๐บ๐ธ
TPI-Abuse
2026-05-03 21:41:26
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 178.20.212.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.212.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 17:41:19.850018 2026] [security2:error] [pid 11356:tid 11356] [client 178.20.212.93:19073] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||photonmatrix.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "photonmatrix.com"] [uri "/"] [unique_id "affA_wZ4Vwmr3D1CGJuRuQAAAAM"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-04-30 00:10:36
(1 month ago)
WP Login Scan Activities: "2026-04-30T07:10:36.627+07:00" "/wp-login.php" "178.20.212.93" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-04-30T07:10:36.627+07:00" "/wp-login.php" "178.20.212.93" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 10:44:56
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 178.20.212.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 178.20.212.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 06:44:50.009470 2026] [security2:error] [pid 12516:tid 12516] [client 178.20.212.93:57665] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geceindia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geceindia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae3somZ-59ACEYBqiEZ4HwAAAFc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-04-20 14:42:17
(1 month ago)
[Mon Apr 20 16:42:13.835671 2026] [proxy_fcgi:error] [pid 577651:tid 577748] [remote 178.20.212.93:0 ...
show more
[Mon Apr 20 16:42:13.835671 2026] [proxy_fcgi:error] [pid 577651:tid 577748] [remote 178.20.212.93:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
[Mon Apr 20 16:42:17.433083 2026] [proxy_fcgi:error] [pid 513251:tid 515265] [remote 178.20.212.93:0] AH01071: Got error 'Primary script unknown\n', referer: https://www.google.com
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2026-04-12 23:59:26
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 178.20.212.93 (SC/Seychelles/-): 2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 178.20.212.93 (SC/Seychelles/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 02:01:17
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.212.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.212.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 22:01:08.926202 2026] [security2:error] [pid 857101:tid 857101] [client 178.20.212.93:44657] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||hdestimating.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "hdestimating.com"] [uri "/"] [unique_id "adRlZBJkfZizrXOmNSADZwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-17 23:22:49
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 178.20.212.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 178.20.212.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 18:22:43.541120 2026] [security2:error] [pid 5205:tid 5205] [client 178.20.212.93:21163] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||shepherdsstaff.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "shepherdsstaff.net"] [uri "/"] [unique_id "aZT4Q8bjzxvrOL-bkoS0jQAAAAc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-12-31 01:10:13
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-11-13 02:52:21
(6 months ago)
XML RPC Scan Activities
Brute-Force
Web App Attack
๐น๐ท
rtbh.com.tr
2025-10-31 20:09:40
(7 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-10-31 00:09:39
(7 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐น๐ท
rtbh.com.tr
2025-10-30 20:09:39
(7 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ฎ๐น
alph44
2025-10-17 23:46:21
(7 months ago)
WordPress attack detected by fail2ban: 3 failed attempts
Web App Attack
Anonymous
2024-10-10 07:10:26
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
Anonymous
2024-10-05 02:02:26
(1 year ago)
This IP was involved in an brute force and password spray attack on 2024/10/04 21:00:13
Port Scan
Brute-Force
Exploited Host
Web App Attack