๐ต๐ฑ
Marek Krolikowski
2024-04-08 06:24:48
(2 years ago)
GET /wp-admin/admin-ajax.php?action=duplicator_download&file=../wp-config.php HTTP/1.0
Web App Attack
๐ง๐ช
Ivo Vynckier
2024-04-07 09:06:00
(2 years ago)
89.200.203.20 - - [07/Apr/2024:02:54:59 +0200] "GET /wp-admin/admin-ajax.php?action=duplicator_downl ...
show more
89.200.203.20 - - [07/Apr/2024:02:54:59 +0200] "GET /wp-admin/admin-ajax.php?action=duplicator_download&file=../wp-config.php HTTP/1.1" 301 326 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0"
89.200.203.20 - - [07/Apr/2024:02:54:59 +0200] "GET /wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php HTTP/1.1" 301 326 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 06:58:29
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 02:58:26.222230 2024] [security2:error] [pid 28585] [client 89.200.203.20:53478] [client 89.200.203.20] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anegadabeachclub.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZhJEEnO0ZgN45tnUgerkrgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 06:25:31
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 02:25:25.231735 2024] [security2:error] [pid 2248] [client 89.200.203.20:46266] [client 89.200.203.20] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sumilondon.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZhI8VYQTRjub0d5lrt_yqAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2024-04-07 06:06:34
(2 years ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 89.200.203.20 (NL/The Ne ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 89.200.203.20 (NL/The Netherlands/plesk5.duocast.net)
show less
Port Scan
๐ฉ๐ช
SCHAPPY
2024-04-07 05:25:26
(2 years ago)
Critical web app attack detected. Path Traversal Attack (/../)
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-04-07 05:22:55
(2 years ago)
89.200.203.20 - - [07/Apr/2024:08:22:54 +0300] "GET /wp-admin/admin-ajax.php?action=duplicator_downl ...
show more
89.200.203.20 - - [07/Apr/2024:08:22:54 +0300] "GET /wp-admin/admin-ajax.php?action=duplicator_download&file=../wp-config.php HTTP/1.1" 404 276 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/72.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 04:50:35
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 00:50:30.363813 2024] [security2:error] [pid 20129] [client 89.200.203.20:44682] [client 89.200.203.20] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dianogah.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZhImFgu0Bcus23KTjOdGTAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 04:16:37
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 07 00:16:31.657495 2024] [security2:error] [pid 19213] [client 89.200.203.20:58012] [client 89.200.203.20] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.34thprs.org"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZhIeH5VREAtg42QAYOtSdAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-04-07 03:53:38
(2 years ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 03:47:04
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 06 23:46:59.971179 2024] [security2:error] [pid 1892673] [client 89.200.203.20:52150] [client 89.200.203.20] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.quakeprediction.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZhIXM_RKes_WrfO2EjuxZgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 03:07:52
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 06 23:07:43.926161 2024] [security2:error] [pid 5561] [client 89.200.203.20:42206] [client 89.200.203.20] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.petercoadandthecoadsisters.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZhIN_81psXRFPGA-bjixdwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 02:25:08
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 06 22:25:01.065721 2024] [security2:error] [pid 19743] [client 89.200.203.20:52138] [client 89.200.203.20] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frankweyer.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZhID_SUoc_G_PSAVfbggrAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
IRT@Unisi
2024-04-07 02:24:36
(2 years ago)
web_app3:WordPress.HTTP.Path.Traversal
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-07 01:55:01
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 89.200.203.20 (plesk5.duocast.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 06 21:54:56.422937 2024] [security2:error] [pid 11575] [client 89.200.203.20:51556] [client 89.200.203.20] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blaslandsporthorses.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZhH88GTPx8C6yhzuMEF-jAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack