๐ฉ๐ช
Lino Project
2026-07-23 12:27:20
(5 minutes ago)
CrowdSec abuse IP report (host SRV-2) Scenario: LePresidente/http-generic-403-bf
Hacking
๐ฉ๐ช
SwinT
2026-07-23 10:00:05
(2 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ธ๐ฌ
securejdprop
2026-07-23 09:57:52
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor E ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor Exit Node Traffic group 79).
show less
Hacking
Web App Attack
๐บ๐ธ
ANTI SCANNER
2026-07-23 06:44:01
(5 hours ago)
Scanner : /administrator/index.php
Web Spam
๐ฎ๐ฉ
securejdprop
2026-07-22 08:25:46
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor E ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET TOR Known Tor Exit Node Traffic group 76).
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-07-22 01:20:20
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 10:46:51
(3 days ago)
(mod_security) mod_security (id:211190) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:211190) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:46:45.340501 2026] [security2:error] [pid 9352:tid 9352] [client 204.8.96.65:49750] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||test.nationalccl.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /cgi-bin/zml.cgi?file=../../../../../../../../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.nationalccl.com"] [uri "/cgi-bin/zml.cgi"] [unique_id "al38laa5nIvS2Mg-vwOt9wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-20 03:08:47
(3 days ago)
[MonJul2005:08:44.0762122026][security2:error][pid1445814:tid1445862][client204.8.96.65:0]ModSecurit ...
show more
[MonJul2005:08:44.0762122026][security2:error][pid1445814:tid1445862][client204.8.96.65:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"morgenstern-swiss.ch\"][uri\"/index.php\"][unique_id\"al2RPKUlZSP-4kwoRshs5AAAAM4\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 17:20:17
(3 days ago)
(mod_security) mod_security (id:210350) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:210350) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 13:20:13.047353 2026] [security2:error] [pid 32120:tid 32120] [client 204.8.96.65:36832] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||whateverhappenedto.xyz|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "whateverhappenedto.xyz"] [uri "/cpanel/"] [unique_id "al0HTUb590qHLWEZDxNQowAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 12:57:46
(4 days ago)
(mod_security) mod_security (id:210831) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:210831) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 08:57:43.681515 2026] [security2:error] [pid 540566:tid 540566] [client 204.8.96.65:42772] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.kraftre.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.kraftre.com"] [uri "/robots.txt"] [unique_id "alt4R9E_3-XzX8vhdirpuwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 01:37:45
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:240335) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 21:37:37.669596 2026] [security2:error] [pid 22243:tid 22243] [client 204.8.96.65:38756] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 204.8.96.65 (+1 hits since last alert)|ekur-art.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ekur-art.com"] [uri "/xmlrpc.php"] [unique_id "almHYfvBRBP6wn1NbaqkMQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 21:42:04
(6 days ago)
(mod_security) mod_security (id:210831) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:210831) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 17:41:56.577248 2026] [security2:error] [pid 32061:tid 32061] [client 204.8.96.65:50262] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.ahuramazda.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.ahuramazda.com"] [uri "/robots.txt"] [unique_id "allQJGtq1DjiT_rIVao25QAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-16 07:54:03
(1 week ago)
HTTP flood against /retreat-corp on Apache webserver
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-14 22:28:54
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last ...
show more
(mod_security) mod_security (id:210831) triggered by 204.8.96.65 (tor42.quintex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 18:28:50.914111 2026] [security2:error] [pid 29299:tid 29299] [client 204.8.96.65:37306] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.satanisdead.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.satanisdead.com"] [uri "/robots.txt"] [unique_id "ala4IldnQ_cIy6iCbwxJaAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-03 03:00:29
(2 weeks ago)
2026-07-02 20:00:04,130 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.65
2026-07-02 ...
show more
2026-07-02 20:00:04,130 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.65
2026-07-02 22:00:10,330 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.65
2026-07-03 00:01:00,198 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.65
2026-07-03 03:00:29,698 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.65
2026-07-03 06:00:29,258 fail2ban.actions [3625835]: NOTICE [tor] Ban 204.8.96.65
show less
Brute-Force