๐ฉ๐ช
AetherFox
2026-08-18 18:11:46
(1 week ago)
AetherFox VoidGuard detected: [Tue Aug 18 18:11:18.789266 2026] [authz_core:error] [pid 2167264:tid ...
show more
AetherFox VoidGuard detected: [Tue Aug 18 18:11:18.789266 2026] [authz_core:error] [pid 2167264:tid 2167302] [client 41.220.17.62:47114] AH01630: client denied by server configuration: proxy:http://[MASKED]/ucp.php, referer: http://ikosa-dragons.de/ucp.php?mode=register&sid=6cd56f41a3550cb3479e8b9905656a2b
[Tue Aug 18 18:11:18.789497 2026] [authz_core:error] [pid 2167264:tid 2167302] [client 41.220.17.62:47114] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html, referer: http://ikosa-dragons.de/ucp.php?mode=register&sid=6cd56f41a3550cb3479e8b9905656a2b
[Tue Aug 18 18:11:45.026024 2026] [authz_core:error] [pid 2167263:tid 2167282] [client 41.220.17.62:40938] AH01630: client denied by server configuration: proxy:http://[MASKED]/ucp.php, referer: http://ikosa-dragons.de/ucp.php?mode=register&sid=6cd56f41a3550cb3479e8b9905656a2b
[Tue Aug 18 18:11:45.026276 2026] [authz_core:error] [pid 2167263:tid 2167282] [client 41.220.17.62:40938]
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
mikekarl
2026-08-10 18:58:07
(2 weeks ago)
SQL INJECTION Hi, It seems golf-4-all.de could be bringing in more visitors and turning more of thos ...
show more
SQL INJECTION Hi, It seems golf-4-all.de could be bringing in more visitors and turning more of those visitors into customers.
Want the details? Simply reply "YES" and I''ll get it over to you today.
To unsubscribe, please reply with subject: Unsubscribe !golf-4-all.de
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-05 20:01:45
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 41.220.17.62 (16.62.telone.co.zw): 1 in the las ...
show more
(mod_security) mod_security (id:210730) triggered by 41.220.17.62 (16.62.telone.co.zw): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 16:01:39.109184 2026] [security2:error] [pid 31310:tid 31333] [client 41.220.17.62:58158] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iamfluff.com|F|2"] [data ".iamfluff.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iamfluff.com"] [uri "/ftp:/ftp.iamfluff.com"] [unique_id "anOWo8hlTLPVM-sV1nx1tQAAARE"], referer: http://iamfluff.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-07-24 23:06:09
(1 month ago)
requested honeypot page - ignored robots.txt - scraping botnet or virus
...
Bad Web Bot
Exploited Host
๐บ๐ธ
gu-alvareza
2026-07-22 07:05:43
(1 month ago)
WordPress.xmlrpc.Pingback.DoS
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 02:40:43
(1 month ago)
(mod_security) mod_security (id:217280) triggered by 41.220.17.62 (16.62.telone.co.zw): 1 in the las ...
show more
(mod_security) mod_security (id:217280) triggered by 41.220.17.62 (16.62.telone.co.zw): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 22:40:38.217207 2026] [security2:error] [pid 222673:tid 222673] [client 41.220.17.62:40992] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||www.johnprimerano.com|F|2"] [data "Matched Data: get found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.johnprimerano.com"] [uri "/contact.html"] [unique_id "amAtppLpTEWS5BqglaooQwAAABM"], referer: http://www.johnprimerano.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mehmet_The_Script_Kiddie
2026-07-21 14:12:11
(1 month ago)
CloudFlare WAF REPORT: /wp-login.php
Bad Web Bot
Web App Attack
๐ซ๐ท
RootOPSOVH
2026-07-17 04:42:21
(1 month ago)
GET /admin | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Ch ...
show more
GET /admin | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 YaBrowser/26.3.0.0 Safari/537.36
show less
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
R.G.
2026-07-13 20:35:04
(1 month ago)
(XMLRPCorWHATEVER) Get lost please 41.220.17.62 (ZW/Zimbabwe/16.62.telone.co.zw): 3 in the last 900 ...
show more
(XMLRPCorWHATEVER) Get lost please 41.220.17.62 (ZW/Zimbabwe/16.62.telone.co.zw): 3 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ซ๐ท
RootOPSOVH
2026-07-12 16:48:24
(1 month ago)
GET /admin | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Ch ...
show more
GET /admin | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.36
show less
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-06-26 18:40:03
(1 month ago)
| [Dangerous/Zimbabwe] Aggressive IP 41.220.17.62 (~30 hits). Type: DoS Defender- Web server 400 err ...
show more
| [Dangerous/Zimbabwe] Aggressive IP 41.220.17.62 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
AetherFox
2026-06-25 10:55:05
(2 months ago)
AetherFox VoidGuard detected: [Thu Jun 25 10:54:48.744579 2026] [authz_core:error] [pid 2159075:tid ...
show more
AetherFox VoidGuard detected: [Thu Jun 25 10:54:48.744579 2026] [authz_core:error] [pid 2159075:tid 2159089] [client 41.220.17.62:57382] AH01630: client denied by server configuration: proxy:http://[MASKED]/, referer: http://draconigen.net/
[Thu Jun 25 10:54:48.744778 2026] [authz_core:error] [pid 2159075:tid 2159089] [client 41.220.17.62:57382] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html, referer: http://draconigen.net/
[Thu Jun 25 10:54:54.623024 2026] [authz_core:error] [pid 2159075:tid 2159085] [client 41.220.17.62:57396] AH01630: client denied by server configuration: proxy:http://[MASKED]/, referer: http://draconigen.net/
[Thu Jun 25 10:54:54.623284 2026] [authz_core:error] [pid 2159075:tid 2159085] [client 41.220.17.62:57396] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html, referer: http://draconigen.net/
[Thu Jun 25 10:55:04.929048 2026] [authz_core:error] [pid 2159075:tid 2159090]
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-06-21 18:46:18
(2 months ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
Anonymous
2026-05-30 00:46:33
(2 months ago)
"GET /.aws/credentials HTTP/1.1"
Hacking
Web App Attack
๐ซ๐ท
Security_Whaller
2026-05-30 00:40:15
(2 months ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack