๐ณ๐ฑ
exxos
2025-09-29 19:05:32
(10 months ago)
Attacks with Bad user agents
Hacking
๐บ๐ธ
TPI-Abuse
2025-08-01 13:20:24
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 103.28.253.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 103.28.253.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 09:20:20.635236 2025] [security2:error] [pid 31515:tid 31515] [client 103.28.253.9:4527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/app/etc/local.xml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "endemic.com"] [uri "/store/app/etc/local.xml"] [unique_id "aIy_FF97fxG9og3LSH6vTwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Arnold Maarten
2025-07-30 13:37:58
(1 year ago)
103.28.253.9 (IN/India/-), more than 20 Apache 403 hits
Hacking
Anonymous
2025-07-27 16:32:10
(1 year ago)
Agressive scraper not respecting robots.txt or not identifying itself properly
...
Bad Web Bot
๐ฆ๐บ
2000cn.com.au
2025-07-27 13:15:34
(1 year ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Hacking
Web App Attack
๐ซ๐ท
dynamix
2025-07-26 23:39:39
(1 year ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-23 01:29:03
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 103.28.253.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 103.28.253.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 22 21:28:47.500052 2025] [security2:error] [pid 30915:tid 30915] [client 103.28.253.9:12269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heinsohn.com"] [uri "/sftp-config.json"] [unique_id "aIA6zwQRr1rDG7Z87bxiWwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-22 13:32:18
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 103.28.253.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 103.28.253.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 22 09:32:02.586015 2025] [security2:error] [pid 6036:tid 6036] [client 103.28.253.9:5463] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cypro.com"] [uri "/wp-config.php-backup"] [unique_id "aH-S0vELOOslKcLI_sOEBAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-22 09:38:55
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 103.28.253.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 103.28.253.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 22 05:38:41.841964 2025] [security2:error] [pid 24285:tid 24285] [client 103.28.253.9:1695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summithost.com"] [uri "/wp-config.php.bk"] [unique_id "aH9cIfUU4IzI4KgkmpWmvAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2025-07-19 23:11:08
(1 year ago)
Web vulnerability probing
Web App Attack
๐ซ๐ท
dynamix
2025-07-18 13:55:03
(1 year ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
VHosting
2025-07-16 23:10:55
(1 year ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2025-07-16 22:45:53
(1 year ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2025-07-16 12:24:47
(1 year ago)
181 requests with url.path *.sql.rar
180 requests with url.path *.sql.gz
180 requests with url.pa ...
show more
181 requests with url.path *.sql.rar
180 requests with url.path *.sql.gz
180 requests with url.path *.sql.xz
180 requests with url.path *.sql.lz
180 requests with url.path *.sql.z
179 requests with url.path *.sql.7z
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2025-07-16 10:14:33
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack