🇺🇸
TPI-Abuse
2026-09-13 10:15:49
(2 hours ago)
(mod_security) mod_security (id:218420) triggered by 13.140.172.132 (vmi3556634.contaboserver.net): ...
show more
(mod_security) mod_security (id:218420) triggered by 13.140.172.132 (vmi3556634.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 06:15:41.679722 2026] [security2:error] [pid 29400:tid 29400] [client 13.140.172.132:40138] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "38"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.151.37:443|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.151.37"] [uri "/hello.world"] [unique_id "aqZ3zV_20ai-acQUuPzhiQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 10:10:42
(2 hours ago)
2222/tcp (1 or more attempts)
Port Scan
🇳🇱
Savvii
2026-09-13 09:36:19
(3 hours ago)
20 attempts against mh-ssh on cmdb
Brute-Force
SSH
🇩🇪
ghostwarriors
2026-09-13 09:20:09
(3 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇱🇹
sobakintech
2026-09-13 09:15:55
(3 hours ago)
Detected by CrowdSec on Traefik reverse proxy: crowdsecurity/thinkphp-cve-2018-20062
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-13 08:46:02
(3 hours ago)
Bot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/. ...
show more
Bot / scanning and/or hacking attempts: POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e
show less
Hacking
Web App Attack
🇧🇾
lns.bz
2026-09-13 08:32:36
(4 hours ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-09-13 08:08:17
(4 hours ago)
[13/Sep/2026:18:08:16 +1000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh ...
show more
[13/Sep/2026:18:08:16 +1000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 266 "libredtail-http"
show less
Hacking
Web App Attack
🇳🇱
Selckie
2026-09-13 07:51:43
(4 hours ago)
fail2ban: NGINX unusual impact
Web App Attack
🇩🇪
mxpgmbh
2026-09-13 07:45:29
(5 hours ago)
2026-09-13T09:44:54.394437+02:00 **** sshd-session[48267]: pam_unix(sshd:auth): authentication failu ...
show more
2026-09-13T09:44:54.394437+02:00 **** sshd-session[48267]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=13.140.172.132 user=root
2026-09-13T09:44:56.628456+02:00 **** sshd-session[48267]: Failed password for root from 13.140.172.132 port 38230 ssh2
2026-09-13T09:45:26.868169+02:00 **** sshd-session[48844]: Invalid user **** from 13.140.172.132 port 49254
2026-09-13T09:45:26.869455+02:00 **** sshd-session[48844]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=13.140.172.132
2026-09-13T09:45:28.597659+02:00 **** sshd-session[48844]: Failed password for invalid user **** from 13.140.172.132 port 49254 ssh2
show less
Brute-Force
SSH
🇺🇸
RAP
2026-09-13 07:34:28
(5 hours ago)
2026-09-13 07:34:28 UTC Unauthorized activity to TCP port 23. Telnet
Port Scan
🇺🇸
TPI-Abuse
2026-09-13 07:34:24
(5 hours ago)
(mod_security) mod_security (id:218420) triggered by 13.140.172.132 (vmi3556634.contaboserver.net): ...
show more
(mod_security) mod_security (id:218420) triggered by 13.140.172.132 (vmi3556634.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:34:19.572635 2026] [security2:error] [pid 2378:tid 2378] [client 13.140.172.132:59214] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.149:80|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.149"] [uri "/hello.world"] [unique_id "aqZR-9doBSUEnd7UrDaQXAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 07:14:49
(5 hours ago)
(mod_security) mod_security (id:218420) triggered by 13.140.172.132 (vmi3556634.contaboserver.net): ...
show more
(mod_security) mod_security (id:218420) triggered by 13.140.172.132 (vmi3556634.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:14:45.714289 2026] [security2:error] [pid 24977:tid 24977] [client 13.140.172.132:48654] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.174:443|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.174"] [uri "/hello.world"] [unique_id "aqZNZejrYWaYY3aEToSznwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-13 07:12:18
(5 hours ago)
Host header is a numeric IP address. Pattern match "^ (920350-131)
Hacking
Bad Web Bot
🇮🇪
AutosOnShow
2026-09-13 07:06:05
(5 hours ago)
blocked for webapp attack | path requested: /index.php | seen at 2026-09-13 07:05:39.566 |
Web App Attack