|
๐ฉ๐ช
hbrks
|
|
HEAD http://techtronicgambia.com/restore/techtronicgambia.com.tar.gz * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
๐ฉ๐ช
hbrks
|
|
HEAD http://techtronicgambia.com/bak/techtronicgambia.com.rar * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
๐ง๐ท
diego
|
|
Events: TCP SYN Discovery or Flooding, Seen 3 times in the last 10800 seconds
|
DDoS Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 13:50:30.653839 2024] [security2:error] [pid 4689] [client 94.46.13.80:31561] [client 94.46.13.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chewlas.brandpumice.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chewlas.brandpumice.com"] [uri "/www.sql"] [unique_id "Zh1o5pWy5JoKq0BVvGOHvQAAABU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 13 21:21:57.585288 2024] [security2:error] [pid 10280] [client 94.46.13.80:53655] [client 94.46.13.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jfexpressfr8.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jfexpressfr8.com"] [uri "/backups/hotshotfr8.com.sql"] [unique_id "ZhsvtdzD0YDL89KyVkZeOQAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
hbrks
|
|
HEAD http://ncs.guru/public_html.tar * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
๐ฉ๐ช
hbrks
|
|
HEAD http://techtronicgambia.com/backup/.well-known.zip * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 13 00:25:50.809226 2024] [security2:error] [pid 31739] [client 94.46.13.80:29903] [client 94.46.13.80] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gcigmbh.com"] [uri "/sftp-config.json"] [unique_id "ZhoJTv2hmZKjzm5xmbtFVwAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 08 17:51:41.222757 2024] [security2:error] [pid 19283] [client 94.46.13.80:22885] [client 94.46.13.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lusocleaningservice.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lusocleaningservice.com"] [uri "/bak/backup.sql"] [unique_id "ZhRm7UiD9U5zR1JLCWtCSAAAACA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 08 17:02:44.407008 2024] [security2:error] [pid 11219] [client 94.46.13.80:37387] [client 94.46.13.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/bak/dump.sql"] [unique_id "ZhRbdA0eFTRHVTcH2lk6vgAAAAQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
hbrks
|
|
HEAD http://crm.marche-be.com/bak/sql.sql * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
๐ฉ๐ช
hbrks
|
|
HEAD http://crm.marche-be.com/back/config.json * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
๐ฉ๐ช
hbrks
|
|
HEAD http://crm.marche-be.com/backups/backup.zip * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 01 05:48:12.409403 2024] [security2:error] [pid 2123507] [client 94.46.13.80:13201] [client 94.46.13.80] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||firejasstrio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "firejasstrio.com"] [uri "/bak/dump.sql"] [unique_id "ZgqC3EGuv5LCKwVSbFtZtwAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 94.46.13.80 (ffletter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 31 12:38:20.363684 2024] [security2:error] [pid 23804] [client 94.46.13.80:11991] [client 94.46.13.80] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrepoch.art"] [uri "/restore/.env"] [unique_id "ZgmRfANXDSKOEHtQCKlqRgAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|