๐ฉ๐ช
big-cloud.nl
2026-07-30 18:41:22
(3 hours ago)
Try to access /https://meneerdekok.nl/xmlrpc.php?rsd
Web App Attack
๐ฉ๐ช
LRob
2026-07-30 02:10:09
(19 hours ago)
CrowdSec: crowdsecurity/http-probing | req: /https://www.atce-energies.com/feed/ | 11 distinct paths ...
show more
CrowdSec: crowdsecurity/http-probing | req: /https://www.atce-energies.com/feed/ | 11 distinct paths | UA: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.8) Gecko/20100214 Ubuntu/9.10 (karmic) Firefox/3.5.8
show less
Port Scan
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-23 18:41:24
(1 week ago)
Try to access /https://meneerdekok.nl/xmlrpc.php?rsd
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 04:50:45
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 00:50:36.509959 2026] [security2:error] [pid 2318683:tid 2318683] [client 207.127.94.142:43298] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.solcargomiami.com|F|2"] [data ".arpiximagepro.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.solcargomiami.com"] [uri "/https:/www.arpiximagepro.com"] [unique_id "amGdnJ9eAW2whNJN_dV7YAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-23 02:10:07
(1 week ago)
CrowdSec: crowdsecurity/http-probing | req: /https://www.atce-energies.com/feed/ | 11 distinct paths ...
show more
CrowdSec: crowdsecurity/http-probing | req: /https://www.atce-energies.com/feed/ | 11 distinct paths | UA: Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1667.0 Safari/537.36
show less
Port Scan
Web App Attack
Anonymous
2026-07-21 07:20:02
(1 week ago)
Malicious activity detected
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-16 18:40:20
(2 weeks ago)
Try to access /https://meneerdekok.nl/xmlrpc.php
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-16 02:48:57
(2 weeks ago)
cloudlinux2 fail2ban: 2026-07-16 04:44:02,477 fail2ban.filter [1812]: INFO [plesk-apache] ...
show more
cloudlinux2 fail2ban: 2026-07-16 04:44:02,477 fail2ban.filter [1812]: INFO [plesk-apache] Found 54.149.186.213 - 2026-07-16 04:44:02cloudlinux2 fail2ban: 2026-07-16 04:44:19,031 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.214.232 - 2026-07-16 04:44:18cloudlinux2 fail2ban: 2026-07-16 04:44:14,887 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.214.232 - 2026-07-16 04:44:13cloudlinux2 fail2ban: 2026-07-16 04:46:58,801 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 137.184.209.151 - 2026-07-16 04:46:56cloudlinux2 fail2ban: 2026-07-16 04:46:58,633 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 137.184.209.151 - 2026-07-16 04:46:56cloudlinux2 fail2ban: 2026-07-16 04:46:59,744 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 216.73.163.178 - 2026-07-16 04:46:58cloudlinux2 fail2ban: 2026-07-16 04:47:09,043 fail2ban.filter [1812]: INFO [plesk-modsecurity] Found 207.127.94.142 - 2026-07-16 04:47:0
show less
Web App Attack
๐ฉ๐ช
LRob
2026-07-16 02:10:08
(2 weeks ago)
CrowdSec: crowdsecurity/http-probing | req: /https://www.atce-energies.com/feed/ | 11 distinct paths ...
show more
CrowdSec: crowdsecurity/http-probing | req: /https://www.atce-energies.com/feed/ | 11 distinct paths | UA: Mozilla/5.0 (compatible; Konqueror/4.3; Linux) KHTML/4.3.2 (like Gecko)
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 20:47:47
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 16:47:42.780606 2026] [security2:error] [pid 9026:tid 9026] [client 207.127.94.142:33990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.primelb.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.primelb.com"] [uri "/https:/directnic.com"] [unique_id "alfx7nj2Tmq6d69QcMfBfAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 20:16:10
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 16:16:03.502843 2026] [security2:error] [pid 21361:tid 21361] [client 207.127.94.142:47674] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.maffiniandbearce.com|F|2"] [data ".maffiniandbearce.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.maffiniandbearce.com"] [uri "/https:/www.maffiniandbearce.com"] [unique_id "alfqg0SO5Prx6mzp6Ui8RQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-07-12 15:08:11
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /https://onlinetours.es/es/casas/casas.htm | Evid ...
show more
Web scanning / probing for vulnerable paths | URL: /https://onlinetours.es/es/casas/casas.htm | Evidence: onlinetours.es 207.127.94.142 - - [12/Jul/2026:17:07:10 +0200] \"GET /https://onlinetours.es/es/casas/casas.htm HTTP/1.1\" 404 51355 \"-\" \"Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/[internal_ip] Safari/534.16\" GEOIP_COUNTRY_CODE=SE | ASN: ORACLE-BMC-31898 | Country: SE
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 03:41:15
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 23:41:09.373237 2026] [security2:error] [pid 8490:tid 8490] [client 207.127.94.142:43900] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.insua.com|F|2"] [data ".googleapis.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.insua.com"] [uri "/https:/fonts.googleapis.com"] [unique_id "alMM1ZUARdBRPTadLfk8sAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-12 02:13:43
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-11 12:35:17
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 207.127.94.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 08:35:09.842424 2026] [security2:error] [pid 8721:tid 8721] [client 207.127.94.142:35216] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.1214productions.com|F|2"] [data ".zodiacgate.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.1214productions.com"] [uri "/https:/www.zodiacgate.com"] [unique_id "alI4fUNOuhjQNb_UAqAERAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack