π©πͺ
uhlhosting
2024-08-26 03:42:41
(2 years ago)
autojanser.ch 84.247.59.120 - - [26/Aug/2024:05:42:39.523838 +0200] "GET /wp-content/themes/sonoran/ ...
show more
autojanser.ch 84.247.59.120 - - [26/Aug/2024:05:42:39.523838 +0200] "GET /wp-content/themes/sonoran/mobile.php HTTP/1.1" 403 199 "-" "-" Zsv5r7w43HikhKK_dIPshwAAAQ4 "-" /apache/20240826/20240826-0542/20240826-054239-Zsv5r7w43HikhKK_dIPshwAAAQ4 0 1708 md5:d4f776e2796592d9ff849a337fcab63e
autojanser.ch 84.247.59.120 - - [26/Aug/2024:05:42:40.211599 +0200] "GET /wp-content/themes/intense/block-css.php HTTP/1.1" 403 199 "-" "-" Zsv5sLw43HikhKK_dIPsiAAAAQY "-" /apache/20240826/20240826-0542/20240826-054240-Zsv5sLw43HikhKK_dIPsiAAAAQY 0 1715 md5:aaa414f9140cc9f06015472c6d16af6c
autojanser.ch 84.247.59.120 - - [26/Aug/2024:05:42:40.711487 +0200] "GET /wp-content/themes/suntech/css_blocks.php HTTP/1.1" 403 199 "-" "-" Zsv5sLw43HikhKK_dIPsiQAAAQQ "-" /apache/20240826/20240826-0542/20240826-054240-Zsv5sLw43HikhKK_dIPsiQAAAQQ 0 1717 md5:190b15ecae99757b740b9ecf15808b00
autojanser.ch 84.247.59.120 - - [26/Aug/2024:05:42:41.219432 +0200] "GET /sidwsi.PhP7 HTTP/1.1" 403 199 "-" "-" Zsv5sbw43HikhK
...
show less
DDoS Attack
Brute-Force
π¦πΊ
MAGIC
2024-08-20 09:06:59
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2024-08-06 07:26:08
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2024-07-28 01:29:50
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 84.247.59.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 84.247.59.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 21:29:45.824347 2024] [security2:error] [pid 2110:tid 2110] [client 84.247.59.120:60345] [client 84.247.59.120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thenolangroup.llc|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thenolangroup.llc"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZqWfCRj_RCOC1bup4fmTzgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-21 23:53:39
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.247.59.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 84.247.59.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 21 19:53:32.726401 2024] [security2:error] [pid 7018:tid 7018] [client 84.247.59.120:49801] [client 84.247.59.120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/www.sql"] [unique_id "Zp2ffDYrFxjKvP-RNt4yvQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-19 09:35:35
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.247.59.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 84.247.59.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 19 05:35:31.003083 2024] [security2:error] [pid 21386:tid 21481] [client 84.247.59.120:30967] [client 84.247.59.120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||liquido.cocoonprojects.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "liquido.cocoonprojects.com"] [uri "/old/dump.sql"] [unique_id "ZpozY4Lh6S02aPUJT9hcFQAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
MAGIC
2024-07-05 13:00:57
(2 years ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π¦πΊ
MAGIC
2024-07-05 00:08:28
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π³π±
Linuxmalwarehuntingnl
2024-07-01 10:36:29
(2 years ago)
Unauthorized connection attempt
Brute-Force
Anonymous
2024-06-28 09:17:23
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
π«π·
jk jk
2024-06-19 18:25:10
(2 years ago)
GoPot Honeypot 1
Hacking
Web App Attack
π§πͺ
cmbplf
2024-06-19 14:36:07
(2 years ago)
1.000 requests to */xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2024-06-08 15:30:38
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.247.59.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 84.247.59.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 08 11:30:33.042946 2024] [security2:error] [pid 13486] [client 84.247.59.120:47151] [client 84.247.59.120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoinpornhub.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoinpornhub.com"] [uri "/wallet.dat"] [unique_id "ZmR5GTL1Dm2IFZ64US3IwAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-06-04 04:04:09
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
FireballDWF
2024-05-22 19:35:15
(2 years ago)
404 NOT FOUND
Web App Attack