|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 46.249.98.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 46.249.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 21:33:23.379519 2026] [security2:error] [pid 17555:tid 17555] [client 46.249.98.146:54648] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dmasoftlab.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dmasoftlab.com"] [uri "/dmasoftlab.com.sql"] [unique_id "aXwYc9ZKrbg-GDvkjIc9mAAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
ingroscart.it
|
|
(mod_security) mod_security triggered on hostname [redacted] 46.249.98.146 (DE/Germany/-)
|
SQL Injection
|
|
|
Anonymous
|
|
46.249.98.146 - - [27/Jan/2026:02:50:32 +0100] "GET /webmail.gl-amf.sql.zip HTTP/2.0" 404 106 "http: ...
show more
46.249.98.146 - - [27/Jan/2026:02:50:32 +0100] "GET /webmail.gl-amf.sql.zip HTTP/2.0" 404 106 "http://webmail.gl-amf.net/webmail.gl-amf.sql.zip" "Go-http-client/2.0"
46.249.98.146 - - [27/Jan/2026:02:50:32 +0100] "GET /webmail.gl-amf.net.sql.zip HTTP/2.0" 404 106 "http://webmail.gl-amf.net/webmail.gl-amf.net.sql.zip" "Go-http-client/2.0"
...
show less
|
Web App Attack
|
|
|
๐ต๐ฑ
Might Man
|
|
nazi attack
|
Hacking
Exploited Host
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 46.249.98.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 46.249.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 26 05:15:45.710527 2024] [security2:error] [pid 13237:tid 13408] [client 46.249.98.146:60498] [client 46.249.98.146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||geekshop.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "geekshop.com"] [uri "/geekshop.sql"] [unique_id "Z20s0dHIQBW4L0gFpvTaywAAAM8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
uhlhosting
|
|
uhlhost.net 46.249.98.146 - - [25/Dec/2024:23:28:51.603707 +0100] "GET /uhlhost.sql HTTP/1.1" 403 19 ...
show more
uhlhost.net 46.249.98.146 - - [25/Dec/2024:23:28:51.603707 +0100] "GET /uhlhost.sql HTTP/1.1" 403 199 "-" "-" Z2yHI24FtxymqRdJrWe_XwAAAEY "-" /apache/20241225/20241225-2328/20241225-232851-Z2yHI24FtxymqRdJrWe_XwAAAEY 0 1653 md5:f5cdf2b51d1fd627c150eb6be2cc5e64
uhlhost.net 46.249.98.146 - - [25/Dec/2024:23:28:51.678204 +0100] "GET /uhlhost.net.sql HTTP/1.1" 403 199 "-" "-" Z2yHI24FtxymqRdJrWe_YAAAAEg "-" /apache/20241225/20241225-2328/20241225-232851-Z2yHI24FtxymqRdJrWe_YAAAAEg 0 1661 md5:f740b52620535ed54b8f5a94cf8682e9
uhlhost.net 46.249.98.146 - - [25/Dec/2024:23:28:51.706522 +0100] "GET /www.uhlhost.sql HTTP/1.1" 403 199 "-" "-" Z2yHIzxiyvff2l4gHwrPKAAAAQY "-" /apache/20241225/20241225-2328/20241225-232851-Z2yHIzxiyvff2l4gHwrPKAAAAQY 0 1661 md5:41967c0adb35fa808d6a92d54151206e
uhlhost.net 46.249.98.146 - - [25/Dec/2024:23:28:51.730176 +0100] "GET /www.uhlhost.net.sql HTTP/1.1" 403 199 "-" "-" Z2yHI24FtxymqRdJrWe_YQAAAEo "-" /apache/20241225/20241225-2328/20241225-232851-Z2yHI24Ft
...
show less
|
DDoS Attack
Brute-Force
|
|
|
๐ช๐ธ
el-brujo
|
|
09/Dec/2024:20:44:46.118569 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
09/Dec/2024:20:44:46.118569 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 46.249.98.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "hwagm.elhacker.net"] [uri "/elhacker.sql"] [unique
...
show less
|
Hacking
Web App Attack
|
|
|
๐ช๐ธ
el-brujo
|
|
06/Dec/2024:11:30:29.189728 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
06/Dec/2024:11:30:29.189728 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 46.249.98.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "hwagm.elhacker.net"] [uri "/www.elhacker.net.sql"]
...
show less
|
Hacking
Web App Attack
|
|
|
๐ช๐ธ
el-brujo
|
|
02/Dec/2024:11:25:23.162585 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
02/Dec/2024:11:25:23.162585 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 46.249.98.146] ModSecurity: Warning. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1056"] [id "920440"] [msg "URL file extension is restricted by policy"] [data ".sql"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "hwagm.elhacker.net"] [uri "/hwagm.elhacker.sql"] [
...
show less
|
Hacking
Web App Attack
|
|
|
๐ณ๐ฟ
Tripwire
|
|
Scanning for backup files
|
Web App Attack
|
|
|
Anonymous
|
|
Brute force attack seen during log review
|
Web App Attack
|
|
|
๐ฆ๐บ
weblite
|
|
LONG_RUNNING WP_MALWARE_PROBE
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 46.249.98.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 46.249.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 18 12:13:24.218706 2024] [security2:error] [pid 17135:tid 17135] [client 46.249.98.146:50923] [client 46.249.98.146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kochcreative.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kochcreative.com"] [uri "/kochcreative.sql"] [unique_id "ZxKJJKUApzCgfY3eBdyr8gAAAA8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฌ๐ง
SecondEdge
|
|
A web attack was detected from 46.249.98.146 (Hong Kong) against second-edge.com (PHPSQLAdmin).
|
Web App Attack
|
|
|
๐ฌ๐ง
SecondEdge
|
|
A web attack was detected from 46.249.98.146 (Hong Kong) against second-edge.com (PHPSQLAdmin).
|
Web App Attack
|
|