π¬π§
djboddington
2026-02-03 11:55:17
(5 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-backdoors-attempts
Hacking
Exploited Host
πΊπΈ
ersei.net
2026-02-03 11:11:31
(5 months ago)
Brute force multiple 403s
Brute-Force
π©πͺ
Starburst SysOp Team
2026-02-03 10:17:45
(5 months ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-nue6-2)
Hacking
Bad Web Bot
Anonymous
2026-02-03 09:59:44
(5 months ago)
[Tue Feb 03 10:59:41.285194 2026] [authz_core:error] [pid 428487:tid 428503] [client 178.128.220.111 ...
show more
[Tue Feb 03 10:59:41.285194 2026] [authz_core:error] [pid 428487:tid 428503] [client 178.128.220.111:44432] AH01630: client denied by server configuration: /var/www/html/
[Tue Feb 03 10:59:41.802559 2026] [authz_core:error] [pid 428487:tid 428501] [client 178.128.220.111:44442] AH01630: client denied by server configuration: /var/www/html/form.html
[Tue Feb 03 10:59:42.314328 2026] [authz_core:error] [pid 428488:tid 428527] [client 178.128.220.111:44454] AH01630: client denied by server configuration: /var/www/html/upl.php
[Tue Feb 03 10:59:42.830033 2026] [authz_core:error] [pid 428487:tid 428508] [client 178.128.220.111:44462] AH01630: client denied by server configuration: /var/www/html/t4
[Tue Feb 03 10:59:43.370822 2026] [authz_core:error] [pid 428487:tid 428499] [client 178.128.220.111:44478] AH01630: client denied by server configuration: /var/www/html/geoip
...
show less
Web App Attack
π΅π±
nfsec.pl
2026-02-03 08:13:38
(5 months ago)
178.128.220.111 - - [03/Feb/2026:08:13:35 +0000] "GET /form.html HTTP/1.1" 404 384 "-" "curl/8.1.2"
...
show more
178.128.220.111 - - [03/Feb/2026:08:13:35 +0000] "GET /form.html HTTP/1.1" 404 384 "-" "curl/8.1.2"
178.128.220.111 - - [03/Feb/2026:08:13:36 +0000] "GET /upl.php HTTP/1.1" 404 384 "-" "Mozilla/5.0"
178.128.220.111 - - [03/Feb/2026:08:13:36 +0000] "GET /t4 HTTP/1.1" 404 384 "-" "Mozilla/5.0"
178.128.220.111 - - [03/Feb/2026:08:13:36 +0000] "GET /geoip/ HTTP/1.1" 404 384 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
178.128.220.111 - - [03/Feb/2026:08:13:38 +0000] "GET /1.php HTTP/1.1" 404 384 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
...
show less
Exploited Host
Web App Attack
πΊπΈ
gu-alvareza
2026-02-03 07:05:15
(5 months ago)
SystemBC.Botnet
DDoS Attack
Hacking
π©πͺ
Tamsy
2026-02-03 06:06:34
(5 months ago)
HTTPD - Web Application scripting attack
Web App Attack
π³πΏ
Antinson
2026-02-03 04:32:40
(5 months ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
π³π±
0xffffffff
2026-02-03 04:16:54
(5 months ago)
[2026-02-03 06:16:51.588385] [authz_core:error] [pid 1994128:tid 123607145477824] [client 178.128.22 ...
show more
[2026-02-03 06:16:51.588385] [authz_core:error] [pid 1994128:tid 123607145477824] [client 178.128.220.111:47574] AH01630: client denied by server configuration: /var/www/html/ , error_notes:wrong-host , URI:'/'
[2026-02-03 06:16:51.909930] [authz_core:error] [pid 1994127:tid 123607103514304] [client 178.128.220.111:47586] AH01630: client denied by server configuration: /var/www/html/form.html , error_notes:wrong-host , URI:'/form.html'
[2026-02-03 06:16:52.231202] [authz_core:error] [pid 1994128:tid 123607128692416] [client 178.128.220.111:47600] AH01630: client denied by server configuration: /var/www/html/upl.php , error_notes:wrong-host , URI:'/upl.php'
[2026-02-03 06:16:52.553013] [authz_core:error] [pid 1994127:tid 123607011292864] [client 178.128.220.111:47616] AH01630: client denied by server configuration: /var/www/html/t4 , error_notes:wrong-host , URI:'/t4'
[2026-02-03 06:16:52.874381] [authz_core:error] [pid 1994127:tid 123606994507456] [client 178.128.220.111:47628] AH01630: client denied by serve
show less
Bad Web Bot
Web App Attack
πΊπΈ
antlac1
2026-02-03 01:51:58
(5 months ago)
crowdsecurity/http-backdoors-attempts
Brute-Force
Web App Attack
π©πͺ
Mr-Money
2026-02-02 23:03:42
(5 months ago)
scenario: crowdsecurity/http-backdoors-attempts - events: 2
Hacking
Web App Attack
πΊπΈ
Starburst SysOp Team
2026-02-02 22:50:55
(5 months ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-4)
Hacking
Bad Web Bot
Anonymous
2026-02-02 22:40:04
(5 months ago)
Hacking
πͺπΈ
liewebs
2026-02-02 22:21:08
(5 months ago)
SYN Flood attack detected - server.liewebs.es
DDoS Attack
Port Scan
πͺπΈ
yvoictra
2026-02-02 19:39:49
(5 months ago)
178.128.220.111 - - [02/Feb/2026:20:39:46 +0100] "GET /form.html HTTP/1.1" 404 134 "-" "curl/8.1.2"
...
show more
178.128.220.111 - - [02/Feb/2026:20:39:46 +0100] "GET /form.html HTTP/1.1" 404 134 "-" "curl/8.1.2"
178.128.220.111 - - [02/Feb/2026:20:39:47 +0100] "GET /upl.php HTTP/1.1" 404 134 "-" "Mozilla/5.0"
178.128.220.111 - - [02/Feb/2026:20:39:47 +0100] "GET /t4 HTTP/1.1" 404 134 "-" "Mozilla/5.0"
178.128.220.111 - - [02/Feb/2026:20:39:47 +0100] "GET /geoip/ HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
178.128.220.111 - - [02/Feb/2026:20:39:48 +0100] "GET /favicon.ico HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack