Anonymous
2026-07-27 18:47:56
(11 hours ago)
Web App Attack
Brute-Force
Web App Attack
Anonymous
2026-07-13 19:54:29
(2 weeks ago)
Web App Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 03:19:27
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.69.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 23:19:20.956865 2026] [security2:error] [pid 13312:tid 13312] [client 172.69.9.127:9443] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||renjunews.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "renjunews.com"] [uri "/tox.ini"] [unique_id "aj3vuCEsba1l43aagFKgUAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-23 15:00:03
(3 months ago)
Aggressive web scan
Web App Attack
Anonymous
2026-04-08 15:14:50
(3 months ago)
Aggressive web scan
Web App Attack
Anonymous
2026-04-03 07:12:20
(3 months ago)
[Fri Apr 03 09:12:07.257747 2026] [authz_core:error] [pid 6797] [client 172.69.9.127:9303] AH01630: ...
show more
[Fri Apr 03 09:12:07.257747 2026] [authz_core:error] [pid 6797] [client 172.69.9.127:9303] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Apr 03 09:12:19.112901 2026] [authz_core:error] [pid 18541] [client 172.69.9.127:9376] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Apr 03 09:12:19.687423 2026] [authz_core:error] [pid 18541] [client 172.69.9.127:9376] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
ersei.net
2026-03-05 10:16:00
(4 months ago)
Brute force multiple 403s
Brute-Force
Anonymous
2026-03-02 13:06:08
(4 months ago)
172.69.9.127 - - [02/Mar/2026:15:06:05 +0200] "GET //wp-content/uploads/2021/02/index.php HTTP/1.0" ...
show more
172.69.9.127 - - [02/Mar/2026:15:06:05 +0200] "GET //wp-content/uploads/2021/02/index.php HTTP/1.0" 404 455 "-" "-"
172.69.9.127 - - [02/Mar/2026:15:06:05 +0200] "GET //wp-content/uploads/2021/02/index.php HTTP/1.1" 404 243 "-" "-"
172.69.9.127 - - [02/Mar/2026:15:06:06 +0200] "GET /wp-includes/Text/Diff/Engine/about.php HTTP/1.0" 404 455 "-" "-"
172.69.9.127 - - [02/Mar/2026:15:06:06 +0200] "GET /wp-includes/Text/Diff/Engine/about.php HTTP/1.1" 404 243 "-" "-"
172.69.9.127 - - [02/Mar/2026:15:06:07 +0200] "GET //wp-includes/css/index.php?p= HTTP/1.0" 404 455 "-" "-"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-02-22 15:25:12
(5 months ago)
Web App Attack
Brute-Force
Web App Attack
๐ฉ๐ช
swk
2025-11-18 00:25:47
(8 months ago)
172.69.9.127 - - [18/Nov/2025:08:25:40 +0800] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 301 16 ...
show more
172.69.9.127 - - [18/Nov/2025:08:25:40 +0800] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.69.9.127 - - [18/Nov/2025:08:25:41 +0800] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.69.9.127 - - [18/Nov/2025:08:25:46 +0800] "GET /test/wp-includes/wlwmanifest.xml HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2025-10-27 15:40:54
(9 months ago)
Web vulnerability probing: /.git/HEAD
Web App Attack
๐ฎ๐น
alph44
2025-10-06 06:29:59
(9 months ago)
WordPress attack detected by fail2ban: 3 failed attempts
Web App Attack
๐ฆ๐ฉ
bakunin1848
2025-07-11 10:47:06
(1 year ago)
Firewall IPS Detection on 11-07-2025 at 12:47:06
Port Scan
Exploited Host
Anonymous
2025-05-22 18:12:43
(1 year ago)
[Thu May 22 20:12:42.104019 2025] [authz_core:error] [pid 28025] [client 172.69.9.127:31736] AH01630 ...
show more
[Thu May 22 20:12:42.104019 2025] [authz_core:error] [pid 28025] [client 172.69.9.127:31736] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu May 22 20:12:42.286562 2025] [authz_core:error] [pid 28025] [client 172.69.9.127:31736] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu May 22 20:12:42.468843 2025] [authz_core:error] [pid 28025] [client 172.69.9.127:31736] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-06 20:16:44
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.69.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 06 16:16:30.635343 2025] [security2:error] [pid 27229:tid 27229] [client 172.69.9.127:42682] [client 172.69.9.127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redish.org"] [uri "/sandbox/.git/config"] [unique_id "Z_LhHrpjHEOmq8f16MMWXgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack