Anonymous
2026-10-07 00:46:29
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
j-tap
2026-10-07 00:10:27
(1 day ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 02:32:55
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 104.28.197.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.197.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 22:32:49.553178 2026] [security2:error] [pid 11735:tid 11735] [client 104.28.197.151:57082] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.iplayriichi.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.iplayriichi.com"] [uri "/"] [unique_id "asRd0StPdywwCcUnR76B2gAAAAg"], referer: https://generatebacklink.space/dir/manual-seo-backlinks-102515
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 08:58:20
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 104.28.197.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.197.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:58:13.555557 2026] [security2:error] [pid 13455:tid 13455] [client 104.28.197.151:12651] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||westonimports.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "westonimports.com"] [uri "/"] [unique_id "ar9yJbl58kYoGMnVoYZNVAAAAAw"], referer: https://whitehatbacklinks.online/dir/natural-seo-backlinks-231234
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 08:10:12
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 104.28.197.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.197.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 04:10:07.362050 2026] [security2:error] [pid 11981:tid 11981] [client 104.28.197.151:13984] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kinaffanchufoods.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kinaffanchufoods.com"] [uri "/"] [unique_id "arzD3w7CKjuNTvs3WXOTagAAAAg"], referer: https://backlinksubmissiontool.space/dir/organic-visibility-backlinks-113877
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 03:00:16
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐จ๐ฆ
Dunham Support
2026-09-30 02:57:46
(1 week ago)
(wordpress) Failed wordpress login from 104.28.197.151 (BD/Bangladesh/-)
Brute-Force
๐บ๐ธ
kosada.com
2026-09-29 17:26:17
(1 week ago)
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B0%5 ...
show more
Repeated requests classified as pathological web bot behavior, for example: /[redacted]?topics%5B0%5D=44&topics%5B1%5D=29&topics%5B2%5D=56&topics%5B3%5D=43 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36")
show less
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-26 13:03:51
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 104.28.197.151 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.28.197.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 09:03:46.402727 2026] [security2:error] [pid 1776:tid 1776] [client 104.28.197.151:48860] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||satanisdead.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "satanisdead.com"] [uri "/"] [unique_id "arfCsme3rvxtjFu6LfqQVAAAAAA"], referer: https://bestrankchecker.site/dir/premium-backlink-services-183014
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paprika
2026-09-16 06:59:46
(3 weeks ago)
Automated report #1: 1 attacks detected. Types: Brute-force (login).
Brute-Force
Email Spam
๐ซ๐ฎ
YF
2026-09-15 14:30:44
(3 weeks ago)
WordPress author enumeration
Web App Attack
๐ซ๐ท
businessbl
2026-09-13 11:56:28
(3 weeks ago)
Web request attack. Source IP is in our local ban list (cyberstit.com). Time:2026-09-13 11:56:28 UTC
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-09-08 02:18:03
(1 month ago)
block ruleset DA4A07AEE48B136A3922182BE8AA8BFBC1840803
Bad Web Bot
๐บ๐ธ
xmission.com
2026-09-06 16:02:57
(1 month ago)
104.28.197.151 - - [06/Sep/2026:10:02:56 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Mozilla/5.0 ...
show more
104.28.197.151 - - [06/Sep/2026:10:02:56 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 OPR/108.0.0.0"
...
show less
Web App Attack
๐บ๐ธ
cwytech
2026-09-03 23:16:32
(1 month ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack