] [client 45.92.229.122:51665] [client 45.92.229.122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "corporatepresentation.net"] [uri "/assets/js/wp-config.php"] [unique_id "ZjPZcQbVbWzNl0ntV2OvhAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-02 09:24:51
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 45.92.229.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.92.229.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 02 05:24:43.928525 2024] [security2:error] [pid 14229] [client 45.92.229.122:18113] [client 45.92.229.122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cornerstonecharitablescholarshiptrust.org"] [uri "/assets/js/wp-config.php"] [unique_id "ZjNb254i1OKpOGyJUPEIuwAAABs"], referer: http://cornerstonecharitablescholarshiptrust.org/assets/js/wp-config.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2024-04-08 11:13:34
(2 years ago)
bermanfamily.com.au:443 45.92.229.122 - - [08/Apr/2024:21:13:26 +1000] "GET /wp-includes/theme-compa ...
show more
bermanfamily.com.au:443 45.92.229.122 - - [08/Apr/2024:21:13:26 +1000] "GET /wp-includes/theme-compat/wp-conflg.php HTTP/1.1" 404 5593 "http://bermanfamily.com.au/wp-includes/theme-compat/wp-conflg.php" "Go-http-client/1.1"
bermanfamily.com.au:443 45.92.229.122 - - [08/Apr/2024:21:13:27 +1000] "GET /_well-known/amaxx.php HTTP/1.1" 404 1801 "http://bermanfamily.com.au/_well-known/amaxx.php" "Go-http-client/1.1"
bermanfamily.com.au:443 45.92.229.122 - - [08/Apr/2024:21:13:28 +1000] "GET /Wp-includes/amaxx.php HTTP/1.1" 404 1801 "http://bermanfamily.com.au/Wp-includes/amaxx.php" "Go-http-client/1.1"
bermanfamily.com.au:443 45.92.229.122 - - [08/Apr/2024:21:13:28 +1000] "GET /text.php HTTP/1.1" 404 490 "http://bermanfamily.com.au/text.php" "Go-http-client/1.1"
bermanfamily.com.au:443 45.92.229.122 - - [08/Apr/2024:21:13:29 +1000] "GET /wp-info.php HTTP/1.1" 404 490 "http://bermanfamily.com.au/wp-info.php" "Go-http-client/1.1"
bermanfamily.com.au:443 45.92.229.122 - - [08/Apr/2024:21:13:30
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2024-03-28 04:56:34
(2 years ago)
Multiple WAF Violations
Brute-Force
Web App Attack