๐ฉ๐ช
HandyTreff.de
2026-05-30 07:04:16
(6 days ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -51.896 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -51.896 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.171.61
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-08 15:07:45
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 178.20.212.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.212.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 10:07:40.145385 2026] [security2:error] [pid 9402:tid 9402] [client 178.20.212.157:35389] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||laradioactivitat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "laradioactivitat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYimvLHxnKFeAD9-VrOL1AAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HandyTreff.de
2025-11-21 02:43:37
(6 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -36.775 (Bad < -10 / Very Bad < -20) ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -36.775 (Bad < -10 / Very Bad < -20) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.2483.1
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-19 13:40:07
(6 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-05 06:39:12
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.212.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.212.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 05 01:39:06.887039 2025] [security2:error] [pid 13873:tid 13873] [client 178.20.212.157:60531] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||lcoor.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "lcoor.org"] [uri "/"] [unique_id "aQrxCnPrL2ah6IUXCqyWzwAAABg"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-20 08:25:01
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.212.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.212.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 20 04:24:58.048278 2025] [security2:error] [pid 26907:tid 26907] [client 178.20.212.157:32299] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||passy.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "passy.us"] [uri "/"] [unique_id "aPXx2tVI0Ox7jaMKlpHAeAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-15 14:42:42
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.212.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.212.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 15 10:42:36.065072 2025] [security2:error] [pid 22558:tid 22558] [client 178.20.212.157:55557] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||stormwlf.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "stormwlf.com"] [uri "/"] [unique_id "aO-y3DyK83HuPTfxGupbFgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-07-02 05:10:08
(11 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
Anonymous
2025-05-08 07:14:35
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-10-29 08:06:33
(1 year ago)
This IP was involved in an brute force and password spray attack on 2024/10/29 03:03:49
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฆ
wil.com
2024-10-26 05:32:50
(1 year ago)
GlobalProtect login attempts with user powerbi.
VPN IP
Brute-Force
๐บ๐ธ
NXTwoThou
2024-10-10 12:22:09
(1 year ago)
/RDWeb/Pages/
Web App Attack
Anonymous
2024-10-01 01:50:08
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
๐ท๐บ
sms.ru
2024-09-20 16:50:04
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
Anonymous
2024-08-08 13:27:00
(1 year ago)
Attack on wp-login.php.
Hacking
Brute-Force
Web App Attack