๐บ๐ธ
TPI-Abuse
2026-05-17 05:14:32
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 157.15.40.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.40.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 01:14:25.846680 2026] [security2:error] [pid 29140:tid 29140] [client 157.15.40.60:63502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pierrebastin.com"] [uri "/sftp-config.json"] [unique_id "aglOsZ7bPKZK9dxMX5hSDgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nodepile
2026-05-15 07:45:13
(2 weeks ago)
Requests denied due to active blacklist hits (tenant=82 method=GET path=/ ua='Mozilla/5.0 (Windows N ...
show more
Requests denied due to active blacklist hits (tenant=82 method=GET path=/ ua='Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.168 Safari/537.36')
show less
Web App Attack
Exploited Host
๐ฎ๐ฉ
sockominfo
2026-05-13 18:00:48
(3 weeks ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-13 17:00:13
(3 weeks ago)
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Repo ...
show more
Late night login (22:00-05:30) - High risk Jakarta timezone (WIB). Threat Score: 8.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-06 01:42:37
(4 weeks ago)
157.15.40.60 - - [06/May/2026:04:42:36 +0300] "GET /blog/wp-includes/fonts/iqb.php HTTP/1.1" 404 628 ...
show more
157.15.40.60 - - [06/May/2026:04:42:36 +0300] "GET /blog/wp-includes/fonts/iqb.php HTTP/1.1" 404 628 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-05 08:23:45
(4 weeks ago)
157.15.40.60 - - [05/May/2026:11:23:44 +0300] "GET /blog/wp-includes/fonts/dev.php HTTP/1.1" 404 628 ...
show more
157.15.40.60 - - [05/May/2026:11:23:44 +0300] "GET /blog/wp-includes/fonts/dev.php HTTP/1.1" 404 628 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
157.15.40.60 - - [05/May/2026:11:23:44 +0300] "GET /blog/wp-includes/fonts/iqb.php HTTP/1.1" 404 628 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-05-05 05:28:52
(4 weeks ago)
PAD: Scan_404,No_Ref detected
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-05-05 03:05:49
(4 weeks ago)
157.15.40.60 - - [05/May/2026:06:05:49 +0300] "GET /blog/wp-includes/fonts/iqb.php HTTP/1.1" 404 628 ...
show more
157.15.40.60 - - [05/May/2026:06:05:49 +0300] "GET /blog/wp-includes/fonts/iqb.php HTTP/1.1" 404 628 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-04 17:05:30
(4 weeks ago)
157.15.40.60 - - [04/May/2026:20:05:28 +0300] "GET /blog/wp-includes/fonts/dev.php HTTP/1.1" 404 628 ...
show more
157.15.40.60 - - [04/May/2026:20:05:28 +0300] "GET /blog/wp-includes/fonts/dev.php HTTP/1.1" 404 628 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
157.15.40.60 - - [04/May/2026:20:05:28 +0300] "GET /blog/wp-includes/fonts/iqb.php HTTP/1.1" 404 628 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-04 00:59:23
(1 month ago)
LF_CPANEL: (cpanel) Failed cPanel login from 157.15.40.60 (ID/Indonesia/-): 1 in the last 3600 secs
Brute-Force
๐ฎ๐ฉ
Burayot
2026-05-02 13:07:51
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 157.15.40.60 (ID/Indonesia/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 157.15.40.60 (ID/Indonesia/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฌ๐ง
Greg Poulson
2026-05-01 21:00:04
(1 month ago)
Our website was hit by this DDOS at a rate of 366 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐ง๐ช
voormedia
2026-05-01 02:05:28
(1 month ago)
Accessed trap at '/wp-admin/install.php'
Web App Attack
๐บ๐ธ
nyt
2026-05-01 00:04:04
(1 month ago)
Hacking, Web App Attack, suspicious: Web Shell Probe
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-04-30 20:59:24
(1 month ago)
Multiple WAF Violations
Web App Attack