π¦πΊ
MAGIC
2026-06-14 01:02:40
(4 days ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-13 06:45:46
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 216.73.217.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 216.73.217.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 02:45:38.590299 2026] [security2:error] [pid 18348:tid 18348] [client 216.73.217.174:47290] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pjvcds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pjvcds.com"] [uri "/wordpress/wp-json/wp/v2/users/1"] [unique_id "aiz8kst0LLG9x58fKuiaTQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Dorian GRANDHAY
2026-06-13 03:50:20
(4 days ago)
(PERMBLOCK) 216.73.217.174 (US/United States/-) has had more than 4 temp blocks in the last 604800 s ...
show more
(PERMBLOCK) 216.73.217.174 (US/United States/-) has had more than 4 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
πͺπΈ
masterguru
2026-06-12 05:47:08
(5 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-10 06:46:07
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 216.73.217.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 216.73.217.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 02:46:01.870268 2026] [security2:error] [pid 5867:tid 5867] [client 216.73.217.174:3421] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.srosa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.srosa.com"] [uri "/ srosa.com"] [unique_id "aikIKSm-Gi8Qryd7uC6jJQAAABo"], referer: http://www.srosa.com/%20srosa.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 04:56:04
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 216.73.217.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 216.73.217.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 00:56:00.028797 2026] [security2:error] [pid 14530:tid 14530] [client 216.73.217.174:6208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jamworldmovements.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jamworldmovements.com"] [uri "/jwr/zine/wc2000/Mailto:[email protected] "] [unique_id "aijuYNNdzayTNmQFMY5fMwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 22:06:09
(1 week ago)
Blocked: Reason='Suspicious traffic score=65 (review-based detection)'; Requests=28
Hacking
π«π·
Bruno
2026-06-09 21:47:01
(1 week ago)
216.73.217.174 - - [09/Jun/2026:23:25:13 +0200] "GET /robots.txt HTTP/1.1" 403 440 "-" "Mozilla/5.0 ...
show more
216.73.217.174 - - [09/Jun/2026:23:25:13 +0200] "GET /robots.txt HTTP/1.1" 403 440 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
216.73.217.174 - - [09/Jun/2026:23:25:16 +0200] "GET /index.php/2007/01/03/409-les-chevaliers-du-subjonctif-erik-orsenna HTTP/1.1" 403 439 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
216.73.217.174 - - [09/Jun/2026:23:35:33 +0200] "GET /index.php/2006/03/15/234-l-art-de-la-joie-goliarda-sapienza HTTP/1.1" 403 440 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
216.73.217.174 - - [09/Jun/2026:23:39:49 +0200] "GET /robots.txt HTTP/1.1" 403 440 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
216.73.217.174 - - [09/Jun/2026:23:39:54 +0200] "GET /index.php/post/2008/05/02/Le-fils-de-lhomme-invisible-Francois-Berlea
...
show less
Web App Attack
π¨π
rt
2026-06-07 08:32:18
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
π©πͺ
mwgbr
2026-06-05 20:00:20
(1 week ago)
(PERMBLOCK) 216.73.217.174 (US/United States/-) has had more than 4 temp blocks
Hacking
π©πͺ
mwgbr
2026-06-05 16:40:10
(1 week ago)
216.73.217.174 (US/United States/-), more than 10 Apache 403 hits
Hacking
πΊπΈ
TPI-Abuse
2026-06-03 14:48:25
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 216.73.217.174 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 216.73.217.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 10:48:20.350038 2026] [security2:error] [pid 12834:tid 12842] [client 216.73.217.174:29616] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.peterhansenranch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.peterhansenranch.com"] [uri "/GGsCookbook/wp-json/wp/v2/users/1"] [unique_id "aiA-tNGeimRrYMuoACT15QAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Viveronese
2026-06-02 03:41:13
(2 weeks ago)
HTTP vulnerability scanning
Web App Attack
π¨πΏ
ptlab
2026-06-01 16:45:06
(2 weeks ago)
Detected php_null_array_access attack from WP-host.
Hacking
Web App Attack
π©πͺ
filstal.org
2026-05-31 21:00:03
(2 weeks ago)
Unauthorized web crawling by known aggressive crawler or data harvesting bot detected by Fail2Ban
Bad Web Bot