๐ฉ๐ช
big-cloud.nl
2026-05-26 22:45:09
(1 week ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 22:33:34
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 18:33:26.106293 2026] [security2:error] [pid 28892:tid 28892] [client 38.135.25.97:38622] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kairoslogammakmur.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kairoslogammakmur.com"] [uri "/dump.sql"] [unique_id "ahYftj6W90e9HEYXO_Z6ZAAAAAw"], referer: kairoslogammakmur.com/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-05-26 20:30:26
(1 week ago)
Form spam
Web Spam
๐ฉ๐ช
Carsten
2026-05-26 12:06:04
(1 week ago)
HEAD [dump.sql]
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-26 06:21:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 02:21:44.506314 2026] [security2:error] [pid 1087:tid 1087] [client 38.135.25.97:60200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.allotrope.com"] [uri "/.git/config"] [unique_id "ahU7-C1QqW94Ez1sTjtwMwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 23:20:18
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 19:20:15.020591 2026] [security2:error] [pid 11820:tid 11820] [client 38.135.25.97:49128] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||understory.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "understory.us"] [uri "/dump.sql"] [unique_id "ahTZL-UEYZXR6Jpq9azQtwAAABI"], referer: understory.us/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 20:09:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 38.135.25.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 16:09:03.337969 2026] [security2:error] [pid 2239:tid 2253] [client 38.135.25.97:60082] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stratifiedstudios.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stratifiedstudios.com"] [uri "/dump.sql"] [unique_id "ahSsXxFSiWX9pAtHqqr58QAAAEo"], referer: stratifiedstudios.com/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
MatStef132
2026-05-21 15:51:13
(1 week ago)
MatShield L7: blocked on mathost.eu (ua-quarantined)
Bad Web Bot
๐ณ๐ฑ
MatStef132
2026-05-19 20:23:15
(2 weeks ago)
MatShield L7: blocked on chat.justchat.icu (suspicious behaviour)
DDoS Attack
Anonymous
2026-05-18 07:12:26
(2 weeks ago)
[Drupal AbuseIPDB module] form spam
Web App Attack
๐ฉ๐ช
F242
2026-05-16 19:34:18
(2 weeks ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฎ๐น
[email protected]
2026-05-16 01:32:48
(2 weeks ago)
[Sat May 16 03:32:40.148072 2026] [authz_core:error] [pid 716011:tid 716063] [remote 38.135.25.97:55 ...
show more
[Sat May 16 03:32:40.148072 2026] [authz_core:error] [pid 716011:tid 716063] [remote 38.135.25.97:55070] AH01630: client denied by server configuration: /var/www/html/MyWeb/Wordpress_www/wp-login.php
show less
Brute-Force
Web App Attack
๐ซ๐ท
EDSL
2026-05-15 01:06:49
(2 weeks ago)
[mail.edsl.fr] Blocked by SysWarden Firewall (Web Attack Port 80)
Web App Attack
Hacking
Port Scan
๐ฌ๐ง
relianoid.com
2026-05-14 21:37:04
(2 weeks ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam
๐ฉ๐ช
FeG Deutschland
2026-05-14 07:07:39
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack