Anonymous
2024-02-23 00:06:59
(2 years ago)
apache-noscript
Brute-Force
๐ฆ๐บ
weblite
2024-02-22 15:56:53
(2 years ago)
WP_EXPLOIT_PROBE WP_MALWARE_PROBE
Hacking
Web App Attack
๐ซ๐ท
pm33
2024-02-22 11:31:35
(2 years ago)
Probing for resource vulnerabilities
Web App Attack
๐ซ๐ท
uhlhosting
2024-02-22 04:59:24
(2 years ago)
mediation-recht-surber.ch 51.91.80.80 - - [22/Feb/2024:05:55:02.461000 +0100] "GET /wp-includes/js/t ...
show more
mediation-recht-surber.ch 51.91.80.80 - - [22/Feb/2024:05:55:02.461000 +0100] "GET /wp-includes/js/tinymce/plugins/wordpress/index.php?520=1 HTTP/1.1" 403 199 "-" "-" ZdbTpntCVwf0a2g53MCB1wAAAAY "-" /apache/20240222/20240222-0555/20240222-055502-ZdbTpntCVwf0a2g53MCB1wAAAAY 0 1327 md5:87c8e0c950e2ffa981c9bf02e1ccc18a
mediation-recht-surber.ch 51.91.80.80 - - [22/Feb/2024:05:56:12.195126 +0100] "GET /wp-includes/blocks/site-tagline/index.php?520=1 HTTP/1.1" 403 199 "-" "-" ZdbT7PkGtPHQBLeN07wo_AAAAI8 "-" /apache/20240222/20240222-0556/20240222-055612-ZdbT7PkGtPHQBLeN07wo_AAAAI8 0 1309 md5:3c3c22baba86fb21b20e0555d47c5b45
mediation-recht-surber.ch 51.91.80.80 - - [22/Feb/2024:05:57:20.886301 +0100] "GET /wp-includes/blocks/html/index.php?520=1 HTTP/1.1" 403 199 "-" "-" ZdbUMHtCVwf0a2g53MCCDAAAAAA "-" /apache/20240222/20240222-0557/20240222-055720-ZdbUMHtCVwf0a2g53MCCDAAAAAA 0 1293 md5:9d5c1010073a8040c5720e9640997074
mediation-recht-surber.ch 51.91.80.80 - - [22/Feb/2024:05:58:55.83461
...
show less
DDoS Attack
Brute-Force
๐บ๐ธ
WebWizards.NZ
2024-02-21 15:16:37
(2 years ago)
Trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-21 05:44:27
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 51.91.80.80 (ns1.agence-web.company): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 51.91.80.80 (ns1.agence-web.company): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 21 00:44:22.958426 2024] [security2:error] [pid 6921] [client 51.91.80.80:47174] [client 51.91.80.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tallpinesranch.org|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tallpinesranch.org"] [uri "/wp-content/plugins/wordfence/vendor/wordfence/wf-waf/src/rules.key"] [unique_id "ZdWNti1olr_HtyjTYHyI4QAAAAQ"], referer: tallpinesranch.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2024-02-20 18:30:04
(2 years ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-20 18:14:10
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 51.91.80.80 (ns1.agence-web.company): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 51.91.80.80 (ns1.agence-web.company): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 20 13:14:06.555501 2024] [security2:error] [pid 19834] [client 51.91.80.80:52588] [client 51.91.80.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||samadmiraly.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "samadmiraly.com"] [uri "/wp-content/plugins/wordfence/vendor/wordfence/wf-waf/src/rules.key"] [unique_id "ZdTr7n2wrNkvoT5RBO1vQgAAAAk"], referer: samadmiraly.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-20 16:58:39
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 51.91.80.80 (ns1.agence-web.company): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 51.91.80.80 (ns1.agence-web.company): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 20 11:58:33.291682 2024] [security2:error] [pid 15875] [client 51.91.80.80:55666] [client 51.91.80.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cosplayculture.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cosplayculture.com"] [uri "/wp-content/plugins/wordfence/vendor/wordfence/wf-waf/src/rules.key"] [unique_id "ZdTaOasXxmVR3S-nSmODpQAAAAE"], referer: cosplayculture.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-20 16:29:35
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 51.91.80.80 (ns1.agence-web.company): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 51.91.80.80 (ns1.agence-web.company): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 20 11:29:28.286224 2024] [security2:error] [pid 11897:tid 47321628829440] [client 51.91.80.80:59292] [client 51.91.80.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pilargarciamanzanares.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pilargarciamanzanares.com"] [uri "/wp-content/plugins/wordfence/vendor/wordfence/wf-waf/src/rules.key"] [unique_id "ZdTTaBNAPOQX-yfbvIVdfwAAAYw"], referer: pilargarciamanzanares.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2024-02-20 10:54:32
(2 years ago)
Blocking for trying to access an exploit file: /scripts/admin.php?520=1
Hacking
๐ฆ๐บ
MAGIC
2024-02-19 09:11:01
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ซ๐ฎ
JimArchon72
2024-02-11 03:11:01
(2 years ago)
2024/02/11 03:10:50 "GET /wp-admin/user/admin.php?520=1 HTTP/1.1"
Web App Attack
Anonymous
2024-02-10 15:04:14
(2 years ago)
Automated report (2024-02-10T15:04:14+00:00). Caught probing for webshells/backdoors. Host might be ...
show more
Automated report (2024-02-10T15:04:14+00:00). Caught probing for webshells/backdoors. Host might be compromised.
show less
Hacking
Exploited Host
Web App Attack
๐ฆ๐บ
weblite
2024-02-07 23:03:18
(2 years ago)
WP_EXPLOIT_PROBE WP_MALWARE_PROBE
Hacking
Web App Attack