๐ฎ๐น
VHosting
2026-09-12 18:20:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-03 17:22:41
(2 weeks ago)
IP matched detection query saxova.cz.
Brute-Force
Anonymous
2026-09-03 16:34:08
(2 weeks ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 01:27:40
(3 weeks ago)
(mod_security) mod_security (id:217210) triggered by 51.161.131.235 (vps-bc97317a.vps.ovh.ca): 1 in ...
show more
(mod_security) mod_security (id:217210) triggered by 51.161.131.235 (vps-bc97317a.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:27:36.260358 2026] [security2:error] [pid 30654:tid 30654] [client 51.161.131.235:42760] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||weathercarib.com:443|F|4"] [data "CONNECT weathercarib.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "weathercarib.com"] [uri "/"] [unique_id "apYqCJInvHYKZHihepz1sQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-08-31 12:47:20
(3 weeks ago)
[Mon Aug 31 22:46:39.209707 2026] [authz_core:error] [pid 1793443:tid 1793503] [client 51.161.131.23 ...
show more
[Mon Aug 31 22:46:39.209707 2026] [authz_core:error] [pid 1793443:tid 1793503] [client 51.161.131.235:33710] AH01630: client denied by server configuration: /srv/http/
[Mon Aug 31 22:46:43.098992 2026] [authz_core:error] [pid 1793443:tid 1793504] [client 51.161.131.235:55084] AH01630: client denied by server configuration: /srv/http/
[Mon Aug 31 22:47:20.023550 2026] [authz_core:error] [pid 1786207:tid 1786260] [client 51.161.131.235:47718] AH01630: client denied by server configuration: /srv/http/
...
show less
Brute-Force
Web App Attack
๐น๐ท
neron
2026-08-15 23:06:48
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-10 16:29:22
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-05 06:29:42
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-03 01:34:08
(1 month ago)
(mod_security) mod_security (id:217210) triggered by 51.161.131.235 (vps-bc97317a.vps.ovh.ca): 1 in ...
show more
(mod_security) mod_security (id:217210) triggered by 51.161.131.235 (vps-bc97317a.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 21:34:04.124892 2026] [security2:error] [pid 19755:tid 19755] [client 51.161.131.235:50970] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||southernreader.com:443|F|4"] [data "CONNECT southernreader.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "southernreader.com"] [uri "/"] [unique_id "am_wDLCH9Gqnqnn7mzIJQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-07-29 06:19:38
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-27 12:19:38
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-19 18:27:03
(2 months ago)
http:scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 09:34:45
(2 months ago)
(mod_security) mod_security (id:217210) triggered by 51.161.131.235 (vps-bc97317a.vps.ovh.ca): 1 in ...
show more
(mod_security) mod_security (id:217210) triggered by 51.161.131.235 (vps-bc97317a.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 05:34:38.407100 2026] [security2:error] [pid 6858:tid 6858] [client 51.161.131.235:35054] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||nrvoutdoors.com:443|F|4"] [data "CONNECT nrvoutdoors.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nrvoutdoors.com"] [uri "/"] [unique_id "akONrjoSym3MzZWYIzSpCQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-04-29 00:02:21
(4 months ago)
2026-04-28 22:33:29 //hkxiaoxin.alianan.cn:4433
2026-04-28 22:24:23 //hkxiaoxin.alianan.cn:4433
2026 ...
show more
2026-04-28 22:33:29 //hkxiaoxin.alianan.cn:4433
2026-04-28 22:24:23 //hkxiaoxin.alianan.cn:4433
2026-04-28 22:25:47 //hkxiaoxin.alianan.cn:4433
show less
Web App Attack
๐ธ๐ช
KIDOS
2026-03-28 19:26:24
(5 months ago)
malicious activity
Web App Attack