๐ซ๐ท
masterguru
2026-06-03 13:46:01
(16 hours ago)
PHP Injection Attack: High-Risk PHP Function Name Found. Matched phrase "call_user_func" at ARGS:fun ...
show more
PHP Injection Attack: High-Risk PHP Function Name Found. Matched phrase "call_user_func" at ARGS:function. (933150-195)
show less
Hacking
๐ฉ๐ช
EGP Abuse Dept
2026-06-03 00:43:26
(1 day ago)
Scanning for web/db/file exploits on www.sdi-aop.org
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:10:17
(1 day ago)
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwcl ...
show more
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwclouds-dns.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:10:13.299599 2026] [security2:error] [pid 5105:tid 5105] [client 124.70.140.201:47546] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||engineeringarts.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?s=index/\\x5cthink\\x5capp/invokefunction&function=call_user_func_array&vars%5B0%5D=think\\x5c__include_file&vars%5B1%5D%5B%5D=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "engineeringarts.com"] [uri "/index.php"] [unique_id "ah8AZWcNPRGa7iSDKxccfAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-06-02 09:27:44
(1 day ago)
scans/SQL injection/spam posts : 54 queries
Web App Attack
SQL Injection
๐ซ๐ท
dynamix
2026-06-01 18:48:45
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 18:09:31
(2 days ago)
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwcl ...
show more
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwclouds-dns.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 14:09:25.210461 2026] [security2:error] [pid 14251:tid 14251] [client 124.70.140.201:60662] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||protection4allsecurity.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?s=index/\\x5cthink\\x5capp/invokefunction&function=call_user_func_array&vars%5B0%5D=think\\x5c__include_file&vars%5B1%5D%5B%5D=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "protection4allsecurity.com"] [uri "/index.php"] [unique_id "ah3K1WltJaulRS6nBFzOKwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 08:16:21
(2 days ago)
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwcl ...
show more
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwclouds-dns.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 04:16:16.401236 2026] [security2:error] [pid 21079:tid 21097] [client 124.70.140.201:38726] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||buy-directv.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?s=index/\\x5cthink\\x5capp/invokefunction&function=call_user_func_array&vars%5B0%5D=think\\x5c__include_file&vars%5B1%5D%5B%5D=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buy-directv.com"] [uri "/index.php"] [unique_id "ah0_0Bbrh0lladlzSULBIwAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 12:14:36
(4 days ago)
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwcl ...
show more
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwclouds-dns.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 08:14:27.902041 2026] [security2:error] [pid 16270:tid 16270] [client 124.70.140.201:60958] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||lordcain.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?s=index/\\x5cthink\\x5capp/invokefunction&function=call_user_func_array&vars%5B0%5D=think\\x5c__include_file&vars%5B1%5D%5B%5D=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lordcain.net"] [uri "/index.php"] [unique_id "ahrUo9k31Iqka9Ersc4CggAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 19:16:52
(6 days ago)
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwcl ...
show more
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwclouds-dns.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 15:16:45.450419 2026] [security2:error] [pid 11632:tid 11632] [client 124.70.140.201:48536] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||weirdlovemakers.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?s=index/\\x5cthink\\x5capp/invokefunction&function=call_user_func_array&vars%5B0%5D=think\\x5c__include_file&vars%5B1%5D%5B%5D=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weirdlovemakers.com"] [uri "/index.php"] [unique_id "ahiUnSTGCjEhUcEVQyi61gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
RoboSOC
2026-05-28 06:43:20
(6 days ago)
ThinkPHP Remote Code Execution Vulnerability , PTR: ecs-124-70-140-201.compute.hwclouds-dns.com.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 03:26:21
(1 week ago)
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwcl ...
show more
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwclouds-dns.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 23:26:13.854456 2026] [security2:error] [pid 6578:tid 6578] [client 124.70.140.201:50038] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||southshorestreetrods.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?s=index/\\x5cthink\\x5capp/invokefunction&function=call_user_func_array&vars%5B0%5D=think\\x5c__include_file&vars%5B1%5D%5B%5D=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southshorestreetrods.com"] [uri "/index.php"] [unique_id "ahZkVTOqfqyp1wKyLeVygAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 01:30:03
(1 week ago)
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwcl ...
show more
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwclouds-dns.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 21:29:58.075179 2026] [security2:error] [pid 25972:tid 25972] [client 124.70.140.201:35906] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||postalfables.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?s=index/\\x5cthink\\x5capp/invokefunction&function=call_user_func_array&vars%5B0%5D=think\\x5c__include_file&vars%5B1%5D%5B%5D=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "postalfables.com"] [uri "/index.php"] [unique_id "ahZJFnPJB3HyWK4zpefvyQAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-05-27 00:42:40
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 01:24:19
(1 week ago)
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwcl ...
show more
(mod_security) mod_security (id:211190) triggered by 124.70.140.201 (ecs-124-70-140-201.compute.hwclouds-dns.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 21:24:12.971491 2026] [security2:error] [pid 27558:tid 27657] [client 124.70.140.201:58328] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.vote4joegardner.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?s=index/\\x5cthink\\x5capp/invokefunction&function=call_user_func_array&vars%5B0%5D=think\\x5c__include_file&vars%5B1%5D%5B%5D=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vote4joegardner.com"] [uri "/index.php"] [unique_id "ahT2PEnNOLH5_DJw7I82GgAAAoU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-05-24 10:32:29
(1 week ago)
ece-12 : Block return, carriage return, ... characters=>/?s=/manage/\think\view\driver\php/display&a ...
show more
ece-12 : Block return, carriage return, ... characters=>/?s=/manage/\think\view\driver\php/display&content=%3C?php%20phpinfo();?%3E(>)
show less
Hacking