๐ฉ๐ช
FeG Deutschland
2026-10-10 06:12:06
(23 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:18:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:18:28.369242 2026] [security2:error] [pid 30219:tid 30219] [client 201.251.46.148:40294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||echinech.utilis.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "echinech.utilis.net"] [uri "/pgsql/export.sql"] [unique_id "askh5DLKWkgK-TvtLxtKVAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-10-08 22:14:46
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 01:15:46
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 21:15:39.254682 2026] [security2:error] [pid 4032:tid 4032] [client 201.251.46.148:60200] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||terryhildebrandprints.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "terryhildebrandprints.com"] [uri "/"] [unique_id "asGouzOnham6-SoImVklRgAAAAY"], referer: https://bestbacklinkbuilding.shop/dir/seo-link-building-services-206407
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 13:37:22
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 09:37:16.337138 2026] [security2:error] [pid 576091:tid 576116] [client 201.251.46.148:59790] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jefftappan.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jefftappan.com"] [uri "/"] [unique_id "asEFDFQuhBwOJ4VWOwUKyQAAAM4"], referer: https://searchengineoptimization.website/dir/results-driven-link-building-105881
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:27:19
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:27:13.642663 2026] [security2:error] [pid 16655:tid 16655] [client 201.251.46.148:57918] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||webuydinwiddiehouses.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "webuydinwiddiehouses.com"] [uri "/"] [unique_id "ar8IccxjT_jdBWqVXlIf-wAAAAk"], referer: https://onewaylinkbuilding.site/dir/backlinks-for-ranking-230312
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 06:51:58
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 02:51:53.985079 2026] [security2:error] [pid 32269:tid 32269] [client 201.251.46.148:44710] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tristarus.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tristarus.com"] [uri "/about/"] [unique_id "artgCT8QpdZAxoBAYX_06gAAAAM"], referer: https://tristarus.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
Countryman
2026-09-28 00:10:01
(1 week ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-23 08:13:07
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-22 04:27:50
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-22 00:52:39
(2 weeks ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-09-20 10:53:00
(2 weeks ago)
IPBlock protected site ID [4055-d][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-19 08:17:39
(3 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36 Edg/144.0.0.0
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2026-09-18 14:38:00
(3 weeks ago)
HTTP DDoS Attack Layer 7
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 01:26:43
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 ...
show more
(mod_security) mod_security (id:210350) triggered by 201.251.46.148 (201-251-46-148.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:26:39.972349 2026] [security2:error] [pid 12570:tid 12570] [client 201.251.46.148:44956] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||myriadpubs.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "myriadpubs.com"] [uri "/"] [unique_id "aqiez4nEgCZHzoBOmZxWRQAAAA4"], referer: https://docmokcomics.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack