π§πͺ
taivas.nl
2024-01-30 05:32:30
(2 years ago)
Many_bad_calls
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-29 13:31:50
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 29 08:31:43.908639 2024] [security2:error] [pid 16531:tid 47404258150144] [client 78.143.236.87:55635] [client 78.143.236.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.visionforandfromchildren.org"] [uri "/.wp-config.php.swo"] [unique_id "Zbeov8V_JDgw99LGHJYCggAAAMc"], referer: https://www.yahoo.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
taivas.nl
2024-01-29 12:32:15
(2 years ago)
Bad_requests
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-01-28 22:22:09
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 28 17:22:01.361423 2024] [security2:error] [pid 3303] [client 78.143.236.87:40279] [client 78.143.236.87] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desertautoworks.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desertautoworks.com"] [uri "/wp-config.inc"] [unique_id "ZbbTiUyF_uGOmv7MJX_HLwAAAA8"], referer: https://www.yahoo.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-28 18:25:30
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 28 13:25:22.424648 2024] [security2:error] [pid 21975] [client 78.143.236.87:30349] [client 78.143.236.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flyc2c.com"] [uri "/wp-config.bak"] [unique_id "ZbacEiT8D7qloD9TozkuOAAAADM"], referer: https://www.yahoo.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-27 03:11:08
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 26 22:10:59.783441 2024] [security2:error] [pid 3586] [client 78.143.236.87:8293] [client 78.143.236.87] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.splashstation.org"] [uri "/.wp-config.php.swp"] [unique_id "ZbR0Qymi0eIvu_uvyA18jgAAAAs"], referer: https://www.yahoo.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Aetherweb Ark
2024-01-27 01:05:54
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 78.143.236.87 (NL/The Netherlands/-): N in the ...
show more
(mod_security) mod_security (id:210492) triggered by 78.143.236.87 (NL/The Netherlands/-): N in the last X secs
show less
Web App Attack
π©πͺ
nextweb
2024-01-26 13:05:11
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 78.143.236.87 (NL/The Netherlands/North Holland ...
show more
(mod_security) mod_security (id:210730) triggered by 78.143.236.87 (NL/The Netherlands/North Holland/Hoofddorp/-/[AS6830 Liberty Global B.V.]): 5 in the last 3600 secs (CF_ENABLE)
show less
Brute-Force
πΊπΈ
mnsf
2024-01-25 22:08:20
(2 years ago)
Too many Status 40X (21)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2024-01-23 15:58:02
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 78.143.236.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 23 10:57:55.944721 2024] [security2:error] [pid 7360] [client 78.143.236.87:21903] [client 78.143.236.87] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||genesis-castle.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "genesis-castle.com"] [uri "/wp-config.conf"] [unique_id "Za_iA_M-TKa462UEl4ocoQAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Frank Henkes
2024-01-21 16:01:43
(2 years ago)
[405 HEAD Request: 21 januari 2024 - 11:09]
BPS: 6.9
WP: 6.4.2
Event Code: BFHS-HEAD - HEAD Reque ...
show more
[405 HEAD Request: 21 januari 2024 - 11:09]
BPS: 6.9
WP: 6.4.2
Event Code: BFHS-HEAD - HEAD Request Blocked
Solution: https://forum.ait-pro.com/forums/topic/security-log-event-codes/
REMOTE_ADDR: 78.143.236.87
Host Name: 78.143.236.87
SERVER_PROTOCOL: HTTP/1.1
HTTP_CLIENT_IP:
HTTP_FORWARDED:
HTTP_X_FORWARDED_FOR:
HTTP_X_CLUSTER_CLIENT_IP:
REQUEST_METHOD: HEAD
HTTP_REFERER: https://www.google.com
REQUEST_URI: /wp-config.dump
QUERY_STRING:
HTTP_USER_AGENT: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
show less
Hacking
Brute-Force