๐บ๐ธ
TPI-Abuse
2026-09-20 00:37:39
(5 hours ago)
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in ...
show more
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 20:37:32.681318 2026] [security2:error] [pid 23344:tid 23344] [client 82.66.53.48:41180] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||dubb.productions|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "dubb.productions"] [uri "/security.txt"] [unique_id "aq8qzHKGH4A8FooW7OCW-gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
BelleFashion
2026-09-19 20:37:00
(9 hours ago)
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 17:52:41
(12 hours ago)
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in ...
show more
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:52:37.985943 2026] [security2:error] [pid 13068:tid 13068] [client 82.66.53.48:55036] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.crazypencil.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.crazypencil.com"] [uri "/"] [unique_id "aq7L5VFGMNs8WKxCVO6ihwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 16:49:01
(13 hours ago)
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in ...
show more
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 12:48:55.480759 2026] [security2:error] [pid 21466:tid 21568] [client 82.66.53.48:43942] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||ecocentri.city|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "ecocentri.city"] [uri "/security.txt"] [unique_id "aq6897XpXd4G18xJwTxU5AAAAgg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-19 06:58:21
(23 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-19 01:57:07
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in ...
show more
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 21:57:00.779165 2026] [security2:error] [pid 25850:tid 25850] [client 82.66.53.48:35584] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||inwriting.buzz|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "inwriting.buzz"] [uri "/security.txt"] [unique_id "aq3r7Ibkf_iqPPcPjAEW1gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 23:57:36
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in ...
show more
(mod_security) mod_security (id:210831) triggered by 82.66.53.48 (82-66-53-48.subs.proxad.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 19:57:29.965952 2026] [security2:error] [pid 32356:tid 32371] [client 82.66.53.48:57198] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||property-management.company|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "property-management.company"] [uri "/.well-known/security.txt"] [unique_id "aq3P6Qpz9iP3zyyzdz2c9QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Bensay
2026-09-18 21:32:24
(1 day ago)
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show more
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=unknown
show less
Port Scan
๐ซ๐ท
krys-abuseip
2026-09-18 15:25:02
(1 day ago)
82.66.53.48 - - [18/Sep/2026:17:24:25 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 5615 "-" " ...
show more
82.66.53.48 - - [18/Sep/2026:17:24:25 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 5615 "-" "Mozilla/5.0 (compatible; SecurityTxtSurveyBot/1.0; recherche journalistique sur l'adoption de security.txt sur le TLD .fr; contact: [email protected] )"
82.66.53.48 - - [18/Sep/2026:17:24:25 +0200] "GET /security.txt HTTP/1.1" 404 5615 "-" "Mozilla/5.0 (compatible; SecurityTxtSurveyBot/1.0; recherche journalistique sur l'adoption de security.txt sur le TLD .fr; contact: [email protected] )"
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-09-18 09:46:04
(1 day ago)
connection to honeypot
Email Spam
Port Scan
๐ฉ๐ช
sverson
2026-09-18 08:54:41
(1 day ago)
Mutliple unauthorized attempts to access web resources
Web App Attack
๐ฌ๐ท
setupgr
2026-09-18 07:10:27
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 82.66.53.48 (FR/France/-/-/-/[AS12322 Free SA ...
show more
(mod_security) mod_security (id:11000011) triggered by 82.66.53.48 (FR/France/-/-/-/[AS12322 Free SAS]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 18 10:10:23.243301 2026] [security2:error] [pid 473930:tid 474107] [client 82.66.53.48:52020] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "proxad.net" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 82-66-53-48.subs.proxad.net"] [severity "CRITICAL"] [hostname "babis.photo"] [uri "/.well-known/security.txt"] [unique_id "aqzj3_IyyznYGdIp_jlP9AAAAZE"]
show less
Port Scan
๐ซ๐ท
Bensay
2026-09-18 03:22:46
(2 days ago)
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show more
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=Mozilla/5.0 (compatible; SecurityTxtSurveyBot/1.0; recherche journalistique sur l'adoption de security.txt sur le TLD .fr; contact: [email protected] )
show less
Port Scan
๐ณ๐ฑ
BlueWire Hosting
2026-09-18 02:12:43
(2 days ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐จ๐ฆ
Roper123
2026-09-17 17:54:35
(2 days ago)
Web app exploits
Web App Attack