๐ฒ๐พ
Rizzy
2026-08-01 19:06:54
(22 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-01 19:04:47
(24 minutes ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
yvoictra
2026-08-01 16:05:25
(3 hours ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-bad-user-agent
Web App Attack
Anonymous
2026-08-01 14:04:42
(5 hours ago)
147.90.209.100 - - [01/Aug/2026:22:04:41 +0800] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 404 ...
show more
147.90.209.100 - - [01/Aug/2026:22:04:41 +0800] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 404 13851 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
147.90.209.100 - - [01/Aug/2026:22:04:41 +0800] "POST /wp-plain.php HTTP/1.1" 404 13851 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
147.90.209.100 - - [01/Aug/2026:22:04:41 +0800] "POST /wp-plain.php HTTP/1.1" 404 13851 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
147.90.209.100 - - [01/Aug/2026:22:04:41 +0800] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 13850 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/53
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 11:40:56
(7 hours ago)
Automatically blocked after 11 security events. Observed web-shell or malicious-file probes. Source: ...
show more
Automatically blocked after 11 security events. Observed web-shell or malicious-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-08-01 10:07:17
(9 hours ago)
147.90.209.100 - - [01/Aug/2026:10:07:16 +0000] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 ...
show more
147.90.209.100 - - [01/Aug/2026:10:07:16 +0000] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 413 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
147.90.209.100 - - [01/Aug/2026:10:07:16 +0000] "POST /wp-plain.php HTTP/1.1" 403 413 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
147.90.209.100 - - [01/Aug/2026:10:07:16 +0000] "POST /alfacgiapi/perl.alfa HTTP/1.1" 403 413 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
147.90.209.100 - - [01/Aug/2026:10:07:16 +0000] "GET /jylgtgfy.php?Fox=d3wL7 HTTP/1.1" 404 31577 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML
...
show less
Web App Attack
Exploited Host
๐ช๐ธ
masterguru
2026-08-01 08:17:52
(11 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "mozlila" at REQUEST_HEADERS:User-Agent. (1100000-12 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "mozlila" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐ฌ๐ท
setupgr
2026-08-01 07:39:01
(11 hours ago)
(mod_security) mod_security (id:1000001) triggered by 147.90.209.100 (DE/Germany/Hesse/Frankfurt am ...
show more
(mod_security) mod_security (id:1000001) triggered by 147.90.209.100 (DE/Germany/Hesse/Frankfurt am Main/-/[AS212238 CDNEXT]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:39:00.362522 2026] [security2:error] [pid 979034:tid 979164] [client 147.90.209.100:63455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/db.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /wp-content/themes/seotheme/db.php"] [severity "CRITICAL"] [tag "security"] [hostname "babis.photo"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "am2ilFu4KziqrlooK9ZVtgAAAcc"], referer: www.google.com
show less
Port Scan
๐จ๐ฆ
polycoda
2026-08-01 06:53:24
(12 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-08-01 04:34:26
(14 hours ago)
147.90.209.100 - - [01/Aug/2026:05:34:29 +0100] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 63 ...
show more
147.90.209.100 - - [01/Aug/2026:05:34:29 +0100] "GET /wp-content/plugins/fix/up.php HTTP/1.1" 404 6355 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36"
147.90.209.100 - - [01/Aug/2026:05:34:29 +0100] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 404 6355 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
147.90.209.100 - - [01/Aug/2026:05:34:29 +0100] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 6355 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-01 04:19:56
(15 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฉ๐ช
LRob
2026-08-01 02:38:08
(16 hours ago)
CrowdSec: crowdsecurity/http-bad-user-agent | req: /ALFA_DATA/alfacgiapi/perl.alfa | 2 distinct path ...
show more
CrowdSec: crowdsecurity/http-bad-user-agent | req: /ALFA_DATA/alfacgiapi/perl.alfa | 2 distinct paths | UA: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.
show less
Bad Web Bot
๐บ๐ธ
Mundo Bueno
2026-08-01 00:01:58
(19 hours ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /alfa_data/alfacgiapi/perl.alfa | Pays: DE | UA: Mozlila ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /alfa_data/alfacgiapi/perl.alfa | Pays: DE | UA: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) V
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 21:54:03
(21 hours ago)
(mod_security) mod_security (id:210350) triggered by 147.90.209.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 147.90.209.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:53:56.560758 2026] [security2:error] [pid 3633484:tid 3633484] [client 147.90.209.100:55721] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.prayers4america.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.prayers4america.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "am0ZdAwW4-18SxnegqfdCAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-07-31 21:39:43
(21 hours ago)
(mod_security) mod_security (id:980001) triggered by 147.90.209.100 (DE/Germany/-): 3 in the last 36 ...
show more
(mod_security) mod_security (id:980001) triggered by 147.90.209.100 (DE/Germany/-): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot