🇫🇷
Tilellit.PRO
2026-08-24 02:26:05
(22 hours ago)
PrestaShop faceted search filter flooding attempt
DDoS Attack
Bad Web Bot
Anonymous
2026-08-06 00:00:00
(2 weeks ago)
“HTTP Flood DDoS targeting domain.tld:443 via repeated GET requests to /[category]?q=Po%C4%8Det+stra ...
show more
“HTTP Flood DDoS targeting domain.tld:443 via repeated GET requests to /[category]?q=Po%C4%8Det+stran-[random-numbers] (e.g., /2-vsechny-produkty?q=Po%C4%8Det+stran-112-144-160-368-96). Uses spoofed Chrome/Safari/Googlebot UAs. Returns 403/404 errors due to fail2ban. Likely Layer 7 attack to exhaust server resources via pagination brute-forcing.“
show less
DDoS Attack
🇺🇸
quilla
2026-04-03 03:20:35
(4 months ago)
Botnet infected device observed in honeypot (Vector: TCP)
DDoS Attack
🇺🇸
TPI-Abuse
2026-02-14 00:32:16
(6 months ago)
(mod_security) mod_security (id:217210) triggered by 170.231.122.231 (170-231-122-231.bmitelecom.com ...
show more
(mod_security) mod_security (id:217210) triggered by 170.231.122.231 (170-231-122-231.bmitelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 19:32:09.981287 2026] [security2:error] [pid 3610513:tid 3610513] [client 170.231.122.231:27325] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||ca7challenges.xyz|F|4"] [data "GET http://ca7challenges.xyz HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ca7challenges.xyz"] [uri "/"] [unique_id "aY_CiXzV1uWgVTCFVL8C8wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-26 00:33:42
(8 months ago)
scanning http requests from known botnet
Web App Attack
🇮🇩
hermawan
2025-11-22 06:27:35
(9 months ago)
[Sat Nov 22 13:25:36.655743 2025] [security2:error] [pid 767103:tid 140648585860800] [client 170.231 ...
show more
[Sat Nov 22 13:25:36.655743 2025] [security2:error] [pid 767103:tid 140648585860800] [client 170.231.122.231:41479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "AOLBUILD" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "247"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: AOLBUILD found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 ADG/11.0.2566 AOLBUILD/11.0.2566 Safari/537.36 request_line = GET /index.php/profil/meteorologi/list-all-categories/4221-klimatologi/prakiraan-klimatologi/prakiraan-dasarian/prakiraan-dasarian-daerah-potensi-banjir/prakiraan-dasarian-daerah-potensi-banjir-di-provinsi-jawa-timur/prakiraan-dasarian-daerah-potensi-banjir-di-provinsi-jawa-timur-tahun-..."] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list
...
show less
Hacking
Web App Attack
Anonymous
2025-11-14 19:41:14
(9 months ago)
scanning http requests from known botnet
Web App Attack
🇪🇸
Global Cyber Police
2025-07-27 17:26:37
(1 year ago)
Malicious bot activity detected: Hitting honeypot page (200 OK with 258/259 bytes sent).
Port Scan
Brute-Force
Web App Attack
Anonymous
2025-06-22 10:44:16
(1 year ago)
22-06-2025 12:44:15.6 ERROR util.AccessViolations - 170.231.122.231 report to fail2ban - action: blo ...
show more
22-06-2025 12:44:15.6 ERROR util.AccessViolations - 170.231.122.231 report to fail2ban - action: block
...
show less
Hacking
Brute-Force
Bad Web Bot
🇩🇪
botreporter
2025-05-18 01:18:12
(1 year ago)
botnet ignoring robots.txt 2
Bad Web Bot
Anonymous
2025-02-05 05:24:14
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
🇬🇧
Aetherweb Ark
2025-01-24 11:28:07
(1 year ago)
170.231.122.231 (BR/Brazil/170-231-122-231.bmitelecom.com.br), N distributed cpanel attacks on accou ...
show more
170.231.122.231 (BR/Brazil/170-231-122-231.bmitelecom.com.br), N distributed cpanel attacks on account in the last X secs
show less
Hacking
Anonymous
2025-01-23 00:31:48
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH