๐ซ๐ท
ELYAZ
2026-07-25 01:26:43
(1 hour ago)
(y3) Failed access -byebye- from 137.175.83.225 (US/United States/edm05.51jyoo.com): (CF_ENABLE)
Hacking
๐บ๐ธ
nyt
2026-07-25 00:34:01
(2 hours ago)
404 flood (16/60s)
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 19:05:33
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฑ
CryptoYakari
2026-07-22 18:59:04
(2 days ago)
137.175.83.225 - - [22/Jul/2026:21:59:00 +0300] "GET /backup.zip HTTP/1.0" 404 3515 "https://www.dog ...
show more
137.175.83.225 - - [22/Jul/2026:21:59:00 +0300] "GET /backup.zip HTTP/1.0" 404 3515 "https://www.dogan.org/backup.zip" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
137.175.83.225 - - [22/Jul/2026:21:59:00 +0300] "GET /backup.rar HTTP/1.0" 404 8484 "https://www.dogan.org/backup.rar" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
137.175.83.225 - - [22/Jul/2026:21:59:00 +0300] "GET /backup.tar.gz HTTP/1.0" 404 3515 "https://www.dogan.org/backup.tar.gz" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
137.175.83.225 - - [22/Jul/2026:21:59:00 +0300] "HEAD /backup.tgz HTTP/1.0" 404 617 "https://www.dogan.org/backup.tgz" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
137.175.83.225 - - [22/Jul/2026:21:59:00 +0300] "HEAD /backup.sql HTTP/1.0" 404 617 "https://www.dogan.org/backup.sql" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
...
show less
Web Spam
Blog Spam
Web App Attack
Bad Web Bot
๐ณ๐ฑ
doarg
2026-07-22 18:56:05
(2 days ago)
[Wed Jul 22 20:56:00.562430 2026] [authz_core:error] [pid 243253] [client 137.175.83.225:64934] AH01 ...
show more
[Wed Jul 22 20:56:00.562430 2026] [authz_core:error] [pid 243253] [client 137.175.83.225:64934] AH01630: client denied by server configuration: /var/www/doarg.com/backup.sql, referer: https://www.doarg.com/backup.sql
[Wed Jul 22 20:56:01.579867 2026] [authz_core:error] [pid 243250] [client 137.175.83.225:65009] AH01630: client denied by server configuration: /var/www/doarg.com/db.sql, referer: https://www.doarg.com/db.sql
[Wed Jul 22 20:56:02.593784 2026] [authz_core:error] [pid 243288] [client 137.175.83.225:65080] AH01630: client denied by server configuration: /var/www/doarg.com/data.sql, referer: https://www.doarg.com/data.sql
[Wed Jul 22 20:56:03.609716 2026] [authz_core:error] [pid 243197] [client 137.175.83.225:65124] AH01630: client denied by server configuration: /var/www/doarg.com/web.sql, referer: https://www.doarg.com/web.sql
[Wed Jul 22 20:56:04.615652 2026] [authz_core:error] [pid 243244] [client 137.175.83.225:65175] AH01630: client denied by server configuration: /var/w
...
show less
Brute-Force
๐ซ๐ท
ELYAZ
2026-07-22 18:37:20
(2 days ago)
(y3) Failed access -byebye- from 137.175.83.225 (US/United States/edm05.51jyoo.com): (CF_ENABLE)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-22 18:06:22
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 137.175.83.225 (edm05.51jyoo.com): 1 in the las ...
show more
(mod_security) mod_security (id:210730) triggered by 137.175.83.225 (edm05.51jyoo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 14:06:16.615555 2026] [security2:error] [pid 1295233:tid 1295233] [client 137.175.83.225:61794] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||disio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disio.com"] [uri "/backup.sql"] [unique_id "amEGmKmrDLS7bqpffwmtKQAAAAE"], referer: https://disio.com/backup.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-07-21 11:42:47
(3 days ago)
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. U ...
show more
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. UA: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 10:55:46
(3 days ago)
[PathScanning] Path scanning/probing detected: Archive file probe (path: /backup.zip) | [DatabaseBac ...
show more
[PathScanning] Path scanning/probing detected: Archive file probe (path: /backup.zip) | [DatabaseBackupAccess] Database backup access attempt: Database archive file: .zip with backup (path: /backup.zip)
show less
Port Scan
Hacking
Web App Attack
Anonymous
2026-07-19 18:56:08
(5 days ago)
[PathScanning] Path scanning/probing detected: Archive file probe (path: /backup.zip) | [DatabaseBac ...
show more
[PathScanning] Path scanning/probing detected: Archive file probe (path: /backup.zip) | [DatabaseBackupAccess] Database backup access attempt: Database archive file: .zip with backup (path: /backup.zip)
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-19 18:30:02
(5 days ago)
ModSecurity rule 949110 triggered on cumberland. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
Anonymous
2026-07-18 19:06:05
(6 days ago)
Trying to access config files
Web App Attack
๐บ๐ธ
Lee Daniel
2026-07-18 18:41:14
(6 days ago)
137.175.83.225 - - [18/Jul/2026:14:41:13 -0400] "HEAD /backup.sql HTTP/1.1" 403 5440 "-" "Mozilla/5. ...
show more
137.175.83.225 - - [18/Jul/2026:14:41:13 -0400] "HEAD /backup.sql HTTP/1.1" 403 5440 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 17:10:59
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 137.175.83.225 (edm05.51jyoo.com): 1 in the las ...
show more
(mod_security) mod_security (id:210730) triggered by 137.175.83.225 (edm05.51jyoo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 13:10:54.863616 2026] [security2:error] [pid 31308:tid 31308] [client 137.175.83.225:57200] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.oualierealty.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.oualierealty.com"] [uri "/backup.sql"] [unique_id "alpiHmGKmbvsFi2JltzhLwAAAA0"], referer: http://www.cbskn.com/backup.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-16 00:38:30
(1 week ago)
Aggressive web search of vulnerable pages: /backup.zip /backup.rar /backup.tar.gz /backup.tgz /backu ...
show more
Aggressive web search of vulnerable pages: /backup.zip /backup.rar /backup.tar.gz /backup.tgz /backup.sql ...
show less
Web App Attack