|
๐ช๐ธ
el-brujo
|
|
DDoS Attack Layer 7 Silent Bot
|
DDoS Attack
|
|
|
๐ฎ๐ฉ
David Koswari
|
|
"DDoS Attack containing REQ_CHALLENGE_JAVASCRIPT"
|
Brute-Force
|
|
|
๐ฎ๐ฉ
David Koswari
|
|
"DDoS Attack containing REQ_CHALLENGE_JAVASCRIPT"
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240950) triggered by 51.222.32.193 (ip193.ip-51-222-32.net): 1 in th ...
show more
(mod_security) mod_security (id:240950) triggered by 51.222.32.193 (ip193.ip-51-222-32.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 23 01:18:06.961829 2025] [security2:error] [pid 12370:tid 12370] [client 51.222.32.193:33874] [client 51.222.32.193] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||goldengatecorgis.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "goldengatecorgis.org"] [uri "/"] [unique_id "Z5HfHubbmSfNW3LVbdOj7QAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฒ๐น
Malta
|
|
51.222.32.193 - - [03/Oct/2024:05:43:07 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (X11; Linux ...
show more
51.222.32.193 - - [03/Oct/2024:05:43:07 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.138 Safari/537.36"
Brute-force password attempt
show less
|
Hacking
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 51.222.32.193 (ip193.ip-51-222-32.net): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 51.222.32.193 (ip193.ip-51-222-32.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 02 19:08:19.519557 2024] [security2:error] [pid 1468:tid 1468] [client 51.222.32.193:51902] [client 51.222.32.193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 51.222.32.193 (+1 hits since last alert)|www.gac-newsletter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.gac-newsletter.com"] [uri "/xmlrpc.php"] [unique_id "Zv3SY2YKbDSHDE8aHLiNlwAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 51.222.32.193 (ip193.ip-51-222-32.net): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 51.222.32.193 (ip193.ip-51-222-32.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 02 17:56:40.628978 2024] [security2:error] [pid 9916:tid 9916] [client 51.222.32.193:35172] [client 51.222.32.193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 51.222.32.193 (+1 hits since last alert)|www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.vangentholding.com"] [uri "/xmlrpc.php"] [unique_id "Zv3BmNIySzO1QyhSTvf6dAAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ธ๐ช
vaia.cloud
|
|
trying wp-login.php/xmlrpc.php 54 times in 1 minutes
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 51.222.32.193 (ip193.ip-51-222-32.net): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 51.222.32.193 (ip193.ip-51-222-32.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 02 07:14:44.581630 2024] [security2:error] [pid 15049:tid 15049] [client 51.222.32.193:50104] [client 51.222.32.193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 51.222.32.193 (+1 hits since last alert)|joevallone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "joevallone.com"] [uri "/xmlrpc.php"] [unique_id "Zv0rJGN-y0Tw2kQ5fnjeaQAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
apache-wordpress-login
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
|
Open Proxy
|
|
|
Anonymous
|
|
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
|
Open Proxy
|
|
|
Anonymous
|
|
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
|
Open Proxy
|
|
|
๐ช๐ธ
el-brujo
|
|
Proxies digitalstress[.]su used for attacking
|
DDoS Attack
|
|