🇺🇸
TPI-Abuse
2026-09-08 21:49:06
(7 hours ago)
(mod_security) mod_security (id:243420) triggered by 2407:3640:2331:3601::1 (vmi3313601.contaboserve ...
show more
(mod_security) mod_security (id:243420) triggered by 2407:3640:2331:3601::1 (vmi3313601.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:49:01.494244 2026] [security2:error] [pid 2287:tid 2287] [client 2407:3640:2331:3601::1:55984] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6649"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||aifactoid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aifactoid.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aqCCyZ_y1P-8NZssxcN8PwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MarkGGN
2026-09-08 20:21:42
(8 hours ago)
Web attack. 2407:3640:2331:3601::1 - - [08/Sep/2026:22:21:41 +0200] "GET /api/v1/configs HTTP/1.1" 3 ...
show more
Web attack. 2407:3640:2331:3601::1 - - [08/Sep/2026:22:21:41 +0200] "GET /api/v1/configs HTTP/1.1" 301 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:30:39
(16 hours ago)
(mod_security) mod_security (id:243420) triggered by 2407:3640:2331:3601::1 (vmi3313601.contaboserve ...
show more
(mod_security) mod_security (id:243420) triggered by 2407:3640:2331:3601::1 (vmi3313601.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:30:34.749085 2026] [security2:error] [pid 7201:tid 7201] [client 2407:3640:2331:3601::1:46892] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||advantagesystemsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "advantagesystemsgroup.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ap__5DEkN6e5RRdMkUSejwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:35:48
(1 day ago)
(mod_security) mod_security (id:243420) triggered by 2407:3640:2331:3601::1 (vmi3313601.contaboserve ...
show more
(mod_security) mod_security (id:243420) triggered by 2407:3640:2331:3601::1 (vmi3313601.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:35:36.615213 2026] [security2:error] [pid 24506:tid 24506] [client 2407:3640:2331:3601::1:46208] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||3beeze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "3beeze.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ap715Vw-j2Gprub8eP2JcgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 06:53:42
(2 days ago)
(mod_security) mod_security (id:243420) triggered by 2407:3640:2331:3601::1 (vmi3313601.contaboserve ...
show more
(mod_security) mod_security (id:243420) triggered by 2407:3640:2331:3601::1 (vmi3313601.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 02:53:34.419233 2026] [security2:error] [pid 1535:tid 1547] [client 2407:3640:2331:3601::1:59902] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:redirect" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||colegiopiramide.edu.gt|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "colegiopiramide.edu.gt"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ap0N7TzxcZcE5R1eJ--DvgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 03:27:57
(3 days ago)
147 requests with url.path *sftp.json
138 requests with url.path *config.json
Brute-Force
Bad Web Bot
🇩🇪
MarkGGN
2026-09-06 03:18:35
(3 days ago)
Web attack. 2407:3640:2331:3601::1 - - [06/Sep/2026:05:18:33 +0200] "GET /.vscode/sftp.json HTTP/1.1 ...
show more
Web attack. 2407:3640:2331:3601::1 - - [06/Sep/2026:05:18:33 +0200] "GET /.vscode/sftp.json HTTP/1.1" 403 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
2407:3640:2331:3601::1 - - [06/Sep/2026:05:18:34 +0200] "GET /public/.vscode/sftp.json HTTP/1.1" 403 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Web App Attack
🇮🇩
origrata
2026-09-05 14:11:54
(3 days ago)
[OGWAF] bad_reputation attack on /jancox/alfacgiapi/bash.alfa (severity: high, hits: 4 in 7d)
Brute-Force
Hacking
🇮🇩
origrata
2026-09-05 14:11:54
(3 days ago)
[OGWAF] bad_reputation attack on /ERENUSE/py.Eren (severity: high, hits: 4 in 7d)
Brute-Force
Hacking
🇮🇩
origrata
2026-09-05 14:11:54
(3 days ago)
[OGWAF] bad_reputation attack on /ALFA_DATA/alfacgiapi/perl.alfa (severity: high, hits: 4 in 7d)
Brute-Force
Hacking
🇮🇩
origrata
2026-09-05 14:11:54
(3 days ago)
[OGWAF] bad_reputation attack on /ALFA_DATA/alfacgiapi/bash.alfa (severity: high, hits: 4 in 7d)
Brute-Force
Hacking
🇬🇧
openstrike.co.uk
2026-09-01 05:13:44
(1 week ago)
12 attacks on Alfa URLs:
GET /jancox/alfacgiapi/perl.alfa HTTP/1.1
Hacking
🇫🇷
Tilellit.PRO
2026-08-31 00:33:10
(1 week ago)
Web application probing for unlinked paths and hidden files
Web App Attack
Hacking
🇩🇪
filstal.org
2026-08-26 18:21:39
(1 week ago)
Bad bot activity detected (automated scraping/probing).
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-19 13:00:04
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack