๐ฉ๐ช
ghostwarriors
2026-07-15 19:50:07
(1 month ago)
Unauthorized connection to FTP port 21
FTP Brute-Force
Brute-Force
Anonymous
2026-07-12 09:33:06
(1 month ago)
2026-07-12T11:17:58.705513+02:00 host.nilsbossaller.de sshd[2618107]: Connection closed by authentic ...
show more
2026-07-12T11:17:58.705513+02:00 host.nilsbossaller.de sshd[2618107]: Connection closed by authenticating user root 2a02:c207:2308:1246::1 port 41886 [preauth]
2026-07-12T11:33:03.808253+02:00 host.nilsbossaller.de sshd[2621496]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=2a02:c207:2308:1246::1 user=root
2026-07-12T11:33:05.674691+02:00 host.nilsbossaller.de sshd[2621496]: Failed password for root from 2a02:c207:2308:1246::1 port 47908 ssh2
...
show less
Brute-Force
SSH
๐ฉ๐ช
www.Examensfragen.de
2026-05-31 02:13:31
(3 months ago)
Web Spam
Bad Web Bot
Anonymous
2026-05-30 15:35:20
(3 months ago)
[31/May/2026:01:35:20 +1000] "GET /sitemap.xml HTTP/1.1" 404 236 "Mozilla/5.0 (X11; Linux x86_64; rv ...
show more
[31/May/2026:01:35:20 +1000] "GET /sitemap.xml HTTP/1.1" 404 236 "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
show less
Hacking
Web App Attack
๐จ๐ญ
rt
2026-05-28 06:17:12
(3 months ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ณ๐ฟ
nixnut
2026-05-28 02:44:00
(3 months ago)
Web Spam
Email Spam
๐ซ๐ฎ
wpwoodo
2026-05-27 09:53:26
(3 months ago)
Webpage crawler
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-26 21:15:51
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserve ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 17:15:45.981543 2026] [security2:error] [pid 12672:tid 12672] [client 2a02:c207:2308:1246::1:55554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.urlpick.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.urlpick.com"] [uri "/urlpick.com"] [unique_id "ahYNgQ_NQXTC2IWtqQ_L6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 20:37:47
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserve ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 16:37:43.504259 2026] [security2:error] [pid 10328:tid 10446] [client 2a02:c207:2308:1246::1:54926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adventistdeathconfusion.com|F|2"] [data ".deathconfusion.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adventistdeathconfusion.com"] [uri "/www.deathconfusion.com"] [unique_id "ahYEl499xI0rVfcpRkR2CAAAAlc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
filou812
2026-05-25 05:37:01
(3 months ago)
url tried is "/sitemap.xml"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 23:00:36
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserve ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 19:00:31.379802 2026] [security2:error] [pid 19538:tid 19538] [client 2a02:c207:2308:1246::1:47568] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rodrandolph.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rodrandolph.com"] [uri "/facebook.com"] [unique_id "ahDgD1mggmSShxvShCS3LwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-05-22 06:02:24
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -29.099 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -29.099 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 17_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Ve
show less
Web App Attack
Bad Web Bot
๐ต๐พ
armandosaucedo.me
2026-05-21 09:29:39
(3 months ago)
Threat Intelligence via ARMTI, Web Attack: GET /sitemap.xml
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 05:28:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 01:27:55.154556 2026] [security2:error] [pid 13533:tid 13533] [client 2a02:c207:2308:1246::1:48508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archief.org"] [uri "/bak.htaccess"] [unique_id "ag1GWyOnSo0VPVylCNIUqAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 00:05:56
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserve ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:c207:2308:1246::1 (vmi3081246.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 20:05:49.871945 2026] [security2:error] [pid 1190:tid 1190] [client 2a02:c207:2308:1246::1:55846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||flashbackmusicmemories.com|F|2"] [data ".40svocaltrio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "flashbackmusicmemories.com"] [uri "/www.40svocaltrio.com"] [unique_id "agz63WYNO9_rYT1ykcAP-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack