๐ต๐ฑ
Budyn
2026-10-11 00:29:47
(1 hour ago)
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_7 | Action: AWS API Call | Token: 4dv ...
show more
Budyn SOC Canary Trap: AWS Key Compromised! | Memo: AWS_Token_7 | Action: AWS API Call | Token: 4dvmm7wgh55qaj86jjj1vqe1z | Client Tool: aws-cli/2.33.12 md/awscrt#0.31.1 ua/2.1 os/linux#5.15.0-191-generic md/arch#x86_64 lang/python#3.13.11 md/pyimpl#CPython m/Z,g,b,E cfg/retry-mode#standard md...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-10-03 06:09:56
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-07-22 04:06:30
(2 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 03:10:17
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 23:09:43.323979 2026] [security2:error] [pid 12159:tid 12159] [client 206.232.1.57:37037] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tcit.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tcit.org"] [uri "/about-us"] [unique_id "acs698jGRIhDEUbRqZGgggAAABc"], referer: https://tcit.org/about-us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 21:42:31
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 17:42:12.093641 2026] [security2:error] [pid 18508:tid 18508] [client 206.232.1.57:54091] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||swhinc.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "swhinc.net"] [uri "/contact"] [unique_id "acb5tOZ6jxP15R4uPwGS6wAAAAA"], referer: https://swhinc.net/contact
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-17 03:53:56
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 23:53:51.797413 2026] [security2:error] [pid 25090:tid 25097] [client 206.232.1.57:33927] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||trident-environmental.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "trident-environmental.com"] [uri "/company-profile"] [unique_id "abjQT91aoJsGEEzoeWELfQAAAEU"], referer: https://trident-environmental.com/company-profile
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 14:20:45
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 10:20:36.606844 2026] [security2:error] [pid 16798:tid 16798] [client 206.232.1.57:51625] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||advantagesystemsgroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "advantagesystemsgroup.com"] [uri "/about"] [unique_id "abVutEfIrTPjXCTepwAcfQAAABI"], referer: https://advantagesystemsgroup.com/about
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 19:30:58
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 206.232.1.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 15:30:52.864161 2026] [security2:error] [pid 12480:tid 12480] [client 206.232.1.57:32303] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||artbyrt.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "artbyrt.com"] [uri "/artbyrt_docs/cv.html"] [unique_id "aa8f7P8Z7mQVUgLQdJkAGQAAAB8"], referer: https://artbyrt.com/artbyrt_docs/cv.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-04-19 17:43:33
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/19/2025 5:43 pm (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2025-04-08 11:20:54
(1 year ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 4/8/2025 11:20 am (UTC-6)
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-04-05 17:43:05
(1 year ago)
WP Login Scan Activities
Web App Attack
Anonymous
2024-11-11 03:30:09
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
๐ฌ๐ง
UKFast Security
2022-02-28 23:46:12
(4 years ago)
WordPress XML RPC POST Brute Force Attack
Web App Attack
๐ฌ๐ง
UKFast Security
2022-02-25 16:50:01
(4 years ago)
WordPress XML RPC POST Brute Force Attack
Web App Attack
๐ฌ๐ง
UKFast Security
2022-02-20 18:30:04
(4 years ago)
WordPress XML RPC POST Brute Force Attack
Web App Attack