๐ต๐น
PT
2026-07-20 13:04:00
(4 days ago)
web app attack
Brute-Force
Web App Attack
๐ฎ๐ฑ
spd.co.il
2026-07-08 19:01:38
(2 weeks ago)
Web application attack detected
Hacking
Web App Attack
๐บ๐ธ
gu-alvareza
2026-07-07 07:05:18
(2 weeks ago)
Cross.Site.Scripting
Web App Attack
Hacking
Anonymous
2026-07-07 06:09:12
(2 weeks ago)
Querying for PHP services on a non-PHP site (/index.php)
Web App Attack
Anonymous
2026-07-06 20:21:06
(2 weeks ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-06 20:01:03
(2 weeks ago)
170.124.32.146 - - [06/Jul/2026:23:00:55 +0300] "GET /wp-includes/Requests/about.php HTTP/1.1" 404 2 ...
show more
170.124.32.146 - - [06/Jul/2026:23:00:55 +0300] "GET /wp-includes/Requests/about.php HTTP/1.1" 404 251 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
170.124.32.146 - - [06/Jul/2026:23:00:56 +0300] "GET /wp-content/plugins/index.php HTTP/1.1" 404 251 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-06 11:37:07
(2 weeks ago)
(mod_security) mod_security (id:212620) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212620) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 07:36:52.266463 2026] [security2:error] [pid 26025:tid 26025] [client 170.124.32.146:57729] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||verenacastle.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /g12cartcontents.php?fromwhere=g12generic.php&fromwhat=itemdetail'\\x22><script>alert(68752)</script>&itemid=*"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "verenacastle.com"] [uri "/g12cartcontents.php"] [unique_id "akuTVFA9_EhIZdWAsUnougAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-06 10:27:45
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 06:27:32.209397 2026] [security2:error] [pid 24196:tid 24196] [client 170.124.32.146:58377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fiyaplatform.com"] [uri "/.env.dev.local"] [unique_id "akuDFCveGRKkuWe9kSrG_wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-06 08:27:57
(2 weeks ago)
WordPress HTTP Brute Force Login Attempt.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-06 08:11:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 04:10:49.735341 2026] [security2:error] [pid 3051:tid 3071] [client 170.124.32.146:39173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fnaandpartners.com"] [uri "/.env.bak"] [unique_id "aktjCQ3b9UYGpzZsPgXDHQAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-06 00:35:56
(2 weeks ago)
SQL Injection
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-05 23:17:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 19:17:06.512072 2026] [security2:error] [pid 15175:tid 15175] [client 170.124.32.146:40995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coffeewitheinstein.com"] [uri "/.env.prod.local"] [unique_id "akrl8vz4zTqUqaovGFQUiAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-05 22:51:42
(2 weeks ago)
[MonJul0600:51:33.1805872026][security2:error][pid700949:tid701247][client170.124.32.146:0]ModSecuri ...
show more
[MonJul0600:51:33.1805872026][security2:error][pid700949:tid701247][client170.124.32.146:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"comarcosa.com\"][uri\"/.env.production\"][unique_id\"akrf9VzbYVy_0BkAvhU7HgAAAIg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
RidgeStar
2026-07-05 21:24:04
(2 weeks ago)
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-05 21:17:00
(2 weeks ago)
(mod_security) mod_security (id:212620) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212620) triggered by 170.124.32.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 17:16:46.202408 2026] [security2:error] [pid 618:tid 618] [client 170.124.32.146:46071] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||kingscruff.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /g12ordergen.php?fromwhere=g12generic.php'\\x22><script>alert(68752)</script>&fromwhat=itemdetail&itemid=62"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "kingscruff.com"] [uri "/g12ordergen.php"] [unique_id "akrJvr_13hCaN3PKdY1s0wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack