Anonymous
2024-09-30 18:03:34
(2 years ago)
Malicious activity detected
Hacking
Web App Attack
๐ฆ๐บ
MAGIC
2024-09-30 15:03:49
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ช๐ธ
seoxan.es
2024-09-27 23:39:27
(2 years ago)
SQL Injection attempt detected Type Footer
SQL Injection
๐บ๐ธ
TPI-Abuse
2024-09-26 16:27:51
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazon ...
show more
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 26 12:27:47.295584 2024] [security2:error] [pid 27624:tid 27653] [client 54.234.14.37:55200] [client 54.234.14.37] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kerrfamilyassociation.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kerrfamilyassociation.com"] [uri "/[email protected] "] [unique_id "ZvWLg1ak_6XgYCfE12gm7wAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
fbarbosa
2024-09-26 07:06:00
(2 years ago)
Abusive scrapping, Accessing pages in multiple languages rapidly, indicating non-human browsing beha ...
show more
Abusive scrapping, Accessing pages in multiple languages rapidly, indicating non-human browsing behavior
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-25 23:03:11
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazon ...
show more
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 25 19:03:03.720495 2024] [security2:error] [pid 10123:tid 10123] [client 54.234.14.37:34862] [client 54.234.14.37] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.backstore.com|F|2"] [data ".losangelesseating.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.backstore.com"] [uri "/www.losangelesseating.com"] [unique_id "ZvSWp4ZKthFJynMuCWgnmgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-25 16:35:07
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazon ...
show more
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 25 12:35:02.308197 2024] [security2:error] [pid 18725:tid 18725] [client 54.234.14.37:57956] [client 54.234.14.37] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.newisci.org|F|2"] [data ".safari-eha.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.newisci.org"] [uri "/expo_2025/www.safari-eha.com"] [unique_id "ZvQ7tqRVfWAsdEyg7e05BQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-25 08:51:55
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazon ...
show more
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 25 04:51:47.816282 2024] [security2:error] [pid 12793:tid 12861] [client 54.234.14.37:50176] [client 54.234.14.37] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.munatseng.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.munatseng.org"] [uri "/stories/tsengkwongchi.com"] [unique_id "ZvPPIzXajxueuqs58Ozl0wAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
valeon
2024-09-24 17:52:45
(2 years ago)
Bad Web Bot
Web App Attack
๐ฌ๐ง
my.wildye.com
2024-09-24 12:49:27
(2 years ago)
AUTOMATED REPORT: Trying to spam. Automated form submission
Web Spam
๐ซ๐ท
COMAITE
2024-09-23 01:40:47
(2 years ago)
Multiple web server 400 error codes from same source ip 54.234.14.37.
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-22 18:58:06
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazon ...
show more
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 22 14:57:59.076145 2024] [security2:error] [pid 4188:tid 4188] [client 54.234.14.37:59338] [client 54.234.14.37] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thequietplacemassage.net|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thequietplacemassage.net"] [uri "/[email protected] "] [unique_id "ZvBot2e5qZtshQJaco7QxQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Michael McCarthy
2024-09-22 18:27:00
(2 years ago)
Web Spam
๐บ๐ธ
TPI-Abuse
2024-09-22 15:40:57
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazon ...
show more
(mod_security) mod_security (id:210730) triggered by 54.234.14.37 (ec2-54-234-14-37.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 22 11:40:53.098248 2024] [security2:error] [pid 18891:tid 18891] [client 54.234.14.37:41378] [client 54.234.14.37] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||climasyequipos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "climasyequipos.com"] [uri "/[email protected] "] [unique_id "ZvA6hbTvAf6p9Tn8PAqH8wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
strzonnek
2024-09-22 13:17:14
(2 years ago)
attack on webform
Brute-Force
Web App Attack