๐ซ๐ท
bigorre.org
2026-06-15 14:58:11
(1 week ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-05-27 22:01:14
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-05-27
Web App Attack
SSH
Hacking
๐ซ๐ท
masterguru
2026-05-27 13:35:01
(3 weeks ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 23.94.138.208 (US/United States/23-94 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 23.94.138.208 (US/United States/23-94-138-208-host.colocrossing.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 00:24:11
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:24:04.501442 2026] [security2:error] [pid 15090:tid 15090] [client 23.94.138.208:35379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photoboutiqueamerica.com"] [uri "/app/config/parameters.yml"] [unique_id "ahY5pGhlLBXnymo9iUA6FwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 23:55:34
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing. ...
show more
(mod_security) mod_security (id:210730) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 19:55:25.150375 2026] [security2:error] [pid 32699:tid 32699] [client 23.94.138.208:45783] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sharperform.dppc.studio|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sharperform.dppc.studio"] [uri "/db_backup.sql"] [unique_id "ahYy7ed5M8ig9kpfrFHG9QAAAAY"], referer: https://www.google.com/search?q=sharperform.dppc.studio
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 17:55:01
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:54:54.865846 2026] [security2:error] [pid 23597:tid 23597] [client 23.94.138.208:42059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stonetarot.com"] [uri "/.env.bak"] [unique_id "ahXebvls7HRUkcmKxlExdgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 07:55:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 02:54:47.898947 2026] [security2:error] [pid 22997:tid 22997] [client 23.94.138.208:43591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.cpcalendars"] [unique_id "aWtAR2kl5JHTtQN4f2iHIgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
[email protected]
2025-12-29 04:46:23
(5 months ago)
Attack attempt against Interwebbi servers; *Port Scan* detected from 23.94.138.208 (US/United States ...
show more
Attack attempt against Interwebbi servers; *Port Scan* detected from 23.94.138.208 (US/United States/23-94-138-208-host.colocrossing.com). 5 hits in the last 371 seconds; IP: 23.94.138.208; Ports: *; Direction: 0; Trigger: PS_LIMIT;
show less
Brute-Force
Anonymous
2025-08-20 01:35:07
(10 months ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-26 23:13:59
(10 months ago)
(mod_security) mod_security (id:221260) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing. ...
show more
(mod_security) mod_security (id:221260) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 19:08:19.999625 2025] [security2:error] [pid 19500:tid 19512] [client 23.94.138.208:36497] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.kettlehill.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/"] [unique_id "aIVf4y-82AcwFY0KVGEYWAAAAEY"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
PulseServers
2025-06-03 10:18:58
(1 year ago)
Probing a honeypot for vulnerabilities. Ignored robots.txt - UK10 Honeypot
...
Hacking
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-06-03 09:58:39
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 00:37:05
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing. ...
show more
(mod_security) mod_security (id:211190) triggered by 23.94.138.208 (23-94-138-208-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 20:36:58.732801 2025] [security2:error] [pid 3852931:tid 3852931] [client 23.94.138.208:52609] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.farmers123.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?op=fileviewer&file=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.farmers123.com"] [uri "/index.php"] [unique_id "aDj9qmJO40wr11RzwBQbMAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-15 02:50:27
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
oncord
2024-06-05 04:39:19
(2 years ago)
Form spam
Web Spam