๐ซ๐ท
mail.avx.gr
2026-07-30 21:49:20
(23 hours ago)
Plesk Fail2Ban jail: plesk-apache-badbot. Evidence: 74.7.243.194 - - [31/Jul/2026:00:49:19 +0300] "G ...
show more
Plesk Fail2Ban jail: plesk-apache-badbot. Evidence: 74.7.243.194 - - [31/Jul/2026:00:49:19 +0300] "GET / HTTP/2.0" 200 464 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
largo-it.net
2026-07-30 18:21:56
(1 day ago)
Jul 30 20:21:26 vps-9f3cdc33 haproxy[3469808]: 74.7.243.194:45014 [30/Jul/2026:20:21:25.526] www_fro ...
show more
Jul 30 20:21:26 vps-9f3cdc33 haproxy[3469808]: 74.7.243.194:45014 [30/Jul/2026:20:21:25.526] www_frontend~ finance_cluster/finance1_test1_https 0/0/12/805/1014 404 175967 - - CD-- 109/61/4/4/0 0/0 "GET https://largo-finance.com/fr/?marriage/223011714 HTTP/2.0"
Jul 30 20:21:33 vps-9f3cdc33 haproxy[3469808]: 74.7.243.194:45014 [30/Jul/2026:20:21:32.947] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/869/910 404 199653 - - ---- 103/55/5/5/0 0/0 "GET https://largo-finance.com/fr/?standard/072031061 HTTP/2.0"
Jul 30 20:21:38 vps-9f3cdc33 haproxy[3469808]: 74.7.243.194:45014 [30/Jul/2026:20:21:37.974] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/746/756 404 3151 - - ---- 101/53/4/4/0 0/0 "GET https://largo-finance.com/ranking/emphasis/d117hzsvwieapck_32361.phtml HTTP/2.0"
Jul 30 20:21:43 vps-9f3cdc33 haproxy[3469808]: 74.7.243.194:45014 [30/Jul/2026:20:21:42.282] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/742/753 404 3151 - - ---- 100/52/3/3/0 0/0 "GET
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-30 18:07:04
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
masterguru
2026-07-30 16:05:58
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 74.7.243.194 (US/United States/-): 1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 74.7.243.194 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ท
masterguru
2026-07-30 11:52:28
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 74.7.243.194 (US/United States/-): 2 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 74.7.243.194 (US/United States/-): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
stechusa
2026-07-29 23:46:01
(1 day ago)
[Askari] | country=US | ASN=Microsoft Corporation | Behavior: Sustained high traffic, Rapid page enu ...
show more
[Askari] | country=US | ASN=Microsoft Corporation | Behavior: Sustained high traffic, Rapid page enumeration, Automated crawling
show less
Bad Web Bot
DDoS Attack
๐บ๐ธ
stechusa
2026-07-29 23:46:01
(1 day ago)
country=US | ASN=Microsoft Corporation | AbuseIPDB=71% | 20 facet requests/minute (threshold: 20) | ...
show more
country=US | ASN=Microsoft Corporation | AbuseIPDB=71% | 20 facet requests/minute (threshold: 20) | 50 requests with only 2 static assets (4%) - likely automated | 10 facet requests/minute
show less
Bad Web Bot
DDoS Attack
๐ฎ๐น
sssrit
2026-07-28 17:52:23
(3 days ago)
74.7.243.194 - - [28/Jul/2026:19:52:22 +0200] "GET /wp-content/uploads/sites/3/complianz/css/banner- ...
show more
74.7.243.194 - - [28/Jul/2026:19:52:22 +0200] "GET /wp-content/uploads/sites/3/complianz/css/banner-%7Bbanner_id%7D-%7Btype%7D.css?v=1852 HTTP/2.0" 404 88 "https://onida.sssr.it/" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 08:07:06
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 74.7.243.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 74.7.243.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:06:58.686211 2026] [security2:error] [pid 3092600:tid 3092600] [client 74.7.243.194:54538] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wryemusings.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wryemusings.com"] [uri "/ESTemplate.ini"] [unique_id "amcRol2LRHVlglVmMXEFVwAAAA4"], referer: https://en.m.uesp.net
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-27 01:10:21
(4 days ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐ฉ๐ช
DocNetzwerk
2026-07-25 23:36:37
(5 days ago)
(php-url-fopen) Failed php-url-fopen trigger from 74.7.243.194 (US/United States/-)
Web App Attack
๐ซ๐ท
Dorian GRANDHAY
2026-07-22 22:55:04
(1 week ago)
(PERMBLOCK) 74.7.243.194 (US/United States/-) has had more than 4 temp blocks in the last 604800 sec ...
show more
(PERMBLOCK) 74.7.243.194 (US/United States/-) has had more than 4 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-22 20:16:02
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 74.7.243.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 74.7.243.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 16:15:56.433131 2026] [security2:error] [pid 2034573:tid 2034590] [client 74.7.243.194:43970] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.iancaird.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.iancaird.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "amEk_IYKwbTtc0sxdQ-TswAAAM0"], referer: https://www.iancaird.com/author/admin/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-22 03:54:09
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
Dorian GRANDHAY
2026-07-21 15:38:40
(1 week ago)
(PERMBLOCK) 74.7.243.194 (US/United States/-) has had more than 4 temp blocks in the last 604800 sec ...
show more
(PERMBLOCK) 74.7.243.194 (US/United States/-) has had more than 4 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan