๐ฌ๐ง
Globe2
2025-11-28 21:45:43
(9 months ago)
ModSec - Multiple 403s within a short period of time [server: H3]
Web App Attack
๐บ๐ธ
LotPhantom
2025-11-22 09:17:38
(9 months ago)
62.146.238.71 - - [22/Nov/2025:09:16:38 +0000] "HEAD / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (X11; Linux ...
show more
62.146.238.71 - - [22/Nov/2025:09:16:38 +0000] "HEAD / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36" "0"
...
show less
Web App Attack
๐บ๐ธ
LotPhantom
2025-11-18 15:32:47
(9 months ago)
62.146.238.71 - - [18/Nov/2025:15:31:47 +0000] "HEAD / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT ...
show more
62.146.238.71 - - [18/Nov/2025:15:31:47 +0000] "HEAD / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
gerensat
2025-11-16 12:52:45
(10 months ago)
2025-11-16 09:52:45 | / | [] | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, ...
show more
2025-11-16 09:52:45 | / | [] | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
show less
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2025-11-15 21:51:49
(10 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ง๐ท
leolemos
2025-11-15 15:52:24
(10 months ago)
[Sat Nov 15 12:52:24.014967 2025] [authz_core:error] [pid 433757:tid 247214718513344] [client 62.146 ...
show more
[Sat Nov 15 12:52:24.014967 2025] [authz_core:error] [pid 433757:tid 247214718513344] [client 62.146.238.71:0] AH01630: client denied by server configuration: [redacted][redacted]/sites/index.php
[Sat Nov 15 12:52:24.016281 2025] [authz_core:error] [pid 433757:tid 247214718513344] [client 62.146.238.71:0] AH01630: client denied by server configuration: [redacted][redacted]/sites/index.php
[Sat Nov 15 12:52:24.412698 2025] [authz_core:error] [pid 433757:tid 247214735421632] [client 62.146.238.71:0] AH01630: client denied by server configuration: [redacted][redacted]/sites/index.php
show less
Brute-Force
๐บ๐ธ
agenciahypelab.com.br
2025-11-12 21:20:51
(10 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
LotPhantom
2025-11-12 12:14:26
(10 months ago)
62.146.238.71 - - [12/Nov/2025:12:13:26 +0000] "HEAD / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT ...
show more
62.146.238.71 - - [12/Nov/2025:12:13:26 +0000] "HEAD / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-11-10 14:12:07
(10 months ago)
62.146.238.71 - - [10/Nov/2025:16:12:05 +0200] "GET /wp-content/uploads/ HTTP/1.1" 404 196 "-" "Mozi ...
show more
62.146.238.71 - - [10/Nov/2025:16:12:05 +0200] "GET /wp-content/uploads/ HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
62.146.238.71 - - [10/Nov/2025:16:12:06 +0200] "GET /wp-content/plugins/ HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฒ๐พ
syokadmin
2025-11-10 10:53:32
(10 months ago)
62.146.238.71 (SG/Singapore/vmi2802276.contaboserver.net), more than 2 Apache 403 hits in the last 3 ...
show more
62.146.238.71 (SG/Singapore/vmi2802276.contaboserver.net), more than 2 Apache 403 hits in the last 3600 secs
show less
Brute-Force
๐ฎ๐ฉ
Burayot
2025-11-09 12:27:37
(10 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 62.146.238.71 (SG/Singapore/vmi2802 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 62.146.238.71 (SG/Singapore/vmi2802276.contaboserver.net): 2 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-09 07:26:35
(10 months ago)
[Sun Nov 09 14:25:46.616316 2025] [security2:error] [pid 1002428:tid 140439592105664] [client 62.146 ...
show more
[Sun Nov 09 14:25:46.616316 2025] [security2:error] [pid 1002428:tid 140439592105664] [client 62.146.238.71:62072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/wp" at REQUEST_FILENAME. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "83"] [id "448101"] [msg "BAD REQUEST FILENAME - Detected and Blocked"] [data "Matched Data: /wp found within REQUEST_FILENAME: /wp-content/uploads/ request_line = GET /wp-content/uploads/ HTTP/1.1"] [severity "NOTICE"] [hostname "matomo.staklim-malang.info"] [uri "/wp-content/uploads/"] [unique_id "aRBB-tflE2c9oQqaZws7xQAAAE0"] [matomo.staklim-malang.info] [matomo.staklim-malang.info] top=[1002468] [wvy1UiTKRAs] [aRBB-tflE2c9oQqaZws7xQAAAE0] keep_alive=[0] [2025-11-09 14:25:46.616319] [R:aRBB-tflE2c9oQqaZws7xQAAAE0] UA:'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36' Host:'matomo.staklim-malang.info' COOKIE:'MATOMO_SESSID=c860a04ef4
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2025-11-08 13:21:14
(10 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 62.146.238.71 (SG/Singapore/vmi28022 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 62.146.238.71 (SG/Singapore/vmi2802276.contaboserver.net): 1 in the last 3600 secs
show less
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-08 12:02:53
(10 months ago)
[Sat Nov 08 19:02:18.672638 2025] [authz_core:error] [pid 1123834:tid 139842600969920] [client 62.14 ...
show more
[Sat Nov 08 19:02:18.672638 2025] [authz_core:error] [pid 1123834:tid 139842600969920] [client 62.146.238.71:64613] AH01630: client denied by server configuration: /var/matomo/ [matomo.staklim-malang.info] [matomo.staklim-malang.info] top=[1123868] [M5XOEZTqEeE] [aQ8xSq57EYb0XGrOh-soaQAAA4c] keep_alive=[0] [2025-11-08 19:02:18.672652] [R:aQ8xSq57EYb0XGrOh-soaQAAA4c] UA:'Mozilla/5.0 (iPad; CPU OS 16_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.4 Mobile/15E148 Safari/604.1' Host:'mail.staklim-malang.info' ACCEPT:'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7' Accept-Encoding:'gzip, deflate, br Accept-Language:'en-US,en;q=0.9,fr;q=0.8 Upgrade-Insecure-Requests:'1
...
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2025-11-01 10:08:00
(10 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack