๐ง๐ท
ICS Labs
2026-07-16 01:06:44
(2 months ago)
ICS Labs identified 5.255.117.134 as a malicious indicator from threat intelligence.
Hacking
๐ซ๐ฎ
nNordic
2026-06-09 10:16:03
(3 months ago)
Connection attempt blocked by IDS/IPS from 5.255.117.134/32
Hacking
๐ฉ๐ช
MusicLibrary
2026-06-02 12:55:56
(4 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-31 20:35:46
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 16:35:41.081748 2026] [security2:error] [pid 7237:tid 7237] [client 5.255.117.134:55300] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dianadelapava.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dianadelapava.com"] [uri "/dump.sql"] [unique_id "ahybnYFwlsLqmLFTZOOc5AAAAAM"], referer: dianadelapava.com/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-05-27 13:45:20
(4 months ago)
Plesk panel login attempt with forbidden username (root/admin), blocked by Fail2Ban in custom-plesk- ...
show more
Plesk panel login attempt with forbidden username (root/admin), blocked by Fail2Ban in custom-plesk-login jail
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 07:42:07
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 03:41:58.916595 2026] [security2:error] [pid 23731:tid 23731] [client 5.255.117.134:34878] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shannonraevocalstudio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shannonraevocalstudio.com"] [uri "/dump.sql"] [unique_id "ahagRr4UUwgSCOpG9xGTQwAAABA"], referer: shannonraevocalstudio.com/dump.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-19 15:40:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 11:40:07.178177 2026] [security2:error] [pid 14069:tid 14184] [client 5.255.117.134:44526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.anointedtour.com"] [uri "/.git/config"] [unique_id "agyEVw0R1BsnHMU3-2ZMtAAAAkY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-05-13 08:14:13
(4 months ago)
[URL BRUTE-FROCE] >50 404 in <1 min
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
ICS Labs
2026-05-12 01:29:29
(4 months ago)
ICS Labs identified 5.255.117.134 as a malicious indicator from threat intelligence.
Hacking
๐ซ๐ท
marc
2026-05-11 06:12:00
(4 months ago)
Hacking web forms for spam
Web Spam
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-07 00:51:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 20:51:27.077378 2026] [security2:error] [pid 10731:tid 10731] [client 5.255.117.134:48960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nldi.us"] [uri "/.git/config"] [unique_id "afviD8Ii8qscOAgQgVvG8gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
demonsword
2026-05-01 20:10:28
(5 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: egrul.nalog.ru:443
show less
Open Proxy
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-26 21:46:05
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 5.255.117.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 17:45:59.628386 2026] [security2:error] [pid 22701:tid 22701] [client 5.255.117.134:51678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bergopro.co.uk|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bergopro.co.uk"] [uri "/wp-config.backup"] [unique_id "ae6Hl7be3XH7Q0GEuscl2QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
nNordic
2026-04-24 07:10:50
(5 months ago)
Connection attempt blocked by IDS/IPS from 5.255.117.134/32
Hacking
๐จ๐ญ
backslash
2026-04-20 19:48:25
(5 months ago)
DDoS Attack