๐จ๐ญ
backslash
2026-06-05 13:42:04
(2 weeks ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
๐ฉ๐ช
Vegascosmetics
2026-05-29 05:49:37
(3 weeks ago)
Kingcopy(AI-IDS):IP is Probing for Multiple vulnerabilities WTF:Banned
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-16 22:28:01
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 140.235.1.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 140.235.1.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 18:27:52.061130 2026] [security2:error] [pid 12681:tid 12681] [client 140.235.1.160:53883] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Logan 3014/Thumbs.db"] [unique_id "agjvaDLI2oVEmTQkXg2UFQAAAA4"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Logan%203014/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-04-29 04:48:00
(1 month ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-10 02:09:33
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 140.235.1.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 140.235.1.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 22:09:25.702961 2026] [security2:error] [pid 29499:tid 29499] [client 140.235.1.160:34991] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||evolute.io|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "evolute.io"] [uri "/"] [unique_id "aa99VU_LpQMZXwUMkku8XAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Block Rockin' Beats
2026-02-25 15:52:19
(3 months ago)
Attempted Wordpress exploit
Hacking
Web App Attack
๐บ๐ธ
Psycho Solutions LLC
2026-02-18 04:20:36
(4 months ago)
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N ...
show more
Detected Wordpress Scanning. - Request Method: GET - Target: {PC} wp-login.php - User Agent: N/A - Timestamp: 2/18/2026 4:20 am (UTC-6)
show less
Web App Attack
Bad Web Bot
Web Spam
Hacking
Anonymous
2026-02-09 09:21:33
(4 months ago)
"POST /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
๐ง๐ช
voormedia
2026-02-09 05:09:15
(4 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ฆ๐ท
RocketEmi
2026-02-09 00:50:36
(4 months ago)
They are probing for vulnerable files to hack my website.
Hacking
๐ฉ๐ช
MusicLibrary
2026-02-08 21:09:55
(4 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
๐ฎ๐ฉ
sockominfo
2026-02-08 18:00:11
(4 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-02-08 17:44:47
(4 months ago)
140.235.1.160 - - [08/Feb/2026:19:44:47 +0200] "POST /xmlrpc.php HTTP/1.1" 404 2935 "-" "Mozilla/5.0 ...
show more
140.235.1.160 - - [08/Feb/2026:19:44:47 +0200] "POST /xmlrpc.php HTTP/1.1" 404 2935 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0"
140.235.1.160 - - [08/Feb/2026:19:44:47 +0200] "POST /xmlrpc.php HTTP/1.1" 404 2936 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0"
...
show less
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-08 16:50:33
(4 months ago)
[WAZUH] Mixed case extension detected (case variation bypass)
Hacking
Web App Attack
๐ฌ๐ง
Bytemark
2026-02-08 15:47:38
(4 months ago)
140.235.1.160 - - [08/Feb/2026:15:47:33 +0000] "POST /xmlrpc.php HTTP/1.1" 301 5856 "-" "Mozilla/5.0 ...
show more
140.235.1.160 - - [08/Feb/2026:15:47:33 +0000] "POST /xmlrpc.php HTTP/1.1" 301 5856 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0"
140.235.1.160 - - [08/Feb/2026:15:47:33 +0000] "POST /xmlrpc.php HTTP/1.1" 301 5856 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0"
140.235.1.160 - - [08/Feb/2026:15:47:36 +0000] "GET /xmlrpc.php HTTP/1.1" 404 5657 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0"
140.235.1.160 - - [08/Feb/2026:15:47:37 +0000] "GET /xmlrpc.php HTTP/1.1" 404 5657 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0"
show less
Brute-Force
Web App Attack