๐ฉ๐ช
/dev/null
2025-03-26 21:34:33
(1 year ago)
CMS Bruteforce / WebApp Attack attempt
Hacking
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-03-26 20:41:06
(1 year ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 20:39:04
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 52.254.84.129 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 52.254.84.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 16:39:01.211880 2025] [security2:error] [pid 2381840:tid 2381840] [client 52.254.84.129:12567] [client 52.254.84.129] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||drlaurengardner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "drlaurengardner.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-Rl5a-BLNnKkzr94mFIewAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-26 20:28:50
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted] 52.254.84.129 (US/United States/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-03-26 19:23:10
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 52.254.84.129 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 52.254.84.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 15:23:04.685442 2025] [security2:error] [pid 21097:tid 21097] [client 52.254.84.129:12606] [client 52.254.84.129] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||solarpowersignage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "solarpowersignage.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-RUGGih27oKcTdaRO6ejwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 18:43:47
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 52.254.84.129 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 52.254.84.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 14:43:42.922175 2025] [security2:error] [pid 1533682:tid 1533682] [client 52.254.84.129:12498] [client 52.254.84.129] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||andreas-villa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "andreas-villa.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z-RK3h3QaJbx0R-MqP7hTQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-03-26 17:00:43
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
ph
2025-03-26 15:57:39
(1 year ago)
Bad web bot attempting to run wp-content on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2025-03-26 13:55:46
(1 year ago)
52.254.84.129 - - [26/Mar/2025:13:54:01 +0000] "GET /cgi-bin/fm.php HTTP/2.0" 404 16824 "-" rt="0.46 ...
show more
52.254.84.129 - - [26/Mar/2025:13:54:01 +0000] "GET /cgi-bin/fm.php HTTP/2.0" 404 16824 "-" rt="0.465" "-" "52.254.84.129" h="ccoo.app" sn="ccoo.app" ru="/cgi-bin/fm.php" u="/index.php" ucs="-" ua="unix:/var/run/php/ccooapp82.sock" us="404" uct="0.000" urt="0.465"
52.254.84.129 - - [26/Mar/2025:13:54:01 +0000] "GET /cgi-bin/fm.php HTTP/2.0" 404 16824 "-" "-" "52.254.84.129"
52.254.84.129 - - [26/Mar/2025:13:55:29 +0000] "GET /cgi-bin/1.php HTTP/2.0" 404 16823 "-" rt="0.376" "-" "52.254.84.129" h="ccoo.app" sn="ccoo.app" ru="/cgi-bin/1.php" u="/index.php" ucs="-" ua="unix:/var/run/php/ccooapp82.sock" us="404" uct="0.000" urt="0.377"
52.254.84.129 - - [26/Mar/2025:13:55:30 +0000] "GET /cgi-bin/admin.php HTTP/2.0" 404 16822 "-" rt="0.332" "-" "52.254.84.129" h="ccoo.app" sn="ccoo.app" ru="/cgi-bin/admin.php" u="/index.php" ucs="-" ua="unix:/var/run/php/ccooapp82.sock" us="404" uct="0.000" urt="0.332"
52.254.84.129 - - [26/Mar/2025:13:55:38 +0000] "GET /cgi-bin/about.php HTTP/2.0" 404 1682
...
show less
Bad Web Bot
๐จ๐ญ
backslash
2025-03-26 13:00:26
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
kosada.com
2025-03-26 11:47:04
(1 year ago)
Web vulnerability probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 10:21:37
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 52.254.84.129 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 52.254.84.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 06:21:30.781729 2025] [security2:error] [pid 28731:tid 28731] [client 52.254.84.129:1710] [client 52.254.84.129] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.murphylumber.ca|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.murphylumber.ca"] [uri "/images/stories/admin-post.php"] [unique_id "Z-PVKuMo37GR2O8-w3vpGwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
mitsurugi
2025-03-26 09:17:00
(1 year ago)
Probing for too many things.
Bad Web Bot
Web App Attack
๐ฆ๐บ
advena
2025-03-26 08:46:02
(1 year ago)
52.254.84.129 (AS8075 MICROSOFT-CORP-MSN-AS-BLOCK) was intercepted at 2025-03-26T08:37:22Z after vio ...
show more
52.254.84.129 (AS8075 MICROSOFT-CORP-MSN-AS-BLOCK) was intercepted at 2025-03-26T08:37:22Z after violating WAF directive: 874a3e315c344b1281ad4f00046aab6f. Pre-cautionary/corrective action applied: managed_challenge.
show less
Web Spam
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2025-03-26 08:23:26
(1 year ago)
Multiple WAF Violations
Web App Attack