๐ฉ๐ช
maxpower
2026-10-03 17:32:04
(17 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 206.232.75.66 (JP/Japan/-): 1 in the las ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 206.232.75.66 (JP/Japan/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 206.232.75.66 - - [03/Oct/2026:19:32:03 +0200] "GET /aws/credentials.json HTTP/1.1" 200 12016 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" "-" host=keyprint.com.br
show less
Port Scan
๐บ๐ธ
myagent.site
2026-03-06 05:28:18
(6 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐บ๐ธ
Mundo Bueno
2026-03-06 00:34:11
(6 months ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /xmlrpc.php | Pays: JP | UA: Mozilla/5.0 (Windows NT 10. ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /xmlrpc.php | Pays: JP | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0
show less
Hacking
Web App Attack
๐ฉ๐ช
webanyone
2026-03-01 22:00:37
(7 months ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 12:29:06
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 07:29:00.367781 2026] [security2:error] [pid 483:tid 664] [client 206.232.75.66:50997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.kettlehill.com"] [uri "/api/.env"] [unique_id "aX9HDAMxl-cQ0UzvOvSdBQAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 06:35:22
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 01:35:13.959750 2026] [security2:error] [pid 2629:tid 2629] [client 206.232.75.66:53213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nbcnewsradio.com"] [uri "/.env.bak"] [unique_id "aWncIcuiZxR8JCLIVW5N5wAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 06:18:13
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 01:18:10.349510 2025] [security2:error] [pid 12048:tid 12048] [client 206.232.75.66:49267] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".nbcnewsradio.com.key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/ftp.nbcnewsradio.com.key"] [unique_id "aRQmojlK8y7FwnYigGLUAAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 14:42:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 10:42:32.930287 2025] [security2:error] [pid 17241:tid 17252] [client 206.232.75.66:37005] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.kettlehill.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.kettlehill.com"] [uri "/admin/log/error.log"] [unique_id "aN092Kh4GLz6vZLSqBypjgAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-05 23:32:42
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 19:32:39.469530 2025] [security2:error] [pid 27948:tid 27948] [client 206.232.75.66:42069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nbcnewsradio.com"] [uri "/_.htaccess"] [unique_id "aJKUl8vKO3_yycs-TgE9MwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-01 06:59:53
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 02:59:48.179244 2025] [security2:error] [pid 3332372:tid 3332394] [client 206.232.75.66:38287] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.kettlehill.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.kettlehill.net"] [uri "/php_errors.log"] [unique_id "aIxl5B33aKcnOojmIbhfJAAAApQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 06:56:12
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 02:56:08.883046 2025] [security2:error] [pid 2749697:tid 2749800] [client 206.232.75.66:54039] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.kettlehill.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.kettlehill.net"] [uri "/errors.log"] [unique_id "aDv5iGzUxJS8AZi9Bz3VQwAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-01 02:20:02
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-28 19:22:31
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 206.232.75.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 28 15:22:25.094971 2025] [security2:error] [pid 1773455:tid 1773455] [client 206.232.75.66:41633] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||autodiscover.farmers123.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "autodiscover.farmers123.com"] [uri "/index.php"] [unique_id "aDdicVg9XfiJKmD5yj447QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack