🇳🇱
pixelXp
2026-09-13 13:32:15
(17 hours ago)
Reason:10 (Web Spam), Via: watishijmooi.nl/index-ajax.php, Message: detectSuspiciousPost count:6 det ...
show more
Reason:10 (Web Spam), Via: watishijmooi.nl/index-ajax.php, Message: detectSuspiciousPost count:6 details: Array -
show less
Web Spam
🇳🇱
pixelXp
2026-09-13 13:10:14
(18 hours ago)
Reason:15 (Hacking), Via: keramischebuitentegelsleggen.nl/index-ajax.php, Message: Blocked URL patte ...
show more
Reason:15 (Hacking), Via: keramischebuitentegelsleggen.nl/index-ajax.php, Message: Blocked URL pattern: 'index-ajax.php'. [POST] Gevaarlijk woord 'EVAL' in Value in 'search' [+35]; Gevaarlijk woord 'eval' in Value in 'ucfg' [+35]; Verdachte string 'base64_decode' in Value in 'ucfg' [+20]; Verdachte Base64 content: [
show less
Hacking
🇳🇱
pixelXp
2026-09-13 09:28:25
(21 hours ago)
Reason:15 (Hacking), Via: bomenrooien.com/index-ajax.php, Message: Blocked URL pattern: 'index- ...
show more
Reason:15 (Hacking), Via: bomenrooien.com/index-ajax.php, Message: Blocked URL pattern: 'index-ajax.php'. [POST] Gevaarlijk woord 'EVAL' in Value in 'search' [+35]; Gevaarlijk woord 'eval' in Value in 'ucfg' [+35]; Verdachte string 'base64_decode' in Value in 'ucfg' [+20]; Verdachte Base64 content: [
show less
Hacking
🇦🇺
Bay13
2026-09-13 01:46:18
(1 day ago)
CrowdSec:custom/http-probing
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 01:26:13
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.y ...
show more
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:26:10.212137 2026] [security2:error] [pid 2352333:tid 2352385] [client 65.109.179.105:25396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vivierae.com|F|2"] [data ".com_rsfiles.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vivierae.com"] [uri "/language/en-GB/en-GB.com_rsfiles.ini"] [unique_id "aqX7sor23b_J63zEf2VRQQAAAZY"], referer: https://www.vivierae.com/administrator/components/com_rsfiles/rsfiles.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 00:51:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.y ...
show more
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:51:00.288181 2026] [security2:error] [pid 2320:tid 2320] [client 65.109.179.105:60306] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vientodelevante.es|F|2"] [data ".com_rsfiles.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vientodelevante.es"] [uri "/language/en-GB/en-GB.com_rsfiles.ini"] [unique_id "aqXzdOVvNyIO6dNfwoW2YgAAAA4"], referer: https://vientodelevante.es/administrator/components/com_rsfiles/rsfiles.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇮
administrator
2026-09-11 23:03:01
(2 days ago)
2026-09-08 08:42:11,953 fail2ban.actions [1054]: NOTICE [error-bots] Ban 65.109.179.105
2026 ...
show more
2026-09-08 08:42:11,953 fail2ban.actions [1054]: NOTICE [error-bots] Ban 65.109.179.105
2026-09-08 08:42:11,953 fail2ban.actions [1054]: NOTICE [error-bots] Ban 65.109.179.105
2026-09-08 08:42:11,953 fail2ban.actions [1054]: NOTICE [error-bots] Ban 65.109.179.105
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 22:32:32
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.y ...
show more
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 18:32:26.912115 2026] [security2:error] [pid 27114:tid 27114] [client 65.109.179.105:28326] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jkperis.com|F|2"] [data ".pkg_sourcerer.sys.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jkperis.com"] [uri "/language/en-GB/en-GB.pkg_sourcerer.sys.ini"] [unique_id "aqHeeoiY3Pqo3ikOJ0JQ9wAAAAo"], referer: https://jkperis.com/administrator/manifests/packages/pkg_sourcerer.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-09 20:53:36
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-09 10:45:51
(4 days ago)
apache vulnerability scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:32:50
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.y ...
show more
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:32:46.747089 2026] [security2:error] [pid 5436:tid 5436] [client 65.109.179.105:49262] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||debbieweibler.com|F|2"] [data ".pkg_sourcerer.sys.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "debbieweibler.com"] [uri "/language/en-GB/en-GB.pkg_sourcerer.sys.ini"] [unique_id "aqEZrpw0hiaCUEvzQus6lgAAAAk"], referer: https://debbieweibler.com/administrator/manifests/packages/pkg_sourcerer.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:13:21
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.y ...
show more
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:13:16.306326 2026] [security2:error] [pid 7720:tid 7720] [client 65.109.179.105:33424] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dailybeautysupply.com|F|2"] [data ".pkg_sourcerer.sys.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dailybeautysupply.com"] [uri "/language/en-GB/en-GB.pkg_sourcerer.sys.ini"] [unique_id "aqEVHDOJlZjDB9xSsNC8uAAAAAU"], referer: https://dailybeautysupply.com/administrator/manifests/packages/pkg_sourcerer.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-09 06:59:09
(5 days ago)
[09/Sep/2026:09:59:09 +0300] -- 65.109.179.105 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[09/Sep/2026:09:59:09 +0300] -- 65.109.179.105 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/wpmudev-updates/changelog.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:20:02
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.y ...
show more
(mod_security) mod_security (id:210730) triggered by 65.109.179.105 (static.105.179.109.65.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:19:58.117686 2026] [security2:error] [pid 23734:tid 23739] [client 65.109.179.105:46364] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clmtic.es|F|2"] [data ".pkg_sourcerer.sys.ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clmtic.es"] [uri "/language/en-GB/en-GB.pkg_sourcerer.sys.ini"] [unique_id "aqD6jgbAcnist_-LBXkJGQAAAUM"], referer: https://clmtic.es/administrator/manifests/packages/pkg_sourcerer.xml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
findlab
2026-09-09 05:35:13
(5 days ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack