๐ฉ๐ช
on-com
2026-10-10 05:10:54
(7 minutes ago)
URL scan
Brute-Force
Web App Attack
๐ฉ๐ช
paissangroup
2026-10-10 05:06:20
(12 minutes ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-10-10 05:04:12
(14 minutes ago)
Bot / seems abusive / Apache connections: 34
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 04:45:41
(32 minutes ago)
(mod_security) mod_security (id:211190) triggered by 168.144.254.181 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 168.144.254.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 00:45:37.964037 2026] [security2:error] [pid 29127:tid 29127] [client 168.144.254.181:49764] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mwrn.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /images/index.html?id=%24%7B%40print_r%28%40system%28%22cat+/etc/passwd%22%29%29%7D"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mwrn.com"] [uri "/images/index.html"] [unique_id "asnC8bm096I6cqP-dCnn0wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-10 04:45:20
(33 minutes ago)
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-10 04:30:57
(47 minutes ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 168.144.254.181 - - [10/Oct/2026:06:30:46 +0200] "GET /images/index.html?id=%24%7B%40print_r%28%40system%28%22cat+/etc/passwd%22%29%29%7D HTTP/2.0" 404 20442 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 04:23:45
(54 minutes ago)
(mod_security) mod_security (id:211190) triggered by 168.144.254.181 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 168.144.254.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 00:23:40.804961 2026] [security2:error] [pid 24827:tid 24827] [client 168.144.254.181:45688] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||lusineweb.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /images/index.html?id=%24%7B%40print_r%28%40system%28%22cat+/etc/passwd%22%29%29%7D"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lusineweb.com"] [uri "/images/index.html"] [unique_id "asm9zL9uWswmxSopfs_N1QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
conseilgouz
2026-10-10 04:21:07
(57 minutes ago)
loe-404 : Too many 404 errors
Brute-Force
Anonymous
2026-10-10 03:36:31
(1 hour ago)
Login brute force on default-vhost (5 attempts in 24h). Reported by CRMON.
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-10 02:55:58
(2 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
dot.mg
2026-10-10 02:44:03
(2 hours ago)
Bad behaviour
Web Spam
๐ช๐ธ
el-brujo
2026-10-10 02:41:04
(2 hours ago)
10/Oct/2026:04:41:04.200387 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
10/Oct/2026:04:41:04.200387 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 168.144.254.181] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:id. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: ${@print_r(@system(id))} found within ARGS:id: ${@print_r(@system(id))}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/88"] [tag "PCI/6.5.2"] [hostname "elhacker.info"] [uri "/images/index.html"] [unique_id "asmlwNypfwSUSOI1ZllezgAAAY8"]
...
show less
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-10-10 02:39:39
(2 hours ago)
481 requests with url.path *config.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-10 02:16:58
(3 hours ago)
(mod_security) mod_security (id:211190) triggered by 168.144.254.181 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 168.144.254.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 22:16:53.420636 2026] [security2:error] [pid 9914:tid 9914] [client 168.144.254.181:60736] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||cruisingforsex.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /images/index.html?id=%24%7B%40print_r%28%40system%28%22cat+/etc/passwd%22%29%29%7D"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruisingforsex.com"] [uri "/images/index.html"] [unique_id "asmgFcWe2sPxT2qsNr0DWwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 02:05:12
(3 hours ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=45
Hacking