๐ฉ๐ฐ
HostingGroup
2026-07-20 06:11:54
(4 days ago)
Automated malicious activity (404 Flood) detected and blocked at the CDN edge by NordicCDN Shield. O ...
show more
Automated malicious activity (404 Flood) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 2. First blocked: 2026-07-20.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
hackthetime
2026-07-19 10:35:59
(5 days ago)
Tried to access /wp-admin/install.php (auto-added by Hype UI)
Web App Attack
๐ฆ๐น
nomzamo
2026-07-18 01:12:12
(6 days ago)
Fail2Ban reported: nginx-noscript
Brute-Force
๐ท๐บ
DZBOT
2026-07-17 08:53:07
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 10:14:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 06:14:17.580307 2026] [security2:error] [pid 8072:tid 8072] [client 172.71.164.190:10395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gisur.com"] [uri "/.env.old"] [unique_id "alddeaVRh3PEGOZG_Su6wgAAAEM"], referer: https://www.google.com/search?q=gisur.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 03:05:33
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 23:05:25.519467 2026] [security2:error] [pid 20880:tid 20880] [client 172.71.164.190:10920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krugmans.com"] [uri "/.git/config"] [unique_id "akCPdV4KZcqAnZUSc--15wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-22 10:58:02
(1 month ago)
172.71.164.190 - - [22/Jun/2026:13:58:02 +0300] "GET /wp-login.php HTTP/1.1" 404 768 "-" "Mozilla/5. ...
show more
172.71.164.190 - - [22/Jun/2026:13:58:02 +0300] "GET /wp-login.php HTTP/1.1" 404 768 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 02:01:24
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 22:01:20.942586 2026] [security2:error] [pid 5233:tid 5240] [client 172.71.164.190:14077] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.java-nation.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.java-nation.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ajX0cGlobxl39DOr9UCWPgAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-17 13:12:26
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
hackthetime
2026-06-16 14:28:18
(1 month ago)
Tried to access /wp-admin/install.php (auto-added by Hype UI)
Web App Attack
๐ฎ๐ฉ
Burayot
2026-06-16 08:59:35
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.71.164.190 (DE/Germany/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.71.164.190 (DE/Germany/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 08:56:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 04:56:35.898014 2026] [security2:error] [pid 15370:tid 15370] [client 172.71.164.190:12266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "technesa.com"] [uri "/.git/config"] [unique_id "ajEPwzgd7JVEwlMJXj_W7wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hackthetime
2026-06-10 20:37:04
(1 month ago)
Auto report for path '/wp-admin/install.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:52:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:52:49.638764 2026] [security2:error] [pid 5077:tid 5077] [client 172.71.164.190:10115] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fina.pronio.com"] [uri "/.git/config"] [unique_id "aicdkbUWbaUprx_Fs25AkQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 15:07:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:07:38.977792 2026] [security2:error] [pid 2548:tid 2548] [client 172.71.164.190:11813] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humans2humans.org"] [uri "/.git/config"] [unique_id "aiGUuvAbE-7_2I7fWTcmMgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack