π΅π±
strefapi_com
2024-09-09 03:45:20
(2 years ago)
Brute-force web
...
Hacking
Brute-Force
Web App Attack
πΊπΈ
lavnet.net
2024-08-13 19:30:02
(2 years ago)
[Tue Aug 13 19:30:00.793465 2024] [authz_core:error] [pid 2887652:tid 2887652] [client 74.208.2.234: ...
show more
[Tue Aug 13 19:30:00.793465 2024] [authz_core:error] [pid 2887652:tid 2887652] [client 74.208.2.234:33527] AH01630: client denied by server configuration: /var/www/a0a0.org/web/index.php
[Tue Aug 13 19:30:00.793863 2024] [authz_core:error] [pid 2887652:tid 2887652] [client 74.208.2.234:33527] AH01630: client denied by server configuration: /var/www/a0a0.org/web/index.php
[Tue Aug 13 19:30:02.034612 2024] [authz_core:error] [pid 2887652:tid 2887652] [client 74.208.2.234:33527] AH01630: client denied by server configuration: /var/www/a0a0.org/web/wp-cron.php
...
show less
Brute-Force
π©πͺ
kommunos
2024-06-01 16:37:44
(2 years ago)
/wp-cron.php
Web App Attack
πΊπΈ
TPI-Abuse
2024-04-10 03:51:33
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 09 23:51:27.505684 2024] [security2:error] [pid 20684] [client 74.208.2.234:56709] [client 74.208.2.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nccb.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nccb.org"] [uri "/theunion.com"] [unique_id "ZhYMv8U6Zz1XW8CjPeO-AQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
lavnet.net
2024-04-07 22:58:59
(2 years ago)
[Sun Apr 07 22:58:57.803575 2024] [authz_core:error] [pid 2655618] [client 74.208.2.234:36987] AH016 ...
show more
[Sun Apr 07 22:58:57.803575 2024] [authz_core:error] [pid 2655618] [client 74.208.2.234:36987] AH01630: client denied by server configuration: /var/www/a0a0.org/web/index.php
[Sun Apr 07 22:58:57.803750 2024] [authz_core:error] [pid 2655618] [client 74.208.2.234:36987] AH01630: client denied by server configuration: /var/www/a0a0.org/web/index.php
[Sun Apr 07 22:58:59.150344 2024] [authz_core:error] [pid 2655618] [client 74.208.2.234:36987] AH01630: client denied by server configuration: /var/www/a0a0.org/web/wp-cron.php
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2024-03-18 14:21:31
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 18 10:21:26.007909 2024] [security2:error] [pid 24204:tid 47202951857920] [client 74.208.2.234:60457] [client 74.208.2.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wsotc.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wsotc.org"] [uri "/[email protected] "] [unique_id "ZfhN5vH5lM2yccX5WPDx4AAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-14 01:49:48
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 13 20:49:45.033142 2024] [security2:error] [pid 26086] [client 74.208.2.234:35615] [client 74.208.2.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dalessalesandservice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dalessalesandservice.com"] [uri "/[email protected] "] [unique_id "ZcwcORvBQ4_tz7diR73XoAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-02-14 00:56:24
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 13 19:56:16.550006 2024] [security2:error] [pid 19144] [client 74.208.2.234:58891] [client 74.208.2.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chicagowca.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chicagowca.com"] [uri "/[email protected] "] [unique_id "ZcwPsAEIeGmCOAs5SEgb7wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Buster
2024-01-25 18:52:38
(2 years ago)
Repeated script kiddie mass distributed attack attempts on multiple sites from Perm Blocked Extremel ...
show more
Repeated script kiddie mass distributed attack attempts on multiple sites from Perm Blocked Extremely High Risk ASN and country:
show less
Open Proxy
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-15 07:21:43
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 74.208.2.234 (crawlga161.1and1.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 15 02:21:38.725970 2024] [security2:error] [pid 16536] [client 74.208.2.234:59159] [client 74.208.2.234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rodrandolph.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rodrandolph.com"] [uri "/instagram.com"] [unique_id "ZaTdAjMPN22vMHJ0QielbAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Al Coholic
2024-01-10 02:29:38
(2 years ago)
Detected By Fail2ban
Hacking
Web App Attack
π©πͺ
kommunos
2023-12-13 21:02:41
(2 years ago)
/wp-cron.php
Web App Attack
πΊπΈ
findlab
2023-12-03 00:20:02
(2 years ago)
Backdrop CMS module - scanning for vulnerable files
Bad Web Bot
Web App Attack
πΈπ¬
mypatricks
2023-05-16 01:18:57
(3 years ago)
74.208.2.234 | Port: 20768 | DNS: crawlga161.1and1.org 2023-05-16T09:18:56+08:00 Asia/Singapore | Un ...
show more
74.208.2.234 | Port: 20768 | DNS: crawlga161.1and1.org 2023-05-16T09:18:56+08:00 Asia/Singapore | Un-authorized bots or crawlers | UA: IonCrawl (https://www.ionos.de/terms-gtc/faq-crawler-en/) HTTP/1.1 443 GET | URL: /wp-sitemap.xml | Ref: - | Country: US/United States/-08:00 IP City: 7c7fca17594a03b4-ORD/Chicago, IL, United States 1 hits/0 secs Robots 0
show less
Web Spam
Blog Spam
Brute-Force
Exploited Host
Web App Attack
π¬π§
findlab
2023-01-16 03:22:49
(3 years ago)
Backdrop CMS module - Request: /wp-admin/admin-ajax.php
Bad Web Bot
Web App Attack