๐บ๐ธ
TPI-Abuse
2024-11-26 23:27:42
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 64.137.92.129 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 64.137.92.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 26 18:27:34.576618 2024] [security2:error] [pid 14709:tid 14867] [client 64.137.92.129:46841] [client 64.137.92.129] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /wp-content/plugins/usc-e-shop/functions/content-log.php?logfile=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/wp-content/plugins/usc-e-shop/functions/content-log.php"] [unique_id "Z0ZZZqT8ZjqC-hUlXJfnCgAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2024-11-22 04:10:32
(1 year ago)
r=test/sss&data=TzoyMzoieWlpXGRiXEJhdGNoUXVlcnlSZXN1bHQiOjE6e3M6MzY6IgB5aWlcZGJcQmF0Y2hRdWVyeVJlc3Vs ...
show more
r=test/sss&data=TzoyMzoieWlpXGRiXEJhdGNoUXVlcnlSZXN1bHQiOjE6e3M6MzY6IgB5aWlcZGJcQmF0Y2hRdWVyeVJlc3VsdABfZGF0YVJlYWRlciI7TzoxNToiRmFrZXJcR2VuZXJhdG9yIjoxOntzOjEzOiIAKgBmb3JtYXR0ZXJzIjthOjE6e3M6NToiY2xvc2UiO2E6Mjp7aTowO086MjE6InlpaVxyZXN0XENyZWF0ZUFjdGlvbiI6Mjp7czoxMToiY2hlY2tBY2Nlc3MiO3M6Njoic3lzdGVtIjtzOjI6ImlkIjtzOjY6ImxzIC1hbCI7fWk6MTtzOjM6InJ1biI7fX19fQ==
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-04 02:56:31
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 64.137.92.129 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 64.137.92.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 22:56:25.692404 2024] [security2:error] [pid 23641:tid 23641] [client 64.137.92.129:50179] [client 64.137.92.129] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.stdavids-media.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_news_portal&controller=../../../../../../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stdavids-media.com"] [uri "/index.php"] [unique_id "ZtfMWYwm7pCD6OiNJs7d8AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-01 01:55:15
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.137.92.129 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 64.137.92.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:52:22.669948 2024] [security2:error] [pid 3087953:tid 3087964] [client 64.137.92.129:37603] [client 64.137.92.129] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.net"] [uri "/spring-mvc-showcase/resources/%5c%5c..%5c/..%5c/..%5c/..%5c/..%5c/..%5c/..%5c/..%5c/..%5c/windows/win.ini"] [unique_id "ZtPI1upNq9YuaJqIJW3JAwAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-08-03 17:03:41
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฆ๐บ
oncord
2024-07-23 12:52:46
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
oncord
2024-07-20 05:59:44
(1 year ago)
Form spam
Web Spam
๐จ๐ญ
backslash
2024-07-17 16:00:15
(1 year ago)
block ruleset 6A1105329D233F6F53B9B61CE056BD4DAAE75AB4
Web Spam
๐ฌ๐ง
oncord
2024-07-16 02:25:13
(1 year ago)
Form spam
Web Spam
๐ฉ๐ช
ps-center
2024-07-15 19:25:23
(1 year ago)
SS1: Web Attack GET /wp-content/plugins/wpsite-background-takeover/exports/download.php?filename=../ ...
show more
SS1: Web Attack GET /wp-content/plugins/wpsite-background-takeover/exports/download.php?filename=../../../../wp-config.php
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-07-14 00:06:32
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
oncord
2024-07-13 02:42:37
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2024-06-27 07:15:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.137.92.129 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 64.137.92.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 03:15:39.570321 2024] [security2:error] [pid 31354:tid 47386278582016] [client 64.137.92.129:39641] [client 64.137.92.129] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.net"] [uri "/base_import/static/c:/windows/win.ini"] [unique_id "Zn0Rm216tgjLDvCz7qLiSwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-05-08 17:03:00
(2 years ago)
Brute force seen in log review
Brute-Force
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:01:07
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force