๐ต๐ฑ
lns.bz
2026-07-30 15:34:16
(1 hour ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ฉ๐ช
stinpriza
2026-07-30 14:39:21
(2 hours ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 12:59:31
(4 hours ago)
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 08:59:27.777887 2026] [security2:error] [pid 3805:tid 3805] [client 150.136.92.243:16152] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:author_exclude. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||grexicon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "grexicon.com"] [uri "/"] [unique_id "amtKrwW_0arfsgukTeM3XQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 11:55:33
(5 hours ago)
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 07:55:28.124298 2026] [security2:error] [pid 1010253:tid 1010253] [client 150.136.92.243:30286] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:author_exclude. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||ferrarapanfitness.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "ferrarapanfitness.com"] [uri "/"] [unique_id "ams7sFTya6_q705_MeucugAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 11:23:42
(5 hours ago)
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 07:23:34.870298 2026] [security2:error] [pid 421089:tid 421089] [client 150.136.92.243:11060] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:author_exclude. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||fernfield.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "fernfield.com"] [uri "/"] [unique_id "ams0Ns2X2hOZ_vCl81Fq2QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-30 11:15:02
(5 hours ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-30 10:34:30
(6 hours ago)
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 06:34:22.695469 2026] [security2:error] [pid 1880846:tid 1880846] [client 150.136.92.243:9620] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:author_exclude. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||jesussotoca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "jesussotoca.com"] [uri "/"] [unique_id "amsorp-eMJvYXQTJ2-aByAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-30 10:25:45
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ง๐ช
taivas.nl
2026-07-30 09:32:10
(7 hours ago)
Bad_requests
Bad Web Bot
๐ฌ๐ง
gigatech
2026-07-30 08:55:04
(8 hours ago)
Webserver Probing
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-30 08:51:44
(8 hours ago)
Modsecurity: probe or injection attempt
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 08:33:57
(8 hours ago)
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218580) triggered by 150.136.92.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 04:33:49.815131 2026] [security2:error] [pid 964430:tid 964430] [client 150.136.92.243:13584] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:author_exclude. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||insidepublications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "insidepublications.com"] [uri "/"] [unique_id "amsMbf6jecc-vB-hR8qCnAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-30 08:28:13
(8 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-195 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "python" at REQUEST_HEADERS:User-Agent. (1100000-195)
show less
Bad Web Bot
๐ฉ๐ช
4server
2026-07-30 07:51:36
(9 hours ago)
[ThuJul3009:51:34.3902202026][security2:error][pid2665425:tid2665481][client150.136.92.243:0]ModSecu ...
show more
[ThuJul3009:51:34.3902202026][security2:error][pid2665425:tid2665481][client150.136.92.243:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"dgtime.ch\"][uri\"/\"][unique_id\"amsChvz8KJCSlDePBGUrqwAAAFM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-30 07:37:09
(9 hours ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack