๐ฌ๐ง
openstrike.co.uk
2025-09-03 05:13:42
(11 months ago)
3 attacks on Alfa URLs, PHP URLs:
POST /alfacgiapi/perl.alfa HTTP/1.1
POST /wp-plain.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
cheatmaster.store
2025-09-02 22:43:52
(11 months ago)
Automated abuse report from VPS monitoring
Brute-Force
SSH
๐ฉ๐ช
Vegascosmetics
2025-09-02 21:50:41
(11 months ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
๐ซ๐ท
Quarks Solutions
2025-09-02 17:53:04
(11 months ago)
crowdsecurity/http-bad-user-agent
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-02 17:38:02
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 13:37:57.541733 2025] [security2:error] [pid 19373:tid 19373] [client 13.76.137.177:2002] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gabbyspetnanny.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gabbyspetnanny.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "aLcrdZukYNy9TcurnOtRFQAAAAY"], referer: www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-02 17:05:56
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 13:05:48.937221 2025] [security2:error] [pid 21843:tid 21843] [client 13.76.137.177:5226] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lukeschicago.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lukeschicago.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "aLcj7GMxzgrlp1myqrUncwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-09-02 16:55:52
(11 months ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐ฆ๐บ
clapper
2025-09-02 16:43:14
(11 months ago)
(mod_security) mod_security (id:980001) triggered by 13.76.137.177 (SG/Singapore/-): 5 in the last 3 ...
show more
(mod_security) mod_security (id:980001) triggered by 13.76.137.177 (SG/Singapore/-): 5 in the last 3600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
SCHAPPY
2025-09-02 16:40:06
(11 months ago)
Malicious activity from IP detected: crowdsecurity/http-bad-user-agent.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-02 16:30:38
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 12:30:31.529452 2025] [security2:error] [pid 8195:tid 8195] [client 13.76.137.177:2015] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.fredlandia.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.fredlandia.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "aLcbp7yyoWOGFmZBdgswywAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
Tokolosh Hunters
2025-09-02 16:24:56
(11 months ago)
AutoBlockWindow-Known bad useragent query-2025-09-02 16:24:55
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-02 16:15:28
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 12:15:25.300827 2025] [security2:error] [pid 7569:tid 7569] [client 13.76.137.177:1601] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.fractalsky.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.fractalsky.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "aLcYHSgv4StnYNIAL-CutQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2025-09-02 15:50:00
(11 months ago)
BadBot
13.76.137.177 - - [02/Sep/2025:17:49:58 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP ...
show more
BadBot
13.76.137.177 - - [02/Sep/2025:17:49:58 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 548 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-09-02 15:47:03
(11 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-02 15:43:01
(11 months ago)
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 13.76.137.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 11:42:54.595907 2025] [security2:error] [pid 1326:tid 1326] [client 13.76.137.177:1106] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.forerunnersjazz.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.forerunnersjazz.org"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "aLcQfjZ5tOlm5dTKhGNqzgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack