|
๐ณ๐ฟ
Antinson
|
|
Scraping with a high error ratio and request rate
|
Bad Web Bot
|
|
|
๐ซ๐ท
dynamix
|
|
WordPress XMLRPC Brute Force Attack
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=15
|
Hacking
|
|
|
๐บ๐ธ
ipblock.com
|
|
IPBlock protected site ID [4055-d][s=03].
Exploit request, vulnerability scanner.
|
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
Baking333
|
|
[redacted] 37.77.56.147 - - [19/Mar/2026:03:39:30 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" ...
show more
[redacted] 37.77.56.147 - - [19/Mar/2026:03:39:30 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" 302 5277 0/63411 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" [redacted] 37.77.56.147 - - [19/Mar/2026:03:39:38 +0100] "GET /[redacted]?rsd HTTP/1.1" 302 1549 0/40579 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 02:33:36.647462 2026] [security2:error] [pid 12438:tid 12438] [client 37.77.56.147:25817] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jussetcotradinglimited.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jussetcotradinglimited.co"] [uri "/backups/www.sql"] [unique_id "abekQOE_xk3nRnuwlNLQWwAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 10:31:53.145931 2026] [security2:error] [pid 27621:tid 27621] [client 37.77.56.147:52779] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lundtrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lundtrading.com"] [uri "/backups/dump.sql"] [unique_id "abF82baCRfiwlYj816v7VAAAABo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ต๐พ
armandosaucedo.me
|
|
37.77.56.147 - - [10/Mar/2026:21:29:24 +0000] "GET /bak/bak.gz HTTP/1.1" 404 196 "-" "-"
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 20:28:06.984565 2026] [security2:error] [pid 17163:tid 17163] [client 37.77.56.147:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eddysgroup.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eddysgroup.com"] [uri "/backups/backup.sql"] [unique_id "aaDzJkiMvayVD2fLRjeY3QAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
itsolon
|
|
[26/Feb/2026:15:15:00 +0100] 177211530089.453218 37.77.56.147 30083 217.154.7.177 80
[26/Feb/2026:15 ...
show more
[26/Feb/2026:15:15:00 +0100] 177211530089.453218 37.77.56.147 30083 217.154.7.177 80
[26/Feb/2026:15:15:02 +0100] 177211530283.134423 37.77.56.147 64695 217.154.7.177 80
[26/Feb/2026:15:15:04 +0100] 177211530444.060291 37.77.56.147 64273 217.154.7.177 80
...
show less
|
Port Scan
Hacking
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 09:12:44.286366 2026] [security2:error] [pid 23663:tid 23663] [client 37.77.56.147:47965] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||powderriverinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "powderriverinc.com"] [uri "/bak/www.sql"] [unique_id "aaBU3GNcrk4xjU0h7w74MQAAABk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฏ๐ต
Valhalla
|
|
/config.js
|
Hacking
Web App Attack
|
|
|
๐ฉ๐ช
bescared
|
|
F2B - Malicious activity detected. URL Probing.
|
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 37.77.56.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 03:00:37.168045 2026] [security2:error] [pid 12055:tid 12055] [client 37.77.56.147:23507] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dudleyanddudley.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dudleyanddudley.com"] [uri "/backup/wallet.dat"] [unique_id "aZArpWzOw-zy9lMdRdkz6AAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
BlueWire Hosting
|
|
Suspicious HTTP(s) activity without a user agent provided
|
Bad Web Bot
|
|