๐ท๐ด
clauss
2026-09-02 04:40:28
(2 hours ago)
124.198.131.186 - - [02/Sep/2026:07:40:26 +0300] "GET /1.php HTTP/2.0" 404 20 "http://bucuresti.24fu ...
show more
124.198.131.186 - - [02/Sep/2026:07:40:26 +0300] "GET /1.php HTTP/2.0" 404 20 "http://bucuresti.24fun.ro/1.php" "Go-http-client/1.1"
124.198.131.186 - - [02/Sep/2026:07:40:28 +0300] "GET /wso.php HTTP/2.0" 404 20 "http://bucuresti.24fun.ro/wso.php" "Go-http-client/1.1"
...
show less
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-02 04:12:03
(3 hours ago)
Wordpress malicious attack:[octascan]
Web App Attack
๐ฉ๐ช
maxpower
2026-09-02 03:26:39
(3 hours ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 124.198.131.186 (US/United States/-): 1 in the last ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 124.198.131.186 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 124.198.131.186 - - [02/Sep/2026:05:26:35 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/2.0" 200 4736 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" "124.198.131.186" host=notaiopanella.it
show less
Port Scan
๐ซ๐ท
Tilellit.PRO
2026-09-02 01:55:22
(5 hours ago)
Malicious or fake user-agent string used to bypass scraping restrictions
Web App Attack
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-09-02 01:29:33
(5 hours ago)
124.198.131.186 - - [02/Sep/2026:03:29:33 +0200] "GET / HTTP/1.1" 403 3087 "-" "Mozlila/5.0 (Linux; ...
show more
124.198.131.186 - - [02/Sep/2026:03:29:33 +0200] "GET / HTTP/1.1" 403 3087 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
124.198.131.186 - - [02/Sep/2026:03:29:33 +0200] "GET /wp-content/themes/seotheme/db.php?u= HTTP/1.1" 403 498 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
124.198.131.186 - - [02/Sep/2026:03:29:33 +0200] "POST /ALFA_DATA/alfacgiapi/perl.alfa HTTP/1.1" 403 498 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
124.198.131.186 - - [02/Sep/2026:03:29:33 +0200] "POST /wp-plain.php HTTP/1.1" 403 498 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-02 01:18:52
(6 hours ago)
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozlila/5 ...
show more
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112. (+1 more) | path: /wp-content/themes/seotheme/db.php (+3 more) | 2026-09-02 01:18 UTC
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2026-09-01 23:45:43
(7 hours ago)
02/Sep/2026:01:45:43.182829 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
02/Sep/2026:01:45:43.182829 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 124.198.131.186] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at REQUEST_COOKIES:g. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: echo found within REQUEST_COOKIES:g: echo Sp3ctra"] [severity "CRITICAL"] [ver
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
0xffffffff
2026-09-01 22:53:48
(8 hours ago)
[2026-09-02 01:53:46.383488] [authz_core:error] [pid 2614489:tid 137763898459840] [client 124.198.13 ...
show more
[2026-09-02 01:53:46.383488] [authz_core:error] [pid 2614489:tid 137763898459840] [client 124.198.131.186:0] AH01630: client denied by server configuration: /var/www/*/wp-content/themes/seotheme, referer www.google.com , error_notes:wp:include-files , URI:'/wp-content/themes/seotheme/db.php?u'
[2026-09-02 01:53:46.403570] [authz_core:error] [pid 2614489:tid 137763890067136] [client 124.198.131.186:0] AH01630: client denied by server configuration: /var/www/*/ALFA_DATA, referer www.google.com , error_notes:alfa-shell , URI:'/ALFA_DATA/alfacgiapi/perl.alfa'
[2026-09-02 01:53:46.434010] [authz_core:error] [pid 2614488:tid 137763873281728] [client 124.198.131.186:0] AH01630: client denied by server configuration: /var/www/*/wp-content/plugins/fix , error_notes:wp:include-files , URI:'/wp-content/plugins/fix/up.php'
[2026-09-02 01:53:46.403570] [authz_core:error] [pid 2614489:tid 137763890067136] [client 124.198.131.186:0] AH01630: client denied by server configuration: /var/www/*/ALFA_DATA, referer www.google.com
show less
Web App Attack
Bad Web Bot
๐ช๐ธ
el-brujo
2026-09-01 21:46:44
(9 hours ago)
01/Sep/2026:23:46:43.924262 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
01/Sep/2026:23:46:43.924262 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 124.198.131.186] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at REQUEST_COOKIES:g. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: echo found within REQUEST_COOKIES:g: echo Sp3ctra"] [severity "CRITICAL"] [ver
...
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 20:01:53
(11 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST (+1 mor ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST (+1 more) | path: /wp-plain.php (+3 more) | 2026-09-01 20:01 UTC
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-09-01 19:48:45
(11 hours ago)
01/Sep/2026:21:48:44.932248 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
01/Sep/2026:21:48:44.932248 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 124.198.131.186] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at REQUEST_COOKIES:g. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: echo found within REQUEST_COOKIES:g: echo Sp3ctra"] [severity "CRITICAL"] [ver
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-01 19:25:44
(11 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /ALFA_DATA/ (Match: /ALFA_DATA/)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-09-01 19:16:11
(12 hours ago)
vulnerability scan
Web App Attack
๐ฆ๐บ
clapper
2026-09-01 19:14:00
(12 hours ago)
(mod_security) mod_security (id:980001) triggered by 124.198.131.186 (US/United States/-): 5 in the ...
show more
(mod_security) mod_security (id:980001) triggered by 124.198.131.186 (US/United States/-): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
Skyrider
2026-09-01 19:05:42
(12 hours ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack