|
Anonymous
|
|
Malicious activity detected
|
Hacking
Web App Attack
|
|
|
๐ฆ๐บ
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|
|
๐ฉ๐ช
mxinfra
|
|
Blocked by Fail2Ban (plesk-modsecurity)
|
Hacking
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 01 02:09:44.248449 2024] [security2:error] [pid 747129:tid 747129] [client 64.64.123.40:21935] [client 64.64.123.40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aeongames.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aeongames.com"] [uri "/backup.sql"] [unique_id "Z0wLuAtOUHfMdwkliRxS8wAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ฟ
Honzas
|
|
Unsolicited connection attemps(12458), port 3389/TCP
|
Brute-Force
|
|
|
๐จ๐ฆ
Skynet
|
|
date=1732952987;service=RDP;attempts=5
|
Brute-Force
|
|
|
๐จ๐ฆ
Skynet
|
|
date=1732949335;service=RDP;attempts=6
|
Brute-Force
|
|
|
๐จ๐ฆ
Skynet
|
|
date=1732947480;service=RDP;attempts=5
|
Brute-Force
|
|
|
๐จ๐ฆ
Skynet
|
|
date=1732946557;service=RDP;attempts=7
|
Brute-Force
|
|
|
๐จ๐ฟ
Neoloop
|
|
[Harmony] RDP recent login attempts (more than 6 tries, last user tried: ELITESERVIDOR)
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 28 07:11:17.973385 2024] [security2:error] [pid 20489:tid 20599] [client 64.64.123.40:30381] [client 64.64.123.40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.fishrapper.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.fishrapper.com"] [uri "/backups/sql.sql"] [unique_id "Z0hd5QwFBeCBlNX0CHYqIgAAAM8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 22 01:36:12.725252 2024] [security2:error] [pid 30075:tid 30075] [client 64.64.123.40:40267] [client 64.64.123.40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barnesandbrower.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barnesandbrower.com"] [uri "/back/sql.sql"] [unique_id "Z0AmXGUWep10Yp2KJKTgLgAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 22 01:16:31.426166 2024] [security2:error] [pid 17948:tid 17948] [client 64.64.123.40:38387] [client 64.64.123.40] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.enriquelaw.com"] [uri "/old/sftp-config.json"] [unique_id "Z0Ahv0_v4SAJsskV3xSi_AAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.64.123.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 20 06:43:55.973532 2024] [security2:error] [pid 711988:tid 711988] [client 64.64.123.40:63493] [client 64.64.123.40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lundtrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lundtrading.com"] [uri "/bak/www.sql"] [unique_id "Zz3Le19wLWpC8c0vUsCKtwAAACk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
CryptoYakari
|
|
64.64.123.40 - - [19/Nov/2024:15:51:52 +0300] "HEAD /restore/www.sql HTTP/1.0" 404 436 "-" "-"
64.64 ...
show more
64.64.123.40 - - [19/Nov/2024:15:51:52 +0300] "HEAD /restore/www.sql HTTP/1.0" 404 436 "-" "-"
64.64.123.40 - - [19/Nov/2024:15:51:54 +0300] "GET /backup/bak.zip HTTP/1.0" 404 28881 "-" "-"
64.64.123.40 - - [19/Nov/2024:15:51:54 +0300] "HEAD /bak/wallet.dat HTTP/1.0" 404 436 "-" "-"
64.64.123.40 - - [19/Nov/2024:15:51:56 +0300] "GET /restore/full_backup.zip HTTP/1.0" 404 28963 "-" "-"
64.64.123.40 - - [19/Nov/2024:15:51:57 +0300] "GET /backup/bak.rar HTTP/1.0" 404 28881 "-" "-"
...
show less
|
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
|
|