🇹🇷
neron
2026-09-06 00:55:33
(19 hours ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
🇹🇷
neron
2026-09-03 00:48:47
(3 days ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
🇹🇷
neron
2026-08-22 03:21:51
(2 weeks ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
🇹🇷
neron
2026-08-19 04:26:22
(2 weeks ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
🇹🇷
neron
2026-08-11 03:06:50
(3 weeks ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
🇹🇷
neron
2026-07-30 03:06:20
(1 month ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
🇹🇷
neron
2026-07-26 11:20:49
(1 month ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
🇮🇳
liveaspankaj
2026-02-13 09:16:54
(6 months ago)
DDoS attack: 182 requests in 5m (GET / or repair.php).
DDoS Attack
🇺🇸
findlab
2025-09-19 06:20:01
(11 months ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-18 20:43:07
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 18 16:43:03.273237 2025] [security2:error] [pid 21031:tid 21031] [client 77.111.247.128:64779] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mtsneffels.com|F|2"] [data ".dat.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mtsneffels.com"] [uri "/wallet.dat.backup"] [unique_id "aMxu11vI7SR3k809JH4-4AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-18 13:50:33
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 18 09:50:28.697743 2025] [security2:error] [pid 17215:tid 17215] [client 77.111.247.128:30039] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.infinityartistsgroup.com|F|2"] [data ".dat.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.infinityartistsgroup.com"] [uri "/wallet.dat.backup"] [unique_id "aMwOJBJW9A5eTZ1lvHg5TgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-18 13:34:27
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 18 09:34:20.365326 2025] [security2:error] [pid 532224:tid 532242] [client 77.111.247.128:36593] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||allstartaxidermy.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "allstartaxidermy.com"] [uri "/wallet.dat"] [unique_id "aMwKXKmnj0XYva46hQ_BDQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-17 03:33:05
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 16 23:33:00.452844 2025] [security2:error] [pid 13008:tid 13008] [client 77.111.247.128:35141] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ndanou.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ndanou.com"] [uri "/wallet.dat"] [unique_id "aMor7HrQoiNwPOt0vP4aFQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-16 21:34:19
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 16 17:34:14.480675 2025] [security2:error] [pid 18819:tid 18975] [client 77.111.247.128:41215] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ilovemyparrot.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ilovemyparrot.com"] [uri "/wallet.dat"] [unique_id "aMnX1nTQgj2-Nb0BdHdpWQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-14 03:58:19
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 77.111.247.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 13 23:58:15.761283 2025] [security2:error] [pid 16412:tid 16412] [client 77.111.247.128:42705] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cometoorderva.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cometoorderva.com"] [uri "/wallet.backup"] [unique_id "aMY9VzZWbJCYt5Tr-t6e4gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack