๐ซ๐ท
masterguru
2026-08-18 07:02:58
(8 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 74.7.243.128 (US/United States/-): 1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 74.7.243.128 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ต๐ฑ
Budyn
2026-08-17 21:05:04
(18 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: panel.astropot.store | URI: /xmlrpc.php?rsd | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Dorian GRANDHAY
2026-08-17 18:10:18
(21 hours ago)
(PERMBLOCK) 74.7.243.128 (US/United States/-) has had more than 4 temp blocks in the last 604800 sec ...
show more
(PERMBLOCK) 74.7.243.128 (US/United States/-) has had more than 4 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ซ๐ฎ
000rosiu
2026-08-17 15:51:03
(23 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: / | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
filstal.org
2026-08-17 12:09:01
(1 day ago)
Persistent bad bot: repeated automated abuse detected
Bad Web Bot
Web App Attack
Anonymous
2026-08-17 09:57:17
(1 day ago)
Malicious activity detected
Hacking
Web App Attack
๐ซ๐ท
Dorian GRANDHAY
2026-08-15 23:43:29
(2 days ago)
(PERMBLOCK) 74.7.243.128 (US/United States/-) has had more than 4 temp blocks in the last 604800 sec ...
show more
(PERMBLOCK) 74.7.243.128 (US/United States/-) has had more than 4 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ฉ๐ช
Petros Stefanakis
2026-08-15 20:32:59
(2 days ago)
(PERMBLOCK) 74.7.243.128 (US/United States/-) has had more than 4 temp blocks
Hacking
๐ซ๐ฎ
000rosiu
2026-08-15 04:42:26
(3 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: / | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Petros Stefanakis
2026-08-15 03:11:23
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 74.7.243.128 (US/United States/-)
SQL Injection
๐ช๐ธ
librebit
2026-08-15 02:36:09
(3 days ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-12 14:03:54
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 74.7.243.128 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 74.7.243.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 10:03:46.708044 2026] [security2:error] [pid 1656408:tid 1656408] [client 74.7.243.128:60836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||legalnexusbali.legalnexuslawfirm.com|F|2"] [data ".rcube.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "legalnexusbali.legalnexuslawfirm.com"] [uri "/backup/backup-5.17.2020_09-32-45_legalnexusbali/from_old_server/etc/legalnexusbali.com/tyas.rcube.db"] [unique_id "anx9QpAs1rViSWaRIwCzJgAAAAA"], referer: https://legalnexusbali.legalnexuslawfirm.com/backup/backup-5.17.2020_09-32-45_legalnexusbali/from_old_server/etc/legalnexusbali.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Dorian GRANDHAY
2026-08-12 11:23:03
(6 days ago)
(PERMBLOCK) 74.7.243.128 (US/United States/-) has had more than 4 temp blocks in the last 604800 sec ...
show more
(PERMBLOCK) 74.7.243.128 (US/United States/-) has had more than 4 temp blocks in the last 604800 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-12 01:52:32
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 74.7.243.128 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 74.7.243.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 21:52:27.444981 2026] [security2:error] [pid 842152:tid 842152] [client 74.7.243.128:54748] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.test.grimone.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.test.grimone.com"] [uri "/patrick/German/Europe Day 11/Thumbs.db"] [unique_id "anvR2xpzzmF-7tWxBhv0LQAAABI"], referer: https://www.test.grimone.com/patrick/German/Europe%20Day%2011/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-11 22:31:55
(6 days ago)
Excessive multi-domain requests
Brute-Force