๐บ๐ธ
TPI-Abuse
2026-09-23 13:17:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 84.252.113.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 84.252.113.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:17:15.272342 2026] [security2:error] [pid 17239:tid 17239] [client 84.252.113.50:36986] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fastquizmaker.com.creartest.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fastquizmaker.com.creartest.com"] [uri "/htdocs/user.sql"] [unique_id "arPRWyTQCRcGV0JAWTA-PwAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:27:21
(3 days ago)
(mod_security) mod_security (id:210350) triggered by 84.252.113.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 84.252.113.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:27:18.010326 2026] [security2:error] [pid 15403:tid 15403] [client 84.252.113.50:29297] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||spacebooger.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "spacebooger.com"] [uri "/"] [unique_id "arIDpsjfZ-iLvrXEmRTH7QAAABI"], referer: https://pulphero.blogspot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 15:41:28
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 84.252.113.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 84.252.113.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 11:41:22.347117 2026] [security2:error] [pid 16193:tid 16193] [client 84.252.113.50:10175] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||personal-sportswear.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "personal-sportswear.com"] [uri "/"] [unique_id "aq1boppuYp8ZYXfgsHBsmAAAAAI"], referer: https://five.co.in/redirect.php?ref_host=zenlignbands.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
fbarela
2026-09-18 09:00:04
(1 week ago)
FortiGate SSL VPN login failures.
Brute-Force
Hacking
๐จ๐ฟ
unhfree.net
2026-09-17 08:37:34
(1 week ago)
Sep 17 10:37:31 canopus postfix/smtpd[1437665]: NOQUEUE: reject: RCPT from unknown[84.252.113.50]: 5 ...
show more
Sep 17 10:37:31 canopus postfix/smtpd[1437665]: NOQUEUE: reject: RCPT from unknown[84.252.113.50]: 554 5.7.1 Service unavailable; Client host [84.252.113.50] blocked using zen.spamhaus.org; Listed by XBL, see https://check.spamhaus.org/query/ip/84.252.113.50; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<googlemail.com>
Sep 17 10:37:31 canopus postfix/smtpd[1437665]: NOQUEUE: reject: RCPT from unknown[84.252.113.50]: 554 5.7.1 Service unavailable; Client host [84.252.113.50] blocked using zen.spamhaus.org; Listed by XBL, see https://check.spamhaus.org/query/ip/84.252.113.50; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<googlemail.com>
Sep 17 10:37:32 canopus postfix/smtpd[1437665]: NOQUEUE: reject: RCPT from unknown[84.252.113.50]: 554 5.7.1 Service unavailable; Client host [84.252.113.50] blocked using zen.spamhaus.org; Listed by XBL, see https://check.spamhaus.org/query/ip/84.252.113.50; from=<[email protected] > to=<39ec758ec8114a1
...
show less
Brute-Force
Exploited Host
๐บ๐ธ
LARL-Stompro-2024
2026-09-15 03:42:16
(1 week ago)
Evergreen ILS - Mylist Bot Abuse - HTTP Port 443 - Fake UserAgent. Requests:2
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-09-11 22:31:00
(1 week ago)
IPBlock protected site ID [4055-d][s=06].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyuuzyou
2026-09-08 14:49:22
(2 weeks ago)
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on applic ...
show more
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on application ports 80/443. Observed 2026-09-08T14:49:22Z.
show less
Bad Web Bot
๐บ๐ธ
Zandro
2026-09-08 05:00:14
(2 weeks ago)
distributed harvester
DDoS Attack
Bad Web Bot
Exploited Host
๐บ๐ธ
ipblock.com
2026-09-03 06:52:00
(3 weeks ago)
IPBlock protected site ID [4055-d][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 07:03:59
(3 weeks ago)
denied traffic to a honeypot network. destination port 23.
Port Scan
Hacking
Anonymous
2026-08-27 09:02:44
(4 weeks ago)
denied Telnet access attempt. destination port 23.
Port Scan
Brute-Force
๐บ๐ธ
ipblock.com
2026-08-27 05:13:00
(4 weeks ago)
IPBlock protected site ID [4055-d][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-08-22 18:00:53
(1 month ago)
Zimbra: Login failures from malicious IP: 84.252.113.50. Threat Score: 6.4/10 (MEDIUM). Confidence: ...
show more
Zimbra: Login failures from malicious IP: 84.252.113.50. Threat Score: 6.4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 77%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-08-10 00:24:16
(1 month ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot