http-bad-user-agent - IP: 173.211.69.69 - time="2026-05-02T10:29:38+02:00" level=info msg="(555f66b ...
show morehttp-bad-user-agent - IP: 173.211.69.69 - time="2026-05-02T10:29:38+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-bad-user-agent by ip 173.211.69.69 (US/13332) : 4h ban on Ip 173.211.69.69" module=db
show less
Recurrent distributed campaign detected (51 requests, 51 unique IPs over 63857 sec); unauth. bot tra ...
show moreRecurrent distributed campaign detected (51 requests, 51 unique IPs over 63857 sec); unauth. bot traffic w/o verification; first observed at 2026-02-26T18:20:25+01:00
show less
[Fri Sep 12 20:15:25.812775 2025] [security2:error] [pid 1511834:tid 140660960020160] [client 173.21 ...
show more[Fri Sep 12 20:15:25.812775 2025] [security2:error] [pid 1511834:tid 140660960020160] [client 173.211.69.69:57143] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "372"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 173.211.69.69 request_line = GET /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/6-bulan-ke-depan/555561124-prakiraan-bulanan-curah-hujan-di-kabupaten-lumajang-untuk-6-bulan-ke-depan HTTP/1.1 Request URI RAW = /index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-curah-hujan-bulanan/6-bulan-ke-depan/555561124-prakiraan-bulanan-curah-hujan-di..."] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-iklim/prakiraan-bulanan/prakiraan-cur
...
show less
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 173.211.69.69 (US/United States/-): ...
show moreLF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 173.211.69.69 (US/United States/-): 1 in the last 3600 secs
show less
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 173.211.69.69 (US/United States/-): ...
show moreLF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 173.211.69.69 (US/United States/-): 1 in the last 3600 secs
show less
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 173.211.69.69 (US/United States/-): ...
show moreLF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 173.211.69.69 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
Showing 1 to
10
of 10 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ