๐ฉ๐ช
luxuria.cfd
2026-08-30 19:31:20
(10 hours ago)
Credential scanning on player_api.php (5 distinct logins in 120s). Auto-blocked by XUI Shield.
DDoS Attack
Port Scan
๐ฒ๐พ
Rizzy
2026-05-07 04:14:04
(3 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-04-29 11:46:48
(4 months ago)
GET /node/18/done/ HTTP/1.1
Web App Attack
๐ซ๐ฎ
xyz.rip
2026-04-17 15:51:52
(4 months ago)
WAF Violation
...
Hacking
Web App Attack
๐บ๐ธ
myagent.site
2026-04-13 05:33:11
(4 months ago)
Banned for trying to spam /contact/ {"action":"contact_form_ajax","first_name":"KatrinaSoomaAN","las ...
show more
Banned for trying to spam /contact/ {"action":"contact_form_ajax","first_name":"KatrinaSoomaAN","last_name":"KatrinaSoomaAN","email":"[email protected] ","message":"\u0415\u0441\u043b\u0438 \u0445\u043e\u0442\u0438\u0442\u0435 \u0431\u044b\u0441\u0442\u0440\u043e \u043f\u0440\u043e\u0434\u0430\u0442\u044c \u043a\u0432\u0430\u0440\u0442\u0438\u0440\u0443 \u0432 \u0421\u0430\u043d\u043a\u0442-\u041f\u0435\u0442\u0435\u0440\u0431\u0443\u0440\u0433\u0435, \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0439\u0442\u0435\u0441\u044c \u0443\u0441\u043b\u0443\u0433\u043e\u0439 <a href=https:\/\/dzen.ru\/a\/Zxp9pdVG8ABYo4MS>\u0441\u043a\u0443\u043f\u043a\u0430 \u043a\u0432\u0430\u0440\u0442\u0438\u0440 \u0432 \u0441\u043f\u0431<\/a>. \u0412\u044b\u043a\u0443\u043f \u043a\u0432\u0430\u0440\u0442\u0438\u0440 \u0441\u0430\u043d\u043a\u0442 \u043f\u0435\u0442\u0435\u0440\u0431\u0443\u0440\u0433 - \u043e\u0431\u0435\u0441\u043f\u0435\u0447\u0438\u0442\u044c \u0434\u043b\u044f \u0441\u043e\u0431\u0441\u0442\u04
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-09 10:22:01
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 77.242.177.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 77.242.177.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 06:21:54.588579 2026] [security2:error] [pid 442286:tid 442286] [client 77.242.177.57:38506] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thevillageartcenter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thevillageartcenter.com"] [uri "/mailto:[email protected] "] [unique_id "add9whraBZOGqasbTuzdfgAAABY"], referer: http://thevillageartcenter.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 03:19:44
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 77.242.177.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 77.242.177.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 23:19:39.824546 2026] [security2:error] [pid 41983:tid 42105] [client 77.242.177.57:59480] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||isoceansl.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "isoceansl.com"] [uri "/mailto:[email protected] "] [unique_id "adXJS3adyF71kC8MGy2ungAAAQo"], referer: http://isoceansl.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
GunsawianHosting
2026-03-12 17:08:57
(5 months ago)
Open Proxy
Open Proxy
๐ง๐ฌ
cheatmaster.store
2026-02-26 05:50:08
(6 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: Italy
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
๐ต๐ฑ
IROK
2026-01-28 11:11:56
(7 months ago)
Firewall Blocked - Unauthorized Port Scanning
...
Port Scan
Anonymous
2026-01-22 03:34:44
(7 months ago)
Forum/form spam
Web Spam
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-16 18:25:53
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-07 03:55:40
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 77.242.177.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 77.242.177.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 22:55:36.738247 2025] [security2:error] [pid 27457:tid 27457] [client 77.242.177.57:34888] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ik3co.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ik3co.com"] [uri "/mailto:[email protected] "] [unique_id "aTT6uKvXS3HbBU4pdBhIpAAAAAU"], referer: http://ik3co.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
EGP Abuse Dept
2025-09-21 01:17:04
(11 months ago)
forum signup bot
Web Spam
Blog Spam
Web App Attack
๐ธ๐ฌ
Charles
2025-07-04 13:59:23
(1 year ago)
77.242.177.57 - - [04/Jul/2025:21:59:20 +0800] "GET /ip/contact/ HTTP/1.1" 404 2073 "http://amstar.t ...
show more
77.242.177.57 - - [04/Jul/2025:21:59:20 +0800] "GET /ip/contact/ HTTP/1.1" 404 2073 "http://amstar.tw/ip/contact/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5042.0 Safari/537.36"
...
show less
Web Spam
Email Spam
Brute-Force
Bad Web Bot
Web App Attack
SSH