๐ฉ๐ช
dwmp
2024-05-15 11:14:35
(2 years ago)
Url probing: /wp-admin/admin-ajax.php
Web App Attack
๐ฒ๐พ
syokadmin
2024-05-15 10:02:10
(2 years ago)
(mod_security) mod_security (id:77141007) triggered by 70.36.35.44 (US/United States/-): 1 in the la ...
show more
(mod_security) mod_security (id:77141007) triggered by 70.36.35.44 (US/United States/-): 1 in the last 3600 secs
show less
Brute-Force
Anonymous
2024-05-15 04:06:30
(2 years ago)
70.36.35.44 - - [15/May/2024:06:06:29 +0200] "GET /wp-admin/admin-ajax.php?action=duplicator_downloa ...
show more
70.36.35.44 - - [15/May/2024:06:06:29 +0200] "GET /wp-admin/admin-ajax.php?action=duplicator_download&file=../wp-config.php HTTP/1.1" 403 363 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0"
...
show less
Web App Attack
๐ฆ๐บ
weblite
2024-05-14 10:52:04
(2 years ago)
WP_MALWARE_PROBE
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2024-05-14 09:58:03
(2 years ago)
Looking for CMS/PHP/SQL vulnerablilities - 1
Exploited Host
Web App Attack
๐ฎ๐ฉ
Burayot
2024-05-14 07:30:30
(2 years ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 70.36.35.44 (US/United States/-): 2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 70.36.35.44 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-05-14 00:51:43
(2 years ago)
70.36.35.44 - - [14/May/2024:03:51:43 +0300] "GET /wp-admin/admin-ajax.php?action=duplicator_downloa ...
show more
70.36.35.44 - - [14/May/2024:03:51:43 +0300] "GET /wp-admin/admin-ajax.php?action=duplicator_download&file=../wp-config.php HTTP/1.1" 404 279 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-13 22:48:26
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 13 18:48:18.655973 2024] [security2:error] [pid 24878] [client 70.36.35.44:58378] [client 70.36.35.44] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "assistfeed.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZkKYsuTZyT58Hyphh6DrqAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Swiptly
2024-05-13 21:07:15
(2 years ago)
Multiple critical ModSecurity events
...
Web Spam
Bad Web Bot
๐บ๐ธ
mnsf
2024-05-13 19:01:11
(2 years ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-13 18:26:26
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 13 14:26:22.994064 2024] [security2:error] [pid 5175] [client 70.36.35.44:32912] [client 70.36.35.44] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ashwoodsecurity.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZkJbTqe1_lvj_jDORnNEpgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-13 17:56:04
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 13 13:56:00.675162 2024] [security2:error] [pid 17903] [client 70.36.35.44:59426] [client 70.36.35.44] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ashburnp.us"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZkJUMBA1N14dsW1BlfmByAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-13 15:06:04
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 13 11:06:00.200511 2024] [security2:error] [pid 4811] [client 70.36.35.44:43444] [client 70.36.35.44] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mitchellart.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZkIsWEAf3GAyOg7KG1YKaQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-05-13 14:39:31
(2 years ago)
70.36.35.44 - - [13/May/2024:17:39:30 +0300] "GET /wp-admin/admin-ajax.php?action=duplicator_downloa ...
show more
70.36.35.44 - - [13/May/2024:17:39:30 +0300] "GET /wp-admin/admin-ajax.php?action=duplicator_download&file=../wp-config.php HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0"
70.36.35.44 - - [13/May/2024:17:39:31 +0300] "GET /wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-13 14:37:01
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 70.36.35.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 13 10:36:53.851050 2024] [security2:error] [pid 2384796] [client 70.36.35.44:54908] [client 70.36.35.44] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artritiscanina.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZkIlhamLKijcCboXsFs5jAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack