๐ฉ๐ช
ghostwarriors
2026-06-17 03:20:35
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 21:28:33
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 148.113.128.238 (proxy-ca014-san238.ahrefs.net) ...
show more
(mod_security) mod_security (id:210730) triggered by 148.113.128.238 (proxy-ca014-san238.ahrefs.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 17:28:28.435704 2026] [security2:error] [pid 29141:tid 29141] [client 148.113.128.238:51424] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.coolwebsites.org|F|2"] [data ".livingston.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.coolwebsites.org"] [uri "/www.livingston.com"] [unique_id "ajBufPcj5vT3d8Lq656iFAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-06-12 14:50:13
(6 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
dineshskt4all
2026-06-10 02:09:30
(1 week ago)
148.113.128.238 - - [10/Jun/2026:02:09:28 +0000] "GET /wp-content/uploads/2021/10/casino-online/best ...
show more
148.113.128.238 - - [10/Jun/2026:02:09:28 +0000] "GET /wp-content/uploads/2021/10/casino-online/best-real-money-pokies-app-australia.html HTTP/2.0" 304 0 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
...
show less
IoT Targeted
Anonymous
2026-06-08 15:18:57
(1 week ago)
[server.tmg.gr] httpd-noisy-crawler-swarm: sites=eumedline.eu; logs=/var/log/httpd/domains/eumedline ...
show more
[server.tmg.gr] httpd-noisy-crawler-swarm: sites=eumedline.eu; logs=/var/log/httpd/domains/eumedline.eu.log; samples=crawler=ahrefsbot | window=5m | distinct_ips=119
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-05-25 05:20:28
(3 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-05-23 17:54:02
(3 weeks ago)
HTTP attack observed: GET /robots.txt HTTP/2.0 | status=200 | response_size=134
Port Scan
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-05-23 17:54:02
(3 weeks ago)
HTTP attacks observed: GET /robots.txt HTTP/2.0 | status=200
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-14 11:17:07
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 148.113.128.238 (proxy-ca014-san238.ahrefs.net) ...
show more
(mod_security) mod_security (id:210730) triggered by 148.113.128.238 (proxy-ca014-san238.ahrefs.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 07:17:00.691721 2026] [security2:error] [pid 13239:tid 13239] [client 148.113.128.238:28970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mrccertification.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mrccertification.com"] [uri "/hello-world/crazytimeit.com"] [unique_id "agWvLJjvBi33R4DwOs43oAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-05-06 12:55:09
(1 month ago)
148.113.128.238 - - [06/May/2026:12:54:35 +0000] "GET /patient-resources/surgical-instructions HTTP/ ...
show more
148.113.128.238 - - [06/May/2026:12:54:35 +0000] "GET /patient-resources/surgical-instructions HTTP/2.0" 502 150 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2026-05-01 18:50:51
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-04-28 06:18:46
(1 month ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 148.113.128.238 (CA/ ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 148.113.128.238 (CA/Canada/proxy-ca014-san238.ahrefs.net)
show less
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2026-04-27 12:50:30
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-04-12 05:19:07
(2 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 148.113.128.238 (CA/ ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 148.113.128.238 (CA/Canada/proxy-ca014-san238.ahrefs.net)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-10 13:56:17
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 148.113.128.238 (proxy-ca014-san238.ahrefs.net) ...
show more
(mod_security) mod_security (id:210730) triggered by 148.113.128.238 (proxy-ca014-san238.ahrefs.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 09:56:11.208553 2026] [security2:error] [pid 1808896:tid 1808896] [client 148.113.128.238:19462] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nationalnova.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nationalnova.com"] [uri "/images/decode/_vti_cnf/Thumbs.db"] [unique_id "adkBe2eZRMtqQenkX1HCwgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack