๐ณ๐ฑ
melroy89
2026-04-01 20:22:22
(4 months ago)
31.58.32.170 - - [01/Apr/2026:21:59:41 +0200] "GET /m/[email protected] /t/583841/-/comment/5040987 ...
show more
31.58.32.170 - - [01/Apr/2026:21:59:41 +0200] "GET /m/[email protected] /t/583841/-/comment/5040987 HTTP/1.1" 302 282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36" "kbin.melroy.org" 0.018
...
show less
DDoS Attack
๐ฉ๐ช
HandyTreff.de
2026-01-31 20:09:41
(6 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -41.431 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -41.431 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 18:32:33
(7 months ago)
(mod_security) mod_security (id:211190) triggered by 31.58.32.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 31.58.32.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:32:30.397333 2025] [security2:error] [pid 25028:tid 25049] [client 31.58.32.170:56713] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?p=3232&wp_automatic=download&link=file:///etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/"] [unique_id "aVLJPnoCEO1cw_Cklcin3AAAAcs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 11:03:55
(9 months ago)
(mod_security) mod_security (id:212750) triggered by 31.58.32.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212750) triggered by 31.58.32.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 06:03:51.940639 2025] [security2:error] [pid 32198:tid 32198] [client 31.58.32.170:56821] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: onload= found within REQUEST_URI: /control/stream?contentid='\\x5c\\x22><svg/onload=alert(/xss/)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "ftp.nbcnewsradio.com"] [uri "/control/stream"] [unique_id "aRW7FxvDVCbKxYhUzjefyAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-10-13 03:23:20
(10 months ago)
query: option=com_jcollection&controller=../../../../../../../etc/passwd%00
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-27 00:22:50
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 31.58.32.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.58.32.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:22:44.776624 2025] [security2:error] [pid 172499:tid 172612] [client 31.58.32.170:35959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.com"] [uri "/.env.www"] [unique_id "aIVxVIEn7YGnahfIo_jKoAAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-07-25 11:20:05
(1 year ago)
IP was involved in L7 DDoS attack.
DDoS Attack
Anonymous
2025-07-01 13:20:01
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
Anonymous
2025-06-23 13:16:24
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH