|
π§π·
diego
|
|
Events: TCP SYN Discovery or Flooding, Seen 4 times in the last 10800 seconds
|
DDoS Attack
|
|
|
π©πͺ
hbrks
|
|
HEAD http://techtronicgambia.com/backups/dump.sql * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 23 14:14:00.521190 2024] [security2:error] [pid 15037] [client 94.46.167.6:61241] [client 94.46.167.6] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wethepeoplealliance.network|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wethepeoplealliance.network"] [uri "/restore/www.sql"] [unique_id "Zif6aABiP37LDFkJgWFHGAAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 18 15:56:05.593735 2024] [security2:error] [pid 13990] [client 94.46.167.6:44941] [client 94.46.167.6] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cryptoedge.net|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cryptoedge.net"] [uri "/backups/wallet.dat"] [unique_id "ZiF61VnmHcgP0OBOe_ThcgAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
hbrks
|
|
HEAD http://crm.marche-be.com/marche-be.com.tar.gz * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
π©πͺ
hbrks
|
|
HEAD http://crm.marche-be.com/back/public_html.zip * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
π©πͺ
hbrks
|
|
HEAD http://crm.marche-be.com/backups/config.json * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
π©πͺ
hbrks
|
|
HEAD http://marche-be.com/back/marche-be.com.rar * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 15 04:03:49.894237 2024] [security2:error] [pid 6652] [client 94.46.167.6:34563] [client 94.46.167.6] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||boat-accessories.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boat-accessories.net"] [uri "/restore/www.sql"] [unique_id "ZhzfZY9PpmFQijVuRByCUgAAACI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
hbrks
|
|
HEAD http://techtronicgambia.com/backups/dump.sql * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
π©πͺ
hbrks
|
|
HEAD http://techtronicgambia.com/restore/directory.rar * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
π©πͺ
hbrks
|
|
HEAD http://marche-be.com/back/backup.gz * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
π©πͺ
hbrks
|
|
HEAD http://crm.marche-be.com/bak/public_html.zip * statusCode: 503 *
|
Web Spam
Hacking
Bad Web Bot
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 04 22:07:26.244175 2024] [security2:error] [pid 23403] [client 94.46.167.6:33745] [client 94.46.167.6] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ccbank.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ccbank.net"] [uri "/back/dump.sql"] [unique_id "Zg9c3o_U8eGoqofMx0DQaAAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 94.46.167.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 03 01:46:43.293707 2024] [security2:error] [pid 11293] [client 94.46.167.6:55537] [client 94.46.167.6] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bayareamustangs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bayareamustangs.com"] [uri "/restore/dump.sql"] [unique_id "ZgztQwBV3axaQlMU77GsygAAAAw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|