๐ช๐ธ
10dencehispahard SL
2024-03-24 16:01:34
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-03-20 19:49:49
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 20 15:49:44.592588 2024] [security2:error] [pid 9278] [client 84.32.71.73:59693] [client 84.32.71.73] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nationalenq.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nationalenq.com"] [uri "/backups/www.sql"] [unique_id "Zfs92GTV6hjwL9acTFlTnwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-13 20:44:39
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 13 16:44:32.236833 2024] [security2:error] [pid 12865:tid 47691614705408] [client 84.32.71.73:58737] [client 84.32.71.73] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||liquido.cocoonprojects.com|F|2"] [data ".info.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "liquido.cocoonprojects.com"] [uri "/bak/liquidorganization.info.sql"] [unique_id "ZfIQMNF-zzGaqJMKHbf4YQAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2024-02-17 22:14:24
(2 years ago)
HEAD http://marche-be.com/restore/backup.rar
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-02-17 11:34:56
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 17 06:34:49.032232 2024] [security2:error] [pid 14049] [client 84.32.71.73:24087] [client 84.32.71.73] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/backup/backup.sql"] [unique_id "ZdCZ2X8JxRMzFZV4CXHRbgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2024-02-12 09:06:18
(2 years ago)
HEAD http://ncs.guru/restore/config.json
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-02-08 23:38:59
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 08 18:38:50.962674 2024] [security2:error] [pid 25291] [client 84.32.71.73:64061] [client 84.32.71.73] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bitcoinbtcshop.com"] [uri "/backups/.env"] [unique_id "ZcVmCo1K97xgCmu_5K4ufQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2024-02-08 23:37:59
(2 years ago)
HEAD http://epay.world/restore/public_html.gz
statusCode: 503
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-02-01 12:04:18
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 84.32.71.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 01 07:04:11.080148 2024] [security2:error] [pid 27316] [client 84.32.71.73:52119] [client 84.32.71.73] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bayareamustangs.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bayareamustangs.com"] [uri "/restore/bayareamustangs.com.sql"] [unique_id "ZbuIu0qk3THOtubqtOEbEgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฑ
FAZ_Noc
2023-12-19 07:09:50
(2 years ago)
SQL injection - Unauthorized connection attempt detected from IP address
SQL Injection
Anonymous
2023-09-22 04:28:05
(3 years ago)
This IP was involved in an authentication attack on 2023-09-22T04:22:17.640407+00:00
Brute-Force
Exploited Host
๐บ๐ธ
sumnone
2023-07-21 04:28:35
(3 years ago)
Vulnerability probing: Error 404. The requested page (/old/backup.sql) was not found
Bad Web Bot
Exploited Host
Web App Attack