Anonymous
2026-06-30 10:04:08
(2 months ago)
[ssd1.kdns.gr] httpd-404: sites=gflawoffice.com; logs=/var/log/httpd/domains/gflawoffice.com.log; sa ...
show more
[ssd1.kdns.gr] httpd-404: sites=gflawoffice.com; logs=/var/log/httpd/domains/gflawoffice.com.log; samples=/wp-includes/assets/index.php | /wp-includes/assets/ | /wp-includes/Requests/src/Auth/index.php
show less
Web App Attack
๐ช๐ธ
masterguru
2026-06-30 03:26:26
(2 months ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐ณ๐ฟ
Antinson
2026-06-15 18:55:13
(2 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ง๐ช
cmbplf
2026-06-15 09:50:12
(2 months ago)
2.000 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
๐ฐ๐ท
MW
2026-06-12 08:26:43
(2 months ago)
85.203.45.77 - - [12/Jun/2026:17:26:39 +0900] "GET /wp-includes/fonts/ HTTP/1.1" 404 4232 "http://pi ...
show more
85.203.45.77 - - [12/Jun/2026:17:26:39 +0900] "GET /wp-includes/fonts/ HTTP/1.1" 404 4232 "http://piazza.co.kr/wp-includes/fonts/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
85.203.45.77 - - [12/Jun/2026:17:26:41 +0900] "GET /wp-includes/Requests/src/Exception/Transport/ HTTP/1.1" 404 459 "http://piazza.co.kr/wp-includes/Requests/src/Exception/Transport/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
85.203.45.77 - - [12/Jun/2026:17:26:42 +0900] "GET /edit.php HTTP/1.1" 404 459 "http://piazza.co.kr/edit.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-12 00:33:42
(2 months ago)
Excessive 404/403 errors
Brute-Force
๐ง๐ช
cmbplf
2026-06-11 18:34:23
(2 months ago)
16.347 requests with url.path */xmlrpc.php
16.347 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2026-05-10 20:23:06
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฏ๐ต
Valhalla
2026-02-28 18:26:13
(6 months ago)
/backup/latest.zip
Hacking
Web App Attack
Anonymous
2026-02-15 13:22:46
(6 months ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-02-15 05:50:26
(6 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-06 06:07:39
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.45.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 01:07:35.487587 2026] [security2:error] [pid 20924:tid 20924] [client 85.203.45.77:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ccamp.dev|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ccamp.dev"] [uri "/backups/wallet.dat"] [unique_id "aYWFJ9CzpXjDyj23Kng_fAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-02-05 13:52:33
(6 months ago)
/backup/directory.rar
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-02 02:18:10
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 85.203.45.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 85.203.45.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 21:18:06.733942 2026] [security2:error] [pid 24421:tid 24421] [client 85.203.45.77:46521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linuxforpoets.com"] [uri "/old/sftp-config.json"] [unique_id "aYAJXvLdTckdf4RZyOAVTgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 21:03:15
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.45.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 16:03:11.654268 2026] [security2:error] [pid 4249:tid 4249] [client 85.203.45.77:59469] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||doubloonswap.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "doubloonswap.com"] [uri "/www.sql"] [unique_id "aX-_jxQg-XLKScXz6T0udQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack