[SunFeb2011:56:13.5288142022][:error][pid25416:tid46920942814976][client62.210.114.59:47114][client6 ... show more[SunFeb2011:56:13.5288142022][:error][pid25416:tid46920942814976][client62.210.114.59:47114][client62.210.114.59]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.php\"atARGS:img.[file\"/etc/apache2/conf.d/modsec_rules/99_asl_jitp.conf\"][line\"787\"][id\"337479\"][rev\"2\"][msg\"Atomicorp.comWAFRules-VirtualJustInTimePatch:WordpressRevslidernon-imagefiledownloadAttack\"][severity\"CRITICAL\"][hostname\"prova.gmpsud.ch\"][uri\"/wp-admin/admin-ajax.php\"][unique_id\"YhIeTVPqAB6CyDBEcrt5pwAAAE0\"][SunFeb2011:56:14.9029062022][:error][pid25576:tid46920955422464][client62.210.114.59:47193][client62.210.114.59]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"wp-content/uploads/.\*\\\\\\\\.ph\(\?:p\|tml\|t\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/99_asl_jitp.conf\"][line\"5028\"][id\"382238\"][rev\"2\"][msg\"Atomicorp.comWAFRules-VirtualJustInTimePatch:PHPfileexecutioninuploadsdirectorydenied\"][data\"wp-content/uploads/wp-craft-report.php\"][severity\"CRITICAL\"][ show less
(mod_security) mod_security (id:210492) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern ... show more(mod_security) mod_security (id:210492) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern-rdns.eu): 1 in the last 3600 secs show less
Brute-Force
Anonymous
/wp-content/themes/classic/inc/
/wp-content/plugins/networker/networker.php
/wp-includ ... show more/wp-content/themes/classic/inc/
/wp-content/plugins/networker/networker.php
/wp-includes/bacot.php
/wp-admin/css/colors/blue/blue.php?ch=1 show less
[SatFeb1220:20:03.2562902022][:error][pid25196:tid47734746924800][client62.210.114.59:43979][client6 ... show more[SatFeb1220:20:03.2562902022][:error][pid25196:tid47734746924800][client62.210.114.59:43979][client62.210.114.59]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"wp_is_mobile\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"61\"][id\"337741\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AccessPressThemesbackdoorblocked\"][severity\"CRITICAL\"][hostname\"annunci-ticino.ch\"][uri\"/\"][unique_id\"YggIYxqscA6G66JoJTpkhgAAAMw\"][SatFeb1220:20:03.8998642022][:error][pid25872:tid47734761633536][client62.210.114.59:55893][client62.210.114.59]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"wp_is_mobile\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"61\"][id\"337741\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AccessPressThemesbackdoorblocked\"][severity\"CRITICAL\"][hostname\"www.annunci-ticino.ch\"][uri\"/en/\"][unique_id\"YggIYyiRuUhH0zBBVRMO6QAAABM\"]\,referer:http://annunci-ticino.ch show less
Blog Spam
Anonymous
62.210.114.59 - - [11/Feb/2022:18:45:25 +0100] "GET //wp-content/themes/wp-update.php HTTP/1.1" 404 ... show more62.210.114.59 - - [11/Feb/2022:18:45:25 +0100] "GET //wp-content/themes/wp-update.php HTTP/1.1" 404 4765 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36"
62.210.114.59 - - [11/Feb/2022:18:45:25 +0100] "GET //wp-content/themes/p.txt HTTP/1.1" 404 5808 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36"
62.210.114.59 - - [11/Feb/2022:18:45:25 +0100] "GET //doc.php HTTP/1.1" 404 4765 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36"
62.210.114.59 - - [11/Feb/2022:18:45:25 +0100] "GET //wp-admin/edit-form-up.php HTTP/1.1" 404 4765 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36"
... show less
(PERMBLOCK) 62.210.114.59 (FR/France/62.210.114.59.hdintern-rdns.eu) has had more than 2 temp blocks ... show more(PERMBLOCK) 62.210.114.59 (FR/France/62.210.114.59.hdintern-rdns.eu) has had more than 2 temp blocks in the last 86400 secs show less
(mod_security) mod_security (id:950130) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern ... show more(mod_security) mod_security (id:950130) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern-rdns.eu): 1 in the last 3600 secs show less
(mod_security) mod_security (id:400010) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern ... show more(mod_security) mod_security (id:400010) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern-rdns.eu): 5 in the last 3600 secs show less
(mod_security) mod_security (id:933150) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern ... show more(mod_security) mod_security (id:933150) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern-rdns.eu): 1 in the last 3600 secs show less
(mod_security) mod_security (id:933150) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern ... show more(mod_security) mod_security (id:933150) triggered by 62.210.114.59 (FR/France/62.210.114.59.hdintern-rdns.eu): 1 in the last 3600 secs show less