๐ฎ๐ช
RoboSOC
2026-02-13 10:44:04
(4 months ago)
HTTP Directory Traversal Vulnerability , PTR: PTR record not found
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-13 08:35:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 163.61.102.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 163.61.102.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 03:35:49.573944 2026] [security2:error] [pid 391111:tid 391111] [client 163.61.102.133:56988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fiyaplatform.com"] [uri "/.env"] [unique_id "aY7iZd9eIvqCXEkDWtFR9wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
conseilgouz
2026-02-13 08:10:13
(4 months ago)
upe-21 : Rogue PHP files=>/adminer.php
Hacking
๐จ๐ฆ
polycoda
2026-02-13 08:01:25
(4 months ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ SQL Injection Attempt (Non Decay-Based) - ๐ ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ SQL Injection Attempt (Non Decay-Based) - ๐ Admin Panel Scanning (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
Tonga-Soa
2026-02-13 07:59:06
(4 months ago)
"Inject SQL SELECT ... <script..."
Hacking
SQL Injection
๐น๐ผ
kk_it_man
2026-02-12 17:30:32
(4 months ago)
Hacking
๐ต๐ฑ
get-money.pl
2026-02-01 15:37:00
(4 months ago)
Confirmed source of repeated and high-risk malicious activity targeting web applications. Observed b ...
show more
Confirmed source of repeated and high-risk malicious activity targeting web applications. Observed behavior includes high-volume automated requests, multiple confirmed SQL injection attempts, and targeted exploitation of application endpoints. The activity triggered repeated critical Fail2Ban detections (Category: SQL injection / intrusion) and demonstrates clear hostile intent. Due to persistence and severity, the IP address has been permanently blocked at firewall and WAF level and classified as malicious.
show less
Hacking
SQL Injection
Brute-Force
Web App Attack
SSH
๐ฎ๐น
Rosh
2026-02-01 14:55:56
(4 months ago)
[02/01/26 15:55:56] 1 attack: /---er.php (severity 8);
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 14:52:21
(4 months ago)
(mod_security) mod_security (id:210580) triggered by 163.61.102.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210580) triggered by 163.61.102.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 09:52:16.369738 2026] [security2:error] [pid 676:tid 676] [client 163.61.102.133:49512] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:cPath. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||psdinnersready.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:cPath: ../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "psdinnersready.com"] [uri "/index.php"] [unique_id "aX9ooMiI2K3g258hIBiMIgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2026-02-01 14:03:40
(4 months ago)
COMODO WAF: Cross-site Scripting (XSS) Attack. Pattern match "<script\\\\b" at REQUEST_URI. (212620- ...
show more
COMODO WAF: Cross-site Scripting (XSS) Attack. Pattern match "<script\\\\b" at REQUEST_URI. (212620-124)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-01 13:58:27
(4 months ago)
(mod_security) mod_security (id:210580) triggered by 163.61.102.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210580) triggered by 163.61.102.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 08:58:21.042856 2026] [security2:error] [pid 26934:tid 26934] [client 163.61.102.133:56688] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:action. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.oualierealty.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:action: ../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.oualierealty.com"] [uri "/index.php"] [unique_id "aX9b_RgV2WKLRwyWVdgoFgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-02-01 12:33:29
(4 months ago)
153 requests with url.path *.env
Brute-Force
Bad Web Bot
๐น๐ท
Doruk
2025-11-08 14:30:01
(7 months ago)
Unauthorized connection attempt
Brute-Force
๐ฉ๐ช
Grizzlytools
2025-10-17 05:14:18
(8 months ago)
Kingcopy(AI-IDS)RouterOS: Portscanner detected.
Port Scan
๐ฉ๐ช
KPS
2025-10-16 15:55:43
(8 months ago)
PortscanM
Port Scan