๐บ๐ธ
TPI-Abuse
2026-09-02 19:04:49
(8 hours ago)
(mod_security) mod_security (id:220150) triggered by 146.70.40.171 (scolex.locategic.com): 1 in the ...
show more
(mod_security) mod_security (id:220150) triggered by 146.70.40.171 (scolex.locategic.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 15:04:43.352342 2026] [security2:error] [pid 1636219:tid 1636242] [client 146.70.40.171:59415] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:return. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||seips.org|F|2"] [data "viewitem.php?id=495/**//**/union/**//**/selectnull,null,null,null,null,null,null,null,null,null,null,null,null,null---"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "seips.org"] [uri "/newuser.php"] [unique_id "aphzS6LIMjJhp8a7vfcY1AAAAA0"], referer: https://seips.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 17:15:07
(10 hours ago)
(mod_security) mod_security (id:220150) triggered by 146.70.40.171 (scolex.locategic.com): 1 in the ...
show more
(mod_security) mod_security (id:220150) triggered by 146.70.40.171 (scolex.locategic.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:14:58.514517 2026] [security2:error] [pid 27186:tid 27186] [client 146.70.40.171:43269] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:option. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||southtncardio.com|F|2"] [data "com_sppagebuilder/**//**/union/**//**/selectnull,null,null,null,null,null,null,null,null,null,null,null,null,null---"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "southtncardio.com"] [uri "/index.php"] [unique_id "aphZkhb5erd0oK5QG2P7wAAAAAY"], referer: http://southtncardio.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 16:19:47
(11 hours ago)
SQL injection, multiple attempts.
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-02 14:11:01
(13 hours ago)
(mod_security) mod_security (id:220150) triggered by 146.70.40.171 (scolex.locategic.com): 1 in the ...
show more
(mod_security) mod_security (id:220150) triggered by 146.70.40.171 (scolex.locategic.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:10:55.025570 2026] [security2:error] [pid 6025:tid 6025] [client 146.70.40.171:53739] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:main_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||www.nchsfootballgolfouting.com|F|2"] [data "product_info/**//**/union/**//**/selectnull,null,null,null,null,null,null---"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.nchsfootballgolfouting.com"] [uri "/index.php"] [unique_id "apgub87cn2eZLnCqvZJnJQAAAA8"], referer: https://www.nchsfootballgolfouting.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-02 12:53:29
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 146.70.40.171 (FR/France/scolex.locateg ...
show more
(mod_security) mod_security triggered on hostname [redacted] 146.70.40.171 (FR/France/scolex.locategic.com)
show less
SQL Injection
๐ฉ๐ช
britishrock
2026-09-02 12:09:17
(15 hours ago)
Automated Block: HACK in URI: extractvalue
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-02 12:01:41
(15 hours ago)
(mod_security) mod_security (id:220150) triggered by 146.70.40.171 (scolex.locategic.com): 1 in the ...
show more
(mod_security) mod_security (id:220150) triggered by 146.70.40.171 (scolex.locategic.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:01:35.641194 2026] [security2:error] [pid 22724:tid 22724] [client 146.70.40.171:35921] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.*\\\\*\\\\/)?select)" at ARGS:enttype. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5671"] [id "220150"] [rev "4"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||kountz.org|F|2"] [data "f'/**//**/union/**//**/selectnull---"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kountz.org"] [uri "/suggest.php"] [unique_id "apgQH54i4v6DFij_WKplZAAAAAU"], referer: http://kountz.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-02 11:58:40
(15 hours ago)
[SQL UNION SELECT] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(UNION%20| ...
show more
[SQL UNION SELECT] f2b match %{+Q}r for ^.*haproxy\[[0-9]+\]: <HOST>:.* (GET |POST ).*\?.*(UNION%20|union%20|SELECT%20|select%20).* HTTP/1.1$
show less
SQL Injection
Anonymous
2026-09-02 11:30:07
(15 hours ago)
| Multiple SQL injection attempts from same source ip.(multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฌ๐ง
gbzret4d
2026-02-23 15:28:15
(6 months ago)
Honeypot [uk-production01]: Suspicious payload (possible command injection); 8728 [1] TCP
Hacking
๐ต๐ฑ
sefinek.net
2026-02-23 15:25:32
(6 months ago)
Honeypot hit: Suspicious payload (possible command injection); 8728 [1] TCP
Reported by: https://git ...
show more
Honeypot hit: Suspicious payload (possible command injection); 8728 [1] TCP
Reported by: https://github.com/sefinek/T-Pot-To-AbuseIPDB
show less
Hacking