๐ฉ๐ช
ghostwarriors
2026-07-31 18:21:16
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:08:08
(2 months ago)
(mod_security) mod_security (id:211540) triggered by 157.230.226.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211540) triggered by 157.230.226.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:08:00.396847 2026] [security2:error] [pid 1905855:tid 1905855] [client 157.230.226.95:52862] ModSecurity: Access denied with code 403 (phase 2). Match of "contains /wp-json/yoast/" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "17"] [id "211540"] [rev "14"] [msg "COMODO WAF: Blind SQL Injection Attack||goglobex.com|F|2"] [data "Matched Data: WAITFOR DELAY found within REQUEST_URI: /service/~iufo/com.ufida.web.action.ActionServlet?action=nc.ui.iufo.release.ReleaseRepMngAction&method=updateDelFlag&TableSelectedID=1%27);WAITFOR+DELAY+%270:0:6%27--"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "goglobex.com"] [uri "/service/~iufo/com.ufida.web.action.ActionServlet"] [unique_id "amGhsNs3InhS_6GaOdv2JAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-21 11:38:03
(2 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-20 17:17:37
(2 months ago)
(mod_security) mod_security (id:211190) triggered by 157.230.226.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 157.230.226.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:17:30.600831 2026] [security2:error] [pid 29002:tid 29002] [client 157.230.226.95:55200] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||acme-aviation.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /export/classroom-course-statistics?fileNames[]=../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acme-aviation.com"] [uri "/export/classroom-course-statistics"] [unique_id "al5YKlrSCWm-DrJgfnRfBgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 01:07:49
(2 months ago)
(mod_security) mod_security (id:218420) triggered by 157.230.226.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218420) triggered by 157.230.226.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 21:07:44.775507 2026] [security2:error] [pid 2310888:tid 2310888] [client 157.230.226.95:41788] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||ritterlien.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input: -d allow_url_include=on -d auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "ritterlien.com"] [uri "/index.php"] [unique_id "al104DSoHwyhfUULHRR5NAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-18 21:20:05
(2 months ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
Ghost Rider
2026-07-18 02:29:00
(2 months ago)
RdpGuard detected brute-force attempt on RDP
Brute-Force
๐บ๐ธ
lifelightweb
2026-07-17 21:11:00
(2 months ago)
Web App Attack
๐จ๐ฆ
Mediashaker
2026-07-17 20:59:46
(2 months ago)
(CT) IP 157.230.226.95 (US/United States/-) found to have 851 connections
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 18:58:35
(2 months ago)
(mod_security) mod_security (id:211190) triggered by 157.230.226.95 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 157.230.226.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 14:58:31.503680 2026] [security2:error] [pid 18571:tid 18571] [client 157.230.226.95:47398] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||idahostem.org|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /export/classroom-course-statistics?fileNames[]=../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idahostem.org"] [uri "/export/classroom-course-statistics"] [unique_id "alp7V_6xamX_wu3MvgL3hAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-16 09:30:01
(2 months ago)
ModSecurity rule 949110 triggered on wp2. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
Anonymous
2026-05-26 01:51:23
(4 months ago)
unsolicited connect TCP dport 8808 (sport 61006)
Hacking
๐ฌ๐ง
PeravixGroup
2026-05-26 01:22:37
(4 months ago)
Honeypot detection: Remote Desktop Protocol (RDP) brute-force attempt on port 3389. Severity: HIGH. ...
show more
Honeypot detection: Remote Desktop Protocol (RDP) brute-force attempt on port 3389. Severity: HIGH. Aaran.cloud
show less
Brute-Force
Hacking
๐จ๐ฆ
Lagserv.com
2021-05-01 07:40:03
(5 years ago)
XMLRPC brute force
Web Spam
Blog Spam
Brute-Force
Web App Attack