๐ช๐ธ
10dencehispahard SL
2024-03-24 00:06:51
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐ฉ๐ช
hbrks
2024-03-08 23:07:48
(2 years ago)
HEAD http://leralmedia.com/backups/config.json
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐ฉ๐ช
hbrks
2024-03-05 10:34:13
(2 years ago)
HEAD http://epay.world/old/public_html.gz
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-03-05 03:35:59
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 04 22:35:53.097956 2024] [security2:error] [pid 6402] [client 84.32.71.60:25241] [client 84.32.71.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powderriverinc.com"] [uri "/backups/.env"] [unique_id "ZeaTGQXtmEHmUfrWEZt06QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-02 05:23:35
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 02 00:23:29.079747 2024] [security2:error] [pid 29447] [client 84.32.71.60:2207] [client 84.32.71.60] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barnesandbrower.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barnesandbrower.com"] [uri "/restore/barnesandbrower.com.sql"] [unique_id "ZeK30eUwwscnjnwO88kRhAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-17 10:52:16
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 17 05:52:08.690397 2024] [security2:error] [pid 18789:tid 47609309669120] [client 84.32.71.60:49853] [client 84.32.71.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liquido.cocoonprojects.com"] [uri "/backup/sftp-config.json"] [unique_id "ZdCP2NQxnU9xuybwQ3bfOgAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-09 00:09:43
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 08 19:09:35.787214 2024] [security2:error] [pid 27760] [client 84.32.71.60:51991] [client 84.32.71.60] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bitcoinbtcshop.com"] [uri "/restore/sftp-config.json"] [unique_id "ZcVtPye2KwHWsEQEKbmm8QAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-16 00:13:03
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 15 19:12:55.960196 2024] [security2:error] [pid 659] [client 84.32.71.60:53733] [client 84.32.71.60] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.robcohn.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.robcohn.com"] [uri "/backup.sql"] [unique_id "ZaXKB1gXgcYs9w6g5pkYuAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฑ
FAZ_Noc
2023-12-19 07:09:50
(2 years ago)
SQL injection - Unauthorized connection attempt detected from IP address
SQL Injection
๐จ๐ญ
blinx
2023-10-03 17:33:30
(3 years ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
sumnone
2023-07-20 05:08:32
(3 years ago)
Vulnerability probing: Error 404. The requested page (/backups/www.sql) was not found
Bad Web Bot
Exploited Host
Web App Attack