๐บ๐ธ
mnsf
2026-05-21 07:06:38
(1 month ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 16:33:45
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 31.134.3.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.3.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:33:42.110711 2026] [security2:error] [pid 26694:tid 26702] [client 31.134.3.250:45819] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gabegabel.com"] [uri "/wp-config.php.save"] [unique_id "ag3iZj6I9K63VkkSTgj6PwAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 12:57:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 31.134.3.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.3.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:57:05.754733 2026] [security2:error] [pid 7378:tid 7378] [client 31.134.3.250:34219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonesband.com"] [uri "/wp-config.php.orig"] [unique_id "ag2voXnndVho6jykhjQxDwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 12:40:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 31.134.3.250 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.134.3.250 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:40:08.449693 2026] [security2:error] [pid 4797:tid 4797] [client 31.134.3.250:21195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vintageamptubes.ink2wear.com"] [uri "/wp-config.php.dist"] [unique_id "ag2rqJeKHbNgL5D_A2kQwwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-05-19 13:08:59
(1 month ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 31.134.3.250 (SC/Seychelles/-): 1 in the last ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 31.134.3.250 (SC/Seychelles/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 31.134.3.250 - - [19/May/2026:16:07:53 +0300] "HEAD /wp-login.php HTTP/1.1" 200 0 "-" "Go-http-client/1.1"
show less
Port Scan
๐บ๐ธ
stechusa
2026-05-06 14:41:57
(1 month ago)
ELEVATED_THREAT | country=SC | ASN=Fast Servers (Pty) Ltd | AbuseIPDB=10% | 15 IPs targeting /catego ...
show more
ELEVATED_THREAT | country=SC | ASN=Fast Servers (Pty) Ltd | AbuseIPDB=10% | 15 IPs targeting /category/transformers-low-voltage.html | Facet request during elevated threat (facet_ratio=0.74, unique_ips=62) | HTTP/1.1 over TLS (elevated=True)
show less
Bad Web Bot
DDoS Attack
๐บ๐ธ
stechusa
2026-05-06 14:41:57
(1 month ago)
[Askari] | country=SC | Behavior: Concurrent page load during attack, No referrer on deep pages, HTT ...
show more
[Askari] | country=SC | Behavior: Concurrent page load during attack, No referrer on deep pages, HTTP/1.1 over TLS, Targeting specific pages
show less
Bad Web Bot
DDoS Attack
๐ซ๐ท
dynamix
2026-04-17 03:19:21
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
sssrit
2026-04-15 11:08:31
(2 months ago)
31.134.3.250 - - [15/Apr/2026:13:08:30 +0200] "GET /wp-content/mu-plugins/ HTTP/1.1" 403 548 "-" "Mo ...
show more
31.134.3.250 - - [15/Apr/2026:13:08:30 +0200] "GET /wp-content/mu-plugins/ HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-01-20 04:43:36
(5 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2026.01.20 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2026.01.20 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-09 20:07:45
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.09 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.09 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-09-08 05:01:42
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH