🇫🇷
Lunix
2026-09-04 02:18:41
(4 hours ago)
SQL Injection
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-10 22:50:49
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 91.245.236.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 91.245.236.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 18:50:42.199871 2026] [security2:error] [pid 30632:tid 30632] [client 91.245.236.238:60875] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pscc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pscc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agELwkPIqDHA1nYmA8c9gQAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
KIDOS
2026-03-21 08:24:21
(5 months ago)
malicious activity
Web App Attack
🇩🇪
Packets-Decreaser.NET
2025-12-10 14:34:35
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇺🇸
TPI-Abuse
2025-12-05 10:10:20
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 91.245.236.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 91.245.236.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 05:10:16.031330 2025] [security2:error] [pid 17103:tid 17103] [client 91.245.236.238:24185] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ww-bbs.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ww-bbs.com"] [uri "/"] [unique_id "aTKviEj9UHPhdVtIRCYyQAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-15 17:08:32
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 91.245.236.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 91.245.236.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 12:08:25.022557 2025] [security2:error] [pid 15706:tid 15706] [client 91.245.236.238:20397] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||opere.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "opere.com"] [uri "/"] [unique_id "aRiziU9c9pXO57ZawS8qZAAAAHI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Swiptly
2024-05-27 22:59:45
(2 years ago)
WordPress xmlrpc spam or enumeration
...
Web Spam
Bad Web Bot
Web App Attack
🇸🇪
www.remote24.se
2022-07-22 07:16:31
(4 years ago)
IDS admin
Brute-Force
🇺🇸
www.serverprotection.dev
2022-07-14 01:16:25
(4 years ago)
Repeated RDP login failures. Last user: ADMINISTRATOR
Brute-Force
🇿🇦
IrisFlower
2022-07-12 06:52:02
(4 years ago)
Unauthorized connection attempt detected from IP address 91.245.236.238 to port 3389 [J]
Port Scan
Hacking
🇿🇦
IrisFlower
2022-06-12 10:39:53
(4 years ago)
Unauthorized connection attempt detected from IP address 91.245.236.238 to port 2929 [J]
Port Scan
Hacking