๐ต๐น
PT
2026-07-20 13:07:00
(5 days ago)
web app attack
Brute-Force
Web App Attack
๐ฎ๐ฑ
spd.co.il
2026-07-08 19:01:41
(2 weeks ago)
Web application attack detected
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-06 20:54:03
(2 weeks ago)
170.124.32.155 - - [06/Jul/2026:23:53:56 +0300] "GET /wp-includes/Requests/about.php HTTP/1.1" 404 4 ...
show more
170.124.32.155 - - [06/Jul/2026:23:53:56 +0300] "GET /wp-includes/Requests/about.php HTTP/1.1" 404 4216 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-06 19:43:22
(2 weeks ago)
170.124.32.155 - - [06/Jul/2026:22:34:59 +0300] "GET /wp-includes/css/buttons.css HTTP/1.1" 404 251 ...
show more
170.124.32.155 - - [06/Jul/2026:22:34:59 +0300] "GET /wp-includes/css/buttons.css HTTP/1.1" 404 251 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
170.124.32.155 - - [06/Jul/2026:22:43:17 +0300] "GET /wp-content/plugins/pwnd/pwnd.php HTTP/1.1" 404 4221 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ธ๐ช
KIDOS
2026-07-06 12:19:42
(2 weeks ago)
malicious activity
Web App Attack
๐บ๐ธ
ipblock.com
2026-07-06 09:25:00
(2 weeks ago)
IPBlock protected site ID [4055-d][s=01].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-06 08:21:00
(2 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-06 07:37:28
(2 weeks ago)
(mod_security) mod_security (id:212620) triggered by 170.124.32.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212620) triggered by 170.124.32.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 03:37:13.005545 2026] [security2:error] [pid 12147:tid 12147] [client 170.124.32.155:48961] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "3"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||hanabritgermanshepherds.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /index.php/component/content/article/index.php?option=com_content&view=article&id=23&catid=2'\\x22><script>alert(68752)</script>&itemid=116"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "hanabritgermanshepherds.com"] [uri "/index.php/component/content/article/index.php"] [unique_id "aktbKDZyVvK8jiu7BC5dkgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RidgeStar
2026-07-06 00:49:28
(2 weeks ago)
2026-07-05T17:40:06-07:00: FAQ'"><script>alert(68752)</script>
Port Scan
Hacking
๐บ๐ธ
RidgeStar
2026-07-06 00:27:59
(2 weeks ago)
2026-07-05T13:11:02-07:00: display'"><script>alert(68752)</script>
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-05 23:06:00
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 170.124.32.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.124.32.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 19:05:41.261056 2026] [security2:error] [pid 21766:tid 21766] [client 170.124.32.155:51971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cs-mall.com"] [uri "/.env"] [unique_id "akrjRRMQcnI71A0UW5Qn5AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
conseilgouz
2026-07-05 22:57:36
(2 weeks ago)
upe-11 : Block illegal characters=>/index.php?option=com_content&view=article%27%22%3E%3Cscript% ...
show more
upe-11 : Block illegal characters=>/index.php?option=com_content&view=article%27%22%3E%3Cscript%3Ealert(68752)%3C/script%3E&id=...(alert(alert)
show less
Hacking
๐จ๐ญ
4server
2026-07-05 22:15:01
(2 weeks ago)
[MonJul0600:14:48.7840002026][security2:error][pid560210:tid560443][client170.124.32.155:0]ModSecuri ...
show more
[MonJul0600:14:48.7840002026][security2:error][pid560210:tid560443][client170.124.32.155:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\<\?/\?\?script\|\(\?:\<\|\<\?/\)\(\?:\(\?:java\|vb\)script\|about\|applet\|activex\|chrome\|qx\?ss\|embed\)\|\<\?/\?i\?frame\\\\\\\\b\|\<\?imgsrc\?=\|\<\?basehref\?=\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1010\"][id\"340147\"][rev\"163\"][msg\"Atomicorp.comWAFRules:PotentialCrossSiteScriptingAttack\"][data\"\<script\"][severity\"CRITICAL\"][hostname\"comarcosa.com\"][uri\"/cgi-sys/suspendedpage.cgi\"][unique_id\"akrXWG31WRgidpc-ft0fEQAAAcs\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 21:53:25
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 170.124.32.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.124.32.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 17:53:06.164856 2026] [security2:error] [pid 16140:tid 16140] [client 170.124.32.155:43039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verenacastle.com"] [uri "/.env.dev.local"] [unique_id "akrSQjEv-utzXgiK0y6VpQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 21:37:25
(2 weeks ago)
(mod_security) mod_security (id:210381) triggered by 170.124.32.155 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210381) triggered by 170.124.32.155 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 17:37:12.384274 2026] [security2:error] [pid 8342:tid 8342] [client 170.124.32.155:49659] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||coffeewitheinstein.com|F|4"] [data "REQUEST_URI=/index.php?main_page=page&id=1100%90%CRITICAL"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "coffeewitheinstein.com"] [uri "/index.php"] [unique_id "akrOiE0uYNf-1Z7sTHx_ZQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack