๐บ๐ธ
mw
2026-07-20 00:00:24
(12 hours ago)
POST /wp-admin/admin-ajax.php HTTP/1.1
Web App Attack
๐ท๐บ
DZBOT
2026-07-19 13:03:31
(22 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 11:45:41
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 07:45:34.259063 2026] [security2:error] [pid 26488:tid 26494] [client 102.158.2.96:45765] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||liquido.cocoonprojects.com|F|2"] [data ".cocoonprojects.com.key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "liquido.cocoonprojects.com"] [uri "/ssl/liquido.cocoonprojects.com.key"] [unique_id "aly43tQVkQa3ZyLuWcLuAgAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-19 11:05:03
(1 day ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=21
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-19 11:03:24
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 07:03:20.235206 2026] [security2:error] [pid 3414916:tid 3414916] [client 102.158.2.96:41949] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gubbio.name|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gubbio.name"] [uri "/ftps.ini"] [unique_id "alyu-Or6b9iEgWjqPFK5-gAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-07-19 10:45:39
(1 day ago)
Detected env_leak attack from WP-host.
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-07-19 09:32:52
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 09:29:01
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 05:28:55.285976 2026] [security2:error] [pid 24879:tid 24879] [client 102.158.2.96:51329] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thecrimsonpirate.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecrimsonpirate.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "alyY11kL4t-YRGlKeT4GFQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-19 08:27:01
(1 day ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-07-19 08:13:04
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-19 06:45:12
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 02:44:59.677309 2026] [security2:error] [pid 1402947:tid 1402947] [client 102.158.2.96:5038] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "experimentalscene.com"] [uri "/db.sql"] [unique_id "alxya-oeKLHPlL1fIkqvZAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 06:19:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 102.158.2.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 02:19:21.991211 2026] [security2:error] [pid 990:tid 990] [client 102.158.2.96:63200] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jamesrobertparish.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jamesrobertparish.com"] [uri "/privatekey.key"] [unique_id "alxsaefqlIuGeYG1qm0mFQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-07-19 06:18:05
(1 day ago)
Malicious web traffic detected by CrowdSec
Hacking
๐บ๐ธ
nyt
2026-07-19 05:15:55
(1 day ago)
Accessing non-existent admin database page, Sensitive File Probe
Web App Attack
๐ณ๐ฑ
melroy89
2026-07-19 04:52:31
(1 day ago)
102.158.2.96 - - [19/Jul/2026:06:51:33 +0200] "GET /application.json HTTP/1.1" 404 189 "-" "Mozilla ...
show more
102.158.2.96 - - [19/Jul/2026:06:51:33 +0200] "GET /application.json HTTP/1.1" 404 189 "-" "Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15" "blog.melroy.org" 0.000
102.158.2.96 - - [19/Jul/2026:06:51:33 +0200] "GET /settings.json HTTP/1.1" 404 207 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" "blog.melroy.org" 0.000
102.158.2.96 - - [19/Jul/2026:06:51:33 +0200] "GET /conf.json HTTP/1.1" 404 189 "-" "Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.4" "blog.melroy.org" 0.000
102.158.2.96 - - [19/Jul/2026:06:51:33 +0200] "GET /configuration.json HTTP/1.1" 404 189 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/601.1.56 (KHTML, like Gecko) Version/9.0 Safari/601.1.56" "blog.melroy.org" 0.000
102.158.2.96 - - [19/Jul/2026:06:51:33 +0200] "GET /config.dev.json HTTP/1.1" 404 189 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) G
...
show less
Web App Attack