๐บ๐ธ
Starburst SysOp Team
2025-06-09 01:47:32
(11 months ago)
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked. Matched phrase "MJ12bot" at REQUEST_HEADE ...
show more
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. (1100000-stl2-14)
show less
Bad Web Bot
๐ฉ๐ช
rh24
2025-06-07 01:25:50
(11 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 2001:41d0:303:1eb3:: ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 2001:41d0:303:1eb3::1 (Unknown)
show less
Bad Web Bot
๐ฉ๐ช
SpaceHost-Server
2025-06-04 22:28:28
(11 months ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
Roderic
2025-06-04 21:00:41
(11 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-06-04 06:57:12
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2001:41d0:303:1eb3::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210381) triggered by 2001:41d0:303:1eb3::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 04 02:57:06.453274 2025] [security2:error] [pid 1265395:tid 1265395] [client 2001:41d0:303:1eb3::1:44984] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||1st-pick.com|F|4"] [data "REQUEST_URI=/FindListing/%Illinois%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "1st-pick.com"] [uri "/FindListing/%Illinois%"] [unique_id "aD_uQoD-MblSuWrK8aEjXQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2025-06-03 22:35:54
(1 year ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Bad Web Bot
Web App Attack
๐ฉ๐ช
SpaceHost-Server
2025-06-03 22:28:19
(1 year ago)
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2025-06-03 20:01:16
(1 year ago)
2025/06/03 20:01:12 [error] 1504810#1504810: *172985252 access forbidden by rule, client: 2001:41d0: ...
show more
2025/06/03 20:01:12 [error] 1504810#1504810: *172985252 access forbidden by rule, client: 2001:41d0:303:1eb3::1, server: binixo.mx, request: "GET /wp-content/uploads/2018/02/Cr%C3%A9dito-express.jpg HTTP/2.0", host: "binixo.mx"
2025/06/03 20:01:13 [error] 1504809#1504809: *172985321 access forbidden by rule, client: 2001:41d0:303:1eb3::1, server: binixo.mx, request: "GET /wp-content/uploads/2018/02/Prestamos-en-l%C3%ADnea-al-instante.jpg HTTP/2.0", host: "binixo.mx"
2025/06/03 20:01:16 [error] 1504806#1504806: *172985400 access forbidden by rule, client: 2001:41d0:303:1eb3::1, server: binixo.mx, request: "GET /wp-content/uploads/2018/02/Prestamos-v%C3%ADa-nomina.jpg HTTP/2.0", host: "binixo.mx"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-02 20:54:43
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2001:41d0:303:1eb3::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210381) triggered by 2001:41d0:303:1eb3::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 02 16:54:35.964143 2025] [security2:error] [pid 3378034:tid 3378049] [client 2001:41d0:303:1eb3::1:34190] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||orthopedica.org|F|4"] [data "REQUEST_URI=/wp-content/languages/plugins/\\x22%2$s/\\x22"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "orthopedica.org"] [uri "/wp-content/languages/plugins/\\"%2$s/\\""] [unique_id "aD4Pi_ixBpvJO_NOhqk0LgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2025-05-31 20:24:59
(1 year ago)
2001:41d0:303:1eb3::1 - - [31/May/2025:21:24:57 +0100] "GET /robots.txt HTTP/1.1" 403 146 "-" "Mozil ...
show more
2001:41d0:303:1eb3::1 - - [31/May/2025:21:24:57 +0100] "GET /robots.txt HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)"
...
show less
Bad Web Bot
๐บ๐ธ
construct.net
2025-05-24 22:59:41
(1 year ago)
Triggered rate limiter [PRD-VM-WEB1a]
Bad Web Bot
๐ฎ๐น
Progetto1
2025-05-22 13:12:03
(1 year ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
Roderic
2025-05-20 14:33:03
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ฉ๐ช
MarkGGN
2025-05-19 08:58:03
(1 year ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-17 01:14:14
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2001:41d0:303:1eb3::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210381) triggered by 2001:41d0:303:1eb3::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 21:14:06.932781 2025] [security2:error] [pid 3098547:tid 3098547] [client 2001:41d0:303:1eb3::1:46772] [client 2001:41d0:303:1eb3::1] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||babylontravelone.com|F|4"] [data "REQUEST_URI=/2022/01/13/how-can-i-sell-bitcoins-and-transfer-the-funds-to/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "babylontravelone.com"] [uri "/2022/01/13/how-can-i-sell-bitcoins-and-transfer-the-funds-to/%url%"] [unique_id "aCfi3kYqUAZ5rEDthDN9egAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack