๐ฑ๐ป
garmtech.com
2026-06-12 07:15:00
(1 week ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-14.104.245.240.236.web-spam ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 10-14.104.245.240.236.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 09:29:53
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 104.245.240.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 104.245.240.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 05:29:50.241227 2026] [security2:error] [pid 22994:tid 22994] [client 104.245.240.236:40383] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Briarwood II/Briarwood II/Stetson Coffee/originals/Thumbs.db"] [unique_id "ah_0DlLDBp1-JGNvkMLmmAAAAAQ"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Briarwood%20II/Briarwood%20II/Stetson%20Coffee/originals/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-05-29 05:51:43
(3 weeks ago)
Kingcopy(AI-IDS):IP is Probing for Multiple vulnerabilities WTF:Banned
Hacking
Bad Web Bot
๐ซ๐ฎ
JimArchon72
2026-05-27 14:10:01
(3 weeks ago)
2026/05/27 14:09:36 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-05-22 15:52:13
(4 weeks ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -39.214 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -39.214 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.1176.2
show less
Web App Attack
Bad Web Bot
Anonymous
2026-04-20 14:10:49
(2 months ago)
104.245.240.236 - - [20/Apr/2026:14:10:45 +0000] "GET /cgi-bin/printenv.pl HTTP/1.1" 302 733 "-" "Mo ...
show more
104.245.240.236 - - [20/Apr/2026:14:10:45 +0000] "GET /cgi-bin/printenv.pl HTTP/1.1" 302 733 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-19 05:15:08
(2 months ago)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-06 20:39:13
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 104.245.240.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 104.245.240.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 15:39:04.925417 2026] [security2:error] [pid 25062:tid 25062] [client 104.245.240.236:14331] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||zodiacwin.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "zodiacwin.com"] [uri "/"] [unique_id "aas7aLhkViRBVZefmIAQFgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-03-03 22:42:05
(3 months ago)
block ruleset 486D2EE5E731CC049D1E480D68D04DFFE28AADF1
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-19 03:56:04
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.245.240.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.245.240.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:55:53.325857 2026] [security2:error] [pid 11302:tid 11302] [client 104.245.240.236:9445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.csm-dtc.com"] [uri "/wp-config.php.orig"] [unique_id "aZaJycC4_2Kp2SiafQKkNwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-08 20:41:18
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.245.240.236 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 104.245.240.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 15:41:10.056290 2026] [security2:error] [pid 31340:tid 31340] [client 104.245.240.236:20159] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goalsnet.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goalsnet.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aYj05rkFLpFiLGfibXh1RQAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
OnTheEdge
2025-03-05 10:49:37
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-03-05 10:40:45
(1 year ago)
2 port probes: 2x tcp/9443
[srv133]
Port Scan
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-03-05 10:02:49
(1 year ago)
3 port probes: 2x tcp/8151, tcp/9443
[srv133]
Port Scan
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-03-05 09:46:49
(1 year ago)
3 port probes: 2x tcp/9443, tcp/8151
[srv133]
Port Scan