π¨π
dalslab ltd
2026-07-30 04:05:59
(2 days ago)
2026/07/30 06:05:59 [error] 616#616: *1280136 limiting requests, excess: 20.850 by zone "rl_per_ip", ...
show more
2026/07/30 06:05:59 [error] 616#616: *1280136 limiting requests, excess: 20.850 by zone "rl_per_ip", client: 74.179.67.173, server: immich.dalslab.com, request: "GET /_app/immutable/chunks/13Jiqd0o.js HTTP/2.0", host: "immich.dalslab.com", referrer: "https://immich.dalslab.com/"
2026/07/30 06:05:59 [error] 616#616: *1280136 limiting requests, excess: 20.850 by zone "rl_per_ip", client: 74.179.67.173, server: immich.dalslab.com, request: "GET /_app/immutable/chunks/FD9-5WYv2.js HTTP/2.0", host: "immich.dalslab.com", referrer: "https://immich.dalslab.com/"
2026/07/30 06:05:59 [error] 616#616: *1280136 limiting requests, excess: 20.830 by zone "rl_per_ip", client: 74.179.67.173, server: immich.dalslab.com, request: "GET /_app/immutable/chunks/gaw8GWTo.js HTTP/2.0", host: "immich.dalslab.com", referrer: "https://immich.dalslab.com/"
2026/07/30 06:05:59 [error] 616#616: *1280136 limiting requests, excess: 20.830 by zone "rl_per_ip", client: 74.179.67.173, server: immich.dalslab.com, request
...
show less
Brute-Force
SSH
πΊπΈ
anti-res
2026-07-29 13:27:32
(2 days ago)
Attempt of unauthorized access
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
anti-res
2026-07-22 16:41:48
(1 week ago)
Attempt of unauthorized access
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 17:22:31
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 74.179.67.173 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 74.179.67.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 13:22:25.728288 2026] [security2:error] [pid 9539:tid 9539] [client 74.179.67.173:11073] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||keystroke.info|F|2"] [data ".php.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "keystroke.info"] [uri "/LocalSettings.php.backup"] [unique_id "alpk0TYrE-Tq4MB78AaWtwAAABo"], referer: https://keystroke.info/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
HamSammich
2026-07-09 13:31:42
(3 weeks ago)
Automated sensor: 2 HTTPS connection/probe attempts over the last 24h (latest 2026-07-09T13:31Z).
Brute-Force
Web App Attack
π¨π
backslash
2026-06-30 15:06:00
(1 month ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-29 13:16:40
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 74.179.67.173 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 74.179.67.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 09:16:33.436980 2026] [security2:error] [pid 11645:tid 11645] [client 74.179.67.173:27140] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gapanda.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gapanda.com"] [uri "/php-old.ini"] [unique_id "akJwMRZ4Xbc21Avb4GR2TwAAABc"], referer: http://gapanda.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TNZ
2026-06-14 23:08:55
(1 month ago)
Automated honeypot: bot_detected:alphabetical_scanning | Path: /.netlify/functions/beta-spots | ISP: ...
show more
Automated honeypot: bot_detected:alphabetical_scanning | Path: /.netlify/functions/beta-spots | ISP: AS8075 Microsoft Corporation | ASN: AS8075 Microsoft Corporation [HOSTING] | Abuse score: 19 | Open ports: [] | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
show less
Bad Web Bot
Web App Attack
πΊπΈ
cwytech
2026-06-11 07:26:35
(1 month ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/tactical-rmm-lockdown-high.
Hacking
π·π΄
Fn4ticHz
2026-06-07 23:56:16
(1 month ago)
DDoS blocked via ZeroGuard.ID
DDoS Attack
Exploited Host
π¨π¦
dispensight
2026-06-03 15:37:13
(1 month ago)
Automated web scanner: 4 GET requests to s01-app.dispensight.ca. Paths: /static/css/main.css, /stati ...
show more
Automated web scanner: 4 GET requests to s01-app.dispensight.ca. Paths: /static/css/main.css, /static/css/themes.css. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.7444.162 Safari/537.36. Microsoft Corporation (Quincy, United States).
show less
Bad Web Bot