Anonymous
2026-01-12 12:28:01
(8 months ago)
wordpress-trap
Web App Attack
๐ฎ๐ฉ
Burayot
2026-01-04 03:28:45
(9 months ago)
LF_MODSEC: (mod_security) mod_security (id:10000003) triggered by 80.76.49.47 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:10000003) triggered by 80.76.49.47 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-04 00:23:00
(9 months ago)
(mod_security) mod_security (id:217291) triggered by 80.76.49.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217291) triggered by 80.76.49.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 19:22:55.031015 2026] [security2:error] [pid 13558:tid 13558] [client 80.76.49.47:63463] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||jeffersonlynn.com|F|2"] [data "Matched Data: \\x0a found within ARGS_NAMES:\\x5cnfromwhere: \\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "jeffersonlynn.com"] [uri "/g12privacy.php"] [unique_id "aVmy3-SrwcvAcisQtBtSjwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
thefoofighter
2026-01-03 18:54:04
(9 months ago)
[Sat Jan 03 18:54:03.540132 2026] [:error] [pid 1469919] [client 80.76.49.47:64515] [client 80.76.49 ...
show more
[Sat Jan 03 18:54:03.540132 2026] [:error] [pid 1469919] [client 80.76.49.47:64515] [client 80.76.49.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "aislingmcnally.com"] [uri "/index.php"] [unique_id "aVlly0O2DhWUO-_YwdeiNAAAAAY"]
[Sat Jan 03 18:54:03.734959 2026] [:error] [pid 1469124] [client 80.76.49.47:64539] [client 80.76.49.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-03 08:55:24
(9 months ago)
(mod_security) mod_security (id:217291) triggered by 80.76.49.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217291) triggered by 80.76.49.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 03:55:19.604357 2026] [security2:error] [pid 32021:tid 32021] [client 80.76.49.47:50936] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||groupof12.com|F|2"] [data "Matched Data: \\x0a found within ARGS_NAMES:\\x5cnfromwhere: \\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "groupof12.com"] [uri "/g12privacy.php"] [unique_id "aVjZd3WRVJdtxu_T97AfwQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
djboddington
2026-01-02 13:17:14
(9 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Hacking
Web App Attack
๐ซ๐ท
COMAITE
2026-01-02 05:28:58
(9 months ago)
SQL injection attempt from 80.76.49.47.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-02 02:47:55
(9 months ago)
(mod_security) mod_security (id:217291) triggered by 80.76.49.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:217291) triggered by 80.76.49.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 21:47:49.629584 2026] [security2:error] [pid 3527:tid 3527] [client 80.76.49.47:55227] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||furballrecords.com|F|2"] [data "Matched Data: \\x0a found within ARGS_NAMES:\\x5cnfromwhere: \\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "furballrecords.com"] [uri "/g12aboutsite.php"] [unique_id "aVcx1VCp36nw0WxkTLoF4QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
fortypoundhead
2025-12-11 13:12:23
(9 months ago)
SQL Injection Attempt
SQL Injection
Web App Attack
๐ฆ๐น
Markus Woegerbauer
2025-11-26 05:28:26
(10 months ago)
(mod_security) mod_security triggered on hostname [redacted] 80.76.49.47 (US/United States/-)
SQL Injection
๐ฆ๐บ
screwlooseit.com.au
2025-11-26 03:18:29
(10 months ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
BG/Bulgaria/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 03:06:51
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 80.76.49.47 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 80.76.49.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 22:06:44.941208 2025] [security2:error] [pid 11573:tid 11573] [client 80.76.49.47:54983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "londonconsulting.info"] [uri "/.env"] [unique_id "aSZuxOqzDMSnSJn7ecXN7wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2025-11-26 02:49:41
(10 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
Anonymous
2025-11-26 02:26:33
(10 months ago)
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /.env_sample HTTP/1.1, GET /.env.www HTT ...
show more
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /.env_sample HTTP/1.1, GET /.env.www HTTP/1.1, GET /.env_1 HTTP/1.1, GET /api/.env HTTP/1.1, GET /.env.save HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2025-11-26 01:10:24
(10 months ago)
(mod_security) mod_security triggered on hostname [redacted] 80.76.49.47 (US/United States/-)
SQL Injection