๐น๐ท
neron
2026-08-22 03:21:51
(1 week ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-19 04:26:21
(2 weeks ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-30 03:06:20
(1 month ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-26 11:20:48
(1 month ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-04-14 04:00:03
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-02-15 10:52:53
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.168 (tor79.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.168 (tor79.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 15 05:52:45.508150 2024] [security2:error] [pid 6786] [client 199.249.230.168:49056] [client 199.249.230.168] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||avalderlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "avalderlaw.com"] [uri "/wordpress.sql"] [unique_id "Zc3s_VgR86Eo-JmNlgfIrAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-13 17:05:19
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.168 (tor79.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.168 (tor79.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 13 12:05:11.986413 2024] [security2:error] [pid 32438] [client 199.249.230.168:33118] [client 199.249.230.168] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||frenchla.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "frenchla.com"] [uri "/fren.sql"] [unique_id "ZcuhR8K5zdPXy9ZjwJsmSwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2024-02-13 15:23:29
(2 years ago)
levellapromotions.com.au:443 199.249.230.168 - - [14/Feb/2024:02:21:49 +1100] "POST /Form HTTP/1.1" ...
show more
levellapromotions.com.au:443 199.249.230.168 - - [14/Feb/2024:02:21:49 +1100] "POST /Form HTTP/1.1" 404 171899 "https://levellapromotions.com.au/Form" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.101 Safari/537.36"
levellapromotions.com.au:443 199.249.230.168 - - [14/Feb/2024:02:21:58 +1100] "POST /Form HTTP/1.1" 404 171899 "https://levellapromotions.com.au/Form" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.101 Safari/537.36"
levellapromotions.com.au:443 199.249.230.168 - - [14/Feb/2024:02:22:09 +1100] "POST /Form HTTP/1.1" 404 171899 "https://levellapromotions.com.au/Form" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.101 Safari/537.36"
levellapromotions.com.au:443 199.249.230.168 - - [14/Feb/2024:02:22:19 +1100] "POST /Form HTTP/1.1" 404 171899 "https://levellapromotions.com.au/Form" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) App
...
show less
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-13 01:02:54
(2 years ago)
Web Attack ([13/Feb/2024:02:02:50 +0100] )
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SpaceHost-Server
2024-02-12 12:48:14
(2 years ago)
199.249.230.168 - - [12/Feb/2024:13:48:10 +0100] "POST /xmlrpc.php HTTP/1.1" 200 221 "-" "Mozilla/5. ...
show more
199.249.230.168 - - [12/Feb/2024:13:48:10 +0100] "POST /xmlrpc.php HTTP/1.1" 200 221 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36"
199.249.230.168 - - [12/Feb/2024:13:48:12 +0100] "POST /xmlrpc.php HTTP/1.1" 200 221 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36"
199.249.230.168 - - [12/Feb/2024:13:48:14 +0100] "POST /xmlrpc.php HTTP/1.1" 200 221 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36"
show less
Hacking
Web App Attack
๐ฆ๐บ
oncord
2024-02-12 05:38:02
(2 years ago)
Form spam
Web Spam
๐ฉ๐ช
niceshops.com
2024-02-11 19:19:51
(2 years ago)
Web Attack multi (Feb 24 20:19:50 Matching rules: Detect possible SQL injection - E.g. CHR(72),Dete ...
show more
Web Attack multi (Feb 24 20:19:50 Matching rules: Detect possible SQL injection - E.g. CHR(72),Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-10 07:15:21
(2 years ago)
Web Attack multi (Feb 24 08:15:21 Matching rules: Detect possible SQL injection - E.g. CHR(72) )
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
niceshops.com
2024-02-07 13:47:43
(2 years ago)
Web Attack multi (Feb 24 14:47:43 Matching rules: Detect possible SQL injection - E.g. Select * fro ...
show more
Web Attack multi (Feb 24 14:47:43 Matching rules: Detect possible SQL injection - E.g. Select * from )
show less
SQL Injection
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-06 04:32:05
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 199.249.230.168 (tor79.quintex.com): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 199.249.230.168 (tor79.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 05 23:31:57.636540 2024] [security2:error] [pid 27034] [client 199.249.230.168:46348] [client 199.249.230.168] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||webseographics.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webseographics.com"] [uri "/seographics.sql"] [unique_id "ZcG2PTo94eM87Z3aOE_ALgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack