๐ณ๐ฑ
Site.eu
2025-04-17 04:33:35
(1 year ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
ipblock.com
2025-04-16 08:34:00
(1 year ago)
IPBlock protected site ID [1438-do].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2025-04-15 12:18:36
(1 year ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
S.O.B.A. Dev.
2025-04-14 05:01:13
(1 year ago)
Threat Blocked by BeeHive from (ASN:16276) (Network:OVH) (Host:soba.dev) (Method:GET) (Protocol:HTTP ...
show more
Threat Blocked by BeeHive from (ASN:16276) (Network:OVH) (Host:soba.dev) (Method:GET) (Protocol:HTTP/1.1) (Timestamp:2025-04-14T05:01:13Z)
show less
Web Spam
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2025-04-10 06:20:04
(1 year ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2025-04-10 05:57:39
(1 year ago)
2025/04/10 07:57:38 [error] 22#1017369: *13951916 limiting requests, excess: 0.670 by zone "crawler" ...
show more
2025/04/10 07:57:38 [error] 22#1017369: *13951916 limiting requests, excess: 0.670 by zone "crawler", client: 2001:41d0:1004:be::1, server: new.hondaforum.hu, request: "GET /do-not-scrape/ HTTP/1.1", host: "new.hondaforum.hu"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-04-07 03:04:08
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2001:41d0:1004:be::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210381) triggered by 2001:41d0:1004:be::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 06 23:04:03.051359 2025] [security2:error] [pid 4129984:tid 4129984] [client 2001:41d0:1004:be::1:47114] [client 2001:41d0:1004:be::1] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||1st-pick.com|F|4"] [data "REQUEST_URI=/FindListing/%Illinois%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "1st-pick.com"] [uri "/FindListing/%Illinois%"] [unique_id "Z_NAoxZybqcy0RBSqJJsTwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-06 12:48:07
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 2001:41d0:1004:be::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:240950) triggered by 2001:41d0:1004:be::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 06 08:48:00.884031 2025] [security2:error] [pid 3472592:tid 3472592] [client 2001:41d0:1004:be::1:49606] [client 2001:41d0:1004:be::1] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||goldengatecorgis.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "goldengatecorgis.org"] [uri "/"] [unique_id "Z_J4AELA-DmjhqGajaWkZwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-06 05:33:54
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
MarkGGN
2025-04-06 05:22:19
(1 year ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2025-04-03 01:11:09
(1 year ago)
2001:41d0:1004:be::1 - - [03/Apr/2025:02:11:04 +0100] "GET /robots.txt HTTP/1.0" 404 1234 "-" "Mozil ...
show more
2001:41d0:1004:be::1 - - [03/Apr/2025:02:11:04 +0100] "GET /robots.txt HTTP/1.0" 404 1234 "-" "Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-04-02 13:00:46
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:1004:be::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:1004:be::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 02 09:00:39.363586 2025] [security2:error] [pid 27383:tid 27383] [client 2001:41d0:1004:be::1:59912] [client 2001:41d0:1004:be::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.miranda-race-walks.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.miranda-race-walks.com"] [uri "/Pages/[email protected] "] [unique_id "Z-009wCUotTGDa_rkeHmGgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-02 07:56:58
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:1004:be::1 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:1004:be::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 02 03:56:50.940685 2025] [security2:error] [pid 385590:tid 385590] [client 2001:41d0:1004:be::1:34264] [client 2001:41d0:1004:be::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chriseaton.com|F|2"] [data ".ticketmaster.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chriseaton.com"] [uri "/WWW.ticketmaster.com"] [unique_id "Z-ztwl8eHW8jsGbO_1YdYAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-04-02 06:01:45
(1 year ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ธ๐ฌ
mypatricks
2025-03-31 22:19:35
(1 year ago)
2001:41d0:1004:be::1/241.131.111.145 | Port: 57460 | DNS: 2001:41d0:1004:be::1 2025-04-01T06:19:34+0 ...
show more
2001:41d0:1004:be::1/241.131.111.145 | Port: 57460 | DNS: 2001:41d0:1004:be::1 2025-04-01T06:19:34+08:00 Europe/Paris | Un-authorized bots or crawlers | UA: Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/) HTTP/1.1 443 GET | URL: /3DFondant_Cakes_Disney_Frozen_Olaf/ | Ref: - | Country: FR/France/+01:00 IP City: 92933a9c19db9f09-CDG/Paris, France 1 hits/0 secs Robots 1
show less
Web Spam
Blog Spam
Brute-Force
Exploited Host
Web App Attack