๐ฉ๐ช
LRob
2026-09-20 18:35:03
(11 hours ago)
L7 DDoS: hammering a site's endpoints (login page, AJAX, dynamic pages) with automated requests far ...
show more
L7 DDoS: hammering a site's endpoints (login page, AJAX, dynamic pages) with automated requests far beyond any human use | path: /calendrier-2/action~agenda/cat_ids~311/tag_ids~483,454,635,323/request_format~json/ | 2026-09-20 18:35 UTC
show less
DDoS Attack
Web App Attack
Anonymous
2026-09-19 09:30:07
(1 day ago)
Blocked by ModSec and CSF
Port Scan
๐ฉ๐ช
LRob
2026-09-16 16:04:00
(4 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-16 16:04 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-12 05:34:50
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 120.53.246.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 120.53.246.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:34:44.327334 2026] [security2:error] [pid 795:tid 795] [client 120.53.246.23:53294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.frightlibrary.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.frightlibrary.org"] [uri "/citizen/ontarioplace.com"] [unique_id "aqTkdPtH_hIVFLN-tyW6swAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 01:24:25
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 120.53.246.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 120.53.246.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:24:21.727112 2026] [security2:error] [pid 16597:tid 16597] [client 120.53.246.23:42992] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ozkanturker.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ozkanturker.com"] [uri "/makaleler/tezgah/_vti_cnf/Thumbs.db"] [unique_id "apodxdQTi8nvzLZd9e9-2wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-08-29 10:42:56
(3 weeks ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐ฉ๐ช
Inamin
2026-08-26 00:48:38
(3 weeks ago)
120.53.246.23 - - [26/Aug/2026:08:48:31 +0800] "GET /index.php?title=%E3%83%9F%E3%82%A2%E3%83%BB%E3% ...
show more
120.53.246.23 - - [26/Aug/2026:08:48:31 +0800] "GET /index.php?title=%E3%83%9F%E3%82%A2%E3%83%BB%E3%83%86%E3%82%A4%E3%83%A9%E3%83%BC/%E8%AA%9E%E9%9F%B3%E8%A1%A8&action=history&offset=20210925092401%7C12222 HTTP/2.0" 200 52388 "https://as.llsif.moe/index.php?title=%E3%83%9F%E3%82%A2%E3%83%BB%E3%83%86%E3%82%A4%E3%83%A9%E3%83%BC%2F%E8%AA%9E%E9%9F%B3%E8%A1%A8&action=history&offset=20210925092401%7C12222" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
120.53.246.23 - - [26/Aug/2026:08:48:35 +0800] "GET /index.php?title=%E3%83%9F%E3%82%A2%E3%83%BB%E3%83%86%E3%82%A4%E3%83%A9%E3%83%BC%2F%E8%AA%9E%E9%9F%B3%E8%A1%A8&action=history&offset=848459487 HTTP/2.0" 200 52313 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Bad Web Bot
Web App Attack
๐ป๐ณ
trung.fun
2026-08-22 08:08:13
(4 weeks ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-09 18:16:17
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 120.53.246.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 120.53.246.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 14:16:10.609558 2026] [security2:error] [pid 2818546:tid 2818546] [client 120.53.246.23:52854] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoutinsignia.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoutinsignia.com"] [uri "/WS_FTP.LOG"] [unique_id "anjD6sPiXAC-QJ4aVO4_OwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-09 11:26:27
(1 month ago)
๐ Probes for tons of inexistent files and/or PHP scripts
Hacking
Web App Attack
Anonymous
2026-08-08 08:00:11
(1 month ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack