๐ธ๐ฌ
securejdprop
2026-07-24 13:53:42
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ETN AGGRESSIVE IPs ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ETN AGGRESSIVE IPs Group 18).
show less
Hacking
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-24 11:33:01
(3 hours ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
US/United States/-
Web App Attack
๐ฎ๐ฉ
bps-statistics
2026-07-24 11:01:24
(4 hours ago)
Malicious Access
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-19 01:07:06
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 21:06:58.671800 2026] [security2:error] [pid 10378:tid 10378] [client 104.28.159.128:14805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jwphotodesign.jonathanwilson.me"] [uri "/sftp-config.json"] [unique_id "alwjMnrEWzxQclmVurG_lAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 12:41:48
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 08:41:43.822504 2026] [security2:error] [pid 17955:tid 17955] [client 104.28.159.128:15395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ds12bonn.de"] [uri "/sftp-config.json"] [unique_id "alt0h-IzqKlOOKV2G8zxQgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
Prcek
2026-07-17 20:50:31
(6 days ago)
PortScan:HOST=104.28.159.128,DPORTS=80,443
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-17 08:49:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:49:50.132022 2026] [security2:error] [pid 12710:tid 12725] [client 104.28.159.128:16270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gemini.pe"] [uri "/sftp-config.json"] [unique_id "alnsrrlAreBh9fiWtFGjrQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-17 01:18:45
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-16 20:51:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 16:50:56.907754 2026] [security2:error] [pid 5210:tid 5210] [client 104.28.159.128:15784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cbrarauco.cl"] [uri "/sftp-config.json"] [unique_id "allEMLLcbEt6YW1zZrkVjgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-16 05:34:23
(1 week ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
SSH
Web App Attack
Anonymous
2026-07-15 16:31:25
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
๐ง๐ช
cmbplf
2026-07-15 08:01:09
(1 week ago)
1.001 requests to many distinct domains in 1 hour (4w5h59s)
Brute-Force
Bad Web Bot
๐บ๐ธ
IndigoRidge
2026-07-14 02:46:47
(1 week ago)
104.28.159.128 - - [13/Jul/2026:22:46:46 -0400] "GET /wp-login.php HTTP/1.1" 301 162 "-" "Mozilla/5. ...
show more
104.28.159.128 - - [13/Jul/2026:22:46:46 -0400] "GET /wp-login.php HTTP/1.1" 301 162 "-" "Mozilla/5.0"
104.28.159.128 - - [13/Jul/2026:22:46:46 -0400] "GET /wp-login.php HTTP/1.1" 301 162 "-" "Mozilla/5.0"
104.28.159.128 - - [13/Jul/2026:22:46:46 -0400] "GET /wp-login.php HTTP/1.1" 301 162 "-" "Mozilla/5.0"
104.28.159.128 - - [13/Jul/2026:22:46:46 -0400] "GET /wp-login.php HTTP/1.1" 301 162 "-" "Mozilla/5.0"
104.28.159.128 - - [13/Jul/2026:22:46:46 -0400] "GET /wp-login.php HTTP/1.1" 301 162 "-" "Mozilla/5.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 21:35:30
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 104.28.159.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 17:35:26.990178 2026] [security2:error] [pid 5917:tid 5917] [client 104.28.159.128:56178] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 104.28.159.128 (+1 hits since last alert)|eefinchco.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eefinchco.com"] [uri "/xmlrpc.php"] [unique_id "alQIns21Pk5gDr-UTYoqZAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-07-08 23:13:59
(2 weeks ago)
IP reached maximum auth failures for a one day block
Brute-Force