๐ณ๐ฑ
Mangelot Hosting
2025-08-30 09:24:17
(9 months ago)
(modsecurity) srv101 ModSecurity 2a00:1b88:4::4 (Unknown): 5 in the last 3600 secs; Ports: *; Direct ...
show more
(modsecurity) srv101 ModSecurity 2a00:1b88:4::4 (Unknown): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
MarkGGN
2025-08-29 21:34:58
(9 months ago)
Webexploits. 2a00:1b88:4::4 - - [29/Aug/2025:23:34:51 +0200] "GET /wp-config.php.zip HTTP/2.0" 444 0 ...
show more
Webexploits. 2a00:1b88:4::4 - - [29/Aug/2025:23:34:51 +0200] "GET /wp-config.php.zip HTTP/2.0" 444 0 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB5; FBSMTWB; BTRS26718; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618; .NET4.0C; BRI/1)"
2a00:1b88:4::4 - - [29/Aug/2025:23:34:57 +0200] "GET /mysql.zip HTTP/2.0" 301 0 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB5; FBSMTWB; BTRS26718; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30618; .NET4.0C; BRI/1)"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-27 00:53:55
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 26 20:53:49.295250 2025] [security2:error] [pid 31966:tid 31966] [client 2a00:1b88:4::4:52488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integrabroadcast.com"] [uri "/wp-config.php.zip"] [unique_id "aK5XHfA7jXmCI61-Lyn0pgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-08-24 18:59:29
(10 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ง๐ช
cmbplf
2025-08-22 12:01:00
(10 months ago)
785 limiting connections by zone (1h39m59sfromnow)
DDoS Attack
๐ฉ๐ช
on-com
2025-08-10 22:45:48
(10 months ago)
URL scan
Brute-Force
Web App Attack
๐ฉ๐ช
CommanderRoot
2025-08-10 18:57:27
(10 months ago)
Bot crawler
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-08-09 19:12:21
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 09 15:12:16.215844 2025] [security2:error] [pid 24794:tid 24794] [client 2a00:1b88:4::4:58396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||inquisitivequincie.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "inquisitivequincie.com"] [uri "/uincie.sql"] [unique_id "aJedkKFMqPndwHspXbevgwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-08-06 09:10:13
(10 months ago)
619 limiting connections by zone (10m59sfromnow)
DDoS Attack
๐ฌ๐ง
SuperEvilLuke
2025-08-05 18:59:25
(10 months ago)
Malicious activity detected from 29075 IELO IELO Main Network towards host panel.embotic.xyz (GET HT ...
show more
Malicious activity detected from 29075 IELO IELO Main Network towards host panel.embotic.xyz (GET HTTP/2) @ 2025-08-05T18:59:25Z (3 occurrences)
show less
DDoS Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-08-03 21:59:24
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 03 17:59:17.243805 2025] [security2:error] [pid 18230:tid 18230] [client 2a00:1b88:4::4:40878] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.goglobex.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.goglobex.com"] [uri "/wordpress.sql"] [unique_id "aI_btSg1ie7svmCNrVVGkgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-03 21:37:08
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 03 17:37:02.629154 2025] [security2:error] [pid 9217:tid 9217] [client 2a00:1b88:4::4:40510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hpepaper.com"] [uri "/.git/config"] [unique_id "aI_Wfv2nG7ezhh_FwQe-OAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2025-07-30 18:12:21
(10 months ago)
GET /admin.php HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-28 19:57:03
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 28 15:57:00.240207 2025] [security2:error] [pid 2700615:tid 2700634] [client 2a00:1b88:4::4:42696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pecanvalleyestates.net"] [uri "/.git/config"] [unique_id "aIfWDNfkvJ0VO4DBd2Mr9gAAAc4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 07:10:04
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a00:1b88:4::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 27 03:09:55.729258 2025] [security2:error] [pid 7540:tid 7540] [client 2a00:1b88:4::4:50084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hshr.com"] [uri "/.git/config"] [unique_id "aIXQw7UNepZelwDxHQ28WgAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack