๐ฉ๐ช
Vegascosmetics
2025-10-06 21:51:51
(10 months ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-06 19:23:10
(10 months ago)
(mod_security) mod_security (id:210831) triggered by 51.44.245.140 (ec2-51-44-245-140.eu-west-3.comp ...
show more
(mod_security) mod_security (id:210831) triggered by 51.44.245.140 (ec2-51-44-245-140.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 06 15:23:07.795125 2025] [security2:error] [pid 16817:tid 16876] [client 51.44.245.140:58186] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||antidote-it.com|F|4"] [data "grub-client"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "antidote-it.com"] [uri "/js/jquery.cslider.js"] [unique_id "aOQXG4ikoQNy9IqPk6NAMwAAAcE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-06 19:20:12
(10 months ago)
Bot / seems abusive / Apache connections: 24
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2025-10-06 18:12:30
(10 months ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
rh24
2025-10-06 17:45:08
(10 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 51.44.245.140 (FR/Fr ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 51.44.245.140 (FR/France/ec2-51-44-245-140.eu-west-3.compute.amazonaws.com)
show less
Bad Web Bot
๐บ๐ธ
LotPhantom
2025-10-06 16:44:48
(10 months ago)
51.44.245.140 - - [06/Oct/2025:16:43:47 +0000] "GET / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Linux; Andro ...
show more
51.44.245.140 - - [06/Oct/2025:16:43:47 +0000] "GET / HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Linux; Android 8.0.0; SM-A520F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
1gz
2025-10-06 16:32:40
(10 months ago)
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from FR.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML like Gecko) Maxthon/4.0.0.2000 Chrome/22.0.1229.79 Safari/537.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ฎ
Jordy
2025-10-06 09:51:16
(10 months ago)
06/Oct/2025:11:53:37.210115 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
06/Oct/2025:11:53:37.210115 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 51.44.245.140] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "worldcup.jordymarije.nl"] [uri "/"] [unique_id "aOORoTEJiSdVb3_5vEOcZwAAAAI"]
06/Oct/2025:11:53:37.210115 +0200Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 51.44.245.140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched
...
show less
Web App Attack
๐ณ๐ฑ
GabrielJST
2025-10-06 09:04:51
(10 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 51.44.245.140 (FR/Fr ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 51.44.245.140 (FR/France/ec2-51-44-245-140.eu-west-3.compute.amazonaws.com)
show less
Bad Web Bot
๐ฎ๐ฉ
Burayot
2025-10-06 08:34:05
(10 months ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 51.44.245.140 (FR/France/ec2-51-44-2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 51.44.245.140 (FR/France/ec2-51-44-245-140.eu-west-3.compute.amazonaws.com): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2025-10-06 07:47:31
(10 months ago)
(CT) IP 51.44.245.140 (FR/France/ec2-51-44-245-140.eu-west-3.compute.amazonaws.com) found to have 15 ...
show more
(CT) IP 51.44.245.140 (FR/France/ec2-51-44-245-140.eu-west-3.compute.amazonaws.com) found to have 153 connections
show less
DDoS Attack
๐ณ๐ฑ
BlueWire Hosting
2025-10-05 20:10:09
(10 months ago)
Detected as a bad bot
Bad Web Bot
๐ฉ๐ช
ScchutzZ
2025-10-05 19:59:22
(10 months ago)
Failed login attempt detected by Fail2Ban in plesk-apache-badbot jail
Web App Attack
๐ฌ๐ง
Apache
2025-10-05 18:09:04
(10 months ago)
(mod_security) mod_security (id:20000010) triggered by 51.44.245.140 (FR/France/ec2-51-44-245-140.eu ...
show more
(mod_security) mod_security (id:20000010) triggered by 51.44.245.140 (FR/France/ec2-51-44-245-140.eu-west-3.compute.amazonaws.com): 5 in the last 300 secs
show less
Email Spam
Brute-Force
Web App Attack
๐จ๐ฆ
polycoda
2025-10-05 17:44:41
(10 months ago)
๐ Probes for tons of inexistent files and/or PHP scripts
Hacking
Web App Attack