๐ธ๐ฌ
anotherwatcher
2026-08-31 10:06:52
(25 minutes ago)
bad bot
Bad Web Bot
๐ฉ๐ช
Sรฉfora Srl
2026-08-16 04:00:11
(2 weeks ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
๐บ๐ธ
SOC Blue Team
2026-08-11 11:34:24
(2 weeks ago)
Tatic: TA0006 | Technique: T1110 | Source: TAP | Country Destination: BR
Brute-Force
๐ง๐ช
madeit
2026-08-05 17:41:51
(3 weeks ago)
Web App Attack
๐ฉ๐ช
palla89
2026-07-24 04:21:18
(1 month ago)
(wordpress) Failed wordpress login from 172.71.172.229 (DE/Germany/-)
Brute-Force
๐ท๐บ
DZBOT
2026-07-23 13:37:44
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
mawan
2026-07-22 20:57:55
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 02:06:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 22:06:00.546308 2026] [security2:error] [pid 14055:tid 14076] [client 172.71.172.229:10634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativelabor.com"] [uri "/.git/config"] [unique_id "alg8iCpZ37VECudHNFe3FgAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 22:19:43
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.71.172.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.172.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 18:19:37.486077 2026] [security2:error] [pid 10942:tid 10942] [client 172.71.172.229:11817] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.perissosdigitalmarketing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.perissosdigitalmarketing.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ais0eUUiSogdBJrcKuuMHQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 23:33:27
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 19:33:22.407638 2026] [security2:error] [pid 16501:tid 16501] [client 172.71.172.229:10170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lanuevaley.com"] [uri "/.git/config"] [unique_id "aiSuQrcFQY4xAlueporQ2wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
serverutama
2026-06-06 14:03:01
(2 months ago)
Nginx scanner: 172.71.172.229 - - [06/Jun/2026:20:58:26 +0700] "GET /.env.backup HTTP/1.1" 444 0 "-" ...
show more
Nginx scanner: 172.71.172.229 - - [06/Jun/2026:20:58:26 +0700] "GET /.env.backup HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.4.22" "95.216.39.43"
show less
Web App Attack
Bad Web Bot
๐ฆ๐บ
afleventoffice.com.au
2026-06-06 10:52:04
(2 months ago)
GET /.git/config HTTP/1.1
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 19:05:46
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 10:24:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:24:07.324524 2026] [security2:error] [pid 21131:tid 21131] [client 172.71.172.229:11114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artevoix.com"] [uri "/.git/config"] [unique_id "ah6vRxXeCEKBxqrgJvN3VwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-27 11:25:59
(3 months ago)
[Wed May 27 13:25:57.180971 2026] [authz_core:error] [pid 19203] [client 172.71.172.229:10913] AH016 ...
show more
[Wed May 27 13:25:57.180971 2026] [authz_core:error] [pid 19203] [client 172.71.172.229:10913] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed May 27 13:25:57.303298 2026] [authz_core:error] [pid 19203] [client 172.71.172.229:10913] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed May 27 13:25:58.737681 2026] [authz_core:error] [pid 19203] [client 172.71.172.229:10913] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack