๐ง๐ช
Saec
2026-07-15 16:42:26
(1 week ago)
Jarvis auto-ban: CF honeypot path /wp-login.php (2ร on saec.me)
Port Scan
Web App Attack
๐จ๐ด
JN
2026-06-19 19:29:01
(1 month ago)
Reporte automatizado de actividad sospechosa
DDoS Attack
๐จ๐ด
AF
2026-06-19 17:48:08
(1 month ago)
Reporte automatizado de actividad sospechosa
DDoS Attack
๐จ๐ด
Dricci
2026-06-19 17:35:55
(1 month ago)
Reporte automatizado de actividad sospechosa
Port Scan
๐ช๐ธ
librebit
2026-06-09 12:47:35
(1 month ago)
RDWeb scan
Web App Attack
๐ฎ๐ฉ
RasyiidWho
2026-02-14 02:04:03
(5 months ago)
ip112.20 . 83.142.52.77 - - [14/Feb/2026:09:04:02 +0700] "POST /xmlrpc.php HTTP/1.1" 401 172 "-" "Ap ...
show more
ip112.20 . 83.142.52.77 - - [14/Feb/2026:09:04:02 +0700] "POST /xmlrpc.php HTTP/1.1" 401 172 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
...
show less
DDoS Attack
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-11-26 19:56:37
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 83.142.52.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 83.142.52.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 14:56:32.595747 2025] [security2:error] [pid 27201:tid 27201] [client 83.142.52.77:17939] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||teamconnell.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "teamconnell.com"] [uri "/"] [unique_id "aSdbcPBj0B_0JPOIQpl-VAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 16:15:47
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 83.142.52.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 83.142.52.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 11:15:40.071859 2025] [security2:error] [pid 26036:tid 26036] [client 83.142.52.77:59343] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||waking.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "waking.com"] [uri "/"] [unique_id "aSCQLHptMhc6704aUtEqJwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 18:20:10
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 83.142.52.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 83.142.52.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 13:20:01.877691 2025] [security2:error] [pid 19022:tid 19022] [client 83.142.52.77:32541] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dwars.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dwars.net"] [uri "/"] [unique_id "aRjEUZmGVmL0xA-QHdvazgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 06:04:31
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 83.142.52.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 83.142.52.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 01:04:25.499889 2025] [security2:error] [pid 31134:tid 31134] [client 83.142.52.77:24277] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||g-h2o.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "g-h2o.com"] [uri "/"] [unique_id "aRQjadhJadnwQ4gfeHWpjgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-22 20:28:12
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-07-21 05:17:15
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-07-18 17:18:24
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
nowyouknow
2025-07-18 11:46:57
(1 year ago)
(From [email protected] ) We have hacked your website https://greenriverchiropractic. ...
show more
(From [email protected] ) We have hacked your website https://greenriverchiropractic.net and extracted your databases.
How did this happen?
Our team has found a vulnerability within your site that we were able to exploit. After finding the vulnerability we were able to get your database credentials and extract your entire database and move the information to an offshore server.
What does this mean?
We will systematically go through a series of steps of totally damaging your reputation. First your database will be leaked or sold to the highest bidder which they will use with whatever their intentions are. Next if there are e-mails found they will be e-mailed that their information has been sold or leaked and your site https://greenriverchiropractic.net was at fault thusly damaging your reputation and having angry customers/associates with whatever angry customers/associates do. Lastly any links that you have indexed in the search engines will be de-indexed based off of blackhat techn
show less
Phishing
Web Spam
Anonymous
2025-07-16 19:39:58
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH