πΏπ¦
conure.sh
2026-09-19 12:06:13
(3 days ago)
csagent: score 20.1: wp-config backup grab x2, 404 noise floor x1; 2 domain(s) in 2s
Web App Attack
πΏπ¦
conure.sh
2026-09-18 21:19:45
(4 days ago)
csagent: score 20.1: wp-config backup grab x2, 404 noise floor x1; 1 domain(s) in 2s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 11:29:15
(5 days ago)
(mod_security) mod_security (id:210350) triggered by 109.236.42.191 (dynamic.pool-109-236-42-191.abi ...
show more
(mod_security) mod_security (id:210350) triggered by 109.236.42.191 (dynamic.pool-109-236-42-191.abissnet.al): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:29:10.498489 2026] [security2:error] [pid 289729:tid 289729] [client 109.236.42.191:50394] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gc-africa.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gc-africa.com"] [uri "/"] [unique_id "aqvPBvs9pWycHQ-hHIl9JQAAABM"], referer: https://bulkdacheckeronline.online/dir/seo-outreach-backlinks-79658
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
gui-ying233
2026-08-31 05:06:16
(3 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Bad Web Bot
πΊπΈ
gui-ying233
2026-08-27 09:04:43
(3 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Bad Web Bot
πͺπΈ
el-brujo
2026-08-26 13:01:11
(3 weeks ago)
HTTP DDoS Attack Layer 7
DDoS Attack
πΊπΈ
kosada.com
2026-08-25 14:39:06
(4 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-08-24 00:30:27
(4 weeks ago)
| [Dangerous/Albania] Aggressive IP 109.236.42.191 (~30 hits). Type: DoS Defender- Web server 400 er ...
show more
| [Dangerous/Albania] Aggressive IP 109.236.42.191 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
πΊπΈ
kosada.com
2026-07-28 20:45:28
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-03-09 16:36:46
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 109.236.42.191 (dynamic.pool-109-236-42-191.abi ...
show more
(mod_security) mod_security (id:210730) triggered by 109.236.42.191 (dynamic.pool-109-236-42-191.abissnet.al): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 12:36:42.216916 2026] [security2:error] [pid 30404:tid 30404] [client 109.236.42.191:50632] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Golden-Technologies/pics/Golden Technologies 2009 Marketing CD/Lift Chairs/Maxicomfort Series/Thumbs.db"] [unique_id "aa73GnqgCcucq1Xlm6Z-VQAAAAM"], referer: https://vitalitywebb.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π·
SOC Blue Team
2025-12-27 18:10:09
(8 months ago)
Tatic: TA0006 | Technique: T1110 | Source: TAP | Country Destination: BR
Brute-Force
Anonymous
2025-11-18 15:57:23
(10 months ago)
scanning http requests from known botnet
Web App Attack
πΈπ¬
mypatricks
2025-08-22 11:11:44
(1 year ago)
109.236.42.191 | Port: 33718 | DNS: dynamic.pool-109-236-42-191.abissnet.al 2025-08-22T19:11:43+08:0 ...
show more
109.236.42.191 | Port: 33718 | DNS: dynamic.pool-109-236-42-191.abissnet.al 2025-08-22T19:11:43+08:00 Europe/Tirane | Bad Behavior Activity | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Edg/121.0.0.0 HTTP/1.1 443 GET | URL: /shop/compare/?1748035995= | Ref: - | Country: AL/Albania/+01:00 IP City: Tirana 9731ee5222b820e6-SOF/Sofia, Bulgaria 1 hits/0 secs Robots 2
show less
Web Spam
Blog Spam
Brute-Force
Exploited Host
Web App Attack
π΅π±
ChillScanner
2021-05-02 11:39:09
(5 years ago)
1 probe(s) @ TCP(432)
Port Scan