๐ฆ๐บ
oncord
2025-07-01 09:58:40
(11 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-07-01 01:48:09
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il) ...
show more
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 30 21:48:04.978363 2025] [security2:error] [pid 14196:tid 14196] [client 195.47.238.44:15812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cdphotography.us"] [uri "/.git/config"] [unique_id "aGM-VAHc-nRhfVAXUB2WXwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-30 21:03:17
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il) ...
show more
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 30 17:03:11.308681 2025] [security2:error] [pid 19678:tid 19678] [client 195.47.238.44:8582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "firebelly.org"] [uri "/.git/config"] [unique_id "aGL7j3mFDqo_xNmZaLMCYAAAABA"], referer: http://www.firebelly.org/.git/config
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-30 11:33:01
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il) ...
show more
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 30 07:32:57.332002 2025] [security2:error] [pid 3820428:tid 3820470] [client 195.47.238.44:41734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.interludes.info"] [uri "/.git/config"] [unique_id "aGJ16fq86y3lYkaD_pZXyAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-30 01:44:06
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il) ...
show more
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 29 21:43:59.255477 2025] [security2:error] [pid 870709:tid 870709] [client 195.47.238.44:35632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.acsellsre.com"] [uri "/.git/config"] [unique_id "aGHr303InhkDkbIh88imVQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-29 22:39:15
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il) ...
show more
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 29 18:39:07.075435 2025] [security2:error] [pid 1137537:tid 1137537] [client 195.47.238.44:47740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aquatech-ind.com"] [uri "/.git/config"] [unique_id "aGHAiw-kUNHYcHQ4nIp5yAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-29 19:40:09
(11 months ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-28 23:56:24
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il) ...
show more
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 28 19:56:18.366444 2025] [security2:error] [pid 4171659:tid 4171659] [client 195.47.238.44:57504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "truewaveboards.com"] [uri "/wp-config.php.save.2"] [unique_id "aGCBIpyJ6s9shs--JSFoiQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 21:12:05
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il) ...
show more
(mod_security) mod_security (id:210492) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 17:11:57.739579 2025] [security2:error] [pid 3276571:tid 3276571] [client 195.47.238.44:35296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.weroinc.com"] [uri "/.git/config"] [unique_id "aF8JHZxkzlvWWoVHLCmmDQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2025-06-27 16:07:02
(11 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
LRob.fr
2025-06-26 05:45:10
(11 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฌ๐ง
Globe2
2025-06-24 20:48:53
(11 months ago)
[24/Jun/2025:21:48:50 +0100] G7p7qgjtU0i-pVVqSHVXg94L 195.47.238.44 32796 91.212.212.13 443
[24/Jun/ ...
show more
[24/Jun/2025:21:48:50 +0100] G7p7qgjtU0i-pVVqSHVXg94L 195.47.238.44 32796 91.212.212.13 443
[24/Jun/2025:21:48:51 +0100] x175-h68CgVnSgQGWwwvaGAL 195.47.238.44 37676 91.212.212.13 443
[24/Jun/2025:21:48:52 +0100] aSKgW64cpb-FHXhsNhkQpZQK 195.47.238.44 16666 91.212.212.13 443
...
show less
Web App Attack
๐บ๐ธ
oncord
2025-06-24 16:50:19
(11 months ago)
Form spam
Web Spam
๐ฉ๐ช
NetworkOperationsTeam
2025-06-24 09:42:08
(11 months ago)
SMS Bombing. Trying to authenticate. API Abuse rate limit exceeded
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-23 18:09:00
(11 months ago)
(mod_security) mod_security (id:210831) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il) ...
show more
(mod_security) mod_security (id:210831) triggered by 195.47.238.44 (anonode.se-1.prod.encrypt.co.il): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 23 14:08:53.267373 2025] [security2:error] [pid 70510:tid 70510] [client 195.47.238.44:54422] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.ewingmissouri.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.ewingmissouri.com"] [uri "/robots.txt"] [unique_id "aFmYNTkyu9SnzQIIj2GwHwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack