๐บ๐ธ
SX Communications
2026-07-21 15:14:36
(6 days ago)
HTTP application-layer DoS / botnet traffic from 66.181.160.110: repeated high-cost dynamic page and ...
show more
HTTP application-layer DoS / botnet traffic from 66.181.160.110: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐บ๐ธ
kosada.com
2026-07-06 21:02:54
(2 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
mnsf
2026-06-24 02:07:23
(1 month ago)
Login Too Frequent (7)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 01:53:15
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 66.181.160.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 66.181.160.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 21:53:08.761408 2026] [security2:error] [pid 25469:tid 25469] [client 66.181.160.110:36370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 66.181.160.110 (+1 hits since last alert)|gemco-mfg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gemco-mfg.com"] [uri "/xmlrpc.php"] [unique_id "ajs4hN94DdEbWpuFLTTDEAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 09:00:06
(1 month ago)
Botnet activity. Attribution: Angara Technologies Group / mikhail-smirnov-79830322 | Attack Signatur ...
show more
Botnet activity. Attribution: Angara Technologies Group / mikhail-smirnov-79830322 | Attack Signature Blocked: /wishlist/index/add/product/11175/form_key/9BTLuMX5c5NXUOCq/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like G...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-06-01 05:24:45
(1 month ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 04:53:55
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 66.181.160.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 66.181.160.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 00:53:50.612258 2026] [security2:error] [pid 19298:tid 19298] [client 66.181.160.110:59571] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 66.181.160.110 (+1 hits since last alert)|livinghopehighschool.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "livinghopehighschool.org"] [uri "/xmlrpc.php"] [unique_id "ah0QXsKj_DulvjgATOnj6wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 04:12:59
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 66.181.160.110 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 66.181.160.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 00:12:52.609529 2026] [security2:error] [pid 18221:tid 18221] [client 66.181.160.110:22571] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 66.181.160.110 (+1 hits since last alert)|haverhillhouse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "haverhillhouse.com"] [uri "/xmlrpc.php"] [unique_id "ah0GxNCkLUZj07aIcYJTCAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-05-02 01:03:00
(2 months ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐บ๐ธ
quilla
2026-04-03 03:20:35
(3 months ago)
Botnet infected device observed in honeypot (Vector: TCP)
DDoS Attack
๐ณ๐ฑ
EGP Abuse Dept
2026-03-04 02:32:05
(4 months ago)
Scraping webshop URLs (www.dewijs-3d.com), likely botnet drone
Bad Web Bot
Exploited Host
๐ฉ๐ช
check-the-sum.fr
2025-12-20 06:39:44
(7 months ago)
Port Scanning
Port Scan
Anonymous
2025-12-12 05:40:22
(7 months ago)
scanning http requests from known botnet
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 14:52:11
(7 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
Anonymous
2025-11-26 02:22:53
(8 months ago)
scanning http requests from known botnet
Web App Attack