Anonymous
2026-06-14 06:57:27
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted] 104.164.168.11 (VN/Vietnam/-)
SQL Injection
๐จ๐ญ
backslash
2026-04-16 14:48:00
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ซ๐ท
Octopuce
2026-04-16 14:42:38
(4 months ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/hello-plus/classes/ehp-sarang.php /wp ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/hello-plus/classes/ehp-sarang.php /wp-content/plugins/so-pinyin-slugs/inc/main_j ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 09:37:28
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 104.164.168.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:234930) triggered by 104.164.168.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 05:37:20.539144 2026] [security2:error] [pid 463171:tid 463171] [client 104.164.168.11:54815] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||guldunyayayinlari.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "guldunyayayinlari.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aeCt0M8JKDqY7jP_H3bnmAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 07:02:38
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 104.164.168.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:234930) triggered by 104.164.168.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 03:02:31.730801 2026] [security2:error] [pid 1708137:tid 1708137] [client 104.164.168.11:55623] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6787"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||chrisamedee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "chrisamedee.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aeCJh4ZuSqzFBZmzcnBUIwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-04-16 04:25:43
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mawan
2026-04-15 14:21:21
(4 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-04-02 07:55:28
(5 months ago)
BruteForce IMAP/POP3/SMTP
Brute-Force
๐ฉ๐ช
georgengelmann
2026-04-01 00:31:39
(5 months ago)
Failed login attempt for rosalynhocking4
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-02-23 10:06:56
(6 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-02-23 08:32:06
(6 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
myagent.site
2026-02-23 00:20:06
(6 months ago)
Blocking for trying to access an exploit file: /vendor/phpunit/phpunit/src/Util/PHP/
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-22 22:36:25
(6 months ago)
(mod_security) mod_security (id:240000) triggered by 104.164.168.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 104.164.168.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 17:36:20.248000 2026] [security2:error] [pid 23766:tid 23766] [client 104.164.168.11:42685] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "87"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||informant-systems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "informant-systems.com"] [uri "/images/stories/themes.php"] [unique_id "aZuE5AMyAbnZPzdSmMe8tQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-13 06:12:40
(6 months ago)
104.164.168.11 - - [13/Feb/2026:06:12:36 +0000] "GET /wp-includes/block-supports/autoload_classmap.p ...
show more
104.164.168.11 - - [13/Feb/2026:06:12:36 +0000] "GET /wp-includes/block-supports/autoload_classmap.php HTTP/1.1" 302 624 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
104.164.168.11 - - [13/Feb/2026:06:12:37 +0000] "GET /wp-admin/network/network.php HTTP/1.1" 302 584 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
104.164.168.11 - - [13/Feb/2026:06:12:37 +0000] "GET /wp-admin/file.php
...
show less
Web App Attack
๐ณ๐ฟ
Antinson
2026-02-13 04:08:12
(6 months ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot