๐ฌ๐ง
Steve
2026-06-03 20:25:01
(1 week ago)
Forum Spam
Web Spam
๐ช๐ธ
robotstxt
2026-05-05 03:49:20
(1 month ago)
191.102.132.28 - - [05/May/2026:03:49:08 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 13402 " ...
show more
191.102.132.28 - - [05/May/2026:03:49:08 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 13402 "https://www.nextlevel.es" rt="0.621" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-" h="www.nextlevel.es" sn="www.nextlevel.es" ru="/mailto:[email protected] " u="/index.php" ucs="-" ua="unix:/var/run/php/nextlevel82.sock" us="404" uct="0.000" urt="0.621"
191.102.132.28 - - [05/May/2026:03:49:09 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 13402 "https://www.nextlevel.es" rt="0.263" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-" h="www.nextlevel.es" sn="www.nextlevel.es" ru="/mailto:[email protected] " u="/index.php" ucs="-" ua="unix:/var/run/php/nextlevel82.sock" us="404" uct="0.000" urt="0.263"
191.102.132.28 - - [05/May/2026:03:49:11 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 13402 "https://www.nextlevel.es" rt="0.441" "Mozill
...
show less
Bad Web Bot
๐ฎ๐ฉ
hermawan
2026-04-24 22:57:32
(1 month ago)
04/25/2026-00:59:46.247745 [Drop] [**] [1:43238:4] Suricata SERVER-WEBAPP Imatix Xitami web server ...
show more
04/25/2026-00:59:46.247745 [Drop] [**] [1:43238:4] Suricata SERVER-WEBAPP Imatix Xitami web server head processing denial of service attempt [**] [Classification: Attempted Denial of Service] [Priority: 3] {TCP} 191.102.132.28:40927 -> 103.166.156.58:80
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-04-24 18:11:12
(1 month ago)
1777053586.247745 Chzb5437kcMAa7f4mj 191.102.132.28 40927 103.166.156.58 80 1 HEAD staklim-jatim.bmk ...
show more
1777053586.247745 Chzb5437kcMAa7f4mj 191.102.132.28 40927 103.166.156.58 80 1 HEAD staklim-jatim.bmkg.go.id / http://staklim-jatim.bmkg.go.id - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 - 0 0 - - - - (empty) - - - - - - - - - he11nr050000_3658ef221638_000000000000_000000000000 04/25/2026-00:59:46.247745
...
show less
Email Spam
Hacking
๐ฑ๐ป
garmtech.com
2026-04-20 05:41:51
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-41.191.102.132.28.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 08-41.191.102.132.28.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 21:39:07
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 17:38:57.717818 2026] [security2:error] [pid 26949:tid 26949] [client 191.102.132.28:33087] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "achKcerrleFDT3fec9wEtQAAAAY"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-07 05:12:46
(4 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-02-04 08:55:32
(4 months ago)
Critical web app attack detected. Illegal Accept header: charset parameter
Web App Attack
Anonymous
2026-01-21 05:20:03
(4 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 02:08:56
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 06 21:08:49.934146 2026] [security2:error] [pid 28832:tid 28832] [client 191.102.132.28:32143] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aV3AMU8s0qJ3tu6S5bLq5wAAAAM"], referer: http://www.capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-05-28 20:02:43
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
Psycho Solutions LLC
2025-04-19 20:10:47
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/19/2025 8:10 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-04-19 10:07:38
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-04-04 18:46:00
(1 year ago)
WP Login Scan Activities
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-03 14:08:13
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 191.102.132.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 191.102.132.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 03 10:08:06.566599 2025] [security2:error] [pid 8439:tid 8439] [client 191.102.132.28:41631] [client 191.102.132.28] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.CapitalSwissCorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "Z-6WRvBxOoSNYpJOlSjNKwAAAAo"], referer: http://www.CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack