๐ฉ๐ช
LRob
2026-10-01 22:07:48
(2 days ago)
Shop search flood (L7 DDoS) | path: /29-meilleur-velo-entre-1000-et-2000-euros | query: q=Marque-Ber ...
show more
Shop search flood (L7 DDoS) | path: /29-meilleur-velo-entre-1000-et-2000-euros | query: q=Marque-Bergamont-Lapierre | src_port: 56654
show less
DDoS Attack
Web App Attack
๐ท๐ธ
Smel
2026-04-16 06:06:16
(5 months ago)
Mail/25/465/587-993/995 Probe, Reject, BadAuth, Hack, SPAM -
Email Spam
Hacking
Brute-Force
Anonymous
2026-04-11 08:44:32
(5 months ago)
2026-04-11T10:44:31.032457+02:00 soli-gate cyrus/imaps[849846]: badlogin: [197.95.55.109] plaintext ...
show more
2026-04-11T10:44:31.032457+02:00 soli-gate cyrus/imaps[849846]: badlogin: [197.95.55.109] plaintext ([email protected] ) [SASL(-13): authentication failure: checkpass failed]
...
show less
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-02-21 14:42:30
(7 months ago)
Mail: - login with unknown user - bruteforce
Brute-Force
Anonymous
2026-01-12 13:17:12
(8 months ago)
Detected Hacking, SQL Injection or general Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 07:37:39
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 197.95.55.109 (197-95-55-109.ftth.web.africa): ...
show more
(mod_security) mod_security (id:210350) triggered by 197.95.55.109 (197-95-55-109.ftth.web.africa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 02:37:22.982195 2025] [security2:error] [pid 16791:tid 16791] [client 197.95.55.109:44692] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||autodiscover.laradioactivitat.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "autodiscover.laradioactivitat.com"] [uri "/"] [unique_id "aVIvstmMSgMwTe9C9bHuzgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-26 22:53:33
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 197.95.55.109 (197-95-55-109.ftth.web.africa): ...
show more
(mod_security) mod_security (id:210350) triggered by 197.95.55.109 (197-95-55-109.ftth.web.africa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 26 17:52:27.890285 2025] [security2:error] [pid 32140:tid 32140] [client 197.95.55.109:34310] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mail.pascalevial.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mail.pascalevial.com"] [uri "/"] [unique_id "aU8Rq2Y2ImrbQ4eTFxzlrQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-18 00:48:41
(10 months ago)
scanning http requests from known botnet
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2025-10-19 13:00:38
(11 months ago)
2025/10/19 15:00:36 [error] 40530#204332: *3306492 access forbidden by rule, client: 197.95.55.109, ...
show more
2025/10/19 15:00:36 [error] 40530#204332: *3306492 access forbidden by rule, client: 197.95.55.109, server: crxforum.ksol.io, request: "GET /showTopic2.php?seed=BDB494B443&topicId=895 HTTP/1.1", host: "crxforum.ksol.io"
...
show less
Web Spam
๐ญ๐บ
ksol-hostmaster
2025-10-19 13:00:38
(11 months ago)
Massive botnet baited into scraping tarpit
Bad Web Bot
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-10-08 07:38:29
(11 months ago)
Port probe to tcp/888 (cd database)
[srv130]
Port Scan
๐ณ๐ฑ
exxos
2025-08-29 15:03:01
(1 year ago)
http-no-verb
Hacking
Anonymous
2025-07-13 16:21:29
(1 year ago)
Ports: 143,993; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH