π¬π§
consul.to
2026-07-19 16:44:59
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
Site.eu
2026-07-18 22:54:46
(1 day ago)
Excessive multi-domain requests
Brute-Force
π¬π§
consul.to
2026-07-18 14:37:57
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-18 09:47:00
(1 day ago)
(mod_security) mod_security (id:240000) triggered by 135.136.42.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 135.136.42.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 05:46:53.548536 2026] [security2:error] [pid 23983:tid 23983] [client 135.136.42.227:30609] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||arcticwarriors.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "arcticwarriors.org"] [uri "/images/stories/themes.php"] [unique_id "altLjRd91Xspuuuf3lPtqQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
HERA - Operations
2026-07-18 07:58:33
(1 day ago)
sensobox - searching for vulnerable scripts: install.php 2026/07/18 09:58:33
Web App Attack
π¬π§
consul.to
2026-07-17 13:37:06
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
Site.eu
2026-07-17 09:19:41
(2 days ago)
Excessive multi-domain requests
Brute-Force
π«π·
dynamix
2026-07-17 06:45:49
(2 days ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 05:25:25
(2 days ago)
(mod_security) mod_security (id:240000) triggered by 135.136.42.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 135.136.42.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 01:25:16.388949 2026] [security2:error] [pid 312110:tid 312110] [client 135.136.42.227:43581] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||washcountyfair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "washcountyfair.com"] [uri "/images/stories/themes.php"] [unique_id "alm8vC3a6ckl63nUnELCCgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 01:53:52
(2 days ago)
[redacted] 135.136.42.227 - - [17/Jul/2026:03:53:42 +0200] "GET /.well-known/pki-validation/admin.ph ...
show more
[redacted] 135.136.42.227 - - [17/Jul/2026:03:53:42 +0200] "GET /.well-known/pki-validation/admin.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
[redacted] 135.136.42.227 - - [17/Jul/2026:03:53:43 +0200] "GET /wp-includes/IXR/admin.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
[redacted] 135.136.42.227 - - [17/Jul/2026:03:53:43 +0200] "GET /wp-admin/js/index.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0"
[redacted] 135.136.42.227 - - [17/Jul/2026:03:53:45 +0200] "GET /wp-admin/network/network.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0"
[redacted] 135.136.42.227 - - [17/Jul/2026:03:53:45 +0200] "GET /admin/upload/css.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like G
...
show less
Hacking
Web App Attack
π―π΅
beon
2026-07-16 18:03:04
(3 days ago)
[DateTime=>2026-07-16T18:03:04Z to 2026-07-16T18:07:43Z (UTC)] , [HoneyPot_Hits=>974 times] , [Honey ...
show more
[DateTime=>2026-07-16T18:03:04Z to 2026-07-16T18:07:43Z (UTC)] , [HoneyPot_Hits=>974 times] , [HoneyPots=>/bless.php, /O-Simple.php, /lock360.php, /zwso.php, /chosen.php, /about.php and others] , [404targets=>/uploads/94056-upload.phtml, /warm.PhP7, /adminfuns.php7, /xp.php%20, /file.php%20, /about/function.php%20 and others] , [total_Hits=>993 times] , [hit_per_second=>3.55] , [Keyword=>WordPress, file manager scripts, .well-known, PHP web shells]
show less
Bad Web Bot
Web App Attack
Hacking
π¬π§
consul.to
2026-07-16 13:31:08
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
maxpower
2026-07-16 05:55:13
(3 days ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 135.136.42.227 (CN/China/-): 1 in the last 3600 sec ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 135.136.42.227 (CN/China/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 135.136.42.227 - - [16/Jul/2026:07:55:07 +0200] "GET /bless.php HTTP/1.1" 404 30262 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36" "135.136.42.227" host=abruzzotour.it
show less
Port Scan
π³π±
Site.eu
2026-07-16 02:30:51
(3 days ago)
Excessive 404/403 errors
Brute-Force
π«π·
dynamix
2026-07-15 12:44:50
(4 days ago)
Multiple WAF Violations
Web App Attack